|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 58
Members: 0
Total: 58
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Musaaf |
|
Replies: 19 |
Views: 53834 |
|
|
|
|
|
|
credit to everyone that found this bug
poc
http://kisobox.com/exploits/phpbb.2.0.19.xss+cookies.stealer.txt
brief video tutorial about it.
http://kisobox.com/vtu.php or http://kisobox.com/ ... |
|
|
|
Musaaf |
|
Replies: 12 |
Views: 29147 |
|
|
|
|
|
|
Yeah just use the 2.0.12 exploit. That ll work for 2.0.11:
phpBB 2.0.12 Session Handling Authentication Bypass ..
easy to use exploit ..
** YOU DON'T HAVE TO REGISTER AT THE VICTIM'S FORUM. ... |
|
|
|
Musaaf |
|
Replies: 31 |
Views: 212346 |
|
|
|
|
|
|
The easy way is this:
- get Mozilla firefox!
- install Live http headers plug-in ( http://livehttpheaders.mozdev.org/ )
- open the live http header option. Go to the phpbb board. Scroll to the to ... |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|