Graal Forums  

Go Back   Graal Forums > General Forums > Graal Main Forum (English)
FAQ Members List Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 04-26-2004, 04:58 PM
Kristi Kristi is offline
Bowie's Deciple
Kristi's Avatar
Join Date: Dec 2003
Location: Boston, MA
Posts: 748
Kristi has a spectacular aura aboutKristi has a spectacular aura about
Send a message via AIM to Kristi Send a message via MSN to Kristi
My guess (pretty much confirmed by moonie's post) is XSS exploits. With VBulliten 3 came increased support for cross site scripting, which (expolits have been around for a long time) lets you able to easily take cookies.

A well crafted pm/thread does not even need you to click a link to steal your session (and since Vbulliten sessions are perminant, its pretty deadly)

I'm not aware of a release to fix it, or any automatic way to disable the XSS, I suggest downgrading the forum personally =p

Disable html everywhere on the forum for starters. (I believe this has been done)

The bad news for us "non moderators" is many of us have our graal passwords set as our forums passwords... yeah...

http://www.securityfocus.com/bid/9943 is an example, there are many.

*edit
okay after reading around, i see it was angels pass stolen... Protect the forums against the above anyway =p
__________________
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 07:51 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.