DorkForge
Advanced Search Pattern Generator ยท Security Research
v2.0
passive recon authorized targets educational
PREVIEW โ€” view onlyA live look at the interface. Generating, importing & exporting are disabled in the demo.DM @Crypt0NymzzJoin channel
1 Target Scope (optional)
Gov .gov .mil .gov.uk .gov.au
Edu .edu .ac.uk
Generic .com .org .net .io .dev
EU .co.uk .de .fr .nl .it .es .ru
APAC .cn .jp .in .au .kr
2 Mode
Effective: Each generation rotates pattern banks for unique dork sets.
3 Extensions
.php.asp.aspx.jsp.jspx.cfm.cgi.pl.do.action.html.htm.phtml.shtml.ashx.json
4 Categories
Selected: 0
Modern SQL Patterns
Rotating SQL-targeted templates โ€” highest hit ratio, max variation
SQL Errors
Surfaced DB error strings โ€” MySQL/MSSQL/Oracle/Postgres signatures
Injectable Params
Dynamic ?param= endpoints with high SQLi/IDOR surface
LFI / Inclusion
page= file= include= path= load= traversal-prone params
Login / Auth
Sign-in portals, auth flows, session & token endpoints
Admin / Panels
Dashboards, control panels, management & backend routes
Exposed Files
ext:env ext:sql ext:log ext:bak โ€” leaked configs & dumps
Open Directories
intitle:"index of" listings of sensitive folders
E-commerce
product/cart/order params โ€” DB-driven storefronts
API / Endpoints
REST/GraphQL routes, keys, versioned API surfaces
Stack Traces
Fatal/parse errors, debug output, framework traces
Info Disclosure
phpinfo, server-status, env dumps, build metadata
User Data
profile/account/member endpoints exposing PII params
5 Keyword (optional)
admin login config backup database upload .env password
Generated Dorks (8)
site:example.com inurl:view.php?action=
site:example.com inurl:"&do=" OR inurl:"?do=" ext:php
site:example.com filetype:php inurl:"load=" "admin"
site:example.com inurl:login.php
site:example.com "mysql_fetch_array()"
site:example.com intitle:"index of" "config.php"
site:example.com inurl:?id= intext:admin ext:php
site:example.com ~token key ext:php inurl:?id=
โš 
Authorized targets only. Only use on systems you own or have written permission to test.
Domains (one per line)
โšก top 20 EU Asia ร— clear
Keywords (one per line ยท every keyword maps to a parameter)
โšก add all HQ ๐Ÿ”‘ auth set โš™ CMS set ร— clear
๐ŸŽฒ random HY keywords generate + append
Login / Auth
loginsigninsignupsignoutregisterlogoutauthoauthssoaccountuserpasswordresetforgotverifyactivateconfirmotptwofacaptchasessiontokencredentialauthenticateauthorize
Admin / Panels
adminadministratoradministrationsuperadminmanagemanagermanagementcontrolcontrolpanelcpaneldashboardpanelbackendmoderatorconsolesettingsettingspreferencepreferences
Config / System
configconfigurationsetupinstallenvenvironmentsystemservicecrontaskjobqueuecachewidgetmodulepluginthemetemplatelayout
File Operations
uploaddownloadfilefilesfolderdirectoryattachmentattachdocumentdocumentsfileuploadfilemanagerstorageassetresourcedocpdfcsvexcelprint
E-commerce
shopstorecartcheckoutorderpaymentinvoiceproductproductscatalogcategoryitemitemsbrandpricepurchasetransactionwishlistcoupondiscountvouchersubscriptionplanbillingrefund
User Data
profilemembercustomercustomerssubscriberemployeestaffcontactcontactsaddressrecordrecordsgroupteamrolepermissionmessagemailfeedback
Content / Blog
newsarticlearticlespostpostsblogblogsstorystoriesreviewreviewsratingcategorytagforumthreadtopiccommentfeedrssnewsletterannouncementfaqhelpsupportticketkbwiki
Media
imageimagesphotophotosgalleryalbumalbumsvideovideosaudiomusictrackmediastreamplayerthumbnail
API / Infra
apirestgraphqlendpointwebhookcallbackkeytokenproxygatewayrouterredirecturlstatushealthmonitormetrictraceloglogsdebugreportexport
Database
databasedbsqlquerytabledumpbackupmysqlmssqloraclepostgresmongoredisphpmyadminadminer
Location / Geo
locationcityregioncountrymapgeostore_locatorbrancheventcalendarbookingreservation
Click or drop .txt โ€” import keywords
Extensions
.php.asp.aspx.jsp.jspx.cfm.cgi.pl.do.action.html.htm.phtml.shtml.ashx.json
Categories
Selected: 0
Modern SQL Patterns
Rotating SQL-targeted templates โ€” highest hit ratio, max variation
SQL Errors
Surfaced DB error strings โ€” MySQL/MSSQL/Oracle/Postgres signatures
Injectable Params
Dynamic ?param= endpoints with high SQLi/IDOR surface
LFI / Inclusion
page= file= include= path= load= traversal-prone params
Login / Auth
Sign-in portals, auth flows, session & token endpoints
Admin / Panels
Dashboards, control panels, management & backend routes
Exposed Files
ext:env ext:sql ext:log ext:bak โ€” leaked configs & dumps
Open Directories
intitle:"index of" listings of sensitive folders
E-commerce
product/cart/order params โ€” DB-driven storefronts
API / Endpoints
REST/GraphQL routes, keys, versioned API surfaces
Stack Traces
Fatal/parse errors, debug output, framework traces
Info Disclosure
phpinfo, server-status, env dumps, build metadata
User Data
profile/account/member endpoints exposing PII params
Mode
0
domains
0
keywords
5
extensions
0
categories
18
est. dorks
โš 
Authorized targets only.
1 Paste URLs (one per line)
2 Extensions
.php.asp.aspx.jsp.jspx.cfm.cgi.pl.do.action.html.htm.phtml.shtml.ashx.json
3 Mode
Category bias adds category-styled dorks built from each link
โš 
Authorized targets only.
! Authorization required
This tool performs static, passive candidate-scoring of URL parameters and emits sqlmap commands you run yourself. It sends no traffic to any target. Only assess systems you own or have written permission to test. Unauthorized testing is illegal.
1 URLs (paste below, or import a large file โ€” up to ~1M URLs)
Click or drop a .txt of URLs โ€” streamed in chunks, no memory limit
2 sqlmap profile
--batch --random-agent --tor --delay=1 --threads=4
3 Test type (which sqlmap commands to emit)
๐Ÿ” detect injection ๐Ÿงฌ fingerprint DB ๐Ÿ—ƒ enumerate databases ๐Ÿ’พ dump data ๐Ÿ›ก WAF check + bypass
Detect: probes whether the parameter is injectable. Start here before any enumeration.
High-rate cutoff for export โ‰ฅ60% โ‰ฅ70% โ‰ฅ80% โ‰ฅ90%
โš 
Authorized targets only. sqlmap commands are for execution against systems you are permitted to test. You run them in your own environment โ€” this page sends nothing.
Saved (0)
No saved dorks yet
CategoryExampleDescription
Modern SQL Patternssite:example.com inurl:view.php?action=Rotating SQL-targeted templates โ€” highest hit ratio, max variation
SQL Errorssite:example.com "mysql_fetch_array()"Surfaced DB error strings โ€” MySQL/MSSQL/Oracle/Postgres signatures
Injectable Paramssite:example.com inurl:"&do=" OR inurl:"?do=" ext:phpDynamic ?param= endpoints with high SQLi/IDOR surface
LFI / Inclusionsite:example.com filetype:php inurl:"load=" "admin"page= file= include= path= load= traversal-prone params
Login / Authsite:example.com inurl:login.phpSign-in portals, auth flows, session & token endpoints
Admin / Panelssite:example.com inurl:cpanelDashboards, control panels, management & backend routes
Exposed Filessite:example.com ext:yml intext:adminext:env ext:sql ext:log ext:bak โ€” leaked configs & dumps
Open Directoriessite:example.com intitle:"index of" "files"intitle:"index of" listings of sensitive folders
E-commercesite:example.com inurl:id= intext:admin ext:phpproduct/cart/order params โ€” DB-driven storefronts
API / Endpointssite:example.com ~token key ext:php inurl:?id=REST/GraphQL routes, keys, versioned API surfaces
Stack Tracessite:example.com "Stack trace:"Fatal/parse errors, debug output, framework traces
Info Disclosuresite:example.com intext:"Environment" inurl:envphpinfo, server-status, env dumps, build metadata
User Datasite:example.com inurl:account OR inurl:?search= >" member ext:phpprofile/account/member endpoints exposing PII params
Load Dork File
Click or drop .txt file
Or paste dorks
โš 
Authorized targets only.
Paste or import dorks to optimize & expand (import up to 10,000,000 โ€” streamed & parsed in chunks)
Click or drop a .txt of dorks โ€” up to 10M lines, streamed, no memory limit
Retarget domain (optional)
Operations
โš 
Authorized targets only. Optimizes and expands search queries; sends no traffic.