![]() |
||
The Crucial Blog - Archive August 23, 2008
Joomla 1.5 Exploit Fix mod_security – Token Password Reset Exploit and SQL InjectionIf you are running sites running Joomla, and have not recently patched your installation you will probably have found your installation has been hacked one or more times. As a system adminsitrar you may find a number of sites on a server running Joomla 1.5 getting hacked. To prevent this at the firewall level, and help stop your Joomla installations being hacked implement the following mod_security 1.x rule on each server:
A permanent fix/solution for each Joomla installation is as follows: Upgrade to latest Joomla! version (1.5.6 or newer), or patch /components/com_user/models/reset.php with the code below: After global $mainframe; on line 113 of reset.php, add: Tags: joomla, security, server-administration (1) Comment Filed under: Uncategorized by — aaron @ 9:47 pm April 6, 2008
Removing Joomla Copyright/GNU/GPL BannerFollow these steps to remove the “Joomla is Free Software released under the GNU/GPL License” from your website: 1. Goto /includes/version.php 2. Comment the following line 3. If you edited the file locally on your computer, make sure you upload the file to your hosting account. Tags: fantastico, joomla(1) Comment Filed under: Uncategorized by — aaron @ 5:44 pm |
Tag Cloud
ssh
ruby-on-rails
windows server
php
wordpress
XenServer
control panels
vmware
joomla
vds
esxi
subversion
apache
firewall
lxadmin
lxlabs
hypervm
virtual dedicated servers
system administration
networking
debian
mail
virtualization
centos
gentoo
fedora
exchange
cpanel
servers
cisco
windows 2008 server
centos5
webmin
yum
server-administration
fantastico
xen
security
ubuntu
linux
windows
microsoft
raid
storage
vps
|
|
Quick Links: Debian Dedicated Servers, Direct Deposit Hosting, Unmetered Dedicated Servers, Virtual Dedicated Servers, Windows Server Management, High Traffic Web Hosting - Load Balanced Clusters, Windows 2008 Server Virtual Dedicated Servers
© Copyright 2003-2008
Crucial Paradigm
ABN 97 125 618 662