MyBB Community Forums

Full Version: I found a "How to hack" MyBB 1.1.3 guide
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
I wasn't sure quite where to post this, but it needed to be seen nevertheless. A mod can move it if this is not in a good place.

After my board was "hacked" by someone, a website was left on the 'this page was hacked' page. I went to the website using Google's Arabic translator, and I found an article entitled " MyBB < = 1.1.3 Create An Admin Exploit" Here's the link to it, 'already translated' (Google has a very bad Arabic translatorSmile
http://64.233.179.104/translate_c?hl=en&...6sid%3D183

It looks like you have to download it, which I have not. This may be the key to figuring out how to stop these "hacks." Just because this guide is for 1.1.3 doesn't mean that it doesn't work in later versions. Perhaps this article was created when 1.1.3 was the latest version.

I hope this helps. And, if someone can help translate better, it might help, too.
This was an exploit in 1.1.3, this does not work on later versions of MyBB.
1.1.4 fixed that security flaw.
Alright. I'm glad it's fixed then.
It is not Arabic!
<SCRIPT src="includes/persian/farsi.js" type=text/javascript></SCRIPT>

Yes! it is farsi.(persian)

btw you can visit its original advisory in:
http://myimei.com/security/2006-06-21/my...ccess.html

I anounce Chris and he realease patch before that bug published. I proffer you to join to mailing list to get latest anouncements .
bests.
imei
Nevertheless version 1.1.5 is out which is .2 versions above version 1.1.3, so be sure to make sure you always have the latest version of MyBB installed on your server.