vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Forum and Server Management (https://vborg.vbsupport.ru/forumdisplay.php?f=232)
-   -   Errors.php? Whats that? (https://vborg.vbsupport.ru/showthread.php?t=196690)

FockerFGAA 11-19-2008 02:07 PM

Errors.php? Whats that?
 
I have been told multiple times by our server host that error.php has caused high server load and this time they said it was running remotely exploitable scripts. Now here is what errors.php says:

PHP Code:

<?include($_REQUEST["error"] . "/errors.php");?>

I have no idea really what would be using that and how that is remotely exploitable, but I figured some of you smarter guys would know.

kermit2 11-19-2008 06:34 PM

I've never heard of errors.php - it's certainly not in my version of vbulletin. That include statement looks very dodgy too. If $_REQUEST isn't being sanitized you've got the potential for a remote file inclusion attack. I'd get rid of that file straight away (or at least rename it or comment that line out)

SEOvB 11-19-2008 07:02 PM

Errors.php isn't part of vBulletin, make sure its not part of Joomla if its to the site in your signature.

FockerFGAA 11-21-2008 12:01 AM

ya this had nothing to do with vbulletin. it was in the joomla area, but when i downloaded newer versions of joomla and checked their files there was no errors.php. i removed the file and the site seems to be running normally. i just had no idea where it came from.


All times are GMT. The time now is 06:31 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01013 seconds
  • Memory Usage 1,711KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_php_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (4)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete