During passive reconnaissance you want to discover whether the target company has accidentally left downloadable SQL database dumps exposed on any of its publicly reachable sub-domains. Which Google dork will most precisely list those files while avoiding results that reside on unrelated domains?
The Google operator "site:" limits results to the specified domain and all of its sub-domains, while "filetype:" restricts the returned documents to a given extension. Therefore, the query "site:*.example.com filetype:sql" (with the asterisk wildcard for any sub-domain) will show only .sql files hosted under any host inside example.com.
The other options are less precise:
Using "inurl:" simply searches for the text in the URL and can return results from many different domains that mention the string, so it does not guarantee the file is hosted by the target.
The "link:" operator lists pages that link to a domain, not files served by it, so it is unsuitable for locating exposed dumps.
"ext:" works like "filetype:", but without the domainālimiting "site:" it can return SQL backups stored anywhere on the Internet, not just the company's infrastructure. Thus, only the combination of the wildcarded "site:" operator with the appropriate "filetype:" filter meets all requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is passive reconnaissance in ethical hacking?
Open an interactive chat with Bash
What are Google dorks and how are they used in cybersecurity?
Open an interactive chat with Bash
What does the 'site:' and 'filetype:' operators achieve in a Google search query?
Open an interactive chat with Bash
What is passive reconnaissance?
Open an interactive chat with Bash
What is a Google dork?
Open an interactive chat with Bash
What is the 'site:' operator in Google searches?
Open an interactive chat with Bash
Certified Ethical Hacker (CEH)
Reconnaissance Techniques
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .