Site Security Problem - Joomla! Forum - community, help and support
problem description :: forum post assistant (v1.2.3) : 11th january 2013 wrote:users of site report site has been compromised.
forum post assistant (v1.2.3) : 11th january 2013 wrote:basic environment :: wrote:joomla! instance :: joomla! 2.5.8-stable (ember) 8-november-2012
joomla! platform :: joomla platform 11.4.0-stable (brian kernighan) 03-jan-2012
joomla! configured :: yes | writable (644) | owner: u64385312 (uid: 1/gid: 1) | group: ftpusers (gid: 1) | valid for: 2.5
configuration options :: offline: 0 | sef: 1 | sef suffix: 0 | sef rewrite: 0 | .htaccess/web.config: yes | gzip: 0 | cache: 0 | ftp layer: 0 | ssl: n/a | error reporting: default | site debug: 0 | language debug: 0 | default access: 1 | unicode slugs: 0 | database credentials present: yes
host configuration :: os: linux infong 2.4 #1 smp fri may 18 17:32:59 utc 2012 i686 gnu/linux | os version: linux infong 2.4 #1 smp fri may 18 17:32:59 utc 2012 i686 gnu/linux | technology: linux infong 2.4 #1 smp fri may 18 17:32:59 utc 2012 i686 gnu/linux | web server: apache | encoding: identity | doc root: /kunden/homepages/24/d375607198/htdocs | system tmp writable: yes
php configuration :: version: 5.4.10 | php api: cgi-fcgi | session path writable: yes | display errors: 1 | error reporting: 22519 | log errors to: | last known error: | register globals: | magic quotes: | safe mode: | open base: | uploads: 1 | max. upload size: 40m | max. post size: 8m | max. input time: -1 | max. execution time: 50000 | memory limit: 90m
mysql configuration :: version: 5.0.96-log (client:mysqlnd 5.0.10 - 20111026 - $id: b0b3b15c693b7f6aeb3aa66b646fee339f175e39 $) | host: --protected-- (--protected--) | collation: utf8_general_ci (character set: utf8) | database size: 3.07 mib | #of tables: 200detailed environment :: wrote:php extensions :: core (5.4.10) | date (5.4.10) | ereg () | libxml () | openssl () | pcre () | sqlite3 (0.7) | zlib (2.0) | bcmath () | bz2 () | calendar () | ctype () | curl () | dba () | dom (20031129) | hash (1.0) | fileinfo (1.0.5) | filter (0.11.0) | ftp () | gd () | gettext () | spl (0.2) | iconv () | session () | intl (1.1.0) | json (1.2.1) | mbstring () | mcrypt () | standard (5.4.10) | mysqlnd (mysqlnd 5.0.10 - 20111026 - $id: b0b3b15c693b7f6aeb3aa66b646fee339f175e39 $) | pdo (1.0.4dev) | pdo_mysql (1.0.2) | pdo_sqlite (1.0.1) | phar (2.0.1) | posix () | reflection ($id: 60f1e547a6dd00239162151e701566debdcee660 $) | imap () | shmop () | simplexml (0.1) | soap () | mysqli (0.1) | sqlite (2.0-dev) | exif (1.4 $id$) | tidy (2.0) | tokenizer (0.1) | wddx () | xml () | xmlreader (0.1) | xmlwriter (0.1) | xsl (0.1) | zip (1.11.0) | mysql (1.0) | cgi-fcgi () | mhash () | zend engine (2.4.0) |
potential missing extensions :: suhosin |
switch user environment (experimental) :: php cgi: yes | server su: yes | php su: yes | custom su (litespeed/cloud/grid): yes
potential ownership issues: nofolder permissions :: wrote:core folders :: images/ (755) | components/ (755) | modules/ (755) | plugins/ (755) | language/ (755) | templates/ (755) | cache/ (755) | logs/ (755) | tmp/ (755) | administrator/components/ (755) | administrator/modules/ (755) | administrator/language/ (755) | administrator/templates/ (755) |
elevated permissions (first 10) ::extensions discovered :: wrote:components :: site :: com_mailto (2.5.0) | com_wrapper (2.5.0) | wf_aggregator_vimeo_title (2.3.1) | [youtube] (2.3.1) | wf_aggregator_googlemaps_title (2.3.1) | wf_filesystem_joomla_title (2.3.1) | wf_links_joomlalinks_title (2.3.1) | wf_mediaplayer_jceplayer_title (2.3.1) | wf_popups_jcemediabox_title (2.3.1) | wf_popups_window_title (2.3.1) | wf_link_search_title (2.3.1) | wf_anchor_title (2.3.1) | wf_article_title (2.3.1) | wf_autosave_title (2.3.1) | wf_browser_title (2.3.1) | wf_cleanup_title (2.3.1) | wf_contextmenu_title (2.3.1) | wf_directionality_title (2.3.1) | wf_fullscreen_title (2.3.1) | wf_imgmanager_title (2.3.1) | wf_inlinepopups_title (2.3.1) | [do not buy our kitchens!] (2.3.1) | wf_layer_title (2.3.1) | wf_link_title (2.3.1) | wf_lists_title (2.3.1) | wf_media_title (2.3.1) | wf_nonbreaking_title (2.3.1) | wf_preview_title (2.3.1) | wf_print_title (2.3.1) | wf_searchreplace_title (2.3.1) | wf_source_title (2.3.1) | wf_spellchecker_title (2.3.1) | wf_style_title (2.3.1) | wf_table_title (2.3.1) | wf_textcase_title (2.3.1) | wf_visualblocks_title (2.3.1) | wf_visualchars_title (2.3.1) | wf_xhtmlxtras_title (2.3.1) | wf_clipboard_title (2.3.1) |
components :: admin :: com_admin (2.5.0) | com_banners (2.5.0) | com_cache (2.5.0) | com_categories (2.5.0) | com_checkin (2.5.0) | com_config (2.5.0) | com_content (2.5.0) | com_cpanel (2.5.0) | com_finder (2.5.0) | com_installer (2.5.0) | com_languages (2.5.0) | com_login (2.5.0) | com_media (2.5.0) | com_menus (2.5.0) | com_messages (2.5.0) | com_modules (2.5.0) | com_newsfeeds (2.5.0) | com_plugins (2.5.0) | com_redirect (2.5.0) | com_search (2.5.0) | com_templates (2.5.0) | com_users (2.5.0) | com_weblinks (2.5.0) | com_spupgrade (2.1.7) | unknown (-) | unknown (-) | breezingforms (1.8 stable (b) | jevents (2.2.7) | akeeba (3.6.10) | com_joomlaupdate (2.5.0) | unknown (-) | editor - jce (2.3.1) | editor - jce (2.3.1) | jce file browser (2.3.1) | plg_quickicon_jcefilebrowser (2.5.0) | jce (2.3.1) |
modules :: site :: mod_articles_archive (2.5.0) | mod_articles_categories (2.5.0) | mod_articles_category (2.5.0) | mod_articles_latest (2.5.0) | mod_articles_news (2.5.0) | mod_articles_popular (2.5.0) | mod_banners (2.5.0) | mod_breadcrumbs (2.5.0) | mod_custom (2.5.0) | mod_feed (2.5.0) | mod_finder (2.5.0) | mod_footer (2.5.0) | mod_languages (2.5.0) | mod_login (2.5.0) | mod_menu (2.5.0) | mod_random_image (2.5.0) | mod_related_items (2.5.0) | mod_search (2.5.0) | mod_stats (2.5.0) | mod_syndicate (2.5.0) | mod_users_latest (2.5.0) | mod_weblinks (2.5.0) | mod_whosonline (2.5.0) | mod_wrapper (2.5.0) | breezingforms (1.7.3) | art news ticker (1.0.1) | art featured image slider (1.2.| art image cycle (1.4.7) | art media box (1.0.3) | art universal lightbox (1.4.4) | latest jevents (2.2.4) | rs-flashion (1.5) | art showcase (1.5.2) |
modules :: admin :: mod_custom (2.5.0) | mod_feed (2.5.0) | mod_latest (2.5.0) | mod_logged (2.5.0) | mod_login (2.5.0) | mod_menu (2.5.0) | mod_multilangstatus (2.5.0) | mod_popular (2.5.0) | mod_quickicon (2.5.0) | mod_status (2.5.0) | mod_submenu (2.5.0) | mod_title (2.5.0) | mod_toolbar (2.5.0) | mod_version (2.5.0) |
plugins :: site :: plg_authentication_gmail (2.5.0) | plg_authentication_joomla (2.5.0) | plg_authentication_ldap (2.5.0) | plg_captcha_recaptcha (2.5.0) | plg_content_emailcloak (2.5.0) | plg_content_finder (2.5.0) | plg_content_geshi (2.5.0) | plg_content_joomla (2.5.0) | plg_content_loadmodule (2.5.0) | plg_content_pagebreak (2.5.0) | plg_content_pagenavigation (2.5.0) | plg_content_vote (2.5.0) | breezingforms (1.7.3) | simple image gallery (1.6.7) | plg_editors_codemirror (1.0) | plg_editors_tinymce (3.5.2) | editor - jce (2.3.1) | plg_editors-xtd_article (2.5.0) | plg_editors-xtd_image (2.5.0) | plg_editors-xtd_pagebreak (2.5.0) | plg_editors-xtd_readmore (2.5.0) | plg_extension_joomla (2.5.0) | plg_finder_categories (2.5.0) | plg_finder_contacts (2.5.0) | plg_finder_content (2.5.0) | plg_finder_newsfeeds (2.5.0) | plg_finder_weblinks (2.5.0) | plg_quickicon_extensionupdate (2.5.0) | plg_quickicon_joomlaupdate (2.5.0) | plg_quickicon_jcefilebrowser (2.5.0) | plg_search_categories (2.5.0) | plg_search_contacts (2.5.0) | plg_search_content (2.5.0) | plg_search_newsfeeds (2.5.0) | plg_search_weblinks (2.5.0) | plg_system_cache (2.5.0) | plg_system_debug (2.5.0) | plg_system_highlight (2.5.0) | plg_system_languagecode (2.5.0) | plg_system_languagefilter (2.5.0) | plg_system_log (2.5.0) | plg_system_logout (2.5.0) | plg_system_p3p (2.5.0) | plg_system_redirect (2.5.0) | plg_system_remember (2.5.0) | plg_system_sef (2.5.0) | system - nice paypal donations (1.04) | google maps (2.18) | system - nice paypal button (2.91) | shadowbox media viewer (4.0) | plg_user_contactcreator (2.5.0) | plg_user_joomla (2.5.0) | plg_user_profile (2.5.0) | plg_jmonitoring_akeebabackup_t (1.0) |templates discovered :: wrote:templates :: site :: atomic (2.5.0) | beez5 (2.5.0) | beez_20 (2.5.0) | creativa (1.0.2.5.4) |
templates :: admin :: bluestork (2.5.0) | hathor (2.5.0) |
additional screen shots attached.
ypr52
sounds pharma hack me, ,check out thread @mandville tells how prevent happening in future,
viewtopic.php?f=432&t=730870
also akeeba provides great walkthrough on how dehack site
https://www.akeebabackup.com/documentat ... -site.html
& myjoomla provides 1 free audit , set of tools fix issues such these.
http://myjoomla.com/ first audit free
regards
@bewebdev ^aw
sounds pharma hack me, ,check out thread @mandville tells how prevent happening in future,
viewtopic.php?f=432&t=730870
also akeeba provides great walkthrough on how dehack site
https://www.akeebabackup.com/documentat ... -site.html
& myjoomla provides 1 free audit , set of tools fix issues such these.
http://myjoomla.com/ first audit free
regards
@bewebdev ^aw
Comments
Post a Comment