Chrome data breach warning on upgrade?

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
zebu
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Wed Aug 26, 2020 4:32 pm

Chrome data breach warning on upgrade?

Post by zebu » Wed Aug 26, 2020 4:47 pm

When attempting to upgrade Joomla 3.9.20 to 3.9.21 using the admin interface in Google Chrome, I got a Chrome dialog warning me that "A data breach on a site or app exposed your password." (See https://security.googleblog.com/2019/12 ... hrome.html and https://blog.google/products/chrome/bet ... rotectionsfor details on how this feature works.)

This only occurred on the update, not when logging in to the site, so I don't think it's my credentials, but I could be mistaken. Does the upgrade page use a default username/password for a Joomla site that this feature might be triggering on? Any other theories as to what might be going on?

zebu
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Wed Aug 26, 2020 4:32 pm

Re: Chrome data breach warning on upgrade?

Post by zebu » Wed Aug 26, 2020 5:28 pm

My current theory is that it was trying $ftp_pass from configuration.php, a pretty weak password from a previous version of the site. Testing suggests that Google has flagged that as a 'breached password' from previously appearing in an unrelated data breach. Does that sound plausible?

User avatar
AMurray
Joomla! Exemplar
Joomla! Exemplar
Posts: 9915
Joined: Sat Feb 13, 2010 7:35 am
Location: Australia

Re: Chrome data breach warning on upgrade?

Post by AMurray » Wed Aug 26, 2020 9:52 pm

Remove the FTP information entirely - you don't need it.
Regards - A Murray
General Support Moderator

User avatar
AMurray
Joomla! Exemplar
Joomla! Exemplar
Posts: 9915
Joined: Sat Feb 13, 2010 7:35 am
Location: Australia

Re: Chrome data breach warning on upgrade?

Post by AMurray » Wed Aug 26, 2020 9:54 pm

All you need when updating Joomla is log on with your Super Admin account, go to Joomla Update and do the update.

The FTP function is there for use if required but on majority of decent hosting, is not required.
Regards - A Murray
General Support Moderator

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44175
Joined: Sat Apr 05, 2008 9:58 pm

Re: Chrome data breach warning on upgrade?

Post by Webdongle » Wed Aug 26, 2020 10:17 pm

http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".


Locked

Return to “Security in Joomla! 3.x”