You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 411 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Admin AddAuthor POST Twist Exploit (Score: 1)
by IACOJ on Monday, May 17 @ 17:13:23 CEST
(User Info | Send a Message)
We have seen the following similar URI:

admin.php?op=AddAuthor&add_aid=ADDAID&add_name=God&add_pwd=ADDPWD&add_email=foo@bar.com&add_radminsuper=1

Used within IMG tags that when viewed by validated admins against their domain will launch an attack on themselves without knowing.

These attacks can be sent via forums, via news articles, and even via HTML emails.

Admin Tap stops these. HTTP Authentication does not. Once you are logged in, then the attack works. Admin Tap works regardless of logged in status.

The choice to either secure your system or not is all yours. We simply provide the know-how.


| Parent
Powered by TOGETHER TEAM srl ITALY http://www.togetherteam.it - DONDELEO E-COMMERCE http://www.DonDeLeo.com - TUTTISU E-COMMERCE http://www.tuttisu.it
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.103 Seconds - 178 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::