June 20, 2008

Google - Tips & Tricks

. June 20, 2008

Google - Tips & Tricks



Method 1:

www.google.com

Put this
string in google search:

"parent directory " /appz/ -xxx -html -htm -php
-shtml -opendivx -md5 -md5sums

"parent directory " DVDRip -xxx -html -htm
-php -shtml -opendivx -md5 -md5sums

"parent directory "Xvid -xxx -html
-htm -php -shtml -opendivx -md5 -md5sums

"parent directory " Gamez -xxx
-html -htm -php -shtml -opendivx -md5 -md5sums

"parent directory " MP3
-xxx -html -htm -php -shtml -opendivx -md5 -md5sums

"parent directory "
Name of artist or album -xxx -html -htm -php -shtml -opendivx -md5
-md5sums

Notice that only the search-phrase after “parent directory”
change, and you can use whatever phrase or word that suits you and a lot of
otherwise hidden links will turn
up.

===========================


Method 2:

www.google.com

Put this
string in google search:

?intitle:index.of? mp3

You only need to
add the name of the song/album/artist/singer
Example:
?intitle:index.of?
mp3 jackson

==============================


Method 3:

www.google.com

Put this
string in google search:

inurl:Mcft filetype:iso

You can change
the search-string to excactly what you desire, eg: Mcft to adobe, ISO to zip/rar
and so on.

Also check this out:
http://www.googleguide.com/advanced_operators.html



================



How
to search for Warez In GOOGLE?, Help this topic to
grow!!!!!!!!!


Everyone knows google in the security sector...and what
a powerful tool it is, just by entering certain search strings you can gain a
vast amount of knowledge and information of your chosen target...often revealing
sensitive data...this is all down to badly configured systems...brought on by
sloppy administration allowing directory indexing and accessing , password
files, log entrys, files, paths, etc , etc


Search Tips so how do we
start ?

the common search inputs below will give you an idea...for
instance if you
want to search for the an index of "root"

in the
search box put in exactly as you see it
below

==================

Example 1:

allintitle: "index
of/root"

result:

http://www.google.com/search?hl=en&ie=ISO-...G=Google+Search

what
it reveals is 2,510 pages that you can possible browse at your
will...

====================

Example
2:

inurl:"auth_user_file.txt"

http://www.google.com/search?num=100&hl=en...G=Google+Search

this
result spawned 414 possible files to access

here is an actual file
retrieved from a site and edited , we know who the
admin is and we have the
hashes thats a job for JTR (john the
ripper)

txUKhXYi4xeFs|master|admin|Worasit|Junsawang|xxx@xxx|on
qk6GaDj9iBfNg|tomjang||Bug|Tom|xxx@xxx|on

with
the many variations below it should keep you busy for a long time mixing them
reveals many different
permutations

*************************************

SEARCH
PATHS....... more to be
added

*************************************

"Index of
/admin"
"Index of /password"
"Index of /mail"
"Index of /"
+passwd
"Index of /" +password.txt
"Index of /" +.htaccess
index of ftp
+.mdb allinurl:/cgi-bin/
+mailto

administrators.pwd.index
authors.pwd.index
service.pwd.index
filetype:config
web
gobal.asax index

allintitle: "index of/admin"
allintitle:
"index of/root"
allintitle: sensitive filetype:doc
allintitle: restricted
filetype :mail
allintitle: restricted filetype:doc
site:gov

inurl:paqswd filetype:txt
inurl:admin
filetype:db
inurl:iisadmin
inurl:"auth_user_file.txt"
inurl:"wwwroot/*."


top
secret site:mil
confidential site:mil

allinurl: winnt/system32/ (get
cmd.exe)
allinurl:/bash_history

intitle:"Index of"
.sh_history
intitle:"Index of" .bash_history
intitle:"index of"
passwd
intitle:"index of" people.lst
intitle:"index of"
pwd.db
intitle:"index of" etc/shadow
intitle:"index of"
spwd
intitle:"index of" master.passwd
intitle:"index of"
htpasswd
intitle:"index of" members OR accounts
intitle:"index of"
user_carts OR user_cart

ALTERNATIVE
INPUTS====================

_vti_inf.html
service.pwd
users.pwd
authors.pwd
administrators.pwd
shtml.dll
shtml.exe
fpcount.exe
default.asp
showcode.asp
sendmail.cfm
getFile.cfm
imagemap.exe
test.bat
msadcs.dll
htimage.exe
counter.exe
browser.inc
hello.bat
default.asp
dvwssr.dll
cart32.exe
add.exe
index.jsp
SessionServlet
shtml.dll
index.cfm
page.cfm
shtml.exe
web_store.cgi
shop.cgi
upload.asp
default.asp
pbserver.dll
phf
test-cgi
finger
Count.cgi
jj
php.cgi
php
nph-test-cgi
handler
webdist.cgi
webgais
websendmail
faxsurvey
htmlscript
perl.exe
wwwboard.pl
www-sql
view-source
campas
aglimpse
glimpse
man.sh
AT-admin.cgi
AT-generate.cgi
filemail.pl
maillist.pl
info2www
files.pl
bnbform.cgi
survey.cgi
classifieds.cgi
wrap
cgiwrap
edit.pl
perl
names.nsf
webgais
dumpenv.pl
test.cgi
submit.cgi
guestbook.cgi
guestbook.pl
cachemgr.cgi
responder.cgi
perlshop.cgi
query
w3-msql
plusmail
htsearch
infosrch.cgi
publisher
ultraboard.cgi
db.cgi
formmail.cgi
allmanage.pl
ssi
adpassword.txt
redirect.cgi
cvsweb.cgi
login.jsp
dbconnect.inc
admin
htgrep
wais.pl
amadmin.pl
subscribe.pl
news.cgi
auctionweaver.pl
.htpasswd
acid_main.php
access.log
log.htm
log.html
log.txt
logfile
logfile.htm
logfile.html
logfile.txt
logger.html
stat.htm
stats.htm
stats.html
stats.txt
webaccess.htm
wwwstats.html
source.asp
perl
mailto.cgi
YaBB.pl
mailform.pl
cached_feed.cgi
global.cgi
Search.pl
build.cgi
common.php
show
global.inc
ad.cgi
WSFTP.LOG
index.html~
index.php~
index.html.bak
index.php.bak
print.cgi
register.cgi
webdriver
bbs_forum.cgi
mysql.class
sendmail.inc
CrazyWWWBoard.cgi
search.pl
way-board.cgi
webpage.cgi
pwd.dat
adcycle
post-query
help.cgi


there are to many
people to thank for the bits of information cut and pasted and added to form
this paper most have been collected from various forums , txt , doc's etc...like
to thank you all, its not intended to rip anyone its just a combo of various
search inputs...put on the one Paper to use as a reference.


German
manual:
http://www.stephan-bender.de/download/its_tutorials/google/geheime%20google%20tipps.pdf

"parent
directory " /appz/ -xxx -html -htm -php -shtml -opendivx -md5
-md5sums

"parent directory " DVDRip -xxx -html -htm -php -shtml -opendivx
-md5 -md5sums

"parent directory "Xvid -xxx -html -htm -php -shtml
-opendivx -md5 -md5sums

"parent directory " Gamez -xxx -html -htm -php
-shtml -opendivx -md5 -md5sums

"parent directory " Name of Singer or
album -xxx -html -htm -php -shtml -opendivx -md5 -md5sums


http://www.google.com/search?hl=en&lr=&ie=UTF-8&q=inurl%3Amicrosoft+filetype%3Aiso&btnG=Search


http://www.google.com/search?hl=en&lr=&ie=UTF-8&q=inurl%3Amicrosoft+%22msdn%22+filetype%3Amsi&btnG=Search

http://www.google.com/search?hl=en&lr=&ie=UTF-8&q=inurl%3Alonghorn+%22leaked%22&btnG=Search

http://www.google.com/search?hl=en&lr=&ie=UTF-8&q=inurl%3Aoffice+filetype%3Aiso&btnG=Search

http://www.google.com/search?hl=en&lr=&ie=UTF-8&q=inurl%3Apanther+filetype%3Aiso&btnG=Search

http://www.google.com/search?hl=en&lr=&ie=UTF-8&q=inurl%3Amicrosoft+filetype%3Aiso+%22server%22&btnG=Search

http://www.google.com/search?hl=en&lr=&ie=UTF-8&q=inurl%3Aantivirus++filetype%3Aiso&btnG=Search

What
u think? Yes, google is a powerfull instrument:


http://www.wolfgarten.com/downloads/Watch_out_google.pdf


http://johnny.ihackstuff.com/security/premium/The_Google_Hackers_Guide_v1.0.pdf



http://www.law.fsu.edu/current_students/technology/pdf/google.pdf



Other
google Searchtips:

http://"user:password"@site.com/members -> in
search space / user& pwd replace for * and google find the alternatives in
existing pages.-



Hand type the following prefixes and note their
utility:



link:url Shows other pages with links to that
url.

related:url same as "what's related" on serps.

site:domain
restricts search results to the given domain.

allinurl: shows only pages
with all terms in the url.

inurl: like allinurl, but only for the next
query word.

allintitle: shows only results with terms in
title.

intitle: similar to allintitle, but only for the next word.
"intitle:webmasterworld google" finds only pages with webmasterworld in the
title, and google anywhere on the page.

cache:url will show the Google
version of the passed url.

info:url will show a page containing links to
related searches, backlinks, and pages containing the url. This is the same as
typing the url into the search box.

spell: will spell check your query
and search for it.

stocks: will lookup the search query in a stock
index.

filetype: will restrict searches to that filetype. "-filetype:doc"
to remove Mcft word files.

daterange: is supported in Julian date format
only. 2452384 is an example of a Julian date.

maps: If you enter a street
address, a link to Yahoo Maps and to MapBlast will be presented.

phone:
enter anything that looks like a phone number to have a name and address
displayed. Same is true for something that looks like an address (include a name
and zip code)

site:www.somesite.net "+www.somesite.+net"
(tells you
how many pages of your site are indexed by google)

allintext: searches
only within text of pages, but not in the links or page title

allinlinks:
searches only within links, not text or title


Here are some tips to
find eBooks with Google:


Find Apache's (default) Index
page

Try this query:


+("index of") +("/ebooks"|"/book")
+(chm|pdf|zip|rar) +apache



Find a particular eBook
file

Try this query:


allinurl: +(rar|chm|zip|pdf|tgz)
TheTitle


Finding wareshizzle using Google


Disclaimer: This
post is not about encouraging you to download unlicensed software (reads:
w00t!). Use at your own risk.

Finding pirated software is surprisingly
easy with Google. Yes, we have astalavista to find the serial numbers and key
generators, but it might take you a little more time to find the original setup
files, and software that do not use serial numbers to validate the
license.

Enter Google. Google China, to be exact.

It's okay if you
don't read chinese. You just have to know some keywords (with trasnlation below)
to download any files successfully, with the success rate of as high as 100%.
Believe it.

1. First, go to Google China (http://www.google.com/intl/zh-cn/ - the trailing slash is
important).

2. Key in the software name you want to download in the
search field. And remember to check the following option. It tells Google to
look for China only web sites (distinguished by the use of simplified chinese
only characters).





3. Now, look for the following
highlighted keywords:




Hang on cowboy, don't worry if you
don't understand what the heck they mean. The words highlighted in yellow mean
"fixed version", and the words in green mean "download".

4. Follow the
links. Now you will see more chinese characters! Don't worry though, their
layouts are typically the same. Now keep looking for the green keywords above,
they should be at the bottom of the page, or the row of the table that describes
the software. You can usually get to know their ratings too. Talk about
professional w00t!!

5. That's it!

There is absolutely no magic or
advanced techniques to be used here. The root of the problem is, China has way
too many w00t! sites run by individuals, and Google is so far still crawling and
indexing them. The high number of w00t! sites makes Google to usually return
links to w00t! sites on the first page of the results, some even get to ranked
first. And of course, this technique can be used with Google Russia (http://www.google.ru)
too.

The table of translations you might find useful. Of course, do not
hesitate to use some online translation tools like
Babelfish.





Copy and pastable keywords (in chinese. will
be displayed as question marks if not properly encoded):
??, ????, ??, ???,
??, ??, ???, ???, ??.



Find net cams with the following
searches:
inurl:"ViewerFrame?Mode="
intitle:"WJ-NT104 Main
Page"
inurl:netw_tcp.shtml
intitle:"supervisioncam protocol"

These
searches really do turn up some neat stuff.

Try out the searches
here:

inurl:"view/index.shtml"
inurl:"ViewerFrame?Mode="

fficial&start=120&sa=N"
target="_blank" class="postlink">Google -
inurl:"ViewerFrame?Mode="

fficial" target="_blank"
class="postlink">Google - inurl:"view/index.shtml"

That last search
turns up some really good cameras.
Here's a .gov.uk camera that is really
smooth:
http://cam1.east-ayrshire.gov.uk/view/index.shtml

If
you have a webcam on your system, you may want to password protect
it.

EDIT: here's one from Finland:
http://blindedby.it.helsinki.fi/view/index.shtml

Here's
another from a Date Center:
http://195.74.96.252/view/index.shtml?videos=one

Related Posts by Categories



1 comments:

Unknown said...

BBC NewsI hope there will be some good news and some good profits, and people will realize we have a lot of outstanding executives, and a lot of companies that are doing a good job, and those are good companies to invest in.

 
Namablogkamu is proudly powered by Blogger.com | Template by L-W