http://www.cnsu.org-->site $ }# Z, v. M1 w' s- c! ]. Z
www.cnsu.org-->inurl
adminàinurl 5 N1 |5 r# w7 X( j# D# ^8 u) [
。asp D D》filetype ' e/ B0 q4 y! q* a 2 F- g% W- Q' F- O
标题 D D》intitle ( W! z7 }: s: o' Y; S
页面文字 D D》intext - a4 ~3 i" |; I6 u
页面编号 D D》numeange 6 `% L9 h0 i7 y# A! g$ w + e0 h& f/ z7 v. |# s
- 逻辑非,“A-B”表示包含A没有B的网页 ' X, v! L& l/ O( L) U
*代表单个字符 ! o/ B6 G0 q; j: ~) T7 h9 q8 v, V, \ , Y7 y3 _5 \" w% R) v" P P
or操作 ( e" }6 C' T- `# M0 t: z1 z " g% O% r( g0 J: }
“”用短语做关键字,必须加上引号,不然会被当作与操作 ! j1 c- D* m8 d% [( c. }$ r2 s 4 g5 L [) ?8 k& |9 W' X
。空格 1 H1 ]$ |) s' X4 L: c! \5 B% M
Google对一些网路上出现频率极高的英文单词,如“i”、“com”、“www”等,以及一些符号如“*”、“。”等,作忽略处理 ( {" V5 A1 J) c! }
可以用+强制搜索 * t" v1 P: u9 K. P0 q 7 ?" x: C4 R7 _1 r
下面的语句是我搜集来的,大家可以试着用下
比如用Intitle:welcome.to.iis.4.0 IIS4会找到好多winNT的主机,呵呵 4 x0 h0 M1 M3 e' N- j2 W 4 K! ]3 m3 C* k; t$ R- l5 h
Site:sohu.com 6 u: |6 b. F2 K! e( w1 X i! a* j$ \' y, i' P
Site:sohu.com-site:www.sohu.com ; c; h% S5 W' b7 }% D/ X& z& @ 0 H$ k) c' [. H( M5 l T1 j
Intitle:index.of/admin 7 Z2 x+ P4 v- _' h7 `( q 7 C! u m& I& G0 A0 V" Z9 J
Intitle:index.of apache server.at ( o- e: p/ A1 G
Intitle:test.page.for.apache “it workd” 3 G$ x/ @& A$ K9 a( ]8 _( `7 ^7 c * M, M9 ]1 R0 K/ e+ H
Allintitle:Netscape Fasr Track Server Home Page ! I% P5 c$ t, _* v2 b, F( q; {
Intitle:”welcome to windows 2000 internet services”
IIS—win2000
Allintitle:welcome to windows XP server internet
services iis---XP ' u/ ^$ B, I) b* K# J7 j& ^ $ ?1 F v5 x0 ?$ j6 M: g: N( q
Intitle:welcome.to.iis.4.0 IIS4 $ y, z% Q$ \3 k# V
Allintrtle:”welcome to internet information server” % Z ]; M- ~: T0 b" B% }0 u* Q5 p
IIS-- generic 7 Z( v7 ^6 ?1 c* I; m5 r% P x; ?2 O# G* d/ ? ]
Intitle:”apache http server”
Intitle:”documentation” ' Y; \9 C- M5 Q. j ~& f3 m
Intitle:””error using hypernews””server software” ' v- }3 s7 L( C
“HTTP_USER_AGENT=Googlebot”
“HTTP_USER_AGENT=Googlebot”TNS_ADMIN 9 T3 G: |3 W9 D- ? 9 U! O8 H% T/ \( T' L
Inurl:/admin/login.asp / O6 R. }+ e+ l- A% T$ }8 R
Intitle:”remote desktop wen connection” |9 @: Z( A$ S8 H# Q
“welcome to *” “Your password is *” 1 [/ [1 [& h4 c( p, b! f & X1 f+ U) ?: G% q
Inurl(browse top_rated power_search hot create_admin_user)+”powered
by inde xu” 4 z7 R: c2 Q/ b( O. \! \: J2 x' y ) K( E8 G' k) U5 q8 ]0 I; y
“adding new user” inurl:addnewuser C“there are no / ]* n, {" E3 F, r2 P: t
domain”
Filetype:log inurl:”password.log” ( `/ H( L6 P- j O
Intitle:”PHP Shell *” “enable stderr” filetype:php D' ~ |" g f0 \
Intitle:confixx login password 7 e8 m1 z8 l0 }/ @ 0 r& G) l8 A/ W6 a6 g
“powered by rover” : ~ m' R% Y# ]( F: u % N+ F8 g) G! Y4 Z- l. \* s
Inurl:iisadmpwd " l1 O- q9 }+ P: s t3 \1 T2 r
Inurl:5800 . }" S1 {: U1 E2 u& q
“VNC desktop” inurl:5800 $ O7 {3 h! \1 Q& q K, u ; H, ^0 N* ?" q
Inurl:webmin inurl:10000 . r: ~8 G3 ^0 H. X" j 9 q& L9 b) Q( S( y+ w2 y
Inurl:8080 Cintext:8080 # c8 d* A. E5 N. w
“access denird for user” “using password” " Q: f: `& b1 P- d; U* Q2 i+ B
“# Dumping data for table” , K& p1 T4 c* |! e" P3 P
“# Dumping data for table” username password H! i. [: A, N4 k$ d4 q9 G( q
“# Dumping data for table * i2 ^: _4 X* T- b5 D
(username user users password)” 0 S1 o# J/ H/ [+ |7 m2 b : Y& |5 [0 g1 [
Inurl:main.php welcome to phpmyadmin - V* r. i& @, C v$ _ 7 p! F$ t- o& a" f
Intitle:”phpmyadmin running on *” welcome to phpmyadmin " y6 E5 ?' B' @; n) g& `5 S6 f6 Q$ K
Filetype:inc intext:mysql connect
Filetype:sql + “INENTIFIED BY” Ccvs # X0 d5 g5 V; @8 m3 {
Filetype:sql + “INENTIFIED BY” (“grant * on *” “create 6 ~# Y/ N9 o) O9 x/ K
user”) % |. G( z# ~1 ]$ M - \% I0 i+ Q M- F
“this report lists” “identified by internet scaner”
ACID “by roman danyliw” Filetype
HP 3 Q9 q1 R: ]3 G% Y8 i. p3 p
小提示:用google hacking工具搜索这些,真的是多快好省啊:) 8 i5 p6 g4 [( B; T) ^' c
great!!
看不懂。。。。。。。。
!!!!!!!!!!!!!!
| 欢迎光临 数学建模社区-数学中国 (http://www.madio.net/) | Powered by Discuz! X2.5 |