Você está na página 1de 101

Google Hacking Fórmula Hacking

________________________________________________

Google
Hacking

Desenvolvido por: Ruan Federle FormulaHacking.com 1


Google Hacking Fórmula Hacking
________________________________________________

1. Uma breve Introdução…

→ Não se preocupe! Você logo vai poder colocar a mão na massa :)

“Não existe segurança na rede!” - Kevin Mitnick

Toda empresa, por menor que seja, deseja colocar a sua marca na web através da criação de
um website. Tendo em vista esta tendência, o número de novos websites registrados a cada dia é
enorme. Estes, por sua vez, são indexados pela famosa Google (aquele buscador com uma interface
inconfundível e protegida por direitos autorais). Com um desing minimalista, a interface do google
é limpa e simples fazendo com que passe despercido o poder escondido por trás desta ferramenta de
busca.
O Google, em 1996, possuía 25 milhões de páginas indexadas contra 40 bilhões em 2010.
Colocando essa informação em perspectiva, para exibir todos os sites indexados pelo Google em
2010, teríamos que usar um monitor com 9.660,000 quilômetros de ponta a ponta ou 241 vezes o
comprimento da linha do Equador. Se alguém dedicar um minuto a cada página existente no Google
em 2010, esta pessoa levaria 38.026 anos para ver todas. O Google, por sua vez, leva 0,5 segundos
no máximo.
Os números do Google realmente impressionam, mas o ponto chave é a maneira qual a
ferramenta pode ser usada para explorar vulnerabilidades.

No Google, a pesquisa não se baseia na procura de informações sensíveis, como usuários e


senhas, mas sim em focar no que se procura, visando usar essas informações para seus próprios
objetivos. Encontrar esse tipo de dados é parte da rotina básica de um hacker. Com tantas páginas
indexadas diariamente, hackers e crackers tiram proveito dessas informações para os mais diversos
fins.
Existem inúmeras maneiras de se conseguir dados, como nome de usuário e senha por
exemplo, utilizando o Google. Um excelente exemplo é o registro do Windows, responsável por
armazenar todo tipo de informações para autenticação, desde nome de usuário até chaves de
registros de programas. Entretanto, é raro e muito incomum encontrar esse tipo de informação, visto
que é necessário exportar esse registro e disponibiliza-lo na web. No momento que esse artigo foi
escrito existiam cerca de 228 resultados para a consulta: filetype:reg HKEY_CURRENT_USER
username, responsável por localizar arquivos de registro do Windows que contenham a palavra
username e em alguns casos a senha.
Qualquer invasor talentoso ou profissional de segurança dirá que é raro conseguir acesso a
esse tipo de informação disponibilizada tão facilmente. A maioria das descobertas consideráveis
precisam de persistência, criatividade, inteligência e um pouco de sorte. Por exemplo: considere o
portal Microsoft Outlook Web Access que pode ser localizado pela busca inurl:root. asp?
acs=anon. Infelizmente não é incomum encontrar empresas que hospedam esse serviço com algum
diretório público.

Desenvolvido por: Ruan Federle FormulaHacking.com 2


Google Hacking Fórmula Hacking
________________________________________________

Uma consulta realmente efetiva no Google é ter uma ideia firme sobre a sintaxe básica e, em
seguida, visando obter resultados melhores, é a compreensão das técnicas de construção de busca
para aprimorar o resultado final da busca.

É possível usar várias formas de pesquisa no Google para localizar senhas na Web.
Administradores de sites muitas vezes hospedam arquivos de texto (.txt) contendo os dados de
acesso à administração do site, dados dos clientes e funcionários da empresa, entre outras
informações sigilosas. Hospedando os arquivos em alguma url extensa acreditam que ninguém
jamais irá descobrir a url para ter acesso a tal conteúdo. Mal podem imaginar que os robôs do
google estão farejando milhões de websites a cada segundo à procura de um novo endereço para
indexar. Na maioria dos casos, senhas descobertas na Web são criptografadas ou codificadas de
alguma maneira, senhas estas que podem ser quebradas usando algumas ferramentas de quebra de
criptografia, permitindo que a senha seja usada em uma invasão.

Ao pesquisar por inurl:auth_user_file.txt o Google retornou na pesquisa 178 registros.


Clicando no primeiro registro foi possível ver o nome de usuário, senha, nome e o e-mail.

Já para o termo filetype:xls inurl:”email.xls” o Google retornou na pesquisa 914


resultados. Em poucos cliques é possível ter acesso a conversas de e-mail, telefone residencial,
nome completo, número de registro de empregado, ramal e etc.
Pode-se supor que você, em sua residência, toma algumas precauções de privacidade
visando não se expor na internet. Mas, por uma falha da empresa em que trabalha, suas informações
e detalhes pessoais são expostos na rede.

Já dizia Kevin Mitnick:


“ Mesmo quando o usuário classifica suas informações como restritas nas redes
sociais, o mundo pode ver. Um amigo seu pode, sem querer, fornecer
informações para um hacker do mal. ”

Nem mesmo as câmeras de segurança interna de empresas ao redor do mundo estão a salvo.
Ao pesquisar pelo termo inurl:IndexFrame.shtml “Axis Video Server” várias câmeras de
segurança são expostas.
Em alguns casos é possível ver o nome da empresa escrito no tapete da porta de entrada.
Pelo IP das câmeras é possível localizar o endereço, site e telefone da empresa.

O indexador do Google é bastante eficaz, sendo possível informar quais páginas não devem
ser indexadas pelo Google através da criação de um arquivo chamado “robots.txt”. Empresas e
websites governamentais optam por fazer esse processo para que algumas páginas sejam acessadas
pelo público. A consulta que retorna esses registros é “robots.txt” “disallow:” filetype:txt .

Desenvolvido por: Ruan Federle FormulaHacking.com 3


Google Hacking Fórmula Hacking
________________________________________________
Como se não bastasse, através do Google é possível monitorar, configurar e imprimir
documentos. A pesquisa que retorna esses registros é inurl:”port_255” –htm. Nos resultados,
podemos encontrar diversos dispositivos de universidades e empresas cujo acesso pode ser feito
utilizando o usuário e senha padrão ou, em muitos casos, sem a necessidade de credenciais.

De forma a concluir esta introdução, notamos acima que existe uma quantidade expressiva
de informações sigilosas e sensíveis que deveriam ser de acesso restrito, porém estão expostas ao
mundo através de simples consultas no Google. A exposição de informações contempla desde
usuários comuns até sites governamentais e de grandes empresas.
O alarmante é perceber que erros primários cometidos por pessoas da área de informática
comprometem toda a estrutura de segurança da informação. A facilidade de acesso à tecnologia é
louvável, mas a falta de capacitação técnica por parte de seus usuários é preocupante, uma vez que
as informações estão acessíveis a qualquer pessoa com um mínimo conhecimento em informática.
Não é necessário ser um hacker para ter acesso a essas informações, basta ser uma pessoa
com interesse e disponibilidade de tempo para pesquisar e investigar. Hoje, com o advento das redes
sociais, informações que antes eram difíceis de conseguir estão à alguns cliques , por exemplo:
quem são os familiares de determinada pessoa? Onde ela trabalha? Estuda? e etc, munindo, desta
forma, pessoas más intencionadas para um ataque de Engenharia Social.
Rotinas, que antes eram privadas, estão sendo expostas por seus próprios usuários sem levar
em considerações questões de segurança da informação e o mais perigoso, a sua própria segurança.

LONG, Johnny. 2007. Google Hacking for Penetration Testers. Google Hacking: Teste de Invasão.
Rockland, Massachusetts, EUA: Syngress.

Desenvolvido por: Ruan Federle FormulaHacking.com 4


Google Hacking Fórmula Hacking
________________________________________________

Agora Sim!
Se você me conhece já sabe que eu costumo dizer: “ O Fórmula Hacking te coloca no campo
de batalha para aprender Hacking na prática”. E eu realmente acredito no aprendizado através da
prática. Porém, a batalha, para a maior parte das pessoas, começa quando se está cara-a-cara com o
inimigo. Para alguns poucos começa quando se está afiando a espada. Para uma minoria maior
ainda, elá já começou antes mesmo de afiar a espada, ao buscar o equilíbrio mental e emocional
correto para ter sucesso em campo. E acredite, isso faz toda a diferença. E você, já afiou a sua
espada?
Sem mais delongas, nas próximas páginas você vai encontrar inúmeras técnicas que, com
dedicação e estudo, te farão dominar a arte de Google Hacking. Lembre-se: “Com grandes poderes
vem grandes responsabilidades”. Faça uso deste conhecimento com sabedoria.

Desenvolvido por: Ruan Federle FormulaHacking.com 5


Google Hacking Fórmula Hacking
________________________________________________

→Bibliografia Recomendada:
As técnicas contidas neste ebook podem ser
encontradas com maior detalhamento no livro
“Google Hacking para Testes de Invasão” de
Johny Long, traduzido e disponibilizado em
português pela editora Digerati.

Desenvolvido por: Ruan Federle FormulaHacking.com 6


Google Hacking Fórmula Hacking
________________________________________________

> Operadores Avançados

“ Antes de você começar a correr é preciso aprender a caminhar. ”


Traduzindo isso para o Google seria entender os Operadores Avançados.

Os Operadores Avançados existem para nos ajudar a refinar as buscas no


Google.
• Eles são incluídos como parte de uma consulta padrão do Google.
• Operadores Avançados utilizam a sintaxe como esta:
operador:termo_de_procura
• Não vai espaço entre o operador, os dois pontos, e o termo de busca!

Desenvolvido por: Ruan Federle FormulaHacking.com 7


Google Hacking Fórmula Hacking
________________________________________________
Operador Função Combina com Pode ser Web? Image Grupos Notícias
outro usado ns
oprador? sozinho?
intitle Procura por título Sim Sim Sim Sim Sim Sim
de página
allintile Procura por título Não Sim Sim Sim Sim Sim
de página
inurl Procura por url Sim Sim Sim Sim Não Sim
mesmo
allinurl Procura por url Não Sim Sim Sim Sim Sim
filetype Procura arquivos Sim Não Sim Sim Não Não mesmo
específicos
allintext Procura somente Não mesmo Sim Sim Sim Sim Sim
por texto dentro de
páginas
site Procura em um Sim Sim Sim Sim Não Não mesmo
site específico
link Procura por links Não Sim Sim Não Não Não mesmo
para páginas
inanchor Procura por Sim Sim Sim Sim Não Sim
âncoras mesmo
numrange Localiza números Sim Sim Sim Não Não Não mesmo
com um alcance
específico
daterange Localiza uma data Sim Não Sim Não Não Não mesmo
específica mesmo mesmo
author Procura pelo autor Sim Sim Não Não Sim Não mesmo
de um grupo
group Procura pelo nome Não mesmo Sim Não Não Sim Não mesmo
de um grupo
insubject Procura pelo Sim Sim Sim Sim SIm Não mesmo
assunto de um
grupo
• Note que em alguns casos os Operadores Avançados podem ser
combinados. Com o Operador “inurl”, por exemplo.
• Em outros casos, como no operador “link” por exemplo, combinar deve
ser evitado.

Desenvolvido por: Ruan Federle FormulaHacking.com 8


Google Hacking Fórmula Hacking
________________________________________________

> Operadores Conflitantes

• Alguns Operadores buscam por áreas conflitantes. Considere os


Operadores seguintes operadores:

→ site: O operador “site” não procura por portas;


→ inurl: O operador “inurl”, por sua vez, pesquisa o conteúdo de uma
URL inteira, tanto a porta quanto o formato (filetype);
→ filetype: O operador “filetype” procura apenas por extensões de
arquivos, oque pode ser difícil de distinguir em URL’s extensas.

Desenvolvido por: Ruan Federle FormulaHacking.com 9


Google Hacking Fórmula Hacking
________________________________________________

> Busca Avançada

• Existem muitas maneiras de encontrar uma mesma página. Estes


operadores podem ajudar:

→ site: O operador “site” nãoo procura por portas;


→ inurl: O operador “inurl”, por sua vez, pesquisa o conteúdo de uma
URL inteira, tanto a porta quanto o formato (filetype);
→ filetype: O operador “filetype” procura apenas por extensões de
arquivos, oque pode ser difícil de distinguir em URL’s extensas.

Desenvolvido por: Ruan Federle FormulaHacking.com 10


Google Hacking Fórmula Hacking
________________________________________________

> Busca Avançada

• Juntando os Operadores e formando um montruoso código de pesquisa


você obtém um resultado específico.
• Ao adicionar Operadores Avançados, você reduz o número de resultados
dando foco à busca.

Desenvolvido por: Ruan Federle FormulaHacking.com 11


Google Hacking Fórmula Hacking
________________________________________________

> O Básico de Google Hacking

• Colocar Operadores para buscarem juntos de forma inteligente pode


parecer inofensivo a princípio...

… porém, os resultados podem se mostrar devastadores.

• Veja, no exemplo acima, o arquivo encontrado contendo nomes de


clientes, valor total das compras e, ainda, detalhes do pagamento.

Desenvolvido por: Ruan Federle FormulaHacking.com 12


Google Hacking Fórmula Hacking
________________________________________________

O Básico de Google Hacking

Agora vamos dar uma olhada em algumas técnicas básicas:


• Como utilizar o Google Hacking de forma anônima;
• Conhecendo os caracteres especiais.

Desenvolvido por: Ruan Federle FormulaHacking.com 13


Google Hacking Fórmula Hacking
________________________________________________

> Google Hacking Anônimo

Os links em cachê do google são uma ótima maneira de continuar


exibindo os conteúdos após as páginas terem sido deletadas. A questão é,
de onde este conteúdo está vindo realmente?

• Algumas pessoas usam a ferramenta cache do google para ficarem


anônimas, acreditando que o conteúdo acessado está vindo do Google;
• Vamos observar mais de perto …

Desenvolvido por: Ruan Federle FormulaHacking.com 14


Google Hacking Fórmula Hacking
________________________________________________

> Google Hacking Anônimo

Para o exemplo a seguir, fizemos uso do famoso sniffer tcpdump


que nos mostrou o tráfego de nossa rede enquanto carregava um link em
cache. Veja o que ele retornou:

• 64.233.167.104:80 – Endereço do Google


• 82.165.25.125:80 – Website original
Ou seja, nos conectamos ao servidor do website. Desta forma não estamos
anônimos.

Desenvolvido por: Ruan Federle FormulaHacking.com 15


Google Hacking Fórmula Hacking
________________________________________________

> Google Hacking Anônimo

Aqui, com um maior detalhamento no tcpdump podemos notar que


foi carregada uma imagem que vinha do website original:

Desenvolvido por: Ruan Federle FormulaHacking.com 16


Google Hacking Fórmula Hacking
________________________________________________

Fazendo uso de uma pequena técnica, podemos bloquear o download


de imagens. Carregando o cache apenas em texto, teremos certeza que a
nossa conexão está acontecendo somente com o Google. Basta que, ao
final do link cache, você adicione &strip=1. Veja o exemplo:
• Link Cache Normal: http://64.233.187.104/search?
q=cache:Z7FntxDMrMIJ:www.phrack.org/hardcover62/+phrack+h
ardcover62&hl=en
• Link Cache em Texto e Anônimo: http://64.233.187.104/search?
q=cache:Z7FntxDMrMIJ:www.phrack.org/hardcover62/+phrack+h
ardcover62&hl=en&strip=1
Observe a mudança na exibição de um exemplo para outro:

Desenvolvido por: Ruan Federle FormulaHacking.com 17


Google Hacking Fórmula Hacking
________________________________________________

> Caracteres Especiais


• Vamos usar alguns caracteres especiais no nosso exemplo;
• Estes caracteres tem um significado especial para o Google;
• Nunca use espaço em volta deles.

•( + ) força a inclusão de algo comum


• ( - ) exclui um termo da busca
• ( “ ) utiliza citações ao redor das frases buscadas
• ( . ) um único caractere
• ( * ) qualquer palavra
• ( | ) operador ‘OR’
• Utilizando parênteses: (“master card” | mastercard).

Desenvolvido por: Ruan Federle FormulaHacking.com 18


Google Hacking Fórmula Hacking
________________________________________________

> Lista de Dorks


Exitem inúmeros dorks, disponibilizarei alguns exemplo e em seguida uma lista um
pouco extensa. Para um melhor aproveitamento, tente usar o google para encontrar
dorks que se encaixam no seu objetivo.

• Exemplos de busca:
Exemplo de busca por endereços de e-mail em arquivos de texto
intitle:email filetype:txt
Acesso remoto a impressoras
intitle:"Web image Monitor" & inurl:"/mainframe.cgi"
Busca por arquivos de base de dados em sites do governo:

site:gov.br ext:SQL

Busca por um servidor específico

inurl:"powered by" site:sistema.com.br

A pesquisa busca arquivos de e-mail em formato .mdb

inurl:e-mail filetype:mdb

Essa pesquisa busca telefones disponíveis em intranet encontradas pelo


Google

Desenvolvido por: Ruan Federle FormulaHacking.com 19


Google Hacking Fórmula Hacking
________________________________________________

inurl:intranet + intext:"telefone"

Realizando uma pesquisa dessa maneira é possível identificar muitos dos


subdomínios da Oracle

site:oracle.com -site:www.oracle.com

Detectando sistemas que usando a porta 8080

inurl:8080 -intext:8080

Encontrando VNC

intitle:VNC inurl:5800 intitle:VNC

Encontrando VNC

intitle:"VNC Viewer for Java"

Encontrando Webcam ativa

"Active Webcam Page" inurl:8080

Encontrando Webcam da toshiba:

intitle:"toshiba network camera - User Login"

Encontrando Apache 1.3.20:

"Apache/1.3.20 server at" intitle:index.of

Asterisk VOIP Flash Interface

intitle:"Flash Operator Panel" -ext:php -wiki -cms -inurl:as

Possíveis falhas em aplicações web:

allinurl:".php?site="
allinurl:".php?do="
allinurl:".php?content="
allinurl:".php?meio="
allinurl:".php?produto="

Desenvolvido por: Ruan Federle FormulaHacking.com 20


Google Hacking Fórmula Hacking
________________________________________________
allinurl:".php?cat="

> Câmeras
inurl:"viewerframe?mode=motion"
inurl:view/view.shtml
•inurl:/view.shtml

•intitle:”Live View / - AXIS” | inurl:view/view.shtml^

•inurl:ViewerFrame?Mode=

•inurl:ViewerFrame?Mode=Refresh

•inurl:axis-cgi/jpg

•inurl:axis-cgi/mjpg (motion-JPEG)

•inurl:view/indexFrame.shtml

•inurl:view/index.shtml

•intitle:start inurl:cgistart

•intitle:”live view” intitle:axis

•intitle:snc-z20 inurl:home/

•intitle:liveapplet

•intitle:”i-Catcher Console - Web Monitor”

•intitle:axis intitle:”video server”

•intitle:liveapplet inurl:LvAppl

•intitle:”EvoCam” inurl:”webcam.html”

•intitle:”Live NetSnap Cam-Server feed”

•intitle:”Live View / - AXIS”

Desenvolvido por: Ruan Federle FormulaHacking.com 21


Google Hacking Fórmula Hacking
________________________________________________
•intitle:”Live View / - AXIS 206W”

•intitle:”Live View / - AXIS 210″

•inurl:indexFrame.shtml Axis

•intitle:”Live View / - AXIS 206M”

•inurl:”MultiCameraFrame?Mode=Motion”

•allintitle:”Network Camera NetworkCamera”

•intitle:”WJ-NT104 Main Page”

•intext:”MOBOTIX M1″ intext:”Open Menu”

•intext:”MOBOTIX M10″ intext:”Open Menu”

•intext:”MOBOTIX D10″ intext:”Open Menu”

•intitle:”netcam live image”

•intitle:snc-cs3 inurl:home/

•intitle:snc-rz30 inurl:home/

•intitle:”sony network camera snc-p1″

•intitle:”sony network camera snc-m1″

•site:.viewnetcam.com -www.viewnetcam.com

•intitle:”Toshiba Network Camera” user login

•+ View Webcam User Accessing

•allinurl:control/multiview

•intitle:”supervisioncam protocol”

Desenvolvido por: Ruan Federle FormulaHacking.com 22


Google Hacking Fórmula Hacking
________________________________________________

> Encontrando dados Sensíveis


•filetype:bak inurl:"htaccess|passwd|shadow|htusers"
•filetype:cfg "mrtg"target
•filetype:cfm "cfapplication name" password
•filetype:conf oekakibbs
•filetype:conf slapd.conf
•filetype:config intext:appSettings “User ID”
•filetype:dat "password.dat"
•filetype:dat inurl:Sites.dat
•filetype:dat wand.dat
•filetype:inc dbconn
•filetype:inc intext:mysql_connect
•filetype:inc mysql_connect OR mysql_pconnect
•filetype:inf sysprep
•filetype:ini inurl:"serv-u.ini"
•filetype:ini inurl:flashFXP.ini
•filetype:ini ServUDaemon
•filetype:ini wcx_ftp
•filetype:ini ws_ftp pwd
•filetype:ldb admin
•filetype:log See ipsec –copyright
•filetype:log inurl:"password.log"
•filetype:mdb inurl:users.mdb
•filetype:mdb wwforum
•filetype:netrc password
•filetype:pass pass intext:userid
•filetype:pem intext:private
•filetype:properties inurl:db intext:password
•filetype:pwd service

Desenvolvido por: Ruan Federle FormulaHacking.com 23


Google Hacking Fórmula Hacking
________________________________________________
•filetype:reg reg +intext:"defaultusername" +intext:"defaultpassword"
•filetype:reg reg HKEY_CURRENT_USER SSHHOSTKEYS
•filetype:sql "insert into" (pass|passwd|password)
•filetype:sql (“values * MD5″ | "values * password" | "values * encrypt")
•filetype:sql +"IDENTIFIED BY" -cvs
•filetype:sql password
•filetype:url +inurl:"ftp://" +inurl:";@"
•filetype:xls username password email
•intext:”enable password 7″
•intext:”enable secret 5 $”
•intext:”EZGuestbook”
•intext:”Web Wiz Journal”
•intitle:”index of” intext:connect.inc
•intitle:”index of” intext:globals.inc
•intitle:”Index of” passwords modified
•intitle:”Index of” sc_serv.conf sc_serv content
•intitle:”phpinfo()” +”mysql.default_password” +”Zend Scripting Language Engine”
•intitle:dupics inurl:(add.asp | default.asp | view.asp | voting.asp) -site:duware.com
•intitle:index.of administrators.pwd
•intitle:Index.of etc shadow
•intitle:index.of intext:”secring.skr”|”secring.pgp”|”secring.bak”
•inurl:”calendarscript/users.txt”
•inurl:”editor/list.asp” | inurl:”database_editor.asp” | inurl:”login.asa” “are set”
•inurl:”GRC.DAT” intext:”password”
•inurl:”Sites.dat”+”PASS=”
•inurl:”slapd.conf” intext:”credentials” -manpage -“Manual Page” -man: -sample
•inurl:”slapd.conf” intext:”rootpw” -manpage -“Manual Page” -man: -sample
•inurl:”wvdial.conf” intext:”password”
•inurl:/db/main.mdb
•inurl:/wwwboard
•inurl:/yabb/Members/Admin.dat
•inurl:ccbill filetype:log
•inurl:cgi-bin inurl:calendar.cfg
•inurl:chap-secrets -cvs
•inurl:config.php dbuname dbpass
•inurl:filezilla.xml -cvs
•inurl:lilo.conf filetype:conf password -tatercounter2000 -bootpwd -man
•inurl:nuke filetype:sql
•inurl:ospfd.conf intext:password -sample -test -tutorial -download

Desenvolvido por: Ruan Federle FormulaHacking.com 24


Google Hacking Fórmula Hacking
________________________________________________
•inurl:pap-secrets -cvs
•inurl:pass.dat
•inurl:perform filetype:ini
•inurl:perform.ini filetype:ini
•inurl:secring ext:skr | ext:pgp | ext:bak
•inurl:server.cfg rcon password
•inurl:ventrilo_srv.ini adminpassword
•inurl:vtund.conf intext:pass -cvs
•inurl:zebra.conf intext:password -sample -test -tutorial -download
•filetype:bkf bkf
•filetype:blt “buddylist”
•filetype:blt blt +intext:screenname
•filetype:cfg auto_inst.cfg
•filetype:cnf inurl:_vti_pvt access.cnf
•filetype:conf inurl:firewall -intitle:cvs
•filetype:config web.config -CVS
•filetype:ctt Contact
•filetype:ctt ctt messenger
•filetype:eml eml +intext:”Subject” +intext:”From” +intext:”To”
•filetype:fp3 fp3
•filetype:fp5 fp5 -site:gov -site:mil -“cvs log”
•filetype:fp7 fp7
•filetype:inf inurl:capolicy.inf
•filetype:lic lic intext:key
•filetype:log access.log -CVS
•filetype:log cron.log
•filetype:mbx mbx intext:Subject
•filetype:myd myd -CVS
•filetype:ns1 ns1
•filetype:ora ora
•filetype:ora tnsnames
•filetype:pdb pdb backup (Pilot | Pluckerdb)
•filetype:php inurl:index inurl:phpicalendar -site:sourceforge.net
•filetype:pot inurl:john.pot
•filetype:PS ps
•filetype:pst inurl:”outlook.pst”
•filetype:pst pst -from -to -date
•filetype:qbb qbb
•filetype:QBW qbw

Desenvolvido por: Ruan Federle FormulaHacking.com 25


Google Hacking Fórmula Hacking
________________________________________________
•filetype:rdp rdp
•filetype:reg “Terminal Server Client”
•filetype:vcs vcs
•filetype:wab wab
•filetype:xls -site:gov inurl:contact
•filetype:xls inurl:”email.xls”
•inurl:finance.xls
•inurl:finances.xls
•Ganglia Cluster Reports
•haccess.ctl
•ICQ chat logs, please…
•intext:”Session Start * * * *:*:* *” filetype:log
•intext:”Tobias Oetiker” “traffic analysis”
•intext:(password | passcode) intext:(username | userid | user) filetype:csv
•intext:SQLiteManager inurl:main.php
•intext:ViewCVS inurl:Settings.php
•intitle:”admin panel” +”RedKernel”
•intitle:”Apache::Status” (inurl:server-status | inurl:status.html | inurl:apache.html)
•intitle:”AppServ Open Project” -site:www.appservnetwork.com
•intitle:”ASP Stats Generator *.*” “ASP Stats Generator” “2003-2004 weppos”
•intitle:”Big Sister” +”OK Attention Trouble”
•intitle:”curriculum vitae” filetype:doc
•intitle:”edna:streaming mp3 server” -forums
•intitle:”index of” +myd size
•intitle:”Index Of” -inurl:maillog maillog size
•intitle:”Index Of” cookies.txt size
•intitle:”index of” mysql.conf OR mysql_config
•intitle:”Index of” upload size parent directory
•intitle:”index.of *” admin news.asp configview.asp
•intitle:”index.of” .diz .nfo last modified
•intitle:”Joomla – Web Installer”
•intitle:”LOGREP – Log file reporting system” -site:itefix.no
•intitle:”Multimon UPS status page”
•intitle:”PHP Advanced Transfer” (inurl:index.php | inurl:showrecent.php )
•intitle:”PhpMyExplorer” inurl:”index.php” -cvs
•intitle:”statistics of” “advanced web statistics”
•intitle:”System Statistics” +”System and Network Information Center”
•intitle:”urchin (5|3|admin)” ext:cgi
•intitle:”Usage Statistics for” “Generated by Webalizer”

Desenvolvido por: Ruan Federle FormulaHacking.com 26


Google Hacking Fórmula Hacking
________________________________________________
•intitle:”wbem” compaq login “Compaq Information Technologies Group”
•intitle:”Web Server Statistics for ****”
•intitle:”web server status” SSH Telnet
•intitle:”Welcome to F-Secure Policy Manager Server Welcome Page”
•intitle:”welcome.to.squeezebox”
•intitle:admin intitle:login
•intitle:Bookmarks inurl:bookmarks.html “Bookmarks
•intitle:index.of “Apache” “server at”
•intitle:index.of cleanup.log
•intitle:index.of dead.letter
•intitle:index.of inbox
•intitle:index.of inbox dbx
•intitle:index.of ws_ftp.ini
•intitle:intranet inurl:intranet +intext:”phone”
•inurl:”/axs/ax-admin.pl” -script
•inurl:”/cricket/grapher.cgi”
•inurl:”bookmark.htm”
•inurl:”cacti” +inurl:”graph_view.php” +”Settings Tree View” -cvs -RPM
•inurl:”newsletter/admin/”
•inurl:”newsletter/admin/” intitle:”newsletter admin”
•inurl:”putty.reg”
•inurl:”smb.conf” intext:”workgroup” filetype:conf conf
•inurl:*db filetype:mdb
•inurl:/cgi-bin/pass.txt
•inurl:/_layouts/settings
•inurl:admin filetype:xls
•inurl:admin intitle:login
•inurl:backup filetype:mdb
•inurl:build.err
•inurl:cgi-bin/printenv
•inurl:cgi-bin/testcgi “Please distribute TestCGI”
•inurl:changepassword.asp
•inurl:ds.py
•inurl:email filetype:mdb
•inurl:fcgi-bin/echo
•inurl:forum filetype:mdb
•inurl:forward filetype:forward -cvs
•inurl:log.nsf -gov
•inurl:main.php phpMyAdmin

Desenvolvido por: Ruan Federle FormulaHacking.com 27


Google Hacking Fórmula Hacking
________________________________________________
•inurl:main.php Welcome to phpMyAdmin
•inurl:netscape.hst
•inurl:netscape.ini
•inurl:odbc.ini ext:ini -cvs
•inurl:perl/printenv
•nurl:php.ini filetype:ini
•inurl:preferences.ini “[emule]”
•inurl:profiles filetype:mdb
•inurl:report “EVEREST Home Edition ”
•inurl:server-info “Apache Server Information”
•inurl:server-status “apache”
•inurl:snitz_forums_2000.mdb
•inurl:ssl.conf filetype:conf
•inurl:tdbin
•inurl:vbstats.php “page generated”
•inurl:wp-mail.php + “There doesn’t seem to be any new mail.”
•inurl:XcCDONTS.asp
•intitle:”Login Forum
•AnyBoard” intitle:”If you are a new user:” intext:”Forum
•AnyBoard” inurl:gochat -edu
•intitle:”Login to @Mail” (ext:pl | inurl:”index”) -waffleman
•!Host=*.* intext:enc_UserPassword=* ext:pcf

•“# -FrontPage-” ext:pwd inurl:(service | authors | administrators | users) “# -FrontPage-”


inurl:service.pwd
•“AutoCreate=TRUE password=*”
•“http://*:*@www” domainname
•“index of/” “ws_ftp.ini” “parent directory”
•“liveice configuration file” ext:cfg -site:sourceforge.net
•“parent directory” +proftpdpasswd
•Duclassified” -site:duware.com “DUware All Rights reserved”
•duclassmate” -site:duware.com
•Dudirectory” -site:duware.com
•dudownload” -site:duware.com
•Elite Forum Version *.*”

•“sets mode: +k”


•“your password is” filetype:log

Desenvolvido por: Ruan Federle FormulaHacking.com 28


Google Hacking Fórmula Hacking
________________________________________________
•DUpaypal” -site:duware.com
•allinurl: admin mdb
•auth_user_file.txt
•config.php
•eggdrop filetype:user user
•enable password | secret “current configuration” -intext:the
•etc (index.of)
•ext:asa | ext:bak intext:uid intext:pwd -“uid..pwd” database | server | dsn
•ext:inc “pwd=” “UID=”
•ext:ini eudora.ini
•ext:ini Version=4.0.0.4 password
•ext:passwd -intext:the -sample -example
•ext:txt inurl:unattend.txt
•ext:yml database inurl:config
•LeapFTP intitle:”index.of./” sites.ini modified
•master.passwd
•mysql history files
•NickServ registration passwords
•passlist
•passlist.txt
•passwd
•passwd / etc
•people.lst
•psyBNC config files
•pwd.db
•server-dbs “intitle:index of”
•signin filetype:url
•spwd.db / passwd
•trillian.ini
•wwwboard WebAdmin inurl:passwd.txt wwwboard|webadmin
•[WFClient] Password= filetype:ica
•intitle:”remote assessment” OpenAanval Console
•intitle:opengroupware.org “resistance is obsolete” “Report Bugs” “Username” “password”

•“bp blog admin” intitle:login | intitle:admin


•“Emergisoft web applications are a part of our”
•“Establishing a secure Integrated Lights Out session with” OR intitle:”Data Frame – Browser not HTTP 1.1
compatible”
•OR intitle:”HP Integrated Lights-

Desenvolvido por: Ruan Federle FormulaHacking.com 29


Google Hacking Fórmula Hacking
________________________________________________
•“HostingAccelerator” intitle:”login” +”Username” -“news” -demo
•“iCONECT 4.1 :: Login”
•“IMail Server Web Messaging” intitle:login
•“inspanel” intitle:”login” -“cannot” “Login ID”
•“Login – Sun Cobalt RaQ”
•“login prompt” inurl:GM.cgi
•“Login to Usermin” inurl:20000
•“Microsoft CRM : Unsupported Browser Version”
•“OPENSRS Domain Management” inurl:manage.cgi
•“pcANYWHERE EXPRESS Java Client”
•“Please authenticate yourself to get access to the management interface”
•“please log in”
•“Please login with admin pass” -“leak”
•CuteNews” “2003..2005 CutePHP”
•DWMail” password intitle:dwmail
•Merak Mail Server Software" -.gov -.mil -.edu
•Midmart Messageboard” “Administrator Login”
•Monster Top List” MTL numrange:200-
•UebiMiau” -site:sourceforge.net

•“site info for” “Enter Admin Password”


•“SquirrelMail version” “By the SquirrelMail development Team”
•“SysCP – login”
•“This is a restricted Access Server” “Javascript Not Enabled!”|”Messenger Express” -edu -ac
•“This section is for Administrators only. If you are an administrator then please”
•“ttawlogin.cgi/?action=”
•“VHCS Pro ver” -demo
•“VNC Desktop” inurl:5800
•“Web-Based Management” “Please input password to login”
•“WebExplorer Server – Login” “Welcome to WebExplorer Server”
•“WebSTAR Mail – Please Log In”

Desenvolvido por: Ruan Federle FormulaHacking.com 30


Google Hacking Fórmula Hacking
________________________________________________
•“You have requested access to a restricted area of our website. Please authenticate yourself to
continue.”
•“You have requested to access the management functions” -.edu
•(intitle:”Please login – Forums UBB.threads”)|(inurl:login.php “ubb”)
•(intitle:”Please login – Forums WWWThreads”)|(inurl:”wwwthreads/login.php”)|
(inurl:”wwwthreads/login.pl?Cat=”)
•(intitle:”rymo Login”)|(intext:”Welcome to rymo”) -family
•(intitle:”WmSC e-Cart Administration”)|(intitle:”WebMyStyle e-Cart Administration”)
•(inurl:”ars/cgi-bin/arweb?O=0″ | inurl:arweb.jsp) -site:remedy.com -site:mil
•4images Administration Control Panel
•allintitle:”Welcome to the Cyclades”
•allinurl:”exchange/logon.asp”
•allinurl:wps/portal/ login
•ASP.login_aspx “ASP.NET_SessionId”
•CGI:IRC Login
•ext:cgi intitle:”control panel” “enter your owner password to continue!”
•ez Publish administration
•filetype:php inurl:”webeditor.php”
•filetype:pl “Download: SuSE Linux Openexchange Server CA”
•filetype:r2w r2w
•Novell NetWare intext:”netware management portal version”
•PHPhotoalbum Statistics
•PHPhotoalbum Upload
•Please enter a valid password! inurl:polladmin
•intitle:”DocuShare” inurl:”docushare/dsweb/” -faq -gov -edu

•“#mysql dump” filetype:sql


•“#mysql dump” filetype:sql 21232f297a57a5a743894a0e4a801fc3
•“allow_call_time_pass_reference” “PATH_INFO”
•“Certificate Practice Statement” inurl:(PDF | DOC)
•“Generated by phpSystem”
•“generated by wwwstat”
•“Host Vulnerability Summary Report”
•“Index of” / “chat/logs”
•“Installed Objects Scanner” inurl:default.asp
•“MacHTTP” filetype:log inurl:machttp.log

Desenvolvido por: Ruan Federle FormulaHacking.com 31


Google Hacking Fórmula Hacking
________________________________________________
•“Mecury Version” “Infastructure Group”
•“Microsoft (R) Windows * (TM) Version * DrWtsn32 Copyright (C)” ext:log
•“Most Submitted Forms and scripts” “this section”
•“Network Vulnerability Assessment Report”
•“not for distribution” confidential
•“not for public release” -.edu -.gov -.mil
•“phone * * *” “address *” “e-mail” intitle:”curriculum vitae”
•“phpMyAdmin” “running on” inurl:”main.php”
•“produced by getstats”
•“Request Details” “Control Tree” “Server Variables”
•“robots.txt” “Disallow:” filetype:txt
•“Running in Child mode”
•“sets mode: +p”
•“sets mode: +s”
•“Thank you for your order” +receipt
•“This is a Shareaza Node”
•“This report was generated by WebLog”
•( filetype:mail | filetype:eml | filetype:mbox | filetype:mbx ) intext:password|subject
•(intitle:”PRTG Traffic Grapher” inurl:”allsensors”)|(intitle:”PRTG Traffic Grapher – Monitoring Results”)
•(intitle:WebStatistica inurl:main.php) | (intitle:”WebSTATISTICA server”) -inurl:statsoft -inurl:statsoftsa -
•inurl:statsoftinc.com -edu -software -rob
•(inurl:”robot.txt” | inurl:”robots.txt” ) intext:disallow filetype:txt
•+”:8080″ +”:3128″ +”:80″ filetype:txt
•-site:php.net -“The PHP Group” inurl:source inurl:url ext:pHp
•94FBR “ADOBE PHOTOSHOP”
•AIM buddy lists
•allinurl:/examples/jsp/snp/snoop.jsp
•allinurl:cdkey.txt
•allinurl:servlet/SnoopServlet
•cgiirc.conf
•contacts ext:wml
•data filetype:mdb -site:gov -site:mil
•exported email addresses

Desenvolvido por: Ruan Federle FormulaHacking.com 32


Google Hacking Fórmula Hacking
________________________________________________
•ext:(doc | pdf | xls | txt | ps | rtf | odt | sxw | psw | ppt | pps | xml) (intext:confidential salary |
intext:”budget approved”)
•inurl:confidential
•ext:asp inurl:pathto.asp
•ext:ccm ccm -catacomb
•ext:CDX CDX
•ext:cgi inurl:editcgi.cgi inurl:file=
•ext:conf inurl:rsyncd.conf -cvs -man
•ext:conf NoCatAuth -cvs
•ext:dat bpk.dat
•ext:gho gho
•ext:ics ics
•ext:ini intext:env.ini
•ext:jbf jbf
•ext:ldif ldif
•ext:log “Software: Microsoft Internet Information Services *.*”
•ext:mdb inurl:*.mdb inurl:fpdb shop.mdb
•ext:nsf nsf -gov -mil
•ext:plist filetype:plist inurl:bookmarks.plist
•ext:pqi pqi -database
•ext:reg “username=*” putty
•ext:txt “Final encryption key”
•ext:txt inurl:dxdiag
•ext:vmdk vmdk
•ext:vmx vmx
•filetype:asp DBQ=” * Server.MapPath(“*.mdb”)
•ipsec.conf
•ipsec.secrets

•“detected an internal error [IBM][CLI Driver][DB2/6000]”


•“error found handling the request” cocoon filetype:xml
•“Incorrect syntax near”
•“Internal Server Error” “server at”
•“Invision Power Board Database Error”
•“ORA-00933: SQL command not properly ended”
•“ORA-12541: TNS:no listener” intitle:”error occurred”
•“Parse error: parse error, unexpected T_VARIABLE” “on line” filetype:php

Desenvolvido por: Ruan Federle FormulaHacking.com 33


Google Hacking Fórmula Hacking
________________________________________________
•“PostgreSQL query failed: ERROR: parser: parse error”
•“Supplied argument is not a valid MySQL result resource”
•“Syntax error in query expression ” -the
•“The script whose uid is ” “is not allowed to access”
•“There seems to have been a problem with the” ” Please try again by clicking the Refresh button in your
web browser.”
•“Unable to jump to row” “on MySQL result index” “on line”
•“Unclosed quotation mark before the character string”
•“Warning: Bad arguments to (join|implode) () in” “on line” -help -forum
•“Warning: Cannot modify header information – headers already sent”
•“Warning: Division by zero in” “on line” -forum
•“Warning: mysql_connect(): Access denied for user: ‘*@*” “on line” -help -forum
•“Warning: mysql_query()” “invalid query”
•“Warning: pg_connect(): Unable to connect to PostgreSQL server: FATAL”
•“Warning: Supplied argument is not a valid File-Handle resource in”
•“Warning:” “failed to open stream: HTTP request failed” “on line”
•“Warning:” “SAFE MODE Restriction in effect.” “The script whose uid is” “is not allowed to access owned
by uid 0 in” “on line”
•“SQL Server Driver][SQL Server]Line 1: Incorrect syntax near”
•An unexpected token “END-OF-STATEMENT” was found
•Coldfusion Error Pages
•filetype:asp + “[ODBC SQL”
•filetype:asp “Custom Error Message” Category Source
•filetype:log “PHP Parse error” | “PHP Warning” | “PHP Error”
•filetype:php inurl:”logging.php” “Discuz” error
•ht://Dig htsearch error
•IIS 4.0 error messages
•IIS web server error messages
•intext:”Error Message : Error loading required libraries.”
•intext:”Warning: Failed opening” “on line” “include_path”
•intitle:”Apache Tomcat” “Error Report”
•intitle:”Default PLESK Page”
•intitle:”Error Occurred While Processing Request” +WHERE (SELECT|INSERT) filetype:cfm

Desenvolvido por: Ruan Federle FormulaHacking.com 34


Google Hacking Fórmula Hacking
________________________________________________
•intitle:”Error Occurred” “The error occurred in” filetype:cfm
•intitle:”Error using Hypernews” “Server Software”
•intitle:”Execution of this script not permitted”
•intitle:”Under construction” “does not currently have”
•intitle:Configuration.File inurl:softcart.exe
•MYSQL error message: supplied argument….
•mysql error with query
•Netscape Application Server Error page
•ORA-00921: unexpected end of SQL command
•ORA-00936: missing expression
•PHP application warnings failing “include_path”
•sitebuildercontent
•sitebuilderfiles
•sitebuilderpictures
•Snitz! forums db path error
•SQL syntax error
•Supplied argument is not a valid PostgreSQL result
•warning “error on line” php sablotron
•Windows 2000 web server error messages

•“ftp://” “www.eastgame.net”
•“html allowed” guestbook
•“: vBulletin Version 1.1.5″
•“Select a database to view” intitle:”filemaker pro”
•“set up the administrator user” inurl:pivot
•“There are no Administrators Accounts” inurl:admin.php -mysql_fetch_row
•“Welcome to Administration” “General” “Local Domains” “SMTP Authentication” inurl:admin
•“Welcome to Intranet”
•“Welcome to PHP-Nuke” congratulations
•“Welcome to the Prestige Web-Based Configurator”
•“YaBB SE Dev Team”
•“you can now password” | “this is a special page only seen by you. your profile visitors” inurl:imchaos
•(“Indexed.By”|”Monitored.By”) hAcxFtpScan
•(inurl:/shop.cgi/page=) | (inurl:/shop.pl/page=)
•allinurl:”index.php” “site=sglinks”
•allinurl:install/install.php

Desenvolvido por: Ruan Federle FormulaHacking.com 35


Google Hacking Fórmula Hacking
________________________________________________
•allinurl:intranet admin
•filetype:cgi inurl:”fileman.cgi”
•filetype:cgi inurl:”Web_Store.cgi”
•filetype:php inurl:vAuthenticate
•filetype:pl intitle:”Ultraboard Setup”
•Gallery in configuration mode
•Hassan Consulting’s Shopping Cart Version 1.18
•intext:”Warning: * am able * write ** configuration file” “includes/configure.php” –
•intitle:”Gateway Configuration Menu”
•intitle:”Horde :: My Portal” -“[Tickets”
•intitle:”Mail Server CMailServer Webmail” “5.2”
•intitle:”MvBlog powered”
•intitle:”Samba Web Administration Tool” intext:”Help Workgroup”
•intitle:”Terminal Services Web Connection”
•intitle:”Uploader – Uploader v6″ -pixloads.com
•intitle:osCommerce inurl:admin intext:”redistributable under the GNU” intext:”Online Catalog” -demo
-site:oscommerce.com
•intitle:phpMyAdmin “Welcome to phpMyAdmin ***” “running on * as root@*”
•inurl:”/NSearch/AdminServlet”
•inurl:”index.php? module=ew_filemanager”
•inurl:aol*/_do/rss_popup?blogID=
•inurl:footer.inc.php
•inurl:info.inc.php
•inurl:ManyServers.htm
•inurl:newsdesk.cgi? inurl:”t=”
•inurl:pls/admin_/gateway.htm
•inurl:rpSys.html
•inurl:search.php vbulletin
•inurl:servlet/webacc
•natterchat inurl:home.asp -site:natterchat.co.uk
•XOOPS Custom Installation
•inurl:htpasswd filetype:htpasswd
•inurl:yapboz_detay.asp
•intitle:”WJ-NT104 Main Page”
•inurl:netw_tcp.shtml
•mail filetype:csv -site:gov intext:name
•Microsoft Money Data Files
•mt-db-pass.cgi files
•MySQL tabledata dumps

Desenvolvido por: Ruan Federle FormulaHacking.com 36


Google Hacking Fórmula Hacking
________________________________________________
•mystuff.xml – Trillian data files
•OWA Public Folders
•php-addressbook “This is the addressbook for *” -warning
•private key files (.csr)
•private key files (.key)
•Quicken data files
•rdbqds -site:.edu -site:.mil -site:.gov
•robots.txt
•site:edu admin grades
•site:www.mailinator.com inurl:ShowMail.do
•SQL data dumps
•Squid cache server reports
•Unreal IRCd
•WebLog Referrers
•Welcome to ntop!
•filetype:log intext:”ConnectionManager2″

•“apricot – admin” 00h


•“by Reimar Hoven. All Rights Reserved. Disclaimer” | inurl:”log/logdb.dta”
•“Network Host Assessment Report” “Internet Scanner”
•“Output produced by SysWatch *”
•“Phorum Admin” “Database Connection” inurl:forum inurl:admin
•phpOpenTracker” Statistics

•“powered | performed by Beyond Security’s Automated Scanning” -kazaa -example


•“Shadow Security Scanner performed a vulnerability assessment”
•“SnortSnarf alert page”
•“The following report contains confidential information” vulnerability -search
•“The statistics were last updated” “Daily”-microsoft.com
•“this proxy is working fine!” “enter *” “URL***” * visit
•“This report lists” “identified by Internet Scanner”
•“Traffic Analysis for” “RMON Port * on unit *”
•“Version Info” “Boot Version” “Internet Settings”
•((inurl:ifgraph “Page generated at”) OR (“This page was built using ifgraph”))
•Analysis Console for Incident Databases
•ext:cgi intext:”nrg-” ” This web page was created on ”

Desenvolvido por: Ruan Federle FormulaHacking.com 37


Google Hacking Fórmula Hacking
________________________________________________
•filetype:pdf “Assessment Report” nessus
•filetype:php inurl:ipinfo.php “Distributed Intrusion Detection System”
•filetype:php inurl:nqt intext:”Network Query Tool”
•filetype:vsd vsd network -samples -examples
•intext:”Welcome to the Web V.Networks” intitle:”V.Networks [Top]” -filetype:htm
•intitle:”ADSL Configuration page”
•intitle:”Azureus : Java BitTorrent Client Tracker”
•intitle:”Belarc Advisor Current Profile” intext:”Click here for Belarc’s PC Management products, for large
and small companies.”
•intitle:”BNBT Tracker Info”
•intitle:”Microsoft Site Server Analysis”
•intitle:”Nessus Scan Report” “This file was generated by Nessus”
•intitle:”PHPBTTracker Statistics” | intitle:”PHPBT Tracker Statistics”
•intitle:”Retina Report” “CONFIDENTIAL INFORMATION”
•intitle:”start.managing.the.device” remote pbx acc
•intitle:”sysinfo * ” intext:”Generated by Sysinfo * written by The Gamblers.”
•intitle:”twiki” inurl:”TWikiUsers”
•inurl:”/catalog.nsf” intitle:catalog
•inurl:”install/install.php”
•inurl:”map.asp?” intitle:”WhatsUp Gold”
•inurl:”NmConsole/Login.asp” | intitle:”Login – Ipswitch WhatsUp Professional 2005″ | intext:”Ipswitch
WhatsUp
•Professional 2005 (SP1)” “Ipswitch, Inc”
•inurl:”sitescope.html” intitle:”sitescope” intext:”refresh” -demo
•inurl:/adm-cfgedit.php
•inurl:/cgi-bin/finger? “In real life”
•inurl:/cgi-bin/finger? Enter (account|host|user|username)
•inurl:/counter/index.php intitle:”+PHPCounter 7.*”
•inurl:CrazyWWWBoard.cgi intext:”detailed debugging information”
•inurl:login.jsp.bak
•inurl:ovcgi/jovw
•inurl:phpSysInfo/ “created by phpsysinfo”
•inurl:portscan.php “from Port”|”Port Range”
•inurl:proxy | inurl:wpad ext:pac | ext:dat findproxyforurl
•inurl:statrep.nsf -gov
•inurl:status.cgi?host=all
•inurl:testcgi xitami
•inurl:webalizer filetype:png -.gov -.edu -.mil -opendarwin
•inurl:webutil.pl

Desenvolvido por: Ruan Federle FormulaHacking.com 38


Google Hacking Fórmula Hacking
________________________________________________
•site:netcraft.com intitle:That.Site.Running Apache

•“A syntax error has occurred” filetype:ihtml


•“access denied for user” “using password”
•“An illegal character has been found in the statement” -“previous message”
•“ASP.NET_SessionId” “data source=”
•“Can’t connect to local” intitle:warning
•“Chatologica MetaSearch” “stack tracking”
•“Fatal error: Call to undefined function” -reply -the -next
•“Duclassified” -site:duware.com “DUware All Rights reserved”
•“Elite Forum Version *.*”
•“Link Department”
•“Chatologica MetaSearch” “stack tracking:”
•“Index of /backup”
•“ORA-00921: unexpected end of SQL command”
•“parent directory ” /appz/ -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
•“parent directory ” DVDRip -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
•“parent directory ” Gamez -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
•“parent directory ” MP3 -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
•“parent directory ” Name of Singer or album -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
•“parent directory “Xvid -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
•?intitle:index.of? mp3 name
•allinurl:auth_user_file.txt
•inurl:passlist.txt
•filetype:bak inurl:”htaccess|passwd|shadow|htusers”
•filetype:cfg mrtg “target
•filetype:cfm “cfapplication name” password
•filetype:config config intext:appSettings “User ID”
•filetype:dat “password.dat”
•filetype:ini inurl:”serv-u.ini”
•filetype:log “See `ipsec –copyright”
•filetype:log inurl:”password.log”
•filetype:pwl pwl

Desenvolvido por: Ruan Federle FormulaHacking.com 39


Google Hacking Fórmula Hacking
________________________________________________
•filetype:reg reg +intext:”defaultusername” +intext:”defaultpassword”
•filetype:reg reg +intext:â? WINVNC3â?
•filetype:sql “insert into” (pass|passwd|password)
•filetype:sql (“values * MD5″ | “values * password” | “values * encrypt”)
•filetype:sql +”IDENTIFIED BY” -cvs
•filetype:url +inurl:”ftp://” +inurl:”;@”
•htpasswd
•htpasswd / htgroup
•htpasswd / htpasswd.bak
•intitle:”phpinfo()” +”mysql.default_password” +”Zend scripting Language Engine”
•intitle:rapidshare intext:login
•Financial spreadsheets: finance.xls
•Financial spreadsheets: finances.xls
•haccess.ctl (one way)
•haccess.ctl (VERY reliable)
•intext:gmail invite intext:http://gmail.google.com/gmail/a
•intitle:”FTP root at”
•inurl:cgi-bin/testcgi.exe “Please distribute TestCGI”
•inurl:getmsg.html intitle:hotmail
•inurl:php.ini filetype:ini
•intext:””BiTBOARD v2.0″ BiTSHiFTERS Bulletin Board”
•intext:”Fill out the form below completely to change your password and user name. If new username is
left blank, your old one will be assumed.” -edu
•intext:”Mail admins login here to administrate your domain.”
•intext:”Master Account” “Domain Name” “Password” inurl:/cgi-bin/qmailadmin
•intext:”Storage Management Server for” intitle:”Server Administration”
•intext:”Welcome to” inurl:”cp” intitle:”H-SPHERE” inurl:”begin.html” -Fee
•intext:”vbulletin” inurl:admincp
•intitle:”*- HP WBEM Login” | “You are being prompted to provide login account information for *” | “Please
provide the information requested and press
•intitle:”Admin Login” “admin login” “blogware”
•intitle:”Admin login” “Web Site Administration” “Copyright”
•intitle:”AlternC Desktop”
•intitle:”Athens Authentication Point”
•intitle:”b2evo > Login form” “Login form. You must log in! You will have to accept cookies in order to log
in” -demo -site:b2evolution.net
•intitle:”Cisco CallManager User Options Log On” “Please enter your User ID and Password in the spaces
provided below and click the Log On button to co
•intitle:”ColdFusion Administrator Login”

Desenvolvido por: Ruan Federle FormulaHacking.com 40


Google Hacking Fórmula Hacking
________________________________________________
•intitle:”communigate pro * *” intitle:”entrance”
•intitle:”Content Management System” “user name”|”password”|”admin” “Microsoft IE 5.5″ -mambo
•intitle:”Dell Remote Access Controller”
•intitle:”Docutek ERes – Admin Login” -edu
•intitle:”Employee Intranet Login”
•intitle:”eMule *” intitle:”- Web Control Panel” intext:”Web Control Panel” “Enter your password here.”
•intitle:”ePowerSwitch Login”
•intitle:”eXist Database Administration” -demo
•intitle:”EXTRANET * – Identification”
•intitle:”EXTRANET login” -.edu -.mil -.gov
•intitle:”EZPartner” -netpond
•intitle:”Flash Operator Panel” -ext:php -wiki -cms -inurl:asternic -inurl:sip -intitle:ANNOUNCE -inurl:lists
•intitle:”i-secure v1.1″ -edu
•intitle:”Icecast Administration Admin Page”
•intitle:”iDevAffiliate – admin” -demo
•intitle:”ISPMan : Unauthorized Access prohibited”
•intitle:”ITS System Information” “Please log on to the SAP System”
•intitle:”Kurant Corporation StoreSense” filetype:bok
•intitle:”ListMail Login” admin -demo
•intitle:”Login –
•intitle:”Login to @Mail” (ext:pl | inurl:”index”) -dwaffleman
•intitle:”Login to Cacti”
•intitle:”Login to the forums – @www.aimoo.com” inurl:login.cfm?id=
•intitle:”MailMan Login”
•intitle:”Member Login” “NOTE: Your browser must have cookies enabled in order to log into the site.”
ext:php OR ext:cgi
•intitle:”Merak Mail Server Web Administration” -ihackstuff.com
•intitle:”microsoft certificate services” inurl:certsrv
•intitle:”MikroTik RouterOS Managing Webpage”
•intitle:”MX Control Console” “If you can’t remember”
•intitle:”Novell Web Services” “GroupWise” -inurl:”doc/11924″ -.mil -.edu -.gov -filetype:pdf
•intitle:”Novell Web Services” intext:”Select a service and a language.”
•intitle:”oMail-admin Administration – Login” -inurl:omnis.ch
•intitle:”OnLine Recruitment Program – Login”
•intitle:”Philex 0.2*” -script -site:freelists.org
•intitle:”PHP Advanced Transfer” inurl:”login.php”
•intitle:”php icalendar administration” -site:sourceforge.net
•intitle:”phpPgAdmin – Login” Language
•intitle:”PHProjekt – login” login password

Desenvolvido por: Ruan Federle FormulaHacking.com 41


Google Hacking Fórmula Hacking
________________________________________________
•intitle:”please login” “your password is *”
•intitle:”Remote Desktop Web Connection” inurl:tsweb
•intitle:”SFXAdmin – sfx_global” | intitle:”SFXAdmin – sfx_local” | intitle:”SFXAdmin – sfx_test”
•intitle:”SHOUTcast Administrator” inurl:admin.cgi
•intitle:”site administration: please log in” “site designed by emarketsouth”
•intitle:”Supero Doctor III” -inurl:supermicro
•intitle:”SuSE Linux Openexchange Server” “Please activate JavaScript!”
•intitle:”teamspeak server-administration
•intitle:”Tomcat Server Administration”
•intitle:”TOPdesk ApplicationServer”
•intitle:”TUTOS Login”
•intitle:”TWIG Login”
•intitle:”vhost” intext:”vHost . 2000-2004″
•intitle:”Virtual Server Administration System”
•intitle:”VisNetic WebMail” inurl:”/mail/”
•intitle:”VitalQIP IP Management System”
•intitle:”VMware Management Interface:” inurl:”vmware/en/”
•intitle:”VNC viewer for Java”
•intitle:”web-cyradm”|”by Luc de Louw” “This is only for authorized users” -tar.gz -site:web-cyradm.org
•intitle:”WebLogic Server” intitle:”Console Login” inurl:console
•intitle:”Welcome Site/User Administrator” “Please select the language” -demos
•intitle:”Welcome to Mailtraq WebMail”
•intitle:”welcome to netware *” -site:novell.com
•intitle:”WorldClient” intext:”? (2003|2004) Alt-N Technologies.”
•intitle:”xams 0.0.0..15 – Login”
•intitle:”XcAuctionLite” | “DRIVEN BY XCENT” Lite inurl:admin
•intitle:”XMail Web Administration Interface” intext:Login intext:password
•intitle:”Zope Help System” inurl:HelpSys
•intitle:”ZyXEL Prestige Router” “Enter password”
•intitle:”inc. vpn 3000 concentrator”
•intitle:(“TrackerCam Live Video”)|(“TrackerCam Application Login”)|(“Trackercam Remote”)
-trackercam.com
•intitle:asterisk.management.portal web-access
•intitle:endymion.sak?.mail.login.page | inurl:sake.servlet
•intitle:Group-Office “Enter your username and password to login”
•intitle:ilohamail ”
•intitle:ilohamail intext:”Version 0.8.10″ ”
•intitle:IMP inurl:imp/index.php3
•intitle:Login * Webmailer

Desenvolvido por: Ruan Federle FormulaHacking.com 42


Google Hacking Fórmula Hacking
________________________________________________
•intitle:Login intext:”RT is ? Copyright”
•intitle:Node.List Win32.Version.3.11
•intitle:Novell intitle:WebAccess “Copyright *-* Novell, Inc”
•intitle:open-xchange inurl:login.pl
•intitle:Ovislink inurl:private/login
•intitle:phpnews.login
•intitle:plesk inurl:login.php3
•inurl:”/admin/configuration. php?” Mystore
•inurl:”/slxweb.dll/external?name=(custportal|webticketcust)”
•inurl:”1220/parse_xml.cgi?”
•inurl:”631/admin” (inurl:”op=*”) | (intitle:CUPS)
•inurl:”:10000″ intext:webmin
•inurl:”Activex/default.htm” “Demo”
•inurl:”calendar.asp?action=login”
•inurl:”default/login.php” intitle:”kerio”
•inurl:”gs/adminlogin.aspx”
•inurl:”php121login.php”
•inurl:”suse/login.pl”
•inurl:”typo3/index.php?u=” -demo
•inurl:”usysinfo?login=true”
•inurl:”utilities/TreeView.asp”
•inurl:”vsadmin/login” | inurl:”vsadmin/admin” inurl:.php|.asp
•nurl:/admin/login.asp
•inurl:/cgi-bin/sqwebmail?noframes=1
•inurl:/Citrix/Nfuse17/
•inurl:/dana-na/auth/welcome.html
•inurl:/eprise/
•inurl:/Merchant2/admin.mv | inurl:/Merchant2/admin.mvc | intitle:”Miva Merchant Administration Login”
-inurl:cheap-malboro.net
•inurl:/modcp/ intext:Moderator+vBulletin
•inurl:/SUSAdmin intitle:”Microsoft Software Update Services”
•inurl:/webedit.* intext:WebEdit Professional -html
•inurl:1810 “Oracle Enterprise Manager”
•inurl:2000 intitle:RemotelyAnywhere -site:realvnc.com
•inurl::2082/frontend -demo
•inurl:administrator “welcome to mambo”
•inurl:bin.welcome.sh | inurl:bin.welcome.bat | intitle:eHealth.5.0
•inurl:cgi-bin/ultimatebb.cgi?ubb=login
•inurl:Citrix/MetaFrame/default/default.aspx

Desenvolvido por: Ruan Federle FormulaHacking.com 43


Google Hacking Fórmula Hacking
________________________________________________
•inurl:confixx inurl:login|anmeldung
•inurl:coranto.cgi intitle:Login (Authorized Users Only)
•inurl:csCreatePro.cgi
•inurl:default.asp intitle:”WebCommander”
•inurl:exchweb/bin/auth/owalogon.asp
•inurl:gnatsweb.pl
•inurl:ids5web
•inurl:irc filetype:cgi cgi:irc
•inurl:login filetype:swf swf
•inurl:login.asp
•inurl:login.cfm
•inurl:login.php “SquirrelMail version”
•inurl:metaframexp/default/login.asp | intitle:”Metaframe XP Login”
•inurl:mewebmail
•inurl:names.nsf?opendatabase
•inurl:ocw_login_username
•inurl:orasso.wwsso_app_admin.ls_login
•inurl:postfixadmin intitle:”postfix admin” ext:php
•inurl:search/admin.php
•inurl:textpattern/index.php
•inurl:WCP_USER
•inurl:webmail./index.pl “Interface”
•inurl:webvpn.html “login” “Please enter your” Login (“admin account info”) filetype:log
•Link Department”
•passlist.txt (a better way)
•passwd / etc (reliable)

•“bp blog admin” intitle:login | intitle:admin -site:johnny.ihackstuff.com


•“Establishing a secure Integrated Lights Out session with” OR intitle:”Data Frame – Browser not HTTP 1.1
compatible” OR intitle:”HP Integrated Lights-
•“inspanel” intitle:”login” -“cannot” “Login ID” -site:inspediumsoft.com
•“intitle:3300 Integrated Communications Platform” inurl:main.htm
•“Please login with admin pass” -“leak” -sourceforge
•Merak Mail Server Software” -.gov -.mil -.edu -site:merakmailserver.com

•“Web-Based Management” “Please input password to login” -inurl:johnny.ihackstuff.com


•(intitle:”Please login – Forums
•UBB.threads”)|(inurl:login.php “ubb”)
•WWWThreads”)|(inurl:”wwwthreads/login.php”)|(inurl:”wwwthreads/login.pl?Cat=”)

Desenvolvido por: Ruan Federle FormulaHacking.com 44


Google Hacking Fórmula Hacking
________________________________________________
•Login (”
•Jetbox One CMS â?¢” | ”
•Jetstream ? *”)
•Outlook Web Access (a better way)
•PhotoPost PHP Upload

•“HTTP_FROM=googlebot” googlebot.com “Server_Software=”


•“Most Submitted Forms and s?ri?ts” “this section”
•(intitle:WebStatistica inurl:main.php) | (intitle:”WebSTATISTICA server”) -inurl:statsoft -inurl:statsoftsa
-inurl:statsoftinc.com -edu -software -rob
•+”HSTSNR” -“netop.com”
•ext:(doc | pdf | xls | txt | ps | rtf | odt | sxw | psw | ppt | pps | xml) (intext:confidential salary |
intext:”budget approved”) inurl:confidential
•intitle:”admin panel” +”
•RedKernel”
•inurl:”/axs/ax-admin.pl” -s?ri?t
•Internal Server Error
•intitle:”Remote Desktop Web Connection”
•+ View Webcam User Accessing
•allinurl:control/multiview
•inurl:”ViewerFrame?Mode=”
•intitle:”supervisioncam protocol”
•OWA Public Folders (direct view)
•Peoples MSN contact lists

•“The statistics were last updated” “Daily”-microsoft.com


•ext:cfg radius.cfg
•inurl:”NmConsole/Login.asp” | intitle:”Login – Ipswitch WhatsUp Professional 2005″ | intext:”Ipswitch
WhatsUp Professional 2005 (SP1)” “Ipswitch, Inc”

•“The script whose uid is ” “is not allowed to access”
•“Warning:” “SAFE MODE Restriction in effect.” “The script whose uid is” “is not allowed to access owned
by uid 0 in” “on line”
•intitle:”Execution of this script not permitted”
•: vBulletin Version 1.1.5″
•inurl:yapboz_detay.asp + View Webcam User Accessing

•“duclassmate” -site:duware.com
•“Dudirectory” -site:duware.com

Desenvolvido por: Ruan Federle FormulaHacking.com 45


Google Hacking Fórmula Hacking
________________________________________________
•“dudownload” -site:duware.com
•“DUpaypal” -site:duware.com
•allintitle:”Network Camera NetworkCamera”
•intitle:”live view” intitle:axis
•intitle:axis intitle:”video server”
•intitle:liveapplet
•inurl:axis-cgi/jpg
•inurl:axis-cgi/mjpg (motion-JPEG)
•inurl:view/index.shtml
•inurl:view/indexFrame.shtml
•inurl:view/view.shtml
•inurl:ViewerFrame?Mode=Refresh
•liveapplet

•” -FrontPage-” ext:pwd inurl:(service | authors | administrators | users)


•“About Mac OS Personal Web Sharing”
•“Copyright © Tektronix, Inc.” “printer status”
•“Dumping data for table”
•“Error Diagnostic Information” intitle:”Error Occurred While”
•“Index of /” +.htaccess
•“Index of /” +passwd
•“Index of /” +password.txt
•“Index of /admin”
•“Index of /mail”
•“Index Of /network” “last modified”
•“Index of /password”
•“index of /private” site:mil
•“index of /private” -site:net -site:com -site:org
•“liveice configuration file” ext:cfg
•“Microsoft ® Windows * ™ Version * DrWtsn32 Copyright ©” ext:log
•“More Info about MetaCart Free”
•“mysql dump” filetype:sql
•“mySQL error with query”

Desenvolvido por: Ruan Federle FormulaHacking.com 46


Google Hacking Fórmula Hacking
________________________________________________
•“ORA-00936: missing expression”
•“phpMyAdmin MySQL-Dump” “INSERT INTO” -“the”
•“phpMyAdmin MySQL-Dump” filetype:txt
•“Powered by mnoGoSearch – free web search engine software”
•“powered by openbsd” +”powered by apache”
•“Powered by UebiMiau” -site:sourceforge.net
•“Supplied argument is not a valid PostgreSQL result”
•“This summary was generated by wwwstat”
•“Web File Browser” “Use regular expression”
•“xampp/phpinfo
•“You have an error in your SQL syntax near”
•“Your password is * Remember this for later use”
•aboutprinter.shtml
•allintitle: “index of/admin”
•allintitle: “index of/root”
•allintitle: restricted filetype :mail
•allintitle: restricted filetype:doc site:gov
•allintitle: sensitive filetype:doc
•allintitle:..”Test page for Apache Installation..”
•allintitle:admin.php
•allinurl:”.r{}_vti_cnf/”
•allinurl:admin mdb
•camera linksys inurl:main.cgi
•Canon Webview netcams
•Comersus.mdb database
•confidential site:mil
•ConnectionTest.java filetype:html
•ext:pwd inurl:(service | authors | administrators | users) “# -FrontPage-”
•filetype:ASP ASP
•filetype:ASPX ASPX
•filetype:BML BML
•filetype:cfg ks intext:rootpw -sample -test -howto
•filetype:CFM CFM
•filetype:CGI CGI
•filetype:conf inurl:psybnc.conf “USER.PASS=”

Desenvolvido por: Ruan Federle FormulaHacking.com 47


Google Hacking Fórmula Hacking
________________________________________________
•filetype:dat “password.dat
•filetype:DIFF DIFF
•filetype:DLL DLL
•filetype:DOC DOC
•filetype:FCGI FCGI
•filetype:HTM HTM
•filetype:HTML HTML
•filetype:JHTML JHTML
•filetype:JSP JSP
•filetype:log inurl:password.log
•filetype:MV MV
•filetype:PDF PDF
•filetype:PHP PHP
•filetype:PHP3 PHP3
•filetype:PHP4 PHP4
•filetype:PHTML PHTML
•filetype:PL PL
•filetype:PPT PPT
•filetype:SHTML SHTML
•filetype:STM STM
•filetype:SWF SWF
•filetype:TXT TXT
•filetype:XLS XLS
•Index of phpMyAdmin
•index of: intext:Gallery in Configuration mode
•index.of passlist
•intext:”d.aspx?id” || inurl:”d.aspx?id”
•intext:”powered by Web Wiz Journal”
•intext:”SteamUserPassphrase=” intext:”SteamAppUser=” -“username” -“user”
•intitle:”— VIDEO WEB SERVER —” intext:”Video Web Server” “Any time & Any where” username
password
•intitle:”500 Internal Server Error” “server at”
•intitle:”actiontec” main setup status “Copyright 2001 Actiontec Electronics Inc”
•intitle:”Browser Launch Page”
•intitle:”EverFocus.EDSR.applet”
•intitle:”Index of” “.htpasswd” “htgroup” -intitle:”dist” -apache -htpasswd.c
•intitle:”Index of” .bash_history
•intitle:”Index of” .mysql_history
•intitle:”Index of” .sh_history

Desenvolvido por: Ruan Federle FormulaHacking.com 48


Google Hacking Fórmula Hacking
________________________________________________
•intitle:”Index of” cfide
•intitle:”index of” etc/shadow
•intitle:”index of” htpasswd
•intitle:”index of” master.passwd
•intitle:”index of” members OR accounts
•intitle:”index of” passwd
•intitle:”index of” people.lst
•intitle:”index of” pwd.db
•intitle:”index of” spwd
•intitle:”Index of” spwd.db passwd -pam.conf
•intitle:”index of” user_carts OR user_cart
•intitle:”Index of..etc” passwd
•intitle:”iVISTA.Main.Page”
•intitle:”network administration” inurl:”nic”
•intitle:”OfficeConnect Cable/DSL Gateway” intext:”Checking your browser”
•intitle:”switch login” “IBM Fast Ethernet Desktop”
•intitle:”SWW link” “Please wait…..”
•intitle:”Welcome to the Advanced Extranet Server, ADVX!”
•intitle:”Welcome to Windows 2000 Internet Services”
•intitle:”Connection Status” intext:”Current login”
•intitle:index.of cgiirc.config
•intitle:Index.of etc shadow site:passwd
•intitle:index.of master.passwd
•intitle:index.of passwd passwd.bak
•intitle:index.of people.lst
•intitle:index.of trillian.ini
•inurl:”8003/Display?what=”
•inurl:”auth_user_file.txt”
•inurl:”printer/main.html” intext:”settings”
•inurl:”wwwroot/
•inurl:access
•inurl:admin filetype:db
•inurl:asp
•inurl:buy
•inurl:cgi
•inurl:cgiirc.config
•inurl:data
•inurl:download
•inurl:file

Desenvolvido por: Ruan Federle FormulaHacking.com 49


Google Hacking Fórmula Hacking
________________________________________________
•inurl:forum
•inurl:home
•inurl:hp/device/this.LCDispatcher
•inurl:html
•inurl:iisadmin
•inurl:inc
•inurl:info
•inurl:list
•inurl:mail
•inurl:midicart.mdb
•inurl:new
•inurl:order
•inurl:pages
•Ultima Online loginservers
•inurl:Proxy.txt
•inurl:public
•inurl:search
•inurl:shop
•inurl:shopdbtest.asp
•inurl:software
•inurl:support
•inurl:user
•inurl:vtund.conf intext:pass -cvs s
•inurl:web
•POWERED BY HIT JAMMER 1.0!
•site:ups.com intitle:”Ups Package tracking” intext:”1Z ### ### ## #### ### #”
•top secret site:mil
•VP-ASP Shop Administrators only
•XAMPP “inurl:xampp/index”
•allintitle:*.php?filename=*
•allintitle:*.php?page=*
•allintitle:*.php?logon=*

Desenvolvido por: Ruan Federle FormulaHacking.com 50


Google Hacking Fórmula Hacking
________________________________________________

> Dorks para SQL injection

about.php?cartID=
accinfo.php?cartId=
acclogin.php?cartID=
add.php?bookid=
add_cart.php?num=
addcart.php?
addItem.php
add-to-cart.php?ID=
addToCart.php?idProduct=
addtomylist.php?ProdId=
adminEditProductFields.php?intProdID=
advSearch_h.php?idCategory=
affiliate.php?ID=
affiliate-agreement.cfm?storeid=
affiliates.php?id=
ancillary.php?ID=
archive.php?id=
article.php?id=
phpx?PageID

Desenvolvido por: Ruan Federle FormulaHacking.com 51


Google Hacking Fórmula Hacking
________________________________________________
basket.php?id=
Book.php?bookID=
book_list.php?bookid=
book_view.php?bookid=
BookDetails.php?ID=
browse.php?catid=
browse_item_details.php
Browse_Item_Details.php?Store_Id=
buy.php?
buy.php?bookid=
bycategory.php?id=
cardinfo.php?card=
cart.php?action=
cart.php?cart_id=
cart.php?id=
cart_additem.php?id=
cart_validate.php?id=
cartadd.php?id=
cat.php?iCat=
catalog.php
catalog.php?CatalogID=
catalog_item.php?ID=
catalog_main.php?catid=
category.php
category.php?catid=
category_list.php?id=
categorydisplay.php?catid=

Desenvolvido por: Ruan Federle FormulaHacking.com 52


Google Hacking Fórmula Hacking
________________________________________________
checkout.php?cartid=
checkout.php?UserID=
checkout_confirmed.php?order_id=
checkout1.php?cartid=
comersus_listCategoriesAndProducts.php?idCategory=
comersus_optEmailToFriendForm.php?idProduct=
comersus_optReviewReadExec.php?idProduct=
comersus_viewItem.php?idProduct=
comments_form.php?ID=
contact.php?cartId=
content.php?id=
customerService.php?****ID1=
default.php?catID=
description.php?bookid=
details.php?BookID=
details.php?Press_Release_ID=
details.php?Product_ID=
details.php?Service_ID=
display_item.php?id=
displayproducts.php
downloadTrial.php?intProdID=
emailproduct.php?itemid=
emailToFriend.php?idProduct=
events.php?ID=
faq.php?cartID=
faq_list.php?id=
faqs.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 53


Google Hacking Fórmula Hacking
________________________________________________
feedback.php?title=
freedownload.php?bookid=
fullDisplay.php?item=
getbook.php?bookid=
GetItems.php?itemid=
giftDetail.php?id=
help.php?CartId=
home.php?id=
index.php?cart=
index.php?cartID=
index.php?ID=
info.php?ID=
item.php?eid=
item.php?item_id=
item.php?itemid=
item.php?model=
item.php?prodtype=
item.php?shopcd=
item_details.php?catid=
item_list.php?maingroup
item_show.php?code_no=
itemDesc.php?CartId=
itemdetail.php?item=
itemdetails.php?catalogid=
learnmore.php?cartID=
links.php?catid=
list.php?bookid=

Desenvolvido por: Ruan Federle FormulaHacking.com 54


Google Hacking Fórmula Hacking
________________________________________________
List.php?CatID=
listcategoriesandproducts.php?idCategory=
modline.php?id=
myaccount.php?catid=
news.php?id=
order.php?BookID=
order.php?id=
order.php?item_ID=
OrderForm.php?Cart=
page.php?PartID=
payment.php?CartID=
pdetail.php?item_id=
powersearch.php?CartId=
price.php
privacy.php?cartID=
prodbycat.php?intCatalogID=
prodetails.php?prodid=
prodlist.php?catid=
product.php?bookID=
product.php?intProdID=
product_info.php?item_id=
productDetails.php?idProduct=
productDisplay.php
productinfo.php?item=
productlist.php?ViewType=Category&CategoryID=
productpage.php
products.php?ID=

Desenvolvido por: Ruan Federle FormulaHacking.com 55


Google Hacking Fórmula Hacking
________________________________________________
products.php?keyword=
products_category.php?CategoryID=
products_detail.php?CategoryID=
productsByCategory.php?intCatalogID=
prodView.php?idProduct=
promo.php?id=
promotion.php?catid=
pview.php?Item=
resellers.php?idCategory=
results.php?cat=
savecart.php?CartId=
search.php?CartID=
searchcat.php?search_id=
Select_Item.php?id=
Services.php?ID=
shippinginfo.php?CartId=
shop.php?a=
shop.php?action=
shop.php?bookid=
shop.php?cartID=
shop_details.php?prodid=
shopaddtocart.php
shopaddtocart.php?catalogid=
shopbasket.php?bookid=
shopbycategory.php?catid=
shopcart.php?title=
shopcreatorder.php

Desenvolvido por: Ruan Federle FormulaHacking.com 56


Google Hacking Fórmula Hacking
________________________________________________
shopcurrency.php?cid=
shopdc.php?bookid=
shopdisplaycategories.php
shopdisplayproduct.php?catalogid=
shopdisplayproducts.php
shopexd.php
shopexd.php?catalogid=
shopping_basket.php?cartID=
shopprojectlogin.php
shopquery.php?catalogid=
shopremoveitem.php?cartid=
shopreviewadd.php?id=
shopreviewlist.php?id=
ShopSearch.php?CategoryID=
shoptellafriend.php?id=
shopthanks.php
shopwelcome.php?title=
show_item.php?id=
show_item_details.php?item_id=
showbook.php?bookid=
showStore.php?catID=
shprodde.php?SKU=
specials.php?id=
store.php?id=
store_bycat.php?id=
store_listing.php?id=
Store_ViewProducts.php?Cat=

Desenvolvido por: Ruan Federle FormulaHacking.com 57


Google Hacking Fórmula Hacking
________________________________________________
store-details.php?id=
storefront.php?id=
storefronts.php?title=
storeitem.php?item=
StoreRedirect.php?ID=
subcategories.php?id=
tek9.php?
template.php?Action=Item&pid=
topic.php?ID=
tuangou.php?bookid=
type.php?iType=
updatebasket.php?bookid=
updates.php?ID=
view.php?cid=
view_cart.php?title=
view_detail.php?ID=
viewcart.php?CartId=
viewCart.php?userID=
viewCat_h.php?idCategory=
viewevent.php?EventID=
viewitem.php?recor=
viewPrd.php?idcategory=
ViewProduct.php?misc=
voteList.php?item_ID=
whatsnew.php?idCategory=
WsAncillary.php?ID=
WsPages.php?ID=noticiasDetalle.php?xid=

Desenvolvido por: Ruan Federle FormulaHacking.com 58


Google Hacking Fórmula Hacking
________________________________________________
sitio/item.php?idcd=
index.php?site=
de/content.php?page_id=
gallerysort.php?iid=
products.php?type=
event.php?id=
showfeature.php?id=
home.php?ID=
tas/event.php?id=
profile.php?id=
details.php?id=
past-event.php?id=
index.php?action=
site/products.php?prodid=
page.php?pId=
resources/vulnerabilities_list.php?id=
site.php?id=
products/index.php?rangeid=
global_projects.php?cid=
publications/view.php?id=
display_page.php?id=
pages.php?ID=
lmsrecords_cd.php?cdid=
product.php?prd=
cat/?catid=
products/product-list.php?id=
debate-detail.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 59


Google Hacking Fórmula Hacking
________________________________________________
cbmer/congres/page.php?LAN=
content.php?id=
news.php?ID=
photogallery.php?id=
index.php?id=
product/product.php?product_no=
nyheder.htm?show=
book.php?ID=
print.php?id=
detail.php?id=
book.php?id=
content.php?PID=
more_detail.php?id=
content.php?id=
view_items.php?id=
view_author.php?id=
main.php?id=
english/fonction/print.php?id=
magazines/adult_magazine_single_page.php?magid=
product_details.php?prodid=
magazines/adult_magazine_full_year.php?magid=
products/card.php?prodID=
catalog/product.php?cat_id=
e_board/modifyform.html?code=
community/calendar-event-fr.php?id=
products.php?p=
news.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 60


Google Hacking Fórmula Hacking
________________________________________________
view/7/9628/1.html?reply=
product_details.php?prodid=
catalog/product.php?pid=
rating.php?id=
?page=
catalog/main.php?cat_id=
index.php?page=
detail.php?prodid=
products/product.php?pid=
news.php?id=
book_detail.php?BookID=
catalog/main.php?cat_id=
catalog/main.php?cat_id=
default.php?cPath=
catalog/main.php?cat_id=
catalog/main.php?cat_id=
category.php?catid=
categories.php?cat=
categories.php?cat=
detail.php?prodID=
detail.php?id=
category.php?id=
hm/inside.php?id=
index.php?area_id=
gallery.php?id=
products.php?cat=
products.php?cat=

Desenvolvido por: Ruan Federle FormulaHacking.com 61


Google Hacking Fórmula Hacking
________________________________________________
media/pr.php?id=
books/book.php?proj_nr=
products/card.php?prodID=
general.php?id=
news.php?t=
usb/devices/showdev.php?id=
content/detail.php?id=
templet.php?acticle_id=
news/news/title_show.php?id=
product.php?id=
index.php?url=
cryolab/content.php?cid=
ls.php?id=
s.php?w=
abroad/page.php?cid=
bayer/dtnews.php?id=
news/temp.php?id=
index.php?url=
book/bookcover.php?bookid=
index.php/en/component/pvm/?view=
product/list.php?pid=
cats.php?cat=
software_categories.php?cat_id=
print.php?sid=
docDetail.aspx?chnum=
index.php?section=
index.php?page=

Desenvolvido por: Ruan Federle FormulaHacking.com 62


Google Hacking Fórmula Hacking
________________________________________________
index.php?page=
en/publications.php?id=
events/detail.php?ID=
forum/profile.php?id=
media/pr.php?id=
content.php?ID=
cloudbank/detail.php?ID=
pages.php?id=
news.php?id=
beitrag_D.php?id=
content/index.php?id=
index.php?i=
?action=
index.php?page=
beitrag_F.php?id=
index.php?pageid=
page.php?modul=
detail.php?id=
index.php?w=
index.php?modus=
news.php?id=
news.php?id=
aktuelles/meldungen-detail.php?id=
item.php?id=
obio/detail.php?id=
page/de/produkte/produkte.php?prodID=
packages_display.php?ref=

Desenvolvido por: Ruan Federle FormulaHacking.com 63


Google Hacking Fórmula Hacking
________________________________________________
shop/index.php?cPath=
modules.php?bookid=
product-range.php?rangeID=
en/news/fullnews.php?newsid=
deal_coupon.php?cat_id=
show.php?id=
blog/index.php?idBlog=
redaktion/whiteteeth/detail.php?nr=
HistoryStore/pages/item.php?itemID=
aktuelles/veranstaltungen/detail.php?id=
tecdaten/showdetail.php?prodid=
?id=
rating/stat.php?id=
content.php?id=
viewapp.php?id=
item.php?id=
news/newsitem.php?newsID=
FernandFaerie/index.php?c=
show.php?id=
?cat=
categories.php?cat=
category.php?c=
product_info.php?id=
prod.php?cat=
store/product.php?productid=
browsepr.php?pr=
product-list.php?cid=

Desenvolvido por: Ruan Federle FormulaHacking.com 64


Google Hacking Fórmula Hacking
________________________________________________
products.php?cat_id=
product.php?ItemID=
category.php?c=
main.php?id=
article.php?id=
showproduct.php?productId=
view_item.php?item=
skunkworks/content.php?id=
index.php?id=
item_show.php?id=
publications.php?Id=
index.php?t=
view_items.php?id=
portafolio/portafolio.php?id=
YZboard/view.php?id=
index_en.php?ref=
index_en.php?ref=
category.php?id_category=
main.php?id=
main.php?id=
calendar/event.php?id=
default.php?cPath=
pages/print.php?id=
index.php?pg_t=
_news/news.php?id=
forum/showProfile.php?id=
fr/commande-liste-categorie.php?panier=

Desenvolvido por: Ruan Federle FormulaHacking.com 65


Google Hacking Fórmula Hacking
________________________________________________
downloads/shambler.php?id=
sinformer/n/imprimer.php?id=
More_Details.php?id=
directory/contenu.php?id_cat=
properties.php?id_cat=
forum/showProfile.php?id=
downloads/category.php?c=
index.php?cat=
product_info.php?products_id=
product_info.php?products_id=
product-list.php?category_id=
detail.php?siteid=
projects/event.php?id=
view_items.php?id=
more_details.php?id=
melbourne_details.php?id=
more_details.php?id=
detail.php?id=
more_details.php?id=
home.php?cat=
idlechat/message.php?id=
detail.php?id=
print.php?sid=
more_details.php?id=
default.php?cPath=
events/event.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 66


Google Hacking Fórmula Hacking
________________________________________________
brand.php?id=
toynbeestudios/content.php?id=
show-book.php?id=
more_details.php?id=
store/default.php?cPath=
property.php?id=
product_details.php?id=
more_details.php?id=
view-event.php?id=
content.php?id=
book.php?id=
page/venue.php?id=
print.php?sid=
colourpointeducational/more_details.php?id=
print.php?sid=
browse/book.php?journalID=
section.php?section=
bookDetails.php?id=
profiles/profile.php?profileid=
event.php?id=
gallery.php?id=
category.php?CID=
corporate/newsreleases_more.php?id=
print.php?id=
view_items.php?id=
more_details.php?id=
county-facts/diary/vcsgen.php?id=
idlechat/message.php?id=
podcast/item.php?pid=
products.php?act=
details.php?prodId=
socsci/events/full_details.php?id=
ourblog.php?categoryid=
mall/more.php?ProdID=
archive/get.php?message_id=

Desenvolvido por: Ruan Federle FormulaHacking.com 67


Google Hacking Fórmula Hacking
________________________________________________
review/review_form.php?item_id=
english/publicproducts.php?groupid=
news_and_notices.php?news_id=
rounds-detail.php?id=
gig.php?id=
board/view.php?no=
index.php?modus=
news_item.php?id=
rss.php?cat=
products/product.php?id=
details.php?ProdID=
els_/product/product.php?id=
store/description.php?iddesc=
socsci/news_items/full_story.php?id=
modules/forum/index.php?topic_id=
feature.php?id=
products/Blitzball.htm?id=
profile_print.php?id=
questions.php?questionid=
html/scoutnew.php?prodid=
main/index.php?action=
********.php?cid=
********.php?cid=
news.php?type=
index.php?page=
viewthread.php?tid=
summary.php?PID=
news/latest_news.php?cat_id=
index.php?cPath=
category.php?CID=
index.php?pid=
more_details.php?id=
specials.php?osCsid=
search/display.php?BookID=
articles.php?id=
print.php?sid=

Desenvolvido por: Ruan Federle FormulaHacking.com 68


Google Hacking Fórmula Hacking
________________________________________________
page.php?id=
more_details.php?id=
newsite/pdf_show.php?id=
shop/category.php?cat_id=
shopcafe-shop-product.php?bookId=
shop/books_detail.php?bookID=
index.php?cPath=
more_details.php?id=
news.php?id=
more_details.php?id=
shop/books_detail.php?bookID=
more_details.php?id=
blog.php?blog=
index.php?pid=
prodotti.php?id_cat=
category.php?CID=
more_details.php?id=
poem_list.php?bookID=
more_details.php?id=
content.php?categoryId=
authorDetails.php?bookID=
press_release.php?id=
item_list.php?cat_id=
colourpointeducational/more_details.php?id=
index.php?pid=
download.php?id=
shop/category.php?cat_id=
i-know/content.php?page=
store/index.php?cat_id=
yacht_search/yacht_view.php?pid=
pharmaxim/category.php?cid=
print.php?sid=
specials.php?osCsid=
store.php?cat_id=
category.php?cid=
displayrange.php?rangeid=

Desenvolvido por: Ruan Federle FormulaHacking.com 69


Google Hacking Fórmula Hacking
________________________________________________
product.php?id=
csc/news-details.php?cat=
products-display-details.php?prodid=
stockists_list.php?area_id=
news/newsitem.php?newsID=
index.php?pid=
newsitem.php?newsid=
category.php?id=
news/newsitem.php?newsID=
details.php?prodId=
publications/publication.php?id=
purelydiamond/products/category.php?cat=
category.php?cid=
product/detail.php?id=
news/newsitem.php?newsID=
details.php?prodID=
item.php?item_id=
edition.php?area_id=
page.php?area_id=
view_newsletter.php?id=
library.php?cat=
categories.php?cat=
page.php?area_id=
categories.php?cat=
publications.php?id=
item.php?sub_id=
page.php?area_id=
page.php?area_id=
category.php?catid=
content.php?cID=
newsitem.php?newsid=
frontend/category.php?id_category=
news/newsitem.php?newsID=
things-to-do/detail.php?id=
page.php?area_id=
page.php?area_id=

Desenvolvido por: Ruan Federle FormulaHacking.com 70


Google Hacking Fórmula Hacking
________________________________________________
listing.php?cat=
item.php?iid=
customer/home.php?cat=
staff/publications.php?sn=
news/newsitem.php?newsID=
library.php?cat=
main/index.php?uid=
library.php?cat=
shop/eventshop/product_detail.php?itemid=
news/newsitem.php?newsID=
news/newsitem.php?newsID=
library.php?cat=
FullStory.php?Id=
publications.php?ID=
publications/book_reviews/full_review.php?id=
newsitem.php?newsID=
newsItem.php?newsId=
site/en/list_service.php?cat=
page.php?area_id=
product.php?ProductID=
releases_headlines_details.php?id=
product.php?shopprodid=
product.php?productid=
product.php?product=
product.php?product_id=
productlist.php?id=
product.php?shopprodid=
garden_equipment/pest-weed-control/product.php?pr=
product.php?shopprodid=
browsepr.php?pr=
productlist.php?id=
kshop/product.php?productid=
product.php?pid=
showproduct.php?prodid=
product.php?productid=
productlist.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 71


Google Hacking Fórmula Hacking
________________________________________________
index.php?pageId=
productlist.php?tid=
product-list.php?id=
onlinesales/product.php?product_id=
garden_equipment/Fruit-Cage/product.php?pr=
product.php?shopprodid=
product_info.php?products_id=
productlist.php?tid=
showsub.php?id=
productlist.php?fid=
products.php?cat=
products.php?cat=
product-list.php?id=
product.php?sku=
store/product.php?productid=
products.php?cat=
productList.php?cat=
product_detail.php?product_id=
product.php?pid=
wiki/pmwiki.php?page****=
summary.php?PID=
productlist.php?grpid=
cart/product.php?productid=
db/CART/product_details.php?product_id=
ProductList.php?id=
products/product.php?id=
product.php?shopprodid=
product_info.php?products_id=
product_ranges_view.php?ID=
cei/cedb/projdetail.php?projID=
products.php?DepartmentID=
product.php?shopprodid=
product.php?shopprodid=
product_info.php?products_id=
index.php?news=
education/content.php?page=

Desenvolvido por: Ruan Federle FormulaHacking.com 72


Google Hacking Fórmula Hacking
________________________________________________
Interior/productlist.php?id=
products.php?categoryID=
modules.php?****=
message/comment_threads.php?postID=
artist_art.php?id=
products.php?cat=
index.php?option=
ov_tv.php?item=
index.php?lang=
showproduct.php?cat=
index.php?lang=
product.php?bid=
product.php?bid=
cps/rde/xchg/tm/hs.xsl/liens_detail.html?lnkId=
item_show.php?lid=
?pagerequested=
downloads.php?id=
print.php?sid=
print.php?sid=
product.php?intProductID=
productList.php?id=
product.php?intProductID=
more_details.php?id=
more_details.php?id=
books.php?id=
index.php?offs=
mboard/replies.php?parent_id=
Computer Science.php?id=
news.php?id=
pdf_post.php?ID=
reviews.php?id=
art.php?id=
prod.php?cat=
event_info.php?p=
view_items.php?id=
home.php?cat=

Desenvolvido por: Ruan Federle FormulaHacking.com 73


Google Hacking Fórmula Hacking
________________________________________________
item_book.php?CAT=
www/index.php?page=
schule/termine.php?view=
goods_detail.php?data=
storemanager/contents/item.php?page_code=
view_items.php?id=
customer/board.htm?mode=
help/com_view.html?code=
n_replyboard.php?typeboard=
eng_board/view.php?T****=
prev_results.php?prodID=
bbs/view.php?no=
gnu/?doc=
zb/view.php?uid=
global/product/product.php?gubun=
m_view.php?ps_db=
naboard/memo.php?bd=
bookmark/mybook/bookmark.php?bookPageNo=
board/board.html?table=
kboard/kboard.php?board=
order.asp?lotid=
english/board/view****.php?code=
goboard/front/board_view.php?code=
bbs/bbsView.php?id=
boardView.php?bbs=
eng/rgboard/view.php?&bbs_id=
product/product.php?cate=
content.php?p=
page.php?module=
?pid=
bookpage.php?id=
view_items.php?id=
index.php?pagina=
product.php?prodid=
notify/notify_form.php?topic_id=
php/index.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 74


Google Hacking Fórmula Hacking
________________________________________________
content.php?cid=
product.php?product_id=
constructies/product.php?id=
detail.php?id=
php/index.php?id=
index.php?section=
product.php?****=
show_bug.cgi?id=
detail.php?id=
bookpage.php?id=
product.php?id=
today.php?eventid=
main.php?item=
index.php?cPath=
news.php?id=
event.php?id=
print.php?sid=
news/news.php?id=
module/range/dutch_windmill_collection.php?rangeId=
print.php?sid=
show_bug.cgi?id=
product_details.php?product_id=
products.php?groupid=
projdetails.php?id=
product.php?productid=
products.php?catid=
product.php?product_id=
product.php?prodid=
product.php?prodid=
newsitem.php?newsID=
newsitem.php?newsid=
profile.php?id=
********s_in_area.php?area_id=
productlist.php?id=
productsview.php?proid=
rss.php?cat=

Desenvolvido por: Ruan Federle FormulaHacking.com 75


Google Hacking Fórmula Hacking
________________________________________________
pub/pds/pds_view.php?start=
products.php?rub=
ogloszenia/rss.php?cat=
print.php?sid=
product.php?id=
print.php?sid=
magazin.php?cid=
galerie.php?cid=
www/index.php?page=
view.php?id=
content.php?id=
board/read.php?tid=
product.php?id_h=
news.php?id=
index.php?book=
products.php?act=
reply.php?id=
stat.php?id=
products.php?cat_id=
free_board/board_view.html?page=
item.php?id=
view_items.php?id=
main.php?prodID=
gb/comment.php?gb_id=
gb/comment.php?gb_id=
classifieds/showproduct.php?product=
view.php?pageNum_rscomp=
cart/addToCart.php?cid=
content/pages/index.php?id_cat=
content.php?id
display.php?ID=
display.php?ID=
ponuky/item_show.php?ID=
default.php?cPath=
main/magpreview.php?id=
***zine/board.php?board=

Desenvolvido por: Ruan Federle FormulaHacking.com 76


Google Hacking Fórmula Hacking
________________________________________________
content.php?arti_id=
mall/more.php?ProdID=
product.php?cat=
news.php?id=
content/view.php?id=
content.php?id=
index.php?action=
board_view.php?s_board_id=
KM/BOARD/readboard.php?id=
board_view.html?id=
content.php?cont_title=
category.php?catid=
mall/more.php?ProdID=
publications.php?id=
irbeautina/product_detail.php?product_id=
print.php?sid=
index_en.php?id=
bid/topic.php?TopicID=
news_content.php?CategoryID=
front/bin/forumview.phtml?bbcode=
cat.php?cat_id=
stat.php?id=
veranstaltungen/detail.php?id=
more_details.php?id=
english/print.php?id=
print.php?id=
view_item.php?id=
content/conference_register.php?ID=
rss/event.php?id=
event.php?id=
main.php?id=
rtfe.php?siteid=
category.php?cid=
classifieds/detail.php?siteid=
tools/print.php?id=
channel/channel-layout.php?objId=

Desenvolvido por: Ruan Federle FormulaHacking.com 77


Google Hacking Fórmula Hacking
________________________________________________
content.php?id=
resources/detail.php?id=
more_details.php?id=
detail.php?id=
view_items.php?id=
content/programme.php?ID=
book.php?id=
php/fid985C124FBD9EF3A29BA8F40521F12D097B0E2016.aspx?s=
detail.php?id=
default.php?cPath=
more_details.php?id=
php/fid8E1BED06B1301BAE3ED64383D5F619E3B1997A70.aspx?s=
content.php?id=
view_items.php?id=
default.php?cPath=
book.php?id=
view_items.php?id=
products/parts/detail.php?id=
category.php?cid=
book.html?isbn=
view_item.php?id=
picgallery/category.php?cid=
detail.php?id=
print.php?sid=
displayArticleB.php?id=
knowledge_base/detail.php?id=
bpac/calendar/event.php?id=
mb_showtopic.php?topic_id=
pages.php?id=
content.php?id=
exhibition_overview.php?id=
singer/detail.php?siteid=
Category.php?cid=
detail.php?id=
print.php?sid=
category.php?cid=

Desenvolvido por: Ruan Federle FormulaHacking.com 78


Google Hacking Fórmula Hacking
________________________________________________
more_detail.php?X_EID=
book.php?ISBN=
view_items.php?id=
category.php?cid=
htmlpage.php?id=
story.php?id=
tools/print.php?id=
print.php?sid=
php/event.php?id=
print.php?sid=
articlecategory.php?id=
print.php?sid=
ibp.php?ISBN=
club.php?cid=
view_items.php?id=
aboutchiangmai/details.php?id=
view_items.php?id=
book.php?isbn=
blog_detail.php?id=
event.php?id=
default.php?cPath=
product_info.php?products_id=
shop_display_products.php?cat_id=
print.php?sid=
modules/content/index.php?id=
printcards.php?ID=
events/event.php?ID=
more_details.php?id=
default.php?TID=
general.php?id=
detail.php?id=
event.php?id=
referral/detail.php?siteid=
view_items.php?id=
event.php?id=
view_items.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 79


Google Hacking Fórmula Hacking
________________________________________________
category.php?id=
cemetery.php?id=
index.php?cid=
content.php?id=
exhibitions/detail.php?id=
bookview.php?id=
edatabase/home.php?cat=
view_items.php?id=
store/view_items.php?id=
print.php?sid=
events/event_detail.php?id=
view_items.php?id=
detail.php?id=
pages/video.php?id=
about_us.php?id=
recipe/category.php?cid=
view_item.php?id=
en/main.php?id=
print.php?sid=
More_Details.php?id=
category.php?cid=
home.php?cat=
article.php?id=
page.php?id=
print-story.php?id=
psychology/people/detail.php?id=
print.php?sid=
print.php?ID=
article_preview.php?id=
Pages/whichArticle.php?id=
view_items.php?id=
Sales/view_item.php?id=
book.php?isbn=
knowledge_base/detail.php?id=
gallery/gallery.php?id=
event.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 80


Google Hacking Fórmula Hacking
________________________________________________
detail.php?id=
store/home.php?cat=
view_items.php?id=
detail.php?ID=
event_details.php?id=
detailedbook.php?isbn=
fatcat/home.php?view=
events/index.php?id=
static.php?id=
answer/default.php?pollID=
news/detail.php?id=
view_items.php?id=
events/unique_event.php?ID=
gallery/detail.php?ID=
print.php?sid=
view_items.php?id=
board/showthread.php?t=
book.php?id=
event.php?id=
more_detail.php?id=
knowledge_base/detail.php?id=
html/print.php?sid=
index.php?id=
content.php?ID=
Shop/home.php?cat=
store/home.php?cat=
print.php?sid=
gallery.php?id=
resources/index.php?cat=
events/event.php?id=
view_items.php?id=
default.php?cPath=
content.php?id=
products/products.php?p=
auction/item.php?id=
products.php?cat=

Desenvolvido por: Ruan Federle FormulaHacking.com 81


Google Hacking Fórmula Hacking
________________________________________________
clan_page.php?cid=
product.php?sku=
item.php?id=
events?id=
comments.php?id=
products/?catID=
modules.php?****=
fshstatistic/index.php?PID=
products/products.php?p=
sport.php?revista=
products.php?p=
products.php?openparent=
home.php?cat=
news/shownewsarticle.php?articleid=
discussions/10/9/?CategoryID=
trailer.php?id=
news.php?id=
?page=
index.php?page=
item/detail.php?num=
features/view.php?id=
site/?details&prodid=
product_info.php?products_id=
remixer.php?id=
proddetails_print.php?prodid=
pylones/item.php?item=
index.php?cont=
product.php?ItemId=
video.php?id=
detail.php?item_id=
filemanager.php?delete=
news/newsletter.php?id=
shop/home.php?cat=
designcenter/item.php?id=
board/kboard.php?board=
index.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 82


Google Hacking Fórmula Hacking
________________________________________________
board/view_temp.php?table=
magazine-details.php?magid=
site:.pk intext:Warning: mysql_free_result(): supplied argument is not a valid
MySQL result resource in & “id”
site:.pk intext:Warning: mysql_fetch_array(): supplied argument is not a valid
MySQL result resource in & “id”
about.php?cartID=
accinfo.php?cartId=
acclogin.php?cartID=
add.php?bookid=
add_cart.php?num=
addcart.php?
addItem.php
add-to-cart.php?ID=
addToCart.php?idProduct=
addtomylist.php?ProdId=
adminEditProductFields.php?intProdID=
advSearch_h.php?idCategory=
affiliate.php?ID=
affiliate-agreement.cfm?storeid=
affiliates.php?id=
ancillary.php?ID=
archive.php?id=
article.php?id=
phpx?PageID
basket.php?id=
Book.php?bookID=
book_list.php?bookid=
book_view.php?bookid=
BookDetails.php?ID=
browse.php?catid=
browse_item_details.php
Browse_Item_Details.php?Store_Id=
buy.php?
buy.php?bookid=
bycategory.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 83


Google Hacking Fórmula Hacking
________________________________________________
cardinfo.php?card=
cart.php?action=
cart.php?cart_id=
cart.php?id=
cart_additem.php?id=
cart_validate.php?id=
cartadd.php?id=
cat.php?iCat=
catalog.php
catalog.php?CatalogID=
catalog_item.php?ID=
catalog_main.php?catid=
category.php
category.php?catid=
category_list.php?id=
categorydisplay.php?catid=
checkout.php?cartid=
checkout.php?UserID=
checkout_confirmed.php?order_id=
checkout1.php?cartid=
comersus_listCategoriesAndProducts.php?idCategory=
comersus_optEmailToFriendForm.php?idProduct=
comersus_optReviewReadExec.php?idProduct=
comersus_viewItem.php?idProduct=
comments_form.php?ID=
contact.php?cartId=
content.php?id=
customerService.php?****ID1=
default.php?catID=
description.php?bookid=
details.php?BookID=
details.php?Press_Release_ID=
details.php?Product_ID=
details.php?Service_ID=
display_item.php?id=
displayproducts.php

Desenvolvido por: Ruan Federle FormulaHacking.com 84


Google Hacking Fórmula Hacking
________________________________________________
downloadTrial.php?intProdID=
emailproduct.php?itemid=
emailToFriend.php?idProduct=
events.php?ID=
faq.php?cartID=
faq_list.php?id=
faqs.php?id=
feedback.php?title=
freedownload.php?bookid=
fullDisplay.php?item=
getbook.php?bookid=
GetItems.php?itemid=
giftDetail.php?id=
help.php?CartId=
home.php?id=
index.php?cart=
index.php?cartID=
index.php?ID=
info.php?ID=
item.php?eid=
item.php?item_id=
item.php?itemid=
item.php?model=
item.php?prodtype=
item.php?shopcd=
item_details.php?catid=
item_list.php?maingroup
item_show.php?code_no=
itemDesc.php?CartId=
itemdetail.php?item=
itemdetails.php?catalogid=
learnmore.php?cartID=
links.php?catid=
list.php?bookid=
List.php?CatID=
listcategoriesandproducts.php?idCategory=

Desenvolvido por: Ruan Federle FormulaHacking.com 85


Google Hacking Fórmula Hacking
________________________________________________
modline.php?id=
myaccount.php?catid=
news.php?id=
order.php?BookID=
order.php?id=
order.php?item_ID=
OrderForm.php?Cart=
page.php?PartID=
payment.php?CartID=
pdetail.php?item_id=
powersearch.php?CartId=
price.php
privacy.php?cartID=
prodbycat.php?intCatalogID=
prodetails.php?prodid=
prodlist.php?catid=
product.php?bookID=
product.php?intProdID=
product_info.php?item_id=
productDetails.php?idProduct=
productDisplay.php
productinfo.php?item=
productlist.php?ViewType=Category&CategoryID=
productpage.php
products.php?ID=
products.php?keyword=
products_category.php?CategoryID=
products_detail.php?CategoryID=
productsByCategory.php?intCatalogID=
prodView.php?idProduct=
promo.php?id=
promotion.php?catid=
pview.php?Item=
resellers.php?idCategory=
results.php?cat=
savecart.php?CartId=

Desenvolvido por: Ruan Federle FormulaHacking.com 86


Google Hacking Fórmula Hacking
________________________________________________
search.php?CartID=
searchcat.php?search_id=
Select_Item.php?id=
Services.php?ID=
shippinginfo.php?CartId=
shop.php?a=
shop.php?action=
shop.php?bookid=
shop.php?cartID=
shop_details.php?prodid=
shopaddtocart.php
shopaddtocart.php?catalogid=
shopbasket.php?bookid=
shopbycategory.php?catid=
shopcart.php?title=
shopcreatorder.php
shopcurrency.php?cid=
shopdc.php?bookid=
shopdisplaycategories.php
shopdisplayproduct.php?catalogid=
shopdisplayproducts.php
shopexd.php
shopexd.php?catalogid=
shopping_basket.php?cartID=
shopprojectlogin.php
shopquery.php?catalogid=
shopremoveitem.php?cartid=
shopreviewadd.php?id=
shopreviewlist.php?id=
ShopSearch.php?CategoryID=
shoptellafriend.php?id=
shopthanks.php
shopwelcome.php?title=
show_item.php?id=
show_item_details.php?item_id=
showbook.php?bookid=

Desenvolvido por: Ruan Federle FormulaHacking.com 87


Google Hacking Fórmula Hacking
________________________________________________
showStore.php?catID=
shprodde.php?SKU=
specials.php?id=
store.php?id=
store_bycat.php?id=
store_listing.php?id=
Store_ViewProducts.php?Cat=
store-details.php?id=
storefront.php?id=
storefronts.php?title=
storeitem.php?item=
StoreRedirect.php?ID=
subcategories.php?id=
tek9.php?
template.php?Action=Item&pid=
topic.php?ID=
tuangou.php?bookid=
type.php?iType=
updatebasket.php?bookid=
updates.php?ID=
view.php?cid=
view_cart.php?title=
view_detail.php?ID=
viewcart.php?CartId=
viewCart.php?userID=
viewCat_h.php?idCategory=
viewevent.php?EventID=
viewitem.php?recor=
viewPrd.php?idcategory=
ViewProduct.php?misc=
voteList.php?item_ID=
whatsnew.php?idCategory=
WsAncillary.php?ID=
WsPages.php?ID=noticiasDetalle.php?xid=
sitio/item.php?idcd=
index.php?site=

Desenvolvido por: Ruan Federle FormulaHacking.com 88


Google Hacking Fórmula Hacking
________________________________________________
de/content.php?page_id=
gallerysort.php?iid=
products.php?type=
event.php?id=
showfeature.php?id=
home.php?ID=
tas/event.php?id=
profile.php?id=
details.php?id=
past-event.php?id=
index.php?action=
site/products.php?prodid=
page.php?pId=
resources/vulnerabilities_list.php?id=
site.php?id=
products/index.php?rangeid=
global_projects.php?cid=
publications/view.php?id=
display_page.php?id=
pages.php?ID=
lmsrecords_cd.php?cdid=
product.php?prd=
cat/?catid=
products/product-list.php?id=
debate-detail.php?id=
cbmer/congres/page.php?LAN=
content.php?id=
news.php?ID=
photogallery.php?id=
index.php?id=
product/product.php?product_no=
nyheder.htm?show=
book.php?ID=
print.php?id=
detail.php?id=
book.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 89


Google Hacking Fórmula Hacking
________________________________________________
content.php?PID=
more_detail.php?id=
content.php?id=
view_items.php?id=
view_author.php?id=
main.php?id=
english/fonction/print.php?id=
magazines/adult_magazine_single_page.php?magid=
product_details.php?prodid=
magazines/adult_magazine_full_year.php?magid=
products/card.php?prodID=
catalog/product.php?cat_id=
e_board/modifyform.html?code=
community/calendar-event-fr.php?id=
products.php?p=
news.php?id=
view/7/9628/1.html?reply=
product_details.php?prodid=
catalog/product.php?pid=
rating.php?id=
?page=
catalog/main.php?cat_id=
index.php?page=
detail.php?prodid=
products/product.php?pid=
news.php?id=
book_detail.php?BookID=
catalog/main.php?cat_id=
catalog/main.php?cat_id=
default.php?cPath=
catalog/main.php?cat_id=
catalog/main.php?cat_id=
category.php?catid=
categories.php?cat=
categories.php?cat=
detail.php?prodID=

Desenvolvido por: Ruan Federle FormulaHacking.com 90


Google Hacking Fórmula Hacking
________________________________________________
detail.php?id=
category.php?id=
hm/inside.php?id=
index.php?area_id=
gallery.php?id=
products.php?cat=
products.php?cat=
media/pr.php?id=
books/book.php?proj_nr=
products/card.php?prodID=
general.php?id=
news.php?t=
usb/devices/showdev.php?id=
content/detail.php?id=
templet.php?acticle_id=
news/news/title_show.php?id=
product.php?id=
index.php?url=
cryolab/content.php?cid=
ls.php?id=
s.php?w=
abroad/page.php?cid=
bayer/dtnews.php?id=
news/temp.php?id=
index.php?url=
book/bookcover.php?bookid=
index.php/en/component/pvm/?view=
product/list.php?pid=
cats.php?cat=
software_categories.php?cat_id=
print.php?sid=
docDetail.aspx?chnum=
index.php?section=
index.php?page=
index.php?page=
en/publications.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 91


Google Hacking Fórmula Hacking
________________________________________________
events/detail.php?ID=
forum/profile.php?id=
media/pr.php?id=
content.php?ID=
cloudbank/detail.php?ID=
pages.php?id=
news.php?id=
beitrag_D.php?id=
content/index.php?id=
index.php?i=
?action=
index.php?page=
beitrag_F.php?id=
index.php?pageid=
page.php?modul=
detail.php?id=
index.php?w=
index.php?modus=
news.php?id=
news.php?id=
aktuelles/meldungen-detail.php?id=
item.php?id=
obio/detail.php?id=
page/de/produkte/produkte.php?prodID=
packages_display.php?ref=
shop/index.php?cPath=
modules.php?bookid=
product-range.php?rangeID=
en/news/fullnews.php?newsid=
deal_coupon.php?cat_id=
show.php?id=
blog/index.php?idBlog=
redaktion/whiteteeth/detail.php?nr=
HistoryStore/pages/item.php?itemID=
aktuelles/veranstaltungen/detail.php?id=
tecdaten/showdetail.php?prodid=

Desenvolvido por: Ruan Federle FormulaHacking.com 92


Google Hacking Fórmula Hacking
________________________________________________
?id=
rating/stat.php?id=
content.php?id=
viewapp.php?id=
item.php?id=
news/newsitem.php?newsID=
FernandFaerie/index.php?c=
show.php?id=
?cat=
categories.php?cat=
category.php?c=
product_info.php?id=
prod.php?cat=
store/product.php?productid=
browsepr.php?pr=
product-list.php?cid=
products.php?cat_id=
product.php?ItemID=
category.php?c=
main.php?id=
article.php?id=
showproduct.php?productId=
view_item.php?item=
skunkworks/content.php?id=
index.php?id=
item_show.php?id=
publications.php?Id=
index.php?t=
view_items.php?id=
portafolio/portafolio.php?id=
YZboard/view.php?id=
index_en.php?ref=
index_en.php?ref=
category.php?id_category=
main.php?id=
main.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 93


Google Hacking Fórmula Hacking
________________________________________________
calendar/event.php?id=
default.php?cPath=
pages/print.php?id=
index.php?pg_t=
_news/news.php?id=
forum/showProfile.php?id=
fr/commande-liste-categorie.php?panier=
downloads/shambler.php?id=
sinformer/n/imprimer.php?id=
More_Details.php?id=
directory/contenu.php?id_cat=
properties.php?id_cat=
forum/showProfile.php?id=
downloads/category.php?c=
index.php?cat=
product_info.php?products_id=
product_info.php?products_id=
product-list.php?category_id=
detail.php?siteid=
projects/event.php?id=
view_items.php?id=
more_details.php?id=
melbourne_details.php?id=
more_details.php?id=
detail.php?id=
more_details.php?id=
home.php?cat=
idlechat/message.php?id=
detail.php?id=
print.php?sid=
more_details.php?id=
default.php?cPath=
events/event.php?id=
brand.php?id=
toynbeestudios/content.php?id=
show-book.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 94


Google Hacking Fórmula Hacking
________________________________________________
more_details.php?id=
store/default.php?cPath=
property.php?id=
product_details.php?id=
more_details.php?id=
view-event.php?id=
content.php?id=
book.php?id=
page/venue.php?id=
print.php?sid=
colourpointeducational/more_details.php?id=
print.php?sid=
browse/book.php?journalID=
section.php?section=
bookDetails.php?id=
profiles/profile.php?profileid=
event.php?id=
gallery.php?id=
category.php?CID=
corporate/newsreleases_more.php?id=
print.php?id=
view_items.php?id=
more_details.php?id=
county-facts/diary/vcsgen.php?id=
idlechat/message.php?id=
podcast/item.php?pid=
products.php?act=
details.php?prodId=
socsci/events/full_details.php?id=
ourblog.php?categoryid=
mall/more.php?ProdID=
archive/get.php?message_id=
review/review_form.php?item_id=
english/publicproducts.php?groupid=
news_and_notices.php?news_id=
rounds-detail.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 95


Google Hacking Fórmula Hacking
________________________________________________
gig.php?id=
board/view.php?no=
index.php?modus=
news_item.php?id=
rss.php?cat=
products/product.php?id=
details.php?ProdID=
els_/product/product.php?id=
store/description.php?iddesc=
socsci/news_items/full_story.php?id=
modules/forum/index.php?topic_id=
feature.php?id=
products/Blitzball.htm?id=
profile_print.php?id=
questions.php?questionid=
html/scoutnew.php?prodid=
main/index.php?action=
********.php?cid=
********.php?cid=
news.php?type=
index.php?page=
viewthread.php?tid=
summary.php?PID=
news/latest_news.php?cat_id=
index.php?cPath=
category.php?CID=
index.php?pid=
more_details.php?id=
specials.php?osCsid=
search/display.php?BookID=
articles.php?id=
print.php?sid=
page.php?id=
more_details.php?id=
newsite/pdf_show.php?id=
shop/category.php?cat_id=

Desenvolvido por: Ruan Federle FormulaHacking.com 96


Google Hacking Fórmula Hacking
________________________________________________
shopcafe-shop-product.php?bookId=
shop/books_detail.php?bookID=
index.php?cPath=
more_details.php?id=
news.php?id=
more_details.php?id=
shop/books_detail.php?bookID=
more_details.php?id=
blog.php?blog=
index.php?pid=
prodotti.php?id_cat=
category.php?CID=
more_details.php?id=
poem_list.php?bookID=
more_details.php?id=
content.php?categoryId=
authorDetails.php?bookID=
press_release.php?id=
item_list.php?cat_id=
colourpointeducational/more_details.php?id=
index.php?pid=
download.php?id=
shop/category.php?cat_id=
i-know/content.php?page=
store/index.php?cat_id=
product.php?pid=
showproduct.php?prodid=
product.php?productid=
productlist.php?id=
index.php?pageId=
productlist.php?tid=
product-list.php?id=
onlinesales/product.php?product_id=
garden_equipment/Fruit-Cage/product.php?pr=
product.php?shopprodid=
product_info.php?products_id=

Desenvolvido por: Ruan Federle FormulaHacking.com 97


Google Hacking Fórmula Hacking
________________________________________________
productlist.php?tid=
showsub.php?id=
productlist.php?fid=
products.php?cat=
products.php?cat=
product-list.php?id=
product.php?sku=
store/product.php?productid=
products.php?cat=
productList.php?cat=
product_detail.php?product_id=
product.php?pid=
wiki/pmwiki.php?page****=
summary.php?PID=
productlist.php?grpid=
cart/product.php?productid=
db/CART/product_details.php?product_id=
ProductList.php?id=
products/product.php?id=
product.php?shopprodid=
product_info.php?products_id=
product_ranges_view.php?ID=
cei/cedb/projdetail.php?projID=
products.php?DepartmentID=
product.php?shopprodid=
product.php?shopprodid=
product_info.php?products_id=
index.php?news=
education/content.php?page=
Interior/productlist.php?id=
products.php?categoryID=
modules.php?****=
message/comment_threads.php?postID=
artist_art.php?id=
products.php?cat=
index.php?option=

Desenvolvido por: Ruan Federle FormulaHacking.com 98


Google Hacking Fórmula Hacking
________________________________________________
ov_tv.php?item=
index.php?lang=
showproduct.php?cat=
index.php?lang=
product.php?bid=
product.php?bid=
cps/rde/xchg/tm/hs.xsl/liens_detail.html?lnkId=
item_show.php?lid=
?pagerequested=
downloads.php?id=
print.php?sid=
print.php?sid=
product.php?intProductID=
productList.php?id=
product.php?intProductID=
more_details.php?id=
more_details.php?id=
books.php?id=
index.php?offs=
mboard/replies.php?parent_id=
Computer Science.php?id=
news.php?id=
pdf_post.php?ID=
reviews.php?id=
art.php?id=
prod.php?cat=
event_info.php?p=
view_items.php?id=
home.php?cat=
item_book.php?CAT=
www/index.php?page=
schule/termine.php?view=
goods_detail.php?data=
storemanager/contents/item.php?page_code=
view_items.php?id=
customer/board.htm?mode=

Desenvolvido por: Ruan Federle FormulaHacking.com 99


Google Hacking Fórmula Hacking
________________________________________________
help/com_view.html?code=
n_replyboard.php?typeboard=
eng_board/view.php?T****=
prev_results.php?prodID=
bbs/view.php?no=
gnu/?doc=
zb/view.php?uid=
global/product/product.php?gubun=
m_view.php?ps_db=
naboard/memo.php?bd=
bookmark/mybook/bookmark.php?bookPageNo=
board/board.html?table=
kboard/kboard.php?board=
order.asp?lotid=
english/board/view****.php?code=
goboard/front/board_view.php?code=
bbs/bbsView.php?id=
boardView.php?bbs=
eng/rgboard/view.php?&bbs_id=
product/product.php?cate=
content.php?p=
page.php?module=
?pid=
bookpage.php?id=

Desenvolvido por: Ruan Federle FormulaHacking.com 100


Google Hacking Fórmula Hacking
________________________________________________

Um projeto Fórmula Hacking!

“Para se defender é preciso aprender a atacar. O


FórmulaHacking te coloca no campo de batalha
para aprender Hacking na prática!”

Acesse: www.formulahacking.com
facebook.com/formulahacking

Desenvolvido por: Ruan Federle FormulaHacking.com 101

Você também pode gostar