Some other exploits at PhoenixPHP

Results 1 to 16 of 16
  1. #1
    hoi ik ben cool Merijn is offline
    MemberRank
    Dec 2009 Join Date
    The NetherlandsLocation
    492Posts

    Some other exploits at PhoenixPHP

    Ohai.
    Before you give a feedback, think wise. Some kids don't understand php. Otherwise, this will be easy to fix for everybody. It are simple Persist Cross-site-scripting Injections.


    The non-persist (Clientside)
    Change you're mission. Just try to put in:
    <script>alert('lol')</script>
    How to fix?
    Open me.php, and search for:
    <div class="Usersmotto"
    The code that you found. Well, let's replace it with:
    <div class="Usersmotto" style="min-width:200px; min-height:30px;"><?php echo .$core->EscapeString($users->UserInfo($username, 'motto')); ?></div>
    Cross-site-scripting at staff.php
    You are a Staff Member? Okay, then you can do this. Again edit you're motto. and write something like this:
    PHP Code:
    <script>alert('lolwut?')</script> 
    And enter. Now go to the Staff Page. And you will see there will be a alert.

    How to fix?
    Go to staff.php

    Search for:
    PHP Code:
    <div class="Usersmotto"><?php echo $staff['motto']; ?></div>
    And replace that with:
    PHP Code:
    <div class="Usersmotto"><?php echo .$core->EscapeString($staff['motto'] ); ?></div>
    Okay, the last Cross-site-scripting leak is in home.php

    Let's say, you make a room. Just rename you're room in something like this
    PHP Code:
    <script>window.location="URL HERE!"</script> 
    Go to you're homepage. And you will see that the page is redirected.

    Fix:
    Openhome.php

    Well, now search for:
    PHP Code:
    <strong><?php echo $userroom['caption']; ?></strong><br /><br />
    And replace it with:
    PHP Code:
    <strong><?php echo .$core->EscapeString($userroom['caption'] ); ?></strong><br /><br />
    Okay, goodluck with this.

    Cya.


  2. #2
    Eye Eye Capt'n Spheral is offline
    MemberRank
    May 2010 Join Date
    TumptonshireLocation
    2,488Posts

    Re: Some other exploits at PhoenixPHP

    Awright, thanks, this seems interesting and helpful.

  3. #3
    Live Ocottish Sverlord Joopie is offline
    LegendRank
    Jun 2010 Join Date
    The NetherlandsLocation
    2,773Posts

    Re: Some other exploits at PhoenixPHP

    Most people don't know that Cross-site-scripting Injections are possible in client x]

  4. #4
    hoi ik ben cool Merijn is offline
    MemberRank
    Dec 2009 Join Date
    The NetherlandsLocation
    492Posts

    Re: Some other exploits at PhoenixPHP

    Quote Originally Posted by joopie View Post
    Most people don't know that Cross-site-scripting Injections are possible in client x]
    Now they know it is possible.

  5. #5
    [title][/title] Phosfor is offline
    MemberRank
    Jul 2010 Join Date
    FranceLocation
    286Posts

    Re: Some other exploits at PhoenixPHP

    Thanks !

  6. #6
    hoi ik ben cool Merijn is offline
    MemberRank
    Dec 2009 Join Date
    The NetherlandsLocation
    492Posts

    Re: Some other exploits at PhoenixPHP

    Quote Originally Posted by Phosfor View Post
    Thanks !

    But strangely my page become blacnk u_U,
    i don't understand why ^^
    Just try it again. Maybe you did something wrong in you're script.

  7. #7
    [title][/title] Phosfor is offline
    MemberRank
    Jul 2010 Join Date
    FranceLocation
    286Posts

    Re: Some other exploits at PhoenixPHP

    Quote Originally Posted by MerijnZ View Post
    Just try it again. Maybe you did something wrong in you're script.
    Well, sorry^^

    Thanks dude !

    Usefull :p

  8. #8
    GreenMaX keven007 is offline
    MemberRank
    Jul 2008 Join Date
    The NetherlandsLocation
    275Posts

    Re: Some other exploits at PhoenixPHP

    Nice merijn, goodjob!

  9. #9
    I don't even know azaidi is offline
    MemberRank
    Apr 2010 Join Date
    the NetherlandsLocation
    2,065Posts

    Re: Some other exploits at PhoenixPHP

    Can someone find the exploit where I get hacked with the whole time on hablow.dyndns.org please?

  10. #10
    Account Upgraded | Title Enabled! rory129 is offline
    MemberRank
    May 2009 Join Date
    МанчестLocation
    233Posts

    Re: Some other exploits at PhoenixPHP

    The moto one is on ubercms aswell.
    Yu enter into the moto then reload the page and it does it everytime,

  11. #11
    Web Developer Papercup is offline
    MemberRank
    Nov 2009 Join Date
    WalesLocation
    1,607Posts

    Re: Some other exploits at PhoenixPHP

    Wow, I wonder if one day it will actulley be safe to run PhoenixPHP... (Nah, That will never happen)

  12. #12
    I don't even know azaidi is offline
    MemberRank
    Apr 2010 Join Date
    the NetherlandsLocation
    2,065Posts

    Re: Some other exploits at PhoenixPHP

    Quote Originally Posted by Seano2o6 View Post
    Wow, I wonder if one day it will actulley be safe to run PhoenixPHP... (Nah, That will never happen)
    I won't stop editing PhoenixPHP untill that's possible..
    So if I can get some support it'll be possible.

  13. #13
    Garry's Mod is addictive! Law is offline
    MemberRank
    Dec 2009 Join Date
    NorwayLocation
    993Posts

    Re: Some other exploits at PhoenixPHP

    The alerts will only be displayed for the user himself, without the staff page one. there it will be displayed for everyone visiting. :P

  14. #14
    Live Ocottish Sverlord Joopie is offline
    LegendRank
    Jun 2010 Join Date
    The NetherlandsLocation
    2,773Posts

    Re: Some other exploits at PhoenixPHP

    ..., After fixing some XSS and SQLi injections is PhoenixPHP `safe`?

    Just by putting this:
    PHP Code:
    foreach ($_POST as $key => $value){ $_POST[$key] = FilterFunction($value); }
    foreach (
    $_GET as $key => $value){ $_GET[$key] = FilterFunction($value); } 
    Into an global file and it's done. x]

    Edit: Then stil to filter some database output saved from the client x]

  15. #15
    Account Upgraded | Title Enabled! Pookie is offline
    MemberRank
    Mar 2011 Join Date
    1,038Posts

    Re: Some other exploits at PhoenixPHP

    Thanks.

  16. #16
    hoi ik ben cool Merijn is offline
    MemberRank
    Dec 2009 Join Date
    The NetherlandsLocation
    492Posts

    Re: Some other exploits at PhoenixPHP

    You're all welcome. Glad to see that i'm helping. Actually; Will find more, and more. And more exploits. Fix it all for you.



Advertisement