Advertisement
Why Joomla 4 & 5 easily get hacked?
Moderators: mandville, General Support Moderators
Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
-
- Joomla! Fledgling
- Posts: 1
- Joined: Tue Jan 16, 2024 2:33 pm
Why Joomla 4 & 5 easily get hacked?
Hello everyone, I hope I don't get bullied for asking or delivering this.
I have been using Joomla since 2006 from Joomla 1.5. Now I am using Joomla 5 for several projects.
I noticed that on several websites that use Joomla 4 and Joomla 5, it is very easy to hack. Hackers can easily change the index.php, .htaccess files, add new folders in the root, and files in the default Joomla folder.
I have tried to implement many things for security, including using a strong password for the administrator and not using the username admin or administrator. I even use a security extension for one of the websites, but hackers can still easily access and mess up the root folder.
And from several hack cases that I have experienced myself, fortunately, the SQL file was not touched. Is it true that hackers are not touched, maybe because they are not noticed or what.
What about the Joomla masters in this forum? Do you have any opinions? Thank you.
I have been using Joomla since 2006 from Joomla 1.5. Now I am using Joomla 5 for several projects.
I noticed that on several websites that use Joomla 4 and Joomla 5, it is very easy to hack. Hackers can easily change the index.php, .htaccess files, add new folders in the root, and files in the default Joomla folder.
I have tried to implement many things for security, including using a strong password for the administrator and not using the username admin or administrator. I even use a security extension for one of the websites, but hackers can still easily access and mess up the root folder.
And from several hack cases that I have experienced myself, fortunately, the SQL file was not touched. Is it true that hackers are not touched, maybe because they are not noticed or what.
What about the Joomla masters in this forum? Do you have any opinions? Thank you.
Advertisement
- AMurray
- Joomla! Master
- Posts: 10566
- Joined: Sat Feb 13, 2010 7:35 am
- Location: Australia
Re: Why Joomla 4 & 5 easily get hacked?
I've not experienced any hacking of a Joomla site in my 15 years using it.
It sounds like your server is compromised more so than Joomla itself. Are you on shared hosting, VPS or a dedicated server - is the server self managed (by you) or managed by the web hosting company?
Can you start by blocking suspect IP addresses and that sort of thing - that's not through Joomla but more likely in your web hosting account which would have utilities for that. If it continues, raise the matter with your web host.
You've not really gone into that much detail of what was changed other than "they changed the index.php and .htaccess file." To what end - what was the result of the hack? A defaced home page or something more malicious?
Additional to a strong password try multifactor authentication and a plugin such as AdminExile. https://extensions.joomla.org/extension/adminexile/ which requires a secret code at the end of the URL in order for it to be accessed. use this in conjunction with the MFA, strong password and even the htaccess/htpasswd on your administrator file for additional login (the credentials of which need to be completely separate from your Joomla details).
It sounds like your server is compromised more so than Joomla itself. Are you on shared hosting, VPS or a dedicated server - is the server self managed (by you) or managed by the web hosting company?
Can you start by blocking suspect IP addresses and that sort of thing - that's not through Joomla but more likely in your web hosting account which would have utilities for that. If it continues, raise the matter with your web host.
You've not really gone into that much detail of what was changed other than "they changed the index.php and .htaccess file." To what end - what was the result of the hack? A defaced home page or something more malicious?
Additional to a strong password try multifactor authentication and a plugin such as AdminExile. https://extensions.joomla.org/extension/adminexile/ which requires a secret code at the end of the URL in order for it to be accessed. use this in conjunction with the MFA, strong password and even the htaccess/htpasswd on your administrator file for additional login (the credentials of which need to be completely separate from your Joomla details).
Regards - A Murray
Global Support Moderator
Global Support Moderator
- pe7er
- Joomla! Master
- Posts: 25403
- Joined: Thu Aug 18, 2005 8:55 pm
- Location: Nijmegen, Netherlands
- Contact:
Re: Why Joomla 4 & 5 easily get hacked?
Do you use the most recent stable Joomla versions?rizalconsulting wrote: ↑Wed Feb 26, 2025 11:01 amI noticed that on several websites that use Joomla 4 and Joomla 5, it is very easy to hack. Hackers can easily change the index.php, .htaccess files, add new folders in the root, and files in the default Joomla folder.
The current Joomla versions (5.2.4 and 4.4.11) are safe.
I use Joomla since 2005 and two of my websites were hacked in the last 20 years:
- Around 2010 my site hacked from the inside. The shared hosting server I used back then, got hacked, and all index.php files got overwritten with political messages.
- In 2022, my Joomla 4 hacked because of a security issue with Joomla's debug mode, which was fixed very fast. I wrote an article about that in Joomla Community Magazine:
https://magazine.joomla.org/all-issues/ ... got-hacked
When your website got hacked, did you analyse how it happened?
Did you remove any backdoor scripts that hackers left on your site?
Kind Regards,
Peter Martin, Global Moderator + Joomla 5.2 Release Manager
Company website: https://db8.nl/en/ - Joomla specialist, Nijmegen, Netherlands
The best website: https://the-best-website.com
Peter Martin, Global Moderator + Joomla 5.2 Release Manager
Company website: https://db8.nl/en/ - Joomla specialist, Nijmegen, Netherlands
The best website: https://the-best-website.com
- JAVesey
- Joomla! Hero
- Posts: 2780
- Joined: Tue May 14, 2013 1:21 pm
- Location: Cardiff, Wales, UK
- Contact:
Re: Why Joomla 4 & 5 easily get hacked?
This ^
How did you clean-up your site after it was hacked? Unless you traced and removed the hack the chances are that it’s still there on your server.
Have you considered an audit by mysites.guru ? Phil is the best at this kind of thing and the first audit is free. I have no connection to the service, btw.
I’ve been using Joomla since 2013 (early in the J3 series) on shared hosting and have never been hacked. It’s not Joomla - it’s either an insecure, out of date extension or your hosting environment.
John V
Cardiff, Wales, UK
Joomla 5.2.5 "live" site on PHP 8.3.16 and MariaDB 10.11.10 (with b/c plugin enabled)
Joomla 5.2.5 on MAMP Pro 7.2.2 with PHP 8.3.14 and MySQL 8.0.40 (with b/c plugin enabled)
Cardiff, Wales, UK
Joomla 5.2.5 "live" site on PHP 8.3.16 and MariaDB 10.11.10 (with b/c plugin enabled)
Joomla 5.2.5 on MAMP Pro 7.2.2 with PHP 8.3.14 and MySQL 8.0.40 (with b/c plugin enabled)
- Webdongle
- Joomla! Master
- Posts: 44993
- Joined: Sat Apr 05, 2008 9:58 pm
Re: Why Joomla 4 & 5 easily get hacked?
I doubt it was Joomla that was hacked otherwise many would be hacked attacking the same vulnerability.
Things to check
3rd part extensions
Other sites on your server (especially if you have wp)
Once you have been hacked the only sure thing to get rid of the hacks is delete ALL the files on the server. You then need to rebuild the site. viewtopic.php?f=843&t=1005473
Things to check
3rd part extensions
Other sites on your server (especially if you have wp)
Once you have been hacked the only sure thing to get rid of the hacks is delete ALL the files on the server. You then need to rebuild the site. viewtopic.php?f=843&t=1005473
http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".
- ManuelVoileux
- Joomla! Intern
- Posts: 88
- Joined: Sun Nov 24, 2013 8:24 am
- Location: France
- Contact:
Re: Why Joomla 4 & 5 easily get hacked?
Hello , for htaccess , I use the common following code , and I had never a change of the htaccessrizalconsulting wrote: ↑Wed Feb 26, 2025 11:01 am I noticed that on several websites that use Joomla 4 and Joomla 5, it is very easy to hack. Hackers can easily change the index.php, .htaccess files, add new folders in the root, and files in the default Joomla folder.
Code: Select all
# secure .htaccess file
<Files .htaccess>
Order allow,deny
Deny from all
</Files>
-
- Joomla! Apprentice
- Posts: 15
- Joined: Fri Dec 30, 2011 3:03 am
Re: Why Joomla 4 & 5 easily get hacked?
I've used Joomla nearly as long as you have. In the J2x days, I had multiple sites (different hosts) get hacked. It's been good since. After my experience many years ago and after a Wordpress experience, I do a lot to keep things secure. Dedicated managed hosting. Firewall. Regular back ups. Monthly update of installed software. Jooolma core updates. It's a lot but it isn't. It's, perhaps, an hour each month to give this kind of attention to the website. Occasionally, there will be an issue that requires more attention or a more serious migration needed for the core CMS. The hosting company also has a schedule for backups too. And with all that, things can still happen.rizalconsulting wrote: ↑Wed Feb 26, 2025 11:01 am Hello everyone, I hope I don't get bullied for asking or delivering this.
I have been using Joomla since 2006 from Joomla 1.5. Now I am using Joomla 5 for several projects.
I noticed that on several websites that use Joomla 4 and Joomla 5, it is very easy to hack. Hackers can easily change the index.php, .htaccess files, add new folders in the root, and files in the default Joomla folder.
What about the Joomla masters in this forum? Do you have any opinions? Thank you.
-
- Joomla! Guru
- Posts: 620
- Joined: Fri Dec 02, 2005 10:46 am
- Location: The Netherlands
Clickbait!
I'm not saying it's not possible, but...
* J4 was released 3+ years ago
* Topic starter has been registered for little over a year and never mentioned this before
* It's TS's first post and has not returned here or elsewhere since
* TS says nothing really about the cause
* Examples given are not really J related and could just as well be a bad server configuration
* The "many things for security" mention the most basic
* No mention of what "security extension" was used
* TS could not have used J1.5 since 2006, 1.5 was released in 2008
* If it is/was so easy, as TS says, the internet would explode
* The internet has not exploded
So either it's specific to TS or it's clickbait!
* J4 was released 3+ years ago
* Topic starter has been registered for little over a year and never mentioned this before
* It's TS's first post and has not returned here or elsewhere since
* TS says nothing really about the cause
* Examples given are not really J related and could just as well be a bad server configuration
* The "many things for security" mention the most basic
* No mention of what "security extension" was used
* TS could not have used J1.5 since 2006, 1.5 was released in 2008
* If it is/was so easy, as TS says, the internet would explode
* The internet has not exploded
So either it's specific to TS or it's clickbait!
-
- Joomla! Champion
- Posts: 6606
- Joined: Tue Aug 23, 2005 1:56 pm
- Location: South coast, UK
- Contact:
Re: Why Joomla 4 & 5 easily get hacked?
+1 @ Mr.Wimpy
https://gadsolutions.biz Electrical services
https://electrical-testing-safety.co.uk Testing services
https://electrical-testing-safety.co.uk Testing services
Advertisement