Home page random string hack

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
User avatar
mojito
Joomla! Guru
Joomla! Guru
Posts: 755
Joined: Wed Sep 07, 2005 10:18 pm
Location: London
Contact:

Home page random string hack

Post by mojito » Thu Apr 01, 2021 4:20 pm

I have the following:
After the homepage final slash of google.com (substitute site) any random string renders the home page normally but with a title from a specific article. I have checked the raw db content for that and nothing suspicious.

When I unpublish this article the issue goes away.

How could I debug this to find perhaps where this is getting manipulated to maybe find the hacked code if it is hacked. Sounds like it is to me.

Always worth checking your sites for this one as it's so quick to do. Even for poorly fashioned redirects it's a good check.

So is the normal route behaviour getting stopped as the 404 should be happening.

Thanks.
I am a freelance SEO (https://cambs.eu) web designer and developer working with Wordpress and Joomla since Mambo.

User avatar
Per Yngve Berg
Joomla! Master
Joomla! Master
Posts: 30891
Joined: Mon Oct 27, 2008 9:27 pm
Location: Romerike, Norway

Re: Home page random string hack

Post by Per Yngve Berg » Thu Apr 01, 2021 4:43 pm

That's normal behaviour with legacy routing.

Switch to Modern Routing and set Remove ID from URL in the Options of Article Manager.

User avatar
mojito
Joomla! Guru
Joomla! Guru
Posts: 755
Joined: Wed Sep 07, 2005 10:18 pm
Location: London
Contact:

Re: Home page random string hack

Post by mojito » Thu Apr 01, 2021 5:10 pm

Hi Per
Thanks for contributing. I checked the options of the articles for this and also at the article level. I didn't find it but duckduckgo did along with your help.

https://docs.joomla.org/J3.x:New_Routing_System

Thanks

I was not using this as it is an older site and I remember the release now. But I think my other older sites don't suffer from this.
I am a freelance SEO (https://cambs.eu) web designer and developer working with Wordpress and Joomla since Mambo.


Locked

Return to “Security in Joomla! 3.x”