PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Pro Support Forums > Photopost Pro How Do I...?

Photopost Pro How Do I...? Wondering how to do things in PhotoPost?

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old September 4th, 2007, 02:30 PM   #1 (permalink)
Member
Verified Customer
 
Join Date: Jun 2004
Location: Southern UK
Posts: 51
Problem with index.php

One of my users Emailed me to say that the site was activating his Antivirus shield, so I ran the site though Black Widow and found that every time the index page was called, it brought up this URL

_http://58.35.235.153/~pozitive/pics/index.php?264730676b8385

So I looked at the page source and found this at the bottom:


Code:
Content visible to verified customers only.
Not sure how it got there, or how long it has been there although my member said it started on sunday, but I am just changing my server login, can I simply over write the index php with a new version?

I'm running 5.62, are there any known backdoors or exploits?

PS. have now managed to edit out the script after disabling my antivirus, butI'm concerned that it may return.

Last edited by rolfw; September 4th, 2007 at 02:45 PM.
rolfw is offline   Reply With Quote
Old September 4th, 2007, 05:36 PM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 68,069
Yes you can overwrite all files to get rid of that provided the code is coming from our end and there is no exploits we are aware of at this time.

I would be very interested here to hear from you exactly where you edited and then we might be able to respond a bit more here on some ideas. As it stands now without a link and some more info I can not say much here on this.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old September 4th, 2007, 05:46 PM   #3 (permalink)
Member
Verified Customer
 
Join Date: Jun 2004
Location: Southern UK
Posts: 51
I simply removed the code above from the very bottom of this page Chuck, my forum homepage is linked to in my profile.
rolfw is offline   Reply With Quote
Old September 4th, 2007, 05:54 PM   #4 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 68,069
Okay cool but that I was asking is what file was the code in? Was this in your footer the index.php itself or a tempate?
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old September 4th, 2007, 06:01 PM   #5 (permalink)
Member
Verified Customer
 
Join Date: Jun 2004
Location: Southern UK
Posts: 51
Sorry, thought I'd put that, but hadn't, it was in index.PHP, have checked a few of the other php pages and it doesn't seem to be in any of them.
rolfw is offline   Reply With Quote
Old September 4th, 2007, 06:07 PM   #6 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 68,069
Interesting I would suggest you check your server for files that look strange or do not belong and remove them. Usually from what I see you need to actually ftp to the server or ssh in and edit the file to add that so this may be an indicatiuon of a security issue elsewhere on the server with a foreign file that is letting people get in your server and change things
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old September 4th, 2007, 06:13 PM   #7 (permalink)
Member
Verified Customer
 
Join Date: Jun 2004
Location: Southern UK
Posts: 51
Thanks Chuck, yes had worked out that it couldn't be altered from the Admin CP in Photopost, have now changed the Control panel login and FTP login as a precaution. Any idea what extension a file would have which would enable this?
rolfw is offline   Reply With Quote
Old September 4th, 2007, 06:21 PM   #8 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 68,069
No honestly I would not. filenames can vary so you would need to browse and look at any directories on your server that are 777 and see if there are any files that should not be there. Kind of a tedious process but keeping to directories that people might be able to access via holes in applications you may have on your server that have security issues will narrow things down. Like Michael P one of the developers here had an issue on his site one time and turned out to be flash chat he had installed with his vbulletin forum.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old September 4th, 2007, 06:28 PM   #9 (permalink)
Member
Verified Customer
 
Join Date: Jun 2004
Location: Southern UK
Posts: 51
OK thanks, may well get the server manager to have a look for me, he would have a better idea of what should and shouldn't be there, plus I only have access to my cpanel, whereas there are multiple sites on the server.

In the meanwhile, I'll check it every day with BlackWidow.

Thanks for your help.

PS. As a matter of interest, what does the file photopost_anywhere.php do?
rolfw is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
index.html redirect to index.php JoeWho Photopost Pro How Do I...? 2 February 20th, 2007 12:40 PM
problem with index not loading without '?' after .php phoenix Photopost Pro Bug Reports 5 January 5th, 2007 10:16 AM
Problem with a PHP include breaking Photopost Index Chris Marks Photopost Pro Installation & Upgrades 6 January 27th, 2006 07:47 PM
After install, no user text on index.php or adm-index.php silknet01 Classifieds Installation & Upgrades 6 April 14th, 2005 01:43 PM
Install successful yet problem with adm-index.php?? omeganostral Photopost Pro Installation & Upgrades 4 October 6th, 2004 02:12 PM


All times are GMT -5. The time now is 08:45 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0