Log in

View Full Version : *\ thread Exploit /*


Stangsta
04-16-2006, 08:55 PM
The subject line throws off the CSS, just letting everyone know incase you are wondering wtf happened in your forums if you see this.

Roms
04-16-2006, 08:59 PM
^ Did you find out the hard way? ;)

Stangsta
04-16-2006, 09:01 PM
^ Did you find out the hard way? ;)No, I saw it on another board and decided to test it on mine.

Borgs8472
04-16-2006, 09:05 PM
could you explain this problem in more detail?

Stangsta
04-16-2006, 09:23 PM
could you explain this problem in more detail?It works on some forums and others it does not. Using */ or \* in the title will strip the CSS from that specific thread. Its a thread break.

akanevsky
04-16-2006, 10:38 PM
Does not seem to break anything for me..

Roms
04-17-2006, 12:00 AM
Didn't seem to work on mine either... Maybe it depends on the variables you use in your CSS....

Stangsta
04-17-2006, 12:43 AM
Didn't seem to work on mine either... Maybe it depends on the variables you use in your CSS....Very well could be, I've seen it happen on a couple of different sites. May also be vb version related.

akanevsky
07-23-2006, 12:16 PM
I understand the thread is outdated and the problem has been fixed, but can anyone explain how this can be used in practice?

sabret00the
07-23-2006, 12:49 PM
you can basically set the whole page to be blank and inset a banner i beleive.

Dean C
07-23-2006, 12:51 PM
How can this possibly even work too. The CSS is within a stylesheet or within a <style> block. Unless the thread title is placed inside the CSS somewhere...

Guest190829
07-23-2006, 01:01 PM
How can this possibly even work too. The CSS is within a stylesheet or within a <style> block. Unless the thread title is placed inside the CSS somewhere...

I was asking myself the same thing...

AN-net
07-23-2006, 01:30 PM
probably the site attacked was not clossing container tags and did not close the <style> tag. it probably wasnt an exploit just bad coding on the website's end. just another reason to follow standards and to validate your pages.

sabret00the
07-24-2006, 06:33 PM
either way, wouldn't it require
*/ $thread['title'] /*

Kirk Y
07-24-2006, 10:40 PM
Is this a 3.6 only exploit, because my 3.5.x board works fine through the "break".

Princeton
07-25-2006, 04:41 PM
Kirk,
no, this is not an exploit in vbulletin

I agree with the above comments ... it's just bad coding on the website's end (not default style)

Kirk Y
07-25-2006, 07:51 PM
Okay, that figures. Thanks Princeton.