vBulletin 4, the most powerful community software + vBSEO 3.5, the ultimate SEO solution = Your ultimate platform for 2010 and beyond. Click below to learn more.

Results 1 to 14 of 14

Photopost vBGallery Exploit

This is a discussion on Photopost vBGallery Exploit within the Off-Topic & Chit Chat forums, part of the Focus on Members category; Yesterday Photopost sent its customers an email advising of an exploit affecting all versions of Photopost vBGallery, that allowed a ...

  1. #1
    vBSEO Staff Ace Shattock's Avatar
    Real Name
    Ace Shattock
    Join Date
    Jul 2005
    Location
    New Zealand
    Posts
    3,676

    Photopost vBGallery Exploit

    Yesterday Photopost sent its customers an email advising of an exploit affecting all versions of Photopost vBGallery, that allowed a user to upload a mis-named file that could be executed by your server.

    Their excuse is that it is Apache's flaw.

    They have provided instructions on how to patch the latest version, but if you are running something older, the instructions are not accurate, so you have the option of paying to renew your account to be able to download the unexploitable version.

    More information Here

    (You cannot download the unexploitable version if your licenses have lapsed).
    Ace Shattock / Crawlability Inc.
    Sneek Preview Video of the new Control Panel

    vBSEO 3.5 RC2 (Pre-Release)- Released for your Evaluation


    My Personal Sites: New Zealand Forum | vBulletin Modifications and Styles | vBulletin Hosting

  2. #2
    Junior Member
    Real Name
    Aaron Cooper
    Join Date
    May 2006
    Posts
    3
    Two of my sites fell victim to hackers due to this :(

  3. #3
    vBSEO Staff Ace Shattock's Avatar
    Real Name
    Ace Shattock
    Join Date
    Jul 2005
    Location
    New Zealand
    Posts
    3,676
    Indeed... i have a site running 2.2 of vB Gallery, and was fortunate enough to be able to figure out where to put the 'patch' myself.

    I hope there aren't too many of their customers who are less-savvy with PHP than I am, and are either exploited, or forced to pay for a renewal they didn't really want.
    Ace Shattock / Crawlability Inc.
    Sneek Preview Video of the new Control Panel

    vBSEO 3.5 RC2 (Pre-Release)- Released for your Evaluation


    My Personal Sites: New Zealand Forum | vBulletin Modifications and Styles | vBulletin Hosting

  4. #4
    Senior Member KW802's Avatar
    Real Name
    Kevin
    Join Date
    Jan 2006
    Posts
    163
    a) Here is a link that deals with why it's an Apache issue. The various patches to vBGallery are to work-around it.

    b) Here are the patch instructions for the work-around and here is list of 'before' chunks of code for the older versions of vBGallery & even vBadvanced Gallery. Nobody has to renew just to get the patch instructions; as far as I know everybody who has a license should be able to view the information. If somebody has a license, expired or not, and can not view the instructions then please post over in the PP forums so it can be looked into. If somebody has a license and has not logged into the forums for a very long time then they may have to update their email address to show as verified.

  5. #5
    vBSEO Staff Ace Shattock's Avatar
    Real Name
    Ace Shattock
    Join Date
    Jul 2005
    Location
    New Zealand
    Posts
    3,676
    Thanks for the extra links Kevin, they weren't in the email, or the threads linked to from it.

    Any reasoning as to why they allowed it to remain in the code for so long? mod_mime's not a new thing.

    *Edit to add* As you can see from the first line of PhotoPost Community - View Single Post - vBGallery clean script Discussions , these were not provided until I requested them.

    and, Zach has edited Michael's original post, so none of that information was available to anyone until this afternoon. Good to see they took my request on board.
    Ace Shattock / Crawlability Inc.
    Sneek Preview Video of the new Control Panel

    vBSEO 3.5 RC2 (Pre-Release)- Released for your Evaluation


    My Personal Sites: New Zealand Forum | vBulletin Modifications and Styles | vBulletin Hosting

  6. #6
    Senior Member KW802's Avatar
    Real Name
    Kevin
    Join Date
    Jan 2006
    Posts
    163
    Quote Originally Posted by Ace Shattock View Post
    Thanks for the extra links Kevin, they weren't in the email, or the threads linked to from it.

    Any reasoning as to why they allowed it to remain in the code for so long? mod_mime's not a new thing.
    Looks like it was a Day 1 item going all the way back to the "vBadvanced Gallery" days. For whatever reason it is just recent that it reached critical mass.

    Based upon different conversations, etc., it looks like it has caught everybody off-guard including a few other projects. One of the reasons likely why is because it is only a small list of extensions that behave unexpectedly. For example, *.php.wmv is vulnerable but *.php.txt and *.php.gif are not.
    Last edited by KW802; 01-10-2008 at 01:37 AM.

  7. #7
    Junior Member
    Real Name
    Michael
    Join Date
    Feb 2006
    Posts
    11
    Quote Originally Posted by Ace Shattock View Post
    Good to see they took my request on board.
    Until this moment I wasn't even aware of this post; so don't pat yourself on the back prematurely.

  8. #8
    Member Zachariah's Avatar
    Real Name
    Zachariah
    Join Date
    May 2007
    Location
    Canoga Park, CA
    Posts
    32
    Quote Originally Posted by Ace Shattock View Post
    and, Zach has edited Michael's original post, so none of that information was available to anyone until this afternoon. Good to see they took my request on board.
    I edit everything
    - ya there were a few revisions of the file thanks for the reminder. I had my head in fixing the problems and forgot on the code changes over the different revisions. Some of the links you were trying to access was still in the Mod area and not moved to live area. Blame me, they are on the east coast 3 hours +, I was still in the shower

    I spent a few days on research and running test cases. I found that every system I ran into 200-250 different hosts have this lay back way of apache setup.

    I spent 4 hours round and round with my web host. They are clueless why the problem happens, I was told I was put on a trouble ticket system (e-mail) as the person that just reads screens to answer questions could not help me. I need to email them the answers.

    Most are limited to wmv, psd problems some servers run file.php.anything
    - apache is just interpreting it as file.php.

    EX:
    helloworld.php = <?php Print "Hello, World!"; ?>

    All the same PHP file: (my host)
    http://www.szone.us/problem/helloworld.php <-- good
    http://www.szone.us/problem/helloworld_php.psd <-- good
    http://www.szone.us/problem/helloworld_php.wmv <-- good
    http://www.szone.us/problem/helloworld.php.psd <- bad
    http://www.szone.us/problem/helloworld.php.wmv <- bad
    Last edited by Zachariah; 01-10-2008 at 08:52 PM.

  9. #9
    vBSEO Staff Ace Shattock's Avatar
    Real Name
    Ace Shattock
    Join Date
    Jul 2005
    Location
    New Zealand
    Posts
    3,676
    Quote Originally Posted by viperalley View Post
    Until this moment I wasn't even aware of this post; so don't pat yourself on the back prematurely.
    Maybe not, but if you figure in the fact that I am "Kall" on your forums, and made the post that prompted the additions, can I begin patting sequence now?

    Ace Shattock / Crawlability Inc.
    Sneek Preview Video of the new Control Panel

    vBSEO 3.5 RC2 (Pre-Release)- Released for your Evaluation


    My Personal Sites: New Zealand Forum | vBulletin Modifications and Styles | vBulletin Hosting

  10. #10
    Member Zachariah's Avatar
    Real Name
    Zachariah
    Join Date
    May 2007
    Location
    Canoga Park, CA
    Posts
    32
    Quote Originally Posted by Ace Shattock View Post
    can I begin patting sequence now?
    I could use a rubdown myself
    - but you better know a cute girl

  11. #11
    vBSEO.com SysAdmin Danny Bembibre's Avatar
    Real Name
    Daniel Bembibre Gude @dbembibre
    Join Date
    Mar 2007
    Location
    Madrid (Spain)
    Posts
    646
    Blog Entries
    20
    I think that something like this

    AddHandler cgi-script .php .php3 .php4 .php5 .phtml .pl .py .jsp .asp .htm .shtml .sh .cgi
    Options -ExecCGI

    Or this in a htaccess of the upload folder

    <Files ^(*.jpeg|*.jpg|*.png|*.gif)>
    order deny,allow
    deny from all
    </Files>

    Can mitigate the problem
    vBSEO Success Story: bmwfaq.com 95% indexed in yahoo, 85% indexed in google and straight up and 10% indexed in bing

  12. #12
    Senior Member
    Real Name
    A.D
    Join Date
    Oct 2007
    Location
    France
    Posts
    159
    Haha I was right finally, that smells like an SQL injection

  13. #13
    Junior Member
    Real Name
    Michael
    Join Date
    Feb 2006
    Posts
    11
    Quote Originally Posted by Ace Shattock View Post
    Maybe not, but if you figure in the fact that I am "Kall" on your forums, and made the post that prompted the additions, can I begin patting sequence now?

    Sure, you can stroke yourself all you want...

  14. #14
    vBSEO Staff Ace Shattock's Avatar
    Real Name
    Ace Shattock
    Join Date
    Jul 2005
    Location
    New Zealand
    Posts
    3,676
    Quote Originally Posted by viperalley View Post
    Sure, you can stroke yourself all you want...
    Awesome.

    I am glad to see the lesson has been learned, and hope that next time an exploit of this level is found in your software, you will provide the relevant information of all prior versions.

    When you took it over and began selling it to people, you assumed responsibility for it.
    Ace Shattock / Crawlability Inc.
    Sneek Preview Video of the new Control Panel

    vBSEO 3.5 RC2 (Pre-Release)- Released for your Evaluation


    My Personal Sites: New Zealand Forum | vBulletin Modifications and Styles | vBulletin Hosting

Similar Threads

  1. [Request] Keyword Rich URLS with Photopost vBGallery?
    By Ace Shattock in forum Custom Rewrite Rules
    Replies: 21
    Last Post: 11-15-2009, 06:52 AM
  2. PhotoPost Pro - vBGallery??
    By Jibber in forum Off-Topic & Chit Chat
    Replies: 8
    Last Post: 11-26-2007, 12:36 PM
  3. PhotoPost vBGallery - Home URL rewritten to Forum URL?
    By Kaelon in forum Custom Rewrite Rules
    Replies: 5
    Last Post: 08-15-2007, 05:52 PM
  4. PhotoPost vBGallery vbseo uyumu
    By zoque in forum Türkçe
    Replies: 17
    Last Post: 01-02-2007, 02:29 PM