|
|
 |
 |
 |
 |
register |
bbs |
search |
rss |
faq |
about
|
 |
 |
meet up |
add to del.icio.us |
digg it
|
 |
 |
| Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net. |
 |
|
|
#1
 2006-02-18, 17:20
|
|
Moderator
|
|
Tokyo, 日本
|
|
IPB forums v1 and v2 hack
cense, consider this my initial contribution pledge. =) - UPDATE - New version: http://www.binswitch.net/downloads/ipbhack-2.0.zip Old version: http://www.binswitch.net/downloads/ipbhack.zip This .NET/Mono utility and code can be used to bypass login for any single user on an IPB 1.*.* and 2.*.* forum. It uses SQL injection in a forged cookie to retrieve the password hashes (MD5) one character at a time for a given user in the IPB MySQL database. It then spits out the complete cookie to send with your GET request to the forum. Has full support for proxies, too. Usage: code:
ipbhack [/proxy proxyaddress proxyport] parent_url user_id metaversion
Example: code:
ipbhack http://ipbsiteofsomekind.com/forums 1 2
The above command would generate a login cookie for the user with an ID of 1 on an IPB forum version 2.*.* Get the picture? The easiest way to use this is to install the Add N Edit Cookies Firefox Extension and pass the generated cookie along to the web server. Obviously, there are other ways of sending the cookie, but I find this to be the easiest. A description of the IPB database layout can be found here. AS WE SPEAK, I am updating my code to work with user NAMES instead of user IDs. (UPDATE: This feature is done.) NOTE: If you come up with all 0's for the password hash, you either typed in the wrong URL or the server doesn't have IPB forums. ANOTHER NOTE: To attempt to reverse your MD5 hash to the actual password, go to http://md5.crysm.net as it's the best one I've found online. [This message has been edited by Trueborn Vorpal (edited 02-18-2006).]
|
|
#2
 2006-02-18, 17:24
|
PyroHydroSmok 
Regular
|
|
|
|
Re: IPB forums v1 and v2 hack
Looks great True.
|
|
#3
 2006-02-18, 19:07
|
|
Moderator
|
|
Tokyo, 日本
|
|
Re: IPB forums v1 and v2 hack
New version uploaded. Now you can retrieve generate login cookies based on a username instead of a user ID. New usage: code:
ipbhack http://forumurl.com/forum /user username /ver <1 or 2, version 2 is assumed> ipbhack http://forumurl.com/forum /uid user_id
Have fun.
|
|
#4
 2006-02-18, 23:45
|
|
Moderator
|
|
Tokyo, 日本
|
|
Re: IPB forums v1 and v2 hack
FORGOT TO MENTION SOMETHING:
Once you get this cookie, set it and go to the URL contained in the source code. That is what will log you in under that user's credentials.
|
|
#5
 2006-02-19, 00:06
|
|
Moderator
|
|
Tokyo, 日本
|
|
Re: IPB forums v1 and v2 hack
ANOTHER UPDATE: Fixed a bug that ignored proxy specification.
|
|
#6
 2006-02-19, 04:31
|
DivineKaos 
Regular
|
|
|
|
Re: IPB forums v1 and v2 hack
This looks great True.
I am having a problem using it however, I am not sure how the firefox extension comes into play with this.
|
|
#7
 2006-02-19, 04:50
|
DivineKaos 
Regular
|
|
|
|
Re: IPB forums v1 and v2 hack
For instance, when I try running this, I try to keep it simple at first. I use my own forum to try it with. ipbhack http://forum.domain.net 1 2
It then proceeds to give me an error;
Unhandled Exception: System.UriFormatException: Invalid URI: The format of the U RI could not be determined. at System.Uri.CreateThis(String uri, Boolean dontEscape, UriKind uriKind) at System.Uri..ctor(String uriString) at IPBHack.modIPBHack.GetTextResponse(String& szReturnText, String szURL, Str ing szProxyURL, String CookieHeader) at IPBHack.modIPBHack.Main(String[] args)
Any idea what the problem is?
|
|
#8
 2006-02-19, 04:58
|
|
Moderator
|
|
Tokyo, 日本
|
|
Re: IPB forums v1 and v2 hack
quote: Originally posted by DivineKaos: For instance, when I try running this, I try to keep it simple at first. I use my own forum to try it with. ipbhack http://forum.domain.net 1 2
It then proceeds to give me an error;
Unhandled Exception: System.UriFormatException: Invalid URI: The format of the U RI could not be determined. at System.Uri.CreateThis(String uri, Boolean dontEscape, UriKind uriKind) at System.Uri..ctor(String uriString) at IPBHack.modIPBHack.GetTextResponse(String& szReturnText, String szURL, Str ing szProxyURL, String CookieHeader) at IPBHack.modIPBHack.Main(String[] args)
Any idea what the problem is?
Which version are you running? That's 1.0 usage. 2.0 is quite a bit different.
|
|
#9
 2006-02-19, 07:07
|
DivineKaos 
Regular
|
|
|
|
Re: IPB forums v1 and v2 hack
The forum I am running is version 2.
If you would like, I can give you my email address and we can play with it on my forum.
|
|
#10
 2006-02-19, 18:19
|
|
Moderator
|
|
Tokyo, 日本
|
|
Re: IPB forums v1 and v2 hack
quote: Originally posted by DivineKaos: The forum I am running is version 2.
If you would like, I can give you my email address and we can play with it on my forum.
Well, sure. Whatever works. But I meant to ask which version of ipbhack you downloaded.
|
|
#11
 2006-02-20, 03:57
|
DivineKaos 
Regular
|
|
|
|
Re: IPB forums v1 and v2 hack
I had downloaded the new version.
|
|
#12
 2006-02-20, 05:43
|
|
Moderator
|
|
Tokyo, 日本
|
|
Re: IPB forums v1 and v2 hack
quote: Originally posted by DivineKaos: I had downloaded the new version.
Yeah. You gotta use the second usage method I posted.
|
|
#13
 2006-03-19, 14:50
|
Squasher 
Regular
|
|
|
|
Re: IPB forums v1 and v2 hack
quote: NOTE: If you come up with all 0's for the password hash, you either typed in the wrong URL or the server doesn't have IPB forums.
I type correct url of my IPB 1.3.1 final ma I get all 0's for my password hash!!! I used last versione with new command! Why don't work? Thank you a lot!
|
|
 |
 |
To the best of our knowledge, the text on this page may be freely reproduced and distributed.

totse.com certificate signatures
|
 |
 |
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
|
 |
 |
 |
 |
|
|