Our newsletter

Updates, actions and work of the Club
View IDoBlog news archive

Download

Try it right now

IDo Community

This community works on IDoBlog community 2.0 More info here.

Login Form



IDoBlog LiveNews

Frequently Asked QuestionsStopping public support

2011.02.02 08:43 1 0

Hello!Forced to inform you that we are close the p...

TroubleshoutingError message when creating a new blog, ping not sent to Twitter

2010.11.11 11:57 2 0

I have added my user name and password for Twitter...

TroubleshoutingError submiting comment on IE 8 with captcha

2010.11.03 04:18 4 0

Hello,I'm using idoblog free version. When submit ...

TroubleshoutingThe french version?

2010.10.26 07:28 1 0

Hello, it is French translation available ?

TroubleshoutingError when new user login

2010.10.22 08:51 0 0

After authentication the new user is sent directly...

IDoBlog Online

 
0 registred users and 14 guests online now

IDoBlog NewUsers

 
Tag: major security issue

TroubleshoutingAvailable entrance for hackers?

DonAlan Rekow 2009.08.22 22:19 10 0.1

 

Update status: solved

I like the blog set up and was pleased to have it on my site but I am starting to get people from Turkey and Saudi Arabia seeking my site out with Google using I+Do+Blog  then I have had one by using a series of requesting passwords a couple of times get in and hack my site.  I have disabled the blog and the login module until I can make sure that there is no security issue with this.  I have been just fine for several years until I added the blog now have suspicious activity on the site.  Can you advise?


Specifically: I have people entering from these site addresses:

http://www.google.com/search?q=allinurl%3A%20com_idoblog&hl=en&lr=&tbo=1&num=30&tbs=qdr:w

http://www.don-alanrekow.net/index.php?option=com_idoblog&task=userblog&userid=62&Itemid=84

The Google search word is: allinurl: com_idoblog  I don't have any idea why I would show up on the first page but what ever it is AND there are only 167 available options it seems to give a certain group of people (ie hackers) access to the admin portion of my site using a series of queries for forgotten passwords. That gives them the ability to add their own index pages. I DO NOT know all that is going on but I don't like it and I hope this helps find a possible security breach. 

This I also found about the problem:

There are security warnings about Idoblog at Secunia and Milworm. SQL injections are the problem. I have not seen anything addressing this vulnerability from the component maker or on the Joomla forums. Has it been fixed?

Please see what can be done.

Thanks.


 
  • Comments disabled. Why?

  • биоревитализация гиалуроновой кислотой