Page 1 of 2 12 LastLast
Results 1 to 10 of 17

osCMax Security Update - Arbitrary Upload Exploit

This is a discussion on osCMax Security Update - Arbitrary Upload Exploit within the Announcement Discussions forums, part of the osCmax News and Announcements category; A new blog entry has been added: [drupal=251]osCMax Security Update - Arbitrary Upload Exploit[/drupal] A security hole was found in ...

      
  1. #1
    osCMax Developer

    michael_s's Avatar
    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    19,501
    Rep Power
    567


    Default osCMax Security Update - Arbitrary Upload Exploit

    A new blog entry has been added:

    [drupal=251]osCMax Security Update - Arbitrary Upload Exploit[/drupal]

    A security hole was found in osCMax 2.0 RC 3.0.1 that allows a remote attacker to upload files to your site via a browser.
    Michael Sasek
    osCMax Developer


    osCmax installation service - Have our professionals install osCmax on your server - same day service!
    osCmax 2.0 User Manual - the must have beginners guide to osCmax v2.0

    Stay Up To Date with everything osCMax:
    Free osCMax Newsletters - Security notices, New Releases, osCMax News
    osCMax on Twitter - Up to the minute info as it happens. Know it first.

    osCmax Documentation

  2. #2
    Active Member MindTwist's Avatar
    Join Date
    Jun 2007
    Location
    Barcelona, Spain
    Posts
    408
    Rep Power
    7


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    I just received 2-3h ago an email with this info. I guess everyone else on the forum must have received, just wanted to say that it is nice to be informed when this kind of vulnerabilities are found.
    Thx!

  3. #3
    New Member
    Join Date
    Aug 2008
    Posts
    17
    Rep Power
    0


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    My company web site changed many code.
    I don't think it is possible update to apply RC3.
    Which files contain this kind of thread.
    Or what can I do to prevent this kind of thread?

    Thx for the notification.

  4. #4
    Active Member MindTwist's Avatar
    Join Date
    Jun 2007
    Location
    Barcelona, Spain
    Posts
    408
    Rep Power
    7


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Follow the link michael_s posted, you only need to delete a few files from your default OSCMAX installation, so it really doesn't matter how much you have modified your store previously

  5. #5
    Active Member
    Join Date
    Jun 2008
    Posts
    195
    Rep Power
    4


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Update appreciated, but I would just like to double check something please.

    Looking at the posted file paths/dirs to be removed, all mine seem to be installed under:

    /filermanager/connectors ( this dir also includes /browsers )

    Within
    /FCKeditor/editor/filemanager/browser/default/connectors/*.*
    In /browser/default/ (as described in e-mail alert and post), this dir contains (2) dirs of: /images & /js

    I am just veriying the posted pathing against what I find/see please?

    Thx...Jim

  6. #6
    osCMax Development Team
    Join Date
    Nov 2002
    Location
    Orlando
    Posts
    433
    Rep Power
    14


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Hi Mike,

    Do you have any additional info that you can share about this exploit? Are there certain files that were being uploaded or changed due to this exploit? My assumption is target files are always credit card related, database, or even email related.
    John

  7. #7
    Active Member MindTwist's Avatar
    Join Date
    Jun 2007
    Location
    Barcelona, Spain
    Posts
    408
    Rep Power
    7


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Arbitrary Upload Exploit - I didn't even check, I just deleted the unnedeed files, but I can assume that those included files are not needed for FCKeditor on OSCMAX/PHP, but could be used to upload anything/anywhere on your store.

    Once someone does that, he can basically do anything they want with your host - download your complete store database, modify your store so when customers use a credit card, details are emailed to someone, upload a PHP script so your store is sending a gazilliom spam messages every day without you even noticing, etc.

  8. #8
    Active Member
    Join Date
    Jun 2008
    Posts
    195
    Rep Power
    4


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Yes, I was curious also as here's a 7 day search result:

    - Google Search

    And I see the new download, contains new folder names?

    Jim

  9. #9
    osCMax Development Team
    Join Date
    Nov 2002
    Location
    Orlando
    Posts
    433
    Rep Power
    14


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Honestly, I'm not a huge fan of FCKeditor anyway.

    One advantage of having a dedicated server and being actively involved with it is things like email can be tightly monitored if things change so I don't think I've been exploited there. But, there's always possibilities for something I haven't considered.

    My biggest fear is credit card related files being altered to compromise customer cc data but I only use one CC system and I watch those files pretty carefully.
    John

  10. #10
    osCMax Developer

    michael_s's Avatar
    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    19,501
    Rep Power
    567


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    The key file(s) to remove are the test.html files included with that version of fckeditor. They do not sanitize input and allow the upload process to occur. Your file structure for FCKeditor may differ from that posted in the security notice, but be sure to remove all the test.html file(s) in fckeditor.

    The other directories/files that are removed were part of a default fckeditor 2.0 install, and should be removed as osCMax does not use them. We took the opportunity to get them out of the package once and for all.
    Michael Sasek
    osCMax Developer


    osCmax installation service - Have our professionals install osCmax on your server - same day service!
    osCmax 2.0 User Manual - the must have beginners guide to osCmax v2.0

    Stay Up To Date with everything osCMax:
    Free osCMax Newsletters - Security notices, New Releases, osCMax News
    osCMax on Twitter - Up to the minute info as it happens. Know it first.

    osCmax Documentation

Page 1 of 2 12 LastLast

Similar Threads

  1. Possible security exploit
    By brendanl79 in forum osCmax v2 Customization/Mods
    Replies: 0
    Last Post: 10-13-2006, 04:11 PM
  2. Security Update HELP
    By inmotion in forum osCmax v1.7 Discussion
    Replies: 0
    Last Post: 05-08-2006, 06:06 PM
  3. osCMax 2.0RC2 Security Patch/Update 051112
    By wilde-uk in forum osCmax v2 Installation issues
    Replies: 5
    Last Post: 04-12-2006, 08:45 PM
  4. osCMax 2.0RC2 Security Patch/Update 051112
    By michael_s in forum Announcements
    Replies: 0
    Last Post: 11-27-2005, 10:12 AM
  5. use bts update,i cant use WYSIWYG upload any picture????????
    By Anonymous in forum osCmax v1.7 Discussion
    Replies: 1
    Last Post: 11-27-2004, 05:08 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •