MALICIOUS PHP SCRIPT INFECTS 2,400 WEBSITES IN THE PAST WEEK

A botnet dubbed Brain Food is giving webmasters indigestion with related attacks that push bogus diet pills and IQ-boosting pills via web pages hosted on legitimate sites. So far, spammers have been successful, thanks to an effective Hypertext Preprocessor (PHP) script (also called Brain Food) that has adroitly avoided detection on websites hosting the pitches.
Over the past four months, researchers at Proofpoint said they have tracked 5,000 Brain Food compromised websites. In a post outlining its research Friday, Proofpoint said 2,400 of those compromised sites have been active over the past seven days pushing dubious pills under the false premise the product claims made were originally on television shows Shark Tank and on identified as Entertainment Today.
“While this botnet is small compared to other spam sending infrastructure, the size of this botnet is sufficient to provide the operators with easily reconfigured redirects,” wrote Kevin Epstein, VP Threat Operations, at Proofpoint in an email interview with Threatpost.
Domain registrar and hosting firm GoDaddy has been disproportionately impacted by the Brain Food script, accounting for 40 percent of the 5,000 compromised sites. That’s followed by hosting firms DreamHost, UnitedLayer and CyrusOne.
“An individual website may contain multiple copies of the PHP script. We have observed this script installed on websites using different content management systems including WordPress and Joomla,” researchers wrote.
Spam attacks hit inboxes in the form of stripped down email messages typically with no subject and basic greeting (see below).
The body of the message contained a URL shortener link using Google’s goog.gl and bit.ly. Spammers had been blocked by Google’s URL shortener service when Google stopped allowing anonymous users from creating goo.gl links. “By the end of April, the spammer appears to have found a means of  circumventing the Google restrictions,” wrote researchers.
Recipients who click on the link are redirected to the compromised website that hosts the diet or intelligence-boosting pill pitch.
Brain Food: Malicious PHP Script
The script itself employs several layers of defense to evade detection by researchers and search engine crawlers. “The code is polymorphic and obfuscated with multiple layers of base64 encoding,” they said. “A version recently uploaded to a malware repository was not flagged by any antivirus engine.”
When a site is infected with the malicious Brain Food PHP code and crawled, the script redirects to the correct page. Next, it staggers for five seconds and “redirects to the root of the compromised domain, delays and returns nothing, or redirects to the UNICEF website,” researchers said.
“The attackers want victims to get redirected. But it wants search engines, analysts and sandboxes to get redirected to an innocuous site – whether it be the root of the compromised domain or the UNICEF website. The built-in delays are enough for many automated analysis systems to time out without detecting a potentially malicious redirect,” Epstein said.
Criminals maintain control over the landing pages and keep stats on the campaigns from C2 servers prostodomen1[.]com and thptlienson[.]com.

Even more worrisome, is a backdoor in the Brain Food code that allows “remote execution of shell code on web servers which are configured to allow the PHP ‘system’ command,” researchers wrote.

Attacks on Popular CMS Joomla Undetectable by Visitors

Avast, a cybersecurity company,y has warned both Joomla users of a new type of attack, which injects fake jQuery script into the header of the website. This type of script changes one line of code to allow the hacked website to point to a malicious script.



Avast stated that the amount of websites hacked using this method is “abnormally high” and has resulted in about 4.5 million users attacked. Visitors of the websites will not notice the code, unless they are looking at the source code because the script is put before the closing tag.



Attacks on Popular CMS Joomla and WordPress Undetectable by Visitors 

Details on the Privilege Escalation Vulnerability in Joomla

Details on the Privilege Escalation Vulnerability in Joomla:



"Yesterday, Joomla! 3.6.4 was released, patching a critical privilege escalation and arbitrary account creation vulnerability.

As we’ve seen some exploits attempts occurring in the wild, we feel it is a good time to describe what the issue is and how it was fixed.

"



Analyzing the Patch

It was fairly easy to figure out where the vulnerable code was, as pretty much all the patch does (with the exception of fixing an additional two factor authentication bug) is basically remove the register method from the UsersControllerUser class. So that’s where our investigation started.


Joomla register method removed in privilege escalation vulnerability code snippet
We removed some original code for improved readability


All in all, what this method does is it takes user input from the user POST parameter (which is intended to be an associative array) and validates whether specific parameters are properly formatted (email address, username, etc.). If it’s all good, it pushes the array to the register method from the UsersModelRegistration class.



'via Blog this'

Joomla! 3.6.4 Released

Upgrade to Joomla! 3.6.4 Today



The Joomla! development team announced the immediate availability of Joomla! 3.6.4 yesterday. This update was issued to fix two critical security flaws in all versions of Joomla! from 3.4.4 to 3.6.3. 



Please note, these security vulnerabilities could lead to your site becoming compromised. So, we advise you to update to the latest version of Joomla! today.

Joomla! 3.6.4 is now available. This is a security release for the 3.x series of Joomla! which addresses two critical security vulnerabilities and a bug fix for two-factor authentication. We strongly recommend that you update your sites immediately.
This release only contains the security fixes and bug fix; no other changes have been made compared to the Joomla! 3.6.3 release.
Joomla Security Release

What's in 3.6.4

Version 3.6.4 is released to address two critical security issues and a bug regarding two-factor authentication.

Security Issues Fixed

  • High Priority - Core - Account Creation (affecting Joomla! 3.4.4 through 3.6.3) More information »
  • High Priority - Core - Elevated Privileges (affecting Joomla! 3.4.4 through 3.6.3) More information »


Joomla! 3.6.4 Released



'via Blog this'

Joomla! CMS 3.6 Beta 2 now out

The Joomla! Project is pleased to announce the availability of Joomla! CMS 3.6 Beta 2. Community members are asked to download and install the package in order to provide quality assurance for the forthcoming 3.6 release.

Joomla! 3 is the latest major release of the Joomla! CMS, with 3.6 the seventh standard-term support release in this series. Please note that going from 3.5 to 3.6 is a one-click upgrade and is NOT a migration. The same is true is for any subsequent versions in the 3 series of the CMS.

That being said, please do not upgrade any of your production sites to the beta version as beta is ONLY intended for testing and there is no upgrade path from Beta.

Release News

Joomla! 3.5.1 Released

This week saw the release of Joomla! 3.5.1 to fix a few bugs that have been reported in the latest version of the popular CMS.



Although you may not feel it is critical to keep your site updated to the latest version of Joomla!, we see new sites every day finding themselves compromised.



Are you avoiding updating your website because of the fear you may have that something may go haywire?

Joomla! 3.5.1 - Bug Release Available

Allow us to take on the frustration and let you feel at ease and continue to do what you do best with your company. We will take the hassle out of your Joomla! update!



We offer installation, maintenance and core support for the following software products



  •     Joomla!
  •     WordPress
  •     Drupal
  •     Magento eCommerce
  •     paGO Commerce




Joomla! 3.5.1 Released

Joomla! Launches Newest CMS, Joomla 3.3

Enhanced Security, Searchability and Speed Makes Joomla 3.3 Out-of-the-Box Experience More Efficient for Developers and Users


 Joomla, one of the world's most popular open source content management systems (CMS) used for everything from websites to blogs to custom apps to Intranets, today announced the immediate availability of Joomla 3.3. The newest Joomla CMS overhauls its approach to security, enables microdata for the first time and replaces MooTools-based JavaScript with jQuery equivalents. These new features make Joomla 3.3 the most secure, searchable and fastest-loading Joomla CMS yet, ensuring the most efficient developer experience for Joomla out of the box.
"Joomla has experienced unprecedented growth recently, blowing through 50 million downloads at the end of February to more than 52 million today," said Sarah Watz, newly elected president of Open Source Matters -- a nonprofit that provides organizational, legal and financial support to the Joomla project. "Despite this massive surge, we are continuing to make improvements to ensure Joomla is cutting-edge for our user community of millions of people around the globe."
More details about the key features in Joomla 3.3 include:
  • Minimum PHP version is 5.3.10 -- This substantially enhances the level of cryptography that can be used for securing passwords.
  • jQuery JavaScript -- By moving from MooTools to jQuery JavaScript, the size of Joomla websites will be reduced, ultimately enabling sites to load faster.
  • Microdata implementation -- This allows many aspects of the content rendered by the Joomla CMS to be explained to search engines using semantic information. Ultimately, this enables Joomla websites to be more searchable.
"Some of the enhancements in Joomla 3.3 came from Joomla student developers from last summer's Google Summer of Code, and we expect more cutting-edge developments from those contributors in upcoming releases," said Chad Windnagle, Google Summer of Code Co-Admin for Joomla. "Although the Joomla community has come up with amazing enhancements, it is important that we stay as current as possible by tapping contributions from the next generation of Internet pioneers like the Google Summer of Code students."
To demo Joomla 3.3 go to demo.joomla.org, to download it go to joomla.org/download, and to access a list of new features go here.


Joomla! Launches Newest CMS, Joomla 3.3

'via Blog this'