Joomla! Discussion Forums



It is currently Wed Nov 25, 2009 3:22 pm (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 5 posts ] 
Author Message
Posted: Fri Nov 06, 2009 4:40 am 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu Aug 10, 2006 3:34 pm
Posts: 26
had my sites defaced today via dropping a 404.php file into my /tmp folder of a site. granted this was running on a older version of joomla. 1.5.0 or 1.5.1 ... i actually thank Red-D3v1L for reminding me of security. could have been worse.
can anyone explain how this was done and is it capable of happening on 1.5.14 or .15?

regards


Top
   
 
Posted: Fri Nov 06, 2009 7:39 am 
User avatar
Joomla! Hero
Joomla! Hero
Offline

Joined: Thu Jul 24, 2008 12:48 pm
Posts: 2067
Location: Austin, TX
In case you haven't updated and need help, I wrote a quick page to help:
http://www.cmsmarket.com/resources/dev-corner/101-how-to-update-joomla

If this was a know exploit in the version of Joomla! you are using, it should be fixed by upgrading. It's possible that it was an exploit with the version of apache you are running or a 3rd party Joomla! component you have installed or a number of other things.

There are also some extensions out there that may help you avoid this kind of thing happening in the future:
http://extensions.joomla.org/extensions/access-a-security/site-security

Eyesite seems like a really cool one that I eventually need to look into:
http://extensions.joomla.org/extensions/access-a-security/site-security/9149


If you find anything you like, post back here because I'd love to know as well.

_________________
Will Mavis - Joomla Extension Developer
http://www.cmsmarket.com/
http://www.sourcecoast.com/
If you think I can help you, feel free to PM me a link to your post and I will respond. Please don't hijack another user's thread. :D


Top
  E-mail  
 
Posted: Mon Nov 09, 2009 8:57 am 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Mon Nov 09, 2009 7:37 am
Posts: 3
Thanks wlrdq for posting such useful links. I had the same problem and looking for solution. You really did great job for people like me.

_________________
Please read forum rules regarding signatures: viewtopic.php?t=65


Top
  E-mail  
 
Posted: Mon Nov 09, 2009 4:07 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Tue Jun 09, 2009 2:21 am
Posts: 1262
Location: WV
You should be very concerned. How did they manage to write that file, THAT's what you need to find out. Was it in your site's tmp/ or the server's root /tmp/ ?

_________________
http://jeffchannell.com - Joomla Extensions & Web Development
Unsolicited private messages/emails asking for help = you wish to hire me to fix your problem.
καλλιστι


Top
   
 
Posted: Mon Nov 09, 2009 4:14 pm 
User avatar
Joomla! Guru
Joomla! Guru
Online

Joined: Sat Oct 21, 2006 10:20 pm
Posts: 730
Location: Wisconsin USA
Any directory that because of server setup that needs 777 permissions to enable Joomla to function properly* can be hacked very easily by basic site hacking scripts. Also any file that has permissions of 777 so you can edit it* on improperly configured servers will be subject to hacking by basic hacking scripts.

* Joomla only needs a max of 755/644 to function properly on a properly configured server

This is one way (there are many others) they can install php scripts in /tmp, /images, and so on directories so they can execute them. You can place an .htaccess file in these directories that can prevent execution of php code (at least by script-kiddies) from these "unprotected" directories.

I looked at Eyesite awhile back and in my opinion Eyesite basically just makes a list of the file dates and if any dates change then it flags the file as being altered. There are ways of not changing the date/time stamp of a file as well as If Eyesite is run on an infected site it does no good.

There are many exploits out there and the versions of Joomla you had I think (without looking it up again) had some sql injection holes. Regardless, there are many ways someone can get into your site. Including getting the credentials necessary from your computer without your knowledge.

Upgrading your site if not thoroughly cleaned of any compromises (the code hides in amazing places once you are hacked) just means your site is not showing signs of the hack, but could still be infected by a backdoor. This is a mistake many posters here make. The time to upgrade is Before your hacked, not after.

I suggest that you read the Security Checklist http://docs.joomla.org/Category:Security_Checklist

Check your extensions against http://docs.joomla.org/Vulnerable_Extensions_List_oct and remove any that match the version numbers or are of an earlier version.

There are a huge number of forum topics in the security forum dealing iframe and other common attacks, including attacks from ones own computer. These also contain some good security information, including a few that describe a basic attack. I suggest you search and check them out.

_________________
Phil


Top
   
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 5 posts ] 

Quick reply

 



Who is online

Users browsing this forum: ant, psrch and 27 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group