Hacker's Favorite Search Queries 3 Note: To be used as Google search query like "www.google.com/search?q=Search text" Beware! Make use of these infos goes at your own risk! LeapFTP intitle:"index.of./" sites.ini modified master.passwd mysql history files NickServ registration passwords passlist passlist.txt (a better way) passwd passwd / etc (reliable) people.lst psyBNC config files pwd.db signin filetype:url spwd.db / passwd trillian.ini wwwboard WebAdmin inurlasswd.txt wwwboard|webadmin "# -FrontPage-" extwd inurlservice | authors | administrators | users) "# -FrontPage-" inurl:service.pwd "AutoCreate=TRUE password=*" "http://*:*@www" domainname "index of/" "ws_ftp.ini" "parent directory" "liveice configuration file" ext:cfg -site:sourceforge.net "powered by ducalendar" -site:duware.com "Powered by Duclassified" -site:duware.com "Powered by Duclassified" -site:duware.com "DUware All Rights reserved" "powered by duclassmate" -site:duware.com "Powered by Dudirectory" -site:duware.com "powered by dudownload" -site:duware.com "Powered By Elite Forum Version *.*" "Powered by Link Department" "sets mode: +k" "Powered by DUpaypal" -site:duware.com allinurl: admin mdb auth_user_file.txt config.php eggdrop filetype:user user etc (index.of) ext:ini eudora.ini ext:ini Version=... password ext:txt inurl:unattend.txt filetype:bak inurl:"htaccess|passwd|shadow|htusers" filetype:cfg mrtg "target " -sample -cvs -example filetype:cfm "cfapplication name" password filetype:conf oekakibbs filetype:conf sc_serv.conf filetype:conf slapd.conf filetype:config config intext:appSettings "User ID" filetype:dat "password.dat" filetype:dat wand.dat filetype:inc dbconn filetype:inc intext:mysql_connect filetype:inc mysql_connect OR mysql_pconnect filetype:inf sysprep filetype:ini inurl:"serv-u.ini" filetype:ini inurl:flashFXP.ini filetype:ini ServUDaemon filetype:ini wcx_ftp filetype:ini ws_ftp pwd filetype:ldb admin filetype:log "See `ipsec copyright" filetype:log inurl:"password.log" filetype:mdb inurl:users.mdb filetype:mdb wwforum filetype:netrc password filetypeass pass intext:userid filetypeem intextrivate filetyperoperties inurl:db intextassword filetypewd service filetypewl pwl filetype:reg reg +intext:"defaultusername" +intext:"defaultpassword" filetype:reg reg HKEY_CURRENT_USER SSHHOSTKEYS filetype:sql ("values * MD" | "values * password" | "values * encrypt") filetype:sql ("passwd values" | "password values" | "pass values" ) filetype:sql +"IDENTIFIED BY" -cvs filetype:sql password filetype:url +inurl:"ftp://" +inurl:";@" filetype:xls username password email htpasswd htpasswd / htgroup htpasswd / htpasswd.bak intext:"enable secret $" intext:"powered by Web Wiz Journal" intitle:"index of" intext:connect.inc intitle:"index of" intext:globals.inc intitle:"Index of" passwords modified intitle:dupics inurladd.asp | default.asp | view.asp | voting.asp) -site: duware.com intitle:index.of administrators.pwd intitle:Index.of etc shadow intitle:index.of intext:"secring.skr"|"secring.pgp"|"secring.bak" inurl:"GRC.DAT" intext:"password" inurl:"slapd.conf" intext:"credentials" -manpage -"Manual Page" -man: -sample inurl:"slapd.conf" intext:"rootpw" -manpage -"Manual Page" -man: -sample inurl:"wvdial.conf" intext:"password" inurl:/db/main.mdb inurl:/wwwboard inurl:ccbill filetype:log inurl:chap-secrets -cvs inurl:config.php dbuname dbpass inurl:filezilla.xml -cvs inurl:lilo.conf filetype:conf password -tatercounter -bootpwd -man inurl:nuke filetype:sql inurlspfd.conf intextassword -sample -test -tutorial -download inurlap-secrets -cvs inurlerform filetype:ini inurl:secring ext:skr | extgp | ext:bak inurl:vtund.conf intextass -cvs inurl:zebra.conf intextassword -sample -test -tutorial -download "Generated by phpSystem" "generated by wwwstat" "Host Vulnerability Summary Report" "HTTP_FROM=googlebot" googlebot.com "Server_Software=" "Index of" / "chat/logs" "Installed Objects Scanner" inurl:default.asp "Mecury Version" "Infastructure Group" "Microsoft (R) Windows * (TM) Version * DrWtsn Copyright (C)" ext:log "Most Submitted Forms and Scripts" "this section" "Network Vulnerability Assessment Report" "not for distribution" confidential "phone * * *" "address *" "e-mail" intitle:"curriculum vitae" "phpMyAdmin" "running on" inurl:"main.php" "produced by getstats" "Request Details" "Control Tree" "Server Variables" "robots.txt" "Disallow:" filetype:txt "Running in Child mode" "sets mode: +p" "sets mode: +s" "Thank you for your order" +receipt "This is a Shareaza Node" "This report was generated by WebLog" ( filetype:mail | filetype:eml | filetype:mbox | filetype:mbx ) intextassword| subject (inurl:"robot.txt" | inurl:"robots.txt" ) intext:disallow filetype:txt +":" +":" +":" filetype:txt +"HSTSNR" -"netop.com" -sitehp.net -"The PHP Group" inurl:source inurl:url extHp FBR "ADOBE PHOTOSHOP" AIM buddy lists allinurl:/examples/jsp/snp/snoop.jsp allinurl:servlet/SnoopServlet cgiirc.conf cgiirc.conf data filetype:mdb -site:gov -site:mil exported email addresses ext:asp inurlathto.asp ext:cgi inurl:editcgi.cgi inurl:file= ext:conf inurl:rsyncd.conf -cvs -man ext:conf NoCatAuth -cvs ext:dat bpk.dat ext:gho gho ext:ini intext:env.ini ext:ldif ldif ext:log "Software: Microsoft Internet Information Services *.*" ext:mdb inurl:*.mdb inurl:fpdb shop.mdb ext:nsf nsf -gov -mil extqi pqi -database ext:reg "username=*" putty ext:txt "Final encryption key" ext:txt inurl:dxdiag ext:vmdk vmdk ext:vmx vmx filetype:asp DBQ=" * Server.MapPath("*.mdb") filetype:bkf bkf filetype:blt "buddylist" filetype:blt blt +intext:screenname filetype:cfg auto_inst.cfg filetype:cnf inurl:_vti_pvt access.cnf filetype:conf inurl:firewall -intitle:cvs filetype:config web.config -CVS filetype:ctt Contact filetype:ctt ctt messenger filetype:eml eml +intext:"Subject" +intext:"From" +intext:"To" filetype:fp fp filetype:fp fp -site:gov -site:mil -"cvs log" filetype:fp fp filetype:inf inurl:capolicy.inf filetype:lic lic intext:key filetype:log access.log -CVS filetype:mbx mbx intext:Subject filetype:myd myd -CVS filetype:ns ns filetypera ora filetypera tnsnames filetypedb pdb backup (Pilot | Pluckerdb) filetypehp inurl:index inurlhpicalendar -site:sourceforge.net filetypeot inurl:john.pot filetypest inurl:"outlook.pst" filetypest pst -from -to -date filetype:qbb qbb filetype:rdp rdp filetype:reg "Terminal Server Client" filetype:vcs vcs filetype:wab wab filetype:xls -site:gov inurl:contact filetype:xls inurl:"email.xls" Financial spreadsheets: finance.xls Financial spreadsheets: finances.xls Ganglia Cluster Reports haccess.ctl (one way) haccess.ctl (VERY reliable) ICQ chat logs, please... iletype:log cron.log intext:"Session Start * * * *:*:* *" filetype:log intext:"Tobias Oetiker" "traffic analysis" intextpassword | passcode) intextusername | userid | user) filetype:csv intext:gmail invite intext:http://gmail.google.com/gmail/a intext:SQLiteManager inurl:main.php intitle:"Apache::Status" (inurl:server-status | inurl:status.html | inurl:apache.html) intitle:"AppServ Open Project" -site:www.appservnetwork.com intitle:"ASP Stats Generator *.*" "ASP Stats Generator" "- weppos" intitle:"Big Sister" +"OK Attention Trouble" intitle:"edna:streaming mp server" -forums intitle:"FTP root at" intitle:"index of" +myd size intitle:"Index Of" -inurl:maillog maillog size intitle:"Index Of" cookies.txt size intitle:"index of" mysql.conf OR mysql_config intitle:"Index of" upload size parent directory intitle:"index.of *" admin news.asp configview.asp intitle:"index.of" .diz .nfo last modified intitle:"Multimon UPS status page" intitle:"PHP Advanced Transfer" (inurl:index.php | inurl:showrecent.php ) intitle:"PhpMyExplorer" inurl:"index.php" -cvs intitle:"statistics of" "advanced web statistics" intitle:"System Statistics" +"System and Network Information Center" intitle:"Usage Statistics for" "Generated by Webalizer" intitle:"wbem" compaq login "Compaq Information Technologies Group" intitle:"Web Server Statistics for ****" intitle:"web server status" SSH Telnet intitle:"welcome.to.squeezebox" intitle:admin intitle:login intitle:index.of "Apache" "server at" intitle:index.of cleanup.log intitle:index.of dead.letter intitle:index.of inbox intitle:index.of inbox dbx intitle:index.of ws_ftp.ini intitle:intranet inurl:intranet +intext:"phone" inurl:"/axs/ax-admin.pl" -script inurl:"/cricket/grapher.cgi" inurl:"bookmark.htm" inurl:"cacti" +inurl:"graph_view.php" +"Settings Tree View" -cvs -RPM inurl:"newsletter/admin/" inurl:"newsletter/admin/" intitle:"newsletter admin" inurl:"putty.reg" inurl:"smb.conf" intext:"workgroup" filetype:conf conf inurl:*db filetype:mdb inurl:/_layouts/settings inurl:admin filetype:xls inurl:admin intitle:login inurl:backup filetype:mdb inurl:cgi-bin/printenv inurl:cgi-bin/testcgi.exe "Please distribute TestCGI" inurl:changepassword.asp inurl:ds.py inurl:email filetype:mdb inurl:fcgi-bin/echo inurl:forum filetype:mdb inurl:forward filetype:forward -cvs inurl:getmsg.html intitle:hotmail inurl:log.nsf -gov inurl:main.php phpMyAdmin inurl:main.php Welcome to phpMyAdmin inurl:netscape.hst inurl:netscape.hst inurl:netscape.ini inurldbc.ini ext:ini -cvs inurlerl/printenv inurlhp.ini filetype:ini inurlreferences.ini "[emule]" inurlrofiles filetype:mdb inurl:report "EVEREST Home Edition " inurl:server-info "Apache Server Information" inurl:server-status "apache" inurl:snitz_forums_.mdb inurl:ssl.conf filetype:conf inurl:tdbin inurl:vbstats.php "page generated" ipsec.conf ipsec.secrets ipsec.secrets Lotus Domino address books mail filetype:csv -site:gov intext:name Microsoft Money Data Files mt-db-pass.cgi files MySQL tabledata dumps mystuff.xml - Trillian data files OWA Public Folders (direct view) Peoples MSN contact lists php-addressbook "This is the addressbook for *" -warning phpinfo() phpMyAdmin dumps phpMyAdmin dumps private key files (.csr) private key files (.key) Quicken data files robots.txt site:edu admin grades SQL data dumps Squid cache server reports Unreal IRCd WebLog Referrers Welcome to ntop! "adding new user" inurl:addnewuser -"there are no domains" (inurl:/cgi-bin/.cobalt/) | (intext:"Welcome to the Cobalt RaQ") +htpasswd +WS_FTP.LOG filetype:log filetypehp HAXPLORER "Server Files Browser" intitle:"Web Data Administrator - Login" intitle:admin intitle:login inurl:"phpOracleAdmin/php" -download -cvs inurl:ConnectComputer/precheck.htm | inurl:Remote/logon.aspx PHP Shell (unprotected) PHPKonsole PHPShell filetypehp -echo Public PHP FileManagers "Index Of /network" "last modified" "index of cgi-bin" "index of" / picasa.ini "index of" inurl:recycler "Index of" rar r nfo Modified "intitle:Index.Of /" stats merchant cgi-* etc "Powered by Invision Power File Manager" (inurl:login.php) | (intitle:"Browsing directory /" ) "Web File Browser" "Use regular expression" "Welcome to phpMyAdmin" " Create new database" allinurl:"/*/_vti_pvt/" | allinurl:"/*/_vti_cnf/" filetype:cfg ks intext:rootpw -sample -test -howto filetype:ini Desktop.ini intext:mydocs.dll filetype:torrent torrent Index of phpMyAdmin index.of.dcim index.of.password index.of.password intext:"d.aspx?id" || inurl:"d.aspx?id" intext:"Powered By: TotalIndex" intitle:"TotalIndex" intitle:"album permissions" "Users who can modify photos" "EVERYBODY" intitle:"Directory Listing For" intext:Tomcat -intitle:Tomcat intitle:"HFS /" +"HttpFileServer" intitle:"Index of *" inurl:"my shared folder" size modified intitle:"Index of /CFIDE/" administrator intitle:"Index of c:\Windows" intitle:"index of" "parent directory" "desktop.ini" site:dyndns.org intitle:"index of" -inurl:htm -inurl:html mp intitle:"Index of" cfide intitle:"index of" intext:"content.ie" intitle:"index of" inurl:ftp (pub | incoming) intitle:"index.of.personal" intitle:"webadmin - /*" filetypehp directory filename permission intitle:index.of (inurl:fileadmin | intitle:fileadmin) intitle:index.of /AlbumArt_ intitle:index.of /maildir/new/ intitle:index.of abyss.conf intitle:intranet inurl:intranet +intext:"human resources" intitle:upload inurl:upload intext:upload -forum -shop -support -wc inurl:/pls/sample/admin_/help/ inurl:/tmp inurl:backup intitle:index.of inurl:admin inurl:explorer.cfm inurldirpath|This_Directory) inurl:jee/examples/jsp inurljspdemos private protected secret secure winnt filetypel -intext:"/usr/bin/perl" inurl:webcal (inurl:webcal | inurl:add | inurl:delete | inurl:config) "File Upload Manager v." "rename to" "Powered by Land Down Under " "powered by YellDL" ext:asp "powered by DUForum" inurlmessages|details|login|default|register) -site: duware.com ext:asp inurlUgallery intitle:"." -site:dugallery.com -site:duware.com ext:cgi inurl:ubb_test ezBOO "Administrator Panel" -cvs filetype:cgi inurl:cachemgr.cgi filetype:cnf my.cnf -cvs -example filetype:inc inc intext:setcookie filetype:lit lit (books|ebooks) filetype:mdb inurl:"news/news" filetypehp inurl:"viewfile" -"index.php" -"idfil filetype:wsdl wsdl Gallery configuration setup files intitle:"ASP FileMan" Resend -site:iisworks.com intitle:"Directory Listing" "tree view" intitle:"Index of /" modified php.exe intitle:"PHP Explorer" exthp (inurlhpexplorer.php | inurl:list.php | inurl:browse.php) intitle:"phpremoteview" filetypehp "Name, Size, Type, Modify" intitle:mywebftp "Please enter your password" inurl:" WWWADMIN.PL" intitle:"wwwadmin" inurl:"nph-proxy.cgi" "Start browsing through this CGI-based proxy" inurl:"plog/register.php" inurl:cgi.asx?StoreID inurl:changepassword.cgi -cvs inurl:click.php intext:PHPClickLog inurlhp.exe filetype:exe -example.com inurl:robpoll.cgi filetype:cgi link:http://www.toastforums.com/ PHP-Nuke - create super user right now ! The Master List