the internet's safety

vBookie.txt

vBookie.txt
Posted Mar 14, 2006
Authored by admin | Site ukgamblingforums.co.uk

On vBulletin, with vBookie installed, it is not possible to donate a negative amount of VChips to yourself or another user; however is it possible to alter the input string to get around this limitation and donate any amount you want to your account, or that of another registered user.

tags | advisory
MD5 | aa0d11d03df114ed5098affe021a70a9

vBookie.txt

Change Mirror Download
This is a multi-part message in MIME format.

------=_NextPart_000_008C_01C6475D.B93DBF00
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: 7bit

Hi,

Here's a little vBulletin Plug-in Hack I discovered yesterday.





Summary:

On vBulletin, with vBookie installed, it is not possible to donate a
negative amount of VChips to yourself or another user; however is it
possible to alter the input string to get around this limitation and donate
any amount you want to your account, or that of another registered user!:


the hack:
in the "Donate" text-box, choose to donate 0+x where x is a positive
integer.

(here you can see the my history off a gambling forum where I have hacked
the VChips and donated 999 to a user called ukgamblingforums.co.uk)

Donate 13th March 2006 10:02 PM 0% 0+999 0.00 ukgamblingforums.co.uk



this does come up in your bank tranfer history for the board mod, but many
administrators will fail to check this.
(I was nice enough to inform the webmasters on the affected site that I
tested, about this bug)

(my fav. gambling board uses VChips to give you poker goodies such as chips,
t-shirts and so on.. perhaps you can win real prizes by using this "trick")

Discovered 13 March 2006 by paul[at]ukgamblingforums.co.uk Uk Gambling
forums, Directory and Articles <http://ukgamblingforums.co.uk>



<original article at http://ukgamblingforums.co.uk/vChipsHack.jsp>



Regards

admin@fruit-machine.net | admin@ukgamblingforums.co.uk




------=_NextPart_000_008C_01C6475D.B93DBF00
Content-Type: text/html;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dus-ascii">
<meta name=3DGenerator content=3D"Microsoft Word 11 (filtered medium)">
<style>
<!--
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman";}
a:link, span.MsoHyperlink
{color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{color:purple;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:Arial;
color:windowtext;}
@page Section1
{size:8.5in 11.0in;
margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
{page:Section1;}
-->
</style>

</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple>

<div class=3DSection1>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>Hi,<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>Here’s a little vBulletin Plug-in Hack I discovered =
yesterday…<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>Summary:<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>On vBulletin, with vBookie installed, it is not possible to =
donate a
negative amount of VChips to yourself or another user; however is it =
possible
to alter the input string to get around this limitation and donate any =
amount
you want to your account, or that of another registered =
user!:<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><br>
the hack:<br>
in the “Donate” text-box, choose to donate 0+x where x is a
positive integer.<br>
<br>
(here you can see the my history off a gambling forum where I have =
hacked the
VChips and donated 999 to a user called ukgamblingforums.co.uk) <br>
<br>
<strong><b><font face=3D"Times New Roman">Donate 13th March 2006 10:02 =
PM 0%
0+999 0.00 ukgamblingforums.co.uk </font></b></strong><br>
<br>
<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>this does come up in your bank tranfer history for the board =
mod, but
many administrators will fail to check this.<br>
(I was nice enough to inform the webmasters on the affected site that I =
tested,
about this bug)<br>
<br>
(my fav. gambling board uses VChips to give you poker goodies such as =
chips,
t-shirts and so on.. perhaps you can win real prizes by using this
"trick") <br>
<br>
Discovered 13 March 2006 by paul[at]ukgamblingforums.co.uk <a
href=3D"http://ukgamblingforums.co.uk">Uk Gambling forums, Directory and =
Articles</a><o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><original article at <a
href=3D"http://ukgamblingforums.co.uk/vChipsHack.jsp">http://ukgamblingfo=
rums.co.uk/vChipsHack.jsp</a>><o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>Regards<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><a =
href=3D"mailto:admin@fruit-machine.net">admin@fruit-machine.net</a> | <a
href=3D"mailto:admin@ukgamblingforums.co.uk">admin@ukgamblingforums.co.uk=
</a> <o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

</div>

</body>

</html>

------=_NextPart_000_008C_01C6475D.B93DBF00--

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close