Клубове Дир.бг
powered by diri.bg
търси в Клубове diri.bg Разширено търсене

Вход
Име
Парола

Клубове
Dir.bg
Взаимопомощ
Горещи теми
Компютри и Интернет
Контакти
Култура и изкуство
Мнения
Наука
Политика, Свят
Спорт
Техника
Градове
Религия и мистика
Фен клубове
Хоби, Развлечения
Общества
Я, архивите са живи
Клубове Дирене Регистрация Кой е тук Въпроси Списък Купувам / Продавам 13:05 23.04.24 
Клубове/ Компютри и Интернет / Хакери, Кракери .... Пълен преглед*
Информация за клуба
Тема Re: PHPbb hack? [re: Morrowind]
Авторrichard (Нерегистриран) 
Публикувано26.12.04 12:29  



aide troshi!

Original release date: December 21, 2004
Last revised: --
Source: US-CERT

Systems Affected

phpBB versions 2.0.10 and prior

Overview

The software phpBB contains an input validation problem in how it
processes a parameter contained in URLs. An intruder can deface a
phpBB website, execute arbitrary commands, or gain administrative
privileges on a compromised bulletin board.

I. Description

phpBB is an open-source bulletin board application. It fails to
properly perform an urldecode() on the "highlight" parameter supplied
to viewtopic.php. This may allow a remote attacker to execute
arbitrary commands on a vulnerable server.

According to reports, this vulnerability is being actively exploited
by the Santy.A worm. The worm appears to propogate by searching for
the keyword "viewtopic.php" in order to find vulnerable sites.

The worm writes itself to a file named "m1ho2of" on the compromised
system. It then overwrites files ending with .htm, .php, .asp. shtm,
.jsp, and .phtm replacing them with HTML content that defaces the web
page. The worm then tries to use PERL to execute itself on the
compromised system and propogate further.
US-CERT is tracking this issue as:

VU#497400 - phpBB viewtopic.php fails to properly sanitize input
passed to the "highlight" parameter

II. Impact

A remote attacker may be able to deface a phpBB website and execute
arbitrary commands on a compromised bulletin board.

III. Solution

Upgrade phpBB

Upgrade to phpBB verison 2.0.11 to prevent exploitation.

Appendix A. References

* US-CERT Vulnerability Note VU#497400 -
<http://www.kb.cert.org/vuls/id/497400>
* phpBB Downloads - < http://www.phpbb.com/downloads.php>
* phpBB Announcement -
<http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240636>
* Symantec Security Response - Perl.Santy -
<http://securityresponse.symantec.com/avcenter/venc/data/perl.santy
.html>
* McAfee - Computer Virus Software and Internet Security -
<http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=
130471>
_________________________________________________________________

This vulnerability was reported by the phpBB Development Team.
_________________________________________________________________

Feedback can be directed to the authors: Jeffrey Gennari and
Jason Rafail
_________________________________________________________________

This document is available from:

<http://www.us-cert.gov/cas/techalerts/TA04-356A.html>

_________________________________________________________________

Copyright 2004 Carnegie Mellon University.

Terms of use: <http://www.us-cert.gov/legal.html>
_________________________________________________________________

Revision History

Dec 21, 2004: Initial release





Цялата тема
ТемаАвторПубликувано
* PHPbb hack? Morrowind   02.12.04 15:55
. * Re: PHPbb hack? ro6avia   03.12.04 10:18
. * Re: PHPbb hack? Morrowind   03.12.04 17:33
. * Re: PHPbb hack? SomethingWrong   21.12.04 00:24
. * Re: PHPbb hack? phpBB   23.12.04 07:57
. * Re: PHPbb hack? richard   26.12.04 12:29
. * Re: PHPbb hack? phpBB   08.01.05 23:16
. * Re: PHPbb hack? haha   10.01.05 17:44
. * Re: PHPbb hack? pgpgp   22.01.05 02:15
. * Re: PHPbb hack? demon   09.01.05 17:34
. * Re: PHPbb hack? haha   10.01.05 17:43
. * Re: PHPbb hack? БaбaПeнka (CoM1)   24.01.05 14:13
. * Re: PHPbb hack? The Priest   24.01.05 18:33
. * Re: PHPbb hack? ethernall   29.01.05 01:42
. * Re: PHPbb hack? CoM1   31.01.05 20:30
Клуб :  


Clubs.dir.bg е форум за дискусии. Dir.bg не носи отговорност за съдържанието и достоверността на публикуваните в дискусиите материали.

Никаква част от съдържанието на тази страница не може да бъде репродуцирана, записвана или предавана под каквато и да е форма или по какъвто и да е повод без писменото съгласие на Dir.bg
За Забележки, коментари и предложения ползвайте формата за Обратна връзка | Мобилна версия | Потребителско споразумение
© 2006-2024 Dir.bg Всички права запазени.