PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Pro Support Forums > Photopost Pro How Do I...?

Photopost Pro How Do I...? Wondering how to do things in PhotoPost?

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old May 2nd, 2007, 11:05 PM   #1 (permalink)
Junior Member
Verified Customer
 
Join Date: Dec 2006
Posts: 5
intruder files in "data" and "uploads" PP folders

I’m running vBulletin 3.6.4 with integrated PhotoPost 5.6.2.

Last night I noticed a bunch of .php files (file name was a string of randomly generated numbers) & modified .htaccess files in the root of number of directories and their subfolders.

Only the folders that had 777 CHMOD were compromised.

I guess my site has been hacked; not sure how.

The folders that were impacted were vBulletin’s Attachments folder and PhotoPost’s “data” and “uploads” folders.

vBulletin support folks have suggested that I move the “attachements” folders below the root of my web site; no problem there.

I’m not sure if I could do the same with the PhotoPost “data” and “uploads” folders? I don’t think so.

I manually cleaned up the files that were uploaded, but I would like to put measures in place to prevent this from happening again.

It looks like I’m all set with vBulletin – any ideas for PhotoPost?

Any suggestions would be greatly appreciated.

Last edited by adiitworks; May 2nd, 2007 at 11:20 PM.
adiitworks is offline   Reply With Quote
Old May 3rd, 2007, 09:34 AM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 66,806
You can not move uploads beneath the webroot and you can move large images underneath the webroot using the storage options but the medium and thumbs must be above the webroot as they are now.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old May 3rd, 2007, 02:10 PM   #3 (permalink)
Junior Member
Verified Customer
 
Join Date: Dec 2006
Posts: 5
Thanks for confirmation Chuck.

I saw the option to move the original pictures. Great functionality there for people who want to make sure their images are NOT being linked to from another site.

That won’t help me - the 777 directory structure still stays exposed for the bad guys.

This Internet is a crazy place ain’t it? There’s always someone out there smarter or faster than you.

I’d love to plug this hole if there’s any way to do that.

My vBulletin or Photo Post application didn’t seem to get compromised. After a careful review of permissions and configuration options, I don’t seem to have any silly wide open holes in my own settings. At least not from what I can tell. I referenced a number of “How To Make My Forums More Secure” type of threads…I seem to be in compliance for the most part. I’m currently tightening a couple of things they suggested though – removing Impex folder... I guess I could upgrade to vBulletin to 3.6.5, but I didn’t get that sense of urgency…

Can I password protect “uploads” and “data” directories using .htaccess/.htpassword ? Would that “break” PhotoPost?

Just exploring all my options.
adiitworks is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Does vBgallery allow "Insert Image" and "Upload File from a URL"? edprush vBGallery Suggestions 13 May 8th, 2010 10:23 PM
Cannot upload images when "Save Original Files" enabled SimonH Installs and Upgrade - vBulletin 3.5.X 6 October 26th, 2006 03:41 PM
PP5.3: How to delete columns "Last Comment" & "Last Photo Upload" snoopy5 Photopost Pro How Do I...? 1 April 17th, 2006 10:36 AM
Question about "Daily Upload Limit (# of files)" Johnny Doomo Photopost Pro Installation & Upgrades 1 October 14th, 2005 04:15 PM
"Scan Database" tool reports "file not found" - ALL files PageUp Installs and Upgrade - vBulletin 3.0.X 4 June 15th, 2005 11:09 AM


All times are GMT -5. The time now is 03:30 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0