|
http://www.cnsu.org-->site |# q E2 Y9 m% D: ]+ p
# Z% D$ A8 \. ?" @ www.cnsu.org-->inurl : @: \9 u) }3 S6 Y
$ G$ ?) e f$ f l adminàinurl 6 D, L0 w! n V- ~6 H# @
' ?' e* I0 F9 V9 D9 Q 。asp D D》filetype
0 w6 L1 G6 g' u O- V: C9 C( D7 a' `+ }0 e+ @. t! o6 J# D; O
标题 D D》intitle
$ W0 b% ^4 P/ g
2 H, O$ v% k0 I& U- H. d 页面文字 D D》intext
" O8 {: ?, O; ?
/ M% K8 [7 c; i; w: v' a3 t 页面编号 D D》numeange
' V$ ?& N* M* ^$ Q+ Y* f
4 v. F$ ?) |) y3 S - 逻辑非,“A-B”表示包含A没有B的网页
( g# u+ a$ H# J& E! N
( V7 K" N/ r K T; b/ B7 ^ *代表单个字符 / E' O: @$ A& R
" s- ~1 ~, \* O+ a9 ~ or操作 . c% t5 @' o3 T
7 y3 B0 e& T; u" \' X3 g
“”用短语做关键字,必须加上引号,不然会被当作与操作 , B2 h* u, R: R8 a( [0 O
- h1 [6 q0 n! c8 q f! \ 。空格 " W6 j/ U* t+ U' \ z- m; G ~
( K6 ~5 h; O9 B3 H- G, G0 | Google对一些网路上出现频率极高的英文单词,如“i”、“com”、“www”等,以及一些符号如“*”、“。”等,作忽略处理 ' ~- C7 f5 X( D
8 Z, K* B5 W0 N7 q% s. ]
可以用+强制搜索
- s, O! c/ Y: ]+ V4 _# a0 b( `4 v/ J- _: M3 H0 A f
下面的语句是我搜集来的,大家可以试着用下
6 j! m& r9 ]/ s( E# y$ L2 h
I3 `$ v$ \+ l4 N 比如用Intitle:welcome.to.iis.4.0 IIS4会找到好多winNT的主机,呵呵
/ m3 Z8 `/ Y+ A2 v7 k$ ]4 \6 v! y2 ^( X4 A/ n9 {% @
Site:sohu.com 5 q J) P) p& ~2 t, K% D
3 U) ?5 U8 o6 {/ i/ s Site:sohu.com-site:www.sohu.com 1 m8 S# w% e- k7 v0 ^
/ t/ m- P3 d0 A1 h Intitle:index.of/admin 8 I) |0 c3 m5 C2 M
% W; ?8 o- M+ L( ^( ^! o: Z Intitle:index.of apache server.at
) c+ S0 i1 s" O2 o! ?( j% I3 U/ ~3 O* E1 K" f L% s
Intitle:test.page.for.apache “it workd”
# f+ i% d4 b$ F& z' n" n9 o% a7 X
Allintitle:Netscape Fasr Track Server Home Page + r, L+ Q" U9 Z+ s$ m b3 |5 @6 s
. D1 k3 w8 n( S5 V8 Y Intitle:”welcome to windows 2000 internet services” . F6 M7 c% P' \: w$ [
% S" a9 O3 ~% Q( A. A( a, P0 J
IIS—win2000
: O9 e9 F# V q* Q r, c1 J+ q- [5 S% J
Allintitle:welcome to windows XP server internet
! Z6 ]7 g! L4 x6 T. E2 p4 C0 V: D
9 w& c7 w7 {# s services iis---XP 7 Z% T$ w0 L0 j( {' d7 h- G0 Z
* r6 ]) T1 R) g- c' r$ T( p Intitle:welcome.to.iis.4.0 IIS4 " [, W3 r& r1 {. p
- M. a, d9 o/ w+ j1 s$ {/ u+ W Allintrtle:”welcome to internet information server”
$ B& I0 o6 `6 @6 j% I: t( A- F. V7 e% O9 X T
IIS-- generic
% }# k6 _8 U& ? Q8 {
9 h5 e! m& D ]- S' s+ s% i4 b2 y Intitle:”apache http server”
0 s# u& w) P2 Y
+ a4 J. V8 t5 T4 ]5 T Intitle:”documentation” : H: s, u* _+ T( [& ?6 t
( X& f& C; P4 U. F7 O; m7 B Intitle:””error using hypernews””server software”
* K# d' o& L' x: b( e6 f, ?; A9 D, ?6 ~* l3 i; f" L
“HTTP_USER_AGENT=Googlebot”
! Y2 q, i8 b7 R8 v+ k2 I& v3 M* v: {7 \, A; u. R+ W* t* \9 i
“HTTP_USER_AGENT=Googlebot”TNS_ADMIN 6 m. t5 [; x0 s/ S0 l
4 E f1 Y: I1 N8 ] Inurl:/admin/login.asp
5 E' x$ n% o( V1 i' C5 K4 f; Q1 P
4 M( L/ r+ f, Q' m! ? Intitle:”remote desktop wen connection”
! W& n5 x" x- Y6 O3 S* x* o3 m, p- o% o8 v( ?9 o0 t
“welcome to *” “Your password is *”
8 C, |; `2 T _, M
0 K* ^7 l4 t; c0 u" E$ d7 ` Inurl(browse top_rated power_search hot create_admin_user)+”powered
3 ?% Z0 Z/ T- b ?
6 q0 W' h" y1 [) E1 R) y1 I by inde xu” ) c( K0 G. C& y
; d1 X1 t& G m: m" F0 g( { “adding new user” inurl:addnewuser C“there are no 2 U# }, p% K1 ^" S# z2 \4 r
+ g G& d S* d |8 I( y$ c domain” }! [* M5 [+ C; }7 N( e
1 W5 W! T4 s5 k0 i% X$ f
Filetype:log inurl:”password.log” $ F0 r- g9 ?3 t- p, g) P
I1 ?) k' l! ~: \: c, f Intitle:”PHP Shell *” “enable stderr” filetype:php
! m( X( c, ]; ?9 ^! W% F
{+ o! ^5 n' P, L Intitle:confixx login password
0 [( W7 T! h' j, A- U; f0 n) G; m: t& Q7 ]8 Y4 }
“powered by rover” [) U: b5 z2 n& S6 \# q9 C
2 w9 b) ~2 g" q+ D
Inurl:iisadmpwd ( p- M8 B$ j; I* S% E) q
0 g: E q9 s' q5 f- c8 U Inurl:5800 9 K" E# i$ Z5 }2 i) {
" ?( ~. r9 o7 x# c' \: h* {1 M( ]* N7 r
“VNC desktop” inurl:5800 * k* d& e2 o8 P& u; [
8 P g* X: s, C9 P1 h" u. H; o0 C
Inurl:webmin inurl:10000
/ ?* Q, C. Q3 i( b+ a$ G1 J( P( t7 a& r+ @+ R0 b0 j
Inurl:8080 Cintext:8080
/ F4 K5 o1 ^( i1 ^0 G- S4 t
9 M# m# i7 r" T9 k7 C$ a3 _ “access denird for user” “using password” , Z9 z3 u8 m, x
- i$ R: X X0 K
“# Dumping data for table” , z6 W3 r. t2 M: n/ N* C* O
- n6 t% H3 n2 l; \' i/ @4 ]2 c( ~
“# Dumping data for table” username password
1 h( v" R! V" F& e. i4 V( f
" P7 o: U; h: @6 H “# Dumping data for table " O3 \/ K8 t4 ]! D2 Z( o, g* ^
" \4 ^: T1 H& j+ ^1 f5 Q (username user users password)”
$ G" y2 W0 a6 M6 H. `0 J, @6 s+ W/ \; Z+ y9 \$ p; u! C8 F' I$ b
Inurl:main.php welcome to phpmyadmin ! h% W6 B4 { n! }1 s; i! ]
8 k Y' F+ N' g& l8 C* C$ ] Intitle:”phpmyadmin running on *” welcome to phpmyadmin $ R( r. o: Y8 b! c! B7 L2 _
0 v& j; U& J/ u+ k$ C
Filetype:inc intext:mysql connect
4 E8 G, ]! ]6 n3 }, G/ J) ^1 r* Q* W* t: `- o
Filetype:sql + “INENTIFIED BY” Ccvs
6 M) ?+ b/ S$ s' u2 E5 g' A# o# n; d" V
Filetype:sql + “INENTIFIED BY” (“grant * on *” “create
* x9 `6 i0 w2 E8 B1 j3 R% _' n z; y. h' Z2 e- j5 f3 r7 r
user”)
3 U1 K( }1 ^* s' Z( f4 d5 o7 a3 O+ E% o; b2 k0 G+ ~
“this report lists” “identified by internet scaner” - _& B4 q. d0 C# {' ?5 a
( o6 B, V6 `& _: F5 w$ x
ACID “by roman danyliw” Filetype HP
$ p0 N {: _7 X% M. b+ z" s' b. s5 r3 L* \# }: i
小提示:用google hacking工具搜索这些,真的是多快好省啊:)
' T; E2 I- F0 y: ~; m |