vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 3.7 Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=228)
-   -   Miscellaneous Hacks - Cyb - Login To User Account (https://vborg.vbsupport.ru/showthread.php?t=177947)

KEKforce 01-09-2009 02:18 PM

Works on 3.8.0. gold!

slowphantom 01-29-2009 09:42 AM

the hack dont work in 3.7.5 any update ?

wally 01-30-2009 07:30 PM

it works on 3.7.4 and on 3.8 so it should also work in 3.7.5 (as 3.7.5 is only a bug fix/maintenaince release)

bo3bdo 02-15-2009 01:29 PM

Hi
vBulletin 3.8.1

on
https://vborg.vbsupport.ru/attachmen...6&d=1209821865

error :(

Database error in vBulletin 3.8.1:

Invalid SQL:
UPDATE cyb_logintouser حدد المراقبين = '91';

MySQL Error : You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'المراقبين = '91'' at line 1
Error Number : 1064
Request Date : Sunday, February 15th 2009 @ 06:27:44 PM
Error Date : Sunday, February 15th 2009 @ 06:27:47 PM
Script : http://www.XXXXX.com/vb/misc.php?do=cybltua_set_do
Referrer : http://www.XXXXXX.com/vb/misc.php?do=cybltua_set
IP Address : XXXXXXX
Username : XXXX

weexto 02-15-2009 03:00 PM

There will be an update for the VB version 3.8.1?

Sweeks 03-30-2009 11:31 AM

Same security issues with this one too on 3.8
________
Amateur Tube

nNJ 04-01-2009 10:04 PM

I guess that this does not work on 3.8.1. Oh well, I will be be waiting for this to be released for the 3.8.x series!

alfaowner 04-04-2009 05:02 PM

Hoping for a 3.8 release soon as I use this with permission to view members problems they are having with their accounts.:)

Phobos49 04-09-2009 08:19 AM

Warning! Dangerous security bug!!!Read here: https://vborg.vbsupport.ru/showpost....8&postcount=62

Phobos49 04-09-2009 11:42 AM

Please stop sending PMs asking for the exploit-URL! Please!

I won't tell anybody exept vB-Staff and Cybernetec!

You don't have to worry! As soon as you deactivate this AddOn your forum is save again. You don't even need to uninstall. Just deactivate AddOn and wait for further instructions by Cybernetec or vB-Staff.

Gsmdenis 04-09-2009 03:38 PM

Confirm the bugs, Hope Cybernetec fix that soon :-)))))

Golzarion 04-09-2009 05:05 PM

I mention and said the warning on : https://vborg.vbsupport.ru/external/2009/04/27.gif 14 Jan 2009, 00:48

https://vborg.vbsupport.ru/showpost....7&postcount=12

This plugin has many bugs ! Specially when you use vbseo or some kind of rewrite_mods !!

It seems some how funny ! because an Administrator use this plugin to log in to user account and read private messages and so on .. BUT the Administrator causes to "hijack" his/her own account first ! and make an unwanted dangerous bug in his/her own forums!!

Phobos49 04-09-2009 05:30 PM

I am still wondering why this 3.7 version is not already in the graveyard like the 3.8 version. :mad:

This version has the same severe security bug!!! :(

Send it to the graveyard at once and inform every user of this addon by email to deactivate it like you did this morning with the 3.8 version!

How long are you going to wait? Until many users complain, that their forums have been nuked?! :confused:

Come on! It's never been easier than today to get full control over a foreign vB by just modifing your browsers URL! :mad:

jesus likes pie 04-09-2009 07:34 PM

Is this safe without an SEO?

Phobos49 04-09-2009 08:01 PM

Quote:

Originally Posted by jesus likes pie (Post 1787619)
Is this safe without an SEO?

NO! It does not matter if you have SEO installed or not. In both cases any account in your forum can be hijacked as long as you don't disable this AddOn.

jesus likes pie 04-09-2009 08:53 PM

Okay, I think this should fix it.

Try it out and see if you can still exploit it.

note: the attached plugin originates from the 3.8 version which is now in the graveyard, but it should probably work for 3.7 as well :)

edit: er, apparently vBulletin doesn't prompt you to overwrite plugins which is kinda lame (heh, been a while since I've uploaded plugins rather than products).

You should delete "Cyb - Login To User Account - MI" and then upload my attachment.

TheCatcher 04-14-2009 10:34 AM

Thx for Version 2.3 (re-installed) :-)

NolF 04-14-2009 10:59 AM

Awesome, thanks for the update :D

wfouly 04-14-2009 11:11 AM

many thanks
Installed and working well with 3.8.2

Sixpackmark 04-14-2009 01:33 PM

Thanks again! Re-installed

haytham 04-14-2009 01:39 PM

Thanks for the update. Can't live without this mod.

Valter 04-14-2009 06:11 PM

v2.3 - Apr 11. 2009.
-Bug fix (non-Admins able to login to user accounts in some cases)
-Bug fix (Admin can not search product entries in ModLog by product ID)
-Bug fix (logging error if username contains special characters)
-Bug fix (Admin must be member of usergroup 6 to use product)
-Minor bugs fixed

Upgrade Info:
-Import product XML, allow overwrite
-Revert product templates if any modified

alfaowner 04-14-2009 06:49 PM

Quote:

Originally Posted by Phobos49 (Post 1787281)
Please stop sending PMs asking for the exploit-URL! Please!

I won't tell anybody exept vB-Staff and Cybernetec!

You don't have to worry! As soon as you deactivate this AddOn your forum is save again. You don't even need to uninstall. Just deactivate AddOn and wait for further instructions by Cybernetec or vB-Staff.

Quote:

Originally Posted by Phobos49 (Post 1787178)
If vb-Admins would like to test hijacking forums - send PN an I'll give you some links to vunerable forums. There you can hijack any account you want. Unbelivable!!!! :mad::down:

This is why you received so many PMs? Anyhow thanks for highlighting this issue, we all owe you!

berrada 04-15-2009 12:17 AM

Thank you very much

nader 04-15-2009 05:37 PM

Great work

Thank you so much

Losha 04-21-2009 12:56 PM

Thank you

bCk 04-27-2009 09:13 AM

Thank you

Dan Clement 05-03-2009 11:17 PM

Really useful tool. Thanks a lot! :)

murekhalir 07-23-2009 05:39 AM

I am getting an issue - i click on a users account - try to login - it says that i login to myself - not the intended user.

anyway to fix this issue?

Valter 07-23-2009 07:13 AM

Clear forum cookies, then try again.

Razor23 08-05-2009 08:07 PM

Can you make it so that this mod has a off and on switch for a user to PM the user being logged into so that user knows if his account is being used by an admin?

bleros 09-15-2009 04:22 AM

Have bugs this plugins in modcp user.php i get this error

Warning: array_merge() [function.array-merge]: Argument #1 is not an array in [path]/modcp/user.php(348) : eval()'d code on line 29

When disable this plugins is ok

mp3president 11-14-2009 08:40 PM

Merci i can use it

Izze_de 02-14-2010 11:59 AM

Are you planning a 4.x version?

Please, I loveit and it helps a lot solving users problems.

Valter 02-26-2010 12:18 PM

vB 4 version released here:
https://vborg.vbsupport.ru/showthread.php?t=233350

vitrag24 03-15-2010 09:28 PM

vb 4.0 update?
thx.

haytham 05-01-2010 08:16 AM

Thank you for this very useful tool.

nlwin 03-03-2011 09:17 PM

Do you have a version for vBulletin 3.8.7? Thank you.

Updated:
Sorry I was tripping. Found new version here [https://vborg.vbsupport.ru/showthread.php?t=201286]

berrada 08-13-2014 01:54 PM

Thank you very much


All times are GMT. The time now is 01:04 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03069 seconds
  • Memory Usage 1,787KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (39)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete