Some interesting stuff is shown here that you can do with the Google search box, from basic things like math to down right scary stuff like find someone’s tax return or network password. I don’t think most know how far Google is capable of indexing and just don’t know what they are leaving open…perhaps even Google themselves. I was astonished to (easily) find what I could preparing this post.
After my presentation at the Skookum Tech Talks someone asked me about the hackability/indexability of the popular file storage service, DropBox. I’ve not heard anything related to this Google hack topic and them, but was just thinking that I added my tax folder to my dropbox. Although kind of fatalistically, the more I find out about online security seems like if someone who knows what they are doing really wants to get you then it’s game over. So bottom line, be nice to each other, follow the security stuff as best as you can…life is too short to worry all these details.
I didn’t get to most of the juicy stuff at the end, I only have 5 minutes for the audio/video. Perhaps that was a good thing for fear of showing you too much…but for those that are interested, here’s some more of juicier tidbits:
- http://goo.gl/7K9WY
Use this search to find FTP servers that have been indexed. Being that most people I assume don’t think Google indexes FTP servers (Yale included), they aren’t as concerned about what information goes up on them. Just think outside the box and try combos of commonly used words on tax returns or how people would request social security numbers. Doesn’t take much thought to reveal some extremely sensitive information. - http://goo.gl/gkyAo
This was an instance of someone hacking into Google Webmaster Tools and showing how you can remove a site from the Google index. This was quickly fixed but shows the power here if you choose to look just below the surface. - http://goo.gl/3pTnB
Kind of scary to reveal that there are this many but this is a list of websites that have uploaded their VPN/network passwords on their server. Kind of mind numbing that there are so many results for this particular type of network. Supposedly, this is a way that many LulzSec and Anonymous users hide their location. By tunneling into others networks and computers they leave a very difficult trail to follow and hide where they are actually entering the net from. - The bullet titled Bowling just refers to the aggressiveness that Google has taken recently to police sites receiving links from spammy/gray area link farms and networks. The assumption here (although unproven to my knowledge) is that you could sign your competitors up for one of these spamy link farms and move them from #1 to result #382.
- Last part titled ‘phpbb’ references a popular forum that is commonly outdated, thus vulnerable. However, PPC (porn, pills, and casinos) SEOers don’t just take down the site or load malware onto it, they use the site’s link juice and further build up their own link popularity, thus increasing their rankings for competitive words in Google. Just do some creative searches (on your home computer!) related to PPC and phpbb…you’ll get all kinds of interesting results.

My-my-my-my search engine sucks hard