Hackers Favourite Keywords : Using Google
"Index of /admin" "Index of /password" "Index of /mail" "Index of /" +passwd "Index of /" +password.txt "Index of /" +.htaccess index of ftp +.mdb allinurl:/cgi-bin/ +mailto
administrators.pwd.index authors.pwd.index service.pwd.index filetype:config web gobal.asax index
allintitle: "index of/admin" allintitle: "index of/root" allintitle: sensitive filetype:doc allintitle: restricted filetype :mail allintitle: restricted filetype:doc site:gov
inurlasswd filetype:txt inurl:admin filetype:db inurl:iisadmin inurl:"auth_user_file.txt" inurl:"wwwroot/*."
top secret site:mil confidential site:mil
allinurl: winnt/system32/ (get cmd.exe) allinurl:/bash_history
intitle:"Index of" .sh_history intitle:"Index of" .bash_history intitle:"index of" passwd intitle:"index of" people.lst intitle:"index of" pwd.db intitle:"index of" etc/shadow intitle:"index of" spwd intitle:"index of" master.passwd intitle:"index of" htpasswd intitle:"index of" members OR accounts intitle:"index of" user_carts OR user_cart | |
ㅤNikhilesh♂ (manage) | May 22 (3 days ago) ALTERNATIVE INPUTS====================
_vti_inf.html service.pwd users.pwd authors.pwd administrators.pwd shtml.dll shtml.exe fpcount.exe default.asp showcode.asp sendmail.cfm getFile.cfm imagemap.exe test.bat msadcs.dll htimage.exe counter.exe browser.inc hello.bat default.asp\ dvwssr.dll cart32.exe add.exe index.jsp SessionServlet shtml.dll index.cfm page.cfm shtml.exe web_store.cgi shop.cgi upload.asp default.asp pbserver.dll phf test-cgi finger Count.cgi jj php.cgi php nph-test-cgi handler webdist.cgi webgais websendmail faxsurvey htmlscript perl.exe wwwboard.pl www-sql view-source campas aglimpse glimpse man.sh AT-admin.cgi AT-generate.cgi filemail.pl maillist.pl info2www files.pl bnbform.cgi survey.cgi classifieds.cgi wrap cgiwrap edit.pl | |
ㅤNikhilesh♂ (manage) | May 22 (3 days ago) perl names.nsf webgais dumpenv.pl test.cgi submit.cgi guestbook.cgi guestbook.pl cachemgr.cgi responder.cgi perlshop.cgi query w3-msql plusmail htsearch infosrch.cgi publisher ultraboard.cgi db.cgi formmail.cgi allmanage.pl ssi adpassword.txt redirect.cgi cvsweb.cgi login.jsp dbconnect.inc admin htgrep wais.pl amadmin.pl subscribe.pl news.cgi auctionweaver.pl .htpasswd acid_main.php access.log log.htm log.html log.txt logfile logfile.htm logfile.html logfile.txt logger.html stat.htm stats.htm stats.html stats.txt webaccess.htm wwwstats.html source.asp perl mailto.cgi YaBB.pl mailform.pl cached_feed.cgi global.cgi Search.pl build.cgi common.php show global.inc ad.cgi WSFTP.LOG index.html~ index.php~ index.html.bak index.php.bak print.cgi register.cgi webdriver bbs_forum.cgi mysql.class sendmail.inc CrazyWWWBoard.cgi search.pl way-board.cgi webpage.cgi pwd.dat adcycle post-query help.cgi | |
ㅤNikhilesh♂ (manage) | May 22 (3 days ago) /robots.txt /admin.mdb /shopping.mdb /arg; /stats/styles.css /statshelp.htm /favicon.ico /stats/admin.mdb /shopdbtest.asp /cgi-bin/test.cgi /cgi-bin/test.pl /cgi-bin/env.cgi /photos/protest/styles.css http://hpcgi1.nifty.com/trino/ProxyJ/prxjdg.cgi /cgi-bin/whereami.cgi /shopping400.mdb /cgi/test.cgi /cgi-bin/test2.pl /photos/protest/kingmarch_02.html /chevy/index.htm /cgi-bin/glocation.cgi /cgi-bin/test2.cgi /ccbill/glocation.cgi /cgi-bin/styles.css /shopping350.mdb /cgi-bin/shopper.cgi /shopadmin.asp /news_2003-02-27.htm /cgi-bin/whois.cgi | |
ㅤNikhilesh♂ (manage) | May 22 (3 days ago) 3 /cgi-bin/calendar.pl 3 /cgi-bin/calendar/calendar.pl 3 /cgibin/styles.css 3 /venem.htm 2 /stats/www.newbauersflowers.com/stats/04-refers.htm 2 /cgi-bin/where.pl 2 /cgibin/shopper.cgi&TEMPLATE=ORDER.LOG 2 /cgibin/recon.cgi 2 /cgibin/test.cgi 2 /WebShop/templates/styles.css 2 /stats/shopping350.mdb 2 /cgi-bin/mailform.cgi 2 /cgi-bin/recon.cgi 2 /chevy 2 /cgi-bin/servinfo.cgi 2 /acart2_0.mdb 2 /cgi-bin/where.cgi 2 /chevy/ 2 /stats/www.savethemall.net/stats/19-refers.htm 2 /ccbill/secure/ccbill.log 2 /cgi/recon.cgi 2 /stats/www.gregoryflynn.com/chevy 2 /ibill/glocation.cgi 2 /ccbill/whereami.cgi 2 /ibill/whereami.cgi 2 /apps_trial.htm 2 /cgi-bin/lancelot/recon.cgi 2 /cgi-bin/DCShop/Orders/styles.css 1 /cgi-bin/htmanage.cgi 1 /stats/www.tysons.net/stats/05-refers.htm 1 /cgi-bin/mastergate/add.cgi 1 /cgi-bin/openjournal.cgi 1 /cgi-bin/calendar/calendar_admin.pl 1 /cgibin/ibill/count.cgi 1 /cgi-bin/nbmember2.cgi 1 /cgi-bin/mastergate/count.cgi 1 /cgi-bin/mastergate/accountcreate.cgi 1 /cgi-bin/ibill/accountcreate.cgi 1 /cgibin/MasterGate2/count.cgi 1 /cgi-bin/amadmin.pl 1 /cgibin/mailform.cgi 1 /cgibin/mastergate/count.cgi 1 /cgibin/harvestor.cgi 1 /cgibin/igate/count.cgi 1 /WebShop 1 /shopdisplaycategories.asp 1 /cgi-bin/DCShop/Orders/orders.txt 1 /cgi-bill/revshare/joinpage.cgi 1 /stats/www.gregoryflynn.com/stats/19-refers.htm 1 /cgi-local/DCShop/auth_data/styles.css 1 /cgi-bin/add-passwd.cgi 1 /cgi-bin/MasterGate/count.cgi 1 /apps_shop.htm%20/comersus/database/comersus.mdb 1 /data/verotellog.txt 1 /epwd/ws_ftp.log 1 /stats/www.dialacure.com/stats/16-refers.htm 1 /cgi/MasterGate2/count.cgi 1 /jump/rsn.tmus/skybox;sz=140x150;segment=all;resor=jackson;state= WY;sect=home;tile=8;ord=57019 | |
ㅤNikhilesh♂ (manage) | May 22 (3 days ago) store/log_files/your_order.log /cg i-bin/DCShop/Orders/orders.txt /vpasp/shopdbtest.asp /orders/checks.txt /WebShop/logs /ccbill/secure/ccbill.log /scripts/cart32.exe / cvv2.txt /cart/shopdbtest.asp /cgi-win/cart.pl /shopdbtest.asp /WebShop/logs/cc.txt /cgi-local/cart.pl /PDG_Cart/order.log /config/---.mdb /cgi-bin/ezmall2000/mall2000.cgi?page=../mall_log_files/order.log%00html /or ders/orders.txt /cgis/cart.pl /webcart/carts /cgi-bin/cart32.exe/cart32clientlist /cgi/cart.pl /comersus/database/comersus.mdb /WebShop/temp lates/cc.txt /Admin_files/order.log /orders/mountain.cfg /cgi-sys/cart.pl /scripts/cart.pl /htbin/cart.pl /productcart/database/EIPC.mdb /shoponline/fpdb/shop.mdb /config/datasources/myorder.mdb /PDG_Cart/shopper.conf /shopping/database/metacart.mdb /bin/cart.pl /cgi-bin/cart32.ini /database/comersus.mdb /cgi-local/medstore/loadpage.cgi?user_id= id&file=data/orders.txt /cgi-bin/store/Admin_files/myorderlog.txt /cgi-bin/orders.txt /cgi-bin/store/Admin_files/your_order.log /test/test.txt /fpdb/shop.mdb /cgibin/shop/orders/orders.txt /shopadmin1.asp /cgi-bin/shop.cgi /cgi-bin/commercesql/index.cgi?page=../admin/manager.cgi /cgi-bin/PDG_cart/card.txt /shopper.cgi?preadd=action&key=PROFA&template=order1.log /store/shopdbtest.asp /log_files/yo ur_order.log /_database/expire.mdb /HyperStat/stat_what.log /cgi bin/DCShop/auth_data/auth_user_file.txt | |
ㅤNikhilesh♂ (manage) | May 22 (3 days ago) /htbin/orders/orders.txt /SHOP/shopadmin.asp /index.cgi?page=../admin/files/order.log /vpshop/shopadmin.asp /webcart/config /PDG/order.txt
/cgi-bin/store/Log_files/your_order.log /cgi-bin /%20shopper.cgi?preadd=action&key=PROFA&template=shopping400.mdb /comersus_message.asp? /orders/import.txt /htbin/DCShop/auth_data/auth_user_file.txt /admin /html_lib.pl /cgi-bin/%20shopper.cgi?preadd=action&key=PROFA&template=myorder.txt /cgi-bin/DCShop/auth_data/auth_user_file.txt /cgi-bin /shop.pl/page=;cat%20shop.pl /cgi-bin/shopper?search=action&keywords=dhenzuser%20&template=order.log /HBill/htpasswd /bin/shop/auth_data/auth_user_file.txt /cgi-bin /cs/shopdbtest.asp /mysql/shopping.mdb /Catalog/config/datasources/Products.mdb /trafficlog /cgi/orders/orders.txt /cgi-local/PDG_Cart/shopper.conf /store/cgi-bin/---.mdb /derbyteccgi/shopper.cgi?key=SC7021&preadd=action&template=order.log /derbyteccgi/shopper.cgi?search=action&keywords=moron&template=order.log /cgi-bin/mc.txt /cgi-bin/mall2000.cgi /cgi-win /DCShop/auth_data/auth_user_file.txt /cgi-bin/shopper.cgi?search=action&keywords=root%20&template=order.log /store/commerce.cgi /scripts/ shop/orders/orders.txt /product/shopping350.mdb /super_stats/access_logs /cgi-local/orders/orders.txt / cgi-bin/PDG_Cart/mc.txt /cgibin/cart32.exe /cgi-bin/Shopper.exe?search=action&keywords=psiber%20&template=other/risinglogorder.log /cgibin/password.txt /Catalog/cart/carttrial.dat /catalog/Admin /Admin.asp /ecommerce/admin/user/admin.asp /data/productcart/database/EIPC.mdb /store/admin_files/commerce_user_lib.pl /cgi-bin/store/index.cgi /paynet.txt /config/datasources/store/billing.mdb /_database/shopping350.mdb /cgi-bin/shopper.exe?search /cgi/shop.pl/page=;cat%20shop.pl /cgi-bin /store/Admin_files/orders.txt /cgi-bin/store/commerce_user_lib.pl /cgi-sys/pagelog.cgi /cgi-sys/shop.pl/ page=;cat%20shop.pl /scripts/weblog /fpdb/shopping400.mdb /htbin/shop/orders/orders.txt /cgi-bin/%20shopper.cgi? | |
ㅤNikhilesh♂ (manage) | May 22 (3 days ago) 1. How do you use this?
You type it in google search. One by one should work, but I guess you can OR them as well.
2. How does it work?
Google crawls from link to link trying to map the internet and make it available for searching. The above search criteria find files that are important to a system but should NOT be publicly available and are part of the installation of some programs, or password files for machines. Since they ARE available (google did map them and you did find them, after all) this means the person has mis-configured something. -sharing entire C: drive (possibly giving you write privilige, but at the very least sharing all his files) -bad FTP/HTTP, etc server install -unprotected CGI/PHP, etc directory The above is awesome if you have write (upload) priviliges since you can put a script that does virtually anything, provided you have minimum programming experience (hell, with a day of reading you can do plenty). If you can't upload your own script it gets a bit more difficult, you can search through the available ones for bad coding using unprotected $_GET (in PHP, but other scripting languages work similar) and pass commands from the address bar that in the best case would be executed on the machine. well, not all of those will yield results that are necessarily hacked or hackable machines, but you will find plenty. Be warned that this list does have a few (harmless) mistakes, for example: /robots.txt is a file that is meant to be publicly available and is there precisely to be found by search engines. Finding that file only means the owner of the machine likely knows what he's doing. | |
Orkut Leave (manage) | May 22 (3 days ago) dsfdsfsdf | |
ㅤNikhilesh♂ (manage) | May 22 (3 days ago) /\ ? | |
No comments:
Post a Comment