Kunena 7.0.9 & Kunena 6.4.14 – Security Updates Released

The Kunena team has announce the arrival of Kunena 7.0.9 [K 7.0.9] in stable which is now available for download as a native Joomla extension for J! 5.4.x/6.0.x./6.1.x. This version addresses most of the issues that were discovered in K 6.2 / K 6.3 / K 6.4 and issues discovered during the last development stages of K 7.0

Question Hack Attempts

More
14 years 5 months ago - 14 years 5 months ago #123210 by Phoenix
Hack Attempts was created by Phoenix
Hello,

There has been a concerted attempt to hack my Kunena forum today (over 200 alerts related to my account) and at one point my provider actually disabled my site to make sure that everything was upgraded. I did update any addons that were a version behind (Joomla was already up to date with 1.5.26 and Kunena is 1.7.2). The only forum add-ons that needed upgrading was uddeim.

When I used the chat support and then changed the permissions back that he had changed to disable it, he suggested I post here to ask why this may be happening and why they are targeting the forum software.

Specifically he said that they were probably targeting any Joomla 1.5 site because it was about to expire (which wasn't completely clear to me because they are attacking the forum software not Joomla itself apparently) and to include the logs (see attachment) and in his words "I'd suggest contacting the developers of Kunena to see why it is flagging our security software with a "PHP REQUEST Exploit"."

So I'm doing that and hopefully this can help others who may be facing the same thing although I have no idea why they are trying to hack my site outside of just random choice or if there is a specific Kunena vulnerability that they are trying to exploit.

Phoenix

File Attachment:

File Name: hacked-themattr.txt
File Size:18.41 KB
Last edit: 14 years 5 months ago by Phoenix.

Please Log in or Create an account to join the conversation.

More
14 years 5 months ago - 14 years 5 months ago #123214 by sozzled
Replied by sozzled on topic Hack Attempts

Phoenix wrote: When I used the chat support ...

From where? There is no "chat support at www.kunena.org and therefore I don't know how this is a Kunena-related issue.

Phoenix wrote: Specifically he said that they were probably targeting any Joomla 1.5 site because it was about to expire

Again, who is "he" who is making this assertion? The conclusion that people are targetting J! 1.5 sites because they're "about to expire" is totally false and, in my opinion, is a complete nonsense statement. Who are these people making claims that these hack attempts are somehow in the domain of the Kunena community to address.

Phoenix wrote: ... contacting the developers of Kunena to see why it is flagging our security software with a 'PHP REQUEST Exploit'."

That's a very serious allegation and I would reject it without corroborative evidence. There is nothing in the attachment that you gave us that refers directly or indirectly to Kunena or supports the conclusions given to you in your "chat support".
Last edit: 14 years 5 months ago by sozzled.

Please Log in or Create an account to join the conversation.

More
14 years 5 months ago - 14 years 5 months ago #123216 by Phoenix
Replied by Phoenix on topic Hack Attempts
The chat support was with my hosting provider which is interactive online. Their support is by chat only so this is why the "chat" reference. "He" is the person who was replying to my questions (David Tanguay) and concerns.

One of his replies was as follows ...

According to the logs it seems they are exploiting Kunena. What version of Kunena are you using?

I'm not sure what version you are using but even with Kunena 1.7.1 it was patching a security vulnerability. See www.kunena.org/blog/19-developer-blog/88-kunena-171-released

Kunena 1.7.2 was only a maintenance release but I would suggest upgrading all outdated extensions.

The hackers are definitely able to exploit your site. Since you have re-enabled the site more alerts keep coming in every 1 minute.

Please let me know if you need any further assistance.


As I mentioned ... at the time of the attack (which apparently has died down now) Joomla 1.5.26 and Kunena 1.7.2 were up to date.

Phoenix
Last edit: 14 years 5 months ago by Phoenix.

Please Log in or Create an account to join the conversation.

More
14 years 5 months ago #123218 by Phoenix
Replied by Phoenix on topic Hack Attempts
Here is his message about targeting Joomla 1.5.26 because it was about to expire ...

They'll hack anyone's site just to get access to it. The reason they are targeting your site is because it uses a soon to be outdated version of Joomla 1.5.26 and was using outdated extensions. They then use it to spam, host phishing sites, attack other sites, etc. You should migrate from Joomla 1.5.26 to 2.5.4 since support for Joomla 1.5.26 ends Monday. You can use jUpgrade to migrate the site. Make sure you have a valid backup before you attempt any type of migration or upgrades.


Phoenix

Please Log in or Create an account to join the conversation.

More
14 years 5 months ago #123219 by sozzled
Replied by sozzled on topic Hack Attempts
The simple truth is that people try to crack into websites around the world for all kinds of reasons. Some people do it because it's a challenge while others try these tricks for competitive gain; other cracks are done as random acts of cyber vandalism and some attempts are part of a deliberate campaign of cyber terrorism. Some genres of websites are more prone to attacks than others (e.g. sites devoted to gaming or "anime" seem to be hit more often than, say, sites designed for people interested in scrapbooking or patchwork quilt-making) but there's no rhyme or reason in why people do what they do to achieve whatever it is they want to achieve.

I want you (and Mr Tanguay) to clearly understand that there is no known security vulnerability in K 1.7.2 that should compromise the integrity of a webhost. If a webhosting provider does not have adequate cyber-threat countermeasures employed, to detect and filter 'PHP REQUEST Exploit' attempts before they reach the sites that are hosted on their servers, I don't know what else we need to do.

I will, however, draw the attention of the Kunena development team to this one case that has been reported and they will respond as they see fit.

Please Log in or Create an account to join the conversation.

More
14 years 5 months ago - 14 years 5 months ago #123221 by sozzled
Replied by sozzled on topic Hack Attempts
In reply to the transcript you gave us from Mr Tanguay,

The reason they are targeting your site is because it uses a soon to be outdated version of Joomla 1.5.26 and was using outdated extensions

That is mere speculation on his part. J! 1.5 is about to be retired from active support by Joomla - which is true - this month. Major security fixes will continue to be offered for J! 1.5 until September this year. Migrating to J! 2.5 is not a guarantee that your site will be free from further attempts at hacking (just as if you chose to use Drupal or Dreamweaver or any other web-development framework) and people who make these kinds of "you must upgrade" claims are only guessing.

I agree, it's very good advice to maintain your site software to the latest revision level. Generally-speaking you will have fewer problems that way. Generally-speaking, that's what I aim for in my own work. As far as Kunena is concerned, K 1.7.2 is the only version currently supported by this community.

In the end it's your website and your choice what software you use and with whom you rely for hosting and support matters. As I wrote, I will refer this matter to the developers for their comments.
Last edit: 14 years 5 months ago by sozzled.

Please Log in or Create an account to join the conversation.

Time to create page: 0.133 seconds