Previous Thread
Next Thread
Print Thread
Rating: 5
Joined: Dec 2000
Posts: 1,471
Addict
Addict
Offline
Joined: Dec 2000
Posts: 1,471
Mod Name / Version: Input validation mod (Security fix) 1.1.1

Description: You all probably noticed that several vulnerabilities have been found in ubb.threads over the last months/weeks. Some of them have been fixed by Infopop, but that's only the tip of the iceberg.

There's no proper input validation in ubb.threads, which makes the door wide open for sql injections. Additionally, the output of ubb.threads isn't escaped properly also. This can be used by "hackers" to start XSS (cross site scripting attacks).

Both types of attacks can used to compromise your boards. Either to damage it or to gain unauthorized access.

During a security audit of ubb.threads, I found more than 10 vulnerabilities.

Infopop is aware of this problem and will "take care" of it in the next release. As this will take at least "some weeks", I created a modification that will prevent most of this attacks.

Note that all current installations of ubb.threads are vulnerable at the moment and that some exploits have already been published to security mailing lists (last one yesterday).

If the modification detects a possible attack an error message is displayed and the attack is logged to a logfile.

Working Under: UBB.Threads 6.3-6.4-6.5

Mod Status: Finished

Any pre-requisites:

Author(s): Astaran

Date: 04/20/05

Credits:

Files Altered: ubbt.inc.php

New Files: Validate.php

Database Altered: no

Info/Instructions: Note that there are three versions of this modification (depending on the ubb.threads version you're using).

Just follow the instructions in instructions.txt.

More experienced users can enhance this class to also validate variables that are used in installed hacks/modifications. See the readme.txt for details.

Disclaimer: Please backup every file that you intend to modify.

If the modification modifies the database, it's a good idea to backup your database before doing so.


Note: If you modify your UBB.Threads code, you may be giving up your right for "official" support from Infopop.If you need official support, you'll need to restore unmodified files.
Attachments
127242-InputValidation1.1.1.zip (0 Bytes, 160 downloads)

Last edited by Astaran; 05/11/2005 5:17 PM.
Sponsored Links
Entire Thread
Subject Posted By Posted
Finished-[6.3-6.4-6.5] Input validation mod (Security fix) 1.1.1 Astaran 04/20/2005 7:33 PM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) scroungr 04/20/2005 7:35 PM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) Medar 04/20/2005 8:22 PM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) AllenAyres 04/21/2005 6:00 AM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) Dalantech 04/21/2005 7:57 AM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) AllenAyres 04/27/2005 12:15 AM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) ksanuk 04/30/2005 3:46 AM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) Calpy 04/30/2005 3:51 AM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) AKD96 04/30/2005 7:56 AM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) Astaran 05/02/2005 12:46 PM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) Astaran 05/02/2005 12:47 PM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) caymuc 05/02/2005 10:25 PM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) AllenAyres 05/03/2005 3:03 AM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) AKD96 05/03/2005 3:31 AM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) ksanuk 05/03/2005 4:07 AM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) Astaran 05/03/2005 6:13 PM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) Astaran 05/06/2005 12:13 AM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) Astaran 05/06/2005 12:57 PM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) SchoolScandals 05/07/2005 12:55 AM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) SchoolScandals 05/07/2005 1:54 AM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) caymuc 05/07/2005 11:50 AM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) SchoolScandals 05/07/2005 6:11 PM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) Astaran 05/07/2005 7:23 PM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) caymuc 05/07/2005 11:04 PM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) Astaran 05/10/2005 10:51 AM
Re: Finished-[6.3-6.5] Input validation mod (Security fix) Astaran 05/12/2005 12:20 AM
Re: Finished-[6.3-6.4-6.5] Input validation mod (Security fix) 1.1.1 krejt 06/07/2005 3:54 PM
Re: Finished-[6.3-6.4-6.5] Input validation mod (Security fix) 1.1.1 Astaran 06/07/2005 4:53 PM
Re: Finished-[6.3-6.4-6.5] Input validation mod (Security fix) 1.1.1 donJulio 06/08/2005 2:49 AM
Re: Finished-[6.3-6.4-6.5] Input validation mod (Security fix) 1.1.1 krejt 06/08/2005 7:43 PM
Re: Finished-[6.3-6.4-6.5] Input validation mod (Security fix) 1.1.1 Zarzal 06/27/2005 8:56 AM
Re: Finished-[6.3-6.4-6.5] Input validation mod (Security fix) 1.1.1 dont 06/27/2005 5:11 PM
Re: Finished-[6.3-6.4-6.5] Input validation mod (Security fix) 1.1.1 Astaran 06/29/2005 12:59 PM
Re: Finished-[6.3-6.4-6.5] Input validation mod (Security fix) 1.1.1 Astaran 06/29/2005 1:00 PM
Re: Finished-[6.3-6.4-6.5] Input validation mod (Security fix) 1.1.1 Zarzal 07/10/2005 7:41 PM
Re: Finished-[6.3-6.4-6.5] Input validation mod (Security fix) 1.1.1 Astaran 07/17/2005 10:14 AM
Re: Finished-[6.3-6.4-6.5] Input validation mod (S peterhd 01/17/2006 8:43 AM
Re: Finished-[6.3-6.4-6.5] Input validation mod (S Zarzal 04/26/2006 1:19 AM
Re: Finished-[6.3-6.4-6.5] Input validation mod (S Zarzal 04/26/2006 1:21 AM
Re: Finished-[6.3-6.4-6.5] Input validation mod (S AllenAyres 04/26/2006 4:28 AM
Re: Finished-[6.3-6.4-6.5] Input validation mod (S Zarzal 04/26/2006 9:30 AM

Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
isaac
isaac
California
Posts: 1,157
Joined: July 2001
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20221218)