, b" p& A6 A* b* ]0 R9 L7 c
( v* l" ^6 k" o G& D! U1 K, c5 W3 Q刚收到的jp,激动了一下。童鞋们,给个币币吧
$ J, v0 n4 B) T) Q8 {按照惯例,继续分享经验+ D& Y6 Y4 L* K. U7 I4 r1 R" b8 u
) }3 @9 u8 D+ w% b% L9 X- F经验分享:
% }. u2 i0 X$ I! Q. O3 E" W9 B# X! M活用GG,可以说gg里面无所不有,上次已经说过google hacking是一本不错的技术手册,建议大家买一本纸质放在手边,随时查阅。现将一些经常用到的列一下
8 e3 s& p0 h J3 b# x0 S& t5 P; j3 r2 {. D F. V. v
.asp ――》filetype 标题――》intitle 页面文字――》intext 页面编号――》numeange - 逻辑非,“A-B”表示包含A没有B的网页 *代表单个字符 or操作 “”用短语做关键字,必须加上引号,不然会被当作与操作 .空格 Google对一些网路上出现频率极高的英文单词,如“i”、“com”、“www”等,以及一些符号如“*”、“.”等,作忽略处理 可以用+强制搜索 下面的语句是我搜集来的,大家可以试着用下 比如用Intitle:welcome.to.iis.4.0 IIS4会找到好多winNT的主机,呵呵 Site:sohu.com Intitle:index.of/admin Intitle:index.of apache server.at Intitle:test.page.for.apache “it workd” Allintitle:Netscape Fasr Track Server Home Page Intitle:”welcome to windows 2000 internet services” IIS—win2000 Allintitle:welcome to windows XP server internet services iis---XP Intitle:welcome.to.iis.4.0 IIS4 Allintrtle:”welcome to internet information server” IIS-- generic Intitle:”apache http server” Intitle:”documentation” Intitle:””error using hypernews””server software” “HTTP_USER_AGENT=Googlebot” “HTTP_USER_AGENT=Googlebot”TNS_ADMIN Inurl:/admin/login.asp Intitle:”remote desktop wen connection” “welcome to *” “Your password is *” Inurl(browse top_rated power_search hot create_admin_user)+”powered by inde xu” “adding new user” inurl:addnewuser –“there are no domain” Filetype:log inurl:”password.log” Intitle:”PHP Shell *” “enable stderr” filetype:php Intitle:confixx login password “powered by rover” Inurl:iisadmpwd Inurl:5800 “VNC desktop” inurl:5800 Inurl:webmin inurl:10000 Inurl:8080 –intext:8080 “access denird for user” “using password” “# Dumping data for table” “# Dumping data for table” username password “# Dumping data for table (username user users password)” Inurl:main.php welcome to phpmyadmin Intitle:”phpmyadmin running on *” welcome to phpmyadmin Filetype:inc intext:mysql connect Filetype:sql + “INENTIFIED BY” –cvs Filetype:sql + “INENTIFIED BY” (“grant * on *” “create user”) “this report lists” “identified by internet scaner” ACID “by roman danyliw” Filetype:PHP / {9 l" `9 ?& |' c( G0 R% [
, B; K- k! f* c7 b# X2 A/ r
: W. {( w# z% b
补充内容 (2013-7-24 21:50):" F2 I/ ?3 T- U# L A) p$ U
都是来吹风的,寒心+ W: t" N; V' V. u6 c
4 H2 O4 @+ q! `/ _9 v4 u4 c$ [补充内容 (2013-7-24 22:02):
4 z8 \! \ h1 U; Q. W5 ahttp://www.cnwebmasters.com/thread-108451-1-1.html |