coppermine-gallery.com/forum

Support => cpg1.4.x Support => Older/other versions => cpg1.4 miscellaneous => Topic started by: jmcnyc on December 03, 2007, 02:54:58 AM

Title: Gallery Hacked
Post by: jmcnyc on December 03, 2007, 02:54:58 AM
I seemed to have the rar file upload problem.  I upgraded to the latest version 1.4.14 - and searched my pictures and deleted all rar files in the gallery.

This did not work.

When I ftp into the site - and browse the albums folder - I see the folder for user pics has been changed to uerpics.  Inside this folder I only have one numbered folder - although my site has hundreds of pictures.  Inside this one folder is a file bvrbrbrebreb.php.rar  I can not delete this file - don't have the right permissions.

I was worried that all the images were gone - but when I browse the database - I see the images. 

Any ideas how to get rid of the rar file - and repair what has gone wrong?

I can give the link to my site - it may be questionable content for some - so would prefer to give it out one-on-one
Title: Re: Gallery Hacked
Post by: Nibbler on December 03, 2007, 04:23:25 AM
If the files are not on the disk then you have lost them. Best thing to do is delete your Coppermine folder completely and restore from a backup. If you have permissions issues then contact your host.
Title: Re: Gallery Hacked
Post by: jmcnyc on December 03, 2007, 10:55:24 AM
Quote from: jmcnyc on December 03, 2007, 02:54:58 AM
I seemed to have the rar file upload problem.  I upgraded to the latest version 1.4.14 - and searched my pictures and deleted all rar files in the gallery.

This did not work.

When I ftp into the site - and browse the albums folder - I see the folder for user pics has been changed to uerpics.  Inside this folder I only have one numbered folder - although my site has hundreds of pictures.  Inside this one folder is a file bvrbrbrebreb.php.rar  I can not delete this file - don't have the right permissions.

I was worried that all the images were gone - but when I browse the database - I see the images. 

Any ideas how to get rid of the rar file - and repair what has gone wrong?

I can give the link to my site - it contains adult content - so would prefer to give it out one-on-one

Title: Re: Gallery Hacked
Post by: jmcnyc on December 03, 2007, 11:02:55 AM
Has this rar virus in the past done this much harm?  Deleating all the image folders?

When I delete my coppermine install - and start over again - can I export my user registration database and import it for the new install so my users dont need to re-register?

Thanks.
Title: Re: Gallery Hacked
Post by: Nibbler on December 03, 2007, 11:18:32 AM
It's not a virus. It gives the attacker control over your webspace, so they can choose to do whatever they like.

You can, but check it first for any extra admin accounts that shouldn't be there.
Title: Re: Gallery Hacked
Post by: dke on December 03, 2007, 01:30:31 PM
and how does someone get affected by this problem? am i safe? (currently running 1.4.14 CPG)
Title: Re: Gallery Hacked
Post by: Nibbler on December 03, 2007, 01:33:38 PM
You get affected if you don't keep Coppermine updated. 1.4.14 is the latest version so it is safe.