1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

My site has been HACKED ! help !

Discussion in 'Security' started by tapalapa, Feb 21, 2007.

  1. #1
    :( :confused: . Help! . at 4:16pm GMT, my joomla site got hacked by a turkish group. They have not removed any database or deleted files.. but they have left a message on the main page. I tried to find where the message is hidden but cant find it !. This is bad for me. a lot of my visitors have seen the message and i have some PR to clean up after this mess as most wont trust to the site . I was making average $20 daily google revenues. today, my site has dropped to $2.13 .

    Please advice. I need to act immediately as i know more of my members are trying to get on the site. The last backup i have was in october! :(
    [​IMG]
     
    tapalapa, Feb 21, 2007 IP
  2. blue_angel

    blue_angel Well-Known Member

    Messages:
    1,174
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    130
    #2
    Your hoster don't have more resent backup ? Do you host your site?
    Anyway There is NO PANIC....
    The most possible hacked your site and your mysql is untouchable and workable.
    1) Save current database mysql backup somewhere else from site (download to you pc local)
    2) Try to remember all your change (templates ....e.t.c) modules installed...
    3) Make your last restore backup you have and upload, re install module may be have install since last backup you have
    4) Upload the backup of database you took earlier and you have your site back
    5) Change ALL PASSWORDS
    6)
     
    blue_angel, Feb 21, 2007 IP
  3. kmzeron

    kmzeron Well-Known Member

    Messages:
    734
    Likes Received:
    40
    Best Answers:
    0
    Trophy Points:
    128
    #3
    What version of joomla are you using ? Try to see what your config file contains ? There must to be !
     
    kmzeron, Feb 21, 2007 IP
  4. Dawzz

    Dawzz Active Member

    Messages:
    66
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    50
    #4
    I notice your running a vps. If you need help let me know. I suggest installing mod_security with a decent set of rules and disabling certain php functions as a frontline defense.
     
    Dawzz, Feb 21, 2007 IP
  5. Mxhub

    Mxhub Active Member

    Messages:
    474
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    55
    #5

    I second that.
    I see lot of hack attempts due to bad scripting found on some of the mods installed with joomla.

    Better careful.
     
    Mxhub, Feb 21, 2007 IP
  6. koolasia

    koolasia Banned

    Messages:
    1,413
    Likes Received:
    59
    Best Answers:
    0
    Trophy Points:
    0
    #6
    just re upload the frsh files and connnect it to databese and it should work
     
    koolasia, Feb 24, 2007 IP
  7. rootbinbash

    rootbinbash Peon

    Messages:
    2,198
    Likes Received:
    88
    Best Answers:
    0
    Trophy Points:
    0
    #7
    without fixing the security vul. its useless to open the site.If you did not touch any file,you can request a log from your hosting provider so you can see which files have been touched.You should check the files in /includes folder.
     
    rootbinbash, Feb 24, 2007 IP
  8. sundaybrew

    sundaybrew Numerati

    Messages:
    7,294
    Likes Received:
    1,260
    Best Answers:
    0
    Trophy Points:
    560
    #8
    I agree.....

    Also , Try just re uploading your index.php...most of the time hackers just swap that out...NOT always but sometimes
     
    sundaybrew, Feb 24, 2007 IP
  9. fouadz

    fouadz Peon

    Messages:
    132
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #9
    if you don't fix the security issue, you will just get hacked another time ....
     
    fouadz, Feb 25, 2007 IP
  10. bigrollerdave

    bigrollerdave Well-Known Member

    Messages:
    2,112
    Likes Received:
    52
    Best Answers:
    0
    Trophy Points:
    140
    #10
    My sites were hacked by the same people. I don't have joomla though it's 100% custom. They don't seem to be out to hurt anyone though more for the fact of doing it. They just uploaded a index.html file that's all. They didn't touch the database or anything like that.
     
    bigrollerdave, Feb 25, 2007 IP
  11. host_planer

    host_planer Banned

    Messages:
    174
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #11

    This is real serious problem. and i also have this same problem from last 2 days. i change my passwords 2 time. but they replace again index file. i am going to open new thread here on security forum. so kindly post there, how to solve this issue.
     
    host_planer, Feb 26, 2007 IP
  12. mcfox

    mcfox Wind Maker

    Messages:
    7,526
    Likes Received:
    716
    Best Answers:
    0
    Trophy Points:
    360
    #12
    Have a look through Zone-h's archives - actually, have a look through your webstats and look for a referral from Zone-h. That will give you the details of the hack and save you time messing about wondering how they got in.
     
    mcfox, Feb 26, 2007 IP
  13. host_planer

    host_planer Banned

    Messages:
    174
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #13
    Yes, but i need solution. how they can just change index file.? they only always just change index file.
    do i have to change my hosting? or what
     
    host_planer, Feb 26, 2007 IP
  14. koolasia

    koolasia Banned

    Messages:
    1,413
    Likes Received:
    59
    Best Answers:
    0
    Trophy Points:
    0
    #14
    actually 1 file is deleted named version.php in includes folder
     
    koolasia, Feb 26, 2007 IP
  15. host_planer

    host_planer Banned

    Messages:
    174
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #15
    what it mean, can you kindly explain ? thanks in advance for your help
     
    host_planer, Feb 26, 2007 IP
  16. koolasia

    koolasia Banned

    Messages:
    1,413
    Likes Received:
    59
    Best Answers:
    0
    Trophy Points:
    0
    #16
    Do You Have The Back Up

    Send Me The File named version.php in includes folder so i can have a lot ?
     
    koolasia, Feb 26, 2007 IP
    Cheap SEO Services likes this.