PostNuke Trojan Horse Vulnerability
BID:11529
Info
PostNuke Trojan Horse Vulnerability
| Bugtraq ID: | 11529 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2004 12:00AM |
| Updated: | Oct 26 2004 12:00AM |
| Credit: | *mheffel* is credited with the discovery of systems that were being compromised by the exploitation of this vulnerability. |
| Vulnerable: |
PostNuke Development Team PostNuke 0.75 |
| Not Vulnerable: | |
Discussion
PostNuke Trojan Horse Vulnerability
It is reported that the server hosting PostNuke, www.postnuke.com, was compromised recently. Additionally, it is reported that the attacker modified the download address of the archive 'PostNuke-0.750.zip'. The new download location contained a trojaned version of the PostNuke archive.
It is reported that users that downloaded the PostNuke archive between Sunday the 24th of Oct 2004 at 23:50 GMT and Tuesday the 26th of Oct 2004 at 8:30 GMT are likely to be affected by this vulnerability.
It is reported that the server hosting PostNuke, www.postnuke.com, was compromised recently. Additionally, it is reported that the attacker modified the download address of the archive 'PostNuke-0.750.zip'. The new download location contained a trojaned version of the PostNuke archive.
It is reported that users that downloaded the PostNuke archive between Sunday the 24th of Oct 2004 at 23:50 GMT and Tuesday the 26th of Oct 2004 at 8:30 GMT are likely to be affected by this vulnerability.
Exploit / POC
PostNuke Trojan Horse Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
PostNuke Trojan Horse Vulnerability
Solution:
The vendor recommends the following actions:
Customers are advised to remove the affected file:
'/includes/pnAPI.php'
This should be replaced with the original file, which is available at the following location:
http://cvs.postnuke.com/viewcvs.cgi/Historic_PostNuke_Library/postnuke-devel/html/includes/pnAPI.php?rev=1.86&content-type=text/vnd.viewcvs-markup)
Modify installation details, for example: 'database details', 'username', 'password' and if possible 'database name'.
Audit HTTP access logs, if an entry is found that contains the string 'oops=', then customers are advised to contact the PostNuke Security Team:
http://forums.postnuke.com/index.php?module=vpContact
Solution:
The vendor recommends the following actions:
Customers are advised to remove the affected file:
'/includes/pnAPI.php'
This should be replaced with the original file, which is available at the following location:
http://cvs.postnuke.com/viewcvs.cgi/Historic_PostNuke_Library/postnuke-devel/html/includes/pnAPI.php?rev=1.86&content-type=text/vnd.viewcvs-markup)
Modify installation details, for example: 'database details', 'username', 'password' and if possible 'database name'.
Audit HTTP access logs, if an entry is found that contains the string 'oops=', then customers are advised to contact the PostNuke Security Team:
http://forums.postnuke.com/index.php?module=vpContact