Advanced search  

News:

CPG Release 1.6.26
Correct PHP8.2 issues with user and language managers.
Additional fixes for PHP 8.2
Correct PHP8 error with SMF 2.0 bridge.
Correct IPTC supplimental category parsing.
Download and info HERE

Pages: [1]   Go Down

Author Topic: Vulnerability? Had shell uploaded through upload.php  (Read 4480 times)

0 Members and 1 Guest are viewing this topic.

SickFinga

  • Coppermine novice
  • *
  • Offline Offline
  • Posts: 22
Vulnerability? Had shell uploaded through upload.php
« on: June 17, 2006, 10:22:40 am »

I was checking my counter, and saw someone was "google hacking"

Someone was searching for "coppermine photo gallery intitle:"Upload File"" and yahoo and got to my site.
I checked my logs and noticed that used tried to access
http://url.com/albums/userpics/is.php.rar

I checked my USERPICS folder and sure is.php.rar was there.
I opened it with notepad, and it is a shell.


So I was wondering if there is any danger?


I have 1.4.5 patched to 1.4.8
« Last Edit: June 18, 2006, 10:38:21 am by GauGau »
Logged

Sami

  • VIP
  • Coppermine addict
  • ***
  • Offline Offline
  • Gender: Male
  • Posts: 3686
  • BMossavari
    • My Project
Re: Vulnerability? Had shell uploaded through upload.php
« Reply #1 on: June 17, 2006, 10:34:09 am »

yes there is , you should delete that file
- as cpg 1.4.6 , gallery is protected against Apache's .rar vulnerability
- This file uploaded ,before you upgraded the gallery
Logged
‍I don't answer to PM with support question
Please post your issue to related board

SickFinga

  • Coppermine novice
  • *
  • Offline Offline
  • Posts: 22
Re: Vulnerability? Had shell uploaded through upload.php
« Reply #2 on: June 17, 2006, 11:04:31 am »

Nope, uploaded yesterday.
Guess I should double check if I acually patched it.
Logged

SickFinga

  • Coppermine novice
  • *
  • Offline Offline
  • Posts: 22
Re: Vulnerability? Had shell uploaded through upload.php
« Reply #3 on: June 17, 2006, 11:14:43 am »

Check function.inc.php and it is patched (patched on May 26)
rar file was uploaded on 16th June.

 ??? ???
Logged

Sami

  • VIP
  • Coppermine addict
  • ***
  • Offline Offline
  • Gender: Male
  • Posts: 3686
  • BMossavari
    • My Project
Re: Vulnerability? Had shell uploaded through upload.php
« Reply #4 on: June 17, 2006, 11:28:06 am »

look for other shell file may be you have a shell file uploaded before update, and they use that to upload new one !
waht is the actual name? is.php.rar or is_php.rar?
- link to site with test (non admin) user would be helpfull
Logged
‍I don't answer to PM with support question
Please post your issue to related board

SickFinga

  • Coppermine novice
  • *
  • Offline Offline
  • Posts: 22
Re: Vulnerability? Had shell uploaded through upload.php
« Reply #5 on: June 17, 2006, 11:56:55 am »

File name is is_php.rar

But when he tried to access it, he tried is.php.rar
[Fri Jun 16 10:05:53 2006] [error] [client 193.226.60.107] File does not exist: /usr/home/tttt/public_html/404.shtml
[Fri Jun 16 10:05:53 2006] [error] [client 193.226.60.107] File does not exist: /usr/home/tttt/public_html/albums/userpics/is.php.rar

site
http://tuningdb.com
Logged

SickFinga

  • Coppermine novice
  • *
  • Offline Offline
  • Posts: 22
Re: Vulnerability? Had shell uploaded through upload.php
« Reply #6 on: June 17, 2006, 11:59:59 am »

OK I just tried to rename the shell to is.php.rar and upload it. Coppermine changed the file name to is_php.rar

So I guess fix does works.

Sorry for the false alarm.
Logged

Sami

  • VIP
  • Coppermine addict
  • ***
  • Offline Offline
  • Gender: Male
  • Posts: 3686
  • BMossavari
    • My Project
Re: Vulnerability? Had shell uploaded through upload.php
« Reply #7 on: June 17, 2006, 12:06:47 pm »

Yes, it works  ;)
Nop ,
Logged
‍I don't answer to PM with support question
Please post your issue to related board
Pages: [1]   Go Up
 

Page created in 0.019 seconds with 20 queries.