What is Googledorks?
The term “googledork” was coined by Johnny Long (http://johnny.ihackstuff.com) and
originally meant “An inept or foolish person as revealed by Google.” After a great deal of
media attention, the term came to describe those “who troll the Internet for confidential
goods.” Either term is fine, really. What matters is that the term googledork conveys the
concept that sensitive stuff is on the web, and Google can help you find it. The official
googledorks page (found at http://johnny.ihackstuff.com/googledorks) lists many different
examples of unbelievable things that have been dug up through Google by the
maintainer of the page, Johnny Long. Each listing shows the Google search required to
find the information along with a description of why the data found on each page is so
interesting.
Google serves almost 80
percent of all search queries on the Internet, proving itself as the
most popular search engine. However Google makes it possible to reach
not only the publicly available information resources, but also gives
access to some of the most confidential information that should never
have been revealed. In this post I will show how to use Google for
exploiting security vulnerabilities within websites. The following are
some of the hacks that can be accomplished using Google.
1. Hacking Security Cameras
There exists many security cameras used for monitoring places like
parking lots, college campus, road traffic etc. which can be hacked
using Google so that you can view the images captured by those cameras
in real time. All you have to do is use the following search query in
Google. Type in Google search box exactly as follows and hit enter
inurl:”viewerframe?mode=motion”
Click on any of the search results (Top 5 recommended) and you will gain access to the live camera which has full controls.
you now have access to the Live cameras which work in real-time. You
can also move the cameras in all the four directions, perform actions
such as zoom in and zoom out. This camera has really a less refresh
rate. But there are other search queries through which you can gain
access to other cameras which have faster refresh rates. So to access
them just use the following search query.
intitle:”Live View / – AXIS”
inurl:/view.shtml
or
intitle:”Live View / – AXIS” | inurl:view/view.shtml^
inurl:ViewerFrame?Mode=
inurl:ViewerFrame?Mode=Refresh
inurl:axis-cgi/jpg
inurl:axis-cgi/mjpg (motion-JPEG)
inurl:view/indexFrame.shtml
inurl:view/index.shtml
inurl:view/view.shtml
liveapplet
intitle:”live view” intitle:axis
intitle:liveapplet
allintitle:”Network Camera NetworkCamera”
intitle:axis intitle:”video server”
intitle:liveapplet inurl:LvAppl
intitle:”EvoCam” inurl:”webcam.html”
intitle:”Live NetSnap Cam-Server feed”
intitle:”Live View / – AXIS”
intitle:”Live View / – AXIS 206M”
intitle:”Live View / – AXIS 206W”
intitle:”Live View / – AXIS 210?
inurl:indexFrame.shtml Axis
inurl:”MultiCameraFrame?Mode=Motion”
intitle:start inurl:cgistart
intitle:”WJ-NT104 Main Page”
intext:”MOBOTIX M1? intext:”Open Menu”
intext:”MOBOTIX M10? intext:”Open Menu”
intext:”MOBOTIX D10? intext:”Open Menu”
intitle:snc-z20 inurl:home/
intitle:snc-cs3 inurl:home/
intitle:snc-rz30 inurl:home/
intitle:”sony network camera snc-p1?
intitle:”sony network camera snc-m1?
site:.viewnetcam.com -www.viewnetcam.com
intitle:”Toshiba Network Camera” user login
intitle:”netcam live image”
intitle:”i-Catcher Console – Web Monitor”
Click on any of the search results to access a different set of live
cameras. Thus you have hacked Security Cameras using Google.
2. Hacking Personal and Confidential Documents
Using Google it is possible to gain access to an email repository
containing CV of hundreds of people which were created when applying for
their jobs. The documents containing their Address, Phone, DOB,
Education, Work experience etc. can be found just in seconds.
intitle:”curriculum vitae” “phone * * *” “address *” “e-mail”
You can gain access to a list of .xls (excel documents) which contain
contact details including email addresses of large group of people. To
do so type the following search query and hit enter.
filetype:xls inurl:”email.xls”
Also it’s possible to gain access to documents potentially containing
information on bank accounts, financial summaries and credit card
numbers using the following search query
intitle:index.of finances.xls
3. Hacking Google to gain access to Free Stuffs
Ever wondered how to hack Google for free music or ebooks. Well here
is a way to do that. To download free music just enter the following
query on google search box and hit enter.
“?intitle:index.of?mp3 avril“
Now you’ll gain access to the whole index of eminem album where in
you can download the songs of your choice. Instead of eminem you can
subtitute the name of your favorite album. To search for the ebooks all
you have to do is replace “eminem” with your favorite book name. Also
replace “mp3″ with “pdf” or “zip” or “rar”.