Joomla! Discussion Forums



It is currently Wed Nov 25, 2009 10:53 pm (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 5 posts ] 
Author Message
 Post subject: Website hacked
Posted: Thu Nov 05, 2009 1:30 pm 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Thu Nov 05, 2009 1:13 pm
Posts: 2
Somebody hacked my Joomla 1.0 and 1.5 sites.
I repair 1.5 sites by changing index.php of a fresh joomla. But i cann't solve the problem with joomla 1.0 sites. pls my site is here:

http://www.bid-bd.org/

also change the Back-end password.

Pls Some one help.


Top
  E-mail  
 
 Post subject: Re: Website hacked
Posted: Thu Nov 05, 2009 2:16 pm 
User avatar
Joomla! Virtuoso
Joomla! Virtuoso
Offline

Joined: Mon Mar 20, 2006 1:56 am
Posts: 3703
Location: The Girly Side of Joomla in Sussex
please run the forum post tool viewtopic.php?f=428&t=272481
and post the results

_________________
HU2HY - GIGO - Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and just deleted
http://community.joomla.org/ Connect Administrator
Avez-vous lu les instructions ? Avez-vous recherché ?


Top
   
 
 Post subject: Re: Website hacked
Posted: Thu Nov 05, 2009 2:29 pm 
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Wed Aug 05, 2009 1:42 pm
Posts: 487
Greetings:

Clean up the hacks; your hosting provider support team should be able to help you.

Upgrade to Joomla 1.5.15 and follow http://docs.joomla.org/Category:Security_Checklist

Thank you.

_________________
Peter M. Abraham
http://www.dynamicnet.net/ - Dynamic Net, Inc. - in business since June 1995; a PCI Compliant, managed hosting provider.


Top
  E-mail  
 
 Post subject: Re: Website hacked
Posted: Thu Nov 05, 2009 5:28 pm 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Thu Nov 05, 2009 1:13 pm
Posts: 2
I Clean up it from index.php but steel the problem.
can u help me where the hacked file could be?
i check in index.php of templates and also in administrator's index.php file.


Top
  E-mail  
 
 Post subject: Re: Website hacked
Posted: Thu Nov 05, 2009 5:41 pm 
User avatar
Joomla! Virtuoso
Joomla! Virtuoso
Offline

Joined: Mon Mar 20, 2006 1:56 am
Posts: 3703
Location: The Girly Side of Joomla in Sussex
* you were asked to run the forum post tool, where are the results?
* you were told to follow the security checklist - did you?
* did you speak to your host?
* have you got a recent back up of your site?
if so then follow these Directions

1. Change all relevant passwords: Assume your passwords have been harvested and immediately change all critical passwords, including shell access, FTP access, Joomla! Administrator accounts, and the database account.
2. Check raw logs: Identify when and how the attackers gained access to your site by carefully reviewing your raw server logs. Make careful note of the date/time and names of attacked files. Note that these logs may have been deleted or altered, so a lack of evidence does not prove a lack of activity.
3. List recently modified files: Before making any changes to your site, generate a list of recently modified files. Here's a php script that will list the files for you. Remove this script as soon as you have your list and don't publish a link to it!
4. Note suspicious newly-created files: Use this list to identify new files that don't belong. Pay particular attention to their creation and modification dates, and correlate them to the dates of attacks shown in your log files.
5. Note suspicious recently-modified files: Check the modified files list for any files that were recently changed. Pay particular attention to the modification, and correlate them to the dates of attacks shown in your log files.
6. Check for bogus CRON Jobs: Hacked cron jobs can be setup to reinfect your site over and over again.
7. Coordinate with your host: If you have identified how you were cracked, report the method to your host. If you are on a shared server, you may habe been attacked through another vulnerable site on your server. Report this to your host. A reputable host will appreciate your efforts in this area.
8. Delete the entire public_html directory: This is the best way to guarantee that every potential vulnerability in that site is removed.
9. Delete related database records: This step may only be possible if you have good backups. Simple script kiddies, who are only trying to mark your index page, may not attack your database, but professionals are usually very interested in confidential data, such as passwords. They may pose as script kiddies to avoid suspicion while repeatedly harvesting confidential information from your database.
10. Reinstall everything: Use pre-crack backups. If you don't have good backups, go on to step 10.
11. Reset critical passwords again: You must reset your passwards again now that your server is finally cleaned of any possible, hidden trojan horses.
12. Rebuild site: If you are unable to rebuild from clean backups, rebuild your entire site using original, pre-crack installs. Use only the latest stable versions of all software, and check the List of Vulnerable Extensions
13. Review security processes: Follow standard security precautions for important settings in php.ini, globals.php, configuration.php, .htaccess, etc.
14. Review backup processes: If you don't already have one, add a dependable backup process to your site administration practices.
15. Stay watchful: Attackers often return repeatedly. Closely monitor your raw logs for suspicious activity.
16. Virus check your PC and everyone else who has access to your site

_________________
HU2HY - GIGO - Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and just deleted
http://community.joomla.org/ Connect Administrator
Avez-vous lu les instructions ? Avez-vous recherché ?


Top
   
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 5 posts ] 

Quick reply

 



Who is online

Users browsing this forum: No registered users and 31 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group