[TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) 05-05-2014, 01:08 PM
#1
Finding SQLi 0days in MyBB Plugins
Requirements:
A Text Editor (I really recommend http://www.sublimetext.com/)
Here are some 0day's I found back in the days when I walzted around with the stupid name Red_Hat spurting rubbish:
Spoiler:
Oh and this is what a good day looks like:
Spoiler:
![[Image: QxOfcYn.png]](http://i.imgur.com/QxOfcYn.png)
0x01.
But lets move on to the fun stuff. First off we need to download a plugin for testing. Head over to http://mods.mybb.com/mods and pick one of your choice.
Dont just choose a random one think about whether or not it would use a database (as this particular tutorial is based around SQLi).
Spoiler:
![[Image: R6KcLQ3.png?2?1658]](http://i.imgur.com/R6KcLQ3.png?2?1658)
0x02.
After downloading, navigate to "\Plugin\inc\plugins" and open the PHP file within. After doing so make a search for "$db", "input", "GET" and "POST" through all the files. If nothing comes up choose another plugin and repeat the process. You may find that this process takes a while.
Spoiler:
![[Image: Ikne63B.png?1]](http://i.imgur.com/Ikne63B.png?1)
0x03.
Now lets take a look at all the variables extracted from the input, GET and POST that are mentioned and see if they sanitized at all.
Here's what a sanitized variable looks like:
![[Image: hinXckY.png]](http://i.imgur.com/hinXckY.png)
If you see anything such as $db->escape_string or intval() these are signs of sanitation.
0x04.
You can also apply this method to WordPress if you ewplace every time Ive mentioned $mybb->input with $_GET and $_POST.
Profit.
If you are unsure about anything in this tutorial please send me a PM and I will aid you in your struggles. Just like to add that I found a persistent XSS vulnerability and an SQL injection vulnerability whilst doing this so if you are curios as to how hard this is dont worry.




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)

























