Author |
Message |
|
The password is saved in your SQL database. It in in the auth table and is encrypted.
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|
has to be the very first thing on the page.
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|
Have you edited the script in anyway ?
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|
Now the big test, can you actually login
As I said above it should work fine but I don't think it will work if the password contains quotes or certain other characters. But then who makes a password with quotes in it ?
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|
Oh and yes, the fix is as I posted in the first post.
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|
I'd say that yes they are now vulnerable. I uploaded the 2.2 sessions.class.php file to my 2.3.1 installation while testing this fix and I was vulnerable to it. Best fix for the login loop appars to be www.carbonize.co.uk/install.zip I just need to weed out the syntax bugs in it.
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|
If you have access to the server then best you do it. It's a simple enough modification. Only problem I can see is if the real password actually contains quotes or certain other symbols.
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|
Another bump as I want someone with a live 2.2 installation to test it. Or am I going to end up emailing a site with a hacked guestbook with the fix.
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|
I assume you are talking about the advanced guestbook. There is an image verification script available to stop the automated signing of the guestbook. You can get it from www.carbonize.co.uk/verification.zip
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|
Let me know because it is annoying.
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|
BBcode does not work in the comments neiter do smileys. The comments are not passed to the same routine as the actual message and so they do not get converted.
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|
Stupid question but did you turn BBcode (AGcode) on in the settings?
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|
If you can access your SQL database you can restore the guestbook to the default username of test and password of 123.
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|
Actually having reread your post I am worried. unlink(index.html) says to me that the script was trying to unlink (delete) the index.php file of the guestbook. I may be wrong though.
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|
You need to change the permissions on both the public and tmp folders in the guestbook folder. You need to CHMOD them both to 777. If you do not know how to do this then read your FTP clients help files.
|
data:image/s3,"s3://crabby-images/6d647/6d647ccdf6226473cedad412dbc6b3827b1b30a5" alt="" |
|