Site hacked - v2.5.8 w/ PW protected Admin dir - Joomla! Forum - community, help and support


hi,

after being hacked recently, deleted , uploaded backup. running 2.5.8 , after hack password protected admin directory. had index.html file acting holding page.
my .htaccess file had allow access 403.shtml , block of previous ip range had hacked site last time.

i hacked again , hacker changed index.html file... logs show accessed following files:

/administrator/index.php 11/21/12 9:50 pm (multiple times in same minute)
//templates/beez/index.php 11/21/12 9:51 pm
//templates/rhuk_milkyway/index.php 11/21/12 9:51 pm
//templates/system/index.php 11/21/12 9:51 pm
//templates/beez/index.php 11/21/12 10:20 pm
//templates/rhuk_milkyway/index.php 11/21/12 10:20 pm
//templates/rhuk_milkyway/index.php 11/21/12 10:20 pm
//templates/system/index.php 11/21/12 10:20 pm
//?option=com_user&view=reset&layout=confirm 11/21/12 10:20 pm mozilla/5.0 (windows; u; windows nt 5.1; en-us; rv:1.8.1.15) gecko/2008111317 firefox/3.0.4
//?option=com_user&task=confirmreset 11/21/12 10:20 pm mozilla/5.0 (windows; u; windows nt 5.1; en-us; rv:1.8.1.15) gecko/2008111317 firefox/3.0.4

i must have missed site when deleting unused templates. several of sites on same vps hacked @ same time had repeat steps each one. must have missed one.

my admin dir password protected...how did gain access?
what final 2 urls doing , why show user agent entry?
how did edit/replace index.html if ftp disabled?

fpa below:
problem description :: forum post assistant (v1.2.3) : 22nd november 2012 wrote:hacked on 2.5.8 pw protected admin dir
forum post assistant (v1.2.3) : 22nd november 2012 wrote:
basic environment :: wrote:joomla! instance :: joomla! 2.5.8-stable (ember) 8-november-2012
joomla! platform :: joomla platform 11.4.0-stable (brian kernighan) 03-jan-2012
joomla! configured :: yes | writable (644) | owner: c6ers (uid: 1/gid: 1) | group: c6ers (gid: 1) | valid for: 2.5
configuration options :: offline: 0 | sef: 1 | sef suffix: 0 | sef rewrite: 0 | .htaccess/web.config: yes | gzip: 0 | cache: 0 | ftp layer: 0 | ssl: 0 | error reporting: default | site debug: 0 | language debug: 0 | default access: 1 | unicode slugs: 0 | database credentials present: yes

host configuration :: os: linux | os version: 2.6.18-274.7.1.el5 | technology: x86_64 | web server: apache | encoding: gzip,deflate,sdch | doc root: /home/c6ers/public_html | system tmp writable: yes

php configuration :: version: 5.2.17 | php api: cgi | session path writable: unknown | display errors: 1 | error reporting: 6135 | log errors to: error_log | last known error: | register globals: 0 | magic quotes: 1 | safe mode: 0 | open base: | uploads: 1 | max. upload size: 12m | max. post size: 12m | max. input time: 600 | max. execution time: 300 | memory limit: 128m

mysql configuration :: version: 5.1.65-cll (client:5.1.65) | host: --protected-- (--protected--) | collation: latin1_swedish_ci (character set: latin1) | database size: 3.23 mib | #of tables:  61
detailed environment :: wrote:php extensions :: date (5.2.17) | libxml () | openssl () | pcre () | zlib (1.1) | bcmath () | bz2 () | calendar () | ctype () | curl () | dbase () | dom (20031129) | hash (1.0) | filter (0.11.0) | ftp () | gd () | gettext () | session () | iconv () | standard (5.2.17) | json (1.2.1) | mbstring () | mcrypt () | mhash () | mime_magic (0.1) | mysql (1.0) | simplexml (0.1) | posix () | pspell () | reflection (0.1) | imap () | spl (0.2) | mysqli (0.1) | soap () | sockets () | exif (1.4 $id: exif.c 293036 2010-01-03 09:23:27z sebastian $) | tidy (2.0) | tokenizer (0.1) | wddx () | xml () | xmlreader (0.1) | xmlrpc (0.51) | xmlwriter (0.1) | xsl (0.1) | zip (1.8.11) | cgi () | timezonedb () | suhosin (0.9.32.1) | pdo (1.0.4dev) | pdo_sqlite (1.0.1) | sqlite (2.0-dev) | pdo_mysql (1.0.2) | ioncube loader () | zend optimizer () | zend engine (2.2.0) |
potential missing extensions ::

switch user environment (experimental) :: php cgi: yes | server su: no | php su: yes | custom su (litespeed/cloud/grid): yes
potential ownership issues: no
folder permissions :: wrote:core folders :: images/ (755) | components/ (755) | modules/ (755) | plugins/ (755) | language/ (755) | templates/ (755) | cache/ (755) | logs/ (755) | tmp/ (755) | administrator/components/ (755) | administrator/modules/ (755) | administrator/language/ (755) | administrator/templates/ (755) |

elevated permissions (first 10) ::
extensions discovered :: wrote:components :: site :: com_wrapper (2.5.0) | com_mailto (2.5.0) |
components :: admin :: com_categories (2.5.0) | com_checkin (2.5.0) | com_newsfeeds (2.5.0) | com_redirect (2.5.0) | com_menus (2.5.0) | com_cache (2.5.0) | com_users (2.5.0) | com_weblinks (2.5.0) | com_plugins (2.5.0) | com_installer (2.5.0) | com_media (2.5.0) | com_banners (2.5.0) | com_login (2.5.0) | com_templates (2.5.0) | com_admin (2.5.0) | com_search (2.5.0) | com_modules (2.5.0) | com_cpanel (2.5.0) | com_finder (2.5.0) | com_languages (2.5.0) | com_content (2.5.0) | com_config (2.5.0) | com_joomlaupdate (2.5.0) | com_messages (2.5.0) |

modules :: site :: s5 news ticker (2.0.0) | mod_whosonline (2.5.0) | mod_related_items (2.5.0) | mod_breadcrumbs (2.5.0) | mod_articles_news (2.5.0) | mod_articles_latest (2.5.0) | mod_articles_categories (2.5.0) | mod_wrapper (2.5.0) | mod_footer (2.5.0) | mod_login (2.5.0) | mod_banners (2.5.0) | mod_feed (2.5.0) | mod_menu (2.5.0) | mod_users_latest (2.5.0) | mod_weblinks (2.5.0) | mod_articles_popular (2.5.0) | mod_articles_category (2.5.0) | mod_finder (2.5.0) | mod_custom (2.5.0) | mod_random_image (2.5.0) | mod_syndicate (2.5.0) | mod_search (2.5.0) | mod_languages (2.5.0) | mod_articles_archive (2.5.0) | mod_stats (2.5.0) |
modules :: admin :: mod_version (2.5.0) | mod_submenu (2.5.0) | mod_latest (2.5.0) | mod_title (2.5.0) | mod_toolbar (2.5.0) | mod_login (2.5.0) | mod_feed (2.5.0) | mod_status (2.5.0) | mod_menu (2.5.0) | mod_multilangstatus (2.5.0) | mod_popular (2.5.0) | mod_quickicon (2.5.0) | mod_custom (2.5.0) | mod_logged (2.5.0) |

plugins :: site :: plg_system_log (2.5.0) | plg_system_highlight (2.5.0) | plg_system_debug (2.5.0) | plg_system_languagecode (2.5.0) | plg_system_cache (2.5.0) | plg_system_remember (2.5.0) | plg_system_languagefilter (2.5.0) | plg_system_p3p (2.5.0) | plg_system_logout (2.5.0) | plg_system_sef (2.5.0) | plg_system_redirect (2.5.0) | plg_editors-xtd_image (2.5.0) | plg_editors-xtd_pagebreak (2.5.0) | plg_editors-xtd_readmore (2.5.0) | plg_editors-xtd_article (2.5.0) | plg_user_joomla (2.5.0) | plg_user_profile (2.5.0) | plg_user_contactcreator (2.5.0) | plg_editors_codemirror (1.0) | plg_editors_tinymce (3.5.4.1) | plg_quickicon_extensionupdate (2.5.0) | plg_quickicon_joomlaupdate (2.5.0) | plg_finder_newsfeeds (2.5.0) | plg_finder_categories (2.5.0) | plg_finder_content (2.5.0) | plg_finder_weblinks (2.5.0) | plg_finder_contacts (2.5.0) | plg_content_emailcloak (2.5.0) | plg_content_pagenavigation (2.5.0) | plg_content_vote (2.5.0) | plg_content_pagebreak (2.5.0) | plg_content_finder (2.5.0) | plg_content_joomla (2.5.0) | plg_content_geshi (2.5.0) | plg_content_loadmodule (2.5.0) | plg_search_newsfeeds (2.5.0) | plg_search_categories (2.5.0) | plg_search_content (2.5.0) | plg_search_weblinks (2.5.0) | plg_search_contacts (2.5.0) | plg_authentication_gmail (2.5.0) | plg_authentication_ldap (2.5.0) | plg_authentication_joomla (2.5.0) | plg_captcha_recaptcha (2.5.0) | plg_extension_joomla (2.5.0) |
templates discovered :: wrote:templates :: site :: beez_20 (2.5.0) | atomic (2.5.0) | beez5 (2.5.0) | c6-ers (1.1) |
templates :: admin :: hathor (2.5.0) | bluestork (2.5.0) |

faldinio wrote:...
after being hacked recently, deleted , uploaded backup. running 2.5.8 , after hack password protected admin directory. had index.html file acting holding page....
your backup may have contained compromised files.(often site hacked months before hack activated).
your computer may have trojan.

please see viewtopic.php?f=621&t=582854 other actions(that have not mentioned) take.


addendum
what url ?





Comments

Popular posts from this blog

How to change text Component easybook reloaded *newbee* - Joomla! Forum - community, help and support

After Effect warning: A problem occurred when processing OpenGL commands

Preconditions Failed. - Joomla! Forum - community, help and support