 |
|
 |
 |
Menu |
 |
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
 |
User Info |
 |
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 90
Members: 0
Total: 90
|
|
|
|
|
 |
Full disclosure |
 |
|
|
 |
|
 |
IT Security and Insecurity Portal |
|
|
|
Ok, maybe this will help. The site is below :
secretfans.com |
|
|
|
|
My guess would be that they haven't upgraded their forums in a while
"Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group."
That would seem to indicate an outdated version of the software.
... |
|
|
|
|
Two weeks without a reply...I'm gonna venture a guess this version is pretty secure?
I did fast look at that advisory and basically it's the way to steal admin or moderator session ID. Nothing diffic ... |
|
|
|
|
Two weeks without a reply...I'm gonna venture a guess this version is pretty secure? |
|
|
|
|
I found a session hijack exploit thru google for the proper phpbb version of the forum in question, but have a few questions :
What is the csrf referred to in the end of this procedure :
"...if t ... |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|