Dorking

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Resources

Google Dorking

  • Config Files:

  • Database files

  • Backup files

  • .git folder

  • Exposed Document

  • SQL Errors

  • PHP errors

  • Login pages

  • Open Redirects

  • Apache Struts RCE

Wordpress files

Other Files

Credentials in Trello

Zoom

Ciphermail Login

Various Services

Linkedin employees

AWS S3 Buckets

Azure

  • site:"blob.core.windows.net" AND intext:[TARGET]

Google Cloud

  • site:"storage.googleapis.com" AND intext:[TARGET]

Digitalocean Spaces

  • site:"digitaloceanspaces.com" [TARGET]

Git Providers

  • site:github.com | site:gitlab.com | site:bitbucket.org [TARGET]

Secrets in Microsoft Devops

  • site:"dev.azure.com" AND intext:secret

  • site:"dev.azure.com" AND intext:password

  • site:"dev.azure.com" AND intext:apikey

Various Services

  • site:stackoverflow.com AND intext:"[TARGET]"

  • site:jfrog.io AND intext:"[TARGET]"

  • [TARGET]

  • intitle:traefik inurl:8080/dashboard [TARGET]

  • intitle:"Dashboard [Jenkins]" [TARGET]

  • (site:bitpaste.app | site:codebeautify.org | site:codepad.co | site:codepad.co |site:ideone.com | site:codepad.org | site:codepen.io | site:codeshare.io | site:coggle.it | site:controlc.com | site:dotnetfiddle.net | site:dpaste.com | site:dpaste.org | site:gitter.im | site:hastebin.com | site:heypasteit.com | site:ide.geeksforgeeks.org | site:ideone.com | site:jsdelivr.com | site:jsdelivr.net | site:jsfiddle.net) AND "[TARGET]"

  • (site:justpaste.it | site:libraries.io | site:npmjs.com | site:npm.runit.com | site:npm.runkit.com | site:papaly.com | site:paste2.org | site:pastebin.com | site:paste.debian.net | site:pastehtml.com | site:paste.org | site:phpfiddle.org | site:prezi.com | site:productforums.google.com | site:repl.it | site:replt.it | site:scribd.com | site:sharecode.io | site:snipplr.com | site:trello.com | site:ycombinator.com) AND "[TARGET]"

Vulnerable web servers

SQL

WordPress

cgi-bin

Juicy files/Pages

Endpoints

Panels/Dashboards

PHPINFO | PHPMYADMIN

Dorks For Bug Bounty Programs

  • Single Dorks

GitHub Dorking

Shodan Dorking

Others

Last updated

Was this helpful?