I want to agree with most of what Chris Hutcheson posted regarding security notification.
I've read in the Security section that one can subscribe to that part of the forum, and thereby receive notifications, but when all posts are moved to the lesser-know/used Sites & Infrastructure section as happened in this case, then many people may be unaware of a potential serious security issue (joomla, extension, PHP or otherwise).
Regarding what eyezberg posted:
eyezberg wrote:
How will publication of the investigations be handled, do we have to wait untill hole and fix both are available if it's Joomla core, will you post the hole if it's a 3rd part extension even before the fix is available so concerned people can remove it from their sites, are there any hints yet..?
Don't know if this part is off topic, but I don't see how posting a screenshot can be considered "rude"... I don't mind readers here not knowing who hacked the site, but how it was done is crucial info, and if these same hackers (a cracker for me is this:
http://www.cepolina.com/freephoto/f/oth ... .bread.jpg ) have, as I understood from a post here, already compromised other sites, it might be helpfull to be able to search with their name or url or whatever to gain insight on the methods they used, and thus maybe be able to secure one's site before the team here is able to post something...
Alsoo think this is more a Security matter than "Sites and Infrastructure", as it doesn't only affect joomla.orgs site(s), and is in no way a "'mechanical' forum or Joomla! sites related issues/suggestions" topic.
While I agree in principle that those who hack sites like this should not be given the exposure they want, I also have to agree with what eyezberg said in his post regarding being able to have all info available (including the name of the person or group that hacked the Joomla.org site), so that we can use this to search for answers.
Using the information gained from other sites, I was for instance able to ascertain that more that 40 web sites built on Joomla! have been hacked by the same person who hacked shop.joomla.org and related sites.
Since I am no expert in this field, I have no easy way of knowing if the exploit is not in something unrelated to Joomla, but with the added information gained it is clear that this is not a joomla.org -only issue, and it therefore raises my level of concern for my own site and that of our customers.
Accordingly I would request that this thread be moved to the Security section (where it will get far greater exposure), or at the very least, that a sticky be placed in that section, linking to this thread.
As Chris said, I'm sure that many people are working very hard behind the scenes to get to the bottom of this hacking incident, and I sincerely appreciate the effort!
regards
Jacques
Edited: amount of hacked sites mentioned