Author |
Message |
Mesum
Useless
data:image/s3,"s3://crabby-images/06860/068606fae01421246b5953a9d726fbdbaa8c0191" alt=""
Joined: Aug 23, 2002
Posts: 213
Location: Chicago
|
Posted:
Sun Apr 25, 2004 2:41 am |
|
Hi, I was just wondering if there will be a newer version of HackAlert will be coming out soon.
thanks. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
Site Admin/Owner
data:image/s3,"s3://crabby-images/6c868/6c86859170a3596c942592f58366e4a982a03ad0" alt=""
Joined: Aug 27, 2002
Posts: 17088
|
Posted:
Sun Apr 25, 2004 6:54 am |
|
For what purpose? Is there a new exploit? |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Mesum
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Sun Apr 25, 2004 6:57 am |
|
I am not sure but I saw people were talking about some new (at least for me) encrypted union attacks or something. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Sun Apr 25, 2004 7:02 am |
|
There's a flurry of discussion about it at nukecops but I've yet to see the exploit that it purports to fix. Their 'fix' is breaking more things than it is fixing so if there is an exploit and someone would send it along, I will be happy to look into it. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Tue Apr 27, 2004 8:54 am |
|
There is one MySQL exploit that can be used to 'mask' the union attack. MySQL and a few other rdbms's allow a comment /* */ to be placed in the Query as a hint to MySQL to override it's determined course. In other words, if MySQL would determine to NOT use an index, for whatever reason, you can give it a 'hint' by placing certain code in the query in /* */. Well, the crackers out there have picked up on this and are exploiting it. Here is a proposed fix for my hack alert code in mainfile.phpCode:$checkurl = preg_replace("#(/\*.*\*/)#", "", $_SERVER["QUERY_STRING"]); //Courtesy of http://www.esnider.net
// Raven http://ravenphpscripts.com
if (stristr($checkurl,'%20union%20')) {
$loc = $_SERVER['QUERY_STRING'];
header("Location: hackattempt.php?$loc");
die();
}
| I am testing it and would like you all to test it too. Once we determine it works I will modify the download. Let me know. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
chatserv
Member Emeritus
data:image/s3,"s3://crabby-images/64da3/64da323207ec74cfcb4c8b8cd8e7ce2879ed8441" alt=""
Joined: May 02, 2003
Posts: 1389
Location: Puerto Rico
|
Posted:
Tue Apr 27, 2004 10:12 am |
|
Testing it but i had to rename the variable as i already use $checkurl in admin.php |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Dogman
New Member
data:image/s3,"s3://crabby-images/0b3dd/0b3dd56bc606132b506b4d2f9c985116ba684530" alt="New Member New Member"
data:image/s3,"s3://crabby-images/ee10b/ee10bd437df5abaafd35434971c9ed80e4c54ce8" alt=""
Joined: Oct 24, 2002
Posts: 1
|
Posted:
Tue Apr 27, 2004 11:12 am |
|
Hm,...
this filter worked for "NukeHackerTrap" v1.2 available at http://www.warp-speed.de :
[/CODE]
if (stristr($sRQ,'/*')) return $this->detect();
[/CODE]
Dogman data:image/s3,"s3://crabby-images/aac24/aac2483665ae15bd71498360df4c319f040e7934" alt="Cool" |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
southern
Client
data:image/s3,"s3://crabby-images/e2bc6/e2bc6dd38112d4ea97c3b1dfdaed7e6c6722995e" alt=""
Joined: Jan 29, 2004
Posts: 624
|
Posted:
Tue Apr 27, 2004 11:24 am |
|
I'll put it in mainfile and let you know how it works. Your original hackalert is great and I wouldn't deign to use the NC plagiarization. |
_________________ Computer Science is no more about computers than astronomy is about telescopes.
- E. W. Dijkstra |
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
southern
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Tue Apr 27, 2004 12:29 pm |
|
Um, where in mainfile does it go? There doesn't seem a $checkurl in mainfile. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
chatserv
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Tue Apr 27, 2004 12:36 pm |
|
Place the line right after the file credits |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
southern
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Tue Apr 27, 2004 1:13 pm |
|
Ok. Just got a bunch of hack attempt alerts from 62.254.64.8, Amsterdam natch. Why don't those little Dutch boys and girls stick their fingers in dykes instead of hacking...? data:image/s3,"s3://crabby-images/46293/4629312abfbf8bc12c3443435059ab7079b9e965" alt="Sad" |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
sixonetonoffun
Spouse Contemplates Divorce
data:image/s3,"s3://crabby-images/8dfed/8dfededcab41558184ffe2905eff0db84df25448" alt=""
Joined: Jan 02, 2003
Posts: 2496
|
Posted:
Tue Apr 27, 2004 1:19 pm |
|
Seems to catch anything I've thrown at it so far. Just a few variations on the standard %20UNION%20 and %20UN/*%20%20%20%20*/ION%20
So on and so on. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Coldy
Hangin' Around
data:image/s3,"s3://crabby-images/f58d6/f58d6845b21b90c3424fd71d3f25a426eac046ff" alt=""
Joined: Apr 24, 2004
Posts: 48
Location: Austria
|
Posted:
Tue Apr 27, 2004 1:30 pm |
|
I´ve testet on two different phpnuke-versions!
I think it works, but i had delete the last fix from sting!
Coldy data:image/s3,"s3://crabby-images/aac24/aac2483665ae15bd71498360df4c319f040e7934" alt="Cool" |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
southern
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Tue Apr 27, 2004 1:31 pm |
|
I put it in mainfile, now I'm going outdoors to tend to my garden...gotta check my possum traps while hack alert traps more Dutch boys and girls. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Johan1982
New Member
data:image/s3,"s3://crabby-images/0b3dd/0b3dd56bc606132b506b4d2f9c985116ba684530" alt="New Member New Member"
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
Joined: Oct 23, 2003
Posts: 24
|
Posted:
Tue Apr 27, 2004 2:06 pm |
|
Code:$checkmyurl = preg_replace("#(/\*.*\*/)#", "", $_SERVER["QUERY_STRING"]); //Courtesy of http://www.esnider.net
// Raven http://ravenphpscripts.com
if (stristr($checkmyurl,'%20union%20')) {
$loc = $_SERVER['QUERY_STRING'];
header("Location: hackattempt.php?$loc");
die();
}
|
data:image/s3,"s3://crabby-images/18c7f/18c7f90b0760483efa00269e247aab58b6ba8ef1" alt="Question" |
Last edited by Johan1982 on Tue Apr 27, 2004 2:27 pm; edited 1 time in total |
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
sixonetonoffun
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Tue Apr 27, 2004 2:08 pm |
|
$checkmyurl doesn't match if (stristr($checkurl |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Johan1982
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Tue Apr 27, 2004 2:44 pm |
|
Corrected this observation in my past post , thanks data:image/s3,"s3://crabby-images/aac24/aac2483665ae15bd71498360df4c319f040e7934" alt="Cool" |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
MickP
Hangin' Around
data:image/s3,"s3://crabby-images/78207/782079b68599db2dac90bfd8bdd54afeaf465245" alt=""
Joined: Sep 17, 2003
Posts: 31
Location: Australia
|
Posted:
Tue Apr 27, 2004 3:01 pm |
|
I have just added to my site and will let you know if there are any problems, I also had to rename $checkurl tho data:image/s3,"s3://crabby-images/fabed/fabed724a04168d23d67c0f0722ee8a640f1adb3" alt="Smile" |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
sixonetonoffun
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Tue Apr 27, 2004 3:14 pm |
|
Yeh Think I'd go for a new name for the variable
Somthing like $union_tap oh wait thats another Paul Laudanski (aka Zhen-Xjell). TM name er let me uhm see here...
How about $no_unions or $union_crap? See the AUP for further details data:image/s3,"s3://crabby-images/7539a/7539a4801a8353552d83c12fb3133d9d91019a9f" alt="Rolling Eyes" |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Tue Apr 27, 2004 3:20 pm |
|
Have you read the latest announcement over there and some feedback? This could get lively! Hey! I forgot to copyright my code! Doggone it - now it's too late. Oh, that's right. I can wait for a more opportune time and then attack one of you for using it. How silly of me! /me slaps me, or is that YOU ARE SLAPPED BY ME? Bad, bad, bad .... |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
sixonetonoffun
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Tue Apr 27, 2004 3:37 pm |
|
So far all I've kept up on is the posts at the .org those virtual slaps are so painful. I bet the script kiddies cry every time they get one. I know the union folks are gonna get tired of it in a hurry. Might even go out on strike over the treatment. data:image/s3,"s3://crabby-images/65647/65647f0db57cf641cbdf8d726317ee9f636d8ec1" alt="Wink" |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Nukeum66
Life Cycles Becoming CPU Cycles
data:image/s3,"s3://crabby-images/f34dc/f34dc4441af8860dc66e338b674474bf234704a0" alt=""
Joined: Jul 30, 2003
Posts: 551
Location: Neurotic, State, USA
|
Posted:
Tue Apr 27, 2004 4:57 pm |
|
Out of curiosity I tested Paul's Union Tap beta3 and needless to say, it should be called Union Crap. It stopped only the original exploit.
Now the Raven_Slap script stopped everything. |
_________________ Scott Johnson MIS Ubuntu/Linux 11.10 |
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Tank863
New Member
data:image/s3,"s3://crabby-images/0b3dd/0b3dd56bc606132b506b4d2f9c985116ba684530" alt="New Member New Member"
data:image/s3,"s3://crabby-images/98bd2/98bd2ae5d7d8e095bfd7e210699fb83d3d55c16b" alt=""
Joined: May 29, 2003
Posts: 16
|
Posted:
Tue Apr 27, 2004 7:12 pm |
|
I must say.. I am once again impressed with your hackalert script Raven.
I tested out your script using Janek's exploit and it stopped it dead in its tracks.
Question for Chatserv... I also use $checkurl in admin.php. I added the new hackalert as is posted above.. it worked.
Do I need to change it? data:image/s3,"s3://crabby-images/e0bb8/e0bb8ae632d5403d592207c5f3b606b6fd5d39bf" alt="Embarassed" |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
chatserv
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Tue Apr 27, 2004 7:28 pm |
|
I only changed it to avoid conflicts with the previous one since mainfile.php gets included by all other files chances are eventually both url checkers might clash. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
dean
Worker
data:image/s3,"s3://crabby-images/8b787/8b787549c86734a98c61309018e332528520bc6f" alt="Worker Worker"
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
Joined: Apr 14, 2004
Posts: 193
|
Posted:
Thu Apr 29, 2004 2:00 pm |
|
At the risk of alienating someone (not intentional), whats a noob to do. Does this script provide the same type of protection as the so called Fortress (nc) or the Protector (mister)? I installed the protector prior to finding this site. And I have gleaned and concluded that chatserv's hackalert may provide better protection? From a consumer's standpoint, it's getting difficult to know which path to follow, so please don't take offense at this question. I just would like to know if anyone has compared the three approaches to security. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
|