SW:Rebellion NetworkHosted by the SW:Rebellion Network
Welcome to Evaders Squadron Coding [ESC]
Home Forums Nuke Patched Core Coding Services Webmaster Services Personal
  Login/Create an Account    

Forums
· Forums FAQ
· Search
· Usergroups
· Profile
· Private Messages

Support Us
This site runs with your support. Please donate:

User Info/Login
Welcome, Anonymous
Nickname
Password
Security Code: Security Code
Type Security Code

(Register)
Membership:
Latest: Cromwell
New Today: 0
New Yesterday: 1
Overall: 10344

People Online:
Visitors: 24
Members: 0
Total: 24

Link to Us

Evaders Squadron Coding [ESC] :: View topic - Security: PHP-Nuke HTTP "referer" SQL Injection Vu
Security: PHP-Nuke HTTP "referer" SQL Injection Vu

 
Post new topic   Reply to topic    Evaders Squadron Coding [ESC] Forum Index -> Coding Services
View previous topic :: View next topic  
Author Message
Evaders99



Joined: Jan 11, 2002
Posts: 3079
Location: USA

PostPosted: Tue Mar 13, 2007 12:04 am    Post subject: Security: PHP-Nuke HTTP "referer" SQL Injection Vu Reply with quote

In response to:
http://secunia.com/advisories/24224/

I am posting an analysis here:

All Patched files may be vulnerable. RavenNuke may be vulnerable.

In index.php

Patched
Code:

$result = $db->sql_query("INSERT INTO ".$prefix."_referer VALUES (NULL, '".$referer."')");

TO

$result = $db->sql_query("INSERT INTO ".$prefix."_referer VALUES (NULL, '".addslashes($referer)."')");



RavenNuke
Code:

$result = $db->sql_query('INSERT INTO '.$prefix.'_referer VALUES (NULL, \''.$referer.'\')');

TO

$result = $db->sql_query('INSERT INTO '.$prefix.'_referer VALUES (NULL, \''.addslashes($referer).'\')');

_________________
Evaders99
SW:Rebellion Fans! Webmaster
Star Wars roleplaying community! Administrator

Fighting is terrible, but not as terrible as losing the will to fight.
- SW:Rebellion Network - Evaders Squadron Coding -

The cake is a lie.
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Evaders99



Joined: Jan 11, 2002
Posts: 3079
Location: USA

PostPosted: Thu Jun 18, 2009 11:59 pm    Post subject: Reply with quote

There was a note added 5/28/2009 here
http://secunia.com/advisories/28624/
http://gsasec.blogspot.com/2009/05/php-nuke-v80-referer-sql-injection.html

But I'm sure this is the same vulnerability and it is the latest Patched files
_________________
Evaders99
SW:Rebellion Fans! Webmaster
Star Wars roleplaying community! Administrator

Fighting is terrible, but not as terrible as losing the will to fight.
- SW:Rebellion Network - Evaders Squadron Coding -

The cake is a lie.
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
ryanrbftp
Newbie
Newbie


Joined: Oct 09, 2009
Posts: 1

PostPosted: Thu Oct 08, 2009 11:41 pm    Post subject: Reply with quote

Does this exist for older version of PHP-Nuke?
Back to top
View user's profile Send private message
Evaders99



Joined: Jan 11, 2002
Posts: 3079
Location: USA

PostPosted: Fri Oct 09, 2009 12:54 am    Post subject: Reply with quote

Most certainly yes.
_________________
Evaders99
SW:Rebellion Fans! Webmaster
Star Wars roleplaying community! Administrator

Fighting is terrible, but not as terrible as losing the will to fight.
- SW:Rebellion Network - Evaders Squadron Coding -

The cake is a lie.
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
stevenswing
Newbie
Newbie


Joined: Oct 09, 2009
Posts: 5

PostPosted: Sat Oct 10, 2009 10:11 am    Post subject: Reply with quote

Just patched our code for this, would this work:

Code:
$sql = "INSERT INTO ".$prefix."_referer VALUES (NULL, '".addslashes($referer)."')";


Question
Back to top
View user's profile Send private message
Evaders99



Joined: Jan 11, 2002
Posts: 3079
Location: USA

PostPosted: Sat Oct 10, 2009 6:58 pm    Post subject: Reply with quote

Looks fine
_________________
Evaders99
SW:Rebellion Fans! Webmaster
Star Wars roleplaying community! Administrator

Fighting is terrible, but not as terrible as losing the will to fight.
- SW:Rebellion Network - Evaders Squadron Coding -

The cake is a lie.
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Display posts from previous:   
Post new topic   Reply to topic    Evaders Squadron Coding [ESC] Forum Index -> Coding Services All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group

^Top
Home Your Account Forums Downloads F.A.Q. Submit News Hosting Contact Us

© 2005 - 2007 by Evaders99. All Rights Reserved.
All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters.
You can syndicate our news using the file backend.php
PHP-Nuke Copyright © 2005 by Francisco Burzi. This is free software, and you may redistribute it under the GPL.
PHP-Nuke comes with absolutely no warranty, for details, see the license.
Page Generation: 0.42 Seconds