|
|
|
|
![]() ![]() |
May 1 2005, 04:27 AM
Post
#1
|
|
|
Newbie ![]() Group: Members Posts: 5 Joined: 28-April 05 Member No.: 6,325 |
A new exploit is already out for phpbb 2.0.13. I've asked the phpbb development team about it, and they say it will be fixed in version 2.0.14.
It's a way to make yourself admin through exploitation of cookie data. Here's the fix anyway: Add $userdata['user_level'] = USER; after every $userdata['user_id'] = ANONYMOUS; in session.php |
|
|
|
May 1 2005, 07:26 AM
Post
#2
|
|
|
Administrator ![]() Group: Admin Posts: 1,480 Joined: 11-June 04 From: Somewhere in Time & Space. Member No.: 1 |
Thanks for sharing this information with us. This will definately help most of the people using PHPbb
|
|
|
|
May 1 2005, 05:07 PM
Post
#3
|
|
|
PhilosopherX ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 106 Joined: 5-February 05 From: Planet X Member No.: 3,613 |
You mean sessions.php, right?
It's located in the includes folder. I found just two instances of CODE $user_id = $userdata['user_id'] = ANONYMOUS; is that all? I don't know PHP very well, so could you confirm that this is all right? Thanks. |
|
|
|
May 1 2005, 06:21 PM
Post
#4
|
|
|
Premium Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 176 Joined: 26-April 05 From: Manchester Member No.: 6,203 |
I beleve it is,
You should take up a cource in php or asp. Its really cool or you could go onto Win server 2005 or 4, which ever ones out now. Anyway, as usual my sig- Thanks, FFC Webmaster, Asad Haider. |
|
|
|
May 1 2005, 06:41 PM
Post
#5
|
|
|
Premium Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 150 Joined: 29-March 05 Member No.: 4,988 |
Thanks for telling us about this flaw. I upgraded as soon as I found this out!
To everoyne else - Make sure that you upgrade your version of phpBB as soon as possible, it is a good habbit to always upgrade |
|
|
|
May 6 2005, 02:24 AM
Post
#6
|
|
|
Newbie ![]() Group: Members Posts: 7 Joined: 6-May 05 Member No.: 6,684 |
Yes I strongly Advise everyone on phpBB to upgrade to 2.0.14 ASAP. My Clan was on phpBB 2.0.13 and some people who disliked us did the same thing and deleted our forums several times.
|
|
|
|
May 9 2005, 08:23 AM
Post
#7
|
|
|
Advanced Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 113 Joined: 14-January 05 From: Philippines Member No.: 3,271 |
why not just upgrade to 2.0.15? it's already released.
|
|
|
|
![]() ![]() |
Similar Topics
|
Lo-Fi Version | Time is now: 7th October 2008 - 04:31 AM |