PBLang - Support Forum
The new international community forum!
Please log in or register.
The date and time is now December 10, 2016, 09:44:25 AM
Home  Search  Help  Log in  Register  Members

New Post Post Reply
PBLang - Support Forum :: Bug Reports :: Security issues :: Software PBLang 4.63 sendpm.php reply file read vulnerability  ::
HRG
Junior Member
Image

HRG Pwns Joo
Posts: 13
Software PBLang 4.63 sendpm.php reply file read vulnerability (March 1, 2005, 01:35:56 AM) quote  
Hey Docewil/PBLang development team.

Here's another for you, my appologies.

[VULNERABILITY RELEASE]

[][][][][][][][][][][][][][][][][][][][][][][][][][][][][]
[]
[] HRG - Hackerlounge Research Group
[] Release: HRG008
[] Monday 03/01/05
[] Software PBLang 4.63 sendpm.php reply file read
[]
[] The author can't be held responsible for any damage
[] done by a reader. You have your own resonsibility
[] Please use this document like it's meant to.
[]
[][][][][][][][][][][][][][][][][][][][][][][][][][][][][]

Vulnerable: PBLang 4.63 (and earlier?)


---

General information:

PBLang is an international BBS-software based on PHP. It does not require any database but bases on a flatfile system. Many professional features. More info on the project website.


---

Description:

This is bad. sendpm.php contains a flaw that allows a registered (and logged in) user to view other users password hashes, as well as their PM's and other files on the forum (and outside of the forum directory even). An attacker can compromise the target system without any trouble using this.


---

Proof Of Concept:

http://localhost/pblang/sendpm.php?to=[username]&subj=[doesnt matter]&num=1&orig=/home/public_html/pblang/db/members/[username]
will load [username]'s entire account information including the MD5'ed password hash and maybe hidden email information. It will be shown in webpages source code, not in the page itself, so right click and view page source.

Including /etc/passwd is possible aswell, as is any file on the server.


---

Fix and Vendor status:

Vendor has been notified, expect official patch soon.


---

Greetz:

All the people at hackerlounge.com, JWT, TGS-Security.com and JWT-Security.net.
Specifically:

Th3_R@v3n (me), Dlab, Riddick, Enjoi, Blademaster, Modzilla, Pingu, Jake Johnson, Afterburn, airo, cardiaC, chis, ComputerGeek, deep_phreeze, dudley, evasion, eXtacy, Mattewan, Afterburn, Thanatos_Starfire, Roz, Sirross, UmInAsHoE, Infinite, Slarty, NoUse, Snake (I hate you), Surreal (I hate you), -=Vanguard=-, The_IRS, puNKiey, driedice, Carnuss, oKiDaN, Mr.Mind, dementis, net-RIDER, voteforpedro, Cryptic_Override, kodaxx, ~CreEpy~NoDquE~, Brainscan, the_exode, phillysteak12345, DerrtyJake, =>HeX<=, m0rk, and anyone else I forgot.


---

Credit:

HRG - Hackerlounge Research Group
http://www.Hackerlounge.com


[][][][][][][][][][][][][][][][][][][][][][][][][][][][][]
[]
[] HRG - Hackerlounge Research Group
[] Release: HRG008
[] Monday 03/01/05
[] Software PBLang 4.63 sendpm.php reply file read
[]
[] The author can't be held responsible for any damage
[] done by a reader. You have your own resonsibility
[] Please use this document like it's meant to.
[]
[][][][][][][][][][][][][][][][][][][][][][][][][][][][][]


Raven

IP logged Status: logged off Profile Send MSN Website 
Order of replies: first reply last :: first reply first
DrMartinus
Developer of PBLang
Image
Image
Developer of PBLang
Posts: 3690
RE: Software PBLang 4.63 sendpm.php reply file read vulnerability (March 1, 2005, 07:14:49 AM) quote  
Accepted, but this bug was long known already and has been fixed in subsequent versions.
4.63 is no longer supported, users should have upgraded by now to 4.65 minimum (better to 4.66r, which is available via CVS).


Dr. Martinus
www.drmartinus.de/
The PBLang-project-page: pblang.drmartinus.de
IP logged Status: logged off Profile Send AIM Send ICQ Website 
weightliftingworkout01
Newbie
Image

PBLang is super!!!
Posts: 1
RE: Software PBLang 4.63 sendpm.php reply file read vulnerability (April 1, 2009, 11:57:21 PM) quote  
Excellent content, I will recommend to my friends, I found very interesting article on the internet, including this ... I will leave an input ----] Weight Lifting for Beginners isn't hard

IP logged Status: logged off Profile Send AIM 
swatbolish
Newbie
Image

PBLang is super!!!
Posts: 3
RE: Software PBLang 4.63 sendpm.php reply file read vulnerability (May 27, 2010, 10:07:34 AM) quote  
Thanks for sharing. how to get pregnant


Adam Baker
IP logged Status: logged off Profile Send AIM 
New Post Post Reply

Software PBLang 4.67.20.a © 2002-2008 by Martin Senftleben & the PBLang-Team
Image