coppermine-gallery.com/forum

Support => cpg1.4.x Support => Older/other versions => cpg1.4 miscellaneous => Topic started by: mrinnoncent on December 19, 2006, 09:35:20 AM

Title: How can I increase security levels in gallery?
Post by: mrinnoncent on December 19, 2006, 09:35:20 AM
I have recently read some where that one of the user using coppermine gallery latest version was tried to be hacked, by placing some index file,help.zip,a.asp & some other files.

How can I prevent myself from tht kind of danger ?

Title: Re: How can I increase security levels in gallery?
Post by: Joachim Müller on December 19, 2006, 09:46:02 AM
The most recent version (cpg1.4.10) should not be vulnerable against such attacks. You mustn't allow the upload of potentially harmful files (PHP, PL etc.). There is an Apache flaw that allowed files named foo.php.rar to be parsed as PHP files. This flaw has been fixed some versions ago. Bottom line: if you really use cpg1.4.10, you should be save. If you don't, upgrade asap.

Quote from: mrinnoncent on December 19, 2006, 09:35:20 AM
I have recently read some where
Where exactly? Please post a link.
Title: Re: How can I increase security levels in gallery?
Post by: mrinnoncent on December 22, 2006, 09:45:16 AM
ok sent you pm of my address
Title: Re: How can I increase security levels in gallery?
Post by: Joachim Müller on December 22, 2006, 10:28:56 AM
I didn't ask for a PM. I told you to post your URL. Ignoring PM.
Title: Re: How can I increase security levels in gallery?
Post by: mrinnoncent on December 24, 2006, 07:18:35 AM
I didn't want the url to go public. thtz the reason pmed u.
Title: Re: How can I increase security levels in gallery?
Post by: Joachim Müller on December 24, 2006, 08:19:16 AM
Haven't asked for the URL of your site, but the address where you claim to have read about the potential flaw. ::)
Title: Re: How can I increase security levels in gallery?
Post by: mrinnoncent on December 31, 2006, 09:19:21 AM
itz my friend's website  :-\
Title: Re: How can I increase security levels in gallery?
Post by: Joachim Müller on December 31, 2006, 11:23:59 AM
Then post the URL, for christ's sake ::). Is your friend an authority in stuff related to Coppermine, or is this just a matter of the blind leading the blind?
Title: Re: How can I increase security levels in gallery?
Post by: Tranz on December 31, 2006, 06:19:14 PM
Also, you said "tried to be hacked". Was the attempt successful? Attempts do not equal success.