Showing posts with label Web apps Security. Show all posts
Showing posts with label Web apps Security. Show all posts

Friday, March 9, 2012

FAKE FILM ARTIS INDONESIA Feat BEEF AND METASPLOIT

This containts is fiction aimed at learning

The Scenario :
  1. Attacker with social enginnering technique using social network, chatting or mail to victim send the url or link the web page contains beef and metasploit. 
  2. Victim open the url of web page and download the metasploit file.
  3. Attacker get connection via opened beef page (url web page) and get backdoor using metasploit
Lets make the hook beef home page...fake web application about porn film. Look the script carefully!.


the script
 How with the display? 
The Fake Web Infected Beef and Metasploit contains
Lets make the payload with the name tyas.avi


Making The Payload
The result ....
The Sexy payload Found
The hooks file ...
Hooks file
Lets to "SOCENG" social engineering technique, send the information about this artist porn film to social network, micro blogging, SEO, email, chatting, sms...etc. 
Next open the BEEF in the attacker..

Beef Log in
 Wait the victim to open the page...and ..ok, the victim open the beef page, so look your beef.


Connected with victim.
Next, victim will download the film...."what is in the victims mind? its a fake file" ...



Victim Download the file
What next .... ?
To be continued......

INTRODUCING XSS ATTACK CROSS SITE SCRIPTING

XSS CROSS SITE SCRIPTING 
Is an action that allows atacker to edit / inject an existing script into web application that vulnerability, For the XSS Cross Site Scripting Cheat Sheet you can read it. Cross-site scripting holes are web-application vulnerabilities which allow attackers to bypass client-side security mechanisms normally imposed on web content by modern web browser. The effect of this attack is enable attacker to handle the target system like key logging, deface, etc. The type of XSS Cross Site Scripting are persistent and non-persistent. The example Non-persistent XSS vulnerabilities in Google could allow malicious sites to attack Google users who visit them while logged in. and A persistent cross-zone scripting vulnerability coupled with a computer worm allowed execution of arbitrary code and listing of filesystem contents via a QuickTime movie on MySpace. (wikipedia). 

Practicall XSS Scripting using Beef Framework.
In the Backtrack there are two kinds of Beef : Beef and Beef-Ng. In this stage tried with beef. Open the beef and look its script load. The hook web page load the beefmagic.js.php to open the conection with target.
Run Beef
Open in the browser
Beef Web Page
After login, to know the beef running normally open in a new browser example hook.
Example Beef
The connection target and attacker been connected.Get the zombie 127.0.0.1 using firefox and linux operating system. In the log summary zombie target connected.
Get zombie
Try to send the deface page...and look the victim web page.

Deface Web Page
Next, tried with DVWA, inject the DVWA page with the hook script. if connected try to send the pop up message like this.
DVWA Pop Up Zombie
DVWA Beef Infected
Keep to try


Tuesday, February 7, 2012

SQL INJECTION and BLIND SQL INJECTION

SQL Injection is often used to attack the security of a website by inputting SQL statements in a web form to get a badly designed website to perform operations on the database (often to dump the database content to the attacker) other than the usual operations as intended by the designer.(wikipedia). SQL injection is technique that exploits and attack vulnerability from the web application security. Commands, sql statement and query embeded SQL is used to penetration test the vulnerability to injected web form into the database, change data or dump the database.

The following line of code illustrates this vulnerability
statement = "SELECT * FROM users WHERE name = '" + userName + "';"
This SQL code is designed to pull up the records of the specified username from its table of users. However, if the "userName" variable is crafted in a specific way by a malicious user, the SQL statement may do more than the code author intended.
' or '1'='1
Or using comments to even block the rest of the query (there are three types of SQL comments, you can  
SQL injection is used to :
  • Perform operations on the database
  • Bypass authentication mechanisms 
  • Read otherwise unavailable information from the database
  • Write information such as new user accounts to the database
Three forms of SQL injections :
  • Redirection and reshaping a query
  • Error message based
  • Blind injection
BLIND SQL injection
Blind SQL Injection is one of the database exploitation techniques that are different from sql injection in which the normal value will be issued but a blind sql injection techniques will not issue any value but the value that we will find out by trial and error will value the test true or false value, Here we use the command
mid () = almost the same function as substring ()
char () = is a variable of character

To test a bug (vulnerable) :
Sql injection :
By inserting the statements  "and 1=0 dan and 1=1"
www.victim.com/client.php?id=3 and 1=0
www.victim.com/client.php?id=3 and 1=1  
maybe have vuln....

Blind sql injection :
Using query: "and mid (user (), 1,1) = CHAR (65)"
mid (user () 1,1) = in this case we do not know the value, so we try and try of what the value of user "()" we try empty and 1.1 points behind () is that while the sequence of CHAR value is in decimal and variables (65) is the decimal value. in the ASCII table 65 is A.

www.victim.com/client.php?id=3and mid(user(),1,1)=CHAR(65)  if with the statement we have false we must try other statment by change the value until we have the true.