Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 11-10-2007, 04:41 PM   #1
ServerGenius
Confirmed User
 
Join Date: Feb 2002
Location: Amsterdam
Posts: 9,377
:stop SERIOUS SECURITY HOLE: Anyone who has scripts that use access.log piping MUST READ

Hi,

If you use scripts on your server that use httpd log file piping CONTACT me
inmediately so I can explain you how to prevent DISSASTERS

hhhhhhmmm OK Genius but how do I know if I do?
Check your apache virtual host configs and look if there's anything that looks
like this:

CustomLog "|/usr/bin/php

or

CustomLog "|/usr/bin/perl

If you have this I suggest you contact me asap......this is MAJOR!

This is no joke and neither some kind of creative SPAM
__________________
| http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho |
ServerGenius is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2007, 04:46 PM   #2
Damian_Maxcash
So Fucking Banned
 
Join Date: Oct 2002
Location: MaxCash.com
Posts: 12,745
I dont know if I do or not?

What would be the common scripts?
Damian_Maxcash is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2007, 05:03 PM   #3
ServerGenius
Confirmed User
 
Join Date: Feb 2002
Location: Amsterdam
Posts: 9,377
you can find it in your httpd.conf file and/or apache config files that you use which contain the virtualhost configs

for example
/path/to/apache/config/vhost.conf or vhost.include

on debian this would be /etc/apache2/sites-availabe/filename

or servers that use control panels kinda of software it's usually in

/usr/home/username/conf or /usr/home/username/public_html/config

Example of scripts that use logfile piping are pennywize and/or other scripts
that are supposed to prevent login/password theft/sharing/abuse

But also other monitoring scripts that read data from the webserver logs
by method of logfile piping are vulnerable.....

This concerns both php and perl cgi scripts and there's no patch to prevent
this as of now.....

__________________
| http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho |
ServerGenius is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2007, 05:15 PM   #4
GrouchyAdmin
Now choke yourself!
 
GrouchyAdmin's Avatar
 
Industry Role:
Join Date: Apr 2006
Posts: 12,085
Piping into any preprocessor that allows redirection is pretty bad. Piping directly into a language based preprocessor is much worse.
__________________

Last edited by GrouchyAdmin; 11-10-2007 at 05:17 PM.. Reason: Typo city.
GrouchyAdmin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2007, 05:34 PM   #5
ServerGenius
Confirmed User
 
Join Date: Feb 2002
Location: Amsterdam
Posts: 9,377
I'm about to head out and get some sleep it's 1:30am on this side of the planet.
please keep this thread on page 1 and anyone who contacts me, leave a message on ICQ and I'll get back to you asap....which will be in 10 hours or so
from now......if you leave your contact info and a message I'll get back to every
single one of you.......

thanks and make sure to check if you could be affected by this problem.
I won't publish proof of concept code for this exploit untill there's a good
solution for everybody affected to be used.....and enough time todo so ;-)

When there's a patch/solution I'll reveal proof of concept code to anyone
who's interested......;-)
__________________
| http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho |
ServerGenius is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2007, 05:47 PM   #6
GrouchyAdmin
Now choke yourself!
 
GrouchyAdmin's Avatar
 
Industry Role:
Join Date: Apr 2006
Posts: 12,085
Patch & Solution: Don't be dumb.

If you have any scripts which actually pipe directly to PHP/Perl, a much better solution would be to utilize apache's native rotatelogs and a daemon which reloads when truncated (rolled over), which feeds into the script, external of the Apache process, which runs as a secured/unpriviledged uid.

If you needed simpler than a daemon, this could even down to as simple as 'tail -f'..
__________________
GrouchyAdmin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2007, 05:51 PM   #7
Enemator
Confirmed User
 
Join Date: Mar 2007
Posts: 1,252
__________________
I live in your nightmares. I make you dream you're getting bumfucked by a razor blade only to wake up and find I gave your wife an enema and tube-fed you her shit.
Enemator is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2007, 09:37 PM   #8
ServerGenius
Confirmed User
 
Join Date: Feb 2002
Location: Amsterdam
Posts: 9,377
bumperdirooh
__________________
| http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho |
ServerGenius is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.