★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/hackscracks_article-5776.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Hacks/Cracks 9/25/2002 18:32

PHP-Nuke SQL Injection Vulnerability Reported

By Pedro Inacio / Bugtraq
Posted By: Nick DeClario
9/25/2002

All PHP-Nuke versions, including the just released 6.0, are vulnerable to a very simple SQL injection that may lead to a basic DoS attack. When the script is stopped, the server will take a few minutes to recover from the load and become acessible again.
 Date: 25 Sep 2002 17:25:46 -0000
 From: Pedro Inacio 
 To: bugtraq@securityfocus.com
 Subject: PHP-Nuke x.x SQL Injection
 
 Hello,
 
 All PHP-Nuke versions, including the just released 6.0, are vulnerable to a
 very simple SQL injection that may lead to a basic DoS attack.
 
 For instance, if you create a short script, to send a few requests, (I have
 tested with just 6) similar to this:
 
 http://www.nukesite.com/modules.php?name=News&file=article&sid=1234%20or%
 201=1
 
 after a real short time the load of the machine is so high that it will
 become inacessible.
 
 When the script is stopped, the server will take a few minutes to recover
 from the load and become acessible again.
 
 Well, the number of requests depends on your MySQL parameters and hardware,
 but in general all the tested php-nuke sites where vulnerable and become
 inacessible.
 
 If you are running PHP-Nuke, I suggest the creation of some filters to 
 avoid this kind of attack.
 
 Other things can be made, but I will not talk about them now. I will wait
 until Francisco fix them.
 
 Francisco was noticed a month ago, but the problems persist.
 Maybe he is busy reading the new revision of the "Building Secure Web 
 Applications and Web Services" OWASP document. :]
 
 Cheers,
 
 Pedro Inacio
 
US Copyright Office Wakes Up To Flaws In Anti-Hacking Law
Oct 14

Detecting Cyberattacks By Profiling "Normal" Computer Habits
Oct 14

NIST Drafts Security Buying Guides
Oct 14

Linux Security Week - October 14th 2002
Oct 14

A Security Nightmare: Wireless Security
Oct 13

Chroot Jails Made Easy with the Jail Chroot ProjectRegister
Oct 11

Sendmail Trojan Looks Familiar
Oct 11

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000