| Forum |
|
|||||||
| Chit-Chat General discussions about anything that doesn't fit into the other sections to be had here |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#1 (permalink) |
|
Wahahaha~!
Join Date: Dec 2006
Location: Pune/there
Posts: 7,109
|
![]() One thing is sure that same guy hacked into other users having Joomla installed. I too has version 1.5.8 but never used it (someone else did...lol). I didn't even installed any addons or posted any post in that, it was a vanilla install. Now I have removed Joomla, Drupal is still running goog. He did change my wordpress blog's (t.webofgoo.com) current theme index page (I wonder why ? He could have simply place an index file in the main directory). Rohan Shenoy aka Victo Rambo any words on it. Probably hacker used password vulnerability as I got this link in Joomla Forum: http://forum.joomla.org/viewtopic.php?f=432&t=316567 PS: Thankfully I had a different password set for WHM and my email |
|
|
| Advertisements. Register and be a member of the community to get rid of them. | |
|
Advertisement
|
|
|
|
#4 (permalink) |
|
हॉर्न ओके प्लीज़
Join Date: Sep 2007
Posts: 1,490
|
You mean rohan_shenoy?
hmmm...i can' t tell enough because I have not fiddled enough with jooma code! BTW I have seen many joomla installations hacked in the past. I think NucleusCore's was also hacked! And what did you say abt the WP theme? Can u plz explain it better? Cudnt get it!
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति गीक होना माँगता Last edited by victor_rambo; 31-01-2009 at 02:33 PM. Reason: Automerged Doublepost |
|
|
|
|
#5 (permalink) |
|
a.k.a VipER
Join Date: Dec 2008
Location: New Bombay
Posts: 604
|
I used to hang out in one of the European gaming server forum and it was vBulletin and even that got hacked by the Turkish people. Whenever someone clicks on any thread or any section it redirects to some Turkish site. The reason why I'm saying is cause i think vBulletin is hard to hack as it doesn't have much vulnerability.
|
|
|
|
|
#6 (permalink) |
|
AFK
Join Date: Oct 2006
Location: Bombay
Posts: 1,596
|
I was shocked on opening your site, T
Anyway, glad its been sorted PS. My friend ditched Joomla because of the same reason about a year ago
__________________
Check out http://thefinal3rd.com, an Indian footie blog. Follow me on http://twitter.com/thewisecrab Fishdumplings!! Duniya goal hai? |
|
|
|
|
#7 (permalink) |
|
Wahahaha~!
Join Date: Dec 2006
Location: Pune/there
Posts: 7,109
|
^^yeah, I wasn't using Joomla for website. I was just learning to use Joomla and Drupal apart from wordpress. Already started learning Drupal, loving it so far. It's just amazing at how much you can do with it. Ofcourse I won't be learning Joomla now, already removed it
Friggin BSNL put me out of the internet for one week. I knew that NucleusKore's website was hacked and it was Joomla too. |
|
|
|
|
#8 (permalink) |
|
Sami Hyypiä, LFC legend
Join Date: Jun 2007
Location: Us desh mein jaha Mera Neta Chor Hai
Posts: 1,940
|
This is sad...
But at least you didn't lose anything precious... Umm... I was considering Joomla, but now with this and considering its SEO is poor, I guess I should look at other CMSes...
__________________
Read before asking / messaging any moderator for any query: FAQ + answers for new members Read all the sticky threads before asking any type of query. Most basic questions are answered in those. Don't use forum for chatting. Visit http://webchat.freenode.net/?channels=krow, enter nick and connect. "Luck has a peculiar habit of favoring those who don't depend on it." |
|
|
|
|
#9 (permalink) |
|
TechFreakiez.com
Join Date: Sep 2006
Location: New Delhi
Posts: 621
|
the latest secured version of Joomla is 1.5.9 if ur using a 1.5.x built...safest is to use J1.0.x
the exploit u r talking abt (that link to joomla forum) works only with Joomla 1.5.4 and below...it exploits forgot my password frm the frontend...it was patched up in the Joomla 1.5.5 release... moreover, there are certain measures u need to take in order to secure ur site...no CMS is secure out-of-the-box... no its SEO is not poor...its got one of the most customizable SEO features using certain extensions like sh404sef...
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome www.TechFreakiez.com Last edited by Abhishek Dwivedi; 31-01-2009 at 07:02 PM. Reason: Automerged Doublepost |
|
|
|
|
#11 (permalink) | |
|
Sami Hyypiä, LFC legend
Join Date: Jun 2007
Location: Us desh mein jaha Mera Neta Chor Hai
Posts: 1,940
|
Quote:
__________________
Read before asking / messaging any moderator for any query: FAQ + answers for new members Read all the sticky threads before asking any type of query. Most basic questions are answered in those. Don't use forum for chatting. Visit http://webchat.freenode.net/?channels=krow, enter nick and connect. "Luck has a peculiar habit of favoring those who don't depend on it." |
|
|
|
|
|
#12 (permalink) |
|
TheSaint
Join Date: Jun 2004
Location: Antigua
Posts: 3,444
|
You should keep updating. Current is 1.5.9
I have subscribed to the security feed on Google reader. I check once a day and update as soon as the patch is released. That's the least I can do. Also read this http://forum.joomla.org/viewtopic.php?f=432&t=335090
__________________
http://www.neville.in http://www.linuxrocks.in "The Future Is Open" Last edited by NucleusKore; 31-01-2009 at 07:42 PM. Reason: Automerged Doublepost |
|
|
|
|
#13 (permalink) |
|
Wahahaha~!
Join Date: Dec 2006
Location: Pune/there
Posts: 7,109
|
^^mine was 1.5.8, I was not running any site on it. It was just for learning...lol. Probably I should've installed it on a very cryptic subdomain instead of main domain.
Anyway, it was a good excuse for me to upgrade to wordpress 2.7 (though I lost a lot of customizations I did to my previous wordpress install and plugins). So far its running fine. |
|
|
|
|
#14 (permalink) |
|
TheSaint
Join Date: Jun 2004
Location: Antigua
Posts: 3,444
|
Ok
I have been hacked, so I've learnt the hard way, it pays to stay up-to-date.
__________________
http://www.neville.in http://www.linuxrocks.in "The Future Is Open" |
|
|
|
|
#15 (permalink) |
|
Davislav Ivanuiz!!!
Join Date: Apr 2004
Location: Pune
Posts: 1,392
|
Dearie me!! That certainly shows that when developers want you to upgrade to a newer version, you probably should (if it's free, that is).
I'll keep this incident in mind while setting up my site. Glad everything's alright now, though.
__________________
I was here when the forum's swear filter kept bleeping out the word 'FUNK'. ![]() ![]() ![]() www.abhi247.com | The Photohblog |
|
|
|
|
#16 (permalink) |
|
Be CoOl rAp RuLeZ !!!
Join Date: Feb 2007
Posts: 1,968
|
i think your DB must be there... reinstall joomla the old version only set it up again and then update it to the newer version if there is any.. change the pass and don't think much more
![]() if your DB is not there ask your hosting provider that does they keep back up of sites ... most of the hosting provider back up the sites every week ..... hope everything will be fine... |
|
|
|
|
#18 (permalink) |
|
TechFreakiez.com
Join Date: Sep 2006
Location: New Delhi
Posts: 621
|
or better use JoomlaPack extention...makes a backup of ur complete site with database and an autoinstaller of ur backup...no pain in a**
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome www.TechFreakiez.com |
|
|
|
|
#20 (permalink) |
|
Wahahaha~!
Join Date: Dec 2006
Location: Pune/there
Posts: 7,109
|
I had the backup, but only bloody thing was that I was on a vacation for whole week so the things went a little worse.
Any way, security is a never ending thing. You must upgrade, watch, protect whats yours. Btw I got the IP address from where the hack was done and the timing too Its from Saudi Arabia, Riyadh |
|
|
|
|
#21 (permalink) |
|
The Smaller Bang
Join Date: Sep 2007
Location: Gautham City
Posts: 7,431
|
WTH ?
I was thinking of learning Joomla. Think I need to stop now. I just need to figure out how to use Wikidot.com and I am a FREE MAN.
__________________
http://TheSmallerBang.wordpress.com eMachines E725 - T4400 2.2GHz, 1GB, 160GB Nokia 5130XM * T-Sonic 610 2GB Nokia 2323C * Samsung Galaxy Y Apple iPad 2 16GB WiFi |
|
|
|
|
#22 (permalink) |
|
Be CoOl rAp RuLeZ !!!
Join Date: Feb 2007
Posts: 1,968
|
c'mmon man you should learn using it ... it is the best CMS i have used till date... i think the bug should have been fixed by now for sure...
__________________
iPhone 3G 16GB + Samsung I450 + Sennheiser CXL 400 + PSP Phat + Samsung NC10 Previous phones: N73ME , W810I , Asus P320 |
|
|
|
|
#23 (permalink) | |
|
TechFreakiez.com
Join Date: Sep 2006
Location: New Delhi
Posts: 621
|
Quote:
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome www.TechFreakiez.com |
|
|
|
|
|
#24 (permalink) |
|
Right Off the Assembly Line
Join Date: Feb 2009
Location: Earth ( mostly.. )
Posts: 6
|
Joomla is great as long as you keep your version updated with them! Start a thread here - http://forum.joomla.org/ and send them a complain ticket
|
|
|
|
|
#26 (permalink) | |
|
हॉर्न ओके प्लीज़
Join Date: Sep 2007
Posts: 1,490
|
Quote:
C'mon...even Linux has bugs and security holes(which you will never know until someone publishes them).
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति गीक होना माँगता |
|
|
|
|
|
#28 (permalink) | |
|
GaurishSharma.com
Join Date: May 2005
Location: Jaipur
Posts: 4,097
|
Quote:
Hum toh dubege Sanam, tumhe sath mein leker dubege Now we seriously need to look into security aspect of websites. Did you do a security audit of your site? so that this never happens again Also, please change all your passwords as a precaution |
|
|
|
|
|
#29 (permalink) |
|
Wahahaha~!
Join Date: Dec 2006
Location: Pune/there
Posts: 7,109
|
^^As long as you data is backed up, you shouldn't worry.
I did a clean install of wordpress 2.7. So far have been updating it regularly. Passwords was not cracked actually. But i have changed them to something deranged out of proportions. |
|
|
|
|
#30 (permalink) | ||
|
हॉर्न ओके प्लीज़
Join Date: Sep 2007
Posts: 1,490
|
Quote:
But I now I hope you people get why security IS important. I have seen many people ignoring the security aspect as if it does not exists. Most people say "Hey it works and that is all I want"....and then they get many more unwanted things Quote:
And with so many loosely coded scripts, its not even worth to have an security audit done! You see, one programmer's stupidity can beat the indigenious fool-proof algorithm of another
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति गीक होना माँगता |
||
|
|
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| need help in installing joomla | sganesh | Software Q&A | 4 | 19-11-2008 02:16 PM |
| Joomla | NucleusKore | Open Source | 5 | 05-02-2008 10:17 PM |
| How easy is Joomla? | goobimama | QnA (read only) | 4 | 13-12-2007 09:13 AM |
| Joomla Forum | nagarjun_424 | Internet & WWW | 2 | 02-05-2006 12:22 PM |
| Joomla + SMF | Maverick340 | Open Source | 3 | 16-03-2006 03:50 PM |