Go Back   Pligg CMS Forum > Pligg Development > Bug Report

Closed Thread
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-08-2006, 09:42 AM
New Pligger
 
Join Date: Oct 2006
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Admin - Huge Security Vuln

Hello i am a PHP developer, i'm pretty decent at finding security vulns and bugs. I also work on http://www.jinzora.org making sure their code is a secure as possible.

Upon examing the pligg code i have found some serious vulnerabilities, that can lead to account hijacking on a viral scale like the MySpace worm. I'm not sure what features the Admin accounts have but i think this exploit won't lead to a server compremise(if the admin can upload php scripts then the sever can be compremised)

Obviously i won't post this vulnerability on the forum but i will give you 3 days to contact me (andiroo@gmail.com) by email. If you fail to contact me within the 3 days i will release the details and a PoC on the forum.

If you do contact me i will try and assit you in fixing this problem. I'm sorry for having to threaten you with 3 days to get in contact with me BUT i've had some companies fail to respond when i notify them of securit problems within their product. This way general forces most companies to comply.

Thanks
P.S I will need proof of who you are, such as putting a hidden file on www.pligg.com and sending me the link to prove to me you are the gunine owners of pligg.com. We wouldn't want some hackers getting ahold of this with malicious intent do we?
  #2 (permalink)  
Old 10-08-2006, 09:46 AM
kbeeveer46's Avatar
Pligg Developer/Admin
Pligg Version: 0
Pligg Template: none
 
Join Date: Jun 2006
Location: Muncie, Indiana
Posts: 3,547
Thanks: 254
Thanked 649 Times in 513 Posts
Thanks for letting us know. You're in the IRC chat with me now so I will probably talk to you there.
__________________
I accept donations for my time helping users like you on the forum and IRC.
  #3 (permalink)  
Old 10-08-2006, 03:20 PM
New Pligger
 
Join Date: Oct 2006
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Wow i should have proof read that message.

Ash has been in contact. Within 10mins of me contacting pligg! Hopefully this will be sorted soon.
  #4 (permalink)  
Old 10-20-2006, 07:13 PM
New Pligger
 
Join Date: Oct 2006
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Pligg vulnerability

Hello,
Thanks to andiroo for his discovery! We're evaluating Pligg for a corporate implementation; is it as serious as first thought?

Thanks,
Francis
  #5 (permalink)  
Old 10-20-2006, 07:38 PM
kbeeveer46's Avatar
Pligg Developer/Admin
Pligg Version: 0
Pligg Template: none
 
Join Date: Jun 2006
Location: Muncie, Indiana
Posts: 3,547
Thanks: 254
Thanked 649 Times in 513 Posts
It was fixed within the hour after contacting Ash about it.
__________________
I accept donations for my time helping users like you on the forum and IRC.
  #6 (permalink)  
Old 10-20-2006, 08:12 PM
Yankidank's Avatar
Coder/Designer
Pligg Version: SVN
Pligg Template: Wistie
 
Join Date: Dec 2005
Location: Ocala, FL
Posts: 1,828
Thanks: 110
Thanked 183 Times in 129 Posts
Send a message via AIM to Yankidank Send a message via Skype™ to Yankidank
We're that good.
__________________
Need a Pligg Host?
Get 3 free months
when you buy a year of hosting.
Use the coupon PLIGG at either...
MidPhase hosting starting at $7.95/month.
ANhosting hosting starting as low as $4.95/month.
Closed Thread

Thread Tools
Display Modes
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Similar Threads
Thread Thread Starter Forum Replies Last Post
Why can't an Admin Account get to Administration? slobizman General Help 1 12-29-2007 01:14 PM
[Fixed] Admin security bug kevin1 Bug Report 4 03-05-2007 10:18 AM
HUGE security concern - anybody can promote story instantly shane Bug Report 2 01-20-2006 09:06 PM


Search Engine Friendly URLs by vBSEO 3.2.0