Showing posts with label Exploits. Show all posts
Showing posts with label Exploits. Show all posts

Wednesday, August 13, 2008

Joomla! Password Reset/Remind Functionality vulnerability - update asap!

There was a serious security vulnerability found in the popular CMS-software Joomla! (1.5.x, including 1.5.5).
The vulnerability/bug resides in the 'com_user/models/reset.php' where It allows an attacker to remotely change your Joomla administration password since it can reset the password for the first enabled user (admin user).



The exploit can be found here. It already affected a lot of Joomla! users. Example.
So if you are running Joomla! (1.5.x, including 1.5.5) then you should update asap to version 1.5.6 or newer.

More info here

Sunday, June 8, 2008

Increase of malware found on legitimate websites

According to ScanSafe, 68% of the Malware is found on legitimate websites nowadays. These sites were hacked as a result of SQL injection attacks or via stolen FTP credentials.
Malicious scripts and (hidden) iframes are added in order to infect the visitor with trojans, backdoors and password-stealing malware.
That's why you should always be cautious, because even known legitimate sites can't be trusted anymore.

Also read: A May 2007 / May 2008 State of the Web Comparative

If you're on Vista, make sure UAC is enabled, so Internet Explorer runs under Protected Mode.
If you're on XP - you can read some tips here: How to Surf More Securely by gizmo.richards
In case you're using Firefox as your default browser, install the NoScript extension.

Tuesday, May 13, 2008

Reminder for Forum owners

This post is actually a reminder to my previous blog post http://miekiemoes.blogspot.com/2008/04/forum-owners-take-your-responsability.html.

This because recently MANY phpbb forums were compromised, where malicious scripts were injected, responsible for redirecting visitors to a fake codec download site.

More detailed info here:

http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9084991
http://blog.trendmicro.com/more-than-a-half-a-million-web-sites-compromised/
http://uploadmalware.blogspot.com/2008/05/mass-file-injection-redirecting-to-zlob.html
http://www.dynamoo.com/blog/2008/05/mass-phpbb-attack-freehostpinoyinfo-and.html
http://d0mber.blogspot.com/2008/05/mass-phpbb-download-infection.html

So once again, I can't stress enough how important it is to take responsibility if you're a forum owner.

Tuesday, March 25, 2008

Who iframed Easter Rabbit

In the last couple of days, a lot of threads were posted at several different forums where people were complaining about being infected via a trustworthy site.
What happened was, many of these sites were hacked and were injected with a malware embedded iframe. This iframe launched a javascript to infect the visitors of the site with a Trojan downloader.

It's still amazing how many people got infected with this, because this is actually an older exploit that was being used - the MS06-014 exploit - Vulnerability in the Microsoft Data Access Components (MDAC).
This means that MANY have not updated their Windows for years, since this was actually patched in april 2006 - almost 2 years ago!

So once again, I cannot stress enough how important it is to update your Windows - don't wait - update TODAY!