reggiep Posted October 6, 2008 Posted October 6, 2008 My school site has been attcked (cannot put certain word beginninng with H as then it gets filtered b y our provider!) the site by p@3t_b@y runs joomla 1.5. Someohow somebody has managed to log on as an administrator, add an article and then change the admin passwoird so I can now no longer log on! HELP! The site is externally hosted but all other bits'n'pieces seem fine on the server so I guess I had a vunerability with my joomla package that I had not upgraded to. Bugger. Does anyone know what this vunerabilty may be so I could use it to get back on and change the password back? Or does anyone know how I could get round this by maybe installing Joomla again and then linking it back to the original joomla database? Thanks
matt40k Posted October 6, 2008 Posted October 6, 2008 Hope you have a backup. Reinstall, restore backup upgrade to latest version (stable). I assuming your using CPanel, in wish case it could have been a breatch from there too.. Check with your provider.
keithu Posted October 6, 2008 Posted October 6, 2008 (edited) You just need to use phpMyAdmin (or whatever) to open the mysql table containing your user passwords. The first user will probably be the admin and will be the one they've messed with. Write a new password to the password field and you'll be able to log in again. The password will probably have to be written in an encrypted form. ETA: You can use this webpage to make a new encrypted password http://elmar-eigner.de/md5_encryption.html Edited October 6, 2008 by keithu more info
alonebfg Posted October 6, 2008 Posted October 6, 2008 just for intrest how many users are admin ie what do your teacher log in as. make sure all your user do not have backend access and only you have this. If you have any more problems pm me and i will talk you through it.
reggiep Posted October 6, 2008 Author Posted October 6, 2008 I managed vto get our hosts to restore from a backup. Thanks dreamhosting.co.uk. I did have a play with phpmyadmin as suggested by keithu and found that the hacker had changed the log on name and email address to his own! I changed the email address back to mine and then went through the lost password procedure to change the password back to mine. That way I did not have to bother with password hashes. i guess I need to upgrade joomla now from 1.5.3 to 1.5.7 to try to protect it from more bored turkish hackers. Thanks
alonebfg Posted October 6, 2008 Posted October 6, 2008 to update download this http://joomlacode.org/gf/download/frsrelease/8375/31008/Joomla_1.5.3_to_1.5.7-Stable-Patch_Package.zip and then ftp it on top of what you got replacing old files. jobe done. 1
saundersmatt Posted October 6, 2008 Posted October 6, 2008 to update download this http://joomlacode.org/gf/download/frsrelease/8375/31008/Joomla_1.5.3_to_1.5.7-Stable-Patch_Package.zip and then ftp it on top of what you got replacing old files. jobe done. Or so you would hope. But i did that this morning after seeing the "my site has been hacked" threads and panicing slightly. Did a backup of current site and ran the upgrade patch. Which failed spectacularly. Tried recovering to the backup, also didn't work (due to me being a complete idiot with the ftp client). So i've spent all day reinstalling joomla, themes and components. Oh well, needed to bugfix a few bits anyway so got that done at the same time. Matt
reggiep Posted October 7, 2008 Author Posted October 7, 2008 I think I was done by the reset password hack. I upgraded yesterday to 1.5.7 just by ftp-ing over the top and everything seems to be working fine with no problems. Thanks guys for all the help.
contink Posted October 7, 2008 Posted October 7, 2008 Or so you would hope. But i did that this morning after seeing the "my site has been hacked" threads and panicing slightly. Did a backup of current site and ran the upgrade patch. Which failed spectacularly. Tried recovering to the backup, also didn't work (due to me being a complete idiot with the ftp client). So i've spent all day reinstalling joomla, themes and components. Oh well, needed to bugfix a few bits anyway so got that done at the same time. Matt The silver lining on stuff like that is that you learn more about the system and are better prep'd when some other issue hits. Still a pain in the **** though..
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now