| View previous topic :: View next topic |
| Author |
Message |
stack
Cadet

 Joined: Dec 12, 2002 Posts: 1 Location: USA
|
Posted: Thu Dec 12, 2002 6:59 am Post subject: Site vulnrable ?? |
|
|
It seems to me that your site is vulnrable. If you allow me, I can test it and give u the suggestions.
-Stack
|
|
| Back to top |
|
 |
cj
Site Moderator Premium Member
 Joined: Mar 06, 2002 Posts: 647 Location: USA
|
Posted: Thu Dec 12, 2002 7:25 am Post subject: |
|
|
Hello stack and welcome to CCSP. Wishing that you enjoy your stay.
If there are any vulnerablities to your finding please submit your results with full details to the site Admin. His name is Paul and he shall contact you a.s.a.p.
Admin Contact:
Paul Laudanski
paul{-AT-}computercops.biz
Thank you,
-cj.-
______
|
|
| Back to top |
|
 |
stack
Guest IP: 210.214.*.*
|
Posted: Thu Dec 12, 2002 7:32 am Post subject: |
|
|
Ok...i will e-mail him..thx..
-Stack
|
|
| Back to top |
|
 |
cj
Site Moderator Premium Member
 Joined: Mar 06, 2002 Posts: 647 Location: USA
|
Posted: Thu Dec 12, 2002 7:58 am Post subject: |
|
|
Glad to have you on board and active on site!
Thanks for posting!
|
|
| Back to top |
|
 |
Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
|
| Back to top |
|
 |
stack
Guest IP: 210.214.*.*
|
Posted: Fri Dec 13, 2002 12:17 pm Post subject: :) |
|
|
Glad to see such a wonderful and practical admin !!
-Stack it..
<b onMouseOver="alert(document.location);">Here is a poosible exploit !! Move ur mouse here and you will see something. A malicious user can possibly exploit this. Disable HTML codes!!</b>
|
|
| Back to top |
|
 |
stack
Guest IP: 210.214.*.*
|
Posted: Fri Dec 13, 2002 12:19 pm Post subject: |
|
|
It's possible to write such a code to steal cookie of another users using this html-code exploit.
-Stack..
|
|
| Back to top |
|
 |
stack
Guest IP: 210.214.*.*
|
Posted: Fri Dec 13, 2002 12:22 pm Post subject: also.. |
|
|
Also..why don't u update to phpBB 2.0.3 ? There may be other bugs in older version.
-Stack..
|
|
| Back to top |
|
 |
Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
Posted: Fri Dec 13, 2002 12:41 pm Post subject: |
|
|
Hmm, I thought I disabled HTML completely. Well now it is. I've been too caught up in my daily work schedule to upgrade the site so I've been patching and locking things down in the meantime.
I am expecting some time in January to begin upgrading the software. _________________ Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
|
|
| Back to top |
|
 |
|
|