Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: CPG - Security: ECards form used for SPAM  (Read 8163 times)

0 Members and 1 Guest are viewing this topic.

ulistaerk

  • Coppermine newbie
  • Offline Offline
  • Posts: 1
CPG - Security: ECards form used for SPAM
« on: January 07, 2006, 02:39:30 am »

I ran a normal cpg setup where everybody (including Anonymous) could send an ECard.

Yesterday the server admin noticed that our server was blacklisted as an open relay. After a short search, cpg was identified as the culprit. Somebody must have wrote a script that sent countinous http-requests to the ECard URL. As result thousands over thousands of emails were sent.

I'm sure there are many cpg installations that have the same critical setup. Due to the spammers script and the google search (just search for "Powered by Coppermine Photo Gallery" and you will find all installations) this can be a significant security issue.

Feature request: Warn the stupid admin  if he allows anonymous to send ecards (warn via the javascript confirm dialog if anonymous can send ecards where you update the permissions)
Logged

kegobeer

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 4637
  • Beer - it does a body good!
    • The Kazebeer Family Website
Re: CPG - Security: ECards form used for SPAM
« Reply #1 on: January 07, 2006, 03:23:10 am »

Quote from: ulistaerk
Feature request: Warn the stupid admin  if he allows anonymous to send ecards (warn via the javascript confirm dialog if anonymous can send ecards where you update the permissions)

Hmm, I don't think so.  That would alienate to thousands of users who know better than to allow anonymous users to send ecards.
Logged
Do not send me a private message unless I ask for one.  Make your post public so everyone can benefit.

There are no stupid questions
But there are a LOT of inquisitive idiots

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: CPG - Security: ECards form used for SPAM
« Reply #2 on: January 08, 2006, 01:45:52 pm »

however, we should add a feature to future coppermine versions that makes such attacks harder (a confirmation dialog or even some sort of Captcha)
Logged
Pages: [1]   Go Up
 

Page created in 0.016 seconds with 19 queries.