Menu's Booby trapped Urgent Please Help

Discussion regarding Joomla! 3.x security issues.

Moderators: Bernard T, mandville, PhilD, fcoulter, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Starhorsepax
Joomla! Apprentice
Joomla! Apprentice
Posts: 29
Joined: Mon Nov 14, 2011 2:54 pm

Menu's Booby trapped Urgent Please Help

Postby Starhorsepax » Tue Sep 05, 2017 3:03 pm

:( The site in question belongs to a school, who we upgraded it for after it got hacked (It was Joomla 3.2 or so, they had never upgraded it. Ever. Very hacked to bits.) It was not an easy update specifically because it was hacked.

Now the menu items are randomly unpublishing themselves. New menu items are wrong. Old sub menu items are showing under the correct header in the front end, but in admin they say menu item root is parent. Move them and blooey, they die.

A glance in the database shows some have type 'component' instead of urls, the params don't all match with the working ones. Some are given a component ID. I have tried individually changing some of these to fix but nothing is working. If you try to move it an old item it unpublishes and refuses to republish.

Admittedly it was an unconventional update. Moving to a newer joomla by attaching database to newer core files and hitting fix database. (I think it was 3.6 something but don't remember for certain). Given how badly it was hacked, we did the best we could in the (much too short) time frame given. Now though we have all these bugs, so any advice how to fix would be appreciated.

User avatar
leolam
Joomla! Master
Joomla! Master
Posts: 18401
Joined: Mon Aug 29, 2005 10:17 am
Location: Netherlands/ UK/ S'pore/Jakarta/ North America
Contact:

Re: Menu's Booby trapped Urgent Please Help

Postby leolam » Tue Sep 05, 2017 3:54 pm

The way a site being restored from a hack is NEVER going to work and is plain wrong. You only have a good chance to restore a site by following the steps in this post viewtopic.php?f=714&t=946026

Leo 8)
Celebrating 12-Years of Professional Joomla Support Services
- Joomla Professional Support:https://gws-desk.com -
- Joomla Specialized Hosting Solutions:https://gws-host.com -
- Member Joomla Bug Squad & J-CMS Release Team

Starhorsepax
Joomla! Apprentice
Joomla! Apprentice
Posts: 29
Joined: Mon Nov 14, 2011 2:54 pm

Re: Menu's Booby trapped Urgent Please Help

Postby Starhorsepax » Tue Sep 05, 2017 5:48 pm

As far as I can tell, this is all linked to this. I did not use a much newer version then it had since I knew they changed stuff around 3.5. https://github.com/joomla/joomla-cms/issues/15719

It's precisely this behavior. type of menu item being set to component, given the wrong params and component id, being unpublished. I just can't figure out how to fix it. Some mention a script but I can't find it or how to use it.


Also telling me how to do it later may help for the future but redoing isn't an option now. It's live, it had to be live. The reason it was a 2 week rush job is they were given an ultimatum: fix web accessibility for the disabled or be sued. And we couldn't even get into the site to do it thanks to the mangled mess the hacker made! So it is live and a work in progress to correct the damage (while sadly doubting the client once set loose won't once again forget that 'update' button is important to their security.)

User avatar
leolam
Joomla! Master
Joomla! Master
Posts: 18401
Joined: Mon Aug 29, 2005 10:17 am
Location: Netherlands/ UK/ S'pore/Jakarta/ North America
Contact:

Re: Menu's Booby trapped Urgent Please Help

Postby leolam » Tue Sep 05, 2017 5:50 pm

No it is not. The only way to resolve this is written in the article of the link I posted

Leo 8)
Celebrating 12-Years of Professional Joomla Support Services
- Joomla Professional Support:https://gws-desk.com -
- Joomla Specialized Hosting Solutions:https://gws-host.com -
- Member Joomla Bug Squad & J-CMS Release Team

Starhorsepax
Joomla! Apprentice
Joomla! Apprentice
Posts: 29
Joined: Mon Nov 14, 2011 2:54 pm

Re: Menu's Booby trapped Urgent Please Help

Postby Starhorsepax » Tue Sep 05, 2017 6:50 pm

What is in that link is what I did! Just what do you think is different?

The problem here is MENUS.

Emphasis here this was months ago. The hacked files are gone - we have access to run the virus scans and prove it. The old version is dead, annihilated kaput. We cannot go back and start over.

We must work with what we have NOW. The site owners have already altered and added things.

So does anyone have any practical advice on how to fix the infernal menus that somehow got set wrong on updating instead of hanging up on a hack thats long fixed?

https://github.com/joomla/joomla-cms/bl ... -01-17.sql

This is what we are trying but it is not working. We are more designers than hard core coders.


Return to “Security in Joomla! 3.x”

Who is online

Users browsing this forum: No registered users and 2 guests