Icy Phoenix

     
 


Post new topic  Reply to topic 
Page 1 of 1
 
 
Reply with quote Download Post 
Post Sql Inyection In My Forum :( 
 
Hi people.
This time i have detected an sql inyection in my forum.
can you see the images.


This appear in my private msg inbox

captura_1207496878_185513  

This is the body of the msg

captura2

And this appear in the library...

captura3

Im checking the logs for more information.
This is not a help ask XD
it's informative to all the comunity...

I will give you more information soon...

EDIT: my forum version is 1.27 with all patches instaled...
sorry for the post in the incorrect place but im so confused


Greetz!

 



 
paramine-gxSend private messageVisit poster's website  
Back to topPage bottom
Icy Phoenix is an open source project, you can show your appreciation and support future development by donating to the project.

Support us
 
Reply with quote Download Post 
Post Re: Sql Inyection In My Forum :( 
 
Is this an injection into the knowledge base? I think the best thing is remove knowledge base scripts if you don't use it
 



 
moreteavicarSend private message  
Back to topPage bottom
Reply with quote Download Post 
Post Re: Sql Inyection In My Forum :( 
 
moreteavicar wrote: [View Post]
Is this an injection into the knowledge base? I think the best thing is remove knowledge base scripts if you don't use it
Good idea   , i have do it now.
so, i can´t find the log to that entry jojo
surely was an atack from any scripting kiddie

thank for the answer
 



 
paramine-gxSend private messageVisit poster's website  
Back to topPage bottom
Reply with quote Download Post 
Post Re: Sql Inyection In My Forum :( 
 
If I recall there were a number of possible injections into knowledge base, but I think they are patched - so possibly when they tried to do it, it triggered the private message, but they weren't actually able to insert the message in knowledge base?

Sometimes this sort of thing is actually done by a bot - the way to tell is look at your server's raw logs. Look for any tell-tale signs, like trying to access knowledgebase. If all you see is a couple of lines directly attempting to insert into the script, and not a load rows of text for the same IP, each one relating to a different part of your webpage (such as images, stylesheets and so on), then the webpage wasn't even loaded, it was just an attempt by a bot to insert via URL string. Often bot creators try and spoof browsers, its easy to create a c++ application that trawls the web and give false header info - indeed even mozilla can be tweaked to declare itself as IE - this used to be necessary a couple of years ago when a lot of site content was deliberately made MS-only (maybe not the developers themselves, but because they used MS web packages, often based on shoddy asp).

This is a guess, since I've never used/inspected knowledge base, but the attempt might not be detected by cracker tracker because it might be a legitimate query string normally used by the mod to send data, you couldn't put that query in the cracker tracker search pattern because it would stop legitimate users. If the data doesn't exist in your knowledge base, then that means its secure, and what we have now is a bug in the message management system, sending messages without checking that the data is actually in your database... just a guess mind you

Perhaps to rule it out, did you check your database and find anything in there?
 



 
moreteavicarSend private message  
Back to topPage bottom
Reply with quote Download Post 
Post Re: Sql Inyection In My Forum :( 
 
Understood, the unique trouble is that there is not any user with that name (hpruleb)
this means that ¿how may be a legitimate post request if there is not any known user?
im so nervius for this question.

For now i've quit the post.
But i put the info cause i think you must be informed...

Is not a critical fact but, must be explained...

Greetz and thanks for the explanation moreteavicar
 



 
paramine-gxSend private messageVisit poster's website  
Back to topPage bottom
Reply with quote Download Post 
Post Re: Sql Inyection In My Forum :( 
 
I don't think it is an injection... did you check your KB permissions?

Are you sure that guests cannot post there?
 




____________
Luca
SEARCH is the quickest way to get support.
Icy Phoenix ColorizeIt - CustomIcy - HON
 
Mighty GorgonSend private messageSend e-mail to userVisit poster's website  
Back to topPage bottom
Reply with quote Download Post 
Post Re: Sql Inyection In My Forum :( 
 
Mighty Gorgon wrote: [View Post]
I don't think it is an injection... did you check your KB permissions?

Are you sure that guests cannot post there?
I did check that and the guest cannot post on the kb.
like i said, there is no a user with that name, but the image appear like if where, so.

i think that is an old problem that have being happen on various forums...
so thanks again, and if this result an true sql injection is one point for me jejejeje

I have looking for posibles sql sintax in milw0rm and related sites but there is nothing of importance...
so thanks again, i hope this would be an falsa alarm
 



 
paramine-gxSend private messageVisit poster's website  
Back to topPage bottom
Reply with quote Download Post 
Post Re: Sql Inyection In My Forum :( 
 
Change permissions and there are problems.


 
 



 
grgaSend private messageVisit poster's website  
Back to topPage bottom
Reply with quote Download Post 
Post Re: Sql Inyection In My Forum :( 
 
grga wrote: [View Post]
Change permissions and there are problems.
icico1
icico
 

  are you the boy?  
But in my ACP the guest cannot post...

Well thanks, now i knoe what is the problem...

Thanks to all people that post in this topic...

Gretz to all!!!  
 



 
paramine-gxSend private messageVisit poster's website  
Back to topPage bottom
Reply with quote Download Post 
Post Re: Sql Inyection In My Forum :( 
 
I pray for nothing.
 
 



 
grgaSend private messageVisit poster's website  
Back to topPage bottom
Post new topic  Reply to topic  Page 1 of 1
 


Display posts from previous:    

HideWas this topic useful?

Link this topic
URL
BBCode
HTML




 
Permissions List
You cannot post new topics
You cannot reply to topics
You cannot edit your posts
You cannot delete your posts
You cannot vote in polls
You cannot attach files
You can download files
You cannot post calendar events


  

 

  cron