Login Register






The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thread Rating:
  • 0 Vote(s) - 0 Average


Using MyBB SQL Injection filter_list
Author
Message
Using MyBB SQL Injection #1
I've seen a lot of tutorials on another forum for example on how to use an SQL injection to hack a forum, but they don't make sense to me. Can anyone please clarify?
(This post was last modified: 09-02-2012, 07:23 PM by Dismas.)
[Image: logo.png]

Reply

RE: Using MyBB SQL Injection #2
Are you specifically wanting to SQL inject a forum or any website in general?

Reply

RE: Using MyBB SQL Injection #3
(09-03-2012, 03:01 AM)Hardz Wrote: Are you specifically wanting to SQL inject a forum or any website in general?

MyBB is a forum software. It's also the one we're using, haha.
The development team tends to stay on top of vulnerabilities and bugs, but you could look at plugins.
[Image: fSEZXPs.png]

Reply

RE: Using MyBB SQL Injection #4
Oh - I didn't see that bit in the title, my bad :p

Reply

RE: Using MyBB SQL Injection #5
MyBB had a plugin (award system) if I'm not mistaken that was vulnerable a while back...best bet is plugins, look for weaknesses in them.
[Image: V8OSA.gif]

Reply

RE: Using MyBB SQL Injection #6
As far as i know, there is no open MyBB injections. It's pretty secure, they're always on top of all vulnerabilities. There will be plenty of plugins though that you could try and inject.

Reply

RE: Using MyBB SQL Injection #7
Found this site for you: http://www.securiteam.com/products/M/MyBB.html

Most probably out-dated but worth a little look-over.

Reply

RE: Using MyBB SQL Injection #8
(09-11-2012, 07:52 PM)Hardz Wrote: Found this site for you: http://www.securiteam.com/products/M/MyBB.html

Most probably out-dated but worth a little look-over.

Nice information, all you need to do is find a site with that information and then abuse it.
[Image: V8OSA.gif]

Reply

RE: Using MyBB SQL Injection #9
(09-11-2012, 08:48 PM)BaneKitty Wrote:
(09-11-2012, 07:52 PM)Hardz Wrote: Found this site for you: http://www.securiteam.com/products/M/MyBB.html

Most probably out-dated but worth a little look-over.

Nice information, all you need to do is find a site with that information and then abuse it.

Ahaha - exactly.

Reply

RE: Using MyBB SQL Injection #10
Find a vulnerability and exploit it. The software itself isn't vulnerable as
of yet so it's your best option. Look around for new releases in the exp
database and you will be sure to find something. You could always try
and scan their ports too to see if there's anything vulnerable running.

Reply







Users browsing this thread: 1 Guest(s)