The Joomla! Forum ™



Forum rules


Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting.
Forum Post Assistant - If you are serious about wanting help, you should use this tool to help you post.



Post new topic Reply to topic  [ 17 posts ] 
Author Message
 Post subject: Where's the bottom?
PostPosted: Thu Jul 16, 2009 5:31 pm 
User avatar
Joomla! Ace
Joomla! Ace

Joined: Tue Jun 09, 2009 2:21 am
Posts: 1963
Location: WV
*sigh*
I love Joomla a lot, but in the past 2 weeks, I've found XSS vulnerabilities in 9 different Joomla components:

  • Agora Forums
  • ccBoard *
  • Ninjaboard *
  • EasyBook *
  • JTag Ticketing System
  • uddeIM
  • Kunena
  • WebAmoeba
  • SOBI2 *
* unpublished for now
Where will the madness end? ??? :eek: ???
Edit: updated list of published exploits

_________________
http://jeffchannell.com - Joomla Extensions & Support
http://biziant.com - Open Joomla Firewall/IDS
Unsolicited private messages/emails = hire me to fix your problem.
καλλιστι


Last edited by jeffchannell on Tue Jul 21, 2009 12:25 pm, edited 1 time in total.

Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Thu Jul 16, 2009 8:01 pm 
User avatar
Joomla! Ace
Joomla! Ace

Joined: Tue Sep 06, 2005 11:18 am
Posts: 1365
Location: Germany
you are running the 1.5.12 ?

_________________
http://www.schrammen.net


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Thu Jul 16, 2009 9:13 pm 
User avatar
Joomla! Ace
Joomla! Ace

Joined: Tue Jun 09, 2009 2:21 am
Posts: 1963
Location: WV
Yes. It's not that I'm getting hacked. I installed each of these components, latest versions on ALL of them, and exploited them myself.

Just lamenting, friend...

_________________
http://jeffchannell.com - Joomla Extensions & Support
http://biziant.com - Open Joomla Firewall/IDS
Unsolicited private messages/emails = hire me to fix your problem.
καλλιστι


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Fri Jul 17, 2009 5:02 am 
User avatar
Joomla! Explorer
Joomla! Explorer

Joined: Fri Nov 24, 2006 6:13 pm
Posts: 335
Jeff, after your email, we got this issue secured as well as 2 others. Thank you very much for your email earlier today. It couldn't have been better timing as we were about to release Agora 3.0 prior to this.

Now our attachment system will check for actual mime types of any executable type of file

_________________
http://jvitals.com


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Fri Jul 17, 2009 10:19 am 
User avatar
Joomla! Ace
Joomla! Ace

Joined: Tue Sep 06, 2005 11:18 am
Posts: 1365
Location: Germany
jeffchannell wrote:
Yes. It's not that I'm getting hacked. I installed each of these components, latest versions on ALL of them, and exploited them myself.

Just lamenting, friend...


ok, now it's clear

_________________
http://www.schrammen.net


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Fri Jul 17, 2009 11:53 am 
User avatar
Joomla! Ace
Joomla! Ace

Joined: Tue Jun 09, 2009 2:21 am
Posts: 1963
Location: WV
Hazzaa - I didn't expect a reply to my email here. :P Can you keep me updated as to when the release will be available, so I can publish the article I wrote? I'll try not to do as I did with Kunena (forgot to set the published param, then Google cached it before I even realized).

_________________
http://jeffchannell.com - Joomla Extensions & Support
http://biziant.com - Open Joomla Firewall/IDS
Unsolicited private messages/emails = hire me to fix your problem.
καλλιστι


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Fri Jul 17, 2009 6:14 pm 
User avatar
Joomla! Explorer
Joomla! Explorer

Joined: Fri Nov 24, 2006 6:13 pm
Posts: 335
It is available now ( http://extensions.joomla.org/extensions ... 91/details ). As for replying to your email here, I think it is perfect allowing others in the community to know (if they use Agora) to update ASAP
We are sending out emails to all our members but this only reaches 7,000+ out of more than 70,000.

Once again, thank you for catching this on our behalf

_________________
http://jvitals.com


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Sat Jul 18, 2009 8:57 pm 
User avatar
Joomla! Ace
Joomla! Ace

Joined: Tue Jun 09, 2009 2:21 am
Posts: 1963
Location: WV
Advertise? My exploits? The published ones are on my blog, see the link in my sig...

...the unpublished ones will stay that way for now.

_________________
http://jeffchannell.com - Joomla Extensions & Support
http://biziant.com - Open Joomla Firewall/IDS
Unsolicited private messages/emails = hire me to fix your problem.
καλλιστι


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Sat Jul 18, 2009 9:11 pm 
User avatar
Joomla! Master
Joomla! Master

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11641
Location: The Girly Side of Joomla in Sussex
legendkiller333 wrote:
can you advertise

5 post PM spammer...
:pop

recommend add to FOE lists

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Sat Jul 18, 2009 9:17 pm 
User avatar
Joomla! Ace
Joomla! Ace

Joined: Tue Jun 09, 2009 2:21 am
Posts: 1963
Location: WV
Nice catch, I've barely been on today...

_________________
http://jeffchannell.com - Joomla Extensions & Support
http://biziant.com - Open Joomla Firewall/IDS
Unsolicited private messages/emails = hire me to fix your problem.
καλλιστι


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Tue Jul 21, 2009 5:05 am 
User avatar
Joomla! Explorer
Joomla! Explorer

Joined: Fri Nov 24, 2006 6:13 pm
Posts: 335
Jeff, though many users have updated, there are many still vulnerable whether through Agora or the other components you have listed. Please be fair to them so they are not hacked.

_________________
http://jvitals.com


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Tue Jul 21, 2009 7:34 am 
Joomla! Guru
Joomla! Guru

Joined: Wed Jan 09, 2008 9:16 pm
Posts: 527
Jeff,

Thanks again for picking these up. Is it safe to assume that you've informed the developers of all these extensions, as I'm a user of more than one of them and would hope that updates are being put in place as I type!

Best wishes,

Dave.

_________________
My website: http://www.davidboggitt.com/
Love and hate both devastate you, but at least love takes you to dinner first.


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Tue Jul 21, 2009 12:07 pm 
User avatar
Joomla! Ace
Joomla! Ace

Joined: Tue Jun 09, 2009 2:21 am
Posts: 1963
Location: WV
Dave - some have patched, some have replied, and some I've still never heard from.

And to those who don't like my exploits being posted here: that's fine. I believe in full disclosure, and I will be publishing these regardless of who likes it, just not here anymore...

_________________
http://jeffchannell.com - Joomla Extensions & Support
http://biziant.com - Open Joomla Firewall/IDS
Unsolicited private messages/emails = hire me to fix your problem.
καλλιστι


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Tue Jul 21, 2009 12:19 pm 
Joomla! Guru
Joomla! Guru

Joined: Wed Jan 09, 2008 9:16 pm
Posts: 527
I'm with you on this one... I think that the devs should be informed of the vulnerabilities and given time to patch their product. Users need to be aware of the vulnerabilities to make a choice over their solution.

Am I to assume you will be publishing on your site/blog instead and why not on the J! extensions forum?

Dave.

_________________
My website: http://www.davidboggitt.com/
Love and hate both devastate you, but at least love takes you to dinner first.


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Tue Jul 21, 2009 12:38 pm 
User avatar
Joomla! Ace
Joomla! Ace

Joined: Tue Jun 09, 2009 2:21 am
Posts: 1963
Location: WV
I'll be publishing on my blog, and probably start sending submissions to milw0rm again. As for here, no. No more vulnerabilities will be posted here. I guess it just rubs some people the wrong way...

_________________
http://jeffchannell.com - Joomla Extensions & Support
http://biziant.com - Open Joomla Firewall/IDS
Unsolicited private messages/emails = hire me to fix your problem.
καλλιστι


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Tue Jul 21, 2009 2:56 pm 
User avatar
Joomla! Virtuoso
Joomla! Virtuoso

Joined: Sat Sep 24, 2005 11:01 pm
Posts: 4779
Location: Toronto, Canada
jeffchannell wrote:
I'll be publishing on my blog, and probably start sending submissions to milw0rm again. As for here, no. No more vulnerabilities will be posted here. I guess it just rubs some people the wrong way...


We don't publish vulnerabilities here because this is a forum, and not a vulnerability reference site. There are other sites that do a much better job.

The proper way to handle exploits that you find is to first contact the developer and give them an opportunity to respond. If they don't respond within a reasonable amount of time then I think it is fair to publish the exploit.

If you find issues in the core itself, please report them at http://developer.joomla.org/security/co ... -team.html.

When we receive security issue reports we investigate them and assess the priority level and take appropriate action - whether that be fixing in the next maintenance release or if it is severe enough starting the release cycle early.

Ian


Top
 Profile  
 
 Post subject: Re: Where's the bottom?
PostPosted: Wed Jul 22, 2009 10:23 pm 
User avatar
Joomla! Ace
Joomla! Ace

Joined: Thu Mar 26, 2009 5:38 pm
Posts: 1272
Location: Gadsden, AL
The Issue

Various extensions have been found to have security vulnerabilites.

The Method of Reporting

Not all issues listed show as "reported to author/developer" on the site listed from the author of this post. Also according to the site this was not done in some cases (see Kunena post - found here: http://jeffchannell.com/Joomla/kunena-f ... ility.html ) In the comments the purpose for Not reporting was "Jeff Channell--The resulting chaos can be fun to watch sometimes."

The Purpose

While reporting security issues is an excellent thing to do and is everyone's responsibility in the community when these are found it is always wise to give the developers the opportunity to fix the issue.

The Result

By basically posting "How To" guides you have provided hackers and hacker-wannabe's additional opportunities that may not have been completely known before. You have assumed that all the developers of these extensions (which are all mostly free to use) are on YOUR time-schedule. You've also assumed that every single user of these extensions are on YOUR update schedule. This is just because you think it's "fun to watch"?

My Thoughts

Instead of publishing a "How To Guide For Hackers" publish a fix and/or a link to the developer's fix. Your guides give no benefit to the community and instead could cause potential trouble for thousands of sites worldwide - all in the name of your personal enjoyment? I believe that many other community members would/do have serious issues with the approach you took here. Maybe next time you'll consider the negative impact on the community.

_________________
~Matt Lipscomb
http://www.USAFreelancers.org
Professional Joomla! Services and Web Development based in the USA


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 17 posts ] 



Who is online

Users browsing this forum: No registered users and 21 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group