change the username and password

Discussion regarding Joomla! 2.5 security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Locked
oilcountry
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Sat Feb 04, 2012 6:44 am

change the username and password

Post by oilcountry » Mon Feb 20, 2012 7:18 am

hi, i have run into a problem i was hacked on my website and i'd like to get some help from a joomla tech person i cannot change my username and password in the backend there is no check marks beside my name , when i put the new information and click save and close button nothing happens and the information does not save.


i have joomla 1.7 version and i tried going to php in my cpanel and that did not work no files there for joomla.
Last edited by imanickam on Tue Feb 21, 2012 3:56 am, edited 1 time in total.
Reason: Moved the topic from the forum General Questions to the forum Security

jzlcdh
Joomla! Explorer
Joomla! Explorer
Posts: 467
Joined: Thu Nov 04, 2010 8:09 am

Re: change the username and password

Post by jzlcdh » Mon Feb 20, 2012 8:39 am

So the hacker has deleted the Joomla files? Have you any more info about the hack? I hope you have a backup.

Suggest you consult
http://docs.joomla.orgSecurity_and_Performance_FAQs#Help.21_My_site.27s_been_compromised._Now_what.3F

It will be interesting if you let us know how you get on (if you can do so without revealing any details which might be useful to hackers of course).

Good Luck

Geoff

P.S. I used to work in the country which has the most oil to export - is that where you are?

jzlcdh
Joomla! Explorer
Joomla! Explorer
Posts: 467
Joined: Thu Nov 04, 2010 8:09 am

Re: change the username and password

Post by jzlcdh » Mon Feb 20, 2012 8:56 am

@lemmespeak - if you had the same problem what do you think the problem is and how did you solve it?

@oilcountry - if there are no Joomla files in your cpanel are you saying you suspect they are still in cache somewhere? Otherwise how could you log in to try to change your password? Are you sure you are looking in the right place (I know nothing about PHP)? Is it your database which has been hacked or files or you are not sure?

oilcountry
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Sat Feb 04, 2012 6:44 am

Re: change the username and password

Post by oilcountry » Mon Feb 20, 2012 5:13 pm

no i can still log in and all the files and everything is still there in joomla, i just cannot change the username and password 1. when you to user manager 2.put check mark in the box 3. click edit 4. enter all new information 5. click save and close nothing gets saved !!!!!!! there is no check mark by enable and activated , so how would i get those to have check marks beside my name ???

jzlcdh
Joomla! Explorer
Joomla! Explorer
Posts: 467
Joined: Thu Nov 04, 2010 8:09 am

Re: change the username and password

Post by jzlcdh » Mon Feb 20, 2012 8:08 pm

I suggest you upgrade to 2.5 soon as it is unlikely there will be any more security releases for 1.7 - just in case the hacker decides to have another attempt at your site.

What actions have you taken so far re the hack? e.g. could the hacker have changed permissions on some files, was your database damaged, did you restore back to before the hack etc etc?

Are you logging in as a SuperUser?

My site is 2.5 so not sure whether yours looks the same but maybe you can post a screenshot of the problem.

oilcountry
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Sat Feb 04, 2012 6:44 am

Re: change the username and password

Post by oilcountry » Mon Feb 20, 2012 11:29 pm

jzlcdh are you Joomla support worker, i deleted all the stuff the hacker put on my website within minutes. all i want is to change username and password so i will not have any problems down the road. if the staff of joomla are reading this please respond i have Joomla version 1.7 right now.

ALL I WANT IS TOO Change the username and password , cause when i go to "edit Profile" or user profile and put a check mark in the box "Edit" then i enter my new information and click "Save & Close" nothing happens it just stays on the same page.

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44096
Joined: Sat Apr 05, 2008 9:58 pm

Re: change the username and password

Post by Webdongle » Mon Feb 20, 2012 11:33 pm

http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

oilcountry
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Sat Feb 04, 2012 6:44 am

Re: change the username and password

Post by oilcountry » Tue Feb 21, 2012 12:51 am

@Webdongle - do you have an e-mail address that i could e-mail me you. we can talk more offline

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44096
Joined: Sat Apr 05, 2008 9:58 pm

Re: change the username and password

Post by Webdongle » Tue Feb 21, 2012 1:25 am

oilcountry wrote:@Webdongle - do you have an e-mail address that i could e-mail me you. we can talk more offline
Perhaps you should read my signature. Perhaps I should state the obvious in it that asking is just as bad.

I post in the forum so that everyone can benefit. What makes you think that you are so special that you should receive preferential treatment ? (don't answer that it is rhetorical)
http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

oilcountry
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Sat Feb 04, 2012 6:44 am

Re: change the username and password

Post by oilcountry » Tue Feb 21, 2012 2:05 am

okay Webdongle , do you know what i need to do to fix this so i can change my username and password ? someone suggested that update to the newer version 2.5 .

i can get to "edit profile" or user manager but as soon as i hit "save and close" button nothing happens.
please tell me what i need to do , i was at the site i cannot see any answers on that link you posted.

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44096
Joined: Sat Apr 05, 2008 9:58 pm

Re: change the username and password

Post by Webdongle » Tue Feb 21, 2012 2:17 am

oilcountry wrote:okay Webdongle , do you know what i need to do to fix this so i can change my username and password ? ...
Yes I posted a link to what you need to do.
http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

oilcountry
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Sat Feb 04, 2012 6:44 am

Re: change the username and password

Post by oilcountry » Tue Feb 21, 2012 2:28 am

@webdongle , okay you are not being clear on what to do or giving any instructions on the website. i'd like another Joomla Support Person who won't be cocky and is willing to work with me.

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44096
Joined: Sat Apr 05, 2008 9:58 pm

Re: change the username and password

Post by Webdongle » Tue Feb 21, 2012 2:48 am

oilcountry wrote:@webdongle , okay you are not being clear on what to do or giving any instructions on the website. i'd like another Joomla Support Person who won't be cocky and is willing to work with me.
The link I posted leads to a post that explains what to do when you've been hacked.

And there are no 'Joomla Support Persons' I (like) the other people on here are just volunteer my time. At nearly 53 years old I am not 'cocky' I am arrogant because (most of the time) am right.

You come on to this forum asking for special treatmeant (by asking to speak to me privately) ... you as for 'another Joomla Support Person' as if you have paid for a service.

You are using a free product and posting for help on a forum supported by people who freely volunteer their time.

You said in your very first post that your site was hacked. I posted a link to a post on the security forum that explains what to do when a website is hacked. Yet you have not followed the advice from the moderators post in that forum. And ask for different advice.

You have been hacked and (like it says in http://forum.joomla.org/viewtopic.php?f=621&t=582854 ) you need to delete all the files on the server ... and a list of other things.
http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

oilcountry
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Sat Feb 04, 2012 6:44 am

Re: change the username and password

Post by oilcountry » Tue Feb 21, 2012 2:59 am

Webdongle , okay i also said that delete all the files that were put on by the hacker, so i do not need that cause they've all been deleted !!!!

what my next step is to do is to change username and password!!! so i'm asking you someone said to upgrade to joomla 2.5 then i can change the username and password ?

jzlcdh
Joomla! Explorer
Joomla! Explorer
Posts: 467
Joined: Thu Nov 04, 2010 8:09 am

Re: change the username and password

Post by jzlcdh » Tue Feb 21, 2012 7:11 am

My advice to upgrade to 2.5 may not be your top priority as I am not certain it would solve your immediate problem. Perhaps you could post a screenshot here as that may give clues - for example you mentioned the lack of check markers but with a screenshot we could see whether there are instead red circles against your user-id.

Do your end-users update your site from the front-end? If so to remove the hack did you have to revert their updates by restoring the database? Or did you decide to do some kind of manual check and correction? Could it be that you thought you had corrected what has been hacked but there is something left behind by the hacker preventing you from amending your user.

Perhaps you are the administrator of the site but are lacking a technical person?
If you want paid support for Joomla I think there is a place (I forget where) you can ask for quotes from Joomla consultants and hopefully people who are more expert in security than I am (but perhaps not more expert than the other poster and the guys who moderate this forum) and who can respond more promptly than myself.
If you work for big oil (as your nickname suggests) it has got to be worth paying what to that size company would be peanuts in order to safeguard your company reputation.

Also I suspect Joomla is as secure (perhaps more so) as other general purpose content management system so perhaps the hack reflects a lack of security somewhere other than Joomla? Have you discussed it with your hosting people?

jzlcdh
Joomla! Explorer
Joomla! Explorer
Posts: 467
Joined: Thu Nov 04, 2010 8:09 am

Re: change the username and password

Post by jzlcdh » Tue Feb 21, 2012 7:51 am

@webdongle - when I click on http://docs.joomla.org/Security_Checklist_7 mentioned in the post you linked to it just gives a blank screen. Do you know if it has been moved? The link I quoted originally to "oilcountry" was last modified over a year ago.

User avatar
ooffick
Joomla! Master
Joomla! Master
Posts: 11616
Joined: Thu Jul 17, 2008 3:10 pm
Location: Ireland
Contact:

Re: change the username and password

Post by ooffick » Tue Feb 21, 2012 9:58 am

There seems to be a temporary issue with the docs, and you can see the page when you are logged in to http://docs.joomla.org (please note the username and password are different for that, so you cannot use your forum login.)

Olaf
Olaf Offick - Global Moderator
learnskills.org

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: change the username and password

Post by mandville » Tue Feb 21, 2012 11:28 am

a cached copy is now available of it at http://forum.joomla.org/viewtopic.php?f=432&t=697597
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44096
Joined: Sat Apr 05, 2008 9:58 pm

Re: change the username and password

Post by Webdongle » Tue Feb 21, 2012 4:44 pm

oilcountry wrote:Webdongle , okay i also said that delete all the files that were put on by the hacker, so i do not need that cause they've all been deleted !!!!
....
Unless you delete all the folders/files on the server you can not be certain to have deleted all the files placed by the Hacker.

If you do not scan your machine(and all machines that have server access) for malware then you can not be sure the site has not got infected again.

If you did not change ftp/database usernames/passwords (or did it before scanning your machine) then you can not be sure the site has not got infected again.

If you do not check you have the latest version of everything .....
http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".


Locked

Return to “Security in Joomla! 2.5”