Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Joomla.org has been hacked
Joomla ^ | 8/18/2007 | armymarinemom

Posted on 08/18/2007 6:07:56 AM PDT by armymarinemom

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-4041-52 next last
To: armymarinemom

Thanks for posting this. Very interesting


21 posted on 08/18/2007 6:29:39 AM PDT by vbmoneyspender
[ Post Reply | Private Reply | To 1 | View Replies]

To: driftdiver
Geeks UNITE!

LOL. I do use the software.

22 posted on 08/18/2007 6:30:43 AM PDT by armymarinemom (My sons freed Iraqi and Afghan Honor Roll students.)
[ Post Reply | Private Reply | To 20 | View Replies]

To: ShadowAce; N3WBI3; adam_az

Pings.


23 posted on 08/18/2007 6:39:08 AM PDT by Salo
[ Post Reply | Private Reply | To 22 | View Replies]

To: KoRn

ALL YOUR BASE ARE BELONG TO US!!


24 posted on 08/18/2007 6:40:09 AM PDT by Conservative Infidel (How come they call it "Tourist Season" if we can't shoot them??)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Conservative Infidel

I’m not worried. I have a POCKET PROTECTOR!


25 posted on 08/18/2007 7:23:51 AM PDT by Clioman
[ Post Reply | Private Reply | To 24 | View Replies]

To: armymarinemom

OMG, not Joomla!!!!!!!!!!!!

Wait, what’s Joomla?


26 posted on 08/18/2007 7:24:34 AM PDT by Larry Lucido (Hunter 2008)
[ Post Reply | Private Reply | To 1 | View Replies]

To: armymarinemom
orginaztion's portal has been hacked

I used to do orginaztion portal repair. Never had much demand, though.

27 posted on 08/18/2007 7:27:53 AM PDT by Larry Lucido (Hunter 2008)
[ Post Reply | Private Reply | To 1 | View Replies]

To: armymarinemom
Joomla.org Hacked
28 posted on 08/18/2007 7:30:02 AM PDT by vbmoneyspender
[ Post Reply | Private Reply | To 22 | View Replies]

To: armymarinemom

From the article, it appears they got hacked twice. Once is wrong. Twice is just being mean.


29 posted on 08/18/2007 7:33:25 AM PDT by vbmoneyspender
[ Post Reply | Private Reply | To 22 | View Replies]

To: KoRn

I wouldn’t be too concerned. It’s only a learning opportunity. :)


30 posted on 08/18/2007 7:35:11 AM PDT by papasmurf (<<<<< Click there to see my dogs! Oh, and I have FRed one liners, too.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: vbmoneyspender
Twice is just being mean.

Ouch.

31 posted on 08/18/2007 7:42:12 AM PDT by armymarinemom (My sons freed Iraqi and Afghan Honor Roll students.)
[ Post Reply | Private Reply | To 29 | View Replies]

To: armymarinemom

I’ve had some sites hacked by the Turk group.

They overwrite the configuration.php file with their own version. Their version redirects to their own server.

I keep backup configuration.php files on hand so I can get the site back up in a few seconds.

Now I keep configuration.php unwriteable unless I work on the site from the backend. I also move configuration.php out of webroot .


32 posted on 08/18/2007 7:46:38 AM PDT by longjack
[ Post Reply | Private Reply | To 1 | View Replies]

To: longjack
Now I keep configuration.php unwriteable unless I work on the site from the backend. I also move configuration.php out of webroot .

I do keep a backup config file but it is a good idea to make it unwritable. Thanks.

33 posted on 08/18/2007 7:51:24 AM PDT by armymarinemom (My sons freed Iraqi and Afghan Honor Roll students.)
[ Post Reply | Private Reply | To 32 | View Replies]

To: armymarinemom

Army,

Depends on the hack. Of course this could be bad for the most recent build *or* an admin got lazy and did not properly secure his site. Could be a poor apache or mysql config. Then again it could be a poorly written stored procedure.

Look at the hack of the ubuntu site recently. They were running on unsupported hardware so they could not patch the kernel *and* they were running clear text ftp. Happens to windows, Linux, Solaris, and pretty much every app out os out there..


34 posted on 08/18/2007 8:16:36 AM PDT by N3WBI3 (Light travels faster than sound. This is why some people appear bright until you hear them speak....)
[ Post Reply | Private Reply | To 7 | View Replies]

To: armymarinemom

How was the hack accomplished?


35 posted on 08/18/2007 8:17:17 AM PDT by N3WBI3 (Light travels faster than sound. This is why some people appear bright until you hear them speak....)
[ Post Reply | Private Reply | To 8 | View Replies]

To: N3WBI3
How was the hack accomplished?

Not announced yet.

36 posted on 08/18/2007 8:19:14 AM PDT by armymarinemom (My sons freed Iraqi and Afghan Honor Roll students.)
[ Post Reply | Private Reply | To 35 | View Replies]

To: longjack

config PHP should *always* be unwritable! you practice good administrative practices. I have seen more than one occasion where someone chmods it so they can edit and never set the perms back. Somebody needs to buy the folks who run that site (this looks less like a Joomla problem than an Apache/PHP misconfig) some Apache administrator books..


37 posted on 08/18/2007 8:26:23 AM PDT by N3WBI3 (Light travels faster than sound. This is why some people appear bright until you hear them speak....)
[ Post Reply | Private Reply | To 32 | View Replies]

To: N3WBI3; ShadowAce; Tribune7; frogjerk; Salo; LTCJ; Calvinist_Dark_Lord; amigatec; Fractal Trader; ..

OSS Ping..

Welcome RhoTheta to the list..

If you want on the OSS ping list please ping or mail me..


38 posted on 08/18/2007 8:28:09 AM PDT by N3WBI3 (Light travels faster than sound. This is why some people appear bright until you hear them speak....)
[ Post Reply | Private Reply | To 23 | View Replies]

To: vbmoneyspender
From the article, it appears they got hacked twice. Once is wrong. Twice is just being mean carelessness.
39 posted on 08/18/2007 10:03:37 AM PDT by Publius6961 (MSM: Israelis are killed by rockets; Lebanese are killed by Israelis.)
[ Post Reply | Private Reply | To 29 | View Replies]

To: driftdiver
It runs on PHP which has some known security issues.

Should have stuck with the 'G' version, PGP. :^)

40 posted on 08/18/2007 10:57:37 AM PDT by Vinnie (You're Nobody 'Til Somebody Jihads You)
[ Post Reply | Private Reply | To 10 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-52 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson