eWriting Component SQL Injection

For all Non-Joomla! security issues. ie 3pd Components etc.

Moderator: General Support Moderators

Forum rules
Locked
pashao
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Wed Dec 12, 2007 1:26 pm

eWriting Component SQL Injection

Post by pashao » Sat Mar 15, 2008 6:52 pm

One of my sites was hacked this morning. I was updating it at the time and was thrown out of admin. When I attempted to log back in my password was unknown. I couldn't even email myself a new password. I thought my site was quite buttoned up so I searched around and found that there is a security risk with eWriting, http://secunia.com/advisories/29292/. This is unfortuante as I host fan fiction. I noticed in my stats that searchs had been made for ewriting (can't recall the exact search string as I got angry and deleted everythign).

Anyone running ewriting be warned.

Sue
Joomla! Apprentice
Joomla! Apprentice
Posts: 38
Joined: Thu Sep 22, 2005 10:17 am

Re: eWriting Component SQL Injection

Post by Sue » Sun Mar 16, 2008 12:34 am

I've had a similar experience. This is a very worrying development for me - I've been using eWriting for years and have hundreds of stories in it.

I don't know quite what to do. I don't have the programming skills necessary to update the code.

tankochan
Joomla! Apprentice
Joomla! Apprentice
Posts: 7
Joined: Tue Feb 26, 2008 12:00 am

Re: eWriting Component SQL Injection

Post by tankochan » Fri Mar 28, 2008 3:25 am

I installed it in a couple of sites, it's working fine but I'm worrying about being hacked now. I guess it's not that complex to patch, but I also have no idea of how to do this.

I hope someone can help us, since eWriting is the only fiction/stories directory component we have.

pashao
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Wed Dec 12, 2007 1:26 pm

Re: eWriting Component SQL Injection

Post by pashao » Fri Mar 28, 2008 7:00 am

I Googled my site and found my login in and password on a forum. It appears that these people hack a site then post the details like a score card or something. I hope it can be made secure as you say it's the only component we have for fiction.


Locked

Return to “3rd Party/Non Joomla! Security Issues”