MyBB Community Forums

Full Version: Mybb 1.6.6 0 Day Password change Vulnerablity
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Hello Mybb,

My Forum was Hacked somedays ago by a hacker they somehow managed to change the password but they werent not able to find the admin panel since i changed it i logged their actions on admin cp Honey pot plugin i have a proof that they changed the password

Can someone Help me out?

FOrum link :<snip - hacking>

it is growing out this attack
Very unlikely this is core 0-day MyBB vuln. My guess is that you have a RAT on your system.

(2012-03-17, 05:31 PM)labrocca Wrote: [ -> ]Very unlikely this is core 0-day MyBB vuln. My guess is that you have a RAT on your system.

If they ratted him, they would have known the admin directory. My guess is that he did not have a RAT on his system, maybe other type of malware, such as a stealer or keylogger.
im not sure if this might help but one way to avoid keylog is to use on screen keyboard.
http://zone-h.org/mirror/id/16874017
Was your forum hacked after this hack ?
Hi,

The MyBB group offers support under the conditions of our Support Eligibility policy. It is apparent that one or more of your forums do not meet the conditions of our policy and therefore you are ineligible for support. This could be because of adult, piracy or hacking related content or because your forum does not display the minimum “Powered by MyBB” notice.

If you have any questions regarding this policy please post in the Private Inquiries forum.

Regards,
The MyBB group.