I have a site I recently set up. Today the web host contacted me to say they have disabled scripting on the site due to a permanent process running on the site. They say this may be due to the site being hacked. The logs show:-
12903 gloucesterphotos.co.uk (449 s) [03/Jan/2017:16:42:32 +0000]
"convert" (/bin/bash) /bin/sh /usr/bin/convert /home/sites/gloucesterphotos.co.uk/public_html/upload/2017/01/03/20170103105939-b5029e17.jpg -filter Lanczos -resize 1008x671! -compose dissolve -define compose:args=100 /home/sites/gloucesterphotos.co.uk/public_html/themes/default/watermarks/copyright.png -gravity NorthWest -geometry +417+311 -composite -quality 95 -interlace line -sampling-factor 4:2:2 /home/sites/gloucesterphotos.co.uk/public_html/_data/i/upload/2017/01/03/20170103105939-b5029e17-la.jpg
convert 12903 gloucesterphotos.co.uk 0r FIFO 0,8 0t0 1165876393 pipe
convert 12903 gloucesterphotos.co.uk 1w FIFO 0,8 0t0 1165876474 pipe
convert 12903 gloucesterphotos.co.uk 2w FIFO 0,8 0t0 1165876474 pipe
convert 12903 gloucesterphotos.co.uk 255r REG 8,5 669 17063 /usr/bin/im-wrapper
Can anyone shed any light on this?
Piwigo version: Not sure was updated to latest version yesterday
PHP version: 5.2
Piwigo URL: http://gloucesterphotos.co.uk
as you can read it's just the processing of uploaded pictures
That's something you will learn in the plugin Take A Tour
Thanks @Flop25. This confuses me as the host say it was running as a continuous process. How can that be as the site only has a few images on it. Is it possible that the process crashed/hung?
check the creation fo those pictrues in _data/i and if the thumbnails displayed are from i.php or _data/i
Or that might be due to the fact that you have very few visitors and so the pictures never got generated until recently someone discovered your gallery
your gallery is locked so I cna't tell
Ps: web hosters for shared hosting won't check themself what's wrong. Their scripts check for errors or anything detrimental for their business, then usually block a part or the whole website.
Just to add that the host has now confirmed that there are no vulnerabilities and that this must have been due to the image process script crashing and remaining open. AFAIK this must be a very rare event as I am now using Piwigo on a number of sites an nothing like this has occurred before.