Google Hacking For Auditors (3/2022)
Google Hacking For Auditors (3/2022)
Search Engines
• Org chart
• Documentatio
• Report
• SOP
• Contact informatio
• Training
5
s
6
7
Search Engines
8
.
site
Site:gwu.edu “CFO”
9
:
10
Google Search Operators
inurl
site:umd.edu inurl:logi
11
.
12
Google Search Operators
intext
13
:
14
Google Search Operators
filetype
site:*.edu filetype:pe
15
:
16
17
18
Google Search Operators
inanchor
19
:
20
21
Other useful tricks
• Usethe minus sign (-) to exclude terms from your
search. One that I frequently use is -inurl:www as it
will exclude all sites with www in the url and show me
other subdomains
• before:YYYY-MM-DD or after:YYYY-MM-DD
22
.
23
Google Hacking Database
• https://www.exploit-db.com/google-hacking-database
• Databaseof Google search queries to help you find
specific technologies, devices, and much more.
24
25
26
Google Dorking Exercise (10 minutes)
27
?
• https://www.google.com/imghp?hl=en&ogbl
• Uploador link a photo and let Google find a matching
photo for you.
29
30
31
32
33
Reverse Image Search
• https://yandex.com/images/
• Yandexreverse image search can also return some useful
results.
34
Cached Pages
• Dependingon the nature of our investigation, we may
not want to visit any of the sites that we find.
Rather, let’s look for cached pages
35
.
36
37
Internet Archive
• The Internet never forgets…thanks to the Internet
Archiv
• https://archive.org/web
• The Internet Archive may have information that is not
otherwise available via a Google Search (cached or
live)
38
e
Google Alerts
• Google Alerts are a great way to create search queries
that will automatically return results if that criteria
is met
• Visit google.com/alerts
39
.
40
Wrapping Up
• Googleis an incredibly powerful tool for gathering
information about just about anything
41
.
Say hello
@maru3
[email protected]
42
7