PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Pro Support Forums > Photopost Pro Bug Reports

Photopost Pro Bug Reports Post post installation PhotoPost Pro problems here.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old May 12th, 2009, 01:05 PM   #1 (permalink)
Member
Verified Customer
 
auto_freak's Avatar
 
Join Date: Apr 2008
Posts: 161
Gumblar Virus in my Templates

Hello,

I cleaned up all the php files still some users are complaining that some virus detection problems are still rising through their browser and virus scanners. Basically, I found out the malicious code that is inserted into the templates of my site. Those codes dont appear in the forum however, but does appear in the classifieds and gallery sections. The templates are being pulled from vbulletin so I belive a simple template edit might fix it. But I am not sure where I can find this code, I searched the header template, forumhome, footer and many other templates, nowhere could be found.

Any guess where this code is from? Please let me know, its troubling and getting rid off my web visitors. My templates are heavily edited and a new template installation might just scare people away.

Code:
Content visible to verified customers only.
__________________
Meer Tauhid Husain
Chairman, WheelsBD Automobile Club Ltd.
www.wheelsBD.com
auto_freak is offline   Reply With Quote
Old May 12th, 2009, 01:07 PM   #2 (permalink)
Member
Verified Customer
 
auto_freak's Avatar
 
Join Date: Apr 2008
Posts: 161
the code in bold is the actual virus code...
__________________
Meer Tauhid Husain
Chairman, WheelsBD Automobile Club Ltd.
www.wheelsBD.com
auto_freak is offline   Reply With Quote
Old May 12th, 2009, 01:11 PM   #3 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 52,667
I would suggest possibly checking your altered files.

My support response would be to upload clean php and templates

You can check pp-inc.php for the code noted in here but that is where the ajaxcode is in the printheader function.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old May 12th, 2009, 01:13 PM   #4 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 52,667
Most hacks are a result of improper file permissions and or modifications to default base code that allow people access.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old May 12th, 2009, 01:14 PM   #5 (permalink)
Member
Verified Customer
 
auto_freak's Avatar
 
Join Date: Apr 2008
Posts: 161
I uploaded fresh new files of php and tmpl, basically uploaded fresh files from photopost gallery and photopost classifieds, vbulletin forum as well. This has to be in the styles/templates in my site....since the style has not been replaced. The styles are heavily edited so you think a fresh upload is necessary or can you see and dig out wherever this code is actually in?
__________________
Meer Tauhid Husain
Chairman, WheelsBD Automobile Club Ltd.
www.wheelsBD.com
auto_freak is offline   Reply With Quote
Old May 12th, 2009, 01:22 PM   #6 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 52,667
So your saying this is in your vbulletin templates?

If you turn off your vbulletin integration boxes under admin edit integration does it appear in your page source anymore?

If you upload clean photopost stuff then the code should not exist in photopost and then you know its pulling it from vb which means you need to sanitize and remove the code from vb templates etc

Places to look in vb would be the header or header-inc templates
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old May 12th, 2009, 01:25 PM   #7 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 52,667
Or possibly in one of your vb plugins like the UKBL ~Menu Styles
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old May 12th, 2009, 02:21 PM   #8 (permalink)
Member
Verified Customer
 
auto_freak's Avatar
 
Join Date: Apr 2008
Posts: 161
As I found out, this is not even in the templates, the viruses are probably still there in the server...I installed a completely new style, still the same problems. Where in the server can these codes be found?
__________________
Meer Tauhid Husain
Chairman, WheelsBD Automobile Club Ltd.
www.wheelsBD.com
auto_freak is offline   Reply With Quote
Old May 12th, 2009, 02:34 PM   #9 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 52,667
I do not beleive these would be on the server they have to be in files.

What happened when you turned off the vb3 integration under edit integration?
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old May 12th, 2009, 02:37 PM   #10 (permalink)
Member
Verified Customer
 
auto_freak's Avatar
 
Join Date: Apr 2008
Posts: 161
I turned off the vb3 integration and the code remained there even then. The stylesheets were obviously all white, but that malicious code was still found in the source code.
__________________
Meer Tauhid Husain
Chairman, WheelsBD Automobile Club Ltd.
www.wheelsBD.com
auto_freak is offline   Reply With Quote
Old May 12th, 2009, 02:47 PM   #11 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 52,667
You host might need to assist you there. I cant tell you anything more than to upload clean files. It is being placed right before your body tag of the page.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old May 12th, 2009, 03:15 PM   #12 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 52,667
We call anything for our head close and body tag in two places.

One in pp-inc.php for a non vb integrated page.

Code:
Content visible to verified customers only.
and for vb integrated in header-inc.php

Code:
Content visible to verified customers only.
If there is no code inserted between there in any of our files then I would have no idea where its being executed from.

This I assume is what your trying to remove

Code:
Content visible to verified customers only.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old May 12th, 2009, 03:19 PM   #13 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 52,667
Also something else to consider

Gumblar .cn Exploit - 12 Facts About This Injected Script | Unmask Parasites. Blog.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old May 12th, 2009, 04:25 PM   #14 (permalink)
Member
Verified Customer
 
auto_freak's Avatar
 
Join Date: Apr 2008
Posts: 161
Chuck, thanks for all the help. owe you one, a fresh upload of clean photopost gallery and classifieds files was enough to fix this issue. give me some tips on how to maintain server security.
__________________
Meer Tauhid Husain
Chairman, WheelsBD Automobile Club Ltd.
www.wheelsBD.com
auto_freak is offline   Reply With Quote
Old May 12th, 2009, 04:40 PM   #15 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 52,667
Well I would make sure that all files etc are maintained with permissions as noted here

PhotoPost PHP Photo Sharing Photo Gallery Installation Guide

One word of caution though. While there are no reported ways to break the photopost script tieing it to vbulletin that has hacks/mods can open up exploits. I always suggest running stock sites and not using code posted by others.

Like there was one reported post where users found .php files throughout the data folder of photopost and Michael himself at one time was a victum of this and it came down to a flashchat for vb Michael has installed. Once your ftp or some other file is compromised users can easily alter any file that is writable on the server or any directory.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old May 12th, 2009, 11:56 PM   #16 (permalink)
Ultimate Member
Verified Customer
 
skidpics's Avatar
 
Join Date: Jun 2007
Location: Texas
Posts: 1,353
Send a message via AIM to skidpics Send a message via Yahoo to skidpics
can you reupload the new file, then apply read only cmod to it?
__________________
-- Skidpics



Skidpics.com is for sale! Domain Name + content - contact me

I decided to get out of the photo hosting business. It was good while it lasted. With that, I present FacesofWoW.net - World of Warcraft Social Site[/color]
skidpics is offline   Reply With Quote
Old May 12th, 2009, 11:57 PM   #17 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 52,667
yes all files except those noted should be 644 which is the server default so uploading it should default to that.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old May 21st, 2009, 09:27 AM   #18 (permalink)
Registered User
 
Join Date: May 2009
Posts: 1
content for verified customers only !?
Lewzor is offline   Reply With Quote
Old May 21st, 2009, 10:32 AM   #19 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 52,667
Yes this is a support site! You need to be a verified customer to obtain support.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Templates? InterFX ReviewPost Suggestions 6 March 28th, 2009 12:26 PM
Templates- what each does peteuga ReviewPost How do I...? 1 December 12th, 2007 10:52 AM
Posible virus in a .jpg what to do? Geiri Photopost Pro How Do I...? 3 September 13th, 2007 11:47 AM
templates sbuncha Classifieds How do I...? 2 January 9th, 2006 01:54 PM


All times are GMT -5. The time now is 02:30 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0