Author |
Message |
hls-bill
New Member
data:image/s3,"s3://crabby-images/0b3dd/0b3dd56bc606132b506b4d2f9c985116ba684530" alt="New Member New Member"
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
Joined: Feb 14, 2007
Posts: 2
|
Posted:
Tue Feb 20, 2007 1:12 pm |
|
Only registered users can see links on this board! Get registered or login!
Any word on this one?
Kind Regards,
Bill |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
stefvar
New Member
data:image/s3,"s3://crabby-images/0b3dd/0b3dd56bc606132b506b4d2f9c985116ba684530" alt="New Member New Member"
data:image/s3,"s3://crabby-images/65f2a/65f2a7b1c7eb1f5d1b1f77a495c014861303b1a2" alt=""
Joined: Oct 30, 2005
Posts: 18
|
Posted:
Tue Feb 20, 2007 3:48 pm |
|
Hello,
Look at also this link :
Only registered users can see links on this board! Get registered or login! data:image/s3,"s3://crabby-images/65647/65647f0db57cf641cbdf8d726317ee9f636d8ec1" alt="Wink" |
_________________ Stef and Co. Bénévolat sur mesure
Only registered users can see links on this board! Get registered or login!
Only registered users can see links on this board! Get registered or login! |
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
technocrat
Life Cycles Becoming CPU Cycles
data:image/s3,"s3://crabby-images/35c25/35c259de005947897e9e0165c0980cfaa17df688" alt=""
Joined: Jul 07, 2005
Posts: 511
|
Posted:
Tue Feb 20, 2007 6:20 pm |
|
Here is a quick fix for first exploit
Open includes/nukesentinel.php
Find:
Code:// Load Blocker Arrays
|
Before add:
Code:function nsnst_valid_ip ($ip) {
return (preg_match('/^(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$/', $ip));
}
|
Find:
Code:$ip = explode(".", $remoteip);
|
After add:
Code: if (!nsnst_valid_ip($remoteip)) {
die('Access Denied');
}
|
Find:
Code:if(empty($template)) { $template = "abuse_default.tpl"; }
|
Before add:
Code:if (!empty($template) && ereg('.php', $template)) $template = '';
|
|
_________________ Only registered users can see links on this board! Get registered or login!
Only registered users can see links on this board! Get registered or login! / Only registered users can see links on this board! Get registered or login!
Last edited by technocrat on Tue Feb 20, 2007 6:31 pm; edited 1 time in total |
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Guardian2003
Site Admin
data:image/s3,"s3://crabby-images/561e7/561e7182bdcacfd2a2232800b5c2bee621501a26" alt=""
Joined: Aug 28, 2003
Posts: 6799
Location: Ha Noi, Viet Nam
|
Posted:
Tue Feb 20, 2007 6:25 pm |
|
I can confirm the developers are aware and working on a permanent fix. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
technocrat
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Tue Feb 20, 2007 6:30 pm |
|
Actually you should probably strip out all the ips
Replace
Code:if(!ereg("([0-9]{1,3})\\.([0-9]{1,3})\\.([0-9]{1,3})\\.([0-9]{1,3})", $nsnst_const['client_ip'])) {$nsnst_const['client_ip'] = "none"; }
if(!ereg("([0-9]{1,3})\\.([0-9]{1,3})\\.([0-9]{1,3})\\.([0-9]{1,3})", $nsnst_const['forward_ip'])) {$nsnst_const['forward_ip'] = "none"; }
if(!ereg("([0-9]{1,3})\\.([0-9]{1,3})\\.([0-9]{1,3})\\.([0-9]{1,3})", $nsnst_const['remote_ip'])) {$nsnst_const['remote_ip'] = "none"; }
if(!ereg("([0-9]{1,3})\\.([0-9]{1,3})\\.([0-9]{1,3})\\.([0-9]{1,3})", $nsnst_const['remote_addr'])) {$nsnst_const['remote_addr'] = "none"; }
|
With:
Code:if (!nsnst_valid_ip($nsnst_const['client_ip'])) {$nsnst_const['client_ip'] = "none"; }
if (!nsnst_valid_ip($nsnst_const['forward_ip'])) {$nsnst_const['forward_ip'] = "none"; }
if (!nsnst_valid_ip($nsnst_const['remote_ip'])) {$nsnst_const['remote_ip'] = "none"; }
if (!nsnst_valid_ip($nsnst_const['remote_addr'])) {$nsnst_const['remote_addr'] = "none"; }
|
And then
Code:if (!nsnst_valid_ip($remoteip)) {
die('Access Denied');
}
|
With:
Code: if (!nsnst_valid_ip($remoteip) && $remoteip != 'none') {
die('Access Denied');
}
|
|
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
montego
Site Admin
data:image/s3,"s3://crabby-images/90769/907690f0b3800b7c3631940ce09741fc8d7ec9ba" alt=""
Joined: Aug 29, 2004
Posts: 9457
Location: Arizona
|
Posted:
Tue Feb 20, 2007 10:15 pm |
|
Really nice of these guys to have posted the exploit without first giving the author(s) of the tool a chance to prepare a fix. Unbelievable!! |
_________________ Only registered users can see links on this board! Get registered or login!
Only registered users can see links on this board! Get registered or login! |
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
montego
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Tue Feb 20, 2007 10:37 pm |
|
For the second one, in the meantime, I have placed the following in my includes directory:
Code:
<Files nsbypass.php>
<Limit GET POST PUT>
require valid-user
</Limit>
AuthName "Restricted for direct access"
AuthType Basic
AuthUserFile <<chg to full path to your .staccess file>>
</Files>
|
Figured this might help initially... I had done something similar awhile back for modules/Forums/admin when we were having all those direct attacks against it. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
evaders99
Former Moderator in Good Standing
data:image/s3,"s3://crabby-images/c915b/c915ba1715f1389dcc5b042d6c45c550b39402b4" alt=""
Joined: Apr 30, 2004
Posts: 3221
|
Posted:
Wed Feb 21, 2007 12:58 am |
|
montego wrote: | Really nice of these guys to have posted the exploit without first giving the author(s) of the tool a chance to prepare a fix. Unbelievable!! |
Always happens. You really have to wonder if they actually believe they are helping people. It will just be another exploit for script kiddies to use before everyone can upgrade their sites. Its sad that it will just lead to more exploited systems and not better security.
I really hate when it says "for educational purposes only" .. when it is obviously not designed to teach anyone, rather to be used in malicious attacks on innocent sites. |
_________________ - Only registered users can see links on this board! Get registered or login! -
Need help? Only registered users can see links on this board! Get registered or login! |
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
stefvar
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Wed Feb 21, 2007 2:02 am |
|
Hello,
If my message could cause a gene, I am really sorry. It was absolutely not its goal. These problems having been diffused as a preliminary on several sites, I thought on the contrary that that will be able to help.
In the future, I will make in kind not announce this kind of information more.
Cordially |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
kguske
Site Admin
data:image/s3,"s3://crabby-images/11363/11363ee4b6d8fcccf066bb96f62969ca855aaa0b" alt=""
Joined: Jun 04, 2004
Posts: 6437
|
Posted:
Wed Feb 21, 2007 5:34 am |
|
They are referring to the people who published the exploit, Stefvar. We definitely appreciate you letting us know! |
_________________ I search, therefore I exist...
Only registered users can see links on this board! Get registered or login! |
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
stefvar
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Wed Feb 21, 2007 5:42 am |
|
Hello,
Thank you Kguske for the precision. I had not interpreted it thus. I have still enormous progress to make for the good comprehension of the English language . |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
technocrat
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Wed Feb 21, 2007 8:28 am |
|
What's odd is this one came out of no where. I did not see it on any of the normal channels before it's release. Usually people are talking about it before hand. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
FireATST
RavenNuke(tm) Development Team
data:image/s3,"s3://crabby-images/61fa0/61fa0aa93a62fb04c4a6ec38a8ef8b14b5b32556" alt=""
Joined: Jun 12, 2004
Posts: 654
Location: Ohio
|
Posted:
Wed Feb 21, 2007 3:23 pm |
|
ty for posting the fix for it technocrat.... data:image/s3,"s3://crabby-images/02649/02649b21d5d3a85591018d7ab15f62ef52d9db66" alt="Cheers" |
|
|
data:image/s3,"s3://crabby-images/94986/94986c1305d77ad4918c72693843b17b87365eb0" alt="ICQ Number ICQ Number" |
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
hls-bill
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Wed Feb 21, 2007 5:15 pm |
|
Seems the acid-root site went poof -- I will depoly the posted fixes this evening.. seems like PhP 5 took a hit today as well. Thanks for the replies on this. One thing that I would like to mention is. What is going on here with NukeSentiel if it was not deployed widely and affected so many --- no one would care if it was exploited. Please keep up the great work on this much needed tool to protect our sites.
Kind Regards,
Bill |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
montego
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Wed Feb 21, 2007 6:00 pm |
|
stefvar, yes, what Kguske said is what I was referring to. Please do not hesitate to let any of us know. Like technocrat said, this "came out of no where".
technocrat, were you actually successful in testing this exploit (actually "these")? I had issues last night with it, but will not mention any details here. Just curious if you had. Thanks. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Gremmie
Former Moderator in Good Standing
data:image/s3,"s3://crabby-images/e0184/e0184c289d846a553594e6ddcdc67f3354a52fed" alt=""
Joined: Apr 06, 2006
Posts: 2415
Location: Iowa, USA
|
Posted:
Wed Feb 21, 2007 6:04 pm |
|
Could someone post complete fixes? I can't tell if Technocrat had changed his mind about his first set of fixes. |
_________________ Only registered users can see links on this board! Get registered or login! - An Event Calendar for PHP-Nuke
Only registered users can see links on this board! Get registered or login! - A Google Maps Nuke Module |
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
evaders99
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Wed Feb 21, 2007 7:11 pm |
|
Yep stefvar, we were commenting on the group that released the exploit and how to use it. We definitely want people to come here and tell us if they notice such things! |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
FireATST
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Wed Feb 21, 2007 7:31 pm |
|
Montego, would you then be advising me to remove his fixes for now. I know you don't want to say what you had problems with, but is it worth me setting it back to the way it was? Guess I just assumed ( I know, I know.... ) that is was good to go. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
montego
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Thu Feb 22, 2007 5:33 am |
|
Quote: |
Montego, would you then be advising me to remove his fixes for now
|
No! Until this is confirmed by the developers and a fix is provided (if needed), there is no reason not to apply these temporary "patches".
Gremmie, Either set of "fixes" should be fine in the interim. Technocrat, in his second post, was just suggesting something a little better and possibly closer to a final fix. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
technocrat
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Thu Feb 22, 2007 7:50 am |
|
Montego - Yes I did and it stopped it as far as I could tell. If you PM me or email me technocrat498 yahoo com I will look at what you found. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Gremmie
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Fri Feb 23, 2007 5:38 pm |
|
I have implemented these two fixes, and now two of my AOL users are seeing 'Access Denied'. Any ideas? |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
technocrat
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Fri Feb 23, 2007 5:47 pm |
|
Look through your Tracked IP for those users and see what their IPs are. I wonder if AOL is sending a blank IP. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Gremmie
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Sat Feb 24, 2007 10:53 am |
|
I didn't have IP tracking turned on, but I turned it on last night. I don't see anything out of the ordinary in the tracked IP listings. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Gremmie
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Sun Feb 25, 2007 9:59 pm |
|
Crap now I have a non-AOL user complaining about Access Denied. Is there another way to fix this? What is the first exploit doing? Thanks. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
technocrat
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon Feb 26, 2007 10:09 am |
|
Try changing:
Code:if (!nsnst_valid_ip($remoteip) && $remoteip != 'none') {
|
To:
Code:if (!nsnst_valid_ip($remoteip) && $remoteip != 'none' && !empty($remoteip)) {
|
|
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
|