PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Pro Support Forums > Photopost Pro Bug Reports

Photopost Pro Bug Reports Post post installation PhotoPost Pro problems here.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old April 3rd, 2007, 08:00 AM   #1 (permalink)
Member
Verified Customer
 
Join Date: Mar 2005
Location: Lancaster, PA
Posts: 44
Ebay Spoof - Site Hacked

Need help! Gallery (5.6.2) has been hacked. It looks like they are exploiting uploadphoto.php. In the uploads directory they were able to upload a php and html file. In addition, I don't have file permissions for either file since they were CHMOD 600. Before contacting our webhost to delete the directory I thought you may want to see.

http://www.woodcarvingillustrated.co.../uploads/3670/.
starman is offline   Reply With Quote
Old April 3rd, 2007, 08:05 AM   #2 (permalink)
Member
Verified Customer
 
1996 328ti's Avatar
 
Join Date: Aug 2004
Location: Greenville, SC
Posts: 195
What is odd is that I don't see any links to a rogue site.
1996 328ti is offline   Reply With Quote
Old April 3rd, 2007, 09:07 AM   #3 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,682
I do not see any way in any form that they are uploading a php file through Photopost and there is no evidence of this at all. Your uploads directory is 777 which has to be set so to allow file uploads to it. Your hacker could get in through many doors on your site and find a directory that is 777 to dump that file in

The only way he would be able to upload a PHP file is if you allowed by you setting it as a multimedia type. Like the next guy said where is the hacking? You can safely just clear out all directories beneath the uploads directory and you should be fine
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old April 3rd, 2007, 10:47 AM   #4 (permalink)
Member
Verified Customer
 
Join Date: Mar 2005
Location: Lancaster, PA
Posts: 44
Chuck thank you for looking into. Currently, the gallery doesn't not allow multimedia files and jumped the gun when I saw php files inside the upload directory and assumed they got there from the upload script. I had our host remove the directories. Currently, I am speculating the exploit is from a mail form script and not photopost.
starman is offline   Reply With Quote
Old April 3rd, 2007, 11:17 AM   #5 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,682
yeah Michael had something like this a while back and it turned out to be one of his vb hacks that one uses off of vbulletin.org so its pretty common for hackers to break in and dump stuff in a directory that is 777.

Being that this specific hacker dumped it in that specific upload directory I would speculate it is that specific user.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old April 3rd, 2007, 06:34 PM   #6 (permalink)
PhotoPost Developer
Verified Customer
 
Join Date: Jan 2002
Posts: 11,834
My server was hacked using a version of FlashChat... they put files all through my website directory structure..
__________________
Please do not PM me for support or sales questions. Thank you for your understanding.
Michael P is offline   Reply With Quote
Old April 4th, 2007, 12:41 PM   #7 (permalink)
Member
Verified Customer
 
Join Date: Mar 2005
Location: Lancaster, PA
Posts: 44
Thanks Michael

No Flash Chat Installed. The hacks I have installed are

NoSpam!
Prevent Spam
Add PhotoPost Pro to each forum
Separate Sticky and Normal Threads
vBSEO
vBSEO :: Conditional Signatures
Welcome Headers
VB Spell Check

I believe the exploit might be coming from a mail form script "PHPforms" which I removed. So far so good and no new files created. That said maybe they haven't been back either.
starman is offline   Reply With Quote
Old April 4th, 2007, 03:55 PM   #8 (permalink)
Senior Member
 
Join Date: Mar 2003
Posts: 1,319
firefox told me your site was dodgy... suspected something or other...
b6gm6n is offline   Reply With Quote
Old April 9th, 2007, 09:43 AM   #9 (permalink)
Member
Verified Customer
 
Join Date: Mar 2005
Location: Lancaster, PA
Posts: 44
Finding specific user

"Being that this specific hacker dumped it in that specific upload directory I would speculate it is that specific user."

uploads/3670/

So would 3670 be the User ID in the VB user table?
starman is offline   Reply With Quote
Old April 9th, 2007, 10:59 AM   #10 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,682
yes that is the userid thing but if you removed php forms and no new occurrences just keep an eye on things
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old April 9th, 2007, 11:05 AM   #11 (permalink)
Member
Verified Customer
 
Join Date: Mar 2005
Location: Lancaster, PA
Posts: 44
It has been quite on the home front since removing the forms. More of just an fyi...
starman is offline   Reply With Quote
Old May 25th, 2007, 01:56 PM   #12 (permalink)
Member
Verified Customer
 
Join Date: Mar 2005
Location: Lancaster, PA
Posts: 44
I've been battling this off and on again for the last month on another site. I found the following http://www.scrollsawer.com/gallery/templates/cmd.php. Since the file is 600 I'm going to have the webhost download for forensics and delete from the server. Does this provide any info on Photposts end.
starman is offline   Reply With Quote
Old May 25th, 2007, 01:59 PM   #13 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,682
Not really your templates directory is not 777 so unless you have set that directory to be uploadable then that file could not get there. I would suspect someone has uploaded that file through a security hole in some vb hack you have installed and they then use that script to upload other files to your site
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old May 25th, 2007, 02:16 PM   #14 (permalink)
Member
Verified Customer
 
Join Date: Mar 2005
Location: Lancaster, PA
Posts: 44
The template directory is 777 according to the install instructiuons. Should I set it to something else?

photopost
images (chmod 755)
uploads (chmod 777)
help (chmod 755)
data (chmod 777)
1 (chmod 777 - including subdirectories)
2 (chmod 777 - including subdirectories)
500 (chmod 777 - including subdirectories)
languages (chmod 755) (a
stylesheets (chmod 777)
templates (chmod 777)
forums (chmod 755)
starman is offline   Reply With Quote
Old May 25th, 2007, 05:14 PM   #15 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,682
Those are the templates themselves not the directory
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Help with hacked site katers Photopost Pro How Do I...? 10 February 27th, 2007 06:32 AM
Am I getting hacked?? leo9 Classifieds Bug Reports 4 October 3rd, 2006 08:45 PM
eBay auctions - charge to credit card instead of PayPal nimzie Classifieds Suggestions 2 March 25th, 2005 01:59 PM
Copied Reviewpost to new site - evrything points to old site criscokid ReviewPost Installation & Upgrades 6 January 9th, 2005 01:03 PM


All times are GMT -5. The time now is 01:49 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0