User Login

Partners

Extreme Joomla | The Complete Joomla Customer Relationship Management (CRM) XHTMLSuite - The Professional HTML editor
Sakic.net - SEF Advanced 2008
YOOtheme - Web 2.0 Joomla Templates
joomla: enriched
JoomLancers - Get your Joomla Project Done Today!
RocketTheme Templates
JoomlArt: More than just a template

DaniWeb IT Discussion Community
Joomla: Because open source matters

Syndicate

RSS Feed provided by FeedBurner! RSS Feed
Azrul Issues Security Notice
Joomla News - Extensions
Written by Tony Lindskog   
Friday, 25 April 2008

Azrul Studio announce a security issue with older versions of JomComment and MyBlog.

Azrul Studio updates JomComment and MyBlogPlease be aware that we have upgraded JomComment's and MyBlog's code in order to prevent exploits to your site via an identified security vulnerability.

Although the attacker could not directly manipulate your site data, they could run a specially crafted code and capture the execution time of the code. By monitoring how long these code took to execute, an attacker could make an accurate guess of your backend password.

Do note however, that this issue only affect Jom Comment build 335 and below and MyBlog build 183 and below, both released in January 2008. Component purchased and installed after February 2008 are not affected by this security issues.

We urge all users to upgrade their JomComment and MyBlog installation to the latest build as soon as possible to ensure the safety of your site.

Note: Not a single web site has been reportedly hacked by this issue, but Azrul Studio decided to make this announcement volounterly to let their clients know just in case they were running an older version.

 JomComment:  JomComment Information
 MyBlog:  MyBlog Information
 Download:  Azrul Support 

Trackback(0)
Comments (0)Add Comment

Write comment
quote
bold
italicize
underline
strike
url
image
quote
quote
smile
wink
laugh
grin
angry
sad
shocked
cool
tongue
kiss
cry
smaller | bigger

security code
Write the displayed characters


busy