[27428] in bugtraq
Re: phpBB2 Showing users ip adresses
daemon@ATHENA.MIT.EDU (nick84@rootsecure.net)
Mon Oct 14 23:16:18 2002
Date: 12 Oct 2002 22:04:45 -0000
Message-ID: <20021012220445.9060.qmail@mail.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: <nick84@rootsecure.net>
To: bugtraq@securityfocus.com
In-Reply-To: <20021009125218.7737.qmail@mail.securityfocus.com>
If anyone wanted to get board readers/posters IP addresses on any phpBB
(and most other bulletin boards), another easy way would be to simply set
up your profile with an off-site avatar. I.e. in the “Link to off-site
Avatar:” box on the profile page, type in the URL to a server where you
able to read the log files. Then post a message, which will get read,
and then note the time of any replies, correlating them to the time you
got a hit on your avatar.
(This could also be done by inserting images/using html iframes etc)
______________________________
Nicholas Skinner
http://www.rootsecure.net/