|
SerrBizSEF suspended 3- 18 - 08 |
It seems in giving the SerrBizSEF component away free, some devious little hacker has managed to figure out away to stuff the SerrBizSEF component with thousands of bogus URLS. Given this, we have suspended downloads of SerrBizSEF for the public. Sorry.
Here is the problem. Some hacker has managed to force bogus URLS into the SerrBizSEF db tables. I believe the purpose of this attacks is similar to the refer log attacks that are common exploits of spam link builders. These attacks have no value ultimately, but do show up in the control panel. The short fix is to just delete the bogus SEFS. They are tied to bogus "components". We are working to determine how this was achieved, and how to close the hole that is being exploited. When we have a solution, we will post here. Until then, SerrBizSEF is suspended and will only be available to our full service clients. If this suspension upsets anyone, please do find your local hacker, and give them a thorough beating..
Note: This may not be a SerrBizSEF hole. SerrBizSEF records components and related SEF generated by the components. This hole may be hole in Joomla and SerrBizSEF is just recording it. Like we said, we are looking for the problem, and will post a notice when resolved.
Available for download again 3-20-8 |
|
Last Updated ( Thursday, 20 March 2008 )
|