Top Banner
Hacking Borhan Kazimi pour
34

Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Dec 18, 2015

Download

Documents

Amelia Page
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

HackingBorhan Kazimi pour

Page 2: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Agenda

• How to hack

• How to hack using

• How to prevent hack using

Page 3: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

How to hack

Page 4: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Huge White

Page 5: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

How works?

Page 6: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

How find us?

• Crawlers

• Add URL (site submission)

• Opera !

Page 7: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

What give us?

Page 8: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

. calculator

Page 9: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Math operators

Page 10: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Math constants

Page 11: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Units:

Page 12: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Physical constants

Page 13: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

limitations

• Query length limit to 32.

• Noise word almost ignored.– A, an, or, the, for, me, any, to …

• Logic operators must be in uppercase.– OR, AND, NOT

Page 14: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Search result

Page 15: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

…Search result

Page 16: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Special notation

Page 17: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

…Special notation

Page 18: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Key words

Page 19: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

… Key words

Page 20: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

How to hack using

Page 21: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Directory listing

Page 22: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

…Directory listing

• intitle:index.of "parent directory“

• intitle:index.of name size

• intitle:index.of.etc

• Intitle:index.of "parent directory "Xvid -html -htm -php -shtml

Page 23: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Versioning

Page 24: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

…Versioning

• intitle:index.of server.at

• intitle:index.of server.at site:aol.com

• …then Search for exploit and …

Page 25: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Server test page

Page 26: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

…Server test page

• intitle:welcome.to intitle:internet IIS• Intitle:test.page "Hey, it worked !" "SSL/TLS-

aware"

• allintitle:Welcome to Windows 2000 Internet Services

• allintitle:Welcome to Windows XP Server Internet Services

• …

Page 27: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Finding ID/Pass

• "# -FrontPage-" inurl:service.pwd • inurl:admin inurl:userlist• "AutoCreate=TRUE password=*" • allinurl: admin mdb• allinurl:auth_user_file.txt • intitle:"Index of" config.php• filetype:bak inurl:"htaccess|passwd|shadow|

htusers"

Page 28: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.
Page 29: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

CGI Scanning

• allinurl:/random_banner/index.cgi

• Visit http://johnny.ihackstuff.com and see tons of golden query

Page 30: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Auto tools

• Gooscan

• Googledorks

• GooPot

• Write yourself using API

Page 31: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

How to prevent hack using

Page 32: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Protect yourself

• Don’t use Opera !

• Keep your sensitive data off the web!

– SSH/SFTP/SSL…

– Encrypted email (PPG,…)

• Removing your site from

• Use a robots.txt file

Page 33: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

… Protect yourself

• Googledork

– Try hack yourself !

• Change error and test pages

• Disable directory listing

• Update and patch

• Setup Honey Pot

Page 34: Hacking Borhan Kazimi pour. Agenda How to hack How to hack using How to prevent hack using.

Thanks to

And You