[08:36:28] Hi there! Our MediaWiki instance (normally at wiki.inventaire.io but I turned it off) got pwned. I was late on the updates, using MediaWiki v1.43.1 🫣: attackers were able to upload php files via `POST /w/api.php HTTP/1.1` (multiple requests for multipart form I guess), and then do remote code execution and further file upload with that php files on [08:36:28] `w/images/xxx.php`. Fortunat [08:36:28] ely our MediaWiki lives in a docker container so limited damages from what I could see. I will of course start by updating MediaWiki but would really like to understand what happened to be able to test on the updated version: it shouldn't be possible to upload php files via`POST /w/api.php`right? Does that vulnerability or improper configuration sound familiar to [08:36:28] anyone? Let me k [08:36:30] now if there is a better channel to discuss this. [08:38:21] With the rise of AI all software packages I know get more and more security fixes each update so could be the case [08:52:47] there is a recent vulnerability with filemanager plugin reported 3-4 days ago. (re @maxlath: Hi there! Our MediaWiki instance (normally at wiki.inventaire.io but I turned it off) got pwned. I was late on the updates, usin...) [08:53:16] https://www.mediawiki.org/wiki/Reporting_security_bugs [08:53:16] I take it your logs don't capture a specific set of parameters they sent to narrow down the endpoint(s) used, or have you stripped them for here? The specific API endpoint they were hitting will help narrow it down - it only takes one mishandled input somewhere. (re @maxlath: Hi there! Our MediaWiki instance (normally at wiki.inventaire.io but I turned it off) got [08:53:16] pwned. I was la [08:53:18] te on the updates, usin...) [08:54:46] Unfortunately, that's all I could find in the logs, I would very much like to be able to increase verbosity to get those requests body ; is there a parameter for that? (re @lcawte: https://www.mediawiki.org/wiki/Reporting_security_bugs [08:54:46] I take it your logs don't capture a specific set of parameters they sent...) [09:07:46] you can set $wgDebugLogGroups['api'] to log used action api parameters [09:08:53] do you have Extension:ExternalData enabled? it had an RCE vulnerability discovered recently, https://lists.wikimedia.org/hyperkitty/list/mediawiki-l@lists.wikimedia.org/thread/5N55R3XNFE7BXQLGWKZI7Q4ZXZSF4C5I/ [09:36:05] @taavi thanks, that's it! We were using Extension:External_Data 3.6 and got the same exploits as described by Marc Lajoie + some web shells