Is 1.2.5 safe on Apache server with multiple extensions feature?

General project discussion. NOT for help questions.
Post Reply
User avatar
Augustas
Forum Members
Forum Members
Posts: 241
Joined: Wed Oct 17, 2007 6:09 pm

Is 1.2.5 safe on Apache server with multiple extensions feature?

Post by Augustas »

I have noticed that earlier vulnerable file "/modules/FileManager/postlet/javaUpload.php" in the newest CMSMS release (1.2.5) was simply renamed to "javaUpload.php.txt".

I have not checked in detailss how the latest security hole was fixed, but I would like to notice that the Apache servers, where multiple extensions feature is activated (e.g. on host providers like icdsoft, lunarpages), the "javaUpload.php.txt" file might still be executed by PHP parser.

Would be nice if CMSMS developers could confirm that servers with "multiple extensions feature" have no risk using the latest CMSMS release.

PS: If you would like to know if multiple extensions are active on your webhost, simply enter the address of mentioned file inside the browser:
http://www.your-domain.com/modules/File ... ad.php.txt
The answer is YES, if the output is something like this:

Code: Select all

POSTLET REPLY
POSTLET:NO
POSTLET:TOO LARGE
POSTLET:ABORT THIS
END POSTLET REPLY
PPS: My website was also hacked, as I did not manage to upgrade CMSMS in time. brrrrr  ??? would not like it to be repeated...
http://FollowTheRoad.com/ - living on the road...
http://www.kligys.com/ - asmeninis blog'as...
Pierre M.

Re: Is 1.2.5 safe on Apache server with multiple extensions feature?

Post by Pierre M. »

Is destroying (rather than renaming) this "javaUpload.php*" a workaround ?

Pierre M.
calguy1000
Support Guru
Support Guru
Posts: 8169
Joined: Tue Oct 19, 2004 6:44 pm

Re: Is 1.2.5 safe on Apache server with multiple extensions feature?

Post by calguy1000 »

yeah, you can safely nuke all of those files

However, I don't have them on my install... not sure why, maybe I nuked them or something.
Follow me on twitter
Please post system information from "Extensions >> System Information" (there is a bbcode option) on all posts asking for assistance.
--------------------
If you can't bother explaining your problem well, you shouldn't expect much in the way of assistance.
Ziggywigged
Power Poster
Power Poster
Posts: 424
Joined: Sat Feb 02, 2008 12:42 am

Re: Is 1.2.5 safe on Apache server with multiple extensions feature?

Post by Ziggywigged »

Calguy, can you be specific as to which files we can safely delete from the modules/FileManager/postlet folder?

Is it the 2 files:
index.html.txt
javaUpload.php.txt

Thanks.
Last edited by Ziggywigged on Wed Jun 04, 2008 10:19 pm, edited 1 time in total.
Take a penny, leave a penny.
calguy1000
Support Guru
Support Guru
Posts: 8169
Joined: Tue Oct 19, 2004 6:44 pm

Re: Is 1.2.5 safe on Apache server with multiple extensions feature?

Post by calguy1000 »

Yeah, and the uploadTest.html file
Follow me on twitter
Please post system information from "Extensions >> System Information" (there is a bbcode option) on all posts asking for assistance.
--------------------
If you can't bother explaining your problem well, you shouldn't expect much in the way of assistance.
cyberman

Re: Is 1.2.5 safe on Apache server with multiple extensions feature?

Post by cyberman »

Augustas wrote: I have not checked in detailss how the latest security hole was fixed, but I would like to notice that the Apache servers, where multiple extensions feature is activated (e.g. on host providers like icdsoft, lunarpages),
Please read this too

http://wiki.cmsmadesimple.org/index.php ... mall_Guide

It contains also a Apache section ...
Post Reply

Return to “General Discussion”