Support Forums | Demo Gallery [1.x] [2.x] | Downloads | News | Site Map ]
Nuked Gallery
  Create a FREE account or Login   As a guest, you don't have access to our FULL navigation system.
 Forum FAQForum FAQ   StatisticsStatistics   SearchSearch   UsergroupsUsergroups   FavoritesFavorites  

Got Hacked...CHMOD 777 Exploit...

 
Post new topic   Reply to topic    NukedGallery.net Forum Index » PHP-Nuke Integration » Other PHPNuke Issues View previous topicPrinter friendly versionView next topic
Author Message
CorpSuit

Beginner
Beginner


Joined: Jan 04, 2006
Posts: 5

PostPosted: Tue Apr 18, 2006 4:06 pm    Post subject: Got Hacked...CHMOD 777 Exploit... Reply with quote

Ok, I know this is a stupid question, but one of my sites had a malcious eggdrop attack originate from it because of a CHMOD 777 folder.

I know the g2data has to have this. I checked to see who owned php on the server and it said [Nobody] so I am assuming I have to CHMOD the g2data folder.

Is there anyway to patch this vulnerability up? I know there are scripts out there that look for read-write-execute folders...which all of the subfolders of g2data are.

Thoughts?

Thanks!
Back to top
Offline View user's profile Send private message
AdBot
   Post subject: Got Hacked...CHMOD 777 Exploit...  

Back to top
srhh

Beginner
Beginner


Joined: Feb 06, 2006
Posts: 7

PostPosted: Tue Apr 18, 2006 4:16 pm    Post subject: Re: Got Hacked...CHMOD 777 Exploit... Reply with quote

I don't know anything about patching vulnerability, but do you have NukeSentinel installed?
It blocks malicious scripts and attacks. It also provides alot of useful info beyond it's protection functions.
Back to top
Offline View user's profile Send private message
CorpSuit

Beginner
Beginner


Joined: Jan 04, 2006
Posts: 5

PostPosted: Tue Apr 18, 2006 5:10 pm    Post subject: Re: Got Hacked...CHMOD 777 Exploit... Reply with quote

srhh wrote: › I don't know anything about patching vulnerability, but do you have NukeSentinel installed?
It blocks malicious scripts and attacks. It also provides alot of useful info beyond it's protection functions.


Sweet! I will look into that, I heard NukeSentinel didn't work with Gallery2, something to do with URL writing permissions or something.
Back to top
Offline View user's profile Send private message
srhh

Beginner
Beginner


Joined: Feb 06, 2006
Posts: 7

PostPosted: Tue Apr 18, 2006 5:43 pm    Post subject: Re: Got Hacked...CHMOD 777 Exploit... Reply with quote

I remember hearing Sentinel can interfere with the initial installation; if it interferes with Gallery in general, I'd certainly be interested to know more since I *just* installed Gallery on my Nuke site. I'm using a version of Nuke that came bundled with NukeSentinel already installed (RavenNuke 7.6) and on their forums some people have managed to install and use Gallery without a prob. I'll ask around and see if they've had issues with Sentinel breaking the Gallery module and let you know.
Back to top
Offline View user's profile Send private message
dari

Site Admin
Site Admin


Joined: Mar 03, 2003
Posts: 6284
Location: Washington Township, NJ, USA

PostPosted: Wed Apr 19, 2006 6:08 am    Post subject: Re: Got Hacked...CHMOD 777 Exploit... Reply with quote

your g2data folder SHOULD NOT be in your public_html directory. read the gallery docs.
_________________
Back to top
Offline View user's profile Send private message Visit poster's website
srhh

Beginner
Beginner


Joined: Feb 06, 2006
Posts: 7

PostPosted: Wed Apr 19, 2006 1:18 pm    Post subject: Re: Got Hacked...CHMOD 777 Exploit... Reply with quote

Whoops. hehehee...Thanks dari. Fixed that. Embarassed
Here's a link on how to move g2data after install:
http://gallery.menalto.com/node/31505?

Anyways, I've asked around and I believe Sentinel was only causing headaches for Gallery 1.x. Version 2.x seems to be working fine for people with Sentinel, myself included.
Back to top
Offline View user's profile Send private message
CorpSuit

Beginner
Beginner


Joined: Jan 04, 2006
Posts: 5

PostPosted: Sun Apr 23, 2006 8:54 pm    Post subject: Re: Got Hacked...CHMOD 777 Exploit... Reply with quote

dari wrote: › your g2data folder SHOULD NOT be in your public_html directory. read the gallery docs.


Err not to be a dolt...but then I am assuming when you install the Gallery2, and follow your instructions the location of the g2data is by default:

public_html/modules/gallery2/g2data

Am I to understand that is wrong??

I can't find anything in the instructions that says to move it. Am I just missing something?!?!
Back to top
Offline View user's profile Send private message
dari

Site Admin
Site Admin


Joined: Mar 03, 2003
Posts: 6284
Location: Washington Township, NJ, USA

PostPosted: Mon Apr 24, 2006 6:43 am    Post subject: Re: Got Hacked...CHMOD 777 Exploit... Reply with quote

they do that because not everyone has the option of placing it outside the gallery 2 directory (some hosts place restrictions). if you read the installer, it recommends that you place it outside the gallery 2 directory, for security.
_________________
Back to top
Offline View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    NukedGallery.net Forum Index » PHP-Nuke Integration » Other PHPNuke Issues View previous topicPrinter friendly versionView next topic

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT - 5 Hours

Powered by phpBB © phpBB Group



Sponsors: Web HostingDedicated ServersDomain NamesDomain Name RegistrationDedicated Web HostingSEO Search Engine OptimisationSEOWeb Design New YorkSEO Web DesignWeb hosting AustraliaCheap Web Design

6th year online! 2003-2009
Legal • Use of this site consitutes agreement to the Acceptable Use Policy
Hosted by Implosion WorksSourceForge.net Logo • Theme by TonicMedia