|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 49
Members: 0
Total: 49
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
[PHP] vBulletin & IbProArcade Exploit needs Automation |
|
Posted: Sun Nov 23, 2008 5:33 am |
|
|
tehhunter |
Valuable expert |
|
|
Joined: Nov 19, 2008 |
Posts: 261 |
|
|
|
|
|
|
|
Hey all,
So I recently stumbled across and have been exploiting IbProArcade through some various means. Basically, my exploit involves retrieving passwords + salts from the database through blind sql injection and parsing through many pages at a time to get a single char of the password/salt.
Anyway, I know for a fact this is implementable in coding, and I would try it in Java (my language of choice), but unfortunately java does not handle sessions/cookies that well. So I am left with the mind-bending task of manually submitting about 150 queries per every password + hash I want to pull out of a forum. Not fun, but hey, I got some good results out of it. I would like to add that I can vouch for the exploit's working-ness and I have myself and some have here recovered the passwords from the salts/hashes.
One important note: to fufill the requirements of this project, you would have to know how to handle cookies and sessions in PHP (I don't know exactly how hard that is) while logging into vBulletin forum, as you must be auth'd as a user to harness this exploit.
So if you are interested in working on a PHP CLI script with me, I would be happy to inform you of the details and exactly how the code would work (I have the pseudo code worked out in my head). I would love to collab with someone who knows what they are doing and enjoys getting results.
@Waraxe: I would love to work on this with you, given your history, if you have the time and willpower that is
Happy hacking,
tehhunter |
|
|
|
|
|
|
|
|
Posted: Sun Nov 23, 2008 8:42 pm |
|
|
_mranderson_ |
Valuable expert |
|
|
Joined: Oct 30, 2008 |
Posts: 51 |
|
|
|
|
|
|
|
to login in a vbulletin forum isn't hard in php-cli, you can even have a look at published exploits for vbulletin, and you will find the code you need to execute the login. handling cookie in php-cli is easy then. |
|
|
|
|
www.waraxe.us Forum Index -> Cooperation proposals
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|