Previous Thread
Next Thread
Print Thread
Rate Thread
#71990 05/15/2001 6:29 PM
Joined: Dec 2000
Posts: 100
Member
Member
Offline
Joined: Dec 2000
Posts: 100
okay.. well lemme find the e-mail

and i QUOTE

START QUOTE

Yo.
Yeah so the idea is, in your cgi application that your
"edit profile" form uses, if any user is signed in to
their account, while they are signed in, someone has
an ability to completely change the person's profile
(ie: change password) except for the avatar icon, and
lock em out/take over the account.

All you need to know is that the user is logged in and
their u=id where id is their user id number (u in the
form name), which can be determined by the order the
people registered. just have to put the proper number
of trailing zero's in front (easy, look at an example
from your own mbs account in the hidden input type in
the source of the html form). the message board
displays this for any user by a post (ie: ender's the
fourth member, I'm the 14th registered, etc), but if
you wanted to, say change the first registrant, which
should always be an admin (you usually got a damn good
idea who =D), or a random one, and see of they're
online, still be bad enough. Don't know about fixing
the hole, but all you have to do to preform the attack
is fill in "valid" options that the user would fill in
to their form, and just add the right user id.... you
can change the pass, displayed name, all that, as long
as all the input types meant to be submitted in your
custom made form match what they would be in the
pregiven form, and a different correct user id is
given (and they're logged in). lala, I'd suggest, if
you got the power (the source, or know enough to code
your own and change the login form) is ask for an "old
password" field, and don't have the form make any
changes without it being properly supplied to the user
account. if not, you can inform uub and complain, I
suppose.

You could even set up a script to run and send change
requests, see if their info changes, and take down the
bot when it does. just keep sending the request until
you catch them logged in if ya don't want a fluke.
very vulnerable........

PS: I still can't make a custom avatar for me (boo
hoo)

Whoo, enough ranting out of me.

END QUOTE

Sponsored Links
Entire Thread
Subject Posted By Posted
6x ubbs can be hacked Sushi Man 05/15/2001 4:08 AM
Re: 6x ubbs can be hacked qasic 05/15/2001 4:23 AM
Re: 6x ubbs can be hacked AllenAyres 05/15/2001 7:53 AM
Re: 6x ubbs can be hacked certify 05/15/2001 9:20 AM
Re: 6x ubbs can be hacked cal 05/15/2001 9:59 AM
Re: 6x ubbs can be hacked Sushi Man 05/16/2001 1:29 AM
Re: 6x ubbs can be hacked qasic 05/16/2001 1:54 AM
Re: 6x ubbs can be hacked qasic 05/16/2001 1:57 AM
Re: 6x ubbs can be hacked cal 05/16/2001 9:51 AM
Re: 6x ubbs can be hacked Sushi Man 05/16/2001 1:20 PM
Re: 6x ubbs can be hacked freak.scene 05/16/2001 2:23 PM
Re: 6x ubbs can be hacked cal 05/16/2001 5:32 PM
Re: 6x ubbs can be hacked AllenAyres 05/16/2001 9:34 PM
Re: 6x ubbs can be hacked Sushi Man 05/17/2001 1:38 AM
Re: 6x ubbs can be hacked Matt Jacob 05/17/2001 1:47 AM
Re: 6x ubbs can be hacked cal 05/17/2001 9:34 AM

Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
Nettomo
Nettomo
Germany, Bremen
Posts: 417
Joined: November 2001
Forum Statistics
Forums63
Topics37,575
Posts293,932
Members13,824
Most Online6,139
Sep 21st, 2024
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,835
Greg Hard 4,625
Top Posters(30 Days)
Gizmo 2
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2025 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.1
(Snapshot build 20240918)