High-severity vulnerability in vBulletin is being actively exploited
arstechnica.com
arstechnica.com
function evalCode($code) {
ob_start();
eval($code);
$output = ob_get_contents();
ob_end_clean();
return $output;
}
... So anyone who looks at a codebase for eval would have found this. There is no doubt in my mind that when some people have claimed that this has been around for years... That it has definitely been around for years.And as the fix is:
// comment out. idk what it breaks but it's a fix for now
//eval($code);
I don't think anyone even knows what the hell that eval was doing there in the first place.It's not a straightforward POST -> eval but goes through a few calls, which is probably why it wasn't discovered sooner.
When I gave notice, I was asked if I'd like to work on vBulletin as an engineer.
(Some good reading at https://vbtruth.com/category/company/vbulletin/ )
I find it depressing that vBulletin has been getting hacked for so long that it's literally outlived several of the major vulnerability disclosure websites that have historically published exploits about it (like milw0rm -- still an amazing theme, btw.) Maybe PHP should throw warnings about eval and recommend an alternative function purely for expressions instead. In Python apparently eval evaluates expressions for a result and exec would do what PHP's eval would do instead. Something like that for PHP would be better than nothing.
You are definitely very correct about that, for a simple forum with basically no extensibility. Bugs arise from the fact that vB is extremely customisable and has lots of points for extension, making its codebase very complex.
Unnamed Goose Game? It's just a bunch of polygons and MIDI riffs. No big whoop.
Slack? It's just a chat agent. Just some input validation and syndication. Easy peasy.
Microsoft Windows? It's just a window manager running on DOS. No sweat, I could whip that up over the weekend.
Interestingly enough, it appeared as though google somehow sanitized the dork proposed in the actual post to return few to no forums, at least when I checked this morning. Checking now from a different IP returns a lot more; very weird.
The actual post to seclists for reference: https://seclists.org/fulldisclosure/2019/Sep/31
Also, why on God's green earth to devs put version numbers so obviously in the software? For instance, on my web servers, I always turn off version number and platform, so an attacker can't easily go hunt down vulns from scraping the web. It seems as though it would be wise to make no version numbers that easily accessible the default.
Version numbers help people get support and know when/where versions are fixed and if they are patched/updated.
A solution is running up to date software, and encouraging developers to release security fixes and for admins to care.
It is a deterrent, and not a solution. But it does prevent the clouds of botnets from labeling you as definitely vulnerable and attacking you the moment a new 0-day gets purchased. The speed of attacks can outpace your speed of your upgrade process.
Security-in-depth should always be the way forward. This is just another tickbox you can use.
All software will have bugs.
There's no good reason to accurately broadcast to the world what specific version you're running of anything, ever.
It's not advocating leaving your production systems to rot with ancient software because you've hidden the versions. You still need to stay vigilant. But the reality is, 0-days happen, and not all bugs being exploited are reported/fixed. Keep the version hidden, or hell, broadcast a completely different software/version altogether.
At that time, a lot of servers showed up. All the top ones had been vandalized already.
This is why we can't have nice things. Zerodium, thanks for being honest, but services such as yours are actively making the internet a worse place.
eval($code);
so it's even worse. Those two wouldn't show up, but you can call them if you want to!Why do our opinions differ?
Fuck reporting vulns, fuck open disclosure. Just sell what you find to brokers.
Cahouki Bekrar says there are three options:
1. Full disclosure so anyone/Govs can (ab)use it without limits/regulation
2. Sell to Govs/brokers and get a decent revenue while limiting (ab)use
3. Report to vendors & get sued, or get shitty bounties and/or your name in advisories
I agree with him.
Yeah it should be a learning experience, fix it and get over it. But it is not easy if you have 3 people waiting for you to slip to get your position. Some other want make money on writing a story about how bad your software is, even though it might be not your issue (VLC-bug story) because software is complicated. Good luck with explaining that was not your fault...
So you're saying that a bunch of volunteer open source developers collectively sued a security researcher? That sounds like it would have made for an epic Hacker News story. Do you have any documentation that this happened?
There's even a conference dedicated to it now: https://www.disclosureconference.com/
Its probably worthwhile to attend.
They used to just dogfood their own software as their homepage: https://web.archive.org/web/20070205162247/http://www.vbulle...
I'm aware of Discourse and Flarum, which use more modern designs:
phpBB and Simple Machines Forum both use classic designs similar to vBulletin:
What's the best alternative to vBulletin?
As a user, Discourse forums have always felt bloated and slow. As a developer, I was shocked when I went to their installation documentation and saw it required 1 GB of RAM and 10 GB of disk space.
There are some improvements over HN: https://www.talkyard.io/-32/how-hacker-news-can-be-improved-...
However, this is unambiguously illegal under anti-hacking laws like CFAA [2] which introduces a variety of practical difficulties.
[1] https://en.wikipedia.org/wiki/Anti-worm [2] https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
It’s script you can just read it guys, everyone fights so hard for open source and no one bothers reading anything.
It took me all of 15 minutes to find code injections appended to the bottom of the code files.
...but that wasn't the interesting part. Since it was a very popular SEO plugin, I actually took the extra time and reported the attack code wordpress security scanners and the torrent site.
A month later I checked back and the plugin had been re-uploaded, but this time with the attack code heavily obfuscated and much more subtely hidden within the plugin.
...and this time when I reported it to the torrent site, the site admins banned me and actually IP blocked me.
tldr; The only open source code getting reviewed is heavily used stuff.
Pirated closed-source themes and plug-ins for WordPress is a very common source of malware on WP sites.
Now where is my facebook dot com shell?