New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 24)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1157
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

phpBB hacking through fake cookie

 
Post new topic   Reply to topic       Computer Cops Forum Index -> General Security
View previous topic :: View next topic  
Author Message
Boeman

Cadet
Cadet



Joined: Jun 02, 2004
Posts: 2
Location: USA

PostPosted: Wed Jun 02, 2004 4:44 pm    Post subject: phpBB hacking through fake cookie
Reply with quote

Hi,

My phpbb forum was hacked recently by the use of a fake cookie.
I never heard of that method of hacking untill then.
I have been told you first need to fetch the md5 hash of the pass from an admin user. And with that hash you can build a fake cookie?

Now that's a really cool thing to do, but i don't want that to happen on my phpBB forum Sad

So my question is: is this still possible with phpBB 2.0.8, if so where the hell do they fetch the md5 hash? And how can i prevent people from doing it?

Thx for all those who can give me some answers,
Boeman
Back to top
View users profile Send private message
Techie-Micheal

Cadet
Cadet



Joined: May 27, 2004
Posts: 6
Location: USA

PostPosted: Wed Jun 02, 2004 9:55 pm    Post subject:
Reply with quote

If you haven't already, please post in the phpBB.com Support Forum (www.phpbb.com/viewtopic.php?f=1). Our Support Team is well-equipped to assist you with this.

Techie-Micheal
phpBB Support Team Member
Back to top
View users profile Send private message Visit posters website
Boeman

Cadet
Cadet



Joined: Jun 02, 2004
Posts: 2
Location: USA

PostPosted: Thu Jun 03, 2004 5:28 am    Post subject:
Reply with quote

Ok thx for the tip, I've posted this in the phpBB Support forum as well:

http://www.phpbb.com/phpBB/viewtopic.php?p=1104538#1104538

Boeman
Back to top
View users profile Send private message
Techie-Micheal

Cadet
Cadet



Joined: May 27, 2004
Posts: 6
Location: USA

PostPosted: Thu Jun 03, 2004 8:54 am    Post subject:
Reply with quote

Thanks. Smile Sorry about the replies, they got to it before I could.
_________________
"Security is like an onion." - Unknown
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> General Security All times are GMT - 5 Hours
Page 1 of 1

 
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops