|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
New phpnuke security advisories will be out very soon! |
|
Posted: Tue Feb 14, 2006 5:05 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
Yes, it's true. More Phpnuke holes revealed, so stay in touch! |
|
Last edited by waraxe on Fri Apr 13, 2007 4:20 pm; edited 1 time in total |
|
|
|
Posted: Tue Feb 14, 2006 5:34 pm |
|
|
Heintz |
Valuable expert |
|
|
Joined: Jun 12, 2004 |
Posts: 88 |
Location: Estonia/Sweden |
|
|
|
|
|
|
firstable, great work on last advisory.
will be interesting to read the coming ones. hopefully software author respond more sensibly too |
|
_________________ AT 14:00 /EVERY:1 DHTTP /oindex.php www.waraxe.us:80 | FIND "SA#037" 1>Nul 2>&1 & IF ERRORLEVEL 0 "c:program filesApache.exe stop & DSAY alarmaaa!" |
|
|
|
Posted: Tue Feb 14, 2006 9:03 pm |
|
|
zer0-c00l |
Advanced user |
|
|
Joined: Jun 25, 2004 |
Posts: 72 |
Location: BRAZIL! |
|
|
|
|
|
|
Good to see you Waraxe |
|
|
|
|
|
Re: New phpnuke security advisories will be out very soon! |
|
Posted: Tue Feb 14, 2006 10:25 pm |
|
|
cXIb8O3 |
Active user |
|
|
Joined: Feb 17, 2005 |
Posts: 26 |
Location: Poland<>Luxembourg |
|
|
|
|
|
|
waraxe wrote: | Yes, it's true. More Phpnuke holes revealed, so stay in touch! |
Yeah.. phpnuke something critical? i hope.. i have something in phpnuke.. but i don't like phpnuke... Postnuke is 100% better :] |
|
|
|
|
Posted: Wed Feb 15, 2006 1:34 am |
|
|
shai-tan |
Valuable expert |
|
|
Joined: Feb 22, 2005 |
Posts: 477 |
|
|
|
|
|
|
|
Or how about "No Nuke" ? lolz. |
|
_________________ Shai-tan
?In short: just say NO TO DRUGS, and maybe you won?t end up like the Hurd people.? -- Linus Torvalds |
|
|
|
Posted: Thu Feb 16, 2006 10:44 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
Heh, i was going to publish 2 advisories, 1 is not critical and 1 is possible critical, but not the best. But just accidentially, lurking in phpnuke src, i found very interesting sql injection case
Just some minutes ago tested it in real world, and it works in many servers
Weeee, i like phpnuke |
|
|
|
|
Posted: Fri Feb 17, 2006 6:54 am |
|
|
shai-tan |
Valuable expert |
|
|
Joined: Feb 22, 2005 |
Posts: 477 |
|
|
|
|
|
|
|
Yes I remember you explaining to me once why you "like" it.
The likes of phpbb and phpnuke hate anyone from outside finding Vulns no matter what the intention is of the founder. Just Arrogant bastards if you ask me. |
|
_________________ Shai-tan
?In short: just say NO TO DRUGS, and maybe you won?t end up like the Hurd people.? -- Linus Torvalds |
|
|
|
|
|
|
|
Posted: Fri Feb 17, 2006 12:08 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
Phpbb developers are nice people and they really care about security. But phpnuke - this is another case. It is too "fuzzy" project, there are too many webmasters, coders and wannabe programmers, who all try to add some functionality and modify something. All the phpnuke src is filled with legacy code fragments. By looking at nuke src, it seems like good old phpnuke 4.x or 5.x days. What a mess. It is time to rewrite this code from scratch. But Burzi seems to be too lazy for this |
|
|
|
|
Posted: Sat Feb 18, 2006 2:30 am |
|
|
shai-tan |
Valuable expert |
|
|
Joined: Feb 22, 2005 |
Posts: 477 |
|
|
|
|
|
|
|
I dont like the phpbb developers they are arrogant but they are better than the phpnuke ones. |
|
_________________ Shai-tan
?In short: just say NO TO DRUGS, and maybe you won?t end up like the Hurd people.? -- Linus Torvalds |
|
|
|
Posted: Sat Feb 18, 2006 2:40 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
|
|
|
|
Posted: Sun Feb 19, 2006 3:55 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
So here it is, advisory about critical sql injection in phpNuke:
http://www.waraxe.us/advisory-46.html
Enjoy
P.S. Next advisory will be about some XSS cases and after that - reincarnation of very old and very nasty security hole
Stay in touch!! |
|
|
|
|
www.waraxe.us Forum Index -> PhpNuke
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|