Rabu, 04 April 2012

PHP Flooder Tested by Ze Cor

Buat kmu yg udah punya bnyak hosting ato punya shell di hosting2 yg buanyaks

Bisa dipaki buat Flood nie ane tulis PHP floodernya, jgn dipake yg gak bener ya, ato dipake nyerang we yg nulis nie janji..?? okay ane anggap kmu kmu setuju ma we ;) we are brother


Exploit Untuk Wordpress

Wordpress Exploit ;)

timthumb php file inclusion

wp-content/plugins/category-grid-view-gallery/includes/timthumb.php

AllWebMenus WordPress Menu Plugin

wp-content/plugins/allwebmenus-wordpress-menu-plugin/actions.php

Count per Day

wp-content/plugins/count-per-day/map/map.php

Whois Search Plugin

wp-content/plugins/wordpress-whois-search/vendors/samswhois/samswhois.inc.php

WP Symposium A Social Network For WordPress


OneFileCMS v.1.1.5 Local File Inclusion Vulnerability

# Exploit Title: OneFileCMS v.1.1.5 Local File Inclusion Vulnerability
# Google Dork: --
# Date: 16/03/2012
# Author: mr.pr0n (@_pr0n_)
# Homepage: http://ghostinthelab.wordpress.com/ - http://s3cure.gr
# Software Link: https://github.com/rocktronica/OneFileCMS
# Version: OneFileCMS v.1.1.5
# Tested on: Linux Fedora 14
===============
Description
===============

Encaps PHP Gallery SQL Injection

# Exploit Title: Encaps PHP Gallery SQL Injection
# Date: 14/03/2012
# Author: Daniel Godoy
# Author Mail: DanielGodoy[at]GobiernoFederal[dot]com
# Author Web: www.delincuentedigital.com.ar
# Software: Encaps PHP Gallery
# http://www.encaps.net/software/encapsgallery/
# Tested on: Linux
# Dork: "shopcart.php?action=add&item_id="

DirectAdmin ADD Sub Domain CSRF Exploit

#!/usr/bin/perl
########################################################################
# Title    : DirectAdmin Web Control Panel � 2005 JBMC Software
# Author   : Onur T�RKE�HAN
# Homepage : http://www.directadmin.com/
# tested on : Windows 7
# Seni Unutmayacagiz MIRIM-

Webdav vulnerability google dork

Google dork:

intitle:"index.of" intext:"(Win32) DAV/2" intext:"Apache"

or

intitle:"index.of" intext:"(Win32) DAV/2" intext:"Apache" site:edu

or intitle:"index.of" intext:"(Win32) DAV/2" intext:"Apache" site:gov

or intitle:"index.of" intext:"(Win32) DAV/2" intext:"Apache" site:YOURCOUNTRY

Just add the /webdav extension to the URL if you found "WebDAV testpage"

So go ahead it's Webdav vulnerability hackable :)

Example:

http://www.hebron.edu/webdav/
http://www.jcjc.edu/webdav/
http://archnet.asu.edu/webdav/
http://mvl.mit.edu/webdav/
http://www.engl.niu.edu/webdav/
http://www.mstc.edu/webdav/

Enjoy.
©2011, copyright BLACK BURN

Awas! Bahaya Wifi Percuma

Mungkin ramai yang suka atau sering online facebook, twitter, email dan sebagainya di tempat awam yang menyediakan kemudahan internet atau wifi percuma terutamanya di kolej, kedai-kedai makan, pusat membeli belah dan sebagainya. Tapi tahukah anda online di tempat terbuka sebenarnya berisiko tinggi untuk di hack?

Ya betul, online di tempat terbuka memang memudahkan akaun anda di godam oleh pihak yang tidak bertanggungjawab menggunakan kaedah Rampasan Sesi atau Session Hijacking dengan menggunakan Firesheep iaitu add on yang di buat untuk browser Mozilla Firefox.

Dengan teknik ini, pengodam dengan mudah dapat mencuri cookies iaitu data lengkap tentang akaun seseorang yang terdapat dalam komputer/ laptop pemangsa. Ianya memang mudah bagi yang pakar.. ekeke, apabila dapat cookies atau data ni, pengodam hanya terus masuk ke akaun pemangsa tanpa perlu log in, bahaya bukan? bagaimana dengan urusan perbankan? memang bahaya.


Jadi antara tips-tips yang boleh diberi:-

1. Jangan log masuk atau online dekat wifi percuma yang pelik- pelik di kawasan perumahan yang tidak diketahui datang dari mana.

2. Kalau dah selesai urusan di internet, cepat-cepat log keluar dan clear history dan cookies.

3. Jangan log in di mana – mana laman web yang tidak mempunyai https dalam url laman web nya. (Dikatakan laman web yang menggunakan https lebih selamat daripada rampasan sesi Session Hijacking.

4. Nak selamat, jangan buat urusan perbankan seperti maybank2u, cimb click di tempat awam dan di cyber cafe juga..


p/s: macam-macam cara atau teknik sekarang ni, hati-hati yer

Sumber : https://www.facebook.com/groups/NuhibbuQittun.KamiSayangKucing