Google hacking is a technique in which we make complex queries in Google in order to extract the information that we can use to hack website and many more stuff. Google hacking technique don't hack a website, but it provides information that assisst in hacking. This information is not available by making simple query in google.
Many people have misconsideration that in this technique we hack google.com, this is incorrect we don't hack google.com, no one does (after all it is a great search engine ;-) )
Before trying ur hand on google hacking I would like u to take care of some tips.
1. Don't use Google chrome for google hacking.
2. Open google.com now if u see ur email id on top right corner of ur browser then sign out first before performing google hacking.
3. Every website is not vulnerable to google hacking.
4. "|" used in google hacking means OR.
So now how to make complex queries. Complex queries are made by using google operators and ur innovation. There are several operators each have different function and give different result when used in google search query. But it depends upon ur thinking power that how u make a query to find specific results. You can also use more than one operator at a time.Lets start with all operators 1 by 1.
1. Site operator:
This operator is basically used for searching basic information about a target website.
type in google the following:
site:website address
Following is example to how to use it:
type site:yahoo.com in google and see the results. You can now see all the other domains of yahoo.com. you can use any site instead of yahoo.com
Howover u may be thinking this information is very common. But hackers uasually use this information to learn all the links of a site.
A long time before I tried site:hotmail.com in google query and i got so only 2 links in result. And u may not believe me that when I examined those urls they contained username and password. But when i tried to login those account it just failed.
2. intitle:index.of
This operator provides universal directory listing. It most works on apache based servers.
for this type follwoing in google:
intitle:index.of
you can also use it for specific websites like as following:
site:yahoo.com intitle:index.of
site:naukri.com intitle:index.of
3. Error|Warning
This operator can reveal gr8 information about target.This operator provide the information related to error that have occured on a website. This can reveal the applications used, OS etc of web server. Following must be entered in google:
intitle:error|warning
or try this
intitle:index.of intitle:error
for example enter the following in google and hit enter to see the results:
intitle:error
4. login|logon
This operator can reveal information regarding the login process. This operator can aslo reveal information containing email addresses, phone numbers or URLs of human assistants who can help who has trouble due to lost password. This assisstant help desk persons are perfect target of Social Engineering. Type the following in google:
login|logon
for example enter the following in google and search.
site:kreeda.com login|logon
5. Username|Userid|employe.id|your username is
This operator can be used to obtain username from target. You sholud use "your username is" string with intext operator. like intext:"your uesrname is"
Enter the follwoing code in Google:
username|userid|employee.id|your username is
if u get username then u can try to get the password of that site.
for example enter the following code to see in results u can get username of some persons:
site:myspace.com username|userid|employee.id|your username is
or
site:myspace.com intext:username|userid|employee.id|your username is
6. password|passcode|passkey|key|pwd|your password is
This operator can be used to reveal password from a website. It could also reveal the login authentication procedure. This query must used with site operator for specific results.
Enter the follwoing in google:
password|passcode|key|pwd|your password is
7. admin|administrator
This operator can get information about admin of website. However this operator give many irrevelant results too. Many times when error occurs we are provided with message to contact o administrator. So this query can also lead u too such results.
type followng in google:
admin|administrator
8. admin logon
This operator can reveal the admin login pages that is the page where admin logins a website.
However this operator needs to be used along with inurl operator for better results. like
inurl:admin logon
If u get password of admin then u can own a site.
9. -ext or filetype:
This operator is similar to operator filetype: Both operators can be used to get file os particular formats -ext is synonym of filetype: operator. -ext is -ve operator that means it wont give any result if used alone. So use it with site: operator like: site:website name -ext:pdf
In case of filetype: operator. For eg. if u want to get file of pdf format then type follwoing in google:
filetype:pdf
It will give u all pdf files. but if u want a specific pdf file like crypto.pdf then try following
code in google:
intext:crypto filetype:pdf
This operator is very important if u are looking for some specfic file on internet. eg. Suppose u want a file named crypto.mp3 from a specific website www.songslover.com then in order to find such file type u shall type follwoing code:
site:songslover.com intext:crypto filetype:mp3
This operator can be used to search books, software, songs, videos, games etc.
try this :
filetype:pdf intext:Hacking
The filetype: operator can aslo be used to get passwords. For example we can search specific registry files that can contain password. The password is usually in encrypted form or in hexadecimal.
type following in google:
filetype:reg intext:"internet account manager"
similarily u can extract passwords from a .mdb, .pwd and other database extension files.
try this:
filetype:pwd intext:"password is"|"passcode"
try this:
filetype:pwd inurl:_vti_pvt inurl:authors|administrators
10. inurl:temp|inurl:tmp|inurl:backup|inurl:bak
This operator basically searches for backup files on internet. This operator must be used with site: operator in order to find temperory or backup files of the target website. The temperory files and backup files can contain sensitive information.
The above query can also be written as inurl:temp|temperory|bak|backup
but remember when we use lots of OR's that is "|" in our query then we don't get much good results.
11. inurl:
This operator is also very useful one. Suppose u want to get the names of websites that contain a specific word. Then use this operator to assisst u. just type follwoing in google:
inurl:keyword
here keyword is the word that u want in url or web address.for eg. if I enter following in google:
inurl:crypto36
you can see it gives URLs that belong to my blogspot...!!!
Remember:
1. Avoid using lot of "|" in query.
2. The google hacking depends on ur thinking power & innovation. you can create ur own queries
by using different operators.
3. Every website is not vulnerable to google hacking. Besause of awareness of google hacking
many websites have started avoiding their specific pages to be displayed in google's result.
For example as i told u before the case of site:hotmail.com , now u wont find that result that i saw
year ago.
Here are some more queries that you can try. Type in google the following queries and see the results :