www.sekuritionline.net
FAQ  •  Search  •  Memberlist  •  Usergroups  •  Register  •  Profile  •  Log in to check your private messages  •  Log in

  www.sekuritionline.net Forum Index » Kirim Artikel » HowTo Insecure Cookie Handling Vulnerability
View previous topic
View next topic

Reply to topic
 HowTo Insecure Cookie Handling Vulnerability
Author Message
dbanie
SO-AddiCT


Joined: 12 Dec 2008
Posts: 291

PostPosted: Fri Jun 26, 2009 9:17 am    Post subject: HowTo Insecure Cookie Handling Vulnerability Reply with quote

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
How to See Insecure Cookie Handling Vulnerability on Site
Using Tamper Add.On:

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

1.
Buka firefox
Install Tamper Data 10.1.0
https://addons.mozilla.org/en-US/firefox/addons/policy/0/966/33806

2.
Tools -> Tamper Data


3.
Open url: http://www.mrcgiguy.com/cgi-bin/tts-demo/admin.cgi di firefox


Coba dilihat jendela Tamper Data untuk melihat proses request dan response dari browser kita


4.
klik Start Tamper pada jendela Tamper Data.


Kemudian coba login di site dengan memasukkan username dan password yang tersedia lalu submit


Uncheck Continue Tampering, Klik Tamper


5.
Perhatikan popup dari jendela Tamper Data Klik Ok


Perhatikan kembali jendela Tamper Data


Disini dengan jelas kita bisa melihat variable session yang valid dari user admin yang tersimpan di cookie.


Dari informasi diatas kita bisa mengexploitasi situs tersebut dengan menggunakan perintah JavaScript untuk membuat cookie yang berisi variable diatas pada browser untuk menBypass proses login.

Exploit script : javascript:document.cookie="ttc_admin=1%7Cadmin;path=/";



HOW TO:
1. Buka Firefox (bersihkan cookie di firefox) Tools -> Clear Private Data
2. Buka halaman url diatas : www.mrcgiguy.com/cgi-bin/tts-demo/admin.cgi
3. Ganti url dengan script : javascript:document.cookie="ttc_admin=1%7Cadmin;path=/";
4. Ganti kembali dengan url awal : www.mrcgiguy.com/cgi-bin/tts-demo/admin.cgi
5. walalalalal ..... xixixixi hal login berhasil terbypasss


=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
# Dedicated : To All noobie like I am Very Happy
# Thanks to : All Admin and SekuritiOnline Moderator and active member
# Object taken from paper[at]http://milw0rm.com/exploits/8687
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
_________________
-- Help I'm a Noobtz . . . Plz Guided Me --
Back to top
View user's profile Send private message Visit poster's website Yahoo Messenger
kujanglapuk
SO-MaNiaK


Joined: 23 Jun 2007
Posts: 66

PostPosted: Fri Jun 26, 2009 12:33 pm    Post subject: Wow MAntap Reply with quote

Hiihhihi Mantap Uyy

Teruskan perjuangan..mu
me mah minta yg dah masaknya aja hihii
keep berkereasi..

Diatas Langit Masih Ada LAngit
Regrads,
Back to top
View user's profile Send private message
k3nz0
SO-MaNiaK


Joined: 28 Sep 2008
Posts: 93

PostPosted: Fri Jun 26, 2009 1:21 pm    Post subject: Reply with quote

wah mantap ni om
Back to top
View user's profile Send private message Yahoo Messenger
cyberlog
Admin SO


Joined: 06 Jun 2007
Posts: 1086

PostPosted: Fri Jun 26, 2009 4:46 pm    Post subject: Reply with quote

wew, sep dibuat juga, me ga sempet buat, ntar aku taruh di depan, nice to share
Back to top
View user's profile Send private message
letjen
Admin SO


Joined: 15 Jul 2007
Posts: 216
Location: in my Desk

PostPosted: Fri Jun 26, 2009 5:00 pm    Post subject: Reply with quote

Sebenernya itu terlalu ribet bikin bingung Cool coba kalian gunakan Opera

klik Tools >> Preference >> Advanced >> Cookies

Cari Cookies web target dan silahkan edit sesuai kreativitas kamu

ga usah pake yg gitu2an ribet just make simple


Hacking itu seni sama ama Perang gunain yg udah ada di sekitar kamu.
_________________
.:: Letjen Touch The Forum ::.
Back to top
View user's profile Send private message Visit poster's website Yahoo Messenger MSN Messenger
dbanie
SO-AddiCT


Joined: 12 Dec 2008
Posts: 291

PostPosted: Sat Jun 27, 2009 2:54 am    Post subject: Reply with quote

Very Happy xixixi namanya juga noobie um en ane ga pernah pake opera sih um... hehehe thks yh um letjen tas info nya...

mao nyuba juga ah pake opera...
_________________
-- Help I'm a Noobtz . . . Plz Guided Me --
Back to top
View user's profile Send private message Visit poster's website Yahoo Messenger
cyberlog
Admin SO


Joined: 06 Jun 2007
Posts: 1086

PostPosted: Sat Jun 27, 2009 11:50 am    Post subject: Reply with quote

dbanie wrote:
Very Happy xixixi namanya juga noobie um en ane ga pernah pake opera sih um... hehehe thks yh um letjen tas info nya...

mao nyuba juga ah pake opera...

==
wekke ndak sah takut untuk mencoba hal baru bro, ini juga salah satu trik kok, walau opera browser juga nyedian manage cokies, jadi semuana bisa dicoba, ibarat kata loe klo mau deketin cwek bisa segala cara, hehehehe
Back to top
View user's profile Send private message
exnome
SO-AddiCT


Joined: 14 Nov 2007
Posts: 293
Location: Belakang Proxy

PostPosted: Mon Jun 29, 2009 5:03 am    Post subject: Reply with quote

cyberlog wrote:
dbanie wrote:
Very Happy xixixi namanya juga noobie um en ane ga pernah pake opera sih um... hehehe thks yh um letjen tas info nya...

mao nyuba juga ah pake opera...

==
wekke ndak sah takut untuk mencoba hal baru bro, ini juga salah satu trik kok, walau opera browser juga nyedian manage cokies, jadi semuana bisa dicoba, ibarat kata loe klo mau deketin cwek bisa segala cara, hehehehe


yupz .... bnr bgt ....
crinya beda2, tp tujuannya sama ....

@om letjen:pke itu lbh simple, wktu iktan misi hacking di coder... he..he....

Wink Wink
Back to top
View user's profile Send private message Send e-mail Yahoo Messenger MSN Messenger
D4rXz
SO-MaNiaK


Joined: 17 Jun 2007
Posts: 132

PostPosted: Sun Aug 02, 2009 12:31 pm    Post subject: Reply with quote

salut....nih hacking jenis kaya gini uda skelas advanced... mantap om...numpang copas di flashdisk..
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group :: Design by SO Crew