Home Private Messages Search
CPG Dragonfly™ CMS stopsoftwarepatents.eu petition banner
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ Phpbb hack :: Archived


Phpbb hack :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page 1, 2  Next
Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
bidibooum
Nice poster
Nice poster

Offline Offline
Joined: Jan 19, 2005
Posts: 59

PostPosted: Fri Feb 10, 2006 10:24 pm
Post subject: Phpbb hack

I've be notified for a bug in phpbb forum with the [img.] tag.

is that an update for dragonfly avalaible?

_________________
I'm French, sorry for my poor english...

bidibooum's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.29 /10333100 /4.1.18 /4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website
bigern75
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Aug 18, 2004
Posts: 2102
Location: River Valley - FS AR
PostPosted: Sat Feb 11, 2006 12:21 am
Post subject: Re: Phpbb hack

bidibooum please enter your server specs in your user profile! Twisted Evil

_________________
iPad 1

bigern75's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/2.2.6/5.0.86/5.2.8/9.3.2
Back to top
View user's profile Visit poster's website
bidibooum
Nice poster
Nice poster

Offline Offline
Joined: Jan 19, 2005
Posts: 59

PostPosted: Sat Feb 11, 2006 11:11 am
Post subject: Re: Phpbb hack

I use the latest dragonfly cms, and my webhosting is infomaniak.

_________________
I'm French, sorry for my poor english...

bidibooum's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.29 /10333100 /4.1.18 /4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website
alva
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: May 31, 2005
Posts: 1150
Location: The Netherlands
PostPosted: Sat Feb 11, 2006 11:18 am
Post subject: Re: Phpbb hack

OS/Apache/MySQL/PHP/CPGNuke versions: *


alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
bidibooum
Nice poster
Nice poster

Offline Offline
Joined: Jan 19, 2005
Posts: 59

PostPosted: Sat Feb 11, 2006 11:23 am
Post subject: Re: Phpbb hack

I don't know if that correct...

but the informatiosn here are too
imu33.infomaniak.ch/info

_________________
I'm French, sorry for my poor english...

bidibooum's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.29 /10333100 /4.1.18 /4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website
alva
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: May 31, 2005
Posts: 1150
Location: The Netherlands
PostPosted: Sat Feb 11, 2006 12:32 pm
Post subject: Re: Phpbb hack

Many phpbb-issues don't apply to cpgbb. If one does then I'm pretty sure there will be an announcement in the Community Center or the Security Forum.

(To make your specs readily readible and understandable you could use a questionmark (?) for Apache, leave out PERL and switch orders for PHP and MySQL.)


alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
bidibooum
Nice poster
Nice poster

Offline Offline
Joined: Jan 19, 2005
Posts: 59

PostPosted: Sun Feb 12, 2006 8:13 pm
Post subject: Re: Phpbb hack

:s

_________________
I'm French, sorry for my poor english...

bidibooum's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.29 /10333100 /4.1.18 /4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website
pretzy
500+ Posts Club
500+ Posts Club

Offline Offline
Joined: Sep 09, 2005
Posts: 519
Location: Australia
PostPosted: Sun Feb 12, 2006 8:25 pm
Post subject: Re: Phpbb hack

change this

"bidibooum's server specs (Server OS / Apache / MySQL / PHP / CPG-Nuke)
Linux/4.4.2/5.008002/4.1.12/9.0.6.1"

to this Smile

bidibooum's server specs (Server OS / Apache / MySQL / PHP / CPG-Nuke)
Linux/Apache?/4.1.12/4.4.2/9.0.6.1

_________________
Pretzy's Place Pertzel Family Tree History Genealogy
Riverlife Church Henty

pretzy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
XP_Apache 2.2.2_MySQL 5.0.21_PHP 5.1.4_CPGNuke 9.1.1
Back to top
View user's profile Visit poster's website
bidibooum
Nice poster
Nice poster

Offline Offline
Joined: Jan 19, 2005
Posts: 59

PostPosted: Sun Feb 12, 2006 8:28 pm
Post subject: Re: Phpbb hack

ok thanks.

_________________
I'm French, sorry for my poor english...

bidibooum's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.29 /10333100 /4.1.18 /4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website
bidibooum
Nice poster
Nice poster

Offline Offline
Joined: Jan 19, 2005
Posts: 59

PostPosted: Sun Feb 12, 2006 8:33 pm
Post subject: Re: Phpbb hack

for the exploit here the source.

create a folder 'sig.jpg' on your webserver.
create a index.php page and putt this code in

Code::
<?php header("Location: http://yourwebsite/index.php?name=Your_Account&op=logout" ); exit; ?>

now, go to your website and insert
Code::
[img]http://yourwebsite/sig.jpg[/img] on a forum.

All visitor their visit your post is disconnected.

_________________
I'm French, sorry for my poor english...

bidibooum's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.29 /10333100 /4.1.18 /4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website
alva
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: May 31, 2005
Posts: 1150
Location: The Netherlands
PostPosted: Sun Feb 12, 2006 9:25 pm
Post subject: Re: Phpbb hack

I don't think you will find such code in Dragonfly Forums, or anywhere... Docs/f=url_redirect.html


alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
bidibooum
Nice poster
Nice poster

Offline Offline
Joined: Jan 19, 2005
Posts: 59

PostPosted: Mon Feb 13, 2006 4:43 pm
Post subject: Re: Phpbb hack

I don't understand you.

_________________
I'm French, sorry for my poor english...

bidibooum's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.29 /10333100 /4.1.18 /4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website
spacebar
Dragonfly addicted
Dragonfly addicted

Offline Offline
Joined: Sep 28, 2005
Posts: 413
Location: Providence
PostPosted: Mon Feb 13, 2006 7:46 pm
Post subject: Re: Phpbb hack

Any ideas on how to fix this?

_________________


spacebar's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Unix / 2.0.46 (Red Hat) / 0.9.7a / 4.1.9-standard / 4.3.2 / 9.0.6.1
Back to top
View user's profile Visit poster's website ICQ Number AIM Address MSN Messenger Yahoo Messenger
DJ Maze
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 5683
Location: http://tinyurl.com/5z8dmv
PostPosted: Mon Feb 13, 2006 9:33 pm
Post subject: Re: Phpbb hack

Fix is easy just remove the img from the post.
Akamu and i did talk about remote validation but this is just nuts.
Let me explain why.

Every submitted data must be split and not only the images but also archives and multimedia like flash needs to be validated.
The issue is that on each "view" request you must validate the remote content.
If we only did this on submit the remote website can always modify the file afterwards.

lets give me an example:

You submit the above mentioned img and the website verifies the image on submit. By checking the first 4 bytes of the content of yourwebsite/sig.jpg.
When verified and the data is submitted the owner of sig.jpg modifies it into a redirect.
The exploit is still there.

Solution:

Check the 4 bytes of the remote file on each "view" request.
The issue here is that your website first has to make a connection to the remote servers to check all remote images.
This will add a massive overhead on very regular visited websites.

Conclusion:

Just ignore this exploit since it will not do any damage anyway because Dragonfly needs the POST method for all important controls. This exploit only provides access to GET annoyancees.

If you are realy scared then just remove the [img] tag from the /includes/nbbcode.php file.
But do keep in mind this will make your website less accessible.

NOTE: this is not only related to the bbcode [img] all other systems and especialy the WYSIWYG are vulnerable for these kinds of attacks.
That's also one of the reasons why the wysiwyg system in Dragonfly is still unsupported and in beta stage.
We know you want wysiwyg in anything, including the News and Content modules, but i hope you now atleast know why only the administration newsletter system supports it.

Reason: the reason why we still support multimedia links is simple. If we removed/disallowed remote data the use and attraction to your website will be lowered to a minimum. For example you have a website about a FPS game or RPG. You need images to show your WOOT level or to show hidden areas or tricks in a game.
If that was gone i know 80% of our users complaints in these forums why we don't support media.


DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora 15 / 2.2.22 / 5.5.20 / 5.3.10 / CVS
Back to top
View user's profile Visit poster's website Yahoo Messenger Photo Gallery
spacebar
Dragonfly addicted
Dragonfly addicted

Offline Offline
Joined: Sep 28, 2005
Posts: 413
Location: Providence
PostPosted: Mon Feb 13, 2006 9:55 pm
Post subject: Re: Phpbb hack

True. I've spent some time thinking about this as well.

I supose if it got really bad, a confirmation button to click "yes" to logout could be put in.

Also since in my forums you have to be a reg. member to post, I'd quickly ban the IP of anyone who was stupid enough to do this... and the IP is logged for those who submit news... etc.

_________________


spacebar's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Unix / 2.0.46 (Red Hat) / 0.9.7a / 4.1.9-standard / 4.3.2 / 9.0.6.1
Back to top
View user's profile Visit poster's website ICQ Number AIM Address MSN Messenger Yahoo Messenger
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 2
All times are GMT
Go to page 1, 2  Next

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

もっと読む

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy