osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 

Security Notice : osCMax 2.0.4 Released

This is a discussion on Security Notice : osCMax 2.0.4 Released within the Announcement Discussions forums, part of the osCMax News and Announcements category; A new blog entry has been added: Security Notice : osCMax 2.0.4 Released A serious security vulnerability has been discovered ...



Find us on Facebook
Go Back   osCommerce and osCMax shopping cart software forums > osCMax News and Announcements > Announcement Discussions

Connect with Facebook Register FAQDonate Members List Calendar Mark Forums Read


Reply

 

LinkBack Thread Tools
  #1  
Old 11-09-2009, 05:05 PM
michael_s's Avatar
osCMax Developer


 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 16,712
Thanks: 150
Thanked 674 Times in 577 Posts
Rep Power: 558
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default Security Notice : osCMax 2.0.4 Released

A new blog entry has been added:

Security Notice : osCMax 2.0.4 Released

Quote:
A serious security vulnerability has been discovered in osCMax v2.0.3
and all prior versions. It is important that you follow the below
instructions carefully to secure your site. Failure to do so could
result in your site being breached by attack.<br><br>The following files must be removed from your site's administrative panel folder:<br><br>/admin/<b>file_manager.php</b><br>/admin/<b>define_language.php</b><br><br>Removing these files will close this vulnerability.<br><br>osCMax
v2.0.4 has been posted to osCMax.com and the vulnerability has been
patched. The security fix has also been added in SVN. It is recommended
that all osCMax site owners remove these files immediately. <br>
Visit the above link to download the new release. Feel free to post your comments, questions, problems or thoughts regarding this project here.

This thread will serve as the official discussion thread for this project.
__________________
Michael Sasek
osCMax Developer

*** Do not PM me requesting paid help. The only paid work I do is for AABox Web Hosting customers ***

Stay Up To Date with everything osCMax:
Free osCMax Newsletters - Security notices, New Releases, osCMax News
osCMax on Twitter - Up to the minute info as it happens. Know it first.

osCMax User Manual - osCMax Templates - Advanced Template Tutorial

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following 3 Users Say Thank You to michael_s For This Useful Post:
GedC (11-09-2009), MindTwist (11-10-2009), vallys (11-09-2009)
  #2  
Old 11-09-2009, 06:38 PM
New Member
 
Join Date: Oct 2008
Posts: 15
Thanks: 2
Thanked 0 Times in 0 Posts
Rep Power: 0
user123 is on a distinguished road
Default Re: Security Notice : osCMax 2.0.4 Released

Hi Michael,

Do we just need to remove those 2 files or do we have to install 2.04 as well? In the upgrade folder, I see 2 files - upgrade.php and sql file. Do we use this to upgrade from 2.03 to 2.04? It would be great if you can tell us how to update the site for newbies like me.

Thanks for the update.

Jay
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3  
Old 11-09-2009, 06:51 PM
michael_s's Avatar
osCMax Developer


 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 16,712
Thanks: 150
Thanked 674 Times in 577 Posts
Rep Power: 558
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default Re: Security Notice : osCMax 2.0.4 Released

Just delete the two files from your admin panel. That is all you need to do. No downloads needed.
__________________
Michael Sasek
osCMax Developer

*** Do not PM me requesting paid help. The only paid work I do is for AABox Web Hosting customers ***

Stay Up To Date with everything osCMax:
Free osCMax Newsletters - Security notices, New Releases, osCMax News
osCMax on Twitter - Up to the minute info as it happens. Know it first.

osCMax User Manual - osCMax Templates - Advanced Template Tutorial

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to michael_s For This Useful Post:
altenter (12-22-2009)
  #4  
Old 11-09-2009, 06:55 PM
New Member
 
Join Date: Oct 2008
Posts: 15
Thanks: 2
Thanked 0 Times in 0 Posts
Rep Power: 0
user123 is on a distinguished road
Default Re: Security Notice : osCMax 2.0.4 Released

Cool! That's easy
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5  
Old 11-09-2009, 11:06 PM
New Member
 
Join Date: Mar 2009
Location: Ukraine
Posts: 5
Thanks: 1
Thanked 2 Times in 2 Posts
Rep Power: 0
vallys is on a distinguished road
Default Re: Security Notice : osCMax 2.0.4 Released

Thanks for useful info!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6  
Old 11-10-2009, 12:12 AM
pgmarshall's Avatar
osCMax Development Team
 
Join Date: Feb 2009
Location: London
Posts: 1,194
Thanks: 64
Thanked 255 Times in 218 Posts
Rep Power: 15
pgmarshall has much to be proud ofpgmarshall has much to be proud ofpgmarshall has much to be proud ofpgmarshall has much to be proud ofpgmarshall has much to be proud ofpgmarshall has much to be proud ofpgmarshall has much to be proud ofpgmarshall has much to be proud ofpgmarshall has much to be proud of
Question Re: Security Notice : osCMax 2.0.4 Released

Michael,

Is this a temporary fix? Ie. Are we looking at replacing the file manager?

Define Languages - I never use anyway - but I do use the File Manager quite a lot! Especially when helping other people with their sites ... saves having to ask for FTP details which they never have ...

Since the File Manager is stand alone could we not rename it to a complete random name? Which coupled with the rename of the Admin folder make it reasonably secure again?

Do you have any more details of the security hole?

Regards,
__________________
pgmarshall
_______________________________
Test Site: www.cottonbarn.info

Want to say thank you if I helped you out? Help me block this waste incinerator plan (www.nywag.org) in North Yorkshire, UK. Sign the petition here (only takes 1 minute). Thanks.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7  
Old 11-10-2009, 12:18 AM
Lurker
 
Join Date: May 2009
Posts: 4
Thanks: 2
Thanked 0 Times in 0 Posts
Rep Power: 0
GedC is on a distinguished road
Default Re: Security Notice : osCMax 2.0.4 Released

Thanks Michael - on the ball as usual.

One question - removing the 2 files from the admin folder also removes the functionality from the admin->tools section right? Is the functionality replaced in 2.0.4 (from a quick look, I don't see either file in there)?

define languages isn't that big a problem for me but some clients use file manager.

Thanks for your help.
Ged
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8  
Old 11-10-2009, 01:01 AM
pgmarshall's Avatar
osCMax Development Team
 
Join Date: Feb 2009
Location: London
Posts: 1,194
Thanks: 64
Thanked 255 Times in 218 Posts
Rep Power: 15
pgmarshall has much to be proud ofpgmarshall has much to be proud ofpgmarshall has much to be proud ofpgmarshall has much to be proud ofpgmarshall has much to be proud ofpgmarshall has much to be proud ofpgmarshall has much to be proud ofpgmarshall has much to be proud ofpgmarshall has much to be proud of
Smile Re: Security Notice : osCMax 2.0.4 Released

GedC,

Yes - removing the files will remove the functionality ...

As per my previous post - I find the File Manager very useful - as an interim measure I have renamed the file something complicated using numbers and upper and lower cases.

If you want to do the same then -
1) Rename the file_manager.php something else eg. s4feRn4mE.php
2) open admin/filenames.php and change the define for FILE_MANAGER
3) rename the language file in admin/includes/languages/<your language>/s4feRn4mE.php.

Assuming you have also renamed your Admin folder then the potential hacker needs to be able to find 2 random string names by chance ... unless someone can tell me more about the security hole ...

Quote:
Perhaps, the osCMax installer should be updated to generate a random name for the ADMIN folder and file_manager.php at setup and store these in the relevant places within the configure, filenames, language files?
Regards,
__________________
pgmarshall
_______________________________
Test Site: www.cottonbarn.info

Want to say thank you if I helped you out? Help me block this waste incinerator plan (www.nywag.org) in North Yorkshire, UK. Sign the petition here (only takes 1 minute). Thanks.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9  
Old 11-10-2009, 03:20 AM
Lurker
 
Join Date: May 2009
Posts: 4
Thanks: 2
Thanked 0 Times in 0 Posts
Rep Power: 0
GedC is on a distinguished road
Default Re: Security Notice : osCMax 2.0.4 Released

pgmarshall,

Excellent advice - thank you. I will make those changes immediately (I hadn't thought of renaming the ADMIN folder but will do so).

Do you think it might be worthwhile applying the same logic to some (or all) of the other key files to really lock down any potential holes? It would appear to make sense, given the open source nature of oscmax/oscommerce.

In fact this has spurred me into the idea of reworking the admin interface completely and customizing it for individual clients........ no rest for the wicked, as they say .

Thanks again

GedC
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10  
Old 11-10-2009, 04:30 AM
Nimitz_1061's Avatar
New Member
 
Join Date: Oct 2003
Posts: 13
Thanks: 1
Thanked 0 Times in 0 Posts
Rep Power: 0
Nimitz_1061
Default Re: Security Notice : osCMax 2.0.4 Released

These files have been known to be security risks in the basic osCommerce for quite some time. Both had some reworking before being re-included in CRE Loaded. I would presume similar work had been done on the osCMax versions. This would tend to indicate an entirely new risk has been found which is not covered by the admin access system despite recent patches. This makes the details quite important in regards to the question of whether these files are safe in other distributions or any installations at all.

I can understand that Michael would not want to disclose such details in open forum (or blog) - is there a closed forum here for identified developers in which confidential discussion may take place during the early phases of security response?? If not, I do provide one in the oscommerceuniversity.com forums.
__________________
--------------
Nondenominational osCommerce education: http://www.oscommerceuniversity.com/school/
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
osCMax v2.0.3 Security Update Released michael_s Announcements 0 07-01-2009 10:14 AM
osCMax v2.0.0 Released michael_s Announcement Discussions 2 03-28-2009 01:31 PM
osCMax 2.0 RC4 Released michael_s Announcements 2 03-15-2009 03:12 PM
osCMax v2.0 RC2 Released michael_s Announcements 0 09-21-2005 03:43 PM
osCMax v2.0 RC1 Released! michael_s Announcements 0 06-14-2005 01:51 PM


All times are GMT -8. The time now is 06:35 AM.


Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO
Copyright 2010 osCmax
Inactive Reminders By Icora Web Design