Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >> General Public > Chit Chat Public
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Chit Chat Public Talk about any thing you want! This forum is public.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 02-10-2005, 10:44 AM
mdwatkin's Avatar
mdwatkin mdwatkin is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Send a message via Yahoo to mdwatkin
AWStats - Vulnerability?

Has anyone seen the eWeek article (http://www.eweek.com/article2/0,1759,1763152,00.asp) about howthe PhpBB.com website was compromised using a flaw in AWStats? We are on 6.1 I believe. Is there any plan to upgrade?
__________________
Mark
Reply With Quote
  #2  
Old 02-10-2005, 01:00 PM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
Yea we know about it.
__________________
Brad Pugh
http://www.vortechhosting.com
------

Local System/Network Monitor
http://nagios.hsphere.cc/
Login:guest Pass:guest
XML FEED http://nagios.hsphere.cc/feed.xml
------

My Other Life:
Reply With Quote
  #3  
Old 02-10-2005, 04:10 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
It's only an issue if you have Allow Manual Update enabled.
Reply With Quote
  #4  
Old 02-10-2005, 07:15 PM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
Well we did update AWstats on all windows servers they are all 6.3 now.

Unix will take a bit of time to update as it does a awstats.pl in every user dir.

Brangwyn did I miss something? What is "Allow Manual Update" I thought it was all AWstats and was in the awstats.pl file that caused the issue from what I read on psofts forum anyway.
__________________
Brad Pugh
http://www.vortechhosting.com
------

Local System/Network Monitor
http://nagios.hsphere.cc/
Login:guest Pass:guest
XML FEED http://nagios.hsphere.cc/feed.xml
------

My Other Life:
Reply With Quote
  #5  
Old 02-10-2005, 08:00 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Straight from the AWStats site

Quote:
Warning, a security hole was recently found in AWStats versions from 5.0 to 6.2 when AWStats is used as a CGI: A remote user can execute arbitrary commands on your server using permissions of your web server user (in most cases user "nobody").
If you use AWStats with another version or with option AllowToUpdateStatsFromBrowser to 0, you are safe. If not, it is highly recommanded to update to 6.3 version that fix this security hole.
Hence I didn't mention the exploit earlier, I thought we had AWStats running without the allow update option.

For those interested it was actually this AWStats exploit that I believe took down the PHPBB2 Home pages... edit this was already pointed out, should have reread the first post myself

Last edited by Brangwyn : 02-10-2005 at 08:02 PM.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
No AWSTATS from 6/29-7/01 jmbeach Chit Chat Public 1 07-05-2004 05:40 PM
mnoGoSearch vulnerability cardmagic Chit Chat Public 0 07-27-2003 05:45 AM


All times are GMT -5. The time now is 09:28 PM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.55923 seconds with 16 queries
[Output: 56.26 Kb. compressed to 52.53 Kb. by saving 3.73 Kb. (6.63%)]