Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 04-17-2009, 04:57 AM
rob01 rob01 is offline
 
Join Date: Sep 2008
Location: Mexico
Posts: 410
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default new vb exploit! :S

there is a new vb exploit problem!


im not sure if it was already fixed in verison 3.8.2, but is still available under 3.8.1 and 3.8.2



picture::



cheers


ahh sorry about the double post... pls delete the other post
Reply With Quote
  #2  
Old 04-17-2009, 05:13 AM
Michael.A's Avatar
Michael.A Michael.A is offline
 
Join Date: Dec 2008
Location: L.A
Posts: 449
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

how did u use the same name????
Reply With Quote
  #3  
Old 04-17-2009, 05:15 AM
rob01 rob01 is offline
 
Join Date: Sep 2008
Location: Mexico
Posts: 410
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

is a name exploit ! all vb 3.8.* has it
Reply With Quote
  #4  
Old 04-17-2009, 12:12 PM
TigerC10's Avatar
TigerC10 TigerC10 is offline
 
Join Date: Apr 2006
Location: Austin, TX
Posts: 616
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It results from a bad import of data, it's not an exploit - it's bad administration.
Reply With Quote
  #5  
Old 04-17-2009, 12:55 PM
BlueNinjaGo's Avatar
BlueNinjaGo BlueNinjaGo is offline
 
Join Date: Mar 2009
Posts: 668
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by TigerC10 View Post
It results from a bad import of data, it's not an exploit - it's bad administration.
Like how? So I can avoid it...
Reply With Quote
  #6  
Old 04-17-2009, 01:35 PM
nexialys
Guest
 
Posts: n/a
Default

an Exploit is something that can help a hacker insert or extract data from the engine, not changing username of a member post...

and from what i see from the screeny, if it's not a very modified vBulletin *(with possible flaws due to modifications) it's a phpBB forum.
Reply With Quote
  #7  
Old 04-17-2009, 02:09 PM
TigerC10's Avatar
TigerC10 TigerC10 is offline
 
Join Date: Apr 2006
Location: Austin, TX
Posts: 616
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by BlueNinjaGo View Post
Like how? So I can avoid it...
One case is if you restore a database backup and an error occurs during restoration. Another, more common occurance, is when merging one board into another board where the username already exists. I've even experienced it when an admin switches vB over to something else like PHPBB and then switches back over to vB - duplication occurs.

Anyway, after importing data the admin should always check for username duplication.

Quote:
Originally Posted by nexialys View Post
an Exploit is something that can help a hacker insert or extract data from the engine, not changing username of a member post...
I disagree, if a person were able to change their username upon post - it is still an exploit. It may not be a traditional "hack", but it is still considered an exploit.

Quote:
Originally Posted by nexialys View Post
and from what i see from the screeny, if it's not a very modified vBulletin *(with possible flaws due to modifications) it's a phpBB forum.
If it is a PHPBB forum, then they're using the vBulletin online status image next to the username.
Reply With Quote
  #8  
Old 04-17-2009, 02:18 PM
rob01 rob01 is offline
 
Join Date: Sep 2008
Location: Mexico
Posts: 410
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

is not PHPBB

is not a bad merge since this forum has been using vb since ages, and is not a databese backup , since this is posible to do in other vb forums

cheers

i dont think the other vb forums have the same problem of bad import data

but this forum is since 2007 or older.. and they always have used vb
Reply With Quote
  #9  
Old 04-17-2009, 02:57 PM
TigerC10's Avatar
TigerC10 TigerC10 is offline
 
Join Date: Apr 2006
Location: Austin, TX
Posts: 616
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It could be a database backup, do you host this website yourself or do you have a hosting provider? Because I've known hosting providers to lose servers and restore backups only to have a hitch in the backup or in the restoration of the backup.

EDIT:
Nevermind, I figured this one out. Instead of using a standard "M" in the username, this person used the greek letter Mu html character code "Μ" or "Μ". This allows for a completly new user with the name that looks just like someone else's since the character "Mu" is not the same as M.

Here's a list of some other greek symbols that can be used for registration fake outs:
http://www.w3schools.com/tags/ref_symbols.asp

Alpha, Beta, Epsilon, Zeta, Eta, Iota, Kappa, Mu, Nu, Omicron, Rho, Tau, Upsilon, Chi


To fix it, add these to your illegal user names

AdminCP -> vBulletin Options -> User Registration Options -> Illegal User Names
Code:
Α Β Ε Ζ Η Ι Κ Μ Ν Ο Ρ Τ Υ Χ ν ο
Code:
Α Β Ε Ζ Η Ι Κ Μ Ν Ο Ρ Τ Υ Χ ν ο
Or if you really want to be strict about it, just add a singular semicolin like ';' to the illegal name list.
Reply With Quote
  #10  
Old 04-17-2009, 03:23 PM
BlueNinjaGo's Avatar
BlueNinjaGo BlueNinjaGo is offline
 
Join Date: Mar 2009
Posts: 668
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Nevermind, didn't see your edit.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 10:12 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.06212 seconds
  • Memory Usage 2,251KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_code
  • (4)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (9)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete