Security issue? Form open for hacking?

  • Petter
  • Topic Author
  • Offline
  • Senior Member
  • Senior Member
More
12 years 10 months ago - 12 years 10 months ago #28363 by Petter
I had some strange activity on my site yesterday; illegal e-mails to be more specific. :unsure:
Via cPanel I found that there is an invite-form accessible even if I have turned off everything related to invites in Event Booking:
Code:
http://SOMESITE.COM/component/eventbooking/?task=invite_form&id=3&tmpl=component

No hits when searching the forum for this.

I'm running version 1.5.3 on Joomla 1.5.9
Last edit: 12 years 10 months ago by Petter.

Please Log in or Create an account to join the conversation.

More
12 years 10 months ago - 12 years 10 months ago #28391 by FrankM
Replied by FrankM on topic Re: Security issue? Form open for hacking?
Last Joomla version is 1.5.26 I suggest to update your site.

Productiv: Joomla 3.5.1 / EB 2.4.3 / PHP 7.0.5
Testsys: Joomla 3.5.1 / EB 2.4.3 / PHP 7.0.5

Sorry, english isn't my native language.
Last edit: 12 years 10 months ago by FrankM.

Please Log in or Create an account to join the conversation.

  • Petter
  • Topic Author
  • Offline
  • Senior Member
  • Senior Member
More
12 years 10 months ago #28394 by Petter
Replied by Petter on topic Re: Security issue? Form open for hacking?
I do belive I wrote that I'm running Joomla 1.5.9 and Event Booking 1.5.3...

Please Log in or Create an account to join the conversation.

  • Tuan Pham Ngoc
  • Away
  • Administrator
  • Administrator
More
12 years 10 months ago #28421 by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Re: Security issue? Form open for hacking?
Hi Petter

Could you please submit a support ticket sending us administrator and FTP account of your site ? We will check and get it solved for you.

Regards,

Ossolution Team

Please Log in or Create an account to join the conversation.

  • Petter
  • Topic Author
  • Offline
  • Senior Member
  • Senior Member
More
12 years 10 months ago #28482 by Petter
Replied by Petter on topic Re: Security issue? Form open for hacking?
Hi Tuan,

I would prefer to have an explanation and a solution via the forum, if possible? This way others will benefit as well.

Rgds,

Petter

Please Log in or Create an account to join the conversation.

  • Tuan Pham Ngoc
  • Away
  • Administrator
  • Administrator
More
12 years 10 months ago #28510 by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Re: Security issue? Form open for hacking?
Hi Petter

Yes. We can discuss about this issue in this public forum, that's now problem :).

Basically, at the moment, when you choose to hide invite friend button, the system will only hide the button itself on the page so that users won't be able to see and access to invite function. It doesn't actual "hide" the code itself. So the solution is that we will need to edit the code alitle to redirect users to homepage if they try to access to that function bu accessing directly to the URL.

This is not really an urgent issue, so I will work on this weekend. Will that be OK for you ?

Tuan

Please Log in or Create an account to join the conversation.

  • Petter
  • Topic Author
  • Offline
  • Senior Member
  • Senior Member
More
12 years 10 months ago - 12 years 10 months ago #28557 by Petter
Replied by Petter on topic Re: Security issue? Form open for hacking?
Hi Tuan,

Sounds fine, how about adding Captcha to this form?

Petter

On a side-note; I posted another topic Wednesday this week that seems to have been deleted? Can it be restored or do I have to post again?
Code:
http://www.joomdonation.com/62-general-discussion/28401-remote-venue-20-entries-before-event-is-green.html#28401
Last edit: 12 years 10 months ago by Petter. Reason: added url to deleted post

Please Log in or Create an account to join the conversation.

  • Tuan Pham Ngoc
  • Away
  • Administrator
  • Administrator
More
12 years 10 months ago #28591 by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Re: Security issue? Form open for hacking?
Hi Petter

Adding captcha wil be good solution. But it will take me more time. For now, I think I won't add it, maybe in the next two weeks, pretty busy these days.

For your other topic, I am afraid of we could not recover it. Could you please re-post it? Our forum is spammed so much these days and we usually have to delete spam posts and that might be the reason the post was deleted. Really sorry

Tuan

Please Log in or Create an account to join the conversation.

Moderators: Tuan Pham Ngoc