Part of the EllisLab Network
pMachine Pro has been replaced by ExpressionEngine, our full featured web publishing solution. Please consider upgrading.
You can download pMachine Pro here: Download pMachine Pro  |  Download Language Packs
   
 
xml-rpc exploit?
Posted: 04 July 2005 11:44 PM   [ Ignore ]  
Grad Student
Rank
Total Posts:  42
Joined  2003-09-27

http://it.slashdot.org/article.pl?sid=05/07/04/2153224&tid=95&tid=172&tid=169

Is pmachine vulnerable to this attack.. and if so is there a fix?

Profile
 
 
Posted: 05 July 2005 01:15 AM   [ Ignore ]   [ # 1 ]  
Administrator
Avatar
RankRankRankRankRank
Total Posts:  2541
Joined  2001-12-21

This is a PHP flaw that can only be fixed by updating your PHP installation with the patches, it’s not an application problem.  Contact your hosting provider if they are not aware of the problem.

 Signature 
Profile
 
 
Posted: 05 July 2005 01:38 AM   [ Ignore ]   [ # 2 ]  
Administrator
Avatar
RankRankRankRankRank
Total Posts:  2541
Joined  2001-12-21

Actually…the initial security report we saw from Netcraft earlier indicated this was purely a PHP flaw, but there are conflicting reports.  We’ll look into it.

 Signature 
Profile
 
 
Posted: 05 July 2005 02:08 PM   [ Ignore ]   [ # 3 ]  
Research Scientist
Avatar
RankRankRankRankRankRank
Total Posts:  9868
Joined  2002-06-19

See the new announcement.

 Signature 

Chris Curtis
chriscurtis.org

Profile
 
 
Posted: 08 July 2005 01:09 PM   [ Ignore ]   [ # 4 ]  
Research Assistant
Avatar
RankRankRank
Total Posts:  420
Joined  2004-10-10

Was this annoucement sent out to the newsletter? I did not see an annoucement. I thought that security issues were to be sent via the newsletter - am I wrong or did I just miss it?

Profile
 
 
Posted: 11 October 2005 04:08 PM   [ Ignore ]   [ # 5 ]  
Summer Student
Total Posts:  1
Joined  2005-10-11
Chris Curtis - 05 July 2005 02:08 PM

See the new announcement.

Something went bad here…
Can not access the url
http://expressionengine.com/forums/viewannounce/24385_19/

Error
The following errors were encountered
You are not authorized to perform this action

All I came here for is to find information about the xmlrpc exploit.

I signed up on this board, and still can’t access this page. - Same error as above.

I am denied access to security information.

I just want to make sure my server is not exploitable by the xmlrpc.inc files that are INSIDE Pmachine_Free

If she is exploitable, I will probably see sh, bash, httpd, r0nin or some such worms uploaded soon.

cPanel has fantastico.
Fantastico has Pmachine_Free
Pmachine_Free doesn’t say what version she is.
I look physically at the index.php and it says Version 2.3

This all is supposed to be updated nightly in cPanel
I don’t always like automated things.
Anyway as a sanity check. I do a
locate xmlrpc.inc

and I see master_files/Pmachine_Free/pm/xmlrpc/xmlrpc.inc
among others I am tracking down.

Assuming, this is the NEW install source directory.

Is she patched up or is she supposed to be removed?
If she is patched,  may I please get a md5sum for a patched xmlrpc.inc, and xmlrpcs.inc?

It says v1.20 2003/1/10/  22:01:56 in the comments.

some other examples..to get you to understand where I am coming from
PostNuke I have to physically delete these files. and turn it off in admin. New builds are not gonna have xmlrpc
Drupal - latest version is patched.

PS.  could you please make a security forum, or www.pmachine.com/security
      or something that anonymous (non-registered board members) can check for security at a GLANCE.
      I came in on the fly to help someone lock down their box.

PSPS       I CURRENTLY suggest she TURN OFF IN CPANEL, fantastico’s Pmachine_Free until I solve this - savvy?
              so please get back to me.

Profile
 
 
Posted: 11 October 2005 05:31 PM   [ Ignore ]   [ # 6 ]  
Administrator
Avatar
RankRankRankRankRank
Total Posts:  2541
Joined  2001-12-21

pM Free isn’t even available anymore.  It’s been replaced with pM Pro, which you can download from our download area.  You are encouraged to update to the latest version rather than continuing to use the fantastico version.  We notified Fantastico long ago that the version is out of date but they have not updated it.

 Signature 
Profile
 
 
   
 
 
Post Marker Legend
New Topic New posts Hot Topic Hot Topic with new posts New Poll New Poll Moved Topic Moved Topic Sticky Topic Sticky topic
Old Topic No new posts Hot Old Topic Hot Topic with no new posts Old Poll Old Poll Closed Topic Closed Topic Announcement Announcements
Theme
Change Theme
Visitor Statistics
The most visitors ever was 233, on December 18, 2007 12:04 AM
Total Registered Members: 65017 Total Logged-in Users: 0
Total Topics: 82099 Total Anonymous Users: 0
Total Replies: 441208 Total Guests: 23
Total Posts: 523307    
Members ( View Memberlist )
Active Members: