Home Private Messages Search
CPG Dragonfly™ CMS stopsoftwarepatents.eu petition banner
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ coppermine 1.3 security exploit :: Archived


coppermine 1.3 security exploit :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page Previous  1, 2
Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
purepersian
Heavy poster
Heavy poster

Offline Offline
Joined: May 05, 2004
Posts: 197
Location: london
PostPosted: Mon Sep 06, 2004 11:28 am
Post subject: Re: coppermine 1.3 security exploit

guys, the user that keeps changing usernames, i SUSPENDED his account and hes using the same account, he came on shoutblock and said "aah u think u can suspend my account? haha"
now hes back changing usernames in the comments field

i even blocked his ip and ip range

why does this guy wanna ruin my site? Sad what have i done to him? bloody hell

_________________
Judge not, as you'll be judged first...

Borobiroon.com - Persian Community
Blue Water Media - Professional Webdesign


purepersian's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
latest
Back to top
View user's profile Visit poster's website
alexm
500+ Posts Club
500+ Posts Club

Offline Offline
Joined: Apr 20, 2004
Posts: 574
Location: Lafayette, LA USA
PostPosted: Mon Sep 06, 2004 1:28 pm
Post subject: Re: coppermine 1.3 security exploit

purepersian wrote:
guys, the user that keeps changing usernames, i SUSPENDED his account and hes using the same account, he came on shoutblock and said "aah u think u can suspend my account? haha"
now hes back changing usernames in the comments field
i even blocked his ip and ip range
If you can provide server logs, please PM me and I'll give you an email address to send them to.

Quote::
why does this guy wanna ruin my site? Sad what have i done to him? bloody hell
Some people are just jerks like that.

As far as I can tell, this seems to be isolated to your site only. Without better information, we may never know how this guy's doing it.

alex

_________________
The master will be pleased...

alexm's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Shared Host / Linux / Apache 1.3.23 / Mysql 3.23.58 / PHP 4.3.3 / CPG 8.2b & 8.3CVS
Back to top
View user's profile Visit poster's website Photo Gallery
purepersian
Heavy poster
Heavy poster

Offline Offline
Joined: May 05, 2004
Posts: 197
Location: london
PostPosted: Mon Sep 06, 2004 1:48 pm
Post subject: Re: coppermine 1.3 security exploit

ok thanks a lot

maybe he is abusing some cookies i dont know

he can some how post a comment in coppermine and then change the name, even though i have disabled the EDIT button and also the username field

he can also use a username that i have SUSPENDED and make shouts in the shoutblock and also post comments in the gallery

he can also post multiple comments in the gallery even though iv disabled the function

and iv also banned his ip address and ip range in my htaccess file but he still comes through Sad


maybe a full reinstall of the site would be a good idea? but then again id lose all database information, iv got too many things put on the site to have to do it again, so that would be a last resort

_________________
Judge not, as you'll be judged first...

Borobiroon.com - Persian Community
Blue Water Media - Professional Webdesign


purepersian's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
latest
Back to top
View user's profile Visit poster's website
purepersian
Heavy poster
Heavy poster

Offline Offline
Joined: May 05, 2004
Posts: 197
Location: london
PostPosted: Mon Sep 06, 2004 3:49 pm
Post subject: Re: coppermine 1.3 security exploit

Confused

_________________
Judge not, as you'll be judged first...

Borobiroon.com - Persian Community
Blue Water Media - Professional Webdesign


purepersian's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
latest
Back to top
View user's profile Visit poster's website
DJ Maze
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 5683
Location: http://tinyurl.com/5z8dmv
PostPosted: Mon Sep 06, 2004 4:33 pm
Post subject: Re: coppermine 1.3 security exploit

Mon Sep 06, 2004 3:48 pm VS Mon Sep 06, 2004 5:49 pm

nice way to bump, but there's no way to block UNLESS you block posting from outside servers.
Don't ask me to fix cos we are already working on that and it has issues.

You can try CVS version but that has a ZERO SUPPORT tollerence.


DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora 15 / 2.2.22 / 5.5.20 / 5.3.10 / CVS
Back to top
View user's profile Visit poster's website Yahoo Messenger Photo Gallery
NanoCaiordo
Developer
Developer

Offline Offline
Joined: Jun 29, 2004
Posts: 3878
Location: Melbourne, AU
PostPosted: Mon Sep 06, 2004 10:43 pm
Post subject: Re: coppermine 1.3 security exploit

The link for the fix on the home page needs to be update as well, still point at 1.7

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

Linux 64bit / Apache 2.2 / PHP 5.4 / MySQL 5.5.22 / v9, v10
Linux 32bit / Apache 2.2 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
Windows 64bit / IIS 7.5 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10


NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
mixed
Back to top
View user's profile Visit poster's website Photo Gallery
masterbeta
Translator
Translator

Offline Offline
Joined: May 12, 2004
Posts: 1049
Location: Reading, PA
PostPosted: Tue Sep 14, 2004 3:35 pm
Post subject: Re: coppermine 1.3 security exploit

ok this file is unavailable?

anyone help?

_________________
[]D [] []\/[] []D
Check out my bear site - www.insidebear.com

masterbeta's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
RHL7 2.6.9-67.0.15ELsmp/A1.3.41(Unix)/MySQL4.1.22-standard/PHP5.2.5-ZO/Dragonfly 9.1.2.1
Back to top
View user's profile Visit poster's website
masterbeta
Translator
Translator

Offline Offline
Joined: May 12, 2004
Posts: 1049
Location: Reading, PA
PostPosted: Tue Sep 28, 2004 6:17 pm
Post subject: Re: coppermine 1.3 security exploit

the file on the mainpage of this site is still unavailable...where is the file?

_________________
[]D [] []\/[] []D
Check out my bear site - www.insidebear.com

masterbeta's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
RHL7 2.6.9-67.0.15ELsmp/A1.3.41(Unix)/MySQL4.1.22-standard/PHP5.2.5-ZO/Dragonfly 9.1.2.1
Back to top
View user's profile Visit poster's website
kikilala
Nice poster
Nice poster

Offline Offline
Joined: Aug 25, 2004
Posts: 102

PostPosted: Tue Oct 05, 2004 11:51 pm
Post subject: Re: coppermine 1.3 security exploit

I've update the file that is given in the main page. But I still can edit the my name in the comments. Am I updating the right file?

db_input from the main page >>> replacing >>> db_input in modules/coppermine

Is this right? If this is right, I'm still able to change the nick in the comments section.,

_________________
I don't do nuke. I do CPGnuke.

kikilala's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
linux/1.3.31 (Unix)/4.0.18-standard/4.3.7/CPG 8.2b|CSV 8.3
Back to top
View user's profile Visit poster's website
winglet
Nice poster
Nice poster

Offline Offline
Joined: May 20, 2004
Posts: 99
Location: Vancouver, Canada
PostPosted: Wed Oct 06, 2004 11:01 pm
Post subject: Re: coppermine 1.3 security exploit

Ok, I replaced the db_input.php file with the 1.8 ver and get this error:

Warning: file(): php_network_getaddresses: getaddrinfo failed: Name or service not known in /home/mydomain/www/www/modules/coppermine/include/functions.inc on line 215

Warning: file(http://nukephotogallery.com/ver/version.php?ver=1.3.0c): failed to open stream: No such file or directory in /home/mydomain/www/www/modules/coppermine/include/functions.inc on line 215

Running 8.2b with Coppermine 1.3.0c

??


winglet's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux :: 1.3.33 :: 4.0.24 :: 4.3.11 :: 9.0.4.0 :: Browsers: Mac: Safari 2.0 PC: Firefox 1.0.4, IE6 All Updates
Back to top
View user's profile Visit poster's website
Stephen
Silver Supporter
Silver Supporter

Offline Offline
Joined: Apr 21, 2004
Posts: 734

PostPosted: Thu Oct 07, 2004 12:13 am
Post subject: Re: coppermine 1.3 security exploit

winglet, cpgnuke.com/Forums/vie...html#24822


Stephen's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Cent OS :: 1.3.34 :: 4.1.13 :: 4.4.2 :: CVS
Back to top
View user's profile Visit poster's website Photo Gallery
winglet
Nice poster
Nice poster

Offline Offline
Joined: May 20, 2004
Posts: 99
Location: Vancouver, Canada
PostPosted: Thu Oct 07, 2004 12:43 am
Post subject: Re: coppermine 1.3 security exploit

Arrgh...after looking at line 215 in include.php even my pea-sized brain was able to determine it had something to do with the nukedgallery version update thingy...haven't worked on my site for a while and the error seemed to happen right after I put the new exploit cure file in...thanks Stephen, my bad...


winglet's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux :: 1.3.33 :: 4.0.24 :: 4.3.11 :: 9.0.4.0 :: Browsers: Mac: Safari 2.0 PC: Firefox 1.0.4, IE6 All Updates
Back to top
View user's profile Visit poster's website
Trevor
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 2170
Location: New York
PostPosted: Thu Oct 07, 2004 12:44 am
Post subject: Re: coppermine 1.3 security exploit

The error is only related to nukephotogallery.com being down, it has nothing to do with anything you could have done


Trevor's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux / 1.3.34 / 4.1.18 / 4.4.2 / CVS
Back to top
View user's profile Photo Gallery
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 2 of 2
All times are GMT
Go to page Previous  1, 2

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

read more...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy