Google Hacking Database 3

Vulnerable Servers

These searches reveal servers with specific vulnerabilities. These are found in a different way than the searches found in the "Vulnerable Files" section.

inurl:/vb/install/upgrade.php
inurl:/vb/install/install.php
"CGI-Telnet Unit-x Team Connected to *.com" OR "CGI-Telnet Unit-x Team Connected to"
"www.*.com - c99shell" OR "www.*.net - c99shell" OR "www.*.org - c99shell"
"safe_mode: * PHP version: * cURL: * MySQL: * MSSQL: * PostgreSQL: * Oracle: *"
"r57shell"
"r57shell 1.4"
"[ phpinfo ] [ php.ini ] [ cpu ] [ mem ] [ users ] [ tmp ] [ delete ]"
inurl:index.php?pagedb=rss -Vulnerability -inurl
intitle:"Uploader - Uploader v6" -pixloads.com
intitle:"MvBlog powered"
intitle:"Horde :: My Portal" -"[Tickets"
inurl:rpSys.html
filetype:pl intitle:"Ultraboard Setup"
"Welcome to Administration" "General" "Local Domains" "SMTP Authentication" inurl:admin
XOOPS Custom Installation
"you can now password" | "this is a special page only seen by you. your profile visitors"
"set up the administrator user" inurl:pivot
"html allowed" guestbook
"Powered by: vBulletin Version 1.1.5"
inurl:"/NSearch/AdminServlet"
inurl:servlet/webacc
"There are no Administrators Accounts" inurl:admin.php -mysql_fetch_row
intitle:"Mail Server CMailServer Webmail" "5.2"
inurl:newsdesk.cgi? inurl:"t="
(inurl:/shop.cgi/page=) | (inurl:/shop.pl/page=)
inurl:aol*/_do/rss_popup?blogID=
natterchat inurl:home.asp -site:natterchat.co.uk
intitle:phpMyAdmin "Welcome to phpMyAdmin ***" "running on * as root@*"
"ftp://" "www.eastgame.net"
intext:"Warning: * am able * write ** configuration file" "includes/configure.php" -Forums
allinurl:"index.php" "site=sglinks"
inurl:"index.php? module=ew_filemanager"
filetype:cgi inurl:"fileman.cgi"
filetype:cgi inurl:"Web_Store.cgi"
("Indexed.By"|"Monitored.By") hAcxFtpScan
"Welcome to the Prestige Web-Based Configurator"
filetype:php inurl:vAuthenticate
intitle:"Samba Web Administration Tool" intext:"Help Workgroup"
intitle:"Gateway Configuration Menu"
inurl:pls/admin_/gateway.htm
allinurl:install/install.php
allinurl:intranet admin
"Select a database to view" intitle:"filemaker pro"
"Welcome to PHP-Nuke" congratulations
inurl:info.inc.php
inurl:footer.inc.php
inurl:search.php vbulletin
"Welcome to Intranet"
intitle:"Remote Desktop Web Connection"
inurl:ManyServers.htm
Gallery in configuration mode
"YaBB SE Dev Team"
Hassan Consulting's Shopping Cart Version 1.18
am image

Error Messages

Error messages that say WAY too much!

"plugins/wp-db-backup/wp-db-backup.php"
allintext:"fs-admin.php"
intitle:"Apache Tomcat" "Error Report"
"Unable to jump to row" "on MySQL result index" "on line"
"Warning: Bad arguments to (join|implode) () in" "on line" -help -forum
"Warning:" "failed to open stream: HTTP request failed" "on line"
"Warning: mysql_connect(): Access denied for user: '*@*" "on line" -help -forum
"Warning: Division by zero in" "on line" -forum
filetype:asp + "[ODBC SQL"
"Warning: Supplied argument is not a valid File-Handle resource in"
intitle:"Default PLESK Page"
"Parse error: parse error, unexpected T_VARIABLE" "on line" filetype:php
"[SQL Server Driver][SQL Server]Line 1: Incorrect syntax near" -forum -thread -showthread
intitle:Configuration.File inurl:softcart.exe
"The script whose uid is " "is not allowed to access"
snitz! forums db path error
filetype:log "PHP Parse error" | "PHP Warning" | "PHP Error"
"ASP.NET_SessionId" "data source="
"ORA-12541: TNS:no listener" intitle:"error occurred"
filetype:php inurl:"logging.php" "Discuz" error
"Internal Server Error" "server at"
PHP application warnings failing "include_path"
intext:"Warning: Failed opening" "on line" "include_path"
ht://Dig htsearch error
intitle:"Error Occurred While Processing Request"
intitle:"Error using Hypernews" "Server Software"
"Invision Power Board Database Error"
"error found handling the request" cocoon filetype:xml
intitle:"Execution of this script not permitted"
intitle:"Error Occurred" "The error occurred in" filetype:cfm
warning "error on line" php sablotron
"Fatal error: Call to undefined function" -reply -the -next
filetype:asp "Custom Error Message" Category Source
"Can't connect to local" intitle:warning
intitle:"Under construction" "does not currently have"
"access denied for user" "using password"
"Warning: Cannot modify header information - headers already sent"
"Warning: pg_connect(): Unable to connect to PostgreSQL server: FATAL"
An unexpected token "END-OF-STATEMENT" was found
"detected an internal error [IBM][CLI Driver][DB2/6000]"
"A syntax error has occurred" filetype:ihtml

Anda mungkin menyukai postingan ini