Support

Admin Tools

#21552 Sites using JoomDonation threatened to be taken down

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by arkofhope on Wednesday, 26 November 2014 13:06 CST

arkofhope
 All purchasers, including myself and my nonprofit, of an extension called JoomDonation has been threatened by a hacker. We all began receiving the following email this morning. IN a nutshell, they have hacked JoomDonation and acquired emails and account info supposedly including credit cards. It involved AdminTools because they mention in their threat that they will take down ALL associated sites that used this extension, and that AdminTools cannot protect us. I feel confident in AdminTools security and this threat cannot take our sites down, but when in the midst of such a thing it messes with your confidence at some level that all of our nonprofit sites could be taken down within the next 3-5 days even with AdminTools.
(JoomDonation site is now down, hopefully for maintenance and to fix the hacking of their site) Hopefully hundreds of nonprofit sites are not next)
US based FBI and Homeland Security have been contacted by us. The reason for posting here is for reassurance of the safety of our sites)

Email copied in full with sensitive information ***'ed;

Hello Blair *****

How the hell are you? No need to ask, I’m fine!

I’m the one who has hacked all of your sites, emails, accounts etc. that has been using JoomDonation.com site/components. Scaring? Hell Yea :-)

About 15 months ago, I was able to penetrate into several Joomla sites. One of these luckies was JoomDonation.com After a while I realised that their crappy components were used by other Joomla developers too so I injected my shells into JoomDonation.com components. As per result, I’ve a list of 300000+ Joomla users+emails and you’re just one of them, lucky thing :-)

Don’t you believe? Follow me on twitter.com/joomleaks or #joomleaks hashtag and you’ll see the database of JoomDonation.com as a beginning.

Yea Yea I know you all have scanners, firewalls, admin tools etc installed on your server/site but you what? F*ck em all. They’re just noob tools. Think about, I’ve injected my own shells into 10000+ Joomla sites and none of you or your magic tools have been awared of.

WARNING: You have 5 days to clean up your sites then my bot will start putting your sites down. If your site was not so valuable for me, removing the components would be enough. If so, then I will most probably blackmail you soon :-)

Want an advice from a hacker? Don’t use any script from Thailand/Vietnam developers, their code is so crappy :-) Try Indian quality.

This email was sent to all JoomDonation.com users. We’ll meet again if you have accounts registered to other Joomla developers :-)

This was my thanksgiving gift, keep yourself safe ;-)

JnLiau

nicholas
Akeeba Staff
Manager
Hello Blair,

Please take a look at the following Joomla! forum thread: http://forum.joomla.org/viewtopic.php?f=714&t=866985#p3243888

As the JoomlaDonation's staff disclosed, their server was indeed compromised. The attacker (JoomLeaks) was able to acquire a copy of their database contents. The attacker has so far published semi-anonymised information from this database, namely full names and email addresses. He's said he's in possession of the hashed passwords and payment information, i.e. information which he could have easily find inside the database of the JoomlaDonation site's database.

Furthermore he has sent the same form email to everyone who has ever created an account at JoomlaDonation EVEN IF THEY ARE NOT USING, AND HAVE NEVER USED, THE JOOMLADONATION EXTENSIONS ON THEIR SITES. The emails have been sent to the email addresses registered with the JoomlaDonation site, NOT any email addresses used by Super Users in the allegedly hacked sites.

Based on the aforementioned information we conclude that there is no compelling evidence that this person has hacked sites using JoomlaDonation's extensions, let alone bypass any security solution (including Admin Tools). If he was actually capable of doing so he would have been contacting only people who actually use JoomlaDonation's extensions instead of everyone who had ever created a user account on that site (even those who never used these extensions). Moreover, had he really infiltrated your sites with a remote shell he would have known the Super User real name, username and email and would be contacting you at these email addresses instead of the contact information he retrieved from JoomlaDonation's database.

As a result we believe that the only site compromised was JoomlaDonation. The attacker got a copy of their database and now he's set into a fear, uncertainty and doubt (FUD) campaign to discredit the JoomlaDonation business and scare Joomla! users. There is no evidence whatsoever that he bypassed any security measure, or that he even knows the URLs of sites using JoomlaDonation extensions – something which is a trivial task for anyone who can use Google.

Regarding Admin Tools, just like any security solution it's not perfect or bullet proof. It is designed to make it harder for attackers to exploit your site within some reasonable limitations. For example, if you are using its .htaccess Maker and have enabled the front-end and back-end protection and have not allowed direct execution of arbitrary PHP files in any directories you would be adequately protected against remote shells of the kind this person alleges he has installed on sites: the remote shell is a PHP file which needs direct web access, something which this feature prevents.

As for the attack vector, there was no information provided and in the lack of evidence corroborating the alleged hacks we doubt that there was an attack vector. We can only talk about theoretical methods to compromise a site. If an extension requires direct access to PHP files they can be an attack vector which Admin Tools cannot protect you from: Admin Tools can only run inside Joomla!, not inside arbitrary files. Moreover, there are some kinds of attack such as extensions being tricked into escalating their privileges or creating privileged (Administrator and Super User) accounts when supplied with valid data which do not resemble an attack. Neither Admin Tools nor any other kind of firewall can protect you against this kind of attack vectors.

TL;DR

There is no compelling evidence that the JoomLeaks actor has compromised any site beyond JoomlaDonation itself. There is no compelling evidence that the JoomLeaks actor is able to bypass any security solution including but not limited to firewalls, malware scanners and Admin Tools. Our opinion based on the evidence presented so far is that the JoomLeaks actor has engaged in a fear, uncertainty and doubt (FUD) campaign to discredit the JoomlaDonation developers and spread disinformation to the Joomla! community. Based on the wording of the email he has sent out we consider it very likely that it's a competitor to JoomlaDonation who employs this kind of scare tactics to damage their competitor's business and divert clients to them.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

arkofhope
Thank you for your great response Nicholas. All of those settings mentioned are set so I feel secure. I have suggested the the JoomDobation users that are commenting about this problem in their forum to get AdminTools.

Blair Corbett

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!