Telecom Tidbits
Jared's Network and Security Blog
  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links

Joomla: Security Update

October 6, 2017 Jared Hall General

Joomla corrected a bug that was created 8 years ago where an attacker can steal website administrator credentials.  The bug exists in Joomla’s LDAP (Lightweight Directory Access Protocol).  Input is not properly sanitized, so an attacker can use wildcards to progressively determine credentials.

Although the bug was present for 8 years, Joomla fixed it promptly after being notified by security professionals.  Bitdefender’s report on this issue is available here.

If you haven’t updated already to version 3.8, please do so ASAP.

 

 

 

« Top Attacking Countries: September 2017 » Un-Clouding: Don’t Let This Happen to You!

Tools & Downloads

Download Center

Categories

Good Reads (PDF)

Recent Posts

  • PayPal Woes and Degenerative AI
  • A Pathetic Defense of Julian Assange
  • Damned if you do. Damned if you don’t.
  • ProtonMail? Not Worth an Electron!
  • Give it a REST: Serious WordPress Bugs
$
Select Payment Method
Personal Info

Donation Total: $20.00

↑

  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links
Temporal Based Intelligence © 2017