Welcome Guest ( Log In | Register)



 
Reply to this topicStart new topic
> Phpbb 2.0.13 Important
jamal
post May 1 2005, 04:27 AM
Post #1


Newbie
*

Group: Members
Posts: 5
Joined: 28-April 05
Member No.: 6,325



A new exploit is already out for phpbb 2.0.13. I've asked the phpbb development team about it, and they say it will be fixed in version 2.0.14.

It's a way to make yourself admin through exploitation of cookie data. Here's the fix anyway:

Add
$userdata['user_level'] = USER;

after every
$userdata['user_id']
= ANONYMOUS;

in session.php
Go to the top of the page
 
+Quote Post
OpaQue
post May 1 2005, 07:26 AM
Post #2


Administrator
Group Icon

Group: Admin
Posts: 1,480
Joined: 11-June 04
From: Somewhere in Time & Space.
Member No.: 1



Thanks for sharing this information with us. This will definately help most of the people using PHPbb
Go to the top of the page
 
+Quote Post
gunbound
post May 1 2005, 05:07 PM
Post #3


PhilosopherX
*******

Group: Members
Posts: 106
Joined: 5-February 05
From: Planet X
Member No.: 3,613



You mean sessions.php, right?

It's located in the includes folder.

I found just two instances of

CODE
$user_id = $userdata['user_id'] = ANONYMOUS;


is that all?

I don't know PHP very well, so could you confirm that this is all right?

Thanks.
Go to the top of the page
 
+Quote Post
mbd5882
post May 1 2005, 06:21 PM
Post #4


Premium Member
********

Group: Members
Posts: 176
Joined: 26-April 05
From: Manchester
Member No.: 6,203



I beleve it is,

You should take up a cource in php or asp.
Its really cool or you could go onto Win server 2005 or 4, which ever ones out now.

Anyway, as usual my sig-
Thanks,
FFC Webmaster,
Asad Haider.
Go to the top of the page
 
+Quote Post
Odyssey
post May 1 2005, 06:41 PM
Post #5


Premium Member
********

Group: Members
Posts: 150
Joined: 29-March 05
Member No.: 4,988



Thanks for telling us about this flaw. I upgraded as soon as I found this out!
To everoyne else - Make sure that you upgrade your version of phpBB as soon as possible, it is a good habbit to always upgrade
Go to the top of the page
 
+Quote Post
eX_Raven_
post May 6 2005, 02:24 AM
Post #6


Newbie
*

Group: Members
Posts: 7
Joined: 6-May 05
Member No.: 6,684



Yes I strongly Advise everyone on phpBB to upgrade to 2.0.14 ASAP. My Clan was on phpBB 2.0.13 and some people who disliked us did the same thing and deleted our forums several times.
Go to the top of the page
 
+Quote Post
mobious
post May 9 2005, 08:23 AM
Post #7


Advanced Member
*******

Group: Members
Posts: 113
Joined: 14-January 05
From: Philippines
Member No.: 3,271



why not just upgrade to 2.0.15? it's already released.
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Read This Before Applying For Hosting!(58)
  2. Phpbb - Free Skins(6)
  3. Highly Important Warning About These Free Sites(48)
  4. How To Put A Phpbb Login Box On Your Main Site.(18)
  5. Phpbb Forum Skins(6)
  6. Free Forum Hosting With No Annoying Ads!(29)
  7. Phpbb Forum Site Transfer(20)
  8. Have You Ever Heard Discuz?(7)
  9. Important Things To Be Followed By Everyone!(12)
  10. How To Improve Security Of Your Website?(3)
  11. *** Virus Alert *** Important ***(14)
  12. Some Basic But Important Info About Cancer(3)
  13. How To Improve Analytical Writing (aw) Skills In Gre?(3)
  14. Transferring From Old Server To New Server "database And Forum" [resolved](5)
  15. Vitamin, An Important Nutrient(3)
  1. Deleted Some Important Files In Your Usb/ Mem Stick?(1)
  2. Blood Grouping System(3)
  3. Phpbb Mods That You Should Get For Your Phpbb3 Forum(9)
  4. Hackers Hijack A Half-million Sites: Phpbb Forum Users Must Read(8)
  5. Agent-principal Relationships(0)
  6. In-laws(0)
  7. Phpbb Or Phpnuke?(3)
  8. Important To Get A Job(3)
  9. Domain Problem : This Is Important..(0)
  10. [v.i.q] Shows Ltd. Com Worth Million$ ?(2)
  11. Help With Compiling My Server(0)
  12. 2008 Presidential Debates(4)
  13. Forever Remembered(0)


 



- Lo-Fi Version Time is now: 7th October 2008 - 04:31 AM