TP-Docs
HTML5 Icon HTML5 Icon HTML5 Icon
TP on Social Media

Recent

Welcome to TinyPortal. Please login or sign up.

Members
  • Total Members: 3,963
  • Latest: BiZaJe
Stats
  • Total Posts: 195,917
  • Total Topics: 21,308
  • Online today: 790
  • Online ever: 8,223 (February 19, 2025, 04:35:35 AM)
Users Online
  • Users: 0
  • Guests: 424
  • Total: 424

[bugtracker] Shoutbox Hack - http://free100.tk

Started by scso1502, April 05, 2010, 06:55:14 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Ziygo

I am the said hacker, I will continue to exploit all sites that use that shoutbox until bloc releases a fix for it. The shoutbox is WAY to exploitable, if I was mean I could have used many other tinyportal exploits, but those are coming, prepare yourself :)

bloc

So, this was a css hack, what else do you have then? ..Or was that it?

Ziygo

There are many SQL injections brought in mainly due to your scripts, many available purely because of tinyportal and it's lack of security. Email me if you'd like my findings bloc.

Artimidor

Well, I deleted the shout from the database, so I actually never saw the shout on site and the username is represented only via an ID etc. But I looked if I found Ziygo in the database, and there he is, registration yesterday, IP and e-mail are identical as they can be found in scso1502's post.

But anyway, seems friend Ziygo graces us with his presence... So in case you can provide even more details to identify you, Ziygo , that would be a great help ;)

bloc

Quote from: Ziygo on April 05, 2010, 10:58:19 AM
There are many SQL injections brought in mainly due to your scripts, many available purely because of tinyportal and it's lack of security. Email me if you'd like my findings bloc.

Ok, mail sent.

bloc


Bill.Ramby

Is a fix going to be issue for the non-Beta TP users? 0.98 specifically?

bloc

Yes, I am afraid it will also work on older Shoutbox versions: as its primary a display "trick" it will not harm the database, but be very annoying for users.

This is whats needed for 0.9.8 users:
- Open up TPmodules.php in the Sources folder and find:
  $shout=strip_tags(substr($_POST['tp-shout'],0,300),'<b><u><i>');

Change it to:
  $shout=strip_tags(substr($_POST['tp-shout'],0,300));

Bill.Ramby


Artimidor

Thanks for the quick response! Great work!  :up:

This website is proudly hosted on Crocweb Cloud Website Hosting.