Thursday, August 07, 2008

Other Sites passwords Revealing through Google

also visit my other blogs from


visit this link

Pay attention to your passwords, you can't imagine what can be discovered with google, some people ask me how to recover their blog or website because it was hacked, remember to always backup your files.

here are some examples you can try by yourself in google (just type the left part into Google's search box:



nurl:/db/main.mdb
style='mso-spacerun:yes'>

ASP-Nuke passwords



filetype:cfm “cfapplication
name” password
ColdFusion source with potential
passwords



filetype:pass pass
intext:userid
dbman credentials



allinurl:auth_user_file.txt
style='mso-spacerun:yes'>

DCForum user passwords



eggdrop filetype:user
user
Eggdrop IRC user credentials



filetype:ini
inurl:flashFXP.ini
FlashFXP FTP credentials



filetype:url +inurl:”ftp://”
+inurl:”@”
FTP bookmarks cleartext passwords



inurl:zebra.conf
intext:password -sample -test -tutorial –download
style='mso-spacerun:yes'>

GNU Zebra passwords



filetype:htpasswd
htpasswd
HTTP htpasswd Web user credentials



intitle:”Index of” “.htpasswd”
“htgroup” -intitle:”dist” -apache -htpasswd.c
style='mso-spacerun:yes'>

HTTP htpasswd Web user credentials



intitle:”Index of” “.htpasswd”
htpasswd.bak
HTTP htpasswd Web user credentials



“http://*:*@www” bob:bob
style='mso-spacerun:yes'>

HTTP passwords (bob is a sample
username)



“sets mode: +k”
style='mso-spacerun:yes'>

IRC channel keys (passwords)



“Your password is * Remember
this for later use”
IRC NickServ registration passwords



signin filetype:url
style='mso-spacerun:yes'>

JavaScript authentication
credentials



LeapFTP intitle:”index.of./”
sites.ini modified
LeapFTP client login credentials



inurl:lilo.conf filetype:conf
password -tatercounter2000 -bootpwd –man
style='mso-spacerun:yes'>

LILO passwords



filetype:config config
intext:appSettings “User ID”
Microsoft .NET application
credentials



filetype:pwd service
style='mso-spacerun:yes'>

Microsoft FrontPage Service Web
passwords



intitle:index.of
administrators.pwd
Microsoft FrontPage Web credentials



“# -FrontPage-”
inurl:service.pwd
Microsoft FrontPage Web passwords



ext:pwd inurl:_vti_pvt
inurl:(Service | authors | administrators)
style='mso-spacerun:yes'>

Microsoft FrontPage Web passwords



inurl:perform
filetype:ini
mIRC nickserv credentials



intitle:”index of”
intext:connect.inc
mySQL database credentials



intitle:”index of”
intext:globals.inc
mySQL database credentials



filetype:conf oekakibbs
style='mso-spacerun:yes'>

Oekakibss user passwords



filetype:dat wand.dat
style='mso-spacerun:yes'>

Opera, ÅúMagic Wand,Åù Web
credentials



inurl:ospfd.conf
intext:password -sample -test -tutorial –download
style='mso-spacerun:yes'>

OSPF Daemon Passwords



index.of passlist
style='mso-spacerun:yes'>

Passlist user credentials



inurl:passlist.txt
style='mso-spacerun:yes'>

passlist.txt file user credentials



filetype:dat
“password.dat”
password.dat files



inurl:password.log
filetype:log
password.log file reveals usernames,
passwords, and hostnames


filetype:log
inurl:”password.log”
password.log files cleartext
passwords



inurl:people.lst
filetype:lst
People.lst generic password file



intitle:index.of
config.php
PHP Configuration File database
credentials



inurl:config.php dbuname
dbpass
PHP Configuration File database
credentials



inurl:nuke filetype:sql
style='mso-spacerun:yes'>

PHP-Nuke credentials



filetype:conf
inurl:psybnc.conf “USER.PASS=”
psyBNC IRC user credentials



filetype:ini ServUDaemon
style='mso-spacerun:yes'>

servU FTP Daemon credentials



filetype:conf slapd.conf
style='mso-spacerun:yes'>

slapd configuration files root
password



inurl:”slapd.conf”
intext:”credentials” -manpage -”Manual Page” -man: -sample
style='mso-spacerun:yes'>

slapd LDAP credentials



inurl:”slapd.conf”
intext:”rootpw” -manpage -”Manual Page” -man: -sample
style='mso-spacerun:yes'>

slapd LDAP root password



filetype:sql “IDENTIFIED BY”
–cvs
SQL passwords



filetype:sql password
style='mso-spacerun:yes'>

SQL passwords



filetype:ini wcx_ftp
style='mso-spacerun:yes'>

Total Commander FTP passwords



filetype:netrc password
style='mso-spacerun:yes'>

UNIX .netrc user credentials



index.of.etc
style='mso-spacerun:yes'>

UNIX /etc directories contain
various credential files



intitle:”Index of..etc”
passwd
UNIX /etc/passwd user credentials



intitle:index.of passwd
passwd.bak
UNIX /etc/passwd user credentials



intitle:”Index of” pwd.db
style='mso-spacerun:yes'>

UNIX /etc/pwd.db credentials



intitle:Index.of etc
shadow
UNIX /etc/shadow user credentials



intitle:index.of
master.passwd
UNIX master.passwd user credentials



intitle:”Index of” spwd.db
passwd -pam.conf
UNIX spwd.db credentials



filetype:bak
inurl:”htaccess|passwd|shadow|htusers
UNIX various password file backups



filetype:inc dbconn
style='mso-spacerun:yes'>

Various database credentials



filetype:inc
intext:mysql_connect
Various database credentials, server
names



filetype:properties inurl:db
intext:password
Various database credentials, server
names



inurl:vtund.conf intext:pass
–cvs
Virtual Tunnel Daemon passwords



inurl:”wvdial.conf”
intext:”password”
wdial dialup user credentials



filetype:mdb wwforum
style='mso-spacerun:yes'>

Web Wiz Forums Web credentials



“AutoCreate=TRUE
password=*”
Website Access Analyzer user
passwords



filetype:pwl pwl
style='mso-spacerun:yes'>

Windows Password List user
credentials



filetype:reg reg
+intext:”defaultusername” intext:”defaultpassword”
style='mso-spacerun:yes'>

Windows Registry Keys containing
user credentials



filetype:reg reg
+intext:”internet account manager”
Windows Registry Keys containing
user credentials



“index of/” “ws_ftp.ini”
“parent directory”
WS_FTP FTP credentials



filetype:ini ws_ftp pwd
style='mso-spacerun:yes'>

WS_FTP FTP user credentials



inurl:/wwwboard
style='mso-spacerun:yes'>

wwwboard user credentials