Home Private Messages Search
CPG Dragonfly™ CMS stopsoftwarepatents.eu petition banner
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ CRITICAL: phpBB Search Exploit, Follow-up :: Archived


CRITICAL: phpBB Search Exploit, Follow-up :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page Previous  1, 2, 3, 4
Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
tank
Gold Supporter
Gold Supporter

Offline Offline
Joined: Apr 20, 2004
Posts: 824
Location: Houston, Texas USA
PostPosted: Mon Jan 03, 2005 4:53 pm
Post subject: Re: CRITICAL: phpBB Search Exploit, Follow-up

williamj wrote:
Is the current download of 8.2b fixed? or do these files still need to be patched?

Thank you,

8.2b was reaeased months ago so I would say that the files need to be patched.

_________________
Search is your friend

tank's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora Core 1, Apache 1.3.33, Mysql 4.1.14, PHP 5.0.5 w/ APC cache, Dragonfly 9.0.6.1
Back to top
View user's profile Visit poster's website
djdevon3
Gold Supporter
Gold Supporter

Offline Offline
Joined: Aug 05, 2004
Posts: 4363

PostPosted: Mon Jan 03, 2005 5:02 pm
Post subject: Re: CRITICAL: phpBB Search Exploit, Follow-up

we can release a patched version on cpgnukefiles. everything the same but with the patch. can't imagine they wouldn't patch 8.2b and reupload.


djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.4/4.3.11
Back to top
View user's profile Visit poster's website Photo Gallery
Jeruvy
Security Team
Security Team

Offline Offline
Joined: Apr 23, 2004
Posts: 1432
Location: Canada
PostPosted: Mon Jan 03, 2005 5:06 pm
Post subject: Re: CRITICAL: phpBB Search Exploit, Follow-up

There was a patch released for cpgnuke 8.2b in the downloads, but I'll be damned if I can find it...anyone want to clarify what zip tg.gz file is the 8.2b patch?

_________________
J.
j e r u v y a t y a h o o d o t c o m

Need help? Look here: www.dragonflycms.org/W...d=112.html
Need to chat? Look for me on irc.freenode.net

Jeruvy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Ubuntu7.10/Debian3.1 - 2.2.3/1.3.37 - 5.0.38/4.0.27 - 5.2.1/4.4.7 - CVS/9.1.2}
Back to top
View user's profile ICQ Number Yahoo Messenger Photo Gallery
williamj
Newbie
Newbie

Offline Offline
Joined: Jan 03, 2005
Posts: 14

PostPosted: Mon Jan 03, 2005 5:33 pm
Post subject: Re: CRITICAL: phpBB Search Exploit, Follow-up

I to need the patch please. Can somebody point us to it or do we need to do the manual upgrades? This is the kind of stuff that makes me wonder if GPGNuke is the right package for us. Known exploits but not included in the current installation package??? Sad

Thank you,


williamj please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile
Jeruvy
Security Team
Security Team

Offline Offline
Joined: Apr 23, 2004
Posts: 1432
Location: Canada
PostPosted: Mon Jan 03, 2005 5:37 pm
Post subject: Re: CRITICAL: phpBB Search Exploit, Follow-up

8.2b was released in July 2004, and is NOT current.

CVS is current and is patched.

Just to clarify williamj's points.


BTW attachment mod will ALWAYS have problems and expect to see more exploits in the near future using this code. If you enable attachments and uploads to your site you should be ten times more diligent than another web admin who disables such functions.

Trust me we haven't seen the end of exploits on attachments_mod.

I doubt it will ever be 100% secure.

However I'm very confident that myself and others here will keep on top of these concerns and issues and address them. But not always is there going to be a patch for old versions.

Wish you well,

_________________
J.
j e r u v y a t y a h o o d o t c o m

Need help? Look here: www.dragonflycms.org/W...d=112.html
Need to chat? Look for me on irc.freenode.net

Jeruvy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Ubuntu7.10/Debian3.1 - 2.2.3/1.3.37 - 5.0.38/4.0.27 - 5.2.1/4.4.7 - CVS/9.1.2}


Last edited by Jeruvy on Mon Jan 03, 2005 5:43 pm; edited 1 time in total
Back to top
View user's profile ICQ Number Yahoo Messenger Photo Gallery
williamj
Newbie
Newbie

Offline Offline
Joined: Jan 03, 2005
Posts: 14

PostPosted: Mon Jan 03, 2005 5:41 pm
Post subject: Re: CRITICAL: phpBB Search Exploit, Follow-up

I thought the CVS code was only Version 9 and not recommended for production sites??? Is there an explanation of CVS and how it is supposed to be used anywhere. I run 2 other phpBB's and I know that you are 100% right about the attachment mod. It is a HUGE security risk.

Thank you VERY much for your help!! I may even consider running the V9 code, but I need to learn a lot more about CVS and how to stay up to date, etc before I do. If you can explain this and would rather do it by phone or something like that to make it easy I would be happy to call or you can call me or however. We are trying to roll out a GPGNuke site as an alternative to a straight phpBB2 site, but we need to keep from compromising all the rest of the sites on the box.

Thank you in advance!!

Please PM if we can phone.

Will


williamj please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile
Jeruvy
Security Team
Security Team

Offline Offline
Joined: Apr 23, 2004
Posts: 1432
Location: Canada
PostPosted: Mon Jan 03, 2005 5:48 pm
Post subject: Re: CRITICAL: phpBB Search Exploit, Follow-up

Yes you are right. CVS code is version 9 and not recommended for production sites. Doesn't mean you CANNOT, I do. But....

There are bugs still that are being worked on, and no support will be provided until they are stabilized.

As for the remainder of your remarks I'm a bit confused, how would it affect other sites?

If you wish to bug me on icq or yahoo, or irc I can be found online, not necesarily at the keyboad (I have too bloody many Wink feel free. )

_________________
J.
j e r u v y a t y a h o o d o t c o m

Need help? Look here: www.dragonflycms.org/W...d=112.html
Need to chat? Look for me on irc.freenode.net

Jeruvy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Ubuntu7.10/Debian3.1 - 2.2.3/1.3.37 - 5.0.38/4.0.27 - 5.2.1/4.4.7 - CVS/9.1.2}
Back to top
View user's profile ICQ Number Yahoo Messenger Photo Gallery
djdevon3
Gold Supporter
Gold Supporter

Offline Offline
Joined: Aug 05, 2004
Posts: 4363

PostPosted: Wed Jan 05, 2005 1:45 pm
Post subject: Re: CRITICAL: phpBB Search Exploit, Follow-up

looks like 8.2c was released. good job guys. thank you, your securityness. Smile


djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.4/4.3.11
Back to top
View user's profile Visit poster's website Photo Gallery
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 4 of 4
All times are GMT
Go to page Previous  1, 2, 3, 4

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.
· Removed index.php depency.
· v9 fixed menu hoverings on touch screens.
· Fixed menu hoverings on touch screens.
· Fixed empty $Module object

read more...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy