Remote file inclusion vulnerability in preforked XTreme

ImageNews from out there about new technologies.

It will be updated when possible.

Remote file inclusion vulnerability in preforked XTreme

Postby Juanm on Thursday September 21st, 2006 17h21:28

Synthetic informations
sw name: phpBB XTreme
vendor: oc5id
vulnerability type: remote file inclusion vulnerability
severity: extremely critical

Details

Issue description:
Code: Select all
includes/functions.php

has non function code. This will allow people interested to wreck havoc into the vulnerable site by editing phpBB root path with the usual exploit seen many and many times around the net :)

phpBB vanilla is not vulnerable 'cause includes/functions.php contains only function code

Other preforked with outdated MODs can be affected [break]by the same vulnerability

Fixes/advices

*ultimate fix*
remove that sw from your server and choose other software respecting copyright, able to keep all their code up to date (and possibly without hundreds of queries per page).
Visit this thread for details.

You server and your host will be grateful to you :)

workaround
This stuff is not supported here, so I won't provide any fix. Go to your vendor, look for support over there and good luck (you need it) :mrgreen: .
I'm setting this as workaround 'cause it maybe could fix this issue (update: it *maybe* will block that kind of exploit), but it won't remove the cause laying behind that script: too many MODs and not enough care about keeping all them and the core code up to date :P.

Credits: Techie-Micheal for explaining some tech details about functions.php

side notes:
what's this: another preforked forum sw including a bunch of hacks. It has hundreds of queries for every page load as many other preforked.
the vendor removed copyright informations from php files (GPL violation) and made the files available for registered only.

tech detail: exploit will work with misconfigured servers (register globals=on).
Since many hosts don't want certain clients to complain 'cause "some script don't work", this situation seems to be not so rare.

How can I recognize if my site full of strange stuff is affected?

Look for
Code: Select all
"powered by phpBB XTreme"
in your footer.

But ... I've paid for it believing that paid stuff is more secure
It's a business of yours. :P :rofl:
I installed it believing someone was a professional guy
Well ... now you know :rofl: [rofl]
Juanm

Phpbb related: looking 4 a MOD? :: phpBB bugtracker :: phpBBsecurity tracker :: phpBB knowledge base

D-Off @ MobileReview wrote:who cares about WAP anymore? :)
Try google and search for content
User avatar
Juanm
Site developer
Site developer
 
Posts: 763
Joined: Thursday March 25th, 2004 21h45:21
Location: Behind YOU



Ad
Bot
 


Similar topics


Return to Tech news

Who is online

Users browsing this forum: No registered users and 0 guests

cron

Rate this site