Spam emails

Discussion regarding Joomla! 2.5 security issues.

Moderators: Bernard T, mandville, fcoulter, PhilD, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Locked
Topknotch
Joomla! Apprentice
Joomla! Apprentice
Posts: 44
Joined: Tue Mar 29, 2011 6:28 pm

Spam emails

Post by Topknotch » Tue Apr 14, 2015 8:58 am

Hi,
I currently have a website that is running joomla 2.5.28 . It is sending out spam emails and it seems the script that it is coming from is - /public_html/components/com_users/controllers/plugin.php
Does anyone know what that script is for and how to stop it being compromised ?
Thanks

pradips
Joomla! Apprentice
Joomla! Apprentice
Posts: 45
Joined: Wed Apr 16, 2014 4:41 am

Re: Spam emails

Post by pradips » Tue Apr 14, 2015 9:15 am

Hi,

add captcha field in the form

Br,
Pradip

Topknotch
Joomla! Apprentice
Joomla! Apprentice
Posts: 44
Joined: Tue Mar 29, 2011 6:28 pm

Re: Spam emails

Post by Topknotch » Tue Apr 14, 2015 9:18 am

Sorry I do not know what you mean, are you saying that the plugin.php is for user registration ?
If it is, I have disabled user registration any way.

pradips
Joomla! Apprentice
Joomla! Apprentice
Posts: 45
Joined: Wed Apr 16, 2014 4:41 am

Re: Spam emails

Post by pradips » Tue Apr 14, 2015 9:22 am

captcha avoid spam mails - follow below link

http://www.captcha.net/

and add captcha field in registration form

Topknotch
Joomla! Apprentice
Joomla! Apprentice
Posts: 44
Joined: Tue Mar 29, 2011 6:28 pm

Re: Spam emails

Post by Topknotch » Tue Apr 14, 2015 9:30 am

No that's not what I mean is happening.
The site has been somehow compromised and someone is somehow sending out 1000's of spam emails through it. I have never known this on any joomla website before

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 14788
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: Spam emails

Post by mandville » Tue Apr 14, 2015 12:37 pm

Follow the security checklist. Get your host to disable email and trace the script name / location
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}


Locked

Return to “Security in Joomla! 2.5”