php forum
php mysql forum
php mysql smarty
 
Topic Options
#44295 - 03/18/02 06:44 PM Javascript [IMG] tag exploit
BassTeQ Offline
Moderator / Code Fixer

Registered: 10/14/00
Posts: 891
Loc: Australia
Im going to work on developing a block for the use of javascript between img tags. With the exploit now becoming more widely known I think its time to write a fix.
I know a fix is being developed for version 6.x boards but the version 5 users arent that lucky frown

What Id like some help on is collecting word to filter in a msg post.
Obviously things like :
Javascript
document.onload
document.cokie
Get cookie
etc ....

any others ???

Thanks
_________________________
I can't afford a good signature editor frown

Top
#44296 - 03/19/02 01:08 AM Re: Javascript [IMG] tag exploit
joking-down Offline
deutscher moderator / v5 specialist

Registered: 12/24/00
Posts: 712
Loc: Germany
i use this filter for the IMG-Tag in my privatforums. in all other forums is no IMG allow:
[code][/code]what happen when the user post [img ]somescript.js[/ img ]?
_________________________
UBB-Admin ( kids-hotline.de )


join Team UBBDev

I have [img]http://www.ubbdev.com/ud/?s=1&u=joking-down[/img] Points.

Top
#44297 - 03/19/02 01:15 AM Re: Javascript [IMG] tag exploit
LK Offline
Admin / Code Breaker

Registered: 03/24/01
Posts: 7396
(correct me if I'm wrong) 5.xx users don't have cookies except for private forums, so you don't have to be afraid. And private forums cookies == temporary, so just don't enter any thread in the same IE after you enter private forums.
_________________________

My Hacks Page (will be back with UBB 7!)
UBBDev - We put the class into UBB.classic!

Top
#44298 - 03/19/02 03:50 PM Re: Javascript [IMG] tag exploit
BassTeQ Offline
Moderator / Code Fixer

Registered: 10/14/00
Posts: 891
Loc: Australia
Hi LK, I'll think you'll find 5.XX has cookies, Username and Password respectively. As it does store these fileds so when you post/reply they are automatically populated, therefore that information is coming from somewhere,has to be a cookie.

Cheers
_________________________
I can't afford a good signature editor frown

Top
#44299 - 03/20/02 12:42 AM Re: Javascript [IMG] tag exploit
LK Offline
Admin / Code Breaker

Registered: 03/24/01
Posts: 7396
I should never enter this forum again wink
_________________________

My Hacks Page (will be back with UBB 7!)
UBBDev - We put the class into UBB.classic!

Top
#44300 - 03/20/02 03:54 PM Re: Javascript [IMG] tag exploit
BassTeQ Offline
Moderator / Code Fixer

Registered: 10/14/00
Posts: 891
Loc: Australia
Nahh no need to be like that!
We all make mistakes!
_________________________
I can't afford a good signature editor frown

Top
#44301 - 06/05/02 03:43 PM Re: Javascript [IMG] tag exploit
Onkel_Tom Offline
Member

Registered: 11/18/00
Posts: 51
Loc: Germany-BB
something new about this Chapter ?

I got some attacks with IMG-Code on my Forum and searching for a hotfix wink
_________________________
Best regards and happy coding ...
Tom
Webmaster of
German Hayabusa-Forum
German BMW M5-Forum
German ZX-12r-Forum

Top
#44302 - 06/05/02 06:28 PM Re: Javascript [IMG] tag exploit
BassTeQ Offline
Moderator / Code Fixer

Registered: 10/14/00
Posts: 891
Loc: Australia
What version are you running, Ive only tested my fix on version 5.47d

I can post fix details here if you like.

Regards
BassTeQ
_________________________
I can't afford a good signature editor frown

Top
#44303 - 06/08/02 04:30 AM Re: Javascript [IMG] tag exploit
LK Offline
Admin / Code Breaker

Registered: 03/24/01
Posts: 7396
Bass, you can't fix it by adding many stuff to block list, it's much more complicated. You'll have to make sure img and url tags don't include ", don't begin with javascript, etc, without forgetting that "javascript" can be written with &#stuff
_________________________

My Hacks Page (will be back with UBB 7!)
UBBDev - We put the class into UBB.classic!

Top
#44304 - 06/08/02 05:46 PM Re: Javascript [IMG] tag exploit
joking-down Offline
deutscher moderator / v5 specialist

Registered: 12/24/00
Posts: 712
Loc: Germany
an other filter is:
Code:
[/code]add the code before this code in "ubb_library.pl":
[code]

you can change the text This call of the UBB code [ IMG ] is not permitted... without problems... tipsy
_________________________
UBB-Admin ( kids-hotline.de )


join Team UBBDev

I have [img]http://www.ubbdev.com/ud/?s=1&u=joking-down[/img] Points.

Top
#44305 - 06/11/02 12:28 AM Re: Javascript [IMG] tag exploit
BassTeQ Offline
Moderator / Code Fixer

Registered: 10/14/00
Posts: 891
Loc: Australia
Hi, if i test your example with this code below it doesnt seem to print the message that its Not permitted.

Code:
[/code]If however I pass it a proper IMG path then all works ok

[code]

Any ideas?
_________________________
I can't afford a good signature editor frown

Top



Latest Posts
[7.2.1] - Naked shoutbox
by bellaonline
05/05/12 05:00 PM
[7.x] Stop Forum Spam Integration v0.4
by bellaonline
05/05/12 03:53 PM
Shout Box

(Views)Popular Topics
Known public proxy servers 1689885
Integrated Index Page (IIP) 5.3.1 555705
Finished-[6.5.2] Games Arcade Deluxe v1.9 501236
Integrated Index Page (IIP) 5.1.1 415112
TLD Bv2.1 Released - Threads Links Directory 396822
[6.0x] Who's Online 4.0.0 [Finished] 389412
Finished-[6.5.1] Integrated Index Page (IIP) 6.5 330423
Q & A 298663
Slash UBB 266936
[6.3.x] [beta] Hit Hack 2.0 227970
Forum Stats
13621 Members
59 Forums
37191 Topics
295716 Posts

Max Online: 686 @ 06/28/07 07:04 AM

 

 

 
fusionbb message board php hacks