|
http://www.cnsu.org-->site
' j* C8 e1 D( U& N. O% B4 Y5 n e6 e1 b, L' C
www.cnsu.org-->inurl 6 y) m) r% O4 j+ |$ e0 ~+ @
; @- j k* _& n8 M% Y3 l
adminàinurl
9 O1 i6 i3 m3 n4 Z1 ^ M1 u( d( P1 q' H" S
。asp D D》filetype : t* F- y W8 w# H( `7 N
" }6 Y3 _+ @9 v! C ?
标题 D D》intitle _/ z& b; t. E
) l- ~$ G Q: b4 c& q9 F( W, s1 M
页面文字 D D》intext
, X5 @6 j( ]# c7 {( f8 K5 z3 ^
. C" L# W" v' {0 \# l( ~1 r 页面编号 D D》numeange
, o, [6 P! S% I" O/ @" b# P7 Q l' D5 q3 s9 Z
- 逻辑非,“A-B”表示包含A没有B的网页 6 E' A% K( P, `3 {. e2 b5 l. ]
2 U# [; a' L6 b* U' Y. @ k
*代表单个字符
3 { u1 z# {- T3 z( `$ F2 ?' a, L; r6 D$ }0 `4 G4 @8 b2 T
or操作
0 j" {/ y# L+ s* o7 U0 I% s6 m
7 T$ J! }# k3 h “”用短语做关键字,必须加上引号,不然会被当作与操作
+ x: _6 j/ c6 B" ~! u* ~7 R0 ]& D9 z, W, |8 x: _" V
。空格 7 `8 E w. s! [$ G1 X. C, u) w
6 ~+ c7 B$ F% J9 o
Google对一些网路上出现频率极高的英文单词,如“i”、“com”、“www”等,以及一些符号如“*”、“。”等,作忽略处理 , b- \% \$ @+ v3 g/ G$ L
2 D: M- j9 A# Y; y
可以用+强制搜索
9 |8 v* }. {. A# l& A2 C9 [: J
( t2 X: o+ W/ T5 c( k 下面的语句是我搜集来的,大家可以试着用下 / c2 s4 o* ]; O% G( j; N- w% K
! Q: F! G; q6 M( t7 t1 c
比如用Intitle:welcome.to.iis.4.0 IIS4会找到好多winNT的主机,呵呵 5 [! q, t& \3 ?) h9 }
) n4 ]; D) a$ {8 i$ I) W+ k6 ]& o
Site:sohu.com
( F- u) P6 r; W+ |% T q Z
, p2 p" a! R9 P/ Z2 d Site:sohu.com-site:www.sohu.com
+ U" j/ Q6 q8 I! ~% `# U3 M* n- r/ i7 V( Q/ c
Intitle:index.of/admin
: `7 W; `7 }0 ^& |# V; l$ ~0 w; K0 o& O6 L" j3 `$ `! e+ l& d
Intitle:index.of apache server.at - U+ D% ~5 w% J5 n8 u* t' z
, t9 q1 d! V2 X Intitle:test.page.for.apache “it workd” " e: Z W% z. C7 `5 q
, G- E! {0 E( a( g; X* r
Allintitle:Netscape Fasr Track Server Home Page : q3 }# a$ R! V3 m
1 i5 B3 w, V# A$ u Intitle:”welcome to windows 2000 internet services”
9 j$ B- e3 l% r3 h3 t4 h6 ?
2 E6 D6 w! b4 q IIS—win2000 % M2 l3 V4 ~( ~# M0 Y/ y
5 M1 u( L- ~- n H
Allintitle:welcome to windows XP server internet % k6 L: v) W5 J2 E2 M, U& s. d# P9 V
% Q( ^' Y" h0 |: m/ N" k8 ]7 N1 N
services iis---XP + Y8 `. H( ]4 s6 B
- t4 D! E5 j3 f) D+ q4 K Intitle:welcome.to.iis.4.0 IIS4
9 ]" P+ N8 |! A% j+ q# e2 S
, z" i0 c' W- C; ~, E( F& F Allintrtle:”welcome to internet information server”
* j. |: S0 H4 V+ V$ Q2 _4 G7 Y* k7 v+ `
IIS-- generic
- F7 ~* b% t8 P* a* i: h* M1 M: p1 s+ [5 s4 g
Intitle:”apache http server”
7 N+ j5 ^( U! t' T6 c! u7 n/ o1 D4 }; \/ b9 ~" i
Intitle:”documentation”
- u2 G+ a2 N5 F M# `+ G
; I4 a0 S) J6 X: h# @" G* N. d# w: X Intitle:””error using hypernews””server software” * D& Y8 {6 Y Z: j0 O6 q( o
, o, G! z$ D0 h1 Y, r* e “HTTP_USER_AGENT=Googlebot”
3 s w- \/ r. n$ W- ?2 B d
; X( l e7 k2 I3 O" b, i1 w5 d3 ` “HTTP_USER_AGENT=Googlebot”TNS_ADMIN
( b" I" x. s N- d0 H& M. A5 v! Y
. N1 U( v( _3 T5 U# e Inurl:/admin/login.asp
; V3 [+ {& i4 D
' ]2 f& f0 y, C. {! d: I3 i Intitle:”remote desktop wen connection”
* c3 e* t* L% P! }0 i2 m, |* i
0 ^% d- \* B9 [/ ^6 G4 g “welcome to *” “Your password is *” ; ~" o- Z) ?9 x4 B, j" R, F& k n0 X
. b9 S' R8 `$ A$ g. d. }
Inurl(browse top_rated power_search hot create_admin_user)+”powered 4 q( f9 [- ]( q) T0 Z" ]/ J
- N0 r# S1 D8 P by inde xu” , l+ B# v) p2 G2 P
- a& ~8 b$ L' r' s% M
“adding new user” inurl:addnewuser C“there are no
2 D+ }. X) g ?7 O1 `. a/ X0 V' f
. B* X+ ~' g u/ [* f6 C& y domain”
! W7 c3 K1 H3 c* @# o; I9 w. i$ u
- k1 L+ x1 ]# \; G0 o- E' ]; y Filetype:log inurl:”password.log”
, G4 b5 Q9 H! U3 t& a( ?& ?
5 K' ?1 c6 L# c3 X5 k; s Intitle:”PHP Shell *” “enable stderr” filetype:php , W$ W, o+ E* h
8 E: b5 w3 `5 x8 Z) R2 u9 N Intitle:confixx login password 9 i* `; o" O1 g! L7 N0 D
+ ?/ z" |3 J/ g. e8 E# N! }
“powered by rover” . p! q+ S3 t9 E/ Z( l& o& S1 E
/ t1 [4 p; S. {' o
Inurl:iisadmpwd
. m. V. A. [4 C& U$ e. g$ P1 e8 D7 p: b6 g! C
Inurl:5800 - n3 V7 ?$ {1 p" K
; q; i( n: z4 d r8 `0 p “VNC desktop” inurl:5800
# n0 S7 }( R/ s6 B5 \% T1 K
/ r. E( [. @$ _4 h2 { Inurl:webmin inurl:10000
3 q( L/ j' Y5 m0 ], N+ U$ }; z. M+ f, ^. w
Inurl:8080 Cintext:8080
: D P+ g# |( @& y
& a6 g; h9 V( j3 h! C1 |& r( t3 F “access denird for user” “using password” : H& I& F! a% _, `+ s0 h: H
P; @/ g) f$ J% l: f3 _( {' c& D2 B) H “# Dumping data for table” 5 Q/ o5 ]0 ^ a, ?/ b9 z$ a
U- x" x! I# Z1 o1 R
“# Dumping data for table” username password
5 ]6 E+ q9 ?9 Y% u/ I3 y3 @1 A5 F6 Q1 t0 k
“# Dumping data for table . H5 F9 n2 }! f, t, N
* }9 p% e' W# N7 F) y
(username user users password)” . `7 t/ w. h1 c8 `" z2 {4 r+ w
6 l7 k/ E# i+ A6 f% X/ l$ N Inurl:main.php welcome to phpmyadmin
, w/ f' s2 D3 `
/ K" u3 f- K& X5 k# v Intitle:”phpmyadmin running on *” welcome to phpmyadmin
1 |! `; c4 `" H$ Y+ h! ~1 X2 n7 J% [4 w$ p( C/ {" t
Filetype:inc intext:mysql connect
, Q& L* r2 A w; c$ f8 h% D* [* K# T! F" p3 O, `+ G& m0 [, D
Filetype:sql + “INENTIFIED BY” Ccvs 4 u* P9 U4 \9 h) \$ G1 B
# N, H- b2 c$ A7 {
Filetype:sql + “INENTIFIED BY” (“grant * on *” “create
' K& g4 O! x. U7 ^$ K) m, m* o" I ]* U/ _# ]
user”)
7 B9 u2 C9 y8 N/ @0 D
* O/ M2 R5 l5 e' d* w% y' M “this report lists” “identified by internet scaner” 0 U' }8 W; T5 e' V/ N
4 }* f/ k- ~! P: ^; d9 z ACID “by roman danyliw” Filetype HP ! d; v* R8 h( Q) |& {) A4 q
/ `$ {7 v4 x9 k4 M, Y
小提示:用google hacking工具搜索这些,真的是多快好省啊:) 6 @+ ^: f3 v( d; Y6 n
|