Welcome, Guest. Please login or register.
Did you miss your activation email?


Login with username, password and session length

Search

 
Advanced search

8043 Posts in 1856 Topics- by 2099 Members - Latest Member: roi
Calendar Script CommunitySetup and InstallationProblems and SolutionsI got a message from a hacker today that he found xss scripting problem
Pages: [1]   Go Down
Print
Author Topic: I got a message from a hacker today that he found xss scripting problem  (Read 1558 times)
0 Members and 1 Guest are viewing this topic.
truthonlytruth
New Member
*

Karma: 0
Offline Offline

Posts: 21

:)


« on: December 27, 2007, 02:25:31 PM »

I got a message from a hacker today that he found xss scripting problem....

http://www.mysite.com/cgi-bin/calendar/calendar_admin.pl?calendar=default&username=%22%3E%3Cscript%3Ealert('Uyari%20:%20Turksad%20and%2019%B2%B3Turk%20Grup')%3C/script%3E


URGENT ACTION NEEDED....

Thanks
Logged
musicvid
New Member
*

Karma: 1
Offline Offline

Posts: 8


WWW
« Reply #1 on: December 27, 2007, 09:50:22 PM »

I got a message from a hacker today that he found xss scripting problem...
You got a message from a hacker? That is indeed remarkable. Were you sent an email, or did the hacker appear at your doorstep?
What version of Calendarscript are you using?
I can't find your page at mysite.com
But I must assume you are telling the truth from your login.
Please enlighten.
« Last Edit: December 28, 2007, 10:32:34 AM by musicvid » Logged
DanO
Full Member
***

Karma: 13
Offline Offline

Posts: 230

Please don't PM me. Post in the open forum.


WWW
« Reply #2 on: December 28, 2007, 09:52:20 PM »


What version of Calendarscript are you using?

Dan O.
Logged
truthonlytruth
New Member
*

Karma: 0
Offline Offline

Posts: 21

:)


« Reply #3 on: December 29, 2007, 11:37:30 PM »

I am not that amatuer to give you my site address in this case to publicly target the site... Just replace the domain with your address and you will see the action...

Latest version....

From no where i got that message in an email and telling me exactly what i told you...

Thanks
« Last Edit: December 29, 2007, 11:39:25 PM by truthonlytruth » Logged
truthonlytruth
New Member
*

Karma: 0
Offline Offline

Posts: 21

:)


« Reply #4 on: January 05, 2008, 12:47:26 PM »

What is going on with this script...

New changes: I thought you guys are going to make somthing out of it...
But your demo is not working and so on...

no answer a simple question...
Logged
DanO
Full Member
***

Karma: 13
Offline Offline

Posts: 230

Please don't PM me. Post in the open forum.


WWW
« Reply #5 on: January 05, 2008, 03:48:29 PM »

What version of Calendarscript are you using?

Dan O.
« Last Edit: January 06, 2008, 05:55:15 PM by DanO » Logged
truthonlytruth
New Member
*

Karma: 0
Offline Offline

Posts: 21

:)


« Reply #6 on: January 06, 2008, 12:29:31 PM »

My previous post i said the latest version...

which is 321

Thanks
Logged
DanO
Full Member
***

Karma: 13
Offline Offline

Posts: 230

Please don't PM me. Post in the open forum.


WWW
« Reply #7 on: January 06, 2008, 06:11:11 PM »

Sorry I missed that statement (possibly since it didn't actually state the version number).

Anyway, I tried the code you supplied with my own calendar and all it does is pop up a JavaScript alter box with the hacker's name in it. That is not quite a critical situation.

I believe (although I could be wrong) that one of the previous bug fixes was to remove any HTML tags from being passed to the script via the command line. Maybe the fix was only made for the calendar.pl file? In any case, running JavaScript code only affects the user's browser, not the script installation itself AFAIK. The same could be done on any web page.

If you have more concerns you should probably bring them to Scott's attention via email.

JMO

Dan O.
« Last Edit: January 06, 2008, 06:14:28 PM by DanO » Logged
truthonlytruth
New Member
*

Karma: 0
Offline Offline

Posts: 21

:)


« Reply #8 on: January 06, 2008, 09:24:39 PM »

I have no idea about Perl scripts that's why i brought here...

What do you mean by Scot's attension???
Logged
DanO
Full Member
***

Karma: 13
Offline Offline

Posts: 230

Please don't PM me. Post in the open forum.


WWW
« Reply #9 on: January 07, 2008, 05:00:23 PM »


What do you mean by Scot's attention?

He owns CalendarScript and is solely responsible for its code. If you have security concerns you should talk to him directly about it via email.

I only help out here in the forums.

Dan O.
Logged
truthonlytruth
New Member
*

Karma: 0
Offline Offline

Posts: 21

:)


« Reply #10 on: January 08, 2008, 12:07:35 AM »

I thought that you guys took over the script...

Oh well,
I will do that...
Thanks
Logged
scott
Administrator
Hero Member
*****

Karma: 10000
Offline Offline

Posts: I am a geek!!



WWW
« Reply #11 on: January 08, 2008, 02:04:40 AM »

What did this hacker tell you? Specifics would be helpful...
Logged

DanO
Full Member
***

Karma: 13
Offline Offline

Posts: 230

Please don't PM me. Post in the open forum.


WWW
« Reply #12 on: January 08, 2008, 05:15:10 PM »


I thought that you guys took over the script...

"You guys" IS Scott which is why I suggested you contact him.

JFYI

Dan O.
Logged
truthonlytruth
New Member
*

Karma: 0
Offline Offline

Posts: 21

:)


« Reply #13 on: January 09, 2008, 11:06:28 PM »

I have received this hotmail email in my mailbox and exactly saying that My script is hacked...
He was telling me that xss scripting used by him... and the link that's all...

I have no idea about Perl scripting and I went thru my admin area and disable admin section of the script until you guys figure that out what this email all about...

http://www.mysite.com/cgi-bin/calendar/calendar_admin.pl?calendar=default&username=%22%3E%3Cscript%3Ealert('Uyari%20:%20Turksad%20and%2019%B2%B3Turk%20Grup')%3C/script%3E


That's it... I was afraid of he is going to do something...

Let me know please...

Thanks
« Last Edit: January 14, 2008, 04:32:45 PM by truthonlytruth » Logged
Pages: [1]   Go Up
Print
Jump to: