Discovering vulnerability, site keeps on getting hacked
Moderators: mandville, General Support Moderators
Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
-
- Joomla! Intern
- Posts: 67
- Joined: Sun Oct 15, 2006 12:44 pm
Discovering vulnerability, site keeps on getting hacked
Hi,
I have a site that keeps on getting hacked. I wonder if there is a way to discover how. The site works again when I restore the site's files, so it's nothing in the database.
Things I did to prevent:
- upgrade all components and Joomla (to Joomla 3.x, Joomla 4 is not possible because of template framework)
- configure permissions with Admin Tools
- installed WAF (Admin Tools Pro)
- Changed passwords
- Scanned for infected files
Cheers,
BC
I have a site that keeps on getting hacked. I wonder if there is a way to discover how. The site works again when I restore the site's files, so it's nothing in the database.
Things I did to prevent:
- upgrade all components and Joomla (to Joomla 3.x, Joomla 4 is not possible because of template framework)
- configure permissions with Admin Tools
- installed WAF (Admin Tools Pro)
- Changed passwords
- Scanned for infected files
Cheers,
BC
-
- Joomla! Champion
- Posts: 5950
- Joined: Tue Aug 23, 2005 1:56 pm
- Location: South coast, UK
- Contact:
Re: Discovering vulnerability, site keeps on getting hacked
Go to mysites.guru ,the first audit is free.
https://gadsolutions.biz Electrical services
https://electrical-testing-safety.co.uk Testing services
https://electrical-testing-safety.co.uk Testing services
-
- Joomla! Intern
- Posts: 67
- Joined: Sun Oct 15, 2006 12:44 pm
Re: Discovering vulnerability, site keeps on getting hacked
Not an option, I seem to have used that service before, some years ago,
BC
BC
- leolam
- Joomla! Master
- Posts: 20652
- Joined: Mon Aug 29, 2005 10:17 am
- Location: Netherlands/ Germany/ S'pore/Bogor/ North America
- Contact:
Re: Discovering vulnerability, site keeps on getting hacked
That is not a good reply.... Phil is the best in his field and you should use his service because it could be a server issue as well and hidden code which IS discovered by mysites.guru. Dont be a fool
Leo
Joomla's #1 Professional Services Provider:
#Joomla Professional Support: https://gws-desk.com -
#Joomla Specialized Hosting Solutions: https://gws-host.com -
#Joomla Professional Support: https://gws-desk.com -
#Joomla Specialized Hosting Solutions: https://gws-host.com -
- PhilTaylor-Prazgod
- Joomla! Ace
- Posts: 1402
- Joined: Sat Aug 20, 2005 12:32 pm
- Location: Jersey, Channel Islands
- Contact:
Re: Discovering vulnerability, site keeps on getting hacked
What he means is, he used his free trial and doesn't want to pay.Not an option, I seem to have used that service before, some years ago,
There are other services available charing 199.99-499.99 per year for a SINGLE site if you would prefer:
https://sucuri.net/website-security-platform/signup/
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- leolam
- Joomla! Master
- Posts: 20652
- Joined: Mon Aug 29, 2005 10:17 am
- Location: Netherlands/ Germany/ S'pore/Bogor/ North America
- Contact:
Re: Discovering vulnerability, site keeps on getting hacked
Sure , a free ride to eternal happiness (just did not wanted to be too direct)
Leo
Leo
Joomla's #1 Professional Services Provider:
#Joomla Professional Support: https://gws-desk.com -
#Joomla Specialized Hosting Solutions: https://gws-host.com -
#Joomla Professional Support: https://gws-desk.com -
#Joomla Specialized Hosting Solutions: https://gws-host.com -
-
- Joomla! Intern
- Posts: 67
- Joined: Sun Oct 15, 2006 12:44 pm
Re: Discovering vulnerability, site keeps on getting hacked
Well, someone offered a free scan and simply replied that is not possible. I did not state anything about not wanting to pay anything, that's on you.
BC
BC
- PhilTaylor-Prazgod
- Joomla! Ace
- Posts: 1402
- Joined: Sat Aug 20, 2005 12:32 pm
- Location: Jersey, Channel Islands
- Contact:
Re: Discovering vulnerability, site keeps on getting hacked
LMAO you did not pay anything last time also... but hey up to you. Im not allowed to talk openly about any service I run due to forum rules, so you are at an advantage.
There are other services available, but literally, this is what I do for a living for the last 2 decades.
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
-
- Joomla! Intern
- Posts: 67
- Joined: Sun Oct 15, 2006 12:44 pm
Re: Discovering vulnerability, site keeps on getting hacked
Yeah, of course, last time was free, why would I pay then?
- PhilTaylor-Prazgod
- Joomla! Ace
- Posts: 1402
- Joined: Sat Aug 20, 2005 12:32 pm
- Location: Jersey, Channel Islands
- Contact:
Re: Discovering vulnerability, site keeps on getting hacked
mySites.guru is a subscription service with a limited free trial. It is not a free service.why would I pay then?
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
-
- Joomla! Intern
- Posts: 67
- Joined: Sun Oct 15, 2006 12:44 pm
Re: Discovering vulnerability, site keeps on getting hacked
What is so hard about this? I'm aware the first scan is free and the rest is paid. No argument there.
- Gasoline
- Joomla! Explorer
- Posts: 468
- Joined: Tue Aug 23, 2005 10:33 am
- Location: NL
Re: Discovering vulnerability, site keeps on getting hacked
Just take a one month sub. And you'r problems are solved. I use his serves for almost 8 years now. And will as long as I have Joomla sites. You won't find anything else this good and complete.
Using Joomla since 2005.
-
- Joomla! Intern
- Posts: 67
- Joined: Sun Oct 15, 2006 12:44 pm
Re: Discovering vulnerability, site keeps on getting hacked
-
- Joomla! Intern
- Posts: 67
- Joined: Sun Oct 15, 2006 12:44 pm
Re: Discovering vulnerability, site keeps on getting hacked
Interesting, adding a site does not work, nor automatically, nor manually.
BC
BC
- PhilTaylor-Prazgod
- Joomla! Ace
- Posts: 1402
- Joined: Sat Aug 20, 2005 12:32 pm
- Location: Jersey, Channel Islands
- Contact:
Re: Discovering vulnerability, site keeps on getting hacked
> Interesting, adding a site does not work, nor automatically, nor manually.
There is literally a contact link on every single page of the mySites.guru service. You used it, you got support instantly. You dont mention any of that.
We could not connect to your site because your SSL was incorrectly installed, and did not have the full bundle chain of certificates installed - something that remains the case right now. Teaching people how to correctly install SSL Certificates is beyond the role of the service, but we will attempt to make SECURE connections by default. We enabled a workaround to insecurely connect to your domain.
You received a reply to your support request in 4 mins after it arrived.
For the record, and for balance, you did manage to get connected, and your site was hacked, and the service did reveal LOTS of ancient backdoors and hacked files.
Adding a site did work, and I see you have already started removing the hack. If you are going to tell people that my service "does not work" at least offer the full facts.
There is literally a contact link on every single page of the mySites.guru service. You used it, you got support instantly. You dont mention any of that.
We could not connect to your site because your SSL was incorrectly installed, and did not have the full bundle chain of certificates installed - something that remains the case right now. Teaching people how to correctly install SSL Certificates is beyond the role of the service, but we will attempt to make SECURE connections by default. We enabled a workaround to insecurely connect to your domain.
You received a reply to your support request in 4 mins after it arrived.
For the record, and for balance, you did manage to get connected, and your site was hacked, and the service did reveal LOTS of ancient backdoors and hacked files.
Adding a site did work, and I see you have already started removing the hack. If you are going to tell people that my service "does not work" at least offer the full facts.
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/