The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Weird security flaw
THe other day I was chatting via MSN with one of my fellas and I sent him a full URL to my forums including the session id string...
It was the URL to a new thread posted by me. My surprise was when I reloaded the thread to see his answer.... HE WAS ME! He was posting with MY (admin) account!! Can this be caused by any hack I've installed (sounds familiar to any1?) or is it just the security flaw you mentioned in v2.3.0? Coz I don't have much time right now for an update and I'd like to hear from you first. Thanks! |
#2
|
||||
|
||||
yep it's probably down to a hack, i would check what hacks you've installed and also install the 'clean session hash' by anime-loo to try and prevent anything like this in the future.
|
#3
|
|||
|
|||
Can u think of any close hack that would do that? Most of the hacks i've installed are cosmetic hacks, afaik i'ven't installed any dealing with sessions nor cookies...
|
#4
|
||||
|
||||
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|