PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > General Forums > General Discussion

General Discussion General use discussion forum for PhotoPost products.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old January 9th, 2008, 11:26 AM   #21 (permalink)
Junior Member
Verified Customer
 
Join Date: Dec 2006
Posts: 17
Same here..? I just downloaded clean.php from the first page.

Working in

Scanning for PHP files in your gallery files directory:

Warning: readdir(): supplied argument is not a valid Directory resource in /admincp/clean.php on line 26

Warning: closedir(): supplied argument is not a valid Directory resource in /admincp/clean.php on line 55
processed 0 files


Click Here to remove all files listed

Please remember to delete this clean.php file from your server when done.

Quote:
Originally Posted by V-Rodforums View Post
This is what I get when I try to run the clean.php script.

Working in

Scanning for PHP files in your gallery files directory:

Warning: readdir(): supplied argument is not a valid Directory resource in /admincp/clean.php on line 17

Warning: closedir(): supplied argument is not a valid Directory resource in /admincp/clean.php on line 46
processed 0 files


Click Here to remove all files listed

Please remember to delete this clean.php file from your server when done.
Primopup is offline   Reply With Quote
Old January 9th, 2008, 11:37 AM   #22 (permalink)
Member
Verified Customer
 
Join Date: Oct 2003
Posts: 72
Quote:
Originally Posted by Zachariah View Post
@ V-Rodforums

- I see your problem.
- I did not factor for a code change that gets your directory path on the older gallery version.

1st post attachment updated.
Thanks Zach, I know your working on it, that brings me back the same error as primeopup with a 26 and 55.
V-Rodforums is offline   Reply With Quote
Old January 9th, 2008, 11:41 AM   #23 (permalink)
Member
Verified Customer
 
Join Date: Dec 2004
Posts: 92
thanks for your help, Zachariah!
Happy Camper is offline   Reply With Quote
Old January 9th, 2008, 11:54 AM   #24 (permalink)
Member
Verified Customer
 
Join Date: Jan 2004
Posts: 86
Thanks for the update and security announcement.
rinkrat is offline   Reply With Quote
Old January 9th, 2008, 11:59 AM   #25 (permalink)
PhotoPost Developer
Verified Customer
 
Join Date: Jan 2002
Posts: 11,858
I moved the thread here since every post sends out a notice to a many of our users subscribe to the Announcements forum for notices.
__________________
Please do not PM me for support or sales questions. Thank you for your understanding.
Michael P is offline   Reply With Quote
Old January 9th, 2008, 12:15 PM   #26 (permalink)
Member
Verified Customer
 
Join Date: Aug 2005
Location: NYC
Posts: 63
Quote:
Originally Posted by Primopup View Post
Same here..? I just downloaded clean.php from the first page.

Working in

Scanning for PHP files in your gallery files directory:

Warning: readdir(): supplied argument is not a valid Directory resource in /admincp/clean.php on line 26

Warning: closedir(): supplied argument is not a valid Directory resource in /admincp/clean.php on line 55
processed 0 files


Click Here to remove all files listed

Please remember to delete this clean.php file from your server when done.
Experiencing same issue here when attempting to use clean.php

Zach - is it possible that the admincp directory being renamed to something like admincpx/ could be causing the problem?
antivirus is offline   Reply With Quote
Old January 9th, 2008, 12:34 PM   #27 (permalink)
Junior Member
 
Join Date: Jul 2005
Posts: 3
It seems that the directory variable can not be read.

Quick fix: Open clean.php find
listdir($ppg_options['gallery_filedirectory']);

change it to your path, for example
listdir("/your/path/to/gallery/files");

save, upload and re-run it.

Then change the path again for the userfolder:
listdir("/your/path/to/gallery/users");

re-run it.
Snobbytec is offline   Reply With Quote
Old January 9th, 2008, 01:02 PM   #28 (permalink)
Member
Verified Customer
 
Join Date: Aug 2005
Location: NYC
Posts: 63
Quote:
Originally Posted by Snobbytec View Post
It seems that the directory variable can not be read.

Quick fix: Open clean.php find
listdir($ppg_options['gallery_filedirectory']);

change it to your path, for example
listdir("/your/path/to/gallery/files");

save, upload and re-run it.

Then change the path again for the userfolder:
listdir("/your/path/to/gallery/users");

re-run it.
Thanks Snobbytech, that worked just fine.
antivirus is offline   Reply With Quote
Old January 9th, 2008, 01:16 PM   #29 (permalink)
Member
Verified Customer
 
Join Date: Oct 2003
Posts: 72
Quote:
Originally Posted by Snobbytec View Post
It seems that the directory variable can not be read.

Quick fix: Open clean.php find
listdir($ppg_options['gallery_filedirectory']);

change it to your path, for example
listdir("/your/path/to/gallery/files");

save, upload and re-run it.

Then change the path again for the userfolder:
listdir("/your/path/to/gallery/users");

re-run it.
Thanks, that seems to do it. Can I assume that this means I had no files with problems?

Working in

Scanning for PHP files in your gallery files directory:
processed 130631 files


Click Here to remove all files listed

Please remember to delete this clean.php file from your server when done.
V-Rodforums is offline   Reply With Quote
Old January 9th, 2008, 01:28 PM   #30 (permalink)
Registered User
Verified Customer
 
Zachariah's Avatar
 
Join Date: Nov 2005
Location: Canoga Park, CA
Posts: 3,243
Send a message via ICQ to Zachariah Send a message via AIM to Zachariah Send a message via MSN to Zachariah Send a message via Skype™ to Zachariah
Quote:
Originally Posted by V-Rodforums View Post
Thanks, that seems to do it. Can I assume that this means I had no files with problems?

Working in

Scanning for PHP files in your gallery files directory:
processed 130631 files


Click Here to remove all files listed

Please remember to delete this clean.php file from your server when done.
Your good
- No problems

---------------------------------------------------

EX: Output of problems
There will be a file list output to review:

Scanning for PHP files in your gallery files directory:
Found file -> /home/public_html/gallery/files/1/phpinfo.php.psd
Found file -> /home/public_html/gallery/files/1/somefile.cgi
Found file -> /home/public_html/gallery/files/1/somefile.pl
Found file -> /home/public_html/gallery/files/1/somefile.php.wmv
Found file -> /home/public_html/gallery/files/1/somefile.php.wav
Found file -> /home/public_html/gallery/files/clean.php
processed 6088 files
6 PHP files found!


Click Here to remove all files listed

Please remember to delete this clean.php file from your server when done.

*CLICK*

Scanning for PHP files in your gallery files directory:
Found file -> /home/public_html/gallery/files/1/phpinfo.php.psd
Removing file -> /home/public_html/gallery/files/1/phpinfo.php.psd
Found file -> /home/public_html/gallery/files/1/somefile.cgi
Removing file -> /home/public_html/gallery/files/1/somefile.cgi
Found file -> /home/public_html/gallery/files/1/somefile.pl
Removing file -> /home/public_html/gallery/files/1/somefile.pl
Found file -> /home/public_html/gallery/files/1/somefile.php.wmv
Removing file -> /home/public_html/gallery/files/1/somefile.php.wmv
Found file -> /home/public_html/gallery/files/1/somefile.php.wav
Removing file -> /home/public_html/gallery/files/1/somefile.php.wav
Found file -> /home/public_html/gallery/files/clean.php
Removing file -> /home/public_html/gallery/files/clean.php
processed 6088 files
6 PHP files found!
6 files removed!
Zachariah is offline   Reply With Quote
Old January 9th, 2008, 03:25 PM   #31 (permalink)
Junior Member
Verified Customer
 
Join Date: Jul 2005
Posts: 2
Trying to patch vB Gallery v 2.1

This code: (I can't find)
$filename = preg_replace("/[^a-zA-Z0-9\-_\.]+/", "_", $filename);
$filename = strtolower($filename);

This code: ( I can find)
$filename = preg_replace("/[^a-z_.0-9-]/i", '', $filename);
---------------------------

Do I replace : $filename = preg_replace("/[^a-z_.0-9-]/i", '', $filename);

With:
$ext = substr($filename,strrpos($filename,".")+1);
$name = preg_replace( "/\.\w+$/U", "", $filename );
$name = preg_replace(array('/\.php/', '/\.php3/', '/\.php4/', '/\.php5/', '/\.php6/', '/\.pl/', '/\.cgi/'), "", $name);
$name = preg_replace("#[^a-z0-9_,]#i", " ", $name);
$name = trim(str_replace("_", " ", $name));
$name = str_replace(" ", "_", $name);

$filename = strtolower($name.'.'.$ext);
unset($name, $ext);


Thanks for any help.
imported_Allen is offline   Reply With Quote
Old January 9th, 2008, 04:48 PM   #32 (permalink)
Registered User
Verified Customer
 
Zachariah's Avatar
 
Join Date: Nov 2005
Location: Canoga Park, CA
Posts: 3,243
Send a message via ICQ to Zachariah Send a message via AIM to Zachariah Send a message via MSN to Zachariah Send a message via Skype™ to Zachariah
@imported_Allen

You should have 2 lines of code right next to each other starting with
Quote:
$filename =
Just below:
Quote:
$imginfo['truename'] = $filename;
Zachariah is offline   Reply With Quote
Old January 9th, 2008, 04:57 PM   #33 (permalink)
Member
Verified Customer
 
Join Date: Apr 2004
Posts: 194
I must say, it's quite slack to have allowed this exploit to occur in the first place, but totally rude not to supply people with free 'upgrades' to the unexploited version.

As with Allan, I don't have that code to find/replace in v2.2.

A suggestion to avoid multiple unhappier customers, provide the fix for all versions.
kall is offline   Reply With Quote
Old January 9th, 2008, 05:30 PM   #34 (permalink)
Junior Member
Verified Customer
 
Join Date: Jul 2005
Posts: 2
@ Zacharia

This is what I have:

$imginfo['truename'] = $filename;
$filename = urldecode($filename);
$filename = preg_replace("/[^a-z_.0-9-]/i", '', $filename);
imported_Allen is offline   Reply With Quote
Old January 9th, 2008, 08:37 PM   #35 (permalink)
Member
Verified Customer
 
Join Date: Oct 2004
Location: Florida
Posts: 318
How does one determine the version number currently installed? I don't find it in the script headers or the config file and I have the brand free option.

Skip it. I found it under admin > vBGallery > Statistics

Last edited by oldengine; January 9th, 2008 at 08:45 PM.
oldengine is offline   Reply With Quote
Old January 9th, 2008, 08:59 PM   #36 (permalink)
Registered User
Verified Customer
 
Zachariah's Avatar
 
Join Date: Nov 2005
Location: Canoga Park, CA
Posts: 3,243
Send a message via ICQ to Zachariah Send a message via AIM to Zachariah Send a message via MSN to Zachariah Send a message via Skype™ to Zachariah
Good idea kall

1.0.0 - 2.1
Code:
Content visible to verified customers only.
2.2, 2.3
Code:
Content visible to verified customers only.
2.4 +
Code:
Content visible to verified customers only.
---------------------------------------------------------

@Oldengine

AdminCP -> vBGallery => Statistics
- Installed Version: x.x.x

OR

vBulletin 3.0 - 3.5
Code:
Content visible to verified customers only.
vBulletin 3.5 - 3.6+
Code:
Content visible to verified customers only.
Zachariah is offline   Reply With Quote
Old January 9th, 2008, 11:00 PM   #37 (permalink)
Junior Member
Verified Customer
 
Join Date: Aug 2004
Location: Ashland, MO
Posts: 6
Is there a new update for the "Clean" scanner script? What I used in the email (PhotoPost vBGallery Important Security Bulletin) is no help. My site is hacked big time! Ordered upgrade and to see if that would be faster.
Ozark is offline   Reply With Quote
Old January 9th, 2008, 11:19 PM   #38 (permalink)
Member
Verified Customer
 
Join Date: Apr 2005
Posts: 260
Thanks for providing the fix! The clean.php file needs to be fixed as I had to manually add my files directory to the script.
0ptima is offline   Reply With Quote
Old January 10th, 2008, 12:53 AM   #39 (permalink)
Member
Verified Customer
 
Join Date: Jan 2007
Location: Oklahoma
Posts: 36
since this is actually an apache security hole, will it affect my photopost install which is running on IIS6?
AtomicVette is offline   Reply With Quote
Old January 10th, 2008, 01:36 AM   #40 (permalink)
PhotoPost CEO
 
Join Date: Apr 2003
Posts: 4,758
Quote:
Originally Posted by Ozark View Post
Is there a new update for the "Clean" scanner script? What I used in the email (PhotoPost vBGallery Important Security Bulletin) is no help. My site is hacked big time! Ordered upgrade and to see if that would be faster.
The clean script only removes files that hackers might have uploaded using vBGallery. It doesn't repair anything that a hacker might have done to your site using those uploaded files, since there's no way for us to know what they did or didn't do. A hacker executing a malicious script on your server can do anything from wiping your server's hard drive clean, and deleting your databases, to just changing a few pages around. That's why we always recommend backing up your server daily - most hosts offer these services included. Hackers will always find a way to do their thing despite software developers' best efforts.
ScottW is offline   Reply With Quote
Reply

« Optimization | Iptc »

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
vbAdvanced vBGallery to Photopost Import Script Chuck S Photopost Pro Import Scripts 18 July 16th, 2009 03:49 PM
vBGallery to Photopost Pro Import Script StuartDH Photopost Pro How Do I...? 4 September 29th, 2007 06:04 PM
Photopost to VBgallery import script Silver_2000 How Do I? - vBulletin 3.6x 10 February 18th, 2007 11:08 AM
Import script for Photopost VBGallery attroll Photopost Pro How Do I...? 6 February 4th, 2006 04:32 PM
Cant download PhotoPost to vBGallery import script? Zilvia.net General Discussion 1 December 18th, 2005 08:42 PM


All times are GMT -5. The time now is 08:04 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0