Joomla update plugin email url Topic is solved

Discussion regarding Joomla! 3.x security issues.

Moderators: Bernard T, mandville, fcoulter, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Post Reply
User avatar
alexwalker
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 166
Joined: Thu Sep 15, 2005 3:54 pm
Location: Lancaster, UK (near the Lake District)
Contact:

Joomla update plugin email url

Post by alexwalker » Wed Jul 15, 2020 9:32 pm

I have contacted siteground regarding the URL sent from a website which was incorrect. They say it has nothing to do with the hosting. Does this mean that this site has been hacked? I have admintools installed. domainkey has nothing to do with the site.
Screenshot_20200715-221031.png
Please see the attached screenshot.
Alex Walker
"to assume is to make an ass of u and me"

 
User avatar
AMurray
Joomla! Champion
Joomla! Champion
Posts: 5860
Joined: Sat Feb 13, 2010 7:35 am
Location: Australia

Re: Joomla update plugin email url

Post by AMurray » Wed Jul 15, 2020 9:53 pm

Your question doesn't contain a screenshot, so no reference to know what you're asking.

An incorrect URL is pretty common, e.g. 404 errors happen all the time but are you asking about something else? Is the incorrect URL pointing to something on your site?

I don't really know what you mean (perhaps its the way you phrased it):
....regarding the URL sent from a website which was incorrect
What URL...? What website is "a website"?

What does the Admintools logs (firewall...?) have to say about the strange URL's?

Maybe it's just some automated bot scanning your site. (not with altogether honest intentions).

I would recommend mysites.guru. Set up your site(s) with this service; the first site audit is free (otherwise a subscription service). Do a security audit of your site; it will identify and list anything it identifies as suspect, and give you tips on how to resolve the problems it finds (if any).

Otherwise, does your host have some sort of AV scanner or anti-malware type tools you can scan your site with?
Regards,
--------------------------------------------------------------
A Murray
Millennium Falcon - it's the ship that made the Kessel run in less than 12 parsecs! The fastest hunk of junk in the galaxy.

User avatar
alexwalker
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 166
Joined: Thu Sep 15, 2005 3:54 pm
Location: Lancaster, UK (near the Lake District)
Contact:

Re: Joomla update plugin email url

Post by alexwalker » Thu Jul 16, 2020 6:19 am

Screenshot_20200715-221031.png
You do not have the required permissions to view the files attached to this post.
Alex Walker
"to assume is to make an ass of u and me"

SharkyKZ
Joomla! Ace
Joomla! Ace
Posts: 1759
Joined: Fri Jul 05, 2013 10:35 am
Location: Parts Unknown

Re: Joomla update plugin email url

Post by SharkyKZ » Thu Jul 16, 2020 6:30 am

You have a Joomla! site at https://domainkey.acalltoaction.org.uk/.

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 11949
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: Joomla update plugin email url

Post by brian » Thu Jul 16, 2020 7:04 am

domainkey.* is a dns entry for DKIM

You do not have a web site installed at that subdomain. What you do have is a misconfiguration somewhere in your hosting where anythingatall.acalltocation.org.uk is resolving as your website.

For example brian.acalltoaction.org.uk also appears as your web site

The automated email you received with domainkey.* was just the way that plugin works. It uses the domain name that was visited when the plugin was triggered.

Most likely you have an error in your htaccess file that is causing this. Probably some code you placed there to redirct http:: to http://www. or something very similar.

In the first instance you can test this by disabling the htaccess by renaming it
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/

User avatar
alexwalker
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 166
Joined: Thu Sep 15, 2005 3:54 pm
Location: Lancaster, UK (near the Lake District)
Contact:

Re: Joomla update plugin email url

Post by alexwalker » Thu Jul 16, 2020 7:52 am

Thank you for this response I will check and create a new htacceess file. Not sure I can report back if it works until we have another joomla update lol.
Alex Walker
"to assume is to make an ass of u and me"

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 11949
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: Joomla update plugin email url

Post by brian » Thu Jul 16, 2020 12:42 pm

You will be able to tell if it works by going to
https://leedsutd.acalltoaction.org.uk

Currently you can see your web site but you shouldnt be able to
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/

User avatar
alexwalker
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 166
Joined: Thu Sep 15, 2005 3:54 pm
Location: Lancaster, UK (near the Lake District)
Contact:

Re: Joomla update plugin email url

Post by alexwalker » Thu Jul 16, 2020 1:58 pm

Brian, I virus get to the site after using your Leeds URL. This is after I created a new htacceess file. If this is the case what does it mean?
Alex Walker
"to assume is to make an ass of u and me"

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 11949
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: Joomla update plugin email url

Post by brian » Thu Jul 16, 2020 4:13 pm

If you have changed the htaccess then the problem is in the dns and its doing a wildcard - speak to siteground and explain that to them
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/

User avatar
leolam
Joomla! Master
Joomla! Master
Posts: 20138
Joined: Mon Aug 29, 2005 10:17 am
Location: Netherlands/ UK/ S'pore/Jakarta/ North America
Contact:

Re: Joomla update plugin email url

Post by leolam » Thu Jul 16, 2020 4:59 pm

Did you change the .htaccess with just the plain Joomla distributed htccess file as for Joomla 3.9.20? Do so and if still exists than Brian is fully right since your domain resolves also on https://gwsdesk.acalltoaction.org.uk or https://whatever.acalltoaction.org.uk or https://ihaveaproblem.acalltoaction.org.uk/

Connect with Siteground as Brin suggested

Leo 8)
Joomla's #1 Professional Services Provider:
#Joomla Professional Support: https://gws-desk.com -
#Joomla Specialized Hosting Solutions: https://gws-host.com -
#Joomla Webmaster Services: gws-webmaster.services

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 11949
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: Joomla update plugin email url

Post by brian » Thu Jul 16, 2020 8:01 pm

echo
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/

User avatar
alexwalker
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 166
Joined: Thu Sep 15, 2005 3:54 pm
Location: Lancaster, UK (near the Lake District)
Contact:

Re: Joomla update plugin email url

Post by alexwalker » Thu Jul 16, 2020 8:30 pm

I did indeed have wildcards installed on my domains so I am in the process of deleting them.
Alex Walker
"to assume is to make an ass of u and me"

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 11949
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: Joomla update plugin email url

Post by brian » Thu Jul 16, 2020 9:55 pm

Glad you can get it solved now
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/

User avatar
abernyte
Joomla! Virtuoso
Joomla! Virtuoso
Posts: 3856
Joined: Fri May 15, 2009 2:01 pm
Location: Écosse - Scozia - Escocia - Škotija -स्कॉटलैंड

Re: Joomla update plugin email url

Post by abernyte » Fri Jul 17, 2020 3:10 pm

And now you can update as you are still on 3.9.19 :}
What we obtain too cheap, we esteem too lightly…Thomas Paine

User avatar
alexwalker
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 166
Joined: Thu Sep 15, 2005 3:54 pm
Location: Lancaster, UK (near the Lake District)
Contact:

Re: Joomla update plugin email url

Post by alexwalker » Fri Jul 17, 2020 3:28 pm

Indeed thank you everyone for your help.
Alex Walker
"to assume is to make an ass of u and me"

 

Post Reply

Return to “Security in Joomla! 3.x”