Digital Point Forums
Money Transfer

Go Back   Digital Point Forums > Design & Development > Site & Server Administration > Security
Google Analytics
Log In to view
your analytics

Reply
 
Thread Tools
  #1  
Old Jul 26th 2007, 11:22 am
Blogmaster's Avatar
Blogmaster Blogmaster is offline
SEO Legend
 
Join Date: May 2004
Location: In Firetown!
Posts: 24,393
Blogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond repute
Joomla based site hacked by Turkish hacker

This is my latest site http://www.propertyhogs.com/ and it's just been hacked. Do you believe that Jommla has some serious security issues?
Reply With Quote
  #2  
Old Jul 26th 2007, 11:24 am
sarahk's Avatar
sarahk sarahk is offline
iTamer
 
Join Date: Mar 2004
Location: itamer @ Fibs
Posts: 9,579
sarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond repute
Phone Verified
Joomla have just released a new version... had you upgraded?

you should only need to replace the index page -- although you may find it's the index page of your template, not the main site index
they don't normally do much else
Reply With Quote
  #3  
Old Jul 26th 2007, 11:25 am
Blogmaster's Avatar
Blogmaster Blogmaster is offline
SEO Legend
 
Join Date: May 2004
Location: In Firetown!
Posts: 24,393
Blogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond repute
No, but I'm doing it now. So you think that he got access thru Joomla, right?
Reply With Quote
  #4  
Old Jul 26th 2007, 11:26 am
fsmedia's Avatar
fsmedia fsmedia is offline
WordPress Developer
 
Join Date: Nov 2005
Posts: 5,086
fsmedia is a splendid one to beholdfsmedia is a splendid one to beholdfsmedia is a splendid one to beholdfsmedia is a splendid one to beholdfsmedia is a splendid one to beholdfsmedia is a splendid one to beholdfsmedia is a splendid one to beholdfsmedia is a splendid one to behold
Quote:
Originally Posted by Blogmaster View Post
This is my latest site http://www.propertyhogs.com/ and it's just been hacked. Do you believe that Jommla has some serious security issues?
it's probably the case you left a file with the wrong permissions.

it could happen to ANY cms out there.
__________________
============================================
Web Hosting: Liquid Web, Inc. - Email Marketing: Aweber
============================================
Reply With Quote
  #5  
Old Jul 26th 2007, 11:28 am
sarahk's Avatar
sarahk sarahk is offline
iTamer
 
Join Date: Mar 2004
Location: itamer @ Fibs
Posts: 9,579
sarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond repute
Phone Verified
Quote:
Originally Posted by Blogmaster View Post
No, but I'm doing it now. So you think that he got access thru Joomla, right?
No, but he was probably targetting Joomla because there will be a file commonly left with the wrong permissions
Reply With Quote
  #6  
Old Jul 26th 2007, 11:32 am
Blogmaster's Avatar
Blogmaster Blogmaster is offline
SEO Legend
 
Join Date: May 2004
Location: In Firetown!
Posts: 24,393
Blogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond repute
My server guy just told me it was the latest and most secure version of Joomla. This is really changing my mind about Joomla. Has anyone else you know with a Joomla based site been hacked?
Reply With Quote
  #7  
Old Jul 26th 2007, 11:37 am
sarahk's Avatar
sarahk sarahk is offline
iTamer
 
Join Date: Mar 2004
Location: itamer @ Fibs
Posts: 9,579
sarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond reputesarahk has a reputation beyond repute
Phone Verified
Mike - they may have got in through any number of means. Could be an insecure password which you've used somewhere else and he hacked that site but it's most likely through a config file with 777 perms.

Suck it up, change that index file, check your perms and move on.

The benefits of Joomla outweigh the minor inconvenience.

Oh and get sqlyog and automate your database backups
Reply With Quote
  #8  
Old Jul 26th 2007, 2:57 pm
wendallb's Avatar
wendallb wendallb is online now
Champion of the Naaru
 
Join Date: Jun 2007
Posts: 164
wendallb is on a distinguished road
Yes , I had a joomla site hacked by someone saying they were Turks,

It was my fault as I had the wrong permissions on a file. The permissions issue is now fixed.
__________________
WendallB
General Directory|The Young at Heart Gang|
Reply With Quote
  #9  
Old Jul 26th 2007, 5:16 pm
Blogmaster's Avatar
Blogmaster Blogmaster is offline
SEO Legend
 
Join Date: May 2004
Location: In Firetown!
Posts: 24,393
Blogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond repute
Quote:
Originally Posted by sarahk View Post
Mike - they may have got in through any number of means. Could be an insecure password which you've used somewhere else and he hacked that site but it's most likely through a config file with 777 perms.
I hope so, I'm glad he didn't get to any important parts of the site. For now I have added the old homepage.
Reply With Quote
  #10  
Old Jul 28th 2007, 12:43 am
bading bading is offline
Grunt
 
Join Date: Jul 2007
Posts: 56
bading is on a distinguished road
Same thing happened to my Joomla based site, www.bading.com. Few days ago, I was hacked with this Turkish Hacker, At first, he modified the Index.php of the Joomla based, not the template index.php, then after I fixed it, he went back again and modified the configuration.php. I sent email to Godaddy (my Hosting Server), and they found out that the vulnerable files from my site are came from one of the Joomla Module and not from the Joomla Installed. This Module is the Expose Module (Normally use for Gallery) that you can download for free. After I uninstalled the Module, everything was fixed including the spams on my other modules.

I suggest, please be careful downloading these free modules, there are so many holes on it and some of it was created by the hackers as well.
Reply With Quote
  #11  
Old Jul 28th 2007, 11:33 am
Blogmaster's Avatar
Blogmaster Blogmaster is offline
SEO Legend
 
Join Date: May 2004
Location: In Firetown!
Posts: 24,393
Blogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond reputeBlogmaster has a reputation beyond repute
Has Joomla ever commented on these issues?
Reply With Quote
  #12  
Old Jul 28th 2007, 8:51 pm
bading bading is offline
Grunt
 
Join Date: Jul 2007
Posts: 56
bading is on a distinguished road
Warning: Installing 3rd party extensions may compromise your server's security. Upgrading your Joomla! installation will not update your 3rd party extensions.
For more information on keeping your site secure, please see the Joomla! Security Forum.

That's the only warning.
Reply With Quote
  #13  
Old Jul 31st 2007, 9:17 am
jamestcs jamestcs is offline
Grunt
 
Join Date: Nov 2005
Posts: 32
jamestcs is an unknown quantity at this point
my site was also hacked by Turkish last month... may be the same person are doing it.
__________________
James
FLV player | Chinese Soup |
Reply With Quote
  #14  
Old Jul 31st 2007, 10:31 am
Dubz's Avatar
Dubz Dubz is offline
of the Nightfall
 
Join Date: Feb 2007
Location: Yelling BlogLife & Emptying a Clip!
Posts: 1,863
Dubz has much to be proud ofDubz has much to be proud ofDubz has much to be proud ofDubz has much to be proud ofDubz has much to be proud ofDubz has much to be proud ofDubz has much to be proud ofDubz has much to be proud of
A friends JOomla site got hacked same group. The basic install of joomla is filled with holes.

If you aren't willing to figure it all out / technically capable hire someone or forget it .

A friend of mine does it and it takes a while lots of patches and what not.
__________________
Bloggeries Blogs For Sale - Blogging Forum - -
Reply With Quote
  #15  
Old Aug 1st 2007, 11:18 am
trichnosis trichnosis is offline
Herald of the Titans
 
Join Date: Jul 2005
Location: use this space for 15$/month
Posts: 13,721
trichnosis has much to be proud oftrichnosis has much to be proud oftrichnosis has much to be proud oftrichnosis has much to be proud oftrichnosis has much to be proud oftrichnosis has much to be proud oftrichnosis has much to be proud oftrichnosis has much to be proud oftrichnosis has much to be proud oftrichnosis has much to be proud of
i dont think joomla sites has big security holes.

in my experience , hosting servers are having holes which is being a reason for hacking
__________________
Reply With Quote
  #16  
Old Aug 7th 2007, 3:27 am
deebee's Avatar
deebee deebee is offline
Hand of A'dal
 
Join Date: Mar 2007
Location: In a field
Posts: 410
deebee is just really nicedeebee is just really nicedeebee is just really nicedeebee is just really nicedeebee is just really nice
Quote:
Originally Posted by Blogmaster View Post
No, but I'm doing it now. So you think that he got access thru Joomla, right?
Hi Mike,

I had one site hacked and another about to be hacked by the Turk - here's the lowdown.

The access point was through the cache directory which I stupidly left on 777 (full read/write). It should be 755. Check this dir for files called good.php or ozey.php. If you find either, delete the files and set the dir permission level to 755.

Next step is to chmod all dirs to 755. This will stop you from installing mods/components/templates so if you need to do any installs, temp mod back to 777, do the installs, then mod back to 777 afterwards.
__________________
Bidding Web Directory / SEO Directory / /
Reply With Quote
  #17  
Old Aug 18th 2007, 2:13 pm
Imran's Avatar
Imran Imran is offline
of the Nightfall
Recent Blog: ATI Radeon HD 5970
 
Join Date: Apr 2005
Location: Bangalore
Posts: 2,288
Imran is a splendid one to beholdImran is a splendid one to beholdImran is a splendid one to beholdImran is a splendid one to beholdImran is a splendid one to beholdImran is a splendid one to behold
I know this is a bump, but today my site was hacked as well grrr, index.php file was replaced, I had lots of lots of bad permissions direct 777, now I have set permissions to what they should be dirs 655 and files 644.
Hopefully his will not happen again.
Reply With Quote
  #18  
Old Aug 18th 2007, 11:46 pm
deebee's Avatar
deebee deebee is offline
Hand of A'dal
 
Join Date: Mar 2007
Location: In a field
Posts: 410
deebee is just really nicedeebee is just really nicedeebee is just really nicedeebee is just really nicedeebee is just really nice
You'll find that if you install via Fantastico, it leaves lots of dirs open.

Another tip is to install sh404SEF - that way, it makes Joomla sites less easy to find.
__________________
Bidding Web Directory / SEO Directory / /
Reply With Quote
  #19  
Old Aug 19th 2007, 1:22 am
Divisive Cottonwood Divisive Cottonwood is offline
of the Nightfall
 
Join Date: Jul 2007
Location: DPRK
Posts: 1,622
Divisive Cottonwood has a spectacular aura aboutDivisive Cottonwood has a spectacular aura about
for security the core of joomla is fine, it's when people use extensions that the problems arise.
__________________
Web Design | RSS Directory
Reply With Quote
  #20  
Old Aug 19th 2007, 5:39 am
Imran's Avatar
Imran Imran is offline
of the Nightfall
Recent Blog: ATI Radeon HD 5970
 
Join Date: Apr 2005
Location: Bangalore
Posts: 2,288
Imran is a splendid one to beholdImran is a splendid one to beholdImran is a splendid one to beholdImran is a splendid one to beholdImran is a splendid one to beholdImran is a splendid one to behold
what does sh404SE does? there is already 404 page available in joomla? to handle such errors?
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
SpyGrup going down? (Turkish hacker gang) Daz General Chat 2 Oct 18th 2009 3:45 pm
Any advice on what I can do about this - Turkish hacker jb007uk Site & Server Administration 2 Dec 14th 2008 6:59 am
Hacked by turkish hacker..... dave487 Site & Server Administration 45 Aug 10th 2008 10:48 am
HackeD by UyuSsman ( Turkish Hacker ) bading Site & Server Administration 20 Jul 24th 2007 4:10 am
Who do I report Turkish hacker to ? jb007uk Legal Issues 5 Jun 11th 2007 6:02 am


All times are GMT -8. The time now is 11:57 am.