Invision Power Board 'Allow auto login' setting override

From: Hillel Himovich (hll_at_netvision.net.il)
Date: 11/30/04

  • Next message: Black Dot: "Re: Winamp - Buffer Overflow In IN_CDDA.dll"
    Date: 30 Nov 2004 20:38:55 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    This next Vulnerability was discovered by Keyboard_Criminal <matan.marciano at gmail.com>

    IPB Has a setting that enables admins to disable members from auto-login to the forums
    This can be easily bypassed using this next method:

    1. Use the password reset form and enter there requested nickname.
    2. When you get the email, follow the instructions.

    After filling the form with the user id, the security code and the new password
    you will auto login to the forms, and any attempt to come back to the forums will also result in an auto-login because user id and pass hash are saved in the cookies.

    This method culd be used to save a uid\pass containing cookie that will allow auto login, thus enabling malicious users who have an admin password hash to 'Cookie Edit' the details in the cookie and auto-login under the admin account.

    HLL and Keyboard_Criminal


  • Next message: Black Dot: "Re: Winamp - Buffer Overflow In IN_CDDA.dll"

    Relevant Pages

    • PHP-Nuke v5.6 - Users can compromise admin accts.
      ... Allows any user to get admin access to a PHP-Nuke site. ... into base64 and puts it into a cookie. ... Since PHP Nuke encrypts passes in md5 and then matches the encrypted pass ... Open the message and a cookie will now be set on yer box, ...
      (Bugtraq)
    • [UNIX] PHPNuke Private Messaging Module Allows Compromising of Administrator Accounts
      ... attackers to steal the hashed cookie (containing the password of the ... In newer versions of PHPNuke (version ... /* this is so the admin does not get scared. ... Wait until the administrator checks the message then check cookie.txt ...
      (Securiteam)
    • Admin & user Sections .. how authentication then ????!!!!
      ... I use the cookie name set in web.config file ... for authenticating the admin user of the site. ... normal user membership other that admin to my site. ... regarding "authentication cookie name" for normal users as I have ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: Setting logon accounts
      ... dialog at startup with some pre-defined user/domain/password settings. ... I want to be able to let's say auto-login to a standard/restricted user and ... log-off or switch user back to the admin account. ... >> when turning on the pc and wants it to boot up to the desktop without ...
      (microsoft.public.windowsxp.security_admin)
    • [VulnWatch] Digi-news and Digi-ads version 1.1 admin access without password
      ... Digi-news and Digi-ads version 1.1 admin access without password ... the authentification scheme is based on a cookie. ...
      (VulnWatch)