Skip to content
OSINT GemsSubmit a resource

Google Hacking Database

Catalog of Google search queries, known as dorks, that surface exposed files, devices, and sensitive pages.

Visit Google Hacking Database
Previewexploit-db.com
Screenshot of Google Hacking Database
Price
Free

The Google Hacking Database is Offensive Security’s catalog of Google dorks: search queries that find things people did not mean to leave in public. Exposed documents, login panels, configuration files, cameras, error messages that leak paths. Each entry has a date, a category, and an author. The collection lives on Exploit-DB.

It is a reference, not a scanner. You copy a query, you adapt it to your target or your scope, you run it in a search engine, you look at what came back. Google, Bing, and others change their operators and their appetite for this kind of traffic. A dork that worked last year can return nothing today.

How I use it

When I have a domain and I want to know what a search engine already indexed. That is often faster than crawling the site yourself, and it is the indexed copy that an outsider would find. I keep a short list of dorks I actually understand (site:, filetype:, inurl:) and I use GHDB when I need a reminder of a pattern I have not run in a month.

I do not run the whole catalog against a random company for fun. A lot of these queries exist because someone found a real exposure. Replaying them without a reason is how you become the event in someone else’s log.

Why it is listed

Because “just Google it” is still half of OSINT, and this is the grown-up cheat sheet. It is free, it is categorized, and it does not require an account. I keep it for the questions, not for a finished result.

Find resources like this

Related