Joomla! Discussion Forums



It is currently Tue Nov 24, 2009 7:16 am (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 4 posts ] 
Author Message
Posted: Sat Jun 10, 2006 9:43 pm 
Joomla! Intern
Joomla! Intern
Offline

Joined: Sun Aug 21, 2005 12:53 am
Posts: 72
I remember when installing Joomla that I had to make a bunch of directories writable or 777 before I could go any further with the install. So I made all directories and config.php 777 and it worked. It has been working for quite some time now.

Now I see that I have become a victim of yet another IRC eggdrop shell bullcrap hack where all the files were located in the components folder. After contacting my web host they said they were able to upload those files to that directory based on the 777 permissions. WTF! If I did'nt have it at 777 most of Joomla breaks.

WTF do I do about this situation? How can I have the secure permission levels on directories without Joomla breaking. Here is the breakdown of the files we have been a victim of again.

After downloading a full backup of the domain teamtoc.net I have encountered a few files that have been flagged by norton anti virus as being a hacktool generator or a backdoor trojan. upon browsing the directory structure on the FTP of the domain I have come across a few files that seem rather suspicious. Could you please look into a possible security breach? Here are the locations of the files.

teamtoc.net/public_html/components/.psy/
teamtoc.net/public_html/components/.php/
teamtoc.net/public_html/components/.dat/
teamtoc.net/public_html/components/cbktech.tar.gz
teamtoc.net/public_html/components/ceria.tgz
teamtoc.net/public_html/components/psy.tar.gz


Thanks for writing in. I've checked and corrected the issue. This happened as there are full permissions to the users for few folder/files, due to which the user was able to upload those files. I would like to request you to review the permissions and make sure that they are proper.

Feel free to reply to this email if you need to add anything to this particular issue, or, create a new ticket for any new issue that you wish for us to address.

It looks to me like he made the components folder unwritable anymore. Is this correct? Does this mean I can't install components anymore?


Top
  E-mail  
 
Posted: Sun Jun 25, 2006 8:12 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Tue Jun 06, 2006 12:51 pm
Posts: 29
The joomla folk can crrect me if I'm wrong but you need to set folder perm to 755 and files to 644, this should stop the hackers getting in.

If you need to install new modules or components have a look at the details at the top of the admin screen.

For Components
media/ Unwriteable
administrator/components/ Unwriteable
components/ Unwriteable
images/stories/ Unwriteable

Modules
media/ Unwriteable
administrator/modules/ Unwriteable
modules/ Unwriteable

Mambots
media/ Unwriteable
language/ Unwriteable
mambots/ Unwriteable
mambots/content/ Unwriteable
mambots/search/ Unwriteable
mambots/system/ Unwriteable

These folders have to be changed each time you install something or else you ar eleaving yourself open.

_________________
http://www.nifootball.co.uk
http://www.newtownbredafc.co.uk


Top
  E-mail  
 
Posted: Sun Jun 25, 2006 8:29 pm 
Joomla! Intern
Joomla! Intern
Offline

Joined: Sun Aug 21, 2005 12:53 am
Posts: 72
Why do they have it setup like that. Is'nt that kind of rediculous?


Top
  E-mail  
 
Posted: Sun Jun 25, 2006 10:50 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Mon Dec 05, 2005 10:17 am
Posts: 1318
Location: New Orleans, LA, USA
@stb74

Yes, those are the advisable permissions for directories (755) and files (644).  While this alone cannot stop crackers from compromising your site, it makes it more difficult.

@ 0wn4g3
For the most part, there was no choice.  The limiting factor is not Joomla itself but mostly problems with HTTP daemons and PHP.  Joomla! 1.5 will feature a major work around to this problem that will allow components/modules/templates etc to be installed via FTP instead of by HTTP upload. 

Furthermore, it sounds rediculous but on a practical level, how often are you actually installing new components/modules/templates/etc?  I doubt it is that frequently and most likely you do most of that work in groupings so you only have to adjust the permissions before you start for the day and set them back when you are done.  Not that big of a deal.

Note, files such as configuraton.php should not have file permissions that include 7's, files get set to 6 for read/write permissions.  Directories get 7 for read/write/execute

_________________
Rob Schley - Open Source Matters
Webimagery - http://www.webimagery.net/ - Professional Consulting Services
JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

Quick reply

 



Who is online

Users browsing this forum: No registered users and 12 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group