Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
security report 3.1.2
#21
I would like to know how legitimate this cookie exploit is. I do not care about the others.

It seems it is an invalid exploit as we cannot reproduce.

It makes a critical assumption that the install is not using salted cookies.
We find that this is not the case, however it is possible if a file was removed as there is no fatal warnings and the fallback salt is indeed siteurl.

The lang post insertions is also not reproducible.
We use nonces for settings.php we also have a post['submitted'] evaluation.
Neither are present in your exploit. Even if CSRF protection was voluntarily turned off, it would still not work.

On a properly configured install that is indeed 3.1.2 this proof does not work.

Unless there is something essential missing from the public exploit feel free to pm me.
Also if you want to zip up that entire install and send it to me I would be willing to look at it.
NEW: SA Admin Toolbar Plugin | View All My Plugins
- Shawn A aka Tablatronix
Reply


Messages In This Thread
security report 3.1.2 - by shawn_a - 2013-01-10, 04:30:06
RE: SECURITY EXPLOIT 3.1.2 - by n00dles101 - 2013-01-10, 06:34:09
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-10, 06:37:54
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-10, 07:01:33
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-10, 08:15:49
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-10, 09:56:34
RE: SECURITY EXPLOIT 3.1.2 - by Connie - 2013-01-10, 17:27:27
RE: SECURITY EXPLOIT 3.1.2 - by D.O. - 2013-01-10, 18:08:20
RE: SECURITY EXPLOIT 3.1.2 - by HauntIT - 2013-01-10, 19:17:26
RE: SECURITY EXPLOIT 3.1.2 - by D.O. - 2013-01-10, 20:11:07
RE: SECURITY EXPLOIT 3.1.2 - by HauntIT - 2013-01-10, 21:04:24
RE: SECURITY EXPLOIT 3.1.2 - by Connie - 2013-01-10, 22:01:31
RE: SECURITY EXPLOIT 3.1.2 - by HauntIT - 2013-01-10, 22:48:39
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-11, 00:00:50
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-11, 00:21:51
RE: SECURITY EXPLOIT 3.1.2 - by HauntIT - 2013-01-11, 01:06:06
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-11, 01:14:43
RE: SECURITY EXPLOIT 3.1.2 - by shawn_a - 2013-01-11, 01:38:58
RE: security report 3.1.2 - by shawn_a - 2013-01-11, 06:55:04
RE: security report 3.1.2 - by HauntIT - 2013-01-11, 17:40:42
RE: security report 3.1.2 - by shawn_a - 2013-01-11, 23:10:14
RE: security report 3.1.2 - by n00dles101 - 2013-01-12, 01:05:43
RE: security report 3.1.2 - by shawn_a - 2013-01-12, 02:03:11
RE: security report 3.1.2 - by D.O. - 2013-01-17, 18:55:34
RE: security report 3.1.2 - by n00dles101 - 2013-01-17, 19:39:31
RE: security report 3.1.2 - by D.O. - 2013-01-17, 21:08:04



Users browsing this thread: 1 Guest(s)