(I'm not here right now, please email a message) ([info]reddragdiva) wrote,
@ 2008-04-13 21:20:00
Previous Entry  Add to memories!  Tell a Friend!  Next Entry
Would I lie to you?

I'm at home with sinuses blocked to pain while [info]arkady, Freda and [info]redcountess go down the pub for [info]mirrorshard's birthday. Bah! I think I've run out of intarwebs.

reddragdiva.co.uk and arkady.org.uk got hit by the SQL injection vulnerability in Coppermine. I cleared the toxic waste iframes out of every single PHP and HTML file (and the database login of "cialis") and deleted 97,000 spam comments by hand in MySQL (commenting to be re-enabled only with working captchas) and have resubmitted the site to StopBadware. The Firefox 3 badware warning page is fabulously obnoxious. If you're running Coppermine, UPGRADE NOW.

(To check if your Coppermine gallery's fallen victim: view source, and if there's an iframe at the beginning with a ton of cryptic encoded crap, then your site may infect any IE user happening to look at it. You can check for sure by looking at the source PHP files and seeing if they have iframe code for cryptic encoded crap at the end. If they do, (1) remove the iframes from all PHP and HTML files in your Coppermine installation — and it will be all of them — (2) install either the patch linked above or all of 1.4.17 right away.)

We now have stair gates on the kitchen and hall doors (fitted courtesy Arkady's overpowering manliness), so the lounge is a big playpen for Freda. She bangs her spoon on the bars.

Update: 1.4.17 had a hole as well - get 1.4.18 right away.



(Post a new comment)


[info]baljemmett
2008-04-13 09:44 pm UTC (link)
Luckily nobody actually cares about my gallery, so I disabled comments outright when I got fed up of deleting the spam. I hear newer versions of Gallery 2 implement CAPTCHA that is actually worth a damn; I probably ought to upgrade at some point. Or just go back to my homebrew CGI which I recently dug up off a DAT cartridge...

(Reply to this)(Thread)


[info]reddragdiva
2008-04-13 10:15 pm UTC (link)
Captcha will be in Coppermine 1.5 by default ... whenever that's released.

(Reply to this)(Parent)


[info]secretlondon
2008-04-13 10:35 pm UTC (link)
http://pics.livejournal.com/secretlondon/pic/0001ck8q/

(Reply to this)(Thread)


[info]reddragdiva
2008-04-13 10:39 pm UTC (link)
That's the one! I assume they'll look at the queue in a day or so.

(Reply to this)(Parent)


[info]sister_stella
2008-04-14 02:41 pm UTC (link)
I think I've run out of intarwebs.
Yeah, me too. How did that happen?
*confused*

(Reply to this)


Create an Account
Forgot your login?
Login w/ OpenID
English • Español • Deutsch • Русский…