Simple linkex exploit. BEWARE.

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • fluffygrrl
    So Fucking Banned
    • May 2006
    • 2187

    #1

    Simple linkex exploit. BEWARE.

    Find someone using linkex, note down his url.

    Make a simple webpage, containing just one link to his url.

    Open his linkex, enter the url of the webpage you made, and for an anchor, try
    Code:
    <?php echo 'hi'; ?>
    Check out his links, especially if he auto-adds stuff.

    You can take it from there, I guess, I'm not going to publish working exploits. The linkex people need to fix their script, I would have provided a fix but not for such bullshit code without indentation.

    Right now, running linkex = running a rootkit. Beware.
  • Basic_man
    Programming King Pin
    • Oct 2003
    • 27360

    #2
    Why posting it in public? Dumpass.. Email the owner!
    UUGallery Builder - automated photo/video gallery plugin for Wordpress!
    Stop looking! Checkout Naked Hosting, online since 1999 !

    Comment

    • fluffygrrl
      So Fucking Banned
      • May 2006
      • 2187

      #3
      I would have, had he had the courtesy of releasing his source in some sort of readable format.

      Comment

      • Intricate
        Confirmed User
        • Jun 2007
        • 133

        #4
        Are you kidding me, why would you post this here where there are so many known spammers/scammers around?

        I hope a mod removes this...
        chesterbanksphp [.at.] gmail.com
        icq: 350 656 495

        Comment

        • 4Pics
          Confirmed User
          • Dec 2001
          • 7952

          #5
          why not post the fix?

          It isn't the people who run the scripts fault for the exploit.

          jeez

          Comment

          • geeknik
            l337 h4x0r!#%
            • Feb 2005
            • 8364

            #6
            Why oh why does GFY always attract the biggest morons?
            hacker 4 hire.

            Comment

            • ridikuloz
              Confirmed User
              • Jun 2005
              • 2080

              #7
              it's hax0ring time!
              Each persons' level of stupidity makes us different.

              Comment

              • teg0
                Confirmed User
                • Jan 2006
                • 4204

                #8
                The normal order of events is that you inform the developer. Give them at least a month to fix it, and if they don't then you can post the a notice bout the exploit. Public disclosure gets the developers off their ass and makes everyone away to either secure their shit or remove it.

                If you're running linkex right now just log in and go to settings and disable the public form for now.

                Comment

                • fluffygrrl
                  So Fucking Banned
                  • May 2006
                  • 2187

                  #9
                  Originally posted by teg0
                  The normal order of events is that you inform the developer. Give them at least a month to fix it, and if they don't then you can post the a notice bout the exploit. Public disclosure gets the developers off their ass and makes everyone away to either secure their shit or remove it.

                  If you're running linkex right now just log in and go to settings and disable the public form for now.
                  What he said. Get snapping.

                  Comment

                  • teg0
                    Confirmed User
                    • Jan 2006
                    • 4204

                    #10
                    lol after reading my post i realized that I needed a coffee.

                    Comment

                    • Lycanthrope
                      Confirmed User
                      • Jan 2004
                      • 4517

                      #11
                      I notified the developer and sent him a link to this thread (he is not online at the moment).

                      I did not try what you posted, but I'll take your word on it. For now, everyone should just set their permissions on /linkex/index.php to 0.

                      Comment

                      • fluffygrrl
                        So Fucking Banned
                        • May 2006
                        • 2187

                        #12
                        You can easily try it on your own site. echo 'hi'; as posted is obviously safe.

                        Comment

                        • Vick!
                          Confirmed User
                          • Nov 2005
                          • 6882

                          #13
                          wtf? I am not impressed with your programming expertise. You could have emailed the owner instead of posting details here. If you still wanted to show how cool you are at catching exploits, just tell that you found a bug and want the owner to contact you for details.
                          Affordable Quality Web Hosting

                          Comment

                          • teg0
                            Confirmed User
                            • Jan 2006
                            • 4204

                            #14
                            someone could just easily do a php header redirect, if their url was short enough. Definitely a problem that needs to be fixed.
                            Last edited by teg0; 08-26-2007, 10:32 AM.

                            Comment

                            • SmokeyTheBear
                              ►SouthOfHeaven
                              • Jun 2004
                              • 28609

                              #15
                              thanks for the heads up..

                              i'm on the fence about people reporting exploits this way ..

                              i do believe its nice to inform the script owners first but i have to disagree with others about not reporting it on gfy..


                              gfy is often the quickest way to solve these kinds of problems..


                              exploits such as this are often slow to be fixed ( or ignored ) by the owners if left entirely up to them, a push is helpfull.
                              hatisblack at yahoo.com

                              Comment

                              • fluffygrrl
                                So Fucking Banned
                                • May 2006
                                • 2187

                                #16
                                Again. I would have emailed the guy a fix. EXCEPT, have you looked at his code ? There is not a single line feed or tab in there. I mean, okay, so he doesn't comment his code as he should on anything publicly released. Fine. But take out the line feeds ? That in my book is douchebaggery.

                                Comment

                                • cykoe6
                                  Confirmed User
                                  • Apr 2005
                                  • 4499

                                  #17
                                  Originally posted by teg0
                                  If you're running linkex right now just log in and go to settings and disable the public form for now.
                                  I just did that for all my sites. Does that mean they should be safe now or do I need to do something else?
                                  бабки, шлюхи, сила

                                  Comment

                                  • fluffygrrl
                                    So Fucking Banned
                                    • May 2006
                                    • 2187

                                    #18
                                    If you've disabled the public form (ie people can't type in anchors that you include anymore) you should be safe.

                                    May be worth your time to go through the 1001 or whatever the file you include is called and make sure there's nothing but url's and plain text in there. anything between <? and ?> is evil. anything reading "text/javascript" is also evil.

                                    Comment

                                    • crockett
                                      in a van by the river
                                      • May 2003
                                      • 76818

                                      #19
                                      Originally posted by Basic_man
                                      Why posting it in public? Dumpass.. Email the owner!
                                      Why do most people publish the exploits they find? Why because it allows users to know it there and also forces the authors to fix their shit.

                                      Making exploits public knowledge is a common practice..
                                      In November, you can vote for America's next president or its first dictator.

                                      Comment

                                      • hungry hungry hippy
                                        Confirmed User
                                        • Mar 2007
                                        • 249

                                        #20
                                        so kind of you to post this as there are 18,700 sites using it ....

                                        it's common to go public with exploits, AFTER you have notified the company and given them time to fix it.

                                        Comment

                                        • polle54
                                          Confirmed User
                                          • Jul 2004
                                          • 4626

                                          #21
                                          Narcissistic jerk

                                          glad no one is giving you credit
                                          ICQ# 143561781

                                          Comment

                                          • Libertine
                                            sex dwarf
                                            • May 2002
                                            • 17860

                                            #22
                                            Originally posted by SmokeyTheBear
                                            thanks for the heads up..

                                            i'm on the fence about people reporting exploits this way ..

                                            i do believe its nice to inform the script owners first but i have to disagree with others about not reporting it on gfy..


                                            gfy is often the quickest way to solve these kinds of problems..


                                            exploits such as this are often slow to be fixed ( or ignored ) by the owners if left entirely up to them, a push is helpfull.
                                            I'm on the fence, too.

                                            On one side, GFY is quicker than emailing them, plus it probably reaches more users than an upgrade of their script would (hell, I'm pretty sure that months from now, most users will still use the exploitable version).

                                            On the other side, this ensures that within a week, hundreds if not thousands of sites will be exploited.

                                            Then, on yet another side... anyone who uses that crappy script kinda deserves whatever happens. Linkex is a complete piece of shit, and always has been.
                                            /(bb|[^b]{2})/

                                            Comment

                                            • ZCurve
                                              Confirmed User
                                              • Jul 2007
                                              • 113

                                              #23
                                              I am a newbie and I am not a programmer. So could you please explian to me in simple english what does the exploite do...how does it harm/hurt my site?
                                              Care to exchange hard links? email me: webmaster at teensweek dot com

                                              Comment

                                              • polle54
                                                Confirmed User
                                                • Jul 2004
                                                • 4626

                                                #24
                                                Originally posted by polle54
                                                Narcissistic jerk

                                                glad no one is giving you credit
                                                It is good to know that there is a exploit but you write down how to use it..... it's really not nice here on gfy.
                                                ICQ# 143561781

                                                Comment

                                                • fluffygrrl
                                                  So Fucking Banned
                                                  • May 2006
                                                  • 2187

                                                  #25
                                                  Originally posted by polle54
                                                  Narcissistic jerk

                                                  glad no one is giving you credit
                                                  Listen blockhead. You need to comprehend a few points.

                                                  1. I don't owe you, or any dude running some script, or any dude putting up scripts for download, jack shit. The day you, or those other dudes have me on their payroll, you can raise this point again. Till then, chuck it.

                                                  1.1. I might, might mind you, out of the kindness of my heart, and because I'm such a nice fellow, given the author of the shoddy script a fix, provided he wasn't the sort of douchebag that deliberately makes his "code" hard to read. Call this a lesson in the theory of "karma's a bitch", maybe next time he releases code, he follows standards.

                                                  2. Responsibility for computer code at all times remains with the USER of such code. If you install and run some script you haven't completely read and understood, heck. Your bubblings to the contrary are really akin to the idiots wanting me to keep their children off the "dangerous internet". The internet is for grown-ups. Grown-ups are those people who understand where responsibility lies. Letting children, and you, run amok on the internet is fine, as far as I'm concerned, but their safety is not my problem.

                                                  3. Information belongs out in the open. That Bush, Cheney, and you think it's best to try and restrict the flow of information is exactly your problem, much like the belief in a flat earth and an omnipotent benevolent god is the believer's problem. If some women get butchered in China or if some shitty script has a hole in it, the public has a right to know, and you don't have a right to have an oppinon on the matter.

                                                  Bloody hell.

                                                  Comment

                                                  • woj
                                                    <&(©¿©)&>
                                                    • Jul 2002
                                                    • 47880

                                                    #26
                                                    sucks to be running linkex now, heh... I bet ya at least few blackhatters from here are exploiting it hard now...
                                                    Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
                                                    Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
                                                    Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager

                                                    Comment

                                                    • ZCurve
                                                      Confirmed User
                                                      • Jul 2007
                                                      • 113

                                                      #27
                                                      Originally posted by fluffygrrl
                                                      Listen blockhead. You need to comprehend a few points.

                                                      3. Information belongs out in the open. That Bush, Cheney, and you think it's best to try and restrict the flow of information is exactly your problem, much like the belief in a flat earth and an omnipotent benevolent god is the believer's problem. If some women get butchered in China or if some shitty script has a hole in it, the public has a right to know, and you don't have a right to have an oppinon on the matter.

                                                      Bloody hell.
                                                      I like fluffygrrl
                                                      Care to exchange hard links? email me: webmaster at teensweek dot com

                                                      Comment

                                                      • greg80
                                                        Confirmed User
                                                        • May 2007
                                                        • 1644

                                                        #28
                                                        deamn. How low can you be to steal traffic like that?
                                                        Say no to GoDaddy and high renewal prices! Go with NameSilo - FREE private whois for life, $8.99 regstrations and renewals. Free redirects, emails, great control panel and more! NameSilo rocks!

                                                        Comment

                                                        • cykoe6
                                                          Confirmed User
                                                          • Apr 2005
                                                          • 4499

                                                          #29
                                                          So the result of the exploit is that someone could redirect your links to their own sites..... or is it something worse than that?
                                                          бабки, шлюхи, сила

                                                          Comment

                                                          • u-Bob
                                                            there's no $$$ in porn
                                                            • Jul 2005
                                                            • 33063

                                                            #30
                                                            Originally posted by cykoe6
                                                            So the result of the exploit is that someone could redirect your links to their own sites..... or is it something worse than that?
                                                            yep... running arbitrary code on your box

                                                            Comment

                                                            • Cum&Spam
                                                              Confirmed User
                                                              • Mar 2007
                                                              • 913

                                                              #31
                                                              Whoever does that in my blogs will not gonna work...
                                                              because i check links manually in their sites every now and then hahahahahahah
                                                              Email: ktm525rula at hotmail dot com

                                                              Comment

                                                              • StarkReality
                                                                Confirmed User
                                                                • May 2004
                                                                • 4444

                                                                #32
                                                                Originally posted by ZCurve
                                                                I am a newbie and I am not a programmer. So could you please explian to me in simple english what does the exploite do...how does it harm/hurt my site?
                                                                It simply means that any code/script can be inserted via the exploit with as many characters in total as the anchor text field allows, and inserting a redirect is certainly one of the less evil things I could imagine.

                                                                As for making exploits public: It's often the only way to get things fixed fast, a little public pressure works wonders. It may not be nice, but it's effective.

                                                                Comment

                                                                • bl4h
                                                                  Confirmed User
                                                                  • Jul 2006
                                                                  • 1282

                                                                  #33
                                                                  This is dumb. You should have first given the author the chance to warn people and send out a patch. This isn't about teh script author, you fucked over the webmaster. Nice

                                                                  Comment

                                                                  • v0id
                                                                    Confirmed User
                                                                    • Sep 2006
                                                                    • 43

                                                                    #34
                                                                    Hi guys,
                                                                    I have just released a fix for this exploit.

                                                                    linkex.dk/forums/t1244-exploit-in-linkex-please-be-aware.html

                                                                    - v0id

                                                                    Comment

                                                                    • fluffygrrl
                                                                      So Fucking Banned
                                                                      • May 2006
                                                                      • 2187

                                                                      #35
                                                                      Nice.

                                                                      Did you stick the spacing back in too ?

                                                                      Comment

                                                                      • cykoe6
                                                                        Confirmed User
                                                                        • Apr 2005
                                                                        • 4499

                                                                        #36
                                                                        Originally posted by LinkEX
                                                                        Hi guys,
                                                                        I have just released a fix for this exploit.

                                                                        linkex.dk/forums/t1244-exploit-in-linkex-please-be-aware.html

                                                                        - v0id
                                                                        Thanks for fixing that so quickly.
                                                                        бабки, шлюхи, сила

                                                                        Comment

                                                                        • fluffygrrl
                                                                          So Fucking Banned
                                                                          • May 2006
                                                                          • 2187

                                                                          #37
                                                                          neeevermind.
                                                                          Last edited by fluffygrrl; 08-27-2007, 02:53 AM.

                                                                          Comment

                                                                          • fluffygrrl
                                                                            So Fucking Banned
                                                                            • May 2006
                                                                            • 2187

                                                                            #38
                                                                            Actually. The "fix" doesn't fix the problem, from what I can see. Feel free to give it a try yourself, as explained in the original post.

                                                                            Comment

                                                                            • d-null
                                                                              . . .
                                                                              • Apr 2007
                                                                              • 13724

                                                                              #39
                                                                              most interesting

                                                                              __________________

                                                                              Looking for a custom TUBE SCRIPT that supports massive traffic, load balancing, billing support, and h264 encoding? Hit up Konrad!
                                                                              Looking for designs for your websites or custom tubesite design? Hit up Zuzana Designs
                                                                              Check out the #1 WordPress SEO Plugin: CyberSEO Suite

                                                                              Comment

                                                                              • raven1083
                                                                                Confirmed User
                                                                                • Jul 2007
                                                                                • 7687

                                                                                #40
                                                                                thanks for the warning
                                                                                Femdom Stories | Bound BBW Blog and Videos |Bondage Sex Videos and Pictures

                                                                                Hardcore Japanese Bondage | BDSM Movies And Galleries Mistress Cuckold CBT

                                                                                Comment

                                                                                • v0id
                                                                                  Confirmed User
                                                                                  • Sep 2006
                                                                                  • 43

                                                                                  #41
                                                                                  Originally posted by fluffygrrl
                                                                                  Actually. The "fix" doesn't fix the problem, from what I can see. Feel free to give it a try yourself, as explained in the original post.
                                                                                  Not sure what you mean. Can you elaborate?

                                                                                  - v0id

                                                                                  Comment

                                                                                  • v0id
                                                                                    Confirmed User
                                                                                    • Sep 2006
                                                                                    • 43

                                                                                    #42
                                                                                    Originally posted by fluffygrrl
                                                                                    Actually. The "fix" doesn't fix the problem, from what I can see. Feel free to give it a try yourself, as explained in the original post.
                                                                                    Not sure what you mean. Can you elaborate?
                                                                                    demo.linkex.dk/linkex/data/output/1001

                                                                                    - v0id

                                                                                    Comment

                                                                                    • fluffygrrl
                                                                                      So Fucking Banned
                                                                                      • May 2006
                                                                                      • 2187

                                                                                      #43
                                                                                      Code:
                                                                                      <!-- Output generated by LinkEX (+http://linkex.dk/) -->
                                                                                      <a href="http://lolcunts.org" title="&lt;?php echo'hi'; ?&gt;">&lt;?php echo'hi'; ?&gt;</a><br><br><a href="http://www.teensexvidz.com/" title="Teen Sex Videos">Teen Sex Videos</a><br><br>
                                                                                      does that help ?

                                                                                      Comment

                                                                                      • cykoe6
                                                                                        Confirmed User
                                                                                        • Apr 2005
                                                                                        • 4499

                                                                                        #44
                                                                                        So has this issue been solved or not.....
                                                                                        бабки, шлюхи, сила

                                                                                        Comment

                                                                                        • GirlsOnYou
                                                                                          Confirmed User
                                                                                          • Oct 2006
                                                                                          • 618

                                                                                          #45
                                                                                          Originally posted by fluffygrrl
                                                                                          Code:
                                                                                          <!-- Output generated by LinkEX (+http://linkex.dk/) -->
                                                                                          <a href="http://lolcunts.org" title="&lt;?php echo'hi'; ?&gt;">&lt;?php echo'hi'; ?&gt;</a><br><br><a href="http://www.teensexvidz.com/" title="Teen Sex Videos">Teen Sex Videos</a><br><br>
                                                                                          does that help ?
                                                                                          You do realize that &lt;?php does nothing whereas <?php does, right?
                                                                                          So that code you just posted cannot be harmful because < is replaced with &lt;.

                                                                                          You might know this and I might have missed the point of your post but I told this just in case.
                                                                                          * Selling my adult sites.
                                                                                          Email: furaldbullon48aol9com - Replace 48 with @ and 9 with .

                                                                                          Comment

                                                                                          • potter
                                                                                            Confirmed User
                                                                                            • Dec 2004
                                                                                            • 6559

                                                                                            #46
                                                                                            Originally posted by fluffygrrl
                                                                                            Listen blockhead. You need to comprehend a few points.

                                                                                            1. I don't owe you, or any dude running some script, or any dude putting up scripts for download, jack shit. The day you, or those other dudes have me on their payroll, you can raise this point again. Till then, chuck it.

                                                                                            1.1. I might, might mind you, out of the kindness of my heart, and because I'm such a nice fellow, given the author of the shoddy script a fix, provided he wasn't the sort of douchebag that deliberately makes his "code" hard to read. Call this a lesson in the theory of "karma's a bitch", maybe next time he releases code, he follows standards.

                                                                                            2. Responsibility for computer code at all times remains with the USER of such code. If you install and run some script you haven't completely read and understood, heck. Your bubblings to the contrary are really akin to the idiots wanting me to keep their children off the "dangerous internet". The internet is for grown-ups. Grown-ups are those people who understand where responsibility lies. Letting children, and you, run amok on the internet is fine, as far as I'm concerned, but their safety is not my problem.

                                                                                            3. Information belongs out in the open. That Bush, Cheney, and you think it's best to try and restrict the flow of information is exactly your problem, much like the belief in a flat earth and an omnipotent benevolent god is the believer's problem. If some women get butchered in China or if some shitty script has a hole in it, the public has a right to know, and you don't have a right to have an oppinon on the matter.

                                                                                            Bloody hell.
                                                                                            That was awesome...

                                                                                            Comment

                                                                                            • fluffygrrl
                                                                                              So Fucking Banned
                                                                                              • May 2006
                                                                                              • 2187

                                                                                              #47
                                                                                              Doh. I was including the wrong file.

                                                                                              So yes, linkex.20070827.tar.gz fixes the hole.

                                                                                              Comment

                                                                                              • v0id
                                                                                                Confirmed User
                                                                                                • Sep 2006
                                                                                                • 43

                                                                                                #48
                                                                                                so, now everyone have to update their linex!!

                                                                                                Comment

                                                                                                • KrisKross
                                                                                                  Confirmed User
                                                                                                  • Jan 2006
                                                                                                  • 5025

                                                                                                  #49
                                                                                                  Originally posted by LinkEX
                                                                                                  so, now everyone have to update their linex!!
                                                                                                  No apologies for shitty code?

                                                                                                  Comment

                                                                                                  • teg0
                                                                                                    Confirmed User
                                                                                                    • Jan 2006
                                                                                                    • 4204

                                                                                                    #50
                                                                                                    Originally posted by KrisKross
                                                                                                    No apologies for shitty code?
                                                                                                    Windows = shitty code

                                                                                                    Comment

                                                                                                    Working...