Sub Menu
Links Menu
Online Users

In total there are 237 users online :: 1 registered, 0 hidden and 236 guests

Most users ever online was 1091 on Wed Aug 16, 2023 5:27 pm

Registered users: Google [Bot] based on users active over the past 60 minutes

IntegraMod Security fix

This is where youll find security related information.
Discuss Integramod/phpbb security issues here.

Moderator: Integra Moderator

IntegraMod Security fix

PostAuthor: Michaelo » Sat Aug 26, 2006 3:50 am

To avoid confusion this post has been moved to the Security Forum see link below.

[url=http]Moved to Security Forum[/url]
Last edited by Michaelo on Tue Aug 29, 2006 6:31 pm, edited 1 time in total.
Kiss Portal Engine phpbbireland (status: Released)
User avatar
Michaelo
Administrator
Administrator
 
Posts: 1646
Likes: 0 post
Liked in: 0 post
Joined: Sat Mar 11, 2006 5:14 pm
Cash on hand: 0.00
Location: Dublin, Ireland

PostAuthor: ayasha » Sat Aug 26, 2006 4:52 am

thanks Mike <img>
Last edited by ayasha on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
No one can make you feel inferior without your consent.
~Eleanor Roosevelt

ayasha
Sr Integra Member
Sr Integra Member
 
Posts: 634
Likes: 0 post
Liked in: 0 post
Joined: Tue Mar 28, 2006 5:10 pm
Cash on hand: 0.00

Re: IntegraMod (version 1) Hack fix

PostAuthor: Unregistered » Sat Aug 26, 2006 5:02 am

i believe this fix is for those who ppl who used premoded files..

i have the following code in my functions_portal.php

Code: Select all
if ( !defined('IN_PHPBB') ){     die('Hacking attempt');     exit;}include_once($phpbb_root_path . 'includes/lite.'.$phpEx);  


do i stil need to add the fix code?
Last edited by Unregistered on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
J O N H | P L A Y E R

Unregistered
Sr Integra Member
Sr Integra Member
 
Posts: 254
Likes: 0 post
Liked in: 0 post
Joined: Wed Jun 07, 2006 1:51 pm
Cash on hand: 0.00

Re: IntegraMod (version 1) Hack fix

PostAuthor: ihammo » Sat Aug 26, 2006 5:40 am

Hi

a few of the other function_xxxxx.php files do not have the 'die hack' code in either. Should they have?

also, was a fix ever announced for the STYLE_URL [url=http]exploit[/url]?

Thanks
Last edited by ihammo on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

ihammo
Newbie
Newbie
 
Posts: 28
Likes: 0 post
Liked in: 0 post
Joined: Thu May 25, 2006 1:42 am
Cash on hand: 0.00

PostAuthor: Michaelo » Sat Aug 26, 2006 7:03 am

Unregistered, I guess everyone should check as it depends on when ppl downloaded their copy as we say in Ireland... to be sure to be sure :)

As for the STYLE_URL disable the Style Select block in admin until we have investigated this issue.

Mike
Last edited by Michaelo on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Kiss Portal Engine phpbbireland (status: Released)
User avatar
Michaelo
Administrator
Administrator
 
Posts: 1646
Likes: 0 post
Liked in: 0 post
Joined: Sat Mar 11, 2006 5:14 pm
Cash on hand: 0.00
Location: Dublin, Ireland

PostAuthor: Unregistered » Sat Aug 26, 2006 7:14 am

hi Michaelo,
what i meant was, wudnt it make it as like a duplication code?
Last edited by Unregistered on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
J O N H | P L A Y E R

Unregistered
Sr Integra Member
Sr Integra Member
 
Posts: 254
Likes: 0 post
Liked in: 0 post
Joined: Wed Jun 07, 2006 1:51 pm
Cash on hand: 0.00

PostAuthor: Michaelo » Sat Aug 26, 2006 7:23 am

Unregistered, sorry about that <img> your copy of the file is fine no need for edits.
Mike
Last edited by Michaelo on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Kiss Portal Engine phpbbireland (status: Released)
User avatar
Michaelo
Administrator
Administrator
 
Posts: 1646
Likes: 0 post
Liked in: 0 post
Joined: Sat Mar 11, 2006 5:14 pm
Cash on hand: 0.00
Location: Dublin, Ireland

PostAuthor: Unregistered » Sat Aug 26, 2006 7:28 am

thanks.. and am glad finally Integramod took the STYLE_URL vulnerability to attention <img>
Last edited by Unregistered on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
J O N H | P L A Y E R

Unregistered
Sr Integra Member
Sr Integra Member
 
Posts: 254
Likes: 0 post
Liked in: 0 post
Joined: Wed Jun 07, 2006 1:51 pm
Cash on hand: 0.00

PostAuthor: Unregistered » Sat Aug 26, 2006 7:44 am

As we are gettin more attacks, i think its wise to do a mass email and notify about the security patch who aint yet hacked/attacked..
Last edited by Unregistered on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
J O N H | P L A Y E R

Unregistered
Sr Integra Member
Sr Integra Member
 
Posts: 254
Likes: 0 post
Liked in: 0 post
Joined: Wed Jun 07, 2006 1:51 pm
Cash on hand: 0.00

Re: IntegraMod (version 1) Hack fix

PostAuthor: VillageIdiot » Sat Aug 26, 2006 8:02 am

As a n00b, I need to ask. Does it matter where in the file I put this fix? First, last, throw a dart? <img>
Last edited by VillageIdiot on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

VillageIdiot
Newbie
Newbie
 
Posts: 1
Likes: 0 post
Liked in: 0 post
Joined: Sat Aug 26, 2006 7:59 am
Cash on hand: 0.00

Re: IntegraMod (version 1) Hack fix

PostAuthor: ihammo » Sat Aug 26, 2006 8:49 am

hey Michaelo

thankfully i have already disabled the style select on my site as I dont want people to be able to use it anyway.

I will go through all teh functions and add the die hack code

Cheers

<img>
Last edited by ihammo on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

ihammo
Newbie
Newbie
 
Posts: 28
Likes: 0 post
Liked in: 0 post
Joined: Thu May 25, 2006 1:42 am
Cash on hand: 0.00

Re: IntegraMod (version 1) Hack fix

PostAuthor: evolver » Sat Aug 26, 2006 8:58 am

"ihammo";p="14125" wrote:thankfully i have already disabled the style select on my site as I dont want people to be able to use it anyway.

I don't think disabling the style select has anything to do with it...
It's in the URL that hackers are able to add code to break in...
Last edited by evolver on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
ImageAlways remember you're unique, just like everyone else.
We are born naked, wet and hungry. Then things get worse.
Don't take life too seriously, you won't get out alive.
User avatar
evolver
Sr Integra Member
Sr Integra Member
 
Posts: 420
Likes: 0 post
Liked in: 0 post
Joined: Mon Mar 27, 2006 12:46 pm
Cash on hand: 0.00
Location: Oostende

PostAuthor: Michaelo » Sat Aug 26, 2006 9:30 am

True for you evolve <img> hiding it is not the answer I stand corrected... Once it is disabled we will have to comment out the offending code in functions.php and rename the block file...
[align=center:3mza83rm]Code in this post has been update... See first post in this thred[/align]
Part 1:
Edit this file: functions.php
Find the following codeà¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ ¦

Code: Select all
    if ( isset($HTTP_POST_VARS[STYLE_URL]) || isset($HTTP_GET_VARS[STYLE_URL]) )     {         $style = urldecode( (isset($HTTP_POST_VARS[STYLE_URL])) ? $HTTP_POST_VARS[STYLE_URL] ] );         if ( $theme = setup_style($style) )         {             setcookie($board_config['cookie_name'] . '_style', $style, time() + 31536000, $board_config['cookie_path'], $board_config['cookie_domain'], $board_config['cookie_secure']);             return;         }     }         if ( isset($HTTP_COOKIE_VARS[$board_config['cookie_name'] . '_style']) )     {         $style = $HTTP_COOKIE_VARS[$board_config['cookie_name'] . '_style'];         if ( $theme = setup_style($style) )         {             return;         }     }  


Replace withà¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ ¦
Code: Select all
 /*     if ( isset($HTTP_POST_VARS[STYLE_URL]) || isset($HTTP_GET_VARS[STYLE_URL]) )     {         $style = urldecode( (isset($HTTP_POST_VARS[STYLE_URL])) ? $HTTP_POST_VARS[STYLE_URL] ] );         if ( $theme = setup_style($style) )         {             setcookie($board_config['cookie_name'] . '_style', $style, time() + 31536000, $board_config['cookie_path'], $board_config['cookie_domain'], $board_config['cookie_secure']);             return;         }     }         if ( isset($HTTP_COOKIE_VARS[$board_config['cookie_name'] . '_style']) )     {         $style = $HTTP_COOKIE_VARS[$board_config['cookie_name'] . '_style'];         if ( $theme = setup_style($style) )         {             return;         }     }*/  


Then (for the moment) rename block_imp_style_select.php to something like block_imp_style_select.xxx
Last edited by Michaelo on Tue Aug 29, 2006 4:46 am, edited 1 time in total.
Kiss Portal Engine phpbbireland (status: Released)
User avatar
Michaelo
Administrator
Administrator
 
Posts: 1646
Likes: 0 post
Liked in: 0 post
Joined: Sat Mar 11, 2006 5:14 pm
Cash on hand: 0.00
Location: Dublin, Ireland

PostAuthor: Solomon » Sat Aug 26, 2006 10:40 am

I added the code fix for functions_portal.php last night and was hacked again today. I will try the "Edit this file: functions.php" suggestion next.
Last edited by Solomon on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
[hr]

Solomon
Members
Members
 
Posts: 90
Likes: 0 post
Liked in: 0 post
Joined: Sat May 20, 2006 8:22 am
Cash on hand: 0.00

Re: IntegraMod (version 1) Hack fix

PostAuthor: Michaelo » Sat Aug 26, 2006 11:10 am

You could also try this... Find any occurrence of

[align=center:2qmeehks]Code in this post has been update... See first post in this thred[/align]

Code: Select all
 if(isset($HTTP_POST_VARS['STYLE_URL']) || isset($HTTP_GET_VARS['STYLE_URL']))  replace with  if(isset($HTTP_POST_VARS['STYLE_URL']) || (int) isset($HTTP_GET_VARS['STYLE_URL']))  And  $style = urldecode((isset($HTTP_POST_VARS['STYLE_URL'])) ? $HTTP_POST_VARS['STYLE_URL'] ]);  with  (int) $style = urldecode((isset($HTTP_POST_VARS['STYLE_URL'])) ? $HTTP_POST_VARS['STYLE_URL'] : (int) $HTTP_GET_VARS['STYLE_URL']);  


And have you any more details of the hack...?

We have not determined where the hacker is gaining access... <img>
The only vulnerabilities we can identify include Style Select block code (STYLE_URL) and possibly two other relating to some versions of php

Mike
Last edited by Michaelo on Tue Aug 29, 2006 4:47 am, edited 1 time in total.
Kiss Portal Engine phpbbireland (status: Released)
User avatar
Michaelo
Administrator
Administrator
 
Posts: 1646
Likes: 0 post
Liked in: 0 post
Joined: Sat Mar 11, 2006 5:14 pm
Cash on hand: 0.00
Location: Dublin, Ireland

Next

Return to Forum Security

Who is online

Registered users: Google [Bot]

cron