Has my site been hacked?

Discussion regarding Joomla! 2.5 security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Locked
ReJigged
Joomla! Apprentice
Joomla! Apprentice
Posts: 25
Joined: Fri Aug 25, 2006 9:36 am
Location: Nottingham, UK

Has my site been hacked?

Post by ReJigged » Thu Jul 03, 2014 10:26 am

J! 2.5.19

Hi all,

I was performing a backup this morning when my a/v picked up and removed a file. It was in my /components directory. The filename is ssyny9.php and contains a function looking for cookies called '[removed], Jlma2 & Jlma3'.

There was also another file I didn't recognise in there - movie.php. When this is looked at if has a line started "if(@md5($_POST["gif"])....". This file displays '[removed]' if run in a browser.

The site seems to be ok at the moment but I am concerned my anti-virus may have picked up something I need to be aware of. Searches in Google don't seem to turn anything significant up.

Does anyone recognise these files?

Thanks

RJ

edit - I swear I was posting in the security section. Can't see how to move or delete this post.

User avatar
pe7er
Joomla! Master
Joomla! Master
Posts: 24985
Joined: Thu Aug 18, 2005 8:55 pm
Location: Nijmegen, Netherlands
Contact:

Re: Has my site been hacked?

Post by pe7er » Thu Jul 03, 2014 11:09 am

mod note: moved to security forum.
Please in the future just report your own post & ask for moving it to the right board. Thanks!
Kind Regards,
Peter Martin, Global Moderator
Company website: https://db8.nl/en/ - Joomla specialist, Nijmegen, Netherlands
The best website: https://the-best-website.com

User avatar
Bernard T
Joomla! Guru
Joomla! Guru
Posts: 782
Joined: Thu Jun 29, 2006 11:44 am
Location: Hrvatska
Contact:

Re: Has my site been hacked?

Post by Bernard T » Thu Jul 10, 2014 7:32 pm

You have an old version of Joomla, you should upgrade immediately.

Judging by what you found in your files and your AV reacting on it, I would pretty sure say your website has been compromised with some backdoor/rootkit files.

I'd advise you to follow this instructions closely
http://forum.joomla.org/viewtopic.php?f=621&t=582854
VEL Team || Security Forum || PHP/Web Security Specialist || OWASP member
JAMSS author http://forum.joomla.org/viewtopic.php?f=621&t=777957
Twitter: @toplak


Locked

Return to “Security in Joomla! 2.5”