Sinisterly
[TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.li/Forum-Tutorials)
+--- Thread: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) (/Thread-TUTORIAL-Finding-SQLi-0day-s-in-MyBB-plugins-and-others)



[TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - superMAUS - 05-05-2014

Finding SQLi 0days in MyBB Plugins


Requirements:
A Text Editor (I really recommend http://www.sublimetext.com/)

Here are some 0day's I found back in the days when I walzted around with the stupid name Red_Hat spurting rubbish:

Spoiler:


Oh and this is what a good day looks like:
Spoiler:
[Image: QxOfcYn.png]


0x01.

But lets move on to the fun stuff. First off we need to download a plugin for testing. Head over to http://mods.mybb.com/mods and pick one of your choice.

Dont just choose a random one think about whether or not it would use a database (as this particular tutorial is based around SQLi).

Spoiler:
[Image: R6KcLQ3.png?2?1658]


0x02.
After downloading, navigate to "\Plugin\inc\plugins" and open the PHP file within. After doing so make a search for "$db", "input", "GET" and "POST" through all the files. If nothing comes up choose another plugin and repeat the process. You may find that this process takes a while.

Spoiler:

[Image: Ikne63B.png?1]



0x03.
Now lets take a look at all the variables extracted from the input, GET and POST that are mentioned and see if they sanitized at all.

Here's what a sanitized variable looks like: [Image: hinXckY.png]
If you see anything such as $db->escape_string or intval() these are signs of sanitation.

0x04.
You can also apply this method to WordPress if you ewplace every time Ive mentioned $mybb->input with $_GET and $_POST.

Profit.
If you are unsure about anything in this tutorial please send me a PM and I will aid you in your struggles. Just like to add that I found a persistent XSS vulnerability and an SQL injection vulnerability whilst doing this so if you are curios as to how hard this is dont worry.


RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - Dyme - 05-05-2014

Lol red hat hahahhahahahahaahaha mov ebx hahahhaha


RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - misnar - 05-05-2014

oh my

were you the red_hat on HF who made that hilarious tutorial on 'writing shellcode'?


RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - superMAUS - 05-05-2014

Yas, but I like to think I have improved.

Have you seen my pentesting tutorial though :3

"Ok, so lets scan all the ports, ah look 80 is open! We can attack from there"


RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - Adorapuff - 05-05-2014

It seems that creating an array allows you to bypass escape_string protection.


RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - Alan Turing - 05-06-2014

I got lost at pushing IRET onto the TCP stack.


RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - superMAUS - 05-06-2014

(05-05-2014, 11:28 PM)Adorapuff Wrote: It seems that creating an array allows you to bypass escape_string protection.

Really? Im interested in this method, I really doubt it works though.


RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - Reiko - 05-06-2014

http://community.mybb.com/search.php?action=results&sid[0]=9afaea732cb32f06fa34b1888bd237e2&sortby=&order=
he's talking about this dumb shit, and he's wrong. This is not SQL injection. Sorry.


RE: [TUTORIAL] Finding SQLi 0day's in MyBB plugins (and others) - superMAUS - 05-06-2014

(05-06-2014, 09:09 AM)Reiko Wrote: http://community.mybb.com/search.php?action=results&sid[0]=9afaea732cb32f06fa34b1888bd237e2&sortby=&order=
he's talking about this dumb shit, and he's wrong. This is not SQL injection. Sorry.

Who, what? sorry? huh!

Hope this isnt aimed at me. (Think its Adora dough, cos theres an array)