(06-30-2014, 05:13 PM)RaccoonCity Wrote: Google dorks are typically used in hacking where you search for vulnerable websites.
An example on this would be the search:
That would pop up alot of websites with that url, which probably are vulnerable to it.
Since you didn't elaborate on this much, I will.
The above dork will not bring up a vulnerable sites. It's simply going to give you results of websites which contain that information.
The reason that the above filter is useful, is when people want to test some SQL Injeciton. If a website has php extension followed by a question mark "?", then it's going to be using a get parameter. Most of the time with a setup like this in PHP you are going to be querying a database for results.
For example a URL, like the following
Code:
php?user=Singularity
Is probably querying a database for the result of Singularity in a table. Something like this maybe:
Code:
<?php
$user = $_GET['user'];
$client = new mysqli('localhost', 'user', 'pass', 'user_table');
$query = <<<SQL
SELECT *
FROM `user_table`
WHERE `user` = $user
SQL;
if(!$result = $client->query($query)){
die('Error: [' . $db->error . ']');
}
while($row = $result->fetch_assoc()){
echo $row . '<br />';
}
$result->free();
$db->close();
?>
Now, without proper sanitation, the hacker could manipulate the GET parameter, causing the database to give out more information than was originally intended.
Seriously for a great example, follow the link below, it will give a good understanding of what is happening:
http://sqlfiddle.com/#!2/ecd3fc/1
Now, another thing is that $_GET parameters are also quite suspect to XSS/XSRF attacks too, but we will discuss these at a later time.
I just wanted to emphasis on this and elaborate, as you were extremely dodgy with your wording.