![]() |
||
The Crucial Blog - Archive August 23, 2008
Joomla 1.5 Exploit Fix mod_security - Token Password Reset Exploit and SQL InjectionIf you are running sites running Joomla, and have not recently patched your installation you will probably have found your installation has been hacked one or more times. As a system adminsitrar you may find a number of sites on a server running Joomla 1.5 getting hacked. To prevent this at the firewall level, and help stop your Joomla installations being hacked implement the following mod_security 1.x rule on each server:
A permanent fix/solution for each Joomla installation is as follows: Upgrade to latest Joomla! version (1.5.6 or newer), or patch /components/com_user/models/reset.php with the code below: After global $mainframe; on line 113 of reset.php, add: Tags: joomla, security, server-administration Related posts(1) Comment Filed under: Uncategorized by — aaron @ 9:47 pm April 6, 2008
Removing Joomla Copyright/GNU/GPL BannerFollow these steps to remove the “Joomla is Free Software released under the GNU/GPL License” from your website: 1. Goto /includes/version.php 2. Comment the following line 3. If you edited the file locally on your computer, make sure you upload the file to your hosting account. Tags: fantastico, joomlaRelated posts(1) Comment Filed under: Uncategorized by — aaron @ 5:44 pm |
Tag Cloud
raid
XenServer
joomla
gentoo
ssh
virtual dedicated servers
hypervm
security
storage
ubuntu
control panels
virtualization
fedora
debian
mail
vds
microsoft
vmware
ruby-on-rails
cisco
php
cpanel
yum
firewall
centos5
networking
subversion
centos
windows 2008 server
apache
windows server
vps
windows
webmin
server-administration
servers
lxlabs
system administration
xen
lxadmin
fantastico
wordpress
exchange
linux
esxi
|
|
Quick Links: Debian Dedicated Servers, Direct Deposit Hosting, Unmetered Dedicated Servers, Virtual Dedicated Servers, Windows Server Management, High Traffic Web Hosting - Load Balanced Clusters, Windows 2008 Server Virtual Dedicated Servers
© Copyright 2003-2008
Crucial Paradigm
ABN 97 125 618 662