Welcome to HBH! If you had an account on hellboundhacker.org you will need to reset your password using the Lost Password system before you will be able to login.

Joomla exploit. Allows visitor to change admin password


korg's Avatar
Admin from hell
0 0

Yeah, Did you notice since that exploit was released, Every skid has been hacking into joomla sites now, That haven't been patched.:@


ghost's Avatar
0 0

yup. amazing that eh? but seriously, it's a pretty big flaw, u look at the milw0rm article and the code, you reckon someone would have noticed earlier, white-black-grey. Not at all saying i would have noticed it until shown to me, however i had more faith in the dev's there. I've been using joomla for a few years now, never touched 1.5 just cos of how much the 1.1versions grew. but, now i write my own cms systems, that are probably exploitable as all hell, but with mates like richo, it's the best way for me to lean. build a dynamic php site, following standards and security standards, then hack the shizen out of it(usually i can't, it takes another). anywho, anyone want to diig that article, would love the love :P


Infam0us's Avatar
Member
0 0

I wonder how long this has been known and just kept as a secret weapon. Thats a great find.

korg wrote: Yeah, Did you notice since that exploit was released, Every skid has been hacking into joomla sites now, That haven't been patched.:@

I wouldn't say that they hacked anything :angry:


korg's Avatar
Admin from hell
0 0

I know what you mean, Using posted exploits is bullshit but skids love them and still call it a hack.