(One of) our worst NiGhTmArE(s)
(One of) our worst NiGhTmArE(s)
Author: Tom de Bruijn
Apr 13th, 2008 at 12:00:00
First of: Download the New NewsOffice 1.1.1 Version.
About the new version
Well this a day we will remember for a while, the first (public) bug ever in a script of Newanz. Oh the joy
What happend?
Today I woke up. Just like any other sunday. I was thinking: what to do? "Mike and Mike's", Shore or just relaxing?
NO!
I logged in, went to check for some errors in our error log, and damnit there were some hack ATTEMPTS to crack NewsOffice. That's just the worst my day could start! I did a quick Google to NewsOffice and yes there it was, the bugsite milw0rm.
RoMaNcYxHaCkEr, found a bug in news_show.php. (for the ones that look for a link to the site, I gave enough keywords for a quick google search?)
So what did I do?
Well first contact some people to start up the project again, this was a bug that was dying to be fixed. And so said, we got right to it.
...3 hours later...
Done, he he, about time security bug fixed and prevent some other access methods we were eager to fix. In the mean time I helped out three people with installing NewsOffice and except for one person, it all worked.
What did we learn? We will keep googeling our projects for reported bugs, but then again, we find them in our error logs too.
One last thing: We got an open letter to RoMaNcYxHaCkEr:
Hello RxH,
We caught your "NewsOffice 1.1 Remote File Include Vulnerabilitiy" page on [filtered]
But of course you know that
Well we didn't like it of course, but are on the other hand happy that someone found it.
So we are happy that you informed people about it, but we aren't happy that people tried to hack our website aswell.
What we know of they failed, our server doesn't allow php to include files from other servers.
Would you be so kind that when you find another leak/bug/exploid to inform us too in advance?
Instead of letting it find us in our error logs?
Thank you,
Tom de Bruijn - Newanz.com
We caught your "NewsOffice 1.1 Remote File Include Vulnerabilitiy" page on [filtered]
But of course you know that

Well we didn't like it of course, but are on the other hand happy that someone found it.
So we are happy that you informed people about it, but we aren't happy that people tried to hack our website aswell.
What we know of they failed, our server doesn't allow php to include files from other servers.
Would you be so kind that when you find another leak/bug/exploid to inform us too in advance?
Instead of letting it find us in our error logs?
Thank you,
Tom de Bruijn - Newanz.com
Thank you for reading,
Tom de Bruijn - Newanz Staff