![]() |
|
Google Dorks - Using Google efficiently - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: Google Dorks - Using Google efficiently (/Thread-Google-Dorks-Using-Google-efficiently) |
RE: Google Dorks - Using Google efficiently - lionking - 07-13-2014 Nice tut i didn't knew about some of dorks thanks....... RE: Google Dorks - Using Google efficiently - l4ur15 - 08-09-2014 filetype:pdf is usefull too. I personally use this to find documents. Didn't saw it there!
RE: Google Dorks - Using Google efficiently - Singularity_mybb_import13102 - 08-09-2014 Good tutorial, I didn't know about the "related:" option. I have one thing to point out though: Spoiler:(06-30-2014, 05:13 PM)RaccoonCity Wrote: Google dorks are typically used in hacking where you search for vulnerable websites. Since you didn't elaborate on this much, I will. Code: allinurl:php?id=The reason that the above filter is useful, is when people want to test some SQL Injeciton. If a website has php extension followed by a question mark "?", then it's going to be using a get parameter. Most of the time with a setup like this in PHP you are going to be querying a database for results. For example a URL, like the following Code: php?user=SingularityCode: <?php
$user = $_GET['user'];
$client = new mysqli('localhost', 'user', 'pass', 'user_table');
$query = <<<SQL
SELECT *
FROM `user_table`
WHERE `user` = $user
SQL;
if(!$result = $client->query($query)){
die('Error: [' . $db->error . ']');
}
while($row = $result->fetch_assoc()){
echo $row . '<br />';
}
$result->free();
$db->close();
?>Now, without proper sanitation, the hacker could manipulate the GET parameter, causing the database to give out more information than was originally intended. Seriously for a great example, follow the link below, it will give a good understanding of what is happening: http://sqlfiddle.com/#!2/ecd3fc/1 Now, another thing is that $_GET parameters are also quite suspect to XSS/XSRF attacks too, but we will discuss these at a later time. I just wanted to emphasis on this and elaborate, as you were extremely dodgy with your wording. RE: Google Dorks - Using Google efficiently - Eleven - 08-12-2014 Simple and well explained, Thx for the information! RE: Google Dorks - Using Google efficiently - Ex094 - 08-12-2014 Awesome thread, this is a must read for all of those who don't know how to use google PROPERLY RE: Google Dorks - Using Google efficiently - L0aD1nG - 08-14-2014 Thank you very much, I didn't know about Google Dorks! This will help for sure my infinite search. Great share man! RE: Google Dorks - Using Google efficiently - L0aD1nG - 08-14-2014 Thank you very much, I didn't know about Google Dorks! This will help for sure my infinite search. Great share man! RE: Google Dorks - Using Google efficiently - RaccoonCity_mybb_import13707 - 08-14-2014 (08-14-2014, 10:59 AM)L0aD1nG Wrote: Thank you very much, I didn't know about Google Dorks! You didn't know?! If not this will help you extremely much! RE: Google Dorks - Using Google efficiently - RaccoonCity_mybb_import13707 - 08-14-2014 (08-14-2014, 10:59 AM)L0aD1nG Wrote: Thank you very much, I didn't know about Google Dorks! You didn't know?! If not this will help you extremely much! RE: Google Dorks - Using Google efficiently - L0aD1nG - 08-14-2014 (08-14-2014, 12:05 PM)RaccoonCity Wrote:(08-14-2014, 10:59 AM)L0aD1nG Wrote: Thank you very much, I didn't know about Google Dorks! YES, thats something MUST known that I didn't know! Thank you very much! |