Create an account

Very important

  • To access the important data of the forums, you must be active in each forum and especially in the leaks and database leaks section, send data and after sending the data and activity, data and important content will be opened and visible for you.
  • You will only see chat messages from people who are at or below your level.
  • More than 500,000 database leaks and millions of account leaks are waiting for you, so access and view with more activity.
  • Many important data are inactive and inaccessible for you, so open them with activity. (This will be done automatically)


Thread Rating:
  • 201 Vote(s) - 3.64 Average
  • 1
  • 2
  • 3
  • 4
  • 5
VBulletin Forum Backup Exploit [Hack Forum Database And Deface]

#1
Enjoy The Exploit Guys !

NOTE : I m not the author of this exploit .. I m just sharing with ABH users


Quote:# Exploit Title: Vbulletin Forum Backup Exploit
# Google Dork: allinurl:forumbackup
allinurl:forumbackup.sql
# Date: 14/9/2012
# Exploit Author: BeNji
# Vendor Homepage:

[To see links please register here]

Software Link:

[To see links please register here]

# Version: All Versions
# Tested on:

[To see links please register here]

# CVE : [if one exists, or other VDB reference]

This is a simple vbulletin forum exploit !

With the help of this vulnerability you can hack database of vbulletin forums

Here is the instruction for exploit :

1- Go the google.com and search for this dork

DoRKS :

allinurl:forumbackup
allinurl:forumbackup.sql

2- Find the vulnerability links which looks like :

/wppublic/forumbackup/

/forum/Forumbackup/

/forums/Forumbackup/

/main/Forumbackup/

3 - Here Is the example URL for your demo :

[To see links please register here]


4 - Open The Database And Check for 1st User Name and Pas

5 - Get The user name and crack the hash ! Thats All

Now to go the forum and login with Admin user name and password and deface the forum !
Credits :
BitsHacking Team
Reply

#2
wow noce...thanks for shareing with us
Reply

#3
Once these 0days get released either one, everyone on the planet has owned all the servers vulnerable to it on the first day or the finder of the 0day already took all the work into his own hands and exploited as many servers as he could before releasing it.
Reply

#4
You can still find some vulnerable sites with this.
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

©0Day  2016 - 2023 | All Rights Reserved.  Made with    for the community. Connected through