Google-Dorks-Bug-bounty- Google Dorks列表 用于错误赏金 Web应用程序安全性和pentesting

taibeihacker

Moderator
AVvXsEjw0SFLnTOabwaCF-I0fJ6yf9HM_V7lWJyZlAobhJIAzGdn_CJPabbnBf9lYrvxKLgSP5jXfjQJHQVE3QF96d7DULS1GG5pvCY_a_PwnWTNsWfZv4CALnW3SVIeEmcDyNYqShxDQkjrjqjWNO4U94AiOUbGCBHOxpmDwzmU4-lUnGab3GFyihV4TfGMPqfv=w640-h122

Google Dorks的列表,用于Bug Bounty,Web应用程序安全性和pestesting
实时工具

Broad domain search w/ negative search​

site:Example.com -www -shop -share -ir -mfa

PHP extension w/ parameters​

site:Example.com ext:php inurl:

Disclosed XSS and Open Redirects​

site:openbugbounty.org inurl:reports intext:'example.com'

Juicy Extensions​

site:'example [。] com'ext:log | EXT:TXT | Ext:Conf | EXT:CNF | ext:ini | EXT:ENV | EXT:SH | Ext:bak | ext:backup | EXT:SWP | ext:old | ext:old | Ext:〜 | ext:git | EXT:SVN | EXT:HTPASSWD | EXT:HTACCESS

XSS prone parameters​

inurl:q=| inurl:S=| inurl: -Search=| inurl:query=| inurl:Keyword=| inurl:lang=inurl: site:Example.com

Open Redirect prone parameters​

inurl:url=| inurl:Return=| inurl:Next=| inurl:redirect=| inurl:redir=| inurl:RET=| inurl:r2=| inurl:page=inurl: inurl3:http site:Example.com

SQLi Prone Parameters​

inurl:ID=| inurl:pid=| inurl:category=| inurl:cat=| inurl:Action=| inurl:sid=| inurl:dir=inurl: site:Example.com

SSRF Prone Parameters​

inurl:http | inurl:url=| inurl:path=| inurl:dest=| inurl:html=| inurl:data=| inurl:domain=| inurl:page=inurl: site:Example.com

LFI Prone Parameters​

inurl:include | inurl:dir | inurl:detail=| inurl:file=| inurl:folder=| inurl:inc=| inurl:locate=| inurl:doc=| inurl:conf=inurl: site:example.com

RCE Prone Parameters​

inurl:cmd | inurl:Exec=| inurl:query=| inurl:code=| inurl:do=| inurl:run=| inurl:Read=| inurl:ping=inurl: site:Example.com

High % inurl keywords​

inurl:config | inurl:env | inurl:Setting | inurl:backup | inurl:Admin | inurl:php site:示例[。] com

Sensitive Parameters​

inurl:email=| inurl:phone=| inurl:password=| inurl:secret=inurl: site: example [。] com

API Docs​

inurl:apidocs | inurl:api-docs | inurl:swagger | inurl:api explorer site:'example [。] com'

Code Leaks​

site:pastebin.com'example.com'
site:jsfiddle.net'example.com'
site:codebeautify.org'example.com'
site:codepen.io'example.com'

Cloud Storage​

site:S3.amazonaws.com'example.com'
site:blob.core.windows.net'example.com'
site:googleapis.com'example.com'
site:drive.google.com'example.com'
site:dev.azure.com'示例[。] com'
site:Onedrive.live.com'示例[。] com'
site:digitaloceanspaces.com'示例[。] com'
site:sharepoint.com'示例[。] com'
site:S3-External-1.amazonaws.com'示例[。] com'
site:S3.dualstack.us-east-1.amazonaws.com'示例[。] com'
site:dropbox.com/s'示例[。] com'
site:box.com/s'示例[。] com'
site:docs.google.com inurl:'/d/''example [。] com'

JFrog Artifactory​

site:jfrog.io'示例[。] com'

Firebase​

site:firebaseio.com'示例[。] com'

File upload endpoints​

site:Example.com'选择文件'

Dorks that work better w/o domain​

Bug Bounty programs and Vulnerability Disclosure Programs​

'提交漏洞报告'| “由Bugcrowd驱动” | “由黑客动力”
site:*/security.txt'赏金'

Apache Server Status Exposed​

site:*/server-status apache

WordPress​

inurl:/wp-admin/admin-ajax.php

Drupal​

Intext:''Intext:drupal inurl:user

Joomla​

site:*/joomla/login
更多狗的中等文章:
顶部参数:
Propiesec Dorks:
 
返回
上方