โ† All cheat sheets

GoogleDork

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: Google Dork Builder

BASIC OPERATORS#

site:example.com          Search within specific site
inurl:admin               URL contains "admin"
intitle:login             Page title contains "login"
intext:password           Page body contains "password"
filetype:pdf              Search for PDF files
ext:pdf                   Same as filetype
cache:example.com         Show cached version
link:example.com          Find pages linking to site
related:example.com       Find similar sites
info:example.com          Information about site
define:term               Get definition

COMBINING OPERATORS#

site:example.com filetype:pdf
intitle:index.of inurl:admin
site:gov filetype:xls "password"
inurl:admin intitle:login
site:*.edu filetype:doc "confidential"

FILE DISCOVERY#

# Documents
filetype:pdf "confidential"
filetype:doc "internal use only"
filetype:xls "password"
filetype:ppt "not for distribution"
filetype:docx site:company.com

# Configuration files
filetype:conf inurl:web.conf
filetype:ini inurl:desktop.ini
filetype:env DB_PASSWORD
filetype:cfg
filetype:config

# Database files
filetype:sql "insert into"
filetype:sql password
filetype:db site:gov
filetype:mdb
filetype:sqlite

# Log files
filetype:log
filetype:log "password"
ext:log inurl:password

# Backup files
filetype:bak
filetype:bak inurl:htaccess
filetype:old
filetype:backup
inurl:backup filetype:sql

SENSITIVE DIRECTORIES#

intitle:index.of "parent directory"
intitle:index.of /admin
intitle:index.of /backup
intitle:index.of /config
intitle:index.of /password
intitle:index.of /private
intitle:index.of /secret
intitle:index.of /.git
intitle:index.of /.svn
intitle:index.of /wp-content/uploads

LOGIN PAGES#

inurl:login
inurl:signin
inurl:admin
inurl:administrator
inurl:wp-admin
inurl:wp-login.php
intitle:"admin login"
intitle:"login page"
inurl:auth
inurl:authenticate

VULNERABLE APPLICATIONS#

# WordPress
inurl:wp-content/plugins/
inurl:wp-includes/
"Index of" inurl:wp-content
inurl:xmlrpc.php

# phpMyAdmin
inurl:phpmyadmin
intitle:phpMyAdmin
"Welcome to phpMyAdmin"

# cPanel
inurl:2082
inurl:2083
intitle:cPanel

# Webmail
inurl:webmail
inurl:squirrelmail
inurl:roundcube

EXPOSED CREDENTIALS#

filetype:txt "username" "password"
filetype:log "username" "password"
intext:"password" filetype:csv
"index of" "credentials"
"index of" htpasswd
"index of" passwd
inurl:password.txt
inurl:users.txt

NETWORK DEVICES#

intitle:"Router" inurl:main.html
intitle:"RouterOS" inurl:winbox
intitle:"Network Camera"
intitle:"webcamXP"
intitle:"IP Camera"
inurl:ViewerFrame?Mode=
intitle:"Printer Status"
inurl:hp/device/this.LCDispatcher

SERVER INFORMATION#

intitle:"Apache Status"
intitle:"Apache Server Status"
intitle:"phpinfo()"
"PHP Version" intitle:phpinfo
ext:php intitle:phpinfo
intitle:"Environment Variables"
"Server_Software" intitle:phpinfo

ERROR MESSAGES#

"SQL syntax error"
"mysql_fetch_array"
"mysql_connect"
"Warning: mysql"
"Warning: pg_"
"ORA-00921"
"Microsoft OLE DB Provider for ODBC Drivers error"
"java.sql.SQLException"
"PostgreSQL query failed"

AWS/CLOUD#

site:s3.amazonaws.com filetype:txt
site:s3.amazonaws.com "index of"
site:blob.core.windows.net
site:storage.googleapis.com
inurl:digitaloceanspaces.com

GITHUB SECRETS#

site:github.com "password"
site:github.com "api_key"
site:github.com "secret_key"
site:github.com "AWS_ACCESS_KEY_ID"
site:github.com "DB_PASSWORD"
site:github.com "private_key"
site:github.com filename:.env

EMAIL DISCOVERY#

site:example.com "@example.com"
site:example.com email
intext:"@gmail.com" filetype:xls
"email" filetype:csv site:edu

VULNERABLE PARAMETERS#

inurl:id=
inurl:pid=
inurl:page=
inurl:file=
inurl:cat=
inurl:dir=
inurl:action=
inurl:show=
inurl:document=
inurl:folder=
inurl:path=
inurl:readfile=
inurl:download=
inurl:include=
inurl:require=
inurl:cmd=

SPECIFIC VULNERABILITIES#

# LFI/RFI
inurl:file= ext:php
inurl:page= ext:php
inurl:include= ext:php
inurl:path= ext:asp

# SQL Injection
inurl:id= "You have an error"
inurl:select inurl:from

# XSS
inurl:"<script>"

EXCLUSIONS#

-site:example.com         Exclude site
-filetype:pdf             Exclude file type
-inurl:login              Exclude URL pattern
site:example.com -www     Exclude subdomain

WILDCARDS & RANGES#

site:*.example.com        All subdomains
"version 1.." "version 2.."  Range
"error * denied"          Wildcard

DATE FILTERING#

# Use Google's Tools > Any time
before:2023-01-01
after:2022-01-01

AUTOMATION TOOLS#

# Google Hacking Database (GHDB)
https://www.exploit-db.com/google-hacking-database

# Tools
- theHarvester
- Recon-ng
- GooFuzz
- Pagodo (Passive Google Dork)

TIPS#

- Use quotes for exact phrases
- Combine multiple operators
- Check cached versions
- Use date filters
- Rotate search terms
- Don't overdo it (rate limiting)
- Use VPN for anonymity
- Document findings properly
Only search for information you're authorized to access.
Unauthorized access to systems is illegal.
Use for security research and authorized testing only.