[PATCH AVAIL.] OpenSEF 2.0.0 RC5

For all Non-Joomla! security issues. ie 3pd Components etc.

Moderator: General Support Moderators

Forum rules
Taikonaut
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 213
Joined: Wed Sep 28, 2005 1:52 pm

Patch doesn't help! OpenSEF 2.0.0 RC5 SP2 is vulnerable too

Post by Taikonaut » Wed Mar 05, 2008 11:34 am

OpenSEF 2.0.0. RC5 SP2 is vulnerable TOO!!!

check: http://www.securityfocus.com/bid/19600

My site got hacked via RFI (after finding the log-entry I tried it myself) and removing OpenSEF made the shell access script not working anymore.
  • Delete all bad SEF-URLs in OpenSEF
  • Export the good ones to a csv using OpenSEF
  • Remove OpenSEF via Component installer
  • Install sh404SEF
  • Import the OpenSEF-CSV-Export
You won't see any differences in the frontend but now your site is safe again!

Regards,
Taiko

teclive
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 158
Joined: Thu Nov 24, 2005 7:44 pm

Re: [PATCH AVAIL.] OpenSEF 2.0.0 RC5

Post by teclive » Fri Mar 07, 2008 12:19 am

does sh404SEF work with joomla Joomla! 1.0.15 ?

the site i am workign on has been hit 4 times in the past 2 weeks and always through com_sef which is the open sef component so i need to get it changed, but cant afford to lose the already existing urls..i would be shot on spot if i lose any info :'(

Taikonaut
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 213
Joined: Wed Sep 28, 2005 1:52 pm

Re: [PATCH AVAIL.] OpenSEF 2.0.0 RC5

Post by Taikonaut » Fri Mar 07, 2008 1:24 am

@teclive:

Yes, it does!!! I did what i wrote above several times with sites running 1.0.13 and 1.0.15 without having any problems!

just delete the unpublished and invalid urls in opensef, export the urls (not the config etc) in csv format and import it afterwards to SH404SEF.

@mods: please update the vulnerability list!! Its quite urgent because many people use it.

teclive
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 158
Joined: Thu Nov 24, 2005 7:44 pm

Re: [PATCH AVAIL.] OpenSEF 2.0.0 RC5

Post by teclive » Fri Mar 07, 2008 1:38 am

--Tis ok, i found the import option--

Thanks a bunch for your advice my friend :D
itook your advice and uninstalled opensef and installed the 404sef but i dont see a place in the admin to import the cvs file so i have lost all the urls on the live site :( :( big trouble for me

teclive
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 158
Joined: Thu Nov 24, 2005 7:44 pm

Re: [PATCH AVAIL.] OpenSEF 2.0.0 RC5

Post by teclive » Fri Mar 07, 2008 1:48 am

ok...got a problem

Code: Select all

http://www.huomah.com
if you click on any links on the left hand side, you get an error
Parse error: syntax error, unexpected T_STRING in /home/huomahc/public_html/components/com_sef/cache/shCacheContent.php on line 227
however, if you use any of the top links they are fine.. (ok just checked again, seems all top ones are not fine)

i dont know if its because of the '_' in the urls or not

please help :'(

teclive
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 158
Joined: Thu Nov 24, 2005 7:44 pm

Re: [PATCH AVAIL.] OpenSEF 2.0.0 RC5

Post by teclive » Fri Mar 07, 2008 2:06 am

the only urls i can get to on the site, are default ones, i cant even get to the main page anymore

Code: Select all

http://www.huomah.com/component/option,com_sefservicemap/Itemid,58/

teclive
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 158
Joined: Thu Nov 24, 2005 7:44 pm

Re: [PATCH AVAIL.] OpenSEF 2.0.0 RC5

Post by teclive » Fri Mar 07, 2008 2:23 am

i looked at the line of code in the file it was saying the error was in..

it seems that its a ' in the url, its supposed to be part of the url though :(

line 15

Code: Select all

$shURLDiskCache[9]='index.php?option=com_content&Itemid=37&id=21&lang=en&task=view#personal/family-life/elisia's-left-out.html#1';
the apostrophy is highlighted in my editor, in the word 'elisia's '

was able to fix the problem above, but now its spitting out something else, error on a new line, but this line reads as...

Code: Select all

$shURLDiskCache[113]='index.php?option=com_content&Itemid=66&id=151&lang=en&task=view#search-engines/algorithm-matters/stay-off-the-lsi-bandwagon.html#1';
i dont get the problem i dont see anything wrong in that line

Taikonaut
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 213
Joined: Wed Sep 28, 2005 1:52 pm

Re: [PATCH AVAIL.] OpenSEF 2.0.0 RC5

Post by Taikonaut » Fri Mar 07, 2008 12:39 pm

actually, this is the wrong thread for a discussion how to migrate from opensef to sh404sef. this thread is for security issues!!!

got to: http://forum.joomla.org/viewtopic.php?f ... 1#p1228751

teclive
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 158
Joined: Thu Nov 24, 2005 7:44 pm

Re: [PATCH AVAIL.] OpenSEF 2.0.0 RC5

Post by teclive » Fri Mar 07, 2008 2:56 pm

sorry about that, i guess i lost track of where i was when i went into panic mode :)

thanks for brining it to my attention :)

User avatar
Predator
Joomla! Ace
Joomla! Ace
Posts: 1823
Joined: Wed Aug 17, 2005 10:12 pm
Location: Germany-Bad Abbach
Contact:

Re: [PATCH AVAIL.] OpenSEF 2.0.0 RC5

Post by Predator » Wed Mar 12, 2008 11:30 am

@Taikonaut
The Securityreport you where mention above has been retired: http://www.securityfocus.com/bid/19600/info as stated here http://www.securityfocus.com/archive/1/ ... 0/threaded this BID has been retired because this issue is not exploitable. So better check again your logs.
The "Humor, Fun and Games" forum has  more than 2500 Posts, so why not build a "Humor, Fun and Games Working" Group?
.....
Malicious tongues say we have this WG right from the start, they call it core team :D

Taikonaut
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 213
Joined: Wed Sep 28, 2005 1:52 pm

Re: [PATCH AVAIL.] OpenSEF 2.0.0 RC5

Post by Taikonaut » Wed Mar 12, 2008 12:14 pm

@Predator

Thanks for your reply!

To find out where my vulnerability was, I successively uninstalled one component after another and tested the hack script each time. After uninstalling OpenSEF 2.0.0. RC5 SP2 the script didn't work anymore.

I'll have another look at my log files!

User avatar
Predator
Joomla! Ace
Joomla! Ace
Posts: 1823
Joined: Wed Aug 17, 2005 10:12 pm
Location: Germany-Bad Abbach
Contact:

Re: [PATCH AVAIL.] OpenSEF 2.0.0 RC5

Post by Predator » Wed Mar 12, 2008 12:29 pm

No prob, was just a hint that the mentioned issue was not exploitable so there must be an other issue in Opensef (if it is the culprit) or somewhere if not.

As i saw this report was from 2006-08-19 00:00:00 so the patch in this Thread was fixing this, so not sure which Version you have or got.
The "Humor, Fun and Games" forum has  more than 2500 Posts, so why not build a "Humor, Fun and Games Working" Group?
.....
Malicious tongues say we have this WG right from the start, they call it core team :D


Locked

Return to “3rd Party/Non Joomla! Security Issues”