Joomla accounts hacked in MySQL - Joomla! Forum - community, help and support


hello,
the last week , every day joomla sites, joomla 1.5 sites, hacked @ database , accounts become

username: lcc123
and encrypted password: 44a0bcda611514625ba94e0b1c0bdaed:2iets9ydjr3iodsuyvw54pizyf9m1p5j

problem description :: forum post assistant (v1.2.3) : 9th january 2013 wrote:joomla accounts hacked in mysql
last php error(s) reported :: forum post assistant (v1.2.3) : 9th january 2013 wrote:[29-dec-2012 15:21:34] php warning: unlink(/home/wres/public_html/modules/mod_globeweather/mod_globeweather/metar_data/1356812492_5_calendar_overlayed.png) [<a href=\'function.unlink\'>function.unlink</a>]: no such file or directory in /home/wres/public_html/modules/mod_globeweather/mod_globeweather.php on line 358
actions taken resolve forum post assistant (v1.2.3) 9th january 2013 wrote:daily restoration, lock password administration folder through cpanel
forum post assistant (v1.2.3) : 9th january 2013 wrote:
basic environment :: wrote:joomla! instance :: joomla! 2.5.6-stable (ember) 19-june-2012
joomla! platform :: joomla platform 11.4.0-stable (brian kernighan) 03-jan-2012
joomla! configured :: yes | writable (644) | owner: wres (uid: 1/gid: 1) | group: wres (gid: 1) | valid for: 2.5
configuration options :: offline: 0 | sef: 1 | sef suffix: 0 | sef rewrite: 1 | .htaccess/web.config: yes | gzip: 0 | cache: 0 | ftp layer: 1 | ssl: 0 | error reporting: default | site debug: 0 | language debug: 0 | default access: 1 | unicode slugs: 0 | database credentials present: yes

host configuration :: os: linux | os version: 2.6.18-028stab095.1-ent | technology: i686 | web server: apache | encoding: gzip, deflate | doc root: /home/wres/public_html | system tmp writable: yes

php configuration :: version: 5.2.17 | php api: cgi | session path writable: yes | display errors: 1 | error reporting: 6135 | log errors to: error_log | last known error: 29th december 2012 15:21:34. | register globals: | magic quotes: 1 | safe mode: | open base: | uploads: 1 | max. upload size: 2m | max. post size: 8m | max. input time: 60 | max. execution time: 30 | memory limit: 96m

mysql configuration :: version: 5.1.66-cll (client:5.1.66) | host: --protected-- (--protected--) | collation: latin1_swedish_ci (character set: latin1) | database size: 9.10 mib | #of tables: 88
detailed environment :: wrote:php extensions :: date (5.2.17) | libxml () | openssl () | pcre () | zlib (1.1) | bcmath () | bz2 () | calendar () | ctype () | curl () | dbase () | dom (20031129) | hash (1.0) | filter (0.11.0) | ftp () | gd () | gettext () | session () | iconv () | standard (5.2.17) | json (1.2.1) | mbstring () | mcrypt () | mhash () | mime_magic (0.1) | mysql (1.0) | simplexml (0.1) | pgsql () | posix () | pspell () | reflection (0.1) | imap () | spl (0.2) | mysqli (0.1) | soap () | sockets () | exif (1.4 $id: exif.c 293036 2010-01-03 09:23:27z sebastian $) | tidy (2.0) | tokenizer (0.1) | wddx () | xml () | xmlreader (0.1) | xmlrpc (0.51) | xmlwriter (0.1) | xsl (0.1) | zip (1.8.11) | cgi () | timezonedb () | suhosin (0.9.32.1) | pdo (1.0.4dev) | pdo_sqlite (1.0.1) | sqlite (2.0-dev) | pdo_mysql (1.0.2) | zend optimizer () | zend engine (2.2.0) |
potential missing extensions ::

switch user environment (experimental) :: php cgi: yes | server su: yes | php su: yes | custom su (litespeed/cloud/grid): yes
potential ownership issues: no
folder permissions :: wrote:core folders :: images/ (755) | components/ (755) | modules/ (755) | plugins/ (755) | language/ (755) | templates/ (755) | cache/ (755) | logs/ (755) | tmp/ (755) | administrator/components/ (755) | administrator/modules/ (755) | administrator/language/ (755) | administrator/templates/ (755) |

elevated permissions (first 10) :: images/accordiongallery/galleries/ (777) | images/accordiongallery/gallery/ (777) | images/stories/ (777) | images/stories/remote/ (777) | images/stories/thumbnails/ (777) | modules/mod_globeweather/mod_globeweather/metar_data/ (757) |
extensions discovered :: wrote:components :: site :: com_mailto (2.5.0) | cedthumbnails (2.5.0) | com_wrapper (2.5.0) |
components :: admin :: com_cache (2.5.0) | com_login (2.5.0) | com_admin (2.5.0) | com_categories (2.5.0) | com_menus (2.5.0) | flippingbook (1.6.4) | com_users (2.5.0) | com_banners (2.5.0) | com_newsfeeds (2.5.0) | com_templates (2.5.0) | com_search (2.5.0) | com_plugins (2.5.0) | com_modules (2.5.0) | com_weblinks (2.5.0) | com_installer (2.5.0) | com_cpanel (2.5.0) | com_media (2.5.0) | com_joomlaupdate (2.5.0) | cedthumbnails (2.5.0) | com_languages (2.5.0) | com_messages (2.5.0) | com_content (2.5.0) | com_finder (2.5.0) | com_config (2.5.0) | com_redirect (2.5.0) | com_checkin (2.5.0) |

modules :: site :: mod_random_image (2.5.0) | mod_banners (2.5.0) | mod_articles_category (2.5.0) | ot_news (1.7.0) | facebook fanbox (1.1.0) | mod_wrapper (2.5.0) | mod_stats (2.5.0) | aidanews 2 (2.1.0) | slide show pro (2.4) | filtered news (2.5.0) | mod_search (2.5.0) | db8 site last modified (j2.5-v24) | mod_finder (2.5.0) | lof articlesslideshow module (2.2) | bt content slider (1.3) | mod_custom (2.5.0) | related articles thumbnai (2.5.2) | mod_syndicate (2.5.0) | mod_users_latest (2.5.0) | mod_articles_latest (2.5.0) | rs-flashmatic (1.5) | mod_whosonline (2.5.0) | mod_articles_categories (2.5.0) | sliding caption gallery (1.4.5) | mod_languages (2.5.0) | mod_feed (2.5.0) | freeslider sp1 (1.3.0) | global news (2.5.0) | popular articles thumbnai (2.5.0) | nurte facebook comments (1.1.0.0) | mod_articles_popular (2.5.0) | mod_weblinks (2.5.0) | greek date (4.0.3) | mod_breadcrumbs (2.5.0) | mod_footer (2.5.0) | mod_menu (2.5.0) | globeweather (1.3.4) | mod_login (2.5.0) | mod_articles_archive (2.5.0) | homepage slideshow (2.0) | latest articles thumbnail (2.5.0) | mod_articles_news (2.5.0) |
modules :: admin :: mod_submenu (2.5.0) | mod_quickicon (2.5.0) | mod_version (2.5.0) | mod_multilangstatus (2.5.0) | mod_toolbar (2.5.0) | mod_custom (2.5.0) | mod_title (2.5.0) | mod_popular (2.5.0) | mod_feed (2.5.0) | mod_menu (2.5.0) | mod_unread (1.6.0) | mod_login (2.5.0) | mod_latest (2.5.0) | mod_online (1.6.0) | mod_status (2.5.0) | mod_logged (2.5.0) |

plugins :: site :: plg_editors-xtd_image (2.5.0) | plg_editors-xtd_readmore (2.5.0) | plg_editors-xtd_article (2.5.0) | plg_editors-xtd_pagebreak (2.5.0) | plg_content_joomla (2.5.0) | plg_content_vote (2.5.0) | plg_content_loadmodule (2.5.0) | plg_content_geshi (2.5.0) | plg_content_finder (2.5.0) | content - facebook , sh (4.3) | plg_content_pagenavigation (2.5.0) | plg_content_emailcloak (2.5.0) | content - easiertube (6.1b) | plg_content_pagebreak (2.5.0) | plg_content_mavikthumbnails (0.9.8.4) | content - easy embed video (1.2) | content - googleweather (1.9.1) | plg_editors_codemirror (1.0) | plg_editors_tinymce (3.5.2) | plg_authentication_joomla (2.5.0) | plg_authentication_ldap (2.5.0) | plg_authentication_gmail (2.5.0) | plg_extension_joomla (2.5.0) | plg_captcha_recaptcha (2.5.0) | plg_finder_weblinks (2.5.0) | plg_finder_content (2.5.0) | plg_finder_contacts (2.5.0) | plg_finder_newsfeeds (2.5.0) | plg_finder_categories (2.5.0) | plg_system_cache (2.5.0) | plg_system_remember (2.5.0) | plg_system_logout (2.5.0) | plg_system_log (2.5.0) | plg_system_p3p (2.5.0) | plg_system_languagecode (2.5.0) | plg_system_sef (2.5.0) | plg_system_languagefilter (2.5.0) | plg_system_highlight (2.5.0) | plg_system_debug (2.5.0) | plg_system_redirect (2.5.0) | plg_quickicon_extensionupdate (2.5.0) | plg_quickicon_joomlaupdate (2.5.0) | plg_search_weblinks (2.5.0) | plg_search_content (2.5.0) | plg_search_contacts (2.5.0) | plg_search_newsfeeds (2.5.0) | plg_search_categories (2.5.0) | plg_user_joomla (2.5.0) | plg_user_profile (2.5.0) | plg_user_contactcreator (2.5.0) |
templates discovered :: wrote:templates :: site :: beez5 (2.5.0) | wres_neo (1.0) | wres7b (1.0) | wres_2012d (1.0) | beez_20 (2.5.0) | wres2012 (1.0) | wres_neo6 (1.0) |
templates :: admin :: bluestork (2.5.0) | hathor (2.5.0) |

elevated permissions (first 10) :: images/accordiongallery/galleries/ (777) | images/accordiongallery/gallery/ (777) | images/stories/ (777) | images/stories/remote/ (777) | images/stories/thumbnails/ (777) | modules/mod_globeweather/mod_globeweather/metar_data/ (757) |


this entry point, using accordian?
globeweather - out of date , possibly vulnerable along many others in list
run through checklist 7





Comments

Popular posts from this blog

How to change text Component easybook reloaded *newbee* - Joomla! Forum - community, help and support

After Effect warning: A problem occurred when processing OpenGL commands

Preconditions Failed. - Joomla! Forum - community, help and support