Joomla! Discussion Forums



It is currently Tue Feb 09, 2010 10:26 pm (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 5 posts ] 
Author Message
Posted: Sun Apr 02, 2006 11:07 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu Dec 01, 2005 4:59 am
Posts: 47
Can someone from the Joomla team pm me immediately. I'm getting hacked like crazy on several servers through the same vulnerability. My yim is dcmeagle, aim is dmaricic and msn is dcmeagle@goosemoose.com. I found the problem but I'm not sure how widespread it is. I'm running 1.0.8.

Note that this problem is created by the copperminevis component. I have not found the problem in any other components I've tested.

_________________
Home Inspector Pro Home Inspection Software: http://www.HomeInspectorPro.com
Goosemoose Pet Portals: http://www.GooseMoose.com


Last edited by stingrey on Mon Apr 03, 2006 11:10 am, edited 1 time in total.

Top
   
 
 Post subject: Re: Security leak
Posted: Mon Apr 03, 2006 5:42 am 
User avatar
Joomla! Master
Joomla! Master
Offline

Joined: Thu Aug 18, 2005 7:13 am
Posts: 13347
Have you contacted the developers of copperminevis? If this is a leak in this particular component, they are the persons that will need to look at/fix any security issues within that component.

_________________
Take care


Top
   
 
Posted: Mon Apr 03, 2006 11:17 am 
User avatar
Joomla! Hero
Joomla! Hero
Offline

Joined: Mon Aug 15, 2005 4:36 pm
Posts: 2399
Location: Marikina, Metro Manila, Philippines
Having recieved you PM and looking at the access logs, I would say that if there is a vunerability it lies in the copperminevis component and NOT in the Joomla! core.

You will need to contact the component developer, informing them of this possible security vulnerability in their extension.

_________________
God grant me the Serenity to Accept the things I cannot change, the Courage to change the things I can and the Wisdom to know the Difference.


Top
  E-mail  
 
Posted: Mon Apr 03, 2006 5:02 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu Dec 01, 2005 4:59 am
Posts: 47
It is definately in Copperminevis. I've contacted the author and am waiting for a response. I've identified the line that created the problem.

_________________
Home Inspector Pro Home Inspection Software: http://www.HomeInspectorPro.com
Goosemoose Pet Portals: http://www.GooseMoose.com


Top
   
 
Posted: Tue Apr 04, 2006 3:11 am 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Tue Apr 04, 2006 2:57 am
Posts: 3
Sadly my own site was compromised running CoppermineVis.

This was not a Joomla core issue, but the component.

I worked with my hosting company and it seems they only got access to tmp (and uploaded some crap there).

I scanned my logs and it seems these scumbags are using google to search for:

"index.php?option=com_copperminevis"

to locate the sites and targetting that way.

I have since completely removed this component and all associated with it.


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 5 posts ] 

Quick reply

 



Who is online

Users browsing this forum: MSNbot Media and 21 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group