Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

GHDB—the Google Hacking Database—is a categorized index of search queries that can help authorized reviewers find information an organization has made publicly available and that search engines have indexed. It is not a scanner or exploit kit, and a search result alone does not prove that information is current, a system is vulnerable, or access is authorized.

What GHDB is

OffSec maintains GHDB as an extension of Exploit Database. It describes the database as a categorized index of internet search-engine queries designed to uncover interesting, often sensitive information that is already publicly available. In practical terms, it is a collection of searches—not software that probes a server, verifies a vulnerability, or grants access to a result.

Queries in this context are often called “Google dorks”: carefully constructed search terms intended to locate particular kinds of indexed material. Despite the name, OffSec says the database now includes searches involving other search engines, including Bing, and online repositories such as GitHub. Its remit is therefore broader than Google alone.

How GHDB fits into OSINT

Open-source intelligence (OSINT) uses publicly available information as a source of insight. GHDB contributes a search-query index that can help an authorized reviewer examine what search engines have indexed about an organization’s public footprint. That is different from an active vulnerability scanner, which sends probes to systems, and from an exploit tool, which attempts to take advantage of a weakness.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • What it can help with: noticing publicly indexed material that may have been exposed unintentionally.
  • What it does not establish: whether a result is still online, whether a system is exploitable, or whether the person viewing it has permission to access or test it.

How GHDB began

OffSec traces GHDB’s roots to security researcher Johnny Long, who popularized Google Hacking and began cataloguing queries in 2000. Long transferred the database to OffSec in November 2010 after years of community contributions. OffSec continues to maintain it as part of the Exploit Database project. These milestones describe the database’s history; they do not make older query examples reliable instructions for today’s search engines.

A September 7, 2016 PInow article titled “9 Must-Have OSINT Tools” listed GHDB as item four. That is the historical context behind the title, not evidence that GHDB is currently ranked fourth or that the article’s nine entries represent today’s leading OSINT tools.

Using GHDB for an authorized exposure review

Use GHDB only to assess assets you own or have explicit permission to review. If a result appears to expose sensitive information, do not browse, download, test, or share more than the engagement authorizes. Keep only the minimum evidence needed under the agreed rules and report the finding to the responsible owner so it can be assessed and remediated.

For an organization reviewing its own footprint, the useful outcome is an exposure finding that the owner can investigate—not an assumption that every result is live or exploitable. Search indexes can surface material without confirming its present status, and a public result is not permission to interact with the underlying system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the available evidence does not establish

The documented purpose of GHDB supports describing it as a way to find potentially sensitive indexed material. It does not establish how often individual queries work, whether a particular result remains accessible, or whether a result corresponds to a real vulnerability. Exact query examples and current operator syntax are not established here, so this guide does not present legacy dorks as current instructions.

Sources: OffSec’s GHDB description; PInow’s September 7, 2016 article.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.