Keep getting referrals to my site for inurl:"com_smf" - Security issue or not?

For all Non-Joomla! security issues. ie 3pd Components etc.

Moderator: General Support Moderators

Forum rules
Locked
User avatar
classixuk
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 108
Joined: Tue Nov 07, 2006 5:14 pm

Keep getting referrals to my site for inurl:"com_smf" - Security issue or not?

Post by classixuk » Wed Dec 20, 2006 1:39 pm

Hi everyone,
I keep getting referrals each day (only one or two, but hey) from Google from somebody typing the following in as a search parameter: inurl:"com_smf".

I'm slightly concerned as to why somebody would be looking for any SMF forums wrapped in Joomla. Is this a potential security issue do you think? Is some script kiddie looking for SMF wrapped forums to take advantage of an exploit?

What do you think?

It's been going on for around 4 days now.

Cheers,
Chris.

niemothk
I've been banned!
Posts: 151
Joined: Thu Jan 18, 2007 4:43 am

Re: Keep getting referrals to my site for inurl:"com_smf" - Security issue or no

Post by niemothk » Sat Feb 03, 2007 10:12 am

well....there good be a variety of benign reasons.

Someone developing a website with SMF may want to see others and get ideas, or ....

yeah ..probably some exploit: there have been some just recently patched with 1.1.1 that allow uploaders to enter Javascript cloaked as an image ( gif) which could then lead your browser to...

http://blogs.zdnet.com/security/?p=15


There is also a LONG OUTSTANDING code exposure issue with SMF as well, that allows anybody to see the source code of recently patched SMF files. (This is dangerous if, like some people, you actually hard code sensitive information INSIDE a php file, ie.


Locked

Return to “3rd Party/Non Joomla! Security Issues”