Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


[TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) filter_list
Author
Message
[TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) #1
Finding SQLi 0days in MyBB Plugins


Requirements:
A Text Editor (I really recommend http://www.sublimetext.com/)

Here are some 0day's I found back in the days when I walzted around with the stupid name Red_Hat spurting rubbish:

Spoiler:


Oh and this is what a good day looks like:
Spoiler:
[Image: QxOfcYn.png]


0x01.

But lets move on to the fun stuff. First off we need to download a plugin for testing. Head over to http://mods.mybb.com/mods and pick one of your choice.

Dont just choose a random one think about whether or not it would use a database (as this particular tutorial is based around SQLi).

Spoiler:
[Image: R6KcLQ3.png?2?1658]


0x02.
After downloading, navigate to "\Plugin\inc\plugins" and open the PHP file within. After doing so make a search for "$db", "input", "GET" and "POST" through all the files. If nothing comes up choose another plugin and repeat the process. You may find that this process takes a while.

Spoiler:

[Image: Ikne63B.png?1]



0x03.
Now lets take a look at all the variables extracted from the input, GET and POST that are mentioned and see if they sanitized at all.

Here's what a sanitized variable looks like: [Image: hinXckY.png]
If you see anything such as $db->escape_string or intval() these are signs of sanitation.

0x04.
You can also apply this method to WordPress if you ewplace every time Ive mentioned $mybb->input with $_GET and $_POST.

Profit.
If you are unsure about anything in this tutorial please send me a PM and I will aid you in your struggles. Just like to add that I found a persistent XSS vulnerability and an SQL injection vulnerability whilst doing this so if you are curios as to how hard this is dont worry.

Reply

RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) #2
Lol red hat hahahhahahahahaahaha mov ebx hahahhaha

Reply

RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) #3
oh my

were you the red_hat on HF who made that hilarious tutorial on 'writing shellcode'?
[Image: 383dbcbdd0eb954803ad9bc4f8934f82.png]

Reply

RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) #4
Yas, but I like to think I have improved.

Have you seen my pentesting tutorial though :3

"Ok, so lets scan all the ports, ah look 80 is open! We can attack from there"

Reply

RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) #5
It seems that creating an array allows you to bypass escape_string protection.
#MakeSinisterlySexyAgain

Reply

RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) #6
I got lost at pushing IRET onto the TCP stack.
Unleash the lead from my pistol into my head bumpin' crystal

Reply

RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) #7
(05-05-2014, 11:28 PM)Adorapuff Wrote: It seems that creating an array allows you to bypass escape_string protection.

Really? Im interested in this method, I really doubt it works though.

Reply

RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) #8
http://community.mybb.com/search.php?action=results&sid[0]=9afaea732cb32f06fa34b1888bd237e2&sortby=&order=
he's talking about this dumb shit, and he's wrong. This is not SQL injection. Sorry.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) #9
(05-06-2014, 09:09 AM)Reiko Wrote: http://community.mybb.com/search.php?action=results&sid[0]=9afaea732cb32f06fa34b1888bd237e2&sortby=&order=
he's talking about this dumb shit, and he's wrong. This is not SQL injection. Sorry.

Who, what? sorry? huh!

Hope this isnt aimed at me. (Think its Adora dough, cos theres an array)

Reply