Joomla! Discussion Forums



It is currently Wed Nov 25, 2009 10:22 am (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 2 posts ] 
Author Message
Posted: Sat Dec 29, 2007 5:36 am 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Sat Dec 29, 2007 5:28 am
Posts: 1
Hi All,

I have received this email from my hosting. They have turned off my site for the following reason.



Regarding your shared hosting XXXXXXXRemoved.com.

It has come to our attention that you are running "Joomla! Mambot" where multiple .PHP scripts throughout your content are vulnerable because data used in the "( $mosConfig_absolute_path" parameter is not properly verified before being used to include files. This vulnerability has allowed multiple attack IPs the ability to upload malicious content as far back as August 22, 2007. We recommend that you immediately update software (1.5 RC4) and manually review all code to ensure that input is properly sanitized. We've had the current attack IPs blocked at localhost, vulnerable scripts disabled, and had the malicious content removed.

Please contact us if you have any further issues.

Michael H.
Hosting Support
Hosting Operations



Are they right to be forcing me onto a Release candidate rather than a stable version? I have googled and cannot find any info on the vulnerability they mention. I have been around in circles for days with there only reply is to upgrade to RC4. Any help greatly accepted.

This is my settings.

Joomla! Version:  Joomla! 1.0.13 Stable [ Sunglow ] 21 July 2007 16:00 UTC


Relevant PHP Settings:
Joomla! Register Globals Emulation: OFF
Register Globals: ON
Magic Quotes: ON
Safe Mode: OFF
File Uploads: ON
Session auto start: OFF


Top
  E-mail  
 
Posted: Sat Dec 29, 2007 10:18 am 
User avatar
Joomla! Champion
Joomla! Champion
Offline

Joined: Sun Oct 22, 2006 4:42 am
Posts: 5286
Location: Queensland, Australia
I beleive the important part here is that PHP register_globals is on, if i were you, I would mail back the host and suggest that if they are concerned about the vulnerability of your site exposing their server, that they turn OFF PHP register_globals before suggesting that you must upgrade to 1.5 from 1.0. although this problem is eleviated in 1.5 and lax server security through PHP register_globals is no longer an issue.

Beware though, turning off PHP register_globlas may break certain components of your site if they rely on that settign being on, which is probably what the host is actually complaining about, the use of an old and unsecured extension.

Additional information maybe found here:

  Security & Performance FAQ

The above mentioned FAQ will provide with more than enough information to assist you in further securing your sites.

Particular entries of note and to pay attention to, are;

  Joomla! Administrator's Security Checklist

  Help! My site's been compromised. Now what?

  Vulnerable Extension List

  Joomla! Tools Suite
  How can I check my Joomla! installation's overall security and health?

  What does Joomla! have to do with file permissions?

_________________

** Moved to Queensland** still on/offline intermittantly, will be awhile yet.
Joomla! Tools Suite v2 Beta2 release available at http://joomlacode.org/gf/project/jts/


Top
   
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 2 posts ] 

Quick reply

 



Who is online

Users browsing this forum: No registered users and 19 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group