Home Private Messages Search
CPG Dragonfly™ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ Phpbb Security Vulnerablity - is CPG Nuke affected? :: Archived


Phpbb Security Vulnerablity - is CPG Nuke affected? :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page 1, 2  Next
Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
jstillion
Silver Supporter
Silver Supporter

Offline Offline
Joined: Jul 07, 2004
Posts: 29
Location: Untied States, Ohio
PostPosted: Tue Dec 21, 2004 6:48 pm
Post subject: Phpbb Security Vulnerablity - is CPG Nuke affected?

I just says this on the tech sites....

www.kaspersky.com/news?id=156681162

Santy.a is something of a novelty - it creates a specially formulated Google search request, which results in a list of sites running vulnerable versions of phpBB. It then sends a request containing a procedure which will trigger the vulnerability to these sites. Once the attacked server processes the request, the worm will penetrate the site, gaining control over the resource. It then repeats this routine.

I was wondering if CPG Nuke 8.2B is affected / abled to be scanned?
I do have the Critical phpBB Exploit Affects 8.x patched from the post on this main site.


jstillion please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile Visit poster's website
djdevon3
Gold Supporter
Gold Supporter

Offline Offline
Joined: Aug 05, 2004
Posts: 4363

PostPosted: Wed Dec 22, 2004 1:34 am
Post subject: Re: Phpbb Security Vulnerablity - is CPG Nuke affected?

www.f-secure.com/v-des...ty_a.shtml

Is the 8.2b viewtopic patch that was released 2 weeks ago already cover this or should we expect something new from the security team?


djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.4/4.3.11
Back to top
View user's profile Visit poster's website Photo Gallery
Trevor
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 2170
Location: New York
PostPosted: Wed Dec 22, 2004 1:35 am
Post subject: Re: Phpbb Security Vulnerablity - is CPG Nuke affected?

The viewtopic patch should cover this.


Trevor's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux / 1.3.34 / 4.1.18 / 4.4.2 / CVS
Back to top
View user's profile Photo Gallery
djdevon3
Gold Supporter
Gold Supporter

Offline Offline
Joined: Aug 05, 2004
Posts: 4363

PostPosted: Wed Dec 22, 2004 8:03 am
Post subject: Re: Phpbb Security Vulnerablity - is CPG Nuke affected?

sounds like someone came up with it after they found the security hole and coded the worm for it? and i thought i had no life. whoever does something like that has deep issues. they should coin the phrase internet terrorism. that's all these viruses and worms do. it just incites hatred for those that make them. that's not gaining popularity for your skills. that's being a big lamer.


djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.4/4.3.11
Back to top
View user's profile Visit poster's website Photo Gallery
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Wed Dec 22, 2004 2:38 pm
Post subject: Re: Phpbb Security Vulnerablity - is CPG Nuke affected?

djdevon3 wrote:
they should coin the phrase internet terrorism.
Someone did, long ago, but not for that context.
en.wikipedia.org/wiki/..._terrorism

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
djdevon3
Gold Supporter
Gold Supporter

Offline Offline
Joined: Aug 05, 2004
Posts: 4363

PostPosted: Mon Dec 27, 2004 6:05 am
Post subject: Re: Phpbb Security Vulnerablity - is CPG Nuke affected?

Think about it. Worms like this destroy entire communities. Just because it doesn't kill someone doesn't mean it's not terrorism. {expletive removed} like this should be handled by the FBI or interpol.


djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.4/4.3.11
Back to top
View user's profile Visit poster's website Photo Gallery
shimon
Nice poster
Nice poster

Offline Offline
Joined: Jul 25, 2004
Posts: 146

PostPosted: Mon Dec 27, 2004 12:11 pm
Post subject: Re: Phpbb Security Vulnerablity - is CPG Nuke affected?

this is why cpgnuke need a better backing up system but luckly for me vhcs my control panel on my server has advance site back uping features

_________________
/media/internet

shimon's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
GNU/Debian / Apache 2.latest / MySQL 4.latest / PHP 4.latest / CPGNuke CVS
Back to top
View user's profile Send e-mail Visit poster's website
blackmetalcouk
Newbie
Newbie

Offline Offline
Joined: Oct 22, 2004
Posts: 36

PostPosted: Mon Dec 27, 2004 9:43 pm
Post subject: Re: Phpbb Security Vulnerablity - is CPG Nuke affected?

is version 9.0 affected?


blackmetalcouk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.6.9-22.0.1.ELsmp / Apache 1.3.34 / MySQL 4.0.25 / PHP 4.4.0 / Current 9 CVS
Back to top
View user's profile Visit poster's website
tank
Gold Supporter
Gold Supporter

Offline Offline
Joined: Apr 20, 2004
Posts: 824
Location: Houston, Texas USA
PostPosted: Mon Dec 27, 2004 10:20 pm
Post subject: Re: Phpbb Security Vulnerablity - is CPG Nuke affected?

blackmetalcouk wrote:
is version 9.0 affected?

as it states on the home page 9.0 is not effected by the highlight hack

_________________
Search is your friend

tank's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora Core 1, Apache 1.3.33, Mysql 4.1.14, PHP 5.0.5 w/ APC cache, Dragonfly 9.0.6.1
Back to top
View user's profile Visit poster's website
run0
Supporter
Supporter

Offline Offline
Joined: Jun 28, 2004
Posts: 1559

PostPosted: Tue Dec 28, 2004 3:38 am
Post subject: Re: Phpbb Security Vulnerablity - is CPG Nuke affected?

story.news.yahoo.com/n...rld/119051

theyre coming...

_________________


run0's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33 (Unix)/4.0.22-standard/4.3.9/DF 9.x
Back to top
View user's profile Visit poster's website
shimon
Nice poster
Nice poster

Offline Offline
Joined: Jul 25, 2004
Posts: 146

PostPosted: Tue Dec 28, 2004 4:09 am
Post subject: Re: Phpbb Security Vulnerablity - is CPG Nuke affected?

oh ows i feel sorry for the people who went on and are not by the server to fix this

_________________
/media/internet

shimon's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
GNU/Debian / Apache 2.latest / MySQL 4.latest / PHP 4.latest / CPGNuke CVS
Back to top
View user's profile Send e-mail Visit poster's website
Śyama_Dāsa
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 2048
Location: Dragonfly CMS Tribe
PostPosted: Tue Dec 28, 2004 4:13 am
Post subject: Re: Phpbb Security Vulnerablity - is CPG Nuke affected?

While this wont help for other variants or help secure unsecure sites, this helps cut down the traffic created by the current worm
add to .htaccess (requires mod rewrite)
Code::
#Check for Santy Worms and redirect them to 404
#Variant -1
RewriteCond %{HTTP_USER_AGENT} ^LWP             [NC,OR]
#Variant -2
RewriteCond %{REQUEST_URI} ^visualcoders                [NC,OR]
#Variant -3
RewriteCond %{QUERY_STRING} rush=([^&]+)                [NC]
RewriteRule ^.*$ [F] 
this script is a variant on Raven's
thanks raven

_________________
AKA Akamu / Read these and your life will be successful | Find a Repair
--
Mods and Professional Support via YIM

Śyama_Dāsa's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
win32 / Apache 1.3.33 / MySQL 4.1.16/PHP 4.4/CPG-CVS ( browsers: Mozilla 1.7.x / IE6 / Opera 8.0)
Back to top
View user's profile Visit poster's website Yahoo Messenger Photo Gallery
xfsunoles
XHTML Specialist
XHTML Specialist

Offline Offline
Joined: Apr 30, 2004
Posts: 2502
Location: Melbourne, Florida
PostPosted: Tue Dec 28, 2004 5:14 am
Post subject: Re: Phpbb Security Vulnerablity - is CPG Nuke affected?

akamu, that doesn't block wget.

_________________

Firefox is my Favorite Browser

xfsunoles's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Apache/1.3.34 (Unix)/4.0.25-standard/4.4.1/CVS
Back to top
View user's profile Visit poster's website AIM Address MSN Messenger Yahoo Messenger Photo Gallery
Stephen
Silver Supporter
Silver Supporter

Offline Offline
Joined: Apr 21, 2004
Posts: 734

PostPosted: Tue Dec 28, 2004 5:16 am
Post subject: Re: Phpbb Security Vulnerablity - is CPG Nuke affected?

This is the latest, ravenphpscripts.com/po...html#29267
A cheap solution is to rename wget. Or just chmod it so only root can use it. And other files in /bin

/edit
Also see this, cpgnuke.com/Forums/vie...html#39384


Stephen's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Cent OS :: 1.3.34 :: 4.1.13 :: 4.4.2 :: CVS
Back to top
View user's profile Visit poster's website Photo Gallery
Jeruvy
Security Team
Security Team

Offline Offline
Joined: Apr 23, 2004
Posts: 1432
Location: Canada
PostPosted: Thu Dec 30, 2004 1:46 am
Post subject: Re: Phpbb Security Vulnerablity - is CPG Nuke affected?

Quote::
This is the latest, ravenphpscripts.com/po...html#29267
A cheap solution is to rename wget. Or just chmod it so only root can use it. And other files in /bin/edit
Also see this, cpgnuke.com/Forums/vie...html#39384

Better to create a special user with root privileges (suid) JUST for wget and then disable it for all other users.


Additionally, why would your server every run wget in the first place?

Oh nevermind, I know that answer already Wink

_________________
J.
j e r u v y a t y a h o o d o t c o m

Need help? Look here: www.dragonflycms.org/W...d=112.html
Need to chat? Look for me on irc.freenode.net

Jeruvy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Ubuntu7.10/Debian3.1 - 2.2.3/1.3.37 - 5.0.38/4.0.27 - 5.2.1/4.4.7 - CVS/9.1.2}
Back to top
View user's profile ICQ Number Yahoo Messenger Photo Gallery
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 2
All times are GMT
Go to page 1, 2  Next

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

читај повеќе...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy