Add to Favorites
Hosting Discussion
 

Hosting Discussion > Web Hosting Forums > Hardware and Server Configuration > DCForum Predictable Password Generation Vulnerability
forgot password?


Reply


Old
  Post #1 (permalink)   02-05-2002, 11:22 AM
HD Addict
 
Homer's Avatar
 
Join Date: Jan 2002
Posts: 122

Status: Homer is offline
DCForum is a web based conferencing system, designed to facilitate online discussion. It is implemented in Perl and has few system dependancies, making it available on most operating systems, including Linux, Windows and most Unix varients.

The new password functionality of DCForum, used to recover lost or forgotten passwords, creates passwords with data taken from the session id. This effectively sets the new password to a known value. This function is available to any remote user, and can be used to compromise arbitrary DCForum accounts, including those with administrative privileges.
 
 
 
Reply

Thread Tools

New Post New Post   Old Post Old Post
Posting Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On