Gooscan - Automated Google Hacking Tool

news/2025/2/25 19:08:32

Whilst reading an article the other day I saw this mentioned and realised I haven’t written about this yet either, although I have written about the similar tool Goolag.

What is Gooscan?

Gooscan is a tool that automates queries against Google search appliances, but with a twist. These particular queries are designed to find potential vulnerabilities on web pages. Think “cgi scanner” that never communicates directly with the target web server, since all queries are answered by a Google appliance, not by the target itself.

 

 

Who is it written for?

Security professionals: This tool serves as a front-end for an external web server assessment and aids in the “information gathering” phase of a vulnerability assessment.

Web server administrators: This tool helps to discover what the web community may already know about you thanks to Google.

Is this tool legal?

From Google ToS - “You may not send automated queries of any sort to Google’s system without express permission in advance from Google.”

This means that you should not use this tool to query Google without advance express permission. Google appliances, however, do not have these limitations. You should, however, obtain advance express permission from the owner or maintainer of the Google appliance before searching it with
any automated tool for various legal and moral reasons.

 

 

The author wrote this tool not to violate Google’s terms of service (ToS), but to raise the awareness of the web security community that a ToS may not discourage the bad guys from writing and running a tool like this for malicious purposes. To that end, only use this tool to query _appliances_ unless you are prepared to face the (as yet unquantified) wrath of Google.

Why the proxy feature?

Many companies can only reach the Internet by way of an internal proxy server. When conducting an authorized assessment, it may be necessary to bounce queries of of a web proxy instead of off the Google appliance directly.

You can download Gooscan v1.0 here:

Gooscan v1.0

转载于:https://www.cnblogs.com/Safe3/archive/2009/01/04/1367847.html


http://www.niftyadmin.cn/n/674658.html

相关文章

参股券商 ST板块有“黄金”

近期市场投资者对来自于政策面的担心较为明显,周三两市大盘也因此出现了大幅振荡的走 势,上证综指盘中最大跌幅达100余点,尾市报收于4181.32点。在昨日的盘面中,个股普跌的特征较为明显,部分前期涨幅较大的中价股品种杭…

Palm Pre

Palm公司是我非常尊敬的一家公司。 早在6年前,我就开始Fan他们的产品。在当时,能有个大点的屏幕看点电子书,甚至能够通过蓝牙啥的上下网,就是非常了不起的产品了。那个年代,大家流行用的是T39 Palm来上网。 当年&…

存储器、运算器、控制器基本结构以及一条指令的执行

Abstract:此篇文章讲述的是计算机存储器、控制器、运算器的基本结构组成以及指令的具体执行顺序。 CPU包括运算器和控制器, 而主机主要包括CPU和存储器。 内容参考于:哈工大计算机组成原理(刘宏伟) 存储器的基本组成…

用javascript检测浏览器是否是遨游(Maxthon)浏览器

最近使用一个js的弹出菜单效果,发现在傲游浏览器上对contextmenu事件的执行有些异常。 于是想对傲游浏览器做检测以便作出不同处理。可是遍历网上检查浏览器的代码,都是userAgent,而遨游和IE的userAgent是一样的,检查不出来。 很多…

SharePoint 2010开发实例精选——可排序的搜索核心结果

虽然对于信息工作者来说SharePoint 2010开箱即用的搜索界面已经非常直观并易用,但作为超级用户仍然可以创建属于自己的搜索体验。SharePoint Server 2010包括了许多与搜索相关的强大的Web部件,用于支持超级用户定制搜索体验,包括搜索最佳匹配…

同时使用有线网上内网、无线网上外网

要想同时使用有线网上内网、无线网上外网,可编写bat文件,并在cmd中执行: route delete 0.0.0.0 route add 0.0.0.0 mask 0.0.0.0 192.168.1.1 route add 10.13.4.0 mask 255.255.255.0 10.122.2.1 其中192.168.1.1为无线网网关,1…

如何注册自己的公司

投资咨询 我们为客户提供的咨询服务基本流程为: 1、电话咨询:客户来电询问有关设立公司法规、政策、手续、流程、注意事项等。我们提供免费咨询。 2、网上咨询:客户可以通过网上交流平台咨询公司注册基本事宜。 3、面谈详情:根据…

系统总线(一)

Abstract:以下内容参考于:哈工大计算机组成原理(刘宏伟) ------------------------------------------------------------------------------------------------- 本篇博客讲述的几个问题: 1, 为什么需要…