Joomla! Discussion Forums



It is currently Fri Nov 27, 2009 2:51 pm (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 39 posts ]  Go to page Previous  1, 2
Author Message
Posted: Thu Oct 08, 2009 10:51 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Tue Sep 06, 2005 11:18 am
Posts: 1120
Location: Germany
psujohn wrote:
fw116 wrote:
well,
as you can find in the forum, if your would use search, there is a good chance, that your windows PC is infected
with some crappy software , which use your FTP account in case you connect to your site and infects your site via your own FTp account.


This response is totally out of place and quite rude. As people have pointed out in this thread this is not an FTP issue. If you bury your head in the sand and assume that all hacked sites are because people have spyware on their PC you're just being ignorant and exposing you and people who listen to you to further attacks. It's pretty clear that this is a vulnerability in either Joomla! or one of the installed components. No amount of scanning your PC for "crappy software" is going to help.

In this case all fingers really do point toward Jumi. I don't think there's a site that's been affected that doesn't have Jumi installed and given Jumi's capabilities it would be a logical place to attack.

I do wish I knew a bit more about the attack because I'm not sure that even the most recent version of Jumi isn't vulnerable. I took a look at the Jumi change logs a while back and didn't see anything that would indicate that the developers were aware of or had fixed a vulnerability like this.


that everybody checks his own add ons installed on a system , would be normal behavior.

and no , the response is not out of place, because only some weeks ago, this was a number one topic.

_________________
MCITP - Microsoft Certified IT Professional
CCNA - Cisco Certfied Network Administrator
LPI - Linux Professional
PN for Online Transcript ID Check
http://www.mindset.de


Top
  E-mail  
 
Posted: Tue Nov 03, 2009 3:47 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Tue May 15, 2007 7:15 am
Posts: 233
Location: South Africa
Jumi currently has some Backdoor script issues, see Issue 45 - jumi - BACKDOOR in JUMI 2.0.5 - Project Hosting on Google Code

_________________
Mustaq
War defines who's left , not who's right...
Live. Love, Learn and Joomla !
http://www.herdboy.com - http://www.herdboyhost.com


Top
   
 
Posted: Tue Nov 03, 2009 6:48 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu May 14, 2009 4:29 pm
Posts: 14
I can't be 100% sure for various reasons but I'm pretty close to certain that the sites affected by this did NOT have the Jumi version with the backdoor installed.


Top
  E-mail  
 
Posted: Tue Nov 03, 2009 9:28 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Tue May 15, 2007 7:15 am
Posts: 233
Location: South Africa
psujohn wrote:
I can't be 100% sure for various reasons but I'm pretty close to certain that the sites affected by this did NOT have the Jumi version with the backdoor installed.


So far there was confirmation of Backdoored Versions 2.0.4 and 2.0.5 . What version did you have installed ?

_________________
Mustaq
War defines who's left , not who's right...
Live. Love, Learn and Joomla !
http://www.herdboy.com - http://www.herdboyhost.com


Top
   
 
Posted: Tue Nov 03, 2009 9:47 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu May 14, 2009 4:29 pm
Posts: 14
2.0.3 and I looked and it didn't have the same backdoor that I saw in 2.0.4.

I know 2.0.3 had an SQL injection vulnerability but the db looked fine and SQL injection doesn't let you write files.


Top
  E-mail  
 
Posted: Tue Nov 03, 2009 10:47 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Tue May 15, 2007 7:15 am
Posts: 233
Location: South Africa
Thanks for the confirmation :)

_________________
Mustaq
War defines who's left , not who's right...
Live. Love, Learn and Joomla !
http://www.herdboy.com - http://www.herdboyhost.com


Top
   
 
Posted: Wed Nov 04, 2009 6:58 am 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Tue Jun 09, 2009 2:21 am
Posts: 1265
Location: WV
psujohn wrote:
2.0.3 and I looked and it didn't have the same backdoor that I saw in 2.0.4.

I know 2.0.3 had an SQL injection vulnerability but the db looked fine and SQL injection doesn't let you write files.


Don't be too sure...
http://www.milw0rm.com/papers/372

_________________
http://jeffchannell.com - Joomla Extensions & Web Development
Unsolicited private messages/emails asking for help = you wish to hire me to fix your problem.
καλλιστι


Top
   
 
Posted: Wed Nov 04, 2009 2:00 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu May 14, 2009 4:29 pm
Posts: 14
jeffchannell wrote:


True but my database users don't have file permission.


Top
  E-mail  
 
Posted: Wed Nov 04, 2009 7:31 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Tue Jun 09, 2009 2:21 am
Posts: 1265
Location: WV
I just wanted to clarify for others reading that, yes, it's possible.

_________________
http://jeffchannell.com - Joomla Extensions & Web Development
Unsolicited private messages/emails asking for help = you wish to hire me to fix your problem.
καλλιστι


Top
   
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 39 posts ]  Go to page Previous  1, 2

Quick reply

 



Who is online

Users browsing this forum: asande, Hazzaa, hvanrhijn, ianmac, roykyle and 20 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group