- OpenX Community Forums

Welcome Guest ( Log In | Register )

2 Pages V   1 2 >  
Reply to this topicStart new topic
> Openx Vulnerability? Banner Ads Compromised Somehow
Robsta
post Mar 23 2010, 10:36 PM
Post #1


Member
**

Group: Members
Posts: 18
Joined: 27-May 09
Member No.: 28,305



I'm not sure where to post this, or who to speak to.

I was using OpenX 2.8.0 until yesterday. Google's 'stopbadware.org' service started to block our forum site in the major browsers. In tracking the problem back to the OpenX service, I promptly upgraded to the latest release, v2.8.5 thinking the vulnerability must be fixed in the current release.

The 'stopbadware.org' service now unblocked the site and stated they were nolonger finding the trojan links. A result I thought.

However. I was on the site this evening, and my AVG suddenly brought up a virus alert. Looking at the page, it shows the malicious code in a small grey box right above the banner image in the centre. The page source does not show it.

I've examined the v2.8.0 files, and found no core file difference compared to the downloaded ZIP. Nothing was found in the database to indicate foul play. I can only surmise that the problem is an injection somehow, but I have no idea.

So. To conclude, the latest release is vulnerable somehow. Unless someone can say to me "here's a patch", I'm going to have to move away from OpenX to something else.... if there is something... I've not looked yet!

I've now removed all the banner placements so that our site does not get blocked again.

Suggestions welcome on fixing this issue.
Go to the top of the page
 
+Quote Post
Robsta
post Mar 24 2010, 07:07 AM
Post #2


Member
**

Group: Members
Posts: 18
Joined: 27-May 09
Member No.: 28,305



Could it be this one?
https://secure1.securityspace.com/smysecure....html?id=100462
Go to the top of the page
 
+Quote Post
Robsta
post Mar 24 2010, 09:57 AM
Post #3


Member
**

Group: Members
Posts: 18
Joined: 27-May 09
Member No.: 28,305



Is this file legitimate: \plugins\bannerTypeHtml\oxHtml\genericHtml.delivery.php

And is there meant to be a gzinflate base64_decode section to the file?
Go to the top of the page
 
+Quote Post
Robsta
post Mar 24 2010, 02:37 PM
Post #4


Member
**

Group: Members
Posts: 18
Joined: 27-May 09
Member No.: 28,305



Looks like I'm not the only one...
http://forum.openx.org/index.php?showtopic=503468161
Go to the top of the page
 
+Quote Post
Spritz
post Mar 24 2010, 06:36 PM
Post #5


Administrator
********

Group: OpenX Consultants
Posts: 1,606
Joined: 8-May 01
From: Ferrara, Italy
Member No.: 1



I've found the very same file hacked on a client server. It's a c99madshell encoded script and you absolutely need to remove those lines from the otherwise legitimate file.
Go to the top of the page
 
+Quote Post
lupusyonderboy
post Mar 24 2010, 06:39 PM
Post #6


Advanced Member
***

Group: Members
Posts: 32
Joined: 13-June 06
Member No.: 11,475



QUOTE (Spritz @ Mar 24 2010, 02:36 PM) *
I've found the very same file hacked on a client server. It's a c99madshell encoded script and you absolutely need to remove those lines from the otherwise legitimate file.


Can you give an excerpt of what the code looks like? We haven't been exploited, but it might help others.
Go to the top of the page
 
+Quote Post
Spritz
post Mar 24 2010, 06:50 PM
Post #7


Administrator
********

Group: OpenX Consultants
Posts: 1,606
Joined: 8-May 01
From: Ferrara, Italy
Member No.: 1



QUOTE (lupusyonderboy @ Mar 24 2010, 07:39 PM) *
QUOTE (Spritz @ Mar 24 2010, 02:36 PM) *
I've found the very same file hacked on a client server. It's a c99madshell encoded script and you absolutely need to remove those lines from the otherwise legitimate file.


Can you give an excerpt of what the code looks like? We haven't been exploited, but it might help others.


something like:

CODE
if (basename($_SERVER['PHP_SELF'])=='genericHtml.delivery.php') {
eval(gzinflate(base64_decode("...")));
die;
}


in /plugins/bannerTypeHtml/oxHtml/genericHtml.delivery.php (affected file may change).

when the file is called directly PHP will execute the encoded shell script, which is nicely described here.

Go to the top of the page
 
+Quote Post
lupusyonderboy
post Mar 24 2010, 07:00 PM
Post #8


Advanced Member
***

Group: Members
Posts: 32
Joined: 13-June 06
Member No.: 11,475



QUOTE (Spritz @ Mar 24 2010, 02:50 PM) *
something like:

CODE
if (basename($_SERVER['PHP_SELF'])=='genericHtml.delivery.php') {
eval(gzinflate(base64_decode("...")));
die;
}


in /plugins/bannerTypeHtml/oxHtml/genericHtml.delivery.php (affected file may change).

when the file is called directly PHP will execute the encoded shell script, which is nicely described here.


So my next question is: How is this file being modified? This doesn't appear to be a simple SQL injection that's modifying append or prepend DB columns. Were the files in question writable by the httpd daemon? Did some version of OpenX get trojaned prior to download?

Go to the top of the page
 
+Quote Post
Spritz
post Mar 24 2010, 07:50 PM
Post #9


Administrator
********

Group: OpenX Consultants
Posts: 1,606
Joined: 8-May 01
From: Ferrara, Italy
Member No.: 1



QUOTE (lupusyonderboy @ Mar 24 2010, 08:00 PM) *
So my next question is: How is this file being modified? This doesn't appear to be a simple SQL injection that's modifying append or prepend DB columns. Were the files in question writable by the httpd daemon? Did some version of OpenX get trojaned prior to download?


That's a very good question. I was able to investigate only a customer server and that question is still unanswered. I can suppose that the box was hacked when 2.8.0 was there. I presume that the upgrade to 2.8.5 just copied over the mangled file, but I still need to verify that.

The file is created by OpenX itself when installing the default plugins, so it's definitely (and must be) writable by the webserver.
Go to the top of the page
 
+Quote Post
Garrett
post Mar 25 2010, 12:57 AM
Post #10


Beginner
*

Group: Members
Posts: 2
Joined: 24-March 10
Member No.: 104,341



Just an FYI, same problem here (2.8.0). I found the offending code in 2 files.
I suspect that the entire openXBannerTypes plugin was affected. Plugin manager shows I have version 1.4.1 of plugin
but openX says the latest is 1.0.1 (mines newer) when I hit upgrade.

I upgraded to 2.8.5 and grep'd the code in these two files and deleted it.
CODE
/www/admin/plugins/openXBannerTypes/index.php
/plugins/bannerTypeHtml/oxHtml/genericHtml.delivery.php


don't see "ads. fake-isp. com" showing up in YSlow anymore. But for how long? Has this happened to anyone not already
infected running 2.8.5?

Would like to just delete this plugin and reinstall it cleanly, possible? Where are the files to install?
Go to the top of the page
 
+Quote Post
Robsta
post Mar 25 2010, 10:25 AM
Post #11


Member
**

Group: Members
Posts: 18
Joined: 27-May 09
Member No.: 28,305



Yes, we installed a clean v2.8.5 set of files, move old v2.8.0 out, move new v2.8.5 files in. However using the same database. Standard upgrade process I thought.

Anyone know where the plugin files get installed from? they're not in the downloaded ZIP. If it's coming from the openx.org people during the upgrade process, could their files have been hacked?
Go to the top of the page
 
+Quote Post
Spritz
post Mar 25 2010, 10:28 AM
Post #12


Administrator
********

Group: OpenX Consultants
Posts: 1,606
Joined: 8-May 01
From: Ferrara, Italy
Member No.: 1



QUOTE (Robsta @ Mar 25 2010, 11:25 AM) *
Yes, we installed a clean v2.8.5 set of files, move old v2.8.0 out, move new v2.8.5 files in. However using the same database. Standard upgrade process I thought.

Anyone know where the plugin files get installed from? they're not in the downloaded ZIP. If it's coming from the openx.org people during the upgrade process, could their files have been hacked?


The default plugin ZIP files are in the etc/plugins directory. It's close to impossible that they have been hacked. One thing I still need to verify is the possibility that a hacked plugin doesn't get overwritten dureing the upgrade (remember that you have to provide the old plugin path?)


Cheers
Go to the top of the page
 
+Quote Post
Robsta
post Mar 25 2010, 10:32 AM
Post #13


Member
**

Group: Members
Posts: 18
Joined: 27-May 09
Member No.: 28,305



QUOTE (Spritz @ Mar 25 2010, 10:28 AM) *
(remember that you have to provide the old plugin path?)
Ahh good point. rolleyes.gif

We've not added any additional plug-ins. So anything there would have come from the default installation. It would not make sense to migrate the default plug-ins to the new upgrade release from the old version would it?
Go to the top of the page
 
+Quote Post
Robsta
post Mar 25 2010, 10:39 AM
Post #14


Member
**

Group: Members
Posts: 18
Joined: 27-May 09
Member No.: 28,305



If it makes any difference... I had forgotten about this, but when I upgraded I had the same upgrade error message as in this post... http://forum.openx.org/index.php?showtopic=503468381
Go to the top of the page
 
+Quote Post
Robsta
post Mar 25 2010, 01:32 PM
Post #15


Member
**

Group: Members
Posts: 18
Joined: 27-May 09
Member No.: 28,305



Ok, getting somewhere I think. I've installed a clean version, got the two plugin directories and replace the live install with those clean plugin directories.

How do I fix the issue of version reporting? the live install still reports them as newer. I deleted one of the plugins from the interface, how can I re-install them? Not worked it out yet.
Go to the top of the page
 
+Quote Post

2 Pages V   1 2 >
Reply to this topicStart new topic

 

Locations of visitors to this page