-
site:[TARGET] ext:xml | ext:conf | ext:cnf | ext:reg | ext:inf | ext:rdp | ext:cfg | ext:txt | ext:ora | ext:env | ext:iniThis dork searches for configuration files on the specified target site. Configuration files often contain sensitive information such as database credentials, API keys, and server configurations.
-
site:[TARGET] ext:sql | ext:db | ext:dbf | ext:mdb | ext:sql.gz | ext:sql.gz | ext:db.gz | ext:db.gzThis dork helps to find database files on the specified target site. Database files may contain valuable data and their exposure can lead to unauthorized access or data breaches.
-
site:[TARGET] ext:bkf | ext:bkp | ext:bak | ext:old | ext:backupThis dork is useful for discovering backup files on the specified target site. Backup files are often created to store previous versions of files or data, but if they are exposed, they may contain sensitive or outdated information.
-
inurl:"/.git" [TARGET] -site:github.comThis dork searches for instances of the ".git" folder on the specified target site, excluding results from GitHub. The .git folder contains version control information and can potentially expose sensitive source code and configuration details, leading to unauthorized access or code leaks.
-
site:[TARGET] ext:doc | ext:docx | ext:odt | ext:pdf | ext:rtf | ext:sxw | ext:psw | ext:ppt | ext:pptx | ext:pps | ext:csvThis dork helps to find various document file types on the specified target site. Exposed documents may contain sensitive information such as passwords, intellectual property, or confidential data.
-
site:[TARGET] AND (intext:"sql syntax near" | intext:"syntax error has occurred" | intext:"incorrect syntax near" | intext:"unexpected end of SQL command" | intext:"Warning: mysql_connect()" | intext:"Warning: mysql_query()" | intext:"Warning: pg_connect()")This dork searches for SQL errors on the specified target site. The presence of these errors in web pages may indicate vulnerabilities that can be exploited by attackers to gain unauthorized access to databases or execute malicious SQL queries.
site:[TARGET] AND ("PHP Parse error" | "PHP Warning" | "PHP Error")site:[TARGET] "Index of" inurl:phpmyadmin
site:[TARGET] AND (inurl:signup | inurl:login | inurl:register | intitle:Signup)
site:[TARGET] AND (inurl:redir | inurl:url | inurl:redirect | inurl:return | inurl:location | inurl:next | inurl:dest | inurl:src=http | inurl:r=http)
site:[TARGET] AND (ext:action | ext:struts | ext:do)
site:[TARGET] AND (inurl:wp-content | inurl:wp-includes)site:[TARGET] inurl:wp-config.php intext:DB_PASSWORDsite:[TARGET] intitle:"Index of" wp-admin
-
site:[TARGET] AND (intitle:index.of | ext:log | ext:php intitle:phpinfo "published by the PHP Group" | inurl:shell | inurl:backdoor | inurl:wso | inurl:cmd | shadow | passwd | boot.ini | inurl:backdoor | inurl:readme | inurl:license | inurl:install | inurl:setup | inurl:config | inurl:"/phpinfo.php" | inurl:".htaccess" | ext:swf) -
site:[TARGET] AND (ext:env | ext:log | ext:sql | ext:yml | ext:pem | ext:ini | ext:logs | ext:ibd | ext:txt | ext:php.txt | ext:old | ext:key | ext:frm | ext:bak | ext:zip | ext:swp | ext:conf | ext:db | ext:config | ext:ovpn | ext:svn | ext:git | ext:cfg | ext:exs | ext:dbf | ext:mdb | ext:pem | ext:pub | ext:yaml | ext:zip | ext:asc | ext:xls | ext:xlsx")
site:[TARGET] inurl:_cpanel/forgotpwdsite:[TARGET] inurl:/proc/self/cwdsite:[TARGET] inurl:/etc/site:[TARGET] filename:constantssite:[TARGET] filename:settingssite:[TARGET] filename:databasesite:[TARGET] filename:configsite:[TARGET] filename:environmentsite:[TARGET] filename:specsite:[TARGET] filename:zhrcsite:[TARGET] filename:bashsite:[TARGET] filename:npmrcsite:[TARGET] filename:dockercfgsite:[TARGET] filename:passsite:[TARGET] filename:globalsite:[TARGET] filename:credentialssite:[TARGET] filename:connectionssite:[TARGET] filename:s3cfgsite:[TARGET] filename:wp-configsite:[TARGET] filename:htpasswdsite:[TARGET] filename:git-credentialssite:[TARGET] filename:id_dsasite:[TARGET] filename:id_rsasite:[TARGET] extension:envsite:[TARGET] extension:cfgsite:[TARGET] extension:inisite:[TARGET] language:yaml -filename:travissite:[TARGET] extension:propertiessite:[TARGET] extension:batsite:[TARGET] extension:shsite:[TARGET] extension:zshsite:[TARGET] extension:pemsite:[TARGET] extension:ppksite:[TARGET] extension:sqlsite:[TARGET] extension:jsonsite:[TARGET] extension:xmlsite:[TARGET] filename:bash_historysite:[TARGET] filename:bash_profilesite:[TARGET] filename:bashrcsite:[TARGET] filename:cshrcsite:[TARGET] filename:historysite:[TARGET] filename:netrcsite:[TARGET] filename:pgpasssite:[TARGET] filename:tugboatsite:[TARGET] filename:dhcpd.confsite:[TARGET] filename:express.confsite:[TARGET] filename:filezilla.xmlsite:[TARGET] filename:idea14.keysite:[TARGET] filename:makefilesite:[TARGET] filename:gitconfigsite:[TARGET] filename:prod.exssite:[TARGET] filename:prod.secret.exssite:[TARGET] filename:proftpdpasswdsite:[TARGET] filename:recentservers.xmlsite:[TARGET] filename:robomongo.jsonsite:[TARGET] filename:server.cfgsite:[TARGET] filename:shadowsite:[TARGET] filename:sshd_configsite:[TARGET] filename:known_hostssite:[TARGET] filename:wp-config.phpsite:[TARGET] filename:.envsite:[TARGET] filename:hubsite:[TARGET] filename:.netrcsite:[TARGET] filename:_netrcsite:[TARGET] filename:ventrilo_srv.inisite:[TARGET] filename:dbeaver-data-sources.xmlsite:[TARGET] filename:sftp-config.jsonsite:[TARGET] filename:.esmtprc passwordsite:[TARGET] filename:.remote-sync.jsonsite:[TARGET] filename:WebServers.xmlsite:[TARGET] stagingsite:[TARGET] stgsite:[TARGET] prodsite:[TARGET] preprodsite:[TARGET] swaggersite:[TARGET] internalsite:[TARGET] dotfilessite:[TARGET] dot-filessite:[TARGET] mydotfilessite:[TARGET] configsite:[TARGET] dbpasswdsite:[TARGET] db_passwordsite:[TARGET] db_usernamesite:[TARGET] dbusersite:[TARGET] testusersite:[TARGET] dbpasswordsite:[TARGET] keyPasswordsite:[TARGET] storePasswordsite:[TARGET] passwordssite:[TARGET] passwordsite:[TARGET] secret.passwordsite:[TARGET] database_passwordsite:[TARGET] sql_passwordsite:[TARGET] passwdsite:[TARGET] passsite:[TARGET] pwdsite:[TARGET] pwdssite:[TARGET] root_passwordsite:[TARGET] credentialssite:[TARGET] security_credentialssite:[TARGET] connectionstringsite:[TARGET] private -language:javasite:[TARGET] private_keysite:[TARGET] master_keysite:[TARGET] tokensite:[TARGET] access_tokensite:[TARGET] auth_tokensite:[TARGET] oauth_tokensite:[TARGET] authorizationTokensite:[TARGET] secretsite:[TARGET] secretssite:[TARGET] secret_keysite:[TARGET] secret_tokensite:[TARGET] api_secretsite:[TARGET] app_secretsite:[TARGET] appsecretsite:[TARGET] client_secretsite:[TARGET] keysite:[TARGET] send_keyssite:[TARGET] send.keyssite:[TARGET] sendkeyssite:[TARGET] apikeysite:[TARGET] api_keysite:[TARGET] app_keysite:[TARGET] application_keysite:[TARGET] appkeysite:[TARGET] appkeysecretsite:[TARGET] access_keysite:[TARGET] apiSecretsite:[TARGET] x-api-keysite:[TARGET] apidocssite:[TARGET] secret_access_keysite:[TARGET] encryption_keysite:[TARGET] consumer_keysite:[TARGET] authsite:[TARGET] securesite:[TARGET] loginsite:[TARGET] conn.loginsite:[TARGET] sshpasssite:[TARGET] ssh2_auth_passwordsite:[TARGET] irc_passsite:[TARGET] fb_secretsite:[TARGET] sf_usernamesite:[TARGET] node_envsite:[TARGET] aws_keysite:[TARGET] aws_tokensite:[TARGET] aws_secretsite:[TARGET] aws_accesssite:[TARGET] AWSSecretKeysite:[TARGET] github_keysite:[TARGET] github_tokensite:[TARGET] gh_tokensite:[TARGET] slack_apisite:[TARGET] slack_tokensite:[TARGET] bucket_passwordsite:[TARGET] redis_passwordsite:[TARGET] ldap_usernamesite:[TARGET] ldap_passwordsite:[TARGET] gmail_usernamesite:[TARGET] gmail_passwordsite:[TARGET] codecov_tokensite:[TARGET] fabricApiSecretsite:[TARGET] mailgunsite:[TARGET] mailchimpsite:[TARGET] appspotsite:[TARGET] firebasesite:[TARGET] gitlabsite:[TARGET] stripesite:[TARGET] herokuappsite:[TARGET] cloudfrontsite:[TARGET] amazonawssite:[TARGET] npmrc _authsite:[TARGET] pem privatesite:[TARGET] aws_access_key_idsite:[TARGET] bashrc passwordsite:[TARGET] xoxp OR xoxb OR xoxasite:[TARGET] FTPsite:[TARGET] s3.ymlsite:[TARGET] .exssite:[TARGET] beanstalkd.ymlsite:[TARGET] deploy.rakesite:[TARGET] mysqlsite:[TARGET] .bash_historysite:[TARGET] .slssite:[TARGET] composer.jsonfilename:.npmrc _authsite:[TARGET] filename:.dockercfg authsite:[TARGET] extension:pem privatesite:[TARGET] extension:ppk privatesite:[TARGET] filename:id_rsa or filename:id_dsasite:[TARGET] extension:sql mysql dumpsite:[TARGET] extension:sql mysql dump passwordsite:[TARGET] filename:credentials aws_access_key_idsite:[TARGET] filename:.s3cfgsite:[TARGET] filename:.htpasswdsite:[TARGET] filename:.env DB_USERNAME NOT homesteadsite:[TARGET] filename:.env MAIL_HOST=smtp.gmail.comsite:[TARGET] filename:.git-credentialssite:[TARGET] PT_TOKEN language:bashsite:[TARGET] filename:.bashrc passwordsite:[TARGET] filename:.bashrc mailchimpsite:[TARGET] filename:.bash_profile awssite:[TARGET] rds.amazonaws.com passwordsite:[TARGET] extension:json api.forecast.iosite:[TARGET] extension:json mongolab.comsite:[TARGET] extension:yaml mongolab.comsite:[TARGET] jsforce extension:js conn.loginsite:[TARGET] SF_USERNAME salesforcesite:[TARGET] filename:.tugboat NOT _tugboatsite:[TARGET] HEROKU_API_KEY language:shellsite:[TARGET] HEROKU_API_KEY language:jsonsite:[TARGET] filename:.netrc passwordsite:[TARGET] filename:_netrc passwordsite:[TARGET] filename:hub oauth_tokensite:[TARGET] filename:filezilla.xml Passsite:[TARGET] filename:recentservers.xml Passsite:[TARGET] filename:config.json authssite:[TARGET] filename:config irc_passsite:[TARGET] filename:connections.xmlsite:[TARGET] filename:express.conf path:.openshiftsite:[TARGET] filename:.pgpasssite:[TARGET] [WFClient] Password= extension:icasite:[TARGET] filename:server.cfg rcon passwordsite:[TARGET] JEKYLL_GITHUB_TOKENsite:[TARGET] filename:.bash_historysite:[TARGET] filename:.cshrcsite:[TARGET] filename:.historysite:[TARGET] filename:.sh_historysite:[TARGET] filename:prod.exs NOT prod.secret.exssite:[TARGET] filename:configuration.php JConfig passwordsite:[TARGET] filename:config.php dbpasswdsite:[TARGET] filename:config.php passsite:[TARGET] path:sites databases passwordsite:[TARGET] shodan_api_key language:pythonsite:[TARGET] shodan_api_key language:shellsite:[TARGET] shodan_api_key language:jsonsite:[TARGET] shodan_api_key language:rubysite:[TARGET] filename:shadow path:etcsite:[TARGET] filename:passwd path:etcsite:[TARGET] extension:avastlic "support.avast.com"site:[TARGET] extension:json googleusercontent client_secretsite:[TARGET] HOMEBREW_GITHUB_API_TOKEN language:shellsite:[TARGET] xoxp OR xoxbsite:[TARGET] .mlab.com passwordsite:[TARGET] filename:logins.jsonsite:[TARGET] filename:CCCam.cfgsite:[TARGET] msg nickserv identify filename:configsite:[TARGET] filename:settings.py SECRET_KEYsite:[TARGET] filename:secrets.yml passwordsite:[TARGET] filename:master.key path:configsite:[TARGET] filename:deployment-config.jsonsite:[TARGET] filename:.ftpconfigsite:[TARGET] filename:sftp.json path:.vscodesite:[TARGET] filename:jupyter_notebook_config.jsonsite:[TARGET] "api_hash" "api_id"site:[TARGET] "https://hooks.slack.com/services/"site:[TARGET] filename:github-recovery-codes.txtsite:[TARGET] filename:gitlab-recovery-codes.txtsite:[TARGET] filename:discord_backup_codes.txtsite:[TARGET] extension:yaml cloud.redislabs.comsite:[TARGET] extension:json cloud.redislabs.comsite:[TARGET] stagesite:[TARGET] _keysite:[TARGET] _tokensite:[TARGET] _secretsite:[TARGET] TODOsite:[TARGET] signupsite:[TARGET] registersite:[TARGET] adminsite:[TARGET] administratorsite:[TARGET] testingsite:[TARGET] extension:exssite:[TARGET] extension:slssite:[TARGET] filename:beanstalkd.ymlsite:[TARGET] filename:deploy.rakesite:[TARGET] filename:composer.jsonsite:[TARGET] filename:composer.locksite:[TARGET] ftpsite:[TARGET] ssh
inurl:trello.com AND intext:[TARGET]
If there are numerous results, narrow it further down with:
inurl:trello.com AND intext:username AND intext:[TARGET]inurl:trello.com AND intext:password AND intext:[TARGET]inurl:trello.com AND intext:apikey AND intext:[TARGET]
inurl:http://zoom.us/j [TARGET]inurl:http://zoom.us/j intext:password [TARGET]inurl:http://zoom.us/j intext:id# [TARGET]
site:*.target.com intext:"CipherMail Email Encryption Gateway login"
site:sharepoint.com [TARGET]site:box.com/s [TARGET]site:dropbox.com/s [TARGET]site:onedrive.live.com [TARGET]site:docs.google.com inurl:"/d/" [TARGET]site:[TARGET] inurl:Dashboard.jspa intext:"Atlassian Jira Project Management Software"
site:linkedin.com employees [TARGET]
intext:[TARGET] AND (site:"s3-external-1.amazonaws.com" | site:"s3.amazonaws.com")
Make sure to check the various regions:
intext:[TARGET] AND (site:s3.af-south-1.amazonaws.com | site:s3.ap-east-1.amazonaws.com | site:s3.ap-northeast-1.amazonaws.com | site:s3.ap-northeast-2.amazonaws.com | site:s3.ap-northeast-3.amazonaws.com | site:s3.ap-south-1.amazonaws.com | site:s3.ap-south-2.amazonaws.com | site:s3.ap-southeast-1.amazonaws.com | site:s3.ap-southeast-2.amazonaws.com | site:s3.ap-southeast-3.amazonaws.com | site:s3.ap-southeast-4.amazonaws.com | site:s3.ca-central-1.amazonaws.com | site:s3.eu-central-1.amazonaws.com | site:s3.eu-central-2.amazonaws.com | site:s3.eu-north-1.amazonaws.com | site:s3.eu-south-1.amazonaws.com | site:s3.eu-south-2.amazonaws.com | site:s3.eu-west-1.amazonaws.com | site:s3.eu-west-2.amazonaws.com | site:s3.eu-west-3.amazonaws.com | site:s3.me-central-1.amazonaws.com | site:s3.me-south-1.amazonaws.com | site:s3.sa-east-1.amazonaws.com | site:s3.us-east-1.amazonaws.com | site:s3.us-east-2.amazonaws.com | site:s3.us-gov-east-1.amazonaws.com | site:s3.us-gov-west-1.amazonaws.com | site:s3.us-west-1.amazonaws.com | site:s3.us-west-2.amazonaws.com)intext:[TARGET] AND (site:s3.dualstack.af-south-1.amazonaws.com | site:s3.dualstack.ap-east-1.amazonaws.com | site:s3.dualstack.ap-northeast-1.amazonaws.com | site:s3.dualstack.ap-northeast-2.amazonaws.com | site:s3.dualstack.ap-northeast-3.amazonaws.com | site:s3.dualstack.ap-south-1.amazonaws.com | site:s3.dualstack.ap-south-2.amazonaws.com | site:s3.dualstack.ap-southeast-1.amazonaws.com | site:s3.dualstack.ap-southeast-2.amazonaws.com | site:s3.dualstack.ap-southeast-3.amazonaws.com | site:s3.dualstack.ap-southeast-4.amazonaws.com | site:s3.dualstack.ca-central-1.amazonaws.com | site:s3.dualstack.eu-central-1.amazonaws.com | site:s3.dualstack.eu-central-2.amazonaws.com | site:s3.dualstack.eu-north-1.amazonaws.com | site:s3.dualstack.eu-south-1.amazonaws.com | site:s3.dualstack.eu-south-2.amazonaws.com | site:s3.dualstack.eu-west-1.amazonaws.com | site:s3.dualstack.eu-west-2.amazonaws.com | site:s3.dualstack.eu-west-3.amazonaws.com | site:s3.dualstack.me-central-1.amazonaws.com | site:s3.dualstack.me-south-1.amazonaws.com | site:s3.dualstack.sa-east-1.amazonaws.com | site:s3.dualstack.us-east-1.amazonaws.com | site:s3.dualstack.us-east-2.amazonaws.com | site:s3.dualstack.us-gov-east-1.amazonaws.com | site:s3.dualstack.us-gov-west-1.amazonaws.com | site:s3.dualstack.us-west-1.amazonaws.com | site:s3.dualstack.us-west-2.amazonaws.com)
site:"blob.core.windows.net" AND intext:[TARGET]
site:"storage.googleapis.com" AND intext:[TARGET]
site:"digitaloceanspaces.com" [TARGET]
site:github.com | site:gitlab.com | site:bitbucket.org [TARGET]
site:"dev.azure.com" AND intext:secretsite:"dev.azure.com" AND intext:passwordsite:"dev.azure.com" AND intext:apikey
GitHub, GitLab, BB online dev enviroments?
site:stackoverflow.com AND intext:"[TARGET]"site:jfrog.io AND intext:"[TARGET]"[TARGET]intitle:traefik inurl:8080/dashboard [TARGET]intitle:"Dashboard [Jenkins]" [TARGET](site:bitpaste.app | site:codebeautify.org | site:codepad.co | site:codepad.co |site:ideone.com | site:codepad.org | site:codepen.io | site:codeshare.io | site:coggle.it | site:controlc.com | site:dotnetfiddle.net | site:dpaste.com | site:dpaste.org | site:gitter.im | site:hastebin.com | site:heypasteit.com | site:ide.geeksforgeeks.org | site:ideone.com | site:jsdelivr.com | site:jsdelivr.net | site:jsfiddle.net) AND "[TARGET]"(site:justpaste.it | site:libraries.io | site:npmjs.com | site:npm.runit.com | site:npm.runkit.com | site:papaly.com | site:paste2.org | site:pastebin.com | site:paste.debian.net | site:pastehtml.com | site:paste.org | site:phpfiddle.org | site:prezi.com | site:productforums.google.com | site:repl.it | site:replt.it | site:scribd.com | site:sharecode.io | site:snipplr.com | site:trello.com | site:ycombinator.com) AND "[TARGET]"