Thursday, May 24, 2007

Seminar Jasakom I & II

Kegiatan Komunitas Jasakom
Dalam rangka meramaikan kegiatan offline komunitas Jasakom dengan ini kami mengundang rekan-rekan untuk berpartisipasi dalam acara :

Seminar Jasakom I

Event : Jasakom Seminar I
Hari/Tanggal : Sabtu, 26 Mei 2007
Jam : 13:00 s/d 17:30
Tempat :
Pusat Pertokoan Komputer Poin Square Lt 3
Lb Bulus

Tema :
1. Metasploit, Use at your Own risk (13:00-15:00)
Presented By : Thomas Gregory (Jasakom)
2. Honeypots, Concept and Implementation (15:30-17:30)
Presented By : Hero Suhartono (EchO)

_____________________________________________________________
Jasakom Seminar II

Event : Jasakom Seminar II
Hari/Tanggal : Sabtu, 02 Juni 2007
Jam : 13:00 s/d 17:30
Tempat :
Pusat Pertokoan Komputer Poin Square Lt 3
Lb Bulus

Tema :
1. Security Awareness (13:00-15:00)
Presented By : Gildas Deograt (Security-1st )
2. Google Hacking (15:30-17:30)
Presented By : Yudha Yogasara (Jasakom)

Biaya Pendaftaran :

. Pelajar dan Mahasiswa Rp.20 000
. Member Komunitas Jasakom/EchO Rp 20 000
. Umum dan Corporate Rp 50 000

Door Prizes :
* Kaos Jasakom ( hanya bagi 20 peserta pertama yang mendaftarkan tepat waktu)
* CD Ilmu Komputer
* Poster KKI

Pendaftaran/pembayaran dapat dilakukan ditempat dan untuk keterangan lebih lanjut silahkan hubungi :
Azis : 021-996-991-52
Hadi : 0815-8484-4174

Thursday, April 26, 2007

Daftar Sekarang, Seminar Security Gratis "Microsoft Security Roadshow 2007"


Microsoft Security Roadshow merupakan acara tahunan dari Microsoft yang dikhususkan dalam membahas masalah keamanan komputer. Pada acara tahunan 2007 ini, Jasakom beserta komunitasnya menjadi salah satu partner resmi Microsoft.


Untuk mengikuti acara yang tidak dipungut bayaran ini, para peserta diharuskan mendaftarkan diri terlebih dahulu melalui email maupun telp dan fax. Acara yang diadakan pada tanggal 3 Mei 2007 di hotel shangrilla ini akan diadakan dari jam 8:30 - 18:00 siang. Undangan dan informasi lengkapnya bisa Anda lihat di bawah ini :

































Microsoft Security Roadshow is back!! This time with more new excitements. It’s not only about Microsoft but also we have our security expert Gildas (Security Consultant from Security1st: one of the leading security community), S’to (Writer of many best seller hacking-related books and Security Expert of Jasakom: One of the well-known security and hacking-related Community) and of course we still have Steve Rileys (Senior Security Strategist from Microsoft Corporation USA). But, not just that!!! We have also 5(five) more Microsoft Security Specialist: Jacqueline Peterson, David Foo, Charlie Tan, and Maria Johansson specially brought to you from Asia Pacific Regional and one from Microsoft Indonesia.

TOPIC
Opening and Keynote Speech by Tal Adam Benzion R U Ready for the Next Big Thing in Security? By Jacqueline Peterson Oh no, we've been hacked. Now What? Developing and incident Response Process by Steve Riley Launch Ceremony of Microsoft Forefront and System Center Attack Trends and Techniques by Steve Riley

TRACK 1
Forefront Tech Drilldown by Maria Johansson ISA 2006 Tech Drilldown By Maria Johansson Microsoft Security – Uncensored Discussion with Steve Riley

TRACK 2
Branch Office - Maximizing your IT Infrastructure and Driving Compliance by David Foo Go Secure with the New Longhorn Yos Vincenzo Hacking Case Study by S'to

TRACK 3
Vulnerability Assessment and Security Enforcement by Charlie Tan Security Incident Management by Charlie Tan Penetration Test by Gildas

We are waiting for you to join us at May 3rd 2007, Shangri La Hotel ; your seat is ready!
Reserve now at msevent@qimc.biz or call us at 021 – 51402440 or fax at 021 - 51402441.

Source : http://www.jasakom.com/article.aspx?ID=898

Saturday, April 21, 2007

Cryptography Web Link

Cryptography Web Link

National Security Agency
Lembaga Sandi milik pemerintah Amerika

IT Security
Internet and Computer security Information

Schneier.com
Bruce Schneier's website

crypto.com
Matt Blaze's cryptography resource on the Web

Cryptography.org

williamstallings.com
Web Site for the Books of William Stallings

Friday, April 20, 2007

10 buku bagus yang tak mampu dipelajari

Halo semua dibawah ini ada 10 buku bagus yang tak mampu dipelajari oleh seseorang, mungkin pengaruh umur yang udah tua. Jadi dia sumbangkan aja hasil koleksi selama ini.Jangan pakai program downloader jika tidak punya premium account, agak susah downloadnya kali tapi mungkin bermanfaat buat teman-teman IT-ers.

CODE:
http://rapidshare.de/files/27499227/Hacker_Disassembling_Uncovered.rar
http://rapidshare.de/files/27499497/Hackers_Delight.rar
http://rapidshare.de/files/27499629/Hacking_Exposed-_Windows_2003.rar
http://rapidshare.de/files/27499838/Hacking-The_Art_of_Exploitation.rar
http://rapidshare.de/files/27500110/Practical_Study_Remote_Access.rar
http://rapidshare.de/files/27500175/The_Complete_History_of_Hacking.rar
http://rapidshare.de/files/27500387/Windows_Server_Hack.rar
http://rapidshare.de/files/27500743/Hack_Proofing_Your_Network__Internet_Tradecraft.rar
http://rapidshare.de/files/27501461/Hack_Proofing_Your_Identity_in_the_Information_Age.rar
http://rapidshare.de/files/27502186/Hack_Attacks_Revealed-Complete_Reference_with_Custom_Security_Hacking_Toolkit.rar
http://rapidshare.de/files/27502956/Hacker_s_Desk_Reference.rar
http://rapidshare.de/files/27503294/Maximum_Security-A_Hackers_Guide_to_Protect_Your_Internet_.rar
http://rapidshare.de/files/27503385/Network_Security_Tools__OReilly-_Apr_2005_.rar
http://rapidshare.de/files/27504058/Spidering_Hacks_O_Reilly_.rar
http://rapidshare.de/files/27504083/Hacking_Exposed-_Web_Applications.rar
http://rapidshare.de/files/27504225/Stealing_the_Network.rar
http://rapidshare.de/files/27504306/The_Art_of_Intrusion-The_Real_Stories_Behind_the_Exploits_of_Hackers_Intruders_and_Deceivers.rar
http://rapidshare.de/files/27504395/Google_Hacking_for_Penetration_Tester.rar
http://rapidshare.de/files/27504656/Underground_Hacking_Madness___Obsession_on_the_Electronic_Frontier.rar
http://rapidshare.de/files/27505048/Web_Hacking-_Attacks_and_Defence__Pearson_Education_.rar

Hacking Video

*DeluxeBB 1.06 Exploit (9mb)Remote SQL Injection Exploit.
http://rapidshare.com/files/11156227/100_live585.rar

*NetBios Live Hack (5mb) Shows how to use Super Scan to Hack Netbios opened on remote PC (Port 139)http://rapidshare.com/files/11158778/101_netbios585.rar

*Classified (7mb) Shows how site classified is Hacked.
http://rapidshare.com/files/11158779/102_site585.rar

*Vbulletin 3.5.4 exploit (6mb)By M4k3 from www.pldsoft.com shows how to use Exploit www.vicitimsite.com /forumpath/install/upgrade.php?step= [writehereanylettersbutnotnumbers!]http://rapidshare.com/files/11158786/93_vbulletin.new.rar

*NASA (2mb)NASA Department website Hacked.
http://rapidshare.com/files/11158865/92_meh.zip

*Linux Network Monitor (5mb) This video shows you how to set up ntop, a network monitoring program, on GNU/Linux. Ntop features a web interface that displays tons of information about bandwidth utilization, traffic patterns, etc. It even shows you what applications are using bandwidth on your network such as ftp, bittorrent, http, dns, etc.
http://rapidshare.com/files/11158774/95_CBT4Free-Linux_Network_Monitor.zip

*Linux DNS Server (11mb) This video explains how to set up a DNS server on a GNU/Linux server. In the video I explain a little bit about how DNS works, then I install and configure BIND in a chroot jail on 2 DNS servers in a master/slave relationship. This video is specifically tailored to setting up DNS for a web server.
http://rapidshare.com/files/11158808/97_CBT4Free-Linux_DNS_Server.zip

*Windows Web Server (6mb)This video details the installation and configuration of Apache, MySQL, and PHP on Windows. This video is made specifically or those using Windows 2000 Pro, Windows XP Home, or Windows XP Pro.
http://rapidshare.com/files/11158787/98_Windows_Web_Server.zip

*Win Server 2003 IIS and DNS (4mb)This video shows how to install and configure IIS and DNS on Windows Server 2003 for virtual hosting. These procedures will work with all versions of Windows Server 2003 and possibly with Windows 2000 Server
http://rapidshare.com/files/11158780/99_Windows_Server_2003_IIS_and_DNS.zip

*Hacker Defender Movie (8mb) Shows how Brilliant Hacker defender bypasses several rootkits detectors. You can see bypassing IceSword, BlackLight, RootkitRevealer and more.
http://rapidshare.com/files/11158766/90_Brilliant_Hacker_defender_presentation_movie_MSV1.rar

*0-DAY Simple SQL Injection (8mb) A film project about a cracker with the name zer0day. (Hacking with Linux -php)http://rapidshare.com/files/11158799/89_simple-sql-injection.zip

*vBulletin XSS (3mb)vBulletin XSS Demonstration with Session Hijacking.
http://rapidshare.com/files/11158878/81_vBulletin_XSS.rar

*wbb (10mb)wbb portal hacked by XSS.
http://rapidshare.com/files/11158816/82_wbb_portal.rar

*Reverse Engineering (20mb) Reverse Engineering with LD PRELOAD
http://rapidshare.com/files/11158857/83_reverse.rar

*SWF File Vulnerability Multiple Websites Embedded SWF File Vulnerability Demonstration
http://rapidshare.com/files/11158813/84_SWF_Vul_Demo.rar

*IPB 1.3 SQL (10mb) Invasion Power Board 1.3 SQL Injection Exploit
http://rapidshare.com/files/11158768/86_IPB_SQL.rar

*Qnix Buffer Overflows (11mb)Qnix Demonstrating Exploration of Simple Buffer Overflows
http://rapidshare.com/files/11158770/87_buff.rar

*ASP SQL (5mb) Simple ASP Administrator SQL Injection (5mb)
http://rapidshare.com/files/11158795/88_asp_sql.rar

*Blind MySQL (9mb) Demonstration of Blind MySQL Injection (bsqlbf)
http://rapidshare.com/files/11158804/77_Blind_MySQL.rar

*D-Link Wireless (3mb) Intruders D-Link Wireless Access Point Configuration Disclosure
http://rapidshare.com/files/11158777/78_D-Link_Wireless.rar

*Mysql bftools (8mb)Demonstration of Blind MySQL Injection (mysql_bftools).
http://rapidshare.com/files/11158798/79_mysql_bftools.rar

*PHP Remote File (9mb)PHP Remote File Inclusion Windows Backdoor.
http://rapidshare.com/files/11158805/80_PHP_Remote.rar

*Cracking WEP in 10 Minutes (30mb) A short demo of a wireless WEP attack. This is an interesting technique, where packets are injected to the access point, making it release weak IVs. You'll think twice about WEP after this
http://rapidshare.com/files/11158904/75_see-sec-wepcrack.zip

*Tunneling Exploits via SSH (18mb) An intensive demo showing how SSH Tunneling techniques can be used to exploit an interal, non routable network.
http://rapidshare.com/files/11158855/74_see-sec-ssh-dcom-tunneling.zip

*A classic client side attack (18mb) The MS06-001 vulnerability was used to execute a reverse connect shellcode. More information about this vulnerability can be found at the Microsoft site - MS06-001.
http://rapidshare.com/files/11158860/76_see-sec-client-side.rar

*C++ Video tutorials (29mb) Nice C/C++ Shockwave videos.
http://rapidshare.com/files/11158892/70_C__.rar

*Interview with Kevin Mitnick (12mb) He was on fbi's most wanted list, a nitrous Hacker but now see Kevin's Interview after being freed what he has to say about his past and future.
http://rapidshare.com/files/11158829/68_kevin.rar

*Unix Shell Fundamentals (40mb) VTC Unix Shell Fundamentals Video Tutorials. You need Quicktime player to view the videos.
http://rapidshare.com/files/11158906/69_UnixShellFund.rar

*Microsoft.com BugsNice videos shows of old bug that was exploited on the site.
http://rapidshare.com/files/11164765/67_MICROSOFT.rar

*Bitfrost Server Crypting (15mb) This is nice video for any one learning how to add bytes to make there server undetectable. The rar Password is Crypt.
http://rapidshare.com/files/11164849/66_Bifrost_Server_Cryp.rar

*WMF File Code Execution Vulnerability With Metasploit (38mb) This video covers the use of the recent (Jan 2006) WMF file code execution vulnerability with Metasploit. It shows how to shovel a shell back to the attacker with the WMF vulnerability. See Microsoft Security Advisory 912840. Thanks to kn1ghtl0rd, AcidTonic, Electroman and livinded for their help.
http://rapidshare.com/files/11164775/50_metasploitwmf.swf

*SSH Dynamic Port Forwarding (30mb) I set up a quick video tutorial to show how to set up an encrypted tunnel using SSH's dynamic port forwarding (sort of a poor man's VPN) in both Linux and Windows. The tools used are OpenSSH, PuTTY and Firefox, but it should be enough info to allow you to figure out how to set up other clients.
http://rapidshare.com/files/11164778/51_sshdynamicportforwarding.swf

*Using VMware Player to run Live CDs (Bootable ISOs) (46mb) In this video I show how to use the free VMware Player to run Live CDs like Knoppix, Auditor or Bart's PE Builder from an ISO
http://rapidshare.com/files/11164810/52_vmwareplayerlivecd.swf

*Adding Modules to a Slax or Backtrack Live CD from Windows (43mb)
http://rapidshare.com/files/11164807/53_myslax.swf

*Make your own VMs with hard drive for free: VMware Player + VMX Builder (16mb)http://rapidshare.com/files/11164773/54_vmxbuilder.swf

*Cracking Windows Passwords with BackTrack and the Online Rainbow Tables at Plain-Text.info (44mb)http://rapidshare.com/files/11164795/55_backtrackplaintext.swf

*Droop's Box: Simple Pen-test Using Nmap, Nikto, Bugtraq, Nslookup and Other Tools (67mb) http://rapidshare.com/files/11164818/44_droops1.swf

*WiGLE, JiGLE and Google Earth: Mapping out your wardrive (72mb)
http://rapidshare.com/files/11164827/45_wigle1.swf

*Finding Rogue SMB File Shares On Your Network (60mb)
http://rapidshare.com/files/11164821/46_roguefileshares.swf

*Nmap Video Tutorial 2: Port Scan Boogaloo (13mb) This video covers some intermediate and advanced Nmap options and is a follow-up to "Basic Nmap Usage" presentation.
http://rapidshare.com/files/11164843/47_nmap2.swf

*Metasploit Flash Tutorial This video covers the use of Metasploit, launched from the Auditor Boot CD, to compromise an unpatched Windows XP box by using the RPC DCOM (MS03-026) vulnerability. It then sends back a VNC session to the attacker. This is just one example of the many things Metasploit can do.
http://rapidshare.com/files/11164788/48_metasploit1.swf

*Using VirtualDub and a cheap webcam as a camcorder (10mb) I thought this might be of use to those that would like to submit something to Infonomicon TV or Hack TV but lack the cash for a proper MiniDV camcorder.
http://rapidshare.com/files/11164832/49_cheapcamcorder.avi

*Cracking Syskey and the SAM on Windows Using Samdump2 and John (25mb)http://rapidshare.com/files/11164783/37_samdump2auditor.swf

*Local Password Cracking Presentation for Indiana Higher Education Cybersecurity Summit 2005 (5mb)http://rapidshare.com/files/11164820/40_Local-Password-Cracking.swf

*MAC Bridging with Windows XP and Sniffing (14mb)
http://rapidshare.com/files/11164772/42_xpmacbridge.swf

*Fun with Ettercap Filters:The Movie (Airpwn like stuff) (3mb)
http://rapidshare.com/files/11164787/43_ettercapfiltervid1.swf

*A Quick and Dirty Intro to Nessus (3mb)
http://rapidshare.com/files/11164802/38_nessus.swf

*Basic Nmap Usage (8mb)
http://rapidshare.com/files/11164835/39_nmap1.swf

*How to sniff around switches using Arpspoof and Ngrep (3mb) Shows wireless Spoofing, ARP and NGrep.
http://rapidshare.com/files/11164801/26_sniffing-around-a-switch.avi

*Start a session and get interactive command line access to a remote Windows box (5mb)http://rapidshare.com/files/11164822/27_interactivecmd.avi

*Install VNC Remotely (4mb) Virtual Network Computing (VNC) is a desktop sharing system which uses the RFB (Remote FrameBuffer) protocol to remotely control another computer. It transmits the keyboard presses and mouse clicks from one computer to another relaying the screen updates back in the other direction, over a network.
http://rapidshare.com/files/11164796/28_installvnc.avi

*Boot from Phlak and run Chkrootkit to detect a compromise (3mb)
http://rapidshare.com/files/11164780/31_chkrootkit1.swf

*Using NetworkActiv to sniff webpages on a Wi-Fi network (3mb)
http://rapidshare.com/files/11164784/32_networkactiv.swf

*Basic Tools for Wardriving (3mb)
http://rapidshare.com/files/11164804/36_wardrive1.swf

*Sniffing VoIP Using Cain (3mb)
http://rapidshare.com/files/11164786/41_cainvoip1.swf

*PHP/SQL Injection (3mb) Site hacked with php exploit and known SQL injection.
http://rapidshare.com/files/11164791/63_php_and_sql.rar

*UBB threads 6.2.3 (3mb)UBB Forum hacked with SQL injection.
http://rapidshare.com/files/11164790/64_ubb.rar

*XSS (3mb) Cross site scripting (XSS) in MercuryBoard
http://rapidshare.com/files/11164799/60_new_xss.rar

*John The Ripper (11mb) Basic work with "John The Ripper"
http://rapidshare.com/files/11164782/61_jtr.rar

*wwwHack (7mb)Use of wwwhack tool on vBulletin.
http://rapidshare.com/files/11164781/59_wwwhack.rar

*Yahoo (20mb) Vulnerabilities of the post service yahoo.com
http://rapidshare.com/files/11164805/57_yahoo.com.rar

*Brutus (2mb) Use Brutus to crack a box running telnet.
http://rapidshare.com/files/11164793/17_brutus1.avi

*Hacking Server (2mb) Hacking Web Server and installing Sock
http://rapidshare.com/files/11164806/15_my_noski.rar

*Hacking Site (4mb) Hacking Site and getting r00t.
http://rapidshare.com/files/11164816/16_history_vzlom.rar

*Fusion (3mb) SQL injection on PHP_Fusion Site.
http://rapidshare.com/files/11164779/18_fusion.rar

*Wireless (2mb) This video shows a real life wireless hack.
http://rapidshare.com/files/11164785/19_lequipe.rar

*Netbios (2mb) This video shows how to exploit file sharing.
http://rapidshare.com/files/11164809/20_netbios.rar

*ARP Spoofing (4mb) This video shows how to perform an ARP Spoofing attack.
http://rapidshare.com/files/11164817/21_ARPSpoofing.rar

*Jpeg exploit (5mb) This video shows you how to use the jpeg exploit.
http://rapidshare.com/files/11164815/22_jpegadmin.rar

*Hacking ParaChat (5mb) A video that shows you how to hack parachat version 5.5.
http://rapidshare.com/files/11164792/23_ParaChat1.rar

*Email (5mb) Tracing an E-mail and finding out more about the host that sent it and its IP.
http://rapidshare.com/files/11164797/24_e-mail-ip.avi