Sinisterly
MyBB SQLi Exploit 19-11-2013 - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: MyBB SQLi Exploit 19-11-2013 (/Thread-MyBB-SQLi-Exploit-19-11-2013)

Pages: 1 2 3


RE: MyBB SQLi Exploit 19-11-2013 - RogueCoder - 11-23-2013

And just for info. The password you tried to crack is "password123". The reason why you were not able to crack it the way you did was because of the services you used.

1. They only use a single md5()
2. They doesn't support salts

MyBB hashes the passwords like this md5(md5(salt).md5(password)) so a regular md5() will never work.

This motivated me to write a web service that is a lot more dynamic than what's already out there, so I did. I looked at your video again and wrote down the hash and salt. I then went ahead and created a table and imported my copy of rockyou password list to it. Next I did was trying the information from your video, and this was the result:

Code:
SELECT plaintext FROM hashes WHERE MD5(CONCAT(MD5('8wqOCxry'),MD5(plaintext))) = '18a94a99ad239daae28f3b080965bf2a'

So within 10 seconds I had cracked the hash


RE: MyBB SQLi Exploit 19-11-2013 - RogueCoder - 11-23-2013

And just for info. The password you tried to crack is "password123". The reason why you were not able to crack it the way you did was because of the services you used.

1. They only use a single md5()
2. They doesn't support salts

MyBB hashes the passwords like this md5(md5(salt).md5(password)) so a regular md5() will never work.

This motivated me to write a web service that is a lot more dynamic than what's already out there, so I did. I looked at your video again and wrote down the hash and salt. I then went ahead and created a table and imported my copy of rockyou password list to it. Next I did was trying the information from your video, and this was the result:

Code:
SELECT plaintext FROM hashes WHERE MD5(CONCAT(MD5('8wqOCxry'),MD5(plaintext))) = '18a94a99ad239daae28f3b080965bf2a'

So within 10 seconds I had cracked the hash


RE: MyBB SQLi Exploit 19-11-2013 - coolshame - 11-23-2013

shp0ngl3, I'm so sorry about that, so you are the best for this third, thank you my brother


RE: MyBB SQLi Exploit 19-11-2013 - coolshame - 11-23-2013

shp0ngl3, I'm so sorry about that, so you are the best for this third, thank you my brother


RE: MyBB SQLi Exploit 19-11-2013 - RogueCoder - 11-24-2013

(11-23-2013, 11:03 PM)coolshame Wrote: shp0ngl3, I'm so sorry about that, so you are the best for this third, thank you my brother

Nothing to be sorry about, just giving you a couple of useful hints on how you can get further by doing stuff manually. This is a classic example on how tools can not beat humans if the humans really study their field to get as advanced as possible


RE: MyBB SQLi Exploit 19-11-2013 - RogueCoder - 11-24-2013

(11-23-2013, 11:03 PM)coolshame Wrote: shp0ngl3, I'm so sorry about that, so you are the best for this third, thank you my brother

Nothing to be sorry about, just giving you a couple of useful hints on how you can get further by doing stuff manually. This is a classic example on how tools can not beat humans if the humans really study their field to get as advanced as possible


RE: MyBB SQLi Exploit 19-11-2013 - coolshame - 11-24-2013

yeas of course This is a classic example...
Plzzz Answer my PM


RE: MyBB SQLi Exploit 19-11-2013 - coolshame - 11-24-2013

yeas of course This is a classic example...
Plzzz Answer my PM


RE: MyBB SQLi Exploit 19-11-2013 - blacku33 - 11-24-2013

I checked that one on exploit-db, very less websites using this plugin. .


RE: MyBB SQLi Exploit 19-11-2013 - blacku33 - 11-24-2013

I checked that one on exploit-db, very less websites using this plugin. .