Joomla! Discussion Forums



It is currently Wed Nov 25, 2009 1:02 am (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 11 posts ] 
Author Message
 Post subject: Hacked By X
Posted: Sun Nov 02, 2008 6:29 pm 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Wed Sep 07, 2005 10:18 pm
Posts: 287
Location: London
I was hacked by this guy

Hacked By X

I cant quite see what has made it take over my site, its a very basic page, if anyone knows how or where he has done this if he has done the same to you I'd like to know. I can't see any kind of redirect etc..im faced with reinstall of latest version as it is. I also dont like how joomla exposes the database password in the configuration text file, that is so bad, surely.

_________________
Caribbean Diving Resorts with Joomla: http://caribbean-diving.com


Top
  E-mail  
 
 Post subject: Re: Hacked By NeTBey
Posted: Sun Nov 02, 2008 6:55 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Tue Sep 06, 2005 11:18 am
Posts: 1119
Location: Germany
on top of this forum is a :

HAVE YOU BEEN HACKED, READ THIS

post... it might be a good idea to check that post..

_________________
MCITP - Microsoft Certified IT Professional
CCNA - Cisco Certfied Network Administrator
LPI - Linux Professional
PN for Online Transcript ID Check
http://www.mindset.de


Top
  E-mail  
 
 Post subject: Re: Hacked By X
Posted: Mon Nov 03, 2008 11:07 pm 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Wed Sep 07, 2005 10:18 pm
Posts: 287
Location: London
He must have access to ftp somehow ???? as he changed the index.php page inside my template folder...I dont know if he could see my site passwords therefore or if he was able to just inject the file through the ftp...Is it better to turn the ftp option off I have no idea how it helps anyway ? I have changed the index page back and upgraded to 1.5.7 lets see what happens...

_________________
Caribbean Diving Resorts with Joomla: http://caribbean-diving.com


Top
  E-mail  
 
 Post subject: Re: Hacked By X
Posted: Mon Nov 03, 2008 11:15 pm 
User avatar
Joomla! Master
Joomla! Master
Offline

Joined: Fri Aug 12, 2005 12:38 am
Posts: 11197
Location: Sydney - Australia
Reset your passwords.. all your passwords.

_________________
Brad Baker - Follow me on Twitter @xyzulu @rochenhost
http://www.rochen.com - Joomla! Hosting, the correct way.
http://www.joomlatutorials.com <-- Joomla Help
..somewhere in this hospital the anguished oink of a pig man cries out for help..


Top
  E-mail  
 
 Post subject: Re: Hacked By X
Posted: Mon Nov 03, 2008 11:38 pm 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Wed Sep 07, 2005 10:18 pm
Posts: 287
Location: London
yes i imagine he could see them, this is why i think its strange that they are kept in the public level.and not a directory up above the http (public or htdocs) folder

_________________
Caribbean Diving Resorts with Joomla: http://caribbean-diving.com


Top
  E-mail  
 
 Post subject: Re: Hacked By X
Posted: Tue Nov 04, 2008 5:36 am 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Thu Jul 31, 2008 2:10 am
Posts: 2
2 days ago my site was hacked by [REMOVED] hacker I have his script he used w/ IFRAMES and a bit of php from another page, I am not sure I should share the source but anyone that would like to know should get together with me to figure out how to protect ourselves for future reference.

I am now currently running a trojan executer that reports on the hour everytime a different port has been used.


Top
  E-mail  
 
 Post subject: Re: Hacked By X
Posted: Tue Nov 04, 2008 8:44 am 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Wed Sep 07, 2005 10:18 pm
Posts: 287
Location: London
what is it with the [REMOVED] don't they have better more worthwhile things to do ? They say hackers have small dicks ? I guess this hacking makes them feel good about something.

[MOD Note] country references removed, irrelevant and infamitory

_________________
Caribbean Diving Resorts with Joomla: http://caribbean-diving.com


Top
  E-mail  
 
 Post subject: Re: Hacked By X
Posted: Fri Nov 07, 2008 5:34 am 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Fri Mar 28, 2008 5:40 am
Posts: 17
Location: Australia
Have you flatterned the urls? We have seen of late quite a few instances where hackers have tried to do SQL injections from external sites. For example they have had http://www.sitename..../index.php?itemi ... /xxxx.php.. In turn if the hosting providers security is not very strong or your file permissions are not to standard then the hackers in question can potentially get access to any file on a server.

_________________
Thanks,

Neil


Top
  E-mail  
 
 Post subject: Re: Hacked By X
Posted: Fri Nov 07, 2008 6:00 am 
User avatar
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Tue Nov 04, 2008 10:10 am
Posts: 6
Location: Del Mar
suncoast wrote:
Have you flatterned the urls? We have seen of late quite a few instances where hackers have tried to do SQL injections from external sites. For example they have had http://www.sitename..../index.php?itemi ... /xxxx.php.. In turn if the hosting providers security is not very strong or your file permissions are not to standard then the hackers in question can potentially get access to any file on a server.


Hey Andrew,

Can you give me more information on what you mean by flattened URL's?

Thanks,

_________________
http://www.mid-century-furniture.com
http://www.buy-smart-car.com


Top
  E-mail  
 
 Post subject: Re: Hacked By X
Posted: Fri Nov 07, 2008 1:55 pm 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Thu Jul 31, 2008 2:10 am
Posts: 2
yes, please ... i iwll look into it tonight too, if I find anything I'll post.

THanks for the response guys


Top
  E-mail  
 
 Post subject: Re: Hacked By X
Posted: Fri Nov 07, 2008 4:23 pm 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Sat Apr 26, 2008 6:05 am
Posts: 275
Location: New Jersey
If security was that easy. I assume that you meant to enable sef right? It doesnt protect you from anything if you dont take the right actions. Btw, these people are not hackers, they are dumb script kidd0z.


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 11 posts ] 

Quick reply

 



Who is online

Users browsing this forum: bochaka, Delvasse and 18 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group