Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
google-dorks-bug-bounty — 버그 바운티, 웹 애플리케이션 보안 및 침투 테스트를 위한 Google Dorks 목록 | Kitploit
도구/GitHubGitHub/taksec/google-dorks-bug-bounty
OSINT (Open Source Intelligence)ReconnaissanceInformation GatheringWeb SecurityCurated Resources
GitHubtaksec/google-dorks-bug-bounty

google-dorks-bug-bounty

버그 바운티, 웹 애플리케이션 보안 및 침투 테스트를 위한 Google Dorks 목록

저장소 보기
1.9k269411개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

버그 바운티를 위한 Google Dorks

버그 바운티, 웹 애플리케이션 보안, 모의 침투 테스트를 위한 Google Dorks 목록

Live Tool

도구 스크린샷

Twitter URL


부정 검색을 포함한 광범위 도메인 검색

root@kitploit:~
site:example.com -www -shop -share -ir -mfa

매개변수가 있는 PHP 확장자

root@kitploit:~
site:example.com ext:php inurl:?

API 엔드포인트

root@kitploit:~
site:example[.]com inurl:api | site:*/rest | site:*/v1 | site:*/v2 | site:*/v3

유용한 확장자들

root@kitploit:~
site:"example[.]com" ext:log | ext:txt | ext:conf | ext:cnf | ext:ini | ext:env | ext:sh | ext:bak | ext:backup | ext:swp | ext:old | ext:~ | ext:git | ext:svn | ext:htpasswd | ext:htaccess | ext:json

높은 비율의 inurl 키워드

root@kitploit:~
inurl:conf | inurl:env | inurl:cgi | inurl:bin | inurl:etc | inurl:root | inurl:sql | inurl:backup | inurl:admin | inurl:php site:example[.]com

서버 오류

root@kitploit:~
inurl:"error" | intitle:"exception" | intitle:"failure" | intitle:"server at" | inurl:exception | "database error" | "SQL syntax" | "undefined index" | "unhandled exception" | "stack trace" site:example[.]com

XSS 취약점이 발생하기 쉬운 매개변수

root@kitploit:~
inurl:q= | inurl:s= | inurl:search= | inurl:query= | inurl:keyword= | inurl:lang= inurl:& site:example.com

오픈 리다이렉트 취약점이 발생하기 쉬운 매개변수

root@kitploit:~
inurl:url= | inurl:return= | inurl:next= | inurl:redirect= | inurl:redir= | inurl:ret= | inurl:r2= | inurl:page= inurl:& inurl:http site:example.com

SQLi 취약점이 발생하기 쉬운 매개변수

root@kitploit:~
inurl:id= | inurl:pid= | inurl:category= | inurl:cat= | inurl:action= | inurl:sid= | inurl:dir= inurl:& site:example.com

SSRF 취약점이 발생하기 쉬운 매개변수

root@kitploit:~
inurl:http | inurl:url= | inurl:path= | inurl:dest= | inurl:html= | inurl:data= | inurl:domain=  | inurl:page= inurl:& site:example.com

LFI 취약점이 발생하기 쉬운 매개변수

root@kitploit:~
inurl:include | inurl:dir | inurl:detail= | inurl:file= | inurl:folder= | inurl:inc= | inurl:locate= | inurl:doc= | inurl:conf= inurl:& site:example.com

RCE 취약점이 발생하기 쉬운 매개변수

root@kitploit:~
inurl:cmd | inurl:exec= | inurl:query= | inurl:code= | inurl:do= | inurl:run= | inurl:read=  | inurl:ping= inurl:& site:example.com

파일 업로드 엔드포인트

root@kitploit:~
site:example.com intext:”choose file” | intext:"select file" | intext:"upload PDF"

API 문서

root@kitploit:~
inurl:apidocs | inurl:api-docs | inurl:swagger | inurl:api-explorer | inurl:redoc | inurl:openapi | intitle:"Swagger UI" site:"example[.]com"

로그인 페이지

root@kitploit:~
inurl:login | inurl:signin | intitle:login | intitle:signin | inurl:secure site:example[.]com

테스트 환경

root@kitploit:~
inurl:test | inurl:env | inurl:dev | inurl:staging | inurl:sandbox | inurl:debug | inurl:temp | inurl:internal | inurl:demo site:example.com

민감한 문서

root@kitploit:~
site:example.com ext:txt | ext:pdf | ext:xml | ext:xls | ext:xlsx | ext:ppt | ext:pptx | ext:doc | ext:docx
intext:"confidential" | intext:"Not for Public Release" | intext:”internal use only” | intext:"do not distribute"

민감한 매개변수

root@kitploit:~
inurl:email= | inurl:phone= | inurl:name= | inurl:user= inurl:& site:example[.]com

Adobe Experience Manager (AEM)

root@kitploit:~
inurl:/content/usergenerated | inurl:/content/dam | inurl:/jcr:content | inurl:/libs/granite | inurl:/etc/clientlibs | inurl:/content/geometrixx | inurl:/bin/wcm | inurl:/crx/de site:example[.]com

공개된 XSS 및 오픈 리다이렉트

root@kitploit:~
site:openbugbounty.org inurl:reports intext:"example.com"

Google 그룹

root@kitploit:~
site:groups.google.com "example.com"

코드 유출

root@kitploit:~
site:pastebin.com "example.com"
root@kitploit:~
site:jsfiddle.net "example.com"
root@kitploit:~
site:codebeautify.org "example.com"
root@kitploit:~
site:codepen.io "example.com"

클라우드 스토리지

root@kitploit:~
site:s3.amazonaws.com "example.com"
root@kitploit:~
site:blob.core.windows.net "example.com"
root@kitploit:~
site:googleapis.com "example.com"
root@kitploit:~
site:drive.google.com "example.com"
root@kitploit:~
site:dev.azure.com "example[.]com"
root@kitploit:~
site:onedrive.live.com "example[.]com"
root@kitploit:~
site:digitaloceanspaces.com "example[.]com"
root@kitploit:~
site:sharepoint.com "example[.]com"
root@kitploit:~
site:s3-external-1.amazonaws.com "example[.]com"
root@kitploit:~
site:s3.dualstack.us-east-1.amazonaws.com "example[.]com"
root@kitploit:~
site:dropbox.com/s "example[.]com"
root@kitploit:~
site:docs.google.com inurl:"/d/" "example[.]com"

JFrog Artifactory

root@kitploit:~
site:jfrog.io "example[.]com"

Firebase

root@kitploit:~
site:firebaseio.com "example[.]com"

도메인 없이 더 잘 작동하는 Dorks

버그 바운티 프로그램 및 취약점 공개 프로그램

root@kitploit:~
"submit vulnerability report" | "powered by bugcrowd" | "powered by hackerone"
root@kitploit:~
site:*/security.txt "bounty"

Apache 서버 상태 노출

root@kitploit:~
site:*/server-status apache

WordPress

root@kitploit:~
inurl:/wp-admin/admin-ajax.php

Drupal

root@kitploit:~
intext:"Powered by" & intext:Drupal & inurl:user

Joomla

root@kitploit:~
site:*/joomla/login

더 많은 Dorks를 위한 Medium 글:

https://thegrayarea.tech/5-google-dorks-every-hacker-needs-to-know-fed21022a906

https://infosecwriteups.com/uncover-hidden-gems-in-the-cloud-with-google-dorks-8621e56a329d

https://infosecwriteups.com/10-google-dorks-for-sensitive-data-9454b09edc12

인기 매개변수:

https://github.com/lutfumertceylan/top25-parameter

Proviesec Dorks:

https://github.com/Proviesec/google-dorks

도구 다운로드