![]() |
|
MyBB 1.6.2 Sql Injection - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: MyBB 1.6.2 Sql Injection (/Thread-MyBB-1-6-2-Sql-Injection) |
MyBB 1.6.2 Sql Injection - *The ALLSTAR* - 05-05-2011 Find a forum that is powered by MyBB 1.6.2 using the dork I provided. On most forums, you will need to register to use the search function. After you are there, enter this in the textbox: ' or ' or 1337' Now hit Enter and you will see an error: You have an error in your SQL Syntax. Now you can perform a SQL Injection Attack. This is nothing for newbies, so please do not ask how to inject it then. MyBB 1.6.1 is vulnerable also! RE: MyBB 1.6.2 Sql Injection - H3ROiN - 05-05-2011 where's the dock , lmao ? RE: MyBB 1.6.2 Sql Injection - *The ALLSTAR* - 05-05-2011 Do you mean dock as document then search as google "MyBB 1.6.2 Sql Injection" or simply find a site that using MyBB v1.6.2 then register on that site, in search box copy paste the code. It also depends on the mysql database version as far as I heard. Just search google I bet you will get more information about this sql injection. RE: MyBB 1.6.2 Sql Injection - 9toes - 05-28-2011 Leecher detected ... this is from www.leethackers.org from Envy . the original topic : Code: ---------------------------------------------------------------------------------------------------
# Author: Envy
# Website: www.leethackers.org/board/
# Shouts: www.HackHound.org
# This is an MyBB 1.6.2 SQL Injection Exploit. The search.php is affected. The SQLi can be performed
and the username + password of admins and users stolen.
# Google Dork: intext:Powered by MyBB 1.6.2
---------------------------------------------------------------------------------------------------
Proof of Concept:
Find a forum that is powered by MyBB 1.6.2 using the dork I provided.
On most forums, you will need to register to use the search function. After you are there, enter this in the textbox:
' or ' or 1337'
Now hit Enter and you will see an error: You have an error in your SQL Syntax.
Now you can perform a SQL Injection Attack. This is nothing for newbies, so please do not ask how to inject it then. MyBB 1.6.1 is vulnerable also!
# www.leethackers.org@H3ROiN :may be you mean : dork ? , if it's the cas , as you can see we want to find "Powered by MyBB 1.6.2" in the text of a website , so we add the prefix "intext" , the final result is : intext owered by MyBB 1.6.2So here how you can make a dork in the future . ,9toes . RE: MyBB 1.6.2 Sql Injection - l0c41H0st - 06-22-2011 can anyone make it more clear? |