Members: 16,996
Threads: 38,846
Posts: 159,391
Online: 23

Newest Member: Kl_broka@rediffmail.com


Odoo.tv - Outdoor Television


Sedo - Domains kaufen und verkaufen das Projekt mambers.com steht zum Verkauf Besucherstatistiken von mambers.com etracker® Web-Controlling statt Logfile-Analyse

Go Back   Mambers.com > Archive > Mambo 4.5 > Mambo 4.5 Security

 
 
LinkBack Thread Tools Display Modes
Old 21.02.2005, 22:19   #1 (permalink)
Junior Mamber
 
elta68's Avatar
 
Join Date: Sep 2004
Posts: 40
elta68 is on a distinguished road
Send a message via ICQ to elta68
Default SQL injection in the banner.php code?

I have since 4 days, SEF404 installed, that is why while looking at the 404 logs I found 2 unusual url try:

/Mambo//banners.php?op=click&bid=100%20UNION%20select%20pa ssword%20from%20mos_users%20where%201=1%20

It seems someone is trying to inject some sql...is it a known vulnerability, or only a fool?

beside that, a lot of pirate are using google to locate mambo site (I see the request and referer in webanalyser): trying to access my admin panel for example.

I also get some spams in com_akobook (it is a robots always trying to post some publicity for pills)

do someone notice the same in his site????
elta68 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Old 28.02.2005, 08:43   #2 (permalink)
Baby Mamber
 
Join Date: Nov 2004
Posts: 9
MrSleep is on a distinguished road
Default Re: SQL injection in the banner.php code?

You are under attacking! Dont worry, banners.php not vulnerability to exploit by sql inj. But take care your site. G'luck!
MrSleep is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 28.02.2005, 09:44   #3 (permalink)
Junior Mamber
 
elta68's Avatar
 
Join Date: Sep 2004
Posts: 40
elta68 is on a distinguished road
Send a message via ICQ to elta68
Default Re: SQL injection in the banner.php code?

what do security guy recommend? reduce surface of attack and unpublish as many modules and component as required? watch logs? Backup is done. cedric
elta68 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 28.02.2005, 10:38   #4 (permalink)
Baby Mamber
 
Join Date: Nov 2004
Posts: 9
MrSleep is on a distinguished road
Default Re: SQL injection in the banner.php code?

No more,
1. chmod configuration.php to 644.
2. Do not use database password same like ftp password.
3. Administrator directory requires a password to access via the web (by htaccess).
4. Do not chmod folder to 777 if no need (To prevent upload trojans, backdoor).
5. Upgrade your server and your mambo to lates version.
6. And backup your database daily.

G'luck,
MS
MrSleep is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Component/Module/Bot code checker initiative active6 Mambo 4.5 Security 5 06.02.2005 06:53
Lookup and where to put the SQL Code musicones Component Development 3 30.12.2004 09:06
Sql injection in Akogallery 2.5b In Mambo 4.5.1a MrSleep Mambo 4.5.1 Bugs 2 25.12.2004 06:20
Un idea e un dubbio sulle famose sql injection th3n0x Problematiche generali 7 09.11.2004 20:21
Why Html editors destroys the code? winini Mambo 4.5.1 Installation and Upgrades 2 22.10.2004 00:00


All times are GMT +2. The time now is 02:16.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0
A vBSkinworks Design
© Copyright 2004-2008 by Arthur Konze Webdesign.