Forgot?

Local File Inclusion

Reply Topic
Link to this post 03 Nov 11

I have a problem with my site. It was hacked throught the RSS Syndicator component. I've installed the new version. Then I installed "Marco's interceptor warning" plugin. This plugin send this email every week:

** Local File Inclusion [GET:controller] => ../../../../../../../../../../../../../../../proc/self/environ\0
** Local File Inclusion [REQUEST:controller] => ../../../../../../../../../../../../../../../proc/self/environ\0

*REQUEST_METHOD :
GET

*QUERY_STRING :
b36cb1ffaaaba1ce527ac18349213404=18e30c62d405d320f75163b42a7ef07d/?option=com_ninjarsssyndicator&controller=../../../../../../../../../../../../../../../proc/self/environ%00

*$_GET DUMP
-[b36cb1ffaaaba1ce527ac18349213404] => 18e30c62d405d320f75163b42a7ef07d/?option=com_ninjarsssyndicator
-[controller] => proc/self/environ\0

*$_REQUEST DUMP
-[b36cb1ffaaaba1ce527ac18349213404] => 18e30c62d405d320f75163b42a7ef07d/?option=com_ninjarsssyndicator
-[controller] => proc/self/environ\0

What can I do to prevent being hacked?
Thank you for the help.
Sorry for my english. Let me know if I could explain my self. I am from argentina...

Link to this post 04 Nov 11

Hi tomasloffler,

Sorry to hear that you were hacked via Ninja RSS Syndicator. The vulnerability was patched an reported long time ago.

If you are using the latest version of Ninja RSS Syndicator, you should be fine.

When vulnerabilities for extensions are discovered, script kiddies add them to their scripts. These scripts/bots then scan millions of websites, looking for websites that have the vulnerabilities. That is why you are getting reports of bots trying to "hack" your website. If you have the latest version, you are safe and can ignore the warnings.

When I look at our own server logs, there are hundreds of thousands of lines of this sort of activity... some scripts still scan websites for vulnerabilities in extensions that existed back in the Mambo and Joomla 1.0 days, even though these extensions no longer exist.

Kind regards,
Mark

Link to this post 04 Nov 11

Thanks Mark for the explanation.
Regards
Tomas

Link to this post 04 Nov 11

You're welcome, Tomas.

Have a good weekend.

Mark

Home Forum Joomla Extension Support Ninja RSS Syndicator Local File Inclusion