Home
Download
Add-ons
Help
Forum
Organisation
Project
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 25, 2012, 10:53:14 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
Search:
Advanced search
Wollen Sie dem WebsiteBaker Team beitreten?
Nähere Informationen finden Sie unter
hier
und auf unserer
neuen Webseite
.
155496
Posts in
21710
Topics by
7736
Members
Latest Member:
deenangle
WebsiteBaker Community Forum
English
Help & Support
(Moderators:
Argos
,
badknight
)
WebsiteBaker hacked
Pages:
1
[
2
]
Go Down
Author
Topic: WebsiteBaker hacked (Read 6054 times)
doc
Guest
Re: WebsiteBaker hacked
«
Reply #25 on:
May 29, 2009, 05:10:54 PM »
Hello,
well, some older modules have had security issues in the past which were used to break or manipulate a WB installation.
Most of those issues were due to a lack of sanitizing user inputs. Think of a module which offers a user form to register for a download or to search for something via the frontend. Depending on the server settings (e.g. magic quotes off) and a badly coded SQL query, one can inject it´s own code into the database query, which can then be used e.g. to update the admin password in the DB. Then you can login to the backend and do what ever you want to do, reset the password afterwards and leave again.
If the affected code is e.g. in the view.php file of such a module, the check if the WB_URL is defined does not help at all. Browse the site using WB, use the form to manipulate the DB and you are done.
Some other modules (e.g. WYSIWYG editor modules or image galleries) had some issues in the file handlers which allowed people to upload and execute files from outside, again by invoking a URL of the affected module and pass over some parameters.
Summary:
I do not want to unsettle anybody, but I also do not like statements like: "if WB is hacked, it is in 99.9999% through the server", which is simply not true. We have had issues with faulty external modules in the past and there is no guarantee, that modules listed on the Addons repository or AMASP are free of bugs which can be used to break into a WB installation. The same is true for the provider story.
Regards Christian
«
Last Edit: May 29, 2009, 11:42:36 PM by doc
»
Logged
Xagone
AddOn Development
Offline
Posts: 478
Re: WebsiteBaker hacked
«
Reply #26 on:
May 29, 2009, 06:52:09 PM »
normaly I sanatise using mysql_real_escape_s
tring but in php 5.3 it'll not be there anymore...
Logged
Xagone Inc. (formerly VotreEspace)
http://www.xagone.com/
Pages:
1
[
2
]
Go Up
Jump to:
Please select a destination:
-----------------------------
General
-----------------------------
=> General Announcements
=> Security Announcements
=> Documentation
=> WebsiteBaker Website Showcase
=> Guest Area & Off-Topic
-----------------------------
English
-----------------------------
=> WebsiteBaker 2.9
===> Announcements
===> Help/Support
=====> Modules / Extensions
===> Suggestions
===> Software bugs
=> Help & Support
=> Modules
=> Droplets (PHP code for use with Droplet module) & Snippets (raw PHP code)
=> jQuery
=> Templates, Menus & Design
=> WebsiteBaker Language Files
=> WebsiteBaker 2.x discussion
=> WebsiteBaker 3
=> Archive (posts up to 2007)
-----------------------------
Deutsch (German)
-----------------------------
=> Ankündigungen
=> WebsiteBaker 2.9
===> Ankündigungen
===> Hilfe/Support
=====> Module / Extensions
===> Vorschläge
===> Softwarefehler
===> Erfahrungs und Testberichte
=> Hilfe/Support
=> Module & Snippets
=> Templates & Design
=> Tutorials
=> jQuery
=> Diskussion über WB
=> Off-Topic
=> Archiv für Themen bis 2007
-----------------------------
Nederlands (Dutch)
-----------------------------
=> Aankondigingen
=> Hulp & Ondersteuning
=> Niet-Terzake (Off Topic)
-----------------------------
Francais (French)
-----------------------------
=> Help/Support
-----------------------------
Italiano (Italian)
-----------------------------
=> Help/Support
-----------------------------
Bakery (WB shop module)
-----------------------------
=> Bakery English
=> Bakery Deutsch
-----------------------------
KeepInTouch (Multi Contact Module)
-----------------------------
=> KeepInTouch English
=> KeepInTouch Deutsch
Loading...