The Joomla! Forum ™



Forum rules


Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 5 posts ] 
Author Message
PostPosted: Sun May 06, 2012 12:30 pm 
Joomla! Fledgling
Joomla! Fledgling

Joined: Sun May 06, 2012 12:23 pm
Posts: 2
My site has become infected and I want to clean up my site from stratch. I wonder if its possible to backup my site for exampel my articles ? Or will these still be infected and maybe infected my new installed site?


Top
 Profile  
 
PostPosted: Sun May 06, 2012 1:23 pm 
User avatar
Joomla! Master
Joomla! Master

Joined: Wed Aug 17, 2005 10:27 pm
Posts: 14709
Location: Kent, England
[Mod note: Moved from General Forum to Security Forum;]


Top
 Profile  
 
PostPosted: Fri May 11, 2012 4:31 pm 
User avatar
Joomla! Hero
Joomla! Hero

Joined: Sat Oct 21, 2006 10:20 pm
Posts: 2694
Location: Wisconsin USA
Articles etc. are kept in the database. With the exception of possibly adding a super-admin account to the user table; Normally hacks leave the database data such as articles alone and only hack the files that run the site. Backup the database, but do not back up the files that make up the Joomla installation in public_html. Restoring those files from a backup will only restore the hack.

Follow that I post below to properly clean and repair your website:

PhilD wrote:

It is suggested to do all of the following. Failure to follow the suggestions below may leave your site vulnerable to being hacked again in the future.


You must state what version of Joomla you were using when when the site first became hacked. This can make a difference as to how we approach your individual situation.

[ ] Download and RUN the Forum Post Assistant / FPA Instructions available here and are also included in the download package. Post the generated results in your security/been hacked topic.

[ ] Ensure you have the latest version of Joomla. Delete all files in your Joomla installation, saving a copy of the configuration.php file. Replace the deleted files with fresh copies of a current full version of Joomla (minus the installation directory), and fresh copies of extensions and templates used. Upload the copy of your configuration file. Only by replacing all files in the installation (including extensions and templates) can you be sure to remove the backdoors inserted and hidden in files and directories More detail can be found in the security Checklist 7 link below.

[ ] Review Vulnerable Extensions List

[ ] Review and action Security Checklist 7 to make sure you've gone through all of the steps.

[ ] Scan all machines with FTP, Joomla super admin, and Joomla admin access for malware, virus, trojans, spyware, etc.

[ ] Change all passwords and if possible user names for the website host control panel and your Joomla site.

[ ] Use proper permissions on files and directories. They should never be 777, ideal is 644 and 755 and 444 for the configuration.php file.

[ ] Check your htaccess for for any odd code (i.e. code which is not in the standard htaccess supplied as part of the Joomla installation).

[ ] Check the crontab or Task Scheduler for unexpected jobs/tasks.

[ ] Ensure you do not have anonymous ftp enabled

Note: The forum post tool will work with all versions of Joomla.

_________________
PhilD -- Unrequested PM's and/or emails may not get a response.
Security Moderator


Top
 Profile  
 
PostPosted: Wed May 16, 2012 2:43 pm 
Joomla! Fledgling
Joomla! Fledgling

Joined: Sun May 06, 2012 12:23 pm
Posts: 2
Thanks for your reply

My site has been infected by some googlebot. When searh for my site in google and click on the search result the googlebot redirect the user to another site.

Hope this will help me getting rid of it. I have use the old joomla version 1.5 and will update my site to the latest version 2.5


Top
 Profile  
 
PostPosted: Wed May 16, 2012 3:17 pm 
User avatar
Joomla! Hero
Joomla! Hero

Joined: Sat Oct 21, 2006 10:20 pm
Posts: 2694
Location: Wisconsin USA
Your "GoogleBot Redirect" sounds like the htaccess redirect issue.
viewtopic.php?f=432&t=705216

Follow what I have posted above to properly repair the site.

_________________
PhilD -- Unrequested PM's and/or emails may not get a response.
Security Moderator


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 5 posts ] 



Who is online

Users browsing this forum: wasimshaari and 15 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group