RE: Security Breach 12-31-2014, 03:59 AM
#17
(12-31-2014, 01:36 AM)phyrrus9 Wrote: A backup from 12/26 was restored, so anything made after that is now nonexistent. It does not look as though any breach was done via the hosting company as the injection vector was identified to be the ACP. How they got in there, we don't yet know.
Yeah, the MyBB ACP has a ton of vulnerabilities, and the coders are too lazy to fix them.
Oni, shouldn't it still display in the logs which user accessed the ACP to plant the shell? It could give us a clue to whether any staff/admin accounts were compromised. if no user is shown, then it is possible there is a 0day outside of the ACP that allowed the attacker to gain access to it and plant the shell using a second vulnerability in the ACP itself.
Also, if you guys think there is a unpublished vulnerability, let me know so I can dig through the MyBB source and try and find it.
Anyways, I hope to be more active on Sinisterly. Oni runs a great forum.
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)