files being uploaded under user nobody files being uploaded under user nobody
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

files being uploaded under user nobody

Started by pjssms, March 29, 2009, 02:15:20 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

pjssms

The files are being uploaded but after uploading start beloging to nobody instead of the user.
The process then doesn´t create the thumbnails.

I have tried to enable suexecphp but the scrit doesn´t work with that.

What do you suggest to be done ?.

I spent some time looking for answers in the forum already.

I am copying the debug information.


/upload.php

    * Notice line 1979: Undefined variable: file_failure_array
    * Notice line 1980: Undefined variable: URI_failure_array
    * Notice line 1981: Undefined variable: zip_failure_array


USER:
------------------
Array
(
    [ID] => f3503a02ff93038163e951e5cf5570e2
    [am] => 1
    [lang] => english
)

==========================
USER DATA:
------------------
Array
(
    [user_id] => 1
    [user_name] => deuchand_galeria
    [groups] => Array
        (
           
  • => 1
            )

        [disk_max] => 0
        [disk_min] => 0
        [can_rate_pictures] => 1
        [can_send_ecards] => 1
        [ufc_max] => 3
        [ufc_min] => 3
        [custom_user_upload] => 0
        [num_file_upload] => 5
        [num_URI_upload] => 3
        [can_post_comments] => 1
        [can_upload_pictures] => 1
        [can_create_albums] => 1
        [has_admin_access] => 1
        [pub_upl_need_approval] => 0
        [priv_upl_need_approval] => 0
        [group_name] => Administrators
        [upload_form_config] => 3
        [group_quota] => 0
        [can_see_all_albums] => 1
        [group_id] => 1
    )

    ==========================
    Queries:
    ------------------
    Array
    (
       
  • => SELECT extension, mime, content, player FROM cpg_filetypes; (0s)
        [1] => select * from cpg_plugins order by priority asc; (0s)
        [2] => delete from `deuchand_galeria`.cpg_sessions where time<1238324943 and remember=0; (0s)
        [3] => delete from `deuchand_galeria`.cpg_sessions where time<1237118943; (0s)
        [4] => select user_id from `deuchand_galeria`.cpg_sessions where session_id = '5acaff7f70edc049814e27bd65e7961f' (0.001s)
        [5] => select user_id as id, user_password as password from `deuchand_galeria`.cpg_users where user_id=1 (0s)
        [6] => SELECT u.user_id AS id, u.user_name AS username, u.user_password AS password, u.user_group+100 AS group_id FROM `deuchand_galeria`.cpg_users AS u INNER JOIN `deuchand_galeria`.cpg_usergroups AS g ON u.user_group=g.group_id WHERE u.user_id='1' (0s)
        [7] => SELECT user_group_list FROM `deuchand_galeria`.cpg_users AS u WHERE user_id='1' and user_group_list <> ''; (0s)
        [8] => SELECT MAX(group_quota) as disk_max, MIN(group_quota) as disk_min, MAX(can_rate_pictures) as can_rate_pictures, MAX(can_send_ecards) as can_send_ecards, MAX(upload_form_config) as ufc_max, MIN(upload_form_config) as ufc_min, MAX(custom_user_upload) as custom_user_upload, MAX(num_file_upload) as num_file_upload, MAX(num_URI_upload) as num_URI_upload, MAX(can_post_comments) as can_post_comments, MAX(can_upload_pictures) as can_upload_pictures, MAX(can_create_albums) as can_create_albums, MAX(has_admin_access) as has_admin_access, MIN(pub_upl_need_approval) as pub_upl_need_approval, MIN( priv_upl_need_approval) as  priv_upl_need_approval FROM cpg_usergroups WHERE group_id in (1) (0s)
        [9] => SELECT group_name FROM  cpg_usergroups WHERE group_id= 1 (0s)
        [10] => update `deuchand_galeria`.cpg_sessions set time='1238328543' where session_id = '5acaff7f70edc049814e27bd65e7961f' (0s)
        [11] => SELECT user_favpics FROM cpg_favpics WHERE user_id = 1 (0s)
        [12] => DELETE FROM cpg_banned WHERE expiry < '2009-03-29 12:09:03' (0s)
        [13] => SELECT * FROM cpg_banned WHERE (ip_addr='77.54.200.109' OR ip_addr='77.54.200.109' OR user_id=1) AND brute_force=0 (0s)
        [14] => SELECT aid, title FROM cpg_albums WHERE category < 10000 ORDER BY title (0s)
        [15] => SELECT aid, title FROM cpg_albums WHERE category='10001' ORDER BY title (0s)
        [16] => SELECT COUNT(*) FROM cpg_pictures WHERE approved = 'NO' (0s)
        [17] => SELECT unique_ID FROM cpg_temp_data (0s)
        [18] => INSERT INTO cpg_temp_data VALUES ('727f795d', 'YToxOntpOjA7YToyOntzOjExOiJhY3R1YWxfbmFtZSI7czoxMToiWXZldHRlMy5ibXAiO3M6MTQ6InRlbXBvcmFyeV9uYW1lIjtzOjIzOiJtSFRUUF90ZW1wXzkxY2NmNjZjLmJtcCI7fX0=', '1238328543') (0s)
    )

    ==========================
    GET :
    ------------------
    Array
    (
    )

    ==========================
    POST :
    ------------------
    Array
    (
        [URI_array] => Array
            (
               
  • =>
                [1] =>
                [2] =>
            )

        [control] => phase_1
    )

    ==========================
    VERSION INFO :
    ------------------
    PHP version: 5.2.8 - OK
    ------------------
    mySQL version: 5.0.67-community-log
    ------------------
    Coppermine version: 1.4.21(stable)
    ==========================
    Module: GD
    ------------------
    GD Version: bundled (2.0.34 compatible)
    FreeType Support: 1
    FreeType Linkage: with freetype
    T1Lib Support:
    GIF Read Support: 1
    GIF Create Support: 1
    JPG Support: 1
    PNG Support: 1
    WBMP Support: 1
    XPM Support: 1
    XBM Support: 1
    JIS-mapped Japanese Font Support:

    ==========================
    Module: mysql
    ------------------
    MySQL Supportenabled
    Active Persistent Links 0
    Active Links 1
    Client API version 5.0.67
    MYSQL_MODULE_TYPE external
    MYSQL_SOCKET /var/lib/mysql/mysql.sock
    MYSQL_INCLUDE -I/usr/include/mysql
    MYSQL_LIBS -L/usr/lib -lmysqlclient 
    ==========================
    Module: zlib
    ------------------
    ZLib Support enabled
    Stream Wrapper support compress.zlib://
    Stream Filter support zlib.inflate, zlib.deflate
    Compiled Version 1.2.3
    Linked Version 1.2.3
    ==========================
    Server restrictions (safe mode)?
    ------------------
    Directive | Local Value | Master Value
    safe_mode | Off | Off
    safe_mode_exec_dir | no value | no value
    safe_mode_gid | Off | Off
    safe_mode_include_dir | no value | no value
    safe_mode_exec_dir | no value | no value
    sql.safe_mode | Off | Off
    disable_functions | show_source, system, shell_exec, passthru, popen, proc_open | show_source, system, shell_exec, passthru, popen, proc_open
    file_uploads | On | On
    include_path | .:/usr/lib/php:/usr/local/lib/php | .:/usr/lib/php:/usr/local/lib/php
    open_basedir | /home/deuchand:/usr/lib/php:/usr/local/lib/php:/tmp | no value
    ==========================
    email
    ------------------
    Directive | Local Value | Master Value
    sendmail_from | no value | no value
    sendmail_path | /usr/sbin/sendmail -t -i | /usr/sbin/sendmail -t -i
    SMTP | localhost | localhost
    smtp_port | 25 | 25
    ==========================
    Size and Time
    ------------------
    Directive | Local Value | Master Value
    max_execution_time | 30 | 30
    max_input_time | 60 | 60
    upload_max_filesize | 2M | 2M
    post_max_size | 8M | 8M
    ==========================
    Page generated in 0.017 seconds - 19 queries in 0.001 seconds - Album set : ; Meta set: ;

Joachim Müller

Quote from: pjssms on March 29, 2009, 02:15:20 PM
The files are being uploaded but after uploading start beloging to nobody instead of the user.
In terms of ownership on file system level, all files that are created by the script (that's the intermediate file as well as the thumbnail) are being owned by the user the web server service runs under. That's a matter of webserver setup and not a coppermine issue. If this bothers you, change your webserver setup or ask your webhost for support.

Quote from: pjssms on March 29, 2009, 02:15:20 PM
What do you suggest to be done ?.
I suggest doing as described in the docs, section "asking for support on upload issues", as there's a reason why we have written that section of the docs.

Quote from: pjssms on March 29, 2009, 02:15:20 PM
I am copying the debug information.
Nobody asked for it.

Quote from: pjssms on March 29, 2009, 02:15:20 PM
    * Notice line 1979: Undefined variable: file_failure_array
    * Notice line 1980: Undefined variable: URI_failure_array
    * Notice line 1981: Undefined variable: zip_failure_array
Leave notices_display turned off if you have no idea what it means.

pjssms

thank you for your quick answer.

with suexecphp the gallery gives an error 500 internal server error
with php as cgi i have other scripts that don´t work

/upload.php

    * Notice line 2191: Undefined index: user1
    * Notice line 2192: Undefined index: user2
    * Notice line 2193: Undefined index: user3
    * Notice line 2194: Undefined index: user4

/include/picmgmt.inc.php

    * Notice line 170: Undefined variable: imageinfo
    * Warning line 264: imagecreatefrompng() [function.imagecreatefrompng]: 'albums/userpics/10001/Yvette3~0.bmp' is not a valid PNG file

/include/picmgmt.inc.php

    * Notice line 170: Undefined variable: imageinfo
    * Warning line 264: imagecreatefrompng() [function.imagecreatefrompng]: './albums/edit/mHTTP_temp_1bfc5f3e.bmp' is not a valid PNG file

/include/functions.inc.php

    * Notice line 2732: Undefined variable: i

I tried another format of the image and it worked.

I am not sure if my support had changed anything else in the server