Showing posts with label google. Show all posts
Showing posts with label google. Show all posts

Understanding Google Dorks and How Hackers Use Them

GoogleDorks
The idea of using Google as a hacking tool or platform certainly isn’t a novel idea, and hackers have been leveraging this incredibly popular search engine for years. In fact, Google Dorks have their roots in 2002 when a man by the name of Johnny Long started using custom queries to search for elements of certain websites that he could leverage in an attack. At its core, that’s exactly what Google Dorks are – a way to use the search engine to pinpoint websites that have certain flaws, vulnerabilities, and sensitive information that can be taken advantage of. As a side note, some people refer to Google Dorks as Google Hacking (they’re more or less synonymous terms).GoogleDorks
Believe it or not, Google Dorks can uncover some incredible information such as email addresses and lists, login credentials, sensitive files, website vulnerabilities, and even financial information (e.g. payment card data). In fact, in our WordPress hacking tutorial, we listed a few Google Dorks that could be used to find SQLi (SQL injection) vulnerabilities. And the wonderful thing is that this is an incredibly passive form of attack that doesn’t draw much attention to the hacker. Unfortunately, some people use these techniques for illicit and nefarious activities such as cyberwarfare, digital terrorism, identity theft, and a whole host of other undesirable activities.
If you are reading this to learn how to break into a website and harm others just for kicks, perhaps you should pursue other interests. Let me caution you by stating that breaking into websites is an illegal activity, and it violates not only laws bur moral codes as well. If you get caught, the consequences could be dire. Then why learn this to begin with, you ask? Well, the first place any white hat hacker needs to start is with understanding how hackers operate. Only then can they plug up security holes to prevent future attacks.
Understanding Google Dorks Operators
Just like in simple math equations, programming code, and other types of algorithms, Google Dorks has several operators that aspiring white hat hackers need to understand. There are far too many to include in this guide, but we will go over some of the most common:
  • intitle – this allows a hacker to search for pages with specific text in their HTML title. So intitle: “login page” will help a hacker scour the web for login pages.
  • allintitle – similar to the previous operator, but only returns results for pages that meet all of the keyword criteria.
  • inurl – allows a hacker to search for pages based on the text contained in the URL (i.e. “login.php”).
  • allinurl – similar to the previous operator, but only returns matches for URLs that meet all the matching criteria.
  • filetype – helps a hacker narrow down search results to specific types of files such as PHP, PDF, or TXT file types.
  • ext – very similar to filetype, but this looks for files based on their file extension.
  • intext – this operator searches the entire content of a given page for keywords supplied by the hacker.
  • allintext – similar to the previous operator, but requires a page to match all of the given keywords.
  • site – limits the scope of a query to a single website.
Custom Crafting Google Dork Queries
Now that we have a basic understanding of some of the operators and how Google Dorks can be used to scour the web, it’s time to look at query syntax. The following is the high level structure of Google Dorks that targets a specific domain:
  • inurl: domain/” “additional dorks
A hacker would simply plug in the desired parameters as follows:
  • inurl = the URL of a site you want to query
  • domain = the domain for the site
  • dorks = the sub-fields and parameters that a hacker wants to scan
If a hacker wishes to search by a field other than the URL, the following can be effectively substituted:
  • intitle:
    inurl:
    intext:
    define:
    site:
    phonebook:
    maps:
    book:
    info:
    movie:
    weather:
    related:
    link:
These options will help a hacker uncover a lot of information about a site that isn’t readily apparent without a Google Dork. These options also offer ways to scan the web to located hard to find content. The following is an example of a Google Dork:
Making Effective Use of Operators
It may seem a little cryptic at first, so let me provide a few examples that show how the different operators can be used to locate content and website data. A user can make effective use of the intitle operator to locate anything on a website. Perhaps they are scraping email addresses and want to scan sites for the “@” symbol, or maybe they are looking for an index of other files.
Furthermore, the intext operator can basically be used to scan individual pages for any text you want, such as a target’s email address, name, the name of a web page (like a login screen) or other personal information to collect data about them.
The more you practice, the further you’ll be able to hone your queries to pinpoint different types of websites, pages, and vulnerabilities. Again, I need to caution you not to use these queries to attack another website, because that would be illegal and could get you into a lot of trouble. Still, Google Dorks are a great way to locate hidden information on the web, which is why hackers love to use them to find security flaws in websites.
If you want to dig into some more queries, there are some great Google Dork resources on the web.
Share:

Get Free Google Adwords Voucher for free advertising

  • 0d

  • 0
     

  • Sha
free-75-google-adwords-campaignsThere has been a lot of success stories from advertising using Google adwords, where unlike any other advertising company, Google displays only relevant ads on a particular site which proves really useful for businesses. And this even helps in driving more targeted traffic into your blog or website.

But what if you want to advertise in Google adwords but don’t want to spend money at the same time.Well there is a simple trick or a way to do just that.
75-free-google-adwords-coupon






Google Adwords sends out free vouchers to its customers in order to test out the Adwords service.So here is a free Google  Adwords voucher of $75 which you will be able to get free Adwords Advertising worth $75 for free after you fill out the form using his link.
https://services.google.com/fb/forms/adwordscoupon/
This link takes you to a form by filling which you will receive the free Adwords coupon code within a week or so. You can use this trick multiple times by using different Adwords accounts and filling the form for the free coupon.
So what are you waiting for, get your free $75 Adwords coupon today and get free Advertising for your businesses .
Share:

Get suggestions from Google for speeding up your website

site-speed-hackhow-histogramThere are a lot of tools that are available on the internet for free use and also commercial. But sometimes its best to know what is really  expected from Google from your website about your website speed and loading time , if you want to consider good amount of traffic from search engines like Google.
Google ranks the page based on their content as well as their loading speed and lot of other factors that affect the page rank. So it is required to optimize your site based on interactive and attractive designs and at the same time depend on lighter resources for its implementation.

Google-page-Speed-online-hackhow



So here is a great tool from Google labs that gives you a detailed advice for your entered website url and suggests the best required tweaks based on priority on different aspects of the page speed. The tool is called the Google’s Page Speed online tool which will as you for your website url and after clicking the Analyse Performance carries out the analysis to rank you based on different factors of your website page speed.Also gives you advice on making your site faster.
Fell free to check out this awesome tool to get free useful advice to optimize your site.
Share:

IPv6 test day Just Around the Corner

World IPv6 day is scheduled to be held on June 8th,2011 and is sponsored by the Internet  Society (ISOC). The event mainly is a global scale test flight for the IPv6 and will start at midnight (GMT) of 8th  June for a period of around 24 hours.
IPv6-logo-hackhow




Several Big companies will participate for the test including Google,Facebook,Yahoo and many other companies, will change their IP address from IPv4 to IPv6 for a period of 24 hours simultaneously at the same time. This test of the new IPv6 will provide real-world data for  hardware manufacturers, Internet Service Providers,Operating system vendors and for all the participating Web companies.
It is believed that IPv4 will saturate in the near future and even if its used ,will provide much security risk of managing or blocking a single malicious IP address that may be shared by thousands of genuine users.
What does it mean for you??…Well not much , the test is basically carried out in a controlled manner such that the problems are found and corrected.So a very few errors are expected for the big company sites while testing ,but it wont effect the average user much in terms of latency and might go unnoticed.
Share:

How people try to Cheat Google Adsense

Google adsense is the most profitable  revenue stream for publishers and also a reliable advertiser for its advertisers, but some people may try to earn more money by fraud clicks or many other ways that are mentioned here to finally get their  accounts banned. The post may sound good for people who came in searching for cheating tricks , but if you try these methods, you will surely end up banning your adsense account.So here are the tricks that you should not be doing just to earn some quick bucks..

google adsense





1 Clicking your own Ads
This is the most dumbest method and is mainly used by  noobs who don’t understand web technology and the internet . These fraud clicks may range from few clicks to even hundreds of clicks, just to make money faster. But the end result is no mystery.
2 Click through rate manipulation
Click Through Rate(CTR) of a page is usually considered to be 7% or less on an average.If there are more fraud clicks on your site, resulting in CTR of more than 10%, will surely raise Google’s flag. So some people try to adjust the click through rate by displaying the ads in junk low keyword density pages generating high traffic visits onto those pages. This then lowers the CTR below 10% and they even use the low CPC ads on those junk pages.
3 Fool the Visitors
When the site Admin puts the ads on the section of  ‘Sponsors’ or any other boxes with weird messages like ‘Support Us’ or ‘Click Here’, will raise flags to Google about these high clicked and low  value Ads and get their Account Banned soon enough.Only box title’s mentioned in the Google Adsense TOS policy can be used. So let your Ads look like Ads and don’t try to fool the visitors.
4 No Content , Only Ads in Page
If you insert all Adsense codes on a single page without content, then the user has no choice but to click on the Ads expecting to see some results or information that he came for, but this will lead to more Ad clicks which are closed instantly after the user discovers it as an Ad.So the Google has to protect its Advertisers and provide the value for what they are paying to Google.So google has no other choice but to terminate your account.
5 Ask Friends Or Family to Click your Ads
Here is another trick that’s used by noobs.  The Blogger might ask his friends living far off or abroad to click through his ads. But Google has enough Data from search engines or your profile across the internet to know how the clicks are generated and how that IP is related to your Address and find out if you have any friends or family in that place.So stop asking your relatives or friends to click your ads just because they live in far places.Multiple clicks from that friends IP location will get your Adsense account Banned.
6 The Popular Click Ring Network Cheat
The bloggers organize ring networks using the forums and social networking sites and plan the fraud clicks ,among their mutual website ads and click through each others ads.Once google finds out about this trick, you are sure to get banned from the program.
7 Proxy to Click Ads
Another popular trick among the publishers, for which they use proxy websites like the tor “onion routers” or any other anonymizer to click on their ads on their website.This trick is well known and might land your adsense account into big trouble.
8 Paid Ad Click Cheat
Paid Click Cheaters are often available for around $50 and mainly are people employed from developing countries like China,Phillipines,India or Pakistan. This lets the owner of the site to earn some money until his account gets banned from Google Adsense.
9 Automated Software ClickBots for Advertisements
The ClickBots are smart programs written in order to generate good CTR by browsing multiple pages on the site and then clicking on the ads, and stay for a few minutes to avoid suspicion. Some ClickBots even change their IP address , so that the Ads appear Genuine to Google.
10 Multiple Computers Click Fraud
This user Doesn’t have much knowledge about IP address or internet technology for that instance.The person tries to click on the ads from multiple computers from home ,Internet Centers, or any other internet spots.
Disclaimer: These methods mentioned here are solely to warn you about the consequences of your account getting banned if you try any of these methods listed here.And i do not recommend you to try any of these unethical tricks and even i don’t use these tricks myself. So this post is mainly to help you be aware of the reasons for Google adsense accounts getting banned and help you to prevent your account from getting banned …CHEERS..!!
Share:

How to Get your Own Google+ (Plus) Short Vanity Url

Sharing your Google Plus profile link is difficult as  Google plus doesn’t yet support short url’s for the Google+ profiles yet. So Instead you will need to use the long unique number assigned  to each Google Plus profile, which is difficult to remember and also makes sharing your profile difficult. But there is an alternative to get your own vanity url for your Google plus profile.




Gplus.to is a service that makes it easier to get your own short url for your profile to share it with your friends.This lets you create your own vanity url for your long Google Plus profile and allows you to register your username from 3 characters to 25 characters in length.Just enter in your Google Plus Profile Id in the right and get the desired available username to link that Google Plus Profile Id.
Well there you have it, a service that lets you get your own short url like in Facebook,which will provide you with a unique link to share with your friends.Link –> Gplus.to
Share:

How to: View Hidden Forums and Websites that ask for registration < Firefox version.




Today I will tell you how to do it on Firefox with an Add-on.

What you need is
Firefox
An Add on called User Agent Switcher  ( Download > https://addons.mozilla.org/en-US/firefox/addon/user-agent-switcher/)

All you have to do is to open drop down menu for User Agent Switcher and change your agent to search engine. and then you will views websites like that User Agent (Search engine) that you chooses. Simply after your work is done change the agent back to you own.
Share:

DISCLAIMER

The information provided on hottechtips.blogspot.com is to be used for educational purposes only. The website creator is in no way responsible for any misuse of the information provided. All of the information in this website is meant to help the reader develop a hacker defense attitude in order to prevent the attacks discussed. In no way should you use the information to cause any kind of damage directly or indirectly. The word “Hack” or “Hacking” on hottechtips.blogspot.com should be regarded as “Ethical Hack” or “Ethical hacking” respectively. You implement the information given at your own risk.