vBulletin Modifications

vBSHOUT 2.1 Vulnerability!!

Welcome to vBHackers.com! - vBHackers Updates:

Go Back   vBulletin Modifications > General vBulletin Section > General vBulletin Support

Reply
 
LinkBack Thread Tools
Old 05-20-2007, 10:10 AM   #1
vB Newbie
Join Date: Nov 2006
Red Flag is on a distinguished road

Default vBSHOUT 2.1 Vulnerability!!

Quote:
So yesterday some unregistered wrote in my shoutbox that he'll take my site down, first, i didnt know how his shouting and second i said him to go **** himself.

5 Min after i couldn't log on, my nick was changed, all mods and admins deleted, no access to site anymore. So i had to suspend my account (hosting) and restore backup.

How he did that.


In vbshout folder sb which is chmoded to 777 he puts some script, with that script he browset to my config.php file, saw db name, username and password, with same script logged to mysql, downloaded tables which contains my password in md5 hash, with same script converted md5 to plain text and finaly logged to my admin acc on forum, you know the rest.

I dont't know if i can do this, so please admins or mods delete this if you think it's not right.

I have installed one forum to my localhost and its accessible from internet, also i have putt there that hackers script so if anybody wants to test it please pm me so i dont put link here. I hope this isn't spamm because link doesnt take to my website, it takes to test forum which is empty, i hope you'll find this helpfull
Quote:
I'll test it out...
It's most likely a C99 shell.

PM me the link, and I'll check it out and see how he broke in.


EDIT: I have not seen a C99 shell of this caliber before... this if off the scale.



Format Box
Bypass PHP Safe Mode
Kernel Attack Built-in
View Open Ports
View Logged in Users
View Files such as /etc/passwd

Boy.. this is a hilarious new amount of features...
Yeah, this program can get into your FTP and AdminCP, all from vBshout 2.1




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 05-21-2007, 09:49 AM   #2
vBulletin Guru
Nick R's Avatar
Join Date: May 2006
Real Name: Nick
Location: Cyberspace, UK
Nick R is on a distinguished road

Default

It's impossible to "un-md5" a hash so to speak. On the other hand you can build a hash pretty easily and enter it into the db if you have ftp access.

The main issue your pointing out is being able to inject code into the shoutbox which can then do anything; upload files, run queries, erase the hard drive.

I'll check with zero tolerance about this tonight.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-21-2007, 04:16 PM   #3
vB Newbie
Join Date: Dec 2006
rishabh_sood_best is on a distinguished road

Default

This Is Possible Due to RFI! you Must be having any vuln.. file on you ftp which he used to reach you config.php




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-24-2007, 06:10 PM   #4
vB Newbie
Join Date: Nov 2006
Red Flag is on a distinguished road

Default

What should I CHMOD my files too? 755?




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-25-2007, 01:17 PM   #5
Junior Member
Join Date: Jun 2005
sodhi is on a distinguished road

Default

CHMODing it to 744 should do the trick I assume. I haven't looked into the issue, however..




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-30-2007, 06:50 AM   #6
vB Newbie
Join Date: Mar 2007
conexn is on a distinguished road

Default

Can you put show me the code that allows him to do this? I am trying to learn a bit about this mess so I can prevent it from happening again. I was also running this and lastnight I had a guest in a admin section only, I had even un-installed the program but I guess it left something behind and would also like some help on how to get it completely out.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-30-2007, 08:48 PM   #7
Coder
B34ST's Avatar
Join Date: Feb 2005
B34ST is on a distinguished road

Default

Quote:
Originally Posted by Nick R View Post
It's impossible to "un-md5" a hash so to speak.
You'd better not be to sure about that. I dont know myself how to decrypt a md5 + salt pass (yes you need the salt too ), though I know 2 different people that hack complete user databases (usernames & passwords) in a time of 10-20 minutes. Just for your information.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-03-2007, 10:34 AM   #8
vB Newbie
Join Date: Jun 2007
pokemon is on a distinguished road

Default

does anyone has solved the problem was occured? I have the same problem..hacker defaced our website by using shell to read config.php. They captured our admin user and password very easy... Pleae share your information how to prevent this from happening. Thanks in advanced




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
vBshout 2.1 question Balla General vBulletin Support 17 09-16-2007 01:18 PM
Disable AJAX on vBShout 2.1 Unforgiv3N General vBulletin Support 0 04-12-2007 09:07 AM
VBshout 2.1 not working on Firefox friscogal General vBulletin Discussion 14 12-04-2006 01:50 PM


All times are GMT -3. The time now is 09:11 PM.


SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc. (Patent Pending)