The Joomla! Forum ™



Forum rules


Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 117 posts ]  Go to page Previous  1, 2, 3, 4
Author Message
PostPosted: Sun Jun 13, 2010 1:04 pm 
Joomla! Fledgling
Joomla! Fledgling

Joined: Sun Jun 13, 2010 8:53 am
Posts: 1
I use MySQL. Is there any way to protect it for the case your talk about? Thus, attacking my php files, the database is still protected?
Thanks, Dr. Ian Way.

_________________
Dr. Ian Way
http://www.scibet.com


Top
 Profile  
 
PostPosted: Sun Jun 13, 2010 5:52 pm 
Joomla! Fledgling
Joomla! Fledgling

Joined: Sun Jun 13, 2010 5:39 pm
Posts: 3
Hi All

I'm new to Joomla and Php. I've similar problem with my site and google suggests that I've the malicious script on 4 places.

http://mysiteurl.com/
http://mysiteurl.com/?feed=rss2
http://mysiteurl.com/?page_id=2
http://mysiteurl.com/p=1&cpage=1

The code looks like this: <script src=http://*rimo-*iano.dk/App_Data/Default.aspx.php
></script>

Any suggestions where I should be looking at to delete it?

Thanks in advance.

Mithai


Last edited by mandville on Sun Jun 13, 2010 6:13 pm, edited 1 time in total.
broke links to prevent infection and spam juice


Top
 Profile  
 
PostPosted: Sun Jun 13, 2010 6:16 pm 
User avatar
Joomla! Master
Joomla! Master
Online

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11642
Location: The Girly Side of Joomla in Sussex
is the extension from a 3rd party? does the link appear anywhere else/

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Mon Jun 14, 2010 1:51 am 
Joomla! Fledgling
Joomla! Fledgling

Joined: Sun Jun 13, 2010 5:39 pm
Posts: 3
Hello Mandville

Thanks for your reply. For the moment the site is running smooth and I can't see the script in the index.php or default.php files both in the template and other files that I've gone through. Google only suggested these URLs to check and since the URLs are dynamic, I have no clue where to look at. Previously there was a script in the index.php in the template folder but I deleted the whole site and installed the script from scratch. then I changed the file permission of index.php to 444 and the script didn't come back. But the google still showing the given urls as infected. Please help. Thanks again.


Top
 Profile  
 
PostPosted: Mon Jun 14, 2010 1:55 am 
Joomla! Fledgling
Joomla! Fledgling

Joined: Sun Jun 13, 2010 5:39 pm
Posts: 3
And yes the extensions are from third party but I've downloaded them from joomla site. Can they still be infected?


Top
 Profile  
 
PostPosted: Mon Jun 14, 2010 4:50 am 
User avatar
Joomla! Master
Joomla! Master
Online

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11642
Location: The Girly Side of Joomla in Sussex
it could be that google just hasnt updated its directory afteryour hack.

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Mon Jul 05, 2010 1:07 pm 
User avatar
Joomla! Ace
Joomla! Ace

Joined: Thu May 01, 2008 12:36 pm
Posts: 1111
Location: QubeSys Technologies Pvt. Ltd ,INDIA
I had malicious codes on index.php all over the sites, even though they were all running on 1.5.18 .

Now, Its all good, but my host said, that the server may have been backdoored, meaning, the hackers may have left some php file somewhere inside , by which they can enter again.

So, how can we find those suspicious files or anything ?

Is there a way to find them ?

_________________
http://www.qubesys.com : Web Design, eCommerce and Software Development
http://www.joomclub.org : Joomla Premium Extensions,Templates and Support Packages


Top
 Profile  
 
PostPosted: Mon Jul 05, 2010 3:43 pm 
User avatar
Joomla! Master
Joomla! Master
Online

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11642
Location: The Girly Side of Joomla in Sussex
security checklist 7, safe route to reovery. unless you have a few hours to spare to huynt every folder on your site and check every file!

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Mon Jul 05, 2010 4:08 pm 
User avatar
Joomla! Ace
Joomla! Ace

Joined: Thu May 01, 2008 12:36 pm
Posts: 1111
Location: QubeSys Technologies Pvt. Ltd ,INDIA
Ok, so images, templates, db backup and then new joomla install and putting them back.

Thats it.

And yes, install the same components and modules and plugins again there on the new one.


mandville wrote:
security checklist 7, safe route to reovery. unless you have a few hours to spare to huynt every folder on your site and check every file!

_________________
http://www.qubesys.com : Web Design, eCommerce and Software Development
http://www.joomclub.org : Joomla Premium Extensions,Templates and Support Packages


Top
 Profile  
 
PostPosted: Mon Jul 05, 2010 7:18 pm 
User avatar
Joomla! Master
Joomla! Master
Online

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11642
Location: The Girly Side of Joomla in Sussex
install up2date versions of your extensions

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Tue Jul 06, 2010 1:50 am 
Joomla! Fledgling
Joomla! Fledgling

Joined: Tue Jul 06, 2010 1:41 am
Posts: 1
just wondering, i understand this but i like to know random stuffm, when you talk about the file .js what does JS stand for?


Last edited by mandville on Tue Jul 06, 2010 2:10 am, edited 1 time in total.
signature against forum rules http://forum.joomla.org/viewtopic.php?f=8&t=65


Top
 Profile  
 
PostPosted: Tue Jul 06, 2010 2:13 am 
User avatar
Joomla! Master
Joomla! Master
Online

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11642
Location: The Girly Side of Joomla in Sussex
juanseomind wrote:
just wondering, i understand this but i like to know random stuffm, when you talk about the file .js what does JS stand for?

apart from the title of this topic giving a clue
try
http://www.google.co.uk/search?q=file+type+suffix
followed by http://www.sharpened.net/helpcenter/extensions.php
and then
http://www.sharpened.net/helpcenter/extensions.php
or
http://filext.com/file-extension/JS

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Wed Aug 25, 2010 12:25 pm 
Joomla! Apprentice
Joomla! Apprentice

Joined: Wed Aug 25, 2010 8:59 am
Posts: 9
js stands for JavaScript. Its a programming language.

_________________
Custom made joomla arcades:
- http://www.tripledoublegames.com
- http://www.playcarparkinggames.com


Top
 Profile  
 
PostPosted: Sat Sep 18, 2010 6:29 am 
Joomla! Enthusiast
Joomla! Enthusiast

Joined: Mon Mar 31, 2008 5:34 pm
Posts: 165
Ok Godaddy websites have been hacked again. I'm getting sick of this one. It's all over the news. The domains that websites are redirected to are hosted on Godaddy too. It's all over the internet.

I can't delete and upload everything again and again, I'm feel like I'm going to puke now. :(

Okay; I called'em right away and they seem to have fixed the website now. So cheers!

_________________
Stay Cool!


Top
 Profile  
 
PostPosted: Thu Sep 30, 2010 4:28 am 
User avatar
Joomla! Apprentice
Joomla! Apprentice

Joined: Thu Sep 30, 2010 3:16 am
Posts: 21
Do we have any extensions to scan our site for malicious javascript ??

_________________
Signature rules: Literal URLs only - viewtopic.php?f=8&t=65


Top
 Profile  
 
PostPosted: Thu Sep 30, 2010 1:13 pm 
User avatar
Joomla! Master
Joomla! Master
Online

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11642
Location: The Girly Side of Joomla in Sussex
vampxlr wrote:
Do we have any extensions to scan our site for malicious javascript ??

before this turns into a self promotional post fest, there are several scripts that claim they can scan for such scripts but are they guaranteeed to get all of them.
you also do not know if nything else is installed.
do it the correct way, the safe route to recovery and the rest of checklist 7 (and this topic)

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Wed Oct 13, 2010 1:20 pm 
User avatar
Joomla! Apprentice
Joomla! Apprentice

Joined: Tue Aug 03, 2010 8:06 pm
Posts: 8
There was some kind of tool I used for scanning a long while ago for my blog because it was getting so many problems of this nature. But this was a couple years and I do not have that tool anymore, but thankfully I have not needed anything like it for a good bit.

_________________
That's right, I'm Jack Bauer. What of it?


Top
 Profile  
 
PostPosted: Fri Oct 15, 2010 12:51 am 
User avatar
Joomla! Apprentice
Joomla! Apprentice

Joined: Mon Aug 04, 2008 3:52 pm
Posts: 15
virustotal.com is good for checking your site to see if it still contains malware.

But I find having a zipped backup only takes half an hour to restore a site properly.

Then just a case of closing off permissions where applicable, changing passwords, checking joomla and plugins, modules etc are up to date.


Top
 Profile  
 
PostPosted: Sun Oct 31, 2010 7:10 pm 
Joomla! Apprentice
Joomla! Apprentice

Joined: Fri May 28, 2010 4:10 pm
Posts: 15
last day my computer get infected by keylogger and my email , paypal and file hosting account hacked , we need to use antivirus applications and even we believe something safe . java script is perfect for useful things and dangerous for hacking attempts too . i hope we make joomla everyday better and better .

_________________
Please read forum rules regarding signatures: viewtopic.php?t=65


Top
 Profile  
 
PostPosted: Mon Nov 29, 2010 11:37 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast

Joined: Sat Dec 31, 2005 7:41 pm
Posts: 117
I was recently hit as well on a site I developed using Joomla 1.5

Here is where the 64Decode script was placed in my files. Hope this helps others.

Quote:
/home1/bajashop/public_html/cms/includes/defines.php
/home1/bajashop/public_html/archive/configuration.php
/home1/bajashop/public_html/archive/globals.php

I am also seeing a couple hacking files located here:

/home1/bajashop/public_html/cms/images/img.php
/home1/bajashop/public_html/archive/priv.php


Top
 Profile  
 
PostPosted: Tue Nov 30, 2010 12:08 am 
User avatar
Joomla! Master
Joomla! Master
Online

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11642
Location: The Girly Side of Joomla in Sussex
Quote:
/home1/bajashop/public_html/archive/configuration.php
/home1/bajashop/public_html/archive/globals.php

J1.x ? as not sure what they are and in an archive folder..

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Thu Dec 02, 2010 2:36 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast

Joined: Sat Dec 31, 2005 7:41 pm
Posts: 117
mandville wrote:
Quote:
/home1/bajashop/public_html/archive/configuration.php
/home1/bajashop/public_html/archive/globals.php

J1.x ? as not sure what they are and in an archive folder..


Version 1.5.22


Top
 Profile  
 
PostPosted: Sat Dec 04, 2010 12:15 am 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast

Joined: Sun Oct 04, 2009 10:37 am
Posts: 164
How easy or hard is it to hack a site with malicious code?

_________________
Best regards,
Streamline

Mājas lapu izstrāde un grafiskais dizains - http://www.majas-lapu-izstrade.lv


Top
 Profile  
 
PostPosted: Sat Dec 04, 2010 12:36 pm 
Joomla! Apprentice
Joomla! Apprentice

Joined: Wed May 06, 2009 10:38 am
Posts: 49
Hackers have many methods of hacking a website.

First, they'll scan it with various tools to look for some known vulnerability. Recently, many sites have been subjected to scanning for phpmyadmin folders.

These probing scans will leave clues in your log files. Look for many GETs or POSTs about the same time and returning 404s (page not found).

The key to protect against this attack is to make sure all software is updated and to follow the security guidelines for all software.

Second, the hackers may try a dictionary attack on various login pages. A dictionary attack uses a dictionary of commonly used passwords and it tries various username and password combinations on login pages. The key here is always use strong passwords.

Third, the hackers may use stolen FTP credentials. These are stolen by viruses on PC used to FTP files to websites. The virus can either search for the file that stores the saved passwords, or "sniff" the FTP traffic. Since FTP transmits all data, including username and password, in plain text, it's easy for the virus to see and steal the login credentials and then logs in as a legitimate user via FTP and infects the website.

The key to protection here is to use SFTP, which encrypts the traffic, and constantly scan your PC for viruses. This hack attack will leave clues in the FTP logs, if you have them activated.

There is also cross-site scripting, SQL injection and a variety of other methods, but if you stick to known, good software, the creators are generally responsible for those types of safeguards.

To answer your question directly, it is easy to hack a website if you don't follow the security guidelines, it's hard if you do.


Top
 Profile  
 
PostPosted: Sat Dec 04, 2010 11:42 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast

Joined: Sun Oct 04, 2009 10:37 am
Posts: 164
Thanks for the detailed answer WeWatch!
You actually made me alert and I'm a bit scared of these damn viruses now since they can easily steal my data. Of course I'm using anti-virus software, but they only fights the consequences ...

Guess it's time to start thinking of data synchronization.

_________________
Best regards,
Streamline

Mājas lapu izstrāde un grafiskais dizains - http://www.majas-lapu-izstrade.lv


Top
 Profile  
 
PostPosted: Fri Dec 24, 2010 3:52 am 
User avatar
Joomla! Master
Joomla! Master

Joined: Mon Aug 29, 2005 10:17 am
Posts: 11987
Location: Netherlands/ UK/ S'pore/Jakarta/ North America
Can we please stay on topic: Malicious Javascript in your site?

Thanks!

Leo 8)

_________________
--- Joomla Professional Support Services :: http://gws-desk.com ---
--- Joomla Professional and Specialized Hosting :: http://gws-host.com ---
--- Ready to Roll Joomla! Web Sites : 1 - 7 days only! :: @ gws-market.com ---


Top
 Profile  
 
PostPosted: Sat Jan 15, 2011 2:07 am 
Joomla! Fledgling
Joomla! Fledgling

Joined: Wed Oct 13, 2010 8:56 am
Posts: 3
I thank your problem was solve....


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 117 posts ]  Go to page Previous  1, 2, 3, 4



Who is online

Users browsing this forum: slow riot and 14 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group