Computer attackers are able to gather unprotected information using Google search to attack such computers. This is known as “Google reconnaissance”. The steps below illustrate how the information could be collected for carrying out such an attack.
Uncover MS Excel files with login infomation
Below steps illustrate how a Google search can be performed to retrieve MS Excel files containing user id and password information in clear text. These could then be used to log into or gain access into the computer system or the network.step 1
Use Google advanced search, search words containing “login:*” “password=*”, select file types MS excel “.xls”, then click advanced search.step 2
Below screen shows 1st page of results found by Google that matches the search criteria.step 3
The screen below shows contents of a MS Excel file that contains an actual user id and a password value for a web site with the URL of the web site.Uncover Text files with login infomation
A similar search can be performed to search for text files that contain user id and password values.
No comments:
Post a Comment