Run the downloaded file by double clicking (you need to have virtual machine ).

3. Anonymity when checking the site for SQL injections

Setting up Tor and Privoxy in Kali Linux

[Section under development]

Setting up Tor and Privoxy on Windows

[Section under development]

jSQL Injection proxy settings

[Section under development]

4. Checking the site for SQL injection with jSQL Injection

Working with the program is extremely simple. Just enter the site address and press ENTER.

The following screenshot shows that the site is vulnerable to three types of SQL injections at once (information about them is indicated in the lower right corner). By clicking on the names of the injections, you can switch the method used:

Also, we have already displayed the existing databases.

You can see the contents of each table:

Usually, the most interesting part of the tables is the administrator credentials.

If you are lucky and you found the administrator's data, then it's too early to rejoice. You also need to find the admin panel, where to enter these data.

5. Search for admins with jSQL Injection

To do this, go to the next tab. Here we are met by a list of possible addresses. You can select one or more pages to check:

The convenience is that you do not need to use other programs.

Unfortunately, there are not very many careless programmers who store passwords in clear text. Quite often in the password string we see something like

8743b52063cd84097a65d1633f5c74f5

This is a hash. You can decrypt it with brute force. AND… jSQL Injection has a built-in bruteforcer.

6. Brute-forcing hashes with jSQL Injection

Undoubted convenience is that you do not need to look for other programs. There is support for many of the most popular hashes.

This is not the best option. In order to become a guru in deciphering hashes, the book "" in Russian is recommended.

But, of course, when there is no other program at hand or there is no time to learn, jSQL Injection with a built-in brute-force function will come in handy.

There are settings: you can set which characters are included in the password, the password length range.

7. File operations after SQL injection detection

In addition to operations with databases - reading and modifying them, if SQL injections are detected, the following file operations can be performed:

  • reading files on the server
  • uploading new files to the server
  • uploading shells to the server

And all this is implemented in jSQL Injection!

There are limitations - the SQL server must have file privileges. Reasonable system administrators they are disabled and access to file system cannot be obtained.

The presence of file privileges is easy enough to check. Go to one of the tabs (reading files, creating a shell, uploading a new file) and try to perform one of the indicated operations.

Another very important note - we need to know the exact absolute path to the file with which we will work - otherwise nothing will work.

Look at the following screenshot:

Any attempt to operate on a file is answered by: No FILE privilege(no file privileges). And nothing can be done here.

If instead you have another error:

Problem writing into [directory_name]

This means that you incorrectly specified the absolute path where you want to write the file.

In order to assume an absolute path, one must at least know operating system on which the server is running. To do this, switch to the Network tab.

Such an entry (string Win64) gives us reason to assume that we are dealing with Windows OS:

Keep-Alive: timeout=5, max=99 Server: Apache/2.4.17 (Win64) PHP/7.0.0RC6 Connection: Keep-Alive Method: HTTP/1.1 200 OK Content-Length: 353 Date: Fri, 11 Dec 2015 11:48:31 GMT X-Powered-By: PHP/7.0.0RC6 Content-Type: text/html; charset=UTF-8

Here we have some Unix (*BSD, Linux):

Transfer-Encoding: chunked Date: Fri, 11 Dec 2015 11:57:02 GMT Method: HTTP/1.1 200 OK Keep-Alive: timeout=3, max=100 Connection: keep-alive Content-Type: text/html X- Powered-By: PHP/5.3.29 Server: Apache/2.2.31 (Unix)

And here we have CentOS:

Method: HTTP/1.1 200 OK Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=9p60gtunrv7g41iurr814h9rd0; path=/ Connection: keep-alive X-Cache-Lookup: MISS from t1.hoster.ru:6666 Server: Apache/2.2.15 (CentOS) X-Powered-By: PHP/5.4.37 X-Cache: MISS from t1.hoster.ru Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Date: Fri, 11 Dec 2015 12:08:54 GMT Transfer-Encoding: chunked Content-Type: text/html; charset=WINDOWS-1251

On Windows, a typical site folder is C:\Server\data\htdocs\. But, in fact, if someone "thought" of making a server on Windows, then, very likely, this person has not heard anything about privileges. Therefore, you should start trying directly from the C: / Windows / directory:

As you can see, everything went perfectly the first time.

But the jSQL Injection shells themselves raise my doubts. If you have file privileges, then you may well upload something with a web interface.

8. Bulk checking sites for SQL injections

And even jSQL Injection has this feature. Everything is extremely simple - upload a list of sites (can be imported from a file), select those that you want to check and click the appropriate button to start the operation.

Output by jSQL Injection

jSQL Injection is a good, powerful tool for finding and then using SQL injections found on sites. Its undoubted advantages: ease of use, built-in related functions. jSQL Injection can become best friend newbie at website analysis.

Of the shortcomings, I would note the impossibility of editing databases (at least I did not find this functionality). Like all instruments with GUI, the disadvantages of this program can be attributed to the impossibility of using in scripts. Nevertheless, some automation is possible in this program too - thanks to the built-in mass site check function.

established sample and certificate. Special discount for any faculties and courses!

Start display at page:

Transcription

1 inurl:index.php?id= inurl:trainers.php?id= inurl:buy.php?category= inurl:article.php?id= inurllay_old.php?id= inurl:declaration_more.php?decl_id= inurlageid= inurl :games.php?id= inurlage.php?file= inurl:newsdetail.php?id= inurl:gallery.php?id= inurl:article.php?id= inurl:show.php?id= inurl:staff_id= inurl :newsitem.php?num= inurl:readnews.php?id= inurl:top10.php?cat= inurl:historialeer.php?num= inurl:reagir.php?num= inurltray-questions-view.php?num= inurl :forum_bds.php?num= inurl:game.php?id= inurl:view_product.php?id=

2 inurl:newsone.php?id= inurl:sw_comment.php?id= inurl:news.php?id= inurl:avd_start.php?avd= inurl:event.php?id= inurlroduct-item.php?id= inurl :sql.php?id= inurl:news_view.php?id= inurl:select_biblio.php?id= inurl:humor.php?id= inurl:aboutbook.php?id= inurl:fiche_spectacle.php?id= inurl:communique_detail .php?id= inurl:sem.php3?id= inurl:kategorie.php4?id= inurl:news.php?id= inurl:index.php?id= inurl:faq2.php?id= inurl:show_an.php ?id= inurlreview.php?id= inurl:loadpsb.php?id= inurlpinions.php?id= inurl:spr.php?id=

3 inurlages.php?id= inurl:announce.php?id= inurl:clanek.php4?id= inurlarticipant.php?id= inurl:download.php?id= inurl:main.php?id= inurl:review.php ?id= inurl:chappies.php?id= inurl:read.php?id= inurlrod_detail.php?id= inurl:viewphoto.php?id= inurl:article.php?id= inurlerson.php?id= inurlroductinfo.php ?id= inurl:showimg.php?id= inurl:view.php?id= inurl:website.php?id= inurl:hosting_info.php?id= inurl:gallery.php?id= inurl:rub.php?idr = inurl:view_faq.php?id= inurl:artikelinfo.php?id= inurl:detail.php?id=

4 inurl:index.php?= inurlrofile_view.php?id= inurl:category.php?id= inurllublications.php?id= inurl:fellows.php?id= inurl:downloads_info.php?id= inurlrod_info.php?id= inurl:shop.php?do=part&id= inurlroductinfo.php?id= inurl:collectionitem.php?id= inurl:band_info.php?id= inurlroduct.php?id= inurl:releases.php?id= inurl:ray. php?id= inurlroduit.php?id= inurlop.php?id= inurl:shopping.php?id= inurlroductdetail.php?id= inurlost.php?id= inurl:viewshowdetail.php?id= inurl:clubpage.php? id= inurl:memberinfo.php?id= inurl:section.php?id=

5 inurl:theme.php?id= inurlage.php?id= inurl:shredder-categories.php?id= inurl:tradecategory.php?id= inurlroduct_ranges_view.php?id= inurl:shop_category.php?id= inurl:tran ******.php?id= inurl:channel_id= inurl:item_id= inurl:newsid= inurl:trainers.php?id= inurl:news-full.php?id= inurl:news_display.php?getid= inurl :index2.php?option= inurl:readnews.php?id= inurl:top10.php?cat= inurl:newsone.php?id= inurl:event.php?id= inurlroduct-item.php?id= inurl:sql .php?id= inurl:aboutbook.php?id= inurl:review.php?id= inurl:loadpsb.php?id=

6 inurl:ages.php?id= inurl:material.php?id= inurl:clanek.php4?id= inurl:announce.php?id= inurl:chappies.php?id= inurl:read.php?id= inurl :viewapp.php?id= inurl:viewphoto.php?id= inurl:rub.php?idr= inurl:galeri_info.php?l= inurl:review.php?id= inurl:iniziativa.php?in= inurl:curriculum .php?id= inurl:labels.php?id= inurl:story.php?id= inurl:look.php?id= inurl:newsone.php?id= inurl:aboutbook.php?id= inurl:material.php ?id= inurlpinions.php?id= inurl:announce.php?id= inurl:rub.php?idr= inurl:galeri_info.php?l=

7 inurl:tekst.php?idt= inurl:newscat.php?id= inurl:newsticker_info.php?idn= inurl:rubrika.php?idr= inurl:rubp.php?idr= inurlffer.php?idf= inurl:art .php?idm= inurl:title.php?id= inurl:index.php?id= inurl:trainers.php?id= inurl:buy.php?category= inurl:article.php?id= inurllay_old.php?id = inurl:declaration_more.php?decl_id= inurlageid= inurl:games.php?id= inurlage.php?file= inurl:newsdetail.php?id= inurl:gallery.php?id= inurl:article.php?id= inurl :show.php?id= inurl:staff_id= inurl:newsitem.php?num=

8 inurl:readnews.php?id= inurl:top10.php?cat= inurl:historialeer.php?num= inurl:reagir.php?num= inurltray-questions-view.php?num= inurl:forum_bds.php?num = inurl:game.php?id= inurl:view_product.php?id= inurl:newsone.php?id= inurl:sw_comment.php?id= inurl:news.php?id= inurl:avd_start.php?avd= inurl :event.php?id= inurlroduct-item.php?id= inurl:sql.php?id= inurl:news_view.php?id= inurl:select_biblio.php?id= inurl:humor.php?id= inurl:aboutbook .php?id= inurl:fiche_spectacle.php?id= inurl:communique_detail.php?id= inurl:sem.php3?id= inurl:kategorie.php4?id=

9 inurl:news.php?id= inurl:index.php?id= inurl:faq2.php?id= inurl:show_an.php?id= inurlreview.php?id= inurl:loadpsb.php?id= inurlpinions.php ?id= inurl:spr.php?id= inurlages.php?id= inurl:announce.php?id= inurl:clanek.php4?id= inurlarticipant.php?id= inurl:download.php?id= inurl:main .php?id= inurl:review.php?id= inurl:chappies.php?id= inurl:read.php?id= inurlrod_detail.php?id= inurl:viewphoto.php?id= inurl:article.php?id = inurlerson.php?id= inurlroductinfo.php?id= inurl:showimg.php?id=

10 inurl:view.php?id= inurl:website.php?id= inurl:hosting_info.php?id= inurl:gallery.php?id= inurl:rub.php?idr= inurl:view_faq.php?id= inurl :artikelinfo.php?id= inurl:detail.php?id= inurl:index.php?= inurlrofile_view.php?id= inurl:category.php?id= inurlublications.php?id= inurl:fellows.php?id= inurl:downloads_info.php?id= inurlrod_info.php?id= inurl:shop.php?do=part&id= inurlroductinfo.php?id= inurl:collectionitem.php?id= inurl:band_info.php?id= inurlroduct.php? id= inurl:releases.php?id= inurl:ray.php?id= inurlroduit.php?id=

11 inurlop.php?id= inurl:shopping.php?id= inurlroductdetail.php?id= inurlost.php?id= inurl:viewshowdetail.php?id= inurl:clubpage.php?id= inurl:memberinfo.php?id = inurl:section.php?id= inurl:theme.php?id= inurlage.php?id= inurl:shredder-categories.php?id= inurl:tradecategory.php?id= inurlroduct_ranges_view.php?id= inurl:shop_category .php?id= inurl:tran******.php?id= inurl:channel_id= inurl:item_id= inurl:newsid= inurl:trainers.php?id= inurl:news-full.php?id= inurl :news_display.php?getid= inurl:index2.php?option= inurl:readnews.php?id=

12 inurl:top10.php?cat= inurl:newsone.php?id= inurl:event.php?id= inurlroduct-item.php?id= inurl:sql.php?id= inurl:aboutbook.php?id= inurl :review.php?id= inurl:loadpsb.php?id= inurl:ages.php?id= inurl:material.php?id= inurl:clanek.php4?id= inurl:announce.php?id= inurl:chappies .php?id= inurl:read.php?id= inurl:viewapp.php?id= inurl:viewphoto.php?id= inurl:rub.php?idr= inurl:galeri_info.php?l= inurl:review.php ?id= inurl:iniziativa.php?in= inurl:curriculum.php?id= inurl:labels.php?id= inurl:story.php?id=

13 inurl:look.php?id= inurl:newsone.php?id= inurl:aboutbook.php?id= inurl:material.php?id= inurlpinions.php?id= inurl:announce.php?id= inurl:rub .php?idr= inurl:galeri_info.php?l= inurl:tekst.php?idt= inurl:newscat.php?id= inurl:newsticker_info.php?idn= inurl:rubrika.php?idr= inurl:rubp.php ?idr= inurlffer.php?idf= inurl:art.php?idm= inurl:title.php?id= inurl: info.php?id= inurl:pro.php?id= inurl:"id=" & intext: "warning: mysql_fetch_assoc() inurl:"id=" & intext:"warning: mysql_fetch_array() inurl:"id=" & intext:"warning: mysql_num_rows() inurl:"id=" & intext:"warning: session_start( ) inurl:"id=" & intext:"warning: getimagesize()

14 inurl:"id=" & intext:"warning: is_writable() inurl:"id=" & intext:"warning: getimagesize() inurl:"id=" & intext:"warning: Unknown() inurl:"id =" & intext:"warning: session_start() inurl:"id=" & intext:"warning: mysql_result() inurl:"id=" & intext:"warning: pg_exec() inurl:"id=" & intext: "warning: mysql_result() inurl:"id=" & intext:"warning: mysql_num_rows() inurl:"id=" & intext:"warning: mysql_query() inurl:"id=" & intext:"warning: array_merge( ) inurl:"id=" & intext:"warning: preg_match() inurl:"id=" & intext:"warning: ilesize() inurl:"id=" & intext:"warning: filesize() inurl:"id =" & intext:"warning: require() inurl:index.php?id= inurl:trainers.php?id= inurl:buy.php?category= inurl:article.php?id= inurl:play_old.php?id = inurl:declaration_more.php?decl_id= inurl:pageid= inurl:games.php?id= inurl:page.php?file=

15 inurl:newsdetail.php?id= inurl:gallery.php?id= inurl:article.php?id= inurl:show.php?id= inurl:staff_id= inurl:newsitem.php?num= inurl:readnews.php ?id= inurl:top10.php?cat= inurl:historialeer.php?num= inurl:reagir.php?num= inurl:stray-questions-view.php?num= inurl:forum_bds.php?num= inurl:game .php?id= inurl:view_product.php?id= inurl:newsone.php?id= inurl:sw_comment.php?id= inurl:news.php?id= inurl:avd_start.php?avd= inurl:event.php ?id= inurl:product-item.php?id= inurl:sql.php?id= inurl:news_view.php?id= inurl:select_biblio.php?id=

16 inurl:humor.php?id= inurl:aboutbook.php?id= inurl:ogl_inet.php?ogl_id= inurl:fiche_spectacle.php?id= inurl:communique_detail.php?id= inurl:sem.php3?id= inurl :kategorie.php4?id= inurl:news.php?id= inurl:index.php?id= inurl:faq2.php?id= inurl:show_an.php?id= inurl:preview.php?id= inurl:loadpsb .php?id= inurl:opinions.php?id= inurl:spr.php?id= inurl:pages.php?id= inurl:announce.php?id= inurl:clanek.php4?id= inurl:participant.php ?id= inurl:download.php?id= inurl:main.php?id= inurl:review.php?id= inurl:chappies.php?id=

17 inurl:read.php?id= inurl:prod_detail.php?id= inurl:viewphoto.php?id= inurl:article.php?id= inurl:person.php?id= inurl:productinfo.php?id= inurl :showimg.php?id= inurl:view.php?id= inurl:website.php?id= inurl:hosting_info.php?id= inurl:gallery.php?id= inurl:rub.php?idr= inurl:view_faq .php?id= inurl:artikelinfo.php?id= inurl:detail.php?id= inurl:index.php?= inurl:profile_view.php?id= inurl:category.php?id= inurl:publications.php? id= inurl:fellows.php?id= inurl:downloads_info.php?id= inurl:prod_info.php?id= inurl:shop.php?do=part&id=

18 inurl:productinfo.php?id= inurl:collectionitem.php?id= inurl:band_info.php?id= inurl:product.php?id= inurl:releases.php?id= inurl:ray.php?id= inurl :produit.php?id= inurl:pop.php?id= inurl:shopping.php?id= inurl:productdetail.php?id= inurl:post.php?id= inurl:viewshowdetail.php?id= inurl:clubpage .php?id= inurl:memberinfo.php?id= inurl:section.php?id= inurl:theme.php?id= inurl:page.php?id= inurl:shredder-categories.php?id= inurl:tradecategory .php?id= inurl:product_ranges_view.php?id= inurl:shop_category.php?id= inurl:transcript.php?id= inurl:channel_id=

19 inurl:item_id= inurl:newsid= inurl:trainers.php?id= inurl:news-full.php?id= inurl:news_display.php?getid= inurl:index2.php?option= inurl:readnews.php?id = inurl:top10.php?cat= inurl:newsone.php?id= inurl:event.php?id= inurl:product-item.php?id= inurl:sql.php?id= inurl:aboutbook.php?id = inurl:preview.php?id= inurl:loadpsb.php?id= inurl:pages.php?id= inurl:material.php?id= inurl:clanek.php4?id= inurl:announce.php?id= inurl :chappies.php?id= inurl:read.php?id= inurl:viewapp.php?id= inurl:viewphoto.php?id=

20 inurl:rub.php?idr= inurl:galeri_info.php?l= inurl:review.php?id= inurl:iniziativa.php?in= inurl:curriculum.php?id= inurl:labels.php?id= inurl :story.php?id= inurl:look.php?id= inurl:newsone.php?id= inurl:aboutbook.php?id= inurl:material.php?id= inurl:opinions.php?id= inurl:announce .php?id= inurl:rub.php?idr= inurl:galeri_info.php?l= inurl:tekst.php?idt= inurl:newscat.php?id= inurl:newsticker_info.php?idn= inurl:rubrika.php ?idr= inurl:rubp.php?idr= inurl:offer.php?idf= inurl:art.php?idm= inurl:title.php?id=

21 !scan side.php?arq= allinurl:.php?arq=!scan side.php?table= allinurl:.php?table=!scan side.php?vis= allinurl:.php?vis=!scan side. php?vis= allinurl:side.php?vis=!scan site.php?arq= allinurl:.php?arq=!scan site.php?meio= allinurl:.php?meio=!scan site.php?table= allinurl:.php?table=!scan s.php?table= allinurl:.php?table=!scan start.php?id= allinurl:".php?id="!scan start.php?id= allinurl:" start.php?id="!scan start.php?id= allinurl:start.php?id=!scan start.php?lang= allinurl:".php?lang="!scan start.php?lang= allinurl: "start.php?lang="!scan start.php?lang= allinurl:start.php?lang=!scan start.php?lang=.php?lang=!scan start.php?lang= start.php?lang =!scan start.php?mod= allinurl:".php?mod="!scan start.php?mod= allinurl:"start.php?mod="!scan start.php?page= allinurl:".php? page="!scan start.php?page= allinurl:"start.php?page="!scan start.php?page= start.php?page=!scan start.php?pag= start.php?pag=! scan start.php?pg= start.php?pg=

22 !scan start.php?p= start.php?p=!scan start.php?s= allinurl:".php?s="!scan start.php?s= allinurl:"start.php?s=" !scan start.php?s= allinurl:start.php?s=!scan start.php?s= start.php?s=!scan str.php?lang= str.php?lang=!scan str.php? ln= str.php?ln=!scan str.php?l= str.php?l=!scan str.php?page= str.php?page=!scan str.php?p= str.php?p= !scan sub.php?menu= "sub.php?menu="!scan sub.php?menu= sub.php?menu=!scan sub.php?s= "sub.php?s="!scan sub. php?s= sub.php?s=!scan sub.php?sub= "sub.php?sub="!scan sub.php?sub= sub.php?sub=!scan task.php?task= allinurl: .php?task=!scan task.php?task= allinurl:task.php?task=!scan /templates/mangobery/footer.sample.php?site_path= Mangobery!scan /templates/mangobery/footer.sample.php? site_path= Mangobery 0.5.5!scan /templates/mangobery/footer.sample.php?site_path= Mangobery

23 !scan trans.php?trans= allinurl:".php?trans="!scan trans.php?trans= allinurl:"trans.php?trans="!scan /trans/trans.php?trans=eng&page= allinurl :".php?trans="!scan /trans/trans.php?trans=en&page= allinurl:".php?trans="!scan /trans/trans.php?trans=fr&page= allinurl:".php?trans ="!scan /trans/trans.php?trans=ko&page= allinurl:".php?trans="!scan /trans/trans.php?trans=&page= allinurl:".php?trans="!scan /trans /trans.php?trans=&p= allinurl:".php?trans="!scan view.php?sub= "view.php?sub="!scan view.php?sub= view.php?sub=!scan view.php?table= allinurl:.php?table=!scan voir.php?inc= allinurl:".php?adid="!scan werbungframe.php?do= allinurl:".php?do="!scan / ws/get_events.php?includedir= "WebCalendar"!scan /ws/get_events.php?includedir= Web Calendar!scan /ws/get_events.php?includedir= WebCalendar!scan /ws/get_events.php?includedir= WebCalendar v0. 9.45!scan /ws/get_reminders.php?includedir= WebCalendar!scan /ws/get_reminders.php?includedir= WebCalendar v0.9.45!scan /ws/login.php?includedir= WebCa lendar!scan /ws/login.php?includedir= WebCalendar v0.9.45!scan ocp-103/index.php?req_path= ocportal!scan images/evil.php?owned= e107

24 !scan index.php?ver= allinurl:.php?ver=!scan index.php?ver= allinurl:".php?ver="!scan index.php?ver=.php?ver=!scan /index .php?vis= allinurl:/index.php?vis=!scan /index.php?vis= allinurl:.php?vis=!scan index.php?way= index.php?way=!scan index.php? way=.php?way=!scan index.php?wpage= allinurl:"index.php?wpage="!scan index.php?wpage= allinurl:".php?wpage="!scan info.php?ln= allinurl:"info.php?ln="!scan info.php?ln= allinurl:info.php?ln=!scan info.php?ln= allinurl:".php?ln="!scan /interna.php? meio= allinurl:".php?meio="!scan kalender.php?vis= allinurl:"kalender.php"!scan kalender.php?vis= allinurl:"kalender.php?vis="!scan kalender.php? vis= allinurl:".php?vis="!scan lang.php?arg= allinurl:.php?arg=!scan lang.php?arq= allinurl:.php?arq=!scan lang.php?lk= allinurl :".php?lk="!scan lang.php?ln= allinurl:.php?ln=!scan lang.php?subpage= allinurl:".php?subpage="!scan lang.php?subp= allinurl: ".php?sub="!scan lang.php?subp= allinurl:".php?subp="

25 !scan /lib/db/ez_sql.php?lib_path= ttcms!scan /lib/db/ez_sql.php?lib_path= ttcms<= v4!scan /lib/static/header.php?set_menu= iphoto Album!scan /lib/static/header.php?set_menu= iphotoalbum!scan /lib/static/header.php?set_menu= iphotoalbum v1.1!scan link.php?do= allinurl:".php?do="!scan list.php?product= allinurl:.php?product=!scan list.php?table= allinurl:.php?table=!scan ln.php?ln= allinurl:.php?ln=!scan loc.php?l= allinurl:".php?l="!scan loc.php?l= allinurl:".php?loc="!scan loc.php?lang= allinurl:".php?lang="!scan loc.php?lang= allinurl:".php?loc="!scan loc.php?loc= allinurl:"loc.php?loc="!scan loc.php?loc= allinurl:".php?loc="!scan login.php?loca=.php?loca=!scan magazine.php?inc= allinurl:".php?inc="!scan main1.php?arg= allinurl:.php?arg=!scan main1.php?ln= allinurl:.php?ln=!scan main2.php?ln= allinurl:.php?ln=!scan main.html.php?seite= allinurl:.php?seite=!scan main.php3?act= allinurl:"main.php3?act="!scan main.php3?act= allinurl:".php3?act="

26 !scan main.php5?page=.php5?id=!scan main.php?a= allinurl:".php?a="!scan main.php?arg= allinurl:.php?arg=!scan main. php?ba= allinurl:"main.php?ba="!scan main.php?ba= allinurl:".php?ba="!scan main.php?command= allinurl:"main.php?command="! scan main.php?command= allinurl:".php?command="!scan main.php?d1= allinurl:"main.php?d1="!scan main.php?d1= allinurl:".php?d1= "!scan main.php?f1= allinurl:".php?f1="!scan main.php?fset= allinurl:".php?fset="!scan main.php?id= inurl:"main.php? id=*.php"!scan main.php?inc= allinurl:".php?inc="!scan main.php?ln= allinurl:.php?ln=!scan main.php?ltr= allinurl:". php?ltr="!scan main.php?s= allinurl:"main.php?s="!scan main.php?s= allinurl:main.php?s=!scan main.php?s= allinurl:. php?s=!scan main.php?s= allinurl:".php?s="!scan main.php?sit= allinurl:".php?sit="!scan main.php?table= allinurl:.php ?table=!scan main.php?vis= allinurl:"main.php?vis="!scan main.php?vis= allinurl:main.php?vis=

27 !scan main.php?vis= allinurl:".php?vis="!scan mai.php?act= allinurl:"mai.php?act="!scan mai.php?act= allinurl:mai.php? act=!scan mai.php?loc= allinurl:"mai.php?loc="!scan mai.php?loc= allinurl:mai.php?loc=!scan mai.php?src= allinurl:"mai.php ?src="!scan mai.php?src= allinurl:mai.php?src=!scan map.php?loc= map.php?loc=!scan middle.php?file= inurl:"middle.php?file ="!scan middle.php?file= inurl:"middle.php?page="!scan middle.php?file= inurl:".php?file="!scan middle.php?file= inurl:".php ?page="!scan middle.php?file= middle.php?file=!scan middle.php?file= middle.php?page=!scan middle.php?file=.php?file=!scan middle.php ?file=.php?page=!scan middle.php?page= inurl:"middle.php?page="!scan middle.php?page= inurl:".php?page="!scan middle.php?page = middle.php?page=!scan middle.php?page=.php?page=!scan misc.php?do= allinurl:".php?do="!scan mod.php?mod= allinurl:"mod. php?mod="!scan mod.php?mod= allinurl:".php?mod="

28 !scan module.php?mod= allinurl:"module.php?mod="!scan module.php?mod= allinurl:".php?mod="!scan /modules/postguestbook/styles/internal/header.php ?tpl_pgb_moddir= allinurl:"postguestbook"!scan /modules/postguestbook/styles/internal/header.php?tpl_pgb_moddir= inurl:"postguestbook"!scan /modules/postguestbook/styles/internal/header.php?tpl_pgb_moddir= inurl:" postguestbook 0.6.1"!scan /modules/postguestbook/styles/internal/header.php?tpl_pgb_moddir= "PostGuestbook"!scan /modules/postguestbook/styles/internal/header.php?tpl_pgb_moddir= PostGuestbook!scan /modules/postguestbook/ styles/internal/header.php?tpl_pgb_moddir= PostGuestbook 0.6.1!scan modul.php?mod= allinurl:"modul.php?mod="!scan modul.php?mod= allinurl:".php?mod="! scan more.php?sub="more.php?sub="

29 !scan more.php?sub= more.php?sub=!scan nav.php?g= "nav.php?g="!scan nav.php?g= nav.php?g=!scan nav.php ?go= "nav.php?go="!scan nav.php?go= nav.php?go=!scan nav.php?lk= allinurl:".php?lk="!scan nav.php?ln= allinurl:.php?ln=!scan nav.php?loc= nav.php!scan nav.php?loc= nav.php?loc=!scan nav.php?loc=.php?loc=!scan nav.php ?nav= "nav.php?nav="!scan nav.php?nav= nav.php?nav=!scan nav.php?page= "nav.php?page="!scan nav.php?page= nav .php?page=!scan nav.php?pagina= "nav.php?pagina="!scan template.php?sekce=!scan down*.php?gofile=!scan blank.php?header=!scan start. php?body=!scan standard.php?body=!scan base.php?path=!scan base.php?module=!scan default.php?l=

30 !scan principal.php?strona=!scan info.php?l=!scan template.php?left=!scan index2.php?texto=!scan home.php?eval=!scan padrao.php?section=! scan blank.php?gofile=!scan head.php?loc=!scan index.php?index=!scan page.php?ir=!scan print.php?path=!scan layout.php?ir=!scan blank .php?pollname=!scan down*.php?path=!scan include.php?x=!scan sitio.php?opcion=!scan pagina.php?category=!scan start.php?pageweb=!scan gallery. php?rub=!scan template.php?sp=!scan sub*.php?basepath=!scan press.php?menu=!scan standard.php?section=

31 !scan enter.php?abre=!scan index2.php?pref=!scan index1.php?pa=!scan sitio.php?incl=!scan principal.php?seite=!scan show.php?ki=! scan gallery.php?chapter=!scan nota.php?qry=!scan pagina.php?pagina=!scan index3.php?x=!scan default.php?menu=!scan page.php?strona=!scan * inc*.php?open=!scan index3.php?secao=!scan standard.php?*[*]*=!scan default.php?abre=!scan template.php?basepath=!scan standard.php?gofile =!scan index2.php?ir=!scan file.php?modo=!scan gallery.php?itemnav=!scan main.php?oldal=!scan press.php?pg=

32 !scan down*.php?showpage=!scan start.php?nivel=!scan start.php?destino=!scan index1.php?filepath=!scan blank.php?rub=!scan path.php?ir= !scan layout.php?var=!scan padrao.php?op=!scan mod*.php?pre=!scan index1.php?texto=!scan start.php?pg=!scan default.php?pa=! scan press.php?strona=!scan nota.php?cmd=!scan index1.php?showpage=!scan info.php?go=!scan standard.php?abre=!scan general.php?seccion=!scan index1 .php?itemnav=!scan layout.php?seite=!scan path.php?load=!scan home.php?pollname=!scan path.php?left=

33 !scan down*.php?inc=!scan index3.php?abre=!scan blank.php?where=!scan info.php?start=!scan include.php?channel=!scan print.php?dir= !scan pag inurl:index.php?id= inurl:trainers.php?id= inurl:buy.php?category= inurl:article.php?id= inurl:play_old.php?id= inurl:declaration_more.php?decl_id = inurl:pageid= inurl:games.php?id= inurl:page.php?file= inurl:newsdetail.php?id= inurl:gallery.php?id= inurl:article.php?id= inurl:show.php ?id= inurl:staff_id= inurl:newsitem.php?num= inurl:readnews.php?id=

34 inurl:top10.php?cat= inurl:historialeer.php?num= inurl:reagir.php?num= inurl:stray-questions-view.php?num= inurl:forum_bds.php?num= inurl:game.php ?id= inurl:view_product.php?id= inurl:newsone.php?id= inurl:sw_comment.php?id= inurl:news.php?id= inurl:avd_start.php?avd= inurl:event.php?id = inurl:product-item.php?id= inurl:sql.php?id= inurl:news_view.php?id= inurl:select_biblio.php?id= inurl:humor.php?id= inurl:aboutbook.php?id = inurl:ogl_inet.php?ogl_id= inurl:fiche_spectacle.php?id= inurl:communique_detail.php?id= inurl:sem.php3?id= inurl:kategorie.php4?id=

35 inurl:news.php?id= inurl:index.php?id= inurl:faq2.php?id= inurl:show_an.php?id= inurl:preview.php?id= inurl:loadpsb.php?id= inurl :opinions.php?id= inurl:spr.php?id= inurl:pages.php?id= inurl:announce.php?id= inurl:clanek.php4?id= inurl:participant.php?id= inurl:download .php?id= inurl:main.php?id= inurl:review.php?id= inurl:chappies.php?id= inurl:read.php?id= inurl:prod_detail.php?id= inurl:viewphoto.php ?id= inurl:article.php?id= inurl:person.php?id= inurl:productinfo.php?id= inurl:showimg.php?id=

36 inurl:view.php?id= inurl:website.php?id= inurl:hosting_info.php?id= inurl:gallery.php?id= inurl:rub.php?idr= inurl:view_faq.php?id= inurl :artikelinfo.php?id= inurl:detail.php?id= inurl:index.php?= inurl:profile_view.php?id= inurl:category.php?id= inurl:publications.php?id= inurl:fellows. php?id= inurl:downloads_info.php?id= inurl:prod_info.php?id= inurl:shop.php?do=part&id= inurl:productinfo.php?id= inurl:collectionitem.php?id= inurl:band_info. php?id= inurl:product.php?id= inurl:releases.php?id= inurl:ray.php?id= inurl:produit.php?id=

37 inurl:pop.php?id= inurl:shopping.php?id= inurl:productdetail.php?id= inurl:post.php?id= inurl:viewshowdetail.php?id= inurl:clubpage.php?id= inurl :memberinfo.php?id= inurl:section.php?id= inurl:theme.php?id= inurl:page.php?id= inurl:shredder-categories.php?id= inurl:tradecategory.php?id= inurl :product_ranges_view.php?id= inurl:shop_category.php?id= inurl:transcript.php?id= inurl:channel_id= inurl:item_id= inurl:newsid= inurl:trainers.php?id= inurl:news-full.php ?id= inurl:news_display.php?getid= inurl:index2.php?option= inurl:readnews.php?id=

38 inurl:top10.php?cat= inurl:newsone.php?id= inurl:event.php?id= inurl:product-item.php?id= inurl:sql.php?id= inurl:aboutbook.php?id = inurl:preview.php?id= inurl:loadpsb.php?id= inurl:pages.php?id= inurl:material.php?id= inurl:clanek.php4?id= inurl:announce.php?id= inurl :chappies.php?id= inurl:read.php?id= inurl:viewapp.php?id= inurl:viewphoto.php?id= inurl:rub.php?idr= inurl:galeri_info.php?l= inurl:review .php?id= inurl:iniziativa.php?in= inurl:curriculum.php?id= inurl:labels.php?id= inurl:story.php?id=

39 inurl:look.php?id= inurl:newsone.php?id= inurl:aboutbook.php?id= inurl:material.php?id= inurl:opinions.php?id= inurl:announce.php?id= inurl :rub.php?idr= inurl:galeri_info.php?l= inurl:tekst.php?idt= inurl:newscat.php?id= inurl:newsticker_info.php?idn= inurl:rubrika.php?idr= inurl:rubp .php?idr= inurl:offer.php?idf= inurl:art.php?idm= inurl:title.php?id= inurl:gallery.php?id= inurl:article.php?id= inurl:show.php ?id= inurl:staff_id= inurl:newsitem.php?num= inurl:readnews.php?id= inurl:top10.php?cat=

40 inurl:historialeer.php?num= inurl:reagir.php?num= inurl:stray-questions-view.php?num= inurl:forum_bds.php?num= inurl:game.php?id= inurl:view_product.php ?id= inurl:newsone.php?id= inurl:sw_comment.php?id= inurl:news.php?id= inurl:avd_start.php?avd= inurl:event.php?id= inurl:product-item.php ?id= inurl:sql.php?id= inurl:news_view.php?id= inurl:select_biblio.php?id= inurl:humor.php?id= inurl:aboutbook.php?id= inurl:ogl_inet.php?ogl_id = inurl:fiche_spectacle.php?id= inurl:communique_detail.php?id= inurl:sem.php3?id= inurl:kategorie.php4?id= inurl:news.php?id=

41 inurl:index.php?id= inurl:faq2.php?id= inurl:show_an.php?id= inurl:preview.php?id= inurl:loadpsb.php?id= inurl:opinions.php?id= inurl :spr.php?id= inurl:pages.php?id= inurl:announce.php?id= inurl:clanek.php4?id= inurl:participant.php?id= inurl:download.php?id= inurl:main .php?id= inurl:review.php?id= inurl:chappies.php?id= inurl:read.php?id= inurl:prod_detail.php?id= inurl:viewphoto.php?id= inurl:article.php ?id= inurl:person.php?id= inurl:productinfo.php?id= inurl:showimg.php?id= inurl:view.php?id=

42 inurl:website.php?id= inurl:hosting_info.php?id= inurl:gallery.php?id= inurl:rub.php?idr= inurl:view_faq.php?id= inurl:artikelinfo.php?id= inurl :detail.php?id= inurl:index.php?= inurl:profile_view.php?id= inurl:category.php?id= inurl:publications.php?id= inurl:fellows.php?id= inurl:downloads_info. php?id= inurl:prod_info.php?id= inurl:shop.php?do=part&id= inurl:productinfo.php?id= inurl:collectionitem.php?id= inurl:band_info.php?id= inurl:product. php?id= inurl:releases.php?id= inurl:ray.php?id= inurl:produit.php?id= inurl:pop.php?id=

43 inurl:shopping.php?id= inurl:productdetail.php?id= inurl:post.php?id= inurl:viewshowdetail.php?id= inurl:clubpage.php?id= inurl:memberinfo.php?id= inurl :section.php?id= inurl:theme.php?id= inurl:page.php?id= inurl:shredder-categories.php?id= inurl:tradecategory.php?id= inurl:product_ranges_view.php?id= inurl :shop_category.php?id= inurl:transcript.php?id= inurl:channel_id= inurl:item_id= inurl:newsid= inurl:trainers.php?id= inurl:news-full.php?id= inurl:news_display.php ?getid= inurl:index2.php?option= inurl:readnews.php?id= inurl:top10.php?cat=

44 inurl:newsone.php?id= inurl:event.php?id= inurl:product-item.php?id= inurl:sql.php?id= inurl:aboutbook.php?id= inurl:preview.php?id = inurl:loadpsb.php?id= inurl:pages.php?id= inurl:material.php?id= inurl:clanek.php4?id= inurl:announce.php?id= inurl:chappies.php?id= inurl :read.php?id= inurl:viewapp.php?id= inurl:viewphoto.php?id= inurl:rub.php?idr= inurl:galeri_info.php?l= inurl:review.php?id= inurl:iniziativa .php?in= inurl:curriculum.php?id= inurl:labels.php?id= inurl:story.php?id= inurl:look.php?id=

45 inurl:newsone.php?id= inurl:aboutbook.php?id= inurl:material.php?id= inurl:opinions.php?id= inurl:announce.php?id= inurl:rub.php?idr= inurl :galeri_info.php?l= inurl:tekst.php?idt= inurl:newscat.php?id= inurl:newsticker_info.php?idn= inurl:rubrika.php?idr= inurl:rubp.php?idr= inurl:offer .php?idf= inurl:art.php?idm= inurl:title.php?id=

RO OLLEGELO GFUNDINGFUND ONLINEVISIONONLINE COLLEGELOGINCOLLEGELO ERPROGRESSLEARNERPROGRESSL NONLINEVISIONONLINEVISIONONLIN INGFUNDINGFUNDINGFUNDINGFUN ADATADATADATADATADATADATAD IONONLINEVISIONONLINEVISIONFUN

More information

McAfee VirusScan Enterprise 8.7 Users Guide MCAFEE VIRUSSCAN 8.7 (VS) USER"S GUIDE This document aims to introduce to the users McAfee VS 8.7 software and covers information about how to use it in order

More information

Sophos Anti-Virus for NetApp Storage Systems user guide Product version: 3.0 Document date: May 2014 Contents 1 About this guide...3 2 About Sophos Anti-Virus for NetApp Storage Systems...4 3 System requirements...5

More information

Ethical Hacking and Pentesting Vito Rallo, IBM Security Services Penetration Testing Have a Smartphone? SCAN ME Hackers and Ethical Hackers The hacker manifesto: Yes, I am a criminal. My crime is that

More information

Automated vulnerability scanning and exploitation Dennis Pellikaan Thijs Houtenbos University of Amsterdam System and Network Engineering July 4, 2013 Dennis Pellikaan, Thijs Houtenbos Automated vulnerability

More information

Automated vulnerability scanning and exploitation Dennis Pellikaan Thijs Houtenbos University of Amsterdam System and Network Engineering October 22, 2013 Dennis Pellikaan, Thijs Houtenbos Automated vulnerability

More information

Server-side: PHP and MySQ webserver e.g. Apache)) PHP MySQ!" #$$%& ")& +", -../ -0 &0/ 1 +"1& " hello echo "hello") ; 1 2 "2 & 3&

More information

Web Security CS25010 20th November 2012 Session Errors Some people are having errors creating sessions: Warning: session_start() : open(/var/php_sessions/sess_d7hag76hgsfh2bjuhmdamb974,

More information

Technical Report Antivirus Solution Guide for Clustered Data ONTAP 8.2.1: McAfee Saurabh Singh and Brahmanna Chowdary Kodavali, NetApp June 2015 TR-4286 Abstract An antivirus solution is key for enterprises

More information

Scenario Planning March 15, 2011 Overview Kathy Keeley Northland Foundation Definition Scenario planning is defined as a strategic planning method that organizations use to make flexible long-term plans

More information

Problem Set 7: C$50 Finance due by noon on Thu 11/3 Per the directions at this document s end, submitting this problem set involves submitting source code via submit50 as well as filling out a Web-based

More information

OS X - Quick Start Guide Turning on the computer and logging on: 1. Turn on the computer by pressing the Power Button: emac - the right side of the computer near power plug older full sided imac - on the

More information

CYAN SECURE WEB APPLIANCE User interface manual Jun. 13, 2008 Applies to: CYAN Secure Web 1.4 and above Contents 1 Log in...3 2 Status...3 2.1 Status / System...3 2.2 Status / Network...4 Status / Network

More information

d-files10 d-files25 d-files50 d-files75 d-files100 Initial Kit d-files25 CHECKED by: V. PARISI APPROVED by: G. PALMIERI TEL 522567

More information

Web based document management Simple, Yet Sophisticated Workflow HTML Forms Business Process Automation A guide to capture tools for VisualVault Business Process Automation Document management systems

More information

TWAIN/WIA Driver Operation Guide Introduction This Operaiton Guide explains the procedures for scanning image data by using the TWAIN Driver or WIA Driver. Image Data Scanning with TWAIN / WIA Download

More information

1 of 22 9/20/2010 4:59 PM MySQL Commands Posted on 07-25-2007 00:13:00 UTC Updated on 01-21-2010 02:40:23 UTC Section: /software/mysql/ Permanent Link Tier IV Data Center Colocation Houston SAS70 Audited

More information

360 Degree Survey Your supervisor/colleague would like to get your feedback about their strengths and areas of opportunity as a supervisor. Your honest feedback and specific comments will support them

More information

26.5 Eligibility Tracking Table of Contents UNDERSTANDING CHAPTER 26.5 ELIGIBILITY TRACKING... 2 WHO CAN PERFORM THIS FUNCTION?... 2 MENU PATH... 2 26.5 Pre Display Screen... 2 26.5 Eligibility Tracking

More information

Using Protection Engine for Cloud Services for URL Filtering, Malware Protection and Proxy Integration Hands-On Lab Description In this hands-on session, you will learn how to turn your proxy into a security

More information

The Drobo 5N provides easy, affordable networked attached storage for the connected home or small office. Copy, a new cloud-based service from Barracuda, provides users with the easiest place to store,

More information

The Case of the RSA FUCK-A-DUCK certificate Nadia Heninger Zakir Durumeric Eric Wustrow J. Alex Halderman N=pq SSL certificates We scanned the Internet SSL certificates We scanned the Internet (It was

More information

RC_RFC: 5 RNPP: Computer Networking Program Protocol Specifications October 2014 Prepared for Computer Networking, 2nd Year Grade of Computer Science Engineering University of Seville by Lecturers of the

More information

The fourth sector of the DW2.0 environment is the archival sector. Fig arch.1 shows the architectural positioning of the archival sector. Fig arch.1 The archival sector All data that flows into the archival

More information

RIPS - A static source code analyzer for vulnerabilities in PHP scripts Johannes Dahse Seminar Work at Chair for Network and Data Security Prof. Dr. Jörg Schwenk advised through Dominik Birk 23.08.2010

Technology asset management is essential to the delivery of the IT management vision and all its service components. In order to plan related policies and procedures, seven (7) key operational elements

More information

Plex is a media management system that organizes your entire collection of movies, music, and photos making them available to all media devices in the connected home and remotely accessible by Internet

More information

Build Your Own Database Driven Website Using PHP and MySQL, 3 rd Edition (First 4 Chapters) Thank you for downloading the first four chapters of Kevin Yank s Build Your Own Database Driven Website Using

More information

Summary of Contents Preface... ix 1. Installation... 1 2. Getting Started with MySQL... 29 3. Getting Started with PHP... 43 4. Publishing MySQL Data on the Web... 67 5. Relational Database Design... 85

More information

Overcoming The Fear Factor: Creating a Dynamic Web Site DIANA FARMER 1 and YONGLI ZHOU 2 1 Hale Library, Kansas State University, Manhattan, Kansas, USA 2 Morgan Library, Colorado State University, Fort

More information

Paolo Alessandro Villa Portfolio Index International retail company - Touchscreen application 2 ICBPI - Data management dashboard 7 Telecom Italia - techical operator android app 11 Banca Mediolanum -

More information

The Drobo 5N provides simple and affordable network attached storage for the connected home or small office. ElephantDrive is a cloud-based service that provides real-time protection of all, or a subset

More information

McAfee VirusScan Enterprise for Storage.0 Sizing Guide for NetApp Filer on Data ONTAP 7.x COPYRIGHT Copyright 200 McAfee, Inc. All Rights Reserved. No part of this publication may be reproduced, transmitted,

More information

EPrintsHybridStorageTraining TableofContents 1Introduction EPrintsHybridStorage ManagementandConfiguration 1Introduction... 1 2PowerfulStorage... 2 3Viewingyourstorageserviceusages... 3 4ManagingyourStoragePolicy(Exercises)...

More information

SuSE File and with SuSE Linux Enterprise Server 8 SuSE Linux AG Whitepaper SuSE File and with SuSE Linux Enterprise Server 8 Overview. 3 File Services The User View 3 The Administrator View 3 Samba Web

More information

Table of Contents MyNetFone Virtual Fax MyNetFone Virtual Fax Installation... 1 Changing the SIP endpoint details for the fax driver... 11 Uninstalling Virtual Fax... 13 Virtual Fax Installation Follow

More information

A quick theoretical introduction to network scanning January 8, 2016 Disclaimer/Intro Disclaimer/Intro Network scanning is not exact science When an information system is able to interact over the network

More information

Swaddler: An Approach for the Anomaly-based Detection of State Violations in Web Applications Marco Cova, Davide Balzarotti, Viktoria Felmetsger, and Giovanni Vigna Department of Computer Science, University

More information

Det håndholdte ultralydapparateten nyvinning for hvem? Overlege Dr. med Bjørn Olav Haugen Bjørn Olav Haugen Post doc. MI lab/ntnu Consultant Cardiologist. Dept. of Cardiology St. Olav Trondheim 1 ACUSON

More information

An Oracle Technical White Paper May 2015 How to Configure Kaspersky Anti-Virus Software for the Oracle ZFS Storage Appliance Table of Contents Introduction... 2 How VSCAN Works... 3 Installing Kaspersky

More information

Document Management System 5.6A User Guide Software Documentation This document is the software documentation for the Sage Accpac Document Management System module developed by Visionetix Software. All

More information

A SQL Injection: Internal Investigation of Injection, Detection and Prevention of SQL Injection Attacks Abhay K. Kolhe Faculty, Dept. Of Computer Engineering MPSTME, NMIMS Mumbai, India Pratik Adhikari

More information

Technical Specification WAP Billing (WB.001) Author(s): Erwin van den Boom Silvan van der Veen Michel Westerink (EvdB) (SvdV) (MW) Version history V1.5 MW 9 december 2009 V1.4 V1.3 SvdV SvdV November 23

More information

Configuring Symantec AntiVirus for NetApp Storage system Configuring Symantec AntiVirus for NetApp Storage system The software described in this book is furnished under a license agreement and may be used

More information

Multi-Module Vulnerability Analysis of Web-based Applications Davide Balzarotti, Marco Cova, Viktoria V. Felmetsger, and Giovanni Vigna Computer Security Group University of California, Santa Barbara Santa

More information

Norman Data Defense Systems Oliver Kunzmann Support Manager Author: Oliver Kunzmann. Viren 2004 Bagle.A January MyDoom.A MyDoom.B Netsky.A Netsky.B Netsky.C1 Bagle.C Bagle.D Bagle.E Bagle.F February Bagle.G

More information

Bucharest, July 31, 2012 Cloud Security for Endpoints Customer Presentation Pag. 4 Traditional security pitfalls On-premise management server complexities Too cumbersome for organizations that lack servers

More information

Sample Analysis Design Element2 - Basic Software Concepts Scan Modes Magnetic Scan (BScan): the electric field is kept constant and the magnetic field is varied as a function of time the BScan is suitable

More information

An Oracle Technical White Paper January 2014 How to Configure Symantec Protection Engine for Network Attached Storage for the Oracle ZFS Storage Appliance Table of Contents Introduction... 3 How VSCAN

More information

Customer & Market Analysis Sample Report (actual data) Introduction This Customer & Market Analysis is intended to provide you with a modeled view of your customers, based on statistical analysis. This

More information

Ulteo Open Virtual Desktop - Protocol Description Copyright 2008 Ulteo SAS 1 LIST OF PROTOCOLS USED CONTENTS Contents 1 List of Protocols used 1 1.1 Hyper Text Transfert Protocol (HTTP).................. ............

More information

An Oracle Technical White Paper January 2014 How to Configure the Trend Micro IWSA Virus Scanner for the Oracle ZFS Storage Appliance Table of Contents Introduction... 2 How VSCAN Works... 3 Installing

More information

# SAIC CoM 2014 RG R79343 1. What is your highest known merchant level (1, 2, 3, or 4) as assigned by your acquirer? 2. Approximately how many credit card transactions do you process per year? 300,000;

More information

1 2 SAMS Teach Yourself PHP4 in 24 Hours Matt Zandstra A Division of Macmillan USA 201 West 103rd St., Indianapolis, Indiana, 46290. USA Copyright 2000 by Sams Publishing All rights reserved. no part

More information

LED Standard lamps LED Candle lamps LED Ball lamps LED Spot lamps, shape A60 Switching cycle 20.000 times Dimension 108x60 mm Dimmable and equivalent to 40W 800500 E27 8 Watt 470 Lm 800501 B22 8 Watt 470

More information

NetDefend Firewall UTM Services Unified Threat Management D-Link NetDefend UTM firewalls (DFL-260/860) integrate an Intrusion Prevention System (IPS), gateway AntiVirus (AV), and Web Content Filtering

More information

Accounting Bachelor of Science (52.030100) Employment Employment Available for Unavailable Number 33 1 0 0 0 1 0 8 43 Percent of Total 76.7% 2.3% 0.0% 0.0% 0.0% 2.3% 0.0% 18.6% 100.0% Employment Employment

More information

Qualys is a vulnerability scanner that is used for critical servers and servers subject to compliance reporting. This scanner is not generally to be used for desktop or laptop scanning. OIT has purchased

More information

T23 Concurrent Class 10/3/2013 3:00:00 PM "The Google Hacking Database: A Key Resource to Exposing Vulnerabilities" Presented by: Kiran Karnad Mimos Berhad Brought to you by: 340 Corporate Way, Suite 300,

Module: Leadership Training Workshop for Health Professionals Organization: East Africa HEALTH Alliance Author(s): Dr. Roy William Mayega, 2009-2012 Resource Title: Session 2: The Relationship Between

Every person who at least once engaged in the promotion or building up of puzomer sites faced the problem of the lack of good catalog databases, sites, etc. in free access. Many people buy bases, I usually assemble them myself.

What is needed for this:

Help on the query language for searching in Yandex http://help.yandex.ru/search/?id=481939
- Same for Google search http://www.google.ru/help/operators.html
- Some kind of parser Allsubmitter, Hrefer, AGGRESS Parser

I limited myself to two PS, you can use yahu, bing, mail ...

Let's start, for example, we will try to pull out as many DLE sites as possible. We go to any site on this engine, and look for characteristic features, i.e. what is on every site.

What does each DLE site have?

Registration page located at http://domain.ru/index.php?do=register
- page with feedback form http://domain.ru/index.php?do=feedback
- statistics page http://domain.ru/index.php?do=stats
- page with rules during registration (not for everyone, appeared in the latest versions) http://domain.ru/index.php?do=rules

Google has a useful operator for finding pages containing the desired text in their address, it is called inurl. Those. to find all registration pages, we google inurl:”index.php?do=register”, to find feedback pages inurl:”index.php?do=feedback”, etc. Trying to find inurl:”index.php?do=register”, found: 1,330,000, but there is a problem.

For each request, Google and Yandex give only a thousand results, so you need as many signs as possible, while there are 4, then we “dilute” each sign with some words that occur on the page we are looking for, for example, from the inurl:”index.php sign ?do=register”, we will do the following:

Inurl:”index.php?do=register” “registration”
- inurl:”index.php?do=register” “password”
- inurl:”index.php?do=register” “retype password”
- inurl:”index.php?do=register” “Security Code”
- inurl:”index.php?do=register” “Enter code”
- inurl:”index.php?do=register” “Verify security code”

All words are standard, you can also add English, Ukrainian and other variants of the same words here if you need a database of not only Russian-language sites. In Yandex, everything is similar, only the inurl operator is slightly different, see the help.

While we were considering the operator for searching by the page address, let's consider another parsing option: search by the page title: intitle - in Google and title - in Yandex. Let's try to search for the title of the registration page:

intitle:"Visitor registration", some garbage appeared, we don't need sites that do not work on dle, it's not difficult to filter them out, we'll do the same as when searching by the page address, add a word for a more accurate search:

intitle:"Visitor registration" "Security code", now only DLE and no garbage. Search in Yandex by page title is carried out in almost the same way.

For parsing, I use allsubmitter, it’s nice and easy to use, we add all the features to it, of course, we first take the Goulian ones, and parse Google, then parse Yandex. I parsed 12k sites by going through a quarter of the signs, after removing duplicates, 3.5k remained for sites.

It seems that everything, the most difficult thing to find in engines is what will make Yandex or Google display the list of sites you need, for example, in easybook - this is the page address for reading, adding entries, in addition to the usual address, you can try to search for CNC addresses of the desired pages. In Drupal, for example, entries have the address /node/record_number…

This is the easiest way to find the right sites, there are others…