You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 48 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - New exploit in bb forums!! plz read [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
KrAzYwHiTeBoY
Private
Private


Joined: May 26, 2003
Posts: 47


PostPosted: Mon Nov 10, 2003 11:35 pm Reply with quoteBack to top

phpBB Input Validation Flaw in 'profile.php' Lets Remote Users Inject SQL Commands found on 11/8/03

The report indicates that version 2.0.7 is not affected.But all prior versions are effected


http://www.securitytracker.com/alerts/2003/Nov/1008125.html

has there been a released fix for this yet here on NC ??
Find all posts by KrAzYwHiTeBoYView user's profileSend private message
Daniel-cmw
Site Admin
Site Admin


Joined: Mar 02, 2003
Posts: 1662

Location: The UK!

PostPosted: Tue Nov 11, 2003 3:11 am Reply with quoteBack to top

We are aware and are working on it.

See the front page for news on this that was posted yesterday.

_________________
Read Me
Find all posts by Daniel-cmwView user's profileSend private message
zanis
Lieutenant
Lieutenant


Joined: Aug 21, 2003
Posts: 213


PostPosted: Wed Nov 12, 2003 3:32 am Reply with quoteBack to top

Hi all,

What about this fix?

http://www.securiteam.com/unixfocus/6A0042K8UK.html

Best Regards

zanis
Find all posts by zanisView user's profileSend private message
Daniel-cmw
Site Admin
Site Admin


Joined: Mar 02, 2003
Posts: 1662

Location: The UK!

PostPosted: Wed Nov 12, 2003 5:32 am Reply with quoteBack to top

From our test we found that the fix stated didnt actually work well. I think.
IACOJ will be able to say a little more on this than me.

_________________
Read Me
Find all posts by Daniel-cmwView user's profileSend private message
zanis
Lieutenant
Lieutenant


Joined: Aug 21, 2003
Posts: 213


PostPosted: Wed Nov 12, 2003 2:44 pm Reply with quoteBack to top

Hi all,

Thank you for the update Daniel-cmw. Where would the nukecops fix for this security issue be posted on the web site? I have looked at the code that is at issue and it scares me to think it's that exposed to attack!!

Best regards

Zanis
Find all posts by zanisView user's profileSend private message
Daniel-cmw
Site Admin
Site Admin


Joined: Mar 02, 2003
Posts: 1662

Location: The UK!

PostPosted: Thu Nov 13, 2003 5:05 am Reply with quoteBack to top

It will be posted in the news on the main page of this site.
For a temp fix, chmod the folder /modules/Forums/admin to 000
This means nobody will be able to access it, even you until it is chmod back again.

_________________
Read Me
Find all posts by Daniel-cmwView user's profileSend private message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Thu Nov 13, 2003 4:48 pm Reply with quoteBack to top

Yes its a tough week this one. The main coders, myself and chatserv are out of commission. CS has been gone for a couple weeks now unfortunately. I'm out this week due to Cisco training, not to mention IACOJ are working on starting our lives together. IACOJ is another main coder along with mikem, and they were working on this bug with the rest of our support staff. However... its a real bad week for us all.

I'll be free again this weekend.

But let me state... I am not completely satisfied with this new exploit. I ran some tests earlier in the week without any successful break-ins.

What does this mean?

Well, we really don't have a working valid exploit. This means we really don't have anything to "patch" correctly.

We're inspecting all code, and testing what we can. This is why our patch is late in going public, because we don't really have the actual exploit.

Now if someone would care to share that with us, it would greatly improve our patch release time.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
KrAzYwHiTeBoY
Private
Private


Joined: May 26, 2003
Posts: 47


PostPosted: Thu Nov 13, 2003 6:34 pm Reply with quoteBack to top

well this is all i know on it..

Code:
Example:
http://www.example.com/forum/profile.php?mode=viewprofile&u=2

This URL shows the information for the user with the uid = 2 (the uid is a number assigned to users in phpBB). The content of the 'u' variable isn't filtered for malicious contents.

An attacker could inject arbitrary SQL commands into the system's database.

Example:
http://www.example.com/profile.php?mode=viewprofile&u='[sqlcode]


this is the best example i can give ya zhen Confused
Find all posts by KrAzYwHiTeBoYView user's profileSend private message
Daniel-cmw
Site Admin
Site Admin


Joined: Mar 02, 2003
Posts: 1662

Location: The UK!

PostPosted: Fri Nov 14, 2003 3:13 am Reply with quoteBack to top

I have tried hacking my productions site and numerous test sites on my PC with no luck.

Ill have another go in a minute but as yet that method doesnt seem to do a thing with nuke.

_________________
Read Me
Find all posts by Daniel-cmwView user's profileSend private message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Fri Nov 14, 2003 6:36 pm Reply with quoteBack to top

Yes that is all we have too, but we are unable, like Daniel said, to duplicate it.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.215 Seconds - 158 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::