All my sites are hacked. - Joomla! Forum - community, help and support


my sites curently sending out emails everywhere...
i have file called i_php (in folders) has code in it
b66e5856
0qvcmjd`iunm0mpht
<?=10+20;?>


how fix in 20+ websites?




last php error(s) reported :: forum post assistant (v1.2.3) : 12th january 2013 wrote:[11-jan-2013 20:15:55 utc] php warning: attempt assign property of non-object in /home/londo2/public_html/libraries/joomla/html/editor.php on line 510
forum post assistant (v1.2.3) : 12th january 2013 wrote:
basic environment :: wrote:joomla! instance :: joomla! 2.5.8-stable (ember) 8-november-2012
joomla! platform :: joomla platform 11.4.0-stable (brian kernighan) 03-jan-2012
joomla! configured :: yes | writable (644) | owner: londo2 (uid: 1/gid: 1) | group: londo2 (gid: 1) | valid for: 2.5
configuration options :: offline: 0 | sef: 0 | sef suffix: 0 | sef rewrite: 0 | .htaccess/web.config: no | gzip: 0 | cache: 0 | ftp layer: 0 | ssl: 0 | error reporting: default | site debug: 0 | language debug: 0 | default access: 1 | unicode slugs: 0 | database credentials present: yes

host configuration :: os: linux | os version: 2.6.18-308.1.1.el5 | technology: x86_64 | web server: apache | encoding: gzip, deflate | doc root: /home/londo2/public_html | system tmp writable: yes

php configuration :: version: 5.3.10 | php api: cgi-fcgi | session path writable: yes | display errors: 1 | error reporting: 22519 | log errors to: error_log | last known error: 12th january 2013 07:15:55. | register globals: 0 | magic quotes: 1 | safe mode: 0 | open base: | uploads: 1 | max. upload size: 10m | max. post size: 16m | max. input time: 60 | max. execution time: 30 | memory limit: 64m

mysql configuration :: version: 5.1.66-cll (client:5.1.66) | host: --protected-- (--protected--) | collation: latin1_swedish_ci (character set: latin1) | database size: 31.33 mib | #of tables: 145
detailed environment :: wrote:php extensions :: core (5.3.10) | date (5.3.10) | ereg () | libxml () | openssl () | pcre () | sqlite3 (0.7-dev) | zlib (1.1) | bcmath () | bz2 () | calendar () | ctype () | curl () | dom (20031129) | fileinfo (1.0.5-dev) | filter (0.11.0) | ftp () | gd () | gettext () | hash (1.0) | iconv () | spl (0.2) | json (1.2.1) | mbstring () | mcrypt () | mysql (1.0) | mysqli (0.1) | session () | standard (5.3.10) | posix () | reflection ($revision: 321634 $) | phar (2.0.1) | simplexml (0.1) | soap () | sockets () | imap () | tidy (2.0) | tokenizer (0.1) | xml () | xmlreader (0.1) | xmlrpc (0.51) | xmlwriter (0.1) | zip (1.9.1) | cgi-fcgi () | timezonedb () | pdo (1.0.4dev) | pdo_sqlite (1.0.1) | sqlite (2.0-dev) | pdo_mysql (1.0.2) | ioncube loader () | zend engine (2.3.0) |
potential missing extensions :: suhosin |

switch user environment (experimental) :: php cgi: yes | server su: no | php su: yes | custom su (litespeed/cloud/grid): yes
potential ownership issues: no
folder permissions :: wrote:core folders :: images/ (755) | components/ (755) | modules/ (755) | plugins/ (755) | language/ (755) | templates/ (755) | cache/ (755) | logs/ (755) | tmp/ (755) | administrator/components/ (755) | administrator/modules/ (755) | administrator/language/ (755) | administrator/templates/ (755) |

elevated permissions (first 10) ::
extensions discovered :: wrote:components :: site :: com_wrapper (2.5.0) | com_mailto (2.5.0) |
components :: admin :: com_login (2.5.0) | com_modules (2.5.0) | com_installer (2.5.0) | com_categories (2.5.0) | com_search (2.5.0) | com_igallery (3.2.6) | gd image library joomla (1.0 beta buil) | com_content (2.5.0) | com_users (2.5.0) | com_newsfeeds (2.5.0) | admintools (2.4.3) | jmonitoring slave (2.0.5) | com_cpanel (2.5.0) | com_weblinks (2.5.0) | com_media (2.5.0) | com_foxcontact (2.0.9) | fox contact joomla 1.5 (-) | com_menus (2.5.0) | com_cache (2.5.0) | com_languages (2.5.0) | com_plugins (2.5.0) | com_messages (2.5.0) | com_banners (2.5.0) | com_config (2.5.0) | jetestimonial (1.1.1) | com_joomlaupdate (2.5.0) | com_finder (2.5.0) | mobile joomla! (1.0 rc5) | securitycheck (2.1.1) | k2 (2.5.4) | swmenupro (7.7) | swmenupro (7.7) | com_templates (2.5.0) | com_redirect (2.5.0) | com_admin (2.5.0) | com_checkin (2.5.0) |

modules :: site :: mod_users_latest (2.5.0) | header (1.0 rc5) | k2 login (2.5.4) | mod_syndicate (2.5.0) | mod_login (2.5.0) | mod_articles_archive (2.5.0) | jgmap - google map (0.15.5) | fox contact (2.0.9) | cassrina hover image menu (1.6.2) | ytc k2 slider (1.0) | magic point slideshow (1.0.0) | mod_languages (2.5.0) | mod_articles_latest (2.5.0) | mod_shlmobileswitch (1.0.0) | mod_breadcrumbs (2.5.0) | mod_stats (2.5.0) | k2 tools (2.5.4) | mod_articles_categories (2.5.0) | magic map detail (1.0.0) | k2 comments (2.5.4) | mod_wrapper (2.5.0) | zt slideshow (1.6.0) | magic rotator music (1.0.0) | mod_finder (2.5.0) | swfobject (2.1) | mod_articles_popular (2.5.0) | mod_footer (2.5.0) | k2 users (2.5.4) | je testimonial (2.0.0) | swmenupro (7.7) | ajax slideshow (1.1) | mod_random_image (2.5.0) | mod_feed (2.5.0) | [spam] joomla! (1.0.0) | mod_search (2.5.0) | mod_banners (2.5.0) | pro header [youtube] (1.1.1) | mod_related_items (2.5.0) | k2 user (2.5.4) | mod_weblinks (2.5.0) | mod_articles_category (2.5.0) | mod_custom (2.5.0) | goboslide (1.6.4) | displaynews (2.0.rc4) | mod_whosonline (2.5.0) | mobile menu (1.0 rc5) | mod_articles_news (2.5.0) | mod_menu (2.5.0) | k2 content (2.5.4) | markup chooser (1.0 rc5) |
modules :: admin :: mod_toolbar (2.5.0) | k2 stats (admin) (2.5.4) | mod_latest (2.5.0) | mod_multilangstatus (2.5.0) | mod_login (2.5.0) | mod_version (2.5.0) | admin tools joomla! upgrade no (rev1854e41) | mod_submenu (2.5.0) | mod_quickicon (2.5.0) | mod_status (2.5.0) | mod_popular (2.5.0) | k2 quick icons (admin) (2.5.4) | mod_logged (2.5.0) | mod_feed (2.5.0) | mod_title (2.5.0) | mod_custom (2.5.0) | mod_menu (2.5.0) | mobile joomla! cpanel icon (1.0 rc5) |

plugins :: site :: plg_editors-xtd_articlesanywhe (1.13.4) | plg_editors-xtd_pagebreak (2.5.0) | plg_editors-xtd_image (2.5.0) | plg_editors-xtd_article (2.5.0) | plg_editors-xtd_readmore (2.5.0) | plg_authentication_joomla (2.5.0) | plg_authentication_ldap (2.5.0) | plg_authentication_gmail (2.5.0) | plg_captcha_recaptcha (2.5.0) | plg_system_p3p (2.5.0) | security - jhackguard (1.4.1) | system - admin tools (2.4.3) | system - securitycheck (2.1.1) | plg_system_sef (2.5.0) | plg_system_log (2.5.0) | plg_system_articlesanywhere (1.13.4) | plg_system_jch_optimize (2.0.2) | plg_system_nnframework (11.12.5) | plg_system_highlight (2.5.0) | plg_system_redirect (2.5.0) | system - kc cufon (2.3.1) | plg_system_shlmobile (1.0.1) | system - k2 (2.5.4) | plg_system_logout (2.5.0) | mobile joomla! (1.0 rc5) | plg_system_debug (2.5.0) | plg_system_languagecode (2.5.0) | plg_system_languagefilter (2.5.0) | plg_system_cache (2.5.0) | plg_system_remember (2.5.0) | plg_quickicon_extensionupdate (2.5.0) | plg_quickicon_joomlaupdate (2.5.0) | plg_user_joomla (2.5.0) | user - k2 (2.5.4) | plg_user_profile (2.5.0) | plg_user_contactcreator (2.5.0) | plg_editors_codemirror (1.0) | plg_editors_tinymce (3.5.4.1) | plg_finder_categories (2.5.0) | plg_finder_newsfeeds (2.5.0) | plg_finder_content (2.5.0) | plg_finder_weblinks (2.5.0) | plg_finder_contacts (2.5.0) | plg_content_jetestimonial (1.0.0) | plg_content_joomla (2.5.0) | plg_content_geshi (2.5.0) | plg_content_pagebreak (2.5.0) | plg_content_finder (2.5.0) | plg_content_pagenavigation (2.5.0) | plg_content_loadmodule (2.5.0) | plg_content_emailcloak (2.5.0) | plg_content_vote (2.5.0) | mobile - terawurfl (1.0 rc5) | mobile - forever (1.0 rc5) | mobile - domains (1.0 rc5) | mobile - simple (1.0 rc5) | plg_search_categories (2.5.0) | plg_search_newsfeeds (2.5.0) | search - k2 (2.5.4) | plg_search_content (2.5.0) | plg_search_weblinks (2.5.0) | plg_search_contacts (2.5.0) | plg_extension_joomla (2.5.0) |
templates discovered :: wrote:templates :: site :: blackmobile (1.0.0) | mobile_imode (1.0 rc5) | mobile_pda (1.0 rc5) | wildbbate (1.0.0) | beez_20 (2.5.0) | atomic (2.5.0) | rt_refraction_j15 (1.5.1) | beez5 (2.5.0) | templatename (1.0.0) | gallerytemplate-black (1.0.0) | blogtemplate-black (1.0.0) | mobile_iphone (1.0 rc5) | mobile_wap (1.0 rc5) |
templates :: admin :: bluestork (2.5.0) | hathor (2.5.0) |

mrwild wrote:my sites curently sending out emails everywhere...
i have file called i_php (in folders) has code in it
b66e5856
0qvcmjd`iunm0mpht
<?=10+20;?>


how fix in 20+ websites?

do have ssh access websites?
if there commands remove same file folders.
it's (note: haven't tested myself check it, double & tripple double check @ other sources before using it!)

code: select all

# check code before running!!!
find . -name "i_php" |xargs rm


you might want contact & warn hosting provider.
if site on shared hosting , if has been hacked through other client on server, there's pretty chance other customers have been hacked to.
in case hosting company should remove files folders clients...
if don't so, remove own sites, other clients on same server keep sending spam result in server's ip address getting listed on blocklists...





Comments

Popular posts from this blog

How to change text Component easybook reloaded *newbee* - Joomla! Forum - community, help and support

After Effect warning: A problem occurred when processing OpenGL commands

Preconditions Failed. - Joomla! Forum - community, help and support