Some new faces tonight which was good to see.
Prcoeedings started with a brief talk from Phil about Joomla 3.0 and the update cycle. No major changes in the 2.5.9 upgrade....
Hugh's talk on hacking:
- Initial hack done through an old version of JCE
- A file is uploaded limited to the files types set in JCE config
- The file that is uploaded conforms to all the mine type specs but within it is a simple PHP script.
- Then a complicated mechanism is used to rename the mine type file to a PHP file which then allows the hacker to upload any types of file.
- An individual or group going by the name of Hmei7 are responsible for the hack which is primarily a commercial attempt to sell your site.
They do use a spider to search for vulnerability which can leave a trace in the form of a couple of files:
- X.txt may be one of these.
- Susu.php
- X.txt
- 0day.php or 0day.gif
- Default.php
- Story.gif
Couple of tools that helped...Akeeba AdminTools and MyJoomla Tools although this later one brought about a side discussion which suggested some caution to be excercised with this tool.
..I'm sorry but after that I stopped taking notes but it wasn't long before we were all wrapped up in the pub...