You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 58 guest(s) and 1 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Fix for what hacked your site today [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
Raven
General
General


Joined: Mar 22, 2003
Posts: 5233

Location: USA

PostPosted: Mon Mar 24, 2003 9:55 am Reply with quoteBack to top

Are you going to post the fix for all of us to secure our sites even more?
Find all posts by RavenView user's profileSend private messageVisit poster's website
chatserv
General
General


Joined: Jan 12, 2003
Posts: 3128

Location: Puerto Rico

PostPosted: Mon Mar 24, 2003 10:01 am Reply with quoteBack to top

http://nukecops.com/article104.html

_________________
Feed a man a fish and you feed him for a day. Teach a man to fish and you feed him for a lifetime.
ScriptHeaven | NukeResources
Find all posts by chatservView user's profileSend private messageVisit poster's website
sixonetonoffun
Major
Major


Joined: Jan 13, 2003
Posts: 892


PostPosted: Mon Mar 24, 2003 10:06 am Reply with quoteBack to top

Would not hurt to add to your htaccess < If apache and you have access
php_flag magic_quotes_gpc on

_________________
www.netflake.com
www.glowoptics.com
Find all posts by sixonetonoffunView user's profileSend private message
Raven
General
General


Joined: Mar 22, 2003
Posts: 5233

Location: USA

PostPosted: Mon Mar 24, 2003 10:07 am Reply with quoteBack to top

chatserv wrote:
http://nukecops.com/article104.html

Ouch! So you just hadn't applied the fix (no offense intended - just understanding)
Find all posts by RavenView user's profileSend private messageVisit poster's website
Raven
General
General


Joined: Mar 22, 2003
Posts: 5233

Location: USA

PostPosted: Mon Mar 24, 2003 10:12 am Reply with quoteBack to top

sixonetonoffun wrote:
Would not hurt to add to your htaccess < If apache and you have access
php_flag magic_quotes_gpc on

I NEVER set the global setting to 'ON'. I prefer to let the application handle it through addslashes()Smile
Find all posts by RavenView user's profileSend private messageVisit poster's website
sixonetonoffun
Major
Major


Joined: Jan 13, 2003
Posts: 892


PostPosted: Mon Mar 24, 2003 10:16 am Reply with quoteBack to top

I dunno what ZX applied or didn't but if you followed the events the original patch FB posted failed. The one chatserv revised and released today doesn't.

Remember this only fixes this specific vulnerability in the News. Nothing more. As frogman pointed out there may exist others like it.

_________________
www.netflake.com
www.glowoptics.com
Find all posts by sixonetonoffunView user's profileSend private message
chatserv
General
General


Joined: Jan 12, 2003
Posts: 3128

Location: Puerto Rico

PostPosted: Mon Mar 24, 2003 10:31 am Reply with quoteBack to top

I will be looking at some of the other exploits later on and FB told me he would be doing much the same thing, i imagine others are doing so as well so expect more to come out of this, as for the fix listed in the link i posted it was edited today as the previous fix failed.

_________________
Feed a man a fish and you feed him for a day. Teach a man to fish and you feed him for a lifetime.
ScriptHeaven | NukeResources
Find all posts by chatservView user's profileSend private messageVisit poster's website
Raven
General
General


Joined: Mar 22, 2003
Posts: 5233

Location: USA

PostPosted: Mon Mar 24, 2003 10:46 am Reply with quoteBack to top

chatserv wrote:
I will be looking at some of the other exploits later on and FB told me he would be doing much the same thing, i imagine others are doing so as well so expect more to come out of this, as for the fix listed in the link i posted it was edited today as the previous fix failed.

I think this is all that is needed, isn't it? I know it's splitting hairs but it will save a cycle or two Smile. There is no way that the value can be other than 1-5, so the last 'if' test with the AND's is not needed - agree?

$score = intval($score);
if ($score) {
if ($score > 5) { $score = 5; }
if ($score < 1) { $score = 1; }
Find all posts by RavenView user's profileSend private messageVisit poster's website
chatserv
General
General


Joined: Jan 12, 2003
Posts: 3128

Location: Puerto Rico

PostPosted: Mon Mar 24, 2003 10:55 am Reply with quoteBack to top

Yes, i believe the integer value check of the $score variable should be enough but then again the rest of the code doesn't mess up anything and hence won't hurt having it there.

_________________
Feed a man a fish and you feed him for a day. Teach a man to fish and you feed him for a lifetime.
ScriptHeaven | NukeResources
Find all posts by chatservView user's profileSend private messageVisit poster's website
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.625 Seconds - 371 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::