Previous Thread
Next Thread
Print Thread
Rate Thread
Joined: Nov 2002
Posts: 2
Junior Member
Junior Member
Offline
Joined: Nov 2002
Posts: 2
UBB is an excellent forum to use but I have a few pointers for Admins of forums...

1) Disable HTML posting.
2) Encrypt the password in the cookies.

I know you're probably saying, "Yeah, Ok, tell us something we DON'T know...", but I have just finished a project that uses the XSS exploit on a whole different level that even the browser patch can't stop.
It's in the form of a Flash app that can do this and do it well!
Disabling Javascript commands in posts won't even prevent the Flash app from doing it's thing!
You see, Flash can create and execute Javascript commands on-the-fly from within the app and all it takes is some clever scripting to grab the parent document's cookie and strip the person of their identity!
I have tried this app in other forums to great success, maybe pissed a few Admins off in the process, but I've always notified them of the exploit and how to prevent future attacks. I think I just scared the hell out of them...

I think one of the main pointers is to ENCRYPT the password in the cookie because even if some inexperienced "script kiddie" DID manage to get the cookie, he wouldn't know what to do with the encrypted password,... unless he had a good MD5 decrypter...because if I'm correct, isn't the password encrypted using MD5 process?

Sponsored Links
Joined: Jan 2000
Posts: 5,073
Admin Emeritus
Admin Emeritus
Joined: Jan 2000
Posts: 5,073
MD5 is not an encryption format, it is a message digest - you can not derive the original from the digest.

As of 6.4, passwords in cookies are MD5 encoded.

Today's (upcoming) 6.3.1.2 release and the later 6.4 beta also include enhanced filtering to avoid certain newly revealed XSS attacks that are only possible with HTML enabled.

If you have discovered what you believe to be XSS vulnerabilities, this is not the proper place to post. Please open up a support ticket or mail [email protected] with details.

I am now closing this topic.


UBB.classic: Love it or hate it, it was mine.

Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
Posts: 70
Joined: January 2007
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20240506)