looks like joomla org hacked

If you have any 'mechanical' forum or Joomla! sites related issues/suggestions, please contact the Sites & Infrastructure Workgroup here.

Moderators: brad, Tonie

Forum rules
Forum Rules
READ ME <-- please read before posting, this means YOU.
User avatar
sc00zy
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 106
Joined: Thu Aug 18, 2005 9:07 am
Location: Assen, Netherlands
Contact:

Re: look like joomal.org hacked

Post by sc00zy » Sat Aug 18, 2007 12:30 pm

dragonrider wrote:Now the page I see when visiting the link, shows a page full of adverts, all other links go to joomla.org/parking and an option to make an offer for the domain via sedo??? ???


Look twice the poster posted the wrong url ;) He typed http://www.joomal.org.
Arjan Menger
http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting
http://www.joomlablog.nl - Nederlands Weblog Over Joomla!

User avatar
sc00zy
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 106
Joined: Thu Aug 18, 2005 9:07 am
Location: Assen, Netherlands
Contact:

Re: Joomla.org Hacked

Post by sc00zy » Sat Aug 18, 2007 12:32 pm

Maybe it was just a force hack on a username/password. Let's wait for more news.
Arjan Menger
http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting
http://www.joomlablog.nl - Nederlands Weblog Over Joomla!

dragonrider

Re: look like joomal.org hacked

Post by dragonrider » Sat Aug 18, 2007 12:33 pm

sc00zy wrote:
dragonrider wrote:Now the page I see when visiting the link, shows a page full of adverts, all other links go to joomla.org/parking and an option to make an offer for the domain via sedo??? ???


Look twice the poster posted the wrong url ;) He typed http://www.joomal.org.

Doh! :-[

User avatar
bennieblanco
Joomla! Apprentice
Joomla! Apprentice
Posts: 14
Joined: Wed Jan 25, 2006 6:37 am
Location: USA
Contact:

Re: look like joomal.org hacked

Post by bennieblanco » Sat Aug 18, 2007 12:40 pm

whoever is workin on it , should remove the image first.
firefox developer extention
show image links
High Quality Joomla Templates http://www.youjoomla.com
Joomla Templates | Free Joomla Templates | Joomla Tutorials

User avatar
exrace
Joomla! Apprentice
Joomla! Apprentice
Posts: 33
Joined: Tue Aug 23, 2005 4:55 am
Location: On my CBR 1000rr...

Re: look like joomal.org hacked

Post by exrace » Sat Aug 18, 2007 12:56 pm

How long could this take?
I still see the graphic.
Love, Live PHP.
Love, Live Joomla!
Super Sonic Man...do you want to buy a RockeTheme rocket? -Gary Jules
"I think I will shave my head today!" -Britney Spears

User avatar
sc00zy
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 106
Joined: Thu Aug 18, 2005 9:07 am
Location: Assen, Netherlands
Contact:

Re: look like joomal.org hacked

Post by sc00zy » Sat Aug 18, 2007 12:57 pm

malikperera wrote:I just log in to http://www.joomal.org and get this, Look like site hacked

Template File Not Found! Looking for template:
- Names deleted -


Please remove the names of the hackers. You're actually giving them credits by posting their names.
Arjan Menger
http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting
http://www.joomlablog.nl - Nederlands Weblog Over Joomla!

thestratocaster

JOOMLA HACKED????

Post by thestratocaster » Sat Aug 18, 2007 12:58 pm

Hello all,

Just wondering if anyone else noticed that the main joomla site has been hacked? lol?

This doesn't say very much about Joomla security.....

Can someone explain?

[MOD note: Hacker reference removed. No need to encourage script kiddies. - pe7er]
Last edited by pe7er on Sat Aug 18, 2007 2:20 pm, edited 1 time in total.

User avatar
exrace
Joomla! Apprentice
Joomla! Apprentice
Posts: 33
Joined: Tue Aug 23, 2005 4:55 am
Location: On my CBR 1000rr...

Re: joomla.org hacked?

Post by exrace » Sat Aug 18, 2007 12:59 pm

Surprised moderators didn't remove the image...  ???
Love, Live PHP.
Love, Live Joomla!
Super Sonic Man...do you want to buy a RockeTheme rocket? -Gary Jules
"I think I will shave my head today!" -Britney Spears

iwebdesign
Joomla! Fledgling
Joomla! Fledgling
Posts: 1
Joined: Wed Aug 30, 2006 1:37 pm
Contact:

Re: Hack Attack on the Shop ?

Post by iwebdesign » Sat Aug 18, 2007 12:59 pm

That's really really bad.
What should I tell my customers?  :D

I'd be glad, if the joomla.org team explains in detail, how this could have happened.

Good luck and best regards!
Add your website to the Joomla! Directory for free:
http://www.joomlazone.net
Joomla! Templates & Webdesign:
http://www.iwebdesign.ch

User avatar
sc00zy
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 106
Joined: Thu Aug 18, 2005 9:07 am
Location: Assen, Netherlands
Contact:

Re: Hack Attack on the Shop ?

Post by sc00zy » Sat Aug 18, 2007 1:03 pm

Please remove the screenshots and names of the hackers in your posts. You're giving them credits by doing this!

Thanks!
Arjan Menger
http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting
http://www.joomlablog.nl - Nederlands Weblog Over Joomla!

User avatar
exrace
Joomla! Apprentice
Joomla! Apprentice
Posts: 33
Joined: Tue Aug 23, 2005 4:55 am
Location: On my CBR 1000rr...

Re: look like joomal.org hacked

Post by exrace » Sat Aug 18, 2007 1:05 pm

sc00zy wrote:Please remove the names of the hackers. You're actually giving them credits by posting their names.

You think the mods would be ALL OVER this.  ???
Love, Live PHP.
Love, Live Joomla!
Super Sonic Man...do you want to buy a RockeTheme rocket? -Gary Jules
"I think I will shave my head today!" -Britney Spears

User avatar
sc00zy
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 106
Joined: Thu Aug 18, 2005 9:07 am
Location: Assen, Netherlands
Contact:

Re: look like joomal.org hacked

Post by sc00zy » Sat Aug 18, 2007 1:06 pm

exrace wrote:You think the mods would be ALL OVER this.  ???


Please note it's weekend and a lot of mods are still asleep.
Arjan Menger
http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting
http://www.joomlablog.nl - Nederlands Weblog Over Joomla!

joomila

Re: Joomla.org Hacked

Post by joomila » Sat Aug 18, 2007 1:09 pm

what version of Joomla is running joomla.org??

User avatar
Joomla Starter
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Fri Nov 25, 2005 9:11 pm
Location: Switzerland-Luxemburg-Europe
Contact:

jommla.org main page HACKED

Post by Joomla Starter » Sat Aug 18, 2007 1:09 pm

:o  URGENT I  cant believe it  The official Page of joomla org was hacked today at the moment i write this post ,
I attached  a pdf file


www.joomla.org


:o
Last edited by Joomla Starter on Tue Sep 04, 2007 2:24 pm, edited 1 time in total.

User avatar
exrace
Joomla! Apprentice
Joomla! Apprentice
Posts: 33
Joined: Tue Aug 23, 2005 4:55 am
Location: On my CBR 1000rr...

Re: look like joomal.org hacked

Post by exrace » Sat Aug 18, 2007 1:11 pm

The admins are too I guess... :)
Love, Live PHP.
Love, Live Joomla!
Super Sonic Man...do you want to buy a RockeTheme rocket? -Gary Jules
"I think I will shave my head today!" -Britney Spears

User avatar
exrace
Joomla! Apprentice
Joomla! Apprentice
Posts: 33
Joined: Tue Aug 23, 2005 4:55 am
Location: On my CBR 1000rr...

Re: look like joomal.org hacked

Post by exrace » Sat Aug 18, 2007 1:14 pm

Hummm...
I thought forums and www site on same server?

ping http://www.joomla.org
Pinging joomla.org [72.9.243.251] with 32 bytes of data:

ping forum.joomla.org
Pinging forum.joomla.org [65.254.35.66] with 32 bytes of data:

Edit: I stand corrected. :)
Last edited by exrace on Sat Aug 18, 2007 2:05 pm, edited 1 time in total.
Love, Live PHP.
Love, Live Joomla!
Super Sonic Man...do you want to buy a RockeTheme rocket? -Gary Jules
"I think I will shave my head today!" -Britney Spears

User avatar
ilox
Joomla! Apprentice
Joomla! Apprentice
Posts: 20
Joined: Thu Aug 25, 2005 3:29 pm
Location: Adelaide, South Australia
Contact:

Re: jommla.org main page HACKED

Post by ilox » Sat Aug 18, 2007 1:22 pm

Being discussed here... http://forum.joomla.org/index.php?topic=203014.new;topicseen#new
And I am not sure the PDF is necessary, the staff are aware of the attack. The staff have closed the site though it has again been hacked since their closure hence the change of the hack graphic for the original logo. I think there is a lot going on behind the scenes over there
Cheers,  Ian
"So long, and thanks for all the fish" - The Dolphins - http://www.jengajam.com/r/dolphins
The Hitch Hikers Guide To The Galaxy by Douglas Adams - "Don't forget your towel"

User avatar
sc00zy
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 106
Joined: Thu Aug 18, 2005 9:07 am
Location: Assen, Netherlands
Contact:

Re: jommla.org main page HACKED

Post by sc00zy » Sat Aug 18, 2007 1:24 pm

There are a couple of threads about this allready. Please remove the PDF. You're giving the hackers credits by posting screenshots and their namers.

Thanks!
Arjan Menger
http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting
http://www.joomlablog.nl - Nederlands Weblog Over Joomla!

User avatar
MMMedia
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 233
Joined: Sun Aug 21, 2005 2:25 pm
Location: Somewhere Near Here

Re: joomla.org hacked?

Post by MMMedia » Sat Aug 18, 2007 1:28 pm

I was hoping the one that posted it would edit their own post.  I was giving them time to do it.  Obviously they won't, or aren't going to, so I will remove it.
Be kinder than necessary, for everyone you meet is fighting some kind of battle.
http://www.oddsheepout.com http://www.jennifermarriott.com
JOOMLA ROCKS
Women JOOMLA! Too

User avatar
ilox
Joomla! Apprentice
Joomla! Apprentice
Posts: 20
Joined: Thu Aug 25, 2005 3:29 pm
Location: Adelaide, South Australia
Contact:

Re: joomla.org hacked?

Post by ilox » Sat Aug 18, 2007 1:28 pm

When the site was first closed it was showing the Joomla logo as expected  (I have a screenshot of it). It was just a little later that the hacked image appeared, about 5-10 minutes after the first one showed up (I have a screenshot). I would hazard a guess that even though the site was closed down the hacker somehow still had access and was able to change the graphic over.
------------------------------------------------
Update: Index page now amended and that graphic has gone, thank goodness
Last edited by ilox on Sat Aug 18, 2007 1:42 pm, edited 1 time in total.
Cheers,  Ian
"So long, and thanks for all the fish" - The Dolphins - http://www.jengajam.com/r/dolphins
The Hitch Hikers Guide To The Galaxy by Douglas Adams - "Don't forget your towel"

User avatar
Joomla Starter
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Fri Nov 25, 2005 9:11 pm
Location: Switzerland-Luxemburg-Europe
Contact:

Re: jommla.org main page HACKED

Post by Joomla Starter » Sat Aug 18, 2007 1:29 pm

ok  I have delete the file, it was just for help.

User avatar
sc00zy
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 106
Joined: Thu Aug 18, 2005 9:07 am
Location: Assen, Netherlands
Contact:

Re: jommla.org main page HACKED

Post by sc00zy » Sat Aug 18, 2007 1:29 pm

No problem :)

Thanks!
Arjan Menger
http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting
http://www.joomlablog.nl - Nederlands Weblog Over Joomla!

User avatar
rsd
Joomla! Apprentice
Joomla! Apprentice
Posts: 5
Joined: Mon Jun 26, 2006 6:21 pm
Contact:

Re: joomla.org hacked?

Post by rsd » Sat Aug 18, 2007 1:34 pm

Does enyone knows if the Joomla site's host is in a Joomla owned server or if it is a shared hosting environment?

User avatar
sc00zy
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 106
Joined: Thu Aug 18, 2005 9:07 am
Location: Assen, Netherlands
Contact:

Re: joomla.org hacked?

Post by sc00zy » Sat Aug 18, 2007 1:46 pm

rsd wrote:Does enyone knows if the Joomla site's host is in a Joomla owned server or if it is a shared hosting environment?


Joomla has got their own servers at Rochen.
Arjan Menger
http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting
http://www.joomlablog.nl - Nederlands Weblog Over Joomla!

User avatar
GollumX
Joomla! Fledgling
Joomla! Fledgling
Posts: 4
Joined: Sun Oct 29, 2006 10:51 am
Contact:

Re: look like joomal.org hacked

Post by GollumX » Sat Aug 18, 2007 1:50 pm

can anyone confirm whether joomla.org was running 1.0.13?
Am I counting wrong or are there really 50 extensions for members of www.ninjoomla.com/ ?

User avatar
sc00zy
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 106
Joined: Thu Aug 18, 2005 9:07 am
Location: Assen, Netherlands
Contact:

Re: look like joomal.org hacked

Post by sc00zy » Sat Aug 18, 2007 1:54 pm

GollumX wrote:can anyone confirm whether joomla.org was running 1.0.13?


It isn't sure yet how joomla.org got hacked. They're on it as we speak.
It's most likely joomla.org was running 1.0.13
Arjan Menger
http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting
http://www.joomlablog.nl - Nederlands Weblog Over Joomla!

User avatar
infograf768
Joomla! Engineer
Joomla! Engineer
Posts: 366
Joined: Fri Aug 12, 2005 3:47 pm
Location: •Translation Matters•

Re: jommla.org main page HACKED

Post by infograf768 » Sat Aug 18, 2007 1:57 pm

Merging all similar posts.
Jean-Marie Simonet / infograf · http://www.info-graf.fr · GMT +1
Qui vult dare parva non debet magna rogare.

User avatar
rsd
Joomla! Apprentice
Joomla! Apprentice
Posts: 5
Joined: Mon Jun 26, 2006 6:21 pm
Contact:

Re: joomla.org hacked?

Post by rsd » Sat Aug 18, 2007 2:00 pm

sc00zy wrote:
rsd wrote:Does enyone knows if the Joomla site's host is in a Joomla owned server or if it is a shared hosting environment?


Joomla has got their own servers at Rochen.


So, there is a security flaw in joomla indeed :(

User avatar
ot2sen
Joomla! Ace
Joomla! Ace
Posts: 1384
Joined: Thu Aug 18, 2005 9:58 am
Location: Hillerød - Denmark
Contact:

Re: Hack Attack on the Shop ?

Post by ot2sen » Sat Aug 18, 2007 2:04 pm

sc00zy wrote:Please remove the screenshots and names of the hackers in your posts. You're giving them credits by doing this!

Thanks!

Agree. Image removed above.
Ole Bang Ottosen - http://www.ot2sen.dk
Danish Joomla! support site – http://joomladanmark.org

User avatar
MMMedia
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 233
Joined: Sun Aug 21, 2005 2:25 pm
Location: Somewhere Near Here

Re: joomla.org hacked?

Post by MMMedia » Sat Aug 18, 2007 2:06 pm

It may not be in Joomla! itself.  It could be in a 3PD extension. 

Before making statements please wait until all the information is in.  It isn't right or fair or responsible to just throw things out there that may not be true.  >:(
Be kinder than necessary, for everyone you meet is fighting some kind of battle.
http://www.oddsheepout.com http://www.jennifermarriott.com
JOOMLA ROCKS
Women JOOMLA! Too


Locked