
Bash-based fuzzing tool that leverages Google Dorking for stealthy enumeration of directories, files, subdomains, and parameters without direct server requests.
GooFuzz is a script written in Bash Scripting that uses advanced Google search techniques to obtain sensitive information in files or directories without making requests to the web server.
Want to learn about the new features in version 2.0 and how to use the tool correctly?
Check out the following article and get the most out of the tool.
cxId and apikey to a file. Both are free.GooFuzz-Project).API key.GooFuzz-Search) and click Create.cxId.git clone https://github.com/m3n0sd0n4ld/GooFuzz.git
cd GooFuzz
sudo apt install jq
chmod +x GooFuzz
./GooFuzz -h
git clone https://github.com/m3n0sd0n4ld/GooFuzz.git
cd GooFuzz
docker build -t goofuzz .
docker run --rm -it goofuzz -h
> ./GooFuzz -h
*********************************************************
* GooFuzz v.2.0 - The Power of Google Dorks *
* *
* David Utón (@David_Uton) *
*********************************************************
Usage:
-h Display this help message.
-k <FILE> Specify a FILE with CX_ID,API_KEY pairs, one per line.
-w <DICTIONARY> Specify a DICTIONARY, PATHS or FILES.
-e <EXTENSION> Specify comma-separated extensions.
-t <TARGET> Specify a DOMAIN or IP Address.
-p <PAGES> Specify the number of PAGES (Default: 1).
-x <EXCLUSIONS> EXCLUDES targets (comma-separated or file).
-d <DELAY> Delay in seconds between requests.
-s Lists subdomains of the specified domain.
-c <TEXT> Specify relevant content (comma-separated or file).
-o <FILENAME> Export the results to a file (results only).
-r <PROXY> Specify an [protocol://]host[:port] proxy.
Examples:
GooFuzz -t site.com -k keys_file.txt -e pdf,doc,bak
GooFuzz -t site.com -k keys_file.txt -s -p 10 -d 5 -o GooFuzz-subdomains.txt
GooFuzz -t site.com -k keys_file.txt -w config.php,admin,/images/
GooFuzz -t site.com -k keys_file.txt -w wordlist.txt
GooFuzz -t site.com -k keys_file.txt -w login.html -x dev.site.com
GooFuzz -t site.com -k keys_file.txt -w admin.html -x exclusion_list.txt
GooFuzz -t site.com -k keys_file.txt -c P@ssw0rd!
GooFuzz -t site.com -k keys_file.txt -e pdf -r http://proxy.example.com:8080
> ./GooFuzz -t nasa.gov -e pdf,doc,docx,txt,xls,zip -p 3 -k apikey.lst -o extensions.txt
*********************************************************
* GooFuzz v.2.0 - The Power of Google Dorks *
*********************************************************
Target: nasa.gov
===================================================================
Extension: pdf
===================================================================
https://above.nasa.gov/pdfs/20171020_ASC_Webinar.pdf
https://above.nasa.gov/safety/documents/Bear/bear_ID_brochure_BC.pdf
https://carbon.nasa.gov/pdfs/CMSAVtelecon_20150401_McKainSargent.pdf
https://fun3d.larc.nasa.gov/papers/LowPrecisionSolver.pdf
https://go.nasa.gov/385anj3
https://go.nasa.gov/42QfgGH
https://human-factors.arc.nasa.gov/publications/wenzel_1993_Localization_Head_Related.pdf
https://humansystems.arc.nasa.gov/publications/Barshi_Procedure_Checklist_Design_NASA_TM_2016.pdf
https://mars.nasa.gov/internal_resources/1489/
https://naif.jpl.nasa.gov/pub/naif/generic_kernels/spk/planets/de430_and_de431.pdf
https://nodis3.gsfc.nasa.gov/OPD_Docs/NAII_2800_2_.pdf
https://oig.nasa.gov/docs/IG-15-013.pdf
https://oig.nasa.gov/docs/IG-17-016.pdf
https://oig.nasa.gov/docs/IG-18-016.pdf
https://oig.nasa.gov/docs/IG-18-021.pdf
https://oig.nasa.gov/docs/IG-19-022.pdf
https://orbitaldebris.jsc.nasa.gov/library/usg_orbital_debris_mitigation_standard_practices_november_2019.pdf
https://s3vi.ndc.nasa.gov/ssri-kb/static/resources/529x0g1.pdf
https://sealevel.nasa.gov/internal_resources/535/Suva_Fiji_combined.pdf
https://smap.jpl.nasa.gov/files/smap2/SMAP_Handbook_FINAL_1_JULY_2014_Web.pdf
https://spacemath.gsfc.nasa.gov/moon/5Page28.pdf
https://spacemath.gsfc.nasa.gov/stars/5Page44.pdf
https://spacemath.gsfc.nasa.gov/stars/6Page106.pdf
https://spacemath.gsfc.nasa.gov/weekly/10Page55.pdf
https://spacemath.gsfc.nasa.gov/weekly/6Page89.pdf
https://spaceradiation.larc.nasa.gov/nasapapers/RP1257.pdf
https://spinoff.nasa.gov/back_issues_archives/1985.pdf
https://swift.gsfc.nasa.gov/analysis/xrt_swguide_v1_2.pdf
https://tmo.jpl.nasa.gov/progress_report2/42-44/44N.PDF
https://wind.nasa.gov/docs/MFI_Lepping_SSR1995.pdf
===================================================================
Extension: doc
===================================================================
https://acquisition.jpl.nasa.gov/download/terms-conditions/solicitation-group-a/A16-0359.doc
https://acquisition.jpl.nasa.gov/download/terms-conditions/solicitation-group-b/B13-2703.doc
https://acquisition.jpl.nasa.gov/download/terms-conditions/solicitation-group-b/B1-62-301.doc
https://acquisition.jpl.nasa.gov/download/terms-conditions/solicitation-group-b/B7-2891.doc