<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Dr. Ali Jahangiri</title>
	<atom:link href="http://alijahangiri.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://alijahangiri.org</link>
	<description>Information Security Expert &#38; Cyber Forensic Consultant</description>
	<lastBuildDate>Thu, 09 Feb 2012 15:46:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Practical Ethical Hacking Workshop in Kuala Lumpur</title>
		<link>http://alijahangiri.org/2012/02/practical-ethical-hacking-workshop-in-kuala-lumpur/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=practical-ethical-hacking-workshop-in-kuala-lumpur</link>
		<comments>http://alijahangiri.org/2012/02/practical-ethical-hacking-workshop-in-kuala-lumpur/#comments</comments>
		<pubDate>Thu, 09 Feb 2012 15:46:30 +0000</pubDate>
		<dc:creator>ali jahangiri</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Ali Jahangiri]]></category>
		<category><![CDATA[Dr. Ali Jahangiri]]></category>
		<category><![CDATA[Ethical Hacking]]></category>
		<category><![CDATA[IT Security Workshop]]></category>

		<guid isPermaLink="false">http://alijahangiri.org/?p=202</guid>
		<description><![CDATA[Two day case study based ethical hacking workshop titled“Data Insecurity Workshop” to take place on February 13th to 15th at Maya hotel. Dr. Ali Jahangiri, an information security and ethical hacking expert, is pleased to announce the Data Insecurity Workshop 2012 Malaysia. This unique ethical hackers training course uses real-world case studies and hands-on practical [...]]]></description>
			<content:encoded><![CDATA[<p>Two day case study based ethical hacking workshop titled“Data Insecurity Workshop” to take place on February 13th to 15th at Maya hotel.</p>
<p>Dr. Ali Jahangiri, an information security and ethical hacking expert, is pleased to announce the Data Insecurity Workshop 2012 Malaysia. This unique ethical hackers training course uses real-world case studies and hands-on practical sessions, making this information security workshop like no other.</p>
<p>This practical, case study based workshop is designed to introduce IT professionals to the world of hacking and information security and give them the knowledge they need to thwart the criminal elements in cyberspace. Using real world examples this course will teach attendees the truth about domain hijacking, denial of service attacks, how to abuse SSH enabled servers and how to hack Windows in just 10 seconds!</p>
]]></content:encoded>
			<wfw:commentRss>http://alijahangiri.org/2012/02/practical-ethical-hacking-workshop-in-kuala-lumpur/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Forensic Workshop &#8211; Singapore</title>
		<link>http://alijahangiri.org/2012/01/cyber-forensic-workshop-singapore-2/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cyber-forensic-workshop-singapore-2</link>
		<comments>http://alijahangiri.org/2012/01/cyber-forensic-workshop-singapore-2/#comments</comments>
		<pubDate>Sun, 01 Jan 2012 17:04:34 +0000</pubDate>
		<dc:creator>ali jahangiri</dc:creator>
				<category><![CDATA[Testimonials]]></category>
		<category><![CDATA[Ali Jahangiri]]></category>
		<category><![CDATA[Cyber Forensic Workshop]]></category>

		<guid isPermaLink="false">http://alijahangiri.org/wp/?p=106</guid>
		<description><![CDATA[Dr Ali is one of the trainers I have come across who has vast knowledge and experience in dealing with computer related offences. It was an honor meeting him. Serupepeli Neiko, Fiji Police Force]]></description>
			<content:encoded><![CDATA[<p>Dr Ali is one of the trainers I have come across who has vast knowledge and experience in dealing with computer related offences. It was an honor meeting him.</p>
<p>Serupepeli Neiko, Fiji Police Force</p>
]]></content:encoded>
			<wfw:commentRss>http://alijahangiri.org/2012/01/cyber-forensic-workshop-singapore-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ultimate Live Hacking Master Class &#8211; South Africa</title>
		<link>http://alijahangiri.org/2011/01/ultimate-live-hacking-master-class-south-africa/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ultimate-live-hacking-master-class-south-africa</link>
		<comments>http://alijahangiri.org/2011/01/ultimate-live-hacking-master-class-south-africa/#comments</comments>
		<pubDate>Sat, 01 Jan 2011 17:01:14 +0000</pubDate>
		<dc:creator>ali jahangiri</dc:creator>
				<category><![CDATA[Testimonials]]></category>
		<category><![CDATA[Ali Jahangiri]]></category>
		<category><![CDATA[Ultimate Live Hacking]]></category>

		<guid isPermaLink="false">http://alijahangiri.org/wp/?p=102</guid>
		<description><![CDATA[It was my pleasure to be one of students in a class of Ultimate live Hacking Master Class in South Africa. To my best of my knowledge it was very Educational and Skills transfer in the world of technology. Thanks Dr Ali Jahangiri for your best skills and you have open up our eyes and [...]]]></description>
			<content:encoded><![CDATA[<p>It was my pleasure to be one of students in a class of Ultimate live Hacking Master Class in South Africa. To my best of my knowledge it was very Educational and Skills transfer in the world of technology. Thanks Dr Ali Jahangiri for your best skills and you have open up our eyes and make us see what is happening in today world.</p>
<p>Richard Kwenda &#8211; Namibia Ministry of Home Affairs &amp; Immigration</p>
]]></content:encoded>
			<wfw:commentRss>http://alijahangiri.org/2011/01/ultimate-live-hacking-master-class-south-africa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Future of Cybercrime Forensics</title>
		<link>http://alijahangiri.org/2010/09/the-future-of-cybercrime-forensics/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-future-of-cybercrime-forensics</link>
		<comments>http://alijahangiri.org/2010/09/the-future-of-cybercrime-forensics/#comments</comments>
		<pubDate>Wed, 01 Sep 2010 11:48:15 +0000</pubDate>
		<dc:creator>ali jahangiri</dc:creator>
				<category><![CDATA[Featured Papers]]></category>
		<category><![CDATA[Ali Jahangiri]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber forensic]]></category>
		<category><![CDATA[opinion]]></category>

		<guid isPermaLink="false">http://alijahangiri.org/wp/?p=172</guid>
		<description><![CDATA[Cybercrime Forensic investigation is a complicated science with its own history, implications and future. It is not sufficient merely to consider it a branch of criminology, or the study of cyber criminal behavior, or research into the relationship between the causes of tech related crime and social policies. For cyber criminals, their knowledge and their [...]]]></description>
			<content:encoded><![CDATA[<p>Cybercrime Forensic investigation is a complicated science with its own history, implications and future. It is not sufficient merely to consider it a branch of criminology, or the study of cyber criminal behavior, or research into the relationship between the causes of tech related crime and social policies. For cyber criminals, their knowledge and their crimes are bound together. The possible suspects are rich in knowledge and technical skills. They have mastered the technology better than the technology’s creators, and they know how to use technology against technology.</p>
<p>A multidisciplinary approach is required to fully foresee the future of cybercrime forensics. It requires a team of specialists from different disciplines within the IT industry and related industrial and social segments such as telecom and law. However, in this article the author looks at the future of cybercrime forensics based on his knowledge and experience in this field.</p>
<p><strong>Cybercrime Forensics for Governments</strong></p>
<p>Cybercrime forensics at the governmental level will be more complicated in the future. Governments will need to turn more to their national security organisations to hunt down cyber criminals. In addition, they will need to invent anti-forensic tools and methods to keep their activities and information assets secret.</p>
<p>Cyberspace security and computer related technologies will be a real challenge for governments. The platforms and protocols for computer related technologies may have both domestic and international uses. Therefore, it will be difficult for governments to reach an agreement for international cyber security policies.</p>
<p>At the same time, some countries are the technology owners and this intellectual property ownership will give them an advantage compared to other countries without such a privilege. The technology ownership issue will force the other countries to utilise the open source platforms to develop their own customised operating systems and software.</p>
<p><strong>Cybercrime Forensics for</strong><strong> Corporates</strong><strong> </strong></p>
<p>Currently the cybercrime forensic markets have been dominated by a few companies. These are the pioneers in cybercrime forensics and analysis. They have the tools and the solutions for cyber forensic investigation. They train law enforcement agencies to use their tools and solutions and some of them even have special tools just for governmental use.</p>
<p>There are also many small companies with one or two consultant partners who are either retired law enforcement officers or former IT professionals from Fortune 500 companies. These people use their contacts and credentials to achieve some market share.  However, in the future, cybercrime forensics at the corporate level will be diversified to education and certain specialties and products. It will be difficult for small companies to build a team with the right core competencies. In addition, due to security clearance requirements and national security interests, most of these companies will only practice in their country of origin.</p>
<p>Furthermore, information security standards such as ISO27001 and ITIL will be implemented more in medium to enterprise size companies. Realistically, only these companies can afford the cost of compliance implementation. Therefore, it will be necessary for them to have proper incident response procedures and the corresponding cyber forensic investigation capabilities. These companies may well have their own cyber forensic investigation units.</p>
<p>&nbsp;</p>
<p><strong>Cybercrime Forensics in Professional Institutions</strong></p>
<p>Cybercrime forensics is a new battle ground for professional institutions. Currently, there is no real internationally recognised authority to govern cybercrime forensics practices, regulations and certification.  Therefore, professional institutions are offering cybercrime forensic investigation training programs, certifications and conferences. Currently, some of these institutions are forming alliances (as trade and training partners) to achieve their sales targets. In the future, it is likely that these institutions will start to attack each other to gain market share.</p>
<p><strong>Cybercrime Forensics in Universities</strong></p>
<p>It is sad to note that more and more often information technology advances are coming from industry rather than universities. Within IT, a few companies dominate the industry and therefore the innovations. It will be the same for cybercrime forensics; the companies with market share have the money for research and development. The main issue with academic institutions is their approach, which is slow and traditional compared to the faster speed of development and implementation found in industry.</p>
<p>Furthermore, the training programs in universities are not aligned with the current job market and industry needs. The university students have a lack of practical knowledge compared to the IT professionals who are in the industry (and possibly without academic studies). This is the major reason why students choose further training to achieve professional certification and so distinguish themselves from other graduates.</p>
<p><strong>Cybercrime Forensics in the Media</strong></p>
<p>There will be more magazines, websites and blogs specialising in cybercrime forensics and analysis. They will be the voice of the industry with the power to review, promote and criticise books, products, solutions and training programs. They will sell advertising and help vendors sell their products. Whoever has more marketing budget and better relations will be the most successful in the cybercrime forensics industry. Nevertheless, there will be one or two magazines and websites that will remain independent, but they will find it difficult to survive in such a tough market.</p>
<p><strong>Cybercrime Forensics and Technical Trends</strong></p>
<p>The market will be divided to four main segments with specialised service providers for each segment. The segments are: Microsoft Windows related products, UNIX &amp; Linux related products, Apple related products and computer network &amp; telecom related products.</p>
<p>The solution providers will create more comprehensive tools and solutions to gain better market share. They will transform their solutions into a set of tools for non-IT professionals. They will also try to make their tools web based, for remote forensic investigations.</p>
<p>The open source community will be active for the UNIX &amp; Linux platforms to accrue required legislation to accredit the open source tools in the various countries and judicial systems.</p>
<p>Apple created a giant market for those who want to develop Apple device related tools and solutions. This will be a new era for the professionals who are working in cybercrime forensics.</p>
<p>Cloud computing, cellular networks, WiMax and virtualization will be the other areas of the interest for study and product development. It is obvious that everything is merging towards IT and cyberspace plays an important role in the near future. This will lead governments and authorities to pursue other methods of intelligence gathering, such as web and data mining, to protect their interests.</p>
<p>This will lead to the biggest privacy issue in history. All the data communication, of all users, will be logged at the carrier level. Then the authorities will use data mining tools to identify suspicious behavior of a particular user or users in their own or an allies’ territory. All this information will be saved in massive databases and then the commercial, financial and personal information, in addition to the communication records and social behaviors, will be linked together.</p>
<p>And this will ultimately lead to a new chapter in the history of cybercrime forensics, namely Applied Artificial Intelligence in Cybercrime Forensics.</p>
]]></content:encoded>
			<wfw:commentRss>http://alijahangiri.org/2010/09/the-future-of-cybercrime-forensics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ultimate Live Hacking &amp; Countermeasures Master Class &#8211; Dubai</title>
		<link>http://alijahangiri.org/2010/07/ultimate-live-hacking-countermeasures-master-class-dubai/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ultimate-live-hacking-countermeasures-master-class-dubai</link>
		<comments>http://alijahangiri.org/2010/07/ultimate-live-hacking-countermeasures-master-class-dubai/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 17:19:00 +0000</pubDate>
		<dc:creator>ali jahangiri</dc:creator>
				<category><![CDATA[Testimonials]]></category>
		<category><![CDATA[Ali Jahangiri]]></category>
		<category><![CDATA[Ultimate Live Hacking]]></category>

		<guid isPermaLink="false">http://alijahangiri.org/wp/?p=129</guid>
		<description><![CDATA[I have attended the live hacking workshop for 3 days by Dr. Ali Jahangiri, and it was amazing. Abdulla A Yousif, Dubai Municipality]]></description>
			<content:encoded><![CDATA[<p>I have attended the live hacking workshop for 3 days by Dr. Ali Jahangiri, and it was amazing.</p>
<p>Abdulla A Yousif, Dubai Municipality</p>
]]></content:encoded>
			<wfw:commentRss>http://alijahangiri.org/2010/07/ultimate-live-hacking-countermeasures-master-class-dubai/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ultimate Live Hacking &amp; Countermeasures Master Class, South Africa</title>
		<link>http://alijahangiri.org/2010/04/ultimate-live-hacking-countermeasures-master-class-south-africa-2/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ultimate-live-hacking-countermeasures-master-class-south-africa-2</link>
		<comments>http://alijahangiri.org/2010/04/ultimate-live-hacking-countermeasures-master-class-south-africa-2/#comments</comments>
		<pubDate>Thu, 01 Apr 2010 17:17:56 +0000</pubDate>
		<dc:creator>ali jahangiri</dc:creator>
				<category><![CDATA[Testimonials]]></category>
		<category><![CDATA[Ali Jahangiri]]></category>
		<category><![CDATA[Ultimate Live Hacking]]></category>

		<guid isPermaLink="false">http://alijahangiri.org/wp/?p=127</guid>
		<description><![CDATA[It was a pleasure to be part of the workshop. I am now equipped with knowledge and understanding on how easily the intruders can sneak and destroy the networks. The important part is, it is now easy to detect and take care of vulnerabilities within our network. Thank you Dr Ali for your kindness. Jane [...]]]></description>
			<content:encoded><![CDATA[<p>It was a pleasure to be part of the workshop. I am now equipped with knowledge and understanding on how easily the intruders can sneak and destroy the networks. The important part is, it is now easy to detect and take care of vulnerabilities within our network.</p>
<p>Thank you Dr Ali for your kindness.</p>
<p>Jane Qobolo, Department of Civil Aviation</p>
]]></content:encoded>
			<wfw:commentRss>http://alijahangiri.org/2010/04/ultimate-live-hacking-countermeasures-master-class-south-africa-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ultimate Live Hacking &amp; Countermeasures Master Class &#8211; South Africa</title>
		<link>http://alijahangiri.org/2010/03/ultimate-live-hacking-countermeasures-master-class-south-africa/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ultimate-live-hacking-countermeasures-master-class-south-africa</link>
		<comments>http://alijahangiri.org/2010/03/ultimate-live-hacking-countermeasures-master-class-south-africa/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 17:16:50 +0000</pubDate>
		<dc:creator>ali jahangiri</dc:creator>
				<category><![CDATA[Testimonials]]></category>
		<category><![CDATA[Ali Jahangiri]]></category>
		<category><![CDATA[Ultimate Live Hacking]]></category>

		<guid isPermaLink="false">http://alijahangiri.org/wp/?p=125</guid>
		<description><![CDATA[The course was indeed master class, an eye opener and very necessary for every corporate environment. Christopher Mwale, Zamabia National Commercial Bank]]></description>
			<content:encoded><![CDATA[<p>The course was indeed master class, an eye opener and very necessary for every corporate environment.</p>
<p>Christopher Mwale, Zamabia National Commercial Bank</p>
]]></content:encoded>
			<wfw:commentRss>http://alijahangiri.org/2010/03/ultimate-live-hacking-countermeasures-master-class-south-africa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ultimate Live Hacking &amp; Countermeasures Master Class, South Africa 2010</title>
		<link>http://alijahangiri.org/2010/03/ultimate-live-hacking-countermeasures-master-class-south-africa-2010/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ultimate-live-hacking-countermeasures-master-class-south-africa-2010</link>
		<comments>http://alijahangiri.org/2010/03/ultimate-live-hacking-countermeasures-master-class-south-africa-2010/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 17:15:30 +0000</pubDate>
		<dc:creator>ali jahangiri</dc:creator>
				<category><![CDATA[Testimonials]]></category>
		<category><![CDATA[Ali Jahangiri]]></category>
		<category><![CDATA[Ultimate Live Hacking]]></category>

		<guid isPermaLink="false">http://alijahangiri.org/wp/?p=123</guid>
		<description><![CDATA[After the training, I&#8217;m now able to think outside the box! Ignatius Farirayi, Econet Wireless]]></description>
			<content:encoded><![CDATA[<p>After the training, I&#8217;m now able to think outside the box!</p>
<p>Ignatius Farirayi, Econet Wireless</p>
]]></content:encoded>
			<wfw:commentRss>http://alijahangiri.org/2010/03/ultimate-live-hacking-countermeasures-master-class-south-africa-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Hacking</title>
		<link>http://alijahangiri.org/2010/01/google-hacking/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-hacking</link>
		<comments>http://alijahangiri.org/2010/01/google-hacking/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 16:20:47 +0000</pubDate>
		<dc:creator>ali jahangiri</dc:creator>
				<category><![CDATA[Featured Papers]]></category>
		<category><![CDATA[Ali Jahangiri]]></category>
		<category><![CDATA[google hacking]]></category>
		<category><![CDATA[Google Hacking Database]]></category>

		<guid isPermaLink="false">http://alijahangiri.org/wp/?p=43</guid>
		<description><![CDATA[Abstract: Google hacking is the term used when a hacker tries to find vulnerable targets or sensitive data by using the Google search engine. In Google hacking hackers use search engine commands or complex search queries to locate sensitive data and vulnerable devices on the Internet. What is Google Hacking? Google hacking is the term [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p><strong>Abstract:</strong> Google hacking is the term used when a hacker tries to find vulnerable targets or sensitive data by using the Google search engine. In Google hacking hackers use search engine commands or complex search queries to locate sensitive data and vulnerable devices on the Internet.</p></blockquote>
<p><strong>What is Google Hacking?</strong></p>
<p>Google hacking is the term used when a hacker tries to find vulnerable targets or sensitive data by using the Google search engine. In Google hacking hackers use search engine commands or complex search queries to locate sensitive data and vulnerable devices on the Internet.</p>
<p>Although Google hacking techniques are against Google <a href="http://www.google.com/accounts/TOS" target="_blank">terms of service</a> and Google blocks well-known Google hacking queries, nothing can stop hackers from crawling websites and launching Google queries.</p>
<p>Google hacking can be used to locate vulnerable web servers and websites which are listed in the Google search engine database. In other words, hackers can locate many thousands of vulnerable websites, web servers and online devices all around the world and select their targets randomly. This kind of attack is most commonly launched by applying Google hacking techniques to satisfy junior hackers.</p>
<p>It is obvious that the Google hacking procedure is based on certain keywords, which could be used effectively if they are used by some internal commands of the Google search engine. These commands can be used to help hackers narrow down their search to locate sensitive data or vulnerable devices.</p>
<p>Nevertheless, the success of Google hacking techniques depends on the existence of vulnerable sites, servers and devices. However, we should not ignore the power of the search engines in providing information about the targets to the hackers in the reconnaissance phase.</p>
<p><strong>Beyond Vulnerability</strong></p>
<p>Malicious hackers can use Google hacking techniques to identify vulnerable sites and web servers for known vulnerabilities. In addition, they can look for error pages with the help of technical information or retrieve files and directories with sensitive contents such as databases, passwords, log files, login pages or online devices such as IP cameras and network storage.</p>
<p><strong>Google Proxy</strong></p>
<p>Hackers can use the Google Translate service (<a href="http://translate.google.com/translate_t" target="_blank">http://translate.google.com/translate_t</a>) as a proxy server to visit a website or translate the contents of the website or URLs without leaving any footprints.</p>
<div id="attachment_46" class="wp-caption aligncenter" style="width: 510px"><a href="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-11.png"><img class="size-full wp-image-46 " title="Google-hacking (1) ali jahangiri" src="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-11.png" alt="Figure 1: Google Translate Service." width="500" height="295" /></a><p class="wp-caption-text">Figure 1: Google Translate Service.</p></div>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Google Cache</strong></p>
<p>Google copies the content of a website in its database. This function helps users to access the content of the website if the site is not available. However, a hacker can use this function to access and visit a targeted website without leaving any footprint and in complete anonymity.</p>
<div id="attachment_45" class="wp-caption aligncenter" style="width: 510px"><a href="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-10.png"><img class="size-full wp-image-45 " title="Google-hacking" src="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-10.png" alt="Figure 2: The red cycle indicates the link to access the Cached page. " width="500" height="295" /></a><p class="wp-caption-text">Figure 2: The red cycle indicates the link to access the Cached page.</p></div>
<p><strong>Directory Listings</strong></p>
<p>Web server applications such as Apache and IIS provide facilities that a user can browse and navigate website directories by clicking on the directory name and links such as Parent Directories. The directories and their content can be listed if directory listing or directory browsing are enabled by the administrator. This vulnerability gives an unauthorized access to the files and it may help hackers to gain access to the information which can help them to hack a website or a web server or download its contents.</p>
<div id="attachment_49" class="wp-caption aligncenter" style="width: 510px"><a href="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-2.png"><img class="size-full wp-image-49" title="Google-hacking (2)" src="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-2.png" alt="Figure 3: The result of using intitle:index.of “Parent Directory”." width="500" height="301" /></a><p class="wp-caption-text">Figure 3: The result of using intitle:index.of “Parent Directory”.</p></div>
<p>Directory listings make the parent directory links available to browse directories and files. Hackers can locate the sensitive information and files just by simple browsing. In Google it is easy to find websites or web servers with enabled directory listings because the title of the pages start with the “index of” phrase so we can use index of in the search box to find the directory listings-enabled website. If we want to get better result from our search we can use this combination in the search box intitle:index.of or we can use intitle:index.of “Parent Directory”.</p>
<p>It is obvious that with the first command we used the Google search engine to search in its database for the websites which have been listed with the title of “Index of”. In the second command we used Google to search for sites with the directory listings and with the keyword which is often found in the directory listings.</p>
<p><strong>Specific Directory</strong></p>
<p>Hackers can locate specific directories by using the directory name in their search queries. For instance to locate an “admin” directory in addition to directory listings, the hacker can use these commands: intitle:index.of.admin or intitle:index.of inurl:admin.</p>
<div id="attachment_50" class="wp-caption aligncenter" style="width: 510px"><a href="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-3.png"><img class="size-full wp-image-50" title="Google-hacking (3)" src="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-3.png" alt="Figure 4: The result of using intitle:index.of.admin." width="500" height="306" /></a><p class="wp-caption-text">Figure 4: The result of using intitle:index.of.admin.</p></div>
<p><strong>Specific File</strong></p>
<p>It is possible to search for a certain file by directory listings. For instance, to search for the password.mdb file, this search query can be used: intitle:index.of password.mdb .</p>
<p><strong>Specific File Extension</strong></p>
<p>Google lets users search its database for a specific file extension by using the filetype: command. For instance, if you want to search for pdf files, then you can use the query filetype:pdf in the search box.</p>
<p><strong>Server Information</strong></p>
<p>It is possible to use Google hacking techniques to determine the version of the web server application along with directory listings. This kind of information is vital to an attacker because it will help him or her to use the best way to attack the web server. For instance, hackers can use the search query intitle:index.of &#8220;server at&#8221; to find the web sites with vulnerable directory listings which are operated by an Apache server.</p>
<div id="attachment_51" class="wp-caption aligncenter" style="width: 510px"><a href="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-5.png"><img class=" wp-image-51 " title="Google-hacking (5)" src="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-5.png" alt="Figure 5: The result of intitle:index.of &quot;server at&quot;." width="500" height="301" /></a><p class="wp-caption-text">Figure 5: The result of intitle:index.of &quot;server at&quot;.</p></div>
<p>Different versions of Microsoft IIS servers have wide usage all around the world. It would be easy to find the servers which are operated by Microsoft IIS 6.0 servers, which are listed in the Google database by using the query &#8220;Microsoft IIS/6.0 server at&#8221; on the Google search engine.</p>
<p><strong>Error Pages</strong></p>
<p>The error pages and warning pages are informative for hackers because these pages could be used to determine the vulnerability of the target. Most of the time hackers use the error messages as keywords or search phrase to find their targets. For instance, if you use &#8220;Syntax error in query expression &#8221; –the in the Google search box, you can find the websites which have this error message as an Access error message; this message can display path names, function names and filenames which are helpful for the hackers.</p>
<div id="attachment_52" class="wp-caption aligncenter" style="width: 510px"><a href="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-6.png"><img class="size-full wp-image-52" title="Google-hacking (6)" src="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-6.png" alt="Figure 6: The result of &quot;Syntax error in query expression &quot; –the." width="500" height="308" /></a><p class="wp-caption-text">Figure 6: The result of &quot;Syntax error in query expression &quot; –the.</p></div>
<p>Hackers may use Google to locate vulnerable servers by searching for the error pages of web servers such as IIS. The queries intitle:&#8221;the page cannot be found&#8221;and &#8220;internet information services&#8221; can be used to search for IIS servers that present error 404.</p>
<p><strong>Default Pages</strong></p>
<p>Default pages are major sources of information about targets for hackers. They use Google to find live servers which are on the default page; most of the time, these servers have default configurations with many vulnerabilities.</p>
<p><strong>Login Pages</strong></p>
<p>The login pages can be use for brute force attacks and gain unauthorized access to the target. In addition, the login pages can be useful to provide information about the target server. For instance, if we use the search query allinurl:&#8221;exchange/logon.asp&#8221; in the Google search box, we can find the login page of the Microsoft Outlook Web Access.</p>
<p>For the typical login page in the web applications or portals which have been programmed by ASP, you can use inurl:login.asp or inurl:/admin/login.asp.</p>
<div id="attachment_53" class="wp-caption aligncenter" style="width: 510px"><a href="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-7.png"><img class="size-full wp-image-53" title="Google-hacking (7)" src="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-7.png" alt="Figure 7: The result of allinurl:&quot;exchange/logon.asp&quot;." width="500" height="301" /></a><p class="wp-caption-text">Figure 7: The result of allinurl:&quot;exchange/logon.asp&quot;.</p></div>
<p><strong>Locating CGI-BIN</strong></p>
<p>Common Gateway Interface (CGI) is a standard protocol for interfacing external application software with web servers. Hackers can use Google to locate the CGI-BIN applications or pages to target. For instance, the search query inurl:/cgi-bin/login.cgi locates the login pages base on CGI-BIN.</p>
<p><strong>Online Devices</strong></p>
<p>It is possible to create special search phrases to locate online devices such as IP cameras, network storage and printers with Google. In this technique hackers use the default pages or the application names which vendors used for hardware and that have been supplied by vendors.</p>
<p>For instance, if you want to locate AXIS Network cameras then you can apply the search phrase inurl:indexFrame.shtml Axis to find online AXIS cameras. Here is another example: to locate online Linksys network storage with the GigaDrive Utility, you can use the search phrase intitle:&#8221;GigaDrive Utility&#8221; in the Google Search box.</p>
<div id="attachment_54" class="wp-caption aligncenter" style="width: 510px"><a href="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-8.png"><img class="size-full wp-image-54" title="Google-hacking (8)" src="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-hacking-8.png" alt="Figure 8: The result of inurl:indexFrame.shtml Axis." width="500" height="323" /></a><p class="wp-caption-text">Figure 8: The result of inurl:indexFrame.shtml Axis.</p></div>
<p><strong>Google Hacking Database</strong></p>
<p>There is an unofficial website (<a href="http://johnny.ihackstuff.com/ghdb/" target="_blank">http://johnny.ihackstuff.com/ghdb/</a> ) which acts as a database for hacking of Google. This database has been used since its creation in 2004 by the Google hacking community.</p>
<p>You would be able to develop your own Google hacking database by studying the behaviour of the equipment and identifying the pages, page titles and files which can be called and accessed by user and which will be listed in Google.</p>
<p><strong>Disclaimer:</strong></p>
<ul>
<li>This document is to educate, introduce and demonstrate Google hacking. You should not use the information which has been presented in this document for illegal or malicious attacks and you should not use the described techniques in an attempt to compromise any computer system.</li>
<li>Ali Jahangiri operates a policy of continuous development. The information which this document contains reflects his understanding at the time when presented. Ali Jahangiri reserves the right to revise this document or withdraw it at any time without prior notice and states no obligation to update the data included in this document.</li>
<li>The contents of this document are provided &#8220;as is&#8221;. No warranties of any kind, either express or implied, including, but not limited to, the implied warranties of solutions and instructions for a particular purpose, are made in relation to the accuracy, reliability or contents of this document.</li>
<li>Under no circumstances shall Ali Jahangiri be responsible for any loss of data or income or any special, incidental, consequential or indirect damages howsoever caused.</li>
</ul>
<p><a href="http://alijahangiri.org/wp/wp-content/uploads/2012/01/Google-Hacking-by-Ali-Jahangiri.pdf">Download : Google-Hacking-by-Ali-Jahangiri</a></p>
]]></content:encoded>
			<wfw:commentRss>http://alijahangiri.org/2010/01/google-hacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disaster Recovery &amp; Business Continuity Workshop &#8211; Ghana</title>
		<link>http://alijahangiri.org/2009/10/disaster-recovery-business-continuity-workshop-ghana/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=disaster-recovery-business-continuity-workshop-ghana</link>
		<comments>http://alijahangiri.org/2009/10/disaster-recovery-business-continuity-workshop-ghana/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 17:14:08 +0000</pubDate>
		<dc:creator>ali jahangiri</dc:creator>
				<category><![CDATA[Testimonials]]></category>
		<category><![CDATA[Ali Jahangiri]]></category>
		<category><![CDATA[Business Continuity Workshop]]></category>

		<guid isPermaLink="false">http://alijahangiri.org/wp/?p=121</guid>
		<description><![CDATA[The course was very beneficial both for the office and my domestic usage. The facilitator treated some topics which personally I&#8217;ve taken for granted. Also the examples used for the purpose of illustration were very down to earth. Bravo! Evelyn Malm, Bank of Ghana]]></description>
			<content:encoded><![CDATA[<p>The course was very beneficial both for the office and my domestic usage. The facilitator treated some topics which personally I&#8217;ve taken for granted. Also the examples used for the purpose of illustration were very down to earth. Bravo!</p>
<p>Evelyn Malm, Bank of Ghana</p>
]]></content:encoded>
			<wfw:commentRss>http://alijahangiri.org/2009/10/disaster-recovery-business-continuity-workshop-ghana/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

