Advanced search  

News:

CPG Release 1.6.26
Correct PHP8.2 issues with user and language managers.
Additional fixes for PHP 8.2
Correct PHP8 error with SMF 2.0 bridge.
Correct IPTC supplimental category parsing.
Download and info HERE

Pages: [1]   Go Down

Author Topic: Suspicious behaviour: phpRemoteView (RemView)  (Read 7335 times)

0 Members and 1 Guest are viewing this topic.

GlennP

  • Coppermine newbie
  • Offline Offline
  • Posts: 3
Suspicious behaviour: phpRemoteView (RemView)
« on: December 20, 2005, 12:32:03 pm »

Hi,

I have had someone place a file on my server called a.php.rm. When I remove the .rm it seems to be a valid php file - but I don't like the look of it!

The header is:
Code: [Select]
/* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
 *
 *  Welcome to phpRemoteView (RemView)
 *
 *  View/Edit remove file system:
 *  - view index of directory (/var/log - view logs, /tmp - view PHP sessions)
 *  - view name, size, owner:group, perms, modify time of files
 *  - view html/txt/image/session files
 *  - download any file and open on Notepad
 *  - create/edit/delete file/dirs
 *  - executing any shell commands and any PHP-code
 *
 *  Free download from http://php.spb.ru/remview/
 *  Version 04, 2002-08-24.
 *  Please, report bugs...
 *
 *  This programm for Unix/Windows system.
 *
 *  (c) Dmitry Borodin, dima@php.spb.ru, http://php.spb.ru
 *

Can anyone advise?
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: Suspicious behaviour: phpRemoteView (RemView)
« Reply #1 on: December 20, 2005, 01:56:32 pm »

has been asked before, please search the board for details: on some improperly configured webservers, files with the extension .rm are being parsed as php files. Somebody has indeed beeen trying to attack your site. No saying if the attack was successful. For now, disable the use of files with the extension rm and ram in coppermine's filetypes table, and ask your webhost for support if the vulnerability exists on the server you're hosted on. Delete the suspicious files at once.
Logged

GlennP

  • Coppermine newbie
  • Offline Offline
  • Posts: 3
Re: Suspicious behaviour: phpRemoteView (RemView)
« Reply #2 on: December 20, 2005, 02:15:59 pm »

Thanks - I did search but failed to find anything.
Logged
Pages: [1]   Go Up
 

Page created in 0.051 seconds with 20 queries.