Google Hacking Database (GHDB)

Search the Google Hacking Database or browse GHDB categories

Files containing juicy info

No usernames or passwords, but interesting stuff none the less.

DATE Title Summary
2004-11-21 intitle:"Apache::Status" (inurl:server-s... The Apache::Status returns information about the server software, operating system, number of c...
2004-11-18 intitle:"PhpMyExplorer" inurl:"inde... PhpMyExplorer is a PHP application that allows you to easily update your site online without an...
2004-11-18 filetype:myd myd -CVS MySQL stores its data for each database in individual files with the extension MYD.An attacker ...
2004-11-16 filetype:config web.config -CVS Through Web.config an IIS adminstrator can specify settings like custom 404 error pages, authen...
2004-11-16 filetype:ns1 ns1 Netstunbler files contain information about the wireless network. For a cleanup add stuff like:...
2004-11-16 ext:cgi inurl:editcgi.cgi inurl:file= This was inspired by the K-Otic report. Only two results at time of writing. The cgi script let...
2004-11-12 filetype:pst pst -from -to -date Finds Outlook PST files which can contain emails, calendaring and address information....
2004-11-07 inurl:"putty.reg" This registry dump contains putty saved session data. SSH servers the according usernames and p...
2004-11-07 ext:conf NoCatAuth -cvs NoCatAuth configuration file. This reveals the configuration details of wirless gateway includi...
2004-11-05 "Certificate Practice Statement" inurl:(... Certificate Practice Statement (CPS)A CPS defines the measures taken to secure CA operation an...
2004-11-05 filetype:inf inurl:capolicy.inf The CAPolicy.inf file provides Certificate Servicces configuration information, which is read d...
2004-10-31 filetype:php inurl:index inurl:phpicalendar -site:... PHP iCalendar is a php-based iCal file parser. Its based on v2.0 of the IETF spec. It displays ...
2004-10-31 intitle:"Web Server Statistics for ****" These are www analog webstat reports. The failure report shows information leakage about databa...
2004-10-31 intitle:"AppServ Open Project" -site:www... AppServ is the Apache/PHP/MySQL open source software installer packages. This normally includes...
2004-10-24 intitle:"Index of" upload size parent di... Files uploaded through ftp by other people, sometimes you can find all sorts of things from mov...
2004-10-20 inurl:log.nsf -gov Domino is server technology which transforms Lotus Notes® into an Internet a...
2004-10-20 ext:nsf nsf -gov -mil Domino is server technology which transforms Lotus Notes® into an Internet a...
2004-10-19 intitle:"index.of *" admin news.asp conf... With Compulive News you can enter the details of your news items onto a webform and upload imag...
2004-10-18 inurl:cgi-bin/testcgi.exe "Please distribute ... Test CGI by Lilikoi Software aids in the installation of the Ceilidh discussion engine for the ...
2004-10-18 ext:mdb inurl:*.mdb inurl:fpdb shop.mdb The directory "http:/xxx/fpdb/" is the database folder used by some versions of Front...
2004-10-16 ext:ini intext:env.ini This one shows configuration files for various applications. based on the application an attack...
2004-10-16 "Installed Objects Scanner" inurl:defaul... Installed Objects Scanner makes it easy to test your IIS Webserver for installed components. In...
2004-10-16 intitle:"ASP Stats Generator *.*" "... ASP Stats Generator is a powerful ASP script to track web site activity. It combines a server s...
2004-10-09 inurl:odbc.ini ext:ini -cvs This search will show the googler ODBC client configuration files which may contain usernames/d...
2004-10-05 intext:SQLiteManager inurl:main.php sQLiteManager is a tool Web multi-language of management of data bases SQLite. # Management of...
2004-09-29 +":8080" +":3128" +":80&q... With the string [+":8080" +":3128" +":80" filetype:txt] it is pos...
2004-09-23 inurl:/_layouts/settings With the combined collaboration features of Windows SharePoint Services and SharePoint Portal S...
2004-09-23 ext:ldif ldif www.filext.com says LDIF = LDAP Data Interchange Format.LDAP is used for nearly everything in o...
2004-09-11 filetype:pst inurl:"outlook.pst" All versions of the popular business groupware client called Outlook have the possibility to st...
2004-09-22 filetype:vcs vcs Filext.com says: "Various programs use the *.VCS extension; too many to list individually....
2004-09-21 ext:log "Software: Microsoft Internet Informa... Microsoft Internet Information Services (IIS) has log files that are normally not in the docroo...
2004-09-18 Lotus Domino address books This search will return any Lotus Domino address books which may be open to the public. This ca...
2004-09-18 filetype:asp DBQ=" * Server.MapPath("*.m... This search finds sites using Microsoft Access databases, by looking for the the database conne...
2004-09-10 filetype:pdb pdb backup (Pilot | Pluckerdb) Hotsync database files can be found using "All databases on a Palm device, including the o...
2004-09-10 filetype:xls inurl:"email.xls" Our forum members never get tired of finding juicy MS office files. Here's one by urban that fi...
2004-09-10 filetype:pot inurl:john.pot John the Ripper is a popular cracking program every hacker knows. It's results are stored in a ...
2004-09-07 filetype:reg "Terminal Server Client" These are Microsoft Terminal Services connection settings registry files. They may sometimes co...
2004-09-07 filetype:rdp rdp These are Remote Desktop Connection (rdp) files. They contain the settings and sometimes the cr...
2004-09-07 inurl:snitz_forums_2000.mdb The SnitzTM Forums 2000 Version 3.4.04 Installation Guide and Readme says: "it is strongl...
2004-09-06 filetype:bkf bkf This search will show backupfiles for xp/2000 machines.Of course these files could contain near...