ChronoEngine Forums
Welcome, Guest
Please Login or Register.    Lost Password?
Re:Joomla CSRF vulnerability (1 viewing) (1) Guest
Go to bottom Post Reply Favoured: 0
TOPIC: Re:Joomla CSRF vulnerability
#4802
GreyHead (Admin)
Admin
Posts: 2801
graph
User Offline Click here to see the profile of this user
Joomla CSRF vulnerability 5 Months, 4 Weeks ago Karma: 59  
Hi all,

There have been recent security updates to Joomla 1.5 and to Joomla 1.0.13SVN to protect against Cross-Site Request Forgery. As I understand the problem this is vulnerability means that if you have a site admin session open it is possible for someone to grab your session and act as an admin on your site. This isn't simple and the exploit isn't common - but may become so. Because using ChronoForms may encourage you to keep your admin session open for longer you need to take care.

The best protection is to update to the latest release of Joomla 1.5 or the latest SVN version of Joomla 1.0.13 (a new release is expected in the next few weeks). These have spoof-check functions built into the core code.

If you can't upgrade and your site remains vulnerable then Phil Taylor has made the following recommendations:
  • ALWAYS click LOGOUT in Joomla Admin when you finish
  • NEVER browse other websites while logged in to Joomla Admin
  • If you allow users to upload/modify your site through any third party component then don’t browse/or limit your surfing of your own site while logged in to Joomla Admin
  • NEVER click on links to “Upgrade this component” in 3rd Party Components
  • NEVER browse forums while logged into Joomla Admin
Phil has also suggested that a secure workaround it to access your site admin using the Mozilla Prismdesktop application. This means that your admin session is never available on the web though your browser.

Bob

PS Chronoforms current releases (like most other extensions) do not include the admin spoof-check functions that are in the current core code. I'm hoping that Max will add them for the next releases.
 
Report to moderator   Logged Logged  
 
Bob Janes
info at greyhead.net
ChronoForms Support If you like ChronoForms please vote or post a review at Joomla.org
  The administrator has disabled public write access.
#4957
GreyHead (Admin)
Admin
Posts: 2801
graph
User Offline Click here to see the profile of this user
Re:Joomla CSRF vulnerability 5 Months, 3 Weeks ago Karma: 59  
Joomla 1.0.14 has now been released - you can download here

Bob
 
Report to moderator   Logged Logged  
 
Bob Janes
info at greyhead.net
ChronoForms Support If you like ChronoForms please vote or post a review at Joomla.org
  The administrator has disabled public write access.
Go to top Post Reply
Powered by FireBoardget the latest posts directly to your desktop


equalheight If you have any questions you can post to our forums and we will be glad to help ASAP

Members Login






Lost Password?
No account yet? Register

2CheckOut.com Inc. (Ohio, USA) is an authorized retailer for
goods and services provided by ChronoEngine.com

ChronoForms License

equalheightTo be able to continue working at this component we decided to get a small profit out of it but at the same time don't force everybody to pay in order to use this great component.

 

 From version 1.5 and up a link at the bottom of everyform created will be placed, saying "joomla professional work", the link will be to us here htttp://www.chronoengine.com, its illegal to remove this link from the source code unless you have a license,

so the license is very simply for the same ChronoForms component without a link, thats all!

This License is for 5 different websites ONLY. 

 

 However, in order to allow everybody to still use the component and even get out of this, the link is inside a div with class : chronoform , use this to hide the link by using different colors or whatever if you really can't pay, but of course the link is still exists at your page source.

 

The license is ONLY 25$ can be bought here :

 

Thank you!

 

ChronoEngine.com Team 

Joomla Templates and Joomla Tutorials