vBulletin Modifications

callhomes in products

Welcome to vBHackers.com! - vBHackers Updates:

Go Back   vBulletin Modifications > General vBulletin Section > General vBulletin Support

Reply
 
LinkBack Thread Tools
Old 05-15-2006, 12:02 PM   #1
Junior Member
Join Date: Nov 2005
vbcorolla is on a distinguished road

Default callhomes in products

the org just found that some authors are putting auto-install clickers in their products. I happen to know which mods these are in, but I'm wondering what your opinion on the topic is.

Clicking install may be harmless, but if that code runs.. so could something that sends your database details out over the net to xxx server :ninja:




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 05-15-2006, 01:49 PM   #2
vBulletin Guru
Arnoud's Avatar
Join Date: Nov 2004
Real Name: Arnoud Kuipers
Location: Europe, Flanders
Arnoud is on a distinguished road

Default

You mean in the install script? That trick has been around for ages, I remember using it aswell (not anymore though :p).

Sending data out isn't that simple though, the install script is simply redirecting the browser to the install link. Sending the database details would be a whole different thing ;).




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-15-2006, 01:53 PM   #3
Junior Member
Join Date: Nov 2005
vbcorolla is on a distinguished road

Default

yeah, but the code isn't so different. just add a $variable to the get request and change the domain name and it becomes rather dangerous.

glad I read the source on stuff (:o)




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-15-2006, 02:14 PM   #4
vBulletin Guru
Arnoud's Avatar
Join Date: Nov 2004
Real Name: Arnoud Kuipers
Location: Europe, Flanders
Arnoud is on a distinguished road

Default

Well, it's still not that easy. I'm pretty sure the DB password is either encrypted or unset when starting a script.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-15-2006, 02:23 PM   #5
Junior Member
Join Date: Nov 2005
vbcorolla is on a distinguished road

Default

hehe, maybe I'll need to try a proof of concept on my test board and see what happens

probably do that later today




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-15-2006, 02:25 PM   #6
vBulletin Guru
Arnoud's Avatar
Join Date: Nov 2004
Real Name: Arnoud Kuipers
Location: Europe, Flanders
Arnoud is on a distinguished road

Default

Alright, let me know.

Also, what good is the DB info? You're running their file, if it send the DB info it might aswell make the changes when its ran.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-15-2006, 07:53 PM   #7
Coder
Join Date: Apr 2004
Location: UK
ShavedApe is on a distinguished road

Default

I dont see it as a problem but do wonder about the security side of things.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-15-2006, 09:09 PM   #8
vb.org @dministrator
Join Date: Apr 2006
Paul M is on a distinguished road

Default

Quote:
Originally Posted by vbcorolla
the org just found that some authors are putting auto-install clickers in their products. I happen to know which mods these are in, but I'm wondering what your opinion on the topic is.
I know which mods they are in as well - since I wrote the code they are referring to.

BTW - they aren't actually calling 'home' either, as vb.org is not my home forum.

The whole thing is just unbelievable - I can only guess at the reasons for the massive fuss - calling the link as that code did is utterly harmless - a massive overhype over nothing. They seem bent on self destruction atm - and are doing a fine job about it.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-16-2006, 12:24 AM   #9
Junior Member
Join Date: Nov 2005
vbcorolla is on a distinguished road

Default

Quote:
Originally Posted by Deaths
Alright, let me know.

Also, what good is the DB info? You're running their file, if it send the DB info it might aswell make the changes when its ran.
well, after about 15 minutes of playing around with code I managed to do the following on my test site with an exploit in the .xml

steal database, get config.php contents, delete database, etc.

doesn't seem to be any limit, the product import is not run in any sort of secure environment




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 05-16-2006, 02:27 AM   #10
Coder
Code Monkey's Avatar
Join Date: May 2006
Code Monkey is on a distinguished road

Default

Is all that mountains from molehills crap going to infect this place as well? vBORG staff is again, OTT.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -3. The time now is 10:22 PM.


SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc. (Patent Pending)