Repeated hack by eval(base64_decode - Joomla! Forum - community, help and support


i thought had resolved there must door somewhere on site.

please - 4 sites of mine have been hacked/repaired/hacked - i'm loosing now!

fpa here:

problem description :: forum post assistant (v1.2.3) : 2nd november 2012 wrote:repeated hack eval(base64_decode
log/error message :: forum post assistant (v1.2.3) : 2nd november 2012 wrote:links site in google searches other site
actions taken resolve forum post assistant (v1.2.3) 2nd november 2012 wrote:i upgraded latest version of joomla , extensions - deleted old site , cleaned , uploaded - reinfected after 3 days
forum post assistant (v1.2.3) : 2nd november 2012 wrote:
basic environment :: wrote:joomla! instance :: joomla! 2.5.7-stable (ember) 13-september-2012
joomla! platform :: joomla platform 11.4.0-stable (brian kernighan) 03-jan-2012
joomla! configured :: yes | writable (640) | owner: playsta (uid: 1/gid: 1) | group: playsta (gid: 1) | valid for: 2.5
configuration options :: offline: 0 | sef: 1 | sef suffix: 1 | sef rewrite: 1 | .htaccess/web.config: yes | gzip: 0 | cache: 0 | ftp layer: 0 | ssl: 0 | error reporting: default | site debug: 0 | language debug: 0 | default access: 1 | unicode slugs: 1 | database credentials present: yes

host configuration :: os: linux | os version: 2.6.18-308.8.1.el5 | technology: x86_64 | web server: apache | encoding: gzip,deflate,sdch | doc root: /home/playsta/public_html | system tmp writable: yes

php configuration :: version: 5.3.18 | php api: cgi-fcgi | session path writable: unknown | display errors: 1 | error reporting: 6143 | log errors to: | last known error: | register globals: 0 | magic quotes: 1 | safe mode: 0 | open base: | uploads: 1 | max. upload size: 2m | max. post size: 8m | max. input time: -1 | max. execution time: 30 | memory limit: 128m

mysql configuration :: version: 5.1.65-cll (client:5.1.65) | host: --protected-- (--protected--) | collation: latin1_swedish_ci (character set: latin1) | database size: 2.46 mib | #of tables:  78
detailed environment :: wrote:php extensions :: core (5.3.18) | date (5.3.18) | ereg () | libxml () | openssl () | pcre () | sqlite3 (0.7-dev) | zlib (1.1) | bcmath () | bz2 () | calendar () | ctype () | curl () | dom (20031129) | hash (1.0) | filter (0.11.0) | ftp () | gd () | gettext () | spl (0.2) | iconv () | session () | json (1.2.1) | mbstring () | mcrypt () | mysql (1.0) | mysqli (0.1) | standard (5.3.18) | phar (2.0.1) | posix () | pspell () | reflection ($id: 593a0506b01337cfaf9f63ebc12cd60523fc2c41 $) | imap () | simplexml (0.1) | soap () | sockets () | exif (1.4 $id$) | tidy (2.0) | tokenizer (0.1) | xml () | xmlreader (0.1) | xmlrpc (0.51) | xmlwriter (0.1) | xsl (0.1) | zip (1.11.0) | cgi-fcgi () | zend engine (2.3.0) |
potential missing extensions :: suhosin |

switch user environment (experimental) :: php cgi: yes | server su: yes | php su: yes | custom su (litespeed/cloud/grid): yes
potential ownership issues: no
folder permissions :: wrote:core folders :: images/ (755) | components/ (755) | modules/ (755) | plugins/ (755) | language/ (755) | templates/ (755) | cache/ (755) | logs/ (755) | tmp/ (755) | administrator/components/ (755) | administrator/modules/ (755) | administrator/language/ (755) | administrator/templates/ (755) |

elevated permissions (first 10) :: __macosx/ (775) | __macosx/cli/ (775) | __macosx/libraries/ (775) | __macosx/libraries/joomla/ (775) | __macosx/libraries/joomla/error/ (775) | __macosx/libraries/joomla/github/ (775) | __macosx/libraries/joomla/installer/ (775) | __macosx/libraries/joomla/installer/adapters/ (775) | __macosx/libraries/joomla/user/ (775) | __macosx/tmp/ (775) |
extensions discovered :: wrote:components :: site :: com_mailto (2.5.0) | com_wrapper (2.5.0) |
components :: admin :: com_search (2.5.0) | com_content (2.5.0) | com_templates (2.5.0) | com_installer (2.5.0) | stalker (1.3.1) | com_checkin (2.5.0) | com_menus (2.5.0) | com_config (2.5.0) | com_redirect (2.5.0) | com_login (2.5.0) | com_finder (2.5.0) | com_users (2.5.0) | com_weblinks (2.5.0) | userport (3.0 beta 3 fo) | french (2.1) | nl-nl (2.0) | german (2.0) | com_modules (2.5.0) | com_xmap (2.2.1) | com_messages (2.5.0) | com_cpanel (2.5.0) | com_newsfeeds (2.5.0) | unknown (-) | unknown (-) | breezingforms (1.8 stable (b) | com_joomlaupdate (2.5.0) | com_plugins (2.5.0) | com_languages (2.5.0) | com_banners (2.5.0) | com_cache (2.5.0) | com_categories (2.5.0) | com_media (2.5.0) | com_admin (2.5.0) |

modules :: site :: mod_articles_news (2.5.0) | mod_feed (2.5.0) | mod_weblinks (2.5.0) | mod_finder (2.5.0) | mod_whosonline (2.5.0) | stalker (1.3.1) | mod_search (2.5.0) | mod_login (2.5.0) | mod_articles_latest (2.5.0) | mod_stats (2.5.0) | mod_languages (2.5.0) | mod_users_latest (2.5.0) | mod_articles_categories (2.5.0) | mod_articles_popular (2.5.0) | mod_footer (2.5.0) | mod_custom (2.5.0) | mod_related_items (2.5.0) | mailchimp signup module (0.97.4b) | mod_syndicate (2.5.0) | mod_banners (2.5.0) | mod_articles_archive (2.5.0) | mod_wrapper (2.5.0) | mod_breadcrumbs (2.5.0) | mod_menu (2.5.0) | mod_articles_category (2.5.0) | mod_random_image (2.5.0) |
modules :: admin :: mod_feed (2.5.0) | mod_latest (2.5.0) | mod_version (2.5.0) | mod_title (2.5.0) | mod_submenu (2.5.0) | mod_logged (2.5.0) | mod_login (2.5.0) | mod_quickicon (2.5.0) | mod_multilangstatus (2.5.0) | mod_status (2.5.0) | mod_custom (2.5.0) | mod_toolbar (2.5.0) | mod_menu (2.5.0) | mod_popular (2.5.0) |

plugins :: site :: plg_user_joomla (2.5.0) | plg_user_profile (2.5.0) | plg_user_contactcreator (2.5.0) | plg_content_pagenavigation (2.5.0) | plg_content_geshi (2.5.0) | plg_content_loadmodule (2.5.0) | plg_content_pagebreak (2.5.0) | plg_content_joomla (2.5.0) | plg_content_vote (2.5.0) | plg_content_finder (2.5.0) | plg_content_emailcloak (2.5.0) | plg_system_highlight (2.5.0) | plg_system_remember (2.5.0) | plg_system_languagefilter (2.5.0) | plg_system_sef (2.5.0) | plg_system_p3p (2.5.0) | plg_system_languagecode (2.5.0) | plg_system_debug (2.5.0) | plg_system_redirect (2.5.0) | plg_system_log (2.5.0) | plg_system_logout (2.5.0) | system - union google analytic (1.0) | plg_system_cache (2.5.0) | plg_editors_tinymce (3.5.4.1) | plg_editors_codemirror (1.0) | xmap - content plugin (2.0.3) | xmap - kunena plugin (2.0.2) | xmap - sobipro plugin (2.0.1) | xmap - virtuemart plugin (2.0.0) | xmap - mosets tree plugin (2.0.2) | xmap - weblinks plugin (2.0) | plg_captcha_recaptcha (2.5.0) | plg_quickicon_extensionupdate (2.5.0) | plg_quickicon_joomlaupdate (2.5.0) | plg_finder_content (2.5.0) | plg_finder_weblinks (2.5.0) | plg_finder_newsfeeds (2.5.0) | plg_finder_categories (2.5.0) | plg_finder_contacts (2.5.0) | plg_authentication_joomla (2.5.0) | plg_authentication_ldap (2.5.0) | plg_authentication_gmail (2.5.0) | plg_search_content (2.5.0) | plg_search_weblinks (2.5.0) | plg_search_newsfeeds (2.5.0) | plg_search_categories (2.5.0) | plg_search_contacts (2.5.0) | plg_editors-xtd_pagebreak (2.5.0) | plg_editors-xtd_image (2.5.0) | plg_editors-xtd_article (2.5.0) | plg_editors-xtd_readmore (2.5.0) | plg_extension_joomla (2.5.0) |
templates discovered :: wrote:templates :: site :: beez5 (2.5.0) | playstation_clouds_01 (1.0) | playstation_clouds_03 (1.0) | playstation_clouds_09 (1.0) | atomic (2.5.0) | playstation_clouds_07 (1.0) | playstation_clouds_06 (1.0) | playstation_clouds_05 (1.0) | playstation_clouds_08 (1.0) | playstation_clouds_02 (1.0) | playstation_clouds_04 (1.0) | playstation_clouds (1.0) | beez_20 (2.5.0) |
templates :: admin :: bluestork (2.5.0) | hathor (2.5.0) |

did change passwords (cpanel, admin, sql ...ect) effected sites?
also, if have wordpress phpbb or other programs running on same server creating hole too. inspect sites , reset passwords.

had similar problem 2 1/2 days in, still fingers crossed. have server tech stuff outlined on page http://docs.joomla.org/security_checkli ... rver_setup

make sure steps on page http://docs.joomla.org/security_checkli ... or_defaced

pay close attention /image folder , other restore methods.


if have tech doing you, send them links, double check make sure did all.

good luck





Comments

Popular posts from this blog

How to change text Component easybook reloaded *newbee* - Joomla! Forum - community, help and support

After Effect warning: A problem occurred when processing OpenGL commands

Preconditions Failed. - Joomla! Forum - community, help and support