Showing posts with label My Adventure. Show all posts
Showing posts with label My Adventure. Show all posts

Mar 25, 2013

Extract filezilla ftp password recent use,..mengextract password program ftp filezilla

Saya akan bercerita lagi ini,.
i want to tell you the story

Long time ago , i will make some event and i need several laptop for presentation , and than i borrow from it division,by theway i looked up at filezilla software
 
pada suatu hari saya ada mau bikin event, lah perlu laptop buat prensentasinya,  terus saya pinjem deh di divisi IT terkait eh, iseng iseng saya lihat aplikasi filezilla..

whatts,. there are many history about FTP server. i think  i have a jackpot
looked the picture bellow , so te first step i have the domain name and the user name,  so that way i need to find that passwords

loh kok di sana ada histori dari ftp2 data center,.. :-p  ,..
Serasa dapat jackpot,.. hehehehheehh... Niat Jahat mode On...
di situ terlihat ada dalamnya dan usernya dan host nya ,. kalau  begitu tinggal passwordnya donk..



dan terus di quick connect kalo kita pilih salah satu server,.. boom,, eh langsung masuk,..,
and than  from the softaware logic, conclude the softaware store some password in  the some where on the computer


di sini berarti ada penyimpanan password oleh file zilla tapi dimna,.
bentar lagi kalau acara selesai  lapto di ambil lagii,..
Hemmm Gimana yaww

Ok Lets find the passsword

find find find, use all posble software to find....

Search search seach cari, pakai software filemonitor reg monitor dan blabla bla bla,..


and than binggo ,. i found where it stored C:\Users\Three\AppData\Roaming\FileZilla\ recentservers.xml

Binggo ketemu ,.. Ternyata file password di simpan  C:\Users\Three\AppData\Roaming\FileZilla\ recentservers.xml




whatts no encrypts ,.. hemm it look yummy  :-p

Haizzz parahnya lagi tanpa enkripsi,... Hadewww,.. ini filezilla agak kacoo deh..... tapi ga apa dah,. aku udah dapat yang ku mau :-p


Evil Mode On






oke so that way becaraful if you use fillezilla , make sure you allway clear hystory after you connect to server,.Before you give your laptop to someone, its better you make sure you logout yoour facebook :-D

Sekian makanya ati2 kalao pakai filezilla kalau selesai connect clear historinya ,... apalagi kalao mau di pinjamkan orang jangan lupa facebooknya di logout dulu,.. :-D

Bye byee






melewati security upload by mime, Hack security upload using mime

Sudah lama tidak menulis jadi kangen juga ,  sekarang saya akan mendemokan bagaimana melewati security upload file dengan proteksy tipe file menggunakan mime,.

cerita saya ini sebagai bahan pelajaran saja. supaya kita selalu berhati hati dalam membuat kode,

upload file dalam web merupakan salah satu pintu berbahaya masuknya code jahad maupun software jahat ke sistem kita dalam hal ini server kita. seorang hacker akan mampu mengupload shell yang bisa membuat dia melakukan apa saja di server kita , tentu nya dengan step2 lanjutan misal mendapat user administrator atau root atau apapun itu..

Oke saya akan mulai cerita saya,. ,pada suatu hari saya pingin membuat file php untuk upload file say browsing dan menemukan contoh codenya. misal dari situs APA aja .com

dalam situs itu akan di buat 2 file ,. yang satu sebagai tampilan form dan yang satu nya sebagai script untuk upload tentunya dengan scurity hanya bisa upload file gambar dan ukuran maksimal  20 kb

dengan code form sebagai berikut :
<html><br />
<body><br />
<br />
<form action="upload_file.php" br="" method="post">
enctype="multipart/form-data"&gt;<br />
<label for="file">Filename:</label><br />
<input id="file" name="file" type="file" /><br /><br />
<input name="submit" type="submit" value="Submit" /><br />
</form>
<br />
<br />
</body><br />
</html>&nbsp;

dan code untuk upload sebagai berikut  "upload_file.php"


if ((($_FILES["file"]["type"] == "image/gif")
|| ($_FILES["file"]["type"] == "image/jpeg")
|| ($_FILES["file"]["type"] == "image/jpg")
|| ($_FILES["file"]["type"] == "image/png"))
&& ($_FILES["file"]["size"] < 20000)
)
  {
  if ($_FILES["file"]["error"] > 0)
    {
    echo "Return Code: " . $_FILES["file"]["error"] . "
";
    }
  else
    {
    echo "Upload: " . $_FILES["file"]["name"] . "
";
    echo "Type: " . $_FILES["file"]["type"] . "
";
    echo "Size: " . ($_FILES["file"]["size"] / 1024) . " kB
";
    echo "Temp file: " . $_FILES["file"]["tmp_name"] . "
";

    if (file_exists("upload/" . $_FILES["file"]["name"]))
      {
      echo $_FILES["file"]["name"] . " already exists. ";
      }
    else
      {
      move_uploaded_file($_FILES["file"]["tmp_name"],
      "upload/" . $_FILES["file"]["name"]);
      echo "Stored in: " . "upload/" . $_FILES["file"]["name"];
      }
    }
  }
else
  {
  echo "Invalid file";
  }
?>
Oke sekarang kita coba kodenya




dan kita lihat proses uploadnnya semua terlihat lancar 



 Sekarang kita coba upload file shell,.php


Oooppss ternyata gagal...

Hemmm ini gagal karena di script upload_file.php ada pengecekan terhadap mime
if ((($_FILES["file"]["type"] == "image/gif")
|| ($_FILES["file"]["type"] == "image/jpeg")
|| ($_FILES["file"]["type"] == "image/jpg")
|| ($_FILES["file"]["type"] == "image/png"))
&& ($_FILES["file"]["size"] < 20000)
)

Oke sekarang kita coba melewatinya ,.karena mime adalah variable yang di kirim user,. maka kita bisa memodikasi kiriman dengan addons mozila temper data. oke kita start temper data


kita ulangin proses penguplotan. dan temper data mulai beraksi dia menyuguhkan data yang akan di kirim ke server. coba kita lihat data itu. terlihat application/octedstream <---- br="" di="" ini="" jpg="" kalau="" maka="" masalahnya="" mau="" mestinya="" nbsp="" sukses="" upload="">

 Kita rubah saja :-)

0oke kita cek bim salabim,... taraaaaaa :-D

dan sekarang kita coba eksekusi shell kita di browser,..
tadaaaaaa :-D


hemmm bahaya bukan,. makanya hati2 kalau menulis code,.. lah kode yang cukup aman gmana???
Oke kita akan rubah2 kodenya,. :-p

$allowedExts = array("gif", "jpeg", "jpg", "png");
$extension = end(explode(".", $_FILES["file"]["name"]));
if ((($_FILES["file"]["type"] == "image/gif")
|| ($_FILES["file"]["type"] == "image/jpeg")
|| ($_FILES["file"]["type"] == "image/jpg")
|| ($_FILES["file"]["type"] == "image/png"))
&& ($_FILES["file"]["size"] < 200000)
&& in_array($extension, $allowedExts)) /*----> deteksi extensinya*/
  {
  if ($_FILES["file"]["error"] > 0)
    {
    echo "Return Code: " . $_FILES["file"]["error"] . "
";
    }
  else
    {
    echo "Upload: " . $_FILES["file"]["name"] . "
";
    echo "Type: " . $_FILES["file"]["type"] . "
";
    echo "Size: " . ($_FILES["file"]["size"] / 1024) . " kB
";
   /* echo "Temp file: " . $_FILES["file"]["tmp_name"] . "
";*//*----> salah satu celah tak perlu di tampilkan*/

    if (file_exists("upload/" . $_FILES["file"]["name"]))
      {
      echo $_FILES["file"]["name"] . " already exists. ";
      }
    else
      {
      $random_name           = rand(0000,9999); /*----> ganti semua nama menjadi random */
      $unix_name = "upload/" . $random_name . ".jpg"; /*----> kasih extensi yang boleh..*/
     
      move_uploaded_file($_FILES["file"]["tmp_name"],
      $unix_name);
      /*echo "Stored in: " . "upload/" . $_FILES["file"]["name"];*//*----> salah satu celah tak perlu di tampilkan*/
      }
    }
  }
else
  {
  echo "Invalid file";
  }
?>

Oke  begituu,. minimal code yang di atas lebih kuat dari yang tadi,.. apa masih bisa di hack???
masih kok,. Tak ada security yang bisa 100%, kecuali servermu di matikan dan di kubur,.. :-D dan tak terlihat orang saat menguburnya...


haiz uda 3 jam aku ngetik ginian aja,.. saya mau main dulu daaa ,..

Jun 17, 2012

Stop Membakar sampah

Haiii prennn..


Ini kita bagi bagi infoo nih. Jangan sembaraangn kalau mebakar sampah. Karena itu bahaya. Tahu kan anda bahwa dalam keseharian sampah sangat macam2 . Mulai dari sampaah daun sampah rumah tangga sampah lain lain ... Dalam kimia dalam proses pembakaran  suatu hidro carbon memerlukan panas yang cukup dan merata .. sehingga asap yang di hasilkan akan menjadi asap co2 sempurna.. bila terjadi pembakaran tak sempurna dikatenakan misal sampahya basah atau tertimbun pasir akan menjadi co yaitu gas monoksida yang beracun.. memang ini tak terdeteksi tapi paru2 mu yang akan menerima imbass. Dan biasqnya imbas akan berjangka waktu lama ke belakang..


Itu baru sampah kertas dan daun.. belum yang namanya plastic pvc dan esbes dia akan menghasilkan gas clorin yang beracun dan zat karsinogen yaituu zat penyebap kangker...


Coba bayank kan simplenya mebakar sampah dengan dampak yang di hasilkan....

Makqnya stop membakar sampah. Dan buanglah ketempatnya biar instasi terkait yang mengurusnya


Published with Blogger-droid v2.0.4

Jun 8, 2012

designing basket offshore

In designing basket offshore we use DNV No.2.7-1 Standar for Certification Offshore Containers April 2006. Basket purpose to transported : Know the equipment to be transported Material with weighing max 1500 kg 1. Determine SWL, based on the weight of the load that is 2000 kg, with 500 kg added clearance, then the SWL is 2500 kg. 2. Determine the appropriate dimension to the basket offshore,. So the appropriate dimensions are, length 2180mm, 1570 mm Width, and 1430 mm Height. 3. Frame from hollow size 150 x 150 3. base on material calculation the weight of this basket is 1000 kg. Tare mass then this is it. 4. To get the value of the Rating we must Summarize between SWL and Tare Mass. So the rating is 2500 kg 1000 kg plus or equal to 3500 kg. Padeye Calculation Calculations to determine the pad eye thickness is based on DNV 2.7-1 standard. Here calculation for offshore basket with a rating of 3500 kg, 4 lifting points with a lift angle of 45 °. Based on the value rating 3500 kg then we get the value of WLL is 8410 kg (Table 8.1 Standard DNV 2.7-1). Furthermore, from the value of WLL we can determine the value of working load limits for shackles (WLLs). WLLs = WLL ÷ ((n-1) . cos θ) = 8410 ÷ ((4-1) . cos 45°) = 5336,4 kg So, the shackles that shall be used is shackle with size 7 / 8 “(6.5 tons) The next step is we set the value of RSL (Resulting Sling Load). RSL = (3 . R . g) ÷ ((n-1) . cos θ ) = (3 . 3500 . 9,81) ÷ ((4-1) . cos 45°) = 65293,2 N Before going any further to calculate the tear out stress and contact stress, there are four parameters that we have to specify in advance: 1. Specify the material to be used for the pad eye. In this calculation material used is the yield strength of A36 at value of (Re) 250 MPa. 2. Holes on the pad eye to enter pin Shackle (DH) DH = B + (0,06 . B) , where B is the diameter of shackles pin = 25 + (0,03 . 25) = 25,75 mm , so we shall set the value up = 26 mm 3. Padeye distance from the center hole to the top (H) we set in H = 50 mm 4. For the thickness (t) we also specify in advance = 19 mm. Once all the parameters we’ve got and we set, then we do the calculations to determine the tear out stress criteria and contact stress criteria. Tear Out Stress Criteria Re ≥ (3 x RSL) ÷ ((2 X H X t)-(DH X t)) Re ≥ (3 x 65293.2) ÷ ((2 X 50 X 19)-(26 X 19)) Re ≥ 332965,6 ÷ 2160 250 ≥ 139 MPa —-> OK Contact Stress Criteria Re ≥ 23,7 * (√(RSL ÷ (DH X t))) Re ≥ 23,7 * (√(65293.2÷ (50 X 19))) 250 ≥ 196 MPa —-> OK From the above calculation we can know that the criteria for tear out stress and contact stress with the material A36 is OK. Therefore padeye thickness 19 mm can be used for basket offshore with a rating of 3500 kg.

Jun 7, 2012

membuka dua user account google mail atau gmail dalam satu browser

Dear my frieend .. saya punya 2 email google yang satu email gmail dan satu email perusahaan yang menggunakan gmail corporate untuk fasiltas email... Yang menyebalkan saat kita membuka rmail perusahaan misal webmail.abc.com ,, kemudia setelah itu kita pindah tab dan masuk ke gmail.com maka yanh di temui adalah email prusahaan tadi.. tapi aq menemukan trik supaya bisa membuka gmail sekaligus email perusahaan . Yaitu cuku masuk gmail dulu dengan email pribadi kita..  setelah itu baru masuk email perusahaan.dengan webmail.abc.com...

Dan akhirnya 22 email terbuka... Xoxoxox..

Sekiqn yahhh :)


Published with Blogger-droid v2.0.4

Jun 1, 2012

Particle swarm optimization

Ini adalah source code penggunaan algoritma optimasi partikel swarm optimization PSO untuk mengoptimasi distribusi kapal perang, kode ini aku buat dulu pas kuliah ,,.. buat tugas aja c,.. sapa pun monggo yang mau mendownload dan mengembangkan ataupun apapun itu..
berikut adalah link download nya download

May 29, 2012

Source code VB 6 Antivirus batosai

Beberapa tahun yang lalu ketika saya kulia semester awal hal iseng ini mulai di buat melihat perkembangan killer machine maka saya buat aplikasi ini ,. Anti virus yang fleksibel dalam segala kondisi dan medan,.. berikut source nya Sapa tau ada yang ngembangin lagi
ini ada lah link untuk RTP nya,: Real time scaner download sini ini untuk scanernya download sini banyak konsep anvir di kepala ini, ,.. Tapi ga sempat lagi sayank ,.. T_T,,, go anvir indonesia :)