hackers (?) creating ads hackers (?) creating ads
 

News:

CPG Release 1.6.27
change DB IP storage fields to accommodate IPv6 addresses
remove use of E_STRICT (PHP 8.4 deprecated)
update README to reflect new website
align code with new .com CPG website
correct deprecation in captcha

Main Menu

hackers (?) creating ads

Started by kateheaven, May 05, 2006, 08:07:18 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

kateheaven

Hi,
I'm having a problem with someone (hackers?) adding ad codes into my sites coding (I've deleted them all currently so I can't show you an example, but I think some include 'trafficbiz') - they cause the page to freeze and I have to close all my programs. I've contacted my host about this and they say it's very possibly related to coppermine. So I'm looking for help from anyone here on what to do about this. My host suggested you may have a patch file for this problem? If you do provide this, where/what do I need?
I've just upgraded to 1.4.5.
Thanks.

I'm sorry if this is in the wrong forum, I wasn't sure where it belonged ...

Joachim Müller

make sure you haven't fallen victim to the rar vulnerability (not an actual coppermine issue, but an apache2 / server misconfiguration issue) - search the board for "rar". Impossible to say for sure without details. Your webhost should be capable to tell you more than vague guesses. Another possible attack pattern might be using outdated coppermine versions; I guess you upgraded after having been attacked...
The resulting defacing ads are not relevant, but the way the attackers managed to break into your site. For forensic reasons, create a complete backup (using your FTP app) of all files, and compare the files to your local vanilla copies.