Arhont Ltd.- Information Security Arhont Advisory by: Konstantin Gavrilenko (http://www.arhont.com) Advisory: Ph0rum phorum_uriauth replay attack Class: design bug ? Version: 4.3.7 Model Specific: Other version might have the same bug Contact Date: 11/05/2004 (email sent to tomaz@phorum.org)
DETAILS:
It is possible to relogin into the previously not loged out sessions in Ph0rum udner certain conditions. Two criterias have to be fulfilled: - the member has to leave the phorum without logging out. - you have to intercept the hash of his not logged out session or grep it out of web-seerver logs