Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Mambo - can you bypass login page

Posted on 2009-05-06
2
Medium Priority
?
363 Views
Last Modified: 2013-11-10
I am trying to update a website created in mambo but the admin & user passwords dont work, not sure if thay are correct.
Is there any way I can bypass the login screen, I have access to the database and have also downloaded all files of the website.
I have never used Mambo before, can I bypass the login page or manually create new usernames & passwords directly into the users table?
0
Comment
Question by:sabecs
2 Comments
 
LVL 34

Accepted Solution

by:
Beverley Portlock earned 2000 total points
ID: 24315129
IIRC the Mambo password is just an MD5 password. Try this

insert into _users ( username, password, userType ) values( 'Administrator', MD5('somepassword'), 'Super Administrator')

replacing _users with the actual table name and change the username from "Administrator" to something else if the user table already contains it. Check the _usertypes table contains data as well. Usertype "Super Administrator" should be in there.

It's been a while since I've used Mambo.... I found it too insecure and frequently attacked.
0
 

Author Closing Comment

by:sabecs
ID: 31578461
Thanks...
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this blog, I will share you some basic tips for content marketing and to rank your website on Google.
FAQ pages provide a simple way for you to supply and for customers to find answers to the most common questions about your company. Here are six reasons why your company website should have a FAQ page
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…
The viewer will learn how to look for a specific file type in a local or remote server directory using PHP.
Suggested Courses

782 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question