The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
![]()
vbulletin staff please send out a security bulletin regarding this issue.
What is happening: A user is posting a thread or reply with a image that on mouseover, records the users cookie onto a .php file page, which is printing out the data to a .txt file. The data being recorded is the cookie information of the user mousing over the image. When the user does the mouseover on the image, the image will disappear, when that happens, the cookie information is recorded to the external site. This makes it easy for someone to login as another user, including admins. all the exploiter has to do is edit their cookie file, save it, and visit the site and they are logged in as the user. Admins need to be careful.... This has happened to only 2 forums i know of right now, including mine. After reading the code in the thread that the user posted, its being done using HTML. now, we are always told to disable HTML on our forums, but LOTS of people use it because its a handy tool for users on our forums to play with. so i guess the only fix, besides disabling the HTML on your forums, is to censor out these keywords that are needed for the recording of the cookie data: Quote:
Note: im not sure if "document.sam.src=" is needed to be censored. i think just censoring onMouseover is good enough... |
#2
|
|||
|
|||
![]()
eh thats why vbulletin asks you not to enable html. simple solution reallly
|
#3
|
|||
|
|||
![]()
like Enigma just said... most forum softwares now disable HTML in posts...
so if you've been fool enough to activate it on a large public website, you now learn your lesson. |
#4
|
||||
|
||||
![]()
Enabling HTML is a foolish thing to do.
|
#5
|
|||
|
|||
![]()
where is the option to enable or disable html in the admincp anyways?
|
#6
|
||||
|
||||
![]()
Interesting cause this is also happening with MySpace..........
|
#7
|
||||
|
||||
![]() Quote:
Unless you have installed my modification which makes it a per-usergroup setting. Anyone who has enabled that for non-admins is a tad on the silly side, IMO. |
#8
|
|||
|
|||
![]() Quote:
![]() Personally, i think your flippin crazy to have it enabled any where. |
#9
|
||||
|
||||
![]() Quote:
There is the odd time where I totally forget, and post dodgy cookie-stealing code on my site. ![]() |
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|