Check List
Cheat Sheet
Subdomains Gathering
Negative Search
Copy -www -shop -share -ir -mfa site: $WEBSITE
File Upload Endpoints
Copy "admin" site: $WEBSITE
Http Title
Copy intitle: "Login" site: $WEBSITE
All http Title
Copy allintitle: "Login" site: $WEBSITE
Http Text
Copy intext: "Login" site: $WEBSITE
File Type
Copy filetype:pdf | filetype:csv | filetype:xls site: $WEBSITE
Extension
Copy ext:log |
ext:txt |
ext:conf |
ext:cnf |
ext:ini |
ext:env |
ext:sh |
ext:bak |
ext:backup |
ext:swp |
ext:old |
ext:~ |
ext:git |
ext:svn |
ext:htpasswd |
ext:htaccess |
ext:json |
ext:daf
site:$WEBSITE
Sensitive Documents
Copy ext:txt |
ext:pdf |
ext:xml |
ext:xls |
ext:xlsx |
ext:ppt |
ext:pptx |
ext:doc |
ext:docx intext: "confidential" |
intext: "Not for Public Release" |
intext: "internal use only" |
intext: "do not distribute"
site:$WEBSITE
URI
Copy inurl:conf |
inurl:env |
inurl:cgi |
inurl:bin |
inurl:etc |
inurl:root |
inurl:sql |
inurl:backup |
inurl:admin |
inurl:php
site:$WEBSITE
API Endpoint
Copy inurl:api |
site:*/rest |
site:*/v1 |
site:*/v2 |
site:*/v3
site:$WEBSITE
High % inurl keywords
Copy inurl:conf |
inurl:env |
inurl:cgi |
inurl:bin |
inurl:etc |
inurl:root |
inurl:sql |
inurl:backup |
inurl:admin |
inurl:php
site:$WEBSITE
Server Errors
Copy inurl: "error" |
intitle: "exception" |
intitle: "failure" |
intitle: "server at" |
inurl:exception |
"database error" |
"SQL syntax" |
"undefined index" |
"unhandled exception" |
"stack trace"
site:$WEBSITE
XSS Parameters
Copy inurl:q = |
inurl:s = |
inurl:search = |
inurl:query = |
inurl:keyword = |
inurl:lang = |
inurl: &
site:$WEBSITE
Open Redirect Parameters
Copy inurl:url = |
inurl:return = |
inurl:next = |
inurl:redirect = |
inurl:redir = |
inurl:ret = |
inurl:r2 = |
inurl:page = |
inurl: & |
inurl:http
site:$WEBSITE
SQLi Parameters
Copy inurl:id = |
inurl:pid = |
inurl:category = |
inurl:cat = |
inurl:action = |
inurl:sid = |
inurl:dir = |
inurl: &
site:$WEBSITE
SSRF Parameters
Copy inurl:http |
inurl:url = |
inurl:path = |
inurl:dest = |
inurl:html = |
inurl:data = |
inurl:domain = |
inurl:page = |
inurl: &
site:$WEBSITE
LFI Parameters
Copy inurl:include |
inurl:dir |
inurl:detail = |
inurl:file = |
inurl:folder = |
inurl:inc = |
inurl:locate = |
inurl:doc = |
inurl:conf = |
inurl: &
site:$WEBSITE
RCE Parameters
Copy inurl:cmd |
inurl:exec = |
inurl:query = |
inurl:code = |
inurl:do = |
inurl:run = |
inurl:read = |
inurl:ping = |
inurl: &
site:$WEBSITE
API Docs
Copy inurl:apidocs |
inurl:api-docs |
inurl:swagger |
inurl:api-explorer
site:$WEBSITE
Login Pages
Copy inurl:login |
inurl:signin |
intitle:login |
intitle:signin |
inurl:secure
site:$WEBSITE
Test Environments
Copy inurl:test |
inurl:env |
inurl:dev |
inurl:staging |
inurl:sandbox |
inurl:debug |
inurl:temp |
inurl:internal |
inurl:demo
site:$WEBSITE
Sensitive Parameters
Copy inurl:email = |
inurl:phone = |
inurl:password = |
inurl:secret = |
inurl: &
site:$WEBSITE
Cached Site
Link to a Specific URL
Bug Bounty Reports
Copy "submit vulnerability report" |
"powered by bugcrowd" |
"powered by hackerone"
site:$WEBSITE
Adobe Experience Manager
Copy inurl:/content/usergenerated |
inurl:/content/dam |
inurl:/jcr:content |
inurl:/libs/granite |
inurl:/etc/clientlibs |
inurl:/content/geometrixx |
inurl:/bin/wcm |
inurl:/crx/de
site:$WEBSITE
WordPress
Copy inurl:/wp-admin/admin-ajax.php site: $WEBSITE
Drupal
Copy intext: "Powered by" & intext:Drupal & inurl:user site: $WEBSITE
Joomla
Copy site:*/joomla/login site: $WEBSITE
Subdomains
Http Title
Copy intitle: "Login" site: $WEBSITE
All Http Title
Copy allintitle: "Login" site: $WEBSITE
Http Text
Copy intext: "Login" site: $WEBSITE
File Type
Copy filetype:pdf OR filetype:csv OR filetype:xls site: $WEBSITE
Extension
Copy ext:daf OR ext:bak OR ext:zip OR ext:log site: $WEBSITE
URI
Copy inurl:login |
inurl:logon |
inurl:sign-in |
inurl:signin |
inurl:portal
site:$WEBSITE
Cached Site
Link to a Specific URL
Information Site
City
Country
Geo
Copy geo: "56.913055,118.250862"
Vuln
Copy vuln: "CVE-2019-19781"
Hostname
Copy 'server:"aws" hostname:"$WEBSITE"'
Net
HTTP Title
Organization
Copy org: "United States Department"
Autonomous System Number
Operating System
Copy os: "windows server 2022"
Port
SSL/TLS Certificates
Copy ssl.cert.issuer.cn: "$WEBSITE" ssl.cert.subject.cn: "$WEBSITE"
Before/After
Copy product: "apache" after: "01/01/2020" before: "01/01/2024"
Device Type
Product
Server
SSH Fingerprint
Copy dc:14:de:8e:d7:c1:15:43:23:82:25:81:d2:59:e8:c0
PEM Certificates
Copy http.title: "Index of /" http.html: ".pem"
Industrial Control Systems
Copy 'port:"502" port:"102"'
Exchange 2013 / 2016
Copy "X-AspNet-Version" http.title: "Outlook" - "x-owa-version"
SMB (Samba) File Shares
Copy "Authentication: disabled" port:445
Specifically domain controllers
Copy "Authentication: disabled" NETLOGON SYSVOL -unix port:445
FTP Servers with Anonymous Login
Copy "220" "230 Login successful." port:21
D-Link Webcams
Copy d-Link Internet Camera, 200 OK
Android IP Webcam Server
Copy Server: "IP Webcam Server" "200 OK"
Security DVRs
Copy html: "DVR_H264 ActiveX"
HP Printers
Copy "Serial Number:" "Built:" "Server: HP HTTP"
Chromecast / Smart TVs
Copy "Chromecast:" port:8008
Ethereum Miners
Copy “ETH” “speed” “Total”
Misconfigured WordPress
Copy http.html: "* The wp-config.php creation script uses this file"
WebServers Configuration File
Copy path:**/WebServer.xml
.bash_history Commands
Copy path:**/.bash_history
/etc/passwd File
Copy path:**/passwd path:etc
Password in config.php
Copy path:**/config.php dbpasswd
Shodan API Key in Python Script
Copy shodan_api_key language:python
/etc/shadow File
Copy path:**/shadow path:etc
wp-config.php File
Copy path:**/wp-config.php
MySQL Dump File
Copy path:*.sql mysql dump
City
Copy location.city: "Tehran"
Country
Copy location.country: "Iran"
GEO
Copy location.coordinates.latitude: 38.8951 and location.coordinates.longitude: -77.0364
Vuln
Copy vulnerabilities.cve.keyword: "CVE-2021-34527"
Hostname
NET
Copy ip: [1.1.1.1 to 1.1.255.255]
Http Title
Copy services.http.response.html_title: "Login Page"
Organization
Copy autonomous_system.name: "Google"
Autonomous System Number
Copy autonomous_system.asn: 13335
Operating System
Copy operating_system.product: "Windows"
Port
SSL/TLS Certificates
Copy services.tls.certificate.parsed.subject.common_name: "$WEBSITE"
Before/After
Copy services.software.product: "apache" AND services.observed_at: [2020-01-01 TO 2024-01-01]
Device Type
Product
Copy services.software.vendor = ` Apache `
Server
Copy services.http.response.headers.server: "nginx"
SSH Fingerprint
Copy services.ssh.v2.fingerprint_sha256: "dc:14:de:8e:d7:c1:15:43:23:82:25:81:d2:59:e8:c0"
PEM Certificates
Copy services: (http.response.html_title: "Index of /" and http.response.body: ".pem" )
Industrial Control Systems
Exchange 2013 / 2016
Copy services: (http.response.headers: (key: "X-AspNet-Version" and value.headers: "*" ) and http.response.html_title: "Outlook" and not http.response.headers: ( key: "x-owa-version" and value.headers: "*" ))
SMB (Samba) File Shares
Copy services: (service_name: SMB and banner: "shared_folder" )
Specifically domain controllers
Copy "Authentication: disabled" and services: (service_name: NETLOGON and service_name: SYSVOL ) and not operating_system.product: "unix" and services.port: 445
FTP Servers with Anonymous Login
Copy services.ftp.status_code: 230
Webcams
Copy services.http.response.headers: (key: "Server" and value.headers: "Webcam" )
Android IP Webcam Server
Copy services.http.response.html_title: "IP Webcam"
Security DVRs
Copy services.http.response.html_title: "Security DVR"
Printers
Copy services.http.response.headers: (key: "Server" and value.headers: "Printer" )
Chromecast / Smart TVs
Copy services.http.response.headers: (key: "Server" and value.headers: { "Chromecast" , "Smart TV" } )
Ethereum Miners
Copy services.http.response.html_title: "Ethereum Miner"
Misconfigured WordPress
Copy services: (http.response.html_title: "WordPress" and http.response.headers: (key: "Favicon" and value.headers: "c4d2e77e3e9a4c8d4d2e9b6c9f6d3c6f" ))
Services on Ports 22-25
Copy services.port: {22,23,24,25}
Elasticsearch Service on Port 443
Copy ( services.service_name = ` ELASTICSEARCH ` ) and service.port= ` 443 `
Login Page with Specific Banner Hash in Iran
Copy ((services.banner_hashes = `sha256 : 4 d 3 efcb 4 c 2 cc 2 cdb 96 dddf 455977 c 3291 f 4 b 0 f 6 a 8 a 290 bfc 15 e 460 d 917703226 `) and labels = `login - page`) and location.country = `Iran`
OWA Login Page
Copy same_service(services.http.response.favicons.name: */owa/auth/* and services.http.response.html_title={ "Outlook Web App" , "Outlook" } )
Exchange Server in Iran
Copy ( services.software.product = ` Exchange Server ` ) and location.country= ` Iran `
GEO
Copy geo: "35.6892,51.3890"
Vuln
Copy vuln: "CVE-2021-34527"
Net
Http Title
Copy port:80 AND title: "Login Page"
Organization
Copy organization: "Google"
SSL/TLS Certificates
Copy ssl.cert.subject.cn: "$WEBSITE"
Before/After
Copy product: "apache" after: "2020-01-01" before: "2024-01-01"
Product
Server
SSH Fingerprint
Copy dc:14:de:8e:d7:c1:15:43:23:82:25:81:d2:59:e8:c0
PEM Certificates
Copy http.title: "Index of /" http.html: ".pem"
Industrial Control Systems
Exchange 2013 / 2016
Copy "X-AspNet-Version" http.title: "Outlook" - "x-owa-version"
SMB (Samba) File Shares
Copy "Authentication: disabled" port:445
Specifically domain controllers
Copy smb.share: "SYSVOL" OR smb.share: "NETLOGON"
FTP Servers with Anonymous Login
Copy port:21 ,ftp.anonymous: "true"
D-Link Webcams
Copy title: "d-Link Internet Camera" AND http.status_code: "200"
Android IP Webcam Server
Copy Server: "IP Webcam Server" "200 OK"
Security DVRs
Copy port:80 AND "DVR_H264 ActiveX"
HP Printers
Copy "Serial Number:" "Built:" "Server: HP HTTP"
Chromecast / Smart TVs
Copy product: "Chromecast" OR product: "Smart TV"
Ethereum Miners
Copy “ETH” “speed” “Total”
Misconfigured WordPress
Copy http.title: "WordPress" AND http.favicon.hash: "c4d2e77e3e9a4c8d4d2e9b6c9f6d3c6f"
Web Application
Version
ProFTPD Server
Device Type
Operating System
Service
IP
Devices in 192.168.1.1/24 Network Range
Hostname
Port
City
Country
Autonomous System Number
Header
Found 'hello' in Description'
Title
Site