Transcription
Hello friend, today is about Google. I have mentioned them more than once and shown ways to use them in some situations, but it will be correct to systematize knowledge and analyze this topic entirely, if only because dorks are an extremely useful thing. Using Google's capabilities without dorks, of course, is possible, but only if you have a lot of free time and nothing else to do, because it is long and not very rational. And since OSINT is a sensitive matter, for a rational approach, it is worth understanding the issue of using dorks in detail and comprehensively. Before we start, don't forget to subscribe to the channel; it's not difficult for you, but it's pleasant for me. Well, you can also subscribe to Telegram; it's in the description. But if what I do is useful for you, then through the links in the description, you can support the channel financially to give me more motivation to do more and better. Well, we are starting. For effective use of Google dorks for Google in general, you need to know some points regarding the work of Google itself. First, case does not matter; it doesn't matter in which case, uppercase or lowercase, you write a query for Google, it's the same. This means that, for example, city names or surnames can be written with a lowercase letter, nothing will change. Second, a space between words for Google is a logical OR; that is, it will search not only for the entire phrase but also for each word separately, which accordingly greatly increases the number of results found and, accordingly, the time you will spend sifting through them all. In order for Google to search for an exact match, you need to enclose the search query in quotation marks, and you should always use this when possible. Firstly, to get more accurate results; secondly, to save your time. Furthermore, Google can inflect words, so there is no point in doing it manually, except for cases when you are looking for an exact match, i.e., in quotation marks. Google sorts results by relevance, meaning as it seems most relevant, and Google's opinion does not always coincide with our needs. Of course, the more precise and correct we make the query, the higher the desired answer will be in the results, but it is always worth exploring all the results offered to us. Google searches in the language in which the query is made. Of course, it can correctly translate, for example, names, but you shouldn't rely on it too much, because the most correct approach is to use the language in the query in which we need the result. The history of previous queries affects the result, and therefore the simplest option is to use incognito mode. And it's even better to have a separate browser for OSINT purposes, for example, some Brave, and in it, enable blocking of trackers, digital fingerprints, and automatic deletion of cookies and site data when closing the window. Well, and you don't need to log into Google accounts either, because in such a situation, even with blocking enabled, Google will remember your query history. And geolocation affects the result, which means that if you are looking for some information, for example, about France, it will not be superfluous if your IP is French. Well, and the most important point: dorks can and should be combined, because the combination of correct dorks significantly reduces the number of unnecessary results and greatly speeds up finding the necessary results. Within one video, it's unlikely I'll be able to show all combination options, and there's no point in that. Therefore, I will show the most frequently used combinations so that you understand the principle of how it works, and then everything will depend on your imagination. Now let's move on to the dorks themselves. As you probably know, there are quite a lot of them. The good news is that in OSINT, only a few are used more or less often, and it is their nuances, or rather the nuances of their use, that we will analyze. Let's start with the site dork. It is needed for searching by the content of a specific site. In the simplest version, after the colon, we simply specify the address of the site of interest, and then we enter the search query. And here we come to the first nuance: if there is a lot of information on the site and the query is not very specific, then Google will show a whole bunch of results, including pictures, videos, documents, in general, everything it finds and everything it considers relevant to our query. To get more accurate results, you need to either specify the query or filter out unnecessary results. Or it's best to do both. To specify the query, you need to formulate it in such a way that Google clearly understands what we want. The simplest option is to search for an exact match. For this, you need to enclose our query in quotation marks, for example, like this. This is because a space for Google is a logical OR; that is, when we write a query, it searches not only for the entire phrase but also for each word separately. A more illustrative example is searching for a person by last name, first name, and patronymic. If we write Petrov Alexey Nikolaevich, it will also find a lot of Petrovs, a lot of Alexeys, and a lot of Nikolaeviches. And if we put this query in quotation marks, it will search exclusively for Petrov Alexey Nikolaevich. Quotation marks work well if we know exactly what we are looking for, for example, as in the case of a surname. But sometimes it happens that it is difficult to formulate an exact query right away. For example, if we are looking for information about some event or when we don't know the exact name of what we need. Let's analyze such an example. This is an example of a query for a case when we know exactly part of the question. In our case, we are looking for a guide, but we don't know exactly what it's a guide for, because in parentheses, we list the options that interest us, using the OR operator. You can use a forward slash. Parentheses work here in the same way as in mathematical equations for separating multiple elements. There can also be a case when we know only part of the exact name. In this situation, the query will look like this: we replaced the unknown word with the asterisk operator; it means any value. In all the examples listed, we got very similar results. The meaning of all this is that based on the initial data we have, we select a search query and combine it with search operators to get the desired answer. This, by the way, is the main principle of using dorks, in particular, and Google in general. Another important point of using Google is that to formulate the correct query, you should Google not the question that interests you, but that part of the answer to it that you know, i.e., the expected search result. Then Google, with a higher probability, based on the match of the query and the indexed information, will give you what you need. When using the site dork, it is not necessary to specify the entire address. After all, it can happen that we don't know exactly which site has the necessary information, for example, like this. Essentially, we have now told Google to find all information on the query "list of employees" on all sites with the domain gold.ru. But there may be a need to search not just for information, but for a document. Then we should specify the query by adding FileType to the dork, after which we specify the extension of the file of interest. I talked about the FileType dork in detail in the video "How to Search and Analyze Documents," and also in the article on the website and in Telegram. I will leave a reference guide for all existing file extensions, a reference guide for file formats for Vortex or PowerPoint, and a list of the most common extensions indexed by Google. Another useful operator is the minus sign. It allows you to remove results that we definitely don't need. This can be anything. For example, you can remove a site or a part of the query from the results. For example, if, as in the previous case, we are looking for a list of employees, but we definitely don't need employees of, for example, the Ministry of Finance, then the query will look like this. Another example: you are looking for a person by surname, but he has a namesake who works as a dentist, and in the search results, a lot of sites with reviews, advertising, or something similar related to his work pop up. Accordingly, the simplest solution would be to remove everything from the results where the words dentist, doctor, or other synonyms are mentioned. When studying sites, another useful dork not to forget is cache. Its use will show the version of the site that was saved in Google's cache. The time and date when this version was added will also be indicated. You can view the site in three variants: full view, text version, and source code. By the way, this is not the only way to see a cached version of a site. When you Google something, in the search results near the page address, there is a small arrow. If you click on it, a "Saved copy" button will appear. By clicking on it, we will also see the version of the site from Google's cache. If we are studying a site, it is definitely worth checking the cached version, because sometimes there is information there that is no longer on the current version of the site. This can also help if the site is currently not working or the necessary information has been deleted, but we see it in the search results. Two more useful dorks that you need to know are inurl and allinurl. As you might guess, the essence is that they search by URL. The difference is that inurl searches only by one word that is specified immediately after the colon, and allinurl searches by the phrase that is specified after the colon. One of the possible applications, for example, if you find an email address, the logic of use is that people very often use similar names in their email addresses, which often coincide with names used for registration on other sites, including social networks. Accordingly, we take the first part of the email address and use the inurl dork. As a result, we get social network accounts and sites where this name is used. This is generally a universal dork. You can see how a particular site forms its URLs and, based on this, figure out how to use this dork to search for the necessary information. The inurl dork can be combined with other dorks. For example, we can search on a specific site by specifying it with the site dork. In this way, you can search for posts on social networks, for example. Similar situations are greatly helped by additional Google tools. If you click the "Tools" button, you can specify the time range for which you need results or even a specific date. In the case of the allinurl dork, if we are looking for social networks, we will use the full name if it is known. As a result, we will get all sites in whose URL the desired name is present. Here you need to remember that this dork works on its own and cannot be combined with other dorks. In the previous example, we searched in the URL, but on the same principle, you can search in the page title. For this, the intitle and allintitle dorks are used. They work symmetrically: intitle searches by the word that is specified after the colon. Well, as an option, you can specify a multi-word query in quotation marks. And allintitle searches by the phrase that is specified after the colon. Since we can search in the URL and in the title, then of course, we can also search in the site's body, or more precisely, in everything that is between the Body tags. For this, the intext and allintext dorks are used. The logic of application is exactly the same as for the two previous ones. Another useful dork worth mentioning is Around. It helps to search in situations when we cannot formulate the entire query completely, but we know that there are a few words between its elements. The approximate, or rather the maximum number of these unknown words, we enter as numbers in parentheses, for example, like this. Well, and finally, there is a cool dork constructor, dorksearch.com. There you can create your own Google dork combinations, or there are already ready-made templates. In any case, it will be useful for those who are too lazy to type dorks manually, as well as for those who want to study the topic more deeply, because there are many options to explore and try. As you can see, just using Google dorks gives us enormous search capabilities. Of course, within this video, I have shown not all possible dork combinations, and not even all dorks, but that was not the goal. The main thing you need is to understand the principle of how it works and gain practice, because this is precisely the topic where experience matters, and the scope of application is practically limitless, starting from searching for people and studying news, to searching for subdomains, directories, passwords from binomo, or checking for plagiarism. It all comes down to your imagination and desire, so don't limit yourself to the examples I've shown, but come up with your own combinations and areas of application. And with you, as always, was Puls. Subscribe to the channel and see you next time.