PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
ballymuntrev
Hangin' Around


Joined: Mar 22, 2004
Posts: 49

PostPosted: Fri Mar 26, 2004 1:41 pm Reply with quote Back to top

ffs, another one ! I reckon the phpBB codeing group should employ chatserv and Raven to look over their code and improve *before* they ever release it.

Any idea's guys on how to fix it ?

Only registered users can see links on this board!
Get registered or login to the forums!


That link is the direct link to the exploit.
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Fri Mar 26, 2004 1:54 pm Reply with quote Back to top

You know, this is pathetic. I'm sorry to be so harsh, but it is. Actually they should pass their code by the guy who wrote the exploit Evil or Very Mad
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
ballymuntrev
Hangin' Around


Joined: Mar 22, 2004
Posts: 49

PostPosted: Fri Mar 26, 2004 2:11 pm Reply with quote Back to top

Here is the problem code of privmsg.php

EDIT: I'll just remove the code here that I entered, in case it confuses things Smile


Last edited by ballymuntrev on Fri Mar 26, 2004 2:25 pm; edited 1 time in total
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Fri Mar 26, 2004 2:14 pm Reply with quote Back to top

I've read the exploit and ultimately it's still the UNION exploit, if I read it correctly. The code isn't quoted properly.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
chatserv
The Mouse Is Extension Of Arm


Joined: May 02, 2003
Posts: 1396
Location: Puerto Rico

PostPosted: Fri Mar 26, 2004 2:39 pm Reply with quote Back to top

The hack alert script and similar protection lines block this attack, i assume one is to remove the . in $pm_sql_user .= " but i'll wait for phpBB group's reaction.

sigh
View user's profile Send private message Visit poster's website
Tank863
New Member
New Member


Joined: May 29, 2003
Posts: 16

PostPosted: Fri Mar 26, 2004 10:10 pm Reply with quote Back to top

I have tried this on my site...

Raven's Hack Alert stopped it and sent me an email.
Protector Stopped it and recorded it.
Admin Secure sent me an email and stopped it.

Good deal..

Tank863
View user's profile Send private message
Johan1982
New Member
New Member


Joined: Oct 23, 2003
Posts: 24

PostPosted: Fri Mar 26, 2004 11:26 pm Reply with quote Back to top

See this
Only registered users can see links on this board!
Get registered or login to the forums!
View user's profile Send private message
Johan1982
New Member
New Member


Joined: Oct 23, 2003
Posts: 24

PostPosted: Fri Mar 26, 2004 11:58 pm Reply with quote Back to top

This I do not understand, privmsg.php comes as it says the patch Rolling Eyes Rolling Eyes
View user's profile Send private message
Johan1982
New Member
New Member


Joined: Oct 23, 2003
Posts: 24

PostPosted: Sun Mar 28, 2004 8:43 pm Reply with quote Back to top

chatserv wrote:
The hack alert script and similar protection lines block this attack, i assume one is to remove the . in $pm_sql_user .= " but i'll wait for phpBB group's reaction.

sigh


Correct, check
Only registered users can see links on this board!
Get registered or login to the forums!


Remove the . .
View user's profile Send private message
chatserv
The Mouse Is Extension Of Arm


Joined: May 02, 2003
Posts: 1396
Location: Puerto Rico

PostPosted: Sun Mar 28, 2004 11:43 pm Reply with quote Back to top

The current zip and the PHP-Nuke Patched version have it already removed, i took it off the day i posted that comment and since nothing seemed to break i went ahead and edited the file.
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum