vBulletin Modifications

Warning Serious Flaws in Htaccess / Ip restriction Hack(s)!

Welcome to vBHackers.com! - vBHackers Updates:

Go Back   vBulletin Modifications > General vBulletin Section > General vBulletin Support

Reply
 
LinkBack Thread Tools
Old 09-03-2005, 10:21 AM   #1
Advanced Coder
Niels's Avatar
Join Date: Jun 2004
Real Name: Niels
Location: NL
Niels is on a distinguished road

Default Warning Serious Flaws in Htaccess / Ip restriction Hack(s)!

Thread:
IP Restriction 1.2 + Fake 404/Fake 403/Redirect
Sql injection thread: the one from fury will look up later ;)

Flaw:
You must first be a registered member to view any code.
With register_globals set to Off use this to get in with an false ip:
http://forum-url.com/index.php?w00t=true
And You are inside!

Fix:
Set register_globals to on or:
You must first be a registered member to view any code.
In the new htaccess/ip hack by Fury it's fixed by setting $valid / $w00t to false before the ip check so he just adds $valid = "false";
The ip restriction/htaccess hack by Isaiah had this flaw also but I can't find the code anymore ? :S

Then another last word in the mysql query for htaccess many hacks are using something like this:
You must first be a registered member to view any code.
$_SERVER['PHP_AUTH_USER']
isn't addslasht before the query!!!
Username: ' OR username = '
With this the script could be vuln to sql injections although it would be hard to find any damiging code...
Fix:
You must first be a registered member to view any code.
This post is NOT any critic on these hacks!!! It's for information and security...

I hope you enjoyed AND/OR learned from this post.

Greets,
Niels AKA Slash.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 09-03-2005, 05:45 PM   #2
Member
Join Date: Jun 2005
biocore is on a distinguished road

Default

Real nice work mate, respect, i hope you test the one from fury soon too ;)




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-08-2005, 04:26 PM   #3
Coder
Join Date: Aug 2004
Fury is on a distinguished road

Default

pff, you tested the hack of my hack glad you found some security issiues that should be fixed and one's that i fixed already cool mate. Thanks for the effort!




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -3. The time now is 10:53 PM.


SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc. (Patent Pending)