1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Joomla based site hacked by Turkish hacker

Discussion in 'Security' started by Blogmaster, Jul 26, 2007.

  1. #1
    This is my latest site http://www.propertyhogs.com/ and it's just been hacked. Do you believe that Jommla has some serious security issues?
     
    Blogmaster, Jul 26, 2007 IP
  2. sarahk

    sarahk iTamer Staff

    Messages:
    28,500
    Likes Received:
    4,460
    Best Answers:
    123
    Trophy Points:
    665
    #2
    Joomla have just released a new version... had you upgraded?

    you should only need to replace the index page -- although you may find it's the index page of your template, not the main site index
    they don't normally do much else
     
    sarahk, Jul 26, 2007 IP
  3. Blogmaster

    Blogmaster Blood Type Dating Affiliate Manager

    Messages:
    25,924
    Likes Received:
    1,354
    Best Answers:
    0
    Trophy Points:
    380
    #3
    No, but I'm doing it now. So you think that he got access thru Joomla, right?
     
    Blogmaster, Jul 26, 2007 IP
  4. fsmedia

    fsmedia Prominent Member

    Messages:
    5,163
    Likes Received:
    262
    Best Answers:
    0
    Trophy Points:
    390
    #4
    it's probably the case you left a file with the wrong permissions.

    it could happen to ANY cms out there.
     
    fsmedia, Jul 26, 2007 IP
  5. sarahk

    sarahk iTamer Staff

    Messages:
    28,500
    Likes Received:
    4,460
    Best Answers:
    123
    Trophy Points:
    665
    #5
    No, but he was probably targetting Joomla because there will be a file commonly left with the wrong permissions
     
    sarahk, Jul 26, 2007 IP
  6. Blogmaster

    Blogmaster Blood Type Dating Affiliate Manager

    Messages:
    25,924
    Likes Received:
    1,354
    Best Answers:
    0
    Trophy Points:
    380
    #6
    My server guy just told me it was the latest and most secure version of Joomla. This is really changing my mind about Joomla. Has anyone else you know with a Joomla based site been hacked?
     
    Blogmaster, Jul 26, 2007 IP
  7. sarahk

    sarahk iTamer Staff

    Messages:
    28,500
    Likes Received:
    4,460
    Best Answers:
    123
    Trophy Points:
    665
    #7
    Mike - they may have got in through any number of means. Could be an insecure password which you've used somewhere else and he hacked that site but it's most likely through a config file with 777 perms.

    Suck it up, change that index file, check your perms and move on.

    The benefits of Joomla outweigh the minor inconvenience.

    Oh and get sqlyog and automate your database backups ;)
     
    sarahk, Jul 26, 2007 IP
  8. wendallb

    wendallb Active Member

    Messages:
    180
    Likes Received:
    9
    Best Answers:
    0
    Trophy Points:
    78
    #8
    Yes , I had a joomla site hacked by someone saying they were Turks,

    It was my fault as I had the wrong permissions on a file. The permissions issue is now fixed.
     
    wendallb, Jul 26, 2007 IP
  9. Blogmaster

    Blogmaster Blood Type Dating Affiliate Manager

    Messages:
    25,924
    Likes Received:
    1,354
    Best Answers:
    0
    Trophy Points:
    380
    #9
    I hope so, I'm glad he didn't get to any important parts of the site. For now I have added the old homepage.
     
    Blogmaster, Jul 26, 2007 IP
  10. bading

    bading Peon

    Messages:
    62
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Same thing happened to my Joomla based site, www.bading.com. Few days ago, I was hacked with this Turkish Hacker, At first, he modified the Index.php of the Joomla based, not the template index.php, then after I fixed it, he went back again and modified the configuration.php. I sent email to Godaddy (my Hosting Server), and they found out that the vulnerable files from my site are came from one of the Joomla Module and not from the Joomla Installed. This Module is the Expose Module (Normally use for Gallery) that you can download for free. After I uninstalled the Module, everything was fixed including the spams on my other modules.

    I suggest, please be careful downloading these free modules, there are so many holes on it and some of it was created by the hackers as well.
     
    bading, Jul 28, 2007 IP
  11. Blogmaster

    Blogmaster Blood Type Dating Affiliate Manager

    Messages:
    25,924
    Likes Received:
    1,354
    Best Answers:
    0
    Trophy Points:
    380
    #11
    Has Joomla ever commented on these issues?
     
    Blogmaster, Jul 28, 2007 IP
  12. bading

    bading Peon

    Messages:
    62
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Warning: Installing 3rd party extensions may compromise your server's security. Upgrading your Joomla! installation will not update your 3rd party extensions.
    For more information on keeping your site secure, please see the Joomla! Security Forum.

    That's the only warning. :)
     
    bading, Jul 28, 2007 IP
  13. jamestcs

    jamestcs Peon

    Messages:
    33
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #13
    my site was also hacked by Turkish last month... may be the same person are doing it.
     
    jamestcs, Jul 31, 2007 IP
  14. Dubz

    Dubz Peon

    Messages:
    1,859
    Likes Received:
    156
    Best Answers:
    0
    Trophy Points:
    0
    #14
    A friends JOomla site got hacked same group. The basic install of joomla is filled with holes.

    If you aren't willing to figure it all out / technically capable hire someone or forget it :).

    A friend of mine does it and it takes a while lots of patches and what not.
     
    Dubz, Jul 31, 2007 IP
  15. trichnosis

    trichnosis Prominent Member

    Messages:
    13,785
    Likes Received:
    333
    Best Answers:
    0
    Trophy Points:
    300
    #15
    i dont think joomla sites has big security holes.

    in my experience , hosting servers are having holes which is being a reason for hacking
     
    trichnosis, Aug 1, 2007 IP
  16. deebee

    deebee Active Member

    Messages:
    414
    Likes Received:
    64
    Best Answers:
    0
    Trophy Points:
    70
    #16
    Hi Mike,

    I had one site hacked and another about to be hacked by the Turk - here's the lowdown.

    The access point was through the cache directory which I stupidly left on 777 (full read/write). It should be 755. Check this dir for files called good.php or ozey.php. If you find either, delete the files and set the dir permission level to 755.

    Next step is to chmod all dirs to 755. This will stop you from installing mods/components/templates so if you need to do any installs, temp mod back to 777, do the installs, then mod back to 777 afterwards.
     
    deebee, Aug 7, 2007 IP
  17. Imran

    Imran Notable Member

    Messages:
    2,340
    Likes Received:
    190
    Best Answers:
    0
    Trophy Points:
    230
    #17
    I know this is a bump, but today my site was hacked as well grrr, index.php file was replaced, I had lots of lots of bad permissions direct 777, now I have set permissions to what they should be dirs 655 and files 644.
    Hopefully his will not happen again.
     
    Imran, Aug 18, 2007 IP
  18. deebee

    deebee Active Member

    Messages:
    414
    Likes Received:
    64
    Best Answers:
    0
    Trophy Points:
    70
    #18
    You'll find that if you install via Fantastico, it leaves lots of dirs open.

    Another tip is to install sh404SEF - that way, it makes Joomla sites less easy to find.
     
    deebee, Aug 18, 2007 IP
    Imran likes this.
  19. Divisive Cottonwood

    Divisive Cottonwood Peon

    Messages:
    1,674
    Likes Received:
    35
    Best Answers:
    0
    Trophy Points:
    0
    #19
    for security the core of joomla is fine, it's when people use extensions that the problems arise.
     
    Divisive Cottonwood, Aug 19, 2007 IP
  20. Imran

    Imran Notable Member

    Messages:
    2,340
    Likes Received:
    190
    Best Answers:
    0
    Trophy Points:
    230
    #20
    what does sh404SE does? there is already 404 page available in joomla? to handle such errors?
     
    Imran, Aug 19, 2007 IP