Phpbb hack
Post new topic   Reply to topic   Printer Friendly Page     Forum IndexSecurity
Author Message
bidibooum
Nice poster


Joined: Jan 19, 2005
Posts: 59

PostPost subject: Phpbb hack
Posted: Fri Feb 10, 2006 10:24 pm
Reply with quote

I've be notified for a bug in phpbb forum with the [img.] tag.

is that an update for dragonfly avalaible?

_________________
I'm French, sorry for my poor english...

bidibooum's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.29 /10333100 /4.1.18 /4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website
bigern75
Platinum Supporter


Joined: Aug 18, 2004
Posts: 2102

PostPost subject: Re: Phpbb hack
Posted: Sat Feb 11, 2006 12:21 am
Reply with quote

bidibooum please enter your server specs in your user profile! Twisted Evil
_________________
iPad 1 running iOS 5.1 b2

bigern75's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/2.2.6/5.0.86/5.2.8/9.3.2
Back to top
View user's profile Visit poster's website
bidibooum
Nice poster


Joined: Jan 19, 2005
Posts: 59

PostPost subject: Re: Phpbb hack
Posted: Sat Feb 11, 2006 11:11 am
Reply with quote

I use the latest dragonfly cms, and my webhosting is infomaniak.
_________________
I'm French, sorry for my poor english...

bidibooum's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.29 /10333100 /4.1.18 /4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website
alva
1000+ Posts Club


Joined: May 31, 2005
Posts: 1150
Location: The Netherlands

PostPost subject: Re: Phpbb hack
Posted: Sat Feb 11, 2006 11:18 am
Reply with quote

OS/Apache/MySQL/PHP/CPGNuke versions: *

alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
bidibooum
Nice poster


Joined: Jan 19, 2005
Posts: 59

PostPost subject: Re: Phpbb hack
Posted: Sat Feb 11, 2006 11:23 am
Reply with quote

I don't know if that correct...

but the informatiosn here are too
imu33.infomaniak.ch/info

_________________
I'm French, sorry for my poor english...

bidibooum's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.29 /10333100 /4.1.18 /4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website
alva
1000+ Posts Club


Joined: May 31, 2005
Posts: 1150
Location: The Netherlands

PostPost subject: Re: Phpbb hack
Posted: Sat Feb 11, 2006 12:32 pm
Reply with quote

Many phpbb-issues don't apply to cpgbb. If one does then I'm pretty sure there will be an announcement in the Community Center or the Security Forum.

(To make your specs readily readible and understandable you could use a questionmark (?) for Apache, leave out PERL and switch orders for PHP and MySQL.)


alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
bidibooum
Nice poster


Joined: Jan 19, 2005
Posts: 59

PostPost subject: Re: Phpbb hack
Posted: Sun Feb 12, 2006 8:13 pm
Reply with quote

:s
_________________
I'm French, sorry for my poor english...

bidibooum's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.29 /10333100 /4.1.18 /4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website
pretzy
500+ Posts Club


Joined: Sep 09, 2005
Posts: 519
Location: Australia

PostPost subject: Re: Phpbb hack
Posted: Sun Feb 12, 2006 8:25 pm
Reply with quote

change this

"bidibooum's server specs (Server OS / Apache / MySQL / PHP / CPG-Nuke)
Linux/4.4.2/5.008002/4.1.12/9.0.6.1"

to this Smile

bidibooum's server specs (Server OS / Apache / MySQL / PHP / CPG-Nuke)
Linux/Apache?/4.1.12/4.4.2/9.0.6.1

_________________
Pretzy's Place Pertzel Family Tree History Genealogy
Riverlife Church Henty

pretzy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
XP_Apache 2.2.2_MySQL 5.0.21_PHP 5.1.4_CPGNuke 9.1.1
Back to top
View user's profile Visit poster's website
bidibooum
Nice poster


Joined: Jan 19, 2005
Posts: 59

PostPost subject: Re: Phpbb hack
Posted: Sun Feb 12, 2006 8:28 pm
Reply with quote

ok thanks.
_________________
I'm French, sorry for my poor english...

bidibooum's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.29 /10333100 /4.1.18 /4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website
bidibooum
Nice poster


Joined: Jan 19, 2005
Posts: 59

PostPost subject: Re: Phpbb hack
Posted: Sun Feb 12, 2006 8:33 pm
Reply with quote

for the exploit here the source.

create a folder 'sig.jpg' on your webserver.
create a index.php page and putt this code in

Code:
<?php header("Location: http://yourwebsite/index.php?name=Your_Account&op=logout" ); exit; ?>

now, go to your website and insert
Code:
[img]http://yourwebsite/sig.jpg[/img] on a forum.

All visitor their visit your post is disconnected.

_________________
I'm French, sorry for my poor english...

bidibooum's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.29 /10333100 /4.1.18 /4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website
alva
1000+ Posts Club


Joined: May 31, 2005
Posts: 1150
Location: The Netherlands

PostPost subject: Re: Phpbb hack
Posted: Sun Feb 12, 2006 9:25 pm
Reply with quote

I don't think you will find such code in Dragonfly Forums, or anywhere... Docs/f=url_redirect.html

alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
bidibooum
Nice poster


Joined: Jan 19, 2005
Posts: 59

PostPost subject: Re: Phpbb hack
Posted: Mon Feb 13, 2006 4:43 pm
Reply with quote

I don't understand you.
_________________
I'm French, sorry for my poor english...

bidibooum's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.29 /10333100 /4.1.18 /4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website
spacebar
Dragonfly addicted


Joined: Sep 28, 2005
Posts: 413
Location: Providence

PostPost subject: Re: Phpbb hack
Posted: Mon Feb 13, 2006 7:46 pm
Reply with quote

Any ideas on how to fix this?
_________________


spacebar's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Unix / 2.0.46 (Red Hat) / 0.9.7a / 4.1.9-standard / 4.3.2 / 9.0.6.1
Back to top
View user's profile Visit poster's website ICQ Number AIM Address MSN Messenger Yahoo Messenger
DJ Maze
Developer


Joined: Apr 19, 2004
Posts: 5668
Location: http://tinyurl.com/5z8dmv

PostPost subject: Re: Phpbb hack
Posted: Mon Feb 13, 2006 9:33 pm
Reply with quote

Fix is easy just remove the img from the post.
Akamu and i did talk about remote validation but this is just nuts.
Let me explain why.

Every submitted data must be split and not only the images but also archives and multimedia like flash needs to be validated.
The issue is that on each "view" request you must validate the remote content.
If we only did this on submit the remote website can always modify the file afterwards.

lets give me an example:

You submit the above mentioned img and the website verifies the image on submit. By checking the first 4 bytes of the content of yourwebsite/sig.jpg.
When verified and the data is submitted the owner of sig.jpg modifies it into a redirect.
The exploit is still there.

Solution:

Check the 4 bytes of the remote file on each "view" request.
The issue here is that your website first has to make a connection to the remote servers to check all remote images.
This will add a massive overhead on very regular visited websites.

Conclusion:

Just ignore this exploit since it will not do any damage anyway because Dragonfly needs the POST method for all important controls. This exploit only provides access to GET annoyancees.

If you are realy scared then just remove the [img] tag from the /includes/nbbcode.php file.
But do keep in mind this will make your website less accessible.

NOTE: this is not only related to the bbcode [img] all other systems and especialy the WYSIWYG are vulnerable for these kinds of attacks.
That's also one of the reasons why the wysiwyg system in Dragonfly is still unsupported and in beta stage.
We know you want wysiwyg in anything, including the News and Content modules, but i hope you now atleast know why only the administration newsletter system supports it.

Reason: the reason why we still support multimedia links is simple. If we removed/disallowed remote data the use and attraction to your website will be lowered to a minimum. For example you have a website about a FPS game or RPG. You need images to show your WOOT level or to show hidden areas or tricks in a game.
If that was gone i know 80% of our users complaints in these forums why we don't support media.


DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora 12 / 2.2.15 / 5.1.47 / 5.3.3 / CVS
Back to top
View user's profile Visit poster's website Yahoo Messenger
spacebar
Dragonfly addicted


Joined: Sep 28, 2005
Posts: 413
Location: Providence

PostPost subject: Re: Phpbb hack
Posted: Mon Feb 13, 2006 9:55 pm
Reply with quote

True. I've spent some time thinking about this as well.

I supose if it got really bad, a confirmation button to click "yes" to logout could be put in.

Also since in my forums you have to be a reg. member to post, I'd quickly ban the IP of anyone who was stupid enough to do this... and the IP is logged for those who submit news... etc.

_________________


spacebar's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Unix / 2.0.46 (Red Hat) / 0.9.7a / 4.1.9-standard / 4.3.2 / 9.0.6.1
Back to top
View user's profile Visit poster's website ICQ Number AIM Address MSN Messenger Yahoo Messenger
Display posts from previous:   
Post new topic   Reply to topic   Printer Friendly Page     Forum IndexSecurity All times are GMT
Go to page 1, 2  Next
Page 1 of 2


Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum

stopsoftwarepatents.eu petition banner
User Info [x]

Welcome Anonymous

Nickname
Password
(Register)

Last CVS commits [x]

Languages [x]

Community [x]

Support for DragonflyCMS in a other languages:

Deutsch
Español

X-links [x]
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

Preview theme [x]
Each user can view the site with a different theme.
Themes marked with a * also change the forum look.


You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
This page generated in 0.511 seconds with 17 DB Queries in 0.1467 seconds
Memory Usage: 3.11 MB
Interactive software released under GNU GPL, Code Credits, Privacy Policy