Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: [Solved]: My gallery has been hacked - what now?  (Read 3584 times)

0 Members and 1 Guest are viewing this topic.

photo-mariages

  • Coppermine newbie
  • Offline Offline
  • Posts: 14
    • Photographe de mariage a Nice
[Solved]: My gallery has been hacked - what now?
« on: April 14, 2008, 12:52:04 pm »

Hello,

My gallery www.photo06.fr has been hacked. When accessing this URL the only message you get is:
"Fatal Error :"

I really don't know where to start. I access my server via FTP and the files seem to be there - well at least the index.php on the root is there and so are my album files.
I had nothing else on this site than a coppermine gallery...

Where should I start?

thanks!

http://www.photo06.fr
« Last Edit: April 20, 2008, 02:30:40 am by Joachim Müller »
Logged

Hein Traag

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: nl
  • Offline Offline
  • Gender: Male
  • Posts: 2166
  • A, B, Cpg
    • Personal website - Spintires.nl
Re: My gallery has been hacked - what now?
« Reply #1 on: April 14, 2008, 12:54:10 pm »

Which version were you using ? If this was not 1.4.17 then upgrade following the instructions in the documentation.
Logged

Pascal YAP

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: fr
  • Offline Offline
  • Gender: Male
  • Posts: 13833
  • Hello World :-)
    • CPG 1.5.x ExperiMental website
Re: My gallery has been hacked - what now?
« Reply #2 on: April 14, 2008, 02:58:55 pm »

If you want to explain more easily your problem, go to our French Board here :
http://coppermine-gallery.net/forum/index.php?board=38.0

PYAP
Logged

Hein Traag

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: nl
  • Offline Offline
  • Gender: Male
  • Posts: 2166
  • A, B, Cpg
    • Personal website - Spintires.nl
Re: My gallery has been hacked - what now?
« Reply #3 on: April 14, 2008, 03:16:04 pm »

It's all French to me  ;D

Thanks PYAP
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: My gallery has been hacked - what now?
« Reply #4 on: April 15, 2008, 07:54:18 am »

Your site has NOT been hacked, at least you can't conclude that from the error message. The fatal error you get is not a sign of having been hacked. It's a sign that something is wrong, that's all. Enable debug_mode to see the actual error message (after having upgraded, as you now have cpg1.4.13, while the most recent stable release currently is cpg1.4.18). If you still have the fatal error after having performed the update, do as suggested in http://coppermine-gallery.net/tutorial/debug_mode.php
Logged

photo-mariages

  • Coppermine newbie
  • Offline Offline
  • Posts: 14
    • Photographe de mariage a Nice
Re: My gallery has been hacked - what now?
« Reply #5 on: April 19, 2008, 09:15:38 am »

Hi,

It took me a few days to figure out how to set up phpmyadmin but finally got it working to set up the debug mode.

When I now type www.photo06.fr (root of the coppermine gallery) I get the following explanation after Fatal Error:

----
While executing query "delete from `U7575134`.cpg14x_sessions where time<1208585577 and remember=0;" on Resource id #6

mySQL error: Can't open file: 'cpg14x_sessions.MYI'. (errno: 145)
----

It makes no sense to me at all and unfortunately does not help me to fix my problem. Any idea of what my next step should be?

thanks...
Logged

photo-mariages

  • Coppermine newbie
  • Offline Offline
  • Posts: 14
    • Photographe de mariage a Nice
Fatal Error
« Reply #6 on: April 19, 2008, 09:37:02 am »

Hi,

When I go in phpmyadmin to the table cpg14x_sessions I get the following information:

----
Error

SQL query: Edit

SHOW INDEX FROM `cpg14x_sessions` ;

MySQL said: Documentation
#1016 - Can't open file: 'cpg14x_sessions.MYI'. (errno: 145)
----

Am I missing a table?
Logged

Abbas Ali

  • Administrator
  • Coppermine addict
  • *****
  • Country: in
  • Offline Offline
  • Gender: Male
  • Posts: 2165
  • Spread the PHP Web
    • Ranium Systems
Logged
Chief Geek at Ranium Systems

photo-mariages

  • Coppermine newbie
  • Offline Offline
  • Posts: 14
    • Photographe de mariage a Nice
Re: My gallery has been hacked - what now?
« Reply #8 on: April 19, 2008, 03:13:39 pm »

Dear Abbas Ali,

Thank you for the analysis and the link. It now finally works!

I don't understand what happened - or why this happened, but am happy to have it fixed :)

www.photo06.fr
Logged
Pages: [1]   Go Up
 

Page created in 0.028 seconds with 20 queries.