coppermine-gallery.com/forum

Support => cpg1.4.x Support => Older/other versions => cpg1.4 miscellaneous => Topic started by: eXess on May 29, 2007, 02:47:26 AM

Title: My site was hacked
Post by: eXess on May 29, 2007, 02:47:26 AM
My site has been hacked twice this month, fortunately i've managed to recover it. How can I give you information to fix the possible exploit?
Title: Re: My site was hacked
Post by: Joachim Müller on May 29, 2007, 07:13:05 AM
If you have actually discovered a genuine bug/vulnerability in Coppermine itself, you're allowed to PM it to me. You could as well post it here publicly, since we don't believe in security by obscurity. If you have actually discovered a genuine vulnerability, we will come up with a fix asap.
Title: Re: My site was hacked
Post by: eXess on June 08, 2007, 08:53:05 PM
Well, I don't know where is the problem. Some guy is hacking my site and leaving dirty messages, accusing me. How can I discover where is the vulnerability ?
Title: Re: My site was hacked
Post by: Nibbler on June 08, 2007, 09:28:03 PM
Are you running the latest version of Coppermine and sure the attack is actually via Coppermine?
Title: Re: My site was hacked
Post by: Joachim Müller on June 09, 2007, 05:23:00 PM
Is the site in question http://portal.pazardjik.com/cpg/ (which is on cpg1.4.10)? If yes: when did you upgrade to cpg1.4.10? What do you actually mean by saying that your site got hacked? Did the attacker post comment spam? Did your site get defaced? Post screenshots of the defacement by attaching them to this posting (using "additional options" when composing your message). Your main site appears to be using PHP-Fusion: are you sure that it was actually Coppermine that got hacked? It's very likely that your portal got hacked instead.