NYCPHP Meetup

NYPHP.org

[joomla] Probe via search module?

Gary Mort garyamort at gmail.com
Tue Mar 9 00:43:56 EST 2010


On Mon, Mar 8, 2010 at 11:22 PM, Web Project <web at kluger.com> wrote:

> Hi,
>
> My log watch detected the following request on my Joomla site. --
>
>     index.php?module=search&q=./../../../../../../../../etc/passwd
>
> Is this sort of thing a known exploit?
>

That is not even a joomla function.

Joomla functions would be options=com_something&task=sometask&q=something

It's more likely an exploit for some other set of PHP code and their just
scanning every website for it.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.nyphp.org/pipermail/joomla/attachments/20100309/0f7866dd/attachment.html>


More information about the Joomla mailing list