Google Hacking Database
Google Hacking Database
Google Hacking Database
Sensitive Directories
Google's collection of web sites sharing sensitive directories. The files contained in here will vary from sesitive
to uber-secret!
DATE
Title
Summary
2003What kinds of things might you find in directories marked
private
06-27
"private?" let's find out.....
2003What kinds of goodies lurk in directories marked as
secret
06-27
"secret?" Find out......
2003Backup directories are often very interesting places to
Look in my backup directories! Please?
06-24
explore. More than one server has been ...
2004Adding "inurl:ftp (pub | incoming)" to the "index.of"
intitle:"index of" inurl:ftp (pub | inco...
12-30
searches helps locati...
2004allinurl:"/*/_vti_pvt/" | allinurl:"...
Frontpage extensions for Unix ? So be it.....
12-29
2004These directories reveal the configuration file of the abyss
intitle:index.of abyss.conf
12-19
webserver. These files can contain...
2004With ColdFusion, you can build and deploy powerful web
intitle:"Index of /CFIDE/" administrator
12-19
applications and web services with far l...
2004Invision Power File Manager is a popular file
"Powered by Invision Power File Manager"...
12-19
management script, written in the popular PHP Scr...
2004This search uses desktop.ini to track users with a
intitle:"index of" "parent director...
12-05
webserver running on their desktop computers...
2004TotalIndex v2.0 is an open source script that is designed
intext:"Powered By: TotalIndex" intitle:...
11-28
to replace the simple, and boring def...
2004This search looks for indexes with the following
"intitle:Index.Of /" stats merchant cgi-...
11-07
subdirectories: stats, merchant, online-store ...
2004This dork indicates the "Local settings" dir in most cases,
intitle:"index of" intext:"content....
10-31
and browseble server dire...
2004Yes! I probably have should have told you guys earlier,
intitle:"index of" -inurl:htm -inurl:htm...
10-20
but this is how ive been getting 100% ...
2004The DCIM directory is the default name for a few brands
index.of.dcim
10-25
of digital camers. This is not a big ne...
2004The Google Hackers Guide explains how to find Apache
intitle:"Directory Listing For" intext:T...
10-19
directory indexes, which are the most comm...
2004Webadmin.php is a free simple Web-based file manager.
intitle:"webadmin - /*" filetype:php dir...
09-24
This search finds sites that use this sof...
2004- intitle:index.of (inurl:fileadmin |
TYPO3 is a free Open Source content management
09-21 intitle:filead...
2004intitle:"Index of *" inurl:"my shar...
09-10
2004intitle:index.of /AlbumArt_
08-26
200408-05
200407-20
200407-16
200410-31
200407-12
200406-14
200406-02
200406-01
200405-13
200405-11
200405-04
200404-28
200404-28
200404-28
200404-23
200404-19
200403-29
200402-10
200308-12
200403-16
200306-27
2003-
intext:"d.aspx?id" || inurl:"d.aspx...
"index of" / picasa.ini
index.of.password
inurl:explorer.cfm inurl:(dirpath|
This_Directory)
06-27
200306-27
200306-27
201505-27
201505-26
201504-23
201504-03
201504-03
201502-27
201502-19
201502-11
201501-06
201402-05
201311-25
201309-24
201308-08
201308-08
201308-08
201304-09
201304-09
201211-02
201111-19
201011-10
201011-10
201011-10
secure
winnt
inurl:wp-admin/ intext:css/
intitle:"Index of ftp"
find out......
What could be hiding in directories marked as "secure?"
let's find out......
The \WINNT directory is the directory that Windows NT
is installed into by default. Now just be...
The dork finds misconfigured WordPress sites.
Author:NickiK. ...
This dork finds open ftps. This is a base dork, where you
can add intext:"ssh/" for ...
intitle:index.of.dropbox
intitle:index.of.accounts
intitle:index.of +"Indexed by
Apache::Gallery...
inurl:/wp-content/wpbackitup_backups
"Config" intitle:"Index of" in...
inurl:/cgi-bin/.cgi
allinurl:/hide_my_wp=
intitle:"index of" intext:".ds_stor...
intitle:"index of" myshare
inurl:8080 intitle:"Dashboard [Jenkins]"
intitle:index.of intext:.bash_history
intext:xampp-dav-unsecure:
$apr1$6O9scpDQ$JGw2Tjz0j...
"index of" inurl:sym
"index of" inurl:root intitle:symlink
inurl:ckfinder intext:"ckfinder.html" in...
inurl:/xampp
200607-14
200602-28
200601-16
200512-01
200511-28
200511-11
200509-26
200509-26
200509-13
200507-21
200505-02
200503-26
200502-17
200501-16
200501-09
200501-07
200501-05
200501-01
201611-29
201611-29
201610-04
201608-08
201607-27
201606-06
2016-
06-06
2016inurl:/sites/default/files/webform/
05-10
2016intitle:Index of /__MACOSX ...
04-21
2016(intext:"index of /.git") ("parent ...
03-22
2016inurl:safm.asp ext:asp
03-07
201601-06
201512-21
201511-13
201511-11
201511-11
201511-02
201510-30
201510-22
201510-22
201510-20
201510-19
201510-19
201510-19
201510-16
201510-16
201510-16
201509-17
201509-10
201509-07
2015-
Decoy ...
Description: Drupal default web-forms' storage path,
usually a lot of files there contains juic...
MAC OS X. Parent Directory Wordpress information.
-Xploit ...
This dork will find git repository's which may have
sensitive information. (intext:"ind...
inurl:safm.asp ext:asp
http://atawho.blogspot.com.tr/2016/03/simple-aspfilemanager.html ...
Awstats Log file's directory can reveal file/directory
location These logs file may also revea...
Google Search: inurl:/server/webapps Submission Date:
12/19/2015 Description: Apache Tomcat...
Dork with juicy info. Enjoy xD. Dork by Rootkit
Pentester. ...
inurl:"wp-content/uploads/private"
http://www.google.com/search?q=intitle:index.of parent
inurl:repos Shared repositories. Very...
http://www.google.com/search?q="Desktop" parent
intitle:index.of Desktops shared o...
http://www.google.com/search?q="My Documents"
"parent" intitle:index.of ...
Directories containing SQL Installs and/or SQL
databases... Decoy ...
Google dork Description: Juice Directory "ASP" Google
search: inurl:/aspnet_client/s...
inurl:.DS_Store intitle:index.of
inurl:.listing intitle:index.of
inurl:users intitle:index.of
private parent intitle:index.of
mail spool intitle:index.of
inurl:"default.php" intext:"website...
intitle:"Index.of" "attachments&quo...
intitle:"Index of" "WhatsApp Databa...
inurl:"/cms/app/webroot"
http://www.google.com/search?q=inurl:users
intitle:index.of User folders containing interest...
http://www.google.com/search?q=private parent
intitle:index.of Dork for all sorts of juicy s...
Dork for mail spools. Decoy ...
Dork= inurl:"default.php" intext:"website" "has been
successfully inst...
Directories with interesting info. Have Fun Responsible.
Dork by Rootkit Pentester. ...
this dork find db.crypt/.db files of whatsapp conversations
you can open them with https://co...
inurl:"/cms/app/webroot" Author:ShockvaWe (mrnoone)
09-01
201508-24
201508-19
201508-10
201507-09
201506-30
201506-17
201506-17
201506-10
201506-04
zm ...
WhatsApp Images folder, usually from backups.
--pmbento ...
A lot of Camera Photos Dump. Have Fun!. Rootkit. ...
Dork: intext:index of sym Most of hacker use auto server
symlink script and grab all the con...
Exploit title: intitle:index.of.pubs Description:
intitle:index.of.pubs Sensitive Directories...
inurl:private_files
https://www.exploit-db.com/google-hacking-database/3/?pg=1
Table of Contents:
Footholds
Files containing usernames
Sensitive Directories
Web Server Detection
Vulnerable Files
Vulnerable Servers
Error Messages
Files containing juicy info
Files containing passwords
Sensitive Online Shopping Info
Network or vulnerability data
Pages containing login portals
Various Online Devices
credit http://www.exploit-db.com/google-dorks/
2014-04intitle:Zimbra Web Client Sign In
21
2014-04inurl:typo3/install/index.php?mode=
07
2014-04inurl:typo3conf/localconf.php
07
2013inurl:1337w0rm.php intitle:1337w0rm
08-08
2012inurl:r00t.php
11-02
2012intitle:C0ded By web.sniper
11-02
User & Domain || Symlink Using this dork you can find t
User and the Domains of the Serv
2012intitle:Priv8 SCR
11-02
2011- inurl:amfphp/browser/servicebrowser.swf
AMFPHP service browser, debug interface. Author: sydd
09-26
2011allintext:fs-admin.php
01-09
searches for scripts that let you upload files which you
then execute on the server.
2006inurl:tmtrack.dll?
01-04
2005inurl:polly/CP
10-06
2004- inurl:phpOracleAdmin/php
12-19 -download -cv
2004- PHPKonsole PHPShell filetype:php PHPKonsole is just a little telnet like shell wich allows you to ru
11-28 -echo
commands on the webserver.
2004- filetype:php HAXPLORER Server
11-28 Files Browser&
2004- inurl:ConnectComputer/precheck.h Windows Small Business Server 2003: The network configurati
11-06 tm | inurl:Remote/
page is called ConnectCompu
2004- (inurl:81/cgi-bin/.cobalt/) |
10-22 (intext:Welco
The famous Sun linux appliance. The default page displays thi
text:Congratulations on Ch
PHP Shell is a shell wrapped in a PHP script. Its a tool you can
to execute arbiritary she
2003intitle:admin intitle:login
09-09
Admin Login pages. Now, the existance of this page does not
necessarily mean a server is vulner
2013- intext:root:x:0:0:root:/root:/bin/bash
Author: ./tic0 | Izzudin al-Qassam Cyber Fighter
04-22
2013inurl:/root/etc/passwd intext:ho inurl:/root/etc/passwd intext:home/*:
04-22
2006- site:extremetracking.com
07-31 inurl:login=
2005- intext:SteamUserPassphrase=
06-05 intext:&qu
These log files record info about the SSH client PUTTY. These
files contain usernames, site nam
This page shows the halflife stat script and reveals the
username to the system. Table structur
2004index.of perform.ini
04-13
This file contains information about the mIRC client and may
include channel and user names.
2004index of / lck
04-13
2003sh_history files
06-24
2003bash_history files
06-24
2014allinurl:/hide_my_wp=
02-05
2013intitle:index of intext:.ds_stor
11-25
2013intitle:index of myshare
09-24
2013intitle:index.of intext:.bash_history
08-08
2013- intext:xampp-dav-unsecure:
08-08 $apr1$6O9scpDQ$JGw2Tjz0j
2013index of inurl:sym
04-09
2011inurl:/xampp
11-19
2010allintext:WebServerX Server at
11-10
2006intitle:index.of.config
07-14
2006allintitle:FirstClass Login
02-28
2005Directory Listing for Hosted by directory listing for Xerver web server
09-26
2005- intitle:Folder Listing
09-26 Folder Li
2005- intitle:Backup09-13 Management
(phpMyBackup v.0.4
to a different server u
2005- intitle:pictures
This search reveals the photo albums taken by Sprint PCS customers.
07-21 thumbnails site:pictu Pictures taken with Sprint
2005Finds java powered web servers which have indexing enabled on their co
intitle:index.of WEB-INF
05-02
directory
2005- intitle:index.of
03-26 /maildir/new/
This dork finds any webshared windows folder inside my docs. You can
change the end bit i
2005filetype:torrent torrent
01-16
Torrent files .. dont expect to find spectacular stuff with this kind of strin
this just to
2005- Web File Browser Use This will ask google to search for a php script used to manage files on a
01-07 regular exp
server. The script &q
2005- intitle:HFS /
01-05 +HttpFileServer&qu
intitle:upload
2005The search reveals server upload portals.An attacker can use server spa
inurl:upload
01-01
for his own benefit.
intext:upload -forum -
2004- intitle:index.of
12-19 abyss.conf
2004- intitle:Index of /CFIDE/ With ColdFusion, you can build and deploy powerful web applications an
12-19 administrator
web services with far l
2004- Powered by Invision
12-19 Power File Manager
2004- intitle:index of parent This search uses desktop.ini to track users with a webserver running on
12-05 director
desktop computers
2004- intext:Powered By:
11-28 TotalIndex intitle:
2004- intitle:Index.Of / stats This search looks for indexes with the following subdirectories: stats,
11-07 merchant cgi-
merchant, online-store
2004- intitle:index of
10-31 intext:content.
This dork indicates the Local settings dir in most cases, and browseble
server dire
Yes! I probably have should have told you guys earlier, but this is ho
ive been getting 100%
2004index.of.dcim
10-25
The DCIM directory is the default name for a few brands of digital
camers. This is not a big ne
2004- intitle:Directory Listing For The Google Hackers Guide explains how to find Apache directory
10-19 intext:T
indexes, which are the most comm
2004- intitle:webadmin /*
09-24 filetype:php dir
intitle:index.of
2004(inurl:fileadmin |
09-21
intitle:filead
2004- intitle:Index of * inurl:my These are index pages of My Shared Folder. Sometimes they conta
09-10 shar
juicy stuff like
2004intitle:index.of /AlbumArt_
08-26
2004- intext:d.aspx?id ||
08-05 inurl:d.aspx
2004index of / picasa.ini
07-20
2004index.of.password
07-16
2004Index of phpMyAdmin
07-12
2004- filetype:cfg ks intext:rootpw Anaconda is a linux configuration tool like yast on suse linux. The ro
06-14 -sample -test -howto
password is often encr
2004- intitle:album permissions
06-02 Users
Many times, this search will reveal temporary files and directories on
web server. The info
2004index of inurl:recycler
05-04
This is the default name of the Windows recycle bin. The files in this
directory may contain se
2004- inurl:/pls/sample/admin_/hel This is the default installation location of Oracle manuals. This helps
04-28 p/
footprinting a serve
2004- inurl:ojspdemos
This directory contains sample Oracle JSP scripts which are installed
04-28
2004inurl:j2ee/examples/jsp
04-28
This directory contains sample JSP scripts which are installed on the ser
These programs ma
2004index of cgi-bin
04-23
2004intitle:Index of cfide
04-19
These pages indicate that they are sharing the C:\WINDOWS directory,
which is the system folder
Welcome to
2003phpMyAdmin Create
08-12
ne
inurl:backup
2004intitle:index.of
03-16
inurl:admin
This query reveals backup directories. These directories can contain var
information rangin
2003index.of.password
06-27
These directories are named password. I wonder what you might find
here. Warning
2003protected
06-27
2003secure
06-27
2003winnt
06-27
2003private
06-27
What kinds of things might you find in directories marked private? let
find out..
2003secret
06-27
Backup directories are often very interesting places to explore. More tha
one server has been
List server apparently keeps track of many clients, not just Domains and
hardware, but Operatin
2005- inurl:nnls_brand.html OR Novell Nterprise Linux Services detection dork. Some of the features are
11-16 inurl:nnls_nav.html
A reverse proxy is a gateway for servers, and enables one web server to
provide content from an
2005- intitle:Welcome to
05-20 602LAN SUITE *
intitle:Welcome To Your
2005This is the default page for the WebSTAR (Macintosh) web server (Heade
WebSTAR Home
05-02
say > Server: Web
Page&qu
2005- intitle:Welcome to the Webserver detection: The Advanced Extranet Server project aims to cre
04-27 Advanced Extranet Ser an extensible open sou
intitle:Welcome to
2005Another way to find Small Business Server 2003, for more results check
Windows Small Business
04-16
dork by JimmyNeutron
Se
2005thttpd webserver
03-29
2005- intitle:IPC@CHIP
03-29 Infopage
2005yaws.*.server.at
03-31
2005- intitle:welcome to mono XSD is the demo webserver for the Mono project and allows the executio
02-15 xsp
ASP.NET on Unix
2005- inurl:oraweb
01-27 -site:oraweb.org
Rather than submitting various searches for all kinds of NetWare related
pages, Novell NetWare
2005- XAMPP
01-21 inurl:xampp/index
2004inurl:2506/jana-admin
12-13
2004- allintext:Powered by
12-13 LionMax Software
WWW File Share Pro is a small HTTP server that can help you share files w
your friends. They
Resin provides a fast standalone web server. This search locates those
2004- intitle:Welcome To
11-28 Xitami -site:xitami
2004- About Mac OS Personal Mac OS Personal Web Sharing allows Mac OS users to share Folders over
11-07 Web Sharing
Web.If you open this
2004- Switch to table format This is an index page of OReilly WebSite Professional.WebsitePro was
11-07 inurl:table|pla
developed by Oreily and d
2004- intitle:Object not
10-12 found! intext:
This one detects apache werbservers (2.0.X/SuSE) with its error page.
2004- intitle:error 404 From WebLogic Server Process Edition extends the functionality of the Applicat
10-12 RFC 2068
Server by convergi
2004- intitle:Directory Listing, Vendor page:Einfache HTTP-Server-Software fr privates
10-12 Index of /*/
Homepage-Hosting
2004- intitle:Lotus Domino Go Domino Go Webserver is a scalable high-performance Web server that ru
10-12 Webserver: &qu
on a broad range of pla
2004- intitle:Object not
10-09 found netware
intitle:AnswerBook2
2004inurl:ab2/ (inurl:8888 |
09-26
inurl
First of all this search indicates solaris machines and second the webserv
is vulnerable to
This search finds IIS 5.0 error pages = IIS 5.0 Server
2004- intitle:Shoutcast
07-29 Administrator
shoutcast is software for streaming mp3 and such. This search finds the
administrator page. It
2004- powered by
07-29 shoutstats hour
Novell, Inc
2004WEBACCESS Username This may be used to find Novell Grouwise Webaccess servers.
07-26
Passwor
2004- httpd+ssl/kttd *
07-19 server at intitle:ind
The version of a particular web server can be detected with a simple que
like this one. Altho
2004- fitweb-wwws * server at The version of a particular web server can be detected with a simple que
07-19 intitle:index.of
like this one. Altho
2004- sEDWebserver * server The version of a particular web server can be detected with a simple que
07-19 +at intitle:index.of
like this one. Altho
2004- Red Hat Secure/3.0
The version of a particular web server can be detected with a simple que
07-19 server at
The version of a particular web server can be detected with a simple que
like this one. Altho
2004- OpenSA/1.0.4
07-19 intitle:index.of
The version of a particular web server can be detected with a simple que
like this one. Altho
2004- OmniHTTPd/2.10
07-19 intitle:index.of
The version of a particular web server can be detected with a simple que
like this one. Altho
2004- Microsoft-IIS/6.0
07-19 intitle:index.of
The version of a particular web server can be detected with a simple que
like this one. Altho
2004- Microsoft-IIS/5.0 server The version of a particular web server can be detected with a simple que
07-19 at
like this one. Altho
2004- Microsoft-IIS/4.0
07-19 intitle:index.of
The version of a particular web server can be detected with a simple que
like this one. Altho
The version of a particular web server can be detected with a simple que
like this one. Altho
2004- MaXX/3.1
07-19 intitle:index.of
The version of a particular web server can be detected with a simple que
like this one. Altho
The version of a particular web server can be detected with a simple que
like this one. Altho
2004- CERN httpd 3.0B (VAX The version of a particular web server can be detected with a simple que
07-19 VMS)
like this one. Altho
2004- AnWeb/1.42h
07-19 intitle:index.of
The version of a particular web server can be detected with a simple que
like this one. Altho
Red Hat UNIX Administration Pages. This search detects the fixed title for
admin pages on c
2004Environment vars
07-02
2004- allinurl:.nsconfig
06-18 -sample -howto -tut
2004inurl:domcfg.nsf
05-17
This will return a listing of servers running Lotus Domino. These servers b
default have very
This search shows sites that have the 300 error code, but also reveal a s
tag at the botto
2004- intitle:Snap.Server
04-23 inurl:Func=
This page reveals the existance of a SNAP server (Netowrk attached serv
NAS devices) Depen
This is the default web page for Apache 1.2.6 1.3.9. Hackers can use th
information to dete
2004- allintitle:Netscape
This finds default installations of Netscape Fasttrack Server. In many case
03-18 FastTrack Server Home default installat
Page
2004- intitle:Test Page for
03-04 Apache It
This is the default web page for Apache 1.2.6 1.3.9. Hackers can use th
information to dete
This is the default web page for Apache 1.2.6 1.3.9. Hackers can use th
information to dete
This is the default web page for Apache 1.3.11 1.3.26. Hackers can use
information to de
aboutprinter.shtml
2003More Xerox printers on the web! Google found these printers. Should the
(More Xerox printers on
08-11
management interface
the web
index_i.shtml Ready
2003(Xerox printers on the
08-11
web!)
2003- inurl:tech-support
08-07 inurl:show Cisco
This is a way to find Cisco products with an open web interface. These ar
generally supposed t
I like the OpenBSD operating system. I really do. And I like the Apache we
server software. Ho
2003IIS 4.0
06-24
2003- Windows 2000 Internet At first glance, this search reveals even more examples of operating syst
06-24 Services
users enabling the
2003- Apache online
06-24 documentation
When you install the Apache web server, you get a nice set of online
documentation. When you le
2013- -site:simplemachines.org
09-24 These are the paths
2011- allinurl:forcedownload.php?
08-25 file=
Didnt see this anywhere in the GHDB, but its been known for a wh
and widely abused by oth
hxxp://evuln.com/vulns/94/summary.html
2006- inurl:updown.php |
02-28 intext:Powered by PHP Upl
this (evil ) script lets you to upload a php shell on target server, in
most cases not password
2005- inurl:guestbook/guestbooklist. A sql vulnerability has been reported in a Techno Dreams asp scrip
12-19 asp Post Date&
login.asp. http://search.s
2005intitle:CJ Link Out V1
10-26
09-26
takevorsoftware:site: http://w
2005- intitle:Control panel Control Build, manage and customize your own search engine friendly new
09-25 Pa
article site from scratch
2005inurl:cartwiz/store/index.asp
09-25
The CartWIZ eCommerce Shopping Cart System will help you build
your online store through an int
2005- maxwebportal
09-13 inurl:default
2005- Mail-it Now! intitle:Contact Mail-it Now! 1.5 (possibly prior versions) contact.php remote code
09-11 for
executionsite: http://www.sk
2005- Warning: Cannot execute a Warning: passthru(): Cannot execute a blank command in Warn
09-11 blank
system(): Can
2005Powered by Xcomic
09-08
2005Powered by FunkBoard
08-08
2005- inurl:nquser.php
08-07 filetype:php
2005- PHPFreeNews
08-07 inurl:Admin.php
2005- intitle:PHPstat
06-03 intext:Browser&q
2005- intitle:SSHVnc
05-20 AppletOR intitle:
2005- inurl:cgi-bin
04-27 inurl:bigate.cgi
Anonymous surfing with bigate.cgi. Remove http:// when you copy paste
it wont work.
filetype:pl
2004-intext:/usr/bin/perl
12-01
inur
2004- filetype:mdb
11-30 inurl:news/news
Web Wiz Site News unprotected database holds config and admin
information in a microsoft access
inurl:php.exe
2004filetype:exe
11-28
-example.com
It is possible to read any file remotely on the server with PHP.EXE (assum
a script alias fo
2004- Powered by Land Down sQL injection vulnerability in Land Down Under 601 could give an attack
11-18 Under 601
administrative access
2004- ext:asp powered by
DUForum is one of those free forum software packages. The database
11-16 DUForum inurl:(mess location is determined by th
2004- ext:asp inurl:DUgallery
11-16 intitle:3.0 -s
2004- filetype:cgi
11-04 inurl:cachemgr.cgi
2004powered by YellDL
10-31
2004- inurl:click.php
10-27 intext:PHPClickLog
A script written in PHP 4 which logs a users statistics when they click on
link. The log is
thepeak file upload manager let you manage your webtree with up and
downloading files.
2004- intitle:phpremoteview phpRemoteView is webbased filemanger with a basic shell. With this an
10-26 filetype:php &qu
attacker can browse the s
2004- intitle:ASP FileMan
10-19 Resend -site:iiswo
2004inurl:changepassword.cgi -cvs
10-09
2004inurl:cgi.asx?StoreID
10-05
Observing the web cracker in the wild, one feels like they are
watching a bear. Like a bear sto
2004- link:http://www.toastforums.co Toast Forums is an ASP message board on the Internet. Toast Foru
09-06 m/
also has all the features of
2004inurl:plog/register.php
09-06
2004inurl:robpoll.cgi filetype:cgi
08-30
This searches for PHP Explorer scripts. This looks like a file manag
with some nice extra opt
2004ext:cgi inurl:ubb6_test
08-13
The UBB trial version contains files that are not safe to keep onlin
after going live. The ins
2004Cookies are often used for authentication and a lot of other stuff.
filetype:inc inc intext:setcookie
08-01
inc php head
2004filetype:wsdl wsdl
08-01
The XML headers are called *.wsdl files.they can include data,
functions or objects. An attacke
Google search for actoin files wich could be explotable via CVE
2013-2251 Multiple Remot
inurl:.php?
2013inurl:.php? intext:CHARACTER_SETS,COLLATIONS, ?
intext:CHARACTER_SETS,COLLATIO
08-08
intitle:phpmyadmin view phpMyAdmin of web sit
NS, ?int
2012inurl:/wp-content/w3tc/dbcache/
12-31
Jay Townsend
2012More than 100k sites affected It will show asp sites that are
intext: intext: intext: intext: intext:
08-21
vulnerable to sql injection (
2012- intitle:awen+intitle:asp.net
Hi, This google dork exposes any already uploaded asp.net she
05-15
2011- filetype:php inanchor:c99 inurl:c99 This search attempts to find the c99 backdoor that may be
11-24 intitle:c99she
knowingly or unknowingly installed o
2011- inurl:php intitle:Cpanel , FTP
11-19 CraCkeR
2011intitle:#k4raeL sh3LL
10-11
2011inurl:view.php?board1_sn=
09-26
2011intitle:m1n1 1.01
07-26
2011- intitle:Locus7shell
05-03 intext:Software:
2011- intitle:[EasyPHP]
03-23 Administration
Author :- eXeSoul You will get lots of web shells even some priv
shells.
2010inurl:/vb/install/upgrade.php
12-10
2010- inurl:/vb/install/install.ph Vbulletin installation wizards, allow users to modify installation paramete
12-10 p
May also reveal
CGI-Telnet Unit-x Team
2010Connected to
12-09
*.com&qu
2010r57shell
12-07
12-07
2010- [ phpinfo ] [ php.ini ]
12-07 [ cpu ] [ mem ]
inurl:index.php?
2010pagedb=rss
11-13
-Vulnerability -inurl
CVE: 2007-4007 EDB-ID: 4221 This google dork possibly exposes sites w
the Article Direct
2006- intitle:Uploader
05-03 Uploader v6 -pixloa
2006inurl:rpSys.html
01-22
filetype:pl
2006intitle:Ultraboard
01-16
Setup
Welcome to
2005Administration
09-17
Genera
This reveals admin site for Argo Software Design Mail Server.
2005- you can now password IMchaos link tracker admin pages. Reveals AIM screennames, IP ADDRES
09-15 | this is a
AND OTHER INFO via deta
2005- set up the administrator Using this, you can find sites with a Pivot weblog installed but not set up
07-03 user inurl:pi
default set up
2005- html allowed
06-11 guestbook
When this is typed in google it finds websites which have HTML Enabled
guestbooks. This is real
This google dork reveals vulnerable message boards. It works for all Vbu
version up to 2.
2005- inurl:/NSearch/AdminSe This search brings up results for Novell NetWares Web Search Manager..
01-26 rvlet
best the sites will
2005inurl:servlet/webacc
01-06
I was playing around on the net when I found a small problem with
Novells WebAcces. With User.
2004- intitle:Mail Server CMailServer CMailServer is a small mail webmail server. Multiple vulnerabilities
12-04 Webmail
were found, including buff
2004inurl:newsdesk.cgi? inurl:t=
11-07
2004- (inurl:/shop.cgi/page=) |
11-07 (inurl:/shop.pl/page=)
2004- inurl:aol*/_do/rss_popup?
11-06 blogID=
2004- intitle:phpMyAdmin Welcome phpMyAdmin is a tool written in PHP intended to handle the
10-31 to phpMyAdmin ***
administration of MySQL over the Web
2004- intitle:phpMyAdmin Welcome search for phpMyAdmin installations that are configured to run the
08-21 to phpMyAdmin ***
MySQL database with root pri
2004ftp:// www.eastgame.net
08-20
2004- allinurl:index.php
07-29 site=sglinks&
2004- inurl:index.php?
07-29 module=ew_filemanager
http://www.cirt.net/advisories/ew_file_manager.shtml:Product:
EasyWeb FileManager Module http
2004filetype:cgi inurl:fileman.cgi
07-26
2004- filetype:cgi
07-26 inurl:Web_Store.cgi
2004- (Indexed.By|Monitored.By) hAcxFtpScan software that use l33t h@x0rz to monitor their file
07-26
stroz on ftp. On the ftp se
2004- Welcome to the Prestige Web- This is the configuration screen for a Prestige router. This page
06-04 Based Configurat
indicates that the router has
2004- intitle:Gateway Configuration This is a normally protected configuration menu for Oracle Portal
04-28 Menu
Database Access Descriptors (
2004- inurl:pls/admin_/gateway.ht This is a default login portal used by Oracle. In addition to the fact tha
04-28 m
this file can be us
2004allinurl:install/install.php
04-06
2004allinurl:intranet admin
03-29
2004- Select a database to view An oldie but a goodie. This search locates servers which provides acc
03-29 intitle:&quo
to Filemaker pro datab
2004- Welcome to PHP-Nuke
03-18 congratulations
2004inurl:info.inc.php
03-14
2004inurl:footer.inc.php
03-14
2004inurl:search.php vbulletin
03-04
0000Welcome to Intranet
00-00
2004inurl:ManyServers.htm
03-04
2004- intitle:osCommerce
This is a decent way to explore the admin interface of osCommerce e
03-04 inurl:admin intext:redist commerce sites. Depending o
2004- Gallery in configuration
03-04 mode
Gallery is a nice little php program that allows users to post personal
pictures on their websi
Yet Another Bulletin Board (YABB) SE (versions 1.5.4 and 1.5.5 and
perhaps others) contain an S
2005- intext:powered by
05-29 Hosting Controller i
site:ups.com
2004intitle:"Ups
11-25
Package trackin
Ever use the UPS Automated Tracking Service?? Wanna see where packa
are going? Want to Man-i
2004inurl:midicart.mdb
10-10
2004inurl:shopdbtest.asp
10-10
2004- Comersus.mdb
07-12 database
Comersus is an e-commerce system and has been installed all over the w
in more than 20000 s
VP-ASP (Virtual Programming ASP) has won awards both in the US and
France. It is now in use i
Hit Jammer is a Unix compatible script that allows you to manage the con
and traffic exchan
2014
[function.getimagesize]: failed to open
-02stre
05
2014
-02- intext:Access denied for intitle:
05
2013
inurl:advsearch.php?module= & intext:sql
-04synta
09
2012
Dork to find Plugin errors in wordpress websites Dork
-12- intext:Fatal error: Class Red_Action not f
intext:Fatal error: Class Red_A
06
2012
CHARACTER_SETS
-08COLLATION_CHARACT
21
CHARACTER_SETS+COLLATION_CHARACTER_SET_A
CABILITY find sql injectab
2012
-05- inurl:*.php?*=*.php intext:Warni
15
2011
inurl:index.php?
-01m=content+c=rss+catid=10&quo
21
2010
Many of the results of the search show error logs whic
-12- plugins/wp-db-backup/wp-db-backup.php
give an attacker the server side paths
08
2010
-11- allintext:fs-admin.php
11
2006
-06- intitle:Apache Tomcat Error Repo
15
2006
-04- Unable to jump to row on MySQL r
25
2006
Warning: Bad arguments to (join|implode)
-04()
25
2006
-04- Warning: failed to open stream:
25
2006
Warning: mysql_connect(): Access denied
-04for
25
2006
-04- Warning: Division by zero in on
25
2006
-03- filetype:asp + [ODBC SQL
13
This search returns more than just the one I saw alrea
here. This one will return all ODBC SQ
2005
-09- Warning: SAFE MODE Restriction i
25
2005
Warning: Supplied argument is not a valid
-09Fi
25
2005
There seems to have been a problem with search reveals database errors on vbulletin sites. View
-08the&
page source and you can get informa
16
2005
-04- intitle:Default PLESK Page
26
This throws up pages which contain CGI ERROR reports which includ
file (and
Warning:
2004mysql_query() invalid
11-28
q
2004- intitle:Configuration.File This search finds configuration file errors within the softcart application.
11-13 inurl:softcart.exe
includes the na
2004- The script whose uid is
This PHP error message is revealing the webservers directory and user
10-16 is not
2004- snitz! forums db path
09-07 error
snitz forums uses a microsoft access databases for storage and the defa
name is Snitz_
This search will show an attacker some PHP error logs wich may contain
information on wich an a
2004- ASP.NET_SessionId
07-26 data source=&q
In many cases, these pages display nice bits of SQL code which can be u
by an attacker to mo
2004- filetype:php
Discuz! Board error messages related to MySQL. The error message may
07-16 inurl:logging.php D empty or contain path i
2004- Internal Server Error
07-16 server at&
2004- PHP application warnings These error messages reveal information about the application that crea
07-14 failing include_pat
them as well as reve
2004- intext:Warning: Failed
07-09 opening o
These error messages reveal information about the application that crea
them as well as reve
The ht://Dig system is a complete world wide web indexing and searchin
system for a domain or
HyperNews is a cross between the WWW and Usenet News. Readers can
browse through the messages w
These are SQL error messages, ranging from to many connections, acce
denied to user xxx, show
2004- intitle:Execution of this This is a cgiwrap error message which displays admin name and email, p
04-28 script not permitt
numbers, path names,
2004- intitle:Error Occurred This is a typical error message from ColdFusion. A good amount of
04-19 The error
information is available from
2004- warning error on line sablotron is an XML toolit thingie. This query hones in on error messages
03-11 php sablotron
generated by this too
2004- Fatal error: Call to
03-16 undefined function
This error message can reveal information such as compiler used, langua
used, line numbers, p
This is an ASP error message that can reveal information such as compile
used, language used,
2004- Cant connect to local Another SQL error message, this message can display database name, p
03-04 intitle:warning
names and partial SQL c
2004- intitle:Under
03-04 construction does
This error message can be used to narrow down the operating system an
web server version which
Another SQL error message, this message can display the username,
database, path names and part
Warning: Cannot
2004modify header
03-04
information
A PHP error message, this message can display path names, function nam
filenames and partial
2004- Warning: pg_connect(): This search reveals Postgresql servers in yet another way then we had se
08-25 Unable to connect to before. Path informa
An unexpected token
2004END-OF-STATEMENT
03-04
w
A DB2 error message, this message can display path names, function na
filenames, partial co
An Informix error message, this message can display path names, functio
names, filenames and p
2004- An illegal character has An Informix error message, this message can display path names, functio
03-04 been found in the s
names, filenames and p
2004- Syntax error in query
03-04 expression -the
An Access error message, this message can display path names, function
names, filenames and par
supplied argument is
2004not a valid PostgreSQL
03-04
result
PostgreSQL query
2004failed: ERROR: parser:
03-04
pa
2004An SQL Server error message, this message can display path names, fun
Incorrect syntax near
03-04
names, filenames and
2004An SQL Server error message, this message can display path names, fun
Incorrect syntax near
03-04
names, filenames and
Unclosed quotation
2004mark before the
03-04
character
An SQL Server error message, this message can display path names, fun
names, filenames and
ORA-00933: SQL
2004command not properly
03-04
ended&qu
An Oracle error message, this message can display path names, function
names, filenames and par
2004- ORA-00921: unexpected Another generic SQL message, this message can display path names,
03-04 end of SQL command
function names, filenames and
2004- ORA-00936: missing
03-04 expression
A generic ORACLE error message, this message can display path names,
function names, filenames
Supplied argument is
2004not a valid MySQL
03-04
resul
Another generic SQL message, this message can display path names,
function names, filenames and
Another generic SQL message, this message can display path names and
partial SQL code, both of
Another error message, this appears when an SQL query bails. This is a
generic mySQL message, s
This one shows the type of web server running on the site, and has the
ability to show other in
This query finds various types of IIS servers. This error message is fairly
indicative of a som
Windows 2000 web servers. Aging, fairly easy to hack, especially out of t
box
2004sitebuilderpictures
03-04
This is a default directory for the sitebuilder web design software program
these people po
2004sitebuilderfiles
03-04
This is a default directory for the sitebuilder web design software program
these people po
2004sitebuildercontent
03-04
This is a default directory for the sitebuilder web design software program
these people po
2004- ORA-00921: unexpected Another SQL error message from Cesar. This one coughs up full web
01-09 end of SQL command
pathnames and/or php filename
Chatologica
2003MetaSearch stack
08-15
tra
There is soo much crap in this error message Apache version, CGI
environment vars, path name
These arent too horribly bad, but there are SO MANY of them. These site
got googlebotted whil
2012inurl:finger.cgi
11-02
2012- site*.*.*/webalizer
Shows usage statistics of sites. Includes monthy reports on the IP
08-21 intitle:Usage Statistics addresses, user agents, and
2006- intitle:r57shell +uname
05-04 -bbpress
compromised servers a lot are dead links, but pages cached show
interesting info, this is r5
2006- inurl:/counter/index.php
04-06 intitle:+PHPCounter
2005inurl:ovcgi/jovw
12-31
2005- Shadow Security Scanner This is a googledork to find vulnerability reports produced by Shadow
10-26 performed a vulnerab
Security Scanner. They c
2005- The following report
10-26 contains confidential i
2005inurl:status.cgi?host=all
10-04
Nagios Status page. See what ports are being monitored as well as ip
addresses.Be sure to check
2005inurl:login.jsp.bak
09-30
This search finds Beyond Security reports. Beyond Security sells a box
which performs automated
2004- intitle:PHPBTTracker
12-30 Statistics | inti
2004- intitle:Azureus : Java BitTorrent This query shows machines using the Azureus BitTorrent clients b
12-30 Client Tra
in tracker the pages ar
2004inurl:install/install.php
12-29
This searches for the install.php file. Most results will be a Bulletin
board like Phpbb etc.T
see and control JVC webcameras, you can move the camera, zoom
change the settings, etc.
2004- inurl:sitescope.html
12-03 intitle:sit
2004- intitle:twiki
12-02 inurl:TWikiUsers&q
2004- Output produced by SysWatch sysWatch is a CGI to display current information about your UNIX
11-28 *
system. It can display drive p
2004inurl:testcgi xitami
11-28
2004- filetype:log
11-28 intext:ConnectionManager2
2004- intitle:sysinfo *
11-12 intext:Genera
This is general search for online port scanners which accept any I
does not find a specifi
2004inurl:/adm-cfgedit.php
11-07
PhotoPost Pro is photo gallery system. This dork finds its installati
page.You can use this p
2004inurl:webutil.pl
11-07
2004inurl:statrep.nsf -gov
10-20
2004- inurl:map.asp?
10-05 intitle:WhatsUp G
WhatsUp Golds new SNMP Viewer tool enables Area-Wide to easily trac
variables associate
NRG is a system for maintaining and visualizing network data and other
resource utilization dat
ifGraph is a set of perl scripts that were created to fetch data from SNMP
agents and feed a RR
2004- inurl:/catalog.nsf
09-10 intitle:catalog
This will return servers which are running versions of Lotus Domino. The
catalog.nsf is the ser
2004- Powered by
09-21 phpOpenTracker
Statistics
site:netcraft.com
2004Netcraft reports a sites operating system, web server, and netblock own
intitle:That.Site.Running
09-21
together with, if av
Apache
2004- this proxy is working
08-13 fine! ente
These are test pages for some proxy program. Some have a text field th
allows you to use that
This search shows the webserver access stats as the user admin. The
language used i
ACID stands for for Analysis Console for Incident Databases. It is a php
frontend f
2004Looking Glass
06-22
A Looking Glass is a CGI script for viewing results of simple queries exec
on remote router
This is the status page for a Belkin Cable/DSL gateway. Information can
retrieved from this
2004- intitle:ADSL
06-04 Configuration page
This is the status screen for the Solwise ADSL modem. Information avail
from this page incl
2004- filetype:vsd vsd network Reveals network maps (or any other kind you seek) that can provide
05-13 -samples -examples
sensitive information such a
2004- filetype:pdf Assessment These are reports from the Nessus Vulnerability Scanner. These report
05-03 Report nessus
contain detailed informat
inurl:phpSysInfo/
2004created by
04-16
phpsysinfo
This statistics program allows the an admin to view stats about a webse
Some sites leave t
2014
filetype:pdf acunetix
-03Finds reports generated by Acunetix scans. Andy G twitter.com/vxhex
website audit &q
31
2014 inurl:clientaccesspolic Locates clientaccesspolicy.xml files used by silverlight to determine the cros
-03- y filetype:xml
27
intext:allow
domain policy
2014 inurl:crossdomain
Locates crossdomain.xml files used by flash/flex/silverlight to determine the
-03- filetype:xml
cross domain pol
27
intext:allow-access
2014
site:bitbucket.org
-02inurl:.bash_history
05
2013 intext:phpMyAdmin
intext:phpMyAdmin SQL Dump filetype:sql intext:INSERT INTO `admin` (`id`
-11- SQL Dump filetype:sql
`user`, `password`) V
27
intext:INS
2013
inurl:mikrotik
-11filetype:backup
27
2013
filetype:xml
-11inurl:sitemap
25
Sitemaps, the opposite of Web Robots Exclusion Detail directory and page m
-[Volun
2013 inurl:jmxJBoss
-11- console/HtmlAdaptor http://docs.jboss.org/jbossas/docs/Server_Configuration_Guide/4/html/Conne
25
intitle:
g_to_the_J
2013
-11- inurl:tar filetype:gz
25
Tar files Contain user and group information (in addition to potentially usefu
files)
2013
filetype:bak (inurl:php This one could be used to find all sorts of backup data, but this example is
-11| inurl:asp | inurl:rb)
limited to just c
25
2013 site:github.com
-11- inurl:id_rsa
25
-inurl:&q
2013 site:github.com
-11- inurl:known_hosts
25
&quo
Git config file Easy way to find Git Repositories -[Voluntas Vincit Omnia]website
2013 filetype:php
Project Honey Pot anti-spammer detection (http://www.projecthoneypot.org/
-11- intext:PROJECT
Can identify the
25
HONEY POT ADDRES
2013 inurl:github.com
-11- intext:sftp-conf.json
25
+intext:/wp
Find FTP logins and full path disclosures pushed to github inurl:github.com
intext:sftp-conf
2013 inurl:*/webalizer/*
-09- intitle:Usage
24
Statistics
*Obrigado,*
2013
intitle:index.of
-09intext:.ssh
24
2013 filetype:txt
This dork can be used to find symlinked WordPress configuration files of othe
-08- inurl:~~Wordpress2.t
web sites
08
xt
2013
filetype:txt inurl:wp-08config.txt
08
Easily hunt the WordPress configuration file in of remote web sites Author :
Un0wn_X
2013inurl:~~joomla3.txt filetype:txt
08-08
2013inurl:fluidgalleries/dat/login.dat
08-08
2013information_schema filetype:sql
08-08
2013ext:gnucash
02-05
2013runtimevar softwareVersion=
02-05
nitish mehta
2012- inurl:newsnab/www/
12-06 automated.config.php
2012inurl:.com/configuration.php-dist
11-02
2012filetype:avastlic
08-21
2012- filetype:docx Domain Registrar $user Dork :- *filetype:docx Domain Registrar $user $pass* Use :- *
08-21 $pass
find domain login password fo
2012- inurl:phpmyadmin/index.php
08-21 intext:&quo
This dork can fetch you Avast product licenses especially Ava
Antiviruses , including Profes
2012?intitle:index.of?.mysql_history
05-15
) in a xls for
2011- List of Phone Numbers (In XLS File ) This is a dork for a list of Phone Private Numbers in Argentina
12-19 allinurl:tele
Author: Luciano UNLP
2011- Microsoft-IIS/7.0 intitle:index.of
12-19 name size
2011filetype:old (mysql_connect) ()
11-24
filetype:reg reg
2011HKEY_CURRENT_USER
11-19
SSHHOSTKEYS
2011- intitle:index.of?
11-19 configuration.php.zip
2011inurl:/includes/config.php
11-19
The Dork Allows you to get data base information from config
files. Author: XeNon
2011filetype:pem Microsoft
07-26
2011- site:mediafire.com cv Or resume OR Searches Mediafire for publicly avaliable PDFs containing
07-18 curriculum vita
information used in a CV/Resume/Cur
2011- site:docs.google.com intitle:(cv Or
07-18 resume OR curr
2011inurl:sarg inurl:siteuser.html
05-26
2011inurl:app/etc/local.xml
02-19
2010allinurl:/xampp/security.php
12-13
2010inurl:phpinfo.php
12-10
2010inurl:config.php.new +vbulletin
12-07
2010inurl:configuration.php-dist
12-07
2006intext:ViewCVS inurl:Settings.php
01-16
2006inurl:build.err
01-16
2005inurl:/cgi-bin/pass.txt
12-22
Passwords
(intitle:WebStatistica
2005WebStatistica provides detailed statistics about a web page. Normally y
inurl:main.php) | (intitle:
12-19
would have to login
inurl:wp-mail.php +
2005There doesnt seem to
11-24
b
An attacker may want to know about the antivirus software running. The
description says he can
intitle:Bookmarks
2005inurl:bookmarks.html
10-22
Bookm
2005contacts ext:wml
08-23
2005- intitle:curriculum vitae Hello. 1. It reveals personal datas, often private addresses, phone numb
08-12 filetype:doc
e-mails, how many
2005- intitle:admin panel
08-16 +Powered by
This finds all versions of RedKernel Referer Tracker(stats page) it just giv
out some nice in
2005- ext:(doc | pdf | xls | txt | Although this search is a bit broken (the file extensions dont always wo
07-30 ps | rtf | odt | sxw
it reveals intere
2005- site:www.mailinator.com Mailinator.com allows people to use temporary email boxes. Read the si
07-24 inurl:ShowMail.do
wont explain here.
2005allinurl:cdkey.txt
07-21
cdkeys
2005filetype:PS ps
07-08
2005filetype:QBW qbw
06-21
2005inurl:XcCDONTS.asp
06-07
This query reveals an .asp script which can often be used to send
anonymous emails from fake se
2005ext:DCA DCA
04-27
2005ext:DBF DBF
04-27
Dbase DAtabase file. Can contain sensitive data like any other database
2005ext:jbf jbf
04-27
There is a full path disclosure in .jbf files (paint shop pro), which by
itself is not a vulner
These Safari bookmarks that might show very interesting info abou
users surfing habits
2005ext:ics ics
04-26
2005WebLog Referrers
03-30
this is a mod of one of the previous queries posted in here. the basi
thing is, to add this:21
2005filetype:ora tnsnames
02-15
This searches for tns names files. This is an Oracle configuration file
that sets up connectio
2005- inurl:getmsg.html
03-02 intitle:hotmail
2005+HSTSNR -netop.com
02-28
This search reveals NetOp license files. From the netop website: N
Remote Control is
scripts to view the source code of PHP scripts running on the server
Can be very interesting i
2005inurl:netscape.hst
01-27
2005inurl:bookmark.htm
01-27
2005inurl:netscape.hst
01-27
2005inurl:netscape.ini
01-27
Edna allows you to access your MP3 collection from any networked
computer. This software stream
2005ext:txt inurl:dxdiag
01-22
This will find text dumps of the DirectX Diag utility. It gives an outlin
the hardware of t
2005intitle:FTP root at
01-13
This dork will return some FTP root directories. The string can be m
more specific by adding
intext:gmail invite
2005This is a dork I did today. At first, I wanted to find out the formula fo
intext:http://gmail.google.co
01-02
making one, but
m
2005Peoples MSN contact lists
01-02
This will give msn contact lists .. modify the msn to what ever you
feel is messeng
2005filetype:ctt Contact
01-02
2004- intitle:index.of .diz .nfo last File_id.diz is a description file uploaders use to describe packages
12-30 modifi
uploaded to FTP sites. Alt
2004filetype:blt buddylist
12-30
AIM buddylists.
2004- intitle:welcome.to.squeezebo squeezebox is the easiest way for music lovers to enjoy high-qualit
12-19 x
playback of their whole di
2004- inurl:preferences.ini
This finds the emule configuration file which contains some genera
12-19 [emule]
proxy information.Somet
2004- ext:conf inurl:rsyncd.conf -cvs rsync is an open source utility that provides fast incremental file
12-19 -man
transfer.rsync can also tal
2004inurl:ds.py
12-13
2004ext:dat bpk.dat
12-13
2004- php-addressbook This is the php-addressbook shows user address information without a
12-05 addressbook for
password.
2004Generated by phpSystem
12-05
2004- inurl:/axs/ax-admin.pl
12-04 -script
This system records visits to your site. This admin script allows you
display these records
2004ext:vmx vmx
12-03
2004ext:vmdk vmdk
12-03
2004ext:gho gho
12-03
2004- intitle:DocuShare
11-28 inurl:docushar
2004- ext:txt Final encryption IPSec debug/log data which contains user data and password hashes.Ca
11-28 key
used to crack password
2004- inurl:report EVEREST
11-20 Home Edition
Well what can be said about this one, Ive added it to the DB under Juicy
info, however it coul
2004- Microsoft (R) Windows * This file spills a lot of juicy info in some cases, passwords in the raw du
11-23 (TM) Version * DrWts but not in an
2004- intitle:Apache::Status
11-21 (inurl:server-s
2004- intitle:PhpMyExplorer
11-18 inurl:inde
MySQL stores its data for each database in individual files with the exten
MYD.An attacker
2004- filetype:config
11-16 web.config -CVS
2004filetype:ns1 ns1
11-16
This was inspired by the K-Otic report. Only two results at time of writing
The cgi script let
2004- filetype:pst pst -from -to Finds Outlook PST files which can contain emails, calendaring and addre
11-12 -date
information.
2004inurl:putty.reg
11-07
This registry dump contains putty saved session data. SSH servers the
according usernames and p
2004- filetype:inf
11-05 inurl:capolicy.inf
filetype:php inurl:index
2004PHP iCalendar is a php-based iCal file parser. Its based on v2.0 of the IET
inurl:phpicalendar -site:
10-31
spec. It displays
These are www analog webstat reports. The failure report shows informa
leakage about databa
2004- intitle:Index of upload Files uploaded through ftp by other people, sometimes you can find all s
10-24 size parent di
of things from mov
2004inurl:log.nsf -gov
10-20
2004- intitle:index.of * admin With Compulive News you can enter the details of your news items onto
10-19 news.asp conf
webform and upload imag
2004- inurl:cgi-bin/testcgi.exe
10-18 Please distribute
Test CGI by Lilikoi Software aids in the installation of the Ceilidh discussi
engine for the
2004ext:ini intext:env.ini
10-16
This one shows configuration files for various applications. based on the
application an attack
Installed Objects Scanner makes it easy to test your IIS Webserver for
installed components. In
ASP Stats Generator is a powerful ASP script to track web site activity. It
combines a server s
2004This search will show the googler ODBC client configuration files which m
inurl:odbc.ini ext:ini -cvs
10-09
contain usernames/d
2004- intext:SQLiteManager
10-05 inurl:main.php
2004inurl:/_layouts/settings
09-23
2004ext:ldif ldif
09-23
2004- filetype:pst
09-11 inurl:outlook.pst
All versions of the popular business groupware client called Outlook hav
the possibility to st
2004filetype:vcs vcs
09-22
Filext.com says: Various programs use the *.VCS extension; too many t
individually.
ext:log Software:
2004Microsoft Internet
09-21
Informa
Microsoft Internet Information Services (IIS) has log files that are normal
not in the docroo
This search will return any Lotus Domino address books which may be o
to the public. This ca
This search finds sites using Microsoft Access databases, by looking for t
the database conne
2004- filetype:pdb pdb backup Hotsync database files can be found using All databases on a Palm dev
09-10 (Pilot | Pluckerdb)
including the o
2004- filetype:xls
09-10 inurl:email.xls
Our forum members never get tired of finding juicy MS office files. Here
one by urban that fi
2004- filetype:pot
09-10 inurl:john.pot
John the Ripper is a popular cracking program every hacker knows. Its
results are stored in a
2004filetype:rdp rdp
09-07
2004inurl:snitz_forums_2000.mdb
09-07
2004filetype:bkf bkf
09-06
2004filetype:qbb qbb
09-06
2004ext:asp inurl:pathto.asp
08-13
The UBB trial version contains files that are not safe to keep onlin
after going live. The ins
2004- intext:Session Start * * * *:*:* These are IRC and a few AIM log files. They may contain juicy info
08-09 * fil
just hours of good clean
2004- (inurl:robot.txt |
08-09 inurl:robots.
2004filetype:cfg auto_inst.cfg
08-05
2004filetype:fp7 fp7
08-05
2004filetype:fp3 fp3
08-05
2004inurl:*db filetype:mdb
08-02
2004- allow_call_time_pass_referenc Returns publically visible pages generated by the php function
08-02 e P
phpinfo(). This search differs f
2004filetype:ora ora
08-01
Greetings, The *.ora files are configuration files for oracle clients.
attacker can identify
2004- intitle:Index Of -inurl:maillog This google search reveals all maillog files within various directori
07-28 maill
on a webserver. This se
2004filetype:rdp rdp
09-07
2004inurl:snitz_forums_2000.mdb
09-07
2004filetype:bkf bkf
09-06
2004filetype:qbb qbb
09-06
2004ext:asp inurl:pathto.asp
08-13
The UBB trial version contains files that are not safe to keep onlin
after going live. The ins
2004- intext:Session Start * * * *:*:* These are IRC and a few AIM log files. They may contain juicy info
08-09 * fil
just hours of good clean
2004- (inurl:robot.txt |
08-09 inurl:robots.
2004filetype:cfg auto_inst.cfg
08-05
2004filetype:fp7 fp7
08-05
2004filetype:fp3 fp3
08-05
2004inurl:*db filetype:mdb
08-02
2004- allow_call_time_pass_referenc Returns publically visible pages generated by the php function
08-02 e P
phpinfo(). This search differs f
2004filetype:ora ora
08-01
Greetings, The *.ora files are configuration files for oracle clients.
attacker can identify
2004- intitle:Index Of -inurl:maillog This google search reveals all maillog files within various directori
07-28 maill
on a webserver. This se
2004- inurl:profiles
07-26 filetype:mdb
intext:(password |
2004passcode) intext:
07-26
(username | us
2004- intitle:Index Of
searches for cookies.txt file. On MANY servers this file holds all cookie
information, which ma
2004- inurl:forum
07-26 filetype:mdb
2004- inurl:backup
07-26 filetype:mdb
This search reveals secret channels on IRC as revealed by IRC chat logs
2004sets mode: +p
07-19
This search reveals private channels on IRC as revealed by IRC chat logs
2004- inurl:ssl.conf
07-15 filetype:conf
The information contained in these files depends on the actual file itself.
SSL.conf files cont
This search will find private key files Private key files are supposed to b
well privat
This search will find private key files Private key files are supposed to b
well privat
2004Welcome to ntop!
07-06
Ntop shows the current network usage. It displays a list of hosts that are
currently using the
Microsoft Money 2004 provides a way to organize and manage your pers
finances (http://www.m
This search looks for Outlook Web Access Public Folders directly. These lin
open public folde
2004Unreal IRCd
07-06
MSN Messenger uses the file extension *.ctt when you export the contact
An attacker could
94FBR is part of many serials. An malicious user would only have to cha
the programm name (p
2004- inurl:forward
05-26 filetype:forward -cvs
Users on *nix boxes can forward their mail by placing a .forward file in t
home directory.
2004- intitle:System Statistics This search reveals internal network information including network
05-24 +Syste
configuratino, ping times, s
2004- inurl:cacti
This search reveals internal network info including architecture, hosts a
05-24 +inurl:graph_view.ph services available.
2004- inurl:/cricket/grapher.cgi This search reveals information about internal networks, such as
05-24
configuration, services, bandw
2004- intitle:Big Sister +OK This search reveals Internal network status information about services a
05-24 Attention
hosts.
2004- Mecury Version
05-18 Infastructure Gro
2004inurl:php.ini filetype:ini
05-17
The php.ini file contains all the configuration for how PHP is parsed on a
server. It can cont
intitle:intranet
2004inurl:intranet
05-17
+intext:phon
These pages are often private intranet pages which contain phone listin
and email addresses.
Reveals AIM buddy lists, including screenname and whos on their budd
list and their blocke
These are http server access logs which contain all sorts of information
ranging from usernames
2004filetype:log cron.log
05-14
Displays logs from cron, the *nix automation daemon. Can be used to
determine backups, full an
License files for various software titles that may contain contact info an
the product version
2004- intitle:index of
This file contains port number, version number and path info to MySQL
05-13 mysql.conf OR mysql_c server.
These searches reveal Outlook v 1-4 or Eudora mailbox files. Often thes
are made public on pur
2004filetype:wab wab
05-10
These are Microsoft Outlook Mail address books. The information contai
will vary, but at the
2004- HTTP_FROM=googlebot These pages contain trace information that was collected when the
05-06 googlebot.com &qu
googlebot crawled a page. The
2004- filetype:conf inurl:firewall These are firewall configuration files. Although these are often example
05-05 -intitle:cvs
sample files, in m
2004- inurl:smb.conf
05-04 intext:workgroup&
2004- inurl:tdbin
05-03
(http://www.mercuryinteractive.com/products/test
This is the MRTG traffic analysis pages. This page lists informatio
about machines on the netw
2004inurl:perl/printenv
04-28
2004inurl:cgi-bin/printenv
04-28
2004inurl:fcgi-bin/echo
04-28
2004inurl:server-status apache
04-26
This page shows all sort of information about the Apache web
server. It can be used to track pr
2004allinurl:servlet/SnoopServlet
04-20
2004- allinurl:/examples/jsp/snp/snoop.j These pages reveal information about the server including path
04-20 sp
information, port information, e
2004inurl:newsletter/admin/
04-16
2004- inurl:newsletter/admin/
04-16 intitle:
2004Index of / chat/logs
04-13
This is your typical stats page listing referrers and top ips and su
This information can ce
2004intitle:index.of cleanup.log
04-05
2004intitle:index.of inbox
04-05
After placing an order via the web, many sites provide a page containin
phrase Thank
2004- inurl:changepassword.as This is a common script for changing passwords. Now, this doesnt actu
03-24 p
reveal the password,
2004- Most Submitted Forms
03-22 and Scripts
More www statistics on the web. This one is very nice.. Lots of directory
and client acce
2004inurl:admin filetype:xls
03-16
2004- intitle:index.of Apache This is a very basic string found on directory listing pages which show th
03-04 server a
version of the Apac
2004- intitle:wbem compaq
03-04 login Compaq
2004- inurl:main.php Welcome From phpmyadmin.net : phpMyAdmin is a tool written in PHP intended
03-04 to phpMyAdmin
handle the administ
2004- inurl:main.php
03-04 phpMyAdmin
2004- phpMyAdmin running From phpmyadmin.net : phpMyAdmin is a tool written in PHP intended
03-04 on inur
handle the administ
2004- robots.txt Disallow:
03-04 filet
The robots.txt file serves as a set of instructions for web crawlers. The
disallow
The webalizer program shows web statistics for web servers. This
information includes who is vi
2004- intitle:statistics of
03-04 advanced w
the awstats program shows web statistics for web servers. This informa
includes who is visi
2004ipsec.conf
03-04
The ipsec.conf file could help hackers figure out what uber-secure users
freeS/WAN are prote
2004ipsec.secrets
03-04
2004ipsec.secrets
03-04
2004cgiirc.conf
03-04
This is another less reliable way of finding the cgiirc.config file. CGIIRC is a
web-based IRC
2004cgiirc.conf
03-04
CGIIRC is a web-based IRC client. Very cool stuff. The cgiirc.config file lists
options for
2004phpMyAdmin dumps
03-04
2004phpMyAdmin dumps
03-04
This particular file contains web links that trillian users have entered into
tool. Trillia
2003I never really thought about this until I started coming up with juicy exam
site:edu admin grades
07-10
for DEFCON 11..
2003- haccess.ctl (VERY
06-30 reliable)
2003- generated by
06-30 wwwstat
More www statistics on the web. This one is very nice.. Lots of directory in
and client acce
2003Another web statistics package. This one originated from a google scan o
produced by getstats
06-30
ivy league college
2003- This report was
These are weblog-generated statistics for web sites A roadmap of files,
06-27 generated by WebLog referrers, errors, s
2003robots.txt
06-27
The robots.txt file contains rules about where web spiders are allowed (
NOT all
2004phpinfo()
11-18
this brings up sites with phpinfo(). There is SO much cool stuff in here tha
you just have to
2003mt-db-pass.cgi files
06-24
These folks had the technical prowess to unpack the movable type files, b
couldnt manage to
sQL database dumps. LOTS of data in these. So much data, infact, Im pre
to think of what e
2003- Financial spreadsheets: Hey! I have a great idea! Lets put our finances on our website in a secre
06-24 finances.xls
directory so
2003- Financial spreadsheets: Hey! I have a great idea! Lets put our finances on our website in a secre
06-24 finance.xls
directory so
2003- ICQ chat logs,
06-24 please
These are server cluster reports, great for info gathering. Lesse, what were
those server names
These are squid server cache reports. Fairly benign, really except when yo
consider using them
2012inurl:finger.cgi
11-02
2012- site*.*.*/webalizer
Shows usage statistics of sites. Includes monthy reports on the IP
08-21 intitle:Usage Statistics addresses, user agents, and
2006- intitle:r57shell +uname
05-04 -bbpress
compromised servers a lot are dead links, but pages cached show
interesting info, this is r5
2006- inurl:/counter/index.php
04-06 intitle:+PHPCounter
2005- Shadow Security Scanner This is a googledork to find vulnerability reports produced by Shadow
10-26 performed a vulnerab
Security Scanner. They c
2005- The following report
10-26 contains confidential i
2005inurl:status.cgi?host=all
10-04
Nagios Status page. See what ports are being monitored as well as ip
addresses.Be sure to check
2005inurl:login.jsp.bak
09-30
This search finds Beyond Security reports. Beyond Security sells a box
which performs automated
2004- intitle:PHPBTTracker
12-30 Statistics | inti
2004- intitle:Azureus : Java BitTorrent This query shows machines using the Azureus BitTorrent clients b
12-30 Client Tra
in tracker the pages ar
2004inurl:install/install.php
12-29
This searches for the install.php file. Most results will be a Bulletin
board like Phpbb etc.T
see and control JVC webcameras, you can move the camera, zoom
change the settings, etc.
2004- inurl:sitescope.html
12-03 intitle:sit
2004- intitle:twiki
12-02 inurl:TWikiUsers&q
2004- Output produced by SysWatch sysWatch is a CGI to display current information about your UNIX
11-28 *
system. It can display drive p
2004inurl:testcgi xitami
11-28
2004- filetype:log
11-28 intext:ConnectionManager2
2004- intitle:sysinfo *
11-12 intext:Genera
This is general search for online port scanners which accept any I
does not find a specifi
2004inurl:/adm-cfgedit.php
11-07
PhotoPost Pro is photo gallery system. This dork finds its installati
page.You can use this p
2004inurl:webutil.pl
11-07
2004inurl:statrep.nsf -gov
10-20
2004- inurl:map.asp?
10-05 intitle:WhatsUp G
WhatsUp Golds new SNMP Viewer tool enables Area-Wide to easily trac
variables associate
NRG is a system for maintaining and visualizing network data and other
resource utilization dat
ifGraph is a set of perl scripts that were created to fetch data from SNMP
agents and feed a RR
2004- inurl:/catalog.nsf
09-10 intitle:catalog
This will return servers which are running versions of Lotus Domino. The
catalog.nsf is the ser
Powered by
2004phpOpenTracker
09-21
Statistics
site:netcraft.com
2004Netcraft reports a sites operating system, web server, and netblock own
intitle:That.Site.Running
09-21
together with, if av
Apache
2004- this proxy is working
08-13 fine! ente
These are test pages for some proxy program. Some have a text field th
allows you to use that
This search shows the webserver access stats as the user admin. The
language used i
ACID stands for for Analysis Console for Incident Databases. It is a php
frontend f
2004Looking Glass
06-22
A Looking Glass is a CGI script for viewing results of simple queries exec
on remote router
This is the status page for a Belkin Cable/DSL gateway. Information can
retrieved from this
2004- intitle:ADSL
06-04 Configuration page
This is the status screen for the Solwise ADSL modem. Information avail
from this page incl
2004- filetype:vsd vsd network Reveals network maps (or any other kind you seek) that can provide
05-13 -samples -examples
sensitive information such a
2004- filetype:pdf Assessment These are reports from the Nessus Vulnerability Scanner. These report
05-03 Report nessus
contain detailed informat
inurl:phpSysInfo/
2004created by
04-16
phpsysinfo
This statistics program allows the an admin to view stats about a webse
Some sites leave t
201
typo3 passwords
4inurl:typo3conf/localconf.php
0407
201
4inurl:/backup intitle:index of
03- backup intext:*sql
31
Bruno Schmid
Google Search:https://www.google.com/search?
client=opera&q=admin+username+and+pass&sour
201
3Passwords for Java Management Extensions (JMX Remote) Used by
filetype:password jmxremote
11jconsole, Eclipses MAT, Java Vi
25
201
3ext:sql intext:@gmail.com
11- intext:password
25
author:haji
201
3site:github.com inurl:sftp11- config.json
25
201
3site:github.com inurl:sftp11- config.json intext:/wp-
25
Finds disclosed ftp FTP for WordPress installs, which have been pushe
a public repo on GitH
201
3BEGIN RSA PRIVATE KEY
09- filetype:key -gi
24
201
3filetype:sql insite:pass &&
04- user
22
Google Dork: filetype:sql insite:pass && user We Can get login userna
and password
201
3ext:sql intext:@hotmail.com
04- intext :password
09
201
3filetype:config
04- inurl:web.config inurl:ftp
09
201
3filetype:inc OR filetype:bak
02- OR filetype:old mysql
05
201
3ext:xml (proto=prpl- |
02- prpl-ya
05
201
2allinurl:User_info/auth_user_ Google dork for find user info and configuration password of DCForum
11- file.txt
allinurl:User_info/
05
201
2inurl:/dbman/default.pass
1102
201
2parent directory
11- proftpdpasswd intitle
02
201
2filetype:xls username |
11- password
02
201
ext:xml
2(mode_passive|mode_defa OffSec: So the dork is: ext:xml (mode_passive|mode_default) Th
11u
02
201
2intext:charset_test= email=
08- default_persistent=
21
201 inurl:passes OR
Hack the $cr1pt kiddies. There are a lot of Phishing pages hosted on
20821
inurl:passwords&
201
2filetype:cfg radius (pass|
05- passwd|passw
15
Find config files with radius configs and passwords and secrets Lov
Bastich
2011filetype:sql inurl:wp-content/backup-*
12-14
2011- filetype:php~ (pass|passwd|password| Backup or temp versions of php files containing you gues
10-11 dbpass|db_pass
it passwords or other ripe for the
2011inurl:ftp password filetype:xls
09-26
2011- filetype:ini pdo_mysql (pass|passwd| full details dbname dbuser dbpass all plain text
04-18 pa
Author:Bastich
2011inurl:web/frontend_dev.php -trunk
01-09
2006ext:php intext:$dbms$dbhost
08-10
2006inurl:calendarscript/users.txt
03-21
2006- filetype:reg reg +intext: This can be used to get encoded vnc passwords which can otherwis
02-05
obtained by a local regist
2006- ext:asa | ext:bak intext:uid
01-02 intext:pwd -uid
2006- inurl:editor/list.asp |
01-02 inurl:da
2006filetype:bak createobject sa
01-01
This query searches for files that have been renamed to a .bak
extension (obviously), but inclu
2005- inurl:ventrilo_srv.ini
12-19 adminpassword
User names and password hashes from web server backups genera
by cpanel for ProFTPd. Passwo
FlashFXP has the ability to import a Sites.dat file into its current
Sites.dat file, using this
2005server-dbs intitle:index of
10-30
2005- inurl:/yabb/Members/Admin.d This search will show you the Administrator password (very first lin
09-28 at
YaBB forums whose own
2005- admin account info
09-25 filetype:log
This search finds log files containing the phrase (Your password is).
These files often contain
some people are that stupid to keep their Cisco routers config files
site. You can easly fin
2005filetype:dat inurl:Sites.dat
09-13
If you want to find out FTP passwords from FlashFXP Client, just typ
this query in google and
2005- inurl:cgi-bin
06-24 inurl:calendar.cfg
2005- intitle:phpinfo()
06-05 +mysql.default
This will look throught default phpinfo pages for ones that have a defau
mysql password.
2005inurl:pass.dat
06-04
Accesses passwords mostly in cgibin but not all the timeCan find passw
+ usernames (sometim
2005- inurl:perform.ini
06-06 filetype:ini
2005- intext:powered by
05-11 EZGuestbook
!Host=*.*
2005some people actually keep their VPN profiles on the internetomg Sim
intext:enc_UserPassword
05-02
donwload the pcf f
=* ext:pcf
wwwboard WebAdmin
2005inurl:passwd.txt
03-28
wwwboard|webad
2005filetype:inf sysprep
03-20
Find insert statements where the field (or table name) preceding the
operator VALUES will be
2005- intitle:Index of
02-10 sc_serv.conf sc_serv
This dork lists sc_serv.conf files. These files contain information for
Shoutcast servers and o
Link management script with advanced yet easy to use admin control
panel, fully template driven
"Powered by
2005DUpaypal"
02-07
-site:duwa
Here is another DUware product, DUpaypal. Once you get hold of the
database it contains the adm
filetype:inc
2005mysql_connect OR
02-09
mysql_pconnect
INC files have PHP code within them that contain unencrypted usernam
passwords, and addresse
The servU FTP Daemon ini file contains setting and session information
including usernames, pas
2004ext:ini eudora.ini
12-19
Web Wiz Journal ASP Blog. The MDB database is mostly unprotected an
can be downloaded directly
2004inurl:filezilla.xml -cvs
12-02
2004- inurl:GRC.DAT
symantec Norton Anti-Virus Corporate Edition data file containing encrypte
11-28 intext:password&qu passwords.
2004- filetype:log See
11-28 `ipsec copyright
powered by
2004dudownload
11-23
-site:duware.com
intitle:dupics inurl:
2004Most duware products use Microsoft Access databases in default locations
(add.asp | default.asp
11-23
without instructing th
| view
powered by
2004duclassmate
11-23
-site:duware.co
Powered by
2004Duclassified
11-23
-site:duware.c
Powered by
2004Dudirectory
11-23
-site:duware.co
Powered by
2004Duclassified
11-23
-site:duware.c
powered by
2004ducalendar
11-23
-site:duware.com
2004- intext:enable secret 5 sometimes people make mistakes and post their cisco configs on help site
11-16 $
and dont
This finds the liveice.cfg file which contains all configuration data for an Ice
server. P
2004- filetype:ini inurl:serv- serv-U is a ftp/administration server for Windows. This file leaks info about
11-06 u.ini
version, user
2004linux vpns store there usernames and passwords for PAP authentification in
inurl:pap-secrets -cvs
11-06
file called
2004linux vpns store their usernames and passwords for CHAP authentification
inurl:chap-secrets -cvs
11-06
file called
2004- filetype:ini
10-10 inurl:flashFXP.ini
FlashFXP offers the easiest and fastest way to transfer any file using FTP,
providing an except
Elite forums is one of those Microsoft Access .mdb file based forums. This o
is particularly
2004Web Wiz Forums is a free ASP Bulletin Board software package. It uses a
filetype:mdb wwforum
09-24
Microsoft Access databa
2004- index of/ ws_ftp.ini This search is a cleanup of a previous entry by J0hnny. It uses parent
09-17
directory to
filetype:config config
2004intext:appSettings
09-16
Us
2004filetype:ini wcx_ftp
08-25
This searches for Total commander FTP passwords (encrypted) in a file calle
wcx_ftp.ini. Only
2004filetype:conf oekakibbs
08-16
2004http://*:*@www domainname
08-14
This will search for backup files (*.bak) created by some editors
even by the administrator
2004inurl:/db/main.mdb
08-13
2004inurl:nuke filetype:sql
08-10
2004filetype:ini ServUDaemon
08-06
The servU FTP Daemon ini file contains setting and session
information including usernames, pas
Generally, these are dbman password files. They are not clearte
but still allow an attacker
2004filetype:pwl pwl
07-29
These are Windows Password List files and have been known to
easy to crack since the release
2004sets mode: +k
07-19
2004filetype:mdb inurl:users.mdb
06-16
2004inurl:ccbill filetype:log
06-18
inurl:zebra.conf
2004GNU Zebra is free software that manages TCP/IP based routing protocols.
intext:password -sample
06-10
supports BGP-4 prot
-test -tu
2004filetype:pwd service
06-10
2004filetype:sql password
06-04
2004- filetype:sql
06-04 +IDENTIFIED BY -cvs
2004filetype:ldb admin
06-02
According to filext.com, the ldb file is A lock file is used to keep muti-use
databases
The world-famous web-browser Opera has the ability to save the passwo
for you, and it call th
05-26
combos. There is
2004The .netrc file is used for automatic login to servers. The passwords are
filetype:netrc password
05-26
stored in cleartext.
2004filetype:ini ws_ftp pwd
05-26
2004- inurl:slapd.conf
05-25 intext:rootpw&q
slapd.conf is the configuration file for slapd, the opensource LDAP deamo
You can view a clea
2004- inurl:slapd.conf
05-25 intext:credenti
slapd.conf is the configuration file for slapd, the opensource LDAP deamo
The key crede
2004filetype:inc dbconn
05-26
This file contains the username and password the website uses to conne
the db. Lots of th
2004- inurl:wvdial.conf
05-24 intext:passwor
2004- filetype:pem
05-17 intext:private
This search will find private key files Private key files are supposed to b
well privat
2004slapd.conf is the file that contains all the configuration for OpenLDAP,
filetype:conf slapd.conf
05-17
including the root pas
2004- filetype:dat
05-17 password.dat
2004- filetype:log
05-13 inurl:password.log
These files contain cleartext usernames and passwords, as well as the sit
associated with tho
filetype:url
2004+inurl:ftp://
05-12
+inurl:&qu
These are FTP Bookmarks, some of which contain plaintext login names a
passwords.
2004- inurl:vtund.conf
05-12 intext:pass -cvs
filetype:reg reg
2004HKEY_CURRENT_USER
05-11
SSHHOSTKEYS
This search reveals SSH host key fro the Windows Registry. These fi
contain information abou
filetype:reg reg
2004These pages display windows registry keys which reveal passwords
+intext:defaultusername&qu
05-07
and/or usernames.
o
2004- filetype:inc
05-05 intext:mysql_connect
INC files have PHP code within them that contain unencrypted
usernames, passwords, and addresse
2004- intitle:index of
05-03 intext:globals.inc
2004inurl:perform filetype:ini
05-03
Displays the perform.ini file used by the popular irc client mIRC. Of
times has channel pass
2004- intitle:index of
04-26 intext:connect.inc
These files contain ColdFusion source code. In some cases, the pag
are examples that are foun
2004- inurl:secring ext:skr | ext:pgp This file is the secret keyring for PGP encryption. Armed with this fi
03-04 | ext:bak
(and perhaps a passphr
2004- intitle:index.of
03-04 administrators.pwd
2004htpasswd
03-04
2003trillian.ini
08-19
Trillian pulls together all sort of messaging clients like AIM MSN, Yah
IRC, ICQ, etc. The v
The old config.php script. This puppy should be held very closely. It
should never be viewable
2003auth_user_file.txt
07-11
2003etc (index.of)
06-27
This search gets you access to the etc directory, where many many
many types of password files
2003passlist
06-27
Im not sure what uses this, but the passlist and passlist.txt files contain
passwords in CLEAR
2003config.php
06-24
This search brings up sites with config.php files. To skip the technical
discussion
2003spwd.db / passwd
06-24
2003htpasswd / htgroup
06-24
2003master.passwd
06-24
2003passwd
06-24
2003people.lst
06-24
*sigh*
2003- intitle:index.of
PGP is a great encryption technology. It keeps secrets safe. Everyone fro
06-24 intext:secring.skr|&q drug lords to the he
2003mysql history files
06-24
2014inurl:typo3/install/index.php?mode=
04-07
2014inurl:Citrix/XenApp/auth/login.aspx
03-31
2014allinurl:zimbra/?zinitmode=http -googl
02-05
2014allinurl:/main/auth/profile.php -githu
01-03
[+] This dork will help you find Chamilo login porta
Depending on the version, the site co
2013inurl:/administrator/index.php?autologin=1
12-03
2013inurl:/data/nanoadmin.php
11-25
2013inurl:/secure/login.aspx
08-08
2013- inurl:5000/webman/index.c
Synology nas login
08-08 gi
2013- Welcome to phpMyAdmin
Finds cPanel login pages. Andy G twitter.com/vxhex
08-08 + Username
2013- inurl:/secure/Dashboard.jsp Finds login pages and system dashboards for Atlassians JIRA. Andy
08-08 a intitle:System
twitter.com/vxhex
2013- intitle:Cisco Integrated
08-08 Management Controll
2013inurl:dasdec/dasdec.csp
08-08
2013- Serv-U (c) Copyright 1995- # Category: FTP Login Portals # Description : Dork for finding FTP Log
04-22 2013 Rhino Software, Inc portals # Google Dor
2013- intext:Computer Misuse Act Category : Pages containing login portals Description : Dork for findin
04-09 inurl:login.aspx
sensitive login porta
04-09
SYSTEM AUTHORISED
ACCESS
2013site:login.*.*
02-05
Gives sites with default username root and no password nitish meh
2012inurl:phpliteadmin.php
11-02
This dork will find most Linux-based DVR web clients that are accessib
to the web and throug
2012- inurl:/app_dev.php/login
08-21 Environment
2012inurl:cgi-bin/webcgi/main
08-21
2010inurl:src/login.php
11-13
2010inurl:/dana-na/auth/
11-12
2006inurl:+:8443/login.php3
09-27
2006FlashChat v4.5.7
07-29
2006intitle:IMP inurl:imp/index.php3
05-03
2006intitle:TWIG Login
05-03
2006(intitle:rymo Login)|(intext:We
05-03
2006- inurl:/slxweb.dll/external?
05-03 name=(custportal|
2006inurl:php121login.php
05-03
2006intitle:EZPartner -netpond
03-21
2006inurl:vsadmin/login | inurl:vsad
03-21
inurl:2000
2006RemotelyAnywhere is a program that enables remote control, in the sa
intitle:RemotelyAnywhere
03-21
matter as VNC. Once Log
-site:realvnc.
2006- inurl:/admin/configuratio simply google inurl trick for Oscommerce for open administrator page.I
03-07 n. php? Mysto
no .htpassword is set f
2006inurl:ids5web
02-09
The page to change admin passwords. Minor threat but the place to sta
an attack.
2006- intitle:Ovislink
01-16 inurl:private/login
betaparticle (bp) blog is blog software coded in asp. This google dork fi
the admin logins.
12-31
2005- intitle:Admin login Web sift Group makes a web site administration product which can be acces
12-19 Site Adm
via a web browser. Th
inurl:/Merchant2/admin.m
2005Miva Merchant is a product that helps buisnesses get into e-commerce.
v|
12-19
dork locates their
inurl:/Merchant2/admin
2005- site info for Enter
11-21 Admin Passwo
This will take you to the cash crusader admin login screen. It is my first
google hack.. also t
2005- inurl:webvpn.html login The Cisco WebVPN Services Module is a high-speed, integrated Secure
11-16 Please e
Sockets Layer (SSL) VPN ser
2005- This is a restricted
11-16 Access Server &qu
2005- intitle:Merak Mail Server User login pages for Merak Email Server Suite which consists of Merak
11-16 Web Administration
Email Server core and opt
2005- Powered by Merak Mail
11-13 Server Software
Webmail login portals for Merak Email ServerMerak Email Server Suite
consists of multiple award
This search finds the login page for iCONECTnxt, it enables firms to sea
organize, and revi
WorkZone Extranet Solution login page. All portals are in french or span
belive.
intitle:OnLine
2005Recruitment Program
11-12
Login&q
Docutek Eres is software that helps libaries get an internet end to them
This dork finds the a
2005- intitle:iDevAffiliate
09-25 admin -demo
2005- Please login with admin PHPsFTPd is a web based administration and configuration interface for
09-25 pass -le
SLimFTPd ftp serverI
2005- intitle:Admin Login
09-25 admin login&
Aimoo Login Pages. Looking for a free message board solution? Aimoo
provides one of the m
inurl:/modcp/
2005there have been several dorks for vBulletin, but I could not find one in t
intext:Moderator+vBullet
09-23
search that target
in
2005- intitle:PHProjekt login PHProjekt is a group managing software for online calenders, chat, forum
09-21 login passwo
etc. I looked aroun
2005- login prompt
09-13 inurl:GM.cgi
2005- Powered by Monster Top 2 Step dork Change url to add filename admin.php (just remove
09-13 List MTL numran
index.php&stuff
2005- intext:Master Account
09-13 Domain Na
intitle:Content
2005Management System
09-13
&quo
WorkZone Extranet Solution login page. All portals are in french or span
belive.
intitle:OnLine
2005Recruitment Program
11-12
Login&q
Docutek Eres is software that helps libaries get an internet end to them
This dork finds the a
10-13 e
2005- intitle:Supero Doctor III Supero Doctor III Remote Management by Supermicro, Inc.info:
09-26 -inurl:super
http://www.supermicro.
2005- intitle:iDevAffiliate
09-25 admin -demo
2005- Please login with admin PHPsFTPd is a web based administration and configuration interface for
09-25 pass -le
SLimFTPd ftp serverI
2005- intitle:Admin Login
09-25 admin login&
Aimoo Login Pages. Looking for a free message board solution? Aimoo
provides one of the m
inurl:/modcp/
2005there have been several dorks for vBulletin, but I could not find one in t
intext:Moderator+vBullet
09-23
search that target
in
2005- intitle:PHProjekt login PHProjekt is a group managing software for online calenders, chat, forum
09-21 login passwo
etc. I looked aroun
2005- login prompt
09-13 inurl:GM.cgi
2005- Powered by Monster Top 2 Step dork Change url to add filename admin.php (just remove
09-13 List MTL numran
index.php&stuff
2005- intext:Master Account
09-13 Domain Na
intitle:Content
2005Management System
09-13
&quo
2005- intitle:Content
08-30 Management System
&quo
2005inurl:csCreatePro.cgi
08-28
This is the login for xams it should catch from 0.0.1-0.0.150.0.15 being
latest version as
2005- HostingAccelerator
08-14 intitle:login
This will find the login portal for HostingAccelerator ControlPanel I have
looked for explo
2005- intitle:communigate pro Just reveals the login for Communigate Pro webmail. A brute force attac
08-11 * * intitle:&q
could be attempted. Th
2005intitle:AlternC Desktop This finds the login page for AlternC Desktop I dont know what versions
08-15
2005intitle:phpnews.login
08-10
This dork reveals login pages for Kerio Mail server. Kerio MailServer is a
state-of-the-art gro
Pretty standered login pages, they all have various differences but it
appears that they use th
2005- intitle:TOPdesk
07-22 ApplicationServer
2005- inurl:textpattern/index.ph
Login portal for textpattern a CMS/Blogger tool.
06-09 p
2005intitle:Login to Cacti
06-24
2005intext:Welcome to inurl:cp
06-05
This gives results for hosting plans that dont have assoc
fees, so anyone can sign up wit
2005intitle:XcAuctionLite | DRIVEN B
06-07
This search reveals the login page for the Cyclades TS10
and TS2000 Web Management Service. T
2005inurl:exchweb/bin/auth/owalogon.asp
05-15
2005- inurl:Citrix/MetaFrame/default/default.as
MetaFrame Presentation Server
05-15 px
2005inurl::2082/frontend -demo
05-11
2005intitle:WorldClient intext:
05-02
2005intitle:open-xchange inurl:login.pl
05-02
2005inurl:gnatsweb.pl
05-02
This search will show the login page for Cisco VPN 3000
concentrators. Since the default user
2005- intext:"vbulletin"
04-09 inurl:admincp
2005- inurl:usysinfo?
01-25 login=true
PhotoPost was designed to help you give your users exactly what they w
Your users will be t
Homepage: http://www.stoverud.com/PHPhotoalbum/PHPhotoalbum is a
picturegallery script. You can
2005- inurl:631/admin
01-18 (inurl:op=*
Administration pages for CUPS, The Common UNIX Printing System. Mos
are password protected.
2005- inurl:Activex/default.htm This search will reveal the active X plugin page that allows someone to
01-15 Demo&q
access PC Anywhere from
2005- pcANYWHERE EXPRESS This search will reveal the java script program that allows someone to
01-15 Java Client
access PC Anywhere from,
2004- intext:BiTBOARD v2.0 The bitboard2 is a board that need no database to work. So it is useful f
12-19 BiTSHiFTERS
webmaster that have
2004- intitle:Login intext:RT is RT is an enterprise-grade ticketing system which enables a group of peo
12-19
to intelligently and
2004- intitle:Athens
12-19 Authentication Point
Enterprise Manager 10g Grid Control provides a single tool that can mo
and manage not only
2004- intitle:WebLogic Server BEA WebLogic Server 8.1 provides an industrial-strength application
12-19 intitle:
infrastructure for developi
2004- intitle:MX Control
12-19 Console If yo
2004- intitle:VitalQIP IP
12-07 Management System
The VitalQIP Web Client Interface provides a World Wide Web interface f
the VitalQIP IP Manag
intext:Storage
2004These pages can reveal information about the operating system and pa
Management Server for
11-30
level, as well as provi
i
2004- intitle:PHP Advanced
2004- inurl:/webedit.* intext:WebEdit WebEdit is a content management system. This is the login portal
11-18 Professional -html
search.
2005- intitle:phpPgAdmin Login
03-03 Language
2004- inurl:postfixadmin
11-16 intitle:postfix admin&quo
2004- intitle:Icecast Administration Icecast streaming audio server web admin.This gives you a list of
11-07 Admin Page&qu
connected clients. Interestin
2004inurl:irc filetype:cgi cgi:irc
11-04
2004intitle:plesk inurl:login.php3
10-20
2004- intitle:ISPMan : Unauthorized ISPMan is a distributed system to manage components of ISP from
10-19 Access prohibi
central management interface.
2004SysCP login
10-19
2004- inurl:calendar.asp?
10-06 action=login
intitle:remote
2004The Aanval Intrusion Detection Console is an advanced intrusion detect
assessment OpenAanval
10-16
monitor and alerting
C
2004- WebExplorer Server
10-16 Login Welco
Philex (phile file explorer) is a web content manager based php what
philex can do ? eas
2004- inurl:default.asp
Polycom WebCommander gives you control over all aspects of setting u
10-14 intitle:WebCommander conferences on Polycom MG
2004intitle:MailMan Login
10-11
intitle:oMail-admin
2004Administration
10-05
Login&q
2004- intitle:microsoft
09-24 certificate services
2004inurl:mewebmail
09-23
2004- inurl:typo3/index.php?
09-21 u= -demo
2004- inurl:administrator
09-21 welcome to mambo
This finds login portals for Apache Tomcat, an open source Java servlet
container which can run
Easy File Sharing Web Server is a file sharing software that allows visito
upload/download
Usermin is a web interface that can be used by any user on a Unix syste
to easily perform task
2004intitle:TUTOS Login
09-18
TUTOS stands for The Ultimate Team Organization Software. This sear
finds the log
filetype:pl Download:
2004SuSE Linux
09-10
Openexchang
this search will get you on the web administration portal of linux open
exchange servers.
intitle:Novell
2004intitle:WebAccess
08-21
Copyright *
2004- Login (Powered by Jetbox Jetbox is a content management systems (CMS) that uses MySQL or
08-20 One CMS
equivalent databases. There is
2004- intitle:ITS System
08-16 Information P
Novell NetWare
2004intext:netware
08-16
management por
inurl:cgi2004bin/ultimatebb.cgi?
08-13
ubb=login
These are login pages for Infopops message board UBB.classic. For th
UBB.threads you can use
2004- intitle:please login your These administrators were friendly enough to give hints about the
08-13 passwo
password.
2004Ultima Online loginservers This one finds login servers for the Ultima Online game.
08-09
2004- WebSTAR Mail Please
08-09 Log In
2004- intitle:teamspeak server- TeamSpeak is an application which allows its users to talk to each othe
08-09 administration
over the internet and
2004- inurl:/cgi-bin/sqwebmail?
08-06 noframes=1
2004- (inurl:ars/cgi-bin/arweb?
08-05 O=0 | inurl:a
2004- intitle:Node.List
08-05 Win32.Version.3.11
2004- inurl:utilities/TreeView.asp From the marketing brochure: UltiPro Workforce Management offers y
07-29
the most comprehensi
2004- ASP.login_aspx
07-26 ASP.NET_SessionId
.NET based login pages serving the whole environment and process tr
for your viewing pleasur
2004Powered by INDEXU
07-22
2004phpWebMail
07-12
2004- filetype:php
07-09 inurl:webeditor.php
2004CGI:IRC Login
06-22
2004ttawlogin.cgi/?action=
06-04
2004filetype:r2w r2w
06-04
2004inurl:search/admin.php
05-30
2004inurl:/eprise/
05-26
2004please log in
05-13
2004inurl:webadmin filetype:nsf
05-11
This iks the login page for eMule, the p2p file-sharing program.
These pages forego the login n
2004inurl:/Citrix/Nfuse17/
05-10
These are Citrix Metaframe login portals. Attackers can use thes
profile a site and can use
2004- inurl:metaframexp/default/login.a These are Citrix Metaframe login portals. Attackers can use thes
05-10 sp | intitle:&quo
profile a site and can use
2004inurl:names.nsf?opendatabase
05-04
2004inurl:/admin/login.asp
04-21
2004inurl:login.asp
04-21
2004- inurl::10000
04-20 intext:webmin
2004inurl:login.cfm
04-19
This is the default login page for ColdFusion. Although many of these a
secured, this is an i
2004- intitle:ColdFusion
04-19 Administrator Login
2004- allinurl:exchange/logon.as According to Microsoft Microsoft (R) Outlook (TM) Web Access is a
04-16 p
Microsoft Exchange Acti
2014- intitle:not accepted
02-05 inurl:union+select
2013filetype:jnlp
11-25
2013intitle:IPCam Client
11-25
With this search you can view results for mikrotik graphics interfac
*Obrigado,*
Yet another DVR system. Probably requires Java to display. 4N6 Sec
2013inurl:/webcm?getpage=
09-24
2013inurl:/cgi-mod/index.cgi
09-24
2013- intitle:SPA504G
09-24 Configuration
2013- intitle:Web Image Monitor & #Summary: Several printers that use Web Image Monitor contro
08-08 inurl:
panel ( http://ricoh
2013- intitle:Transponder/EOL
08-08 Configuration:
2013- inurl:/voice/advanced/
04-22 intitle:Linksys SPA configu
2013inurl:/control/userimage.html
02-05
This dork finds web interfaces of various routers using custom firm
DD-WRT. Default login
2012inurl:32400/web/index.html
11-02
Submitting this for the GHDB. These are web accessible Plex Media
Servers where you can watch
This dork will locate Unsecured PHP APC Installations. With regards
Shubham Mittal (Hack
HP LaserJet printers
2012- inurl:Settings.aspx
05-15 intitle:Beyond TV
Beyond TV gives you the capability to turn your PC into a high qual
digital video recorder
2012- intitle:HtmlAnvView:D7B039 This dork finds Wireless Security/Webcams that are accessible from
05-15 C1
web. The interesting p
2011inurl:cgi-bin/cosmobdf.cgi?
12-28
2011- inurl:RgFirewallRL.asp |
12-27 inurl:RgDmzHost.asp | inu
2011intitle:SpectraIV-IP
12-26
2011inurl:/cgi-bin/makecgi-pro
12-12
UniMep is a device for managing fuel station. You can see process
fueling cars and you can
2010inurl:/level/15/exec/11-21
2010- inurl:/level/15/exec/-/configure
Default Cisco 2800 Series page
11-21 /http
2010- allintitle:SyncThru Web
11-11 Service
2010- intitle:EvoCam
11-10 inurl:webcam.html
2006- intitle:Your Network Device Login page for the Solwise Sar715+ ADSL Router from solwise.co.u
10-02 Status (LA
Thanks to jeffball55 for the
2006- SnapGear Management
10-02 Console Welc
2006- LANCOM DSL/*-* Office * h**p://www.lancom-systems.de/Login page for these Lancom online D
10-02 Entry Pa
devices.
2006inurl:wrcontrollite
09-11
2006allintitle:DVR login
06-30
2006- intitle:stingray fts login | ( The Stingray File Transfer Server: Open communication regardless of
06-29 login.j
platform, protocol or locat
2006- intitle:BlueNet Video
06-25 Viewer
Near broadcast quality video over the internet. A full 30fps at the 320
240 size. 12fps at th
2006- allintitle: Axis 2.10 OR 2.12 No one search will reveal all Axis cameras. This is a variant for the 2xx
06-25 OR 2.30 OR 2.31 OR 2
series.
2006- intitle:Live View / AXIS | No one search will reveal all Axis cameras. This is my mod of one of th
06-25 inurl:vie
queries. It usualy ret
2006intitle:Divar Web Client
06-25
Everfocus EDR400
Everfocus EDR1600
2006- allintitle: EverFocus | EDSR Modified Everfocus search, pulls in EDSR400s as well s a few strays
06-25 | EDSR400 Applet
missed by original query.
2006- intitle:SNC-RZ30 HOME
06-22 -demo
(intitle:(EyeSpyFX|
2006OptiCamFX) go to
05-04
camera&q
hxxp://www.netbotz.com/products/index.htmlNetwork/server/room
security and enviromental alarm d
(intitle:MOBOTIX
2006intitle:PDAS) |
04-19
(intitle:MOBOTIX
2006intitle:IVC Control Panel this searches for security cameras, vendor site:http://www.ivcco.com/
04-18
2006- intitle:Edr1680 remote
03-21 viewer
This search finds the 1680 series digital video recorder from EverFocus
2006- OK logout inurl:vb.htm? This is a google dork for Hunt Electronics web cams. To get to the came
03-21 logout=1
remove the vb.htm?l
2006- intitle:DVR Client -the
03-21 -free -pdf -do
intitle:Skystream
2006Networks Edge Media
03-18
Router
2006- intitle:NAS
03-18 inurl:indexeng.html
This is used in serverrooms and such where climate conditions are cruci
hardware health. I
This is the web interface for Alcatels Omniswitch. Default login is:
admin/switch.
2006- inurl:setdo.cgi intext:Set Dcs-2100 camerasBy removing intext:Set DO OK you will get more hit
02-08 DO OK
but they will r
2006- intext:Welcome to
02-08 Taurus The Tau
2006- intitle:::::: INTELLINET IP A variation on Jeffball55s original Intellinet Ip Camera.This search finds
01-16 Camera Homepage
several more web ca
Login pages for the DCS-950 Web Camera. Even comes with a built in
microphone.
intitle:Axis
2005similar searchs exist. This search finds a few more results as well as acc
inurl:/admin/admin.shtm
12-31
to the Admin area
l
2005inurl:/img/vr.htm
12-31
2005inurl:Printers/ipp_0001.asp
12-08
2005- (port_255/home)|(inurl:home?
11-05 port
2005- Phaser numrange:100-100000 Name This is a search for various phaser network printers. With thi
09-21 DNS IP More
search you can look for printe
2005- intitle:netbotz appliance -inurl:.php Netbotz devices are made to monitor video, temperature,
09-16
electricity and door access in server r
2005- intitle:NetCam Live Image -.edu
09-06 -.gov
2005intitle:INTELLINET intitle:IP Ca
08-27
video
2005intitle:Java Applet Page inurl:ml
07-22
2005printers/printman.html
06-07
2005intitle:configuration inurl:port_0
06-07
2005inurl:CgiStart?page=
06-08
2005inurl:S=320240 | inurl:S=16012
06-07
2005- (cam1java)|(cam2java)|(cam3java)|(cam4java)|
06-01 (cam5j
2005- ( intitle:PacketShaper
05-20 Login)|(intitle
2005- intitle:PacketShaper
05-19 Customer Login
2005- intitle:Dell *
05-31 inurl:port_0
oA few Online Dell Printers, status, paper, toner levels, ips macs, the usu
(Lexmark and De
speedtouch 510 DSL modem devices that were once unprotected. That m
have changed by now.
2005inurl:start.htm?scrw=
05-14
Zyxel Zywall
2005inurl:port_255 -htm
05-02
Another way to dig up some not yet dorked Lexmark and a couple of De
printers.http://johnny.i
2005- intitle:Freifunk.Net
05-02 Status -site:co
ext:dhtml
2005intitle:"document
05-02
centre|(home)
A search for some HTML code used in a variety of D-link network devices
(webcams and such).
2005- intitle:NeroNET
04-20 burning online
Just a bit of fun, should reveal a few instances of a Winamp HTTP contro
program. Without logi
2005- intitle:OfficeConnect
04-16 Cable/DSL Gateway
2005inurl:JPGLogin.htm
04-12
intitle:jdewshlp
2005Welcome to the
04-12
Embedded Web
2005inurl:/en/help.cgi ID=* Aficio printers (this search locates the help pages)..
04-12
Actiontec Routers.
2005- intitle:asterisk.management.po Coalescent Systems Inc. launched The Asterisk Management Port
03-20 rtal web-access
project to bring together best-
2005inurl:camctrl.cgi
03-05
2005- intitle:supervisioncam
02-22 protocol
2005- intitle:Linksys
02-15 site:ourlinksys.com
2005- intitle:"Brother"
02-04 intext:&qu
2005- intitle:"Connection
02-02 Status" inte
2005inurl:na_admin
02-01
This searches for the admin pages for a Network Appliance box
authenticated use
This reveals the Epson Web Assist page (internal to the machine)
2005allinurl:index.htm?cus?audio
01-27
This will find webcams made by Sweex, Orite and others. Support
motion detection, ftp, smtp an
Axis Network Print Server devices. This search has all the possible
(more than strictly ne
2005filetype:cgi transcoder.cgi
01-11
2004- inurl:next_file=main_fs.htm
12-30 inurl:img
2005- intitle:SpeedStream *
01-08 Management Interface&q
2004- intitle:Sipura.SPA.Configuratio Query returns configuration pages for online Voice over IP devices
12-30 n -.pdf
Discloses an obscene amount
200412-08
some of the sites are very, very interesting try a search substitu
site:gov instead of si
2004intitle:Cayman-DSL.home
12-19
2004intitle:iVISTA.Main.Page
12-13
2004- intitle:AudioReQuest.web.serv Audio ReQuest home CD/MP3 player. Various information about th
12-06 er
configuration of the host and s
2004intitle:V-Gear BEE
12-06
2004- intitle:Live NetSnap
12-06 Cam-Server feed
2004- axis storpoint file view The Axis Storpoint device turns a SCSI or ATA box with lots of cdrom pla
12-04 inurl:/volume
(or writers) into
2004- inurl:printer/main.html
Brother HL Printers.
12-03 intext:s
2004- intext:MaiLinX Alert
12-03 (Notify) -site:ne
intext:Videoconference
2004Tandberg video conferencing appliancesThe webinterface enables you t
Management
11-28
drop calls and to browse
System&quo
2004- intitle:Smoothwall
11-24 Express inurl:cgi-b
2004intitle:ipcop main
11-23
IPCop Firewall is a Linux firewall for home and SOHO users. IPCop can be
managed from a simple
2004- intitle:EvoCam
11-18 inurl:webcam.html
Evocams !
siteZap webcams !
2004inurl:axis-cgi
11-16
Just another search string to detect the infamous Axis netcams. This
company actually changed t
Lexmark printers (T620, T522, Optra T614, E323, T622, Optra T610, Op
T616, T520 and Optra S
2004- WebControl intitle:AMX AMX Netlink is a server appliance which connects various devices like a
11-06 NetLinx
beamer, laptop or video
2004- please visit intitle:i-
11-03 Catcher C
2004- intitle:toshiba network
Web interface of Toshiba network cameras.
10-25 camera User Login&
2004- inurl:level/15/exec/-/sho This search finds Cisco devices which have level 15 access open via
10-20 w
webinterface. If an attacke
2004- site:.viewnetcam.com
10-19 -www.viewnetcam.com
2004- inurl:TiVoConnect?
10-18 Command=QueryServer
2004inurl:netw_tcp.shtml
10-12
2004- (inurl:webArch/mainFrame.cgi ) |
10-11 (intitle:we
2004intitle:DEFAULT_CONFIG HP
10-09
2004intitle:webeye inurl:login.ml
10-05
2004inurl:hp/device/this.LCDispatcher
10-05
2004intitle:lantronix web-manager
09-29
2004Aficio 1022
09-29
The Axis 200 HOME pages reside within the AXIS 200 devi
and hold information about the curre
2004this search will show web administration interfaces of linux dream boxes.
intitle:dreambox web
09-10
Dreambox is one of
2004- Phasers
08-05 4500/6250/8200/8400
Canon has a series of netcams that all use the WebView LiveScope
software. They are
2004- Xerox Phaser This product is supported but no longer sold by Xerox in the United State
07-22 840 Color Printer
Support and supplie
2004Xerox Phaser 8200
07-22
Brochure info: The Phaser 8200 uses solid ink, an alternative technology
laser printin
2004- Xerox Phaser This product is supported but no longer sold by Xerox in the United State
07-22 740 Color Printer
Replacement Product
2004Xerox Phaser 6250
07-22
2004- intitle:BorderManager
07-19 Information alert
These AXIS cams seem to run their own http server (Boa/0.94.13). The se
button can be hidden
powered by
2004webcamXP Pro|
07-16
Broadcas
2004Mobotix netcams
07-10
2004- sony SNC-RZ20 network sony NC RZ20 cameras, only one result for this cam at the moment, a nic
07-10 cameras
street view from a sky
2004- seyeon FlexWATCH
07-10 cameras
2004- sony SNC-RZ30 Network sony NC RZ30 cameras require a java capable browser. The admin pane
07-10 Cameras
found at http://[siten
2004- Panasonic Network
07-10 Cameras
These printers configuration is wide open. Attackers can change just abo
The AXIS 2400 is a Web server of its own. This means that the server is
secured like any other