Joomla! Discussion Forums



It is currently Thu Nov 26, 2009 11:33 am (All times are UTC )

 




Post new topic Reply to topic  [ 96 posts ]  Go to page Previous  1, 2, 3, 4  Next
Author Message
Posted: Tue Jul 11, 2006 2:46 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Fri Feb 17, 2006 4:30 pm
Posts: 222
brian wrote:
Maybe so but the previous warning was still ignored.


Too bad some webmaster, still waiting for this incident to happen.  :(

_________________
[ http://www.GIMIK.COM ] My current project.
[ http://www.KING.NET ] My Blog.


Top
  E-mail  
 
Posted: Tue Jul 11, 2006 4:21 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Mon Dec 05, 2005 10:17 am
Posts: 1318
Location: New Orleans, LA, USA
Vulnerability reports with 3rd party components are always tricky to deal with because
1. We don't always have good contact information for the developer, even when the projects are hosted on our forge. 
2. Often the vulnerabilities that get discovered are for projects that aren't actively developed anymore (simpeboard and extcalendar are excellent examples of this).
3. It is hard to address the issue from a reactionary position until you have log files of someone who has been hacked which I had a difficult time getting my hands on when this first started.
4. As someone who isn't familiar with the code, it is not always easy to know exactly what is causing the security vulnerability to exist.  Add this to the 1st and 2nd problems and things get very difficult.

As mentioned in some other thread, I have proposed starting a security mailing list specifically for Joomla and I have also proposed an automatic update/warning feature in Joomla backend that is version aware.  The mailing list was kind of deemed unnecessary by others due to the ability to subscribe to the forum announcements thread.  I personally disagree with this but I don't know what else to say.  As for the automatic warning/update features in the backend well, that stuff takes time to build.

_________________
Rob Schley - Open Source Matters
Webimagery - http://www.webimagery.net/ - Professional Consulting Services
JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions


Top
  E-mail  
 
Posted: Tue Jul 11, 2006 4:43 pm 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Sat Aug 20, 2005 12:32 pm
Posts: 990
Location: Tewkesbury, UK
RobS wrote:
As mentioned in some other thread, I have proposed starting a security mailing list specifically for Joomla


Well almost 10,000 Joomla Users were notified thanks to my opt-in mailing list, including over 7000 customers who have purchased Joomla Components from our site.

Phil.

_________________
Phil Taylor - Full Time Expert Joomla-Only Developer
Blue Flame IT Ltd.
-- http://www.phil-taylor.com/
SPEED UP Joomla 1.5.x Admin Console with this: http://extensions.joomla.org/extensions ... 53/details


Top
   
 
Posted: Tue Jul 11, 2006 4:49 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Fri Feb 17, 2006 4:30 pm
Posts: 222
PhilTaylor-Prazgod wrote:
RobS wrote:
As mentioned in some other thread, I have proposed starting a security mailing list specifically for Joomla


Well almost 10,000 Joomla Users were notified thanks to my opt-in mailing list, including over 7000 customers who have purchased Joomla Components from our site.

Phil.


I highly recommended this as well. Hopefully within joomla.

_________________
[ http://www.GIMIK.COM ] My current project.
[ http://www.KING.NET ] My Blog.


Top
  E-mail  
 
Posted: Tue Jul 11, 2006 4:49 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Mon Dec 05, 2005 10:17 am
Posts: 1318
Location: New Orleans, LA, USA
That is good to know Phil and definitely not a small amount of people.  I think it is great that you have access to a tool like that and that you were considerate enough to send a warning about the recent vulnerabilities.  Unfortunately, that is probably still only a small fraction of our users.  

I would really like to see something that would add your email address to the (low traffic) security mailing list during the J! installation process (optional of course).  If they choose not to opt in so be it but I think it would be an effective tool for us and our users to fight back against the crackers.

_________________
Rob Schley - Open Source Matters
Webimagery - http://www.webimagery.net/ - Professional Consulting Services
JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions


Last edited by RobS on Tue Jul 11, 2006 4:52 pm, edited 1 time in total.

Top
  E-mail  
 
Posted: Tue Jul 11, 2006 4:52 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Fri Feb 17, 2006 4:30 pm
Posts: 222
RobS wrote:
That is good to know Phil and definitely not a small amount of people.  Unfortunately, that is probably still only a small fraction of our users.  

I would really like to see something that would add your email address to the security mailing list during the J! installation process (optional of course).  If they choose not to opt in so be it but I think it would be an effective tool for us and our users.


That's even better.

But I do recommend that optional thing should be easily shown to the administrator so they will not come back to us that we are spamming them since they installed joomla.

_________________
[ http://www.GIMIK.COM ] My current project.
[ http://www.KING.NET ] My Blog.


Top
  E-mail  
 
Posted: Tue Jul 11, 2006 4:52 pm 
Joomla! Virtuoso
Joomla! Virtuoso
Offline

Joined: Fri Aug 12, 2005 7:19 am
Posts: 4471
Location: Leeds, UK
i agree that a security mailing list is essential. an email based system is far more appropiate than a web based one for this post of stuff. never understood other peoples objections to this


Top
  E-mail  
 
Posted: Tue Jul 11, 2006 4:54 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Mon Dec 05, 2005 10:17 am
Posts: 1318
Location: New Orleans, LA, USA
I agree but I think it is critical that the user understand what the list is before they decide to opt out.  In my opinion it should be a low traffic moderated list to keep away from the burden of keeping up with general discussion mailing lists.  It would be much easier for us to refer discussion on topic X back to a specific thread in the forum.

_________________
Rob Schley - Open Source Matters
Webimagery - http://www.webimagery.net/ - Professional Consulting Services
JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions


Top
  E-mail  
 
Posted: Tue Jul 11, 2006 5:54 pm 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Tue Aug 30, 2005 9:11 pm
Posts: 538
Location: Aix-En-Provence, France
I confirm the problem with JoomlaBoard 1.1.2
My site has been defaced last sunday and I found it in the logs!

Logs waiting for your email...

EDIT MOD: NOT CONFIRMED

_________________
May the forge be with you!
http://www.joomlation.eu (intl)
http://www.joomlation.org (fr)


Last edited by infograf768 on Thu Jul 13, 2006 5:28 am, edited 1 time in total.

Top
  E-mail  
 
Posted: Tue Jul 11, 2006 5:55 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Fri Feb 17, 2006 4:30 pm
Posts: 222
globule wrote:
I confirm the problem with JoomlaBoard 1.1.2
My site has been defaced last sunday and I found it in the logs!

Logs waiting for your email...


Ouch !!!

_________________
[ http://www.GIMIK.COM ] My current project.
[ http://www.KING.NET ] My Blog.


Top
  E-mail  
 
Posted: Tue Jul 11, 2006 5:56 pm 
Joomla! Virtuoso
Joomla! Virtuoso
Offline

Joined: Fri Aug 12, 2005 7:19 am
Posts: 4471
Location: Leeds, UK
yes an announce only list that requires moderation before any mail is sent


Top
  E-mail  
 
Posted: Tue Jul 11, 2006 6:25 pm 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Fri Aug 19, 2005 9:01 am
Posts: 63
Location: Stockholm, Sweden
A tip for ppl that are running their own servers and/or have good connections with the "hoster"....
http://www.modsecurity.org

and I collect updated rules from
http://www.gotroot.com/tiki-index.php?page=mod_security+rules

But if you install this - please check the output (logg) for the mod... some things blocks things that shouldn't be but after removing those rules 99,999% of all "vulnerability"-scanners gets the extended middle finger (including the Simpleboard & ExtCalendar vulnerability got caught in this "firewall" on my server).

It's not a solution for the actual vulnerability but with it on your server you'll probably sleep better. (I pipe the logentries to my mail and I have between 5 and 150 reports a day - there's a lot of ***h*les out there)

_________________
Member of the Swedish Translation Team


Top
   
 
Posted: Tue Jul 11, 2006 9:16 pm 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Tue Aug 30, 2005 9:11 pm
Posts: 538
Location: Aix-En-Provence, France
Mea culpa :
I was parsing my logs to check the history of the attack and at the end, I realised something strange :
all entries was refering to 'simpleboard" instead of 'joomlaboard'. :-[

What happened?
When I upgrade from Simpleboard 1.1.0 to Joomlaboard, the old files were not automaticaly delete. I knew it but I kept old version, just in case... :'(
So, even if there was no menu entry refering to Simpleboard, the hacker could access to it. He just supposed if Joomlaboard is installed, there is a chance there was Simpleboard before... and he was right!

Conclusion : This attack DOES NOT concern Joomlaboard but ONLY SimpleBoard

Recommandation : People who upgraded from SimpleBoard to JoomlaBoard should check if they delete SimpleBoard files.

I'm really sorry.

_________________
May the forge be with you!
http://www.joomlation.eu (intl)
http://www.joomlation.org (fr)


Top
  E-mail  
 
Posted: Tue Jul 11, 2006 10:14 pm 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Tue Jul 11, 2006 9:32 pm
Posts: 4
PhilTaylor-Prazgod wrote:
RobS wrote:
As mentioned in some other thread, I have proposed starting a security mailing list specifically for Joomla


Well almost 10,000 Joomla Users were notified thanks to my opt-in mailing list, including over 7000 customers who have purchased Joomla Components from our site.

Phil.


Yeah,  thanks Phil.  I got the email this morning and fortunately my site hasn't been hacked yet.    I have done the "rename" folder thing as suggested. 

Is there any new news on a fix?  I really would like to get my forums back up.


Top
   
 
Posted: Tue Jul 11, 2006 10:19 pm 
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Thu Aug 18, 2005 8:54 pm
Posts: 367
P_Funk wrote:
Is there any new news on a fix?  I really would like to get my forums back up.


The fix is:
  • Uninstall simpleboard
  • Install joomlaboard 1.1.2
  • When asked for during install, click to have the database updated

Oh yes, dont forget to make a backup of the database & files first. Just in case.

MOST IMPORTANT: DONT KEEP ANY SIMPLEBOARD FOLDERS AND FILES ON THE SERVER!


Last edited by Anonymous on Tue Jul 11, 2006 10:21 pm, edited 1 time in total.

Top
  E-mail  
 
Posted: Wed Jul 12, 2006 12:12 am 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Tue Jul 11, 2006 9:32 pm
Posts: 4
Done!!!! Thanks !!!


Top
   
 
Posted: Wed Jul 12, 2006 4:52 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Fri May 05, 2006 1:01 pm
Posts: 19
Hello,

I have simpleboard 1.1 and those bots have been trying to deface my site for about 1-2 weeks. Nothing happened yet, but they are really annoying because they try to do this about 50-100 times/minute. I will uninstall simpleboard and install joomlaboard. All posts/confs will be saved?


Top
  E-mail  
 
Posted: Wed Jul 12, 2006 8:40 pm 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Thu Sep 01, 2005 2:43 pm
Posts: 87
Location: Næstved
RobS wrote:

This code should be in all files installed by com_simpleboard and com_extcalender.  Basically, everything in /path/to/Joomla/components/com_extcalender,  /path/to/Joomla/administrator/components/com_extcalender, /path/to/Joomla/components/com_simpleboard, and /path/to/Joomla/administrator/components/com_simpleboard

Code:
// no direct access
defined( '_VALID_MOS' ) or die( 'Restricted access' );


Refer to this link for more information about extCalender: http://forum.joomla.org/index.php/topic,75390.0.html


Just checking to see if I get this right: every single file in those folders +subfolders have to be opened and edited..? (really hoping that I'm wrong on this..!)  :'(


Top
  E-mail  
 
Posted: Thu Jul 13, 2006 12:46 am 
User avatar
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Wed Dec 28, 2005 11:17 pm
Posts: 36
I'm sorry, I'm not a coder, but where should I paste this code in the files?

Thanks much!

dave


Top
   
 
Posted: Thu Jul 13, 2006 1:18 am 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Wed Aug 17, 2005 10:11 pm
Posts: 85
vokaldesign wrote:
Just checking to see if I get this right: every single file in those folders +subfolders have to be opened and edited..? (really hoping that I'm wrong on this..!)  :'(

You're absolutely correct, sorry. Upgrading to Joomlaboard should be easier in this case.

_________________
Michael Morris - BuyHTTP Internet Services
www.demoplaza.com : Flash Tutorials For Joomla
www.buyhttp.com : Joomla Hosting Specialists
Free Joomla Professional Installation + Free Joomla Template


Top
   
 
Posted: Thu Jul 13, 2006 1:22 am 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Wed Aug 17, 2005 10:11 pm
Posts: 85
davemgood wrote:
I'm sorry, I'm not a coder, but where should I paste this code in the files?

Thanks much!

dave

At the very top , right after
Code:
<?php

_________________
Michael Morris - BuyHTTP Internet Services
www.demoplaza.com : Flash Tutorials For Joomla
www.buyhttp.com : Joomla Hosting Specialists
Free Joomla Professional Installation + Free Joomla Template


Top
   
 
Posted: Thu Jul 13, 2006 2:22 am 
User avatar
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Wed Dec 28, 2005 11:17 pm
Posts: 36
My Joomlaboard already had that code there. I didn't touch it.

My ExtCalendar 2 did not have the code. I added it to each file in both directories.

Thanks much!

dave


Top
   
 
Posted: Thu Jul 13, 2006 6:00 am 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Mon Dec 05, 2005 10:17 am
Posts: 1318
Location: New Orleans, LA, USA
Joomlaboard is currently not thought to have any vulnerabilities.  SimpleBoard is the one with the problems.

_________________
Rob Schley - Open Source Matters
Webimagery - http://www.webimagery.net/ - Professional Consulting Services
JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions


Top
  E-mail  
 
Posted: Thu Jul 13, 2006 6:18 am 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Wed Aug 17, 2005 11:26 pm
Posts: 869
Anybody that changed from simpleboard to Joomlaboard needs to make sure they have removed all simpleboard files from the site.
Simpleboard can be exploited even if it is unpublished and not showing on the site.

_________________
For Mambo assistance: http://forum.mambo-foundation.org
Open Source Research & Best Practice: http://osprojects.info


Top
  E-mail  
 
Posted: Thu Jul 13, 2006 8:01 am 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Thu Sep 01, 2005 2:43 pm
Posts: 87
Location: Næstved
I've installed joomlaboard and was surprised how easy it all went - all of my forums and settings from simpleboard were integrated right away!  :-*
Now I've removed the simpleboard component + modules and tjecked via ftp that every thing has gone...

Still thinking about the calendar thouhg... I've just added the
Quote:
// no direct access
defined( '_VALID_MOS' ) or die( 'Restricted access' );

code to the files in the main folders (.../components/ext_calendar and  .../administrator/somponents/ext_calendar) and not to all files in the subfolders yet... But I suppose I better get started.

Do we know anything about a new release of this calendar? It is in my opinion by far the best calendar components. I've during this process been looking at other alternatives but I just can't seem to find any other calendars that I want...  ???


Top
  E-mail  
 
Posted: Thu Jul 13, 2006 8:14 am 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Mon Dec 05, 2005 10:17 am
Posts: 1318
Location: New Orleans, LA, USA
There have been hints (one by Elpie and I think I saw another somewhere) about someone picking up where the original developer left off and updating the component to deal with the recent security issues and whatnot but I cannot confirm whether or not this is the case. 

I suggest you do what you can to secure it or maybe disable it for now.  chmod -R 000 components/com_extcalendar/* administrator/components/com_extcalendar/* should be suffecient to disable it temporarily. 

_________________
Rob Schley - Open Source Matters
Webimagery - http://www.webimagery.net/ - Professional Consulting Services
JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions


Top
  E-mail  
 
Posted: Thu Jul 13, 2006 12:11 pm 
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Thu Aug 18, 2005 8:54 pm
Posts: 367
After replacing simpleboard by joomlaboard we still get tons of hack attempts because the simpleboard links are still in the search engines.

To hold those infected machines away from trying as many targets as possible, I have recreated the files /components/com_simpleboard/file_upload.php and image_upload.php as:

sleep(100);
?>


Top
  E-mail  
 
Posted: Thu Jul 13, 2006 12:24 pm 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Wed Aug 17, 2005 11:26 pm
Posts: 869
RobS wrote:
There have been hints (one by Elpie and I think I saw another somewhere) about someone picking up where the original developer left off and updating the component to deal with the recent security issues and whatnot but I cannot confirm whether or not this is the case. 

I suggest you do what you can to secure it or maybe disable it for now.  chmod -R 000 components/com_extcalendar/* administrator/components/com_extcalendar/* should be suffecient to disable it temporarily. 


I can confirm that a new release to update ExtCalendar is on its way ;)
Unfortunately, the defined( '_VALID_MOS' ) is NOT enough to protect ExtCalendar. In going through the files we have discovered a number of security issues, including SQL injection. This has led to a considerable amount of recoding to correct the problems.
Due to the number of issues we have found I cannot give you a time for release yet - it will be as soon as we can though.
DO NOT Uninstall the ExtCalendar component unless you have a backup of your data or are willing to lose all your events.
If you want to keep your events I suggest you follow Robs advice and temporarily disable ExtCalendar.

_________________
For Mambo assistance: http://forum.mambo-foundation.org
Open Source Research & Best Practice: http://osprojects.info


Top
  E-mail  
 
Posted: Thu Jul 13, 2006 12:35 pm 
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Thu Aug 18, 2005 8:54 pm
Posts: 367
What a topic mess in this thread  ???


Top
  E-mail  
 
Posted: Thu Jul 13, 2006 9:27 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu Jul 13, 2006 7:39 pm
Posts: 12
I recently traced my latest hack to secunia.

Who are they? or is this part of the simpleboard program?


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 96 posts ]  Go to page Previous  1, 2, 3, 4  Next

Quick reply

 



Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group