Joomla hacked?

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
sylwekb
Joomla! Explorer
Joomla! Explorer
Posts: 384
Joined: Mon Mar 14, 2011 5:08 pm

Joomla hacked?

Post by sylwekb » Thu Mar 30, 2023 1:26 pm

Hello
Have you ever encountered a situation where someone called you and said that they could do everything from the registered user level, e.g. replace photos, etc.? Can you fully protect yourself from it?

Regards

Joomla 3.10.11

User avatar
AMurray
Joomla! Exemplar
Joomla! Exemplar
Posts: 9747
Joined: Sat Feb 13, 2010 7:35 am
Location: Australia

Re: Joomla hacked?

Post by AMurray » Thu Mar 30, 2023 9:46 pm

Do you mean this caller claims he can change only content an Editor or Publisher might create and edit from the front-end, and not administrative functions normally done by a Manager, Administrator or Super administrator in the back-end?

Suggest updating to Joomla 4. (Joomla 3.10.11 will be out of support by August). While 3.10 gets security updates, the team needs to know about security issues. If concerned, I suggest reporting it to https://issues.joomla.org - with full details and where possible, methodology to replicate the problem.

If the caller is claiming he can do things normally prohibited as a registered user, I'd have thought there would be some record of it in the User Action Log. "Joe Bloggs updated [such and such] article on DD/MM/YYYY") or things like that.

Are you sure they are not registered as an Editor or Publisher, rather than just Registered?

Check the User Manager list and see if you can identify any registered user that looks "out of place".

https://docs.joomla.org/J3.x:User_Action_Logs
https://docs.joomla.org/Help310:Compone ... gs_Options

As to protecting users:
  • Have your registered users use very strong passwords (no words commonly known, and none from dictionaries)
  • increase the number of characters required in a password e.g. minimum 12 characters.
  • Set minimum numbers of different characters - e.g. mix of alpha-numeric and symbols (e.g.mini 2 numbers, min 2 symbols).
  • Encourage the use of Multi-factor authentication (MFA). (As you're on 3.10, suggest the inbuilt 2FA, or Akeeba's Login Guard (which in J4, is now part of the core as of v4.2), but is still available as a download for J3.x
Regards - A Murray
General Support Moderator

sylwekb
Joomla! Explorer
Joomla! Explorer
Posts: 384
Joined: Mon Mar 14, 2011 5:08 pm

Re: Joomla hacked?

Post by sylwekb » Fri Mar 31, 2023 6:52 am

Thank you for your answer. Indeed, in the event log I have such a user Suddeas77777 and his IP address, he is only registered but I do not see a hack. I scanned the server for antivirus and found nothing. Yes, it claims that from the level of registered permissions it can do everything, but I don't see it. I don't see anything unusual in the server logs for this IP address. The hosting provider also confirmed that he did not see anything unusual in this user's behavior. As a preventive measure, I changed the admin, database and FTP user passwords to very strong ones. All in all, these passwords were already very strong and in line with current standards.

User avatar
AMurray
Joomla! Exemplar
Joomla! Exemplar
Posts: 9747
Joined: Sat Feb 13, 2010 7:35 am
Location: Australia

Re: Joomla hacked?

Post by AMurray » Thu Apr 06, 2023 10:52 pm

if still concerned, suggest doing a full audit of the site with mysites.guru (first audit is free) but it is a subscription service well worth its weight in Euros, so to speak.
Regards - A Murray
General Support Moderator

sylwekb
Joomla! Explorer
Joomla! Explorer
Posts: 384
Joined: Mon Mar 14, 2011 5:08 pm

Re: Joomla hacked?

Post by sylwekb » Fri Apr 07, 2023 6:55 am

I monitor the site all the time and my hosting provider has turned on additional monitoring for this site and has not detected anything so far. My website has a lot of data. I am aware of the end of support for Joomla 3.10.11 and I am planning to migrate to Joomla 4 but for now there are no add-ons for Joomla 4.

User avatar
Per Yngve Berg
Joomla! Master
Joomla! Master
Posts: 30942
Joined: Mon Oct 27, 2008 9:27 pm
Location: Romerike, Norway

Re: Joomla hacked?

Post by Per Yngve Berg » Fri Apr 07, 2023 7:50 am

Photos etc. are stored as regular files on the server. They can be accessed directly without going through Joomla. Are file permissions set correctly on the server?

sylwekb
Joomla! Explorer
Joomla! Explorer
Posts: 384
Joined: Mon Mar 14, 2011 5:08 pm

Re: Joomla hacked?

Post by sylwekb » Fri Apr 07, 2023 8:14 am

The hosting provider says all permissions are correct. I checked in Filezilla and they also agree with the Joomla documentation. I will be migrating to Joomla 4 soon but I have a problem because I have over 10000 attachments and the developer of the add-on has opted out of updating to Joomla 4 https://extensions.joomla.org/extension/attachments/. This is a really great addition to handle attachments in an article. I looked at other add-ons but they work differently and there will be a problem with automatic migration. Handling such a large amount by hand is a lot of work.

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44096
Joined: Sat Apr 05, 2008 9:58 pm

Re: Joomla hacked?

Post by Webdongle » Fri Apr 07, 2023 8:57 am

sylwekb wrote:
Thu Mar 30, 2023 1:26 pm
Hello
Have you ever encountered a situation where someone called you and said that they could do everything from the registered user level, e.g. replace photos, etc.? Can you fully protect yourself from it?

Regards

Joomla 3.10.11
If they could do it they would have done it. If they done it they would only contact you if they locked you out and ransomed the site.
http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".


Locked

Return to “Security in Joomla! 3.x”