Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: SECURITY ISSUES WITH GALLERY?  (Read 4682 times)

0 Members and 1 Guest are viewing this topic.

souravga

  • Coppermine newbie
  • Offline Offline
  • Posts: 6
SECURITY ISSUES WITH GALLERY?
« on: December 17, 2008, 02:48:03 pm »

I have 1.4.17 gallery version. I want to ensure that this version has no spyware or malware. I am getting trojan warnings on my site and my server host has made sure that the account is secure. They want me to ensure that all third party applications are safe to use.

Also, if there are any new upgrades, how can I upgrade without losing any of the data on the gallery?
Logged

Nibbler

  • Guest
Re: SECURITY ISSUES WITH GALLERY?
« Reply #1 on: December 17, 2008, 02:53:40 pm »

Current version is 1.4.19 and there are update instructions in the documentation.

For cleanup instructions see http://forum.coppermine-gallery.net/index.php/topic,51927.0.html
Logged

souravga

  • Coppermine newbie
  • Offline Offline
  • Posts: 6
Re: SECURITY ISSUES WITH GALLERY?
« Reply #2 on: December 17, 2008, 04:40:25 pm »

Thanks. Is there a way I can know what the infected files are? I'm really unsure what files may be infected. As for the coopermine gallery, is that suspectible to attacks...can I assume it is a safe application to use?
Logged

Hein Traag

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: nl
  • Offline Offline
  • Gender: Male
  • Posts: 2166
  • A, B, Cpg
    • Personal website - Spintires.nl
Re: SECURITY ISSUES WITH GALLERY?
« Reply #3 on: December 17, 2008, 04:43:31 pm »

1.4.19 is safe to use. Read that article Nibbler point you to, most questions are answered in there.
Logged

souravga

  • Coppermine newbie
  • Offline Offline
  • Posts: 6
Re: SECURITY ISSUES WITH GALLERY?
« Reply #4 on: December 17, 2008, 07:46:41 pm »

did the 1.4.17 have malware? I was told that one of the older versions of coppermine was infected. This is the version I am using right now.
Logged

Fabricio Ferrero

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: 00
  • Offline Offline
  • Gender: Male
  • Posts: 1996
  • From San Juan, Argentina, to the World!
    • http://fabricioferrero.com/
Re: SECURITY ISSUES WITH GALLERY?
« Reply #5 on: December 17, 2008, 07:52:42 pm »

Quote
This is the version I am using right now.
But yo have to stop using it inmediatly. There is no *infected* version of Coppermine. You get infected because it was an old version. Don't post anymore, just follow Nibbler's link and do as suggested.
Logged
Read Docs and Search the Forum before posting. - Soporte en español
--*--
Fabricio Ferrero's Website

Catching up! :)

souravga

  • Coppermine newbie
  • Offline Offline
  • Posts: 6
Re: SECURITY ISSUES WITH GALLERY?
« Reply #6 on: December 17, 2008, 08:27:29 pm »

yes that's fine. But when I downloaded it, that was the latest version. If it gets infected simply because it's old, that is bad because I cannot check everyday to see whether there is a new version or not. Is there a way I can be on the mailing list or something?
Logged

Nibbler

  • Guest
Re: SECURITY ISSUES WITH GALLERY?
« Reply #7 on: December 17, 2008, 08:45:41 pm »

You can subscribe to notifications on the download page and/or subscribe to the announcements board on this forum.
Logged

souravga

  • Coppermine newbie
  • Offline Offline
  • Posts: 6
Re: SECURITY ISSUES WITH GALLERY?
« Reply #8 on: December 17, 2008, 09:25:21 pm »

can you please provde me the link? I couldn't find it under announcmenets.

Also, int he installtion of the new upgraded version, it says to not replace the config.php file. I am unsure which they are referring to because I have a config.php file in the cpg1419 folder and another in cpg1419/include/config.php.

Could you please tell me which is the file I need to save?

Thanks,
Logged

François Keller

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: fr
  • Offline Offline
  • Gender: Male
  • Posts: 9094
  • aka Frantz
    • Ma galerie
Re: SECURITY ISSUES WITH GALLERY?
« Reply #9 on: December 18, 2008, 07:27:16 am »

you must not overwrite the include/config.inc.php file
Logged
Avez vous lu la DOC ? la FAQ ? et cherché sur le forum avant de poster ?
Did you read the DOC ? the FAQ ? and search the board before posting ?
Mon Blog

Hein Traag

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: nl
  • Offline Offline
  • Gender: Male
  • Posts: 2166
  • A, B, Cpg
    • Personal website - Spintires.nl
Re: SECURITY ISSUES WITH GALLERY?
« Reply #10 on: December 18, 2008, 08:19:13 am »

To be notified of new topics being posted on any part of the forum you must go to that part (for example the announcements) and click on the Notify button at the top. See screenshot.
Logged

souravga

  • Coppermine newbie
  • Offline Offline
  • Posts: 6
Re: SECURITY ISSUES WITH GALLERY?
« Reply #11 on: December 19, 2008, 01:19:12 am »

should all the other files except config.php in the include folder be replaced? Also, is it ok to upload the config.php file that lies outside in the cpg1419 folder?

Thanks for the help.
Logged

Hein Traag

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: nl
  • Offline Offline
  • Gender: Male
  • Posts: 2166
  • A, B, Cpg
    • Personal website - Spintires.nl
Re: SECURITY ISSUES WITH GALLERY?
« Reply #12 on: December 19, 2008, 06:59:26 am »

Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: SECURITY ISSUES WITH GALLERY?
« Reply #13 on: December 20, 2008, 11:26:34 am »

This thread is cluttered with replies by the thread starter that clearly show that he hasn't read the docs, nor board rules, not did he use the search. The subject line is crap, there's a lot of thread drift. That's enough misbehaviour for one thread imo. Locking.
Logged
Pages: [1]   Go Up
 

Page created in 0.022 seconds with 20 queries.