Support Forum

  • Page:
  • 1

Joomla 3.03 hacked Privilege Escalation Vulnerability?

zentoolsIf you use Zentools please post a review at the Joomla! Extensions Directory.

I just got notified by hostgator that my site a 3.03 install was hacked (they suspected the Privilege Escalation Vulnerability, which they told me to refer to here, jeffchannell.com/Joomla/joomla-161725-privilege-escalation-vulnerability.html. (Fix is turning off Allow New Users to Register)

After reviewing that page it does not seem to be an issue for 3.03, so I am installing Admin Tools Pro.

Wondered if anyone else has had an issue like this, are there other fixes I might need to know about and is updating within version 3.x painless?

What about sitelock as a service, I just took on a medical security expert as a client for his business site, and having his site hacked would be a nightmare.
  • handsun's Avatar
  • handsun
  • 12 Month basic
  • 511 posts
  • Karma: 1
The administrator has disabled public write access.
There is also an exploit for uploading a file via a media manager I think that applies up to 3.1.5 and up to 2.5.14

It sounds like that is just as likely

All J3 sites at 3.03 should be upgraded as soon as possible

I'll ask the team for suggestions regarding extensions :)

Cheers
Paul
  • manh's Avatar
  • manh
  • Moderator
  • 45248 posts
  • 2106 Thanks
  • Karma: 603
The administrator has disabled public write access.
I have a blog post at beta using this video

vimeo.com/82268015

from siteground

Cheers
Paul
  • manh's Avatar
  • manh
  • Moderator
  • 45248 posts
  • 2106 Thanks
  • Karma: 603
The administrator has disabled public write access.
Thanks, I am updating the 3.03 site right away, are the 2.5 joomla bamboo templates compatible with 3.x, is it pretty painless to update them too?
  • handsun's Avatar
  • handsun
  • 12 Month basic
  • 511 posts
  • Karma: 1
The administrator has disabled public write access.
That would depend on the template

I'd suggest if you don't have a particular reason to upgrade to J3+, sticking with 2.5 as that is still the current long term release

2.5 is currently at 2.5.17

Cheers
Paul
  • manh's Avatar
  • manh
  • Moderator
  • 45248 posts
  • 2106 Thanks
  • Karma: 603
Last Edit: 10 years 3 months ago by manh.
The administrator has disabled public write access.
The vidoe does contain suggestions extension and good practice wise

Together with questions to ask your host

Cheers
Paul
  • manh's Avatar
  • manh
  • Moderator
  • 45248 posts
  • 2106 Thanks
  • Karma: 603
The administrator has disabled public write access.

zentoolsIf you use Zentools please post a review at the Joomla! Extensions Directory.

Happy Campers