| 
  
    | 
	|  | Menu |  |  
     
     | 
      
       | 
        
         | 
          
           | 
						|  |  |  Home |  |  |  |  |  |  |  |  Discussions |  |  |  |  |  |  |  |  Tools |  |  |  |  |  |  |  |  Affiliates |  |  |  |  |  |  |  |  Content |  |  |  |  |  |  |  |  Info |  |  |  |  |  |  |  |  |  |  
  
    | 
	|  | User Info |  |  
     
     | 
      
       | 
        
         | 
          
           |  Membership: 
  Latest: MichaelSnaRe 
  New Today: 0 
  New Yesterday: 0 
  Overall: 9144 
 
  People Online: 
  Visitors: 480 
  Members: 0 
  Total: 480 
 |  |  |  |  |  
  
    | 
	|  | Full disclosure |  |  
     
     | 
      
       | 
        
         | 
          
           | CyberDanube Security Research 20251014-0 | Multiple Vulnerabilities in Phoenix Contact QUINT4 UPS apis.google.com - Insecure redirect via __lu parameter(exploited in the wild)
 Urgent Security Vulnerabilities Discovered in Mercku Routers Model M6a
 Re: Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
 Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
 [SBA-ADV-20250730-01] CVE-2025-39664: Checkmk Path Traversal
 [SBA-ADV-20250724-01] CVE-2025-32919: Checkmk Agent Privilege Escalation via Insecure Temporary Files
 CVE-2025-59397 - Open Web Analytics SQL Injection
 Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
 Re: Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
 Re: Defense in depth -- the Microsoft way (part 93): SRP/SAFERwhitelisting goes black on Windows 11
 Re: [FD]: "Glass Cage" – Zero-Click iMessage ? Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885)
 Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
 Samtools v1.22.1 Uncontrolled Memory Allocation from Large BED Intervals Causes Denial-of-Service in Samtools/HTSlib
 Samtools v1.22.1 Improper Handling of Excessive Histogram Bin Counts in Samtools Coverage Leads to Stack Overflow
 
 |  |  |  |  |  | 
  
    | 
	|  |  |  |  
        
          | 
              
                | 
                    
                      | 
                          
                            | 
	| 
	
		|  |  |  
		|  | IT Security and Insecurity Portal |  |  
 
	|  | PHPBB 2.13 new exploit |  |  
	| 
	
		|  Posted: Sat Mar 26, 2005 2:31 am |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| kontol_ngaceng |  | Beginner |  |  
  |  |  |  | Joined: Mar 26, 2005 |  | Posts: 2 |  |  |  |  
 
 |  |  
			|  |  |  
 
 |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Sat Mar 26, 2005 11:27 am |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| y3dips |  | Valuable expert |  |  
  |  |  |  | Joined: Feb 25, 2005 |  | Posts: 281 |  | Location: Indonesia |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| please read the article clearly, that guy only find that after failed exploitation (path forum) the guest (attacker) still mark as an admin , n he still finding out how to use it or take more advantage from this situation <-- this from what i understand by reading that
 
 so i guest he put a wrong title for that article (post)
 
 CMIIW
 |  |  
		| 
		
			| _________________
 IO::y3dips->new(http://clog.ammar.web.id);
 |  |  |  
	|  |  |  | 
 
	|  |  |  |  
	| 
	
		|  Posted: Tue Mar 29, 2005 10:28 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| kontol_ngaceng |  | Beginner |  |  
  |  |  |  | Joined: Mar 26, 2005 |  | Posts: 2 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| I have found this 
  	  | Quote: |  	  | ------------------------------------------------------------------------
 # phpBB 2.0.13 user level exploit
 # By : Morinex
 # e-mail : m0r1n3x@gmail.com
 # date : 20-03-2005
 # greetz : Ali7 (for helping me =P) , Zeltha , [code] , ASC and w00pie.NL
 
 Exploit not founded by me!
 Dunno who is the founder of this bug.
 The original not works so i have fixed the some shit.
 
 *Spechial thx 2 the founder of this bug*
 
 
 This one goes for all phpBB versions up to 2.0.13. While applying and
 testing the
 patch for the autologin bug I found that phpBB2 doesn't reset the
 $userdata['user_level']
 variable after a failed autologin.
 
 This is the vulvernable code in sessions.php:
 
 Code:
 f ( $user_id != ANONYMOUS )
 {
 $auto_login_key = $userdata['user_password'];
 
 if ( $auto_create )
 {
 if ( isset($sessiondata['autologinid']) && $userdata['user_active'] )
 {
 // We have to login automagically
 if( $sessiondata['autologinid'] === $auto_login_key )
 {
 // autologinid matches password
 $login = 1;
 $enable_autologin = 1;
 }
 else
 {
 // No match; don't login, set as anonymous user
 $login = 0;
 $enable_autologin = 0;
 $user_id = $userdata['user_id'] = ANONYMOUS;
 }
 }
 else
 {
 // Autologin is not set. Don't login, set as anonymous user
 $login = 0;
 $enable_autologin = 0;
 $user_id = $userdata['user_id'] = ANONYMOUS;
 }
 }
 else
 {
 $login = 1;
 }
 }
 else
 {
 $login = 0;
 $enable_autologin = 0;
 }
 
 
 As you can see, if autologin fails it will reset the
 $userdata['user_id'] value to
 ANONYMOUS, but $userdata['user_level'] stays at the value of the user
 account that
 failed to login.
 
 Now phpBB only checks for the userlevel in various locations and
 ignores the user_id
 there. So if you manipulate the "_data" cookie to send the user_id of an admin
 you can see some information that should only be visible to an admin.
 Like hidden
 users on the "who is online page" or email adresses from users, even if the
 user disallowed that, in their profiles. Maybe you can even use some
 admin functions,
 I didn't check this in depth.
 
 The cookie manipulation will only work on the first page requestet, as
 the session.php
 will then overwrite the user_id in it, unless you prevent the browser from
 modifying the cookie of course.
 
 The fix is quite simple, add $userdata['user_level'] = USER; after
 every $userdata['user_id']
 = ANONYMOUS; in session.php.
 
 *Reported 2 PHPBB ^^
 
 
 Morinex
 
 
 | 
 
 
 Look like the bugs is there..but haven't found anyone wrote working script to run it.
 
 Might be one of member will write it ?
 |  |  
		|  |  |  
	|  |  |  | 
 
	|  |  |  |  
	| 
	
		|  Posted: Tue Mar 29, 2005 10:35 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| mecha |  | Beginner |  |  
  |  |  |  | Joined: Mar 30, 2005 |  | Posts: 2 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| Let's hope it works, can't wait  |  |  
		|  |  |  
	|  |  
	| www.waraxe.us Forum Index -> PhpBB 
 
	
		| You cannot post new topics in this forum You cannot reply to topics in this forum
 You cannot edit your posts in this forum
 You cannot delete your posts in this forum
 You cannot vote in polls in this forum
 
 | All times are GMT Page 1 of 1
 
 |  |  
	|  |  
 Powered by phpBB © 2001-2008 phpBB Group
 
 
 
 
 |  |  |  |  |  |