admin pages hacked - Please help!!

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
mcg68
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Fri Jul 11, 2014 9:39 am

admin pages hacked - Please help!!

Post by mcg68 » Fri Jul 11, 2014 9:56 am

Hi,

We had a Joomla site designed for us a few tyears ago. The web designer has disappeared now and we have no idea what to do.

Our site has been hacked with the following symptoms....
: Today, we couldn't log in to the admin using the usual username and password.
: Looked at database using myPhp and saw a new user called admin2 so reset this password and logged in.
: When we log in, there is no admin page, just a page showing flags and a hackers logo or something. Looks pretty scary.
: In the database, all the users seem to be intact, but I can only log in with the admin2 user which takes me to some replacement page described above.

I have looked at the code in the index.php file and nothing looks like it is pointing to any other page, like redirects or anything. I am no expert in Joomla, PHP, web design or anything of that nature so could really use some help to get my admin page back so I can see if my content has vanished. I know there was a backup done a while ago but have no idea where it will be.

Any help would be great,
Thanks,
Michael
Last edited by mandville on Fri Jul 11, 2014 6:38 pm, edited 1 time in total.
Reason: retitled to be more descriptive

mcg68
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Fri Jul 11, 2014 9:39 am

Re: Please help!!

Post by mcg68 » Fri Jul 11, 2014 10:53 am

Update.... The main admin page is being replaced by an image, source "[removed kudos]"

I cannot see this anywhere in any of the code or even searching the database. Does anyone know (or can guess) where this is being executed?

Thanks,
Michael
Last edited by mandville on Fri Jul 11, 2014 6:48 pm, edited 1 time in total.
Reason: removed hacker kudos.

User avatar
dpacadmin
Joomla! Champion
Joomla! Champion
Posts: 6029
Joined: Sat Aug 16, 2008 1:46 pm
Location: the Bat Cave
Contact:

Re: Please help!!

Post by dpacadmin » Fri Jul 11, 2014 2:58 pm

Try uploading a new administrator folder from your last good backup. Also read the stick posts at the top of this Security forum.


Locked

Return to “Security in Joomla! 1.5”