Joomla! Discussion Forums



It is currently Mon Nov 23, 2009 9:24 pm (All times are UTC )

 




Post new topic Reply to topic  [ 76 posts ]  Go to page Previous  1, 2, 3  Next
Author Message
Posted: Tue Jul 24, 2007 12:27 am 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Thu Aug 18, 2005 1:16 am
Posts: 961
Location: Glendale, CA, USA
Do you get an error message or what?

_________________
http://www.virtuemart-extensions.com


Top
  E-mail  
 
Posted: Tue Jul 24, 2007 12:29 am 
Joomla! Intern
Joomla! Intern
Offline

Joined: Wed May 02, 2007 7:34 am
Posts: 55
i've just replaced the configuration.php aswell with the details in configuration.php-dist and now i get this error:

Code:
Warning: require_once(/index/joomla/install/includes/version.php) [function.require-once]: failed to open stream: No such file or directory in /home/me/public_html/index/includes/joomla.php on line 71

Fatal error: require_once() [function.require]: Failed opening required '/index/joomla/install/includes/version.php' (include_path='.:/usr/lib/php:/usr/local/lib/php') in /home/me/public_html/index/includes/joomla.php on line 71


Last edited by yazeft on Tue Jul 24, 2007 1:25 am, edited 1 time in total.

Top
  E-mail  
 
Posted: Tue Jul 24, 2007 12:37 am 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Sun Sep 04, 2005 4:42 am
Posts: 84
Location: San Francisco, CA, USA
removing those files and installing the expose patch will not fix your site. That just patches expose. Depending on what files the hackers modified you may need to restore a backup. Mainly the index.php and configurartion.php from others have said.

_________________
Until Next Time,

Josh
http://www.gotgtek.net


Top
  E-mail  
 
Posted: Tue Jul 24, 2007 12:57 am 
Joomla! Intern
Joomla! Intern
Offline

Joined: Wed May 02, 2007 7:34 am
Posts: 55
i havent made any backups before.. :(

i downloaded joomla again, and i replaced the index.php and configuration.php with the 'default' ones and made the appropriate changes... is this enough?

also how do i know which files the hacker has made changes to?


this is the error:


Code:
Warning: require_once(/index/install/includes/version.php) [function.require-once]: failed to open stream: No such file or directory in /home/me/public_html/index/includes/joomla.php on line 71

Fatal error: require_once() [function.require]: Failed opening required '/index/install/includes/version.php' (include_path='.:/usr/lib/php:/usr/local/lib/php') in /home/me/public_html/index/includes/joomla.php on line 71


Top
  E-mail  
 
Posted: Tue Jul 24, 2007 1:03 am 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Sun Sep 04, 2005 4:42 am
Posts: 84
Location: San Francisco, CA, USA
Something is clearly wrong.

**On a side note I would highly recommend backing up your site just in case anything happens, I had my SMF Forum hacked once and didnt have a current backup at the time, so I can completely understand the problems.**

If you try replacing the entire "includes" directory with the one of the ones in the default Joomla ZIP file, does that work?
Call your hosting provider to see if they may have a backup too  ;) Sometimes they backup the servers.

Lastly, try this:

- Export your MySQL DB
- Backup your current Joomla File Structure (verify that its a good backup)
- reinstall Joomla
- restore your DB
- Drag over your custom folders (i.e. Templates, Components, Administrator folders, mambots etc...)

That might work also.

Good Luck,

Josh

_________________
Until Next Time,

Josh
http://www.gotgtek.net


Top
  E-mail  
 
Posted: Tue Jul 24, 2007 1:29 am 
Joomla! Intern
Joomla! Intern
Offline

Joined: Wed May 02, 2007 7:34 am
Posts: 55
i replaced all the .php files in 'includes'

.. still get the same error.. but the file is definitely there!!! araghh...

would the CHMOD settings make a difference for the dir and files? - currently set at 0644


Top
  E-mail  
 
Posted: Tue Jul 24, 2007 2:33 am 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Sun Sep 04, 2005 4:42 am
Posts: 84
Location: San Francisco, CA, USA
as long as the files are 644 and the directories are 755, I dont see any issues. Did you ask your Hosting Provider about a backup? They must backup their systems.

_________________
Until Next Time,

Josh
http://www.gotgtek.net


Top
  E-mail  
 
Posted: Wed Jul 25, 2007 12:45 am 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Wed Apr 11, 2007 11:45 pm
Posts: 114
Location: C-Town USA
When did all this happen.
I thought you had a patch for uploadimg.php now your saying to just delete that.
So confused.
Does this work with 1.0.13

_________________
I'm the Real, RealRitzcracker!
Real cause im fo Real
Ritz cause im ritzy
Cracka cause im white


Top
  E-mail  
 
Posted: Wed Jul 25, 2007 6:02 am 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Sun Sep 04, 2005 4:42 am
Posts: 84
Location: San Francisco, CA, USA
We did originally patch those files and after looking further into it, we found that it would be best to entirely remove that function to prevent future attacks on the same files. We are working on a new / better way to upload background images (thats all that file did, has nothing to do with stand photo uploads). Once it is done and stable we will update the package for testing.

Sorry for the trouble.

_________________
Until Next Time,

Josh
http://www.gotgtek.net


Top
  E-mail  
 
Posted: Wed Jul 25, 2007 8:05 am 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Wed Jul 25, 2007 7:48 am
Posts: 1
I was also hacked by a group called "d.o.m Team" (spain 2007). I applyed the patch, removed 4 files from the img directory, cleared the cache directory (here a file called function.php was installed), removed a file called index.htm in the root and replaced the index.php in the root, but nothing changed. So I searched again, and I found that my com_content.php has also been changed and all my content in the jos_content table in the database had been overwritten with HTML-Code for showing the defaced-screen. I changed the com_content.php under /administrator/components to the original one and cleared the jos_content Table and the homepage was in the old state (but without the article content). All other things (the images in expose, a guestbook, perForm Forms, aso.) worked now.

Hans


Top
  E-mail  
 
Posted: Wed Jul 25, 2007 1:44 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Wed Jul 25, 2007 1:20 pm
Posts: 15
Here is what I did, but I still have a problem, any ideas please help!!!

1. I removed expose completely using the unistall in joomla
2. went to joomlaexplorer and completely removed the expose folder
3. changed the index.php content to what it should be (it was modified by the hacker), I used a index.php from another site and just copied it
4. the site comes up, but nw I have an error: at the top of my page: (beneath my error is my site)

Warning: Cannot modify header information - headers already sent by (output started at /home/content/A/I/A/AIAE10/html/joomla/index.php:2) in /home/content/A/I/A/AIAE10/html/joomla/includes/joomla.php on line 697

my site is: http://www.aiae.net/joomla

what do I do next???

thanks,
Laura

_________________
www.RytechSites.com
Attend / Sponsor JoomlaDayNYC!!! Visit www.JoomlaDayNYC.com


Top
  E-mail  
 
Posted: Wed Jul 25, 2007 3:53 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Sun Dec 24, 2006 5:54 pm
Posts: 17
Location: Antwerp
Synchronize your site with a backup to search for modified files, or when you don't have one, synchronize with a standard Joomla installation package. Fixed my site twice in no time with this trick.


Top
  E-mail  
 
Posted: Wed Jul 25, 2007 5:31 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Wed Apr 11, 2007 11:45 pm
Posts: 114
Location: C-Town USA
doctorj wrote:
We did originally patch those files and after looking further into it, we found that it would be best to entirely remove that function to prevent future attacks on the same files. We are working on a new / better way to upload background images (thats all that file did, has nothing to do with stand photo uploads). Once it is done and stable we will update the package for testing.

Sorry for the trouble.


No problem I was just a little confused.

Thanks for Expose man I love it!

_________________
I'm the Real, RealRitzcracker!
Real cause im fo Real
Ritz cause im ritzy
Cracka cause im white


Top
  E-mail  
 
Posted: Wed Jul 25, 2007 5:53 pm 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Sun Sep 04, 2005 4:42 am
Posts: 84
Location: San Francisco, CA, USA
;D

_________________
Until Next Time,

Josh
http://www.gotgtek.net


Top
  E-mail  
 
Posted: Sun Jul 29, 2007 7:12 pm 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Sun Jul 29, 2007 7:06 pm
Posts: 1
Hello, I paid for your expose gallery for my commerical website.

You guys should be held responsible everyone's site your company compromised with a very reckless bug in your expose gallery.

I've download your patch, uploaded it to my server, and the site still gets hacked. I then completely remove your gallery. But it looks like your gallery punched a lot more holes into my site from what I read from Joomla forums.

Why is this not addressed in the front page of http://www.gotgtek.com? And why are the answers no where to be found on the front page?

"Since 1998, we have built a reputation for creating a positive return on investment for our clients." - gtek

I paid for a software that allowed hackers to walk in and out of my site. Your software has ruined the trust of my clients.

If your software was shiny car rims, your rims will have a button that says "press here to steal." It would completely bypass all car security opening all the doors and starting the engine for the car thieves. Everyone would deserve a recall. Those who PAID for this reckless code should be compensated completely.


Top
  E-mail  
 
Posted: Sun Jul 29, 2007 7:31 pm 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Thu Jul 19, 2007 11:30 am
Posts: 4
The user implementing third party software is responsible himself.

If it were different Microsoft would have gone bankrupt by now because of all the lawsuits of guys who got hacked because of the never-ending chain of security holes M$ provides us with since years.

You pay for the usage but not for a security warranty.

Sorry dude!

Since I was hacked to I really feel sorry for you but I don't agree with your statements.  ;)


Top
   
 
Posted: Sun Jul 29, 2007 11:10 pm 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Sun Sep 04, 2005 4:42 am
Posts: 84
Location: San Francisco, CA, USA
goofiva wrote:
Hello, I paid for your expose gallery for my commerical website.

You guys should be held responsible everyone's site your company compromised with a very reckless bug in your expose gallery.

I've download your patch, uploaded it to my server, and the site still gets hacked. I then completely remove your gallery. But it looks like your gallery punched a lot more holes into my site from what I read from Joomla forums.

Why is this not addressed in the front page of http://www.gotgtek.com? And why are the answers no where to be found on the front page?

"Since 1998, we have built a reputation for creating a positive return on investment for our clients." - gtek

I paid for a software that allowed hackers to walk in and out of my site. Your software has ruined the trust of my clients.

If your software was shiny car rims, your rims will have a button that says "press here to steal." It would completely bypass all car security opening all the doors and starting the engine for the car thieves. Everyone would deserve a recall. Those who PAID for this reckless code should be compensated completely.


You really need to understand what you are getting and be a little more professional with your comments. Bruno and myself both work on this software on our free time. Here are a few things you need to take into consideration:

  • This component is a bridge for the main Expose Gallery found at http://www.slooz.com, We have full permission from Ivan to give away this bridge as open source as long as the main expose gallery (what we call the core) stays in full tact
  • You Paid for the Expose Gallery Rights for commercial Use (as said above, Thank You JoomlaJasper) not for any guarantees that it will never get hacked
  • We (Bruno and Myself) have full time Jobs and do this for **FREE** on our spare time, we only receive about $10 a month in donations. This doesnt even cover my server costs/bandwidth

I mean non of this out of disrespect, but just want you and others to realize the full story before you go accusing us of neglect. Most of this software is written late at night and it is easy to overlooka missing semi-colon or a "valid MOS tag". This is why we always HIGHLY recommend daily backups just in case. This should be a good security practice for anyone using Web Applications.

The reason this was not on my frontpage (gotgtek.com) is because that is mainly for personal things and does not have much to do with Expose. That is why we have an external Demo site (thanks to http://www.modus.ie). They have been very generous in donating space to host our demo site.

If you have any other questions I am here.

-Josh

_________________
Until Next Time,

Josh
http://www.gotgtek.net


Top
  E-mail  
 
Posted: Mon Jul 30, 2007 6:58 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Tue Apr 03, 2007 10:25 pm
Posts: 12
tomhay wrote:
Hi all,
I have applied the patch, deleted the two .php files, replaced the configuration.php and index.php and now the site is showing this error.

Warning: require_once(W:/www/louise/includes/version.php) [function.require-once]: failed to open stream: No such file or directory in /home/.ouida/tomhay/onelou.com/includes/joomla.php on line 71

Fatal error: require_once() [function.require]: Failed opening required 'W:/www/louise/includes/version.php' (include_path='.:/usr/local/php5/lib/php:/usr/local/lib/php') in /home/.ouida/tomhay/onelou.com/includes/joomla.php on line 71

I am a bit new to this so any help would be most appreciated.

Tom


I got the same type of message.  So when I used JoomlaXplorer to look around, the expose folder is completely gone from the components section.  I didn't uninstal it.  In fact, it's still in the component menu.  But the whole folder containing it and all the images are gone.  Doubly sad for me is that I don't have a back-up of the site nor a back-up of all the text I typed into it.  I typed it all straight into Expose.

At this point I doubt I'm going to reinstall Expose.  As much as I loved what it did, if it keeps getting hacked into, it's not worth it.  Not right now.


Top
   
 
Posted: Mon Jul 30, 2007 7:26 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Sun Dec 24, 2006 5:54 pm
Posts: 17
Location: Antwerp
The security hole has been fixed in 4.6.1, but as long as you don't remove the files that the hacker added/changed on your server (can be all over the site, but usually they are located in the expose folder), they can access your site at any time, even when using our updated release, or even when removing the expose component completely.
All you need to do is verify your site with the latest clean backup, and all differences will appear. I fixed my site in a few minutes doing so, but since you don't have one this will be difficult...
I would try to reinstall your Joomla site locally (use wamp or so) with clean install packages then use my ftp-compare trick to get yours back in the state it was before. When finished, keep this copy as backup. You only need to make a safety copy of your database from time to time (there are some components who can do this for you).


Last edited by Tokapi on Mon Jul 30, 2007 8:09 pm, edited 1 time in total.

Top
  E-mail  
 
Posted: Tue Jul 31, 2007 6:23 pm 
User avatar
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Tue Mar 27, 2007 12:44 am
Posts: 2
Location: United States
If someone notices a fix at the Expose homepage please post it here as well so we all are up to date on the latest

Thanks


Top
   
 
Posted: Tue Jul 31, 2007 9:39 pm 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Sun Sep 04, 2005 4:42 am
Posts: 84
Location: San Francisco, CA, USA
We are working a new version of the component that will have a small notification area in the check system script. This will help tell you what the latest version of the release is. We will also post security hole fixes there as needed. Its too hard for us to develop a component and remember to update the 20 different forums (including ours, Tokapi and myself) that we belong too. If you have any other ideas we are here to listen.

_________________
Until Next Time,

Josh
http://www.gotgtek.net


Top
  E-mail  
 
Posted: Mon Aug 13, 2007 4:00 am 
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Mon Jul 31, 2006 4:33 pm
Posts: 151
doctorj wrote:
axl_fugazi wrote:
hi so my site got hacked as well. am using expose. i removed the .php and one .jpg file from the components/com_expose/expose/img directory and replaced the index.php file (as mentioned above).

but i notice a fix was posted with a link. that link does not work. what else do i have to do to prevent a repeat of this problem?

thanks - i'm not a experience web manager so i appreciate any help.


The link is here http://joomlacode.org/gf/download/frsre ... 7.2007.zip it is best to always watch the root here: http://joomlacode.org/gf/project/expose/frs/  , the link changes every time I update the package. My apologies for that.


This link doe snot work.

~R


Top
  E-mail  
 
Posted: Mon Aug 13, 2007 4:03 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Sun Dec 24, 2006 5:54 pm
Posts: 17
Location: Antwerp
Use 2nd link (http://joomlacode.org/gf/project/expose/frs/) and search in the files for a patch or latest release.


Top
  E-mail  
 
Posted: Fri Aug 17, 2007 6:04 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Tue Feb 13, 2007 7:41 pm
Posts: 26
MImpola wrote:
If someone notices a fix at the Expose homepage please post it here as well so we all are up to date on the latest

Thanks


New version of this nice piece of software is out:
http://joomlacode.org/gf/project/expose/frs/

Cheers


Top
  E-mail  
 
Posted: Mon Aug 20, 2007 3:57 pm 
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Mon Jul 31, 2006 4:33 pm
Posts: 151
Seems there is still a vulnerability.

I have patch my install, remove dubious files and my site was hacked again today..
I found two php files in the img directory  r57.php and c99.php

I have talen off tis component until it get sorted.

>:(


Top
  E-mail  
 
Posted: Mon Aug 20, 2007 5:53 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Sun Dec 24, 2006 5:54 pm
Posts: 17
Location: Antwerp
Did you remove the two files as described in the readme, or just patched it ?
Did you check your site for more changed/added files also?


Top
  E-mail  
 
Posted: Tue Aug 21, 2007 5:19 am 
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Mon Jul 31, 2006 4:33 pm
Posts: 151
Yeap did all of that You mean the uploadimg.php & uploadimage.php
and all of the above and checked all the folders for other suspicious php files...
~R


Top
  E-mail  
 
Posted: Tue Aug 21, 2007 8:06 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Thu Sep 08, 2005 2:04 pm
Posts: 123
Location: Brasil
Well.. I was hacked too, but I'm not have espose stuff here.  ??? I came to this topic thru forum search tool (hacker name).

I'm trying to find "where is the hole" here, what is the component etc...  I will post more info later.


Top
  E-mail  
 
Posted: Tue Aug 21, 2007 8:24 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Tue Aug 15, 2006 8:14 am
Posts: 43
I had my expose hacked as well. I did remove the required files and added the patch and still got hacked. Here is the message I received when I went to view my gallery in expose:

hacked by_crab muslým hackers.org

Is there anything else I can do to keep expose from being hacked as i have my design portfolio there and it's getting old being hacked now 3 times.

Thanks,

Alyn


Top
  E-mail  
 
Posted: Tue Aug 21, 2007 8:45 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Tue Feb 13, 2007 7:41 pm
Posts: 26
I got hacked as well when I had RC4 installed on my site.
I completely removed the component and all maps from the server.

Next I installed the latest version of Expose 4 which is 4.6.1
The version can be found here ...............
http://joomlacode.org/gf/project/expose/frs/

This version has the patch inside and is working for me.

Arkomat


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 76 posts ]  Go to page Previous  1, 2, 3  Next

Quick reply

 



Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group