Support => cpg1.4.x Support => Older/other versions => cpg1.4 miscellaneous => Topic started by: kateheaven on May 05, 2006, 08:07:18 pm

Title: hackers (?) creating ads
Post by: kateheaven on May 05, 2006, 08:07:18 pm
I'm having a problem with someone (hackers?) adding ad codes into my sites coding (I've deleted them all currently so I can't show you an example, but I think some include 'trafficbiz') - they cause the page to freeze and I have to close all my programs. I've contacted my host about this and they say it's very possibly related to coppermine. So I'm looking for help from anyone here on what to do about this. My host suggested you may have a patch file for this problem? If you do provide this, where/what do I need?
I've just upgraded to 1.4.5.

I'm sorry if this is in the wrong forum, I wasn't sure where it belonged ...
Title: Re: hackers (?) creating ads
Post by: Joachim Müller on May 05, 2006, 09:23:30 pm
make sure you haven't fallen victim to the rar vulnerability (not an actual coppermine issue, but an apache2 / server misconfiguration issue) - search the board for "rar". Impossible to say for sure without details. Your webhost should be capable to tell you more than vague guesses. Another possible attack pattern might be using outdated coppermine versions; I guess you upgraded after having been attacked...
The resulting defacing ads are not relevant, but the way the attackers managed to break into your site. For forensic reasons, create a complete backup (using your FTP app) of all files, and compare the files to your local vanilla copies.