Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | phpbb 2.0.13 Exploit (bug) |
|---|---|
| Date: | Fri, 25 Mar 2005 21:09:46 +0200 |
------------------------------------------------------------------------ # phpBB 2.0.13 failure to reset user level after failed exploit # discovered By : tOnk3r # e-mail : m[at]spywire[dot]net # date : 22-march-05 # shouts: pureone, spywire.net crew , and everybody i know! # Versions affected : ALL versions upto and including 2.0.13 # status : vendor notified (phpbb) ------------------------------------------------------------------------ phpBB is a high powered, fully scalable, and highly customisable open-source bulletin board package. phpBB has a user-friendly interface, simple and straightforward administration panel, and helpful FAQ. Based on the powerful PHP server language and your choice of MySQL, MS-SQL, PostgreSQL or Access/ODBC database servers, phpBB is the ideal free community solution for all web sites. +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ This exploit is an extention of the phpbb 2.0.12 boolean exploit that can be found here http://www.spywire.net/forum/viewtopic.php?t=781 . This exploit works because the login allows true boolean strings to be entered in place of the password hash and session id. It allows an attacker to login as any user without having to enter any authentication by editing a cookie and sending it back to the site. The bug i discovered is a bug in the user privlage reset. After trying to exploit a patched forum the user remains as admin, even though the forum is patched. The forum fails to reset the attackers status to guest after a failed exploit. The attacker is able to view invisible members and the "admin control pannel" link but is unable to navigate the forum as admin. With some more investigation im certain a critical exploit can be found. but so far i am unable to keep admin status after clicking another link. ''''''''''''''''''''''''''' ][=-tOnk3r-=][ ''''''''''''''''''''''''''' if you have any more info on this bug please notify me either at m[at]spywire[dot]net or at www.spywire.net/forum
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Secure Science issues preview of their upcoming block cipher, Ralf-Philipp Weinmann |
|---|---|
| Next by Date: | ZH2005-03SA -- multiple vulnerabilities in NukeBookmarks .6, Gerardo Astharot Di Giacomo |
| Previous by Thread: | TCP timestamp & advanced fingerprinting, Erwan Arzur |
| Next by Thread: | ZH2005-03SA -- multiple vulnerabilities in NukeBookmarks .6, Gerardo Astharot Di Giacomo |
| Indexes: | [Date] [Thread] [Top] [All Lists] |