Web Java Attack With SET on Backtrack V
#41
oy,, baru maksud ane om.,

hasilnya ini om t4 ane

sama kyk t4 om., pling yang beda user ma passnya

#
# These settings are for the database used by the Metasploit Framework
# unstable tree included in this installer, not the commercial editions.
#
development:
adapter: "postgresql"
database: "msf3dev"
username: "msf3"
password: "c80c3cea"
port: 7337
host: "localhost"
pool: 256
timeout: 5

production:
adapter: "postgresql"
database: "msf3dev"
username: "msf3"
password: "c80c3cea"
port: 7337
host: "localhost"
pool: 256
timeout: 5
Dari Hati Untuk Raga dan Untuk Kalian

#42
coba setting lagi user sama password utk buat database postgresqlnya kemudian cocokkan

#43
(08-11-2012, 08:52 AM)konspirasi Wrote: coba setting lagi user sama password utk buat database postgresqlnya kemudian cocokkan

udah ane cocokan om, tpi tetep kyk gnie :
[Image: 95x8i1.png]

setelah ane coba di komputer sebelah kyk gnie om, gak jln2
[Image: 29bgj88.png]





Dari Hati Untuk Raga dan Untuk Kalian

#44
(08-11-2012, 01:03 AM)koecroet Wrote:
(08-09-2012, 12:12 PM)eMJe009 Wrote: setelah dieksekusi hasilnya malah begini om ?
nie maksudnya gimana om ?


192.168.4.50 - - [09/Aug/2012 00:10:47] "GET / HTTP/1.1" 200 -
192.168.4.50 - - [09/Aug/2012 00:10:48] code 404, message File not found
192.168.4.50 - - [09/Aug/2012 00:10:48] "GET /Java.class HTTP/1.1" 404 -

itu victim baru nge buka halaman palsu milik S.E.T tetapi belum mengeksekusi backdoor java alias belum mengeksekusi verivikasi yes/no dari alert java yg di ciptakan S.E.T. walaupun victim sudah mengklik yes dari alert java yang di ciptakan S.E.T tetapi jika si victim menggunakan antivirus luar yg selalu di update tetap saja attacker tidak akan mendapatkan session meterpreter. dikarenakan payload yg dihasilkan S.E.T terditeksi sebagai virus

waktu buka halaman S.E.T tidak ada alert apapun bang..
trus di PC itu tidak ada antivirus yang ampuh, cuma smadav sama McAfee, itupun cuma crack..

(08-11-2012, 01:06 AM)konspirasi Wrote:
(08-11-2012, 12:12 AM)anon03 Wrote:
(08-10-2012, 10:40 PM)konspirasi Wrote: tombol tab itu sebelah atasnya capslock

udah om.,
tpi mlh keluar kyk gnie:


/opt/metasploit/config/database.yml: line 6: development:: command not found
/opt/metasploit/config/database.yml: line 7: adapter:: command not found
/opt/metasploit/config/database.yml: line 8: database:: command not found
/opt/metasploit/config/database.yml: line 9: username:: command not found
/opt/metasploit/config/database.yml: line 10: password:: command not found
/opt/metasploit/config/database.yml: line 11: port:: command not found
/opt/metasploit/config/database.yml: line 12: host:: command not found
/opt/metasploit/config/database.yml: line 13: pool:: command not found
/opt/metasploit/config/database.yml: line 14: timeout:: command not found
/opt/metasploit/config/database.yml: line 16: production:: command not found
/opt/metasploit/config/database.yml: line 17: adapter:: command not found
/opt/metasploit/config/database.yml: line 18: database:: command not found
/opt/metasploit/config/database.yml: line 19: username:: command not found
/opt/metasploit/config/database.yml: line 20: password:: command not found
/opt/metasploit/config/database.yml: line 21: port:: command not found
/opt/metasploit/config/database.yml: line 22: host:: command not found
/opt/metasploit/config/database.yml: line 23: pool:: command not found
/opt/metasploit/config/database.yml: line 24: timeout:: command not found

kok command not found? buka database.yml nya pake apa? vim atau gedit atau kwrite?

(08-11-2012, 12:36 AM)eMJe009 Wrote:
(08-09-2012, 12:12 PM)eMJe009 Wrote: setelah dieksekusi hasilnya malah begini om ?
nie maksudnya gimana om ?


192.168.4.50 - - [09/Aug/2012 00:10:47] "GET / HTTP/1.1" 200 -
192.168.4.50 - - [09/Aug/2012 00:10:48] code 404, message File not found
192.168.4.50 - - [09/Aug/2012 00:10:48] "GET /Java.class HTTP/1.1" 404 -

itu eksekusi yg mana? pas jalanin set atau setelah milih2 menunya?
sepertinya get http ke ip tsb dapat feedback 404 alias ga ada filenya, itu ip hostmu? apachenya jalan normal? ada yg pake port 80 ga?

setelah saya meng eksekusi reverse handler 192.168.1.2 <== ip saya
pada PC laen om..

coba lihat netstat -anpt cari port 80 nyala ga? klo nyala matiin

[/quote]

Port 80 gg hidup bang..Sad
Udah gini aja :v

#45
berarti bener yg dikatakan om koecrot, set ga dapet exploit dari korban

#46
(08-12-2012, 01:23 AM)konspirasi Wrote: berarti bener yg dikatakan om koecrot, set ga dapet exploit dari korban

trus biar set dapat exploit dari korban gimana bang ?
apa set nya eror atau, emang PC korban yang gg bisa..?

maaf nie bang banyak nanya Smile
penasaran soalnya...
Udah gini aja :v

#47
kok ane error nya gni bro ??
ntu gmna mksd nya ??


" Something went wrong, printing the error: [Errno 2] No such file or directory: 'src/html/msf.exe' "

#48
(08-12-2012, 10:22 PM)eMJe009 Wrote:
(08-12-2012, 01:23 AM)konspirasi Wrote: berarti bener yg dikatakan om koecrot, set ga dapet exploit dari korban

trus biar set dapat exploit dari korban gimana bang ?
apa set nya eror atau, emang PC korban yang gg bisa..?

maaf nie bang banyak nanya Smile
penasaran soalnya...

berarti saatnya cari korban yg lain hehe
klo memang pengen korban yg itu ya berarti harus dibuat backdoor khusus

(08-13-2012, 07:24 PM)bee_os Wrote: kok ane error nya gni bro ??
ntu gmna mksd nya ??


" Something went wrong, printing the error: [Errno 2] No such file or directory: 'src/html/msf.exe' "

setting folder metasploitnya dulu

#49

(08-13-2012, 07:24 PM)bee_os Wrote: kok ane error nya gni bro ??
ntu gmna mksd nya ??


" Something went wrong, printing the error: [Errno 2] No such file or directory: 'src/html/msf.exe' "

setting folder metasploitnya dulu

[/quote]

cara nyettingnya gimana om konspirasi ??
Big Grin

#50
(08-11-2012, 09:32 AM)anon03 Wrote:
(08-11-2012, 08:52 AM)konspirasi Wrote: coba setting lagi user sama password utk buat database postgresqlnya kemudian cocokkan

udah ane cocokan om, tpi tetep kyk gnie :
[Image: 95x8i1.png]

setelah ane coba di komputer sebelah kyk gnie om, gak jln2
[Image: 29bgj88.png]

dilihat dari gambarnya udah jalan kok, klo ada tulisan database support disabled berarti username sama password postgresnya keliru tuh, coba disetting dulu
search aja caranya udah ada di forum

(08-14-2012, 11:06 PM)bee_os Wrote:
(08-13-2012, 07:24 PM)bee_os Wrote: kok ane error nya gni bro ??
ntu gmna mksd nya ??


" Something went wrong, printing the error: [Errno 2] No such file or directory: 'src/html/msf.exe' "

setting folder metasploitnya dulu

cara nyettingnya gimana om konspirasi ??
Big Grin

ada di post 28 trit ini






Users browsing this thread: 3 Guest(s)