Re: [Full-Disclosure] Re: Authentication flaw in Web Wiz forum

From: Bruce Corkhill (bruce_at_webwizguide.info)
Date: 03/02/04

  • Next message: Shachar Shemesh: "Re: [Full-Disclosure] Israeli Judge has Enlighted Outlook on Hacking"
    To: "Alexander" <pk95@yandex.ru>
    Date: Tue, 02 Mar 2004 22:18:15 +0000
    
    

    Yet again!! Alexander aka. Pig Killer and Michael have found there report
    to be incorrect and have tried to retract it but not fully with another
    incorrect bug report.

    The Forgotten Password feature requires the user to enter details about
    themselves including user name, email address, etc. that they used when
    registering. Only once this data is entered correctly is a new password
    emailed to the users emails address.

    So the security flaw mentioned by Alexander aka. Pig Killer and Michael is
    incorrect as it is not applicable when using this feature.

    If you are using Web Wiz Forums then please ignore all bug reports by
    Alexander aka. Pig Killer and Michael as they are incorrect (and not for
    the first time!!) so you do not need to worry or email the site for a new
    version.

    At 21:40 02/03/2004, you wrote:

    >Hi all again!
    >
    >This bug works only when password changes using "Forgotten your password?"
    >future.
    >
    >The user code is changed when changing the password using "user profile".
    >
    >Sorry for my mistake.
    >
    >
    >----- Original Message -----
    >From: "Alexander" <pk95@yandex.ru>
    >To: <full-disclosure@lists.netsys.com>
    >Cc: "Bruce Corkhill" <bruce@webwizguide.info>
    >Sent: Wednesday, March 03, 2004 12:20 AM
    >Subject: Authentication flaw in Web Wiz forum
    >
    >
    > > Product: Web Wiz forum 7.0-7.7a www.webwizforum.com
    > >
    > > Risk: Medium
    > >
    > > Date: 02 March, 2004
    > >
    > > Autor: Pig Killer and Michael ( www.SecurityLab.ru)
    > >
    > >
    > >
    > > When user log on forum, for his cookies identification forum using
    >User_code
    > > value from tblAutor table from underlying database, which doesn't change
    > > with changing of password. As a result, when user change password, he can
    > > register in the forum using old cookies. As a result, if users cookies was
    > > compromised (for example by XSS), then even password changing will doesn't
    > > protect his account from unauthorized using.
    > >
    > >
    > >
    > > The forum also allows logged in user to change the password without
    >entering
    > > the old one. Thus, having cookie, you can change the password without
    > > knowing the old one.
    > >
    >
    >_______________________________________________
    >Full-Disclosure - We believe in it.
    >Charter: http://lists.netsys.com/full-disclosure-charter.html

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Shachar Shemesh: "Re: [Full-Disclosure] Israeli Judge has Enlighted Outlook on Hacking"

    Relevant Pages

    • Re: how can this be ???
      ... incorrect - or are you stating that all posts in that forum are incorrectly ... Of course if the battery were defective, ... >>> Colin ... ...
      (microsoft.public.windowsxp.basics)
    • Re: use assert and defensive together
      ... It would be better if you used different return codes for each type of failure, but I'm not going to fix al of your code. ... because the calling program is notified and will report to the user that it failed and if the calling program is any good at all will report the reason for the failure. ... But by confusing programming errors with incorrect paths, you are bug hiding. ... The function is therefore incorrect because it should use them or incorrect because it takes them. ...
      (comp.lang.c)
    • [Full-Disclosure] Re: Authentication flaw in Web Wiz forum
      ... The security flaw reported below is incorrect as they state that the user ... password then the user code is not changed so the user doesn't have to log ... back in if they request a new password from the forum admin. ... for his cookies identification forum using User_code ...
      (Full-Disclosure)
    • Re: Keywords: "Ray Haddad" "Fake Vietnam Vet" "USS Ranger" "Valor Thief" (was: Re: writing is va
      ... No proof at all, just incorrect data. ... The port visits were cancelled. ... Compiled in August 2003 by the Naval Aviation History ... Ranger Command History Report for 1974. ...
      (misc.writing)
    • Re: Keywords: "Ray Haddad" "Fake Vietnam Vet" "USS Ranger" "Valor Thief" (was: Re: writing is va
      ... Sylvia is at it again. ... No proof at all, just incorrect data. ... Ranger Command History Report for 1974. ...
      (misc.writing)

    Loading