You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 65 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - read>phpNuke 7.5 WITH HEAVY SECURITY HOLES.Is there anypa [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
kristalaz
Nuke Cadet
Nuke Cadet


Joined: Sep 25, 2004
Posts: 3

Location: Germany

PostPosted: Mon Oct 04, 2004 5:27 am Reply with quoteBack to top

Code:
 phpNuke 7.5 WITH HEAVY SECURITY HOLES     
     Sicherheit

Tora von MaaxDesign writes: “When testing new administration system of phpNuke 7.5 I discovered heavy security holes. All modules, which use the new admin directory in the module directory, can be manipulated without being logged in as administrator.
On my test system it was possible for me to create download categories and delete user by simple URL manipulation. We have not tested more details until now. However possible also all other administration functions of these modules are easy to manipulate via the same way. Therefore I can only advise against the installation of this new version. wrote on 18.09


is there any patch?
Find all posts by kristalazView user's profileSend private messageVisit poster's website
scandicdiscopub
Sergeant
Sergeant


Joined: Oct 20, 2003
Posts: 88


PostPosted: Mon Oct 04, 2004 6:43 am Reply with quoteBack to top

hmmm what kind of url manipulation.
the way you write it makes it even kind of misterical
???
if you say something say it good else dont say nothing

_________________
All we want is knowledge and if knowledge is power we should be considered dangerous.

http://www.nukeroyal.com|http://www.mexicomiamore.com|
Find all posts by scandicdiscopubView user's profileSend private message
FreeBee
Sergeant
Sergeant


Joined: Aug 26, 2004
Posts: 75


PostPosted: Mon Oct 04, 2004 7:21 am Reply with quoteBack to top

Ok i've downloaded 7.5 a minute ago and checked it.

PHP-Nuke 7.5 is high risk vulnerable

The whole admin area is exploitable you can do everything even when you are not logged in as admin.
This the worst release i've ever seen.

I will tell where the risk is ONLY to a responsible Admin that has narrow contact with FB unless someone reports the bug with full exposure.
Find all posts by FreeBeeView user's profileSend private message
afc
Lieutenant
Lieutenant


Joined: May 28, 2003
Posts: 203


PostPosted: Mon Oct 04, 2004 3:45 pm Reply with quoteBack to top

i have fix for it just re-add everything he deleted in 7.5 and put 7.4 patched files version 2.6 by ChatServ. run to do it now
Find all posts by afcView user's profileSend private message
FreeBee
Sergeant
Sergeant


Joined: Aug 26, 2004
Posts: 75


PostPosted: Mon Oct 04, 2004 9:15 pm Reply with quoteBack to top

afc wrote:
i have fix for it just re-add everything he deleted in 7.5 and put 7.4 patched files version 2.6 by ChatServ. run to do it now


AFAIK i have downloaded ChatServ patched 7.5 and it is still exploitable
Find all posts by FreeBeeView user's profileSend private message
Evaders99
Site Admin
Site Admin


Joined: Aug 17, 2003
Posts: 12482


PostPosted: Mon Oct 04, 2004 10:28 pm Reply with quoteBack to top

Tried any of the security addons? I'd hate to see these holes not stopped by any of them.

_________________
Helping those that help themselves
Read FIRST or DIE!

"Fighting is terrible, but not as terrible as losing the will to fight."
Star Wars Rebellion Network - Need Help? Evaders Squadron Coding
Find all posts by Evaders99View user's profileSend private messageVisit poster's websiteAIM Address
FreeBee
Sergeant
Sergeant


Joined: Aug 26, 2004
Posts: 75


PostPosted: Mon Oct 04, 2004 10:34 pm Reply with quoteBack to top

It bypasses all security add-ons so I've contacted Bob Marion and he is working on a quick fix and a rewrite of the offending file.

I've described him how to prevent 90% of the attempts so the fix should be good and a "must have" when released.

just keep an eye on nukescripts.net
Find all posts by FreeBeeView user's profileSend private message
Tora
Nuke Cadet
Nuke Cadet


Joined: Jan 11, 2004
Posts: 8


PostPosted: Mon Oct 11, 2004 2:45 pm Reply with quoteBack to top

Hi Smile

read here:

http://nukecops.net/postlite34786-ignore.html
Find all posts by ToraView user's profileSend private messageVisit poster's website
chatserv
General
General


Joined: Jan 12, 2003
Posts: 3128

Location: Puerto Rico

PostPosted: Mon Oct 11, 2004 4:31 pm Reply with quoteBack to top

So what are the so called vulnerabilities? and please don't give me that page with a foreign language, makes no sense.

_________________
Feed a man a fish and you feed him for a day. Teach a man to fish and you feed him for a lifetime.
ScriptHeaven | NukeResources
Find all posts by chatservView user's profileSend private messageVisit poster's website
FreeBee
Sergeant
Sergeant


Joined: Aug 26, 2004
Posts: 75


PostPosted: Mon Oct 11, 2004 5:18 pm Reply with quoteBack to top

Ask Dr. Bob, i don't gonna exploit it here untill a fix is made.
Find all posts by FreeBeeView user's profileSend private message
JohnGotti
Corporal
Corporal


Joined: Sep 06, 2004
Posts: 57


PostPosted: Mon Oct 11, 2004 6:17 pm Reply with quoteBack to top

Has a fix for this been made yet?

Is there something that can be done in the mean time to prevent such a problem?

I've checked NukeScripts.net but cant seem to find any information on this!

If someone can point me in the right direction, I would greatly appreciate that! Smile

_________________
C-4 Hosting
http://www.C-4.us
PHP Nuke Site Packages Starting At $5.99 per month!
Find all posts by JohnGottiView user's profileSend private message
BobMarion
Nuke Soldier
Nuke Soldier


Joined: Feb 20, 2003
Posts: 17


PostPosted: Mon Oct 11, 2004 8:33 pm Reply with quoteBack to top

http://www.nukescripts.net/modules.php?name=News&file=article&sid=1249&mode=thread&order=0&thold=0

_________________
Bob Marion
http://www.nukescripts.net
Codito Ergo Sum
Find all posts by BobMarionView user's profileSend private messageVisit poster's website
JohnGotti
Corporal
Corporal


Joined: Sep 06, 2004
Posts: 57


PostPosted: Mon Oct 11, 2004 9:27 pm Reply with quoteBack to top

BobMarion wrote:
http://www.nukescripts.net/modules.php?name=News&file=article&sid=1249&mode=thread&order=0&thold=0
Thank you soooo much! Smile

_________________
C-4 Hosting
http://www.C-4.us
PHP Nuke Site Packages Starting At $5.99 per month!
Find all posts by JohnGottiView user's profileSend private message
Tora
Nuke Cadet
Nuke Cadet


Joined: Jan 11, 2004
Posts: 8


PostPosted: Mon Oct 11, 2004 11:04 pm Reply with quoteBack to top

Hi Smile

@ chatserv
Sorry, my english is not well enough...

But you have fixed this Exploit in your nukepatched-project.

http://cvs.sourceforge.net/viewcvs.py/nukepatched/75patched/modules/Downloads/admin/index.php?rev=1.1&view=markup

This line undoes a manipulating of the URL:
if (!eregi("admin.php", $_SERVER['SCRIPT_NAME'])) { die ("Access Denied"); }
Find all posts by ToraView user's profileSend private messageVisit poster's website
FreeBee
Sergeant
Sergeant


Joined: Aug 26, 2004
Posts: 75


PostPosted: Tue Oct 12, 2004 5:22 pm Reply with quoteBack to top

Ok the fix is placed so here's the exploit:

When going to a phpnuke website you know who the admins are since the adminname is 90% the username.
Also the News articles show the author which is the adminname and not the original name of the person who posted the article.

So the admin loginname is exploited all over the place.

Now you need to know which variable stores the admin name and that is $aid.

So a GET, POST or COOKIE that has aid=ADMINNAME bypasses the whole security system since it only checks for $admin (the cookie)

So constructing a URL like: admin.php?aid=FreeBee&op=mod_author you have full control over that admin option since the new admin system in 7.5 uses the adminname and not $admin
Find all posts by FreeBeeView user's profileSend private message
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by TOGETHER TEAM srl ITALY http://www.togetherteam.it - DONDELEO E-COMMERCE http://www.DonDeLeo.com - TUTTISU E-COMMERCE http://www.tuttisu.it
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.588 Seconds - 46 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::