The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#4
|
|||
|
|||
![]() Quote:
Try this: 1) Login to vbulletin.org 2) Delete the cookies highlighted below: ![]() 3) Close your browser completely (ending any authentication sessions) 4) Visit vbulletin.org 5) You are re-authenticated So, surely this means that vBulletin is reauthenticating you based on your hashed password value (it doesn't matter how it is hashed) and your user ID. This means that should vbulletin.org be attacked via an XSS flaw, an attacker could load an iframe on vbulletin.org of a malicious website and steal my cookie, using it to cleanly authenticate. Are my assumptions here correct? |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|