Insert spam files using POST query

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
jeyganesh_77
Joomla! Fledgling
Joomla! Fledgling
Posts: 1
Joined: Tue Aug 23, 2016 5:35 am

Insert spam files using POST query

Post by jeyganesh_77 » Tue Aug 23, 2016 6:08 am

Recently our website hacked, we resolved all issues such as upload the old backup and db scripts. but we review the our server log every day many IPs are try to insert the spam files using POST query.

our server log:

Code: Select all

85.214.51.0 - - [22/Aug/2016:19:11:36 +0200] "GET /x.php HTTP/1.1" 200 1465 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
5.196.121.0 - - [22/Aug/2016:19:11:36 +0200] "GET /x.php HTTP/1.1" 404 1465 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
our website url: speedstep.de

Please let me know how the spammer insert the spam file using POST query... we have strong FTP password, protect the admin using google authentication. still we have received the type of POST queries.

User avatar
toivo
Joomla! Master
Joomla! Master
Posts: 17438
Joined: Thu Feb 15, 2007 5:48 am
Location: Sydney, Australia

Re: Insert spam files using POST query

Post by toivo » Tue Aug 23, 2016 6:50 am

When you cleaned your site, did you follow the instructions from the sticky post at the top of this forum:
http://forum.joomla.org/viewtopic.php?f=714&t=757645

Just above your post there is a link to the Forum Post Assistant (FPA). Including the output from FPA will help others to see if there is something in the configuration of your server or some vulnerable extension: http://forum.joomla.org/viewtopic.php?f=621&t=582860
Toivo Talikka, Global Moderator

User avatar
JAVesey
Joomla! Hero
Joomla! Hero
Posts: 2636
Joined: Tue May 14, 2013 1:21 pm
Location: Cardiff, Wales, UK
Contact:

Re: Insert spam files using POST query

Post by JAVesey » Tue Aug 23, 2016 9:42 am

jeyganesh_77 wrote:Recently our website hacked, we resolved all issues such as upload the old backup and db scripts. but we review the our server log every day many IPs are try to insert the spam files using POST query.
You say "try" but don't say if the attempts were successful.

I would suggest that attempts such as this are common on the 'net and you won't actually stop the attempts themselves but can help prevent their success by keeping your code (joomla core + extensions) up to date and using a secure hosting provider.
John V
Cardiff, Wales, UK
Joomla 5.1.0 "live" site on PHP 8.2.15 and MariaDB 10.11.7
Joomla 5.1.0 on XAMMP for OSX with PHP 8.2.4 and MariaDB 10.4.28


Locked

Return to “Security in Joomla! 3.x”