SerrBizSEF Fake SEFS in DB tables

For all Non-Joomla! security issues. ie 3pd Components etc.

Moderator: General Support Moderators

Forum rules
Locked
User avatar
serrbiz
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 231
Joined: Mon Sep 18, 2006 3:48 pm
Location: Dallas, TX
Contact:

SerrBizSEF Fake SEFS in DB tables

Post by serrbiz » Wed Mar 19, 2008 1:01 pm

Hi. We are the original developers of SerrBizSEF. We have discovered a benign security issue.

A spammer has found a way to force bogus URLS / Component into the SerrBizSEF DB tables. We suspect they are trying to create "link popularity" by doing this. It does not as the sefs created have no content, and return a "permission denied" page if called through a browser. However, it is annoying and clogs the system with junk sef urls. We are looking into how this is happening and thought we'd post here to see what the community thinks.

The short fix is to just delete all bogus SEFS through the SerrBizSEF control panel, but that's not really a fix.

Does anyone have any thoughts as to where we should start looking?

Thanks in advance.

Note: We are not sure this is indeed a SerrBizSEF issue. SerrBizSEF may just be recording the bogus sefs / components from a different component / aspect of Joomla that is being exploited. Again, any thoughts or suggestions would be helpful in debugging this.

M.

-- Update --
This is an issue related to Forms LT. It is NOT A SECURITY RISK.

Details / solution is here:

http://www.serr.biz/news-blog/joomla-se ... 32008.html
Last edited by serrbiz on Thu Mar 20, 2008 2:11 pm, edited 1 time in total.

User avatar
serrbiz
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 231
Joined: Mon Sep 18, 2006 3:48 pm
Location: Dallas, TX
Contact:

Re: SerrBizSEF Fake SEFS in DB tables

Post by serrbiz » Thu Mar 20, 2008 2:10 pm

Ok. We have tracked down the issue. It's related to Forms LT, but is NOT A SECURITY RISK.

You can read details here and the solution.

http://www.serr.biz/news-blog/joomla-se ... 32008.html


Locked

Return to “3rd Party/Non Joomla! Security Issues”