![]() |
||
The Crucial Blog - Archive August 23, 2008
Joomla 1.5 Exploit Fix mod_security – Token Password Reset Exploit and SQL InjectionIf you are running sites running Joomla, and have not recently patched your installation you will probably have found your installation has been hacked one or more times. As a system adminsitrar you may find a number of sites on a server running Joomla 1.5 getting hacked. To prevent this at the firewall level, and help stop your Joomla installations being hacked implement the following mod_security 1.x rule on each server:
A permanent fix/solution for each Joomla installation is as follows: Upgrade to latest Joomla! version (1.5.6 or newer), or patch /components/com_user/models/reset.php with the code below: After global $mainframe; on line 113 of reset.php, add: Tags: joomla, security, server-administration (1) Comment Filed under: Uncategorized by — aaron @ 9:47 pm |
Tag Cloud
networking
wordpress
system administration
yum
apache
vds
ruby-on-rails
server-administration
virtual dedicated servers
lxlabs
security
windows server
debian
webmin
exchange
subversion
ubuntu
xen
gentoo
vps
servers
linux
lxadmin
cpanel
centos5
windows 2008 server
firewall
mail
joomla
control panels
fantastico
fedora
centos
php
virtualization
storage
raid
microsoft
XenServer
esxi
hypervm
windows
cisco
vmware
ssh
|
|
Quick Links: Debian Dedicated Servers, Direct Deposit Hosting, Unmetered Dedicated Servers, Virtual Dedicated Servers, Windows Server Management, High Traffic Web Hosting - Load Balanced Clusters, Windows 2008 Server Virtual Dedicated Servers
© Copyright 2003-2008
Crucial Paradigm
ABN 97 125 618 662