|
-: Google Hacking :-
1) Google Search :- "Active
Webcam Page" inurl:8080
Description- Active WebCam is a shareware program for capturing and sharing
the video streams from a lot of video devices. Known bugs: directory traversal
and cross site scripting.
2) Google Search :- "delete
entries" inurl:admin/delete.asp
Description- AspJar contains a flaw that may allow a malicious user to delete
arbitrary messages. The issue is triggered when the authentication method
is bypassed and /admin/delete.asp is accessed directly. It is possible that
the flaw may allow a malicious user to delete messages resulting in a loss
of integrity.
3) Google Search :- "phone
* * *" "address *" "e-mail" intitle:"curriculum
vitae"
Description- This search gives hundreds of existing curriculum vitae with
names and address. An attacker could steal identity if there is an SSN in
the document.
4) Google Search :- inurl:*.exe
ext:exe inurl:/*cgi*/
Description- a cgi-bin executables xss/asp injection miscellanea: some
examples: inurl:keycgi.exe ext:exe inurl:/*cgi*/ xss: http://[target]/[path]/cgi-bin/keycgi.exe?
cmd=download&product=">[XSS HERE]
inurl:wa.exe ext:exe inurl:/*cgi*/ xss:
http://[target]/[path]/cgi-bin/wa.exe?SUBED1=">[XSS HERE] inurl:mqinterconnect.exe
ext:exe inurl:/*cgi*/ xss: http://[target]/[path]/cgi-bin/mqinterconnect.exe? poi1iconid=11111&poi1streetaddress=">[XSS HERE] &poi1city=city&poi1state=OK
5) Google Search :- intitle:"index
of" finance.xls
Description- Secret financial spreadsheets 'finance.xls' or 'finances.xls'
of companies may revealed by this query.
6) Google Search :- intitle:"index.of"
robots.txt
Description- The robots.txt file contains "rules" about where
web spiders are allowed (and NOT allowed) to look in a website's directory
structure. Without over-complicating things, this means that the robots.txt
file gives a mini-roadmap of what's somewhat public and what's considered
more private on a web site. Have a look at the robots.txt file itself, it
contains interesting stuff. However, don't forget to check out the other
files in these directories since they are usually at the top directory level
of the web server!
7) Google Search :- intitle:index.of.admin
Description- Locate "admin" directories that are accessible from
directory listings.
8) Google Search :- inurl:"nph-proxy.cgi" "start browsing"
Description- Returns lots of proxy servers that protects your identity online.
|
|
|
|
|
|