Advertisement
MalwareMustDie

Have a "xmlrpc.php" & GooDork for Breakfast

Feb 6th, 2014
2,163
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
XML 41.17 KB | None | 0 0
  1. # This is MalwareMustDie's duet investigation, between @0xerror and @unixfreaxjp on
  2. # grabbing injection malicious code in many blog/WP site with xmlrpc.php
  3. # The investigation is still on going, we share this note for the
  4. # sharing of the GooDork's usage in security purpose, specially dealing with the mass
  5. # infection. During the investigation I happened to listen on "Smoke on the water /Deep Purple"
  6.  
  7. //-----------------------------
  8. // SMOKE ON THE WATER.....
  9. //-----------------------------
  10.  
  11. $ ./GooDork.py
  12.                                                                  
  13.      _/_/_/                   _/_/_/                     _/      
  14.   _/         _/_/     _/_/   _/    _/   _/_/   _/  _/_/ _/  _/  
  15.  _/  _/_/ _/    _/ _/    _/ _/    _/ _/    _/ _/_/     _/_/      
  16. _/    _/ _/    _/ _/    _/ _/    _/ _/    _/ _/       _/  _/    
  17.  _/_/_/   _/_/     _/_/   _/_/_/     _/_/   _/       _/    _/    
  18.                                                                  
  19.                                                                  
  20.                                         _             _  _______ _ _____ ____  
  21.                                        | |__  _   _  | |/ /___ /| |___  / /\ \
  22.                                        | '_ \| | | | | / /  |_ \| |  / / |  | |
  23.                                        | |_) | |_| | | \ \ ___) | | / /| |  | |
  24.                                        |_.__/ \__, | | |\_\____/| |/_/ | |  | |
  25.                                               |___/  |_|        |_|     \_\/_/
  26.  
  27. ===================================
  28. .::GooDork::. 2.0
  29.  
  30. Usage: ./GooDork [dork] {-b[pattern]|-t[pattern]|-a[pattern]}
  31.  
  32. dork            -- google search query
  33. pattern         -- a regular expression to search for
  34. -b          -- search the displayable text of the dork results for 'pattern'
  35. -t          -- search the titles of the dork results for 'pattern'
  36. -u          -- search the urls of the dork results for 'pattern'
  37. -a          -- search in the anchors of the dork results for 'pattern'
  38. -L          -- Limit the amount of restults processed to the first L results
  39. -U          -- Custom User-agent
  40. e.g ./GooDork site:.edu -bStudents #returns urls to all pages in the .edu domain displaying 'Students'
  41.  
  42.  
  43. //-----------------------------
  44. // ...FIRE IN THE SKY...
  45. //-----------------------------
  46.  
  47.  ./GooDork.py "inurl:.com/xmlrpc.php" > TEST1.TXT
  48. Searching >>inurl:.com/xmlrpc.php<<
  49.  
  50.  
  51. 200
  52. OKDate: Fri, 07 Feb 2014 04:21:10 GMT
  53. Expires: -1
  54. Cache-Control: private, max-age=0
  55. Content-Type: text/html; charset=ISO-8859-1
  56. Set-Cookie: PREF=ID=c0783564044ea5dc:FF=0:TM=1391746870:LM=1391746870:S=1K6W9UCVBctDyYO8; expires=Sun, 07-Feb-2016 04:21:10 GMT; path=/; domain=.google.com
  57. Set-Cookie: NID=67=k2GA5tl93Ht90PWjy3X7yFUh1b0ZL3GDez0fwnlwvZ0hx_VZhfUEWfl_nywGmrvL6IwVuZLJpTUV4_pW5UJ62MWDopRg1_ZfY9vt9PYKBpUhdfQYP56mUgn0uOWEMXWS; expires=Sat, 09-Aug-2014 04:21:10 GMT; path=/; domain=.google.com; HttpOnly
  58. P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 for more info."
  59. Server: gws
  60. X-XSS-Protection: 1; mode=block
  61. X-Frame-Options: SAMEORIGIN
  62. Alternate-Protocol: 80:quic
  63.  
  64. Searching >>inurl:.com/xmlrpc.php<<
  65.  
  66.  
  67. 200
  68. OKDate: Fri, 07 Feb 2014 04:21:16 GMT
  69. Expires: -1
  70. Cache-Control: private, max-age=0
  71. Content-Type: text/html; charset=ISO-8859-1
  72. Set-Cookie: PREF=ID=31b3c6868222b769:FF=0:TM=1391746876:LM=1391746876:S=aZloNmPPYEXTHfKX; expires=Sun, 07-Feb-2016 04:21:16 GMT; path=/; domain=.google.com
  73. Set-Cookie: NID=67=IJ0_9zLr_3nrywu6S52-uqbhz_dBkBClQwUBCY3RXZgeD3EHlKAW7hZA8ysCETNJakaJn1iO28PjoVieX6Qz8gP5qvqZtfN4FhQudqGYjVXQg-0xui32i6WImwlwGmVN; expires=Sat, 09-Aug-2014 04:21:16 GMT; path=/; domain=.google.com; HttpOnly
  74. P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 for more info."
  75. Server: gws
  76. X-XSS-Protection: 1; mode=block
  77. X-Frame-Options: SAMEORIGIN
  78. Alternate-Protocol: 80:quic
  79.  
  80. Searching >>inurl:.com/xmlrpc.php<<
  81.  
  82.  
  83. 200
  84. OKDate: Fri, 07 Feb 2014 04:21:20 GMT
  85. Expires: -1
  86. Cache-Control: private, max-age=0
  87. Content-Type: text/html; charset=ISO-8859-1
  88. Set-Cookie: PREF=ID=bf94fcb66457b43c:FF=0:TM=1391746880:LM=1391746880:S=B46TaglNIB2hjjVz; expires=Sun, 07-Feb-2016 04:21:20 GMT; path=/; domain=.google.com
  89. Set-Cookie: NID=67=NhBagcKRuomNfq_W07g4XpiHUJwEc47zRT9sfrvWdHp-C3EffB41TWCwGMONixAKMYBOagdirFWAsLbNFSiMs_7tknDfPhm-0YK0v3ejMn8mmoc6w7s-ICfi52Rjwn_X; expires=Sat, 09-Aug-2014 04:21:20 GMT; path=/; domain=.google.com; HttpOnly
  90. P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 for more info."
  91. Server: gws
  92. X-XSS-Protection: 1; mode=block
  93. X-Frame-Options: SAMEORIGIN
  94.  
  95.  
  96. $ less TEST1.TXT
  97.  
  98.                                                                
  99.     _/_/_/                   _/_/_/                     _/      
  100.  _/         _/_/     _/_/   _/    _/   _/_/   _/  _/_/ _/  _/  
  101. _/  _/_/ _/    _/ _/    _/ _/    _/ _/    _/ _/_/     _/_/      
  102. _/    _/ _/    _/ _/    _/ _/    _/ _/    _/ _/       _/  _/    
  103. _/_/_/   _/_/     _/_/   _/_/_/     _/_/   _/       _/    _/    
  104.                                                                
  105.                                                                
  106.                                        _             _  _______ _ _____ ____  
  107.                                       | |__  _   _  | |/ /___ /| |___  / /\ \
  108.                                       | '_ \| | | | | / /  |_ \| |  / / |  | |
  109.                                       | |_) | |_| | | \ \ ___) | | / /| |  | |
  110.                                       |_.__/ \__, | | |\_\____/| |/_/ | |  | |
  111.                                              |___/  |_|        |_|     \_\/_/
  112. ===================================
  113. []
  114. ['http://mashable.com/xmlrpc.php%3Frsd', 'http://wordpress.com/xmlrpc.php%3Frsd', 'http://livinglighting.com/xmlrpc.php%3Frsd', 'http://learnthesecrethandshake.com/xmlrpc.php%3Frsd', 'http://net.tutsplus.com/xmlrpc.php%3Frsd', 'http://brushgunz.com/xmlrpc.php%3Frsd', 'http://en.blog.wordpress.com/xmlrpc.php%3Frsd', 'http://jquery.com/xmlrpc.php%3Frsd', 'http://wolfemoving.com/xmlrpc.php%3Frsd', 'http://api.jquery.com/xmlrpc.php%3Frsd', 'http://love4acure.com/xmlrpc.php%3Frsd', 'http://blog.stackoverflow.com/xmlrpc.php%3Frsd', 'http://remysharp.com/xmlrpc.php%3Frsd', 'http://twogiraffes.com/xmlrpc.php%3Frsd', 'http://joesrestaurant.com/xmlrpc.php%3Frsd', 'http://www.belgradelakesgolf.com/xmlrpc.php%3Frsd', 'http://www.kindlingapp.com/xmlrpc.php%3Frsd', 'http://blog.imulus.com/xmlrpc.php%3Frsd', 'http://www.css3files.com/xmlrpc.php%3Frsd', 'http://www.polarfocus.com/xmlrpc.php%3Frsd', 'http://www.polymth.com/xmlrpc.php%3Frsd', 'http://linkeddata.uriburner.com/about/html/http/lukeoming.com/xmlrpc.php', 'http://linkeddata.uriburner.com/about/html/http/announcements.ebay.com/xmlrpc.php', 'http://360llc.com/xmlrpc.php%3Frsd', 'http://www.northhealthdirect.com/xmlrpc.php%3Frsd', 'http://www.smartcows.com/xmlrpc.php%3Frsd', 'http://www.super8madison.com/xmlrpc.php%3Frsd', 'http://aclphysicaltherapy.com/xmlrpc.php%3Frsd', 'http://www.xmarks.com/site/ping.syndic8.com/xmlrpc.php', 'http://www.scottporad.com/xmlrpc.php%3Frsd', 'http://paultraynor.com/xmlrpc.php', 'http://www.davidottaproductions.com/xmlrpc.php%3Frsd', 'http://fashiondenver.com/xmlrpc.php%3Frsd', 'http://www.flooramaflooring.com/xmlrpc.php%3Frsd', 'http://www.torrentsmafia.biz/645a/www-89-com-xmlrpc-php', 'http://webhostingtop3.com/xmlrpc.php%3Frsd', 'http://antiquesfrederickmd.com/xmlrpc.php%3Frsd', 'http://madebyvadim.com/xmlrpc.php%3Frsd', 'http://mp3bunny.com/search.html%3Fq%3DWww%2Bmusicadelos60%2Bcom%2Bxmlrpc%2Bphp', 'http://contentsmagazine.com/xmlrpc.php%3Frsd', 'http://maverickinc.com/xmlrpc.php%3Frsd', 'http://2013.industryconf.com/xmlrpc.php%3Frsd', 'http://rickconvertino.com/xmlrpc.php', 'http://www.mm-line.com/xmlrpc.php', 'http://downloads.godhatesfags.com/xmlrpc.php%3Frsd', 'http://linuxgizmos.com/xmlrpc.php%3Frsd', 'http://doc-wordpress.com/xmlrpc.php.source.html', 'http://doc-wordpress.com/xmlrpc.php.html', 'http://thebreakfastklub.com/xmlrpc.php%3Frsd', 'http://www.richpowerinc.com/xmlrpc.php', 'http://www.blogging4jobs.com/xmlrpc.php%3Frsd', 'http://bundesligafanatic.com/xmlrpc.php%3Frsd', 'http://www.conilgalerie.com/xmlrpc.php', 'http://perrottasmarbleshop.com/xmlrpc.php', 'http://www.loketpos.com/xmlrpc.php%3Frsd', 'http://drleonardcoldwell.com/xmlrpc.php%3Frsd', 'http://www.dinhochinesebbq.com/xmlrpc.php%3Frsd', 'http://www.hypable.com/xmlrpc.php%3Frsd', 'http://programming.oreilly.com/xmlrpc.php%3Frsd', 'http://www.migueljara.com/xmlrpc.php%3Frsd', 'http://mylifeinapyramid.com/xmlrpc.php%3Frsd', 'http://www.somosdavivienda.com/xmlrpc.php', 'http://www.alldesignstuffs.com/xmlrpc.php', 'http://www.axege.com/xmlrpc.php%3Frsd', 'http://shbabeiat.com/xmlrpc.php%3Frsd', 'http://archive.news.mn/archive.shtml%3Fq%3Dwww.bonus.skytel.com/xmlrpc.php', 'http://najemnews.com/xmlrpc.php%3Frsd', 'http://www.bio-pac.com/xmlrpc.php%3Frsd', 'http://www.freshwestgrill.com/xmlrpc.php', 'http://politedentalcare.com/xmlrpc.php', 'http://doc-drupal.com/xmlrpc.php.html', 'http://pixzii.com/xmlrpc.php%3Frsd', 'http://www.holalondres.com/xmlrpc.php%3Frsd', 'http://www.indiancharlie.com/xmlrpc.php%3Frsd', 'http://panalure.com/xmlrpc.php', 'http://cindipuffer.com/xmlrpc.php', 'http://www.sandseventcenter.com/xmlrpc.php%3Frsd', 'http://bsdcoins.com/xmlrpc.php', 'http://www.thebeanofavemaria.com/xmlrpc.php', 'http://millstreamfab.com/xmlrpc.php', 'http://www.mujerglobal.com/xmlrpc.php%3Frsd', 'http://www.detroitsportsrag.com/xmlrpc.php', 'http://www.maps4news.com/xmlrpc.php%3Frsd']
  115. step: 101 ,results: 83
  116. ['http://hairmetaltimemachine.com/xmlrpc.php', 'http://presidentialmonsters.com/xmlrpc.php%3Frsd', 'http://infaround.com/xmlrpc.php%3Frsd', 'http://www.bdbaffiliates.com/xmlrpc.php%3Frsd', 'http://lared140.com/xmlrpc.php%3Frsd', 'http://renewhealthandwellness.com/xmlrpc.php', 'http://sdcornshowdown.com/xmlrpc.php%3Frsd', 'http://www.desafioushuaia.com/xmlrpc.php%3Frsd', 'http://www.rotolos.com/xmlrpc.php%3Frsd', 'http://www.cobaltproject.com/xmlrpc.php%3Frsd', 'http://www.suryafansclub.com/xmlrpc.php%3Frsd', 'http://mrpmproductions.com/xmlrpc.php', 'http://bonanzasteakhouses.com/xmlrpc.php%3Frsd', 'http://chefcorestaurantma.com/xmlrpc.php', 'http://buicongdanh.wordpress.com/xmlrpc.php%3Frsd', 'http://cresttrail.whitepasstravel.com/xmlrpc.php%3Frsd', 'http://www.mabbly.com/xmlrpc.php%3Frsd', 'http://www.tradersworldmarket.com/xmlrpc.php%3Frsd', 'http://wtbubbas.com/xmlrpc.php%3Frsd', 'http://www.angemalt.com/xmlrpc.php%3Frsd', 'http://www.purnellbodyshop.com/xmlrpc.php%3Frsd', 'http://theeggbistro.com/xmlrpc.php', 'http://lakeweatherfordmarina.com/xmlrpc-php/', 'http://www.thingsarecooking.com/xmlrpc.php%3Frsd', 'http://www.denollen.com/xmlrpc.php%3Frsd', 'http://www.thesocietyinternational.com/xmlrpc.php%3Frsd', 'http://www.fondbites.com/xmlrpc.php%3Frsd', 'http://svdpmadison.wordpress.com/xmlrpc.php%3Frsd', 'http://davidcerezophotography.com/xmlrpc.php', 'http://heiditunnellcatering.com/xmlrpc.php%3Frsd', 'http://www.marionhphotography.com/xmlrpc.php%3Frsd', 'http://thedaytripper.com/xmlrpc.php%3Frsd', 'http://dentistsalud.com/xmlrpc.php', 'http://www.cleartalkwireless.com/xmlrpc.php%3Frsd', 'http://www.valleycartage.com/xmlrpc.php%3Frsd', 'http://www.decoapartmentsbarcelona.com/xmlrpc.php%3Frsd', 'http://www.freshaireducators.com/xmlrpc.php%3Frsd', 'http://www.villaschiatti.com/xmlrpc.php%3Frsd', 'http://rivermaya.wordpress.com/xmlrpc.php%3Frsd', 'http://thecommercialhotel.com/xmlrpc.php%3Frsd', 'http://bloc11.com/xmlrpc.php%3Frsd', 'http://www.b7klan.com/xmlrpc.php%3Frsd', 'http://www.profmehdi.com/xmlrpc.php', 'http://realdlhughley.com/xmlrpc.php%3Frsd', 'http://growthintel.com/xmlrpc.php%3Frsd', 'http://raleighbrewingcompany.com/xmlrpc.php%3Frsd', 'http://www.image-models.com/xmlrpc.php%3Frsd', 'http://sleeplessinarizona.com/xmlrpc.php', 'http://www.sandraslatonlaw.com/xmlrpc.php', 'http://mckinneyswesternstore.com/xmlrpc.php%3Frsd', 'http://www.chadmattandrob.com/xmlrpc.php%3Frsd', 'http://www.remalosangeles.com/xmlrpc.php', 'http://www.pemberleydigital.com/xmlrpc.php%3Frsd', 'http://fr.competitor.com/xmlrpc.php%3Frsd', 'http://libertystormradio.com/xmlrpc.php%3Frsd', 'http://szechenyispabaths.com/xmlrpc.php%3Frsd', 'http://bryantdentalcare.com/xmlrpc.php', 'http://www.thebeercade.com/xmlrpc.php%3Frsd', 'http://www.aluminiosmoscatel.com/xmlrpc.php', 'http://chapmanufiji.com/xmlrpc.php', 'http://silverlandlabs.com/xmlrpc.php', 'http://educators.honeywell.com/xmlrpc.php%3Frsd', 'http://proformeuropa.com/xmlrpc.php', 'http://230newton.com/xmlrpc.php%3Frsd', 'http://douglasdentaldesmoines.com/xmlrpc.php', 'http://bluebubblelab.com/xmlrpc.php%3Frsd']
  117. step: 201 ,results: 66
  118. ['http://geisthalf.com/xmlrpc.php%3Frsd', 'http://makethatthing.com/xmlrpc.php%3Frsd', 'http://atlanticcapitaladvisors.com/xmlrpc.php', 'http://www.manchesterhdw.com/xmlrpc.php', 'http://telesud.com/xmlrpc.php%3Frsd', 'http://sunrisehotelobzor.com/xmlrpc.php%3Frsd', 'http://www.luckydogtampa.com/xmlrpc.php%3Frsd', 'http://www.threeriversrambler.com/xmlrpc.php%3Frsd', 'http://germanfest.com/xmlrpc.php%3Frsd', 'http://beneficialreggae.com/xmlrpc.php%3Frsd', 'http://smacgym.com/xmlrpc.php', 'http://www.iosoffices.com/xmlrpc.php%3Frsd', 'http://www.ixs.com/xmlrpc.php%3Frsd', 'http://www.wpelevation.com/xmlrpc.php%3Frsd', 'http://online.lindenmeyr.com/xmlrpc.php%3Frsd', 'http://www.fuschilloandhamilton.com/xmlrpc.php', 'http://odontsis.com/xmlrpc.php%3Frsd', 'http://www.flawlessfinish.com/xmlrpc.php%3Frsd', 'http://qriverresort.com/xmlrpc.php%3Frsd', 'http://www.moccamedia.com/xmlrpc.php%3Frsd', 'http://www.perivolashideaway.com/xmlrpc.php%3Frsd', 'http://ghiniscafe.com/xmlrpc.php%3Frsd', 'http://beantownclassic.com/xmlrpc.php%3Frsd', 'http://www.theteapartyleadershipfund.com/xmlrpc.php%3Frsd', 'http://lyngenet.com/xmlrpc.php%3Frsd', 'http://www.overviewthemovie.com/xmlrpc.php%3Frsd', 'http://uwprepharmacy.com/xmlrpc.php%3Frsd', 'http://www.thirtyeightdegreesnorth.com/xmlrpc.php%3Frsd', 'http://www.boldacademy.com/xmlrpc.php%3Frsd', 'http://www.farjami.com/xmlrpc.php%3Frsd', 'http://pabelonastudio.com/xmlrpc.php%3Frsd', 'http://www.enactusmemorial.com/xmlrpc.php%3Frsd', 'http://www.asmallgame.com/xmlrpc.php%3Frsd', 'http://havasufightnight.com/xmlrpc.php', 'http://yourpowertv.com/xmlrpc.php%3Frsd', 'http://www.captureitota.com/xmlrpc.php%3Frsd', 'http://www.wightmaterialshandling.com/xmlrpc.php%3Frsd', 'http://davidbaldacci.com/xmlrpc.php%3Frsd', 'http://symmetrytilenh.com/xmlrpc.php%3Frsd', 'http://www.smprtitle.com/xmlrpc.php%3Frsd', 'http://mabra.com/xmlrpc.php%3Frsd', 'http://www.woodendbarn.com/xmlrpc.php%3Frsd', 'http://playlist-live.com/xmlrpc.php%3Frsd', 'http://www.thesenewpuritans.com/xmlrpc.php%3Frsd', 'http://acquirethefire.com/xmlrpc.php%3Frsd', 'http://ericcahan.com/xmlrpc.php%3Frsd', 'http://www.mhsindiana.com/xmlrpc.php%3Frsd', 'http://www.vidyard.com/xmlrpc.php%3Frsd', 'http://www.everybodyltd.com/xmlrpc.php%3Frsd', 'http://heartlinetheatricals.com/xmlrpc.php', 'http://www.alfredyanna.com/xmlrpc.php%3Frsd', 'http://biketechmiami.com/xmlrpc.php%3Frsd', 'http://www.nextcontrols.com/xmlrpc.php%3Frsd', 'http://insiderscash.com/xmlrpc.php%3Frsd', 'http://healocapital.com/xmlrpc.php', 'http://iamdjp.com/xmlrpc.php%3Frsd', 'http://www.sfautoshow.com/xmlrpc.php%3Frsd', 'http://adventuresoflilylapp.com/xmlrpc.php%3Frsd', 'http://sisygarza.com/xmlrpc.php%3Frsd', 'http://www.kamloopscurlingclub.com/xmlrpc.php%3Frsd']
  119. step: 301 ,results: 60
  120. ['http://ramiismail.com/xmlrpc.php%3Frsd', 'http://craftbutchery.com/xmlrpc.php%3Frsd', 'http://ontariosake.com/xmlrpc.php%3Frsd', 'http://mattgreenphoto.com/xmlrpc.php%3Frsd', 'http://southbendjazzfestival.com/xmlrpc.php%3Frsd', 'http://www.igrglobal.com/xmlrpc.php%3Frsd', 'http://farrahgray.com/xmlrpc.php%3Frsd', 'http://www.region1gymnastics.com/xmlrpc.php%3Frsd', 'http://lawrencegymnastics.com/xmlrpc.php%3Frsd', 'http://missrenaissancepageant.com/xmlrpc.php%3Frsd', 'http://www.crossmark.com/xmlrpc.php%3Frsd', 'http://www.hgi-global.com/xmlrpc.php%3Frsd', 'http://zodop.com/xmlrpc.php%3Frsd', 'http://www.aashirwadapartments.com/xmlrpc.php%3Frsd', 'http://mytastythai.com/xmlrpc.php', 'http://isostick.com/xmlrpc.php%3Frsd', 'http://www.zoeleela.com/xmlrpc.php%3Frsd', 'http://holdenlink.com/xmlrpc.php%3Frsd', 'http://www.squadrati.com/xmlrpc.php%3Frsd', 'http://www.rippedtogether.com/xmlrpc.php%3Frsd', 'http://www.secretgeometry.com/xmlrpc.php%3Frsd', 'http://www.albertmohler.com/xmlrpc.php%3Frsd', 'http://www.walmartlabs.com/xmlrpc.php%3Frsd', 'http://www.arpeggiata.com/xmlrpc.php%3Frsd', 'http://www.huddler.com/xmlrpc.php%3Frsd', 'http://www.valuescoupons.com/xmlrpc.php%3Frsd', 'http://www.vault-prep.com/xmlrpc.php', 'http://babinlek.com/xmlrpc.php%3Frsd', 'http://rigop.kdari.com/xmlrpc.php%3Frsd', 'http://benthesage.com/xmlrpc.php%3Frsd', 'http://www.impactradius.com/xmlrpc.php%3Frsd', 'http://www.mcilveenfamilylaw.com/xmlrpc.php%3Frsd', 'http://www.littlehotelier.com/xmlrpc.php%3Frsd', 'http://www.bgtpartners.com/xmlrpc.php%3Frsd', 'http://www.ganeshayogachicago.com/xmlrpc.php%3Frsd', 'http://www.cuartoscuro.com/xmlrpc.php%3Frsd', 'http://www.weedportal.com/xmlrpc.php%3Frsd', 'http://lostvalleyoflondon.com/xmlrpc.php%3Frsd', 'http://alport.com/xmlrpc.php%3Frsd', 'http://www.kevinlileschallenge.com/xmlrpc.php%3Frsd', 'http://www.alanaragonblog.com/xmlrpc.php%3Frsd', 'http://www.vivreavechooponopono.com/xmlrpc.php%3Frsd', 'http://rockhealth.com/xmlrpc.php%3Frsd', 'http://www.andreimaxwel.com/xmlrpc.php%3Frsd', 'http://istanbulviva.com/xmlrpc.php%3Frsd', 'http://zipxworld.com/xmlrpc.php%3Frsd', 'http://petpalssj.com/xmlrpc.php', 'http://swing46.com/xmlrpc.php', 'http://thedentalcentrelondon.com/xmlrpc.php%3Frsd', 'http://www.mduperu.com/xmlrpc.php%3Frsd', 'http://samsonmotorworks.com/xmlrpc.php%3Frsd', 'http://blog.ringcentral.com/xmlrpc.php%3Frsd', 'http://www.anitarenfroe.com/xmlrpc.php%3Frsd', 'http://tankeinc.com/xmlrpc.php%3Frsd', 'http://www.readingpokertells.com/xmlrpc.php%3Frsd', 'http://www.dance-teacher.com/xmlrpc.php%3Frsd', 'http://barbarashor.com/xmlrpc.php%3Frsd', 'http://www.enclaveformacion.com/xmlrpc.php%3Frsd', 'http://dermaribas.com/xmlrpc.php%3Frsd', 'http://www.agnesabecassis.com/xmlrpc.php%3Frsd', 'http://bergcloud.com/xmlrpc.php%3Frsd', 'http://www.countrysurvival.com/xmlrpc.php%3Frsd', 'http://www.crownweather.com/xmlrpc.php%3Frsd', 'http://www.saddlemountainrvpark.com/xmlrpc.php%3Frsd', 'http://www.rcrfilms.com/xmlrpc.php%3Frsd', 'http://www.themapsystem.com/xmlrpc.php%3Frsd', 'http://www.wefixnow.com/xmlrpc.php%3Frsd', 'http://hotelesdoradal.com/xmlrpc.php', 'http://grassrootscampaigns.com/xmlrpc.php%3Frsd', 'http://www.mrwing.com/xmlrpc.php%3Frsd']
  121. step: 401 ,results: 70
  122. ['http://www.theageofmiraclesbook.com/xmlrpc.php%3Frsd', 'http://www.mgcaledonian.com/xmlrpc.php%3Frsd', 'http://www.moustacheusa.com/xmlrpc.php%3Frsd', 'http://jessefrohman.com/xmlrpc.php%3Frsd', 'http://www.gosubuilds.com/xmlrpc.php%3Frsd', 'http://www.monitorproducts.com/xmlrpc.php%3Frsd', 'http://whoismatt.com/xmlrpc.php%3Frsd', 'http://www.thelongevitynowconference.com/xmlrpc.php%3Frsd', 'http://www.jasonplumb.com/xmlrpc.php%3Frsd', 'http://www.potsc.com/xmlrpc.php%3Frsd', 'http://www.lowcarbcruiseinfo.com/xmlrpc.php%3Frsd', 'http://www.weddingnetworkusa.com/xmlrpc.php%3Frsd', 'http://miscbaseball.wordpress.com/xmlrpc.php%3Frsd', 'http://fungalaxygeorgia.com/xmlrpc.php%3Frsd', 'http://www.xhelazz.com/xmlrpc.php%3Frsd', 'http://www.kusumasarivilla.com/xmlrpc.php%3Frsd', 'http://www.portaldecoquimbo.com/xmlrpc.php', 'http://www.asesinos-en-serie.com/xmlrpc.php%3Frsd', 'http://flyplugins.com/xmlrpc.php%3Frsd', 'http://westchasedistrict.com/xmlrpc.php%3Frsd', 'http://www.lagrotteduyeti.com/xmlrpc.php%3Frsd', 'http://vinoseguren.com/xmlrpc.php%3Frsd', 'http://domgosci.benedyktyni.com/xmlrpc.php%3Frsd', 'http://www.ker-downeyafrica.com/xmlrpc.php%3Frsd', 'http://www.brain-surgery.com/xmlrpc.php%3Frsd', 'http://completelyseriouscomics.com/xmlrpc.php%3Frsd', 'http://www.legalforcelaw.com/xmlrpc.php%3Frsd', 'http://turismobackpacker.com/xmlrpc.php%3Frsd', 'http://www.lifesongs.com/xmlrpc.php%3Frsd', 'http://www.myreporter.com/xmlrpc.php%3Frsd', 'http://www.visit-okinawa.com/xmlrpc.php%3Frsd', 'http://www.socialknx.com/xmlrpc.php%3Frsd', 'http://www.pccougars.com/xmlrpc.php%3Frsd', 'http://www.chrononsystems.com/xmlrpc.php%3Frsd', 'http://lrtimelapse.com/xmlrpc.php%3Frsd', 'http://www.citynewsmumbai.com/xmlrpc.php%3Frsd', 'http://www.sinemensuel.com/xmlrpc.php%3Frsd', 'http://www.fuzzyfriendsrescue.com/xmlrpc.php%3Frsd', 'http://cafefuerte.com/xmlrpc.php%3Frsd', 'http://www.redwormcomposting.com/xmlrpc.php%3Frsd', 'http://www.indianlakecottages.com/xmlrpc.php', 'http://www.lead-converter.com/xmlrpc.php%3Frsd', 'http://www.gretchenrubin.com/xmlrpc.php%3Frsd', 'http://suitepieces.com/xmlrpc.php%3Frsd', 'http://bretthoebel.com/xmlrpc.php%3Frsd', 'http://evetravel.wordpress.com/xmlrpc.php%3Frsd', 'http://www.danesemilano.com/xmlrpc.php%3Frsd', 'http://www.insieme2.com/xmlrpc.php', 'http://english.bouletcorp.com/xmlrpc.php%3Frsd', 'http://www.bgprod.com/xmlrpc.php%3Frsd', 'http://member.wishlistproducts.com/xmlrpc.php%3Frsd', 'http://askvadisi.com/xmlrpc.php%3Frsd', 'http://www.davidhogansermons.com/xmlrpc.php%3Frsd', 'http://theartistsden.com/xmlrpc.php%3Frsd', 'http://www.puremountainholidays.com/xmlrpc.php%3Frsd', 'http://adventureamericas.wordpress.com/xmlrpc.php%3Frsd', 'http://www.divorcecorp.com/xmlrpc.php%3Frsd', 'http://www.madisonmilesmedia.com/xmlrpc.php%3Frsd', 'http://www.downtownfwb.com/xmlrpc.php%3Frsd', 'http://westank.com/xmlrpc.php%3Frsd', 'http://soulowicz.wordpress.com/xmlrpc.php%3Frsd', 'http://bonniesandler.com/xmlrpc.php', 'http://dryiceenergy.com/xmlrpc.php%3Frsd', 'http://kepaacero.com/xmlrpc.php%3Frsd', 'http://www.takeoffbriefing.com/xmlrpc.php%3Frsd', 'http://aardvarks420.com/xmlrpc.php', 'http://maximumble.thebookofbiff.com/xmlrpc.php%3Frsd', 'http://microinteractions.com/xmlrpc.php%3Frsd', 'http://askjudgemathis.com/xmlrpc.php%3Frsd', 'http://www.altjband.com/xmlrpc.php%3Frsd', 'http://www.conocebarrick.com/xmlrpc.php%3Frsd', 'http://www.egoitaliano.com/xmlrpc.php%3Frsd', 'http://www.doveawards.com/xmlrpc.php%3Frsd', 'http://www.jmromero.com/xmlrpc.php%3Frsd', 'http://www.dev47apps.com/xmlrpc.php%3Frsd', 'http://www.houseinteriorz.com/xmlrpc.php%3Frsd']
  123. step: 501 ,results: 76
  124. ['http://www.gopdfs.com/xmlrpc.php--index.php-mysql']
  125. step: 601 ,results: 1
  126. ['http://www.gopdfs.com/xmlrpc.php--index.php-mysql']
  127. step: 701 ,results: 1
  128. User stopped dork
  129. //-----------------------------------------------------------------------
  130. // SOME STUPID WITH THE FLARE GUN....BURNS THE PLACE TO THE GROUND.....
  131. // (bummer...)
  132. //-----------------------------------------------------------------------
  133. sh-3.2$ ./GooDork.py "inurl:.com/xmlrpc.php" |more
  134. Searching >>inurl:.com/xmlrpc.php<<
  135.  
  136.  
  137. 302
  138. FoundLocation: http://ipv4.google.com/sorry/IndexRedirect?continue=http://www.google.com/search%3Fnum%3D500%26q%3Dinurl:.com/xmlrpc.php%26start%3D1
  139. Date: Fri, 07 Feb 2014 04:25:47 GMT
  140. Pragma: no-cache
  141. Expires: Fri, 01 Jan 1990 00:00:00 GMT
  142. Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
  143. Content-Type: text/html; charset=UTF-8
  144. Server: HTTP server (unknown)
  145. Content-Length: 329
  146. X-XSS-Protection: 1; mode=block
  147. X-Frame-Options: SAMEORIGIN
  148. Alternate-Protocol: 80:quic
  149.  
  150.                                                                
  151.     _/_/_/                   _/_/_/                     _/      
  152.  _/         _/_/     _/_/   _/    _/   _/_/   _/  _/_/ _/  _/  
  153. _/  _/_/ _/    _/ _/    _/ _/    _/ _/    _/ _/_/     _/_/      
  154. _/    _/ _/    _/ _/    _/ _/    _/ _/    _/ _/       _/  _/    
  155. _/_/_/   _/_/     _/_/   _/_/_/     _/_/   _/       _/    _/    
  156.                                                                
  157.                                                                
  158.                                        _             _  _______ _ _____ ____  
  159.                                       | |__  _   _  | |/ /___ /| |___  / /\ \
  160.                                       | '_ \| | | | | / /  |_ \| |  / / |  | |
  161.                                       | |_) | |_| | | \ \ ___) | | / /| |  | |
  162.                                       |_.__/ \__, | | |\_\____/| |/_/ | |  | |
  163.                                              |___/  |_|        |_|     \_\/_/
  164. ===================================
  165. []
  166. []
  167. step: 1 ,results: 0
  168. Results:
  169. Found 0 results in 0.584308 seconds
  170. sh-3.2$
  171. //-----------------------------------------------------------
  172. // AGAIN..(All OF YOU, SING IT!) SMOKE ON THE WA--TER...
  173. //------------------------------------------------------------
  174. /* Gratitude to 0xerror!! , you save the day!! :)  */
  175. [*] Results of ['inurl:.com/xmlrpc.php', '-oaldshfkajkshf\xc3\xb6kjahs.txt']
  176. [0] http://www.hypable.com/xmlrpc.php%3Frsd
  177. [1] http://odelleducation.com/xmlrpc.php%3Frsd
  178. [2] http://barbarashor.com/xmlrpc.php%3Frsd
  179. [3] http://bloc11.com/xmlrpc.php%3Frsd
  180. [4] http://www.indiancharlie.com/xmlrpc.php%3Frsd
  181. [5] http://higherlevelri.com/xmlrpc.php
  182. [6] http://maverickinc.com/xmlrpc.php%3Frsd
  183. [7] http://www.moccamedia.com/xmlrpc.php%3Frsd
  184. [8] http://www.spartzinc.com/xmlrpc.php%3Frsd
  185. [9] http://www.thelongevitynowconference.com/xmlrpc.php%3Frsd
  186. [10] http://antiquesfrederickmd.com/xmlrpc.php%3Frsd
  187. [11] http://www.mm-line.com/xmlrpc.php
  188. [12] http://www.cnx-software.com/xmlrpc.php%3Frsd
  189. [13] http://www.mcgladreyclassic.com/xmlrpc.php%3Frsd
  190. [14] http://www.loketpos.com/xmlrpc.php%3Frsd
  191. [15] http://rickconvertino.com/xmlrpc.php
  192. [16] http://www.detroitsportsrag.com/xmlrpc.php
  193. [17] http://drleonardcoldwell.com/xmlrpc.php%3Frsd
  194. [18] http://odontsis.com/xmlrpc.php%3Frsd
  195. [19] http://newbooksinbrief.com/xmlrpc.php%3Frsd
  196. [20] http://craftbutchery.com/xmlrpc.php%3Frsd
  197. [21] http://www.css3files.com/xmlrpc.php%3Frsd
  198. [22] http://chapmanufiji.com/xmlrpc.php
  199. [23] http://boxmanstudios.com/xmlrpc.php%3Frsd
  200. [24] http://www.gosubuilds.com/xmlrpc.php%3Frsd
  201. [25] http://bluebubblelab.com/xmlrpc.php%3Frsd
  202. [26] http://domgosci.benedyktyni.com/xmlrpc.php%3Frsd
  203. [27] http://blog.hipchat.com/xmlrpc.php%3Frsd
  204. [28] http://www.captureitota.com/xmlrpc.php%3Frsd
  205. [29] http://downloads.godhatesfags.com/xmlrpc.php%3Frsd
  206. [30] http://chadsarno.com/xmlrpc.php%3Frsd
  207. [31] http://www.harryup.com/xmlrpc.php%3Frsd
  208. [32] http://annabethbarnes.com/xmlrpc.php%3Frsd
  209. [33] http://www.thereconnection.com/xmlrpc.php
  210. [34] http://www.boldacademy.com/xmlrpc.php%3Frsd
  211. [35] http://cresttrail.whitepasstravel.com/xmlrpc.php%3Frsd
  212. [36] http://aclphysicaltherapy.com/xmlrpc.php%3Frsd
  213. [37] http://petersagal.com/xmlrpc.php%3Frsd
  214. [38] http://www.danesemilano.com/xmlrpc.php%3Frsd
  215. [39] http://stoningtongardens.com/xmlrpc.php%3Frsd
  216. [40] http://www.egoitaliano.com/xmlrpc.php%3Frsd
  217. [41] http://www.mimictechnologies.com/xmlrpc.php%3Frsd
  218. [42] http://rivermaya.wordpress.com/xmlrpc.php%3Frsd
  219. [43] http://www.kusumasarivilla.com/xmlrpc.php%3Frsd
  220. [44] http://lared140.com/xmlrpc.php%3Frsd
  221. [45] http://istanbulviva.com/xmlrpc.php%3Frsd
  222. [46] http://www.cabionline.com/xmlrpc.php%3Frsd
  223. [47] http://samsonmotorworks.com/xmlrpc.php%3Frsd
  224. [48] http://clevelandrootcanal.com/xmlrpc.php
  225. [49] http://lakeweatherfordmarina.com/xmlrpc-php/
  226. [50] http://www.suryafansclub.com/xmlrpc.php%3Frsd
  227. [51] http://www.decoapartmentsbarcelona.com/xmlrpc.php%3Frsd
  228. [52] http://petpalssj.com/xmlrpc.php
  229. [53] http://en.blog.wordpress.com/xmlrpc.php%3Frsd
  230. [54] http://www.anothergirlatplay.com/xmlrpc.php%3Frsd
  231. [55] http://officenaps.com/xmlrpc.php
  232. [56] http://www.adextent.com/xmlrpc.php%3Frsd
  233. [57] http://www.entradasgo.com/xmlrpc.php%3Frsd
  234. [58] http://www.brain-surgery.com/xmlrpc.php%3Frsd
  235. [59] http://www.enactusmemorial.com/xmlrpc.php%3Frsd
  236. [60] http://raleighbrewingcompany.com/xmlrpc.php%3Frsd
  237. [61] http://www.ixs.com/xmlrpc.php%3Frsd
  238. [62] http://shbabeiat.com/xmlrpc.php%3Frsd
  239. [63] http://thetasteofnm.com/xmlrpc.php
  240. [64] http://livinglighting.com/xmlrpc.php%3Frsd
  241. [65] http://www.chrononsystems.com/xmlrpc.php%3Frsd
  242. [66] http://www.thingsarecooking.com/xmlrpc.php%3Frsd
  243. [67] http://www.agnesabecassis.com/xmlrpc.php%3Frsd
  244. [68] http://www.maps4news.com/xmlrpc.php%3Frsd
  245. [69] http://apethebook.com/xmlrpc.php%3Frsd
  246. [70] http://www.profmehdi.com/xmlrpc.php
  247. [71] http://www.airesdecambio.com/xmlrpc.php%3Frsd
  248. [72] http://panalure.com/xmlrpc.php
  249. [73] http://www.yadshow.com/xmlrpc.php%3Frsd
  250. [74] http://linkeddata.uriburner.com/about/html/http/lukeoming.com/xmlrpc.php
  251. [75] http://hotelsolixent.com/xmlrpc.php%3Frsd
  252. [76] http://www.polarfocus.com/xmlrpc.php%3Frsd
  253. [77] http://advo911.com/xmlrpc.php%3Frsd
  254. [78] http://www.angemalt.com/xmlrpc.php%3Frsd
  255. [79] http://growthintel.com/xmlrpc.php%3Frsd
  256. [80] http://uwprepharmacy.com/xmlrpc.php%3Frsd
  257. [81] http://www.visit-okinawa.com/xmlrpc.php%3Frsd
  258. [82] http://mylifeinapyramid.com/xmlrpc.php%3Frsd
  259. [83] http://www.manchesterhdw.com/xmlrpc.php
  260. [84] http://mhall119.com/xmlrpc.php%3Frsd
  261. [85] http://www.northhealthdirect.com/xmlrpc.php%3Frsd
  262. [86] http://net.tutsplus.com/xmlrpc.php%3Frsd
  263. [87] http://omruk.com/xmlrpc.php%3Frsd
  264. [88] http://bodyandsoul-nyc.com/xmlrpc.php%3Frsd
  265. [89] http://lakonianblade.com/xmlrpc.php
  266. [90] http://dermaribas.com/xmlrpc.php%3Frsd
  267. [91] http://www.weedportal.com/xmlrpc.php%3Frsd
  268. [92] http://www.pizzeriaortica.com/xmlrpc.php%3Frsd
  269. [93] http://buicongdanh.wordpress.com/xmlrpc.php%3Frsd
  270. [94] http://www.cuartoscuro.com/xmlrpc.php%3Frsd
  271. [95] http://jonssonworkwear.com/xmlrpc.php%3Frsd
  272. [96] http://www.jasonplumb.com/xmlrpc.php%3Frsd
  273. [97] http://dentistsalud.com/xmlrpc.php
  274. [98] http://pixzii.com/xmlrpc.php%3Frsd
  275. [99] http://bayanortopedidoktoru.com/xmlrpc.php
  276. [100] http://www.iosoffices.com/xmlrpc.php%3Frsd
  277. [101] http://www.taledar.com/xmlrpc.php%3Frsd
  278. [102] http://www.bdbaffiliates.com/xmlrpc.php%3Frsd
  279. [103] http://www.holalondres.com/xmlrpc.php%3Frsd
  280. [104] http://doc-drupal.com/xmlrpc.php.source.html
  281. [105] http://support.publish.nokia.com/xmlrpc.php%3Frsd
  282. [106] http://pabelonastudio.com/xmlrpc.php%3Frsd
  283. [107] http://fashiondenver.com/xmlrpc.php%3Frsd
  284. [108] http://mrswilkes.com/xmlrpc.php%3Frsd
  285. [109] http://www.theageofmiraclesbook.com/xmlrpc.php%3Frsd
  286. [110] http://bonniesandler.com/xmlrpc.php
  287. [111] http://www.bistrotdepays.com/xmlrpc.php%3Frsd
  288. [112] http://bsdcoins.com/xmlrpc.php
  289. [113] http://www.myreporter.com/xmlrpc.php%3Frsd
  290. [114] http://www.readingpokertells.com/xmlrpc.php%3Frsd
  291. [115] http://learnthesecrethandshake.com/xmlrpc.php%3Frsd
  292. [116] http://ericcahan.com/xmlrpc.php%3Frsd
  293. [117] http://www.socialknx.com/xmlrpc.php%3Frsd
  294. [118] http://www.deardenwine.com/xmlrpc.php
  295. [119] http://germanfest.com/xmlrpc.php%3Frsd
  296. [120] http://mp3bunny.com/search.html%3Fq%3DWww%2Bmusicadelos60%2Bcom%2Bxmlrpc%2Bphp
  297. [121] http://diggiloo.com/xmlrpc.php%3Frsd
  298. [122] http://www.janetreitman.com/xmlrpc.php%3Frsd
  299. [123] http://linuxgizmos.com/xmlrpc.php%3Frsd
  300. [124] http://www.super8madison.com/xmlrpc.php%3Frsd
  301. [125] http://jeddiffenderfer.com/xmlrpc.php
  302. [126] http://www.ganeshayogachicago.com/xmlrpc.php%3Frsd
  303. [127] http://www.4tsg.com/xmlrpc.php%3Frsd
  304. [128] http://adventureamericas.wordpress.com/xmlrpc.php%3Frsd
  305. [129] http://doc-wordpress.com/xmlrpc.php.source.html
  306. [130] http://iamdjp.com/xmlrpc.php%3Frsd
  307. [131] http://180muncie.com/xmlrpc.php
  308. [132] http://www.neilcuninghame.com/xmlrpc.php%3Frsd
  309. [133] http://chefcorestaurantma.com/xmlrpc.php
  310. [134] http://the-talks.com/xmlrpc.php%3Frsd
  311. [135] http://www.avionicaata.com/xmlrpc.php
  312. [136] http://benthesage.com/xmlrpc.php%3Frsd
  313. [137] http://www.bogeysclubandcafe.com/xmlrpc.php%3Frsd
  314. [138] http://www.patrawsonsurfboards.com/xmlrpc.php%3Frsd
  315. [139] http://www.huddler.com/xmlrpc.php%3Frsd
  316. [140] http://casagaiapr.com/xmlrpc.php
  317. [141] http://thaibasilutah.com/xmlrpc.php%3Frsd
  318. [142] http://fungalaxygeorgia.com/xmlrpc.php%3Frsd
  319. [143] http://www.thirtyeightdegreesnorth.com/xmlrpc.php%3Frsd
  320. [144] http://makethatthing.com/xmlrpc.php%3Frsd
  321. [145] http://brushfirerecords.com/xmlrpc.php%3Frsd
  322. [146] http://joesrestaurant.com/xmlrpc.php%3Frsd
  323. [147] http://whoismatt.com/xmlrpc.php%3Frsd
  324. [148] http://sisygarza.com/xmlrpc.php%3Frsd
  325. [149] http://poundandgrain.com/xmlrpc.php%3Frsd
  326. [150] http://huntprooutfitters.com/xmlrpc.php%3Frsd
  327. [151] http://crewandlu.com/xmlrpc.php%3Frsd
  328. [152] http://svdpmadison.wordpress.com/xmlrpc.php%3Frsd
  329. [153] http://thebreakfastklub.com/xmlrpc.php%3Frsd
  330. [154] http://www.freshaireducators.com/xmlrpc.php%3Frsd
  331. [155] http://www.threeriversrambler.com/xmlrpc.php%3Frsd
  332. [156] http://novafounders.com/xmlrpc.php%3Frsd
  333. [157] http://www.bgprod.com/xmlrpc.php%3Frsd
  334. [158] http://wtbubbas.com/xmlrpc.php%3Frsd
  335. [159] http://www.victoriousflooring.com/xmlrpc.php%3Frsd
  336. [160] http://www.alfredyanna.com/xmlrpc.php%3Frsd
  337. [161] http://szechenyispabaths.com/xmlrpc.php%3Frsd
  338. [162] http://mouseflow.com/xmlrpc.php%3Frsd
  339. [163] http://ohiyafriends.com/xmlrpc.php%3Frsd
  340. [164] http://www.kamloopscurlingclub.com/xmlrpc.php%3Frsd
  341. [165] http://miscbaseball.wordpress.com/xmlrpc.php%3Frsd
  342. [166] http://www.peakstonegroup.com/xmlrpc.php%3Frsd
  343. [167] http://atlanticcapitaladvisors.com/xmlrpc.php
  344. [168] http://sonomacountycollective.com/xmlrpc.php
  345. [169] http://www.thesocietyinternational.com/xmlrpc.php%3Frsd
  346. [170] http://blog.ringcentral.com/xmlrpc.php%3Frsd
  347. [171] http://www.hgi-global.com/xmlrpc.php%3Frsd
  348. [172] http://www.diamondknot.com/xmlrpc.php%3Frsd
  349. [173] http://www.rancholoslobos.com/xmlrpc.php%3Frsd
  350. [174] http://bergcloud.com/xmlrpc.php%3Frsd
  351. [175] http://lrtimelapse.com/xmlrpc.php%3Frsd
  352. [176] http://suitepieces.com/xmlrpc.php%3Frsd
  353. [177] http://greatvalleyrealestate.com/xmlrpc.php%3Frsd
  354. [178] http://www.lead-converter.com/xmlrpc.php%3Frsd
  355. [179] http://telesud.com/xmlrpc.php%3Frsd
  356. [180] http://www.vault-prep.com/xmlrpc.php
  357. [181] http://demo.openlinksw.com/about/html/http/markdionsbartramstravels.com/xmlrpc.php
  358. [182] http://www.tucsonattractions.com/xmlrpc.php%3Frsd
  359. [183] http://www.asuni.com/xmlrpc.php%3Frsd
  360. [184] http://cafefuerte.com/xmlrpc.php%3Frsd
  361. [185] http://billfletcherjr.com/xmlrpc.php%3Frsd
  362. [186] http://5thirtyone.com/xmlrpc.php%3Frsd
  363. [187] http://www.mobicage.com/xmlrpc.php%3Frsd
  364. [188] http://html5doctor.com/xmlrpc.php%3Frsd
  365. [189] http://ashleyabroad.com/xmlrpc.php%3Frsd
  366. [190] http://www.filmovita.com/xmlrpc.php%3Frsd
  367. [191] http://mgovideo.com/xmlrpc.php%3Frsd
  368. [192] http://judahfriedlander.com/xmlrpc.php%3Frsd
  369. [193] http://www.desafioushuaia.com/xmlrpc.php%3Frsd
  370. [194] http://sdcornshowdown.com/xmlrpc.php%3Frsd
  371. [195] http://madebyvadim.com/xmlrpc.php%3Frsd
  372. [196] http://washingtonstreetinfo.com/xmlrpc.php
  373. [197] http://www.bio-pac.com/xmlrpc.php%3Frsd
  374. [198] http://www.farjami.com/xmlrpc.php%3Frsd
  375. [199] http://goodforyouband.com/xmlrpc.php%3Frsd
  376. [200] http://www.legalforcelaw.com/xmlrpc.php%3Frsd
  377. [201] http://www.tagshardware.com/xmlrpc.php%3Frsd
  378. [202] http://www.pemberleydigital.com/xmlrpc.php%3Frsd
  379. [203] http://proformeuropa.com/xmlrpc.php
  380. [204] http://www.cityicepavilion.com/xmlrpc.php%3Frsd
  381. [205] http://petroneedintl.com/xmlrpc.php
  382. [206] http://wolfemoving.com/xmlrpc.php%3Frsd
  383. [207] http://www.smprtitle.com/xmlrpc.php%3Frsd
  384. [208] http://www.coonrestoration.com/xmlrpc.php%3Frsd
  385. [209] http://thenextweb.com/xmlrpc.php%3Frsd
  386. [210] http://www.dinhochinesebbq.com/xmlrpc.php%3Frsd
  387. [211] http://www.b7klan.com/xmlrpc.php%3Frsd
  388. [212] http://www.countrysurvival.com/xmlrpc.php%3Frsd
  389. [213] http://brushgunz.com/xmlrpc.php%3Frsd
  390. [214] http://twogiraffes.com/xmlrpc.php%3Frsd
  391. [215] http://www.wirelessideology.com/xmlrpc.php%3Frsd
  392. [216] http://symmetrytilenh.com/xmlrpc.php%3Frsd
  393. [217] http://www.blogging4jobs.com/xmlrpc.php%3Frsd
  394. [218] http://www.freedyjohnston.com/xmlrpc.php%3Frsd
  395. [219] http://harmonysheds.com/xmlrpc.php%3Frsd
  396. [220] http://www.belgradelakesgolf.com/xmlrpc.php%3Frsd
  397. [221] http://doc-drupal.com/xmlrpc.php.html
  398. [222] http://www.freshwestgrill.com/xmlrpc.php
  399. [223] http://www.asesinos-en-serie.com/xmlrpc.php%3Frsd
  400. [224] http://www.boycecollege.com/xmlrpc.php%3Frsd
  401. [225] http://www.migueljara.com/xmlrpc.php%3Frsd
  402. [226] http://www.pccougars.com/xmlrpc.php%3Frsd
  403. [227] http://douglasdentaldesmoines.com/xmlrpc.php
  404. [228] http://www.albertmohler.com/xmlrpc.php%3Frsd
  405. [229] http://www.freeangelcardreadingsonline.com/xmlrpc.php%3Frsd
  406. [230] http://blog.imulus.com/xmlrpc.php%3Frsd
  407. [231] http://playlist-live.com/xmlrpc.php%3Frsd
  408. [232] http://beantownclassic.com/xmlrpc.php%3Frsd
  409. [233] http://www.remalosangeles.com/xmlrpc.php
  410. [234] http://www.secretgeometry.com/xmlrpc.php%3Frsd
  411. [235] http://www.scottporad.com/xmlrpc.php%3Frsd
  412. [236] http://renewhealthandwellness.com/xmlrpc.php
  413. [237] http://www.xmarks.com/site/ping.syndic8.com/xmlrpc.php
  414. [238] http://bootcamptulsa.com/xmlrpc.php%3Frsd
  415. [239] http://jessefrohman.com/xmlrpc.php%3Frsd
  416. [240] http://mytastythai.com/xmlrpc.php
  417. [241] http://notredameduchene.com/xmlrpc.php%3Frsd
  418. [242] http://www.cafelunavashon.com/xmlrpc.php%3Frsd
  419. [243] http://love4acure.com/xmlrpc.php%3Frsd
  420. [244] http://isostick.com/xmlrpc.php%3Frsd
  421. [245] http://naturalreflectionshealthcare.com/xmlrpc.php%3Frsd
  422. [246] http://www.moustacheusa.com/xmlrpc.php%3Frsd
  423. [247] http://contentsmagazine.com/xmlrpc.php%3Frsd
  424. [248] http://www.walmartlabs.com/xmlrpc.php%3Frsd
  425. [249] http://refaurences.wordpress.com/xmlrpc.php%3Frsd
  426. [250] http://theeggbistro.com/xmlrpc.php
  427. [251] http://acquirethefire.com/xmlrpc.php%3Frsd
  428. [252] http://millercoach.com/xmlrpc.php%3Frsd
  429. [253] http://najemnews.com/xmlrpc.php%3Frsd
  430. [254] http://mabra.com/xmlrpc.php%3Frsd
  431. [255] http://cateringbyscott.com/xmlrpc.php%3Frsd
  432. [256] http://www.monitorproducts.com/xmlrpc.php%3Frsd
  433. [257] http://www.rippedtogether.com/xmlrpc.php%3Frsd
  434. [258] http://farrahgray.com/xmlrpc.php%3Frsd
  435. [259] http://www.youngstownsymphony.com/xmlrpc.php%3Frsd
  436. [260] http://www.dedicatedmedia.com/xmlrpc.php%3Frsd
  437. [261] http://bonanzasteakhouses.com/xmlrpc.php%3Frsd
  438. [262] http://www.overviewthemovie.com/xmlrpc.php%3Frsd
  439. [263] http://www.cobaltproject.com/xmlrpc.php%3Frsd
  440. [264] http://www.mgcaledonian.com/xmlrpc.php%3Frsd
  441. [265] http://healocapital.com/xmlrpc.php
  442. [266] http://www.brandnetworksinc.com/xmlrpc.php%3Frsd
  443. [267] http://realdlhughley.com/xmlrpc.php%3Frsd
  444. [268] http://svcyclesport.com/xmlrpc.php%3Frsd
  445. [269] http://joselynquintero.com/xmlrpc.php%3Frsd
  446. [270] http://millstreamfab.com/xmlrpc.php
  447. [271] http://hatteland.com/xmlrpc.php%3Frsd
  448. [272] http://corynorrisart.com/xmlrpc.php
  449. [273] http://wordpress.com/xmlrpc.php%3Frsd
  450. [274] http://www.callstream.com/xmlrpc.php%3Frsd
  451. [275] http://geisthalf.com/xmlrpc.php%3Frsd
  452. [276] http://www.thesenewpuritans.com/xmlrpc.php%3Frsd
  453. [277] http://programming.oreilly.com/xmlrpc.php%3Frsd
  454. [278] http://www.luckydogtampa.com/xmlrpc.php%3Frsd
  455. [279] http://www.sitc-group.com/xmlrpc.php%3Frsd
  456. [280] http://cognitivetherapysi.com/xmlrpc.php
  457. [281] http://www.alldesignstuffs.com/xmlrpc.php
  458. [282] http://www.somosdavivienda.com/xmlrpc.php
  459. [283] http://www.valleycartage.com/xmlrpc.php%3Frsd
  460. [284] http://www.thebeanofavemaria.com/xmlrpc.php
  461. [285] http://www.grossyowell.com/xmlrpc.php%3Frsd
  462. [286] http://www.intothemangrove.com/xmlrpc.php%3Frsd
  463. [287] http://360llc.com/xmlrpc.php%3Frsd
  464. [288] http://www.zoeleela.com/xmlrpc.php%3Frsd
  465. [289] http://zodop.com/xmlrpc.php%3Frsd
  466. [290] http://www.lagrotteduyeti.com/xmlrpc.php%3Frsd
  467. [291] http://www.anitarenfroe.com/xmlrpc.php%3Frsd
  468. [292] http://www.licht-raum-klang.com/xmlrpc.php%3Frsd
  469. [293] http://www.solren.com/xmlrpc.php%3Frsd
  470. [294] http://evetravel.wordpress.com/xmlrpc.php%3Frsd
  471. [295] http://zipxworld.com/xmlrpc.php%3Frsd
  472. [296] http://mrpmproductions.com/xmlrpc.php
  473. [297] http://www.aluminiosmoscatel.com/xmlrpc.php
  474. [298] http://hairmetaltimemachine.com/xmlrpc.php
  475. [299] http://davidcerezophotography.com/xmlrpc.php
  476. [300] http://www.nextcontrols.com/xmlrpc.php%3Frsd
  477. [301] http://westendbathandkitchen.com/xmlrpc.php%3Frsd
  478. [302] http://www.potsc.com/xmlrpc.php%3Frsd
  479. [303] http://ibntt.com/xmlrpc.php
  480. [304] http://sleeplessinarizona.com/xmlrpc.php
  481. [305] http://www.davidottaproductions.com/xmlrpc.php%3Frsd
  482. [306] http://www.axege.com/xmlrpc.php%3Frsd
  483. [307] http://www.aashirwadapartments.com/xmlrpc.php%3Frsd
  484. [308] http://www.vidyard.com/xmlrpc.php%3Frsd
  485. [309] http://www.magiaentucentro.com/xmlrpc.php
  486. [310] http://heiditunnellcatering.com/xmlrpc.php%3Frsd
  487. [311] http://archive.news.mn/archive.shtml%3Fq%3Dwww.bonus.skytel.com/xmlrpc.php
  488. [312] http://www.gopdfs.com/xmlrpc.php--index.php-mysql
  489. [313] http://www.vivreavechooponopono.com/xmlrpc.php%3Frsd
  490. [314] http://www.smartcows.com/xmlrpc.php%3Frsd
  491. [315] http://www.theteapartyleadershipfund.com/xmlrpc.php%3Frsd
  492. [316] http://www.discountcenterweb.com/xmlrpc.php%3Frsd
  493. [317] http://www.scenicboattours.com/xmlrpc.php%3Frsd
  494. [318] http://ghiniscafe.com/xmlrpc.php%3Frsd
  495. [319] http://www.bgtpartners.com/xmlrpc.php%3Frsd
  496. [320] http://libertystormradio.com/xmlrpc.php%3Frsd
  497. [321] http://www.caudwell.com/xmlrpc.php%3Frsd
  498. [322] http://www.partexchangewarehouse.com/xmlrpc.php
  499. [323] http://www.citynewsmumbai.com/xmlrpc.php%3Frsd
  500. [324] http://fr.competitor.com/xmlrpc.php%3Frsd
  501. [325] http://lostvalleyoflondon.com/xmlrpc.php%3Frsd
  502. [326] http://www.fehrwaytours.com/xmlrpc.php%3Frsd
  503. [327] http://bryantdentalcare.com/xmlrpc.php
  504. [328] http://www.littlehotelier.com/xmlrpc.php%3Frsd
  505. [329] http://www.faubourg-immobilier.com/xmlrpc.php%3Frsd
  506. [330] http://reaktorwarsaw.com/xmlrpc.php%3Frsd
  507. [331] http://smacgym.com/xmlrpc.php
  508. [332] http://api.jquery.com/xmlrpc.php%3Frsd
  509. [333] http://www.purnellbodyshop.com/xmlrpc.php%3Frsd
  510. [334] http://230newton.com/xmlrpc.php%3Frsd
  511. [335] http://www.mujerglobal.com/xmlrpc.php%3Frsd
  512. [336] http://www.wightmaterialshandling.com/xmlrpc.php%3Frsd
  513. [337] http://www.andreimaxwel.com/xmlrpc.php%3Frsd
  514. [*] Found 0 in 36.221966
  515. -----------------------
  516. #MalwareMustDie!
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement