com_joomlalib security problem

For all Non-Joomla! security issues. ie 3pd Components etc.

Moderator: General Support Moderators

Forum rules
Locked
paulmc
Joomla! Apprentice
Joomla! Apprentice
Posts: 27
Joined: Tue Jul 25, 2006 12:52 pm

com_joomlalib security problem

Post by paulmc » Tue Oct 16, 2007 10:44 am

Hi

I just received the following message from one of my providers last night. Any comments?
We have received complaints about content hosted on your VPS at the following URL:

http://www.mydomaine.org/components/com ... index.html

Upon further investigation, we have found additional software in place on your system which was actively used to gather personal information such as logins and passwords for the Bank of America. These files are located at the following location:

/home/virtual/mydomaine.org/webroot/htdocs/components/com_joomlalib/standalone:
---------- 1 root root 161220 Sep 18 12:26 mag.php
---------- 1 root root 8031 Sep 18 12:26 stubjambo.php
---------- 1 root root 72121 Oct 13 08:41 http://www.BankOfAmeria.com-2007.zip
d--------- 3 root root 1024 Oct 13 08:42 http://www.BankOfAmeria.com-2007
---------- 1 root root 183465 Oct 13 09:16 bankofamerica.zip
d--------- 5 root root 1024 Oct 15 07:06 bankofamerica

We have taken steps to disable and remove access to these files. However, it is possible that there are other compromised sites which we have been unable to detect.

The likely source of this compromise is outdated web software which you are running on this domain. In this case, a version of Joomla is running that has known, published vulnerabilities to allow an attacker unauthorized system access.

User avatar
rued
Joomla! Virtuoso
Joomla! Virtuoso
Posts: 4840
Joined: Fri Sep 16, 2005 10:23 pm
Location: Finland / Norway
Contact:

Re: com_joomlalib security problem

Post by rued » Tue Oct 16, 2007 11:30 am

In this case, a version of Joomla is running that has known, published vulnerabilities to allow an attacker unauthorized system access.
What version of Joomla! are you running then?
Have you considered to upgrade to latest version, if you haven't already?
Rune Rasmussen - https://syntaxerror.no/
Norske nettløsninger og integrasjoner, brukerstøtte og vedlikehold m.m. for betalende kunder.

Norske oversettelser -> viewtopic.php?f=210&t=1006497

User avatar
Tonie
Joomla! Master
Joomla! Master
Posts: 16553
Joined: Thu Aug 18, 2005 7:13 am

Re: com_joomlalib security problem

Post by Tonie » Tue Oct 16, 2007 11:35 am

Also, which version of bsq_sitestats are you running?

paulmc
Joomla! Apprentice
Joomla! Apprentice
Posts: 27
Joined: Tue Jul 25, 2006 12:52 pm

Re: com_joomlalib security problem

Post by paulmc » Tue Oct 16, 2007 12:00 pm

The site is running on v1.0.13 and I'm not running bsq_sitestats.

User avatar
Tonie
Joomla! Master
Joomla! Master
Posts: 16553
Joined: Thu Aug 18, 2005 7:13 am

Re: com_joomlalib security problem

Post by Tonie » Tue Oct 16, 2007 12:16 pm

My mistake. Are you running joomlalib then? The com_joomlalib in the message is a directory of this extension.

paulmc
Joomla! Apprentice
Joomla! Apprentice
Posts: 27
Joined: Tue Jul 25, 2006 12:52 pm

Re: com_joomlalib security problem

Post by paulmc » Tue Oct 16, 2007 12:33 pm

Hi Tonie. Thanks for helping me on this.

It appears that my provider has completely removed the directory for com_joomlalib. The weird thing is that I don't recall installing joomlalib, though it may have been a legacy from a older plugin install - the site has been up for a while.

Do you happen to know what components besides the Gallery2 bridge, which I don't use, would have used it?

Paul

User avatar
Tonie
Joomla! Master
Joomla! Master
Posts: 16553
Joined: Thu Aug 18, 2005 7:13 am

Re: com_joomlalib security problem

Post by Tonie » Tue Oct 16, 2007 12:56 pm

Not really, all I did was search on 'com_joomlalib security' on google. If there are security issues with an extension, this will get you the results you need normally.

User avatar
infograf768
Joomla! Master
Joomla! Master
Posts: 19133
Joined: Fri Aug 12, 2005 3:47 pm
Location: **Translation Matters**

Re: com_joomlalib security problem

Post by infograf768 » Tue Oct 16, 2007 2:25 pm

Jean-Marie Simonet / infograf
---------------------------------
ex-Joomla Translation Coordination Team • ex-Joomla! Production Working Group

paulmc
Joomla! Apprentice
Joomla! Apprentice
Posts: 27
Joined: Tue Jul 25, 2006 12:52 pm

Re: com_joomlalib security problem

Post by paulmc » Tue Oct 16, 2007 2:43 pm

Thanks.


Locked

Return to “3rd Party/Non Joomla! Security Issues”