Site Security Issues

alzika

New member
Joined
Jan 13, 2007
Messages
1
It has come to my attention that directadmin.com is highly vulnerable to hacking. Passwords of any user can be stolen by them simply clicking on a link, as I will demonstrate below.

Here is an example link that is vulnerable. Basically, it rips the cookie of any user containing that user's login information. An attacker can gain entry to anyone's account who clicks on the link, including site administrators and moderators. Here is the link:

http://www.directadmin.com/forum/me...kie</SCRIPT>&ltr=&perpage=25&orderby=username

The link injects javascript code remotely. The javascript code that is injected redirects the user to another server which includes the full cookie of the user currently logged in on directadmin.com. This is an EXTREMELY HIGH security risk.

In order to remedy the above problem and protect the integrity of directadmin's almost 8,000 members, I STRONGLY suggest that you upgrade the version of vBulletin to the most recent version. The current version used by directadmin is almost 5 years old and several security flaws have been found in vBulletin version 2.2.9.

I hope the staff at directadmin takes this message seriously. Luckily, an honest person found this flaw and chose not to exploit this bug with malicious intent. This could have been much worse if a true hacker found your site's bug. Furthermore, if you ever need additional assistance regarding technical information or security related issues, please feel free to contact me.

-alzika
 
Last edited:
It's NOT a security issue in DirectAdmin though it may be a security issue in the forum software.

And it may disclose your forum password, but I don't see how that makes DA insecure.

Jeff
 
I think he was only talking about the forum software - not DA itself.

But I think his concern is that people either way probably don't want their passwords unnecessarily compromised, no matter what the situation.

And of course with that said, it naturally might look unfavorably on DA, even if it is completely unrelated.

I read an interesting article recently about forum software and software companies. The short version is that people using free and/or unsecure forum software (phpbb, etc) generally are perceived as less professional than those using commercial packages (vBulletin, etc).

Just food for thought
 
Last edited:
I'm honestly just happy that the software was upgraded so we can all take advantage of the current release of the forum software :)
 
I think it's much uglier. So far it's harder to use, but that may get better with age :) .

Jeff
 
The default theme, yes - it UGLY!

However, there are several ways to modify it to make it look pretty. I run one site (novahomebrew.com) which is a bit prettier when I went out and bought a template. There are several template places out there on the web (seeing how I am graphicly challenged) to work wounderfuly with vB...
 
I also, just noticed the SPAMER's hit here. If you want any help "secureing" the vB - let me know, there is a neat little graphic you can put up that is required for non-registered people posting and also for singing up for an account.

-jay
 
yeah this forum could do with the anti automated registration protection, lots of spammers.

this new version I am finding harder to use but I will get used to it.
 
Yea, I never used any of the older versions myself - but other free forums that are out there.

I believe the GD Freetype thing is already in the forum package - the server just needs to be configured properly and the options get turned on...
 
If non-registered users can post, I would recommend it there as well. :)
 
Back
Top