vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Potential Security Issue (https://vborg.vbsupport.ru/showthread.php?t=221797)

TimberFloorAu 08-26-2009 09:14 AM

Potential Security Issue
 
Today we have had 2 members join, whos ips match 2 of our senior moderators.

Now , our mods have denied that they have set up a new acct,.... so can someone explain.

Is their a security flaw?

Someone is obviously, going to the trouble of obtaining our users IP addresses, then signing up , using a bogus IP addy, that matches our Mods.

Sounds Bizarre but true. Currently have VBSEO online with us, assisting with Suhosin settings

Can anyone please explain how this vulnerability can happen ?

TheLastSuperman 08-26-2009 03:42 PM

Quote:

Originally Posted by TimberFloorAu (Post 1874637)
Today we have had 2 members join, whos ips match 2 of our senior moderators.

Now , our mods have denied that they have set up a new acct,.... so can someone explain.

Is their a security flaw?

Someone is obviously, going to the trouble of obtaining our users IP addresses, then signing up , using a bogus IP addy, that matches our Mods.

Sounds Bizarre but true. Currently have VBSEO online with us, assisting with Suhosin settings

Can anyone please explain how this vulnerability can happen ?

I happened to check on a friends forum the night before last... I logged in and saw (1 Viewing) beside an admin forum... I looked @ WOL and only me and one other member w/ no guest so I clicked the sub-forum and it had the member listed as viewing their admin forums.

Oddly enough they had setup a general admin account a while back when on 3.6 to post RSS feeds and guess what? The users IP matched the admin accounts IP.

So same question here as it sounds oddly familiar to yours TimberFloorAU except they do not use vBSEO (Gamer forums no need etc).

TimberFloorAu 08-26-2009 07:47 PM

Very weird huh Michael.

We appear to have suhosin re enabled, but our host hasnt been totally helpful, asking us to enable it within easy apache. But it is enabled, the coder over at vbseo, stated via shell access that we do seem to have a misconfigured suhosin... so perhaps that is the issue.

He however managed to fix this via a htaccess fix, but I am still concerned as to this security issue, and how it is/has been exploited.

Ste

Lynne 08-26-2009 08:31 PM

If you think there is a security issue, you really should post about it over on vb.com since the vb.com guys don't come over here to read about things like this.

TimberFloorAu 08-26-2009 09:45 PM

I have posted this now over at vb.com

One of our admins, has spotted a peculiarity.

We have the New Member Auto Greeting
https://vborg.vbsupport.ru/showthread.php?t=214702

It appears that whoever greets the new member, that new member then posesses that "greeters" IP.

Weird huh !! Will post on the thread of the mod.

Ste

TheLastSuperman 08-28-2009 05:16 AM

Quote:

Originally Posted by TimberFloorAu (Post 1875033)
I have posted this now over at vb.com

One of our admins, has spotted a peculiarity.

We have the New Member Auto Greeting
https://vborg.vbsupport.ru/showthread.php?t=214702

It appears that whoever greets the new member, that new member then posesses that "greeters" IP.

Weird huh !! Will post on the thread of the mod.

Ste

Yes this is weird... Glad to see more being found out about this Timber ;) however the forum I found this on does not have that mod installed but it does point out the problem with having the same IP, security risk IMO.

matthewhotdude 08-28-2009 10:11 AM

Quote:

Originally Posted by TheLastSuperman (Post 1875651)
Yes this is weird... Glad to see more being found out about this Timber ;) however the forum I found this on does not have that mod installed but it does point out the problem with having the same IP, security risk IMO.

What I did, Because the welcome threads get people talking, and I can't find another mod like it, was to create a user called "welcome Party" that is basically a bot that never logs on.
It only replicated the I.P's in the welcome threads tho ?

TheLastSuperman 08-28-2009 11:17 PM

Quote:

Originally Posted by matthewhotdude (Post 1875720)
What I did, Because the welcome threads get people talking, and I can't find another mod like it, was to create a user called "welcome Party" that is basically a bot that never logs on.
It only replicated the I.P's in the welcome threads tho ?

And those forums I bet are public or viewable to guest and the rest are permission'ed for usergroups right?

RLShare 08-28-2009 11:46 PM

The mod creates a post based on a user registering, so it naturally attaches the IP of the User registering to the thread created. And since your username is used by the mod to create the thread, the same IP attached to the thread also gets attached to your account as one you have used. It is not really a security risk at all.

And if you do not want it attaching another IP to your account someone already posted how you can attach a specific IP to those threads instead of VB automatically attaching the users IP to your account.


All times are GMT. The time now is 10:19 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01372 seconds
  • Memory Usage 1,743KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (4)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (9)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete