Using google to attack on your personal web server

last updated in Categories Apache, lighttpd, Security

According to this document Google can be utilized to attack on your personal web server.
Google can be utilized to hack into websites – actively exploiting them (not information gathering by the use of Google hacking, although that is how most of the sites vulnerable to RFI attacks are found).

By placing a URL on any web page, Google will find it, visit it and then index it. With this mechanism, it is possible to anonymize attacks on third party web sites through Google by the use of its crawler.

Read more at securiteam.com blog… (found via slashdot)

Solution is quite simple put a web server in chrooted jail 😀 Or use OpenBSD which runs Apache out of box in chrooted jail.

Posted by: Vivek Gite

The author is the creator of nixCraft and a seasoned sysadmin, DevOps engineer, and a trainer for the Linux operating system/Unix shell scripting. Get the latest tutorials on SysAdmin, Linux/Unix and open source topics via RSS/XML feed or weekly email newsletter.

2 comment

  1. Some example hot to use Google to hack some websites, just for fun:

    http://www.google.com/search?q=localhost+site%3A.com%2Fconfig.inc

    Have a question? Post it on our forum!