Forum     

Go Back   Digit Technology Discussion Forum > Bandwidth Wastage > Chit-Chat
Register FAQ Calendar Mark Forums Read

Chit-Chat General discussions about anything that doesn't fit into the other sections to be had here

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 31-01-2009, 12:46 PM   #1 (permalink)
Wahahaha~!
 
Faun's Avatar
 
Join Date: Dec 2006
Location: Pune/there
Posts: 7,109
Default Joomla can be more friendly for hackers too !!!

For 1 week my net connection was down ! And today when I opened my blog (webofgoo.com), I found that the index page was altered by some hacker.


One thing is sure that same guy hacked into other users having Joomla installed. I too has version 1.5.8 but never used it (someone else did...lol). I didn't even installed any addons or posted any post in that, it was a vanilla install.

Now I have removed Joomla, Drupal is still running goog. He did change my wordpress blog's (t.webofgoo.com) current theme index page (I wonder why ? He could have simply place an index file in the main directory).

Rohan Shenoy aka Victo Rambo any words on it. Probably hacker used password vulnerability as I got this link in Joomla Forum:
http://forum.joomla.org/viewtopic.php?f=432&t=316567

PS: Thankfully I had a different password set for WHM and my email That saved some guys who share their website in my reseller account.
__________________
Steam/Flickr: psygeist
Spoiler:
Asus Z68 V-Pro|i5 2500k|TRUE Black|Ripjaws X+Corsair Vengeance|U2311H|N560GTX|D7000|XONAR STX|RE272|RE0|CC51|XE200PRO Walnut| TD II V2| Ultraphile|N5800

Mono
Faun is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 31-01-2009, 01:27 PM   #2 (permalink)
a.k.a VipER
 
Ecstasy's Avatar
 
Join Date: Dec 2008
Location: New Bombay
Posts: 604
Default Re: Joomla can be more friendly for hackers too !!!

Could it be one of the forum members?
__________________
Quote:
Originally Posted by shayanthebest View Post
I want to buy a new computer which can play 2-3 year old games at good resolutions. My budget is 5 to 6 lakhs. Please help
Ecstasy is offline  
Old 31-01-2009, 01:46 PM   #3 (permalink)
Wahahaha~!
 
Faun's Avatar
 
Join Date: Dec 2006
Location: Pune/there
Posts: 7,109
Default Re: Joomla can be more friendly for hackers too !!!

^^nope as this guy uses MS frontpage to make pages...lol. Probably he is from Arabian land.
__________________
Steam/Flickr: psygeist
Spoiler:
Asus Z68 V-Pro|i5 2500k|TRUE Black|Ripjaws X+Corsair Vengeance|U2311H|N560GTX|D7000|XONAR STX|RE272|RE0|CC51|XE200PRO Walnut| TD II V2| Ultraphile|N5800

Mono
Faun is offline  
Old 31-01-2009, 02:30 PM   #4 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,490
Default Re: Joomla can be more friendly for hackers too !!!

Quote:
Originally Posted by Ecstasy View Post
Could it be one of the forum members?
You mean rohan_shenoy?

hmmm...i can' t tell enough because I have not fiddled enough with jooma code!
BTW I have seen many joomla installations hacked in the past. I think NucleusCore's was also hacked!

And what did you say abt the WP theme? Can u plz explain it better? Cudnt get it!
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता

Last edited by victor_rambo; 31-01-2009 at 02:33 PM. Reason: Automerged Doublepost
victor_rambo is offline  
Old 31-01-2009, 03:25 PM   #5 (permalink)
a.k.a VipER
 
Ecstasy's Avatar
 
Join Date: Dec 2008
Location: New Bombay
Posts: 604
Default Re: Joomla can be more friendly for hackers too !!!

I used to hang out in one of the European gaming server forum and it was vBulletin and even that got hacked by the Turkish people. Whenever someone clicks on any thread or any section it redirects to some Turkish site. The reason why I'm saying is cause i think vBulletin is hard to hack as it doesn't have much vulnerability.
__________________
Quote:
Originally Posted by shayanthebest View Post
I want to buy a new computer which can play 2-3 year old games at good resolutions. My budget is 5 to 6 lakhs. Please help
Ecstasy is offline  
Old 31-01-2009, 05:14 PM   #6 (permalink)
AFK
 
thewisecrab's Avatar
 
Join Date: Oct 2006
Location: Bombay
Posts: 1,596
Default Re: Joomla can be more friendly for hackers too !!!

I was shocked on opening your site, T
Anyway, glad its been sorted
PS. My friend ditched Joomla because of the same reason about a year ago
__________________
Check out http://thefinal3rd.com, an Indian footie blog. Follow me on http://twitter.com/thewisecrab

Fishdumplings!! Duniya goal hai?
thewisecrab is offline  
Old 31-01-2009, 06:55 PM   #7 (permalink)
Wahahaha~!
 
Faun's Avatar
 
Join Date: Dec 2006
Location: Pune/there
Posts: 7,109
Default Re: Joomla can be more friendly for hackers too !!!

^^yeah, I wasn't using Joomla for website. I was just learning to use Joomla and Drupal apart from wordpress. Already started learning Drupal, loving it so far. It's just amazing at how much you can do with it. Ofcourse I won't be learning Joomla now, already removed it

Friggin BSNL put me out of the internet for one week.

I knew that NucleusKore's website was hacked and it was Joomla too.
__________________
Steam/Flickr: psygeist
Spoiler:
Asus Z68 V-Pro|i5 2500k|TRUE Black|Ripjaws X+Corsair Vengeance|U2311H|N560GTX|D7000|XONAR STX|RE272|RE0|CC51|XE200PRO Walnut| TD II V2| Ultraphile|N5800

Mono
Faun is offline  
Old 31-01-2009, 07:00 PM   #8 (permalink)
Sami Hyypiä, LFC legend
 
Liverpool_fan's Avatar
 
Join Date: Jun 2007
Location: Us desh mein jaha Mera Neta Chor Hai
Posts: 1,940
Default Re: Joomla can be more friendly for hackers too !!!

This is sad...
But at least you didn't lose anything precious...
Umm... I was considering Joomla, but now with this and considering its SEO is poor, I guess I should look at other CMSes...
__________________
Read before asking / messaging any moderator for any query: FAQ + answers for new members

Read all the sticky threads before asking any type of query. Most basic questions are answered in those.

Don't use forum for chatting. Visit http://webchat.freenode.net/?channels=krow, enter nick and connect.

"Luck has a peculiar habit of favoring those who don't depend on it."
Liverpool_fan is offline  
Old 31-01-2009, 07:00 PM   #9 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Default Re: Joomla can be more friendly for hackers too !!!

the latest secured version of Joomla is 1.5.9 if ur using a 1.5.x built...safest is to use J1.0.x

the exploit u r talking abt (that link to joomla forum) works only with Joomla 1.5.4 and below...it exploits forgot my password frm the frontend...it was patched up in the Joomla 1.5.5 release...

moreover, there are certain measures u need to take in order to secure ur site...no CMS is secure out-of-the-box...

Quote:
Originally Posted by Anurag_panda View Post
This is sad...
But at least you didn't lose anything precious...
Umm... I was considering Joomla, but now with this and considering its SEO is poor, I guess I should look at other CMSes...
no its SEO is not poor...its got one of the most customizable SEO features using certain extensions like sh404sef...
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome
www.TechFreakiez.com

Last edited by Abhishek Dwivedi; 31-01-2009 at 07:02 PM. Reason: Automerged Doublepost
Abhishek Dwivedi is offline  
Old 31-01-2009, 07:13 PM   #10 (permalink)
Wise Old Mouse
 
mrintech's Avatar
 
Join Date: Sep 2005
Location: India
Posts: 1,811
Default Re: Joomla can be more friendly for hackers too !!!

Now I got who is victor_rambo
mrintech is offline  
Old 31-01-2009, 07:24 PM   #11 (permalink)
Sami Hyypiä, LFC legend
 
Liverpool_fan's Avatar
 
Join Date: Jun 2007
Location: Us desh mein jaha Mera Neta Chor Hai
Posts: 1,940
Default Re: Joomla can be more friendly for hackers too !!!

Quote:
Originally Posted by Abhishek Dwivedi View Post
the latest secured version of Joomla is 1.5.9 if ur using a 1.5.x built...safest is to use J1.0.x

the exploit u r talking abt (that link to joomla forum) works only with Joomla 1.5.4 and below...it exploits forgot my password frm the frontend...it was patched up in the Joomla 1.5.5 release...

moreover, there are certain measures u need to take in order to secure ur site...no CMS is secure out-of-the-box...



no its SEO is not poor...its got one of the most customizable SEO features using certain extensions like sh404sef...
Thanks for the info.
__________________
Read before asking / messaging any moderator for any query: FAQ + answers for new members

Read all the sticky threads before asking any type of query. Most basic questions are answered in those.

Don't use forum for chatting. Visit http://webchat.freenode.net/?channels=krow, enter nick and connect.

"Luck has a peculiar habit of favoring those who don't depend on it."
Liverpool_fan is offline  
Old 31-01-2009, 07:38 PM   #12 (permalink)
TheSaint
 
NucleusKore's Avatar
 
Join Date: Jun 2004
Location: Antigua
Posts: 3,444
Default Re: Joomla can be more friendly for hackers too !!!

You should keep updating. Current is 1.5.9
I have subscribed to the security feed on Google reader. I check once a day and update as soon as the patch is released. That's the least I can do.

Also read this
http://forum.joomla.org/viewtopic.php?f=432&t=335090
__________________
http://www.neville.in
http://www.linuxrocks.in
"The Future Is Open"

Last edited by NucleusKore; 31-01-2009 at 07:42 PM. Reason: Automerged Doublepost
NucleusKore is offline  
Old 31-01-2009, 07:43 PM   #13 (permalink)
Wahahaha~!
 
Faun's Avatar
 
Join Date: Dec 2006
Location: Pune/there
Posts: 7,109
Default Re: Joomla can be more friendly for hackers too !!!

^^mine was 1.5.8, I was not running any site on it. It was just for learning...lol. Probably I should've installed it on a very cryptic subdomain instead of main domain.

Anyway, it was a good excuse for me to upgrade to wordpress 2.7 (though I lost a lot of customizations I did to my previous wordpress install and plugins). So far its running fine.
__________________
Steam/Flickr: psygeist
Spoiler:
Asus Z68 V-Pro|i5 2500k|TRUE Black|Ripjaws X+Corsair Vengeance|U2311H|N560GTX|D7000|XONAR STX|RE272|RE0|CC51|XE200PRO Walnut| TD II V2| Ultraphile|N5800

Mono
Faun is offline  
Old 31-01-2009, 10:33 PM   #14 (permalink)
TheSaint
 
NucleusKore's Avatar
 
Join Date: Jun 2004
Location: Antigua
Posts: 3,444
Default Re: Joomla can be more friendly for hackers too !!!

Ok
I have been hacked, so I've learnt the hard way, it pays to stay up-to-date.
__________________
http://www.neville.in
http://www.linuxrocks.in
"The Future Is Open"
NucleusKore is offline  
Old 31-01-2009, 10:39 PM   #15 (permalink)
Davislav Ivanuiz!!!
 
Kl@w-24's Avatar
 
Join Date: Apr 2004
Location: Pune
Posts: 1,392
Default Re: Joomla can be more friendly for hackers too !!!

Dearie me!! That certainly shows that when developers want you to upgrade to a newer version, you probably should (if it's free, that is).

I'll keep this incident in mind while setting up my site. Glad everything's alright now, though.
__________________
I was here when the forum's swear filter kept bleeping out the word 'FUNK'.

www.abhi247.com | The Photohblog
Kl@w-24 is offline  
Old 01-02-2009, 04:49 AM   #16 (permalink)
Be CoOl rAp RuLeZ !!!
 
krates's Avatar
 
Join Date: Feb 2007
Posts: 1,968
Default Re: Joomla can be more friendly for hackers too !!!

i think your DB must be there... reinstall joomla the old version only set it up again and then update it to the newer version if there is any.. change the pass and don't think much more

if your DB is not there ask your hosting provider that does they keep back up of sites ...
most of the hosting provider back up the sites every week .....

hope everything will be fine...
krates is offline  
Old 01-02-2009, 06:03 AM   #17 (permalink)
TheSaint
 
NucleusKore's Avatar
 
Join Date: Jun 2004
Location: Antigua
Posts: 3,444
Default Re: Joomla can be more friendly for hackers too !!!

^+1
I now use the lazybackup to backup the DB
http://extensions.joomla.org/extensions/4445/details
__________________
http://www.neville.in
http://www.linuxrocks.in
"The Future Is Open"
NucleusKore is offline  
Old 01-02-2009, 10:13 AM   #18 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Default Re: Joomla can be more friendly for hackers too !!!

or better use JoomlaPack extention...makes a backup of ur complete site with database and an autoinstaller of ur backup...no pain in a**
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Old 01-02-2009, 01:39 PM   #19 (permalink)
TheSaint
 
NucleusKore's Avatar
 
Join Date: Jun 2004
Location: Antigua
Posts: 3,444
Default Re: Joomla can be more friendly for hackers too !!!

^Thanks
__________________
http://www.neville.in
http://www.linuxrocks.in
"The Future Is Open"
NucleusKore is offline  
Old 01-02-2009, 05:02 PM   #20 (permalink)
Wahahaha~!
 
Faun's Avatar
 
Join Date: Dec 2006
Location: Pune/there
Posts: 7,109
Default Re: Joomla can be more friendly for hackers too !!!

I had the backup, but only bloody thing was that I was on a vacation for whole week so the things went a little worse.

Any way, security is a never ending thing. You must upgrade, watch, protect whats yours.

Btw I got the IP address from where the hack was done and the timing too

Its from Saudi Arabia, Riyadh There were three IP's, IMO dynamic IPs for a single PC.
__________________
Steam/Flickr: psygeist
Spoiler:
Asus Z68 V-Pro|i5 2500k|TRUE Black|Ripjaws X+Corsair Vengeance|U2311H|N560GTX|D7000|XONAR STX|RE272|RE0|CC51|XE200PRO Walnut| TD II V2| Ultraphile|N5800

Mono
Faun is offline  
Old 01-02-2009, 05:39 PM   #21 (permalink)
The Smaller Bang
 
MetalheadGautham's Avatar
 
Join Date: Sep 2007
Location: Gautham City
Posts: 7,431
Default Re: Joomla can be more friendly for hackers too !!!

WTH ?
I was thinking of learning Joomla. Think I need to stop now.
I just need to figure out how to use Wikidot.com and I am a FREE MAN.
__________________
http://TheSmallerBang.wordpress.com
eMachines E725 - T4400 2.2GHz, 1GB, 160GB
Nokia 5130XM * T-Sonic 610 2GB
Nokia 2323C * Samsung Galaxy Y
Apple iPad 2 16GB WiFi
MetalheadGautham is online now  
Old 02-02-2009, 12:09 AM   #22 (permalink)
Be CoOl rAp RuLeZ !!!
 
krates's Avatar
 
Join Date: Feb 2007
Posts: 1,968
Default Re: Joomla can be more friendly for hackers too !!!

Quote:
Originally Posted by MetalheadGautham View Post
WTH ?
I was thinking of learning Joomla. Think I need to stop now.
I just need to figure out how to use Wikidot.com and I am a FREE MAN.
c'mmon man you should learn using it ... it is the best CMS i have used till date... i think the bug should have been fixed by now for sure...
__________________
iPhone 3G 16GB + Samsung I450 + Sennheiser CXL 400 + PSP Phat + Samsung NC10

Previous phones: N73ME , W810I , Asus P320
krates is offline  
Old 02-02-2009, 03:53 PM   #23 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Default Re: Joomla can be more friendly for hackers too !!!

Quote:
Originally Posted by MetalheadGautham View Post
WTH ?
I was thinking of learning Joomla. Think I need to stop now.
I just need to figure out how to use Wikidot.com and I am a FREE MAN.
dude the exploit was in Joomla 1.5.4 n below...patches ages ago...lolz...its safe...moreover, there are 2 versions of joomla running at the same time..Joomla 1.5.x n Joomla 1.0.x....u shud learn
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Old 03-02-2009, 12:56 PM   #24 (permalink)
Right Off the Assembly Line
 
Join Date: Feb 2009
Location: Earth ( mostly.. )
Posts: 6
Default Re: Joomla can be more friendly for hackers too !!!

Joomla is great as long as you keep your version updated with them! Start a thread here - http://forum.joomla.org/ and send them a complain ticket
c0mrade is offline  
Old 03-02-2009, 01:14 PM   #25 (permalink)
bang bang!
 
Chirag's Avatar
 
Join Date: Feb 2005
Location: Vadodara
Posts: 1,158
Default Re: Joomla can be more friendly for hackers too !!!

Any cracker here? Need a little help. A good deed. Serious.
Chirag is offline  
Old 03-02-2009, 05:46 PM   #26 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,490
Default Re: Joomla can be more friendly for hackers too !!!

Quote:
Originally Posted by MetalheadGautham View Post
WTH ?
I was thinking of learning Joomla. Think I need to stop now.
I just need to figure out how to use Wikidot.com and I am a FREE MAN.
Typical average user.

C'mon...even Linux has bugs and security holes(which you will never know until someone publishes them).
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता
victor_rambo is offline  
Old 03-02-2009, 10:50 PM   #27 (permalink)
Right Off the Assembly Line
 
Join Date: Feb 2009
Location: Earth ( mostly.. )
Posts: 6
Default Re: Joomla can be more friendly for hackers too !!!

Quote:
Originally Posted by victor_rambo View Post
Typical average user.
Well you dared to point it out
c0mrade is offline  
Old 13-02-2009, 02:31 AM   #28 (permalink)
GaurishSharma.com
 
gary4gar's Avatar
 
Join Date: May 2005
Location: Jaipur
Posts: 4,097
Default Re: Joomla can be more friendly for hackers too !!!

Quote:
Originally Posted by T159 View Post

PS: Thankfully I had a different password set for WHM and my email That saved some guys who share their website in my reseller account.
Shesh that was close!, you could have taken me down as well,
Hum toh dubege Sanam, tumhe sath mein leker dubege
Now we seriously need to look into security aspect of websites.


Did you do a security audit of your site?
so that this never happens again

Also, please change all your passwords as a precaution
gary4gar is offline  
Old 13-02-2009, 02:38 AM   #29 (permalink)
Wahahaha~!
 
Faun's Avatar
 
Join Date: Dec 2006
Location: Pune/there
Posts: 7,109
Default Re: Joomla can be more friendly for hackers too !!!

^^As long as you data is backed up, you shouldn't worry.

I did a clean install of wordpress 2.7. So far have been updating it regularly.

Passwords was not cracked actually. But i have changed them to something deranged out of proportions.
__________________
Steam/Flickr: psygeist
Spoiler:
Asus Z68 V-Pro|i5 2500k|TRUE Black|Ripjaws X+Corsair Vengeance|U2311H|N560GTX|D7000|XONAR STX|RE272|RE0|CC51|XE200PRO Walnut| TD II V2| Ultraphile|N5800

Mono
Faun is offline  
Old 13-02-2009, 02:47 AM   #30 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,490
Default Re: Joomla can be more friendly for hackers too !!!

Quote:
Originally Posted by gary4gar View Post
Now we seriously need to look into security aspect of websites.
lol...u are over-reacting
But I now I hope you people get why security IS important. I have seen many people ignoring the security aspect as if it does not exists. Most people say "Hey it works and that is all I want"....and then they get many more unwanted things

Quote:
Did you do a security audit of your site?
Errr??? You really think T is SO RICH that he can afford to do it for the sake of few personal accounts.....dude, security audit is a BIG thing, and usually is undertaken at data-center level, not reseller or front-line level.

And with so many loosely coded scripts, its not even worth to have an security audit done! You see, one programmer's stupidity can beat the indigenious fool-proof algorithm of another
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता
victor_rambo is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
need help in installing joomla sganesh Software Q&A 4 19-11-2008 02:16 PM
Joomla NucleusKore Open Source 5 05-02-2008 10:17 PM
How easy is Joomla? goobimama QnA (read only) 4 13-12-2007 09:13 AM
Joomla Forum nagarjun_424 Internet & WWW 2 02-05-2006 12:22 PM
Joomla + SMF Maverick340 Open Source 3 16-03-2006 03:50 PM


All times are GMT +5.5. The time now is 07:17 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2