Major security hole exposed!

www.sghackers.org down for weeks due to what I was told is hardware problem. But seems that the hardware problem is not the only problem cuz it exposed the site to a major security vulnerability!

The MIME types dunno what corrupted or what, but it is failing to render x-http-php file headers so browser not only dun understand the returned data, but server dun render the file content or recognise it.

So when server dun render a file especially scripted code, what happens? The server RETURNED THE ENTIRE FILE!

Ya, and since the site run WordPress, you hit wp-config.php and it return the whole file with DB username and password.

Super. Can access phpmyadmin WTF… and if UN/PW same, can also access email, cpanel login, ftp, etc etc.

Advertisement

~ by benghacks on February 22, 2010.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

 
Follow

Get every new post delivered to your Inbox.