The Joomla! Forum ™



Forum rules


Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: Mon May 07, 2012 4:53 pm 
Joomla! Explorer
Joomla! Explorer

Joined: Wed Dec 28, 2005 1:04 am
Posts: 269
Hi . . .

My clients site was attaced by a virus called Blackhole Exploit Kit (type 2146) I removed it and scanned the site and it was set as clean and not blacklisted. She is still getting errors when visiting the admin when she tries to edit the site in the section/content error. I cannot repeat the error on my side on any computer. It is only happening on her side. But it is only appearing when she tries to edit the site in the admin. Could it be her virus program that is throwing the error?

She scanned her home computer and cleaned a virus below
MacAfee removed the following potential threat: JS/Exploit-BlaCole.l (Trojan)
but she is still getting the error when visiting the site

thanks


Top
 Profile  
 
PostPosted: Thu May 10, 2012 3:44 pm 
User avatar
Joomla! Hero
Joomla! Hero

Joined: Sat Oct 21, 2006 10:20 pm
Posts: 2694
Location: Wisconsin USA
Due to the nature of what was found, I doubt you have it all. This malware is usually well hidden.

You should install and also have your client install at least one anti-malware program and run it to scan your and her computer(s). http://docs.joomla.org/Security_Checkli ... l_Security

Malwarebytes
Spybot Search and Destroy

These two are good ones and won't interfere with any installed anti-virus program. They also do not interfere with each other. I would do full scanns with scan with both as nothing can find or catch every malware program.

Once your and your clients computers are clean or scan clean, then follow what is below to properly clean and remove traces of the malware and repair the clients site.

PhilD wrote:

It is suggested to do all of the following. Failure to follow the suggestions below may leave your site vulnerable to being hacked again in the future.

You must state what version of Joomla you were using when when the site became hacked. This can make a difference as to how we approach your individual situation.

[ ] Run the Forum Post Assistant / FPA Instructions available here and are also included in the download package.

[ ] Ensure you have the latest version of Joomla. Delete all files in your Joomla installation, saving a copy of the configuration.php file. Replace the deleted files with fresh copies of a current full version of Joomla (minus the installation directory), and fresh copies of extensions and templates used. Upload the copy of your configuration file. Only by replacing all files in the installation (including extensions and templates) can you be sure to remove the backdoors inserted and hidden in files and directories More detail can be found in the security Checklist 7 link below.

[ ] Review Vulnerable Extensions List

[ ] Review and action Security Checklist 7 to make sure you've gone through all of the steps.

[ ] Scan all machines with FTP, Joomla super admin, and Joomla admin access for malware, virus, trojans, spyware, etc.

[ ] Change all passwords and if possible user names for the website host control panel and your Joomla site.

[ ] Use proper permissions on files and directories. They should never be 777, ideal is 644 and 755 and 444 for the configuration.php file.

[ ] Check your htaccess for for any odd code (i.e. code which is not in the standard htaccess supplied as part of the Joomla installation).

[ ] Check the crontab or Task Scheduler for unexpected jobs/tasks.

[ ] Ensure you do not have anonymous ftp enabled

Note: The forum post tool will work with 1.0.x, J1.6.x, J1.7.x, 2.5.x versions of Joomla.

_________________
PhilD -- Unrequested PM's and/or emails may not get a response.
Security Moderator


Top
 Profile  
 
PostPosted: Thu May 10, 2012 4:58 pm 
Joomla! Explorer
Joomla! Explorer

Joined: Wed Dec 28, 2005 1:04 am
Posts: 269
I did find the hack at the myApi component I had installed. I removed that. I also had the hosting company run a deep scan of the server for any Malware and it was found in the myApi component folder.

Thank you!


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 



Who is online

Users browsing this forum: No registered users and 17 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group