Welcome, Guest. Please Login or Register.
April 29, 2025, 11:25:53 PM
Home Help Search Log in Register
News: If you are still using YaBB SE, please consider upgrading to SMF as soon as possible.

YaBB SE Community  |  General Category  |  Feedback  |  YaBB SE Flawe « previous next »
Pages: [1] Reply Ignore Print
Author Topic: YaBB SE Flawe  (Read 1009 times)
Forum Doveloper
Noobie
*
Posts: 42


YaBB SE Flawe
« on: August 25, 2002, 10:11:05 PM »
Reply with quote

MIME. exploit  virus. (I disabled sendmail) it infected the display.php then it hit strait for the admin.php, subs.php, and index.php (basically the hub where the virus can spread rapidly) then it attempted to use the send mail (Disabled it) to duplicate and spread itself.

It only took minutes. I had to use NetSheild to clean the virus. You  guys should really dovelop some file to combat this. Not only will it save people trouble but it will also put YaBB SE ahead of other BBS.

You should seriously consider it because there are heavy loaded internet viruses out there.
Logged
mediman
Support Team
YaBB God
*****
Posts: 2858


WWW
Re:YaBB SE Flawe
« Reply #1 on: August 25, 2002, 10:30:34 PM »
Reply with quote

your php files was infected by a mime virus that used the mime header bug ???

mediman



Logged

mainComm Dev Team
Forum Doveloper
Noobie
*
Posts: 42


Re:YaBB SE Flawe
« Reply #2 on: August 25, 2002, 10:37:18 PM »
Reply with quote

No Mime.exploit virus is kinda like a Worm + virus + trojan. You see Once an infected system visits the board this virus is automatically transfered, or if the person who has the virus even trys to put it on attachment or has it on there default IE program it infects the system automatically. Regardless of anything. Index.php uses a different type of veiwing so in this case index.php serves as a hub to infect all other files. Then whoever visits the board contracts the virus.

This is a flawe most BBS have so if you are capable of doveloping something to trap/ prevent this YaBB would be a much safer board to use thus improving its status to a 'suggested board'
Logged
David
Destroyer Dave
Global Moderator
YaBB God
*****
Posts: 5761


I'm not a llama!

WWW
Re:YaBB SE Flawe
« Reply #3 on: August 25, 2002, 10:38:49 PM »
Reply with quote

Feel like giving us a link to a Symantec or other virus site about this?
Logged

Forum Doveloper
Noobie
*
Posts: 42


Re:YaBB SE Flawe
« Reply #4 on: August 25, 2002, 10:44:36 PM »
Reply with quote

go to http://vil.mcafee.com/dispVirus.asp?virus_k=99273
I took the virus from the e-mail and placed it into my IE Beta version folder (I using IE Stable) and used it on Yabb
Logged
mediman
Support Team
YaBB God
*****
Posts: 2858


WWW
Re:YaBB SE Flawe
« Reply #5 on: August 25, 2002, 10:45:56 PM »
Reply with quote

Yes, please a link! I know about Pirus.PHP but this is another story.

mediman
Logged

mainComm Dev Team
Forum Doveloper
Noobie
*
Posts: 42


Re:YaBB SE Flawe
« Reply #6 on: August 25, 2002, 10:52:08 PM »
Reply with quote

I already gave the link in my last post... Now Onto virus #2 http://vil.mcafee.com/dispVirus.asp?virus_k=98882
that page give you info on JS/Seeker.gen virus. I used it on YaBB SE and it proved affective. It slowly crippled the test server so I had to use desperate measures. this has no impact on the user of the board untill the server is fully corupted in which time it trys to spread itself.
Logged
mediman
Support Team
YaBB God
*****
Posts: 2858


WWW
Re:YaBB SE Flawe
« Reply #7 on: August 25, 2002, 11:05:42 PM »
Reply with quote

i know it was that header thing! there is no way to make yabbse more secure with this prob. maybe php, but not yabbse!

this virus change the mime information into the email header, not into the attached file!

here“s a patch for this header security hole!

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS01-020.asp

mediman
« Last Edit: August 25, 2002, 11:07:13 PM by mediman » Logged

mainComm Dev Team
chris
Guest
Re:YaBB SE Flawe
« Reply #8 on: September 03, 2002, 12:18:52 PM »
Reply with quote

Quote from: Forum Doveloper on August 25, 2002, 10:11:05 PMMIME. exploit  virus. (I disabled sendmail) it infected the display.php then it hit strait for the admin.php, subs.php, and index.php (basically the hub where the virus can spread rapidly) then it attempted to use the send mail (Disabled it) to duplicate and spread itself.

It only took minutes. I had to use NetSheild to clean the virus. You  guys should really dovelop some file to combat this. Not only will it save people trouble but it will also put YaBB SE ahead of other BBS.

You should seriously consider it because there are heavy loaded internet viruses out there.

On which OS was YaBB running? What exactly did the virus do?

It shouldn't be the task of a bulletin board to protect the server against Bugs in the WebServer/Operating System/Browser....

At least thats my opinion.
Logged
Pages: [1] Reply Ignore Print 
YaBB SE Community  |  General Category  |  Feedback  |  YaBB SE Flawe « previous - next »
 


Powered by MySQL Powered by PHP YaBB SE Community | Powered by YaBB SE
© 2001-2003, YaBB SE Dev Team. All Rights Reserved.
SMF 2.1.4 © 2023, Simple Machines
Valid XHTML 1.0! Valid CSS

Page created in 0.125 seconds with 21 queries.