Main menu
Home
News
News from Alphaplug
Download
Forum
Support us
Search
Links
Demo site
Contact
Invite a friend
Joomlastreets News
Sign-up





Lost Password?
No account yet? Register

If you find my free stuff useful, why not leave me a little something with PayPal.

Donations are greatly appreciated, and help with the costs of providing FREE Joomla! addons.




Welcome, Guest
Please Login or Register.    Lost Password?

Site hacked - extension vulnerability
(1 viewing) (1) Guest
Go to bottomPage: 1
TOPIC: Site hacked - extension vulnerability
#3924
Site hacked - extension vulnerability 3 Years, 10 Months ago Karma: 0
I had alphacontent extension 2.5.8.

Vulnerability is described here:
www.securityfocus.com/bid/28443/exploit

When they type in the line of code, they get admin, password hash, and database details pop up in the browser.
Removing alphacontent and changing passwords etc. until a fix is found.

I have the sane problem in more site with alphacontent.

I upgrade alphacontent to latest release 3.0.3 but i'm not sure to fix problem...

Suggestions???
loris_batacchi
Fresh Boarder
Posts: 1
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
#3926
Re:Site hacked - extension vulnerability 3 Years, 10 Months ago Karma: 28
This exploit available just with 2.5.8 and older. If you install the last version, no problem.
admin
Admin
Posts: 1095
graph
User Offline Click here to see the profile of this user
Gender: Male Location: Corbeil-Essonnes Birthday: 02/28
The administrator has disabled public write access.
All components are free but...
Ever thought about giving something back?
Please make a donation if you want to support its continued development. Your donations help by hardware, hosting services and other expenses.
 
#3981
Re:Site hacked - extension vulnerability 3 Years, 10 Months ago Karma: 0
admin wrote:
This exploit available just with 2.5.8 and older. If you install the last version, no problem.

If i can advice, think it's more safe if is possible to remove the version of the component from the footer on the next release.
For ex. let only "Powered by AlphaContent © 2005-2008 - All rights reserved". The life of those "children" hackers will be a bit more complicated

Keep up the great work!!
Cheers<br /><br />Post edited by: xplay, at: 2008/04/07 11:41
xplay
Fresh Boarder
Posts: 1
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
#4362
Re:Site hacked - extension vulnerability 3 Years, 6 Months ago Karma: 0
What is about that: milw0rm.com/exploits/5512

Source: www.joomla-downloads.de/unsichere-kompon...content-version.html

On this popular site alphacontent is marked as &quot;unsecure&quot;! The version which ist vulnerable for the exploit above is not known.
Pitt
Fresh Boarder
Posts: 1
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
#4758
Re:Site hacked - extension vulnerability 3 Years ago Karma: 0
Hello,
I have alphacontent 3.0.4

I have a problem:
Trojan-downloader.JS.Psyme.me
c:/www:sauv_administrator:components:com_alphacontents/

All photographys disappear. How to prevent the hacker from starting again?

Thank you for answer.

Jean-Claude Charles
Jean
Fresh Boarder
Posts: 1
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
Go to topPage: 1