1. Home
  2. Computing & Technology
  3. Internet / Network Security

Information Leakage: Protect Against 'Google Hacking'
Stopping Data Leakage

From Tony Bradley, CISSP-ISSAP, for About.com

After you have conducted your web risk assessment and found out just how much of your data is available via the web, now what? For starters, you have to fix the security issues internally that led to confidential or sensitive data being available via the web.

Harlan Carvey, author of Windows Forensics and Incident Recovery, says “The issue is lack of senior management support. Just about every time I respond to an incident, the IT staff on-site is under-manned, under-trained, and over-tasked. No one has time to do anything other than install the OS and web server, and if the guys developing the application say that a certain setting needs to be there, or a specific password needs to be set (and cannot change), no one questions it. No one seems to understand the architecture for the application, so you then get a defacement due to FrontPage extension vulnerabilities (when you were told by three people the FrontPage extensions weren't installed) or a compromise due to SQL injection, when none of the IT staff seemed to know about the database.”

Whether it is a matter of changing passwords or providing better file and folder security, the data must be protected and secured so that it is no longer available on the web and is also limited to only authorized users within the network as well. You can also update the robots.txt file to direct the Google bots not to index certain folders, or the META tag reference to notify Google not to maintain a cached version of certain web pages. The issue doesn’t end there though. The information may still exist on Google (or other search engines).

Google maintains a cached version of many sites and may still have links to or fragments of your classified data. Google provides an automatic URL removal tool which can be found at http://services.google.com/urlconsole/controller. One of the options, Remove an Outdated Link, allows you to erase the file from the index and any other references or associated links as well.

Explore Internet / Network Security
About.com Special Features

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

Easy ways to connect two computers for networking purposes. More >

  1. Home
  2. Computing & Technology
  3. Internet / Network Security
  4. Advanced Security
  5. Perimeter Security
  6. Information Leakage: Protect Against 'Google Hacking' - Part 5

©2009 About.com, a part of The New York Times Company.

All rights reserved.