From 484ab9e986faf750b4f8c87ba678b15f1fa370f9 Mon Sep 17 00:00:00 2001
From: Alexandre ZANNI <16578570+noraj@users.noreply.github.com>
Date: Thu, 7 Oct 2021 11:03:42 +0200
Subject: [PATCH] Update fuzz-Bo0oM.txt
---
Fuzzing/fuzz-Bo0oM.txt | 602 +++++++++++++++++++++++++++++++++++++++--
1 file changed, 578 insertions(+), 24 deletions(-)
diff --git a/Fuzzing/fuzz-Bo0oM.txt b/Fuzzing/fuzz-Bo0oM.txt
index e83c751..c3b6da1 100644
--- a/Fuzzing/fuzz-Bo0oM.txt
+++ b/Fuzzing/fuzz-Bo0oM.txt
@@ -3,25 +3,10 @@
!.htpasswd
%20../
%2e%2e//google.com
-%2e%2e;/test
+%2e%2e;test/
%3f/
%C0%AE%C0%AE%C0%AF
%ff/
-+CSCOU+/../+CSCOE+/files/file_list.json
-#
-%23
-#3ooo
%25
-#'-alert(document.domain)-'
-;/..;/
-..;/..;/
-foo;name=foo/
-status/..;/
-..;/x
-login;foo/
-login;/
-login;/..;/admin
-;/
-;
..;/
.7z
.access
@@ -37,6 +22,7 @@ login;/..;/admin
.aws/credentials
.axoCover/
.babelrc
+.backup
.bak
.bash_history
.bash_logout
@@ -62,6 +48,7 @@ login;/..;/admin
.cabal-sandbox/
.cache
.cache/
+.canna
.capistrano
.capistrano/
.capistrano/metrics
@@ -72,6 +59,9 @@ login;/..;/admin
.cfg
.cfignore
.checkstyle
+.circleci/
+.circleci/.firebase.secrets.json
+.circleci/.firebase.secrets.json.enc
.circleci/config.yml
.classpath
.cobalt
@@ -109,6 +99,8 @@ login;/..;/admin
.cvsignore
.dart_tool/
.dat
+.db.xml
+.db.yaml
.deployignore
.dev/
.directory
@@ -123,15 +115,21 @@ login;/..;/admin
.elasticbeanstalk/
.elb
.elc
+.emacs
.emacs.desktop
.emacs.desktop.lock
.empty-folder
.env
.env.dev
+.env.dev.local
+.env.development.local
.env.development.sample
+.env.docker
.env.docker.dev
.env.php
.env.prod
+.env.prod.local
+.env.production.local
.env.sample.php
.env.test.sample
.environment
@@ -158,6 +156,7 @@ login;/..;/admin
.fontconfig/
.fontcustom-manifest.json
.forward
+.ftp
.ftp-access
.ftppass
.ftpquota
@@ -196,6 +195,7 @@ login;/..;/admin
.gradletasknamecache
.grunt
.grunt/
+.gtkrc
.guile_history
.gwt-tmp/
.gwt/
@@ -292,11 +292,15 @@ login;/..;/admin
.jekyll-metadata
.jestrc
.joe_state
+.jpilot
.jscsrc
.jshintignore
.jshintrc
+.jsp
.JustCode
+.kde
.keep
+.keys.yml
.kitchen.local.yml
.kitchen.yml
.kitchen/
@@ -334,6 +338,7 @@ login;/..;/admin
.maintenance2
.mc
.mc/
+.members
.memdump
.mergesources.yml
.merlin
@@ -370,6 +375,7 @@ login;/..;/admin
.nra.cache
.nrepl-port
.nsconfig
+.nsf
.ntvs_analysis.dat
.nuget/
.nuget/packages.config
@@ -381,7 +387,12 @@ login;/..;/admin
.ost
.packages
.paket/
+.pass
+.passes
.passwd
+.password
+.passwords
+.passwrd
.patches/
.pdf
.perf
@@ -411,6 +422,7 @@ login;/..;/admin
.psqlrc
.pst
.pub/
+.pwd
.pydevproject
.pytest_cache/
.Python
@@ -433,6 +445,7 @@ login;/..;/admin
.repl_history
.revision
.Rhistory
+.rhost
.rhosts
.robots.txt
.rocketeer/
@@ -467,6 +480,7 @@ login;/..;/admin
.sh_history
.shrc
.sln
+.smileys
.smushit-status
.spamassassin
.spyderproject
@@ -542,7 +556,9 @@ login;/..;/admin
.Trashes
.travis.yml
.tx/
+.txt
.user.ini
+.users
.vacation.cache
.vagrant
.venv
@@ -565,17 +581,23 @@ login;/..;/admin
.zfs/
.zip
.zsh_history
+.zshrc
0.htpasswd
0.php
0admin/
0manager/
+1.7z
1.htaccess
1.htpasswd
1.php
+1.rar
1.sql
+1.tar
+1.tar.bz2
1.tar.gz
1.txt
1.zip
+10-flannel.conf
123.php
123.txt
1c/
@@ -584,49 +606,76 @@ login;/..;/admin
2.txt
2010.sql
2010.tar
+2010.tar.bz2
2010.tar.gz
2010.tgz
2010.zip
2011.sql
2011.tar
+2011.tar.bz2
2011.tar.gz
2011.tgz
2011.zip
2012.sql
2012.tar
+2012.tar.bz2
2012.tar.gz
2012.tgz
2012.zip
2013.sql
2013.tar
+2013.tar.bz2
2013.tar.gz
2013.tgz
2013.zip
2014.sql
2014.tar
+2014.tar.bz2
2014.tar.gz
2014.tgz
2014.zip
2015.sql
2015.tar
+2015.tar.bz2
2015.tar.gz
2015.tgz
2015.zip
2016.sql
2016.tar
+2016.tar.bz2
2016.tar.gz
2016.tgz
2016.zip
2017.sql
2017.tar
+2017.tar.bz2
2017.tar.gz
2017.tgz
2017.zip
2018.sql
2018.tar
+2018.tar.bz2
2018.tar.gz
2018.tgz
2018.zip
+2019.sql
+2019.tar
+2019.tar.bz2
+2019.tar.gz
+2019.tgz
+2019.zip
+2020.sql
+2020.tar
+2020.tar.bz2
+2020.tar.gz
+2020.tgz
+2020.zip
+2021.sql
+2021.tar
+2021.tar.bz2
+2021.tar.gz
+2021.tgz
+2021.zip
2phpmyadmin/
3.php
4.php
@@ -640,12 +689,14 @@ login;/..;/admin
9678.php
\..\..\..\..\..\..\..\..\..\etc\passwd
_.htpasswd
+__admin
__cache/
__dummy.html
__history/
__index.php
__init__.py
__MACOSX
+__main__.py
__pma___
__pycache__/
__recovery/
@@ -666,10 +717,12 @@ _Dockerfile
_errors
_eumm/
_files
+_fragment
_h5ai/
_include
_index.php
_install
+_internal
_layouts
_layouts/
_layouts/alllibs.htm
@@ -704,6 +757,7 @@ _pages
_phpmyadmin/
_pkginfo.txt
_private
+_proxy
_Pvt_Extensions
_site/
_source
@@ -731,6 +785,7 @@ _yardoc/
a%5c.aspx
a.out
aadmin/
+abs/
acceptance_config.yml
acceso
acceso.php
@@ -740,6 +795,7 @@ access-log.1
access.1
access.log
access.php
+access.txt
access/
access_.log
access_log
@@ -749,15 +805,24 @@ account.html
account.php
accounts
accounts.php
+accounts.sql
accounts.txt
accounts.xml
accounts/
acct_login/
+activemq/
activity.log
+actuator
+actuator/dump
+actuator/env
+actuator/logfile
+actuator/mappings
+actuator/trace
ad_login
ad_manage
add.php
add_admin
+adfs/services/trust/2005/windowstransport
adm
adm.html
adm.php
@@ -1077,6 +1142,7 @@ admins/log.txt
adminsite/
AdminTools/
adminuser
+admission_controller_config.yaml
admloginuser.php
admpar/
admpar/.ftppass
@@ -1094,6 +1160,7 @@ amad.php
amministratore.php
analog.html
anchor/errors.log
+ansible/
answers/
answers/error_log
apache/
@@ -1107,14 +1174,31 @@ apc/
apc/apc.php
apc/index.php
api
+api-doc
+api-docs
api.log
+api.php
+api.py
api/
+api/2/explore/
api/error_log
+api/jsonws
+api/login.json
+api/package_search/v4/documentation
+api/swagger
api/swagger-ui.html
+api/swagger.yml
+api/v1
+api/v2
+api/v3
apibuild.pyc
-apidocs/
-apidocs/api-docs.json
-api-docs/
+apidoc
+apidocs
+apiserver-aggregator-ca.cert
+apiserver-aggregator.cert
+apiserver-aggregator.key
+apiserver-client.crt
+apiserver-key.pem
app.config
app.js
app.php
@@ -1172,12 +1256,14 @@ app_dev.php
appcache.manifest
appengine-generated/
applet
+application
application.log
application.wadl
application/
application/cache/
application/configs/application.ini
application/logs/
+apply.cgi
AppPackages/
apps/
apps/__pycache__/
@@ -1188,17 +1274,21 @@ Aptfile
ar-lib
archaius
archaius.json
+archive.7z
archive.rar
archive.sql
archive.tar
archive.tar.gz
+archive.tgz
archive.zip
article/
article/admin
article/admin/admin.asp
+artifactory/
artifacts/
ASALocalRun/
asp.aspx
+aspnet_client/
aspnet_webadmin
aspwpadmin
aspxspy.aspx
@@ -1207,14 +1297,19 @@ assets/
assets/fckeditor
assets/js/fckeditor
assets/npm-debug.log
+assets/pubspec.yaml
asterisk.log
+asterisk/
AT-admin.cgi
atlassian-ide-plugin.xml
+audit.log
auditevents
auditevents.json
auth
auth.inc
auth.php
+auth.tar.gz
+auth.zip
auth_user_file.txt
authadmin
authadmin.php
@@ -1223,6 +1318,7 @@ authenticate
authenticate.php
authentication
authentication.php
+authlog.txt
authorization.config
authorize.php
authorized_keys
@@ -1232,21 +1328,38 @@ authuser.php
auto/
autoconfig
autoconfig.json
+autodiscover/
autologin
autologin.php
autologin/
autom4te.cache
autoscan.log
AutoTest.Net/
+autoupdate/
+av/
+aws/
awstats
awstats.conf
awstats.pl
awstats/
+axis/
+axis//happyaxis.jsp
+axis2-web//HappyAxis.jsp
+axis2/
+axis2//axis2-web/HappyAxis.jsp
+axis2/axis2-web/HappyAxis.jsp
+azure-pipelines.yml
azureadmin/
b2badmin/
+babel.config.js
back.sql
+back_office.php
+backoffice.php
+backoffice/
+backoffice/v1/ui
backup
backup.7z
+backup.cfg
backup.htpasswd
backup.inc
backup.inc.old
@@ -1280,9 +1393,12 @@ backups.tgz
backups.zip
backups/
bak/
+bamb/
+bamboo/
banner.swf
banneradmin/
base/
+basic_auth.csv
bb-admin/
bb-admin/admin
bb-admin/admin.html
@@ -1296,11 +1412,17 @@ bbadmin/
bbs/
bbs/admin/login
bbs/admin_index.asp
+bea_wls_cluster_internal/
+bea_wls_deployment_internal/
+bea_wls_deployment_internal/DeploymentService
+bea_wls_diagnostics/
+bea_wls_internal/
beans
beans.json
behat.yml
BenchmarkDotNet.Artifacts/
Berksfile
+beta
bigadmin/
bigdump.php
billing
@@ -1310,6 +1432,7 @@ bin-debug/
bin-release/
bin/
bin/config.sh
+bin/hostname
bin/libs
bin/reset-db-prod.sh
bin/reset-db.sh
@@ -1317,11 +1440,18 @@ bin/RhoBundle
bin/target
bin/tmp
Binaries/
+bitbucket-pipelines.yml
bitrix/
+bitrix/.settings
+bitrix/.settings.bak
+bitrix/.settings.php
+bitrix/.settings.php.bak
bitrix/admin/help.php
bitrix/admin/index.php
bitrix/authorization.config
bitrix/backup/
+bitrix/cache
+bitrix/cache_image
bitrix/dumper/
bitrix/error.log
bitrix/import/
@@ -1329,18 +1459,30 @@ bitrix/import/files
bitrix/import/import
bitrix/import/m_import
bitrix/logs/
+bitrix/managed_cache
+bitrix/modules
bitrix/modules/error.log
bitrix/modules/error.log.old
bitrix/modules/main/admin/restore.php
bitrix/modules/main/classes/mysql/agent.php
+bitrix/modules/serverfilelog-0.dat
+bitrix/modules/serverfilelog-1.dat
+bitrix/modules/serverfilelog_tmp.dat
bitrix/modules/smtpd.log
bitrix/modules/updater.log
bitrix/modules/updater_partner.log
bitrix/otp/
+bitrix/php_interface/dbconn.php
bitrix/php_interface/dbconn.php2
+bitrix/settings
+bitrix/settings.bak
+bitrix/settings.php
+bitrix/settings.php.bak
+bitrix/stack_cache
bitrix/web.config
bitrix_server_test.log
bitrix_server_test.php
+bitrixsetup.php
biy/
biy/upload/
Black.php
@@ -1369,8 +1511,10 @@ Brocfile.js
browser/
brunch-config.coffee
brunch-config.js
+bsmdashboards/messagebroker/amfsecure
buck.sql
buffer.conf
+bugs
Build
build
build-iPhoneOS/
@@ -1384,6 +1528,7 @@ build.xml
build/
build/build.properties
build/buildinfo.properties
+build/reference/web-api/explore
build/Release
build_config_private.ini
build_isolated/
@@ -1395,6 +1540,8 @@ c100.php
c22.php
c99.php
c99shell.php
+ca.crt
+ca.kru
cabal-dev
cabal.project.local
cabal.project.local~
@@ -1404,12 +1551,15 @@ cache-downloads
cache/
cache/sql_error_latest.cgi
cachemgr.cgi
+caches
cadmins/
Cakefile
Capfile
+capistrano/
captures/
Cargo.lock
Carthage/Build
+cassandra/
catalog.wci
CATKIN_IGNORE
cbx-portal/
@@ -1420,7 +1570,11 @@ ccbill.log
ccp14admin/
celerybeat-schedule
cell.xml
+centreon/
cert/
+certenroll/
+certprov/
+certsrv/
cfexec.cfm
cfg/
cfg/cpp/
@@ -1435,6 +1589,7 @@ cgi-bin/php.ini
cgi-bin/printenv.pl
cgi-bin/test-cgi
cgi-bin/test.cgi
+cgi-bin/ViewLog.asp
cgi-sys/
cgi-sys/realsignup.cgi
cgi.pl/
@@ -1474,13 +1629,16 @@ checked_accounts.txt
checklogin
checklogin.php
checkouts/
+checkstyle/
checkuser
checkuser.php
+chef/
Cheffile
chefignore
chkadmin
chklogin
chubb.xml
+ci/
cidr.txt
circle.yml
Citrix/
@@ -1503,6 +1661,7 @@ classic.json
classic.jsonp
cleanup.log
cli/
+client.ovpn
client_secret.json
client_secrets.json
ClientAccessPolicy.xml
@@ -1512,7 +1671,9 @@ cliente/downloads/h4xor.php
clients.mdb
clients.sql
clients.sqlite
+clients.tar.gz
clients.zip
+cloud/
cmake_install.cmake
CMakeCache.txt
CMakeFiles
@@ -1531,7 +1692,14 @@ cms/Web.config
cmsadmin
cmsadmin.php
cmsadmin/
+cmscockpit/
+cni-conf.json
codeception.yml
+codeship/
+collectd/
+collectl/
+com.tar.gz
+com.zip
command.php
common.inc
common.xml
@@ -1546,6 +1714,8 @@ composer.json
composer.lock
composer.phar
composer/installed.json
+conditions
+conf
conf/
conf/Catalina
conf/catalina.policy
@@ -1563,6 +1733,7 @@ config.core
config.dat
config.guess
config.h.in
+config.hash
config.inc
config.inc.bak
config.inc.old
@@ -1578,10 +1749,13 @@ config.ini.txt
config.json
config.json.cfm
config.local
+config.local.php_old
+config.local.php~
config.old
config.php
config.php-eb
config.php.bak
+config.php.bkp
config.php.dist
config.php.inc
config.php.inc~
@@ -1590,9 +1764,11 @@ config.php.old
config.php.save
config.php.swp
config.php.txt
+config.php.zip
config.php~
config.rb
config.ru
+config.source
config.sub
config.txt
config.xml
@@ -1645,6 +1821,7 @@ configuration.php.old
configuration.php.save
configuration.php.swp
configuration.php.txt
+configuration.php.zip
configuration.php~
configuration/
configure
@@ -1656,6 +1833,7 @@ connect.inc
console/
console/base/config.json
console/payments/config.json
+consul/
content/
content/debug.log
CONTRIBUTING.md
@@ -1675,6 +1853,7 @@ cookie
cookie.php
COPYING
COPYRIGHT.txt
+core/latest/swagger-ui/index.html
count_admin
cover
cover_db/
@@ -1696,6 +1875,9 @@ cpbt.php
cpn.php
craft/
crash.log
+credentials
+credentials.csv
+credentials.txt
credentials.xml
credentials/
credentials/gcloud.json
@@ -1711,7 +1893,9 @@ cron_sku.log
crond/
crond/logs/
cronlog.txt
+cscockpit/
csdp.cache
+csp/gateway/slc/api/swagger-ui.html
css.php
csx/
CTestTestfile.cmake
@@ -1736,6 +1920,8 @@ d0main.php
d0maine.php
d0mains.php
dam.php
+dat.tar.gz
+dat.zip
data-nseries.tsv
data.mdb
data.sql
@@ -1777,6 +1963,7 @@ Database_Administration/
Database_Backup/
database_credentials.inc
databases.yml
+datadog/
dataobject.ini
davmail.log
DB
@@ -1794,6 +1981,8 @@ Db.script
db.sql
db.sqlite
db.sqlite3
+db.xml
+db.yaml
db/
db/db-admin/
db/dbadmin/
@@ -1818,6 +2007,7 @@ db1.sqlite
db2
db__.init.php
db_admin
+db_backup.sql
db_backups/
db_session.init.php
db_status.php
@@ -1826,11 +2016,13 @@ dbadmin.php
dbadmin/
dbadmin/index.php
dbase
+dbase.sql
dbbackup/
dbdump.sql
dbfix/
dbweb/
dead.letter
+DEADJOE
debug
debug-output.txt
debug.inc
@@ -1840,11 +2032,14 @@ debug.py
debug.txt
debug.xml
debug/
+debug/pprof
debug_error.jsp
delete.php
+demo
demo.php
demo/
demo/ejb/index.html
+demo/ojspext/events/globals.jsa
demo/sql/index.jsp
demos/
denglu
@@ -1859,9 +2054,11 @@ deps
deps/deps.jl
DerivedData/
DerivedDataCache/
+desk/
Desktop.ini
desktop/
desktop/index_framed.htm
+dev
dev.php
dev/
devdata.db
@@ -1872,8 +2069,12 @@ development-parts/
development.esproj/
development.log
development/
+deviceupdatefiles_ext/
+deviceupdatefiles_int/
df_main.sql
dfshealth.jsp
+dhcp_log/
+dialin/
dir-login/
dir.php
directadmin/
@@ -1881,25 +2082,33 @@ dist
dist/
dkms.conf
dlldata.c
+dms/AggreSpy
+dms/DMSDump
+dns.alpha.kubernetes.io
doc
doc/
doc/api/
docker-compose-dev.yml
docker-compose.yml
+docker/
Dockerfile
DocProject/buildhelp/
DocProject/Help/html
DocProject/Help/Html2
+docs
docs.json
docs/
docs/_build/
doctrine/
doctrine/schema/eirec.yml
doctrine/schema/tmx.yml
+documentation
documentation/
documentation/config.yml
+dokuwiki/
dom.php
domcfg.nsf
+door.php
down/
down/login
download/
@@ -1908,9 +2117,14 @@ download/users.csv
downloader/
downloader/cache.cfg
downloader/connect.cfg
+downloadFile.php
downloads/
downloads/dom.php
dra.php
+dswsbobje/
+dswsbobje//happyaxis.jsp
+dswsbobje/happyaxis.jsp
+duckrails/mocks/
dummy
dummy.php
dump
@@ -1922,13 +2136,16 @@ dump.log
dump.old
dump.rar
dump.rdb
+dump.sh
dump.sql
dump.sql.old
+dump.sql.tgz
dump.sqlite
dump.tar
dump.tar.bz2
dump.tar.gz
dump.tgz
+dump.txt
dump.zip
dump/
dumper.php
@@ -1941,6 +2158,7 @@ dz1.php
eagle.epf
ecf/
ecosystem.json
+ecp/
edit.php
editor.php
editor/
@@ -1952,10 +2170,13 @@ editors/
editors/FCKeditor
eggs/
ehthumbs.db
+elastic/
+elasticsearch/
elfinder/
elfinder/elfinder.php
elm-stuff
elmah.axd
+email/
encode-explorer.php
encode-explorer_5.0/
encode-explorer_5.1/
@@ -1972,6 +2193,8 @@ encode_explorer-4.0/
encode_explorer.php
encode_explorer/
encode_explorer_32/
+engine.tar.gz
+engine.zip
engine/
engine/classes/swfupload/swfupload.swf
engine/classes/swfupload/swfupload_f9.swf
@@ -2016,16 +2239,23 @@ errors.txt
errors/
errors/creation
errors/local.xml
+etc
etc/
etc/config.ini
etc/database.xml
etc/hosts
etc/lib/pChart2/examples/imageMap/index.php
etc/passwd
+etcd-apiserver-client.key
+etcd-ca.crt
+etcd-events.log
+etcd.log
eudora.ini
eula.txt
eula_en.txt
+ews/
example.php
+examples
examples/
examples/jsp/%252e%252e/%252e%252e/manager/html/
examples/jsp/snp/snoop.jsp
@@ -2033,6 +2263,9 @@ examples/servlet/SnoopServlet
examples/servlets/servlet/CookieExample
examples/servlets/servlet/RequestHeaderExample
exception.log
+exchange/
+exchweb/
+exec
expires.conf
exploded-archives/
explore
@@ -2058,6 +2291,7 @@ extjs/
extjs/resources//charts.swf
extras/documentation
ezsqliteadmin/
+fabric/
fake-eggs/
FakesAssemblies/
FAQ
@@ -2066,6 +2300,10 @@ fastlane/readme.md
fastlane/report.xml
fastlane/screenshots
fastlane/test_output
+fcgi-bin/echo
+fcgi-bin/echo.exe
+fcgi-bin/echo2
+fcgi-bin/echo2.exe
FCKeditor
fckeditor
FCKeditor/
@@ -2119,8 +2357,14 @@ filemanager/
filemanager/views/js/ZeroClipboard.swf
filerun.php
filerun/
+files.7z
files.md5
files.php
+files.rar
+files.tar
+files.tar.bz2
+files.tar.gz
+files.zip
files/
Files/binder.autosave
Files/binder.backup
@@ -2131,15 +2375,20 @@ files/tmp/
Files/user.lock
fileupload/
filezilla.xml
+findbugs/
+firebase-debug.log
flash/
flash/ZeroClipboard.swf
flashFXP.ini
fluent.conf
fluent_aggregator.conf
+flyway
+fmr.php
formslogin/
forum.rar
forum.sql
forum.tar
+forum.tar.bz2
forum.tar.gz
forum.zip
forum/
@@ -2157,6 +2406,8 @@ fuel/app/config/
fuel/app/logs/
function.require
functions/
+ganglia/
+gateway/
gaza.php
gbpass.pl
Gemfile
@@ -2167,10 +2418,13 @@ Generated_Code/
get.php
getFile.cfm
git-service
+git/
github-cache
github-recovery-codes.txt
+github/
gitlab/
gitlog
+gl/
global
global.asa
global.asa.bak
@@ -2186,16 +2440,25 @@ global.asax.temp
global.asax.tmp
globals
globals.inc
+globals.jsa
globes_admin/
+glpi/
google-services.json
grabbed.html
gradle-app.setting
+gradle/
+grafana/
graphiql.php
graphiql/
+graphite/
+graphql.js
graphql.php
graphql/
graphql/console/
grappelli/
+graylog/
+groovy/
+groupexpansion/
gruntfile.coffee
Gruntfile.coffee
GruntFile.coffee
@@ -2214,18 +2477,24 @@ gulpfile.js
Gulpfile.js
gwt-unitCache/
h2console
+hac/
+happyaxis.jsp
+haproxy/
health
health.json
+healthcheck.php
heapdump
heapdump.json
HISTORY
HISTORY.txt
+hmc/
HNAP1/
hndUnblock.cgi
home.html
home.php
home.rar
home.tar
+home.tar.bz2
home.tar.gz
home.zip
Homestead.json
@@ -2245,6 +2514,10 @@ htaccess.old
htaccess.txt
htdocs
htgroup
+html.tar
+html.tar.bz2
+html.tar.gz
+html.zip
html/
html/config.rb
html/js/misc/swfupload/swfupload.swf
@@ -2267,10 +2540,13 @@ httpd/logs/access.log
httpd/logs/access_log
httpd/logs/error.log
httpd/logs/error_log
+httptrace
hudson/
hudson/login
+hybridconfig/
hystrix
i.php
+icinga/
id_dsa
id_dsa.ppk
id_rsa
@@ -2283,6 +2559,7 @@ images/Sym.php
import.php
import/
import_error.log
+importcockpit/
in/
inc/
inc/config.inc
@@ -2325,11 +2602,16 @@ index.php3
index.php4
index.php5
index.php~
+index.tar
+index.tar.bz2
+index.tar.gz
index.xml
+index.zip
index2.php
index3.php
index_manage
Indy_admin/
+influxdb/
info
info.json
info.php
@@ -2389,7 +2671,9 @@ installer.php
installer_files/
install~/
instance/
+integrationgraph
Intermediate/
+internal/docs
invoker/
invoker/JMXInvokerServlet
invoker/readonly/JMXInvokerServlet
@@ -2402,25 +2686,42 @@ irequest/
isadmin
isadmin.php
ispmgr/
+iwa/authenticated.aspx
+iwa/iwa_test.aspx
j2ee/servlet/SnoopServlet
+jacoco/
Jakefile
javascripts/bundles
javax.faces.resource.../
javax.faces.resource.../WEB-INF/web.xml.jsf
+jboss-net/
+jboss-net//happyaxis.jsp
+jboss-net/happyaxis.jsp
jboss/server/all/deploy/project.ext
jboss/server/all/log/
jboss/server/default/deploy/project.ext
jboss/server/default/log/
jboss/server/minimal/deploy/project.ext
jbossws/services
+jbpm-console/app/tasks.jsf
jdbc
+jdkstatus
+jenkins/
Jenkinsfile
jira/
+jk-status
+jk/
+jkmanager
+jkmanager-auth
+jkstatus
+jkstatus-auth
jmx-console
jmx-console/
jmx-console/HtmlAdaptor?action=inspectMBean&name=jboss.system:type=ServerInfo
jo.php
+jolokia
jolokia/
+jolokia/list
joomla.rar
joomla.xml
joomla.zip
@@ -2428,7 +2729,11 @@ joomla/
joomla/administrator
js/
js/elfinder/elfinder.php
+js/envConfig.js
js/FCKeditor
+js/prepod.js
+js/prod.js
+js/qa.js
js/routing
js/swfupload/swfupload.swf
js/swfupload/swfupload_f9.swf
@@ -2446,13 +2751,27 @@ jsp-reverse.jsp
jsp/viewer/snoop.jsp
jspm_packages/
jssresource/
+juju/
+junit/
+kafka/
+kairosdb/
karma.conf.js
kcfinder/
kcfinder/browse.php
keys.json
+kibana/
killer.php
+known_tokens.csv
kpanel/
+krb.log
+krblog.txt
+kube-apiserver.log
+kube-controller-manager.log
+kube-proxy.log
+kube-scheduler.log
kube/
+kuber/
+kubernetes/
l0gs.txt
L3b.php
lander.logs
@@ -2461,9 +2780,11 @@ latest/user-data
layouts/
ldap.prop
ldap.prop.sample
+ldap/
letmein
letmein.php
letmein/
+level
lg/
lg/lg.conf
lia.cache
@@ -2494,7 +2815,9 @@ LICENSE.md
license.php
license.txt
LICENSE.txt
+license_key.php
liferay.log
+liferay/
lighttpd.access.log
lighttpd.error.log
lilo.conf
@@ -2503,6 +2826,7 @@ linkhub/
linkhub/linkhub.log
linktous.html
linusadmin-phpinfo.php
+liquibase
list_emails
listener.log
lists/
@@ -2519,6 +2843,8 @@ local/composer.lock
local/composer.phar
local_bd_new.txt
local_bd_old.txt
+local_conf.php.bac
+local_conf.php.bak
local_settings.py
localhost.sql
localsettings.php.bak
@@ -2534,6 +2860,7 @@ log-in.php
log-in/
log.htm
log.html
+log.json
log.mdb
log.php
log.sqlite
@@ -2578,6 +2905,7 @@ login.asp
login.cgi
login.htm
login.html
+login.json
login.php
login/
login/admin/admin.asp
@@ -2629,6 +2957,7 @@ logs/wsadmin.traceout
logs/www-error.log
logs_backup/
logs_console/
+logstash/
lol.php
Lotus_Domino_Admin/
ltmain.sh
@@ -2646,6 +2975,8 @@ magmi/
magmi/conf/magmi.ini
mail
mail.log
+mail/
+Mail/smtp/Admin/smadv.asp
mailer/.env
mailman/
mailman/listinfo
@@ -2675,6 +3006,8 @@ manage_index
management
management.php
management/
+management/configprops
+management/env
manager
manager.php
manager/
@@ -2695,13 +3028,27 @@ manuallogin/
mappings
mappings.json
master.passwd
+master.tar
+master.tar.bz2
+master.tar.gz
master.zip
master/
master/portquotes_new/admin.log
+mattermost/
+maven/
mbox
+mcollective/
+mcx/
+mcx/mcxservice.svc
mdate-sh
+media.tar
+media.tar.bz2
+media.tar.gz
+media.zip
media/
media/export-criteo.xml
+meet/
+meeting/
member
member.php
member/
@@ -2723,24 +3070,34 @@ members.txt
members.xls
members/
membersonly
+memcached/
memlogin/
mercurial.ini
+mercurial/
Mercury.modules
Mercury/
+mesos/
META-INF/
META-INF/context.xml
META.json
META.yml
meta_login/
metadata.rb
+metric/
metric_tracking
metric_tracking.json
metrics
metrics.json
metrics/
-metrics/*.json
+microsoft-server-activesync/
+mics/
+mics/mics.html
+mifs/
+mifs/user/index.html
mimosa-config.coffee
mimosa-config.js
+mirror.cfg
+mirror/
misc
missing
mkdocs.yml
@@ -2772,6 +3129,10 @@ Module.symvers
modules.order
modules/
modules/admin/
+mongo/
+mongodb/
+monit/
+monitor
monitor/
monitoring
monitoring/
@@ -2786,6 +3147,12 @@ munin/
muracms.esproj
mw-config/
mx.php
+my.7z
+my.rar
+my.tar
+my.tar.bz2
+my.tar.gz
+my.zip
myadm/
MyAdmin/
myadmin/
@@ -2800,6 +3167,11 @@ mysql-admin/index.php
mysql.err
mysql.log
mysql.php
+mysql.sql
+mysql.tar
+mysql.tar.bz2
+mysql.tar.gz
+mysql.zip
mysql/
mysql/admin/
mysql/db/
@@ -2818,6 +3190,7 @@ mysqladmin/scripts/setup.php
mysqldumper/
mysqlitedb.db
mysqlmanager/
+naginator/
nagios/
nano.save
native_stderr.log
@@ -2830,12 +3203,21 @@ nbproject/private/private.properties
nbproject/private/private.xml
nbproject/project.properties
nbproject/project.xml
+netdata/
New%20Folder
New%20folder%20(2)
+new.7z
new.php
+new.rar
+new.tar
+new.tar.bz2
+new.tar.gz
+new.zip
newbbs/
newbbs/login
newsadmin/
+nextcloud/
+nfs/
ng-cli-backup.json
nginx-access.log
nginx-error.log
@@ -2848,6 +3230,7 @@ ngx_pagespeed_beacon/
nia.cache
nimcache/
nlia.cache
+node-role.kubernetes.io
node_modules
node_modules/
nohup.out
@@ -2862,24 +3245,39 @@ nsw/admin/login.php
nwp-content/
nwp-content/plugins/disqus-comment-system/disqus.php
nytprof.out
+oab/
obj/
+ocp.php
+ocsp/
odbc
Office/
Office/graph.php
olap/
old
+old.7z
old.htaccess
old.htpasswd
+old.rar
+old.tar
+old.tar.bz2
+old.tar.gz
+old.zip
old/
old_files
old_site/
oldfiles
+ona
opa-debug-js
-open-flash-chart.swf?get-data=(function(){alert(document.domain)})()
+open-flash-chart.swf?get-data=xss
OpenCover/
+openshift/
+openstack/
+opentsdb/
openvpnadmin/
operador/
operator/
+oprocmgr-service
+oprocmgr-status
ops/
oracle
order.log
@@ -2896,12 +3294,16 @@ orders.xls
orders_log
orleans.codegen.cs
ospfd.conf
+osticket/
+otrs/
out.txt
out/
output
output-build.txt
output/
OWA/
+owa/
+owncloud/
p.php
p/
p/m/a/
@@ -2909,7 +3311,9 @@ package-cache
package-lock.json
package.json
Package.StoreAssociation.xml
+package/
packer_cache/
+pagerduty/
pages/
pages/admin/
pages/admin/admin-login
@@ -2960,9 +3364,11 @@ payment.log
payment_authorizenet.log
payment_paypal_express.log
pbmadmin/
+pbx/
pentaho/
perl-reverse-shell.pl
perlcmd.cgi
+persistentchat/
personal
personal.mdb
personal.sqlite
@@ -2972,6 +3378,8 @@ pgadmin.log
pgadmin/
PharoDebug.log
phinx.yml
+phoenix
+phoneconferencing/
php
php-backdoor.php
php-cgi.core
@@ -2991,6 +3399,7 @@ php-myadmin/
php-reverse-shell.php
php-tiny-shell.php
php.core
+php.error.log
php.ini
php.ini-orig.txt
php.ini.sample
@@ -3037,13 +3446,14 @@ phpinfos.php
phpini.bak
phpldapadmin
phpldapadmin/
-phpliteadmin 2.php
+phpliteadmin%202.php
phpliteadmin.php
phpLiteAdmin/
phpLiteAdmin_/
phpm/
phpma/
phpma/index.php
+phpmailer
phpmanager/
phpmem/
phpmemcachedadmin/
@@ -3237,6 +3647,7 @@ play-stash
player.swf
playground.xcworkspace
plugin.xml
+plugins
plugins.log
plugins/
plugins/editors/fckeditor
@@ -3291,6 +3702,8 @@ pom.xml.versionsBackup
portal/
postgresql.conf
power_user/
+powershell/
+pprof/
printenv
printenv.tmp
priv8.php
@@ -3303,6 +3716,7 @@ Procfile
Procfile.dev
Procfile.offline
product.json
+productcockpit/
production.log
profiles
profiles.xml
@@ -3315,6 +3729,7 @@ project.xml
project/project
project/target
prometheus
+prometheus/
prometheus/targets
propel.ini
protected/data/
@@ -3322,10 +3737,12 @@ protected/runtime/
providers.json
proxy.pac
proxy.stream?origin=https://google.com
+proxy/
prv/
PSUser/
public
public..
+public/
public/hot
public/storage
public/system
@@ -3333,6 +3750,7 @@ publication_list.xml
publish/
PublishScripts/
pubspec.lock
+puppet/
pureadmin/
putty.reg
pw.txt
@@ -3353,15 +3771,19 @@ r57eng.php
r57shell.php
r58.php
r99.php
+rabbitmq/
+radius/
radmind-1/
radmind/
rails/info/properties
Rakefile
+raygun/
rcf/
rcjakar/
rcjakar/admin/login.php
rcLogin/
rdoc/
+reach/sip.svc
Read
Read%20Me.txt
read.me
@@ -3390,11 +3812,13 @@ README.TXT
ReadMe.txt
Readme.txt
recentservers.xml
+redis/
redmine/
refresh
refresh.json
register.php
registration/
+registry/
rel/example_project
release.properties
RELEASE_NOTES.txt
@@ -3404,7 +3828,11 @@ relogin.html
relogin.php
remote/fgt_lang?lang=/../../../../////////////////////////bin/sslvpnd
remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession
+repo/
request.log
+requesthandler/
+requesthandlerext/
+requirements.txt
rerun.txt
reseller
resources.xml
@@ -3416,6 +3844,8 @@ resources/tmp/
rest-api/
rest-auth/
rest/
+rest/v1
+rest/v3/doc
restart
restart.json
restore.php
@@ -3424,6 +3854,8 @@ resume
resume.json
revision.inc
revision.txt
+rgs/
+rgsclients/
robot.txt
robots.txt
robots.txt.dist
@@ -3431,8 +3863,11 @@ root/
RootCA.crt
roundcube/index.php
rpc/
+rpcwithcert/
rsconnect/
rst.php
+rudder/
+run.sh
RushSite.xml
s.php
sa.php
@@ -3444,9 +3879,14 @@ sales.sql.gz
sales.txt
sales.xls
salesforce.schema
+saltstack/
sample.txt
sample.txt~
Saved/
+sbt/
+scalyr/
+scheduledtasks
+scheduler/
schema.sql
schema.yml
script/
@@ -3461,23 +3901,31 @@ sdb.php
sdist/
searchreplacedb2.php
searchreplacedb2cli.php
+secret
Secret/
secret/
+secrets.env
secrets/
secring.bak
secring.pgp
secring.skr
secure/
security/
+selenium/
sendgrid.env
+sensu/
sentemails.log
+sentry/
serv-u.ini
Server
server-info
server-status/
+server.cert
server.cfg
server.js
+server.key
server.log
+server.ovpn
Server.php
server.pid
server.xml
@@ -3494,18 +3942,22 @@ serverStatus.log
service-registry/instance-status
service-registry/instance-status.json
service.asmx
+serviceaccount.crt
ServiceFabricBackup/
services
services/
services/config/databases.yml
servlet/
servlet/%C0%AE%C0%AE%C0%AF
+servlet/DMSDump
servlet/Oracle.xml.xsql.XSQLServlet/soapdocs/webapps/soap/WEB-INF/config/soapConfig.xml
servlet/oracle.xml.xsql.XSQLServlet/soapdocs/webapps/soap/WEB-INF/config/soapConfig.xml
servlet/Oracle.xml.xsql.XSQLServlet/xsql/lib/XSQLConfig.xml
servlet/oracle.xml.xsql.XSQLServlet/xsql/lib/XSQLConfig.xml
servlet/SnoopServlet
+servlet/Spy
session/
+sessions
sessions/
settings.php
settings.php.bak
@@ -3533,8 +3985,11 @@ shell.sh
shell/
shellz.php
shopdb/
+show
showcode.asp
showlogin/
+shutdown
+sidekiq
sidekiq_monitor
sign-in
sign-in/
@@ -3546,11 +4001,15 @@ signin/
signup.action
simple-backdoor.php
simpleLogin/
+sip/
site
site.rar
site.sql
+site.tar
+site.tar.bz2
site.tar.gz
site.txt
+site.zip
site/
site/common.xml
site_admin
@@ -3572,10 +4031,16 @@ sized/
slapd.conf
smblogin/
snoop.jsp
+snort/
soap/
+soap/servlet/soaprouter
+soap/servlet/Spy
soapdocs/
soapdocs/webapps/soap/WEB-INF/config/soapConfig.xml
soapserver/
+sonar/
+sonarcube/
+sonarqube/
source
source.php
source/
@@ -3590,6 +4055,7 @@ spec/lib/database.yml
spec/lib/settings.local.yml
spec/reports/
spec/tmp
+splunk/
spwd.db
spy.aspx
sql-admin/
@@ -3597,6 +4063,8 @@ sql.inc
sql.php
sql.sql
sql.tar
+sql.tar.bz2
+sql.tar.gz
sql.tgz
sql.txt
sql.zip
@@ -3624,6 +4092,7 @@ sqladmin/
sqlbuddy
sqlbuddy/
sqlbuddy/login.php
+sqldump.sql
sqlmanager/
sqlmigrate.php
sqlnet.log
@@ -3631,6 +4100,8 @@ sqlweb/
SQLyogTunnel.php
SqueakDebug.log
squid-reports/
+squid/
+squid3_log/
src/
src/app.js
src/index.js
@@ -3642,6 +4113,7 @@ ssh/
sshadmin/
ssl/
st.php
+stackstorm/
stacktrace.log
staff/
stamp-h1
@@ -3649,7 +4121,10 @@ staradmin/
start.html
start.sh
startServer.log
+startup.cfg
startup.sh
+stas/
+stash/
stat/
static..
static/dump.sql
@@ -3657,12 +4132,15 @@ statistics
statistics/
stats
stats/
+statsd/
+status.php
status.xsl
status/
status?full=true
statusicon/
storage/
storage/logs/laravel.log
+store.tgz
StreamingStatistics
stronghold-info
stronghold-status
@@ -3670,6 +4148,7 @@ stssys.htm
StyleCopReport.xml
stylesheets/bundles
sub-login/
+subversion/
sugarcrm.log
supe.php
super
@@ -3694,21 +4173,28 @@ supervise/
supervise/Logi.php
supervise/Login
supervisor/
+supervisord/
+support/
support_login/
surgemail/
surgemail/mtemp/surgeweb/tpl/shared/modules/swfupload.swf
surgemail/mtemp/surgeweb/tpl/shared/modules/swfupload_f9.swf
suspended.page
svn.revision
-SVN/
svn/
+SVN/
+swagger
swagger-resources
+swagger-ui
swagger-ui.html
swagger.json
swagger.yaml
swagger/index.html
+swagger/swagger-ui.htm
swagger/swagger-ui.html
+swagger/ui
swagger/v1/swagger.json
+swaggerui
swfobject.js
swfupload
swfupload.swf
@@ -3735,6 +4221,7 @@ sypex.php
sypexdumper.php
SypexDumper_2011/
sys-admin/
+sys/pprof
sysadm
sysadm.php
sysadm/
@@ -3767,14 +4254,18 @@ tags
tar
tar.bz2
tar.gz
+tar.php
target
target/
+tasks/
tconn.conf
+team/
technico.txt
telephone
telphin.log
temp-testng-customsuite.xml
temp.php
+temp.sql
TEMP/
temp/
template/
@@ -3787,6 +4278,7 @@ templates/protostar/
templates/rhuk_milkyway/index.php
templates/system/
templates_c/
+teraform/
test
test-build/
test-driver
@@ -3836,9 +4328,11 @@ themes
themes/
themes/default/htdocs/flash/ZeroClipboard.swf
Thorfile
+threaddump
Thumbs.db
thumbs.db
thumbs/
+tikiwiki
timeline.xctimeline
tiny_mce/
tiny_mce/plugins/filemanager/examples.html
@@ -3849,9 +4343,11 @@ tinyfilemanager-2.2.0/
tinyfilemanager-2.3/
tinyfilemanager.php
tinyfilemanager/
+tinymce
tinymce/
-TMP
tmp
+TMP
+tmp.php
tmp/
tmp/2.php
tmp/access.log
@@ -3892,7 +4388,9 @@ tmp/whmcs.php
tmp/xd.php
TODO
tomcat-docs/appdev/sample/web/hello.jsp
+tomcat/axis/
tools
+tools.php
tools/
tools/_backups/
tools/phpMyAdmin/index.php
@@ -3901,6 +4399,9 @@ Trace.axd
Trace.axd::$DATA
trace.json
transmission/web/
+tresearch/
+tresearch/happyaxis.jsp
+tripwire/
trivia/
tsconfig.json
tst
@@ -3920,7 +4421,13 @@ uber/
uber/phpMemcachedAdmin/
uber/phpMyAdmin/
uber/phpMyAdminBackup/
+ucwa/
+uddi
+uddiexplorer
+ui
+ui/
unattend.txt
+unifiedmessaging/
up.php
update
update.php
@@ -3932,7 +4439,9 @@ upgrade.php
upgrade.readme
UPGRADE.txt
UpgradeLog.XML
+upguard/
upl.php
+upload
Upload
upload.asp
upload.aspx
@@ -3986,6 +4495,7 @@ user_guide_src/cilexer/pycilexer.egg-info/
user_uploads
useradmin
useradmin/
+userdb
UserFile
UserFiles
userfiles
@@ -4016,10 +4526,22 @@ usuarios/login.php
utility_login/
uvpanel/
uwsgi.ini
+v1
+v1.0
+v1.1
+v1/
+v1/public/yql
+v1/test/js/console.html
+v1/test/js/console_ajax.js
+v2
+v2.0
+v2/
v2/_catalog
v2/keys/?recursive=true
+v3
vadmind/
vagrant-spec.config.rb
+vagrant/
Vagrantfile
Vagrantfile.backup
validator.php
@@ -4039,6 +4561,8 @@ var/log/payment_paypal_express.log
var/logs/
var/package/
var/sessions/
+variant/
+vault/
vb.rar
vb.sql
vb.zip
@@ -4046,6 +4570,7 @@ vendor/
vendor/assets/bower_components
vendor/bundle
vendor/composer/installed.json
+vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
vendors/
venv.bak/
venv/
@@ -4056,7 +4581,10 @@ version/
video-js.swf
view-source
view.php
+views
vignettes/
+violations/
+vm
vmailadmin/
vorod
vorod.php
@@ -4127,12 +4655,15 @@ webadmin/index.html
webadmin/index.php
webadmin/login.html
webadmin/login.php
+webalizer
+webapp/wm/runtime.jsp
webdav.password
webdav/
webdav/index.html
webdav/servlet/webdav/
webdb/
webgrind
+weblogs
webmail/
webmail/src/configtest.php
webmaster
@@ -4140,11 +4671,20 @@ webmaster.php
webmaster/
webmin/
webpack.config.js
+webpack.mix.js
website.git
+website.tar
+website.tar.bz2
+website.tar.gz
+website.zip
websql/
+webstat
webstat/
+webstats
webstats.html
webstats/
+webticket/
+webticket/webticketservice.svc
weixiao.php
wenzhang
wheels/
@@ -4153,6 +4693,10 @@ whmcs/
whmcs/downloads/dz.php
wiki/
wizmysqladmin/
+wordpress.tar
+wordpress.tar.bz2
+wordpress.tar.gz
+wordpress.zip
wordpress/
wordpress/wp-login.php
workspace.xml
@@ -4173,6 +4717,7 @@ wp-config.php.old
wp-config.php.save
wp-config.php.swp
wp-config.php.txt
+wp-config.php.zip
wp-config.php~
wp-content/
wp-content/backup-db/
@@ -4187,6 +4732,7 @@ wp-content/plugins/hello.php
wp-content/upgrade/
wp-content/uploads/
wp-content/uploads/dump.sql
+wp-content/uploads/file-manager/log.txt
wp-includes/
wp-includes/rss-functions.php
wp-json/
@@ -4209,10 +4755,13 @@ wsadmin.traceout
wsadmin.valout
wsadminListener.out
wshell.php
+wsman
WSO.php
wso.php
wso2.5.1.php
wso2.php
+wssgs/
+wssgs/happyaxis.jsp
wstats
wuwu11.php
wvdial.conf
@@ -4221,12 +4770,14 @@ www-test/
www.rar
www.sql
www.tar
+www.tar.bz2
www.tar.gz
www.tgz
www.zip
www/phpMyAdmin/index.php
wwwboard/
wwwboard/passwd.txt
+wwwlog
wwwroot.7z
wwwroot.rar
wwwroot.sql
@@ -4235,6 +4786,7 @@ wwwroot.tar.bz2
wwwroot.tar.gz
wwwroot.tgz
wwwroot.zip
+wwwstat
wwwstats.htm
x.php
xampp/
@@ -4254,6 +4806,7 @@ xmlrpc.php
xmlrpc_server.php
xphperrors.log
xphpMyAdmin/
+xprober.php
xshell.php
xsl/
xsl/_common.xsl
@@ -4283,6 +4836,7 @@ zehir.php
zeroclipboard.swf
zf_backend.php
zimbra/
+zipkin/
zone-h.php
~/
~admin/