Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 1 of 1
  1. #1
    Registered User
    Join Date
    Nov 2004
    Posts
    4

    Exclamation SECURITY ISSUE: phpCoin Remote File Include Vuln

    The version of PHPCoin that comes with Fantastico is vulnerable to a remote file include vulnerability. What this means is that you can have an attacker essentially pull a file from another server and execute it on your server via PHPCoin.

    Please see: http://downloads.securityfocus.com/v...2.3_fi_poc.txt

    Now, to the best of my knowledge, you should never ever have anyone posting content to that file. So for those of us smart enough to run mod_security, toss this in your modsecurty configuration.



    SecFilter "PKG_PATH_INCL"



    That should take care of it until Fantastico/PHPCoin releases an update.

    Chris Meisinger
    WingSix Hosting
    www.wingsix.com


    edit: Thanks to HalB on the cPanel IRC Channel for pointing this out to me.

    Edit part 2: After a bit of playing with phpCoin, this can be executed through apparently any script in the coin_includes directory, so I've updated the modsec rule to filter that. Beforehand I was just filtering on a single file, now i'm just 403ing everything that uses the PKG_PATH_INCL var in the URL. I can't think of any good reason to include a var like that in a URL. heh
    Last edited by cmeisinger; 08-26-2006 at 10:17 PM.

Similar Threads & Tags
Similar threads

  1. PHP include URL issue
    By brhospedagens in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 06-09-2008, 07:19 AM
  2. can't include() remote website in php / phtml files
    By SoftDux in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 12-10-2007, 01:42 AM
  3. php4 and Zend - issue with include()
    By EWD in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 12-09-2007, 11:32 PM
  4. Security issue - pget file in /tmp
    By jols in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 12-05-2006, 08:18 PM
  5. cPAddons - old versions include security fixes?
    By Duncan in forum cPanel Developers
    Replies: 2
    Last Post: 05-26-2006, 06:07 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube