Rapid Recipes Exploit

For all Non-Joomla! security issues. ie 3pd Components etc.

Moderator: General Support Moderators

Forum rules
Locked
eli_cook
Joomla! Apprentice
Joomla! Apprentice
Posts: 14
Joined: Wed Feb 13, 2008 7:29 pm

Rapid Recipes Exploit

Post by eli_cook » Wed Feb 13, 2008 7:54 pm

The Joomla component Rapid Recipes that I had purchased has an SQL Injection exploit that allows an attacker to see the admin user's hash. I am unsure as to whether I should post the code or not, this is my first post here. The eventual result was the attacker removed the mySQL user from the database (from what I can tell) then contacted me via the contact form and let me know that my site had a bug!

A few things to add - I am using v. 1.6.5 of Rapid Recipes and the most current is 1.6.6 of the 15 fixes they have listed this SQL injection is not addressed in 1.6.6.

eli_cook
Joomla! Apprentice
Joomla! Apprentice
Posts: 14
Joined: Wed Feb 13, 2008 7:29 pm

Re: Rapid Recipes Exploit

Post by eli_cook » Wed Feb 13, 2008 9:49 pm

I wanted to clear up one issue, the attacker did not remove the user from the mySQL database and did not gain access to the system. The mySQL user being removed from the database was a result of another co-worker thinking the database user should be removed and added back with as few permissions as possible, I apologize for any confusion.

eli_cook
Joomla! Apprentice
Joomla! Apprentice
Posts: 14
Joined: Wed Feb 13, 2008 7:29 pm

Re: Rapid Recipes Exploit

Post by eli_cook » Thu Feb 14, 2008 5:10 pm

The latest version has the fixes for the SQL injection - the version is 1.6.7 - you can find instructions on how to download the updated files from http://www.rapid-source.com

ami01
Joomla! Fledgling
Joomla! Fledgling
Posts: 1
Joined: Wed Aug 11, 2010 9:34 am

Re: Rapid Recipes Exploit

Post by ami01 » Thu Oct 14, 2010 12:46 pm

I think this issue is still in there new recipe :pop
Last edited by mandville on Tue Oct 19, 2010 4:47 pm, edited 1 time in total.
Reason: signature against forum rules- literal urls only

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: Rapid Recipes Exploit

Post by mandville » Tue Oct 19, 2010 4:48 pm

as this topic is 2.5 years old, i think ou best contact the dev to ask more..
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}


Locked

Return to “3rd Party/Non Joomla! Security Issues”