![]() |
litespeed hacked?
|
|
That doesn't seem like a terribly sophisticated script.
It would be rather strange & disappointing if it does indeed let someone suck up a permissions restricted file off a LSWS server, and perhaps set up the attacker to do even more. |
Perhaps this is an old bug that was fixed and only affects those that haven't upgraded?
I've tested this on 4.0.13 and 4.0.14 on x86 and x64 and it's not working. |
There's another version floating about which does work.
This needs patching immediately. If the mods want the link to the other version, PM me. |
I can confirm that it does work on 4.0.14. A mod_security rule appears to sufficiently block the attempts at this time.
|
What rule are you using? There are two versions of this exploit and the rule in the WHT thread only works for one.
|
The one on WHT.
Do you have a rule for this other exploit? Or maybe you can PM me the link to it and I can see if we can get one working. |
I've also now verified that this is indeed a legitimate vulnerability and exploit.
|
Quote:
Due to monthly cost - or yearly I'm shocked this hasn't been patched up yet or announced by LiteSpeed, though I do understand it's weekend should someone give then a ring a ding? |
| All times are GMT -7. The time now is 10:55 AM. |