Browse Definitions:
Definition

Google Hack Honeypot (GHH)

Contributor(s): Ivy Wigmore

A Google Hack Honeypot (GHH) is a system designed to be vulnerable to sophisticated search engine queries for the purpose of attracting hackers and studying their behavior. 

GHH places an invisible link on the user’s website that can be detected through the use of advanced search operators. Google hacking (sometimes called Google dorking) is the use of advanced search operators to access hard-to-find information. Although Google hacking has many valid research purposes, it's also employed by attackers to gather information that can be used for illicit purposes, such as identity theft or corporate espionage. The reason Google hacking is effective is that neither website security nor corporate assets are adequately protected.

To an attacker, a honeypot acts like a live system, but it doesn’t actually provide access to any important data. A properly configured honeypot also doesn’t provide evidence to a hacker that his actions are being monitored. It should have user accounts, system files and ports that respond to port scans. However, instead of providing access to real backend data, the invisible link on the user website directs would-be hackers to a PHP script that logs their activity.

Administrators can use the information gathered to block access to resources, compile hacking attempt statistics or, if they chose, turn hacker information over to the authorities.

 

This was last updated in September 2014

Continue Reading About Google Hack Honeypot (GHH)

Join the conversation

1 comment

Send me notifications when other members comment.

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Please create a username to comment.

Interesting. I have not looked into this much but how are these invisible links set up and triggered? 
Cancel

-ADS BY GOOGLE

File Extensions and File Formats

SearchCompliance

  • smart contract

    A smart contract, also known as a cryptocontract, is a computer program that directly controls the transfer of digital currencies...

  • risk map (risk heat map)

    A risk map, also known as a risk heat map, is a data visualization tool for communicating specific risks an organization faces. A...

  • internal audit (IA)

    An internal audit (IA) is an organizational initiative to monitor and analyze its own business operations in order to determine ...

SearchSecurity

  • evil maid attack

    An evil maid attack is a security exploit that targets a computing device that has been shut down and left unattended.  An evil ...

  • Common Body of Knowledge (CBK)

    In security, Common Body of Knowledge (CBK) is a comprehensive framework of all the relevant subjects a security professional ...

  • rootkit

    A rootkit is a program or, more often, a collection of software tools that gives a threat actor remote access to and control over...

SearchHealthIT

  • value-based healthcare

    Value-based healthcare, also known as value-based care, is a payment model that rewards healthcare providers for providing ...

  • health informatics

    Health informatics is the practice of acquiring, studying and managing health data and applying medical concepts in conjunction ...

  • clinical trial

    A clinical trial, also known as a clinical research study, is a protocol to evaluate the effects and efficacy of experimental ...

SearchDisasterRecovery

  • crisis communication

    Crisis communication is a method of corresponding with people and organizations during a disruptive event to provide them with ...

  • Zerto

    Zerto is a storage software vendor that specializes in enterprise-class business continuity and disaster recovery in virtual and ...

  • crisis management plan (CMP)

    A crisis management plan (CMP) is a document that outlines the processes an organization will use to respond to a critical ...

SearchStorage

  • hard disk

    A hard disk is part of a unit -- often called a disk drive, hard drive or hard disk drive -- that stores and provides relatively ...

  • cache memory

    Cache memory, also called CPU memory, is high-speed static random access memory (SRAM) that a computer microprocessor can access ...

  • RAID 10 (RAID 1+0)

    RAID 10, also known as RAID 1+0, is a RAID configuration that combines disk mirroring and disk striping to protect data.

SearchSolidStateStorage

  • hybrid hard disk drive (HDD)

    A hybrid hard disk drive is an electromechanical spinning hard disk that contains some amount of NAND Flash memory.

Close