Kyfx

sample sqli dorks/Accurate Exact Web Pentest Dorks

Oct 9th, 2015
2,577
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 49.14 KB | None | 0 0
  1. 1. inurl:index.php?id=aboutus
  2. 2. inurl:?item_id=6310
  3. 3. inurl:ZoomItemDetail.aspx?item_id=
  4.  
  5. Dork 1 Site: inurl:virtual_show_detail.php?ID=
  6.  
  7.  
  8.  
  9.  
  10. Vulnerabilidades
  11. comment:advisories and vulnerabilities*-----
  12. "1999-2004 FuseTalk Inc" -site:fusetalk.com
  13. "2003 DUware All Rights Reserved"
  14. "Active Webcam Page" inurl:8080
  15. "BlackBoard 1.5.1-f | © 2003-4 by Yves Goergen"
  16. "BosDates Calendar System " "powered by BosDates v3.2 by BosDev"
  17. "Copyright © 2002 Agustin Dondo Scripts"
  18. "delete entries" inurl:admin/delete.asp
  19. "driven by: ASP Message Board"
  20. "Enter ip" inurl:"php-ping.php"
  21. "IceWarp Web Mail 5.3.0" "Powered by IceWarp"
  22. "Ideal BB Version: 0.1" -idealbb.com
  23. "inurl:/site/articles.asp?idcategory="
  24. "Obtenez votre forum Aztek" -site:forum-aztek.com
  25. "Online Store - Powered by ProductCart"
  26. "Powered *: newtelligence" ("dasBlog 1.6"| "dasBlog 1.5"| "dasBlog 1.4"|"dasBlog 1.3")
  27. "Powered by A-CART"
  28. "Powered by AJ-Fork v.167"
  29. "powered by antiboard"
  30. "Powered by Coppermine Photo Gallery"
  31. "Powered by CubeCart"
  32. "Powered by DCP-Portal v5.5"
  33. "Powered by DMXReady Site Chassis Manager" -site:dmxready.com
  34. "Powered by FUDforum"
  35. "Powered by Gallery v1.4.4"
  36. "Powered by IceWarp Software" inurl:mail
  37. "Powered by Ikonboard 3.1.1"
  38. "Powered by Megabook *" inurl:guestbook.cgi
  39. "Powered by MercuryBoard [v1"
  40. "powered by minibb" -site:www.minibb.net -intext:1.7f
  41. "Powered by My Blog" intext:"FuzzyMonkey.org"
  42. "Powered by ocPortal" -demo -ocportal.com
  43. "powered by phpWebSite" 0.9-3-2...4
  44. "Powered by PowerPortal v1.3"
  45. "powered by vbulletin 3.0"
  46. "Powered by WordPress" -html filetype:php -demo -wordpress.org -bugtraq
  47. "Powered by WowBB" -site:wowbb.com
  48. "Powered by YaPig V0.92b"
  49. "Powered by yappa-ng"
  50. "running: Nucleus v3.1" -.nucleuscms.org -demo
  51. "SquirrelMail version 1.4.4" inurl:src ext:php
  52. "This page has been automatically generated by Plesk Server Administrator"
  53. +"Powered by Invision Power Board v2.0.0..2"
  54. +"Powered by phpBB 2.0.6..10" -phpbb.com -phpbb.pl
  55. inurl:"dispatch.php?atknodetype" | inurl:class.at -----Achievo webbased project management-----
  56. allintitle:aspjar.com guestbook
  57. inurl:"/becommunity/community/index.php?pageurl=" -----E-market remote code execution-----
  58. inurl:custva.asp -----EarlyImpact Productcart-----
  59. ext:php intext:"Powered by phpNewMan Version"
  60. ext:pl inurl:cgi intitle:"FormMail *" -"*Referrer" -"* Denied" -sourceforge -error -cvs -input
  61. filetype:cgi inurl:nbmember.cgi
  62. filetype:cgi inurl:pdesk.cgi
  63. filetype:cgi inurl:tseekdir.cgi
  64. filetype:php inurl:index.php inurl:"module=subjects" inurl:"func=*" (listpages| viewpage | listcat)
  65. intext:("UBB.threads™ 6.2"|"UBB.threads™ 6.3") intext:"You * not logged *" -site:ubbcentral.com
  66. intitle:"EMUMAIL - Login" "Powered by EMU Webmail"
  67. intitle:"MRTG/RRD" 1.1* (inurl:mrtg.cgi | inurl:14all.cgi |traffic.cgi)
  68. intitle:"View Img" inurl:viewimg.php
  69. intitle:"WebJeff - FileManager" intext:"login" intext:Pass|PAsse
  70. intitle:"WordPress > * > Login form" inurl:"wp-login.php"
  71. intitle:guestbook "advanced guestbook 2.2 powered"
  72. intitle:welcome.to.horde
  73. inurl:"/cgi-bin/loadpage.cgi?user_id="
  74. inurl:"/site/articles.asp?idcategory="
  75. inurl:"comment.php?serendipity"
  76. inurl:"messageboard/Forum.asp?"
  77. inurl:"slxweb.dll"
  78. inurl:/SiteChassisManager/
  79. inurl:cal_make.pl
  80. inurl:citrix/metaframexp/default/login.asp? ClientDetection=On
  81. inurl:comersus_message.asp
  82. inurl:directorypro.cgi
  83. inurl:gotoURL.asp?url=
  84. inurl:technote inurl:main.cgi*filename=*
  85. inurl:ttt-webmaster.php
  86. inurl:wiki/MediaWiki
  87. "Powered by Invision Power Board(U) v1.3 Final" -----Invision Power Board SSI.PHP SQL Injection-----
  88. "Powered by mnoGoSearch - free web search engine software" -----nGoSearch vulnerability-----
  89. "FC Bigfeet" -inurl:mail -----Quicksite demopages for Typo3-----
  90. inurl:com_remository -----ReMOSitory module for Mambo-----
  91. uploadpics.php?did= -forumintext:Generated.by.phpix.1.0? inurl:$mode=album
  92. "Powered by: vBulletin * 3.0.1" inurl:newreply.php -----vBulletin version 3.0.1 newreply.php XSS-----
  93. filetype:asp inurl:"shopdisplayproducts.asp" -----VP-ASP Shopping Cart XSS-----
  94. inurl:/cgi-bin/index.cgi inurl:topics inurl:viewcat= +intext:"WebAPP" -site:web-app.org -----WebAPP directory traversal-----
  95.  
  96.  
  97. Arquivos com senha
  98.  
  99.  
  100. comment:Files containing passwords***-----
  101. "# -FrontPage-" ext:pwd inurl:(service | authors | administrators | users)
  102. "# -FrontPage-" inurl:service.pwd
  103. "AutoCreate=TRUE password=*"
  104. "http://*:*@www" domainname
  105. "index of/" "ws_ftp.ini" "parent directory"
  106. "liveice configuration file" ext:cfg -site:sourceforge.net
  107. "powered by ducalendar" -site:duware.com
  108. "Powered by Duclassified" -site:duware.com
  109. "Powered by Duclassified" -site:duware.com "DUware All Rights reserved"
  110. "powered by duclassmate" -site:duware.com
  111. "Powered by Dudirectory" -site:duware.com
  112. "powered by dudownload" -site:duware.com
  113. "Powered By Elite Forum Version *.*"
  114. "Powered by Link Department"
  115. "sets mode: +k"
  116. "Powered by DUpaypal" -site:duware.com
  117. allinurl: admin mdb
  118. auth_user_file.txt
  119. config.php
  120. eggdrop filetype:user user
  121. etc (index.of)
  122. ext:ini eudora.ini
  123. ext:ini Version=4.0.0.4 password
  124. filetype:bak inurl:"htaccess|passwd|shadow|htusers"
  125. filetype:cfg mrtg "target[*]" -sample -cvs -example
  126. filetype:cfm "cfapplication name" password
  127. filetype:conf oekakibbs
  128. filetype:conf sc_serv.conf
  129. filetype:conf slapd.conf
  130. filetype:config config intext:appSettings "User ID"
  131. filetype:dat "password.dat"
  132. filetype:dat wand.dat
  133. filetype:inc dbconn
  134. filetype:inc intext:mysql_connect
  135. filetype:inc mysql_connect OR mysql_pconnect
  136. filetype:ini inurl:"serv-u.ini"
  137. filetype:ini inurl:flashFXP.ini
  138. filetype:ini ServUDaemon
  139. filetype:ini wcx_ftp
  140. filetype:ini ws_ftp pwd
  141. filetype:ldb admin
  142. filetype:log "See `ipsec --copyright"
  143. filetype:log inurl:"password.log"
  144. filetype:mdb inurl:users.mdb
  145. filetype:mdb wwforum
  146. filetype:netrc password
  147. filetype:pass pass intext:userid
  148. filetype:pem intext:private
  149. filetype:properties inurl:db intext:password
  150. filetype:pwd service
  151. filetype:pwl pwl
  152. filetype:reg reg +intext:"defaultusername" +intext:"defaultpassword"
  153. filetype:reg reg HKEY_CURRENT_USER SSHHOSTKEYS
  154. filetype:sql ("values * MD5" | "values * password" | "values * encrypt")
  155. filetype:sql ("passwd values" | "password values" | "pass values" )
  156. filetype:sql +"IDENTIFIED BY" -cvs
  157. filetype:sql password
  158. filetype:url +inurl:"ftp://" +inurl:";@"
  159. filetype:xls username password email
  160. htpasswd
  161. htpasswd / htgroup
  162. htpasswd / htpasswd.bak
  163. intext:"enable secret 5 $"
  164. intext:"powered by Web Wiz Journal"
  165. intitle:"index of" intext:connect.inc
  166. intitle:"index of" intext:globals.inc
  167. intitle:"Index of" passwords modified
  168. intitle:dupics inurl:(add.asp | default.asp | view.asp | voting.asp) -site:duware.com
  169. intitle:index.of administrators.pwd
  170. intitle:Index.of etc shadow
  171. intitle:index.of intext:"secring.skr"|"secring.pgp"|"secring.bak"
  172. inurl:"GRC.DAT" intext:"password"
  173. inurl:"slapd.conf" intext:"credentials" -manpage -"Manual Page" -man: -sample
  174. inurl:"slapd.conf" intext:"rootpw" -manpage -"Manual Page" -man: -sample
  175. inurl:"wvdial.conf" intext:"password"
  176. inurl:/db/main.mdb
  177. inurl:/wwwboard
  178. inurl:ccbill filetype:log
  179. inurl:chap-secrets -cvs
  180. inurl:config.php dbuname dbpass
  181. inurl:filezilla.xml -cvs
  182. inurl:lilo.conf filetype:conf password -tatercounter2000 -bootpwd -man
  183. inurl:nuke filetype:sql
  184. inurl:ospfd.conf intext:password -sample -test -tutorial -download
  185. inurl:pap-secrets -cvs
  186. inurl:perform filetype:ini
  187. inurl:secring ext:skr | ext:pgp | ext:bak
  188. inurl:vtund.conf intext:pass -cvs
  189. inurl:zebra.conf intext:password -sample -test -tutorial -download
  190. LeapFTP intitle:"index.of./" sites.ini modified
  191. intitle:index.of master.passwd -----master.passwd-----
  192. intitle:"Index of" .mysql_history -----mysql history files-----
  193. "Your password is * Remember this for later use" -----NickServ registration passwords-----
  194. index.of passlist -----passlist-----
  195. inurl:passlist.txt -----passlist.txt-----
  196. intitle:index.of passwd passwd.bak -----passwd-----
  197. intitle:"Index of..etc" passwd -----passwd / etc-----
  198. intitle:index.of people.lst -----people.lst-----
  199. filetype:conf inurl:psybnc.conf "USER.PASS=" -----psyBNC config files-----
  200. intitle:"Index of" pwd.db -----pwd.db-----
  201. signin filetype:url
  202. intitle:"Index of" spwd.db passwd -pam.conf -----spwd.db / passwd-----
  203. intitle:index.of trillian.ini -----trillian.ini-----
  204.  
  205. Diretórios sensíveis
  206.  
  207. comment:Sensitive Directories***]
  208. "Index Of /network" "last modified"
  209. "index of cgi-bin"
  210. "index of" / picasa.ini
  211. "index of" inurl:recycler
  212. "Index of" rar r01 nfo Modified 2004
  213. "intitle:Index.Of /" stats merchant cgi-* etc
  214. "Powered by Invision Power File Manager" (inurl:login.php) | (intitle:"Browsing directory /" )
  215. "Web File Browser" "Use regular expression"
  216. "Welcome to phpMyAdmin" " Create new database"
  217. allinurl:"/*/_vti_pvt/" | allinurl:"/*/_vti_cnf/"
  218. filetype:cfg ks intext:rootpw -sample -test -howto
  219. filetype:torrent torrent
  220. Index of phpMyAdmin
  221. index.of.dcim
  222. index.of.password
  223. index.of.password
  224. intext:"d.aspx?id" || inurl:"d.aspx?id"
  225. intext:"Powered By: TotalIndex" intitle:"TotalIndex"
  226. intitle:"album permissions" "Users who can modify photos" "EVERYBODY"
  227. intitle:"Directory Listing For" intext:Tomcat -intitle:Tomcat
  228. intitle:"HFS /" +"HttpFileServer"
  229. intitle:"Index of *" inurl:"my shared folder" size modified
  230. intitle:"Index of /CFIDE/" administrator
  231. intitle:"Index of c:\Windows"
  232. intitle:"index of" "parent directory" "desktop.ini" site:dyndns.org
  233. intitle:"index of" -inurl:htm -inurl:html mp3
  234. intitle:"Index of" cfide
  235. intitle:"index of" intext:"content.ie5"
  236. intitle:"index of" inurl:ftp (pub | incoming)
  237. intitle:"index.of.personal"
  238. intitle:"webadmin - /*" filetype:php directory filename permission
  239. intitle:index.of (inurl:fileadmin | intitle:fileadmin)
  240. intitle:index.of /AlbumArt_
  241. intitle:index.of abyss.conf
  242. intitle:intranet inurl:intranet +intext:"human resources"
  243. intitle:upload inurl:upload intext:upload -forum -shop -support -w3c
  244. inurl:/pls/sample/admin_/help/
  245. inurl:/tmp
  246. inurl:backup intitle:index.of inurl:admin
  247. inurl:explorer.cfm inurl:(dirpath|This_Directory)
  248. inurl:j2ee/examples/jsp
  249. inurl:ojspdemos
  250. "Index of /backup" -----Look in my backup directories! Please?-----
  251. index.of.private -----private-----
  252. index.of.protected -----protected-----
  253. index.of.secret -----secret-----
  254. index.of.secure -----secure-----
  255. index.of.winnt -----winnt-----
  256.  
  257. -----------------------------------------------------------------------------------
  258.  
  259. ERROS
  260.  
  261. comment:Error messages***-----
  262. "A syntax error has occurred" filetype:ihtml
  263. "access denied for user" "using password"
  264. "An illegal character has been found in the statement" -"previous message"
  265. "ASP.NET_SessionId" "data source="
  266. "Can't connect to local" intitle:warning
  267. "Chatologica MetaSearch" "stack tracking"
  268. "detected an internal error [IBM][CLI Driver][DB2/6000]"
  269. "error found handling the request" cocoon filetype:xml
  270. "Fatal error: Call to undefined function" -reply -the -next
  271. "Incorrect syntax near"
  272. "Incorrect syntax near"
  273. "Internal Server Error" "server at"
  274. "Invision Power Board Database Error"
  275. "ORA-00933: SQL command not properly ended"
  276. "ORA-12541: TNS:no listener" intitle:"error occurred"
  277. "PostgreSQL query failed: ERROR: parser: parse error"
  278. "Supplied argument is not a valid MySQL result resource"
  279. "Syntax error in query expression " -the
  280. "The script whose uid is " "is not allowed to access"
  281. "Unclosed quotation mark before the character string"
  282. "Warning: Cannot modify header information - headers already sent"
  283. "Warning: mysql_query()" "invalid query"
  284. "Warning: pg_connect(): Unable to connect to PostgreSQL server: FATAL"
  285. An unexpected token "END-OF-STATEMENT" was found
  286. "Error Diagnostic Information" intitle:"Error Occurred While" -----Coldfusion Error Pages-----
  287. filetype:asp "Custom Error Message" Category Source
  288. filetype:log "PHP Parse error" | "PHP Warning" | "PHP Error"
  289. filetype:php inurl:"logging.php" "Discuz" error
  290. ht://Dig htsearch error
  291. intitle:"the page cannot be found" inetmgr -----IIS 4.0 error messages-----
  292. intitle:"the page cannot be found" "internet information services" -----IIS web server error messages-----
  293. intitle:"500 Internal Server Error" "server at" -----Internal Server Error-----
  294. intext:"Error Message : Error loading required libraries."
  295. intext:"Warning: Failed opening" "on line" "include_path"
  296. intitle:"Error Occurred While Processing Request" +WHERE (SELECT|INSERT) filetype:cfm
  297. intitle:"Error Occurred" "The error occurred in" filetype:cfm
  298. intitle:"Error using Hypernews" "Server Software"
  299. intitle:"Execution of this script not permitted"
  300. intitle:"Under construction" "does not currently have"
  301. intitle:Configuration.File inurl:softcart.exe
  302. "supplied argument is not a valid MySQL result resource" -----MYSQL error message: supplied argument....-----
  303. "mySQL error with query" -----mysql error with query-----
  304. "ORA-00921: unexpected end of SQL command" -----ORA-00921: unexpected end of SQL command-----
  305. "ORA-00936: missing expression" -----ORA-00936: missing expression-----
  306. intext:"Warning: Failed opening" "on line" "include_path" -----PHP application warnings failing "include_path"-----
  307. inurl:sitebuildercontent -----sitebuildercontent-----
  308. inurl:sitebuilderfiles -----sitebuilderfiles-----
  309. inurl:sitebuilderpictures -----sitebuilderpictures-----
  310. databasetype. Code : 80004005. Error Description -----Snitz! forums db path error-----
  311. "You have an error in your SQL syntax near" -----SQL syntax error-----
  312. "Supplied argument is not a valid PostgreSQL result" -----Supplied argument is not a valid PostgreSQL result-----
  313. warning "error on line" php sablotron
  314. intitle:"the page cannot be found" "2004 microsoft corporation" -----Windows 2000 web server error messages-----
  315.  
  316. -----------------------------------------------------------------------------------
  317.  
  318. Arquivos de user's
  319.  
  320. comment:Files containing usernames***-----
  321. "index of" / lck
  322. +intext:"webalizer" +intext:"Total Usernames" +intext:"Usage Statistics for"
  323. intitle:index.of .bash_history -----bash_history files-----
  324. filetype:conf inurl:proftpd.conf -sample
  325. filetype:log username putty
  326. filetype:reg reg +intext:"internet account manager"
  327. filetype:reg reg HKEY_CURRENT_USER username
  328. index.of perform.ini
  329. inurl:admin filetype:asp inurl:userlist
  330. inurl:admin inurl:userlist
  331. inurl:php inurl:hlstats intext:"Server Username"
  332. inurl:root.asp?acs=anon -----OWA Public folders & Address book-----
  333. intitle:index.of .sh_history -----sh_history files-----
  334. comment:Footholds***-----
  335. "adding new user" inurl:addnewuser -"there are no domains"
  336. (inurl:81/cgi-bin/.cobalt/) | (intext:"Welcome to the Cobalt RaQ")
  337. +htpasswd +WS_FTP.LOG filetype:log
  338. filetype:php HAXPLORER "Server Files Browser"
  339. intitle:"Web Data Administrator - Login"
  340. intitle:admin intitle:login
  341. inurl:"phpOracleAdmin/php" -download -cvs
  342. inurl:ConnectComputer/precheck.htm | inurl:Remote/logon.aspx
  343. intitle:"PHP Shell *" "Enable stderr" filetype:php -----PHP Shell (unprotected)-----
  344. PHPKonsole PHPShell filetype:php -echo
  345. "Powered by PHPFM" filetype:php -username -----Public PHP FileManagers-----
  346. comment:Pages containing login portals***-----
  347. intitle:"remote assessment" OpenAanval Console
  348. intitle:opengroupware.org "resistance is obsolete" "Report Bugs" "Username" "password"
  349. "IMail Server Web Messaging" intitle:login
  350. "Login - Sun Cobalt RaQ"
  351. "Login to Usermin" inurl:20000
  352. "Microsoft CRM : Unsupported Browser Version"
  353. "OPENSRS Domain Management" inurl:manage.cgi
  354. "pcANYWHERE EXPRESS Java Client"
  355. "please log in"
  356. "powered by CuteNews" "2003..2005 CutePHP"
  357. "SysCP - login"
  358. "ttawlogin.cgi/?action="
  359. "VHCS Pro ver" -demo
  360. "VNC Desktop" inurl:5800
  361. "Web Control Panel" "Enter your password here"
  362. "WebExplorer Server - Login" "Welcome to WebExplorer Server"
  363. "WebSTAR Mail - Please Log In"
  364. (inurl:"ars/cgi-bin/arweb?O=0" | inurl:arweb.jsp) -site:remedy.com -site:mil
  365. "4images Administration Control Panel"
  366. allinurl:"exchange/logon.asp"
  367. ASP.login_aspx "ASP.NET_SessionId"
  368. filetype:cgi inurl:"irc.cgi" | intitle:"CGI:IRC Login" -----CGI:IRC Login-----
  369. Admin intitle:"eZ publish administration" -----ez Publish administration-----
  370. filetype:php inurl:"webeditor.php"
  371. filetype:pl "Download: SuSE Linux Openexchange Server CA"
  372. filetype:r2w r2w
  373. intext:""BiTBOARD v2.0" BiTSHiFTERS Bulletin Board"
  374. intext:"Mail admins login here to administrate your domain."
  375. intext:"Storage Management Server for" intitle:"Server Administration"
  376. intitle:"Athens Authentication Point"
  377. intitle:"ColdFusion Administrator Login"
  378. intitle:"Dell Remote Access Controller"
  379. intitle:"ePowerSwitch Login"
  380. intitle:"Icecast Administration Admin Page"
  381. intitle:"ISPMan : Unauthorized Access prohibited"
  382. intitle:"ITS System Information" "Please log on to the SAP System"
  383. intitle:"Kurant Corporation StoreSense" filetype:bok Posts: 23 filetype:bok intitle:"Kurant Corporation StoreSense"
  384. intitle:"Login - powered by Easy File Sharing Web Server"
  385. intitle:"MailMan Login"
  386. intitle:"microsoft certificate services" inurl:certsrv
  387. intitle:"MikroTik RouterOS Managing Webpage"
  388. intitle:"MX Control Console" "If you can't remember"
  389. intitle:"Novell Web Services" intext:"Select a service and a language."
  390. intitle:"oMail-admin Administration - Login" -inurl:omnis.ch
  391. intitle:"Philex 0.2*" -script -site:freelists.org
  392. intitle:"PHP Advanced Transfer" inurl:"login.php"
  393. intitle:"php icalendar administration" -site:sourceforge.net
  394. intitle:"php icalendar administration" -site:sourceforge.net
  395. intitle:"please login" "your password is *"
  396. intitle:"Remote Desktop Web Connection" inurl:tsweb
  397. intitle:"teamspeak server-administration
  398. intitle:"Tomcat Server Administration"
  399. intitle:"TUTOS Login"
  400. intitle:"vhost" intext:"vHost . 2000-2004"
  401. intitle:"Virtual Server Administration System"
  402. intitle:"VitalQIP IP Management System"
  403. intitle:"VNC viewer for Java"
  404. intitle:"WebLogic Server" intitle:"Console Login" inurl:console
  405. intitle:"Welcome Site/User Administrator" "Please select the language" -demos
  406. intitle:"welcome to netware *" -site:novell.com
  407. intitle:"ZyXEL Prestige Router" "Enter password"
  408. intitle:Group-Office "Enter your username and password to login"
  409. intitle:Login * Webmailer
  410. intitle:Login intext:"RT is © Copyright"
  411. intitle:Node.List Win32.Version.3.11
  412. intitle:Novell intitle:WebAccess "Copyright *-* Novell, Inc"
  413. intitle:plesk inurl:login.php3
  414. inurl:"1220/parse_xml.cgi?"
  415. inurl:"631/admin" (inurl:"op=*") | (intitle:CUPS)
  416. inurl:":10000" intext:webmin
  417. inurl:"Activex/default.htm" "Demo"
  418. inurl:"calendar.asp?action=login"
  419. inurl:"gs/adminlogin.aspx"
  420. inurl:"typo3/index.php?u=" -demo
  421. inurl:"usysinfo?login=true"
  422. inurl:"utilities/TreeView.asp"
  423. inurl:"webadmin" filetype:nsf
  424. inurl:/admin/login.asp
  425. inurl:/cgi-bin/sqwebmail?noframes=1
  426. inurl:/Citrix/Nfuse17/
  427. inurl:/dana-na/auth/welcome.html
  428. inurl:/eprise/
  429. inurl:/webedit.* intext:WebEdit Professional -html
  430. inurl:1810 "Oracle Enterprise Manager"
  431. inurl:administrator "welcome to mambo"
  432. inurl:cgi-bin/ultimatebb.cgi?ubb=login
  433. inurl:confixx inurl:login|anmeldung
  434. inurl:coranto.cgi intitle:Login (Authorized Users Only)
  435. inurl:default.asp intitle:"WebCommander"
  436. inurl:irc filetype:cgi cgi:irc
  437. inurl:login filetype:swf swf
  438. inurl:login.asp
  439. inurl:login.cfm
  440. inurl:login.php "SquirrelMail version"
  441. inurl:metaframexp/default/login.asp | intitle:"Metaframe XP Login"
  442. inurl:mewebmail
  443. inurl:names.nsf?opendatabase
  444. inurl:orasso.wwsso_app_admin.ls_login
  445. inurl:postfixadmin intitle:"postfix admin" ext:php
  446. inurl:search/admin.php
  447. inurl:WCP_USER
  448. Login ("Powered by Jetbox One CMS ™" | "Powered by Jetstream © *")
  449. Novell NetWare intext:"netware management portal version"
  450. inurl:"exchange/logon.asp" OR intitle:"Microsoft Outlook Web Access - Logon" -----Outlook Web Access (a better way)-----
  451. -Login inurl:photopost/uploadphoto.php -----PhotoPost PHP Upload-----
  452. inurl:PHPhotoalbum/statistics intitle:"PHPhotoalbum - Statistics" -----PHPhotoalbum Statistics-----
  453. intitle:"PHPhotoalbum - Upload" | inurl:"PHPhotoalbum/upload" -----PHPhotoalbum Upload-----
  454. filetype:php login (intitle:phpWebMail|WebMail) -----phpWebMail-----
  455. +"Powered by INDEXU" inurl:(browse|top_rated|power) -----Powered by INDEXU-----
  456. filetype:cfg login "LoginServer=" -----Ultima Online loginservers-----
  457. uploadpics.php?did= -forum -----W-Nailer Upload Area-----
  458.  
  459.  
  460. Informações Senciveis de ADM online
  461.  
  462. comment:Sensitive Online Shopping Info***-----
  463. "More Info about MetaCart Free"
  464. inurl:"/database/comersus.mdb" -----Comersus.mdb database-----
  465. inurl:midicart.mdb
  466. inurl:shopdbtest.asp
  467. POWERED BY HIT JAMMER 1.0!
  468. site:ups.com intitle:"Ups Package tracking" intext:"1Z ### ### ## #### ### #"
  469. inurl:"shopadmin.asp" "Shop Administrators only" -----VP-ASP Shop Administrators only-----
  470. comment:Various online devices***-----
  471. "Copyright (c) Tektronix, Inc." "printer status"
  472. "intitle:Cisco Systems, Inc. VPN 3000 Concentrator"
  473. "please visit" intitle:"i-Catcher Console" Copyright "iCode Systems"
  474. "powered by webcamXP" "Pro|Broadcast"
  475. "Starting SiteZAP 6.0"
  476. ("Fiery WebTools" inurl:index2.html) | "WebTools enable * * observe, *, * * * flow * print jobs"
  477. inurl:sts_index.cgi -----Aficio 1022-----
  478. allintitle:Brains, Corp. camera
  479. allinurl:index.htm?cus?audio
  480. inurl:indexFrame.shtml Axis -----Axis Network Cameras-----
  481. axis storpoint "file view" inurl:/volumes/
  482. camera linksys inurl:main.cgi
  483. intitle:"remote ui:top page" -----Canon ImageReady machines-----
  484. intitle:liveapplet inurl:LvAppl -----Canon Webview netcams-----
  485. filetype:cgi transcoder.cgi
  486. intext:"MaiLinX Alert (Notify)" -site:networkprinters.com
  487. intext:"Please enter correct password for Administrator Access. Thank you" "Copyright © 2003 SMC Networks, Inc. All rights reserved."
  488. intext:"Ready with 10/100T Ethernet"
  489. intext:"UAA (MSB)" Lexmark -ext:pdf
  490. intext:"Videoconference Management System" ext:htm
  491. intitle:"AudioReQuest.web.server"
  492. intitle:"axis storpoint CD" intitle:"ip address"
  493. intitle:"BorderManager Information alert"
  494. intitle:"Browser Launch Page"
  495. intitle:"Cayman-DSL.home"
  496. intitle:"DEFAULT_CONFIG - HP"
  497. intitle:"DEFAULT_CONFIG - HP"
  498. intitle:"dreambox web"
  499. intitle:"DVR Web client"
  500. intitle:"EpsonNet WebAssist Rev"
  501. intitle:"EverFocus.EDSR.applet"
  502. intitle:"EvoCam" inurl:"webcam.html"
  503. intitle:"Home" "Xerox Corporation" "Refresh Status"
  504. intitle:"ipcop - main"
  505. intitle:"iVISTA.Main.Page"
  506. intitle:"lantronix web-manager"
  507. intitle:"Live NetSnap Cam-Server feed"
  508. intitle:"Live View / - AXIS"
  509. intitle:"my webcamXP server!" inurl:":8080"
  510. intitle:"Network Print Server" filetype:shtm ( inurl:u_printjobs | inurl:u_server | inurl:a_server | inurl:u_generalhelp | u_printjobs )
  511. intitle:"Network Print Server" intext:"http://www.axis.com" filetype:shtm
  512. intitle:"Setup Home" "You will need * log in before * * change * settings"
  513. intitle:"Sipura.SPA.Configuration" -.pdf
  514. intitle:"Smoothwall Express" inurl:cgi-bin "up * days"
  515. intitle:"Spam Firewall" inurl:"8000/cgi-bin/index.cgi"
  516. intitle:"SpeedStream Router Management Interface"
  517. intitle:"supervisioncam protocol"
  518. intitle:"switch home page" "cisco systems" "Telnet - to"
  519. intitle:"switch login" "IBM Fast Ethernet Desktop"
  520. intitle:"The AXIS 200 Home Page"
  521. intitle:"toshiba network camera - User Login"
  522. intitle:"V-Gear BEE"
  523. intitle:"View and Configure PhaserLink"
  524. intitle:"Brother" intext:"View Configuration" intext:"Brother Industries, Ltd."
  525. intitle:"Connection Status" intext:"Current login"
  526. intitle:Linksys site:ourlinksys.com
  527. intitle:RICOH intitle:"Network Administration"
  528. intitle:webeye inurl:login.ml
  529. inurl:"8003/Display?what="
  530. inurl:":631/printers" -php -demo
  531. inurl:"ipp/pdisplay.htm"
  532. inurl:"level/15/exec/-/show"
  533. inurl:"next_file=main_fs.htm" inurl:img inurl:image.cgi
  534. inurl:"printer/main.html" intext:"settings"
  535. inurl:axis-cgi
  536. inurl:camctrl.cgi
  537. inurl:hp/device/this.LCDispatcher
  538. inurl:na_admin
  539. inurl:netw_tcp.shtml
  540. inurl:TiVoConnect?Command=QueryServer
  541. inurl:webArch/mainFrame.cgi
  542. intitle:"network administration" inurl:"nic" -----Konica Network Printer Administration-----
  543. (intext:"MOBOTIX M1" | intext:"MOBOTIX M10") intext:"Open Menu" Shift-Reload -----Mobotix netcams-----
  544. intitle:"Live View / - AXIS" | inurl:view/view.sht -----More Axis netcams !-----
  545. inurl:"ViewerFrame?Mode=" -----Panasonic Network Cameras-----
  546. intitle:"WJ-NT104 Main Page" -----Panasonic WJ-NT104 netcams-----
  547. intext:centreware inurl:status -----Phasers 4500/6250/8200/8400-----
  548. intitle:flexwatch intext:"Home page ver" -----Seyeon FlexWATCH cameras-----
  549. site:.viewnetcam.com -www.viewnetcam.com
  550. intitle:snc-z20 inurl:home/ -----Sony SNC-RZ20 network cameras-----
  551. intitle:snc-rz30 inurl:home/ -----Sony SNC-RZ30 Network Cameras-----
  552. WebControl intitle:"AMX NetLinx"
  553. "Phaser 6250" "Printer Neighborhood" "XEROX CORPORATION" -----Xerox Phaser 6250-----
  554. "Phaser 8200" "© Xerox" "refresh" " Email Alerts" -----Xerox Phaser 8200-----
  555. "Phaser® 740 Color Printer" "printer named: " -----Xerox Phaser® 740 Color Printer-----
  556. "Phaser® 840 Color Printer" "Current Status" "printer named:" -----Xerox Phaser® 840 Color Printer-----
  557.  
  558.  
  559.  
  560. Arquivos com informaçoes LOG's
  561.  
  562. comment:Files containing juicy info***]
  563. intitle:"DocuShare" inurl:"docushare/dsweb/" -faq -gov -edu
  564. "#mysql dump" filetype:sql
  565. "allow_call_time_pass_reference" "PATH_INFO"
  566. "Certificate Practice Statement" inurl:(PDF | DOC)
  567. "Generated by phpSystem"
  568. "generated by wwwstat"
  569. "Host Vulnerability Summary Report"
  570. "HTTP_FROM=googlebot" googlebot.com "Server_Software="
  571. "Index of" / "chat/logs"
  572. "Installed Objects Scanner" inurl:default.asp
  573. "Mecury Version" "Infastructure Group"
  574. "Microsoft (R) Windows * (TM) Version * DrWtsn32 Copyright (C)" ext:log
  575. "Most Submitted Forms and Scripts" "this section"
  576. "Network Vulnerability Assessment Report"
  577. "not for distribution" confidential
  578. "phone * * *" "address *" "e-mail" intitle:"curriculum vitae"
  579. "phpMyAdmin" "running on" inurl:"main.php"
  580. "produced by getstats"
  581. "Request Details" "Control Tree" "Server Variables"
  582. "robots.txt" "Disallow:" filetype:txt
  583. "Running in Child mode"
  584. "sets mode: +p"
  585. "sets mode: +s"
  586. "Thank you for your order" +receipt
  587. "This is a Shareaza Node"
  588. "This report was generated by WebLog"
  589. ( filetype:mail | filetype:eml | filetype:mbox | filetype:mbx ) intext:password|subject
  590. (inurl:"robot.txt" | inurl:"robots.txt" ) intext:disallow filetype:txt
  591. +":8080" +":3128" +":80" filetype:txt
  592. +"HSTSNR" -"netop.com"
  593. -site:php.net -"The PHP Group" inurl:source inurl:url ext:pHp
  594. 94FBR "ADOBE PHOTOSHOP"
  595. buddylist.blt -----AIM buddy lists-----
  596. allinurl:/examples/jsp/snp/snoop.jsp
  597. allinurl:servlet/SnoopServlet
  598. intitle:index.of cgiirc.config -----cgiirc.conf-----
  599. inurl:cgiirc.config -----cgiirc.conf-----
  600. data filetype:mdb -site:gov -site:mil
  601. e-mail address filetype:csv csv -----exported email addresses-----
  602. ext:asp inurl:pathto.asp
  603. ext:cgi inurl:editcgi.cgi inurl:file=
  604. ext:conf inurl:rsyncd.conf -cvs -man
  605. ext:conf NoCatAuth -cvs
  606. ext:dat bpk.dat
  607. ext:gho gho
  608. ext:ini intext:env.ini
  609. ext:ldif ldif
  610. ext:log "Software: Microsoft Internet Information Services *.*"
  611. ext:mdb inurl:*.mdb inurl:fpdb shop.mdb
  612. ext:nsf nsf -gov -mil
  613. ext:pqi pqi -database
  614. ext:reg "username=*" putty
  615. ext:txt "Final encryption key"
  616. ext:txt inurl:dxdiag
  617. ext:vmdk vmdk
  618. ext:vmx vmx
  619. filetype:asp DBQ=" * Server.MapPath("*.mdb")
  620. filetype:bkf bkf
  621. filetype:blt "buddylist"
  622. filetype:blt blt +intext:screenname
  623. filetype:cfg auto_inst.cfg
  624. filetype:cnf inurl:_vti_pvt access.cnf
  625. filetype:conf inurl:firewall -intitle:cvs
  626. filetype:config web.config -CVS
  627. filetype:ctt Contact
  628. filetype:ctt ctt messenger
  629. filetype:eml eml +intext:"Subject" +intext:"From" +intext:"To"
  630. filetype:fp3 fp3
  631. filetype:fp5 fp5 -site:gov -site:mil -"cvs log"
  632. filetype:fp7 fp7
  633. filetype:inf inurl:capolicy.inf
  634. filetype:lic lic intext:key
  635. filetype:log access.log -CVS
  636. filetype:mbx mbx intext:Subject
  637. filetype:myd myd -CVS
  638. filetype:ns1 ns1
  639. filetype:ora ora
  640. filetype:pdb pdb backup (Pilot | Pluckerdb)
  641. filetype:php inurl:index inurl:phpicalendar -site:sourceforge.net
  642. filetype:pot inurl:john.pot
  643. filetype:pst inurl:"outlook.pst"
  644. filetype:pst pst -from -to -date
  645. filetype:qbb qbb
  646. filetype:rdp rdp
  647. filetype:reg "Terminal Server Client"
  648. filetype:vcs vcs
  649. filetype:wab wab
  650. filetype:xls -site:gov inurl:contact
  651. filetype:xls inurl:"email.xls"
  652. intitle:"Index of" finance.xls -----Financial spreadsheets: finance.xls-----
  653. intitle:index.of finances.xls -----Financial spreadsheets: finances.xls-----
  654. intitle:"Ganglia" "Cluster Report for" -----Ganglia Cluster Reports-----
  655. intitle:index.of haccess.ctl -----haccess.ctl (one way)-----
  656. filetype:ctl Basic -----haccess.ctl (VERY reliable)-----
  657. intitle:"Index of" dbconvert.exe chats -----ICQ chat logs, please...-----
  658. filetype:log cron.log
  659. intext:"Session Start * * * *:*:* *" filetype:log
  660. intext:"Tobias Oetiker" "traffic analysis"
  661. intext:(password | passcode) intext:(username | userid | user) filetype:csv
  662. intext:gmail invite intext:http://gmail.google.com/gmail/a
  663. intext:SQLiteManager inurl:main.php
  664. intitle:"Apache::Status" (inurl:server-status | inurl:status.html | inurl:apache.html)
  665. intitle:"AppServ Open Project" -site:www.appservnetwork.com
  666. intitle:"ASP Stats Generator *.*" "ASP Stats Generator" "2003-2004 weppos"
  667. intitle:"Big Sister" +"OK Attention Trouble"
  668. intitle:"edna:streaming mp3 server" -forums
  669. intitle:"FTP root at"
  670. intitle:"index of" +myd size
  671. intitle:"Index Of" -inurl:maillog maillog size
  672. intitle:"Index Of" cookies.txt size
  673. intitle:"index of" mysql.conf OR mysql_config
  674. intitle:"Index of" upload size parent directory
  675. intitle:"index.of *" admin news.asp configview.asp
  676. intitle:"index.of" .diz .nfo last modified
  677. intitle:"Multimon UPS status page"
  678. intitle:"PHP Advanced Transfer" (inurl:index.php | inurl:showrecent.php )
  679. intitle:"PhpMyExplorer" inurl:"index.php" -cvs
  680. intitle:"statistics of" "advanced web statistics"
  681. intitle:"System Statistics" +"System and Network Information Center"
  682. intitle:"Usage Statistics for" "Generated by Webalizer"
  683. intitle:"wbem" compaq login
  684. intitle:"Web Server Statistics for ****"
  685. intitle:"web server status" SSH Telnet
  686. intitle:"welcome.to.squeezebox"
  687. intitle:admin intitle:login
  688. intitle:index.of "Apache" "server at"
  689. intitle:index.of cleanup.log
  690. intitle:index.of dead.letter
  691. intitle:index.of inbox
  692. intitle:index.of inbox dbx
  693. intitle:index.of ws_ftp.ini
  694. intitle:intranet inurl:intranet +intext:"phone"
  695. inurl:"/axs/ax-admin.pl" -script
  696. inurl:"/cricket/grapher.cgi"
  697. inurl:"bookmark.htm"
  698. inurl:"cacti" +inurl:"graph_view.php" +"Settings Tree View" -cvs -RPM
  699. inurl:"newsletter/admin/"
  700. inurl:"newsletter/admin/" intitle:"newsletter admin"
  701. inurl:"putty.reg"
  702. inurl:"smb.conf" intext:"workgroup" filetype:conf conf
  703. inurl:*db filetype:mdb
  704. inurl:/_layouts/settings
  705. inurl:admin filetype:xls
  706. inurl:admin intitle:login
  707. inurl:backup filetype:mdb
  708. inurl:cgi-bin/printenv
  709. inurl:cgi-bin/testcgi.exe "Please distribute TestCGI"
  710. inurl:changepassword.asp
  711. inurl:ds.py
  712. inurl:email filetype:mdb
  713. inurl:fcgi-bin/echo
  714. inurl:forum filetype:mdb
  715. inurl:forward filetype:forward -cvs
  716. inurl:getmsg.html intitle:hotmail
  717. inurl:log.nsf -gov
  718. inurl:main.php phpMyAdmin
  719. inurl:main.php Welcome to phpMyAdmin
  720. inurl:netscape.hst
  721. inurl:netscape.hst
  722. inurl:netscape.ini
  723. inurl:odbc.ini ext:ini -cvs
  724. inurl:perl/printenv
  725. inurl:php.ini filetype:ini
  726. inurl:preferences.ini "[emule]"
  727. inurl:profiles filetype:mdb
  728. inurl:report "EVEREST Home Edition "
  729. inurl:server-info "Apache Server Information"
  730. inurl:server-status "apache"
  731. inurl:snitz_forums_2000.mdb
  732. inurl:ssl.conf filetype:conf
  733. inurl:tdbin
  734. inurl:vbstats.php "page generated"
  735. inurl:ipsec.conf -intitle:manpage -----ipsec.conf-----
  736. inurl:ipsec.secrets -history -bugs -----ipsec.secrets-----
  737. inurl:ipsec.secrets "holds shared secrets" -----ipsec.secrets-----
  738. inurl:"/names.nsf?OpenDatabase" -----Lotus Domino address books-----
  739. mail filetype:csv -site:gov intext:name
  740. filetype:mny mny -----Microsoft Money Data Files-----
  741. intitle:index.of mt-db-pass.cgi -----mt-db-pass.cgi files-----
  742. "# Dumping data for table (username|user|users|password)" -----MySQL tabledata dumps-----
  743. intitle:index.of mystuff.xml -----mystuff.xml - Trillian data files-----
  744. inurl:/public/?Cmd=contents -----OWA Public Folders (direct view)-----
  745. filetype:ctt "msn" -----Peoples MSN contact lists-----
  746. php-addressbook "This is the addressbook for *" -warning
  747. intitle:phpinfo "PHP Version" -----phpinfo()-----
  748. "# phpMyAdmin MySQL-Dump" filetype:txt -----phpMyAdmin dumps-----
  749. "# phpMyAdmin MySQL-Dump" "INSERT INTO" -"the" -----phpMyAdmin dumps-----
  750. BEGIN (CERTIFICATE|DSA|RSA) filetype:csr -----private key files (.csr)-----
  751. BEGIN (CERTIFICATE|DSA|RSA) filetype:key -----private key files (.key)-----
  752. filetype:QDF QDF -----Quicken data files-----
  753. intitle:index.of robots.txt -----robots.txt-----
  754. site:edu admin grades
  755. "# Dumping data for table" -----SQL data dumps-----
  756. "cacheserverreport for" "This analysis was produced by calamaris" -----Squid cache server reports-----
  757. filetype:conf inurl:unrealircd.conf -cvs -gentoo -----Unreal IRCd-----
  758. intitle:"Welcome to ntop!" -----Welcome to ntop!-----
  759.  
  760. INFORMAÇÕES DE SERVES
  761.  
  762. comment:Pages containing network or vulnerability data***-----
  763. filetype:log intext:"ConnectionManager2"
  764. "apricot - admin" 00h
  765. "Network Host Assessment Report" "Internet Scanner"
  766. "Output produced by SysWatch *"
  767. "Phorum Admin" "Database Connection" inurl:forum inurl:admin
  768. "Powered by phpOpenTracker" Statistics
  769. "powered | performed by Beyond Security's Automated Scanning" -kazaa -example
  770. "SnortSnarf alert page"
  771. "This file was generated by Nessus"
  772. "this proxy is working fine!" "enter *" "URL***" * visit
  773. "This report lists" "identified by Internet Scanner"
  774. "Traffic Analysis for" "RMON Port * on unit *"
  775. "Version Info" "Boot Version" "Internet Settings"
  776. ((inurl:ifgraph "Page generated at") OR ("This page was built using ifgraph"))
  777. ACID "by Roman Danyliw" filetype:php -----Analysis Console for Incident Databases 12-Jul-2004 866-----
  778. ext:cfg radius.cfg
  779. ext:cgi intext:"nrg-" " This web page was created on "
  780. filetype:pdf "Assessment Report" nessus
  781. filetype:php inurl:ipinfo.php "Distributed Intrusion Detection System"
  782. filetype:php inurl:nqt intext:"Network Query Tool"
  783. filetype:vsd vsd network -samples -examples
  784. intext:"Welcome to the Web V.Networks" intitle:"V.Networks [Top]" -filetype:htm
  785. intitle:"ADSL Configuration page"
  786. intitle:"Azureus : Java BitTorrent Client Tracker"
  787. intitle:"BNBT Tracker Info"
  788. intitle:"Microsoft Site Server Analysis"
  789. intitle:"PHPBTTracker Statistics" | intitle:"PHPBT Tracker Statistics"
  790. intitle:"start.managing.the.device" remote pbx acc
  791. intitle:"sysinfo * " intext:"Generated by Sysinfo * written by The Gamblers."
  792. intitle:"twiki" inurl:"TWikiUsers"
  793. inurl:"/catalog.nsf" intitle:catalog
  794. inurl:"install/install.php"
  795. inurl:"map.asp?" intitle:"WhatsUp Gold"
  796. inurl:"sitescope.html" intitle:"sitescope" intext:"refresh" -demo
  797. inurl:/adm-cfgedit.php
  798. inurl:/cgi-bin/finger? "In real life"
  799. inurl:/cgi-bin/finger? Enter (account|host|user|username)
  800. inurl:phpSysInfo/ "created by phpsysinfo"
  801. inurl:portscan.php "from Port"|"Port Range"
  802. inurl:statrep.nsf -gov
  803. inurl:testcgi xitami
  804. inurl:webutil.pl
  805. "Looking Glass" (inurl:"lg/" | inurl:lookingglass) -----Looking Glass-----
  806. intitle:That.Site.Running Apache
  807.  
  808.  
  809. ARQUIVOS SENCIVEIS
  810.  
  811. comment:Vulnerable files***-----
  812. filetype:pl -intext:"/usr/bin/perl" inurl:webcal (inurl:webcal | inurl:add | inurl:delete | inurl:config)
  813. "File Upload Manager v1.3" "rename to"
  814. "Powered by Land Down Under 601"
  815. "powered by YellDL"
  816. ext:asp "powered by DUForum" inurl:(messages|details|login|default|register) -site:duware.com
  817. ext:asp inurl:DUgallery intitle:"3.0" -site:dugallery.com -site:duware.com
  818. ext:cgi inurl:ubb6_test
  819. ezBOO "Administrator Panel" -cvs
  820. filetype:cgi inurl:cachemgr.cgi
  821. filetype:cnf my.cnf -cvs -example
  822. filetype:inc inc intext:setcookie
  823. filetype:lit lit (books|ebooks)
  824. filetype:mdb inurl:"news/news"
  825. filetype:php inurl:"viewfile" -"index.php" -"idfil
  826. filetype:wsdl wsdl
  827. intitle:gallery inurl:setup "Gallery configuration" -----Gallery configuration setup files-----
  828. intitle:"ASP FileMan" Resend -site:iisworks.com
  829. intitle:"Directory Listing" "tree view"
  830. intitle:"Index of /" modified php.exe
  831. intitle:"PHP Explorer" ext:php (inurl:phpexplorer.php | inurl:list.php | inurl:browse.php)
  832. intitle:"phpremoteview" filetype:php "Name, Size, Type, Modify"
  833. intitle:mywebftp "Please enter your password"
  834. inurl:" WWWADMIN.PL" intitle:"wwwadmin"
  835. inurl:"nph-proxy.cgi" "Start browsing through this CGI-based proxy"
  836. inurl:"plog/register.php"
  837. inurl:cgi.asx?StoreID
  838. inurl:changepassword.cgi -cvs
  839. inurl:click.php intext:PHPClickLog
  840. inurl:php.exe filetype:exe -example.com
  841. inurl:robpoll.cgi filetype:cgi
  842. link:http://www.toastforums.com/
  843. "create the Super User" "now by clicking here" -----PHP-Nuke - create super user right now !-----
  844. intitle:"Index of" _vti_inf.html
  845. intitle:"Index of" service.pwd
  846. intitle:"Index of" users.pwd
  847. intitle:"Index of" authors.pwd
  848. intitle:"Index of" administrators.pwd
  849. intitle:"Index of" shtml.dll
  850. intitle:"Index of" shtml.exe
  851. intitle:"Index of" fpcount.exe
  852. intitle:"Index of" default.asp
  853. intitle:"Index of" showcode.asp
  854. intitle:"Index of" sendmail.cfm
  855. intitle:"Index of" getFile.cfm
  856. intitle:"Index of" imagemap.exe
  857. intitle:"Index of" test.bat
  858. intitle:"Index of" msadcs.dll
  859. intitle:"Index of" htimage.exe
  860. intitle:"Index of" counter.exe
  861. intitle:"Index of" browser.inc
  862. intitle:"Index of" hello.bat
  863. intitle:"Index of" default.asp\\
  864. intitle:"Index of" dvwssr.dll
  865. intitle:"Index of" dvwssr.dll
  866. intitle:"Index of" dvwssr.dll
  867. intitle:"Index of" cart32.exe
  868. intitle:"Index of" add.exe
  869. intitle:"Index of" index.JSP
  870. intitle:"Index of" index.jsp
  871. intitle:"Index of" SessionServlet
  872. intitle:"Index of" shtml.dll
  873. intitle:"Index of" index.cfm
  874. intitle:"Index of" page.cfm
  875. intitle:"Index of" shtml.exe
  876. intitle:"Index of" web_store.cgi
  877. intitle:"Index of" shop.cgi
  878. intitle:"Index of" upload.asp
  879. intitle:"Index of" default.asp
  880. intitle:"Index of" pbserver.dll
  881. intitle:"Index of" phf
  882. intitle:"Index of" test-cgi
  883. intitle:"Index of" finger
  884. intitle:"Index of" Count.cgi
  885. intitle:"Index of" jj
  886. intitle:"Index of" php.cgi
  887. intitle:"Index of" php
  888. intitle:"Index of" nph-test-cgi
  889. intitle:"Index of" handler
  890. intitle:"Index of" webdist.cgi
  891. intitle:"Index of" webgais
  892. intitle:"Index of" websendmail
  893. intitle:"Index of" faxsurvey
  894. intitle:"Index of" htmlscript
  895. intitle:"Index of" perl.exe
  896. intitle:"Index of" wwwboard.pl
  897. intitle:"Index of" www-sql
  898. intitle:"Index of" view-source
  899. intitle:"Index of" campas
  900. intitle:"Index of" aglimpse
  901. intitle:"Index of" glimpse
  902. intitle:"Index of" man.sh
  903. intitle:"Index of" AT-admin.cgi
  904. intitle:"Index of" AT-generate.cgi
  905. intitle:"Index of" filemail.pl
  906. intitle:"Index of" maillist.pl
  907. intitle:"Index of" info2www
  908. intitle:"Index of" files.pl
  909. intitle:"Index of" bnbform.cgi
  910. intitle:"Index of" survey.cgi
  911. intitle:"Index of" classifieds.cgi
  912. intitle:"Index of" wrap
  913. intitle:"Index of" cgiwrap
  914. intitle:"Index of" edit.pl
  915. intitle:"Index of" perl
  916. intitle:"Index of" names.nsf
  917. intitle:"Index of" webgais
  918. intitle:"Index of" dumpenv.pl
  919. intitle:"Index of" test.cgi
  920. intitle:"Index of" submit.cgi
  921. intitle:"Index of" submit.cgi
  922. intitle:"Index of" guestbook.cgi
  923. intitle:"Index of" guestbook.pl
  924. intitle:"Index of" cachemgr.cgi
  925. intitle:"Index of" responder.cgi
  926. intitle:"Index of" perlshop.cgi
  927. intitle:"Index of" query
  928. intitle:"Index of" w3-msql
  929. intitle:"Index of" plusmail
  930. intitle:"Index of" htsearch
  931. intitle:"Index of" infosrch.cgi
  932. intitle:"Index of" publisher
  933. intitle:"Index of" ultraboard.cgi
  934. intitle:"Index of" db.cgi
  935. intitle:"Index of" formmail.cgi
  936. intitle:"Index of" allmanage.pl
  937. intitle:"Index of" ssi
  938. intitle:"Index of" adpassword.txt
  939. intitle:"Index of" redirect.cgi
  940. intitle:"Index of" f
  941. intitle:"Index of" cvsweb.cgi
  942. intitle:"Index of" login.jsp
  943. intitle:"Index of" login.jsp
  944. intitle:"Index of" dbconnect.inc
  945. intitle:"Index of" admin
  946. intitle:"Index of" htgrep
  947. intitle:"Index of" wais.pl
  948. intitle:"Index of" amadmin.pl
  949. intitle:"Index of" subscribe.pl
  950. intitle:"Index of" news.cgi
  951. intitle:"Index of" auctionweaver.pl
  952. intitle:"Index of" .htpasswd
  953. intitle:"Index of" acid_main.php
  954. intitle:"Index of" access_log
  955. intitle:"Index of" access-log
  956. intitle:"Index of" access.log
  957. intitle:"Index of" log.htm
  958. intitle:"Index of" log.html
  959. intitle:"Index of" log.txt
  960. intitle:"Index of" logfile
  961. intitle:"Index of" logfile.htm
  962. intitle:"Index of" logfile.html
  963. intitle:"Index of" logfile.txt
  964. intitle:"Index of" logger.html
  965. intitle:"Index of" stat.htm
  966. intitle:"Index of" stats.htm
  967. intitle:"Index of" stats.html
  968. intitle:"Index of" stats.txt
  969. intitle:"Index of" webaccess.htm
  970. intitle:"Index of" wwwstats.html
  971. intitle:"Index of" source.asp
  972. intitle:"Index of" perl
  973. intitle:"Index of" mailto.cgi
  974. intitle:"Index of" YaBB.pl
  975. intitle:"Index of" mailform.pl
  976. intitle:"Index of" cached_feed.cgi
  977. intitle:"Index of" cr
  978. intitle:"Index of" global.cgi
  979. intitle:"Index of" Search.pl
  980. intitle:"Index of" build.cgi
  981. intitle:"Index of" common.php
  982. intitle:"Index of" common.php
  983. intitle:"Index of" show
  984. intitle:"Index of" global.inc
  985. intitle:"Index of" ad.cgi
  986. intitle:"Index of" WSFTP.LOG
  987. intitle:"Index of" index.html~
  988. intitle:"Index of" index.php~
  989. intitle:"Index of" index.html.bak
  990. intitle:"Index of" index.php.bak
  991. intitle:"Index of" print.cgi
  992. intitle:"Index of" register.cgi
  993. intitle:"Index of" webdriver
  994. intitle:"Index of" bbs_forum.cgi
  995. intitle:"Index of" mysql.class
  996. intitle:"Index of" sendmail.inc
  997. intitle:"Index of" CrazyWWWBoard.cgi
  998. intitle:"Index of" search.pl
  999. intitle:"Index of" way-board.cgi
  1000. intitle:"Index of" webpage.cgi
  1001. intitle:"Index of" pwd.dat
  1002. intitle:"Index of" adcycle
  1003. intitle:"Index of" post-query
  1004. intitle:"Index of" help.cgi
  1005.  
  1006.  
  1007.  
  1008.  
  1009. intitle:upload inurl:upload intext:upload -forum -shop -support -wc
  1010. intitle: private, protected, secret, secure, winnt
  1011. intitle:"DocuShare" inurl:"docushare/dsweb/" -faq -gov -edu
  1012. "Certificate Practice Statement" inurlPDF | DOC) mil
  1013. filetype:mdb inurl:.mdb mil
  1014. filetype:log inurl:"password.log"
  1015. filetype:bak inurl:"htaccess|passwd|shadow|htusers"
  1016. filetype:ini inurl:"serv-u.ini"
  1017. filetype:ini inurl:flashFXP.ini
  1018. filetype:ini ServUDaemon
  1019. filetype:ini wcx_ftp
  1020. filetype:ini ws_ftp pwd
  1021. filetype:pem intext:private 搜索加密密匙
  1022. filetype:reg reg +intext:"defaultusername" +intext:"defaultpassword" 找肉鸡,看admin密码
  1023. filetype:reg reg HKEY_CURRENT_USER SSHHOSTKEYS
  1024. filetype:url +inurl:"ftp://" +inurl:";@" 此技巧最好分开使用
  1025. intitle:"index of" intext:connect.inc
  1026. intitle:"index of" intext:globals.inc
  1027. intitle:"Index of" passwords modified 推荐
  1028. intitle:"index of" intext:welcome 如有pub和etc一般都有welcome
  1029. intitle:Index.of etc shadow
  1030. site:.gov filetype:sql
  1031. "HTTP_FROM=googlebot" googlebot.com "Server_Software=" 好的很啊
  1032. ( filetype:mail | filetype:eml | filetype:mbox | filetype:mbx ) intext:password|subject site:edu 2005
  1033. filetype:eml eml +intext:"Subject" +intext:"From" +intext:"To"
  1034. inurl:forward filetype:forward -cvs 找密码和ftp最好的技巧
  1035. top secret site:mil
  1036. confidential site:mil
  1037.  
  1038. inurl:
  1039. private
  1040. protected
  1041. secret
  1042. secure
  1043. --------------------------------------------------------------------
  1044.  
  1045. filetype:xls username password email
  1046. "config.php"
  1047. service filetype:pwd (frontpage)
  1048. inurl:_vti_cnf (frontpage files)
  1049. allinurl:/msadc/samples/selector/showcode.asp
  1050. allinurl:/examples/jsp/snp/snoop.jsp
  1051. ipsec filetype:conf
  1052. "mydomain.com" nessus report
  1053. "report generated by"
  1054. "ws_ftp.log"
  1055. inurl:server-info "Apache Server Information"
  1056. inurl:ssl.conf filetype:conf
  1057. ipsec.conf
  1058. Lotus Domino address books 用户数据库,重要
  1059. robots.txt 看目录
  1060.  
  1061.  
  1062.  
  1063. filetype:url +inurl:"ftp://" +inurl:"@"
  1064.  
  1065. filetype:cnf inurl:_vti_pvt access.cnf
  1066.  
  1067.  
  1068. allinurl:"/*/_vti_pvt/" | allinurl:"/*/_vti_cnf/" 推荐
  1069. "access denied for user" "using password" mysql暴错,暴出路径
  1070. intitleogin intext:"RT is ? Copyright" 找登陆页子
  1071. intitle:index.of WEB-INF 目录
  1072. intitle:"Index of" config.php
  1073. "Index of /admin" + passwd
  1074. inurl:passwd.txt wwwboard|webadmin
  1075. master.passwd
  1076. filetype:cfg mrtg "target
  1077. " -sample -cvs -example 看MRTG的配置的
  1078. ext:ini Version=... password
  1079. filetype:cfm "cfapplication name" password
  1080. filetype:config config intext:appSettings "User ID"
  1081. filetype:dat "password.dat"
  1082. filetype:inc dbconn 推荐
  1083. "#mysql dump" filetype:sql
  1084. "allow_call_time_pass_reference" "ATH_INFO"
  1085. filetype:inc intext:mysql_connect
  1086. filetype:inc mysql_connect or mysql_pconnect
  1087. filetype:mdb inurl:users.mdb
  1088.  
  1089. filetype:pass pass intext:userid
  1090. filetype:properties inurl:db intext:password ]
  1091.  
  1092. filetype:sql ("values * MD" | "values * password" | "values * encrypt")
  1093. filetype:sql ("passwd values" | "password values" | "pass values" )
  1094. filetype:sql +"IDENTIFIED BY" -cvs
  1095. filetype:sql password
  1096. filetype:xls username password email mil
  1097.  
  1098. htpasswd
  1099. htpasswd / htgroup
  1100. htpasswd / htpasswd.bak
  1101.  
  1102. inurljspdemos private protected secret secure
  1103.  
  1104. intitle:dupics inurladd.asp | default.asp | view.asp | voting.asp) -site:duware.com
  1105. inurl:config.php dbuname dbpass phpnuke的漏洞
  1106. "Welcome to phpMyAdmin" " Create new database"
  1107. "phone * * *" "address *" "e-mail" intitle:"curriculum vitae" 跟踪
  1108. "phpMyAdmin" "running on" inurl:"main.php"
  1109. "robots.txt" "Disallow:" filetype:txt 可以查看漏洞
  1110. ext:reg "username=*" putty
  1111. -site:php.net -"The PHP Group" inurl:source inurl:url ext:pHp
  1112. ext:log "Software: Microsoft Internet Information Services *.*"
  1113. filetype:asp DBQ=" * Server.MapPath("*.mdb")
  1114. filetype:php inurl:index inurl:phpicalendar -site:sourceforge.net 泄露源代码
  1115. haccess.ctl (one way)
  1116. haccess.ctl (VERY reliable)
  1117. intext:gmail invite intext:http://gmail.google.com/gmail/a
  1118. -------------------------------------------------------------------------------------
  1119. intitle:"Index of" upload size parent directory
  1120. intitle:"System Statistics" +"System and Network Information Center"
  1121. intitle:"wbem" compaq login "Compaq Information Technologies Group"
  1122. intitle:index.of "Apache" "server at"
  1123. intitle:index.of cleanup.log
  1124. intitle:index.of dead.letter
  1125. intitle:index.of inbox
  1126. intitle:index.of inbox dbx
  1127. "intitle:Index.Of /" stats cgi-* etc
  1128. intitle:"Directory Listing For" intext:Tomcat -intitle:Tomcat mil
  1129. intitle:"Index of *" inurl:"my shared folder" size modified
  1130. intitle:"index of" "parent directory" "desktop.ini" site:gov NASA
  1131. "Index of /backup"
  1132. intitle:"Index of /" modified php.exe
  1133.  
  1134. intitle:"index of" -inurl:htm -inurl:html mp
  1135. intitle:"Index of" cfide
  1136. intitle:"index of" intext:"content.ie"
  1137. intitle:"index.of.personal"
  1138. intitle:"webadmin - /*" filetype:php directory filename permission
  1139. intitle:index.of (inurl:fileadmin | intitle:fileadmin)
  1140. intitle:index.of /AlbumArt_
  1141. intitle:index.of /maildir/new/
  1142. intitle:index.of abyss.conf
  1143. intitle:intranet inurl:intranet +intext:"human resources"
  1144. inurl:/tmp
  1145.  
  1146. filetype:pl -intext:"/usr/bin/perl" inurl:webcal (inurl:webcal | inurl:add | inurl:delete | inurl:config)
  1147.  
  1148. inurl:explorer.cfm inurldirpath|This_Directory)
  1149.  
  1150.  
  1151.  
  1152. "parent directory " /appz/ -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
  1153.  
  1154. "parent directory " DVDRip -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
  1155.  
  1156. "parent directory "Xvid -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
  1157.  
  1158. "parent directory " Gamez -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
  1159.  
  1160. "parent directory " MP3 -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
  1161.  
  1162. "parent directory " Name of Singer or album -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
  1163.  
  1164. "AutoCreate=TRUE password=*"
  1165.  
  1166. "index of cgi-bin"
  1167. +htpasswd +WS_FTP.LOG filetype:log
  1168. filetype:cfg ks intext:rootpw -sample -test -howto gov
  1169. config.inc.php 偶自己发现地
  1170. site:mil admin grades
  1171. inurl:backup filetype:mdb
  1172. inurl:perl/printenv
  1173. inurldbc.ini ext:ini -cvs
  1174. "Index Of /network" "last modified"
  1175. filetype:mbx mbx intext:Subject
  1176. Apache Tomcat Admin intitle:”Tomcat Server Administration”
  1177. ASP.NET inurl:ASP.login_aspx
  1178. Citrix Metaframe inurl:/Citrix/Nfuse17/
  1179. Citrix Metaframe inurl:citrix/metaframexp/default/login.asp
  1180. ColdFusion Admin intitle:”ColdFusion Administrator Login”
  1181. ColdFusion Generic inurl:login.cfm
  1182. Lotus Domino Admin inurl:”webadmin” filetype:nsf
  1183. Lotus Domino inurl:names.nsf?opendatabase
  1184. Microsoft Certificate Server intitle:”microsoft certificate services”
  1185. inurl:certsrv
  1186. Microsoft Outlook Web Access allinurl:”exchange/logon.asp”
  1187. Microsoft Outlook Web Access inurl:”exchange/logon.asp” or
  1188. intitle:”Microsoft Outlook Web Access –
  1189. Logon”
  1190. Microsoft Remote Desktop intitle:Remote.Desktop.Web.Connection
  1191. inurl:tsweb
  1192. Network Appliance Admin inurl:na_admin
  1193. Novell Groupwise Web Access inurl:/servlet/webacc Novell
  1194. Shockwave Flash Login inurl:login filetype:swf swf
  1195. Tivoli Server Administration intitle:”Server Administration” “Tivoli power”
  1196. VNC “VNC Desktop” inurl:5800
  1197.  
  1198. inurl:error.log filetype:log -cvs Apache error log
  1199. inurl:access.log filetype:log –cvs Apache access log (Windows)
  1200. filetype:log inurl:cache.log Squid cache log
  1201. filetype:log inurl:store.log RELEASE Squid disk store log
  1202. filetype:log inurl:access.log TCP_HIT Squid access log
  1203. filetype:log inurl:useragent.log Squid useragent log
  1204. filetype:log hijackthis “scan saved” Hijackthis scan log
  1205. ext:log “Software: Microsoft IIS server log files
  1206. Internet Information Services *.*”
  1207. filetype:log iserror.log MS Install Shield logs
  1208. intitle:index.of .bash_history UNIX bash shell history file
  1209. intitle:index.of .sh_history UNIX shell history file
  1210. “Index of” / “chat/logs” Chat logs
  1211. filetype:log username putty Putty SSH client logs
  1212. filetype:log inurl:”password.log” Password logs
  1213. filetype:log cron.log UNIX cron logs
  1214. filetype:log access.log –CVS HTTPD server access logs
  1215. +htpasswd WS_FTP.LOG filetype:log WS_FTP client log files
  1216. “sets mode: +k” IRC logs, channel key set
  1217. “sets mode: +s” IRC logs, secret channel set
  1218. intitle:”Index Of” -inurl:maillog Mail log files
  1219. maillog size
Add Comment
Please, Sign In to add comment