Author Topic: Security Proplem in 4images 1.7.1  (Read 16835 times)

0 Members and 1 Guest are viewing this topic.

Offline naif824

  • Newbie
  • *
  • Posts: 27
    • View Profile
Security Proplem in 4images 1.7.1
« on: March 23, 2005, 05:45:07 AM »
Mornings Ppl

I'm using 1.7.1

after I logged in with a regular registered user , assume the user : aa

then after I browse the gallery

if I stopped by an Image

and copy the URL in the address bar

then sent it to any body like this :

http://www.kashtah.com/4images/details.php?image_id=623&sessionid=NMPJf2wUjHBvw

he will be able to get him self into my account !!

How could I modify this to restrict that?

I mean to ask for a user & password if there was no cockie ??



best regards

Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: Security Proplem in 4images 1.7.1
« Reply #1 on: March 23, 2005, 07:11:57 AM »
the reason sessionid printed in the url is because no cookies were set previosly...
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)

Offline naif824

  • Newbie
  • *
  • Posts: 27
    • View Profile
Re: Security Proplem in 4images 1.7.1
« Reply #2 on: March 23, 2005, 10:38:12 AM »
How could I enable cockies?

Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: Security Proplem in 4images 1.7.1
« Reply #3 on: March 23, 2005, 11:55:20 PM »
cookes are part of web client (browser). If browser or some other software are blocking cookies, there is not much u can do about it from server side...
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)

Offline naif824

  • Newbie
  • *
  • Posts: 27
    • View Profile
Re: Security Proplem in 4images 1.7.1
« Reply #4 on: March 24, 2005, 12:48:48 AM »
Well the cockies are enabled on my browser , and I got that link , How could that be understood?

Offline naif824

  • Newbie
  • *
  • Posts: 27
    • View Profile
Re: Security Proplem in 4images 1.7.1
« Reply #5 on: March 24, 2005, 12:49:29 AM »
BTW , Have a look @ my Gallery , http://www.kashtah.com/4images


regards

Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: Security Proplem in 4images 1.7.1
« Reply #6 on: March 24, 2005, 01:13:29 AM »
that is problem with your server configuration and cache feature in v1.7.1

Unfortunetly the topic with a fix was lost after the hack...and I dont remmeber what exactly was causing it and how to fix it...
for now, try to disable cache feature.
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)

Offline naif824

  • Newbie
  • *
  • Posts: 27
    • View Profile
Re: Security Proplem in 4images 1.7.1
« Reply #7 on: March 24, 2005, 10:50:39 AM »
i dunno how to disable it :(

Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: Security Proplem in 4images 1.7.1
« Reply #8 on: March 24, 2005, 02:28:41 PM »
read documentation that came with v1.7.1 ;)
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)

Offline naif824

  • Newbie
  • *
  • Posts: 27
    • View Profile
Re: Security Proplem in 4images 1.7.1
« Reply #9 on: March 24, 2005, 03:29:00 PM »
here we are the doc :

  -- Advanced control of the caching system ----------------

  You can control the caching system in your config.php with
  the following configuration variables:

  - $cache_enable = 1;
      A value of 1 enables the caching system, 0 disables it.
      Default value is 0.

while see my config.php :

Code: [Select]
<?php
/**************************************************************************
 *                                                                        *
 *    4images - A Web Based Image Gallery Management System               *
 *    ----------------------------------------------------------------    *
 *                                                                        *
 *             File: config.php                                           *
 *        Copyright: (C) 2002 Jan Sorgalla                                *
 *            Email: jan@4homepages.de                                    *
 *              Web: http://www.4homepages.de                             *
 *    Scriptversion: 1.7.1                                                *
 *                                                                        *
 *    Never released without support from: Nicky (http://www.nicky.net)   *
 *                                                                        *
 **************************************************************************
 *                                                                        *
 *    Dieses Script ist KEINE Freeware. Bitte lesen Sie die Lizenz-       *
 *    bedingungen (Lizenz.txt) fr weitere Informationen.                 *
 *    ---------------------------------------------------------------     *
 *    This script is NOT freeware! Please read the Copyright Notice       *
 *    (Licence.txt) for further information.                              *
 *                                                                        *
 *************************************************************************/

$db_servertype "mysql";
$db_host "localhost";
$db_name "XXXXXXXXXXXXXXXX";
$db_user "XXXXXXXXXXXXXX";
$db_password "XXXXXXXXXX";

$table_prefix "4images_";

define("4IMAGES_ACTIVE"1);

?>



sHALL i ADD IT LIKE THIS :


Code: [Select]
<?php
/**************************************************************************
 *                                                                        *
 *    4images - A Web Based Image Gallery Management System               *
 *    ----------------------------------------------------------------    *
 *                                                                        *
 *             File: config.php                                           *
 *        Copyright: (C) 2002 Jan Sorgalla                                *
 *            Email: jan@4homepages.de                                    *
 *              Web: http://www.4homepages.de                             *
 *    Scriptversion: 1.7.1                                                *
 *                                                                        *
 *    Never released without support from: Nicky (http://www.nicky.net)   *
 *                                                                        *
 **************************************************************************
 *                                                                        *
 *    Dieses Script ist KEINE Freeware. Bitte lesen Sie die Lizenz-       *
 *    bedingungen (Lizenz.txt) fr weitere Informationen.                 *
 *    ---------------------------------------------------------------     *
 *    This script is NOT freeware! Please read the Copyright Notice       *
 *    (Licence.txt) for further information.                              *
 *                                                                        *
 *************************************************************************/

$db_servertype "mysql";
$db_host "localhost";
$db_name "XXXXXXXXXXXXXXXX";
$db_user "XXXXXXXXXXXXXX";
$db_password "XXXXXXXXXX";

$table_prefix "4images_";

$cache_enable 0;

define("4IMAGES_ACTIVE"1);

?>


Offline Jan

  • Administrator
  • 4images Guru
  • *****
  • Posts: 5.024
    • View Profile
    • 4images - Image Gallery Management System
Re: Security Proplem in 4images 1.7.1
« Reply #10 on: March 24, 2005, 03:37:50 PM »
You should also read through this: http://php.net/session
This issue is a known one and is possible for all sessions based on session ids. You can try to set the configuration options in config.php by the ini_set() function, eg
Code: [Select]
ini_set('session.use_only_cookies', 1);
Your first three "must do" before you ask a question:
1. Forum rules
2. FAQ
3. Search

Offline naif824

  • Newbie
  • *
  • Posts: 27
    • View Profile
Re: Security Proplem in 4images 1.7.1
« Reply #11 on: March 25, 2005, 12:00:15 AM »
thx

Great support

adding :

ini_set('session.use_only_cookies', 1);


to config file solved the problem


best regards

Offline artistichideaway

  • Newbie
  • *
  • Posts: 15
    • View Profile
Re: Security Proplem in 4images 1.7.1
« Reply #12 on: August 16, 2006, 12:22:36 PM »
Hello,

I have 4images 1.7.1. gallery installed for some time. Everyting runs fine, only problem is, "log me on automatically on next visit" doesn't work for anyone. Deleting temporary interent files and cookies doesn't help.
I even heard from 2 users they can't log on no matter what.

I tried to find some useful advice in previous topics but nothing worked.

I attach PHP session info as I think the problem might be there. Can anyone please have a look and let me know if the settings need to be changed in some way.
Thank you.

otherwise the gallery is at:

www.michaeljacksonart.com
login: test
pass: test


Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: Security Proplem in 4images 1.7.1
« Reply #13 on: August 16, 2006, 03:04:11 PM »
In your case, there are no cookies being set AT ALL when you login with "remmember me" checkbox ticked...
Try use default, not modifyed sessions.php and see if it works...
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)

Offline artistichideaway

  • Newbie
  • *
  • Posts: 15
    • View Profile
Re: Security Proplem in 4images 1.7.1
« Reply #14 on: August 16, 2006, 06:07:11 PM »
Thank you for your advice.... :D
I tried but no change  :cry:......I think I had this problem from the very beginning I installed 4images, even without any mods installed.
Do you think, it could help to upgrade to 4images version 1.7.3 ?



« Last Edit: August 16, 2006, 07:27:18 PM by artistichideaway »