The Joomla security team has fixed a highly critical zero-day bug, which appears to have already been used to compromise and take control of Joomla websites.
A few hours ago, the Joomla released version 3.4.6, along with security patches for older versions of the CMS, even though some of them have reached EoL (End of Life) and are no longer officially supported.
The reason behind this unusual security update is a critical zero-day bug that allows attackers to inject code into the Joomla database and later execute it.
The entry point for malicious code is the user agent string, which is advertised by the browser of each website visitor, to let websites know the appropriate techniques for each user in order to deliver the best or most appropriate version of the site.
Apparently, this string is stored in the Joomla database , but it is not properly configured for malicious code detection.
With the help of special applications and scripts that can transmit fake user agent strings, attackers can very easily create a custom string and attach malicious code to it.
Security experts from Sucuri claim that attacks that exploit this technique have been observed.
The first attacks began on December 12, but “today, the wave of attacks is even greater, with virtually every site and honeypot being attacked. This means that in all likelihood every other Joomla website out there has also been targeted,” said Daniel Cid, Founder and CTO of Sucuri.
To mitigate the risk, Mr. Cid advises website owners to update their versions as soon as possible with version 3.4.6 or the security patches offered by the Joomla. All versions of the CMS, starting from 1.5.x, are affected.
Additionally, to see if they have been compromised, webmasters should check their logs for requests from 146.0.72.83, 74.3.170.33 or 194.28.174.106, where most of the attacks have originated to date. The malicious user agent string contains the strings: “JDatabaseDriverMysqli” or “O”.
The latest version of Joomla CMS is available on Github. Security patches for older versions of Joomla can be found on the Joomla.

