#

It is with great disappointment that I have to post that the Wits End website was hacked and the site was off-line since around 18-AUG.  It amazes me that people out there have nothing better to do than deface other peoples websites.

It looks like the version of Joomla! was vulnerable, and may have been what allowed the site to get hacked.  As good measure I reset all the passwords for the site, and my hosting account.  Joomla! is upgraded and hopefully won't be as vulnerable this time around.

I was made aware of the site defacing by a post to the Joomla.org forums.  Thanks to Eclectik on the Joomla! forums who posted the message that notified me of the hacking.

The good and bad news is, this web site was not alone in the hacking attacks.  Apparently many Joomla! based web sites were hacked in this fashion.  Joomla! however was fast acting and patched the issue within 3 hours of becoming aware of the exploit.  Unfortunately many of the Joomla! user community do not follow all the security related posts and did not update to the latest version.

At the time Wits End front page was compromised Wits End was running on Joomla! 1.5.3.  The latest version which is supposed to not be vulnerable to the specific exploit to compromise the web site is Joomla! 1.5.6.  For more information check the Announcements forum on the Joomla! web site.  http://forum.joomla.org/index.php