On Monday, the Cult of the Dead Cow hacker group released an open-source Web auditing tool that aims to let owners check their Web sites for security vulnerabilities. Dubbed the Goolag Scanner, the technology is based on “Google hacking,” a form of vulnerability research developed by Johnny I Hack Stuff. Goolag Scanner is a standalone Windows GUI-based application.
“It’s no big secret that the Web is the platform,” Cult of the Dead Cow spokesperson Oxblood Ruffin said. “And this platform pretty much sucks from a security perspective. Goolag Scanner provides one more tool for Web-site owners to patch up their online properties.”
‘Scary Holes’ in the Web
Hackers are constantly looking for vulnerable Web sites on which to plant malicious code. The Sophos 2008 Security Threat Report published in January revealed just how prevalent the danger is.
Sophos detects a newly infected Web page every 14 seconds. Eighty-three percent of those pages belong to companies and individuals who are unaware that their sites have been hacked.
“We’ve seen some pretty scary holes through random tests with the scanner in North America, Europe and the Middle East,” Ruffin said. “If I were a government, a large corporation, or anyone with a large web site, I’d be downloading this beast and aiming it at my site yesterday. The vulnerabilities are that serious.”
Clear and Present Danger
Cybercriminals can target any computer user through e-mails containing links to the poisoned Web pages. The hacked Web site can determine if the visiting computer is a Mac or a PC, and deliver malware custom-written for the surfer’s operating system.
Web sites of all types from antique dealers to ice-cream manufacturers to wedding photographers have hosted malware, according to Graham Cluley, a senior technology consultant at Sophos.
“Tools like Goolag can help Web-site owners determine if their sites are vulnerable,”…