คลัง
recon

Google Dorks

Google Dorks ใช้ search operator ขั้นสูงค้นหาข้อมูลที่ถูก index แต่ไม่ตั้งใจเปิดเผย — ไฟล์ sensitive, login page, exposed config, error message เป็น passive recon ทรงพลัง บทนี้ลงลึก operator ทุกตัว, dork สำเร็จรูปตามเป้าหมาย, GHDB, และการใช้กับ target (เนื้อหาเพื่อ recon ที่ได้รับอนุญาต)

BeginnerIntermediate#google-dorks#recon#osint#operators#exposed-files#passive#ctf

1. หลักการ

Google index หน้าเว็บมหาศาล รวมถึงไฟล์/หน้าที่เจ้าของไม่ตั้งใจเปิดเผยแต่ไม่ได้ป้องกัน — config, backup, login page, directory listing, error ที่เผยข้อมูล Google Dorks ใช้ search operator ค้นเจาะจงสิ่งเหล่านี้ เป็น passive recon (ค้น Google ไม่แตะ target) ที่บางทีเจอข้อมูลอ่อนไหวโดยตรง

เนื้อหานี้เพื่อการ reconnaissance ในงานที่ได้รับอนุญาต (CTF, OSINT, pentest) เท่านั้น — เข้าถึงเฉพาะข้อมูลที่ index สาธารณะ ไม่เจาะระบบ

2. Search operators

operatorความหมายตัวอย่าง
site:เฉพาะ domainsite:example.com
filetype: / ext:ชนิดไฟล์filetype:pdf
intitle:ใน titleintitle:"index of"
inurl:ใน URLinurl:admin
intext:ในเนื้อหาintext:password
cache:หน้า cachecache:example.com
"..."exact phrase"confidential"
-ไม่รวมsite:example.com -www
OR / |หรือadmin OR login

3. Dork สำเร็จรูปตามเป้าหมาย

dork ยอดนิยม (แทน example.com ด้วย target)
# เอกสาร/ไฟล์ของ target
site:example.com filetype:pdf
site:example.com filetype:xlsx OR filetype:docx
site:example.com filetype:env OR filetype:config OR filetype:bak

# directory listing (เปิดดูไฟล์ได้)
site:example.com intitle:"index of"
intitle:"index of" "parent directory" site:example.com

# login / admin pages
site:example.com inurl:login OR inurl:admin OR inurl:portal

# exposed credential/config
site:example.com intext:password OR intext:"api_key"
site:example.com ext:env "DB_PASSWORD"
site:example.com inurl:wp-config OR inurl:.git

# error messages (เผย tech/path)
site:example.com intext:"sql syntax near" OR intext:"stack trace"

# subdomains
site:*.example.com -www

# exposed services
site:example.com inurl:phpmyadmin OR inurl:jenkins
เริ่มจาก site:target + filetype/inurl/intext; index of = directory listing; ระวังไฟล์ที่เป็นข้อมูลจริงของ target

4. GHDB + automation

  • Google Hacking Database (GHDB): exploit-db.com/google-hacking-database — dork สำเร็จรูปหลายพันรายการ จัดหมวด (login, files, vulnerable servers, ...)
  • ใช้ dork จาก GHDB + เติม site:target เพื่อเจาะเฉพาะเป้าหมาย
  • หลาย search engine: dork ใช้กับ Bing, DuckDuckGo, Yandex ได้ (operator ต่างเล็กน้อย) — บางที index ต่างกัน
  • tools: เครื่องมือ automate dork มี (เช่น pagodo) แต่ระวัง Google rate-limit/CAPTCHA — manual มัก practical กว่า
  • specialized: Shodan/Censys (ดูหัวข้อนั้น) สำหรับ exposed service/device โดยตรง

5. Quick Reference

  • passive recon — ค้นข้อมูลที่ index แต่ไม่ตั้งใจเปิด
  • operators: site: filetype: intitle: inurl: intext: "phrase"
  • directory listing: site:X intitle:"index of"
  • config/cred: site:X ext:env OR filetype:bak intext:password
  • login: site:X inurl:admin OR inurl:login
  • GHDB (exploit-db) = dork สำเร็จรูป + เติม site:target
  • ใช้กับ Bing/Yandex ได้; Shodan/Censys สำหรับ service

🧭 จับมือทำทีละขั้น (มีแค่ Kali) + ถ้าติดไปไหนต่อ

สมมติมีแค่ชื่อ domain กับเบราว์เซอร์ ไม่มีเครื่องมือพิเศษเลย อยากหาไฟล์/หน้าที่ target เผลอเปิดเผย ทำตามนี้ทีละขั้น

  1. 1เริ่มจาก dork กว้างๆ ก่อน: site:target.com ดูว่า index ไว้เยอะแค่ไหน
  2. 2หา directory listing ที่เปิดโล่ง: site:target.com intitle:"index of"
  3. 3หาไฟล์เอกสาร/สำรอง: site:target.com filetype:pdf OR filetype:xlsx OR filetype:bak
  4. 4หาหน้า login/admin: site:target.com inurl:admin OR inurl:login OR inurl:portal
  5. 5หา config/credential ที่หลุด: site:target.com ext:env "DB_PASSWORD"
  6. 6ถ้ายังไม่เจออะไร ลองเปิด exploit-db.com/google-hacking-database (GHDB) หา dork สำเร็จรูปเพิ่ม
  7. 7เอา dork จาก GHDB มาเติม site:target.com แล้วลองทีละอัน
  8. 8ลองสลับ search engine (Google อาจ rate-limit): ใช้ syntax เดียวกันกับ Bing/DuckDuckGo
  9. 9เจอไฟล์/หน้าอ่อนไหว → เปิดดูเนื้อหา จดว่ามี credential/endpoint/path อะไรที่ต่อยอดได้
  10. 10ถ้า dork ไม่เจออะไรเลยหลังลองครบ สลับไปทาง GitHub Dorks (บางทีของหลุดใน repo ไม่ใช่หน้าเว็บ) หรือ directory enumeration ตรงๆ
dork เจอของไหม? ทำอะไรต่อ
site:target.com + operator (filetype/inurl/intext)
เจอไฟล์/หน้าที่น่าสนใจไหม?
✅ เจอ (index of / config / login page)→ เปิดดู เก็บข้อมูลต่อยอด
❌ ไม่เจอเลย→ ลอง dork จาก GHDB / สลับ search engine
ลอง GHDB (exploit-db) + Bing/DuckDuckGo
✅ เจอเพิ่ม→ เปิดดู เก็บข้อมูลต่อยอด
❌ ยังไม่เจอ→ ข้ามไปหาทางอื่น
ขั้นตอน/งานเครื่องมือใน Kaliติดตั้งเพิ่ม (ถ้าไม่มี)เครื่องมือออนไลน์
ค้น dork หลักเบราว์เซอร์-google.com, bing.com
หา dork สำเร็จรูป--exploit-db.com/google-hacking-database
สลับ search engine--bing.com, duckduckgo.com
ดูหน้าที่ถูกลบไปแล้ว--web.archive.org
automate dork (ระวัง rate-limit)python3pip install pagodo-
หา service/port แทนไฟล์--shodan.io, censys.io
🚑 ถ้าตันสนิท ลองท่าถัดไป: GitHub Dorks (ถ้าเว็บไม่มีอะไรหลุด ลองหา secret ใน repo แทน), Directory Enumeration (dork หา index of ไม่เจอ ลอง brute-force path ตรงๆ ด้วย ffuf/gobuster), Web Methodology (พอเจอ endpoint/หน้า admin แล้ว ไปวางแผนทดสอบเว็บแอปแบบเต็ม), Info Gathering (รวบรวมข้อมูลที่เจอทั้งหมดมาวางแผน attack surface ต่อ)

โน้ตของฉัน

ยังไม่มีโน้ตสำหรับหัวข้อนี้