| Value | Definition |
| 0 | No Access | " . "
| 1 | Execute Access | " . "
| 2 | Write Access | " . "
| 3 | Execute & Write Access | " . "
| 4 | Read Access | " . "
| 5 | Execute & Read Access | " . "
| 6 | Write & Read Access | " . "
| 7 | Execute, Write, & Read Access | " . "
| Explanation |
| A bold three digit number will be displayed below after each directory and file listing (resource). The leftmost digit signifies the Owner of the resource. The middle digit signifies the Group the resource belongs to. Lastly, the rightmost digit signifies the rest of the world, or All. | "
. "
| Example: 777 = Owner, Group, and All have full Execute, Write, & Read Access. Example: 541 = Owner has Execute & Read Access, Group has Read Access, and All others have only Execute Access. Example: 644 = Owner has Write & Read Access, both Group and All others have only Read Access. | "
. "
| Type | Value |
| dbhost | $dbhost |
| dbname | $dbname |
| dbuname | $dbuname |
| prefix | $prefix |
| user_prefix | $user_prefix |
| dbtype | $dbtype |
| Type | Value |
| dbhost | $dbhost |
| dbname | $dbname |
| dbuname | $dbuname |
| prefix | $prefix |
| user_prefix | $user_prefix |
| dbtype | $dbtype |
| PHP Version | Reason For Vulnerability |
| ". phpversion() ." | This PHP version contains a vulnerability in \"php_mime_split\" function allowing arbitrary code execution. Tell your host to read the CERT/CC Vulnerability Note VU#297363 by clicking --> here. Until that is resolved, PHP-Nuke should be the least of your worries. |
| PHP Version | Reason For Vulnerability |
| ". phpversion() ." | This PHP version contains a file uploads vulnerability. Tell your host to read the e-matters Advisory 01/2002 by clicking --> here. Until that is resolved, PHP-Nuke should be the least of your worries. |
| PHP Version | Reason For Vulnerability |
| ". phpversion() ." | This PHP version fails to properly parse the headers of HTTP POST requests. Tell your host to read the CERT/CC Vulnerability Note VU#929115 by clicking --> here. Until that is resolved, PHP-Nuke should be the least of your worries. Please reference PHP.net directly for a full review of this serious vulnerability: --> click here. |
| PHP Version | Reason For Vulnerability |
| ". phpversion() ." | PHP Security Advisory: CGI vulnerability in PHP version 4.3.0. PHP contains code for preventing direct access to the CGI binary with configure option \"--enable-force-cgi-redirect\" and php.ini option \"cgi.force_redirect\". In PHP 4.3.0 there is a bug which renders these options useless. For a full report go here --> here. Solution is to upgrade to PHP 4.3.1 as there are no other workarounds. The impact: \"Anyone with access to websites hosted on a web server which employs the CGI module may exploit this vulnerability to gain access to any file readable by the user under which the webserver runs. A remote attacker could also trick PHP into executing arbitrary PHP code if attacker is able to inject the code into files accessible by the CGI. This could be for example the web server access-logs.\" Until that is resolved, PHP-Nuke should be the least of your worries. . |
| MySQL Server Version | Reason For Vulnerability |
| ". mysql_get_server_info() ." | A vulnerability has been discovered in MySQL that may cause a denial of service. It has been reported that, under certain circumstances, a malicious MySQL client may be able to trigger a condition in which MySQL attempts to free the same memory twice. MySQL Daemon can be crashed unless upgraded. Details can be found by clicking --> here. Until that is resolved, PHP-Nuke should be the least of your worries. |
| MySQL Server Version | Reason For Vulnerability |
| ". mysql_get_server_info() ." | This MySQL Server version monitor drop database command contains buffer overflow. Tell your host to read the CERT/CC Vulnerability Note VU#367320 by clicking --> here. Until that is resolved, PHP-Nuke should be the least of your worries. |
| \$sitekey value | Reason For Vulnerability |
| ". $sitekey ." | PHP-Nuke has a default \$sitekey value as distributed in config.php. You should change this immediately to a unique value only you know. |
| php.ini magic_quotes.gpc value | Reason For Vulnerability |
| Not Enabled (Not \"On\") | If your magic_quotes_gpc is not On, as it currently isn't, you should change this immediately to the On value. If left disabled then your site is susceptible to member password retrieval and member admin escalation. For full details and exploits for testing go here. For details on exactly what code to insert if you cannot enable magic_quotes_gpc read here. |
| path/filename | Reason For Vulnerability |
| modules/WebMail/mailattach.php | Highly advised by Francisco Burzi (nukelite) and Nuke Cops, this file should be removed completely from your system regardless of WebMail activation. This file can be used to copy any file on your system and make it available for download. You don't want your config.php file downloaded do you? Remove this file immediately! |
| path/filename | Reason For Vulnerability |
| nukesql.php | This Web Browser based tables installer should have been deleted after it was used. This file can be used to run a Replace Tables which will empty your site's database tables, thus allowing anyone to restart your site and become a Superuser. You wouldn't want to have to start all over again do you? Remove this file immediately! |
| Your Version | Reason For Vulnerability |
| $NCVersion_Num | PHP-Nuke, with each new release (currently at 6.5), fixes vulnerabilities and exploits that older versions are susceptible to. This is a general alert for you to be aware that running older PHP-Nuke versions may leave it open to such attacks. It is your choice whether to upgrade or not to the newest version (regardless of status: gold, release candidate, or beta). But if you do decide to upgrade, for your sake make sure you backup 100% your MySQL database and all of your filesystem files. |
| Version | Reason For Vulnerability |
| 2$NCFver | The phpBB group at phpBB.com frequently update their forums software to eliminate known vulnerabilities and exploits. Analyzer has found that your forums port is not the newest release: 2.0.4. Please visit http://nukecops.com in order to obtain an upgrade package to 2.0.4. By not staying current in phpBB upgrades you leave your forums open to attack. The choice to upgrade, backup, or stay at current version is 100% completely yours, all we have done is alerted you to it. |
| Type | Value |
| dbhost | $dbhost | " . "
| dbname | $dbname | " . "
| dbuname | $dbuname | " . "
| prefix | $prefix | " . "
| user_prefix | $user_prefix | " . "
| dbtype | $dbtype | " . "
| Type | Value |
| GD Version | echo $gi1; ?> |
| FreeType Support | echo $gi2; ?> |
| T1Lib Support | echo $gi3; ?> |
| GIF Read Support | echo $gi4; ?> |
| GIF Create Support | echo $gi5; ?> |
| JPG Support | echo $gi6; ?> |
| PNG Support | echo $gi7; ?> |
| WBMP Support | echo $gi8; ?> |
| XBM Support | echo $gi9; ?> |
| Extension Status |
| Not-Loaded |
| Destination | Result |
| MySQL Health Check | Successful | " . "
| MySQL Server: $dbhost | Successful | " . "
| MySQL Datbase: $dbname | Successful | " . "
| MySQL Username: $dbuname | Successful | " . "
| Category | Value |
| PHP Version | ". phpversion() ." |
| Type | Value |
| OS Type | ".php_uname()." | " . "
| Type | Value |
| OS | ".$pu['sysname']." | " . "
| Node Name | ".$pu['nodename']." | " . "
| Build Release | ".$pu['release']." | " . "
| Version | ".$pu['version']." | " . "
| Machine Platform | ".$pu['machine']." | " . "
| Domain Name | ".$pu['domainname']." | " . "
| Category | Value |
| " . "Server Version | ". mysql_get_server_info() ."" . " |
| " . "Client Version | ". mysql_get_client_info() ."" . " |
| " . "Host Information | ". mysql_get_host_info() ."" . " |
| " . "Protocol Information | ". mysql_get_proto_info() ."" . " |
| Theme ID | Style Name | Template Name | Version |
| $NCconfig_value | $NCstyle_name | $NCtemplate_name | 2$NCFver | " . "
| Default_Theme | Version | Locale | Language |
| $NCDefault_Theme | $NCVersion_Num | $NClocale | $NClanguage | " . "
| Database Name |
| " . $row->Database . " | " . "
| " . $row->Database . " | " . "
| Module | Active Code | View Code |
| $NCtitle | $NCactive | $NCview |
| Block | Active Code | View Code |
| $NCTitle | $NCActive | $NCView |
| phpBB2 Rank Title | PHP-Nuke Rank Level | Member Name | Member UID |
| $NCrank_title | $NCuser_level | $NCuname | $NCuid |
| phpBB2 Rank Title | PHP-Nuke Rank Level | Member Name | Member UID |
| $NCrank_title | $NCuser_level | $NCuname | $NCuid |
| PHP-Nuke Rank Level | Member Name | Member UID |
| $NCuser_level | $NCuname | $NCuid |
| PHP-Nuke Rank Level | Member Name | Member UID |
| $NCuser_level | $NCuname | $NCuid |
| PHP-Nuke Rank Level | Member Name | Member UID |
| $NCuser_level | $NCuname | $NCuid |
| PHP-Nuke Rank Level | Member Name | Member UID |
| $NCuser_level | $NCuname | $NCuid |
| Number | Table Name | Fields | Records | |
| $i | $row[0] | "; $sql2 = "DESCRIBE $row[0]"; $result2 = mysql_num_rows(mysql_query($sql2)); if ($result2) { echo "$result2 | "; } else { $result2 = "0"; } $sql3 = "SELECT COUNT(*) as nccount FROM ".$row[0]; $result3 = mysql_query($sql3); while (list($nccount) = mysql_fetch_row($result3)) { if ($nccount) { echo "$nccount | "; } else { $nccount = 0; echo "$nccount | "; } } $i++; } echo "
";
print_r(parse_ini_file(get_cfg_var('cfg_file_path')));
echo " |
| Global / Local / Access : php.ini data | ||
| The Key for [access] | ||
| Constant | Value | Meaning |
| PHP_INI_USER | 1 | Entry can be set in user scripts |
| PHP_INI_PERDIR | 2 | Entry can be set in php.ini, .htaccess, or httpd.conf |
| PHP_INI_SYSTEM | 4 | Entry can be set in php.ini, or httpd.conf |
| PHP_INI_ALL | 7 | Entry can be set anywhere |
"; print_r($cfgOut); echo " | ||
";
print_r(mysql_stat($dbi));
echo " |
| Security Code Image with Random Number |
| "
. " |
| Security Code Image with Random Number |
| "
. " |
| Status |
| GD Loaded but security images are not present. |
| Extension Status |
| Not-Loaded |
| php.ini location |
| " . get_cfg_var("cfg_file_path") . " |