Showing posts with label Shell code. Show all posts
Showing posts with label Shell code. Show all posts

Sunday, August 26, 2012

..:: How to upload shell via Wordpress ::..[2 methods]



Wordpress ထဲကို ကိုယ္ရထားတဲ႔ username / password နဲ႔ login ၀င္ပါ...Dashboard ကိုေရာက္ပါလိမ္႔မယ္...ဘယ္ဘက္နားက appearance ကိုႏွိပ္ပါ...editor ကိုဆက္ႏွိပ္ပါ...Select theme to edit ဆိုျပီး ဒီလိုမ်ိဳးေလးျမင္ရပါလိမ္႔မယ္...ၾကိဳက္ႏွစ္သက္ရာ theme ကုိထားလိုက္ပါ...ကၽြန္ေတာ္ကေတာ႔ url ေခၚရ လြယ္ကူရွင္းလင္းေအာင္ twentyten ကိုပဲထားလိုက္ပါတယ္...select ကို ႏွိပ္ပါ...ပံုေတာ႔နည္းနည္းေသးတယ္....သည္းခံၾကည္႔ဗ်ာ....


 ျပီးရင္ ညာဘက္ျခမ္းနားက 404.php / sidebar.php / page.php စသည္ျဖင္႔ php ေတြအမ်ားၾကီး ရွိပါတယ္...ၾကိဳက္ႏွစ္သက္ရာ php တစ္ခုကို click လိုက္ပါ...edit box ထဲမွာ က်လာတဲ႔ သူ႔ရဲ႔ source code ကို shell ရဲ႔ source code နဲ႔လဲျပီး update ကို ႏွိပ္လိုက္ပါ...wordpress ကို shell တင္ျခင္း လုပ္ငန္းျပီးဆံုးပါျပီ....

shell url ကိုေခၚပါမယ္...သူ႔ path က ဒီလိုပါ...

www.site.com/wp-content/themes/themename/shellname.php


ကဲ...shell ၀င္သြားပါျပီဗ်ာ...ဒါပါပဲ...ေနာက္နည္းေတြလည္း ရွိေသးတယ္ဗ်...ဒါေပမယ္႔ ဒါကေတာ႔ အေသခ်ာဆံုးနည္းပဲ...


ေနာက္တစ္နည္း....
ဒီနည္းကို တို႔အစ္ကိုၾကီးတုတ္ေကာက္ ျပထားတာပါ...

http://www.site.com/...eme-install.php ဆိုတဲ႔အဲ path ကိုသြားပါ... upload option ေတြ႔ပါလိမ္႔မယ္...ႏွိပ္ျပီးေတာ႔ ေတြ႔တဲ႔ browse ကေန shell တင္ပါမယ္....






ဒီမွာ မွတ္ထားရမွာက shell ကိုဒီအတိုင္း .php အေနနဲ႔ တင္လို႔မရပါဘူး.... .zip နဲ႔တင္မွရပါမယ္...ဒီေတာ႔ ကိုယ္တို႔ shell က ccc.php ဆိုပါစို႔...... .zip နဲ႔ ခ်ံဳ႔လိုက္ပါမယ္..... ccc.zip ေပါ႔.... အဲဒီ ccc.zip ကို upload လုပ္ပါ.... .rar မဟုတ္ဘူးေနာ္... zip ... ေသခ်ာေျပာတယ္ေနာ္... .zip လို႔....

တင္လိုက္တာရသြားရင္ ဒီလိုမ်ိဳးစာျပပါလိမ္႔မယ္....


Unpacking the package
Installing the theme
Theme installed successfully.

ဒါဆို shell ရသြားပါျပီ... 
မ်ားမ်ားမေျပာဘူး....သူ႔ shell path က ဒီလိုမ်ိဳးေလးျဖစ္ပါမယ္...မေမ႔ခ်င္ရင္ က်က္ထား... 

www.site.com/wp-content/themes/ccc/ccc.php

ကၽြန္ေတာ္က 404.zip ကိုတင္လိုက္တယ္....ဒီေတာ႔ ကၽြန္ေတာ္႔ shell path က ဒီလိုျဖစ္သြားတာေပါ႔ဗ်ာ.... 
http://www.divinginsurance.org/wp-content/themes/404/404.php



copy from MHU
Read More ->>

Tuesday, June 26, 2012

Shell Using Tutorial



ဘာတင္ရင္ ေကာင္းမလဲ စဥ္းစားရင္းနဲ႔ အရင္ MHF က post ေတြ ျပန္သြားေမြၾကည္႔ေတာ႔ ၾဆာ hacker625 နဲ႔ ၾဆာl33t Bomber ေဆြးေႏြးထားတာကို ျပန္ေပါင္းစပ္ျပီး post တစ္ခုအျဖစ္ျပန္တင္လိုက္ပါတယ္ ...
credit to hacker625 & l33t Bomber :)

Deface အုပ္တတ္ခ်င္တယ္ ... Deface ဘယ္လိုအုပ္ရလဲ ဆိုျပီး လာလာေမးတာေတြ ၾကံဳဖူးပါတယ္ ... Fully Deface အုပ္တယ္ဆိုတာ site ေပၚကို shell ေရာက္မွ အုပ္လို႔ရတာပါ ... တခ်ိဳ႔ shell link ၾကီး ခြထိုင္ထားတာ ေတာင္မွ deface ဘယ္လိုအုပ္ရမွာလဲ ဆိုျပီးေမးတာက ရွိပါေသးတယ္ ...
shell တင္တာကို အသာထားဦး.. အခုက shell ေရာက္ျပီးတဲ႔ အပိုင္းကေန စေျပာပါမယ္ ....
shell ဆိုတာ ဘာလဲ ?
ဒီမွာ l33t Bomber ရဲ႔ ေဆြးေႏြးခ်က္ကို ထည္႔လိုက္ပါတယ္ ... ဟီးး

"shell ဆိုတာ ဟက္ကာေတြအတြက္လက္နက္/စက္ရုပ္ေပါ့
ဥပမာ
site တစ္ခု ကို အိမ္တစ္ခုလို႔သေဘာထားၾကည့္ပါစို႔
ကိုယ္က အိမ္ထဲ၀င္သြားတယ္ remote စက္ရုပ္တစ္ခု သြားထားနိုင္တယ္ဆိုပါစို႔
ဒါဆို အဲစက္ရုပ္နဲ႔ အိမ္ထဲမွာရွိတဲ့ဟာမွန္သမွ် စိတ္ၾကိဳက္လုပ္ႏိုင္ျပီေပါ့
:D "

ဥပမာ shell ကို ဒီမွာ ၾကည္႔ပါ ...
http://www.gemco.gov.bd/upload/c100.php



browse button ကေန မိမိတို႔ deface / another shell စသျဖင္႔ upload တင္ခ်င္တာကို တင္ႏိူင္ပါျပီဗ်ာ ... ဖ်က္ခ်င္တာကို select မွတ္ျပီးေတာ႔လည္း ဖ်က္ႏူိင္ပါျပီ ... index ကို ကိုင္ခ်င္တယ္ ဆိုရင္လည္း မူရင္း index.html/index.php ကို source code edit လုပ္ျခင္းျဖစ္ေသာ္လည္းေကာင္ း ၊ မူရင္း index file ကိုဖ်က္ျပီး ကိုယ္႔ index ကို ျပန္ upload တင္ျခင္းျဖစ္ေသာ္လည္းေကာင္း fully deface အုပ္ႏိူင္ပါတယ္ ... shell ဆိုတာကို တစ္မ်ိဳး ႏွစ္မ်ိဳးပဲ မမွတ္ပါနဲ႔ ... php type / asp type ႏွစ္မ်ိဳးအျပင္ Name အမ်ိဳးမ်ိဳး Version အမ်ိဳးမ်ိဳး ရွိပါေသးတယ္ ဗ်ာ ... ခု ကၽြန္ေတာ္ တင္ျပထားတာက c100 shell ပါ ... တစ္ေယာက္ေယာက္က shell replace လုပ္မသြားေသးသေရြ႔ေတာ႔ ၾကည္႔ရႈေလ႔လာႏိူင္ပါတယ္ ...


ဒီမွာ ကၽြန္ေတာ္ upload directory ထဲက index.html ေလးကို ကၽြန္ေတာ္႔ deface source code နဲ႔လဲျပီး save လုိက္ပါတယ္ ... ဒါ site.com/upload ကို fully deface တာပါပဲ ... ဒီေတာ႔ ကၽြန္ေတာ္႔ hacked link ကၽြန္ေတာ္႔ deface link က ဒီလိုေလးျဖစ္သြားမယ္ ...

http://www.gemco.gov.bd/upload/index.html
http://www.zone-hack.com/mirror/id/66285

shell တင္မယ္ ဆိုတာကို စဥ္းစားၾကည္႔ရေအာင္ဗ်ာ ... နည္းနည္း tips သေဘာေလး ေပါ႔ ...

ဘယ္လိုဆိုရင္ shell တင္လို႔ရမလဲ ????
upload option ရွိရင္ / ကိုယ္႔မွာ upload လုပ္ခြင္႔ permission ရွိရင္ shell တင္ႏိူင္ပါတယ္ ... ဒီေတာ႔ ဆက္စဥ္းစားၾကည္႔ရေအာင္ ... ဒီအတိုင္း ပလိန္းၾကီးေတာ႔ upload လုပ္ခြင္႔ရတာ ရွားပါတယ္ ... upload လုပ္ဖို႔ permission ရဖို႔လိုတယ္ ... permission ဘယ္လိုရႏိူင္မလဲ ??? ကိုယ္က admin username နဲ႔ password နဲ႔ သိလို႔ admin access ရသြားရင္ ရျပီ ေပါ႔ ... :D

admin access လြယ္လြယ္ကူူကူရႏိူင္တာ ဘာရွိလဲ ???
Sql Injection ကို ညြန္းပါတယ္ ဗ်ာ ...
ကဲ ...
ဒီမွာ တစ္ခန္းရပ္ပါတယ္ ... ေနာက္ပိုင္းအခန္းေတြက sql injection နဲ႔ ဆိုင္သြားပါျပီ ...





မွတ္ခ်က္။    ။Shell ဘယ္လိုသံုးရမလဲ ဆိုတာတစ္ေယာက္ေမးထားတုန္း.....mhu alarm ကတင္ေပးလိုက္
တာနဲ႕ ကၽြန္ေတာ္ေကာက္တင္လိုက္တာ.....နည္းနည္းေတာ့သက္သာသြားတာေပါ့....။
အဲ သူတို႕ သံုးေယာက္လံုးကိုေက်းဇူးတင္ပါတယ္.....။
mmhackforums.comကရတာပါ....။

Read More ->>

Thursday, May 3, 2012

Shell Uploading Via PHP Myadmin(ebook)


ထံုးစံအတိုင္း နေဂးတစ္သန္ဒါေရးထားတာပါ..........။ကၽြန္ေတာ္စုေဆာင္းထားခ်င္လို႕ တင္ထားပါ...။
လိုခ်င္တဲ့သူရိွရင္လဲ .......ေဒါင္းသြားႏိုင္တာေပါ့ဗ်ာ.....။
MHF ကိုလဲ ခရက္တစ္ ေပးပါတယ္ဗ်ာ.......။
ေအာက္ကလင့္မွာရႏိုင္ပါတယ္........။

Download
Read More ->>

Wednesday, April 18, 2012

Shell collections (download)


ကၽြန္ေတာ္သိသေလာက္ျပန္စုထားတာ ...ကၽြန္ေတာ္မအားလို႕ virus scan လုပ္မေပးႏိုင္ဘူး ကိုယ္ဘာသာ လုပ္ယူၾကေပေတာ့ ....ဒီထဲမွာကၽြန္ေတာ္သိသေလာက္ shell (၂၀) ထည့္ေပးထားတယ္.....။
ေအာက္ကလင့္ကေနေဒါင္းလိုက္ၾကပါ.......။


Download

ေအာက္ပါေနရာကလဲရႏိုင္သည္....။
http://sh3ll.org/
Read More ->>

Wednesday, April 4, 2012

XXXXXXXX***************xxxxxxxxxxxxxxxx[Tutorials]



မေန ့ညကပ်င္းပ်င္းနဲ ့ ... ဒီ ဘန္ဂလားဆိုက္ဒ္ေတြ scan ရတာနဲ ့ေညာင္းလာလို ့ samuels080 နဲ ့ ေတာ္ကီပစ္ေနၾကတာ ေတာင္ေရာက္ေၿမာက္ေရာက္ေပါ့ ... အဲ့မွာ သူကေမးတယ္..ဘာလုပ္ေနလဲလို ့ .. ဒါနဲ ့က်ေနာ္လည္း က်ေနာ့္ ဝသီအတုိင္း ေတာင္ေရာက္ေၿမာက္ေရာက္လို ့ ... ၿပီးေတာ့ သူ ့ကိုၿပန္ေမးေတာ့ http://shweo.com/myanmar-videos/play/4250 ေရႊအိုးဆို္က္ဒ္မွာ ၿမန္မာကားၾကည့္ေနတယ္ (သူကမေလးမွာေလ) ဒါနဲ ့ကိုလည္း ကိုယ့္ႏိုင္ငံေကာ္နက္ရွင္ နဲ ့အားက်မခံ ဘယ္ရမလဲ ဖြင့္ၾကည့္တာ .. အမယ္ .. သေကာင့္သား connection ကတတ္ခ်င္ေယာင္ေဆာင္ၿပေနတာ ...  ဒါနဲ ပဲ .. အၿပစ္မရွိအၿပစ္ရွာ .. shweo ဆိုက္ဒ္ကိုတင္းတင္းနဲ ့ ...လက္ကလဲ ကၿမင္းခ်င္တာနဲ ့ ... တခ်က္ရွိဳးလိုက္တယ္.. အဲ့မွာ .. shweo ဆိုက္ဒ္က အၾကမ္းဖ်င္းၾကည့္လိုက္ေတာ့ အေပါက္ရွာမေတြ ့ဖူးေပါ့ ...

ဒါနဲ ့ ဘယ္ရမလဲ ... သူ ့ ip scan တယ္.. သူနဲ ့host တူတာလိုက္ရွာလိုက္တာ.. http://www.shwehousing.com/ ဒီဆို္က္ဒ္ကေလးေတြ ့ပါေလေရာ .. အခမဲ့ေၾကာ္ၿငာ ( အခန္းေတြ ) လို ့ရတဲ့ ၿမန္မာ ယsearch engine ဆိုက္ဒ္တမ်ိဳးပါပဲ .. သူ့ဆိုက္ဒ္ကိုလဲ အၾကမ္းဖ်င္းၾကည့္လိုက္တာ .. မလြယ္ဘူး .. ရွာလို ့လဲမေတြ ့ဘူး .( ဆိုက္ဒ္ကဒီလိုပံုစံနဲ ့ေရးထားတာကိုး http://www.shwehousing.com/ads/index/page/6. ) ဆိုၿပီး ေတာ္ၿပီလို ့ လက္ေလွ်ာ့မယ္အလုပ္မွာ ... ညာဘက္ေထာင့္နားက အၿပာေရာင္ button ေလးနဲ ့ free ေၾကာ္ၿငာေနရာေတြ ့ပါေလေရာ .. ဒန္  တန္ ့ တန္ ....  :mrgreen:

စဥ္းစားလိုက္တယ္.. ေၾကာ္ၿငာ ... ၿပီးေတာ့ အခန္းေတြဆုိေတာ့  picture ပါမွာပဲ ... ဒါဆို upload ကေတာ့မၿဖစ္မေနေပးကိုေပးထားရမွာဆိုၿပီး .. အဲ့ဒိေနရာ ဝင္စမ္းမယ္ကြာဆိုၿပီး.. ဆက္ၾကည့္ၾကပါ...

က်ေနာ္ တဆင့္ခ်င္းစီ ပံုႏွင့္တကြရွင္းၿပမွာၿဖစ္ပါတယ္ ...
ဒီေအာက္ကၿမင္၇တဲ့အတိုင္း အဲ့ေနရာမွာ free ေၾကာ္ၿငာတင္ဖို ့ေနရာပါ...

ဒီေအာက္ကပံုကေတာ့ .. ေၾကာ္ၿငာတင္ ( image upload ) function ရဖို ့အတြက္ ... ေၾကာ္ၿငာတင္မည့္ အေပၚကလင့္ခ္ကိုႏွိပ္လိုက္ပါတယ္ 
 


ကဲ.. ေနာက္တပံု .. ဒါကေတာ့ form ၿဖည့္ဖို ့ေနရာနဲ ့ က်ေနာ္တို ့အဓိကရွာေနတဲ ့( လုပ္ကြက္ ) image upload ကိုေတြ ့ပါၿပီဗ်ာ ... ေအာက္မွာၿပထားတဲ့အတိုင္းပါပဲ
 
 



အဓကေနရာလာပါၿပီ ... က်ေနာ္အေပၚက ေဖာင္မွာ nick တို ့ ph num:  တို ့ email တို ့ ကို ၿဖည့္လိုက္ပါ ( အစစ္ေတြမလို ) .. ခု ဒီဆိုက္ဒ္မွာ ေတြ ့ရတဲ့ image uploader ေလးက ကိုယ့္စက္ထဲက shell ကိုေရြးေပးလိုက္တာနဲ ့ auto uploader ေလးပါ .. ေနာက္ page ကိုမေၿပာင္းပဲ ဒီ page မွာတင္ upload တင္ထားလိုက္ပါတယ္ .. ကဲထားပါ ... ခုတင္လိုက္ၿပီ .. အဲ့ေတာ့ ဒီလိုေလးေပၚလာမယ္..



information လိုတာရယ္ shell ရယ္ upload တင္ၿပီးရင္ click လုိက္ပါ .. ေနာက္တစ္ page ကိုေ၇ာက္ေအာင္ .. ခုနက shell က ပလိန္းဂ်ီး upload တင္လို ့ရလိုက္တာကိုေရာ သတိထားမိၾကရဲ ့လား .. အဲ့ဒါပဲ အဓိက အမွား ... ဆိုက္ဒ္ရဲ ့ vulnerable hole .. file extension ကိုေသခ်ာမစစ္ဘူး .. အကုန္လက္ခံတဲ့ အတြက္ .. ခံေပေတာ့ေပါ့ေနာ့္ ...  ...
ကဲ ကဲ .. ေအာက္ကပံုေပၚလာရင္ ... ကိုယ့္ ads တင္ထားတာကိုၿပန္ၾကည့္ၾကမယ္.. click လိုက္ပါ ၿပထားတဲ့အတိုင္း


ဒါဆိုရင္ေတာ့ ကိုတင္ထားတဲ့ shell ပါပါတဲ့ ads ကိုေတြ ့၇မွာၿဖစ္ပါတယ္... ပံုမွာၿပထားတဲ့အတိုင္း ... photo ေနရာမွာ shell ကိုတင္ထားေတာ့ photo ကိုေရြးေပးပါ .. အနီေရာင္ ေလးေထာင့္ကြက္ေလးေပၚေနတာေတြ ့ရပါလိမ့္မယ္ ... (မေတြ ့ရင္ ေဖာ္ၿမဴလာမွားေနလို ့   ခိ ... ခိ) 
 
 

ကဲပံုမွာၿပထားတဲ့အတိုင္း  photo ေနရာကိုေရြးၿပီး၇င္ ဘာမွမလုပ္ပါနဲ ့.. ဒီတိုင္းထားပါ... .. ခင္ဗ်ားတို ့လုပ္ရမွာက .. right-click ဖြင့္ view page source code ကိုေရြးၿပီး သူ ့ page ရဲ ့ source code ေတြကိုရွာမယ္... ဘာလို ့လဲသိလား... ** က်ေနာ္တို ့ခုနကတင္ထားတဲ့ shell ေနရာကိုအတိအက်သိရေအာင္လို ့ပါ **
ေအာက္မွာၿပထားတဲ့အတိုင္း code မ်ိုဳးေလးကိုရေအာင္ ရွာပါ .


BINGO ... here we go .. I successfully uploaded shell to shwehousing.com >>
 

ကဲ ကဲ ပံုႏွင့္ တကြ ေသခ်ာရွင္းၿပထားတယ္ေနာ္ ... အ့ဲေတာ plx do not touch that mm site .. this tutorial for educational purpose only. ကိုယ့္ကိုကို hacker လို ့ခံယူထားရင္ hacker ေတြရဲ ့ 'ethic' အတိုင္းေတာ့ေနၾကဖို ့လိုပါလိမ့္မယ္... ဒါေၾကာင့္ဘာမွမလုပ္ပါနဲ့ .. ကုိယ့္ႏိုင္ငံဆိုက္ဒ္ၿဖစ္ေနတဲ့အတြက္ ...

ဒီဟာကို tutorial section ထဲမွာဘာလို ့ထည့္တာလဲဆိုေတာ့ shell upload တင္ၿပီးၿပန္ရွာပံုကိုပါသိေစခ်င္လို ့ ေသခ်ာရွင္းၿပထားတဲ့အတြက္ပါ ...

shweo နဲ ့ အဲ့ဒိ http://www.shwehousing.com နဲ ့က host တူပါတယ္ .. shell တင္ၿပီးရင္ၾကည့္ၾကည့္ပါ ...

က်ေနာ္ .. tutorial ဆိုေတာ္ယံုေရးခဲပါတယ္ .. (ေသာက္ရမ္းပ်င္းတာ :D) ခုေတာ္ေတာ္ေလးေတာင္ေညာင္းသြားဘီ ..............

Note...............................................................................................................................................
**** copyright@2012<dongoth> ***** this tutorial is made by me. but you can share it. have fun ..
.......................................................................................................................................................
copy from mmhackforums.noonhost.com
Read More ->>

Monday, February 27, 2012

Shell Uploading By Passing Security Checks



Upload Page ေတြ႕တယ္ Shell Upload လုပ္လို႕မရဘူးဆိုတဲ့ အသံေတြက Beginner ေတြဆီကထြက္တတ္ေလ့ရွိပါတယ္. အခုေတာ့ အဲ့ဒီ့ကိစၥေတြအတြက္ ေရးလို္က္ပါတယ္.။ Developer ေတြလည္း Check လုပ္ႏုိင္ေအာင္ Black Hat မ်ားလည္း အသံုး၀င္ေအာင္ ( ကၽြန္ေတာ့္ထံုးစံအတုိင္း အတြင္းက်က် တတ္ႏိုင္သမွ် ) ေရးေပးလိုက္ပါတယ္။ :-)

ပထမဆံုး Upload Page က Upload Form ကို အရင္ၾကည့္ရေအာင္

<form name=upload action=upload.php method=post>
upload a file : <input type=file name=fileName >
<input type=submit name=upload>
</form>

ရႈပ္ရႈပ္ရွက္ရွက္လည္းမဟုတ္ေတာ့ သိပ္မရွင္းေတာ့ပါဘူး Post Method နဲ႕ တင္တဲ့ File ကို တင္တယ္ေပါ့ :-D  ဒီလိုတင္တဲ့ေနရာမွာ.....

(a) Normal Implementation
အခု ေျပာမွာကေတာ့ Normal Upload Form ပါ.။ Seurity Check မရွိဘဲ ရိုးရိုးတင္ခ်င္တဲ့ File အတင္ခံတဲ့ Upload Page ေပါ့ ။

<?php
$uploaddir = 'uploads/'; // Relative path under webroot
$uploadfile = $uploaddir . basename($_FILES['userfile']['name']);
if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile))
{
echo "File is valid, and was successfully uploaded.\n";
}
else
{
echo "File uploading failed.\n";
}
?>

ပံုမွန္ဆိုတဲ့အတိုင္းပံုမွန္ပါပဲ.။ Upload တင္ခိုင္းတဲ့ File ကို သတ္မွတ္ထားတဲ့ Directory အတိုင္း တင္သြားမယ္.။ ၾကားထဲကမွ Connection Error မ်ိဳးျဖစ္ရင္ Failed ျပမယ္ ဒါပါပဲ.။ ဒီေတာ့ ပံုမွန္အတိုင္းျပႆနာမရွိတင္ႏိုင္ပါတယ္

http://www.site.com/uploads/shell.php

(b) Content Type Verification

ဒီေနရာမွာေတာ့ ခုနကလို တင္ခုိင္းသမွ် ဖိုင္ကို လြယ္လြယ္ကူကူ မတင္ခိုင္းေတာ့ပါ.။ File အမ်ိဳးအစားကို စစ္ျပီးမွ အတင္ခံပါ့မယ္.။ .txt File မ်ိဳး .php File မ်ိဳးကို အတင္မခံေတာ့ပါ. ေအာက္မွာၾကည့္လိုက္ရင္ ရွင္းသြားမွာပါ.။

<?php
//checks if file is Gif or not
if($_FILES['userfile']['type'] != "image/gif")
{
echo "Sorry, we only allow uploading GIF images";
exit;
}
$uploaddir = 'uploads/';
$uploadfile = $uploaddir . basename($_FILES['userfile']['name']);
if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile))
{
echo "File is valid, and was successfully uploaded.\n";
}
else
{
echo "File uploading failed.\n";
}
?>

ၾကည့္လုိက္ပါ.။ ဖိုင္ကို Upload မလုပ္ခင္ .Gif Image ဟုတ္ မဟုတ္ အရင္စစ္ပါတယ္ တကယ္လို႕ မဟုတ္ဖူးဆိုရင္ "Sorry, we only allow uploading GIF images" Alert တက္ခုိင္းပါ့မယ္ ဒီေတာ့ .php လိုမ်ိဳးကို ဒဲ့တင္လို႕မရေတာ့ပါ :lol
သုိ႕ေသာ္လည္း GIF Image မဟုတ္တဲ့ ဖိုင္ကိုတင္မယ္ဆိုရင္ HTTP Request ကေတာ့ ဒီလိုသြားေနပါလိမ့္မယ္

POST /upload2.php HTTP/1.1
TE: deflate,gzip;q=0.3
Connection: TE, close
Host: localhost
User-Agent: libwww-perl/5.803
Content-Type: multipart/form-data; boundary=xYzZY
Content-Length: 156
--xYzZY
Content-Disposition: form-data; name="userfile"; filename="shell.php"
Content-Type: text/plain

ဒီလို Security Check လိုဟာမ်ိဳးကိုေတာ့ Temper Data လို Firefox Addon နဲ႕ Shell တင္ႏုိင္ပါတယ္ :-P
( C ) File Name Verification

ဒီတခါေတာ့ Developer က File ရဲ႕ Extensions ကို စစ္ျပီးမွ အတင္ခံမွာျဖစ္ပါတယ္။ တစ္ခ်က္ၾကည့္ရေအာင္.။

<?php
$blacklist = array(".php", ".phtml", ".php3", ".php4");
foreach ($blacklist as $item)
{
if(preg_match("/$item\$/i", $_FILES['userfile']['name']))
{
echo "We do not allow uploading PHP files\n";
exit;
}
}
$uploaddir = 'uploads/';
$uploadfile = $uploaddir . basename($_FILES['userfile']['name']);
if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile)) {
echo "File is valid, and was successfully uploaded.\n";
}
else
{
echo "File uploading failed.\n";
}

ၾကည့္လိုက္ပါ ပထမဆံုး လာလာခ်င္းမွာပဲ .php , .phtml , php3 စတဲ့ အႏၱရာယ္ရွိႏိုင္ေသာ Extensions မ်ားကို Blacklist လုပ္ျပီး ပိတ္ခ်ပစ္လိုက္ပါတယ္ ျပီးမွ We do not allow uploading PHP files
ဆိုျပီး Alert တက္ခုိင္းတယ္ ျပီးမွ Upload Form ဆက္ပါတယ္
ဒီလို Check မ်ိဳးကိုေတာ့ Nulled Byte သံုးျပီး Extension ဆင့္ခံျခင္းျဖင့္ တင္ႏိုင္ပါတယ္
Shell.php.gif လုိေပါ့..။

ဒါဆို ပံုမွန္အတုိင္းပဲ http://www.site.com/uploads/Shell.php ဆိုျပီး Shell ကို Access လုပ္ႏုိင္ပါျပီ.။









( D ) Image File Content Verification

ဒီတစ္ခုကေတာ့ အရင္ဟာေတြထက္ အဆင့္ျမင့္သြားပါတယ္ Image ဆိုရင္ေတာင္ Image File Content ကို ကိုယ္တုိင္စစ္ျပီး ဟုတ္မွ အတင္ခံမွာပါ Extensions ေတြနဲ႕တင္မဟုတ္ပဲေပါ့ :-D

<?php
$imageinfo = getimagesize($_FILES['userfile']['tmp_name']); //check image size
if($imageinfo['mime'] != 'image/gif' && $imageinfo['mime'] != 'image/jpeg')
{
echo "Sorry, we only accept GIF and JPEG images\n";
exit;
}
$uploaddir = 'uploads/';
$uploadfile = $uploaddir . basename($_FILES['userfile']['name']);
if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile)) {
echo "File is valid, and was successfully uploaded.\n";
} else {
echo "File uploading failed.\n";
}

အထက္ပါ Code ကိုၾကည့္လိုက္ရင္ သိသာပါတယ္. Image File ဟုတ္ရဲ႕လားဆိုျပီး ေသခ်ာ မေသခ်ာစစ္ျပီးမွ အတင္ခံတာပါ ဒါမ်ိဳး Security Check ကိုေတာ့ Gimp လို Image Editor မ်ိဳးသံုးျပီး Shell Code ကို GIF Image ထဲ Embedded လုပ္ျပီး တင္ရပါမယ္ ဒီေတာ့ Security Check က စစ္ေတာင္ Image Code ေတြေတြ႕တဲ့အတြက္ Image File ဆိုျပီး အတင္ခံမွာပါ ဒါေပမယ့္ Shell ကိုသြား Access လုပ္တဲ့အခါမွာေတာ့

http://www.site.com/uploads/shell.gif ဆိုရင္ GIF Image ကို ေတြ႕ရမွာျဖစ္ျပီး

http://www.site.com/uploads/shell.php ဆိုရင္ shell ကို Access လုပ္ႏိုင္မွာျဖစ္ပါတယ္ :-D

( E ) Antivirus

အေရွ႕မွာေျပာခဲ့ဟာ အားလံုးဟာ Upload Form မွာတင္ Check လုပ္ေနတဲ့ Security Check ေတြပါ Upload Form ကိုေက်ာ္လႊားႏုိင္ခဲ့ေပမယ့္ Server မွာ Run ထားတဲ့ Antivirus က Shell Script ကို ဖ်က္ခ်ပစ္ပါတယ္ ဒီေတာ့ Shell ကို Encrypt လုပ္ရပါ့မယ္.။ Shell Script ဆိုတာကလည္း PHP Script ေတြပဲျဖစ္လို႕ PHP Encrypter ေတြနဲ႕လုပ္ရပါမယ္ Google မွာ PHP Encrypter ေတြအမ်ားၾကီးရွိပါတယ္ ၾကည့္ၾကပ္သံုးလို႕ရပါလိမ့္မယ္..။
ကဲ ျပီးပါျပီ နည္းနည္း လည္း ရွည္သြားပါတယ္.ကၽြန္ေတာ့္ရဲ႕စာေတြဟာ တစ္စံုတစ္ဦးကိုမွ် အဆိပ္မသင့္ဖို႕ေမွ်ာ္လင္ပါ့တယ္
Read More ->>

Saturday, December 17, 2011

c99 shell ကိုလက္ေတြ႕ အသံုးျပဳျခင္း


ကၽြန္ေတာ္တို႔ MHU ညာဘက္ျခမ္း sidebar က Quick Link ကေန c99 shell ကို download ဆြဲလိုက္ပါ....

example အေနနဲ႔  Tutorial အေနနဲ႔ မို႔လို႔  www.nazuka.net မွာပဲ စမ္းၾကတာေပါ႔.... nazuka မွာ register လုပ္ပါ....file manager ထဲက Public_html directory ထဲမွာ  upload လုပ္လိုက္ပါ....upload ျပီးသြားရင္ေတာ႔   www.yoursitename.nazuka.net/c99.php   မွာ ျပန္ၾကည္႔ၾကည္႔လိုက္ပါ.... nazuka.net ရဲ႔ ကိုယ္႔အေကာင္႔ ထဲကို sign in ၀င္စရာ မလိုပဲ   manage လုပ္ႏိူင္ပါလိမ္႔မယ္....

အဲ...တစ္ခုေတာ႔ ရွိတာေပါ႔....ခဏတစ္ျဖဳတ္စမ္းၾကည္႔ျပီးရင္ေတာ႔  c99 file ကို ျပန္ဖ်က္ပစ္လိုက္ပါ...မဖ်က္ရင္ေတာ႔  အဲအေကာင္႔ဟာ မၾကာခင္ suspended ျဖစ္သြားပါလိမ္႔မယ္:D:D:D ...စမ္းၾကည္႔ၾကေပါ႔ဗ်ာ...ဟဲဟဲ...ေပ်ာ္စရာေလး တစ္ခုေပါ႔.... =D>=D>=D>

Hacker1989@MHU...
Read More ->>

Monday, December 5, 2011

[Win32 C++] Shell Code Generator


ကြ်န္ေတာ္တုိ ့ code ေတြကို txt ဖုိင္နဲ ့ထည့္ေပးလုိက္ပါတယ္...
C++ တတ္ကြ်မ္းထားသူမ်ား code ေတြကိုေလ့လာလုိ ့ရေအာင္ပါ..

Shell Code Generator v1.2  ျဖစ္ပါတယ္..
ကို ့ဘာသာ .exe ေျပာငး္လုိက္ၾကပါ.. code ေတြကို ေလ့လာေစခ်င္လုိ ့ txt ဖုိင္နဲ ့ထည့္ေပးလုိက္ပါတယ္..

Download :   Mediafire Zshare Easy-Share Depositfiles Wupload Filesonic
source @ mmcracker.multiply.com
Read More ->>

php shell

ဘယ္ကရတယ္ဆိုတာကိုမေမးပါနဲ႔။ကၽြန္ေတာ့္သင္ ဆရာျမင္ဆရာျဖစ္တဲ့ ကိုေသာ္ဆီကပဲေပါ့။အသံုးလိုတဲ့ သူေတြအတြက္ကေတာ့ ခ်ိဳပါလိမ့္မယ္။
တစ္ခ်ို့ ျမန္မာဆိုက္ဆိုက္ေတြမွာေတြရတယ္ php shell ေတြကို ဒါေပမဲ့ တလြဲ့ေတြခ်ဥ္ပဲ မျပည္စံုတာခ်ဥ္ပဲ

တစ္ကယ္အစစ္က ဘာလည္းဆိုတာ ျပမယ္ ေလ့လာလိုသူေတြအတြက္တင္ေပးလိုက္ပါတယ္

ပညာေရး နွင့္ ပရွိဂရမ္းမင္းေလ့လာသူေတြအတြက္ ေပါ့  ကိုယ္ဆိုက္ကာကြယခ်င္သူေတြအတြက္

c99 shell ေပါ့နာျမည္ျကီး china hacker group က  web sever ေတြကို ေဖာက္တဲ့ ေနရာမွာ သံုးသြားတာေပါ့ လြန္ပါတယ္ r57 Shell က ေတာ့ russia က ဟက္ကာေတြလက္စြဲေပါ့ လူသံုးမ်ားတဲ့ဟာေတြပဲတင္ေပးလိုက္ပါတယ္


c99 shell
r57 Shell
c100 Shell
Sniper-Sa Shell
Egy-Spider Shell
Locus Shell
FX29 Shell
Uploader
PHPjackal1.3
Mail List Maker
Cgi-Telnet
php backdoor
Safe Mode Breaker



ေဒါင္းလိုက္ပါ


http://www.mediafire.com/?i41w1ldc187h4y3

မရရင္
http://www.ziddu.com/download/17688293/allphp.rar.html

အဆင္ျပပါေစ
Read More ->>

ROCK FOREVER (MUSIC)

Pageviewers

CBOX

Manutd-Results

Label

Android (3) autorun (3) Backtrack (8) batch file (19) blogger (10) Botnet (2) browser (5) Brute Force (6) cafezee (2) cmd (5) Cookies (2) crack (12) Cracking (2) crypter (7) DDos (20) deepfreeze (4) defacing (1) defence (16) domain (4) Dos (9) downloader (4) ebomb (2) ebook (48) Exploit (26) firewall (3) game (2) gmail (11) google hack (16) Hacking Show (3) Hash (4) hosting (1) icon changer (1) ip adress (6) Keygen (1) keylogger (8) knowledge (67) locker (1) maintainence (8) network (17) news (31) other (35) passwoard viewer (7) password (12) Philosophy (6) Phishing (8) premium account (2) proxy (7) RAT (10) run commands (4) script (27) Shell code (10) shortcut Key (2) SMTP ports (1) social engineering (7) spammer (1) SQL Injection (30) Stealer.crack (5) tools (125) Tools Pack (4) tutorial (107) USB (3) virus (32) website (84) WiFi (4) word list (2)

Blogger templates

picoodle.com

Blogger news

Print Friendly and PDF

HOW IS MY SITE?

Powered by Blogger.

Followers

About Me

My Photo
Hacking= intelligent+techonology+psychology