Hacked. Super User account is compromised Topic is solved

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
charleyhankins
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 233
Joined: Fri Oct 12, 2007 7:07 pm

Hacked. Super User account is compromised

Post by charleyhankins » Thu Sep 09, 2021 9:22 pm

We need some professional assistance.

Our site appears to have been hacked.

Someone keeps creating an article for [* spam *].

My Super User account won't keep Super User rights.

When I attempt to change my password, it tells me that the passwords do not match.

Does anyone have any experience with these sorts of things?

Thanks,
Charley
Last edited by imanickam on Sun Sep 12, 2021 2:22 pm, edited 1 time in total.
Reason: Moved topic » from Professional Development Services to Security in Joomla! 3.x

User avatar
JAVesey
Joomla! Hero
Joomla! Hero
Posts: 2637
Joined: Tue May 14, 2013 1:21 pm
Location: Cardiff, Wales, UK
Contact:

Re: Hacked. Super User account is compromised

Post by JAVesey » Sun Sep 12, 2021 4:46 pm

charleyhankins wrote:
Thu Sep 09, 2021 9:22 pm
Does anyone have any experience with these sorts of things?
Try here:
https://mysites.guru/

First scan is free. Phil is the go-to guy for Joomla security. He will advise you should you wish to use his service following the scan.
John V
Cardiff, Wales, UK
Joomla 5.1.0 "live" site on PHP 8.2.15 and MariaDB 10.11.7
Joomla 5.1.0 on XAMMP for OSX with PHP 8.2.4 and MariaDB 10.4.28

User avatar
Per Yngve Berg
Joomla! Master
Joomla! Master
Posts: 30940
Joined: Mon Oct 27, 2008 9:27 pm
Location: Romerike, Norway

Re: Hacked. Super User account is compromised

Post by Per Yngve Berg » Sun Sep 12, 2021 6:57 pm

Step One: Use the Forum Post Assistant. See red frame above.

sozzled
I've been banned!
Posts: 13639
Joined: Sun Jul 05, 2009 3:30 am
Location: Canberra, Australia

Re: Hacked. Super User account is compromised

Post by sozzled » Sun Sep 12, 2021 8:41 pm

When the topic was located in the Professional Development Services forum—which means that discussions are locked and the only means of replying to the person who opens such topics there is privately/offline from the forum—I sent the OP a private message. That is how the Professional Development Services forum is supposed to operate. It was not "soliciting work". It was simply a gesture on my part to offer the OP the opportunity to discuss the matter privately.

I sent the private message to the OP within 30 minutes of the topic appearing on the Professional Development Services forum ; in other words, nearly three days ago. My message remained in the outbox—i.e. uncollected—but I have deleted it now because the moderators have moved the post to the public area for discussion.

I wish to point out that I have never used the forum to "solicit work"; I have never sought payment, nor have I received payment, for any help I have given people offline from this forum. Even though the topic was originally posted in the Professional Development Services forum, I would not have sought any payment of any kind for any help I may have been able to give. When requests are made in the Professional Development Services forum they are posted there inviting people to offer their help (including "professional services) to deal with a unique issue (or range of issues) that people may have. I want to make that point abundantly clear. I am happy to help the OP, should the OP be interested, either publicly on the forum or, if the OP wants, privately. This is not "soliciting": this is simply saying that I would help if we knew more about how the problem is caused (as @Per suggests, to use the Forum Post Assistant tool) but, otherwise, it's difficult to provide advice when (a) forum users ask about something on the forum and do not follow up their questions by checking for replies, and (b) we don't have information about what may have caused the problem in the first place.

I agree with the forum moderators that "soliciting" is against the forum rules. I want to state, for the public record, that my reply here at this time is not to contradict the forum policy about "soliciting" nor is it an invitation for people to question my motives. Thank you. :)

User avatar
AMurray
Joomla! Exemplar
Joomla! Exemplar
Posts: 9745
Joined: Sat Feb 13, 2010 7:35 am
Location: Australia

Re: Hacked. Super User account is compromised

Post by AMurray » Sun Sep 12, 2021 9:48 pm

Sorry, if I might have misread the question and I requested the post be moved to "security". Apologies if it has been moved to the wrong place. However the mods agreed and have moved it. If it's wrong, it can be moved back.
Regards - A Murray
General Support Moderator

sozzled
I've been banned!
Posts: 13639
Joined: Sun Jul 05, 2009 3:30 am
Location: Canberra, Australia

Re: Hacked. Super User account is compromised

Post by sozzled » Sun Sep 12, 2021 9:54 pm

Thanks, Andy. You were doing what you thought was right. No problem there. :)

If the OP wants to move the topic back—so that it's handled privately—then the OP can report the matter to the forum moderators.

User avatar
mjparadac
Joomla! Hero
Joomla! Hero
Posts: 2488
Joined: Mon Oct 29, 2012 3:58 pm

Re: Hacked. Super User account is compromised

Post by mjparadac » Mon Sep 13, 2021 5:18 pm

viewtopic.php?f=813&t=988545
I just just read this post, it might help.

Regards,
Joomla Community Ambassador for A2 Hosting | A2 Hosting - Our speed, your success | https://www.a2hosting.com/joomla-hosting


Locked

Return to “Security in Joomla! 3.x”