Google say my site is still hacked after cleanup [solved]

Discussion regarding Joomla! 3.x security issues.

Moderators: Bernard T, mandville, fcoulter, PhilD, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
User avatar
bgrinter
Joomla! Apprentice
Joomla! Apprentice
Posts: 38
Joined: Wed Jan 03, 2007 2:06 pm
Location: Sydney

Google say my site is still hacked after cleanup [solved]

Postby bgrinter » Thu Apr 20, 2017 9:56 pm

Hi
I have a site (http://www.airleague.com.au) that was hacked in March and cleaned by Phil at myjoomla.com

This morning I received an email from Google


Content injection
These pages appear to be modified by a hacker with the intent of spamming search results.
Show details
Sample URLs Last detected
http://www.airleague.com.au/?start=30 10/04/2017
http://www.airleague.com.au/news/articl ... -last-f111 10/04/2017


This was 11 days ago, but after the cleanup.

I've run another audit from myjoomla.com and no hacked content found

I've checked the pages rendered by google and appears to be no spammy content

I've downloaded samples from their page but the "snippets" column is empty

Has anyone seem false positives before? Is this showing me old results from before the cleanup?

Before I request a review I want to make sure everything is covered
Last edited by mandville on Sun Apr 23, 2017 3:21 pm, edited 1 time in total.
Reason: marked solved as per op
Brian

User avatar
leolam
Joomla! Master
Joomla! Master
Posts: 17497
Joined: Mon Aug 29, 2005 10:17 am
Location: Netherlands/ UK/ S'pore/Jakarta/ North America
Contact:

Re: Google say my site is still hacked after cleanup

Postby leolam » Fri Apr 21, 2017 4:31 am

Links and site seem to be clean (virustotal.com). I have scanned the 2 pages for any malicious code and reviewed the code and the pages do not contain any malware. You can ask for a review imho but one general remark is needed. You should consider getting an SSL for the site. Google is since January indexing sites that have a) login and b) mail subscription without any SSL as risky sites. That is since their campaign Safe Browsing started and will give your site in their Chrome browser (Firefox starts implementing this moment as well) the "unsafe" warning (you are already marked as unsafe) See more https://security.googleblog.com/2016/09 ... e-web.html

I would first make sure that you have a proper working SSL installed, make sure that your script links (mailchimp for instance) point to https external site links (otherwise you still will get unsafe notice) and follow up after that with a Review

Leo 8)
- Joomla Professional Support Services :https://gws-desk.com -
- Joomla Specialized Hosting Solutions:https://gws-host.com -
- Joomla Professional Web Development :www.gws-studio.com -
- Member Joomla Bug Squad & J-CMS Release Team

User avatar
bgrinter
Joomla! Apprentice
Joomla! Apprentice
Posts: 38
Joined: Wed Jan 03, 2007 2:06 pm
Location: Sydney

Re: Google say my site is still hacked after cleanup

Postby bgrinter » Fri Apr 21, 2017 5:27 am

Thanks for the quick reply Leo

Sorting out SSL is on the to-do list for this weekend. Its a website for a not-for-profit so maintenance is done after hours / weekends.

Things we do! :)
Brian

User avatar
leolam
Joomla! Master
Joomla! Master
Posts: 17497
Joined: Mon Aug 29, 2005 10:17 am
Location: Netherlands/ UK/ S'pore/Jakarta/ North America
Contact:

Re: Google say my site is still hacked after cleanup

Postby leolam » Fri Apr 21, 2017 6:14 am

namecheap.com offers cheap SSL (Comodo Positive SSL only US$ 9,95/year . Sufficient for a non-profit

Leo 8)
- Joomla Professional Support Services :https://gws-desk.com -
- Joomla Specialized Hosting Solutions:https://gws-host.com -
- Joomla Professional Web Development :www.gws-studio.com -
- Member Joomla Bug Squad & J-CMS Release Team

User avatar
bgrinter
Joomla! Apprentice
Joomla! Apprentice
Posts: 38
Joined: Wed Jan 03, 2007 2:06 pm
Location: Sydney

Re: Google say my site is still hacked after cleanup

Postby bgrinter » Sun Apr 23, 2017 1:03 pm

leolam wrote:namecheap.com offers cheap SSL (Comodo Positive SSL only US$ 9,95/year . Sufficient for a non-profit

Leo 8)

Found a local hosting company who include SSL with plans - moving to new hosts and getting set up

Getting there :P
Brian

User avatar
bgrinter
Joomla! Apprentice
Joomla! Apprentice
Posts: 38
Joined: Wed Jan 03, 2007 2:06 pm
Location: Sydney

Re: Google say my site is still hacked after cleanup

Postby bgrinter » Sun Apr 23, 2017 2:02 pm

Ok - I've got an SSL certificate set up, I've configured Force HTTPS for entire site, however I only see a padlock on the administrator backend, not the front end.

Is there anything I'm missing?

https://www.airleague.com.au
Brian

User avatar
bgrinter
Joomla! Apprentice
Joomla! Apprentice
Posts: 38
Joined: Wed Jan 03, 2007 2:06 pm
Location: Sydney

Re: Google say my site is still hacked after cleanup

Postby bgrinter » Sun Apr 23, 2017 2:29 pm

bgrinter wrote:Ok - I've got an SSL certificate set up, I've configured Force HTTPS for entire site, however I only see a padlock on the administrator backend, not the front end.

Is there anything I'm missing?

https://www.airleague.com.au


Nevermind - PEBKAC

All good now.

Now to get Google to remove the flag on the results...
Brian


Return to “Security in Joomla! 3.x”

Who is online

Users browsing this forum: hoanta and 9 guests