Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Joomla site hacked. bad link has been added

Posted on 2014-04-16
8
Medium Priority
?
566 Views
Last Modified: 2014-04-23
Hi
www.planetaid-uk.org
If you sroll all the way to to bottom, 3 bad links to porno sites has been added
I am trying to remove them but cant find any place where they have added it
I have tried the index.php of my template but its not there

Please see attached.
Is there a way to find out where this 3 links has been added so i can remove it?
hacking.jpg
0
Comment
Question by:morten444
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
8 Comments
 
LVL 1

Expert Comment

by:ceo_tech
ID: 40004906
Restore your backup and you should be back up and running in know time. Also you should get fail2ban install.
0
 
LVL 54

Expert Comment

by:Scott Fell, EE MVE
ID: 40004925
If you have any plug ins for forms, ads, comments etc.  Turn those off.  Then make sure they are all up to date.
0
 

Author Comment

by:morten444
ID: 40009265
Hi
Thanks for advice.
My question was more if there is a way to locate using firebug or any other tool how to find in what PHP file this has been inserted?

we have file2ban installed
Have 15days rolling backup. problem is customer discovered so late that even the first one is infected so restore no option.
I need to find where the text has been inseted

Anyone?
0
Veeam Task Manager for Hyper-V

Task Manager for Hyper-V provides critical information that allows you to monitor Hyper-V performance by displaying real-time views of CPU and memory at the individual VM-level, so you can quickly identify which VMs are using host resources.

 
LVL 54

Expert Comment

by:Scott Fell, EE MVE
ID: 40009298
I would just query the db and look for <script>something bad... </script> and remove/find and replace.
0
 

Author Comment

by:morten444
ID: 40009812
Hi
Thanks for your answer.
I have tried to search how i can search any text from any table in my database

I have a database called planetaiduk
I have about 60 tables (joomla and extentions)
I use PhPmyadmin
There is a search field when my database is highligted but i get no maches when i search for example "r43dsworlduk" (one of the hacked links)

I also do not get any match if i search planetaid so i guess i can not search in that way
Can you tell me how i can search any text containing the word
r43dsworlduk
in any table in my database using phpmyadmin?
0
 

Author Comment

by:morten444
ID: 40009817
Hi again
Sorry if i mark all the tables i do get responds but no match on this word
I do get matches on other words i search so i guess the database is not compremised
So it has to be inseted into a php file i guess
any other idears?
0
 

Accepted Solution

by:
morten444 earned 0 total points
ID: 40009829
Issue solved
I downloaded website and did a search on this word without any match
i then updated joomla to latest version and that seem to have removed the script
0
 

Author Closing Comment

by:morten444
ID: 40017025
Updating Joomla must have overwritten the file that was infected.
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are times when I have encountered the need to decompress a response from a PHP request. This is how it's done, but you must have control of the request and you can set the Accept-Encoding header.
In this article, I’ll talk about multi-threaded slave statistics printed in MySQL error log file.
Learn how to match and substitute tagged data using PHP regular expressions. Demonstrated on Windows 7, but also applies to other operating systems. Demonstrated technique applies to PHP (all versions) and Firefox, but very similar techniques will w…
In this video, Percona Solution Engineer Rick Golba discuss how (and why) you implement high availability in a database environment. To discuss how Percona Consulting can help with your design and architecture needs for your database and infrastr…
Suggested Courses

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question