GHDB « Hackers For Charity

GHDB

GHDB

Google Search: filetype:bak createobject sa

nihil2006 rates this entry 10 out of 10.
Submitted: 2006-01-01 00:00:00
Added by: nihil2006
Hits: 1151
Score: 10

This query searches for files that have been renamed to a .bak extension (obviously), but includes a search for the characters “sa” (default SQL server admin id) and “createobject” which is requisite VBScript for opening some sort of odbc/ado connection. Since the sql id and password are plain text, it’s easy to connect to the SQL server once you have this information… especially those that use “server=127.0.0.1″ so you know IIS & SQL Server are running on the same box.


Comments:


5 Responses to “GHDB”

  1. Jack says:

    Does GHDB still updates for now?

  2. Johnny says:

    The GHDB is alive and well, updated through the ExploitDB: http://www.exploit-db.com/google-dorks.

  3. The Artist says:

    Hi Johnny,been a while since I’ve came last. Aren’t you gonna update this website anymore???

  4. Johnny says:

    The GHDB is not updated and lives with the exploitdb: http://http://www.exploit-db.com. Please check out the awesome folks at Offensive Security as well: http://www.offensive-security.com!

  5. Velmurugan says:

    Is any offline view-able resources is available of this product ?

Leave a Reply