🔒 Closed How to generate http injector payload based on host's response header

Status
Not open for further replies.
Good day PHC!
Today I will share the way kung pano ako gumagawa ng payload.

Requirements:
Talas ng Isip
Mahabang pasensya

Notes:
Host URL used in this example is google based.
SIM used: TM (no regular load and promo)
APN used: Default

Okay, since alam niyo na ang pinaka basic sa paggawa ng ehi config, from creating an ssh account to what and where to put values. Diretso na tayo.

First.
Look for a host for your payload.
Example: m.google.com
or you can look for a more unique host.
How?
Use a reverse IP look up tool.
Here is an example of a website which has a reverse ip tool:
You do not have permission to view the full content of this post. Log in or register now.

Just query your favorite website/host, then it will show you all websites hosted by the same domain. Then choose ONE.

Second:
Look for a working Remote Proxy.
How?
Search it on google, it's free.
Ex. You do not have permission to view the full content of this post. Log in or register now.
*You can also use a Squid proxy from your favorite SSH hosting website.
*Always check your proxy status for better connection.
How?
Search "proxy checker" on google, it's free.
Ex. You do not have permission to view the full content of this post. Log in or register now.
Third:
Let's use the Host Checker from the HTTP Injector itself, to know what response header that your host will return to your proxy.
Screenshot:

As shown above, the host reponded status 301 Moved Permanently with GET request method. So if you use the GET request in generating your payload, you will get the same response. Now, you have an idea what to avoid.
This status may give you trouble connecting.
Also notice the Connection status, "Keep-alive".
I personally choose host with "Connection: keep-alive" in its header, because it means that,when the host recieved a request and granted a connection, it will keep the gateway open until the client will close it.

Status 301 Move Permanently means, the host either redirect you to its main domain or your local ip/remote proxy is blacklisted/blocked from accessing the host.
So we need to set our payload correctly.
How do we know?
We MUST AVOID seeing the "Status 301" or any other status aside from Status 200, in our log. So keep on trying until the Status 301 is eliminated.

*You can also try different request aside from GET in Host Checker, you might run into a status 200 response. That way, you will have an idea what request to use and avoid.

Fourth.
Set your payload.

Screenshot:
Setting that returned status 301 (Wrong method)

The log shows a successful connection because the HTTP injector, resend another request, a correct request for status 200.

What does it mean? It means that your settings is wrong.
You might say that it doesnt matter as long as it is connected. But NO, based on my experience, my config that has a different status aside from Status 200, did not work on others and has disconnection issues.
Also, it does not mean that your settings is faster than Status 200, or you may think and feel that its cool. Then you're wrong. An error is always an error, and say thank you to http injector for correcting you.

Screenshot:
Setting that returned Status 200 at first response (Correct method)

So, here we have a status 200. As you can see I used the CONNECT request method. The most common and simple type of method. You might ask, how did I know that I need to use this type of method to get a status 200 response.
If we go back to the Host Checker, the "content type" says "txt/html" and no more other content status or header fields indicating a complex data are displayed. It means this host does not contain any complicated codes(php,flash,databases etc). So it is not neccessary to use GET or request for a complicated response, a simple CONNECTion is enough for the host to establish a successful handshake.

If you are still getting an error after using all the request methods. Its tme for you to experiment with extra options.
Read below.




So, ayan lang po. Kayo na lang ang humusga. Di ko na eexplain kung pano ko kinalikot ang Payload, kasi random trial and error yan. Haha Pinakita ko lang kung paano mag base ng Payload sa response header. Hindi din po ako experto, so pag pasensyahan niyo na kung my mali akong naisulat, at mas mabuti kung i-correct niyo. Im glad to learn.
Personal experience is mas mabilis mag-inject ang status 200 na setting kesa sa ibang status.

Another Note: Kelangan mo ng internet connection pag gumamit ng host checker at sa paghahanap ng mga host at proxy.

Disclaimer: This tutorial does not guarantee you a free working internet from any ISP. This only serves as a guideline for you to explore on how to make it free that comes with your effort. More power to the army! :D

*Kung my naiasulat man ako na may kaparehong post or may naunang thread, I give credit to all of them. I made this solely based on my own venture.



Questions? Drop it in the comment box. I'll try my best to answer it.
Thank you for reading! Goodluck!

➖➖➖➖➖➖➖➖➖➖➖
Remember you are a human,
the highest being in the animal kingdom,
not a sponge.
➖➖➖➖➖➖➖➖➖➖➖
thanks paps
 
Maraming salamat din sa inyong lahat! haha mabuti at my natutunan kayo. Madagdagan na ang mga magsshare ng config.
Tanong lang kayo, kung my gusto i-clarify. sasagutin ko yan hanggat makakaya.
 
Salamat ng marami dito ts :)

try ko to thanks sir

Maraming salamat, napakahaba nun...

Salamat sir

thanks d2 master. nakatulong. :)

Thanks ts! Good procedure.

Salamat ts dagdag kaalaman to skin(y)wag po SNA kayong mgsawa mg bahagi ng kaalaman nyo sa larangan ng freenet...:D

salamat sa karagdagang kaalaman :)

Salamat sir

Thanks sa pagbahagi boss keep it up :) (y)

ty pohh bosing

Very helful tut to. Pag begginer k etong tut n nato makakatulong

Hindi katulad ng ibang puro kaartehan lng alam s threads nla

thanks paps

thank you po!

Malaking tulong boss para magawa ng sarilling ehi file..keep sharing po

Lupit mo paps!!
weee haha pasensya na ang sipag ko magquote. haha ang gaan lng sa pakiramdam ang bagong UI ng PHC. haha
Welcome sa inyong lahat, enjoy kayo and goodluck po mga papsi!
 
At last. e.e may napagana din ako with Promo. Mababasag ulo ko kaka try. Globe LTE SIM
Salamat sa thread na to!
wow! great discovery! hehe matry ko nga yan mamayang hapon. ang dami ko pang MB sa Globe e. haha salamat! share share na! gumana na pala config. haha
welcome po!
oo sir meron pa yung time na mapapagana ko sya isang beses.. tapos mag status 503 mga ilang mins lang.. kainis
aw. pag 503 nagkaka-initan ang port mo. mjo mahaba kasi routing ng sayo since naka wifi. hmmm dapat mabait na rp anh kailangan. yung di maarte sa ssh port.
 
Status
Not open for further replies.

About this Thread

  • 1K
    Replies
  • 90K
    Views
  • 586
    Participants
Last reply from:
diwit11

Online now

Members online
1,305
Guests online
1,210
Total visitors
2,515

Forum statistics

Threads
2,271,738
Posts
28,937,778
Members
1,237,838
Latest member
gyver991625
Back
Top