Waraxe IT Security Portal
Login or Register
September 22, 2026
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 161
Members: 0
Total: 161
Full disclosure
[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2)
[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8)
[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)
[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)
[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2)
[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)
[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8)
[0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8)
**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)
CVE-2026-52307: Stored XSS in 1CMS v5.6
HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 /CVE-2026-12556
Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists
O-CMS 1.0.0 Authenticated OS Command Injection viaai_cli_script
Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion
Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> PhpBB -> Need some help...
Post new topicReply to topic View previous topic :: View next topic
Need some help...
PostPosted: Sun Aug 03, 2008 5:37 pm Reply with quote
Lolipop
Regular user
Regular user
Joined: Aug 03, 2008
Posts: 7




Hi!

I own a free forum, and after 6 months of working I have some problems.
Some of my members (I don`t know who) are stealing my art work, my ideas, topics... pretty much everything I own and then post this on their forums. They are doing this on purpose and I warned them already for many times, but they just ignore me. Some of them already banned me from their forums so I am not able to warn them anymore.

I also send a compalint to people who are offering that kind of free forums, but it seems they are powerless in that kind of cases. So I decided to try the dirty way... All in all I am against hacking, but in this case I don`t see any other way/solution.

So, can anyone help? Perhaps with short tutorial, how to hack into phpBB2 forum? I have problems with cookies, because when I want to change them (and I am not registrated on "victim`s" forum), there is no forum address... just some forumlogix.com site...

However, I would be really happy, if someone would help me out of this unbearable situation.

Thanks!
View user's profile Send private message MSN Messenger
PostPosted: Thu Aug 07, 2008 2:33 pm Reply with quote
Lolipop
Regular user
Regular user
Joined: Aug 03, 2008
Posts: 7




Any one? Plz, I would really need some help. Thanks
View user's profile Send private message MSN Messenger
PostPosted: Thu Aug 07, 2008 2:47 pm Reply with quote
oniric
Advanced user
Advanced user
Joined: Jul 24, 2008
Posts: 65




I'm not sure I correctly understood but if there is no forum URL, (i.e. the forum is located at http://www.somesite.com/ instead of the common http://www.somesite.com/forum ) then the Cookie path is only "/", without quotes.
View user's profile Send private message
PostPosted: Thu Aug 07, 2008 3:01 pm Reply with quote
Lolipop
Regular user
Regular user
Joined: Aug 03, 2008
Posts: 7




The problem is, that when I am NOT logged in forum, there are absolutuley no cookies from this forum. How`s this possible?
View user's profile Send private message MSN Messenger
PostPosted: Thu Aug 07, 2008 3:09 pm Reply with quote
oniric
Advanced user
Advanced user
Joined: Jul 24, 2008
Posts: 65




Yes, is possible indeed. But you can login to obtain a session and then change your cookies with a browser extension for example Cookie Editor for Firefox.


Last edited by oniric on Thu Aug 07, 2008 4:10 pm; edited 1 time in total
View user's profile Send private message
PostPosted: Thu Aug 07, 2008 3:24 pm Reply with quote
Lolipop
Regular user
Regular user
Joined: Aug 03, 2008
Posts: 7




Cookie Editor..hmmm... ok I`ll try. Thanks.
View user's profile Send private message MSN Messenger
PostPosted: Sun Aug 10, 2008 8:19 am Reply with quote
Lolipop
Regular user
Regular user
Joined: Aug 03, 2008
Posts: 7




uf grrrr... can`t do it! Anyone can help? plz Rolling Eyes
View user's profile Send private message MSN Messenger
PostPosted: Sun Aug 10, 2008 12:11 pm Reply with quote
lenny
Valuable expert
Valuable expert
Joined: May 15, 2008
Posts: 275




I am confused as to your exact problem. Just use "Clear private data" in either Firefox or IE. Then you need to register a new account on the victims forum... if thats any help
View user's profile Send private message
PostPosted: Fri Aug 22, 2008 12:43 pm Reply with quote
ketchup
Regular user
Regular user
Joined: May 16, 2006
Posts: 23
Location: no




Describe as detailed as possible what your problem is, with only relevant
information.

-Version of phpbb
-exploit you are trying to use
-whats going wrong
-what don't you understand
-

also before asking, do some research

Greetz ketchup
View user's profile Send private message
PostPosted: Fri Aug 22, 2008 7:16 pm Reply with quote
Lolipop
Regular user
Regular user
Joined: Aug 03, 2008
Posts: 7




I did some research already... last I was checking this topic.

The forum must be 2.0.× - I can not find out the last number, I was trying use, what Howitzer gave, but it just doesn`t work.

I have problem already at the beginning...

Code:
127.0.0.1 FALSE / FALSE 1141920503 phpbb2mysql_data a%3A0%3A%7B%7D


There is only one FALSE, the other one is TRUE...

How should I say... I am,... well quite lost in this Rolling Eyes
View user's profile Send private message MSN Messenger
Need some help...
www.waraxe.us Forum Index -> PhpBB
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT
Page 1 of 1

Post new topicReply to topic


Powered by phpBB © 2001-2008 phpBB Group



PCWizardHub - Helping you fix, build, and optimize your PC life
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.036 Seconds