vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   vbulletin 3.8.6 cookie security hole (https://vborg.vbsupport.ru/showthread.php?t=276589)

Mihemed Ş?yar 01-07-2012 06:51 PM

vbulletin 3.8.6 cookie security hole
 
Hi.
Html code in my web site has been closed.
but,

one

write on my site.
smile and exit,

if I enter the http://46.20.2.51/%7Esecurity/vbulletin/smile.php

See the picture

this one is open,
how to shut down

https://vborg.vbsupport.ru/external/2012/01/55.jpg

--------------- Added [DATE]1325966151[/DATE] at [TIME]1325966151[/TIME] ---------------

look
wrote the code,
vbulletin.com have the security error.

kh99 01-07-2012 07:14 PM

I don't understand what the problem is. It could be because I can't read whatever language that is in the picture.

Lynne 01-07-2012 07:28 PM

That is like an htaccess protection popup. Someone has protection on the directory where the site or image is located.

Mihemed Ş?yar 01-07-2012 07:35 PM

Sorry,
My english very bad,

Now,
Please [IMG]http://46.20.2.51/%7Esecurity/vbulletin/smile.php[/IMG ] write your web site . [/IMG ] delete the space

kh99 01-07-2012 07:59 PM

So are you saying that it's a security hole because that popup might trick people into entering their vbulletin password?

Mihemed Ş?yar 01-07-2012 08:33 PM

No...

1: https://vborg.vbsupport.ru/external/2012/01/7.gif My message

2:

This not a pic. It is a .php files,


https://vborg.vbsupport.ru/external/2012/01/54.jpg

kh99 01-07-2012 08:36 PM

Sorry, I still don't get it. It just seems like you've linked to a file that's password-protected by your web server. If there's something else going on, I don't understand.

It could be that I just don't understand enough about security holes to know what you're saying, but maybe someone else will.

Paul M 01-07-2012 09:32 PM

I think all they are saying is someone linked to a php file using an IMG tag.

Ive removed the links from this thread as the pop-up was annoying.

Max Taxable 01-07-2012 11:09 PM

Quote:

Originally Posted by Paul M (Post 2284963)
I think all they are saying is someone linked to a php file using an IMG tag.

Ive removed the links from this thread as the pop-up was annoying.

And since there was no way to read the source code, no real way to tell what all was in the file.

kh99 01-08-2012 12:06 AM

Quote:

Originally Posted by Max Taxable (Post 2285002)
And since there was no way to read the source code, no real way to tell what all was in the file.

OK, but how is that a security hole (and what does it have to do with cookies)? Maybe if they are saying that someone was able to upload a php file as an image, then run it by putting it in an IMG tag? (No, that doesn't make sense, you could run it without the img tag).


All times are GMT. The time now is 02:28 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01129 seconds
  • Memory Usage 1,729KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete