The Joomla! Forum ™



Forum rules


Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 7 posts ] 
Author Message
PostPosted: Fri Apr 27, 2012 1:23 pm 
Joomla! Enthusiast
Joomla! Enthusiast

Joined: Tue Sep 21, 2010 2:39 pm
Posts: 152
I suddenly lost access to my backend. I enter the correct username and password, but they don't work...

initially, I couldn't login, the loading of the backend would fail and I had to point to a page inside, e.g. com_content to gain access.

Then as I was working, I was logged off, and my login details don't work since.

I checked the database and the username are still there, but for some reason, the passwords don;t work...

I don;t know if it is related to this, but today I had been getting fatal errors once in a while with modules anywhere extension by nonnumber, a fatal error on the helper.php file, line 411...

The site is still online, nothing unusual besides me being locked out...logging in on the frontend does not work either...says I got to rights to connect...

Where can I find the administrator's password?
How can I change it?


Top
 Profile  
 
PostPosted: Fri Apr 27, 2012 1:38 pm 
User avatar
Joomla! Master
Joomla! Master

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11629
Location: The Girly Side of Joomla in Sussex
treat your site as hacked.
[ ] Review Vulnerable Extensions List

[ ] Review and action Security Checklist checklist 7 to make sure you've gone through all of the steps.


[ ] Run the Forum Post Assistant / FPA Instructions available here and are also included in the download package.

[ ] Ensure you have the latest version of Joomla. Delete all files in your Joomla installation. Replace the deleted files with fresh copies of a current full version of Joomla, and fresh copies of extensions and templates used. Only by replacing all files in the installation (including extensions and templates) can you be sure to remove the backdoors inserted and hidden in files and directories


[ ] Scan all machines with FTP, Joomla super admin, and Joomla admin access for malware, virus, trojans, spyware, etc.

[ ] Change all passwords and if possible user names for the website host control panel and your Joomla site.

[ ] Use proper permissions on files and directories. They should never be 777, but ideal is 644 and 755

[ ] Check your htaccess for for any odd code (i.e. code which is not in the standard htaccess supplied as part of the Joomla installation).

[ ] Check the crontab or Task Scheduler for unexpected jobs/tasks.

[ ] Ensure you do not have anonymous ftp enabled

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Fri Apr 27, 2012 1:50 pm 
Joomla! Enthusiast
Joomla! Enthusiast

Joined: Tue Sep 21, 2010 2:39 pm
Posts: 152
Thank you for your response...

Just a couple of minutes after submitting this report, I got back access to my site (not sure if this is more suspicious than losing access in the first place) and immediately changed passwords...

I've checked htaccess and index.php files (never lost access to my CPanel Administration), even during being locked out and didn't see anything unusual...
In CPanel I saw that at the time when I got locked out of my site, the host seems to have changed the entry processes limit (from 50 to 25)...

Before I get to the process described above, could this be explained in any other way?

I'd better be safe than sorry, so I'll go through the process anyhow.

Also, the site was inside a root folder of my hosting account (another site/domain) at public_html and the site I had the trouble with, in a subfolder...
Should I do this for both sites?


Top
 Profile  
 
PostPosted: Fri Apr 27, 2012 1:57 pm 
User avatar
Joomla! Master
Joomla! Master

Joined: Mon Mar 20, 2006 1:56 am
Posts: 11629
Location: The Girly Side of Joomla in Sussex
check you nonumber extension with the latest versions

_________________
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be added to the foe list and possibly just deleted
{Community.Connect Administrator }{ Showcase & Security Moderator}


Top
 Profile  
 
PostPosted: Fri Apr 27, 2012 2:05 pm 
Joomla! Enthusiast
Joomla! Enthusiast

Joined: Tue Sep 21, 2010 2:39 pm
Posts: 152
They were all already updated to their latest version, but reinstalled them anyhow...


Top
 Profile  
 
PostPosted: Fri Apr 27, 2012 4:49 pm 
Joomla! Explorer
Joomla! Explorer

Joined: Sat Aug 13, 2011 6:27 am
Posts: 299
Maybe your database server were extremely slow just under login and that's why it did not work just then.


Top
 Profile  
 
PostPosted: Fri Apr 27, 2012 5:18 pm 
Joomla! Enthusiast
Joomla! Enthusiast

Joined: Tue Sep 21, 2010 2:39 pm
Posts: 152
Hmm don't know really...network is fast, databases run off SSD disks, never happened before either and it was persistent for a period of time (maybe around 30-40 minutes overall since first problems started till my last attempt at logging in worked)...

The site had many guests earlier, around 280, but when the problem started they weren't more than 50-60 guests...

i have Admin Tools installed, protecting the administrator area with an extra password, I have also used it to change the superadmin's id number, the configuration.php file was set to non-writable...

If it was anything, it must have been an extension...the Modules Anywhere extension was previously failing because of requesting more memory than allocated...actually I use it inside each article, loading a "Relative Articles" module, because it would get loaded after Disqus comments if I set it at a position below the content...

But how could that have interfered with the login?


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 



Who is online

Users browsing this forum: wasimshaari and 15 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group