Наиболее распространенные имена папок

Discussion in 'Уязвимости' started by Xex, 4 Jan 2007.

  1. Xex

    Xex Banned

    Joined:
    10 Jul 2005
    Messages:
    108
    Likes Received:
    41
    Reputations:
    7
    Привет! Кто нить знает где взять списочек имен папочек наиболее распространенных для веб-сервера?

    Типа /inc/ /images/ /include/ /admin/

    Говорят типа в хспайдере есть...но не уверен.
     
  2. blaga

    blaga Elder - Старейшина

    Joined:
    23 Mar 2006
    Messages:
    884
    Likes Received:
    273
    Reputations:
    106
    При желании можно самому написать. В чем проблема? Или написать пхп скрипт который будет все папки прошаривать и их названия сохранять, штуки 4 хостов, и у тебя такой список есть.
     
    1 person likes this.
  3. aka PSIH

    aka PSIH Elder - Старейшина

    Joined:
    7 Feb 2006
    Messages:
    582
    Likes Received:
    284
    Reputations:
    51
    Xspider хорошо ищет такие папки
    Nikto - тоже хороший сканер, и папки ищет и уязвимости
    http://www.cirt.net/nikto/nikto-current.tar.gz
     
    1 person likes this.
  4. DIAgen

    DIAgen Banned Life!

    Joined:
    2 May 2006
    Messages:
    1,055
    Likes Received:
    376
    Reputations:
    460
    Вот основные папки
    Можно по желаюнию дополнить этот список ;)
     
    1 person likes this.
  5. max_pain89

    max_pain89 Eat `em UP!

    Joined:
    11 Dec 2004
    Messages:
    451
    Likes Received:
    140
    Reputations:
    146
    у меня самым распространенным считается "Новая папка" и "Новая папка(2)"
     
  6. Xex

    Xex Banned

    Joined:
    10 Jul 2005
    Messages:
    108
    Likes Received:
    41
    Reputations:
    7
    Всех отблагодарил, буду признателен, если еще кто нить еще подкинет списочек аналогичный=)
     
  7. Robin_Hood

    Robin_Hood Elder - Старейшина

    Joined:
    30 Oct 2006
    Messages:
    144
    Likes Received:
    155
    Reputations:
    47
    /dir/
    /home/
    /members/
    /customers/
    /seller/
    /buy/
    /other/
    /host/
    /php/
    /docs/
    /acc/
    /folder/
    /money/
     
    1 person likes this.
  8. darky

    darky ♠ ♦ ♣ ♥

    Joined:
    18 May 2006
    Messages:
    1,773
    Likes Received:
    825
    Reputations:
    1,418
    http://someshit.nm.ru/br/cgi.txt

    правда там не только папки, но 60% ..
     
    2 people like this.
  9. Robin_Hood

    Robin_Hood Elder - Старейшина

    Joined:
    30 Oct 2006
    Messages:
    144
    Likes Received:
    155
    Reputations:
    47
    отсортировал то что дал blackybr:
    Code:
    /password
    /perl
    /srchadm
    /scripts/
    /cgi-bin/
    /cgi_bin/
    /cgibin/
    /cgi/
    /bin/
    /inc/
    /include/
    /msadc/
    /logs/
    /log/
    /root/
    /wwwroot/
    /samples/
    /user/
    /users/
    /usage/
    /adm/
    /admin/
    /etc/
    /pub/
    /public/
    /var/
    /upload/
    /client/
    /clients/
    /order/
    /orders/
    /source/
    /sources/
    /remote/
    /address/
    /access/
    /get/
    /read/
    /view/
    /save/
    /setup/
    /security/
    /db/
    /default/
    /database/
    /pass/
    /passwd/
    /password/
    /passwords/
    /global/
    /login/
    /logins/
    /alias/
    /aliases/
    /beta/
    /test/
    /test12/
    /info/
    /ini/
    /doc/
    /docs/
    /code/
    /codes/
    /email/
    /emails/
    /group/
    /groups/
    /key/
    /keys/
    /mail/
    /mails/
    /ip/
    /host/
    /hosts/
    /service/
    /services/
    /phone/
    /phones/
    /write/
    /forwrite/
    /sys/
    /sysadmin/
    /system/
    /system32/
    /img/
    /images/
    /iisadmin/
    /iissamples/
    /iisadmpwd/
    /forum/
    /chat/
    /aux
    /domcfg/
    /tools/
    /wusage/
    /wstats/
    /wsdocs/
    /WS_fTP.log
    /wforum/passwd.txt
    /wforum/
    /WebTrend/
    /webstats/
    /website/
    /WebShop/templates/cc.txt
    /WebShop/logs/cc.txt
    /WebShop/logs/
    /WebShop/
    /weblogs/
    /weblog/
    /webdata/
    /webcart/
    /webboard/password.txt
    /webboard/password
    /webboard/passwd.txt
    /webboard/passwd
    /webboard/
    /webadmin/
    /webaccess/access-options.txt
    /Web_store/
    /web/bb-hist.sh
    /web/
    /wboard/passwd.txt
    /wboard/
    /way-board/way-board.cgi
    /wais.pl
    /w3perl/admin
    /ustats/
    /usr/adm/
    /users/scripts/submit.cgi
    /users/scripts/admin.cgi
    /users/
    /user/
    /usage/
    /uploads/patch.exe
    /updates/
    /ultraboard.pl
    /tree/
    /trafficlog/
    /tools/newdsn.exe
    /tools/
    /tools/
    /today.nsf
    /tmp/sims_setup.dat
    /tmp/
    /test-cgi/
    /test/test.cgi
    /test/
    /temp/
    /technote/technote/print.cgi
    /tcb/files/auth/?/
    /tcb/files/auth
    /tcb/files/
    /tcb/auth/files/?/
    /tcb/auth/files/
    /tcb/auth/
    /tcb/
    /support/
    /super_stats/access_logs
    /sults_Test/testorder.txt
    /StoreDB/
    /store/
    /status/
    /status
    /Stats/
    /stats/
    /statistics/
    /stat/
    /ssi/envout.bat
    /ss.cfg
    /srchadm
    /sql/
    /source/
    /software/
    /shopper/
    /shop/product.ast 
    /shop/product.asp 
    /shop/
    /shop/
    /setup/
    /server-status
    /server-info
    /server_stats/
    /server%20logfile
    /sell/
    /retail/
    /reseller/
    /registered/
    /register/
    /pw/
    /purchases/
    /purchase/
    /publisher/publish/
    /publisher/
    /publish/
    /public/
    /passwords/
    /pages/
    /order/
    /oracle/
    /news/
    /new/
    /logs/access_log
    /logs/ 
    /login/
    /logging/
    /logger/
    /logfiles/
    /logfile/
    /log/
    /log.nsf
    /info/
    /index.asp::$DATA
    /incoming/
    /includes/global.inc
    /import/
    /ftp/
    /fpadmin/
    /dos/ 
    /domlog.nsf
    /domcfg/
    /domcfg.nsf/?open
    /domcfg.nsf
    /docs/
    /doc-html/
    /doc/
    /doc 
    /DMR/
    /default.asp::$DATA
    /debug.txt
    /ddrint/bin/ddicgi.exe
    /dbase/
    /db/
    /databases/
    /database/
    /DataBase/
    /database/
    /database.nsf
    /data/
    /dat/
    /customers/
    /credit/
    /cp/rac/nsManager.cgi
    /config/import.txt
    /config/html/cnf_gi.htm
    /config/
    /config.inc
    /con
    /com3/
    /com2/
    /com1/
    /cfdocs/
    /ccard/
    /catalyst/exec/show/config/cr
    /catalog.nsf
    /cart/
    /carbo.dll?icatcommand=..\..\boot.ini&catalogname=catalog 
    /cache-stats/
    /c/
    /buynow/
    /bin/test.txt
    /bin/sh/
    /bin/scripts/Fpadmcgi.exe
    /bin/fpsrvadm.exe
    /bin/fpremadm.exe
    /bin/fpadmin.htm
    /bin/contents.htm
    /bin/cfgwiz.exe
    /bin/admin.pl
    /bin/
    /bin
    /backup/
    /aux/
    /aux
    /admisapi/
    /admisapi/
    /admin-serv/
    /admin-serv/
    /adminlogin
    /administrator/
    /admin4.nsf
    /Admin_files/
    /Admin_files/
    /admin/passwd.txt
    /admin/passwd.html
    /admin/main.cfm
    /admin/login.cfm
    /admin/
    /admin.php3
    /admcgi/contents.htm
    /admcgi/
    /accounting/
    /account/
    /access/
    /about/
    /acart/
    /access/
    /account/
    /achievo/
    /address/
    /adm/
    /admin/
    /administration/
    /admins/
    /AdminWeb/
    /alias/
    /aliases/
    /allow/
    /alpha/
    /apache/
    /application/
    /applications/
    /arc/
    /archive/
    /archives/
    /article/
    /articles/
    /audit/
    /auth/
    /b/
    /backup/
    /bank/
    /beta/
    /billpay/
    /bin/
    /boardroom/
    /boot/
    /c/
    /cache/
    /card/
    /cards/
    /cash/
    /catalog/
    /cbi-bin/
    /cdrom/
    /CertControl/
    /CertEnroll/
    /certsrv/
    /cgi/
    /cgi-auth/
    /cgi-bin/
    /cgi-bin2/
    /cgi_bin/
    /cgi-csc/
    /cgi-lib/
    /cgi-local/
    /cgi-scripts/
    /cgi-shl/
    /cgi-shop/
    /cgi-src/
    /cgi-sys/
    /cgi-temp/
    /cgi-win/
    /cgibin/
    /chat/
    /check/
    /citrix/
    /class/
    /classes/
    /client/
    /clients/
    /closeup/
    /code/
    /codes/
    /component/
    /components/
    /conf/
    /config/
    /connect/
    /console/
    /control/
    /css/
    /CS/
    /cvsweb/
    /CVS/
    /cybercash/
    /d/
    /dat/
    /data/
    /database/
    /databases/
    /db/
    /default/
    /demo/
    /deny/
    /development/
    /dir/
    /directory/
    /dirs/
    /disk/
    /disks/
    /distr/
    /distrib/
    /DMR/
    /doc/
    /doc-html/
    /docs/
    /document/
    /documents/
    /down/
    /download/
    /downloads/
    /e/
    /email/
    /emails/
    /error/
    /errors/
    /etc/
    /example/
    /examples/
    /exe/
    /f/
    /file/
    /files/
    /films/
    /find/
    /forum/
    /forums/
    /forwrite/
    /foto/
    /fotos/
    /g/
    /gallery/
    /general/
    /get/
    /global/
    /gold/
    /group/
    /groups/
    /guest/
    /GXApp/
    /gui/
    /h/
    /HB/
    /help/
    /hide/
    /home/
    /host/
    /hosts/
    /i/
    /ibank/
    /ibill/
    /iisadmin/
    /iisadmpwd/
    /iishelp/
    /iissamples/
    /image/
    /images/
    /img/
    /inc/
    /include/
    /index/
    /info/
    /ini/
    /international/
    /ip/
    /isapi/
    /j/
    /java/
    /jdbc/
    /js/
    /jserv/
    /jsp/
    /k/
    /key/
    /keys/
    /l/
    /labs/
    /lib/
    /library/
    /list/
    /log/
    /Log/
    /login/
    /logins/
    /logon/
    /logout/
    /logs/
    /look/
    /m/
    /mail/
    /Mail/
    /mailroot/
    /mails/
    /makefile/
    /master/
    /members/
    /money/
    /mp3/
    /mrtg/
    /msadc/
    /MSMQ/
    /mssql/
    /mysql/
    /n/
    /net/
    /netcat/
    /network/
    /new/
    /NSearch/
    /o/
    /odbc/
    /oetaki/
    /old/
    /order/
    /orders/
    /p/
    /pass/
    /passport/
    /passwd/
    /password/
    /passwords/
    /path/
    /paths/
    /PBSData/
    /PBServer/
    /perl/
    /perl5/
    /phone/
    /phones/
    /photo/
    /php/
    /phpBB/
    /phpnuke/
    /phpproject/
    /picture/
    /pictures/
    /post/
    /postgres/
    /printer/
    /printers/
    /priv/
    /private/
    /product/
    /products/
    /pub/
    /public/
    /q/
    /r/
    /rdp/
    /read/
    /register/
    /registration/
    /remote/
    /rep/
    /report/
    /reports/
    /res/
    /resource/
    /resources/
    /result/
    /results/
    /root/
    /rpc/
    /s/
    /sample/
    /samples/
    /save/
    /scripts/
    /search/
    /secure/
    /security/
    /send/
    /servers/
    /service/
    /services/
    /session/
    /sessions/
    /set/
    /sets/
    /setting/
    /settings/
    /setup/
    /shutdown/
    /silver/
    /slave/
    /soft/
    /sound/
    /source/
    /sources/
    /src/
    /ssl/
    /ssi/
    /stat/
    /stats/
    /status/
    /style/
    /sys/
    /sysadmin/
    /sysinfo/
    /system/
    /system32/
    /t/
    /temp/
    /template/
    /templates/
    /test/
    /test-cgi/
    /test12/
    /ToDo/
    /tmp/
    /tree/
    /trust/
    /tsweb/
    /u/
    /uddi/
    /uddipublic/
    /update/
    /updates/
    /upload/
    /usage/
    /user/
    /users/
    /util/
    /utils/
    /v/
    /var/
    /video/
    /view/
    /w/
    /webaccess/
    /webadmin/
    /webboard/
    /WebBank/
    /weblog/
    /WebShop/
    /write/
    /wwwlog/
    /wwwroot/
    /x/
    /xml/
    /y/
    /z/
    /zip/
    /_backup/
    /_errors/
    /_mem_bin/
    /_pages/
    /_private/
    /_scripts/
    /_vti_bin/
    /_vti_bot/
    /_vti_cnf/
    /_vti_log/
    /_vti_pvt/
    /_vti_script/
    /_vti_shm/
    /_vti_txt/
    /?PageServices
    /?wp-cs-dump
    /1/
    /2/
    /3/
    /4/
    /5/
    /6/
    /7/
    /8/
    /9/
    /0/
    /123/
    /12345/
    /111/
    
     
  10. Xex

    Xex Banned

    Joined:
    10 Jul 2005
    Messages:
    108
    Likes Received:
    41
    Reputations:
    7
    воот=)
    уже серьезный список=)
    всем спасибо отдал плюсами и словами

    Буду непротив, если этот список еще пополнится=))
     
  11. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    у меня лист 26к. записей...
    могу поменяться с владеотцами аналогичных листов.
     
  12. n0ne

    n0ne Elder - Старейшина

    Joined:
    1 Jan 2007
    Messages:
    542
    Likes Received:
    284
    Reputations:
    -56
    Напиши в гугле inurl:robots.txt , папок будет много :D
     
  13. Robin_Hood

    Robin_Hood Elder - Старейшина

    Joined:
    30 Oct 2006
    Messages:
    144
    Likes Received:
    155
    Reputations:
    47
    Code:
    <?php
    $directories = glob("/tmp/*", GLOB_ONLYDIR);
    $complete = glob("/tmp/*");
    $files = array_diff($directories, $complete);
    
    echo "каталоги в /tmp/<BR>";
    
    foreach($directories as $val) {
    echo "$val<BR>\n";
    }
    echo"<BR>Файлы в /tmp/<BR>";
    
    foreach($files as $val) {
    echo "$val<BR>\n";
    }
    
    наконецто дошли руки)
    вместо tmp ставим корневую папку, выводит все подкаталоги и файлы, скидуем в свой список
     
    #13 Robin_Hood, 12 Jan 2007
    Last edited: 12 Jan 2007