You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 697 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Admin Exploit - XSS Type (Score: 1)
by Zhen-Xjell on Monday, March 22 @ 16:58:28 CET
(User Info | Send a Message) http://castlecops.com
Your suggestion doesn't answer the code I have seen that effectively allows admins to be created. And as stated this is a patch until admin.php can be 'enhanced'.

As for accessing admin.php, you are right, unless the referer is passed, then access is cut off. So I highly recommend you use something that passes it.


| Parent

Re: Admin Exploit - XSS Type (Score: 1)
by J-Claude on Monday, March 22 @ 16:59:12 CET
(User Info | Send a Message) http://www.phpnuke-europe.org
So we can patch the admin file with Zhen patch and authros with your and that s ok?


| Parent

Re: Admin Exploit - XSS Type (Score: 1)
by Zhen-Xjell on Monday, March 22 @ 17:05:36 CET
(User Info | Send a Message) http://castlecops.com
Taking a look at the patch again, that means if any of the ops are used outside of 'updateauthor' then it doesn't work. That will effectively break the use of edit authors for authentic admins on the site.


| Parent
Powered by TOGETHER TEAM srl ITALY http://www.togetherteam.it - DONDELEO E-COMMERCE http://www.DonDeLeo.com - TUTTISU E-COMMERCE http://www.tuttisu.it
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.075 Seconds - 283 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::