搜文件的Github黑客语法
filename:manifest.xml
filename:travis.yml
filename:vim_settings.xml
filename:database
filename:prod.exs NOT prod.secret.exs
filename:prod.secret.exs
filename:.npmrc _auth
filename:.dockercfg auth
filename:WebServers.xml
filename:.bash_history
filename:sftp-config.json
filename:sftp.json path:.vscode
filename:secrets.yml password
filename:.esmtprc password
filename:passwd path:etc
filename:dbeaver-data-sources.xml
path:sites databases password
filename:config.php dbpasswd
filename:prod.secret.exs
filename:configuration.php JConfig password
filename:.sh_history
shodan_api_key language:python
filename:shadow path:etc
JEKYLL_GITHUB_TOKEN
filename:proftpdpasswd
filename:.pgpass
filename:idea14.key
filename:hub oauth_token
HEROKU_API_KEY language:json
HEROKU_API_KEY language:shell
SF_USERNAME salesforce
filename:.bash_profile aws
extension:json api.forecast.io
filename:.env MAIL_HOST=smtp.gmail.com
filename:wp-config.php
extension:sql mysql dump
filename:credentials aws_access_key_id
filename:id_rsa or filename:id_dsa
搜代码开发语言的Github黑客语法
language:python username
language:php username
language:sql username
language:html password
language:perl password
language:shell username
language:java api
HOMEBREW_GITHUB_API_TOKEN language:shell
搜相关的Key、API、Toekn、Password的Github黑客语法
api_key
keys”
authorization_bearer:
oauth
auth
authentication
client_secret
api_token:
token”
client_id
password
user_password
user_pass
passcode
client_secret
secret
password hash
OTP
user auth
搜相关的Username的Github黑客语法
user:name (user:admin)
org:name (org:google type:users)
in:login ( in:login)
in:name ( in:name)
fullname:firstname lastname (fullname: )
in:email (data in:email)
按照日期搜索相关的Github黑客语法
created:<2012–04–05
created:>=2011–06–12
created:2016–02–07 location:iceland
created:2011–04–06..2013–01–14 in:username ...
使用拓展查找相关信息的Github黑客语法
extension:pem private
extension:ppk private
extension:sql mysql dump
extension:sql mysql dump password
extension:json api.forecast.io
extension:json mongolab.com
extension:yaml mongolab.com
[WFClient] Password= extension:ica
extension:avastlic “support.avast.com”
extension:json googleusercontent client_secret ...
最常用的github dorks
filename:config key
filename:setting key
filename:env key
filename:config password
filename:setting password
filename:env password
filename:config secret
filename:setting secret
filename:env secret
filename:config passwort
filename:setting passwort
filename:env passwort
filename:config pwd
filename:setting pwd
filename:env pwd
aws-secret-dorks
filename:credentials aws_access_key_id
filename:.bash_profile aws
rds.amazonaws.com password
filename:.s3cfg
ARTIFACTS_AWS_ACCESS_KEY_ID=
ARTIFACTS_AWS_SECRET_ACCESS_KEY=
AWS-ACCT-ID=
AWS-KEY=
AWS-SECRETS=
AWS
AWS.config.accessKeyId=
AWS.config.secretAccessKey=
AWSACCESSKEYID=
AWSCN_ACCESS_KEY_ID=
AWSCN_SECRET_ACCESS_KEY=
AWSSECRETKEY=
AWS_ACCESS=
AWS_ACCESS_KEY=
AWS_ACCESS_KEY_ID=
AWS_CF_DIST_ID=
AWS_DEFAULT
AWS_DEFAULT_REGION=
AWS_S3_BUCKET=
AWS_SECRET=
AWS_SECRET_ACCESS_KEY=
AWS_SECRET_KEY=
AWS_SES_ACCESS_KEY_ID=
AWS_SES_SECRET_ACCESS_KEY=
BUCKETEER_AWS_ACCESS_KEY_ID=
BUCKETEER_AWS_SECRET_ACCESS_KEY=
SANDBOX_AWS_ACCESS_KEY_ID=
SANDBOX_AWS_SECRET_ACCESS_KEY=
S3-EXTERNAL-3.AMAZONAWS.COM=
S3.AMAZONAWS.COM=
filename:.bash_profile aws
rds.amazonaws.com password
db dorks
filename:database password
filename:database pw
filename:database secret
path:sites databases password
filename:config dbpasswd
filename:conf database
filename:.env DB_USERNAME NOT homestead
mysql password
github dorks
filename:config aws_access_key_id
filename:config aws secret
password
HEROKU_API_KEY language:json
HEROKU_API_KEY language:shell
HOMEBREW_GITHUB_API_TOKEN language:shell
JEKYLL_GITHUB_TOKEN
OTP
PT_TOKEN language:bash
SF_USERNAME salesforce
Password= extension:ica
api_key
api_token:
auth
authentication
authorization_bearer:
client_id
client_secret
extension:dbeaver-data-sources.xml
extension:json api.forecast.io
extension:json cloud.redislabs.com
extension:json googleusercontent client_secret
extension:json mongolab.com
extension:pem private
extension:ppk private
extension:sql mysql dump
extension:sql mysql dump password
extension:yaml cloud.redislabs.com
extension:yaml mongolab.com
filename:.bash_history
filename:.bash_history <Domain name>
filename:.bash_profile aws
filename:.bashrc mailchimp
filename:.bashrc password
filename:.cshrc
filename:.dockercfg auth
filename:.env DB_USERNAME NOT homestead
filename:.env MAIL_HOST=smtp.gmail.com
filename:.esmtprc password
filename:.ftpconfig
filename:.git-credentials
filename:.history
filename:.htpasswd
filename:.netrc password
filename:.npmrc _auth
filename:.pgpass
filename:.remote-sync.json
filename:.s3cfg
filename:.sh_history
filename:.tugboat NOT _tugboat
filename:CCCam.cfg
filename:WebServers.xml
filename:_netrc password
filename:config irc_pass
filename:config.json auths
filename:config dbpasswd
filename:config.php pass
filename:config password language:PHP
filename:config password language:XML
filename:config key
filename:configuration.php JConfig password
filename:connections.xml
filename:credentials aws_access_key_id
filename:database
filename:dbeaver-data-sources.xml
filename:deployment-config.json
filename:dhcpd.conf
filename:express.conf path:.openshift
filename:filezilla.xml Pass
filename:hub oauth_token
filename:id_rsa or filename:id_dsa
filename:idea14.key
filename:jupyter_notebook_config.json
filename:logins.json
filename:manifest.xml
filename:master.key path:config
filename:passwd path:etc
filename:prod.exs NOT prod.secret.exs
filename:prod.secret.exs
filename:proftpdpasswd
filename:recentservers.xml Pass
filename:robomongo.json
filename:secrets.yml password
filename:server.cfg rcon password
filename:settings.py SECRET_KEY
filename:settings password
filename:settings key
filenane:settings secret
filename:sftp-config.json
filename:sftp.json path:.vscode
filename:shadow path:etc
filename:sshd_config
filename:travis.yml
filename:travis.yml password
filename:ventrilo_srv.ini
filename:vim_settings.xml
filename:wp-config.php
fullname:firstname lastname (fullname:<name> <surname>)
in:email (data in:email)
in:login (<username> in:login)
in:name (<username> in:name)
jsforce extension:js conn.login
language:html password
language:java api
language:perl password
language:php username
language:python username
language:shell username
language:sql username
msg nickserv identify filename:config
oauth
org:name (org:google type:users)
passcode
password
password hash
path:sites databases password
password
secret
shodan_api_key language:json
shodan_api_key language:python
shodan_api_key language:ruby
shodan_api_key language:shell
user auth
user:name (user:admin)
user_pass
user_password
xoxp OR xoxb
Bearer" :
keys"
token"
PRIVATE KEY-----" NOT test
其他github dorks补充
#email类型
googlemail.com
emailaddress
mailaddress
outlook.com
#htaccess
htaccess RewriteEngine On
htaccess General Apache options
htaccess AddOutputFilterByType
htaccess RewriteCond
#拼写错误的类型
filename:conffig
filename:seting
usser
pasword
passsword
passoword
seccret
secred
sicret
datebase
databasse
setttings
acccess
accout
acount
htacess
mesql
mysqql
bassword
filename:konfig
htaccess_file
.htaccess
htacces
.htacess
推荐相关Github Dork语法字典项目
https://github.com/techgaun/github-dorks
https://github.com/jcesarstef/ghhdb-Github-Hacking-Database
https://github.com/H4CK3RT3CH/github-dorks
https://github.com/Vaidik-pandya/Github_recon_dorks/blob/main/gitdork.txt
在线Github黑客语法工具
https://mr-koanti.github.io/github.html
推荐阅读:
原文始发于微信公众号(HACK学习君):干货 | 2022年最详细的Github黑客语法总结
免责声明:文章中涉及的程序(方法)可能带有攻击性,仅供安全研究与教学之用,读者将其信息做其他用途,由读者承担全部法律及连带责任,本站不承担任何法律及连带责任;如有问题可邮件联系(建议使用企业邮箱或有效邮箱,避免邮件被拦截,联系方式见首页),望知悉。
- 左青龙
- 微信扫一扫
-
- 右白虎
- 微信扫一扫
-
评论