<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>HexEsec &#124; a pentester's view &#187; search</title>
	<atom:link href="http://hexesec.wordpress.com/tag/search/feed/" rel="self" type="application/rss+xml" />
	<link>http://hexesec.wordpress.com</link>
	<description>sudo apt-get install ... security?</description>
	<lastBuildDate>Wed, 16 Dec 2009 23:34:30 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='hexesec.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/92201dabe8b4987549fde15513466bfb?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>HexEsec &#124; a pentester's view &#187; search</title>
		<link>http://hexesec.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hexesec.wordpress.com/osd.xml" title="HexEsec | a pentester&#8217;s view" />
		<item>
		<title>Google Calendar Search for Fun &amp; Profit</title>
		<link>http://hexesec.wordpress.com/2008/09/02/google-calendar-search-for-fun-profit/</link>
		<comments>http://hexesec.wordpress.com/2008/09/02/google-calendar-search-for-fun-profit/#comments</comments>
		<pubDate>Tue, 02 Sep 2008 04:24:40 +0000</pubDate>
		<dc:creator>jcran</dc:creator>
				<category><![CDATA[privacy]]></category>
		<category><![CDATA[web2.0]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[overshare]]></category>
		<category><![CDATA[search]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://hexesec.wordpress.com/?p=61</guid>
		<description><![CDATA[In the same vein as the earlier post on searching for vulnerabilities with Google Code Search, I realized tonight that you can search for private calendars on Google Calendar Search by simply typing &#8216;private&#8217; in the search box. You&#8217;ll be surprised by how many results you get (960 at time of writing).
With such nuggets as:


What
Presentation [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=61&subd=hexesec&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>In the same vein as the <a href="http://hexesec.wordpress.com/2008/09/01/google-code-search-for-fun-and-profit/">earlier post</a> on searching for vulnerabilities with Google Code Search, I realized tonight that you can search for private calendars on Google Calendar Search by simply typing &#8216;private&#8217; in the search box. You&#8217;ll be surprised by how many results you get (960 at time of writing).</p>
<p>With such nuggets as:</p>
<blockquote>
<div id="ff-title" class="field readonly">
<h3 class="label">What</h3>
<div id="wi-title" class="data input field-text readonly text">Presentation in Bern [work]</div>
</div>
<div id="ff-when" class="field readonly">
<h3 class="label">When</h3>
<div id="wi-when" class="data input field-dates readonly daterange">Mon Sep 1 12pm – Mon Sep 1 4pm</div>
</div>
<pre style="display:none;">20080901T120000/20080901T160000</pre>
<div id="ff-where" class="field readonly blank auto-location">
<h3 class="label">Where</h3>
</div>
<div id="ff-by" class="field readonly">
<h3 class="label">Created By</h3>
<p><span class="input readonly text field-owner"><cite class="name"><span style="cursor:pointer;">Michel</span></cite></span></div>
</blockquote>
<p>It&#8217;s certainly not a great deal of work to trace other public details, and find out exactly who this might be.  Interestingly, he&#8217;s also praying at 1AM today, and rowing at 2PM. He looks to be a bit worried about his skills.</p>
<p>This post ties closely to an <a href="http://n0where.org/2008/08/how-much-privacy-we-give-away/">observation made by stan over at n0where.org</a>. What if a bank were able to access your calendar while you were planning to make a week-long trip to vegas? Do you think they&#8217;d still be eager to give you that home-loan? Food for thought, no?</p>
<p><strong>UPDATE 09/02/08:</strong><br />
Google: John Gomez! Are you really sure you want to share this with the world?<br />
John Gomez: *clicks yes*<br />
Google: Are you sure??<br />
John Gomez: just do it, it&#8217;s handy!<br />
Google: Okay, but don&#8217;t say I didn&#8211;<br />
John Gomez: DO IT!<br />
Google: fine. idiot.<br />
[Except this doesn't happen, and people have NO IDEA they're sharing this info most likely]</p>
<blockquote><p><span class="title" style="color:#2952a3;">Delta Air Lines #616, 01:15 PM PDT</span></p>
<div class="detail-content">
<div class="detail-item"><span class="event-details-label">When</span><span class="event-when">Fri, Sep 26, 4:15pm – 10:01pm</span></div>
<div class="detail-item"><span class="event-details-label">Where</span><span class="event-where">SFO &#8211; JFK (<a class="menu-link" href="http://maps.google.com/maps?hl=en&amp;q=SFO%20-%20JFK" target="_blank">map</a>)</span></div>
<div class="detail-item"><span class="event-details-label">Description</span><span class="event-description"> Record Locator: MXNYGI Flight: Delta Air Lines #616 Confirmation: CYT0L0  Departure Location: San Francisco International Airport (SFO) Departure Time: Friday, September 26 at 01:15 PM PDT Departure Terminal: 1  Arrival Location: John F. Kennedy International Airport (JFK) Arrival Time: Friday, September 26 at 10:01 PM EDT Arrival Terminal: 3</span></div>
</div>
</blockquote>
<div class="detail-item"><strong>UPDATE (09/02/08) (2)</strong>:</div>
<div class="detail-item">Looks like our boy John is in good company at least&#8230; 680 results for the term &#8216;Record Locator.&#8217; Ouch.</div>
<div class="detail-item">So how do you take advantage of this?</div>
<div class="detail-item">- Impersonate them</div>
<div class="detail-item">- Break into their house / steal their car while they&#8217;re away</div>
<div class="detail-item">- Frame them for a crime happening in their vicinity</div>
<div class="detail-item">- Call the airport, impersonate an authority (you&#8217;ve got all the details, right?.. right.)</div>
<div class="detail-item"></div>
<p>Out of curiosity, is anyone doing a taxonomy of real-world attacks? The final attack listed above is analogous to a DOS attack, but these are all straight-forward. I&#8217;d love to see a taxonomy of possible ways to exploit a piece of information (vulnerability).</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hexesec.wordpress.com/61/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hexesec.wordpress.com/61/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hexesec.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hexesec.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hexesec.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hexesec.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hexesec.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hexesec.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hexesec.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hexesec.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hexesec.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hexesec.wordpress.com/61/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=61&subd=hexesec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://hexesec.wordpress.com/2008/09/02/google-calendar-search-for-fun-profit/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a7ddf41647a2dd583835558cdf11b280?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jcran</media:title>
		</media:content>
	</item>
	</channel>
</rss>