The Joomla! Forum ™



Forum rules


Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 6 posts ] 
Author Message
PostPosted: Tue Jul 31, 2012 5:18 pm 
Joomla! Enthusiast
Joomla! Enthusiast

Joined: Mon Mar 31, 2008 8:28 pm
Posts: 106
Location: St. John's, Newfoundland, Canada
Hi I received the Site may be compromised message and am just now in the process of reviewing the site. I used the forum post assistant and the following information is what was generated. If anyone can have a look through and let me know if they see anything obvious that needs to be changed... that would be great. Many thanks.

Problem Description :: Forum Post Assistant (v1.2.1) : 31st July 2012 wrote:
Site was flagged as 'may be compromised' by google
Forum Post Assistant (v1.2.1) : 31st July 2012 wrote:
Basic Environment :: wrote:
Joomla! Instance :: Joomla! 1.5.26-Stable (senu takaa ama busani) 27-March-2012
Joomla! Configured :: Yes | Read-Only (444) | Owner: jimfidler (uid: 737966/gid: 195784) | Group: pg574147 (gid: 195784) | Valid For: 1.5
Configuration Options :: Offline: 0 | SEF: 1 | SEF Suffix: 1 | SEF ReWrite: 1 | .htaccess/web.config: Yes | GZip: 0 | Cache: 0 | FTP Layer: 0 | SSL: 0 | Error Reporting: -1 | Site Debug: 0 | Language Debug: 0 | Database Credentials Present: Yes

Host Configuration :: OS: Linux | OS Version: 2.6.32.8-grsec-2.1.14-modsign-xeon-64 | Technology: x86_64 | Web Server: Apache | Encoding: gzip,deflate,sdch | Doc Root: /home/jimfidler/cfnl.ca | System TMP Writable: Yes

PHP Configuration :: Version: 5.2.17 | PHP API: cgi-fcgi | Session Path Writable: Unknown | Display Errors: 1 | Error Reporting: 6135 | Log Errors To: | Last Known Error: | Register Globals: | Magic Quotes: | Safe Mode: | Open Base: | Uploads: 1 | Max. Upload Size: 7M | Max. POST Size: 8M | Max. Input Time: 60 | Max. Execution Time: 30 | Memory Limit: 90M

MySQL Configuration :: Version: 5.1.53-log (Client:5.0.51a) | Host: --protected-- (--protected--) | Collation: utf8_general_ci (Character Set: utf8) | Database Size: 10.65 MiB | #of _FPA_TABLE: 53
Detailed Environment :: wrote:
PHP Extensions :: date (5.2.17) | libxml () | openssl () | pcre () | zlib (1.1) | bcmath () | calendar () | ctype () | curl () | dom (20031129) | hash (1.0) | filter (0.11.0) | ftp () | gd () | gettext () | session () | iconv () | standard (5.2.17) | json (1.2.1) | mbstring () | mcrypt () | mhash () | mysql (1.0) | SimpleXML (0.1) | pcntl () | SPL (0.2) | PDO (1.0.4dev) | pdo_mysql (1.0.2) | pdo_sqlite (1.0.1) | posix () | pspell () | Reflection (0.1) | imap () | mysqli (0.1) | sockets () | SQLite (2.0-dev) | exif (1.4 $Id: exif.c 293036 2010-01-03 09:23:27Z sebastian $) | tokenizer (0.1) | xml () | xmlreader (0.1) | xmlwriter (0.1) | xsl (0.1) | cgi-fcgi () | Zend Optimizer () | Zend Engine (2.2.0) |
Potential Missing Extensions :: zip | suhosin |

Switch User Environment (Experimental) :: PHP CGI: Yes | Server SU: Yes | PHP SU: Yes | Custom SU (LiteSpeed/Cloud/Grid): Yes
Potential Ownership Issues: No
Folder Permissions :: wrote:
Core Folders :: images/ (755) | components/ (755) | modules/ (755) | plugins/ (755) | language/ (755) | templates/ (755) | cache/ (755) | logs/ (755) | tmp/ (755) | administrator/components/ (755) | administrator/modules/ (755) | administrator/language/ (755) | administrator/templates/ (755) |

Elevated Permissions (First 10) :: None
Database Information :: wrote:
Database _FPA_STATS :: Uptime: 3704699 | Threads: 2 | Questions: 74938820 | Slow queries: 646390 | Opens: 1191526 | Flush tables: 44 | Open tables: 350 | Queries per second avg: 20.228 |
Extensions Discovered :: wrote:
Components :: SITE :: Wrapper (1.5.0) | User (1.5.0) | MailTo (1.5.0) |
Components :: ADMIN :: Menus Manager (1.5.0) | Polls (1.5.0) | Trash (1.0.0) | Newsfeeds (1.5.0) | Plugin Manager (1.5.0) | Language Manager (1.5.0) | Installation Manager (1.5.0) | Admintools (2.2.a2) | Mass Mail (1.5.0) | Akeeba (3.4.3) | Search (1.5.0) | Weblinks (1.5.0) | Configuration Manager (1.5.0) | Content Page (1.5.0) | Contact Items (1.0.0) | Banners (1.5.0) | Media Manager (1.5.0) | Cache Manager (1.5.0) | User Manager (1.5.0) | Module Manager (1.5.0) | Frontpage (1.5.0) | Control Panel (1.5.0) | Template Manager (1.5.0) | Messaging (1.5.0) |

Modules :: SITE :: Custom HTML (1.5.0) | Statistics (1.5.0) | Poll (1.5.0) | Most Read Content (1.5.0) | Wrapper (1.0.0) | RokSlideshow (4.2) | Footer (1.5.0) | Who\'s Online (1.0.0) | Banner (1.5.0) | Syndicate (1.5.0) | Related Items (1.0.0) | Login (1.5.0) | Archived Content (1.5.0) | Breadcrumbs (1.5.0) | Menu (1.5.0) | Random Image (1.5.0) | Newsflash (1.5.0) | Latest News (1.5.0) | Search (1.0.0) | Feed Display (1.5.0) | Sections (1.5.0) |
Modules :: ADMIN :: Unread Items (1.0.0) | User Status (1.5.0) | Custom HTML (1.5.0) | Logged in Users (1.0.0) | Items Stats (1.0.0) | Online Users (1.0.0) | Latest News (1.0.0) | Title (1.0.0) | Footer (1.0.0) | Admin Menu (1.0.0) | Quick Icons (1.0.0) | Popular Items (1.0.0) | Admin Submenu (1.0.0) | Toolbar (1.0.0) | Login Form (1.0.0) | Admin Tools Joomla! Upgrade No (2.2.a2) | Akeeba Backup Notification Mod (3.4.3) | Feed Display (1.5.0) |

Plugins :: SITE :: Editor - XStandard Lite for Jo (1.0) | Editor - TinyMCE 3 (3.2.6) | Editor - Artof Editor (1.0.4) | Button - Readmore (1.5) | Button - Image (1.0.0) | Button - Pagebreak (1.5) | Content - Email Cloaking (1.5) | Content - Pagebreak (1.5) | Content - Example (1.0) | Content - Vote (1.5) | Content - Page Navigation (1.5) | Content - Code Highlighter (Ge (1.5) | Content - Load Modules (1.5) | Authentication - GMail (1.5) | Authentication - Joomla (1.5) | Authentication - Example (1.5) | Authentication - LDAP (1.5) | Authentication - OpenID (1.5) | Search - Contacts (1.5) | Search - Content (1.5) | Search - Newsfeeds (1.5) | Search - Categories (1.5) | Search - Weblinks (1.5) | Search - Sections (1.5) | System - Backlinks (1.5) | System - Log (1.5) | System - Admin Tools Update Em (1.0) | System - Cache (1.5) | System - Mootools Upgrade (1.5) | System - Legacy (1.5) | System - Admin Tools (2.2.a2) | System - Debug (1.5) | Akeeba Backup Lazy Scheduling (3.3) | System - Remember Me (1.5) | System - SEF (1.5) | System - Joomla! Update Email (1.0) | User - Joomla! (1.5) | User - Example (1.0) | XML-RPC - Joomla API (1.0) | XML-RPC - Blogger API (1.0) |
Templates Discovered :: wrote:
Templates :: SITE :: JA_Purity (1.2.0) | rt_chromatophore_j15 (1.5.1) | rhuk_milkyway (1.0.2) | beez (1.0.0) |
Templates :: ADMIN :: Khepri (1.0) |


Top
 Profile  
 
PostPosted: Wed Aug 01, 2012 12:31 am 
User avatar
Joomla! Master
Joomla! Master

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11629
Location: The Girly Side of Joomla in Sussex
here are some pointers that need looking at
Owner: jimfidler (uid: 737966/gid: 195784) | Group: pg574147 (gid: 195784) would normally be the same on suphp servers - may cause permissions issues but this may be explained with " Custom SU (LiteSpeed/Cloud/Grid): Yes"
and
Editor - XStandard Lite for Jo (1.0) - out of date
Admintools (2.2.a2) - akeeba? out of date

now assuming you got your template legitimately from RT, then it may be you need to spring clean, and visit google webmaster panel and investigate these suspect links

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Wed Aug 01, 2012 12:47 am 
Joomla! Enthusiast
Joomla! Enthusiast

Joined: Mon Mar 31, 2008 8:28 pm
Posts: 106
Location: St. John's, Newfoundland, Canada
Thanks so much for your reply: I'm not at all sure what the following (from your reply) means however:
here are some pointers that need looking at
Owner: jimfidler (uid: 737966/gid: 195784) | Group: pg574147 (gid: 195784) would normally be the same on suphp servers - may cause permissions issues but this may be explained with " Custom SU (LiteSpeed/Cloud/Grid): Yes"

I do have a legitimate template from RT.

I just actually replaced all of the joomla files but I left the template alone as I was concerned about breaking any customization I did to it.

Any other suggestions are greatly welcome.

Many thanks,

Lillian


Top
 Profile  
 
PostPosted: Wed Aug 01, 2012 12:53 am 
User avatar
Joomla! Master
Joomla! Master

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11629
Location: The Girly Side of Joomla in Sussex
sometimes the fpa doesnt pick up the cloud settings correctly, it was a pointer to look at.
if you have been hacked then just replacing the files is inadequate, follow checklist 7 safe route to recovery

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Wed Aug 01, 2012 12:57 am 
Joomla! Enthusiast
Joomla! Enthusiast

Joined: Mon Mar 31, 2008 8:28 pm
Posts: 106
Location: St. John's, Newfoundland, Canada
Thanks, would you mind pointing me to checklist 7 please? Thanks so much


Top
 Profile  
 
PostPosted: Wed Aug 01, 2012 1:01 am 
User avatar
Joomla! Master
Joomla! Master

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11629
Location: The Girly Side of Joomla in Sussex
its listed in the sticky called "before you post- read this" but http://docs.joomla.org/Security_Checklist_7

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 



Who is online

Users browsing this forum: No registered users and 12 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group