Results 1 to 2 of 2
-
31st Dec 2011, 06:45 PM #1OPRespected Member
ChatBox Vulnerability
It has come to my attention that the KWWHunction ChatBox is vulnerable to a CSRF attack.
Moderators have been tricked into loading URL's that look like this:
When such links are inserted into "IMG" tags within a post; a moderator will unknowingly ban the user from the ChatBox. In the past few minutes alone, myself and other members of staff have fallen victim to this attack (the links having made us ban ourselves).
This makes it impossible to moderate the ChatBox effectively. It is therefore necessary to disable the ChatBox until further notice.
Thank you.Loget Reviewed by Loget on . ChatBox Vulnerability It has come to my attention that the KWWHunction ChatBox is vulnerable to a CSRF attack. Moderators have been tricked into loading URL's that look like this: http://i.imgur.com/Ln4OC.png When such links are inserted into "IMG" tags within a post; a moderator will unknowingly ban the user from the ChatBox. In the past few minutes alone, myself and other members of staff have fallen victim to this attack (the links having made us ban ourselves). This makes it impossible to moderate the Rating: 5
-
31st Dec 2011, 08:04 PM #2OPRespected Member
The issue has been temporarily fixed.
Sponsored Links
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
Critical Vulnerability in Windows RDP
By shahaz in forum Hosting DiscussionReplies: 0Last Post: 15th Mar 2012, 10:32 AM -
Sborg's xss vulnerability
By masterb56 in forum Server ManagementReplies: 5Last Post: 1st Sep 2011, 07:07 AM -
Heyy if chatbox is coming what is that am i banned from chatbox
By nosmoking in forum General DiscussionReplies: 1Last Post: 22nd Mar 2011, 05:41 AM -
[Hiring] Someone to do Comprehensive Vulnerability Tests
By The90sKid in forum Completed TransactionsReplies: 3Last Post: 30th Nov 2010, 04:15 AM -
Linux Kernel Vulnerability - Please Read
By robert420 in forum News & Current EventsReplies: 2Last Post: 23rd Sep 2010, 03:04 PM
themaManager - edit and manage...
Version 4.04 released. Open older version (or...