http://www.cnsu.org-->site 0 S u' a9 [. E. u
www.cnsu.org-->inurl
adminàinurl : M1 y2 B9 E6 [/ a
。asp D D》filetype " f8 @+ S" b0 J% Z5 I) N# d
标题 D D》intitle % u; f& S) C* [& p% ~ & g' A: o5 o& F) C5 Y2 r0 |
页面文字 D D》intext : |& J6 A; A2 Q7 D* \
页面编号 D D》numeange 8 M8 u7 X" z! s" b: \6 K + r) `! q7 F0 c- @2 J3 y
- 逻辑非,“A-B”表示包含A没有B的网页 e( W, m( R( b
*代表单个字符 4 j3 U/ C- D+ _, e% k4 C
or操作 2 I2 S% ^9 t5 Y& F" q+ E3 c! {( W! C
“”用短语做关键字,必须加上引号,不然会被当作与操作
。空格 + ^1 A5 U7 ]: O2 Z$ ?6 }
Google对一些网路上出现频率极高的英文单词,如“i”、“com”、“www”等,以及一些符号如“*”、“。”等,作忽略处理 3 ]* F- p5 r( k$ b8 ^" I$ L5 }: c 0 q* A- y3 ]6 F0 K* k: w
可以用+强制搜索
下面的语句是我搜集来的,大家可以试着用下 3 T" A9 D: E$ d" b. H
比如用Intitle:welcome.to.iis.4.0 IIS4会找到好多winNT的主机,呵呵 " Y: c3 h( a: ]6 D
Site:sohu.com ; v$ y4 [* Z3 z3 B: v" K! ~/ x: I
Site:sohu.com-site:www.sohu.com
Intitle:index.of/admin , M# O ]" C. K3 h& @2 `. s( G ) S+ e6 d, x* x" x) [1 e
Intitle:index.of apache server.at
Intitle:test.page.for.apache “it workd” , X* f" p' J7 U u" X' ]/ ]" Y
Allintitle:Netscape Fasr Track Server Home Page ; I9 R. ^$ L* t5 n j- `$ Q
Intitle:”welcome to windows 2000 internet services” # r% w9 ~5 ^" d# g
IIS—win2000 ' U" z8 D$ u# u' {( q
Allintitle:welcome to windows XP server internet
services iis---XP 5 s4 A; X: `+ j9 _1 Q4 h
Intitle:welcome.to.iis.4.0 IIS4
Allintrtle:”welcome to internet information server”
IIS-- generic
Intitle:”apache http server” + M$ {5 r: r( q! @/ M9 H$ f
Intitle:”documentation” ' i+ K' d! c) E: _! ~! q; ?' y
Intitle:””error using hypernews””server software” / L7 Z+ c# E1 c. f8 r1 h5 @5 e( P
“HTTP_USER_AGENT=Googlebot” 6 Q6 S& e, @, l; J' _ 5 i3 Z7 s8 R( \! O4 |7 [" k) D$ R
“HTTP_USER_AGENT=Googlebot”TNS_ADMIN 7 X3 _2 {. h! O2 ?5 M0 e; O 9 p0 V) D4 e' p- [" X; H0 ~0 g
Inurl:/admin/login.asp " i- d8 @! @* L) {# _+ v
Intitle:”remote desktop wen connection” 5 f9 P3 A* |# d
“welcome to *” “Your password is *” + C2 r+ u8 H* W1 H# ^5 E: V7 P
Inurl(browse top_rated power_search hot create_admin_user)+”powered $ i9 m/ u, N) T" `
by inde xu” 3 _; U8 x9 i1 F9 @% D
“adding new user” inurl:addnewuser C“there are no & e! O6 S) |% q
domain” 9 I8 q5 [4 L! A
Filetype:log inurl:”password.log”
Intitle:”PHP Shell *” “enable stderr” filetype:php 5 s# N% H1 o1 E/ H9 W3 k. p
Intitle:confixx login password
“powered by rover” 8 j6 v1 Y7 X; ?+ ? L& F6 C' Q , g' R5 \- @* ]* t
Inurl:iisadmpwd ; J( w( {* D! i" I* }" L* k/ m- ^/ D
Inurl:5800 9 x9 O( K% N6 P# {* V4 N
“VNC desktop” inurl:5800
Inurl:webmin inurl:10000 3 s+ S3 o s5 F+ I* D( ^& [
Inurl:8080 Cintext:8080 ' d6 \ Z$ N! r" z( X* u
“access denird for user” “using password” $ Q1 q, v% _: R1 d' _! ^' x 6 q+ O6 `6 l6 `. ]# |: A# e5 e
“# Dumping data for table” ! i' d, f7 O/ i% ? v% ?) N
“# Dumping data for table” username password $ i* m8 o& j7 `; A# e
“# Dumping data for table 4 q _- W O- M ?5 p$ k4 A
(username user users password)” 5 U: T) Q" W' E J$ A& z
Inurl:main.php welcome to phpmyadmin ( Y+ D& }6 Z( I, F3 Q: k/ E
Intitle:”phpmyadmin running on *” welcome to phpmyadmin , n0 e& @% l* e8 k+ w% m k
Filetype:inc intext:mysql connect 1 K7 p1 b. L- I; m
Filetype:sql + “INENTIFIED BY” Ccvs 0 @" l7 F! k) t2 x" y
Filetype:sql + “INENTIFIED BY” (“grant * on *” “create 6 j) L1 Z8 p( C+ X: I ; D/ G- O( T2 n# Q
user”) ' I0 K# C4 z \! N' ] ; ]% |6 D5 O {3 i/ d& ]# P6 l
“this report lists” “identified by internet scaner” 7 E8 M- S" S: w3 N6 c' r
ACID “by roman danyliw” Filetype
HP + Y. n9 C, U$ H: i0 p
% P. `/ ?' z% [7 E# r4 `
小提示:用google hacking工具搜索这些,真的是多快好省啊:) . {8 {) V. g) k
great!!
看不懂。。。。。。。。
!!!!!!!!!!!!!!
| 欢迎光临 数学建模社区-数学中国 (http://www.madio.net/) | Powered by Discuz! X2.5 |