Articles

Cisco IOS Commands
An Introduction to Computer Security
Pix Configuration Guide
Metasploit Framework Windows Tutorial
Remote Desktop Connection
Windows Processes That May Be Dangerous
How-To use NetCat a Tutorial
Common Linux Commands
Common Ports
Netcat Commands
HTTP Response Codes
War-Google Hack Terms
Wardriving
Avoiding Social Engineering and Phishing Attacks
Intrusion Detection on Linux
Linux Intrusion Detection
Penetration Testing Guide
Penetration Testing Tools
Social Engineering Fundamentals, Part I: Hacker Tactics
Social engineering (computer security)
The Psychology of Social Engineering

The Archives

General GSO
GovernmentSecurity.org News & Suggestions
In The News
Open Topic
General Security Information
Trash Can
Exploit & Vulnerability Mailing List Archives
Trial Member Forum
Product and Program Reviews GSO Tutorials
System Security
Windows Systems
Beginners Section
Linux & Unix Systems
File Downloads
Exploit Research & Discussion Trojan & Virus Errata
Networking Security / Firewall / IDS / VPN / Routers
System Hardening
E-Mail Security
Wifi Security
Trial Member Uploads
Upload discovered Trojans & Mal ware
GSO Programming Section
C , C++ , VC++
Visual Basic.NET
Perl /CGI
Java/Javascript
PHP/XML/ASP/HTML
Assembly + Other
The Cork Board
Network Security Consultant Directory
Network Security Jobs
The Archives
Encryption Information
General Network Security
Internet Anonymity
HTTP Protocol Security
Linux Security
MS IIS Information
Exploit Articles
Programming / Tool Design
GSO Software Projects
Public Downloads
Microsoft Security Questions and Papers

War-Google Hack Terms

Google can be used to enumerate a large number of hosts, to find potential security flaws. The primary danger by using this method is that a target could be cased without the criminal ever touching the target. Experiment using this search terms against your own server.

Google Search Term War-Googling Search Terms
Find similar domains related:<domain|host>
Find links to domain link:<domain|host>
Find information about domain info:<domain|host>
Find matches in URL inurl:<token>
allinurl:<token> [token] ...
Find specific files filetype:<type>
type such as .htaccess, .xls, .doc
Basic searches “password hint”
“password hint –email”
“show password hint –email”
mrtg
bb4 conn
Poor information management
(combine with a hostname or domain
suffix, such as Acme or gov)
“internal use only”
proprietary
confidential
filetype:htaccess old “config password”
Enumerate OWA users inurl:exchange inurl:finduser inurl:root
Passwords “index of” passwd.txt
“index of” etc passwd
Include files include db.inc
include config.inc
XML resources “index of” wsdl
More info http://www.unixlibre.org/listas/bugtraq/0075.html