Advanced search  

News:

cpg1.5.46 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter recently discovered vulnerabilities. It is important that all users who run version cpg1.5.44 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: upgrade by deleting  (Read 1471 times)

0 Members and 1 Guest are viewing this topic.

diedhert

  • Coppermine novice
  • *
  • Offline Offline
  • Posts: 35
upgrade by deleting
« on: September 02, 2015, 12:05:44 PM »

I wasn't sure about the title - sorry - to make things clear.

My website has been hacked twice in two weeks. It consist of a joomla website and a coppermine forum.
After the first hack, I upgraded the forum without any problems. I do not know if they hacked it via the joomla or coppermine part.

When I install the latest version of coppermine 'over' the old version, maybe some residual (infected) files are left.
To avoid this, I would prefer to install from 'scratch'.

Can I just delete everything, then move all files from 1.5.38 to my website, then copy the old albums folder and config.inc.php to the website and then run the update script ?

Diederik
Logged

Αndré

  • Administrator
  • Coppermine addict
  • *****
  • Country: de
  • Offline Offline
  • Gender: Male
  • Posts: 15277
Re: upgrade by deleting
« Reply #1 on: September 02, 2015, 01:29:56 PM »

Can I just delete everything, then move all files from 1.5.38 to my website, then copy the old albums folder and config.inc.php to the website and then run the update script ?

Yes, but make sure that there are no malicious files in your albums folder. Additionally, you need to re-upload plugins and a custom theme if you used any (same here, make sure that they aren't the vulnerability). Also consider the anycontent.php file, if you modified it.

You should also upgrade any outdated software on your server.
Logged

diedhert

  • Coppermine novice
  • *
  • Offline Offline
  • Posts: 35
Re: upgrade by deleting
« Reply #2 on: September 02, 2015, 01:50:08 PM »

Thanks

The server is servage, so I cannot update anything there.
I have no plugins or custom themes as far as I know.
I have uploaded the old anycontent.php file, but when I run version checker this file seems to be version 1.4.19 and there is a red cross in the column revision. Can I update that file?

Diedrik
Logged

Αndré

  • Administrator
  • Coppermine addict
  • *****
  • Country: de
  • Offline Offline
  • Gender: Male
  • Posts: 15277
Re: upgrade by deleting
« Reply #3 on: September 02, 2015, 02:11:18 PM »

Please attach that file as zip file to your next reply (or just post its content).
Logged

diedhert

  • Coppermine novice
  • *
  • Offline Offline
  • Posts: 35
Re: upgrade by deleting
« Reply #4 on: September 02, 2015, 03:45:18 PM »

Hi

This is the content of the file:

<?php
/*************************
  Coppermine Photo Gallery
  ************************
  Copyright (c) 2003-2008 Dev Team
  v1.1 originally written by Gregory DEMAR

  This program is free software; you can redistribute it and/or modify
  it under the terms of the GNU General Public License version 3
  as published by the Free Software Foundation.
 
  ********************************************
  Coppermine version: 1.4.19
  $HeadURL: https://coppermine.svn.sourceforge.net/svnroot/coppermine/trunk/cpg1.4.x/anycontent.php $
  $Revision: 4392 $
  $Author: gaugau $
  $Date: 2008-04-16 09:25:35 +0200 (Mi, 16 Apr 2008) $
**********************************************/

/**
* Coppermine Photo Gallery 1.4.14 anycontent.php
*
* This file file gets included in the index.php if you set the option in admin
* can be used to display any content from any program, it is always to be edited
* according to tastes and then used
*
* @copyright 2002,2007 Gregory DEMAR, Coppermine Dev Team
* @license http://www.gnu.org/licenses/gpl.html GNU General Public License V3
* @package Coppermine
* @version $Id: anycontent.php 4392 2008-04-16 07:25:35Z gaugau $
*/

if (!defined('IN_COPPERMINE')) die('Not in Coppermine...');

starttable("100%", "Welcome");

?>
<tr><td class="tableb" >
This is for any content block - just a test - Edit the file "anycontent.php" to change what is shown here
</td></tr>
<?php
endtable();

?>



Thanks in advance
Diederik
Logged

Αndré

  • Administrator
  • Coppermine addict
  • *****
  • Country: de
  • Offline Offline
  • Gender: Male
  • Posts: 15277
Re: upgrade by deleting
« Reply #5 on: September 02, 2015, 03:49:23 PM »

You can simply replace that file, as there are no custom modifications.
Logged
Pages: [1]   Go Up
 

Page created in 0.414 seconds with 20 queries.