You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 51 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - New Sentinal Exploit? [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
SubZero
Nuke Soldier
Nuke Soldier


Joined: Oct 27, 2004
Posts: 22


PostPosted: Sun Jan 23, 2005 3:24 am Reply with quoteBack to top

Okay hello all.I make it fast i running phpnuke 7.5 and got Sentinal 2.1 iinstalled.Everything is running ok but today i got a warning that my nuke is still hackable.I am not posting the Exploit only what the Exploit Shows us like this

Warning: main(): open_basedir restriction in effect. File(../../../includes/sentinel.php) is not within the allowed path(s): (/home/sonic:/usr/lib/php:/usr/local/lib/php:/tmp) in /home/111/public_html/mainfile.php on line 3

Warning: main(../../../includes/sentinel.php): failed to open stream: Operation not permitted in /home/111/public_html/mainfile.php on line 3

Warning: main(): Failed opening '../../../includes/sentinel.php' for inclusion (include_path='.:/usr/lib/php:/usr/local/lib/php') in /home/111/public_html/mainfile.php on line 3

Warning: main(): open_basedir restriction in effect. File(../../../config.php) is not within the allowed path(s): (/home/sonic:/usr/lib/php:/usr/local/lib/php:/tmp) in /home/111/public_html/mainfile.php on line 118

Warning: main(../../../config.php): failed to open stream: Operation not permitted in /home/111/public_html/mainfile.php on line 118

Fatal error: main(): Failed opening required '../../../config.php' (include_path='.:/usr/lib/php:/usr/local/lib/php') in /home/111/public_html/mainfile.php on line 118

This is it now he said that he can hack my Nuke with these Data.Any Experts here let me know if this true? and when its true how can i patch this? Waiting 4 reply thanks
Find all posts by SubZeroView user's profileSend private message
Evaders99
Site Admin
Site Admin


Joined: Aug 17, 2003
Posts: 12389


PostPosted: Sun Jan 23, 2005 11:40 am Reply with quoteBack to top

Basically its a standard path disclosure problem. Having this out won't lead to a direct attack, but it may be possible to use this knowledge to do some nasty stuff if your server is already compromised.

_________________
Helping those that help themselves
Read FIRST or DIE!

"Fighting is terrible, but not as terrible as losing the will to fight."
Star Wars Rebellion Network - Need Help? Evaders Squadron Coding
Find all posts by Evaders99View user's profileSend private messageVisit poster's websiteAIM Address
SubZero
Nuke Soldier
Nuke Soldier


Joined: Oct 27, 2004
Posts: 22


PostPosted: Sun Jan 23, 2005 10:47 pm Reply with quoteBack to top

So that means he can do some Stuff to my Site if he knows how.Any way how to patch that and is this a Server or a Nuke Problem? Please any Tips for Me Rolling Eyes
Find all posts by SubZeroView user's profileSend private message
Evaders99
Site Admin
Site Admin


Joined: Aug 17, 2003
Posts: 12389


PostPosted: Sun Jan 23, 2005 11:24 pm Reply with quoteBack to top

If you've already got your files Patched and a good security addon installed (like Sentinel), you should be fine.

_________________
Helping those that help themselves
Read FIRST or DIE!

"Fighting is terrible, but not as terrible as losing the will to fight."
Star Wars Rebellion Network - Need Help? Evaders Squadron Coding
Find all posts by Evaders99View user's profileSend private messageVisit poster's websiteAIM Address
Display posts from previous:      
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.193 Seconds - 204 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::