coppermine-gallery.com/forum

Support => cpg1.4.x Support => Older/other versions => cpg1.4 miscellaneous => Topic started by: halfpint on August 31, 2007, 01:02:03 PM

Title: Is there a way for a hacker to get in through a hole in the msql data base
Post by: halfpint on August 31, 2007, 01:02:03 PM
Hi my website has been hacked twice now first they deleted the whole website now today they deleted the index page
My server host sent me this "but keep in mind if your scripts have SQL injection or other vulnerabilities this isn't something we can really actively scan for. You'll need to keep any scripts and/or CMS systems you have installed updated to the latest versions."

I have coppermine v1.4.10 with no mods or bridges

Is there a way that a hacker can get into my public_html folder and delete all my files using a hole in the coppermine sql script, If there is, is there a patch for this

regards


Title: Re: Is there a way for a hacker to get in through a hole in the msql data base
Post by: Hein Traag on August 31, 2007, 01:10:07 PM
QuoteI have coppermine v1.4.10 with no mods or bridges

Coppermine 1.4.12 is the stable and secure version. You have to update because 1.4.10 had some security issues.
Upgrading a.s.a.p. should put a stop to annoying hackers as wel.

Read this to know what has changed: http://forum.coppermine-gallery.net/index.php?topic=44924.0 (http://forum.coppermine-gallery.net/index.php?topic=44924.0)
Title: Re: Is there a way for a hacker to get in through a hole in the msql data base
Post by: halfpint on August 31, 2007, 01:21:06 PM
ok thanks will this upgrade the current version i have with no problems as the version i installed was from fantastico on my server host

regards
Title: Re: Is there a way for a hacker to get in through a hole in the msql data base
Post by: Hein Traag on August 31, 2007, 01:26:23 PM
 ;D Search for Fantastico on this board to find out how much it is not liked at all.

Your better off doing a fresh install instead of updating the fantastico installation. Save your db before doing so.
Title: Re: Is there a way for a hacker to get in through a hole in the msql data base
Post by: halfpint on August 31, 2007, 01:43:52 PM
oh no i hate it when people say that, :) This means trouble for me o how i hate scripts

I think i will talk to the tech guys on my server before i install the upgrade

Thanks for all your help it is appreciated :)
Title: Re: Is there a way for a hacker to get in through a hole in the msql data base
Post by: Joachim Müller on September 04, 2007, 09:26:35 AM
Don't make your techs perform the upgrade for you. Performing the upgrade is extremely easy, you don't need to know nor understand scripts. Just read the upgrade section of the docs and do exactly as suggested there.