vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 3.8 Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=235)
-   -   Miscellaneous Hacks - Cyb - Login To User Account (https://vborg.vbsupport.ru/showthread.php?t=201286)

padfoot007 04-02-2009 04:25 AM

DUDE...omg this is one of the most amazing and freaky plugin ever...<3 u

Sweeks 04-03-2009 03:55 PM

Youve said this is impossible, well how come it is doing this on our board as a guest even after installing the plugin again?

[removed the link ;)] is exactly what can be used on our forum for some reason with this modification enabled. That is without link on profiles etc and only allowed for myself to use it in the options for this.
________
Mercedes-Benz W125 History

Sweeks 04-03-2009 04:00 PM

Got it at last! This modification is not to blame and I apologise Cyb, I have just figured it out! Another mod is allowing this security risk to be open in conflict which I am reporting.
________
Mflb vaporizer

Sweeks 04-03-2009 04:37 PM

Actually I take that back, it is still doing the same thing.

I have tested the flaw in IE8 but it doesnt work and only seems to work in FF. I have disabled all the modifications using usergroups and still get this problem. Also, our guest count drops to zero guests as soon as I attempt the trick, it resets our guests somehow.
________
Vaporizer Information

Brother Malachi 04-08-2009 09:49 PM

I didn't realize the logging was on by default and have now disabled it, but is there a way to get rid of the logs that are already in the database?

Phobos49 04-09-2009 06:41 AM

Quote:

Originally Posted by Sweeks (Post 1783114)
Youve said this is impossible, well how come it is doing this on our board as a guest even after installing the plugin again?

[high]is exactly what can be used on our forum for some reason with this modification enabled. That is without link on profiles etc and only allowed for myself to use it in the options for this.[/high]

Damn, he is right!!!! :eek::eek::eek::eek:

With this link I am able to login into any account at my forum I want to! Even wihthout being even logged in before!!!

How is this possible?!?!?! DANGEROUS!!!!!!

Brother Malachi 04-09-2009 06:48 AM

Sweeks, edit that link out.

Brother Malachi 04-09-2009 06:53 AM

And of course Cybernetec doesn't accept PMs. Unless he takes a look at the above within a day I'm going to PM one of the mods and have them move this to the mod graveyard.

Phobos49 04-09-2009 07:08 AM

I just edited my Quote so that the URL disappears.

Well, I'm a bit shocked... I never thought, that an AddOn could do things like that! :eek::(

Brother Malachi 04-09-2009 07:10 AM

I PMed an admin to remove the other URL too.


All times are GMT. The time now is 12:02 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01108 seconds
  • Memory Usage 1,734KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete