Advertisement
Guest User

Untitled

a guest
Sep 25th, 2018
242
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.22 KB | None | 0 0
  1. web1
  2.  
  3. buka burpsuite, gunakan intercept saat login, cek header websitenya, yang kitaperluin bagian ini:
  4. http-post, username, password
  5. buka hydra, bandingan dict1&2, lakukan dengan format ini, F untuk cek salahnya
  6. hydra -l admin -P /root/dict/diff1&2.txt unnamed48.ccug.gunadarma.ac.id http-post-form "/web1/index.php:username=^USER^&password=^PASS^:F=Username & password Salah, coba pelajari diffnya"
  7. hasilnya ini -> [80][http-post-form] host: unnamed48.ccug.gunadarma.ac.id login: admin password: 12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152
  8. Flag Is HackFest{Y0u_cAN_Anal1Z3_4rr4Y_d1ff}
  9.  
  10. web2
  11. buka burpsuite, gunakan intercept server response, arahkan ke yg diminta & ubah user agentnya saja
  12. Flag{ed1t_y0ur_H34dEr!!}
  13.  
  14. web4
  15. buka burpsuite, gunakan intercept server response, arahkan ke yg diminta, itu ada tabel header, yg bagian kiri
  16. base64 semua, cari yg Accept-encoding, disampingnya di decode dr rot13 baru base64
  17. flag{ju5t_3nc0de_5om3thin6!!}
  18.  
  19. web5
  20. lakukan register, mendapat id 4, nanti diminta ganti pass, buka burpsuite, gunakan intercept, ubah id admin, kemudian
  21. login dengan user admin memakai pass yg diregister tadi
  22. Flag{S1mple_Privilege_3Scalati0n_HaH??}
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement