
ext:php program_listing intitle:MythWeb.Program.Listing

inurl:preferences.ini “[emule]”

intitle:”Index of /CFIDE/” administrator

“access denied for user” “using password”

ext:php intext:”Powered by phpNewMan Version” 可以看到:path/to/news/browse.php?clang=../../../../../../file/i/want


intitle:”ASP FileMan” Resend

“Enter ip” inurl:”php-ping.php”

ext:conf inurl:rsyncd.conf -cvs -man

intitle: private, protected, secret, secure, winnt

intitle:”DocuShare” inurl:”docushare/dsweb/” -faq -gov -edu
“#mysql dump” filetype:sql

“allow_call_time_pass_reference” “PATH_INFO”

“Certificate Practice Statement” inurl:(PDF | DOC)

LeapFTP intitle:”index.of./” sites.ini modified

mysql history files
NickServ registration passwords
passlist.txt (a better way)
passwd / etc (reliable)
psyBNC config files
signin filetype:url
spwd.db / passwd
wwwboard WebAdmin inurl:passwd.txt wwwboard|webadmin

“# -FrontPage-” ext:pwd inurl:(service | authors | administrators | users) “# -FrontPage-”

“AutoCreate=TRUE password=*”
“http://*:*@www” domainname
“index of/” “ws_ftp.ini” “parent directory”
“liveice configuration file” ext:cfg
“powered by ducalendar”
“Powered by Duclassified”
“Powered by Duclassified” “DUware All Rights reserved”
“powered by duclassmate”
“Powered by Dudirectory”
“powered by dudownload”
“Powered By Elite Forum Version *.*”
“Powered by Link Department”
“sets mode: +k”
“Powered by DUpaypal”
allinurl: admin mdb
eggdrop filetype:user user
etc (index.of)
ext:ini eudora.ini
ext:ini Version=… password
ext:txt inurl:unattend.txt

filetype:bak inurl:”htaccess|passwd|shadow|htusers”

filetype:cfg mrtg “target[*]” -sample -cvs -example

filetype:cfm “cfapplication name” password

filetype:conf oekakibbs
filetype:conf sc_serv.conf

filetype:conf slapd.conf

filetype:config config intext:appSettings “User ID”

filetype:dat “password.dat”

filetype:dat wand.dat

filetype:inc dbconn

filetype:inc intext:mysql_connect
filetype:inc mysql_connect OR mysql_pconnect

filetype:inf sysprep

filetype:ini inurl:”serv-u.ini”
filetype:ini inurl:flashFXP.ini
filetype:ini ServUDaemon
filetype:ini wcx_ftp
filetype:ini ws_ftp pwd

filetype:ldb admin

filetype:log “See `ipsec copyright”

filetype:log inurl:”password.log”

filetype:mdb inurl:users.mdb

filetype:mdb wwforum

filetype:netrc password

filetype:pass pass intext:userid

filetype:pem intext:private

filetype:properties inurl:db intext:password

filetype:pwd service
filetype:pwl pwl

filetype:reg reg +intext:”defaultusername” +intext:”defaultpassword”
filetype:sql (“values * MD” | “values * password” | “values * encrypt”)
filetype:sql (“passwd values” | “password values” | “pass values” )
filetype:sql +”IDENTIFIED BY” -cvs
filetype:sql password

filetype:url +inurl:”ftp://” +inurl:”;@”

filetype:xls username password email

htpasswd / htgroup
htpasswd / htpasswd.bak

intext:”enable secret $”
intext:”powered by Web Wiz Journal”

intitle:”index of”
intitle:”index of”
intitle:”Index of” passwords modified

intitle:dupics inurl:(add.asp | default.asp | view.asp | voting.asp)

intitle:index.of intext:”secring.skr”|”secring.pgp”|”secring.bak”

inurl:”GRC.DAT” intext:”password”

inurl:”slapd.conf” intext:”credentials” -manpage -”Manual Page” -man: -sample

inurl:”slapd.conf” intext:”rootpw” -manpage -”Manual Page” -man: -sample

inurl:”wvdial.conf” intext:”password”


inurl:chap-secrets -cvs

inurl:config.php dbuname dbpass
inurl:filezilla.xml -cvs

inurl:lilo.conf filetype:conf password -tatercounter -bootpwd -man

inurl:nuke filetype:sql

inurl:ospfd.conf intext:password -sample -test -tutorial -download 路由配置
inurl:pap-secrets -cvs

inurl:perform filetype:ini
inurl:secring ext:skr | ext:pgp | ext:bak

inurl:vtund.conf intext:pass -cvs

inurl:zebra.conf intext:password -sample -test -tutorial -download

“Generated by phpSystem”
“generated by wwwstat”

“Host Vulnerability Summary Report” ]

“HTTP_FROM=googlebot” “Server_Software=”

“Index of” / “chat/logs” 聊天室
“Installed Objects Scanner” inurl:default.asp

“Mecury Version” “Infastructure Group”
“Microsoft (R) Windows * ™ Version * DrWtsn Copyright (C)” ext:log

“Most Submitted Forms and Scripts” “this section”

“Network Vulnerability Assessment Report”

“not for distribution” confidential
“phone * * *” “address *” “e-mail” intitle:”curriculum vitae”

“phpMyAdmin” “running on” inurl:”main.php”

“produced by getstats”
“Request Details” “Control Tree” “Server Variables”
“robots.txt” “Disallow:” filetype:txt

“Running in Child mode”

“sets mode: +p”
“sets mode: +s”
“Thank you for your order” +receipt
“This is a Shareaza Node”
“This report was generated by WebLog”
( filetype:mail | filetype:eml | filetype:mbox | filetype:mbx ) intext:password|subject

(inurl:”robot.txt” | inurl:”robots.txt” ) intext:disallow filetype:txt -”The PHP Group” inurl:source inurl:url ext:pHp

AIM buddy lists

data filetype:mdb -site:gov -site:mil

exported email addresses

ext:asp inurl:pathto.asp

ext:cgi inurl:editcgi.cgi inurl:file=

ext:conf inurl:rsyncd.conf -cvs -man
ext:conf NoCatAuth -cvs

ext:dat bpk.dat
ext:gho gho

ext:ini intext:env.ini
ext:ldif ldif

ext:log “Software: Microsoft Internet Information Services *.*”
ext:mdb inurl:*.mdb inurl:fpdb shop.mdb

filetype:bkf bkf
filetype:blt “buddylist”
filetype:blt blt +intext:screenname

filetype:cfg auto_inst.cfg

filetype:conf inurl:firewall -intitle:cvs
filetype:config web.config -CVS

filetype:ctt ctt messenger

filetype:fp fp
filetype:fp fp -site:gov -site:mil -”cvs log”

filetype:inf inurl:capolicy.inf
filetype:lic lic intext:key

filetype:myd myd -CVS
filetype:ns ns
filetype:ora ora
filetype:ora tnsnames
filetype:pdb pdb backup (Pilot | Pluckerdb)

filetype:pot inurl:john.pot
filetype:pst inurl:”outlook.pst”
filetype:pst pst -from -to -date
filetype:qbb qbb
filetype:rdp rdp

filetype:reg “Terminal Server Client”
filetype:vcs vcs
filetype:wab wab

filetype:xls -site:gov inurl:contact
filetype:xls inurl:”email.xls”
Financial spreadsheets: finance.xls
Financial spreadsheets: finances.xls

Ganglia Cluster Reports

haccess.ctl (one way)
haccess.ctl (VERY reliable)
ICQ chat logs, please…

iletype:log cron.log
intext:”Session Start * * * *:*:* *” filetype:log
intext:”Tobias Oetiker” “traffic analysis”

intext:(password | passcode) intext:(username | userid | user) filetype:csv
intext:gmail invite intext:

intext:SQLiteManager inurl:main.php

intitle:”Apache::Status” (inurl:server-status | inurl:status.html | inurl:apache.html)

intitle:”AppServ Open Project”
intitle:”ASP Stats Generator *.*” “ASP Stats Generator” “- weppos”

intitle:”FTP root at”
intitle:”index of” +myd size

intitle:”Index Of” -inurl:maillog maillog size

intitle:”Index Of” cookies.txt size

intitle:”index of” mysql.conf OR mysql_config
intitle:”Index of” upload size parent directory

intitle:”index.of” .diz .nfo last modified
intitle:”Multimon UPS status page”
intitle:”PHP Advanced Transfer” (inurl:index.php | inurl:showrecent.php )
intitle:”PhpMyExplorer” inurl:”index.php” -cvs
intitle:”statistics of” “advanced web statistics”
intitle:”System Statistics” +”System and Network Information Center”
intitle:”Usage Statistics for” “Generated by Webalizer”
intitle:”wbem” compaq login “Compaq Information Technologies Group”

intitle:”Web Server Statistics for ****”
intitle:”web server status” SSH Telnet

intitle:admin intitle:login
intitle:index.of “Apache” “server at”
intitle:index.of cleanup.log
intitle:index.of dead.letter
intitle:index.of inbox
intitle:index.of inbox dbx

intitle:intranet inurl:intranet +intext:”phone”
inurl:”/axs/” -script

inurl:”cacti” +inurl:”graph_view.php” +”Settings Tree View” -cvs -RPM
inurl:”newsletter/admin/” intitle:”newsletter admin”
inurl:”smb.conf” intext:”workgroup” filetype:conf conf

Welcome to ntop!

“adding new user” inurl:addnewuser -”there are no domains”
(inurl:/cgi-bin/.cobalt/) | (intext:”Welcome to the Cobalt RaQ”)

filetype:php HAXPLORER “Server Files Browser”
intitle:”Web Data Administrator – Login”

inurl:ConnectComputer/precheck.htm | inurl:Remote/logon.aspx
PHP Shell (unprotected)
PHPKonsole PHPShell filetype:php -echo
Public PHP FileManagers

“index of” / picasa.ini
“index of” inurl:recycler
“Index of” rar r nfo Modified
“intitle:Index.Of /” stats merchant cgi-* etc
“Powered by Invision Power File Manager” (inurl:login.php) | (intitle:”Browsing directory /” )
“Web File Browser” “Use regular expression”

filetype:ini Desktop.ini intext:mydocs.dll

intext:”d.aspx?id” || inurl:”d.aspx?id”
intext:”Powered By: TotalIndex” intitle:”TotalIndex”
intitle:”album permissions” “Users who can modify photos” “EVERYBODY”
intitle:”Directory Listing For” intext:Tomcat -intitle:Tomcat
intitle:”HFS /” +”HttpFileServer”
intitle:”Index of *” inurl:”my shared folder” size modified

“File Upload Manager v.” “rename to”

ext:asp “powered by DUForum” inurl:(messages|details|login|default|register)
ext:asp inurl:DUgallery intitle:”.”
ext:cgi inurl:ubb_test

ezBOO “Administrator Panel” -cvs

filetype:cgi inurl:cachemgr.cgi
filetype:cnf my.cnf -cvs -example
filetype:inc inc intext:setcookie

filetype:php inurl:”viewfile” -”index.php” -”idfil
filetype:wsdl wsdl

intitle:”ASP FileMan” Resend

intitle:”Index of /” modified php.exe

intitle:”phpremoteview” filetype:php “Name, Size, Type, Modify”

inurl:” WWWADMIN.PL” intitle:”wwwadmin”
inurl:”nph-proxy.cgi” “Start browsing through this CGI-based proxy”

inurl:robpoll.cgi filetype:cgi

The Master List

“More Info about MetaCart Free”

posted @ 2013-09-06 00:23  heikeboy’s Blog  阅读(2320)  评论(0编辑  收藏  举报