![]() |
|
Security Bug? - Printable Version +- ZenphotoCMS Forum (https://forum.zenphoto.org) +-- Forum: Support (https://forum.zenphoto.org/forum-1.html) +--- Forum: General support (https://forum.zenphoto.org/forum-4.html) +--- Thread: Security Bug? (/thread-4697.html) Pages:
1
2
|
Security Bug? - PashaXIII - 16-02-2009 Hi Can you please look at here: http://www.miliwoman.com/ Press on links in LATEST UPDATED GALLERIES I guess someone hack Zen and add this to the albums paths: æ €ç€ç€ç€€ã¨€â¼€â¼€ç€€æ„€æœ€æ”€æ„€æ€ãˆ€â¸€æœ€æ¼€æ¼€æœ€æ°€æ”€çŒ€ç¤€æ¸€æ€æ¤€æŒ€æ„€ç€æ¤€æ¼€æ¸€â¸€æŒ€æ¼€æ´€â¼€ç€€æ„€æœ€æ”€æ„€æ€â¼€çŒ€æ €æ¼€çœ€å¼€æ„€æ€çŒ€â¸€æ¨€çŒ€ And such crappy URLs outputs through this function only: `` Other paths are fully OK And I cannot find this in Admin panel, I can remove it through database only Very strange Security Bug? - acrylian - 16-02-2009 Very strange indeed. How does the function itself in the album_image_plugin.php file look like? IF that has been altered by someonme you should be able to remove this by overwriting that file with the actual one. Also please read this: Security Bug? - PashaXIII - 16-02-2009 Thanks for quick respond I have no such file at all - album_image_plugin.php And yep I set 660 files/770 directories Security Bug? - acrylian - 16-02-2009 Sorry, the file is actually named image_album_statistics.php, thought you know/see what I mean, it's within I would also suggest you contact your host about that. It may be the case that the hack took place via your accout or the server in general and not via zenphoto. Please also read this recent thread: http://www.zenphoto.org/support/topic.php?id=4656 Security Bug? - PashaXIII - 16-02-2009 Checked It looks like someone added info directly into database
Unfortunately it's not a host, it is dedicated server :-) Security Bug? - PashaXIII - 16-02-2009 May it be some kind of sql-injection? or something similar? Security Bug? - PashaXIII - 16-02-2009 Screen from DB: http://pixhost.ws/avaxhome/b5/2e/000b2eb5.png And I can delete all this strange info through database only Security Bug? - sbillard - 16-02-2009 The link you posted above leads to an album which displays, so there must be a folder on your server with that name. This means that someone has hacked your filesystem. Security Bug? - PashaXIII - 16-02-2009
I'm sorry, but no, all folders in æ €ç€ç€ç€€ã¨€â¼€â¼€ç€€æ„€æœ€æ”€æ„€æ€ãˆ€â¸€æœ€æ¼€æ¼€æœ€æ°€æ”€çŒ€ç¤€æ¸€æ€æ¤€æŒ€æ„€ç€æ¤€æ¼€æ¸€â¸€æŒ€æ¼€æ´€â¼€ç€€æ„€æœ€æ”€æ„€æ€â¼€çŒ€æ €æ¼€çœ€å¼€æ„€æ€çŒ€â¸€æ¨€çŒ€ All directory structure not touched. Changes take place in DB only. I hope what it is my mistake and ZenPhoto has no security bugs Security Bug? - olihar - 16-02-2009 you where not playing around with UTF-16. I got some similar strange things when I did that the other day. Security Bug? - sbillard - 16-02-2009 Zenphoto is folder/file based. If there is no folder then it cannot find files from the folder and will show nothing. So, somehow that is being treated as a folder by your filesystem. Security Bug? - PashaXIII - 17-02-2009
I'm not play with UTF-16 or something similar, character encoding, in Admin panel, set as UTF-8
æ €ç€ç€ç€€ã¨€â¼€â¼€ç€€æ„€æœ€æ”€æ„€æ€ãˆ€â¸€æœ€æ¼€æ¼€æœ€æ°€æ”€çŒ€ç¤€æ¸€æ€æ¤€æŒ€æ„€ç€æ¤€æ¼€æ¸€â¸€æŒ€æ¼€æ´€â¼€ç€€æ„€æœ€æ”€æ„€æ€â¼€çŒ€æ €æ¼€çœ€å¼€æ„€æ€çŒ€â¸€æ¨€çŒ€ æ €ç€ç€ç€€ã¨€â¼€â¼€ç€€æ„€æœ€æ”€æ„€æ€ãˆ€â¸€æœ€æ¼€æ¼€æœ€æ°€æ”€çŒ€ç¤€æ¸€æ€æ¤€æŒ€æ„€ç€æ¤€æ¼€æ¸€â¸€æŒ€æ¼€æ´€â¼€ç€€æ„€æœ€æ”€æ„€æ€â¼€çŒ€æ €æ¼€çœ€å¼€æ„€æ€çŒ€â¸€æ¨€çŒ€/Denmark/Army There are no such Chinese folders at all. And this paths appear for Security Bug? - PashaXIII - 17-02-2009 Unfortunately this shit continue I was change all possible passwords, check files/directories permission etc. But it doesn't help Security Bug? - acrylian - 17-02-2009 Maybe the mysql-account has been hacked then? Is there anything strange in your server logs? I currently don't see that the function Security Bug? - PashaXIII - 17-02-2009
It is very doubtful. Mysql use only internal IP, especially it look strange after I was change all passwords. Someone found a way to add data in zp_albums table: http://pixhost.ws/avaxhome/b5/2e/000b2eb5.png and Security Bug? - acrylian - 17-02-2009 Well, we really need to find out the way this data gets into your database. I really doubt it is the printLatestUpdatedAlbums function the leak must be somewhere else. Security Bug? - PashaXIII - 17-02-2009
Thank you, may be what this can be affected on many installed ZenPhoto
Yep, it just Read and Output data. Attack continue, here is part of dump with new "hack" records: http://www.miliwoman.com/dump.sql Too many work for human, I guess it some "hacker script" do this. Maybe it help. P.S. Security Bug? - PashaXIII - 18-02-2009 Yes it's already fixed, but anyway here it is: http://www.xakep.ru/post/41761/Zenphoto-SQL-Injection-Exploit.txt Look like someone found a similar vulnerability :-( Security Bug? - PashaXIII - 18-02-2009 Found another strange regularity, as always as I open similar URL: In Security Bug? - PashaXIII - 18-02-2009 Look like Easter egg )) if someone will open this link in Yep, I was right, this is Easter egg or Links works pretty fine. It ever works with ZenPage |