SW:Rebellion NetworkHosted by the SW:Rebellion Network
Welcome to Evaders Squadron Coding [ESC]
Star Wars fans, Star Wars games, Star Wars community... did we mention Star Wars? The Star Wars Rebellion Network
Home Forums Nuke Patched Core Coding Services Webmaster Services Personal
  Login/Create an Account    

Forums
· Forums FAQ
· Search
· Usergroups
· Profile
· Private Messages

Support Us
This site runs with your support. Please donate:

User Info/Login
Welcome, Anonymous
Nickname
Password
Security Code: Security Code
Type Security Code

(Register)
Membership:
Latest: kurkistan
New Today: 2
New Yesterday: 2
Overall: 9616

People Online:
Visitors: 13
Members: 0
Total: 13

Link to Us

Affliates
RPG Boards Hosting

Evaders Squadron Coding [ESC] :: View topic - Possible security alert: admin_db_utilities.php ?
Possible security alert: admin_db_utilities.php ?

 
Post new topic   Reply to topic    Evaders Squadron Coding [ESC] Forum Index -> Coding Services
View previous topic :: View next topic  
Author Message
LupinOne
Newbie
Newbie


Joined: Nov 03, 2006
Posts: 5

PostPosted: Thu Jan 31, 2008 12:48 am    Post subject: Possible security alert: admin_db_utilities.php ? Reply with quote

Long time no talk to.

Well, I didn't get the notice on the patches and I got hacked... and bad. Server rooted and all that nastiness. One thing I kept seeing in the logs was this:

Code:
[29/Jan/2008:19:31:52 -0800] "GET //modules/Forums/admin/admin_db_utilities.php?phpbb_root_path= (and some url here I've deleted) "


So are they using a similar exploit with this file as well?

I was running NP8.0 with phpbb 2.0.21.

I've just bought the 8.1 and have DL'd the 2.0.22 and have your patches standing by to go in... once the new box is provisioned... and the backups are restored... and I can get in...

Thought I'd give a heads up if this was something else new...

John / LupinOne
Back to top
View user's profile Send private message AIM Address Yahoo Messenger
Evaders99



Joined: Jan 11, 2002
Posts: 3063
Location: USA

PostPosted: Thu Jan 31, 2008 2:04 am    Post subject: Reply with quote

Oh I haven't made phpNuke 8.1 compatible patches here.
But the Patched files at http://www.nukeresources.com are updated for 8.1.
(They just don't include any of the recent security issues for 2008)

I personally don't recommend 8.1 anyway. A lot of untested code and not worth your money.

As to the attacks against the Forums admin scripts, they have been patched a long time ago. Automated bots are trying anyway, on the slight chance you have not been patched. I doubt you were hacked by this exact attack, but there are lots of other vulnerabilities.

If you are sure there's a specific one that allowed hackers in, and you believe your site is properly patched, please let me know and I can investigate it.
_________________
Evaders99
SW:Rebellion Fans! Webmaster
Star Wars roleplaying community! Administrator

Fighting is terrible, but not as terrible as losing the will to fight.
- SW:Rebellion Network - Evaders Squadron Coding -

The cake is a lie.
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
LupinOne
Newbie
Newbie


Joined: Nov 03, 2006
Posts: 5

PostPosted: Thu Jan 31, 2008 2:37 am    Post subject: Reply with quote

yeah, I spent the $12 and got 8.1, but I still had to apply your 2 patches to the ../modules/Search/index.php and to the phpbb2nuke 2.0.22 I downloaded. I guess that 8.1 comes with .21

Not really sure how they got in, but most likely via the PM exploit or the search one.

At any rate, the fantasy is - I may be patched. I just wanted to toss that file up in case it was something new since it was all over my logs.

Oh yeah... and happy new year and all that since we haven't chatted in a while Razz
Back to top
View user's profile Send private message AIM Address Yahoo Messenger
Evaders99



Joined: Jan 11, 2002
Posts: 3063
Location: USA

PostPosted: Thu Jan 31, 2008 2:47 am    Post subject: Reply with quote

Yea you'll need to use BBToNuke 2.0.22. Looks like you're good.

Happy new year to you too!
_________________
Evaders99
SW:Rebellion Fans! Webmaster
Star Wars roleplaying community! Administrator

Fighting is terrible, but not as terrible as losing the will to fight.
- SW:Rebellion Network - Evaders Squadron Coding -

The cake is a lie.
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Display posts from previous:   
Post new topic   Reply to topic    Evaders Squadron Coding [ESC] Forum Index -> Coding Services All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group

^Top
Home Your Account Forums Downloads F.A.Q. Submit News Hosting Contact Us

© 2005 - 2007 by Evaders99. All Rights Reserved.
All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters.
You can syndicate our news using the file backend.php
PHP-Nuke Copyright © 2005 by Francisco Burzi. This is free software, and you may redistribute it under the GPL.
PHP-Nuke comes with absolutely no warranty, for details, see the license.
Page Generation: 0.18 Seconds