#12 Login does not work

Version 2.x
wont-fix
None
5
2015-12-11
2014-01-22
zdo
No

Using version 2.6.8 on metasploitable-2. Login into an existing account doesn't work. Register a new account will write that account into database but login doesn't work as well.

1 Attachments

Related

Bugs: #12

Discussion

  • Jeremy Druin

    Jeremy Druin - 2014-01-22

    Hello zdo,

    What user name and password did you use to create the account which cannot
    login please? I would like to recreate the account locally.

    Regards,

    Jeremy

    On Wed, Jan 22, 2014 at 8:05 AM, zdo zoido@users.sf.net wrote:


    Status: open
    Created: Wed Jan 22, 2014 01:05 PM UTC by zdo
    Last Updated: Wed Jan 22, 2014 01:05 PM UTC
    Owner: nobody

    Using version 2.6.8 on metasploitable-2. Login into an existing account
    doesn't work. Register a new account will write that account into database
    but login doesn't work as well.


    Sent from sourceforge.net because you indicated interest in
    https://sourceforge.net/p/mutillidae/bugs/12/

    To unsubscribe from further messages, please visit
    https://sourceforge.net/auth/subscriptions/

     

    Related

    Bugs: #12

  • zdo

    zdo - 2014-01-23

    Hi Jeremy,

    i tried several user names (new one zoido), even the ones that are preregistered (ed, john, adrian, admin) and I always get that error.

    I updated Mutillidae to 2.6.8 on Metasploitable-2 by downloading the ZIP, removing the old Mutillidae folder from /var/www/ and insert the new one. Then updated the database name in MySQLHandler.php to the old database on Metasploitable-2 (owasp10). This is when I got that error. After that I tried to fix that Error by using a new Database, the one that Mutillidae will install itself (nowasp) and removed the old owasp10 from the MySQLServer on Metasploitable-2. Still no user login possible with any account.

    Metasploitable-2 runs in VirtualBox 4.3.6 on a Host-only Ethernet. The MySQL Version on Metasploitable-2 is the preinstalled 14.12 Distrib 5.0.51a.

    Thanks,

    zdo

     
    • Jeremy Druin

      Jeremy Druin - 2014-01-23

      Ok. I probably can't reproduce the error so I'll review the code to see if
      I see anything.
      On Jan 23, 2014 2:46 AM, "zdo" zoido@users.sf.net wrote:

      Hi Jeremy,

      i tried several user names (new one zoido), even the ones that are
      preregistered (ed, john, adrian, admin) and I always get that error.

      I updated Mutillidae to 2.6.8 on Metasploitable-2 by downloading the ZIP,
      removing the old Mutillidae folder from /var/www/ and insert the new one.
      Then updated the database name in MySQLHandler.php to the old database on
      Metasploitable-2 (owasp10). This is when I got that error. After that I
      tried to fix that Error by using a new Database, the one that Mutillidae
      will install itself (nowasp) and removed the old owasp10 from the
      MySQLServer on Metasploitable-2. Still no user login possible with any
      account.

      Metasploitable-2 runs in VirtualBox 4.3.6 on a Host-only Ethernet. The
      MySQL Version on Metasploitable-2 is the preinstalled 14.12 Distrib 5.0.51a.

      Thanks,

      zdo

      Status: open
      Created: Wed Jan 22, 2014 01:05 PM UTC by zdo
      Last Updated: Wed Jan 22, 2014 01:05 PM UTC
      Owner: nobody

      Using version 2.6.8 on metasploitable-2. Login into an existing account
      doesn't work. Register a new account will write that account into database
      but login doesn't work as well.


      Sent from sourceforge.net because you indicated interest in
      https://sourceforge.net/p/mutillidae/bugs/12/

      To unsubscribe from further messages, please visit
      https://sourceforge.net/auth/subscriptions/

       

      Related

      Bugs: #12

  • Matt Spencer

    Matt Spencer - 2014-04-06

    I am running metasploitable 2 and upgraded mutillidae from the 2.1.19 version that comes preloaded to version 2.6.10. After the update I started having this same problem. I can see that the usernames are created in the db but login will not find any users including ones already in the db.This appears to be happening after changes in 2.6.3.5 (commit 50eaf9d). This was the rewrite of login process.

     
    Last edit: Matt Spencer 2014-04-07
  • Chris Weaver

    Chris Weaver - 2015-04-20

    ok I have this same Problem, however I have the error code, I am using the newest download:

    Line: 126
    Code: 0
    File: /var/www/user-info.php
    Message: Error executing query:"Table 'metasloit.accounts' doesn't exist"
    Trace: #0 /var/www/mutillidae/index.php(469):include() #1 {main}
    Diagnostic
    Information: SELECT * FROM accounts WHERE username='admin' AND passowrd='admin'

                      Did you setup/reset the DB?
    

    I get this error from registering/logging in etc
    I re-downloaded the Image rebuilt my VM & still
    got this error.

     
    • Jeremy Druin

      Jeremy Druin - 2015-04-20

      Make sense now. There is no table metasploit.accounts. the table is
      nowasp.accounts. I'm wondering why the query is going there. I see what's
      wrong though. I might be able to force the query to the correct table.
      On Apr 20, 2015 12:46 AM, "Chris Weaver" chrisweaver@users.sf.net wrote:

      ok I have this same Problem, however I have the error code, I am using the
      newest download:

      Line: 126
      Code: 0
      File: /var/www/user-info.php
      Message: Error executing query:"Table 'metasloit.accounts' doesn't exist"
      Trace: #0 /var/www/mutillidae/index.php(469):include() #1 {main}
      Diagnostic
      Information: SELECT * FROM accounts WHERE username='admin' AND
      passowrd='admin'

                    Did you setup/reset the DB?
      

      I get this error from registering/logging in etc
      I re-downloaded the Image rebuilt my VM & still
      got this error.


      Status: open
      Group: Version 2.x
      Created: Wed Jan 22, 2014 01:05 PM UTC by zdo
      Last Updated: Sun Apr 06, 2014 05:55 PM UTC
      Owner: nobody

      Using version 2.6.8 on metasploitable-2. Login into an existing account
      doesn't work. Register a new account will write that account into database
      but login doesn't work as well.


      Sent from sourceforge.net because you indicated interest in
      https://sourceforge.net/p/mutillidae/bugs/12/

      To unsubscribe from further messages, please visit
      https://sourceforge.net/auth/subscriptions/

       

      Related

      Bugs: #12

      • Chris Weaver

        Chris Weaver - 2015-04-23

        Has there been a change in the Status of this ERROR>>
        I went into set-up-database.php && found no ERRORs in
        the File that would create a metasploit.accounts Table
        it all looked ok. to me, I am confused!

         
        • Jeremy Druin

          Jeremy Druin - 2015-04-23

          I'm confused with you. I'm not sure how the metasploit schema was created.
          My thought is force the schema name in the queries. I'm speaking at AIDE
          today and working nights next week so I hope to look at it in May.
          On Apr 22, 2015 10:47 PM, "Chris Weaver" chrisweaver@users.sf.net wrote:

          Has there been a change in the Status of this ERROR>>
          I went into set-up-database.php && found no ERRORs in
          the File that would create a metasploit.accounts Table
          it all looked ok. to me, I am confused!


          Status: open
          Group: Version 2.x
          Created: Wed Jan 22, 2014 01:05 PM UTC by zdo
          Last Updated: Mon Apr 20, 2015 04:46 AM UTC
          Owner: nobody

          Using version 2.6.8 on metasploitable-2. Login into an existing account
          doesn't work. Register a new account will write that account into database
          but login doesn't work as well.


          Sent from sourceforge.net because you indicated interest in
          https://sourceforge.net/p/mutillidae/bugs/12/

          To unsubscribe from further messages, please visit
          https://sourceforge.net/auth/subscriptions/

           

          Related

          Bugs: #12

  • gtoniser

    gtoniser - 2015-09-19

    Right, the problem here is that several pages use

    isset($lQueryResult->num_rows)

    For some reason this returns false in PHP 5.2 (as discussed here: https://bugs.php.net/bug.php?id=46858 )
    Since Metasploitable ships with PHP 5.2 it breaks Mutillidae.

    Pages using this construction:
    classes/SQLQueryHandler.php
    includes/process-login-attempt.php
    set-up-database.php
    user-info.php

    It seems kind of redundant anyway, the num_rows property is always set unless the query returns an error, which is already caught in the MySQL handler.

     
    Last edit: gtoniser 2015-09-19
  • Jeremy Druin

    Jeremy Druin - 2015-12-11
    • status: open --> wont-fix
    • assigned_to: Jeremy Druin
     
  • Jeremy Druin

    Jeremy Druin - 2015-12-11

    gtoniser determined the issue is with the version of MySQL/PHP installed on Metasploitable-2. The older versions do not support some of the newer features in the latest release of Mutillidae 2.x

     

Log in to post a comment.

Get latest updates about Open Source Projects, Conferences and News.

Sign up for the SourceForge newsletter:

JavaScript is required for this form.





No, thanks