How To Use Google to Hack(Googledorks)
1-HISTORY
Google: If you still do not know what is google, then you need to take a crash course in "how to use the internet"
Dork:Someone who has odd interests, and is often silly at times.
A dork is also someone who can be themselves and not care what anyone thinks
As a passive attack method, Google dorking can return usernames and passwords, email lists, sensitive documents, personally identifiable financial information (PIFI) and website vulnerabilities.
That information can be used for any number of illegal activities, including cyberterrorism, industrial espionage,identity theft and cyberstalking
Lets take a look at the special google search operators that are used to construct those high powered google hack search terms.
Specifying intitle, will tell google to show only those pages that have the term in their html title. For example intitle:"login page" will show those pages which have the term "login page" in the title text.
allintitle
inurl
Searches for the specified term in the url. For example inurl:"login.php".
Same as inurl, but searches for all terms in the url.
filetype
ext
Similar to filetype. ext:pdf finds pdf extension files.
Searches the content of the page. Somewhat like a plain google search. For example intext:"index of /".
allintext
site
Limits the search to a specific site only. site:nullbyte.com
Dorks : They are like search criteria in which a search engine returns results related to your dork.
The process can be a little time consuming, but the outcome will be worth it after learning on how to use dorks.
Basic Formula of dork,
So you would normally understand it like this:
"inurl" = input URL
"domain" = your desired domain ex. .gov
"dorks" = your dork of your choice
Here is another example of that
intitle:
inurl:
intext:
define:
site:
phonebook:
maps:
book:
froogle:
info:
movie:
weather:
related:
link:
All these also help yo find other things then vulnerables.
INTITLE:
You can use the intitle to find anything in the title of the website. Which also could be usefull to find downloads or anything else.
This is an example to download mp3 songs for free.
inurl:index.php?id=
INTEXT:
intext:"Design & Developed By Seawind Solution Pvt.Ltd."
Google will give you all the websites created by IT Masons taht recently has bypass Admin Page Vulnerability in some websites,
And fill username and password like the information below :
Username : '=' 'OR'
Password : '=' 'OR'
and you will get the admin panel of the website some example:
http://www.vulnerablewebsite.com/adminpanel/index.php
DEFINE
define:"sql syntax error"
SITE:
site:wonderhowto.com
Google will look for any site related with wonderhowto.
It will look for the phone number related to me, so use your victims name or yours instead.
phonebook:Mrnakupenda
Google will look on google maps for your search.
BOOKS:
book:java language
This will look for any book gogole hase indexed whith java language in it.
Used for froogle search instead of google.
INFO:
info:firefox
Above dork will show you alot off things about firefox like what is firefox etc.
You can find information about movies on google using this dork.
movie:watch Transformers online
You can find information about weather on google using this dork.
weather: 01/08/2015 london
This will look for anything related to what you have entered next to related: .
related:hacking
LINK:
This one will works better instead of only looking in search url, it will also look in the site for urls that possibly are vulnerable.
This is verry usefull I would say even more then inurl.
Vulnerability Approach :
So our site will look like this,
http://www.site.com/index.php?id=123;
4-SOME EXTRAS
These are some Google Dorks which can affect our online business:
site:.com intitle:"Thank You For Your Order" intext:Click Here to Download
site:.com intitle:"Thank You For Your Purchase" intext:Click Here to Download
intitle:Thank you for your Purchase! intext:PLR OR MRR OR Package OR Bonus
inurl:/thankyou.html intitle:Thank you for your order! intext:Click Here to Download
6- USEFUL WEBSITES
here you will find fresh google dorks and you can also submits yours.
another cool website is http://www.google-dorking.com
you can also mention some websites here
to say that the best way to learn is by teaching, so I'm here to share what I know, and as always
I hope you will make correction where I'm wrong, because it is from mistakes that we learn ..
Comments
Post a Comment