The Joomla! Forum ™



Forum rules


Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 5 posts ] 
Author Message
PostPosted: Thu Feb 09, 2012 6:28 pm 
Joomla! Fledgling
Joomla! Fledgling

Joined: Thu Feb 09, 2012 6:14 pm
Posts: 3
I'm sorry to bother you all, but I'm in over my head here.

I did read through the stickied post about hacked sites, but couldn't apply much of the information there.

My friend has his site hacked and didn't notice for a month. I've never used Joomla and the person that originally created it 3 years ago never updated nor secured it.

After talking to the hosting company, we determined that it was hacked using a template exploit:

Quote:
210.195.35.139 - - [13/Jan/2012:10:16:21 -0600] "POST /templates/beez/index.php?act=f HTTP/1.1" 200 10543 "http://bffmakeup.com/templates/beez/index.php?act=f&file=/home/bffmakeu/public_html//index.php" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.121 Safari/535.2"


I'm coming in to this completely blind as I've never used Joomla and am just trying to help out my friend. Everything I've read about this says to start by logging into the administration control panel, but the people that hacked it seem to have removed that login page.

I don't even know which version of the Joomla application he has installed here. All I have access to is the site and the FTP.

He also has informed me that he doesn't have a backup of the site.

So now that I've finished brow-beating him, is there anything I can do? Could someone point me in the right direction if there is one?

Thanks.


Top
 Profile  
 
PostPosted: Thu Feb 09, 2012 6:50 pm 
User avatar
Joomla! Master
Joomla! Master
Online

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11642
Location: The Girly Side of Joomla in Sussex
ok. you can check the version by looking at the changelog and that will give you a clue BUT the easiest and best thing would be to follow checklist 7
http://docs.joomla.org/Security_Checkli ... ter_relief
the template was just a point of entry, not always the exploit itself.
if the site hasnt been touched for years it could be any number of things.

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Thu Feb 09, 2012 6:56 pm 
Joomla! Fledgling
Joomla! Fledgling

Joined: Thu Feb 09, 2012 6:14 pm
Posts: 3
mandville wrote:
ok. you can check the version by looking at the changelog and that will give you a clue BUT the easiest and best thing would be to follow checklist 7
http://docs.joomla.org/Security_Checkli ... ter_relief
the template was just a point of entry, not always the exploit itself.
if the site hasnt been touched for years it could be any number of things.


Sorry, how do I get to the changelog without being able to get into the admin panel? Just pull the file through FTP I assume?


Top
 Profile  
 
PostPosted: Thu Feb 09, 2012 7:10 pm 
User avatar
Joomla! Master
Joomla! Master
Online

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11642
Location: The Girly Side of Joomla in Sussex
yes.. but as i said, just concentrate on the checklist 7 section i quoted

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Thu Feb 09, 2012 7:15 pm 
Joomla! Fledgling
Joomla! Fledgling

Joined: Thu Feb 09, 2012 6:14 pm
Posts: 3
Ok. I shall do so when I get home this evening. Thank you for the support.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 5 posts ] 



Who is online

Users browsing this forum: n0Ob, stuartwall and 20 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group