Quick Stats
The Intellispire Software Installer is currently being run by 10147 people on 19842 websites - including this one!The Buzz
The URL install for the Updater Pro worked first time Nick - very quick and problem free. The range of addons available is very comprehensive, including the all-important one-click Joomla 1.5.x version upgrade. I particularly like the way each addon is marked whether it needs legacy mode or not, and the one-click button in the menu to turn that mode on or off for the whole site is just brilliant! The aWeber/GetResponse site optin included with Updater Pro is just what many Joomla addicts have been looking for - now we no longer need to 'wash' our old subscriber lists through either service to get accepted for double optin status - it's all one-shot automatic with this plugin. Bottom line - this is going on all my Joomla 1.5 sites and it gets my highest recommendation. Chris Noble |
Joomla! 1.5.6 Security Release |
|
The Joomla! core team has released version 1.5.6 of the Joomla! CMS. This is a security release, and it is a mandatory, immediate upgrade. The rest of this article focuses on the attack itself, what you can do to secure your site, and where to get help if you need it. While the Joomla! Updater is very close to being able to upgrade your Joomla! based websites to the latest version, that functionality is not quite ready for release. In the meantime, you need to perform a manual upgrade of your site. The ProblemThe attack centers around the ability for an anonymous web request to change the first user in the database password to one that the attacker knows - but you do not. That user, usually id #62, is typically the "admin" user with "Super Administration" capabilities - i.e. the sites superuser.   This change typically has two consequences:
  What To DoThe best defense against this attack is to upgrade your existing website to the latest Joomla! version (1.5.6 as of this writing). But if you can't do that - say, you are running JACL or some other program that "hacks" the Joomla! Core, or you simply don't have time at this moment* - there are a few other options. *Make time. There is a 4 line patch on you can find on the Joomla Security Blog. You can change the username of the first user, from "admin" to something else. This won't stop people from resetting your password and locking you out, but it may prevent them from getting "in". You can also insert into the database (as user #61, for example) a "dummy" user who is "blocked". Thus a password reset will have no effect. Personally, I'm implementing all three options on my site and the sites of my clients - upgrading the core, adding an additional "dummy" user, AND changing the "admin" username to something a little less obvious.   Help Is AvailableIf you've been locked out, need a site upgraded or secured, you can put in a single ticket and our professional staff will upgrade your site to 1.5.6 and implement the security fixes described, above. The fee is $39.95, and we're aiming for 4 hour (or less) response time over the next few days. Another source for help is Phil Taylor at Joomla-Expert.com (he charges about 50GPB per hour ... I think that's ~$100usd). One final WarningI have a lot of joomla! sites sitting around, and have "automatically" upgraded them. But that's not enough. If a "bad guy" has reset the admin password on a site you don't normally use, they could "already be in" before you upgraded ... so you need to log into ALL of your sites. If you can login, you are probably safe, but changing the password doesn't hurt. If you can't login, then that probably means a bad guy has been there before you, and you need to take appropriate action. These attacks are happening, today. I have clients who have been locked out, and even the Joomla.org site was defaced. This is not a matter to take lightly, nor one to put off. Drop everything and get your site secured right now. You can find out more from the Joomla! site.
Click Here to Have Intellispire Secure Your Site |
System Requirements
All Joomla! Software requires PHP 5.2 and Joomla 1.5. Software is unencoded (Zend / Ioncube NOT required). Windows servers are not officially supported. Hosting is available.
