Manage Multiple WordPress and Joomla Sites easily!
@mysites.guru
Digital Agency Dashboard for managing unlimited WordPress & Joomla websites - check us out at http://mySites.guru - Not run by chickens... 🐔
JoomShaper stopped patching Joomla 3, and its fixes need Joomla 4+. So we built the only tool that backports them into abandoned SP Page Builder, Helix3 and Helix Ultimate. One toggle. mysites.guru/blog/patch-a...
Another 23 Critical Security Vulnerabilities in Gridbox for Joomla - gulp! mysites.guru/blog/gridbox...
Seeing/Hearing a large wave of exploits against the Gridbox Extension for Joomla this evening following their release last week that patched 23 critical vulnerabilities - make sure you upgraded !!! mysites.guru/blog/gridbox...
Gridbox: 23 More Critical Vulnerabilities | mySites.guru
Balbooa asked us to audit Gridbox. We found 23 vulnerabilities, including a pre-auth RCE in one request. Several are being actively exploited in the wild, and the complete fix is now out in Gridbox…
mysites.guru
Your .htaccess won't stop a Joomla hack. The attacks ride through index.php, the one endpoint it must allow, and an upload bug can overwrite the file itself. Joomla's own docs still ship a rule blocking the word viagra. mysites.guru/blog/your-ht...
Another 23 Critical Security Vulnerabilities in Gridbox for Joomla - gulp! mysites.guru/blog/gridbox...
mySites.guru found four vulnerabilities in SP Page Builder for Joomla by JoomShaper: a pre-auth SQL injection and an unauthenticated mail relay. Fixed in 6.7.1, update now. mysites.guru/blog/sp-page...
Your .htaccess won't stop a Joomla hack. The attacks ride through index.php, the one endpoint it must allow, and an upload bug can overwrite the file itself. Joomla's own docs still ship a rule blocking the word viagra. mysites.guru/blog/your-ht...
Another 23 Critical Security Vulnerabilities in Gridbox for Joomla - gulp! mysites.guru/blog/gridbox...
JCE 2.9.99.10 fixes a rename bug that let a privileged user hide a file in the folder being browsed. Authenticated only, so no repeat of June. The release hardens more than its changelog admits. mysites.guru/blog/jce-2-9...
JoomShaper stopped patching Joomla 3, and its fixes need Joomla 4+. So we built the only tool that backports them into abandoned SP Page Builder, Helix3 and Helix Ultimate. One toggle. mysites.guru/blog/patch-a...
Another 23 Critical Security Vulnerabilities in Gridbox for Joomla - gulp! mysites.guru/blog/gridbox...
INCOMING the worse WORSE worse ever.... details within the hour....
JCE 2.9.99.10 fixes a rename bug that let a privileged user hide a file in the folder being browsed. Authenticated only, so no repeat of June. The release hardens more than its changelog admits. mysites.guru/blog/jce-2-9...
We just launched a new tool at mySites.guru to check for malicious Cron Jobs (the same way hackers drop crons) and within moments we are already seeing results. HACKED cronjobs PRETENDING to be legitimate code #facepalm
Two unauthenticated flaws in Events Booking for Joomla: anonymous file upload on by default, and every user's name and email exposed. Three CVEs. Update to 5.8.1. mysites.guru/blog/events-...
mySites.guru found four vulnerabilities in SP Page Builder for Joomla by JoomShaper: a pre-auth SQL injection and an unauthenticated mail relay. Fixed in 6.7.1, update now. mysites.guru/blog/sp-page...
mySites.guru found and reported an unauthenticated SQL injection in DPCalendar for Joomla. An anonymous request could read the whole database. Fixed in 10.11.2 (8.19.4 on Joomla 3), update now. mysites.guru/blog/dpcalen...
mySites.guru found four vulnerabilities in SP Page Builder for Joomla by JoomShaper: a pre-auth SQL injection and an unauthenticated mail relay. Fixed in 6.7.1, update now. mysites.guru/blog/sp-page...
Another SP Page Builder Security Release - another pathetic response from them, downplaying the security issues and not crediting the reporter for responsible disclosure... The truth: Complete and utter database compromise without authentication! Full blog post coming...
JoomShaper stopped patching Joomla 3, and its fixes need Joomla 4+. So we built the only tool that backports them into abandoned SP Page Builder, Helix3 and Helix Ultimate. One toggle. mysites.guru/blog/patch-a...
Your .htaccess won't stop a Joomla hack. The attacks ride through index.php, the one endpoint it must allow, and an upload bug can overwrite the file itself. Joomla's own docs still ship a rule blocking the word viagra. mysites.guru/blog/your-ht...
The first hack plants a dormant dropper that does nothing visible. Days later, the second wave reactivates it to plant more backdoors. Being hacked yesterday does not mean you are safe today. mysites.guru/blog/hacked-...
Your .htaccess won't stop a Joomla hack. The attacks ride through index.php, the one endpoint it must allow, and an upload bug can overwrite the file itself. Joomla's own docs still ship a rule blocking the word viagra. mysites.guru/blog/your-ht...
The problem with responsible disclosure when it comes to security vulnerabilities is that it requires both parties to act in a responsible manner. #facepalm
Two unauthenticated flaws in Events Booking for Joomla: anonymous file upload on by default, and every user's name and email exposed. Three CVEs. Update to 5.8.1. mysites.guru/blog/events-...
Before EasyStore 2.0.2 for Joomla, any logged-in customer could read every other customer's invoice by editing one URL. We also found an unauth SQL injection and order forgery, fixed quietly. Update now. mysites.guru/blog/easysto...
JoomShaper stopped patching Joomla 3, and its fixes need Joomla 4+. So we built the only tool that backports them into abandoned SP Page Builder, Helix3 and Helix Ultimate. One toggle. mysites.guru/blog/patch-a...
mySites.guru found and reported an unauthenticated SQL injection in Quix Page Builder for Joomla. An anonymous request could read the whole site database. Fixed in Quix 6.2.1, update now. mysites.guru/blog/quix-sq...