 |
 |
Menu |
 |
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
 |
User Info |
 |
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 117
Members: 0
Total: 117
|
|
|
|
|
 |
Full disclosure |
 |
|
|
 |
|
 |
IT Security and Insecurity Portal |
|
|
Musaaf |
|
Replies: 19 |
Views: 54666 |
|
|
 |
 |
 |
|
credit to everyone that found this bug
poc
http://kisobox.com/exploits/phpbb.2.0.19.xss+cookies.stealer.txt
brief video tutorial about it.
http://kisobox.com/vtu.php or http://kisobox.com/ ... |
|
|
|
Musaaf |
|
Replies: 12 |
Views: 30078 |
|
|
 |
 |
 |
|
Yeah just use the 2.0.12 exploit. That ll work for 2.0.11:
phpBB 2.0.12 Session Handling Authentication Bypass ..
easy to use exploit ..
** YOU DON'T HAVE TO REGISTER AT THE VICTIM'S FORUM. ... |
|
|
|
Musaaf |
|
Replies: 31 |
Views: 213711 |
|
|
 |
 |
 |
|
The easy way is this:
- get Mozilla firefox!
- install Live http headers plug-in ( http://livehttpheaders.mozdev.org/ )
- open the live http header option. Go to the phpbb board. Scroll to the to ... |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|