Jump to content

Recommended Posts

Posted

Hi there,

 

The wife has just told me that her school are having issues looking at there website.

 

When going straight to it Home / St Mary's RCPS Lowestoft it goes to the site, well it has here on our IE9 laptop but my iPad just sends me to google.co.uk

 

If you google search for st Mary's school Lowestoft and then click on the link in the search results, you just get sent to google.co.uk

 

Any ideas?

 

Thanks

Posted

Unfortunately it looks like the website has been hacked. When I visit it (via a Google search), it tries to download a dodgy looking Java app from h**p://oxigiqt.lflinkup.com/PJeHubmUDaovPDRCJxGMEzlYXdvvppcg. :eek:

 



be84eb392b






 

Does the school have a backup of the website?

  • Thanks 1
Posted

Let's hope so. :)

 

What is really strange about it, is that I no longer get redirected to that domain above (just Google - like you). I reckon if I installed an old version of Java and/or Flash Player I would probably get infected with a trojan. Not sure I want to try that. ;)

Posted

A restore has just been done albeit from a backup in May but at least they have something to start from again.

 

Has anyone any advice I could pass on re locking down a Joomla 1.5 site?

 

Thanks

Posted
Has anyone any advice I could pass on re locking down a Joomla 1.5 site?

 

Thanks

 

Best bet would be to 1) upgrade to the latest version of Joomla (2.5.7) (2) ensure permissions are correct on directories and finally (3) ensure that all passwords for accessing are nice and strong.

 

:)

  • Thanks 1
Posted (edited)

A few more...

 

3b) Don't forget to change the FTP password.

4) Ensure all third-party Joomla extensions/plug-ins are up-to-date.

5) Upgrade PHP to the latest supported release (v5.3.16 or v5.4.6) since the website is currently several versions behind on v5.3.14 and PHP is frequently exploited. This may not be possible on some shared webhosts however.

6) Use Google's Fetch as Google tool to see the website as Google sees it. Read the text in the grey box for more details on how this helps.

Edited by Arthur
Posted
The chap doing the site has just emailed me to say that when we go to h**t://www.stmarysrcps.co.uk it is picking up the site from a folder called public_html instead of www within the Joomla folder structure. He has read that by having things in the Public_html folder itself is a security flaw. Is this correct? If so how does he go about getting the site picked out of the www folder instead?
Posted
Why are people hacking school websites?

 

A lot of them use bots that don't care about the content of the site, they just look for vulnerabilities in whatever CMS is being used and then drop link spam or malware onto them automatically.

Posted
A lot of them use bots that don't care about the content of the site, they just look for vulnerabilities in whatever CMS is being used and then drop link spam or malware onto them automatically.

 

[ATTACH=CONFIG]15204[/ATTACH].

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...