PDA

View Full Version : vBulletin vunerability (Not)


buro9
Mon 15th Nov '04, 2:11pm
http://www.securityfocus.com/bid/11658/info/

Has anyone traced the file last.php yet?

Clearly it's not one that remains part of an installed vB... but is it third party? Or is it one of the install, upgrade or merge scripts?

Any clues?

Info on the vulnerability at the above address, but in summary:

vBulletin is reported vulnerable to a remote SQL injection vulnerability. This issue is due to a failure of the application to properly validate user-supplied input prior to including it in an SQL query.

An attacker exploits this issue to manipulate and inject SQL queries onto the underlying database. It is reportedly possible to leverage this issue to steal database contents including administrator password hashes and user credentials as well as to attack the underlying database.

Update: It is reported that this vulnerability exists in third party scripts that can be used with vBulletin. Currently, the vendor of the affected scripts is not known. This BID will be updated as more information becomes available.




An example URI sufficient to exploit this vulnerability has been provided:

http://www.example.com/last.php?fsel=,user.password%20as%20title,user.%20 %20%20%20username%20as%20lastposter%20FROM%20user, thread%20%20%20%20%20WHERE%20usergroupid=6%20LIMIT %201



hi all, a new SQL injection found in VBulletin Forums 3.0.x the Vulnerabilite found in last.php, last 10 topics hack. last.php?fsel=,user.password%20as%20title,user.%20 %20%20%20username%20as%20lastposter%20FROM%20user, thread%20%20%20%20%20WHERE%20usergroupid=6%20LIMIT %201 to solve the problem delet fsel? from ttlast.php and last10.php Best Regards, Dr.Death THE MAN OF THE DARK SIDE


I couldn't find mention of it on these boards... but I'd rather face the flak of starting this thread and have it traced and nuked than have us in the dark about this stuff.

What is the last 10 topics hack?

Zachery
Mon 15th Nov '04, 2:14pm
Its from a hack, we have no control over 3rd party scripts, you are best off contacting the author of the hack, and if you have it disable it untill they can release a fix for it.

Steve Machol
Mon 15th Nov '04, 2:14pm
The file last.php is from a hack and not part of the default vB files.

Scott MacVicar
Mon 15th Nov '04, 2:52pm
I cant even find the hack on vbulletin.org anyone know where they got it from?

ManagerJosh
Mon 15th Nov '04, 2:57pm
http://www.google.com/search?hl=en&lr=&safe=off&q=+site:www.vbulletin.org+vbulletin+last.php

Erwin
Mon 15th Nov '04, 6:42pm
Looks like it's part of PHP-Nuke or something. But 100% not part of vBulletin. Securityfocus.com should make it clear. Anyone can write a script with holes in it as a hack for vBulletin.

James Kojiro
Mon 15th Nov '04, 6:57pm
My last.php file currently brings up a 500 Internal Server Error

Joseph777
Mon 15th Nov '04, 8:10pm
This doesn't affect vBadvanced CMPS does it?

The last ten posts (threads) template on the front page?

MGM
Mon 15th Nov '04, 9:15pm
Actually it seems to be from a hack called The Last 10 Posts on a Non-vB Page located here: http://www.vbulletin.org/forum/showthread.php?t=62624

And it seems as if other hackers are using either the same file or a modified version of the file for their Portals/CMS'

MGM out

Erwin
Mon 15th Nov '04, 10:23pm
Why not just use the built-in vB RSS?

ManagerJosh
Tue 16th Nov '04, 12:23am
or vB JS?

ManagerJosh
Tue 16th Nov '04, 12:45am
Erm...gonna double post since its completely different. I rushed an email to security focus and got this reply back:


Thanks, we actually have noted that the vulnerable is not in vBulletin itself:

http://www.securityfocus.com/bid/11658/discussion/ (http://www.securityfocus.com/bid/11658/discussion/)

"Update: It is reported that this vulnerability exists in third party scripts that can be used with vBulletin. Currently, the vendor of the affected scripts is not known. This BID will be updated as more information becomes available."

We have contacted the discovered of the vulnerability and are awaiting a response so that we may correctly associate the vulnerable software (instead of listing vBulletin). Thanks for contacting us on this matter.

Wayne Luke
Tue 16th Nov '04, 1:09am
Wow, they didn't write me back about it.

ManagerJosh
Tue 16th Nov '04, 1:14am
mmmm...dunno. Perhaps Jelsoft woud like to hire a new sales lacky? :p ;)

Zachery
Tue 16th Nov '04, 1:18am
They respond to me all the time :)

Wayne Luke
Tue 16th Nov '04, 1:37am
They updated the vulnerability ticket with the information from my email so it isn't all bad.

Brad.loo
Tue 16th Nov '04, 4:42am
I think the report is incorrect, this is a vB2 hack we are talking about unless I missed a vB3 version of it.

I uploaded a patched version of the file here:

http://www.vbulletin.org/forum/showthread.php?p=572858&posted=1#post572858

James Kojiro
Tue 16th Nov '04, 9:42am
Remember, don't believe everything you read.

Floris
Tue 16th Nov '04, 10:18am
mmmm...dunno. Perhaps Jelsoft woud like to hire a new sales lacky? :p ;)
You have been helping in the Pre-sales a lot last year, maybe you should contact hr@vBulletin.com :)