CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer
image PHPNuke SQL Injection image
PHP-Nuke
Anonymous writes "
PHPnuke, a widely used open-source web portal system, has been found to contain a remotely exploitable SQL injection bug, which allows stealing of the administrator's password hash. With the hash, an attacker may login and gain complete control of the administrative side of the system.

The bug exists in the search engine included with PHPnuke (/modules/search/index.php). In this file, a database call is made without placing quotes around a user supplied variable. Since the database call selects information from the user table, a hacker can use a 'select fish' attack. In this type of attack, the hacker can determine the value of a single character in any given column in the table specified in the statement. The column of most importance to a hacker would be the one holding the administrators encrypted password. Since the passwords in PHPnuke (and many other programs) are an md5 hash, there are only 16 possible values for each character and 32 total characters to expect. Select fishing involves utilizing the MySQL mid() function to return true if the character is guessed correctly, thereby returning a set of results to the screen. If the results show up on the screen, the attacker can determine that the character is guessed correctly, and then proceed to guess the next character in the sequence. Any md5 password hash can be fished in less than 512 (32*16) guesses. When done by hand, this can take anywhere from 20-30 minutes, but when the process is automated with a program it can take only a few minutes. One such program is included at the end of this document.

http://www.xatrix.org/a2703-Secure_Passwords_in_Windows_2000_and_XP.html "
Posted on Monday, 24 February 2003 @ 10:05:00 UTC by cj (4340 reads)
[ Trackback ]
image

"PHPNuke SQL Injection" | Login/Create an Account | 1 comment | Search
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: PHPNuke SQL Injection (Score: 1)
by Paul  on Monday, 24 February 2003 @ 11:04:32 UTC
(User Info | Send a Message | _JOURNAL) http://www.laudanski.com
This is a bogus claim, it has no merit:

Source: http://nukecops.com/article-74-nested-0-0.html


 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· PHP HomePage
· PHP-Nuke
· MySQL Database Server
· HotScripts
· W3 Consortium
· More about PHP-Nuke
· News by cj


Most read story about PHP-Nuke:
PHP-Nuke Referer Hijacking

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer