View Full Version : mail() vulnerability?
Bytor
Thu 12th Jul '01, 4:55pm
Hello all, I recently read on the O'reilly network about a vulnerability in php's mail() function which allows the user to gain shell access under the web server user account. Apparently the code that uses the mail() function needs to strip out certain characters that allow this exploit to work.
I wanted to see if vBulletin is vulnerable or not. Here is the article
http://linux.oreillynet.com/pub/a/linux/2001/07/09/insecurities.html
Thanks for any information.
(I am running 2.01)
The Prohacker
Thu 12th Jul '01, 5:30pm
Its not really an exploit for vB, its only a problem if your a host. You don't obtain shell access via the vBulletin, you only get access if you make a hostile script and upload it.
Sorry if I'm not clear on my explanation...
Wayne Luke
Thu 12th Jul '01, 6:13pm
We don't allow you to pass parameters to the mail function only data that is checked and not allowed to pose a security risk.
Bytor
Thu 12th Jul '01, 6:14pm
I host a vb forum on my site (http://www.tribes2maps.com) ... are you saying I would be vulnerable, or no? I am a bit confused. My interpretation of this exploit is that shell characters could be put in the subject line, or from, or to header, or something, that would cause shell commands to be executed when the mail() function call was made.
Bytor
Thu 12th Jul '01, 6:14pm
Great, thanks wluke!
Wayne Luke
Thu 12th Jul '01, 9:04pm
Just so you know. We have had vBulletin checked by White Crown Security Services (www.whitecrown.net) to make sure that you are safe when you run the application.
vBulletin® v3.8.0 Beta 3, Copyright ©2000-2008, Jelsoft Enterprises Ltd.