Course Overview

Sensitive data from web applications can be indexed by Google and then it becomes publicly exposed to everyone on the Internet. In this course, you’ll learn about different types of sensitive data that can be indexed by Google. What’s more – you’ll learn about the technique known as Google Hacking and you’ll see how Google Hacking can be used by ethical hackers and professional penetration testers for finding security weaknesses in web applications. 

First, the course will present how you can use Google Hacking to find directory listings and SQL syntax?errors. After that, we will demonstrate how you can find publicly exposed backup files and internal server errors by means of Google Hacking.  

Next, you can use Google Hacking to find sensitive data in URLs and insecure HTTP web pages. Then, it will be explained to you what Google Hacking Database is and also inform you about a critical vulnerability in Microsoft Yammer Social Network that allowed the attacker to gain unauthorized access to users’ accounts by means of Google Hacking. 

Finally, you will learn how to prevent Google indexing from happening. 

What you’ll see primarily in this course are demos and real-world scenarios because I want you to make the most of this course and apply this knowledge in your own penetration testing projects.

What You Will Learn

  • Learn how Google Hacking can be used to find security weaknesses in web applications
  • Use Google Hacking to find directory listings and SQL syntax errors
  • Find publicly exposed backup files and internal server errors by means of Google Hacking
  • Use Google Hacking to find sensitive data in URLs and insecure HTTP web pages
  • Discover how to find these security weaknesses step by step in practice (DEMOS)
  • Learn about Google Hacking Database

Program Curriculum

  • Google Hacking: Finding Directory Listings
  • Google Hacking: Finding SQL Syntax Errors
  • Google Hacking: Finding Publicly Exposed Backup Files
  • Google Hacking: Finding Internal Server Errors
  • Google Hacking: Finding Sensitive Data in URLs
  • Google Hacking: Finding Insecure HTTP Web Pages?
  • Google Hacking Database
  • Case Study: Microsoft Yammer Social Network
  • How to Prevent Google Indexing from Happening?
  • Summary
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 01 Quiz

Instructor

Dawid Czagan

Dawid Czagan (@dawidczagan) is an internationally recognized security researcher and trainer. He is listed among the top hackers at HackerOne. Dawid Czagan has found security vulnerabilities in Google, Yahoo, Mozilla, Microsoft, Twitter and other companies. Due to the severity of many bugs, he received numerous awards for his findings. Dawid Czagan shares his security bug hunting experience in his hands-on trainings “Hacking Web Applications – Case Studies of Award-Winning Bugs in Google, Yahoo, Mozilla and More” and “Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation”. He delivered security training courses at key industry conferences such as Hack In The Box (Amsterdam), CanSecWest (Vancouver), 44CON (London), Hack In Paris (Paris), DeepSec (Vienna), NorthSec (Montreal), HITB GSEC (Singapore), BruCON (Ghent) and for many corporate clients. His students include security specialists from Oracle, Adobe, ESET, ING, Red Hat, Trend Micro, Philips and the government sector (references are attached to Dawid Czagan's LinkedIn profile (https://www.linkedin.com/in/dawid-czagan-85ba3666/). They can also be found here: https://silesiasecuritylab.com/services/training/#opinions). Dawid Czagan is the founder and CEO of Silesia Security Lab – a company which delivers specialized security testing and training services. He is also an author of online security courses. To find out about the latest in Dawid Czagan’s work, you are invited to subscribe to his newsletter (https://silesiasecuritylab.com/newsletter) and follow him on Twitter (@dawidczagan) and LinkedIn (https://www.linkedin.com/in/dawid-czagan-85ba3666/).

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Empower Your Learning with Our Flexible Plans

Invest in your future with our flexible subscription plans. Whether you're just starting out or looking to enhance your expertise, there's a plan tailored to meet your needs. Gain access to in-demand skills and courses for your continuous learning needs.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 600+ courses and diverse Learning Paths to enhance your skills.

$ 499.00
Billed annually or $59.00 billed monthly

What is included

  • 700+ Premium Short Courses
  • 50+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs, CTF Challenges, and exclusive EC-Council certifications for comprehensive skill-building.

$ 599.00
Billed annually or $69.00 billed monthly

Everything in Pro and

  • 800+ Practice Lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Practice Labs and Challenges added every month
  • 3 Official EC-Council Essentials Certifications¹ (retails at $897!)
    Exclusive Bonus with Annual Plans

¹This plan includes Digital Forensics Essentials (DFE), Ethical Hacking Essentials (EHE), and Network Defense Essentials (NDE) certifications. No other EC-Council certifications are included.

Related Courses

1 of 8