Site hacked (1.0.12) - Joomla! Forum - community, help and support


hi,
  know there loads of posts , have been hacked before put down age of install.
last friday night hacked , index.php replaced script kiddie.
i have copy of http logs unfortunately in haste restore site lost time stamp on modified files. far can tell left dbase alone.

the exploit looks little this:
post /index.php?mosconfig_absolute_path=nastyfile.txt (i can provide full sanitised logs if needed)
these loads of lines in logs trying lots of different files, lost time stamp on index.php cant pinpoint exact 1 worked.

my joomla ver 1.0.12
php 5.0.4
mysql 4.1.20
apache 2.0.54
globals off
magic quotes on

i have few components installed , wondering if these may problem have read joomla should hardened against type of attack.

3rd party stuff:
tmedit ver 1.0
tinymce ver 2.0.8
hot property ver 0.98
mosforms ver 0.3rc2
sitemap ver 1.2
swmenufree ver 2.0
xaneon extensions ver 2.0.0-beta2

any fantastic site clients entire livelihood , worried @ moment after hacked first time told him upgrading 1.0.12 stop it!

paul

read stickies in forum. check out security faq section in site.
upgrade 1.0.13





Comments

Popular posts from this blog

Error: ‘for’ loop initial declarations are only allowed in C99 or C11 mode - Raspberry Pi Forums

class MPU6050 has no member named begin

missing filename after '-o'