Home Forum
Welcome, Guest
Username Password: Remember me

Got hacked using Expose RC4
(1 viewing) (1) Guest

TOPIC: Got hacked using Expose RC4

Got hacked using Expose RC4 4 years, 10 months ago #5731


  • Posts:4
  • yam90
  • Fresh Boarder
  • OFFLINE
  • Karma: 0
Download the log from here:
---------------------------------------

Is this a new exploit?
The topic has been locked.

Got hacked using Expose RC4 4 years, 10 months ago #5741


  • Posts:1
  • uwe
  • Fresh Boarder
  • OFFLINE
  • Karma: 0
Hi

i also was hacked last night and in the Log the last action was an Upload in Expose!
Does you know what Files i have to change ?
I think i ask my Provider for do a Restore for the whole Site.

Uwe
The topic has been locked.

Got hacked using Expose RC4 4 years, 10 months ago #5742


  • Posts:2162
  • tokapi
  • Administrator
  • OFFLINE
  • Karma: 0
[s]Expose uses the amfphp plugin which caused the hole in the security. You need to change these files:
components/com_expose/expose/manager/amfphp/amf-core/app/Actions.php
components/com_expose/expose/manager/amfphp/amf-core/app/Executive.php
components/com_expose/expose/manager/amfphp/amf-core/app/php5Executive.php
components/com_expose/expose/manager/amfphp/amf-core/io/AMFDeserializer.php
components/com_expose/expose/manager/amfphp/amf-core/io/AMFSerializer.php
administrator/components/com_expose/uploadimg.php (by ftp)

Add a line at the beginning of these scripts with:
defined( '_VALID_MOS' ) or die( 'Direct Access to this location is not allowed.' );[/s]

Or you could download the updated zip on http://joomlacode.org/gf/project/expose/frs/ and [s]replace these six files with JoomXplorer. (use JoomXplorer to preserve the owner of the files)[/s]
Trial and error, but first a backup!
The topic has been locked.

Got hacked using Expose RC4 4 years, 10 months ago #5747


  • Posts:6
  • vdrover
  • Fresh Boarder
  • OFFLINE
  • Karma: 0
I just had 5 sites hacked with this, thanx for the fix.
V-man
The topic has been locked.

Got hacked using Expose RC4 4 years, 10 months ago #5750


  • Posts:2162
  • tokapi
  • Administrator
  • OFFLINE
  • Karma: 0
And I guess a lot of other users will have the same problem :| so making this topic sticky.
Trial and error, but first a backup!
The topic has been locked.

Got hacked using Expose RC4 4 years, 10 months ago #5752


  • Posts:4
  • yam90
  • Fresh Boarder
  • OFFLINE
  • Karma: 0
Thank you for the help Tokapi, I'm re-installing the gallery right now.
The topic has been locked.
Time to create page: 2.64 seconds