Rocksolid Light

News from da outaworlds

mail  files  register  groups  login

Message-ID:  

You will have a long and unpleasant discussion with your supervisor.


comp / comp.security.unix / SQL attack on a formmail

SubjectAuthor
* SQL attack on a formmailThe Doctor
`- Re: SQL attack on a formmailGrant Taylor

1
Subject: SQL attack on a formmail
From: The Doctor
Newsgroups: comp.security.unix, comp.security.misc
Organization: NetKnow News
Date: Fri, 10 Dec 2021 17:17 UTC
Path: eternal-september.org!news.eternal-september.org!reader01.eternal-september.org!reader02.eternal-september.org!news.quux.org!news.nk.ca!.POSTED.doctor.nl2k.ab.ca!not-for-mail
From: doctor@doctor.nl2k.ab.ca (The Doctor)
Newsgroups: comp.security.unix,comp.security.misc
Subject: SQL attack on a formmail
Date: Fri, 10 Dec 2021 17:17:58 -0000 (UTC)
Organization: NetKnow News
Message-ID: <sp0246$2ssi$89@gallifrey.nk.ca>
Injection-Date: Fri, 10 Dec 2021 17:17:58 -0000 (UTC)
Injection-Info: gallifrey.nk.ca; posting-host="doctor.nl2k.ab.ca:204.209.81.1";
logging-data="95122"; mail-complaints-to="usenet@gallifrey.nk.ca"
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: doctor@doctor.nl2k.ab.ca (The Doctor)
View all headers

All right. a formmail form was attacked by a Russian
hacker on Monday using some SQL script.

Anyone seen this before?
--
Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca
Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b
Merry Christmas 2021 and Happy New Year 2022 Beware https://mindspring.com

Subject: Re: SQL attack on a formmail
From: Grant Taylor
Newsgroups: comp.security.unix, comp.security.misc
Organization: TNet Consulting
Date: Fri, 10 Dec 2021 17:34 UTC
References: 1
Path: eternal-september.org!news.eternal-september.org!reader01.eternal-september.org!reader02.eternal-september.org!tncsrv06.tnetconsulting.net!tncsrv09.home.tnetconsulting.net!.POSTED.alpha.home.tnetconsulting.net!not-for-mail
From: gtaylor@tnetconsulting.net (Grant Taylor)
Newsgroups: comp.security.unix,comp.security.misc
Subject: Re: SQL attack on a formmail
Date: Fri, 10 Dec 2021 10:34:49 -0700
Organization: TNet Consulting
Message-ID: <sp034r$sqo$1@tncsrv09.home.tnetconsulting.net>
References: <sp0246$2ssi$89@gallifrey.nk.ca>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Fri, 10 Dec 2021 17:35:23 -0000 (UTC)
Injection-Info: tncsrv09.home.tnetconsulting.net; posting-host="alpha.home.tnetconsulting.net:198.18.18.251";
logging-data="29528"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101
Thunderbird/78.13.0
In-Reply-To: <sp0246$2ssi$89@gallifrey.nk.ca>
Content-Language: en-US
View all headers

On 12/10/21 10:17 AM, The Doctor wrote:
> a formmail form was attacked by hacker on Monday using some SQL script.

What /precisely/ is formmail in this context?

I ask because I've seen a number of things called "formmail" over
decades, with wildly different capabilities and defenses.

> Anyone seen this before?
Yes. I've seen many ... problems ... with various formmail
implementations over the years. Many of the ones that I looked at in
the '00s were -- IMHO -- rooted in formmail trying to be a generic form
handler to send email. The generic nature of it's attempt to be a
simple target to post form content to as a handler made it more than a
little vulnerable. Especially considering that clients could see just
about any if not all protection mechanisms in the page that used formail
as a form action.

I generally avoided such generic formmmail things for that reason and
tended to write specific implementations that hard coded some aspects
(like the target email address) which made it a LOT harder to exploit.

Aside: I'm not quite sure how SQL fits into this overall discussion.
Maybe the version of formmail that you're dealing with uses SQL as a
backend for something. Maybe someone exploited an SQL server and
induced it to do something it shouldn't. There's a LOT of room for
interpretation.

--
Grant. . . .
unix || die

1

rocksolid light 0.9.8
clearnet tor