PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |
Old December 10th, 2005, 11:48 AM   #1 (permalink)
Junior Member
Verified Customer
 
Join Date: Jun 2005
Posts: 15
Upload.php ....

"..image uploads and potentially opens a cross-site-scripting exploit. It has affected many web-based applications that allow image uploads..."

this is the description on Vbulletin.con at this thread:

http://www.vbulletin.com/forum/showthread.php?t=161721

on november, 2

My VBGallery is the last version... and BEFORE of this data....
Today I've found these files :

commands.php
common.php
system.php
time.php
.htaccess

al the files are created at the same time.... at 09.55am
the contents... NO COMMENT.

is it possible that this "malaware" are ulpoaded on my site via upload.php ?
( they are present only in the subdir of gallery... images users etc.. )

thanks in advance.
gnubittol is offline   Reply With Quote
Old December 10th, 2005, 12:44 PM   #2 (permalink)
Registered User
Verified Customer
 
Zachariah's Avatar
 
Join Date: Nov 2005
Location: Canoga Park, CA
Posts: 3,243
Send a message via ICQ to Zachariah Send a message via AIM to Zachariah Send a message via MSN to Zachariah Send a message via Skype™ to Zachariah
There are not standard gallery files included with the install package.

Take a look @ FTP access logs on the webserver to see if those might of been files uploaded in the wrong folder durring a hack install. (draged and dropped in the wrong folder)

Quote:
al the files are created at the same time.... at 09.55am
the contents... NO COMMENT.
Your saying the the files content was "blank" or just had the text "NO COMMENT" ?
Zachariah is offline   Reply With Quote
Old December 10th, 2005, 01:55 PM   #3 (permalink)
Junior Member
Verified Customer
 
Join Date: Jun 2005
Posts: 15
Thumbs down

Quote:
Originally Posted by Zachariah
There are not standard gallery files included with the install package.
I know....

Quote:
Originally Posted by Zachariah
Your saying the the files content was "blank" or just had the text "NO COMMENT" ?
No comment was for the content....for example... this is command.php
Code:
Content visible to verified customers only.
if you wonna I post all the contents of the othe files.....
but as you can read is not good... :|
gnubittol is offline   Reply With Quote
Old December 11th, 2005, 02:46 PM   #4 (permalink)
Junior Member
Verified Customer
 
Join Date: Jun 2005
Posts: 15
Bump...
gnubittol is offline   Reply With Quote
Old December 11th, 2005, 09:17 PM   #5 (permalink)
Registered User
Verified Customer
 
KW802's Avatar
 
Join Date: Nov 2005
Posts: 1,408
Gnubittol, what exactly is the question? And have you deleted those files yet?
KW802 is offline   Reply With Quote
Old December 13th, 2005, 07:27 PM   #6 (permalink)
Junior Member
Verified Customer
 
Join Date: Jun 2005
Posts: 15
Quote:
Originally Posted by KW802
Gnubittol, what exactly is the question? And have you deleted those files yet?
These files were "uploaded" in my web space Only in the folders with "777" chmod , and in the "Files" folder of vbgallery, of course, were presents.

the question is:
Is a bug of PHP or a bug of VBGallery?

These files was REMOVED immediatly from the server and I changed the permissions on all "777" folders NOW vbGalery is READ ONLY ( no upload is available) .....
gnubittol is offline   Reply With Quote
Old November 7th, 2007, 03:42 PM   #7 (permalink)
Junior Member
Verified Customer
 
Join Date: Apr 2007
Posts: 13
And this is still a problem, got exactly the same issue this evening.

Part of the installation manual says;

Now create a directory on your web server for PhotoPost. The directory needs to be accessible via the web. FTP PhotoPost's directories and files from your local machine to your server. The directory structure on your server should be as follows:

photopost
images (chmod 755)
uploads (chmod 777)
help (chmod 755)
data (chmod 777)
1 (chmod 777 - including subdirectories)
2 (chmod 777 - including subdirectories)
500 (chmod 777 - including subdirectories)
languages (chmod 755) (a
stylesheets (chmod 777)
templates (chmod 777)
forums (chmod 755)



So my questions now is, if i set data and uploads to 755 will i then not be able to upload anything in the photo gallery?

What can i do to prevent the photo gallery from being hacked?

I use PhotoPost 562
TheLastMohican is offline   Reply With Quote
Old November 10th, 2007, 06:02 AM   #8 (permalink)
Junior Member
Verified Customer
 
Join Date: Apr 2007
Posts: 13
No answer from any support people or developers here?

Can PhotoPost work if the data, uploads, templates are not set to 777? I would like to have an answer, thanks.
TheLastMohican is offline   Reply With Quote
Old November 10th, 2007, 06:06 AM   #9 (permalink)
Member
Verified Customer
 
Join Date: Nov 2005
Location: Southern Germany
Posts: 194
Maybe no response because you're in the wrong forum category, this is for vbgallery.
Ramses is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Upload Problem - image-inc.php - line 37 Rik Brown Photopost Pro Installation & Upgrades 2 November 30th, 2005 12:33 AM
Upload Link (uploadproduct.php) doesn't work autobrad ReviewPost Installation & Upgrades 13 June 17th, 2005 08:09 AM
question re header-inc.php and install.php Carolem Photopost Pro Installation & Upgrades 1 June 8th, 2005 06:24 AM
Upgrade init.php conflicting with functions_gallery.php golfrewind Installs and Upgrade - vBulletin 3.0.X 2 January 12th, 2005 04:17 AM
Problem with showproduct.php and showcat.php jed423 Classifieds Bug Reports 4 November 14th, 2004 11:48 AM


All times are GMT -5. The time now is 07:07 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0