Joomla 1.5x vulnerability : I was hacked
If you are using Joomla 1.5x (anything prior to release 1.56), then you are the next target for hackers. My joomla website (under development) was hacked into recently, and I lost everything that I have painfully developed. Nevertheless, this is a lesson to me that I should always check for vulnerabilities and to instantly patch it.
For those who are using Joomla, you can use the below method to check if your website is vulnerable to remote admin password change :-
STEP 1
Go to your URL and key in http:www.yourwebsite.com/index.php?option=com_user&view=reset&layout=confirm
(replace www.yourwebsite.com with your actual website)
STEP 2
Type the character ‘ in the box and press ok
STEP 3
Type in your new password
STEP 4
Try to login. If you can login with the new password, then you should rush to the below sites to get a quick fix.
NOTE: Please do not use the below to test on other people’s website, as hacking in any form is illegal and you can be legally prosecuted.
To get a fix :-
- http://developer.joomla.org/security/news/241-20080801-core-password-remind-functionality.html
To get more info :-
- http://securityreason.com/securityalert/4157






Leave a Reply