Sinisterly
MyBB Exploitation via Open Merge Directory - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.li/Forum-Tutorials)
+--- Thread: MyBB Exploitation via Open Merge Directory (/Thread-MyBB-Exploitation-via-Open-Merge-Directory)

Pages: 1 2 3


RE: MyBB Exploitation via Open Merge Directory - Eclipse - 02-13-2014

Thanks for the tutorial Bresh! I have one or two problems though.

One: There is no download link to the SQl file mentioned at the start.
Two: There is no guide on the creating a DB:

"This is where you're going to need the details you created earlier with db4free.net." (I've created the Db but I have no idea how to "ensure MyBB 1.6 exists at this database and with this table prefix."

Could you get that fixed? Thanks!


RE: MyBB Exploitation via Open Merge Directory - BreShiE - 02-13-2014

(02-13-2014, 02:48 PM)Aurora Wrote: Thanks for the tutorial Bresh! I have one or two problems though.

One: There is no download link to the SQl file mentioned at the start.
Two: There is no guide on the creating a DB:

Updated the OP with the download link, sorry about that it must have got lost somewhere, I know for sure I did upload it.

(02-13-2014, 02:48 PM)Aurora Wrote: "This is where you're going to need the details you created earlier with db4free.net." (I've created the Db but I have no idea how to "ensure MyBB 1.6 exists at this database and with this table prefix."

Could you get that fixed? Thanks!

How do you mean? You think that this creates a MyBB database? All this is, is a database host, nothing more nothing less, once you have created the database on db4free.net you have to IMPORT that SQL file I added to the OP via phpMyAdmin. I thought this part was obvious? o_O


RE: MyBB Exploitation via Open Merge Directory - Eclipse - 02-13-2014

(02-13-2014, 03:10 PM)BreShiE Wrote: Updated the OP with the download link, sorry about that it must have got lost somewhere, I know for sure I did upload it.


How do you mean? You think that this creates a MyBB database? All this is, is a database host, nothing more nothing less, once you have created the database on db4free.net you have to IMPORT that SQL file I added to the OP via phpMyAdmin. I thought this part was obvious? o_O

Ohh, I understand now. I misread it. Blush


RE: MyBB Exploitation via Open Merge Directory - Eclipse - 02-13-2014

(02-13-2014, 03:10 PM)BreShiE Wrote: Updated the OP with the download link, sorry about that it must have got lost somewhere, I know for sure I did upload it.


How do you mean? You think that this creates a MyBB database? All this is, is a database host, nothing more nothing less, once you have created the database on db4free.net you have to IMPORT that SQL file I added to the OP via phpMyAdmin. I thought this part was obvious? o_O

Hmm, I get a new error. Do I have to make any edits to the SQL file? It didn't work the first time so I changed the host to the new one and changed the database name to the new one too. Did I have to do these changes?

SQL query:




--
-- Database: `ballsack`
--

-- --------------------------------------------------------

--
-- Table structure for table `mybb_adminlog`
--

CREATE TABLE IF NOT EXISTS `mybb_adminlog` (
`uid` int(10) unsigned NOT NULL DEFAULT '0',
`ipaddress` varchar(50) NOT NULL DEFAULT '',
`dateline` bigint(30) NOT NULL DEFAULT '0',
`module` varchar(50) NOT NULL DEFAULT '',
`action` varchar(50) NOT NULL DEFAULT '',
`data` text NOT NULL,
KEY `module` (`module`,`action`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
MySQL said: Documentation

#1046 - No database selected


RE: MyBB Exploitation via Open Merge Directory - BreShiE - 02-18-2014

(02-13-2014, 07:29 PM)Aurora Wrote: Hmm, I get a new error. Do I have to make any edits to the SQL file? It didn't work the first time so I changed the host to the new one and changed the database name to the new one too. Did I have to do these changes?

SQL query:




--
-- Database: `ballsack`
--

-- --------------------------------------------------------

--
-- Table structure for table `mybb_adminlog`
--

CREATE TABLE IF NOT EXISTS `mybb_adminlog` (
`uid` int(10) unsigned NOT NULL DEFAULT '0',
`ipaddress` varchar(50) NOT NULL DEFAULT '',
`dateline` bigint(30) NOT NULL DEFAULT '0',
`module` varchar(50) NOT NULL DEFAULT '',
`action` varchar(50) NOT NULL DEFAULT '',
`data` text NOT NULL,
KEY `module` (`module`,`action`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
MySQL said: Documentation

#1046 - No database selected

Just to confirm we sorted this out in PM.


RE: MyBB Exploitation via Open Merge Directory - Adorapuff - 02-18-2014

(02-18-2014, 01:33 AM)BreShiE Wrote: Just to confirm we sorted this out in PM.
This happened to me also, can you post a fix on the thread?


RE: MyBB Exploitation via Open Merge Directory - BreShiE - 02-18-2014

(02-18-2014, 04:48 AM)Adorapuff Wrote: This happened to me also, can you post a fix on the thread?



Done.

Quote:Create an account on db4free.net then login, go to phpMyAdmin then select the database you created, then import. Select this downloaded file and you're golden.



RE: MyBB Exploitation via Open Merge Directory - Satan - 02-18-2014

(02-18-2014, 09:28 AM)BreShiE Wrote: Done.

Biggest thing I've gotten from this thread is that host, cos I didn't know about them before this.

So thanks for that information lol.


RE: MyBB Exploitation via Open Merge Directory - Eclipse - 02-18-2014

(02-18-2014, 04:48 AM)Adorapuff Wrote: This happened to me also, can you post a fix on the thread?

Yeah, BreShiE's added it to the thread. I got another error, similar to the error you get when adding " to the end of a vulnerable site. The tables were imported though but when I tried to merge, there were no users. I may just create my own forum and import that.


RE: MyBB Exploitation via Open Merge Directory - Eclipse - 03-01-2014

(03-01-2014, 07:36 PM)Crossfaith Wrote: hello, i have tried changing the username into mine but when i try to merge it i get an error.

Code:
MyBB has experienced an internal SQL error and cannot continue. SQL Error: 1054 - Unknown column 'failedlogin' in 'field list' Query: INSERT INTO mybb_users (`usergroup`,`additionalgroups`,`displaygroup`,`import_usergroup`,`import_additionalgroups`,`import_displaygroup`,`import_uid`,`username`,`password`,`salt`,`loginkey`,`email`,`regdate`,`lastactive`,`lastvisit`,`website`,`showsigs`,`signature`,`showavatars`,`timezone`,`avatardimensions`,`avatartype`,`avatar`,`lastpost`,`icq`,`aim`,`yahoo`,`msn`,`hideemail`,`allownotices`,`regip`,`lastip`,`longregip`,`longlastip`,`language`,`passwordconvert`,`passwordconverttype`,`postnum`,`invisible`,`birthday`,`birthdayprivacy`,`subscriptionmethod`,`receivepms`,`receivefrombuddy`,`pmnotice`,`pmnotify`,`showquickreply`,`ppp`,`tpp`,`daysprune`,`timeformat`,`dst`,`buddylist`,`ignorelist`,`style`,`away`,`awaydate`,`returndate`,`referrer`,`referrals`,`reputation`,`timeonline`,`showcodebuttons`,`totalpms`,`unreadpms`,`pmfolders`,`notepad`,`threadmode`,`showredirect`,`dateformat`,`dstcorrection`,`warningpoints`,`moderateposts`,`moderationtime`,`suspendposting`,`suspensiontime`,`suspendsignature`,`suspendsigtime`,`coppauser`,`classicpostbit`,`loginattempts`,`failedlogin`,`usernotes`,`uid`,`usertitle`,`awayreason`) VALUES ('4','','','4','','','1','derpety','16d0ef1952fdaed62cf6a71ddf4ea543','cGgoB9YM','eP84NtCkG8r4fHvrkQS6ia6wRhJLMxCtbif36i4FHOKH4Pfz76','cool@cool.cool','1393040957','1393040957','1393040957','','1','','1','0','','0','','0','','','','','0','1','199.254.238.143','','-939594097','0','','','','0','0','','all','0','1','0','1','1','1','0','0','0','','0','','','0','0','0','','0','0','0','0','1','0','0','','','','1','','0','0','0','0','0','0','0','0','0','0','1','0','','','','')

but when i check it on my db4free database, i can't find the failedlogin column. thanks for the awesome tut by the way,

Did you import the SQL file correctly? Did you get any errors when doing that?