Support

Admin Tools

#14163 Joomla 2.5.8 sites all running latest Admin tools being hacked. Injection of default.php files which contain malware. What do I do now?

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Tuesday, 25 December 2012 18:00 CST

adiehm

Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? No
Have I searched the tickets before posting? No
Have I read the documentation before posting (which pages?)? No
Joomla! version: (unknown)
PHP version: (unknown)
MySQL version: (unknown)
Host: (optional, but it helps us help you)
Admin Tools version: (unknown)

Description of my issue:

nicholas
Akeeba Staff
Manager

Have you read the Unhacking Your Site walkthrough? That's the first step to understanding what happened, how to fix that and how to prevent that. As you will see in that walkthrough article, it's possible to get hacked from the back door, i.e. another hacked site on your server lead to your site getting hacked (given inadequate ownership and permissions), through a .php file you've allowed to run directly over the web (not though Joomla!) or maybe you were exploited yesterday and hacked today. Admin Tools –like all other security extensions– can only protect you against attacks coming over the web and going through Joomla!'s index.php files. Anything else can go through, hence all the other seemingly paranoid security advice we give. Once you get hacked once I guess none of it sounds paranoid or too expensive any more. Yeah, trust me, we've all been through this.

On the fixing part, there is something not mentioned in those instructions, simply because it wasn't around last year when I wrote the article. It's called Audit My Joomla! and I strongly recommend it. It will audit your site, detect all suspicious files and allow you to unhack your site with a few clicks. Compared to spending days of manually comparing files and missing something, it's well worth the small fee. In your case, I'd recommend the 19.99£ monthly subscription as it will allow you to do unlimited audits: you will need at least two audits per site, one at the beggining of fixing your site, one when you're done, possibly another one in the interim for sanity's sake, times 8 sites. The 19.99£ subscription is really good value in this case.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!