mirror of
https://github.com/Jieyab89/OSINT-Cheat-sheet.git
synced 2025-12-05 20:40:30 -08:00
Edit md and add reesouces
This commit is contained in:
332
README.md
332
README.md
@@ -731,296 +731,8 @@ Dorking is a wonderful thing, you can use this technique to search for anything
|
||||
15. (-) Minus operator avoids showing results that contain certain words, e.g. security -trails will show pages that use "security" in their text, but not those that have the word "trails"
|
||||
|
||||
Example
|
||||
```
|
||||
".mlab.com password"
|
||||
"access_key"
|
||||
"access_token"
|
||||
"amazonaws"
|
||||
"api.googlemaps AIza"
|
||||
"api_key"
|
||||
"api_secret"
|
||||
"apidocs"
|
||||
"apikey"
|
||||
"apiSecret"
|
||||
"app_key"
|
||||
"app_secret"
|
||||
"appkey"
|
||||
"appkeysecret"
|
||||
"application_key"
|
||||
"appsecret"
|
||||
"appspot"
|
||||
"auth"
|
||||
"auth_token"
|
||||
"authorizationToken"
|
||||
"aws_access"
|
||||
"aws_access_key_id"
|
||||
"aws_key"
|
||||
"aws_secret"
|
||||
"aws_token"
|
||||
"AWSSecretKey"
|
||||
"bashrc password"
|
||||
"bucket_password"
|
||||
"client_secret"
|
||||
"cloudfront"
|
||||
"codecov_token"
|
||||
"config"
|
||||
"conn.login"
|
||||
"connectionstring"
|
||||
"consumer_key"
|
||||
"credentials"
|
||||
"database_password"
|
||||
"db_password"
|
||||
"db_username"
|
||||
"dbpasswd"
|
||||
"dbpassword"
|
||||
"dbuser"
|
||||
"dot-files"
|
||||
"dotfiles"
|
||||
"encryption_key"
|
||||
"fabricApiSecret"
|
||||
"fb_secret"
|
||||
"firebase"
|
||||
"ftp"
|
||||
"gh_token"
|
||||
"github_key"
|
||||
"github_token"
|
||||
"gitlab"
|
||||
"gmail_password"
|
||||
"gmail_username"
|
||||
"herokuapp"
|
||||
"internal"
|
||||
"irc_pass"
|
||||
"JEKYLL_GITHUB_TOKEN"
|
||||
"key"
|
||||
"keyPassword"
|
||||
"ldap_password"
|
||||
"ldap_username"
|
||||
"login"
|
||||
"mailchimp"
|
||||
"mailgun"
|
||||
"master_key"
|
||||
"mydotfiles"
|
||||
"mysql"
|
||||
"node_env"
|
||||
"npmrc _auth"
|
||||
"oauth_token"
|
||||
"pass"
|
||||
"passwd"
|
||||
"password"
|
||||
"passwords"
|
||||
"pem private"
|
||||
"preprod"
|
||||
"private_key"
|
||||
"prod"
|
||||
"pwd"
|
||||
"pwds"
|
||||
"rds.amazonaws.com password"
|
||||
"redis_password"
|
||||
"root_password"
|
||||
"secret"
|
||||
"secret.password"
|
||||
"secret_access_key"
|
||||
"secret_key"
|
||||
"secret_token"
|
||||
"secrets"
|
||||
"secure"
|
||||
"security_credentials"
|
||||
"send.keys"
|
||||
"send_keys"
|
||||
"sendkeys"
|
||||
"SF_USERNAME salesforce"
|
||||
"sf_username"
|
||||
"site.com" FIREBASE_API_JSON=
|
||||
"site.com" vim_settings.xml
|
||||
"slack_api"
|
||||
"slack_token"
|
||||
"sql_password"
|
||||
"ssh"
|
||||
"ssh2_auth_password"
|
||||
"sshpass"
|
||||
"staging"
|
||||
"stg"
|
||||
"storePassword"
|
||||
"stripe"
|
||||
"swagger"
|
||||
"testuser"
|
||||
"token"
|
||||
"x-api-key"
|
||||
"xoxb "
|
||||
"xoxp"
|
||||
[WFClient] Password= extension:ica
|
||||
access_key
|
||||
bucket_password
|
||||
dbpassword
|
||||
dbuser
|
||||
extension:avastlic "support.avast.com"
|
||||
extension:bat
|
||||
extension:cfg
|
||||
extension:env
|
||||
extension:exs
|
||||
extension:ini
|
||||
extension:json api.forecast.io
|
||||
extension:json googleusercontent client_secret
|
||||
extension:json mongolab.com
|
||||
extension:pem
|
||||
extension:pem private
|
||||
extension:ppk
|
||||
extension:ppk private
|
||||
extension:properties
|
||||
extension:sh
|
||||
extension:sls
|
||||
extension:sql
|
||||
extension:sql mysql dump
|
||||
extension:sql mysql dump password
|
||||
extension:yaml mongolab.com
|
||||
extension:zsh
|
||||
filename:.bash_history
|
||||
filename:.bash_history DOMAIN-NAME
|
||||
filename:.bash_profile aws
|
||||
filename:.bashrc mailchimp
|
||||
filename:.bashrc password
|
||||
filename:.cshrc
|
||||
filename:.dockercfg auth
|
||||
filename:.env DB_USERNAME NOT homestead
|
||||
filename:.env MAIL_HOST=smtp.gmail.com
|
||||
filename:.esmtprc password
|
||||
filename:.ftpconfig
|
||||
filename:.git-credentials
|
||||
filename:.history
|
||||
filename:.htpasswd
|
||||
filename:.netrc password
|
||||
filename:.npmrc _auth
|
||||
filename:.pgpass
|
||||
filename:.remote-sync.json
|
||||
filename:.s3cfg
|
||||
filename:.sh_history
|
||||
filename:.tugboat NOT _tugboat
|
||||
filename:_netrc password
|
||||
filename:apikey
|
||||
filename:bash
|
||||
filename:bash_history
|
||||
filename:bash_profile
|
||||
filename:bashrc
|
||||
filename:beanstalkd.yml
|
||||
filename:CCCam.cfg
|
||||
filename:composer.json
|
||||
filename:config
|
||||
filename:config irc_pass
|
||||
filename:config.json auths
|
||||
filename:config.php dbpasswd
|
||||
filename:configuration.php JConfig password
|
||||
filename:connections
|
||||
filename:connections.xml
|
||||
filename:constants
|
||||
filename:credentials
|
||||
filename:credentials aws_access_key_id
|
||||
filename:cshrc
|
||||
filename:database
|
||||
filename:dbeaver-data-sources.xml
|
||||
filename:deployment-config.json
|
||||
filename:dhcpd.conf
|
||||
filename:dockercfg
|
||||
filename:environment
|
||||
filename:express.conf
|
||||
filename:express.conf path:.openshift
|
||||
filename:filezilla.xml
|
||||
filename:filezilla.xml Pass
|
||||
filename:git-credentials
|
||||
filename:gitconfig
|
||||
filename:global
|
||||
filename:history
|
||||
filename:htpasswd
|
||||
filename:hub oauth_token
|
||||
filename:id_dsa
|
||||
filename:id_rsa
|
||||
filename:id_rsa or filename:id_dsa
|
||||
filename:idea14.key
|
||||
filename:known_hosts
|
||||
filename:logins.json
|
||||
filename:makefile
|
||||
filename:master.key path:config
|
||||
filename:netrc
|
||||
filename:npmrc
|
||||
filename:pass
|
||||
filename:passwd path:etc
|
||||
filename:pgpass
|
||||
filename:prod.exs
|
||||
filename:prod.exs NOT prod.secret.exs
|
||||
filename:prod.secret.exs
|
||||
filename:proftpdpasswd
|
||||
filename:recentservers.xml
|
||||
filename:recentservers.xml Pass
|
||||
filename:robomongo.json
|
||||
filename:s3cfg
|
||||
filename:secrets.yml password
|
||||
filename:server.cfg
|
||||
filename:server.cfg rcon password
|
||||
filename:settings
|
||||
filename:settings.py SECRET_KEY
|
||||
filename:sftp-config.json
|
||||
filename:sftp-config.json password
|
||||
filename:sftp.json path:.vscode
|
||||
filename:shadow
|
||||
filename:shadow path:etc
|
||||
filename:spec
|
||||
filename:sshd_config
|
||||
filename:token
|
||||
filename:tugboat
|
||||
filename:ventrilo_srv.ini
|
||||
filename:WebServers.xml
|
||||
filename:wp-config
|
||||
filename:wp-config.php
|
||||
filename:zhrc
|
||||
HEROKU_API_KEY language:json
|
||||
HEROKU_API_KEY language:shell
|
||||
HOMEBREW_GITHUB_API_TOKEN language:shell
|
||||
jsforce extension:js conn.login
|
||||
language:yaml -filename:travis
|
||||
msg nickserv identify filename:config
|
||||
org:Target "AWS_ACCESS_KEY_ID"
|
||||
org:Target "list_aws_accounts"
|
||||
org:Target "aws_access_key"
|
||||
org:Target "aws_secret_key"
|
||||
org:Target "bucket_name"
|
||||
org:Target "S3_ACCESS_KEY_ID"
|
||||
org:Target "S3_BUCKET"
|
||||
org:Target "S3_ENDPOINT"
|
||||
org:Target "S3_SECRET_ACCESS_KEY"
|
||||
password
|
||||
path:sites databases password
|
||||
private -language:java
|
||||
PT_TOKEN language:bash
|
||||
redis_password
|
||||
root_password
|
||||
secret_access_key
|
||||
SECRET_KEY_BASE=
|
||||
shodan_api_key language:python
|
||||
WORDPRESS_DB_PASSWORD=
|
||||
xoxp OR xoxb OR xoxa
|
||||
s3.yml
|
||||
.exs
|
||||
beanstalkd.yml
|
||||
deploy.rake
|
||||
.sls
|
||||
AWS_SECRET_ACCESS_KEY
|
||||
API KEY
|
||||
API SECRET
|
||||
API TOKEN
|
||||
ROOT PASSWORD
|
||||
ADMIN PASSWORD
|
||||
GCP SECRET
|
||||
AWS SECRET
|
||||
"private" extension:pgp
|
||||
```
|
||||
|
||||
> intext:"hacking" site:seccodeid.com
|
||||
>
|
||||
> inurl:login site:seccodeid.com
|
||||
>
|
||||
> intext:username filetype:log
|
||||
>
|
||||
> site:www.github.com ext:doc | ext:docx | ext:odt | ext:rtf | ext:sxw | ext:psw | ext:ppt | ext:pptx | ext:pps | ext:csv
|
||||
>
|
||||
[Dorking list](Script/Google-Dork/README.md)
|
||||
|
||||
# Dorking Other Search Engine
|
||||
|
||||
@@ -1030,43 +742,9 @@ AWS SECRET
|
||||
|
||||
# Bash Dorking Script
|
||||
|
||||
PRO TIPS!
|
||||
Example
|
||||
|
||||
You can add other headers, regex and search engine endpoints for refinement and to encode queries
|
||||
|
||||
- BING SEARCH
|
||||
|
||||
WEB
|
||||
|
||||
```WEB
|
||||
for ((i=1;i<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" "https://www.bing.com/search?pglt=2081&q=.php?id=" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep ".php?id" | sort -u ;done
|
||||
```
|
||||
|
||||
Hunt Username
|
||||
|
||||
```USERNAME
|
||||
for ((i=1;1<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/119.0;Accept: */*;Accept-Language: id,en-US;q-0.7,en;q-0.3;Accept-Encoding: gzip, deflate, br;Referer: https: //www.bing.com/;DNT: 1;Connection: keep-alive;Cookie: 1P_JAR=2023-11-05-19;Sec-Fetch-Dest:empty;Sec-Fetch-Mode:cors;Sec-Fetch-Site: same-origin;TE: trailers" "https://www.bing.com/search?pglt=2081&q=Jieyab89" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep -E "Jieyab89|github" | sort -u ;done
|
||||
```
|
||||
|
||||
Hunt Username
|
||||
|
||||
```USERNAME
|
||||
for ((i=1;1<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/119.0;Accept: */*;Accept-Language: id,en-US;q-0.7,en;q-0.3;Accept-Encoding: gzip, deflate, br;Referer: https: //www.bing.com/;DNT: 1;Connection: keep-alive;Cookie: 1P_JAR=2023-11-05-19;Sec-Fetch-Dest:empty;Sec-Fetch-Mode:cors;Sec-Fetch-Site: same-origin;TE: trailers" "Your Bing Request URL Header" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep -E "Jieyab89|github" | sort -u ;done
|
||||
```
|
||||
|
||||
- GOOGLE SEARCH
|
||||
|
||||
Hunt Username
|
||||
|
||||
```USERNAME
|
||||
for ((i=1;1<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/119.0;Accept: */*;Accept-Language: id,en-US;q-0.7,en;q-0.3;Accept-Encoding: gzip, deflate, br;Referer: https: //www.google.com/;DNT: 1;Connection: keep-alive;Cookie: 1P_JAR=2023-11-05-19;Sec-Fetch-Dest:empty;Sec-Fetch-Mode:cors;Sec-Fetch-Site: same-origin;TE: trailers" "https://www.google.com/search?sourceid=chrome-psyapi2&ion=1&espv=2&ie=UTF-8&start=${i}0&q=Jieyab89" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep -E "Jieyab89|github" | sort -u ;done
|
||||
```
|
||||
|
||||
WEB
|
||||
|
||||
```WEB
|
||||
for ((i=1;i<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" "https://www.google.com/search?sourceid=chrome-psyapi2&ion=1&espv=2&ie=UTF-8&start=${i}0&q=.php?id=" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep ".php?id" | sort -u ;done
|
||||
```
|
||||
[Bash Dorking Script](Script/Google-Dork/README.md)
|
||||
|
||||
# Google Advanced Search Tools
|
||||
|
||||
@@ -2094,6 +1772,7 @@ Search channel, username anymore
|
||||
- [geospy](https://geospy.ai/)
|
||||
- [sogou](https://pic.sogou.com/)
|
||||
- [geospy](https://geospy.web.app/)
|
||||
- [alamy](https://www.alamy.com/)
|
||||
|
||||
# Image Analysis
|
||||
|
||||
@@ -2377,6 +2056,7 @@ Browser plugin that allows you to watch YouTube videos frame by frame.
|
||||
- [virtualglobetrotting](https://virtualglobetrotting.com/)
|
||||
- [Population Count](https://landscan.ornl.gov/)
|
||||
- [grid Area mapping](https://grid.bellingcat.com/)
|
||||
- [Maritim world lightphotos](https://www.lightphotos.net/photos/map_all.php)
|
||||
|
||||
Conveter tool
|
||||
|
||||
@@ -2408,6 +2088,7 @@ Geojson viewer
|
||||
- [Blender 3D maker](https://www.blender.org/)
|
||||
- [3D Maker by OSM](https://osmbuildings.org/documentation/leaflet/)
|
||||
- [Microsoft GlobalMLBuildingFootprints](https://github.com/microsoft/GlobalMLBuildingFootprints)
|
||||
- [Microsoft flightsimulator](https://www.flightsimulator.com/)
|
||||
|
||||
# Nearby Map From Geospatial
|
||||
|
||||
@@ -3326,6 +3007,7 @@ VIN Checker
|
||||
- [CMA CGM vesel finder](https://www.cma-cgm.com/ebusiness/schedules/voyage)
|
||||
- [marinevesseltraffic](https://www.marinevesseltraffic.com/2013/02/military-ship-track.html)
|
||||
- [globalmaritimetraffic](https://www.globalmaritimetraffic.org/gmtds.html)
|
||||
- [Maritim world lightphotos](https://www.lightphotos.net/photos/map_all.php)
|
||||
|
||||
NOOA Incident MAP
|
||||
|
||||
|
||||
333
Script/Google-Dork/README.md
Normal file
333
Script/Google-Dork/README.md
Normal file
@@ -0,0 +1,333 @@
|
||||
# List Google Dork
|
||||
|
||||
Example
|
||||
```
|
||||
".mlab.com password"
|
||||
"access_key"
|
||||
"access_token"
|
||||
"amazonaws"
|
||||
"api.googlemaps AIza"
|
||||
"api_key"
|
||||
"api_secret"
|
||||
"apidocs"
|
||||
"apikey"
|
||||
"apiSecret"
|
||||
"app_key"
|
||||
"app_secret"
|
||||
"appkey"
|
||||
"appkeysecret"
|
||||
"application_key"
|
||||
"appsecret"
|
||||
"appspot"
|
||||
"auth"
|
||||
"auth_token"
|
||||
"authorizationToken"
|
||||
"aws_access"
|
||||
"aws_access_key_id"
|
||||
"aws_key"
|
||||
"aws_secret"
|
||||
"aws_token"
|
||||
"AWSSecretKey"
|
||||
"bashrc password"
|
||||
"bucket_password"
|
||||
"client_secret"
|
||||
"cloudfront"
|
||||
"codecov_token"
|
||||
"config"
|
||||
"conn.login"
|
||||
"connectionstring"
|
||||
"consumer_key"
|
||||
"credentials"
|
||||
"database_password"
|
||||
"db_password"
|
||||
"db_username"
|
||||
"dbpasswd"
|
||||
"dbpassword"
|
||||
"dbuser"
|
||||
"dot-files"
|
||||
"dotfiles"
|
||||
"encryption_key"
|
||||
"fabricApiSecret"
|
||||
"fb_secret"
|
||||
"firebase"
|
||||
"ftp"
|
||||
"gh_token"
|
||||
"github_key"
|
||||
"github_token"
|
||||
"gitlab"
|
||||
"gmail_password"
|
||||
"gmail_username"
|
||||
"herokuapp"
|
||||
"internal"
|
||||
"irc_pass"
|
||||
"JEKYLL_GITHUB_TOKEN"
|
||||
"key"
|
||||
"keyPassword"
|
||||
"ldap_password"
|
||||
"ldap_username"
|
||||
"login"
|
||||
"mailchimp"
|
||||
"mailgun"
|
||||
"master_key"
|
||||
"mydotfiles"
|
||||
"mysql"
|
||||
"node_env"
|
||||
"npmrc _auth"
|
||||
"oauth_token"
|
||||
"pass"
|
||||
"passwd"
|
||||
"password"
|
||||
"passwords"
|
||||
"pem private"
|
||||
"preprod"
|
||||
"private_key"
|
||||
"prod"
|
||||
"pwd"
|
||||
"pwds"
|
||||
"rds.amazonaws.com password"
|
||||
"redis_password"
|
||||
"root_password"
|
||||
"secret"
|
||||
"secret.password"
|
||||
"secret_access_key"
|
||||
"secret_key"
|
||||
"secret_token"
|
||||
"secrets"
|
||||
"secure"
|
||||
"security_credentials"
|
||||
"send.keys"
|
||||
"send_keys"
|
||||
"sendkeys"
|
||||
"SF_USERNAME salesforce"
|
||||
"sf_username"
|
||||
"site.com" FIREBASE_API_JSON=
|
||||
"site.com" vim_settings.xml
|
||||
"slack_api"
|
||||
"slack_token"
|
||||
"sql_password"
|
||||
"ssh"
|
||||
"ssh2_auth_password"
|
||||
"sshpass"
|
||||
"staging"
|
||||
"stg"
|
||||
"storePassword"
|
||||
"stripe"
|
||||
"swagger"
|
||||
"testuser"
|
||||
"token"
|
||||
"x-api-key"
|
||||
"xoxb "
|
||||
"xoxp"
|
||||
[WFClient] Password= extension:ica
|
||||
access_key
|
||||
bucket_password
|
||||
dbpassword
|
||||
dbuser
|
||||
extension:avastlic "support.avast.com"
|
||||
extension:bat
|
||||
extension:cfg
|
||||
extension:env
|
||||
extension:exs
|
||||
extension:ini
|
||||
extension:json api.forecast.io
|
||||
extension:json googleusercontent client_secret
|
||||
extension:json mongolab.com
|
||||
extension:pem
|
||||
extension:pem private
|
||||
extension:ppk
|
||||
extension:ppk private
|
||||
extension:properties
|
||||
extension:sh
|
||||
extension:sls
|
||||
extension:sql
|
||||
extension:sql mysql dump
|
||||
extension:sql mysql dump password
|
||||
extension:yaml mongolab.com
|
||||
extension:zsh
|
||||
filename:.bash_history
|
||||
filename:.bash_history DOMAIN-NAME
|
||||
filename:.bash_profile aws
|
||||
filename:.bashrc mailchimp
|
||||
filename:.bashrc password
|
||||
filename:.cshrc
|
||||
filename:.dockercfg auth
|
||||
filename:.env DB_USERNAME NOT homestead
|
||||
filename:.env MAIL_HOST=smtp.gmail.com
|
||||
filename:.esmtprc password
|
||||
filename:.ftpconfig
|
||||
filename:.git-credentials
|
||||
filename:.history
|
||||
filename:.htpasswd
|
||||
filename:.netrc password
|
||||
filename:.npmrc _auth
|
||||
filename:.pgpass
|
||||
filename:.remote-sync.json
|
||||
filename:.s3cfg
|
||||
filename:.sh_history
|
||||
filename:.tugboat NOT _tugboat
|
||||
filename:_netrc password
|
||||
filename:apikey
|
||||
filename:bash
|
||||
filename:bash_history
|
||||
filename:bash_profile
|
||||
filename:bashrc
|
||||
filename:beanstalkd.yml
|
||||
filename:CCCam.cfg
|
||||
filename:composer.json
|
||||
filename:config
|
||||
filename:config irc_pass
|
||||
filename:config.json auths
|
||||
filename:config.php dbpasswd
|
||||
filename:configuration.php JConfig password
|
||||
filename:connections
|
||||
filename:connections.xml
|
||||
filename:constants
|
||||
filename:credentials
|
||||
filename:credentials aws_access_key_id
|
||||
filename:cshrc
|
||||
filename:database
|
||||
filename:dbeaver-data-sources.xml
|
||||
filename:deployment-config.json
|
||||
filename:dhcpd.conf
|
||||
filename:dockercfg
|
||||
filename:environment
|
||||
filename:express.conf
|
||||
filename:express.conf path:.openshift
|
||||
filename:filezilla.xml
|
||||
filename:filezilla.xml Pass
|
||||
filename:git-credentials
|
||||
filename:gitconfig
|
||||
filename:global
|
||||
filename:history
|
||||
filename:htpasswd
|
||||
filename:hub oauth_token
|
||||
filename:id_dsa
|
||||
filename:id_rsa
|
||||
filename:id_rsa or filename:id_dsa
|
||||
filename:idea14.key
|
||||
filename:known_hosts
|
||||
filename:logins.json
|
||||
filename:makefile
|
||||
filename:master.key path:config
|
||||
filename:netrc
|
||||
filename:npmrc
|
||||
filename:pass
|
||||
filename:passwd path:etc
|
||||
filename:pgpass
|
||||
filename:prod.exs
|
||||
filename:prod.exs NOT prod.secret.exs
|
||||
filename:prod.secret.exs
|
||||
filename:proftpdpasswd
|
||||
filename:recentservers.xml
|
||||
filename:recentservers.xml Pass
|
||||
filename:robomongo.json
|
||||
filename:s3cfg
|
||||
filename:secrets.yml password
|
||||
filename:server.cfg
|
||||
filename:server.cfg rcon password
|
||||
filename:settings
|
||||
filename:settings.py SECRET_KEY
|
||||
filename:sftp-config.json
|
||||
filename:sftp-config.json password
|
||||
filename:sftp.json path:.vscode
|
||||
filename:shadow
|
||||
filename:shadow path:etc
|
||||
filename:spec
|
||||
filename:sshd_config
|
||||
filename:token
|
||||
filename:tugboat
|
||||
filename:ventrilo_srv.ini
|
||||
filename:WebServers.xml
|
||||
filename:wp-config
|
||||
filename:wp-config.php
|
||||
filename:zhrc
|
||||
HEROKU_API_KEY language:json
|
||||
HEROKU_API_KEY language:shell
|
||||
HOMEBREW_GITHUB_API_TOKEN language:shell
|
||||
jsforce extension:js conn.login
|
||||
language:yaml -filename:travis
|
||||
msg nickserv identify filename:config
|
||||
org:Target "AWS_ACCESS_KEY_ID"
|
||||
org:Target "list_aws_accounts"
|
||||
org:Target "aws_access_key"
|
||||
org:Target "aws_secret_key"
|
||||
org:Target "bucket_name"
|
||||
org:Target "S3_ACCESS_KEY_ID"
|
||||
org:Target "S3_BUCKET"
|
||||
org:Target "S3_ENDPOINT"
|
||||
org:Target "S3_SECRET_ACCESS_KEY"
|
||||
password
|
||||
path:sites databases password
|
||||
private -language:java
|
||||
PT_TOKEN language:bash
|
||||
redis_password
|
||||
root_password
|
||||
secret_access_key
|
||||
SECRET_KEY_BASE=
|
||||
shodan_api_key language:python
|
||||
WORDPRESS_DB_PASSWORD=
|
||||
xoxp OR xoxb OR xoxa
|
||||
s3.yml
|
||||
.exs
|
||||
beanstalkd.yml
|
||||
deploy.rake
|
||||
.sls
|
||||
AWS_SECRET_ACCESS_KEY
|
||||
API KEY
|
||||
API SECRET
|
||||
API TOKEN
|
||||
ROOT PASSWORD
|
||||
ADMIN PASSWORD
|
||||
GCP SECRET
|
||||
AWS SECRET
|
||||
"private" extension:pgp
|
||||
```
|
||||
|
||||
> intext:"hacking" site:seccodeid.com
|
||||
>
|
||||
> inurl:login site:seccodeid.com
|
||||
>
|
||||
> intext:username filetype:log
|
||||
>
|
||||
> site:www.github.com ext:doc | ext:docx | ext:odt | ext:rtf | ext:sxw | ext:psw | ext:ppt | ext:pptx | ext:pps | ext:csv
|
||||
>
|
||||
|
||||
# Bash Dorking Script
|
||||
|
||||
PRO TIPS!
|
||||
|
||||
You can add other headers, regex and search engine endpoints for refinement and to encode queries
|
||||
|
||||
- BING SEARCH
|
||||
|
||||
WEB
|
||||
|
||||
```WEB
|
||||
for ((i=1;i<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" "https://www.bing.com/search?pglt=2081&q=.php?id=" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep ".php?id" | sort -u ;done
|
||||
```
|
||||
|
||||
Hunt Username
|
||||
|
||||
```USERNAME
|
||||
for ((i=1;1<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/119.0;Accept: */*;Accept-Language: id,en-US;q-0.7,en;q-0.3;Accept-Encoding: gzip, deflate, br;Referer: https: //www.bing.com/;DNT: 1;Connection: keep-alive;Cookie: 1P_JAR=2023-11-05-19;Sec-Fetch-Dest:empty;Sec-Fetch-Mode:cors;Sec-Fetch-Site: same-origin;TE: trailers" "https://www.bing.com/search?pglt=2081&q=Jieyab89" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep -E "Jieyab89|github" | sort -u ;done
|
||||
```
|
||||
|
||||
Hunt Username
|
||||
|
||||
```USERNAME
|
||||
for ((i=1;1<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/119.0;Accept: */*;Accept-Language: id,en-US;q-0.7,en;q-0.3;Accept-Encoding: gzip, deflate, br;Referer: https: //www.bing.com/;DNT: 1;Connection: keep-alive;Cookie: 1P_JAR=2023-11-05-19;Sec-Fetch-Dest:empty;Sec-Fetch-Mode:cors;Sec-Fetch-Site: same-origin;TE: trailers" "Your Bing Request URL Header" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep -E "Jieyab89|github" | sort -u ;done
|
||||
```
|
||||
|
||||
- GOOGLE SEARCH
|
||||
|
||||
Hunt Username
|
||||
|
||||
```USERNAME
|
||||
for ((i=1;1<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/119.0;Accept: */*;Accept-Language: id,en-US;q-0.7,en;q-0.3;Accept-Encoding: gzip, deflate, br;Referer: https: //www.google.com/;DNT: 1;Connection: keep-alive;Cookie: 1P_JAR=2023-11-05-19;Sec-Fetch-Dest:empty;Sec-Fetch-Mode:cors;Sec-Fetch-Site: same-origin;TE: trailers" "https://www.google.com/search?sourceid=chrome-psyapi2&ion=1&espv=2&ie=UTF-8&start=${i}0&q=Jieyab89" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep -E "Jieyab89|github" | sort -u ;done
|
||||
```
|
||||
|
||||
WEB
|
||||
|
||||
```WEB
|
||||
for ((i=1;i<=10;i++));do curl -i -s -k -L -X GET -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" "https://www.google.com/search?sourceid=chrome-psyapi2&ion=1&espv=2&ie=UTF-8&start=${i}0&q=.php?id=" | grep -Eo 'href="[^\"]+"' | grep -Po "(http|https)://[a-zA-Z0-9./?=_%:-]*" | grep ".php?id" | sort -u ;done
|
||||
```
|
||||
Reference in New Issue
Block a user