false positive in Wikto Google Hacking

From: Rick Zhong (sagiko@gmail.com)
Date: Tue Sep 11 2007 - 23:38:50 EDT


Hi,
I am currently doing some testing using Wikto(v2.0.2778.19003)
Googlehacks with Aura(0.0.1). I found that it gave a lot of false
positive for Google queries (retrieved from Aura log) in following
format:

site:www.targeturl.com "# Dumping data for table"
site:www.targeturl.com "# phpMyAdmin MySQL-Dump" filetype:txt
site:www.targeturl.com "# Dumping data for table (username|user|users|password)"
...

When i use these query in the current www.google.com, it does not
return any results. Is there any explanation for this? Also is there
any document to show the actual logic of Wikto's Googlehack when it
analysis the search results? Thank you.

regards,
Rick

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:58:06 EDT