PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Pro Support Forums > Photopost Pro Installation & Upgrades

Photopost Pro Installation & Upgrades If you're having install or upgrade problems

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old August 24th, 2007, 03:39 PM   #1 (permalink)
ldk
Junior Member
Verified Customer
 
Join Date: Jun 2004
Posts: 13
Upgrade & Exploit Prevention Question

It recently sunk in for me how important it is to keep all your scripts up to date in case exploits have been found and fixed! I got hacked and I was running a very old version of PhotoPost (4.8) which might have been what was exploited. I've totally hidden my PhotoPost installation for now and I'm going to upgrade very soon.

My question is this... Upgrading from 4.8 to 5.62...

Is there a chance that a vulnerable php file from 4.8 no longer exists in the 5.6.2 file set and therefore it wouldn't get overwritten or deleted and it would continue to be there and be a risk?

For example, one of the problematic files I've read about is zipndownload.php. If 5.62 doesn't include this file anymore, would the old vulnerable one just remain there?

Or is all this taken into account with the upgrade script?

Obviously I could just delete that one file but there might be others I don't know about...

Thanks for your help!
ldk is offline   Reply With Quote
Old August 24th, 2007, 05:22 PM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,699
You can delete old files sure but no old files are used with our script do I doubt they would work.

If you want to be sure delete all php files except the config files and then upload new files
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Upgrade v2.9 to v3.11 - & is now being shown as &amp criscokid ReviewPost Installation & Upgrades 25 June 18th, 2006 09:20 PM
Is this exploit or etc ? Lizard King Bugs From 1.0.0 13 June 13th, 2005 03:03 PM
5.02 - Upgrade Error Question/Deleted Files Question WB Photopost Pro Installation & Upgrades 5 March 16th, 2005 03:00 PM


All times are GMT -5. The time now is 08:12 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0