← All cheat sheets

GOOFILE

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Goofile searches Google for specific file types on a target domain.
It helps discover documents, spreadsheets, presentations, and other
files that may contain sensitive metadata or information.

BASIC USAGE#

goofile -d <domain> -f <filetype>
                                 # Search for files on domain

FILE TYPE SEARCHES#

goofile -d example.com -f pdf    # Search for PDF files
goofile -d example.com -f doc    # Search for Word documents
goofile -d example.com -f docx   # Search for Word (OOXML)
goofile -d example.com -f xls    # Search for Excel files
goofile -d example.com -f xlsx   # Search for Excel (OOXML)
goofile -d example.com -f ppt    # Search for PowerPoint files
goofile -d example.com -f pptx   # Search for PowerPoint (OOXML)
goofile -d example.com -f txt    # Search for text files
goofile -d example.com -f xml    # Search for XML files
goofile -d example.com -f csv    # Search for CSV files
goofile -d example.com -f conf   # Search for config files
goofile -d example.com -f log    # Search for log files
goofile -d example.com -f bak    # Search for backup files
goofile -d example.com -f sql    # Search for SQL dumps
goofile -d example.com -f mdb    # Search for Access databases

OPTIONS#

goofile -d <domain> -f <type>    # Required: domain and file type
goofile -p <pages>               # Number of Google pages to search

EXAMPLES#

# Find PDF documents on a domain
goofile -d example.com -f pdf

# Search for Excel spreadsheets
goofile -d example.com -f xls

# Search with more Google pages
goofile -d example.com -f doc -p 10

# Find config files that may expose settings
goofile -d example.com -f conf

# Look for database dumps
goofile -d example.com -f sql

EQUIVALENT GOOGLE DORKS#

# Goofile automates these Google queries:
site:example.com filetype:pdf
site:example.com filetype:doc
site:example.com filetype:xls
site:example.com filetype:ppt

FOLLOW-UP ACTIONS#

# After finding files:
# 1. Download discovered files
wget <url>
# 2. Extract metadata with exiftool
exiftool downloaded_file.pdf
# 3. Or use metagoofil for automated extraction

NOTES#

- Uses Google search engine (may be rate-limited)
- Results depend on Google's index
- Discovered files may contain sensitive metadata
- Metadata can reveal usernames, software versions, paths
- Pair with metagoofil for automated metadata extraction
- Consider OSINT implications of discovered documents
- Respect target scope during engagements