Vcoderz Community
We create websites that have it all, beauty & brains
Lebanon Web Design & Development - Coddict
 

Go Back   Vcoderz Community > Computer Zone > Computers & Information Technologies

Notices

Computers & Information Technologies « Everything related to computers and internet. »

Reply
 
Share Thread Tools Search this Thread
Old 04-23-2007   #1
HizbullaH
Registered Member
 
HizbullaH's Avatar
 
Last Online: 09-06-2011
Join Date: Oct 2006
Posts: 397
Thanks: 262
Thanked 215 Times in 87 Posts
Groans: 0
Groaned at 0 Times in 0 Posts
Default XSS In All The Versions Of Vbulletin

I Was Checking The Latest Exploits.
And I Found An Exploit For All The Versions Of Vbulletin!
The Exploit Is Somehow Complicated, But It Will Allow You Steal Cookies Through XSS.
Its Idea Is To Inject Somethings To A Spacer PNG Image Using The Perl Programming Language And Then Uploading It To The Site (Avatar For Example), Then Injecting The Evil Codes.
I Didn't Apply This Exploit And I Didn't Read It All Because Of The Small Free Time.
But I Think Vcoderz And Other Sites Were Hacked In This Way!

~!~ We Are HizbullaH Rockets On The Net ~!~


__________________
من؟ من سينزع سلاح حزب الله!؟
HizbullaH is offline   Reply With Quote
Old 04-23-2007   #2
Jean
Administrator
 
Jean's Avatar
 
Last Online: 04-16-2018
Join Date: Dec 2005
Posts: 5,085
Thanks: 250
Thanked 3,555 Times in 2,245 Posts
Groans: 3
Groaned at 12 Times in 7 Posts
Default Re: XSS In All The Versions Of Vbulletin

Quote:
Originally Posted by HizbullaH
I Was Checking The Latest Exploits.
And I Found An Exploit For All The Versions Of Vbulletin!
The Exploit Is Somehow Complicated, But It Will Allow You Steal Cookies Through XSS.
Its Idea Is To Inject Somethings To A Spacer PNG Image Using The Perl Programming Language And Then Uploading It To The Site (Avatar For Example), Then Injecting The Evil Codes.
I Didn't Apply This Exploit And I Didn't Read It All Because Of The Small Free Time.
But I Think Vcoderz And Other Sites Were Hacked In This Way!

~!~ We Are HizbullaH Rockets On The Net ~!~
clarification : vcoderz.com wasn't hacked , there was an attack against the forum, but they didn't succeed in any thing.
Jean is offline   Reply With Quote
Old 04-27-2007   #3
god
Registered Member
 
god's Avatar
 
Last Online: 02-14-2010
Join Date: Mar 2006
Posts: 846
Thanks: 71
Thanked 293 Times in 217 Posts
Groans: 0
Groaned at 0 Times in 0 Posts
Default Re: XSS In All The Versions Of Vbulletin

double clarification: Vcoderz was hacked by me several times :P
Bas hizbullah uploading it as an avatar wont work, cuz images are parsed into bytes and inserted in vbulletin's database, and displayed not like normal images, so it wont work
__________________
--Capitalisation is the only difference between "I helped my uncle Jack off a horse" and "I helped my uncle jack off a horse" !!
http://img482.imageshack.us/img482/4889/hell7ta.jpg
god is offline   Reply With Quote
Old 04-27-2007   #4
lebanese_a
Registered Member
 
lebanese_a's Avatar
 
Last Online: 04-15-2018
Join Date: Aug 2006
Posts: 1,549
Thanks: 31
Thanked 213 Times in 151 Posts
Groans: 0
Groaned at 1 Time in 1 Post
Default Re: XSS In All The Versions Of Vbulletin

Quote:
Originally Posted by god
double clarification: Vcoderz was hacked by me several times :P
the forum aw the site?7777777777777777777777777
lebanese_a is offline   Reply With Quote
Old 04-27-2007   #5
god
Registered Member
 
god's Avatar
 
Last Online: 02-14-2010
Join Date: Mar 2006
Posts: 846
Thanks: 71
Thanked 293 Times in 217 Posts
Groans: 0
Groaned at 0 Times in 0 Posts
Default Re: XSS In All The Versions Of Vbulletin

both, anyway lets not drift off topic...
__________________
--Capitalisation is the only difference between "I helped my uncle Jack off a horse" and "I helped my uncle jack off a horse" !!
http://img482.imageshack.us/img482/4889/hell7ta.jpg
god is offline   Reply With Quote
Old 05-02-2007   #6
Dazlingo
Registered Member
 
Dazlingo's Avatar
 
Last Online: 12-13-2007
Join Date: Jan 2007
Posts: 51
Thanks: 0
Thanked 3 Times in 2 Posts
Groans: 0
Groaned at 0 Times in 0 Posts
Default Re: XSS In All The Versions Of Vbulletin

ROFL :P
im not sure about that vb feature ur talking about. last time i checked, the Pictures are stored as is , and the link to them is in the DB, so they can be used.
Dazlingo is offline   Reply With Quote
Reply

  Vcoderz Community > Computer Zone > Computers & Information Technologies

Tags
vbulletin, versions, xss



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 07:34 PM.


Lebanon web design and development
Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Ad Management plugin by RedTyger
Share