<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Possible spoofing of $redir url with subdomain/domain</title>
        <description> github.com/Phorum/Core/blob/master/login.php [github.com]

Language: PHP$redir_ok = FALSE;
                $check_urls = array&amp;#40;&amp;#41;;
                if &amp;#40;!empty&amp;#40;$PHORUM&amp;#91;&#039;;login_redir_urls&#039;;&amp;#93;&amp;#41;&amp;#41; &amp;#123;
                    $check_urls = explode&amp;#40;&#039;;,&#039;;, $PHORUM&amp;#91;&#039;;login_redir_urls&#039;;&amp;#93;&amp;#41;;
                &amp;#125;
                $check_urls&amp;#91;&amp;#93; = &#039;;http://localhost&#039;;;
                $check_urls&amp;#91;&amp;#93; = $PHORUM&amp;#91;&#039;;http_path&#039;;&amp;#93;;
&amp;nbsp;
                foreach &amp;#40;$check_urls as $check_url&amp;#41;
                &amp;#123;
                     // The redir-url has to start with one of these URLs.
                     if &amp;#40;stripos&amp;#40;$redir, $check_url&amp;#41; === 0&amp;#41; &amp;#123;
                            $redir_ok = TRUE;
                            break;
                     &amp;#125;
                &amp;#125;


 Correct me if I&amp;#039;m wrong but a cleverly crafted url, any url with localhost* will return true.
IE: [localhost.phishingsite.com], [localhostxffsgaggesgssdsjadsajdasd.com]
This would appear to be an easy way for phishers to bypass the protection written.
Might be possible with the site url as well if the redirect url had multple subdomains.  target.com.phishingsite.com
This should probably be marked for revision if it&amp;#039;s current code.</description>
        <link>https://www.phorum.org/phorum5/read.php?14,154961,154961#msg-154961</link>
        <lastBuildDate>Sun, 08 Mar 2026 14:10:52 -0400</lastBuildDate>
        <generator>Phorum 5.2.22</generator>
        <item>
            <guid>https://www.phorum.org/phorum5/read.php?14,154961,154961#msg-154961</guid>
            <title>Possible spoofing of $redir url with subdomain/domain</title>
            <link>https://www.phorum.org/phorum5/read.php?14,154961,154961#msg-154961</link>
            <description><![CDATA[ github.com/Phorum/Core/blob/master/login.php [<a href="https://github.com/Phorum/Core/blob/master/login.php" target="_blank"  rel="nofollow">github.com</a>]<br />
<br />
<pre class="php bbcode_geshi"><div class="head">Language: PHP</div><span class="re0">$redir_ok</span> <span class="sy0">=</span> <span class="kw4">FALSE</span><span class="sy0">;</span>
                <span class="re0">$check_urls</span> <span class="sy0">=</span> <a href="http://www.php.net/array"><span class="kw3">array</span></a><span class="br0">&#40;</span><span class="br0">&#41;</span><span class="sy0">;</span>
                <span class="kw1">if</span> <span class="br0">&#40;</span><span class="sy0">!</span><a href="http://www.php.net/empty"><span class="kw3">empty</span></a><span class="br0">&#40;</span><span class="re0">$PHORUM</span><span class="br0">&#91;</span><span class="st_h">';login_redir_urls'</span><span class="sy0">;</span><span class="br0">&#93;</span><span class="br0">&#41;</span><span class="br0">&#41;</span> <span class="br0">&#123;</span>
                    <span class="re0">$check_urls</span> <span class="sy0">=</span> <a href="http://www.php.net/explode"><span class="kw3">explode</span></a><span class="br0">&#40;</span><span class="st_h">';,'</span><span class="sy0">;,</span> <span class="re0">$PHORUM</span><span class="br0">&#91;</span><span class="st_h">';login_redir_urls'</span><span class="sy0">;</span><span class="br0">&#93;</span><span class="br0">&#41;</span><span class="sy0">;</span>
                <span class="br0">&#125;</span>
                <span class="re0">$check_urls</span><span class="br0">&#91;</span><span class="br0">&#93;</span> <span class="sy0">=</span> <span class="st_h">';http://localhost'</span><span class="sy0">;;</span>
                <span class="re0">$check_urls</span><span class="br0">&#91;</span><span class="br0">&#93;</span> <span class="sy0">=</span> <span class="re0">$PHORUM</span><span class="br0">&#91;</span><span class="st_h">';http_path'</span><span class="sy0">;</span><span class="br0">&#93;</span><span class="sy0">;</span>
&nbsp;
                <span class="kw1">foreach</span> <span class="br0">&#40;</span><span class="re0">$check_urls</span> <span class="kw1">as</span> <span class="re0">$check_url</span><span class="br0">&#41;</span>
                <span class="br0">&#123;</span>
                     <span class="co1">// The redir-url has to start with one of these URLs.</span>
                     <span class="kw1">if</span> <span class="br0">&#40;</span><a href="http://www.php.net/stripos"><span class="kw3">stripos</span></a><span class="br0">&#40;</span><span class="re0">$redir</span><span class="sy0">,</span> <span class="re0">$check_url</span><span class="br0">&#41;</span> <span class="sy0">===</span> <span class="nu0">0</span><span class="br0">&#41;</span> <span class="br0">&#123;</span>
                            <span class="re0">$redir_ok</span> <span class="sy0">=</span> <span class="kw4">TRUE</span><span class="sy0">;</span>
                            <span class="kw1">break</span><span class="sy0">;</span>
                     <span class="br0">&#125;</span>
                <span class="br0">&#125;</span></pre>
<br />
<br />
 Correct me if I&#039;m wrong but a cleverly crafted url, any url with localhost* will return true.<br />
IE: [<a href="http://localhost.phishingsite.com" target="_blank"  rel="nofollow">localhost.phishingsite.com</a>], [<a href="http://localhostxffsgaggesgssdsjadsajdasd.com" target="_blank"  rel="nofollow">localhostxffsgaggesgssdsjadsajdasd.com</a>]<br />
This would appear to be an easy way for phishers to bypass the protection written.<br />
Might be possible with the site url as well if the redirect url had multple subdomains.  target.com.phishingsite.com<br />
This should probably be marked for revision if it&#039;s current code.]]></description>
            <dc:creator>Emerica</dc:creator>
            <category>Phorum Development</category>
            <pubDate>Tue, 04 Mar 2014 19:22:11 -0500</pubDate>
        </item>
    </channel>
</rss>
