My Website is infected with malware

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
monty777
Joomla! Apprentice
Joomla! Apprentice
Posts: 5
Joined: Sat Aug 18, 2012 10:09 pm

My Website is infected with malware

Post by monty777 » Mon Aug 20, 2012 12:02 am

Hi,

My website is infected with malware. I dont know how to fix this. The hosting support has restored the website though it is no more blacklisted but still there is a malware. Here are the results, please help:
Last PHP Error(s) Reported :: Forum Post Assistant (v1.2.1) : 19th August 2012 wrote:[19-Aug-2012 05:20:26] PHP Warning: Invalid argument supplied for foreach() in /home1/dargahm1/public_html/mohrasharif.com/components/com_easybook/helpers/menu.php on line 25
Forum Post Assistant (v1.2.1) : 19th August 2012 wrote:
Basic Environment :: wrote:Joomla! Instance :: Joomla! 1.5.15-Stable (Wojmamni Ama Mamni) 05-November-2009
Joomla! Configured :: Yes | Read-Only (444) | Owner: dargahm1 (uid: 658/gid: 658) | Group: dargahm1 (gid: 658) | Valid For: 1.5
Configuration Options :: Offline: 0 | SEF: 0 | SEF Suffix: 0 | SEF ReWrite: 0 | .htaccess/web.config: Yes | GZip: 0 | Cache: 0 | FTP Layer: 0 | SSL: 0 | Error Reporting: -1 | Site Debug: 0 | Language Debug: 0 | Database Credentials Present: Yes

Host Configuration :: OS: Linux | OS Version: 2.6.32-20120131.55.1.bh6.x86_64 | Technology: x86_64 | Web Server: Apache | Encoding: gzip,deflate,sdch | Doc Root: /home1/dargahm1/public_html/mohrasharif.com | System TMP Writable: Yes

PHP Configuration :: Version: 5.2.17 | PHP API: cgi-fcgi | Session Path Writable: Unknown | Display Errors: | Error Reporting: 6135 | Log Errors To: error_log | Last Known Error: 19th August 2012 05:20:26. | Register Globals: | Magic Quotes: 1 | Safe Mode: | Open Base: | Uploads: 1 | Max. Upload Size: 10M | Max. POST Size: 10M | Max. Input Time: 60 | Max. Execution Time: 30 | Memory Limit: 64M

MySQL Configuration :: Version: 5.1.63-community-log (Client:5.1.63) | Host: --protected-- (--protected--) | Collation: utf8_general_ci (Character Set: utf8) | Database Size: 445.97 MiB | #of _FPA_TABLE: 168
Detailed Environment :: wrote:PHP Extensions :: date (5.2.17) | libxml () | openssl () | pcre () | zlib (1.1) | bcmath () | bz2 () | calendar () | ctype () | curl () | dba () | dbase () | dom (20031129) | hash (1.0) | filter (0.11.0) | ftp () | gd () | gettext () | gmp () | session () | iconv () | standard (5.2.17) | json (1.2.1) | ldap () | mbstring () | mcrypt () | mhash () | mime_magic (0.1) | mysql (1.0) | SimpleXML (0.1) | ncurses () | odbc (1.0) | pcntl () | SPL (0.2) | PDO (1.0.4dev) | pdo_dblib (1.0.1) | pdo_mysql (1.0.2) | PDO_ODBC (1.0.1) | pdo_pgsql (1.0.2) | pdo_sqlite (1.0.1) | pgsql () | posix () | pspell () | readline () | Reflection (0.1) | imap () | shmop () | mysqli (0.1) | soap () | sockets () | SQLite (2.0-dev) | exif (1.4 $Id: exif.c 293036 2010-01-03 09:23:27Z sebastian $) | sysvmsg () | sysvsem () | sysvshm () | tidy (2.0) | tokenizer (0.1) | wddx () | xml () | xmlreader (0.1) | xmlrpc (0.51) | xmlwriter (0.1) | xsl (0.1) | zip (1.8.11) | cgi-fcgi () | ionCube Loader () | Zend Optimizer () | Zend Engine (2.2.0) |
Potential Missing Extensions :: suhosin |

Switch User Environment (Experimental) :: PHP CGI: Yes | Server SU: Yes | PHP SU: Yes | Custom SU (LiteSpeed/Cloud/Grid): Yes
Potential Ownership Issues: No
Folder Permissions :: wrote:Core Folders :: images/ (755) | components/ (755) | modules/ (755) | plugins/ (755) | language/ (755) | templates/ (755) | cache/ (755) | logs/ (755) | tmp/ (755) | administrator/components/ (755) | administrator/modules/ (755) | administrator/language/ (755) | administrator/templates/ (755) |

Elevated Permissions (First 10) :: None blogs/wp-content/flgallery/ (777) | blogs/wp-content/flgallery/images/ (777) | blogs/wp-content/flgallery/tmp/ (777) | blogs/wp-content/flgallery/xml/ (777) | modules/mod_swmenufree/ (757) | modules/mod_swmenufree/cache/ (757) | modules/mod_swmenufree/images/ (757) | modules/mod_swmenufree/images/transmenu/ (757) | modules/mod_swmenufree/styles/ (757) |
Extensions Discovered :: wrote:Components :: SITE :: Black (1.0.0) | User (2.0.3) | Banners (2.0.2) | Search (2.0.4) | aiContactSafe (1.0.0) | Content (2.0.13) | Mail To (2.0.1) | NewsFeeds (2.0.2) | WebLinks (2.0.2) | Wrapper (2.0.2) | AlphaContent (2.0.1) | Contacts (2.0.2) | QContacts (2.0.0) | MailTo (1.5.0) | User (1.5.0) | Wrapper (1.5.0) |
Components :: ADMIN :: PhocaGallery (2.6.2) | QContacts (1.0.6) | Language Manager (1.5.0) | Menus Manager (1.5.0) | Search (1.5.0) | Messaging (1.5.0) | Installation Manager (1.5.0) | Content Page (1.5.0) | User Manager (1.5.0) | JEvents (1.5.3 (B1629)) | AlphaContent (4.0.15) | AlphaRegistration (2.0.9) | SEF (3.5.4) | aiContactSafe (1.0.0) | aiContactSafe - Link (1.0.4.stable) | aiContactSafe - Form (1.0.8.stable) | aiContactSafe module (1.0.7.stable) | aiContactSafe (2.0.7.stable) | Polls (1.5.0) | Agora (3.0.08 Olympu) | JEvents Plugin (1.0.3) | Hot Property Plugin (1.0.1) | Virtuemart Plugin (1.1.3) | Gallery2 Bridge Plugin (1.0.2) | JoomDOC Extension (1.0.0) | SectionEx Plugin (1.0.2) | Mosets Tree Plugin (1.0.1) | SOBI2 Plugin (1.5.0) | Agora Plugin (1.0.0) | DOCman Plugin (1.5.0) | MyBlog Plugin (1.0.0) | Jomres Plugin (1.0) | Glossary Plugin (1.0.0) | Remository Plugin (1.0.3) | JoomSuite Resources Plugin (1.0.0) | Kunena Plugin (1.0.1) | Content Plugin (1.5.0) | JDownloads Plugin (1.5.0) | Eventlist Plugin (1.0.0) | Rapid Recipe Plugin (1.0.0) | KnowledgeBase Plugin (1.0.0) | JoomGallery Plugin (1.0.0) | JCALPro Plugin (1.0.0) | Contacts Plugin (1.0.1) | Rokdownloads Plugin (1.0.4) | RSGallery2 Extension (1.0.0) | Xmap (1.2.6) | Frontpage (1.5.0) | NoticeBoard (1.3) | Configuration Manager (1.5.0) | swMenuFree (5.2) | Contact Items (1.0.0) | Jumi (2.0.6) | Jumi (2.0.6) | System - Jumi Router (2.0.6) | Jumi (2.0.6) | new_gallery (V1.0) | Plugin Manager (1.5.0) | Newsfeeds (1.5.0) | Trash (1.0.0) | hpalbum (1.0.1) | Control Panel (1.5.0) | Banners (1.5.0) | Template Manager (1.5.0) | AvReloaded (1.2.6) | Media Manager (1.5.0) | JoomlaStats (3.0.2) | Mass Mail (1.5.0) | AcyMailing Tag : Manage the Su (1.1.3) | AcyMailing Tag : online links (1.1.3) | AcyMailing Tag : Joomla User I (1.1.3) | User - AcyMailing (1.1.3) | AcyMailing : Statistics Plugin (1.1.3) | AcyMailing Tag : Subscriber in (1.1.3) | AcyMailing Tag : content inser (1.1.3) | AcyMailing Tag : Date / Time (1.1.3) | AcyMailing onPrepareContent tr (1.1.3) | AcyMailing Template Class Repl (1.1.3) | AcyMailing Module (1.1.3) | AcyMailing (1.1.3) | Agora Olympus Discuss Plugin (1.0.0) | JoomlaPack Backup Notification (1.0) | JoomlaPack (2.4.1) | Cache Manager (1.5.0) | Tag (1.3.0) | Weblinks (1.5.0) | Module Manager (1.5.0) | JCE (1.5.7.4) | JComments (2.2.0.2) | EasyBook (2.0 rc4) |

Modules :: SITE :: c7collapze (1.5.0) | Slick RSS (1.5.0) | Most Read Tags (1.7) | PixSearch (0.4.0) | Related Items (1.0.0) | Who\'s Online (1.0.0) | Breadcrumbs (1.5.0) | Banner (1.5.0) | YOOiecheck (1.5.2) | Page Peel Banner (1.1.2) | Newsflash (1.5.0) | Jumi (2.0.6) | Quran Verse (1.5.x.0) | AcyMailing Module (1.1.3) | Poll (1.5.0) | Extended Menu (1.0.6 (build ) | Salaat Times (1.5.x.0) | JoomlaStats Flags (3.0.0) | Most Read Content (1.5.0) | Footer (1.5.0) | Hijri Date (1.5.0) | Latest News (1.5.0) | Agora Latest Posts Basic (1.1.1 basic) | AllVideos Reloaded (1.2.6) | Agorians Online (1.2.2) | Archived Content (1.5.0) | swMenuFree (5.2) | Moon Phase (1.0) | JoomlaStats Activation (3.0.0) | MiniFrontPage Module for J! 15 (1.2.2) | Random Image (1.5.0) | Search (1.0.0) | Random Tags (1.0) | Custom HTML (1.5.0) | Ultimate Content Display (1.1) | MiniCalendar (1.06) | R3D Floater (1.5.0) | Syndicate (1.5.0) | Menu (1.5.0) | Noticeboard (1.2) | Most Popular Tags (1.7) | Statistics (1.5.0) | Wrapper (1.0.0) | Latest Tags (1.7) | Login (1.5.0) | SlideShow Pro (2.1) | Sections (1.5.0) | Custom Tags Cloud (1.0) | aiContactSafe module (1.0.7.stable) | DWho's Online (1.6.0) | Agora Profile (1.3.2) | Feed Display (1.5.0) |
Modules :: ADMIN :: Online Users (1.0.0) | Agora Admin Manager (1.0.0) | Title (1.0.0) | Toolbar (1.0.0) | Admin Menu (1.0.0) | Latest News (1.0.0) | Footer (1.0.0) | Logged in Users (1.0.0) | Unread Items (1.0.0) | JoomlaPack Backup Notification (1.0) | User Status (1.5.0) | Custom HTML (1.5.0) | Admin Submenu (1.0.0) | Items Stats (1.0.0) | Popular Items (1.0.0) | Quick Icons (1.0.0) | Login Form (1.0.0) | Feed Display (1.5.0) |

Plugins :: SITE :: Editor Button - JComments ON (1.0) | Button - AllVideos Reloaded (1.2.6) | Button - Xmap Link (1.0) | Editor Button - JComments OFF (1.0) | Editor Button - Agora Olympus (1.5) | Button - Image (1.0.0) | Button - Phoca Gallery (2.6.0) | Button - Readmore (1.5) | Button - Pagebreak (1.5) | Editor Button - Add Tags (1.3) | Button - Agora Profile (1.5) | Search - Content (1.5) | Search - QContacts (1.5) | Search - EasyBook (2.0) | Search - Tags (1.5) | Search - Weblinks (1.5) | Search - Newsfeeds (1.5) | Search - Categories (1.5) | Search - Sections (1.5) | Search - Contacts (1.5) | Search - JComments (1.0) | SearchBot - Agora 3 (1.3) | Paste (1.5.7.4) | File Browser (1.5.7.4) | Media Object support (1.5.7.4) | Advanced Code Editor (1.5.7.4) | Image Manager (1.5.7.4) | JCE SPELLCHECKER TITLE (1.5.7.4) | Paste (1.5.7.4) | Joomla! Links for Advanced Lin (1.2.1) | Zoo2 Links for Advanced Link (1.0.0) | Advanced Link (1.5.7.4) | Editor - TinyMCE 3 (3.2.6) | Editor - JCE 1.5.7.4 (1.5.7.4) | Editor - XStandard Lite for Jo (1.0) | AcyMailing Tag : Date / Time (1.1.3) | AcyMailing onPrepareContent tr (1.1.3) | AcyMailing Tag : Subscriber in (1.1.3) | AcyMailing Tag : Joomla User I (1.1.3) | AcyMailing : Statistics Plugin (1.1.3) | AcyMailing Tag : online links (1.1.3) | AcyMailing Tag : Manage the Su (1.1.3) | AcyMailing Tag : content inser (1.1.3) | AcyMailing Template Class Repl (1.1.3) | System - AllVideos Reloaded (1.2.6) | System - Remember Me (1.5) | System - ARTIO JoomSEF (3.3.1) | System - Cache (1.5) | System - AlphaRegistration (2.0.9) | System - Backlinks (1.5) | System - Tag SEF (1.3) | System - Legacy (1.5) | System - Marco's SQL Injection (1.1.0) | System - Metagora (1.4) | System - Debug (1.5) | System - AlphaContent (4.0.15) | System - SEF (1.5) | Security - jHackGuard (1.0.11) | System - Log (1.5) | System - Jumi Router (2.0.6) | System - JComments (1.0) | User - Joomla! (1.5) | User - Example (1.0) | User - AcyMailing (1.1.3) | User - JComments (1.0) | Authentication - Joomla (1.5) | Authentication - Example (1.5) | Authentication - GMail (1.5) | Authentication - OpenID (1.5) | Authentication - LDAP (1.5) | Content - AlphaContent (4.0.15) | Content - AllVideos Reloaded (1.2.6) | Jumi (2.0.6) | Content - Example (1.0) | Google Maps (2.12m) | Content - Agora Olympus Discus (1.0.0) | Content - BonckoLen Image Gall (2.1.0) | Content - Agora AuthorBot Plus (1.1) | Content - Tags (2.1) | Content - Code Highlighter (Ge (1.5) | Jscribd (1.0.1) | Content - Vote (1.5) | Phoca Gallery Plugin (2.6.2) | Content - Email Cloaking (1.5) | Content - Load Modules (1.5) | Content - Pagebreak (1.5) | Content - Page Navigation (1.5) | Phoca Gallery Slideshow Plugin (2.6.2) | Content - JComments (1.0) | XML-RPC - Joomla API (1.0) | XML-RPC - Blogger API (1.0) |
Templates Discovered :: wrote:Templates :: SITE :: siteground-j15-70 (1.0.0) | siteground-j15-73 (1.0.0) | dj-0013 (1.0) | rhuk_milkyway (1.0.2) | lavinya_black (1.0) | JA_Purity (1.2.0) | mountain (1.0.0) | siteground-j15-75 (1.0.0) | beez (1.0.0) | midnight (1.0.0) | uj_darkworld (1.0.1) | siteground-j15-39 (1.0.0) | siteground-j15-18 (1.0.0) | Bucolic2 (1.0) | siteground-j15-1 (1.0.0) | siteground-j15-49 (1.0.0) |
Templates :: ADMIN :: Khepri (1.0) |

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: My Website is infected with malware

Post by mandville » Mon Aug 20, 2012 7:36 am

Here are possible hack points
1. site on 1.5.15 - current version 1.5.26 - using an old, vulnerable, hackable version of joomla
2. error shows as in com_easybook - EasyBook 2.0.0rc4 suffers from multiple persistent XSS vulnerabilities in 2009
3. Elevated Permissions in various folders - 777! including in wp folders

suggested reading
http://forum.joomla.org/viewtopic.php?f=432&t=335090
http://docs.joomla.org/Top_10_Stupidest ... tor_Tricks
http://docs.joomla.org/Security_Checklist_7
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}


Locked

Return to “Security in Joomla! 1.5”