Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: Site hacked, files deleted, restoring help  (Read 6038 times)

0 Members and 1 Guest are viewing this topic.

StephBertha

  • Coppermine newbie
  • Offline Offline
  • Posts: 8
Site hacked, files deleted, restoring help
« on: April 01, 2012, 03:46:34 am »

Hi there,

Here's what happened:

1. My site was hacked.
2. The files were deleted by the hacker.
3. I have the files and the database backed up.
4. Now, I'm trying to put the pieces back together.

So, the database dump is already in place before the site is officially 're-installed'.  I can go to install.php on my site and set everything up, but do I keep the database information the same or rename the tables?

Thank you,
Stephanie

Logged

lucky-luc

  • Coppermine newbie
  • Offline Offline
  • Posts: 14
Re: Site hacked, files deleted, restoring help
« Reply #1 on: April 01, 2012, 02:44:43 pm »

I think both ways will give you the same result, creating a new database and change info in the config file is longer.
Logged

Joe Carver

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: us
  • Offline Offline
  • Gender: Male
  • Posts: 1543
  • aka 'i-imagine'
    • Home Page
Re: Site hacked, files deleted, restoring help
« Reply #2 on: April 02, 2012, 02:50:34 am »

....but do I keep the database information the same or rename the tables?

Keep everything the same if you have clean back up copies. The file include/config.inc.php will need to be edited if you change the name and / or password for the db.
(which might be a good idea if the hacker gained access to your credential information).

You will not want or need to run install.php, only update.php.

Make sure to upgrade your cpg after restoring it.

StephBertha

  • Coppermine newbie
  • Offline Offline
  • Posts: 8
Re: Site hacked, files deleted, restoring help
« Reply #3 on: April 07, 2012, 11:42:00 pm »

Hi Joe,

Bah. So I didn't see your message until now.  I had installed and then updated. I managed to get the data from the database into Coppermine and I upgraded the version to the latest.

However, some images are showing up and some are not.  I checked in my FTP and all the image thumbnails, intermediate, and normal images are in there.  Is there anything else I can do instead of rebatching all the files?
Logged

Αndré

  • Administrator
  • Coppermine addict
  • *****
  • Country: de
  • Offline Offline
  • Gender: Male
  • Posts: 15764
Re: Site hacked, files deleted, restoring help
« Reply #4 on: April 08, 2012, 02:35:08 pm »

Please post a link to your gallery and some links where the image won't show as expected.
Logged

StephBertha

  • Coppermine newbie
  • Offline Offline
  • Posts: 8
Re: Site hacked, files deleted, restoring help
« Reply #5 on: April 15, 2012, 06:36:33 pm »

Sure!  My URL is: http://www.kerrsmith.ws/gallery/ If you look at the home page or any other page in the gallery, you'll notice the thumbnails not showing up. 
Logged

Αndré

  • Administrator
  • Coppermine addict
  • *****
  • Country: de
  • Offline Offline
  • Gender: Male
  • Posts: 15764
Re: Site hacked, files deleted, restoring help
« Reply #6 on: April 16, 2012, 09:28:36 am »

You can use the admin tools to re-create your thumbnails. Unfortunately you haven't posted a test user account, so I could not investigate the issue any further. If the admin tools don't fix your issue, please either post a test user account (no admin account!) or temporary enable guests to view intermediate-sized and full-sized pictures.
Logged

StephBertha

  • Coppermine newbie
  • Offline Offline
  • Posts: 8
Re: Site hacked, files deleted, restoring help
« Reply #7 on: April 21, 2012, 02:37:45 am »

Oh gosh I'm sorry!  I had NO idea guests couldn't view the larger images. I would never set that up in my gallery, must be the default settings.  Anyway, I changed them.

Would you like me to create a user account?  If so, how do I go about doing that?
Logged

Αndré

  • Administrator
  • Coppermine addict
  • *****
  • Country: de
  • Offline Offline
  • Gender: Male
  • Posts: 15764
Re: Site hacked, files deleted, restoring help
« Reply #8 on: April 21, 2012, 11:46:01 am »

Have you already used the admin tools?
Logged

StephBertha

  • Coppermine newbie
  • Offline Offline
  • Posts: 8
Re: Site hacked, files deleted, restoring help
« Reply #9 on: April 25, 2012, 03:28:46 am »

Yes.
Logged

Αndré

  • Administrator
  • Coppermine addict
  • *****
  • Country: de
  • Offline Offline
  • Gender: Male
  • Posts: 15764
Re: Site hacked, files deleted, restoring help
« Reply #10 on: April 25, 2012, 06:28:14 am »

Would you be so kind to tell us which options you used and what exactly Coppermine told you (error messages, etc.)? ::)
Logged

StephBertha

  • Coppermine newbie
  • Offline Offline
  • Posts: 8
Re: Site hacked, files deleted, restoring help
« Reply #11 on: May 26, 2012, 07:54:13 pm »

Sure!

Please see the attached screenshots. I get some images that say "updated successfully" and then some say that say "error".  :(
Logged

Αndré

  • Administrator
  • Coppermine addict
  • *****
  • Country: de
  • Offline Offline
  • Gender: Male
  • Posts: 15764
Re: Site hacked, files deleted, restoring help
« Reply #12 on: May 29, 2012, 10:46:10 am »

It seems that the whole "premieres" directory is missing on your server, as I get an 404 error page: http://kerrsmith.ws/gallery/albums/premieres/

Without that directory (and all subsequent directories/files) Coppermine cannot create thumbnail images, as there are no source images.
Logged

StephBertha

  • Coppermine newbie
  • Offline Offline
  • Posts: 8
Re: Site hacked, files deleted, restoring help
« Reply #13 on: May 30, 2012, 05:27:53 pm »

It may seem like there's no images in that directory, but there are. I'm in my FTP and I'm looking at all the source files.

The only thing I can think of is to remove the entire gallery and rebatch all the images, which would suck, but defeats the purpose of what I have tried to do here.

Would you, kindly explain to me the best thing I can do for future references?  If I make sure I backup my database, backup all my images with thumbnails and normal images, I should be OK right? Cause that's what I did here and it seems like it's not OK.

Logged

Αndré

  • Administrator
  • Coppermine addict
  • *****
  • Country: de
  • Offline Offline
  • Gender: Male
  • Posts: 15764
Re: Site hacked, files deleted, restoring help
« Reply #14 on: May 30, 2012, 05:34:04 pm »

The HTTP error page means that the file or directory doesn't exist. We had one user in the past dealing with the same issue that all files are present at his FTP server but the gallery didn't show up any picture. The reason was, that his hosting provider switch the server but didn't assigned his FTP account to the new server.

To check if your FTP account matches your current gallery HTTP server try to upload a new file somewhere to your server (e.g. to the root directory) and check if it shows up when you visit it with your browser. Alternatively, delete some unimportant file (e.g. http://kerrsmith.ws/gallery/CHANGELOG.txt) and check if it still shows up when you visit it with your browser (don't forget to clear your cache).

Regarding the backup question read http://documentation.coppermine-gallery.net/en/export.htm#backup
Logged
Pages: [1]   Go Up
 

Page created in 0.041 seconds with 20 queries.