官术网_书友最值得收藏!

Google dorks

A Google dork (also referred to as Google hacking) really is a specially crafted search string that returns information that isn't readily available on the website that's being targeted. It does this by leveraging advanced search operators.

Using Google dorks is an excellent way to perform information gathering on your target. You are able to return data such as usernames and passwords, sensitive information, login portals, and more.

Search operators within Google can be used to query specific information. Examples of such search operators are as follows:

  • site: Provides an output of URLs that are specific to the website you define.
  • inurl: With this query, you can define a certain string, and the results will return websites that have that string in them.
  • filetype: Here, you can define specific filetypes that you are looking for. For example, you can specify PDF, XLS, DOC, or any other file extension you want.

Search operators can be used together to perform crafty searches. An example of this is when looking for files with the .doc extension on microsoft.com. Here, you would accomplish this using the search query filetype:doc site:microsoft.com within Google.com.

Exploit-DB houses the Google Hacking Database, which is shown in the following screenshot (Figure 1). Here, you will find a vast collection of Google dorks that are constantly being updated:

The exact location for the Google Hacking Database on Exploit-DB is as follows:  https://www.exploit-db.com/google-hacking-database.
Figure 1: Google Hacking Database listed on exploit-db.com

You will notice that there are multiple categories where you can find various Google dorks. Let's perform information gathering using one of the dorks:

intext:password "Login Info" filetype:txt

The results from Google show how many websites have passwords exposed in clear text, as shown in Figure 2:

Figure 2: Passwords exposed using a Google Dork

As you gather information on your target, you can leverage crafted search queries within Google to discover what information is available. 

主站蜘蛛池模板: 沾化县| 安陆市| 渝北区| 麻江县| 磴口县| 丰镇市| 民乐县| 滕州市| 石柱| 广南县| 濮阳市| 攀枝花市| 衡南县| 鄂伦春自治旗| 海盐县| 修水县| 靖西县| 清新县| 沾益县| 衡水市| 静海县| 尚义县| 新营市| 错那县| 漳州市| 鹿泉市| 平潭县| 苗栗县| 永川市| 南皮县| 克山县| 富顺县| 芒康县| 周宁县| 郴州市| 安岳县| 福泉市| 温泉县| 湟中县| 东光县| 宁强县|