|
[Security] 1.6.4 Security Vulnerability
|
|
10-13-2011, 11:08 PM
Post: #31
|
|||
|
|||
RE: 1.6.4 Security Vulnerability
Just wondering.. what exploit does this allow? It seems such a small change.
|
|||
|
10-13-2011, 11:16 PM
Post: #32
|
|||
|
|||
RE: 1.6.4 Security Vulnerability
(10-13-2011 11:08 PM)MarkW7 Wrote: Just wondering.. what exploit does this allow? It seems such a small change. Ability to modify just about anything by executing arbitrary code in the index.php file. CodeWeavers - CrossOver: Windows Compatibility on Macintosh and Linux ![]() Doesn't like unsolicited PMs |
|||
|
10-14-2011, 07:30 AM
Post: #33
|
|||
|
|||
RE: 1.6.4 Security Vulnerability
(10-13-2011 10:24 PM)JaysonL Wrote: Quite strange to see an exploit already. I don't understand why you would think that. No project is 100% bug free. Bugs and exploits are always there. They just need to be found. -Nathan Malcolm Quality Assurance TeamMyBB Security — MyBB Security & Support Forum |
|||
|
10-14-2011, 07:57 AM
(This post was last modified: 10-14-2011 07:58 AM by seminar techi.)
Post: #34
|
|||
|
|||
RE: 1.6.4 Security Vulnerability
Important
the bot just adding a small script on all index.php and showthread.php after closing php ( thats "?>") ... be aware and search for all index.php to remove suspicious script (i mean all index.php files in server even if there is no relation with mybb files) i hope they used shell access to edit this ..! Seminar Projects Papers || Engineering Project Ideas || MBA Project |
|||
|
10-14-2011, 10:06 AM
Post: #35
|
|||
|
|||
RE: 1.6.4 Security Vulnerability
OK I have cleansed no less than 6 installations of mybb by re-uploading all the compromised files for each one and a file verification for all 6 now comes up clean. So that looks good.
![]() However, I notice that on each installation the config.php was modified at the same time as the other (now cleansed) files. This leads to 2 questions: 1) If the config.php has indeed been modified as the time/date on the file suggests, why doesn't it show as changed in the file verification? I'm guessing it's because the config.php is unique to each mybb and can't be verified? 2) As there is no config.php in the newly available mybb download, what is the correct procedure for replacing the compromised config.php in order to eliminate the apparently altered code? |
|||
|
10-14-2011, 10:19 AM
Post: #36
|
|||
|
|||
RE: 1.6.4 Security Vulnerability
1) Exactly, it is different on all installations.
2) It must look like this: http://wiki.mybb.com/index.php/Inc/config.php |
|||
|
10-14-2011, 11:32 AM
Post: #37
|
|||
|
|||
RE: 1.6.4 Security Vulnerability
Thank you StefanT.
I've now found the code which was added to my config.php files and have removed it, so hopefully I am 100% clean. |
|||
|
10-14-2011, 12:51 PM
Post: #38
|
|||
|
|||
RE: 1.6.4 Security Vulnerability
I guess, that there is still any wrong code on our forums.
I mentioned it already yesterday, when I delete the Spam postings on Moderator-CP, I get to read, that I accepted these postings. They are deleted, but I want the forum show up, that the postings are deleted. Which files depend on Moderation-CP ? Do we perhaps still have another security hole, anywhere on the forum, because, I now had to delete about 30 spam postings, from this morning until now. I run these plugins against spam: Akismet (1.2.1) Bad Behavior (1.0.0) Fassim Anti Spam (1.21) Goodbye Spammer (1.0) Stop forum spam (1.2) Thanks in advance for every answer. |
|||
|
10-14-2011, 01:22 PM
Post: #39
|
|||
|
|||
RE: 1.6.4 Security Vulnerability
Reverted all files reported, applied "Patches Plugin" again (mybb Google Seo)
Thanks mybb Group
[]s, Claudio Tutorial: Jquery (by google API) with mybb (Prototype) Distinction between Paid/Free Plugins Threads |
|||
|
10-14-2011, 01:48 PM
Post: #40
|
|||
|
|||
RE: 1.6.4 Security Vulnerability
I want to emphasize that everyone needs to check config.php. It's not verified by file verification and I found some pretty malicious/dangerous code in mine.
~Paul H. Support PM's will be ignored. (01-19-2012 12:45 AM)euantor Wrote: That's caused by plugins being disabled I believe. Don't quote me on that though
|
|||
|
« Next Oldest | Next Newest »
|
User(s) browsing this thread: 3 Guest(s)
Search
Member List
Calendar
Help


RE: 1.6.4 Security Vulnerability



![[Image: Advocate_125.png]](http://media.codeweavers.com/pub/crossover/marketing/link_banners/Advocate_125.png)

Quality Assurance Team
![[Image: banner.png]](http://files.mybb-forum.de/images/banner.png)

