Posted: Thu Jan 31, 2008 12:48 am Post subject: Possible security alert: admin_db_utilities.php ?
Long time no talk to.
Well, I didn't get the notice on the patches and I got hacked... and bad. Server rooted and all that nastiness. One thing I kept seeing in the logs was this:
Code:
[29/Jan/2008:19:31:52 -0800] "GET //modules/Forums/admin/admin_db_utilities.php?phpbb_root_path= (and some url here I've deleted) "
So are they using a similar exploit with this file as well?
I was running NP8.0 with phpbb 2.0.21.
I've just bought the 8.1 and have DL'd the 2.0.22 and have your patches standing by to go in... once the new box is provisioned... and the backups are restored... and I can get in...
Thought I'd give a heads up if this was something else new...
Oh I haven't made phpNuke 8.1 compatible patches here.
But the Patched files at http://www.nukeresources.com are updated for 8.1.
(They just don't include any of the recent security issues for 2008)
I personally don't recommend 8.1 anyway. A lot of untested code and not worth your money.
As to the attacks against the Forums admin scripts, they have been patched a long time ago. Automated bots are trying anyway, on the slight chance you have not been patched. I doubt you were hacked by this exact attack, but there are lots of other vulnerabilities.
If you are sure there's a specific one that allowed hackers in, and you believe your site is properly patched, please let me know and I can investigate it. _________________ Evaders99 Webmaster Administrator Fighting is terrible, but not as terrible as losing the will to fight.
- SW:Rebellion Network - Evaders Squadron Coding -
yeah, I spent the $12 and got 8.1, but I still had to apply your 2 patches to the ../modules/Search/index.php and to the phpbb2nuke 2.0.22 I downloaded. I guess that 8.1 comes with .21
Not really sure how they got in, but most likely via the PM exploit or the search one.
At any rate, the fantasy is - I may be patched. I just wanted to toss that file up in case it was something new since it was all over my logs.
Oh yeah... and happy new year and all that since we haven't chatted in a while
Yea you'll need to use BBToNuke 2.0.22. Looks like you're good.
Happy new year to you too! _________________ Evaders99 Webmaster Administrator Fighting is terrible, but not as terrible as losing the will to fight.
- SW:Rebellion Network - Evaders Squadron Coding -
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum