RE: MyBB SQLi Exploit 19-11-2013 11-23-2013, 09:49 PM
#11
And just for info. The password you tried to crack is "password123". The reason why you were not able to crack it the way you did was because of the services you used.
1. They only use a single md5()
2. They doesn't support salts
MyBB hashes the passwords like this md5(md5(salt).md5(password)) so a regular md5() will never work.
This motivated me to write a web service that is a lot more dynamic than what's already out there, so I did. I looked at your video again and wrote down the hash and salt. I then went ahead and created a table and imported my copy of rockyou password list to it. Next I did was trying the information from your video, and this was the result:
So within 10 seconds I had cracked the hash
1. They only use a single md5()
2. They doesn't support salts
MyBB hashes the passwords like this md5(md5(salt).md5(password)) so a regular md5() will never work.
This motivated me to write a web service that is a lot more dynamic than what's already out there, so I did. I looked at your video again and wrote down the hash and salt. I then went ahead and created a table and imported my copy of rockyou password list to it. Next I did was trying the information from your video, and this was the result:
Code:
SELECT plaintext FROM hashes WHERE MD5(CONCAT(MD5('8wqOCxry'),MD5(plaintext))) = '18a94a99ad239daae28f3b080965bf2a'So within 10 seconds I had cracked the hash



![[+]](https://sinister.li/images/modern/collapse_collapsed.png)