Advanced search  

News:

CPG Release 1.6.26
Correct PHP8.2 issues with user and language managers.
Additional fixes for PHP 8.2
Correct PHP8 error with SMF 2.0 bridge.
Correct IPTC supplimental category parsing.
Download and info HERE

Pages: [1]   Go Down

Author Topic: CPG - Security: ECards form used for SPAM  (Read 8129 times)

0 Members and 1 Guest are viewing this topic.

ulistaerk

  • Coppermine newbie
  • Offline Offline
  • Posts: 1
CPG - Security: ECards form used for SPAM
« on: January 07, 2006, 02:39:30 am »

I ran a normal cpg setup where everybody (including Anonymous) could send an ECard.

Yesterday the server admin noticed that our server was blacklisted as an open relay. After a short search, cpg was identified as the culprit. Somebody must have wrote a script that sent countinous http-requests to the ECard URL. As result thousands over thousands of emails were sent.

I'm sure there are many cpg installations that have the same critical setup. Due to the spammers script and the google search (just search for "Powered by Coppermine Photo Gallery" and you will find all installations) this can be a significant security issue.

Feature request: Warn the stupid admin  if he allows anonymous to send ecards (warn via the javascript confirm dialog if anonymous can send ecards where you update the permissions)
Logged

kegobeer

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 4637
  • Beer - it does a body good!
    • The Kazebeer Family Website
Re: CPG - Security: ECards form used for SPAM
« Reply #1 on: January 07, 2006, 03:23:10 am »

Quote from: ulistaerk
Feature request: Warn the stupid admin  if he allows anonymous to send ecards (warn via the javascript confirm dialog if anonymous can send ecards where you update the permissions)

Hmm, I don't think so.  That would alienate to thousands of users who know better than to allow anonymous users to send ecards.
Logged
Do not send me a private message unless I ask for one.  Make your post public so everyone can benefit.

There are no stupid questions
But there are a LOT of inquisitive idiots

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: CPG - Security: ECards form used for SPAM
« Reply #2 on: January 08, 2006, 01:45:52 pm »

however, we should add a feature to future coppermine versions that makes such attacks harder (a confirmation dialog or even some sort of Captcha)
Logged
Pages: [1]   Go Up
 

Page created in 0.02 seconds with 19 queries.