http://www.cnsu.org-->site % T% }1 J0 J4 X) n5 s. R
www.cnsu.org-->inurl
adminàinurl ) u8 `% { P6 S; w/ n- D
。asp D D》filetype
标题 D D》intitle * @# d. O/ H; a* \ $ T3 R; Y" ? s
页面文字 D D》intext # E& r' q; J1 x4 K
页面编号 D D》numeange $ ~6 z4 I5 p7 W2 M: P& C 1 p% P! L$ R( H* Z& m
- 逻辑非,“A-B”表示包含A没有B的网页 / k6 ], a0 ^. `, {
*代表单个字符 3 l. X$ {+ x) `* ?
or操作 - U5 m; K- ^" S" X7 S/ `" t
“”用短语做关键字,必须加上引号,不然会被当作与操作 1 x) s% X' K. @5 Z4 l
。空格 * k% h0 v% H, d" G& l j 6 e+ {' [' w/ F# l
Google对一些网路上出现频率极高的英文单词,如“i”、“com”、“www”等,以及一些符号如“*”、“。”等,作忽略处理 : V/ w: r7 U% \7 F
可以用+强制搜索 * G) p5 m4 A: w3 V- c ( T! X& g7 a$ e
下面的语句是我搜集来的,大家可以试着用下
比如用Intitle:welcome.to.iis.4.0 IIS4会找到好多winNT的主机,呵呵 2 `, R/ q* Z; k6 h* ^$ N
Site:sohu.com , \5 G1 D9 Y5 a
Site:sohu.com-site:www.sohu.com 2 J4 _/ k% J( Y" S) b
Intitle:index.of/admin 3 W) @) v, j$ j' X
Intitle:index.of apache server.at * ~$ g9 w, }* \3 z3 G
Intitle:test.page.for.apache “it workd” . |+ P& |2 u4 i0 \$ {; F) @, h0 \
Allintitle:Netscape Fasr Track Server Home Page ) }) ]; y# `5 r m/ |4 F
Intitle:”welcome to windows 2000 internet services”
IIS—win2000 / ~6 M* K- C% y* d: Z# _0 S
Allintitle:welcome to windows XP server internet + b: q) h8 L9 C& V4 A- q * y# P- s8 K& M
services iis---XP
Intitle:welcome.to.iis.4.0 IIS4 ; z! j% ~. [6 Z( \ ~( x3 M3 V, ` 8 ]( D" d- u# B3 q
Allintrtle:”welcome to internet information server”
IIS-- generic ! g( N: P0 @' [9 Y4 m& e6 u1 Q* s
Intitle:”apache http server”
Intitle:”documentation” 2 N/ U' f# d% j0 G4 P" `
Intitle:””error using hypernews””server software”
“HTTP_USER_AGENT=Googlebot”
“HTTP_USER_AGENT=Googlebot”TNS_ADMIN : _! N5 X- W! u' r$ A
Inurl:/admin/login.asp ; J$ K& X2 a5 R 8 v3 j: {; F p: x8 h0 W
Intitle:”remote desktop wen connection”
“welcome to *” “Your password is *” * d \, |4 U! `0 r! Y% p
Inurl(browse top_rated power_search hot create_admin_user)+”powered , Z+ [- Z* w# y! A0 _/ b8 J
by inde xu” ! U, [) z! z, `; y5 d3 J7 M4 B6 ` % V' f/ n- {, I- K) C
“adding new user” inurl:addnewuser C“there are no 0 {$ z$ I+ C; U, O
domain” 3 H* Z; r* f8 o& b : y! Q z/ D! U( I* t0 P" @( y Z
Filetype:log inurl:”password.log” % \8 \) x+ y' J2 x$ T3 c 7 z o% T- a5 O3 J1 ~$ e# P
Intitle:”PHP Shell *” “enable stderr” filetype:php 5 a+ c2 f0 [$ B/ M2 m" \: `0 B - v) ^$ {6 ^# d+ ~1 E
Intitle:confixx login password ( M: \, m% A9 f% Y7 z t$ N- Y1 {. E( D
“powered by rover” 2 S8 b8 T. v4 z5 f8 x1 ~: j ' V1 ?! V; m5 E* N
Inurl:iisadmpwd 7 B! d5 f& O9 U: h7 m
Inurl:5800 / M9 i" _, M& z3 i x) g; V6 w. V9 {
“VNC desktop” inurl:5800
Inurl:webmin inurl:10000 5 r1 @( v3 k' v( K2 }: e
Inurl:8080 Cintext:8080 ; z0 i% i o7 g+ J$ ^' m: s
“access denird for user” “using password” 2 r& g" ~/ O5 p3 N- L! Z- {- a% y4 q
“# Dumping data for table” - y) M8 [3 T: d' A
“# Dumping data for table” username password ! x( Y1 ?' v* _0 M1 f5 g5 q/ J- ~
“# Dumping data for table ) O. k& }. x% O3 O7 `3 a
(username user users password)” 0 g5 K! O, B) u3 F' s
Inurl:main.php welcome to phpmyadmin
Intitle:”phpmyadmin running on *” welcome to phpmyadmin 0 }6 _6 j- {/ f) z
Filetype:inc intext:mysql connect
Filetype:sql + “INENTIFIED BY” Ccvs 2 \ m4 }, [7 E( e N, X
Filetype:sql + “INENTIFIED BY” (“grant * on *” “create 0 W7 l3 O4 F0 p+ u9 r0 V
user”) 5 `3 k/ }4 z9 y4 V
“this report lists” “identified by internet scaner”
ACID “by roman danyliw” Filetype
HP
小提示:用google hacking工具搜索这些,真的是多快好省啊:)
great!!
看不懂。。。。。。。。
!!!!!!!!!!!!!!
| 欢迎光临 数学建模社区-数学中国 (http://www.madio.net/) | Powered by Discuz! X2.5 |