Read this post for details. NukeSentinel™ is named for not stopping this attack when it absolutely does, 100% of the time, if you have the Union blocker on. I have replied to the thread as follows:
[snip]Of course, mysql version 4.x must be used with enabled union functionality. And if there are Sentinel or similar protection systems installed, additional measures must be used to evade them.[/snip]
You are mistaken. If NukeSentinel is installed and active, it blocks them 100% of the time. This exploit is nothing more than a variation on a theme. It's another in a long line of UNION exploits which NukeSentinel has been blocking since day one.
Note:There are actually 2 more "new" exploits listed - All pertaining to nuke 7.6:
http://www.securityfocus.com/bid/13061
http://www.securityfocus.com/bid/13055
If you have Chatserv's patches installed and NukeSentinel(tm) - Sleep well tonight!
PHP-Nuke Bug - SQL Injection
Posted on Sunday, April 10, 2005 @ 23:31:22 CDT in Security
|
Have Your Reviews Been Bronzed?
Posted on Tuesday, March 22, 2005 @ 10:27:22 CST in Security
|
More PayPal Fraud
Posted on Monday, March 14, 2005 @ 10:45:44 CST in Security Nukeum66 writes:
|
phpBB 'usercp_register.php' Error Lets Remote Users Conduct Cross-Site Sc ript
Posted on Monday, March 07, 2005 @ 12:31:09 CST in Security southern writes:
|
Host.Deny SQL file V0.2 Released (NON SOURCEFORGE RELEASE)
Posted on Thursday, March 03, 2005 @ 22:56:24 CST in Security fisicouk writes:
|
CRITICAL UPDATE - phpBB 2.0.13 Security Patch!
Posted on Monday, February 28, 2005 @ 00:31:32 CST in Security 64bitguy writes:
|