ok osi got hacked, here are the details of my findings ***this post was added on the main site irc.cyberarmy.com Posted on Tuesday, September 17 @ 04:06:43 EDT by m101 [ Edit | Delete ] Sorry to inform you people in irc.cyberarmy.com that you have to be sorrily disappointed. This is just to prove to you that i did do it within the thirty minutes time period set. Sorry to any that i have inconvenienced by this action... m101 ~Your Fate has been decided... ***m101 also added himself as an admin user *** his irc connection was as follows m101 is cgiirc@CDB9204.549D004F.7D32077F.IP * [cb99e792] Ictoadd.com CGI:IRC User m101 is using modes +x m101 is connecting from *@209.151.80.64 m101 on #cyberarmy m101 using ctroc.cyberarmy.com Levels of perfection, go figure. m101 has been idle 1min 24secs, signed on Tue Sep 17 09:02:05 m101 End of /WHOIS list. appears to be also known as {Dark^Wolf} *** here is the log of my conversation with him following the breach Start of m101 buffer: Tue Sep 17 10:18:34 2002 Session Ident: m101 (moos@2867FCF5.D6DA63FF.6A6BACC5.IP) cmon, talk to me thanks aah whats your nick on the site ? yeah, i removed the post, and your author do i need to change all the admin accounts too? nah didnt touch any of them no, but did you exploit one to add yourself? i didnt touch the db either no i didnt exploit any admin passes or anything or was it a reply via personal msg cookie hack? within half an hour? i dont know anything about half an hour it would take me longer than that to crack a md5 hash you dont need to you can just use the admin cookie hmm nope but you added yourself as an admin i could, but didnt wanna share the trick? or its for me to find out ;-) its to do with a form of script injection already documented? basically making it redirect other requests so that they do as i wish and no it isnt documented ah nice your famous ;-) care to recommend corrective action? not right now, in a few mins im on a public box dont like leaving stuff around ya k could you atleast post that i did it in the main chan? sure you did well thanks your barnseyboy? topic fair enough? thanks you will enlighten me later? sure i appreciate your position on this your barnseyboy? i am would have been helpful to know, bb didnt click ;) heh i havent seen u around talk tomorow sorry, gtg home thing is i gotta work soon, dont fuck with the site again please, you made the point, and i would like to hear more about how you did it No such nick/channel back... hey man hey >> thing is i gotta work soon, dont fuck with the site again please, you made the point, and i would like to hear more about how you did it i told you i wouldnt so, which script is vulnerable? and dont say all ;-) can i just state, i aint one of the lame fucked up script kiddies who would deface your site at the first chance he could unfortunately most of your site is vulnerable =/ well atleast to diferent forms of attacks yeahm, i can see your not a lamer so, obviously im keen to try and patch the site where posisble at least from the exact same attack u just did sorry dc yeahm, i can see your not a lamer so, obviously im keen to try and patch the site where posisble at least from the exact same attack u just did two things, dont release the exploit, sorry to be a hard ass about it, but i know 9600 sites on google that are vulnerable to it k i dont want them to be hacked by lamers also, in preference, could ya leave me with some form of admin account no, admin accounts are for osi staff members, unless u wanna be in osi, then that would be impossible you want a new less active staff member then ;) lol i dont want to be blackmailed into that position thats all staff members who are admins work hard for osi nah, no blackmail its worth an ask anyway ;) well i like your style but i dont know ya your not a ca member im familiar with and i havent seen you at osi before ofcourse not i like to be a rogue k but you have no interest in open source development? ofcourse i do im working on three projects atm and two are idle aah well thats different then ;-) * bb thought u were just a mercenary hacker ;-) lol anyway, you want to know which sections are vulnerable to this kinda exploit? go ahread your polls are vuln to any partial admin story vuln to anyone, but easily fixed memberlist also vuln to everyone, not as easy to fix, but still pretty easy the fact you are using phpnuke creates some issues as cookies are easy to come by postnuke has a nicer form for cookies recent articles are vuln i havent looked, but i believe the forums may possibly be vuln depending on how you have them setup the approach i took was somewhere inbetween the lot a bit of a mix and you chose us why? and hell more advanced code than an average attacker would take to get the same result oh, thats easy i came into #cyberarmy and basically they said people were trying to hack ca as a whole and i said, couldnt be that hard and they started insulting me etc... calling me lame so i said that i would hack a division of ca within thirty minutes you just happened to be the nicest looking site sorry if i have caused any inconvenience aah k no not at all like most of these attacks they are eyeopeners ca doesnt get hacked much at all very rarely well its not a phpnuke site oh, i could go for ca if i wanted do it man ;-) i bet i could get it with enough time sure nothings impossible right ofcourse not and for fixing just better parsing of input? not quite your in a hole with phpnuke unfortunately its got too many modules to fix yeah we are migrating to postnuke but its a real pain like zzine? dunno could you change it to 15 minutes, as 10 minutes is well... not truthful cmon > gimme some pointers for patching the site filter all html out of anything at alll anything and everything i looked at your admin list only have one admin the rest user style admins but that didnt affect your hack thought right? nope but if i didnt take the same approach, it would have k if i was to, for example do cookie stealing, then it would majorly my recommendation is to not even have your own account super user only log in as god when you really need to partial admins could still exploit your site for god as it is, but with a whole load of effort but atm they could just take the db, crack it and they have your pass any other questions? thanks for your time btw np dont worry, im honourable, i wont give out my pass or add people i wouldnt get anywhere if i shafted everyone i came across my pass? i dont believe you have any passes if you added me that is aah k yeah i can see your honourable ;-) you should meet this guy im tutoring, as dishonourable as shit, took him ages to get anywhere ;) lol u tried our programming challenges? no chance, im very busy these days lol ill do them when i get a chance it took me around six months to find enough time to finish arcanum =/ some of them require more than two minutes thought aah im on 5 5 programming left the trianlge of numbers <{Dark^Wolf}> ? i aint at home friends place ok well i gotta go work we will come up with a plan of action to try and mimize risk have fun, talk some other time perhaps i run it past you when your around will do k and thanks again for the reality check no prob at all End of m101 buffer Tue Sep 17 10:18:34 2002