Live data from Hacker News

The best site to find password leaks: Google

google.com

41–44 of 44 posts

Re: The best site to find password leaks: Google

#41
Welcome to 2005. Hopefully this isn't new to the rest of you.

As someone else mentioned, Johnny posted articles on this years ago. But, he merely popularized it, Google hacking was around long before him.

See also: filetype:mdb, filetype:xls, "ssn" and so on.

For music, try: metallica filetype:mp3 For books, try: oreilly filetype:epub (or whatever)

Re: The best site to find password leaks: Google

#42
post #41

Welcome to 2005. Hopefully this isn't new to the rest of you. As someone else mentioned, Johnny posted articles on this years ago. But, he merely popularized it, Google hacking was around long before him. See also: filetype:mdb, filetype:xls, "ssn" and so on. For music, try: metallica filetype:mp3 For books, try: oreilly filetype:epub (or whatever)

What's really the interesting story is that it isn't 2005 and yet this stuff still works.

Re: The best site to find password leaks: Google

#44

Earlier quoted context omitted.

That's balderdash. These kinds of tools raise awareness of the issue, hopefully making more people think twice about posting private data to a public place. If they continue to be unaware of the danger of doing so, then it is simply exploited silently and everyone wonders how it happened. Your statement assumes that security through obscurity is a good thing.

At this point, you're both right - exposing these things to a massive audience just increases the number of potential attackers. Someone ought to write a tool that follows this account, and e-mails people warning them that their e-mail has been compromised. The hard part would be explaining what happened, how to verify it, and how to fix it to random strangers without convincing them that you're the one who just trie…

www.hacknotifier.com does this (disclaimer: I started it) - but it requires the user to subscribe to our service. Unfortunately, cold emailing them (which we considered), would be considered spam.
Post reply on HN