Archive for August, 2008

New variant on MPACK hacking

Tuesday, August 26th, 2008

I thought these villains had been quiet for too long and then, last night, I happened to notice a support ticket in our queue from a customer claiming that we had hijacked his site, or the server it was on. The ticket had already been pushed up the line to one of our senior techs [...]

Joomla! 1.5.* Vulnerability

Thursday, August 14th, 2008

Project: Joomla! SubProject: com_user Severity: Critical Versions: 1.5.5 and all previous 1.5 releases Exploit type: Password Reset Forgery Reported Date: 2008-August-12 Fixed Date: 2008-August-12 Description A flaw in the reset token validation mechanism allows for non-validating tokens to be forged. This will allow an unauthenticated, unauthorized user to reset the password of the first enabled [...]