Joomla! Discussion Forums



It is currently Wed Nov 25, 2009 3:27 pm (All times are UTC )

 




Post new topic Reply to topic  [ 7 posts ] 
Author Message
Posted: Tue Aug 29, 2006 5:03 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Mon Jul 17, 2006 3:57 am
Posts: 18
I've been running a site using Joomla, and recently noticed my site was hacked through the Link Directory component. I reinstalled my component files, and realised that some of my directory permissions have been set at 777 (I just created the site, and hadn't chmod them back yet). I tried to chmod these files back using Joomlaxplorer and my Cpanel, but I've been logged out of my admin site.  I also had globals_register set to on because I was having trouble with my TSMF forum and changed it so that it would work. I'm going to contact my host to get it turned off again, but I still need help!

I now get a message saying that I am forbidden to view the page (admin login), and I had my site turned offline while trying to fix this. I went into my Cpanel and changed the site to online, and I keep getting error messages saying that components aren't installed, etc.

I have no idea what to do to fix this, since I can't even login to my admin site. Oh please help me! I need my site back online ASAP!!!

Edit: I went into my Cpanel and upgraded to 1.10 (although I had already manually installed the patch from 1.08) and everything was back! A few minor formatting issues, but everything was back! And I added the line of code given elsewhere it linkdirectory to stop hackers... Hopefully problem solved.

TIA,

Na3


Last edited by na3 on Tue Aug 29, 2006 5:21 pm, edited 1 time in total.

Top
  E-mail  
 
Posted: Tue Aug 29, 2006 5:24 pm 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Thu Sep 22, 2005 10:29 am
Posts: 57
You should upgrade to J! 1.0.11 asap.  :)

And check for files that got installed by the hackers, such as mailscripts / shells.


Top
  E-mail  
 
Posted: Tue Aug 29, 2006 5:50 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Mon Jul 17, 2006 3:57 am
Posts: 18
How do I check for mailscripts etc?


Top
  E-mail  
 
Posted: Tue Aug 29, 2006 6:48 pm 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Tue Jun 06, 2006 7:41 am
Posts: 808
Location: Third planet from Sol
I would delete the whole directory, and reinstall everything. That's quicker than trying to find maliciously installed/modified files.
See this list for pointers: http://forum.joomla.org/index.php/topic,81058.0.html

_________________
Web Home: http://www.ronliskey.com
Support http://support.educationgrove.com


Top
  E-mail  
 
Posted: Tue Aug 29, 2006 6:57 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Mon Jul 17, 2006 3:57 am
Posts: 18
Yeah, I'd delete everything except I've worked for two months non-stop on this site, it's an online publication and yesterday I updated all my content, I'm advertising jobs available with my company as of yesterday, and it's almost time for me to get up and go to work.

So far everything seems ok, and I'm trying to upgrade to 1.0.11...

I have a backup, I just need my site to be stable for one day and then I can fix everything tonight.

If I'm using Fantastico, can I just uninstall and then load a backup, and everything will be as it was before the hack?


Top
  E-mail  
 
Posted: Tue Aug 29, 2006 8:13 pm 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Tue Jun 06, 2006 7:41 am
Posts: 808
Location: Third planet from Sol
If you have to use existing files, here's a script that may help you. It lists all the files on your site in order of mod date. Just look at the top of the list for files that should not have been modified lately.
http://www.joomlation.eu/index.php?opti ... &Itemid=35

I made a few tweaks to the original script to show more details, such as file permissions. Available here:
http://www.educationgrove.com/index.php ... Itemid=100

_________________
Web Home: http://www.ronliskey.com
Support http://support.educationgrove.com


Top
  E-mail  
 
Posted: Wed Aug 30, 2006 7:08 am 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Mon Jul 17, 2006 3:57 am
Posts: 18
Thanks so much Rliskey!  :) I'll test it out tonight and let you know how it goes 

Edit: I've just upgraded to 1.0.11, and I'm now using your File permissions script to check all my files. Thanks again Rliskey, this is a life-saver of a script!


Last edited by na3 on Thu Aug 31, 2006 2:20 pm, edited 1 time in total.

Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 

Quick reply

 



Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group