Monday, March 6, 2017

New method to get CC with Google Dorks 2016

New Exclusive Method to get CC with Google Dorks 2016
Dear Users….

Today i will show you how to make unique dork and try to give you an idea that how important is it in hacking area.Lets assume hacker wants to find admin login page of all the site, so we have dork for this inurl because hacker wants to search admin login page and generally admin login page’s name look like adminlogin, admin, login etc.

                                                        
Note:-Everything Written Is Here Only For Educational Purpose…If You Do Any Illegal Activity…We are Not Responsible For That.
so we write dork : inurl:/admin
It will show you the admin dir. of sites. Its a simple dork.
inurl means in the URL, if we want to search on in text then we should write intext: comment.
Lets try another.
intext:”Hikvision” inurl:”login.asp”
The above dork will give us the login page of hikvision cameras which is installed like cctv.
Lets try some more complex and interesting:
intext:phpMyAdmin SQL Dump filetype:sql intext:INSERT INTO `admin` (`id`, `user`, `password`) VALUES -github
The above dork is finding sql dump files which are dumped file of databse of the website. so Here u can see all password and usernames also and all sensitive information which reside on the database.
Another interesting example:
ext:mdb inurl:*.mdb inurl:fpdb shop.mdb
The directory “http:/xxx/fpdb/” is the database folder used by some versions of FrontPage. It contains many types of Microsoft Access databases. It contains customer info like phone numbers but also plain text passwordsRemove the shop.mdb part to see the complete list of databases.
ext:log “Software: Microsoft Internet Information Services *.*”
Above google dork will give you the log files of the sites which has microsoft internet information server installed.This file include ftp usernames, password, path informations, database names.
intitle:”WSO 2.4″ [ Sec. Info ], [ Files ], [ Console ], [  Sql ], [ Php ], [ Safe mode ], [ String tools ], [ Bruteforce ], [  Network ], [ Self remove ]

The above dork will find the ESO 2.4 shells uploaded by the hacker on any server.
allintitle:”index.of” “backup files”

The above dork will give you the backup files of the server.
intitle:”apache 1.3 documentation”

The above dork will show you the apache 1.3 documentation page directly.
————————————————————————————————————————————-
Now come to the point. We all need credit card related dork.
so we need to find that kinds of site that store & save CC data.
Suppose we need credit card data, now if we target ebay.com then will we really get cc info from EBAY DATABASE ?
you will wonder we will not, We will get ebay users and theirs products info, etc etc.
We will not find anythings because ebay use paypal gateway, we input our cc data in paypal.com, so they store on paypal DATABASE not on EBAY.
I Give this example for those people who think only on shopping site contain users cc info. Its not correct idea. Shopping site didnt store it because its risky for them to give its security thats why they use a external payment gateway.
If you want to get some fresh cc , want wo build up a cc shop then it will better to target payment gateway , not shopping site.
For this you may write a dork like this :
intext:CVV2 inurl:checkout.php site:net

————————————————————————————————————————————-
If we want to Target a site of a specific country u can use this “site:” comment.
Like this,
inurl:checkout.php site:in
This dork will only show indian site.
Below is the list of Google dorks you can play with them:
1.“Index of /admin”
2. “Index of /password”
3. “Index of /mail”
4. “Index of /” +passwd
5. “Index of /” +password.txt
6. “Index of /” +.htaccess
7. index of ftp +.mdb allinurl:/cgi-bin/ +mailto
8. administrators.pwd.index
9. authors.pwd.index
10. service.pwd.index
11. filetype:config web
12. gobal.asax index
13. allintitle: “index of/admin”

No comments:

Post a Comment