The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
![]()
A user on my forum turned me on to a BB code exploit. I'm using 4.2.2
A php script could be used to deliver a popup window simply by placing a link to it in the [ IMG ] tags. Upon opening the post or private message, the code is executed and the "victim" gets the popup prompt and displays their IP address (login credentials if the enter them). I tried the censor feature and blocked most of the common programming extensions but it's creating other issues. Does anyone have another idea that might work? Thanks. Here's an example (check the bb code): ![]() |
#2
|
||||
|
||||
![]()
I don't think this has anything to do with the .php extension.
If you image-link to an image (or any file) that is behind an .htaccess password protected directory the web browser automatically pops up the log-in box asking for credentials before it can download the image. There is no php code executed. It's not an exploit of any type, it is simply how all web browsers behave when faced with accessing a password protected directory. Which by the way, you should never put your username/password into such a box unless you know what site has created said box and are legitimately trying to log in- the admin of the remote site can be recording the usernames/passwords being tried in the form. This would happen on all versions of vBulletin, and indeed *any* forum software that allows [IMG] bbcode. |
Благодарность от: | ||
tbworld |
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|