WebsiteBaker Community Forum

General Community => Off-Topic => Topic started by: anon on July 29, 2005, 08:56:09 PM

Title: vulns
Post by: anon on July 29, 2005, 08:56:09 PM
http://www.securityfocus.com/bid/14404
http://www.securityfocus.com/bid/14406
Title: Re: vulns
Post by: Ryan on July 30, 2005, 02:18:43 AM
Hmm, it is sad that these links don't really explain any problems.
Could anyone help diagnose the problem - it is a little to little info for me.
I am guessing these two things have to do with the code module and the media section.
Title: Re: vulns
Post by: hudge on July 30, 2005, 02:27:18 AM
Well I am glad to see that people are getting involved and spreading the word. Too bad they would not post a screename. These features are understood by the administrator. IE if you allow someone to access your site, they can do bad things. Yes limits can be put on and will most likely be there in version 3.

Overall this software is GREAT! Spend some time and see for yourself.
Title: Re: vulns
Post by: Ryan on July 30, 2005, 04:15:24 AM
What I want to know is if these "Vulnerabilities" can be used for people  that do not have an account (i.e. can anyone just go to your website and do the reported things [which i am yet to figure out are]), or do you have to login to the Administration to do these things - if so then it can easily be limited using correct permissions).
Title: Re: vulns
Post by: KenZo on July 31, 2005, 07:09:13 PM
Remote: Yes (via web dus)
Local: No (locale server)

(nl: duidelijk)
Title: Re: vulns
Post by: tgo on August 01, 2005, 06:51:41 PM
I thought I put my details in the post I did when I showed these vulns but I guess not. About the vulns: The cross site scripting one can be done by anyone with access to browse.php. The file upload one is way more dangerous because whoever has access can upload any file type they want such as php and then have php files on the server.  I dont remember exactly if this product had a file that was included for a conenction to the database, but most do, and so with this php file someone uploaded they could include the connection file and then run any query they wanted on the database.

feel free to email me if you want i put my addy in the post
Title: Re: vulns
Post by: tgo on August 01, 2005, 06:56:06 PM
if you want more details check my original post at

http://bluelightningblade.com/papers/wb.txt
Title: Re: vulns
Post by: Ryan on August 06, 2005, 07:34:07 AM
These "security vulerabilities" make things seem much worse than they really are.
These are not really security holes - it is just the way the features work.

If you don't set things up right, you can leave things dangerously vulnerable.
It is like any computer - if you just plug it in "as is", without configuring user accounts and groups with proper permissions, anyone can do anything to a system (well, for Windows this is the case).
However, if configured correctly, only trusted people can do serious things.

Although it is not really a security hole, there are measures that can be taken to prevent these problems, such as disabling certain file-extensions for media.
These features will most likely be added in 2.5.3 (or 2.6.0), just to make things more flexible.
 8-)
Title: Re: vulns
Post by: Ryan on August 18, 2005, 10:24:27 AM
A forum member contacted me regarding the "vulnerabilities", here are the solutions I provided him with until I release another WB2:
- If you are on a shared host, make sure that the PHP error reporting level is set to 0 (found in config file). This way, paths should not be disclosed.
- If you cannot trust your users, a quick fix on an Apache server: you could put a .htaccess file under the media folder that blocks execution of certain file extensions.
By taking these two measure, the two security vulnerabilities become irrelavent.
 8-)
Title: Re: vulns
Post by: Ryan on September 08, 2005, 11:05:41 AM
Just letting you all know that all the known "security vulnerabilities" will be fixed/have been fixed for 2.6.0 (to be released shortly - see here (http://www.WebsiteBaker.org/projects/websitebaker2/milestone/2.6.x)), not that they were that serious anyways :-D
Title: Re: vulns
Post by: fjord on July 19, 2006, 12:01:19 PM
Hello!

Some of you authorities should update the Secunia database, the current status is unresolved. Then WebsiteBaker will get a top ranking on this vulnerability portal.

Check out this excellent status report: http://secunia.com/product/5455/

Thanks for keeping security focus!

Fjord