Sinisterly
MyBB 1.6.2 Sql Injection - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: MyBB 1.6.2 Sql Injection (/Thread-MyBB-1-6-2-Sql-Injection)



MyBB 1.6.2 Sql Injection - *The ALLSTAR* - 05-05-2011

Find a forum that is powered by MyBB 1.6.2 using the dork I provided.

On most forums, you will need to register to use the search function. After you are there, enter this in the textbox:

' or ' or 1337'

Now hit Enter and you will see an error: You have an error in your SQL Syntax.

Now you can perform a SQL Injection Attack. This is nothing for newbies, so please do not ask how to inject it then. MyBB 1.6.1 is vulnerable also!




RE: MyBB 1.6.2 Sql Injection - H3ROiN - 05-05-2011

where's the dock , lmao ?


RE: MyBB 1.6.2 Sql Injection - *The ALLSTAR* - 05-05-2011

Do you mean dock as document then search as google "MyBB 1.6.2 Sql Injection" or simply find a site that using MyBB v1.6.2 then register on that site, in search box copy paste the code. It also depends on the mysql database version as far as I heard.

Just search google I bet you will get more information about this sql injection.



RE: MyBB 1.6.2 Sql Injection - 9toes - 05-28-2011

Leecher detected ...
this is from www.leethackers.org from Envy .
the original topic :
Code:
--------------------------------------------------------------------------------------------------- # Author: Envy # Website: www.leethackers.org/board/ # Shouts: www.HackHound.org # This is an MyBB 1.6.2 SQL Injection Exploit. The search.php is affected. The SQLi can be performed and the username + password of admins and users stolen. # Google Dork: intext:Powered by MyBB 1.6.2 --------------------------------------------------------------------------------------------------- Proof of Concept: Find a forum that is powered by MyBB 1.6.2 using the dork I provided. On most forums, you will need to register to use the search function. After you are there, enter this in the textbox: ' or ' or 1337' Now hit Enter and you will see an error: You have an error in your SQL Syntax. Now you can perform a SQL Injection Attack. This is nothing for newbies, so please do not ask how to inject it then. MyBB 1.6.1 is vulnerable also! # www.leethackers.org

@H3ROiN :may be you mean : dork ? , if it's the cas , as you can see we want to find "Powered by MyBB 1.6.2" in the text of a website , so we add the prefix "intext" , the final result is : intextTongueowered by MyBB 1.6.2
So here how you can make a dork in the future .

,9toes .


RE: MyBB 1.6.2 Sql Injection - l0c41H0st - 06-22-2011

can anyone make it more clear?