8.19.2003

pwned by google

Holy shit, this is fascinating.

I had no idea how much google was archiving of people's stupidity. This website has some amazing searches that you can enter into google and pull crazy stuff in the google cache of someone's site.

http://johnny.ihackstuff.com/index.php?module=prodreviews

Just as a teaser, I'll tell you that I found a bank online with a list of user passwords in google's cache. The passwords were in standard unix encryption style, which could probably be hacked pretty easily with John the Ripper. I also found some encrypted passwords in other formats that are easily crackable. You can also search for executables available on the web, and all kinds of known server vulnerabilities.

Quite simply put, this is a stunning use of google. Not only that, but most of this stuff isn't removable without a huge amount of effort in contacting google that these companies just won't do. Even if you fix the problem, it's all cached! Your site could be totally secure, and the password lists would still be available to hackers on the web.

0 Comments:

Post a Comment

<< Home