GoogleDork
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: Google Dork Builder
BASIC OPERATORS#
site:example.com Search within specific site inurl:admin URL contains "admin" intitle:login Page title contains "login" intext:password Page body contains "password" filetype:pdf Search for PDF files ext:pdf Same as filetype cache:example.com Show cached version link:example.com Find pages linking to site related:example.com Find similar sites info:example.com Information about site define:term Get definition
COMBINING OPERATORS#
site:example.com filetype:pdf intitle:index.of inurl:admin site:gov filetype:xls "password" inurl:admin intitle:login site:*.edu filetype:doc "confidential"
FILE DISCOVERY#
# Documents filetype:pdf "confidential" filetype:doc "internal use only" filetype:xls "password" filetype:ppt "not for distribution" filetype:docx site:company.com # Configuration files filetype:conf inurl:web.conf filetype:ini inurl:desktop.ini filetype:env DB_PASSWORD filetype:cfg filetype:config # Database files filetype:sql "insert into" filetype:sql password filetype:db site:gov filetype:mdb filetype:sqlite # Log files filetype:log filetype:log "password" ext:log inurl:password # Backup files filetype:bak filetype:bak inurl:htaccess filetype:old filetype:backup inurl:backup filetype:sql
SENSITIVE DIRECTORIES#
intitle:index.of "parent directory" intitle:index.of /admin intitle:index.of /backup intitle:index.of /config intitle:index.of /password intitle:index.of /private intitle:index.of /secret intitle:index.of /.git intitle:index.of /.svn intitle:index.of /wp-content/uploads
LOGIN PAGES#
inurl:login inurl:signin inurl:admin inurl:administrator inurl:wp-admin inurl:wp-login.php intitle:"admin login" intitle:"login page" inurl:auth inurl:authenticate
VULNERABLE APPLICATIONS#
# WordPress inurl:wp-content/plugins/ inurl:wp-includes/ "Index of" inurl:wp-content inurl:xmlrpc.php # phpMyAdmin inurl:phpmyadmin intitle:phpMyAdmin "Welcome to phpMyAdmin" # cPanel inurl:2082 inurl:2083 intitle:cPanel # Webmail inurl:webmail inurl:squirrelmail inurl:roundcube
EXPOSED CREDENTIALS#
filetype:txt "username" "password" filetype:log "username" "password" intext:"password" filetype:csv "index of" "credentials" "index of" htpasswd "index of" passwd inurl:password.txt inurl:users.txt
NETWORK DEVICES#
intitle:"Router" inurl:main.html intitle:"RouterOS" inurl:winbox intitle:"Network Camera" intitle:"webcamXP" intitle:"IP Camera" inurl:ViewerFrame?Mode= intitle:"Printer Status" inurl:hp/device/this.LCDispatcher
SERVER INFORMATION#
intitle:"Apache Status" intitle:"Apache Server Status" intitle:"phpinfo()" "PHP Version" intitle:phpinfo ext:php intitle:phpinfo intitle:"Environment Variables" "Server_Software" intitle:phpinfo
ERROR MESSAGES#
"SQL syntax error" "mysql_fetch_array" "mysql_connect" "Warning: mysql" "Warning: pg_" "ORA-00921" "Microsoft OLE DB Provider for ODBC Drivers error" "java.sql.SQLException" "PostgreSQL query failed"
AWS/CLOUD#
site:s3.amazonaws.com filetype:txt site:s3.amazonaws.com "index of" site:blob.core.windows.net site:storage.googleapis.com inurl:digitaloceanspaces.com
GITHUB SECRETS#
site:github.com "password" site:github.com "api_key" site:github.com "secret_key" site:github.com "AWS_ACCESS_KEY_ID" site:github.com "DB_PASSWORD" site:github.com "private_key" site:github.com filename:.env
EMAIL DISCOVERY#
site:example.com "@example.com" site:example.com email intext:"@gmail.com" filetype:xls "email" filetype:csv site:edu
VULNERABLE PARAMETERS#
inurl:id= inurl:pid= inurl:page= inurl:file= inurl:cat= inurl:dir= inurl:action= inurl:show= inurl:document= inurl:folder= inurl:path= inurl:readfile= inurl:download= inurl:include= inurl:require= inurl:cmd=
SPECIFIC VULNERABILITIES#
# LFI/RFI inurl:file= ext:php inurl:page= ext:php inurl:include= ext:php inurl:path= ext:asp # SQL Injection inurl:id= "You have an error" inurl:select inurl:from # XSS inurl:"<script>"
EXCLUSIONS#
-site:example.com Exclude site -filetype:pdf Exclude file type -inurl:login Exclude URL pattern site:example.com -www Exclude subdomain
WILDCARDS & RANGES#
site:*.example.com All subdomains "version 1.." "version 2.." Range "error * denied" Wildcard
DATE FILTERING#
# Use Google's Tools > Any time before:2023-01-01 after:2022-01-01
AUTOMATION TOOLS#
# Google Hacking Database (GHDB) https://www.exploit-db.com/google-hacking-database # Tools - theHarvester - Recon-ng - GooFuzz - Pagodo (Passive Google Dork)
TIPS#
- Use quotes for exact phrases - Combine multiple operators - Check cached versions - Use date filters - Rotate search terms - Don't overdo it (rate limiting) - Use VPN for anonymity - Document findings properly
LEGAL WARNING#
Only search for information you're authorized to access. Unauthorized access to systems is illegal. Use for security research and authorized testing only.