Monday, September 13, 2004

Use search engines for hacking ..

Add to Delicious Digg this links to this post -

Just bought "Hacking exposed" (Stuart McClure, Joel Scambray & Grorge Kurtz).

Try the following queries in your search engine, you will have some surprises!

"index of/root"
inurl:"auth_user_file.txt"
"Index of /admin"
"Index of /password"
"Index of /mail"
"Index of /" +passwd
"Index of /" +password.txt
"Index of /" +.htaccess
index of ftp +.mdb allinurl:/cgi-bin/ +mailto

administrators.pwd.index
authors.pwd.index
service.pwd.index
filetype:config web
gobal.asax index

allintitle: "index of/admin"
allintitle: "index of/root"
allintitle: sensitive filetype:doc
allintitle: restricted filetype :mail
allintitle: restricted filetype:doc site:gov

inurl:passwd filetype:txt
inurl:admin filetype:db
inurl:iisadmin
inurl:"auth_user_file.txt"
inurl:"wwwroot/*."

top secret site:mil
confidential site:mil

allinurl: winnt/system32/ (get cmd.exe)
allinurl:/bash_history

intitle:"Index of" .sh_history
intitle:"Index of" .bash_history
intitle:"index of" passwd
intitle:"index of" people.lst
intitle:"index of" pwd.db
intitle:"index of" etc/shadow
intitle:"index of" spwd
intitle:"index of" master.passwd
intitle:"index of" htpasswd
intitle:"index of" members OR accounts
intitle:"index of" user_carts OR user_cart

The game is open, and your suggestions welcome!
Try this one ;-) :
'input="hidden" name="price"'

You find sites like these!!

Yo then check out the list of their clients :
http://www.fastcart.co.uk/showcase.php

Bingo, I select one the merchant (http://www.beautyspotcosmetics.co.uk/), click on one of their product, .... and just change the price at the end of the url : the best way to get any product for 1p!!
Click here to see the example

This site is using the same free cart system : http://www.advancedbrain.co.uk/ ...




0 Comments:

Post a Comment

Links to this post:

Create a Link

<< Home