-SQL Injection vulnerability in Joomla exploited for hacking attacks, four hours after its disclosure – More than 12,000 attack attempts take place on a daily basis
Last week, the Joomla released an urgent security update to fix a critical SQL injectionthat could allow an attacker to take control of a vulnerable website.
The SQL Injection vulnerability (CVE-2015-7297, CVE-2015-7857, CVE-2015-7858) was discovered by Trustwave researchers, and announced in blog posts on the Joomla and Trustwave websites.
According to reports from security firm Sucuri, the first attacks began to be recorded four hours after the vulnerability details were made public. Over the next few days, the number of attacks increased dramatically, with exploitation attempts now reaching 12,000 per day.
The first attack recorded through the exploitation of this specific vulnerability was unsuccessful, as the website had firewall protection software, which contributed to the detection and effective prevention of this specific type of attack.
Later attacks were more organized, with the attackers evolving the exploit code so that it was able to detect and avoid older versions of Joomla, and only targeting the latest release cycle, 3.x, which is affected by the specific issue.
“Our research shows that the average administrator has less than 24 hours to secure a website after a serious vulnerability disclosure like this,” says Daniel Cid, founder and CTO of Sucuri. “This is true for the average website (small to medium-sized). If you run a popular website, you only have a few hours from the time a vulnerability is disclosed to the time an exploit is attempted, so you need to react quickly,” he adds.


