avatar Upload... photogallery Upload... db Backup.... /cache

Support for IntegraMOD 140

Moderator: Integra Moderator

avatar Upload... photogallery Upload... db Backup.... /cache

PostAuthor: computerz » Mon Aug 28, 2006 10:34 am

It appeas that the avatar upload and photogallery upload as well as the folders for dbbackup and cache have to be chmod to 777 in order for their respective scripts to work (extreme styles for the latter /cache directory).

However, this allows the hacker to offload Perl scripts into these folders, some of which are eggdrop IRC bots, and then assume super user priviledges to the entire server and thereby hack the site. This doesn't appear to be isolated to just the style selector, as I've been hacked 6 times in the last month, where it only occurs when I chmod the following folders to 777[list type=decimal][*] album_mod/upload [*] images/avatars/ [*] (optionally) cache [/list]

And if dont configure these with 777, then the script doesn't work.

Has anyone thought of and/or realized this glaring security vulnerability? And if so, why is integramod written like this? Someone in the hacker fix thread also noticed the same thing.

Can't we protect these directories with an .htaccess file which will allow the script to write to these folders but prevent hackers remote access? And if not, can't we edit the code such that "world" doen't have to have write access to these folders?

I tried to do something like this

<LimitException>
Order Allow,Deny
deny from all
</LimitException>

and I've also tried

<Directory>
Order Allow,Deny
deny from all
allow from mysite.com
</Directory>

And stuck this .htaccess in the respective folders

But not really certain if this is correct.

Any input would be appreciated. Thanks.
Last edited by computerz on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.

computerz
Members
Members
 
Posts: 84
Likes: 0 post
Liked in: 0 post
Joined: Sun Aug 27, 2006 2:21 pm
Cash on hand: 0.00

PostAuthor: Unregistered » Mon Aug 28, 2006 5:32 pm

hmmm... more things to work on i guess ..
Last edited by Unregistered on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
J O N H | P L A Y E R

Unregistered
Sr Integra Member
Sr Integra Member
 
Posts: 254
Likes: 0 post
Liked in: 0 post
Joined: Wed Jun 07, 2006 2:51 pm
Cash on hand: 0.00

Re: avatar Upload... photogallery Upload... db Backup.... /c

PostAuthor: Michaelo » Tue Aug 29, 2006 2:57 pm

Upload directories need to be accessed by all this is the same for every bulletin board ever written...

Update you files with the security fixes to stop the script hack. In you case the style change hack and several others have been plugged.

Please read all Global Announcement and check the Security Forum for updates.
Mike
Last edited by Michaelo on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
Kiss Portal Engine phpbbireland (status: Released)
User avatar
Michaelo
Administrator
Administrator
 
Posts: 1647
Likes: 0 post
Liked in: 2 posts
Joined: Sat Mar 11, 2006 6:14 pm
Cash on hand: 5.10
Location: Dublin, Ireland


Return to IntegraMOD 140

Who is online

Registered users: App360MonitorBot, Bing [Bot], Google [Bot]