Rouge files found in Media Manager ~ Hacked?

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
bertman
Joomla! Apprentice
Joomla! Apprentice
Posts: 17
Joined: Sat Mar 01, 2008 3:35 am

Rouge files found in Media Manager ~ Hacked?

Post by bertman » Sun May 05, 2013 10:14 pm

Hello,
We maintain a site on 1.5 ( I know outdated). I noticed a higher than normal bandwidth usage lately. Although user registration is disabled, I found a new registerd user. I deleted them.
Also, I found two .php files in the Media Manager. I have since deleted them too, but would like some input on them. I have saved and attached as a plain txt file.

Am I wacked, or was this site compromised?

Thanks,

bertman
Last edited by mandville on Mon May 06, 2013 10:17 am, edited 1 time in total.
Reason: removed hacker /kudos files

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: Rouge files found in Media Manager ~ Hacked?

Post by mandville » Mon May 06, 2013 10:18 am

yes - you were hacked.
please follow the forum sticky, post the fpa and follow checklist 7,
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

User avatar
Slackervaara
Joomla! Ace
Joomla! Ace
Posts: 1115
Joined: Sat Aug 13, 2011 6:27 am

Re: Rouge files found in Media Manager ~ Hacked?

Post by Slackervaara » Mon May 06, 2013 11:52 am

If you remember the name of the hacker files, so search for those name in access logs and you might figure out how the hacks was made. takes only a couple of minutes to check this.


Locked

Return to “Security in Joomla! 1.5”