New Joomla Vulnerability

During the last couple of weeks, we have noticed an increase in the number of attacks against websites using the Joomla CMS. These seem to be part of a cyber attack primarily targeting the USA. The attack, dubbed “Operation Ababil”, is organized by Iranian hackers, but carried out by sympathizers around the world.

The JCE vulnerability

The attack focuses on a vulnerability in Joomla’s Content Editor (JCE), and gives attackers the ability to upload any file they like to the website. Most often these are backdoors, which can later be used to carry out cyber attacks, send spam, post phishing pages, and much more.

Protection at Gigahost

It is hard to protect against this attack using firewalls or packet-inspection equipment, because it can be made to look like legitimate traffic. However, we are happy to announce that we have found a way to stop the attacks on thousands of Joomla sites hosted at Gigahost.

We have also notified all customers who were found to be using a vulnerable JCE component.

Keep Joomla updated

As always, the best way to avoid attacks is to keep Joomla updated, along with any components, themes, and other add-ons.