LAB 01

Google Dorking Manual

Advanced search operator ka use karke sensitive information nikalna.

30 Essential Dork Commands

Ghabrana nahi hai! In commands ko samajhna asan hai. Ye sirf Google ko "Filter" karne ke tarike hain.

Command Kyu Use Karein? (Purpose)
intitle:"index of"Open directories dhundne ke liye (Files list).
filetype:pdfSirf PDF files search karne ke liye.
site:example.comSearch ko sirf ek website tak limit karne ke liye.
inurl:adminUn URLs ke liye jisme 'admin' word ho.
intext:"password"Page ke content mein 'password' word dhundna.
cache:example.comWebsite ka purana (cached) version dekhna.
related:target.comTarget se milti-julti websites dhundna.
ext:logLog files (.log) dhundne ke liye.
intitle:"login"Login pages search karne ke liye.
"confidential" filetype:docConfidential documents dhundna.
allinurl:auth loginMultiple words URL mein dhundna.
site:*.govSirf government domains search karna.
inurl:wp-contentWordPress based websites target karna.
intitle:"webcamXP 5"Vulnerable webcams dhundna (Educational).
filetype:sql "INSERT INTO"Database backups dhundne ke liye.
intext:"sql syntax error"Vulnerable SQL sites dhundna.
"internal use only"Private documents search karna.
intitle:"Index of" config.phpConfiguration files dhundna.
inurl:phpinfo()Server information pages check karna.
allintext:username passwordText mein dono words dhundna.
filetype:envSensitive environment files dhundna.
inurl:ftpOpen FTP servers search karna.
site:pastebin.com "target"Leaks dhundna Pastebin par.
ext:xls "email"Email lists dhundne ke liye.
intitle:"Dashboard" site:comAdmin dashboards dhundna.
inurl:/etc/passwdLinux sensitive files (Agar exposed ho).
filetype:bkpBackup files dhundna.
"API_KEY" ext:jsonExposed API keys dhundna.
inurl:cgi-binOld scripts dhundna.
site:github.com "password"GitHub leaks check karna.

Step 1: Objective Setup

Sabse pehle decide karein ki aapko kya dhundna hai. Example: Humein Example.com website ke exposed PDF documents chahiye.

Step 2: Crafting the Dork

Apna dork taiyar karein. Hum combining techniques use karenge:

site:example.com filetype:pdf

Ise Google search bar mein paste karein aur Enter dabayein.

Step 3: Analysis

Results ko dhyan se dekhein. Kya koi document "Confidential" ya "Internal" mark hai? Agar haan, toh wo ek potential security leak hai.

💡 Pro Tip: Agar Google "Captcha" maange, toh ghabrana nahi. Aap bahut fast search kar rahe hain isliye Google confirm kar raha hai ki aap robot nahi hain.

Step 4: Ethical Responsibility

Google Dorking legal hai jab tak aap public information dekh rahe hain. Lekin kisi ke private data ka galat use karna illegal hai. Hamesha White Hat bane rahein.