Sharing Session Penanganan Web Defacement Judi Online
Distinguished Director of Cyber Security and Security at the Central Committee of the BSSN, Deputy Commander of the Data Protection and Data Protection Union, Mr. Marsikal I, TNI, Khairul Akbar Huta Suhud, SHMSD, as well as all participants in the sharing session of the Online Judi Online Web Divestment Management, I am happy.
First of all, let us praise and thank God Almighty because in the morning, sorry, in the afternoon today, we are still given the health and opportunity to join the sharing session of the online judi investment management. Ladies and gentlemen, as we know, online judi is currently a national issue.
that must be overcome together. The propaganda and spread of online judo platforms is so massive, carried out by online judo fans. One of the propaganda carried out by online judo fans is to employ hackers to attack web divestment against various official websites, including official government websites. As a result, many government websites have turned into online judo websites.
Ladies and gentlemen, on this occasion we will have a sharing session on how to handle online judicial web divestment. In this event, we will convey two materials, ladies and gentlemen. First, we will convey the introduction and simulation of the tools for investigating online judicial web divestment, which will be conveyed later by the first source, Mr. Jabang Aru.
Then, we will also deliver lesson learned from handling this online judi web divestment, which will be delivered by the second source, Mr. Danu Ibrahim. Our hope, ladies and gentlemen, is that the materials and tools provided in this sharing session can be implemented in each of your places, so that the system in your place can be freed from the online judi web divestment.
Okay, thank you, Mr. Ival, as an assistant operator of the TNI
Thank you for your time. I really appreciate this activity. First of all, I would like to thank all the participants who have come here. I see that the number of participants has reached 148. Maybe in the future it will increase again.
from the participants of the CISERT or the response engineering response team from the ministries, institutions, central government, and regional government, as well as the IT team in the sector where you all work.
Following my introduction, maybe I didn't go into detail, but I happened to follow the report of Menko Polkam regarding the synergy of the online crime prevention or handling of crimes and also the case of
cyber security and data protection. There are several points that I need to convey here, which are the pressure from DS, which BSSN is one of the stakeholders who joined in the activity, joined in the activity, and collaborated, in addition to Kemenkom DG, Kejaksaan Agung,
Next, the Ministry of Justice and the Ministry of Justice, then related ministries such as the Ministry of Education, Ministry of Religion, then there are from Bank Indonesia, OJK, then from PPATK, KPK, all related to law enforcement.
is included in the Desk on the Dispute of Online Judicial and Cyber Security and Data Protection. There are some information that I need to convey here. So maybe you have heard that
Online judo is a state of emergency in our country. So from the surveys that were delivered by the ATK, around 86% of online judo is very massively promoted in the cyber space. So if you count it,
The total net income of almost Rp. 900 trillion is scattered online. And what is involved in it is in several layers, all communities are involved, starting from TNI Polri, around Rp. 90,000, then children,
from the age of 10 to 30, from the age of 10 to 20 years, there are about 80,000 state officials or ASN, 1.8 million, which in total are all aggregates, the number is 88 million players. Based on the report of the State Police Department that
This is already a pandemic that needs to be handled together. Here, the BSSN as a regulator or operator of cyber security construction cannot do it alone, so the collaboration of all institutions that operate in the field of defense, defense, and cyber security, as well as
and the cyber-criminals in the cyber space, they collaborated to fight against online crime. So, you are part of our desk team, which is run by the government. So today is one of the most important moments, so the sharing session is one of the tasks given,
from online trial tests, in addition to the plan of blockade or plan of access blockade, funding blockade, the third is to carry out public campaigns, how we have to fight or overcome this online trial or this daring. We from the BSSN hope
you, who are part of the CHISER team, the Injury Response Response Team, have the same thoughts and goals as we do in the Central. Because you are our working team or our colleagues who will be leading the strike in the regions. So starting from our own site, starting from our own workplace,
I am sure it will be an important moment for us to get rid of the prejudice from the roots of our own environment. So this is an important moment, I hope from the sources here to provide information on how to handle web defacement, which is one of the strategies from PROTAS to spread
to be able to continue to be accessed by the Indonesian people. Once again, I hope that this sharing session is an important time for us. Hopefully what I have said can be an important moment for our service to the national bank.
That's my introduction. May God always bless us with what we do. Thank you. I close my introduction. Wassalamu'alaikum warahmatullahi wabarakatuh. Salam. Om Santi Santi Om. Nama budaya. Salam kebajikan. I return it back to Asok Satgas, Saudara Ifal. Please.
Thank you, Mr. Director, for your invitation. Before we start, we would like to ask you to fill in the presentation link in the Zoom chat.
Ladies and gentlemen, now we will enter the main event, which is the presentation of the sharing session of the management of web defense in online judo that will be delivered by the source speakers. This event will be led by moderator, Mr. Aprita Danang Permana, who will moderate the sharing session with the two source speakers later. To Mr. Aprita Danang, we invite you. Thank you.
Thank you for your time. Assalamualaikum warahmatullahi wabarakatuh. Introducing from us, the Department of Transportation or the Department of Transportation, the Department of Transportation and Transport, which is formed by the DPSSN,
our performance. Indeed, here, two things will be our points to be conveyed, namely, related to lesson learned, findings or results that can be used as a knowledge. For you, ladies and gentlemen, here, in the management of the electronic system, to prevent and control web defacement incidents, especially, there are many infiltrations
The data on the data is on the website, which is managed by the government. The second is that we will also provide information related to techniques, tools, and live simulation in handling and investigating the data on the data.
To make time more effective, there are two members who are ready to convey the results. The first is Mr. Danu Ibrahim, who will convey the differences related to the lesson learned handling of the web development of the Daring Clinic trial.
And later it will be continued by Mr. Jabang Aru who will convey the introduction of the tools as well as the live simulation of the tools for handling the incident of the incident of this day. Okay, first we invite Mr. Danu Ibrahim to be able to convey his presentation. We invite you. I open first, Assalamualaikum warahmatullahi wabarakatuh.
I will do a little sharing of the lesson from the management
the development of the Daring Project, which we have done in several instances over the past year, Ladies and Gentlemen. So, let me start. As we know, for the Daring Project, it is getting more and more complicated, Ladies and Gentlemen. As we know, this involves several people, I mean several
such as being involved in influencer, artist, apparatus, family, and society in general. As we know, there are several news, the first is that the catchment of 8 influencers, online players who
This turned out to reach 8.8 million people, so it involves the majority of young people and the lower community. And also, it turns out that there is a case where this judicial board that manages the website is spending a lot of money for the exam so that it is not blocked like that. This is very problematic, sir.
For the transaction itself, this is data that I got from the Indonesian Pay.id source. According to the BPAtk, the value of the online exchange rate has continued to increase, starting from 2017, which is as much as Rp 2 trillion, then rose from 2018 to Rp 3.8 trillion, then in 2019, it started to rise twice, to Rp 6.1 trillion, and in 2020, it rose
almost twice as much, Mr. Ibu, which reached Rp. 15 trillion. This 2021 and 2021 also increased very sharply, maybe because during those years there was COVID.
So when there was a COVID-19 outbreak, many people lost their jobs and they wanted to try to follow online judo like that. So it rose to Rp57 trillion, then it rose again in 2022 to Rp104 trillion, and in 2023, it reached Rp327 trillion.
For the year 2024, how much is the transaction? According to the news on November 21, 2024, Menko Polkam mentioned that the Jujuanil RI transaction exceeded Rp. 900 trillion this year. This is of course very disappointing because of course the most donors are lower class communities.
For this, there is also another phenomenon, which is about the promotion of online judo. This is what was popular yesterday, the phenomenon of Joget Cat Bor, where a TikToker who is live, but proved to be
associated with the promotion of the online judo account. How is it related to the promotion of online judo itself? According to the sources I got, when Satghor did live TikTok,
the title accounts will make a auction, so a high value auction, later there will be top viewers or top who auction, in this case it's called Xxx brothers
If someone is flirting, usually on TikTok, like you, when someone flirts, for example, "Thank you for the post, Xxxx." When it is mentioned in writing like that, it will attract attention. Of course, those who join the live will check the profile of the Xxxx. Let's see, ladies and gentlemen.
In the Xxx profile description, there is a description to direct you to search for Google. For example, type in Google "Xxx" and then what will appear is
a web-based element that has been affected by the web development of online judo, and when it is opened, and inside it is already a judo online element, when the button inside it is opened, it will direct to the original website of online judo, which is one of the phenomena of the judo itself.
So for the image like this, Mr. and Mrs. Jodi Online account provides a big show with a pretty big user to get attention from other users. Then when the other user opens the profile of the title account, then it will be directed to search in the search engine according to the description of the profile of the account. Then what will appear at the top
is a website of KL or other instances that have been attacked by the online judo web divestment. When clicked, it will lead to the original online judo website. So that's how the promotion was done, in accordance with the judo banners. To overcome this, at the beginning of this year, Menko Puhlukam formed
the suggestion of the online judi training by Mr. President Joko Widodo, starting from press number 21. For this, BSSN has been involved into the security application team from the online judi training.
Next, this is the "Industrial Security Landscape of Indonesia" in 2023, which is a prediction of the potential cyber threat. What we will focus on this time is Web Diversion, which is of course a main weapon of online security.
What is web divestment? Web divestment is an attack on a website that changes the original appearance or content of a website. Web divestment is currently a trademark on the website of the government and education, especially web divestment online judi.
What is the impact of the system for us, the owners of the electronic system, especially the government? First, the reputation of the government. The appearance of illegal online games on government sites will have a negative effect on government's integrity. Then for the privacy of the public, the public will be able to act on the safety and governance of government sites, as well as the ability of the government to protect sensitive data and public information.
Third, availability, which is divestment can cause interference in services provided by the government, and can cause discomfort and dissatisfaction among the community towards the government.
This is the procedure for the use of incident jibber according to NIST SP 800 volume 61, starting from preparation, detection, then on to analysis, containment, eradication, recovery, post-incident activity, and also close incident. For the details, you can read it yourself. This is
general description of what attack techniques are used by attackers to do web divestment, ladies and gentlemen. So we read from the left, that is when you want to attack, the attacker or the banner or hacker will look for the security of the electronic system, ladies and gentlemen. Usually the security can be through XSS security, security on upload features,
remote code execution, then SQL injection, and the attacker will also use a brute force login method like that, sir. When the attacker has successfully exploited the security, then the attacker will usually upload the web-sale, sir. Uploading the web-sale is used as a backdoor, sir. The attacker can do activities according to the requirements, namely doing remote execution.
Then after the attacker successfully uploaded the web shell and successfully attacked with remote execution, then the attacker will upload the script and also set the Google index,
the attacker succeeded in uploading, the attacker will make a service for the persistent, which is a mechanism for how the attacker can remain in place, even though for example, for example, you as the owner of an electronic system have deleted the online data, but the attacker has planted a persistent system so that when
the owner of the electronic system only removes the page, then the page will be able to reemerge automatically, like that, sir. That is how the general attack or the technique used by the attacker to be able to launch a web defacement attack online, sir. Then we continue to things that can be done when handling incidents, one of them is the most important thing, which is the log analysis, sir.
Log files are very valuable information provided by the server that records the activities, events, and actions that take place during the runtime of a service or application. These activities contain important information about when, how, and by whom the server is being accessed.
There are several types, namely there is a web server lock, usually called access lock and error lock, then there is a system lock, namely out lock and sys lock, then there is a database lock, usually called MySQL lock.
For the teloc itself, it's usually like this, but in some systems there are different structures. But in general, it contains the address of the visitor, the time or timestamp, then the request method, then there are elements that are accessed, then there is a status code. This is the important part, sir.
Usually if 200 is successful, then if 404 is not successful, then there is a browser or user adsense that is used to access, to make access like that.
This is an example of the lock itself, this is an example of the attack of local file inclusion and remote file inclusion. The parameters are like this, sir. Then when the attack is an SQL injection, this is an attack on the database, usually the query is like this, sir.
This is an example of how the attacker attacked, based on what we have found during the Satgas operation. So the first time the attacker successfully uploaded the bioshell,
In today's analysis, there is an activity to execute a website called alpha403.php on July 2, 2024, at 9:49 PM West Indonesia time by the IP address of the web content/upload directory. You can see that there are several requests, and the results are 200 points.
When we find something like this, we must immediately be careful, sir. That means the attacker has succeeded in exploiting this, sir. Then what is the next thing to be done? The attacker, after he has succeeded in exploiting,
Next, what is usually done when incident response is to identify the base history, sir. What is the base history? In Linux, the base history refers to a feature that stores the history of commands that have been executed in the terminal using base shell. This history is stored in the file called .base_history. This base history plays a very important role in the context of incident response in the world of cyber security.
The required rewinds stored in the file .bash_history or other typing systems can provide very useful information in detecting, analyzing, and overcoming cyber security incidents.
In general, this basic story file is stored in the folder /home/username/system/.base_story. However, this can be configured more smoothly, it is not stored in this folder, this is only in general.
What is the function of this basic story? The function is to track the attack activity. In the basic story, we can track the steps taken by the attacker and also detect suspicious orders.
For example, what the attacker does is recorded in this base history, and secondly, analyzing commands that indicate the escalation of access, such as using the sudo command, for example, the sudo su command or sudo base command, which is used to get access to the super user or access above it, or access route, like that, sir.
Then to modify the configuration file, for example, the attacker edits the configuration file that controls the access or security system. And the third, detect the command to delete traces. The attacker often tries to delete their traces
After making an intrusion, they may try to delete the command line using the history_mntc or by deleting the file _history.
Then we continue to the discovery earlier, sir, namely by identifying the base history system. Then it was found that there was a trial of changing the user password XXXX, sir. However, to find this activity, it must be re-checked whether the password change was successful or not. This is seen, sir, the attacker forgot to write the password pseudo of the XXXX account.
This must be checked, when we as the system owners, when we find in the base history there is an attempt by the attacker to change the password, this must be checked, we must check the passwords of the users in our system, whether the password can still be used or not.
So, when there is an indication like this, immediately replace all the passwords in our system. Then it looks like this, sir. The attacker downloaded the robots.txt file from this address, sir. This is a suspicious address, right, sir? Moreover, the file's name is not clear and it looks like this. And he made it a robots.txt file.
This file is for AP, ladies and gentlemen. Let's see.
For robots.txt, the function is first to limit the process of the search engine to access the website so that the capacity of the website's server can be maintained. And secondly, to relieve the burden of the website server. And thirdly, to ensure that there are websites that remain private with the purpose of
staging, setting, or other needs, and also determine or set which page pages can be accessed by both Google search engine or other search engine, so the purpose is to limit which page pages can be accessed by both like that,
This is an example, for example, the form is like this, for example, User Agent, Googlebot, Allow/Disallow the Contact page. In that example, Robot.txt will give permission to Googlebot or Robotbot from Google search engine to do crawling on all data or pages on the website page. However, Robot.txt will not give permission to Googlebot
crawling on a contact page like that. So to limit the bot, you can crawl anything like that.
Then we continue to the meeting earlier, after it was found that the attacker downloaded robots.txt, it turns out that the content is like this, sir and ma'am, the user agent is star, then the disallow is empty. After being checked, it turns out that the attacker tried to make robots that indicate that there is no limitation for bots and search engines to be able to access all elements from the website directory.
This is also dangerous, because the .txt robot has been replaced with a new one and there is no limitation. For example, we have a page that turns out to be a secret, but when the .txt robot is replaced like this, the bot will still be able to access the page.
Then, it turns out that the attacker did other actions, sir. The attacker was indicated to do an inspection on the file "Base History", which is a file that stores the command that has been executed by the system users at this time.
After that, the attacker made an attempt to delete the file with the aim that the stored government documents could not be accessed again. The attacker tried to do this, after he did his action, then he attacked the base story, then he tried to delete this,
he did an RM and a base history. This must be confirmed again later when you have access to the route, it must be confirmed whether the base history is really erased or not. When the base history is empty, it means that this is something that suspects you.
After that, the attacker is indicated to create a new folder with the name "bonus100". This folder is clearly malicious or suspicious. Then the attacker calls the first file again, index.php. He created the "bonus100" folder.
Then he did a wicket again, sir. Indic.php, and it turns out from the same website, but the file name also suspects this, sir. Random like this is the name. Then he also set up Google verification, sir. After that, it turns out he also downloaded file sitemap.xml on the same website, sir. This is an indication that he
the indication is that he downloaded a PHP element and also wants to register it on Google Search Console, as you said, sir.
Then after the investigation, it turns out that the webfileindex.php is also an element of the diary collection that will be used by the attacker. When opened in the form of .txt, it looks like this, but when opened in HTML form or in the form of a browser, the appearance is clear, there is a slot like that.
Then the attacker returned to the set map XML file that you mentioned earlier. After analysis, configuration of the robots file and set map XML, the attacker is used to do indexing on Google Search Engine so that the index.php page that contains the online search page can be easily found in the search engine results.
the index.php page that was in the 100 bonus folder so that it is easy to find when you search or do a search for the judi slot site to appear on Google like that, sir.
Not only that, sir, the attacker also made an effort to change the access permit in the WP Includes directory to 0777. The change of the access permit can cause a risk of security because everyone can change, modify, or run the file, sir.
Then the attacker made a change in the time stamp on the directory to March 3, 2021, 12.12 PM, with the aim of concealing that this file was as if it had been there for a long time. And earlier in the log, we have seen that in July 2024, but this attacker apparently accused the attacker of the file that had been made,
the system owner is confused when the system owner is confused, "Oh, when did this file come out?" It turns out that when it was checked on March 3, 2021, the system owner will say, "Oh, this is an old file, so you don't have to check it." So this is one of the attacking techniques to trick the system owner that the folder has been there for a long time, even though this folder has just been made like that, sir.
Then we go to the next step, which turns out that the attacker also uses Cronjob, ladies and gentlemen. What is Cronjob? Cronjob is a feature in the Linux operating system that allows users to schedule certain tasks to be carried out automatically at a certain time. It can be used for routine tasks such as backup data, email sending, and so on.
or system renovation. However, it can only be used by the packer to schedule a certain malicious activity, sir. For the other campaigns like this, sir, there are stars, this can be set, can be configured and configured according to the needs of the sir.
Next, the attacker did something else, namely found a false process running on the system containing an obfuscation script. This obfuscation file is a warning technique, usually encode or
This activity is recorded in the crown's list and carried out every hour at 0 minutes, such as 1.00 or 02.00, etc.
We can see as follows. Usually in the Quran, the appearance is normal, but when there is something like this, we have to think more carefully. There are a series of letters, random letters and numbers. When we look at it, there is a text "B64", which means there is something that is thrown out in this Quran.
We see that in the previous crown there was a string that was encoded using base64.ibu which will then be executed as a shell command. What is the content of the crown? If it is decoded, the string will be the next command. The point is, in general, this command will be executed with the process
Slug_flush_wq, which aims to ensure that the backdoor or web shell that has been installed on the system remains running, even though there is an effort to turn it off.
Then, a search was carried out on the application's directory and found the status of defunct or zombie, which shows that the process has been completed in execution but still has an entry in the process table. This can be an indication of how attackers maintain a persistent method in maintaining web defense in online judo, sir.
Next, we go to the malware findings. There are several malicious files. The first one, it turns out that this malicious file can be used as a form of image. So when the file is opened, it appears like this. This file is called .jpg format. And then the picture is an anime image like this. It turns out that when opened in a notepad, the display will be like this.
This is a PHP file, but it was deleted into a .jpg file, and when we put it into the total virus, it will be detected as malicious, which is categorized as Trojan Web Cell.
Then, other malware discovery, namely malicious files that are deleted with the technique of obfuscation. When we open it directly using your notepad, the display will look like this, ladies and gentlemen. This is the display of a series of letters and numbers
uh
When the attacker log in to this website, then a website like this will appear, and has the following functions, the attacker can attack the Previlege Escalation, then can do Mesh Device, then can do Database Damage, can do File Upload, can do Directory Search, and other functions that the electronic system has been used.
We have reached the end of the talk, which is to recommend ourselves, and we recommend to routinely make credential changes to the user in the system and limit access to the system. Second, to implement a security system for authentication factor or even if possible, multi-factor authentication. And third,
It's also crucial, only to open the port that is not used. So when we have an electronic system, the port that is weak, safe, or even not used, it should be closed. And then number four, turn off the service or
plugin that is not used. In this case, we must respect the plugin, whatever plugin is needed, and we must maintain the safety factor. The fifth is to do the search and remove malicious files that are still left. This is to sanitize the input. This is also important, ladies and gentlemen, because
I often heard that the entrance gate of the attacker is from the upload file, because the owner of the electronic system did not really sanitize the input on the upload file.
The seventh is to monitor network traffic and apply several roles to the firewall to mitigate malicious activity. The eighth is to test the security of the application to find the vulnerability in the application so that it can avoid the same attack that uses the system vulnerability.
agents such as IDR, IDS, or IPS to detect attacks and take actions of automatic prevention. This is also important, it requires good management of the block. So when there is an attack, the thing that can be our history is
So when we complete the log, and for example, according to the time needed, it will help in the process of handling the incident. We will be easier to understand how the attacker entered, from where the attacker entered, and we are easier to find
what is the flaw of our system, from this lock, sir. Therefore, it is necessary to implement a good lock management. And lastly, it is not important to update the application and the security system routinely. Maybe that's enough from me, sir. Thank you for your attention. I return it back to the moderator. Wassalamu'alaikum warahmatullahi wabarakatuh. Wa'alaikumsalam warahmatullahi wabarakatuh.
Thank you very much, Mr. Danu, for sharing your knowledge. It was also very detailed and comprehensive. From the meetings that were held by this start gas team, from the persistence to the backdoor used. And also, several investigation techniques were also shared by Mr. Danu, as well as recommendations
to improve safety, especially in the electronic system managed by you. In the next session, we will give a discussion session after the second session. So, if you have any questions, you can send them via chat.
And maybe later in the discussion session, we can answer the questions by doing a voice-in. Okay, before the discussion session, we will tell you first about the next session, which is the session that will be told by Mas Jabang Adu, related to the introduction of tools and simulation in a live way.
tools that are used by the Saltgas team in assisting in handling incidents. For the time and place, we will pass it to Mr. Haru to convey the next material. Please. Assalamualaikum warahmatullahi wabarakatuh. May I ask the moderator to thank you for the time you have given. Here I will convey
Next.
Next.
simulation tools and introduction of the tools more or less I have given the red line, sir here starting from the detection and analysis phase starting from the first attack factor then the second sign of an incident then the third incident analysis and documentation of the incident
Then, we will go to containment, eradication, and recovery. The first one is containment, then evidence gathering and handling, and the last one is identifying the attacking host. Why not eradication and recovery? Because in this session, I want to give you a continuous introduction and a simulation. Next.
Here I want to explain a little bit about the compromise assessment, where we will do an investigation. In the investigation, we will do a thorough investigation to find out the source of the incident that happened, Mr. and Mrs. There are roughly two ways to do an investigation, where the first is to do an identification.
where we will do a thorough investigation whether the incident happened at the external level or the application level or has an impact on other assets. Then the second is to do analysis where we will document and analyze every evidence of the incident that will be found later. Then from this investigation, there are four ways, ladies and gentlemen. The first is evidence collection, then road cause,
Then the third one is vulnerability, and the last one is analysis activity. For the first one, evidence collection, where we will collect everything related to evidence of incidents. So here we will collect, ladies and gentlemen, some evidence of incidents that are needed in handling incidents, especially online judi.
Then, road cause, here we will look for the details of the source of the attack and the source of the incident that happened inside. Then the third is vulnerability, here we will do a check in all possible possible signs of a system failure, ladies and gentlemen.
The last one is malicious activity, where we will check if there are suspicious activities in the operating system. Okay, next. Maybe just go ahead, ladies and gentlemen, because I want to introduce the tools here, what are they used for, and at the same time we will try to simulate. Next.
Here we will use four tools, sir. The first is Ubuntu IR or Ubuntu Incident Response. Here is a script, sir, which will be used in evidence collector or collecting several types of evidence. Then here using Torlight.
This toilet is HTML, it will contain some obstacles or weaknesses as well as findings from the malware or backdoor that is inside it. Then the last two tools below, which are Linis and Linpis, are used to audit the system, sir. Maybe I will explain it more clearly in the next session. Next.
For the own log analysis tools or Ubuntu IR, Ubuntu IR is a script that collects several evidences used to analyze a cyber security incident.
This script will run to collect information about the application list, then there is a user list, then a cron job list, and information about malicious software or shell-shaped, which is often found when there is a cyber security incident.
This script can also find the potential of the PHP backdoor in certain directories, sir. Where it will help in analyzing the system security that occurs. To access this tool, you can do the link, we have included it here, sir. Later, please access it. Next. For some evidence collectors, here it is already
the link earlier has been explained or given a little explanation of some commands or scripts that are run to collect some evidence collector later. Next, here I am a little bit, ladies and gentlemen, to explain the content of ubuntu-ir.sa, later we will try to explain it again in a detailed simulation session, ladies and gentlemen. For the first one, the results of the script that
First, here, "Date" produces data 0, this is datetime.txt Here, the output can store the date and time when the event occurs. Then, uname /a
Here, it's in kernel version, ladies and gentlemen. Where the output can store information in kernel form into kernel.txt file. Then the third one is in OS.txt version. Here it will store some information in OS version. In the most affected SE, ladies and gentlemen. And it's stored in OS.txt version. Then process list. Here,
The third one is to be able to store a complete list of all processes running in the system, in the file in the form of the process.txt list. Then the fourth one is the running app list or TXT here.
The output is a complete list of running applications in a system that is a running list of ap.tst files.
Then, regarding the base history, for the base history itself, it will be filled in from root/root/basehistory, where the file that contains the base command script that has been executed by the user of the root into the new file called history.txt.
This script will search and display file lists or directories that are started with cron in /etc directory and store the list in cron.txt file.
Then the seventh is crontab.txt, here it functions to display content from crontab or crontable for users at this time and then today stored on crontab.txt file
Next, here are some additional instructions, ladies and gentlemen, regarding the crontab, namely 7.1 regarding crontab.txt. Here we will take information about crontab from all users that are in the /var/pool/cron/crontabs directory.
This directory is usually used by the system to store crontab files that contain tasks that will be scheduled using cron, the one in number 6. Then there is another one in 7/2, here crontabs.txt.
where the contents can identify all the tasks of Cron or Cron jobs for every registered user in an application system or SE. Okay, next. Then here, continue to number 8, which is inbound.txt, where the netstat command with the
the NP tool will display all the connections that are being heard or listening in a system including the port and program that hears the port this output from the command will be stored in file number 8, inbound.txt then the same as number 8 here there is outbound.txt
More or less the same, the netstat command with the "untube" option will display a list of all active connections, including TCP and UDP connections that are active. The output of this command will be stored on number 9, which is outbound.txt. Then the first one is "establish connect".
.txt here this command will display a list of all connections that are in Establish status or connected, yes, sir and store it in the Establish file connect.txt then the number 11 connect to pc.txt here the command used to display information about users who are logging in to the system
including information about the active connection and the output of this command will be stored in the file connect to pc.txt next, the 12th, here is dns.txt command here is the card used to display the contents of the file /etc/resolve.conf which contains the DNS configuration on a system
The output from this command will later be stored in file number 12, which is dns.txt Then number 13, which is hostname.txt The cat command is used to display the contents of the file /etc/hostname which contains the host name for the entire system The output from this command will later be stored in file number 13, which is hostname.txt
Then in part 14, host.txt itself, the cat command is used to display the contents of the /etc/host file which contains the host name list and the IP address that is suitable for the system. The output from this command will be stored in the host.txt file. Next. Next, number 15, here is the user list.
The CAD command is used to display the contents of the file /acc/passwd which contains information about a user who registered on a system. The output is stored at number 15, register user.txt, then number 16, register user base,
Here the command will look for the rows in the /etc/passwd file containing the word "base" "base" where it can indicate the user who uses the base cell as the default cell in their system The output of this command will later be stored in file number 16, which is the user_base_dos.txt list Then last_log.txt
This Last Lock command is used to display information about the time, the last user that was logged in to a system, sir. The output of this command will later be stored in the form of lastlock.txt with number 17. Then number 18, last.txt command is used to display the login history of the user to the system.
including information about the last login and lockout time as well as information about the duration of the login session, sir. The output of this order will be saved in file 18, which is lastdos.txt. Next, then in number 19, homedir.txt,
Here, the command ls with the option -alt -r /home is used to display all files and directories recursively from the directory /home. This operator, homedir.txt, is used as an operator to direct the output from the command ls to the file text called homedir.txt.
Then the number 20, varwwwdir.txt, more or less the same as number 19, but here it is more detailed in the directory varwww, to display all the files and recursive directories in the directory /var/www. Then it is also used to send output from the ls command to the file text named varwwwdir.txt. Next.
Here is the last one, ladies and gentlemen. In general, this script is used to search the directory /home/var/www to find files that contain PHP functions, which are often used to execute shell commands or other dangerous operations, and store the results in the text file that fits the specified directory.
Then the last one, number 23, there was an update yesterday, ladies and gentlemen, regarding the list slot.txt, where you can find keywords related to several here, such as slot, gachor, maxwin, thailand, sigma slot, zeus, and cuan, and where all the files are in the directory slash zoom, ladies and gentlemen.
Then the conclusion of this tool, so, in a nutshell, this script makes an archive from the Ubuntuir directory with the name collection.tar.gz by using gunzip compression and then erases the entire Ubuntuir directory as well as the contents of the system after the archive process is completed. Next.
This will be implemented, ladies and gentlemen, later here we will power it first and for simulation it will be simulated after the presentation is finished. For the implementation here we have given the tutorial as well for the output as follows. Next, you can continue next, then after the initial installation was done, the collection folder will appear.
/ - the name of the instance.tar.gz, ladies and gentlemen. Where the name of the instance can be adjusted to each one according to the instance of each lady who will be done evidence collector. Then after appearing, later done tar.min.xvf collection name. Here will do GUNZIP, the file will be
After extracting, the results will appear like this, like an image. Next, we will introduce the tools for malware or backdoor scanners, such as Torlight. What is Torlight? Torlight is a portable detection application to detect suspicious activities in the system that will be hacked.
TOR Scanner can detect in-depth to local event log, register, and file system. TOR Scanner can be a detection system for dangerous activities that are passed by antivirus in general, ladies and gentlemen. The results of the detection using TOR Scanner can be exported in HTML, TXT, JSON, and CSV format, ladies and gentlemen.
This toilet is actually open source, can be accessed on Google. This is from Nextron, I have given the image here, you can go to Next. Now for the installation and configuration here, we first register, ladies and gentlemen, in the address in Nextron, in the toilet earlier.
register users by accessing the following address www.nextronsystem.com/torlet/pagar/get-tor and click download the torlet then it will be continued to the registration page as follows then continue by filling in the email with the name using the public email only, the advice is to use the public email and click subscribe
After that, the license and application will be issued. After subscribing, wait a few seconds and a notification will appear on the email that has been previously registered. And the notification will be opened, it will appear as follows, ladies and gentlemen. Continue by clicking confirm and it will reappear on the email notification. Next.
Here, more or less, it will appear like this, sir and madam, download the Torlet, the one on the right. And for the Torlet file pack, here is also an example, it can be in Next. Then, the implementation itself, here we from BSSN have actually made our own Torlet version, sir and madam, which we have perfected from the addition of several rules or signatures.
Here, we will also give the tools to you if you want to try to implement it. First, we have to access the root first, by sudo su. Then we will git clone this address, sir. GitHub adepermanator2, sir.
After downloading, then we will do executable on the Torlet command line by doing chmod +x Torlet Linux so that later it will be green like this, sir. On the right, the color is green, Torlet Linux. For earlier, the Torlet from this basis already has the addition of YaraRules Signature on the Torlet tool. Next.
For the implementation itself, we will run the command like this, ladies and gentlemen. And the result is on the right side. More or less, usually, because it's more specific here, ladies and gentlemen, because the director is /var/ww/html, so maybe
the time for the result later is not too long because the directory is more specific /var/www/html even if you want to scan from /sum it can also be but usually the time is longer, ladies and gentlemen, we will practice later, okay next this is the result later, the output is a process
Here I give more or less red color, the malware found with score 89, later we will try to practice, can be next For the own code, here in the form of .html, more or less the result is like this, later we will try to simulate, next
Next, audit tools TI or here you use two, Linis and Linpis. Next, for doing audits, we need to measure all possible gaps, the gaps that can be exploited by the auditor, yes, sir. To measure it, there are several tools that can be used. One example of the tools is to use Linis and Linpis.
This is an open source tool that can be used to audit and hardening a Unix or Linux operating system. Then, Leanpiece. Leanpiece is a script that requires the possibility of a path or application that can be privileged escalation. In a Unix operating system, it can be used either Linux or MacOS.
for the references here we have also included later can be accessed independently next then for the implementation itself later we will try to practice yes sir in doing the installation configuration we have to enter first to access root using sudo su then git clone this is sir https github slash
Next.
Then for the implementation of the Lendpiece, we will do configuration installation by running the following command. Maybe for this Lendpiece, it is recommended that you don't need to do sudo su, sir, you don't need to do access root. With the script as follows: curl /l /etps/github/epis/
We will try to simulate it later. Next. And this is for the technical guidance, ladies and gentlemen. Technical guidance here, we have also provided. Later, please access some guidance, tools here. Technical guidance, identification and identity analysis. Then we also provide guidance on handling web development incidents online.
and malware scanning guide using Tor Scanner and update guide Tor Scanner signature from us earlier, from BSSN, here is also a guide to update it. Next. Maybe that's it from the material session from me. We will try to simulate, ladies and gentlemen. Here I will allow for a share screen.
Have you seen it, ladies and gentlemen? Here we will try to write the first one using Ubuntu Air, ladies and gentlemen. Let's try to check, it's still empty here. Then we will copy the script. Here is the name of the instance, we will just take an example, ladies and gentlemen. We use Remda1.
I'll try to run it, eh repeat, before entering here we have to enter the access route first, yes, sir, I forgot later I'm afraid it can't be done in a complete way, -1234, so that we can try to run it, I tried to run it, it's still waiting, sir, it's already starting to run, sir, maybe it was still a problem on the internet,
here some of the orders have appeared we wait until it's done here the script is complete, ladies and gentlemen, it's done and for the results we try to check here it has appeared, ladies and gentlemen, collection pmbda1.tar.dz then we do extract using tar xpf collection we enter, we will have done extract, ladies and gentlemen
then we try to check the contents we enter the results so Ubuntu 21 try to check it has appeared, ladies and gentlemen, some of the results, maybe we will take some sample examples, ladies and gentlemen, for us to try to explain maybe the first one is the number
three, three first, three is a process list, we try to check using cat3 process list, here it is visible, ladies and gentlemen, for some of the process lists,
where we will check the CPU usage and the name of the application here has also been displayed. The application is running, whether the data is running smoothly. Here the comments have also appeared, ladies and gentlemen. Later, you can try it yourself.
Then we take another example at number 5 because it was related to base history, which was explained by Mr. Dari Ibrahim, we try to check the results of base history at number 5. For some stories or the results of storing the story on this affected server, here it can be stored in the form of a command summary.
what is used by the user of the route that has been done by the user, sir. Here are some comments used by the user who runs the route. Then we take an example back at number 72 only, related to the crontab. Wait, let's try to check again, 72, crontab.
we check for the Chrome tab or the scheduled application list here we see several users on each server we will do a check whether it has a Chrome job its use on each server here is its use so that the command can read all the users and the Chrome jobs and
for users without the task of crown, usually the message will be displayed in the form of no crown tap, ladies and gentlemen, because here is the result, because then the result is like this, the concept for user root, then some of the results of the concept are already there, ladies and gentlemen, we continue, we try to check back for the list backdoor, just try it here, the list backdoor is in the number
21 and 22 21 from the home dear if it's from farwee dear we try the 22 cat 21 here from 21 we will do string debugging, sir, which is usually used by backdoor here at the home directory, yes, at the home directory, more or less like this, we try to go back to
the backdoor on the farweewee, let's check the backdoor for the baby here, more or less, there are quite a few, sir, let's try to check here some stream notifications that are usually used by this backdoor, let's take an example in
Here, at the very beginning, sir /var/www/html/image/berita/config.php Here we see the string, more or less, this string is usually used for attackers to do backdoor, sir. Here, at eval, yes, gassin_flat, base64, decode,
code like this, more or less, usually from our experience from Satgas, this is usually a file that is deleted by the web browser that has been detected by the backdoor, then we try to check the results again, we try to check the results, we try to get it earlier, it's slash
www.html.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.php.ph
the backdoor here are the codes that are tricky, ladies and gentlemen, here usually this encode is used by the backdoor attacker to load the backdoor, more or less the code is like this, okay, let's try to continue in the number and try to continue again at number 23, let's try to see the slot list, cat23, here
Let's take the lowest example, sir /home/admin/ubuntuir/pemda1/var/www/html/image/berita/slot Let's try to enter the directory, let's try to see if there is a gachor's list slot there, we enter, we open cat /var/www/html/image/berita/slot
Oh, I repeat, we have to go to the directory first. Then we try to check, try to run cat. Now this is Dewa Petir, Dewa Petir HTML. We try cat Dewa Petir HTML. Well, more or less like this, ladies and gentlemen. The HTML page that appears when we check the online judi page.
here it is long, usually we check this HTML dot through the web browser, ladies and gentlemen, if you want the results to be clearer, because we are only using the command cat or only looking at the content of the string, more or less like this, here the demo jackpot slot is guaranteed for free today, here it is usually a website slot, the online judi, then
let's try again enter the cd /sum /admin for the result earlier maybe for the result of ubuntu air more or less like that, ladies and gentlemen, later it can be tried to simulate independently by you and your ladies and gentlemen to find out what evidence collector is when scanned on
the electronic system that you have impacted then here I will try to simulate about the second tool, which is the toilet here we will copy the web from the GitHub, we do the git clone, we wait for the results, this process is still running a little while, ladies and gentlemen, I'm sorry for the internet because here we also use it together, it starts to run again
while we wait, we can try to repeat it again, let's see the results, it hasn't been there yet, let's try again, so it's time to experience an error, let's try again, it's failed again, maybe the internet is broken, let's try again, this is successful, ladies and gentlemen, hopefully successful, ladies and gentlemen, we wait
Maybe later when the trial can be done when the internet is stable, yes, sir. Maybe here too, many users, so maybe the internet is less stable. Maybe while we try again, if you want to ask questions, we will
I will take the session to the first question, while I try it again later if it can be, we will continue later maybe from Mr. Ibu if there is any questions, please so because it's still in the process, so maybe later we try with Mr. Haru to try to finalize the four that haven't been simulated
So, we are happy to see you all while waiting for the preparation from Mr. Haru. There were several discussions that we watched in this chat. Maybe before entering the chat, there were also some who did a presentation from PT IPD Kuin Malang.
We invite the PTID Win Malang to convey the discussion or the question by conveying the name and who is directed to the question. Please for the PTID Win Malang. Assalamualaikum warahmatullahi wabarakatuh. I am Abu Nawas from the PTID Win Malang.
My question is, in our institution, we manage more than 200, almost 250 websites, and that's a lot for management. So for monitoring the slot, we usually do a Google search through the keyword slot or gap or maxwin for every day.
Is there any, sir? For tools crawling automatically on Google, if the website in our domain contains the keyword slot gacor, it can be detected through Google's search engine.
Because we are a university that manages many sub-domain websites in our institution, so are there tools like that? Thank you. Okay, sir, thank you for the question. So are there tools to monitor the position of the script?
Okay, thank you for the question. While we're waiting, do you have any questions? Or maybe from Mr. Aru or Mr. Danu, you can tell us. Maybe from Mr. Aru first, because he's a technical person for monitoring. Please, Mr. Aru, if you have anything to say regarding the question from Mr. Abum Nas.
Yes, thank you for the opportunity to answer the question about tools, sir. Then here we actually have made tools, wait a minute, I'll try to open it, to do data crawling, usually in the form of Google Doorking, we make a Python script, wait a minute, I'll try to open it.
maybe I'll try to fill in the screen, yes, have you seen it, maybe this is a Python script, ladies and gentlemen, here we try to take gambling or the slot that usually happens in
Google or search it in the form of judi casino poker slot Togel Gacor Thailand Maxwin deposit betting jackpot Asia Hoki again Cuanan here usually later we can add it back for the slot list, we usually add more as much as possible so that the results are more maximum, Mr.
Then for the output here, we take an example of 100 domains that will appear when we run this script command. Here we take an example of 100, ladies and gentlemen. Then we try running. Why is it like this? Why does it appear here?
maybe we take an example, sir, we just go straight to the dotku.id star, we will try sampling because we only take 100 searchers, 100 domains, later, the results will be less than a long time, this can be up to 1000, yes, sir, if you want to search as much as possible, maybe it's not limited, but also
the results will also be more, it will be longer later we will try to take 100 gambling domains we wait for the results maybe this, sir, appears, yes, some domains dot go dot id that appear based on some of the gambling care world domains here, the domain is more or less like this
because I took it earlier dot star dot go dot ID so maybe not too detailed domain or results
domain from the website, is it really affected by online gambling because here we are more to Google Dorking, ladies and gentlemen, so we take it maybe here it's just news, it can also be only the website, it can also be because it's not specific, ladies and gentlemen, maybe later it's more specific, for example, some domains from your ladies and gentlemen who are owned by
electronic system in your instance, for example malangkota.co.id or belitarkota.co.id like that, the results will be specific domain that we do the search because here it's more to us in general, just gambling in general from the star .co.id more or less the results are like this and later usually here will be stored
in the form of .txt, sir. In the form of .txt, we will see the output in the form of .go.id. Maybe more or less like that from me, sir. I return it to the moderator. May I? Can be sent.
the script link, which is on Github, maybe sent to chat so that friends can download
Yes, sir. We will tell you later. We will tell you later. Because this tool is open source, hopefully what we introduce can be used by you to do monitoring and investigation. Maybe related to this, please monitor it
So, we will update it later. Okay, maybe that's related to the monitoring tools used by the South Gas team to do the working of South Gas.
Okay, next, there are also some questions related to the previous scripts, we will try to share them later in our GitHub. Then the second one, here is a question, maybe I will read it from the Smooth Processor, Mr. Aprizam Saputra. May I ask, maybe later this can be received from Mr. Danu.
There is a system that has been compromised. We as a research team want to analyze it. This system should not be shut down or still online. How is the practice? And if the system is still online, will the hacker still be active in the system? Have we ever experienced the wrong way of chasing and deleting connection files?
The point is, because the system is already compromised, the hope is that it will remain online or up. What are the intentions? Maybe Mr. Danu can convey his insight so that it will later become a recommendation to you who are experiencing the same condition. Please, Mr. Baim, Mr. Danu.
Thank you for your question. May I answer? For such cases, it can actually be analyzed live, for example, the system is still running, but the analysis is still being done. One of them is done by first, the acquisition first, sir.
the clocks that are in the acquisition, then if it has to be analyzed, if you want to do a scanning, you have to make sure that the server is strong, so when the system is still live, it must be made sure, when you want to use scanning, use the tools that have been applied, it must be made sure that the server is strong
.
in the pursuit of removing those things, this is the point, so when there is a web development online, so don't just focus on removing the online judi, it is not the right solution
That is a solution, but not the maximum solution to be implemented. It should be analyzed first, compromised assessment first, analysis first, then scanning, then scanning using the IR point, then make sure
from where the attacker entered, the malware was deleted, and after the malware or the backdoor web site was found, it was immediately deleted.
and it must be made sure that the persistence mechanism is also removed, so it's not just removing the page, but it must be made sure that the persistence mechanism and the entry door and also the web server of the system have been removed, maybe that's my insight, I'll return it to the moderator. Thank you, Mr. Denu. So, as you said earlier,
There are two ways to do it. One is live investigation, where the system that has been compromised is investigated live. It takes time. The other way is that it has to be taken down first, then investigated using digital collections, etc. As Mr. Danu explained, there are some tools to take the collector's artifact.
Okay, thank you, Mr. Dendo, for your insight. Okay, next, maybe you guys who want to ask, maybe I'll read it again. From Discominfo Bontang. This question wants to be directly conveyed or chatted, Mr. Izin from Mr. Fikri Riza Eswandiari. Mr. Izin, please. Okay, I think there's no additional questions.
Then here also related to the Python script that we will try to upload later, we will update it on the GitHub that was previously conveyed by the source narrators as a further script tool for monitoring. Okay, while waiting for the next discussion, maybe from Mr. Aru, he wants to convey again about the simulation of
malware scanner using the Tor application, are you ready? Yes, I'm ready. Okay, yes, ready. Thank you to the moderator. Thank you to the moderator. We will try to continue again. I ask for a share screen.
Sorry, sir, maybe the internet is not enough to download, because here I try to do the data myself. Here, I have downloaded the tool store, the 2 version of our BSSN. Then after downloading the git clone, here it appears, sir, in our LS, here appears the 2nd store.
So it's already there, let's try to go inside. Let's try to check, it's more or less like this. Earlier in the paparan message, we see that the color is green, because it's already executed there. Using the command chmood + x. So we do the executable mode on the Linux toilet. We chmood + x, x, toilet, Linux.
check it, it's green, yes, sir, then we continue to run the application, run the Linux tool like this, here we do it from the
just a little bit more in short, sir, what I have explained from /. /var/www/html, sir. So the results will not take long. Maybe here I will also explain the script. For the script here, ./storelightlinux is more to run the tools, then /dsh file scan, for the file scan itself here,
We instructed the Tor to focus on file migration in a system and will analyze the contents of the file in the form of metadata and anomalies.
Then here Intense, the option to activate the Intensive mode which runs deeper and more comprehensive storage For this mode usually requires more power sources or CPU memory during storage time and tends to be longer, sir if using this Intense Then, No Risk Control, here we will activate the power source or resource control control
without limitations so that TorLED can use more CPU and memory needed to speed up the migration process. Then cross-platform shows that the migration must consider the platform across the operating system where Tor will look for relevant files or patterns not only on the Linux system but also other platforms such as Windows and MacOS.
Then, all drives, here we will ask the office to move all drives related to the system including external storage and other parts. Then lastly, the DSP / far / eww / html. Here we are more specific, ladies and gentlemen, for the directory path. The move will be limited to the directory.
This directory is usually used for several website files, for example, PHP or HTML-based applications on a web server like Apache or Nginx. Maybe like that, sir. Let's see if the results have been completed. It's done, sir. Let's check the results here.
this is the ubuntu tor 2004 11 22 15 22 dot html and here the output is already explained in the form of dot html, ladies and gentlemen, so here we need to do it for the check, we need to do
copy paste the toilet session to farwee HTML used to check the results, ladies and gentlemen, here it means we will copy the HTML dot, here it is in the form of a copy, it means ubuntu.org 2004.html then we do the copying on this, ladies and gentlemen, we will check
Here we will put the copy in /var/www/html with the name of ubuntu.html file. This is just an example, sir. We give the name ubuntu.html. We try. Then we try to enter the web browser, sir. Wait a minute, I'll try to open the web browser. Here we enter the IP.
I checked the IP again, 72 20 23 23 10 3 / Oh, the license hasn't appeared yet, I'll open it first, I'll share the screen, it's already visible, ladies and gentlemen,
because I tried to copy the results to /var/www/html here we try to access the IP server the IP server was 172.20.10.3/ubuntu.html because we gave the name ubuntu.html so we can check, ladies and gentlemen, for the results of the toilet
then from this result we will try to explain a little bit what is the result of this toilet, what can we get from the result of this toilet, that's the first thing seen from the scan file, sir, here the scan file is used to move the file then some
the argument path here for the path itself, directory from /var/ww/html then for the method we did the scan earlier, several, when we run the scan then for the time here, about 1 minute we do the scan with the IP address, this is the lady has appeared with our access using root
and the platform used is ubuntu 16.04.4 then for the results itself the statistics can be seen, sir here the alert is 0 then the warning is 3 the notice is 3 then the info is 483, sir maybe as an example we take what is seen suspiciously, sir this is from warning number 3
because we have also done the first one using ubuntu ear earlier we saw the file in /var/www/html/image/berita/config.php this config.php earlier already knew if
there is a backdoor, ladies and gentlemen, here it is also visible, the rules are here using the B374K websel, here it is already visible, B374K is usually a backdoor for the match, the string is also visible, more or less the same as that produced by Ubuntu IR, ladies and gentlemen, maybe more or less the contents can be checked later, ladies and gentlemen, to do an independent analysis, some
the strings that are felt that this warning is malware or the background then from this result I also give a little conclusion for this config.php file, usually identified as a web cell
or a backdoor that makes it possible for access to the web server to be incorrect. This time, we identified that the system may have been hacked or there are files that are copied by attackers. Maybe some recommendations
if there is a conflict of this php, we immediately isolate the first file to move this file.config.php to a safe location or we immediately delete it if needed then we will check the server, check the server and look for activities to detect at the time this file is made or modified, sir
Then we will update the system using the latest software version where the operating system and web applications must be updated. Then we need to use the web application firewall or WAV to prevent dangerous code execution in the future.
Then we will make a continuation modification to ensure that there are no other files that are infected or should be sued by you. So maybe when you see some files like this, some recommendations can be tried.
Maybe for this toilet, that's all, ladies and gentlemen, please do it yourself later. We move on to the audit tools, ladies and gentlemen, using Linis and Linpis. We open the terminal again, if I may, sir and madam. We enter, try to do it right away, ladies and gentlemen, because we try to speed up the time.
we just go straight ahead like the one in the material earlier we continue to do git clone when the git clone is done we go in we try to check the linis is already there, we go into linis then we try to run it directly in the form of linis we will do an audit system to scan the security on the audit system
Well, more or less like this, ladies and gentlemen, we will proceed for this clinic, usually can conduct an audit on the configuration of the operating system, service and security for the administrator of the system, usually can also utilize this report to identify safety weaknesses or configuration where there is a need for improvement, ladies and gentlemen, maybe this is also the result that is still waiting
You can check the program, the DTXCOS here, using Ubuntu 16 Linux. Maybe it also takes some time. Here the boot service is also visible. This red one usually needs attention, sir. From the system owned by you, sir, later there will also be a red one.
means that the value is still in the current, sir. And here there is also a warning, maybe later it can be checked on the electronic system, sir, which is affected, maybe more or less from the linear tool like this, sir. This is quite time consuming, sir. Wait a minute, I'll take it. The solution is more or less like this for the linear tool.
Maybe because we're just speeding up, we'll just stop to run this tool. Because it feels quite long. We just stop. Then we continue to the next tool, which is the lane piece. For the lane piece earlier, we are not recommended to use the route, sir. So we just exit. Then we run it earlier.
for the lane piece, sir, more or less like this, later if there is a route here, it will look like there is a color like this, this yellow, then you enter already like a route, like a route, later if you enter the route mode, it will appear like that, but it is recommended not to use the route mode, sir, we have to go out to the route mode,
more or less like this, the results of this link piece are usually quite important tools, ladies and gentlemen, to find the flaw in the Linux system related to privilege escalation. The output of this script is usually useful for the administrator of the system, useful for verifying security configurations, then identifying the potential of
The attack factor and this script are also suitable for use by security researchers and penetration test testers, ladies and gentlemen. Maybe later it can be tried by itself, ladies and gentlemen. More or less, the results will appear later. Some of them have been displayed in the material earlier on the PPT. So the output is more or less there is a CVA that appears, ladies and gentlemen.
CVE traffic jams that appear in the system, the electronic system that is affected later. Maybe while waiting for time, here are some Pet Home Admins, it is felt that he is 90% privilege factor, yes, here is the legend, later it can be read by itself, he is 95% privilege factor with red color, there is
the yellow color like this so it has a 95% escalation so the escalation value is higher then here for some of the CVA schedules are also available, sir, have been given more or less explained here too, later it can be checked independently by you, maybe that's about the lean piece
Maybe if anyone wants to ask again, I allow the moderator to go back. Okay, thank you, Mr. Korn, for the simulation. I hope I can describe it, Mr. and Mrs. Kalian, from the 4 tools that were mentioned, plus the additional tools for monitoring.
that requested from one of the participants earlier. We will also update the link to the tools. Okay, ladies and gentlemen. Maybe there are some things that I want to say here in the chat column. The first is related to Mr. Dewi Firmansyah. For the next session, can you share the way of web exploitation?
So, besides the construction, we also do the secondary. Okay, sir. Maybe this can be a suggestion for the webinar activities in the future, sir. So, besides the blue team, maybe the red team will be a little bit like that. Maybe this is our first suggestion. Then the next one,
May I ask, sir, if there are speakers who enter the webinar, then enter the link-basing, will the business anticipate this? Yes, of course, maybe later we can anticipate it, of course, with the URL that we sorted, Mr. Ibu Tatin. So, because it is assumed that this is a public status,
Maybe later we will try to sort the link that is conveyed here. Then the next one, Mr. Khairul Anwar.
I just tried using the TOR2 tool, it's already finished, but I'm confused. Yes, sir. So, it was explained a little by Mr. Aru, right? So, it's related to technical like this, you have to practice a lot and read the output results, sir. So, often, sir. In the previous session, it was only simple, yes, it's still...
Simple like that Maybe you can try the details later on your own systems that are live Or maybe use several servers that have not been used Make it a learning to run for your own purposes Excuse me sir, for the Google Dorking script, where can it be used? We will upload it later on the GitHub that was earlier Maybe Mas Haru can send the updated link
Okay, next, here, sir, for the case of the Gajar prayer, actually, did they get our website access or just upload the site? Because we have been shown several times that our web file has nothing to do with them. What is the purpose, sir? Maybe a little, Mr. Danu can give insights back related to Mr. Sharif Firdaus from Dikti 11. Please, Mr. Danu, maybe there is an image or maybe there is an insight that can be conveyed. Please.
I would like to ask about what is done by the attacker when he successfully sucked the slot carrier elements. This must be analyzed more closely, because we cannot conclude that the attacker only wants to
uploading the gajar slot only. When the attacker has received a target, of course the attacker can do anything, sir. So we should analyze further what is being done by the attacker in our system.
we can conclude that the attacker can carry out a more continuous attack, that the attacker has taken over the system, or the attacker has carried out a privilege escalation, the attacker can move to another electronic system because of this land, that can only be seen as an attack
We don't know what the actual attacker wants. So if we want to know what the attacker is aiming for, we have to analyze it further. We have to analyze the log, the activity, the base, what the attacker did, and how far the attacker has done his activity. Maybe the attacker can
This is just one example, the attacker may just want to enter and want to get the data that we have. So the attacker may just enter, for example, they don't know, the attacker has entered for a long time, for example, for a year or two, it turns out they extracted our data, our personal data, if not, maybe the essential data, the organization's data, it was extracted, sent to
and then maybe the delivery is a little bit because the data that comes out is not suspicious. So it's usually like that, usually a little bit, but in the long run, one year, two years, three years, it will become one database itself. That's one example, maybe the attacker can carry out activities like that.
Maybe that's all from me, maybe it can be emphasized by the moderator or Mr. Aro. Thank you, Mr. Danu Ibrahim, for the question. Hopefully it can be explained, Mr. Seri Firdaus. If there are any things that need to be said, it can be conveyed later.
Next, maybe we can add this to what Ibrahim said, regarding how to delete Google's Slot Gatcher list. This is one of the lessons learned from the team yesterday in the field, how to delete it so that it doesn't get indexed by Google. Maybe we can add this. This is also from Mr. Apliza, maybe we can add this later.
I
indexing from Google, right? Well, from us, this is, sir, I suggest you go to Google Search Console, then there is a tutorial for how to remove indexing from, for example, the system
our electronic, our URL, for example, a specific URL, it can be removed from the Google indexing. Then enter the Google Search Console, then we verify with
upload it, like, basically, to do verification, then download the file that is in Google, then do verification on our server, when it is verified, then it will be able to continue the indexing removal on Google by removing the search engine optimization, online judo slot that is indexed on Google. Now, when it's removed, I mean,
For this process, of course, it takes time because the system is like making a request. When it is valid, it will be accessed by Google and we will wait for the process. After the process is finished, we can find out that the Google indexing has been lost. The indexing of the title slot has been lost. Next, I will return to the moderator.
Okay, thank you. So one of them is using Google Search Console. Google Search Console can be used to delete the indexing in the Studio Online website. I think it can be a good image. Next,
related to this, this is a comment from the comment section, Mr. Satria, Mr. Ijin, if the audit is on the application side, what tools do you use? Yes, maybe from Mas Aru can give a little brief information about the tools or maybe the mechanism or stage can be implemented to do auditing, please, Mr. Mas Aru, thank you, Mr. Director, this is a question from Mr.
Satria, yes, from the comment to the cow, the cow, here is the ID audit on the application side using what tools for this audit, usually more or less like a VA or Pentax, yes, sir, sir, maybe you can use an open source
it's if I'm not mistaken using burpsit burpsuit or waps zap that's it, ladies and gentlemen, you can try to check it on Google, then for the license, usually if I'm not mistaken using an account netix, maybe as a reference or guidance on several applications or audits
to the TI, especially in the application, maybe later you can refer to the regulations of the National Cyber Agency, number 4, 2021, about the security management of information security and technical standards and security procedures. Later there will also be some
the technical things that are needed to conduct an audit of the IT from the application side, sir. Later, please access or download the tape from the BCC number 4 tape in 2021. Maybe it's enough from me, I'll return it to the moderator.
Maybe one more, because the time is approaching 4 o'clock. One more is related to the question from Jisko Miko Bontang, related to a good monitoring system to prevent hackers from attacking further, and there is confirmation of the existence of a real time. Maybe Mr. Danu can convey his insight.
So, for questions about the monitoring system, Mr. Hikyepa, it actually goes back to the organization's needs.
For example, if there is a budget or more budget, it can use a monitoring system that is paid like that. But for example, in a private organization, for example, if there is a lack of budget, it can use a free monitoring system like that.
For example, using one of the free ones, for example Wazoo. I myself have talked to one of the people in one of the instances. In that instance, there is indeed one of the SDM who likes to practice, ladies and gentlemen.
curious about the monitoring system. The institution also applies the WESU monitoring system which is connected to the system management lock, namely the grey lock. So after the monitoring process, the lock is sent to the grey lock, sir. After that, the WESU is also connected to the telegram bot, sir. So for example,
the SDM is also a barrier, we can monitor the telegram, for example, when there is a notification that the criticality is high, it is immediately sent to the telegram. However, the main condition is that when we want it to be like that, we have to
We have to be curious, we have to be happy to operate like that. But when there is no such SDM, then maybe it is pushed to the top regarding the addition of such a system. Maybe that's it for the monitoring, and of course,
Monitoring also needs to involve human beings, sir. So we don't just believe in the system, but we also have to analyze it as an SDA. That's it. Thank you, Mr. Denmo. So that's the insight, Mr. Beusuk. So if it was just told by Mr. Dede Turgah that there is an intrusion detection system that hosts the bot host,
the name of the platform is open source, Wazoo, security monitoring, so Wazoo is open source, so it needs the most continuous knowledge to make a recipe or a contract, because there are so many implementation of Wazoo to be developed and integrated with several
and the application, as mentioned by Mr. Daniel, there is also Greylock and we have developed the alert to be delivered via telegram as well maybe that can be the next session, maybe in the future we will be given a chance to return it, maybe we will try to convey some of those suggestions, later it can be the themes that we raise in webinars like this
Hi, maybe you guys, okay, finally, Mr. Lutfi, if there is a suggestion to install the business, maybe the company will continue to continue, maybe if there is something that wants to be conveyed again, maybe later
we will send it to the next session, ladies and gentlemen. And also, if there is something missing, at least from us as guides, we have already conveyed everything. So, later it can be discussed first, sir. So, later, let you, ladies and gentlemen, here,
We can do the learning first from the guidance we have given So if there are things that are missing, we will try to bring back activities like this, Mr. Biusik Halian Okay, you guys here, the time is according to the schedule, it's already up to 4 o'clock and it's already close to 4 o'clock So for this session, we try to finish it first
Thank you for your attention, ladies and gentlemen. We thank Mr. Danu and Mr. Aru for their sharing. Hopefully it will be useful and make a new knowledge or insight that can be developed further by you. Thank you for your attention. We return to the MC. Thank you. Assalamualaikum warahmatullahi wabarakatuh.
Waalaikumsalam warahmatullahi wabarakatuh. Thank you, we would like to thank the moderator, Mr. Aprita Danang Permana, and to the speakers, Mr. Jabang Aru and Mr. Danu Ibrahim. Well, Mr. Sialan, it's actually interesting if we want to discuss how this development management will not be enough
through a sharing session for 1 or 2 hours. Maybe it needs to be a BIMTEK-based activity or an activity that we can do it directly, Ladies and Gentlemen. We do hope that we can do BIMTEK-based activities in the future. But once again, if it is from the BSSN that is engaged, of course in the future,
we can only ask for your representation. But if you intend to hold a more intensive BIMTEK, maybe it can be done in-house, at your place. Please make a BIMTEK activity program for the management of
in-house web divestment, and then maybe invite BSN as a teacher, maybe if you really want to get more intensive materials, because we have limitations in providing materials, time and power sources limitations.
Before the event is closed, we will have a photo session together, ladies and gentlemen. Please activate your cameras. Please activate your cameras. Later, our team will do a screenshot for each page on Zoom. Once again, please activate your cameras. Our team will do a screenshot.
Okay, please give us some time, ladies and gentlemen. Right now, our team is doing a screenshot of the drawing for the participants of this sharing session. Please give us some time. The drawing is being done. Okay, while waiting for the team to finish the screenshot, because there are quite a lot of participants, we would like to remind you, ladies and gentlemen, to fill in the presentation
on the presentation link given in the chat column. Meanwhile, we have also provided the material link in the chat column. So, in the material link, there are materials that have been delivered today.
And in the material there is also a link to the guide's guide, including the link for the GitHub itself. So the guide and the GitHub link have also been given in the material given this afternoon.
It's also interesting when there is a request that there is a script or crawling method automatically. It has been said by Mr. Jabang Aru from BSSN, try to prepare a Python script that can be used to do crawling automatically in your place.
So we hope, and we hope that the materials and tools provided in this sharing session, including the script for crawling automatically,
with Python, it can be practiced, it can be tried by you to learn step by step, the guidance is also learned and you try to run it in your respective places, for example, later it will be updated by Mr. Jabang Aru for the Python script, for example, it is executed, run to try to crawl in the system
is owned by you, the system in your place, is there any that is currently affected or defaced by online judi by using the Python script earlier? After the crawling results appeared and showed that there are quite a lot of websites or electronic systems in your place that are affected by online judi defacement,
Then we hope it will be taken down immediately, and then investigation will be carried out with the tools and guidance provided by the source leaders. So that's about it. We hope this can be really practiced in your place. Our hope is that there will be no more government websites
and other official websites that become online fraud sites, which become victims of online fraud web defacement. So immediately do crawling, immediately do the investigation, if found, then immediately do the investigation with the tools that have been provided earlier. That's all, ladies and gentlemen.
Okay, with the material delivered by the speakers until this afternoon, our sharing session is also over. The sharing session is about how to handle online judi web divestment.
Hopefully in the future we can agenda the next series of sessions that may be more thematic. For example, there was a request, how to read the results of the tour light, etc. Maybe this can be the next thematic in the next series of sessions. But once again, when you want a more intensive science or practice,
BIMTEK in-house activities that you have implemented by attracting BSSN hunters to be a fairly effective solution. Okay, if you allow us, we see here that there is Dan Satgas, raise hand. We invite Dan Satgas, please. Thank you, Mr. Sok. I just, earlier, as a, maybe as a closing too, that this activity is hopefully useful for all of us.
And there was a question that I heard earlier about, "Wow, if for example here, will there be anyone suddenly joining our seminar activities, then part of the team that performs or as a spy to perform the collection of information related to the jury?" Yes, as a minghimbau,
Coincidentally, as information from you, I took from the user or as a judge online, will be punished according to information from Jam Pindum, that is, the sentence according to Article 303 is 10 years in prison and a fine
as much as 10 billion, that is according to the KUHAP, but according to the decision of the DES, it will be layered, not only because of Article 303, but because of the layered article, the money laundering article, the money laundering article, and the article
related to fraud and other cases. So it will be very difficult for the airport or those who help the airport, including players, if they are caught in carrying out online judo or organizing online judo. That's the information we can convey to you, because this is no longer an activity
playing or not implementing the government, not doing this seriously, maybe that's just information. So, Mr. Asop, I have been following up from earlier. Thank you to all the teams who have carried out this activity. I would like to thank you. Hopefully it will be useful for all of us. Thank you, Mr. Asop. Please, I will return it. Yes, thank you and Satgas.
Okay, ladies and gentlemen, with the end of the material from the speakers and the closing remarks from Dan Satgas, then the sharing session of our web divestment handling is over. We as the initiators of the event apologize if there are still any shortcomings in the implementation of this event. Thank you for your participation.
Wa bilahi taufiq wal hidayah, wassalamu'alaikum warahmatullahi wabarakatuh. May God bless us. Om Santi Santi Om, Namo Buddhaya, Salam Kebajikan. Thank you, ladies and gentlemen. Thank you.
More transcripts
Explore other videos transcribed with YouTLDR.

Mi niñez fue un fusil AK-47
Comisión de la Verdad · Spanish

7. Un Remanente Fiel - Pr. Esteban Bohr || Verdades Para Este Tiempo
SUMtv Latino · Spanish

PENGERTIAN RELASI, FUNGSI, DOMAIN,KODOMAIN DAN RANGE
Utak Atik Otak · English

ساعة الأثرياء | الدحيح
New Media Academy Life · Arabic

You Won't Believe How Easy AlpineQuest Software Makes Geological Field Work | Offline Mapping
MOoDY 4 knOwledge · English

Mundos Olvidados
Cinematix · English

🎨 Apa Itu Sebenarnya Pelajaran Seni? #BelajardiRumah
Kok Bisa? · English

Bab-I: Teks Laporan Hasil Observasi kelas 10 SMA/SMK ~ Bahasa Indonesia
Belajar Prestasi · Indonesian

KONSEP BUDAYA| PENGERTIAN BUDAYA DAN SENI
BU APRIL · Indonesian

العقيدة الطحاوية (٤٠) | شرح أ.د. صالح سندي
أ.د. صالح سندي · English

Living the Change: Inspiring Stories for a Sustainable Future (Free Full Documentary)
Happen Films · Indonesian

SENI BUDAYA (SENI TARI) "ELEMEN DASAR TARI"
Budianing DNA · English
Get the TLDR of any YouTube video
Transcribe, summarize, and repurpose videos in 125+ languages — free, no signup required.