FPA - my site has been hacked again - Joomla! Forum - community, help and support
hi guys,
need here...
i not sure went wrong, have deleted files , used backup domain provider. reckon backup copy contained files didn't want.
however, see issues report above? in advance!
need here...
forum post assistant (v1.2.3) : 20th november 2012 wrote:basic environment :: wrote:joomla! instance :: joomla! 2.5.8-stable (ember) 8-november-2012
joomla! platform :: joomla platform 11.4.0-stable (brian kernighan) 03-jan-2012
joomla! configured :: yes | writable (644) | owner: 380858 (uid: /gid: ) | group: 382276 (gid: ) | valid for: 2.5
configuration options :: offline: 0 | sef: 1 | sef suffix: 0 | sef rewrite: 0 | .htaccess/web.config: no | gzip: 0 | cache: 0 | ftp layer: 0 | ssl: 0 | error reporting: default | site debug: 0 | language debug: 0 | default access: 1 | unicode slugs: 0 | database credentials present: yes
host configuration :: os: linux | os version: 3.4.10-vs2.3.3.6-20120829-1202-b7d2c37 | technology: x86_64 | web server: apache | encoding: gzip, deflate | doc root: /customers/1skoger.org/1skoger.org/httpd.www | system tmp writable: yes
php configuration :: version: 5.3.17 | php api: cgi-fcgi | session path writable: unknown | display errors: 0 | error reporting: 22519 | log errors to: | last known error: | register globals: 1 | magic quotes: | safe mode: | open base: /customers/1skoger.org/1skoger.org/httpd.www:/customers/1skoger.org/1skoger.org/httpd.private:/customers/1skoger.org/1skoger.org/tmp:/var/www/diagnostics:/usr/share/php | uploads: 1 | max. upload size: 96m | max. post size: 96m | max. input time: 60 | max. execution time: 50 | memory limit: 80m
mysql configuration :: version: 5.0.51a-24+lenny5 (client:mysqlnd 5.0.8-dev - 20102224 - $id: 65fe78e70ce53d27a6cd578597722950e490b0d0 $) | host: --protected-- (--protected--) | collation: utf8_general_ci (character set: utf8) | database size: 10.33 mib | #of tables: 131detailed environment :: wrote:php extensions :: core (5.3.17) | date (5.3.17) | ereg () | libxml () | openssl () | pcre () | sqlite3 (0.7-dev) | zlib (1.1) | bcmath () | calendar () | ctype () | curl () | dba () | dom (20031129) | hash (1.0) | fileinfo (1.0.5-dev) | filter (0.11.0) | gd () | gettext () | spl (0.2) | iconv () | session () | json (1.2.1) | mbstring () | mcrypt () | standard (5.3.17) | mysqlnd (mysqlnd 5.0.8-dev - 20102224 - $id: 65fe78e70ce53d27a6cd578597722950e490b0d0 $) | pdo (1.0.4dev) | pdo_mysql (1.0.2) | pdo_sqlite (1.0.1) | reflection ($id: 593a0506b01337cfaf9f63ebc12cd60523fc2c41 $) | imap () | simplexml (0.1) | soap () | mysqli (0.1) | exif (1.4 $id$) | sysvshm () | tokenizer (0.1) | wddx () | xml () | xmlreader (0.1) | xmlrpc (0.51) | xmlwriter (0.1) | xsl (0.1) | zip (1.11.0) | mysql (1.0) | cgi-fcgi () | xcache (2.0.1) | zend engine (2.3.0) |
potential missing extensions :: suhosin |
switch user environment (experimental) :: php cgi: yes | server su: no | php su: yes | custom su (litespeed/cloud/grid): no
potential ownership issues: maybefolder permissions :: wrote:core folders :: images/ (744) | components/ (744) | modules/ (744) | plugins/ (744) | language/ (744) | templates/ (744) | cache/ (744) | logs/ (744) | tmp/ (744) | administrator/components/ (744) | administrator/modules/ (744) | administrator/language/ (744) | administrator/templates/ (744) |
elevated permissions (first 10) ::extensions discovered :: wrote:components :: site :: com_mailto (2.5.0) | com_wrapper (2.5.0) |
components :: admin :: com_admin (2.5.0) | com_cache (2.5.0) | com_banners (2.5.0) | com_categories (2.5.0) | com_checkin (2.5.0) | com_config (2.5.0) | com_content (2.5.0) | com_cpanel (2.5.0) | com_finder (2.5.0) | com_installer (2.5.0) | jevents (2.2.5) | com_joomlaupdate (2.5.0) | com_languages (2.5.0) | com_login (2.5.0) | com_media (2.5.0) | com_menus (2.5.0) | com_messages (2.5.0) | com_modules (2.5.0) | com_newsfeeds (2.5.0) | com_plugins (2.5.0) | com_redirect (2.5.0) | com_search (2.5.0) | com_templates (2.5.0) | com_users (2.5.0) | com_weblinks (2.5.0) |
modules :: site :: mod_articles_archive (2.5.0) | mod_articles_categories (2.5.0) | mod_articles_latest (2.5.0) | mod_articles_category (2.5.0) | mod_articles_news (2.5.0) | mod_articles_popular (2.5.0) | mod_banners (2.5.0) | mod_breadcrumbs (2.5.0) | mod_custom (2.5.0) | custom facebook slider (1.0) | custom twitter slider (1.0) | mod_feed (2.5.0) | mod_finder (2.5.0) | mod_footer (2.5.0) | jevents calendar (2.2.0) | jevents filter (2.2.0) | latest jevents (2.2.4) | jevents legend (2.2.3) | mod_languages (2.5.0) | mod_login (2.5.0) | mod_menu (2.5.0) | mod_random_image (2.5.0) | mod_related_items (2.5.0) | mod_search (2.5.0) | mod_stats (2.5.0) | mod_syndicate (2.5.0) | mod_users_latest (2.5.0) | mod_weblinks (2.5.0) | mod_whosonline (2.5.0) | mod_wrapper (2.5.0) |
modules :: admin :: mod_custom (2.5.0) | mod_latest (2.5.0) | mod_feed (2.5.0) | mod_logged (2.5.0) | mod_login (2.5.0) | mod_menu (2.5.0) | mod_multilangstatus (2.5.0) | mod_popular (2.5.0) | mod_quickicon (2.5.0) | mod_status (2.5.0) | mod_submenu (2.5.0) | mod_title (2.5.0) | mod_toolbar (2.5.0) | mod_version (2.5.0) |
plugins :: site :: plg_authentication_gmail (2.5.0) | plg_authentication_ldap (2.5.0) | plg_authentication_joomla (2.5.0) | plg_captcha_recaptcha (2.5.0) | plg_editors_codemirror (1.0) | plg_editors_tinymce (3.5.4.1) | plg_content_emailcloak (2.5.0) | plg_content_geshi (2.5.0) | plg_content_finder (2.5.0) | plg_content_joomla (2.5.0) | plg_content_loadmodule (2.5.0) | plg_content_pagebreak (2.5.0) | plg_content_pagenavigation (2.5.0) | plg_content_vote (2.5.0) | plg_editors-xtd_article (2.5.0) | plg_editors-xtd_pagebreak (2.5.0) | plg_editors-xtd_image (2.5.0) | plg_editors-xtd_readmore (2.5.0) | plg_extension_joomla (2.5.0) | plg_finder_categories (2.5.0) | plg_finder_content (2.5.0) | plg_finder_contacts (2.5.0) | plg_finder_newsfeeds (2.5.0) | plg_finder_weblinks (2.5.0) | plg_quickicon_extensionupdate (2.5.0) | plg_quickicon_joomlaupdate (2.5.0) | plg_search_categories (2.5.0) | plg_search_content (2.5.0) | plg_search_contacts (2.5.0) | search - jevents (2.2.0) | plg_search_newsfeeds (2.5.0) | plg_search_weblinks (2.5.0) | plg_system_cache (2.5.0) | plg_system_highlight (2.5.0) | plg_system_debug (2.5.0) | plg_system_languagecode (2.5.0) | plg_system_languagefilter (2.5.0) | plg_system_log (2.5.0) | plg_system_logout (2.5.0) | plg_system_p3p (2.5.0) | plg_system_redirect (2.5.0) | plg_system_remember (2.5.0) | plg_system_sef (2.5.0) | plg_user_contactcreator (2.5.0) | plg_user_profile (2.5.0) | plg_user_joomla (2.5.0) |templates discovered :: wrote:templates :: site :: 20120904 (1.0) | atomic (2.5.0) | beez_20 (2.5.0) | beez5 (2.5.0) |
templates :: admin :: bluestork (2.5.0) | hathor (2.5.0) |
i not sure went wrong, have deleted files , used backup domain provider. reckon backup copy contained files didn't want.
however, see issues report above? in advance!
off hand see
.htaccess/web.config: no -->> should using rename htaccess.txt .htaccess
register globals: 1 -->> register globals should 0 or off. feature deprecated of php 5.3.0 , removed of php 5.4.0 -- should not use host has enabled or allows enabled. if enabled turn off.
folders (directories) set 744. directories set 755, setting them 744 might or cause access issues.
reason:
directories have quirk, if directory not have execute permission set if read bit set, 1 may not able access files within directory. in other words, execute setting allows program (joomla) "execute" commands in directory, without being on program (in our case web server) cannot execute "read" command within directory, , cannot deliver file(s) (joomla) users web browser.
have checked out , gone through before post information?
also sure no extensions versions using appear on vel. if are, updates developers site or remove extension.
.htaccess/web.config: no -->> should using rename htaccess.txt .htaccess
register globals: 1 -->> register globals should 0 or off. feature deprecated of php 5.3.0 , removed of php 5.4.0 -- should not use host has enabled or allows enabled. if enabled turn off.
folders (directories) set 744. directories set 755, setting them 744 might or cause access issues.
reason:
directories have quirk, if directory not have execute permission set if read bit set, 1 may not able access files within directory. in other words, execute setting allows program (joomla) "execute" commands in directory, without being on program (in our case web server) cannot execute "read" command within directory, , cannot deliver file(s) (joomla) users web browser.
have checked out , gone through before post information?
also sure no extensions versions using appear on vel. if are, updates developers site or remove extension.
Comments
Post a Comment