Joomla! Discussion Forums



It is currently Thu Nov 26, 2009 3:36 am (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 117 posts ]  Go to page Previous  1, 2, 3, 4  Next
Author Message
Posted: Sun Nov 20, 2005 9:08 pm 
User avatar
Joomla! Hero
Joomla! Hero
Offline

Joined: Thu Aug 25, 2005 5:48 pm
Posts: 2801
Location: Geneva mostly
I'm less concerned about the discussion, than about getting this patched asap on various sites, running both J! and Mambo.. ;)

_________________
Sometimes one pays most for the things one gets for nothing.
The important thing is not to stop questioning. Curiosity has its own reason for existing. AE
http://joomla15.blogspot.com for J! 1.5 screenshots
http://www.eyezberg.com


Top
  E-mail  
 
Posted: Sun Nov 20, 2005 9:14 pm 
User avatar
Joomla! Exemplar
Joomla! Exemplar
Offline

Joined: Thu Aug 18, 2005 9:07 am
Posts: 9305
Location: Assen, Netherlands
Me too... I would like to see an official fix for this as soon as possible...
I have a lot of websites I'm very concerned about right now! :-\

But I believe they will fix it soon though :D

_________________
Arjan Menger
http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting
http://www.joomlaideal.nl - iDEAL betaalmethode voor Joomla! en Virtuemart


Top
  E-mail  
 
Posted: Sun Nov 20, 2005 9:25 pm 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Sat Sep 10, 2005 10:31 pm
Posts: 823
sc00zy wrote:
But I believe they will fix it soon though :D


Looks like Stingrey is preparing to release Joomla! 1.0.4 on [21-Nov-2005 10:00 UTC]

_________________
We may not be able to control the wind, but we can always adjust our sails


Top
   
 
Posted: Sun Nov 20, 2005 9:25 pm 
User avatar
Joomla! Champion
Joomla! Champion
Offline

Joined: Fri Aug 12, 2005 12:47 am
Posts: 6431
A fix has been created and we are releasing a 1.0.4 securtiy release in the next couple off hours.

_________________
Johan Janssens - Joomla Co-Founder, Lead Developer of Joomla 1.5

http://www.nooku.org - multi-lingual content manager and rapid extension development framework for Joomla 1.5
http://www.joomlatools.eu - training, consulting and extension development


Top
   
 
Posted: Sun Nov 20, 2005 9:26 pm 
User avatar
Joomla! Exemplar
Joomla! Exemplar
Offline

Joined: Thu Aug 18, 2005 9:07 am
Posts: 9305
Location: Assen, Netherlands
Great! Thanks guys :D

_________________
Arjan Menger
http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting
http://www.joomlaideal.nl - iDEAL betaalmethode voor Joomla! en Virtuemart


Top
  E-mail  
 
Posted: Sun Nov 20, 2005 10:43 pm 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Wed Aug 17, 2005 11:07 pm
Posts: 349
we got defaced big time tonight  >:(

patched now.. thanks johan

and thanks all who contributed

_________________
Joomla! Template Shop www.joomlathemes.org

Joomla Template Club
[URL=http://templateclub.mambosolutions.com]templateclub.mambosolutions.com
[/URL]


Top
  E-mail  
 
Posted: Mon Nov 21, 2005 2:19 am 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Sat Oct 08, 2005 3:25 pm
Posts: 361
Location: Australia
um... has Joomla! 1.0.4 been released yet?  :-\

_________________
http://www.persianari.com


Top
   
 
Posted: Mon Nov 21, 2005 2:20 am 
User avatar
Joomla! Exemplar
Joomla! Exemplar
Offline

Joined: Thu Aug 18, 2005 9:07 am
Posts: 9305
Location: Assen, Netherlands
You'll be the first to know if you read the frontpage regularly :laugh:

_________________
Arjan Menger
http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting
http://www.joomlaideal.nl - iDEAL betaalmethode voor Joomla! en Virtuemart


Top
  E-mail  
 
Posted: Mon Nov 21, 2005 3:33 am 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Sat Oct 08, 2005 3:25 pm
Posts: 361
Location: Australia
Jinx wrote:
A fix has been created and we are releasing a 1.0.4 securtiy release in the next couple off hours.

sc00zy wrote:
Great! Thanks guys :D

mambosolutions_JB wrote:
we got defaced big time tonight  >:(
patched now.. thanks johan
and thanks all who contributed


I always check the Joomla! site regularly, but from the above posts I thought that a it had been already released.
But i guess not.
I'll be waiting anxiously for the release.  :-\

_________________
http://www.persianari.com


Top
   
 
Posted: Mon Nov 21, 2005 7:46 am 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Thu Aug 18, 2005 6:40 am
Posts: 1295
Location: Best, Netherlands
An official release is not out yet.
But if you install this globals.php on your Joomla or Mambo 4.5.2.3. site your pretty safe for now. Just make sure you save the file as globals.php and not as globals.php.txt.

_________________
René Kreijveld
http://www.one-company.nl | Joomla! product specialisten


Top
  E-mail  
 
Posted: Mon Nov 21, 2005 8:12 am 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Sat Oct 08, 2005 3:25 pm
Posts: 361
Location: Australia
thanks webguy.
iv put webprotect on my website for now, until an official release comes out.
if it doesnt come out soon, i will use the global.php file you have provided.
thanks again.

_________________
http://www.persianari.com


Top
   
 
Posted: Mon Nov 21, 2005 8:16 am 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Thu Aug 18, 2005 6:40 am
Posts: 1295
Location: Best, Netherlands
persianari wrote:
thanks webguy.
iv put webprotect on my website for now, until an official release comes out.
if it doesnt come out soon, i will use the global.php file you have provided.
thanks again.


Persianari, what is this webprotect thing? I guess I missed that in this thread...

_________________
René Kreijveld
http://www.one-company.nl | Joomla! product specialisten


Top
  E-mail  
 
Posted: Mon Nov 21, 2005 8:23 am 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Sat Oct 08, 2005 3:25 pm
Posts: 361
Location: Australia
no it wasnt mentioned in this thread.
its a setting in cPanel, which stops access to your site.
in order to enter you need a username and password.
i really didnt have any other choice but to do this until a security fix is released.
i dont want to risk getting hacked/defaced.

_________________
http://www.persianari.com


Top
   
 
Posted: Mon Nov 21, 2005 8:24 am 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Sat Oct 08, 2005 3:25 pm
Posts: 361
Location: Australia
you can see what i mean by going to my website.

_________________
http://www.persianari.com


Top
   
 
Posted: Mon Nov 21, 2005 8:26 am 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Thu Aug 18, 2005 6:40 am
Posts: 1295
Location: Best, Netherlands
Okay, I understand. That's .htaccess protection. Thanks for clarifying... :)

_________________
René Kreijveld
http://www.one-company.nl | Joomla! product specialisten


Top
  E-mail  
 
Posted: Mon Nov 21, 2005 8:40 am 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Sat Oct 08, 2005 3:25 pm
Posts: 361
Location: Australia
yeh... thats the one.
im not to good with techy stuff. :-[

i know no one can access my site, but at least i know its not going to get hacked.
do you think what i have done is ok... or am i being too protective here?

does the globals.php file you provided, provide 100% security in regards to the security hole discussed in this thread?

_________________
http://www.persianari.com


Top
   
 
Posted: Mon Nov 21, 2005 8:50 am 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Thu Aug 18, 2005 6:40 am
Posts: 1295
Location: Best, Netherlands
Sorry, I can't garantee this, because I didn't write the patch. However I did install it on a few Joomla! and Mambo 4.5.2.3 sites and tested it. The security hole seems closed.

If you're unsure about the solution, I guess the best tjing to do is keep your site(s) closed and await the official patch.

_________________
René Kreijveld
http://www.one-company.nl | Joomla! product specialisten


Top
  E-mail  
 
Posted: Mon Nov 21, 2005 8:52 am 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Sat Oct 08, 2005 3:25 pm
Posts: 361
Location: Australia
okay.
thanks again.  :)

_________________
http://www.persianari.com


Top
   
 
Posted: Mon Nov 21, 2005 8:59 am 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Sat Sep 10, 2005 10:31 pm
Posts: 823
persianari wrote:
does the globals.php file you provided, provide 100% security in regards to the security hole discussed in this thread?


There won't ever be something like 100% security! However, I think the globals.php you're talking about is quite secure, none of the attacks I know got through. Overwriting of global variables should be blocked out pretty good.

_________________
We may not be able to control the wind, but we can always adjust our sails


Top
   
 
Posted: Mon Nov 21, 2005 12:41 pm 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Sun Nov 20, 2005 2:20 pm
Posts: 1
What is the state here? My servers are under attack...

Just a few thoughts:

1. I am missing a (small) notice on the Joomla! frontpage regarding this security problem and a link to the hot fix provided (Thank you!) here for the people not reading this forum in detail.

2. Maybe I missed it - but is there a mailing list regarding Joomla!-security?

Kind regards

Stephan


Top
  E-mail  
 
Posted: Mon Nov 21, 2005 1:10 pm 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Sat Oct 08, 2005 3:25 pm
Posts: 361
Location: Australia
deep_sheep wrote:
What is the state here? My servers are under attack...

Just a few thoughts:

1. I am missing a (small) notice on the Joomla! frontpage regarding this security problem and a link to the hot fix provided (Thank you!) here for the people not reading this forum in detail.

2. Maybe I missed it - but is there a mailing list regarding Joomla!-security?

Kind regards

Stephan


The only forum section you can subscribe to to get auto notifications is the Announcements section, which doesn't contain any posts or info about this new and very serious security threat.
I believe there should be a mailing list for such security announcements and that the security team should make it clear to everyone if any problems arise.
It should be shown on the home page when such security issues occurs.
There could be many people out there completely unaware that there is a massive security flaw in Joomla! 1.0.3 and that hackers are currently hacking and defacing many Joomla!/Mambo sites.
Such early and appropriate security notices could help many be better prepared for attacks.
I know that it could also create a massive panic attack from many users but its better to be told then not and have your site hacked/defaced without any knowledge that you site is a potential for such attacks.

_________________
http://www.persianari.com


Last edited by Anonymous on Mon Nov 21, 2005 1:17 pm, edited 1 time in total.

Top
   
 
Posted: Mon Nov 21, 2005 2:38 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu Nov 17, 2005 7:34 pm
Posts: 39
I found one problem with the new globals.php (posted here in this forum) that aka forms is not working anymore, mambo and joomla..Have any one a solution for that?

_________________
mie is een hostingprovider


Top
  E-mail  
 
Posted: Mon Nov 21, 2005 2:40 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Fri Aug 19, 2005 12:14 am
Posts: 1163
Location: United Kingdom
I suspect you're going to come up with a lot of issues like this. I've just been going through my own components, and while Jomres seems ok, an import component for a bike shop I wrote had one small problem that, while easily fixed, made me realise that there are likely to be a LOT of components out there that will need tweaking.

_________________
http://www.jomres.net THE online hotel booking and reservation system for Joomla


Top
   
 
Posted: Mon Nov 21, 2005 2:47 pm 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Sat Sep 10, 2005 10:31 pm
Posts: 823
izzi wrote:
I found one problem with the new globals.php (posted here in this forum) that aka forms is not working anymore, mambo and joomla..Have any one a solution for that?


Don't tell that now  :o

Could you please post some more details: setting of RG_EMULATION in globals.php and setting of register_globals in php.ini? I would expect your configuration to be RG_EMULATION=1 and register_globals=0.

_________________
We may not be able to control the wind, but we can always adjust our sails


Top
   
 
Posted: Mon Nov 21, 2005 3:13 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu Nov 17, 2005 7:34 pm
Posts: 39
friesengeist wrote:
izzi wrote:
I found one problem with the new globals.php (posted here in this forum) that aka forms is not working anymore, mambo and joomla..Have any one a solution for that?


Don't tell that now  :o

Could you please post some more details: setting of RG_EMULATION in globals.php and setting of register_globals in php.ini? I would expect your configuration to be RG_EMULATION=1 and register_globals=0.


Yes my configuration is:
RG_EMULATION=1 and register_globals=0
and the register_globals in php.ini = off

_________________
mie is een hostingprovider


Top
  E-mail  
 
Posted: Mon Nov 21, 2005 3:29 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Wed Aug 17, 2005 9:48 pm
Posts: 1279
Location: St Cloud, MN
Official patch has been released.  :)

http://developer.joomla.org/sf/go/proje ... _1_0.1_0_4

--Slixter

_________________
--Search the forums and you will find your answer


Top
  E-mail  
 
Posted: Mon Nov 21, 2005 4:08 pm 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Mon Sep 19, 2005 12:09 pm
Posts: 2
Slixter wrote:
Official patch has been released.  :)


Great, thanks all!
I guess now it's really time to upgrade all my old Mambo installations to Joomla.


Top
   
 
Posted: Mon Nov 21, 2005 4:13 pm 
User avatar
Joomla! Champion
Joomla! Champion
Offline

Joined: Fri Aug 12, 2005 12:47 am
Posts: 6431
Hi guys,

We just released 1.0.4, it contains one critical and 5 smaller security fixes together with about 90 bug fixes. ;) Have fun upgrading :)

_________________
Johan Janssens - Joomla Co-Founder, Lead Developer of Joomla 1.5

http://www.nooku.org - multi-lingual content manager and rapid extension development framework for Joomla 1.5
http://www.joomlatools.eu - training, consulting and extension development


Top
   
 
Posted: Mon Nov 21, 2005 7:04 pm 
Great news. Thanks everyone.


Top
   
 
Posted: Mon Nov 21, 2005 7:22 pm 
User avatar
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Tue Nov 08, 2005 10:12 am
Posts: 12
I don't see why the patch package contains so many files, including image files and template files? I thought the patch package just contained the important files that need to be patched?

Which are the most important files to patch?


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 117 posts ]  Go to page Previous  1, 2, 3, 4  Next

Quick reply

 



Who is online

Users browsing this forum: No registered users and 11 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group