 |
Menu |
 |
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
 |
User Info |
 |
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 313
Members: 0
Total: 313
|
|
|
|
|
 |
Full disclosure |
 |
Google Firebase hosting suspension / "malware distribution"bypass
CyberDanube Security Research 20251014-0 | Multiple Vulnerabilities in Phoenix Contact QUINT4 UPS
apis.google.com - Insecure redirect via __lu parameter(exploited in the wild)
Urgent Security Vulnerabilities Discovered in Mercku Routers Model M6a
Re: Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
[SBA-ADV-20250730-01] CVE-2025-39664: Checkmk Path Traversal
[SBA-ADV-20250724-01] CVE-2025-32919: Checkmk Agent Privilege Escalation via Insecure Temporary Files
CVE-2025-59397 - Open Web Analytics SQL Injection
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Re: Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Re: Defense in depth -- the Microsoft way (part 93): SRP/SAFERwhitelisting goes black on Windows 11
Re: [FD]: "Glass Cage" – Zero-Click iMessage ? Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885)
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Samtools v1.22.1 Uncontrolled Memory Allocation from Large BED Intervals Causes Denial-of-Service in Samtools/HTSlib
|
|
|
|
|
|
 |
|
 |
 |
|
 |
IT Security and Insecurity Portal |
|
 |
New phpnuke security advisories will be out very soon! |
 |
Posted: Tue Feb 14, 2006 5:05 pm |
|
|
waraxe |
Site admin |

 |
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
 |
 |
 |
|
Yes, it's true. More Phpnuke holes revealed, so stay in touch!  |
|
Last edited by waraxe on Fri Apr 13, 2007 4:20 pm; edited 1 time in total |
|
|
|
Posted: Tue Feb 14, 2006 5:34 pm |
|
|
Heintz |
Valuable expert |

 |
|
Joined: Jun 12, 2004 |
Posts: 88 |
Location: Estonia/Sweden |
|
|
 |
 |
 |
|
firstable, great work on last advisory.
will be interesting to read the coming ones. hopefully software author respond more sensibly too  |
|
_________________ AT 14:00 /EVERY:1 DHTTP /oindex.php www.waraxe.us:80 | FIND "SA#037" 1>Nul 2>&1 & IF ERRORLEVEL 0 "c:program filesApache.exe stop & DSAY alarmaaa!" |
|
|
|
Posted: Tue Feb 14, 2006 9:03 pm |
|
|
zer0-c00l |
Advanced user |

 |
|
Joined: Jun 25, 2004 |
Posts: 72 |
Location: BRAZIL! |
|
|
 |
 |
 |
|
Good to see you Waraxe  |
|
|
|
|
 |
Re: New phpnuke security advisories will be out very soon! |
 |
Posted: Tue Feb 14, 2006 10:25 pm |
|
|
cXIb8O3 |
Active user |

 |
|
Joined: Feb 17, 2005 |
Posts: 26 |
Location: Poland<>Luxembourg |
|
|
 |
 |
 |
|
waraxe wrote: | Yes, it's true. More Phpnuke holes revealed, so stay in touch!  |
Yeah.. phpnuke something critical? i hope.. i have something in phpnuke.. but i don't like phpnuke... Postnuke is 100% better :] |
|
|
|
|
Posted: Wed Feb 15, 2006 1:34 am |
|
|
shai-tan |
Valuable expert |

 |
|
Joined: Feb 22, 2005 |
Posts: 477 |
|
|
|
 |
 |
 |
|
Or how about "No Nuke" ? lolz. |
|
_________________ Shai-tan
?In short: just say NO TO DRUGS, and maybe you won?t end up like the Hurd people.? -- Linus Torvalds |
|
|
|
Posted: Thu Feb 16, 2006 10:44 pm |
|
|
waraxe |
Site admin |

 |
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
 |
 |
 |
|
Heh, i was going to publish 2 advisories, 1 is not critical and 1 is possible critical, but not the best. But just accidentially, lurking in phpnuke src, i found very interesting sql injection case
Just some minutes ago tested it in real world, and it works in many servers
Weeee, i like phpnuke  |
|
|
|
|
Posted: Fri Feb 17, 2006 6:54 am |
|
|
shai-tan |
Valuable expert |

 |
|
Joined: Feb 22, 2005 |
Posts: 477 |
|
|
|
 |
 |
 |
|
Yes I remember you explaining to me once why you "like" it.
The likes of phpbb and phpnuke hate anyone from outside finding Vulns no matter what the intention is of the founder. Just Arrogant bastards if you ask me. |
|
_________________ Shai-tan
?In short: just say NO TO DRUGS, and maybe you won?t end up like the Hurd people.? -- Linus Torvalds |
|
|
|
 |
 |
|
 |
Posted: Fri Feb 17, 2006 12:08 pm |
|
|
waraxe |
Site admin |

 |
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
 |
 |
 |
|
Phpbb developers are nice people and they really care about security. But phpnuke - this is another case. It is too "fuzzy" project, there are too many webmasters, coders and wannabe programmers, who all try to add some functionality and modify something. All the phpnuke src is filled with legacy code fragments. By looking at nuke src, it seems like good old phpnuke 4.x or 5.x days. What a mess. It is time to rewrite this code from scratch. But Burzi seems to be too lazy for this  |
|
|
|
|
Posted: Sat Feb 18, 2006 2:30 am |
|
|
shai-tan |
Valuable expert |

 |
|
Joined: Feb 22, 2005 |
Posts: 477 |
|
|
|
 |
 |
 |
|
I dont like the phpbb developers they are arrogant but they are better than the phpnuke ones. |
|
_________________ Shai-tan
?In short: just say NO TO DRUGS, and maybe you won?t end up like the Hurd people.? -- Linus Torvalds |
|
|
|
Posted: Sat Feb 18, 2006 2:40 pm |
|
|
waraxe |
Site admin |

 |
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
 |
 |
 |
|
|
|
|
|
Posted: Sun Feb 19, 2006 3:55 pm |
|
|
waraxe |
Site admin |

 |
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
 |
 |
 |
|
So here it is, advisory about critical sql injection in phpNuke:
http://www.waraxe.us/advisory-46.html
Enjoy
P.S. Next advisory will be about some XSS cases and after that - reincarnation of very old and very nasty security hole
Stay in touch!!  |
|
|
|
|
www.waraxe.us Forum Index -> PhpNuke
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|