Home Settings
Security OSINT • Google Dorking Recon Suite

Security Dorking Recon

Automate target scoping, discover exposed databases, open directories, and confidential records.

🎯 Target Domain Scope (Prepend site:target.com across all dorks)
Exposed .env Credentials
high
Finds publicly accessible dotenv files containing database credentials and app secrets.
filetype:env "DB_PASSWORD" OR "APP_KEY" OR "SECRET_KEY"
AWS / Cloud Credentials
high
Discovers exposed cloud service accounts, AWS credentials, and GCP service keys.
filetype:json "aws_secret_access_key" OR "private_key_id"
Exposed .git Folder
high
Detects misconfigured web servers exposing the entire Git repository history and source code.
inurl:"/.git/config" OR inurl:"/.git/HEAD"
SSH Private Keys
high
Identifies leaked RSA and OpenSSH private encryption keys.
intext:"BEGIN RSA PRIVATE KEY" OR intext:"BEGIN OPENSSH PRIVATE KEY"
Docker & Kubernetes Configs
medium
Detects container and cluster manifests containing hardcoded database credentials.
filename:docker-compose.yml "POSTGRES_PASSWORD" OR filename:kubeconfig
Web Server Directory Index
medium
Locates web servers with auto-indexing enabled exposing underlying folder structures.
intitle:"index of /" "parent directory"
Exposed Backup Archives
high
Finds forgotten full-site backup archives, database snapshots, and zipped source code.
intitle:"index of" (backup.zip OR backup.tar.gz OR site_backup.sql)
Server Log Files
medium
Discovers open server access logs exposing visitor IP addresses, query strings, and system errors.
intitle:"index of /" "access.log" OR "error.log" OR "debug.log"
Open FTP Directories
medium
Finds anonymous or publicly readable FTP directory mirrors.
intitle:"index of /" inurl:ftp
CMS & Web Admin Logins
medium
Discovers authentication endpoints for WordPress, Joomla, Drupal, and custom CMS portals.
inurl:admin/login.php OR inurl:wp-login.php OR inurl:administrator/index.php
phpMyAdmin & Adminer
high
Locates publicly exposed database management consoles.
inurl:phpmyadmin/index.php OR inurl:adminer.php intitle:"Login"
Grafana & Kibana Dashboards
medium
Detects unauthenticated telemetry dashboards and log analytics consoles.
intitle:"Grafana - Home" OR intitle:"Kibana - Discover" inurl:app/kibana
cPanel & Webmin Ports
medium
Identifies exposed web hosting control panels.
inurl:":2083" OR inurl:":10000" intitle:"Webmin Login"
Raw SQL Export Dumps
high
Detects exposed SQL database export files containing user tables and hashed credentials.
filetype:sql ("INSERT INTO" AND "password") OR "CREATE TABLE users"
SQLite Database Files
high
Finds downloadable SQLite database files used by desktop apps and embedded services.
filetype:sqlite OR filetype:db "SQLite format 3"
JSON & MongoDB Collections
high
Discovers exported MongoDB collections and JSON user data stores.
filetype:json ("_id" AND "password_hash" OR "hashedPassword")
Confidential & Internal PDFs
high
Locates leaked corporate documents labeled as strictly confidential.
filetype:pdf ("CONFIDENTIAL" OR "INTERNAL USE ONLY" OR "STRICTLY PRIVATE")
Salary & Payroll Spreadsheets
high
Finds exposed human resources spreadsheets containing employee compensation details.
filetype:xlsx OR filetype:csv ("salary" OR "payroll" OR "bonus" OR "gross pay")
Password Lists & Cleartext Credentials
high
Discovers plain text files and notes containing system passwords.
filetype:txt OR filetype:docx ("username" AND "password" AND "login")
Live phpinfo() Diagnostic
medium
Discloses exact PHP version, enabled modules, operating system, and internal file paths.
intitle:"phpinfo()" "PHP Version" "System" "Loaded Configuration File"
Swagger / OpenAPI Docs
info
Detects exposed interactive REST API documentation and hidden internal endpoints.
inurl:"/swagger-ui.html" OR inurl:"/api-docs" OR inurl:"/swagger/v1/swagger.json"
Spring Boot Actuator
high
Finds vulnerable Java Spring Boot actuator endpoints leaking environment variables.
inurl:"/actuator/env" OR inurl:"/actuator/heapdump"
Detailed Error Stack Traces
medium
Locates unhandled web application errors exposing line numbers, SQL queries, and source code.
"Fatal error:" OR "Uncaught exception" inurl:".php"
AWS S3 Public Buckets
medium
Discovers public cloud storage buckets containing company assets and backups.
site:s3.amazonaws.com OR site:storage.googleapis.com
Open Firebase Databases
high
Detects unauthenticated Firebase real-time databases dumping complete app state.
site:firebaseio.com inurl:.json
Live Video Webcams
medium
Finds public network surveillance cameras streaming video without authentication.
intitle:"Live View / - AXIS" OR inurl:"view/view.shtml" OR intitle:"Network Camera NetworkCamera"
Networked Office Printers
medium
Locates exposed enterprise network printer consoles and queue management pages.
intitle:"Network Print Server" OR inurl:"hp/device/this.LCDispatcher"