### GHDB.TXT
### 22/06/2006
[[start][1]
[[title]Squid cache server reports[[title]]
[[descr]These are squid server cache reports. Fairly benign, really except when you consider using them for evil purposes. For example, an institution stands up a proxy server for their internal users to get to the outside world. Then, the internal user surf all over to their hearts content (including intranet pages cuz well, the admins are stupid) Voila, intranet links show up in the external cache report. Want to make matters worse for yourself as an admin? OK, configure your external proxy server as a trusted internal host. Load up your web browser, set your proxy as their proxy and surf your way into their intranet. Not that I've noticed any examples of this in this google list. *COUGH* *COUGH* *COUGH* unresolved DNS lookups give clues *COUGH* *COUGH* ('scuse me. must be a furball) OK, lets say BEST CASE scenario. Let's say there's not security problems revealed in these logs. Best case scenario is that outsiders can see what your company/agency/workers are surfing. [descr]]
[[url]http://www.google.com/search?q=%22cacheserverreport+for%22+%22This+analysis+was+produced+by+calamaris%22[url]]
[[dork]"cacheserverreport for" "This analysis was produced by calamaris"[dork]]
[end][1]]
[[start][2]
[[title]Ganglia Cluster Reports[[title]]
[[descr]These are server cluster reports, great for info gathering. Lesse, what were those server names again?[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Ganglia%22+%22Cluster+Report+for%22[url]]
[[dork]intitle:"Ganglia" "Cluster Report for"[dork]]
[end][2]]
[[start][3]
[[title]ICQ chat logs, please...[[title]]
[[descr]ICQ (http://www.icq.com) allows you to store the contents of your online chats into a file. These folks have their entire ICQ directories online. On purpose?[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Index+of%22+dbconvert%2Eexe+chats[url]]
[[dork]intitle:"Index of" dbconvert.exe chats[dork]]
[end][3]]
[[start][4]
[[title]Apache online documentation[[title]]
[[descr]When you install the Apache web server, you get a nice set of online documentation. When you learn how to use Apache, your supposed to delete these online Apache manuals. These sites didn't. If they're in such a hurry with Apache installs, I wonder what else they rushed through?[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Apache+HTTP+Server%22+intitle%3A%22documentation%22[url]]
[[dork]intitle:"Apache HTTP Server" intitle:"documentation"[dork]]
[end][4]]
[[start][5]
[[title]Coldfusion Error Pages[[title]]
[[descr]
These aren't too horribly bad, but there are SO MANY of them. These sites got googlebotted while the site was having "technical difficulties." The resulting cached error message gives lots of juicy tidbits about the target site.[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=%22Error+Diagnostic+Information%22+intitle%3A%22Error+Occurred+While%22+[url]]
[[dork]"Error Diagnostic Information" intitle:"Error Occurred While" [dork]]
[end][5]]
[[start][6]
[[title]Financial spreadsheets: finance.xls[[title]]
[[descr]"Hey! I have a great idea! Let's put our finances on our website in a secret directory so we can get to it whenever we need to!"descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Index+of%22+finance.xls[url]]
[[dork]intitle:"Index of" finance.xls[dork]]
[end][6]]
[[start][7]
[[title]Financial spreadsheets: finances.xls[[title]]
[[descr]"Hey! I have a great idea! Let's put our finances on our website in a secret directory so we can get to it whenever we need to!"descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Index+of%22+finances.xls[url]]
[[dork]intitle:"Index of" finances.xls[dork]]
[end][7]]
[[start][8]
[[title]SQL data dumps[[title]]
[[descr]SQL database dumps. LOTS of data in these. So much data, infact, I'm pressed to think of what else an ev1l hax0r would like to know about a target database.. What's that? Usernames and passwords you say? Patience, grasshopper.....[descr]]
[[url]http://www.google.com/search?num=100&hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22%23+Dumping+data+for+table%22[url]]
[[dork]"# Dumping data for table"[dork]]
[end][8]]
[[start][9]
[[title]bash_history files[[title]]
[[descr]Ok, this file contains what a user typed at a shell command prompt. You shouldn't advertise this file. You shouldn't flash it to a web crawler. It contains COMMANDS and USERNAMES and stuff... *sigh* Sometimes there aren't words to describe how lame people can be. This particular theme can be carried further to find all sorts of things along these lines like .profile, .login, .logout files, etc. I just got bored with all the combinations...[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Index+of%22+%2Ebash%5Fhistory[url]]
[[dork]intitle:"Index of" .bash_history[dork]]
[end][9]]
[[start][10]
[[title]sh_history files[[title]]
[[descr]Ok, this file contains what a user typed at a shell command prompt. You shouldn't advertise this file. You shouldn't flash it to a web crawler. It contains COMMANDS and USERNAMES and stuff... *sigh* Sometimes there aren't words to describe how lame people can be. This particular theme can be carried further to find all sorts of things along these lines like .profile, .login, .logout files, etc. I just got bored with all the combinations...[descr]]
[[url]http://www.google.com/search?num=100&hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Index+of%22+.sh_history[url]]
[[dork]intitle:"Index of" .sh_history[dork]]
[end][10]]
[[start][11]
[[title]mysql history files[[title]]
[[descr]The .mysql_history file contains commands that were performed against a mysql database. A "history" of said commands. First, you shouldn't show this file to anyone, especially not a MAJOR SEARCH ENGINE! Secondly, I sure hope you wouldn't type anything sensitive while interacting with your databases, like oh say USERNAMES AND PASSWORDS...[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Index+of%22+%2Emysql%5Fhistory[url]]
[[dork]intitle:"Index of" .mysql_history[dork]]
[end][11]]
[[start][12]
[[title]mt-db-pass.cgi files[[title]]
[[descr]These folks had the technical prowess to unpack the movable type files, but couldn't manage to set up their web servers properly. Check the mt.cfg files for interesting stuffs...[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Index+of%22+mt%2Ddb%2Dpass%2Ecgi[url]]
[[dork]intitle:"Index of" mt-db-pass.cgi[dork]]
[end][12]]
[[start][13]
[[title]Windows 2000 Internet Services[[title]]
[[descr]At first glance, this search reveals even more examples of operating system users enabling the operating system default web server software. This is generally accepted to be a Bad Idea(TM) as mentioned in the previous example. However, the googleDork index on this particular category gets quite a boost from the fact that this particular screen should NEVER be seen by the general public. To quote the default index screen: "Any users attempting to connect to this site are currently receiving an 'Under Construction page'" THIS is not the 'Under Construction page.' I was only able to generate this screen while sitting at the console of the server. The fact that this screen is revealed to the general public may indicate a misconfiguration of a much more insidious nature...[descr]]
[[url]http://www.google.com/search?q=intitle:%22Welcome+to+Windows+2000+Internet+Services%22&num=100&hl=en&lr=&ie=UTF-8&filter=0[url]]
[[dork]intitle:"Welcome to Windows 2000 Internet Services"[dork]]
[end][13]]
[[start][14]
[[title]IIS 4.0[[title]]
[[descr]Moving from personal, lightweight web servers into more production-ready software, we find that even administrators of Microsoft's Internet Information Server (IIS) sometimes don't have a clue what they're doing. By searching on web pages with titles of "Welcome to IIS 4.0" we find that even if they've taken the time to change their main page, some dorks forget to change the titles of their default-installed web pages. This is an indicator that their web server is most likely running, or was upgraded from, the now considered OLD IIS 4.0 and that at least portions of their main pages are still exactly the same as they were out of the box. Conclusion? The rest of the factory-installed stuff is most likely lingering around on these servers as well.
Old code: FREE with operating system.
Poor content management: an average of $40/hour.
Factory-installed default scripts: FREE with operating system.
Getting hacked by a script kiddie that found you on Google: PRICELESS.
For all the things money can't buy, there's a googleDork award.[descr]]
[[url]http://www.google.com/search?q=intitle:%22Welcome+to+IIS+4.0%22&num=100&hl=en&lr=&ie=UTF-8&filter=0[url]]
[[dork]intitle:"Welcome to IIS 4.0"[dork]]
[end][14]]
[[start][15]
[[title]Look in my backup directories! Please?[[title]]
[[descr]Backup directories are often very interesting places to explore. More than one server has been compromised by a hacker's discovery of sensitive information contained in backup files or directories. Some of the sites in this search meant to reveal the contents of their backup directories, others did not. Think about it. What.s in YOUR backup directories? Would you care to share the contents with the whole of the online world? Probably not. Whether intentional or not, bsp.gsa.gov reveals backup directory through Google. Is this simply yet another misconfigured .gov site? You decide. BSP stands for "best security practices," winning this site the Top GoogleDork award for this category.[descr]]
[[url]http://www.google.com/search?q=%22Index+of+/backup%22&num=100&hl=en&lr=&ie=UTF-8&filter=0[url]]
[[dork]"Index of /backup"[dork]]
[end][15]]
[[start][16]
[[title]OpenBSD running Apache[[title]]
[[descr]I like the OpenBSD operating system. I really do. And I like the Apache web server software. Honestly. I admire the mettle of administrators who take the time to run quality, secure software. The problem is that you never know when security problems will pop up. A BIG security problem popped up within the OpenBSD/Apache combo. Now, every administrator that advertised this particular combo with cute little banners has a problem. Hackers can find them with Google. I go easy on these folks since the odds are they.ve patched their sites already. Then again, they may just show up on zone-h..[descr]]
[[url]http://www.google.com/search?sourceid=navclient&q=%22powered+by+openbsd%22+%2B%22powered+by+apache%22[url]]
[[dork]"powered by openbsd" +"powered by apache"[dork]]
[end][16]]
[[start][17]
[[title]intitle:index.of intext:"secring.skr"|"secring.pgp"|"secring.bak"[title]]
[[descr]PGP is a great encryption technology. It keeps secrets safe. Everyone from drug lords to the head of the DEA can download PGP to encrypt their sensitive documents. Everyone, that is except googleDorks. GoogleDorks, it seems, don't understand that anyone in possession of your private keyring (secring) can get to your secret stuff. It should noever be given out, and should certainly not be posted on the Internet. The highest ranking is awarded for this surprising level of ineptitude.[descr]]
[[url]http://www.google.com/search?q=intitle:index.of+intext:%22secring.skr%22%7C%22secring.pgp%22%7C%22secring.bak%22[url]]
[[dork]intitle:index.of intext:"secring.skr"|"secring.pgp"|"secring.bak"[dork]]
[end][17]]
[[start][20]
[[title]master.passwd[[title]]
[[descr]There's nothing that defines a googleDork more than getting your PASSWORDS grabbed by Google for the world to see. Truly the epitome of a googleDork. The hits in this search show "master.passwd" files which contain encrypted passwords which may look like this: "guest MMCHhvZ6ODgFo" A password cracker can eat cheesy hashes faster than Elvis eatin' jelly doughnuts. Bravo googleDorks! Good show!
For master.passwd, be sure to check other files in the same directory...[descr]]
[[url]http://www.google.com/search?sourceid=navclient&q=intitle%3A%22Index+of%22+master%2Epasswd[url]]
[[dork]intitle:"Index of" master.passwd[dork]]
[end][20]]
[[start][21]
[[title]pwd.db[[title]]
[[descr]There's nothing that defines a googleDork more than getting your PASSWORDS grabbed by Google for the world to see. Truly the epitome of a googleDork. The his in this search show "pwd.db" files which contain encrypted passwords which may look like this: "guest MMCHhvZ6ODgFo" A password cracker can eat cheesy hashes faster than Elvis eatin' jelly doughnuts. Bravo googleDorks! Good show![descr]]
[[url]http://www.google.com/search?sourceid=navclient&q=intitle%3A%22Index+of%22+pwd%2Edb[url]]
[[dork]intitle:"Index of" pwd.db[dork]]
[end][21]]
[[start][22]
[[title]htpasswd / htpasswd.bak[[title]]
[[descr]There's nothing that defines a googleDork more than getting your PASSWORDS grabbed by Google for the world to see. Truly the epitome of a googleDork. And what if the passwords are hashed? A password cracker can eat cheesy password hashes faster than Elvis eatin' jelly doughnuts. Bravo googleDorks! Good show![descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=ISO-8859-1&safe=off&q=intitle%3A%22Index+of%22+%22.htpasswd%22+htpasswd.bak[url]]
[[dork]intitle:"Index of" ".htpasswd" htpasswd.bak[dork]]
[end][22]]
[[start][23]
[[title]htpasswd / htgroup[[title]]
[[descr]There's nothing that defines a googleDork more than getting your PASSWORDS grabbed by Google for the world to see. Truly the epitome of a googleDork. And what if the passwords are hashed? A password cracker can eat cheesy password hashes faster than Elvis eatin' jelly doughnuts. Bravo googleDorks! Good show!
You'll need to sift through these results a bit...[descr]]
[[url]http://www.google.com/search?q=intitle:%22Index+of%22+%22.htpasswd%22+%22htgroup%22++-intitle:%22dist%22+-apache+-htpasswd.c&hl=en&lr=&ie=UTF-8&safe=off&start=10&sa=N[url]]
[[dork]intitle:"Index of" ".htpasswd" "htgroup" -intitle:"dist" -apache -htpasswd.c[dork]]
[end][23]]
[[start][24]
[[title]spwd.db / passwd[[title]]
[[descr]There's nothing that defines a googleDork more than getting your PASSWORDS grabbed by Google for the world to see. Truly the epitome of a googleDork. And what if the passwords are hashed? A password cracker can eat cheesy password hashes faster than Elvis eatin' jelly doughnuts. Bravo googleDorks! Good show![descr]]
[[url]http://www.google.com/search?q=intitle:%22Index+of%22+spwd.db+passwd+-pam.conf&hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&start=10&sa=N[url]]
[[dork]intitle:"Index of" spwd.db passwd -pam.conf[dork]]
[end][24]]
[[start][25]
[[title]passwd / etc (reliable)[[title]]
[[descr]There's nothing that defines a googleDork more than getting your PASSWORDS grabbed by Google for the world to see. Truly the epitome of a googleDork. And what if the passwords are hashed? A password cracker can eat cheesy password hashes faster than Elvis eatin' jelly doughnuts. Bravo googleDorks! Good show![descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=ISO-8859-1&safe=off&q=intitle%3A%22Index+of..etc%22+passwd[url]]
[[dork]intitle:"Index of..etc" passwd[dork]]
[end][25]]
[[start][26]
[[title]AIM buddy lists[[title]]
[[descr]These searches bring up common names for AOL Instant Messenger "buddylists". These lists contain screen names of your "online buddies" in Instant Messenger. Not that's not too terribly exciting or stupid unless you want to mess with someone's mind, and besides, some people make these public on purpose. The thing that's interesting are the files that get stored ALONG WITH buddylists. Often this stuff includes downloaded pictures, resumes, all sorts of things. This is really for the peepers out there, and it' possible to spend countless hours rifling through people's personal crap.
A few methods:
1. buddylist.blt
2. buddy.blt
3. buddies.blt[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=buddylist%2Eblt[url]]
[[dork]buddylist.blt[dork]]
[end][26]]
[[start][27]
[[title]config.php[[title]]
[[descr]This search brings up sites with "config.php" files. To skip the technical discussion, this configuration file contains both a username and a password for an SQL database. Most sites with forums run a PHP message base. This file gives you the keys to that forum, including FULL ADMIN access to the database. Way to go, googleDorks!![descr]]
[[url]http://www.google.com/search?sourceid=navclient&q=intitle%3A%22Index+of%22+config%2Ephp[url]]
[[dork]intitle:"Index of" config.php[dork]]
[end][27]]
[[start][28]
[[title]phpinfo()[[title]]
[[descr]this brings up sites with phpinfo(). There is SO much cool stuff in here that you just have to check one out for yourself! I mean full blown system versioning, SSL version, sendmail version and path, ftp, LDAP, SQL info, Apache mods, Apache env vars, *sigh* the list goes on and on! Thanks "joe!" =)[descr]]
[[url]http://www.google.com/search?hl=en&lr=&c2coff=1&q=intitle%3Aphpinfo+%22PHP+Version%22&btnG=Search[url]]
[[dork]intitle:phpinfo "PHP Version"[dork]]
[end][28]]
[[start][29]
[[title]MYSQL error message: supplied argument....[[title]]
[[descr]
One of many potential error messages that spew interesting information. The results of this message give you real path names inside the webserver as well as more php scripts for potential "crawling" activities.[descr]]
[[url]http://www.google.com/search?num=100&hl=en&lr=&ie=ISO-8859-1&q=%22supplied+argument+is+not+a+valid+MySQL+result+resource%22[url]]
[[dork]"supplied argument is not a valid MySQL result resource"[dork]]
[end][29]]
[[start][30]
[[title]The Master List[[title]]
[[descr]CLick on any of the following links to show google's list!
_vti_inf.html (694 hits)
service.pwd (11,800 hits)
users.pwd (23 hits)
authors.pwd (22 hits)
administrators.pwd (22 hits)
shtml.dll (780 hits)
shtml.exe (761 hits)
fpcount.exe (1,370 hits)
default.asp (2,170 hits)
showcode.asp (4 hits)
sendmail.cfm (5 hits)
getFile.cfm (7 hits)
imagemap.exe (510 hits)
test.bat (353 hits)
msadcs.dll (8 hits)
htimage.exe (513 hits)
counter.exe (164 hits)
browser.inc (11 hits)
hello.bat (18 hits)
default.asp\\ (2,170 hits)
dvwssr.dll (571 hits)
dvwssr.dll (571 hits)
dvwssr.dll (571 hits)
cart32.exe (9 hits)
add.exe (38 hits)
index.JSP (998 hits)
index.jsp (998 hits)
SessionServlet (46 hits)
shtml.dll (780 hits)
index.cfm (473 hits)
page.cfm (5 hits)
shtml.exe (761 hits)
web_store.cgi (16 hits)
shop.cgi (63 hits)
upload.asp (27 hits)
default.asp (2,170 hits)
pbserver.dll (6 hits)
phf (370 hits)
test-cgi (1,560 hits)
finger (23,900 hits)
Count.cgi (8,710 hits)
jj (5,600 hits)
php.cgi (170 hits)
php (48,000 hits)
nph-test-cgi (132 hits)
handler (9,220 hits)
webdist.cgi (35 hits)
webgais (37 hits)
websendmail (12 hits)
faxsurvey (27 hits)
htmlscript (50 hits)
perl.exe (340 hits)
wwwboard.pl (455 hits)
www-sql (26,500 hits)
view-source (641 hits)
campas (94 hits)
aglimpse (12 hits)
glimpse (4,530 hits)
man.sh (127 hits)
AT-admin.cgi (789 hits)
AT-generate.cgi (14 hits)
filemail.pl (5 hits)
maillist.pl (16 hits)
info2www (737 hits)
files.pl (267 hits)
bnbform.cgi (91 hits)
survey.cgi (93 hits)
classifieds.cgi (25 hits)
wrap (14,000 hits)
cgiwrap (1,270 hits)
edit.pl (114 hits)
perl (80,700 hits)
names.nsf (12 hits)
webgais (37 hits)
dumpenv.pl (7 hits)
test.cgi (1,560 hits)
submit.cgi (79 hits)
submit.cgi (79 hits)
guestbook.cgi (528 hits)
guestbook.pl (451 hits)
cachemgr.cgi (25 hits)
responder.cgi (4 hits)
perlshop.cgi (30 hits)
query (15,500 hits)
w3-msql (877 hits)
plusmail (12 hits)
htsearch (177 hits)
infosrch.cgi (19 hits)
publisher (2,610 hits)
ultraboard.cgi (24 hits)
db.cgi (96 hits)
formmail.cgi (420 hits)
allmanage.pl (5 hits)
ssi (9,550 hits)
adpassword.txt (39 hits)
redirect.cgi (60 hits)
f (124,000 hits)
cvsweb.cgi (78 hits)
login.jsp (241 hits)
login.jsp (241 hits)
dbconnect.inc (18 hits)
admin (57,000 hits)
htgrep (30 hits)
wais.pl (133 hits)
amadmin.pl (14 hits)
subscribe.pl (65 hits)
news.cgi (387 hits)
auctionweaver.pl (2 hits)
.htpasswd (2,390 hits)
acid_main.php (3 hits)
access_log (1,250 hits)
access-log (618 hits)
access.log (618 hits)
log.htm (386 hits)
log.html (1,310 hits)
log.txt (987 hits)
logfile (23,200 hits)
logfile.htm (76 hits)
logfile.html (671 hits)
logfile.txt (701 hits)
logger.html (37 hits)
stat.htm (398 hits)
stats.htm (687 hits)
stats.html (1,840 hits)
stats.txt (342 hits)
webaccess.htm (11 hits)
wwwstats.html (80 hits)
source.asp (11 hits)
perl (80,700 hits)
mailto.cgi (46 hits)
YaBB.pl (35 hits)
mailform.pl (670 hits)
cached_feed.cgi (6 hits)
cr (27,500 hits)
global.cgi (14 hits)
Search.pl (548 hits)
build.cgi (74 hits)
common.php (184 hits)
common.php (184 hits)
show (33,500 hits)
global.inc (114 hits)
ad.cgi (21 hits)
WSFTP.LOG (11 hits)
index.html~ (81,100 hits)
index.php~ (6,740 hits)
index.html.bak (690 hits)
index.php.bak (69 hits)
print.cgi (61 hits)
register.cgi (172 hits)
webdriver (35 hits)
bbs_forum.cgi (45 hits)
mysql.class (21 hits)
sendmail.inc (97 hits)
CrazyWWWBoard.cgi (68 hits)
search.pl (548 hits)
way-board.cgi (44 hits)
webpage.cgi (89 hits)
pwd.dat (22 hits)
adcycle (12 hits)
post-query (240 hits)
help.cgi (69 hits)
[descr]]
[[url]http://www.google.com/search?q=intitle%3A%22Index+of%22+_vti_inf.html" target="_blank">_vti_inf.html (694 hits)
_vti_inf.html (694 hits)
Have a look at the robots.txt file itself, it contains interesting stuff.
However, don't forget to check out the other files in these directories since they are usually at the top directory level of the web server![descr]]
[[url]http://www.google.com/search?q=intitle:Index.of+robots.txt&hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&start=10&sa=N[url]]
[[dork]intitle:Index.of robots.txt[dork]]
[end][31]]
[[start][32]
[[title]passlist[[title]]
[[descr]I'm not sure what uses this, but the passlist and passlist.txt files contain passwords in CLEARTEXT! That's right, no decoding/decrypting/encrypting required. How easy is this?
*sigh*
Supreme googledorkage[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&q=intitle%3Aindex.of+passlist[url]]
[[dork]intitle:index.of passlist[dork]]
[end][32]]
[[start][33]
[[title]secret[[title]]
[[descr]What kinds of goodies lurk in directories marked as "secret?" Find out...[descr]]
[[url]http://www.google.com/search?q=intitle:index.of.secret&hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&start=0&sa=N[url]]
[[dork]intitle:index.of.secret[dork]]
[end][33]]
[[start][34]
[[title]private[[title]]
[[descr]What kinds of things might you find in directories marked "private?" let's find out....[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=intitle%3Aindex%2Eof%2Eprivate[url]]
[[dork]intitle:index.of.private[dork]]
[end][34]]
[[start][35]
[[title]etc (index.of)[[title]]
[[descr]This search gets you access to the etc directory, where many many many types of password files can be found. This link is not as reliable, but crawling etc directories can be really fun![descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&q=intitle%3Aindex.of.etc[url]]
[[dork]intitle:index.of.etc[dork]]
[end][35]]
[[start][36]
[[title]winnt[[title]]
[[descr]The \WINNT directory is the directory that Windows NT is installed into by default. Now just because google can find them, this doesn't necessarily mean that these are Windows NT directories that made their way onto the web. However, sometimes this happens. Other times, they aren't Windows NT directories, but backup directories for Windows NT data. Wither way, worthy of a nomination.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&q=intitle%3Aindex.of.winnt[url]]
[[dork]intitle:index.of.winnt[dork]]
[end][36]]
[[start][37]
[[title]secure[[title]]
[[descr]What could be hiding in directories marked as "secure?" let's find out...[descr]]
[[url]http://www.google.com/search?q=intitle:%22index.of.secure%22&hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&start=0&sa=N[url]]
[[dork]intitle:"index.of.secure"[dork]]
[end][37]]
[[start][38]
[[title]protected[[title]]
[[descr]What could be in a directory marked as "protected?" Let's find out...[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&q=inurl%3Aindex.of.protected&btnG=Google+Search[url]]
[[dork]inurl:index.of.protected[dork]]
[end][38]]
[[start][39]
[[title]index.of.password[[title]]
[[descr]These directories are named "password." I wonder what you might find in here. Warning: sometimes p0rn sites make directories on servers with directories named "password" and single html files inside named things liks "horny.htm" or "brittany.htm." These are to boost their search results. Don't click them (unless you want to be buried in an avalanche of p0rn...[descr]]
[[url]http://www.google.com/search?q=inurl:index.of.password&hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&start=0&sa=N[url]]
[[dork]inurl:index.of.password[dork]]
[end][39]]
[[start][40]
[[title]"This report was generated by WebLog"[title]]
[[descr]These are weblog-generated statistics for web sites... A roadmap of files, referrers, errors, statistics... yummy... a schmorgasbord! =P[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=%22This+report+was+generated+by+WebLog%22[url]]
[[dork]"This report was generated by WebLog"[dork]]
[end][40]]
[[start][41]
[[title]"produced by getstats"[title]]
[[descr]Another web statistics package. This one originated from a google scan of an ivy league college. *sigh*
There's sooo much stuff in here![descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=%22These+statistics+were+produced+by+getstats%22[url]]
[[dork]"These statistics were produced by getstats"[dork]]
[end][41]]
[[start][42]
[[title]"generated by wwwstat"[title]]
[[descr]More www statistics on the web. This one is very nice.. Lots of directory info, and client access statistics, email addresses.. lots os good stuff.
You know, these are SOOO dangerous, especially if INTRANET users get logged... talk about mapping out an intranet quickly...
thanks, sac =)[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22This+summary+was+generated+by+wwwstat%22[url]]
[[dork]"This summary was generated by wwwstat"[dork]]
[end][42]]
[[start][43]
[[title]haccess.ctl (one way)[[title]]
[[descr]this is the frontpage(?) equivalent of htaccess, I believe. Anyhow, this file describes who can access the directory of the web server and where the other authorization files are. nice find.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=intitle%3Aindex%2Eof+haccess%2Ectl[url]]
[[dork]intitle:index.of haccess.ctl[dork]]
[end][43]]
[[start][44]
[[title]haccess.ctl (VERY reliable)[[title]]
[[descr]haccess.ctl is the frontpage(?) equivalent of the .htaccess file. Either way, this file decribes who can access a web page, and should not be shown to web surfers. Way to go, googledork. =P
This method is very reliable due to the use of this google query:
filetype:ctl Basic
This pulls out the file by name then searches for a string inside of it (Basic) which appears in the standard template for this file.[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=filetype%3Ahtaccess+Basic[url]]
[[dork]filetype:htaccess Basic[dork]]
[end][44]]
[[start][45]
[[title]filetype:xls username password email[[title]]
[[descr]This search shows Microsoft Excel spreadsheets containing the words username, password and email. Beware that there are a ton of blank "template" forms to weed through, but you can tell from the Google summary that some of these are winners... err losers.. depending on your perspective.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=filetype%3Axls+username+password+email[url]]
[[dork]filetype:xls username password email[dork]]
[end][45]]
[[start][46]
[[title]Hassan Consulting's Shopping Cart Version 1.18[[title]]
[[descr]These servers can be messed with in many ways. One specific way is by way of the "../" bug. This lets you cruise around the web server in a somewhat limited fashion.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=inurl%3Ashop+%22Hassan+Consulting%27s+Shopping+Cart+Version+1%2E18%22[url]]
[[dork]inurl:shop "Hassan Consulting's Shopping Cart Version 1.18"[dork]]
[end][46]]
[[start][47]
[[title]site:edu admin grades[[title]]
[[descr]I never really thought about this until I started coming up with juicy examples for DEFCON 11.. A few GLARINGLY bad examples contain not only student grades and names, but also social security numbers, securing the highest of all googledork ratings![descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=site%3Aedu+grades+admin[url]]
[[dork]site:edu grades admin[dork]]
[end][47]]
[[start][48]
[[title]auth_user_file.txt[[title]]
[[descr]DCForum's password file. This file gives a list of (crackable) passwords, usernames and email addresses for DCForum and for DCShop (a shopping cart program(!!!). Some lists are bigger than others, all are fun, and all belong to googledorks. =)[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=allinurl%3Aauth_user_file.txt[url]]
[[dork]allinurl:auth_user_file.txt[dork]]
[end][48]]
[[start][49]
[[title]inurl:config.php dbuname dbpass[[title]]
[[descr]The old config.php script. This puppy should be held very closely. It should never be viewable to your web visitors because it contains CLEARTEXT usernames and passwords!
The hishest of all googledorks ratings![descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=inurl%3Aconfig%2Ephp+dbuname+dbpass[url]]
[[dork]inurl:config.php dbuname dbpass[dork]]
[end][49]]
[[start][50]
[[title]inurl:tech-support inurl:show Cisco[[title]]
[[descr]This is a way to find Cisco products with an open web interface. These are generally supposed to be user and password protected. Google finds ones that aren't. Be sure to use Google's cache if you have trouble connecting. Also, there are very few results (2 at the time of posting.)[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=inurl%3Atech%2Dsupport+inurl%3Ashow+Cisco[url]]
[[dork]inurl:tech-support inurl:show Cisco[dork]]
[end][50]]
[[start][51]
[[title]index_i.shtml Ready (Xerox printers on the web!)[[title]]
[[descr]These printers are not-only web-enabled, but their management interface somehow got crawled by google! These puppies should not be public! You can really muck with these printers. In some cases, going to the "password.shtml" page, you can even lock out the admins if a username and password has not already been set! Thanks to mephisteau@yahoo.co.uk for the idea =)[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=i%5Findex%2Eshtml+%22Ready%22[url]]
[[dork]i_index.shtml "Ready"[dork]]
[end][51]]
[[start][52]
[[title]aboutprinter.shtml (More Xerox printers on the web!)[[title]]
[[descr]More Xerox printers on the web! Google found these printers. Should their management interface be open to the WHOLE INTERNET? I think not.[descr]]
[[url]http://www.google.com/search?hl=en&ie=UTF-8&oe=UTF-8&q=aboutprinter.shtml&btnG=Google+Search[url]]
[[dork]aboutprinter.shtml[dork]]
[end][52]]
[[start][53]
[[title]"Chatologica MetaSearch" "stack tracking"[title]]
[[descr]There is soo much crap in this error message... Apache version, CGI environment vars, path names, stack-freaking-dumps, process ID's, perl version, yadda yadda yadda...[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=%22Chatologica+MetaSearch%22+%22stack+tracking%3A%22[url]]
[[dork]"Chatologica MetaSearch" "stack tracking:"[dork]]
[end][53]]
[[start][54]
[[title]mystuff.xml - Trillian data files[[title]]
[[descr]This particular file contains web links that trillian users have entered into the tool. Trillian combines many different messaging programs into one tool. AIM, MSN, Yahoo, ICQ, IRC, etc. Although this particular file is fairly benign, check out the other files in the same directory. There is usually great stuff here![descr]]
[[url]http://www.google.com/search?q=mystuff.xml+intitle:%22index+of%22[url]]
[[dork]mystuff.xml intitle:"index of"[dork]]
[end][54]]
[[start][55]
[[title]trillian.ini[[title]]
[[descr]Trillian pulls together all sort of messaging clients like AIM MSN, Yahoo, IRC, ICQ, etc. The various ini files that trillian uses include files like aim.ini and msn.ini. These ini files contain encoded passwords, usernames, buddy lists, and all sorts of other fun things. Thanks for putting these on the web for us, googledorks![descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22index+of%22+trillian.ini[url]]
[[dork]intitle:"index of" trillian.ini[dork]]
[end][55]]
[[start][56]
[[title]intitle:admin intitle:login[[title]]
[[descr]Admin Login pages. Now, the existance of this page does not necessarily mean a server is vulnerable, but it sure is handy to let Google do the discovering for you, no? Let's face it, if you're trying to hack into a web server, this is one of the more obvious places to poke.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=ISO-8859-1&q=intitle%3Aadmin+intitle%3Alogin[url]]
[[dork]intitle:admin intitle:login[dork]]
[end][56]]
[[start][57]
[[title]ORA-00921: unexpected end of SQL command[[title]]
[[descr]
Another SQL error message from Cesar. This one coughs up full web pathnames and/or php filenames.[descr]]
[[url]http://www.google.com/search?hl=en&ie=UTF-8&oe=UTF-8&q=%22ORA-00921%3A+unexpected+end+of+SQL+command%22[url]]
[[dork]"ORA-00921: unexpected end of SQL command"[dork]]
[end][57]]
[[start][58]
[[title]passlist.txt (a better way)[[title]]
[[descr]Cleartext passwords. No decryption required![descr]]
[[url]http://www.google.com/search?num=100&hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&q=inurl%3Apasslist.txt[url]]
[[dork]inurl:passlist.txt[dork]]
[end][58]]
[[start][59]
[[title]sitebuildercontent[[title]]
[[descr]
This is a default directory for the sitebuilder web design software program. If these people posted web pages with default sitebuilder sirectory names, I wonder what else they got wrong?[descr]]
[[url]http://www.google.com/search?q=inurl:sitebuildercontent&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=0&sa=N[url]]
[[dork]inurl:sitebuildercontent[dork]]
[end][59]]
[[start][60]
[[title]sitebuilderfiles[[title]]
[[descr]
This is a default directory for the sitebuilder web design software program. If these people posted web pages with default sitebuilder sirectory names, I wonder what else they got wrong?[descr]]
[[url]http://www.google.com/search?q=inurl:sitebuilderfiles&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=0&sa=N[url]]
[[dork]inurl:sitebuilderfiles[dork]]
[end][60]]
[[start][61]
[[title]sitebuilderpictures[[title]]
[[descr]
This is a default directory for the sitebuilder web design software program. If these people posted web pages with default sitebuilder sirectory names, I wonder what else they got wrong?[descr]]
[[url]http://www.google.com/search?q=inurl:sitebuilderpictures&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=0&sa=N[url]]
[[dork]inurl:sitebuilderpictures[dork]]
[end][61]]
[[start][62]
[[title]htpasswd[[title]]
[[descr]This is a nifty way to find htpasswd files. Htpasswd files contain usernames and crackable passwords for web pages and directories. They're supposed to be server-side, not available to web clients! *duh*[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=filetype%3Ahtpasswd+htpasswd[url]]
[[dork]filetype:htpasswd htpasswd[dork]]
[end][62]]
[[start][63]
[[title]"YaBB SE Dev Team"[title]]
[[descr]Yet Another Bulletin Board (YABB) SE (versions 1.5.4 and 1.5.5 and perhaps others) contain an SQL injection vulnerability which may allow several attacks including unauthorized database modification or viewing. See http://www.securityfocus.com/bid/9674
for more information. Also see http://www.securityfocus.com/bid/9677
for information about an information leakage vulnerability in versions YaBB Gold - Sp 1.3.1 and others.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=%22YaBB+SE+Dev+Team%22[url]]
[[dork]"YaBB SE Dev Team"[dork]]
[end][63]]
[[start][64]
[[title]EarlyImpact Productcart[[title]]
[[descr]The EarlyImpact Productcart contains multiple vulnerabilites, which could exploited to allow an attacker to steal user credentials or mount other attacks. See http://www.securityfocus.com/bid/9669 for more informationfor more information. Also see http://www.securityfocus.com/bid/9677
for information about an information leakage vulnerability in versions YaBB Gold - Sp 1.3.1 and others.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3ACustva.asp+[url]]
[[dork]inurl:Custva.asp [dork]]
[end][64]]
[[start][65]
[[title]mnGoSearch vulnerability[[title]]
[[descr]According to http://www.securityfocus.com/bid/9667, certain versions of mnGoSearch contain a buffer overflow vulnerability which allow an attacker to execute commands on the server. [descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22Powered+by+mnoGoSearch+-+free+web+search+engine+software%22[url]]
[[dork]"Powered by mnoGoSearch - free web search engine software"[dork]]
[end][65]]
[[start][66]
[[title]IIS 4.0 error messages[[title]]
[[descr]
IIS 4.0 servers. Extrememly old, incredibly easy to hack...
[descr]]
[[url]http://www.google.com/search?ie=UTF-8&oe=UTF-8&q=intitle%3A%22the+page+cannot+be+found%22+inetmgr[url]]
[[dork]intitle:"the page cannot be found" inetmgr[dork]]
[end][66]]
[[start][67]
[[title]Windows 2000 web server error messages[[title]]
[[descr]
Windows 2000 web servers. Aging, fairly easy to hack, especially out of the box...
[descr]]
[[url]http://www.google.com/search?ie=UTF-8&oe=UTF-8&q=intitle%3A%22the+page+cannot+be+found%22+%222004+microsoft+corporation%22[url]]
[[dork]intitle:"the page cannot be found" "2004 microsoft corporation"[dork]]
[end][67]]
[[start][68]
[[title]IIS web server error messages[[title]]
[[descr]
This query finds various types of IIS servers. This error message is fairly indicative of a somewhat unmodified IIS server, meaning it may be easier to break into...
[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22the+page+cannot+be+found%22+%22internet+information+services%22[url]]
[[dork]intitle:"the page cannot be found" "internet information services"[dork]]
[end][68]]
[[start][69]
[[title]phpMyAdmin dumps[[title]]
[[descr]From phpmyadmin.net : "phpMyAdmin is a tool written in PHP intended to handle the administration of MySQL over the WWW." Great, easy to use, but don't leave your database dumps laying around on the web. They contain all SORTS of sensitive information... [descr]]
[[url]http://www.google.com/search?&q=%22%23+phpMyAdmin+MySQL%2DDump%22+filetype%3Atxt[url]]
[[dork]"# phpMyAdmin MySQL-Dump" filetype:txt[dork]]
[end][69]]
[[start][70]
[[title]phpMyAdmin dumps[[title]]
[[descr]From phpmyadmin.net : "phpMyAdmin is a tool written in PHP intended to handle the administration of MySQL over the WWW." Great, easy to use, but don't leave your database dumps laying around on the web. They contain all SORTS of sensitive information... [descr]]
[[url]http://www.google.com/search?num=100&hl=en&lr=&ie=ISO-8859-1&safe=off&q=%22%23+phpMyAdmin+MySQL-Dump%22+%22INSERT+INTO%22+-%22the%22[url]]
[[dork]"# phpMyAdmin MySQL-Dump" "INSERT INTO" -"the"[dork]]
[end][70]]
[[start][71]
[[title]Gallery in configuration mode[[title]]
[[descr]
Gallery is a nice little php program that allows users to post personal pictures on their website. So handy, in fact, that I use it on my site! However, the Gallery configuration mode allows outsiders to make changes to your gallery. This is why you shouldn't leave your gallery in configuration mode. These people, unfortunately, have done just that![descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Gallery+in+Configuration+mode%22[url]]
[[dork]intitle:"Gallery in Configuration mode"[dork]]
[end][71]]
[[start][72]
[[title]cgiirc.conf[[title]]
[[descr]CGIIRC is a web-based IRC client. Very cool stuff. The cgiirc.config file lists the options for this porgram, including the default sites that can be attached to, server passwords, and crypts of admin passwords. This file is for CGIIRC, not Google surfers!
[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=intitle%3Aindex%2Eof+cgiirc%2Econfig%27[url]]
[[dork]intitle:index.of cgiirc.config'[dork]]
[end][72]]
[[start][73]
[[title]cgiirc.conf[[title]]
[[descr]This is another less reliable way of finding the cgiirc.config file. CGIIRC is a web-based IRC client. Very cool stuff. The cgiirc.config file lists the options for this porgram, including the default sites that can be attached to, server passwords, and crypts of admin passwords. This file is for CGIIRC, not Google surfers!
[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3A%27cgiirc.config%27[url]]
[[dork]inurl:'cgiirc.config'[dork]]
[end][73]]
[[start][74]
[[title]ipsec.secrets[[title]]
[[descr]from the manpage for ipsec_secrets: "It is vital that these secrets be protected. The file should be owned by the super-user, and its permissions should be set to block all access by others." So let's make it plain: DO NOT SHOW THIS FILE TO ANYONE! Googledorks rejoice, these files are on the web!
[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Aipsec.secrets+-history+-bugs[url]]
[[dork]inurl:ipsec.secrets -history -bugs[dork]]
[end][74]]
[[start][75]
[[title]ipsec.secrets[[title]]
[[descr]from the manpage for ipsec_secrets: "It is vital that these secrets be protected. The file should be owned by the super-user, and its permissions should be set to block all access by others." So let's make it plain: DO NOT SHOW THIS FILE TO ANYONE! Googledorks rejoice, these files are on the web!
[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Aipsec.secrets+%22holds+shared+secrets%22[url]]
[[dork]inurl:ipsec.secrets "holds shared secrets"[dork]]
[end][75]]
[[start][76]
[[title]ipsec.conf[[title]]
[[descr]The ipsec.conf file could help hackers figure out what uber-secure users of freeS/WAN are protecting....
[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Aipsec.conf+-intitle%3Amanpage[url]]
[[dork]inurl:ipsec.conf -intitle:manpage[dork]]
[end][76]]
[[start][77]
[[title]Internal Server Error[[title]]
[[descr]
This one shows the type of web server running on the site, and has the ability to show other information depending on how the message is internally formatted.
[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22500+Internal+Server+Error%22+%22server+at%22[url]]
[[dork]intitle:"500 Internal Server Error" "server at"[dork]]
[end][77]]
[[start][78]
[[title]mysql error with query[[title]]
[[descr]
Another error message, this appears when an SQL query bails. This is a generic mySQL message, so there's all sort of information hackers can use, depending on the actual error message...
[descr]]
[[url]http://www.google.com/search?q=%22mySQL+error+with+query%22[url]]
[[dork]"mySQL error with query"[dork]]
[end][78]]
[[start][79]
[[title]SQL syntax error[[title]]
[[descr]
Another generic SQL message, this message can display path names and partial SQL code, both of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=ISO-8859-1&q=%22You+have+an+error+in+your+SQL+syntax+near%22[url]]
[[dork]"You have an error in your SQL syntax near"[dork]]
[end][79]]
[[start][80]
[[title]ORA-00936: missing expression[[title]]
[[descr]
A generic ORACLE error message, this message can display path names, function names, filenames and partial database code, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=%22ORA%2D00936%3A+missing+expression%22[url]]
[[dork]"ORA-00936: missing expression"[dork]]
[end][80]]
[[start][81]
[[title]"Supplied argument is not a valid MySQL result resource"[title]]
[[descr]
Another generic SQL message, this message can display path names, function names, filenames and partial SQL code, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?q=%22Supplied+argument+is+not+a+valid+MySQL+result+resource%22&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=90&sa=N[url]]
[[dork]"Supplied argument is not a valid MySQL result resource"[dork]]
[end][81]]
[[start][82]
[[title]ORA-00921: unexpected end of SQL command[[title]]
[[descr]
Another generic SQL message, this message can display path names, function names, filenames and partial SQL code, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=%22ORA%2D00921%3A+unexpected+end+of+SQL+command%22[url]]
[[dork]"ORA-00921: unexpected end of SQL command"[dork]]
[end][82]]
[[start][83]
[[title]"ORA-00933: SQL command not properly ended"[title]]
[[descr]
An Oracle error message, this message can display path names, function names, filenames and partial SQL code, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22ORA-00933%3A+SQL+command+not+properly+ended%22[url]]
[[dork]"ORA-00933: SQL command not properly ended"[dork]]
[end][83]]
[[start][84]
[[title]"Unclosed quotation mark before the character string"[title]]
[[descr]
An SQL Server error message, this message can display path names, function names, filenames and partial code, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?q=%22Unclosed+quotation+mark+before+the+character+string%22&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=10&sa=N[url]]
[[dork]"Unclosed quotation mark before the character string"[dork]]
[end][84]]
[[start][85]
[[title]"Incorrect syntax near"[title]]
[[descr]
An SQL Server error message, this message can display path names, function names, filenames and partial code, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?q=%22Incorrect+syntax+near%22&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=90&sa=N[url]]
[[dork]"Incorrect syntax near"[dork]]
[end][85]]
[[start][86]
[[title]"Incorrect syntax near"[title]]
[[descr]
An SQL Server error message, this message can display path names, function names, filenames and partial code, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22Incorrect+syntax+near%22+-the[url]]
[[dork]"Incorrect syntax near" -the[dork]]
[end][86]]
[[start][87]
[[title]"PostgreSQL query failed: ERROR: parser: parse error"[title]]
[[descr]
An PostgreSQL error message, this message can display path names, function names, filenames and partial code, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22PostgreSQL+query+failed%3A++ERROR%3A++parser%3A+parse+error%22[url]]
[[dork]"PostgreSQL query failed: ERROR: parser: parse error"[dork]]
[end][87]]
[[start][88]
[[title]Supplied argument is not a valid PostgreSQL result[[title]]
[[descr]
An PostgreSQL error message, this message can display path names, function names, filenames and partial code, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22Supplied+argument+is+not+a+valid+PostgreSQL+result%22[url]]
[[dork]"Supplied argument is not a valid PostgreSQL result"[dork]]
[end][88]]
[[start][89]
[[title]"Syntax error in query expression " -the[[title]]
[[descr]
An Access error message, this message can display path names, function names, filenames and partial code, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?q=%22Syntax+error+in+query+expression+%22+-the&hl=en&lr=&ie=UTF-8&oe=UTF-8[url]]
[[dork]"Syntax error in query expression " -the[dork]]
[end][89]]
[[start][90]
[[title]"An illegal character has been found in the statement" -"previous message"[title]]
[[descr]
An Informix error message, this message can display path names, function names, filenames and partial code, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22An+illegal+character+has+been+found+in+the+statement%22+-%22previous+message%22[url]]
[[dork]"An illegal character has been found in the statement" -"previous message"[dork]]
[end][90]]
[[start][91]
[[title]"A syntax error has occurred" filetype:ihtml[[title]]
[[descr]
An Informix error message, this message can display path names, function names, filenames and partial code, all of which are very helpful for hackers[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22A+syntax+error+has+occurred%22+filetype%3Aihtml[url]]
[[dork]"A syntax error has occurred" filetype:ihtml[dork]]
[end][91]]
[[start][92]
[[title]"detected an internal error [IBM][CLI Driver][DB2/6000]"[title]]
[[descr]
A DB2 error message, this message can display path names, function names, filenames, partial code and program state, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22detected+an+internal+error+%5BIBM%5D%5BCLI+Driver%5D%5BDB2%2F6000%5D%22[url]]
[[dork]"detected an internal error [IBM][CLI Driver][DB2/6000]"[dork]]
[end][92]]
[[start][93]
[[title]An unexpected token "END-OF-STATEMENT" was found[[title]]
[[descr]
A DB2 error message, this message can display path names, function names, filenames, partial code and program state, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=An+unexpected+token+%22END-OF-STATEMENT%22+was+found[url]]
[[dork]An unexpected token "END-OF-STATEMENT" was found[dork]]
[end][93]]
[[start][94]
[[title]intitle:"statistics of" "advanced web statistics"[title]]
[[descr]the awstats program shows web statistics for web servers. This information includes who is visiting the site, what pages they visit, error codes produced, filetypes hosted on the server, number of hits, and more which can provide very interesting recon information for an attacker.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22statistics+of%22+%22advanced+web+statistics%22[url]]
[[dork]intitle:"statistics of" "advanced web statistics"[dork]]
[end][94]]
[[start][95]
[[title]intitle:"Usage Statistics for" "Generated by Webalizer"[title]]
[[descr]The webalizer program shows web statistics for web servers. This information includes who is visiting the site, what pages they visit, error codes produced, filetypes hosted on the server, number of hits, referrers, exit pages, and more which can provide very interesting recon information for an attacker.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Usage+Statistics+for%22+%22Generated+by+Webalizer%22[url]]
[[dork]intitle:"Usage Statistics for" "Generated by Webalizer"[dork]]
[end][95]]
[[start][96]
[[title]"robots.txt" "Disallow:" filetype:txt[[title]]
[[descr]The robots.txt file serves as a set of instructions for web crawlers. The "disallow" tag tells a web crawler where NOT to look, for whatever reason. Hackers will always go to those places first![descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22robots%2Etxt%22+%2B+%22Disallow%3A%22+filetype%3Atxt[url]]
[[dork]"robots.txt" + "Disallow:" filetype:txt[dork]]
[end][96]]
[[start][98]
[[title]"phpMyAdmin" "running on" inurl:"main.php"[title]]
[[descr]From phpmyadmin.net : "phpMyAdmin is a tool written in PHP intended to handle the administration of MySQL over the WWW." Great, easy to use, but lock it down! Things you can do include viewing MySQL runtime information and system variables, show processes, reloading MySQL, changing privileges, and modifying or exporting databases. Hacker-fodder for sure!
[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&q=%22phpMyAdmin%22+%22running+on%22+inurl%3A%22main.php%22&btnG=Google+Search[url]]
[[dork]"phpMyAdmin" "running on" inurl:"main.php"[dork]]
[end][98]]
[[start][99]
[[title]inurl:main.php phpMyAdmin[[title]]
[[descr]From phpmyadmin.net : "phpMyAdmin is a tool written in PHP intended to handle the administration of MySQL over the WWW." Great, easy to use, but lock it down! Things you can do include viewing MySQL runtime information and system variables, show processes, reloading MySQL, changing privileges, and modifying or exporting databases. Hacker-fodder for sure!
[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&q=inurl%3Amain.php+phpMyAdmin[url]]
[[dork]inurl:main.php phpMyAdmin[dork]]
[end][99]]
[[start][100]
[[title]inurl:main.php Welcome to phpMyAdmin[[title]]
[[descr]From phpmyadmin.net : "phpMyAdmin is a tool written in PHP intended to handle the administration of MySQL over the WWW." Great, easy to use, but lock it down! Things you can do include viewing MySQL runtime information and system variables, show processes, reloading MySQL, changing privileges, and modifying or exporting databases. Hacker-fodder for sure!
[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&q=inurl%3Amain.php+Welcome+to+phpMyAdmin[url]]
[[dork]inurl:main.php Welcome to phpMyAdmin[dork]]
[end][100]]
[[start][101]
[[title]"Warning: Cannot modify header information - headers already sent"[title]]
[[descr]
A PHP error message, this message can display path names, function names, filenames and partial code, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=%22Warning%3A+Cannot+modify+header+information+%2D+headers+already+sent%22[url]]
[[dork]"Warning: Cannot modify header information - headers already sent"[dork]]
[end][101]]
[[start][102]
[[title]intitle:"wbem" compaq login "Compaq Information Technologies Group"[title]]
[[descr]These devices are running HP Insight Management Agents for Servers which
"provide device information for all managed subsystems. Alerts are generated by SNMP traps." The information on these pages include server addresses and other assorted SNMP information.
[descr]]
[[url]http://www.google.com/search?q=intitle:%22wbem%22+compaq+login+%22Compaq+Information+Technologies+Group%22&hl=en&lr=&c2coff=1&filter=0[url]]
[[dork]intitle:"wbem" compaq login "Compaq Information Technologies Group"[dork]]
[end][102]]
[[start][103]
[[title]intitle:osCommerce inurl:admin intext:"redistributable under the GNU"
intext:"Online Catalog" -demo -site:oscommerce.com[[title]]
[[descr]This is a decent way to explore the admin interface of osCommerce e-commerce sites. Depending on how bad the setup of the web store is, web surfers can even Google their way into customer details and order status, all from the Google cache.[descr]]
[[url]http://www.google.com/search?q=intitle:osCommerce+inurl:admin+intext:%22redistributable+under+the+GNU%22intext:%22Online+Catalog%22+-demo+-site:oscommerce.com[url]]
[[dork]intitle:osCommerce inurl:admin intext:"redistributable under the GNU"intext:"Online Catalog" -demo -site:oscommerce.com[dork]]
[end][103]]
[[start][104]
[[title]intitle:index.of "Apache" "server at"[title]]
[[descr]This is a very basic string found on directory listing pages which show the version of the Apache web server. Hackers can use this information to find vulnerable targets without querying the servers.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=intitle%3Aindex%2Eof+%22Apache%22+%22server+at%22[url]]
[[dork]intitle:index.of "Apache" "server at"[dork]]
[end][104]]
[[start][105]
[[title]"access denied for user" "using password"[title]]
[[descr]
Another SQL error message, this message can display the username, database, path names and partial SQL code, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22access+denied+for+user%22+%22using+password%22[url]]
[[dork]"access denied for user" "using password"[dork]]
[end][105]]
[[start][106]
[[title]intitle:"Under construction" "does not currently have"[title]]
[[descr]
This error message can be used to narrow down the operating system and web server version which can be used by hackers to mount a specific attack.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Under+construction%22+%22does+not+currently+have%22[url]]
[[dork]intitle:"Under construction" "does not currently have"[dork]]
[end][106]]
[[start][107]
[[title]"seeing this instead" intitle:"test page for apache"[title]]
[[descr]
This is the default web page for Apache 1.3.11 - 1.3.26. Hackers can use this information to determine the version of the web server, or to search Google for vulnerable targets. In addition, this indicates that the web server is not well maintained.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22seeing+this+instead%22+intitle%3A%22test+page+for+apache%22[url]]
[[dork]"seeing this instead" intitle:"test page for apache"[dork]]
[end][107]]
[[start][108]
[[title]intitle:"Test Page for Apache" "It Worked!"[title]]
[[descr]
This is the default web page for Apache 1.2.6 - 1.3.9. Hackers can use this information to determine the version of the web server, or to search Google for vulnerable targets. In addition, this indicates that the web server is not well maintained.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Test+Page+for+Apache%22+%22It+Worked%21%22[url]]
[[dork]intitle:"Test Page for Apache" "It Worked!"[dork]]
[end][108]]
[[start][109]
[[title]intitle:"Test Page for Apache" "It Worked!" "on this web"[title]]
[[descr]
This is the default web page for Apache 1.2.6 - 1.3.9. Hackers can use this information to determine the version of the web server, or to search Google for vulnerable targets. In addition, this indicates that the web server is not well maintained.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Test+Page+for+Apache%22+%22It+Worked%21%22+%22on+this+web%22[url]]
[[dork]intitle:"Test Page for Apache" "It Worked!" "on this web"[dork]]
[end][109]]
[[start][110]
[[title]"Can't connect to local" intitle:warning[[title]]
[[descr]
Another SQL error message, this message can display database name, path names and partial SQL code, all of which are very helpful for hackers...[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22Can%27t+connect+to+local%22+intitle%3Awarning[url]]
[[dork]"Can't connect to local" intitle:warning[dork]]
[end][110]]
[[start][111]
[[title]intitle:index.of dead.letter[[title]]
[[descr]
dead.letter contains the contents of unfinished emails created on the UNIX platform. Emails (finished or not) can contain sensitive information. [descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3Aindex.of+dead.letter[url]]
[[dork]intitle:index.of dead.letter[dork]]
[end][111]]
[[start][112]
[[title]intitle:index.of ws_ftp.ini[[title]]
[[descr]
ws_ftp.ini is a configuration file for a popular FTP client that stores usernames, (weakly) encoded passwords, sites and directories that the user can store for later reference. These should not be on the web![descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3Aindex.of+ws_ftp.ini[url]]
[[dork]intitle:index.of ws_ftp.ini[dork]]
[end][112]]
[[start][113]
[[title]intitle:index.of administrators.pwd[[title]]
[[descr]
This file contains administrative user names and (weakly) encrypted password for Microsoft Front Page. The file should not be readble to the general public.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3Aindex.of+administrators.pwd[url]]
[[dork]intitle:index.of administrators.pwd[dork]]
[end][113]]
[[start][114]
[[title]inurl:secring ext:skr | ext:pgp | ext:bak[[title]]
[[descr]
This file is the secret keyring for PGP encryption. Armed with this file (and perhaps a passphrase), a malicious user can read all your encrypted files! This should not be posted on the web![descr]]
[[url]http://www.google.com/search?q=inurl:secring+ext:skr+%7C+ext:pgp+%7C+ext:bak[url]]
[[dork]inurl:secring ext:skr | ext:pgp | ext:bak[dork]]
[end][114]]
[[start][115]
[[title]intitle:Index.of etc shadow[[title]]
[[descr]
This file contains usernames and (lame) encrypted passwords! Armed with this file and a decent password cracker, an attacker can crack passwords and log into a UNIX system.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3AIndex.of+etc+shadow[url]]
[[dork]intitle:Index.of etc shadow[dork]]
[end][115]]
[[start][116]
[[title]inurl:ManyServers.htm[[title]]
[[descr]
Microsoft Terminal Services Multiple Clients pages. These pages are not necessarily insecure, sine many layers of security can be wrapped around the actual use of this service, but simply being able to find these in Google gives hackers an informational advantage, and many of the sites are not implemented securely.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Amanyservers.htm[url]]
[[dork]inurl:manyservers.htm[dork]]
[end][116]]
[[start][117]
[[title]intitle:"Terminal Services Web Connection"[title]]
[[descr]
Microsoft Terminal Services Web Connector pages. These pages are not necessarily insecure, sine many layers of security can be wrapped around the actual use of this service, but simply being able to find these in Google gives hackers an informational advantage, and many of the sites are not implemented securely. In the worst case scenario these pages may allow an attacker to bypass a firewall gaining access to a "protected" machine.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Terminal+Services+Web+Connection%22[url]]
[[dork]intitle:"Terminal Services Web Connection"[dork]]
[end][117]]
[[start][118]
[[title]intitle:"Remote Desktop Web Connection"[title]]
[[descr]
Microsoft Remote Desktop Connection Web Connection pages. These pages are not necessarily insecure, sine many layers of security can be wrapped around the actual use of this service, but simply being able to find these in Google gives hackers an informational advantage, and many of the sites are not implemented securely. In the worst case scenario these pages may allow an attacker to bypass a firewall gaining access to an otherwise inaccessible machine.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Remote+Desktop+Web+Connection%22[url]]
[[dork]intitle:"Remote Desktop Web Connection"[dork]]
[end][118]]
[[start][119]
[[title]"Welcome to Intranet"[title]]
[[descr]
According to whatis.com: "An intranet is a private network that is contained within an enterprise. [...] The main purpose of an intranet is to share company information and computing resources among employees [...] and in general looks like a private version of the Internet." Intranets, by definition should not be available to the Internet's unwashed masses as they may contain private corporate information.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=%22Welcome+to+Intranet%22[url]]
[[dork]"Welcome to Intranet"[dork]]
[end][119]]
[[start][120]
[[title]inurl:search.php vbulletin[[title]]
[[descr]
Version 3.0.0 candidate 4 and earlier of Vbulletin may have a cross-site scripting vulnerability. See http://www.securityfocus.com/bid/9656
for more info. [descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Asearch.php+vbulletin[url]]
[[dork]inurl:search.php vbulletin[dork]]
[end][120]]
[[start][121]
[[title]inurl:footer.inc.php[[title]]
[[descr]
From http://www.securityfocus.com/bid/9664, the AllMyPHP family of products (Versions 0.1.2 - 0.4) contains several potential vulnerabilities, som elalowing an attacker to execute malicious code on the web server.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Afooter.inc.php[url]]
[[dork]inurl:footer.inc.php[dork]]
[end][121]]
[[start][122]
[[title]inurl:info.inc.php[[title]]
[[descr]
From http://www.securityfocus.com/bid/9664, the AllMyPHP family of products (Versions 0.1.2 - 0.4) contains several potential vulnerabilities, som elalowing an attacker to execute malicious code on the web server.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Ainfo.inc.php[url]]
[[dork]inurl:info.inc.php[dork]]
[end][122]]
[[start][123]
[[title]inurl:admin intitle:login[[title]]
[[descr]
This search can find administrative login pages. Not a vulnerability in and of itself, this query serves as a locator for administrative areas of a site. Further investigation of the surrounding directories can often reveal interesting information.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=inurl%3Aadmin+intitle%3Alogin[url]]
[[dork]inurl:admin intitle:login[dork]]
[end][123]]
[[start][124]
[[title]intitle:admin intitle:login[[title]]
[[descr]
This search can find administrative login pages. Not a vulnerability in and of itself, this query serves as a locator for administrative areas of a site. Further investigation of the surrounding directories can often reveal interesting information.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3Aadmin+intitle%3Alogin[url]]
[[dork]intitle:admin intitle:login[dork]]
[end][124]]
[[start][125]
[[title]filetype:asp "Custom Error Message" Category Source[[title]]
[[descr]
This is an ASP error message that can reveal information such as compiler used, language used, line numbers, program names and partial source code.[descr]]
[[url]http://www.google.com/search?q=filetype:asp+%22Custom+Error+Message%22+Category+Source&ie=UTF-8&oe=UTF-8[url]]
[[dork]filetype:asp "Custom Error Message" Category Source[dork]]
[end][125]]
[[start][126]
[[title]"Fatal error: Call to undefined function" -reply -the -next[[title]]
[[descr]
This error message can reveal information such as compiler used, language used, line numbers, program names and partial source code.[descr]]
[[url]http://www.google.com/search?q=%22Fatal+error:+Call+to+undefined+function%22+-reply+-the+-next&hl=en&lr=lang_en&ie=UTF-8&oe=UTF-8&start=10&sa=N[url]]
[[dork]"Fatal error: Call to undefined function" -reply -the -next[dork]]
[end][126]]
[[start][127]
[[title]inurl:admin filetype:xls[[title]]
[[descr]
This search can find Excel spreadsheets in an administrative directory or of an administrative nature. Many times these documents contain sensitive information.[descr]]
[[url]http://www.google.com/search?hl=en&lr=lang_en&ie=UTF-8&oe=UTF-8&q=inurl%3Aadmin+filetype%3Axls&btnG=Google+Search[url]]
[[dork]inurl:admin filetype:xls[dork]]
[end][127]]
[[start][128]
[[title]inurl:admin inurl:userlist[[title]]
[[descr]
This search reveals userlists of administrative importance. Userlists found using this method can range from benign "message group" lists to system userlists containing passwords.[descr]]
[[url]http://www.google.com/search?hl=en&lr=lang_en&ie=UTF-8&oe=UTF-8&q=inurl%3Aadmin+inurl%3Auserlist&btnG=Google+Search[url]]
[[dork]inurl:admin inurl:userlist[dork]]
[end][128]]
[[start][129]
[[title]inurl:admin filetype:asp inurl:userlist[[title]]
[[descr]
This search reveals userlists of administrative importance. Userlists found using this method can range from benign "message group" lists to system userlists containing passwords.[descr]]
[[url]http://www.google.com/search?hl=en&lr=lang_en&ie=UTF-8&oe=UTF-8&q=inurl%3Aadmin+filetype%3Aasp+inurl%3Auserlist&btnG=Google+Search[url]]
[[dork]inurl:admin filetype:asp inurl:userlist[dork]]
[end][129]]
[[start][130]
[[title]inurl:backup intitle:index.of inurl:admin[[title]]
[[descr]
This query reveals backup directories. These directories can contain various information ranging from source code, sql tables, userlists, and even passwords.[descr]]
[[url]http://www.google.com/search?hl=en&lr=lang_en&ie=UTF-8&oe=UTF-8&q=inurl%3Abackup+intitle%3Aindex.of+inurl%3Aadmin&btnG=Google+Search[url]]
[[dork]inurl:backup intitle:index.of inurl:admin[dork]]
[end][130]]
[[start][131]
[[title]"Welcome to PHP-Nuke" congratulations[[title]]
[[descr]
This finds default installations of the postnuke CMS system. In many cases, default installations can be insecure especially considering that the administrator hasn't gotten past the first few installation steps.[descr]]
[[url]http://www.google.com/search?q=%22Welcome+to+PHP-Nuke%22+congratulations&ie=UTF-8&oe=UTF-8[url]]
[[dork]"Welcome to PHP-Nuke" congratulations[dork]]
[end][131]]
[[start][132]
[[title]allintitle:Netscape FastTrack Server Home Page[[title]]
[[descr]
This finds default installations of Netscape Fasttrack Server. In many cases, default installations can be insecure especially considering that the administrator hasn't gotten past the first few installation steps.[descr]]
[[url]http://www.google.com/search?q=allintitle:Netscape+FastTrack+Server+Home+Page&ie=UTF-8&oe=UTF-8[url]]
[[dork]allintitle:Netscape FastTrack Server Home Page[dork]]
[end][132]]
[[start][133]
[[title]"Welcome to phpMyAdmin" " Create new database"[title]]
[[descr]phpMyAdmin is a widly spread webfrontend used to mantain sql databases. The default security mechanism is to leave it up to the admin of the website to put a .htaccess file in the directory of the application. Well gues what, obviously some admins are either too lazy or don't know how to secure their directories. These pages should obviously not be accessable to the public without some kind of password ;-)[descr]]
[[url]http://www.google.com/[url]]
[[dork][dork]]
[end][133]]
[[start][134]
[[title]intitle:"Index of c:\Windows"[title]]
[[descr]These pages indicate that they are sharing the C:\WINDOWS directory, which is the system folder for many Windows installations. [descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=ISO-8859-1&safe=off&q=intitle%3A%22Index+of+c%3A%5CWindows%22[url]]
[[dork]intitle:"Index of c:\Windows"[dork]]
[end][134]]
[[start][135]
[[title]warning "error on line" php sablotron[[title]]
[[descr]Sablotron is an XML toolit thingie. This query hones in on error messages generated by this toolkit. These error messages reveal all sorts of interesting stuff such as source code snippets, path and filename info, etc.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=ISO-8859-1&safe=off&q=warning+%22error+on+line%22+php+sablotron[url]]
[[dork]warning "error on line" php sablotron[dork]]
[end][135]]
[[start][136]
[[title]"Most Submitted Forms and Scripts" "this section"[title]]
[[descr]More www statistics on the web. This one is very nice.. Lots of directory info, and client access statistics, email addresses.. lots of good stuff.
These are SOOO dangerous, especially if INTRANET users get logged... talk about mapping out an intranet quickly...
[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=%22Most+Submitted+Forms+and+Scripts%22+%22this+section%22[url]]
[[dork]"Most Submitted Forms and Scripts" "this section"[dork]]
[end][136]]
[[start][137]
[[title]inurl:changepassword.asp[[title]]
[[descr]This is a common script for changing passwords. Now, this doesn't actually reveal the password, but it provides great information about the security layout of a server. These links can be used to troll around a website. [descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Achangepassword.asp&btnG=Google+Search[url]]
[[dork]inurl:changepassword.asp[dork]]
[end][137]]
[[start][138]
[[title]"Select a database to view" intitle:"filemaker pro"[title]]
[[descr]An oldie but a goodie. This search locates servers which provides access to Filemaker pro databases via the web. The severity of this search varies wildly depending on the security of the database itself. Regardless, if Google can crawl it, it's potentially using cleartext authentication. [descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22Select+a+database+to+view%22+intitle%3A%22filemaker+pro%22[url]]
[[dork]"Select a database to view" intitle:"filemaker pro"[dork]]
[end][138]]
[[start][139]
[[title]"not for distribution" confidential[[title]]
[[descr]The terms "not for distribution" and confidential indicate a sensitive document. Results vary wildly, but web-based documents are for public viewing, and should neither be considered confidential or private.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22not+for+distribution%22+confidential[url]]
[[dork]"not for distribution" confidential[dork]]
[end][139]]
[[start][140]
[[title]"Thank you for your purchase" +download[[title]]
[[descr]Many web-based businesses provide a method for customers to pay for and subsequently download software via the web. The post-purchase pages often contain the terms "Thank you for your purchase" and provide a link to download the purchased software. In many cases, these pages provide a method to download pay software without paying, a practice I do not advocate. [descr]]
[[url]http://www.google.com/search?ie=UTF-8&oe=UTF-8&q=%22Thank+you+for+your+purchase%22+%2Bdownload[url]]
[[dork]"Thank you for your purchase" +download[dork]]
[end][140]]
[[start][141]
[[title]"Thank you for your order" +receipt[[title]]
[[descr]After placing an order via the web, many sites provide a page containing the phrase "Thank you for your order" and provide a receipt for future reference. At the very least, these pages can provide insight into the structure of a web-based shop.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22Thank+you+for+your+order%22+%2Breceipt[url]]
[[dork]"Thank you for your order" +receipt[dork]]
[end][141]]
[[start][142]
[[title]allinurl:intranet admin[[title]]
[[descr]
According to whatis.com: "An intranet is a private network that is contained within an enterprise. [...] The main purpose of an intranet is to share company information and computing resources among employees [...] and in general looks like a private version of the Internet." Intranets, by definition should not be available to the Internet's unwashed masses as they may contain private corporate information. Some of these pages are simply portals to an Intranet site, which helps with information gathering.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=allinurl%3Aintranet+admin[url]]
[[dork]allinurl:intranet admin[dork]]
[end][142]]
[[start][143]
[[title]intitle:"Nessus Scan Report" "This file was generated by Nessus"[title]]
[[descr]This search yeids nessus scan reports. Even if some of the vulnerabilities have been fixed, we can still gather valuable information about the network/hosts. This also works with ISS and any other vulnerability scanner which produces reports in html or text format.[descr]]
[[url]http://www.google.com/search?q=%0Aintitle%3A%22Nessus+Scan+Report%22+%22This+file+was+generated+by+Nessus%22+[url]]
[[dork]
intitle:"Nessus Scan Report" "This file was generated by Nessus" [dork]]
[end][143]]
[[start][144]
[[title]intitle:"index.of.personal"[title]]
[[descr]This directory has various personal documents and pictures.[descr]]
[[url]http://www.google.com/search?hl=en&ie=UTF-8&oe=UTF-8&q=intitle%3A%22index.of.personal%22&btnG=Google+Search[url]]
[[dork]intitle:"index.of.personal"[dork]]
[end][144]]
[[start][145]
[[title]"This report lists" "identified by Internet Scanner"[title]]
[[descr]This search yeids ISS scan reports, revealing potential vulnerabilities on hosts and networks. Even if some of the vulnerabilities have been fixed, information about the network/hosts can still be gleaned. [descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=%22This+report+lists%22+%22identified+by+Internet+Scanner%22[url]]
[[dork]"This report lists" "identified by Internet Scanner"[dork]]
[end][145]]
[[start][146]
[[title]"Network Host Assessment Report" "Internet Scanner"[title]]
[[descr]This search yeids ISS scan reports, revealing potential vulnerabilities on hosts and networks. Even if some of the vulnerabilities have been fixed, information about the network/hosts can still be gleaned. [descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=%22Network+Host+Assessment+Report%22+%22Internet+Scanner%22[url]]
[[dork]"Network Host Assessment Report" "Internet Scanner"[dork]]
[end][146]]
[[start][147]
[[title]"Network Vulnerability Assessment Report"[title]]
[[descr]This search yeids vulnerability scanner reports, revealing potential vulnerabilities on hosts and networks. Even if some of the vulnerabilities have been fixed, information about the network/hosts can still be gleaned. [descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=%22Network+Vulnerability+Assessment+Report%22[url]]
[[dork]"Network Vulnerability Assessment Report"[dork]]
[end][147]]
[[start][148]
[[title]"Host Vulnerability Summary Report"[title]]
[[descr]This search yeids host vulnerability scanner reports, revealing potential vulnerabilities on hosts and networks. Even if some of the vulnerabilities have been fixed, information about the network/hosts can still be gleaned. [descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22Host+Vulnerability+Summary+Report%22+[url]]
[[dork]"Host Vulnerability Summary Report" [dork]]
[end][148]]
[[start][149]
[[title]intitle:index.of inbox[[title]]
[[descr]This search reveals potential location for mailbox files. In some cases, the data in this directory or file may be of a very personal nature and may include sent and received emails and archives of email data. [descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3Aindex.of+inbox[url]]
[[dork]intitle:index.of inbox[dork]]
[end][149]]
[[start][150]
[[title]intitle:index.of inbox dbx[[title]]
[[descr]This search reveals potential location for mailbox files. In some cases, the data in this directory or file may be of a very personal nature and may include sent and received emails and archives of email data. [descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3Aindex.of+inbox+dbx[url]]
[[dork]intitle:index.of inbox dbx[dork]]
[end][150]]
[[start][151]
[[title]intitle:index.of cleanup.log[[title]]
[[descr]This search reveals potential location for mailbox files by keying on the Outlook Express cleanup.log file. In some cases, the data in this directory or file may be of a very personal nature and may include sent and received emails and archives of email data. [descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3Aindex.of+inbox+dbx[url]]
[[dork]intitle:index.of inbox dbx[dork]]
[end][151]]
[[start][152]
[[title]"#mysql dump" filetype:sql[[title]]
[[descr]This reveals mySQL database dumps. These database dumps list the structure and content of databases, which can reveal many different types of sensitive information.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22%23mysql+dump%22+filetype%3Asql&btnG=Search[url]]
[[dork]"#mysql dump" filetype:sql[dork]]
[end][152]]
[[start][153]
[[title]allinurl:install/install.php[[title]]
[[descr]Pages with install/install.php files may be in the process of installing a new service or program. These servers may be insecure due to insecure default settings. In some cases, these servers may allow for a new installation of a program or service with insecure settings. In other cases, snapshot data about an install process can be gleaned from cached page images.[descr]]
[[url]http://www.google.com/[url]]
[[dork][dork]]
[end][153]]
[[start][154]
[[title]inurl:vbstats.php "page generated"[title]]
[[descr]This is your typical stats page listing referrers and top ips and such. This information can certainly be used to gather information about a site and its visitors.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=inurl%3Avbstats%2Ephp+%22page+generated%22[url]]
[[dork]inurl:vbstats.php "page generated"[dork]]
[end][154]]
[[start][155]
[[title]"index of" / lck[[title]]
[[descr]These lock files often contain usernames of the user that has locked the file. Username harvesting can be done using this technique.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=%22index+of%22+%2F+lck[url]]
[[dork]"index of" / lck[dork]]
[end][155]]
[[start][156]
[[title]"Index of" / "chat/logs"[title]]
[[descr]This search reveals chat logs. Depending on the contents of the logs, these files could contain just about anything![descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22Index+of%22+%2F+%22chat%2Flogs%22+[url]]
[[dork]"Index of" / "chat/logs" [dork]]
[end][156]]
[[start][157]
[[title]index.of perform.ini[[title]]
[[descr]This file contains information about the mIRC client and may include channel and user names.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=index%2Eof+perform%2Eini[url]]
[[dork]index.of perform.ini[dork]]
[end][157]]
[[start][158]
[[title]"SnortSnarf alert page"[title]]
[[descr]Snort is an intrusion detection system. SnorfSnarf creates pretty web pages from intrusion detection data. These pages show what the bad guys are doing to a system. Generally, it's a bad idea to show the bad guys what you've noticed.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=%22SnortSnarf+alert+page%22[url]]
[[dork]"SnortSnarf alert page"[dork]]
[end][158]]
[[start][159]
[[title]inurl:"newsletter/admin/" intitle:"newsletter admin"[title]]
[[descr]These pages generally contain newsletter administration pages. Some of these site are password protected, others are not, allowing unauthorized users to send mass emails to an entire mailing list.[descr]]
[[url]http://www.google.com/search?q=inurl:%22newsletter/admin/%22+intitle:%22newsletter+admin%22&hl=en[url]]
[[dork]inurl:"newsletter/admin/" intitle:"newsletter admin"[dork]]
[end][159]]
[[start][160]
[[title]inurl:"newsletter/admin/"[title]]
[[descr]These pages generally contain newsletter administration pages. Some of these site are password protected, others are not, allowing unauthorized users to send mass emails to an entire mailing list. This is a less acurate search than the similar intitle:"newsletter admin" search.[descr]]
[[url]http://www.google.com/search?q=inurl:%22newsletter/admin/%22+intitle:%22newsletter+admin%22[url]]
[[dork]inurl:"newsletter/admin/" intitle:"newsletter admin"[dork]]
[end][160]]
[[start][161]
[[title]inurl:phpSysInfo/ "created by phpsysinfo"[title]]
[[descr]This statistics program allows the an admin to view stats about a webserver. Some sites leave this in a publically accessible web page. Hackers could have access to data such as the real IP address of the server, server memory usage, general system info such as OS, type of chip, hard-drive makers and much more.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=inurl%3AphpSysInfo%2F+%22created+by+phpsysinfo%22[url]]
[[dork]inurl:phpSysInfo/ "created by phpsysinfo"[dork]]
[end][161]]
[[start][162]
[[title]allinurl: admin mdb[[title]]
[[descr]Not all of these pages are administrator's access databases containing usernames, passwords and other sensitive information, but many are![descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=allinurl%3A+admin+mdb+[url]]
[[dork]allinurl: admin mdb [dork]]
[end][162]]
[[start][163]
[[title]allinurl:"exchange/logon.asp"[title]]
[[descr]According to Microsoft "Microsoft (R) Outlook (TM) Web Access is a Microsoft Exchange Active Server Application that gives you private access to your Microsoft Outlook or Microsoft Exchange personal e-mail account so that you can view your Inbox from any Web Browser. It also allows you to view Exchange server public folders and the Address Book from the World Wide Web. Anyone can post messages anonymously to public folders or search for users in the Address Book. " Now, consider for a moment and you will understand why this could be potentially bad.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=allinurl%3A%22exchange%2Flogon.asp%22[url]]
[[dork]allinurl:"exchange/logon.asp"[dork]]
[end][163]]
[[start][164]
[[title]intitle:big.brother attention trouble unavailable offline[[title]]
[[descr]The "Big Brother" program shows so much information it's sickening! I mean ping data, connection headers, stat info... With an info page like this, an attacker hardly has to run any reconnaisance... they can just throw an attack.. sickening.[descr]]
[[url]http://www.google.com/search?num=100&q=intitle%3Abig.brother+attention+trouble+unavailable+offline[url]]
[[dork]intitle:big.brother attention trouble unavailable offline[dork]]
[end][164]]
[[start][165]
[[title]intitle:"Index of" cfide[[title]]
[[descr]This is the top level directory of ColdFusion, a powerful web development environment. This directory most likely contains sensitive information about a ColdFusion developed site.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=ISO-8859-1&safe=off&q=intitle%3A%22Index+of%22+cfide[url]]
[[dork]intitle:"Index of" cfide[dork]]
[end][165]]
[[start][166]
[[title]intitle:"ColdFusion Administrator Login"[title]]
[[descr]This is the default login page for ColdFusion administration. Although many of these are secured, this is an indicator of a default installation, and may be inherantly insecure. In addition, this search provides good information about the version of ColdFusion as well as the fact that ColdFusion is installed on the server.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=intitle%3A%22ColdFusion+Administrator+Login%22[url]]
[[dork]intitle:"ColdFusion Administrator Login"[dork]]
[end][166]]
[[start][167]
[[title]intitle:"Error Occurred" "The error occurred in" filetype:cfm[[title]]
[[descr]This is a typical error message from ColdFusion. A good amount of information is available from an error message like this including lines of source code, full pathnames, SQL query info, database name, SQL state info and local time info.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Error+Occurred%22+%22The+error+occurred+in%22+filetype%3Acfm[url]]
[[dork]intitle:"Error Occurred" "The error occurred in" filetype:cfm[dork]]
[end][167]]
[[start][168]
[[title]inurl:login.cfm[[title]]
[[descr]This is the default login page for ColdFusion. Although many of these are secured, this is an indicator of a default installation, and may be inherantly insecure. In addition, this search provides good information about the version of ColdFusion as well as the fact that ColdFusion is installed on the server.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=inurl%3Alogin%2Ecfm[url]]
[[dork]inurl:login.cfm[dork]]
[end][168]]
[[start][169]
[[title]filetype:cfm "cfapplication name" password[[title]]
[[descr]These files contain ColdFusion source code. In some cases, the pages are examples that are found in discussion forums. However, in many cases these pages contain live sourcecode with usernames, database names or passwords in plaintext.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=filetype%3Acfm+%22cfapplication+name%22+password[url]]
[[dork]filetype:cfm "cfapplication name" password[dork]]
[end][169]]
[[start][170]
[[title]inurl:":10000" intext:webmin[[title]]
[[descr]Webmin is a html admin interface for Unix boxes. It is run on a proprietary web server listening on the default port of 10000.
[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=inurl%3A%22%3A10000%22+intext%3Awebmin[url]]
[[dork]inurl:":10000" intext:webmin[dork]]
[end][170]]
[[start][171]
[[title]allinurl:/examples/jsp/snp/snoop.jsp[[title]]
[[descr]These pages reveal information about the server including path information, port information, etc.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=allinurl%3A%2Fexamples%2Fjsp%2Fsnp%2Fsnoop%2Ejsp[url]]
[[dork]allinurl:/examples/jsp/snp/snoop.jsp[dork]]
[end][171]]
[[start][172]
[[title]allinurl:servlet/SnoopServlet[[title]]
[[descr]These pages reveal server information such as port, server software version, server name, full paths, etc.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=allinurl%3Aservlet%2FSnoopServlet[url]]
[[dork]allinurl:servlet/SnoopServlet[dork]]
[end][172]]
[[start][173]
[[title]intitle:"Test Page for Apache"[title]]
[[descr]
This is the default web page for Apache 1.2.6 - 1.3.9. Hackers can use this information to determine the version of the web server, or to search Google for vulnerable targets. In addition, this indicates that the web server is not well maintained.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Test+Page+for+Apache+Installation%22[url]]
[[dork]intitle:"Test Page for Apache Installation"[dork]]
[end][173]]
[[start][174]
[[title]inurl:login.asp[[title]]
[[descr]This is a typical login page. It has recently become a target for SQL injection. Comsec's article at http://www.governmentsecurity.org/articles/SQLinjectionBasicTutorial.php brought this to my attention.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=inurl%3Alogin%2Easp[url]]
[[dork]inurl:login.asp[dork]]
[end][174]]
[[start][175]
[[title]inurl:/admin/login.asp[[title]]
[[descr]This is a typical login page. It has recently become a target for SQL injection. Comsec's article at http://www.governmentsecurity.org/articles/SQLinjectionBasicTutorial.php brought this to my attention.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3A%2Fadmin%2Flogin.asp+[url]]
[[dork]inurl:/admin/login.asp [dork]]
[end][175]]
[[start][176]
[[title]"Running in Child mode"[title]]
[[descr]This is a gnutella client that was picked up by google. There is a lot of data present including transfer statistics, port numbers, operating system, memory, processor speed, ip addresses, and gnutella client versions.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22Running+in+Child+mode%22+[url]]
[[dork]"Running in Child mode" [dork]]
[end][176]]
[[start][177]
[[title]"This is a Shareaza Node"[title]]
[[descr]These pages are from Shareaza client programs. Various data is displayed including client version, ip address, listening ports and uptime. [descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22This+is+a+Shareaza+Node%22[url]]
[[dork]"This is a Shareaza Node"[dork]]
[end][177]]
[[start][178]
[[title]"VNC Desktop" inurl:5800[[title]]
[[descr]VNC is a remote-controlled desktop product. Depending on the configuration, remote users may not be presented with a password. Even when presented with a password, the mere existance of VNC can be important to an attacker, as is the open port of 5800.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=%22VNC+Desktop%22+inurl%3A5800[url]]
[[dork]"VNC Desktop" inurl:5800[dork]]
[end][178]]
[[start][179]
[[title]"index of cgi-bin"[title]]
[[descr]CGI directories contain scripts which can often be exploited by attackers. Regardless of the vulnerability of such scripts, a directory listing of these scripts can prove helpful.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=%22index+of+cgi%2Dbin%22[url]]
[[dork]"index of cgi-bin"[dork]]
[end][179]]
[[start][180]
[[title]intitle:Snap.Server inurl:Func=[[title]]
[[descr]This page reveals the existance of a SNAP server (Netowrk attached server or NAS devices) Depending on the configuration, these servers may be vulnerable, but regardless the existance of this server is useful for information gathering.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3ASnap.Server+inurl%3AFunc%3D[url]]
[[dork]intitle:Snap.Server inurl:Func=[dork]]
[end][180]]
[[start][181]
[[title]inurl:server-status "apache"[title]]
[[descr]This page shows all sort of information about the Apache web server. It can be used to track process information, directory maps, connection data, etc.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=inurl%3Aserver%2Dstatus+%22apache%22[url]]
[[dork]inurl:server-status "apache"[dork]]
[end][181]]
[[start][182]
[[title]eggdrop filetype:user user[[title]]
[[descr]These are eggdrop config files. Avoiding a full-blown descussion about eggdrops and IRC bots, suffice it to say that this file contains usernames and passwords for IRC users.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=eggdrop+filetype%3Auser+user[url]]
[[dork]eggdrop filetype:user user[dork]]
[end][182]]
[[start][183]
[[title]intitle:"index of" intext:connect.inc[[title]]
[[descr]These files often contain usernames and passwords for connection to mysql databases. In many cases, the passwords are not encoded or encrypted.[descr]]
[[url]http://www.google.com/search?q=intitle:%22index+of%22+intext:connect.inc+&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=10&sa=N[url]]
[[dork]intitle:"index of" intext:connect.inc [dork]]
[end][183]]
[[start][184]
[[title]intitle:"MikroTik RouterOS Managing Webpage"[title]]
[[descr]This is the front page entry point to a "Mikro Tik" Router.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22MikroTik+RouterOS+Managing+Webpage%22+[url]]
[[dork]intitle:"MikroTik RouterOS Managing Webpage" [dork]]
[end][184]]
[[start][185]
[[title]inurl:fcgi-bin/echo[[title]]
[[descr]This is the fastcgi echo script, which provides a great deal of information including port numbers, server software versions, port numbers, ip addresses, path names, file names, time zone, process id's, admin email, fqdns, etc![descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Afcgi-bin%2Fecho[url]]
[[dork]inurl:fcgi-bin/echo[dork]]
[end][185]]
[[start][186]
[[title]inurl:cgi-bin/printenv[[title]]
[[descr]This is the print environemnts script which lists sensitive information such as path names, server names, port numbers, server software and version numbers, administrator email addresses and more.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Acgi-bin%2Fprintenv[url]]
[[dork]inurl:cgi-bin/printenv[dork]]
[end][186]]
[[start][187]
[[title]intitle:"Execution of this script not permitted"[title]]
[[descr]This is a cgiwrap error message which displays admin name and email, port numbers, path names, and may also include optional information like phone numbers for support personnel.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Execution+of+this+script+not+permitted%22+Contact+phone[url]]
[[dork]intitle:"Execution of this script not permitted" Contact phone[dork]]
[end][187]]
[[start][188]
[[title]inurl:perl/printenv[[title]]
[[descr]This is the print environemnts script which lists sensitive information such as path names, server names, port numbers, server software and version numbers, administrator email addresses and more.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Aperl%2Fprintenv[url]]
[[dork]inurl:perl/printenv[dork]]
[end][188]]
[[start][189]
[[title]inurl:j2ee/examples/jsp[[title]]
[[descr]This directory contains sample JSP scripts which are installed on the server. These programs may have security vulnerabilities and can be used by an attacker to footprint the server.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Aj2ee%2Fexamples%2Fjsp[url]]
[[dork]inurl:j2ee/examples/jsp[dork]]
[end][189]]
[[start][190]
[[title]inurl:ojspdemos[[title]]
[[descr]This directory contains sample Oracle JSP scripts which are installed on the server. These programs may have security vulnerabilities and can be used by an attacker to footprint the server.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Aojspdemos[url]]
[[dork]inurl:ojspdemos[dork]]
[end][190]]
[[start][191]
[[title]inurl:server-info "Apache Server Information"[title]]
[[descr]This is the Apache server-info program. There is so much sensitive stuff listed on this page that it's hard to list it all here. Some informatino listed here includes server version and build, software versions, hostnames, ports, path info, modules installed, module info, configuration data and so much more....[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Aserver-info+%22Apache+Server+Information%22[url]]
[[dork]inurl:server-info "Apache Server Information"[dork]]
[end][191]]
[[start][192]
[[title]inurl:admin_/globalsettings.htm[[title]]
[[descr]This page is a part of the Oracle HTTP Listener and potentially allows for the modification of settings on the server. If the application is secured, this page at least allows for footprinting of the server.[descr]]
[[url]http://www.google.com/search?&ie=UTF-8&oe=UTF-8&q=inurl%3Aadmin%5F%2Fglobalsettings%2Ehtm[url]]
[[dork]inurl:admin_/globalsettings.htm[dork]]
[end][192]]
[[start][193]
[[title]inurl:pls/admin_/gateway.htm[[title]]
[[descr]This is a default login portal used by Oracle. In addition to the fact that this file can be used to footprint a web server and determine it's version and software, this page has been targeted in many vulnerability reports as being a source of an SQL injection vulnerability. This problem, when exploited can lead to unauthorized privileges to the databse. In addition, this page may allow unauthorized modification of parameters on the server.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Apls%2Fadmin_%2Fgateway.htm+[url]]
[[dork]inurl:pls/admin_/gateway.htm [dork]]
[end][193]]
[[start][194]
[[title]inurl:/pls/sample/admin_/help/[[title]]
[[descr]This is the default installation location of Oracle manuals. This helps in footprinting a server, allowing an attacker to determine software version information which may aid in an attack.[descr]]
[[url]http://www.google.com/search?q=inurl:/pls/sample/admin_/help/&hl=en&lr=&ie=UTF-8&oe=UTF-8&filter=0[url]]
[[dork]inurl:/pls/sample/admin_/help/[dork]]
[end][194]]
[[start][195]
[[title]intitle:"Gateway Configuration Menu"[title]]
[[descr]This is a normally protected configuration menu for Oracle Portal Database Access Descriptors (DADs) and Listener settings. This page is normally password protected, but Google has uncovered sites which are not protected. Attackers can make changes to the servers found with this query.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Gateway+Configuration+Menu%22[url]]
[[dork]intitle:"Gateway Configuration Menu"[dork]]
[end][195]]
[[start][196]
[[title]intitle:"Remote Desktop Web Connection" inurl:tsweb[[title]]
[[descr]This is the login page for Microsoft's Remote Desktop Web Connection, which allows remote users to connect to (and optionally control) a user's desktop. Although authentication is built into this product, it is still possible to run this service without authentication. Regardless, this search serves as a footprinting mechanisms for an attacker.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3ARemote.Desktop.Web.Connection+inurl%3Atsweb[url]]
[[dork]intitle:Remote.Desktop.Web.Connection inurl:tsweb[dork]]
[end][196]]
[[start][197]
[[title]inurl:php inurl:hlstats intext:"Server Username"[title]]
[[descr]This page shows the halflife stat script and reveals the username to the system. Table structure, database name and recent SQL queries are also shown on most systems.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Aphp+inurl%3Ahlstats+intext%3A%22Server+Username%22[url]]
[[dork]inurl:php inurl:hlstats intext:"Server Username"[dork]]
[end][197]]
[[start][198]
[[title]intext:"Tobias Oetiker" "traffic analysis"[title]]
[[descr]This is the MRTG traffic analysis pages. This page lists information about machines on the network including CPU load, traffic statistics, etc. This information can be useful in mapping out a network. [descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intext%3A%22Tobias+Oetiker%22+%22traffic+analysis%22[url]]
[[dork]intext:"Tobias Oetiker" "traffic analysis"[dork]]
[end][198]]
[[start][199]
[[title]inurl:tdbin[[title]]
[[descr]This is the default directory for TestDirector (http://www.mercuryinteractive.com/products/testdirector/). This program contains sensitive information including software defect data which should not be publically accessible.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Atdbin[url]]
[[dork]inurl:tdbin[dork]]
[end][199]]
[[start][200]
[[title]+intext:"webalizer" +intext:"Total Usernames" +intext:"Usage Statistics for"[title]]
[[descr]The webalizer program displays various information but this query displays usernames that have logged into the site. Attckers can use this information to mount an attack.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=Google+for%3A+%2Bintext%3A%22webalizer%22+%2Bintext%3A%22Total+Usernames%22+%2Bintext%3A%22Usage+Statistics+for%22[url]]
[[dork]Google for: +intext:"webalizer" +intext:"Total Usernames" +intext:"Usage Statistics for"[dork]]
[end][200]]
[[start][201]
[[title]inurl:perform filetype:ini[[title]]
[[descr]Displays the perform.ini file used by the popular irc client mIRC. Often times has channel passwords and/or login passwords for nickserv.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Aperform+filetype%3Aini&btnG=Search[url]]
[[dork]inurl:perform filetype:ini[dork]]
[end][201]]
[[start][202]
[[title]intitle:"index of" intext:globals.inc[[title]]
[[descr]contains plaintext user/pass for mysql database[descr]]
[[url]http://www.google.com/search?hl=nl&ie=UTF-8&oe=UTF-8&q=intitle%3A%22index+of%22+intext%3Aglobals.inc&lr=[url]]
[[dork]intitle:"index of" intext:globals.inc[dork]]
[end][202]]
[[start][203]
[[title]filetype:pdf "Assessment Report" nessus[[title]]
[[descr]These are reports from the Nessus Vulnerability Scanner. These report contain detailed information about the vulnerabilities of hosts on a network, a veritable roadmap for attackers to folow.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=filetype%3Apdf+%22Assessment+Report%22+nessus[url]]
[[dork]filetype:pdf "Assessment Report" nessus[dork]]
[end][203]]
[[start][204]
[[title]inurl:"smb.conf" intext:"workgroup" filetype:conf conf[[title]]
[[descr]These are samba configuration files. They include information about the network, trust relationships, user accounts and much more. Attackers can use this information to recon a network.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3A%22smb.conf%22+intext%3A%22workgroup%22+filetype%3Aconf+conf[url]]
[[dork]inurl:"smb.conf" intext:"workgroup" filetype:conf conf[dork]]
[end][204]]
[[start][205]
[[title]intitle:"Samba Web Administration Tool" intext:"Help Workgroup"[title]]
[[descr]This search reveals wide-open samba web adminitration servers. Attackers can change options on the server.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=intitle%3A%22Samba+Web+Administration+Tool%22+intext%3A%22Help+Workgroup%22[url]]
[[dork]intitle:"Samba Web Administration Tool" intext:"Help Workgroup"[dork]]
[end][205]]
[[start][206]
[[title]filetype:properties inurl:db intext:password[[title]]
[[descr]The db.properties file contains usernames, decrypted passwords and even hostnames and ip addresses of database servers. This is VERY severe, earning the highest danger rating.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=filetype%3Aproperties+inurl%3Adb+intext%3Apassword[url]]
[[dork]filetype:properties inurl:db intext:password[dork]]
[end][206]]
[[start][207]
[[title]inurl:names.nsf?opendatabase[[title]]
[[descr]A Login portal for Lotus Domino servers. Attackers can attack this page or use it to gather information about the server.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3Anames.nsf%3Fopendatabase[url]]
[[dork]inurl:names.nsf?opendatabase[dork]]
[end][207]]
[[start][208]
[[title]"index of" inurl:recycler[[title]]
[[descr]This is the default name of the Windows recycle bin. The files in this directory may contain sensitive information. Attackers can also crawl the directory structure of the site to find more information. In addition, the SID of a user is revealed also. An attacker could use this in a variety of ways.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22index+of%22+inurl%3Arecycler[url]]
[[dork]"index of" inurl:recycler[dork]]
[end][208]]
[[start][209]
[[title]filetype:conf inurl:firewall -intitle:cvs[[title]]
[[descr]These are firewall configuration files. Although these are often examples or sample files, in many cases they can still be used for information gathering purposes.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=filetype%3Aconf+inurl%3Afirewall+-intitle%3Acvs[url]]
[[dork]filetype:conf inurl:firewall -intitle:cvs[dork]]
[end][209]]
[[start][210]
[[title]filetype:inc intext:mysql_connect[[title]]
[[descr]INC files have PHP code within them that contain unencrypted usernames, passwords, and addresses for the corresponding databases. Very dangerous stuff. The mysql_connect file is especially dangerous because it handles the actual connection and authentication with the database.[descr]]
[[url]http://www.google.com/search?hl=en&ie=UTF-8&oe=UTF-8&q=filetype%3Ainc+intext%3Amysql_connect[url]]
[[dork]filetype:inc intext:mysql_connect[dork]]
[end][210]]
[[start][211]
[[title]"HTTP_FROM=googlebot" googlebot.com "Server_Software="[title]]
[[descr]These pages contain trace information that was collected when the googlebot crawled a page. The information can include many different things such as path names, header information, server software versions and much more. Attackers can use information like this to formulate an attack against a site.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22HTTP_FROM%3Dgooglebot%22++googlebot.com+%22Server_Software%3D%22[url]]
[[dork]"HTTP_FROM=googlebot" googlebot.com "Server_Software="[dork]]
[end][211]]
[[start][212]
[[title]"Request Details" "Control Tree" "Server Variables"[title]]
[[descr]These pages contain a great deal of information including path names, session ID's, stack traces, port numbers, ip addresses, and much much more. Attackers can use this information to formulate a very advanced attack against these targets.[descr]]
[[url]http://www.google.com/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=%22Request+Details%22+%22Control+Tree%22+%22Server+Variables%22[url]]
[[dork]"Request Details" "Control Tree" "Server Variables"[dork]]
[end][212]]
[[start][213]
[[title]filetype:reg reg +intext:"defaultusername" +intext:"defaultpassword"[title]]
[[descr]These pages display windows registry keys which reveal passwords and/or usernames.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=filetype%3Areg+reg+%2Bintext%3A%22defaultusername%22+%2Bintext%3A%22defaultpassword%22[url]]
[[dork]filetype:reg reg +intext:"defaultusername" +intext:"defaultpassword"[dork]]
[end][213]]
[[start][214]
[[title]inurl:metaframexp/default/login.asp | intitle:"Metaframe XP Login"[title]]
[[descr]These are Citrix Metaframe login portals. Attackers can use these to profile a site and can use insecure setups of this application to access the site.[descr]]
[[url]http://www.google.com/search?hl=en&q=inurl%3Ametaframexp%2Fdefault%2Flogin.asp+%7C+intitle%3A%22Metaframe+XP+Login%22[url]]
[[dork]inurl:metaframexp/default/login.asp | intitle:"Metaframe XP Login"[dork]]
[end][214]]
[[start][215]
[[title]inurl:/Citrix/Nfuse17/[[title]]
[[descr]These are Citrix Metaframe login portals. Attackers can use these to profile a site and can use insecure setups of this application to access the site.[descr]]
[[url]http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=inurl%3A%2FCitrix%2FNfuse17%2F+[url]]
[[dork]inurl:/Citrix/Nfuse17/ [dork]]
[end][215]]
[