PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Pro Support Forums > Photopost Pro How Do I...?

Photopost Pro How Do I...? Wondering how to do things in PhotoPost?

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old July 12th, 2007, 01:07 PM   #1 (permalink)
Member
Verified Customer
 
Join Date: Jun 2003
Location: S'pore
Posts: 81
Hacking Alert

I am using the latest version of PhotoPost and it was hacked.

I received notification that this account is getting high loads.

In WHM I saw someone was creating the load by accessing some files in photopost

/photos/data/500/search/stats.php?addurlhttp%3A%2F%2Fwww.s

/photos/data/500/search/distrib_stats.php?takeurl1

These files are not part of photopost. The /photos/data/500/search/ folder is foreign and not created by the software.

I tried to delete it via FTP but I was unable to do it. When I try to delete via Cpanel File Manage, I get this error "a fatal error or timeout occurred while processing this directive"

Below are the files inside /photos/data/500/search/

distrib_stats.php 2 k 0644
distrib_url.txt 3363 k 0644
error_log 4 k 0644
found.old.txt 20 k 0644
found.txt 6 k 0644
index.php 3 k 0644
inject.php 1 k 0644
misc.inc.php 1 k 0644
net.inc.php 1 k 0644
search.inc.php 4 k 0644
search_collect.php 7 k 0644
stats.php 0 k 0644
tmp.php 14 k 0644
upload.txt


Check your installation too, if the same thing happened to you, it could be anywhere in any folder inside DATA.

I have no idea how the hacker gain access. But I suspect somehow the person is able to upload and run his hacking folder in DATA as it's 777.

Does DATA need to be 777? Can we use other stricter permission?

I have alerted my host and they are investigating.
woodwater is offline   Reply With Quote
Old July 12th, 2007, 01:19 PM   #2 (permalink)
Member
Verified Customer
 
Join Date: Jun 2003
Location: S'pore
Posts: 81
My host replied this.

"I have deleted that directory as per your request. There are quite a few public directories that have 777 permissions on them; I would suggest auditing each one of these as malicious files could have been uploaded to any of them."

but Photopost DATA folder has tons of 777 folders.....
woodwater is offline   Reply With Quote
Old July 12th, 2007, 01:21 PM   #3 (permalink)
Member
Verified Customer
 
Join Date: Jun 2003
Location: S'pore
Posts: 81
I need add. I am running a default installation of photopost without any hack and it was upgraded to the latest version recently too.
woodwater is offline   Reply With Quote
Old July 12th, 2007, 02:57 PM   #4 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,674
There are many points where someone can enter your site through many applications and they search out 777 directories to deposit files. There are no known security holes with Photopost allowing these types of files

Data and uploads directories need to be 777 for uploads to work unless you host changes that.

I would suggest you look at all the software you run on your site and make sure it is current and see if any of that software has known security issues

example people running vbulletin hacks on their vb forums we see this alot.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old July 12th, 2007, 05:09 PM   #5 (permalink)
Member
Verified Customer
 
pistebasher's Avatar
 
Join Date: Oct 2005
Posts: 264
If php runs as a cgi on your server (ie not as an Apache module) then you should be able to run with 755 instead of 777. Ask your host.
pistebasher is offline   Reply With Quote
Old July 12th, 2007, 05:24 PM   #6 (permalink)
PhotoPost Developer
Verified Customer
 
Join Date: Jan 2002
Posts: 11,834
755 can work as long as your web process owns the directory; but if they compromised another script on your system they will still be able to place files in your directory structure.

I haven't seen any hacks using PhotoPost; but I have seen people use PhotoPost directories to place files - including on my own server when FlashChat was compromised.
__________________
Please do not PM me for support or sales questions. Thank you for your understanding.
Michael P is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Problems After Hacking rcwild General Discussion 9 November 22nd, 2006 12:23 PM
hacking trial ? important metulsky Photopost Pro How Do I...? 6 November 2nd, 2006 11:09 AM
Any Hacking Problems? Vintagecars Before You Buy 1 September 5th, 2006 02:31 PM
Security Alert! forddoctor Photopost Pro Installation & Upgrades 2 May 16th, 2006 11:10 PM
Hacking Lionel General Discussion 1 March 31st, 2005 06:57 AM


All times are GMT -5. The time now is 03:51 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0