Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: Hacking attempts using exploited coppermine for CMS script  (Read 3490 times)

0 Members and 1 Guest are viewing this topic.

Apoc

  • Coppermine newbie
  • Offline Offline
  • Posts: 2
Hacking attempts using exploited coppermine for CMS script
« on: August 20, 2004, 04:08:58 pm »

Hello,

I work for a quite large webhosting company, and I just did som daily routine security checks, and found out that someone had used an exploited coppermine script to gain access to the server. No serious damage was done, the person was only running a few eggdops (which we don't allow).

I have disabled the script. I'm not able to see what version was running, however could you please verify that the latest version of coppermine is absolutely secure? And are you aware of any exploits in older versions?

I'm going to have to disallow users from running coppermine on any of our servers if you can't show me that coppermine is secure. I really don't want to go there, so I hope you can verify this.

Thank you.
« Last Edit: August 21, 2004, 06:59:26 am by Tarique Sani »
Logged

Apoc

  • Coppermine newbie
  • Offline Offline
  • Posts: 2
Re: Hacking attempts using exploited coppermine script
« Reply #1 on: August 20, 2004, 04:22:46 pm »

Nevermind, already seem to have found what's the problem:

http://forum.coppermine-gallery.net/index.php?topic=5879.0
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: Hacking attempts using exploited coppermine script
« Reply #2 on: August 21, 2004, 03:33:11 am »

just to make this clear for others reading this thread: the security vulnerability and the resulting exploit does not apply to coppermine standalone (with our without bbs integration), but only applies to cpgNuke (aka "Coppermine for CMS"). There are no known security holes in coppermine standalone.
Next time, please make sure to post on the proper board (your report should have gone to the support board for "Coppermine for CMS" here: http://www.nukephotogallery.com/) - posting security related reports is a sensitive area that can ruin a software's reputation without an actual security risk existing.

GauGau
Logged

Tarique Sani

  • VIP
  • Coppermine addict
  • ***
  • Offline Offline
  • Gender: Male
  • Posts: 2712
    • http://tariquesani.net
Re: Hacking attempts using exploited coppermine script
« Reply #3 on: August 21, 2004, 06:57:26 am »

WOLF!!!!
Logged
SANIsoft PHP applications for E Biz
Pages: [1]   Go Up
 

Page created in 0.04 seconds with 15 queries.