_____ __ _____ ___ _____ ___ _____ _____ _____ _____ _____ _____ _____ _____ ____ _____ _ _ _ _____ | __|| | | | ||_ | | | || | | | __|| __|| __ || | || __|| __ | | || __| | \ | || | | || | | | __|| |__ | | | _| |_ | | | ||_ | |__ || __|| -|| | || __|| -| |- -||__ | | | || | || | | || | | | |_____||_____| \___/ |_____||_|___| |_| |_____||_____||__|__| \___/ |_____||__|__| |_____||_____| |____/ |_____||_____||_|___| I DONT WANT TO BE FAME , I DONT WANT TO BE ANY EZINE , I JUST WANT TO SHARE KNOWLEDGE
, ----. ~ Fuck full-disclosure - - ` ~ Fuck the security industry ,__.,' \ ~ Keep 0days private .' *` ~ Hack everyone you can and then hack some more / | | / **\ ~ Blend in. . / ****. ~ Get trusted. | mm | ****| ~ Trust no one. \ | ****| ~ Own everyone. ` ._______ \ ****/ ~ Disclose nothing. \ /`---' ~ Destroy everything. \___( ~ Take back the scene /~~~~\ ~ Never sell out, never surrender. / \ ~ Get in as anonymous, Leave with no trace. / | \ ~ This your Fucking IP | | \ ~ This your Fucking ISP , ~~ . |, ~~ . | |\ ~ FUCK OFF I've got enough friends !!!! ( |||| ) ( |||| )(,,,)` ( |||||| )-( |||||| ) | ^ ( |||||| ) ( |||||| ) |'/ ( |||||| )-( |||||| )___,'- ( |||| ) ( |||| ) ` ~~ ' ` ~~ '

[ Blog ]

[ History ]


Apa sih ?

pagi pagi buka browser dengan ditemani sedikit cemilan, nyoba buka sobekan kecil dengan php injecktion sekalian check file di suatu situs ( barangkali ada malware :P )


sial banget yang ini not w00t



tapi ketika tempelin hollyshit dan jessica
akhirnya masuk :P
heuheuheu


akhirnya datang juga




klik gambar biar jelas



lalu iseng melakukan touch system.

jangan lupa untuk mengisikan code php berikut bilamana akan melakukan perbaikan :)

$page = $_GET[page];
switch($page)
{
case “elvina.php”:
include(”elvina.php”);
break;
case “yess.php”:
include(”yess.php”);
break;
default:
include(”elvina.php”);
}
?>


dan setting server menjadi

allow_url_include = off
allow_url_fopen = off
magic_quotes_gpc= on
open_basedir = “/www/html/servelvina”



hal tersebut hanya untuk membedakan pengincludekan file yang hanya bisa dilakukan di elvina.php dan yess.php
dan jangan lupa untuk berhati-hati dalam penanggulangan 3rd party pada sebuah cms.
setting safe mode untuk menjadi on :)
dont forget to touch your system now !

contoh nya jadi gini

Warning: include() [function.include]: Failed opening '' for inclusion (include_path='.;E:\php5\ext;E:\php5\PEAR;E:\php5\PhpCommon') in I:\www\targetnya\public_html\yess.php on line 134



tapi nonsense cara pembaruan system seperti ini tidak menjamin system anda aman 100%
banyak sekali hole di situs anda yang vulner terhadap serangan lainnya.


.tHx

eLv1N4

Labels:


On 5/5/09 at 10:03 PM



My Profile:


Biography:

short story:

[ Friends Link ]

[ chat with me ]


[ archives ]

[ Notices ]

By title

Apa sih ?

By month

2002.03 2002.12 2005.12 2008.11 2009.02 2009.03 2009.04 2009.05 2009.06 2009.07 2009.08 2009.09 2009.10 2009.11 2009.12 2010.01 2010.03



 


elv1n4 Themes v2.0.0 © 2009 by elv1n4

www[dot]elv1n4.anti-sec[dot]org