Time Nick Message 16:41 cheapie One downside of playing around in Luanti too much: every time I go to configure something using meson, I mistype the command as "mesecon" the first time around 16:52 heston76 lol 17:09 cheapie Meanwhile, one of the fun parts about running Luanti on a riscv64 CPU - with careful programming, it's possible to write a program, assemble it, run it on the real hardware here and have it do something, then copy/paste the same binary into RVController in-game and have it still work and still do the same thing with no modification 17:10 cheapie They have different word sizes, but it's possible for a program to be written such that it autodetects it and adjusts accordingly 18:12 MTDiscord running mesecon build should compile luanti for your riscv emulator 18:14 cheapie TBH about all I'm really missing for something like that (aside from more memory) is interrupts, the privileged architecture, a suitable SBI, and paging 18:25 [MatrxMT] celeron55: https://pentest-tools.com/research/phpbb-authentication-bypass 18:25 [MatrxMT] The Luanti forums are vulnerable to an authentication bypass and should be updated post haste 18:25 [MatrxMT] A friend of mine has already succeeded in signing in to celeron55's account 18:27 badforum Hi, indeed I did, sorry for being invasive but usually this makes the admins far more likely to patch it ASAP: https://forum.luanti.org/viewtopic.php?p=3861#p3861 I only edited this post, haven't checked any other private things. https://www.phpbb.com/community/viewtopic.php?t=2672170 18:30 MTDiscord a critical vulnerability discovered in phpbb, what decade is this?? 18:36 MTDiscord quick, someone use it to improve the forum 18:37 MTDiscord seems like the ACP is inaccessible since that requires another authentication step... 18:37 MTDiscord also this REALLY should have been a private message to c55 rather than announcing "hey you can log into anyone's account on the forums", especially since you know how the forum is... well, maybe a bit neglected maintenance-wise 18:38 badforum ACP is available through default phpBB functionality, the article is incorrect in that 18:38 MTDiscord oh that's even worse 18:38 MTDiscord well I guess that's the end of the forums 18:38 badforum You can't know the admin password of the existing admin accounts so you can't login into ACP from that, but you can make a new account and make it an admin. 18:38 badforum Then you know the password for ACP 18:39 MTDiscord so repetativestrain alt on irc? 18:39 badforum no, i"m not him 18:39 badforum im a completely unrelated person, we just chat with repetitivestrain sometimes on other platforms 18:40 badforum the worst thing that I'm very saddened about is that phpBB is by choice keeping the vulnerability under the wraps, no public CVE yet, and the update announcement is very tame compared to what the vulnerability is 18:40 badforum if anything they should be screaming about it loudly to at least make some of the somewhat-maintained phpBB forums upgrade before its too late 18:41 MTDiscord yeah the release announcement forum post makes it sound like just a little bugfix release 18:41 MTDiscord I would have expected big bold red text 18:41 badforum its buried in "Furthermore, two separate improper checks in the previous OAuth implementation could have been used to hijack user accounts. One of these did not require OAuth to be configured or enabled. We’d like to thank Aikido Security (aikido.dev) for reporting to us via HackerOne, as well as Dan Stefan Alexandru of Pentest-Tools.com and 18:41 badforum Himanshu Anand for reporting to us via email." 18:42 MTDiscord github has an advisory for it but it's not even attached to the phpbb/phpbb repository: https://github.com/advisories/GHSA-24pr-8ggp-h88c 18:43 badforum oh it was only published 12 hours ago, it wasn't there yesterday, nice 23:01 tzenfore Does anyone here happen to have a Windows ARM device they could test a build on? I'm finally getting around to building 5.16.1 for Windows ARM, but I lack a Windows ARM laptop to test it on :/ 23:03 [MatrxMT] btw the ACP isn't needed to wreck havoc, I use BanHammer regularly with no further auth needed