My site was hacked- trying to get it back online

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
ItsMeAgain66
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Fri Jun 07, 2013 2:01 pm

My site was hacked- trying to get it back online

Post by ItsMeAgain66 » Fri Jun 07, 2013 3:17 pm

Hi All

My site was setup by an employee of mine back in 2008 with Joomla and it recently got hacked (last Saturday)

My hoster restored my site from a backup and it was all aok in its pre-hacked state. They changed my ftp password which seemed reasonable since we did not know if my pw was compromised.

My first step was to attempt to install a backup tool but when doing so within the admin console of Joomla i got a message saying "JFTP::login: Unable to login JFTP::store: Unable to use passive mode Warning! Failed to move file." I figured OK So i had been able to install the "connector" to do the Joomla audit but that was prior to having my ftp pw changed. I read on here that I was to go to the Joomla admin page and then to Global Configuration then I changed the password to match the new pw. At this point i now have no access to my site and no access to the admin page.

I noted that the file called configuration.php had a file size of ZERO and there was another file called configuration.php-dist and read where the only thing needed to do was rename the configuration.php-dist to configuration.php but guess what no good..

With the Configuration.php (file size sero) originally Configuration.php-dist in place I get "No configuration file found and no installation code available. Exiting..." and with the Configuration.php (file size 3411) I get "Database Error: Unable to connect to the database:Could not connect to MySQL" Further research told me that others were having a similar problem ( here: http://forum.joomla.org/viewtopic.php?t=265091 ) and their fix was to edit the configuration.php with the proper db, user and pw but opening the configuration.php in notepad I have none of those fields available much less so i can't fix them.

Thinking this shouldn't be terribly hard to resolve but i am missing something...

Thank you in advance for any ideas you may have
Last edited by imanickam on Sat Jun 08, 2013 2:56 am, edited 1 time in total.
Reason: Moved the topic from the forum General Questions/New to Joomla! 1.5 to the forum Security in Joomla! 1.5

ItsMeAgain66
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Fri Jun 07, 2013 2:01 pm

Re: My site was hacked- trying to get it back online

Post by ItsMeAgain66 » Fri Jun 07, 2013 5:54 pm

I was able to get the site restored from a backup again so it is back at 1.5.22

It seems there is no direct patch to go from 1.5.22 to 1.5.26?

Thinking it should be upgraded before the site gets hacked again

User avatar
imanickam
Joomla! Master
Joomla! Master
Posts: 28202
Joined: Wed Aug 13, 2008 2:57 am
Location: Chennai, India

Re: My site was hacked- trying to get it back online

Post by imanickam » Sat Jun 08, 2013 2:59 am

You could use the file Joomla_1.5.0_to_1.5.26-Stable-Patch_Package.zip for this. This file could be downloaded from http://joomlacode.org/gf/project/joomla ... ge_id=6311.

Review of the document http://docs.joomla.org/J1.5:Upgrading_1 ... 5x_version could be of help.
Ilagnayeru (MIG) Manickam | இளஞாயிறு மாணிக்கம்
Joomla! - Global Moderators Team | Joomla! Core - Tamil (தமிழ்) Translation Team Coordinator
Former Joomla! Translations Coordination Team Lead
Eegan - Support the poor and underprivileged

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: My site was hacked- trying to get it back online

Post by mandville » Sat Jun 08, 2013 8:02 am

follow the post hack process at http://docs.joomla.org/Security_Checklist_7
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}


Locked

Return to “Security in Joomla! 1.5”