Welcome, Guest. Please login or register.
Did you miss your activation email?
May 16, 2012, 09:54:23 PM

Login with username, password and session length
Search:     Advanced search
Interested in joining the WebsiteBaker team?
For more Information read here or on our new website.
155094 Posts in 21661 Topics by 7721 Members
Latest Member: arrow345
* Home Help Search Login Register
Pages: [1] 2   Go Down
Print
Author Topic: Urgent security warning! READ THIS!  (Read 14140 times)
Stefan
Guest
« on: December 11, 2005, 12:57:26 PM »

There have been attacks on WebsiteBaker sites (including my own) in the last days.

To close the vulnerability, immediately replace the file framework/class.login.php by the following (remove the appended '.txt' before uploading):

Version 2.5.2

Version 2.6.0

Also, check if any files have been created in your account that you haven't uploaded / created yourself. If so delete them, or have them deleted by your service provider.

An official patch will be released soon.
« Last Edit: December 11, 2005, 04:04:43 PM by Stefan » Logged
Argos
Moderator
**
Offline Offline

Posts: 2146


WWW
« Reply #1 on: December 11, 2005, 01:40:54 PM »


Also, check if any files have been created in your account that you haven't uploaded / created yourself. If so delete them, or have them deleted by your service provider.

Look particularly in the Media folder! Delete any non-mediatype files found there. If you have been hacked, you may find for example these files in the Media folder:

cmd.php
suntzu.php
upload.php
index.phprn
some other .php and/or .pl files

Thanks Stefan!
Logged

Jurgen Nijhuis
Argos Media
Heiloo, The Netherlands
WB Showcase: http://www.mywebsitebaker.com/pages/showcase.php?v&category_id=1242&count=30
----------------------------------------------------------------
Please don't request personal support, use the forums!
Ryan

Offline Offline

Posts: 2048



WWW
« Reply #2 on: December 11, 2005, 01:42:05 PM »

Please note: this is only an issue on servers where the php magic_quotes_gpc setting is set to off.
I will now make this a top priority to have 2.6.1 released within 2 days, for an official patched version.
Logged

Website Baker Project Founder
www.websitebaker.or g

To contact me via email, visit:
www.ryandjurovich.c om
Stefan
Guest
« Reply #3 on: December 11, 2005, 01:47:17 PM »

Ryan, please release official patches for 2.5.2 and 2.6.0 immediately and announce them on the main site.
Logged
Argos
Moderator
**
Offline Offline

Posts: 2146


WWW
« Reply #4 on: December 11, 2005, 01:49:22 PM »

Hm... after patching my 2.5.2 sites, I get a completely blank screen after logging in. Only after going back in my browser and doing a refresh, I get access to the admin.

The 2.6 version is okay.
« Last Edit: December 11, 2005, 01:54:42 PM by Argos » Logged

Jurgen Nijhuis
Argos Media
Heiloo, The Netherlands
WB Showcase: http://www.mywebsitebaker.com/pages/showcase.php?v&category_id=1242&count=30
----------------------------------------------------------------
Please don't request personal support, use the forums!
Ryan

Offline Offline

Posts: 2048



WWW
« Reply #5 on: December 11, 2005, 01:50:10 PM »

Sorry Stefan, I am just about to go to bed - in fact, if I did not decide to check the forum, I would be sleeping right now.
I will do it first thing tomorrow morning. Sorry guys.
In the mean time, we really needa get the SVN repo fixed before we can touch it (I dont want to do any commits until we do the branch - I will send a quick email now.
Logged

Website Baker Project Founder
www.websitebaker.or g

To contact me via email, visit:
www.ryandjurovich.c om
Hans

Offline Offline

Posts: 564


« Reply #6 on: December 11, 2005, 02:41:35 PM »

I have several WB sites with versions earlier than 2.5.2. (2.5.1, 2.3.1 amongst others). Does this vulnerablitiy threaten those sites too? I changed some things in those scripts so that it is not possible to upgrade. If this affects < 2.5.2 sites, can I use the patch for 2.5.2 or could somebody write a patch for those earlier versions?
Thanks!
Hans
Logged

Hans - Nijmegen - The Netherlands
mroony

Offline Offline

Posts: 24


« Reply #7 on: December 11, 2005, 03:13:26 PM »

So far I have applied the patches to 4 sites... 2 are 2.5.2 and 2 are 2.6.  Good on all fronts.  Thank you for the swift response.
Logged
Stefan
Guest
« Reply #8 on: December 11, 2005, 04:02:37 PM »

All versions of WebsiteBaker are affected as far as I know.
Best is to upgrade to 2.5.2 and apply the patch.
Logged
Argos
Moderator
**
Offline Offline

Posts: 2146


WWW
« Reply #9 on: December 11, 2005, 05:12:23 PM »

Am I the only one with the blank screen problem? Does any of the coders know what to do about it?
« Last Edit: December 12, 2005, 12:18:04 PM by Argos » Logged

Jurgen Nijhuis
Argos Media
Heiloo, The Netherlands
WB Showcase: http://www.mywebsitebaker.com/pages/showcase.php?v&category_id=1242&count=30
----------------------------------------------------------------
Please don't request personal support, use the forums!
i2Paq

Offline Offline

Posts: 510


« Reply #10 on: December 11, 2005, 09:32:40 PM »


Also, check if any files have been created in your account that you haven't uploaded / created yourself. If so delete them, or have them deleted by your service provider.

Look particularly in the Media folder! Delete any non-mediatype files found there. If you have been hacked, you may find for example these files in the Media folder:

cmd.php
suntzu.php
upload.php
index.phprn
some other .php and/or .pl files

Thanks Stefan!

Checked all my sites, 1 had this file in the \media; tpl.gif.php

It points to http://ccteam.ru/releases/c99shell


Quote
c99shell.php v.1.0 pre-release build #16
*                     Freeware license.
*                        © CCTeaM.

If you want I can send the file

The funny thing is that this site is hosted on a server with PHP-safe-mode = on
« Last Edit: December 11, 2005, 10:42:19 PM by i2Paq » Logged

Opensource is my life, but then elsewhere.
Ryan

Offline Offline

Posts: 2048



WWW
« Reply #11 on: December 12, 2005, 12:23:01 AM »

Ok, the trunk has been patched. I am not sure what to do next - release 2.6.1?
Logged

Website Baker Project Founder
www.websitebaker.or g

To contact me via email, visit:
www.ryandjurovich.c om
Ryan

Offline Offline

Posts: 2048



WWW
« Reply #12 on: December 12, 2005, 02:32:53 AM »

Ok, 2.6.1 is out with a notice about why (the security vuln). Is this enough, or do we need more?
Logged

Website Baker Project Founder
www.websitebaker.or g

To contact me via email, visit:
www.ryandjurovich.c om
i2Paq

Offline Offline

Posts: 510


« Reply #13 on: December 12, 2005, 07:49:57 AM »

Could someone explain to my what they would gain from hacking a WB site other then destroying someones hard work?
Logged

Opensource is my life, but then elsewhere.
kibmcz

Offline Offline

Posts: 217



WWW
« Reply #14 on: December 12, 2005, 09:09:41 AM »

Could someone explain to my what they would gain from hacking a WB site other then destroying someones hard work?

some people get a kick out of defacing websites
Logged
Woudloper
Guest
« Reply #15 on: December 12, 2005, 09:33:48 AM »

Could someone explain to my what they would gain from hacking a WB site other then destroying someones hard work?
Mostly it are scriptkiddies doing these thing. The like it to screw up other peoples work...
Logged
Stefan
Guest
« Reply #16 on: December 12, 2005, 10:29:43 AM »

@Ryan
A patch for 2.5.2 should be officially released too.
And it would be good to send an announcement message to all community members.
Logged
Olli

Offline Offline

Posts: 290


« Reply #17 on: December 12, 2005, 03:00:05 PM »

thanks for the fix so far!
Logged
zaggi

Offline Offline

Posts: 56


« Reply #18 on: December 12, 2005, 04:37:47 PM »

I was so much hacket... They puttet up shells and all on my server.. Crap! ... :/
But looks like they didnt do anything els than that.. Thx god..

But it really sucks anyway...
Logged
teressa

Offline Offline

Posts: 24



« Reply #19 on: December 12, 2005, 10:28:21 PM »

I didn't get hacked, but my generic.php tells me

magic_quotes_gpc   On   On
magic_quotes_runtim e   Off   Off
magic_quotes_sybase   Off   Off


but I don't use front-end login, don't know if that makes a difference. Anyway, I patched all my 2.5.2 sites, (don't have any 2.6 sites) They look fine. Ryan you should send out an email to everyone.
Logged

baker's man, bake me a cake as fast as you can
SuE

Offline Offline

Posts: 15


WWW
« Reply #20 on: December 13, 2005, 01:20:21 PM »

the vulnerability is also reported at secunia : http://secunia.com/advisories/17945/
with no solution there which may encourage another hackers    cry
the message to all users may help
Logged
jschor

Offline Offline

Posts: 110


« Reply #21 on: December 14, 2005, 11:02:15 PM »

I replaced the class.login.php in one of my 2.5.2 installations. When see the login page but when i give username and password i get the following error
Warning: Cannot modify header information - headers already sent by (output started at /usr/home/rpl/domains/rpl.nl/public_html/wb/framework/class.login.php:361) in /usr/home/rpl/domains/rpl.nl/public_html/wb/framework/class.login.php on line 134

When i then remove /login/index.php and enter again i do come in the admin area (start/index.php).
Before i replace the file in all my installations maybe someone can help me with this.

Update: This seems to be solved with the new fix.
« Last Edit: December 16, 2005, 09:26:39 AM by jschor » Logged
Ryan

Offline Offline

Posts: 2048



WWW
« Reply #22 on: December 16, 2005, 08:20:33 AM »

Hi guys,

Check your inboxes - I just sent out a forum-wide email, with links to the official patches.
Sorry I took so long - I've been extremely busy getting better and then working on my dads new offices, which will be supplying OSB with the AGM board room (more on that to come). grin
Logged

Website Baker Project Founder
www.websitebaker.or g

To contact me via email, visit:
www.ryandjurovich.c om
rabsaul

Offline Offline

Posts: 263


WWW
« Reply #23 on: December 16, 2005, 08:51:28 AM »

Pardon me for my ignorance, but how can one tell if the server has magic_quotes_gpc set to off?

Thx!  smiley
Logged
Axel Krüger

Offline Offline

Posts: 98



« Reply #24 on: December 16, 2005, 09:25:57 AM »

<?
echo phpinfo();
?>
Logged
Pages: [1] 2   Go Up
Print
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!