Repeated hack by eval(base64_decode - Joomla! Forum - community, help and support
i thought had resolved there must door somewhere on site.
please - 4 sites of mine have been hacked/repaired/hacked - i'm loosing now!
fpa here:
please - 4 sites of mine have been hacked/repaired/hacked - i'm loosing now!
fpa here:
problem description :: forum post assistant (v1.2.3) : 2nd november 2012 wrote:repeated hack eval(base64_decode
log/error message :: forum post assistant (v1.2.3) : 2nd november 2012 wrote:links site in google searches other site
actions taken resolve forum post assistant (v1.2.3) 2nd november 2012 wrote:i upgraded latest version of joomla , extensions - deleted old site , cleaned , uploaded - reinfected after 3 days
forum post assistant (v1.2.3) : 2nd november 2012 wrote:basic environment :: wrote:joomla! instance :: joomla! 2.5.7-stable (ember) 13-september-2012
joomla! platform :: joomla platform 11.4.0-stable (brian kernighan) 03-jan-2012
joomla! configured :: yes | writable (640) | owner: playsta (uid: 1/gid: 1) | group: playsta (gid: 1) | valid for: 2.5
configuration options :: offline: 0 | sef: 1 | sef suffix: 1 | sef rewrite: 1 | .htaccess/web.config: yes | gzip: 0 | cache: 0 | ftp layer: 0 | ssl: 0 | error reporting: default | site debug: 0 | language debug: 0 | default access: 1 | unicode slugs: 1 | database credentials present: yes
host configuration :: os: linux | os version: 2.6.18-308.8.1.el5 | technology: x86_64 | web server: apache | encoding: gzip,deflate,sdch | doc root: /home/playsta/public_html | system tmp writable: yes
php configuration :: version: 5.3.18 | php api: cgi-fcgi | session path writable: unknown | display errors: 1 | error reporting: 6143 | log errors to: | last known error: | register globals: 0 | magic quotes: 1 | safe mode: 0 | open base: | uploads: 1 | max. upload size: 2m | max. post size: 8m | max. input time: -1 | max. execution time: 30 | memory limit: 128m
mysql configuration :: version: 5.1.65-cll (client:5.1.65) | host: --protected-- (--protected--) | collation: latin1_swedish_ci (character set: latin1) | database size: 2.46 mib | #of tables: 78detailed environment :: wrote:php extensions :: core (5.3.18) | date (5.3.18) | ereg () | libxml () | openssl () | pcre () | sqlite3 (0.7-dev) | zlib (1.1) | bcmath () | bz2 () | calendar () | ctype () | curl () | dom (20031129) | hash (1.0) | filter (0.11.0) | ftp () | gd () | gettext () | spl (0.2) | iconv () | session () | json (1.2.1) | mbstring () | mcrypt () | mysql (1.0) | mysqli (0.1) | standard (5.3.18) | phar (2.0.1) | posix () | pspell () | reflection ($id: 593a0506b01337cfaf9f63ebc12cd60523fc2c41 $) | imap () | simplexml (0.1) | soap () | sockets () | exif (1.4 $id$) | tidy (2.0) | tokenizer (0.1) | xml () | xmlreader (0.1) | xmlrpc (0.51) | xmlwriter (0.1) | xsl (0.1) | zip (1.11.0) | cgi-fcgi () | zend engine (2.3.0) |
potential missing extensions :: suhosin |
switch user environment (experimental) :: php cgi: yes | server su: yes | php su: yes | custom su (litespeed/cloud/grid): yes
potential ownership issues: nofolder permissions :: wrote:core folders :: images/ (755) | components/ (755) | modules/ (755) | plugins/ (755) | language/ (755) | templates/ (755) | cache/ (755) | logs/ (755) | tmp/ (755) | administrator/components/ (755) | administrator/modules/ (755) | administrator/language/ (755) | administrator/templates/ (755) |
elevated permissions (first 10) :: __macosx/ (775) | __macosx/cli/ (775) | __macosx/libraries/ (775) | __macosx/libraries/joomla/ (775) | __macosx/libraries/joomla/error/ (775) | __macosx/libraries/joomla/github/ (775) | __macosx/libraries/joomla/installer/ (775) | __macosx/libraries/joomla/installer/adapters/ (775) | __macosx/libraries/joomla/user/ (775) | __macosx/tmp/ (775) |extensions discovered :: wrote:components :: site :: com_mailto (2.5.0) | com_wrapper (2.5.0) |
components :: admin :: com_search (2.5.0) | com_content (2.5.0) | com_templates (2.5.0) | com_installer (2.5.0) | stalker (1.3.1) | com_checkin (2.5.0) | com_menus (2.5.0) | com_config (2.5.0) | com_redirect (2.5.0) | com_login (2.5.0) | com_finder (2.5.0) | com_users (2.5.0) | com_weblinks (2.5.0) | userport (3.0 beta 3 fo) | french (2.1) | nl-nl (2.0) | german (2.0) | com_modules (2.5.0) | com_xmap (2.2.1) | com_messages (2.5.0) | com_cpanel (2.5.0) | com_newsfeeds (2.5.0) | unknown (-) | unknown (-) | breezingforms (1.8 stable (b) | com_joomlaupdate (2.5.0) | com_plugins (2.5.0) | com_languages (2.5.0) | com_banners (2.5.0) | com_cache (2.5.0) | com_categories (2.5.0) | com_media (2.5.0) | com_admin (2.5.0) |
modules :: site :: mod_articles_news (2.5.0) | mod_feed (2.5.0) | mod_weblinks (2.5.0) | mod_finder (2.5.0) | mod_whosonline (2.5.0) | stalker (1.3.1) | mod_search (2.5.0) | mod_login (2.5.0) | mod_articles_latest (2.5.0) | mod_stats (2.5.0) | mod_languages (2.5.0) | mod_users_latest (2.5.0) | mod_articles_categories (2.5.0) | mod_articles_popular (2.5.0) | mod_footer (2.5.0) | mod_custom (2.5.0) | mod_related_items (2.5.0) | mailchimp signup module (0.97.4b) | mod_syndicate (2.5.0) | mod_banners (2.5.0) | mod_articles_archive (2.5.0) | mod_wrapper (2.5.0) | mod_breadcrumbs (2.5.0) | mod_menu (2.5.0) | mod_articles_category (2.5.0) | mod_random_image (2.5.0) |
modules :: admin :: mod_feed (2.5.0) | mod_latest (2.5.0) | mod_version (2.5.0) | mod_title (2.5.0) | mod_submenu (2.5.0) | mod_logged (2.5.0) | mod_login (2.5.0) | mod_quickicon (2.5.0) | mod_multilangstatus (2.5.0) | mod_status (2.5.0) | mod_custom (2.5.0) | mod_toolbar (2.5.0) | mod_menu (2.5.0) | mod_popular (2.5.0) |
plugins :: site :: plg_user_joomla (2.5.0) | plg_user_profile (2.5.0) | plg_user_contactcreator (2.5.0) | plg_content_pagenavigation (2.5.0) | plg_content_geshi (2.5.0) | plg_content_loadmodule (2.5.0) | plg_content_pagebreak (2.5.0) | plg_content_joomla (2.5.0) | plg_content_vote (2.5.0) | plg_content_finder (2.5.0) | plg_content_emailcloak (2.5.0) | plg_system_highlight (2.5.0) | plg_system_remember (2.5.0) | plg_system_languagefilter (2.5.0) | plg_system_sef (2.5.0) | plg_system_p3p (2.5.0) | plg_system_languagecode (2.5.0) | plg_system_debug (2.5.0) | plg_system_redirect (2.5.0) | plg_system_log (2.5.0) | plg_system_logout (2.5.0) | system - union google analytic (1.0) | plg_system_cache (2.5.0) | plg_editors_tinymce (3.5.4.1) | plg_editors_codemirror (1.0) | xmap - content plugin (2.0.3) | xmap - kunena plugin (2.0.2) | xmap - sobipro plugin (2.0.1) | xmap - virtuemart plugin (2.0.0) | xmap - mosets tree plugin (2.0.2) | xmap - weblinks plugin (2.0) | plg_captcha_recaptcha (2.5.0) | plg_quickicon_extensionupdate (2.5.0) | plg_quickicon_joomlaupdate (2.5.0) | plg_finder_content (2.5.0) | plg_finder_weblinks (2.5.0) | plg_finder_newsfeeds (2.5.0) | plg_finder_categories (2.5.0) | plg_finder_contacts (2.5.0) | plg_authentication_joomla (2.5.0) | plg_authentication_ldap (2.5.0) | plg_authentication_gmail (2.5.0) | plg_search_content (2.5.0) | plg_search_weblinks (2.5.0) | plg_search_newsfeeds (2.5.0) | plg_search_categories (2.5.0) | plg_search_contacts (2.5.0) | plg_editors-xtd_pagebreak (2.5.0) | plg_editors-xtd_image (2.5.0) | plg_editors-xtd_article (2.5.0) | plg_editors-xtd_readmore (2.5.0) | plg_extension_joomla (2.5.0) |templates discovered :: wrote:templates :: site :: beez5 (2.5.0) | playstation_clouds_01 (1.0) | playstation_clouds_03 (1.0) | playstation_clouds_09 (1.0) | atomic (2.5.0) | playstation_clouds_07 (1.0) | playstation_clouds_06 (1.0) | playstation_clouds_05 (1.0) | playstation_clouds_08 (1.0) | playstation_clouds_02 (1.0) | playstation_clouds_04 (1.0) | playstation_clouds (1.0) | beez_20 (2.5.0) |
templates :: admin :: bluestork (2.5.0) | hathor (2.5.0) |
did change passwords (cpanel, admin, sql ...ect) effected sites?
also, if have wordpress phpbb or other programs running on same server creating hole too. inspect sites , reset passwords.
had similar problem 2 1/2 days in, still fingers crossed. have server tech stuff outlined on page http://docs.joomla.org/security_checkli ... rver_setup
make sure steps on page http://docs.joomla.org/security_checkli ... or_defaced
pay close attention /image folder , other restore methods.
if have tech doing you, send them links, double check make sure did all.
good luck
also, if have wordpress phpbb or other programs running on same server creating hole too. inspect sites , reset passwords.
had similar problem 2 1/2 days in, still fingers crossed. have server tech stuff outlined on page http://docs.joomla.org/security_checkli ... rver_setup
make sure steps on page http://docs.joomla.org/security_checkli ... or_defaced
pay close attention /image folder , other restore methods.
if have tech doing you, send them links, double check make sure did all.
good luck
Comments
Post a Comment