they are fingerprinting my installation through DOCS directory they are fingerprinting my installation through DOCS directory
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

they are fingerprinting my installation through DOCS directory

Started by netrunnercl, November 17, 2010, 06:12:03 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

netrunnercl

Hi.

I was checkin my access logs when i realized some abnormal pattern:

fotos.MYSITE.info/docs/nl/dev_subversion.htm
fotos.MYSITE.info/docs/fr/php-content.htm
fotos.MYSITE.info/docs/es/install.htm
fotos.MYSITE.info/docs/nl/admin_menu.htm
fotos.MYSITE.info/docs/nl/requirements.htm
fotos.MYSITE.info/docs/nl/uploading_http.htm
fotos.MYSITE.info/docs/en/testing.htm
fotos.MYSITE.info/docs/nl/toc.htm
fotos.MYSITE.info/docs/en/theme_copyright.htm
fotos.MYSITE.info/docs/de/upload_troubleshooting.htm
fotos.MYSITE.info/docs/fr/exif.htm
fotos.MYSITE.info/docs/es/start.htm
fotos.MYSITE.info/docs/fr/credits.htm
fotos.MYSITE.info/docs/es/upgrading.htm
fotos.MYSITE.info/docs/de/categories.htm
fotos.MYSITE.info/docs/nl/theme.htm
fotos.MYSITE.info/docs/fr/dev_database.htm
fotos.MYSITE.info/docs/fr/requirements.htm
fotos.MYSITE.info/docs/nl/php-content.htm
fotos.MYSITE.info/docs/es/install.htm
fotos.MYSITE.info/docs/de/index.htm
fotos.MYSITE.info/docs/nl/comments.htm
fotos.MYSITE.info/docs/de/upload_troubleshooting.htm
fotos.MYSITE.info/docs/de/auto-installers.htm


If i go to this pages... the title includes de version as you can see: Coppermine Photo Gallery v1.5.6: Documentatie en Handleiding

Now i guess hackers are fingerprinting coppermine installation through /DOCS/ directory.
I have read the info about deleting part of this directory, but after this, i prefer to delete as much as i can from it.

So, my question is, what can i delete and what i cant from this directory and mantain good de installation?.

It is posible that in next versions you remove this extra info?

thanx!

ΑndrĂ©

You should upgrade instead of hiding the version number. It's important for us when supporting to know which version the user has running. The version number is displayed at other places, too.