Infesting you with Virus News
 

News

Contributed by: Lauren Gerber
Date: June 22, 2009
Lauren Gerber
2
Vote
0

Dangerous BBCode Script Vulnerability In NBBC!

 

I wish I had all the answers for you and I wish I could take away all the vulnerabilities on the web. The harsh reality of the situation is that it is not possible. I may not be able to take away all the vulnerabilities on the web, but I am able to tell you about a new vulnerability which has taken place. The latest vulnerability which has been reported and discovered relates to the BBCode Script Vulnerability in NBBC.Vulnerability.JPG

Before I go any further I would like to provide you with some additional information with regards to NBBC. The reason I would like to explain this to you, is so that you will all have a general idea of exactly what NBBC is, so without any further a due let me proceed in my explanation. NNBC is The New BBCode Parser, which is a fast extensible parser for the BBCode document language. It is written in PHP and it is actually able to convert BBCode input in HTML output, this output will fully conform with the XHTML. NBBC is able to be used on any operating system or web server with the inclusion of Windows 2000. Some of the files of Windows 2000 may include but are not limited to the following: msimdbpc.dll, msimdbmg.dll, msimdbcr.dll, msidpe.dll, msidlpm.dll as well as mshtmdbg.dll.

This vulnerability relates to the specific input which is passed from the "[img]" BBCode tag. This tag as it stands isn't accurately sanitized before the conversion process into HTML. Basically the risk that this presents us with, is that it may be exploited in order to insert various arbitrary HTML as well as script code. This may then get executed in a browser session, in the exact context of a website which is affected when this malicious data is being looked at.7Windows.jpg

This NNBC vulnerability is lethal due to the factor that it may be effectively exploited by malicious individuals in order to perform highly dangerous script insertion attacks. This vulnerability has been rated as moderately critical yet it is still dangerous and could result in disastrous consequences.

The question that may be asked is? What versions does this vulnerability affect? The versions which have been affected by this vulnerability are versions before 1.4.2. Users of NBBC may be wondering at exactly this point in time, what the solution to this problem is? The solution is for all users to update immediately to version 1.4.2. The best of luck to you all in saving yourselves from this vulnerability.

User Comments

Generic Guy in a Trenchcoat July 29, 2009
Thanks for the heads up Lauren! I have been looking around for the best solution for BBcode implentations and NBBC was looking pretty good to me.

Do you have any good suggestions for a javascript driven front end formatter for input?

(I put my real email in this one) :P sry
I kind of like the one that I found below. Its simple but nice.

http://corpocrat.com/2008/08/15/free-wysiwy g-bbcode-editor-in-javascript/
Generic Guy in a Trenchcoat July 29, 2009
Thanks for the heads up Lauren! I have been looking around for the best solution for BBcode implentations and NBBC was looking pretty good to me.

Do you have any good suggestions for a javascript driven front end formatter for input?

I kind of like the one that I found below. Its simple but nice.

http://corpocrat.com/2008/08/15/free-wysiwy g-bbcode-editor-in-javascript/
Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

March 15, 2010
vpshellres dll fix tool more..
March 15, 2010
nice more..
March 14, 2010
Hey i just got P2P-Worm.Win32. .. rm.Win32.Palevovirus on my laptop and i dont know how to remove it... more..
more comments..
rss
Home > Computer Security > Dangerous BBCode Script Vulnerability In NBBC!