|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 139
Members: 0
Total: 139
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
some fixes waraxe released. |
|
Posted: Thu Jul 08, 2004 8:40 pm |
|
|
genoxide |
Regular user |
|
|
Joined: Jun 14, 2004 |
Posts: 15 |
|
|
|
|
|
|
|
Well i'm currently working on a new project of mine and i got cs permission to work with his fixes for phpnuke.
i came across with some of the fixes waraxe made in article.php
Code: | // start code fix by waraxe
$optionbox = '';
// end code fix by waraxe |
now if we look in the old code we see,
Code: | $optionbox [b].[/b]= "<br> ;;<img src=\"images/print.gif\" border=\"0\" alt=\""._PRINTER."\" title=\""._PRINTER."\" width=\"16\" height=\"11\"> ;; ;;<a href=\"modules.php?name=$module_name&file=print&sid=$sid\">"._PRINTER."</a><br><br>";
$optionbox .= " ;;<img src=\"images/friend.gif\" border=\"0\" alt=\""._FRIEND."\" title=\""._FRIEND."\" width=\"16\" height=\"11\"> ;; ;;<a href=\"modules.php?name=$module_name&file=friend&op=FriendSend&sid=$sid\">"._FRIEND."</a><br><br>\n"; |
if we change the code (just remove the dot (.) like,
Code: | $optionbox = "<br> ;;<img src=\"images/print.gif\" border=\"0\" alt=\""._PRINTER."\" title=\""._PRINTER."\" width=\"16\" height=\"11\"> ;; ;;<a href=\"modules.php?name=$module_name&file=print&sid=$sid\">"._PRINTER."</a><br><br>";
$optionbox .= " ;;<img src=\"images/friend.gif\" border=\"0\" alt=\""._FRIEND."\" title=\""._FRIEND."\" width=\"16\" height=\"11\"> ;; ;;<a href=\"modules.php?name=$module_name&file=friend&op=FriendSend&sid=$sid\">"._FRIEND."</a><br><br>\n"; |
isn't the same thing? but more clean that is
also waraxe are u interested for an alpha testing (security check) of my project when it's done? |
|
Last edited by genoxide on Fri Jul 09, 2004 9:17 am; edited 1 time in total |
|
|
|
|
|
|
|
Posted: Thu Jul 08, 2004 8:45 pm |
|
|
genoxide |
Regular user |
|
|
Joined: Jun 14, 2004 |
Posts: 15 |
|
|
|
|
|
|
|
also about the fix in the modules.php
about the $name fix
Code: | $modpath .= "modules/$name/".$file.".php";
if (file_exists($modpath)) { |
how can the 'xploits work? it checks if the file exists in the modules folder right?
so if the attacker puts something like modules.php?name=http://urlhere/cmd.txt it wont work because it will be like
modules/http://urlhere/cmd.txt/index.php and that doesn't exists right? |
|
|
|
|
|
|
|
|
Posted: Fri Jul 09, 2004 9:15 am |
|
|
genoxide |
Regular user |
|
|
Joined: Jun 14, 2004 |
Posts: 15 |
|
|
|
|
|
|
|
and about the $admin or $user exploits
Code: | #############################################################
#--------------- Base64 sanitize by Waraxe -----------------
if(isset($admin))
{
$admin = base64_decode($admin);
$admin = addslashes($admin);
$admin = base64_encode($admin);
}
if(isset($user))
{
$user = base64_decode($user);
$user = addslashes($user);
$user = base64_encode($user);
}
############################################################# |
a real admin or user request should come from the cookies only, right?
so we have: Code: |
#############################################################
#--------------- Base64 sanitize by Waraxe -----------------
if(isset($admin))
{
$admin = $_COOKIE['admin'];
if ($admin) {
$admin = base64_decode($admin);
$admin = addslashes($admin);
$admin = base64_encode($admin);
} else { die('nice try'); }
}
if(isset($user))
{
$user = $_COOKIE['user'];
if ($user) {
$user = base64_decode($user);
$user = addslashes($user);
$user = base64_encode($user);
} else { die('nice try'); }
}
#############################################################
|
|
|
|
|
|
|
www.waraxe.us Forum Index -> PhpNuke
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|