Site was hacked, access logs missing

Discussion regarding Joomla! 2.5 security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Locked
mherzogins
Joomla! Apprentice
Joomla! Apprentice
Posts: 10
Joined: Mon Feb 07, 2011 3:19 pm

Site was hacked, access logs missing

Post by mherzogins » Wed Oct 24, 2012 3:43 pm

I operate a lead generation site with joomla 2.5, moderator deleted

I kept a very close watch on my access logs and backed up regularly, just in case I needed to prove that a specific IP address accessed and downloaded files under contract.

As of today, I've logged into my FTP and my access logs are missing entirely. Using FileZilla, I've made sure that "Force Showing Hidden Files" is selected, as always. So I know it's not just being hidden.

Is there any way of finding out which IP address has accessed the FTP or tampered with the files to my site? My bandwidth went through the roof last night and it was obvious that someone had not only accessed the FTP, but downloaded the entire site.

What can I do about this? I just need to be able to find another log.

Does my server keep logs like this as a backup?

Using:

Ubuntu Linux 10.04LTS Server
EHCP Hosting Control Panel
Joomla 2.5.4 Stable
PHP 5.3.2-1ubuntu4.10
Apache/2.2.14
PHP Interface: apache2handler
Last edited by mandville on Wed Oct 24, 2012 8:09 pm, edited 1 time in total.
Reason: removed irrelevant material unsuitable for this forum and possible subject to legal action

WMRSHelp
Joomla! Apprentice
Joomla! Apprentice
Posts: 10
Joined: Tue Oct 02, 2012 1:34 pm
Location: Sarasota,FL
Contact:

Re: Site was hacked, access logs missing

Post by WMRSHelp » Fri Oct 26, 2012 3:07 am

You can try to contact your hosting company to see if they may possibly have a backup copy of the logs. It sounds like you were compromised and they may have had full access to your account and deleted any evidence.

feifan
Joomla! Fledgling
Joomla! Fledgling
Posts: 1
Joined: Fri Oct 26, 2012 2:58 am
Location: No.158 Lushan road
Contact:

Re: Site was hacked, access logs missing

Post by feifan » Fri Oct 26, 2012 3:20 am

No way thank you for all your info

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: Site was hacked, access logs missing

Post by mandville » Fri Oct 26, 2012 8:42 am

[ ] Download and RUN the Forum Post Assistant / FPA Instructions available here and are also included in the download package. Post the generated results in your security/been hacked topic. Use these links to download the FPA:
Download .tar.gz version or Download the .zip version NOTE: Do not download the FPA from any other website or links found on the Internet.

[ ] Ensure you have the latest version of Joomla for your version of Joomla. Delete all files in your Joomla installation, saving a copy of the configuration.php file.

[ ] Review Vulnerable Extensions List to make sure any 3rd party extensions versions used appear on the vulnerable list.

[ ] Review and action Security Checklist 7 Make sure you've gone through all of the steps.

[ ] Scan all machines with FTP, Joomla super admin, and Joomla admin access for malware, virus, trojans, spyware, etc. Checklist 7 contains a list or recommended scanners.

[ ] Change all passwords and if possible user names for the website host control panel. Change the Joomla database user name and password.

[ ] Use proper permissions on files and directories. They should never be 777, ideal is 644 for files and 755 for directories. The configuration file can be set to 444 which is read only.

[ ] Check your htaccess for for any odd code (i.e. code which is not in the standard htaccess supplied as part of the Joomla installation).

[ ] Check the crontab or Task Scheduler for unexpected jobs/tasks.

[ ] Ensure you do not have anonymous ftp enabled.

[ ] Verify individually that any non-Joomla file such as but not limited to that will be placed back on the website such as images, pdf files, files for download, and other documents and files are valid and are supposed to be part of your website.

[ ] Replace the deleted files with fresh copies of a current full version of Joomla (minus the installation directory) you downloaded earlier. Install freshly downloaded copies of any extensions and templates used on the site. If the Joomla database user name and password were changed earlier, then make the necessary changes to the configuration.php file and upload a copy to the website. Upload any non-Joomla files that are necessary for your website. Only by replacing all files in the installation (including extensions and templates) can you be sure to remove the backdoors inserted and hidden in various files and directories More detailed information can be found in the Security Checklist 7 document.
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}


Locked

Return to “Security in Joomla! 2.5”