|
Tag: major security issue
Troubleshouting → Available entrance for hackers?DonAlan Rekow 2009.08.22 22:19 ↑ 0.1 ↓ Update status: solved I like the blog set up and was pleased to have it on my site but I am starting to get people from Turkey and Saudi Arabia seeking my site out with Google using I+Do+Blog then I have had one by using a series of requesting passwords a couple of times get in and hack my site. I have disabled the blog and the login module until I can make sure that there is no security issue with this. I have been just fine for several years until I added the blog now have suspicious activity on the site. Can you advise? Specifically: I have people entering from these site addresses: http://www.google.com/search?q=allinurl%3A%20com_idoblog&hl=en&lr=&tbo=1&num=30&tbs=qdr:w http://www.don-alanrekow.net/index.php?option=com_idoblog&task=userblog&userid=62&Itemid=84 The Google search word is: allinurl: com_idoblog I don't have any idea why I would show up on the first page but what ever it is AND there are only 167 available options it seems to give a certain group of people (ie hackers) access to the admin portion of my site using a series of queries for forgotten passwords. That gives them the ability to add their own index pages. I DO NOT know all that is going on but I don't like it and I hope this helps find a possible security breach. This I also found about the problem: There are security warnings about Idoblog at Secunia and Milworm. SQL injections are the problem. I have not seen anything addressing this vulnerability from the component maker or on the Joomla forums. Has it been fixed? Please see what can be done. Thanks. |


