 |
|
 |
 |
Menu |
 |
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
 |
User Info |
 |
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 109
Members: 0
Total: 109
|
|
|
|
|
 |
Full disclosure |
 |
CyberDanube Security Research 20251014-0 | Multiple Vulnerabilities in Phoenix Contact QUINT4 UPS
apis.google.com - Insecure redirect via __lu parameter(exploited in the wild)
Urgent Security Vulnerabilities Discovered in Mercku Routers Model M6a
Re: Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
[SBA-ADV-20250730-01] CVE-2025-39664: Checkmk Path Traversal
[SBA-ADV-20250724-01] CVE-2025-32919: Checkmk Agent Privilege Escalation via Insecure Temporary Files
CVE-2025-59397 - Open Web Analytics SQL Injection
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Re: Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Re: Defense in depth -- the Microsoft way (part 93): SRP/SAFERwhitelisting goes black on Windows 11
Re: [FD]: "Glass Cage" – Zero-Click iMessage ? Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885)
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Samtools v1.22.1 Uncontrolled Memory Allocation from Large BED Intervals Causes Denial-of-Service in Samtools/HTSlib
Samtools v1.22.1 Improper Handling of Excessive Histogram Bin Counts in Samtools Coverage Leads to Stack Overflow
|
|
|
|
|
|
 |
|
 |
 |
|
 |
IT Security and Insecurity Portal |
|
 |
[PHP] vBulletin & IbProArcade Exploit needs Automation |
 |
Posted: Sun Nov 23, 2008 5:33 am |
|
|
tehhunter |
Valuable expert |

 |
|
Joined: Nov 19, 2008 |
Posts: 261 |
|
|
|
 |
 |
 |
|
Hey all,
So I recently stumbled across and have been exploiting IbProArcade through some various means. Basically, my exploit involves retrieving passwords + salts from the database through blind sql injection and parsing through many pages at a time to get a single char of the password/salt.
Anyway, I know for a fact this is implementable in coding, and I would try it in Java (my language of choice), but unfortunately java does not handle sessions/cookies that well. So I am left with the mind-bending task of manually submitting about 150 queries per every password + hash I want to pull out of a forum. Not fun, but hey, I got some good results out of it. I would like to add that I can vouch for the exploit's working-ness and I have myself and some have here recovered the passwords from the salts/hashes.
One important note: to fufill the requirements of this project, you would have to know how to handle cookies and sessions in PHP (I don't know exactly how hard that is) while logging into vBulletin forum, as you must be auth'd as a user to harness this exploit.
So if you are interested in working on a PHP CLI script with me, I would be happy to inform you of the details and exactly how the code would work (I have the pseudo code worked out in my head). I would love to collab with someone who knows what they are doing and enjoys getting results.
@Waraxe: I would love to work on this with you, given your history, if you have the time and willpower that is
Happy hacking,
tehhunter |
|
|
|
|
 |
 |
|
 |
Posted: Sun Nov 23, 2008 8:42 pm |
|
|
_mranderson_ |
Valuable expert |

 |
|
Joined: Oct 30, 2008 |
Posts: 51 |
|
|
|
 |
 |
 |
|
to login in a vbulletin forum isn't hard in php-cli, you can even have a look at published exploits for vbulletin, and you will find the code you need to execute the login. handling cookie in php-cli is easy then. |
|
|
|
|
www.waraxe.us Forum Index -> Cooperation proposals
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|