Infiltration in images/stories folder

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
boerssen
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Mon Jun 07, 2010 6:42 pm

Infiltration in images/stories folder

Post by boerssen » Tue May 21, 2013 9:21 am

Hi

I have a Joomla 1.5 website that were hacked a while ago. I have gone through all the steps in the Joomla Security Checklist 7, checked if any of my plugins/modules are on the Vulnerable Extensions List and also made sure they are updated. I changed the database prefix and login details for bot FTP and admin panel.

I used to start seeing infiltrations in the stories images folder and decided to delete the folder all together but for some reason somebody still manages to recreate the folder on my FTP server which includes infiltrated files.

Is there anything that i'm missing here or any help to fully protect my website?

Kind regards
Pieter

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: Infiltration in images/stories folder

Post by mandville » Tue May 21, 2013 9:25 am

you say you went through checklist 7 -
did you do this part http://docs.joomla.org/Security_Checkli ... ter_relief
as i assume the hacker left in several back doors
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

boerssen
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Mon Jun 07, 2010 6:42 pm

Re: Infiltration in images/stories folder

Post by boerssen » Tue May 21, 2013 10:53 am

thx, your right i did not use a new copy of Joomla 1.5

can I do all this locally, then upload the site to a sub directory first. Delete the current files and then move my new site from the sub directory to the root directory to minimize downtime?

thx

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: Infiltration in images/stories folder

Post by mandville » Tue May 21, 2013 11:20 am

please imagine me shouting NO! you directory is comprimised. why are you serving a known exploited site to your users? just think,m shell scripts, malicious drivebydownloads, link spamming, who knows.

the other way of doing this is create a root level directory (public_html_tmp)
upload your new clean joomla install to that put you config file intot he new directory along with all your images etc. (and no - dont just copy the directory)
remove the public-html directory and then rename the tmp directry BUT believe me thats just the same as wiping the orginal directory..
whats wrong with putting up a place holder page sying "specially trained site hamsters having lunch , back in an hour" and following the proces that you didnt do in the first place?
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

boerssen
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Mon Jun 07, 2010 6:42 pm

Re: Infiltration in images/stories folder

Post by boerssen » Tue May 21, 2013 12:25 pm

thanks you so much for the advice, I'm going to be looking into this soon


Locked

Return to “Security in Joomla! 1.5”