|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 85
Members: 0
Total: 85
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
VBulletin 3.0.7 Admin cookies. |
|
Posted: Wed Sep 21, 2005 4:33 am |
|
|
CraZiesT |
Regular user |
|
|
Joined: Sep 21, 2005 |
Posts: 8 |
|
|
|
|
|
|
|
Hello everyone,
I have cookies for 3 admins in a site,i can log in with their cookies and i can browse their msgs and so on,but the question is how can i use these cookies to get into the administration panel?
so far i heard there is no way,but just let me give it a try in this forum.
I know that vb hash passwords cannot be cracked easily.
Anyway if anyone can help me out or can come up with an idea that can make me get into the admin panel will be really appriciated. Thanx |
|
|
|
|
|
Re: VBulletin 3.0.7 Admin cookies. |
|
Posted: Fri Sep 30, 2005 6:32 pm |
|
|
tehchad |
Beginner |
|
|
Joined: Sep 30, 2005 |
Posts: 2 |
|
|
|
|
|
|
|
You can't log into a vBulletin admin or mod CP with cookies, because they always require password authentication.
The hash you have has been hashed three times over (twice on random values), so I wouldn't reccomend trying to crack it.
You used XSS to obtain these cookies? If they haven't patched it you can use the same exploit again and try using some methood of logging the keystrokes when the admin logs in. |
|
|
|
|
|
|
|
|
Posted: Sun Oct 02, 2005 1:02 pm |
|
|
CraZiesT |
Regular user |
|
|
Joined: Sep 21, 2005 |
Posts: 8 |
|
|
|
|
|
|
|
Thanks for ur reply tehchad.
I used a php log to get the cookies,
http://www.linux-soul.net/vb/printthread.php?t=749
How can i use the same exploit to get the keystrokes?that means i need to send a keylogger to the admin?,which i did,i sent undetectable trojan from one admin to the other,but they noticed later,i didnt get enough time to get their passwords and they then changed their passwords
in other words i gave up on that site,thats why i sent a trojan. |
|
|
|
|
www.waraxe.us Forum Index -> Newbies corner
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|