How can I increase security levels in gallery? How can I increase security levels in gallery?
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

How can I increase security levels in gallery?

Started by mrinnoncent, December 19, 2006, 09:35:20 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

mrinnoncent

I have recently read some where that one of the user using coppermine gallery latest version was tried to be hacked, by placing some index file,help.zip,a.asp & some other files.

How can I prevent myself from tht kind of danger ?


Joachim Müller

The most recent version (cpg1.4.10) should not be vulnerable against such attacks. You mustn't allow the upload of potentially harmful files (PHP, PL etc.). There is an Apache flaw that allowed files named foo.php.rar to be parsed as PHP files. This flaw has been fixed some versions ago. Bottom line: if you really use cpg1.4.10, you should be save. If you don't, upgrade asap.

Quote from: mrinnoncent on December 19, 2006, 09:35:20 AM
I have recently read some where
Where exactly? Please post a link.

mrinnoncent


Joachim Müller

I didn't ask for a PM. I told you to post your URL. Ignoring PM.

mrinnoncent

I didn't want the url to go public. thtz the reason pmed u.

Joachim Müller

Haven't asked for the URL of your site, but the address where you claim to have read about the potential flaw. ::)

mrinnoncent


Joachim Müller

Then post the URL, for christ's sake ::). Is your friend an authority in stuff related to Coppermine, or is this just a matter of the blind leading the blind?

Tranz

Also, you said "tried to be hacked". Was the attempt successful? Attempts do not equal success.