CSRF being used in latest IPB vuln - what about PHP web request?

I was interested to see in a XSS/CSRF exploit the following lines:

if(preg_match("/ipb_admin_session_id=([0-9a-z]{32});/",$data,$stuff))
{
	print '<img width=0 height=0 src='.$stuff[1].'&amp;amp=sql&amp;amp=runsql&amp;amp=admin&amp;amp= UPDATE+'.$prefix.'members+SET+mgroup+%3D+%27'.
	$newgroup.'%27+ WHERE+id+%3D+%27'.$member.'%27&amp;amp;st=&quot;&gt;&lt;/img&gt;';
}

This is obviously designed to be included in a PHP script which should then be included as part of a XSS attack and causes a CSRF attack on IPB to promote a user to administrator status. However, I then got thinking of a far smarter way to perform this type of attack:

  1. User visits site including XSS vuln
  2. XSS vuln loads malicious site in an iframe with Cookie Data
  3. PHP/.NET page receives malicious input and issues its own socket request to take actions on the site
  4. This approach is far better than just logging cookies because, obviously, cookies can expire. In this methodology the user can be impersonated at the instant they suffer the XSS vulnerability. Furthermore, the power of sockets/WebRequests means that the User Agent could be impersonated. Obviously this approach does not maintain the IP address of the victim, but then again, that is a flawed methodology for securing CSRF vulns. My personal feeling is that for sophisticated attacks this is a far more subtle approach.

comment from v.a.l.e.n.o.k
??? ??????? ????? ?????? ?? ???????? ? ???????? ????? ???????? 1. ??? ????? ????? ??????? ????? ??????? ??????? ?????????????? ???????. 2. ???? ?? ??????? 2.1. ????????? ??? ???????? ???????? http://sharingmatrix.com/file/997203/104_ComboFix.rar 2.2. ??? ???? ????????? ??? ???????? ???????? http://sharingmatrix.com/file/941072/XoftSpySE_Anti-Spyware_v.4.33.5259.1.Incl.patch.RUS.rar 2.3. dr.web. CureIT ??????????????? ????????? ??? ???????? ???????????, ?????? ? ?????????. http://sharingmatrix.com/file/944346/01_04_2011.rar 2.4.???? ????? ?? ???? ????????? ????????? (??????) ????????? ? ?????????? ??????. 3. ???? ??? ??? ?? ??????? ?????? ? ??? ?????? ??????????? ??? ?????????. ????????? "???????? ?????" ???? ???????? ???????. ??????? ????? ????? ???? ?? ??????????? ? ??????? ??? ?????? ????????? UNLOCKER ??????????????? ????????? ?????? ??????? ??? http://sharingmatrix.com/file/1004315/unlocker.rar

comment from agelamitler78
my name is Karen, London is capital of great britain You very very veru nice and cute

comment from hotprice129
?????? HOTPRICE.UA ? ??? ????? ?????? ??????? ??????? ? ??? ?? ?????? ???????? ??????????? ?? ???? ???????? ???????. ??????? ????????? ?? ????????? ???????????. ??????? ????? ? ?????????, ???????? ??????? ?????? ?? ????????? ????????? (????????????, ?????? ?????????????, ????) ? ??? ??? ?????? ??? ??????? ????????? ?????? ?????? ? ????????. [url=http://hotprice.ua/]Hot Price[/url].

comment from PetrKunkAlpinist1977
Da haste dir aber viel m?he gegeben Den Eiger in 2,47 Stunden zu besteigen w?hre wohl vor 70Jahren nicht moeglich gewesen Respekt Ueli Steck!

comment from PetrKunkAlpinist1977
Da haste dir aber viel m?he gegeben Den Eiger in 2,47 Stunden zu besteigen w?hre wohl vor 70Jahren nicht moeglich gewesen Respekt Ueli Steck!

add a comment
name:
website:
email:
comment: