BOOK THIS SPACE FOR AD
ARTICLE ADHello everyone, I’m Kerstan.
A list of Google Dorks for Bug Bounty,Web Application Security,and Pentesting.
Let’s start.
Photo by Kasia Derenda on Unsplash
Broad domain search w/negative search
site:example.com -wwww -shop -share -ir -mfa
PHP extension w/parameters
site:example.com ext:php inurl:
Disclosed XSS and Open Redirects
site:openbugbounty.org inurl:reports intext:”example.com”
Juicy Extensions
site:”example[.]com”ext:log ext:txt ext:conf ext:cnf ext:inil
ext:env ext:sh ext:bak ext:backup ext:swp ext:old ext:~|ext:git
ext:svn ext:htpasswd ext:htaccess
XSS prone parameters
inurl:q=inurl:s=I inurl:search=inurl:query=inurl:keyword=I
inurl:lang=inurl:site:example.com