Search the Google Hacking Database or browse GHDB categories
|2015-06-30||intitle:"Index of" "wwwroot"||Sensitive Directories|
|2015-06-30||"Futon on Apache" inurl:_utils||Files containing juicy info|
|2015-06-30||phpMyAdmin SQL Dump||Files containing juicy info|
|2015-06-30||site:pastebin.com intext:Username||Files containing passwords|
|2015-06-24||inurl:Citrix/MetaframeXP||Pages containing login portals|
|2015-06-24||"signons.sqlite" intitle:"index of"||Files containing juicy info|
|2015-06-23||Auth inurl:welcome ext:cgi||Pages containing login portals|
|2015-06-23||ext:asp intext:Smart.Shell 1.0 BY P0Uy@_$3r\/3R -||Footholds|
|2015-06-23||filetype:asmx inurl:(_vti_bin|api|webservice)||Web Server Detection|
|2015-06-17||intitle:"Index Of" intext:"iCloud Photos" OR intext:"My Photo Stream" OR intext:"Camera Roll"||Sensitive Directories|
Google's collection of web sites sharing sensitive directories. The files contained in here will vary from sesitive to uber-secret!
These searches reveal servers with specific vulnerabilities. These are found in a different way than the searches found in the "Vulnerable Files" section.
These pages contain such things as firewall logs, honeypot logs, network information, IDS logs... all sorts of fun stuff!
These files contain usernames, but no passwords... Still, google finding usernames on a web site..
Examples of queries that can reveal online shopping info like customer data, suppliers, orders, creditcard numbers, credit card info, etc
These are login pages for various services. Consider them the front door of a website's more sensitive functions.
These searches locate vulnerable servers. These searches are often generated from various security advisory posts, and in many cases are product or version-specific.