Previous Thread
Next Thread
Print Thread
Rate Thread
#174555 03/30/2002 5:17 AM
Joined: Jun 2001
Posts: 2,849
Spotlight Winner
Spotlight Winner
Offline
Joined: Jun 2001
Posts: 2,849
If HTML is enabled, this can grab your cookie. At least on 6.1.0.4

[code snipped by CC]

Sponsored Links
#174556 03/30/2002 9:32 AM
Joined: Mar 2002
Posts: 8
Junior Member
Junior Member
Offline
Joined: Mar 2002
Posts: 8
just one of the many many ways you can do things like that
even with html OFF you can steal cookies, in ANY version.

#174557 03/30/2002 10:01 AM
Joined: Dec 2000
Posts: 371
Member
Member
Offline
Joined: Dec 2000
Posts: 371
maybe there is a way to let the ubb set scrambled cookies? Unrecognizable cookies, yeah. laugh

#174558 03/30/2002 11:15 AM
Joined: Mar 2002
Posts: 8
Junior Member
Junior Member
Offline
Joined: Mar 2002
Posts: 8
quote:
Originally posted by Variables:
maybe there is a way to let the ubb set scrambled cookies? Unrecognizable cookies, yeah. laugh

even then u could still hack up your cookie dir and edit them
md5("$pass$ip") should be safe tipsy

#174559 03/30/2002 12:04 PM
Joined: Jun 2001
Posts: 2,849
Spotlight Winner
Spotlight Winner
Offline
Joined: Jun 2001
Posts: 2,849
These exploits have been known for some time...I would love to see a better fix for them.

Sponsored Links
#174560 03/30/2002 4:07 PM
Joined: Mar 2002
Posts: 8
Junior Member
Junior Member
Offline
Joined: Mar 2002
Posts: 8
use VBB tipsy

#174561 03/30/2002 4:40 PM
Joined: Dec 2001
Posts: 699
Member
Member
Offline
Joined: Dec 2001
Posts: 699
Erm...

**WAS A URL BUT I EDITED IT...**

vB isn't immune...

#174562 03/30/2002 5:03 PM
Joined: Jun 2001
Posts: 2,849
Spotlight Winner
Spotlight Winner
Offline
Joined: Jun 2001
Posts: 2,849
quote:
Originally posted by BlackTyranitar:
use VBB tipsy

I'm sure that there are plenty of places that your humor is appreciated, but this isn't one of them. I'm talking about a real issue here and I would appreciate you either staying on topic or posting in a different thread.

#174563 03/30/2002 6:40 PM
Joined: Jun 2001
Posts: 2,849
Spotlight Winner
Spotlight Winner
Offline
Joined: Jun 2001
Posts: 2,849
A read through this thread may be enlightening to some of you...

[url snipped by CC]

#174564 03/31/2002 2:15 AM
Joined: Jan 2000
Posts: 5,073
Admin Emeritus
Admin Emeritus
Joined: Jan 2000
Posts: 5,073
This is why HTML is dangerous, why the check_html routine is designed to do what it does, why we ALWAYS tell people to keep their versions up to date (6.2.1.1 catches this, and 6.3 does an even more careful job), and why we always tell people to keep HTML off.

If you are going to take a risk and turn HTML on, you will open yourself to things like this.

I have removed the offending code from your post and will now close this topic. Posting it was irresponsible.

Upgrade to 6.2.1.1. Now.


UBB.classic: Love it or hate it, it was mine.
Sponsored Links

Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
isaac
isaac
California
Posts: 1,157
Joined: July 2001
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20221218)