LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > General > litespeed hacked?

Reply
 
Thread Tools Display Modes
  #1  
Old 06-12-2010, 09:02 PM
Nokki Nokki is offline
Member
 
Join Date: Feb 2010
Posts: 10
Default litespeed hacked?

http://r00tsecurity.org/forums/topic...-byte-exploit/

for real?
Reply With Quote
  #2  
Old 06-12-2010, 11:18 PM
JLHC JLHC is offline
Member
 
Join Date: Dec 2008
Location: MY - US
Posts: 31
Also: http://www.webhostingtalk.com/showthread.php?t=955773
Reply With Quote
  #3  
Old 06-13-2010, 02:08 AM
brrr brrr is offline
Senior Member
 
Join Date: Aug 2007
Posts: 94
That doesn't seem like a terribly sophisticated script.

It would be rather strange & disappointing if it does indeed let someone suck up a permissions restricted file off a LSWS server, and perhaps set up the attacker to do even more.

Last edited by brrr; 06-13-2010 at 02:10 AM..
Reply With Quote
  #4  
Old 06-13-2010, 04:05 AM
MikeDVB MikeDVB is offline
Senior Member
 
Join Date: Jul 2009
Posts: 218
Perhaps this is an old bug that was fixed and only affects those that haven't upgraded?

I've tested this on 4.0.13 and 4.0.14 on x86 and x64 and it's not working.
Reply With Quote
  #5  
Old 06-13-2010, 06:34 AM
DanEZPZ DanEZPZ is offline
Senior Member
 
Join Date: Jul 2009
Posts: 53
There's another version floating about which does work.

This needs patching immediately. If the mods want the link to the other version, PM me.
Reply With Quote
  #6  
Old 06-13-2010, 06:58 AM
AndrewT AndrewT is offline
Senior Member
 
Join Date: Jan 2010
Posts: 66
I can confirm that it does work on 4.0.14. A mod_security rule appears to sufficiently block the attempts at this time.
Reply With Quote
  #7  
Old 06-13-2010, 07:00 AM
DanEZPZ DanEZPZ is offline
Senior Member
 
Join Date: Jul 2009
Posts: 53
What rule are you using? There are two versions of this exploit and the rule in the WHT thread only works for one.
Reply With Quote
  #8  
Old 06-13-2010, 07:05 AM
MikeDVB MikeDVB is offline
Senior Member
 
Join Date: Jul 2009
Posts: 218
I've also now verified that this is indeed a legitimate vulnerability and exploit.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 01:46 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.