Hacked UPDATE

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
craig2006
Joomla! Explorer
Joomla! Explorer
Posts: 267
Joined: Wed Mar 01, 2006 1:18 pm
Location: Kansas USA
Contact:

Hacked UPDATE

Post by craig2006 » Sun Aug 17, 2008 3:26 pm

Update: I have since reloaded my 1.5.6. Changed all passwords and access to Administrator. Infact, best thing to do, it create another super admin, and delete the original admin. A good trick from a couple of suggestions from users. Thanks


My site got hacked also. Just noticed this this morning. I also notice many all of a sudden around the world are having hack issues. the Config file was changed. I was using 1.5.4. and going to upgrade soon, but never previously had a problem.

How would the Config file be changed? How can I prevent this?
Craig Davis
CD-Vision Marketing
http://www.cdvisionmarketing.com/

User avatar
adamos46
Joomla! Explorer
Joomla! Explorer
Posts: 275
Joined: Sat Apr 26, 2008 6:05 am
Location: New Jersey

Re: Hacked UPDATE

Post by adamos46 » Mon Aug 18, 2008 7:00 pm

chmod 444 configuration.php if you are using linux or through your sftp client change it to 444

User avatar
ircmaxell
Joomla! Ace
Joomla! Ace
Posts: 1926
Joined: Thu Nov 10, 2005 3:10 am
Location: New Jersey, USA
Contact:

Re: Hacked UPDATE

Post by ircmaxell » Mon Aug 18, 2008 7:31 pm

craig2006 wrote:I was using 1.5.4. and going to upgrade soon, but never previously had a problem.
And you wonder why you got hacked? Tip: When you see a critical security release announced, don't "plan" to upgrade... UPGRADE...
Anthony Ferrara - Core Team - Development Coordinator - Bug Squad - JSST

http://moovum.com/ - The Bird is in the air! Get Mollom Anti-Spam on your Joomla! website with Moovur...
http://www.joomlaperformance.com For All Your Joomla Performance Needs

craig2006
Joomla! Explorer
Joomla! Explorer
Posts: 267
Joined: Wed Mar 01, 2006 1:18 pm
Location: Kansas USA
Contact:

Re: Hacked UPDATE

Post by craig2006 » Tue Aug 19, 2008 1:15 am

definitely.
Craig Davis
CD-Vision Marketing
http://www.cdvisionmarketing.com/

craig2006
Joomla! Explorer
Joomla! Explorer
Posts: 267
Joined: Wed Mar 01, 2006 1:18 pm
Location: Kansas USA
Contact:

Re: Hacked UPDATE

Post by craig2006 » Tue Aug 19, 2008 1:22 am

Adamos, where is ? - chmod - ? not sure what this is/located.
Craig Davis
CD-Vision Marketing
http://www.cdvisionmarketing.com/

orware
Joomla! Explorer
Joomla! Explorer
Posts: 255
Joined: Mon Jul 10, 2006 8:16 pm
Location: CA
Contact:

Re: Hacked UPDATE

Post by orware » Tue Aug 19, 2008 1:49 am

In your FTP program, just right-click on the configuration.php file and choose Properties and then it will have a 3x3 grid where you can select the read, write, and execute permissions and it should also have a box where you can type in the exact permissions right away. The text box is where you type in 444.

User avatar
adamos46
Joomla! Explorer
Joomla! Explorer
Posts: 275
Joined: Sat Apr 26, 2008 6:05 am
Location: New Jersey

Re: Hacked UPDATE

Post by adamos46 » Tue Aug 19, 2008 1:50 am

If you have ssh type it in the correct path or edit it with sftp to make it 444. Or move you configuration.php outside your joomla root directory

craig2006
Joomla! Explorer
Joomla! Explorer
Posts: 267
Joined: Wed Mar 01, 2006 1:18 pm
Location: Kansas USA
Contact:

Re: Hacked UPDATE

Post by craig2006 » Tue Aug 19, 2008 5:24 pm

Right. It is best to have all the attributes checked? Or just 'read'. Does it default to that setting? Write was checked and 444 illustrated.
Craig Davis
CD-Vision Marketing
http://www.cdvisionmarketing.com/


Locked

Return to “Security in Joomla! 1.5”