OutToLunch Posted October 9, 2006 Posted October 9, 2006 Message below arrived over the weekend from one of the sec mailing lists - no confirmation of it on the moodle site or other mailing list members yet though... I don't have a moodle install to test the proof of concept on but thought a few people might want to be aware if they run their Moodle in the configuration mentioned below so they can keep an eye out for security updates. Product: moodle 1.6.2 http://www.moodle.org Vulnerability: SQL injection Notes: - SQL injection can be used to obtain password hash - the moodle blog "module" must be enabled - guest access to the blog must be enabled Left the proof of concept code out, wasn't sure it would be welcome here 8O
Geoff Posted October 9, 2006 Posted October 9, 2006 Blog is a third party module is it not? It doesn't seem to be present on my server.
wesleyw Posted October 9, 2006 Posted October 9, 2006 The blog module is on mine by default. BUt my Moodle site doesn't allow guest access. Wes
Geoff Posted October 9, 2006 Posted October 9, 2006 Nope, defineatly no blog module here. I'm using 1.6.2-STABLE. Anyway, see: http://security.moodle.org/ There's already a fix in CVS if you wish to patch early. http://moodle.cvs.sourceforge.net/moodle/moodle/blog/index.php?r1=1.18.2.2&r2=1.18.2.3
OutToLunch Posted October 9, 2006 Author Posted October 9, 2006 Whoops, how did I miss that security centre? Glad it wasn't all hot air anyway...
Geoff Posted October 9, 2006 Posted October 9, 2006 This is also probably a good time to remind everyone to use mod_security to protect their LAMP servers. http://www.modsecurity.org/ I'll see if I can find/cook a snort IDS rule for the above SQL injection attack.
mighty.grey.eagle Posted October 9, 2006 Posted October 9, 2006 Nope, defineatly no blog module here. I'm using 1.6.2-STABLE. That is probably because the blog has been turned off in the administration!!!
Geoff Posted October 9, 2006 Posted October 9, 2006 I was looking physically at the moodle files. I presume the blog module would be hiding in "/mod/blog" which doesn't appear to exist in our install.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now