Check List
Cheat Sheet
Subdomains Gathering
Negative Search
Copy -www -shop -share -ir -mfa site:$WEBSITE
File Upload Endpoints
Copy "admin" site:$WEBSITE
Http Title
Copy intitle:"Login" site:$WEBSITE
All http Title
Copy allintitle:"Login" site:$WEBSITE
Http Text
Copy intext:"Login" site:$WEBSITE
File Type
Copy filetype:pdf |
filetype:csv |
filetype:xls |
filetype:json |
filetype:xml |
filetype:ini |
filetype:ppt |
filetype:docx |
filetype:doc |
filetype:pptx |
filetype:txt |
filetype:xlsx |
filetype:env
site:$WEBSITE
Extension
Copy ext:log |
ext:txt |
ext:conf |
ext:cnf |
ext:ini |
ext:env |
ext:sh |
ext:bak |
ext:backup |
ext:swp |
ext:old |
ext:~ |
ext:git |
ext:svn |
ext:htpasswd |
ext:htaccess |
ext:json |
ext:daf
site:$WEBSITE
Sensitive Documents
Copy ext:txt |
ext:pdf |
ext:xml |
ext:xls |
ext:xlsx |
ext:ppt |
ext:pptx |
ext:doc |
ext:docx
site:$WEBSITE
Sensitive JS Libs
Copy intitle:"index of" inurl:"/js/" ("config.js" | "credentials.js" | "secrets.js" | "keys.js" | "password.js" | "api_keys.js" | "auth_tokens.js" | "access_tokens.js" | "sessions.js" | "authorization.js" | "encryption.js" | "certificates.js" | "ssl_keys.js" | "passphrases.js" | "policies.js" | "permissions.js" | "privileges.js" | "hashes.js" | "salts.js" | "nonces.js" | "signatures.js" | "digests.js" | "tokens.js" | "cookies.js" | "topsecr3tdonotlook.js") site:$WEBSITE
Backup Files
Copy intitle:index.of "backup" OR "bkp" OR "bak" |
intitle:index.of id_rsa OR id_dsa filetype:key
site:$WEBSITE
URI
Copy inurl:conf |
inurl:env |
inurl:cgi |
inurl:bin |
inurl:etc |
inurl:root |
inurl:sql |
inurl:backup |
inurl:admin |
inurl:api |
inurl:swagger |
inurl:database |
inurl:php
site:$WEBSITE
API Endpoints
Copy inurl:api |
site:*/rest |
site:*/v1 |
site:*/v2 |
site:*/v3
site:$WEBSITE
High % inurl keywords
Copy inurl:conf |
inurl:env |
inurl:cgi |
inurl:bin |
inurl:etc |
inurl:root |
inurl:sql |
inurl:backup |
inurl:admin |
inurl:php
site:$WEBSITE
Server Errors
Copy inurl:"error" |
intitle:"exception" |
intitle:"failure" |
intitle:"server at" |
intext:"confidential" |
intext:"Not for Public Release" |
intext:"internal use only" |
intext:"do not distribute" |
inurl:exception |
"database error" |
"SQL syntax" |
"undefined index" |
"unhandled exception" |
"stack trace" |
inurl:error.log OR inurl:debug.log filetype:log
site:$WEBSITE
XSS Parameters
Copy inurl:q= |
inurl:s= |
inurl:search= |
inurl:query= |
inurl:keyword= |
inurl:lang= |
inurl:&
site:$WEBSITE
Open Redirect Parameters
Copy inurl:url= |
inurl:return= |
inurl:next= |
inurl:redirect= |
inurl:redir= |
inurl:ret= |
inurl:r2= |
inurl:page= |
inurl:& |
inurl:http
site:$WEBSITE
SQLi Parameters
Copy inurl:id= |
inurl:pid= |
inurl:category= |
inurl:cat= |
inurl:action= |
inurl:sid= |
inurl:dir= |
inurl:&
site:$WEBSITE
SSRF Parameters
Copy inurl:http |
inurl:url= |
inurl:path= |
inurl:dest= |
inurl:html= |
inurl:data= |
inurl:domain= |
inurl:page= |
inurl:&
site:$WEBSITE
LFI Parameters
Copy inurl:include |
inurl:dir |
inurl:detail= |
inurl:file= |
inurl:folder= |
inurl:inc= |
inurl:locate= |
inurl:doc= |
inurl:conf= |
inurl:&
site:$WEBSITE
RCE Parameters
Copy inurl:cmd |
inurl:exec= |
inurl:query= |
inurl:code= |
inurl:do= |
inurl:run= |
inurl:read= |
inurl:ping= |
inurl:&
site:$WEBSITE
API Docs
Copy inurl:apidocs |
inurl:api-docs |
inurl:swagger |
inurl:api-explorer
site:$WEBSITE
Login Pages
Copy inurl:login |
inurl:signin |
intitle:login |
intitle:signin |
inurl:secure
site:$WEBSITE
Test Environments
Copy inurl:test |
inurl:env |
inurl:dev |
inurl:staging |
inurl:sandbox |
inurl:debug |
inurl:temp |
inurl:exports |
inurl:downloads |
inurl:internal |
inurl:demo
site:$WEBSITE
Sensitive Parameters
Copy inurl:email= |
inurl:phone= |
inurl:password= |
inurl:pass= |
inurl:pwd= |
inurl:secret= |
inurl:&
site:$WEBSITE
Cached Site
Link to a Specific URL
Bug Bounty Reports
Copy "submit vulnerability report" |
"powered by bugcrowd" |
"powered by hackerone"
site:$WEBSITE
Adobe Experience Manager
Copy inurl:/content/usergenerated |
inurl:/content/dam |
inurl:/jcr:content |
inurl:/libs/granite |
inurl:/etc/clientlibs |
inurl:/content/geometrixx |
inurl:/bin/wcm |
inurl:/crx/de
site:$WEBSITE
WordPress
Copy inurl:/wp-admin/admin-ajax.php site:$WEBSITE
Drupal
Copy intext:"Powered by" & intext:Drupal & inurl:user site:$WEBSITE
Joomla
Copy site:*/joomla/login site:$WEBSITE
Subdomains
Http Title
Copy intitle:"Login" site:$WEBSITE
All Http Title
Copy allintitle:"Login" site:$WEBSITE
Http Text
Copy intext:"Login" site:$WEBSITE
File Type
Copy filetype:pdf OR filetype:csv OR filetype:xls site:$WEBSITE
Extension
Copy ext:daf OR ext:bak OR ext:zip OR ext:log site:$WEBSITE
URI
Copy inurl:login |
inurl:logon |
inurl:sign-in |
inurl:signin |
inurl:portal
site:$WEBSITE
Cached Site
Link to a Specific URL
Information Site
City
Country
Geo
Copy geo:"56.913055,118.250862"
Vuln
Copy vuln:"CVE-2019-19781"
Hostname
Copy 'server:"aws" hostname:"$WEBSITE"'
Net
HTTP Title
Organization
Copy org:"United States Department"
Autonomous System Number
Operating System
Copy os:"windows server 2022"
Port
SSL/TLS Certificates
Copy ssl.cert.issuer.cn:"$WEBSITE" ssl.cert.subject.cn:"$WEBSITE"
Before/After
Copy product:"apache" after:"01/01/2020" before:"01/01/2024"
Device Type
Product
Server
SSH Fingerprint
Copy dc:14:de:8e:d7:c1:15:43:23:82:25:81:d2:59:e8:c0
PEM Certificates
Copy http.title:"Index of /" http.html:".pem"
Industrial Control Systems
Copy 'port:"502" port:"102"'
Exchange 2013 / 2016
Copy "X-AspNet-Version" http.title:"Outlook" -"x-owa-version"
SMB (Samba) File Shares
Copy "Authentication: disabled" port:445
Specifically domain controllers
Copy "Authentication: disabled" NETLOGON SYSVOL -unix port:445
FTP Servers with Anonymous Login
Copy "220" "230 Login successful." port:21
D-Link Webcams
Copy d-Link Internet Camera, 200 OK
Android IP Webcam Server
Copy Server:"IP Webcam Server" "200 OK"
Security DVRs
Copy html:"DVR_H264 ActiveX"
HP Printers
Copy "Serial Number:" "Built:" "Server: HP HTTP"
Chromecast / Smart TVs
Copy "Chromecast:" port:8008
Ethereum Miners
Copy “ETH” “speed” “Total”
Misconfigured WordPress
Copy http.html:"* The wp-config.php creation script uses this file"
WebServers Configuration File
Copy path:**/WebServer.xml
.bash_history Commands
Copy path:**/.bash_history
/etc/passwd File
Copy path:**/passwd path:etc
Password in config.php
Copy path:**/config.php dbpasswd
Shodan API Key in Python Script
Copy shodan_api_key language:python
/etc/shadow File
Copy path:**/shadow path:etc
wp-config.php File
Copy path:**/wp-config.php
MySQL Dump File
Copy path:*.sql mysql dump
City
Copy location.city: "Tehran"
Country
Copy location.country: "Iran"
GEO
Copy location.coordinates.latitude: 38.8951 and location.coordinates.longitude: -77.0364
Vuln
Copy vulnerabilities.cve.keyword: "CVE-2021-34527"
Hostname
NET
Copy ip: [1.1.1.1 to 1.1.255.255]
Http Title
Copy services.http.response.html_title: "Login Page"
Organization
Copy autonomous_system.name: "Google"
Autonomous System Number
Copy autonomous_system.asn: 13335
Operating System
Copy operating_system.product: "Windows"
Port
SSL/TLS Certificates
Copy services.tls.certificate.parsed.subject.common_name: "$WEBSITE"
Before/After
Copy services.software.product: "apache" AND services.observed_at: [2020-01-01 TO 2024-01-01]
Device Type
Product
Copy services.software.vendor=`Apache`
Server
Copy services.http.response.headers.server: "nginx"
SSH Fingerprint
Copy services.ssh.v2.fingerprint_sha256: "dc:14:de:8e:d7:c1:15:43:23:82:25:81:d2:59:e8:c0"
PEM Certificates
Copy services: (http.response.html_title: "Index of /" and http.response.body: ".pem")
Industrial Control Systems
Exchange 2013 / 2016
Copy services: (http.response.headers: (key: "X-AspNet-Version" and value.headers: "*") and http.response.html_title: "Outlook" and not http.response.headers: (key: "x-owa-version" and value.headers: "*"))
SMB (Samba) File Shares
Copy services: (service_name: SMB and banner: "shared_folder")
Specifically domain controllers
Copy "Authentication: disabled" and services: (service_name: NETLOGON and service_name: SYSVOL) and not operating_system.product: "unix" and services.port: 445
FTP Servers with Anonymous Login
Copy services.ftp.status_code: 230
Webcams
Copy services.http.response.headers: (key: "Server" and value.headers: "Webcam")
Android IP Webcam Server
Copy services.http.response.html_title: "IP Webcam"
Security DVRs
Copy services.http.response.html_title: "Security DVR"
Printers
Copy services.http.response.headers: (key: "Server" and value.headers: "Printer")
Chromecast / Smart TVs
Copy services.http.response.headers: (key: "Server" and value.headers: {"Chromecast", "Smart TV"})
Ethereum Miners
Copy services.http.response.html_title: "Ethereum Miner"
Misconfigured WordPress
Copy services: (http.response.html_title: "WordPress" and http.response.headers: (key: "Favicon" and value.headers: "c4d2e77e3e9a4c8d4d2e9b6c9f6d3c6f"))
Services on Ports 22-25
Copy services.port: {22,23,24,25}
Elasticsearch Service on Port 443
Copy (services.service_name=`ELASTICSEARCH`) and service.port=`443`
Login Page with Specific Banner Hash in Iran
Copy ((services.banner_hashes=`sha256:4d3efcb4c2cc2cdb96dddf455977c3291f4b0f6a8a290bfc15e460d917703226`) and labels=`login-page`) and location.country=`Iran`
OWA Login Page
Copy same_service(services.http.response.favicons.name: */owa/auth/* and services.http.response.html_title={"Outlook Web App", "Outlook"})
Exchange Server in Iran
Copy (services.software.product=`Exchange Server`) and location.country=`Iran`
GEO
Copy geo:"35.6892,51.3890"
Vuln
Copy vuln:"CVE-2021-34527"
Net
Http Title
Copy port:80 AND title:"Login Page"
Organization
Copy organization:"Google"
SSL/TLS Certificates
Copy ssl.cert.subject.cn:"$WEBSITE"
Before/After
Copy product:"apache" after:"2020-01-01" before:"2024-01-01"
Product
Server
SSH Fingerprint
Copy dc:14:de:8e:d7:c1:15:43:23:82:25:81:d2:59:e8:c0
PEM Certificates
Copy http.title:"Index of /" http.html:".pem"
Industrial Control Systems
Exchange 2013 / 2016
Copy "X-AspNet-Version" http.title:"Outlook" -"x-owa-version"
SMB (Samba) File Shares
Copy "Authentication: disabled" port:445
Specifically domain controllers
Copy smb.share:"SYSVOL" OR smb.share:"NETLOGON"
FTP Servers with Anonymous Login
Copy port:21 ,ftp.anonymous:"true"
D-Link Webcams
Copy title:"d-Link Internet Camera" AND http.status_code:"200"
Android IP Webcam Server
Copy Server:"IP Webcam Server" "200 OK"
Security DVRs
Copy port:80 AND "DVR_H264 ActiveX"
HP Printers
Copy "Serial Number:" "Built:" "Server: HP HTTP"
Chromecast / Smart TVs
Copy product:"Chromecast" OR product:"Smart TV"
Ethereum Miners
Copy “ETH” “speed” “Total”
Misconfigured WordPress
Copy http.title:"WordPress" AND http.favicon.hash:"c4d2e77e3e9a4c8d4d2e9b6c9f6d3c6f"
Web Application
Version
ProFTPD Server
Device Type
Operating System
Service
IP
Devices in 192.168.1.1/24 Network Range
Hostname
Port
City
Country
Autonomous System Number
Header
Found 'hello' in Description'
Title
Site