Sitemap

Member-only story

How I Found Sensitive Information using Github Dorks in Bug Bounties — Part 3 🔥

3 min readApr 7, 2025

--

Hey Ethical Hackers, welcome back to another blog!, Before starting, comment “ethical hacking” and I will share a PDF on side hustles on cyber security you can earn🔥from it. In this blog, I will share how I found sensitive information using GitHub dorks in bug bounties. Without wasting any time we get started

Press enter or click to view image in full size

User’s GitHub dorks:

This is the user GitHub dork used to find sensitive information.

Press enter or click to view image in full size
Photo by Pankaj Patel on Unsplash

“example.com” user:<username> auth_token
“example.com” user:<username> api_key
“example.com” user:<username> secret

eg: user:smith password:smith

— — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — —

Extension dorks:

This is an extension dork used to find sensitive files with juicy information.

Press enter or click to view image in full size
Photo by Ferenc Almasi on Unsplash

extension: SQL MySQL dump

--

--

Mukilan Baskaran
Mukilan Baskaran

Written by Mukilan Baskaran

CTF player | Cyber Security Enthusiast