phantomas90 Posted June 14, 2010 Report Posted June 14, 2010 (edited) Am gasit aici : zonabakhacker.org - ZBH TEAM “admin account info” filetype:log!Host=*.* intext:enc_UserPassword=* ext:pcf“# -FrontPage-” ext:pwd inurl:(service | authors | administrators | users) “# -FrontPage-” inurl:service.pwd“AutoCreate=TRUE password=*”“http://*@www” domainname“index of/” “ws_ftp.ini” “parent directory”“liveice configuration file” ext:cfg -site:sourceforge.net“parent directory” +proftpdpasswd“powered by ducalendar” -site:duware.com“Powered by Duclassified” -site:duware.com“Powered by Duclassified” -site:duware.com “DUware All Rights reserved”“powered by duclassmate” -site:duware.com“Powered by Dudirectory” -site:duware.com“powered by dudownload” -site:duware.com“Powered By Elite Forum Version *.*”“Powered by Link Department”“sets mode: +k”“your password is” filetype:log"Powered by DUpaypal" -site:duware.comallinurl: admin mdbauth_user_file.txtconfig.phpeggdrop filetype:user userenable password | secret “current configuration” -intext:theetc (index.of)ext:asa | ext:bak intext:uid intext:pwd -”uid..pwd” database | server | dsnext:inc “pwd=” “UID=”ext:ini eudora.iniext:ini Version=4.0.0.4 passwordext:passwd -intext:the -sample -exampleext:txt inurl:unattend.txtext:yml database inurl:configfiletype:bak createobject safiletype:bak inurl:”htaccess|passwd|shadow|htusers”filetype:cfg mrtg “target[*]” -sample -cvs -examplefiletype:cfm “cfapplication name” passwordfiletype:conf oekakibbsfiletype:conf slapd.conffiletype:config config intext:appSettings “User ID”filetype:dat “password.dat”filetype:dat inurl:Sites.datfiletype:dat wand.datfiletype:inc dbconnfiletype:inc intext:mysql_connectfiletype:inc mysql_connect OR mysql_pconnectfiletype:inf sysprepfiletype:ini inurl:”serv-u.ini”filetype:ini inurl:flashFXP.inifiletype:ini ServUDaemonfiletype:ini wcx_ftpfiletype:ini ws_ftp pwdfiletype:ldb adminfiletype:log “See `ipsec –copyright”filetype:log inurl:”password.log”filetype:mdb inurl:users.mdbfiletype:mdb wwforumfiletype:netrc passwordfiletype:pass pass intext:useridfiletype:pem intext:privatefiletype:properties inurl:db intext:passwordfiletype:pwd servicefiletype:pwl pwlfiletype:reg reg +intext:”defaultusername” +intext:”defaultpassword”filetype:reg reg +intext:”WINVNC3”filetype:reg reg HKEY_CURRENT_USER SSHHOSTKEYSfiletype:sql “insert into” (pass|passwd|password)filetype:sql (”values * MD5? | “values * password” | “values * encrypt”)filetype:sql ("passwd values" | "password values" | "pass values" )filetype:sql +”IDENTIFIED BY” -cvsfiletype:sql passwordfiletype:url +inurl:”ftp://” +inurl:”;@"filetype:xls username password emailhtpasswdhtpasswd / htgrouphtpasswd / htpasswd.bakintext:”enable password 7?intext:”enable secret 5 $”intext:”powered by EZGuestbook”intext:”powered by Web Wiz Journal”intitle:”index of” intext:connect.incintitle:”index of” intext:globals.incintitle:”Index of” passwords modifiedintitle:”Index of” sc_serv.conf sc_serv contentintitle:”phpinfo()” +”mysql.default_password” +”Zend Scripting Language Engine”intitle:dupics inurl:(add.asp | default.asp | view.asp | voting.asp) -site:duware.comintitle:index.of administrators.pwdintitle:Index.of etc shadowintitle:index.of intext:”secring.skr”|”secring.pgp”|”secring.bak”intitle:rapidshare intext:logininurl:”calendarscript/users.txt”inurl:”editor/list.asp” | inurl:”database_editor.asp” | inurl:”login.asa” “are set”inurl:”GRC.DAT” intext:”password”inurl:”Sites.dat”+”PASS=”inurl:”slapd.conf” intext:”credentials” -manpage -”Manual Page” -man: -sampleinurl:”slapd.conf” intext:”rootpw” -manpage -”Manual Page” -man: -sampleinurl:”wvdial.conf” intext:”password”inurl:/db/main.mdbinurl:/wwwboardinurl:/yabb/Members/Admin.datinurl:ccbill filetype:loginurl:cgi-bin inurl:calendar.cfginurl:chap-secrets -cvsinurl:config.php dbuname dbpassinurl:filezilla.xml -cvsinurl:lilo.conf filetype:conf password -tatercounter2000 -bootpwd -maninurl:nuke filetype:sqlinurl:ospfd.conf intext:password -sample -test -tutorial -downloadinurl:pap-secrets -cvsinurl:pass.datinurl:perform filetype:iniinurl:perform.ini filetype:iniinurl:secring ext:skr | ext:pgp | ext:bakinurl:server.cfg rcon passwordinurl:ventrilo_srv.ini adminpasswordinurl:vtund.conf intext:pass -cvsinurl:zebra.conf intext:password -sample -test -tutorial -downloadLeapFTP intitle:”index.of./” sites.ini modifiedmaster.passwdmysql history filesNickServ registration passwordspasslistpasslist.txt (a better way)passwdpasswd / etc (reliable)people.lstpsyBNC config filespwd.dbserver-dbs “intitle:index of”signin filetype:urlspwd.db / passwdtrillian.iniwwwboard WebAdmin inurl:passwd.txt wwwboard|webadmin[WFClient] Password= filetype:ica Doar copy/paste la fiecare sintaxa si cautati prin rezultate. Voi continua acest tutorial daca nu il considerati "boring".Urmatoarea parte este despre folosirea combinata a operatorilor pentru cautari mai stricte.Am inceput prin postarea acestor sintaxe considerandu-le mai importante decat ce urmeaza.Folositi https://www.google.com/pentru cautare. Edited June 14, 2010 by phantomas90 Quote
blech Posted June 14, 2010 Report Posted June 14, 2010 cred ca mai degraba tu vroiai sa ne arati dork-urile pt ca nu sunt cele mai bune exemple pt a arata modul de folosire al operatorilor.... bun pt cei care nu le stiau deja dar oricum oldschoolla mai multe posturi... Quote
phantomas90 Posted June 14, 2010 Author Report Posted June 14, 2010 @blech nu am incercat inca toate sintaxele dar cateva au scos loguri bune.De exemplu cu “admin account info” filetype:log am dat de cateva loguri(mai vechi intradevar)....Am cartea "google hacking for penetration testers" si as vrea sa fac pe capitole.Am incercat cate ceva si de acolo si cel putin cele cu camerele de supraveghere merg(nu nimeresti exact ce vrei tu sa privesti).De exemplu asta: http://24.231.158.230:8888/ViewerFrame?Mode=MotionSau asta: AXIS Video Serversau cautari de genu: https://www.google.com/#hl=en&source=hp&q=intitle%3Aindex.of+ws_ftp.ini&btnG=Google+Search&aq=f&aqi=&aql=&oq=intitle%3Aindex.of+ws_ftp.ini&gs_rfai=&fp=d2dedfa38fcb60cedupa parole de conectare FTP..Poate intr'adevar sunt vechituri care nu mai merg..cum am mai zis:Daca e nefolositor sa stearga un admin postul..Daca nu revin pe diseara cu inceputul:operatori logici,sintaxe si binding intre sintaxe. Quote