Re: Hosting Controller Vulnerability

From: Ben M (webmasterat_private)
Date: Sun Jul 14 2002 - 22:07:42 PDT

  • Next message: Adam [wp-ckkl]: "Re: Remote ICQ Sound Desactivation"

    
     ('binary' encoding is not supported, stored as-is)
    In-Reply-To: <20020714213121.A7F7E36F9at_private>
    
    
    >Instead of using something like @stake web proxy, could you also save the 
    >html output of (/accounts/updateuserdesc.asp) locally and change username 
    >to administrator and re-submit the form? 
    
    I am not sure, it depends on how your browser handles the cookies. The 
    login cookie is a ASP session cookie.
    
    >And how are they validating the user name after applying the patch ?
    You can look at the patch, it is in ASP, so you can read it. All it does 
    is to select the users you have the rights to admin, and checks that the 
    user you are editing is one of those users.
    >
    >Regards, 
    >---------
    >Muhammad Faisal Rauf Danka
    >
    >Chief Technology Officer
    >Gem Internet Services (Pvt) Ltd.
    >web: www.gem.net.pk
    



    This archive was generated by hypermail 2b30 : Mon Jul 15 2002 - 16:00:59 PDT