vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 3.8 Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=235)
-   -   Miscellaneous Hacks - Cyb - Login To User Account (https://vborg.vbsupport.ru/showthread.php?t=201286)

Valter 03-30-2009 03:29 PM

Quote:

Originally Posted by Sweeks (Post 1780233)
There is a serious security bug in this modification which can allow a member to access any user account. DO NOT INSTALL! Been hacked twice because of this product!

Impossible.

You can always check in moderator log who used this hack.

Sweeks 03-30-2009 04:45 PM

Quote:

Originally Posted by Cybernetec (Post 1780386)
Impossible.

You can always check in moderator log who used this hack.

There is some form of security bug in this which allows even a guest to use it. If I could PM you I would let you experience the flaw as I dont wish to post it publically.

Now unless there is something wrong with how I have set this up then there definitely is a problem. The only users I have allowed to use this is two admin accounts, I dont understand how guests could use it.
________
Extreme Vaporizer Sale

Sweeks 03-30-2009 07:57 PM

We have also found out that users were able to use the login to user account via a link on all members profiles as a guest.
________
BODY SCIENCE

Raptor 03-30-2009 09:53 PM

<a href="https://vborg.vbsupport.ru/showthread.php?t=168819" target="_blank">https://vborg.vbsupport.ru/showthread.php?t=168819</a>

this works great on vb 3.8.1

Sweeks 03-30-2009 10:03 PM

Quote:

Originally Posted by Raptor (Post 1780657)

Apparently not fully:

https://vborg.vbsupport.ru/showpost....&postcount=247

I hope that this is something I have overlooked.
________
Ferrari Fx

Valter 03-30-2009 11:16 PM

Quote:

Originally Posted by Sweeks (Post 1780442)
There is some form of security bug in this which allows even a guest to use it. If I could PM you I would let you experience the flaw as I dont wish to post it publically.

Now unless there is something wrong with how I have set this up then there definitely is a problem. The only users I have allowed to use this is two admin accounts, I dont understand how guests could use it.

Have you checked your ModLog for this product entries?

Feel free to report product to forum Staff so they can check it and move it to "Mod Graveyard" if they find such bug. Noone reported such issue before.

Check your settings and ensure that proper user IDs are added to the list of Admins. IDs should be separated with commas.

nascartr 03-31-2009 02:24 PM

I tested with a regular member and a guest, I don't have the problem.

Sweeks 03-31-2009 06:25 PM

There is no logs at all of the activity as it is a guest able to do this. All user ID's have been correct too. @ Nascartr, I have tested it myself on a friends board without the same problem. I am sure this wasnt possible on our board until lately. Could it be anything to do with not using the default memberinfo template?
________
FAMILY GUY DICUSSION

Wifey 04-01-2009 08:19 PM

I got a vbulletin error page when I tried to log in to an account on my site. I went back to the main page and it was gone, and I was logged in as myself but it was telling me I was logged in as someone else. I haven't even opened this site yet and have maybe 4 other hacks total installed. Any idea?

Great hack, by the way -- I had it on my last board and it was very useful with helping out a user on their account without having them change their password to something generic and then changing it back.

Valter 04-01-2009 08:59 PM

Quote:

Originally Posted by Sweeks (Post 1781228)
Could it be anything to do with not using the default memberinfo template?

Nope. Even if you give them direct link to loginasuser script they will not be able to do that.
Quote:

Originally Posted by Wifey (Post 1781967)
I got a vbulletin error page when I tried to log in to an account on my site.

What error?

Try to clear forum cookies, then re-log-in to your account, then try to log-in as user.

padfoot007 04-02-2009 04:25 AM

DUDE...omg this is one of the most amazing and freaky plugin ever...<3 u

Sweeks 04-03-2009 03:55 PM

Youve said this is impossible, well how come it is doing this on our board as a guest even after installing the plugin again?

[removed the link ;)] is exactly what can be used on our forum for some reason with this modification enabled. That is without link on profiles etc and only allowed for myself to use it in the options for this.
________
Mercedes-Benz W125 History

Sweeks 04-03-2009 04:00 PM

Got it at last! This modification is not to blame and I apologise Cyb, I have just figured it out! Another mod is allowing this security risk to be open in conflict which I am reporting.
________
Mflb vaporizer

Sweeks 04-03-2009 04:37 PM

Actually I take that back, it is still doing the same thing.

I have tested the flaw in IE8 but it doesnt work and only seems to work in FF. I have disabled all the modifications using usergroups and still get this problem. Also, our guest count drops to zero guests as soon as I attempt the trick, it resets our guests somehow.
________
Vaporizer Information

Brother Malachi 04-08-2009 09:49 PM

I didn't realize the logging was on by default and have now disabled it, but is there a way to get rid of the logs that are already in the database?

Phobos49 04-09-2009 06:41 AM

Quote:

Originally Posted by Sweeks (Post 1783114)
Youve said this is impossible, well how come it is doing this on our board as a guest even after installing the plugin again?

[high]is exactly what can be used on our forum for some reason with this modification enabled. That is without link on profiles etc and only allowed for myself to use it in the options for this.[/high]

Damn, he is right!!!! :eek::eek::eek::eek:

With this link I am able to login into any account at my forum I want to! Even wihthout being even logged in before!!!

How is this possible?!?!?! DANGEROUS!!!!!!

Brother Malachi 04-09-2009 06:48 AM

Sweeks, edit that link out.

Brother Malachi 04-09-2009 06:53 AM

And of course Cybernetec doesn't accept PMs. Unless he takes a look at the above within a day I'm going to PM one of the mods and have them move this to the mod graveyard.

Phobos49 04-09-2009 07:08 AM

I just edited my Quote so that the URL disappears.

Well, I'm a bit shocked... I never thought, that an AddOn could do things like that! :eek::(

Brother Malachi 04-09-2009 07:10 AM

I PMed an admin to remove the other URL too.

Phobos49 04-09-2009 07:20 AM

Did somebody already cross check versions 3.7, 3.6 and 3.5 if they have the same heavy bug?

btw: every admin using this AddOn should be informed "asap" by eMail as soon as Cybernetec or vb-Admin has confirmed this bug.

Phobos49 04-09-2009 07:47 AM

Here I go again...

Seems like we have a worst-case-scenario... :( I just tried to "hijack" an admin account of a forum postet in the signatur of an user using the 3.7-Version.

Unfortunatly, I was successfull...
I now have full access of his forum! Don't worry - I will not do any harm!

ADMINs! Please remove all versions of this AddOn & inform every admin to disable this AddOn as soon as possible!
If vb-Admins would like to test hijacking forums - send PN an I'll give you some links to vunerable forums. There you can hijack any account you want. Unbelivable!!!! :mad::down:

TheCatcher 04-09-2009 08:15 AM

Confirm the Phobos49 called Bug!

Sweeks 04-09-2009 08:51 AM

Told you it wasnt impossible :D The only mod that does the same and seems secure right now is:

https://vborg.vbsupport.ru/showthread.php?t=168819
________
FISTING MILF

rmxs 04-14-2009 11:06 AM

I think now the problem fixed :P

KURTZ 04-14-2009 11:09 AM

changelog?

sturdy 04-14-2009 11:10 AM

Im currently using this hack for my forum. But how is it possible that somebody easily uses the url ? Does he need an account on the forum or which way does it work ?

-=Leb=- 04-14-2009 11:33 AM

a confirmation from cyb will be nice.
Sorry if i ask Cyb, is this mod safe now? can i install it?

-=Leb=- 04-14-2009 11:35 AM

if this mod safe now, plz edit phobos post above!

Phobos49 04-14-2009 11:53 AM

Quote:

Originally Posted by Leb (Post 1790967)
if this mod safe now, plz edit phobos post above!

Why? Version 2.2 ist absolutly unsafe!

Version 2.3 should be safe now (did not test myself yet).

But every admin MUST updated to 2.3 to secure his forum!

So I am not going to edit my posting.

Sweeks 04-14-2009 01:06 PM

Quote:

Originally Posted by sturdy (Post 1790949)
Im currently using this hack for my forum. But how is it possible that somebody easily uses the url ? Does he need an account on the forum or which way does it work ?

Guests could also use the exploit.
________
Ipad guide

sturdy 04-14-2009 01:34 PM

When I try to add this url-code to the member.php I just see a login screen. So, there is no problem is it ?

Phobos49 04-14-2009 02:56 PM

Quote:

Originally Posted by sturdy (Post 1791010)
When I try to add this url-code to the member.php I just see a login screen. So, there is no problem is it ?

If you allow guest to view member profiles - you will have this problem. Try!

atmaca 04-14-2009 03:05 PM

Thanks for update.

Valter 04-14-2009 06:09 PM

v2.3 - Apr 11. 2009.
-Bug fix (non-Admins able to login to user accounts in some cases)
-Bug fix (Admin can not search product entries in ModLog by product ID)
-Bug fix (logging error if username contains special characters)
-Bug fix (Admin must be member of usergroup 6 to use product)
-Minor bugs fixed

Upgrade Info:
-Import product XML, allow overwrite
-Revert product templates if any modified

KevinGupta 04-14-2009 09:04 PM

nice man!

Sweeks 04-16-2009 08:06 AM

The update is working fine now Thank you. The only problem is when manually placing the link in MEMBERINFO everyone can see it unless you wrap it in a conditional like the following.

Code:

<if condition="is_member_of($vbulletin->userinfo, array( 6))">

$cyb_ltoua_link_mi
</if>

They cant use it though even as a guest but the link certainly needs a conditional around it before it is hidden to everyone else.
________
Halfbaked

tommyturnage 04-24-2009 06:12 AM

Works perfect

Thanks!

jaredwilli 04-24-2009 02:54 PM

When I click on Set Admins, it loads misc.php in that frame, and no where can I set the admins that can use this.
It seems this link isnt working

misc.php?do=cybltua_set

Skyrider 05-02-2009 06:31 PM

It doesn't matter who I "log in to" I always get:

Quote:

FF|SkyPirate, You are currently using FF|SkyPirate's account. Click here to go back to your admin account.
Is this right? Always logging in to myself? I checked the link, and the UserID when it logs in to the account on the end is always different.


All times are GMT. The time now is 04:14 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01432 seconds
  • Memory Usage 1,820KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_code_printable
  • (11)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (3)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete