Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Usual Suspects Top List of Website Vulnerabilities | Main | Feature Creep too Often Means Vulnerability Creep »

Googling for Vulnerabilities

Phishers and other attackers can use Google to find sites with known vulnerabilities so if you thought you could get by with out vulnerability scanning, better read on.

Dark Reading is reporting on work done by John LaCour from MarkMonitor who has compiled lists of search terms indicating particular vulnerabilities in Websites (aka "dorks"):

With the dork inurl:index1.php?go=*.php, for instance, the phisher would enter that string into the search engine. "The search results would return a list of potentially vulnerable sites. The attacker then selects one of the sites and exploits the PHP application by referencing their own remote PHP file for inclusion," LaCour says.

The only way to keep up with the speed at which site vulnerabilities can be discovered with Google is to use vulnerability scanning tools as part of the pre-deployment test process.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/684

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net