Hack 3.8.12 Joomla

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
Kenechard
Joomla! Fledgling
Joomla! Fledgling
Posts: 1
Joined: Mon Oct 15, 2018 4:38 pm

Hack 3.8.12 Joomla

Post by Kenechard » Mon Oct 15, 2018 4:59 pm

We are dealing with a hack on one of our sites. Here is what is happening. We currently know that a file was added to the site somehow. We were able to track down this and also it also seems to be creating a file. The source code file was added to /public_html/libraries and the file generated from that is added to public_html. We have the files but sadly they are a bit more complicated then what I'm used to. I'll post it in the attachments. The type of hack is/was as I understand it a keyword hack which spams google searches with links in other languages. We have determined that there are not files set to 777 or 755 access otherwise here is the source code and the file which was generated. I did some digging into other sites for what this could be and also attempt some decryptions to see if there was anything about this online with little return from it. If you are worried about this being an issues file I"ll post the start of the source code where so you can see something before attempting a download.

[ redacted ]

This goes on for a very long length.

Any thoughts would be helpful.

Thanks,
Last edited by toivo on Mon Oct 15, 2018 5:26 pm, edited 1 time in total.
Reason: mod note: hack code and attachment deleted

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44088
Joined: Sat Apr 05, 2008 9:58 pm

Re: Hack 3.8.12 Joomla

Post by Webdongle » Mon Oct 15, 2018 5:32 pm

http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

User avatar
leolam
Joomla! Master
Joomla! Master
Posts: 20652
Joined: Mon Aug 29, 2005 10:17 am
Location: Netherlands/ Germany/ S'pore/Bogor/ North America
Contact:

Re: Hack 3.8.12 Joomla

Post by leolam » Mon Oct 22, 2018 10:46 am

Visit myjoomla.com First scan is free and hire Phil to clean up the mess. He is a Pro.

Leo 8)
Joomla's #1 Professional Services Provider:
#Joomla Professional Support: https://gws-desk.com -
#Joomla Specialized Hosting Solutions: https://gws-host.com -

User avatar
JAVesey
Joomla! Hero
Joomla! Hero
Posts: 2636
Joined: Tue May 14, 2013 1:21 pm
Location: Cardiff, Wales, UK
Contact:

Re: Hack 3.8.12 Joomla

Post by JAVesey » Mon Oct 22, 2018 4:17 pm

leolam wrote:
Mon Oct 22, 2018 10:46 am
Visit myjoomla.com First scan is free and hire Phil to clean up the mess. He is a Pro.

Leo 8)
No reply from the OP for over a week. You're wasting your time with this, I fear.
John V
Cardiff, Wales, UK
Joomla 5.1.0 "live" site on PHP 8.2.15 and MariaDB 10.11.7
Joomla 5.1.0 on XAMMP for OSX with PHP 8.2.4 and MariaDB 10.4.28

User avatar
leolam
Joomla! Master
Joomla! Master
Posts: 20652
Joined: Mon Aug 29, 2005 10:17 am
Location: Netherlands/ Germany/ S'pore/Bogor/ North America
Contact:

Re: Hack 3.8.12 Joomla

Post by leolam » Sun Nov 25, 2018 3:34 pm

Sometimes people are so thankful for the help they receive

Leo 8)
Joomla's #1 Professional Services Provider:
#Joomla Professional Support: https://gws-desk.com -
#Joomla Specialized Hosting Solutions: https://gws-host.com -


Locked

Return to “Security in Joomla! 3.x”