Web Images Videos Maps News Shopping Gmail more »
Recently Visited Groups | Help | Sign in
Google Groups Home
Sql injection admin hash disclosure exploit for wp-trackback.php
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  9 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
mar...@wiso.cz  
View profile  
 More options Jan 10 2007, 6:01 am
From: mar...@wiso.cz
Date: Wed, 10 Jan 2007 12:01:46 +0100 (CET)
Local: Wed, Jan 10 2007 6:01 am
Subject: [wp-hackers] Sql injection admin hash disclosure exploit for wp-trackback.php
Hello all, I found that there is a new exploit for wp-trackback.php script
using Sql Injection. Details can be found here -
http://milw0rm.com/exploits/3109

Does anyone test it? I have to say that for some of my installations of WP
it works and for other not. I did some quick fix for this specific
exploit, but it is not ideal...

Kind regards,

Martin Wiso
==================
WWW: www.wiso.cz

_______________________________________________
wp-hackers mailing list
wp-hack...@lists.automattic.com
http://lists.automattic.com/mailman/listinfo/wp-hackers


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Computer Guru  
View profile  
 More options Jan 10 2007, 6:17 am
From: Computer Guru <computerg...@neosmart.net>
Date: Wed, 10 Jan 2007 13:17:13 +0200
Local: Wed, Jan 10 2007 6:17 am
Subject: RE: [wp-hackers] Sql injection admin hash disclosure exploit for wp-trackback.php

>From the sheet:

/*********************************************************************\
Wordpress <= 2.0.6 wp-trackback.php Zend_Hash_Del_Key_Or_Index /
/ sql injection admin hash disclosure exploit
(needs register_globals=on, 4 <= PHP < 4.4.3,< 5.1.4)
by rgod
dork: "is proudly powered by WordPress"
mail: retrog at alice dot it
site: http://retrogod.altervista.org
/*********************************************************************\

Only affects less than 2.0.6, which was a security update.

Computer Guru
NeoSmart Technologies
http://neosmart.net/blog/

_______________________________________________
wp-hackers mailing list
wp-hack...@lists.automattic.com
http://lists.automattic.com/mailman/listinfo/wp-hackers

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Rob  
View profile  
 More options Jan 10 2007, 6:25 am
From: Rob <r...@robm.me.uk>
Date: Wed, 10 Jan 2007 11:25:02 +0000
Local: Wed, Jan 10 2007 6:25 am
Subject: Re: [wp-hackers] Sql injection admin hash disclosure exploit for wp-trackback.php
It says less than or equal to 2.0.6...

On 10/01/07, Computer Guru <computerg...@neosmart.net> wrote:

--
Rob Miller
http://robm.me.uk/
_______________________________________________
wp-hackers mailing list
wp-hack...@lists.automattic.com
http://lists.automattic.com/mailman/listinfo/wp-hackers

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Computer Guru  
View profile  
 More options Jan 10 2007, 7:06 am
From: Computer Guru <computerg...@neosmart.net>
Date: Wed, 10 Jan 2007 14:06:13 +0200
Local: Wed, Jan 10 2007 7:06 am
Subject: RE: [wp-hackers] Sql injection admin hash disclosure exploit for wp-trackback.php

> It says less than or equal to 2.0.6...

> On 10/01/07, Computer Guru <computerg...@neosmart.net> wrote:
> > Only affects less than 2.0.6, which was a security update.

Ouch - I can't believe I misread that - thanks for pointing that out to
me...

I created a blog on a server that matches the requirements outlined in the
exploit - it didn't work however.

-CG

_______________________________________________
wp-hackers mailing list
wp-hack...@lists.automattic.com
http://lists.automattic.com/mailman/listinfo/wp-hackers


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
mar...@wiso.cz  
View profile  
 More options Jan 10 2007, 7:09 am
From: mar...@wiso.cz
Date: Wed, 10 Jan 2007 13:09:34 +0100 (CET)
Local: Wed, Jan 10 2007 7:09 am
Subject: RE: [wp-hackers] Sql injection admin hash disclosure exploit for wp-trackback.php
I did some more test and it really works only on versions less than 2.0.6
for me...

Martin Wiso

_______________________________________________
wp-hackers mailing list
wp-hack...@lists.automattic.com
http://lists.automattic.com/mailman/listinfo/wp-hackers

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mark Jaquith  
View profile  
 More options Jan 11 2007, 3:04 am
From: Mark Jaquith <mark.wordpr...@txfx.net>
Date: Thu, 11 Jan 2007 03:04:28 -0500
Local: Thurs, Jan 11 2007 3:04 am
Subject: Re: [wp-hackers] Sql injection admin hash disclosure exploit for wp-trackback.php
On Jan 10, 2007, at 6:01 AM, mar...@wiso.cz wrote:

> Does anyone test it? I have to say that for some of my  
> installations of WP
> it works and for other not. I did some quick fix for this specific
> exploit, but it is not ideal...

It depends on your PHP version and you need register_globals on.  It  
has been fixed in WordPress 2.0.7 RC1.

Info here:

http://comox.textdrive.com/pipermail/wp-testers/2007-January/003644.html

--
Mark Jaquith
http://markjaquith.com/

Covered Web Services
http://covered.be/

_______________________________________________
wp-hackers mailing list
wp-hack...@lists.automattic.com
http://lists.automattic.com/mailman/listinfo/wp-hackers


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Roland Häder  
View profile  
 More options Jan 11 2007, 3:13 am
From: "Roland Häder" <r.hae...@will-hier-weg.de>
Date: Thu, 11 Jan 2007 09:13:37 +0100
Local: Thurs, Jan 11 2007 3:13 am
Subject: Re: [wp-hackers] Sql injection admin hash disclosure exploit for wp-trackback.php
I suppose "register_globals on" *is* the security hole? ;) If your application requires register_globals turned on, then please rewrite by your own (if allowed by the included license) or search for an alternative. "register_globals on" is bad (in combination with other PHP options a nightmare).

Roland

> It depends on your PHP version and you need register_globals on.  It  
> has been fixed in WordPress 2.0.7 RC1.

> Info here:

> http://comox.textdrive.com/pipermail/wp-testers/2007-January/003644.html

--
Der GMX SmartSurfer hilft bis zu 70% Ihrer Onlinekosten zu sparen!
Ideal für Modem und ISDN: http://www.gmx.net/de/go/smartsurfer
_______________________________________________
wp-hackers mailing list
wp-hack...@lists.automattic.com
http://lists.automattic.com/mailman/listinfo/wp-hackers

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mark Jaquith  
View profile  
 More options Jan 11 2007, 11:57 am
From: Mark Jaquith <mark.wordpr...@txfx.net>
Date: Thu, 11 Jan 2007 11:57:19 -0500
Local: Thurs, Jan 11 2007 11:57 am
Subject: Re: [wp-hackers] Sql injection admin hash disclosure exploit for wp-trackback.php
On Jan 11, 2007, at 3:13 AM, Roland Häder wrote:

> I suppose "register_globals on" *is* the security hole? ;) If your  
> application requires register_globals turned on, then please  
> rewrite by your own (if allowed by the included license) or search  
> for an alternative. "register_globals on" is bad (in combination  
> with other PHP options a nightmare).

WordPress has never required register_gloabls to be turned on.  We  
hate register globals.  :-)  We have code in WordPress that  
unregisters global variables.  The bug was a PHP bug that makes use  
of unset() to de-register variables unsafe.  I found a workaround.

--
Mark Jaquith
http://markjaquith.com/

Covered Web Services
http://covered.be/

_______________________________________________
wp-hackers mailing list
wp-hack...@lists.automattic.com
http://lists.automattic.com/mailman/listinfo/wp-hackers


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mark Jaquith  
View profile  
 More options Jan 15 2007, 12:15 pm
From: Mark Jaquith <mark.wordpr...@txfx.net>
Date: Mon, 15 Jan 2007 12:15:57 -0500
Local: Mon, Jan 15 2007 12:15 pm
Subject: Re: [wp-hackers] Sql injection admin hash disclosure exploit for wp-trackback.php
On Jan 10, 2007, at 6:25 AM, Rob wrote:

> It says less than or equal to 2.0.6...

Indeeed.  A fix for this has been put into 2.0.7 which will be out  
*very* soon (both RCs have the fix too).

--
Mark Jaquith
http://markjaquith.com/

Covered Web Services
http://covered.be/

_______________________________________________
wp-hackers mailing list
wp-hack...@lists.automattic.com
http://lists.automattic.com/mailman/listinfo/wp-hackers


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google