forum.coppermine-gallery.net

Support => cpg1.4.x Support => Older/other versions => cpg1.4 miscellaneous => Topic started by: nautis on June 26, 2006, 05:21:41 pm

Title: webadmin.php upload hack
Post by: nautis on June 26, 2006, 05:21:41 pm
Someone has been uploading a .rar file to my photo album (public permissions all to post). Inside the rar is a file called webadmin.php which looks like a web file manager. Does this mean someone is trying to hack my photo album? if so, are there security messures in place to block this sort of activity? Thanks.

- Matthew
Title: Re: webadmin.php upload hack
Post by: Justttt on June 26, 2006, 05:24:35 pm
i dont think they would be able to hack uploading a file in a .rar why dont you download the .rar  nd paste the code in here maybe someone can tell you what the file is  ::)
Title: Re: webadmin.php upload hack
Post by: Tranz on June 26, 2006, 05:25:49 pm
Someone has been uploading a .rar file to my photo album (public permissions all to post). Inside the rar is a file called webadmin.php which looks like a web file manager. Does this mean someone is trying to hack my photo album? if so, are there security messures in place to block this sort of activity? Thanks.

- Matthew
Yes. Please upgrade to 1.4.8. Search for any other backdoor files and remove them. Change your admin password.
Title: Re: webadmin.php upload hack
Post by: Tranz on June 26, 2006, 05:26:57 pm
i dont think they would be able to hack uploading a file in a .rar why dont you download the .rar  nd paste the code in here maybe someone can tell you what the file is  ::)
Yes, they could. http://forum.coppermine-gallery.net/index.php?topic=31671.0
Title: Re: webadmin.php upload hack
Post by: nautis on June 27, 2006, 06:35:00 pm
i had already upgraded to the latest version. i deleted the file, but you find out more about it here: http://wacker-welt.de/webadmin/. is there a way i can turn off uploading archives?
Title: Re: webadmin.php upload hack
Post by: Nibbler on June 27, 2006, 06:56:25 pm
Set the allowed filetypes to whatever you like in config.