Hacked, Cracked, whatever
In light of all the recent attacks on Joomla! and its extensions, new ways of securing sites need to be found quickly.
This very site was hacked (or cracked, as apparently it's now called -who cares) while still running 1.0.10 a week ago, while I was on hollidays without internet access.
To the hackers 
(never heard anyone call themselves a cracker, so I'll keep using hacker):
Thanks for only changing the one frontpage article and not making a mess of all the rest.
This is the second time this site got hacked.
I offer tutorials and ressources about Flash and Joomla for free.
I really do not understand: how can anyone take pride in defacing or hacking such a site?
If someone can explain the mind and thoughts of such people to me?
In my opinion, it is as if a gangster walks around bragging how he robbed $0.50 from the homeless guy out in the street!
Shame on you. Just because you can, doesn't make it right, cool, or whatever.
Exploiting one single security hole on as many sites as possible is just plain stupid, waste of time and energy, anyone can.
If you got skillZ, contribute to the code. If not, you're a looser!
To the Joomla! developers and extension contributors
The current "stable" version 1.0.11 introduces recommendations for some settings to make sites more secure.
It seems strange to only have one (1) person working on the current version's SVN: Rey?! Is there still a team around?
It also seems strange, reading the purpose of the stability releases such as .11:
Maintenance Release Number (1.1.X)
An increment of the maintenance number usually indicates bug fixing within
the minor release and possibly small enhancements and limited new
features. Fully backward compatible with previous maintenance increments.
to see code and recommendations introduced which (would) make this version not backwards compatible with previous versions at all, as it breaks some widely used extensions.
The last few updates have almost always introduced as many new bugs as they fixed bugs. It might be in the best interest of future users to focuse all efforts on making 1.5 beta / Stable, but as I said before, at the moment, millions of sites run on 1.0.x. This code needs better updates. Not new features, just all bugs fixed / no new ones introduced.
Once a site gets hacked, from the users perspective it doesn't make ANY difference if it's Joomla core or an extension at fault, the result is the same: site gone.
Of course, it is easy to say, as during the last weeks, "Joomla 1.0.10 is secure, there are no known issues" and "only use trusted extensions".
But looking at the changelog, it appears there were holes in the Core (ok, related to specific server settings, but not all users can change these, and "change host" is no real answer either..).
|