Jump to content

Recommended Posts

Posted

My school site has been attcked (cannot put certain word beginninng with H as then it gets filtered b y our provider!)

 

the site by p@3t_b@y runs joomla 1.5.

Someohow somebody has managed to log on as an administrator, add an article and then change the admin passwoird so I can now no longer log on!

 

HELP!

 

The site is externally hosted but all other bits'n'pieces seem fine on the server so I guess I had a vunerability with my joomla package that I had not upgraded to.

 

Bugger.

 

Does anyone know what this vunerabilty may be so I could use it to get back on and change the password back?

 

Or does anyone know how I could get round this by maybe installing Joomla again and then linking it back to the original joomla database?

 

Thanks

Posted

Hope you have a backup.

 

Reinstall, restore backup upgrade to latest version (stable).

 

I assuming your using CPanel, in wish case it could have been a breatch from there too.. Check with your provider.

Posted (edited)

You just need to use phpMyAdmin (or whatever) to open the mysql table containing your user passwords. The first user will probably be the admin and will be the one they've messed with. Write a new password to the password field and you'll be able to log in again. The password will probably have to be written in an encrypted form.

 

ETA: You can use this webpage to make a new encrypted password

http://elmar-eigner.de/md5_encryption.html

Edited by keithu
more info
Posted
just for intrest how many users are admin ie what do your teacher log in as. make sure all your user do not have backend access and only you have this. If you have any more problems pm me and i will talk you through it.
Posted

I managed vto get our hosts to restore from a backup. Thanks dreamhosting.co.uk.

 

I did have a play with phpmyadmin as suggested by keithu and found that the hacker had changed the log on name and email address to his own!

 

I changed the email address back to mine and then went through the lost password procedure to change the password back to mine. That way I did not have to bother with password hashes.

 

i guess I need to upgrade joomla now from 1.5.3 to 1.5.7 to try to protect it from more bored turkish hackers.

 

Thanks

Posted
to update download this http://joomlacode.org/gf/download/frsrelease/8375/31008/Joomla_1.5.3_to_1.5.7-Stable-Patch_Package.zip and then ftp it on top of what you got replacing old files. jobe done.

 

Or so you would hope. But i did that this morning after seeing the "my site has been hacked" threads and panicing slightly. Did a backup of current site and ran the upgrade patch. Which failed spectacularly. Tried recovering to the backup, also didn't work (due to me being a complete idiot with the ftp client). So i've spent all day reinstalling joomla, themes and components.

Oh well, needed to bugfix a few bits anyway so got that done at the same time.

 

Matt

Posted

I think I was done by the reset password hack.

I upgraded yesterday to 1.5.7 just by ftp-ing over the top and everything seems to be working fine with no problems.

 

Thanks guys for all the help. ;)

Posted
Or so you would hope. But i did that this morning after seeing the "my site has been hacked" threads and panicing slightly. Did a backup of current site and ran the upgrade patch. Which failed spectacularly. Tried recovering to the backup, also didn't work (due to me being a complete idiot with the ftp client). So i've spent all day reinstalling joomla, themes and components.

Oh well, needed to bugfix a few bits anyway so got that done at the same time.

 

Matt

 

The silver lining on stuff like that is that you learn more about the system and are better prep'd when some other issue hits. Still a pain in the **** though.. :o

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...