Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
7,843 Members
164,844 Posts
43 Users Online

Please welcome our newest member, mmmmmu!

Affiliates
Go Back AdminFusion » Getting Started » Software » Other Software » [MyBB News] Regarding the "Debug mode, change users password" Vulnerability
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 03-30-2007, 02:40 AM   #1

Title: Apprentice

Points: 4,964, Level: 20Points: 4,964, Level: 20Points: 4,964, Level: 20
Level up: 21%, 86 Points neededLevel up: 21%, 86 Points neededLevel up: 21%, 86 Points needed
Activity: 45%Activity: 45%Activity: 45%

Join Date: Sep 2005

Posts: 443

Industry News is on a distinguished road
 
 
Post [MyBB News] Regarding the "Debug mode, change users password" Vulnerability

Hi,

It has come to our attention that users have discovered what they believe to be a vulnerability in MyBB with the lost password functionality and debug mode.

We want to make it clear this is not a vulnerability in MyBB and has hugely been miss-reported and identified by "HACKERS PAL" the group who "discovered it".

The supposed vulnerability states that using the MyBB debug mode users can see the challenge code we save in the database for password resets and this can then be used to change the password of a user.

Lets look at the facts:
  • The ?debug=1 mode parameter is only available to Administrators who can also change the password of a user using the Admin CP.
  • If for some reason debug mode is publicly accessible and someone does manage retrieve an activation key, it will just reset the password of the user and MyBB will email them a new one - the person attempting this "exploit" would not be able to specify a new password for the user or see the newly generated one.
  • The debug mode is a list of queries. If this were a true exploit it could be stated that the debug mode also allows you to see things such as registered email addresses being checked in the back end, login keys, encrypted passwords and password salts.
We're treating this vulnerability as bogus due to the above reasons.

If for some reason you do have the debug mode functionality accessible to the public (either by a code modification yourself or someone else) then we recommend you disable it.

More...
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
Getting Site User Feedback shellspeare Handling Problem Members 2 03-09-2006 08:34 PM

AdminFusion

All times are GMT +1. The time now is 07:39 AM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0 © 2005-2008 AdminFusion - All Rights Reserved



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72