lord of the bing - owasp of the bing taking back search engine hacking from google and bing 8...

45
Lord of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Presented by: Presented by: Presented by: Rob Ragan Stach & Liu, LLC www.stachliu.com

Upload: phungbao

Post on 17-Mar-2018

217 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Lord of the BingTaking Back Search Engine Hacking From Google and Bing 8 October 2010

Presented by: Presented by: Presented by: Presented by: Rob RaganStach & Liu, LLCwww.stachliu.com

Page 2: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Goals

2

• To improve To improve To improve To improve Google Hacking• Attacks and defenses• Advanced tools and techniques

• To think differently To think differently To think differently To think differently about exposures in publicly available sources

• To blow your mind!

D E S I R E D O U T C O M E

Page 3: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Google/Bing HackingS E A R C H E N G I N E A T T A C K S

3

Page 4: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Attack Targets

4

• Advisories and Vulnerabilities (215)

• Error Messages (58)

• Files containing juicy info (230)

• Files containing passwords (135)

• Files containing usernames (15)

• Footholds (21)

• Pages containing login portals (232)

G O O G L E H A C K I N G D A T A B A S E

• Pages containing network or vulnerability data (59)

• Sensitive Directories (61)

• Sensitive Online Shopping Info (9)

• Various Online Devices (201)

• Vulnerable Files (57)

• Vulnerable Servers (48)

• Web Server Detection (72)

Page 5: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Attack Targets

5

Old School Examples• Error Messages

• filetype:asp + "[ODBC SQL“

• "Warning: mysql_query()" "invalid query“

• Files containing passwords• inurl:passlist.txt

G O O G L E H A C K I N G D A T A B A S E

Page 6: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

New Toolkit

6

Google Diggity• Uses Google AJAX API

• Not blocked by Google bot detection• Does not violate Terms of Service

• Can leverage

Bing Diggity• Uses Bing SOAP API• Company/Webapp Profiling

• Enumerate: URLs, IP-to-virtual hosts, etc.• Bing Hacking Database (BHDB)

• Vulnerability search queries in Bing format

S T A C H & L I U T O O L S

Page 7: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

New Toolkit

7

GoogleScrape Diggity• Uses Google mobile

interface• Light-weight, no

advertisements or extras• Violates Terms of Service

• Automatically leverages valid open proxies

• Spoofs User-agent and Referer headers

• Random &&&&useripuseripuseripuserip= = = = value

S T A C H & L I U T O O L S

Page 8: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

New Hack Databases

8

BHDB – Bing Hacking Data Base• First ever Bing Hacking database

• Bing has limitations that make it difficult to create vuln search queries

• Bing disabled the link:link:link:link: and linkdomainlinkdomainlinkdomainlinkdomain:::: directives to combat abuse in March 2007

• Does not support ext: ext: ext: ext: or inurlinurlinurlinurl::::• The filetypefiletypefiletypefiletype: : : : functionality is limited

A T T A C K Q U E R I E S

Example ---- Bing vulnerability search:• GHDB query

• "allintitle:Netscape FastTrack Server Home Page"

• BHDB version• "intitle:Netscape FastTrack Server Home Page"

Page 9: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

New Hack Databases

9

SLDB - Stach & Liu Data Base• New Google/Bing hacking searches in active development by the

S&L team

SLDB Examples• ext:(doc | pdf | xls | txt | ps | rtf | odt | sxw | psw | ppt | pps |

xml) (intext:confidential salary | intext:"budget approved")

inurl:confidential

• ( filetype:mail | filetype:eml | filetype:mbox | filetype:mbx )

intext:password|subject

• filetype:sql "insert into" (pass|passwd|password)

• !Host=*.* intext:enc_UserPassword=* ext:pcf

• "your password is" filetype:log

A T T A C K Q U E R I E S

Page 10: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

DEMODEMODEMODEMON E W G O O G L E H A C K I N G T O O L S

10

Page 11: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Traditional DefensesG O O G L E H A C K I N G D E F E N S E S

11

• “Google Hack yourself” organization• Employ tools and techniques used by hackers• Remove info leaks from Google cache

• Using Google Webmaster Tools

• Regularly update your robots.txt.• Or robots meta tags for individual page exclusion

• Data Loss Prevention/Extrusion Prevention Systems• Free Tools: OpenDLP, Senf

• Policy and Legal Restrictions

Page 12: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Traditional DefensesG O O G L E H A C K I N G D E F E N S E S

12

• “Google Hack yourself” organization• Employ tools and techniques used by hackers• Remove info leaks from Google cache

• Using Google Webmaster Tools

• Regularly update your robots.txt.• Or robots meta tags for individual page exclusion

• Data Loss Prevention/Extrusion Prevention Systems• Free Tools: OpenDLP, Senf

• Policy and Legal Restrictions

Page 13: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Advanced DefensesP R O T E C T Y O N E C K

13

Page 14: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Existing Defenses“H A C K Y O U R S E L F”

14

MultiMultiMultiMulti----engine resultsengine resultsengine resultsengine results�

RealRealRealReal----time updatestime updatestime updatestime updates�

ConvenientConvenientConvenientConvenient�

Historical archived dataHistorical archived dataHistorical archived dataHistorical archived data�

� MultiMultiMultiMulti----domain searchingdomain searchingdomain searchingdomain searching

Tools existTools existTools existTools exist�

Page 15: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Advanced DefensesN E W H O T S I Z Z L E

Stach & Liu now proudly presents:• Google Hacking AlertsGoogle Hacking AlertsGoogle Hacking AlertsGoogle Hacking Alerts

• Bing Hacking AlertsBing Hacking AlertsBing Hacking AlertsBing Hacking Alerts

15

Page 16: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Google Hacking AlertsA D V A N C E D D E F E N S E S

16

Google Hacking Alerts• All hacking database queries using

• Real-time vuln updates to >2400 hack queries via RSS

• Organized and available via importable file

Page 17: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Google Hacking AlertsA D V A N C E D D E F E N S E S

17

Page 18: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Bing Hacking AlertsA D V A N C E D D E F E N S E S

18

Bing Hacking Alerts• Bing searches with regexs from BHDB• Leverage &format=&format=&format=&format=rssrssrssrss directive to turn into update feeds

Page 19: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

DEMODEMODEMODEMOA D V A N C E D D E F E N S E T O O L S

19

Page 20: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

New Defenses“G O O G L E / B I N G H A C K A L E R T S”

20

MultiMultiMultiMulti----engine resultsengine resultsengine resultsengine results�

RealRealRealReal----time updatestime updatestime updatestime updates�

ConvenientConvenientConvenientConvenient�

Historical archived dataHistorical archived dataHistorical archived dataHistorical archived data�

� MultiMultiMultiMulti----domain searchingdomain searchingdomain searchingdomain searching

Tools existTools existTools existTools exist�

Page 21: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Google Apps ExplosionS O M A N Y A P P L I C A T I O N S T O A B U S E

21

Page 22: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Google VoiceP A R T Y L I N E

22

Page 23: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Google Code SearchV U L N S I N O P E N S O U R C E C O D E

23

• Regex search for vulnerabilities in public code

• Example: SQL Injection in ASP querystring

• select.*from.*request\.QUERYSTRING

Page 24: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

DEMODEMODEMODEMOG O O G L E C O D E S E A R C H H A C K I N G

24

Page 25: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Google Code SearchV U L N S I N O P E N S O U R C E C O D E

25

Page 26: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Google Code SearchV U L N S I N O P E N S O U R C E C O D E

26

Page 27: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Black Hat SEO

• Use popular search topics du jour

• Pollute results with links to badware

• Increase chances of a successful attack

27

S E A R C H E N G I N E O P T I M I Z A T I O N

Page 28: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Google TrendsB L A C K H A T S E O R E C O N

28

Page 29: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking
Page 30: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

DefensesB L A C K H A T S E O D E F E N S E S

30

• Malware Warning Filters• Google Safe Browsing• Microsoft SmartScreen Filter• Yahoo Search Scan

• Sandbox Software• Sandboxie (sandboxie.com)• Dell KACE - Secure Browser• Adobe Reader Sandbox (Protected Mode)

• No-script and Ad-block browser plugins

Page 31: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Mass Injection AttacksM A L W A R E G O N E W I L D

31

Malware Distribution Woes• Popular websites victimized, become malware distribution sites to their own

customers

Page 32: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Malware Browser FiltersU R L B L A C K L I S T

32

Protecting users from known threats• Joint effort to protect customers from known malware and phishing links

Page 33: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Inconvenient Truth D I C K H E A D A L E R T S

33

Malware Black List Woes• Average web administrator has no idea when their site gets black listed

Page 34: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Advanced DefensesP R O T E C T Y O N E C K

34

Page 35: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Malware DiggityA D V A N C E D D E F E N S E S

35

Malware Diggity• Uses Bing’s linkfromdomain:linkfromdomain:linkfromdomain:linkfromdomain: directive to identify off-site links of the domain(s)

you wish to monitor

• Compares to known malware sites/domains • Alerts if site is compromised and now distributing malware

• Monitors new Google Trends links

Malware Diggity Alerts• Leverages the Bing ‘&format=rss’ ‘&format=rss’ ‘&format=rss’ ‘&format=rss’ directive, to actively monitor new off-site

links of your site as they appear

• Immediately lets you know if you have been compromised by one of these mass injection attacks or if your site has been black listed

Page 36: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Malware DiggityA D V A N C E D D E F E N S E S

36

Page 37: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Malware DiggityA D V A N C E D D E F E N S E S

37

Page 38: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Identify

External Links

Identify

External Links

Identify

Incoming Links

Identify

Incoming Links

Compare to

Black List

Compare to

Black List

Detect

Infected Links

Detect

Infected Links

AlertAlert

Malware MonitoringI N F E C T I O N D E T E C T I O N

38

Page 39: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Identify

Malware Links

Identify

Malware Links

Mass Inject

Competition

Mass Inject

Competition

Competition

Black Listed

Competition

Black Listed

Competition

PageRank is 0

Competition

PageRank is 0

ProfitProfit

Search Engine deOptimizationB L A C K L I S T Y O U R F O E S

39

Page 40: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Safe Browsing AlertsA D V A N C E D D E F E N S E S

40

Page 41: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Future DirectionP R E D I C T I O N S

41

Page 42: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Google policy is to get right up to the creepy line and notnotnotnot cross it.

-- Eric Schmidt Google CEO

Page 43: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Predictions

43

Data Explosion• More data indexed,

searchable

• Real-time, streaming updates

• Faster, more robust search interfaces

Google Involvement• Filtering of search results

• Better GH detection and tool blocking

Renewed Tool Dev• Google Ajax API based

• Bing/Yahoo/other engines

• Search engine aggregators

• Customized search engines

• Google Code and Other Open Source Repositories

• MS CodePlex, SourceForge, …

• More automation in tools

• Real-time detection and exploitation

• Google worms

F U T U R E D I R E C T I O N S

Page 44: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Questions?Ask us somethingWe’ll try to answer it.

For more info: For more info: For more info: For more info: Email: [email protected]: [email protected] & Liu, LLCwww.stachliu.com

Page 45: Lord of the Bing - OWASP of the Bing Taking Back Search Engine Hacking From Google and Bing 8 October 2010 Presented by: Rob Ragan Stach & Liu, LLC Goals 2 • To improve Google Hacking

Thank You

45

Stach & Liu Project info: Stach & Liu Project info: Stach & Liu Project info: Stach & Liu Project info: http://www.stachliu.com/index.php/resources/tools/google-hacking-diggity-project/