Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 20 Apr 2004 15:52:11 +0200
From:      Frankye - ML <listsucker@ipv5.net>
To:        freebsd-vuxml@FreeBSD.org
Cc:        liukang@bjpu.edu.cn
Subject:   [vuxml entry] phpBB 2.0.8a ip spoofing
Message-ID:  <20040420155211.6fad1eb0@godzilla>

next in thread | raw e-mail | index | archive | help
This is a multi-part message in MIME format.

--Multipart=_Tue__20_Apr_2004_15_52_11_+0200_.=i41_C/ULStS__1
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit

(cc-ed to the port maintainer)
Hi everyone on the list and Mr. Liu

An Ip spoofing issue was just posted on bugtraq.
The issue seems trivial, but if anyone can spoof his ip address forging a
browser header maybe an installation which make heavy use of ip based acls
can suffer a lot. For what I understand you could easily spoof yourself as
127.0.0.1 ...
An unofficial patch was published on bugtraq too, and is available in the
message (http://marc.theaimsgroup.com/?l=bugtraq&m=108241122908409) and
online (http://www.nettwerked.co.uk/code/phpbb-ipspoof.patch)

Attached is the vuxml snippet for this issue.

Frankye

ps: To Mr. Liu: if you're not following the whole vuxml thing and you're
wondering what this is all about there's some info there
(http://lists.freebsd.org/pipermail/freebsd-security/2004-April/001859.ht
ml)


--Multipart=_Tue__20_Apr_2004_15_52_11_+0200_.=i41_C/ULStS__1
Content-Type: application/octet-stream;
 name="phpbb20040420.xml.snippet"
Content-Disposition: attachment;
 filename="phpbb20040420.xml.snippet"
Content-Transfer-Encoding: base64

PHZ1bG4gdmlkPSJjZmUxN2NhNi02ODU4LTQ4MDUtYmExZC1hNjBhNjFlYzliNGQiPgogIDx0b3Bp
Yz5waHBCQiBpcCBzcG9vZmluZzwvdG9waWM+CiAgPGFmZmVjdHM+CiAgICA8cGFja2FnZT4KICAg
ICAgPG5hbWU+cGhwYmI8L25hbWU+CiAgICAgIDxyYW5nZT48bGU+Mi4wLjhfMjwvbGU+PC9yYW5n
ZT4KICAgIDwvcGFja2FnZT4KICA8L2FmZmVjdHM+CiAgPGRlc2NyaXB0aW9uPgogICAgPGJvZHkg
eG1sbnM9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkveGh0bWwiPgogICAgICA8cD5Db21tb24ucGhw
IHNjcmlwdCBhbHdheXMgdHJ1c3RzIHRoZSAoY2xpZW50IHN1cHBsaWVkKSBYLUZvcndhcmRlZC1G
b3IgSFRUUCBoZWFkZXIuCiAgICAgIEEgcmVtb3RlIHVzZXIgY291bGQgZm9yZ2Ugc3VjaCBhbmQg
aGVhZGVyLCBieXBhc3NpbmcgYW55IGlwIGFkZHJlc3MgYmFzZWQKICAgICAgcmVzdHJpY3Rpb25z
LCBzdWNoIGFzIGJhbm5pbmcuPC9wPgogICAgPC9ib2R5PgogIDwvZGVzY3JpcHRpb24+CiAgPHJl
ZmVyZW5jZXM+CiAgICA8bWxpc3QgbXNnaWQ9IjIwMDQwNDE5MDAwMTI5LjI4OTE3LnFtYWlsQHd3
dy5zZWN1cml0eWZvY3VzLmNvbSI+aHR0cDovL21hcmMudGhlYWltc2dyb3VwLmNvbS8/bD1idWd0
cmFxJmFtcDttPTEwODI0MTEyMjkwODQwOTwvbWxpc3Q+CiAgPC9yZWZlcmVuY2VzPgogIDxkYXRl
cz4KICAgIDxkaXNjb3Zlcnk+MjAwNC0wNC0xODwvZGlzY292ZXJ5PgogICAgPGVudHJ5Lz4KICA8
L2RhdGVzPgo8L3Z1bG4+Cg==

--Multipart=_Tue__20_Apr_2004_15_52_11_+0200_.=i41_C/ULStS__1--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040420155211.6fad1eb0>