Google searching tricks for passwords,credit cards ...etc

Discussion in 'Google' started by energy.fs, Nov 21, 2007.

  1. #1
    i want to share some google searching techniques ..here :)

    Querying for vulnerable sites or servers using Google’s advance syntaxes
    Using “Index of ” syntax to find sites enabled with Index browsing
    A webserver with Index browsing enabled means anyone can browse
    the webserver directories like ordinary local directories. Here
    I shall discuss how one can use “index of” syntax to get a list
    links to webserver which has got directory browsing enabled.
    This becomes an easy source for information gathering for a
    hacker. Imagine if the get hold of password files or others
    sensitive files which are not normally visible to the internet.
    Below given are few examples using which one can get access to
    many sensitive information much easily.
    Index of /admin
    Index of /passwd
    Index of /password
    Index of /mail
    "Index of /" +passwd
    "Index of /" +password.txt
    "Index of /" +.htaccess
    "Index of /secret"
    "Index of /confidential"
    "Index of /root"
    "Index of /cgi-bin"
    "Index of /credit-card"
    "Index of /logs"
    "Index of /config"
    Looking for vulnerable sites or servers using “inurl:” or “allinurl:”
    a. Using “allinurl:winnt/system32/” (without quotes) will list
    down all the links to the server which gives access to
    restricted directories like “system32” through web. If you are
    lucky enough then you might get access to the cmd.exe in the
    “system32” directory. Once you have the access to “cmd.exe”
    and are able to execute it then you can go ahead in further
    escalating your privileges over the server and compromise it.
    b. Using “allinurl:wwwboard/passwd.txt”(without quotes) in the
    Google search will list down all the links to the server which
    are vulnerable to “WWWBoard Password vulnerability


    if u like this ..tell me i will post more ....
     
    energy.fs, Nov 21, 2007 IP
  2. astup1didiot

    astup1didiot Notable Member

    Messages:
    5,926
    Likes Received:
    270
    Best Answers:
    0
    Trophy Points:
    280
    #2
    Script kiddie methods, respectable webmasters have this crapped closed already. This is NOT a hacking forum.
     
    astup1didiot, Nov 21, 2007 IP
  3. Diddy1

    Diddy1 Peon

    Messages:
    295
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Yeah you might wanna watch out of the ban hammer this is methods blackhats use.

    Thank You
     
    Diddy1, Nov 21, 2007 IP
  4. energy.fs

    energy.fs Peon

    Messages:
    46
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    i m posting just for information not for hacking purpose .....i know webmasters closed ......
     
    energy.fs, Nov 21, 2007 IP
  5. astup1didiot

    astup1didiot Notable Member

    Messages:
    5,926
    Likes Received:
    270
    Best Answers:
    0
    Trophy Points:
    280
    #5
    This is nothing new to anyone with "minimum" security knowledge.
     
    astup1didiot, Nov 21, 2007 IP
  6. lorien1973

    lorien1973 Notable Member

    Messages:
    12,206
    Likes Received:
    601
    Best Answers:
    0
    Trophy Points:
    260
    #6
    Yeah ok. Then what other reason would you want to get to someone's cmd.exe file? To launch a screensaver? Please.
     
    lorien1973, Nov 21, 2007 IP