Error Unknown column 'a.id' in 'where clause' SQL

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
Fredsnet
Joomla! Fledgling
Joomla! Fledgling
Posts: 4
Joined: Wed May 25, 2016 10:53 am

Error Unknown column 'a.id' in 'where clause' SQL

Post by Fredsnet » Wed May 25, 2016 11:10 am

My website was hacked and the database affected.
I get the above mentioned error if i try to open the [extentions] [plugin] tab the

is there a procedure to repair the database?

my thoughts are to import the content and menu items in a new database
could this work?

I already read the information on cleaning and security of the html section on the server.


the info of the forumpost assist:
Problem Description :: Forum Post Assistant (v1.2.7) : 25th May 2016 wrote:database hack
Log/Error Message :: Forum Post Assistant (v1.2.7) : 25th May 2016 wrote:Error Unknown column 'a.id' in 'where clause' SQL=SELECT COUNT(*) FROM `
Actions Taken To Resolve by Forum Post Assistant (v1.2.7) 25th May 2016 wrote:removed invisible user from database and removed several php scripts from the http://www.root
Forum Post Assistant (v1.2.7) : 25th May 2016 wrote:
Basic Environment :: wrote:Joomla! Instance :: Joomla! 3.4.8-Stable (Ember) 24-December-2015
Joomla! Platform :: Joomla Platform 13.1.0-Stable (Curiosity) 24-Apr-2013
Joomla! Configured :: Yes | Read-Only (444) | Owner: 0 (uid: /gid: ) | Group: 0 (gid: ) | Valid For: 3.4
Configuration Options :: Offline: 0 | SEF: 1 | SEF Suffix: 0 | SEF ReWrite: 0 | .htaccess/web.config: No | GZip: 0 | Cache: 0 | FTP Layer: 0 | SSL: 0 | Error Reporting: default | Site Debug: 0 | Language Debug: 0 | Default Access: 1 | Unicode Slugs: 0 | Database Credentials Present: Yes

Host Configuration :: OS: Windows NT | OS Version: 6.2 | Technology: i586 | Web Server: Microsoft-IIS/8.5 | Encoding: gzip, deflate | Doc Root: C:/domains/tegenspel.nl/subdomeinen/deanderen/wwwroot | System TMP Writable: Yes

PHP Configuration :: Version: 5.3.28 | PHP API: cgi-fcgi | Session Path Writable: Yes | Display Errors: 1 | Error Reporting: 30711 | Log Errors To: /domains/_SERVICES/PHP-sessiondata/logs/tegenspel.nl/deanderen/error.log | Last Known Error: | Register Globals: | Magic Quotes: | Safe Mode: | Open Base: | Uploads: 1 | Max. Upload Size: 768M | Max. POST Size: 768M | Max. Input Time: 900 | Max. Execution Time: 900 | Memory Limit: 256M

MySQL Configuration :: Version: 5.6.21 (Client:mysqlnd 5.0.8-dev - 20102224 - $Id: 731e5b87ba42146a687c29995d2dfd8b4e40b325 $) | Host: --protected-- (--protected--) | Collation: latin1_swedish_ci (Character Set: latin1) | Database Size: 10.90 MiB | #of Tables: 73
Detailed Environment :: wrote:PHP Extensions :: Core (5.3.28) | bcmath () | calendar () | ctype () | date (5.3.28) | ereg () | filter (0.11.0) | ftp () | hash (1.0) | iconv () | json (1.2.1) | mcrypt () | SPL (0.2) | odbc (1.0) | pcre () | Reflection ($Id: 4af6c4c676864b1c0bfa693845af0688645c37cf $) | session () | standard (5.3.28) | mysqlnd (mysqlnd 5.0.8-dev - 20102224 - $Id: 731e5b87ba42146a687c29995d2dfd8b4e40b325 $) | tokenizer (0.1) | zip (1.11.0) | zlib (1.1) | libxml () | dom (20031129) | PDO (1.0.4dev) | bz2 () | SimpleXML (0.1) | wddx () | xml () | xmlreader (0.1) | xmlwriter (0.1) | cgi-fcgi () | openssl () | com_dotnet (0.1) | curl () | fileinfo (1.0.5-dev) | gd () | gettext () | intl (1.1.0) | imap () | mbstring () | exif (1.4 $Id$) | mysql (1.0) | mysqli (0.1) | Phar (2.0.1) | pdo_mysql (1.0.2) | pdo_pgsql (1.0.2) | pdo_sqlite (1.0.1) | soap () | SQLite (2.0-dev) | sqlite3 (0.7-dev) | tidy (2.0) | xmlrpc (0.51) | xsl (0.1) | SourceGuardian (10.1.3) | memcache (3.0.8) | mhash () | ionCube Loader () | Zend Guard Loader () | Zend Engine (2.3.0) |
Potential Missing Extensions :: suhosin |

Switch User Environment (Experimental) :: PHP CGI: Yes | Server SU: No | PHP SU: Yes | Custom SU (LiteSpeed/Cloud/Grid): Yes
Potential Ownership Issues: No
Folder Permissions :: wrote:Core Folders :: images/ (777) | components/ (777) | modules/ (777) | plugins/ (777) | language/ (777) | templates/ (777) | cache/ (777) | logs/ (777) | tmp/ (777) | administrator/components/ (777) | administrator/modules/ (777) | administrator/language/ (777) | administrator/templates/ (777) |

Elevated Permissions (First 10) :: administrator/ (777) | administrator/cache/ (777) | administrator/components/ (777) | administrator/components/com_admin/ (777) | administrator/components/com_admin/controllers/ (777) | administrator/components/com_admin/helpers/ (777) | administrator/components/com_admin/helpers/html/ (777) | administrator/components/com_admin/models/ (777) | administrator/components/com_admin/models/forms/ (777) | administrator/components/com_admin/postinstall/ (777) |
Extensions Discovered :: wrote:Components :: SITE :: WF_AGGREGATOR_DAILYMOTION_TITL (2.5.16) | WF_AGGREGATOR_VIMEO_TITLE (2.5.16) | WF_AGGREGATOR_VINE_TITLE (2.5.16) | WF_AGGREGATOR_[youtube]_TITLE (2.5.16) | WF_FILESYSTEM_JOOMLA_TITLE (2.5.16) | WF_LINKS_JOOMLALINKS_TITLE (2.5.16) | K2 Links for JCE Link (2.2) | WF_MEDIAPLAYER_JCEPLAYER_TITLE (2.5.16) | WF_POPUPS_JCEMEDIABOX_TITLE (2.5.16) | WF_POPUPS_WINDOW_TITLE (2.5.16) | WF_LINK_SEARCH_TITLE (2.5.16) | WF_ANCHOR_TITLE (2.5.16) | WF_ARTICLE_TITLE (2.5.16) | WF_AUTOSAVE_TITLE (2.5.16) | WF_BROWSER_TITLE (2.5.16) | WF_CHARMAP_TITLE (2.5.16) | WF_CLEANUP_TITLE (2.5.16) | WF_CLIPBOARD_TITLE (2.5.16) | WF_CONTEXTMENU_TITLE (2.5.16) | WF_DIRECTIONALITY_TITLE (2.5.16) | WF_FONTCOLOR_TITLE (2.5.16) | WF_FONTSELECT_TITLE (2.5.16) | WF_FONTSIZESELECT_TITLE (2.5.16) | WF_FORMATSELECT_TITLE (2.5.16) | WF_FULLSCREEN_TITLE (2.5.16) | WF_HR_TITLE (2.5.16) | WF_IMGMANAGER_TITLE (2.5.16) | WF_INLINEPOPUPS_TITLE (2.5.16) | WF_KITCHENSINK_TITLE (2.5.16) | WF_LAYER_TITLE (2.5.16) | WF_LINK_TITLE (2.5.16) | WF_LISTS_TITLE (2.5.16) | WF_MEDIA_TITLE (2.5.16) | WF_MEDIAMANAGER_TITLE (2.0.16) | WF_NONBREAKING_TITLE (2.5.16) | WF_PREVIEW_TITLE (2.5.16) | WF_PRINT_TITLE (2.5.16) | WF_SEARCHREPLACE_TITLE (2.5.16) | WF_SOURCE_TITLE (2.5.16) | WF_SPELLCHECKER_TITLE (2.5.16) | WF_STYLE_TITLE (2.5.16) | WF_STYLESELECT_TITLE (2.5.16) | WF_TABLE_TITLE (2.5.16) | WF_TEXTCASE_TITLE (2.5.16) | WF_VISUALBLOCKS_TITLE (2.5.16) | WF_VISUALCHARS_TITLE (2.5.16) | WF_XHTMLXTRAS_TITLE (2.5.16) | com_mailto (3.0.0) | com_wrapper (3.0.0) |
Components :: ADMIN :: com_admin (3.0.0) | com_ajax (3.2.0) | com_banners (3.0.0) | com_cache (3.0.0) | com_categories (3.0.0) | com_checkin (3.0.0) | com_config (3.0.0) | com_content (3.0.0) | com_contenthistory (3.2.0) | com_cpanel (3.0.0) | com_finder (3.0.0) | com_installer (3.0.0) | JCE (2.5.16) | Unknown (-) | com_joomlaupdate (3.0.0) | com_languages (3.0.0) | com_login (3.0.0) | com_media (3.0.0) | com_menus (3.0.0) | com_messages (3.0.0) | com_modules (3.0.0) | com_newsfeeds (3.0.0) | com_plugins (3.0.0) | com_postinstall (3.2.0) | com_redirect (3.0.0) | com_search (3.0.0) | COM_SPTRANSFER (3.5.7) | COM_SPUPGRADE (3.4.11) | com_tags (3.1.0) | com_templates (3.0.0) | com_users (3.0.0) | com_weblinks (3.4.1) |

Modules :: SITE :: mod_articles_archive (3.0.0) | mod_articles_categories (3.0.0) | mod_articles_category (3.0.0) | mod_articles_latest (3.0.0) | mod_articles_news (3.0.0) | mod_articles_popular (3.0.0) | mod_banners (3.0.0) | mod_breadcrumbs (3.0.0) | mod_custom (3.0.0) | mod_feed (3.0.0) | mod_finder (3.0.0) | mod_footer (3.0.0) | mod_languages (3.0.0) | mod_login (3.0.0) | mod_menu (3.0.0) | mod_random_image (3.0.0) | mod_related_items (3.0.0) | mod_search (3.0.0) | mod_stats (3.0.0) | mod_syndicate (3.0.0) | mod_tags_popular (3.1.0) | mod_tags_similar (3.1.0) | mod_users_latest (3.0.0) | mod_weblinks (3.4.1) | mod_whosonline (3.0.0) | mod_wrapper (3.0.0) |
Modules :: ADMIN :: mod_custom (3.0.0) | mod_feed (3.0.0) | mod_latest (3.0.0) | mod_logged (3.0.0) | mod_login (3.0.0) | mod_menu (3.0.0) | mod_multilangstatus (3.0.0) | mod_popular (3.0.0) | mod_quickicon (3.0.0) | mod_stats_admin (3.0.0) | mod_status (3.0.0) | mod_submenu (3.0.0) | mod_title (3.0.0) | mod_toolbar (3.0.0) | mod_version (3.0.0) |

Plugins :: SITE :: plg_authentication_cookie (3.0.0) | plg_authentication_gmail (3.0.0) | plg_authentication_joomla (3.0.0) | plg_authentication_ldap (3.0.0) | plg_captcha_recaptcha (3.4.0) | plg_content_emailcloak (3.0.0) | plg_content_finder (3.0.0) | plg_content_joomla (3.0.0) | plg_content_loadmodule (3.0.0) | plg_content_pagebreak (3.0.0) | plg_content_pagenavigation (3.0.0) | plg_content_vote (3.0.0) | plg_editors_codemirror (5.6) | plg_editors_jce (2.5.16) | plg_editors_tinymce (4.1.7) | plg_editors-xtd_article (3.0.0) | plg_editors-xtd_image (3.0.0) | plg_editors-xtd_pagebreak (3.0.0) | plg_editors-xtd_readmore (3.0.0) | plg_extension_joomla (3.0.0) | plg_finder_categories (3.0.0) | plg_finder_contacts (3.0.0) | plg_finder_content (3.0.0) | plg_finder_newsfeeds (3.0.0) | plg_finder_tags (3.0.0) | plg_finder_weblinks (3.4.1) | plg_installer_webinstaller (1.0.5) | plg_quickicon_extensionupdate (3.0.0) | plg_quickicon_jcefilebrowser (2.5.16) | plg_quickicon_joomlaupdate (3.0.0) | plg_search_categories (3.0.0) | plg_search_contacts (3.0.0) | plg_search_content (3.0.0) | plg_search_newsfeeds (3.0.0) | plg_search_tags (3.0.0) | plg_search_weblinks (3.4.1) | plg_system_cache (3.0.0) | plg_system_debug (3.0.0) | plg_system_highlight (3.0.0) | plg_system_jce (2.5.16) | plg_system_languagecode (3.0.0) | plg_system_languagefilter (3.0.0) | plg_system_log (3.0.0) | plg_system_logout (3.0.0) | plg_system_p3p (3.0.0) | plg_system_redirect (3.0.0) | plg_system_remember (3.0.0) | plg_system_sef (3.0.0) | plg_twofactorauth_totp (3.2.0) | plg_twofactorauth_yubikey (3.2.0) | plg_user_contactcreator (3.0.0) | plg_user_joomla (3.0.0) | plg_user_profile (3.0.0) |
Templates Discovered :: wrote:Templates :: SITE :: beez3 (3.1.0) | protostar (1.0) |
Templates :: ADMIN :: hathor (3.0.0) | isis (1.0) |

itoctopus
Joomla! Virtuoso
Joomla! Virtuoso
Posts: 4025
Joined: Mon Nov 25, 2013 4:35 pm
Location: Montreal, Canada
Contact:

Re: Error Unknown column 'a.id' in 'where clause' SQL

Post by itoctopus » Wed May 25, 2016 1:42 pm

Do you have the full query that is affected? If I'm not mistaken, I think you can find the full query in the error log of your Joomla website. Once you have it, then you can just post it here.

As for the database hack - it typically is rare, but it happens. What have you done to address it if I may ask? An expedient way to address this problem is to revert back to a previous backup of the database (if the backup is recent and if the database hasn't changed much).
http://www.itoctopus.com - Joomla consulting at its finest
https://twitter.com/itoctopus - Follow us on Twitter


Locked

Return to “Security in Joomla! 3.x”