malicious joomla update notification

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
sopp_ladios
Joomla! Fledgling
Joomla! Fledgling
Posts: 4
Joined: Sun Aug 06, 2017 7:23 pm

malicious joomla update notification

Post by sopp_ladios » Sun Aug 06, 2017 7:41 pm

Hi all,


i have recently received a number of joomla update notification emails.
Most of which looks perfectly normal, except for a few that shows domain names which are not of my site's.

it comes with heading like this (translated to eng so the wordings may not agree with the 'original')

Joomla! update available <site name is always correct> – http://www . [ redacted ] . com/ <-- but this is not my site

(tells me that 3.7.3 update is available with my site currently at 3.7.2... )

and the update link included also points to the above malicious site:

http://www . [ redacted ] . com/administrator/...

i have so far received such notifications pointing to the following sites:
www . [ redacted ] . com
[ redacted ] . com


have any one else came across these?
i plan on upgrading my site but would like to make sure it is clean, how should i proceed?

thanks. =>
Last edited by toivo on Sun Aug 06, 2017 8:37 pm, edited 1 time in total.
Reason: mod note: moved to 3.x Security, malicious domains removed

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: malicious joomla update notification

Post by mandville » Sun Aug 06, 2017 9:08 pm

so let me get this straight, you get an email everytime you log into your site to say that your out of date site is out of date and vulnerable to exploits?
how is that malicious.
as regarding other domain names you claim are not yours,. what does your host say
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

sopp_ladios
Joomla! Fledgling
Joomla! Fledgling
Posts: 4
Joined: Sun Aug 06, 2017 7:23 pm

Re: malicious joomla update notification

Post by sopp_ladios » Mon Aug 07, 2017 6:45 am

so let me get this straight, you get an email everytime you log into your site to say that your out of date site is out of date and vulnerable to exploits? how is that malicious.

-------------
I know those are legit notifications and have no problem with those...
I have since updated the site but am just wondering how those malicious notifications get sent among the legit ones...
-------------

as regarding other domain names you claim are not yours,. what does your host say

-------------
I host my own site.
I have also checked the email headers and it shows that the 'sender' is in fact my site admin (the email account I set in Joomla admin console), this is what bugs me.
-------------

apart from a little outdated on joomla version, the server has selinux enforced blocking all write access apart from the images folder (which I checked and found nothing), all folders/files set to 755/644 as advised under htdocs and behind a separate firewall which only has port 80 opened.

jadeuniverse
Joomla! Fledgling
Joomla! Fledgling
Posts: 1
Joined: Sun May 17, 2009 3:54 pm

Re: malicious joomla update notification

Post by jadeuniverse » Thu Oct 05, 2017 4:09 pm

Hi sopp_ladios,

I have received that weird notification mail you mentioned before
Correct site name but false domain name
I have updated my site, everything seems OK
Should I be worried?
How did you solve that?


Locked

Return to “Security in Joomla! 3.x”