Go grab my app! Choke on it, you silly bitches.
FOR IMMEDIATE RELEASESECURITY ADVISORY: The following program may screw a large Internet search
engine and make the Web a safer place.LUBBOCK, TX, February 20th -- Today CULT OF THE DEAD COW (cDc), the world's
most attractive hacker group, announced the release of Goolag Scanner, a web
auditing tool. Goolag Scanner enables everyone to audit his or her own web
site via Google. The scanner technology is based on "Google hacking," a form
of vulnerability research developed by Johnny I Hack Stuff. He's a lovely
fellow. Go buy him a drink."It's no big secret that the Web is the platform," said cDc spokesmodel
Oxblood Ruffin. "And this platform pretty much sucks from a security
perspective. Goolag Scanner provides one more tool for web site owners to
patch up their online properties. We've seen some pretty scary holes through
random tests with the scanner in North America, Europe, and the Middle East.
If I were a government, a large corporation, or anyone with a large web site,
I'd be downloading this beast and aiming it at my site yesterday. The v
ulnerabilities are that serious."
Goolag Scanner will be released open source under the GNU Affero General
Public license. It is dedicated to the memory of Wau Holland, founder of the
Chaos Computer Club, and a true champion of privacy rights and social justice.GOOLAG SCANNER FUNCTIONS AND FEATURES
Goolag Scanner is a standalone windows GUI based application. It uses one
xml-based configuration file for its settings. All dorks coming with the
distribution of gS are kept inside one file.
--Press Contact
Oxblood Ruffin
oxblood at hacktivismo.com
Digg does not like me.
Posted by Pawl at 04:54 PM February 21, 2008Goolag likes you...
Posted by rembrandt at 12:33 PM February 22, 2008Well dude.. what's the PW of the rar containing the source code?
And did you guys ever heared about bittorrent? :-p
Posted by Cindy Lou Who at 03:51 PM February 22, 2008
It may would make sense (except of having slow Servers :) )goolag dot org is offline. Anyone have a copy of the program that they can send to me via email at cindylouwho at thebabecams dot com
Posted by KK at 05:32 PM February 22, 2008
Try goolag.net instead; same thing. Torrent coming soon.
Posted by buherator at 11:58 AM February 24, 2008Sorry to say...but I don't find this tool very useful. There are much better vunerability scanners out there, but if I just want to scan the available dorks I could write a simple script which does the job and doesn't require Windows, .NET or anything fancy.
Wake up guys! You can do much much better than this!
Posted by buherator at 12:37 PM February 24, 2008OMG! I just had a look at the gdorks.xml file...Are you serious? Have you ever heard of data structures? This is lame!
Posted by br0d at 07:35 PM February 25, 2008It's very easily useable since it does not require a local proxy like Sensepost Aura but also seems to be still hindered by the google bot captcha problem due to this simplicity...it should probably integrate an API key or something like Aura with Wikto/GHDB...I got blocked in short order.
Posted by quangntenemy at 12:43 AM February 26, 2008A new frontend for GHDB?
Posted by phil at 04:47 AM February 26, 2008Mirror:
Self-extracting .exe (install only):
http://rapidshare.com/files/95037326/Goolag_Scanner_1.0.0.40_Setup.exeFull source distribution:
Posted by Vincent at 01:04 PM February 27, 2008
http://rapidshare.com/files/95037951/GoolagScanner_1.0.0.41.rarHi,
Interesting app.
Don't forget that computer insecurity is everywhere :www.xssed.com/mirror/30220/
Posted by Alex in Taiwan at 12:11 AM February 29, 2008
fuckin CDC~
Posted by YuBou Jian at 10:00 PM March 03, 2008
stupid guy~
CDC sucks~
Goolag sucks~Mother Fucker CDC !!!
Posted by BenjaminTallmadge at 10:41 AM March 04, 2008
Suck my dick~I understand that the Host string is used as the 'site' parameter in the query. I thought that meant you would only find pages on that host URL that had the dork. However, I'm getting successful queries that have URLs that are unrelated to the host I entered. If you go to the url shown in the successful result you can see the dork string but there's nothing about the host on that page.
Posted by Pawl at 01:41 AM March 08, 2008For you folks who can't access goolag.org
look on PacketStormSecurity.org for GoolagScanner 1.0.40
Posted by Pawl at 01:43 AM March 08, 2008
It's a .RAR file with the source and self extracting binary. Enjoy!http://packetstormsecurity.org/filedesc/GS1.0.0.40OfficialRelease.rar.html
Posted by Mykahh at 03:18 PM March 09, 2008I visit this web from searching from www.avun.com
Posted by rgod at 01:14 AM March 16, 2008You should kiss my ass even for advisory/vulnerability section. You asked to the Johnny community forums if you can do this Windows shit?
rgod
Post a comment






