Kali Linux on Stick

Kali Linux on USB Stick has over 600 preinstalled penetration-testing programs. It includes Armitage (a graphical cyber attack management tool). Nmap (a port scanner), Wireshark (a packet analyzer) & John the Ripper password cracker. Aircrack-ng (a software suite for penetration-testing wireless LANs). Burp suite and OWASP ZAP web application security scanners. Kali Linux can run natively when installed on a computer’s hard disk. It can be booted from a live CD or live USB. It can run within a virtual machine. It is a supported platform of the Metasploit Project‘s Metasploit Framework. It is a tool for developing and executing security exploits.”

Google Hacking introduction & Working with Search operators

Anyone who has ever been online must have heard of the search engine “Google”. In case you didn’t knew, it is also the one of the most visited website since the last few years.

Apart from its normal usage to layman, it also serves as an important tool for hackers to find out secret information and vulnerabilities, in products, through which they can get in. It can be used to get Credit Card Information, Server Versions, Login Panels, Usernames and passwords, sensitive files and much other useful stuff.  It could also be used to find web applications exposed to a particular vulnerability.

Also, let me tell you that Google Hacking has nothing to do with hacking “Google” website or its database servers. It is all just about using Google in a way, so as to reveal the hidden information.

Google Dorks, or the specialized search queries, is used to get important and sensitive information using Google. It is done using the help of Google’s Advanced Search operators.

Before going into the details of hacking using Google, let’s have a look at the Google Search Operators.

Google Search Operators

Given below are some of the advanced search operators useful from a security point of view.

  • Using quotes is to indicate Google to search for exact queries inside the quotes
site: To restrict the search results to only a particular website or domain

Syntax: site:monster.com “Information Security”

filetype(or ext): To restrict the search results to only a particular file extension.

Syntax: ext:pdf “Making money”

The file extension should be written without a dot(.). For instance, if you are looking for file formats with .pdf extension, your search should be ext:pdf instead of ext:.pdf .

intitle: To restrict the search results to webpages with only the specified title
Syntax: intitle:”Administrator Area”

inurl: To restrict the search results to webpages having the given query in the URL
Syntax : inurl:login.php

intext: To restrict the search to webpages with having the query in their page’s content
Syntax : intext:Username