Google say my site is still hacked after cleanup [solved]

Discussion regarding Joomla! 3.x security issues.

Moderators: Bernard T, mandville, fcoulter, PhilD, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
User avatar
bgrinter
Joomla! Apprentice
Joomla! Apprentice
Posts: 38
Joined: Wed Jan 03, 2007 2:06 pm
Location: Sydney

Google say my site is still hacked after cleanup [solved]

Postby bgrinter » Thu Apr 20, 2017 9:56 pm

Hi
I have a site (http://www.airleague.com.au) that was hacked in March and cleaned by Phil at myjoomla.com

This morning I received an email from Google


Content injection
These pages appear to be modified by a hacker with the intent of spamming search results.
Show details
Sample URLs Last detected
http://www.airleague.com.au/?start=30 10/04/2017
http://www.airleague.com.au/news/articl ... -last-f111 10/04/2017


This was 11 days ago, but after the cleanup.

I've run another audit from myjoomla.com and no hacked content found

I've checked the pages rendered by google and appears to be no spammy content

I've downloaded samples from their page but the "snippets" column is empty

Has anyone seem false positives before? Is this showing me old results from before the cleanup?

Before I request a review I want to make sure everything is covered
Last edited by mandville on Sun Apr 23, 2017 3:21 pm, edited 1 time in total.
Reason: marked solved as per op
Brian

User avatar
leolam
Joomla! Master
Joomla! Master
Posts: 18006
Joined: Mon Aug 29, 2005 10:17 am
Location: Netherlands/ UK/ S'pore/Jakarta/ North America
Contact:

Re: Google say my site is still hacked after cleanup

Postby leolam » Fri Apr 21, 2017 4:31 am

Links and site seem to be clean (virustotal.com). I have scanned the 2 pages for any malicious code and reviewed the code and the pages do not contain any malware. You can ask for a review imho but one general remark is needed. You should consider getting an SSL for the site. Google is since January indexing sites that have a) login and b) mail subscription without any SSL as risky sites. That is since their campaign Safe Browsing started and will give your site in their Chrome browser (Firefox starts implementing this moment as well) the "unsafe" warning (you are already marked as unsafe) See more https://security.googleblog.com/2016/09 ... e-web.html

I would first make sure that you have a proper working SSL installed, make sure that your script links (mailchimp for instance) point to https external site links (otherwise you still will get unsafe notice) and follow up after that with a Review

Leo 8)
Get Professional Joomla Support Services
- Joomla Professional Support:https://gws-desk.com -
- Joomla Specialized Hosting Solutions:https://gws-host.com -
- Member Joomla Bug Squad & J-CMS Release Team

User avatar
bgrinter
Joomla! Apprentice
Joomla! Apprentice
Posts: 38
Joined: Wed Jan 03, 2007 2:06 pm
Location: Sydney

Re: Google say my site is still hacked after cleanup

Postby bgrinter » Fri Apr 21, 2017 5:27 am

Thanks for the quick reply Leo

Sorting out SSL is on the to-do list for this weekend. Its a website for a not-for-profit so maintenance is done after hours / weekends.

Things we do! :)
Brian

User avatar
leolam
Joomla! Master
Joomla! Master
Posts: 18006
Joined: Mon Aug 29, 2005 10:17 am
Location: Netherlands/ UK/ S'pore/Jakarta/ North America
Contact:

Re: Google say my site is still hacked after cleanup

Postby leolam » Fri Apr 21, 2017 6:14 am

namecheap.com offers cheap SSL (Comodo Positive SSL only US$ 9,95/year . Sufficient for a non-profit

Leo 8)
Get Professional Joomla Support Services
- Joomla Professional Support:https://gws-desk.com -
- Joomla Specialized Hosting Solutions:https://gws-host.com -
- Member Joomla Bug Squad & J-CMS Release Team

User avatar
bgrinter
Joomla! Apprentice
Joomla! Apprentice
Posts: 38
Joined: Wed Jan 03, 2007 2:06 pm
Location: Sydney

Re: Google say my site is still hacked after cleanup

Postby bgrinter » Sun Apr 23, 2017 1:03 pm

leolam wrote:namecheap.com offers cheap SSL (Comodo Positive SSL only US$ 9,95/year . Sufficient for a non-profit

Leo 8)

Found a local hosting company who include SSL with plans - moving to new hosts and getting set up

Getting there :P
Brian

User avatar
bgrinter
Joomla! Apprentice
Joomla! Apprentice
Posts: 38
Joined: Wed Jan 03, 2007 2:06 pm
Location: Sydney

Re: Google say my site is still hacked after cleanup

Postby bgrinter » Sun Apr 23, 2017 2:02 pm

Ok - I've got an SSL certificate set up, I've configured Force HTTPS for entire site, however I only see a padlock on the administrator backend, not the front end.

Is there anything I'm missing?

https://www.airleague.com.au
Brian

User avatar
bgrinter
Joomla! Apprentice
Joomla! Apprentice
Posts: 38
Joined: Wed Jan 03, 2007 2:06 pm
Location: Sydney

Re: Google say my site is still hacked after cleanup

Postby bgrinter » Sun Apr 23, 2017 2:29 pm

bgrinter wrote:Ok - I've got an SSL certificate set up, I've configured Force HTTPS for entire site, however I only see a padlock on the administrator backend, not the front end.

Is there anything I'm missing?

https://www.airleague.com.au


Nevermind - PEBKAC

All good now.

Now to get Google to remove the flag on the results...
Brian

User avatar
darb
Joomla! Ace
Joomla! Ace
Posts: 1201
Joined: Thu Jul 06, 2006 12:57 pm
Location: Stockholm Sweden
Contact:

Re: Google say my site is still hacked after cleanup

Postby darb » Sun Apr 30, 2017 9:02 am

leolam wrote:namecheap.com offers cheap SSL (Comodo Positive SSL only US$ 9,95/year . Sufficient for a non-profit

Leo 8)


Nothing better than free:) Lets Encrypt is free and working well too https://letsencrypt.org/ some hosting providers have this service for free..
Success in the long run Its not about the code its about the people and community that's make it!
Its not what you say its what you do that matters!

Darb - aka ssnobben


Return to “Security in Joomla! 3.x”

Who is online

Users browsing this forum: No registered users and 14 guests