![]() |
|
[TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) (/Thread-TUTORIAL-Finding-SQLi-0day-s-in-MyBB-plugins-and-others) |
[TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - superMAUS - 05-05-2014 Finding SQLi 0days in MyBB Plugins Requirements: A Text Editor (I really recommend http://www.sublimetext.com/) Here are some 0day's I found back in the days when I walzted around with the stupid name Red_Hat spurting rubbish: Spoiler:Oh and this is what a good day looks like: Spoiler:![]() 0x01. But lets move on to the fun stuff. First off we need to download a plugin for testing. Head over to http://mods.mybb.com/mods and pick one of your choice. Dont just choose a random one think about whether or not it would use a database (as this particular tutorial is based around SQLi). Spoiler:![]() 0x02. After downloading, navigate to "\Plugin\inc\plugins" and open the PHP file within. After doing so make a search for "$db", "input", "GET" and "POST" through all the files. If nothing comes up choose another plugin and repeat the process. You may find that this process takes a while. Spoiler:![]() 0x03. Now lets take a look at all the variables extracted from the input, GET and POST that are mentioned and see if they sanitized at all. Here's what a sanitized variable looks like: ![]() If you see anything such as $db->escape_string or intval() these are signs of sanitation. 0x04. You can also apply this method to WordPress if you ewplace every time Ive mentioned $mybb->input with $_GET and $_POST. Profit. If you are unsure about anything in this tutorial please send me a PM and I will aid you in your struggles. Just like to add that I found a persistent XSS vulnerability and an SQL injection vulnerability whilst doing this so if you are curios as to how hard this is dont worry. RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - Dyme - 05-05-2014 Lol red hat hahahhahahahahaahaha mov ebx hahahhaha RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - misnar - 05-05-2014 oh my were you the red_hat on HF who made that hilarious tutorial on 'writing shellcode'? RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - superMAUS - 05-05-2014 Yas, but I like to think I have improved. Have you seen my pentesting tutorial though :3 "Ok, so lets scan all the ports, ah look 80 is open! We can attack from there" RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - Adorapuff - 05-05-2014 It seems that creating an array allows you to bypass escape_string protection. RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - Alan Turing - 05-06-2014 I got lost at pushing IRET onto the TCP stack. RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - superMAUS - 05-06-2014 (05-05-2014, 11:28 PM)Adorapuff Wrote: It seems that creating an array allows you to bypass escape_string protection. Really? Im interested in this method, I really doubt it works though. RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - Reiko - 05-06-2014 http://community.mybb.com/search.php?action=results&sid[0]=9afaea732cb32f06fa34b1888bd237e2&sortby=&order= he's talking about this dumb shit, and he's wrong. This is not SQL injection. Sorry. RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - superMAUS - 05-06-2014 (05-06-2014, 09:09 AM)Reiko Wrote: http://community.mybb.com/search.php?action=results&sid[0]=9afaea732cb32f06fa34b1888bd237e2&sortby=&order= Who, what? sorry? huh! Hope this isnt aimed at me. (Think its Adora dough, cos theres an array) |