lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 18 Nov 2005 15:19:29 +0000
From: Petko Petkov <ppetkov@...citizen.org>
To: Christopher Carpenter <ccarpenter@...a.net>
Cc: full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com
Subject: Re: Google Base


Yes Chris,
However, how exactly google knows if the information that you are
sending is hacking related!
I see too many problems with google base. Unfortunately, what is done is
done.

Christopher Carpenter wrote:

>Except anything broadly defined as "hacking-related" is forbidden by the
>Google Base ToS:
>
>"Posting is not permitted for the promotion of hacking or cracking. For
>example, items must not provide instructions or equipment to illegally
>access or tamper with software, servers, or websites."
>
>From: http://base.google.com/base/base_policies.html
>
>Chris
>
>-----Original Message-----
>From: full-disclosure-bounces@...ts.grok.org.uk
>[mailto:full-disclosure-bounces@...ts.grok.org.uk] On Behalf Of Petko
>Petkov
>Sent: Friday, November 18, 2005 3:29 AM
>To: full-disclosure@...ts.grok.org.uk; bugtraq@...urityfocus.com
>Subject: [Full-disclosure] Google Base
>
>OK, I need to start this subject since nobody else has discussed
>anything yet on the mailing list. Do you guys know about Google Base?:
>Google our big hacker friend that helps us to find malicious scripts and
>open proxies just like that. Well, Google has a new service: Google
>Base. And there are many cool stuff that you can do with it.
>
>First of all I would like to mention that Google Base is sort of
>database where you can put whatever information you want: you can blog,
>you can post your advisories there, you can write awesome worms that
>upload and read commands from there, you can even use it as the biggest
>rainbow table in the world that can crack any hash in less than a
>second. check it out: http://base.google.com
>
>I was playing around with goggle base and I must say I am quite
>impressed and in the same time scared to death. Goggle base is the most
>amazing thing I have seen for a while and it can be used for many
>different things.
>
>Now here is a list that I built for you how to use goggle base for your
>own good:
>
>* Brute forcer - massive storage for mare mortals.
>* Keep your exploits
>* Keep your code fragments
>* Keep your advisories and security notes
>* Log there :)
>* Write a book (Goggle Book) :)
>* You can write even a Game Book.
>* Write a game and store its data on goggle base
>* Use it to hold your secret hacker tools (with encryption) :) just
>joking
>* Make a goggle base forum
>* Make a security list
>
>If you have more ideas how to use and abuse goggle base service, just
>contribute to the thread. Of course we all have to be responsible. This
>is the reason why I believe that this early notice about goggle base
>power is fair enough.
>
>Cheers
>_______________________________________________
>Full-Disclosure - We believe in it.
>Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>Hosted and sponsored by Secunia - http://secunia.com/
>
>  
>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Powered by blists - more mailing lists