Delete CHANGELOG.php?

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
neptun81
Joomla! Fledgling
Joomla! Fledgling
Posts: 1
Joined: Mon Feb 21, 2011 2:03 pm

Delete CHANGELOG.php?

Post by neptun81 » Mon Feb 21, 2011 2:10 pm

I have had some new files on the server, and I find that is C99Shell.U trojan, and i delete all, but for CHANGELOG.php (380KB) antivirus said it is WEBShell.BU trojan, and i can`t copy. Is it safe to delete file, or to replace with other CHANGELOG.php?

User avatar
Tonie
Joomla! Master
Joomla! Master
Posts: 16553
Joined: Thu Aug 18, 2005 7:13 am

Re: Delete CHANGELOG.php?

Post by Tonie » Mon Feb 21, 2011 2:45 pm

You can also completely remove CHANGELOG.php, it is not a necessary file.

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: Delete CHANGELOG.php?

Post by mandville » Mon Feb 21, 2011 4:15 pm

A Safe route for disaster relief

* save the configuration.php file and your images and personal files one by one, (not the folder as it may contain unwanted files)
* wipe the entire folder where Joomla! is installed
* upload a new clean full package latest version of joomla 1.5.x (minus the install folder)
* reupload your configuration file & images, templates (even better is to use original clean copies to ensure that the hacker/defacer did not leave any shell script files in your site)
* reupload or reinstall the latest versions of your extensions.

To do this will take your site off line for around 15 minutes. To track down your hacked/defaced html may take hours or even longer
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}


Locked

Return to “Security in Joomla! 1.5”