Google dorking hacking techniques
What is Goolge Dorking ?
Google dorking is an advanced technique to retrieve or obtain information from google.Google dorking is mostly used to find vulnerable targets and sensitive data using advance search queries.
In other words google dorking is an art of making google search efficient and simpler.
Basic google dorking techniques:
Just like programming languages google also uses search operators.There are plenty of search operators to refine google search.Some commonly used are:
1 . intitle returns the pages that contain the strings you specify example:
intitle:python tutorial it will return the pages which have python tutorial in the title text.
intitle:python tutorial it will return the pages which have python tutorial in the title text.
2 . allintitle:admin login it returns the pages whose title have both admin and login in the tilte.
3 . inurl:adminlogin.php It returns the pages which have adminlogin.php in their url. You can use similar term to find asp pages inurl:adminlogin.asp.
inurl:login
inurl:login
4 . related:www.tutorialpoint.com It will return similar website to tutorialpoint.
5 . cache:www.tutorialpoint.com It returns cached pages even when website is down or internet not workin.
6 . ext:ppt python it will return ppt files on python.
7 . site:www.python.com it returns the links within the python.com
8 .
book:python language it will search for python books inside google online library. Dorks for Finding Vulnerable for SQL injection
- inurl:newsDetail.php?id=
- inurl:news.php?id=
- inurl:avd_start.php?avd=
- inurl:event.php?id=
- inurl:product-item.php?id=
- inurl:aboutbook.php?id=
- inurl:show.php?id=
- inurl:newsitem.php?num=
- inurl:play_old.php?id=
- inurl:games.php?id=
- inurl:page.php?file=
- inurl:newsDetail.php?id=
- inurl:gallery.php?id=
- inurl:article.php?id=
- inurl:view_product.php?id=
- inurl:sw_comment.php?id=
- inurl:sql.php?id=
- inurl:avd_start.php?avd=
- inurl:news.php?id=
- inurl:kategorie.php4?id=
- inurl:faq2.php?id=
- inurl:opinions.php?id=
- inurl:pages.php?id=
- inurl:participant.php?id=
- inurl:participant.php?id=
- inurl:chappies.php?id=
- inurl:prod_detail.php?id=
- inurl:productinfo.php?id=
- inurl:review.php?id=
- inurl:page.php?id=
- inurl:newsid=
- inurl:news_display.php?getid=
- inurl:news-full.php?id=
- inurl:newsid=
- inurl:item_id=
- inurl:shredder-categories.php?id=
- inurl:main.php?id=
- inurl:download.php?id=
- inurl:avd_start.php?avd=
- intitle:Login * Webmailer
- inurl:staff_id=
- inurl:staff_id=
- inurl:show.php?id=
- inurl:newsDetail.php?id=
- inurl:newsitem.php?num=
- inurl:pageid=
- inurl:article.php?ID=
- intitle:ANNOUNCE -inurl:lists
- inurl:curriculum.php?id=
- inurl:tekst.php?idt
- nurl:newsticker_info.php?idn=
Advance Google Dorking techniques
Dork for finding password lists
inurl:wp-content/uploads filetype:xls | filetype:xlsx password
filetype:log intext:password | pass | pw
inurl:"ftp" intext:"user" | "username" | "userID" | "user ID" | "logon" | "login" intext:"password" | "passcode" filetype:xls | filetype:xlsx
intext:smtp | pop3 intext:login | logon intext:password | passcode filetype:xls | filetype:xlsx
ext:xls intext:NAME intext:TEL intext:EMAIL intext:PASSWORD
inurl:etc -intext:etc ext:passwd
Dork for finding usernames
site:extremetracking.com inurl:"login="
intext:"SteamUserPassphrase=" intext:"SteamAppUser=" -"username" -"user"
inurl:root.asp?acs=anon
filetype:conf inurl:proftpd.conf -sample
কোন মন্তব্য নেই:
একটি মন্তব্য পোস্ট করুন