IP Address Harvesting Lewat Signature (PHPBB)

Forum untuk membahas semua tentang web hacking mulai dari footprint, scanning, gain access, escalate previlege, exploit,cover track, backdoors sampai mengamankan web

Moderators: Paman, Xshadow, indounderground, NeOS-01

Forum rules
Membahas bugs,penetrasi, eksploitasi dan teknik mengamankan website - websrver. Sertakan POC disini agar member dapat mempelajarinya
Post Reply
User avatar
shad.hckr
Posts: 555
Joined: Mon Sep 29, 2008 4:48 am
Location: /home/sh4dhckr
Contact:

IP Address Harvesting Lewat Signature (PHPBB)

Post by shad.hckr » Wed Mar 10, 2010 8:21 pm

awalnya iseng bikin IP visitor tapi kujadiin image biar bisa dipasang di signature forum Xcode tercinta..
ternyata bisa tampil dengan sempurna dengan code :

Code: Select all

<?php

$sh4d = ' sh4dhckr said your IP is '.$_SERVER['REMOTE_ADDR'].' ';

$i = imagecreate(strlen($sh4d)*8,15);
$b = imagecolorallocate($i,0,0,0);
$t = imagecolorallocate($i,0,255,0);
imagestring($i,4,2,0,$sh4d,$t);

header('Content-type: image/gif');
imagegif($i);
imagedestroy($i);

?>
trus pas lagi iseng nyari mangsa buat metasploit tau2 dapet ide buat IP Logger di Forum..
aku sisipin code buat log IP :

Code: Select all

<?
$log="log.txt";
$ip = $_SERVER['REMOTE_ADDR'];
$cookie = $_SERVER['QUERY_STRING'];
$rem_host = $_SERVER['REMOTE_HOST'];
$rem_port = $_SERVER['REMOTE_PORT'];
$user_agent = $_SERVER['HTTP_USER_AGENT'];
$rqst_method = $_SERVER['METHOD'];
$file = fopen($log,'a+');

echo fwrite($file, "IP: $ip \nPORT: $rem_port \nHOST: $rem_host \nAgent: $user_agent \nMETHOD: $rqst_method \nCOOKIE:  $cookie \n\n"); 
fclose($file);

?>
habis itu aku cek di log ternyata BERHASIL.. :kaca: :kaca:

sekian.. semoga bermanfaat.. :maaf: :maaf: :maaf:

User avatar
poni
Posts: 1666
Joined: Mon Dec 05, 2005 10:44 am
Location: Indonesia
Contact:

Re: IP Address Harvesting Lewat Signature (PHPBB)

Post by poni » Wed Mar 10, 2010 8:45 pm

IP Harvesting.. cool. nice share brother..
tuh hasil panen IP na dibawah ini

Code: Select all

http://sh4dhckr.com/tools/log.txt
Last edited by shad.hckr on Wed Mar 10, 2010 8:54 pm, edited 1 time in total.
Reason: ikut ngedit benerin extensi nama file.. :p
.::...Cr3ditz......::....
join us : www.xcode.or.id - 001101
"@ b3tt3r d1g1t4l w0rlD" -- 010110000110001001

User avatar
shad.hckr
Posts: 555
Joined: Mon Sep 29, 2008 4:48 am
Location: /home/sh4dhckr
Contact:

Re: IP Address Harvesting Lewat Signature (PHPBB)

Post by shad.hckr » Wed Mar 10, 2010 8:53 pm

iseng aja pak.. :circle: :circle:
kayaknya ada yang diedit tuh.. :p ckikikiki.. :licik: :licik: :licik:
tapi gak papa kok om.. :ngakak: :ngakak:
biar agak sopan dikit ya om.. :malumalu: :malumalu: :malumalu:
hohohoho..

EDITED : ternyata gak diedit.. tapi kena sensor kata mutiara forum.. :p

User avatar
vodork
Posts: 191
Joined: Wed Jun 10, 2009 1:52 am
Location: jogja/sarkem
Contact:

Re: IP Address Harvesting Lewat Signature (PHPBB)

Post by vodork » Sat Mar 20, 2010 2:10 pm

shad.hckr wrote:awalnya iseng bikin IP visitor tapi kujadiin image biar bisa dipasang di signature forum Xcode tercinta..
ternyata bisa tampil dengan sempurna dengan code :

Code: Select all

<?php

$sh4d = ' sh4dhckr said your IP is '.$_SERVER['REMOTE_ADDR'].' ';

$i = imagecreate(strlen($sh4d)*8,15);
$b = imagecolorallocate($i,0,0,0);
$t = imagecolorallocate($i,0,255,0);
imagestring($i,4,2,0,$sh4d,$t);

header('Content-type: image/gif');
imagegif($i);
imagedestroy($i);
?>
trus pas lagi iseng nyari mangsa buat metasploit tau2 dapet ide buat IP Logger di Forum..
aku sisipin code buat log IP :

Code: Select all

<?
$log="log.txt";
$ip = $_SERVER['REMOTE_ADDR'];
$cookie = $_SERVER['QUERY_STRING'];
$rem_host = $_SERVER['REMOTE_HOST'];
$rem_port = $_SERVER['REMOTE_PORT'];
$user_agent = $_SERVER['HTTP_USER_AGENT'];
$rqst_method = $_SERVER['METHOD'];
$file = fopen($log,'a+');

echo fwrite($file, "IP: $ip \nPORT: $rem_port \nHOST: $rem_host \nAgent: $user_agent \nMETHOD: $rqst_method \nCOOKIE:  $cookie \n\n"); 
fclose($file);

?>
habis itu aku cek di log ternyata BERHASIL.. :kaca: :kaca:

sekian.. semoga bermanfaat.. :maaf: :maaf: :maaf:
ipku mlebu nang logmu :gebrak: :gebrak:
.::[tresno jalaran saking kulino]::.

.::[nek wes kullino]::.

.::[karepmu]::.

User avatar
Xshadow
Posts: 482
Joined: Thu May 31, 2007 8:01 pm
Location: http://captureflags.com
Contact:

Re: IP Address Harvesting Lewat Signature (PHPBB)

Post by Xshadow » Sat Mar 20, 2010 3:26 pm

trus korbannya anak xcode juga?
[X]perimental [S]ynthetic [H]umanoid [A]ssembled for [D]estruction and [O]nline [W]arfare

User avatar
t3cm4n
Posts: 50
Joined: Sat Sep 27, 2008 6:55 am
Location: S 06*52.406' E 112*21.631' Elev 49m

Re: IP Address Harvesting Lewat Signature (PHPBB)

Post by t3cm4n » Mon Mar 22, 2010 12:31 am

Mantab bro and lanjut kan he..e..e..yg lebih seru
" Keep Learning & Never Surrender "
Image

User avatar
shad.hckr
Posts: 555
Joined: Mon Sep 29, 2008 4:48 am
Location: /home/sh4dhckr
Contact:

Re: IP Address Harvesting Lewat Signature (PHPBB)

Post by shad.hckr » Tue Mar 23, 2010 8:49 am

@master Xshadow
iya mas.. saya sudah confirm sama mas poni di channel #xcode tentang masalah signature ini dan beliau bilang nggak papa. publish aja.

log yang masuk salah satunya juga dari forum ini. apabila ada yang tidak berkenan dengan log tersebut akan saya hapus log dan signature tersebut. namun tidak menutup kemungkinan ada pihak lain yang memanfaatkannya di forum ini juga.
:maaf: :maaf: :maaf: :maaf: :maaf: :maaf:

Post Reply

Return to “Web Hacking”