<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Mambo and Joomla exposed as script kiddies have their summer holidays</title>
	<atom:link href="http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/</link>
	<description>My personal piece of cyberspace</description>
	<lastBuildDate>Wed, 25 Jan 2012 20:21:14 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: tj</title>
		<link>http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-9896</link>
		<dc:creator>tj</dc:creator>
		<pubDate>Fri, 11 Jan 2008 08:47:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-9896</guid>
		<description>Remember that gaining access to configuration.php is just one way you can do harm here. There are lots of other things that can happen, including as you say e-mail spammers, so I don&#039;t think ioncube should make you sleep better. Anything can be cracked, even ioncube. A quick google search found this for instance: http://blog.php-security.org/archives/14-PHP-Encoders-Protection-where-are-you.html</description>
		<content:encoded><![CDATA[<p>Remember that gaining access to configuration.php is just one way you can do harm here. There are lots of other things that can happen, including as you say e-mail spammers, so I don&#8217;t think ioncube should make you sleep better. Anything can be cracked, even ioncube. A quick google search found this for instance: <a href="http://blog.php-security.org/archives/14-PHP-Encoders-Protection-where-are-you.html" rel="nofollow">http://blog.php-security.org/archives/14-PHP-Encoders-Protection-where-are-you.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tj</title>
		<link>http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-19715</link>
		<dc:creator>tj</dc:creator>
		<pubDate>Fri, 11 Jan 2008 08:47:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-19715</guid>
		<description>Remember that gaining access to configuration.php is just one way you can do harm here. There are lots of other things that can happen, including as you say e-mail spammers, so I don&#039;t think ioncube should make you sleep better. Anything can be cracked, even ioncube. A quick google search found this for instance: http://blog.php-security.org/archives/14-PHP-Encoders-Protection-where-are-you.html</description>
		<content:encoded><![CDATA[<p>Remember that gaining access to configuration.php is just one way you can do harm here. There are lots of other things that can happen, including as you say e-mail spammers, so I don&#8217;t think ioncube should make you sleep better. Anything can be cracked, even ioncube. A quick google search found this for instance: <a href="http://blog.php-security.org/archives/14-PHP-Encoders-Protection-where-are-you.html" rel="nofollow">http://blog.php-security.org/archives/14-PHP-Encoders-Protection-where-are-you.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian Wright</title>
		<link>http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-9895</link>
		<dc:creator>Ian Wright</dc:creator>
		<pubDate>Fri, 11 Jan 2008 05:16:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-9895</guid>
		<description>I am using Joomla 1.0.13, virtue mart 1.0.13a and have almost no other extensions added to my site, but still i have had my site hacked into. They hacked in sometime in October according to the file dates, and left a small  directory called com_uk in the public_html/components directory.

It was a file manager script, allowing anybody to visit that page and have all the info about my site, no idea how they gained access, as all the permissions were correct etc.

I have now found that 4 of my sites were email spammers, and also had open access. I then found a small text file in another directory that had links to other sites with the file manager, 2 of them were mine on my other servers.

It is getting to the stage where I&#039;m seriously wondering if using Joomla is the best idea as a commercial sense. I have never minded paying for scripts, as i sell them at the end of the day. So i have already started looking for commercial components.

Do you think encrypting the configuration.php file in ioncube would help, or can ioncube be cracked?

All the best
Ian</description>
		<content:encoded><![CDATA[<p>I am using Joomla 1.0.13, virtue mart 1.0.13a and have almost no other extensions added to my site, but still i have had my site hacked into. They hacked in sometime in October according to the file dates, and left a small  directory called com_uk in the public_html/components directory.</p>
<p>It was a file manager script, allowing anybody to visit that page and have all the info about my site, no idea how they gained access, as all the permissions were correct etc.</p>
<p>I have now found that 4 of my sites were email spammers, and also had open access. I then found a small text file in another directory that had links to other sites with the file manager, 2 of them were mine on my other servers.</p>
<p>It is getting to the stage where I&#8217;m seriously wondering if using Joomla is the best idea as a commercial sense. I have never minded paying for scripts, as i sell them at the end of the day. So i have already started looking for commercial components.</p>
<p>Do you think encrypting the configuration.php file in ioncube would help, or can ioncube be cracked?</p>
<p>All the best<br />
Ian</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian Wright</title>
		<link>http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-19714</link>
		<dc:creator>Ian Wright</dc:creator>
		<pubDate>Fri, 11 Jan 2008 05:16:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-19714</guid>
		<description>I am using Joomla 1.0.13, virtue mart 1.0.13a and have almost no other extensions added to my site, but still i have had my site hacked into. They hacked in sometime in October according to the file dates, and left a small  directory called com_uk in the public_html/components directory.

It was a file manager script, allowing anybody to visit that page and have all the info about my site, no idea how they gained access, as all the permissions were correct etc.

I have now found that 4 of my sites were email spammers, and also had open access. I then found a small text file in another directory that had links to other sites with the file manager, 2 of them were mine on my other servers.

It is getting to the stage where I&#039;m seriously wondering if using Joomla is the best idea as a commercial sense. I have never minded paying for scripts, as i sell them at the end of the day. So i have already started looking for commercial components.

Do you think encrypting the configuration.php file in ioncube would help, or can ioncube be cracked?

All the best
Ian</description>
		<content:encoded><![CDATA[<p>I am using Joomla 1.0.13, virtue mart 1.0.13a and have almost no other extensions added to my site, but still i have had my site hacked into. They hacked in sometime in October according to the file dates, and left a small  directory called com_uk in the public_html/components directory.</p>
<p>It was a file manager script, allowing anybody to visit that page and have all the info about my site, no idea how they gained access, as all the permissions were correct etc.</p>
<p>I have now found that 4 of my sites were email spammers, and also had open access. I then found a small text file in another directory that had links to other sites with the file manager, 2 of them were mine on my other servers.</p>
<p>It is getting to the stage where I&#8217;m seriously wondering if using Joomla is the best idea as a commercial sense. I have never minded paying for scripts, as i sell them at the end of the day. So i have already started looking for commercial components.</p>
<p>Do you think encrypting the configuration.php file in ioncube would help, or can ioncube be cracked?</p>
<p>All the best<br />
Ian</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: abby lim</title>
		<link>http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-9832</link>
		<dc:creator>abby lim</dc:creator>
		<pubDate>Sat, 22 Dec 2007 15:28:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-9832</guid>
		<description>i&#039;d like to add com_poll component in joomla 1.5
recently been bugged by an irc -- eggdrop
hackers attempting to use our server to use it as irc</description>
		<content:encoded><![CDATA[<p>i&#8217;d like to add com_poll component in joomla 1.5<br />
recently been bugged by an irc &#8212; eggdrop<br />
hackers attempting to use our server to use it as irc</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: abby lim</title>
		<link>http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-19713</link>
		<dc:creator>abby lim</dc:creator>
		<pubDate>Sat, 22 Dec 2007 15:28:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-19713</guid>
		<description>i&#039;d like to add com_poll component in joomla 1.5
recently been bugged by an irc -- eggdrop
hackers attempting to use our server to use it as irc</description>
		<content:encoded><![CDATA[<p>i&#8217;d like to add com_poll component in joomla 1.5<br />
recently been bugged by an irc &#8212; eggdrop<br />
hackers attempting to use our server to use it as irc</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tj</title>
		<link>http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-7594</link>
		<dc:creator>tj</dc:creator>
		<pubDate>Thu, 12 Jul 2007 09:10:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-7594</guid>
		<description>Script kiddies do not need administration access to upload and hide folders, so you should not assume that they have admin access, but that is besides the point at this time.

Hackers could just as easily have gotten in through another application or even another website if you are using a shared hosting service. The only way to find that out is to go through the webserver logs, which your hosting co. should do.

What you need to do, regardless of what your hosting company does, is:

a) Secure your data. 
You probably do not want to lose your data that you have worked alot to accumulate. So make backups of your database and the files you might have uploaded or modified. Typical folders you would want to backup is your images folder and your templates folder. Joomla core files are not important, unless you have made modifications to them.

You might end up backing up some data that the hackers have put there, so after you have made the backup you should go through the data to ensure that it is in fact your data.

b) Go through your installed components, mambots and modules.
Compare their version numbers with the ones you find on the extension websites, for instance on extensions.joomla.org. Download the most recent versions of the stuff you have installed. Using old extensions that might have known security holes is a big security risk.

c) Consider switching hosting companies
If your hosting company is unable to stop what ever is happening to the server you should reconsider using their service, and you should at least demand to be moved to another server that is not compromised. If the hosting company will not set up a new account for you, you should consider switching host.

Do a fresh Joomla install, using the latest Joomla version available in the 1.0 series (1.0.12 at this time). Also: Install new versions of the components you had on your old site, if new versions are available. 

Alot of other security tips and measures plus help and assistance can be found in the &lt;a href=&quot;http://forum.joomla.org/index.php?board=267.0&quot; rel=&quot;nofollow&quot;&gt;Joomla security forums&lt;/a&gt;.

Hope this helps!

- Torkil</description>
		<content:encoded><![CDATA[<p>Script kiddies do not need administration access to upload and hide folders, so you should not assume that they have admin access, but that is besides the point at this time.</p>
<p>Hackers could just as easily have gotten in through another application or even another website if you are using a shared hosting service. The only way to find that out is to go through the webserver logs, which your hosting co. should do.</p>
<p>What you need to do, regardless of what your hosting company does, is:</p>
<p>a) Secure your data.<br />
You probably do not want to lose your data that you have worked alot to accumulate. So make backups of your database and the files you might have uploaded or modified. Typical folders you would want to backup is your images folder and your templates folder. Joomla core files are not important, unless you have made modifications to them.</p>
<p>You might end up backing up some data that the hackers have put there, so after you have made the backup you should go through the data to ensure that it is in fact your data.</p>
<p>b) Go through your installed components, mambots and modules.<br />
Compare their version numbers with the ones you find on the extension websites, for instance on extensions.joomla.org. Download the most recent versions of the stuff you have installed. Using old extensions that might have known security holes is a big security risk.</p>
<p>c) Consider switching hosting companies<br />
If your hosting company is unable to stop what ever is happening to the server you should reconsider using their service, and you should at least demand to be moved to another server that is not compromised. If the hosting company will not set up a new account for you, you should consider switching host.</p>
<p>Do a fresh Joomla install, using the latest Joomla version available in the 1.0 series (1.0.12 at this time). Also: Install new versions of the components you had on your old site, if new versions are available. </p>
<p>Alot of other security tips and measures plus help and assistance can be found in the <a href="http://forum.joomla.org/index.php?board=267.0" rel="nofollow">Joomla security forums</a>.</p>
<p>Hope this helps!</p>
<p>- Torkil</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tj</title>
		<link>http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-19712</link>
		<dc:creator>tj</dc:creator>
		<pubDate>Thu, 12 Jul 2007 09:10:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-19712</guid>
		<description>Script kiddies do not need administration access to upload and hide folders, so you should not assume that they have admin access, but that is besides the point at this time.

Hackers could just as easily have gotten in through another application or even another website if you are using a shared hosting service. The only way to find that out is to go through the webserver logs, which your hosting co. should do.

What you need to do, regardless of what your hosting company does, is:

a) Secure your data. 
You probably do not want to lose your data that you have worked alot to accumulate. So make backups of your database and the files you might have uploaded or modified. Typical folders you would want to backup is your images folder and your templates folder. Joomla core files are not important, unless you have made modifications to them.

You might end up backing up some data that the hackers have put there, so after you have made the backup you should go through the data to ensure that it is in fact your data.

b) Go through your installed components, mambots and modules.
Compare their version numbers with the ones you find on the extension websites, for instance on extensions.joomla.org. Download the most recent versions of the stuff you have installed. Using old extensions that might have known security holes is a big security risk.

c) Consider switching hosting companies
If your hosting company is unable to stop what ever is happening to the server you should reconsider using their service, and you should at least demand to be moved to another server that is not compromised. If the hosting company will not set up a new account for you, you should consider switching host.

Do a fresh Joomla install, using the latest Joomla version available in the 1.0 series (1.0.12 at this time). Also: Install new versions of the components you had on your old site, if new versions are available. 

Alot of other security tips and measures plus help and assistance can be found in the &lt;a href=&quot;http://forum.joomla.org/index.php?board=267.0&quot; rel=&quot;nofollow&quot;&gt;Joomla security forums&lt;/a&gt;.

Hope this helps!

- Torkil</description>
		<content:encoded><![CDATA[<p>Script kiddies do not need administration access to upload and hide folders, so you should not assume that they have admin access, but that is besides the point at this time.</p>
<p>Hackers could just as easily have gotten in through another application or even another website if you are using a shared hosting service. The only way to find that out is to go through the webserver logs, which your hosting co. should do.</p>
<p>What you need to do, regardless of what your hosting company does, is:</p>
<p>a) Secure your data.<br />
You probably do not want to lose your data that you have worked alot to accumulate. So make backups of your database and the files you might have uploaded or modified. Typical folders you would want to backup is your images folder and your templates folder. Joomla core files are not important, unless you have made modifications to them.</p>
<p>You might end up backing up some data that the hackers have put there, so after you have made the backup you should go through the data to ensure that it is in fact your data.</p>
<p>b) Go through your installed components, mambots and modules.<br />
Compare their version numbers with the ones you find on the extension websites, for instance on extensions.joomla.org. Download the most recent versions of the stuff you have installed. Using old extensions that might have known security holes is a big security risk.</p>
<p>c) Consider switching hosting companies<br />
If your hosting company is unable to stop what ever is happening to the server you should reconsider using their service, and you should at least demand to be moved to another server that is not compromised. If the hosting company will not set up a new account for you, you should consider switching host.</p>
<p>Do a fresh Joomla install, using the latest Joomla version available in the 1.0 series (1.0.12 at this time). Also: Install new versions of the components you had on your old site, if new versions are available. </p>
<p>Alot of other security tips and measures plus help and assistance can be found in the <a href="http://forum.joomla.org/index.php?board=267.0" rel="nofollow">Joomla security forums</a>.</p>
<p>Hope this helps!</p>
<p>- Torkil</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Freddy Egersdorfer</title>
		<link>http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-7578</link>
		<dc:creator>Freddy Egersdorfer</dc:creator>
		<pubDate>Wed, 11 Jul 2007 15:17:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-7578</guid>
		<description>It seems someone has found a way to get into my administration. So far they are uploading huge amounts of content into my hosting server and I find that they hide the folders, sometimes as so that my hosting co. can not find them.

Please help as I do not know how to upgrade properly, really scared about losing all my content. I&#039;m so far using 1.0.10.</description>
		<content:encoded><![CDATA[<p>It seems someone has found a way to get into my administration. So far they are uploading huge amounts of content into my hosting server and I find that they hide the folders, sometimes as so that my hosting co. can not find them.</p>
<p>Please help as I do not know how to upgrade properly, really scared about losing all my content. I&#8217;m so far using 1.0.10.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Freddy Egersdorfer</title>
		<link>http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-19711</link>
		<dc:creator>Freddy Egersdorfer</dc:creator>
		<pubDate>Wed, 11 Jul 2007 15:17:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.torkiljohnsen.com/2006/07/19/mambo-and-joomla-exposed-as-script-kiddies-have-their-summer-holidays/#comment-19711</guid>
		<description>It seems someone has found a way to get into my administration. So far they are uploading huge amounts of content into my hosting server and I find that they hide the folders, sometimes as so that my hosting co. can not find them.

Please help as I do not know how to upgrade properly, really scared about losing all my content. I&#039;m so far using 1.0.10.</description>
		<content:encoded><![CDATA[<p>It seems someone has found a way to get into my administration. So far they are uploading huge amounts of content into my hosting server and I find that they hide the folders, sometimes as so that my hosting co. can not find them.</p>
<p>Please help as I do not know how to upgrade properly, really scared about losing all my content. I&#8217;m so far using 1.0.10.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.331 seconds -->

