Learn how to Make Money Online doing freelancing, Affiliate Marketing, Blogging and many more ...
Go4Expert
Go4Expert RSS Feed

Go Back   Programming and SEO Forum >  Go4Expert > Articles / Source Code > Ethical hacking

Discuss / Comment  Copy HTML to Clipboard  Copy BBCode to Clipboard  | More
 
Bookmarks Article Tools Search this Article Display Modes

Get full access thru "Welcome to phpMyAdmin"


On 18th July, 2008
Get full access thru "Welcome to phpMyAdmin"

Show Printable Version Email this Page Subscription Add to Favorites Copy Get full access thru "Welcome to phpMyAdmin" link

Author

P455w0rd_Cr4kz ( Ambitious contributor )

Yet to provide details about himself


All articles By P455w0rd_Cr4kz

Recent Articles

Similar Articles

Noobs,don't go crazy messing up people sites,this is to make awareness of how negligent can an administrator be.

1- Why deface when you can own it?
Go to Google and type this:
intitle:PhpMyAdmin "Welcome to phpMyAdmin***" running on * as root@*"

This will give you tons of no passworded phpMyAdmin,means you'll have access to all files,can make changes ect.
======================================
To find websites Admin Password type the following in the Google bar:
inurl:vti_pvt "service.pwd"
(password will be encrypted) "convert encrypted password to md5 hash then use milw0rm

Also You can You use this codes when you have free time..enjoy

Google Search strings
-------------------------
  • inurl:/db/main.mdb |ASP-Nuke passwords
  • filetype:cfm "cfapplication |ColdFusion source with potential passwords name" password
  • filetype:pass |dbman credentials pass intext:userid
  • allinurl:auth_user_file.txt |DCForum user passwords
  • eggdrop filetype:user user |Eggdrop IRC user credentials
  • filetype:ini inurl:flashFXP.ini |FlashFXP FTP credentials
  • filetype:url +inurl:"ftp://" |FTP bookmarks cleartext passwords
    +inurl:"@"
  • inurl:zebra.conf intext: |GNU Zebra passwords
    password -sample -test
    -tutorial –download
  • filetype:htpasswd htpasswd |HTTP htpasswd Web user credentials
  • intitle:"Index of" ".htpasswd" |HTTP htpasswd Web user credentials
    "htgroup" -intitle:"dist"
    -apache -htpasswd.c
  • intitle:"Index of" ".htpasswd" |HTTP htpasswd Web user credentials
    htpasswd.bak
  • "http://*:*@www" bob:bob |HTTP passwords (bob is a sample username)
  • "sets mode: +k" |IRC channel keys (passwords)
  • "Your password is * |Remember IRC NickServ registration passwords
    this for later use"
  • signin filetype:url |JavaScript authentication credentials
  • LeapFTP intitle:"index.of./" |LeapFTP client login credentials
    sites.ini modified
  • inurl:lilo.conf filetype:conf |LILO passwords
    password -tatercounter2000
    -bootpwd –man
  • filetype:config config intext: |Mcft .NET application credentials
    appSettings "User ID"
  • filetype:pwd service |Mcft FrontPage Service Web passwords
  • intitle:index.of |Mcft FrontPage Web credentials
    administrators.pwd
  • "# -FrontPage-" |Mcft FrontPage Web passwords
    inurl:service.pwd
    ext:pwd inurl:_vti_pvt inurl: |Mcft FrontPage Web passwords
    (Service | authors | administrators)
  • inurl:perform filetype:ini |mIRC nickserv credentials
  • intitle:"index of" intext: |mySQL database credentials
    connect.inc
  • intitle:"index of" intext: |mySQL database credentials
    globals.inc
  • filetype:conf oekakibbs |Oekakibss user passwords
  • filetype:dat wand.dat |Opera‚ ÄúMagic Wand‚Äù Web credentials
  • inurl:ospfd.conf intext: |OSPF Daemon Passwords
    password -sample -test
    -tutorial –download
  • index.of passlist |Passlist user credentials
  • inurl:passlist.txt |passlist.txt file user credentials
  • filetype:dat "password.dat" |password.dat files
  • inurl:password.log filetype:log |password.log file reveals usernames,
    |passwords,and hostnames
  • filetype:log inurl:"password.log" |password.log files cleartext
    |passwords
  • inurl:people.lst filetype:lst |People.lst generic password file
  • intitle:index.of config.php |PHP Configuration File database
    |credentials
  • inurl:config.php dbuname dbpass |PHP Configuration File database
    |credentials
  • inurl:nuke filetype:sql |PHP-Nuke credentials
  • filetype:conf inurl:psybnc.conf |psyBNC IRC user credentials
    "USER.PASS="
  • filetype:ini ServUDaemon |servU FTP Daemon credentials
  • filetype:conf slapd.conf |slapd configuration files root password
  • inurl:"slapd.conf" intext: |slapd LDAP credentials
    "credentials" -manpage
    -"Manual Page" -man: -sample
  • inurl:"slapd.conf" intext: |slapd LDAP root password
    "rootpw" -manpage
    -"Manual Page" -man: -sample
  • filetype:sql "IDENTIFIED BY" –cvs |SQL passwords
  • filetype:sql password |SQL passwords
  • filetype:ini wcx_ftp |Total Commander FTP passwords
  • filetype:netrc password |UNIX .netrc user credentials
  • index.of.etc |UNIX /etc directories contain
    |various credential files
  • intitle:"Index of..etc" passwd |UNIX /etc/passwd user credentials
  • intitle:index.of passwd |UNIX /etc/passwd user credentials
    passwd.bak
  • intitle:"Index of" pwd.db |UNIX /etc/pwd.db credentials
  • intitle:Index.of etc shadow |UNIX /etc/shadow user credentials
  • intitle:index.of master.passwd |UNIX master.passwd user credentials
  • intitle:"Index of" spwd.db |UNIX spwd.db credentials
    passwd -pam.conf
  • filetype:bak inurl:"htaccess| |UNIX various password file backups
    passwd|shadow|htusers
  • filetype:inc dbconn |Various database credentials
  • filetype:inc intext:mysql_ |Various database credentials, server names
    connect
  • filetype:properties inurl:db |Various database credentials, server names
    intext:password
  • inurl:vtund.conf intext:pass –cvs |Virtual Tunnel Daemon passwords
  • inurl:"wvdial.conf" intext: |wdial dialup user credentials
    "password"
  • filetype:mdb wwforum |Web Wiz Forums Web credentials
  • "AutoCreate=TRUE password=*" |Website Access Analyzer user passwords
  • filetype:pwl pwl |Windows Password List user credentials
  • filetype:reg reg +intext: |Windows Registry Keys containing user
    "defaultusername" intext: |credentials
    "defaultpassword"
  • filetype:reg reg +intext: |Windows Registry Keys containing user
    "internet account manager" |credentials
  • "index of/" "ws_ftp.ini" |WS_FTP FTP credentials
    "parent directory"
  • filetype:ini ws_ftp pwd |WS_FTP FTP user credentials
  • inurl:admin filetype: |asp Generic userlist files
    inurl:userlist |
  • inurl:php inurl: |Half-life statistics file, lists username and
    hlstats intext: |other information
    Server Username |
  • filetype:ctl |
    inurl:haccess. |Mcft FrontPage equivalent of htaccess
    ctl Basic |shows Web user credentials
  • filetype:reg |
    reg intext: |Mcft Internet Account Manager can
  • "internet account manager" |reveal usernames and more
    filetype:wab wab |Mcft Outlook Express Mail address
    |books
  • filetype:mdb inurl:profiles |Mcft Access databases containing
    |profiles.
  • index.of perform.ini |mIRC IRC ini file can list IRC usernames and
    |other information
  • inurl:root.asp?acs=anon |Outlook Mail Web Access directory can be
    |used to discover usernames
  • filetype:conf inurl:proftpd. |PROFTP FTP server configuration file
    conf –sample |reveals
    |username and server information
  • filetype:log username putty |PUTTY SSH client logs can reveal
    |usernames
    |and server information
  • filetype:rdp rdp |Remote Desktop Connection files reveal user
    |credentials
  • intitle:index.of |UNIX bash shell history reveals commands
    .bash_history |typed at a bash command prompt; usernames
    |are often typed as argument strings
  • intitle:index.of |UNIX shell history reveals commands typed at
    .sh_history |a shell command prompt; usernames are
    |often typed as argument strings
  • "index of " lck |Various lock files list the user currently using
    |a file
  • +intext:webalizer +intext: |Webalizer Web statistics page lists Web user-
    Total Usernames +intext: |names and statistical information
    "Usage Statistics for"
  • filetype:reg reg HKEY_ |Windows Registry exports can reveal
    CURRENT_USER |username usernames and other information
Note: Special Thanks to Shabbir for reviewing and allowing this post.
Old 07-19-2008, 08:10 AM   #2
Go4Expert Founder
 
shabbir's Avatar
 
Join Date: Jul 2004
Location: On Earth
Posts: 12,516
Thanks: 53
Thanked 276 Times in 215 Posts
Rep Power: 10
shabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud of
Send a message via Yahoo to shabbir

Re: Get full access thru "Welcome to phpMyAdmin"


My pleasure and the only reason to allow this is for people like me can be careful and know what can be found using Google.
shabbir is offline   Reply With Quote
Old 07-19-2008, 04:47 PM   #3
Ambitious contributor
 
GreenGrass's Avatar
 
Join Date: Jul 2008
Location: Norway
Posts: 123
Thanks: 0
Thanked 3 Times in 2 Posts
Rep Power: 3
GreenGrass is on a distinguished road
Send a message via MSN to GreenGrass

Re: Get full access thru "Welcome to phpMyAdmin"


Well this is crazy Nice Post..
GreenGrass is offline   Reply With Quote
Old 07-19-2008, 09:34 PM   #4
Invasive contributor
 
Join Date: Jun 2007
Posts: 569
Thanks: 0
Thanked 4 Times in 4 Posts
Rep Power: 0
XXxxImmortalxxXX is on a distinguished road

Re: Get full access thru "Welcome to phpMyAdmin"


hahahah lol gotta love it i did that once except i set mine up to be like that and they attacker would go through ONLY frontpage to access my files BUT what they didnt know is is that i had 2 sets of the files one is the bad file for the victam and 1 for me the one for me is set up on another server as the bad one is hosted on my pc so when he connects to my pc and goes to my www folder and opens up some files a trojan remotly gets installed on his pc as well as other stuff and a alert msg poping up ever 10 minutes saying

DONT GO THROUGH MY SHIT ASSWHOLE

so yea i love it when ppl use those commands its funny becuase U NEVER KNOW WHO UR MESSING WITH ON THE INTERNET
XXxxImmortalxxXX is offline   Reply With Quote
Old 07-19-2008, 09:59 PM   #5
Invasive contributor
 
Join Date: Jun 2007
Posts: 569
Thanks: 0
Thanked 4 Times in 4 Posts
Rep Power: 0
XXxxImmortalxxXX is on a distinguished road

Re: Get full access thru "Welcome to phpMyAdmin"


also u dont need to convert it those passwords are encrypted by DES encryption
XXxxImmortalxxXX is offline   Reply With Quote
Old 07-20-2008, 12:31 AM   #6
Skilled contributor
 
faizulhaque's Avatar
 
Join Date: May 2008
Location: Karachi
Posts: 217
Thanks: 0
Thanked 1 Time in 1 Post
Rep Power: 3
faizulhaque is on a distinguished road
Send a message via Yahoo to faizulhaque

Re: Get full access thru "Welcome to phpMyAdmin"


All the Request code are available in below

http://code.google.com/p/googlehacks/downloads/list

It's official Google Hack Site, own made by google's
__________________
If you start judging people you will
be having no time to love them.....
faizulhaque is offline   Reply With Quote
Old 07-20-2008, 02:28 AM   #7
Invasive contributor
 
Join Date: Jun 2007
Posts: 569
Thanks: 0
Thanked 4 Times in 4 Posts
Rep Power: 0
XXxxImmortalxxXX is on a distinguished road

Re: Get full access thru "Welcome to phpMyAdmin"


i dont know why google when put that site up its a security risk that there making but hey its not hurting me nay lol
XXxxImmortalxxXX is offline   Reply With Quote
Old 08-02-2008, 11:58 AM   #8
Go4Expert Founder
 
shabbir's Avatar
 
Join Date: Jul 2004
Location: On Earth
Posts: 12,516
Thanks: 53
Thanked 276 Times in 215 Posts
Rep Power: 10
shabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud of
Send a message via Yahoo to shabbir

Re: Get full access thru "Welcome to phpMyAdmin"


shabbir is offline   Reply With Quote
Old 08-19-2008, 10:36 AM   #9
Go4Expert Founder
 
shabbir's Avatar
 
Join Date: Jul 2004
Location: On Earth
Posts: 12,516
Thanks: 53
Thanked 276 Times in 215 Posts
Rep Power: 10
shabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud ofshabbir has much to be proud of
Send a message via Yahoo to shabbir

Re: Get full access thru "Welcome to phpMyAdmin"


shabbir is offline   Reply With Quote
Old 08-23-2008, 07:51 AM   #10
Skilled contributor
 
hanleyhansen's Avatar
 
Join Date: Jan 2008
Location: Passaic
Posts: 253
Thanks: 13
Thanked 2 Times in 2 Posts
Rep Power: 3
hanleyhansen is on a distinguished road
Send a message via AIM to hanleyhansen Send a message via MSN to hanleyhansen

Re: Get full access thru "Welcome to phpMyAdmin"


Lol funny!!!
hanleyhansen is offline   Reply With Quote
Discuss / Comment  Copy HTML to Clipboard  Copy BBCode to Clipboard  | More


Currently Active Users Reading This Article: 1 (0 members and 1 guests)
 
Article Tools Search this Article
Search this Article:

Advanced Search
Display Modes
Bookmarks

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads / Articles
Thread Thread Starter Forum Replies Last Post
Ethical Hacking Basics Class part 1 XXxxImmortalxxXX Ethical hacking 27 06-03-2010 06:34 PM
Ethical Hacking Class part 2 XXxxImmortalxxXX Ethical hacking 7 07-11-2008 09:55 AM
.NET access modifiers shabbir C# 0 12-06-2006 02:33 PM

 

All times are GMT +5.5. The time now is 05:29 AM.