| Topic Archived |
View previous topic :: View next topic |
| Author |
Message |
purepersian Heavy poster


Offline Joined: May 05, 2004 Posts: 197 Location: london
|
Posted: Mon Sep 06, 2004 11:28 am Post subject: Re: coppermine 1.3 security exploit |
|
guys, the user that keeps changing usernames, i SUSPENDED his account and hes using the same account, he came on shoutblock and said "aah u think u can suspend my account? haha"
now hes back changing usernames in the comments field
i even blocked his ip and ip range
why does this guy wanna ruin my site?  what have i done to him? bloody hell
_________________ Judge not, as you'll be judged first...
Borobiroon.com - Persian Community
Blue Water Media - Professional Webdesign
purepersian's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) latest
|
|
| Back to top |
|
 |
alexm 500+ Posts Club


Offline Joined: Apr 20, 2004 Posts: 574 Location: Lafayette, LA USA
|
Posted: Mon Sep 06, 2004 1:28 pm Post subject: Re: coppermine 1.3 security exploit |
|
| purepersian wrote: |
guys, the user that keeps changing usernames, i SUSPENDED his account and hes using the same account, he came on shoutblock and said "aah u think u can suspend my account? haha"
now hes back changing usernames in the comments field
i even blocked his ip and ip range |
If you can provide server logs, please PM me and I'll give you an email address to send them to.
| Quote:: |
why does this guy wanna ruin my site? what have i done to him? bloody hell |
Some people are just jerks like that.
As far as I can tell, this seems to be isolated to your site only. Without better information, we may never know how this guy's doing it.
alex
_________________ The master will be pleased...
alexm's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Shared Host / Linux / Apache 1.3.23 / Mysql 3.23.58 / PHP 4.3.3 / CPG 8.2b & 8.3CVS
|
|
| Back to top |
|
 |
purepersian Heavy poster


Offline Joined: May 05, 2004 Posts: 197 Location: london
|
Posted: Mon Sep 06, 2004 1:48 pm Post subject: Re: coppermine 1.3 security exploit |
|
ok thanks a lot
maybe he is abusing some cookies i dont know
he can some how post a comment in coppermine and then change the name, even though i have disabled the EDIT button and also the username field
he can also use a username that i have SUSPENDED and make shouts in the shoutblock and also post comments in the gallery
he can also post multiple comments in the gallery even though iv disabled the function
and iv also banned his ip address and ip range in my htaccess file but he still comes through
maybe a full reinstall of the site would be a good idea? but then again id lose all database information, iv got too many things put on the site to have to do it again, so that would be a last resort
_________________ Judge not, as you'll be judged first...
Borobiroon.com - Persian Community
Blue Water Media - Professional Webdesign
purepersian's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) latest
|
|
| Back to top |
|
 |
purepersian Heavy poster


Offline Joined: May 05, 2004 Posts: 197 Location: london
|
Posted: Mon Sep 06, 2004 3:49 pm Post subject: Re: coppermine 1.3 security exploit |
|
_________________ Judge not, as you'll be judged first...
Borobiroon.com - Persian Community
Blue Water Media - Professional Webdesign
purepersian's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) latest
|
|
| Back to top |
|
 |
DJ Maze Developer


Offline Joined: Apr 19, 2004 Posts: 5683 Location: http://tinyurl.com/5z8dmv
|
Posted: Mon Sep 06, 2004 4:33 pm Post subject: Re: coppermine 1.3 security exploit |
|
Mon Sep 06, 2004 3:48 pm VS Mon Sep 06, 2004 5:49 pm
nice way to bump, but there's no way to block UNLESS you block posting from outside servers.
Don't ask me to fix cos we are already working on that and it has issues.
You can try CVS version but that has a ZERO SUPPORT tollerence.
DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Fedora 15 / 2.2.22 / 5.5.20 / 5.3.10 / CVS
|
|
| Back to top |
|
 |
NanoCaiordo Developer


Offline Joined: Jun 29, 2004 Posts: 3878 Location: Melbourne, AU
|
Posted: Mon Sep 06, 2004 10:43 pm Post subject: Re: coppermine 1.3 security exploit |
|
The link for the fix on the home page needs to be update as well, still point at 1.7
_________________ .:: I met php the 03 December 2003 :: Unforgettable day! ::.
Linux 64bit / Apache 2.2 / PHP 5.4 / MySQL 5.5.22 / v9, v10
Linux 32bit / Apache 2.2 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
Windows 64bit / IIS 7.5 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) mixed
|
|
| Back to top |
|
 |
masterbeta Translator


Offline Joined: May 12, 2004 Posts: 1049 Location: Reading, PA
|
Posted: Tue Sep 14, 2004 3:35 pm Post subject: Re: coppermine 1.3 security exploit |
|
ok this file is unavailable?
anyone help?
_________________ []D [] []\/[] []D
Check out my bear site - www.insidebear.com
masterbeta's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) RHL7 2.6.9-67.0.15ELsmp/A1.3.41(Unix)/MySQL4.1.22-standard/PHP5.2.5-ZO/Dragonfly 9.1.2.1
|
|
| Back to top |
|
 |
masterbeta Translator


Offline Joined: May 12, 2004 Posts: 1049 Location: Reading, PA
|
Posted: Tue Sep 28, 2004 6:17 pm Post subject: Re: coppermine 1.3 security exploit |
|
the file on the mainpage of this site is still unavailable...where is the file?
_________________ []D [] []\/[] []D
Check out my bear site - www.insidebear.com
masterbeta's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) RHL7 2.6.9-67.0.15ELsmp/A1.3.41(Unix)/MySQL4.1.22-standard/PHP5.2.5-ZO/Dragonfly 9.1.2.1
|
|
| Back to top |
|
 |
kikilala Nice poster


Offline Joined: Aug 25, 2004 Posts: 102
|
Posted: Tue Oct 05, 2004 11:51 pm Post subject: Re: coppermine 1.3 security exploit |
|
I've update the file that is given in the main page. But I still can edit the my name in the comments. Am I updating the right file?
db_input from the main page >>> replacing >>> db_input in modules/coppermine
Is this right? If this is right, I'm still able to change the nick in the comments section.,
_________________ I don't do nuke. I do CPGnuke.
kikilala's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) linux/1.3.31 (Unix)/4.0.18-standard/4.3.7/CPG 8.2b|CSV 8.3
|
|
| Back to top |
|
 |
winglet Nice poster


Offline Joined: May 20, 2004 Posts: 99 Location: Vancouver, Canada
|
Posted: Wed Oct 06, 2004 11:01 pm Post subject: Re: coppermine 1.3 security exploit |
|
Ok, I replaced the db_input.php file with the 1.8 ver and get this error:
Warning: file(): php_network_getaddresses: getaddrinfo failed: Name or service not known in /home/mydomain/www/www/modules/coppermine/include/functions.inc on line 215
Warning: file(http://nukephotogallery.com/ver/version.php?ver=1.3.0c): failed to open stream: No such file or directory in /home/mydomain/www/www/modules/coppermine/include/functions.inc on line 215
Running 8.2b with Coppermine 1.3.0c
??
winglet's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux :: 1.3.33 :: 4.0.24 :: 4.3.11 :: 9.0.4.0 :: Browsers: Mac: Safari 2.0 PC: Firefox 1.0.4, IE6 All Updates
|
|
| Back to top |
|
 |
Stephen Silver Supporter


Offline Joined: Apr 21, 2004 Posts: 734
|
Posted: Thu Oct 07, 2004 12:13 am Post subject: Re: coppermine 1.3 security exploit |
|
Stephen's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Cent OS :: 1.3.34 :: 4.1.13 :: 4.4.2 :: CVS
|
|
| Back to top |
|
 |
winglet Nice poster


Offline Joined: May 20, 2004 Posts: 99 Location: Vancouver, Canada
|
Posted: Thu Oct 07, 2004 12:43 am Post subject: Re: coppermine 1.3 security exploit |
|
Arrgh...after looking at line 215 in include.php even my pea-sized brain was able to determine it had something to do with the nukedgallery version update thingy...haven't worked on my site for a while and the error seemed to happen right after I put the new exploit cure file in...thanks Stephen, my bad...
winglet's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux :: 1.3.33 :: 4.0.24 :: 4.3.11 :: 9.0.4.0 :: Browsers: Mac: Safari 2.0 PC: Firefox 1.0.4, IE6 All Updates
|
|
| Back to top |
|
 |
Trevor Developer


Offline Joined: Apr 19, 2004 Posts: 2170 Location: New York
|
Posted: Thu Oct 07, 2004 12:44 am Post subject: Re: coppermine 1.3 security exploit |
|
The error is only related to nukephotogallery.com being down, it has nothing to do with anything you could have done
Trevor's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux / 1.3.34 / 4.1.18 / 4.4.2 / CVS
|
|
| Back to top |
|
 |
|
|