Use reg security issue hacker?

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
User avatar
darb
Joomla! Hero
Joomla! Hero
Posts: 2047
Joined: Thu Jul 06, 2006 12:57 pm
Location: Stockholm Sweden

Use reg security issue hacker?

Post by darb » Wed Nov 11, 2020 1:00 pm

Hi I got a user that could register unoticed in one Joomla 3.9.22 site and can bypass the user register process. I have disable everything but discovered that he still can login to the site though I get this info notice from Joomla Joomla User Actions. See below and attachment pics.

Latest User Actions

This is the latest action performed by a user on your website.
Action Date Extension Name IP Address
User logged out from site 2020-11-10 01:28:20 UTC Users 114.119.150.227

What to do and any tips?
db3.jpg
db1.jpg

I will check if he is going trough the ACY mailing extension in some way..hmm :eek: nope he is not present there. Problem is I got these Latest User Actions even I have not login to the site and I dont know whats going on whey I get notice of logout of site and another ip no :pop 871 is my id but I have not login to the site...
You do not have the required permissions to view the files attached to this post.
Last edited by mandville on Wed Nov 11, 2020 1:43 pm, edited 1 time in total.
Reason: Removed assumed nationality

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44175
Joined: Sat Apr 05, 2008 9:58 pm

Re: Use reg security issue hacker?

Post by Webdongle » Wed Nov 11, 2020 7:52 pm

http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

User avatar
darb
Joomla! Hero
Joomla! Hero
Posts: 2047
Joined: Thu Jul 06, 2006 12:57 pm
Location: Stockholm Sweden

Re: Use reg security issue hacker?

Post by darb » Tue Nov 17, 2020 6:10 am

I will do that.

I had a review of the whole site and removed all unwanted extensions plg etc but today again..

I got a new reg spammer now [ redacted ] email: [ redacted ] with IP no address: [ redacted ] and from 15 nov to 17 nov this guy had some activity
Details: [ redacted ] appears in our database 124 times https://www.stopforumspam.com/domain/[ redacted ]

So strange when I have register as disabled and no other reg extension on this site..
Last edited by toivo on Tue Nov 17, 2020 6:44 am, edited 1 time in total.
Reason: mod note: 'personal' details removed

User avatar
darb
Joomla! Hero
Joomla! Hero
Posts: 2047
Joined: Thu Jul 06, 2006 12:57 pm
Location: Stockholm Sweden

Re: Use reg security issue hacker?

Post by darb » Tue Nov 17, 2020 7:31 am

HI Toivo, you are breaking the forum rules.

Can you explain your reason to have "personal" details removed?

Is this your own interpretation of what can be post here or not? Pls give me the forum rules that tell that you have the power to remove this... :eek:
Last edited by toivo on Tue Nov 17, 2020 7:44 am, edited 1 time in total.
Reason: mod note: 'personal' details removed

User avatar
toivo
Joomla! Master
Joomla! Master
Posts: 17516
Joined: Thu Feb 15, 2007 5:48 am
Location: Sydney, Australia

Re: Use reg security issue hacker?

Post by toivo » Tue Nov 17, 2020 7:56 am

Neither hacker nor hack details are allowed here. As simple as that.
Toivo Talikka, Global Moderator

User avatar
darb
Joomla! Hero
Joomla! Hero
Posts: 2047
Joined: Thu Jul 06, 2006 12:57 pm
Location: Stockholm Sweden

Re: Use reg security issue hacker?

Post by darb » Tue Nov 17, 2020 8:06 am

toivo wrote: Tue Nov 17, 2020 7:56 am Neither hacker nor hack details are allowed here. As simple as that.
Ok can you point me to that forum rules here Toivo? or is this your own interpretation?

sozzled
I've been banned!
Posts: 13639
Joined: Sun Jul 05, 2009 3:30 am
Location: Canberra, Australia

Re: Use reg security issue hacker?

Post by sozzled » Tue Nov 17, 2020 8:39 am

darb wrote: Tue Nov 17, 2020 8:06 am
toivo wrote: Tue Nov 17, 2020 7:56 am Neither hacker nor hack details are allowed here. As simple as that.
Ok can you point me to that forum rules here Toivo? or is this your own interpretation?
FYI, the forum rules clearly state:
This is not the place to settle a commercial disagreement for custom development or to be a 'wall of shame'. Any posts deemed to be of this nature will be removed. Settle your disputes in private please.
It's as simple as that.

User avatar
AMurray
Joomla! Exemplar
Joomla! Exemplar
Posts: 9915
Joined: Sat Feb 13, 2010 7:35 am
Location: Australia

Re: Use reg security issue hacker?

Post by AMurray » Tue Nov 17, 2020 8:51 am

As a "Joomla Ace" you should know the rules 8)
Regards - A Murray
General Support Moderator

User avatar
darb
Joomla! Hero
Joomla! Hero
Posts: 2047
Joined: Thu Jul 06, 2006 12:57 pm
Location: Stockholm Sweden

Re: Use reg security issue hacker?

Post by darb » Tue Nov 17, 2020 9:11 am

AMurray wrote: Tue Nov 17, 2020 8:51 am As a "Joomla Ace" you should know the rules 8)
Yes I know the rules and have being in this community since it started also suggested to use/promote phpBB at that time we started up. I had a another name in the beginning but that was messed up after an update.

Anyhow I dont agree with you n o t to disclose this information, and there is no rule about it, bcs I also think it can help and let other people know about these important security hacks that occour.

But now I know now what and why this happend to a fresh new Joomla 3.9.22 install with only 2 respected updated extensions only. For others I recommend to follow that link and block all these IP numbers from xxx hackers until Joomla have a solution. ;)

All the best!

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44175
Joined: Sat Apr 05, 2008 9:58 pm

Re: Use reg security issue hacker?

Post by Webdongle » Tue Nov 17, 2020 11:38 am

Blocking ip addresses will be as much use as a chocolate teapot.

Posting spam details is (in itself) spam. And posting spam is against the rules.
http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

User avatar
darb
Joomla! Hero
Joomla! Hero
Posts: 2047
Joined: Thu Jul 06, 2006 12:57 pm
Location: Stockholm Sweden

Re: Use reg security issue hacker?

Post by darb » Tue Nov 17, 2020 2:40 pm

Webdongle wrote: Tue Nov 17, 2020 11:38 am Blocking ip addresses will be as much use as a chocolate teapot.

Posting spam details is (in itself) spam. And posting spam is against the rules.
Good logic?


Locked

Return to “Security in Joomla! 3.x”