recon
Google Dorks
Google Dorks ใช้ search operator ขั้นสูงค้นหาข้อมูลที่ถูก index แต่ไม่ตั้งใจเปิดเผย — ไฟล์ sensitive, login page, exposed config, error message เป็น passive recon ทรงพลัง บทนี้ลงลึก operator ทุกตัว, dork สำเร็จรูปตามเป้าหมาย, GHDB, และการใช้กับ target (เนื้อหาเพื่อ recon ที่ได้รับอนุญาต)
BeginnerIntermediate#google-dorks#recon#osint#operators#exposed-files#passive#ctf
1. หลักการ
Google index หน้าเว็บมหาศาล รวมถึงไฟล์/หน้าที่เจ้าของไม่ตั้งใจเปิดเผยแต่ไม่ได้ป้องกัน — config, backup, login page, directory listing, error ที่เผยข้อมูล Google Dorks ใช้ search operator ค้นเจาะจงสิ่งเหล่านี้ เป็น passive recon (ค้น Google ไม่แตะ target) ที่บางทีเจอข้อมูลอ่อนไหวโดยตรง
เนื้อหานี้เพื่อการ reconnaissance ในงานที่ได้รับอนุญาต (CTF, OSINT, pentest) เท่านั้น — เข้าถึงเฉพาะข้อมูลที่ index สาธารณะ ไม่เจาะระบบ
2. Search operators
| operator | ความหมาย | ตัวอย่าง |
|---|---|---|
| site: | เฉพาะ domain | site:example.com |
| filetype: / ext: | ชนิดไฟล์ | filetype:pdf |
| intitle: | ใน title | intitle:"index of" |
| inurl: | ใน URL | inurl:admin |
| intext: | ในเนื้อหา | intext:password |
| cache: | หน้า cache | cache:example.com |
| "..." | exact phrase | "confidential" |
| - | ไม่รวม | site:example.com -www |
| OR / | | หรือ | admin OR login |
3. Dork สำเร็จรูปตามเป้าหมาย
dork ยอดนิยม (แทน example.com ด้วย target)
# เอกสาร/ไฟล์ของ target
site:example.com filetype:pdf
site:example.com filetype:xlsx OR filetype:docx
site:example.com filetype:env OR filetype:config OR filetype:bak
# directory listing (เปิดดูไฟล์ได้)
site:example.com intitle:"index of"
intitle:"index of" "parent directory" site:example.com
# login / admin pages
site:example.com inurl:login OR inurl:admin OR inurl:portal
# exposed credential/config
site:example.com intext:password OR intext:"api_key"
site:example.com ext:env "DB_PASSWORD"
site:example.com inurl:wp-config OR inurl:.git
# error messages (เผย tech/path)
site:example.com intext:"sql syntax near" OR intext:"stack trace"
# subdomains
site:*.example.com -www
# exposed services
site:example.com inurl:phpmyadmin OR inurl:jenkinsเริ่มจาก site:target + filetype/inurl/intext; index of = directory listing; ระวังไฟล์ที่เป็นข้อมูลจริงของ target
4. GHDB + automation
- Google Hacking Database (GHDB): exploit-db.com/google-hacking-database — dork สำเร็จรูปหลายพันรายการ จัดหมวด (login, files, vulnerable servers, ...)
- ใช้ dork จาก GHDB + เติม
site:targetเพื่อเจาะเฉพาะเป้าหมาย - หลาย search engine: dork ใช้กับ Bing, DuckDuckGo, Yandex ได้ (operator ต่างเล็กน้อย) — บางที index ต่างกัน
- tools: เครื่องมือ automate dork มี (เช่น pagodo) แต่ระวัง Google rate-limit/CAPTCHA — manual มัก practical กว่า
- specialized: Shodan/Censys (ดูหัวข้อนั้น) สำหรับ exposed service/device โดยตรง
5. Quick Reference
- passive recon — ค้นข้อมูลที่ index แต่ไม่ตั้งใจเปิด
- operators: site: filetype: intitle: inurl: intext: "phrase"
- directory listing: site:X intitle:"index of"
- config/cred: site:X ext:env OR filetype:bak intext:password
- login: site:X inurl:admin OR inurl:login
- GHDB (exploit-db) = dork สำเร็จรูป + เติม site:target
- ใช้กับ Bing/Yandex ได้; Shodan/Censys สำหรับ service
🧭 จับมือทำทีละขั้น (มีแค่ Kali) + ถ้าติดไปไหนต่อ
สมมติมีแค่ชื่อ domain กับเบราว์เซอร์ ไม่มีเครื่องมือพิเศษเลย อยากหาไฟล์/หน้าที่ target เผลอเปิดเผย ทำตามนี้ทีละขั้น
- 1เริ่มจาก dork กว้างๆ ก่อน:
site:target.comดูว่า index ไว้เยอะแค่ไหน - 2หา directory listing ที่เปิดโล่ง:
site:target.com intitle:"index of" - 3หาไฟล์เอกสาร/สำรอง:
site:target.com filetype:pdf OR filetype:xlsx OR filetype:bak - 4หาหน้า login/admin:
site:target.com inurl:admin OR inurl:login OR inurl:portal - 5หา config/credential ที่หลุด:
site:target.com ext:env "DB_PASSWORD" - 6ถ้ายังไม่เจออะไร ลองเปิด exploit-db.com/google-hacking-database (GHDB) หา dork สำเร็จรูปเพิ่ม
- 7เอา dork จาก GHDB มาเติม
site:target.comแล้วลองทีละอัน - 8ลองสลับ search engine (Google อาจ rate-limit): ใช้ syntax เดียวกันกับ Bing/DuckDuckGo
- 9เจอไฟล์/หน้าอ่อนไหว → เปิดดูเนื้อหา จดว่ามี credential/endpoint/path อะไรที่ต่อยอดได้
- 10ถ้า dork ไม่เจออะไรเลยหลังลองครบ สลับไปทาง GitHub Dorks (บางทีของหลุดใน repo ไม่ใช่หน้าเว็บ) หรือ directory enumeration ตรงๆ
dork เจอของไหม? ทำอะไรต่อ
site:target.com + operator (filetype/inurl/intext)
เจอไฟล์/หน้าที่น่าสนใจไหม?
✅ เจอ (index of / config / login page)→→ เปิดดู เก็บข้อมูลต่อยอด
❌ ไม่เจอเลย→→ ลอง dork จาก GHDB / สลับ search engine
ลอง GHDB (exploit-db) + Bing/DuckDuckGo
✅ เจอเพิ่ม→→ เปิดดู เก็บข้อมูลต่อยอด
❌ ยังไม่เจอ→→ ข้ามไปหาทางอื่น
| ขั้นตอน/งาน | เครื่องมือใน Kali | ติดตั้งเพิ่ม (ถ้าไม่มี) | เครื่องมือออนไลน์ |
|---|---|---|---|
| ค้น dork หลัก | เบราว์เซอร์ | - | google.com, bing.com |
| หา dork สำเร็จรูป | - | - | exploit-db.com/google-hacking-database |
| สลับ search engine | - | - | bing.com, duckduckgo.com |
| ดูหน้าที่ถูกลบไปแล้ว | - | - | web.archive.org |
| automate dork (ระวัง rate-limit) | python3 | pip install pagodo | - |
| หา service/port แทนไฟล์ | - | - | shodan.io, censys.io |
🚑 ถ้าตันสนิท ลองท่าถัดไป: GitHub Dorks (ถ้าเว็บไม่มีอะไรหลุด ลองหา secret ใน repo แทน), Directory Enumeration (dork หา index of ไม่เจอ ลอง brute-force path ตรงๆ ด้วย ffuf/gobuster), Web Methodology (พอเจอ endpoint/หน้า admin แล้ว ไปวางแผนทดสอบเว็บแอปแบบเต็ม), Info Gathering (รวบรวมข้อมูลที่เจอทั้งหมดมาวางแผน attack surface ต่อ)
หัวข้อที่เชื่อมโยง
Information Gatheringเกี่ยวข้องโดยตรงGitHub Dorksอยู่ใน workflowWHOISเทคนิคเดียวกันCensysเทคนิคเดียวกันSubdomain EnumerationเทคนิคเดียวกันASN EnumerationเทคนิคเดียวกันShodanเทคนิคเดียวกันAmassเทคนิคเดียวกันAssetfinderเทคนิคเดียวกันSubfinderเทคนิคเดียวกันDirectory Enumerationอยู่ใน workflowDNS Enumerationเทคนิคเดียวกัน
โน้ตของฉัน
ยังไม่มีโน้ตสำหรับหัวข้อนี้