Sunday, 31 July 2011

Google Reveals A Lot (Google-dorks)

Google helps in creating complex search engine queries in order to filter information related to computer security through large amounts of search results.

In its malicious format, it can be used to detect websites that are vulnerable to numerous exploits and vulnerabilities. It can also locate private, sensitive information about others, such as credit card numbers, social security numbers and even PASSWORDS.

Below I had shown that how you can use GOOGLE to search for a particular result.
(Click on image to enlarge)


Filetype operator:

This searches for a particular file type format.  This is as shown below.






Site operator:

This will search in a particular site i.e. this type of search is bounded for a particular site. This is as shown below.






Inurl operator:

This will search for the result set which appears in the URL i.e. Uniform Resource Locator. Below is an example.





Server Versioning:
Knowing the server on which the website runs on(Also called as Server versioning). Below is an example.
query for google search:  

 intitle:index.of “server at”



Find FTP logs:

As we know there`s often a FTP log which remains in plain text format, we can now even search for that logs that reveals a lot. Below is an example.



Directory Searching:
This way you can search for some of the directories of websites. Below is an example for this.





Particular Directory Listing:
Below is an example of how you will list a directory of the file extensions you want.











Recommended References:

http://www.i-hacked.com/content/view/23/42/

http://www.ngohaianh.info/data/GoogleHacks.pdf

http://www.exploit-db.com/google-dorks/



No comments: