My site was hacked, so that visitors would see a plain white screen with this text:
A1TS /home/clements Ownz /home/clements :: by Shaka
It appears that only the index.php file was over written. I could still access the back end and all the content was still there. As well, a second installation of Joomla (1.0.7) in a sub domain remained untouched.
Details:
Joomla 1.0.8
PHP 4.4.1
MySQL 4.1.14-standard-log
Apache 1.3.34 (Unix)
Site is hosted by
http://www.bluehost.com and is shared hosting.
I have access to the “Raw Access Logs” through cpanel, but have trouble sorting through the text. (Is there some sort of application that organizes that data?)
I have the following components installed on the site: AKObook 3.42 with the hack to add the security codes; Coppermine 1.4.3; CoppermineVIS Premium 1.30; joomlaXplorer 1.3.2; mosCE 1.0.3; PU Arcade.
Hmm… I *did* have JCE editor installed, but it seems to have vanished.
I have the following mambots installed: MGM Image Gallery; Imbed PHP (kl_php); the usual regular stuff.
My service provider told me this: My Fantastico control panel indicates I have Coppermine 1.3.4 and Joomla 1.0.3 installed. Those are the last versions I had installed via Fantastico before I started doing it myself. The tech support guy claimed that this is how the kiddie got in and told me to uninstall those old versions through Control Panel if I had manually installed newer versions myself. I am 99.999% sure that if I do that, I will be uninstalling my existing versions. He told me to do a full back up download, uninstall, then reinstall from the back up to clean it up, making the additional claim that I needed to do this because they probably got into my databases, too. Hmmm. Is this good advice?
Meanwhile, they did a restore and the site is back. I think if I just had a copy of the index.php file I could have uploaded it.
One more piece of information: I use .htaccess to protect the admin folder, so I have to login twice when accessing the backend, once to get through .htaccess, and once to get into Joomla.
The big question is: Where is the weak point that allowed this to happen?Edit: title of post