You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 82 guest(s) and 1 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Remote Hack Vulnerability [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
LunaFaye
Nuke Soldier
Nuke Soldier


Joined: Jun 12, 2005
Posts: 20

Location: Columbus OH

PostPosted: Mon Jun 19, 2006 7:27 pm Reply with quoteBack to top

Has anyone heard of these? Apparently there are critical risks allowing remote hacks.

http://seclists.org/lists/bugtraq/2006/May/0682.html
http://www.securityfocus.com/archive/1/435975/30/0/threaded
http://securitytracker.com/alerts/2006/May/1016053.html

Is there a solution to these?

Luna Faye

_________________
Oracle of Pæthieon
Find all posts by LunaFayeView user's profileSend private messageVisit poster's website
spottedhog
Captain
Captain


Joined: Apr 30, 2004
Posts: 566


PostPosted: Tue Jun 20, 2006 3:12 am Reply with quoteBack to top

OK, for the first link, I am not sure if the latest bbtonuke release addresses this or not. I do not use the phpbb forums, so I am not open to these security hacks with phpbb.

2nd link, has nothing to do with PHP Nuke code.

3rd link, is a windows asp issue, which again, has nothing to do with PHP Nuke code.

_________________
SMF-Nuke admin

SMF and PHP Nuke integration is ready! Take a look at it by clicking on the link above.
Find all posts by spottedhogView user's profileSend private messageSend e-mailVisit poster's website
guardianms
Nuke Cadet
Nuke Cadet


Joined: Apr 19, 2006
Posts: 3


PostPosted: Fri Jun 23, 2006 6:41 am Reply with quoteBack to top

Luna,

I found a nice little mod for apache that seems to be working just fine for me now. I started noticing I was getting multiple shell access hacks among other things. I added mod_security and I have had no problems since.

Mod_Security analyzes the requests and data transfered for bad strings. They also keep the strings up to date and you can set a cron job to auto download the updates.

I would suggest to anyone that they get that added to their apache setup. If you are not the host, ask your host to apply this.

The only draw back I have heard about is CPU and Memory. I have not noticed any difference in load times. Maybe like from .69 to .75 at the most.

As for the asp one, I quit using asp about 2 years ago and move up to php.

_________________
God Bless,

Guardian Angel Store - Chrisitan Gifts and Books
Find all posts by guardianmsView user's profileSend private messageVisit poster's website
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.169 Seconds - 256 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::