Forums / Developer / eZ publish 3.2 vulnerable to spam attacks

eZ publish 3.2 vulnerable to spam attacks

Author Message

Roy Viggo Pedersen

Friday 24 October 2003 8:13:55 am

The new /form/process function in 3.2 makes it possible to use eZ publish to send spam. Both sender and receiver email address are sent to the function as HTTP POST variables, and the email is sent without any checking where the response came from. All eZ 3.2 sites that use /form/process (need access to form module by Anonymous role) can therefore be used by spammers.

I've made a mod that use a hidden id (ContentObjectID) in the form, and a modified process.php that fetch the content object. The object is of class Form, which contain all the fields needed to send the email. In that way, email is always sent to the receiver. A little better, but not perfect.

I hope this function get some attention in eZ 3.3?

Check out the mod:
http://ez.no/developer/ez_publish_3/contributions/form_processing_spam_prevention_mod

Roy Viggo Pedersen

Paul Forsyth

Friday 24 October 2003 8:32:09 am

Im sure it will. Security is always a priority.

paul

Jan Borsodi

Monday 27 October 2003 7:05:34 am

I'm currently looking into this problem, the fix will be part of the 3.2-3 release.
Thanks for the notice.

--
Amos

Documentation: http://ez.no/ez_publish/documentation
FAQ: http://ez.no/ez_publish/documentation/faq

Jan Borsodi

Tuesday 28 October 2003 2:11:25 am

The module will be turned off by default in 3.2-3 and 3.3 (uses a separate setting). The reason for this is that the module is insecure by design and should only be used if you really need this kind of functionality.

As for 3.3 I would recommend using the new revised information collector system, you will be able to do the same things you have in your fix.

--
Amos

Documentation: http://ez.no/ez_publish/documentation
FAQ: http://ez.no/ez_publish/documentation/faq

Paul Forsyth

Tuesday 28 October 2003 2:24:11 am

Does this affect current 3.2-2 information collectors? We have several sites using this.

Paul

Jan Borsodi

Tuesday 28 October 2003 4:16:32 am

The 'spam attack' problem is not in the information collection system but in the separate form module.
This module will fetch all POST variables, generate a mail out of it and send it.

--
Amos

Documentation: http://ez.no/ez_publish/documentation
FAQ: http://ez.no/ez_publish/documentation/faq

Paul Forsyth

Tuesday 28 October 2003 4:22:27 am

My post was referring to the switching off of the process module. You mentioned that users should use the new improved information collecter routines in ez3.3. If the form module is seperate why mention this?

This implied that the switching of the module affects current info collector routines. Does it?

paul

Jan Borsodi

Wednesday 29 October 2003 1:47:36 am

> This implied that the switching of the module affects current
> info collector routines. Does it?

No, the switch is only for the form/process module.

--
Amos

Documentation: http://ez.no/ez_publish/documentation
FAQ: http://ez.no/ez_publish/documentation/faq

eZ debug

Timing: Jan 18 2025 16:00:57
Script start
Timing: Jan 18 2025 16:00:57
Module start 'content'
Timing: Jan 18 2025 16:00:58
Module end 'content'
Timing: Jan 18 2025 16:00:58
Script end

Main resources:

Total runtime0.8437 sec
Peak memory usage4,096.0000 KB
Database Queries211

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0084 589.2734180.8125
Module start 'content' 0.00840.7162 770.0859626.4922
Module end 'content' 0.72460.1191 1,396.5781341.0547
Script end 0.8436  1,737.6328 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00450.5293210.0002
Check MTime0.00150.1745210.0001
Mysql Total
Database connection0.00110.130810.0011
Mysqli_queries0.762890.41202110.0036
Looping result0.00210.25312090.0000
Template Total0.813296.420.4066
Template load0.00220.262620.0011
Template processing0.811096.122420.4055
Template load and register function0.00010.017210.0001
states
state_id_array0.00110.129810.0011
state_identifier_array0.00100.120720.0005
Override
Cache load0.00190.2300360.0001
Sytem overhead
Fetch class attribute can translate value0.00160.191940.0004
Fetch class attribute name0.00200.240590.0002
XML
Image XML parsing0.00200.237340.0005
class_abstraction
Instantiating content class attribute0.00000.0028120.0000
General
dbfile0.00370.4400280.0001
String conversion0.00000.000630.0000
Note: percentages do not add up to 100% because some accumulators overlap

CSS/JS files loaded with "ezjscPacker" during request:

CacheTypePacklevelSourceFiles
CSS0extension/community/design/community/stylesheets/ext/jquery.autocomplete.css
extension/community_design/design/suncana/stylesheets/scrollbars.css
extension/community_design/design/suncana/stylesheets/tabs.css
extension/community_design/design/suncana/stylesheets/roadmap.css
extension/community_design/design/suncana/stylesheets/content.css
extension/community_design/design/suncana/stylesheets/star-rating.css
extension/community_design/design/suncana/stylesheets/syntax_and_custom_tags.css
extension/community_design/design/suncana/stylesheets/buttons.css
extension/community_design/design/suncana/stylesheets/tweetbox.css
extension/community_design/design/suncana/stylesheets/jquery.fancybox-1.3.4.css
extension/bcsmoothgallery/design/standard/stylesheets/magnific-popup.css
extension/sevenx/design/simple/stylesheets/star_rating.css
extension/sevenx/design/simple/stylesheets/libs/fontawesome/css/all.min.css
extension/sevenx/design/simple/stylesheets/main.v02.css
extension/sevenx/design/simple/stylesheets/main.v02.res.css
JS0extension/ezjscore/design/standard/lib/yui/3.17.2/build/yui/yui-min.js
extension/ezjscore/design/standard/javascript/jquery-3.7.0.min.js
extension/community_design/design/suncana/javascript/jquery.ui.core.min.js
extension/community_design/design/suncana/javascript/jquery.ui.widget.min.js
extension/community_design/design/suncana/javascript/jquery.easing.1.3.js
extension/community_design/design/suncana/javascript/jquery.ui.tabs.js
extension/community_design/design/suncana/javascript/jquery.hoverIntent.min.js
extension/community_design/design/suncana/javascript/jquery.popmenu.js
extension/community_design/design/suncana/javascript/jScrollPane.js
extension/community_design/design/suncana/javascript/jquery.mousewheel.js
extension/community_design/design/suncana/javascript/jquery.cycle.all.js
extension/sevenx/design/simple/javascript/jquery.scrollTo.js
extension/community_design/design/suncana/javascript/jquery.cookie.js
extension/community_design/design/suncana/javascript/ezstarrating_jquery.js
extension/community_design/design/suncana/javascript/jquery.initboxes.js
extension/community_design/design/suncana/javascript/app.js
extension/community_design/design/suncana/javascript/twitterwidget.js
extension/community_design/design/suncana/javascript/community.js
extension/community_design/design/suncana/javascript/roadmap.js
extension/community_design/design/suncana/javascript/ez.js
extension/community_design/design/suncana/javascript/ezshareevents.js
extension/sevenx/design/simple/javascript/main.js

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1node/view/full.tplfull/forum_topic.tplextension/sevenx/design/simple/override/templates/full/forum_topic.tplEdit templateOverride template
8content/datatype/view/ezxmltext.tpl<No override>extension/community_design/design/suncana/templates/content/datatype/view/ezxmltext.tplEdit templateOverride template
9content/datatype/view/ezxmltags/paragraph.tpl<No override>extension/ezwebin/design/ezwebin/templates/content/datatype/view/ezxmltags/paragraph.tplEdit templateOverride template
4content/datatype/view/ezxmltags/line.tpl<No override>design/standard/templates/content/datatype/view/ezxmltags/line.tplEdit templateOverride template
4content/datatype/view/ezimage.tpl<No override>extension/sevenx/design/simple/templates/content/datatype/view/ezimage.tplEdit templateOverride template
1pagelayout.tpl<No override>extension/sevenx/design/simple/templates/pagelayout.tplEdit templateOverride template
 Number of times templates used: 27
 Number of unique templates used: 6

Time used to render debug report: 0.0001 secs