Advanced search  

News:

CPG Release 1.6.26
Correct PHP8.2 issues with user and language managers.
Additional fixes for PHP 8.2
Correct PHP8 error with SMF 2.0 bridge.
Correct IPTC supplimental category parsing.
Download and info HERE

Pages: [1]   Go Down

Author Topic: Gallery Attack?  (Read 5381 times)

0 Members and 2 Guests are viewing this topic.

wildwalker

  • Coppermine novice
  • *
  • Offline Offline
  • Posts: 34
Gallery Attack?
« on: April 12, 2008, 12:38:49 pm »

Hello all,

I am using Coppermine 1.4.8 (stable) and everything has been fine for ages, I have 4 websites running, but one of them keeps getting messed up.

In the Config page of my site the following values keep getting changed:

Number of levels of categories to display - Gets set to '1' and I normally use '2'
Number of albums to display - Gets set to '1' and I normally use '50'
Number of columns for the album list - Gets set to '1' and I normally use '2'

Number of columns on thumbnail page - Gets set to '1' and I normally use '4'
Number of rows on thumbnail page - Gets set to '1' and I normally use '3'
Number of items in film strip - Gets set to '1' and I normally use '5'

Max width or height of an intermediate picture/video ** - Gets set to '1' and I normally use '10000' (the default)

My website is www.cameraangle.co.uk

The other sites are all unaffected.

So, is someone messing me around? I realise this could be done via SQL and not through the coppermine interface. I am the only one with any admin rights, or is my server somehow doing this?

I am going to upgrade today to whatever the latest coppermine build is, and maybe that will help.

Thanks in advance for any replies.

Alan Walker.

Logged

François Keller

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: fr
  • Offline Offline
  • Gender: Male
  • Posts: 9094
  • aka Frantz
    • Ma galerie
Re: Gallery Attack?
« Reply #1 on: April 12, 2008, 01:04:00 pm »

your site was hacked There is a long thread who deals with this problem. http://forum.coppermine-gallery.net/index.php/topic,51671.0.html
clean up your install and upgrade to the latest version (1.4.17 who fix the vulnerability)
Logged
Avez vous lu la DOC ? la FAQ ? et cherché sur le forum avant de poster ?
Did you read the DOC ? the FAQ ? and search the board before posting ?
Mon Blog

steveeh131047

  • Supporter
  • Coppermine frequent poster
  • ****
  • Offline Offline
  • Posts: 217
Re: Gallery Attack?
« Reply #2 on: April 12, 2008, 01:05:33 pm »

And better not fall so far behind on upgrades next time!
Logged

wildwalker

  • Coppermine novice
  • *
  • Offline Offline
  • Posts: 34
Re: Gallery Attack?
« Reply #3 on: April 12, 2008, 01:09:32 pm »

your site was hacked There is a long thread who deals with this problem. http://forum.coppermine-gallery.net/index.php/topic,51671.0.html
clean up your install and upgrade to the latest version (1.4.17 who fix the vulnerability)

Thank you for the reply Francois, I am doing the upgrade right now and will have a long read of the link you posted.

Many thanks for the swift reply.

All the best,
Alan Walker.

Logged

NoviceScotty

  • Coppermine newbie
  • Offline Offline
  • Posts: 7
Re: Gallery Attack?
« Reply #4 on: April 12, 2008, 01:48:15 pm »

Hi - sorry, I only read this after posting my problem.

My cpg148 has been hacked big time - I think it downloads a virus to anyone who looks at it.

All the php and html files have an extra line appended that executes a php file on a remote computer.

The hack seems to have been an uploaded jpg containing php code instead of a picture in my first album.

 
Logged

wildwalker

  • Coppermine novice
  • *
  • Offline Offline
  • Posts: 34
Re: Gallery Attack?
« Reply #5 on: April 12, 2008, 01:57:25 pm »

Okay,

So I have upgraded to 1.4.17. I will keep an eye out to see if this stops my issue :)

Thanks again for the help.

Best regards,
Alan Walker.
Logged

girlstyle

  • Coppermine newbie
  • Offline Offline
  • Posts: 14
Re: Gallery Attack?
« Reply #6 on: April 12, 2008, 03:48:01 pm »

Looks like we've just been hacked too :-(

I've tried to upgrade, but the install is calling for this domain:

(https://forum.coppermine-gallery.net/proxy.php?request=http%3A%2F%2Fwww.girlstyle.co.uk%2Fhack.jpg&hash=58edc8ef34856500164cee0c0ffba42b75e59b7d)

The installer also wants to launch my outlook.exe. Looks like doing the upgrade isn't erradiacting the problem.

I think I'm pumped :-( Any way to do a fresh install? Looks like there is something lurking in the gallery. I don't want to put users at risk, can anyone suggest a sure fire course of action to clean out this hack? I know, late with upgrades, but no one notifies us?

Logged

Llama8668

  • Coppermine newbie
  • Offline Offline
  • Posts: 18
Re: Gallery Attack?
« Reply #7 on: April 12, 2008, 04:02:13 pm »

There are a few threads around on this (the big one is here). Basically you clean up by doing an upgraded (as all files are overwritten when you do this). You need to be careful to remove all malicious files (which will typically be  .zip's or .jpg's with the filename 142739_298w3). Files such as custom theme and config files will not be overwritten so you need to manually remove the code from those.
Logged

wildwalker

  • Coppermine novice
  • *
  • Offline Offline
  • Posts: 34
Re: Gallery Attack?
« Reply #8 on: April 14, 2008, 06:33:35 pm »

Just an update.

I applied the update (1.4.17) as advised and have been trouble free for a couple of days now, so it looks like a simple upgrade to the latest version has fixed my problem.

Thanks to all that helped, much appreciated.

All the best,
Alan Walker.
Logged

François Keller

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: fr
  • Offline Offline
  • Gender: Male
  • Posts: 9094
  • aka Frantz
    • Ma galerie
Re: Gallery Attack?
« Reply #9 on: April 14, 2008, 06:39:44 pm »

update to the latest version (1.4.18 was released today) to fix an other security hole (see the announcment thread here http://forum.coppermine-gallery.net/index.php/topic,51882.0.html)
Logged
Avez vous lu la DOC ? la FAQ ? et cherché sur le forum avant de poster ?
Did you read the DOC ? the FAQ ? and search the board before posting ?
Mon Blog

wildwalker

  • Coppermine novice
  • *
  • Offline Offline
  • Posts: 34
Re: Gallery Attack?
« Reply #10 on: April 14, 2008, 10:20:45 pm »

update to the latest version (1.4.18 was released today) to fix an other security hole (see the announcment thread here http://forum.coppermine-gallery.net/index.php/topic,51882.0.html)

Lol, I was just feeling all smug after upgrading to 1.4.17, then I read this...

Upgrading to 1.4.18 as we speak :)

I did just change the coppermine.inc.php, but of course the version is still shown as 1.4.17 as only one file has changed, so I decided to just do the whole thing.

Thanks for your help,
Alan Walker.
Logged
Pages: [1]   Go Up
 

Page created in 0.03 seconds with 19 queries.