swiss army list for every bug hunter 💀💀💀
</p>
site:*.example.com
site:example.com -www -shop -share -ir -mfa
site:example.com ext:php inurl:?
site:openbugbounty.org inurl:reports intext:”example.com”
site:”example[.]com” ext:log ext:txt ext:conf ext:cnf ext:ini ext:env ext:sh ext:bak ext:backup ext:swp ext:old ext:~ ext:git ext:svn ext:htpasswd ext:htaccess
inurl:q= inurl:s= inurl:search= inurl:query= inurl:keyword= inurl:lang= inurl:& site:example.com
inurl:url= inurl:return= inurl:next= inurl:redirect= inurl:redir= inurl:ret= inurl:r2= inurl:page= inurl:& inurl:http site:example.com
inurl:id= inurl:pid= inurl:category= inurl:cat= inurl:action= inurl:sid= inurl:dir= inurl:& site:example.com
inurl:http inurl:url= inurl:path= inurl:dest= inurl:html= inurl:data= inurl:domain= inurl:page= inurl:& site:example.com
inurl:include inurl:dir inurl:detail= inurl:file= inurl:folder= inurl:inc= inurl:locate= inurl:doc= inurl:conf= inurl:& site:example.com
inurl:cmd inurl:exec= inurl:query= inurl:code= inurl:do= inurl:run= inurl:read= inurl:ping= inurl:& site:example.com
inurl:config inurl:env inurl:setting inurl:backup inurl:admin inurl:php site:example[.]com
inurl:email= inurl:phone= inurl:password= inurl:secret= inurl:& site:example[.]com
inurl:apidocs inurl:api-docs inurl:swagger inurl:api-explorer site:”example[.]com”
site:pastebin.com “example.com”
site:jsfiddle.net “example.com”
site:codebeautify.org “example.com”
site:codepen.io “example.com”
site:s3.amazonaws.com “example.com”
site:blob.core.windows.net “example.com”
site:googleapis.com “example.com”
site:drive.google.com “example.com”
site:dev.azure.com “example[.]com”
site:onedrive.live.com “example[.]com”
site:digitaloceanspaces.com “example[.]com”
site:sharepoint.com “example[.]com”
site:s3-external-1.amazonaws.com “example[.]com”
site:s3.dualstack.us-east-1.amazonaws.com “example[.]com”
site:dropbox.com/s “example[.]com”
site:box.com/s “example[.]com”
site:docs.google.com inurl:”/d/” “example[.]com”
site:jfrog.io “example[.]com”
site:firebaseio.com “example[.]com”
site:example.com ”choose file”
“submit vulnerability report” “powered by bugcrowd” “powered by hackerone”
site:*/security.txt “bounty”
site:*/server-status apache
inurl:/wp-admin/admin-ajax.php
intext:”Powered by” & intext:Drupal & inurl:user
site:*/joomla/login
Top Parameters:
https://github.com/lutfumertceylan/top25-parameter