Skip to main content
RSAC 2019: Joomla! Mail Flaw Exploited to Create Mass Phishing Infrastructure

RSAC 2019: Joomla! Mail Flaw Exploited to Create Mass Phishing Infrastructure

The Jmail Breaker attack leverages an old vulnerability in Joomla! along with a newly found flaw in the mail module.

UPDATE

SAN FRANCISCO — A fresh campaign from a known adversary is using a flaw in the popular Joomla! CMS platform to carry out a large-scale phishing and spam operation, according to researchers.

According to Check Point Research, the issue is with Jmail, which enables users to send mail through the platform; the firm said that it lacks security mechanisms to prevent the manipulation of messages’ HTTP headers. As a result, a cybercriminal can use Jmail for phishing, spam or, in this case, to implement a fully fledged backdoor infrastructure within the platform to carry out those first two activities at scale. ...Click Here

About

Kenya Education Network CERT(KENET-CERT) is a Cybersecurity Emergency Response Team and Co-ordination Center operated by the National Research and Education Network of Kenya. KENET-CERT coordination center promotes awareness on cybersecurity incidences as well as coordinates and assists member institutions in responding effectively to cyber security threats and incidences. KENET-CERT works closely with Kenya's National CIRT coordination center (CIRT/CC) as a sector CIRT for the academic institutions. KENET promotes use of ICT in Teaching, Learning and Research in Higher Education Institutions in Kenya. KENET aims to interconnect all the Universities, Tertiary and Research Institutions in Kenya by setting up a cost effective and sustainable private network with high speed access to the global Internet. KENET also facilitates electronic communication among students and faculties in member institutions, share learning and teaching resources by collaboration in Research and Development of Educational content.