Current time: 04-26-2024, 05:48 AM Hello There, Guest! (LoginRegister)


Post Reply 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Security hole in ISPCP 1.0.5
Author Message
Nuxwin
Unregistered

 
Post: #2
RE: Security hole in ISPCP 1.0.5
Hello

Ok for logs but you know the procedure for reproduce this attack ? The logs are not relevant. Who is admin, who is reseller, who is customer in the logs ?
(07-14-2010 07:38 AM)Alex Joe Wrote:  Hello,

Unfortunately, it is possible to compromise the password to the panel and carrying out attack on the server.

IP attacker: 188.249.164 and 62.120.196.147

ISPCP Admin log in attachment. Server logs are destroyed by attacker.

Edit: What was broken on your server ? Just for the record:

Code:
User IP: 188.249.164.80 11.07.2010 14:54 Warning! user |1tech.pl| requested |/reseller/domain delete
php?domain_id=157| with REQUEST_METHOD |GET|

is not a security hole since a login checking is made by all called scripts. It's just warning.

The warn occurs when an user like admin or customer call the reseller/domain_delete.php?domain_id=123 directly for example.

Now, just for security reasons, I'll inspect better but please, provides us more information.

Best regards ;
07-14-2010 07:42 AM
Quote this message in a reply
Post Reply 


Messages In This Thread
Security hole in ISPCP 1.0.5 - Alex Joe - 07-14-2010, 07:38 AM
RE: Security hole in ISPCP 1.0.5 - Nuxwin - 07-14-2010 07:42 AM
RE: Security hole in ISPCP 1.0.5 - RatS - 07-14-2010, 05:38 PM
RE: Security hole in ISPCP 1.0.5 - ZooL - 07-15-2010, 06:31 AM
RE: Security hole in ISPCP 1.0.5 - gOOvER - 07-15-2010, 06:56 AM
RE: Security hole in ISPCP 1.0.5 - nuke3d - 07-16-2010, 06:36 PM
RE: Security hole in ISPCP 1.0.5 - kilburn - 07-16-2010, 07:39 PM
RE: Security hole in ISPCP 1.0.5 - joximu - 07-16-2010, 08:12 PM
RE: Security hole in ISPCP 1.0.5 - kilburn - 07-20-2010, 08:32 PM
RE: Security hole in ISPCP 1.0.5 - nuke3d - 07-20-2010, 09:23 PM
RE: Security hole in ISPCP 1.0.5 - joximu - 07-20-2010, 11:16 PM

Forum Jump:


User(s) browsing this thread: 1 Guest(s)