- Posts: 67
- Thank you received: 1
Kunena 7.0.9 & Kunena 6.4.14 – Security Updates Released
The Kunena team has announce the arrival of Kunena 7.0.9 [K 7.0.9] in stable which is now available for download as a native Joomla extension for J! 5.4.x/6.0.x./6.1.x. This version addresses most of the issues that were discovered in K 6.2 / K 6.3 / K 6.4 and issues discovered during the last development stages of K 7.0
Question Hack Attempts
There has been a concerted attempt to hack my Kunena forum today (over 200 alerts related to my account) and at one point my provider actually disabled my site to make sure that everything was upgraded. I did update any addons that were a version behind (Joomla was already up to date with 1.5.26 and Kunena is 1.7.2). The only forum add-ons that needed upgrading was uddeim.
When I used the chat support and then changed the permissions back that he had changed to disable it, he suggested I post here to ask why this may be happening and why they are targeting the forum software.
Specifically he said that they were probably targeting any Joomla 1.5 site because it was about to expire (which wasn't completely clear to me because they are attacking the forum software not Joomla itself apparently) and to include the logs (see attachment) and in his words "I'd suggest contacting the developers of Kunena to see why it is flagging our security software with a "PHP REQUEST Exploit"."
So I'm doing that and hopefully this can help others who may be facing the same thing although I have no idea why they are trying to hack my site outside of just random choice or if there is a specific Kunena vulnerability that they are trying to exploit.
Phoenix
Please Log in or Create an account to join the conversation.
From where? There is no "chat support at www.kunena.org and therefore I don't know how this is a Kunena-related issue.Phoenix wrote: When I used the chat support ...
Again, who is "he" who is making this assertion? The conclusion that people are targetting J! 1.5 sites because they're "about to expire" is totally false and, in my opinion, is a complete nonsense statement. Who are these people making claims that these hack attempts are somehow in the domain of the Kunena community to address.Phoenix wrote: Specifically he said that they were probably targeting any Joomla 1.5 site because it was about to expire
That's a very serious allegation and I would reject it without corroborative evidence. There is nothing in the attachment that you gave us that refers directly or indirectly to Kunena or supports the conclusions given to you in your "chat support".Phoenix wrote: ... contacting the developers of Kunena to see why it is flagging our security software with a 'PHP REQUEST Exploit'."
Blue Eagle vs. Crypsis reference guide
Read my blog and
Please Log in or Create an account to join the conversation.
One of his replies was as follows ...
According to the logs it seems they are exploiting Kunena. What version of Kunena are you using?
I'm not sure what version you are using but even with Kunena 1.7.1 it was patching a security vulnerability. See www.kunena.org/blog/19-developer-blog/88-kunena-171-released
Kunena 1.7.2 was only a maintenance release but I would suggest upgrading all outdated extensions.
The hackers are definitely able to exploit your site. Since you have re-enabled the site more alerts keep coming in every 1 minute.
Please let me know if you need any further assistance.
As I mentioned ... at the time of the attack (which apparently has died down now) Joomla 1.5.26 and Kunena 1.7.2 were up to date.
Phoenix
Please Log in or Create an account to join the conversation.
They'll hack anyone's site just to get access to it. The reason they are targeting your site is because it uses a soon to be outdated version of Joomla 1.5.26 and was using outdated extensions. They then use it to spam, host phishing sites, attack other sites, etc. You should migrate from Joomla 1.5.26 to 2.5.4 since support for Joomla 1.5.26 ends Monday. You can use jUpgrade to migrate the site. Make sure you have a valid backup before you attempt any type of migration or upgrades.
Phoenix
Please Log in or Create an account to join the conversation.
I want you (and Mr Tanguay) to clearly understand that there is no known security vulnerability in K 1.7.2 that should compromise the integrity of a webhost. If a webhosting provider does not have adequate cyber-threat countermeasures employed, to detect and filter 'PHP REQUEST Exploit' attempts before they reach the sites that are hosted on their servers, I don't know what else we need to do.
I will, however, draw the attention of the Kunena development team to this one case that has been reported and they will respond as they see fit.
Blue Eagle vs. Crypsis reference guide
Read my blog and
Please Log in or Create an account to join the conversation.
That is mere speculation on his part. J! 1.5 is about to be retired from active support by Joomla - which is true - this month. Major security fixes will continue to be offered for J! 1.5 until September this year. Migrating to J! 2.5 is not a guarantee that your site will be free from further attempts at hacking (just as if you chose to use Drupal or Dreamweaver or any other web-development framework) and people who make these kinds of "you must upgrade" claims are only guessing.The reason they are targeting your site is because it uses a soon to be outdated version of Joomla 1.5.26 and was using outdated extensions
I agree, it's very good advice to maintain your site software to the latest revision level. Generally-speaking you will have fewer problems that way. Generally-speaking, that's what I aim for in my own work. As far as Kunena is concerned, K 1.7.2 is the only version currently supported by this community.
In the end it's your website and your choice what software you use and with whom you rely for hosting and support matters. As I wrote, I will refer this matter to the developers for their comments.
Blue Eagle vs. Crypsis reference guide
Read my blog and
Please Log in or Create an account to join the conversation.