1 of 10

JOOMLA! XSS VULNERABILITIES

-- Riyaz Ahemed Walikar

2 of 10

Background

  • Joomla! - Content Management System
  • PHP, MySQL
  • Ease of design and publishing
  • Admin Module
  • User pages

3 of 10

Examples

  • http://www.danone.com/?lang=en
  • http://www.itwire.com/
  • http://vho.nasa.gov/
  • http://new.lincolncenter.org/live/
  • http://www.spl.usace.army.mil/cms/index.php
  • http://tatanano.inservices.tatamotors.com/tatamotors/index.php

4 of 10

Tools

  • Local installation
  • Firefox + web developer addon
  • Patience!

5 of 10

HowTo

  • Install Joomla! locally
  • Open in Firefox
  • Login to Admin Module
  • Change POSTs to GETs
  • Insert script tags and alert (‘xss’) on various URL parameters
  • If (alert=true) { print “yay!!”}

6 of 10

Technojabble

  • The search parameter
  • Exploit code
    • " onmousemove=alert('xss') />
    • " onmousemove=alert(document.cookie) />
    • " onmousemove=window.location.assign(url) />
  • 17 component modules
  • All versions prior to 1.5.18
  • Phishing, malware download, cookie

stealing etc.

7 of 10

Timeline

  • Discovered between May 10th -12th
  • Informed JSST on May 13th
  • Acknowledged on May 13th
  • Constant updates
  • Fixed version release May 28th
  • Fixed Version 1.5.18 [latest stable]
  • Bugtraq and Secunia June 2nd
  • NVD June 4th

8 of 10

References

  • CVE-2010-1649

  • BID: 40444

9 of 10

References

  • OSVDB: 65011
    • http://www.osvdb.org/65011

  • SECUNIA: 39964

  • Keeda ID: K-31

10 of 10

Thank You!

riyazwalikar@gmail.com