Previous Thread
Next Thread
Print Thread
Rate Thread
#213111 12/02/2001 2:33 AM
Joined: Nov 2001
Posts: 52
Power User
Power User
Offline
Joined: Nov 2001
Posts: 52
Hi,

www.extremeforums.org from Poil has been hacked and I hope Poil had a good db backup cause it looked like they just dropped the DB.

I really feel sorry for Poil and hope he can recover fast, but shouldn't we look into how this has happenend so some script kiddiez don't get too much fun and start dropping a lot of DB's ...

[]http://www.artenovo.com/extreme_forums.gif[/]

Heads Up Poil !!!

Sponsored Links
Joined: Nov 2001
Posts: 52
Power User
Power User
Offline
Joined: Nov 2001
Posts: 52
Hi,

Driving in the car I was thinking again about this and another little accident that happened here at Threadsdev and I must say it took me 2 minutes to hack into my own TestForum and alter the database.

I'll send a PM to Scream with the full details, but it's damn simple ... and actually a little bit frightening ...

Joined: May 1999
Posts: 3,039
Guru
Guru
Offline
Joined: May 1999
Posts: 3,039
There are a couple of things that can be dangerous to allow. One being HTML enabled in forums and the other is accepting file attachments with a .php extension. Not sure if either of these was used but I've sent an email off to the posted email addresses so we'll see.


UBB.threads Developer
Joined: May 1999
Posts: 3,039
Guru
Guru
Offline
Joined: May 1999
Posts: 3,039
Poil was also running a pretty hacked version so it's also possible that there was an exploit introduced with some of the stuff that he was working on. Hopefully we'll get some more info.


UBB.threads Developer
Joined: May 1999
Posts: 90
Member
Member
Offline
Joined: May 1999
Posts: 90
I think that the adminstrative option of sending direct sql commands to the server should be 'disablable' from the config file. If you manage to get to the administrative menu -- doesn't matter how, although a certain advisory issued earlier this year comes to mind for no reason wink -- you can easily alter/drop whatever databases the threads user has priviledges on. Of course you can destroy stuff with the other (delete related) admin functions but that requires a little more effort from the attacker.

Sponsored Links
Joined: Feb 2002
Posts: 6
Lurker
Lurker
Offline
Joined: Feb 2002
Posts: 6
Does the default setting of the PHP version of threads allow users to upload .php attachments?


Joined: Oct 2000
Posts: 60
Power User
Power User
Offline
Joined: Oct 2000
Posts: 60
Scream, would there be any drawbacks in having UBBThreads use a user who doesn't have create/drop privaleges?

Joined: May 1999
Posts: 3,039
Guru
Guru
Offline
Joined: May 1999
Posts: 3,039
The default setting only allows .gif,.jpg and .txt attachments.


UBB.threads Developer
Joined: May 1999
Posts: 3,039
Guru
Guru
Offline
Joined: May 1999
Posts: 3,039
Not allowing DROPs would be fine and a good idea. CREATEs are sometimes used when alterting a table when upgrading to a new version so this one might be a problem from time to time.


UBB.threads Developer
Joined: Oct 2000
Posts: 60
Power User
Power User
Offline
Joined: Oct 2000
Posts: 60
Well, I assumed for upgrading, you'd need a full account. I was just asking about during regular operations.

Sponsored Links

Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
Posts: 70
Joined: January 2007
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20240430)