From a6dc96fe81d4ba4bd3c48e7349cb0a29b1acda23 Mon Sep 17 00:00:00 2001 From: Daniel Miessler Date: Tue, 4 Aug 2015 11:05:52 -0700 Subject: [PATCH] Moar structure updates. --- GrepStrings/README | 1 - GrepStrings/basic_grepstrings.txt | 14 --- GrepStrings/malicious.txt | 94 ------------------ GrepStrings/pcap_strings.txt | 13 --- GrepStrings/thickclient_basic_.txt | 13 --- .../Backdoors/Web Backdoors/FUZZDB_Simple.php | 0 .../Backdoors/Web Backdoors/FUZZDB_Up.php | 0 .../Backdoors/Web Backdoors/FUZZDB_cmd.jsp | 0 .../Backdoors/Web Backdoors/FUZZDB_cmd.php | 0 .../Backdoors/Web Backdoors/FUZZDB_cmd.sh | 0 .../Web Backdoors/FUZZDB_cmdasp.aspx | 0 .../Web Backdoors/FUZZDB_jsp-reverse.jsp | 0 .../Backdoors/Web Backdoors/FUZZDB_list.jsp | 0 .../Backdoors/Web Backdoors/FUZZDB_list.php | 0 .../Backdoors/Web Backdoors/FUZZDB_list.sh | 0 .../Backdoors/Web Backdoors/FUZZDB_nc.exe | Bin .../Web Backdoors/FUZZDB_php-backdoor.php | 0 .../Backdoors/Web Backdoors/FUZZDB_up.sh | 0 .../Web Backdoors/laudanum-0.8/CREDITS | 0 .../Backdoors/Web Backdoors/laudanum-0.8/GPL | 0 .../Web Backdoors/laudanum-0.8/README | 0 .../Web Backdoors/laudanum-0.8/asp/dns.asp | 0 .../Web Backdoors/laudanum-0.8/asp/file.asp | 0 .../Web Backdoors/laudanum-0.8/asp/proxy.asp | 0 .../Web Backdoors/laudanum-0.8/asp/shell.asp | 0 .../Web Backdoors/laudanum-0.8/aspx/dns.aspx | 0 .../Web Backdoors/laudanum-0.8/aspx/file.aspx | 0 .../laudanum-0.8/aspx/shell.aspx | 0 .../Web Backdoors/laudanum-0.8/cfm/shell.cfm | 0 .../Web Backdoors/laudanum-0.8/jsp/cmd.war | Bin .../Web Backdoors/laudanum-0.8/jsp/makewar.sh | 0 .../jsp/warfiles/META-INF/MANIFEST.MF | 0 .../laudanum-0.8/jsp/warfiles/WEB-INF/web.xml | 0 .../laudanum-0.8/jsp/warfiles/cmd.jsp | 0 .../Web Backdoors/laudanum-0.8/php/dns.php | 0 .../Web Backdoors/laudanum-0.8/php/file.php | 0 .../laudanum-0.8/php/php-reverse-shell.php | 0 .../Web Backdoors/laudanum-0.8/php/proxy.php | 0 .../Web Backdoors/laudanum-0.8/php/shell.php | 0 39 files changed, 135 deletions(-) delete mode 100755 GrepStrings/README delete mode 100755 GrepStrings/basic_grepstrings.txt delete mode 100644 GrepStrings/malicious.txt delete mode 100644 GrepStrings/pcap_strings.txt delete mode 100755 GrepStrings/thickclient_basic_.txt rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/FUZZDB_Simple.php (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/FUZZDB_Up.php (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/FUZZDB_cmd.jsp (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/FUZZDB_cmd.php (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/FUZZDB_cmd.sh (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/FUZZDB_cmdasp.aspx (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/FUZZDB_jsp-reverse.jsp (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/FUZZDB_list.jsp (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/FUZZDB_list.php (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/FUZZDB_list.sh (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/FUZZDB_nc.exe (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/FUZZDB_php-backdoor.php (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/FUZZDB_up.sh (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/CREDITS (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/GPL (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/README (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/asp/dns.asp (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/asp/file.asp (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/asp/proxy.asp (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/asp/shell.asp (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/aspx/dns.aspx (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/aspx/file.aspx (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/aspx/shell.aspx (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/cfm/shell.cfm (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/jsp/cmd.war (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/jsp/makewar.sh (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/META-INF/MANIFEST.MF (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/WEB-INF/web.xml (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/cmd.jsp (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/php/dns.php (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/php/file.php (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/php/php-reverse-shell.php (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/php/proxy.php (100%) rename {Scripts => Web_Payloads}/Backdoors/Web Backdoors/laudanum-0.8/php/shell.php (100%) diff --git a/GrepStrings/README b/GrepStrings/README deleted file mode 100755 index 5680b123..00000000 --- a/GrepStrings/README +++ /dev/null @@ -1 +0,0 @@ -The GrepStrings directory will hold various lists that can be passed to grep when looking for intersting content within filesystems or source code. diff --git a/GrepStrings/basic_grepstrings.txt b/GrepStrings/basic_grepstrings.txt deleted file mode 100755 index b38d17a8..00000000 --- a/GrepStrings/basic_grepstrings.txt +++ /dev/null @@ -1,14 +0,0 @@ -password -user -username -select -update -delete -ssn -dob -ccn -passwd -pass -administrator -secret -key diff --git a/GrepStrings/malicious.txt b/GrepStrings/malicious.txt deleted file mode 100644 index f5e258ff..00000000 --- a/GrepStrings/malicious.txt +++ /dev/null @@ -1,94 +0,0 @@ -# strings for finding backdoor shells, rootkits, botnets, and exploitable functions -# grep -Rn "shell *(" /var/www - -passthru -shell_exec -system -phpinfo -base64_decode -chmod -mkdir -fopen -fclose -readfile -php_uname -eval -edoced_46esab -popen -include -create_function -mysql_execute -php_uname -proc_open -pcntl_exec -`` -include_once -require -require_once -posix_mkfifo -posix_getlogin -posix_ttyname -getenv -get_current_user -proc_get_status -get_cfg_var -disk_free_space -disk_total_space -diskfreespace -getcwd -getlastmo -getmygid -getmyinode -getmypid -getmyuid -assert -extract -parse_str -putenv -ini_set -pfsockopen -fsockopen -apache_child_terminate -posix_kill -posix_setpgid -posix_setsid -posix_setuid -tmpfile -bzopen -gzopen -chgrp -chown -copy -file_put_contents -lchgrp -lchown -link -mkdir -move_uploaded_file -symlink -tempnam -imagecreatefromgif -imagecreatefromjpeg -imagecreatefrompng -imagecreatefromwbmp -imagecreatefromxbm -imagecreatefromxpm -ftp_put -ftp_nb_put -exif_read_data -read_exif_data -exif_thumbnail -exif_imagetype -hash_file -hash_hmac_file -hash_update_file -md5_file -sha1_file -highlight_file -show_source -php_strip_whitespace -get_meta_tags -str_repeat -unserialize -register_tick_function -register_shutdown_function diff --git a/GrepStrings/pcap_strings.txt b/GrepStrings/pcap_strings.txt deleted file mode 100644 index b2916466..00000000 --- a/GrepStrings/pcap_strings.txt +++ /dev/null @@ -1,13 +0,0 @@ -username -SSN -DOB -password -uname -encryption-key -encryptionkey -secretkey -secret_key -secret-key -aeskey -passphrase -wombat diff --git a/GrepStrings/thickclient_basic_.txt b/GrepStrings/thickclient_basic_.txt deleted file mode 100755 index 0ef7c715..00000000 --- a/GrepStrings/thickclient_basic_.txt +++ /dev/null @@ -1,13 +0,0 @@ -password -select -username -social -ssn -dob -DOB -Password -security -protected -SSN -update -delete diff --git a/Scripts/Backdoors/Web Backdoors/FUZZDB_Simple.php b/Web_Payloads/Backdoors/Web Backdoors/FUZZDB_Simple.php similarity index 100% rename from Scripts/Backdoors/Web Backdoors/FUZZDB_Simple.php rename to Web_Payloads/Backdoors/Web Backdoors/FUZZDB_Simple.php diff --git a/Scripts/Backdoors/Web Backdoors/FUZZDB_Up.php b/Web_Payloads/Backdoors/Web Backdoors/FUZZDB_Up.php similarity index 100% rename from Scripts/Backdoors/Web Backdoors/FUZZDB_Up.php rename to Web_Payloads/Backdoors/Web Backdoors/FUZZDB_Up.php diff --git a/Scripts/Backdoors/Web Backdoors/FUZZDB_cmd.jsp b/Web_Payloads/Backdoors/Web Backdoors/FUZZDB_cmd.jsp similarity index 100% rename from Scripts/Backdoors/Web Backdoors/FUZZDB_cmd.jsp rename to Web_Payloads/Backdoors/Web Backdoors/FUZZDB_cmd.jsp diff --git a/Scripts/Backdoors/Web Backdoors/FUZZDB_cmd.php b/Web_Payloads/Backdoors/Web Backdoors/FUZZDB_cmd.php similarity index 100% rename from Scripts/Backdoors/Web Backdoors/FUZZDB_cmd.php rename to Web_Payloads/Backdoors/Web Backdoors/FUZZDB_cmd.php diff --git a/Scripts/Backdoors/Web Backdoors/FUZZDB_cmd.sh b/Web_Payloads/Backdoors/Web Backdoors/FUZZDB_cmd.sh similarity index 100% rename from Scripts/Backdoors/Web Backdoors/FUZZDB_cmd.sh rename to Web_Payloads/Backdoors/Web Backdoors/FUZZDB_cmd.sh diff --git a/Scripts/Backdoors/Web Backdoors/FUZZDB_cmdasp.aspx b/Web_Payloads/Backdoors/Web Backdoors/FUZZDB_cmdasp.aspx similarity index 100% rename from Scripts/Backdoors/Web Backdoors/FUZZDB_cmdasp.aspx rename to Web_Payloads/Backdoors/Web Backdoors/FUZZDB_cmdasp.aspx diff --git a/Scripts/Backdoors/Web Backdoors/FUZZDB_jsp-reverse.jsp b/Web_Payloads/Backdoors/Web Backdoors/FUZZDB_jsp-reverse.jsp similarity index 100% rename from Scripts/Backdoors/Web Backdoors/FUZZDB_jsp-reverse.jsp rename to Web_Payloads/Backdoors/Web Backdoors/FUZZDB_jsp-reverse.jsp diff --git a/Scripts/Backdoors/Web Backdoors/FUZZDB_list.jsp b/Web_Payloads/Backdoors/Web Backdoors/FUZZDB_list.jsp similarity index 100% rename from Scripts/Backdoors/Web Backdoors/FUZZDB_list.jsp rename to Web_Payloads/Backdoors/Web Backdoors/FUZZDB_list.jsp diff --git a/Scripts/Backdoors/Web Backdoors/FUZZDB_list.php b/Web_Payloads/Backdoors/Web Backdoors/FUZZDB_list.php similarity index 100% rename from Scripts/Backdoors/Web Backdoors/FUZZDB_list.php rename to Web_Payloads/Backdoors/Web Backdoors/FUZZDB_list.php diff --git a/Scripts/Backdoors/Web Backdoors/FUZZDB_list.sh b/Web_Payloads/Backdoors/Web Backdoors/FUZZDB_list.sh similarity index 100% rename from Scripts/Backdoors/Web Backdoors/FUZZDB_list.sh rename to Web_Payloads/Backdoors/Web Backdoors/FUZZDB_list.sh diff --git a/Scripts/Backdoors/Web Backdoors/FUZZDB_nc.exe b/Web_Payloads/Backdoors/Web Backdoors/FUZZDB_nc.exe similarity index 100% rename from Scripts/Backdoors/Web Backdoors/FUZZDB_nc.exe rename to Web_Payloads/Backdoors/Web Backdoors/FUZZDB_nc.exe diff --git a/Scripts/Backdoors/Web Backdoors/FUZZDB_php-backdoor.php b/Web_Payloads/Backdoors/Web Backdoors/FUZZDB_php-backdoor.php similarity index 100% rename from Scripts/Backdoors/Web Backdoors/FUZZDB_php-backdoor.php rename to Web_Payloads/Backdoors/Web Backdoors/FUZZDB_php-backdoor.php diff --git a/Scripts/Backdoors/Web Backdoors/FUZZDB_up.sh b/Web_Payloads/Backdoors/Web Backdoors/FUZZDB_up.sh similarity index 100% rename from Scripts/Backdoors/Web Backdoors/FUZZDB_up.sh rename to Web_Payloads/Backdoors/Web Backdoors/FUZZDB_up.sh diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/CREDITS b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/CREDITS similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/CREDITS rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/CREDITS diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/GPL b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/GPL similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/GPL rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/GPL diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/README b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/README similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/README rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/README diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/asp/dns.asp b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/asp/dns.asp similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/asp/dns.asp rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/asp/dns.asp diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/asp/file.asp b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/asp/file.asp similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/asp/file.asp rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/asp/file.asp diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/asp/proxy.asp b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/asp/proxy.asp similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/asp/proxy.asp rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/asp/proxy.asp diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/asp/shell.asp b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/asp/shell.asp similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/asp/shell.asp rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/asp/shell.asp diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/aspx/dns.aspx b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/aspx/dns.aspx similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/aspx/dns.aspx rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/aspx/dns.aspx diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/aspx/file.aspx b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/aspx/file.aspx similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/aspx/file.aspx rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/aspx/file.aspx diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/aspx/shell.aspx b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/aspx/shell.aspx similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/aspx/shell.aspx rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/aspx/shell.aspx diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/cfm/shell.cfm b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/cfm/shell.cfm similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/cfm/shell.cfm rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/cfm/shell.cfm diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/jsp/cmd.war b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/jsp/cmd.war similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/jsp/cmd.war rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/jsp/cmd.war diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/jsp/makewar.sh b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/jsp/makewar.sh similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/jsp/makewar.sh rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/jsp/makewar.sh diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/META-INF/MANIFEST.MF b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/META-INF/MANIFEST.MF similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/META-INF/MANIFEST.MF rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/META-INF/MANIFEST.MF diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/WEB-INF/web.xml b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/WEB-INF/web.xml similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/WEB-INF/web.xml rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/WEB-INF/web.xml diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/cmd.jsp b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/cmd.jsp similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/cmd.jsp rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/jsp/warfiles/cmd.jsp diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/php/dns.php b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/php/dns.php similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/php/dns.php rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/php/dns.php diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/php/file.php b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/php/file.php similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/php/file.php rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/php/file.php diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/php/php-reverse-shell.php b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/php/php-reverse-shell.php similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/php/php-reverse-shell.php rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/php/php-reverse-shell.php diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/php/proxy.php b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/php/proxy.php similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/php/proxy.php rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/php/proxy.php diff --git a/Scripts/Backdoors/Web Backdoors/laudanum-0.8/php/shell.php b/Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/php/shell.php similarity index 100% rename from Scripts/Backdoors/Web Backdoors/laudanum-0.8/php/shell.php rename to Web_Payloads/Backdoors/Web Backdoors/laudanum-0.8/php/shell.php