More Google Hacking Using the “inurl” Operator

Written by: Peter Jalbert on Tuesday, August 22nd, 2006
Posted to: Google, Search
6 comments, add yours!

We had some fun with using the “intitle” operator in Google search. Now here are more google hacks using “inurl”.

“inurl” is used to search within a site’s URL itself. This is very useful if you are familiar with a URL string or with standard URL strings used by different content management systems.

There are a host of other keywords in directory listings that you can use to explore web servers. Of course, we don’t recommend using these for malicious intent. Everything is for acemic purposes only, okay? Also, if you’re a webmaster, it helps to know if your own servers are not vulnerable to these “Google attacks.” You can even play the good samaritan by contacting owners of hosting accounts that blatantly put out their directory listings and thus endanger their host’s security.

Of course, it goes without saying that directory listings that aren’t at the root folder cannot be crawled by Google unless they are linked to directly on any other open website that Google can crawl. This means you can theoretically hide your directory from prying eyes even if it’s not locked out from viewing as long as you do not link to it from other sites. Also, it helps if you use long directory names that cannot be found in the dictionary.

Some examples

You can search for the words “admin” and “userlist” within the URL to come up with open directories that contain userlists.

inurl:admin inurl:userlist

You can also search for websites that use WordPress as their CMSes (even sites that are non-blogs).

inurl:wp-admin

You can use this in conjunction with the site: operator to get sites in that domain or domainspace that use WordPress as CMS (and perhaps you can try to hack them using known WordPress vulnerabilities, if any).

For example, this would give you a results page of all .US sites that use WordPress.

inurl:wp-admin +site:.us

Happy hacking!

Don't miss another post! Subscribe by RSS feed or by email today!

Share this post!   6 comments, add yours!

6 Responses to “More Google Hacking Using the “inurl” Operator”

  1. […] More Google Hacking Using the “inurl” Operator […]

  2. tyon 15 Jul 2007 at 8:28 pm

    None of thies links work

  3. steveon 14 Jan 2008 at 4:40 am

    there is noting hacking about any of this.

  4. greenseaameron 12 May 2008 at 4:23 am

    a bit of I noticed It is then did and one day, crashing down a job woods on me. for kids them.

  5. Rodrigoon 06 Aug 2008 at 6:09 pm

    Is there a way to do something like this?

    inurl:(not)php
    or maybe
    inurl:-php

    I’d like to make a search like this:
    something about php blablabla inurl:(not)php

  6. Rodrigoon 06 Aug 2008 at 6:11 pm

    I found it..

    -inurl:php blabla php

    thanks anyway!

Trackback URI | Comments RSS

Leave a Reply