Advanced search  

News:

CPG Release 1.6.26
Correct PHP8.2 issues with user and language managers.
Additional fixes for PHP 8.2
Correct PHP8 error with SMF 2.0 bridge.
Correct IPTC supplimental category parsing.
Download and info HERE

Pages: [1]   Go Down

Author Topic: ly.php.rar fkn HACKED!!!  (Read 6327 times)

0 Members and 1 Guest are viewing this topic.

Dead J. Dona

  • Coppermine novice
  • *
  • Offline Offline
  • Gender: Male
  • Posts: 27
  • Yeppie-kaye, mazafaka (c) Bruce Willis
    • Æåíñêèé æóðíàë ÍÀÒÀËÈ
ly.php.rar fkn HACKED!!!
« on: May 15, 2006, 09:01:34 am »

ly.php.rar  >:(   >:( >:(

try to search by this file. Is this CG or PHP hole??  ???
« Last Edit: May 15, 2006, 09:15:51 am by GauGau »
Logged
wbr, Me. Dead J. Dona

Abbas Ali

  • Administrator
  • Coppermine addict
  • *****
  • Country: in
  • Offline Offline
  • Gender: Male
  • Posts: 2165
  • Spread the PHP Web
    • Ranium Systems
Re: ly.php.rar fkn HACKED!!!
« Reply #1 on: May 15, 2006, 09:10:30 am »

neither cpg nor php....its apahce (web server).

Search the board. This issue has been discussed many times.
Logged
Chief Geek at Ranium Systems

Dead J. Dona

  • Coppermine novice
  • *
  • Offline Offline
  • Gender: Male
  • Posts: 27
  • Yeppie-kaye, mazafaka (c) Bruce Willis
    • Æåíñêèé æóðíàë ÍÀÒÀËÈ
Re: ly.php.rar fkn HACKED!!!
« Reply #2 on: May 15, 2006, 09:16:03 am »

oops, i can't find anything here
i mean THIS filename never used in forum.
please give me a link or two....
Logged
wbr, Me. Dead J. Dona

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Logged

Dead J. Dona

  • Coppermine novice
  • *
  • Offline Offline
  • Gender: Male
  • Posts: 27
  • Yeppie-kaye, mazafaka (c) Bruce Willis
    • Æåíñêèé æóðíàë ÍÀÒÀËÈ
Re: ly.php.rar fkn HACKED!!!
« Reply #4 on: May 15, 2006, 09:30:35 am »

thank you!!!

but there's some kind of problem.

when using /aaa.php.lalala filename it also run as php script. PHP Version 4.4.2
maybe theres some PHP or apache guru can help me???
Logged
wbr, Me. Dead J. Dona

Tranz

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: 00
  • Offline Offline
  • Gender: Female
  • Posts: 6149
Re: ly.php.rar fkn HACKED!!!
« Reply #5 on: May 15, 2006, 10:05:53 am »

Something Nibbler suggested was to put the following in .htaccess:
Code: [Select]
AddHandler application/x-rar .rar
But I dunno about your particular case...
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: ly.php.rar fkn HACKED!!!
« Reply #6 on: May 15, 2006, 10:32:13 am »

ask your webhost to fix their webserver setup, as suggested here: Coppermine-driven galleries hit by RAR exploit
Logged

Abbas Ali

  • Administrator
  • Coppermine addict
  • *****
  • Country: in
  • Offline Offline
  • Gender: Male
  • Posts: 2165
  • Spread the PHP Web
    • Ranium Systems
Re: ly.php.rar fkn HACKED!!!
« Reply #7 on: May 15, 2006, 10:45:01 am »

when using /aaa.php.lalala filename it also run as php script. PHP Version 4.4.2

Then your web server is badly configured.
Logged
Chief Geek at Ranium Systems

Dead J. Dona

  • Coppermine novice
  • *
  • Offline Offline
  • Gender: Male
  • Posts: 27
  • Yeppie-kaye, mazafaka (c) Bruce Willis
    • Æåíñêèé æóðíàë ÍÀÒÀËÈ
Re: ly.php.rar fkn HACKED!!!
« Reply #8 on: May 15, 2006, 02:16:08 pm »

Allowed document types
"ALL" will result in all allowable document file types to be uploaded. If you want to restrict the allowable file types to certain extensions only, enter a slash-separated list of extensions, e.g. txt/pdf.

Note that being able to browse a document file requires the cpg-user to have a compatible software installed and configured properly on their computer that is capable of displaying the type of document in question, e.g. if you allow the file type xls, users who wish to browse the file will need to have an application installed on their computer that can display MS-Excel sheets. Be extremely careful with document that are known to be vulnerable to virus contamination, embedded or as macros. This is especially true if you plan to allow users the capability of uploading documents without admin approval.

Warning: if your webserver is not hardened against an exploit of a vulnerability in the apache webserver setup, then it might be a security risk to allow the upload of rar-files. If you're not sure, do not allow this file type.

What should I put here to disable ALL documents upload? NONE, NIL, NOTHING, or just left blank?
Logged
wbr, Me. Dead J. Dona

Dead J. Dona

  • Coppermine novice
  • *
  • Offline Offline
  • Gender: Male
  • Posts: 27
  • Yeppie-kaye, mazafaka (c) Bruce Willis
    • Æåíñêèé æóðíàë ÍÀÒÀËÈ
Re: ly.php.rar fkn HACKED!!!
« Reply #9 on: May 15, 2006, 02:17:32 pm »

Then your web server is badly configured.

Can you tell me what must be changed?
Logged
wbr, Me. Dead J. Dona

Nibbler

  • Guest
Re: ly.php.rar fkn HACKED!!!
« Reply #10 on: May 15, 2006, 02:18:55 pm »

Any of those will work, but blank is probably the best option.
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: ly.php.rar fkn HACKED!!!
« Reply #11 on: May 15, 2006, 02:40:58 pm »

did you read the thread I refered to earlier:
ask your webhost to fix their webserver setup, as suggested here: Coppermine-driven galleries hit by RAR exploit

You're just doing what you're not suppossed to: you're doctoring the symptoms (fiddling with Coppermine settings). Instead, do as suggested and cure the reason for all of your troubles: make your webhost fix their webserver setup asap. Coppermine is not the reason for the issues you have, it's silly webserver setup.
Logged
Pages: [1]   Go Up
 

Page created in 0.022 seconds with 19 queries.