Joomla 2.5.8 site hacked - images/post.php - Joomla! Forum - community, help and support
hi all,
we've been notified our host our joomla 2.5.8 has been hacked. more specifically, noted post.php file located in /images folder taking cpu resource.
looking @ apache logs, found following:
91.223.75.104 - - [09/dec/2012:20:55:52 +0200] "post /images/post.php http/1.1" 200 7 "-" "-"
91.223.75.104 - - [09/dec/2012:20:55:57 +0200] "post /images/post.php http/1.1" 200 92 "-" "-"
91.223.75.104 - - [09/dec/2012:20:55:24 +0200] "post /images/post.php http/1.1" 200 57 "-" "-"
at moment site blocked our host until clear situtation.
would appreciate assistance , advice.
rgrds,
chris
we've been notified our host our joomla 2.5.8 has been hacked. more specifically, noted post.php file located in /images folder taking cpu resource.
looking @ apache logs, found following:
91.223.75.104 - - [09/dec/2012:20:55:52 +0200] "post /images/post.php http/1.1" 200 7 "-" "-"
91.223.75.104 - - [09/dec/2012:20:55:57 +0200] "post /images/post.php http/1.1" 200 92 "-" "-"
91.223.75.104 - - [09/dec/2012:20:55:24 +0200] "post /images/post.php http/1.1" 200 57 "-" "-"
at moment site blocked our host until clear situtation.
would appreciate assistance , advice.
rgrds,
chris
welcome joomla forum!
sorry hear website has been hacked.
which 3rd party extensions use? updated recent versions?
could check them list? http://docs.joomla.org/vulnerable_extensions_list
sorry hear website has been hacked.
which 3rd party extensions use? updated recent versions?
could check them list? http://docs.joomla.org/vulnerable_extensions_list
Comments
Post a Comment