Pages: [1]   Go Down
  Print  
Author Topic: KNOW HOLES IN SCRIPT  (Read 2017 times)
757jterrell
Administrator
Hero Member
*****
Offline Offline

Posts: 1637



View Profile WWW
« on: July 06, 2010, 03:44:16 AM »

Hello all,

In this thread we are going to talk about know holes in the script and what files need to be removed or the actions needed to remove those holes.

UpdateDB.php: This is an old file that allows people to add stuff to your database. It should be removed immediately if its on your site.  If you have a maderite script it is most likely in there.  All SDR scripts have had this file removed and we usually remove it when a site is upgraded. However, all owners should check to ensure that this file is not on their site. The file is located in the public folder.  

help.php: This is a recent hole that was discovered. It allows people to gain access to your cpanel. Remove it immediately. It located in the public folder. We are working on a new file that does the same thing without creating a hole and will post it in the fix section once its done.

EDIT:  A new help file was added to the SDR 2 script, so its not a problem on them and up. And it has been added to the SDR Basic.

config.php: This file needs to have the permissions on it set to 0644. Please check to ensure that it is not set to 0777, it will allow people to upload stuff into their accounts.

If other files are discovered that create holes or problems, we will post them.

EDIT:  Also, when you are done setting up your sites settings, please make sure that you close the hole on the includes/settings.php and lock your settings. It should be changed from a 0777 settings to a 0644 settings once your settings are set up.


« Last Edit: December 05, 2010, 11:14:02 AM by 757jterrell » Logged

Upgrade to an SDR 3
cARRIE
Administrator
Hero Member
*****
Offline Offline

Posts: 1458



View Profile WWW
« Reply #1 on: July 06, 2010, 06:05:04 PM »


Thanks a lot for this topic.
help.php removed. config.php already had 644 permission.
Logged

gsbux
Full Member
***
Offline Offline

Posts: 185


View Profile
« Reply #2 on: July 29, 2010, 06:00:26 AM »

Thanks JT, unfortunately I had all the three holes in GSBux  Shocked

Fixed them, thanks again.
Logged
757jterrell
Administrator
Hero Member
*****
Offline Offline

Posts: 1637



View Profile WWW
« Reply #3 on: September 16, 2010, 10:44:47 PM »

BIg bug in the Swap Referrals to Cash addon,  it allows members to get the bonus without transferring the referral, Please deactivate this addon until we get a fix posted.


Edit: Fix has been posted here for all SDR 2 and SDR 1 series with it before the 9-15-10 update:

http://auroraadmintraining.info/index.php/topic,875.0.html
« Last Edit: September 18, 2010, 11:08:00 PM by 757jterrell » Logged

Addons
Full Member
***
Offline Offline

Posts: 158


View Profile
« Reply #4 on: September 17, 2010, 03:54:58 PM »

BIg bug in the Swap Referrals to Cash addon,  it allows members to get the bonus without transferring the referral, Please deactivate this addon until we get a fix posted.

Thanks for the info
Logged

757jterrell
Administrator
Hero Member
*****
Offline Offline

Posts: 1637



View Profile WWW
« Reply #5 on: September 18, 2010, 11:07:08 PM »

Fix for the swap referrals to cash add on is provided here:

http://auroraadmintraining.info/index.php/topic,875.0.html

It is also fixed in the SDR 2 9-15-10 update.
« Last Edit: September 18, 2010, 11:41:56 PM by 757jterrell » Logged

divemaster
Newbie
*
Offline Offline

Posts: 35



View Profile
« Reply #6 on: December 21, 2010, 06:11:52 PM »

HI found these do I need to delete them?    /public_html/help.php    And   /public_html/admin2/help.php    are they A breach of security?  and how just right click delete them? And I was reading some were it said it's not A good idea to keep your backups on cpanel where would you keep them on your PC?   
Logged
cARRIE
Administrator
Hero Member
*****
Offline Offline

Posts: 1458



View Profile WWW
« Reply #7 on: December 22, 2010, 10:19:57 AM »

Replace only public_html/help.php file with this file
http://auroraadmintraining.info/index.php/topic,583.0.html
admin2/help.php is fine.

Never keep the backup files in the public_html folder, they are damn easy to download, the best place for backup is your pc.
Logged

757jterrell
Administrator
Hero Member
*****
Offline Offline

Posts: 1637



View Profile WWW
« Reply #8 on: December 22, 2010, 11:23:24 AM »

The help file was updated to a newer version that does not create a hole on the SDR 2 on the 9-15-10 update and on the SDR Basic on the 11-15-10 update. If your scripts are not since these updates, then you should replace the help.php file.  The admin2 one is ok.
Logged

chicoi08
Full Member
***
Offline Offline

Posts: 237


View Profile WWW
« Reply #9 on: April 04, 2011, 11:50:54 AM »

I accidentally deleted my backupDB.php

Can anyone upload it? thanks!
Logged

cARRIE
Administrator
Hero Member
*****
Offline Offline

Posts: 1458



View Profile WWW
« Reply #10 on: April 04, 2011, 11:59:21 AM »

I accidentally deleted my backupDB.php

Can anyone upload it? thanks!

Here it is
backupDB.zip
Logged

chicoi08
Full Member
***
Offline Offline

Posts: 237


View Profile WWW
« Reply #11 on: April 04, 2011, 12:08:45 PM »

Here it is
backupDB.zip


Thank you cARRIE.
Logged

cARRIE
Administrator
Hero Member
*****
Offline Offline

Posts: 1458



View Profile WWW
« Reply #12 on: April 05, 2011, 07:24:26 AM »

You're welcome  Wink
Logged

Get a SDR 3 NOW at http://ptcfactory.info

The best and most up to date Aurora script in the market!!
Pages: [1]   Go Up
  Print  
 
Jump to: