Full service web hosting, great prices and support. Starts at $1.99/month!
Page 1 of 2 12 LastLast
Results 1 to 10 of 17

Thread: osCMax Security Update - Arbitrary Upload Exploit

  1. #1
    osCMax Developer


    osCMax Security Update - Arbitrary Upload Exploit


    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    23,134
    Contribute If you enjoy reading the
    content here, click the below
    image to support our site.
    Click Here To Contribute To Our Site

    Total Contributions For

    michael_s     $ 10.00
    Rep Power
    598


    Default osCMax Security Update - Arbitrary Upload Exploit

    A new blog entry has been added:

    [drupal=251]osCMax Security Update - Arbitrary Upload Exploit[/drupal]

    A security hole was found in osCMax 2.0 RC 3.0.1 that allows a remote attacker to upload files to your site via a browser.

  2. #2
    Active Member MindTwist's Avatar
    Join Date
    Jun 2007
    Location
    Barcelona, Spain
    Posts
    409
    Contribute If you enjoy reading the
    content here, click the below
    image to support our site.
    Click Here To Contribute To Our Site

    Total Contributions For

    MindTwist     $ 0.00
    Rep Power
    19


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    I just received 2-3h ago an email with this info. I guess everyone else on the forum must have received, just wanted to say that it is nice to be informed when this kind of vulnerabilities are found.
    Thx!

  3. #3
    ryoyin
    Guest


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    My company web site changed many code.
    I don't think it is possible update to apply RC3.
    Which files contain this kind of thread.
    Or what can I do to prevent this kind of thread?

    Thx for the notification.

  4. #4
    Active Member MindTwist's Avatar
    Join Date
    Jun 2007
    Location
    Barcelona, Spain
    Posts
    409
    Contribute If you enjoy reading the
    content here, click the below
    image to support our site.
    Click Here To Contribute To Our Site

    Total Contributions For

    MindTwist     $ 0.00
    Rep Power
    19


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Follow the link michael_s posted, you only need to delete a few files from your default OSCMAX installation, so it really doesn't matter how much you have modified your store previously

  5. #5
    trochia
    Guest


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Update appreciated, but I would just like to double check something please.

    Looking at the posted file paths/dirs to be removed, all mine seem to be installed under:

    /filermanager/connectors ( this dir also includes /browsers )

    Within
    /FCKeditor/editor/filemanager/browser/default/connectors/*.*
    In /browser/default/ (as described in e-mail alert and post), this dir contains (2) dirs of: /images & /js

    I am just veriying the posted pathing against what I find/see please?

    Thx...Jim

  6. #6
    JohnW
    Guest


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Hi Mike,

    Do you have any additional info that you can share about this exploit? Are there certain files that were being uploaded or changed due to this exploit? My assumption is target files are always credit card related, database, or even email related.

  7. #7
    Active Member MindTwist's Avatar
    Join Date
    Jun 2007
    Location
    Barcelona, Spain
    Posts
    409
    Contribute If you enjoy reading the
    content here, click the below
    image to support our site.
    Click Here To Contribute To Our Site

    Total Contributions For

    MindTwist     $ 0.00
    Rep Power
    19


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Arbitrary Upload Exploit - I didn't even check, I just deleted the unnedeed files, but I can assume that those included files are not needed for FCKeditor on OSCMAX/PHP, but could be used to upload anything/anywhere on your store.

    Once someone does that, he can basically do anything they want with your host - download your complete store database, modify your store so when customers use a credit card, details are emailed to someone, upload a PHP script so your store is sending a gazilliom spam messages every day without you even noticing, etc.

  8. #8
    trochia
    Guest


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Yes, I was curious also as here's a 7 day search result:

    - Google Search

    And I see the new download, contains new folder names?

    Jim

  9. #9
    JohnW
    Guest


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Honestly, I'm not a huge fan of FCKeditor anyway.

    One advantage of having a dedicated server and being actively involved with it is things like email can be tightly monitored if things change so I don't think I've been exploited there. But, there's always possibilities for something I haven't considered.

    My biggest fear is credit card related files being altered to compromise customer cc data but I only use one CC system and I watch those files pretty carefully.

  10. #10
    osCMax Developer


    osCMax Security Update - Arbitrary Upload Exploit


    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    23,134
    Contribute If you enjoy reading the
    content here, click the below
    image to support our site.
    Click Here To Contribute To Our Site

    Total Contributions For

    michael_s     $ 10.00
    Rep Power
    598


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    The key file(s) to remove are the test.html files included with that version of fckeditor. They do not sanitize input and allow the upload process to occur. Your file structure for FCKeditor may differ from that posted in the security notice, but be sure to remove all the test.html file(s) in fckeditor.

    The other directories/files that are removed were part of a default fckeditor 2.0 install, and should be removed as osCMax does not use them. We took the opportunity to get them out of the package once and for all.

Page 1 of 2 12 LastLast

Similar Threads

  1. Possible security exploit
    By brendanl79 in forum osCmax v2 Customization/Mods
    Replies: 0
    Last Post: 10-13-2006, 03:11 PM
  2. Security Update HELP
    By inmotion in forum osCmax v1.7 Discussion
    Replies: 0
    Last Post: 05-08-2006, 05:06 PM
  3. osCMax 2.0RC2 Security Patch/Update 051112
    By wilde-uk in forum osCmax v2 Installation issues
    Replies: 5
    Last Post: 04-12-2006, 07:45 PM
  4. osCMax 2.0RC2 Security Patch/Update 051112
    By michael_s in forum Announcements
    Replies: 0
    Last Post: 11-27-2005, 10:12 AM
  5. use bts update,i cant use WYSIWYG upload any picture????????
    By Anonymous in forum osCmax v1.7 Discussion
    Replies: 1
    Last Post: 11-27-2004, 05:08 PM

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •