<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Web Review &#187; hack</title>
	<atom:link href="http://www.raneri.it/blog/eng/index.php/tag/hack/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.raneri.it/blog/eng</link>
	<description>A blog by Riccardo Raneri</description>
	<lastBuildDate>Wed, 14 Jul 2010 10:59:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>How to hack hundreds of websites with a single Google search</title>
		<link>http://www.raneri.it/blog/eng/index.php/2008/11/07/how-to-hack-hundreds-of-websites-with-a-single-google-search/</link>
		<comments>http://www.raneri.it/blog/eng/index.php/2008/11/07/how-to-hack-hundreds-of-websites-with-a-single-google-search/#comments</comments>
		<pubDate>Fri, 07 Nov 2008 15:08:52 +0000</pubDate>
		<dc:creator>riccardo</dc:creator>
				<category><![CDATA[Tricks]]></category>
		<category><![CDATA[hack]]></category>

		<guid isPermaLink="false">http://riccardo.raneri.it/blog/eng/?p=210</guid>
		<description><![CDATA[Disclaimer:
This post doesn&#8217;t want to be an invite to hack websites. The admin pages linked by search engines in the &#8220;search suggestions&#8221; in the article are so easy to find that it&#8217;s, I think, exagerated to define this an &#8220;hack practice&#8221; (infact, many of them were already hacked and spammed by automatic bots   [...]]]></description>
			<content:encoded><![CDATA[<blockquote style="font-size:11px; line-height:13px;"><p><strong>Disclaimer:<br />
</strong>This post doesn&#8217;t want to be an invite to hack websites. The admin pages linked by search engines in the &#8220;search suggestions&#8221; in the article are so easy to find that it&#8217;s, I think, exagerated to define this an &#8220;hack practice&#8221; (infact, many of them were already hacked and spammed by automatic bots <img src='http://www.raneri.it/blog/eng/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  ). On the contrary, it wants to be an advice to webmasters and sysadmins to double-check their installations and security measures.</p></blockquote>
<p>Search engines scan the Web. The <em>entire</em> web, and they often discover something that nobody should see.</p>
<p>This is one of this cases: a webmaster forgets to password-protect the folder where a critical admin tool like <a href="http://en.wikipedia.org/wiki/PhpMyAdmin" target="_blank"><strong>phpMyAdmin</strong></a> is, a search engine reaches the folder and it puts in its search index the link.</p>
<p><img class="alignleft size-medium wp-image-211" title="yahoo-hacker" src="http://riccardo.raneri.it/blog/eng/wp-content/uploads/2008/11/yahoo-hacker-300x225.png" alt="" width="240" height="180" />At this point it&#8217;s easy for everyone to discover these security breaches: with <strong><a href="http://search.yahoo.com/search?p=phpmyadmin+%22please+select+a+database%22+%22root%40localhost%22&amp;fr=yfp-t-501&amp;toggle=1&amp;cop=mss&amp;ei=UTF-8" target="_blank">a very simple search on a search engine like Yahoo!</a></strong> you&#8217;ll get 196 results (November, 7th 2008), they bring to the administrative home page of phpMyAdmin from several domains, with root privileges.<span id="more-210"></span></p>
<p>The <a href="http://www.google.com/search?hl=en&amp;q=phpmyadmin+%22please+select+a+database%22+%22root%40localhost%22&amp;btnG=Google+Search&amp;aq=f&amp;oq=" target="_blank">same search on Google</a> brings 286 results, <a href="http://search.live.com/results.aspx?q=phpmyadmin+%22please+select+a+database%22+%22root%40localhost%22&amp;go=&amp;form=QBLH" target="_blank">Live Search other 113</a> and so on, you&#8217;ve only to test other search engines to gain new opened phpMyAdmin page.</p>
<p><!--adsense--></p>
<p>This (phpMyAdmin) is only an example: there are a lot of other &#8220;magic words&#8221; you can try to search around, to discover that, while developers try to fix also the smallest security bug in their softwares every day, there are a lot of sysadmin that leave the door completely open for everyone.</p>
<p>Do you want to suggest some other search? <img src='http://www.raneri.it/blog/eng/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.raneri.it/blog/eng/index.php/2008/11/07/how-to-hack-hundreds-of-websites-with-a-single-google-search/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
