Bugtraq mailing list archives
Re: Arbitrary code execution in eping plugin
From: oliver () codersquad de
Date: 11 Jun 2005 20:15:09 -0000
Hello, the problem is in function eping_validaddr() in functions.php where the host is checked if it is valid as the name says... But the only check is to see if it is a valid ip adress for eping, here is the code: --------------8<-----------------------------------------8<------------------------------------- function eping_validaddr($eping_hosttocheck) { If (ereg("(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)", $eping_hosttocheck)) { return true; } else { return false; } --------------8<-----------------------------------------8<------------------------------------- I am sorry but I am a coder and my eyes are bleeding when looking at stuff like that so here is my suggestion for replaceing the if-statement: if(preg_match("/^[0-9]{2,3}?\.[0-9]{1,3}?\.[0-9]{1,3}?\.[0-9]{1,3}?$/", $eping_hosttocheck)) So only IP-Adresses are allowed and no kind of code injection is possible. And everyone who thinks 'will he ever stop writeing?' will be disappointed: The same vulnerability also exists in the eTrace modul from E107. It looks like the same Author of the ePing modul. The only difference is the you have to search for 'etrace' instead of 'eping' in the files Greetings from Germany Oliver -- use the force - treat the source http://codersquad.de
Current thread:
- Arbitrary code execution in eping plugin y0int (Jun 09)
- Re: Arbitrary code execution in eping plugin Oliver Monneke (Jun 13)
- Re: Arbitrary code execution in eping plugin Jonathan Angliss (Jun 14)
- Re: Arbitrary code execution in eping plugin Christoph 'knurd' Jeschke (Jun 14)
- Re: Arbitrary code execution in eping plugin Anders Henke (Jun 15)
- Re: Arbitrary code execution in eping plugin Jonathan Angliss (Jun 14)
- Re: Arbitrary code execution in eping plugin Oliver Monneke (Jun 13)
- <Possible follow-ups>
- Re: Arbitrary code execution in eping plugin oliver (Jun 11)
- Re: Arbitrary code execution in eping plugin Sam Michaels (Jun 13)
- Re: Arbitrary code execution in eping plugin exon (Jun 13)