1
EastEnd99
Re: XoopsGallery Easly Hacked
  • 2008/1/10 13:45

  • EastEnd99

  • Just popping in

  • Posts: 1

  • Since: 2005/9/4 1


This is a (sanitized) messages log from my webserver:
Jan  6 18:06:47 httpdPHP Warning:  main(): URL file-access is disabled in the server configuration in /..../modules/xoopsgallery/init_basic.php on line 83
Jan  6 18
:06:47 httpdPHP Warning:  main(http://kamekfm.org/test.txt???platform/fs_unix.php): failed to open stream: no suitable wrapper could be found in ../modules/xoopsgallery/init_basic.php on line 83
Jan  6 18:06:47 httpdPHP Fatal error:  main(): Failed opening required 'http://kamekfm.org/test.txt???platform/fs_unix.php' (include_path='.:/usr/share/pear-addons:/usr/share/pear'in ../modules/xoopsgallery/init_basic.php on line 83


Line 83 of init_basic.php shows the $GALLERY_BASEDIR variable is replaced by an external URL at runtime. These external references vary each time. My knowledge of PHP is limited: I cannot figure out which code is responsible for the value of this variable at runtime. I am stuck.

Am I looking at the same hack situation?
If it is: The hack does not seem to have any consequences: I can not find strange files inside the xoopsgallery directory structure. May be turning off URL file-access in the servers PHP configuration disables the hack. Other posiblity may be the hack check in each php file should be extended (it validates empty $GALLERY_BASEDIR variables) to make sure it is pointing to the local XOOPS installation.

If I can be of any help, please let me know.

EE99




TopTop



Login

Who's Online

178 user(s) are online (116 user(s) are browsing Support Forums)


Members: 0


Guests: 178


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Apr 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits