My website as hacked

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
keupsonite
Joomla! Fledgling
Joomla! Fledgling
Posts: 1
Joined: Wed May 29, 2013 12:26 pm

My website as hacked

Post by keupsonite » Wed May 29, 2013 12:32 pm

Hello everybody,

My website has been hacked, i've run the pfa-en.php script, you can view the post assistant post detail on bottom.

I can't update my joomla because my customers didn't want to pay for that.

Thank you in advance if you can help me.
Keupsonite.
Problem Description :: Forum Post Assistant (v1.2.3) : 29th May 2013 wrote:Website hacked
Forum Post Assistant (v1.2.3) : 29th May 2013 wrote:
Basic Environment :: wrote:Joomla! Instance :: Joomla! 1.5.26-Stable (senu takaa ama busani) 27-March-2012
Joomla! Configured :: Yes | Read-Only (444) | Owner: www-data (uid: 1/gid: 1) | Group: (gid: ) | Valid For: 1.5
Configuration Options :: Offline: 0 | SEF: 1 | SEF Suffix: 1 | SEF ReWrite: 1 | .htaccess/web.config: Yes | GZip: 0 | Cache: 0 | FTP Layer: 0 | SSL: 0 | Error Reporting: -1 | Site Debug: 0 | Language Debug: 0 | Database Credentials Present: Yes

Host Configuration :: OS: Linux | OS Version: 3.2.0-0.bpo.2-amd64 | Technology: x86_64 | Web Server: Apache/2.2.16 (Debian) | Encoding: gzip, deflate | Doc Root: /var/alternc/html/h/hdifrance/ | System TMP Writable: Yes

PHP Configuration :: Version: 5.3.3-7+squeeze15 | PHP API: apache2handler | Session Path Writable: No | Display Errors: | Error Reporting: 22527 | Log Errors To: | Last Known Error: | Register Globals: | Magic Quotes: | Safe Mode: 0 | Open Base: /var/alternc/html/h/hdifrance/:/usr/share/php/:/var/alternc/tmp:/tmp | Uploads: 1 | Max. Upload Size: 200M | Max. POST Size: 200M | Max. Input Time: 60 | Max. Execution Time: 30 | Memory Limit: 512M

MySQL Configuration :: Version: 5.1.66-0+squeeze1-log (Client:5.1.66) | Host: --protected-- (--protected--) | Collation: latin1_swedish_ci (Character Set: latin1) | Database Size: 2.89 MiB | #of Tables: 86
Detailed Environment :: wrote:PHP Extensions :: Core (5.3.3-7+squeeze15) | date (5.3.3-7+squeeze15) | ereg () | libxml () | openssl () | pcre () | zlib (1.1) | bcmath () | bz2 () | calendar () | ctype () | dba () | dom (20031129) | hash (1.0) | fileinfo (1.0.5-dev) | filter (0.11.0) | ftp () | gettext () | session () | iconv () | json (1.2.1) | mbstring () | apc (3.1.3p1) | posix () | Reflection ($Revision: 300393 $) | standard (5.3.3-7+squeeze15) | shmop () | SPL (0.2) | soap () | sockets () | SimpleXML (0.1) | exif (1.4 $Id: exif.c 293036 2010-01-03 09:23:27Z sebastian $) | sysvmsg () | sysvsem () | sysvshm () | tokenizer (0.1) | wddx () | xml () | xmlreader (0.1) | xmlwriter (0.1) | zip (1.9.1) | apache2handler () | Phar (2.0.1) | curl () | gd () | mcrypt () | mysql (1.0) | mysqli (0.1) | PDO (1.0.4dev) | pdo_mysql (1.0.2) | suhosin (0.9.32.1) | mhash () | Zend Engine (2.3.0) |
Potential Missing Extensions ::

Switch User Environment (Experimental) :: PHP CGI: No | Server SU: No | PHP SU: No | Custom SU (LiteSpeed/Cloud/Grid): Yes
Potential Ownership Issues: No

Apache Modules :: core | mod_log_config | mod_logio | prefork | http_core | mod_so | mod_alias | mod_auth_basic | mod_authn_file | mod_authz_default | mod_authz_groupfile | mod_authz_host | mod_authz_user | mod_autoindex | mod_cgi | mod_deflate | mod_dir | mod_env | mod_mime | mod_negotiation | mod_perl | mod_php5 | mod_python | mod_reqtimeout | mod_rewrite | mod_setenvif | mod_ssl | mod_status | mod_vhost_alias | Apache/2.2.16 (Debian) |
Potential Missing Modules :: mod_expires | mod_security | mod_evasive | mod_dosevasive | mod_qos | mod_userdir |
Folder Permissions :: wrote:Core Folders :: images/ (755) | components/ (755) | modules/ (755) | plugins/ (755) | language/ (755) | templates/ (755) | cache/ (755) | logs/ (755) | tmp/ (755) | administrator/components/ (755) | administrator/modules/ (755) | administrator/language/ (755) | administrator/templates/ (755) |

Elevated Permissions (First 10) ::
Extensions Discovered :: wrote:Components :: SITE :: CB Mamblog Tab (1.2) | CB Mambo Author Tab (1.2) | Yanc Integration (1.2) | comprofiler (1.4) | MailTo (1.5.0) | User (1.5.0) | Wrapper (1.5.0) |
Components :: ADMIN :: Akeeba (3.1.5) | Banners (1.5.0) | Cache Manager (1.5.0) | comprofiler (1.4) | comprofiler (1.4) | comprofiler (1.4) | Configuration Manager (1.5.0) | Contact Items (1.0.0) | Content Page (1.5.0) | Control Panel (1.5.0) | Frontpage (1.5.0) | HsConfig (2.0.9) | Installation Manager (1.5.0) | JCE (1.5.7 FR-EN) | Language Manager (1.5.0) | Mass Mail (1.5.0) | Media Manager (1.5.0) | Menus Manager (1.5.0) | Messaging (1.5.0) | Module Manager (1.5.0) | Newsfeeds (1.5.0) | Free Mono (-) | Helvetica (-) | PhocaPDF (1.0.9) | Plugin Manager (1.5.0) | Polls (1.5.0) | QuickForm (1.1.0) | Search (1.5.0) | Template Manager (1.5.0) | Trash (1.0.0) | User Manager (1.5.0) | Weblinks (1.5.0) | System - Password Encrypt (1.6.6) | encrypt_configuration (2.0.3) |

Modules :: SITE :: Archived Content (1.5.0) | Banner (1.5.0) | Breadcrumbs (1.5.0) | CB Login (1.4) | CB Workflows (1.4) | CB Online (1.4) | Custom HTML (1.5.0) | Feed Display (1.5.0) | Footer (1.5.0) | JA Content Slider Module (1.1.0) | JA Bulletin (1.0.1) | JA News Sticker Module (1.0.2) | JA Side News Module (1.0.1) | JA Slideshow2 Module (2.0.3) | JA Tabs (1.5.0) | Latest News (1.5.0) | Login (1.5.0) | Menu (1.5.0) | Most Read Content (1.5.0) | Newsflash (1.5.0) | Poll (1.5.0) | Random Image (1.5.0) | Related Items (1.0.0) | Search (1.0.0) | Sections (1.5.0) | Statistics (1.5.0) | Syndicate (1.5.0) | Who\'s Online (1.0.0) | Wrapper (1.0.0) |
Modules :: ADMIN :: Akeeba Backup Notification Mod (3.1.5) | Custom HTML (1.5.0) | Feed Display (1.5.0) | Footer (1.0.0) | Latest News (1.0.0) | Logged in Users (1.0.0) | Login Form (1.0.0) | Admin Menu (1.0.0) | Online Users (1.0.0) | Popular Items (1.0.0) | Quick Icons (1.0.0) | Items Stats (1.0.0) | User Status (1.5.0) | Admin Submenu (1.0.0) | Title (1.0.0) | Toolbar (1.0.0) | Unread Items (1.0.0) |

Plugins :: SITE :: Authentication - Example (1.5) | Authentication - GMail (1.5) | Authentication - Joomla (1.5) | Authentication - LDAP (1.5) | Authentication - OpenID (1.5) | Content - Email Cloaking (1.5) | Content - Example (1.0) | Content - Pagebreak for FLEXIc (1.0.1) | Content - Code Highlighter (Ge (1.5) | Content - Highslide (2.0.4) | JA Tabs for Joomla! 1.5 (1.0) | Content - Load Modules (1.5) | Content - Pagebreak (1.5) | Content - Page Navigation (1.5) | Content - JA Thumbnail (1.0) | Content - Vote (1.5) | Button - Image (1.0.0) | Button - Pagebreak (1.5) | Button - Readmore (1.5) | Advanced Code Editor (1.5.6) | Joomla! Links for Advanced Lin (1.2.1) | Advanced Link (1.5.1) | File Browser (1.5.0 Stable) | Paste (1.5.0) | Highslide Expander (2.0.0) | Highslide HTML Expander (2.0.1) | Image Manager (1.5.2) | Object Support (1.5.1) | Paste (1.5.6) | SpellChecker (2.0.0) | Editeur - JCE 1.5.6 (1.5.6 FR-EN) | Editor - TinyMCE 3 (3.2.6) | Editor - XStandard Lite for Jo (1.0) | Search - Categories (1.5) | Search - Contacts (1.5) | Search - Content (1.5) | Search - Newsfeeds (1.5) | Search - Sections (1.5) | Search - Weblinks (1.5) | Akeeba Backup Lazy Scheduling (3.1.5) | System - Backlinks (1.5) | System - Cache (1.5) | System - Debug (1.5) | System - Highslide (2.0.3) | System - JCE Utilities 2.2.4 (2.2.4) | System - Legacy (1.5) | System - Log (1.5) | Phoca PDF - Content (1.0.6) | System - JA Map (1.0.1) | JA Menu Parameters (1.0.1) | System - Remember Me (1.5) | System - SEF (1.5) | System - Mootools Upgrade (1.5) | System - Password Encrypt (1.6.6) | User - Example (1.0) | User - Joomla! (1.5) | XML-RPC - Blogger API (1.0) | XML-RPC - Joomla API (1.0) |
Templates Discovered :: wrote:Templates :: SITE :: beez (1.0.0) | JA_Purity_II (1.2) | JA_Rasite (1.0.1) | rhuk_milkyway (1.0.2) |
Templates :: ADMIN :: Khepri (1.0) |

paulera
Joomla! Explorer
Joomla! Explorer
Posts: 324
Joined: Tue Sep 07, 2010 5:23 pm
Location: Ireland
Contact:

Re: My website as hacked

Post by paulera » Wed May 29, 2013 1:40 pm

With these information I do not know exactly what happened... You can take a look at this post about website hacked (Joomla 2.5): http://forum.joomla.org/viewtopic.php?f=621&t=582854 and this: http://jure-stern.si/blog/joomla-websit ... hat-to-do/

I strongly recommend you to upgrade... Think about that as an investment on your business, someday a hacked website can cost you much more money and headache than the hours you gonna expend to upgrade them now.


Locked

Return to “Security in Joomla! 1.5”