PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Classifieds Support > Classifieds How do I...?

Classifieds How do I...? Wondering how to do something in Classifieds?

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old March 1st, 2007, 10:52 AM   #1 (permalink)
Member
Verified Customer
 
Join Date: Jan 2007
Posts: 32
My Classifieds have been hacked - second posting

Ok so my first post disapeared after it was answered.
My original question is how this could happen. I did a search on google and got the following result.

Edited by REDMTNEX: I removed the body of this post.


Is this a huge security hole or what is it?

Last edited by redmtnex; March 1st, 2007 at 12:43 PM.
redmtnex is offline   Reply With Quote
Old March 1st, 2007, 10:56 AM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,654
We moved your post in the moderators lounge out of the public eye cause you asked this and we already responded twice that there is no way to uploads a PHP file to our application so it appears they broke in elsewhere on your site and where able to write their file into our data directory because it is 777 permissions which it has to be to allow file uploads. I would suggest you search and see if there are exploits in other programs you use. We have not seen any on ours and the few topics over the years we have seen on this it always comes down to an external program that has an exploit. Our senior developer Michael even had something like this happen to him where they copied a file to his data directory but his investigation led to a flashchat program he used with his vbulletin forum.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old March 1st, 2007, 12:59 PM   #3 (permalink)
Member
Verified Customer
 
Join Date: Jan 2007
Posts: 32
Chuck
I never got to see the second answer and I can't get access to where it was moved.

Anyhow I did have a hit counter running in the footer, here is the code below.
I just removed it and will delete out the .php files in the data directories.
So what do you think, was it the hit counter code?

Code:
Content visible to verified customers only.
redmtnex is offline   Reply With Quote
Old March 1st, 2007, 01:36 PM   #4 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,654
It is possible I am not familiar with that app. I am sure there are other apps on your site. Just passing along the info as I see it. The only thing our program is going to put in the data directory are image files so if something else shows up there then it seems to be coming from some external app which is merely searching for a directory it can write to
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old March 1st, 2007, 03:46 PM   #5 (permalink)
Member
Verified Customer
 
Join Date: Jan 2007
Posts: 32
Thanks Chuck
And thanks Harry for your phone call this morning.
The other ap I have running is google adsence, can't imagine that playing games. For now I am going to point my finger at the counter code. Every folder that was set to 777 had a numbered .php file written into it. I saved some of them if you would like to check them out.
Greg
redmtnex is offline   Reply With Quote
Old March 1st, 2007, 03:53 PM   #6 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,654
Try deleting all of them and then remove that code and see.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old March 1st, 2007, 04:00 PM   #7 (permalink)
Member
Verified Customer
 
Join Date: Jan 2007
Posts: 32
Did that. I will give it a couple of days and see if any thing returns.
redmtnex is offline   Reply With Quote
Old March 2nd, 2007, 02:06 AM   #8 (permalink)
Junior Member
Verified Customer
 
Join Date: Feb 2006
Location: GA
Posts: 14
Actually, I have the same problem that I thought was resolved. Come to find out, some how in my data directory, there are no folders there for ads that are currently up and running. So when I try to edit the ad, it tells me that the /data/#/ is not available. And it isn't when I FTP and look inside. I have another thread that I thought was resolved. I just wanted to chime in because this happen a day ago also.
theprofessional is offline   Reply With Quote
Old March 2nd, 2007, 07:52 AM   #9 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,654
This is not the same problem as this gentleman is reporting. Your reporting a permissions issue on your data directory and you would need to contact your webhost about this and resolve the issue.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old September 24th, 2008, 10:12 AM   #10 (permalink)
Junior Member
Verified Customer
 
Join Date: Sep 2008
Posts: 9
I am posting in this thread because of the security theme and the mention of 777 permissions for the data directories.

Is there any lower permission that will work?

What are the exact security risks that I am exposed to as a result of the data directory having 777 permissions?
ColoradoGuy is offline   Reply With Quote
Old September 24th, 2008, 06:29 PM   #11 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,654
There are no security issues I am aware of having a directory set to 777 as thats needed universally for uploads to work to a server. Only way I have ever seen anyone hacked is when integrating with vbulletin and they are hacked due to a vb hack they where running.

At any rate 755 could work if your host had things worked out right but on most servers one needs 777.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old September 25th, 2008, 11:12 AM   #12 (permalink)
Junior Member
Verified Customer
 
Join Date: Sep 2008
Posts: 9
Could you please advise me of what to discuss with my host to all use of 755 for the directories?
ColoradoGuy is offline   Reply With Quote
Old September 25th, 2008, 11:16 AM   #13 (permalink)
Junior Member
Verified Customer
 
Join Date: Sep 2008
Posts: 9
Can you please confirm or deny the following that I fellow programmer shared with me? If this is a valid exploit, please delete or remove this post to a non searchable area to avoid educating the wrong people.

With a photo/data directory set to 777 you are subject to being used as an illegal photo server, including having p o r n pics posted on your site at night and removed in the morning...
ColoradoGuy is offline   Reply With Quote
Old September 25th, 2008, 05:17 PM   #14 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,654
You need to have the data directory set to 777 for uploads to work.

I cant tell you how to make it work as 755 as I am not a server host and do not know the specifics of what needs to be set on a server to allow that. I just know its possible. your host may know how to do it to allow file uploads etc without directories being 777 but for 99.9% of servers they need to be 777.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Am I getting hacked?? leo9 Classifieds Bug Reports 4 October 3rd, 2006 08:45 PM
Forum Posting & Admin Login issues Classifieds/Pro PPGVJ General Discussion 3 April 23rd, 2006 10:54 PM
I was hacked and photopost is gone Al Gregory Photopost Pro How Do I...? 6 September 17th, 2005 03:37 PM


All times are GMT -5. The time now is 05:05 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0