BLOG PRIBADIKU

personal

Wednesday, November 22, 2006

Perl proxy checker using samair.ru

hi

here it is, perl proxy checker using samair.ru ,

u can supply list in there, max 15 lines manually,

see hints in the code, you can see at :
http://www.geocities.com/iko94/project/proxck-001.pl.txt


practically :

E:\data>proxck-001.pl
#########################################
# proxck-001.pl - perl proxy list checker
# using samair.ru proxy list checker
# (c) nov 2006 @ b1ma a.k.a bima_
# for educational purposes only
# GPL v.2
#########################################


Processing: www.samair.ru
[~] 167.206.216.206:6588|bad proxy or timeout
[~] 210.91.51.41:8080|bad proxy or timeout
[~] 200.71.62.100:6588|Static-IP-cr2007162100.cable.net.co - elite - speed: good
[~] 200.204.176.138:6588|bad proxy or timeout
[~] 222.165.189.95:80|bad proxy or timeout
[~] 203.94.89.112:80|bad proxy or timeout
[~] 201.53.121.30:6588|bad proxy or timeout
[~] 201.31.11.69:6588|bad proxy or timeout
[~] 203.94.89.144:80|bad proxy or timeout
[~] 201.21.222.112:6588|bad proxy or timeout
[~] 211.215.17.73:4480|bad proxy or timeout
[~] 203.94.89.44:80|bad proxy or timeout
[~] 222.165.189.64:80|bad proxy or timeout
[~] 222.165.189.14:80|bad proxy or timeout
[~] 222.165.189.77:80|bad proxy or timeout

E:\data>


xixixixixixixixi, any comments ???


./b1ma
iko94.blogspot.com

Friday, November 17, 2006

Google Code Search a.k.a. Google Bug Hunter

/*********************************************************
* Google Code Search
* a.k.a. Google Bug Hunter
*
*
* oleh : bima_ (iko94@yahoo.com)
* www.geocities.com/iko94
*
* release : nov, 17, 2006
*
* No Warranty. This tutorial is for educational use only,
* commercial use is prohibited.
*
**********************************************************/


Seperti yang kita ketahui, google mengeluarkan fitur anyar yang bisa digunakan untuk
bug hunting. Dengan Google Code Search, kita bisa mencari function definitions dan
sample code dengan hasil tempat hostingnya dan nama public source kodenya.
Coba anda lihat di :
http://www.google.com/codesearch
atau versi detil pencarian di :
http://www.google.com/codesearch/advanced_code_search

Ini contoh dari webnya :

Syntax and Examples (more about regexp syntax)
regexp Search for a regular expression
go{2}gle hello,\ world ^int printk
"exact string" Search for exact string
"compiler happy"
file:regexp Search only in files or directories matching regexp
file:\.js$ XMLHttpRequest file:include/ ioctl
file:/usr/sys/ken/slp.c "You are not expected to understand this."
package:regexp Search packages with names matching regexp.
(A package's name is its URL or CVS server information.)
package:perl Frodo package:linux-2.6 int\ printk
lang:regexp Search only for programs written in languages matching regexp
lang:lisp xml lang:"c++" sprintf.*%s
license:regexp Search only for files with licenses matching regexp.
license:bsd int\ printf -license:gpl heapsort

Ini dari FAQ - nya :
mendukung POSIX extended regular expression syntax ,
dan juga mendukung beberapa sintax perl berikut :
\w Matches a word character. (alphanumeric plus "_")
\W Matches a non-word character.
\s Matches a whitespace character.
\S Matches a non-whitespace character.
\d Matches a digit character.
\D Matches a non-digit character.




contoh nyata untuk mencari bug:

Remote File Inclusion :
http://www.google.com/codesearch?hl=en&lr=&q=%28include%7Crequire%29%28_once%29%3F%5C%28%5C%24_%28GET%7CPOST%7CREQUEST%7CCOOKIE%29&btnG=Search
http://www.google.com/codesearch?q=%28eval%29%5C%28%5C%24_%28GET%7CPOST%7CREQUEST%7CCOOKIE%29&hl=en&lr=

MySQL Injection :
http://www.google.com/codesearch?hl=en&lr=&q=mysql_query.%3F%5C%28%5B%22%27%5D%3F%28%5B%5E%29%5D%29*%5C%24_%28GET%7CPOST%7CREQUEST%7CCOOKIE%29.*%5C%29&btnG=Search

For HTTP response splitting vulnerabilities :
http://www.google.com/codesearch?hl=en&lr=&q=lang%3Aphp+header%5Cs*%5C%28%22Location%3A.*%5C%24_%28GET%7CPOST%7CCOOKIE%7CREQUEST%7CSERVER%29.*%5C%29&btnG=Search


Tentunya hasilnya adalah para source code dari software public,
untuk mencari bug-nya anda harus terlebih dahulu mempelajari source code nya
lebih lanjut, lebih baik lagi jika anda memasangnya di komputer anda sendiri,
lalu di tes dengan tool penetration tester yang anda punyai, jika anda jeli
sabar, dan beruntung... maka bisa keluarlah advisory dari anda ke BUgTRAQ.

Anda tertarik ???
Lihat saja proyek satu ini :
http://www.cipher.org.uk/index.php?p=projects/bugle.project

Happy bug hunting...



./iko
iko94.blogspot.com


########################
[+] THX GOD 4 everything

*very very very special greetz to:
[+][+][+] my beloved anna [+][+][+]

*special greetz to:
[+] www.neoteker.or.id : zka
[+] www.echo.or.id
[+] www.bosen.net : bosen & tioEuy
[+] all #1stlink #neoteker #e-c-h-o #batamhacker crew @ dal net
[+] all #1stlink #romance #hackers @ centrin
[+] alphacentupret, boeboe, fuzk3 kendi, sakitjiwa, ftp_geo, K_Clown
[+] y3d1ps, z3r0byt3, kawan2 lamaku : qq & tiyox, biatch-x, K-159, Cmaster4


kirimkan kritik && saran ke iko94@yahoo.com

[EOF]
 
Free Web Site Counter
Free Web Site Counter