vB4 vt.Lai VBB Anti CSRF 1.2 - Anti CSRF Attack To AdminCP vBulletin

  • Downloading from our site will require you to have a paid membership. Upgrade to a Premium Membership today!

    Dont forget read our Rules! Also anyone caught Sharing this content will be banned. By using this site you are agreeing to our rules so read them. Saying I did not know is simply not an excuse! You have been warned.

Radio

    ven0m

    Administrator
    Staff member
    Administrator
    Moderator
    Platinum
    xenForo 2.x.x
    xenForo 1.x.x
    Contributor
    vBulletin All Access Pass
    The Chest
    Verified
    Ultra Platinum VIP
    Platinum VIP
    Gold VIP
    Silver VIP
    Premium
    Member
    Jul 17, 2005
    20,497
    7,735
    321
    localhost
    vB Version: 4.2.0

    How to attack:

    [video=youtube;0W8KWdiHzCI]
    You must be registered for see medias

    How to Fix ?

    + First solution:
    Rename admincp dir. This is simple solution. However, when used in this way, will be some mod is not working or error.
    In another case, if you have sub forum Admin, when you change the AdminCP dir, you must inform them of this. => They still know where is admincp folder.

    + Second solution:
    Use this add on

    Applies to all vbulletin versions

    Change log:
    v1.2: Fix some issue if admincp folder name has special char
    v1.1: Fix loop error + Add some options
     

    Attachments

    • SinhVienIT.NET---anti-rscf-1.2-options.jpg
      SinhVienIT.NET---anti-rscf-1.2-options.jpg
      20.7 KB · Views: 2
    • SinhVienIT.NET---vbb-anti-csrf.jpg
      SinhVienIT.NET---vbb-anti-csrf.jpg
      17.7 KB · Views: 2
    • VBB Anti CSRF.zip
      6.3 KB · Views: 0
    Last edited: