Thursday, 4 February 2016

Google hacking

Google searches can be more than a treasure for a pentester, if he uses them effectively. With Google searches, an attacker may be able to gather some very interesting information, including passwords, on the target. Google has developed a few search parameters in order to improve targeted search. However, they are abused by hackers to search for sensitive information via Google.

SOME BASIC PARAMETERS

Site
The site parameter is used to search for all the web pages that are indexed by Google. Webmasters have the option of specifying what pages should or should not be indexed by Google, and this information is saved in the robots.txt file, which an attacker can easily view. Example:-
http://www.techlotips.com/robots.txt
G1.png
As you can see from this screenshot the Webmaster has disallowed some directories from being indexed. Sometimes, you may find some interesting information in them such as admin pages and other sensitive directories that the webmaster would not like the search engines to crawl. Coming back to the site parameter, let’s take a look at its usage.
Usage
Site: http://www.techlotips.com
This query will return all the web pages indexed by Google.
Link:
Link: http://www.techlotips.com
This search query will return all the websites that have linked to techlotips.com. These websites may contain some interesting information regarding the target.
Intitle:
Intitle keyword is used to return some results with a specific title.
Usage
Site: http://www.techlotips.com Intitle:ftp users
This query will return all the pages from techlotips that contain the title “ftp users”
Note: This usage query is just for demonstration as it may not work in most cases.
Inurl:
Inurl is a very useful search query. It can be used to return URLs with specific keywords.
Site: http://www.techlotips.com inurl:ceo names
This query will return all URLs with the given keyword.
Filetype:
Site: http://www.msn.com filetype:pdf
G2.png
You can also ask Google to return specific files such as PDF and .docx by using the filetype
query.
G3.png

18 comments:

  1. I have read your blog it is very helpful for me. I want to say thanks to you. I have bookmark your site for future updates. http://singaporesecurityservice.simplesite.com/

    ReplyDelete
  2. It was a very good post indeed. I thoroughly enjoyed reading it in my lunch time. Will surely come and visit this blog more often. Thanks for sharing. Prince Security Company

    ReplyDelete
  3. I wanted to thank you for this excellent read!! I definitely loved every little bit of it. I have you bookmarked your site to check out the new stuff you post. security service in cambodia

    ReplyDelete
  4. Nice to be visiting your blog again, it has been months for me. Well this article that i've been waited for so long. I need this article to complete my assignment in the college, and it has same topic with your article. Thanks, great share. best Security Company

    ReplyDelete
  5. Thanks for the blog filled with so many information. Stopping by your blog helped me to get what I was looking for. Now my task has become as easy as ABC. Reliable Security Service in Cambodia

    ReplyDelete
  6. I really loved reading your blog. It was very well authored and easy to undertand. Unlike additional blogs I have read which are really not tht good. I also found your posts very interesting. In fact after reading, I had to go show it to my friend and he ejoyed it as well! https://www.evernote.com/shard/s341/sh/2fb066d1-01d0-cf8e-da1c-5a7515666234/12027d13af5e2514b9c99ae6dcda16e8

    ReplyDelete
  7. I was looking at some of your posts on this website and I conceive this web site is really instructive! Keep putting up.. security company in cambodia

    ReplyDelete
  8. I have read all the comments and suggestions posted by the visitors for this article are very fine,We will wait for your next article so only.Thanks! https://bestsecuritycompany.jimdosite.com/

    ReplyDelete
  9. The post is written in very a good manner and it contains many useful information for me. https://security45s-website.yolasite.com

    ReplyDelete
  10. I wanted to thank you for this great read!! I definitely enjoying every little bit of it I have you bookmarked to check out new stuff you post. best security company in cambodia

    ReplyDelete
  11. This is my first time i visit here. I found so many interesting stuff in your blog especially its discussion. From the tons of comments on your articles, I guess I am not the only one having all the enjoyment here keep up the good work https://security-service-company-in-cambodia.mystrikingly.com/

    ReplyDelete
  12. You make so many great points here that I read your article a couple of times. Your views are in accordance with my own for the most part. This is great content for your readers. security company in phnom penh

    ReplyDelete
  13. This comment has been removed by the author.

    ReplyDelete
  14. Took me time to read all the comments, but I really enjoyed the article. It proved to be Very helpful to me and I am sure to all the commenters here! It’s always nice when you can not only be informed, but also entertained! khmer security company

    ReplyDelete
  15. Nice to be visiting your blog again, it has been months for me. Well this article that i've been waited for so long. I need this article to complete my assignment in the college, and it has same topic with your article. Thanks, great share. security guard

    ReplyDelete
  16. Thank you because you have been willing to share information with us. we will always appreciate all you have done here because I know you are very concerned with our. security guard sihanoukville

    ReplyDelete