website hacked, not sure how - Joomla! Forum - community, help and support


hi, past few weeks have been hacked.
used have 2.5.1 version, upgraded 2.5.8 , ran fpa tool close permissions, turned out images/stories/virtuemart/resized/{some folders} had 777. fixed it.

here current fpa report:

problem description :: forum post assistant (v1.2.3) : 8th january 2013 wrote:site hacked
actions taken resolve forum post assistant (v1.2.3) 8th january 2013 wrote:permissions hardened
forum post assistant (v1.2.3) : 8th january 2013 wrote:
basic environment :: wrote:joomla! instance :: joomla! 2.5.8-stable (ember) 8-november-2012
joomla! platform :: joomla platform 11.4.0-stable (brian kernighan) 03-jan-2012
joomla! configured :: yes | writable (644) | owner: myskincoil (uid: 1/gid: 1) | group: myskincoil (gid: 1) | valid for: 2.5
configuration options :: offline: 0 | sef: 0 | sef suffix: 0 | sef rewrite: 0 | .htaccess/web.config: no | gzip: 0 | cache: 0 | ftp layer: 0 | ssl: 0 | error reporting: default | site debug: 0 | language debug: 0 | default access: 1 | unicode slugs: 0 | database credentials present: yes

host configuration :: os: linux | os version: 2.6.18-92.1.22.el5pae | technology: i686 | web server: apache/1.3.37 | encoding: gzip,deflate,sdch | doc root: /hsphere/local/home/myskincoil/myskin.co.il | system tmp writable: yes

php configuration :: version: 5.2.17 | php api: cgi-fcgi | session path writable: no | display errors: 1 | error reporting: 6135 | log errors to: /hsphere/local/var/httpd/logs/php_error.log | last known error: | register globals: | magic quotes: 1 | safe mode: | open base: | uploads: 1 | max. upload size: 10m | max. post size: 8m | max. input time: 60 | max. execution time: 30 | memory limit: 48m

mysql configuration :: version: 5.1.63-community-log (client:5.1.63) | host: --protected-- (--protected--) | collation: utf8_general_ci (character set: utf8) | database size: 2.36 mib | #of tables:  175
detailed environment :: wrote:php extensions :: date (5.2.17) | libxml () | openssl () | pcre () | zlib (1.1) | bz2 () | ctype () | dba () | dom (20031129) | filter (0.11.0) | ftp () | gd () | gettext () | hash (1.0) | json (1.2.1) | mbstring () | mcrypt () | mhash () | mime_magic (0.1) | posix () | reflection (0.1) | session () | simplexml (0.1) | spl (0.2) | sockets () | standard (5.2.17) | tokenizer (0.1) | xml () | xmlreader (0.1) | xmlwriter (0.1) | xsl (0.1) | cgi-fcgi () | bcmath () | calendar () | curl () | dbase () | exif (1.4 $id: exif.c 293036 2010-01-03 09:23:27z sebastian $) | fileinfo (0.1) | gmp () | htscanner (0.6.0) | iconv () | imap () | ldap () | mysql (1.0) | mysqli (0.1) | odbc (1.0) | pdo (1.0.4dev) | pdo_mysql (1.0.2) | pdo_pgsql (1.0.2) | pdo_sqlite (1.0.1) | pgsql () | pspell () | soap () | sqlite (2.0-dev) | ioncube loader () | zend optimizer () | xcache (1.2.2) | zend engine (2.2.0) |
potential missing extensions :: zip | suhosin |

switch user environment (experimental) :: php cgi: yes | server su: yes | php su: yes | custom su (litespeed/cloud/grid): yes
potential ownership issues: no
folder permissions :: wrote:core folders :: images/ (755) | components/ (755) | modules/ (755) | plugins/ (755) | language/ (755) | templates/ (755) | cache/ (755) | logs/ (755) | tmp/ (755) | administrator/components/ (755) | administrator/modules/ (755) | administrator/language/ (755) | administrator/templates/ (755) |

elevated permissions (first 10) ::
extensions discovered :: wrote:components :: site :: com_mailto (2.5.0) | com_wrapper (2.5.0) | wf_filesystem_joomla_title (2.0.21) | wf_popups_jcemediabox_title (2.0.21) | wf_popups_window_title (2.0.21) | wf_aggregator_vimeo_title (2.0.21) | [youtube] (2.0.21) | wf_links_joomlalinks_title (2.0.21) | wf_mediaplayer_jceplayer_title (2.0.21) | wf_article_title (2.0.21) | wf_visualchars_title (2.0.21) | wf_imgmanager_title (2.0.21) | wf_nonbreaking_title (2.0.21) | wf_table_title (2.0.21) | wf_browser_title (2.0.21) | wf_media_title (2.0.21) | wf_link_title (2.0.21) | wf_spellchecker_title (2.0.21) | wf_contextmenu_title (2.0.21) | wf_inlinepopups_title (2.0.21) | wf_autosave_title (2.0.21) | wf_cleanup_title (2.0.21) | wf_xhtmlxtras_title (2.0.21) | wf_style_title (2.0.21) | wf_searchreplace_title (2.0.21) | wf_layer_title (2.0.21) | wf_paste_title (2.0.21) | wf_preview_title (2.0.21) | wf_textcase_title (2.0.21) | wf_directionality_title (2.0.21) | wf_print_title (2.0.21) | wf_source_title (2.0.21) | wf_fullscreen_title (2.0.21) | double email field (1.0.0) |
components :: admin :: com_modules (2.5.0) | com_search (2.5.0) | virtuemart_allinone (-) | com_cpanel (2.5.0) | admintools (2.4.4) | com_admin (2.5.0) | ecb currency converter (1.0) | virtuemart (-) | com_weblinks (2.5.0) | com_categories (2.5.0) | com_messages (2.5.0) | com_redj (1.6.2) | com_config (2.5.0) | com_media (2.5.0) | com_finder (2.5.0) | com_users (2.5.0) | com_redirect (2.5.0) | jce (2.0.21) | unknown (-) | editor - jce (2.0.21) | com_joomlaupdate (2.5.0) | com_content (2.5.0) | com_newsfeeds (2.5.0) | com_templates (2.5.0) | onepage (2.0.106.12121) | com_cache (2.5.0) | com_plugins (2.5.0) | joomgallery (2.0.0) | com_login (2.5.0) | com_banners (2.5.0) | extplorer (2.1.0rc5) | com_checkin (2.5.0) | awocoupon (2.0.4) | com_menus (2.5.0) | com_installer (2.5.0) | skinner (0.0.13) | com_languages (2.5.0) |

modules :: site :: mod_breadcrumbs (2.5.0) | mod_login (2.5.0) | easy folder listing (2.0) | mod_virtuemart_manufacturer (2.0.0rc3) | mod_related_items (2.5.0) | mod_virtuemart_currencies (2.0.0rc3) | mod_virtuemart_category (2.0.0rc3) | mod_virtuemart_product (2.0.0rc3) | mod_custom_js (1.0.0) | mod_articles_categories (2.5.0) | simple file upload v1.3 (for j (1.3) | easy file uploader (2.0) | simple image gallery module (2.7.0) | mod_random_image (2.5.0) | mod_footer (2.5.0) | mod_ninja_simple_icon_menu (1.9.0) | mod_articles_category (2.5.0) | inow slider (1.0) | simple file lister v1.0 (1.0) | mod_weblinks (2.5.0) | icemegamenu module (1.6.0) | mod_search (2.5.0) | ari ext menu (2.0.21) | mod_banners (2.5.0) | mod_stats (2.5.0) | mod_articles_news (2.5.0) | dj-menu (1.6.3.stable) | mod_articles_latest (2.5.0) | mod_finder (2.5.0) | mod_articles_archive (2.5.0) | mod_feed (2.5.0) | mod_syndicate (2.5.0) | mod_users_latest (2.5.0) | mod_languages (2.5.0) | mod_wrapper (2.5.0) | virtuemart frontpage categorie (1.1.0) | mod_articles_popular (2.5.0) | virtuemart shopping cart (2.0.0rc3) | mod_custom (2.5.0) | mod_whosonline (2.5.0) | mod_virtuemart_search (2.0.0rc3) | skinner images (1.5.0) | mod_menu (2.5.0) |
modules :: admin :: mod_login (2.5.0) | mod_status (2.5.0) | mod_version (2.5.0) | mod_title (2.5.0) | admin tools joomla! upgrade no (rev709797c) | mod_quickicon (2.5.0) | mod_multilangstatus (2.5.0) | mod_toolbar (2.5.0) | mod_popular (2.5.0) | mod_logged (2.5.0) | mod_submenu (2.5.0) | mod_latest (2.5.0) | mod_feed (2.5.0) | mod_custom (2.5.0) | mod_menu (2.5.0) |

plugins :: site :: plg_extension_joomla (2.5.0) | plg_user_contactcreator (2.5.0) | plg_user_joomla (2.5.0) | plg_user_profile (2.5.0) | xml-rpc - article widget (1.0.0) | vmpayment_paypal (2.0.1) | vmpayment_standard (2.0.1) | vm - payment, systempay (1.2) | vm payment - authorize.net aim (2.0.1) | vm - payment, payzen (1.2) | vm - payment, tranzila (1.2) | vmcustom - textinput (1.9.8) | vmcustom_stockable (1.9.8) | vmcustom - specification (2.0.0rc3) | vmshipment_weight_countries (2.0.1) | plg_finder_categories (2.5.0) | plg_finder_content (2.5.0) | plg_finder_weblinks (2.5.0) | plg_finder_contacts (2.5.0) | plg_finder_newsfeeds (2.5.0) | editor - jce (2.0.21) | plg_editors_codemirror (1.0) | plg_editors_tinymce (3.5.4.1) | plg_content_loadmodule (2.5.0) | plg_content_finder (2.5.0) | plg_content_emailcloak (2.5.0) | plg_content_geshi (2.5.0) | simple image gallery (by jooml (2.2) | plg_content_vote (2.5.0) | plg_content_joomla (2.5.0) | plg_content_pagebreak (2.5.0) | plg_content_pagenavigation (2.5.0) | plg_search_categories (2.5.0) | plg_search_content (2.5.0) | plg_search_weblinks (2.5.0) | plg_search_contacts (2.5.0) | plg_search_virtuemart (1.5) | plg_search_newsfeeds (2.5.0) | plg_authentication_gmail (2.5.0) | plg_authentication_joomla (2.5.0) | plg_authentication_ldap (2.5.0) | plg_captcha_recaptcha (2.5.0) | vmcoupon - awocoupon (2.0.0) | plg_editors-xtd_article (2.5.0) | plg_editors-xtd_readmore (2.5.0) | plg_editors-xtd_image (2.5.0) | plg_editors-xtd_pagebreak (2.5.0) | plg_quickicon_extensionupdate (2.5.0) | plg_quickicon_joomlaupdate (2.5.0) | plg_system_jch_optimize (2.0.2) | plg_system_remember (2.5.0) | plg_system_cache (2.5.0) | system - disable mootools (1.0) | plg_system_highlight (2.5.0) | plg_system_sef (2.5.0) | plg_system_debug (2.5.0) | system - admin tools (2.4.4) | system - jquery++ integrator b (v 1.5.4) | plg_system_p3p (2.5.0) | plg_system_logout (2.5.0) | plg_system_redirect (2.5.0) | plg_system_log (2.5.0) | plg_system_onepage (1.7.0) | plg_system_languagecode (2.5.0) | plg_sys_scriptsdown (1.10) | plg_system_languagefilter (2.5.0) | plg_system_redj (1.6.2) | user books (1.5) |
templates discovered :: wrote:templates :: site :: atomic (2.5.0) | atomic (2.5.0) | atomic (2.5.0) | beez_20 (2.5.0) | beez_20 (2.5.0) | beez5 (2.5.0) |
templates :: admin :: hathor (2.5.0) | bluestork (2.5.0) |


any ideas ?

viewtopic.php?f=621&t=582854

http://stackoverflow.com/questions/1103 ... -diagnosis

do know whether hacked once or has happened again since hardened site?

i have used free "jsecure" harden admin logon.

regards

geoff





Comments

Popular posts from this blog

How to change text Component easybook reloaded *newbee* - Joomla! Forum - community, help and support

After Effect warning: A problem occurred when processing OpenGL commands

Preconditions Failed. - Joomla! Forum - community, help and support