Joomla! Discussion Forums



It is currently Sun Nov 22, 2009 3:43 am (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 9 posts ] 
Author Message
Posted: Fri Jun 12, 2009 12:40 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu Mar 12, 2009 12:49 am
Posts: 11
Hi, so i got problem with some iframe hack, dont know really how it comes, only thing i know is that every morning when i wake up, my website show a unexpect error in the index.php and my administrator panel show,

Warning: Unterminated comment starting line 84 in /home/fran8600/public_html/siteweb/administrator/index.php on line 84

Warning: session_start() [function.session-start]: Cannot send session cookie - headers already sent by (output started at /home/f............

Warning: session_start() [function.session-start]: Cannot send session cache limiter - headers already sent (output started at /home/joom............

Warning: Cannot modify header information - headers already sent by (output started at /home/joom/public_html/siteweb/admini............

The thing is that i only need to change my files from a back up i did, and things come back to normal, but now every mornings its coming back and its annoying, on each index.php, there is an iframe at the bottom, iframe linking to some pepsixx web site, that finally aint a pepsi's site. Anyone know how i can stop this?

Thx


Last edited by DeadPoetic on Mon Jun 15, 2009 5:35 pm, edited 2 times in total.

Top
  E-mail  
 
 Post subject: Re: IFrame
Posted: Fri Jun 12, 2009 12:46 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu Mar 12, 2009 12:49 am
Posts: 11
ho and now on my admin panel, there is an iframe linking to lotwager . cn (ps do not go on this website) and now, even if I put back my old files, it still stay there. help?


Top
  E-mail  
 
 Post subject: Re: IFrame
Posted: Fri Jun 12, 2009 1:07 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Tue Sep 06, 2005 11:18 am
Posts: 1119
Location: Germany
start here:

http://docs.joomla.org/Category:Security_Checklist

then search for:

iframe injection

_________________
MCITP - Microsoft Certified IT Professional
CCNA - Cisco Certfied Network Administrator
LPI - Linux Professional
PN for Online Transcript ID Check
http://www.mindset.de


Top
  E-mail  
 
 Post subject: Re: IFrame
Posted: Sun Jun 14, 2009 4:23 am 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu Mar 12, 2009 12:49 am
Posts: 11
I've delete and replace all the files, upload jsecure, joomsuite defender, but still each day im getting a php injection or iframe, and i didnt find anything about php injection, or iframe injection in the doc. My joomla platform is 1.5.11, well im getting tired to replace all file each time. Anyone got a solution.


Top
  E-mail  
 
 Post subject: Re: IFrame
Posted: Sun Jun 14, 2009 1:11 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Tue Sep 06, 2005 11:18 am
Posts: 1119
Location: Germany
well, you should check for modifiyed cron jobs ..

maybe (if your are on shared hosting) another site has been hacked any everybody now get's in touch with the result...

_________________
MCITP - Microsoft Certified IT Professional
CCNA - Cisco Certfied Network Administrator
LPI - Linux Professional
PN for Online Transcript ID Check
http://www.mindset.de


Top
  E-mail  
 
 Post subject: Re: IFrame
Posted: Mon Jun 15, 2009 2:32 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu Mar 12, 2009 12:49 am
Posts: 11
so there's my problem, i've search on the internet and it looks like i'm not the only one getting problem with the index.php in the past few days, every night this code is getting back in my index.php at line 89

<?php echo '<script type="text/javascript">

var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");

document.write(unescape("%3Cscript sr?='" + gaJsHost + "google-analytics.com/ga.js' " + ') + "' type='text/javascript'%3E%3C/script%3E"));

</script>

<script type="text/javascript">

try {

var pageTracker = _gat._getTracker("UA-xxxxxxx-xx");

pageTracker._trackPageview();

} catch(err) {}</script>'; ?>


Last edited by ianmac on Tue Jul 21, 2009 2:58 pm, edited 1 time in total.
removing hacker credits


Top
  E-mail  
 
 Post subject: Re: IFrame
Posted: Mon Jun 15, 2009 5:35 pm 
Joomla! Apprentice
Joomla! Apprentice
Offline

Joined: Thu Mar 12, 2009 12:49 am
Posts: 11
I've search on the internet, and it seem that thousand of people are having the same problem it the past few days, some are with joomla, other with wordpress, it is related to Google Analytics, it might be a hack, since i don't think no one knows what to do, I'll keep up with news if it ever happen to some of you.


Top
  E-mail  
 
Posted: Mon Jun 15, 2009 6:52 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Thu May 28, 2009 6:05 pm
Posts: 133
Location: California, USA
Hi DeadPoetic,

Have you verified that your host is secure as fw116 mentioned above? He's already covered most of the other possibilities as well. At least 25% of the posts in this Security forum relate directly to your problem.

This isn't related to Google Analytics or Joomla, it's a security problem with your site, host, or passwords. Malware distributors have been doing this for years, not just the past few days. The only difference in the past few days is that they have been modifying/replacing google analytics javascript instead of inserting their own iframe in order to obfuscate what they are doing.

As long as you follow the recommendations on the official security checklist and these basic Joomla! security recommendations your site will be secure without the need for things like jsecure or joomsuite defender.

_________________
Adam Boswell - Rochen Ltd.
http://www.rochen.com - Performance Joomla Hosting Solutions - Make your Joomla! install fly.
http://blog.rochen.com - Great security tips and more for Joomla!
Follow us on Twitter @rochenhost


Top
  E-mail  
 
Posted: Tue Jul 21, 2009 2:53 pm 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Tue Jul 21, 2009 2:44 pm
Posts: 1
i have the same problem with my wordpress and my smf forum .. both got infected ... please if you kow a way to get rid of this hijacking let me know.

thank you


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 

Quick reply

 



Who is online

Users browsing this forum: kakarukeys and 13 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group