Solved

Joomla hack redirects article saves to malware

Posted on 2011-03-01
6
1,104 Views
Last Modified: 2012-05-11
I have a 2 y/o Joomla site.  Using Joomla 1.5.2.  Has worked fine until today.  Attempted to edit the article home page.  Made the change and clicked on Save. Was immediately redirected to a site declaring i was infected ...  great fireworks showing phony scans indicating many infections. X'd out of all and end processed the offending tab ..   went to site to see if my change had taken.  It hadn't.  Went back to admin and it appears that once in an article if I attempt to save or close or apply I am immediately redirected to an unbranded Search site with Facebook themed hits.  This happens on any computer.  Verio is my host and it happened to my tech support rep.
There has been no impact on the site itself ...  it's just admin so far that is affected/infected.   THere is only an htaccess.txt file in the site root.  The files licenses.php, license.php, install.php,index.php credits.php, configuration.php and changelog.php all have dates of 2/23/2011 ..  I made no changes on that day.
Welcome suggestions ..
0
Comment
Question by:bborner
6 Comments
 
LVL 3

Expert Comment

by:thomasd04
ID: 35012987
Hi bborner. Are you asking for how this may have happened or how to fix the problem?
Are you using any forms on the website? If so perhaps a possible SQL Injection.
Or do you use unsecured FTP to transfer files or install extensions?

0
 

Author Comment

by:bborner
ID: 35013032
attached are the last 200 lines of my logfile ... says morpheus strikes again
 logfiles.txt
0
 
LVL 28

Expert Comment

by:chilternPC
ID: 35013117
have you every backed up the system? if I would restore the source files (not the database - leave that)
if no backup then I would back up the site first (use http://www.akeebabackup.com/download.html)
then I would reupload your original Joomla source files (except for the installation directory)
if that doesn't fix it  re-install any extensions you have iinstalled.
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 8

Expert Comment

by:austega
ID: 35014036
Mmmm... Take a deep breath and don't rush into anything, in order to avoid making things worse.

Then follow the path that others have found safest and most useful - see the one on the Joomla doc site at http://docs.joomla.org/Security_and_Performance_FAQs#Help.21_My_site.27s_been_compromised._Now_what.3F .

From what you have said I would think that a complete new install - either via Akeeba's Kickstart script if you have an Akeeba backup from before the hack or using a Joomla 1.5.22 install will be required. Probably your database is okay.

Remember to review your backup and security arrangements while you are motivated to put them in place!
0
 

Accepted Solution

by:
bborner earned 0 total points
ID: 35071708
Thank you all for your comments ...  
I found the obscure code in each of the files; licenses.php, changelog.php, configuration.php, copyright.php, credits.php, index.php immediately after the first <?php...

All is well .. thanks again
0
 

Author Closing Comment

by:bborner
ID: 35120648
Found the incriminating code causing the problem
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
PHP Upload using Uploadify 4 59
Apache 2.2 on Windows 2008 32 53
htaccess file 3 65
.htaccess rewrite url with querystring problem 13 75
This article summarizes using a simple matrix to map the different type of phishing attempts and its targeted victims. It also run through many scam scheme scenario with "real" phished emails. There are safeguards highlighted to stay vigilance and h…
Ransomware continues to be a growing problem for both personal and business users alike and Antivirus companies are still struggling to find a reliable way to protect you from this dangerous threat.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now